This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Trojan:Win32/Sirefer.AB and Trojan :Win64/Sirefef.P [Solved]

15 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Problem is I've been infected with these two trojans.
Sincerely,
Karl

OTL logfile created on: 6/28/2012 3:42:02 PM - Run 1
OTL by OldTimer - Version 3.2.53.0 Folder = C:\Users\Karl\Desktop
64bit- Professional Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7601.17514)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

4.00 Gb Total Physical Memory | 2.47 Gb Available Physical Memory | 61.66% Memory free
8.00 Gb Paging File | 6.29 Gb Available in Paging File | 78.68% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 465.66 Gb Total Space | 397.86 Gb Free Space | 85.44% Space Free | Partition Type: NTFS

Computer Name: KARL-PC | User Name: Karl | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Users\Karl\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Windows\csifcsvc.exe (Thomson Reuters)
PRC - C:\Program Files (x86)\Common Files\Intuit\QuickBooks\QBCFMonitorService.exe (Intuit)
PRC - C:\Program Files (x86)\Common Files\Intuit\DataProtect\QBIDPService.exe (Intuit Inc.)
PRC - C:\Windows\csasvc.exe (Thomson Reuters)
PRC - C:\Windows\twain_32\fjscan32\FiWiaChecker.exe (PFU LIMITED)
PRC - C:\Windows\twain_32\fjscan32\ERG\FTErGuid.exe (PFU LIMITED)
PRC - C:\Windows\twain_32\fjscan32\FjtwMkup.exe (FUJITSU LIMITED)
PRC - C:\Program Files (x86)\Spybot - Search & Destroy\TeaTimer.exe (Safer-Networking Ltd.)
PRC - C:\Windows\twain_32\fjscan32\SOP\FtLnSOP.exe (PFU LIMITED)
PRC - C:\Windows\twain_32\fjscan32\FTPWREVT\FTPWREVT.exe (PFU LIMITED)
PRC - C:\Program Files (x86)\PFU\CardMinder V3.2\CardLauncher.exe (PFU Limited.)
PRC - C:\Windows\twain_32\fjscan32\FJTWMKSV.exe (PFU LIMITED)


========== Modules (No Company Name) ==========

MOD - C:\Program Files (x86)\PFU\CardMinder V3.2\CardPath.dll ()


========== Win32 Services (SafeList) ==========

SRV:64bit: - (NisSrv) – c:\Program Files\Microsoft Security Client\NisSrv.exe (Microsoft Corporation)
SRV:64bit: - (MsMpSvc) – c:\Program Files\Microsoft Security Client\MsMpEng.exe (Microsoft Corporation)
SRV:64bit: - (AMD External Events Utility) – C:\Windows\SysNative\atiesrxx.exe (AMD)
SRV:64bit: - (AppMgmt) – C:\Windows\SysNative\appmgmts.dll (Microsoft Corporation)
SRV - (AdobeFlashPlayerUpdateSvc) – C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe (Adobe Systems Incorporated)
SRV - (FCPrintService) – C:\Windows\csifcsvc.exe (Thomson Reuters)
SRV - (QBCFMonitorService) – C:\Program Files (x86)\Common Files\Intuit\QuickBooks\QBCFMonitorService.exe (Intuit)
SRV - (QBVSS) – C:\Program Files (x86)\Common Files\Intuit\DataProtect\QBIDPService.exe (Intuit Inc.)
SRV - (clr_optimization_v4.0.30319_32) – C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation)
SRV - (CSAPrintService) – C:\Windows\csasvc.exe (Thomson Reuters)
SRV - (QBFCService) – C:\Program Files (x86)\Common Files\Intuit\QuickBooks\FCS\Intuit.QuickBooks.FCS.exe (Intuit Inc.)
SRV - (clr_optimization_v2.0.50727_32) – C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
SRV - (FJTWMKSV) – C:\Windows\twain_32\fjscan32\FJTWMKSV.exe (PFU LIMITED)


========== Driver Services (SafeList) ==========

DRV:64bit: - (NisDrv) – C:\Windows\SysNative\drivers\NisDrvWFP.sys (Microsoft Corporation)
DRV:64bit: - (Fs_Rec) – C:\Windows\SysNative\drivers\fs_rec.sys (Microsoft Corporation)
DRV:64bit: - (atikmdag) – C:\Windows\SysNative\drivers\atikmdag.sys (ATI Technologies Inc.)
DRV:64bit: - (amdkmdag) – C:\Windows\SysNative\drivers\atikmdag.sys (ATI Technologies Inc.)
DRV:64bit: - (amdkmdap) – C:\Windows\SysNative\drivers\atikmpag.sys (Advanced Micro Devices, Inc.)
DRV:64bit: - (amdsata) – C:\Windows\SysNative\drivers\amdsata.sys (Advanced Micro Devices)
DRV:64bit: - (amdxata) – C:\Windows\SysNative\drivers\amdxata.sys (Advanced Micro Devices)
DRV:64bit: - (HpSAMD) – C:\Windows\SysNative\drivers\HpSAMD.sys (Hewlett-Packard Company)
DRV:64bit: - (TsUsbFlt) – C:\Windows\SysNative\drivers\TsUsbFlt.sys (Microsoft Corporation)
DRV:64bit: - (AtiHDAudioService) – C:\Windows\SysNative\drivers\AtihdW76.sys (Advanced Micro Devices)
DRV:64bit: - (RTL8167) – C:\Windows\SysNative\drivers\Rt64win7.sys (Realtek )
DRV:64bit: - (VIAHdAudAddService) – C:\Windows\SysNative\drivers\viahduaa.sys (VIA Technologies, Inc.)
DRV:64bit: - (AtiHdmiService) – C:\Windows\SysNative\drivers\AtiHdmi.sys (ATI Technologies, Inc.)
DRV:64bit: - (MTsensor) – C:\Windows\SysNative\drivers\ASACPI.sys ()
DRV:64bit: - (amdsbs) – C:\Windows\SysNative\drivers\amdsbs.sys (AMD Technologies Inc.)
DRV:64bit: - (LSI_SAS2) – C:\Windows\SysNative\drivers\lsi_sas2.sys (LSI Corporation)
DRV:64bit: - (stexstor) – C:\Windows\SysNative\drivers\stexstor.sys (Promise Technology)
DRV:64bit: - (ebdrv) – C:\Windows\SysNative\drivers\evbda.sys (Broadcom Corporation)
DRV:64bit: - (b06bdrv) – C:\Windows\SysNative\drivers\bxvbda.sys (Broadcom Corporation)
DRV:64bit: - (b57nd60a) – C:\Windows\SysNative\drivers\b57nd60a.sys (Broadcom Corporation)
DRV:64bit: - (hcw85cir) – C:\Windows\SysNative\drivers\hcw85cir.sys (Hauppauge Computer Works, Inc.)
DRV:64bit: - (AtiPcie) AMD PCI Express (3GIO) – C:\Windows\SysNative\drivers\AtiPcie.sys (Advanced Micro Devices Inc.)
DRV:64bit: - (AN983X64) – C:\Windows\SysNative\drivers\an983x64.sys (Infineon Technologies AG)
DRV - (WIMMount) – C:\Windows\SysWOW64\drivers\wimmount.sys (Microsoft Corporation)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE:64bit: - HKLM\..\SearchScopes,DefaultScope = {6A1806CD-94D4-4689-BA73-E35EA1EA9990}
IE:64bit: - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE:64bit: - HKLM\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.com/search?q={searchTerm…mp;sourceid=ie7
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\..\SearchScopes,DefaultScope = {6A1806CD-94D4-4689-BA73-E35EA1EA9990}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKLM\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.com/search?q={searchTerm…mp;sourceid=ie7

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://www.msn.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-us
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 8D FC FE 92 58 95 CB 01 [binary data]
IE - HKCU\..\SearchScopes,DefaultScope = {6A1806CD-94D4-4689-BA73-E35EA1EA9990}
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}…amp;FORM=IE8SRC
IE - HKCU\..\SearchScopes\{4B8C28A7-A9BC-45F8-990D-21499EED643C}: "URL" = http://www.questscan.com/?prt=QstscanPB&am…s={searchTerms}
IE - HKCU\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.com/search?q={searchTerm…1I7GGHP_enUS460
IE - HKCU\..\SearchScopes\{EE8F44DF-6319-4466-BD9D-D72454A5D0C1}: "URL" = http://mp3tubetoolbar.com/?tmp=toolbar_sb_…3e6e90329bbfee7
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0


========== FireFox ==========

FF:64bit: - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF64_10_3_162.dll File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\5.1.10411.0\npctrl.dll ( Microsoft Corporation)
FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files (x86)\Java\jre6\bin\plugin2\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files (x86)\Microsoft Silverlight\5.1.10411.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=8: C:\Program Files (x86)\Google\Update\1.2.183.39\npGoogleOneClick8.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\Adobe Acrobat: C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Air\nppdf32.dll (Adobe Systems Inc.)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Browser\WCFirefoxExtn [2012/04/12 09:58:14 | 000,000,000 | —D | M]


O1 HOSTS File: ([2011/12/23 09:07:32 | 000,001,395 | RHS- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O1 - Hosts: 69.72.252.254 www.google-analytics.com.
O1 - Hosts: 69.72.252.254 ad-emea.doubleclick.net.
O1 - Hosts: 69.72.252.254 www.statcounter.com.
O1 - Hosts: 184.95.41.155 www.google-analytics.com.
O1 - Hosts: 184.95.41.155 ad-emea.doubleclick.net.
O1 - Hosts: 184.95.41.155 www.statcounter.com.
O2:64bit: - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
O2:64bit: - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.7.7018.1622\swg64.dll (Google Inc.)
O2 - BHO: (Spybot-S&D IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files (x86)\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O2 - BHO: (Java™ Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (Adobe PDF Conversion Toolbar Helper) - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files (x86)\Google\GoogleToolbarNotifier\5.7.7018.1622\swg.dll (Google Inc.)
O2 - BHO: (SmartSelect Class) - {F4971EE7-DAA0-4053-9964-665D8EE6A077} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O3:64bit: - HKLM\..\Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (Mp3Tube Toolbar) - {46897C77-E7A6-4c33-BFFB-E9C2E2718942} - C:\Program Files (x86)\Mp3Tube Toolbar\mp3tubetb.DLL (Mp3Tube Toolbar)
O3 - HKLM\..\Toolbar: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O3:64bit: - HKCU\..\Toolbar\WebBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (Mp3Tube Toolbar) - {46897C77-E7A6-4C33-BFFB-E9C2E2718942} - C:\Program Files (x86)\Mp3Tube Toolbar\mp3tubetb.DLL (Mp3Tube Toolbar)
O3 - HKCU\..\Toolbar\WebBrowser: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O4:64bit: - HKLM..\Run: [MSC] c:\Program Files\Microsoft Security Client\msseces.exe (Microsoft Corporation)
O4 - HKLM..\Run: [] File not found
O4 - HKLM..\Run: [Acrobat Assistant 8.0] "C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe" File not found
O4 - HKLM..\Run: [Adobe Acrobat Speed Launcher] C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Acrobat_sl.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [FiWIA Service Checker] C:\Windows\twain_32\fjscan32\FiWiaChecker.exe (PFU LIMITED)
O4 - HKLM..\Run: [FJTWAIN Setup] C:\Windows\Twain_32\fjscan32\FjtwMkup.exe (FUJITSU LIMITED)
O4 - HKLM..\Run: [FtLnSOP_setup] C:\Windows\twain_32\fjscan32\SOP\FtLnSOP.exe (PFU LIMITED)
O4 - HKLM..\Run: [FTPWRENV] C:\Windows\twain_32\fjscan32\FTPWREVT\FTPWREVT.exe (PFU LIMITED)
O4 - HKLM..\Run: [Intuit SyncManager] C:\Program Files (x86)\Common Files\Intuit\Sync\IntuitSyncManager.exe (Intuit Inc. All rights reserved.)
O4 - HKCU..\Run: [SpybotSD TeaTimer] C:\Program Files (x86)\Spybot - Search & Destroy\TeaTimer.exe (Safer-Networking Ltd.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O8:64bit: - Extra context menu item: Append Link Target to Existing PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8:64bit: - Extra context menu item: Append to Existing PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8:64bit: - Extra context menu item: Convert Link Target to Adobe PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8:64bit: - Extra context menu item: Convert to Adobe PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Append Link Target to Existing PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Append to Existing PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert Link Target to Adobe PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert to Adobe PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O9 - Extra 'Tools' menuitem : Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files (x86)\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000001 - mmswsock.dll File not found
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000002 - mmswsock.dll File not found
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000003 - mmswsock.dll File not found
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000004 - mmswsock.dll File not found
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000005 - mmswsock.dll File not found
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000006 - mmswsock.dll File not found
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000007 - mmswsock.dll File not found
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000008 - mmswsock.dll File not found
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000009 - mmswsock.dll File not found
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000010 - mmswsock.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - %SystemRoot%\System32\winrnr.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - %SystemRoot%\System32\winrnr.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - %SystemRoot%\System32\winrnr.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - %SystemRoot%\System32\winrnr.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - %SystemRoot%\System32\winrnr.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000006 - %SystemRoot%\System32\winrnr.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000007 - %SystemRoot%\System32\winrnr.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000008 - %SystemRoot%\System32\winrnr.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000009 - %SystemRoot%\System32\winrnr.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000010 - %SystemRoot%\System32\winrnr.dll File not found
O1364bit: - gopher Prefix: missing
O13 - gopher Prefix: missing
O16:64bit: - DPF: {4871A87A-BFDD-4106-8153-FFDE2BAC2967} http://dlm.tools.akamai.com/dlmanager/vers…x64-2.2.6.0.cab (DLM Control)
O16:64bit: - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} http://download.divx.com/player/DivXBrowserPlugin.cab (Reg Error: Key error.)
O16:64bit: - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_23)
O16:64bit: - DPF: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_23)
O16:64bit: - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_23)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_31)
O16 - DPF: {CAFEEFAC-0016-0000-0031-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_31)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_31)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = [removed] [removed]
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{0EBFCCB0-C442-4059-B6BB-CF231475AA84}: DhcpNameServer = [removed] [removed]
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{7D372210-BAD2-4B02-92F2-9B87EC97E0A7}: NameServer = 209.18.47.61,209.18.47.62
O18:64bit: - Protocol\Handler\intu-help-qb2 - No CLSID value found
O18:64bit: - Protocol\Handler\intu-help-qb3 - No CLSID value found
O18:64bit: - Protocol\Handler\intu-help-qb4 - No CLSID value found
O18:64bit: - Protocol\Handler\intu-help-qb5 - No CLSID value found
O18:64bit: - Protocol\Handler\ipp - No CLSID value found
O18:64bit: - Protocol\Handler\ipp\0x00000001 - No CLSID value found
O18:64bit: - Protocol\Handler\msdaipp - No CLSID value found
O18:64bit: - Protocol\Handler\msdaipp\0x00000001 - No CLSID value found
O18:64bit: - Protocol\Handler\msdaipp\oledb - No CLSID value found
O18:64bit: - Protocol\Handler\ms-help - No CLSID value found
O18:64bit: - Protocol\Handler\qbwc - No CLSID value found
O18 - Protocol\Handler\intu-help-qb2 {84D77A00-41B5-4b8b-8ADF-86486D72E749} - C:\Program Files (x86)\Intuit\QuickBooks 2009\HelpAsyncPluggableProtocol.dll (Intuit, Inc.)
O18 - Protocol\Handler\intu-help-qb3 {c5e479ea-0a65-4b05-8c6c-2fc8cc682eb4} - C:\Program Files (x86)\Intuit\QuickBooks 2010\HelpAsyncPluggableProtocol.dll (Intuit, Inc.)
O18 - Protocol\Handler\intu-help-qb4 {ACE22922-D07C-4860-B51B-8CF472FEC2CB} - C:\Program Files (x86)\Intuit\QuickBooks Enterprise Solutions 11.0\HelpAsyncPluggableProtocol.dll (Intuit, Inc.)
O18 - Protocol\Handler\intu-help-qb5 {867FCB77-9823-4cd6-8210-D85F968D466F} - C:\Program Files (x86)\Intuit\QuickBooks 2012\HelpAsyncPluggableProtocol.dll (Intuit, Inc.)
O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11D1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11D1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11D1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysNative\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (userinit.exe) - C:\Windows\SysWow64\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *)
O35:64bit: - HKLM\..comfile [open] – "%1" %*
O35:64bit: - HKLM\..exefile [open] – "%1" %*
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37:64bit: - HKLM\…com [@ = comfile] – "%1" %*
O37:64bit: - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKCU\…exe [@ = exefile] – Reg Error: Key error. File not found
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=consrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)

NetSvcs:64bit: AppMgmt - C:\Windows\SysNative\appmgmts.dll (Microsoft Corporation)

Drivers32:64bit: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.l3acm - C:\Windows\SysWOW64\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: vidc.cvid - C:\Windows\SysWow64\iccvid.dll (Radius Inc.)

CREATERESTOREPOINT
Restore point Set: OTL Restore Point

========== Files/Folders - Created Within 30 Days ==========

[2012/06/28 15:39:22 | 000,596,992 | —- | C] (OldTimer Tools) – C:\Users\Karl\Desktop\OTL.exe
[2012/06/28 13:32:40 | 000,000,000 | —D | C] – C:\Windows\SysNative\MpEngineStore
[2012/06/28 11:29:36 | 000,050,392 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\drivers\aqjbutgu.sys
[2012/06/28 11:22:55 | 063,220,256 | —- | C] (Microsoft Corporation) – C:\Users\Karl\Desktop\mpam-fex64.exe
[2012/06/28 08:10:40 | 000,000,000 | —D | C] – C:\Program Files (x86)\Microsoft Security Client
[2012/06/28 08:10:34 | 000,000,000 | —D | C] – C:\Program Files\Microsoft Security Client
[2012/06/28 08:05:47 | 002,622,464 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wucltux.dll
[2012/06/28 08:05:47 | 000,057,880 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wuauclt.exe
[2012/06/28 08:05:47 | 000,044,056 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wups2.dll
[2012/06/28 08:05:39 | 000,701,976 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wuapi.dll
[2012/06/28 08:05:39 | 000,099,840 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wudriver.dll
[2012/06/28 08:05:39 | 000,038,424 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wups.dll
[2012/06/28 08:05:24 | 000,186,752 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wuwebv.dll
[2012/06/28 08:05:24 | 000,036,864 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wuapp.exe
[2012/06/20 08:22:21 | 001,388,544 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\temp.028
[2012/06/20 08:22:21 | 001,118,720 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\temp.026
[2012/06/20 08:22:21 | 000,044,032 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\temp.027
[2012/06/20 08:22:21 | 000,022,288 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\temp.029
[2012/06/20 08:22:07 | 000,995,383 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\temp.025
[2012/06/20 08:22:07 | 000,401,462 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\temp.023
[2012/06/20 08:22:07 | 000,295,000 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\temp.024
[2012/06/19 14:38:02 | 000,000,000 | —D | C] – C:\Users\Karl\Desktop\Budget Finance
[2012/06/13 08:07:44 | 000,918,016 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\jscript.dll
[2012/06/13 08:07:43 | 000,716,800 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\jscript.dll
[2012/06/13 08:07:35 | 000,735,744 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\msfeeds.dll
[2012/06/13 08:07:34 | 000,097,792 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\mshtmled.dll
[2012/06/13 08:07:34 | 000,067,584 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\mshtmled.dll
[2012/06/13 08:07:33 | 000,247,808 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ieui.dll
[2012/06/13 08:07:33 | 000,176,640 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ieui.dll
[2012/06/13 08:07:32 | 000,134,144 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\url.dll
[2012/06/13 08:07:32 | 000,132,096 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\url.dll
[2012/06/13 08:07:26 | 000,149,504 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\rdpcorekmts.dll
[2012/06/13 08:07:26 | 000,077,312 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\rdpwsx.dll
[2012/06/13 08:07:26 | 000,009,216 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\rdrmemptylst.exe
[2012/06/13 08:07:18 | 005,559,664 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ntoskrnl.exe
[2012/06/13 08:07:16 | 003,913,072 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ntoskrnl.exe
[2012/06/13 08:07:15 | 003,968,368 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ntkrnlpa.exe
[2012/06/13 08:07:07 | 001,462,272 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\crypt32.dll
[2012/06/13 08:07:06 | 000,140,288 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\cryptnet.dll
[2012/06/13 08:07:03 | 003,216,384 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\msi.dll
[2 C:\Users\Karl\AppData\Local\*.tmp files -> C:\Users\Karl\AppData\Local\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2012/06/28 15:47:10 | 000,050,392 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\drivers\tafeffsm.sys
[2012/06/28 15:42:47 | 000,014,848 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2012/06/28 15:42:47 | 000,014,848 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2012/06/28 15:40:06 | 000,796,026 | —- | M] () – C:\Windows\SysNative\PerfStringBackup.INI
[2012/06/28 15:40:06 | 000,671,192 | —- | M] () – C:\Windows\SysNative\perfh009.dat
[2012/06/28 15:40:06 | 000,126,278 | —- | M] () – C:\Windows\SysNative\perfc009.dat
[2012/06/28 15:39:25 | 000,596,992 | —- | M] (OldTimer Tools) – C:\Users\Karl\Desktop\OTL.exe
[2012/06/28 15:35:18 | 000,000,890 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2012/06/28 15:35:05 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2012/06/28 15:34:55 | 3220,574,208 | -HS- | M] () – C:\hiberfil.sys
[2012/06/28 11:29:37 | 000,050,392 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\drivers\aqjbutgu.sys
[2012/06/28 11:23:13 | 063,220,256 | —- | M] (Microsoft Corporation) – C:\Users\Karl\Desktop\mpam-fex64.exe
[2012/06/28 11:23:00 | 000,000,830 | —- | M] () – C:\Windows\tasks\Adobe Flash Player Updater.job
[2012/06/28 10:59:00 | 000,000,894 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2012/06/28 08:11:01 | 000,001,945 | —- | M] () – C:\Windows\epplauncher.mif
[2012/06/28 08:10:43 | 000,809,684 | —- | M] () – C:\Windows\SysWow64\PerfStringBackup.INI
[2012/06/27 16:24:13 | 000,000,000 | —- | M] () – C:\Users\Karl\AppData\Local\{1CAC96A0-425A-45FE-A3DE-A7427F550A50}
[2012/06/27 16:13:19 | 000,003,424 | —- | M] () – C:\bootsqm.dat
[2012/06/27 15:38:05 | 000,000,256 | -H– | M] () – C:\ProgramData\XhbXwlbhQSr92x
[2012/06/27 15:34:41 | 000,000,136 | -H– | M] () – C:\ProgramData\-XhbXwlbhQSr92xr
[2012/06/27 15:34:41 | 000,000,000 | -H– | M] () – C:\ProgramData\-XhbXwlbhQSr92x
[2012/06/20 08:28:06 | 000,002,469 | —- | M] () – C:\Users\Public\Desktop\Accounting CS.lnk
[2012/06/20 08:22:07 | 000,001,728 | —- | M] () – C:\Users\Karl\Desktop\Creative Solutions Accounting.lnk
[2012/06/19 16:56:38 | 000,000,000 | -H– | M] () – C:\Users\Karl\AppData\Local\{CB688969-CB1E-4969-83D1-D09119E78324}
[2012/06/14 07:57:07 | 000,367,000 | —- | M] () – C:\Windows\SysNative\FNTCACHE.DAT
[2012/06/12 07:51:59 | 000,426,184 | —- | M] (Adobe Systems Incorporated) – C:\Windows\SysWow64\FlashPlayerApp.exe
[2012/06/12 07:51:59 | 000,070,344 | —- | M] (Adobe Systems Incorporated) – C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
[2012/06/06 07:52:59 | 000,002,479 | —- | M] () – C:\Users\Public\Desktop\Practice CS 2012.1.lnk
[2012/06/02 17:19:46 | 000,038,424 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\wups.dll
[2012/06/02 17:19:42 | 000,057,880 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\wuauclt.exe
[2012/06/02 17:19:42 | 000,044,056 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\wups2.dll
[2012/06/02 17:19:23 | 000,701,976 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\wuapi.dll
[2012/06/02 17:15:31 | 002,622,464 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\wucltux.dll
[2012/06/02 17:15:08 | 000,099,840 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\wudriver.dll
[2012/06/02 15:19:42 | 000,186,752 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\wuwebv.dll
[2012/06/02 15:15:12 | 000,036,864 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\wuapp.exe
[2 C:\Users\Karl\AppData\Local\*.tmp files -> C:\Users\Karl\AppData\Local\*.tmp -> ]

========== Files Created - No Company Name ==========

[2012/06/28 08:11:01 | 000,001,945 | —- | C] () – C:\Windows\epplauncher.mif
[2012/06/28 08:10:49 | 000,001,915 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Security Essentials.lnk
[2012/06/27 16:23:56 | 000,000,000 | —- | C] () – C:\Users\Karl\AppData\Local\{1CAC96A0-425A-45FE-A3DE-A7427F550A50}
[2012/06/27 16:13:19 | 000,003,424 | —- | C] () – C:\bootsqm.dat
[2012/06/27 15:32:29 | 000,001,296 | -H– | C] () – C:\Users\Karl\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OneNote 2010 Screen Clipper and Launcher.lnk
[2012/06/27 15:20:39 | 000,000,136 | -H– | C] () – C:\ProgramData\-XhbXwlbhQSr92xr
[2012/06/27 15:20:38 | 000,000,000 | -H– | C] () – C:\ProgramData\-XhbXwlbhQSr92x
[2012/06/27 15:18:15 | 000,000,256 | -H– | C] () – C:\ProgramData\XhbXwlbhQSr92x
[2012/06/20 08:28:06 | 000,002,469 | —- | C] () – C:\Users\Public\Desktop\Accounting CS.lnk
[2012/06/19 16:56:38 | 000,000,000 | -H– | C] () – C:\Users\Karl\AppData\Local\{CB688969-CB1E-4969-83D1-D09119E78324}
[2012/06/06 07:52:59 | 000,002,479 | —- | C] () – C:\Users\Public\Desktop\Practice CS 2012.1.lnk
[2012/01/09 12:52:06 | 000,000,257 | —- | C] () – C:\Windows\pixcache.ini
[2012/01/09 12:52:05 | 000,000,000 | —- | C] () – C:\Windows\SetScan.ini
[2012/01/09 12:33:28 | 000,000,712 | R— | C] () – C:\Windows\FJTWSTI.INI
[2012/01/06 11:54:25 | 000,003,155 | —- | C] () – C:\Windows\SysWow64\atipblag.dat
[2011/12/28 16:23:48 | 000,009,616 | —- | C] () – C:\Users\Karl\AppData\Local\k6480ph3847nj8n3r544876sfkvmt3wru4ff12
[2011/12/28 16:23:48 | 000,009,616 | —- | C] () – C:\ProgramData\k6480ph3847nj8n3r544876sfkvmt3wru4ff12
[2011/12/28 16:23:43 | 000,346,112 | —- | C] () – C:\Users\Karl\AppData\Local\ksv.exe
[2011/12/22 13:42:37 | 000,009,788 | -HS- | C] () – C:\Users\Karl\AppData\Local\143306s0j286x770y614f0jar4x1
[2011/12/22 13:42:37 | 000,009,788 | -HS- | C] () – C:\ProgramData\143306s0j286x770y614f0jar4x1
[2011/12/22 13:42:32 | 000,304,640 | —- | C] () – C:\Users\Karl\AppData\Local\fno.exe
[2011/08/19 21:26:28 | 000,000,186 | —- | C] () – C:\Windows\SysWow64\Gsw32.exe.config
[2011/08/12 16:11:18 | 000,000,092 | -H– | C] () – C:\Users\Karl\AppData\Local\fusioncache.dat
[2011/06/21 16:44:39 | 000,000,208 | —- | C] () – C:\Windows\ODBCINST.INI
[2011/03/07 14:55:52 | 000,809,684 | —- | C] () – C:\Windows\SysWow64\PerfStringBackup.INI
[2011/01/05 10:10:44 | 000,000,384 | —- | C] () – C:\Users\Karl\CJB Farms, Inc.QBW.DSN
[2011/01/05 10:10:44 | 000,000,334 | -H– | C] () – C:\Users\Karl\CJB Farms, Inc.QBW.ND
[2011/01/05 10:09:22 | 003,735,552 | RH– | C] () – C:\Users\Karl\CJB Farms, Inc.QBW.TLG
[2011/01/05 10:09:21 | 020,557,824 | RH– | C] () – C:\Users\Karl\CJB Farms, Inc.QBW
[2011/01/05 09:44:03 | 000,000,384 | —- | C] () – C:\Users\Karl\B5 Land and Cattle Company.QBW.DSN
[2011/01/05 09:44:03 | 000,000,346 | -H– | C] () – C:\Users\Karl\B5 Land and Cattle Company.QBW.ND
[2011/01/05 09:42:54 | 002,359,296 | RH– | C] () – C:\Users\Karl\B5 Land and Cattle Company.QBW.TLG
[2011/01/05 09:42:53 | 009,875,456 | RH– | C] () – C:\Users\Karl\B5 Land and Cattle Company.QBW
[2010/12/22 11:01:55 | 005,771,264 | -H– | C] () – C:\Users\Karl\B5 Land and Cattle Company 12-16-10 (Backup Dec 22,2010 10 01 AM).QBB
[2010/12/22 10:00:14 | 000,000,095 | —- | C] () – C:\Windows\QBChanUtil_Trigger.ini
[2010/12/06 15:03:59 | 000,000,490 | —- | C] () – C:\Windows\ODBC.INI
[2010/12/06 10:38:32 | 000,000,000 | —- | C] () – C:\Windows\ativpsrm.bin
[2010/12/06 10:35:41 | 000,024,576 | —- | C] () – C:\Windows\SysWow64\AsIO.dll
[2010/12/06 10:35:41 | 000,013,440 | —- | C] () – C:\Windows\SysWow64\drivers\AsIO.sys
[2010/12/06 10:12:18 | 000,039,266 | —- | C] () – C:\Windows\Ascd_log.ini
[2010/12/06 10:11:26 | 000,001,769 | —- | C] () – C:\Windows\Language_trs.ini
[2010/12/06 10:11:21 | 000,031,453 | —- | C] () – C:\Windows\Ascd_tmp.ini

========== LOP Check ==========

[2012/06/27 19:31:29 | 000,000,000 | —D | M] – C:\Users\Karl\AppData\Roaming\Fujitsu
[2010/12/06 11:37:32 | 000,000,000 | -H-D | M] – C:\Users\Karl\AppData\Roaming\Leadertech
[2012/06/27 19:31:37 | 000,000,000 | —D | M] – C:\Users\Karl\AppData\Roaming\PFU
[2012/06/05 10:14:47 | 000,000,000 | -H-D | M] – C:\Users\Karl\AppData\Roaming\PrimoPDF
[2012/06/27 19:34:09 | 000,000,000 | —D | M] – C:\Users\Karl\AppData\Roaming\RFFlow
[2011/06/15 10:29:40 | 000,000,000 | -H-D | M] – C:\Users\Karl\AppData\Roaming\webex
[2012/02/21 09:44:10 | 000,032,602 | —- | M] () – C:\Windows\Tasks\SCHEDLGU.TXT

========== Purity Check ==========



========== Custom Scans ==========

< %SYSTEMDRIVE%\*.* >
[2012/06/27 16:13:19 | 000,003,424 | —- | M] () – C:\bootsqm.dat
[2012/06/28 15:34:55 | 3220,574,208 | -HS- | M] () – C:\hiberfil.sys
[2006/12/02 00:37:14 | 000,904,704 | —- | M] (Microsoft Corporation) – C:\msdia80.dll
[2012/06/28 15:35:00 | 4294,103,040 | -HS- | M] () – C:\pagefile.sys

< %systemroot%\Fonts\*.com >
[2009/07/14 00:32:31 | 000,026,040 | —- | M] () – C:\Windows\Fonts\GlobalMonospace.CompositeFont
[2009/07/14 00:32:31 | 000,026,489 | —- | M] () – C:\Windows\Fonts\GlobalSansSerif.CompositeFont
[2009/07/14 00:32:31 | 000,029,779 | —- | M] () – C:\Windows\Fonts\GlobalSerif.CompositeFont
[2009/07/14 00:32:31 | 000,043,318 | —- | M] () – C:\Windows\Fonts\GlobalUserInterface.CompositeFont

< %systemroot%\Fonts\*.dll >

< %systemroot%\Fonts\*.ini >
[2009/06/10 15:49:50 | 000,000,065 | —- | M] () – C:\Windows\Fonts\desktop.ini

< %systemroot%\Fonts\*.ini2 >

< %systemroot%\Fonts\*.exe >

< %systemroot%\system32\spool\prtprocs\w32x86\*.* >

< %systemroot%\REPAIR\*.bak1 >

< %systemroot%\REPAIR\*.ini >

< %systemroot%\system32\*.jpg >

< %systemroot%\*.jpg >

< %systemroot%\*.png >

< %systemroot%\*.scr >

< %systemroot%\*._sy >

< %APPDATA%\Adobe\Update\*.* >

< %ALLUSERSPROFILE%\Favorites\*.* >

< %APPDATA%\Microsoft\*.* >

< %PROGRAMFILES%\*.* >
[2009/07/13 23:54:24 | 000,000,174 | -HS- | M] () – C:\Program Files (x86)\desktop.ini

< %APPDATA%\Update\*.* >

< %systemroot%\*. /mp /s >

< %systemroot%\System32\config\*.sav >

< %PROGRAMFILES%\bak. /s >

< %systemroot%\system32\bak. /s >

< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >

< %systemroot%\system32\config\systemprofile\*.dat /x >

< %systemroot%\*.config >

< %systemroot%\system32\*.db >

< %PROGRAMFILES%\Internet Explorer\*.dat >

< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2010/12/06 10:15:53 | 000,000,221 | -HS- | M] () – C:\Users\Karl\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\desktop.ini

< %USERPROFILE%\Desktop\*.exe >
[2011/09/21 13:55:56 | 487,666,616 | —- | M] (Adobe Systems Incorporated) – C:\Users\Karl\Desktop\AcrobatPro_10_Web_WWEFD.exe
[2012/06/28 11:23:13 | 063,220,256 | —- | M] (Microsoft Corporation) – C:\Users\Karl\Desktop\mpam-fex64.exe
[2012/06/28 15:39:25 | 000,596,992 | —- | M] (OldTimer Tools) – C:\Users\Karl\Desktop\OTL.exe

< %PROGRAMFILES%\Common Files\*.* >

< %systemroot%\*.src >

< %systemroot%\install\*.* >

< %systemroot%\system32\DLL\*.* >

< %systemroot%\system32\HelpFiles\*.* >

< %systemroot%\system32\rundll\*.* >

< %systemroot%\winn32\*.* >

< %systemroot%\Java\*.* >

< %systemroot%\system32\test\*.* >

< %systemroot%\system32\Rundll32\*.* >

< %systemroot%\AppPatch\Custom\*.* >

< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >

< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >

< >

========== Hard Links - Junction Points - Mount Points - Symbolic Links ==========
[C:\Windows\system64] -> \systemroot\system32 -> Mount Point

< End of report >


OTL Extras logfile created on: 6/28/2012 3:42:02 PM - Run 1
OTL by OldTimer - Version 3.2.53.0 Folder = C:\Users\Karl\Desktop
64bit- Professional Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7601.17514)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

4.00 Gb Total Physical Memory | 2.47 Gb Available Physical Memory | 61.66% Memory free
8.00 Gb Paging File | 6.29 Gb Available in Paging File | 78.68% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 465.66 Gb Total Space | 397.86 Gb Free Space | 85.44% Space Free | Partition Type: NTFS

Computer Name: KARL-PC | User Name: Karl | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.url[@ = InternetShortcut] – C:\Windows\SysNative\rundll32.exe (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – C:\Windows\SysWow64\control.exe (Microsoft Corporation)

========== Shell Spawning ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
InternetShortcut [open] – "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\ieframe.dll",OpenURL %l (Microsoft Corporation)
InternetShortcut [print] – "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] – Reg Error: Value error.
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] – Reg Error: Value error.
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 0

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"VistaSp1" = 28 4D B2 76 41 04 CA 01 [binary data]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

========== Authorized Applications List ==========


========== Vista Active Open Ports Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{05BEDE1D-6E8E-4F19-B916-9BD4A6BB9420}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{07DB1477-F286-458D-A4F2-9EE824EF98FF}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{0F332172-E290-454A-8CB7-3F4B0D701BE9}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe |
"{223FC365-CB60-438D-AB58-24704D36F2D3}" = lport=445 | protocol=6 | dir=in | app=system |
"{418D2541-1B96-497F-91D4-B51E236231B9}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{45148F05-DC69-4302-9A38-4CF0293B7717}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{4B1EFD3C-6C14-443D-995C-58B3FE28537A}" = rport=445 | protocol=6 | dir=out | app=system |
"{5E8C88BB-865E-4836-AD2F-0B3BEB5E100B}" = lport=3702 | protocol=17 | dir=in | svc=fdphost | app=%systemroot%\system32\svchost.exe |
"{660AFE77-E24F-42CF-B2E6-3F3F9349A2EF}" = rport=139 | protocol=6 | dir=out | app=system |
"{668C183C-052F-49E0-946A-07F3B1906CD8}" = lport=137 | protocol=17 | dir=in | app=system |
"{67D2C6AC-34A1-4DD2-8C1A-6875CC517E9D}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{694ADE0D-F15F-4052-A6C1-D6F84D99EFFE}" = lport=138 | protocol=17 | dir=in | app=system |
"{7169E762-9F76-48B3-AE26-1AEDD4256C00}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{71C4B3C1-88E7-4BB2-923F-2D73F7ADA7E2}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=@firewallapi.dll,-28539 |
"{97BCFCFE-70CA-49E8-A31A-4630C98CC87F}" = lport=139 | protocol=6 | dir=in | app=system |
"{A4DD5C7B-D04C-4FF0-AFF0-D4C94F4B8AF7}" = rport=3702 | protocol=17 | dir=out | svc=fdrespub | app=%systemroot%\system32\svchost.exe |
"{A9FA2BC1-A85F-4225-B794-3A526422342F}" = rport=3702 | protocol=17 | dir=out | svc=fdphost | app=%systemroot%\system32\svchost.exe |
"{AAEE13D0-92AE-409D-9998-D5ABB59A4220}" = lport=6004 | protocol=17 | dir=in | app=c:\program files (x86)\microsoft office\office14\outlook.exe |
"{B811C3D2-C3FE-4CB4-97D9-02EABA3FB04E}" = lport=3702 | protocol=17 | dir=in | svc=fdrespub | app=%systemroot%\system32\svchost.exe |
"{CC8B2FDF-608E-4729-A892-A4855DCE0F4A}" = rport=138 | protocol=17 | dir=out | app=system |
"{D58EA692-5EE8-4A85-B007-04283C09A005}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{E3BE1BB7-4D05-420A-A2A1-5F6B422FB6BC}" = rport=137 | protocol=17 | dir=out | app=system |
"{E6F809A6-44B2-472C-B784-B348B8B4EF16}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe |

========== Vista Active Application Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{0D08AEA3-2C25-4BAA-8042-9AE2F42A80C7}" = protocol=1 | dir=in | name=@firewallapi.dll,-28543 |
"{42952034-8061-4FE9-B07F-4496F3C3C9EA}" = protocol=58 | dir=out | name=@firewallapi.dll,-28546 |
"{5CF72601-5BFD-44B7-9DBF-EB7715ED8B51}" = protocol=58 | dir=in | name=@firewallapi.dll,-28545 |
"{5DC6529C-EBA3-484B-8AEF-444AE2EE9D73}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe |
"{66CAEEBA-D726-4C2C-B3CE-F19749CC33A8}" = protocol=6 | dir=in | app=c:\program files (x86)\microsoft office\office14\onenote.exe |
"{8F63A96E-FC9A-4A4D-9E7F-A962E2BF0699}" = protocol=17 | dir=in | app=c:\program files (x86)\microsoft office\office14\onenote.exe |
"{97D32749-C470-4785-B32C-CC08091FB244}" = protocol=1 | dir=out | name=@firewallapi.dll,-28544 |
"TCP Query User{AB05B6FA-2477-4D7C-8C5C-46B69EEE85C3}C:\program files (x86)\google\google earth\client\googleearth.exe" = protocol=6 | dir=in | app=c:\program files (x86)\google\google earth\client\googleearth.exe |
"TCP Query User{F07CB558-9B02-47A3-A91F-0436B5F765E7}C:\program files (x86)\google\google earth\client\googleearth.exe" = protocol=6 | dir=in | app=c:\program files (x86)\google\google earth\client\googleearth.exe |
"UDP Query User{B638367F-6166-4889-88EA-54910CFCE85C}C:\program files (x86)\google\google earth\client\googleearth.exe" = protocol=17 | dir=in | app=c:\program files (x86)\google\google earth\client\googleearth.exe |
"UDP Query User{C0F4C45D-6410-4ED7-99B8-7FA7B95AC872}C:\program files (x86)\google\google earth\client\googleearth.exe" = protocol=17 | dir=in | app=c:\program files (x86)\google\google earth\client\googleearth.exe |

========== HKEY_LOCAL_MACHINE Uninstall List ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{071c9b48-7c32-4621-a0ac-3f809523288f}" = Microsoft Visual C++ 2005 Redistributable (x64)
"{1F4DF73B-1834-18B3-21AF-A511CE493480}" = ccc-utility64
"{26A24AE4-039D-4CA4-87B4-2F86416023FF}" = Java™ 6 Update 23 (64-bit)
"{824A8A6E-476F-E791-2478-0DBAEDADDAC1}" = ATI Catalyst Install Manager
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8E34682C-8118-31F1-BC4C-98CD9675E1C2}" = Microsoft .NET Framework 4 Extended
"{90140000-002A-0000-1000-0000000FF1CE}" = Microsoft Office Office 64-bit Components 2010
"{90140000-002A-0409-1000-0000000FF1CE}" = Microsoft Office Shared 64-bit MUI (English) 2010
"{90140000-0116-0409-1000-0000000FF1CE}" = Microsoft Office Shared 64-bit Setup Metadata MUI (English) 2010
"{9D046B26-7978-47CD-91E6-AC3C1DFBC3D0}" = Microsoft Security Client
"{aac9fcc4-dd9e-4add-901c-b5496a07ab2e}" = Microsoft Visual C++ 2005 Redistributable (x64) - KB2467175
"{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}" = Microsoft Visual C++ 2005 Redistributable (x64)
"{B6E3757B-5E77-3915-866A-CCFC4B8D194C}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x64 8.0.50727.4053
"{C3600AE6-93A0-3DB7-B7AA-45BD58F133B5}" = Microsoft Visual Studio 2010 Tools for Office Runtime (x64)
"{CFF38A17-4A0B-D116-625A-CC1D8305EA6C}" = ATI AVIVO64 Codecs
"{DA5E371C-6333-3D8A-93A4-6FD5B20BCC6E}" = Microsoft Visual C++ 2010 x64 Redistributable - 10.0.30319
"{EB6C7429-626E-96E9-D25F-D02A44C8FF1E}" = AMD Drag and Drop Transcoding
"{F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4}" = Microsoft .NET Framework 4 Client Profile
"{F7925A6B-1868-A1E9-90CD-62A22673A8DB}" = ccc-utility64
"Adobe Flash Player ActiveX 64" = Adobe Flash Player 10 ActiveX 64-bit
"Adobe Flash Player Plugin 64" = Adobe Flash Player 10 Plugin 64-bit
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"Microsoft .NET Framework 4 Extended" = Microsoft .NET Framework 4 Extended
"Microsoft Security Client" = Microsoft Security Essentials
"Microsoft Visual Studio 2010 Tools for Office Runtime (x64)" = Microsoft Visual Studio 2010 Tools for Office Runtime (x64)

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}" = Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148
"{02C8D869-16E6-47FB-AC73-A98E99E0982D}" = Scan to Microsoft SharePoint
"{06A9E630-DBA6-4D92-9DE7-A235AA6496C7}" = QuickBooks
"{0700E22B-A423-40A5-BD20-04BF618CA0F9}" = QuickBooks Premier: Accountant Edition 2010
"{07CF5F78-B6B6-397F-42B8-8674DDEBF622}" = CCC Help Spanish
"{088E4B32-7108-5CBB-A3FB-EE2BF2368927}" = CCC Help Russian
"{08DAF727-49D2-F499-EDAB-DCE69167970C}" = CCC Help Chinese Standard
"{0BB5D4C7-1FB7-0AAB-374F-9815C308E5C0}" = CCC Help Thai
"{0DB06245-87D5-4D84-4636-1AE25CAB135E}" = CCC Help Czech
"{11E0AC7D-6823-4F67-865F-EE1C13D28C38}" = QuickBooks Premier: Accountant Edition 2011
"{11E0AC7D-6829-4F67-865F-EE1C13D28C38}" = QuickBooks Enterprise Solutions: Accountant Edition 11.0
"{14D6D5E1-5425-4BD1-BAFB-C26C053DC0AF}" = Infragisticsv62Install
"{18455581-E099-4BA8-BC6B-F34B2F06600C}" = Google Toolbar for Internet Explorer
"{1D080AF7-5F9E-F5D6-A24A-469FBCE95C8B}" = CCC Help Norwegian
"{1D70AABC-CB59-4700-A708-EA56D1CA07B0}" = QuickBooks
"{1EFCFB56-B8BB-4834-AE8E-29EE73FF8611}" = QuickBooks
"{20D4A895-748C-4D88-871C-FDB1695B0169}" = Platform
"{2181214D-1954-4C60-91FD-EEA7EBB32022}" = QuickBooks Premier: Accountant Edition 2012
"{2318C2B1-4965-11d4-9B18-009027A5CD4F}" = Google Toolbar for Internet Explorer
"{239F3BCA-2608-D50E-4B5F-E41528C22EE6}" = CCC Help Danish
"{24118298-9ADD-CA82-16D0-C6CE0937C3CF}" = CCC Help Portuguese
"{25E202D1-D8E7-46AF-B4B0-157D9993A93E}" = QuickBooks
"{26A24AE4-039D-4CA4-87B4-2F83216031FF}" = Java™ 6 Update 31
"{26FC9CD1-A915-DDEC-BAB1-E3B7059A9A3F}" = Catalyst Control Center Localization All
"{2804D8D5-ED80-9535-6CFB-903DF29AF851}" = CCC Help Portuguese
"{37F89D69-BA37-4813-B603-0FB42408C546}" = CCC Help Korean
"{3C3D696B-0DB7-3C6D-A356-3DB8CE541918}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729
"{3CF491D7-1DD5-32C7-1C73-C51651A6CCB0}" = CCC Help Chinese Traditional
"{46427F73-901E-F790-CC7B-C360FB5B86B0}" = HydraVision
"{4733F335-7B0A-CE50-9492-AEEBABA9B030}" = Catalyst Control Center Localization All
"{48F9BD28-514D-AB00-6355-A2701D6D6B28}" = CCC Help Japanese
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{4B99F903-230A-4E33-9A60-F58C1908D29E}" = Error Recovery Guide for fi-6130/fi-6230
"{4BE46E95-DBFC-6779-E8C5-399AC4C3F9C8}" = CCC Help Russian
"{4D4C2006-5CF9-63DB-4CCE-F528A7B4B604}" = CCC Help English
"{55584E16-4D70-44EE-93DD-F144E8B7D4B7}" = QuickBooks Product Listing Service
"{56E99876-587A-7F8D-AD8E-8FCDF67B0575}" = CCC Help Polish
"{580E9BBC-A51E-4AE9-A977-7B0939BEDAD3}" = Scanner Utility for Microsoft Windows V09L21
"{5A3F6A80-7913-475E-8B96-477A952CFA43}" = SupportSoft Assisted Service
"{5BC3A763-5F75-358B-7F21-E5B5068E610B}" = CCC Help Japanese
"{5C01E990-F14D-4E3C-A009-29F3640F034B}" = Infragisticsv62Install
"{663FA652-A645-B849-C9B9-54C59D2FC769}" = CCC Help Italian
"{6781C3BE-E76A-22C1-BCC6-614C908B3AD2}" = CCC Help Swedish
"{68D5E12C-E353-B87C-5C36-CDA29FA692FD}" = CCC Help Spanish
"{6DB7AD00-F781-11DF-9EEF-001279CD8240}" = Google Earth
"{705292ED-22B2-4BCF-8DD4-F9B393844D7D}" = Infragisticsv62Install 2010
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{716E0306-8318-4364-8B8F-0CC4E9376BAC}" = MSXML 4.0 SP2 Parser and SDK
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{73BE88D4-25B1-6431-F3FD-2D9510CC325F}" = CCC Help Turkish
"{7605F54E-3B38-ADF0-460C-2CAF0454D7AF}" = CCC Help Turkish
"{7699AA03-8A8C-489E-AF9D-A76A5E97E879}" = UltraTax Font Installer
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{775EB52A-3454-1F75-1C18-813A9C33D079}" = CCC Help Danish
"{786F6333-02D3-E5ED-5B0E-35270AE74C60}" = CCC Help French
"{7AE0E1CB-3EF7-287D-EBEE-788C9A459CC4}" = Catalyst Control Center InstallProxy
"{7D6D03A9-422F-E58D-4F21-627A3AB1F15B}" = CCC Help Chinese Traditional
"{7E545666-F423-45FD-B3DF-C0B99A1A579F}" = QuickBooks Premier: Accountant Edition 2007
"{7E5F6EAB-05E9-DA44-3FC4-CF74B2F1F3E0}" = CCC Help Dutch
"{7F1BF20D-72B0-5CB8-9E3A-4CF60EA4DE9E}" = CCC Help Polish
"{8651E9B1-6469-6FAF-14F7-1E02AB6027C0}" = CCC Help German
"{86CE85E6-DBAC-3FFD-B977-E4B79F83C909}" = Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570
"{86E183C0-50C7-4C33-918F-AAA0792922DC}" = Infragisticsv62Install 2009
"{8833FFB6-5B0C-4764-81AA-06DFEED9A476}" = Realtek Ethernet Controller Driver For Windows Vista and Later
"{8CB0CF3C-3DE2-F908-3C38-BA67F5633E3F}" = CCC Help English
"{8D0DCC82-0D64-6AB1-AE0E-B927D72FF325}" = CCC Help Norwegian
"{8D5B681B-2BFD-5C99-8309-179E07200EA0}" = CCC Help Czech
"{8DBA214A-E740-BE5B-E306-B545DF8F13B6}" = CCC Help Korean
"{8DE169C8-2F91-3239-04F4-615984E0FD88}" = CCC Help Hungarian
"{90120000-0020-0409-0000-0000000FF1CE}" = Compatibility Pack for the 2007 Office system
"{90140000-0015-0409-0000-0000000FF1CE}" = Microsoft Office Access MUI (English) 2010
"{90140000-0015-0409-0000-0000000FF1CE}_Office14.SingleImage_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2010
"{90140000-0016-0409-0000-0000000FF1CE}_Office14.SingleImage_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2010
"{90140000-0018-0409-0000-0000000FF1CE}_Office14.SingleImage_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0019-0409-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (English) 2010
"{90140000-0019-0409-0000-0000000FF1CE}_Office14.SingleImage_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-001A-0409-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (English) 2010
"{90140000-001A-0409-0000-0000000FF1CE}_Office14.SingleImage_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2010
"{90140000-001B-0409-0000-0000000FF1CE}_Office14.SingleImage_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2010
"{90140000-001F-0409-0000-0000000FF1CE}_Office14.SingleImage_{99ACCA38-6DD3-48A8-96AE-A283C9759279}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2010
"{90140000-001F-040C-0000-0000000FF1CE}_Office14.SingleImage_{46298F6A-1E7E-4D4A-B5F5-106A4F0E48C6}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2010
"{90140000-001F-0C0A-0000-0000000FF1CE}_Office14.SingleImage_{DEA87BE2-FFCC-4F33-9946-FCBE55A1E998}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-002A-0000-1000-0000000FF1CE}_Office14.SingleImage_{967EF02C-5C7E-4718-8FCB-BDC050190CCF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-002A-0409-1000-0000000FF1CE}_Office14.SingleImage_{D6C6B46A-6CE1-4561-84A0-EFD58B8AB979}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2010
"{90140000-002C-0409-0000-0000000FF1CE}_Office14.SingleImage_{7CA93DF4-8902-449E-A42E-4C5923CFBDE3}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-003D-0000-0000-0000000FF1CE}" = Microsoft Office Single Image 2010
"{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{047B0968-E622-4FAA-9B4B-121FA109EDDE}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2010
"{90140000-006E-0409-0000-0000000FF1CE}_Office14.SingleImage_{4560037C-E356-444A-A015-D21F487D809E}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-00A1-0409-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2010
"{90140000-00A1-0409-0000-0000000FF1CE}_Office14.SingleImage_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2010
"{90140000-0115-0409-0000-0000000FF1CE}_Office14.SingleImage_{4560037C-E356-444A-A015-D21F487D809E}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0116-0409-1000-0000000FF1CE}_Office14.SingleImage_{D6C6B46A-6CE1-4561-84A0-EFD58B8AB979}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0117-0409-0000-0000000FF1CE}" = Microsoft Office Access Setup Metadata MUI (English) 2010
"{90140000-0117-0409-0000-0000000FF1CE}_Office14.SingleImage_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{93151469-F890-77E5-4CF7-4CB89510834E}" = CCC Help Dutch
"{963C55D7-A1D3-92AE-2820-AF41C947389E}" = CCC Help Chinese Standard
"{99C8E660-0147-5000-B714-28104014C6E7}" = CCC Help Finnish
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9A2F0810-3623-4E86-9072-973FBE1679C5}" = QuickBooks Premier: Accountant Edition 2009
"{9A8A3E6C-43E5-C168-B4DF-6343721EC89E}" = CCC Help Greek
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{A49F249F-0C91-497F-86DF-B2585E8E76B7}" = Microsoft Visual C++ 2005 Redistributable
"{A5055D64-3EF9-4E8A-BD12-676FD213CBE6}" = ToolBox CS
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{AA381987-A7D1-7F4C-2357-F7890B4C2EC7}" = Catalyst Control Center Graphics Previews Common
"{AC76BA86-1033-F400-7760-000000000005}" = Adobe Acrobat X Pro - English, Français, Deutsch
"{B32BEF70-3256-BF83-304B-D9BED7065C9F}" = Catalyst Control Center
"{B4092C6D-E886-4CB2-BA68-FE5A88D31DE6}_is1" = Spybot - Search & Destroy
"{BCB31D5A-B489-F788-5404-7C5D578A79BB}" = CCC Help Finnish
"{C3125E2D-6B61-40A1-80C0-F5383C9968B7}" = GoldMine
"{C918E3D8-208F-43DB-B346-6299D59336D7}" = CardMinder V3.2
"{CA0CD0A5-C64C-0ECF-8835-67C47B8269AF}" = Catalyst Control Center Graphics Previews Common
"{CB084DB3-7E26-8C34-A35C-552820C0578C}" = CCC Help Italian
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{CB6D7032-291D-46EE-900C-7B17587A92F9}" = Accounting CS
"{CCC4FC13-1AEC-2BFF-E3C9-3BB2DE6FD4DF}" = CCC Help French
"{D1E35070-00F1-F60A-7429-FF1F2F1226C3}" = CCC Help Greek
"{D4F2AFD3-0167-4464-B92F-78AB6DA8A0AA}" = CardMinder V3.2
"{E030DF26-3E3A-4250-8994-3CA571CFD970}" = CS Fonts
"{E1EDD15D-1079-FAB8-54D6-51115B1D7DFE}" = CCC Help German
"{ED6FE34F-1733-BF98-B022-7D41590C7982}" = Catalyst Control Center InstallProxy
"{EE540252-D58A-4480-B051-AF8204B6AE61}" = Practice CS
"{EEEE69BC-02A9-09C8-4AD9-E8B20DFFFC6F}" = CCC Help Hungarian
"{EF8672E3-C9C0-4BDF-948B-77BC58BECFF9}" = Fujitsu ScandAll PRO V1.8 Update1
"{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}" = Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219
"{F428D74A-2578-B0F5-8761-305D80C388ED}" = CCC Help Thai
"{F4F89CB2-D086-43DA-BD78-65A28F2ED8FF}" = Client Bookkeeping Solution 2007.1
"{F7FFF37F-DB74-408C-840F-BD8B8E955B5B}" = FUJITSU Scanner USB HotFix
"{FC0085A5-8836-6118-7AAD-C5A51F28480A}" = CCC Help Swedish
"{FCBE340B-D08D-45AA-BDC5-97A00415A47D}" = Tic, Tie & Calculate Professional
"Adobe Flash Player ActiveX" = Adobe Flash Player 11 ActiveX
"Creative Solutions Accounting Workstation" = Creative Solutions Accounting - Workstation
"FileCabinet CS" = FileCabinet CS
"FileCabinet CS Print Driver" = FileCabinet CS Print Driver
"Fixed Assets CS" = Fixed Assets CS
"InstallShield_{20D4A895-748C-4D88-871C-FDB1695B0169}" = VIA Platform Device Manager
"IspAssistant-Mp3Tube" = IspAssistant-Mp3Tube
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"Office14.SingleImage" = Microsoft Office Home and Business 2010
"Planner CS" = Planner CS
"PrimoPDF" = PrimoPDF – brought to you by Nitro PDF Software
"RFFlow" = RFFlow
"ScandAllPRO" = Fujitsu ScandAll PRO V1.8 Update1
"Software Operation Panel" = Software Operation Panel
"TValue 5" = TValue 5
"UltraTax CS 2011" = UltraTax CS 2011
"WinZip" = WinZip

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"ActiveTouchMeetingClient" = WebEx
"Document Uploader" = Document Uploader
"JoinMe" = join.me

========== Last 20 Event Log Errors ==========

[ Application Events ]
Error - 6/19/2012 3:36:40 PM | Computer Name = Karl-PC | Source = QuickBooks | ID = 4
Description = An unexpected error has occured in "QuickBooks": Returning NULL QBWinInstance
Hand

Error - 6/19/2012 3:36:40 PM | Computer Name = Karl-PC | Source = QuickBooks | ID = 4
Description = An unexpected error has occured in "QuickBooks": Returning NULL QBWinInstance
Hand

Error - 6/19/2012 3:36:40 PM | Computer Name = Karl-PC | Source = QuickBooks | ID = 4
Description = An unexpected error has occured in "QuickBooks": Returning NULL QBWinInstance
Hand

Error - 6/19/2012 3:37:02 PM | Computer Name = Karl-PC | Source = QuickBooks | ID = 4
Description = An unexpected error has occured in "QuickBooks Accountant 2012": QuickBooks
has experienced a problem and must be shut dow

Error - 6/19/2012 3:37:09 PM | Computer Name = Karl-PC | Source = QuickBooks | ID = 4
Description = An unexpected error has occured in "QuickBooks": Returning NULL QBWinInstance
Hand

Error - 6/19/2012 3:37:09 PM | Computer Name = Karl-PC | Source = QuickBooks | ID = 4
Description = An unexpected error has occured in "QuickBooks": Returning NULL QBWinInstance
Hand

Error - 6/19/2012 3:37:09 PM | Computer Name = Karl-PC | Source = QuickBooks | ID = 4
Description = An unexpected error has occured in "QuickBooks": Returning NULL QBWinInstance
Hand

Error - 6/19/2012 3:43:44 PM | Computer Name = Karl-PC | Source = QuickBooks | ID = 4
Description = An unexpected error has occured in "QuickBooks Accountant 2012": QuickBooks
has experienced a problem and must be shut dow

Error - 6/19/2012 3:45:20 PM | Computer Name = Karl-PC | Source = QuickBooks | ID = 4
Description = An unexpected error has occured in "QuickBooks": Returning NULL QBWinInstance
Hand

Error - 6/19/2012 3:45:20 PM | Computer Name = Karl-PC | Source = QuickBooks | ID = 4
Description = An unexpected error has occured in "QuickBooks": Returning NULL QBWinInstance
Hand

Error - 6/19/2012 3:45:20 PM | Computer Name = Karl-PC | Source = QuickBooks | ID = 4
Description = An unexpected error has occured in "QuickBooks": Returning NULL QBWinInstance
Hand

Error - 6/27/2012 4:10:12 PM | Computer Name = Karl-PC | Source = Application Error | ID = 1000
Description = Faulting application name: er_00_1_l.exe, version: 0.0.0.0, time stamp:
0x403188d2 Faulting module name: unknown, version: 0.0.0.0, time stamp: 0x00000000
Exception
code: 0xc0000005 Fault offset: 0x00000000 Faulting process id: 0xdbc Faulting application
start time: 0x01cd54a0db27a355 Faulting application path: C:\Users\Karl\AppData\Local\Temp\er_00_1_l.exe
Faulting
module path: unknown Report Id: 199c21cc-c094-11e1-9b1f-00045a8ccd11

[ System Events ]
Error - 6/28/2012 3:40:53 PM | Computer Name = Karl-PC | Source = Service Control Manager | ID = 7001
Description = The Network List Service service depends on the Network Location Awareness
service which failed to start because of the following error: %%1068

Error - 6/28/2012 3:40:53 PM | Computer Name = Karl-PC | Source = Service Control Manager | ID = 7001
Description = The Network List Service service depends on the Network Location Awareness
service which failed to start because of the following error: %%1068

Error - 6/28/2012 3:40:55 PM | Computer Name = Karl-PC | Source = Service Control Manager | ID = 7001
Description = The Network List Service service depends on the Network Location Awareness
service which failed to start because of the following error: %%1068

Error - 6/28/2012 3:40:55 PM | Computer Name = Karl-PC | Source = Service Control Manager | ID = 7001
Description = The Network List Service service depends on the Network Location Awareness
service which failed to start because of the following error: %%1068

Error - 6/28/2012 3:40:55 PM | Computer Name = Karl-PC | Source = Service Control Manager | ID = 7001
Description = The Network List Service service depends on the Network Location Awareness
service which failed to start because of the following error: %%1068

Error - 6/28/2012 3:40:55 PM | Computer Name = Karl-PC | Source = Service Control Manager | ID = 7001
Description = The Network List Service service depends on the Network Location Awareness
service which failed to start because of the following error: %%1068

Error - 6/28/2012 3:40:55 PM | Computer Name = Karl-PC | Source = Service Control Manager | ID = 7001
Description = The Network List Service service depends on the Network Location Awareness
service which failed to start because of the following error: %%1068

Error - 6/28/2012 3:40:55 PM | Computer Name = Karl-PC | Source = Service Control Manager | ID = 7001
Description = The Network List Service service depends on the Network Location Awareness
service which failed to start because of the following error: %%1068

Error - 6/28/2012 3:51:54 PM | Computer Name = Karl-PC | Source = Service Control Manager | ID = 7001
Description = The Network List Service service depends on the Network Location Awareness
service which failed to start because of the following error: %%1068

Error - 6/28/2012 4:35:39 PM | Computer Name = Karl-PC | Source = Service Control Manager | ID = 7003
Description = The SBSD Security Center Service service depends the following service:
wscsvc. This service might not be installed.


< End of report >
Hello and welcome to What the Tech.

My name is Michael and I will be helping you with your computer problems.

Be aware that I am currently in training, which means that my replies must first be approved by one of my teachers. This may cause a slight delay in my responses, but keep in mind that this process is only to ensure you are receiving advice of the utmost accuracy.

Please keep the following points in mind:
  • Malware research is often a time consuming process and sometimes multiple tools/methods will have to be employed before an infection is completely dealt with. Please be patient during the process of removal.
  • Read my instructions carefully before carrying them out. Also, consider printing out any instructions in case you lose your Internet connection.
  • If you have any questions, please ask before carrying out a fix. Clearing up any confusion beforehand will save time in the long run. That said, I will try to post instructions as clearly and concisely as possible.
  • Please reply to this thread. Do not start a new topic, and do not request help on other forums during the course of the cleaning process.
  • If you do not reply after three (3) days, your thread will be closed.
IMPORTANT NOTE: Please do not delete anything unless instructed to.
DO NOT use any TOOLS such as Combofix or HijackThis fixes without supervision. Doing so could make your system inoperable and could require a full reinstall of your Operating System and losing all your programs and data.

I will be back as soon as possible with a response.
  • Please download aswMBR.exe and save it to your desktop.
  • Double click aswMBR.exe to start the tool.
  • When prompted to download virus definitions, please do so.
  • Click Scan. Note: Do NOT attempt any Fix yet.
  • When the scan completes, click Save log, save it to your desktop and post it in your next reply.
  • There should also be another file that is created on your desktop named MBR.dat. Please right-click that file and select Send To>Compressed (zipped) file. Attach that zipped file in your next reply as well.
aswMBR version 0.9.9.1665 Copyright© 2011 AVAST Software Run date: 2012-06-29 08:06:01 —————————– 08:06:01.131 OS Version: Windows x64 6.1.7601 Service Pack 1 08:06:01.131 Number of processors: 2 586 0x603 08:06:01.131 ComputerName: KARL-PC UserName: Karl 08:06:04.985 Initialize success 08:07:24.118 AVAST engine defs: 12062901 08:07:40.732 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-0 08:07:40.732 Disk 0 Vendor: WDC_WD5000AAKS-00UU3A0 01.03B01 Size: 476940MB BusType: 3 08:07:40.779 Disk 0 MBR read successfully 08:07:40.779 Disk 0 MBR scan 08:07:40.795 Disk 0 Windows 7 default MBR code 08:07:40.810 Disk 0 Partition 1 80 (A) 07 HPFS/NTFS NTFS 100 MB offset 2048 08:07:40.857 Disk 0 Partition 2 00 07 HPFS/NTFS NTFS 476838 MB offset 206848 08:07:40.935 Disk 0 scanning C:\Windows\system32\drivers 08:08:01.059 Service scanning 08:08:38.764 Service TrustedInstaller C:\Windows\servicing\TrustedInstaller.exe **HIDDEN** 08:08:45.379 Modules scanning 08:08:45.379 Disk 0 trace - called modules: 08:08:45.394 ntoskrnl.exe CLASSPNP.SYS disk.sys ACPI.sys ataport.SYS pciide.sys 08:08:45.909 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0xfffffa80048875c0] 08:08:45.909 3 CLASSPNP.SYS[fffff880019bd43f] -> nt!IofCallDriver -> [0xfffffa8004882520] 08:08:45.909 5 ACPI.sys[fffff88000fa97a1] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP0T0L0-0[0xfffffa800487e680] 08:08:52.118 AVAST engine scan C:\Windows 08:08:57.594 AVAST engine scan C:\Windows\system32 08:09:14.988 File: C:\Windows\system32\consrv.dll **INFECTED** Win32:Sirefef-HO [Rtk] 08:11:38.743 File: C:\Windows\assembly\GAC_32\Desktop.ini **INFECTED** Win32:Sirefef-FQ [Drp] 08:11:42.616 File: C:\Windows\assembly\GAC_64\Desktop.ini **INFECTED** Win32:Sirefef-HO [Rtk] 08:13:23.986 AVAST engine scan C:\Windows\system32\drivers 08:13:33.565 AVAST engine scan C:\Users\Karl 08:13:34.579 File: C:\Users\Karl\AppData\Local\fno.exe **INFECTED** Win32:MalOb-GR [Cryp] 08:13:36.388 File: C:\Users\Karl\AppData\Local\ksv.exe **INFECTED** Win32:MalOb-GR [Cryp] 08:15:43.029 Disk 0 MBR has been saved successfully to "C:\Users\Karl\Desktop\MBR.dat" 08:15:43.045 The log file has been saved successfully to "C:\Users\Karl\Desktop\aswMBR.txt"

Attachments:

  • ComboFix

    Refer to the ComboFix User's Guide

  • Download ComboFix from one of these locations:

    Link 1
    Link 2

    * IMPORTANT !!! Place ComboFix.exe on your Desktop
  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with ComboFix.
    You can get help on disabling your protection programs here
  • Double click on ComboFix.exe & follow the prompts.
  • Your desktop may go blank. This is normal. It will return when ComboFix is done. ComboFix may reboot your machine. This is normal.
  • When finished, it shall produce a log for you. Post that log in your next reply

    Note:
    Do not mouse click ComboFix's window whilst it's running. That may cause it to stall.


    ———————————————————————————————
  • Ensure your AntiVirus and AntiSpyware applications are re-enabled.

    ———————————————————————————————

NOTE: If you encounter a message "illegal operation attempted on registry key that has been marked for deletion" and no programs will run - please just reboot and that will resolve that error.
Thanks again for your expert assistance. Here is the log file: ComboFix 12-06-28.03 - Karl 06/29/2012 19:29:57.1.2 - x64 Microsoft Windows 7 Professional 6.1.7601.1.1252.1.1033.18.4095.2442 [GMT -5:00] Running from: c:\users\[removed]\Desktop\ComboFix.exe SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} . . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . . c:\program files (x86)\Mp3Tube Toolbar c:\program files (x86)\Mp3Tube Toolbar\ffmpeg.exe c:\program files (x86)\Mp3Tube Toolbar\Mp3TubeSvc.exe c:\program files (x86)\Mp3Tube Toolbar\mp3Tubetb.dll c:\program files (x86)\Mp3Tube Toolbar\Mp3TubeVideoToMp3.exe c:\program files (x86)\Mp3Tube Toolbar\ShowMsg.exe c:\program files (x86)\Mp3Tube Toolbar\uninstall.exe c:\programdata\143306s0j286x770y614f0jar4x1 c:\programdata\XhbXwlbhQSr92x c:\users\Karl\AppData\Local\fno.exe c:\users\Karl\AppData\Local\ksv.exe c:\users\Karl\AppData\Local\Microsoft\Windows\Temporary Internet Files\2308AccountantCenter.html c:\users\Karl\AppData\Local\Microsoft\Windows\Temporary Internet Files\2960AccountantCenter.html c:\users\Karl\AppData\Local\Microsoft\Windows\Temporary Internet Files\3112AccountantCenter.html c:\users\Karl\AppData\Local\Microsoft\Windows\Temporary Internet Files\3552AccountantCenter.html c:\users\Karl\AppData\Local\Microsoft\Windows\Temporary Internet Files\3824AccountantCenter.html c:\users\Karl\AppData\Local\Microsoft\Windows\Temporary Internet Files\464AccountantCenter.html c:\users\Karl\AppData\Local\Microsoft\Windows\Temporary Internet Files\ac.js c:\users\Karl\AppData\Local\Microsoft\Windows\Temporary Internet Files\close_pop.png c:\users\Karl\AppData\Local\Microsoft\Windows\Temporary Internet Files\jquery.corner.js c:\users\Karl\AppData\Local\Microsoft\Windows\Temporary Internet Files\jquery.min.js c:\users\Karl\AppData\Local\Microsoft\Windows\Temporary Internet Files\viewChanges.html c:\windows\A5F4E84E0C164F6EA68C60AFC943350E.dll c:\windows\assembly\GAC_32\Desktop.ini c:\windows\assembly\GAC_64\Desktop.ini c:\windows\system32\consrv.dll c:\windows\System64 . . ((((((((((((((((((((((((( Files Created from 2012-05-28 to 2012-06-30 ))))))))))))))))))))))))))))))) . . 2012-06-30 00:34 . 2012-06-30 00:34 ——– d—–w- c:\users\Default\AppData\Local\temp 2012-06-29 13:09 . 2012-05-04 11:06 5559664 —-a-w- c:\windows\system32\ntoskrnl.exe 2012-06-29 13:02 . 2012-06-02 22:19 2428952 —-a-w- c:\windows\system32\wuaueng.dll 2012-06-29 13:02 . 2012-06-02 22:19 57880 —-a-w- c:\windows\system32\wuauclt.exe 2012-06-29 13:02 . 2012-06-02 22:19 44056 —-a-w- c:\windows\system32\wups2.dll 2012-06-29 13:02 . 2012-06-02 22:15 2622464 —-a-w- c:\windows\system32\wucltux.dll 2012-06-29 13:02 . 2012-06-02 22:19 38424 —-a-w- c:\windows\system32\wups.dll 2012-06-29 13:02 . 2012-06-02 22:19 701976 —-a-w- c:\windows\system32\wuapi.dll 2012-06-29 13:02 . 2012-06-02 22:15 99840 —-a-w- c:\windows\system32\wudriver.dll 2012-06-29 13:02 . 2012-06-02 20:19 186752 —-a-w- c:\windows\system32\wuwebv.dll 2012-06-29 13:02 . 2012-06-02 20:15 36864 —-a-w- c:\windows\system32\wuapp.exe 2012-06-28 18:32 . 2012-06-28 22:06 ——– d—–w- c:\windows\system32\MpEngineStore 2012-06-28 13:10 . 2012-06-28 21:38 ——– d—–w- c:\program files (x86)\Microsoft Security Client 2012-06-28 13:10 . 2012-06-28 21:38 ——– d—–w- c:\program files\Microsoft Security Client 2012-06-27 21:24 . 2012-06-27 21:24 0 —ha-w- c:\users\Karl\AppData\Local\BIT929.tmp 2012-06-19 21:56 . 2012-06-19 21:56 0 —ha-w- c:\users\Karl\AppData\Local\BIT5AED.tmp . . . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2012-05-05 17:23 . 2012-03-30 13:05 419488 —-a-w- c:\windows\SysWow64\FlashPlayerApp.exe 2012-05-05 17:23 . 2011-06-08 13:02 70304 —-a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl 2012-05-05 17:23 . 2012-04-14 17:23 8769696 —-a-w- c:\windows\SysWow64\FlashPlayerInstaller.exe . . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 . [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "swg"="c:\program files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2011-11-28 39408] "SpybotSD TeaTimer"="c:\program files (x86)\Spybot - Search & Destroy\TeaTimer.exe" [2009-03-05 2260480] . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] "Adobe Acrobat Speed Launcher"="c:\program files (x86)\Adobe\Acrobat 10.0\Acrobat\Acrobat_sl.exe" [2012-04-04 36760] "Acrobat Assistant 8.0"="c:\program files (x86)\Adobe\Acrobat 10.0\Acrobat\Acrotray.exe" [2012-04-04 815512] "Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-01-03 843712] "StartCCC"="c:\program files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2011-03-22 98304] "FtLnSOP_setup"="c:\windows\Twain_32\Fjscan32\SOP\FtLnSOP.exe" [2008-12-10 143360] "FJTWAIN Setup"="c:\windows\Twain_32\fjscan32\FjtwMkup.exe" [2009-07-08 131072] "FTPWRENV"="c:\windows\Twain_32\Fjscan32\FTPWREVT\FTPWREVT.exe" [2007-10-17 45056] "FiWIA Service Checker"="c:\windows\Twain_32\Fjscan32\FiWiaChecker.exe" [2009-10-21 86016] "SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2012-01-18 254696] . c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\ CardMinder Viewer.lnk - c:\program files (x86)\PFU\CardMinder V3.2\CardLauncher.exe [2010-12-6 36864] CS Connect Background Services.lnk - \\Quintonfs1\CSIbase\WinCSI\TOOLS\ConnectBGDL.exe [N/A] Error Recovery Guide.lnk - c:\windows\twain_32\fjscan32\ERG\FTErGuid.exe [2012-1-9 286720] Intuit Data Protect.lnk - c:\program files (x86)\Common Files\Intuit\DataProtect\IntuitDataProtect.exe [2011-8-19 5828952] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "ConsentPromptBehaviorAdmin"= 5 (0x5) "ConsentPromptBehaviorUser"= 3 (0x3) "EnableUIADesktopToggle"= 0 (0x0) . R2 gupdate;Google Update Service (gupdate);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-12-07 136176] R3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-05-05 257696] R3 gupdatem;Google Update Service (gupdatem);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-12-07 136176] R3 osppsvc;Office Software Protection Platform;c:\program files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-10 4925184] R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2010-11-20 59392] R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe [2010-12-06 1255736] S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [2011-03-22 203776] S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576] S2 CSAPrintService;Creative Solutions Accounting Print Service;c:\windows\csasvc.exe [2009-11-10 118784] S2 FJTWMKSV;FJTWMKSV;c:\windows\twain_32\fjscan32\FJTWMKSV.exe [2007-03-08 45056] S2 QBVSS;QBIDPService;c:\program files (x86)\Common Files\Intuit\DataProtect\QBIDPService.exe [2011-08-20 1248256] S2 SBSDWSCService;SBSD Security Center Service;c:\program files (x86)\Spybot - Search & Destroy\SDWinSec.exe [2009-01-26 1153368] S3 amdkmdag;amdkmdag;c:\windows\system32\DRIVERS\atikmdag.sys [2011-03-22 9259520] S3 amdkmdap;amdkmdap;c:\windows\system32\DRIVERS\atikmpag.sys [2011-03-22 300544] S3 AN983X64;Infineon AN983B PCI Fast Ethernet Adapter for Windows X64;c:\windows\system32\DRIVERS\AN983X64.sys [2005-05-19 48128] S3 AtiHDAudioService;ATI Function Driver for HD Audio Service;c:\windows\system32\drivers\AtihdW76.sys [2010-11-17 115216] S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys [2010-06-23 344680] S3 VIAHdAudAddService;VIA High Definition Audio Driver Service;c:\windows\system32\drivers\viahduaa.sys [2009-10-21 1270784] . . — Other Services/Drivers In Memory — . *NewlyCreated* - WS2IFSL . Contents of the 'Scheduled Tasks' folder . 2012-06-30 c:\windows\Tasks\Adobe Flash Player Updater.job - c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-03-30 17:23] . 2012-06-30 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job - c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-12-07 21:54] . 2012-06-29 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job - c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-12-07 21:54] . . ——— X64 Entries ———– . . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "combofix"="c:\combofix\CF13107.3XE" [2010-11-20 345088] . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows] "LoadAppInit_DLLs"=0x0 . ——- Supplementary Scan ——- . uLocal Page = c:\windows\system32\blank.htm uStart Page = hxxp://www.google.com/ mLocal Page = c:\windows\SysWOW64\blank.htm IE: Append Link Target to Existing PDF - c:\program files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppendSelLinks.html IE: Append to Existing PDF - c:\program files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppend.html IE: Convert Link Target to Adobe PDF - c:\program files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECaptureSelLinks.html IE: Convert to Adobe PDF - c:\program files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECapture.html IE: E&xport to Microsoft Excel - c:\progra~2\MICROS~1\Office14\EXCEL.EXE/3000 IE: Se&nd to OneNote - c:\progra~2\MICROS~1\Office14\ONBttnIE.dll/105 TCP: DhcpNameServer = [removed] [removed] TCP: Interfaces\{7D372210-BAD2-4B02-92F2-9B87EC97E0A7}: NameServer = 209.18.47.61,209.18.47.62 Handler: intu-help-qb5 - {867FCB77-9823-4cd6-8210-D85F968D466F} - c:\program files (x86)\Intuit\QuickBooks 2012\HelpAsyncPluggableProtocol.dll . - - - - ORPHANS REMOVED - - - - . HKLM-Run-ATIModeChange - Ati2mdxx.exe AddRemove-IspAssistant-Mp3Tube - c:\program files (x86)\Mp3Tube Toolbar\uninstall.exe . . . ——————— LOCKED REGISTRY KEYS ——————— . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}] @Denied: (A 2) (Everyone) @="FlashBroker" "LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_2_202_235_ActiveX.exe,-101" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation] "Enabled"=dword:00000001 . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_2_202_235_ActiveX.exe" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Shockwave Flash Object" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_2_202_235.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus] @="0" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID] @="ShockwaveFlash.ShockwaveFlash.11" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_2_202_235.ocx, 1" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="ShockwaveFlash.ShockwaveFlash" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Macromedia Flash Factory Object" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_2_202_235.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID] @="FlashFactory.FlashFactory.1" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_2_202_235.ocx, 1" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="FlashFactory.FlashFactory" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}] @Denied: (A 2) (Everyone) @="IFlashBroker4" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32] @="{00020424-0000-0000-C000-000000000046}" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" "Version"="1.0" . [HKEY_LOCAL_MACHINE\software\Wow6432Node\Microsoft\Office\Common\Smart Tag\Actions\{B7EFF951-E52F-45CC-9EF7-57124F2177CC}] @Denied: (A) (Everyone) "Solution"="{15727DE6-F92D-4E46-ACB4-0E2C58B31A18}" . [HKEY_LOCAL_MACHINE\software\Wow6432Node\Microsoft\Schema Library\ActionsPane3] @Denied: (A) (Everyone) . [HKEY_LOCAL_MACHINE\software\Wow6432Node\Microsoft\Schema Library\ActionsPane3\0] "Key"="ActionsPane3" "Location"="c:\\Program Files (x86)\\Common Files\\Microsoft Shared\\VSTO\\ActionsPane3.xsd" . [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\PCW\Security] @Denied: (Full) (Everyone) . ———————— Other Running Processes ———————— . c:\windows\csifcsvc.exe c:\program files (x86)\Common Files\Intuit\QuickBooks\QBCFMonitorService.exe c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe . ************************************************************************** . Completion time: 2012-06-29 19:44:31 - machine was rebooted ComboFix-quarantined-files.txt 2012-06-30 00:44 . Pre-Run: 429,752,053,760 bytes free Post-Run: 429,447,872,512 bytes free . - - End Of File - - 44446F2674EC780F432632CD8E3D739F
  • Malwarebytes' Anti-Malware

    Download Malwarebytes' Anti-Malware to your desktop.

    • Double-click mbam-setup.exe and follow the prompts to install the program.
    • At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
    • If an update is found, it will download and install the latest version.
    • Once the program has loaded, select Perform quick scan, then click Scan.
    • When the scan is complete, click OK, then Show Results to view the results.
    • Be sure that everything is checked, and click Remove Selected.
    • When completed, a log will open in Notepad. This log is saved by MBAM and can be viewed by clicking the Logs tab.
    • Click on "Edit > Select All" then click on "Edit > Copy" to copy the entire contents of the log.
    • Note: If you receive a notice that some of the items couldn't be removed, that they have been added to the delete on reboot list, please reboot.
  • TFC

    Download TFC to your desktop

    • Close any open windows.
    • Double click the TFC icon to run the program
    • TFC will close all open programs itself in order to run.
    • Click the Start button to begin the process.
    • Allow TFC to run uninterrupted.
    • The program should not take long to finish its job.
    • Once it's finished it should automatically reboot your machine.
    • If it doesn't, manually reboot to ensure a complete clean.
  • ESET Online Scanner

    Please disable any real-time security programs such as your anti-virus before proceeding with this scan.

    • Open Internet Explorer.
    • Download ESET Online Scanner.
    • Put a checkmark in the checkbox next to YES, I accept the Terms of Use.
    • Click Start.
    • When prompted by your web browser, click Install.
    • Uncheck Remove found threats.
    • Check Scan archives.
    • Click Start and let the scanner finish downloading virus signatures. The scan will begin afterward.
    • When the scan completes, click List of found threats.
    • Click Export to text file… and save the file to your desktop.
    • Click Back.
    • Click Finish.
Please paste the log for MBAM and the log for ESET (if it created one) in your next reply.
Malwarebytes Anti-Malware 1.61.0.1400 www.malwarebytes.org Database version: v2012.06.30.05 Windows 7 Service Pack 1 x64 NTFS Internet Explorer 8.0.7601.17514 Karl :: KARL-PC [administrator] 6/30/2012 8:24:47 AM mbam-log-2012-06-30 (08-24-47).txt Scan type: Quick scan Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM Scan options disabled: P2P Objects scanned: 211336 Time elapsed: 1 minute(s), 53 second(s) Memory Processes Detected: 0 (No malicious items detected) Memory Modules Detected: 0 (No malicious items detected) Registry Keys Detected: 5 HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{4B8C28A7-A9BC-45F8-990D-21499EED643C} (Adware.QuestScan) -> Quarantined and deleted successfully. HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{A078F691-9C07-4AF2-BF43-35E79EECF8B7} (Adware.Softomate) -> Quarantined and deleted successfully. HKLM\SOFTWARE\Mp3Tube (Adware.Mp3Tube) -> Quarantined and deleted successfully. HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\IspAssistant-Mp3Tube (Adware.Adware.MP3TubeToolBar) -> Quarantined and deleted successfully. HKLM\SOFTWARE\QUESTSCAN (Adware.QuestScan) -> Quarantined and deleted successfully. Registry Values Detected: 1 HKLM\SOFTWARE\QuestScan|DllPath (Adware.QuestScan) -> Data: C:\Program Files (x86)\QuestScan\questscan.dll -> Quarantined and deleted successfully. Registry Data Items Detected: 0 (No malicious items detected) Folders Detected: 0 (No malicious items detected) Files Detected: 0 (No malicious items detected) (end) ————————————————————————————————– C:\Qoobox\Quarantine\C\Users\Karl\AppData\Local\fno.exe.vir a variant of Win32/Kryptik.XWS trojan C:\Qoobox\Quarantine\C\Users\Karl\AppData\Local\ksv.exe.vir a variant of Win32/Kryptik.YDQ trojan C:\Qoobox\Quarantine\C\Windows\assembly\GAC_32\Desktop.ini.vir Win32/Sirefef.DN trojan C:\Qoobox\Quarantine\C\Windows\assembly\GAC_64\Desktop.ini.vir Win64/Sirefef.G trojan C:\Qoobox\Quarantine\C\Windows\System32\consrv.dll.vir Win64/Sirefef.G trojan
Hi redder,

Please open your Start menu and navigate to Control Panel (icon view) > Programs and Features. Please uninstall any versions of Java you may have and reboot if necessary. Then, please go here and download the latest Java installer for your PC. I notice you have an old 64-bit Java version installed. If you need a 64-bit version for some specific purpose, then you will also need to download the 64-bit offline installer and go through the installation.

Clear Java cache

Go into the Control Panel and double-click the Java icon (looks like a coffee cup). If you do not see the icon, switch to icon view.

  • On the General tab, under Temporary Internet Files, click the Settings button.
  • Next, click on the Delete Files button
  • There are two options in the window to clear the cache - Leave BOTH Checked
    • Applications and Applets
    • Trace and Log Files
  • Click OK on Delete Temporary Files Window
    Note: This deletes ALL the Downloaded Applications and Applets from the CACHE.
  • Click OK to leave the Temporary Files Window
  • You may now close the Java control panel.

Please also run OTL again using the instructions from earlier and post a fresh log in your next reply. It should only produce one log this time (OTL.txt).
Hi Michael!!

Thanks again for all of your help.

Here is the OTL log output:

OTL logfile created on: 6/30/2012 1:11:18 PM - Run 1
OTL by OldTimer - Version 3.2.53.0 Folder = C:\Users\Karl\Desktop
64bit- Professional Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7601.17514)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

4.00 Gb Total Physical Memory | 2.34 Gb Available Physical Memory | 58.58% Memory free
8.00 Gb Paging File | 6.24 Gb Available in Paging File | 78.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 465.66 Gb Total Space | 400.89 Gb Free Space | 86.09% Space Free | Partition Type: NTFS

Computer Name: KARL-PC | User Name: Karl | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Users\Karl\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\acrotray.exe (Adobe Systems Inc.)
PRC - C:\Windows\csifcsvc.exe (Thomson Reuters)
PRC - C:\Program Files (x86)\ESET\ESET Online Scanner\OnlineCmdLineScanner.exe ()
PRC - C:\Program Files (x86)\Common Files\Intuit\QuickBooks\QBCFMonitorService.exe (Intuit)
PRC - C:\Program Files (x86)\Common Files\Intuit\DataProtect\IntuitDataProtect.exe (Intuit Inc.)
PRC - C:\Program Files (x86)\Common Files\Intuit\DataProtect\QBIDPService.exe (Intuit Inc.)
PRC - C:\Windows\csasvc.exe (Thomson Reuters)
PRC - C:\Windows\twain_32\fjscan32\FiWiaChecker.exe (PFU LIMITED)
PRC - C:\Windows\twain_32\fjscan32\FjtwMkup.exe (FUJITSU LIMITED)
PRC - C:\Program Files (x86)\Spybot - Search & Destroy\TeaTimer.exe (Safer-Networking Ltd.)
PRC - C:\Program Files (x86)\Spybot - Search & Destroy\SDWinSec.exe (Safer Networking Ltd.)
PRC - C:\Windows\twain_32\fjscan32\FTPWREVT\FTPWREVT.exe (PFU LIMITED)
PRC - C:\Program Files (x86)\PFU\CardMinder V3.2\CardLauncher.exe (PFU Limited.)
PRC - C:\Windows\twain_32\fjscan32\FJTWMKSV.exe (PFU LIMITED)


========== Modules (No Company Name) ==========

MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\PresentationFramewo#\199683f6e79076b634ee6cc0a82c0654\PresentationFramework.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\PresentationCore\e7dc084827f8df2dbdc819db5c633a0d\PresentationCore.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Windows.Forms\3971e166cf827b6726e142f344061dc9\System.Windows.Forms.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\WindowsBase\21f37f9f5162af7efb52169012bd111e\WindowsBase.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Drawing\8c40f40ef36622109793788049fbe9ab\System.Drawing.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\System.ServiceModel\cfece6f67593b4d8bb58d23b7fdcc470\System.ServiceModel.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Web.Services\dbe597aa9c12df5d08fb2f3f9872b834\System.Web.Services.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Xaml\d234eceae699d070b5a5712ce776c01f\System.Xaml.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Xml\d1f299160424bad90fe9f658661389e2\System.Xml.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Configuration\623d2a0f11dd82bb9bc13d1cb981b239\System.Configuration.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Core\ed91b57205429a23bb91f4499059a459\System.Core.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\System\6f9f0467e8b2dd3f69b015c8e30ac945\System.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\mscorlib\3953b1d8b9b57e4957bff8f58145384e\mscorlib.ni.dll ()
MOD - C:\Program Files (x86)\ESET\ESET Online Scanner\OnlineCmdLineScanner.exe ()
MOD - C:\Program Files (x86)\PFU\CardMinder V3.2\CardPath.dll ()


========== Win32 Services (SafeList) ==========

SRV:64bit: - (AMD External Events Utility) – C:\Windows\SysNative\atiesrxx.exe (AMD)
SRV:64bit: - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV:64bit: - (AppMgmt) – C:\Windows\SysNative\appmgmts.dll (Microsoft Corporation)
SRV - (AdobeFlashPlayerUpdateSvc) – C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe (Adobe Systems Incorporated)
SRV - (FCPrintService) – C:\Windows\csifcsvc.exe (Thomson Reuters)
SRV - (QBCFMonitorService) – C:\Program Files (x86)\Common Files\Intuit\QuickBooks\QBCFMonitorService.exe (Intuit)
SRV - (QBVSS) – C:\Program Files (x86)\Common Files\Intuit\DataProtect\QBIDPService.exe (Intuit Inc.)
SRV - (clr_optimization_v4.0.30319_32) – C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation)
SRV - (CSAPrintService) – C:\Windows\csasvc.exe (Thomson Reuters)
SRV - (QBFCService) – C:\Program Files (x86)\Common Files\Intuit\QuickBooks\FCS\Intuit.QuickBooks.FCS.exe (Intuit Inc.)
SRV - (clr_optimization_v2.0.50727_32) – C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
SRV - (FJTWMKSV) – C:\Windows\twain_32\fjscan32\FJTWMKSV.exe (PFU LIMITED)


========== Driver Services (SafeList) ==========

DRV:64bit: - (Fs_Rec) – C:\Windows\SysNative\drivers\fs_rec.sys (Microsoft Corporation)
DRV:64bit: - (atikmdag) – C:\Windows\SysNative\drivers\atikmdag.sys (ATI Technologies Inc.)
DRV:64bit: - (amdkmdag) – C:\Windows\SysNative\drivers\atikmdag.sys (ATI Technologies Inc.)
DRV:64bit: - (amdkmdap) – C:\Windows\SysNative\drivers\atikmpag.sys (Advanced Micro Devices, Inc.)
DRV:64bit: - (amdsata) – C:\Windows\SysNative\drivers\amdsata.sys (Advanced Micro Devices)
DRV:64bit: - (amdxata) – C:\Windows\SysNative\drivers\amdxata.sys (Advanced Micro Devices)
DRV:64bit: - (HpSAMD) – C:\Windows\SysNative\drivers\HpSAMD.sys (Hewlett-Packard Company)
DRV:64bit: - (TsUsbFlt) – C:\Windows\SysNative\drivers\TsUsbFlt.sys (Microsoft Corporation)
DRV:64bit: - (AtiHDAudioService) – C:\Windows\SysNative\drivers\AtihdW76.sys (Advanced Micro Devices)
DRV:64bit: - (RTL8167) – C:\Windows\SysNative\drivers\Rt64win7.sys (Realtek )
DRV:64bit: - (VIAHdAudAddService) – C:\Windows\SysNative\drivers\viahduaa.sys (VIA Technologies, Inc.)
DRV:64bit: - (AtiHdmiService) – C:\Windows\SysNative\drivers\AtiHdmi.sys (ATI Technologies, Inc.)
DRV:64bit: - (MTsensor) – C:\Windows\SysNative\drivers\ASACPI.sys ()
DRV:64bit: - (amdsbs) – C:\Windows\SysNative\drivers\amdsbs.sys (AMD Technologies Inc.)
DRV:64bit: - (LSI_SAS2) – C:\Windows\SysNative\drivers\lsi_sas2.sys (LSI Corporation)
DRV:64bit: - (stexstor) – C:\Windows\SysNative\drivers\stexstor.sys (Promise Technology)
DRV:64bit: - (ebdrv) – C:\Windows\SysNative\drivers\evbda.sys (Broadcom Corporation)
DRV:64bit: - (b06bdrv) – C:\Windows\SysNative\drivers\bxvbda.sys (Broadcom Corporation)
DRV:64bit: - (b57nd60a) – C:\Windows\SysNative\drivers\b57nd60a.sys (Broadcom Corporation)
DRV:64bit: - (hcw85cir) – C:\Windows\SysNative\drivers\hcw85cir.sys (Hauppauge Computer Works, Inc.)
DRV:64bit: - (AtiPcie) AMD PCI Express (3GIO) – C:\Windows\SysNative\drivers\AtiPcie.sys (Advanced Micro Devices Inc.)
DRV:64bit: - (AN983X64) – C:\Windows\SysNative\drivers\an983x64.sys (Infineon Technologies AG)
DRV - (WIMMount) – C:\Windows\SysWOW64\drivers\wimmount.sys (Microsoft Corporation)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE:64bit: - HKLM\..\SearchScopes,DefaultScope = {6A1806CD-94D4-4689-BA73-E35EA1EA9990}
IE:64bit: - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE:64bit: - HKLM\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.com/search?q={searchTerm…mp;sourceid=ie7
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\..\SearchScopes,DefaultScope = {6A1806CD-94D4-4689-BA73-E35EA1EA9990}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKLM\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.com/search?q={searchTerm…mp;sourceid=ie7

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-us
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 8D FC FE 92 58 95 CB 01 [binary data]
IE - HKCU\..\SearchScopes,DefaultScope = {6A1806CD-94D4-4689-BA73-E35EA1EA9990}
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}…amp;FORM=IE8SRC
IE - HKCU\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.com/search?q={searchTerm…1I7GGHP_enUS460
IE - HKCU\..\SearchScopes\{EE8F44DF-6319-4466-BD9D-D72454A5D0C1}: "URL" = http://mp3tubetoolbar.com/?tmp=toolbar_sb_…3e6e90329bbfee7
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0


========== FireFox ==========

FF:64bit: - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF64_10_3_162.dll File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.5.0: C:\Windows\system32\npDeployJava1.dll (Oracle Corporation)
FF:64bit: - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.5.0: C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\5.1.10411.0\npctrl.dll ( Microsoft Corporation)
FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.5.0: C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.5.0: C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files (x86)\Microsoft Silverlight\5.1.10411.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=8: C:\Program Files (x86)\Google\Update\1.2.183.39\npGoogleOneClick8.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\Adobe Acrobat: C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Air\nppdf32.dll (Adobe Systems Inc.)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Browser\WCFirefoxExtn [2012/04/12 09:58:14 | 000,000,000 | —D | M]


O1 HOSTS File: ([2011/12/23 09:07:32 | 000,001,395 | RHS- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O1 - Hosts: 69.72.252.254 www.google-analytics.com.
O1 - Hosts: 69.72.252.254 ad-emea.doubleclick.net.
O1 - Hosts: 69.72.252.254 www.statcounter.com.
O1 - Hosts: 184.95.41.155 www.google-analytics.com.
O1 - Hosts: 184.95.41.155 ad-emea.doubleclick.net.
O1 - Hosts: 184.95.41.155 www.statcounter.com.
O2:64bit: - BHO: (Java™ Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
O2:64bit: - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
O2:64bit: - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.7.7018.1622\swg64.dll (Google Inc.)
O2:64bit: - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O2 - BHO: (Spybot-S&D IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files (x86)\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O2 - BHO: (Java™ Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
O2 - BHO: (Adobe PDF Conversion Toolbar Helper) - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files (x86)\Google\GoogleToolbarNotifier\5.7.7018.1622\swg.dll (Google Inc.)
O2 - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O2 - BHO: (SmartSelect Class) - {F4971EE7-DAA0-4053-9964-665D8EE6A077} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O3:64bit: - HKLM\..\Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O3:64bit: - HKCU\..\Toolbar\WebBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O4:64bit: - HKLM..\Run: [ATIModeChange] Ati2mdxx.exe File not found
O4 - HKLM..\Run: [Acrobat Assistant 8.0] C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Acrotray.exe (Adobe Systems Inc.)
O4 - HKLM..\Run: [Adobe Acrobat Speed Launcher] C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Acrobat_sl.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [FiWIA Service Checker] C:\Windows\twain_32\fjscan32\FiWiaChecker.exe (PFU LIMITED)
O4 - HKLM..\Run: [FJTWAIN Setup] C:\Windows\Twain_32\fjscan32\FjtwMkup.exe (FUJITSU LIMITED)
O4 - HKLM..\Run: [FTPWRENV] C:\Windows\twain_32\fjscan32\FTPWREVT\FTPWREVT.exe (PFU LIMITED)
O4 - HKLM..\Run: [StartCCC] C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.)
O4 - HKCU..\Run: [SpybotSD TeaTimer] C:\Program Files (x86)\Spybot - Search & Destroy\TeaTimer.exe (Safer-Networking Ltd.)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O8:64bit: - Extra context menu item: Append Link Target to Existing PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8:64bit: - Extra context menu item: Append to Existing PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8:64bit: - Extra context menu item: Convert Link Target to Adobe PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8:64bit: - Extra context menu item: Convert to Adobe PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Append Link Target to Existing PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Append to Existing PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert Link Target to Adobe PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert to Adobe PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O9 - Extra 'Tools' menuitem : Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files (x86)\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000004 - mmswsock.dll File not found
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000005 - mmswsock.dll File not found
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000006 - mmswsock.dll File not found
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000007 - mmswsock.dll File not found
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - %SystemRoot%\System32\nwprovau.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000025 - %SystemRoot%\System32\winrnr.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000026 - %SystemRoot%\System32\winrnr.dll File not found
O16:64bit: - DPF: {4871A87A-BFDD-4106-8153-FFDE2BAC2967} http://dlm.tools.akamai.com/dlmanager/vers…x64-2.2.6.0.cab (DLM Control)
O16:64bit: - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} http://download.divx.com/player/DivXBrowserPlugin.cab (Reg Error: Key error.)
O16:64bit: - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} http://download.eset.com/special/eos/OnlineScanner.cab (OnlineScanner Control)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = [removed] [removed]
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{0EBFCCB0-C442-4059-B6BB-CF231475AA84}: DhcpNameServer = [removed] [removed]
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{7D372210-BAD2-4B02-92F2-9B87EC97E0A7}: NameServer = 209.18.47.61,209.18.47.62
O18:64bit: - Protocol\Handler\intu-help-qb2 - No CLSID value found
O18:64bit: - Protocol\Handler\intu-help-qb3 - No CLSID value found
O18:64bit: - Protocol\Handler\intu-help-qb4 - No CLSID value found
O18:64bit: - Protocol\Handler\intu-help-qb5 - No CLSID value found
O18:64bit: - Protocol\Handler\ipp - No CLSID value found
O18:64bit: - Protocol\Handler\ipp\0x00000001 - No CLSID value found
O18:64bit: - Protocol\Handler\msdaipp - No CLSID value found
O18:64bit: - Protocol\Handler\msdaipp\0x00000001 - No CLSID value found
O18:64bit: - Protocol\Handler\msdaipp\oledb - No CLSID value found
O18:64bit: - Protocol\Handler\ms-help - No CLSID value found
O18:64bit: - Protocol\Handler\qbwc - No CLSID value found
O18 - Protocol\Handler\intu-help-qb2 {84D77A00-41B5-4b8b-8ADF-86486D72E749} - C:\Program Files (x86)\Intuit\QuickBooks 2009\HelpAsyncPluggableProtocol.dll (Intuit, Inc.)
O18 - Protocol\Handler\intu-help-qb3 {c5e479ea-0a65-4b05-8c6c-2fc8cc682eb4} - C:\Program Files (x86)\Intuit\QuickBooks 2010\HelpAsyncPluggableProtocol.dll (Intuit, Inc.)
O18 - Protocol\Handler\intu-help-qb4 {ACE22922-D07C-4860-B51B-8CF472FEC2CB} - C:\Program Files (x86)\Intuit\QuickBooks Enterprise Solutions 11.0\HelpAsyncPluggableProtocol.dll (Intuit, Inc.)
O18 - Protocol\Handler\intu-help-qb5 {867FCB77-9823-4cd6-8210-D85F968D466F} - C:\Program Files (x86)\Intuit\QuickBooks 2012\HelpAsyncPluggableProtocol.dll (Intuit, Inc.)
O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11D1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11D1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11D1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysNative\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysWOW64\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *)
O35:64bit: - HKLM\..comfile [open] – "%1" %*
O35:64bit: - HKLM\..exefile [open] – "%1" %*
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37:64bit: - HKLM\…com [@ = ComFile] – "%1" %*
O37:64bit: - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKLM\…com [@ = ComFile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)

NetSvcs:64bit: AppMgmt - C:\Windows\SysNative\appmgmts.dll (Microsoft Corporation)

Drivers32:64bit: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.l3acm - C:\Windows\SysWOW64\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: vidc.cvid - C:\Windows\SysWow64\iccvid.dll (Radius Inc.)

CREATERESTOREPOINT
Restore point Set: OTL Restore Point

========== Files/Folders - Created Within 30 Days ==========

[2012/06/30 13:10:09 | 000,596,992 | —- | C] (OldTimer Tools) – C:\Users\Karl\Desktop\OTL.exe
[2012/06/30 13:03:46 | 000,772,592 | —- | C] (Oracle Corporation) – C:\Windows\SysWow64\npDeployJava1.dll
[2012/06/30 13:03:45 | 000,227,824 | —- | C] (Oracle Corporation) – C:\Windows\SysWow64\javaws.exe
[2012/06/30 13:03:33 | 000,174,064 | —- | C] (Oracle Corporation) – C:\Windows\SysWow64\javaw.exe
[2012/06/30 13:03:33 | 000,174,064 | —- | C] (Oracle Corporation) – C:\Windows\SysWow64\java.exe
[2012/06/30 13:03:27 | 000,000,000 | —D | C] – C:\Program Files (x86)\Java
[2012/06/30 13:03:02 | 021,054,960 | —- | C] (Oracle Corporation) – C:\Users\Karl\Desktop\jre-7u5-windows-i586.exe
[2012/06/30 13:02:19 | 000,955,840 | —- | C] (Oracle Corporation) – C:\Windows\SysNative\npDeployJava1.dll
[2012/06/30 13:02:19 | 000,268,720 | —- | C] (Oracle Corporation) – C:\Windows\SysNative\javaws.exe
[2012/06/30 13:02:07 | 000,189,360 | —- | C] (Oracle Corporation) – C:\Windows\SysNative\javaw.exe
[2012/06/30 13:02:07 | 000,188,840 | —- | C] (Oracle Corporation) – C:\Windows\SysNative\java.exe
[2012/06/30 13:02:02 | 000,000,000 | —D | C] – C:\Program Files\Java
[2012/06/30 13:01:34 | 021,869,488 | —- | C] (Oracle Corporation) – C:\Users\Karl\Desktop\jre-7u5-windows-x64.exe
[2012/06/30 12:55:11 | 000,000,000 | -HSD | C] – C:\Config.Msi
[2012/06/30 08:42:52 | 000,000,000 | —D | C] – C:\Program Files (x86)\ESET
[2012/06/30 08:35:17 | 000,448,512 | —- | C] (OldTimer Tools) – C:\Users\Karl\Desktop\TFC.exe
[2012/06/30 08:24:19 | 000,000,000 | —D | C] – C:\Users\Karl\AppData\Roaming\Malwarebytes
[2012/06/30 08:24:13 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2012/06/30 08:24:12 | 000,024,904 | —- | C] (Malwarebytes Corporation) – C:\Windows\SysNative\drivers\mbam.sys
[2012/06/30 08:24:12 | 000,000,000 | —D | C] – C:\Program Files (x86)\Malwarebytes' Anti-Malware
[2012/06/30 08:24:12 | 000,000,000 | —D | C] – C:\ProgramData\Malwarebytes
[2012/06/30 08:23:26 | 010,063,024 | —- | C] (Malwarebytes Corporation ) – C:\Users\Karl\Desktop\mbam-setup.exe
[2012/06/29 19:46:21 | 000,000,000 | -HSD | C] – C:\$RECYCLE.BIN
[2012/06/29 19:44:33 | 000,000,000 | —D | C] – C:\Windows\temp
[2012/06/29 19:27:36 | 000,518,144 | —- | C] (SteelWerX) – C:\Windows\SWREG.exe
[2012/06/29 19:27:36 | 000,406,528 | —- | C] (SteelWerX) – C:\Windows\SWSC.exe
[2012/06/29 19:27:36 | 000,060,416 | —- | C] (NirSoft) – C:\Windows\NIRCMD.exe
[2012/06/29 19:27:29 | 000,000,000 | —D | C] – C:\Qoobox
[2012/06/29 19:27:08 | 000,000,000 | —D | C] – C:\Windows\erdnt
[2012/06/29 19:25:23 | 004,566,027 | R— | C] (Swearware) – C:\Users\Karl\Desktop\ComboFix.exe
[2012/06/29 08:10:50 | 000,918,016 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\jscript.dll
[2012/06/29 08:10:50 | 000,716,800 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\jscript.dll
[2012/06/29 08:10:44 | 000,735,744 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\msfeeds.dll
[2012/06/29 08:10:43 | 000,097,792 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\mshtmled.dll
[2012/06/29 08:10:43 | 000,067,584 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\mshtmled.dll
[2012/06/29 08:10:42 | 000,247,808 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ieui.dll
[2012/06/29 08:10:42 | 000,176,640 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ieui.dll
[2012/06/29 08:10:42 | 000,134,144 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\url.dll
[2012/06/29 08:10:42 | 000,132,096 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\url.dll
[2012/06/29 08:10:14 | 000,149,504 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\rdpcorekmts.dll
[2012/06/29 08:10:14 | 000,077,312 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\rdpwsx.dll
[2012/06/29 08:10:14 | 000,009,216 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\rdrmemptylst.exe
[2012/06/29 08:09:51 | 005,559,664 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ntoskrnl.exe
[2012/06/29 08:09:49 | 003,968,368 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ntkrnlpa.exe
[2012/06/29 08:09:49 | 003,913,072 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ntoskrnl.exe
[2012/06/29 08:09:32 | 003,216,384 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\msi.dll
[2012/06/29 08:09:26 | 001,462,272 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\crypt32.dll
[2012/06/29 08:09:25 | 000,140,288 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\cryptnet.dll
[2012/06/29 08:03:45 | 004,731,392 | —- | C] (AVAST Software) – C:\Users\Karl\Desktop\aswMBR.exe
[2012/06/29 08:02:47 | 002,622,464 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wucltux.dll
[2012/06/29 08:02:47 | 000,057,880 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wuauclt.exe
[2012/06/29 08:02:47 | 000,044,056 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wups2.dll
[2012/06/29 08:02:30 | 000,701,976 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wuapi.dll
[2012/06/29 08:02:30 | 000,099,840 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wudriver.dll
[2012/06/29 08:02:30 | 000,038,424 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wups.dll
[2012/06/29 08:02:15 | 000,186,752 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wuwebv.dll
[2012/06/29 08:02:15 | 000,036,864 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wuapp.exe
[2012/06/28 13:32:40 | 000,000,000 | —D | C] – C:\Windows\SysNative\MpEngineStore
[2012/06/19 14:38:02 | 000,000,000 | —D | C] – C:\Users\Karl\Desktop\Budget Finance
[2 C:\Users\Karl\AppData\Local\*.tmp files -> C:\Users\Karl\AppData\Local\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2012/06/30 13:10:11 | 000,596,992 | —- | M] (OldTimer Tools) – C:\Users\Karl\Desktop\OTL.exe
[2012/06/30 13:03:28 | 000,772,592 | —- | M] (Oracle Corporation) – C:\Windows\SysWow64\npDeployJava1.dll
[2012/06/30 13:03:28 | 000,687,600 | —- | M] (Oracle Corporation) – C:\Windows\SysWow64\deployJava1.dll
[2012/06/30 13:03:28 | 000,227,824 | —- | M] (Oracle Corporation) – C:\Windows\SysWow64\javaws.exe
[2012/06/30 13:03:28 | 000,174,064 | —- | M] (Oracle Corporation) – C:\Windows\SysWow64\javaw.exe
[2012/06/30 13:03:28 | 000,174,064 | —- | M] (Oracle Corporation) – C:\Windows\SysWow64\java.exe
[2012/06/30 13:03:02 | 021,054,960 | —- | M] (Oracle Corporation) – C:\Users\Karl\Desktop\jre-7u5-windows-i586.exe
[2012/06/30 13:02:02 | 000,955,840 | —- | M] (Oracle Corporation) – C:\Windows\SysNative\npDeployJava1.dll
[2012/06/30 13:02:02 | 000,268,720 | —- | M] (Oracle Corporation) – C:\Windows\SysNative\javaws.exe
[2012/06/30 13:02:02 | 000,189,360 | —- | M] (Oracle Corporation) – C:\Windows\SysNative\javaw.exe
[2012/06/30 13:02:02 | 000,188,840 | —- | M] (Oracle Corporation) – C:\Windows\SysNative\java.exe
[2012/06/30 13:01:34 | 021,869,488 | —- | M] (Oracle Corporation) – C:\Users\Karl\Desktop\jre-7u5-windows-x64.exe
[2012/06/30 12:59:00 | 000,000,894 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2012/06/30 12:23:00 | 000,000,830 | —- | M] () – C:\Windows\tasks\Adobe Flash Player Updater.job
[2012/06/30 08:46:34 | 000,014,848 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2012/06/30 08:46:34 | 000,014,848 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2012/06/30 08:43:34 | 000,792,590 | —- | M] () – C:\Windows\SysNative\PerfStringBackup.INI
[2012/06/30 08:43:34 | 000,669,064 | —- | M] () – C:\Windows\SysNative\perfh009.dat
[2012/06/30 08:43:34 | 000,125,250 | —- | M] () – C:\Windows\SysNative\perfc009.dat
[2012/06/30 08:39:29 | 000,000,890 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2012/06/30 08:39:18 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2012/06/30 08:39:13 | 3220,574,208 | -HS- | M] () – C:\hiberfil.sys
[2012/06/30 08:35:19 | 000,448,512 | —- | M] (OldTimer Tools) – C:\Users\Karl\Desktop\TFC.exe
[2012/06/30 08:24:13 | 000,001,113 | —- | M] () – C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2012/06/30 08:23:40 | 010,063,024 | —- | M] (Malwarebytes Corporation ) – C:\Users\Karl\Desktop\mbam-setup.exe
[2012/06/30 08:21:25 | 000,001,945 | —- | M] () – C:\Windows\epplauncher.mif
[2012/06/29 19:55:13 | 000,809,684 | —- | M] () – C:\Windows\SysWow64\PerfStringBackup.INI
[2012/06/29 19:25:31 | 004,566,027 | R— | M] (Swearware) – C:\Users\Karl\Desktop\ComboFix.exe
[2012/06/29 19:21:41 | 000,367,000 | —- | M] () – C:\Windows\SysNative\FNTCACHE.DAT
[2012/06/29 08:15:58 | 000,000,559 | —- | M] () – C:\Users\Karl\Desktop\MBR.zip
[2012/06/29 08:15:43 | 000,000,512 | —- | M] () – C:\Users\Karl\Desktop\MBR.dat
[2012/06/29 08:04:22 | 004,731,392 | —- | M] (AVAST Software) – C:\Users\Karl\Desktop\aswMBR.exe
[2012/06/27 16:24:13 | 000,000,000 | —- | M] () – C:\Users\Karl\AppData\Local\{1CAC96A0-425A-45FE-A3DE-A7427F550A50}
[2012/06/27 15:34:41 | 000,000,136 | -H– | M] () – C:\ProgramData\-XhbXwlbhQSr92xr
[2012/06/27 15:34:41 | 000,000,000 | -H– | M] () – C:\ProgramData\-XhbXwlbhQSr92x
[2012/06/19 16:56:38 | 000,000,000 | -H– | M] () – C:\Users\Karl\AppData\Local\{CB688969-CB1E-4969-83D1-D09119E78324}
[2012/06/02 17:19:46 | 000,038,424 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\wups.dll
[2012/06/02 17:19:42 | 000,057,880 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\wuauclt.exe
[2012/06/02 17:19:42 | 000,044,056 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\wups2.dll
[2012/06/02 17:19:23 | 000,701,976 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\wuapi.dll
[2012/06/02 17:15:31 | 002,622,464 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\wucltux.dll
[2012/06/02 17:15:08 | 000,099,840 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\wudriver.dll
[2012/06/02 15:19:42 | 000,186,752 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\wuwebv.dll
[2012/06/02 15:15:12 | 000,036,864 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\wuapp.exe
[2 C:\Users\Karl\AppData\Local\*.tmp files -> C:\Users\Karl\AppData\Local\*.tmp -> ]

========== Files Created - No Company Name ==========

[2012/06/30 08:24:13 | 000,001,113 | —- | C] () – C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2012/06/29 19:55:34 | 000,001,945 | —- | C] () – C:\Windows\epplauncher.mif
[2012/06/29 19:27:36 | 000,256,000 | —- | C] () – C:\Windows\PEV.exe
[2012/06/29 19:27:36 | 000,208,896 | —- | C] () – C:\Windows\MBR.exe
[2012/06/29 19:27:36 | 000,098,816 | —- | C] () – C:\Windows\sed.exe
[2012/06/29 19:27:36 | 000,080,412 | —- | C] () – C:\Windows\grep.exe
[2012/06/29 19:27:36 | 000,068,096 | —- | C] () – C:\Windows\zip.exe
[2012/06/29 08:15:58 | 000,000,559 | —- | C] () – C:\Users\Karl\Desktop\MBR.zip
[2012/06/29 08:15:43 | 000,000,512 | —- | C] () – C:\Users\Karl\Desktop\MBR.dat
[2012/06/27 16:23:56 | 000,000,000 | —- | C] () – C:\Users\Karl\AppData\Local\{1CAC96A0-425A-45FE-A3DE-A7427F550A50}
[2012/06/27 15:20:39 | 000,000,136 | -H– | C] () – C:\ProgramData\-XhbXwlbhQSr92xr
[2012/06/27 15:20:38 | 000,000,000 | -H– | C] () – C:\ProgramData\-XhbXwlbhQSr92x
[2012/06/19 16:56:38 | 000,000,000 | -H– | C] () – C:\Users\Karl\AppData\Local\{CB688969-CB1E-4969-83D1-D09119E78324}
[2012/01/09 12:52:06 | 000,000,257 | —- | C] () – C:\Windows\pixcache.ini
[2012/01/09 12:52:05 | 000,000,000 | —- | C] () – C:\Windows\SetScan.ini
[2012/01/09 12:33:28 | 000,000,712 | R— | C] () – C:\Windows\FJTWSTI.INI
[2012/01/06 11:54:25 | 000,003,155 | —- | C] () – C:\Windows\SysWow64\atipblag.dat
[2011/12/28 16:23:48 | 000,009,616 | —- | C] () – C:\Users\Karl\AppData\Local\k6480ph3847nj8n3r544876sfkvmt3wru4ff12
[2011/12/28 16:23:48 | 000,009,616 | —- | C] () – C:\ProgramData\k6480ph3847nj8n3r544876sfkvmt3wru4ff12
[2011/12/22 13:42:37 | 000,009,788 | -HS- | C] () – C:\Users\Karl\AppData\Local\143306s0j286x770y614f0jar4x1
[2011/08/19 21:26:28 | 000,000,186 | —- | C] () – C:\Windows\SysWow64\Gsw32.exe.config
[2011/08/12 16:11:18 | 000,000,092 | -H– | C] () – C:\Users\Karl\AppData\Local\fusioncache.dat
[2011/06/21 16:44:39 | 000,000,208 | —- | C] () – C:\Windows\ODBCINST.INI
[2011/03/07 14:55:52 | 000,809,684 | —- | C] () – C:\Windows\SysWow64\PerfStringBackup.INI
[2011/01/05 10:10:44 | 000,000,384 | —- | C] () – C:\Users\Karl\CJB Farms, Inc.QBW.DSN
[2011/01/05 10:10:44 | 000,000,334 | -H– | C] () – C:\Users\Karl\CJB Farms, Inc.QBW.ND
[2011/01/05 10:09:22 | 003,735,552 | RH– | C] () – C:\Users\Karl\CJB Farms, Inc.QBW.TLG
[2011/01/05 10:09:21 | 020,557,824 | RH– | C] () – C:\Users\Karl\CJB Farms, Inc.QBW
[2011/01/05 09:44:03 | 000,000,384 | —- | C] () – C:\Users\Karl\B5 Land and Cattle Company.QBW.DSN
[2011/01/05 09:44:03 | 000,000,346 | -H– | C] () – C:\Users\Karl\B5 Land and Cattle Company.QBW.ND
[2011/01/05 09:42:54 | 002,359,296 | RH– | C] () – C:\Users\Karl\B5 Land and Cattle Company.QBW.TLG
[2011/01/05 09:42:53 | 009,875,456 | RH– | C] () – C:\Users\Karl\B5 Land and Cattle Company.QBW
[2010/12/22 11:01:55 | 005,771,264 | -H– | C] () – C:\Users\Karl\B5 Land and Cattle Company 12-16-10 (Backup Dec 22,2010 10 01 AM).QBB
[2010/12/22 10:00:14 | 000,000,095 | —- | C] () – C:\Windows\QBChanUtil_Trigger.ini
[2010/12/06 15:03:59 | 000,000,490 | —- | C] () – C:\Windows\ODBC.INI
[2010/12/06 10:38:32 | 000,000,000 | —- | C] () – C:\Windows\ativpsrm.bin
[2010/12/06 10:35:41 | 000,024,576 | —- | C] () – C:\Windows\SysWow64\AsIO.dll
[2010/12/06 10:35:41 | 000,013,440 | —- | C] () – C:\Windows\SysWow64\drivers\AsIO.sys
[2010/12/06 10:12:18 | 000,039,266 | —- | C] () – C:\Windows\Ascd_log.ini
[2010/12/06 10:11:26 | 000,001,769 | —- | C] () – C:\Windows\Language_trs.ini
[2010/12/06 10:11:21 | 000,031,453 | —- | C] () – C:\Windows\Ascd_tmp.ini

========== LOP Check ==========

[2012/06/28 16:31:51 | 000,000,000 | —D | M] – C:\Users\Karl\AppData\Roaming\Fujitsu
[2010/12/06 11:37:32 | 000,000,000 | -H-D | M] – C:\Users\Karl\AppData\Roaming\Leadertech
[2012/06/28 16:32:04 | 000,000,000 | —D | M] – C:\Users\Karl\AppData\Roaming\PFU
[2012/06/05 10:14:47 | 000,000,000 | -H-D | M] – C:\Users\Karl\AppData\Roaming\PrimoPDF
[2012/06/28 16:39:10 | 000,000,000 | —D | M] – C:\Users\Karl\AppData\Roaming\RFFlow
[2011/06/15 10:29:40 | 000,000,000 | -H-D | M] – C:\Users\Karl\AppData\Roaming\webex
[2012/02/21 09:44:10 | 000,032,602 | —- | M] () – C:\Windows\Tasks\SCHEDLGU.TXT

========== Purity Check ==========



========== Custom Scans ==========

< %SYSTEMDRIVE%\*.* >
[2012/06/29 19:44:32 | 000,015,237 | —- | M] () – C:\ComboFix.txt
[2012/06/30 08:39:13 | 3220,574,208 | -HS- | M] () – C:\hiberfil.sys
[2006/12/02 00:37:14 | 000,904,704 | —- | M] (Microsoft Corporation) – C:\msdia80.dll
[2012/06/30 08:39:17 | 4294,103,040 | -HS- | M] () – C:\pagefile.sys

< %systemroot%\Fonts\*.com >
[2009/07/14 00:32:31 | 000,026,040 | —- | M] () – C:\Windows\Fonts\GlobalMonospace.CompositeFont
[2009/07/14 00:32:31 | 000,026,489 | —- | M] () – C:\Windows\Fonts\GlobalSansSerif.CompositeFont
[2009/07/14 00:32:31 | 000,029,779 | —- | M] () – C:\Windows\Fonts\GlobalSerif.CompositeFont
[2009/07/14 00:32:31 | 000,043,318 | —- | M] () – C:\Windows\Fonts\GlobalUserInterface.CompositeFont

< %systemroot%\Fonts\*.dll >

< %systemroot%\Fonts\*.ini >
[2009/06/10 15:49:50 | 000,000,065 | —- | M] () – C:\Windows\Fonts\desktop.ini

< %systemroot%\Fonts\*.ini2 >

< %systemroot%\Fonts\*.exe >

< %systemroot%\system32\spool\prtprocs\w32x86\*.* >

< %systemroot%\REPAIR\*.bak1 >

< %systemroot%\REPAIR\*.ini >

< %systemroot%\system32\*.jpg >

< %systemroot%\*.jpg >

< %systemroot%\*.png >

< %systemroot%\*.scr >

< %systemroot%\*._sy >

< %APPDATA%\Adobe\Update\*.* >

< %ALLUSERSPROFILE%\Favorites\*.* >

< %APPDATA%\Microsoft\*.* >

< %PROGRAMFILES%\*.* >
[2009/07/13 23:54:24 | 000,000,174 | -HS- | M] () – C:\Program Files (x86)\desktop.ini

< %APPDATA%\Update\*.* >

< %systemroot%\*. /mp /s >

< %systemroot%\System32\config\*.sav >

< %PROGRAMFILES%\bak. /s >

< %systemroot%\system32\bak. /s >

< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >

< %systemroot%\system32\config\systemprofile\*.dat /x >

< %systemroot%\*.config >

< %systemroot%\system32\*.db >

< %PROGRAMFILES%\Internet Explorer\*.dat >

< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2010/12/06 10:15:53 | 000,000,221 | -HS- | M] () – C:\Users\Karl\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\desktop.ini

< %USERPROFILE%\Desktop\*.exe >
[2011/09/21 13:55:56 | 487,666,616 | —- | M] (Adobe Systems Incorporated) – C:\Users\Karl\Desktop\AcrobatPro_10_Web_WWEFD.exe
[2012/06/29 08:04:22 | 004,731,392 | —- | M] (AVAST Software) – C:\Users\Karl\Desktop\aswMBR.exe
[2012/06/29 19:25:31 | 004,566,027 | R— | M] (Swearware) – C:\Users\Karl\Desktop\ComboFix.exe
[2012/06/30 13:03:02 | 021,054,960 | —- | M] (Oracle Corporation) – C:\Users\Karl\Desktop\jre-7u5-windows-i586.exe
[2012/06/30 13:01:34 | 021,869,488 | —- | M] (Oracle Corporation) – C:\Users\Karl\Desktop\jre-7u5-windows-x64.exe
[2012/06/30 08:23:40 | 010,063,024 | —- | M] (Malwarebytes Corporation ) – C:\Users\Karl\Desktop\mbam-setup.exe
[2012/06/30 13:10:11 | 000,596,992 | —- | M] (OldTimer Tools) – C:\Users\Karl\Desktop\OTL.exe
[2012/06/30 08:35:19 | 000,448,512 | —- | M] (OldTimer Tools) – C:\Users\Karl\Desktop\TFC.exe

< %PROGRAMFILES%\Common Files\*.* >

< %systemroot%\*.src >

< %systemroot%\install\*.* >

< %systemroot%\system32\DLL\*.* >

< %systemroot%\system32\HelpFiles\*.* >

< %systemroot%\system32\rundll\*.* >

< %systemroot%\winn32\*.* >

< %systemroot%\Java\*.* >

< %systemroot%\system32\test\*.* >

< %systemroot%\system32\Rundll32\*.* >

< %systemroot%\AppPatch\Custom\*.* >

< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >

< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >

< >

< >

< End of report >
  • OTL

    Run OTL.exe.

  • Copy/paste the following text written inside of the code box into the Custom Scans/Fixes box located at the bottom of OTL.

    :OTL
    IE - HKCU\..\SearchScopes\{EE8F44DF-6319-4466-BD9D-D72454A5D0C1}: "URL" = http://mp3tubetoolbar.com/?tmp=toolbar_sb_…3e6e90329bbfee7
    [2 C:\Users\Karl\AppData\Local\*.tmp files -> C:\Users\Karl\AppData\Local\*.tmp -> ]
    [2012/06/27 16:24:13 | 000,000,000 | —- | M] () – C:\Users\Karl\AppData\Local\{1CAC96A0-425A-45FE-A3DE-A7427F550A50}
    [2012/06/27 15:34:41 | 000,000,136 | -H– | M] () – C:\ProgramData\-XhbXwlbhQSr92xr
    [2012/06/27 15:34:41 | 000,000,000 | -H– | M] () – C:\ProgramData\-XhbXwlbhQSr92x
    [2012/06/19 16:56:38 | 000,000,000 | -H– | M] () – C:\Users\Karl\AppData\Local\{CB688969-CB1E-4969-83D1-D09119E78324}
    [2011/12/28 16:23:48 | 000,009,616 | —- | C] () – C:\Users\Karl\AppData\Local\k6480ph3847nj8n3r544876sfkvmt3wru4ff12
    [2011/12/28 16:23:48 | 000,009,616 | —- | C] () – C:\ProgramData\k6480ph3847nj8n3r544876sfkvmt3wru4ff12
    [2011/12/22 13:42:37 | 000,009,788 | -HS- | C] () – C:\Users\Karl\AppData\Local\143306s0j286x770y614f0jar4x1
    
    :Commands
    [createrestorepoint]
    [purity]
    [resethosts]
    [emptytemp]

  • Click the Run Fix button.
  • OTL will now process the instructions.
  • When finished a box will open asking you to open the fix log, click OK.
  • The fix log will open.
  • Copy/Paste the log in your next reply please.

Note: If necessary, OTL may reboot your computer, or request that you do so. If it does, please go ahead and reboot your machine. After rebooting, open up Windows Explorer (Windows Key +E) and navigate to C:\_OTL\MovedFiles. Within, you should find a .log file with the format mmddyyyy_hhmmss, which represents the date and time the fix was run. Please copy and paste the contents of that file, making sure Word Wrap is off beforehand, if necessary.
Hi Michael!! I ran OTL according to your instructions. First I got a message "Cannot create file c:\windows\system32\drives\etc\hosts." as it began running. Now OTL appears to be "hung" at the point where the message "Resetting HOSTS file. DO NOT INTERRUPT…" appears at the bottom of the OTL program. So far it has been on that message for over an hour. I opened Windows Task Manager, and OTL appears not to be using any CPU time at all. It is consistently showing zeros for OTL.exe. What should I do next?
Hi redder,

Try this instead:

  • OTL

    Run OTL.exe.

  • Copy/paste the following text written inside of the code box into the Custom Scans/Fixes box located at the bottom of OTL.

    :OTL
    IE - HKCU\..\SearchScopes\{EE8F44DF-6319-4466-BD9D-D72454A5D0C1}: "URL" = http://mp3tubetoolbar.com/?tmp=toolbar_sb_…3e6e90329bbfee7
    [2 C:\Users\Karl\AppData\Local\*.tmp files -> C:\Users\Karl\AppData\Local\*.tmp -> ]
    [2012/06/27 16:24:13 | 000,000,000 | —- | M] () – C:\Users\Karl\AppData\Local\{1CAC96A0-425A-45FE-A3DE-A7427F550A50}
    [2012/06/27 15:34:41 | 000,000,136 | -H– | M] () – C:\ProgramData\-XhbXwlbhQSr92xr
    [2012/06/27 15:34:41 | 000,000,000 | -H– | M] () – C:\ProgramData\-XhbXwlbhQSr92x
    [2012/06/19 16:56:38 | 000,000,000 | -H– | M] () – C:\Users\Karl\AppData\Local\{CB688969-CB1E-4969-83D1-D09119E78324}
    [2011/12/28 16:23:48 | 000,009,616 | —- | C] () – C:\Users\Karl\AppData\Local\k6480ph3847nj8n3r544876sfkvmt3wru4ff12
    [2011/12/28 16:23:48 | 000,009,616 | —- | C] () – C:\ProgramData\k6480ph3847nj8n3r544876sfkvmt3wru4ff12
    [2011/12/22 13:42:37 | 000,009,788 | -HS- | C] () – C:\Users\Karl\AppData\Local\143306s0j286x770y614f0jar4x1
    
    :Commands
    [createrestorepoint]
    [purity]
    [emptytemp]

  • Click the Run Fix button.
  • OTL will now process the instructions.
  • When finished a box will open asking you to open the fix log, click OK.
  • The fix log will open.
  • Copy/Paste the log in your next reply please.

Note: If necessary, OTL may reboot your computer, or request that you do so. If it does, please go ahead and reboot your machine. After rebooting, open up Windows Explorer (Windows Key +E) and navigate to C:\_OTL\MovedFiles. Within, you should find a .log file with the format mmddyyyy_hhmmss, which represents the date and time the fix was run. Please copy and paste the contents of that file, making sure Word Wrap is off beforehand, if necessary.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI