This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Rootkit buster: self-replicating rootkits [Closed]

8 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi, Thanks in advance for your help. My pc is really acting up, slow sluggish response on start up and slow to load pages. I use the following clean up tools regularly. System mechanic by IOLO to keep my registry clean and free of memory eating junk. Super-Antispyware to clean out cookies and adware, Trend Micro's Housecall and rootkit buster for viruses and rootkits. Several days ago rootkit buster found several new infections in my media player (which is strange since I rarely use it). After several attempts to fix it using rootkit buster, I dont know what else to do.. Every time its the same thing, rootkit buster tells me to restart my computer and when I rescan the same rootkits are there. Its seems that they are self-replicating. Housecall isn't finding anything. I am posting the hijack this log and the rootkit buster log. Any help you could give would be extremely appreciated. Thank you ~Gloria

+—————————————————-
| Trend Micro RootkitBuster
| Module version: 5.0.0.1061
| Computer Name: GLORI970-PC
| OS version: 6.1-7601
| User Name: glori970
+—————————————————-


–== Dump Hidden MBR, Hidden Files and Alternate Data Streams on C:\ ==–
MBR unsupported disk type
[FILE_STREAM]:
FullPath : C:\Users\glori970\Desktop\HousecallLauncher.exe:Zone.Identifier:$DATA
FullPathLength: 47
DesiredAccess : 0x0
Options : 0x0
Attributes : 0x20
ShareAccess : 0x0
Type : 0x0
1 hidden files found.

–== Dump Hidden Registry Value on HKLM ==–
[HIDDEN_REGISTRY][Hidden Reg Value]:
KeyPath : HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\MediaPlayer\PREFERENCES\HME\S-1-5-21-3142601519-2184618316-1143777451-501
Root : 904a938
SubKey : S-1-5-21-3142601519-2184618316-1143777451-501
ValueName : SharedLibraryPath
Data : C:\Users\Guest\AppData\Local\Microsoft\Media Player
ValueType : 1
AccessType: 0
FullLength: 111
DataSize : 104
[HIDDEN_REGISTRY][Hidden Reg Value]:
KeyPath : HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\MediaPlayer\PREFERENCES\HME\S-1-5-21-3142601519-2184618316-1143777451-501
Root : 904a938
SubKey : S-1-5-21-3142601519-2184618316-1143777451-501
ValueName : AcceptedPrivacyStatement
Data : 0
ValueType : 4
AccessType: 0
FullLength: 111
DataSize : 4
[HIDDEN_REGISTRY][Hidden Reg Value]:
KeyPath : HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\MediaPlayer\PREFERENCES\HME\S-1-5-21-3142601519-2184618316-1143777451-501
Root : 904a938
SubKey : S-1-5-21-3142601519-2184618316-1143777451-501
ValueName : UsageTracking
Data : 0
ValueType : 4
AccessType: 0
FullLength: 111
DataSize : 4
[HIDDEN_REGISTRY][Hidden Reg Value]:
KeyPath : HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\MediaPlayer\PREFERENCES\HME\S-1-5-21-3142601519-2184618316-1143777451-501
Root : 904a938
SubKey : S-1-5-21-3142601519-2184618316-1143777451-501
ValueName : ForceUsageTracking
Data : 0
ValueType : 4
AccessType: 0
FullLength: 111
DataSize : 4
[HIDDEN_REGISTRY][Hidden Reg Value]:
KeyPath : HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\MediaPlayer\PREFERENCES\HME\S-1-5-21-3142601519-2184618316-1143777451-501
Root : 904a938
SubKey : S-1-5-21-3142601519-2184618316-1143777451-501
ValueName : DisplayName
Data : Guest
ValueType : 1
AccessType: 0
FullLength: 111
DataSize : 12
[HIDDEN_REGISTRY][Hidden Reg Key]:
KeyPath : HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Media Player NSS\3.0\Events\{DA3151A8-75F0-492A-BBE7-0DBD89F63357}
SubKey : {DA3151A8-75F0-492A-BBE7-0DBD89F63357}
FullLength: 112
6 hidden registry entries found.


–== Dump Hidden Process ==–
No hidden processes found.

–== Dump Hidden Driver ==–
No hidden drivers found.

–== Service Win32 API Hook List ==–
No hidden operating system service hooks found.

–== Dump Hidden Port ==–
No hidden ports found.

–== Dump Kernel Code Patching ==–
No kernel code patching detected.

–== Dump Hidden Services ==–
No hidden services found.


Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 2:50:31 PM, on 7/3/2012
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v8.00 (8.00.7601.17514)
Boot mode: Normal

Running processes:
C:\Windows\system32\taskhost.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Hewlett-Packard\HP Wireless Elite Keyboard\HPKEYBOARDg.EXE
C:\Windows\WindowsMobile\wmdc.exe
C:\Program Files\SUPERAntiSpyware\SUPERANTISPYWARE.EXE
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Users\glori970\Desktop\HijackThis.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Mozilla Firefox\plugin-container.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: YTNavAssist.YTNavAssistPlugin Class - {81017EA9-9AA8-4A6A-9734-7AF40E7D593F} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\YTNavAssist.dll
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O4 - HKLM\..\Run: [iolo Startup] "C:\Program Files\iolo\Common\Lib\ioloLManager.exe"
O4 - HKLM\..\Run: [HP KEYBOARDg] "C:\Program Files\Hewlett-Packard\HP Wireless Elite Keyboard\HPKEYBOARDg.EXE"
O4 - HKLM\..\Run: [Windows Mobile Device Center] %windir%\WindowsMobile\wmdc.exe
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O9 - Extra button: @C:\Windows\WindowsMobile\INetRepl.dll,-222 - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll
O9 - Extra 'Tools' menuitem: @C:\Windows\WindowsMobile\INetRepl.dll,-223 - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll
O16 - DPF: Garmin Communicator Plug-In - https://static.garmincdn.com/gcp/ie/3.0.1.0…inAxControl.CAB
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab
O18 - Protocol: cardisabled - (no CLSID) - (no file)
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL
O23 - Service: SAS Core Service (!SASCORE) - SUPERAntiSpyware.com - C:\Program Files\SUPERAntiSpyware\SASCORE.EXE
O23 - Service: iolo System Service (ioloSystemService) - iolo technologies, LLC - C:\Program Files\iolo\Common\Lib\ioloServiceManager.exe
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: NVIDIA Update Service Daemon (nvUpdatusService) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - CACE Technologies, Inc. - C:\Program Files\WinPcap\rpcapd.exe

–
End of file - 4383 bytes
Hi and Welcome!! :) My name is Jeff. I would be more than happy to take a look at your malware results logs and help you with solving any malware problems you might have. Logs can take a while to research, so please be patient and know that I am working hard to get you a clean and functional system back in your hands. I'd be grateful if you would note the following:
  • I will be working on your Malware issues, this may or may not, solve other issues you have with your machine.
  • The fixes are specific to your problem and should only be used for the issues on this machine.
  • Please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear.
  • It's often worth reading through these instructions and printing them for ease of reference.
  • If you don't know or understand something, please don't hesitate to say or ask!! It's better to be sure and safe than sorry.
  • Please reply to this thread. Do not start a new topic.

IMPORTANT NOTE : Please do not delete anything unless instructed to.
DO NOT use any TOOLS such as Combofix or HijackThis fixes without supervision.
Doing so could make your system inoperable and could require a full reinstall of your OS losing all your programs and data.


Vista and Windows 7 users:
These tools MUST be run from the executable (.exe) every time you run them
with Admin Rights (Right click, choose "Run as Administrator")


Stay with this topic until I give you the all clean post.

First we need to make all files and folders VISIBLE:

  • Go to start>control panel>folder options>view
  • Choose to "show hidden files and folders,"
  • Uncheck the "hide protected operating system files" and the "hide extensions for know file types" boxes.
  • Close the window with OK
———-

Please download DDS from either of these links

LINK 1
LINK 2

and save it to your desktop.
  • Disable any script blocking protection
  • Right-click and Run as Administrator dds to run the tool.
  • When done, two DDS.txt's will open.
  • Save both reports to your desktop.
—————————————————
Please include the contents of the following in your next reply:

DDS.txt

Attach.txt
———-

Please download aswMBR to your desktop.

  • Right click and Run as Administrator the aswMBR icon to run it.
  • Click the Scan button to start scan.
  • If asked whether you would like to update the Avast virus database please do.
  • When it finishes, press the save log button, save the logfile to your desktop and post its contents in your next reply.

[external image: Posted Image]
Click the image to enlarge it
———-

In your next reply please post the logs made by DDS and aswMBR.exe :)
Hi Jeff, Thank you so much for getting back to me so quickly. I really appreciate it and any help you can give me. Here are the scans you requested. Should I hide my hidden files again or leave them as is? . DDS (Ver_2011-08-26.01) - NTFSx86 Internet Explorer: 8.0.7601.17514 Run by [removed] at 16:12:14 on 2012-07-03 Microsoft Windows 7 Professional 6.1.7601.1.1252.1.1033.18.3071.1795 [GMT -4:00] . SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} . ============== Running Processes =============== . C:\Windows\system32\wininit.exe C:\Windows\system32\lsm.exe C:\Windows\system32\svchost.exe -k DcomLaunch C:\Windows\system32\svchost.exe -k RPCSS C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted C:\Windows\system32\svchost.exe -k netsvcs C:\Windows\system32\svchost.exe -k LocalService C:\Windows\system32\svchost.exe -k NetworkService C:\Windows\System32\spoolsv.exe C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork C:\Program Files\SUPERAntiSpyware\SASCORE.EXE C:\Windows\system32\svchost.exe -k HsfXAudioService C:\Program Files\iolo\Common\Lib\ioloServiceManager.exe C:\Windows\system32\svchost.exe -k imgsvc C:\Windows\system32\SearchIndexer.exe C:\Windows\system32\WUDFHost.exe C:\Program Files\iolo\System Mechanic\SystemGuardAlerter.exe C:\Windows\system32\taskhost.exe C:\Windows\system32\Dwm.exe C:\Windows\Explorer.EXE C:\Program Files\Hewlett-Packard\HP Wireless Elite Keyboard\HPKEYBOARDg.EXE C:\Windows\WindowsMobile\wmdc.exe C:\Program Files\SUPERAntiSpyware\SUPERANTISPYWARE.EXE C:\Program Files\Windows Sidebar\sidebar.exe C:\Windows\system32\svchost.exe -k WindowsMobile C:\Program Files\Windows Media Player\wmpnetwk.exe C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation C:\Windows\System32\svchost.exe -k LocalServicePeerNet C:\Users\glori970\Desktop\RootkitBuster_v5_1061.exe C:\Program Files\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe C:\Windows\System32\svchost.exe -k secsvcs C:\Program Files\Mozilla Firefox\firefox.exe C:\Program Files\Mozilla Firefox\plugin-container.exe C:\Windows\system32\Macromed\Flash\FlashUtil11c_ActiveX.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Program Files\Yahoo!\Companion\Installs\cpn0\ytbb.exe C:\Windows\system32\SearchFilterHost.exe C:\Windows\system32\SearchProtocolHost.exe C:\Windows\system32\DllHost.exe C:\Windows\system32\DllHost.exe C:\Windows\system32\conhost.exe C:\Windows\system32\wbem\wmiprvse.exe . ============== Pseudo HJT Report =============== . uURLSearchHooks: YTNavAssist.YTNavAssistPlugin Class: {81017ea9-9aa8-4a6a-9734-7af40e7d593f} - c:\program files\yahoo!\companion\installs\cpn0\YTNavAssist.dll BHO: &Yahoo! Toolbar Helper: {02478d38-c3f9-4efb-9b51-7695eca05670} - c:\program files\yahoo!\companion\installs\cpn0\yt.dll BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll TB: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\program files\yahoo!\companion\installs\cpn0\yt.dll uRun: [SUPERAntiSpyware] c:\program files\superantispyware\SUPERAntiSpyware.exe uRun: [Sidebar] c:\program files\windows sidebar\sidebar.exe /autoRun mRun: [iolo Startup] "c:\program files\iolo\common\lib\ioloLManager.exe" mRun: [HP KEYBOARDg] "c:\program files\hewlett-packard\hp wireless elite keyboard\HPKEYBOARDg.EXE" mRun: [Windows Mobile Device Center] %windir%\WindowsMobile\wmdc.exe mPolicies-system: ConsentPromptBehaviorAdmin = 5 (0x5) mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3) mPolicies-system: EnableUIADesktopToggle = 0 (0x0) IE: {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - {2EAF5BB0-070F-11D3-9307-00C04FAE2D4F} - c:\windows\windowsmobile\INetRepl.dll IE: {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - {2EAF5BB0-070F-11D3-9307-00C04FAE2D4F} - c:\windows\windowsmobile\INetRepl.dll DPF: Garmin Communicator Plug-In - hxxps://static.garmincdn.com/gcp/ie/3.0.1.0/GarminAxControl.CAB DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} - c:\program files\yahoo!\common\Yinsthelper.dll DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab TCP: DhcpNameServer = 192.168.2.1 [removed] [removed] TCP: Interfaces\{186D0D4E-8612-4824-9CD1-B097D9ABB3CE} : DhcpNameServer = [removed] [removed] TCP: Interfaces\{C2F9835C-85E5-445A-A00F-8490464B49B9} : DhcpNameServer = 192.168.2.1 [removed] [removed] TCP: Interfaces\{C2F9835C-85E5-445A-A00F-8490464B49B9}\2375942554733323 : DhcpNameServer = 192.168.1.254 Notify: !SASWinLogon - c:\program files\superantispyware\SASWINLO.DLL SEH: SABShellExecuteHook Class: {5ae067d3-9afb-48e0-853a-ebb7f4a000da} - c:\program files\superantispyware\SASSEH.DLL . ================= FIREFOX =================== . FF - ProfilePath - c:\users\glori970\appdata\roaming\mozilla\firefox\profiles\6ygcnyc1.default\ . —- FIREFOX POLICIES —- FF - user.js: yahoo.ytff.general.dontshowhpoffer - true ============= SERVICES / DRIVERS =============== . R1 ElRawDisk;ElRawDisk;c:\windows\system32\drivers\ElRawDsk.sys [2011-12-22 20392] R1 SASDIFSV;SASDIFSV;c:\program files\superantispyware\sasdifsv.sys [2011-7-22 12880] R1 SASKUTIL;SASKUTIL;c:\program files\superantispyware\SASKUTIL.SYS [2011-7-12 67664] R1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\drivers\vwififlt.sys [2009-7-13 48128] R2 !SASCORE;SAS Core Service;c:\program files\superantispyware\SASCore.exe [2011-8-11 116608] R2 HsfXAudioService;HsfXAudioService;c:\windows\system32\svchost.exe -k HsfXAudioService [2009-7-13 20992] R2 ioloSystemService;iolo System Service;c:\program files\iolo\common\lib\ioloServiceManager.exe [2012-4-19 1047336] R2 nvUpdatusService;NVIDIA Update Service Daemon;c:\program files\nvidia corporation\nvidia updatus\daemonu.exe [2011-8-31 2255464] R2 tmrkb;tmrkb;c:\windows\system32\drivers\tmrkb.sys [2012-7-3 131344] R3 HCW85BDA;Hauppauge WinTV 885 Video Capture;c:\windows\system32\drivers\HCW85BDA.sys [2009-7-14 1443584] R3 netr73;RT73 USB Extensible Wireless LAN Card Driver;c:\windows\system32\drivers\netr73.sys [2011-10-5 564800] R3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\drivers\Rt86win7.sys [2009-3-2 139776] S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384] S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0;c:\windows\system32\drivers\b57nd60x.sys [2009-7-13 229888] S3 MozillaMaintenance;Mozilla Maintenance Service;c:\program files\mozilla maintenance service\maintenanceservice.exe [2012-4-26 113120] S3 StorSvc;Storage Service;c:\windows\system32\svchost.exe -k LocalSystemNetworkRestricted [2009-7-13 20992] S3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\TsUsbFlt.sys [2011-8-20 52224] S3 VST_DPV;VST_DPV;c:\windows\system32\drivers\VSTDPV3.SYS [2009-7-13 980992] S3 VSTHWBS2;VSTHWBS2;c:\windows\system32\drivers\VSTBS23.SYS [2009-7-13 266752] S3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\wat\WatAdminSvc.exe [2011-8-21 1343400] S4 MemeoBackgroundService;MemeoBackgroundService;c:\program files\memeo\autobackup\MemeoBackgroundService.exe [2010-4-22 25824] S4 SeagateDashboardService;Seagate Dashboard Service;c:\program files\seagate\seagate dashboard\SeagateDashboardService.exe [2011-6-1 14088] . =============== File Associations =============== . JSEFile=NOTEPAD.EXE %1 regfile=NOTEPAD.EXE "%1" scrfile=NOTEPAD.EXE "%1" VBEFile=NOTEPAD.EXE %1 VBSFile=NOTEPAD.EXE %1 . =============== Created Last 30 ================ . 2012-07-03 17:08:47 205072 —-a-w- c:\windows\system32\drivers\tmcomm.sys 2012-07-03 17:04:05 131344 —-a-w- c:\windows\system32\drivers\tmrkb.sys 2012-07-03 06:04:50 6762896 —-a-w- c:\programdata\microsoft\windows defender\definition updates\{57d8a87b-9482-44ef-9e2a-c47d486a93a2}\mpengine.dll 2012-07-02 15:52:01 ——– d—–w- c:\users\glori970\appdata\local\NPE 2012-06-25 16:32:12 ——– d—–w- c:\program files\common files\Symantec Shared 2012-06-25 16:27:52 ——– d—–w- c:\programdata\Symantec 2012-06-25 16:27:47 ——– d—–w- c:\programdata\Norton 2012-06-25 16:27:45 ——– d—–w- c:\programdata\NortonInstaller 2012-06-19 22:05:33 770384 —-a-w- c:\program files\mozilla firefox\msvcr100.dll 2012-06-19 22:05:33 421200 —-a-w- c:\program files\mozilla firefox\msvcp100.dll 2012-06-19 22:05:33 113120 —-a-w- c:\program files\mozilla firefox\maintenanceservice.exe 2012-06-19 15:31:42 2422272 —-a-w- c:\windows\system32\wucltux.dll 2012-06-19 15:31:12 88576 —-a-w- c:\windows\system32\wudriver.dll 2012-06-19 15:30:53 33792 —-a-w- c:\windows\system32\wuapp.exe 2012-06-19 15:30:53 171904 —-a-w- c:\windows\system32\wuwebv.dll 2012-06-18 15:16:39 ——– d—–w- c:\programdata\RegRun 2012-06-18 15:15:16 2 –shatr- c:\windows\winstart.bat 2012-06-18 15:15:13 ——– d—–w- c:\program files\Greatis 2012-06-13 08:24:55 164352 —-a-w- c:\windows\system32\profsvc.dll 2012-06-13 08:24:53 140288 —-a-w- c:\windows\system32\cryptsvc.dll 2012-06-13 08:24:53 1158656 —-a-w- c:\windows\system32\crypt32.dll 2012-06-13 08:24:53 103936 —-a-w- c:\windows\system32\cryptnet.dll 2012-06-09 22:28:13 ——– d—–w- c:\program files\SecondLifeViewer 2012-06-06 03:53:11 737072 —-a-w- c:\programdata\microsoft\ehome\packages\sportsv2\sportstemplatecore-2\Microsoft.MediaCenter.Sports.UI.dll 2012-06-06 03:52:57 4283672 —-a-w- c:\programdata\microsoft\ehome\packages\mceclientux\updateablemarkup-2\markup.dll 2012-06-06 03:52:45 42776 —-a-w- c:\programdata\microsoft\ehome\packages\mceclientux\dsm-2\StartResources.dll 2012-06-06 03:52:41 539984 —-a-w- c:\programdata\microsoft\ehome\packages\mcespotlight\mcespotlight-2\SpotlightResources.dll . ==================== Find3M ==================== . 2012-05-15 03:03:54 981504 —-a-w- c:\windows\system32\wininet.dll 2012-05-15 01:05:38 2343936 —-a-w- c:\windows\system32\win32k.sys 2012-04-28 03:17:07 183808 —-a-w- c:\windows\system32\drivers\rdpwd.sys 2012-04-26 04:45:55 58880 —-a-w- c:\windows\system32\rdpwsx.dll 2012-04-26 04:45:54 129536 —-a-w- c:\windows\system32\rdpcorekmts.dll 2012-04-26 04:41:16 8192 —-a-w- c:\windows\system32\rdrmemptylst.exe 2012-04-20 03:16:44 1638912 —-a-w- c:\windows\system32\mshtml.tlb 2012-04-17 14:11:44 33280 —-a-w- c:\windows\system32\iolobtdfg.exe 2012-04-17 14:11:34 15360 —-a-w- c:\windows\system32\smrgdf.exe 2012-04-17 13:37:02 2095816 —-a-w- c:\windows\system32\Incinerator32.dll 2012-04-07 11:26:29 2342400 —-a-w- c:\windows\system32\msi.dll . ============= FINISH: 16:12:27.84 =============== aswMBR version 0.9.9.1665 Copyright© 2011 AVAST Software Run date: 2012-07-03 16:07:10 —————————– 16:07:10.443 OS Version: Windows 6.1.7601 Service Pack 1 16:07:10.443 Number of processors: 4 586 0xF0B 16:07:10.444 ComputerName: GLORI970-PC UserName: glori970 16:07:11.866 Initialize success 16:11:03.166 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-2 16:11:03.171 Disk 0 Vendor: WDC_WD10 80.0 Size: 953869MB BusType: 8 16:11:03.178 Disk 0 MBR read successfully 16:11:03.181 Disk 0 MBR scan 16:11:03.184 Disk 0 Windows 7 default MBR code 16:11:03.188 Disk 0 Partition 1 80 (A) 07 HPFS/NTFS NTFS 100 MB offset 2048 16:11:03.192 Disk 0 Partition 2 00 07 HPFS/NTFS NTFS 953767 MB offset 206848 16:11:03.197 Disk 0 scanning sectors +1953521664 16:11:03.266 Disk 0 scanning C:\Windows\system32\drivers 16:11:07.560 Service scanning 16:11:17.609 Modules scanning 16:11:21.191 Disk 0 trace - called modules: 16:11:21.212 ntkrnlpa.exe CLASSPNP.SYS disk.sys iaStorV.sys halmacpi.dll 16:11:21.216 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x86d84a58] 16:11:21.222 3 CLASSPNP.SYS[8b84959e] -> nt!IofCallDriver -> \Device\Ide\IAAStorageDevice-2[0x85ec9028] 16:11:21.227 Scan finished successfully 16:11:32.472 Disk 0 MBR has been saved successfully to "C:\Users\glori970\Desktop\MBR.dat" 16:11:32.478 The log file has been saved successfully to "C:\Users\glori970\Desktop\aswMBR.txt"

Attachments:

Hi,

Download Combofix from the link below, and save it to your desktop.
Link

**Note: It is important that it is saved directly to your desktop**
If you get a message saying "Illegal operation attempted on a registry key that has been marked for deletion", please restart your computer.


——————————————————————–

IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here

——————————————————————–

Right-Click and Run as Administrator on ComboFix.exe & follow the prompts.
  • When finished, it will produce a report for you.
  • Please post the C:\ComboFix.txt for further review.
Hi Jeff :) Here's the Combo fix log. Thanks again.~Gloria ComboFix 12-07-02.01 - glori970 07/03/2012 21:31:26.1.4 - x86 Microsoft Windows 7 Professional 6.1.7601.1.1252.1.1033.18.3071.2056 [GMT -4:00] Running from: c:\users\[removed]\Downloads\ComboFix.exe SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} . . ((((((((((((((((((((((((( Files Created from 2012-06-04 to 2012-07-04 ))))))))))))))))))))))))))))))) . . 2012-07-04 01:35 . 2012-07-04 01:35 ——– d—–w- c:\users\UpdatusUser\AppData\Local\temp 2012-07-04 01:35 . 2012-07-04 01:35 ——– d—–w- c:\users\Default\AppData\Local\temp 2012-07-04 01:35 . 2012-07-04 01:35 ——– d—–w- c:\users\Guest\AppData\Local\temp 2012-07-03 17:08 . 2012-07-03 17:08 205072 —-a-w- c:\windows\system32\drivers\tmcomm.sys 2012-07-03 17:04 . 2012-07-03 17:08 131344 —-a-w- c:\windows\system32\drivers\tmrkb.sys 2012-07-03 06:04 . 2012-05-31 03:41 6762896 —-a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{57D8A87B-9482-44EF-9E2A-C47D486A93A2}\mpengine.dll 2012-07-02 15:52 . 2012-07-02 16:15 ——– d—–w- c:\users\glori970\AppData\Local\NPE 2012-06-25 16:32 . 2012-06-26 04:19 ——– d—–w- c:\program files\Common Files\Symantec Shared 2012-06-25 16:27 . 2012-06-26 04:30 ——– d—–w- c:\programdata\Symantec 2012-06-25 16:27 . 2012-07-02 15:52 ——– d—–w- c:\programdata\Norton 2012-06-19 22:05 . 2012-06-19 22:05 770384 —-a-w- c:\program files\Mozilla Firefox\msvcr100.dll 2012-06-19 22:05 . 2012-06-19 22:05 421200 —-a-w- c:\program files\Mozilla Firefox\msvcp100.dll 2012-06-19 22:05 . 2012-06-19 22:05 113120 —-a-w- c:\program files\Mozilla Firefox\maintenanceservice.exe 2012-06-19 15:31 . 2012-06-02 22:19 53784 —-a-w- c:\windows\system32\wuauclt.exe 2012-06-19 15:31 . 2012-06-02 22:19 45080 —-a-w- c:\windows\system32\wups2.dll 2012-06-19 15:31 . 2012-06-02 22:19 1933848 —-a-w- c:\windows\system32\wuaueng.dll 2012-06-19 15:31 . 2012-06-02 22:12 2422272 —-a-w- c:\windows\system32\wucltux.dll 2012-06-19 15:31 . 2012-06-02 22:19 35864 —-a-w- c:\windows\system32\wups.dll 2012-06-19 15:31 . 2012-06-02 22:19 577048 —-a-w- c:\windows\system32\wuapi.dll 2012-06-19 15:31 . 2012-06-02 22:12 88576 —-a-w- c:\windows\system32\wudriver.dll 2012-06-19 15:30 . 2012-06-02 19:19 171904 —-a-w- c:\windows\system32\wuwebv.dll 2012-06-19 15:30 . 2012-06-02 19:12 33792 —-a-w- c:\windows\system32\wuapp.exe 2012-06-18 15:16 . 2012-06-18 16:32 ——– d—–w- c:\programdata\RegRun 2012-06-18 15:15 . 2012-06-18 15:15 2 –shatr- c:\windows\winstart.bat 2012-06-18 15:15 . 2012-06-18 15:15 ——– d—–w- c:\program files\Greatis 2012-06-13 08:24 . 2012-05-01 04:44 164352 —-a-w- c:\windows\system32\profsvc.dll 2012-06-13 08:24 . 2012-04-24 04:36 140288 —-a-w- c:\windows\system32\cryptsvc.dll 2012-06-13 08:24 . 2012-04-24 04:36 1158656 —-a-w- c:\windows\system32\crypt32.dll 2012-06-13 08:24 . 2012-04-24 04:36 103936 —-a-w- c:\windows\system32\cryptnet.dll 2012-06-09 22:28 . 2012-06-09 22:28 ——– d—–w- c:\program files\SecondLifeViewer 2012-06-06 03:53 . 2012-06-06 03:53 737072 —-a-w- c:\programdata\Microsoft\eHome\Packages\SportsV2\SportsTemplateCore-2\Microsoft.MediaCenter.Sports.UI.dll 2012-06-06 03:52 . 2012-06-06 03:52 4283672 —-a-w- c:\programdata\Microsoft\eHome\Packages\MCEClientUX\UpdateableMarkup-2\markup.dll 2012-06-06 03:52 . 2012-06-06 03:52 42776 —-a-w- c:\programdata\Microsoft\eHome\Packages\MCEClientUX\dSM-2\StartResources.dll 2012-06-06 03:52 . 2012-06-06 03:52 539984 —-a-w- c:\programdata\Microsoft\eHome\Packages\MCESpotlight\MCESpotlight-2\SpotlightResources.dll . . . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2012-06-27 16:42 . 2012-05-27 02:04 737072 —-a-w- c:\programdata\Microsoft\eHome\Packages\SportsV2\SportsTemplateCore\Microsoft.MediaCenter.Sports.UI.dll 2012-05-27 01:54 . 2012-05-27 01:54 4283672 —-a-w- c:\programdata\Microsoft\eHome\Packages\MCEClientUX\UpdateableMarkup\markup.dll 2012-05-27 01:53 . 2012-05-27 01:53 42776 —-a-w- c:\programdata\Microsoft\eHome\Packages\MCEClientUX\dSM\StartResources.dll 2012-05-27 01:53 . 2012-05-27 01:53 539984 —-a-w- c:\programdata\Microsoft\eHome\Packages\MCESpotlight\MCESpotlight\SpotlightResources.dll 2012-04-17 14:11 . 2011-08-31 03:44 33280 —-a-w- c:\windows\system32\iolobtdfg.exe 2012-04-17 14:11 . 2011-08-31 03:44 15360 —-a-w- c:\windows\system32\smrgdf.exe 2012-04-17 13:37 . 2011-08-31 03:44 2095816 —-a-w- c:\windows\system32\Incinerator32.dll 2012-06-19 22:05 . 2011-08-19 13:52 85472 —-a-w- c:\program files\mozilla firefox\components\browsercomps.dll . . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 . [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks] "{81017EA9-9AA8-4A6A-9734-7AF40E7D593F}"= "c:\program files\Yahoo!\Companion\Installs\cpn0\YTNavAssist.dll" [2011-03-16 214840] . [HKEY_CLASSES_ROOT\clsid\{81017ea9-9aa8-4a6a-9734-7af40e7d593f}] [HKEY_CLASSES_ROOT\YTNavAssist.YTNavAssistPlugin.1] [HKEY_CLASSES_ROOT\TypeLib\{A31F34A1-EBD2-45A2-BF6D-231C1B987CC8}] [HKEY_CLASSES_ROOT\YTNavAssist.YTNavAssistPlugin] . [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "SUPERAntiSpyware"="c:\program files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2012-06-20 3905408] "Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2010-11-20 1174016] . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "iolo Startup"="c:\program files\iolo\Common\Lib\ioloLManager.exe" [2012-04-17 938680] "HP KEYBOARDg"="c:\program files\Hewlett-Packard\HP Wireless Elite Keyboard\HPKEYBOARDg.EXE" [2009-07-23 701592] "Windows Mobile Device Center"="c:\windows\WindowsMobile\wmdc.exe" [2007-05-31 648072] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "ConsentPromptBehaviorAdmin"= 5 (0x5) "ConsentPromptBehaviorUser"= 3 (0x3) "EnableUIADesktopToggle"= 0 (0x0) . [hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks] "{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2011-07-19 113024] . [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon] 2011-05-04 17:54 551296 —-a-w- c:\program files\SUPERAntiSpyware\SASWINLO.DLL . [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager] BootExecute REG_MULTI_SZ autocheck . [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\!SASCORE] @="" . [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ioloSystemService] @="Service" . R3 MozillaMaintenance;Mozilla Maintenance Service;c:\program files\Mozilla Maintenance Service\maintenanceservice.exe [x] R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [x] R3 VST_DPV;VST_DPV;c:\windows\system32\DRIVERS\VSTDPV3.SYS [x] R3 VSTHWBS2;VSTHWBS2;c:\windows\system32\DRIVERS\VSTBS23.SYS [x] R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe [x] R4 MemeoBackgroundService;MemeoBackgroundService;c:\program files\Memeo\AutoBackup\MemeoBackgroundService.exe [x] R4 SeagateDashboardService;Seagate Dashboard Service;c:\program files\Seagate\Seagate Dashboard\SeagateDashboardService.exe [x] S1 ElRawDisk;ElRawDisk;c:\windows\system32\drivers\ElRawDsk.sys [x] S1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\SASDIFSV.SYS [x] S1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [x] S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [x] S2 !SASCORE;SAS Core Service;c:\program files\SUPERAntiSpyware\SASCORE.EXE [x] S2 HsfXAudioService;HsfXAudioService;c:\windows\system32\svchost.exe [x] S2 ioloSystemService;iolo System Service;c:\program files\iolo\Common\Lib\ioloServiceManager.exe [x] S2 NPF;NetGroup Packet Filter Driver;c:\windows\system32\drivers\npf.sys [x] S2 nvUpdatusService;NVIDIA Update Service Daemon;c:\program files\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe [x] S3 HCW85BDA;Hauppauge WinTV 885 Video Capture;c:\windows\system32\drivers\HCW85BDA.sys [x] S3 netr73;RT73 USB Extensible Wireless LAN Card Driver;c:\windows\system32\DRIVERS\netr73.sys [x] S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt86win7.sys [x] . . — Other Services/Drivers In Memory — . *Deregistered* - ioloSGuardDriver *Deregistered* - tmcomm . [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost] HsfXAudioService REG_MULTI_SZ HsfXAudioService WindowsMobile REG_MULTI_SZ wcescomm rapimgr LocalServiceRestricted REG_MULTI_SZ WcesComm RapiMgr . . ——- Supplementary Scan ——- . TCP: DhcpNameServer = 192.168.2.1 [removed] [removed] DPF: Garmin Communicator Plug-In - hxxps://static.garmincdn.com/gcp/ie/3.0.1.0/GarminAxControl.CAB FF - ProfilePath - c:\users\glori970\AppData\Roaming\Mozilla\Firefox\Profiles\6ygcnyc1.default\ FF - user.js: yahoo.ytff.general.dontshowhpoffer - true . . ——- File Associations ——- . JSEFile=NOTEPAD.EXE %1 . . ——————— LOCKED REGISTRY KEYS ——————— . [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\PCW\Security] @Denied: (Full) (Everyone) . Completion time: 2012-07-03 21:36:25 ComboFix-quarantined-files.txt 2012-07-04 01:36 . Pre-Run: 935,502,397,440 bytes free Post-Run: 935,429,722,112 bytes free . - - End Of File - - AFED2D63B42D71B71628C3CE835F79F7
Hi,
  • Please open Notepad (Start -> Run -> type notepad in the Open field -> OK) and copy and paste the text present inside the code box below:
    ClearJavaCache::
    
    File::
    c:\windows\winstart.bat
    c:\windows\system32\iolobtdfg.exe
    
    RegLock::
    [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
  • Save this as CFScript.txt and change the "Save as type" to "All Files" and place it on your desktop.

    [external image: Posted Image]
  • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before following the steps below. They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
  • Referring to the screenshot above, drag CFScript.txt into ComboFix.exe.
  • ComboFix will now run a scan on your system. It may reboot your system when it finishes. This is normal.
  • When finished, it shall produce a log for you. Copy and paste the contents of the log in your next reply.
CAUTION: Do not mouse-click ComboFix's window while it is running. That may cause it to stall.
———-
hi Jeff :D here's the combofix log with CFScript. ~Gloria ComboFix 12-07-04.04 - glori970 07/04/2012 14:57:07.2.4 - x86 Microsoft Windows 7 Professional 6.1.7601.1.1252.1.1033.18.3071.2207 [GMT -4:00] Running from: c:\users\[removed]\Downloads\ComboFix.exe SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} . . ((((((((((((((((((((((((( Files Created from 2012-06-04 to 2012-07-04 ))))))))))))))))))))))))))))))) . . 2012-07-04 19:00 . 2012-07-04 19:00 ——– d—–w- c:\users\UpdatusUser\AppData\Local\temp 2012-07-04 19:00 . 2012-07-04 19:00 ——– d—–w- c:\users\Guest\AppData\Local\temp 2012-07-04 19:00 . 2012-07-04 19:00 ——– d—–w- c:\users\Default\AppData\Local\temp 2012-07-03 06:04 . 2012-05-31 03:41 6762896 —-a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{57D8A87B-9482-44EF-9E2A-C47D486A93A2}\mpengine.dll 2012-07-02 15:52 . 2012-07-02 16:15 ——– d—–w- c:\users\glori970\AppData\Local\NPE 2012-06-25 16:32 . 2012-06-26 04:19 ——– d—–w- c:\program files\Common Files\Symantec Shared 2012-06-25 16:27 . 2012-06-26 04:30 ——– d—–w- c:\programdata\Symantec 2012-06-25 16:27 . 2012-07-02 15:52 ——– d—–w- c:\programdata\Norton 2012-06-19 22:05 . 2012-06-19 22:05 770384 —-a-w- c:\program files\Mozilla Firefox\msvcr100.dll 2012-06-19 22:05 . 2012-06-19 22:05 421200 —-a-w- c:\program files\Mozilla Firefox\msvcp100.dll 2012-06-19 22:05 . 2012-06-19 22:05 113120 —-a-w- c:\program files\Mozilla Firefox\maintenanceservice.exe 2012-06-19 15:31 . 2012-06-02 22:19 53784 —-a-w- c:\windows\system32\wuauclt.exe 2012-06-19 15:31 . 2012-06-02 22:19 45080 —-a-w- c:\windows\system32\wups2.dll 2012-06-19 15:31 . 2012-06-02 22:19 1933848 —-a-w- c:\windows\system32\wuaueng.dll 2012-06-19 15:31 . 2012-06-02 22:12 2422272 —-a-w- c:\windows\system32\wucltux.dll 2012-06-19 15:31 . 2012-06-02 22:19 35864 —-a-w- c:\windows\system32\wups.dll 2012-06-19 15:31 . 2012-06-02 22:19 577048 —-a-w- c:\windows\system32\wuapi.dll 2012-06-19 15:31 . 2012-06-02 22:12 88576 —-a-w- c:\windows\system32\wudriver.dll 2012-06-19 15:30 . 2012-06-02 19:19 171904 —-a-w- c:\windows\system32\wuwebv.dll 2012-06-19 15:30 . 2012-06-02 19:12 33792 —-a-w- c:\windows\system32\wuapp.exe 2012-06-18 15:16 . 2012-06-18 16:32 ——– d—–w- c:\programdata\RegRun 2012-06-18 15:15 . 2012-06-18 15:15 2 –shatr- c:\windows\winstart.bat 2012-06-18 15:15 . 2012-06-18 15:15 ——– d—–w- c:\program files\Greatis 2012-06-13 08:24 . 2012-05-01 04:44 164352 —-a-w- c:\windows\system32\profsvc.dll 2012-06-13 08:24 . 2012-04-24 04:36 140288 —-a-w- c:\windows\system32\cryptsvc.dll 2012-06-13 08:24 . 2012-04-24 04:36 1158656 —-a-w- c:\windows\system32\crypt32.dll 2012-06-13 08:24 . 2012-04-24 04:36 103936 —-a-w- c:\windows\system32\cryptnet.dll 2012-06-09 22:28 . 2012-06-09 22:28 ——– d—–w- c:\program files\SecondLifeViewer 2012-06-06 03:53 . 2012-06-06 03:53 737072 —-a-w- c:\programdata\Microsoft\eHome\Packages\SportsV2\SportsTemplateCore-2\Microsoft.MediaCenter.Sports.UI.dll 2012-06-06 03:52 . 2012-06-06 03:52 4283672 —-a-w- c:\programdata\Microsoft\eHome\Packages\MCEClientUX\UpdateableMarkup-2\markup.dll 2012-06-06 03:52 . 2012-06-06 03:52 42776 —-a-w- c:\programdata\Microsoft\eHome\Packages\MCEClientUX\dSM-2\StartResources.dll 2012-06-06 03:52 . 2012-06-06 03:52 539984 —-a-w- c:\programdata\Microsoft\eHome\Packages\MCESpotlight\MCESpotlight-2\SpotlightResources.dll . . . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2012-06-27 16:42 . 2012-05-27 02:04 737072 —-a-w- c:\programdata\Microsoft\eHome\Packages\SportsV2\SportsTemplateCore\Microsoft.MediaCenter.Sports.UI.dll 2012-05-27 01:54 . 2012-05-27 01:54 4283672 —-a-w- c:\programdata\Microsoft\eHome\Packages\MCEClientUX\UpdateableMarkup\markup.dll 2012-05-27 01:53 . 2012-05-27 01:53 42776 —-a-w- c:\programdata\Microsoft\eHome\Packages\MCEClientUX\dSM\StartResources.dll 2012-05-27 01:53 . 2012-05-27 01:53 539984 —-a-w- c:\programdata\Microsoft\eHome\Packages\MCESpotlight\MCESpotlight\SpotlightResources.dll 2012-04-17 14:11 . 2011-08-31 03:44 33280 —-a-w- c:\windows\system32\iolobtdfg.exe 2012-04-17 14:11 . 2011-08-31 03:44 15360 —-a-w- c:\windows\system32\smrgdf.exe 2012-04-17 13:37 . 2011-08-31 03:44 2095816 —-a-w- c:\windows\system32\Incinerator32.dll 2012-06-19 22:05 . 2011-08-19 13:52 85472 —-a-w- c:\program files\mozilla firefox\components\browsercomps.dll . . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 . [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks] "{81017EA9-9AA8-4A6A-9734-7AF40E7D593F}"= "c:\program files\Yahoo!\Companion\Installs\cpn0\YTNavAssist.dll" [2011-03-16 214840] . [HKEY_CLASSES_ROOT\clsid\{81017ea9-9aa8-4a6a-9734-7af40e7d593f}] [HKEY_CLASSES_ROOT\YTNavAssist.YTNavAssistPlugin.1] [HKEY_CLASSES_ROOT\TypeLib\{A31F34A1-EBD2-45A2-BF6D-231C1B987CC8}] [HKEY_CLASSES_ROOT\YTNavAssist.YTNavAssistPlugin] . [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "SUPERAntiSpyware"="c:\program files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2012-06-20 3905408] "Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2010-11-20 1174016] . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "iolo Startup"="c:\program files\iolo\Common\Lib\ioloLManager.exe" [2012-04-17 938680] "HP KEYBOARDg"="c:\program files\Hewlett-Packard\HP Wireless Elite Keyboard\HPKEYBOARDg.EXE" [2009-07-23 701592] "Windows Mobile Device Center"="c:\windows\WindowsMobile\wmdc.exe" [2007-05-31 648072] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "ConsentPromptBehaviorAdmin"= 5 (0x5) "ConsentPromptBehaviorUser"= 3 (0x3) "EnableUIADesktopToggle"= 0 (0x0) . [hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks] "{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2011-07-19 113024] . [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon] 2011-05-04 17:54 551296 —-a-w- c:\program files\SUPERAntiSpyware\SASWINLO.DLL . [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager] BootExecute REG_MULTI_SZ autocheck . [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\!SASCORE] @="" . [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ioloSystemService] @="Service" . R3 MozillaMaintenance;Mozilla Maintenance Service;c:\program files\Mozilla Maintenance Service\maintenanceservice.exe [x] R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [x] R3 VST_DPV;VST_DPV;c:\windows\system32\DRIVERS\VSTDPV3.SYS [x] R3 VSTHWBS2;VSTHWBS2;c:\windows\system32\DRIVERS\VSTBS23.SYS [x] R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe [x] R4 MemeoBackgroundService;MemeoBackgroundService;c:\program files\Memeo\AutoBackup\MemeoBackgroundService.exe [x] R4 SeagateDashboardService;Seagate Dashboard Service;c:\program files\Seagate\Seagate Dashboard\SeagateDashboardService.exe [x] S1 ElRawDisk;ElRawDisk;c:\windows\system32\drivers\ElRawDsk.sys [x] S1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\SASDIFSV.SYS [x] S1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [x] S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [x] S2 !SASCORE;SAS Core Service;c:\program files\SUPERAntiSpyware\SASCORE.EXE [x] S2 HsfXAudioService;HsfXAudioService;c:\windows\system32\svchost.exe [x] S2 ioloSystemService;iolo System Service;c:\program files\iolo\Common\Lib\ioloServiceManager.exe [x] S2 NPF;NetGroup Packet Filter Driver;c:\windows\system32\drivers\npf.sys [x] S2 nvUpdatusService;NVIDIA Update Service Daemon;c:\program files\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe [x] S3 HCW85BDA;Hauppauge WinTV 885 Video Capture;c:\windows\system32\drivers\HCW85BDA.sys [x] S3 netr73;RT73 USB Extensible Wireless LAN Card Driver;c:\windows\system32\DRIVERS\netr73.sys [x] S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt86win7.sys [x] . . — Other Services/Drivers In Memory — . *Deregistered* - ioloSGuardDriver *Deregistered* - tmcomm *Deregistered* - tmrkb . [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost] HsfXAudioService REG_MULTI_SZ HsfXAudioService WindowsMobile REG_MULTI_SZ wcescomm rapimgr LocalServiceRestricted REG_MULTI_SZ WcesComm RapiMgr . . ——- Supplementary Scan ——- . TCP: DhcpNameServer = 192.168.2.1 [removed] [removed] DPF: Garmin Communicator Plug-In - hxxps://static.garmincdn.com/gcp/ie/3.0.1.0/GarminAxControl.CAB FF - ProfilePath - c:\users\glori970\AppData\Roaming\Mozilla\Firefox\Profiles\6ygcnyc1.default\ FF - user.js: yahoo.ytff.general.dontshowhpoffer - true . . ——- File Associations ——- . JSEFile=NOTEPAD.EXE %1 . . ——————— LOCKED REGISTRY KEYS ——————— . [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\PCW\Security] @Denied: (Full) (Everyone) . Completion time: 2012-07-04 15:02:10 ComboFix-quarantined-files.txt 2012-07-04 19:02 ComboFix2.txt 2012-07-04 01:36 . Pre-Run: 945,279,090,688 bytes free Post-Run: 945,238,482,944 bytes free . - - End Of File - - 7602F780D56ADAC6847C0863E392B4DB
Hi,

Please download Malwarebytes' Anti-Malware to your desktop.

  • Right-click and Run as Administrator mbam-setup.exe and follow the prompts to install the program.
  • At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select Perform quick scan, then click Scan as shown below.

    [external image: Posted Image]
  • When the scan is complete, click OK, then Show Results to view the results.
  • Be sure that everything is checked, and click Remove Selected.
  • When completed, a log will open in Notepad. Please save it to a convenient location and post the results.


The log can also be found here:
C:\Documents and Settings\\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\Logs\mbam-log-date (time).txt
———-

Please run a free online scan with the ESET Online Scanner
Note: You will need to use Internet Explorer for this scan
  • Tick the box next to YES, I accept the Terms of Use
  • Click Start
  • When asked, allow the ActiveX control to install
  • Click Start
  • Make sure that the options Remove found threats is NOT selected and the option Scan unwanted applications is selected.
  • Click Scan (This scan can take several hours, so please be patient)
  • If there are threats that are found, please press List of found threats and then in the next window that opens press Export to text file…
  • Copy and paste/or attach that log as a reply to this topic
**Note** If not threats are found there will not be a log created.
———-

In your next reply please post the logs created by Malwarebytes and ESET online scanner. :)
Hi Jeff, neither ESET or MBAM found anything. Here's MBAM's log :D ~Gloria 2012/07/05 09:30:41 -0400 GLORI970-PC glori970 MESSAGE Executing scheduled update: Daily 2012/07/05 09:30:42 -0400 GLORI970-PC glori970 MESSAGE Starting protection 2012/07/05 09:30:45 -0400 GLORI970-PC glori970 MESSAGE Protection started successfully 2012/07/05 09:30:48 -0400 GLORI970-PC glori970 MESSAGE Starting IP protection 2012/07/05 09:30:49 -0400 GLORI970-PC glori970 MESSAGE IP Protection started successfully 2012/07/05 09:30:49 -0400 GLORI970-PC glori970 MESSAGE Scheduled update executed successfully: database updated from version v2012.07.05.01 to version v2012.07.05.05 2012/07/05 09:30:49 -0400 GLORI970-PC glori970 MESSAGE Starting database refresh 2012/07/05 09:30:49 -0400 GLORI970-PC glori970 MESSAGE Stopping IP protection 2012/07/05 09:33:23 -0400 GLORI970-PC glori970 MESSAGE IP Protection stopped 2012/07/05 09:33:25 -0400 GLORI970-PC glori970 MESSAGE Database refreshed successfully 2012/07/05 09:33:25 -0400 GLORI970-PC glori970 MESSAGE Starting IP protection 2012/07/05 09:33:27 -0400 GLORI970-PC glori970 MESSAGE IP Protection started successfully
Hi Jeff, my pc is still painfully slow on start up and is loading pages like I'm on dial-up instead of broadband. slow slow slow. Rootkit Buster is showing the same self-replicating rootkits in my media player. I am also noticing my memory is being eaten faster too. Im defragging my memory 5 times a day with IOLO's system mechanic just to keep it at around 60 percent. Thanks for taking the time to look at all this for me, it's much appreciated.
Hi,

Ok…let's dig deeper. :)

Please download TDSSKiller.zip
  • Extract it to your desktop
  • Double click TDSSKiller.exe
  • when the window opens, click on Change Parameters
  • under ”Additional options”, put a check mark in the box next to “Detect TDLFS File System”
  • click OK
  • Press Start Scan
    • Only if Malicious objects are found then ensure Cure is selected
    • Then click Continue > Reboot now
  • Attach the log in your next reply
    • A copy of the log will be saved automatically to the root of the drive (typically C:\)
———-

OTL
  • Download OTL to your desktop.
  • Right-click and Run as Administrator on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • Select All Users
  • When the window appears, underneath Output at the top change it to Minimal Output.
  • Check the boxes beside LOP Check and Purity Check.
  • Under the Custom Scan box paste this in

    netsvcs
    /md5start
    consrv.dll
    explorer.exe
    winlogon.exe
    Userinit.exe
    svchost.exe
    /md5stop
    CREATERESTOREPOINT
  • Click the Quick Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
  • When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt.
    Note:These logs can be located in the OTL. folder on you C:\ drive if they fail to open automatically.
  • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post it with your next reply. You may need two posts to fit them both in.
———-
Hi Jeff, Thank you so much, i really appreciate your help with this. here are the logs :) ~Gloria
OTL Extras logfile created on: 7/5/2012 12:05:17 PM - Run 1
OTL by OldTimer - Version 3.2.53.1 Folder = C:\Users\glori970\Downloads
Professional Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7601.17514)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

3.00 Gb Total Physical Memory | 2.18 Gb Available Physical Memory | 72.61% Memory free
6.00 Gb Paging File | 4.80 Gb Available in Paging File | 80.06% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 931.41 Gb Total Space | 880.17 Gb Free Space | 94.50% Space Free | Partition Type: NTFS

Computer Name: GLORI970-PC | User Name: glori970 | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – C:\Windows\System32\control.exe (Microsoft Corporation)
.hlp [@ = hlpfile] – C:\Windows\winhlp32.exe (Microsoft Corporation)

[HKEY_USERS\S-1-5-21-3142601519-2184618316-1143777451-1000\SOFTWARE\Classes\]
.html [@ = FirefoxHTML] – C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
hlpfile [open] – %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] – Reg Error: Value error.
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1
"FirewallDisableNotify" = 0
"AntiVirusDisableNotify" = 0
"UpdatesDisableNotify" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"VistaSp1" = Reg Error: Unknown registry data type – File not found
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]

========== System Restore Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile]

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]


========== Vista Active Open Ports Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{10B2486A-FD0D-4973-8B9D-FE4660B0E0BD}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=@firewallapi.dll,-28539 |
"{15C0B803-AD98-4F1C-8EE9-CCF885DBA691}" = rport=138 | protocol=17 | dir=out | app=system |
"{21B6BC66-22E8-481C-9B7C-96D83ED7C14D}" = rport=445 | protocol=6 | dir=out | app=system |
"{234450F4-BD57-4419-A269-F91443084935}" = rport=10243 | protocol=6 | dir=out | app=system |
"{32595288-19F7-4790-B5EA-504F97547C4D}" = lport=139 | protocol=6 | dir=in | app=system |
"{326D82BA-E01D-45B9-A6A0-AB4C74049CED}" = lport=2177 | protocol=17 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{3454FFB8-4D94-4525-931B-8E8389CA27DC}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{35670C1E-F855-4AB5-BFF9-1869A30D363B}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{3B20B918-5790-40AB-AD20-A8A8020F5AA4}" = rport=2177 | protocol=17 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{4F57AAF2-B2F8-444A-B459-C62D7AD0A43B}" = lport=5721 | protocol=6 | dir=in | svc=rapimgr | app=%systemroot%\system32\svchost.exe |
"{4FE44844-54FE-42E4-9380-F08F8BBF0EF2}" = lport=138 | protocol=17 | dir=in | app=system |
"{5DEA9E29-1B87-47FF-8D46-FA6071885F6D}" = rport=137 | protocol=17 | dir=out | app=system |
"{73FC567A-6ED5-47D6-8C9D-F7455386C8E1}" = lport=5678 | protocol=6 | dir=in | app=%systemroot%\windowsmobile\wmdhost.exe |
"{7D9B324E-73AE-487D-89FE-AB4C25B97E45}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{871967E6-BB64-4AEA-B527-DC02C8211DD8}" = lport=999 | protocol=6 | dir=in | app=%systemroot%\windowsmobile\wmdhost.exe |
"{8D1158D4-D7BB-4DFC-A004-2CFB8420B533}" = lport=137 | protocol=17 | dir=in | app=system |
"{8D9BD3AE-994B-4AD0-BF7E-95D3959F55DF}" = rport=5679 | protocol=17 | dir=out | svc=rapimgr | app=%systemroot%\system32\svchost.exe |
"{8DB52A30-83B7-48B0-A253-44E359F55C92}" = lport=990 | protocol=6 | dir=in | svc=rapimgr | app=%systemroot%\system32\svchost.exe |
"{8DBDB7FE-AC11-43A9-803A-D0F02F0BE666}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{8EDD0F01-44D9-4316-B33D-76E1742DFEE6}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe |
"{972F5630-0076-427A-941F-89A8ADC3EF28}" = lport=445 | protocol=6 | dir=in | app=system |
"{B2818656-E9D7-4AD5-BC9E-E441139FD1D9}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{BB2D9FD7-DC6D-4845-B35B-615B25C02003}" = rport=2177 | protocol=6 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{C70783FB-24C5-4880-881A-0A6E3BBFE541}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{CD59352E-A0D1-4F03-8379-E75CF1182136}" = lport=2869 | protocol=6 | dir=in | app=system |
"{DDDC59FD-0E1B-4535-A3D5-8963BD5C4B4F}" = rport=139 | protocol=6 | dir=out | app=system |
"{E49ADA50-D800-46A3-813D-B15E290B8221}" = lport=26675 | protocol=6 | dir=in | name=@%systemroot%\windowsmobile\wmdcbase.exe,-4006 |
"{F2E34E77-1C21-434B-BFC8-CB6C7F197026}" = lport=2177 | protocol=6 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{FA15DF79-DF82-4C49-B56F-2FAC8C59C88B}" = lport=10243 | protocol=6 | dir=in | app=system |

========== Vista Active Application Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{19AAE553-488F-4C51-9FCF-BFAF7DB68864}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
"{1D9C0B08-7F2F-48B6-8839-81819DEE41C0}" = protocol=6 | dir=out | svc=wcescomm | app=%systemroot%\system32\svchost.exe |
"{2C25816C-B52C-42B7-957E-498592C5952F}" = protocol=58 | dir=out | name=@firewallapi.dll,-28546 |
"{2D03A95B-8998-4ED1-83DD-8197938819DA}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
"{2E851435-BC21-4FA2-8C87-DC4E9FC1FF53}" = protocol=58 | dir=in | name=@firewallapi.dll,-28545 |
"{3896CC56-C2D5-4012-AAE3-162BD1735B5A}" = protocol=6 | dir=in | app=c:\program files\world of warcraft\launcher.patch.exe |
"{40F8B509-6F5D-4634-8A4E-0651F548CFEB}" = protocol=17 | dir=out | svc=wcescomm | app=%systemroot%\system32\svchost.exe |
"{4205EC04-B764-405F-AEF8-BA2BFC43FD35}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{4B810F1E-8472-4B19-AF5B-EA410974B02A}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe |
"{4DB4338E-A457-4DE6-B471-E8F1F87BA01E}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{5374B6EA-FFDA-48EA-B61C-E1FD51A66AAC}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
"{5FE08C20-8B0A-4D25-BF43-9B4017793DF1}" = protocol=6 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
"{62890899-05DF-4F4F-ABF3-41E24106B1EE}" = protocol=6 | dir=out | svc=rapimgr | app=%systemroot%\system32\svchost.exe |
"{662BEEFC-5EB8-4166-AF66-E0940E69E320}" = protocol=6 | dir=out | app=system |
"{6B8DB320-88B4-4B03-B061-EF0F53961092}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
"{70D43543-F685-4ED6-92E0-06AE017FA742}" = protocol=17 | dir=out | svc=rapimgr | app=%systemroot%\system32\svchost.exe |
"{78E6D042-BC80-42EB-B60D-D26733946A1D}" = protocol=17 | dir=in | app=c:\program files\world of warcraft\launcher.patch.exe |
"{97000AEF-02BC-4A3E-B5B2-02F8517589DD}" = protocol=1 | dir=in | name=@firewallapi.dll,-28543 |
"{9E5AD0EB-A186-405E-AF80-7A208798D8A8}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
"{AA7B893E-1790-40C7-B2B0-81352A8AA346}" = protocol=1 | dir=out | name=@firewallapi.dll,-28544 |
"{AC1A9125-7ED9-4340-80ED-97C120296796}" = protocol=17 | dir=in | app=c:\program files\world of warcraft\launcher.exe |
"{B5AC8BA0-9884-48FB-8AFB-4FB313216C53}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{BC29C004-C196-45A9-99F6-280212FCA6E1}" = protocol=6 | dir=in | svc=wcescomm | app=%systemroot%\system32\svchost.exe |
"{D3F9E5B3-5BCE-42C1-8DE7-8B3009EBD320}" = protocol=6 | dir=in | app=c:\program files\world of warcraft\launcher.exe |
"{D8B3E0AE-415C-494E-9A28-2BB4264A85F8}" = dir=in | app=c:\program files\seagate\seagate dashboard\hipservagent\hipservagent.exe |
"{E133E42D-0850-4BEA-AB1F-13932774D5C0}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"TCP Query User{09511605-F3D2-4B98-B3F8-4450FA66EABD}C:\program files\world of warcraft\launcher.exe" = protocol=6 | dir=in | app=c:\program files\world of warcraft\launcher.exe |
"TCP Query User{36AD1DB1-9ADA-4890-8DAE-012B2CB325CC}C:\program files\secondlifeviewer2\slvoice.exe" = protocol=6 | dir=in | app=c:\program files\secondlifeviewer2\slvoice.exe |
"TCP Query User{62217AE1-67E0-4F75-BC34-DE8E8F70B9FF}C:\program files\secondlifeviewer\slvoice.exe" = protocol=6 | dir=in | app=c:\program files\secondlifeviewer\slvoice.exe |
"TCP Query User{7B543D23-9BFE-47B8-B3B2-90D444F4F580}C:\program files\world of warcraft\temp\wow-4.2.1.2617-enus-tools-downloader.exe" = protocol=6 | dir=in | app=c:\program files\world of warcraft\temp\wow-4.2.1.2617-enus-tools-downloader.exe |
"TCP Query User{994C7AF3-CDAE-4399-8E08-C23E1571AB2C}C:\program files\world of warcraft\temp\wow-4.2.1.2609-enus-tools-downloader.exe" = protocol=6 | dir=in | app=c:\program files\world of warcraft\temp\wow-4.2.1.2609-enus-tools-downloader.exe |
"TCP Query User{BC8C6E8F-9754-4FE4-9C35-4F8AFA6E5F61}C:\program files\world of warcraft\backgrounddownloader.exe" = protocol=6 | dir=in | app=c:\program files\world of warcraft\backgrounddownloader.exe |
"TCP Query User{C49ABC31-C4C7-42EA-A5C7-99B1F4155D09}C:\program files\secondlifeviewer2\slvoice.exe" = protocol=6 | dir=in | app=c:\program files\secondlifeviewer2\slvoice.exe |
"UDP Query User{6C02D9C4-38DB-4A17-8BBF-2D8BD0B0774B}C:\program files\world of warcraft\backgrounddownloader.exe" = protocol=17 | dir=in | app=c:\program files\world of warcraft\backgrounddownloader.exe |
"UDP Query User{7CED1111-6CFD-45C7-A9BF-FCE0B4E1BA77}C:\program files\world of warcraft\temp\wow-4.2.1.2609-enus-tools-downloader.exe" = protocol=17 | dir=in | app=c:\program files\world of warcraft\temp\wow-4.2.1.2609-enus-tools-downloader.exe |
"UDP Query User{9EB1ACD9-B605-43C8-885B-5CC4F6CF85C9}C:\program files\secondlifeviewer2\slvoice.exe" = protocol=17 | dir=in | app=c:\program files\secondlifeviewer2\slvoice.exe |
"UDP Query User{B899882C-04D7-4D58-BFCC-F2A9BD10BF52}C:\program files\world of warcraft\temp\wow-4.2.1.2617-enus-tools-downloader.exe" = protocol=17 | dir=in | app=c:\program files\world of warcraft\temp\wow-4.2.1.2617-enus-tools-downloader.exe |
"UDP Query User{D9E710A5-9F41-49CA-B417-782D9C3C56A5}C:\program files\secondlifeviewer2\slvoice.exe" = protocol=17 | dir=in | app=c:\program files\secondlifeviewer2\slvoice.exe |
"UDP Query User{E4FD1A1B-69E8-41CD-961F-A1F2A23B271D}C:\program files\secondlifeviewer\slvoice.exe" = protocol=17 | dir=in | app=c:\program files\secondlifeviewer\slvoice.exe |
"UDP Query User{F10342A0-4E52-4A61-B1A2-FBC0F437F666}C:\program files\world of warcraft\launcher.exe" = protocol=17 | dir=in | app=c:\program files\world of warcraft\launcher.exe |

========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{17E3A651-12B9-4149-BAE8-E6FB9A5ADC4F}" = Microsoft Works Suite Add-in for Microsoft Word
"{1BC77CEF-C52F-4092-BF87-0D4E6B86D860}" = Memeo Share
"{3C3901C5-3455-3E0A-A214-0B093A5070A6}" = Microsoft .NET Framework 4 Client Profile
"{55FD1D5A-7AEF-4DA3-8FAF-A71B2A52FFC7}_is1" = iolo technologies' System Mechanic
"{6D52C408-B09A-4520-9B18-475B81D393F1}" = Microsoft Works
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{75B7F766-7998-44d8-A202-F1EC76A121BA}" = Memeo AutoSync
"{81784157-3D4D-4bc1-B988-B24C32A26DA8}" = Memeo Send
"{8E666407-AC41-46a2-9692-6C7BFCBFDD37}" = Memeo Instant Backup
"{901B0409-6000-11D3-8CFE-0050048383C9}" = Microsoft Word 2002
"{904CCF62-818D-4675-BC76-D37EB399F917}" = Windows Mobile Device Center
"{AC76BA86-7AD7-1033-7B44-A94000000001}" = Adobe Reader 9.4.0
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.ControlPanel" = NVIDIA Control Panel 280.26
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver" = NVIDIA Graphics Driver 280.26
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.NVIRUSB" = NVIDIA 3D Vision Controller Driver 280.19
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX" = NVIDIA PhysX System Software 9.10.0514
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Update" = NVIDIA Update 1.4.28
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_installer" = NVIDIA Install Application
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_NVIDIA.Update" = NVIDIA Update Components
"{B9DB4C76-01A4-46D5-8910-F7AA6376DBAF}" = NVIDIA PhysX
"{C3A11907-930D-41AC-A135-CC3B12F92011}" = Seagate Dashboard
"{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}" = SUPERAntiSpyware
"{DE1AF137-C455-494A-A817-EFE44BCCFDEE}" = Works Upgrade
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{FE23D063-934D-4829-A0D8-00634CE79B4A}" = Adobe AIR
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 11 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 11 Plugin
"CNXT_MODEM_PCI_VEN_14F1&DEV_2F20&SUBSYS_200C14F1" = Soft Data Fax Modem with SmartCP
"ESET Online Scanner" = ESET Online Scanner v3
"HP Wireless Elite Keyboard_is1" = HP Wireless Elite Keyboard
"Malwarebytes' Anti-Malware_is1" = Malwarebytes Anti-Malware version 1.61.0.1400
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"Mozilla Firefox 13.0.1 (x86 en-US)" = Mozilla Firefox 13.0.1 (x86 en-US)
"MozillaMaintenanceService" = Mozilla Maintenance Service
"NVIDIA StereoUSB Driver" = NVIDIA 3D Vision Controller Driver
"SecondLifeViewer" = SecondLifeViewer (remove only)
"WinPcapInst" = WinPcap 4.1.1
"Works2006Setup" = Microsoft Works Suite 2006 Setup Launcher
"World of Warcraft" = World of Warcraft
"Yahoo! Companion" = Yahoo! Toolbar
"Yahoo! Software Update" = Yahoo! Software Update

========== Last 20 Event Log Errors ==========

[ Application Events ]
Error - 6/18/2012 12:10:17 PM | Computer Name = glori970-PC | Source = Microsoft-Windows-CAPI2 | ID = 513
Description = Cryptographic Services failed while processing the OnIdentity() call
in the System Writer Object. Details: AddLegacyDriverFiles: Unable to back up image
of binary TfNetMon. System Error: The system cannot find the file specified. .

Error - 6/18/2012 12:10:17 PM | Computer Name = glori970-PC | Source = Microsoft-Windows-CAPI2 | ID = 513
Description = Cryptographic Services failed while processing the OnIdentity() call
in the System Writer Object. Details: AddLegacyDriverFiles: Unable to back up image
of binary TfFsMon. System Error: The system cannot find the file specified. .

Error - 6/18/2012 12:23:36 PM | Computer Name = glori970-PC | Source = VSS | ID = 8194
Description =

Error - 6/18/2012 4:48:51 PM | Computer Name = glori970-PC | Source = Application Error | ID = 1000
Description = Faulting application name: setup.exe_Trend Micro iRobot, version:
1.50.0.1154, time stamp: 0x4e1d0b67 Faulting module name: libcurl.dll, version: 7.21.1.0,
time stamp: 0x4ca465d4 Exception code: 0xc000000d Fault offset: 0x0003f1e2 Faulting
process id: 0x1384 Faulting application start time: 0x01cd4d93a1bf36d0 Faulting application
path: C:\Users\glori970\AppData\Local\Temp\7zS1DAE.tmp\setup.exe Faulting module
path: C:\Users\glori970\AppData\Local\Temp\7zS1DAE.tmp\libcurl.dll Report Id: 01fa7442-b987-11e1-a3e0-001e8c2b0cab

Error - 6/19/2012 5:20:25 PM | Computer Name = glori970-PC | Source = Application Hang | ID = 1002
Description = The program iexplore.exe version 8.0.7601.17514 stopped interacting
with Windows and was closed. To see if more information about the problem is available,
check the problem history in the Action Center control panel. Process ID: b38 Start
Time: 01cd4e51dcc9c560 Termination Time: 570 Application Path: C:\Program Files\Internet
Explorer\iexplore.exe Report Id:

Error - 6/22/2012 2:18:58 PM | Computer Name = glori970-PC | Source = Application Hang | ID = 1002
Description = The program iexplore.exe version 8.0.7601.17514 stopped interacting
with Windows and was closed. To see if more information about the problem is available,
check the problem history in the Action Center control panel. Process ID: bbc Start
Time: 01cd508fabd88cd5 Termination Time: 6 Application Path: C:\Program Files\Internet
Explorer\iexplore.exe Report Id: b0ded93f-bc96-11e1-b36b-001e8c2b0cab

Error - 6/25/2012 12:26:43 PM | Computer Name = glori970-PC | Source = Application Hang | ID = 1002
Description = The program Explorer.EXE version 6.1.7601.17567 stopped interacting
with Windows and was closed. To see if more information about the problem is available,
check the problem history in the Action Center control panel. Process ID: 6d0 Start
Time: 01cd52e93e8aa43f Termination Time: 290 Application Path: C:\Windows\Explorer.EXE

Report
Id: 70723d43-bee2-11e1-a173-001e8c2b0cab

Error - 6/27/2012 8:26:34 PM | Computer Name = glori970-PC | Source = Application Error | ID = 1000
Description = Faulting application name: iexplore.exe, version: 8.0.7601.17514,
time stamp: 0x4ce79912 Faulting module name: Flash11c.ocx, version: 11.0.1.152, time
stamp: 0x4e7d1782 Exception code: 0x40000015 Fault offset: 0x00405b99 Faulting process
id: 0xffc Faulting application start time: 0x01cd54b3d64ba833 Faulting application
path: C:\Program Files\Internet Explorer\iexplore.exe Faulting module path: C:\Windows\system32\Macromed\Flash\Flash11c.ocx
Report
Id: e9c06c08-c0b7-11e1-afe0-001e8c2b0cab

Error - 6/30/2012 6:39:51 PM | Computer Name = glori970-PC | Source = Application Hang | ID = 1002
Description = The program iexplore.exe version 8.0.7601.17514 stopped interacting
with Windows and was closed. To see if more information about the problem is available,
check the problem history in the Action Center control panel. Process ID: 514 Start
Time: 01cd56e7c1789903 Termination Time: 10 Application Path: C:\Program Files\Internet
Explorer\iexplore.exe Report Id: 7c42589f-c304-11e1-aea2-001e8c2b0cab

Error - 7/5/2012 12:03:17 PM | Computer Name = glori970-PC | Source = Application Hang | ID = 1002
Description = The program OTL.exe version 3.2.53.1 stopped interacting with Windows
and was closed. To see if more information about the problem is available, check
the problem history in the Action Center control panel. Process ID: c28 Start Time:
01cd5ac720c142e5 Termination Time: 0 Application Path: C:\Users\glori970\Downloads\OTL.exe

Report
Id: e9104175-c6ba-11e1-b5e7-001e8c2b0cab

[ Media Center Events ]
Error - 6/3/2012 11:39:30 AM | Computer Name = glori970-PC | Source = MCUpdate | ID = 0
Description = 11:39:29 AM - Error connecting to the internet. 11:39:29 AM - Unable
to contact server..

Error - 6/3/2012 11:57:14 PM | Computer Name = glori970-PC | Source = MCUpdate | ID = 0
Description = 11:57:14 PM - Error connecting to the internet. 11:57:14 PM - Unable
to contact server..

Error - 6/3/2012 11:57:20 PM | Computer Name = glori970-PC | Source = MCUpdate | ID = 0
Description = 11:57:19 PM - Error connecting to the internet. 11:57:19 PM - Unable
to contact server..

Error - 6/4/2012 11:49:26 AM | Computer Name = glori970-PC | Source = MCUpdate | ID = 0
Description = 11:49:26 AM - Error connecting to the internet. 11:49:26 AM - Unable
to contact server..

Error - 6/4/2012 11:49:32 AM | Computer Name = glori970-PC | Source = MCUpdate | ID = 0
Description = 11:49:31 AM - Error connecting to the internet. 11:49:31 AM - Unable
to contact server..

Error - 6/4/2012 11:53:07 PM | Computer Name = glori970-PC | Source = MCUpdate | ID = 0
Description = 11:53:07 PM - Error connecting to the internet. 11:53:07 PM - Unable
to contact server..

Error - 6/4/2012 11:53:13 PM | Computer Name = glori970-PC | Source = MCUpdate | ID = 0
Description = 11:53:12 PM - Error connecting to the internet. 11:53:12 PM - Unable
to contact server..

Error - 6/5/2012 11:01:09 AM | Computer Name = glori970-PC | Source = MCUpdate | ID = 0
Description = 11:01:09 AM - Error connecting to the internet. 11:01:09 AM - Unable
to contact server..

Error - 6/5/2012 11:01:15 AM | Computer Name = glori970-PC | Source = MCUpdate | ID = 0
Description = 11:01:14 AM - Error connecting to the internet. 11:01:14 AM - Unable
to contact server..

Error - 6/27/2012 11:40:50 AM | Computer Name = glori970-PC | Source = MCUpdate | ID = 0
Description = 11:40:50 AM - Failed to retrieve SportsV2 (Error: The underlying connection
was closed: Could not establish trust relationship for the SSL/TLS secure channel.)


[ System Events ]
Error - 7/3/2012 9:31:11 PM | Computer Name = glori970-PC | Source = Service Control Manager | ID = 7030
Description = The PEVSystemStart service is marked as an interactive service. However,
the system is configured to not allow interactive services. This service may not
function properly.

Error - 7/3/2012 9:33:21 PM | Computer Name = glori970-PC | Source = Service Control Manager | ID = 7030
Description = The PEVSystemStart service is marked as an interactive service. However,
the system is configured to not allow interactive services. This service may not
function properly.

Error - 7/3/2012 9:35:27 PM | Computer Name = glori970-PC | Source = Service Control Manager | ID = 7030
Description = The PEVSystemStart service is marked as an interactive service. However,
the system is configured to not allow interactive services. This service may not
function properly.

Error - 7/4/2012 11:06:03 AM | Computer Name = glori970-PC | Source = volsnap | ID = 393252
Description = The shadow copies of volume C: were aborted because the shadow copy
storage could not grow due to a user imposed limit.

Error - 7/4/2012 12:25:05 PM | Computer Name = glori970-PC | Source = DCOM | ID = 10010
Description =

Error - 7/4/2012 2:56:51 PM | Computer Name = glori970-PC | Source = Service Control Manager | ID = 7030
Description = The PEVSystemStart service is marked as an interactive service. However,
the system is configured to not allow interactive services. This service may not
function properly.

Error - 7/4/2012 2:58:59 PM | Computer Name = glori970-PC | Source = Service Control Manager | ID = 7030
Description = The PEVSystemStart service is marked as an interactive service. However,
the system is configured to not allow interactive services. This service may not
function properly.

Error - 7/4/2012 3:00:52 PM | Computer Name = glori970-PC | Source = Service Control Manager | ID = 7030
Description = The PEVSystemStart service is marked as an interactive service. However,
the system is configured to not allow interactive services. This service may not
function properly.

Error - 7/5/2012 11:31:37 AM | Computer Name = glori970-PC | Source = DCOM | ID = 10010
Description =

Error - 7/5/2012 11:55:03 AM | Computer Name = glori970-PC | Source = DCOM | ID = 10010
Description =


< End of report >
and you were right.. it does take 2 posts for these logs. here's the 2nd. ~gloria

OTL logfile created on: 7/5/2012 12:05:17 PM - Run 1
OTL by OldTimer - Version 3.2.53.1 Folder = C:\Users\glori970\Downloads
Professional Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7601.17514)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

3.00 Gb Total Physical Memory | 2.18 Gb Available Physical Memory | 72.61% Memory free
6.00 Gb Paging File | 4.80 Gb Available in Paging File | 80.06% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 931.41 Gb Total Space | 880.17 Gb Free Space | 94.50% Space Free | Partition Type: NTFS

Computer Name: GLORI970-PC | User Name: glori970 | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Users\glori970\Downloads\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\SUPERAntiSpyware\SUPERANTISPYWARE.EXE (SUPERAntiSpyware.com)
PRC - C:\Program Files\iolo\System Mechanic\SystemGuardAlerter.exe (iolo technologies, LLC)
PRC - C:\Program Files\iolo\Common\Lib\ioloServiceManager.exe (iolo technologies, LLC)
PRC - C:\Malwarebytes' Anti-Malware\mbamservice.exe (Malwarebytes Corporation)
PRC - C:\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
PRC - C:\Program Files\SUPERAntiSpyware\SASCore.exe (SUPERAntiSpyware.com)
PRC - C:\Program Files\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe (NVIDIA Corporation)
PRC - C:\Windows\explorer.exe (Microsoft Corporation)
PRC - C:\Windows\System32\taskhost.exe (Microsoft Corporation)
PRC - C:\Program Files\Hewlett-Packard\HP Wireless Elite Keyboard\HPKEYBOARDg.EXE (Hewlett-Packard)


========== Modules (No Company Name) ==========

MOD - C:\ProgramData\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\SD10006.dll ()
MOD - C:\ProgramData\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\SD10007.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\Microsoft.VisualBas#\6c59a14a23f734093e80d6093e25302a\Microsoft.VisualBasic.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Web\a501b7960f6c6e2e39162b83f3303aaa\System.Web.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\6bb439b3f87736d3248ae27d43e2c0d6\System.Drawing.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System\ce9ff6baf9053ed2ed673d948179195c\System.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\acfc1391e45fedd2a359778ea57d914c\mscorlib.ni.dll ()
MOD - C:\ProgramData\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\UIREPAIR.DLL ()
MOD - C:\ProgramData\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\SD10005.dll ()


========== Win32 Services (SafeList) ==========

SRV - (MozillaMaintenance) – C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe (Mozilla Foundation)
SRV - (ioloSystemService) – C:\Program Files\iolo\Common\Lib\ioloServiceManager.exe (iolo technologies, LLC)
SRV - (MBAMService) – C:\Malwarebytes' Anti-Malware\mbamservice.exe (Malwarebytes Corporation)
SRV - (WatAdminSvc) – C:\Windows\System32\Wat\WatAdminSvc.exe (Microsoft Corporation)
SRV - (!SASCORE) – C:\Program Files\SUPERAntiSpyware\SASCore.exe (SUPERAntiSpyware.com)
SRV - (nvUpdatusService) – C:\Program Files\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe (NVIDIA Corporation)
SRV - (SeagateDashboardService) – C:\Program Files\Seagate\Seagate Dashboard\SeagateDashboardService.exe (Memeo)
SRV - (WinHttpAutoProxySvc) – winhttp.dll (Microsoft Corporation)
SRV - (MemeoBackgroundService) – C:\Program Files\Memeo\AutoBackup\MemeoBackgroundService.exe (Memeo)
SRV - (rpcapd) Remote Packet Capture Protocol v.0 (experimental) – C:\Program Files\WinPcap\rpcapd.exe (CACE Technologies, Inc.)
SRV - (StorSvc) – C:\Windows\System32\StorSvc.dll (Microsoft Corporation)
SRV - (SensrSvc) – C:\Windows\System32\sensrsvc.dll (Microsoft Corporation)
SRV - (PeerDistSvc) – C:\Windows\System32\PeerDistSvc.dll (Microsoft Corporation)
SRV - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV - (HsfXAudioService) – C:\Windows\System32\XAudio32.dll (Conexant Systems, Inc.)
SRV - (YahooAUService) – C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe (Yahoo! Inc.)
SRV - (WcesComm) – C:\Windows\WindowsMobile\wcescomm.dll (Microsoft Corporation)
SRV - (RapiMgr) – C:\Windows\WindowsMobile\rapimgr.dll (Microsoft Corporation)


========== Driver Services (SafeList) ==========

DRV - (catchme) – C:\Users\glori970\AppData\Local\Temp\catchme.sys File not found
DRV - (MBAMProtector) – C:\Windows\System32\drivers\mbam.sys (Malwarebytes Corporation)
DRV - (nvlddmkm) – C:\Windows\System32\drivers\nvlddmkm.sys (NVIDIA Corporation)
DRV - (netr73) – C:\Windows\System32\drivers\netr73.sys (Ralink Technology, Corp.)
DRV - (SASDIFSV) – C:\Program Files\SUPERAntiSpyware\sasdifsv.sys (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (SASKUTIL) – C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (vmbus) – C:\Windows\System32\drivers\vmbus.sys (Microsoft Corporation)
DRV - (storflt) – C:\Windows\System32\drivers\vmstorfl.sys (Microsoft Corporation)
DRV - (storvsc) – C:\Windows\System32\drivers\storvsc.sys (Microsoft Corporation)
DRV - (TsUsbFlt) – C:\Windows\System32\drivers\TsUsbFlt.sys (Microsoft Corporation)
DRV - (VMBusHID) – C:\Windows\System32\drivers\VMBusHID.sys (Microsoft Corporation)
DRV - (s3cap) – C:\Windows\System32\drivers\vms3cap.sys (Microsoft Corporation)
DRV - (NPF) – C:\Windows\System32\drivers\npf.sys (CACE Technologies, Inc.)
DRV - (HCW85BDA) – C:\Windows\System32\drivers\HCW85BDA.sys (Hauppauge Computer Works)
DRV - (Serial) – C:\Windows\System32\drivers\serial.sys (Brother Industries Ltd.)
DRV - (VSTHWBS2) – C:\Windows\System32\drivers\VSTBS23.SYS (Conexant Systems, Inc.)
DRV - (XAudio) – C:\Windows\System32\drivers\XAudio32.sys (Conexant Systems, Inc.)
DRV - (HSXHWBS2) – C:\Windows\System32\drivers\HSXHWBS2.sys (Conexant Systems, Inc.)
DRV - (HSF_DP) – C:\Windows\System32\drivers\HSX_DP.sys (Conexant Systems, Inc.)
DRV - (ElRawDisk) – C:\Windows\System32\drivers\ElRawDsk.sys (EldoS Corporation)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC


IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0



IE - HKU\S-1-5-21-3142601519-2184618316-1143777451-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://www.msn.com/?ocid=iehp
IE - HKU\S-1-5-21-3142601519-2184618316-1143777451-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-us
IE - HKU\S-1-5-21-3142601519-2184618316-1143777451-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = D4 FB 7E 26 18 5A CD 01 [binary data]
IE - HKU\S-1-5-21-3142601519-2184618316-1143777451-1000\..\URLSearchHook: {81017EA9-9AA8-4A6A-9734-7AF40E7D593F} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\YTNavAssist.dll (Yahoo! Inc.)
IE - HKU\S-1-5-21-3142601519-2184618316-1143777451-1000\..\SearchScopes,DefaultScope = {90F6AADB-6ABF-4E36-A18D-04CCEE5293CD}
IE - HKU\S-1-5-21-3142601519-2184618316-1143777451-1000\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}…amp;FORM=IE8SRC
IE - HKU\S-1-5-21-3142601519-2184618316-1143777451-1000\..\SearchScopes\{90F6AADB-6ABF-4E36-A18D-04CCEE5293CD}: "URL" = http://search.yahoo.com/search?p={searchTe…amp;fr=chr-tyc8
IE - HKU\S-1-5-21-3142601519-2184618316-1143777451-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0


========== FireFox ==========



FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found

FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 13.0.1\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2012/06/19 18:05:34 | 000,000,000 | —D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Firefox 13.0.1\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2012/06/19 18:05:34 | 000,000,000 | —D | M]

[2011/08/19 09:53:15 | 000,000,000 | —D | M] (No name found) – C:\Users\glori970\AppData\Roaming\Mozilla\Extensions
[2012/05/19 16:59:41 | 000,000,000 | —D | M] (No name found) – C:\Users\glori970\AppData\Roaming\Mozilla\Firefox\Profiles\6ygcnyc1.default\extensions
[2012/05/19 16:59:41 | 000,000,000 | —D | M] (Yahoo! Toolbar) – C:\Users\glori970\AppData\Roaming\Mozilla\Firefox\Profiles\6ygcnyc1.default\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1}
[2011/08/19 09:52:51 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions
[2012/06/19 18:05:34 | 000,085,472 | —- | M] (Mozilla Foundation) – C:\Program Files\mozilla firefox\components\browsercomps.dll
[2012/06/19 18:05:32 | 000,002,252 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\bing.xml
[2012/06/19 18:05:32 | 000,002,040 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\twitter.xml

O1 HOSTS File: ([2009/06/10 17:39:37 | 000,000,824 | —- | M]) - C:\Windows\System32\drivers\etc\hosts
O2 - BHO: (&Yahoo! Toolbar Helper) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll (Yahoo! Inc.)
O3 - HKLM\..\Toolbar: (Yahoo! Toolbar) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll (Yahoo! Inc.)
O4 - HKLM..\Run: [HP KEYBOARDg] C:\Program Files\Hewlett-Packard\HP Wireless Elite Keyboard\HPKEYBOARDg.EXE (Hewlett-Packard)
O4 - HKLM..\Run: [iolo Startup] C:\Program Files\iolo\Common\Lib\ioloLManager.exe (iolo technologies, LLC)
O4 - HKLM..\Run: [Malwarebytes' Anti-Malware] C:\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
O4 - HKU\S-1-5-21-3142601519-2184618316-1143777451-1000..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERANTISPYWARE.EXE (SUPERAntiSpyware.com)
O4 - HKU\S-1-5-21-3142601519-2184618316-1143777451-1001..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (Microsoft Corporation)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-3142601519-2184618316-1143777451-1000\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-3142601519-2184618316-1143777451-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKU\S-1-5-21-3142601519-2184618316-1143777451-1001\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O9 - Extra Button: @C:\Windows\WindowsMobile\INetRepl.dll,-222 - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : @C:\Windows\WindowsMobile\INetRepl.dll,-223 - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll (Microsoft Corporation)
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} C:\Program Files\Yahoo!\Common\Yinsthelper.dll (Installation Support)
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} http://download.eset.com/special/eos/OnlineScanner.cab (OnlineScanner Control)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab (Shockwave Flash Object)
O16 - DPF: Garmin Communicator Plug-In https://static.garmincdn.com/gcp/ie/3.0.1.0…inAxControl.CAB (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{186D0D4E-8612-4824-9CD1-B097D9ABB3CE}: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{C2F9835C-85E5-445A-A00F-8490464B49B9}: DhcpNameServer = 192.168.1.1
O18 - Protocol\Handler\cardisabled - No CLSID value found
O18 - Protocol\Filter\application/octet-stream {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - mscoree.dll (Microsoft Corporation)
O18 - Protocol\Filter\application/x-complus {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - mscoree.dll (Microsoft Corporation)
O18 - Protocol\Filter\application/x-msdownload {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - mscoree.dll (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\System32\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - SystemPropertiesPerformance.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20 - Winlogon\Notify\!SASWinLogon: DllName - (C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL) - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL (SUPERAntiSpyware.com)
O28 - HKLM ShellExecuteHooks: {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - C:\Program Files\SUPERAntiSpyware\SASSEH.DLL (SuperAdBlocker.com)
O29 - HKLM SecurityProviders - (credssp.dll) - credssp.dll (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009/06/10 17:42:20 | 000,000,024 | —- | M] () - C:\autoexec.bat – [ NTFS ]
O34 - HKLM BootExecute: (autocheck)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)

NetSvcs: FastUserSwitchingCompatibility - File not found
NetSvcs: Ias - C:\Windows\System32\ias.dll (Microsoft Corporation)
NetSvcs: Nla - File not found
NetSvcs: Ntmssvc - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: SRService - File not found
NetSvcs: WmdmPmSp - File not found
NetSvcs: LogonHours - File not found
NetSvcs: PCAudit - File not found
NetSvcs: helpsvc - File not found
NetSvcs: uploadmgr - File not found

CREATERESTOREPOINT
Restore point Set: OTL Restore Point

========== Files/Folders - Created Within 30 Days ==========

[2012/07/05 11:57:38 | 000,000,000 | —D | C] – C:\Users\glori970\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\HP Wireless Elite Keyboard
[2012/07/04 23:24:30 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2012/07/04 23:24:29 | 000,022,344 | —- | C] (Malwarebytes Corporation) – C:\Windows\System32\drivers\mbam.sys
[2012/07/04 23:24:29 | 000,000,000 | —D | C] – C:\Malwarebytes' Anti-Malware
[2012/07/04 22:43:57 | 000,000,000 | —D | C] – C:\Program Files\ESET
[2012/07/04 17:12:40 | 000,000,000 | —D | C] – C:\Users\glori970\AppData\Local\ElevatedDiagnostics
[2012/07/04 15:03:25 | 000,000,000 | –SD | C] – C:\ComboFix
[2012/07/04 15:01:52 | 000,000,000 | -HSD | C] – C:\$RECYCLE.BIN
[2012/07/03 21:30:32 | 000,518,144 | —- | C] (SteelWerX) – C:\Windows\SWREG.exe
[2012/07/03 21:30:32 | 000,406,528 | —- | C] (SteelWerX) – C:\Windows\SWSC.exe
[2012/07/03 21:30:32 | 000,060,416 | —- | C] (NirSoft) – C:\Windows\NIRCMD.exe
[2012/07/03 21:30:28 | 000,000,000 | —D | C] – C:\Qoobox
[2012/07/03 21:30:19 | 000,000,000 | —D | C] – C:\Windows\erdnt
[2012/07/03 13:16:23 | 000,388,608 | —- | C] (Trend Micro Inc.) – C:\Users\glori970\Desktop\HijackThis.exe
[2012/07/03 11:06:21 | 002,002,944 | —- | C] (Trend Micro Inc.) – C:\Users\glori970\Desktop\HousecallLauncher.exe
[2012/07/02 20:01:46 | 002,135,640 | —- | C] (Kaspersky Lab ZAO) – C:\Users\glori970\Desktop\TDSSKiller.exe
[2012/07/02 11:52:01 | 000,000,000 | —D | C] – C:\Users\glori970\AppData\Local\NPE
[2012/06/25 12:32:12 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Symantec Shared
[2012/06/25 12:27:52 | 000,000,000 | —D | C] – C:\ProgramData\Symantec
[2012/06/25 12:27:47 | 000,000,000 | —D | C] – C:\ProgramData\Norton
[2012/06/25 12:27:45 | 000,000,000 | —D | C] – C:\ProgramData\NortonInstaller
[2012/06/23 21:28:43 | 000,000,000 | —D | C] – C:\Users\glori970\Desktop\log
[2012/06/23 21:28:42 | 000,000,000 | —D | C] – C:\Users\glori970\Desktop\TMRBLog
[2012/06/20 21:59:54 | 008,656,400 | —- | C] (Trend Micro Inc.) – C:\Users\glori970\Desktop\RootkitBuster_v5_1061.exe
[2012/06/18 11:16:39 | 000,000,000 | —D | C] – C:\ProgramData\RegRun
[2012/06/18 11:16:35 | 000,000,000 | —D | C] – C:\Users\Public\Documents\RegRunInfo
[2012/06/18 11:15:15 | 000,000,000 | —D | C] – C:\Users\glori970\Documents\RegRun2
[2012/06/18 11:15:13 | 000,000,000 | —D | C] – C:\Program Files\Greatis
[2012/06/09 18:28:38 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Second Life Viewer
[2012/06/09 18:28:13 | 000,000,000 | —D | C] – C:\Program Files\SecondLifeViewer

========== Files - Modified Within 30 Days ==========

[2012/07/05 12:04:05 | 000,013,648 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2012/07/05 12:04:05 | 000,013,648 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2012/07/05 11:56:42 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2012/07/05 11:56:36 | 2415,357,952 | -HS- | M] () – C:\hiberfil.sys
[2012/07/04 23:24:30 | 000,000,708 | —- | M] () – C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2012/07/04 14:55:20 | 000,013,360 | —- | M] () – C:\Users\glori970\Desktop\ComboFix.exe - Shortcut.lnk
[2012/07/03 16:11:32 | 000,000,512 | —- | M] () – C:\Users\glori970\Desktop\MBR.dat
[2012/07/03 13:16:26 | 000,388,608 | —- | M] (Trend Micro Inc.) – C:\Users\glori970\Desktop\HijackThis.exe
[2012/07/03 12:46:53 | 000,621,379 | —- | M] () – C:\Users\glori970\AppData\Local\census.cache
[2012/07/03 12:46:50 | 000,092,984 | —- | M] () – C:\Users\glori970\AppData\Local\ars.cache
[2012/07/03 11:06:22 | 002,002,944 | —- | M] (Trend Micro Inc.) – C:\Users\glori970\Desktop\HousecallLauncher.exe
[2012/07/02 20:01:46 | 002,135,640 | —- | M] (Kaspersky Lab ZAO) – C:\Users\glori970\Desktop\TDSSKiller.exe
[2012/06/20 22:42:38 | 000,000,000 | —- | M] () – C:\Windows\System32\signons.sqlite
[2012/06/20 21:59:55 | 008,656,400 | —- | M] (Trend Micro Inc.) – C:\Users\glori970\Desktop\RootkitBuster_v5_1061.exe
[2012/06/18 11:15:16 | 000,002,577 | —- | M] () – C:\Windows\System32\config.nt
[2012/06/18 11:15:16 | 000,001,688 | —- | M] () – C:\Windows\System32\autoexec.nt
[2012/06/18 11:15:16 | 000,000,002 | RHS- | M] () – C:\Windows\winstart.bat
[2012/06/14 03:22:27 | 000,319,000 | —- | M] () – C:\Windows\System32\FNTCACHE.DAT
[2012/06/14 03:04:31 | 000,632,708 | —- | M] () – C:\Windows\System32\perfh009.dat
[2012/06/14 03:04:31 | 000,110,342 | —- | M] () – C:\Windows\System32\perfc009.dat
[2012/06/09 18:28:40 | 000,001,087 | —- | M] () – C:\Users\Public\Desktop\Second Life Viewer.lnk

========== Files Created - No Company Name ==========

[2012/07/04 23:24:30 | 000,000,708 | —- | C] () – C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2012/07/04 14:55:20 | 000,013,360 | —- | C] () – C:\Users\glori970\Desktop\ComboFix.exe - Shortcut.lnk
[2012/07/03 21:30:32 | 000,256,000 | —- | C] () – C:\Windows\PEV.exe
[2012/07/03 21:30:32 | 000,208,896 | —- | C] () – C:\Windows\MBR.exe
[2012/07/03 21:30:32 | 000,098,816 | —- | C] () – C:\Windows\sed.exe
[2012/07/03 21:30:32 | 000,080,412 | —- | C] () – C:\Windows\grep.exe
[2012/07/03 21:30:32 | 000,068,096 | —- | C] () – C:\Windows\zip.exe
[2012/07/03 16:11:32 | 000,000,512 | —- | C] () – C:\Users\glori970\Desktop\MBR.dat
[2012/06/20 22:42:38 | 000,000,000 | —- | C] () – C:\Windows\System32\signons.sqlite
[2012/06/18 11:15:16 | 000,000,002 | RHS- | C] () – C:\Windows\winstart.bat
[2012/06/09 18:28:40 | 000,001,087 | —- | C] () – C:\Users\Public\Desktop\Second Life Viewer.lnk
[2012/04/28 18:17:21 | 000,007,606 | —- | C] () – C:\Users\glori970\AppData\Local\Resmon.ResmonCfg
[2011/12/20 15:51:17 | 000,000,906 | —- | C] () – C:\Users\glori970\AppData\Roaming\wklnhst.dat
[2011/12/20 15:49:25 | 000,000,376 | —- | C] () – C:\Windows\ODBC.INI
[2011/10/12 12:40:09 | 000,000,269 | —- | C] () – C:\Windows\SysMech.INI
[2011/09/16 11:28:43 | 000,621,379 | —- | C] () – C:\Users\glori970\AppData\Local\census.cache
[2011/09/16 11:28:39 | 000,092,984 | —- | C] () – C:\Users\glori970\AppData\Local\ars.cache
[2011/09/10 12:32:27 | 000,000,036 | —- | C] () – C:\Users\glori970\AppData\Local\housecall.guid.cache
[2011/08/30 23:41:59 | 000,074,703 | —- | C] () – C:\Windows\System32\mfc45.dll
[2011/08/20 15:28:37 | 000,066,048 | —- | C] () – C:\Windows\System32\PrintBrmUi.exe
[2011/08/03 06:31:54 | 000,311,912 | —- | C] () – C:\Windows\System32\nvStreaming.exe

========== LOP Check ==========

[2012/07/03 12:49:02 | 000,000,000 | —D | M] – C:\Users\glori970\AppData\Roaming\iolo
[2011/08/19 01:53:21 | 000,000,000 | —D | M] – C:\Users\glori970\AppData\Roaming\Leadertech
[2011/08/19 02:09:46 | 000,000,000 | —D | M] – C:\Users\glori970\AppData\Roaming\Memeo
[2011/08/19 01:55:26 | 000,000,000 | —D | M] – C:\Users\glori970\AppData\Roaming\Seagate
[2011/09/25 08:15:09 | 000,000,000 | —D | M] – C:\Users\glori970\AppData\Roaming\SecondLife
[2012/03/27 13:25:34 | 000,000,000 | —D | M] – C:\Users\glori970\AppData\Roaming\Template
[2011/08/22 13:00:00 | 000,000,000 | —D | M] – C:\Users\glori970\AppData\Roaming\Windows SideBar
[2011/10/10 23:28:41 | 000,000,000 | —D | M] – C:\Users\Guest\AppData\Roaming\iolo
[2011/10/10 23:28:42 | 000,000,000 | —D | M] – C:\Users\Guest\AppData\Roaming\Memeo
[2011/10/10 23:28:42 | 000,000,000 | —D | M] – C:\Users\Guest\AppData\Roaming\Seagate
[2012/06/24 16:29:38 | 000,032,590 | —- | M] () – C:\Windows\Tasks\SCHEDLGU.TXT

========== Purity Check ==========



========== Custom Scans ==========

< MD5 for: EXPLORER.EXE >
[2011/02/26 01:19:21 | 002,616,320 | —- | M] (Microsoft Corporation) MD5=0FB9C74046656D1579A64660AD67B746 – C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.21669_none_54149f9ef14031fc\explorer.exe
[2009/07/13 21:14:20 | 002,613,248 | —- | M] (Microsoft Corporation) MD5=15BC38A7492BEFE831966ADB477CF76F – C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16385_none_518afd35db100430\explorer.exe
[2011/02/26 01:51:13 | 002,614,784 | —- | M] (Microsoft Corporation) MD5=255CF508D7CFB10E0794D6AC93280BD8 – C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20910_none_525b5180f3f95373\explorer.exe
[2009/10/31 01:45:39 | 002,614,272 | —- | M] (Microsoft Corporation) MD5=2626FC9755BE22F805D3CFA0CE3EE727 – C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16450_none_51a66d6ddafc2ed1\explorer.exe
[2011/02/26 01:33:07 | 002,614,784 | —- | M] (Microsoft Corporation) MD5=2AF58D15EDC06EC6FDACCE1F19482BBF – C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16768_none_51a3a583dafd0cef\explorer.exe
[2010/11/20 08:17:09 | 002,616,320 | —- | M] (Microsoft Corporation) MD5=40D777B7A95E00593EB1568C68514493 – C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17514_none_53bc10fdd7fe87ca\explorer.exe
[2011/02/25 01:30:54 | 002,616,320 | —- | M] (Microsoft Corporation) MD5=8B88EBBB05A0E56B7DCC708498C02B3E – C:\Windows\erdnt\cache\explorer.exe
[2011/02/25 01:30:54 | 002,616,320 | —- | M] (Microsoft Corporation) MD5=8B88EBBB05A0E56B7DCC708498C02B3E – C:\Windows\explorer.exe
[2011/02/25 01:30:54 | 002,616,320 | —- | M] (Microsoft Corporation) MD5=8B88EBBB05A0E56B7DCC708498C02B3E – C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17567_none_5389023fd8245f84\explorer.exe
[2009/08/03 01:49:47 | 002,613,248 | —- | M] (Microsoft Corporation) MD5=9FF6C4C91A3711C0A3B18F87B08B518D – C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20500_none_526619d4f3f142e6\explorer.exe
[2009/08/03 01:35:50 | 002,613,248 | —- | M] (Microsoft Corporation) MD5=B95EEB0F4E5EFBF1038A35B3351CF047 – C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16404_none_51e07e31dad00878\explorer.exe
[2009/10/31 02:00:51 | 002,614,272 | —- | M] (Microsoft Corporation) MD5=C76153C7ECA00FA852BB0C193378F917 – C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20563_none_52283b2af41f3691\explorer.exe

< MD5 for: SVCHOST.EXE >
[2012/04/04 15:56:38 | 000,199,240 | —- | M] () MD5=097D0E812D7A9A3101CE46CB2BE0474D – C:\Malwarebytes' Anti-Malware\Chameleon\svchost.exe
[2009/07/13 21:14:41 | 000,020,992 | —- | M] (Microsoft Corporation) MD5=54A47F6B5E09A77E61649109C6A08866 – C:\Windows\erdnt\cache\svchost.exe
[2009/07/13 21:14:41 | 000,020,992 | —- | M] (Microsoft Corporation) MD5=54A47F6B5E09A77E61649109C6A08866 – C:\Windows\System32\svchost.exe
[2009/07/13 21:14:41 | 000,020,992 | —- | M] (Microsoft Corporation) MD5=54A47F6B5E09A77E61649109C6A08866 – C:\Windows\winsxs\x86_microsoft-windows-services-svchost_31bf3856ad364e35_6.1.7600.16385_none_b591afc466a15356\svchost.exe

< MD5 for: USERINIT.EXE >
[2010/11/20 08:17:48 | 000,026,624 | —- | M] (Microsoft Corporation) MD5=61AC3EFDFACFDD3F0F11DD4FD4044223 – C:\Windows\erdnt\cache\userinit.exe
[2010/11/20 08:17:48 | 000,026,624 | —- | M] (Microsoft Corporation) MD5=61AC3EFDFACFDD3F0F11DD4FD4044223 – C:\Windows\System32\userinit.exe
[2010/11/20 08:17:48 | 000,026,624 | —- | M] (Microsoft Corporation) MD5=61AC3EFDFACFDD3F0F11DD4FD4044223 – C:\Windows\winsxs\x86_microsoft-windows-userinit_31bf3856ad364e35_6.1.7601.17514_none_de3024012ff21116\userinit.exe
[2009/07/13 21:14:43 | 000,026,112 | —- | M] (Microsoft Corporation) MD5=6DE80F60D7DE9CE6B8C2DDFDF79EF175 – C:\Windows\winsxs\x86_microsoft-windows-userinit_31bf3856ad364e35_6.1.7600.16385_none_dbff103933038d7c\userinit.exe

< MD5 for: WINLOGON.EXE >
[2012/04/04 15:56:38 | 000,199,240 | —- | M] () MD5=097D0E812D7A9A3101CE46CB2BE0474D – C:\Malwarebytes' Anti-Malware\Chameleon\winlogon.exe
[2009/10/28 02:17:59 | 000,285,696 | —- | M] (Microsoft Corporation) MD5=37CDB7E72EB66BA85A87CBE37E7F03FD – C:\Windows\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.16447_none_6fc699643622d177\winlogon.exe
[2009/10/28 01:52:08 | 000,285,696 | —- | M] (Microsoft Corporation) MD5=3BABE6767C78FBF5FB8435FEED187F30 – C:\Windows\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.20560_none_703394514f56f7c2\winlogon.exe
[2010/11/20 08:17:54 | 000,286,720 | —- | M] (Microsoft Corporation) MD5=6D13E1406F50C66E2A95D97F22C47560 – C:\Windows\erdnt\cache\winlogon.exe
[2010/11/20 08:17:54 | 000,286,720 | —- | M] (Microsoft Corporation) MD5=6D13E1406F50C66E2A95D97F22C47560 – C:\Windows\System32\winlogon.exe
[2010/11/20 08:17:54 | 000,286,720 | —- | M] (Microsoft Corporation) MD5=6D13E1406F50C66E2A95D97F22C47560 – C:\Windows\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7601.17514_none_71ca6b0233339500\winlogon.exe
[2009/07/13 21:14:45 | 000,285,696 | —- | M] (Microsoft Corporation) MD5=8EC6A4AB12B8F3759E21F8E3A388F2CF – C:\Windows\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.16385_none_6f99573a36451166\winlogon.exe

< End of report >
ps: I cant find tdskiller logs. tho i did note the scans came back clean, so perhaps there was no log? I have to leave to run an errand ( id postone it if I could, but really can't, sorry) will be back asap. Thanks again Jeff. ;D ~gloria

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI