This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Trojan:Win32/Sirefer.AB and Trojan :Win64/Sirefef.P [Solved]

15 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi Michael!! When I clicked to close the "hung" program OTL, as it closed, it opened this log file: Files\Folders moved on Reboot… File move failed. C:\Windows\System32\drivers\etc\Hosts scheduled to be moved on reboot. PendingFileRenameOperations files… [2011/12/23 09:07:32 | 000,001,395 | RHS- | M] () C:\Windows\System32\drivers\etc\Hosts : MD5=D48381E3E119679FD18DB3D1DA0EF406 Registry entries deleted on Reboot… ———————————————————————- Then I reran OTL using the changed commands that you suggested. This time it finished with no problems, and after rebooting, and it gave me this log: All processes killed ========== OTL ========== Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{EE8F44DF-6319-4466-BD9D-D72454A5D0C1}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{EE8F44DF-6319-4466-BD9D-D72454A5D0C1}\ not found. File/Folder C:\Users\Karl\AppData\Local\*.tmp not found. File C:\Users\Karl\AppData\Local\{1CAC96A0-425A-45FE-A3DE-A7427F550A50} not found. File C:\ProgramData\-XhbXwlbhQSr92xr not found. File C:\ProgramData\-XhbXwlbhQSr92x not found. File C:\Users\Karl\AppData\Local\{CB688969-CB1E-4969-83D1-D09119E78324} not found. File C:\Users\Karl\AppData\Local\k6480ph3847nj8n3r544876sfkvmt3wru4ff12 not found. File C:\ProgramData\k6480ph3847nj8n3r544876sfkvmt3wru4ff12 not found. File C:\Users\Karl\AppData\Local\143306s0j286x770y614f0jar4x1 not found. ========== COMMANDS ========== Restore point Set: OTL Restore Point [EMPTYTEMP] User: All Users User: Default ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes User: Default User ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes User: Karl ->Temp folder emptied: 119537 bytes ->Temporary Internet Files folder emptied: 18636819 bytes ->Java cache emptied: 1 bytes ->Flash cache emptied: 1611 bytes User: Public ->Temp folder emptied: 0 bytes %systemdrive% .tmp files removed: 0 bytes %systemroot% .tmp files removed: 0 bytes %systemroot%\System32 .tmp files removed: 0 bytes %systemroot%\System32 (64bit) .tmp files removed: 0 bytes %systemroot%\System32\drivers .tmp files removed: 0 bytes Windows Temp folder emptied: 2966 bytes %systemroot%\sysnative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 33170 bytes %systemroot%\sysnative\config\systemprofile\AppData\LocalLow\Sun\Java\Deployment folder emptied: 666 bytes RecycleBin emptied: 0 bytes Total Files Cleaned = 18.00 mb OTL by OldTimer - Version 3.2.53.0 log created on 07012012_110227 Files\Folders moved on Reboot… C:\Users\Karl\AppData\Local\Temp\FXSAPIDebugLogFile.txt moved successfully. C:\Users\Karl\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\UJH2JPQK\header-728-90[1].htm moved successfully. C:\Users\Karl\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\UJH2JPQK\si[7].htm moved successfully. C:\Users\Karl\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\UJH2JPQK\tag_tlvmedia_com[2].htm moved successfully. C:\Users\Karl\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\RLE0MJIL\adoapn_AppNexusDemoActionTag_1[1].htm moved successfully. C:\Users\Karl\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\RLE0MJIL\iframe[1].htm moved successfully. C:\Users\Karl\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\RLE0MJIL\jstagsCANEG2XZ.htm moved successfully. C:\Users\Karl\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\RLE0MJIL\search[1].htm moved successfully. C:\Users\Karl\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\OOTZRO0Q\st[1].htm moved successfully. C:\Users\Karl\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\HMZ97UQF\bv[1].htm moved successfully. C:\Users\Karl\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\HMZ97UQF\index[5].htm moved successfully. C:\Users\Karl\AppData\Local\Microsoft\Windows\Temporary Internet Files\AntiPhishing\2CEDBFBC-DBA8-43AA-B1FD-CC8E6316E3E2.dat moved successfully. PendingFileRenameOperations files… File C:\Users\Karl\AppData\Local\Temp\FXSAPIDebugLogFile.txt not found! File C:\Users\Karl\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\UJH2JPQK\header-728-90[1].htm not found! File C:\Users\Karl\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\UJH2JPQK\si[7].htm not found! File C:\Users\Karl\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\UJH2JPQK\tag_tlvmedia_com[2].htm not found! File C:\Users\Karl\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\RLE0MJIL\adoapn_AppNexusDemoActionTag_1[1].htm not found! File C:\Users\Karl\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\RLE0MJIL\iframe[1].htm not found! File C:\Users\Karl\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\RLE0MJIL\jstagsCANEG2XZ.htm not found! File C:\Users\Karl\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\RLE0MJIL\search[1].htm not found! File C:\Users\Karl\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\OOTZRO0Q\st[1].htm not found! File C:\Users\Karl\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\HMZ97UQF\bv[1].htm not found! File C:\Users\Karl\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\HMZ97UQF\index[5].htm not found! File C:\Users\Karl\AppData\Local\Microsoft\Windows\Temporary Internet Files\AntiPhishing\2CEDBFBC-DBA8-43AA-B1FD-CC8E6316E3E2.dat not found! Registry entries deleted on Reboot…
download Farbar Recovery Scan Tool 64-Bit and save it to a flash drive.

Plug the flashdrive into the infected PC.

Enter System Recovery Options.

To enter System Recovery Options from the Advanced Boot Options:
  • Restart the computer.
  • As soon as the BIOS is loaded begin tapping the F8 key until Advanced Boot Options appears.
  • Use the arrow keys to select the Repair your computer menu item.
  • Select US as the keyboard language settings, and then click Next.
  • Select the operating system you want to repair, and then click Next.
  • Select your user account an click Next.

To enter System Recovery Options by using Windows installation disc:
  • Insert the installation disc.
  • Restart your computer.
  • If prompted, press any key to start Windows from the installation disc. If your computer is not configured to start from a CD or DVD, check your BIOS settings.
  • Click Repair your computer.
  • Select US as the keyboard language settings, and then click Next.
  • Select the operating system you want to repair, and then click Next.
  • Select your user account and click Next.

On the System Recovery Options menu you will get the following options:Startup Repair
System Restore
Windows Complete PC Restore
Windows Memory Diagnostic Tool
Command Prompt

[*]Select Command Prompt

[*]In the command window type in notepad and press Enter.

[*]The notepad opens. Under File menu select Open.

[*]Select "Computer" and find your flash drive letter and close the notepad.

[*]In the command window type e:\frst64) and press Enter

Note: Replace letter e with the drive letter of your flash drive.
[*]The tool will start to run.

[*]When the tool opens click Yes to disclaimer.

[*]Press Scan button.

[*]It will make a log (FRST.txt) on the flash drive. Please copy and paste it to your reply.

Hi Michael!! Here is the log from FRST: Scan result of Farbar Recovery Scan Tool Version: 01-07-2012 Ran by [removed] at 01-07-2012 11:54:18 Running from F:\ Windows 7 Professional (X64) OS Language: English(US) The current controlset is ControlSet001 ========================== Registry (Whitelisted) ============= HKLM\…\Run: [ATIModeChange] Ati2mdxx.exe [x] HKLM-x32\…\Run: [Adobe Acrobat Speed Launcher] "C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Acrobat_sl.exe" [36760 2012-04-03] (Adobe Systems Incorporated) HKLM-x32\…\Run: [Acrobat Assistant 8.0] "C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Acrotray.exe" [815512 2012-04-03] (Adobe Systems Inc.) HKLM-x32\…\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [843712 2012-01-02] (Adobe Systems Incorporated) HKLM-x32\…\Run: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun [98304 2011-03-21] (Advanced Micro Devices, Inc.) HKLM-x32\…\Run: [FJTWAIN Setup] C:\Windows\Twain_32\fjscan32\FjtwMkup.exe /Station [131072 2009-07-08] (FUJITSU LIMITED) HKLM-x32\…\Run: [FTPWRENV] C:\Windows\Twain_32\Fjscan32\FTPWREVT\FTPWREVT.exe [45056 2007-10-16] (PFU LIMITED) HKLM-x32\…\Run: [FiWIA Service Checker] C:\Windows\Twain_32\Fjscan32\FiWiaChecker.exe [86016 2009-10-21] (PFU LIMITED) HKU\Karl\…\Run: [swg] "C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [39408 2011-11-28] (Google Inc.) HKU\Karl\…\Run: [SpybotSD TeaTimer] C:\Program Files (x86)\Spybot - Search & Destroy\TeaTimer.exe [2260480 2009-03-05] (Safer-Networking Ltd.) Tcpip\Parameters: [DhcpNameServer] [removed] [removed] Tcpip\..\Interfaces\{7D372210-BAD2-4B02-92F2-9B87EC97E0A7}: [NameServer]209.18.47.61,209.18.47.62 Startup: C:\Users\All Users\Start Menu\Programs\Startup\CardMinder Viewer.lnk ShortcutTarget: CardMinder Viewer.lnk -> C:\Program Files (x86)\PFU\CardMinder V3.2\CardLauncher.exe (PFU Limited.) Startup: C:\Users\All Users\Start Menu\Programs\Startup\CS Connect Background Services.lnk ShortcutTarget: CS Connect Background Services.lnk -> (No File) Startup: C:\Users\All Users\Start Menu\Programs\Startup\Intuit Data Protect.lnk ShortcutTarget: Intuit Data Protect.lnk -> C:\Program Files (x86)\Common Files\Intuit\DataProtect\IntuitDataProtect.exe (Intuit Inc.) ==================== Services (Whitelisted) ====== 2 CSAPrintService; C:\Windows\csasvc.exe [118784 2009-11-10] (Thomson Reuters) 2 FCPrintService; C:\Windows\csifcsvc.exe [136192 2011-10-30] (Thomson Reuters) 2 FJTWMKSV; C:\Windows\twain_32\fjscan32\FJTWMKSV.exe [45056 2007-03-08] (PFU LIMITED) 4 NetTcpPortSharing; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [124240 2010-03-18] (Microsoft Corporation) 2 QBCFMonitorService; "C:\Program Files (x86)\Common Files\Intuit\QuickBooks\QBCFMonitorService.exe" [45056 2011-08-19] (Intuit) 3 QBFCService; "C:\Program Files (x86)\Common Files\Intuit\QuickBooks\FCS\Intuit.QuickBooks.FCS.exe" [61440 2009-07-23] (Intuit Inc.) 2 QBVSS; "C:\Program Files (x86)\Common Files\Intuit\DataProtect\QBIDPService.exe" [1248256 2011-08-19] (Intuit Inc.) 2 SBSDWSCService; C:\Program Files (x86)\Spybot - Search & Destroy\SDWinSec.exe [1153368 2009-01-26] (Safer Networking Ltd.) ========================== Drivers (Whitelisted) ============= 3 AN983X64; C:\Windows\System32\Drivers\AN983X64.sys [48128 2005-05-19] (Infineon Technologies AG) 1 AsIO; C:\Windows\SysWow64\Drivers\AsIO.sys [13440 2009-08-03] () 3 MTsensor; C:\Windows\System32\DRIVERS\ASACPI.sys [15416 2009-07-15] () 3 catchme; \??\C:\ComboFix\catchme.sys [x] ========================== NetSvcs (Whitelisted) =========== ============ One Month Created Files and Folders ============== 2012-07-01 08:00 - 2012-07-01 08:00 - 00000672 ____A C:\Users\Karl\Desktop\06302012_153109.log 2012-06-30 12:31 - 2012-06-30 12:31 - 00000000 ____D C:\_OTL 2012-06-30 10:10 - 2012-06-30 10:10 - 00596992 ____A (OldTimer Tools) C:\Users\Karl\Desktop\OTL.exe 2012-06-30 10:03 - 2012-06-30 10:03 - 21054960 ____A (Oracle Corporation) C:\Users\Karl\Desktop\jre-7u5-windows-i586.exe 2012-06-30 10:03 - 2012-06-30 10:03 - 00772592 ____A (Oracle Corporation) C:\Windows\SysWOW64\npDeployJava1.dll 2012-06-30 10:03 - 2012-06-30 10:03 - 00227824 ____A (Oracle Corporation) C:\Windows\SysWOW64\javaws.exe 2012-06-30 10:03 - 2012-06-30 10:03 - 00174064 ____A (Oracle Corporation) C:\Windows\SysWOW64\javaw.exe 2012-06-30 10:03 - 2012-06-30 10:03 - 00174064 ____A (Oracle Corporation) C:\Windows\SysWOW64\java.exe 2012-06-30 10:03 - 2012-06-30 10:03 - 00000000 ____D C:\Program Files (x86)\Java 2012-06-30 10:02 - 2012-06-30 10:02 - 00955840 ____A (Oracle Corporation) C:\Windows\System32\npDeployJava1.dll 2012-06-30 10:02 - 2012-06-30 10:02 - 00268720 ____A (Oracle Corporation) C:\Windows\System32\javaws.exe 2012-06-30 10:02 - 2012-06-30 10:02 - 00189360 ____A (Oracle Corporation) C:\Windows\System32\javaw.exe 2012-06-30 10:02 - 2012-06-30 10:02 - 00188840 ____A (Oracle Corporation) C:\Windows\System32\java.exe 2012-06-30 10:02 - 2012-06-30 10:02 - 00000000 ____D C:\Program Files\Java 2012-06-30 10:01 - 2012-06-30 10:01 - 21869488 ____A (Oracle Corporation) C:\Users\Karl\Desktop\jre-7u5-windows-x64.exe 2012-06-30 07:03 - 2012-06-30 07:03 - 00000452 ____A C:\Users\Karl\Desktop\eset.txt 2012-06-30 05:42 - 2012-06-30 05:42 - 00000000 ____D C:\Program Files (x86)\ESET 2012-06-30 05:35 - 2012-06-30 05:35 - 00448512 ____A (OldTimer Tools) C:\Users\Karl\Desktop\TFC.exe 2012-06-30 05:35 - 2012-06-30 05:35 - 00001653 ____A C:\Users\Karl\Desktop\anti malware.txt 2012-06-30 05:34 - 2012-06-30 05:34 - 00000000 ____A C:\Users\Karl\Desktop\New Text Document.txt 2012-06-30 05:24 - 2012-06-30 05:24 - 00001113 ____A C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk 2012-06-30 05:24 - 2012-06-30 05:24 - 00000000 ____D C:\Users\Karl\AppData\Roaming\Malwarebytes 2012-06-30 05:24 - 2012-06-30 05:24 - 00000000 ____D C:\Users\All Users\Malwarebytes 2012-06-30 05:24 - 2012-06-30 05:24 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware 2012-06-30 05:24 - 2012-04-04 12:56 - 00024904 ____A (Malwarebytes Corporation) C:\Windows\System32\Drivers\mbam.sys 2012-06-30 05:23 - 2012-06-30 05:23 - 10063024 ____A (Malwarebytes Corporation ) C:\Users\Karl\Desktop\mbam-setup.exe 2012-06-29 16:55 - 2012-06-30 05:21 - 00001945 ____A C:\Windows\epplauncher.mif 2012-06-29 16:44 - 2012-06-29 16:44 - 00015237 ____A C:\ComboFix.txt 2012-06-29 16:27 - 2012-06-29 16:44 - 00000000 ____D C:\Qoobox 2012-06-29 16:27 - 2012-06-29 16:43 - 00000000 ____D C:\Windows\erdnt 2012-06-29 16:27 - 2011-06-25 22:45 - 00256000 ____A C:\Windows\PEV.exe 2012-06-29 16:27 - 2010-11-07 09:20 - 00208896 ____A C:\Windows\MBR.exe 2012-06-29 16:27 - 2009-04-19 20:56 - 00060416 ____A (NirSoft) C:\Windows\NIRCMD.exe 2012-06-29 16:27 - 2000-08-30 16:00 - 00518144 ____A (SteelWerX) C:\Windows\SWREG.exe 2012-06-29 16:27 - 2000-08-30 16:00 - 00406528 ____A (SteelWerX) C:\Windows\SWSC.exe 2012-06-29 16:27 - 2000-08-30 16:00 - 00098816 ____A C:\Windows\sed.exe 2012-06-29 16:27 - 2000-08-30 16:00 - 00080412 ____A C:\Windows\grep.exe 2012-06-29 16:27 - 2000-08-30 16:00 - 00068096 ____A C:\Windows\zip.exe 2012-06-29 16:25 - 2012-06-29 16:25 - 04566027 ____R (Swearware) C:\Users\Karl\Desktop\ComboFix.exe 2012-06-29 05:15 - 2012-06-29 05:15 - 00002399 ____A C:\Users\Karl\Desktop\aswMBR.txt 2012-06-29 05:15 - 2012-06-29 05:15 - 00000559 ____A C:\Users\Karl\Desktop\MBR.zip 2012-06-29 05:15 - 2012-06-29 05:15 - 00000512 ____A C:\Users\Karl\Desktop\MBR.dat 2012-06-29 05:10 - 2012-05-14 20:01 - 01188864 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll 2012-06-29 05:10 - 2012-05-14 19:59 - 00064512 ____A (Microsoft Corporation) C:\Windows\System32\jsproxy.dll 2012-06-29 05:10 - 2012-05-14 19:03 - 00981504 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2012-06-29 05:10 - 2012-05-14 19:00 - 00048128 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2012-06-29 05:10 - 2012-04-25 21:41 - 00149504 ____A (Microsoft Corporation) C:\Windows\System32\rdpcorekmts.dll 2012-06-29 05:10 - 2012-04-25 21:41 - 00077312 ____A (Microsoft Corporation) C:\Windows\System32\rdpwsx.dll 2012-06-29 05:10 - 2012-04-25 21:34 - 00009216 ____A (Microsoft Corporation) C:\Windows\System32\rdrmemptylst.exe 2012-06-29 05:10 - 2012-04-19 21:42 - 12297216 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll 2012-06-29 05:10 - 2012-04-19 21:42 - 09059840 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll 2012-06-29 05:10 - 2012-04-19 21:42 - 02454528 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll 2012-06-29 05:10 - 2012-04-19 21:42 - 01494016 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll 2012-06-29 05:10 - 2012-04-19 21:42 - 00735744 ____A (Microsoft Corporation) C:\Windows\System32\msfeeds.dll 2012-06-29 05:10 - 2012-04-19 21:42 - 00247808 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll 2012-06-29 05:10 - 2012-04-19 21:42 - 00134144 ____A (Microsoft Corporation) C:\Windows\System32\url.dll 2012-06-29 05:10 - 2012-04-19 21:42 - 00097792 ____A (Microsoft Corporation) C:\Windows\System32\mshtmled.dll 2012-06-29 05:10 - 2012-04-19 21:00 - 01231360 ____A (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2012-06-29 05:10 - 2012-04-19 21:00 - 00132096 ____A (Microsoft Corporation) C:\Windows\SysWOW64\url.dll 2012-06-29 05:10 - 2012-04-19 20:57 - 06027776 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2012-06-29 05:10 - 2012-04-19 20:57 - 00627712 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2012-06-29 05:10 - 2012-04-19 20:57 - 00067584 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll 2012-06-29 05:10 - 2012-04-19 20:56 - 11020800 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2012-06-29 05:10 - 2012-04-19 20:56 - 02073600 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2012-06-29 05:10 - 2012-04-19 20:56 - 00176640 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll 2012-06-29 05:10 - 2012-04-19 19:45 - 01638912 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb 2012-06-29 05:10 - 2012-04-19 19:16 - 01638912 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2012-06-29 05:10 - 2012-04-16 21:31 - 00918016 ____A (Microsoft Corporation) C:\Windows\System32\jscript.dll 2012-06-29 05:10 - 2012-04-16 20:34 - 00716800 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll 2012-06-29 05:09 - 2012-05-14 17:32 - 03146752 ____A (Microsoft Corporation) C:\Windows\System32\win32k.sys 2012-06-29 05:09 - 2012-05-04 03:06 - 05559664 ____A (Microsoft Corporation) C:\Windows\System32\ntoskrnl.exe 2012-06-29 05:09 - 2012-05-04 02:03 - 03968368 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe 2012-06-29 05:09 - 2012-05-04 02:03 - 03913072 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe 2012-06-29 05:09 - 2012-04-30 21:40 - 00209920 ____A (Microsoft Corporation) C:\Windows\System32\profsvc.dll 2012-06-29 05:09 - 2012-04-27 19:55 - 00210944 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\rdpwd.sys 2012-06-29 05:09 - 2012-04-23 21:37 - 01462272 ____A (Microsoft Corporation) C:\Windows\System32\crypt32.dll 2012-06-29 05:09 - 2012-04-23 21:37 - 00184320 ____A (Microsoft Corporation) C:\Windows\System32\cryptsvc.dll 2012-06-29 05:09 - 2012-04-23 21:37 - 00140288 ____A (Microsoft Corporation) C:\Windows\System32\cryptnet.dll 2012-06-29 05:09 - 2012-04-23 20:36 - 01158656 ____A (Microsoft Corporation) C:\Windows\SysWOW64\crypt32.dll 2012-06-29 05:09 - 2012-04-23 20:36 - 00140288 ____A (Microsoft Corporation) C:\Windows\SysWOW64\cryptsvc.dll 2012-06-29 05:09 - 2012-04-23 20:36 - 00103936 ____A (Microsoft Corporation) C:\Windows\SysWOW64\cryptnet.dll 2012-06-29 05:09 - 2012-04-07 04:31 - 03216384 ____A (Microsoft Corporation) C:\Windows\System32\msi.dll 2012-06-29 05:09 - 2012-04-07 03:26 - 02342400 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msi.dll 2012-06-29 05:03 - 2012-06-29 05:04 - 04731392 ____A (AVAST Software) C:\Users\Karl\Desktop\aswMBR.exe 2012-06-29 05:02 - 2012-06-02 14:19 - 02428952 ____A (Microsoft Corporation) C:\Windows\System32\wuaueng.dll 2012-06-29 05:02 - 2012-06-02 14:19 - 00701976 ____A (Microsoft Corporation) C:\Windows\System32\wuapi.dll 2012-06-29 05:02 - 2012-06-02 14:19 - 00057880 ____A (Microsoft Corporation) C:\Windows\System32\wuauclt.exe 2012-06-29 05:02 - 2012-06-02 14:19 - 00044056 ____A (Microsoft Corporation) C:\Windows\System32\wups2.dll 2012-06-29 05:02 - 2012-06-02 14:19 - 00038424 ____A (Microsoft Corporation) C:\Windows\System32\wups.dll 2012-06-29 05:02 - 2012-06-02 14:15 - 02622464 ____A (Microsoft Corporation) C:\Windows\System32\wucltux.dll 2012-06-29 05:02 - 2012-06-02 14:15 - 00099840 ____A (Microsoft Corporation) C:\Windows\System32\wudriver.dll 2012-06-29 05:02 - 2012-06-02 12:19 - 00186752 ____A (Microsoft Corporation) C:\Windows\System32\wuwebv.dll 2012-06-29 05:02 - 2012-06-02 12:15 - 00036864 ____A (Microsoft Corporation) C:\Windows\System32\wuapp.exe 2012-06-28 12:51 - 2012-06-30 10:18 - 00072074 ____A C:\Users\Karl\Desktop\Extras.Txt 2012-06-28 12:49 - 2012-06-30 10:16 - 00088140 ____A C:\Users\Karl\Desktop\OTL.Txt 2012-06-28 10:32 - 2012-06-28 14:06 - 00000000 ____D C:\Windows\System32\MpEngineStore 2012-06-19 11:38 - 2012-06-27 16:34 - 00000000 ____D C:\Users\Karl\Desktop\Budget Finance ============ 3 Months Modified Files ======================== 2012-07-01 08:49 - 2010-12-07 13:54 - 00000890 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2012-07-01 08:49 - 2009-07-13 21:08 - 00000006 ___AH C:\Windows\Tasks\SA.DAT 2012-07-01 08:49 - 2009-07-13 20:51 - 01708736 ____A C:\Windows\setupact.log 2012-07-01 08:48 - 2010-12-05 20:51 - 02051368 ____A C:\Windows\WindowsUpdate.log 2012-07-01 08:23 - 2012-03-30 05:05 - 00000830 ____A C:\Windows\Tasks\Adobe Flash Player Updater.job 2012-07-01 08:12 - 2009-07-13 20:45 - 00014848 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2012-07-01 08:12 - 2009-07-13 20:45 - 00014848 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2012-07-01 08:09 - 2009-07-13 21:13 - 00792590 ____A C:\Windows\System32\PerfStringBackup.INI 2012-07-01 08:00 - 2012-07-01 08:00 - 00000672 ____A C:\Users\Karl\Desktop\06302012_153109.log 2012-07-01 07:59 - 2010-12-07 13:54 - 00000894 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2012-06-30 10:18 - 2012-06-28 12:51 - 00072074 ____A C:\Users\Karl\Desktop\Extras.Txt 2012-06-30 10:16 - 2012-06-28 12:49 - 00088140 ____A C:\Users\Karl\Desktop\OTL.Txt 2012-06-30 10:10 - 2012-06-30 10:10 - 00596992 ____A (OldTimer Tools) C:\Users\Karl\Desktop\OTL.exe 2012-06-30 10:03 - 2012-06-30 10:03 - 21054960 ____A (Oracle Corporation) C:\Users\Karl\Desktop\jre-7u5-windows-i586.exe 2012-06-30 10:03 - 2012-06-30 10:03 - 00772592 ____A (Oracle Corporation) C:\Windows\SysWOW64\npDeployJava1.dll 2012-06-30 10:03 - 2012-06-30 10:03 - 00227824 ____A (Oracle Corporation) C:\Windows\SysWOW64\javaws.exe 2012-06-30 10:03 - 2012-06-30 10:03 - 00174064 ____A (Oracle Corporation) C:\Windows\SysWOW64\javaw.exe 2012-06-30 10:03 - 2012-06-30 10:03 - 00174064 ____A (Oracle Corporation) C:\Windows\SysWOW64\java.exe 2012-06-30 10:03 - 2011-06-20 08:15 - 00687600 ____A (Oracle Corporation) C:\Windows\SysWOW64\deployJava1.dll 2012-06-30 10:02 - 2012-06-30 10:02 - 00955840 ____A (Oracle Corporation) C:\Windows\System32\npDeployJava1.dll 2012-06-30 10:02 - 2012-06-30 10:02 - 00268720 ____A (Oracle Corporation) C:\Windows\System32\javaws.exe 2012-06-30 10:02 - 2012-06-30 10:02 - 00189360 ____A (Oracle Corporation) C:\Windows\System32\javaw.exe 2012-06-30 10:02 - 2012-06-30 10:02 - 00188840 ____A (Oracle Corporation) C:\Windows\System32\java.exe 2012-06-30 10:01 - 2012-06-30 10:01 - 21869488 ____A (Oracle Corporation) C:\Users\Karl\Desktop\jre-7u5-windows-x64.exe 2012-06-30 07:03 - 2012-06-30 07:03 - 00000452 ____A C:\Users\Karl\Desktop\eset.txt 2012-06-30 05:39 - 2011-03-08 15:02 - 00034780 ____A C:\Windows\PFRO.log 2012-06-30 05:35 - 2012-06-30 05:35 - 00448512 ____A (OldTimer Tools) C:\Users\Karl\Desktop\TFC.exe 2012-06-30 05:35 - 2012-06-30 05:35 - 00001653 ____A C:\Users\Karl\Desktop\anti malware.txt 2012-06-30 05:34 - 2012-06-30 05:34 - 00000000 ____A C:\Users\Karl\Desktop\New Text Document.txt 2012-06-30 05:24 - 2012-06-30 05:24 - 00001113 ____A C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk 2012-06-30 05:23 - 2012-06-30 05:23 - 10063024 ____A (Malwarebytes Corporation ) C:\Users\Karl\Desktop\mbam-setup.exe 2012-06-30 05:21 - 2012-06-29 16:55 - 00001945 ____A C:\Windows\epplauncher.mif 2012-06-29 16:55 - 2011-03-07 11:55 - 00809684 ____A C:\Windows\SysWOW64\PerfStringBackup.INI 2012-06-29 16:44 - 2012-06-29 16:44 - 00015237 ____A C:\ComboFix.txt 2012-06-29 16:39 - 2009-07-13 18:34 - 00000215 ____A C:\Windows\system.ini 2012-06-29 16:38 - 2009-07-13 18:34 - 86245376 ____A C:\Windows\System32\config\software.bak 2012-06-29 16:38 - 2009-07-13 18:34 - 16252928 ____A C:\Windows\System32\config\system.bak 2012-06-29 16:38 - 2009-07-13 18:34 - 04980736 ____A C:\Windows\System32\config\default.bak 2012-06-29 16:38 - 2009-07-13 18:34 - 00262144 ____A C:\Windows\System32\config\security.bak 2012-06-29 16:38 - 2009-07-13 18:34 - 00262144 ____A C:\Windows\System32\config\sam.bak 2012-06-29 16:25 - 2012-06-29 16:25 - 04566027 ____R (Swearware) C:\Users\Karl\Desktop\ComboFix.exe 2012-06-29 16:21 - 2009-07-13 20:45 - 00367000 ____A C:\Windows\System32\FNTCACHE.DAT 2012-06-29 05:42 - 2010-12-06 07:50 - 58957832 ____A (Microsoft Corporation) C:\Windows\System32\MRT.exe 2012-06-29 05:15 - 2012-06-29 05:15 - 00002399 ____A C:\Users\Karl\Desktop\aswMBR.txt 2012-06-29 05:15 - 2012-06-29 05:15 - 00000559 ____A C:\Users\Karl\Desktop\MBR.zip 2012-06-29 05:15 - 2012-06-29 05:15 - 00000512 ____A C:\Users\Karl\Desktop\MBR.dat 2012-06-29 05:04 - 2012-06-29 05:03 - 04731392 ____A (AVAST Software) C:\Users\Karl\Desktop\aswMBR.exe 2012-06-02 14:19 - 2012-06-29 05:02 - 02428952 ____A (Microsoft Corporation) C:\Windows\System32\wuaueng.dll 2012-06-02 14:19 - 2012-06-29 05:02 - 00701976 ____A (Microsoft Corporation) C:\Windows\System32\wuapi.dll 2012-06-02 14:19 - 2012-06-29 05:02 - 00057880 ____A (Microsoft Corporation) C:\Windows\System32\wuauclt.exe 2012-06-02 14:19 - 2012-06-29 05:02 - 00044056 ____A (Microsoft Corporation) C:\Windows\System32\wups2.dll 2012-06-02 14:19 - 2012-06-29 05:02 - 00038424 ____A (Microsoft Corporation) C:\Windows\System32\wups.dll 2012-06-02 14:15 - 2012-06-29 05:02 - 02622464 ____A (Microsoft Corporation) C:\Windows\System32\wucltux.dll 2012-06-02 14:15 - 2012-06-29 05:02 - 00099840 ____A (Microsoft Corporation) C:\Windows\System32\wudriver.dll 2012-06-02 12:19 - 2012-06-29 05:02 - 00186752 ____A (Microsoft Corporation) C:\Windows\System32\wuwebv.dll 2012-06-02 12:15 - 2012-06-29 05:02 - 00036864 ____A (Microsoft Corporation) C:\Windows\System32\wuapp.exe 2012-05-14 20:01 - 2012-06-29 05:10 - 01188864 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll 2012-05-14 19:59 - 2012-06-29 05:10 - 00064512 ____A (Microsoft Corporation) C:\Windows\System32\jsproxy.dll 2012-05-14 19:03 - 2012-06-29 05:10 - 00981504 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2012-05-14 19:00 - 2012-06-29 05:10 - 00048128 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2012-05-14 17:32 - 2012-06-29 05:09 - 03146752 ____A (Microsoft Corporation) C:\Windows\System32\win32k.sys 2012-05-05 09:23 - 2012-04-14 09:23 - 08769696 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerInstaller.exe 2012-05-05 09:23 - 2012-03-30 05:05 - 00419488 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe 2012-05-05 09:23 - 2011-06-08 05:02 - 00070304 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl 2012-05-04 03:06 - 2012-06-29 05:09 - 05559664 ____A (Microsoft Corporation) C:\Windows\System32\ntoskrnl.exe 2012-05-04 02:03 - 2012-06-29 05:09 - 03968368 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe 2012-05-04 02:03 - 2012-06-29 05:09 - 03913072 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe 2012-04-30 21:40 - 2012-06-29 05:09 - 00209920 ____A (Microsoft Corporation) C:\Windows\System32\profsvc.dll 2012-04-27 19:55 - 2012-06-29 05:09 - 00210944 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\rdpwd.sys 2012-04-25 21:41 - 2012-06-29 05:10 - 00149504 ____A (Microsoft Corporation) C:\Windows\System32\rdpcorekmts.dll 2012-04-25 21:41 - 2012-06-29 05:10 - 00077312 ____A (Microsoft Corporation) C:\Windows\System32\rdpwsx.dll 2012-04-25 21:34 - 2012-06-29 05:10 - 00009216 ____A (Microsoft Corporation) C:\Windows\System32\rdrmemptylst.exe 2012-04-23 21:37 - 2012-06-29 05:09 - 01462272 ____A (Microsoft Corporation) C:\Windows\System32\crypt32.dll 2012-04-23 21:37 - 2012-06-29 05:09 - 00184320 ____A (Microsoft Corporation) C:\Windows\System32\cryptsvc.dll 2012-04-23 21:37 - 2012-06-29 05:09 - 00140288 ____A (Microsoft Corporation) C:\Windows\System32\cryptnet.dll 2012-04-23 20:36 - 2012-06-29 05:09 - 01158656 ____A (Microsoft Corporation) C:\Windows\SysWOW64\crypt32.dll 2012-04-23 20:36 - 2012-06-29 05:09 - 00140288 ____A (Microsoft Corporation) C:\Windows\SysWOW64\cryptsvc.dll 2012-04-23 20:36 - 2012-06-29 05:09 - 00103936 ____A (Microsoft Corporation) C:\Windows\SysWOW64\cryptnet.dll 2012-04-19 21:42 - 2012-06-29 05:10 - 12297216 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll 2012-04-19 21:42 - 2012-06-29 05:10 - 09059840 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll 2012-04-19 21:42 - 2012-06-29 05:10 - 02454528 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll 2012-04-19 21:42 - 2012-06-29 05:10 - 01494016 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll 2012-04-19 21:42 - 2012-06-29 05:10 - 00735744 ____A (Microsoft Corporation) C:\Windows\System32\msfeeds.dll 2012-04-19 21:42 - 2012-06-29 05:10 - 00247808 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll 2012-04-19 21:42 - 2012-06-29 05:10 - 00134144 ____A (Microsoft Corporation) C:\Windows\System32\url.dll 2012-04-19 21:42 - 2012-06-29 05:10 - 00097792 ____A (Microsoft Corporation) C:\Windows\System32\mshtmled.dll 2012-04-19 21:00 - 2012-06-29 05:10 - 01231360 ____A (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2012-04-19 21:00 - 2012-06-29 05:10 - 00132096 ____A (Microsoft Corporation) C:\Windows\SysWOW64\url.dll 2012-04-19 20:57 - 2012-06-29 05:10 - 06027776 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2012-04-19 20:57 - 2012-06-29 05:10 - 00627712 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2012-04-19 20:57 - 2012-06-29 05:10 - 00067584 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll 2012-04-19 20:56 - 2012-06-29 05:10 - 11020800 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2012-04-19 20:56 - 2012-06-29 05:10 - 02073600 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2012-04-19 20:56 - 2012-06-29 05:10 - 00176640 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll 2012-04-19 19:45 - 2012-06-29 05:10 - 01638912 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb 2012-04-19 19:16 - 2012-06-29 05:10 - 01638912 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2012-04-17 11:10 - 2011-05-24 05:17 - 00001663 ____A C:\Users\Karl\Desktop\UltraTax CS 2005.lnk 2012-04-16 21:31 - 2012-06-29 05:10 - 00918016 ____A (Microsoft Corporation) C:\Windows\System32\jscript.dll 2012-04-16 20:34 - 2012-06-29 05:10 - 00716800 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll 2012-04-12 06:58 - 2011-09-21 11:07 - 00002026 ____A C:\Users\Public\Desktop\Adobe Acrobat X Pro.lnk 2012-04-12 00:04 - 2009-07-13 18:34 - 00000499 ____A C:\Windows\win.ini 2012-04-07 04:31 - 2012-06-29 05:09 - 03216384 ____A (Microsoft Corporation) C:\Windows\System32\msi.dll 2012-04-07 03:26 - 2012-06-29 05:09 - 02342400 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msi.dll 2012-04-04 12:56 - 2012-06-30 05:24 - 00024904 ____A (Malwarebytes Corporation) C:\Windows\System32\Drivers\mbam.sys ========================= Known DLLs (Whitelisted) ============ ========================= Bamital & volsnap Check ============ C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\SysWOW64\wininit.exe => MD5 is legit C:\Windows\explorer.exe => MD5 is legit C:\Windows\SysWOW64\explorer.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\SysWOW64\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\SysWOW64\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\SysWOW64\userinit.exe => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit ==================== EXE ASSOCIATION ===================== HKLM\…\.exe: exefile => OK HKLM\…\exefile\DefaultIcon: %1 => OK HKLM\…\exefile\open\command: "%1" %* => OK ========================= Memory info ====================== Percentage of memory in use: 15% Total physical RAM: 4095.18 MB Available physical RAM: 3468.95 MB Total Pagefile: 4093.32 MB Available Pagefile: 3453.88 MB Total Virtual: 8192 MB Available Virtual: 8191.9 MB ======================= Partitions ========================= 1 Drive c: () (Fixed) (Total:465.66 GB) (Free:402.12 GB) NTFS 3 Drive f: (CENTON USB) (Removable) (Total:1.88 GB) (Free:1.88 GB) FAT 4 Drive x: (Boot) (Fixed) (Total:0.03 GB) (Free:0.03 GB) NTFS 5 Drive y: (System Reserved) (Fixed) (Total:0.1 GB) (Free:0.07 GB) NTFS ==>[System with boot components (obtained from reading drive)] Disk ### Status Size Free Dyn Gpt ——– ————- ——- ——- — — Disk 0 Online 465 GB 0 B Disk 1 Online 1925 MB 0 B Partitions of Disk 0: =============== Partition ### Type Size Offset ————- —————- ——- ——- Partition 1 Primary 100 MB 1024 KB Partition 2 Primary 465 GB 101 MB ================================================================================ == Disk: 0 Partition 1 Type : 07 Hidden: No Active: Yes Volume ### Ltr Label Fs Type Size Status Info ———- — ———– —– ———- ——- ——— ——– * Volume 1 Y System Rese NTFS Partition 100 MB Healthy ================================================================================ == Disk: 0 Partition 2 Type : 07 Hidden: No Active: No Volume ### Ltr Label Fs Type Size Status Info ———- — ———– —– ———- ——- ——— ——– * Volume 2 C NTFS Partition 465 GB Healthy ================================================================================ == Partitions of Disk 1: =============== Partition ### Type Size Offset ————- —————- ——- ——- Partition 1 Primary 1924 MB 252 KB ================================================================================ == Disk: 1 Partition 1 Type : 06 Hidden: No Active: Yes Volume ### Ltr Label Fs Type Size Status Info ———- — ———– —– ———- ——- ——— ——– * Volume 3 F CENTON USB FAT Removable 1924 MB Healthy ================================================================================ == ========================================================== Last Boot: 2012-06-28 10:55 ======================= End Of Log ==========================
Click Start > click Run > type %systemroot%\system32\drivers\etc and then click OK.


Rename the hosts file to hosts.old

Create a new default hosts file.

To do this, follow these steps:

Right-click an open space in the c:\windows\system32\drivers\etc folder

point to New, click Text Document, type hosts, and then press ENTER

Click Yes to confirm that the file name extension will not be txt

click on the newly created hosts file to open it > you will be asked what program to open it with > choose Notepad


Copy the following text to the file:

127.0.0.1 localhost
::1 localhost


Save the change and exit

reboot your computer
  • OTL

    Let's run another OTL scan.

  • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • Select All Users
  • Under the Custom Scan box paste this in
    netsvcs
    %SYSTEMDRIVE%\*.exe
    /md5start
    explorer.exe
    winlogon.exe
    Userinit.exe
    svchost.exe
    /md5stop
    %systemroot%\*. /rp /s
    DRIVES
    CREATERESTOREPOINT
  • Click the Quick Scan button. Do not change any settings unless otherwise told to do so. The scan won't take long.
  • When the scan completes, it will open a notepad window of OTL.txt.
  • Post the log
Done!

Here is the log:

OTL logfile created on: 7/1/2012 4:09:08 PM - Run 2
OTL by OldTimer - Version 3.2.53.0 Folder = C:\Users\Karl\Desktop
64bit- Professional Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7601.17514)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

4.00 Gb Total Physical Memory | 2.56 Gb Available Physical Memory | 63.93% Memory free
8.00 Gb Paging File | 6.37 Gb Available in Paging File | 79.63% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 465.66 Gb Total Space | 402.12 Gb Free Space | 86.35% Space Free | Partition Type: NTFS
Drive E: | 1.88 Gb Total Space | 1.88 Gb Free Space | 99.93% Space Free | Partition Type: FAT

Computer Name: KARL-PC | User Name: Karl | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Quick Scan | Include 64bit Scans
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Users\Karl\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\acrotray.exe (Adobe Systems Inc.)
PRC - C:\Windows\csifcsvc.exe (Thomson Reuters)
PRC - C:\Program Files (x86)\Common Files\Intuit\QuickBooks\QBCFMonitorService.exe (Intuit)
PRC - C:\Program Files (x86)\Common Files\Intuit\DataProtect\IntuitDataProtect.exe (Intuit Inc.)
PRC - C:\Program Files (x86)\Common Files\Intuit\DataProtect\QBIDPService.exe (Intuit Inc.)
PRC - C:\Windows\csasvc.exe (Thomson Reuters)
PRC - C:\Windows\twain_32\fjscan32\FiWiaChecker.exe (PFU LIMITED)
PRC - C:\Windows\twain_32\fjscan32\FjtwMkup.exe (FUJITSU LIMITED)
PRC - C:\Program Files (x86)\Spybot - Search & Destroy\TeaTimer.exe (Safer-Networking Ltd.)
PRC - C:\Program Files (x86)\Spybot - Search & Destroy\SDWinSec.exe (Safer Networking Ltd.)
PRC - C:\Windows\twain_32\fjscan32\FTPWREVT\FTPWREVT.exe (PFU LIMITED)
PRC - C:\Program Files (x86)\PFU\CardMinder V3.2\CardLauncher.exe (PFU Limited.)
PRC - C:\Windows\twain_32\fjscan32\FJTWMKSV.exe (PFU LIMITED)


========== Modules (No Company Name) ==========

MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\PresentationFramewo#\199683f6e79076b634ee6cc0a82c0654\PresentationFramework.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\PresentationCore\e7dc084827f8df2dbdc819db5c633a0d\PresentationCore.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Windows.Forms\3971e166cf827b6726e142f344061dc9\System.Windows.Forms.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\WindowsBase\21f37f9f5162af7efb52169012bd111e\WindowsBase.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Drawing\8c40f40ef36622109793788049fbe9ab\System.Drawing.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\System.ServiceModel\cfece6f67593b4d8bb58d23b7fdcc470\System.ServiceModel.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Web.Services\dbe597aa9c12df5d08fb2f3f9872b834\System.Web.Services.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Xaml\d234eceae699d070b5a5712ce776c01f\System.Xaml.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Xml\d1f299160424bad90fe9f658661389e2\System.Xml.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Configuration\623d2a0f11dd82bb9bc13d1cb981b239\System.Configuration.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Core\ed91b57205429a23bb91f4499059a459\System.Core.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\System\6f9f0467e8b2dd3f69b015c8e30ac945\System.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\mscorlib\3953b1d8b9b57e4957bff8f58145384e\mscorlib.ni.dll ()
MOD - C:\Program Files (x86)\PFU\CardMinder V3.2\CardPath.dll ()


========== Win32 Services (SafeList) ==========

SRV:64bit: - (AMD External Events Utility) – C:\Windows\SysNative\atiesrxx.exe (AMD)
SRV:64bit: - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV:64bit: - (AppMgmt) – C:\Windows\SysNative\appmgmts.dll (Microsoft Corporation)
SRV - (AdobeFlashPlayerUpdateSvc) – C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe (Adobe Systems Incorporated)
SRV - (FCPrintService) – C:\Windows\csifcsvc.exe (Thomson Reuters)
SRV - (QBCFMonitorService) – C:\Program Files (x86)\Common Files\Intuit\QuickBooks\QBCFMonitorService.exe (Intuit)
SRV - (QBVSS) – C:\Program Files (x86)\Common Files\Intuit\DataProtect\QBIDPService.exe (Intuit Inc.)
SRV - (clr_optimization_v4.0.30319_32) – C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation)
SRV - (CSAPrintService) – C:\Windows\csasvc.exe (Thomson Reuters)
SRV - (QBFCService) – C:\Program Files (x86)\Common Files\Intuit\QuickBooks\FCS\Intuit.QuickBooks.FCS.exe (Intuit Inc.)
SRV - (clr_optimization_v2.0.50727_32) – C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
SRV - (FJTWMKSV) – C:\Windows\twain_32\fjscan32\FJTWMKSV.exe (PFU LIMITED)


========== Driver Services (SafeList) ==========

DRV:64bit: - (Fs_Rec) – C:\Windows\SysNative\drivers\fs_rec.sys (Microsoft Corporation)
DRV:64bit: - (atikmdag) – C:\Windows\SysNative\drivers\atikmdag.sys (ATI Technologies Inc.)
DRV:64bit: - (amdkmdag) – C:\Windows\SysNative\drivers\atikmdag.sys (ATI Technologies Inc.)
DRV:64bit: - (amdkmdap) – C:\Windows\SysNative\drivers\atikmpag.sys (Advanced Micro Devices, Inc.)
DRV:64bit: - (amdsata) – C:\Windows\SysNative\drivers\amdsata.sys (Advanced Micro Devices)
DRV:64bit: - (amdxata) – C:\Windows\SysNative\drivers\amdxata.sys (Advanced Micro Devices)
DRV:64bit: - (HpSAMD) – C:\Windows\SysNative\drivers\HpSAMD.sys (Hewlett-Packard Company)
DRV:64bit: - (TsUsbFlt) – C:\Windows\SysNative\drivers\TsUsbFlt.sys (Microsoft Corporation)
DRV:64bit: - (AtiHDAudioService) – C:\Windows\SysNative\drivers\AtihdW76.sys (Advanced Micro Devices)
DRV:64bit: - (RTL8167) – C:\Windows\SysNative\drivers\Rt64win7.sys (Realtek )
DRV:64bit: - (VIAHdAudAddService) – C:\Windows\SysNative\drivers\viahduaa.sys (VIA Technologies, Inc.)
DRV:64bit: - (AtiHdmiService) – C:\Windows\SysNative\drivers\AtiHdmi.sys (ATI Technologies, Inc.)
DRV:64bit: - (MTsensor) – C:\Windows\SysNative\drivers\ASACPI.sys ()
DRV:64bit: - (amdsbs) – C:\Windows\SysNative\drivers\amdsbs.sys (AMD Technologies Inc.)
DRV:64bit: - (LSI_SAS2) – C:\Windows\SysNative\drivers\lsi_sas2.sys (LSI Corporation)
DRV:64bit: - (stexstor) – C:\Windows\SysNative\drivers\stexstor.sys (Promise Technology)
DRV:64bit: - (ebdrv) – C:\Windows\SysNative\drivers\evbda.sys (Broadcom Corporation)
DRV:64bit: - (b06bdrv) – C:\Windows\SysNative\drivers\bxvbda.sys (Broadcom Corporation)
DRV:64bit: - (b57nd60a) – C:\Windows\SysNative\drivers\b57nd60a.sys (Broadcom Corporation)
DRV:64bit: - (hcw85cir) – C:\Windows\SysNative\drivers\hcw85cir.sys (Hauppauge Computer Works, Inc.)
DRV:64bit: - (AtiPcie) AMD PCI Express (3GIO) – C:\Windows\SysNative\drivers\AtiPcie.sys (Advanced Micro Devices Inc.)
DRV:64bit: - (AN983X64) – C:\Windows\SysNative\drivers\an983x64.sys (Infineon Technologies AG)
DRV - (WIMMount) – C:\Windows\SysWOW64\drivers\wimmount.sys (Microsoft Corporation)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE:64bit: - HKLM\..\SearchScopes,DefaultScope = {6A1806CD-94D4-4689-BA73-E35EA1EA9990}
IE:64bit: - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE:64bit: - HKLM\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.com/search?q={searchTerm…mp;sourceid=ie7
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\..\SearchScopes,DefaultScope = {6A1806CD-94D4-4689-BA73-E35EA1EA9990}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKLM\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.com/search?q={searchTerm…mp;sourceid=ie7


IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0



IE - HKU\S-1-5-21-1223943980-3166616486-3786436184-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/
IE - HKU\S-1-5-21-1223943980-3166616486-3786436184-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-us
IE - HKU\S-1-5-21-1223943980-3166616486-3786436184-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 8D FC FE 92 58 95 CB 01 [binary data]
IE - HKU\S-1-5-21-1223943980-3166616486-3786436184-1000\..\SearchScopes,DefaultScope = {6A1806CD-94D4-4689-BA73-E35EA1EA9990}
IE - HKU\S-1-5-21-1223943980-3166616486-3786436184-1000\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}…amp;FORM=IE8SRC
IE - HKU\S-1-5-21-1223943980-3166616486-3786436184-1000\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.com/search?q={searchTerm…1I7GGHP_enUS460
IE - HKU\S-1-5-21-1223943980-3166616486-3786436184-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0


========== FireFox ==========

FF:64bit: - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF64_10_3_162.dll File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.5.0: C:\Windows\system32\npDeployJava1.dll (Oracle Corporation)
FF:64bit: - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.5.0: C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\5.1.10411.0\npctrl.dll ( Microsoft Corporation)
FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.5.0: C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.5.0: C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files (x86)\Microsoft Silverlight\5.1.10411.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=8: C:\Program Files (x86)\Google\Update\1.2.183.39\npGoogleOneClick8.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\Adobe Acrobat: C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Air\nppdf32.dll (Adobe Systems Inc.)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Browser\WCFirefoxExtn [2012/04/12 09:58:14 | 000,000,000 | —D | M]


O1 HOSTS File: ([2012/07/01 15:21:24 | 000,000,038 | —- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2:64bit: - BHO: (Java™ Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
O2:64bit: - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
O2:64bit: - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.7.7018.1622\swg64.dll (Google Inc.)
O2:64bit: - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O2 - BHO: (Spybot-S&D IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files (x86)\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O2 - BHO: (Java™ Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
O2 - BHO: (Adobe PDF Conversion Toolbar Helper) - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files (x86)\Google\GoogleToolbarNotifier\5.7.7018.1622\swg.dll (Google Inc.)
O2 - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O2 - BHO: (SmartSelect Class) - {F4971EE7-DAA0-4053-9964-665D8EE6A077} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O3:64bit: - HKLM\..\Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O3:64bit: - HKU\S-1-5-21-1223943980-3166616486-3786436184-1000\..\Toolbar\WebBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
O3 - HKU\S-1-5-21-1223943980-3166616486-3786436184-1000\..\Toolbar\WebBrowser: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O4:64bit: - HKLM..\Run: [ATIModeChange] Ati2mdxx.exe File not found
O4 - HKLM..\Run: [Acrobat Assistant 8.0] C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Acrotray.exe (Adobe Systems Inc.)
O4 - HKLM..\Run: [Adobe Acrobat Speed Launcher] C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Acrobat_sl.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [FiWIA Service Checker] C:\Windows\twain_32\fjscan32\FiWiaChecker.exe (PFU LIMITED)
O4 - HKLM..\Run: [FJTWAIN Setup] C:\Windows\Twain_32\fjscan32\FjtwMkup.exe (FUJITSU LIMITED)
O4 - HKLM..\Run: [FTPWRENV] C:\Windows\twain_32\fjscan32\FTPWREVT\FTPWREVT.exe (PFU LIMITED)
O4 - HKLM..\Run: [StartCCC] C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.)
O4 - HKU\S-1-5-21-1223943980-3166616486-3786436184-1000..\Run: [SpybotSD TeaTimer] C:\Program Files (x86)\Spybot - Search & Destroy\TeaTimer.exe (Safer-Networking Ltd.)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-1223943980-3166616486-3786436184-1000\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-1223943980-3166616486-3786436184-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O8:64bit: - Extra context menu item: Append Link Target to Existing PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8:64bit: - Extra context menu item: Append to Existing PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8:64bit: - Extra context menu item: Convert Link Target to Adobe PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8:64bit: - Extra context menu item: Convert to Adobe PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Append Link Target to Existing PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Append to Existing PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert Link Target to Adobe PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert to Adobe PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O9 - Extra 'Tools' menuitem : Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files (x86)\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000004 - mmswsock.dll File not found
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000005 - mmswsock.dll File not found
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000006 - mmswsock.dll File not found
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000007 - mmswsock.dll File not found
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - %SystemRoot%\System32\nwprovau.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000025 - %SystemRoot%\System32\winrnr.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000026 - %SystemRoot%\System32\winrnr.dll File not found
O16:64bit: - DPF: {4871A87A-BFDD-4106-8153-FFDE2BAC2967} http://dlm.tools.akamai.com/dlmanager/vers…x64-2.2.6.0.cab (DLM Control)
O16:64bit: - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} http://download.divx.com/player/DivXBrowserPlugin.cab (Reg Error: Key error.)
O16:64bit: - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} http://download.eset.com/special/eos/OnlineScanner.cab (OnlineScanner Control)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = [removed] [removed]
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{0EBFCCB0-C442-4059-B6BB-CF231475AA84}: DhcpNameServer = [removed] [removed]
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{7D372210-BAD2-4B02-92F2-9B87EC97E0A7}: NameServer = 209.18.47.61,209.18.47.62
O18:64bit: - Protocol\Handler\intu-help-qb2 - No CLSID value found
O18:64bit: - Protocol\Handler\intu-help-qb3 - No CLSID value found
O18:64bit: - Protocol\Handler\intu-help-qb4 - No CLSID value found
O18:64bit: - Protocol\Handler\intu-help-qb5 - No CLSID value found
O18:64bit: - Protocol\Handler\ipp - No CLSID value found
O18:64bit: - Protocol\Handler\ipp\0x00000001 - No CLSID value found
O18:64bit: - Protocol\Handler\msdaipp - No CLSID value found
O18:64bit: - Protocol\Handler\msdaipp\0x00000001 - No CLSID value found
O18:64bit: - Protocol\Handler\msdaipp\oledb - No CLSID value found
O18:64bit: - Protocol\Handler\ms-help - No CLSID value found
O18:64bit: - Protocol\Handler\qbwc - No CLSID value found
O18 - Protocol\Handler\intu-help-qb2 {84D77A00-41B5-4b8b-8ADF-86486D72E749} - C:\Program Files (x86)\Intuit\QuickBooks 2009\HelpAsyncPluggableProtocol.dll (Intuit, Inc.)
O18 - Protocol\Handler\intu-help-qb3 {c5e479ea-0a65-4b05-8c6c-2fc8cc682eb4} - C:\Program Files (x86)\Intuit\QuickBooks 2010\HelpAsyncPluggableProtocol.dll (Intuit, Inc.)
O18 - Protocol\Handler\intu-help-qb4 {ACE22922-D07C-4860-B51B-8CF472FEC2CB} - C:\Program Files (x86)\Intuit\QuickBooks Enterprise Solutions 11.0\HelpAsyncPluggableProtocol.dll (Intuit, Inc.)
O18 - Protocol\Handler\intu-help-qb5 {867FCB77-9823-4cd6-8210-D85F968D466F} - C:\Program Files (x86)\Intuit\QuickBooks 2012\HelpAsyncPluggableProtocol.dll (Intuit, Inc.)
O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11D1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11D1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11D1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysNative\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysWOW64\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *)
O35:64bit: - HKLM\..comfile [open] – "%1" %*
O35:64bit: - HKLM\..exefile [open] – "%1" %*
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37:64bit: - HKLM\…com [@ = ComFile] – "%1" %*
O37:64bit: - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKLM\…com [@ = ComFile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)

NetSvcs:64bit: AppMgmt - C:\Windows\SysNative\appmgmts.dll (Microsoft Corporation)

CREATERESTOREPOINT
Restore point Set: OTL Restore Point

========== Files/Folders - Created Within 30 Days ==========

[2012/07/01 15:20:09 | 000,000,000 | —D | C] – C:\Users\Karl\Desktop\New folder
[2012/07/01 14:54:07 | 000,000,000 | —D | C] – C:\FRST
[2012/06/30 15:31:09 | 000,000,000 | —D | C] – C:\_OTL
[2012/06/30 13:10:09 | 000,596,992 | —- | C] (OldTimer Tools) – C:\Users\Karl\Desktop\OTL.exe
[2012/06/30 13:03:27 | 000,000,000 | —D | C] – C:\Program Files (x86)\Java
[2012/06/30 13:02:02 | 000,000,000 | —D | C] – C:\Program Files\Java
[2012/06/30 12:55:11 | 000,000,000 | -HSD | C] – C:\Config.Msi
[2012/06/30 08:42:52 | 000,000,000 | —D | C] – C:\Program Files (x86)\ESET
[2012/06/30 08:35:17 | 000,448,512 | —- | C] (OldTimer Tools) – C:\Users\Karl\Desktop\TFC.exe
[2012/06/30 08:24:19 | 000,000,000 | —D | C] – C:\Users\Karl\AppData\Roaming\Malwarebytes
[2012/06/30 08:24:13 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2012/06/30 08:24:12 | 000,024,904 | —- | C] (Malwarebytes Corporation) – C:\Windows\SysNative\drivers\mbam.sys
[2012/06/30 08:24:12 | 000,000,000 | —D | C] – C:\Program Files (x86)\Malwarebytes' Anti-Malware
[2012/06/30 08:24:12 | 000,000,000 | —D | C] – C:\ProgramData\Malwarebytes
[2012/06/30 08:23:26 | 010,063,024 | —- | C] (Malwarebytes Corporation ) – C:\Users\Karl\Desktop\mbam-setup.exe
[2012/06/29 19:46:21 | 000,000,000 | -HSD | C] – C:\$RECYCLE.BIN
[2012/06/29 19:44:33 | 000,000,000 | —D | C] – C:\Windows\temp
[2012/06/29 19:27:36 | 000,518,144 | —- | C] (SteelWerX) – C:\Windows\SWREG.exe
[2012/06/29 19:27:36 | 000,406,528 | —- | C] (SteelWerX) – C:\Windows\SWSC.exe
[2012/06/29 19:27:36 | 000,060,416 | —- | C] (NirSoft) – C:\Windows\NIRCMD.exe
[2012/06/29 19:27:29 | 000,000,000 | —D | C] – C:\Qoobox
[2012/06/29 19:27:08 | 000,000,000 | —D | C] – C:\Windows\erdnt
[2012/06/29 19:25:23 | 004,566,027 | R— | C] (Swearware) – C:\Users\Karl\Desktop\ComboFix.exe
[2012/06/29 08:03:45 | 004,731,392 | —- | C] (AVAST Software) – C:\Users\Karl\Desktop\aswMBR.exe
[2012/06/28 13:32:40 | 000,000,000 | —D | C] – C:\Windows\SysNative\MpEngineStore
[2012/06/19 14:38:02 | 000,000,000 | —D | C] – C:\Users\Karl\Desktop\Budget Finance

========== Files - Modified Within 30 Days ==========

[2012/07/01 15:59:00 | 000,000,894 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2012/07/01 15:30:03 | 000,014,848 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2012/07/01 15:30:03 | 000,014,848 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2012/07/01 15:27:22 | 000,000,890 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2012/07/01 15:27:06 | 000,792,590 | —- | M] () – C:\Windows\SysNative\PerfStringBackup.INI
[2012/07/01 15:27:06 | 000,669,064 | —- | M] () – C:\Windows\SysNative\perfh009.dat
[2012/07/01 15:27:06 | 000,125,250 | —- | M] () – C:\Windows\SysNative\perfc009.dat
[2012/07/01 15:23:01 | 000,000,830 | —- | M] () – C:\Windows\tasks\Adobe Flash Player Updater.job
[2012/07/01 15:22:52 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2012/07/01 15:22:46 | 3220,574,208 | -HS- | M] () – C:\hiberfil.sys
[2012/07/01 15:21:24 | 000,000,038 | —- | M] () – C:\Windows\SysNative\drivers\etc\hosts
[2012/06/30 13:10:11 | 000,596,992 | —- | M] (OldTimer Tools) – C:\Users\Karl\Desktop\OTL.exe
[2012/06/30 08:35:19 | 000,448,512 | —- | M] (OldTimer Tools) – C:\Users\Karl\Desktop\TFC.exe
[2012/06/30 08:24:13 | 000,001,113 | —- | M] () – C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2012/06/30 08:23:40 | 010,063,024 | —- | M] (Malwarebytes Corporation ) – C:\Users\Karl\Desktop\mbam-setup.exe
[2012/06/30 08:21:25 | 000,001,945 | —- | M] () – C:\Windows\epplauncher.mif
[2012/06/29 19:55:13 | 000,809,684 | —- | M] () – C:\Windows\SysWow64\PerfStringBackup.INI
[2012/06/29 19:25:31 | 004,566,027 | R— | M] (Swearware) – C:\Users\Karl\Desktop\ComboFix.exe
[2012/06/29 19:21:41 | 000,367,000 | —- | M] () – C:\Windows\SysNative\FNTCACHE.DAT
[2012/06/29 08:15:58 | 000,000,559 | —- | M] () – C:\Users\Karl\Desktop\MBR.zip
[2012/06/29 08:15:43 | 000,000,512 | —- | M] () – C:\Users\Karl\Desktop\MBR.dat
[2012/06/29 08:04:22 | 004,731,392 | —- | M] (AVAST Software) – C:\Users\Karl\Desktop\aswMBR.exe

========== Files Created - No Company Name ==========

[2012/06/30 08:24:13 | 000,001,113 | —- | C] () – C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2012/06/29 19:55:34 | 000,001,945 | —- | C] () – C:\Windows\epplauncher.mif
[2012/06/29 19:27:36 | 000,256,000 | —- | C] () – C:\Windows\PEV.exe
[2012/06/29 19:27:36 | 000,208,896 | —- | C] () – C:\Windows\MBR.exe
[2012/06/29 19:27:36 | 000,098,816 | —- | C] () – C:\Windows\sed.exe
[2012/06/29 19:27:36 | 000,080,412 | —- | C] () – C:\Windows\grep.exe
[2012/06/29 19:27:36 | 000,068,096 | —- | C] () – C:\Windows\zip.exe
[2012/06/29 08:15:58 | 000,000,559 | —- | C] () – C:\Users\Karl\Desktop\MBR.zip
[2012/06/29 08:15:43 | 000,000,512 | —- | C] () – C:\Users\Karl\Desktop\MBR.dat
[2012/01/09 12:52:06 | 000,000,257 | —- | C] () – C:\Windows\pixcache.ini
[2012/01/09 12:52:05 | 000,000,000 | —- | C] () – C:\Windows\SetScan.ini
[2012/01/09 12:33:28 | 000,000,712 | R— | C] () – C:\Windows\FJTWSTI.INI
[2012/01/06 11:54:25 | 000,003,155 | —- | C] () – C:\Windows\SysWow64\atipblag.dat
[2011/08/19 21:26:28 | 000,000,186 | —- | C] () – C:\Windows\SysWow64\Gsw32.exe.config
[2011/08/12 16:11:18 | 000,000,092 | -H– | C] () – C:\Users\Karl\AppData\Local\fusioncache.dat
[2011/06/21 16:44:39 | 000,000,208 | —- | C] () – C:\Windows\ODBCINST.INI
[2011/03/07 14:55:52 | 000,809,684 | —- | C] () – C:\Windows\SysWow64\PerfStringBackup.INI
[2011/01/05 10:10:44 | 000,000,384 | —- | C] () – C:\Users\Karl\CJB Farms, Inc.QBW.DSN
[2011/01/05 10:10:44 | 000,000,334 | -H– | C] () – C:\Users\Karl\CJB Farms, Inc.QBW.ND
[2011/01/05 10:09:22 | 003,735,552 | RH– | C] () – C:\Users\Karl\CJB Farms, Inc.QBW.TLG
[2011/01/05 10:09:21 | 020,557,824 | RH– | C] () – C:\Users\Karl\CJB Farms, Inc.QBW
[2011/01/05 09:44:03 | 000,000,384 | —- | C] () – C:\Users\Karl\B5 Land and Cattle Company.QBW.DSN
[2011/01/05 09:44:03 | 000,000,346 | -H– | C] () – C:\Users\Karl\B5 Land and Cattle Company.QBW.ND
[2011/01/05 09:42:54 | 002,359,296 | RH– | C] () – C:\Users\Karl\B5 Land and Cattle Company.QBW.TLG
[2011/01/05 09:42:53 | 009,875,456 | RH– | C] () – C:\Users\Karl\B5 Land and Cattle Company.QBW
[2010/12/22 11:01:55 | 005,771,264 | -H– | C] () – C:\Users\Karl\B5 Land and Cattle Company 12-16-10 (Backup Dec 22,2010 10 01 AM).QBB
[2010/12/22 10:00:14 | 000,000,095 | —- | C] () – C:\Windows\QBChanUtil_Trigger.ini
[2010/12/06 15:03:59 | 000,000,490 | —- | C] () – C:\Windows\ODBC.INI
[2010/12/06 10:38:32 | 000,000,000 | —- | C] () – C:\Windows\ativpsrm.bin
[2010/12/06 10:35:41 | 000,024,576 | —- | C] () – C:\Windows\SysWow64\AsIO.dll
[2010/12/06 10:35:41 | 000,013,440 | —- | C] () – C:\Windows\SysWow64\drivers\AsIO.sys
[2010/12/06 10:12:18 | 000,039,266 | —- | C] () – C:\Windows\Ascd_log.ini
[2010/12/06 10:11:26 | 000,001,769 | —- | C] () – C:\Windows\Language_trs.ini
[2010/12/06 10:11:21 | 000,031,453 | —- | C] () – C:\Windows\Ascd_tmp.ini

========== LOP Check ==========

[2012/06/28 16:31:51 | 000,000,000 | —D | M] – C:\Users\Karl\AppData\Roaming\Fujitsu
[2010/12/06 11:37:32 | 000,000,000 | -H-D | M] – C:\Users\Karl\AppData\Roaming\Leadertech
[2012/06/28 16:32:04 | 000,000,000 | —D | M] – C:\Users\Karl\AppData\Roaming\PFU
[2012/06/05 10:14:47 | 000,000,000 | -H-D | M] – C:\Users\Karl\AppData\Roaming\PrimoPDF
[2012/06/28 16:39:10 | 000,000,000 | —D | M] – C:\Users\Karl\AppData\Roaming\RFFlow
[2011/06/15 10:29:40 | 000,000,000 | -H-D | M] – C:\Users\Karl\AppData\Roaming\webex
[2012/02/21 09:44:10 | 000,032,602 | —- | M] () – C:\Windows\Tasks\SCHEDLGU.TXT

========== Purity Check ==========



========== Custom Scans ==========

< %SYSTEMDRIVE%\*.exe >

< MD5 for: EXPLORER.EXE >
[2011/02/26 01:23:14 | 002,870,272 | —- | M] (Microsoft Corporation) MD5=0862495E0C825893DB75EF44FAEA8E93 – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16768_none_adc24107935a7e25\explorer.exe
[2011/02/26 00:19:21 | 002,616,320 | —- | M] (Microsoft Corporation) MD5=0FB9C74046656D1579A64660AD67B746 – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.21669_none_ba87e574ddfe652d\explorer.exe
[2009/07/13 20:14:20 | 002,613,248 | —- | M] (Microsoft Corporation) MD5=15BC38A7492BEFE831966ADB477CF76F – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16385_none_b7fe430bc7ce3761\explorer.exe
[2011/02/26 00:51:13 | 002,614,784 | —- | M] (Microsoft Corporation) MD5=255CF508D7CFB10E0794D6AC93280BD8 – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20910_none_b8ce9756e0b786a4\explorer.exe
[2009/10/31 00:45:39 | 002,614,272 | —- | M] (Microsoft Corporation) MD5=2626FC9755BE22F805D3CFA0CE3EE727 – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16450_none_b819b343c7ba6202\explorer.exe
[2011/02/26 00:33:07 | 002,614,784 | —- | M] (Microsoft Corporation) MD5=2AF58D15EDC06EC6FDACCE1F19482BBF – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16768_none_b816eb59c7bb4020\explorer.exe
[2011/02/25 01:19:30 | 002,871,808 | —- | M] (Microsoft Corporation) MD5=332FEAB1435662FC6C672E25BEB37BE3 – C:\Windows\erdnt\cache86\explorer.exe
[2011/02/25 01:19:30 | 002,871,808 | —- | M] (Microsoft Corporation) MD5=332FEAB1435662FC6C672E25BEB37BE3 – C:\Windows\explorer.exe
[2011/02/25 01:19:30 | 002,871,808 | —- | M] (Microsoft Corporation) MD5=332FEAB1435662FC6C672E25BEB37BE3 – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17567_none_afa79dc39081d0ba\explorer.exe
[2011/02/26 01:14:34 | 002,871,808 | —- | M] (Microsoft Corporation) MD5=3B69712041F3D63605529BD66DC00C48 – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.21669_none_b0333b22a99da332\explorer.exe
[2010/11/20 07:17:09 | 002,616,320 | —- | M] (Microsoft Corporation) MD5=40D777B7A95E00593EB1568C68514493 – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17514_none_ba2f56d3c4bcbafb\explorer.exe
[2009/08/03 01:19:07 | 002,868,224 | —- | M] (Microsoft Corporation) MD5=700073016DAC1C3D2E7E2CE4223334B6 – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20500_none_ae84b558ac4eb41c\explorer.exe
[2011/02/25 00:30:54 | 002,616,320 | —- | M] (Microsoft Corporation) MD5=8B88EBBB05A0E56B7DCC708498C02B3E – C:\Windows\SysWOW64\explorer.exe
[2011/02/25 00:30:54 | 002,616,320 | —- | M] (Microsoft Corporation) MD5=8B88EBBB05A0E56B7DCC708498C02B3E – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17567_none_b9fc4815c4e292b5\explorer.exe
[2009/10/31 01:34:59 | 002,870,272 | —- | M] (Microsoft Corporation) MD5=9AAAEC8DAC27AA17B053E6352AD233AE – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16450_none_adc508f19359a007\explorer.exe
[2009/08/03 00:49:47 | 002,613,248 | —- | M] (Microsoft Corporation) MD5=9FF6C4C91A3711C0A3B18F87B08B518D – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20500_none_b8d95faae0af7617\explorer.exe
[2010/11/20 08:24:45 | 002,872,320 | —- | M] (Microsoft Corporation) MD5=AC4C51EB24AA95B77F705AB159189E24 – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17514_none_afdaac81905bf900\explorer.exe
[2009/10/31 01:38:38 | 002,870,272 | —- | M] (Microsoft Corporation) MD5=B8EC4BD49CE8F6FC457721BFC210B67F – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20563_none_ae46d6aeac7ca7c7\explorer.exe
[2009/08/03 00:35:50 | 002,613,248 | —- | M] (Microsoft Corporation) MD5=B95EEB0F4E5EFBF1038A35B3351CF047 – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16404_none_b853c407c78e3ba9\explorer.exe
[2009/07/13 20:39:10 | 002,868,224 | —- | M] (Microsoft Corporation) MD5=C235A51CB740E45FFA0EBFB9BAFCDA64 – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16385_none_ada998b9936d7566\explorer.exe
[2009/10/31 01:00:51 | 002,614,272 | —- | M] (Microsoft Corporation) MD5=C76153C7ECA00FA852BB0C193378F917 – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20563_none_b89b8100e0dd69c2\explorer.exe
[2011/02/26 01:26:45 | 002,870,784 | —- | M] (Microsoft Corporation) MD5=E38899074D4951D31B4040E994DD7C8D – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20910_none_ae79ed04ac56c4a9\explorer.exe
[2009/08/03 01:17:37 | 002,868,224 | —- | M] (Microsoft Corporation) MD5=F170B4A061C9E026437B193B4D571799 – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16404_none_adff19b5932d79ae\explorer.exe

< MD5 for: SVCHOST.EXE >
[2012/04/04 15:56:38 | 000,199,240 | —- | M] () MD5=097D0E812D7A9A3101CE46CB2BE0474D – C:\Program Files (x86)\Malwarebytes' Anti-Malware\Chameleon\svchost.exe
[2009/07/13 20:14:41 | 000,020,992 | —- | M] (Microsoft Corporation) MD5=54A47F6B5E09A77E61649109C6A08866 – C:\Windows\erdnt\cache86\svchost.exe
[2009/07/13 20:14:41 | 000,020,992 | —- | M] (Microsoft Corporation) MD5=54A47F6B5E09A77E61649109C6A08866 – C:\Windows\SysWOW64\svchost.exe
[2009/07/13 20:14:41 | 000,020,992 | —- | M] (Microsoft Corporation) MD5=54A47F6B5E09A77E61649109C6A08866 – C:\Windows\winsxs\x86_microsoft-windows-services-svchost_31bf3856ad364e35_6.1.7600.16385_none_b591afc466a15356\svchost.exe
[2009/07/13 20:39:46 | 000,027,136 | —- | M] (Microsoft Corporation) MD5=C78655BC80301D76ED4FEF1C1EA40A7D – C:\Windows\erdnt\cache64\svchost.exe
[2009/07/13 20:39:46 | 000,027,136 | —- | M] (Microsoft Corporation) MD5=C78655BC80301D76ED4FEF1C1EA40A7D – C:\Windows\SysNative\svchost.exe
[2009/07/13 20:39:46 | 000,027,136 | —- | M] (Microsoft Corporation) MD5=C78655BC80301D76ED4FEF1C1EA40A7D – C:\Windows\winsxs\amd64_microsoft-windows-services-svchost_31bf3856ad364e35_6.1.7600.16385_none_11b04b481efec48c\svchost.exe

< MD5 for: USERINIT.EXE >
[2010/11/20 07:17:48 | 000,026,624 | —- | M] (Microsoft Corporation) MD5=61AC3EFDFACFDD3F0F11DD4FD4044223 – C:\Windows\erdnt\cache86\userinit.exe
[2010/11/20 07:17:48 | 000,026,624 | —- | M] (Microsoft Corporation) MD5=61AC3EFDFACFDD3F0F11DD4FD4044223 – C:\Windows\SysWOW64\userinit.exe
[2010/11/20 07:17:48 | 000,026,624 | —- | M] (Microsoft Corporation) MD5=61AC3EFDFACFDD3F0F11DD4FD4044223 – C:\Windows\winsxs\x86_microsoft-windows-userinit_31bf3856ad364e35_6.1.7601.17514_none_de3024012ff21116\userinit.exe
[2009/07/13 20:14:43 | 000,026,112 | —- | M] (Microsoft Corporation) MD5=6DE80F60D7DE9CE6B8C2DDFDF79EF175 – C:\Windows\winsxs\x86_microsoft-windows-userinit_31bf3856ad364e35_6.1.7600.16385_none_dbff103933038d7c\userinit.exe
[2009/07/13 20:39:48 | 000,030,208 | —- | M] (Microsoft Corporation) MD5=6F8F1376A13114CC10C0E69274F5A4DE – C:\Windows\winsxs\amd64_microsoft-windows-userinit_31bf3856ad364e35_6.1.7600.16385_none_381dabbceb60feb2\userinit.exe
[2010/11/20 08:25:24 | 000,030,720 | —- | M] (Microsoft Corporation) MD5=BAFE84E637BF7388C96EF48D4D3FDD53 – C:\Windows\erdnt\cache64\userinit.exe
[2010/11/20 08:25:24 | 000,030,720 | —- | M] (Microsoft Corporation) MD5=BAFE84E637BF7388C96EF48D4D3FDD53 – C:\Windows\SysNative\userinit.exe
[2010/11/20 08:25:24 | 000,030,720 | —- | M] (Microsoft Corporation) MD5=BAFE84E637BF7388C96EF48D4D3FDD53 – C:\Windows\winsxs\amd64_microsoft-windows-userinit_31bf3856ad364e35_6.1.7601.17514_none_3a4ebf84e84f824c\userinit.exe

< MD5 for: WINLOGON.EXE >
[2012/04/04 15:56:38 | 000,199,240 | —- | M] () MD5=097D0E812D7A9A3101CE46CB2BE0474D – C:\Program Files (x86)\Malwarebytes' Anti-Malware\Chameleon\winlogon.exe
[2010/11/20 08:25:30 | 000,390,656 | —- | M] (Microsoft Corporation) MD5=1151B1BAA6F350B1DB6598E0FEA7C457 – C:\Windows\erdnt\cache64\winlogon.exe
[2010/11/20 08:25:30 | 000,390,656 | —- | M] (Microsoft Corporation) MD5=1151B1BAA6F350B1DB6598E0FEA7C457 – C:\Windows\SysNative\winlogon.exe
[2010/11/20 08:25:30 | 000,390,656 | —- | M] (Microsoft Corporation) MD5=1151B1BAA6F350B1DB6598E0FEA7C457 – C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7601.17514_none_cde90685eb910636\winlogon.exe
[2009/07/13 20:39:52 | 000,389,120 | —- | M] (Microsoft Corporation) MD5=132328DF455B0028F13BF0ABEE51A63A – C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.16385_none_cbb7f2bdeea2829c\winlogon.exe
[2009/10/28 02:01:57 | 000,389,632 | —- | M] (Microsoft Corporation) MD5=A93D41A4D4B0D91C072D11DD8AF266DE – C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.20560_none_cc522fd507b468f8\winlogon.exe
[2009/10/28 01:24:40 | 000,389,632 | —- | M] (Microsoft Corporation) MD5=DA3E2A6FA9660CC75B471530CE88453A – C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.16447_none_cbe534e7ee8042ad\winlogon.exe

< %systemroot%\*. /rp /s >

========== Drive Information ==========

Physical Drives
—————

Drive: \\\\.\\PHYSICALDRIVE0 - Fixed hard disk media
Interface type: IDE
Media Type: Fixed hard disk media
Model: WDC WD5000AAKS-00UU3A0 ATA Device
Partitions: 2
Status: OK
Status Info: 0

Drive: \\\\.\\PHYSICALDRIVE1 - Removable Media
Interface type: USB
Media Type: Removable Media
Model: CENTON DS Pro USB Device
Partitions: 1
Status: OK
Status Info: 0

Partitions
—————

DeviceID: Disk #0, Partition #0
PartitionType: Installable File System
Bootable: True
BootPartition: True
PrimaryPartition: True
Size: 0.00GB
Starting Offset: 1048576
Hidden sectors: 0


DeviceID: Disk #0, Partition #1
PartitionType: Installable File System
Bootable: False
BootPartition: False
PrimaryPartition: True
Size: 466.00GB
Starting Offset: 105906176
Hidden sectors: 0


DeviceID: Disk #1, Partition #0
PartitionType: MS-DOS V4 Huge
Bootable: True
BootPartition: True
PrimaryPartition: True
Size: 2.00GB
Starting Offset: 258048
Hidden sectors: 0


< End of report >
Do you mean I am finished? My computer seems ok. Should I reinstall my antivirus software and do another scan just to be sure?
Your logs appear to indicate that your system is clean. :thumbup: Please temporarily disable your real-time security programs before carrying out the following cleanup procedure. Afterward, please reinstall your antivirus and re-enable any other real-time security programs.

Also, before leaving, please post one last reply confirming your machine is in proper working order so that we may close the thread.


  • Uninstalling ComboFix

    • Click Start > Run (or WindowsKey + R)
    • In the Run box, type combofix /uninstall and then click OK.
    • A window should pop up shortly after saying that ComboFix has been uninstalled.
  • OTL Cleanup

    • Start OTL.exe.
    • Close all other programs apart from OTL as this step will require a reboot.
    • On the OTL main screen, press the CLEANUP button.
    • Click Yes at the prompt and then allow the program to reboot your computer.
  • Other information you should know before you leave:

    SpywareBlaster
    • If you ever use Internet Explorer, SpywareBlaster provides excellent additional protection.
    • SpywareBlaster prevents the installation of ActiveX-based spyware and other potentially unwanted programs.
    • Download it for free here.
    Web of Trust
    • WOT is a browsing tool that helps you determine the safety of unknown websites.
    • It places color-coded symbols next to URLs.
    • Green - Go
    • Yellow - Caution
    • Red - Stop
  • You can download it here.
Secunia Online Software Inspector
  • This is a nice little Java applet that will determine if any software on your computer is out of date.
  • Check it out here.
Other tips
  • Please go here for more valuable security tips.
Wow!!! Thanks Michael! The anti-virus scan shows that my computer is completely clean!!! Thanks so much!!!!!! You were great!! Now, for the last, but most important question. I understand the "What the Tech?" sometimes accepts donations. Could you give me info as to how to accomplish that? Thanks again!
Hi redder,

It was our pleasure to help you. :) The help you received will always be free, but should you wish to donate, you can find information here.

Take care. :wavey:

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI