This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

can't run programs [Solved]

17 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi, Thanks in advance for your assistance. All the icons on my desktop and quicklaunch went generic and when I click on them, I get a message that it can find something and should it search online. Even when I go in Windows Explorer and try to find executable files, it does something similar. If I try to open a text file by double clicking on it, no matter what file type, it is opened by Wordpad. Image files are opened by Windows though. I'm on an old XP machine, 2002, Service Pack 2. I'm running OTL right now. Thanks, Don

**In any case where you happen to be busy or unable to give us a reply, we would be grateful if you keep us informed in advance and we will be more than happy to wait. Failure to do so we will have your thread closed in THREE(3) days. :)


Hello there, Don

:welcome:

I'm Conspire, I'll be glad to help you with your computer problems.

Please observe these rules while we work:
  • Read the entire procedure
  • It is important to perform ALL actions in sequence.
  • If you don't know, stop and ask! Don't keep going on.
  • Please reply to this thread. Do not start a new topic.
  • Stick with me till you're given the all clear.
  • Remember, absence of symptoms does not mean the infection is all gone.
  • Don't attempt to clean your computer with any tools other than the ones I ask you to use during the cleanup process.

IMPORTANT NOTE : Please do not delete anything unless instructed to. Remember to backup all your important data(if possible) before moving on.

—————————————————————————————————

Seems like your machine is awfully outdated with SP 2.

I will wait for your OTL log.

—————————————————————————————————
Conspire, I appreciate your assistance. I'll past in OTL outputs below. Some more background: files or websites associated with 'funmoods' keep showing up, making me wonder if that is a malware name or source. Its not something I'm familiar with or would have downloaded deliberately. Also, before contacting Whatthetech, I un-installed a variety of applications that I don't use or didn't recognize, to see if that made a difference, and I downloaded and ran first antimalwarebytes and then stopzilla, and none of this seemed to help, and having read your instructions above, I hope it doesn't inhibit diagosis.

I realize that this computer is very out of date. A local computer store removed some more recent service packs because they were slowing down the machine so much. I'm planning on replacing the computer soon, but would like to get it up and running to facilitate file management - the hard drive has a lot of data I don't want to lose.

How often should I check back in for your response?

OK, here's OTL:


OTL logfile created on: 7/29/2012 11:45:53 AM - Run 1
OTL by OldTimer - Version 3.2.55.0 Folder = C:\Documents and Settings\Don\My Documents\Downloads
Windows XP Home Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.11)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

767.48 Mb Total Physical Memory | 189.29 Mb Available Physical Memory | 24.66% Memory free
1.46 Gb Paging File | 0.70 Gb Available in Paging File | 48.39% Paging File free
Paging file location(s): C:\pagefile.sys 768 1536 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 37.27 Gb Total Space | 5.21 Gb Free Space | 13.98% Space Free | Partition Type: NTFS
Drive H: | 149.01 Gb Total Space | 63.66 Gb Free Space | 42.72% Space Free | Partition Type: FAT32

Computer Name: UPSTAIRSDESKTOP | User Name: Don | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Documents and Settings\Don\My Documents\Downloads\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Google\Chrome\Application\chrome.exe (Google Inc.)
PRC - C:\WINDOWS\system32\afasrv32.exe ()
PRC - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe ()
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\epson\Creativity Suite\Event Manager\EEventManager.exe (SEIKO EPSON CORPORATION)


========== Modules (No Company Name) ==========

MOD - C:\Program Files\Google\Chrome\Application\20.0.1132.57\ppgooglenaclpluginchrome.dll ()
MOD - C:\Program Files\Google\Chrome\Application\20.0.1132.57\pdf.dll ()
MOD - C:\Program Files\Google\Chrome\Application\20.0.1132.57\libglesv2.dll ()
MOD - C:\Program Files\Google\Chrome\Application\20.0.1132.57\libegl.dll ()
MOD - C:\Program Files\Google\Chrome\Application\20.0.1132.57\avutil-51.dll ()
MOD - C:\Program Files\Google\Chrome\Application\20.0.1132.57\avformat-54.dll ()
MOD - C:\Program Files\Google\Chrome\Application\20.0.1132.57\avcodec-54.dll ()
MOD - C:\Program Files\Google\Chrome\Application\20.0.1132.57\gcswf32.dll ()
MOD - C:\WINDOWS\system32\afasrv32.exe ()
MOD - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe ()
MOD - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcnet.dll ()
MOD - C:\WINDOWS\system32\hpotscl.dll ()


========== Win32 Services (SafeList) ==========

SRV - (HidServ) – %SystemRoot%\System32\hidserv.dll File not found
SRV - (CLTNetCnService) – C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe /h ccCommon File not found
SRV - (AppMgmt) – %SystemRoot%\System32\appmgmts.dll File not found
SRV - (AdobeFlashPlayerUpdateSvc) – C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe (Adobe Systems Incorporated)
SRV - (AfaService) – C:\WINDOWS\system32\afasrv32.exe ()
SRV - (Symantec Core LC) – C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe ()
SRV - (Pml Driver HPZ12) – C:\WINDOWS\system32\HPZipm12.exe (HP)


========== Driver Services (SafeList) ==========

DRV - (Winsock - Google Desktop Search Backup Before Last Install) – File not found
DRV - (Winsock - Google Desktop Search Backup Before First Install) – File not found
DRV - (WDICA) – File not found
DRV - (PDRFRAME) – File not found
DRV - (PDRELI) – File not found
DRV - (PDFRAME) – File not found
DRV - (PDCOMP) – File not found
DRV - (PCIDump) – File not found
DRV - (MHIKEY10) – System32\Drivers\MHIKEY10.sys File not found
DRV - (lbrtfdc) – File not found
DRV - (i2omgmt) – File not found
DRV - (GEARAspiWDM) – System32\Drivers\GEARAspiWDM.sys File not found
DRV - (Changer) – File not found
DRV - (SBRE) – C:\WINDOWS\system32\drivers\SBREDrv.sys (GFI Software)
DRV - (sscdmdm) – C:\WINDOWS\system32\drivers\sscdmdm.sys (MCCI Corporation)
DRV - (ssadmdm) – C:\WINDOWS\system32\drivers\ssadmdm.sys (MCCI Corporation)
DRV - (sscdbus) – C:\WINDOWS\system32\drivers\sscdbus.sys (MCCI Corporation)
DRV - (ssadbus) – C:\WINDOWS\system32\drivers\ssadbus.sys (MCCI Corporation)
DRV - (androidusb) – C:\WINDOWS\system32\drivers\ssadadb.sys (Google Inc)
DRV - (sscdmdfl) – C:\WINDOWS\system32\drivers\sscdmdfl.sys (MCCI Corporation)
DRV - (ssadmdfl) – C:\WINDOWS\system32\drivers\ssadmdfl.sys (MCCI Corporation)
DRV - (ssmdrv) – C:\WINDOWS\system32\drivers\ssmdrv.sys (Avira GmbH)
DRV - (eeCtrl) – C:\Program Files\Common Files\Symantec Shared\eengine\eectrl.sys (Symantec Corporation)
DRV - (2WIREPCP) – C:\WINDOWS\system32\drivers\2WirePCP.sys (2Wire, Inc.)
DRV - (symlcbrd) – C:\WINDOWS\system32\drivers\symlcbrd.sys (Symantec Corporation)
DRV - (MDC8021X) – C:\WINDOWS\system32\drivers\mdc8021x.sys (Meetinghouse Data Communications)
DRV - (nvnforce) – C:\WINDOWS\system32\drivers\nvapu.sys (NVIDIA Corporation)
DRV - (nvax) – C:\WINDOWS\system32\drivers\nvax.sys (NVIDIA Corporation)
DRV - (AFS2K) – C:\WINDOWS\System32\drivers\AFS2K.SYS (Oak Technology Inc.)
DRV - (rtl8139) – C:\WINDOWS\system32\drivers\rtl8139.sys (Realtek Semiconductor Corporation)
DRV - (PalmUSBD) – C:\WINDOWS\system32\drivers\PalmUSBD.sys (Palm, Inc.)
DRV - (ANVIOCTL) – C:\WINDOWS\system32\drivers\anvioctl.sys (ASUSTeK)
DRV - (asuskbnt) – C:\WINDOWS\system32\drivers\asuskbnt.sys (ASUSTeK COMPUTER INC.)
DRV - (nv_agp) – C:\WINDOWS\system32\drivers\nv_agp.SYS (NVIDIA Corporation)
DRV - (NVENET) – C:\WINDOWS\system32\drivers\NVENET.sys (NVIDIA Corporation)
DRV - (IPFilter) – C:\WINDOWS\system32\drivers\ipfilter.sys (Microsoft Corporation)
DRV - (pfc) – C:\WINDOWS\system32\drivers\PFC.SYS (Padus, Inc.)
DRV - (V124) – C:\WINDOWS\system32\drivers\HSF_V124.sys (Conexant)
DRV - (Tones) – C:\WINDOWS\system32\drivers\HSF_TONE.sys (Conexant)
DRV - (hsf_msft) – C:\WINDOWS\system32\drivers\HSF_MSFT.sys (Conexant)
DRV - (Rksample) – C:\WINDOWS\system32\drivers\HSF_SAMP.sys (Conexant)
DRV - (K56) – C:\WINDOWS\system32\drivers\HSF_K56K.sys (Conexant)
DRV - (Fallback) – C:\WINDOWS\system32\drivers\HSF_FALL.sys (Conexant)
DRV - (SoftFax) – C:\WINDOWS\system32\drivers\HSF_FAXX.sys (Conexant)
DRV - (Fsks) – C:\WINDOWS\system32\drivers\HSF_FSKS.sys (Conexant)
DRV - (basic2) – C:\WINDOWS\system32\drivers\HSF_BSC2.sys (Conexant)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://start.funmoods.com/?f=1&a;=axl&a;…p;cr=2110581096
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie
IE - HKLM\..\SearchScopes,Backup.Old.DefaultScope = {6A1806CD-94D4-4689-BA73-E35EA1EA9990}
IE - HKLM\..\SearchScopes,DefaultScope = {B7971660-A1CE-4FDD-B9E0-2C37D77AFB0B}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://search.live.com/results.aspx?q={sea…ferrer:source?}
IE - HKLM\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.com/search?q={searchTerm…mp;sourceid=ie7
IE - HKLM\..\SearchScopes\{B7971660-A1CE-4FDD-B9E0-2C37D77AFB0B}: "URL" = http://start.funmoods.com/results.php?f=4&…p;cr=2110581096

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Backup.Old.Start Page = http://us.yhs4.search.yahoo.com/web/partne…729,16897,0,5,0
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultName = Google
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultURL = http://www.google.com/search?q={searchTerm…tf8&oe;=utf8
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://start.funmoods.com/?f=1&a;=axl&a;…p;cr=2110581096
IE - HKCU\..\URLSearchHook: - No CLSID value found
IE - HKCU\..\URLSearchHook: {81017EA9-9AA8-4A6A-9734-7AF40E7D593F} - No CLSID value found
IE - HKCU\..\SearchScopes,Backup.Old.DefaultScope = {EA68C3CB-B327-453B-B890-39BF9951F14C}
IE - HKCU\..\SearchScopes,DefaultScope = {EA68C3CB-B327-453B-B890-39BF9951F14C}
IE - HKCU\..\SearchScopes\{105E99FF-8B9A-4492-B155-06194B9056D2}: "URL" = http://search.live.com/results.aspx?FORM=S…ferrer:source?}
IE - HKCU\..\SearchScopes\{19F2B849-4ADE-4d4b-85F9-C31C643DBDE9}: "URL" = http://fastbrowsersearch.com/results/resul…p;s=DSP&v;=9
IE - HKCU\..\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}: "URL" = http://search.conduit.com/ResultsExt.aspx?…;ctid=CT2801948
IE - HKCU\..\SearchScopes\{B7971660-A1CE-4FDD-B9E0-2C37D77AFB0B}: "URL" = http://start.funmoods.com/results.php?f=4&…p;cr=2110581096
IE - HKCU\..\SearchScopes\{E1213956-41C3-4FD3-8D7C-20740A2EE7B3}: "URL" = http://search.yahoo.com/search?p={searchte…0729,6900,0,5,0
IE - HKCU\..\SearchScopes\{EA68C3CB-B327-453B-B890-39BF9951F14C}: "URL" = http://www.google.com/search?q={searchTerm…;rlz=1I7GPEA_en
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = 127.0.0.1


========== FireFox ==========

FF - HKLM\Software\MozillaPlugins\@garmin.com/GpsControl: C:\Program Files\Garmin GPS Plugin\npGarmin.dll (GARMIN Corp.)
FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files\Microsoft Silverlight\4.1.10111.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.115\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.115\npGoogleUpdate3.dll (Google Inc.)



========== Chrome ==========

CHR - homepage: http://start.funmoods.com/?f=1&a;=axl&a;…p;cr=2110581096
CHR - default_search_provider: Web Search (Enabled)
CHR - default_search_provider: search_url = http://start.funmoods.com/results.php?f=4&…p;cr=2110581096
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?client=chrome&hl;={language}&q;={searchTerms}
CHR - homepage: http://start.funmoods.com/?f=1&a;=axl&a;…p;cr=2110581096
CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Program Files\Google\Chrome\Application\20.0.1132.57\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Program Files\Google\Chrome\Application\20.0.1132.57\pdf.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Program Files\Google\Chrome\Application\20.0.1132.57\gcswf32.dll
CHR - plugin: Adobe Acrobat (Enabled) = C:\Program Files\Adobe\Reader 8.0\Reader\Browser\nppdf32.dll
CHR - plugin: Java Deployment Toolkit 6.0.200.2 (Enabled) = C:\Program Files\Java\jre6\bin\new_plugin\npdeployJava1.dll
CHR - plugin: Java™ Platform SE 6 U20 (Enabled) = C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin2.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin3.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin4.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin5.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin6.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin7.dll
CHR - plugin: Microsoft\u00AE DRM (Enabled) = C:\Program Files\Windows Media Player\npdrmv2.dll
CHR - plugin: Microsoft\u00AE DRM (Enabled) = C:\Program Files\Windows Media Player\npwmsdrm.dll
CHR - plugin: Windows Media Player Plug-in Dynamic Link Library (Enabled) = C:\Program Files\Windows Media Player\npdsplay.dll
CHR - plugin: Garmin Communicator Plug-In (Enabled) = C:\Program Files\Garmin GPS Plugin\npGarmin.dll
CHR - plugin: Google Earth Plugin (Enabled) = C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll
CHR - plugin: Google Updater (Enabled) = C:\Program Files\Google\Google Updater\2.4.2432.1652\npCIDetect14.dll
CHR - plugin: Google Update (Enabled) = C:\Program Files\Google\Update\1.3.21.79\npGoogleUpdate3.dll
CHR - plugin: Silverlight Plug-In (Enabled) = C:\Program Files\Microsoft Silverlight\4.0.60831.0\npctrl.dll
CHR - plugin: iTunes Application Detector (Enabled) = C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll
CHR - plugin: Windows Presentation Foundation (Enabled) = C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll
CHR - plugin: Default Plug-in (Enabled) = default_plugin
CHR - Extension: SpeedDial = C:\Documents and Settings\Don\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\cjpglkicenollcignonpgiafdgfeehoj\4.0_0\
CHR - Extension: Make this page red = C:\Documents and Settings\Don\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\dnfaglepmjgohnkcoieaijlheabmcdeo\1.2_0\

O1 HOSTS File: ([2009/12/29 21:07:28 | 000,000,027 | —- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - No CLSID value found.
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (Qwiklinx) - {3E7C8B5A-96AB-438F-BF9B-782400655440} - C:\Documents and Settings\Don\Application Data\Qwiklinx\Qwiklinx.dll (Qwiklinx, Inc.)
O2 - BHO: (NetAssistantBHO Class) - {E38FA08E-F56A-4169-ABF5-5C71E3C153A1} - C:\Program Files\Freeze.com\NetAssistant\NetAssistant.dll (W3i, LLC)
O3 - HKLM\..\Toolbar: (no name) - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - No CLSID value found.
O3 - HKLM\..\Toolbar: (no name) - {DB9FBA9D-AB1B-4CC6-9745-F3B549D64E40} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {C4069E3A-68F1-403E-B40E-20066696354B} - No CLSID value found.
O4 - HKLM..\Run: [EEventManager] C:\Program Files\epson\Creativity Suite\Event Manager\EEventManager.exe (SEIKO EPSON CORPORATION)
O4 - HKLM..\Run: [NvCplDaemon] C:\WINDOWS\System32\NvCpl.dll (NVIDIA Corporation)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe (Adobe Systems, Inc.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\hp psc 2000 Series.lnk = C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpobnz08.exe (Hewlett-Packard Co.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\hpoddt01.exe.lnk = C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe (Hewlett-Packard)
O4 - Startup: C:\Documents and Settings\Don\Start Menu\Programs\Startup\HotSync Manager.LNK = C:\Program Files\Palm\HOTSYNC.EXE (Palm, Inc.)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\control panel present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\restrictions present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O9 - Extra Button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - Reg Error: Key error. File not found
O16 - DPF: {01010E00-5E80-11D8-9E86-0007E96C65AE} http://symantec.atgnow.com/sdccommon/download/tgctlsi.cab (SupportSoft SmartIssue)
O16 - DPF: {01118F00-3E00-11D2-8470-0060089874ED} http://symantec.atgnow.com/sdccommon/download/ssrc.cab (SupportSoft RemoteControl Class)
O16 - DPF: {01119400-3E00-11D2-8470-0060089874ED} http://symantec.atgnow.com/sdccommon/download/sprtctlln.cab (SupportSoft Listener Control)
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} http://appldnld.apple.com.edgesuite.net/co…ex/qtplugin.cab (QuickTime Object)
O16 - DPF: {05CA9FB0-3E3E-4B36-BF41-0E3A5CAA8CD8} http://download.microsoft.com/download/e/7…/OGAControl.cab (Office Genuine Advantage Validation Tool)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://go.microsoft.com/fwlink/?linkid=39204 (Windows Genuine Advantage Validation Tool)
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} http://gfx2.hotmail.com/mail/w2/pr02/resources/MSNPUpld.cab (MSN Photo Upload Tool)
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} http://security.symantec.com/sscv6/SharedC…n/bin/cabsa.cab (Symantec RuFSI Utility Class)
O16 - DPF: {6A344D34-5231-452A-8A57-D064AC9B7862} https://webdl.symantec.com/activex/symdlmgr.cab (Symantec Download Manager)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} http://update.microsoft.com/microsoftupdat…b?1132454647671 (MUWebControl Class)
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} http://download.eset.com/special/eos/OnlineScanner.cab (Reg Error: Key error.)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get/flash…r/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} http://v4.windowsupdate.microsoft.com/CAB/…8015.5386805556 (Reg Error: Key error.)
O16 - DPF: {B020B534-4AA2-4B99-BD6D-5F6EE286DF5C} http://a248.e.akamai.net/f/248/5462/2h/www…ol/SymDlBrg.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O16 - DPF: {FFFFFFFF-CACE-BABE-BABE-00AA0055595A} http://www.trueswitch.com/msn/TrueInstallMSN.exe (Reg Error: Key error.)
O16 - DPF: DirectAnimation Java Classes file://C:\WINDOWS\Java\classes\dajava.cab (Reg Error: Key error.)
O16 - DPF: Garmin Communicator Plug-In https://static.garmincdn.com/gcp/ie/3.0.1.0…inAxControl.CAB (Reg Error: Key error.)
O16 - DPF: Microsoft XML Parser for Java file://C:\WINDOWS\Java\classes\xmldso.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{3AC852D7-B3F4-4C96-8016-39CC10635D74}: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{810006C9-F0F5-4282-BCE8-E5926F44E330}: DhcpNameServer = [removed] [removed]
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) - C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O20 - Winlogon\Notify\dimsntfy: DllName - (Reg Error: Value error.) - Reg Error: Value error. File not found
O20 - Winlogon\Notify\TPSvc: DllName - (TPSvc.dll) - File not found
O24 - Desktop WallPaper:
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Don\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2004/01/29 12:51:55 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O32 - AutoRun File - [2011/02/08 19:05:54 | 000,000,000 | —D | M] - H:\autorun – [ FAT32 ]
O32 - AutoRun File - [2005/11/15 11:08:04 | 000,000,036 | -H– | M] () - H:\autorun.inf – [ FAT32 ]
O33 - MountPoints2\{11b84416-fe88-11d5-bccc-000c768e4a97}\Shell\AutoRun\command - "" = G:\RECYCLER\recycld.exe e
O33 - MountPoints2\{11b84416-fe88-11d5-bccc-000c768e4a97}\Shell\open\command - "" = G:\RECYCLER\recycld.exe
O33 - MountPoints2\{1b7348ff-9b6c-11db-b739-000c768e4a97}\Shell - "" = AutoRun
O33 - MountPoints2\{1b7348ff-9b6c-11db-b739-000c768e4a97}\Shell\AutoRun - "" = Auto&Play;
O33 - MountPoints2\{1b7348ff-9b6c-11db-b739-000c768e4a97}\Shell\AutoRun\command - "" = G:\LaunchU3.exe -a
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = Reg Error: Key error.] – Reg Error: Key error. File not found
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKCU\…exe [@ = exefile] – Reg Error: Key error. File not found
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)

NetSvcs: 6to4 - File not found
NetSvcs: AppMgmt - %SystemRoot%\System32\appmgmts.dll File not found
NetSvcs: HidServ - %SystemRoot%\System32\hidserv.dll File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found
NetSvcs: Ip6FwHlp - File not found

Drivers32: msacm.iac2 - C:\WINDOWS\System32\iac25_32.ax (Intel Corporation)
Drivers32: msacm.l3acm - C:\WINDOWS\system32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.sl_anet - C:\WINDOWS\System32\sl_anet.acm (Sipro Lab Telecom Inc.)
Drivers32: msacm.trspch - C:\WINDOWS\System32\tssoft32.acm (DSP GROUP, INC.)
Drivers32: vidc.cvid - C:\WINDOWS\System32\iccvid.dll (Radius Inc.)
Drivers32: vidc.iv31 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv32 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv41 - C:\WINDOWS\System32\ir41_32.ax (Intel Corporation)
Drivers32: vidc.iv50 - C:\WINDOWS\System32\ir50_32.dll (Intel Corporation)
Drivers32: vidc.tscc - C:\WINDOWS\System32\tsccvid.dll (TechSmith Corporation)
Drivers32: wave1 - C:\WINDOWS\System32\serwvdrv.dll (Microsoft Corporation)

CREATERESTOREPOINT
Restore point Set: OTL Restore Point

========== Files/Folders - Created Within 30 Days ==========

[2012/07/29 08:58:53 | 000,000,000 | —D | C] – C:\WINDOWS\LastGood
[2012/07/28 18:16:14 | 000,101,112 | R— | C] (GFI Software) – C:\WINDOWS\System32\drivers\SBREDrv.sys
[2012/07/28 18:16:14 | 000,042,864 | R— | C] (GFI Software) – C:\WINDOWS\System32\SBBD.EXE
[2012/07/28 18:16:05 | 000,000,000 | —D | C] – C:\Program Files\STOPzilla!
[2012/07/21 19:40:23 | 000,000,000 | —D | C] – C:\zamzar
[2012/07/21 19:17:50 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Tarma Installer
[2012/07/21 19:16:36 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\PC Optimizer Pro
[2012/07/21 19:08:35 | 000,000,000 | —D | C] – C:\Documents and Settings\Don\Local Settings\Application Data\visi_coupon
[2012/07/21 19:07:35 | 000,000,000 | —D | C] – C:\Documents and Settings\Don\AbiSuite
[2012/07/21 19:07:32 | 000,000,000 | —D | C] – C:\Documents and Settings\Don\My Documents\ShopToWin
[2012/07/21 19:06:43 | 000,000,000 | —D | C] – C:\Program Files\Free Offers from Freeze.com
[2012/07/21 19:06:40 | 000,000,000 | —D | C] – C:\extensions
[2012/07/21 19:06:38 | 000,000,000 | —D | C] – C:\Program Files\Qwiklinx
[2012/07/21 19:06:38 | 000,000,000 | —D | C] – C:\Documents and Settings\Don\Application Data\Qwiklinx
[2012/07/21 19:06:33 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\PC Optimizer Pro
[2012/07/21 19:06:29 | 000,000,000 | —D | C] – C:\Program Files\PC Optimizer Pro
[2012/07/21 19:05:49 | 000,000,000 | —D | C] – C:\Program Files\Yahoo!
[2 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2012/07/29 11:55:00 | 000,000,422 | -H– | M] () – C:\WINDOWS\tasks\User_Feed_Synchronization-{3164E000-95DA-4E16-A4B2-D13B5FE2D76C}.job
[2012/07/29 11:32:00 | 000,000,830 | —- | M] () – C:\WINDOWS\tasks\Adobe Flash Player Updater.job
[2012/07/29 11:08:00 | 000,000,886 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2012/07/29 08:58:27 | 000,000,912 | —- | M] () – C:\WINDOWS\System32\drivers\kgpcpy.cfg
[2012/07/29 08:58:21 | 000,000,882 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2012/07/29 08:58:19 | 000,012,652 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2012/07/29 08:58:11 | 000,000,406 | —- | M] () – C:\WINDOWS\tasks\PC Optimizer Pro startups.job
[2012/07/29 08:56:33 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2012/07/28 19:55:32 | 000,000,284 | —- | M] () – C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2012/07/27 20:47:25 | 000,000,784 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes Anti-Malware.lnk
[2012/07/27 20:32:38 | 000,426,184 | —- | M] (Adobe Systems Incorporated) – C:\WINDOWS\System32\FlashPlayerApp.exe
[2012/07/27 20:32:38 | 000,070,344 | —- | M] (Adobe Systems Incorporated) – C:\WINDOWS\System32\FlashPlayerCPLApp.cpl
[2012/07/27 20:32:34 | 009,230,024 | —- | M] (Adobe Systems Incorporated) – C:\WINDOWS\System32\FlashPlayerInstaller.exe
[2012/07/26 22:19:55 | 000,000,664 | —- | M] () – C:\WINDOWS\System32\d3d9caps.dat
[2012/07/21 19:18:15 | 000,001,300 | —- | M] () – C:\Documents and Settings\Don\Desktop\Install OpenOffice Writer.lnk
[2012/07/21 19:17:17 | 000,384,844 | —- | M] () – C:\Documents and Settings\Don\Local Settings\Application Data\funmoods-speeddial.crx
[2012/07/21 19:16:38 | 000,000,434 | —- | M] () – C:\WINDOWS\tasks\PC Optimizer Pro Updates.job
[2012/07/21 19:06:43 | 000,001,613 | —- | M] () – C:\Documents and Settings\Don\Desktop\Free Music Downloads.lnk
[2012/07/21 19:06:43 | 000,001,613 | —- | M] () – C:\Documents and Settings\Don\Desktop\Free Dolphin Screensaver.lnk
[2012/07/21 19:06:43 | 000,001,603 | —- | M] () – C:\Documents and Settings\Don\Desktop\Free Games!!.lnk
[2012/07/21 19:06:35 | 000,000,786 | —- | M] () – C:\Documents and Settings\Don\Application Data\Microsoft\Internet Explorer\Quick Launch\PC Optimizer Pro.lnk
[2012/07/21 19:06:35 | 000,000,768 | —- | M] () – C:\Documents and Settings\All Users\Desktop\PC Optimizer Pro.lnk
[2012/07/21 17:48:03 | 000,000,488 | —- | M] () – C:\hpfr5550.xml
[2012/07/12 21:13:08 | 000,001,813 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Google Chrome.lnk
[2012/07/03 13:46:44 | 000,022,344 | —- | M] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys
[2 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]

========== Files Created - No Company Name ==========

[2012/07/29 08:57:19 | 000,000,912 | —- | C] () – C:\WINDOWS\System32\drivers\kgpcpy.cfg
[2012/07/28 19:55:32 | 000,000,284 | —- | C] () – C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2012/07/21 19:18:15 | 000,001,300 | —- | C] () – C:\Documents and Settings\Don\Desktop\Install OpenOffice Writer.lnk
[2012/07/21 19:17:22 | 000,384,844 | —- | C] () – C:\Documents and Settings\Don\Local Settings\Application Data\funmoods-speeddial.crx
[2012/07/21 19:16:37 | 000,000,434 | —- | C] () – C:\WINDOWS\tasks\PC Optimizer Pro Updates.job
[2012/07/21 19:16:36 | 000,000,406 | —- | C] () – C:\WINDOWS\tasks\PC Optimizer Pro startups.job
[2012/07/21 19:06:43 | 000,001,613 | —- | C] () – C:\Documents and Settings\Don\Desktop\Free Music Downloads.lnk
[2012/07/21 19:06:43 | 000,001,613 | —- | C] () – C:\Documents and Settings\Don\Desktop\Free Dolphin Screensaver.lnk
[2012/07/21 19:06:43 | 000,001,603 | —- | C] () – C:\Documents and Settings\Don\Desktop\Free Games!!.lnk
[2012/07/21 19:06:35 | 000,000,786 | —- | C] () – C:\Documents and Settings\Don\Application Data\Microsoft\Internet Explorer\Quick Launch\PC Optimizer Pro.lnk
[2012/07/21 19:06:35 | 000,000,768 | —- | C] () – C:\Documents and Settings\All Users\Desktop\PC Optimizer Pro.lnk
[2011/06/26 22:06:35 | 000,002,528 | —- | C] () – C:\Documents and Settings\Don\Application Data\$_hpcst$.hpc
[2011/06/06 16:18:06 | 000,000,121 | —- | C] () – C:\Documents and Settings\Don\mobac-profile.xml
[2010/12/31 15:48:51 | 000,001,793 | —- | C] () – C:\WINDOWS\System32\fxsperf.ini
[2010/03/14 21:48:11 | 004,727,808 | —- | C] () – C:\Program Files\Works632_en-US.msi
[2008/03/05 21:05:54 | 000,000,032 | —- | C] () – C:\Documents and Settings\All Users\Application Data\ezsid.dat
[2007/12/31 18:15:25 | 000,000,305 | —- | C] () – C:\Documents and Settings\All Users\Application Data\addr_file.html
[2007/09/13 22:34:32 | 000,000,126 | —- | C] () – C:\Documents and Settings\Don\Local Settings\Application Data\fusioncache.dat
[2004/12/14 22:38:32 | 000,000,000 | -H– | C] () – C:\Documents and Settings\Don\hpothb07.tif
[2004/12/14 22:38:32 | 000,000,000 | -H– | C] () – C:\Documents and Settings\Don\hpothb07.dat
[2004/02/25 19:57:32 | 000,097,280 | —- | C] () – C:\Documents and Settings\Don\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2004/02/04 20:34:34 | 000,063,730 | —- | C] () – C:\Program Files\viewsonicinstruct_xp.pdf

========== LOP Check ==========

[2011/09/21 22:20:56 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\GARMIN
[2012/07/22 15:36:04 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\iolo
[2004/02/21 17:23:31 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\MSScanAppDataDir
[2006/08/07 13:14:07 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Napster
[2010/12/27 21:42:46 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\NCH Swift Sound
[2012/07/21 19:16:36 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\PC Optimizer Pro
[2008/07/02 22:02:32 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\PureEdge
[2011/06/26 22:59:57 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Samsung
[2010/05/24 15:22:53 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\SSScanAppDataDir
[2012/07/29 09:02:07 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\STOPzilla!
[2007/03/19 12:48:17 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\SupportSoft
[2012/07/22 15:38:12 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Tarma Installer
[2011/07/22 16:58:11 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
[2005/11/28 20:27:44 | 000,000,000 | —D | M] – C:\Documents and Settings\Don\Application Data\EPSON
[2011/09/22 22:16:39 | 000,000,000 | —D | M] – C:\Documents and Settings\Don\Application Data\Garmin
[2004/02/04 20:36:30 | 000,000,000 | —D | M] – C:\Documents and Settings\Don\Application Data\Leadertech
[2011/05/13 22:28:05 | 000,000,000 | —D | M] – C:\Documents and Settings\Don\Application Data\Mobile Atlas Creator
[2010/12/27 21:41:19 | 000,000,000 | —D | M] – C:\Documents and Settings\Don\Application Data\NCH Swift Sound
[2008/07/02 22:03:38 | 000,000,000 | —D | M] – C:\Documents and Settings\Don\Application Data\PureEdge
[2012/07/21 19:06:39 | 000,000,000 | —D | M] – C:\Documents and Settings\Don\Application Data\Qwiklinx
[2011/03/14 12:52:18 | 000,000,000 | —D | M] – C:\Documents and Settings\Don\Application Data\TeamViewer
[2010/06/12 11:12:16 | 000,000,000 | —D | M] – C:\Documents and Settings\Don\Application Data\TrueSwitch
[2010/12/07 23:15:14 | 000,000,000 | —D | M] – C:\Documents and Settings\Don\Application Data\YouSendIt
[2012/07/29 08:58:11 | 000,000,406 | —- | M] () – C:\WINDOWS\Tasks\PC Optimizer Pro startups.job
[2012/07/21 19:16:38 | 000,000,434 | —- | M] () – C:\WINDOWS\Tasks\PC Optimizer Pro Updates.job
[2011/01/31 20:14:00 | 000,000,274 | —- | M] () – C:\WINDOWS\Tasks\switchShakeIcon.job
[2012/07/29 11:55:00 | 000,000,422 | -H– | M] () – C:\WINDOWS\Tasks\User_Feed_Synchronization-{3164E000-95DA-4E16-A4B2-D13B5FE2D76C}.job
[2010/12/27 21:42:55 | 000,000,278 | —- | M] () – C:\WINDOWS\Tasks\wavepadSevenDays.job
[2010/12/27 21:42:55 | 000,000,278 | —- | M] () – C:\WINDOWS\Tasks\wavepadShakeIcon.job

========== Purity Check ==========



========== Custom Scans ==========

< %SYSTEMDRIVE%\*.* >
[2012/02/16 20:24:00 | 000,000,000 | —- | M] () – C:\2012-01-28 17.12.52.jpg
[2012/02/16 20:24:00 | 000,000,000 | —- | M] () – C:\2012-01-28 17.13.01.jpg
[2004/01/29 12:51:55 | 000,000,000 | —- | M] () – C:\AUTOEXEC.BAT
[2004/11/03 21:49:38 | 000,000,211 | —- | M] () – C:\Boot.bak
[2009/12/29 20:43:35 | 000,000,281 | RHS- | M] () – C:\boot.ini
[2004/08/04 00:00:00 | 000,260,272 | —- | M] () – C:\cmldr
[2004/01/29 12:51:55 | 000,000,000 | —- | M] () – C:\CONFIG.SYS
[2012/07/21 17:48:03 | 000,000,488 | —- | M] () – C:\hpfr5550.xml
[2004/01/29 12:51:55 | 000,000,000 | RHS- | M] () – C:\IO.SYS
[2004/01/29 12:51:55 | 000,000,000 | RHS- | M] () – C:\MSDOS.SYS
[2004/11/03 21:41:28 | 000,047,564 | RHS- | M] () – C:\NTDETECT.COM
[2002/01/01 00:58:04 | 000,250,032 | RHS- | M] () – C:\ntldr
[2012/07/29 08:56:27 | 805,306,368 | -HS- | M] () – C:\pagefile.sys
[2011/07/05 19:37:31 | 000,011,264 | -HS- | M] () – C:\Thumbs.db

< %systemroot%\Fonts\*.com >
[2006/04/18 15:39:28 | 000,026,040 | —- | M] () – C:\WINDOWS\Fonts\GlobalMonospace.CompositeFont
[2006/06/29 14:53:56 | 000,026,489 | —- | M] () – C:\WINDOWS\Fonts\GlobalSansSerif.CompositeFont
[2006/04/18 15:39:28 | 000,029,779 | —- | M] () – C:\WINDOWS\Fonts\GlobalSerif.CompositeFont
[2006/06/29 14:58:52 | 000,030,808 | —- | M] () – C:\WINDOWS\Fonts\GlobalUserInterface.CompositeFont

< %systemroot%\Fonts\*.dll >

< %systemroot%\Fonts\*.ini >
[2004/01/29 12:51:35 | 000,000,067 | -HS- | M] () – C:\WINDOWS\Fonts\desktop.ini

< %systemroot%\Fonts\*.ini2 >

< %systemroot%\Fonts\*.exe >

< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2008/07/06 05:06:10 | 000,089,088 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\filterpipelineprintproc.dll
[2007/04/09 13:23:54 | 000,028,552 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\mdippr.dll
[2008/07/06 03:50:04 | 000,597,504 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\printfilterpipelinesvc.exe

< %systemroot%\REPAIR\*.bak1 >

< %systemroot%\REPAIR\*.ini >

< %systemroot%\system32\*.jpg >

< %systemroot%\*.jpg >

< %systemroot%\*.png >

< %systemroot%\*.scr >

< %systemroot%\*._sy >

< %APPDATA%\Adobe\Update\*.* >

< %ALLUSERSPROFILE%\Favorites\*.* >

< %APPDATA%\Microsoft\*.* >
[2012/02/05 14:17:23 | 000,001,626 | -H– | M] () – C:\Documents and Settings\Don\Application Data\Microsoft\LastFlashConfig.WFC

< %PROGRAMFILES%\*.* >
[2002/09/11 07:26:52 | 000,063,730 | —- | M] () – C:\Program Files\viewsonicinstruct_xp.pdf
[2010/03/14 21:48:11 | 004,727,808 | —- | M] () – C:\Program Files\Works632_en-US.msi

< %APPDATA%\Update\*.* >

< %systemroot%\*. /mp /s >

< %systemroot%\System32\config\*.sav >
[2004/01/29 04:44:01 | 000,094,208 | —- | M] () – C:\WINDOWS\System32\config\default.sav
[2004/01/29 04:44:01 | 000,602,112 | —- | M] () – C:\WINDOWS\System32\config\software.sav
[2004/01/29 04:44:01 | 000,405,504 | —- | M] () – C:\WINDOWS\System32\config\system.sav

< %PROGRAMFILES%\bak. /s >

< %systemroot%\system32\bak. /s >

< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >
[2008/08/27 16:05:21 | 000,000,272 | -HS- | M] () – C:\Documents and Settings\All Users\Start Menu\desktop.ini

< %systemroot%\system32\config\systemprofile\*.dat /x >

< %systemroot%\*.config >

< %systemroot%\system32\*.db >

< %PROGRAMFILES%\Internet Explorer\*.dat >

< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2012/06/24 21:47:24 | 000,014,506 | —- | M] () – C:\Documents and Settings\Don\Application Data\Microsoft\Internet Explorer\Quick Launch\10 Day Weather Forecast for Pendleton, OR (97801) - weather.com.url
[2012/06/21 22:53:29 | 000,003,881 | —- | M] () – C:\Documents and Settings\Don\Application Data\Microsoft\Internet Explorer\Quick Launch\7-Day Forecast for Latitude 45.68°N and Longitude 118.78°W (Elev. 1207 ft).url
[2006/08/30 18:18:59 | 000,000,177 | -HS- | M] () – C:\Documents and Settings\Don\Application Data\Microsoft\Internet Explorer\Quick Launch\desktop.ini
[2011/12/22 18:08:45 | 000,006,089 | —- | M] () – C:\Documents and Settings\Don\Application Data\Microsoft\Internet Explorer\Quick Launch\Dictionary.com.url
[2002/01/06 05:48:21 | 000,000,465 | —- | M] () – C:\Documents and Settings\Don\Application Data\Microsoft\Internet Explorer\Quick Launch\Hotmail is now Windows Live Hotmail. Free e-mail with security by Microsoft..url
[2009/04/26 19:41:25 | 000,000,245 | —- | M] () – C:\Documents and Settings\Don\Application Data\Microsoft\Internet Explorer\Quick Launch\Main Page - Wikipedia, the free encyclopedia.url
[2012/05/19 21:07:45 | 000,000,695 | —- | M] () – C:\Documents and Settings\Don\Application Data\Microsoft\Internet Explorer\Quick Launch\MapQuest Maps - Driving Directions - Map.url
[2004/02/02 23:30:56 | 000,000,079 | —- | M] () – C:\Documents and Settings\Don\Application Data\Microsoft\Internet Explorer\Quick Launch\Show Desktop.scf

< %USERPROFILE%\Desktop\*.exe >
[2009/12/29 21:27:52 | 004,844,272 | —- | M] (Malwarebytes Corporation ) – C:\Documents and Settings\Don\Desktop\mbam-setup.exe

< %PROGRAMFILES%\Common Files\*.* >

< %systemroot%\*.src >

< %systemroot%\install\*.* >

< %systemroot%\system32\DLL\*.* >

< %systemroot%\system32\HelpFiles\*.* >

< %systemroot%\system32\rundll\*.* >

< %systemroot%\winn32\*.* >

< %systemroot%\Java\*.* >

< %systemroot%\system32\test\*.* >

< %systemroot%\system32\Rundll32\*.* >

< %systemroot%\AppPatch\Custom\*.* >

< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >

< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2012-07-29 02:59:00

< End of report >


And here is 'Extras' from OTL:


OTL Extras logfile created on: 7/29/2012 11:45:53 AM - Run 1
OTL by OldTimer - Version 3.2.55.0 Folder = C:\Documents and Settings\Don\My Documents\Downloads
Windows XP Home Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.11)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

767.48 Mb Total Physical Memory | 189.29 Mb Available Physical Memory | 24.66% Memory free
1.46 Gb Paging File | 0.70 Gb Available in Paging File | 48.39% Paging File free
Paging file location(s): C:\pagefile.sys 768 1536 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 37.27 Gb Total Space | 5.21 Gb Free Space | 13.98% Space Free | Partition Type: NTFS
Drive H: | 149.01 Gb Total Space | 63.66 Gb Free Space | 42.72% Space Free | Partition Type: FAT32

Computer Name: UPSTAIRSDESKTOP | User Name: Don | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.bat [@ = Reg Error: Key error.] – Reg Error: Key error. File not found
.chm [@ = Reg Error: Key error.] – Reg Error: Key error. File not found
.cmd [@ = Reg Error: Key error.] – Reg Error: Key error. File not found
.com [@ = Reg Error: Key error.] – Reg Error: Key error. File not found
.cpl [@ = Reg Error: Key error.] – Reg Error: Key error. File not found
.hlp [@ = Reg Error: Key error.] – Reg Error: Key error. File not found
.hta [@ = Reg Error: Key error.] – Reg Error: Key error. File not found
.html [@ = Reg Error: Key error.] – Reg Error: Key error. File not found
.inf [@ = Reg Error: Key error.] – Reg Error: Key error. File not found
.ini [@ = Reg Error: Value error.] – Reg Error: Key error. File not found
.url [@ = Reg Error: Key error.] – Reg Error: Key error. File not found
.js [@ = Reg Error: Key error.] – Reg Error: Key error. File not found
.jse [@ = Reg Error: Key error.] – Reg Error: Key error. File not found
.pif [@ = Reg Error: Key error.] – Reg Error: Key error. File not found
.reg [@ = Reg Error: Key error.] – Reg Error: Key error. File not found
.scr [@ = Reg Error: Key error.] – Reg Error: Key error. File not found
.txt [@ = Reg Error: Value error.] – Reg Error: Key error. File not found
.vbe [@ = Reg Error: Key error.] – Reg Error: Key error. File not found
.vbs [@ = Reg Error: Key error.] – Reg Error: Key error. File not found
.wsf [@ = Reg Error: Key error.] – Reg Error: Key error. File not found
.wsh [@ = Reg Error: Key error.] – Reg Error: Key error. File not found

[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.exe [@ = exefile] – Reg Error: Key error. File not found
.html [@ = htmlfile] – Reg Error: Key error. File not found

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*
exefile [open] – "%1" %*
InternetShortcut [open] – rundll32.exe ieframe.dll,OpenURL %l
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"AntiVirusOverride" = 1
"FirewallOverride" = 0
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
"DisableMonitoring" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
"DisableMonitoring" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]
"DisableMonitoring" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

========== System Restore Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sr]
"Start" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SrService]
"Start" = 2

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile]

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
"139:TCP" = 139:TCP:*:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:*:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:*:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:*:Enabled:@xpsp2res.dll,-22002
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DoNotAllowExceptions" = 0
"DisableNotifications" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008
"139:TCP" = 139:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22002

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
"C:\Program Files\Windows Live\Messenger\msnmsgr.exe" = C:\Program Files\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger
"C:\Program Files\Windows Live\Messenger\livecall.exe" = C:\Program Files\Windows Live\Messenger\livecall.exe:*:Enabled:Windows Live Messenger (Phone)

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\WINDOWS\system32\ActionDump\Support_Files\INITCONN.EXE" = C:\WINDOWS\system32\ActionDump\Support_Files\INITCONN.EXE:*:Enabled:INITCONN
"C:\Program Files\Palm\HOTSYNC.EXE" = C:\Program Files\Palm\HOTSYNC.EXE:*:Enabled:HotSync® Manager Application – (Palm, Inc.)
"C:\Program Files\Real\RealPlayer\realplay.exe" = C:\Program Files\Real\RealPlayer\realplay.exe:*:Disabled:RealPlayer
"C:\Don\programs\Ares Ultra\Ares Ultra.exe" = C:\Don\programs\Ares Ultra\Ares Ultra.exe:*:Disabled:Ares Ultra
"C:\Program Files\Skype\Phone\Skype.exe" = C:\Program Files\Skype\Phone\Skype.exe:*:Enabled:Skype. Take a deep breath
"C:\Program Files\Windows Live\Messenger\msnmsgr.exe" = C:\Program Files\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger
"C:\Program Files\Windows Live\Messenger\livecall.exe" = C:\Program Files\Windows Live\Messenger\livecall.exe:*:Enabled:Windows Live Messenger (Phone)
"C:\Program Files\Google\Google Earth\client\googleearth.exe" = C:\Program Files\Google\Google Earth\client\googleearth.exe:*:Enabled:Google Earth – (Google)
"C:\WINDOWS\system32\fxsclnt.exe" = C:\WINDOWS\system32\fxsclnt.exe:*:Enabled:Microsoft Fax Console – (Microsoft Corporation)
"C:\Documents and Settings\Karen\Application Data\Spotify\spotify.exe" = C:\Documents and Settings\Karen\Application Data\Spotify\spotify.exe:*:Enabled:Spotify – (Spotify Ltd)


========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}" = Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148
"{08C5815C-2C6E-44f8-8748-0E61BC9AFB68}" = Symantec KB-DocID:2003093015493306
"{0AB76F69-E761-4CFA-B9B0-A1906B4E9E4B}" = WD Diagnostics
"{172423F9-522A-483A-AD65-03600CE4CA4F}" = Microsoft Works 6-9 Converter
"{178BAABD-0C95-4EB6-9E12-29A039EA27F6}" = Qwest eChat Support Tools
"{184E7118-0295-43C4-B72C-1D54AA75AAF7}" = Windows Live Mail
"{1FD0C5C1-B01B-4B4C-9607-E5D3B3D1318F}" = Microsoft IntelliPoint 4.1
"{20C45B32-5AB6-46A4-94EF-58950CAF05E5}" = EPSON Attach To Email
"{26A24AE4-039D-4CA4-87B4-2F83216020FF}" = Java™ 6 Update 20
"{2A88F1BF-7041-4E42-84B1-6B4ACB83AC64}" = EPSON Scan Assistant
"{2E497885-E60B-420A-832D-0148B392E058}_is1" = Qwiklinx
"{341201D4-4F61-4ADB-987E-9CCE4D83A58D}" = Windows Live Toolbar Extension (Windows Live Toolbar)
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{43DCF766-6838-4F9A-8C91-D92DA586DFA7}" = Microsoft Windows Journal Viewer
"{48F22622-1CC2-4A83-9C1E-644DD96F832D}" = EPSON Event Manager
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{4D8314D2-11FE-4397-A7CC-7015CFF50BCE}" = Palm Desktop
"{57752979-A1C9-4C02-856B-FBB27AC4E02C}" = QuickTime
"{5A3C1721-F8ED-11E0-8AFB-B8AC6F97B88E}" = Google Earth
"{5CF30F9D-EF11-4A61-B1AF-188DDDEEB9E9}" = Data Analysis with Microsoft Excel: Updated for Office XP
"{63569CE9-FA00-469C-AF5C-E5D4D93ACF91}" = Windows Genuine Advantage v1.3.0254.0
"{67EDD823-135A-4D59-87BD-950616D6E857}" = EPSON Copy Utility 3
"{6811CAA0-BF12-11D4-9EA1-0050BAE317E1}" = PowerDVD
"{6ECB39BD-73C2-44DD-B1A0-898207C58D8B}" = HP Photo and Imaging 2.0 - All-in-One Drivers
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{7745B7A9-F323-4BB9-9811-01BF57A028DA}" = Map Button (Windows Live Toolbar)
"{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}" = Apple Software Update
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8C8224B7-AA9B-4807-97CD-55899BAC83FE}" = YouSendIt Express
"{90120000-0020-0409-0000-0000000FF1CE}" = Compatibility Pack for the 2007 Office system
"{90150409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office Access 2003
"{913DA816-E8E4-4467-8D22-E2DF5DBF04E4}" = hp psc 2200 series
"{91CA0409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office Small Business Edition 2003
"{9692FD03-6662-4E62-B08C-30DFF51651E1}" = Actiontec Gateway
"{9867A917-5D17-40DE-83BA-BEA5293194B1}" = HP Photo and Imaging 2.0 - All-in-One
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9DE006A5-B384-4EDE-A760-0F217136B9EA}" = Microsoft IntelliType Pro 2.2
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{A3BC5D37-30F9-4CF7-BD5C-0DFF063E4B6D}" = 2Wire Wireless Client
"{A49F249F-0C91-497F-86DF-B2585E8E76B7}" = Microsoft Visual C++ 2005 Redistributable
"{A4D490D0-CF24-47AB-B8B3-BE19366D80C8}" = Actiontec Gateway/Router
"{A4D7B764-4140-11D4-88EB-0050DA3579C0}" = Nero - Burning Rom
"{A5C4AD72-25FE-4899-B6DF-6D8DF63C93CF}" = Highlight Viewer (Windows Live Toolbar)
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{AC76BA86-7AD7-1033-7B44-A81300000003}" = Adobe Reader 8.1.3
"{B1102A25-3AA3-446B-AA0F-A699B07A02FD}" = Garmin USB Drivers
"{B376402D-58EA-45EA-BD50-DD924EB67A70}" = HP Memories Disc
"{B4FEA924-630D-11D4-B78E-005004566E4D}" = ViewSonic Monitor Drivers
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{C701DC2B-7240-43D8-B776-3653952E781F}" = Garmin TOPO U.S. 24K West v2
"{C792A75A-2A1F-4991-9B85-291745478A79}" = NetAssistant
"{C9B0EED0-BF09-468F-8516-5556294BD14B}" = ADP Sample Data
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{D0795B21-0CDA-4a92-AB9E-6E92D8111E44}" = SAMSUNG USB Driver for Mobile Phones
"{D167DA32-32AB-45FC-AEC1-7380BE2221A2}" = QuickConnect
"{E0000600-0600-0600-0600-000000000600}" = ICS Viewer 6.0
"{E86BC406-944E-41F6-ADE6-2C136734C96B}" = EPSON File Manager
"{EE43894E-FDCF-4A8C-BCD6-3AAA9A48B486}" = Kies mini
"{F084395C-40FB-4DB3-981C-B51E74E1E83D}" = Smart Menus (Windows Live Toolbar)
"{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU]
"{FC47C7A5-BE63-11D5-B7C9-005004566E4D}" = ViewSonic Windows XP Signed Files
"{FCE65C4E-B0E8-4FBD-AD16-EDCBE6CD591F}" = HighMAT Extension to Microsoft Windows XP CD Writing Wizard
"45A7283175C62FAC673F913C1F532C5361F97841" = Windows Driver Package - Garmin (grmnusb) GARMIN Devices (03/08/2007 2.2.1.0)
"Adobe Flash Player ActiveX" = Adobe Flash Player 11 ActiveX
"Ares Ultra_is1" = Ares Ultra 3.0.0
"AsusNv" = ASUS Display Drivers
"EPSON Scanner" = EPSON Scan
"ERUNT_is1" = ERUNT 1.1j
"Google Chrome" = Google Chrome
"hp instant support" = hp instant support
"HP PSC 2200 Series" = HP Photo and Imaging 2.0 - hp psc 2200 series
"IDNMitigationAPIs" = Microsoft Internationalized Domain Names Mitigation APIs
"ie7" = Windows Internet Explorer 7
"InstallShield_{20C45B32-5AB6-46A4-94EF-58950CAF05E5}" = EPSON Attach To Email
"InstallShield_{8C8224B7-AA9B-4807-97CD-55899BAC83FE}" = YouSendIt Express
"InstallShield_{EE43894E-FDCF-4A8C-BCD6-3AAA9A48B486}" = Kies mini
"IrfanView" = IrfanView (remove only)
"LP Recorder" = LP Recorder
"LP Ripper" = LP Ripper
"Malwarebytes' Anti-Malware_is1" = Malwarebytes Anti-Malware version 1.62.0.1300
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"MSCompPackV1" = Microsoft Compression Client Pack 1.0 for Windows XP
"NLSDownlevelMapping" = Microsoft National Language Support Downlevel APIs
"NVIDIA Audio Driver" = NVIDIA Audio Driver
"NVIDIA Display Driver" = NVIDIA Display Driver
"NVIDIA Drivers" = NVIDIA Drivers
"NVIDIA nForce Drivers" = NVIDIA nForce Drivers
"PC Optimizer Pro" = PC Optimizer Pro
"Silent Package Run-Time Sample" = EPSON Perf 4490P Guide
"Switch" = Switch Sound File Converter
"Wave Corrector DeClick_is1" = Wave Corrector DeClick version 1.1
"WavePad" = WavePad Sound Editor
"Wdf01005" = Microsoft Kernel-Mode Driver Framework Feature Pack 1.5
"WIC" = Windows Imaging Component
"Windows Media Format Runtime" = Windows Media Format 11 runtime
"Windows Media Player" = Windows Media Player 11
"WMFDist11" = Windows Media Format 11 runtime
"wmp11" = Windows Media Player 11
"Wudf01000" = Microsoft User-Mode Driver Framework Feature Pack 1.0

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Adobe Acrobat Connect Add-in" = Adobe Acrobat Connect Add-in

========== Last 20 Event Log Errors ==========

[ Application Events ]
Error - 7/21/2012 10:20:21 PM | Computer Name = UPSTAIRSDESKTOP | Source = Application Error | ID = 1000
Description = Faulting application iexplore.exe, version 7.0.6000.17080, faulting
module mshtml.dll, version 7.0.6000.17080, fault address 0x0006462f.

Error - 7/28/2012 9:17:50 PM | Computer Name = UPSTAIRSDESKTOP | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt>
with error: This operation returned because the timeout period expired.

Error - 7/28/2012 9:17:50 PM | Computer Name = UPSTAIRSDESKTOP | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt>
with error: The specified server cannot perform the requested operation.

Error - 7/28/2012 9:17:50 PM | Computer Name = UPSTAIRSDESKTOP | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt>
with error: This operation returned because the timeout period expired.

Error - 7/28/2012 9:17:50 PM | Computer Name = UPSTAIRSDESKTOP | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt>
with error: The specified server cannot perform the requested operation.

Error - 7/28/2012 9:51:39 PM | Computer Name = UPSTAIRSDESKTOP | Source = MsiInstaller | ID = 11721
Description = Product: Apple Software Update – Error 1721. There is a problem with
this Windows Installer package. A program required for this install to complete
could not be run. Contact your support personnel or package vendor. Action: SoftwareUpdate_UnregServer,
location: C:\Program Files\Apple Software Update\SoftwareUpdate.exe, command: /UnregServer


Error - 7/28/2012 9:53:05 PM | Computer Name = UPSTAIRSDESKTOP | Source = MsiInstaller | ID = 11721
Description = Product: Apple Software Update – Error 1721. There is a problem with
this Windows Installer package. A program required for this install to complete
could not be run. Contact your support personnel or package vendor. Action: SoftwareUpdate_UnregServer,
location: C:\Program Files\Apple Software Update\SoftwareUpdate.exe, command: /UnregServer


Error - 7/28/2012 10:24:18 PM | Computer Name = UPSTAIRSDESKTOP | Source = MsiInstaller | ID = 11721
Description = Product: Apple Software Update – Error 1721. There is a problem with
this Windows Installer package. A program required for this install to complete
could not be run. Contact your support personnel or package vendor. Action: SoftwareUpdate_UnregServer,
location: C:\Program Files\Apple Software Update\SoftwareUpdate.exe, command: /UnregServer


Error - 7/28/2012 10:55:32 PM | Computer Name = UPSTAIRSDESKTOP | Source = MsiInstaller | ID = 11721
Description = Product: Apple Software Update – Error 1721. There is a problem with
this Windows Installer package. A program required for this install to complete
could not be run. Contact your support personnel or package vendor. Action: SoftwareUpdate_UnregServer,
location: C:\Program Files\Apple Software Update\SoftwareUpdate.exe, command: /UnregServer


Error - 7/29/2012 12:06:02 PM | Computer Name = UPSTAIRSDESKTOP | Source = Microsoft Office 11 | ID = 2000
Description = Accepted Safe Mode action : Microsoft Office Outlook.

[ System Events ]
Error - 7/29/2012 12:02:23 PM | Computer Name = UPSTAIRSDESKTOP | Source = Service Control Manager | ID = 7023
Description = The Application Management service terminated with the following error:
%%126

Error - 7/29/2012 12:02:23 PM | Computer Name = UPSTAIRSDESKTOP | Source = Service Control Manager | ID = 7023
Description = The Application Management service terminated with the following error:
%%126

Error - 7/29/2012 12:02:23 PM | Computer Name = UPSTAIRSDESKTOP | Source = Service Control Manager | ID = 7023
Description = The Application Management service terminated with the following error:
%%126

Error - 7/29/2012 12:02:23 PM | Computer Name = UPSTAIRSDESKTOP | Source = Service Control Manager | ID = 7023
Description = The Application Management service terminated with the following error:
%%126

Error - 7/29/2012 12:02:23 PM | Computer Name = UPSTAIRSDESKTOP | Source = Service Control Manager | ID = 7023
Description = The Application Management service terminated with the following error:
%%126

Error - 7/29/2012 12:02:23 PM | Computer Name = UPSTAIRSDESKTOP | Source = Service Control Manager | ID = 7023
Description = The Application Management service terminated with the following error:
%%126

Error - 7/29/2012 12:02:23 PM | Computer Name = UPSTAIRSDESKTOP | Source = Service Control Manager | ID = 7023
Description = The Application Management service terminated with the following error:
%%126

Error - 7/29/2012 12:02:23 PM | Computer Name = UPSTAIRSDESKTOP | Source = Service Control Manager | ID = 7023
Description = The Application Management service terminated with the following error:
%%126

Error - 7/29/2012 12:02:24 PM | Computer Name = UPSTAIRSDESKTOP | Source = Service Control Manager | ID = 7023
Description = The Application Management service terminated with the following error:
%%126

Error - 7/29/2012 12:02:24 PM | Computer Name = UPSTAIRSDESKTOP | Source = Service Control Manager | ID = 7023
Description = The Application Management service terminated with the following error:
%%126


< End of report >
Thanks for your input. It's very helpful to me for diagnosing. And no, the removals you done doesn't inhibit any of the process.

Funmoods has been identified as malicious, there are many similar cases happening in here actually.

You can check back everyday, but I believe we are half way of the world apart so probably in the morning and night(your side, assuming you're from US) you may receive a reply from me. So I first apologize for any possible delay because of this.

===================================================

Please download ExeFix.scr by Farbar and save it to a flashdrive or on the root of the system drive (usually C:).
  • Important: Boot your computer into the account that has trouble running exe files.
  • Run the tool.
  • The tool notifies you within a fraction of a second to reboot the computer, please do so.
  • Please tell me if you are now able to run programs.
Note: If the tool did not run you may change the extension to .com or .bat or .cmd or .pif
Also note that in order the fix to work you need to be booted to the user account that has trouble running exe files.

===================================================

[external image: Posted Image]
  • Please download GMER from one of the following locations, and save it to your desktop:
  • Main Mirror
    This version will download a randomly named file (Recommended)
  • Zip Mirror
    This version will download a zip file you will need to extract first. If you use this mirror, please extract the zip file to your desktop.
  • Extract the contents of the zipped file to desktop (applicable only to Zip mirror) .
  • Double click [external image: Posted Image] or [external image: Posted Image] on your desktop.
  • If it gives you a warning about rootkit activity and asks if you want to run scan…click on NO.
    [external image: Posted Image]

    [external image: Posted Image]
    Click the image to enlarge it
  • In the right panel, you will see several boxes that have been checked. Uncheck the following …
    • IAT/EAT
    • Drives/Partition other than Systemdrive (typically C:\)
    • Show All (don't miss this one)
  • Then click the Scan button & wait for it to finish.
  • Once done click on the [Save..] button, and in the File name area, type in "Gmer.txt" or it will save as a .log file which cannot be uploaded to your post.
  • Save it where you can easily find it, such as your desktop, and attach it in your reply.
**Caution**
Rootkit scans often produce false positives. Do NOT take any action on any "<— ROOKIT" entries


===================================================

Download TDSSKiller.exe and save it to your desktop

Execute TDSSKiller.exe by doubleclicking on it.
Press Start Scan
If Malicious objects are found, do NOT select Cure. Change the action to Skip, and save the log.
Once complete, a log will be produced at the root drive which is typically C:\ ,for example, C:\TDSSKiller.log.txt

===================================================

On your next reply please post :
GMER log
TDSS Killer log


Please STOP and let me know if you have any problems in performing with the steps above or any questions you may have.

Good Day!
I was not able to run exefix. On the affected computer, when I clicked on the link or did ctrl-click, I'd get a blank screen or an error message. I then emailed the link to a laptop and downloaded exefix to a thumb drive, and plugged that into the problem computer. While booted into the admin area where the problem is occurring I tried both double clicking on exefix and running it from the windows/start button run command. I tried replacing the extension (which seemed to be a screen saver, scr, ext.) with all those you suggested. No matter which way I tried to run exefix, or which extension I used, I'd get one or the other of two error messages: -Windows can't open this file… To open this file, Windows needs to know what program created it… ( and it gives options to find the program via web or a list) -Windows cannot find…. Make sure you typed the name correctly, and try again. To search… I didn't run the scans you sent since I imagine you wanted them to scan the results of exefix. Any thoughts on what else I can do?
LOL seems like I missed that .scr wouldn't run either..

Let's try it this way..

Copy the below code. Click Start, Run and enter CMD A Command Prompt window will open. Right click in this Window and select Paste. Then press Enter.

assoc.bat=batfile

Next,

I need you to make a batch file.

Open a new Notepad session

  • Click the Start button, click Run
  • In the run box type notepad
  • Click OK
  • In the notepad, Click "Format" and be certain that Word Wrap is not checked.
  • Copy and paste all the text in the code box below into the Notepad. Do Not copy the word CODE
REM Restore Default File Associations for Windows XP.
REM Copyright 2003 - Doug Knox
REM This BAT file restores the Default associations that XP ships with
REM It does not restore associations created by 3rd party applications.

Echo Restoring Default File Associations

assoc.323=h323file
assoc.386=vxdfile
assoc.aca=Agent.Character.2
assoc.acf=Agent.Character.2
assoc.acs=Agent.Character2.2
assoc.acw=acwfile
assoc.ai=
assoc.aif=AIFFFile
assoc.aifc=AIFFFile
assoc.aiff=AIFFFile
assoc.ani=anifile
assoc.aps=
assoc.asa=aspfile
assoc.ascx=
assoc.asf=ASFFile
assoc.asm=
assoc.asmx=
assoc.asp=aspfile
assoc.aspx=
assoc.asx=ASXFile
assoc.au=AUFile
assoc.AudioCD=AudioCD
assoc.avi=avifile
assoc.bat=batfile
assoc.bfc=Briefcase
assoc.bin=
assoc.bkf=msbackupfile
assoc.blg=PerfFile
assoc.bmp=Paint.Picture
assoc.bsc=
assoc.c=
assoc.cab=CLSID\{0CD7A5C0-9F37-11CE-AE65-08002B2E1262}
assoc.cat=CATFile
assoc.cda=CDAFile
assoc.cdf=ChannelFile
assoc.cdx=aspfile
assoc.cer=CERFile
assoc.cgm=
assoc.chk=chkfile
assoc.chm=chm.file
assoc.clp=clpfile
assoc.cmd=cmdfile
assoc.cnf=ConferenceLink
assoc.com=comfile
assoc.cpl=cplfile
assoc.cpp=
assoc.crl=CRLFile
assoc.crt=CERFile
assoc.css=CSSfile
assoc.csv=
assoc.CTT=MessengerContactList
assoc.cur=curfile
assoc.cxx=
assoc.dat=
assoc.db=dbfile
assoc.dbg=
assoc.dct=
assoc.def=
assoc.der=CERFile
assoc.DeskLink=CLSID\{9E56BE61-C50F-11CF-9A2C-00A0C90A90CE}
assoc.dib=Paint.Picture
assoc.dic=
assoc.diz=
assoc.dll=dllfile
assoc.dl_=
assoc.doc=WordPad.Document.1
assoc.dos=
assoc.dot=
assoc.drv=drvfile
assoc.dsn=MSDASQL
assoc.dun=dunfile
assoc.DVD=DVD
assoc.emf=emffile
assoc.eml=Microsoft Internet Mail Message
assoc.eps=
assoc.exe=exefile
assoc.exp=
assoc.ex_=
assoc.eyb=
assoc.fif=
assoc.fnd=fndfile
assoc.fnt=
assoc.Folder=Folder
assoc.fon=fonfile
assoc.ghi=
assoc.gif=giffile
assoc.grp=MSProgramGroup
assoc.gz=
assoc.h=
assoc.hhc=
assoc.hlp=hlpfile
assoc.hpp=
assoc.hqx=
assoc.ht=htfile
assoc.hta=htafile
assoc.htc=
assoc.htm=htmlfile
assoc.html=htmlfile
assoc.htt=HTTfile
assoc.htw=
assoc.htx=
assoc.hxx=
assoc.icc=icmfile
assoc.icm=icmfile
assoc.ico=icofile
assoc.idb=
assoc.idl=
assoc.idq=
assoc.iii=iiifile
assoc.ilk=
assoc.imc=
assoc.inc=
assoc.inf=inffile
assoc.ini=inifile
assoc.ins=x-internet-signup
assoc.inv=
assoc.inx=
assoc.in_=
assoc.isp=x-internet-signup
assoc.its=ITS File
assoc.IVF=IVFFile
assoc.java=
assoc.jbf=
assoc.jfif=pjpegfile
assoc.job=JobObject
assoc.jod=Microsoft.Jet.OLEDB.4.0
assoc.jpe=jpegfile
assoc.jpeg=jpegfile
assoc.jpg=jpegfile
assoc.JS=JSFile
assoc.JSE=JSEFile
assoc.latex=
assoc.lib=
assoc.lnk=lnkfile
assoc.local=
assoc.log=txtfile
assoc.lwv=LWVFile
assoc.m14=
assoc.m1v=mpegfile
assoc.m3u=m3ufile
assoc.man=
assoc.manifest=
assoc.MAPIMail=CLSID\{9E56BE60-C50F-11CF-9A2C-00A0C90A90CE}
assoc.mdb=
assoc.mht=mhtmlfile
assoc.mhtml=mhtmlfile
assoc.mid=midfile
assoc.midi=midfile
assoc.mmf=
assoc.mmm=MPlayer
assoc.mov=
assoc.movie=
assoc.mp2=mpegfile
assoc.mp2v=mpegfile
assoc.mp3=mp3file
assoc.mpa=mpegfile
assoc.mpe=mpegfile
assoc.mpeg=mpegfile
assoc.mpg=mpegfile
assoc.mpv2=mpegfile
assoc.msc=MSCFile
assoc.msg=
assoc.msi=Msi.Package
assoc.msp=Msi.Patch
assoc.MsRcIncident=MsRcIncident
assoc.msstyles=msstylesfile
assoc.MSWMM=Windows.Movie.Maker
assoc.mv=
assoc.mydocs=CLSID\{ECF03A32-103D-11d2-854D-006008059367}
assoc.ncb=
assoc.nfo=MSInfo.Document
assoc.nls=
assoc.NMW=T126_Whiteboard
assoc.nsc=
assoc.nvr=
assoc.nws=Microsoft Internet News Message
assoc.obj=
assoc.ocx=ocxfile
assoc.oc_=
assoc.odc=
assoc.otf=otffile
assoc.p10=P10File
assoc.p12=PFXFile
assoc.p7b=SPCFile
assoc.p7c=certificate_wab_auto_file
assoc.p7m=P7MFile
assoc.p7r=SPCFile
assoc.p7s=P7SFile
assoc.pbk=pbkfile
assoc.pch=
assoc.pdb=
assoc.pds=
assoc.pfm=pfmfile
assoc.pfx=PFXFile
assoc.php3=
assoc.pic=
assoc.pif=piffile
assoc.pko=PKOFile
assoc.pl=
assoc.plg=
assoc.pma=PerfFile
assoc.pmc=PerfFile
assoc.pml=PerfFile
assoc.pmr=PerfFile
assoc.pmw=PerfFile
assoc.pnf=pnffile
assoc.png=pngfile
assoc.pot=
assoc.pps=
assoc.ppt=
assoc.prf=prffile
assoc.ps=
assoc.psd=
assoc.psw=PSWFile
assoc.qds=SavedDsQuery
assoc.rat=ratfile
assoc.rc=
assoc.RDP=RDP.File
assoc.reg=regfile
assoc.res=
assoc.rle=
assoc.rmi=midfile
assoc.rnk=rnkfile
assoc.rpc=
assoc.rsp=
assoc.rtf=rtffile
assoc.sam=
assoc.sbr=
assoc.sc2=
assoc.scf=SHCmdFile
assoc.scp=txtfile
assoc.scr=scrfile
assoc.sct=scriptletfile
assoc.sdb=appfixfile
assoc.sed=
assoc.shb=DocShortcut
assoc.shs=ShellScrap
assoc.shtml=
assoc.shw=
assoc.sit=
assoc.snd=AUFile
assoc.spc=SPCFile
assoc.spl=ShockwaveFlash.ShockwaveFlash
assoc.sql=
assoc.sr_=
assoc.sst=CertificateStoreFile
assoc.stl=STLFile
assoc.stm=
assoc.swf=ShockwaveFlash.ShockwaveFlash
assoc.sym=
assoc.sys=sysfile
assoc.sy_=
assoc.tar=
assoc.text=
assoc.tgz=
assoc.theme=themefile
assoc.tif=TIFImage.Document
assoc.tiff=TIFImage.Document
assoc.tlb=
assoc.tsp=
assoc.tsv=
assoc.ttc=ttcfile
assoc.ttf=ttffile
assoc.txt=txtfile
assoc.UDL=MSDASC
assoc.uls=ulsfile
assoc.URL=InternetShortcut
assoc.VBE=VBEFile
assoc.vbs=VBSFile
assoc.vbx=
assoc.vcf=vcard_wab_auto_file
assoc.vxd=vxdfile
assoc.wab=wab_auto_file
assoc.wav=soundrec
assoc.wax=WAXFile
assoc.wb2=
assoc.webpnp=webpnpFile
assoc.WHT=Whiteboard
assoc.wk4=
assoc.wll=
assoc.wlt=
assoc.wm=ASFFile
assoc.wma=WMAFile
assoc.wmd=WMDFile
assoc.wmf=wmffile
assoc.wmp=WMPFile
assoc.wms=WMSFile
assoc.wmv=WMVFile
assoc.wmx=ASXFile
assoc.wmz=WMZFile
assoc.wpd=
assoc.wpg=
assoc.wri=wrifile
assoc.wsc=scriptletfile
assoc.WSF=WSFFile
assoc.WSH=WSHFile
assoc.wsz=
assoc.wtx=txtfile
assoc.wvx=WVXFile
assoc.x=
assoc.xbm=
assoc.xix=
assoc.xlb=
assoc.xlc=
assoc.xls=
assoc.xlt=
assoc.xml=xmlfile
assoc.xsl=xslfile
assoc.z=
assoc.z96=
assoc.zap=zapfile
assoc.ZFSendToTarget=CLSID\{888DCA60-FC0A-11CF-8F0F-00C04FD7D062}
assoc.zip=CompressedFolder

Echo Default File Associations Restored

In the notepad

Click File, Save as…, and set the Save in to your Desktop
In the filename box, type (including quotation marks) as the filename: "fix.bat"
Click Save


You should now have a file on your desktop with an icon like this [external image: Posted Image]

Double click on fix.bat & allow it to run. A small black screen may briefly flash on and off, that normal.

Finally, let me know if you could run GMER and TDSS Killer with this fix.
You're welcome :)

Now we should be able to run some tools.

Please read through these instructions to familiarize yourself with what to expect when this tool runs

Refer to the ComboFix User's Guide

Download ComboFix from one of these locations:

Link 1
Link 2


* IMPORTANT- Save ComboFix.exe to your Desktop

====================================================

Disable your AntiVirus and AntiSpyware applications as they will interfere with our tools and the removal. If you are unsure how to do this, please refer to our sticky topic How to disable your security applications

====================================================


Double click on ComboFix.exe & follow the prompts.

  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.


[external image: Posted Image]


Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:


[external image: Posted Image]


Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply for further review.
I ran combofix and copied the log in below in this message box. It seemed odd - didn't want to download, didn't look/ask for a restore option, didn't have all the stages (like saying its ending at stage 34 as the instructions said). But it produced a log - hope that worked - here it is:



ComboFix 12-07-31.06 - Don 08/03/2012 20:31:11.4.1 - x86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.767.475 [GMT -7:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\documents and settings\All Users\Start Menu\Programs\Startup\hpoddt01.exe.lnk
c:\documents and settings\Default User\WINDOWS
c:\documents and settings\Don\My Documents\ShopToWin
c:\documents and settings\Don\WINDOWS
c:\documents and settings\Karen\WINDOWS
c:\program files\Freeze.com\NetAssistant\NeTAssistant.dll
c:\windows\system32\config\systemprofile\WINDOWS
c:\windows\system32\DIFxAPI.dll
c:\windows\system32\DIFxAPI.dll\DIFxAPI.dll
c:\windows\system32\URTTemp
c:\windows\system32\URTTemp\fusion.dll
c:\windows\system32\URTTemp\mscoree.dll
c:\windows\system32\URTTemp\mscoree.dll.local
c:\windows\system32\URTTemp\mscorsn.dll
c:\windows\system32\URTTemp\mscorwks.dll
c:\windows\system32\URTTemp\msvcr71.dll
c:\windows\system32\URTTemp\regtlib.exe
H:\autorun.inf
.
.
((((((((((((((((((((((((( Files Created from 2012-07-04 to 2012-08-04 )))))))))))))))))))))))))))))))
.
.
2012-08-04 02:09 . 2012-08-04 02:09 ——– d—–w- c:\windows\LastGood
2012-07-29 01:16 . 2012-01-19 17:22 42864 —-a-r- c:\windows\system32\SBBD.EXE
2012-07-29 01:16 . 2012-01-12 16:26 101112 —-a-r- c:\windows\system32\drivers\SBREDrv.sys
2012-07-29 01:16 . 2012-07-29 16:02 ——– d—–w- c:\program files\STOPzilla!
2012-07-22 02:40 . 2012-07-22 02:42 ——– d—–w- C:\zamzar
2012-07-22 02:17 . 2012-07-22 22:38 ——– d—–w- c:\documents and settings\All Users\Application Data\Tarma Installer
2012-07-22 02:16 . 2012-07-22 02:16 ——– d—–w- c:\documents and settings\All Users\Application Data\PC Optimizer Pro
2012-07-22 02:08 . 2012-07-22 02:08 ——– d—–w- c:\documents and settings\Don\Local Settings\Application Data\visi_coupon
2012-07-22 02:07 . 2012-07-22 03:00 ——– d—–w- c:\documents and settings\Don\AbiSuite
2012-07-22 02:06 . 2012-07-22 02:06 ——– d—–w- c:\program files\Free Offers from Freeze.com
2012-07-22 02:06 . 2012-07-22 02:06 ——– d—–w- C:\extensions
2012-07-22 02:06 . 2012-07-22 02:06 ——– d—–w- c:\documents and settings\Don\Application Data\Qwiklinx
2012-07-22 02:06 . 2012-07-22 02:06 ——– d—–w- c:\program files\Qwiklinx
2012-07-22 02:06 . 2012-07-22 02:16 ——– d—–w- c:\program files\PC Optimizer Pro
2012-07-22 02:05 . 2012-07-22 22:36 ——– d—–w- c:\program files\Yahoo!
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-07-28 03:32 . 2012-04-17 05:01 426184 —-a-w- c:\windows\system32\FlashPlayerApp.exe
2012-07-28 03:32 . 2011-07-11 18:42 70344 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2012-07-28 03:32 . 2012-05-05 17:32 9230024 —-a-w- c:\windows\system32\FlashPlayerInstaller.exe
2010-03-15 04:48 . 2010-03-15 04:48 4727808 —-a-w- c:\program files\Works632_en-US.msi
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"EEventManager"="c:\program files\EPSON\Creativity Suite\Event Manager\EEventManager.exe" [2005-04-08 102400]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2003-11-17 3022848]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2010-11-30 421888]
.
c:\documents and settings\Don\Start Menu\Programs\Startup\
HotSync Manager.LNK - c:\program files\Palm\HOTSYNC.EXE [2003-9-25 299008]
.
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Gamma Loader.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2005-11-28 113664]
hp psc 2000 Series.lnk - c:\program files\Hewlett-Packard\Digital Imaging\bin\hpobnz08.exe [2003-4-6 323646]
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\Palm\\HOTSYNC.EXE"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Google\\Google Earth\\client\\googleearth.exe"=
"c:\\WINDOWS\\system32\\fxsclnt.exe"=
"c:\\Documents and Settings\\Karen\\Application Data\\Spotify\\spotify.exe"=
.
R1 ANVIOCTL;ANVIOCTL;c:\windows\system32\drivers\anvioctl.sys [1/29/2004 5:36 PM 233280]
R1 SBRE;SBRE;c:\windows\system32\drivers\SBREDrv.sys [7/28/2012 6:16 PM 101112]
S2 AfaService;Afa Card Reader Service;c:\windows\system32\afasrv32.exe [3/9/2010 6:17 PM 65536]
S2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [1/29/2010 9:23 PM 135664]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [4/16/2012 10:01 PM 250056]
S3 androidusb;SAMSUNG Android Composite ADB Interface Driver;c:\windows\system32\drivers\ssadadb.sys [6/26/2011 10:06 PM 30312]
S3 gupdatem;Google Update Service (gupdatem);c:\program files\Google\Update\GoogleUpdate.exe [1/29/2010 9:23 PM 135664]
S3 MHIKEY10;MHIKEY10;c:\windows\system32\Drivers\MHIKEY10.sys –> c:\windows\system32\Drivers\MHIKEY10.sys [?]
S3 ssadbus;SAMSUNG Android USB Composite Device driver (WDM);c:\windows\system32\drivers\ssadbus.sys [6/26/2011 10:06 PM 96488]
S3 ssadmdfl;SAMSUNG Android USB Modem (Filter);c:\windows\system32\drivers\ssadmdfl.sys [6/26/2011 10:06 PM 12776]
S3 ssadmdm;SAMSUNG Android USB Modem Drivers;c:\windows\system32\drivers\ssadmdm.sys [6/26/2011 10:06 PM 121576]
.
Contents of the 'Scheduled Tasks' folder
.
2012-08-04 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-04-17 03:32]
.
2012-08-04 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-01-30 04:23]
.
2012-08-04 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-01-30 04:23]
.
2012-08-04 c:\windows\Tasks\PC Optimizer Pro startups.job
- c:\program files\PC Optimizer Pro\StartApps.exe [2012-06-13 11:27]
.
2012-08-02 c:\windows\Tasks\PC Optimizer Pro Updates.job
- c:\program files\PC Optimizer Pro\StartApps.exe [2012-06-13 11:27]
.
2011-02-01 c:\windows\Tasks\switchShakeIcon.job
- c:\program files\NCH Swift Sound\Switch\switch.exe [2010-12-28 04:41]
.
2012-08-04 c:\windows\Tasks\User_Feed_Synchronization-{3164E000-95DA-4E16-A4B2-D13B5FE2D76C}.job
- c:\windows\system32\msfeedssync.exe [2006-10-17 19:58]
.
2010-12-28 c:\windows\Tasks\wavepadSevenDays.job
- c:\program files\NCH Swift Sound\WavePad\wavepad.exe [2010-12-28 04:42]
.
2010-12-28 c:\windows\Tasks\wavepadShakeIcon.job
- c:\program files\NCH Swift Sound\WavePad\wavepad.exe [2010-12-28 04:42]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://start.funmoods.com/?f=1&a=axl&chnl=axl&cd=2XzuyEtN2Y1L1QzutDtDtD0CyByCzz0EyE0AzyyByC0BtAyDtN0D0Tzu0CtBtDtAtN1L2Xzut
BtFtCtFtDtFtAtDtC&cr=2110581096
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
mStart Page = hxxp://start.funmoods.com/?f=1&a=axl&chnl=axl&cd=2XzuyEtN2Y1L1QzutDtDtD0CyByCzz0EyE0AzyyByC0BtAyDtN0D0Tzu0CtBtDtAtN1L2Xzut
BtFtCtFtDtFtAtDtC&cr=2110581096
uInternet Settings,ProxyOverride = 127.0.0.1
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
TCP: DhcpNameServer = 192.168.1.1
DPF: DirectAnimation Java Classes - file://c:\windows\Java\classes\dajava.cab
DPF: Garmin Communicator Plug-In - hxxps://static.garmincdn.com/gcp/ie/3.0.1.0/GarminAxControl.CAB
DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
DPF: {01118F00-3E00-11D2-8470-0060089874ED} - hxxp://symantec.atgnow.com/sdccommon/download/ssrc.cab
DPF: {01119400-3E00-11D2-8470-0060089874ED} - hxxp://symantec.atgnow.com/sdccommon/download/sprtctlln.cab
.
- - - - ORPHANS REMOVED - - - -
.
URLSearchHooks-{81017EA9-9AA8-4A6A-9734-7AF40E7D593F} - (no file)
Notify-dimsntfy - (no file)
Notify-TPSvc - TPSvc.dll
AddRemove-Ares Ultra_is1 - c:\don\programs\Ares Ultra\unins000.exe
AddRemove-03_Swallowtail - c:\program files\Samsung\USB Drivers\03_Swallowtail\Uninstall.exe
AddRemove-04_semseyite - c:\program files\Samsung\USB Drivers\04_semseyite\Uninstall.exe
AddRemove-16_Shrewsbury - c:\program files\Samsung\USB Drivers\16_Shrewsbury\Uninstall.exe
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2012-08-03 20:45
Windows 5.1.2600 Service Pack 2 NTFS
.
scanning hidden processes …
.
scanning hidden autostart entries …
.
scanning hidden files …
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————
.
[HKEY_USERS\S-1-5-21-1214440339-630328440-839522115-1006\Software\Microsoft\SystemCertificates\AddressBook*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
.
Completion time: 2012-08-03 20:49:24
ComboFix-quarantined-files.txt 2012-08-04 03:49
.
Pre-Run: 5,602,656,256 bytes free
Post-Run: 6,519,484,416 bytes free
.
- - End Of File - - 86C67CC019A708EAD9B9F88E87E96F86
Sometimes the stages will be different than what it is shown due to the differences in computers. We will take it from here.

Run OTL.exe
  • Copy/paste the following text written inside of the code box into the Custom Scans/Fixes box located at the bottom of OTL

    :OTL
    IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://start.funmoods.com/?f=1&a=axl&a…p;cr=2110581096
    IE - HKLM\..\SearchScopes\{B7971660-A1CE-4FDD-B9E0-2C37D77AFB0B}: "URL" = http://start.funmoods.com/results.php?f=4&…p;cr=2110581096
    IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://start.funmoods.com/?f=1&a=axl&a…p;cr=2110581096
    IE - HKCU\..\URLSearchHook: - No CLSID value found
    IE - HKCU\..\SearchScopes\{19F2B849-4ADE-4d4b-85F9-C31C643DBDE9}: "URL" = http://fastbrowsersearch.com/results/resul…p;s=DSP&v=9
    IE - HKCU\..\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}: "URL" = http://search.conduit.com/ResultsExt.aspx?…;ctid=CT2801948
    IE - HKCU\..\SearchScopes\{B7971660-A1CE-4FDD-B9E0-2C37D77AFB0B}: "URL" = http://start.funmoods.com/results.php?f=4&…p;cr=2110581096
    IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
    IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = 127.0.0.1
    CHR - homepage: http://start.funmoods.com/?f=1&a=axl&a…p;cr=2110581096
    CHR - default_search_provider: Web Search (Enabled)
    CHR - default_search_provider: search_url = http://start.funmoods.com/results.php?f=4&…p;cr=2110581096
    CHR - homepage: http://start.funmoods.com/?f=1&a=axl&a…p;cr=2110581096
    
    :Files
    c:\program files\Free Offers from Freeze.com
    
    :Commands
    [EMPTYFLASH]
    [EMPTYTEMP]
    [RESETHOSTS]
    [CREATERESTOREPOINT]
  • Then click the Run Fix button at the top
  • Let the program run unhindered, reboot when it is done
  • Then post Fix OTL log as well as a new OTL log by rerunning it after reboot without custom scans script.
Hi,

No need to attach the logs, it will be easier for us to research if you copy/paste the whole thing. Split into separate posts if need be. :)

Run OTL.exe
  • Copy/paste the following text written inside of the code box into the Custom Scans/Fixes box located at the bottom of OTL

    :OTL
    [2012/07/21 19:17:22 | 000,384,844 | —- | C] () – C:\Documents and Settings\Don\Local Settings\Application Data\funmoods-speeddial.crx
    
    :Commands
    [REBOOT]
    [CLEARALLRESTOREPOINTS]
  • Then click the Run Fix button at the top
  • Let the program run unhindered, reboot when it is done
  • Then post Fix OTL log as well as a new OTL log by rerunning it after reboot without custom scans script.
===================================================

ESET Online Scanner
I'd like us to scan your machine with ESET OnlineScan

Note: If you are using Windows Vista/7, open your browser by right-clicking on its icon and select 'Run as administrator' to perform this scan.

*Note
It is recommended to disable onboard antivirus program and antispyware programs while performing scans so there are no conflicts and it will speed up scan time.
Please don't go surfing while your resident protection is disabled!
Once the scan is finished remember to re-enable your antivirus along with your antispyware programs.



  • Hold down Control and click on the following link to open ESET OnlineScan in a new window.
    ESET OnlineScan
  • Click the [external image: Posted Image] button.
  • For alternate browsers only: (Microsoft Internet Explorer users can skip these steps)
    • Click on [external image: Posted Image] to download the ESET Smart Installer. Save it to your desktop.
    • Double click on the [external image: Posted Image] icon on your desktop.
  • Check [external image: Posted Image]
  • Click the [external image: Posted Image] button.
  • Accept any security warnings from your browser.
  • Check [external image: Posted Image]
  • Make sure that the option "Remove found threats" is Unchecked
  • Push the Start button.
  • ESET will then download updates for itself, install itself, and begin
    scanning your computer. Please be patient as this can take some time.
  • When the scan completes, push [external image: Posted Image]
  • Push [external image: Posted Image], and save the file to your desktop using a unique name, such as MyEsetScan. Alternatively, look for report in C:\Program Files\ESET\ESET Online Scanner\log.txt. Include the contents of this report in your next reply.
  • Push the Back button.
  • Select Uninstall application on close check box and push [external image: Posted Image]
===================================================

Malwarebytes' Anti-Malware
Download Malwarebytes' Anti-Malware here and save to your desktop.
  • Double-click mbam-setup.exe and follow the prompts to install the program. (Note to Vista users, please right-click and select Run as Administrator.)
  • At the end, be sure a checkmark is placed next to:
    • Update Malwarebytes' Anti-Malware
    • Launch Malwarebytes' Anti-Malware
  • Then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select Perform quick scan, then click Scan.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Be sure that everything is checked, and click Remove Selected.
  • When completed, a log will open in Notepad. Please copy and paste the log back into your next reply
Note:
  • The log can also be found here:
    C:\Documents and Settings\Username\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\Logs\mbam-log-date (time).txt
  • Or via the Logs tab when Malwarebytes' Anti-Malware is started.
Note: If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts.
Click OK to either and let MBAM proceed with the disinfection process.
If asked to restart the computer, please do so. Failure to reboot will prevent MBAM from removing all the malware.


===================================================

On your next reply please post :
OTL fix log
Fresh OTL log
ESET log
MBAM log


Please STOP and let me know if you have any problems in performing with the steps above or any questions you may have.

Good Day!
Conspire,

I've pasted in all the logs below,that I was able to produce, as follows:

OTL fix log - OTL did not generate a log when I ran the fix code that you sent, or if if id did, it wasn't on the desktop or in the downloads folder where it was in the past

Fresh OTL log - pasted below.

ESET log - I ran ESET, but when I did the uninstall it deleted the log - I should have saved that elsewhere first. I didn't realize this until after I ran MBAM. Should I run it again?

MBAM log - pasted below. MBAM didn't seem to find anything and so didn't ask me to remove threats, didn't provide the option to show results, so I'm not sure I followed instructions exactly.

Regards,
Don


OTL logfile created on: 8/5/2012 8:55:39 PM - Run 3
OTL by OldTimer - Version 3.2.55.0 Folder = C:\Documents and Settings\Don\My Documents\Downloads
Windows XP Home Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.11)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

767.48 Mb Total Physical Memory | 525.11 Mb Available Physical Memory | 68.42% Memory free
1.46 Gb Paging File | 1.29 Gb Available in Paging File | 88.84% Paging File free
Paging file location(s): C:\pagefile.sys 768 1536 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 37.27 Gb Total Space | 10.02 Gb Free Space | 26.89% Space Free | Partition Type: NTFS
Drive H: | 149.01 Gb Total Space | 57.91 Gb Free Space | 38.86% Space Free | Partition Type: FAT32

Computer Name: UPSTAIRSDESKTOP | User Name: Don | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Documents and Settings\Don\My Documents\Downloads\OTL.exe (OldTimer Tools)
PRC - C:\WINDOWS\system32\afasrv32.exe ()
PRC - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe ()
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\epson\Creativity Suite\Event Manager\EEventManager.exe (SEIKO EPSON CORPORATION)
PRC - C:\Program Files\Palm\HOTSYNC.EXE (Palm, Inc.)
PRC - C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hposts08.exe (Hewlett-Packard Co.)
PRC - C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpoevm08.exe (Hewlett-Packard Co.)
PRC - C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpobnz08.exe (Hewlett-Packard Co.)
PRC - C:\WINDOWS\system32\HPZipm12.exe (HP)


========== Modules (No Company Name) ==========

MOD - C:\WINDOWS\system32\afasrv32.exe ()
MOD - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe ()
MOD - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcnet.dll ()
MOD - C:\WINDOWS\system32\hpotscl.dll ()


========== Win32 Services (SafeList) ==========

SRV - (HidServ) – %SystemRoot%\System32\hidserv.dll File not found
SRV - (CLTNetCnService) – C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe /h ccCommon File not found
SRV - (AppMgmt) – %SystemRoot%\System32\appmgmts.dll File not found
SRV - (AdobeFlashPlayerUpdateSvc) – C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe (Adobe Systems Incorporated)
SRV - (AfaService) – C:\WINDOWS\system32\afasrv32.exe ()
SRV - (Symantec Core LC) – C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe ()
SRV - (Pml Driver HPZ12) – C:\WINDOWS\system32\HPZipm12.exe (HP)


========== Driver Services (SafeList) ==========

DRV - (Winsock - Google Desktop Search Backup Before Last Install) – File not found
DRV - (Winsock - Google Desktop Search Backup Before First Install) – File not found
DRV - (WDICA) – File not found
DRV - (PDRFRAME) – File not found
DRV - (PDRELI) – File not found
DRV - (PDFRAME) – File not found
DRV - (PDCOMP) – File not found
DRV - (PCIDump) – File not found
DRV - (MHIKEY10) – System32\Drivers\MHIKEY10.sys File not found
DRV - (lbrtfdc) – File not found
DRV - (i2omgmt) – File not found
DRV - (GEARAspiWDM) – System32\Drivers\GEARAspiWDM.sys File not found
DRV - (Changer) – File not found
DRV - (catchme) – C:\DOCUME~1\Don\LOCALS~1\Temp\catchme.sys File not found
DRV - (SBRE) – C:\WINDOWS\system32\drivers\SBREDrv.sys (GFI Software)
DRV - (sscdmdm) – C:\WINDOWS\system32\drivers\sscdmdm.sys (MCCI Corporation)
DRV - (ssadmdm) – C:\WINDOWS\system32\drivers\ssadmdm.sys (MCCI Corporation)
DRV - (sscdbus) – C:\WINDOWS\system32\drivers\sscdbus.sys (MCCI Corporation)
DRV - (ssadbus) – C:\WINDOWS\system32\drivers\ssadbus.sys (MCCI Corporation)
DRV - (androidusb) – C:\WINDOWS\system32\drivers\ssadadb.sys (Google Inc)
DRV - (sscdmdfl) – C:\WINDOWS\system32\drivers\sscdmdfl.sys (MCCI Corporation)
DRV - (ssadmdfl) – C:\WINDOWS\system32\drivers\ssadmdfl.sys (MCCI Corporation)
DRV - (ssmdrv) – C:\WINDOWS\system32\drivers\ssmdrv.sys (Avira GmbH)
DRV - (eeCtrl) – C:\Program Files\Common Files\Symantec Shared\eengine\eectrl.sys (Symantec Corporation)
DRV - (2WIREPCP) – C:\WINDOWS\system32\drivers\2WirePCP.sys (2Wire, Inc.)
DRV - (symlcbrd) – C:\WINDOWS\system32\drivers\symlcbrd.sys (Symantec Corporation)
DRV - (MDC8021X) – C:\WINDOWS\system32\drivers\mdc8021x.sys (Meetinghouse Data Communications)
DRV - (nvnforce) – C:\WINDOWS\system32\drivers\nvapu.sys (NVIDIA Corporation)
DRV - (nvax) – C:\WINDOWS\system32\drivers\nvax.sys (NVIDIA Corporation)
DRV - (AFS2K) – C:\WINDOWS\System32\drivers\AFS2K.SYS (Oak Technology Inc.)
DRV - (rtl8139) – C:\WINDOWS\system32\drivers\rtl8139.sys (Realtek Semiconductor Corporation)
DRV - (PalmUSBD) – C:\WINDOWS\system32\drivers\PalmUSBD.sys (Palm, Inc.)
DRV - (ANVIOCTL) – C:\WINDOWS\system32\drivers\anvioctl.sys (ASUSTeK)
DRV - (asuskbnt) – C:\WINDOWS\system32\drivers\asuskbnt.sys (ASUSTeK COMPUTER INC.)
DRV - (nv_agp) – C:\WINDOWS\system32\drivers\nv_agp.SYS (NVIDIA Corporation)
DRV - (NVENET) – C:\WINDOWS\system32\drivers\NVENET.sys (NVIDIA Corporation)
DRV - (IPFilter) – C:\WINDOWS\system32\drivers\ipfilter.sys (Microsoft Corporation)
DRV - (pfc) – C:\WINDOWS\system32\drivers\PFC.SYS (Padus, Inc.)
DRV - (V124) – C:\WINDOWS\system32\drivers\HSF_V124.sys (Conexant)
DRV - (Tones) – C:\WINDOWS\system32\drivers\HSF_TONE.sys (Conexant)
DRV - (hsf_msft) – C:\WINDOWS\system32\drivers\HSF_MSFT.sys (Conexant)
DRV - (Rksample) – C:\WINDOWS\system32\drivers\HSF_SAMP.sys (Conexant)
DRV - (K56) – C:\WINDOWS\system32\drivers\HSF_K56K.sys (Conexant)
DRV - (Fallback) – C:\WINDOWS\system32\drivers\HSF_FALL.sys (Conexant)
DRV - (SoftFax) – C:\WINDOWS\system32\drivers\HSF_FAXX.sys (Conexant)
DRV - (Fsks) – C:\WINDOWS\system32\drivers\HSF_FSKS.sys (Conexant)
DRV - (basic2) – C:\WINDOWS\system32\drivers\HSF_BSC2.sys (Conexant)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie
IE - HKLM\..\SearchScopes,Backup.Old.DefaultScope = {6A1806CD-94D4-4689-BA73-E35EA1EA9990}
IE - HKLM\..\SearchScopes,DefaultScope = {B7971660-A1CE-4FDD-B9E0-2C37D77AFB0B}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://search.live.com/results.aspx?q={sea…ferrer:source?}
IE - HKLM\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.com/search?q={searchTerm…mp;sourceid=ie7

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Backup.Old.Start Page = http://us.yhs4.search.yahoo.com/web/partne…729,16897,0,5,0
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultName = Google
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultURL = http://www.google.com/search?q={searchTerm…tf8&oe=utf8
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
IE - HKCU\..\SearchScopes,Backup.Old.DefaultScope = {EA68C3CB-B327-453B-B890-39BF9951F14C}
IE - HKCU\..\SearchScopes,DefaultScope = {EA68C3CB-B327-453B-B890-39BF9951F14C}
IE - HKCU\..\SearchScopes\{105E99FF-8B9A-4492-B155-06194B9056D2}: "URL" = http://search.live.com/results.aspx?FORM=S…ferrer:source?}
IE - HKCU\..\SearchScopes\{E1213956-41C3-4FD3-8D7C-20740A2EE7B3}: "URL" = http://search.yahoo.com/search?p={searchte…0729,6900,0,5,0
IE - HKCU\..\SearchScopes\{EA68C3CB-B327-453B-B890-39BF9951F14C}: "URL" = http://www.google.com/search?q={searchTerm…;rlz=1I7GPEA_en
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" =


========== FireFox ==========

FF - HKLM\Software\MozillaPlugins\@garmin.com/GpsControl: C:\Program Files\Garmin GPS Plugin\npGarmin.dll (GARMIN Corp.)
FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files\Microsoft Silverlight\4.1.10111.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.115\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.115\npGoogleUpdate3.dll (Google Inc.)



========== Chrome ==========

CHR - homepage: http://start.funmoods.com/?f=1&a=axl&a…p;cr=2110581096
CHR - default_search_provider: Web Search (Enabled)
CHR - default_search_provider: search_url = http://start.funmoods.com/results.php?f=4&…p;cr=2110581096
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?client=chrome&hl={language}&q={searchTerms}
CHR - homepage: http://start.funmoods.com/?f=1&a=axl&a…p;cr=2110581096
CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Program Files\Google\Chrome\Application\21.0.1180.60\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Program Files\Google\Chrome\Application\21.0.1180.60\pdf.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Program Files\Google\Chrome\Application\21.0.1180.60\gcswf32.dll
CHR - plugin: Adobe Acrobat (Enabled) = C:\Program Files\Adobe\Reader 8.0\Reader\Browser\nppdf32.dll
CHR - plugin: Java Deployment Toolkit 6.0.200.2 (Enabled) = C:\Program Files\Java\jre6\bin\new_plugin\npdeployJava1.dll
CHR - plugin: Java™ Platform SE 6 U20 (Enabled) = C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin2.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin3.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin4.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin5.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin6.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin7.dll
CHR - plugin: Microsoft\u00AE DRM (Enabled) = C:\Program Files\Windows Media Player\npdrmv2.dll
CHR - plugin: Microsoft\u00AE DRM (Enabled) = C:\Program Files\Windows Media Player\npwmsdrm.dll
CHR - plugin: Windows Media Player Plug-in Dynamic Link Library (Enabled) = C:\Program Files\Windows Media Player\npdsplay.dll
CHR - plugin: Garmin Communicator Plug-In (Enabled) = C:\Program Files\Garmin GPS Plugin\npGarmin.dll
CHR - plugin: Google Earth Plugin (Enabled) = C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll
CHR - plugin: Google Updater (Enabled) = C:\Program Files\Google\Google Updater\2.4.2432.1652\npCIDetect14.dll
CHR - plugin: Google Update (Enabled) = C:\Program Files\Google\Update\1.3.21.79\npGoogleUpdate3.dll
CHR - plugin: Silverlight Plug-In (Enabled) = C:\Program Files\Microsoft Silverlight\4.0.60831.0\npctrl.dll
CHR - plugin: iTunes Application Detector (Enabled) = C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll
CHR - plugin: Windows Presentation Foundation (Enabled) = C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll
CHR - plugin: Default Plug-in (Enabled) = default_plugin
CHR - Extension: SpeedDial = C:\Documents and Settings\Don\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\cjpglkicenollcignonpgiafdgfeehoj\4.0_0\
CHR - Extension: Make this page red = C:\Documents and Settings\Don\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\dnfaglepmjgohnkcoieaijlheabmcdeo\1.2_0\

O1 HOSTS File: ([2012/08/04 14:44:54 | 000,000,098 | —- | M]) - C:\WINDOWS\system32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - No CLSID value found.
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O3 - HKLM\..\Toolbar: (no name) - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {C4069E3A-68F1-403E-B40E-20066696354B} - No CLSID value found.
O4 - HKLM..\Run: [EEventManager] C:\Program Files\epson\Creativity Suite\Event Manager\EEventManager.exe (SEIKO EPSON CORPORATION)
O4 - HKLM..\Run: [NvCplDaemon] C:\WINDOWS\System32\NvCpl.dll (NVIDIA Corporation)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe (Adobe Systems, Inc.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\hp psc 2000 Series.lnk = C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpobnz08.exe (Hewlett-Packard Co.)
O4 - Startup: C:\Documents and Settings\Don\Start Menu\Programs\Startup\HotSync Manager.LNK = C:\Program Files\Palm\HOTSYNC.EXE (Palm, Inc.)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\control panel present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O9 - Extra Button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - Reg Error: Key error. File not found
O16 - DPF: {01010E00-5E80-11D8-9E86-0007E96C65AE} http://symantec.atgnow.com/sdccommon/download/tgctlsi.cab (SupportSoft SmartIssue)
O16 - DPF: {01118F00-3E00-11D2-8470-0060089874ED} http://symantec.atgnow.com/sdccommon/download/ssrc.cab (SupportSoft RemoteControl Class)
O16 - DPF: {01119400-3E00-11D2-8470-0060089874ED} http://symantec.atgnow.com/sdccommon/download/sprtctlln.cab (SupportSoft Listener Control)
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} http://appldnld.apple.com.edgesuite.net/co…ex/qtplugin.cab (QuickTime Object)
O16 - DPF: {05CA9FB0-3E3E-4B36-BF41-0E3A5CAA8CD8} http://download.microsoft.com/download/e/7…/OGAControl.cab (Office Genuine Advantage Validation Tool)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://go.microsoft.com/fwlink/?linkid=39204 (Windows Genuine Advantage Validation Tool)
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} http://gfx2.hotmail.com/mail/w2/pr02/resources/MSNPUpld.cab (MSN Photo Upload Tool)
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} http://security.symantec.com/sscv6/SharedC…n/bin/cabsa.cab (Symantec RuFSI Utility Class)
O16 - DPF: {6A344D34-5231-452A-8A57-D064AC9B7862} https://webdl.symantec.com/activex/symdlmgr.cab (Symantec Download Manager)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} http://update.microsoft.com/microsoftupdat…b?1132454647671 (MUWebControl Class)
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} http://download.eset.com/special/eos/OnlineScanner.cab (Reg Error: Key error.)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get/flash…r/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} http://v4.windowsupdate.microsoft.com/CAB/…8015.5386805556 (Reg Error: Key error.)
O16 - DPF: {B020B534-4AA2-4B99-BD6D-5F6EE286DF5C} http://a248.e.akamai.net/f/248/5462/2h/www…ol/SymDlBrg.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O16 - DPF: {FFFFFFFF-CACE-BABE-BABE-00AA0055595A} http://www.trueswitch.com/msn/TrueInstallMSN.exe (Reg Error: Key error.)
O16 - DPF: DirectAnimation Java Classes file://C:\WINDOWS\Java\classes\dajava.cab (Reg Error: Key error.)
O16 - DPF: Garmin Communicator Plug-In https://static.garmincdn.com/gcp/ie/3.0.1.0…inAxControl.CAB (Reg Error: Key error.)
O16 - DPF: Microsoft XML Parser for Java file://C:\WINDOWS\Java\classes\xmldso.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{3AC852D7-B3F4-4C96-8016-39CC10635D74}: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{810006C9-F0F5-4282-BCE8-E5926F44E330}: DhcpNameServer = [removed] [removed]
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) - C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Documents and Settings\Don\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Don\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2004/01/29 12:51:55 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O32 - AutoRun File - [2011/02/08 19:05:54 | 000,000,000 | —D | M] - H:\autorun – [ FAT32 ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = ComFile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)

========== Files/Folders - Created Within 30 Days ==========

[2012/08/04 14:44:50 | 000,000,000 | -HSD | C] – C:\RECYCLER
[2012/08/04 14:40:41 | 000,000,000 | —D | C] – C:\_OTL
[2012/08/03 20:28:12 | 000,518,144 | —- | C] (SteelWerX) – C:\WINDOWS\SWREG.exe
[2012/08/03 20:28:12 | 000,406,528 | —- | C] (SteelWerX) – C:\WINDOWS\SWSC.exe
[2012/08/03 20:28:12 | 000,212,480 | —- | C] (SteelWerX) – C:\WINDOWS\SWXCACLS.exe
[2012/08/03 20:28:12 | 000,060,416 | —- | C] (NirSoft) – C:\WINDOWS\NIRCMD.exe
[2012/08/03 20:25:22 | 004,729,092 | R— | C] (Swearware) – C:\Documents and Settings\Don\Desktop\ComboFix.exe
[2012/07/28 18:16:14 | 000,101,112 | R— | C] (GFI Software) – C:\WINDOWS\System32\drivers\SBREDrv.sys
[2012/07/28 18:16:14 | 000,042,864 | R— | C] (GFI Software) – C:\WINDOWS\System32\SBBD.EXE
[2012/07/28 18:16:05 | 000,000,000 | —D | C] – C:\Program Files\STOPzilla!
[2012/07/21 19:40:23 | 000,000,000 | —D | C] – C:\zamzar
[2012/07/21 19:17:50 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Tarma Installer
[2012/07/21 19:16:36 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\PC Optimizer Pro
[2012/07/21 19:08:35 | 000,000,000 | —D | C] – C:\Documents and Settings\Don\Local Settings\Application Data\visi_coupon
[2012/07/21 19:07:35 | 000,000,000 | —D | C] – C:\Documents and Settings\Don\AbiSuite
[2012/07/21 19:06:40 | 000,000,000 | —D | C] – C:\extensions
[2012/07/21 19:06:38 | 000,000,000 | —D | C] – C:\Program Files\Qwiklinx
[2012/07/21 19:06:38 | 000,000,000 | —D | C] – C:\Documents and Settings\Don\Application Data\Qwiklinx
[2012/07/21 19:06:33 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\PC Optimizer Pro
[2012/07/21 19:06:29 | 000,000,000 | —D | C] – C:\Program Files\PC Optimizer Pro
[2012/07/21 19:05:49 | 000,000,000 | —D | C] – C:\Program Files\Yahoo!

========== Files - Modified Within 30 Days ==========

[2012/08/05 21:00:00 | 000,000,422 | -H– | M] () – C:\WINDOWS\tasks\User_Feed_Synchronization-{3164E000-95DA-4E16-A4B2-D13B5FE2D76C}.job
[2012/08/05 20:54:12 | 000,000,882 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2012/08/05 20:54:07 | 000,012,652 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2012/08/05 20:54:03 | 000,000,406 | —- | M] () – C:\WINDOWS\tasks\PC Optimizer Pro startups.job
[2012/08/05 20:53:21 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2012/08/05 20:32:00 | 000,000,830 | —- | M] () – C:\WINDOWS\tasks\Adobe Flash Player Updater.job
[2012/08/05 20:08:00 | 000,000,886 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2012/08/05 19:06:00 | 000,000,434 | —- | M] () – C:\WINDOWS\tasks\PC Optimizer Pro Updates.job
[2012/08/05 15:32:59 | 000,426,184 | —- | M] (Adobe Systems Incorporated) – C:\WINDOWS\System32\FlashPlayerApp.exe
[2012/08/05 15:32:59 | 000,070,344 | —- | M] (Adobe Systems Incorporated) – C:\WINDOWS\System32\FlashPlayerCPLApp.cpl
[2012/08/05 15:32:56 | 009,231,560 | —- | M] (Adobe Systems Incorporated) – C:\WINDOWS\System32\FlashPlayerInstaller.exe
[2012/08/04 14:44:54 | 000,000,098 | —- | M] () – C:\WINDOWS\System32\drivers\etc\Hosts
[2012/08/03 20:25:22 | 004,729,092 | R— | M] (Swearware) – C:\Documents and Settings\Don\Desktop\ComboFix.exe
[2012/08/01 23:27:07 | 000,001,813 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Google Chrome.lnk
[2012/08/01 23:27:06 | 000,001,825 | —- | M] () – C:\Documents and Settings\Don\Desktop\Google Chrome.lnk
[2012/08/01 18:04:52 | 000,302,592 | —- | M] () – C:\Documents and Settings\Don\Desktop\gmer.exe
[2012/08/01 17:58:14 | 000,006,087 | —- | M] () – C:\Documents and Settings\Don\Desktop\fix.bat
[2012/07/29 08:58:27 | 000,000,912 | —- | M] () – C:\WINDOWS\System32\drivers\kgpcpy.cfg
[2012/07/26 22:19:55 | 000,000,664 | —- | M] () – C:\WINDOWS\System32\d3d9caps.dat
[2012/07/21 19:06:43 | 000,001,613 | —- | M] () – C:\Documents and Settings\Don\Desktop\Free Music Downloads.lnk
[2012/07/21 19:06:35 | 000,000,786 | —- | M] () – C:\Documents and Settings\Don\Application Data\Microsoft\Internet Explorer\Quick Launch\PC Optimizer Pro.lnk
[2012/07/21 19:06:35 | 000,000,768 | —- | M] () – C:\Documents and Settings\All Users\Desktop\PC Optimizer Pro.lnk
[2012/07/21 17:48:03 | 000,000,488 | —- | M] () – C:\hpfr5550.xml

========== Files Created - No Company Name ==========

[2012/08/03 20:28:12 | 000,256,000 | —- | C] () – C:\WINDOWS\PEV.exe
[2012/08/03 20:28:12 | 000,208,896 | —- | C] () – C:\WINDOWS\MBR.exe
[2012/08/03 20:28:12 | 000,098,816 | —- | C] () – C:\WINDOWS\sed.exe
[2012/08/03 20:28:12 | 000,080,412 | —- | C] () – C:\WINDOWS\grep.exe
[2012/08/03 20:28:12 | 000,068,096 | —- | C] () – C:\WINDOWS\zip.exe
[2012/08/01 18:05:13 | 000,302,592 | —- | C] () – C:\Documents and Settings\Don\Desktop\gmer.exe
[2012/08/01 17:58:14 | 000,006,087 | —- | C] () – C:\Documents and Settings\Don\Desktop\fix.bat
[2012/07/29 08:57:19 | 000,000,912 | —- | C] () – C:\WINDOWS\System32\drivers\kgpcpy.cfg
[2012/07/21 19:16:37 | 000,000,434 | —- | C] () – C:\WINDOWS\tasks\PC Optimizer Pro Updates.job
[2012/07/21 19:16:36 | 000,000,406 | —- | C] () – C:\WINDOWS\tasks\PC Optimizer Pro startups.job
[2012/07/21 19:06:43 | 000,001,613 | —- | C] () – C:\Documents and Settings\Don\Desktop\Free Music Downloads.lnk
[2012/07/21 19:06:35 | 000,000,786 | —- | C] () – C:\Documents and Settings\Don\Application Data\Microsoft\Internet Explorer\Quick Launch\PC Optimizer Pro.lnk
[2012/07/21 19:06:35 | 000,000,768 | —- | C] () – C:\Documents and Settings\All Users\Desktop\PC Optimizer Pro.lnk
[2011/06/26 22:06:35 | 000,002,528 | —- | C] () – C:\Documents and Settings\Don\Application Data\$_hpcst$.hpc
[2011/06/06 16:18:06 | 000,000,121 | —- | C] () – C:\Documents and Settings\Don\mobac-profile.xml
[2010/12/31 15:48:51 | 000,001,793 | —- | C] () – C:\WINDOWS\System32\fxsperf.ini
[2010/03/14 21:48:11 | 004,727,808 | —- | C] () – C:\Program Files\Works632_en-US.msi
[2008/03/05 21:05:54 | 000,000,032 | —- | C] () – C:\Documents and Settings\All Users\Application Data\ezsid.dat
[2007/12/31 18:15:25 | 000,000,305 | —- | C] () – C:\Documents and Settings\All Users\Application Data\addr_file.html
[2007/09/13 22:34:32 | 000,000,126 | —- | C] () – C:\Documents and Settings\Don\Local Settings\Application Data\fusioncache.dat
[2004/12/14 22:38:32 | 000,000,000 | -H– | C] () – C:\Documents and Settings\Don\hpothb07.tif
[2004/12/14 22:38:32 | 000,000,000 | -H– | C] () – C:\Documents and Settings\Don\hpothb07.dat
[2004/02/25 19:57:32 | 000,097,280 | —- | C] () – C:\Documents and Settings\Don\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2004/02/04 20:34:34 | 000,063,730 | —- | C] () – C:\Program Files\viewsonicinstruct_xp.pdf

< End of report >



Malwarebytes Anti-Malware 1.62.0.1300
www.malwarebytes.org

Database version: v2012.08.06.13

Windows XP Service Pack 2 x86 NTFS
Internet Explorer 7.0.5730.11
Don :: UPSTAIRSDESKTOP [administrator]

8/6/2012 8:42:12 PM
mbam-log-2012-08-06 (20-42-12).txt

Scan type: Quick scan
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
Scan options disabled: P2P
Objects scanned: 218094
Time elapsed: 5 minute(s), 17 second(s)

Memory Processes Detected: 0
(No malicious items detected)

Memory Modules Detected: 0
(No malicious items detected)

Registry Keys Detected: 0
(No malicious items detected)

Registry Values Detected: 0
(No malicious items detected)

Registry Data Items Detected: 0
(No malicious items detected)

Folders Detected: 0
(No malicious items detected)

Files Detected: 0
(No malicious items detected)

(end)
I found the log afterall, it was still on the desktop. I did this after running it again to reproduce it. Both logs are below, the first one run before MBAM and the second one after. C:\Documents and Settings\All Users\Application Data\Tarma Installer\{DE3B7BF9-0770-4104-BC0B-B1CCCCE2F053}\_Setupx.dll a variant of Win32/Adware.Yontoo.B application C:\Documents and Settings\All Users\Application Data\Tarma Installer\{DE3B7BF9-0770-4104-BC0B-B1CCCCE2F053}\_Setupx.dll a variant of Win32/Adware.Yontoo.B application

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI