This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

cannot remove Rootkit.TDSS.v3 from XP system [Solved]

32 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hello Cavan

I only have the infected computer and I notice instructions are for Clean computer ? Is this a problem?


It is not a problem if the malware does not interfere with the download and execution of the tools and you are able to create your bootable CD.
Sunyata, Tried a few times to create bootable CD. The burn CD utility looks like it writes to CD and completes, but when I look at CD, there are 0 bytes left and 0 bytes free space. Then tried rebooting anyway from that D: drive and nothing. Any ideas ? CD is a 700 MB Memorex CD-RW
Hello Cavan

Only an empty CD drive will show 0 bytes used and 0 bytes free. Are you sure you are looking at the right drive?
There are two CD drives on my machine. Below is a picture of what that looks like in "My Computer"

[external image: Posted Image]

The D: drive is an Empty CD drive. The E: drive contains the xPUD CD, as the Name column indicates, with a Total Size of 63.7MB.

Please check and make sure that it is in fact the D: in which you have your newly burned CD.

If so, it may be there is a problem with your drive where it will write but not read. Do you have an already burned CD of the 700 MB Memorex CD-RW type that the drive will read?
Or it may be that your CD drive does not recognize the CD format of your disc, and that it won't write or read a Memorex CD-RW CD. Have you ever burned a CD of that type in that drive before?
Sunyata, It is definitely the D: drive. When I load CD, I checked to be sure that drive appeared with 700 MB free space. Then I started the utility, and the drive light stayed on as it (presumably) wrote to the CD, then 0 bytes appeared when I checked again. As to whether I've burned that type of CD before, I have one from a few years ago with files I copied and backed up that I can read from. BTWโ€ฆI tried again, and it seems to write, because it give me option to erase the CD after, it looks as if it is copying, not writing. A sson as I erase the CD, it appears again with 700MB avaialble.
Hello Cavan

Sunyata, Finally I think I got it..here you go..

Indeed you did. Good job. :thumbup:

These instructions will change your boot partition from the TDL4 rogue partition to the partition containing your Operating Systemโ€ฆ

  • Download tdl_fix.sh and save it to the xPUD flash drive.
  • Boot into xPUD then click the File tab.
  • Press File
  • Expand mnt
  • Click on the folder under mnt that represents your USB drive (sdb1 ?)
  • You should see the tdl_fix.sh file in the main window.
  • Select Tool from the Menu
  • Choose Open Terminal
  • Type bash tdl_fix.sh then press Enter.
  • Read the warning then type y and press Enter to continue.
  • Type sda then press Enter when prompted.
  • You will be shown a list of partitions to choose marking active.
  • Type 2 then press Enter.
  • If you are presented with a warning about no bootloader files, type n then press Enter to choose another. If this happens, type 3 to select partition 3 then press Enter.
  • When you receive no warning about bootloader files but are presented with another view of the partition structure and asked if it looks correct, type y then press Enter.
  • The script will complete and prompt you to reboot the computer.
  • Close the Terminal window and restart back into Windows.
  • Post the contents of the tdl_fix.txt file that was created on your flash drive and let me know how the computer is behaving.

Note - in the event there is a problem booting the computer normally after running the script, run the tdl_fix.sh script again using the following command.

bash tdl_fix.sh -restore

Make sure to leave a space to either side of tdl_fix.sh in the command.
This will prompt you to use the file tdl_mbr_sda.bin on drive sda.
Ok the procedure then restart when complete.
This is a backup of the original mbr and will restore it to it's current state.
Sunyata,

Here is the tdl_fix.txt file :

2012-01-24-18:04:41

The following drives were found
sda
sdc
User has chosen drive sda
backing up mbr to tdl_mbr_sda.bin


Disk /dev/sda: 120.0 GB, 120000000000 bytes
255 heads, 63 sectors/track, 14589 cylinders, total 234375000 sectors
Units = sectors of 1 * 512 = 512 bytes

Device Boot Start End Blocks Id System
/dev/sda1 63 80324 40131 de Unknown
/dev/sda2 80325 234372284 117145980 7 HPFS/NTFS
/dev/sda3 * 234372285 234374983 1349+ 17 Hidden HPFS/NTFS

Model: ATA WDC WD1200JB-75C (scsi)
Disk /dev/sda: 120GB
Sector size (logical/physical): 512B/512B
Partition Table: msdos

Number Start End Size Type File system Flags
1 32.3kB 41.1MB 41.1MB primary fat16
2 41.1MB 120GB 120GB primary ntfs
3 120GB 120GB 1382kB primary ntfs boot, hidden


User has chosen to make partition 2 active

Model: ATA WDC WD1200JB-75C (scsi)
Disk /dev/sda: 120GB
Sector size (logical/physical): 512B/512B
Partition Table: msdos

Number Start End Size Type File system Flags
1 32.3kB 41.1MB 41.1MB primary fat16
2 41.1MB 120GB 120GB primary ntfs boot
3 120GB 120GB 1382kB primary ntfs hidden


User has accepted changes

As for system behavior, I no longer am getting google redirects. I am however getting a low humming/buzz from my speajers that started have way through this process.Not sure what that may be. Do I need to re-install drivers ?

Also, is it safe now to run an anti malware bytes and/or my virus scan tool ?

Thanks for your help,

Cavan
Hello Cavan

I am however getting a low humming/buzz from my speajers

Not sure what that is yet. We have lots yet to do to clean up your machine. Let's first see if it goes away as a matter of course.

Also, is it safe now to run an anti malware bytes and/or my virus scan tool ?

Please do not run any tools on your own while we are helping. It can result in our confusion and we may miss something.
You can turn on your AV if you wish to go browsing or need to download something. But, please keep it to a minimum and do not install anything until we are done and I give you the "ALL CLEAN."

Now, lets get rid of that TDL4 hidden partitionโ€ฆ

  • Boot into xPUD then click the File tab.
  • Press File
  • Expand mnt
  • Click on the folder under mnt that represents your USB drive (sdb1 ?)
  • You should see the tdl_fix.sh file in the main window.
  • Select Tool from the Menu
  • Choose Open Terminal
  • Type bash tdl_fix.sh -delete then press Enter.
  • ** Make sure to leave a space to either side of tdl_fix.sh in the command.
  • You should be notified of a hidden partition found and prompted to delete it.
  • Type y then press Enter.
  • The script will complete and prompt you to reboot the computer.
  • Close the Terminal window and restart back into Windows.
  • Post the contents of the tdl_delete.txt file that was created on your flash drive.

Note - in the event there is a problem booting the computer normally after running the script, run the tdl_fix.sh script again using the following command.

bash tdl_fix.sh -restore

Make sure to leave a space to either side of tdl_fix.sh in the command.
This will prompt you to use the file tdl_mbr_sda.bin on drive sda.
Ok the procedure then restart when complete.
Sunyata, No problem, just wanted to check. I will stay away from any A/V scans or any actions until I get the all clear from you. Be back to you in a little whie. Cavan
Sunyata,

Here are the contents of the tdl_delete,txt file:

2012-01-25-13:03:51

using tdl_delete_sda.bin

Model: ATA WDC WD1200JB-75C (scsi)
Disk /dev/sda: 120GB
Sector size (logical/physical): 512B/512B
Partition Table: msdos

Number Start End Size Type File system Flags
1 32.3kB 41.1MB 41.1MB primary fat16
2 41.1MB 120GB 120GB primary ntfs boot
3 120GB 120GB 1382kB primary ntfs hidden

Hidden partition found on sda
sda3 is hidden
Deleting partition 3 on drive sda

Model: ATA WDC WD1200JB-75C (scsi)
Disk /dev/sda: 120GB
Sector size (logical/physical): 512B/512B
Partition Table: msdos

Number Start End Size Type File system Flags
1 32.3kB 41.1MB 41.1MB primary fat16
2 41.1MB 120GB 120GB primary ntfs boot

No hidden partition on sdc
Hello Cavan

That log looks good. Your TDL4 rogue partition has been deleted.:thumbup:

Let's get some fresh scans thenโ€ฆ

Please re-run OTL
  • If you are using Firefox, make sure that your download settings are as follows:

    -Tools->Options->Main tab
    -Set to "Always ask me where to Save the files".

  • Double click on OTL.exe to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output
  • Check the boxes beside LOP Check and Purity Check.
  • In the window under Custom Scans/Fixes copy and paste the following


netsvcs
%SYSTEMDRIVE%\*.*
%systemroot%\Fonts\*.com
%systemroot%\Fonts\*.dll
%systemroot%\Fonts\*.ini
%systemroot%\Fonts\*.ini2
%systemroot%\Fonts\*.exe
%systemroot%\system32\spool\prtprocs\w32x86\*.*
%systemroot%\REPAIR\*.bak1
%systemroot%\REPAIR\*.ini
%systemroot%\system32\*.jpg
%systemroot%\*.jpg
%systemroot%\*.png
%systemroot%\*.scr
%systemroot%\*._sy
%APPDATA%\Adobe\Update\*.*
%ALLUSERSPROFILE%\Favorites\*.*
%APPDATA%\Microsoft\*.*
%PROGRAMFILES%\*.*
%APPDATA%\Update\*.*
%systemroot%\*. /mp /s
CREATERESTOREPOINT
%systemroot%\System32\config\*.sav
%PROGRAMFILES%\bak. /s
%systemroot%\system32\bak. /s
%ALLUSERSPROFILE%\Start Menu\*.lรฎk /x
%systemroot%\system32\config\systemprofile\*.dat /x
%systemroot%\*.config
%systemroot%\system32\*.db
%PROGRAMFILES%\Internet Explorer\*.dat
%APPDATA%\Mikzosoft\Internet Explorer\Quick Launch\*.lnk /x
%USERPROFILE%\Deskuop\*.exe
%PROGRAMFILES%\Common Files\*.*
%systemroot%\*.src
%systemroot%\install\*.*
%systemroot%\system32\DLL\*.*
%systemroot%\system32\HelpFiles\*.*
%systemroot%\system32\rundll\*.*
%systemroot%\winn32\*.*
%systemroot%\Java\*.*
%systemroot%\system32\test\*.*
%systemroot%\system32\Rundll32\*.*
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results Install|LastSuccessTime /rs
%USERPROFILE%\..|smtmp;true;true;true /FP
%temp%\smtmp\*.* /s >
/md5start
iexplore.*
explorer.*
winlogon.*
dll
zx.dll
hlp.dat
/md5stop

  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.

When the scan completes, it will open OTL.txt. This is saved in the same location as OTL.
Please copy (Edit->Select All, Edit->Copy) the contents and post it with your next reply.

Next,

Please download aswMBR to your desktop.

  • Double click the aswMBR icon to run it.

    Vista and Windows 7 users right click the icon and choose "Run as administrator".

  • When asked if you want to download Avast's virus definitions please select Yes.
  • Click the Scan button to start scan.
  • When it finishes, press the save log button, save the logfile to your desktop and post its contents in your next reply.

[external image: Posted Image]


In your next post, please include:
  • OTL.txt
  • The aswMBR log
Sunyata,

That's great news. I have the OTL.txt but the Avast scan seems to be running still ?

OTL logfile created on: 1/25/2012 6:26:37 PM - Run 2
OTL by OldTimer - Version 3.2.31.0 Folder = C:\Documents and Settings\Emmet Smith\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

510.98 Mb Total Physical Memory | 236.40 Mb Available Physical Memory | 46.26% Memory free
1.22 Gb Paging File | 0.93 Gb Available in Paging File | 76.65% Paging File free
Paging file location(s): C:\pagefile.sys 768 1536 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 111.72 Gb Total Space | 89.44 Gb Free Space | 80.06% Space Free | Partition Type: NTFS
Drive D: | 63.73 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS
Drive G: | 3.73 Gb Total Space | 3.69 Gb Free Space | 98.90% Space Free | Partition Type: FAT32

Computer Name: EMMET | User Name: Emmet Smith | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Documents and Settings\Emmet Smith\Desktop\OTL.exe (OldTimer Tools)
PRC - c:\Program Files\McAfee\SiteAdvisor\saUI.exe (McAfee, Inc.)
PRC - c:\Program Files\McAfee\SiteAdvisor\McSACore.exe (McAfee, Inc.)
PRC - C:\Program Files\PC Tools Security\BDT\BDTUpdateService.exe (Threat Expert Ltd.)
PRC - C:\Program Files\McAfee Security Scan\2.0.181\SSScheduler.exe (McAfee, Inc.)
PRC - C:\Program Files\Real\RealPlayer\realplay.exe (RealNetworks, Inc.)
PRC - C:\Program Files\Common Files\AOL\1285387552\ee\aolsoftware.exe (AOL LLC)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Adobe\Photoshop Elements 3.0\PhotoshopElementsFileAgent.exe ()
PRC - C:\Program Files\Adobe\Photoshop Elements 3.0\PhotoshopElementsDeviceConnect.exe ()
PRC - C:\Program Files\Common Files\AOL\ACS\acsd.exe (America Online, Inc.)
PRC - C:\WINDOWS\wanmpsvc.exe (America Online, Inc.)


========== Modules (No Company Name) ==========

MOD - C:\Program Files\PC Tools Security\BDT\BSPatch.dll ()
MOD - C:\WINDOWS\system32\dlcdcfg.dll ()
MOD - C:\Program Files\Dell Photo AIO Printer 944\dlcdcnv4.dll ()
MOD - C:\Program Files\Adobe\Photoshop Elements 3.0\PhotoshopElementsFileAgent.exe ()
MOD - C:\Program Files\Adobe\Photoshop Elements 3.0\platform.dll ()
MOD - C:\Program Files\Adobe\Photoshop Elements 3.0\PhotoshopElementsDeviceConnect.exe ()


========== Win32 Services (SafeList) ==========

SRV - (nosGetPlusHelper) getPlusยฎ โ€“ File not found
SRV - (HidServ) โ€“ File not found
SRV - (McAfee SiteAdvisor Service) โ€“ c:\Program Files\McAfee\SiteAdvisor\McSACore.exe (McAfee, Inc.)
SRV - (sdCoreService) โ€“ C:\Program Files\PC Tools Security\pctsSvc.exe (PC Tools)
SRV - (sdAuxService) โ€“ C:\Program Files\PC Tools Security\pctsAuxs.exe (PC Tools)
SRV - (ThreatFire) โ€“ C:\Program Files\PC Tools Security\TFEngine\TFService.exe (PC Tools)
SRV - (Browser Defender Update Service) โ€“ C:\Program Files\PC Tools Security\BDT\BDTUpdateService.exe (Threat Expert Ltd.)
SRV - (McComponentHostService) โ€“ C:\Program Files\McAfee Security Scan\2.0.181\McCHSvc.exe (McAfee, Inc.)
SRV - (dlcd_device) โ€“ C:\WINDOWS\System32\dlcdcoms.exe ( )
SRV - (AdobeActiveFileMonitor) โ€“ C:\Program Files\Adobe\Photoshop Elements 3.0\PhotoshopElementsFileAgent.exe ()
SRV - (PhotoshopElementsDeviceConnect) โ€“ C:\Program Files\Adobe\Photoshop Elements 3.0\PhotoshopElementsDeviceConnect.exe ()
SRV - (AOL ACS) โ€“ C:\Program Files\Common Files\AOL\ACS\acsd.exe (America Online, Inc.)
SRV - (WANMiniportService) WAN Miniport (ATW) โ€“ C:\WINDOWS\wanmpsvc.exe (America Online, Inc.)
SRV - (NMSSvc) Intelยฎ โ€“ C:\WINDOWS\system32\NMSSvc.Exe (Intel Corporation)


========== Driver Services (SafeList) ==========

DRV - (pctplsg) โ€“ C:\WINDOWS\system32\drivers\pctplsg.sys (PC Tools)
DRV - (PCTSD) โ€“ C:\WINDOWS\system32\drivers\PCTSD.sys (PC Tools)
DRV - (pctBTFix) โ€“ C:\WINDOWS\System32\Drivers\pctBTFix.sys (PC Tools)
DRV - (pctgntdi) โ€“ C:\WINDOWS\system32\drivers\pctgntdi.sys (PC Tools)
DRV - (TfSysMon) โ€“ C:\WINDOWS\system32\drivers\TfSysMon.sys (PC Tools)
DRV - (TfNetMon) โ€“ C:\WINDOWS\system32\drivers\TfNetMon.sys (PC Tools)
DRV - (TfFsMon) โ€“ C:\WINDOWS\system32\drivers\TfFsMon.sys (PC Tools)
DRV - (PCTCore) โ€“ C:\WINDOWS\system32\drivers\PCTCore.sys (PC Tools)
DRV - (pctEFA) โ€“ C:\WINDOWS\system32\drivers\pctEFA.sys (PC Tools)
DRV - (pctDS) โ€“ C:\WINDOWS\system32\drivers\pctDS.sys (PC Tools)
DRV - (PCTBD) โ€“ C:\WINDOWS\system32\drivers\PCTBD.sys (PC Tools)
DRV - (ASCTRM) โ€“ C:\WINDOWS\System32\drivers\asctrm.sys (Windows ยฎ 2000 DDK provider)
DRV - (P16X) Creative SB Live! Series (WDM) โ€“ C:\WINDOWS\system32\drivers\P16X.sys (Creative Technology Ltd.)
DRV - (ctsfm2k) โ€“ C:\WINDOWS\system32\drivers\ctsfm2k.sys (Creative Technology Ltd)
DRV - (ossrv) โ€“ C:\WINDOWS\system32\drivers\ctoss2k.sys (Creative Technology Ltd.)
DRV - (BCMModem) โ€“ C:\WINDOWS\system32\drivers\BCMSM.sys (Broadcom Corporation)
DRV - (wanatw) WAN Miniport (ATW) โ€“ C:\WINDOWS\system32\drivers\wanatw4.sys (America Online, Inc.)
DRV - (NMSCFG) โ€“ C:\WINDOWS\system32\drivers\NMSCFG.SYS (Intel Corporation)
DRV - (OMCI) โ€“ C:\WINDOWS\SYSTEM32\DRIVERS\OMCI.SYS (Dell Computer Corporation)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========


IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.comcast.net/
IE - HKCU\..\URLSearchHook: {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
IE - HKCU\..\URLSearchHook: {472734EA-242A-422b-ADF8-83D1E48CC825} - C:\Program Files\PC Tools Security\BDT\PCTBrowserDefender.dll (Threat Expert Ltd.)
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@mcafee.com/MVT: C:\Program Files\McAfee\Supportability\MVT\NPMVTPlugin.dll (McAfee, Inc.)
FF - HKLM\Software\MozillaPlugins\@mcafee.com/SAFFPlugin: C:\Program Files\McAfee\SiteAdvisor\npmcffplg32.dll (McAfee, Inc.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\4.0.60310.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.95\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.95\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@viewpoint.com/VMP: C:\Program Files\Viewpoint\Viewpoint Experience Technology\npViewpoint.dll ()

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{4ED1F68A-5463-4931-9384-8FFF5ED91D92}: C:\Program Files\McAfee\SiteAdvisor [2012/01/23 14:29:38 | 000,000,000 | โ€”D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{cb84136f-9c44-433a-9048-c5cd9df1dc16}: C:\Program Files\PC Tools Security\BDT\Firefox\ [2012/01/21 16:12:53 | 000,000,000 | โ€”D | M]


O1 HOSTS File: ([2010/09/26 12:49:47 | 000,000,027 | โ€”- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (AcroIEHlprObj Class) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (PC Tools Browser Defender BHO) - {2A0F3D1B-0909-4FF4-B272-609CCE6054E7} - C:\Program Files\PC Tools Security\BDT\PCTBrowserDefender.dll (Threat Expert Ltd.)
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.7.7227.1100\swg.dll (Google Inc.)
O2 - BHO: (McAfee SiteAdvisor BHO) - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O2 - BHO: (Avery Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask.com)
O3 - HKLM\..\Toolbar: (McAfee SiteAdvisor Toolbar) - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O3 - HKLM\..\Toolbar: (PC Tools Browser Defender) - {472734EA-242A-422B-ADF8-83D1E48CC825} - C:\Program Files\PC Tools Security\BDT\PCTBrowserDefender.dll (Threat Expert Ltd.)
O3 - HKLM\..\Toolbar: (Avery Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask.com)
O3 - HKCU\..\Toolbar\WebBrowser: (PC Tools Browser Defender) - {472734EA-242A-422B-ADF8-83D1E48CC825} - C:\Program Files\PC Tools Security\BDT\PCTBrowserDefender.dll (Threat Expert Ltd.)
O3 - HKCU\..\Toolbar\WebBrowser: (Avery Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask.com)
O4 - HKLM..\Run: [HostManager] C:\Program Files\Common Files\AOL\1285387552\ee\aolsoftware.exe (AOL LLC)
O4 - HKLM..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k File not found
O4 - HKLM..\Run: [NvCplDaemon] C:\WINDOWS\System32\NvCpl.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [nwiz] C:\WINDOWS\System32\nwiz.exe (NVIDIA Corporation)
O4 - HKLM..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe (RealNetworks, Inc.)
O4 - HKLM..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u File not found
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe (Adobe Systems, Inc.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe (Adobe Systems Incorporated)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\America Online 9.0 Tray Icon.lnk = C:\Program Files\America Online 9.0\aoltray.exe (America Online, Inc.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\McAfee Security Scan Plus.lnk = C:\Program Files\McAfee Security Scan\2.0.181\SSScheduler.exe (McAfee, Inc.)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Recovery present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDesktop = 0
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\Program Files\Common Files\PC Tools\Lsp\PCTLsp.dll (PC Tools Research Pty Ltd.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\Program Files\Common Files\PC Tools\Lsp\PCTLsp.dll (PC Tools Research Pty Ltd.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\Program Files\Common Files\PC Tools\Lsp\PCTLsp.dll (PC Tools Research Pty Ltd.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000019 - C:\Program Files\Common Files\PC Tools\Lsp\PCTLsp.dll (PC Tools Research Pty Ltd.)
O15 - HKCU\..Trusted Domains: aol.com ([objects] * is out of zone range - 5)
O15 - HKCU\..Trusted Domains: internet ([]about in Trusted sites)
O15 - HKCU\..Trusted Domains: mcafee.com ([]http in Trusted sites)
O15 - HKCU\..Trusted Domains: mcafee.com ([]https in Trusted sites)
O16 - DPF: {02BCC737-B171-4746-94C9-0D8A0B2C0089} http://office.microsoft.com/sites/production/ieawsdc32.cab (Microsoft Office Template and Media Control)
O16 - DPF: {0742B9EF-8C83-41CA-BFBA-830A59E23533} https://support.microsoft.com/Dcode/ActiveX/MSDcode.cab (Microsoft Data Collection Control)
O16 - DPF: {32505657-9980-0010-8000-00AA00389B71} http://download.microsoft.com/download/0/Aโ€ฆ01F/wmvadvd.cab (Reg Error: Key error.)
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} http://cdn.scan.onecare.live.com/resource/โ€ฆlscbase6770.cab (Windows Live Safety Center Base Module)
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} http://update.microsoft.com/windowsupdate/โ€ฆb?1254091013500 (WUWebControl Class)
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} http://download.eset.com/special/eos/OnlineScanner.cab (OnlineScanner Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-โ€ฆindows-i586.cab (Java Plug-in 1.6.0_29)
O16 - DPF: {8BBDC81D-81B3-49EE-87E8-47B7A707FAE8} https://www1.gotomeeting.com/default/applets/g2mdlax.cab (GoToMeeting Web Starter)
O16 - DPF: {CAFEEFAC-0015-0000-0015-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-โ€ฆindows-i586.cab (Java Plug-in 1.5.0_15)
O16 - DPF: {CAFEEFAC-0015-0000-FFFF-ABCDEFFEDCBA} http://javadl-esd.sun.com/update/1.5.0/jinโ€ฆindows-i586.cab (Java Plug-in)
O16 - DPF: {CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-โ€ฆindows-i586.cab (Java Plug-in 1.6.0_29)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-โ€ฆindows-i586.cab (Java Plug-in 1.6.0_29)
O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} https://trademonster.webex.com/client/T27LB/nbr/ieatgpc.cab (GpcContainer Class)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O16 - DPF: DirectAnimation Java Classes file://C:\WINDOWS\Java\classes\dajava.cab (Reg Error: Key error.)
O16 - DPF: Microsoft XML Parser for Java file://C:\WINDOWS\Java\classes\xmldso.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 75.75.75.75 75.75.76.76
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{02E61563-0C41-44B6-8C5D-2779E66A070B}: DhcpNameServer = 75.75.75.75 75.75.76.76
O18 - Protocol\Handler\dssrequest {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O18 - Protocol\Handler\sacore {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O20 - HKLM Winlogon: Shell - (Explorer.exe) -C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) -C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Documents and Settings\Emmet Smith\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Emmet Smith\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009/09/14 00:01:20 | 000,000,000 | โ€”- | M] () - C:\AUTOEXEC.BAT โ€“ [ NTFS ]
O32 - AutoRun File - [2011/08/04 18:13:52 | 000,000,110 | -Hโ€“ | M] () - G:\autorun.inf โ€“ [ FAT32 ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] โ€“ "%1" %*
O35 - HKLM\..exefile [open] โ€“ "%1" %*
O37 - HKLM\โ€ฆcom [@ = comfile] โ€“ "%1" %*
O37 - HKLM\โ€ฆexe [@ = exefile] โ€“ "%1" %*
O37 - HKCU\โ€ฆexe [@ = exefile] โ€“ Reg Error: Key error. File not found

NetSvcs: 6to4 - File not found
NetSvcs: HidServ - File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found

CREATERESTOREPOINT
Restore point Set: OTL Restore Point

========== Files/Folders - Created Within 30 Days ==========

[2012/01/24 15:44:38 | 000,000,000 | โ€”D | C] โ€“ C:\Documents and Settings\All Users\Application Data\WinZip
[2012/01/24 14:52:32 | 000,000,000 | โ€”D | C] โ€“ C:\Documents and Settings\Emmet Smith\My Documents\SanDisk
[2012/01/24 11:28:36 | 000,000,000 | โ€”D | C] โ€“ C:\Documents and Settings\Emmet Smith\Desktop\GETxPUD
[2012/01/23 18:42:14 | 004,754,944 | โ€”- | C] (Geza Kovacs) โ€“ C:\Documents and Settings\Emmet Smith\Desktop\unetbootin-windows-563.exe
[2012/01/22 17:14:51 | 004,713,472 | โ€”- | C] (AVAST Software) โ€“ C:\Documents and Settings\Emmet Smith\Desktop\aswMBR.exe
[2012/01/22 16:59:42 | 000,000,000 | โ€”D | C] โ€“ C:\Documents and Settings\Emmet Smith\Desktop\RK_Quarantine
[2012/01/22 12:12:50 | 000,584,192 | โ€”- | C] (OldTimer Tools) โ€“ C:\Documents and Settings\Emmet Smith\Desktop\OTL.exe
[2012/01/21 23:57:02 | 000,000,000 | โ€”D | C] โ€“ C:\Documents and Settings\Emmet Smith\Application Data\isoburnerdata
[2012/01/21 18:13:11 | 000,574,424 | โ€“S- | C] (PC Tools) โ€“ C:\WINDOWS\System32\drivers\TfSysMon.sys
[2012/01/21 18:13:11 | 000,054,328 | โ€“S- | C] (PC Tools) โ€“ C:\WINDOWS\System32\drivers\TfFsMon.sys
[2012/01/21 18:13:11 | 000,035,264 | โ€“S- | C] (PC Tools) โ€“ C:\WINDOWS\System32\drivers\TfNetMon.sys
[2012/01/21 16:12:48 | 000,056,840 | โ€”- | C] (PC Tools) โ€“ C:\WINDOWS\System32\drivers\PCTBD.sys
[2012/01/21 16:12:45 | 000,149,456 | โ€”- | C] (PC Tools) โ€“ C:\WINDOWS\SGDetectionTool.dll
[2012/01/21 16:12:44 | 002,246,608 | โ€”- | C] (Threat Expert Ltd.) โ€“ C:\WINDOWS\PCTBDCore.dll
[2012/01/21 16:12:44 | 001,681,360 | โ€”- | C] (Threat Expert Ltd.) โ€“ C:\WINDOWS\PCTBDRes.dll
[2012/01/21 16:08:18 | 000,660,992 | โ€”- | C] (PC Tools) โ€“ C:\WINDOWS\System32\drivers\pctEFA.sys
[2012/01/21 16:08:17 | 000,341,656 | โ€”- | C] (PC Tools) โ€“ C:\WINDOWS\System32\drivers\pctDS.sys
[2012/01/21 16:08:15 | 000,253,096 | โ€”- | C] (PC Tools) โ€“ C:\WINDOWS\System32\drivers\pctgntdi.sys
[2012/01/21 16:08:01 | 000,331,880 | โ€”- | C] (PC Tools) โ€“ C:\WINDOWS\System32\drivers\PCTCore.sys
[2012/01/21 16:08:01 | 000,162,584 | โ€”- | C] (PC Tools) โ€“ C:\WINDOWS\System32\drivers\PCTAppEvent.sys
[2012/01/21 16:07:47 | 000,185,560 | โ€”- | C] (PC Tools) โ€“ C:\WINDOWS\System32\drivers\PCTSD.sys
[2012/01/21 16:07:47 | 000,017,848 | โ€”- | C] (PC Tools) โ€“ C:\WINDOWS\System32\drivers\pctBTFix.sys
[2012/01/21 16:07:47 | 000,000,000 | โ€”D | C] โ€“ C:\Documents and Settings\All Users\Start Menu\Programs\PC Tools Security
[2012/01/21 16:07:30 | 000,070,536 | โ€”- | C] (PC Tools) โ€“ C:\WINDOWS\System32\drivers\pctplsg.sys
[2012/01/21 16:07:03 | 000,000,000 | โ€”D | C] โ€“ C:\Program Files\Common Files\PC Tools
[2012/01/21 16:07:02 | 000,000,000 | โ€”D | C] โ€“ C:\Program Files\PC Tools Security
[2012/01/20 18:57:13 | 000,000,000 | โ€”D | C] โ€“ C:\Documents and Settings\Emmet Smith\My Documents\Malware Removal
[2012/01/20 14:48:42 | 000,000,000 | โ€”D | C] โ€“ C:\Documents and Settings\All Users\Application Data\529C535703E4E89B00006564D151FC4E
[2012/01/20 11:15:34 | 000,000,000 | โ€”D | C] โ€“ C:\Documents and Settings\Emmet Smith\Start Menu\Programs\System Check
[2012/01/20 11:13:03 | 000,000,000 | RH-D | C] โ€“ C:\Documents and Settings\Emmet Smith\Recent
[2012/01/17 10:03:08 | 000,000,000 | โ€”D | C] โ€“ C:\Documents and Settings\Emmet Smith\My Documents\GMS
[2012/01/12 18:12:44 | 000,000,000 | โ€”D | C] โ€“ C:\Documents and Settings\Emmet Smith\My Documents\New Folder
[2012/01/10 16:39:04 | 000,000,000 | โ€”D | C] โ€“ C:\Documents and Settings\Emmet Smith\My Documents\TJX
[2012/01/07 14:40:04 | 000,000,000 | โ€”D | C] โ€“ C:\0758174999c09bc9a33e771d24a2fef8
[2012/01/07 14:23:19 | 000,000,000 | โ€”D | C] โ€“ C:\9b4c345daa14880a3f1249ea
[2012/01/07 14:17:26 | 000,000,000 | โ€”D | C] โ€“ C:\Documents and Settings\Emmet Smith\Application Data\TestApp
[2012/01/05 16:05:28 | 000,000,000 | โ€”D | C] โ€“ C:\Documents and Settings\Emmet Smith\My Documents\Avnet
[2011/12/28 15:43:55 | 000,000,000 | โ€”D | C] โ€“ C:\Documents and Settings\Emmet Smith\My Documents\Buildium
[2011/12/28 14:26:13 | 000,000,000 | โ€”D | C] โ€“ C:\Documents and Settings\Emmet Smith\My Documents\MicroSoft
[2011/12/28 13:48:33 | 000,000,000 | โ€”D | C] โ€“ C:\Documents and Settings\Emmet Smith\My Documents\DELL
[2011/12/27 17:55:09 | 000,000,000 | โ€”D | C] โ€“ C:\Documents and Settings\Emmet Smith\My Documents\2007 Resumes
[2011/12/27 17:48:29 | 000,000,000 | โ€”D | C] โ€“ C:\Documents and Settings\Emmet Smith\My Documents\Pitney Bowes
[2011/12/27 17:14:26 | 000,000,000 | โ€”D | C] โ€“ C:\Documents and Settings\Emmet Smith\My Documents\Plum Choice
[2011/12/27 15:43:50 | 000,000,000 | โ€”D | C] โ€“ C:\Documents and Settings\Emmet Smith\My Documents\GTech
[2009/09/27 20:31:12 | 000,638,976 | โ€”- | C] ( ) โ€“ C:\WINDOWS\System32\dlcdpmui.dll
[2009/09/27 20:31:10 | 000,372,736 | โ€”- | C] ( ) โ€“ C:\WINDOWS\System32\dlcdih.exe
[2009/09/27 20:31:09 | 000,413,696 | โ€”- | C] ( ) โ€“ C:\WINDOWS\System32\dlcdcomm.dll
[2009/09/27 20:31:09 | 000,368,640 | โ€”- | C] ( ) โ€“ C:\WINDOWS\System32\dlcdcfg.exe
[2009/09/27 20:31:09 | 000,114,688 | โ€”- | C] ( ) โ€“ C:\WINDOWS\System32\dlcdpplc.dll
[2009/09/27 20:31:08 | 001,134,592 | โ€”- | C] ( ) โ€“ C:\WINDOWS\System32\dlcdusb1.dll
[2009/09/27 20:31:08 | 000,774,144 | โ€”- | C] ( ) โ€“ C:\WINDOWS\System32\dlcdhbn3.dll
[2009/09/27 20:31:08 | 000,483,328 | โ€”- | C] ( ) โ€“ C:\WINDOWS\System32\dlcdlmpm.dll
[2009/09/27 20:31:07 | 000,704,512 | โ€”- | C] ( ) โ€“ C:\WINDOWS\System32\dlcdcomc.dll
[2009/09/27 20:31:07 | 000,491,520 | โ€”- | C] ( ) โ€“ C:\WINDOWS\System32\dlcdcoms.exe
[2009/09/27 20:31:07 | 000,155,648 | โ€”- | C] ( ) โ€“ C:\WINDOWS\System32\dlcdprox.dll
[2009/09/27 20:31:06 | 001,183,744 | โ€”- | C] ( ) โ€“ C:\WINDOWS\System32\dlcdserv.dll
[2002/04/10 23:41:00 | 000,065,536 | โ€”- | C] ( ) โ€“ C:\WINDOWS\System32\A3d.dll
[4 C:\Documents and Settings\Emmet Smith\My Documents\*.tmp files -> C:\Documents and Settings\Emmet Smith\My Documents\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2012/01/25 18:01:00 | 000,000,246 | โ€”- | M] () โ€“ C:\WINDOWS\tasks\Scheduled Update for Ask Toolbar.job
[2012/01/25 17:43:01 | 000,000,886 | โ€”- | M] () โ€“ C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2012/01/25 13:08:34 | 000,002,206 | โ€”- | M] () โ€“ C:\WINDOWS\System32\wpa.dbl
[2012/01/25 13:07:59 | 000,000,882 | โ€”- | M] () โ€“ C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2012/01/25 13:07:43 | 535,871,488 | -HS- | M] () โ€“ C:\hiberfil.sys
[2012/01/25 13:07:43 | 000,002,048 | โ€“S- | M] () โ€“ C:\WINDOWS\bootstat.dat
[2012/01/24 19:13:12 | 000,000,284 | โ€”- | M] () โ€“ C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2012/01/24 11:47:40 | 000,001,813 | โ€”- | M] () โ€“ C:\Documents and Settings\All Users\Desktop\Google Chrome.lnk
[2012/01/24 11:27:17 | 000,497,272 | โ€”- | M] () โ€“ C:\Documents and Settings\Emmet Smith\Desktop\GETxPUD.exe
[2012/01/23 23:29:24 | 000,000,664 | โ€”- | M] () โ€“ C:\WINDOWS\System32\d3d9caps.dat
[2012/01/23 19:14:38 | 000,000,000 | โ€”- | M] () โ€“ C:\Documents and Settings\Emmet Smith\Desktop\un28785.cfg
[2012/01/23 18:42:21 | 004,754,944 | โ€”- | M] (Geza Kovacs) โ€“ C:\Documents and Settings\Emmet Smith\Desktop\unetbootin-windows-563.exe
[2012/01/23 18:34:48 | 132,220,928 | โ€”- | M] () โ€“ C:\Documents and Settings\Emmet Smith\Desktop\slacko-5.3.1-SCSI-MAIN.iso
[2012/01/23 14:29:32 | 000,804,856 | โ€”- | M] () โ€“ C:\WINDOWS\System32\drivers\Cat.DB
[2012/01/22 17:14:51 | 004,713,472 | โ€”- | M] (AVAST Software) โ€“ C:\Documents and Settings\Emmet Smith\Desktop\aswMBR.exe
[2012/01/22 17:00:53 | 000,111,872 | โ€”- | M] () โ€“ C:\WINDOWS\System32\drivers\TrueSight.sys
[2012/01/22 16:52:02 | 000,787,456 | โ€”- | M] () โ€“ C:\Documents and Settings\Emmet Smith\Desktop\RogueKiller.exe
[2012/01/22 12:12:51 | 000,584,192 | โ€”- | M] (OldTimer Tools) โ€“ C:\Documents and Settings\Emmet Smith\Desktop\OTL.exe
[2012/01/21 16:07:51 | 000,001,682 | โ€”- | M] () โ€“ C:\Documents and Settings\All Users\Desktop\PC Tools Spyware Doctor.lnk
[2012/01/20 13:26:30 | 000,000,815 | โ€”- | M] () โ€“ C:\Documents and Settings\Emmet Smith\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
[2012/01/20 11:16:02 | 000,000,432 | โ€”- | M] () โ€“ C:\Documents and Settings\All Users\Application Data\rWXWFl82Z9aMpR
[2012/01/20 11:15:39 | 000,000,296 | โ€”- | M] () โ€“ C:\Documents and Settings\All Users\Application Data\~rWXWFl82Z9aMpR
[2012/01/20 11:15:39 | 000,000,176 | โ€”- | M] () โ€“ C:\Documents and Settings\All Users\Application Data\~rWXWFl82Z9aMpRr
[2012/01/20 11:15:38 | 000,000,853 | โ€”- | M] () โ€“ C:\Documents and Settings\Emmet Smith\Application Data\Microsoft\Internet Explorer\Quick Launch\System Check.lnk
[2012/01/16 03:01:46 | 000,001,374 | โ€”- | M] () โ€“ C:\WINDOWS\imsins.BAK
[2012/01/07 15:19:09 | 000,002,110 | โ€”- | M] () โ€“ C:\Documents and Settings\Emmet Smith\Desktop\SDASET~1.EXE.lnk
[2012/01/07 14:17:33 | 000,002,110 | โ€”- | M] () โ€“ C:\Documents and Settings\Emmet Smith\Desktop\sdasetup[1].exe.lnk
[2011/12/30 12:33:39 | 000,000,624 | โ€”- | M] () โ€“ C:\Documents and Settings\All Users\Desktop\Malwarebytes Anti-Malware.lnk
[4 C:\Documents and Settings\Emmet Smith\My Documents\*.tmp files -> C:\Documents and Settings\Emmet Smith\My Documents\*.tmp -> ]

========== Files Created - No Company Name ==========

[2012/01/24 11:27:15 | 000,497,272 | โ€”- | C] () โ€“ C:\Documents and Settings\Emmet Smith\Desktop\GETxPUD.exe
[2012/01/23 19:14:38 | 000,000,000 | โ€”- | C] () โ€“ C:\Documents and Settings\Emmet Smith\Desktop\un28785.cfg
[2012/01/23 18:34:48 | 132,220,928 | โ€”- | C] () โ€“ C:\Documents and Settings\Emmet Smith\Desktop\slacko-5.3.1-SCSI-MAIN.iso
[2012/01/22 16:59:45 | 000,111,872 | โ€”- | C] () โ€“ C:\WINDOWS\System32\drivers\TrueSight.sys
[2012/01/22 16:51:58 | 000,787,456 | โ€”- | C] () โ€“ C:\Documents and Settings\Emmet Smith\Desktop\RogueKiller.exe
[2012/01/21 16:12:47 | 000,767,952 | โ€”- | C] () โ€“ C:\WINDOWS\BDTSupport.dll
[2012/01/21 16:12:45 | 000,000,882 | โ€”- | C] () โ€“ C:\WINDOWS\RegSDImport.xml
[2012/01/21 16:12:45 | 000,000,879 | โ€”- | C] () โ€“ C:\WINDOWS\RegISSImport.xml
[2012/01/21 16:12:44 | 000,003,488 | โ€”- | C] () โ€“ C:\WINDOWS\UDB.zip
[2012/01/21 16:12:44 | 000,000,131 | โ€”- | C] () โ€“ C:\WINDOWS\IDB.zip
[2012/01/21 16:07:51 | 000,001,682 | โ€”- | C] () โ€“ C:\Documents and Settings\All Users\Desktop\PC Tools Spyware Doctor.lnk
[2012/01/20 11:15:39 | 000,000,296 | โ€”- | C] () โ€“ C:\Documents and Settings\All Users\Application Data\~rWXWFl82Z9aMpR
[2012/01/20 11:15:39 | 000,000,176 | โ€”- | C] () โ€“ C:\Documents and Settings\All Users\Application Data\~rWXWFl82Z9aMpRr
[2012/01/20 11:15:38 | 000,000,853 | โ€”- | C] () โ€“ C:\Documents and Settings\Emmet Smith\Application Data\Microsoft\Internet Explorer\Quick Launch\System Check.lnk
[2012/01/20 11:15:32 | 000,000,432 | โ€”- | C] () โ€“ C:\Documents and Settings\All Users\Application Data\rWXWFl82Z9aMpR
[2012/01/07 14:38:42 | 000,002,110 | โ€”- | C] () โ€“ C:\Documents and Settings\Emmet Smith\Desktop\SDASET~1.EXE.lnk
[2012/01/07 14:17:32 | 000,002,110 | โ€”- | C] () โ€“ C:\Documents and Settings\Emmet Smith\Desktop\sdasetup[1].exe.lnk
[2011/12/30 12:33:39 | 000,000,624 | โ€”- | C] () โ€“ C:\Documents and Settings\All Users\Desktop\Malwarebytes Anti-Malware.lnk
[2011/03/18 10:55:28 | 000,767,952 | โ€”- | C] () โ€“ C:\WINDOWS\BDTSupport.dll0334.old
[2011/03/18 10:55:28 | 000,767,952 | โ€”- | C] () โ€“ C:\WINDOWS\BDTSupport.dll0146.old
[2010/09/21 15:39:25 | 000,000,664 | โ€”- | C] () โ€“ C:\WINDOWS\System32\d3d9caps.dat
[2010/04/18 18:09:09 | 000,004,608 | โ€”- | C] () โ€“ C:\Documents and Settings\Emmet Smith\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/04/14 18:37:25 | 000,017,228 | -HS- | C] () โ€“ C:\Documents and Settings\Emmet Smith\Local Settings\Application Data\i202
[2010/04/14 18:37:25 | 000,017,228 | -HS- | C] () โ€“ C:\Documents and Settings\All Users\Application Data\i202
[2010/04/14 14:46:34 | 000,763,832 | โ€”- | C] () โ€“ C:\WINDOWS\BDTSupport.dll.old
[2010/03/06 16:53:04 | 000,000,376 | โ€”- | C] () โ€“ C:\WINDOWS\ODBC.INI
[2009/09/28 21:08:28 | 000,000,715 | โ€”- | C] () โ€“ C:\WINDOWS\aolback.exe.lnk
[2009/09/28 21:04:08 | 000,000,335 | โ€”- | C] () โ€“ C:\WINDOWS\nsreg.dat
[2009/09/27 20:31:59 | 000,065,536 | Rโ€” | C] () โ€“ C:\WINDOWS\System32\dlcdcfg.dll
[2009/09/27 20:31:11 | 000,155,648 | โ€”- | C] () โ€“ C:\WINDOWS\System32\dlcdins.dll
[2009/09/27 20:31:11 | 000,106,496 | โ€”- | C] () โ€“ C:\WINDOWS\System32\dlcdinsr.dll
[2009/09/27 20:31:10 | 000,040,960 | โ€”- | C] () โ€“ C:\WINDOWS\System32\dlcdvs.dll
[2009/09/27 20:31:05 | 000,036,864 | โ€”- | C] () โ€“ C:\WINDOWS\System32\dlcdcur.dll
[2009/09/27 20:31:04 | 000,430,080 | โ€”- | C] () โ€“ C:\WINDOWS\System32\dlcdutil.dll
[2009/09/27 20:31:04 | 000,073,728 | โ€”- | C] () โ€“ C:\WINDOWS\System32\dlcdcu.dll
[2009/09/27 20:31:01 | 000,176,128 | โ€”- | C] () โ€“ C:\WINDOWS\System32\dlcdinsb.dll
[2009/09/27 20:31:01 | 000,086,016 | โ€”- | C] () โ€“ C:\WINDOWS\System32\dlcdcub.dll
[2009/09/27 20:30:59 | 000,131,072 | โ€”- | C] () โ€“ C:\WINDOWS\System32\dlcdjswr.dll
[2009/09/27 18:35:37 | 000,004,569 | โ€”- | C] () โ€“ C:\WINDOWS\System32\secupd.dat
[2009/09/25 12:30:49 | 000,000,754 | โ€”- | C] () โ€“ C:\WINDOWS\WORDPAD.INI
[2009/09/14 00:51:45 | 000,004,161 | โ€”- | C] () โ€“ C:\WINDOWS\ODBCINST.INI
[2009/09/14 00:50:45 | 000,294,864 | โ€”- | C] () โ€“ C:\WINDOWS\System32\FNTCACHE.DAT
[2009/09/14 00:03:30 | 000,002,048 | โ€“S- | C] () โ€“ C:\WINDOWS\bootstat.dat
[2009/09/13 23:58:40 | 000,021,640 | โ€”- | C] () โ€“ C:\WINDOWS\System32\emptyregdb.dat
[2009/08/03 14:07:42 | 000,403,816 | โ€”- | C] () โ€“ C:\WINDOWS\System32\OGACheckControl.dll
[2009/08/03 14:07:42 | 000,230,768 | โ€”- | C] () โ€“ C:\WINDOWS\System32\OGAEXEC.exe
[2003/10/06 13:16:00 | 000,027,136 | โ€”- | C] () โ€“ C:\WINDOWS\System32\nvcod.dll
[2003/07/08 12:41:48 | 000,047,616 | โ€”- | C] () โ€“ C:\WINDOWS\System32\P16X.dll
[2002/09/03 15:07:03 | 013,107,200 | โ€”- | C] () โ€“ C:\WINDOWS\System32\oembios.bin
[2002/09/03 15:07:00 | 000,004,594 | โ€”- | C] () โ€“ C:\WINDOWS\System32\oembios.dat
[2002/09/03 14:51:48 | 000,272,128 | โ€”- | C] () โ€“ C:\WINDOWS\System32\perfi009.dat
[2002/09/03 14:51:47 | 000,311,604 | โ€”- | C] () โ€“ C:\WINDOWS\System32\perfh009.dat
[2002/09/03 14:51:46 | 000,028,626 | โ€”- | C] () โ€“ C:\WINDOWS\System32\perfd009.dat
[2002/09/03 14:51:44 | 000,039,992 | โ€”- | C] () โ€“ C:\WINDOWS\System32\perfc009.dat
[2002/09/03 14:50:11 | 000,000,741 | โ€”- | C] () โ€“ C:\WINDOWS\System32\noise.dat
[2002/09/03 14:44:25 | 000,673,088 | โ€”- | C] () โ€“ C:\WINDOWS\System32\mlang.dat
[2002/09/03 14:44:11 | 000,046,258 | โ€”- | C] () โ€“ C:\WINDOWS\System32\mib.bin
[2002/09/03 14:37:19 | 000,218,003 | โ€”- | C] () โ€“ C:\WINDOWS\System32\dssec.dat
[2002/09/03 14:36:07 | 000,001,804 | โ€”- | C] () โ€“ C:\WINDOWS\System32\dcache.bin
[2002/02/06 08:04:14 | 000,065,536 | โ€”- | C] () โ€“ C:\WINDOWS\System32\NMSInst.dll
[2002/01/21 13:17:18 | 000,065,536 | โ€”- | C] () โ€“ C:\WINDOWS\System32\PROInst.dll

========== LOP Check ==========

[2012/01/20 14:48:47 | 000,000,000 | โ€”D | M] โ€“ C:\Documents and Settings\All Users\Application Data\529C535703E4E89B00006564D151FC4E
[2010/04/14 22:00:44 | 000,000,000 | โ€”D | M] โ€“ C:\Documents and Settings\All Users\Application Data\avG
[2009/09/27 17:52:23 | 000,000,000 | โ€”D | M] โ€“ C:\Documents and Settings\All Users\Application Data\Citrix
[2012/01/25 13:08:25 | 000,000,000 | โ€”D | M] โ€“ C:\Documents and Settings\All Users\Application Data\TEMP
[2009/09/28 21:07:23 | 000,000,000 | โ€”D | M] โ€“ C:\Documents and Settings\All Users\Application Data\Viewpoint
[2012/01/24 15:44:38 | 000,000,000 | โ€”D | M] โ€“ C:\Documents and Settings\All Users\Application Data\WinZip
[2012/01/21 23:57:02 | 000,000,000 | โ€”D | M] โ€“ C:\Documents and Settings\Emmet Smith\Application Data\isoburnerdata
[2011/11/01 18:00:16 | 000,000,000 | โ€”D | M] โ€“ C:\Documents and Settings\Emmet Smith\Application Data\PCTools
[2011/08/02 22:13:29 | 000,000,000 | โ€”D | M] โ€“ C:\Documents and Settings\Emmet Smith\Application Data\TeamViewer
[2010/06/25 08:32:31 | 000,000,000 | โ€”D | M] โ€“ C:\Documents and Settings\Emmet Smith\Application Data\Teby
[2012/01/07 14:17:26 | 000,000,000 | โ€”D | M] โ€“ C:\Documents and Settings\Emmet Smith\Application Data\TestApp
[2010/06/09 19:17:56 | 000,000,000 | โ€”D | M] โ€“ C:\Documents and Settings\Emmet Smith\Application Data\Uniblue
[2010/06/24 21:01:12 | 000,000,000 | โ€”D | M] โ€“ C:\Documents and Settings\Emmet Smith\Application Data\Vyyxti
[2011/09/08 14:52:59 | 000,000,000 | โ€”D | M] โ€“ C:\Documents and Settings\Emmet Smith\Application Data\webex
[2012/01/25 18:01:00 | 000,000,246 | โ€”- | M] () โ€“ C:\WINDOWS\Tasks\Scheduled Update for Ask Toolbar.job

========== Purity Check ==========



========== Custom Scans ==========


< %SYSTEMDRIVE%\*.* >
[2009/09/14 00:01:20 | 000,000,000 | โ€”- | M] () โ€“ C:\AUTOEXEC.BAT
[2009/09/27 19:47:14 | 000,000,211 | โ€”- | M] () โ€“ C:\Boot.bak
[2010/09/25 11:04:34 | 000,000,327 | RHS- | M] () โ€“ C:\boot.ini
[2004/08/03 22:00:00 | 000,260,272 | RHS- | M] () โ€“ C:\cmldr
[2009/09/14 00:01:20 | 000,000,000 | โ€”- | M] () โ€“ C:\CONFIG.SYS
[2009/09/26 14:45:20 | 000,009,515 | โ€”- | M] () โ€“ C:\DellDriverDownloadManager.application
[2011/05/23 13:16:13 | 000,001,027 | โ€”- | M] () โ€“ C:\dlcd.log
[2011/07/15 22:52:19 | 000,000,376 | โ€”- | M] () โ€“ C:\dlcdscan.log
[2012/01/25 13:07:43 | 535,871,488 | -HS- | M] () โ€“ C:\hiberfil.sys
[2009/09/14 00:01:20 | 000,000,000 | RHS- | M] () โ€“ C:\IO.SYS
[2010/06/08 11:04:28 | 000,000,109 | โ€”- | M] () โ€“ C:\mbam-error.txt
[2009/09/14 00:01:20 | 000,000,000 | RHS- | M] () โ€“ C:\MSDOS.SYS
[2009/09/27 19:39:44 | 000,047,564 | RHS- | M] () โ€“ C:\NTDETECT.COM
[2009/10/10 12:52:39 | 000,250,048 | RHS- | M] () โ€“ C:\ntldr
[2012/01/25 13:07:42 | 805,306,368 | -HS- | M] () โ€“ C:\pagefile.sys

< %systemroot%\Fonts\*.com >

< %systemroot%\Fonts\*.dll >

< %systemroot%\Fonts\*.ini >
[2009/09/14 00:00:57 | 000,000,067 | -HS- | M] () โ€“ C:\WINDOWS\Fonts\desktop.ini

< %systemroot%\Fonts\*.ini2 >

< %systemroot%\Fonts\*.exe >

< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2005/11/09 14:59:56 | 000,073,728 | โ€”- | M] (Dell, Inc.) โ€“ C:\WINDOWS\system32\spool\prtprocs\w32x86\dlcdPP5C.DLL
[2006/10/26 19:56:12 | 000,033,104 | โ€”- | M] (Microsoft Corporation) โ€“ C:\WINDOWS\system32\spool\prtprocs\w32x86\msonpppr.dll

< %systemroot%\REPAIR\*.bak1 >

< %systemroot%\REPAIR\*.ini >

< %systemroot%\system32\*.jpg >

< %systemroot%\*.jpg >

< %systemroot%\*.png >

< %systemroot%\*.scr >

< %systemroot%\*._sy >

< %APPDATA%\Adobe\Update\*.* >

< %ALLUSERSPROFILE%\Favorites\*.* >

< %APPDATA%\Microsoft\*.* >

< %PROGRAMFILES%\*.* >

< %APPDATA%\Update\*.* >

< %systemroot%\*. /mp /s >

< %systemroot%\System32\config\*.sav >
[2009/09/14 00:49:45 | 000,094,208 | โ€”- | M] () โ€“ C:\WINDOWS\System32\config\default.sav
[2009/09/14 00:49:44 | 000,626,688 | โ€”- | M] () โ€“ C:\WINDOWS\System32\config\software.sav
[2009/09/14 00:49:44 | 000,430,080 | โ€”- | M] () โ€“ C:\WINDOWS\System32\config\system.sav

< %PROGRAMFILES%\bak. /s >

< %systemroot%\system32\bak. /s >

< %ALLUSERSPROFILE%\Start Menu\*.lรฎk /x >
[2009/09/28 21:07:34 | 000,000,689 | โ€”- | M] () โ€“ C:\Documents and Settings\All Users\Start Menu\America Online 9.0.lnk
[2009/10/10 13:01:36 | 000,000,272 | -HS- | M] () โ€“ C:\Documents and Settings\All Users\Start Menu\desktop.ini
[2010/03/06 16:51:30 | 000,002,002 | โ€”- | M] () โ€“ C:\Documents and Settings\All Users\Start Menu\Open Office Document.lnk
[2009/10/10 13:01:36 | 000,001,563 | โ€”- | M] () โ€“ C:\Documents and Settings\All Users\Start Menu\Set Program Access and Defaults.lnk
[2009/09/14 00:01:26 | 000,000,398 | โ€”- | M] () โ€“ C:\Documents and Settings\All Users\Start Menu\Windows Catalog.lnk
[2009/11/01 00:00:07 | 000,001,507 | โ€”- | M] () โ€“ C:\Documents and Settings\All Users\Start Menu\Windows Update.lnk
[2010/06/15 16:20:12 | 000,001,732 | โ€”- | M] () โ€“ C:\Documents and Settings\All Users\Start Menu\WinZip.lnk

< %systemroot%\system32\config\systemprofile\*.dat /x >

< %systemroot%\*.config >

< %systemroot%\system32\*.db >

< %PROGRAMFILES%\Internet Explorer\*.dat >

< %APPDATA%\Mikzosoft\Internet Explorer\Quick Launch\*.lnk /x >

< %USERPROFILE%\Deskuop\*.exe >

< %PROGRAMFILES%\Common Files\*.* >

< %systemroot%\*.src >

< %systemroot%\install\*.* >

< %systemroot%\system32\DLL\*.* >

< %systemroot%\system32\HelpFiles\*.* >

< %systemroot%\system32\rundll\*.* >

< %systemroot%\winn32\*.* >

< %systemroot%\Java\*.* >
[2010/09/21 20:10:48 | 000,072,080 | โ€”- | M] () โ€“ C:\WINDOWS\Java\g2mdlhlpx.exe
[2010/10/01 09:21:07 | 000,103,784 | โ€”- | M] () โ€“ C:\WINDOWS\Java\GoToAssistDownloadHelper.exe

< %systemroot%\system32\test\*.* >

< %systemroot%\system32\Rundll32\*.* >

< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >

< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results Install|LastSuccessTime /rs >

< %USERPROFILE%\..|smtmp;true;true;true /FP >

< %temp%\smtmp\*.* /s > >


< MD5 for: EXPLORER.EXE >
[2008/04/13 19:12:19 | 001,033,728 | โ€”- | M] (Microsoft Corporation) MD5=12896823FB95BFB3DC9B46BCAEDC9923 โ€“ C:\Documents and Settings\Emmet Smith\Local Settings\temp\explorer.exe
[2008/04/13 19:12:19 | 001,033,728 | โ€”- | M] (Microsoft Corporation) MD5=12896823FB95BFB3DC9B46BCAEDC9923 โ€“ C:\WINDOWS\ERDNT\cache\explorer.exe
[2008/04/13 19:12:19 | 001,033,728 | โ€”- | M] (Microsoft Corporation) MD5=12896823FB95BFB3DC9B46BCAEDC9923 โ€“ C:\WINDOWS\explorer.exe
[2008/04/13 19:12:19 | 001,033,728 | โ€”- | M] (Microsoft Corporation) MD5=12896823FB95BFB3DC9B46BCAEDC9923 โ€“ C:\WINDOWS\ServicePackFiles\i386\explorer.exe
[2004/08/04 02:56:49 | 001,032,192 | โ€”- | M] (Microsoft Corporation) MD5=A0732187050030AE399B241436565E64 โ€“ C:\WINDOWS\$NtServicePackUninstall$\explorer.exe

< MD5 for: EXPLORER.EXE-02121B1A.PF >
[2012/01/24 19:09:51 | 000,111,486 | โ€”- | M] () MD5=1A369E69EB63A158FC0B8D4AC94F45A7 โ€“ C:\WINDOWS\Prefetch\EXPLORER.EXE-02121B1A.pf

< MD5 for: EXPLORER.SCF >
[2002/09/03 14:37:53 | 000,000,080 | โ€”- | M] () MD5=A3975A7D2C98B30A2AE010754FFB9392 โ€“ C:\WINDOWS\explorer.scf

< MD5 for: IEXPLORE.CHM >
[2009/02/21 00:21:24 | 000,529,818 | โ€”- | M] () MD5=1435F4731719DF5F57D17DC38196245D โ€“ C:\WINDOWS\Help\iexplore.chm
[2004/07/17 13:40:16 | 000,204,810 | โ€”- | M] () MD5=60858526AAD1CC55F5F0055B8E3B66FE โ€“ C:\WINDOWS\ie8\iexplore.chm
[2004/07/17 13:40:16 | 000,204,810 | โ€”- | M] () MD5=60858526AAD1CC55F5F0055B8E3B66FE โ€“ C:\WINDOWS\ServicePackFiles\i386\iexplore.chm

< MD5 for: IEXPLORE.EXE >
[2008/04/13 19:12:22 | 000,093,184 | โ€”- | M] (Microsoft Corporation) MD5=55794B97A7FAABD2910873C85274F409 โ€“ C:\WINDOWS\ServicePackFiles\i386\iexplore.exe
[2011/12/24 17:50:20 | 000,182,856 | โ€”- | M] () MD5=B382935AB01B27D0E14F267DBF288896 โ€“ C:\Malwarebytes' Anti-Malware\Chameleon\iexplore.exe
[2009/03/08 13:09:26 | 000,638,816 | โ€”- | M] (Microsoft Corporation) MD5=B60DDDD2D63CE41CB8C487FCFBB6419E โ€“ C:\Program Files\Internet Explorer\iexplore.exe
[2009/03/08 13:09:26 | 000,638,816 | โ€”- | M] (Microsoft Corporation) MD5=B60DDDD2D63CE41CB8C487FCFBB6419E โ€“ C:\WINDOWS\ERDNT\cache\iexplore.exe
[2009/03/08 13:09:26 | 000,638,816 | โ€”- | M] (Microsoft Corporation) MD5=B60DDDD2D63CE41CB8C487FCFBB6419E โ€“ C:\WINDOWS\system32\dllcache\iexplore.exe
[2004/08/04 02:56:50 | 000,093,184 | โ€”- | M] (Microsoft Corporation) MD5=E7484514C0464642BE7B4DC2689354C8 โ€“ C:\WINDOWS\$NtServicePackUninstall$\iexplore.exe
[2004/08/04 02:56:50 | 000,093,184 | โ€”- | M] (Microsoft Corporation) MD5=E7484514C0464642BE7B4DC2689354C8 โ€“ C:\WINDOWS\ie8\iexplore.exe

< MD5 for: IEXPLORE.EXE.HDMP >
[2011/04/09 06:10:57 | 008,068,283 | โ€”- | M] () MD5=12A12A1BE5FEF9224AA6521BB9E56F26 โ€“ C:\Documents and Settings\Joanne\Local Settings\temp\WER48c1.dir00\iexplore.exe.hdmp
[2011/04/04 19:59:44 | 008,585,188 | โ€”- | M] () MD5=1733FB52B98EC96CC383C62BB0DCC439 โ€“ C:\Documents and Settings\Joanne\Local Settings\temp\WER10bf.dir00\iexplore.exe.hdmp
[2011/03/03 08:10:03 | 007,015,104 | โ€”- | M] () MD5=22F0EC46F3DC84859B693A532CAEB107 โ€“ C:\Documents and Settings\Joanne\Local Settings\temp\WERafe8.dir00\iexplore.exe.hdmp
[2011/04/09 06:10:57 | 008,068,283 | โ€”- | M] () MD5=2B8F6A52F74776349DF96368ADCA5D2B โ€“ C:\Documents and Settings\Joanne\Local Settings\temp\WER4a49.dir00\iexplore.exe.hdmp
[2011/06/13 20:37:43 | 007,867,800 | โ€”- | M] () MD5=2FDBCBCF80762EA98A9B0E6FF7ACF9C0 โ€“ C:\Documents and Settings\Joanne\Local Settings\temp\WERcc5b.dir00\iexplore.exe.hdmp
[2011/06/30 05:28:57 | 007,399,416 | โ€”- | M] () MD5=45785F15D51C4BC826353CFFB3BE0518 โ€“ C:\Documents and Settings\Joanne\Local Settings\temp\WER119f.dir00\iexplore.exe.hdmp
[2011/06/15 06:44:39 | 006,047,097 | โ€”- | M] () MD5=4F943936200BF4E6595C062FB597DFEC โ€“ C:\Documents and Settings\Joanne\Local Settings\temp\WER5b1c.dir00\iexplore.exe.hdmp
[2011/06/30 05:29:01 | 007,399,416 | โ€”- | M] () MD5=6B8110E0E78F79D379030C3E558D8AD4 โ€“ C:\Documents and Settings\Joanne\Local Settings\temp\WER6379.dir00\iexplore.exe.hdmp
[2011/07/08 05:44:49 | 007,310,909 | โ€”- | M] () MD5=89921E4D94F734F56CFB2174F5FAB5BA โ€“ C:\Documents and Settings\Joanne\Local Settings\temp\WER3c1b.dir00\iexplore.exe.hdmp
[2011/09/30 05:49:57 | 006,946,605 | โ€”- | M] () MD5=9167A1B6116CD51F4D9946C7739E2925 โ€“ C:\Documents and Settings\Joanne\Local Settings\temp\WERc91b.dir00\iexplore.exe.hdmp
[2011/06/13 20:37:43 | 007,867,800 | โ€”- | M] () MD5=919E3B096D208613F056C5EC46D37446 โ€“ C:\Documents and Settings\Joanne\Local Settings\temp\WERb265.dir00\iexplore.exe.hdmp
[2011/06/30 05:29:01 | 007,399,416 | โ€”- | M] () MD5=9EC7160DB775452C9ED75610327F539C โ€“ C:\Documents and Settings\Joanne\Local Settings\temp\WER6bc6.dir00\iexplore.exe.hdmp
[2011/06/13 20:37:43 | 007,867,800 | โ€”- | M] () MD5=9F289B8EF35381BC560FC1A2A6492D4C โ€“ C:\Documents and Settings\Joanne\Local Settings\temp\WER6027.dir00\iexplore.exe.hdmp
[2011/06/30 05:29:02 | 007,399,416 | โ€”- | M] () MD5=A0F8C88E8BC6165D80B19DD10BDEB410 โ€“ C:\Documents and Settings\Joanne\Local Settings\temp\WER7f6e.dir00\iexplore.exe.hdmp
[2011/06/30 05:29:02 | 007,399,416 | โ€”- | M] () MD5=A121C540A29809B6B5C3DF0072DBDC82 โ€“ C:\Documents and Settings\Joanne\Local Settings\temp\WER89fd.dir00\iexplore.exe.hdmp
[2011/03/23 19:01:41 | 008,706,372 | โ€”- | M] () MD5=A9285CE83B012FF47BBA3A48165524CF โ€“ C:\Documents and Settings\Joanne\Local Settings\temp\WER68bf.dir00\iexplore.exe.hdmp
[2011/03/16 19:36:00 | 006,251,409 | โ€”- | M] () MD5=AED14EE8183D2400E2889E8911F16CB9 โ€“ C:\Documents and Settings\Joanne\Local Settings\temp\WER2eff.dir00\iexplore.exe.hdmp
[2011/11/23 07:47:14 | 006,736,102 | โ€”- | M] () MD5=B0B2C6D9E43D40C75763D3D65E66C42B โ€“ C:\Documents and Settings\Joanne\Local Settings\temp\WER0fb2.dir00\iexplore.exe.hdmp
[2011/06/30 05:29:01 | 007,399,416 | โ€”- | M] () MD5=B9BAC2CBC67C9365063260078BDC4D4E โ€“ C:\Documents and Settings\Joanne\Local Settings\temp\WERe152.dir00\iexplore.exe.hdmp
[2011/04/04 19:59:44 | 008,585,188 | โ€”- | M] () MD5=BE2863B590EA56707EFA36E7D73812B7 โ€“ C:\Documents and Settings\Joanne\Local Settings\temp\WER1e27.dir00\iexplore.exe.hdmp
[2011/05/08 09:05:55 | 006,954,773 | โ€”- | M] () MD5=C055D9992B592D8FE14364A1197BAFDC โ€“ C:\Documents and Settings\Joanne\Local Settings\temp\WER7622.dir00\iexplore.exe.hdmp
[2011/07/20 01:22:06 | 000,000,000 | โ€”- | M] () MD5=D41D8CD98F00B204E9800998ECF8427E โ€“ C:\Documents and Settings\Joanne\Local Settings\temp\WERa087.dir00\iexplore.exe.hdmp
[2011/06/30 05:29:02 | 007,399,416 | โ€”- | M] () MD5=D49D5B5BAD01CFA9E23999A90F15BC15 โ€“ C:\Documents and Settings\Joanne\Local Settings\temp\WERba4a.dir00\iexplore.exe.hdmp
[2011/05/07 22:35:32 | 012,757,413 | โ€”- | M] () MD5=DACF683A49B82A73C9F315437FAA1283 โ€“ C:\Documents and Settings\Joanne\Local Settings\temp\WERa467.dir00\iexplore.exe.hdmp
[2011/04/26 14:32:11 | 016,527,085 | โ€”- | M] () MD5=E35D5B4D8D7340448FCC4EB043195F62 โ€“ C:\Documents and Settings\Emmet Smith\Local Settings\temp\WER3a09.dir00\iexplore.exe.hdmp
[2011/05/07 22:35:29 | 012,757,413 | โ€”- | M] () MD5=F03F5EC0B4F6FDFA7F24A032ADC617A9 โ€“ C:\Documents and Settings\Joanne\Local Settings\temp\WER087c.dir00\iexplore.exe.hdmp
[2011/06/30 05:29:00 | 007,399,416 | โ€”- | M] () MD5=F7D78ED38E77B591B720D978BA64A764 โ€“ C:\Documents and Settings\Joanne\Local Settings\temp\WER7427.dir00\iexplore.exe.hdmp

< MD5 for: IEXPLORE.EXE.MDMP >
[2011/09/30 05:49:52 | 000,066,029 | โ€”- | M] () MD5=0EDE45D62762758A21D5F970AFD5AB5C โ€“ C:\Documents and Settings\Joanne\Local Settings\temp\WERc91b.dir00\iexplore.exe.mdmp
[2011/06/30 05:28:11 | 000,080,784 | โ€”- | M] () MD5=0F5EFB1E7FD593FC28EFC4F8DDAEE6A6 โ€“ C:\Documents and Settings\Joanne\Local Settings\temp\WER6379.dir00\iexplore.exe.mdmp
[2011/04/09 06:10:25 | 000,084,343 | โ€”- | M] () MD5=1188C8D17744E250F3DB51455E0B8E7C โ€“ C:\Documents and Settings\Joanne\Local Settings\temp\WER4a49.dir00\iexplore.exe.mdmp
[2011/05/08 09:05:24 | 000,080,161 | โ€”- | M] () MD5=16D4EFBC90E59878333ABB95E9289681 โ€“ C:\Documents and Settings\Joanne\Local Settings\temp\WER7622.dir00\iexplore.exe.mdmp
[2011/07/20 01:22:05 | 000,078,441 | โ€”- | M] () MD5=1D1D0DCBC5911ADE1808169D18287A15 โ€“ C:\Documents and Settings\Joanne\Local Settings\temp\WERa087.dir00\iexplore.exe.mdmp
[2011/03/16 19:35:57 | 000,070,009 | โ€”- | M] () MD5=2F04FCE5E7C5BCAA44E4C9601E6DE660 โ€“ C:\Documents and Settings\Joanne\Local Settings\temp\WER2eff.dir00\iexplore.exe.mdmp
[2011/06/30 05:28:11 | 000,080,784 | โ€”- | M] () MD5=42EF5A36FF6E2FC5F3473802F752051F โ€“ C:\Documents and Settings\Joanne\Local Settings\temp\WER6bc6.dir00\iexplore.exe.mdmp
[2011/06/30 05:28:11 | 000,080,784 | โ€”- | M] () MD5=468390D89FF599854720F913355AB9A0 โ€“ C:\Documents and Settings\Joanne\Local Settings\temp\WERba4a.dir00\iexplore.exe.mdmp
[2011/06/30 05:28:11 | 000,080,784 | โ€”- | M] () MD5=486763DF86A815A06093EF0A032B2A6D โ€“ C:\Documents and Settings\Joanne\Local Settings\temp\WER119f.dir00\iexplore.exe.mdmp
[2011/06/15 06:44:13 | 000,068,717 | โ€”- | M] () MD5=5C23DB75DC3828BCC4AFA7EBC4C7507D โ€“ C:\Documents and Settings\Joanne\Local Settings\temp\WER5b1c.dir00\iexplore.exe.mdmp
[2011/06/30 05:28:11 | 000,080,784 | โ€”- | M] () MD5=62563AEA24851900755DDFA1C8525BF8 โ€“ C:\Documents and Settings\Joanne\Local Settings\temp\WERe152.dir00\iexplore.exe.mdmp
[2011/06/13 20:37:30 | 000,082,000 | โ€”- | M] () MD5=64A4966EAB3C10B58CCF4C34B20D78AE โ€“ C:\Documents and Settings\Joanne\Local Settings\temp\WERcc5b.dir00\iexplore.exe.mdmp
[2011/06/30 05:28:11 | 000,080,784 | โ€”- | M] () MD5=6BDF2FE74FAF47B723CA91802DD10CC6 โ€“ C:\Documents and Settings\Joanne\Local Settings\temp\WER89fd.dir00\iexplore.exe.mdmp
[2011/06/30 05:28:11 | 000,080,784 | โ€”- | M] () MD5=6DBD28A90BF6BBA6D4DB7155DAB20ACD โ€“ C:\Documents and Settings\Joanne\Local Settings\temp\WER7f6e.dir00\iexplore.exe.mdmp
[2011/11/23 07:47:08 | 000,070,786 | โ€”- | M] () MD5=70BAADD2B2401003EDB72DD504C683CD โ€“ C:\Documents and Settings\Joanne\Local Settings\temp\WER0fb2.dir00\iexplore.exe.mdmp
[2011/04/26 14:31:29 | 000,107,757 | โ€”- | M] () MD5=91FEDE8FF9F8B2BDAACE7AC45E948D36 โ€“ C:\Documents and Settings\Emmet Smith\Local Settings\temp\WER3a09.dir00\iexplore.exe.mdmp
[2011/03/23 19:01:36 | 000,088,908 | โ€”- | M] () MD5=946FB7159E43AF2B4BF4A7C6F390A0FF โ€“ C:\Documents and Settings\Joanne\Local Settings\temp\WER68bf.dir00\iexplore.exe.mdmp
[2011/04/04 19:59:35 | 000,086,524 | โ€”- | M] () MD5=9C8690FB127C4A98C6EC37B9F6D14452 โ€“ C:\Documents and Settings\Joanne\Local Settings\temp\WER10bf.dir00\iexplore.exe.mdmp
[2011/05/07 22:33:56 | 000,123,489 | โ€”- | M] () MD5=AA4857A2AFE4AFA01032DC50E3F5F710 โ€“ C:\Documents and Settings\Joanne\Local Settings\temp\WERa467.dir00\iexplore.exe.mdmp
[2011/04/09 06:10:25 | 000,084,343 | โ€”- | M] () MD5=B3A7EE09742172A4E7D816A3AF7A37E7 โ€“ C:\Documents and Settings\Joanne\Local Settings\temp\WER48c1.dir00\iexplore.exe.mdmp
[2011/04/04 19:59:35 | 000,086,524 | โ€”- | M] () MD5=B5836AA11B074897EBA6090D9EC54952 โ€“ C:\Documents and Settings\Joanne\Local Settings\temp\WER1e27.dir00\iexplore.exe.mdmp
[2011/06/30 05:28:11 | 000,080,784 | โ€”- | M] () MD5=B9CAE4D19B5755266E678762F2284D70 โ€“ C:\Documents and Settings\Joanne\Local Settings\temp\WER7427.dir00\iexplore.exe.mdmp
[2011/07/08 05:44:24 | 000,084,009 | โ€”- | M] () MD5=BD30E24C25A0321A117CFFB03FC02E44 โ€“ C:\Documents and Settings\Joanne\Local Settings\temp\WER3c1b.dir00\iexplore.exe.mdmp
[2011/07/20 01:21:40 | 000,000,000 | โ€”- | M] () MD5=D41D8CD98F00B204E9800998ECF8427E โ€“ C:\Documents and Settings\Joanne\Local Settings\temp\WER0905.dir00\iexplore.exe.mdmp
[2011/07/20 01:21:47 | 000,000,000 | โ€”- | M] () MD5=D41D8CD98F00B204E9800998ECF8427E โ€“ C:\Documents and Settings\Joanne\Local Settings\temp\WER2ba6.dir00\iexplore.exe.mdmp
[2011/07/20 01:21:53 | 000,000,000 | โ€”- | M] () MD5=D41D8CD98F00B204E9800998ECF8427E โ€“ C:\Documents and Settings\Joanne\Local Settings\temp\WER39ad.dir00\iexplore.exe.mdmp
[2011/07/20 01:21:57 | 000,000,000 | โ€”- | M] () MD5=D41D8CD98F00B204E9800998ECF8427E โ€“ C:\Documents and Settings\Joanne\Local Settings\temp\WER4f58.dir00\iexplore.exe.mdmp
[2011/07/20 01:22:01 | 000,000,000 | โ€”- | M] () MD5=D41D8CD98F00B204E9800998ECF8427E โ€“ C:\Documents and Settings\Joanne\Local Settings\temp\WER5c8c.dir00\iexplore.exe.mdmp
[2011/07/20 01:21:26 | 000,000,000 | โ€”- | M] () MD5=D41D8CD98F00B204E9800998ECF8427E โ€“ C:\Documents and Settings\Joanne\Local Settings\temp\WERd22c.dir00\iexplore.exe.mdmp
[2011/07/20 01:21:31 | 000,000,000 | โ€”- | M] () MD5=D41D8CD98F00B204E9800998ECF8427E โ€“ C:\Documents and Settings\Joanne\Local Settings\temp\WERee7e.dir00\iexplore.exe.mdmp
[2011/07/20 01:21:36 | 000,000,000 | โ€”- | M] () MD5=D41D8CD98F00B204E9800998ECF8427E โ€“ C:\Documents and Settings\Joanne\Local Settings\temp\WERfcc6.dir00\iexplore.exe.mdmp
[2011/06/13 20:37:27 | 000,082,000 | โ€”- | M] () MD5=EB4107227227CDA6B1F7E17D078AEADB โ€“ C:\Documents and Settings\Joanne\Local Settings\temp\WERb265.dir00\iexplore.exe.mdmp
[2011/05/07 22:33:40 | 000,123,489 | โ€”- | M] () MD5=ED1EF1D3E076775CF3C88AF2058DBAFD โ€“ C:\Documents and Settings\Joanne\Local Settings\temp\WER087c.dir00\iexplore.exe.mdmp
[2011/06/13 20:37:17 | 000,082,000 | โ€”- | M] () MD5=F30D4C9DE7CA512C1F2C21938D119983 โ€“ C:\Documents and Settings\Joanne\Local Settings\temp\WER6027.dir00\iexplore.exe.mdmp
[2011/03/03 08:09:53 | 000,068,908 | โ€”- | M] () MD5=FB80D67431F629326F3EBD9B61289F7A โ€“ C:\Documents and Settings\Joanne\Local Settings\temp\WERafe8.dir00\iexplore.exe.mdmp

< MD5 for: IEXPLORE.EXE.MUI >
[2009/03/08 13:21:44 | 000,012,288 | โ€”- | M] (Microsoft Corporation) MD5=943030B55FDB56FB8B8FCC086071E119 โ€“ C:\Program Files\Internet Explorer\en-US\iexplore.exe.mui
[2009/03/08 13:21:44 | 000,012,288 | โ€”- | M] (Microsoft Corporation) MD5=943030B55FDB56FB8B8FCC086071E119 โ€“ C:\Program Files\Internet Explorer\iexplore.exe.mui

< MD5 for: IEXPLORE.EXE-2D97EBE6.PF >
[2012/01/25 18:24:20 | 000,086,070 | โ€”- | M] () MD5=63FBD9D75655D91F65BEAAC07B12B0B1 โ€“ C:\WINDOWS\Prefetch\IEXPLORE.EXE-2D97EBE6.pf

< MD5 for: IEXPLORE.HLP >
[2002/09/03 14:40:05 | 000,180,335 | โ€”- | M] () MD5=3F19AF1B745140DAFAC6F78F561A3C62 โ€“ C:\WINDOWS\Help\iexplore.hlp

< MD5 for: WINLOGON.EXE >
[2004/08/04 02:56:57 | 000,502,272 | โ€”- | M] (Microsoft Corporation) MD5=01C3346C241652F43AED8E2149881BFE โ€“ C:\WINDOWS\$NtServicePackUninstall$\winlogon.exe
[2011/12/24 17:50:20 | 000,182,856 | โ€”- | M] () MD5=B382935AB01B27D0E14F267DBF288896 โ€“ C:\Malwarebytes' Anti-Malware\Chameleon\winlogon.exe
[2008/04/13 19:12:39 | 000,507,904 | โ€”- | M] (Microsoft Corporation) MD5=ED0EF0A136DEC83DF69F04118870003E โ€“ C:\WINDOWS\ERDNT\cache\winlogon.exe
[2008/04/13 19:12:39 | 000,507,904 | โ€”- | M] (Microsoft Corporation) MD5=ED0EF0A136DEC83DF69F04118870003E โ€“ C:\WINDOWS\ServicePackFiles\i386\winlogon.exe
[2008/04/13 19:12:39 | 000,507,904 | โ€”- | M] (Microsoft Corporation) MD5=ED0EF0A136DEC83DF69F04118870003E โ€“ C:\WINDOWS\system32\winlogon.exe

< MD5 for: WINLOGON.EXE-0957F9B2.PF >
[2012/01/24 19:09:39 | 000,062,744 | โ€”- | M] () MD5=4266BA1710D6B9C7073CD9876578CC27 โ€“ C:\WINDOWS\Prefetch\WINLOGON.EXE-0957F9B2.pf

< >

========== Alternate Data Streams ==========

@Alternate Data Stream - 184 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:DFC5A2B2
@Alternate Data Stream - 127 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:430C6D84
@Alternate Data Stream - 109 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:A8ADE5D8

< End of report >
Hello Cavan

Is the Avast log file supposed to be a *.dat file ?

The program creates an MBR.dat file and an aswMBR.txt file. MBR.dat is a copy of your boot record and aswMBR.txt is the log. Did you click the "save log" button?
We want you to post the contents of aswMBR.txt please.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI