This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Possibly infected [Solved]

35 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I ran a McAfee scan and here are the results: Viruses: 0 Trojans: 5 Rootkits: 0 Tracking Cookies: 14 Buffer Overflows: 0 Potentially Unwanted Programs: 0
Hi,

I have been looking over your malware logs and nothing malware related is just jumping out at me.

I would suggest that you start a new topic here. The techs there are fantastic and you will certainly be in good hands. Please be sure to post a link in your new topic to the topic here so that they can see what we have done. If they don't find anything we can keep digging. If they are able to fix up your internet problem come back when complete and we will remove our tools. :)
So I should not be alarmed that it found 5 Trojans? I think I will return his computer to his house before posting to the Networking techs, so the connection issue can be resolved at his house. If you would send me the directions, I should probably remove your tools before returning his computer.
Hi, Did it produce a log that showed what the trojans were? If so please post that so we can take a look and know the actual location. They are probably already quarantined.
OK, this is what I found under History and Logs. Threats Detected: Downloader-BCS!m (Trojan) found on 8/18/2012 Quarantined File: C:/Documents and Settings/Compaq_Owner/ApplicationData/Sun/Java/Deployment/cache/6.0/3e90c6dc-5431097 Also, under Incoming Events there are several things that are listed. All with a Host: dfw06s16-in-f16. 1e100net (with the number after the f changing) One of these says Rasmin Trojan. Another says BBN IAD. Another ABBS. Another nimreg. The others TCP port (with different numbers.)
Hi,

Please download the following programmes to your desktop:

Dr Web Live CD

ImgBurn

Install IMGBurn
  • Double click Dr Web
  • IMGBurn will open
  • Burn the ISO to a cd
  • Reboot the infected computer with the CD in the drive
  • Ensure that the first boot device is CD - If you are not sure about that then see this page for instructions
  • As loading starts, a dialogue window will prompt you to choose between the standard and safe modes.

    [external image: Posted Image]
  • Use arrow keys to select DrWeb-LiveCD (Default)
  • When the system is loaded, check the disks or folders you want to scan, and click on “Start”.

    [external image: Posted Image]
  • The programme will now scan for and cure/delete any malware that it finds. Allow it to do so
  • Once completed reboot to normal windows
  • No log is produced so once in normal windows run a fresh OTL scan and let me know if the problems persist
I downloaded the IMG Burn and the drweb on my dad's computer in safe mode. I installed the IMG Burn and then double clicked, but nothing happened. So I restarted in normal mode and double clicked and a window opened with: Sonic RecordNow! The feature you are trying to use is on a network resource that is unavailable. Click OK to try again or enter an alternate path to a folder containing the installation package 'RNENU.msi in the box below. Suggestions? Do I need to burn this on my computer instead of my dad's?
OTL logfile created on: 9/4/2012 8:17:32 AM - Run 2
OTL by OldTimer - Version 3.2.59.1 Folder = C:\Documents and Settings\Compaq_Owner\Desktop
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.11)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

959.48 Mb Total Physical Memory | 421.35 Mb Available Physical Memory | 43.91% Memory free
1.51 Gb Paging File | 1.01 Gb Available in Paging File | 66.60% Paging File free
Paging file location(s): C:\pagefile.sys 672 1344 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 111.81 Gb Total Space | 89.50 Gb Free Space | 80.05% Space Free | Partition Type: NTFS

Computer Name: YOUR-22CA86D5C4 | User Name: Compaq_Owner | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - [2012/08/31 17:15:05 | 000,598,528 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Compaq_Owner\Desktop\OTL.exe
PRC - [2012/08/31 09:12:23 | 000,161,768 | —- | M] (Oracle Corporation) – C:\Program Files\Java\jre7\bin\jqs.exe
PRC - [2012/07/03 13:46:44 | 000,655,944 | —- | M] (Malwarebytes Corporation) – C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
PRC - [2012/07/03 13:46:44 | 000,462,920 | —- | M] (Malwarebytes Corporation) – C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe
PRC - [2012/03/21 21:16:10 | 001,318,816 | —- | M] (McAfee, Inc.) – C:\Program Files\McAfee.com\Agent\mcagent.exe
PRC - [2012/03/20 13:11:32 | 000,151,880 | —- | M] (McAfee, Inc.) – C:\WINDOWS\system32\mfevtps.exe
PRC - [2012/03/20 13:05:00 | 000,161,632 | —- | M] (McAfee, Inc.) – C:\Program Files\Common Files\McAfee\SystemCore\mfefire.exe
PRC - [2012/03/20 13:04:32 | 000,166,288 | —- | M] (McAfee, Inc.) – C:\Program Files\Common Files\McAfee\SystemCore\mcshield.exe
PRC - [2012/01/13 11:21:10 | 000,095,200 | —- | M] (McAfee, Inc.) – C:\Program Files\McAfee\SiteAdvisor\McSACore.exe
PRC - [2011/01/27 19:28:14 | 000,214,904 | —- | M] (McAfee, Inc.) – C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe
PRC - [2010/01/15 07:49:20 | 000,255,536 | —- | M] (McAfee, Inc.) – C:\Program Files\McAfee Security Scan\2.0.181\SSScheduler.exe
PRC - [2009/08/19 10:23:24 | 007,418,368 | —- | M] (OpenOffice.org) – C:\Program Files\OpenOffice.org 3\program\soffice.bin
PRC - [2009/08/19 10:23:22 | 007,424,000 | —- | M] (OpenOffice.org) – C:\Program Files\OpenOffice.org 3\program\soffice.exe
PRC - [2008/04/13 19:12:19 | 001,033,728 | —- | M] (Microsoft Corporation) – C:\WINDOWS\explorer.exe
PRC - [2005/08/24 07:51:18 | 000,442,455 | —- | M] (Motive, Inc.) – C:\Program Files\SBC Self Support Tool\SmartBridge\MotiveSB.exe
PRC - [2004/09/15 03:52:53 | 000,393,216 | —- | M] (2Wire, Inc.) – C:\Program Files\2Wire\2PortalMon.exe
PRC - [2004/01/16 12:33:44 | 000,049,152 | —- | M] (S3 Graphics, Inc.) – C:\WINDOWS\system32\VTTimer.exe
PRC - [2003/10/10 09:06:10 | 000,192,512 | —- | M] () – C:\Program Files\SBC Self Support Tool\bin\mpbtn.exe


========== Modules (No Company Name) ==========

MOD - [2012/06/13 18:18:22 | 000,843,776 | —- | M] () – c:\windows\assembly\nativeimages1_v1.1.4322\system.drawing\1.0.5000.0__b03f5f7f11d50a3a_8c537cd8\system.drawing.dll
MOD - [2012/06/13 18:18:08 | 003,035,136 | —- | M] () – c:\windows\assembly\nativeimages1_v1.1.4322\system.windows.forms\1.0.5000.0__b77a5c561934e089_e6b9822c\system.windows.forms.dll
MOD - [2012/06/13 18:17:42 | 000,471,040 | —- | M] () – c:\windows\assembly\gac\system.drawing\1.0.5000.0__b03f5f7f11d50a3a\system.drawing.dll
MOD - [2012/01/11 14:04:42 | 003,391,488 | —- | M] () – c:\windows\assembly\nativeimages1_v1.1.4322\mscorlib\1.0.5000.0__b77a5c561934e089_aabe377f\mscorlib.dll
MOD - [2012/01/11 14:04:25 | 002,088,960 | —- | M] () – c:\windows\assembly\nativeimages1_v1.1.4322\system.xml\1.0.5000.0__b77a5c561934e089_801b485d\system.xml.dll
MOD - [2012/01/11 14:04:03 | 001,966,080 | —- | M] () – c:\windows\assembly\nativeimages1_v1.1.4322\system\1.0.5000.0__b77a5c561934e089_7a2d994d\system.dll
MOD - [2012/01/11 14:03:49 | 001,232,896 | —- | M] () – c:\windows\assembly\gac\system\1.0.5000.0__b77a5c561934e089\system.dll
MOD - [2012/01/11 14:03:46 | 002,064,384 | —- | M] () – c:\windows\assembly\gac\system.windows.forms\1.0.5000.0__b77a5c561934e089\system.windows.forms.dll
MOD - [2009/08/18 15:54:22 | 000,970,752 | —- | M] () – C:\Program Files\OpenOffice.org 3\program\libxml2.dll
MOD - [2008/09/30 14:05:22 | 000,071,696 | —- | M] () – c:\Program Files\McAfee\SiteAdvisor\mcfrmwk.dll
MOD - [2008/09/30 14:05:18 | 000,207,376 | —- | M] () – c:\Program Files\McAfee\SiteAdvisor\cntscan.dll
MOD - [2008/09/30 14:05:16 | 000,117,264 | —- | M] () – c:\Program Files\McAfee\SiteAdvisor\apengine.dll
MOD - [2006/11/28 18:16:32 | 001,339,392 | —- | M] () – c:\windows\assembly\gac\system.xml\1.0.5000.0__b77a5c561934e089\system.xml.dll
MOD - [2005/05/05 18:11:14 | 000,032,768 | —- | M] () – c:\windows\assembly\gac\hpqcprsc\3.0.0.0__a53cf5803f4c3827\hpqcprsc.dll
MOD - [2005/05/05 18:11:14 | 000,006,656 | —- | M] () – c:\windows\assembly\gac\hpqcprsc.resources\3.0.0.0_en_a53cf5803f4c3827\hpqcprsc.resources.dll
MOD - [2005/05/05 18:11:10 | 000,614,400 | —- | M] () – c:\windows\assembly\gac\hpqietpz\3.0.0.0__a53cf5803f4c3827\hpqietpz.dll
MOD - [2005/05/05 18:10:52 | 000,032,768 | —- | M] () – c:\windows\assembly\gac\hpqisrtb\4.0.0.0__a53cf5803f4c3827\hpqisrtb.dll
MOD - [2005/05/05 18:10:34 | 000,430,080 | —- | M] () – c:\windows\assembly\gac\lead.wrapper\13.0.0.66__9cf889f53ea9b907\lead.wrapper.dll
MOD - [2005/05/05 18:10:34 | 000,081,920 | —- | M] () – c:\windows\assembly\gac\lead.drawing\13.0.0.66__9cf889f53ea9b907\lead.drawing.dll
MOD - [2005/05/05 18:10:34 | 000,081,920 | —- | M] () – c:\windows\assembly\gac\lead\13.0.0.66__9cf889f53ea9b907\lead.dll
MOD - [2005/05/05 18:10:34 | 000,045,056 | —- | M] () – c:\windows\assembly\gac\hpqthumb\3.0.0.0__a53cf5803f4c3827\hpqthumb.dll
MOD - [2005/05/05 18:10:34 | 000,036,864 | —- | M] () – c:\windows\assembly\gac\lead.windows.forms\13.0.0.66__9cf889f53ea9b907\lead.windows.forms.dll
MOD - [2005/05/05 18:10:34 | 000,010,240 | —- | M] () – c:\windows\assembly\gac\interop.hpqimgr\1.0.0.0__a53cf5803f4c3827\interop.hpqimgr.dll
MOD - [2005/05/05 18:10:33 | 000,368,640 | —- | M] () – c:\windows\assembly\gac\hpqtray\3.0.0.0__a53cf5803f4c3827\hpqtray.dll
MOD - [2005/05/05 18:10:33 | 000,249,856 | —- | M] () – c:\windows\assembly\gac\hpqtray.resources\3.0.0.0_en_a53cf5803f4c3827\hpqtray.resources.dll
MOD - [2005/05/05 18:10:33 | 000,163,840 | —- | M] () – c:\windows\assembly\gac\hpqimgrc\3.0.0.0__a53cf5803f4c3827\hpqimgrc.dll
MOD - [2005/05/05 18:10:33 | 000,151,552 | —- | M] () – c:\windows\assembly\gac\hpqgldlg\3.0.0.0__a53cf5803f4c3827\hpqgldlg.dll
MOD - [2005/05/05 18:10:33 | 000,028,672 | —- | M] () – c:\windows\assembly\gac\hpqfmrsc\3.0.0.0__a53cf5803f4c3827\hpqfmrsc.dll
MOD - [2005/05/05 18:10:33 | 000,024,576 | —- | M] () – c:\windows\assembly\gac\hpqasset\3.0.0.0__a53cf5803f4c3827\hpqasset.dll
MOD - [2005/05/05 18:10:33 | 000,016,384 | —- | M] () – c:\windows\assembly\gac\hpqiface\3.0.0.0__a53cf5803f4c3827\hpqiface.dll
MOD - [2005/05/05 18:10:33 | 000,007,168 | —- | M] () – c:\windows\assembly\gac\hpqfmrsc.resources\3.0.0.0_en_a53cf5803f4c3827\hpqfmrsc.resources.dll
MOD - [2005/05/05 18:09:37 | 000,192,512 | —- | M] () – c:\windows\assembly\gac\hpqccrsc\3.0.0.0__a53cf5803f4c3827\hpqccrsc.dll
MOD - [2005/05/05 18:09:37 | 000,151,552 | —- | M] () – c:\windows\assembly\gac\hpqutils\3.0.0.0__a53cf5803f4c3827\hpqutils.dll
MOD - [2005/05/05 18:09:37 | 000,077,824 | —- | M] () – c:\windows\assembly\gac\hpqgskin\3.0.0.0__a53cf5803f4c3827\hpqgskin.dll
MOD - [2005/05/05 18:09:37 | 000,036,864 | —- | M] () – c:\windows\assembly\gac\interop.hpqcxm08\3.0.0.0__a53cf5803f4c3827\interop.hpqcxm08.dll
MOD - [2005/05/05 18:09:37 | 000,016,384 | —- | M] () – c:\windows\assembly\gac\hpqptfnd\3.0.0.0__a53cf5803f4c3827\hpqptfnd.dll
MOD - [2005/05/05 18:09:36 | 000,557,056 | —- | M] () – c:\windows\assembly\gac\hpqcmctl\3.0.0.0__a53cf5803f4c3827\hpqcmctl.dll
MOD - [2004/08/09 01:08:28 | 000,007,680 | —- | M] () – c:\windows\assembly\gac\accessibility\1.0.5000.0__b03f5f7f11d50a3a\accessibility.dll
MOD - [2003/10/10 09:06:12 | 000,057,344 | —- | M] () – C:\Program Files\SBC Self Support Tool\bin\AsstCatalog.dll
MOD - [2003/10/10 09:06:10 | 000,192,512 | —- | M] () – C:\Program Files\SBC Self Support Tool\bin\mpbtn.exe


========== Services (SafeList) ==========

SRV - File not found [On_Demand | Stopped] – %SystemRoot%\System32\appmgmts.dll – (AppMgmt)
SRV - File not found [Auto | Stopped] – C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\001542~1.EXE – (0015421346290574mcinstcleanup)
SRV - [2012/09/01 17:52:05 | 000,114,144 | —- | M] (Mozilla Foundation) [On_Demand | Stopped] – C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe – (MozillaMaintenance)
SRV - [2012/08/31 09:12:23 | 000,161,768 | —- | M] (Oracle Corporation) [Auto | Running] – C:\Program Files\Java\jre7\bin\jqs.exe – (JavaQuickStarterService)
SRV - [2012/08/23 11:55:10 | 000,362,008 | —- | M] (McAfee, Inc.) [On_Demand | Stopped] – C:\Program Files\McAfee\VirusScan\mcods.exe – (McODS)
SRV - [2012/08/17 15:43:40 | 000,250,056 | —- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] – C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe – (AdobeFlashPlayerUpdateSvc)
SRV - [2012/07/03 13:46:44 | 000,655,944 | —- | M] (Malwarebytes Corporation) [Auto | Running] – C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe – (MBAMService)
SRV - [2012/03/20 13:11:32 | 000,151,880 | —- | M] (McAfee, Inc.) [Auto | Running] – C:\WINDOWS\system32\mfevtps.exe – (mfevtp)
SRV - [2012/03/20 13:05:00 | 000,161,632 | —- | M] () [Auto | Running] – C:\Program Files\Common Files\McAfee\SystemCore\\mfefire.exe – (mfefire)
SRV - [2012/03/20 13:04:32 | 000,166,288 | —- | M] () [Auto | Running] – C:\Program Files\Common Files\McAfee\SystemCore\\mcshield.exe – (McShield)
SRV - [2012/01/13 11:21:10 | 000,095,200 | —- | M] (McAfee, Inc.) [Auto | Running] – C:\Program Files\McAfee\SiteAdvisor\McSACore.exe – (McAfee SiteAdvisor Service)
SRV - [2011/01/27 19:28:14 | 000,214,904 | —- | M] (McAfee, Inc.) [Auto | Running] – C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe – (McProxy)
SRV - [2011/01/27 19:28:14 | 000,214,904 | —- | M] (McAfee, Inc.) [Auto | Running] – C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe – (McNASvc)
SRV - [2011/01/27 19:28:14 | 000,214,904 | —- | M] (McAfee, Inc.) [Auto | Running] – C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe – (McNaiAnn)
SRV - [2011/01/27 19:28:14 | 000,214,904 | —- | M] (McAfee, Inc.) [Auto | Running] – C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe – (mcmscsvc)
SRV - [2011/01/27 19:28:14 | 000,214,904 | —- | M] (McAfee, Inc.) [Auto | Running] – C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe – (McMPFSvc)
SRV - [2010/01/15 07:49:20 | 000,227,232 | —- | M] (McAfee, Inc.) [On_Demand | Stopped] – C:\Program Files\McAfee Security Scan\2.0.181\McCHSvc.exe – (McComponentHostService)
SRV - [2007/08/09 02:27:52 | 000,073,728 | —- | M] (HP) [Auto | Stopped] – C:\WINDOWS\system32\HPZipm12.exe – (Pml Driver HPZ12)


========== Driver Services (SafeList) ==========

DRV - File not found [Kernel | On_Demand | Stopped] – – (WDICA)
DRV - File not found [Kernel | On_Demand | Stopped] – – (PDRFRAME)
DRV - File not found [Kernel | On_Demand | Stopped] – – (PDRELI)
DRV - File not found [Kernel | On_Demand | Stopped] – – (PDFRAME)
DRV - File not found [Kernel | On_Demand | Stopped] – – (PDCOMP)
DRV - File not found [Kernel | System | Stopped] – – (PCIDump)
DRV - File not found [Kernel | On_Demand | Unknown] – – (mfeavfk01)
DRV - File not found [Kernel | System | Stopped] – – (lbrtfdc)
DRV - File not found [Kernel | On_Demand | Stopped] – C:\Program Files\Lavasoft\Ad-Aware\KernExplorer.sys – (Lavasoft Kernexplorer)
DRV - File not found [Kernel | Boot | Unknown] – – (IPVNMon)
DRV - File not found [Kernel | System | Stopped] – – (i2omgmt)
DRV - File not found [Kernel | System | Stopped] – – (Changer)
DRV - File not found [Kernel | On_Demand | Stopped] – C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\catchme.sys – (catchme)
DRV - File not found [Kernel | On_Demand | Stopped] – – (71777363)
DRV - [2012/07/03 13:46:44 | 000,022,344 | —- | M] (Malwarebytes Corporation) [File_System | On_Demand | Running] – C:\WINDOWS\system32\drivers\mbam.sys – (MBAMProtector)
DRV - [2012/02/22 13:29:46 | 000,464,304 | —- | M] (McAfee, Inc.) [Kernel | Boot | Running] – C:\WINDOWS\system32\drivers\mfehidk.sys – (mfehidk)
DRV - [2012/02/22 13:29:46 | 000,340,920 | —- | M] (McAfee, Inc.) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\mfefirek.sys – (mfefirek)
DRV - [2012/02/22 13:29:46 | 000,180,848 | —- | M] (McAfee, Inc.) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\mfeavfk.sys – (mfeavfk)
DRV - [2012/02/22 13:29:46 | 000,121,544 | —- | M] (McAfee, Inc.) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\mfeapfk.sys – (mfeapfk)
DRV - [2012/02/22 13:29:46 | 000,089,792 | —- | M] (McAfee, Inc.) [Kernel | System | Running] – C:\WINDOWS\system32\drivers\mfetdi2k.sys – (mfetdi2k)
DRV - [2012/02/22 13:29:46 | 000,087,656 | —- | M] (McAfee, Inc.) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\mferkdet.sys – (mferkdet)
DRV - [2012/02/22 13:29:46 | 000,083,856 | —- | M] (McAfee, Inc.) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\mfendisk.sys – (mfendiskmp)
DRV - [2012/02/22 13:29:46 | 000,083,856 | —- | M] (McAfee, Inc.) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\mfendisk.sys – (mfendisk)
DRV - [2012/02/22 13:29:46 | 000,059,456 | —- | M] (McAfee, Inc.) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\mfebopk.sys – (mfebopk)
DRV - [2012/02/22 13:29:46 | 000,057,600 | —- | M] (McAfee, Inc.) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\cfwids.sys – (cfwids)
DRV - [2010/08/12 07:15:20 | 000,064,288 | —- | M] (Lavasoft AB) [File_System | Boot | Running] – C:\WINDOWS\system32\drivers\Lbd.sys – (Lbd)
DRV - [2006/11/28 14:53:53 | 000,028,672 | —- | M] () [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\CO_Mon.sys – (CO_Mon)
DRV - [2005/12/12 17:27:00 | 000,019,072 | —- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\PS2.sys – (Ps2)
DRV - [2005/03/04 12:02:20 | 001,066,278 | —- | M] (Agere Systems) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\AGRSM.sys – (AgereSoftModem)
DRV - [2004/10/01 11:24:02 | 002,279,424 | —- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\ALCXWDM.SYS – (ALCXWDM)
DRV - [2004/09/15 03:42:14 | 000,068,672 | R— | M] (2Wire, Inc.) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\2WirePCP.sys – (2WIREPCP)
DRV - [2004/08/04 00:31:34 | 000,020,992 | —- | M] (Realtek Semiconductor Corporation) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\RTL8139.sys – (rtl8139)
DRV - [2004/04/13 20:20:08 | 000,015,781 | R— | M] (Meetinghouse Data Communications) [Kernel | Auto | Running] – C:\WINDOWS\system32\drivers\mdc8021x.sys – (MDC8021X)
DRV - [2004/02/09 13:06:22 | 000,015,360 | —- | M] (Motorola Inc.) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\NetMotCM.sys – (ndiscm)
DRV - [2003/12/11 17:54:14 | 000,391,424 | —- | M] (Sensaura Ltd) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\ALCXSENS.SYS – (ALCXSENS)
DRV - [2003/07/03 03:42:00 | 000,027,904 | —- | M] (VIA Technologies, Inc.) [Kernel | Boot | Running] – C:\WINDOWS\system32\drivers\VIAAGP1.SYS – (viaagp1)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://att.yahoo.com
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomSearch =
IE - HKLM\..\SearchScopes,DefaultScope = {6A1806CD-94D4-4689-BA73-E35EA1EA9990}
IE - HKLM\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.com/search?q={searchTerm…mp;sourceid=ie7


IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = 127.0.0.1

IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = 127.0.0.1



IE - HKU\S-1-5-21-2357082363-25780252-2909908178-1009\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = http://www.yahoo.com/search/ie.html
IE - HKU\S-1-5-21-2357082363-25780252-2909908178-1009\SOFTWARE\Microsoft\Internet Explorer\Main,SEARCH PAGE =
IE - HKU\S-1-5-21-2357082363-25780252-2909908178-1009\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultName = Yahoo! Search
IE - HKU\S-1-5-21-2357082363-25780252-2909908178-1009\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultURL = http://search.yahoo.com/search?p={searchTe…-8&fr;=b1ie7
IE - HKU\S-1-5-21-2357082363-25780252-2909908178-1009\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://att.yahoo.com
IE - HKU\S-1-5-21-2357082363-25780252-2909908178-1009\..\URLSearchHook: {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
IE - HKU\S-1-5-21-2357082363-25780252-2909908178-1009\..\URLSearchHook: {EF99BD32-C1FB-11D2-892F-0090271D4F88} - No CLSID value found
IE - HKU\S-1-5-21-2357082363-25780252-2909908178-1009\..\SearchScopes,DefaultScope = {6A1806CD-94D4-4689-BA73-E35EA1EA9990}
IE - HKU\S-1-5-21-2357082363-25780252-2909908178-1009\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.com/search?q={searchTerm…;rlz=1I7GGLL_en
IE - HKU\S-1-5-21-2357082363-25780252-2909908178-1009\..\SearchScopes\{9A1DCB73-4F92-446F-B9F2-2B458DAAD40D}: "URL" = http://search.yahoo.com/search?p={searchTe…-8&fr;=b1ie7
IE - HKU\S-1-5-21-2357082363-25780252-2909908178-1009\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-2357082363-25780252-2909908178-1009\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = 127.0.0.1

========== FireFox ==========

FF - prefs.js..browser.search.selectedEngine: "Bing"
FF - prefs.js..browser.startup.homepage: "http://att.my.yahoo.com/"
FF - prefs.js..extensions.enabledItems: [removed]:1.0
FF - prefs.js..extensions.enabledItems: {B7082FAA-CB62-4872-9106-E42DD88EDE45}:3.3.1
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}:6.0.21
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}:6.0.23
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}:6.0.24


FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32_11_3_300_271.dll ()
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.7.2: C:\WINDOWS\system32\npDeployJava1.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.7.2: C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@mcafee.com/MSC,version=10: c:\progra~1\mcafee\msc\npmcsn~1.dll ()
FF - HKLM\Software\MozillaPlugins\@mcafee.com/MVT: C:\Program Files\McAfee\Supportability\MVT\npmvtplugin.dll (McAfee, Inc.)
FF - HKLM\Software\MozillaPlugins\@mcafee.com/SAFFPlugin: C:\Program Files\McAfee\SiteAdvisor\npmcffplg32.dll (McAfee, Inc.)
FF - HKLM\Software\MozillaPlugins\@sun.com/npsopluginmi;version=1.0: C:\Program Files\OpenOffice.org 3\program [2009/09/07 10:20:27 | 000,000,000 | —D | M]
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.115\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.115\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@yverinfo.yahoo.com/YahooVersionInfoPlugin;version=1.0.0.1: C:\Program Files\Yahoo!\Shared\npYVerInfo.dll File not found
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKLM\Software\MozillaPlugins\[removed]/YahooActiveXPluginBridge;version=1.0.0.1: C:\WINDOWS\cache\npyaxmpb.dll File not found

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\extensions\\{4ED1F68A-5463-4931-9384-8FFF5ED91D92}: C:\Program Files\McAfee\SiteAdvisor [2012/08/11 08:35:09 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\extensions\\{D19CA586-DD6C-4a0a-96F8-14644F340D60}: C:\Program Files\Common Files\McAfee\SystemCore [2012/09/04 08:18:34 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 15.0\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2012/09/01 17:52:08 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 15.0\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2012/08/31 09:13:11 | 000,000,000 | —D | M]

[2008/12/20 12:21:18 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Compaq_Owner\Application Data\Mozilla\Extensions
[2012/05/03 07:42:46 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Compaq_Owner\Application Data\Mozilla\Firefox\Profiles\mrook2ld.default\extensions
[2012/03/23 20:44:16 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions
[2012/09/04 08:18:34 | 000,000,000 | —D | M] (McAfee ScriptScan for Firefox) – C:\PROGRAM FILES\COMMON FILES\MCAFEE\SYSTEMCORE
[2012/08/11 08:35:09 | 000,000,000 | —D | M] (McAfee SiteAdvisor) – C:\PROGRAM FILES\MCAFEE\SITEADVISOR
[2012/09/01 17:52:08 | 000,266,720 | —- | M] (Mozilla Foundation) – C:\Program Files\mozilla firefox\components\browsercomps.dll
[2011/04/14 14:01:38 | 000,024,376 | —- | M] (McAfee, Inc.) – C:\Program Files\mozilla firefox\components\Scriptff.dll
[2011/03/18 13:32:12 | 000,091,552 | —- | M] (Coupons, Inc.) – C:\Program Files\mozilla firefox\plugins\npCouponPrinter.dll
[2011/03/18 13:32:14 | 000,091,552 | —- | M] (Coupons, Inc.) – C:\Program Files\mozilla firefox\plugins\npMozCouponPrinter.dll
[2012/09/01 17:52:01 | 000,002,253 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\twitter.xml

========== Chrome ==========

CHR - homepage: http://cm.my.yahoo.com/
CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{g
oogle:searchFieldtrialParameter}sourceid=chrome&ie;={inputEncoding}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client=chrome&hl;={language}&q;={searchTerms}
CHR - homepage: http://cm.my.yahoo.com/
CHR - plugin: Shockwave Flash (Enabled) = C:\Program Files\Google\Chrome\Application\21.0.1180.89\PepperFlash\pepflashplayer.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Program Files\Google\Chrome\Application\21.0.1180.89\gcswf32.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\WINDOWS\system32\Macromed\Flash\NPSWF32_11_3_300_271.dll
CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Program Files\Google\Chrome\Application\21.0.1180.89\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Program Files\Google\Chrome\Application\21.0.1180.89\pdf.dll
CHR - plugin: McAfee SiteAdvisor (Enabled) = C:\Documents and Settings\Compaq_Owner\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\fheoggkfdfchfphceeifdbepaooicaho\3.41.123.2_0\McChPlg.dll
CHR - plugin: McAfee SiteAdvisor (Enabled) = C:\Program Files\McAfee\SiteAdvisor\npmcffplg32.dll
CHR - plugin: Adobe Acrobat (Enabled) = C:\Program Files\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll
CHR - plugin: Coupons Inc., Coupon Printer Manager (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npCouponPrinter.dll
CHR - plugin: Coupons Inc., Coupon Printer Manager (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npMozCouponPrinter.dll
CHR - plugin: Microsoft Office 2003 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\NPOFFICE.DLL
CHR - plugin: QuickTime Plug-in 6.5.1 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin.dll
CHR - plugin: QuickTime Plug-in 6.5.1 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin2.dll
CHR - plugin: Microsoft\u00AE DRM (Enabled) = C:\Program Files\Windows Media Player\npdrmv2.dll
CHR - plugin: Microsoft\u00AE DRM (Enabled) = C:\Program Files\Windows Media Player\npwmsdrm.dll
CHR - plugin: Windows Media Player Plug-in Dynamic Link Library (Enabled) = C:\Program Files\Windows Media Player\npdsplay.dll
CHR - plugin: Google Update (Enabled) = C:\Program Files\Google\Update\1.3.21.115\npGoogleUpdate3.dll
CHR - plugin: Java™ Platform SE 7 U7 (Disabled) = C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll
CHR - plugin: Java Deployment Toolkit 7.0.70.10 (Disabled) = C:\WINDOWS\system32\npDeployJava1.dll
CHR - plugin: McAfee Virtual Technician (Enabled) = C:\Program Files\McAfee\Supportability\MVT\npmvtplugin.dll
CHR - plugin: McAfee SecurityCenter (Enabled) = c:\progra~1\mcafee\msc\npmcsn~1.dll
CHR - Extension: SiteAdvisor = C:\Documents and Settings\Compaq_Owner\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\fheoggkfdfchfphceeifdbepaooicaho\3.41.123.2_0\

O1 HOSTS File: ([2012/09/02 15:15:56 | 000,000,098 | —- | M]) - C:\WINDOWS\system32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2 - BHO: (Java™ Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
O2 - BHO: (scriptproxy) - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\Common Files\McAfee\SystemCore\ScriptSn.20120829220454.dll (McAfee, Inc.)
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.7.7529.1424\swg.dll (Google Inc.)
O2 - BHO: (McAfee SiteAdvisor BHO) - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O2 - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O3 - HKLM\..\Toolbar: (McAfee SiteAdvisor Toolbar) - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O3 - HKU\S-1-5-21-2357082363-25780252-2909908178-1009\..\Toolbar\ShellBrowser: (no name) - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - No CLSID value found.
O3 - HKU\S-1-5-21-2357082363-25780252-2909908178-1009\..\Toolbar\WebBrowser: (no name) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - No CLSID value found.
O4 - HKLM..\Run: [2wSysTray] C:\Program Files\2Wire\2PortalMon.exe (2Wire, Inc.)
O4 - HKLM..\Run: [Malwarebytes' Anti-Malware] C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
O4 - HKLM..\Run: [mcui_exe] C:\Program Files\McAfee.com\Agent\mcagent.exe (McAfee, Inc.)
O4 - HKLM..\Run: [Motive SmartBridge] C:\Program Files\SBC Self Support Tool\SmartBridge\MotiveSB.exe (Motive, Inc.)
O4 - HKLM..\Run: [Recguard] C:\WINDOWS\SMINST\Recguard.exe ()
O4 - HKLM..\Run: [VTTimer] C:\WINDOWS\System32\VTTimer.exe (S3 Graphics, Inc.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk = File not found
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\AT&T; Self Support Tool.lnk = C:\Program Files\SBC Self Support Tool\bin\matcli.exe (Motive Communications, Inc.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\HP Image Zone Fast Start.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe (Hewlett-Packard Co.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\McAfee Security Scan Plus.lnk = C:\Program Files\McAfee Security Scan\2.0.181\SSScheduler.exe (McAfee, Inc.)
O4 - Startup: C:\Documents and Settings\Compaq_Owner\Start Menu\Programs\Startup\OpenOffice.org 3.0.lnk = C:\Program Files\OpenOffice.org 3\program\quickstart.exe ()
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\WINDOWS\system32\nwprovau.dll (Microsoft Corporation)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://download.microsoft.com/download/9/b…heckControl.cab (Windows Genuine Advantage Validation Tool)
O16 - DPF: {459E93B6-150E-45D5-8D4B-45C66FC035FE} http://apps.corel.com/nos_dl_manager_dev/p…IEGetPlugin.ocx (get_atlcom Class)
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} http://www.update.microsoft.com/windowsupd…b?1346272295078 (WUWebControl Class)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} http://www.update.microsoft.com/microsoftu…b?1346524905875 (MUWebControl Class)
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} http://download.eset.com/special/eos/OnlineScanner.cab (OnlineScanner Control)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload.macromedia.com/get/flash…ent/swflash.cab (Shockwave Flash Object)
O16 - DPF: Microsoft XML Parser for Java file:///C:/WINDOWS/Java/classes/xmldso.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = [removed] [removed]
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{BEC2432F-43EB-49BD-A650-9A91D963025D}: DhcpNameServer = [removed] [removed]
O18 - Protocol\Handler\cetihpz {CF184AD3-CDCB-4168-A3F7-8E447D129300} - C:\Program Files\HP\hpcoretech\comp\hpuiprot.dll (Hewlett-Packard Company)
O18 - Protocol\Handler\dssrequest {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O18 - Protocol\Handler\sacore {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O18 - Protocol\Filter\application/x-mfe-ipt {3EF5086B-5478-4598-A054-786C45D75692} - c:\Program Files\McAfee\MSC\McSnIePl.dll (McAfee, Inc.)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) - C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Documents and Settings\Compaq_Owner\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Compaq_Owner\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2004/08/09 00:45:44 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = ComFile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)

========== Files/Folders - Created Within 30 Days ==========

[2012/09/04 08:16:37 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\McAfee
[2012/09/03 15:49:18 | 000,000,000 | —D | C] – C:\Documents and Settings\Compaq_Owner\Application Data\ImgBurn
[2012/09/03 15:46:31 | 000,000,000 | —D | C] – C:\Program Files\ImgBurn
[2012/09/03 15:33:09 | 006,118,990 | —- | C] (LIGHTNING UK!) – C:\Documents and Settings\Compaq_Owner\Desktop\SetupImgBurn_2.5.7.0.exe
[2012/09/02 15:14:45 | 000,000,000 | —D | C] – C:\_OTL
[2012/08/31 17:15:05 | 000,598,528 | —- | C] (OldTimer Tools) – C:\Documents and Settings\Compaq_Owner\Desktop\OTL.exe
[2012/08/31 13:09:40 | 000,000,000 | —D | C] – C:\Documents and Settings\Compaq_Owner\Local Settings\Application Data\Sun
[2012/08/31 09:55:04 | 000,000,000 | —D | C] – C:\Program Files\ESET
[2012/08/31 09:13:20 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Java
[2012/08/31 09:13:12 | 000,143,872 | —- | C] (Oracle Corporation) – C:\WINDOWS\System32\javacpl.cpl
[2012/08/31 09:13:11 | 000,821,736 | —- | C] (Oracle Corporation) – C:\WINDOWS\System32\npDeployJava1.dll
[2012/08/31 09:13:11 | 000,246,760 | —- | C] (Oracle Corporation) – C:\WINDOWS\System32\javaws.exe
[2012/08/31 09:13:00 | 000,174,056 | —- | C] (Oracle Corporation) – C:\WINDOWS\System32\javaw.exe
[2012/08/31 09:12:59 | 000,174,056 | —- | C] (Oracle Corporation) – C:\WINDOWS\System32\java.exe
[2012/08/31 09:11:33 | 000,000,000 | —D | C] – C:\Program Files\Java
[2012/08/31 09:06:15 | 000,000,000 | —D | C] – C:\Sun
[2012/08/31 08:44:44 | 000,000,000 | -HSD | C] – C:\RECYCLER
[2012/08/30 16:50:59 | 000,000,000 | —D | C] – C:\WINDOWS\temp
[2012/08/30 14:38:25 | 000,518,144 | —- | C] (SteelWerX) – C:\WINDOWS\SWREG.exe
[2012/08/30 14:38:25 | 000,406,528 | —- | C] (SteelWerX) – C:\WINDOWS\SWSC.exe
[2012/08/30 14:38:25 | 000,212,480 | —- | C] (SteelWerX) – C:\WINDOWS\SWXCACLS.exe
[2012/08/30 14:38:25 | 000,060,416 | —- | C] (NirSoft) – C:\WINDOWS\NIRCMD.exe
[2012/08/30 14:38:17 | 000,000,000 | —D | C] – C:\Qoobox
[2012/08/30 14:38:02 | 000,000,000 | —D | C] – C:\WINDOWS\erdnt
[2012/08/29 17:41:53 | 000,000,000 | —D | C] – C:\Documents and Settings\Compaq_Owner\Application Data\Malwarebytes
[2012/08/29 16:20:32 | 000,000,000 | —D | C] – C:\Documents and Settings\Compaq_Owner\Application Data\McAfee
[2012/08/29 14:52:26 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Google Chrome
[2012/08/29 13:58:50 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Malwarebytes' Anti-Malware
[2012/08/29 13:58:50 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Malwarebytes
[2012/08/29 13:58:49 | 000,022,344 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys
[2012/08/29 13:58:49 | 000,000,000 | —D | C] – C:\Program Files\Malwarebytes' Anti-Malware
[2012/08/27 19:29:35 | 000,000,000 | —D | C] – C:\Program Files\AVAST Software
[2012/08/27 19:29:35 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\AVAST Software
[2012/08/27 10:23:47 | 000,000,000 | —D | C] – C:\Documents and Settings\Compaq_Owner\DoctorWeb
[2006/11/24 22:30:46 | 000,218,112 | —- | C] (Soeperman Enterprises Ltd.) – C:\Program Files\HijackThis.exe

========== Files - Modified Within 30 Days ==========

[2012/09/04 08:40:13 | 000,000,886 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2012/09/04 08:13:45 | 000,001,158 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2012/09/04 08:11:14 | 000,000,882 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2012/09/04 08:11:12 | 000,000,188 | —- | M] () – C:\WINDOWS\System\hpsysdrv.DAT
[2012/09/04 08:11:07 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2012/09/04 08:11:06 | 1006,161,920 | -HS- | M] () – C:\hiberfil.sys
[2012/09/03 17:42:00 | 000,000,830 | —- | M] () – C:\WINDOWS\tasks\Adobe Flash Player Updater.job
[2012/09/03 15:46:31 | 000,001,536 | —- | M] () – C:\Documents and Settings\All Users\Desktop\ImgBurn.lnk
[2012/09/03 15:44:59 | 199,591,936 | —- | M] () – C:\Documents and Settings\Compaq_Owner\Desktop\drweb-livecd-600.iso
[2012/09/03 15:33:14 | 006,118,990 | —- | M] (LIGHTNING UK!) – C:\Documents and Settings\Compaq_Owner\Desktop\SetupImgBurn_2.5.7.0.exe
[2012/09/03 13:17:08 | 524,288,000 | —- | M] () – C:\REMOVE_THIS_FILE.livecd.swap
[2012/09/03 04:52:12 | 000,001,821 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Google Chrome.lnk
[2012/09/02 21:13:56 | 001,517,814 | —- | M] () – C:\Documents and Settings\Compaq_Owner\Desktop\McAfee Scan.bmp
[2012/09/02 15:15:56 | 000,000,098 | —- | M] () – C:\WINDOWS\System32\drivers\etc\Hosts
[2012/08/31 17:15:05 | 000,598,528 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Compaq_Owner\Desktop\OTL.exe
[2012/08/31 16:46:21 | 000,001,160 | —- | M] () – C:\WINDOWS\checkip.dat
[2012/08/31 13:09:39 | 000,000,664 | —- | M] () – C:\WINDOWS\System32\d3d9caps.dat
[2012/08/31 09:12:29 | 000,093,672 | —- | M] (Oracle Corporation) – C:\WINDOWS\System32\WindowsAccessBridge.dll
[2012/08/31 09:12:18 | 000,246,760 | —- | M] (Oracle Corporation) – C:\WINDOWS\System32\javaws.exe
[2012/08/31 09:12:18 | 000,174,056 | —- | M] (Oracle Corporation) – C:\WINDOWS\System32\javaw.exe
[2012/08/31 09:12:18 | 000,143,872 | —- | M] (Oracle Corporation) – C:\WINDOWS\System32\javacpl.cpl
[2012/08/31 09:12:17 | 000,174,056 | —- | M] (Oracle Corporation) – C:\WINDOWS\System32\java.exe
[2012/08/31 09:12:15 | 000,821,736 | —- | M] (Oracle Corporation) – C:\WINDOWS\System32\npDeployJava1.dll
[2012/08/31 09:12:15 | 000,746,984 | —- | M] (Oracle Corporation) – C:\WINDOWS\System32\deployJava1.dll
[2012/08/29 19:48:03 | 000,000,281 | RHS- | M] () – C:\boot.ini
[2012/08/29 17:39:14 | 000,008,704 | —- | M] () – C:\Documents and Settings\Compaq_Owner\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2012/08/29 16:43:29 | 000,001,821 | —- | M] () – C:\Documents and Settings\Compaq_Owner\Application Data\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk
[2012/08/29 14:58:18 | 000,001,779 | —- | M] () – C:\Documents and Settings\All Users\Desktop\McAfee Virtual Technician.lnk
[2012/08/29 13:58:50 | 000,000,792 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes Anti-Malware.lnk
[2012/08/29 12:32:59 | 000,002,577 | —- | M] () – C:\WINDOWS\System32\CONFIG.NT
[2012/08/27 13:38:06 | 000,000,000 | —- | M] () – C:\WINDOWS\System32\drivers\setup_xp.ini
[2012/08/17 16:36:27 | 000,161,936 | —- | M] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2012/08/17 15:47:10 | 000,001,374 | —- | M] () – C:\WINDOWS\imsins.BAK
[2012/08/17 15:43:36 | 000,426,184 | —- | M] (Adobe Systems Incorporated) – C:\WINDOWS\System32\FlashPlayerApp.exe
[2012/08/17 15:43:35 | 000,070,344 | —- | M] (Adobe Systems Incorporated) – C:\WINDOWS\System32\FlashPlayerCPLApp.cpl

========== Files Created - No Company Name ==========

[2012/09/03 15:54:31 | 1006,161,920 | -HS- | C] () – C:\hiberfil.sys
[2012/09/03 15:46:31 | 000,001,536 | —- | C] () – C:\Documents and Settings\All Users\Desktop\ImgBurn.lnk
[2012/09/03 15:31:36 | 199,591,936 | —- | C] () – C:\Documents and Settings\Compaq_Owner\Desktop\drweb-livecd-600.iso
[2012/09/03 13:16:18 | 524,288,000 | —- | C] () – C:\REMOVE_THIS_FILE.livecd.swap
[2012/09/02 21:13:56 | 001,517,814 | —- | C] () – C:\Documents and Settings\Compaq_Owner\Desktop\McAfee Scan.bmp
[2012/08/31 16:44:24 | 000,001,160 | —- | C] () – C:\WINDOWS\checkip.dat
[2012/08/31 07:55:18 | 000,000,664 | —- | C] () – C:\WINDOWS\System32\d3d9caps.dat
[2012/08/30 14:38:25 | 000,256,000 | —- | C] () – C:\WINDOWS\PEV.exe
[2012/08/30 14:38:25 | 000,208,896 | —- | C] () – C:\WINDOWS\MBR.exe
[2012/08/30 14:38:25 | 000,098,816 | —- | C] () – C:\WINDOWS\sed.exe
[2012/08/30 14:38:25 | 000,080,412 | —- | C] () – C:\WINDOWS\grep.exe
[2012/08/30 14:38:25 | 000,068,096 | —- | C] () – C:\WINDOWS\zip.exe
[2012/08/29 16:43:29 | 000,001,821 | —- | C] () – C:\Documents and Settings\Compaq_Owner\Application Data\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk
[2012/08/29 14:58:18 | 000,001,779 | —- | C] () – C:\Documents and Settings\All Users\Desktop\McAfee Virtual Technician.lnk
[2012/08/29 14:57:31 | 000,001,783 | —- | C] () – C:\Documents and Settings\All Users\Start Menu\Programs\McAfee Virtual Technician.lnk
[2012/08/29 14:52:28 | 000,001,821 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Google Chrome.lnk
[2012/08/29 13:58:50 | 000,000,792 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes Anti-Malware.lnk
[2012/08/27 13:38:06 | 000,000,000 | —- | C] () – C:\WINDOWS\System32\drivers\setup_xp.ini
[2012/08/21 16:47:00 | 000,001,765 | —- | C] () – C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk
[2012/08/21 16:47:00 | 000,000,872 | —- | C] () – C:\Documents and Settings\Compaq_Owner\Start Menu\Programs\Startup\OpenOffice.org 3.0.lnk
[2012/02/15 09:40:35 | 000,003,072 | —- | C] () – C:\WINDOWS\System32\iacenc.dll
[2011/04/26 13:07:03 | 000,000,064 | —- | C] () – C:\WINDOWS\System32\rp_stats.dat
[2011/04/26 13:07:03 | 000,000,044 | —- | C] () – C:\WINDOWS\System32\rp_rules.dat
[2006/11/25 22:49:11 | 000,000,000 | —- | C] () – C:\Documents and Settings\Compaq_Owner\netstat
[2005/12/25 10:51:07 | 000,008,704 | —- | C] () – C:\Documents and Settings\Compaq_Owner\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2005/01/22 17:29:19 | 000,000,135 | —- | C] () – C:\Documents and Settings\Compaq_Owner\Local Settings\Application Data\fusioncache.dat

< End of report >
I am unable to run the ESET online scan. I went into Safe Mode with Networking and opened IE, opened the ESET website and clicked on Run ESET online and nothing happens. Disregard I have it running.
C:\Program Files\Yahoo!\YPSR\updates\ypsr_dat_05.05.19.17_setup_.exe probably unknown NewHeur_PE virus cleaned by deleting - quarantined C:\Program Files\Yahoo!\YPSR\updates\ypsr_dat_05.07.21.14_setup_.exe probably unknown NewHeur_PE virus cleaned by deleting - quarantined C:\Program Files\Yahoo!\YPSR\updates\ypsr_dat_05.09.15.18_setup_.exe probably unknown NewHeur_PE virus cleaned by deleting - quarantined C:\Program Files\Yahoo!\YPSR\updates\ypsr_dat_05.10.13.17_setup_.exe probably unknown NewHeur_PE virus cleaned by deleting - quarantined C:\Program Files\Yahoo!\YPSR\updates\ypsr_dat_06.01.06.17_setup_.exe probably unknown NewHeur_PE virus cleaned by deleting - quarantined C:\Program Files\Yahoo!\YPSR\updates\ypsr_dat_06.02.21.17_setup_.exe probably unknown NewHeur_PE virus cleaned by deleting - quarantined C:\System Volume Information\_restore{A85EC1FF-58D4-4723-A09B-E5784A945816}\RP2125\A0166920.exe probably unknown NewHeur_PE virus cleaned by deleting - quarantined C:\System Volume Information\_restore{A85EC1FF-58D4-4723-A09B-E5784A945816}\RP2125\A0166921.exe probably unknown NewHeur_PE virus cleaned by deleting - quarantined C:\System Volume Information\_restore{A85EC1FF-58D4-4723-A09B-E5784A945816}\RP2125\A0166922.exe probably unknown NewHeur_PE virus cleaned by deleting - quarantined C:\System Volume Information\_restore{A85EC1FF-58D4-4723-A09B-E5784A945816}\RP2125\A0166923.exe probably unknown NewHeur_PE virus cleaned by deleting - quarantined C:\System Volume Information\_restore{A85EC1FF-58D4-4723-A09B-E5784A945816}\RP2125\A0166924.exe probably unknown NewHeur_PE virus cleaned by deleting - quarantined C:\System Volume Information\_restore{A85EC1FF-58D4-4723-A09B-E5784A945816}\RP2125\A0166925.exe probably unknown NewHeur_PE virus cleaned by deleting - quarantined
I am going to look over these logs again and get back as quickly as possible. In the meantime…

Please download Farbar Service Scanner and run it on the computer with the issue.
  • Make sure the following options are checked:
    • Internet Services
    • Windows Firewall
    • System Restore
    • Security Center
    • Windows Update
    • Windows Defender
  • Press "Scan".
  • It will create a log (FSS.txt) in the same directory the tool is run.
  • Please copy and paste the log to your reply.
———-

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI