This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Babylon browser hijack [Solved]

22 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Good day, folks. It seems as though one of my kids installed something that included a browser hijack. I think it was the Nintendo emulator, but can't be sure. Whatever doesn't matter, as long as we can fix this. Normally I muddle through these alone, and have always came out squeaky clean (I think), but this time I'm going to leave it to the pros.

When I first ID'd there was a problem, I changed all the browser's home pages back to where they were. I thought that was the end of it, but it wasn't. Searches are still being redirected, and I'm tired of fooling with it.

So, here's my log, and thank you in advance!
jaeason


.
DDS (Ver_2011-08-26.01) - NTFSx86
Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 1.6.0_29
Run by [removed] at 23:44:36 on 2012-02-20
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.3316.1765 [GMT -6:00]
.
AV: Microsoft Security Essentials *Enabled/Updated* {EDB4FA23-53B8-4AFA-8C5D-99752CCA7095}
AV: Microsoft Security Essentials *Disabled/Updated* {BCF43643-A118-4432-AEDE-D861FCBCFCDF}
.
============== Running Processes ===============
.
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
c:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
C:\WINDOWS\system32\svchost.exe -k WudfServiceGroup
svchost.exe
svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\logishrd\LVMVFM\UMVPFSrv.exe
C:\WINDOWS\Explorer.EXE
svchost.exe
C:\Program Files\SUPERAntiSpyware\SASCORE.EXE
C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Program Files\Intel Audio Studio\IntelAudioStudio.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\system32\igfxpers.exe
C:\WINDOWS\eHome\ehSched.exe
C:\WINDOWS\zHotkey.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\StartupMonitor.exe
C:\Program Files\dcmsvc\dcmsvc.exe
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\WINDOWS\system32\libusbd-nt.exe
C:\Program Files\Microsoft Security Client\msseces.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\System32\svchost.exe -k HPZ12
C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
C:\Program Files\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\WINDOWS\System32\svchost.exe -k HPZ12
C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
C:\WINDOWS\ehome\RMSvc.exe
svchost.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
c:\Program Files\Zune\ZuneBusEnum.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\OpenDNS Updater\OpenDNSUpdater.exe
C:\Program Files\AquaSnap\AquaSnap.Daemon.exe
C:\Program Files\MyTomTom 3\MyTomTomSA.exe
C:\Documents and Settings\Owner\Application Data\Dropbox\bin\Dropbox.exe
C:\WINDOWS\system32\dllhost.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\System32\svchost.exe -k HTTPFilter
C:\WINDOWS\system32\wuauclt.exe
C:\Documents and Settings\Owner\Application Data\mjusbsp\magicJack.exe
C:\WINDOWS\system32\WISPTIS.EXE
C:\Program Files\Common Files\Java\Java Update\jucheck.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Documents and Settings\Owner\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Owner\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Owner\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Owner\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Owner\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Owner\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Owner\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Owner\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Program Files\Microsoft Office\Office12\EXCEL.EXE
C:\Documents and Settings\Owner\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Owner\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Owner\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Owner\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Owner\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Owner\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
.
============== Pseudo HJT Report ===============
.
uSearch Bar = hxxp://www.google.com/ie
uInternet Settings,ProxyOverride = *.local
uURLSearchHooks: H - No File
BHO: I Want This: {11111111-1111-1111-1111-110011221158} - c:\program files\i want this\I Want This.dll
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: Groove GFS Browser Helper: {72853161-30c5-4d22-b7f9-0bbc1d38a37e} - c:\program files\microsoft office\office12\GrooveShellExtensions.dll
BHO: Fantapper: {8a86d350-37ab-410a-8531-7d1363f317b3} - c:\program files\brand affinity technologies\fantapper player\\IEInstaller.dll
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
BHO: Yontoo Layers: {fd72061e-9fde-484d-a58a-0bab4151cad8} - c:\program files\yontoo layers runtime\YontooIEClient.dll
TB: {0B53EAC3-8D69-4B9E-9B19-A37C9A5676A7} - No File
TB: {D4027C7F-154A-4066-A1AD-4243D8127440} - No File
TB: {98279C38-DE4B-4BCF-93C9-8EC26069D6F4} - No File
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
uRun: [OpenDNS Updater] "c:\program files\opendns updater\OpenDNSUpdater.exe" /autostart
uRun: [DW6] "c:\program files\the weather channel fw\desktop\DesktopWeather.exe"
uRun: [Google Update] "c:\documents and settings\owner\local settings\application data\google\update\GoogleUpdate.exe" /c
uRun: [cdloader] "c:\documents and settings\owner\application data\mjusbsp\cdloader2.exe" MAGICJACK
uRun: [AquaSnap] c:\program files\aquasnap\AquaSnap.Daemon.exe
uRun: [Skype] "c:\program files\skype\phone\Skype.exe" /nosplash /minimized
uRun: [MyTomTomSA.exe] "c:\program files\mytomtom 3\MyTomTomSA.exe"
uRun: [SUPERAntiSpyware] c:\program files\superantispyware\SUPERAntiSpyware.exe
mRun: [Recguard] c:\windows\sminst\RECGUARD.EXE
mRun: [IntelAudioStudio] "c:\program files\intel audio studio\IntelAudioStudio.exe" TRAY
mRun: [IgfxTray] c:\windows\system32\igfxtray.exe
mRun: [HotKeysCmds] c:\windows\system32\hkcmd.exe
mRun: [Persistence] c:\windows\system32\igfxpers.exe
mRun: [CHotkey] zHotkey.exe
mRun: [ShowWnd] ShowWnd.exe
mRun: [Run StartupMonitor] StartupMonitor.exe
mRun: [dcmsvc] c:\program files\dcmsvc\dcmsvc.exe
mRun: [GrooveMonitor] "c:\program files\microsoft office\office12\GrooveMonitor.exe"
mRun: [Zune Launcher] "c:\program files\zune\ZuneLauncher.exe"
mRun: [MSC] "c:\program files\microsoft security client\msseces.exe" -hide -runkey
mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
mRun: [VirtualCloneDrive] "c:\program files\elaborate bytes\virtualclonedrive\VCDDaemon.exe" /s
mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"
mRun: [APSDaemon] "c:\program files\common files\apple\apple application support\APSDaemon.exe"
mRun: [QuickTime Task] "c:\program files\quicktime alternative\QTTask.exe" -atboottime
mRun: [LWS] c:\program files\logitech\lws\webcam software\LWS.exe -hide
StartupFolder: c:\docume~1\owner\startm~1\programs\startup\dropbox.lnk - c:\documents and settings\owner\application data\dropbox\bin\Dropbox.exe
StartupFolder: c:\docume~1\owner\startm~1\programs\startup\magicj~1.lnk - c:\documents and settings\owner\application data\mjusbsp\magicJackLoader.exe
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: E&xport to Microsoft Excel - c:\progra~1\micros~4\office12\EXCEL.EXE/3000
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\progra~1\micros~4\office12\ONBttnIE.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~4\office12\REFIEBAR.DLL
DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} - hxxp://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1273990342921
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab
DPF: {CAFEEFAC-0015-0000-0002-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_02-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0018-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_18-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
TCP: DhcpNameServer = 192.168.1.1
TCP: Interfaces\{970DBA6D-F618-4FE7-83D3-1423480D9736} : NameServer = 208.67.220.222,208.67.220.220
TCP: Interfaces\{970DBA6D-F618-4FE7-83D3-1423480D9736} : DhcpNameServer = 192.168.1.1
Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - c:\program files\microsoft office\office12\GrooveSystemServices.dll
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\common~1\skype\SKYPE4~1.DLL
Notify: !SASWinLogon - c:\program files\superantispyware\SASWINLO.DLL
Notify: igfxcui - igfxdev.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
SEH: Groove GFS Stub Execution Hook: {b5a7f190-dda6-4420-b3ba-52453494e6cd} - c:\program files\microsoft office\office12\GrooveShellExtensions.dll
SEH: SABShellExecuteHook Class: {5ae067d3-9afb-48e0-853a-ebb7f4a000da} - c:\program files\superantispyware\SASSEH.DLL
.
================= FIREFOX ===================
.
FF - ProfilePath - c:\documents and settings\owner\application data\mozilla\firefox\profiles\se87x6w3.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.babylon.com/web/{searchTerms}?babsrc=browsersearch&AF=17014
FF - prefs.js: browser.search.selectedEngine - Search the web (Babylon)
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/
FF - prefs.js: keyword.URL - hxxp://search.babylon.com/?babsrc=KW_def&AF=17014&q=
FF - plugin: c:\documents and settings\owner\application data\facebook\npfbplugin_1_0_3.dll
FF - plugin: c:\documents and settings\owner\application

data\mozilla\firefox\profiles\se87x6w3.default\extensions\{195a3098-0bd5-4e90-ae22-ba1c540afd1e}\plugins\npGarmin.dll
FF - plugin: c:\documents and settings\owner\application data\mozilla\plugins\npgoogletalk.dll
FF - plugin: c:\documents and settings\owner\application data\mozilla\plugins\npgtpo3dautoplugin.dll
FF - plugin: c:\documents and settings\owner\local settings\application data\google\update\1.3.21.99\npGoogleUpdate3.dll
FF - plugin: c:\program files\canon\zoombrowser ex\program\NPCIG.dll
FF - plugin: c:\program files\common files\oberon media\ncadapter\1.0.0.7\npapicomadapter.dll
FF - plugin: c:\program files\google\picasa3\npPicasa3.dll
FF - plugin: c:\program files\java\jre6\bin\new_plugin\npdeployJava1.dll
FF - plugin: c:\program files\microsoft silverlight\4.1.10111.0\npctrlui.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npdeployJava1.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npqtplugin8.dll
.
—- FIREFOX POLICIES —-
FF - user.js: yahoo.homepage.dontask - true);user_pref(extentions.y2layers.installId, 7f95972f-9a1a-4a3c-8f25-b37bd4bd86f2
FF - user.js: extentions.y2layers.defaultEnableAppsList - Buzzdock,BuzzdockTease,DropDownDeals,BestVideoDownloader,BestVideoDownloader,
.
============= SERVICES / DRIVERS ===============
.
R1 MpFilter;Microsoft Malware Protection Driver;c:\windows\system32\drivers\MpFilter.sys [2011-4-18 165648]
R1 MpKsl3f59ca6d;MpKsl3f59ca6d;c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition

updates\{1a0be462-27e9-4cd0-9f7d-713db44d8c74}\MpKsl3f59ca6d.sys [2012-2-20 29904]
R1 SASDIFSV;SASDIFSV;c:\program files\superantispyware\sasdifsv.sys [2011-7-22 12880]
R1 SASKUTIL;SASKUTIL;c:\program files\superantispyware\SASKUTIL.SYS [2011-7-12 67664]
R2 !SASCORE;SAS Core Service;c:\program files\superantispyware\SASCore.exe [2011-8-11 116608]
R2 libusbd;LibUsb-Win32 - Daemon, Version 0.1.10.1;system32\libusbd-nt.exe –> system32\libusbd-nt.exe [?]
R2 McrdSvc;Media Center Extender Service;c:\windows\ehome\McrdSvc.exe [2005-10-20 96256]
R2 UMVPFSrv;UMVPFSrv;c:\program files\common files\logishrd\lvmvfm\UMVPFSrv.exe [2011-8-19 450848]
R3 libusb0;LibUsb-Win32 - Kernel Driver, Version 0.1.10.1;c:\windows\system32\drivers\libusb0.sys [2012-1-14 33792]
S2 FTSvc;Fantapper Player Update Service;c:\program files\brand affinity technologies\fantapper player\FantapperUpdateService.exe [2011-12-15 11776]
S3 HTCAND32;HTC Device Driver;c:\windows\system32\drivers\androidusb.sys –> c:\windows\system32\drivers\ANDROIDUSB.sys [?]
S3 PCIUtil;PCI Utility;\??\c:\docume~1\owner\locals~1\temp\pciutil.sys –> c:\docume~1\owner\locals~1\temp\PCIUtil.sys [?]
S3 pneteth;PdaNet Broadband;c:\windows\system32\drivers\pneteth.sys [2010-10-15 13312]
S3 WMZuneComm;Zune Windows Mobile Connectivity Service;c:\program files\zune\WMZuneComm.exe [2010-11-11 268528]
.
=============== Created Last 30 ================
.
2012-02-21 05:30:34 29904 —-a-w- c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition

updates\{1a0be462-27e9-4cd0-9f7d-713db44d8c74}\MpKsl3f59ca6d.sys
2012-02-20 09:33:01 6557240 —-a-w- c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition

updates\{1a0be462-27e9-4cd0-9f7d-713db44d8c74}\mpengine.dll
2012-02-17 18:17:46 ——– d—–w- c:\documents and settings\owner\local settings\application data\I Want This
2012-02-17 18:17:41 ——– d—–w- c:\program files\I Want This
2012-02-17 18:17:38 ——– d—–w- c:\program files\Babylon
2012-02-17 18:17:24 ——– d—–w- c:\program files\Brand Affinity Technologies
2012-02-17 18:17:14 ——– d—–w- c:\program files\Yontoo Layers Runtime
2012-02-17 18:17:10 ——– d—–w- c:\documents and settings\all users\application data\Tarma Installer
2012-02-15 12:35:07 3072 -c—-w- c:\windows\system32\dllcache\iacenc.dll
2012-02-15 12:35:07 3072 ——w- c:\windows\system32\iacenc.dll
2012-01-31 14:41:36 ——– d—–w- c:\documents and settings\owner\application data\SUPERAntiSpyware.com
2012-01-31 14:41:08 ——– d—–w- c:\program files\SUPERAntiSpyware
2012-01-31 14:41:08 ——– d—–w- c:\documents and settings\all users\application data\SUPERAntiSpyware.com
.
==================== Find3M ====================
.
2012-01-31 12:44:05 237072 ——w- c:\windows\system32\MpSigStub.exe
2012-01-18 06:44:52 540960 —-a-w- c:\windows\system32\LVUI2RC.dll
2012-01-18 06:44:52 4332960 —-a-w- c:\windows\system32\drivers\lvuvc.sys
2012-01-18 06:44:40 545056 —-a-w- c:\windows\system32\LVUI2.dll
2012-01-18 06:44:28 312096 —-a-w- c:\windows\system32\drivers\lvrs.sys
2012-01-18 06:44:26 307488 —-a-w- c:\windows\system32\lvcodec2.dll
2012-01-18 06:44:26 196896 —-a-w- c:\windows\system32\lvci13311044.dll
2012-01-18 06:44:00 336408 —-a-w- c:\windows\system32\DevManagerCore.dll
2012-01-18 06:44:00 10920984 —-a-w- c:\windows\system32\LogiDPP.dll
2012-01-18 06:44:00 104472 —-a-w- c:\windows\system32\LogiDPPApp.exe
2012-01-12 16:53:24 1859968 —-a-w- c:\windows\system32\win32k.sys
2011-12-17 19:46:36 916992 —-a-w- c:\windows\system32\wininet.dll
2011-12-17 19:46:36 43520 —-a-w- c:\windows\system32\licmgr10.dll
2011-12-17 19:46:36 1469440 —-a-w- c:\windows\system32\inetcpl.cpl
2011-12-16 12:22:58 385024 —-a-w- c:\windows\system32\html.iec
2011-12-15 23:03:40 138056 —-a-w- c:\windows\system32\atl100.dll
2011-12-02 15:03:26 414368 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2011-11-25 21:57:19 293376 —-a-w- c:\windows\system32\winsrv.dll
2011-06-07 13:28:17 443 —-a-w- c:\program files\060720118281746.bat
2006-05-02 23:00:00 163328 –sha-r- c:\windows\system32\flvDX.dll
2007-02-20 23:00:00 31232 –sha-r- c:\windows\system32\msfDX.dll
2008-03-15 23:00:00 216064 –sha-r- c:\windows\system32\nbDX.dll
.
============= FINISH: 23:44:54.81 ===============
Hello jaeason and :welcome:

My name is JonTom

  • Malware Logs can sometimes take a lot of time to research and interpret.
  • Please be patient while I try to assist with your problem. If at any time you do not understand what is required, please ask for further explanation.
  • Please note that there is no "Quick Fix" to modern malware infections and we may need to use several different approaches to get your system clean.
  • Read every reply you receive carefully and thoroughly before carrying out the instructions. You may also find it helpful to print out the instructions you receive, as in some instances you may have to disconnect your computer from the Internet.
  • PLEASE NOTE: If you do not reply after 3 days your thread will be closed.

Lets begin withthe following:

  • Download and run OTL by Oldtimer


    • Please download OTL by Oldtimer by clicking here and save the file (called OTL.exe) to your desktop.
    • Close all open windows on your computer then Double click on the OTL.exe icon to run the program.
    • Check the boxes beside "LOP Check" and "Purity Check".
    • Under Custom Scan paste this in:

    netsvcs
    %SYSTEMDRIVE%\*.exe
    /md5start
    eventlog.dll
    scecli.dll
    netlogon.dll
    cngaudit.dll
    sceclt.dll
    ntelogon.dll
    logevent.dll
    iaStor.sys
    nvstor.sys
    atapi.sys
    IdeChnDr.sys
    viasraid.sys
    AGP440.sys
    vaxscsi.sys
    nvatabus.sys
    viamraid.sys
    nvata.sys
    nvgts.sys
    iastorv.sys
    ViPrt.sys
    eNetHook.dll
    ahcix86.sys
    KR10N.sys
    nvstor32.sys
    ahcix86s.sys
    nvrd32.sys
    symmpi.sys
    adp3132.sys
    /md5stop
    %systemroot%\*. /mp /s
    %systemroot%\system32\*.dll /lockedfiles
    %systemroot%\Tasks\*.job /lockedfiles
    %systemroot%\system32\drivers\*.sys /lockedfiles
    %systemroot%\System32\config\*.sav
    %systemroot%\system32\drivers\*.sys /90
    CREATERESTOREPOINT


    • Click the "Run Scan" button. Do not change any settings unless specifically told to do so. The scan will not take long.

    • When the scan completes, it will open two notepad windows: OTL.Txt and Extras.Txt.
    • Note: These logs can be located in the OTL. folder on you C:\ drive if they fail to open automatically.
    • Please Copy and Paste the contents of both files in your next reply. You may need two posts to fit them both in.

  • aswMBR


    • Download aswMBR.exe to your desktop.
    • Double click the aswMBR.exe to run it.
    • When asked if you want to download Avast's virus definitions please select Yes.
    • Click the "Scan" button to start scan.

    [external image: Posted Image]

    • On completion of the scan click save log, save it to your desktop and post in your next reply.

    [external image: Posted Image]

    Please post both OTL logs and the aswMBR log in your next reply.
as requested OTL.txt

OTL logfile created on: 2/21/2012 8:33:15 AM - Run 1
OTL by OldTimer - Version 3.2.33.1 Folder = C:\Documents and Settings\Owner\Desktop\OLT
Windows XP Media Center Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

3.24 Gb Total Physical Memory | 2.22 Gb Available Physical Memory | 68.64% Memory free
5.08 Gb Paging File | 4.07 Gb Available in Paging File | 80.23% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 228.71 Gb Total Space | 73.52 Gb Free Space | 32.15% Space Free | Partition Type: NTFS
Drive D: | 4.16 Gb Total Space | 0.96 Gb Free Space | 23.18% Space Free | Partition Type: FAT32
Drive E: | 129.43 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS

Computer Name: BLACKGATE | User Name: Owner | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - [2012/02/21 08:00:55 | 000,583,168 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Owner\Desktop\OLT\OTL.exe
PRC - [2012/02/19 14:07:12 | 004,617,600 | —- | M] (SUPERAntiSpyware.com) – C:\Program Files\SUPERAntiSpyware\SUPERANTISPYWARE.EXE
PRC - [2012/02/14 23:03:37 | 001,049,072 | —- | M] (Google Inc.) – C:\Documents and Settings\Owner\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
PRC - [2012/01/18 12:54:06 | 024,246,216 | —- | M] (Dropbox, Inc.) – C:\Documents and Settings\Owner\Application Data\Dropbox\bin\Dropbox.exe
PRC - [2011/11/14 05:02:04 | 000,435,672 | —- | M] (TomTom) – C:\Program Files\MyTomTom 3\MyTomTomSA.exe
PRC - [2011/08/23 14:03:08 | 022,140,304 | —- | M] (magicJack L.P.) – C:\Documents and Settings\Owner\Application Data\mjusbsp\magicJack.exe
PRC - [2011/08/19 03:26:50 | 000,450,848 | —- | M] (Logitech Inc.) – C:\Program Files\Common Files\LogiShrd\LVMVFM\UMVPFSrv.exe
PRC - [2011/08/11 17:38:07 | 000,116,608 | —- | M] (SUPERAntiSpyware.com) – C:\Program Files\SUPERAntiSpyware\SASCore.exe
PRC - [2011/06/15 14:16:48 | 000,997,920 | —- | M] (Microsoft Corporation) – C:\Program Files\Microsoft Security Client\msseces.exe
PRC - [2011/06/09 12:06:06 | 000,507,624 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files\Common Files\Java\Java Update\jucheck.exe
PRC - [2011/04/27 14:39:26 | 000,011,736 | —- | M] (Microsoft Corporation) – c:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe
PRC - [2011/01/21 21:54:18 | 000,875,008 | —- | M] (http://www.nurgo-software.com) – C:\Program Files\AquaSnap\AquaSnap.Daemon.exe
PRC - [2010/11/11 13:55:56 | 000,057,072 | —- | M] (Microsoft Corporation) – c:\Program Files\Zune\ZuneBusEnum.exe
PRC - [2010/06/16 15:42:58 | 000,839,680 | —- | M] () – C:\Program Files\OpenDNS Updater\OpenDNSUpdater.exe
PRC - [2010/05/15 23:54:01 | 000,172,032 | —- | M] (New Boundary Technologies, Inc.) – C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
PRC - [2009/04/07 13:53:32 | 000,030,440 | —- | M] () – C:\Program Files\dcmsvc\dcmsvc.exe
PRC - [2008/04/13 18:12:19 | 001,033,728 | —- | M] (Microsoft Corporation) – C:\WINDOWS\explorer.exe
PRC - [2005/05/10 17:02:52 | 007,086,080 | —- | M] (Intel Corporation) – C:\Program Files\Intel Audio Studio\IntelAudioStudio.exe
PRC - [2005/03/09 20:50:18 | 000,018,944 | —- | M] (http://libusb-win32.sourceforge.net) – C:\WINDOWS\system32\libusbd-nt.exe
PRC - [2004/05/17 19:30:04 | 000,543,232 | —- | M] () – C:\WINDOWS\zHotkey.exe
PRC - [2000/05/20 16:23:48 | 000,086,016 | —- | M] () – C:\WINDOWS\StartupMonitor.exe


========== Modules (No Company Name) ==========

MOD - [2012/02/19 14:07:19 | 000,063,488 | —- | M] () – C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\SD10006.dll
MOD - [2012/02/19 14:07:19 | 000,052,736 | —- | M] () – C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\SD10007.dll
MOD - [2012/02/14 23:03:36 | 000,429,040 | —- | M] () – C:\Documents and Settings\Owner\Local Settings\Application Data\Google\Chrome\Application\17.0.963.56\ppgooglenaclpluginchrome.dll
MOD - [2012/02/14 23:03:34 | 003,772,912 | —- | M] () – C:\Documents and Settings\Owner\Local Settings\Application Data\Google\Chrome\Application\17.0.963.56\pdf.dll
MOD - [2012/02/14 23:02:10 | 000,122,880 | —- | M] () – C:\Documents and Settings\Owner\Local Settings\Application Data\Google\Chrome\Application\17.0.963.56\avutil-51.dll
MOD - [2012/02/14 23:02:08 | 000,220,672 | —- | M] () – C:\Documents and Settings\Owner\Local Settings\Application Data\Google\Chrome\Application\17.0.963.56\avformat-53.dll
MOD - [2012/02/14 23:02:07 | 001,747,456 | —- | M] () – C:\Documents and Settings\Owner\Local Settings\Application Data\Google\Chrome\Application\17.0.963.56\avcodec-53.dll
MOD - [2012/02/14 20:00:24 | 008,593,568 | —- | M] () – C:\Documents and Settings\Owner\Local Settings\Application Data\Google\Chrome\Application\17.0.963.56\gcswf32.dll
MOD - [2012/01/31 08:41:50 | 000,117,760 | —- | M] () – C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\UIREPAIR.DLL
MOD - [2012/01/31 08:41:50 | 000,052,224 | —- | M] () – C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\SD10005.dll
MOD - [2011/11/14 05:02:08 | 000,202,712 | —- | M] () – C:\Program Files\MyTomTom 3\TomTomSupporterProxy.dll
MOD - [2011/11/14 05:02:06 | 000,063,960 | —- | M] () – C:\Program Files\MyTomTom 3\TomTomSupporterBase.dll
MOD - [2011/11/14 05:01:52 | 007,964,160 | —- | M] () – C:\Program Files\MyTomTom 3\QtGui4.dll
MOD - [2011/11/14 05:01:52 | 002,302,464 | —- | M] () – C:\Program Files\MyTomTom 3\QtCore4.dll
MOD - [2011/11/14 05:01:52 | 000,980,480 | —- | M] () – C:\Program Files\MyTomTom 3\QtNetwork4.dll
MOD - [2011/11/14 05:01:52 | 000,357,888 | —- | M] () – C:\Program Files\MyTomTom 3\QtXml4.dll
MOD - [2011/11/03 09:28:36 | 001,292,288 | —- | M] () – C:\WINDOWS\system32\quartz.dll
MOD - [2011/09/27 07:23:00 | 000,087,912 | —- | M] () – C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll
MOD - [2011/09/27 07:22:40 | 001,242,472 | —- | M] () – C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll
MOD - [2011/08/23 14:08:48 | 000,083,352 | —- | M] () – C:\Documents and Settings\Owner\Application Data\mjusbsp\octvqem_apiw.dll
MOD - [2011/02/04 17:48:30 | 000,291,840 | —- | M] () – C:\WINDOWS\system32\sbe.dll
MOD - [2011/01/21 21:54:24 | 000,256,512 | —- | M] () – C:\Program Files\AquaSnap\AquaSnap.Hook.dll
MOD - [2010/11/21 08:54:34 | 000,094,208 | —- | M] () – C:\Program Files\FileZilla FTP Client\fzshellext.dll
MOD - [2010/06/16 15:42:58 | 000,839,680 | —- | M] () – C:\Program Files\OpenDNS Updater\OpenDNSUpdater.exe
MOD - [2010/03/15 10:28:22 | 000,141,824 | —- | M] () – C:\Program Files\WinRAR\RarExt.dll
MOD - [2009/11/05 07:39:40 | 000,087,552 | —- | M] () – C:\WINDOWS\system32\cpwmon2k.dll
MOD - [2009/04/07 13:53:32 | 000,030,440 | —- | M] () – C:\Program Files\dcmsvc\dcmsvc.exe
MOD - [2008/04/13 18:11:59 | 000,014,336 | —- | M] () – C:\WINDOWS\system32\msdmo.dll
MOD - [2008/04/13 18:11:51 | 000,059,904 | —- | M] () – C:\WINDOWS\system32\devenum.dll
MOD - [2004/05/17 19:30:04 | 000,543,232 | —- | M] () – C:\WINDOWS\zHotkey.exe
MOD - [2001/07/02 21:36:30 | 000,024,576 | —- | M] () – C:\WINDOWS\HKNTDLL.dll
MOD - [2000/05/20 16:23:48 | 000,086,016 | —- | M] () – C:\WINDOWS\StartupMonitor.exe


========== Win32 Services (SafeList) ==========

SRV - [2011/12/15 17:03:40 | 000,011,776 | —- | M] (Brand Affinity Technologies) [Auto | Stopped] – C:\Program Files\Brand Affinity Technologies\Fantapper Player\FantapperUpdateService.exe – (FTSvc)
SRV - [2011/08/19 03:26:50 | 000,450,848 | —- | M] (Logitech Inc.) [Auto | Running] – C:\Program Files\Common Files\LogiShrd\LVMVFM\UMVPFSrv.exe – (UMVPFSrv)
SRV - [2011/08/11 17:38:07 | 000,116,608 | —- | M] (SUPERAntiSpyware.com) [Auto | Running] – C:\Program Files\SUPERAntiSpyware\SASCORE.EXE – (!SASCORE)
SRV - [2011/04/27 14:39:26 | 000,011,736 | —- | M] (Microsoft Corporation) [Auto | Running] – c:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe – (MsMpSvc)
SRV - [2010/11/11 13:57:04 | 000,268,528 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – c:\Program Files\Zune\WMZuneComm.exe – (WMZuneComm)
SRV - [2010/11/11 13:57:02 | 000,444,656 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – c:\Program Files\Zune\ZuneWlanCfgSvc.exe – (ZuneWlanCfgSvc)
SRV - [2010/11/11 13:55:56 | 006,351,600 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – c:\Program Files\Zune\ZuneNss.exe – (ZuneNetworkSvc)
SRV - [2010/11/11 13:55:56 | 000,057,072 | —- | M] (Microsoft Corporation) [Auto | Running] – c:\Program Files\Zune\ZuneBusEnum.exe – (ZuneBusEnum)
SRV - [2010/05/15 23:54:01 | 000,172,032 | —- | M] (New Boundary Technologies, Inc.) [Auto | Running] – C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS – (PrismXL)
SRV - [2005/03/09 20:50:18 | 000,018,944 | —- | M] (http://libusb-win32.sourceforge.net) [Auto | Running] – C:\WINDOWS\system32\libusbd-nt.exe – (libusbd)


========== Driver Services (SafeList) ==========

DRV - [2012/01/18 00:44:52 | 004,332,960 | —- | M] (Logitech Inc.) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\lvuvc.sys – (LVUVC) Logitech HD Webcam C270(UVC)
DRV - [2012/01/18 00:44:28 | 000,312,096 | —- | M] (Logitech Inc.) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\lvrs.sys – (LVRS)
DRV - [2011/07/22 10:27:02 | 000,012,880 | —- | M] (SUPERAdBlocker.com and SUPERAntiSpyware.com) [Kernel | System | Running] – C:\Program Files\SUPERAntiSpyware\sasdifsv.sys – (SASDIFSV)
DRV - [2011/07/12 15:55:22 | 000,067,664 | —- | M] (SUPERAdBlocker.com and SUPERAntiSpyware.com) [Kernel | System | Running] – C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS – (SASKUTIL)
DRV - [2011/03/18 10:08:54 | 000,025,240 | —- | M] (Almico Software) [Kernel | Boot | Running] – C:\WINDOWS\system32\speedfan.sys – (speedfan)
DRV - [2010/09/02 16:49:06 | 000,013,312 | —- | M] (June Fabrics Technology Inc.) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\pneteth.sys – (pneteth)
DRV - [2008/03/12 02:00:00 | 000,009,200 | —- | M] (Sonic Solutions) [Kernel | System | Stopped] – C:\WINDOWS\System32\drivers\cdralw2k.sys – (Cdralw2k)
DRV - [2008/03/12 02:00:00 | 000,009,072 | —- | M] (Sonic Solutions) [Kernel | System | Stopped] – C:\WINDOWS\System32\drivers\cdr4_xp.sys – (Cdr4_xp)
DRV - [2006/11/02 06:00:08 | 000,039,368 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\winusb.sys – (WinUSB)
DRV - [2005/04/27 11:45:08 | 000,300,672 | —- | M] (SigmaTel, Inc.) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\sthda.sys – (STHDA) High Definition Audio Driver (WDM)
DRV - [2005/04/05 17:38:32 | 000,132,352 | —- | M] (Broadcom Corporation) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\b57xp32.sys – (b57w2k)
DRV - [2005/04/04 09:01:34 | 000,035,712 | —- | M] (Sonic Focus, Inc) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\sfng32.sys – (sfng32)
DRV - [2005/03/09 20:50:16 | 000,033,792 | —- | M] () [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\libusb0.sys – (libusb0)
DRV - [2004/06/17 16:56:22 | 000,220,032 | —- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\HSFHWBS2.sys – (HSFHWBS2)
DRV - [2004/06/17 16:55:38 | 000,685,056 | —- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\HSF_CNXT.sys – (winachsf)
DRV - [2004/06/17 16:55:04 | 001,041,536 | —- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\HSF_DP.sys – (HSF_DP)
DRV - [2001/08/17 14:49:32 | 000,019,968 | —- | M] (Macronix International Co., Ltd. ) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\mxnic.sys – (mxnic)
DRV - [1996/04/03 13:33:26 | 000,005,248 | —- | M] () [Kernel | Boot | Running] – C:\WINDOWS\system32\giveio.sys – (giveio)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========


IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = http://www.google.com/ie
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://www.msn.com/?ocid=iehp
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-us
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0C 30 D7 FC EC ED CC 01 [binary data]
IE - HKCU\..\URLSearchHook: - No CLSID value found
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local

========== FireFox ==========


FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\WINDOWS\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@canon.com/MycameraPlugin: C:\Program Files\Canon\ZoomBrowser EX\Program\NPCIG.dll (CANON INC.)
FF - HKLM\Software\MozillaPlugins\@google.com/npPicasa3,version=3.0.0: C:\Program Files\Google\Picasa3\npPicasa3.dll (Google, Inc.)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\4.1.10111.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@oberon-media.com/ONCAdapter: C:\Program Files\Common Files\Oberon Media\NCAdapter\1.0.0.7\npapicomadapter.dll (Oberon-Media )
FF - HKCU\Software\MozillaPlugins\@facebook.com/FBPlugin,version=1.0.3: C:\Documents and Settings\Owner\Application Data\Facebook\npfbplugin_1_0_3.dll ( )
FF - HKCU\Software\MozillaPlugins\@talk.google.com/GoogleTalkPlugin: C:\Documents and Settings\Owner\Application Data\Mozilla\plugins\npgoogletalk.dll (Google)
FF - HKCU\Software\MozillaPlugins\@talk.google.com/O3DPlugin: C:\Documents and Settings\Owner\Application Data\Mozilla\plugins\npgtpo3dautoplugin.dll ()
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Documents and Settings\Owner\Local Settings\Application Data\Google\Update\1.3.21.99\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Documents and Settings\Owner\Local Settings\Application Data\Google\Update\1.3.21.99\npGoogleUpdate3.dll (Google Inc.)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 10.0.2\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2012/02/18 12:25:14 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 10.0.2\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2012/02/07 10:54:27 | 000,000,000 | —D | M]

[2010/05/26 05:30:51 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Owner\Application Data\Mozilla\Extensions
[2010/05/26 05:30:51 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Owner\Application Data\Mozilla\Extensions\[removed]
[2012/02/17 18:09:27 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\se87x6w3.default\extensions
[2012/01/31 18:46:22 | 000,000,000 | —D | M] (FireShot) – C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\se87x6w3.default\extensions\{0b457cAA-602d-484a-8fe7-c1d894a011ba}
[2011/08/25 22:02:10 | 000,000,000 | —D | M] (Garmin Communicator) – C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\se87x6w3.default\extensions\{195A3098-0BD5-4e90-AE22-BA1C540AFD1E}
[2012/02/17 12:17:46 | 000,000,000 | —D | M] ("I Want This") – C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\se87x6w3.default\extensions\[removed]
[2010/05/25 16:25:13 | 000,000,000 | —D | M] (Drag & Drop.io) – C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\se87x6w3.default\extensions\dropio@dropio
[2012/02/17 18:09:27 | 000,000,000 | —D | M] (Babylon) – C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\se87x6w3.default\extensions\[removed]
[2011/12/21 07:36:35 | 000,000,000 | —D | M] (Awesome screenshot: Capture and Annotate) – C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\se87x6w3.default\extensions\jid0-GXjLLfbCoAx0LcltEdFrEkQdQPI@jetpack
[2012/02/17 12:17:15 | 000,000,000 | —D | M] (Yontoo Layers) – C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\se87x6w3.default\extensions\[removed]
[2012/02/17 12:22:28 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions
[2012/02/18 12:25:14 | 000,134,104 | —- | M] (Mozilla Foundation) – C:\Program Files\mozilla firefox\components\browsercomps.dll
[2011/10/03 04:06:04 | 000,476,904 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files\mozilla firefox\plugins\npdeployJava1.dll
[2012/02/17 12:17:12 | 000,002,226 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\babylon.xml
[2012/02/13 19:04:43 | 000,002,252 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\bing.xml
[2012/02/13 19:04:43 | 000,002,040 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\twitter.xml

========== Chrome ==========

CHR - default_search_provider: Search the web (Babylon) (Enabled)
CHR - default_search_provider: search_url = http://search.babylon.com/?q={searchTerms}…ef⁡=17014
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}client
=chrome&hl;={language}&q;={searchTerms}
CHR - plugin: Shockwave Flash (Disabled) = C:\Documents and Settings\Owner\Local Settings\Application Data\Google\Chrome\User Data\PepperFlash\11.1.31.203\pepflashplayer.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Documents and Settings\Owner\Local Settings\Application Data\Google\Chrome\Application\17.0.963.56\gcswf32.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll
CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Documents and Settings\Owner\Local Settings\Application Data\Google\Chrome\Application\17.0.963.56\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Documents and Settings\Owner\Local Settings\Application Data\Google\Chrome\Application\17.0.963.56\pdf.dll
CHR - plugin: Screen Capture Plugin (Enabled) = C:\Documents and Settings\Owner\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\alelhddbbhepgpmgidjdcjakblofbmce\3.2.6_0\plugins/screen_capture.dll
CHR - plugin: Google Talk Plugin (Enabled) = C:\Documents and Settings\Owner\Application Data\Mozilla\plugins\npgoogletalk.dll
CHR - plugin: Google Talk Plugin Video Accelerator (Enabled) = C:\Documents and Settings\Owner\Application Data\Mozilla\plugins\npgtpo3dautoplugin.dll
CHR - plugin: Adobe Acrobat (Disabled) = C:\Program Files\Adobe\Reader 9.0\Reader\Browser\nppdf32.dll
CHR - plugin: Java Deployment Toolkit 6.0.290.11 (Enabled) = C:\Program Files\Java\jre6\bin\new_plugin\npdeployJava1.dll
CHR - plugin: Java™ Platform SE 6 U29 (Enabled) = C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll
CHR - plugin: Microsoft\u00AE Windows Media Player Firefox Plugin (Enabled) = C:\Program Files\Mozilla Firefox\plugins\np-mswmp.dll
CHR - plugin: 2007 Microsoft Office system (Enabled) = C:\Program Files\Mozilla Firefox\plugins\NPOFF12.DLL
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin2.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin3.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin4.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin5.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin6.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin7.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin8.dll
CHR - plugin: Facebook Plugin (Enabled) = C:\Documents and Settings\Owner\Application Data\Facebook\npfbplugin_1_0_3.dll
CHR - plugin: Google Update (Enabled) = C:\Documents and Settings\Owner\Local Settings\Application Data\Google\Update\1.3.21.99\npGoogleUpdate3.dll
CHR - plugin: NPCIG.dll (Enabled) = C:\Program Files\Canon\ZoomBrowser EX\Program\NPCIG.dll
CHR - plugin: Oberon com adapter (Enabled) = C:\Program Files\Common Files\Oberon Media\NCAdapter\1.0.0.7\npapicomadapter.dll
CHR - plugin: Picasa (Enabled) = C:\Program Files\Google\Picasa3\npPicasa3.dll
CHR - plugin: iTunes Application Detector (Enabled) = C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll
CHR - plugin: Shockwave for Director (Enabled) = C:\WINDOWS\system32\Adobe\Director\np32dsw.dll
CHR - plugin: Silverlight Plug-In (Enabled) = c:\Program Files\Microsoft Silverlight\4.1.10111.0\npctrl.dll
CHR - plugin: Windows Presentation Foundation (Enabled) = c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll
CHR - plugin: Default Plug-in (Enabled) = default_plugin
CHR - Extension: Entanglement = C:\Documents and Settings\Owner\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\aciahcmjmecflokailenpkdchphgkefd\2.7.9_0\
CHR - Extension: Angry Birds = C:\Documents and Settings\Owner\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\aknpkdffaafgjchaibgeefbgmgeghloj\1.1.2.1_0\
CHR - Extension: Awesome Screenshot: Capture & Annotate = C:\Documents and Settings\Owner\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\alelhddbbhepgpmgidjdcjakblofbmce\3.2.6_0\
CHR - Extension: Awesome Screenshot: Capture & Annotate = C:\Documents and Settings\Owner\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\alelhddbbhepgpmgidjdcjakblofbmce\3.2.7_0\
CHR - Extension: Google Docs = C:\Documents and Settings\Owner\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\5.3_0\
CHR - Extension: BeFunky Photo Editor = C:\Documents and Settings\Owner\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\apfkepiiddolifkgjmfdgpnipgnfejab\1.1_0\
CHR - Extension: Audiotool = C:\Documents and Settings\Owner\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\bkgoccjhfjgjedhkiefaclppgbmoobnk\1.1_0\
CHR - Extension: Weebly - Website Builder = C:\Documents and Settings\Owner\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\cnocophcbjfiimmnhlhleaooedeheifb\1.0.4_0\
CHR - Extension: Aviary Markup Editor = C:\Documents and Settings\Owner\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\fjinggjjjcdolmgegjcdimhnmjffgfik\0.0.0.7_0\
CHR - Extension: Stupeflix Video Maker = C:\Documents and Settings\Owner\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\fkdmcfnoimoilncpjchamnenebopocem\1.5_0\
CHR - Extension: Springpad = C:\Documents and Settings\Owner\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\fkmopoamfjnmppabeaphohombnjcjgla\4_0\
CHR - Extension: PicSkinny = C:\Documents and Settings\Owner\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\fmgodhpfkdhipidhjdiaokhbgofopkjb\1.3_0\
CHR - Extension: AdBlock = C:\Documents and Settings\Owner\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.5.16_0\
CHR - Extension: AdBlock = C:\Documents and Settings\Owner\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.5.19_0\
CHR - Extension: Weather Window by WeatherBug = C:\Documents and Settings\Owner\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\ihdkejbciahopmbagpnjmmkkdpfpaaak\1.0.12_0\
CHR - Extension: Skyrim Map Theme = C:\Documents and Settings\Owner\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\ipgcbcdkenhoakpbdginjipkbfddjnkn\1.0_0\
CHR - Extension: Unit Converter = C:\Documents and Settings\Owner\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\joeaphagfhgdocpnjfaagffkimgcenho\1.1_0\
CHR - Extension: The Secret of Grisly Manor = C:\Documents and Settings\Owner\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\kpaadcbfeeiehmjlfbgpafdjbeikhgff\1.0_0\
CHR - Extension: Evernote Web = C:\Documents and Settings\Owner\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\lbfehkoinhhcknnbdgnnmjhiladcgbol\1.0.7_0\
CHR - Extension: Sketchpad = C:\Documents and Settings\Owner\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\lkllajgbhondgjjnhmmgbjndmogapinp\1.0.0.1_0\
CHR - Extension: Poppit = C:\Documents and Settings\Owner\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\mcbkbpnkkkipelfledbfocopglifcfmi\2.2_0\
CHR - Extension: Earbits Radio = C:\Documents and Settings\Owner\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\mgkjffcdjblaipglnmhanakilfbniihj\1.0.2_0\
CHR - Extension: Earbits Radio = C:\Documents and Settings\Owner\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\mgkjffcdjblaipglnmhanakilfbniihj\1.1.8_0\
CHR - Extension: Berzerk Ball = C:\Documents and Settings\Owner\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\mlhdccfnfabmabdlpmlgmnegfekcpgpb\0.0.0.3_0\
CHR - Extension: I Want This = C:\Documents and Settings\Owner\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\mpfapcdfbbledbojijcbcclmlieaoogk\1.14.20_0\
CHR - Extension: deviantART muro = C:\Documents and Settings\Owner\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\namljbfbglehfnlonjmebceimaalofei\1.0_0\
CHR - Extension: Yontoo = C:\Documents and Settings\Owner\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\niapdbllcanepiiimjjndipklodoedlc\1.0.1_0\
CHR - Extension: Yontoo = C:\Documents and Settings\Owner\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\niapdbllcanepiiimjjndipklodoedlc\1.0.2_0\
CHR - Extension: Amazon Windowshop = C:\Documents and Settings\Owner\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\nielaigelomefgdoljcpfgbdbfefhdjc\1.1.0.0_0\
CHR - Extension: Fantapper = C:\Documents and Settings\Owner\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\ohgcjecomkebbohfjgmncelbhogbbokf\1.0.6_0\
CHR - Extension: Picasa = C:\Documents and Settings\Owner\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\onlgmecjpnejhfeofkgbfgnmdlipdejb\6.2.2_0\
CHR - Extension: Atari - Missile Command = C:\Documents and Settings\Owner\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\oobnopfjjndfekinfcddimnjbhjdgmbg\1.0_0\
CHR - Extension: Psykopaint = C:\Documents and Settings\Owner\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\pgjchkcfmigkkhedgjedmffdepgmpfil\0.0.0.4_0\
CHR - Extension: Gmail = C:\Documents and Settings\Owner\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\

O1 HOSTS File: ([2004/08/10 13:00:00 | 000,000,734 | —- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (I Want This) - {11111111-1111-1111-1111-110011221158} - C:\Program Files\I Want This\I Want This.dll (215 Apps)
O2 - BHO: (Fantapper) - {8A86D350-37AB-410A-8531-7D1363F317B3} - C:\Program Files\Brand Affinity Technologies\Fantapper Player\\IEInstaller.dll ()
O2 - BHO: (Yontoo Layers) - {FD72061E-9FDE-484D-A58A-0BAB4151CAD8} - C:\Program Files\Yontoo Layers Runtime\YontooIEClient.dll (Yontoo LLC)
O3 - HKCU\..\Toolbar\ShellBrowser: (no name) - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {0B53EAC3-8D69-4B9E-9B19-A37C9A5676A7} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {98279C38-DE4B-4BCF-93C9-8EC26069D6F4} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {D4027C7F-154A-4066-A1AD-4243D8127440} - No CLSID value found.
O4 - HKLM..\Run: [APSDaemon] C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [CHotkey] C:\WINDOWS\zHotkey.exe ()
O4 - HKLM..\Run: [dcmsvc] C:\Program Files\dcmsvc\dcmsvc.exe ()
O4 - HKLM..\Run: [IntelAudioStudio] C:\Program Files\Intel Audio Studio\IntelAudioStudio.exe (Intel Corporation)
O4 - HKLM..\Run: [LWS] C:\Program Files\Logitech\LWS\Webcam Software\LWS.exe (Logitech Inc.)
O4 - HKLM..\Run: [MSC] c:\Program Files\Microsoft Security Client\msseces.exe (Microsoft Corporation)
O4 - HKLM..\Run: [QuickTime Task] C:\Program Files\QuickTime Alternative\QTTask.exe (Apple Inc.)
O4 - HKLM..\Run: [Recguard] C:\WINDOWS\SMINST\Recguard.exe ()
O4 - HKLM..\Run: [Run StartupMonitor] C:\WINDOWS\StartupMonitor.exe ()
O4 - HKLM..\Run: [ShowWnd] C:\WINDOWS\ShowWnd.exe ()
O4 - HKLM..\Run: [Zune Launcher] c:\Program Files\Zune\ZuneLauncher.exe (Microsoft Corporation)
O4 - HKCU..\Run: [AquaSnap] C:\Program Files\AquaSnap\AquaSnap.Daemon.exe (http://www.nurgo-software.com)
O4 - HKCU..\Run: [DW6] "C:\Program Files\The Weather Channel FW\Desktop\DesktopWeather.exe" File not found
O4 - HKCU..\Run: [MyTomTomSA.exe] C:\Program Files\MyTomTom 3\MyTomTomSA.exe (TomTom)
O4 - HKCU..\Run: [OpenDNS Updater] C:\Program Files\OpenDNS Updater\OpenDNSUpdater.exe ()
O4 - HKCU..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERANTISPYWARE.EXE (SUPERAntiSpyware.com)
O4 - Startup: C:\Documents and Settings\Owner\Start Menu\Programs\Startup\Dropbox.lnk = C:\Documents and Settings\Owner\Application Data\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
O4 - Startup: C:\Documents and Settings\Owner\Start Menu\Programs\Startup\magicJack.lnk = C:\Documents and Settings\Owner\Application Data\mjusbsp\magicJackLoader.exe (magicJack L.P.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: InstallVisualStyle = C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles (Microsoft)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: InstallTheme = C:\WINDOWS\Resources\Themes\Royale.theme ()
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O8 - Extra context menu item: Add to Google Photos Screensa&ver; - C:\WINDOWS\System32\GPhotos.scr (Google Inc.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O15 - HKCU\..Trusted Domains: //@surf.mar@/ ([]money in Local intranet)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} http://www.update.microsoft.com/microsoftu…b?1273990342921 (MUWebControl Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_29)
O16 - DPF: {CAFEEFAC-0015-0000-0002-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0018-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_29)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_29)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab (Shockwave Flash Object)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{970DBA6D-F618-4FE7-83D3-1423480D9736}: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{970DBA6D-F618-4FE7-83D3-1423480D9736}: NameServer = 208.67.220.222,208.67.220.220
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) - C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O20 - Winlogon\Notify\!SASWinLogon: DllName - (C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL) - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL (SUPERAntiSpyware.com)
O24 - Desktop WallPaper: C:\Documents and Settings\Owner\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Owner\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O28 - HKLM ShellExecuteHooks: {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - C:\Program Files\SUPERAntiSpyware\SASSEH.DLL (SuperAdBlocker.com)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2005/04/13 11:20:25 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O32 - AutoRun File - [2004/09/13 12:15:24 | 000,000,053 | -HS- | M] () - D:\Autorun.inf – [ FAT32 ]
O32 - AutoRun File - [2010/11/22 16:54:07 | 000,000,075 | R— | M] () - E:\autorun.inf – [ CDFS ]
O33 - MountPoints2\{14698cc8-60b1-11df-a082-806d6172696f}\Shell - "" = AutoRun
O33 - MountPoints2\{14698cc8-60b1-11df-a082-806d6172696f}\Shell\AutoRun - "" = Auto&Play;
O33 - MountPoints2\{14698cc8-60b1-11df-a082-806d6172696f}\Shell\AutoRun\command - "" = E:\Setup.exe – [2010/11/22 17:02:11 | 000,128,336 | R— | M] (Logitech, Inc.)
O33 - MountPoints2\{c559b8bb-4a96-11e0-a0c4-0013205ed0f5}\Shell - "" = AutoRun
O33 - MountPoints2\{c559b8bb-4a96-11e0-a0c4-0013205ed0f5}\Shell\AutoRun - "" = Auto&Play;
O33 - MountPoints2\{c559b8bb-4a96-11e0-a0c4-0013205ed0f5}\Shell\AutoRun\command - "" = J:\LaunchU3.exe -a
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

NetSvcs: 6to4 - File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found

CREATERESTOREPOINT
Restore point Set: OTL Restore Point

========== Files/Folders - Created Within 30 Days ==========

[2012/02/21 08:02:18 | 000,000,000 | —D | C] – C:\Documents and Settings\Owner\Desktop\OLT
[2012/02/20 23:29:32 | 000,000,000 | R–D | C] – C:\Documents and Settings\Owner\Start Menu\Programs\Administrative Tools
[2012/02/19 14:40:05 | 000,000,000 | —D | C] – C:\WINDOWS\LastGood
[2012/02/17 12:17:46 | 000,000,000 | —D | C] – C:\Documents and Settings\Owner\Local Settings\Application Data\I Want This
[2012/02/17 12:17:41 | 000,000,000 | —D | C] – C:\Program Files\I Want This
[2012/02/17 12:17:38 | 000,000,000 | —D | C] – C:\Program Files\Babylon
[2012/02/17 12:17:24 | 000,000,000 | —D | C] – C:\Program Files\Brand Affinity Technologies
[2012/02/17 12:17:14 | 000,000,000 | —D | C] – C:\Program Files\Yontoo Layers Runtime
[2012/02/17 12:17:10 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Tarma Installer
[2012/01/31 08:41:36 | 000,000,000 | —D | C] – C:\Documents and Settings\Owner\Application Data\SUPERAntiSpyware.com
[2012/01/31 08:41:15 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\SUPERAntiSpyware
[2012/01/31 08:41:08 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
[2012/01/31 08:41:08 | 000,000,000 | —D | C] – C:\Program Files\SUPERAntiSpyware
[2012/01/24 19:18:07 | 000,000,000 | —D | C] – C:\Documents and Settings\Owner\Desktop\snes
[2012/01/24 19:17:09 | 001,021,440 | —- | C] (Firelight Technologies) – C:\Documents and Settings\Owner\Desktop\fmodex64.dll
[3 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2012/02/21 08:09:00 | 000,000,978 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-229652688-3306118827-56669048-1006UA.job
[2012/02/20 15:09:00 | 000,000,926 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-229652688-3306118827-56669048-1006Core.job
[2012/02/19 14:38:54 | 000,001,261 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Logitech Webcam Software .lnk
[2012/02/19 02:12:26 | 000,000,424 | -H– | M] () – C:\WINDOWS\tasks\MP Scheduled Scan.job
[2012/02/16 15:10:23 | 000,002,284 | —- | M] () – C:\Documents and Settings\Owner\Desktop\Google Chrome.lnk
[2012/02/16 15:10:23 | 000,002,262 | —- | M] () – C:\Documents and Settings\Owner\Application Data\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk
[2012/02/16 14:45:00 | 000,000,284 | —- | M] () – C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2012/02/16 03:32:27 | 000,001,004 | —- | M] () – C:\Documents and Settings\Owner\Desktop\magicJack.lnk
[2012/02/16 03:29:43 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2012/02/16 03:29:41 | 3476,893,696 | -HS- | M] () – C:\hiberfil.sys
[2012/02/16 03:29:41 | 000,303,624 | —- | M] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2012/02/16 03:13:05 | 000,444,456 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2012/02/16 03:13:05 | 000,072,332 | —- | M] () – C:\WINDOWS\System32\perfc009.dat
[2012/02/16 03:03:46 | 000,001,374 | —- | M] () – C:\WINDOWS\imsins.BAK
[2012/02/14 22:36:56 | 000,002,515 | —- | M] () – C:\Documents and Settings\Owner\Desktop\Microsoft Office Word 2007.lnk
[2012/02/08 23:34:25 | 000,002,205 | —- | M] () – C:\Documents and Settings\Owner\.recently-used.xbel
[2012/02/08 23:31:09 | 007,104,420 | —- | M] () – C:\Documents and Settings\Owner\My Documents\BeerLabel-ackbar.xcf
[2012/02/07 20:19:32 | 000,274,816 | —- | M] () – C:\Documents and Settings\Owner\Desktop\Dobby-Harry-Potter-Deathly-Hallows-Wallpaper.jpg
[2012/02/01 06:51:33 | 000,001,008 | —- | M] () – C:\Documents and Settings\Owner\Start Menu\Programs\Startup\Dropbox.lnk
[2012/02/01 06:51:33 | 000,001,008 | —- | M] () – C:\Documents and Settings\Owner\Desktop\Dropbox.lnk
[2012/01/31 08:41:15 | 000,001,678 | —- | M] () – C:\Documents and Settings\All Users\Desktop\SUPERAntiSpyware Free Edition.lnk
[2012/01/31 06:44:05 | 000,237,072 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\MpSigStub.exe
[2012/01/24 15:21:58 | 000,027,829 | —- | M] () – C:\Documents and Settings\Owner\My Documents\Elizabeth 2011_Federal_Return.pdf
[2012/01/23 12:17:14 | 000,027,264 | —- | M] () – C:\Documents and Settings\Owner\Desktop\Michael 2011_Federal_Return.pdf
[3 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]

========== Files Created - No Company Name ==========

[2012/02/15 06:35:07 | 000,003,072 | —- | C] () – C:\WINDOWS\System32\iacenc.dll
[2012/02/15 06:35:07 | 000,003,072 | —- | C] () – C:\WINDOWS\System32\dllcache\iacenc.dll
[2012/02/08 23:34:25 | 000,002,205 | —- | C] () – C:\Documents and Settings\Owner\.recently-used.xbel
[2012/02/08 23:31:09 | 007,104,420 | —- | C] () – C:\Documents and Settings\Owner\My Documents\BeerLabel-ackbar.xcf
[2012/02/07 20:19:35 | 000,274,816 | —- | C] () – C:\Documents and Settings\Owner\Desktop\Dobby-Harry-Potter-Deathly-Hallows-Wallpaper.jpg
[2012/01/31 08:41:15 | 000,001,678 | —- | C] () – C:\Documents and Settings\All Users\Desktop\SUPERAntiSpyware Free Edition.lnk
[2012/01/24 15:21:58 | 000,027,829 | —- | C] () – C:\Documents and Settings\Owner\My Documents\Elizabeth 2011_Federal_Return.pdf
[2012/01/23 12:17:14 | 000,027,264 | —- | C] () – C:\Documents and Settings\Owner\Desktop\Michael 2011_Federal_Return.pdf
[2012/01/14 17:06:23 | 000,033,792 | —- | C] () – C:\WINDOWS\System32\drivers\libusb0.sys
[2011/10/19 23:05:59 | 000,045,056 | —- | C] () – C:\WINDOWS\System32\BRTCPCON.DLL
[2011/10/19 23:05:59 | 000,000,114 | —- | C] () – C:\WINDOWS\System32\BRLMW03A.INI
[2011/10/19 23:05:59 | 000,000,050 | —- | C] () – C:\WINDOWS\System32\BRADM10A.DAT
[2011/08/19 03:26:20 | 010,920,984 | —- | C] () – C:\WINDOWS\System32\LogiDPP.dll
[2011/08/19 03:26:20 | 000,336,408 | —- | C] () – C:\WINDOWS\System32\DevManagerCore.dll
[2011/08/19 03:26:20 | 000,104,472 | —- | C] () – C:\WINDOWS\System32\LogiDPPApp.exe
[2011/08/12 12:20:14 | 000,015,896 | —- | C] () – C:\WINDOWS\System32\drivers\iKeyLFT2.dll
[2011/07/26 00:48:54 | 000,028,418 | —- | C] () – C:\WINDOWS\System32\lvcoinst.ini
[2011/07/03 14:57:22 | 000,495,616 | —- | C] () – C:\WINDOWS\System32\lame_enc.dll
[2011/06/07 07:28:17 | 000,000,443 | —- | C] () – C:\Program Files\060720118281746.bat
[2011/06/07 07:02:09 | 000,000,196 | -H– | C] () – C:\WINDOWS\System32\tscct1.dll
[2011/06/07 07:02:03 | 000,270,409 | —- | C] () – C:\WINDOWS\System32\TifToPdfCtxMenu.dll
[2010/10/16 09:21:29 | 000,027,648 | —- | C] () – C:\WINDOWS\System32\AVSredirect.dll
[2010/08/25 05:09:08 | 000,000,437 | —- | C] () – C:\Documents and Settings\Owner\Application Data\ImageTuner.ini
[2010/08/05 13:24:21 | 000,000,742 | R— | C] () – C:\WINDOWS\MSPPWSV.ini
[2010/06/30 12:34:14 | 000,064,820 | -H– | C] () – C:\WINDOWS\System32\mlfcache.dat
[2010/06/11 17:40:59 | 000,007,680 | —- | C] () – C:\WINDOWS\System32\ff_vfw.dll
[2010/05/20 21:23:49 | 000,087,552 | —- | C] () – C:\WINDOWS\System32\cpwmon2k.dll
[2010/05/16 16:31:12 | 000,000,128 | —- | C] () – C:\Documents and Settings\Owner\Local Settings\Application Data\fusioncache.dat
[2010/05/16 00:19:38 | 000,035,328 | —- | C] () – C:\Documents and Settings\Owner\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/05/15 23:57:19 | 000,000,000 | —- | C] () – C:\WINDOWS\nsreg.dat
[2010/05/15 23:56:01 | 000,543,232 | —- | C] () – C:\WINDOWS\zHotkey.exe
[2010/05/15 23:56:01 | 000,532,544 | —- | C] () – C:\WINDOWS\PIC.dll
[2010/05/15 23:56:01 | 000,036,864 | —- | C] () – C:\WINDOWS\ShowWnd.exe
[2010/05/15 23:56:01 | 000,024,576 | —- | C] () – C:\WINDOWS\HKNTDLL.dll
[2010/05/15 23:54:01 | 000,471,298 | —- | C] () – C:\WINDOWS\wallpg.exe

========== LOP Check ==========

[2011/02/04 15:00:35 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\2DBoy
[2011/10/28 13:41:49 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Big Fish Games
[2010/09/19 19:17:51 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Electronic Arts
[2011/07/05 16:49:16 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Elephant Games
[2011/05/01 21:27:25 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\HipSoft
[2010/05/16 12:58:59 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Macrium
[2011/08/12 16:54:19 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\magicJack
[2011/01/30 23:52:29 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\MumboJumbo
[2010/05/16 01:00:58 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Napster
[2011/02/17 17:07:32 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Oberon Media
[2010/10/16 15:27:25 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\PassMark
[2012/02/17 12:17:13 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Tarma Installer
[2012/01/28 07:58:53 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TEMP
[2011/03/08 08:16:54 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\YNAB
[2010/05/17 14:35:46 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
[2011/12/20 20:06:41 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\.minecraft
[2011/02/20 21:21:01 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Alawar
[2011/07/03 14:44:07 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Amazon
[2010/10/15 16:32:20 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\AnvSoft
[2011/09/05 16:13:30 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Auslogics
[2010/08/25 06:15:44 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Canon
[2011/01/01 07:56:47 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\com.warnerbros.DigitalCopyManager.449F66ACC381FDC604DC2AA255FEECEEBBBEE1E5.
1
[2011/07/06 18:53:46 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\DailyMagic
[2012/02/20 15:30:45 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Dropbox
[2011/07/05 16:49:16 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Elephant Games
[2011/02/10 20:35:25 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\ERS Game Studios
[2010/05/24 11:04:09 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Facebook
[2011/02/26 02:26:09 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\FileZilla
[2011/07/10 07:50:05 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\FireShot
[2010/05/26 05:30:48 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Flickr
[2011/07/03 14:45:52 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\FreeAudioPack
[2011/05/02 07:04:41 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\GARMIN
[2010/08/25 06:25:57 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\GetRightToGo
[2011/02/22 22:27:05 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\GOL_byHasbro
[2012/02/08 23:34:25 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\gtk-2.0
[2011/09/05 14:39:49 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\JGoodies
[2011/12/21 13:08:07 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Leadertech
[2012/02/16 03:32:33 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\mjusbsp
[2012/01/14 17:03:15 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\MotioninJoy
[2011/01/30 23:52:29 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\MumboJumbo
[2011/02/17 17:07:42 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Oberon Media
[2010/07/26 17:24:07 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\OpenDNS Updater
[2010/05/28 23:56:47 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\OpenOffice.org
[2011/01/10 11:50:49 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\PlayPond
[2010/05/15 23:54:49 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\SampleView
[2010/07/19 17:54:34 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Skunk Studios
[2011/04/22 23:40:54 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\TOMI3
[2011/01/24 18:08:39 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\URSE Games
[2011/08/15 13:00:01 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Vast Studios
[2010/08/25 06:27:12 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Xilisoft
[2012/02/19 02:12:26 | 000,000,424 | -H– | M] () – C:\WINDOWS\Tasks\MP Scheduled Scan.job
[2010/05/17 11:23:54 | 000,000,266 | —- | M] () – C:\WINDOWS\Tasks\RegTask.job

========== Purity Check ==========



========== Custom Scans ==========


< %SYSTEMDRIVE%\*.exe >


< MD5 for: AGP440.SYS >
[2004/08/10 13:00:00 | 016,971,599 | —- | M] () .cab file – C:\WINDOWS\Driver Cache\i386\sp2.cab:AGP440.sys
[2010/05/16 12:18:27 | 023,852,652 | —- | M] () .cab file – C:\WINDOWS\Driver Cache\i386\sp3.cab:AGP440.sys
[2004/08/10 13:00:00 | 016,971,599 | —- | M] () .cab file – C:\WINDOWS\I386\sp2.cab:AGP440.sys
[2010/05/16 12:18:27 | 023,852,652 | —- | M] () .cab file – C:\WINDOWS\ServicePackFiles\i386\sp3.cab:AGP440.sys
[2008/04/13 12:36:38 | 000,042,368 | —- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 – C:\WINDOWS\ServicePackFiles\i386\agp440.sys
[2008/04/13 12:36:38 | 000,042,368 | —- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 – C:\WINDOWS\system32\drivers\agp440.sys
[2004/08/04 07:07:42 | 000,042,368 | —- | M] (Microsoft Corporation) MD5=2C428FA0C3E3A01ED93C9B2A27D8D4BB – C:\WINDOWS\$NtServicePackUninstall$\agp440.sys

< MD5 for: ATAPI.SYS >
[2004/08/10 13:00:00 | 016,971,599 | —- | M] () .cab file – C:\WINDOWS\Driver Cache\i386\sp2.cab:atapi.sys
[2010/05/16 12:18:27 | 023,852,652 | —- | M] () .cab file – C:\WINDOWS\Driver Cache\i386\sp3.cab:atapi.sys
[2004/08/10 13:00:00 | 016,971,599 | —- | M] () .cab file – C:\WINDOWS\I386\sp2.cab:atapi.sys
[2010/05/16 12:18:27 | 023,852,652 | —- | M] () .cab file – C:\WINDOWS\ServicePackFiles\i386\sp3.cab:atapi.sys
[2008/04/13 12:40:30 | 000,096,512 | —- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 – C:\WINDOWS\ServicePackFiles\i386\atapi.sys
[2008/04/13 12:40:30 | 000,096,512 | —- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 – C:\WINDOWS\system32\dllcache\atapi.sys
[2008/04/13 12:40:30 | 000,096,512 | —- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 – C:\WINDOWS\system32\drivers\atapi.sys
[2008/04/13 12:40:30 | 000,096,512 | —- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 – C:\WINDOWS\system32\ReinstallBackups\0005\DriverFiles\i386\atapi.sys
[2008/04/13 12:40:30 | 000,096,512 | —- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 – C:\WINDOWS\system32\ReinstallBackups\0006\DriverFiles\i386\atapi.sys
[2004/08/04 06:59:44 | 000,095,360 | —- | M] (Microsoft Corporation) MD5=CDFE4411A69C224BD1D11B2DA92DAC51 – C:\WINDOWS\$NtServicePackUninstall$\atapi.sys

< MD5 for: EVENTLOG.DLL >
[2008/04/13 18:11:53 | 000,056,320 | —- | M] (Microsoft Corporation) MD5=6D4FEB43EE538FC5428CC7F0565AA656 – C:\WINDOWS\ServicePackFiles\i386\eventlog.dll
[2008/04/13 18:11:53 | 000,056,320 | —- | M] (Microsoft Corporation) MD5=6D4FEB43EE538FC5428CC7F0565AA656 – C:\WINDOWS\system32\eventlog.dll
[2004/08/10 13:00:00 | 000,055,808 | —- | M] (Microsoft Corporation) MD5=82B24CB70E5944E6E34662205A2A5B78 – C:\WINDOWS\$NtServicePackUninstall$\eventlog.dll

< MD5 for: NETLOGON.DLL >
[2008/04/13 18:12:01 | 000,407,040 | —- | M] (Microsoft Corporation) MD5=1B7F071C51B77C272875C3A23E1E4550 – C:\WINDOWS\ServicePackFiles\i386\netlogon.dll
[2008/04/13 18:12:01 | 000,407,040 | —- | M] (Microsoft Corporation) MD5=1B7F071C51B77C272875C3A23E1E4550 – C:\WINDOWS\system32\netlogon.dll
[2009/02/06 12:46:09 | 000,408,064 | —- | M] (Microsoft Corporation) MD5=6C476D33D82F1054849790181E8F7772 – C:\WINDOWS\$hf_mig$\KB968389\SP2QFE\netlogon.dll
[2009/02/06 12:46:09 | 000,408,064 | —- | M] (Microsoft Corporation) MD5=6C476D33D82F1054849790181E8F7772 – C:\WINDOWS\$hf_mig$\KB975467\SP2QFE\netlogon.dll
[2004/08/10 13:00:00 | 000,407,040 | —- | M] (Microsoft Corporation) MD5=96353FCECBA774BB8DA74A1C6507015A – C:\WINDOWS\$NtServicePackUninstall$\netlogon.dll

< MD5 for: SCECLI.DLL >
[2004/08/10 13:00:00 | 000,180,224 | —- | M] (Microsoft Corporation) MD5=0F78E27F563F2AAF74B91A49E2ABF19A – C:\WINDOWS\$NtServicePackUninstall$\scecli.dll
[2008/04/13 18:12:05 | 000,181,248 | —- | M] (Microsoft Corporation) MD5=A86BB5E61BF3E39B62AB4C7E7085A084 – C:\WINDOWS\ServicePackFiles\i386\scecli.dll
[2008/04/13 18:12:05 | 000,181,248 | —- | M] (Microsoft Corporation) MD5=A86BB5E61BF3E39B62AB4C7E7085A084 – C:\WINDOWS\system32\scecli.dll

< %systemroot%\*. /mp /s >

< %systemroot%\system32\*.dll /lockedfiles >
[3 C:\WINDOWS\system32\*.tmp files -> C:\WINDOWS\system32\*.tmp -> ]

< %systemroot%\Tasks\*.job /lockedfiles >

< %systemroot%\system32\drivers\*.sys /lockedfiles >

< %systemroot%\System32\config\*.sav >
[2005/04/13 04:06:16 | 000,094,208 | —- | M] () – C:\WINDOWS\System32\config\default.sav
[2005/04/13 04:06:16 | 000,659,456 | —- | M] () – C:\WINDOWS\System32\config\software.sav
[2005/04/13 04:06:16 | 000,856,064 | —- | M] () – C:\WINDOWS\System32\config\system.sav

< %systemroot%\system32\drivers\*.sys /90 >
[2012/01/18 00:44:28 | 000,312,096 | —- | M] (Logitech Inc.) – C:\WINDOWS\system32\drivers\lvrs.sys
[2012/01/18 00:44:52 | 004,332,960 | —- | M] (Logitech Inc.) – C:\WINDOWS\system32\drivers\lvuvc.sys

========== Alternate Data Streams ==========

@Alternate Data Stream - 238 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:9812B773
@Alternate Data Stream - 236 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:3EC5BC08
@Alternate Data Stream - 232 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:FC70A22A
@Alternate Data Stream - 232 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:40EE25BB
@Alternate Data Stream - 222 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:329BA65B
@Alternate Data Stream - 217 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:9BB8C675
@Alternate Data Stream - 217 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:24C072FF
@Alternate Data Stream - 213 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:CAC06C34
@Alternate Data Stream - 204 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:B1FBBD09
@Alternate Data Stream - 204 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:78ADFF54
@Alternate Data Stream - 149 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:5B132D3E
@Alternate Data Stream - 142 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:961B84C5
@Alternate Data Stream - 130 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:864881BF
@Alternate Data Stream - 128 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:2C6A77F3
@Alternate Data Stream - 128 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:2211E7A0
@Alternate Data Stream - 125 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:BE6B5FC3
@Alternate Data Stream - 125 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:937C8022
@Alternate Data Stream - 120 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:1968990D
@Alternate Data Stream - 116 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:661DFA1C
@Alternate Data Stream - 112 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:E5496666

< End of report >
as requested EXTRAS.txt AND aswMBR.txt


OTL Extras logfile created on: 2/21/2012 8:33:15 AM - Run 1
OTL by OldTimer - Version 3.2.33.1 Folder = C:\Documents and Settings\Owner\Desktop\OLT
Windows XP Media Center Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

3.24 Gb Total Physical Memory | 2.22 Gb Available Physical Memory | 68.64% Memory free
5.08 Gb Paging File | 4.07 Gb Available in Paging File | 80.23% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 228.71 Gb Total Space | 73.52 Gb Free Space | 32.15% Space Free | Partition Type: NTFS
Drive D: | 4.16 Gb Total Space | 0.96 Gb Free Space | 23.18% Space Free | Partition Type: FAT32
Drive E: | 129.43 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS

Computer Name: BLACKGATE | User Name: Owner | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*

[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.html [@ = FirefoxHTML] – C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*
exefile [open] – "%1" %*
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [Digital Photo Professional] – C:\Program Files\Canon\Digital Photo Professional\DPPViewer.exe /path "%1" (CANON INC.)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

========== System Restore Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sr]
"Start" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SrService]
"Start" = 2

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
"139:TCP" = 139:TCP:*:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:*:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:*:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:*:Enabled:@xpsp2res.dll,-22002

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"3776:UDP" = 3776:UDP:*:Enabled:Media Center Extender Service
"3390:TCP" = 3390:TCP:*:Enabled:Remote Media Center Experience
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"139:TCP" = 139:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22002

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\WINDOWS\system32\usmt\migwiz.exe" = C:\WINDOWS\system32\usmt\migwiz.exe:*:Enabled:Files and Settings Transfer Wizard – (Microsoft Corporation)
"C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe" = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe:*:Enabled:hpqtra08.exe
"C:\Program Files\HP\Digital Imaging\bin\hpqste08.exe" = C:\Program Files\HP\Digital Imaging\bin\hpqste08.exe:*:Enabled:hpqste08.exe
"C:\Program Files\HP\Digital Imaging\bin\hposid01.exe" = C:\Program Files\HP\Digital Imaging\bin\hposid01.exe:*:Enabled:hposid01.exe
"C:\Program Files\HP\Digital Imaging\bin\hpiscnapp.exe" = C:\Program Files\HP\Digital Imaging\bin\hpiscnapp.exe:*:Enabled:hpiscnapp.exe
"C:\Program Files\HP\Digital Imaging\bin\hpqkygrp.exe" = C:\Program Files\HP\Digital Imaging\bin\hpqkygrp.exe:*:Enabled:hpqkygrp.exe
"C:\Program Files\Java\jre6\bin\java.exe" = C:\Program Files\Java\jre6\bin\java.exe:*:Disabled:Java™ Platform SE binary – (Sun Microsystems, Inc.)
"C:\Program Files\TVersity\Media Server\MediaServer.exe" = C:\Program Files\TVersity\Media Server\MediaServer.exe:*:Enabled:TVersity Media Server
"C:\Documents and Settings\Owner\Local Settings\Application Data\Google\Google Talk Plugin\googletalkplugin.exe" = C:\Documents and Settings\Owner\Local Settings\Application Data\Google\Google Talk Plugin\googletalkplugin.exe:*:Enabled:Google Talk Plugin – (Google)
"C:\My Backup – 15-05-10 2154\Program Files\FileZilla Client\filezilla.exe" = C:\My Backup – 15-05-10 2154\Program Files\FileZilla Client\filezilla.exe:*:Enabled:FileZilla FTP Client
"C:\Program Files\Electronic Arts\EADM\Core.exe" = C:\Program Files\Electronic Arts\EADM\Core.exe:*:Enabled:EA Download Manager
"C:\allan\babyftp.exe" = C:\allan\babyftp.exe:*:Enabled:Baby FTP Server – (Pablo Software Solutions)
"C:\Documents and Settings\Owner\Application Data\Dropbox\bin\Dropbox.exe" = C:\Documents and Settings\Owner\Application Data\Dropbox\bin\Dropbox.exe:*:Enabled:Dropbox – (Dropbox, Inc.)
"C:\Program Files\HP\HP Deskjet 1050 J410 series\Bin\USBSetup.exe" = C:\Program Files\HP\HP Deskjet 1050 J410 series\Bin\USBSetup.exe:LocalSubNet:Enabled:HP Device Setup – (Hewlett-Packard Co.)
"C:\Program Files\Common Files\Apple\Apple Application Support\WebKit2WebProcess.exe" = C:\Program Files\Common Files\Apple\Apple Application Support\WebKit2WebProcess.exe:*:Enabled:WebKit – (Apple Inc.)
"C:\Documents and Settings\Owner\Application Data\mjusbsp\magicJack.exe" = C:\Documents and Settings\Owner\Application Data\mjusbsp\magicJack.exe:*:Enabled:magicJack – (magicJack L.P.)


========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}" = Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148
"{05BFB060-4F22-4710-B0A2-2801A1B606C5}" = Microsoft Antimalware
"{07EEE598-5F21-4B57-B40B-46592625B3D9}" = Zune Language Pack (PTB)
"{08610298-29AE-445B-B37D-EFBE05802967}" = LWS Pictures And Video
"{138A4072-9E64-46BD-B5F9-DB2BB395391F}" = LWS VideoEffects
"{15634701-BACE-4449-8B25-1567DA8C9FD3}" = CameraHelperMsi
"{1651216E-E7AD-4250-92A1-FB8ED61391C9}" = LWS Help_main
"{174A3B31-4C43-43DD-866F-73C9DB887B48}" = LWS Twitter
"{196467F1-C11F-4F76-858B-5812ADC83B94}" = MSXML 4.0 SP3 Parser
"{1CB92574-96F2-467B-B793-5CEB35C40C29}" = Image Resizer Powertoy for Windows XP
"{21DF0294-6B9D-4741-AB6F-B2ABFBD2387E}" = LWS YouTube Plugin
"{226837D8-0BF8-4CBE-BAB2-8F07E2C2B4DD}" = HP Deskjet 1050 J410 series Basic Device Software
"{23FE964A-853B-4176-86D7-9E18B5CA1FC0}" = Media Center Extender
"{26A24AE4-039D-4CA4-87B4-2F83216018F0}" = Java™ 6 Update 18
"{26A24AE4-039D-4CA4-87B4-2F83216020FF}" = Java™ 6 Update 29
"{2A697B53-0DE3-42DA-B41D-C3F804B1C538}" = iTunes
"{2A981294-F14C-4F0F-9627-D793270922F8}" = Bonjour
"{2C4E2E4E-A7C9-4CCB-BF03-FE6EBD5D4AB7}" = Windows Mobile Device Updater Component
"{31A559C1-9E4D-423B-9DD3-34A6C5398752}" = HTC BMP USB Driver
"{3248F0A8-6813-11D6-A77B-00B0D0150020}" = J2SE Runtime Environment 5.0 Update 2
"{330DAC67-5B62-452A-A0E4-6B4A5923940F}_is1" = MotioninJoy ds3 driver version 0.6.0005
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{3D1B20A6-E31D-4BB5-BC5C-DDD3B0D91728}" = Intel Audio Studio
"{3EE9BCAE-E9A9-45E5-9B1C-83A4D357E05C}" = erLT
"{4412F224-3849-4461-A3E9-DEEF8D252790}" = Visual Studio C++ 10.0 Runtime
"{46C045BF-2B3F-4BC4-8E4C-00E0CF8BD9DB}" = Adobe AIR
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{529125EF-E3AC-4B74-97E6-F688A7C0F1BF}" = Paint.NET v3.5.10
"{54B6DC7D-8C5B-4DFB-BC15-C010A3326B2B}" = Microsoft Security Client
"{5C90D8CF-F12A-41C6-9007-3B651A1F0D78}" = HP Deskjet 1050 J410 series Help
"{5C93E291-A1CC-4E51-85C6-E194209FCDB4}" = Zune Language Pack (PTG)
"{612C34C7-5E90-47D8-9B5C-0F717DD82726}" = swMSM
"{65F9E1F3-A2C1-4AA9-9F33-A3AEB0255F0E}" = Garmin USB Drivers
"{6740BCB0-5863-47F4-80F4-44F394DE4FE2}" = Zune Language Pack (NLD)
"{6811CAA0-BF12-11D4-9EA1-0050BAE317E1}" = PowerDVD
"{69FDFBB6-351D-4B8C-89D8-867DC9D0A2A4}" = Windows Media Player Firefox Plugin
"{6ADD0603-16EF-400D-9F9E-486432835002}" = OpenOffice.org 3.2
"{6B33492E-FBBC-4EC3-8738-09E16E395A10}" = Zune Language Pack (ESP)
"{6E66ECBD-FCA7-4AE1-A8C5-1CA78BEEB057}" = Multimedia Keyboard Driver
"{6F76EC3C-34B1-436E-97FB-48C58D7BEDCD}" = LWS Gallery
"{7006ED29-58F2-40C3-AE87-039287AD20B6}" = Zune
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{71E66D3F-A009-44AB-8784-75E2819BA4BA}" = LWS Motion Detection
"{76EFAC4F-1712-401F-B2AE-590B170C9BCE}" = StartupMonitor
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}" = Apple Software Update
"{7BE15435-2D3E-4B58-867F-9C75BED0208C}" = QuickTime
"{7F1B3341-A94E-4F5C-B587-CA0EB964221E}" = Microsoft Money Shared Libraries
"{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-116623990}" = THE GAME OF LIFE by Hasbro
"{83C8FA3C-F4EA-46C4-8392-D3CE353738D6}" = LWS Launcher
"{889DF117-14D1-44EE-9F31-C5FB5D47F68B}" = Yontoo Layers Runtime 1.10.01
"{8937D274-C281-42E4-8CDB-A0B2DF979189}" = LWS Webcam Software
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8A708DD8-A5E6-11D4-A706-000629E95E20}" = Intel® Graphics Media Accelerator Driver
"{8DCE550C-CA43-4E82-92DF-FFC4A48F5BE1}" = Napster Burn Engine
"{90120000-0010-0409-0000-0000000FF1CE}" = Microsoft Software Update for Web Folders (English) 12
"{90120000-0015-0409-0000-0000000FF1CE}" = Microsoft Office Access MUI (English) 2007
"{90120000-0015-0409-0000-0000000FF1CE}_ENTERPRISER_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2007
"{90120000-0016-0409-0000-0000000FF1CE}_ENTERPRISER_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2007
"{90120000-0018-0409-0000-0000000FF1CE}_ENTERPRISER_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0019-0409-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (English) 2007
"{90120000-0019-0409-0000-0000000FF1CE}_ENTERPRISER_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001A-0409-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (English) 2007
"{90120000-001A-0409-0000-0000000FF1CE}_ENTERPRISER_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2007
"{90120000-001B-0409-0000-0000000FF1CE}_ENTERPRISER_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}_ENTERPRISER_{ABDDE972-355B-4AF1-89A8-DA50B7B5C045}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-040C-0000-0000000FF1CE}_ENTERPRISER_{F580DDD5-8D37-4998-968E-EBB76BB86787}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007
"{90120000-001F-0C0A-0000-0000000FF1CE}_ENTERPRISER_{187308AB-5FA7-4F14-9AB9-D290383A10D9}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007
"{90120000-0044-0409-0000-0000000FF1CE}" = Microsoft Office InfoPath MUI (English) 2007
"{90120000-0044-0409-0000-0000000FF1CE}_ENTERPRISER_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}_ENTERPRISER_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-00A1-0409-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2007
"{90120000-00A1-0409-0000-0000000FF1CE}_ENTERPRISER_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-00BA-0409-0000-0000000FF1CE}" = Microsoft Office Groove MUI (English) 2007
"{90120000-00BA-0409-0000-0000000FF1CE}_ENTERPRISER_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0114-0409-0000-0000000FF1CE}" = Microsoft Office Groove Setup Metadata MUI (English) 2007
"{90120000-0114-0409-0000-0000000FF1CE}_ENTERPRISER_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007
"{90120000-0115-0409-0000-0000000FF1CE}_ENTERPRISER_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0117-0409-0000-0000000FF1CE}" = Microsoft Office Access Setup Metadata MUI (English) 2007
"{90120000-0117-0409-0000-0000000FF1CE}_ENTERPRISER_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{91120000-0030-0000-0000-0000000FF1CE}" = Microsoft Office Enterprise 2007
"{91120000-0030-0000-0000-0000000FF1CE}_ENTERPRISER_{0B36C6D6-F5D8-4EAF-BF94-4376A230AD5B}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{91120000-0030-0000-0000-0000000FF1CE}_ENTERPRISER_{3D019598-7B59-447A-80AE-815B703B84FF}" = Security Update for Microsoft Office system 2007 (972581)
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{9559F7CA-5E34-4237-A2D9-D856464AD727}" = Project64 1.6
"{9584B2EF-99BE-41A5-8AF0-779B92E1C015}" = Fantapper Player
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{9DAEA76B-E50F-4272-A595-0124E826553D}" = LWS WLM Plugin
"{9F0E3482-8FB8-41E3-8A04-517BCD797D91}" = AquaSnap
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{A462213D-EED4-42C2-9A60-7BDD4D4B0B17}" = SigmaTel Audio
"{A760067A-C07E-1033-0000-A764AC000010}" = Avery Template
"{A83279FD-CA4B-4206-9535-90974DE76654}" = Apple Application Support
"{AA59DDE4-B672-4621-A016-4C248204957A}" = Skype™ 5.6
"{AC76BA86-7AD7-1033-7B44-A94000000001}" = Adobe Reader 9.4.4
"{B9561886-9EDF-48C8-A613-9843F1EE512E}" = Intel Audio Studio
"{BE236D9A-52EC-4A17-82DA-84B5EAD31E3E}" = Zune Language Pack (DEU)
"{C05D8CDB-417D-4335-A38C-A0659EDFD6B8}" = The Sims™ 3
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{C5D37FFA-7483-410B-982B-91E93FD3B7DA}" = Zune Language Pack (ITA)
"{C68D33B1-0204-4EBE-BC45-A6E432B1D13A}" = Zune Language Pack (FRA)
"{C9E4932C-8417-4E4C-A0E3-EE534810AB4D}" = ClearType Tuning Control Panel Applet
"{CACAEB5F-174D-4C7C-AC56-A33289A807CA}" = Apple Mobile Device Support
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{CCF13D13-A87B-34E8-B689-1896D0C2DBA2}" = Google Talk Plugin
"{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}" = SUPERAntiSpyware
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{D17111CB-C992-42A9-9D56-C19395102AAA}" = Garmin WebUpdater
"{D40EB009-0499-459c-A8AF-C9C110766215}" = Logitech Webcam Software
"{DF6A13C0-77DF-41FE-BD05-6D5201EB0CE7}_is1" = Auslogics Disk Defrag
"{E3E71D07-CD27-46CB-8448-16D4FB29AA13}" = Microsoft WSE 3.0 Runtime
"{EED027B7-0DB6-404B-8F45-6DFEE34A0441}" = LWS Video Mask Maker
"{F1E63043-54FC-429B-AB2C-31AF9FBA4BC7}" = 32 Bit HP CIO Components Installer
"{FF167195-9EE4-46C0-8CD7-FBA3457E88AB}" = LWS Facebook
"{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022
"49CF605F02C7954F4E139D18828DE298CD59217C" = Windows Driver Package - Garmin (grmnusb) GARMIN Devices (06/03/2009 2.3.0.0)
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 11 Plugin
"Adobe Shockwave Player" = Adobe Shockwave Player 11.6
"Amazon MP3 Downloader" = Amazon MP3 Downloader 1.0.12
"Any Video Converter Professional_is1" = Any Video Converter Professional 3.1.8
"Audacity_is1" = Audacity 1.2.6
"BFG-Behind the Reflection" = Behind the Reflection
"BFGC" = Big Fish Games: Game Manager
"BFG-Dark Dimensions - City of Fog" = Dark Dimensions: City of Fog
"BFG-Dark Tales - Edgar Allan Poe's The Black Cat Collector's Edition" = Dark Tales: ™ Edgar Allan Poe's The Black Cat Collector's Edition
"BFG-Finding Hope" = Finding Hope
"BFG-Flux Family Secrets - The Rabbit Hole" = Flux Family Secrets - The Rabbit Hole
"BFG-Haunted Legends - The Queen of Spades" = Haunted Legends: The Queen of Spades
"BFG-Luxor - 5th Passage" = Luxor: 5th Passage
"BFG-Mystery Legends - The Phantom of the Opera" = Mystery Legends: The Phantom of the Opera
"BFG-Mystery Trackers - Raincliff" = Mystery Trackers: Raincliff
"BFG-Mystery Trackers - The Void" = Mystery Trackers: The Void
"BFG-Plants vs Zombies" = Plants vs. Zombies
"BFG-PuppetShow - Lost Town" = PuppetShow: Lost Town
"BFG-Season Match - Curse of the Witch Crow" = Season Match: Curse of the Witch Crow
"BFG-Slingo Quest Egypt" = Slingo Quest Egypt
"BFG-The Treasures of Mystery Island - The Ghost Ship" = The Treasures of Mystery Island: The Ghost Ship
"BFG-Written Legends - Nightmare at Sea" = Written Legends: Nightmare at Sea
"CANON iMAGE GATEWAY Task" = CANON iMAGE GATEWAY Task for ZoomBrowser EX
"Canon Internet Library for ZoomBrowser EX" = Canon Internet Library for ZoomBrowser EX
"Canon MOV Decoder" = Canon MOV Decoder
"Canon MOV Encoder" = Canon MOV Encoder
"CNXT_MODEM_PCI_VEN_14F1&DEV_2F20&SUBSYS_200014F1" = SoftV92 Data Fax Modem with SmartCP
"CutePDF Writer Installation" = CutePDF Writer 2.8
"dcmsvc_is1" = dcmsvc 1.0
"DPP" = Canon Utilities Digital Photo Professional 3.8
"EHome Devices" = Media Center Extender
"ENTERPRISER" = Microsoft Office Enterprise 2007
"EOS Utility" = Canon Utilities EOS Utility
"ffdshow_is1" = ffdshow [rev 1723] [2007-12-24]
"FileZilla Client" = FileZilla Client 3.3.5.1
"Flickr Uploadr" = Flickr Uploadr 3.2.1
"I Want This" = I Want This
"ie8" = Windows Internet Explorer 8
"Image Tuner_is1" = Image Tuner 1.3
"JDiskReport 1.3.2" = JGoodies JDiskReport 1.3.2
"LAME for Audacity_is1" = LAME v3.98.3 for Audacity
"LibUSB-Win32_is1" = LibUSB-Win32-0.1.10.1
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Microsoft Security Client" = Microsoft Security Essentials
"Money2008b" = Microsoft Money Plus
"MovieEditTask" = Canon MovieEdit Task for ZoomBrowser EX
"Mozilla Firefox 10.0.2 (x86 en-US)" = Mozilla Firefox 10.0.2 (x86 en-US)
"MSCompPackV1" = Microsoft Compression Client Pack 1.0 for Windows XP
"MyTomTom" = MyTomTom 3.1.0.530
"OpenDNS Updater" = OpenDNS Updater 2.2.1
"Original Data Security Tools" = Canon Utilities Original Data Security Tools
"PhotoStitch" = Canon Utilities PhotoStitch
"Picasa 3" = Picasa 3
"Picture Style Editor" = Canon Utilities Picture Style Editor
"QuicktimeAlt_is1" = QuickTime Alternative 3.2.2
"SequoiaView" = SequoiaView
"SpeedFan" = SpeedFan (remove only)
"SUPER ©" = SUPER © Version 2010.bld.38 (May 2, 2010)
"Tiff to PDF converter_is1" = Tiff to PDF converter 1.0
"VirtualCloneDrive" = VirtualCloneDrive
"Wdf01009" = Microsoft Kernel-Mode Driver Framework Feature Pack 1.9
"WFTK" = Canon Utilities WFT Utility
"Windows Media Format Runtime" = Windows Media Format 11 runtime
"Windows Media Player" = Windows Media Player 11
"Windows XP Service Pack" = Windows XP Service Pack 3
"WinGimp-2.0_is1" = GIMP 2.6.11
"WinRAR archiver" = WinRAR archiver
"winusb0100" = Microsoft WinUsb 1.0
"WMFDist11" = Windows Media Format 11 runtime
"wmp11" = Windows Media Player 11
"Wubi" = Linux Mint
"Wudf01009" = Microsoft User-Mode Driver Framework Feature Pack 1.9
"Xilisoft 3GP Video Converter" = Xilisoft 3GP Video Converter 6
"YNAB_Pro_is1" = YNAB Pro version 2.9.4.0
"ZoomBrowser EX" = Canon Utilities ZoomBrowser EX
"ZoomBrowser EX Memory Card Utility" = Canon ZoomBrowser EX Memory Card Utility
"Zune" = Zune

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Dropbox" = Dropbox
"Facebook Plug-In" = Facebook Plug-In
"Google Chrome" = Google Chrome
"JoinMe" = join.me
"magicJack" = magicJack
"WinDirStat" = WinDirStat 1.1.2

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 12/6/2011 11:56:17 AM | Computer Name = BLACKGATE | Source = MPSampleSubmission | ID = 5000
Description = EventType avsubmit, P1 microsoft security essentials (edb4fa23-53b8-4afa-8c5d-99752cca7094),
P2 1.1.7903.0, P3 1.117.389.0, P4 1.117.389.0, P5 05b05dae-0000-0000-0000-000000000000_7160a23f44d8d90c44e3394953415191bc1e217b,
P6 NIL, P7 NIL, P8 NIL, P9 NIL, P10 NIL.

Error - 1/14/2012 5:38:05 PM | Computer Name = BLACKGATE | Source = Application Hang | ID = 1002
Description = Hanging application firefox.exe, version 9.0.1.4371, hang module hungapp,
version 0.0.0.0, hang address 0x00000000.

Error - 1/14/2012 5:50:24 PM | Computer Name = BLACKGATE | Source = Application Hang | ID = 1002
Description = Hanging application firefox.exe, version 9.0.1.4371, hang module hungapp,
version 0.0.0.0, hang address 0x00000000.

Error - 1/14/2012 5:50:27 PM | Computer Name = BLACKGATE | Source = Application Hang | ID = 1001
Description = Fault bucket -1544775435.

Error - 1/14/2012 10:45:35 PM | Computer Name = BLACKGATE | Source = Application Error | ID = 1000
Description = Faulting application project64.exe, version 0.0.0.0, faulting module
unknown, version 0.0.0.0, fault address 0x0230aacd.

Error - 1/19/2012 3:38:42 PM | Computer Name = BLACKGATE | Source = Application Hang | ID = 1002
Description = Hanging application firefox.exe, version 9.0.1.4371, hang module hungapp,
version 0.0.0.0, hang address 0x00000000.

Error - 1/20/2012 12:14:37 AM | Computer Name = BLACKGATE | Source = Application Hang | ID = 1002
Description = Hanging application firefox.exe, version 9.0.1.4371, hang module hungapp,
version 0.0.0.0, hang address 0x00000000.

Error - 1/22/2012 9:42:42 AM | Computer Name = BLACKGATE | Source = Application Error | ID = 1000
Description = Faulting application project64.exe, version 0.0.0.0, faulting module
project64.exe, version 0.0.0.0, fault address 0x00020723.

Error - 1/22/2012 9:53:40 AM | Computer Name = BLACKGATE | Source = Application Error | ID = 1000
Description = Faulting application project64.exe, version 0.0.0.0, faulting module
project64.exe, version 0.0.0.0, fault address 0x00020723.

Error - 1/24/2012 9:26:22 PM | Computer Name = BLACKGATE | Source = Application Hang | ID = 1002
Description = Hanging application WinRAR.exe, version 3.93.0.0, hang module hungapp,
version 0.0.0.0, hang address 0x00000000.

[ System Events ]
Error - 1/20/2012 5:21:48 AM | Computer Name = BLACKGATE | Source = Service Control Manager | ID = 7026
Description = The following boot-start or system-start driver(s) failed to load:
Cdr4_xp

Error - 1/27/2012 4:51:37 PM | Computer Name = BLACKGATE | Source = Service Control Manager | ID = 7011
Description = Timeout (30000 milliseconds) waiting for a transaction response from
the libusbd service.

Error - 1/28/2012 3:18:50 AM | Computer Name = BLACKGATE | Source = Service Control Manager | ID = 7011
Description = Timeout (30000 milliseconds) waiting for a transaction response from
the libusbd service.

Error - 2/12/2012 2:15:57 PM | Computer Name = BLACKGATE | Source = Service Control Manager | ID = 7011
Description = Timeout (30000 milliseconds) waiting for a transaction response from
the libusbd service.

Error - 2/13/2012 2:54:15 AM | Computer Name = BLACKGATE | Source = MRxSmb | ID = 8003
Description = The master browser has received a server announcement from the computer
TOSH-C655 that believes that it is the master browser for the domain on transport
NetBT_Tcpip_{970DBA6D-F618-4FE7. The master browser is stopping or an election is
being forced.

Error - 2/16/2012 5:30:34 AM | Computer Name = BLACKGATE | Source = Service Control Manager | ID = 7026
Description = The following boot-start or system-start driver(s) failed to load:
Cdr4_xp

Error - 2/18/2012 5:39:20 AM | Computer Name = BLACKGATE | Source = MRxSmb | ID = 8003
Description = The master browser has received a server announcement from the computer
TOSH-C655 that believes that it is the master browser for the domain on transport
NetBT_Tcpip_{970DBA6D-F618-4FE7. The master browser is stopping or an election is
being forced.

Error - 2/19/2012 4:40:43 PM | Computer Name = BLACKGATE | Source = Service Control Manager | ID = 7011
Description = Timeout (30000 milliseconds) waiting for a transaction response from
the libusbd service.

Error - 2/19/2012 5:26:51 PM | Computer Name = BLACKGATE | Source = Service Control Manager | ID = 7011
Description = Timeout (30000 milliseconds) waiting for a transaction response from
the libusbd service.

Error - 2/19/2012 5:28:26 PM | Computer Name = BLACKGATE | Source = Service Control Manager | ID = 7011
Description = Timeout (30000 milliseconds) waiting for a transaction response from
the libusbd service.


< End of report >


aswMBR version 0.9.9.1618 Copyright© 2011 AVAST Software
Run date: 2012-02-21 09:01:59
—————————–
09:01:59.913 OS Version: Windows 5.1.2600 Service Pack 3
09:01:59.913 Number of processors: 2 586 0x404
09:01:59.913 ComputerName: BLACKGATE UserName: Owner
09:02:00.648 Initialize success
09:03:04.087 AVAST engine defs: 12022100
09:03:31.088 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP1T0L0-e
09:03:31.088 Disk 0 Vendor: WDC_WD2500JD-22HBC0 08.02D08 Size: 238475MB BusType: 3
09:03:31.119 Disk 0 MBR read successfully
09:03:31.119 Disk 0 MBR scan
09:03:31.150 Disk 0 unknown MBR code
09:03:31.166 Disk 0 Partition 1 80 (A) 07 HPFS/NTFS NTFS 234197 MB offset 8739360
09:03:31.181 Disk 0 Partition 2 00 0B FAT32 RECOVERY 4267 MB offset 63
09:03:31.181 Disk 0 scanning sectors +488376000
09:03:31.244 Disk 0 scanning C:\WINDOWS\system32\drivers
09:03:41.619 Service scanning
09:03:57.291 Modules scanning
09:04:02.557 Disk 0 trace - called modules:
09:04:02.573 ntkrnlpa.exe CLASSPNP.SYS disk.sys atapi.sys hal.dll pciide.sys PCIIDEX.SYS
09:04:02.573 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x8af97200]
09:04:02.573 3 CLASSPNP.SYS[ba168fd7] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP1T0L0-e[0x8afce8a8]
09:04:03.370 AVAST engine scan C:\WINDOWS
09:04:15.573 AVAST engine scan C:\WINDOWS\system32
09:06:52.093 AVAST engine scan C:\WINDOWS\system32\drivers
09:07:14.281 AVAST engine scan C:\Documents and Settings\Owner
09:23:13.821 File: C:\Documents and Settings\Owner\Local Settings\Application Data\uofsoujsi\kslmyhxtssd.exe **INFECTED** Win32:MalOb-IJ [Cryp]
09:55:54.527 AVAST engine scan C:\Documents and Settings\All Users
09:59:50.627 Scan finished successfully
10:06:13.887 Disk 0 MBR has been saved successfully to "C:\Documents and Settings\Owner\Desktop\OLT\MBR.dat"
10:06:13.903 The log file has been saved successfully to "C:\Documents and Settings\Owner\Desktop\OLT\aswMBR.txt"


Thanks!
Hello jaeason

Thank you for the logs.

  • Combofix


  • Download ComboFix from one of the following locations:

    Link 1
    Link 2

  • VERY IMPORTANT !!! Save ComboFix.exe to your Desktop

  • IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here .
  • Double click on ComboFix.exe & follow the prompts.

  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.
  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.
  • Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.

[external image: Posted Image]

  • Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]

  • Click on Yes, to continue scanning for malware.
  • When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.
  • Notes: Do not mouse-click Combofix's window while it is running. That may cause it to stall.
  • Do not "re-run" Combofix. If you have a problem, reply back for further instructions.
  • Should there be issues with internet afterward:

    In IE: Tools Menu -> Internet Options -> Connections Tab -> Lan Settings -> uncheck "use a proxy server" or reconfigure the Proxy server again in case you have set it previously.

    In Firefox: Tools Menu -> Options… -> Advanced Tab -> Network Tab -> "Settings" under Connection and uncheck the proxyserver, set it to No Proxy.

Please post the Combofix log in your next reply.
Spyware and antivirus disabled, combofix saved to desktop. When combofix executed, it did indeed install the recovery console. BUT, when combofix got to somewhere around stage 24 the computer rebooted itself. When it came back up a little message on the right side of the toolbar said something like "an update was installed that required a reboot". I am unsure if PC crashed, or actually did a "planned" reboot for a piece of software. So, do I try ComboFix again? I don't see where it created any log, and searches still redirect to babylon. Please advise, jaeason
Hello jaeason

Thank you for letting me know.

Please check to see if a log was created. If a log was produced it will be on your C:\ drive (C:\ComboFix.txt).

If there is no log, please try Combofix again and let me know if the scan is able to complete.

If the same thing happens again we can try a different approach :)
The second running of Combofix worked without error.

Here is the log it created:


ComboFix 12-02-21.02 - Owner 02/21/2012 15:53:35.2.2 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.3316.2876 [GMT -6:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
AV: Microsoft Security Essentials *Disabled/Updated* {BCF43643-A118-4432-AEDE-D861FCBCFCDF}
AV: Microsoft Security Essentials *Disabled/Updated* {EDB4FA23-53B8-4AFA-8C5D-99752CCA7095}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\documents and settings\Administrator\WINDOWS
c:\documents and settings\All Users\Application Data\Tarma Installer
c:\documents and settings\All Users\Application Data\Tarma Installer\{2E1037EA-038A-425F-86B9-6CD19B8497E9}\_Setup.dll
c:\documents and settings\All Users\Application Data\Tarma Installer\{2E1037EA-038A-425F-86B9-6CD19B8497E9}\_Setupx.dll
c:\documents and settings\All Users\Application Data\Tarma Installer\{2E1037EA-038A-425F-86B9-6CD19B8497E9}\Setup.dat
c:\documents and settings\All Users\Application Data\Tarma Installer\{2E1037EA-038A-425F-86B9-6CD19B8497E9}\Setup.exe
c:\documents and settings\All Users\Application Data\Tarma Installer\{2E1037EA-038A-425F-86B9-6CD19B8497E9}\Setup.ico
c:\documents and settings\All Users\Application Data\Tarma Installer\{889DF117-14D1-44EE-9F31-C5FB5D47F68B}\_Setup.dll
c:\documents and settings\All Users\Application Data\Tarma Installer\{889DF117-14D1-44EE-9F31-C5FB5D47F68B}\_Setupx.dll
c:\documents and settings\All Users\Application Data\Tarma Installer\{889DF117-14D1-44EE-9F31-C5FB5D47F68B}\Setup.dat
c:\documents and settings\All Users\Application Data\Tarma Installer\{889DF117-14D1-44EE-9F31-C5FB5D47F68B}\Setup.exe
c:\documents and settings\All Users\Application Data\Tarma Installer\{889DF117-14D1-44EE-9F31-C5FB5D47F68B}\Setup.ico
c:\documents and settings\All Users\Application Data\TEMP
c:\documents and settings\All Users\invokesi.exe
c:\documents and settings\Default User\WINDOWS
c:\documents and settings\MCX1\WINDOWS
c:\documents and settings\Owner\Recent\Thumbs.db
c:\documents and settings\Owner\WINDOWS
c:\program files\Brand Affinity Technologies
c:\program files\Brand Affinity Technologies\Fantapper Player\ChromeInstaller.dll
c:\program files\Brand Affinity Technologies\Fantapper Player\ChromeInstaller.InstallState
c:\program files\Brand Affinity Technologies\Fantapper Player\fantapper_gi20111005.crx
c:\program files\Brand Affinity Technologies\Fantapper Player\fantapper_gi20111005.xpi
c:\program files\Brand Affinity Technologies\Fantapper Player\FantapperUpdateService.exe
c:\program files\Brand Affinity Technologies\Fantapper Player\FantapperUpdateService.InstallState
c:\program files\Brand Affinity Technologies\Fantapper Player\FirefoxInstaller.dll
c:\program files\Brand Affinity Technologies\Fantapper Player\FirefoxInstaller.InstallState
c:\program files\Brand Affinity Technologies\Fantapper Player\FT_Enabled.ico
c:\program files\Brand Affinity Technologies\Fantapper Player\FT_Plugin_Installer.jpg
c:\program files\Brand Affinity Technologies\Fantapper Player\IEInstaller.dll
c:\program files\Brand Affinity Technologies\Fantapper Player\OpenIE.dll
c:\program files\Brand Affinity Technologies\Fantapper Player\OpenIE.InstallState
c:\windows\05
c:\windows\05\.picasa.ini
c:\windows\05\IMG_3102.JPG
c:\windows\05\late night\.picasa.ini
c:\windows\05\late night\IMG_3637.JPG
c:\windows\05\late night\Thumbs.db
c:\windows\05\Thumbs.db
c:\windows\system32\config\systemprofile\WINDOWS
c:\windows\system32\ijl11.dll
c:\windows\system32\PowerToyReadme.htm
c:\windows\system32\SETB9.tmp
c:\windows\system32\SETC5.tmp
c:\windows\wallpg.exe
D:\Autorun.inf
.
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
——-\Legacy_FTSvc
——-\Legacy_FTSvc
——-\Service_FTSvc
——-\Service_FTSvc
.
.
((((((((((((((((((((((((( Files Created from 2012-01-21 to 2012-02-21 )))))))))))))))))))))))))))))))
.
.
2012-02-21 21:01 . 2012-02-08 06:03 6552120 —-a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{2BDFE632-4490-42E3-B60B-2729DA752599}\mpengine.dll
2012-02-17 18:17 . 2012-02-17 18:17 ——– d—–w- c:\documents and settings\Owner\Local Settings\Application Data\I Want This
2012-02-17 18:17 . 2012-02-17 18:17 ——– d—–w- c:\program files\I Want This
2012-02-17 18:17 . 2012-02-17 18:17 ——– d—–w- c:\program files\Babylon
2012-02-17 18:17 . 2012-02-17 18:17 ——– d—–w- c:\program files\Yontoo Layers Runtime
2012-02-15 12:35 . 2012-01-11 19:06 3072 -c—-w- c:\windows\system32\dllcache\iacenc.dll
2012-02-15 12:35 . 2012-01-11 19:06 3072 ——w- c:\windows\system32\iacenc.dll
2012-01-31 14:41 . 2012-01-31 14:41 ——– d—–w- c:\documents and settings\Owner\Application Data\SUPERAntiSpyware.com
2012-01-31 14:41 . 2012-02-21 20:04 ——– d—–w- c:\program files\SUPERAntiSpyware
2012-01-31 14:41 . 2012-01-31 14:41 ——– d—–w- c:\documents and settings\All Users\Application Data\SUPERAntiSpyware.com
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-01-31 12:44 . 2010-05-16 06:31 237072 ——w- c:\windows\system32\MpSigStub.exe
2012-01-18 06:44 . 2011-08-19 09:26 540960 —-a-w- c:\windows\system32\LVUI2RC.dll
2012-01-18 06:44 . 2011-08-19 09:26 4332960 —-a-w- c:\windows\system32\drivers\lvuvc.sys
2012-01-18 06:44 . 2011-08-19 09:26 545056 —-a-w- c:\windows\system32\LVUI2.dll
2012-01-18 06:44 . 2011-08-19 09:26 312096 —-a-w- c:\windows\system32\drivers\lvrs.sys
2012-01-18 06:44 . 2012-01-18 06:44 196896 —-a-w- c:\windows\system32\lvci13311044.dll
2012-01-18 06:44 . 2011-08-19 09:26 307488 —-a-w- c:\windows\system32\lvcodec2.dll
2012-01-18 06:44 . 2011-08-19 09:26 336408 —-a-w- c:\windows\system32\DevManagerCore.dll
2012-01-18 06:44 . 2011-08-19 09:26 10920984 —-a-w- c:\windows\system32\LogiDPP.dll
2012-01-18 06:44 . 2011-08-19 09:26 104472 —-a-w- c:\windows\system32\LogiDPPApp.exe
2012-01-12 16:53 . 2005-04-13 16:56 1859968 —-a-w- c:\windows\system32\win32k.sys
2012-01-06 04:19 . 2010-05-16 06:52 6557240 —-a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
2011-12-21 19:08 . 2011-12-21 19:08 53248 —-a-r- c:\documents and settings\Owner\Application Data\Microsoft\Installer\{3EE9BCAE-E9A9-45E5-9B1C-83A4D357E05C}\ARPPRODUCTICON.exe
2011-12-17 19:46 . 2005-04-13 16:56 916992 —-a-w- c:\windows\system32\wininet.dll
2011-12-17 19:46 . 2005-04-13 16:55 43520 —-a-w- c:\windows\system32\licmgr10.dll
2011-12-17 19:46 . 2005-04-13 16:55 1469440 —-a-w- c:\windows\system32\inetcpl.cpl
2011-12-16 12:22 . 2005-04-13 16:55 385024 —-a-w- c:\windows\system32\html.iec
2011-12-15 23:03 . 2011-12-15 23:03 138056 —-a-w- c:\windows\system32\atl100.dll
2011-12-02 15:03 . 2011-12-02 15:03 414368 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2011-11-25 21:57 . 2005-04-13 16:56 293376 —-a-w- c:\windows\system32\winsrv.dll
2011-06-07 13:28 . 2011-06-07 13:28 443 —-a-w- c:\program files\060720118281746.bat
2012-02-18 18:25 . 2010-03-26 16:29 134104 —-a-w- c:\program files\mozilla firefox\components\browsercomps.dll
2006-05-02 23:00 163328 –sha-r- c:\windows\system32\flvDX.dll
2007-02-20 23:00 31232 –sha-r- c:\windows\system32\msfDX.dll
2008-03-15 23:00 216064 –sha-r- c:\windows\system32\nbDX.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{11111111-1111-1111-1111-110011221158}]
2012-01-25 16:17 475480 —-a-w- c:\program files\I Want This\I Want This.dll
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{FD72061E-9FDE-484D-A58A-0BAB4151CAD8}]
2011-09-30 17:27 194848 —-a-w- c:\program files\Yontoo Layers Runtime\YontooIEClient.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1]
@="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}]
2011-02-18 05:12 94208 —-a-w- c:\documents and settings\Owner\Application Data\Dropbox\bin\DropboxExt.14.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2]
@="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}]
2011-02-18 05:12 94208 —-a-w- c:\documents and settings\Owner\Application Data\Dropbox\bin\DropboxExt.14.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3]
@="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}]
2011-02-18 05:12 94208 —-a-w- c:\documents and settings\Owner\Application Data\Dropbox\bin\DropboxExt.14.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt4]
@="{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}]
2011-02-18 05:12 94208 —-a-w- c:\documents and settings\Owner\Application Data\Dropbox\bin\DropboxExt.14.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"OpenDNS Updater"="c:\program files\OpenDNS Updater\OpenDNSUpdater.exe" [2010-06-16 839680]
"cdloader"="c:\documents and settings\Owner\Application Data\mjusbsp\cdloader2.exe" [2011-08-23 50592]
"AquaSnap"="c:\program files\AquaSnap\AquaSnap.Daemon.exe" [2011-01-22 875008]
"Skype"="c:\program files\Skype\Phone\Skype.exe" [2011-10-13 19979400]
"MyTomTomSA.exe"="c:\program files\MyTomTom 3\MyTomTomSA.exe" [2011-11-14 435672]
"SUPERAntiSpyware"="c:\program files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2012-02-19 4617600]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Recguard"="c:\windows\SMINST\RECGUARD.EXE" [2002-09-13 212992]
"IntelAudioStudio"="c:\program files\Intel Audio Studio\IntelAudioStudio.exe" [2005-05-10 7086080]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2005-04-05 94208]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2005-04-05 77824]
"Persistence"="c:\windows\system32\igfxpers.exe" [2005-04-05 114688]
"CHotkey"="zHotkey.exe" [2004-05-18 543232]
"ShowWnd"="ShowWnd.exe" [2003-09-19 36864]
"Run StartupMonitor"="StartupMonitor.exe" [2000-05-20 86016]
"dcmsvc"="c:\program files\dcmsvc\dcmsvc.exe" [2009-04-07 30440]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2008-10-25 31072]
"Zune Launcher"="c:\program files\Zune\ZuneLauncher.exe" [2010-11-11 159472]
"MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2011-06-15 997920]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2011-03-07 421160]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-01-03 843712]
"VirtualCloneDrive"="c:\program files\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe" [2011-03-07 89456]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2011-06-09 254696]
"APSDaemon"="c:\program files\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2011-09-27 59240]
"QuickTime Task"="c:\program files\QuickTime Alternative\QTTask.exe" [2011-10-24 421888]
"LWS"="c:\program files\Logitech\LWS\Webcam Software\LWS.exe" [2011-11-11 205336]
.
c:\documents and settings\Owner\Start Menu\Programs\Startup\
Dropbox.lnk - c:\documents and settings\Owner\Application Data\Dropbox\bin\Dropbox.exe [2012-1-18 24246216]
magicJack.lnk - c:\documents and settings\Owner\Application Data\mjusbsp\magicJackLoader.exe [2011-8-23 800240]
.
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2011-07-19 113024]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2011-05-04 17:54 551296 —-a-w- c:\program files\SUPERAntiSpyware\SASWINLO.DLL
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\!SASCORE]
@=""
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfSvc]
@="Service"
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Extender Resource Monitor.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Extender Resource Monitor.lnk
backup=c:\windows\pss\Extender Resource Monitor.lnkCommon Startup
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk
backup=c:\windows\pss\HP Digital Imaging Monitor.lnkCommon Startup
.
[HKLM\~\startupfolder\C:^Documents and Settings^Owner^Start Menu^Programs^Startup^OneNote 2007 Screen Clipper and Launcher.lnk]
path=c:\documents and settings\Owner\Start Menu\Programs\Startup\OneNote 2007 Screen Clipper and Launcher.lnk
backup=c:\windows\pss\OneNote 2007 Screen Clipper and Launcher.lnkStartup
.
[HKLM\~\startupfolder\C:^Documents and Settings^Owner^Start Menu^Programs^Startup^OpenOffice.org 3.2.lnk]
path=c:\documents and settings\Owner\Start Menu\Programs\Startup\OpenOffice.org 3.2.lnk
backup=c:\windows\pss\OpenOffice.org 3.2.lnkStartup
.
[HKLM\~\startupfolder\C:^Documents and Settings^Owner^Start Menu^Programs^Startup^PdaNet Desktop.lnk]
path=c:\documents and settings\Owner\Start Menu\Programs\Startup\PdaNet Desktop.lnk
backup=c:\windows\pss\PdaNet Desktop.lnkStartup
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
2012-01-03 07:37 843712 —-a-w- c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ehTray]
2005-08-05 18:56 64512 —-a-w- c:\windows\ehome\ehtray.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Update]
2010-05-16 06:24 136176 —-atw- c:\documents and settings\Owner\Local Settings\Application Data\Google\Update\GoogleUpdate.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\GrooveMonitor]
2008-10-25 16:44 31072 —-a-w- c:\program files\Microsoft Office\Office12\GrooveMonitor.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
2011-03-07 20:33 421160 —-a-w- c:\program files\iTunes\iTunesHelper.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
2008-04-14 00:12 1695232 —-a-w- c:\program files\Messenger\msmsgs.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
2011-06-09 18:06 254696 —-a-w- c:\program files\Common Files\Java\Java Update\jusched.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Zune Launcher]
2010-11-11 19:55 159472 —-a-w- c:\program files\Zune\ZuneLauncher.exe
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\WINDOWS\\system32\\usmt\\migwiz.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\Java\\jre6\\bin\\java.exe"=
"c:\\Documents and Settings\\Owner\\Local Settings\\Application Data\\Google\\Google Talk Plugin\\googletalkplugin.exe"=
"c:\\allan\\babyftp.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Documents and Settings\\Owner\\Application Data\\Dropbox\\bin\\Dropbox.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Common Files\\Apple\\Apple Application Support\\WebKit2WebProcess.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\Documents and Settings\\Owner\\Application Data\\mjusbsp\\magicJack.exe"=
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3776:UDP"= 3776:UDP:Media Center Extender Service
"3390:TCP"= 3390:TCP:Remote Media Center Experience
.
R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys [7/22/2011 10:27 AM 12880]
R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [7/12/2011 3:55 PM 67664]
R2 !SASCORE;SAS Core Service;c:\program files\SUPERAntiSpyware\SASCore.exe [8/11/2011 5:38 PM 116608]
R2 libusbd;LibUsb-Win32 - Daemon, Version 0.1.10.1;system32\libusbd-nt.exe –> system32\libusbd-nt.exe [?]
R2 UMVPFSrv;UMVPFSrv;c:\program files\Common Files\LogiShrd\LVMVFM\UMVPFSrv.exe [8/19/2011 3:26 AM 450848]
R3 libusb0;LibUsb-Win32 - Kernel Driver, Version 0.1.10.1;c:\windows\system32\drivers\libusb0.sys [1/14/2012 5:06 PM 33792]
S1 MpKsl1d7bbd5e;MpKsl1d7bbd5e;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{2BDFE632-4490-42E3-B60B-2729DA752599}\MpKsl1d7bbd5e.sys –> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{2BDFE632-4490-42E3-B60B-2729DA752599}\MpKsl1d7bbd5e.sys [?]
S3 HTCAND32;HTC Device Driver;c:\windows\system32\Drivers\ANDROIDUSB.sys –> c:\windows\system32\Drivers\ANDROIDUSB.sys [?]
S3 PCIUtil;PCI Utility;\??\c:\docume~1\Owner\LOCALS~1\Temp\PCIUtil.sys –> c:\docume~1\Owner\LOCALS~1\Temp\PCIUtil.sys [?]
S3 pneteth;PdaNet Broadband;c:\windows\system32\drivers\pneteth.sys [10/15/2010 10:27 PM 13312]
S3 WMZuneComm;Zune Windows Mobile Connectivity Service;c:\program files\Zune\WMZuneComm.exe [11/11/2010 1:57 PM 268528]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
QWAVE REG_MULTI_SZ QWAVE
.
Contents of the 'Scheduled Tasks' folder
.
2012-02-16 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2011-06-01 23:57]
.
2012-02-21 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-229652688-3306118827-56669048-1006Core.job
- c:\documents and settings\Owner\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2010-05-16 06:24]
.
2012-02-21 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-229652688-3306118827-56669048-1006UA.job
- c:\documents and settings\Owner\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2010-05-16 06:24]
.
2012-02-21 c:\windows\Tasks\MP Scheduled Scan.job
- c:\program files\Microsoft Security Client\Antimalware\MpCmdRun.exe [2011-04-27 20:39]
.
.
——- Supplementary Scan ——-
.
uInternet Settings,ProxyOverride = *.local
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~4\Office12\EXCEL.EXE/3000
TCP: DhcpNameServer = 192.168.1.1
TCP: Interfaces\{970DBA6D-F618-4FE7-83D3-1423480D9736}: NameServer = 208.67.220.222,208.67.220.220
FF - ProfilePath - c:\documents and settings\Owner\Application Data\Mozilla\Firefox\Profiles\se87x6w3.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.babylon.com/web/{searchTerms}?babsrc=browsersearch&AF=17014
FF - prefs.js: browser.search.selectedEngine - Search the web (Babylon)
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/
FF - prefs.js: keyword.URL - hxxp://search.babylon.com/?babsrc=KW_def&AF=17014&q=
FF - user.js: yahoo.homepage.dontask - true);user_pref(extentions.y2layers.installId, 7f95972f-9a1a-4a3c-8f25-b37bd4bd86f2
FF - user.js: extentions.y2layers.defaultEnableAppsList - Buzzdock,BuzzdockTease,DropDownDeals,BestVideoDownloader,BestVideoDownloader,
.
- - - - ORPHANS REMOVED - - - -
.
BHO-{8A86D350-37AB-410A-8531-7D1363F317B3} - c:\program files\Brand Affinity Technologies\Fantapper Player\\IEInstaller.dll
WebBrowser-{D4027C7F-154A-4066-A1AD-4243D8127440} - (no file)
WebBrowser-{98279C38-DE4B-4BCF-93C9-8EC26069D6F4} - (no file)
HKCU-Run-DW6 - c:\program files\The Weather Channel FW\Desktop\DesktopWeather.exe
SafeBoot-WudfPf
SafeBoot-WudfRd
MSConfigStartUp-EA Core - c:\program files\Electronic Arts\EADM\Core.exe
MSConfigStartUp-SelectRebates - c:\program files\SelectRebates\SelectRebates.exe
AddRemove-{889DF117-14D1-44EE-9F31-C5FB5D47F68B} - c:\docume~1\ALLUSE~1\APPLIC~1\TARMAI~1\{889DF~1\Setup.exe
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2012-02-21 16:11
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes …
.
scanning hidden autostart entries …
.
scanning hidden files …
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————
.
[HKEY_LOCAL_MACHINE\software\Microsoft\Environment*]
"Licence0"="REMOVED"
.
——————— DLLs Loaded Under Running Processes ———————
.
- - - - - - - > 'winlogon.exe'(760)
c:\program files\SUPERAntiSpyware\SASWINLO.DLL
c:\windows\system32\WININET.dll
.
- - - - - - - > 'explorer.exe'(2444)
c:\windows\system32\WININET.dll
c:\program files\AquaSnap\AquaSnap.Hook.dll
c:\documents and settings\Owner\Application Data\Dropbox\bin\DropboxExt.14.dll
c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.6195_x-ww_44262b86\MSVCR80.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
———————— Other Running Processes ————————
.
c:\program files\Microsoft Security Client\Antimalware\MsMpEng.exe
c:\program files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\windows\eHome\ehRecvr.exe
c:\windows\eHome\ehSched.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\windows\system32\libusbd-nt.exe
c:\program files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
c:\windows\ehome\RMSvc.exe
c:\program files\Zune\ZuneBusEnum.exe
c:\windows\ehome\mcrdsvc.exe
c:\windows\system32\dllhost.exe
c:\windows\system32\wscntfy.exe
c:\windows\zHotkey.exe
c:\windows\StartupMonitor.exe
c:\program files\iPod\bin\iPodService.exe
c:\documents and settings\Owner\Application Data\mjusbsp\magicJack.exe
c:\windows\system32\WISPTIS.EXE
.
**************************************************************************
.
Completion time: 2012-02-21 16:20:10 - machine was rebooted
ComboFix-quarantined-files.txt 2012-02-21 22:19
.
Pre-Run: 80,800,145,408 bytes free
Post-Run: 81,830,670,336 bytes free
.
- - End Of File - - F2DA74E9F6911844BE43924AB40D670E
Hello jaeason

Glad to hear Combofix worked this time.

We still have more to do but before we continue, I would like to take a closer look at the following:


  • Please scan the following files


    • Please go to VirusTotal


    • On the page you'll find a "Choose File" button.
    • Click on the Choose File button.
    • In the File Upload window which opens, copy and paste this into the File Name box.


    C:\Documents and Settings\Owner\Local Settings\Application Data\uofsoujsi\kslmyhxtssd.exe


    • Next, click the Open button.
    • Then click the "Send File" button just below.
    • This will scan the file. Please be patient.
    • If you get a message saying File has already been analyzed: click Reanalyze file now.
    • Once scanned, copy and paste the link to the results page into notepad.
    • Repeat the scan for the following file:


    C:\Program Files\I Want This\I Want This.dll

  • Please download SystemLook by JPShortstuff


    • Please download SystemLook by JPShortstuff by clicking here or here and save the file (called SystemLook.exe) to your desktop.
    • Double click SystemLook.exe to run the program.
    • Copy the content of the following codebox into the main textfield:

    :dir
    C:\Documents and Settings\All Users\Application Data\YNAB

    • Click the Look button to start the scan.
    • When finished, a notepad window will open with the results of the scan. Please post this log in your next reply.
    • Note: The log can also be found on your Desktop entitled SystemLook.txt

    Please post the links to the VirusTotal result pages and the systemlook log in your next reply.
Microsoft Security Essentials 'caught' kslmyhxtssd.exe when I went to upload it. I allowed access to the file in the interest of science :)

C:\Documents and Settings\Owner\Local Settings\Application Data\uofsoujsi\kslmyhxtssd.exe
https://www.virustotal.com/file/197bc6af88b…sis/1329868565/


C:\Program Files\I Want This\I Want This.dll
https://www.virustotal.com/file/c8347a4eb7a…sis/1329868720/


SystemLook 30.07.11 by jpshortstuff
Log created at 18:01 on 21/02/2012 by Owner
Administrator - Elevation successful

========== dir ==========

C:\Documents and Settings\All Users\Application Data\YNAB - Parameters: "(none)"

—Files—
LicensedApp.lic –a—- 41 bytes [14:16 08/03/2011] [14:16 08/03/2011]

—Folders—
None found.

-= EOF =-
Hello jaeason

Thank you for the infomation.

Microsoft Security Essentials 'caught' kslmyhxtssd.exe when I went to upload it. I allowed access to the file in the interest of science

:thumbup: It was flagged by aswMBR so I wanted to confirm (there is'nt much doubt that it needs to go).

We'll script out the directory as part of our fix in due course.

As for "I Want This" there is not a great deal of information available on this file.

Did you knowingly install this program?


Please scan the following file with VirusTotal as you did with the others:


C:\Documents and Settings\All Users\Application Data\YNAB\LicensedApp.lic


I have to sleep now so we'll continue in a few hours :)
Hello jaeason

Thank you for the scan data and information about YNAB :)

We need to use Combofix again but this time, we will be running it in a slightly different way:


  • Please work through the following steps


    • Open Notepad (Click on "Start", then on "Run" and type "notepad" (without quotations) in the Open field, then click on "OK").
    • NOTE: Do not Use Wordpad or any other text editor except Notepad or the script will fail.
    • Copy and Paste the text in the quotebox below into the open Notepad window:

      File::
      c:\program files\I Want This\I Want This.dll

      Folder::
      C:\Documents and Settings\Owner\Local Settings\Application Data\uofsoujsi
      c:\documents and settings\Owner\Local Settings\Application Data\I Want This
      c:\program files\I Want This
      c:\program files\Babylon

      Registry::
      [-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{11111111-1111-1111-1111-110011221158}]

      Firefox::
      FF - ProfilePath - c:\documents and settings\Owner\Application Data\Mozilla\Firefox\Profiles\se87x6w3.default\
      FF - prefs.js: browser.search.defaulturl - hxxp://search.babylon.com/web/{searchTerms}?babsrc=browsersearch&AF=17014
      FF - prefs.js: browser.search.selectedEngine - Search the web (Babylon)
      FF - prefs.js: keyword.URL - hxxp://search.babylon.com/?babsrc=KW_def&AF=17014&q=

    • Save this as "CFScript.txt" (including the quotation marks), change the "Save as type" to "All Files" and save it to your desktop.
    • Close any open browsers.
    • Disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.
    • Refering to the picture below, drag CFScript.txt into ComboFix.exe

      [external image: Posted Image]
    • When finished, it shall produce a log for you at C:\ComboFix.txt which I will require in your next reply.
    • Once the log is produced, re-engage your resident anti virus.

  • MalwareBytes AntiMalware:


    • I can see that you have MBAM installed.
    • Double click on your MalwareBytes AntiMalware icon to launch the program.
    • Click on the "Update" tab and then on "Check for Updates".
    • The program will now install the latest Malware definition files.
    • Once complete, click on the "Scanner" tab, select "Perform Quick Scan"and then click on "Scan".
    • Once the program has scanned your computer, a log file will be created in Notepad.
    • Click on "Edit > Select All" then click on "Edit > Copy" to copy the entire contents of the log.


    • If the scan detects any Malware-related objects, make sure that everything is checked, and click "Remove Selected" <– Very Important.
    • When disinfection is completed, a log will open in Notepad and you may be prompted to restart your computer.
    • The log is automatically saved by MBAM and can be viewed by clicking the "Logs" tab.
    • Note: If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts, click OK to either and let MBAM proceed with the disinfection process. If asked to restart your computer, please do so immediately.
    • Come back here to this thread and Paste the log in your next reply.

    Please post the Combofix log and the MBAM log in your next reply, along with a new OTL scan log.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI