This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Trojan.zbot [Closed]

19 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

My husband advised me that his computer had been taken over. when he turned it on, the screen turned white and a box came up saying some nonsense about a cleaning. i managed to click start, run, browse…and did a malwarebytes scan . 2 items with the name Trojan.zbot came up and were deleted.
now, i feel like i need you professionals to take a look and see if there is more work to do to clean his machine.
OTL logfile created on: 10/8/2012 8:11:40 PM - Run 2
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Documents and Settings\Owner.PETE-05CK9PEMS6\Desktop
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

638.00 Mb Total Physical Memory | 356.77 Mb Available Physical Memory | 55.92% Memory free
1.52 Gb Paging File | 1.12 Gb Available in Paging File | 73.48% Paging File free
Paging file location(s): C:\pagefile.sys 960 1920 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 37.21 Gb Total Space | 22.88 Gb Free Space | 61.49% Space Free | Partition Type: NTFS

Computer Name: PETE-05CK9PEMS6 | User Name: Owner | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Documents and Settings\Owner.PETE-05CK9PEMS6\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Norton Security Suite\Engine\6.3.0.14\ccsvchst.exe (Symantec Corporation)
PRC - C:\Program Files\IObit\Advanced SystemCare 5\ASCTray.exe (IObit)
PRC - C:\Program Files\IObit\Advanced SystemCare 5\ASCService.exe (IObit)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe (Musicmatch, Inc.)
PRC - C:\Program Files\Canon\BJCard\Bjmcmng.exe (CANON INC.)


========== Modules (No Company Name) ==========

MOD - C:\Program Files\IObit\Advanced SystemCare 5\ASCv5ExtMenu.dll ()
MOD - C:\Program Files\IObit\Advanced SystemCare 5\madexcept_.bpl ()
MOD - C:\Program Files\IObit\Advanced SystemCare 5\madbasic_.bpl ()
MOD - C:\Program Files\IObit\Advanced SystemCare 5\maddisAsm_.bpl ()
MOD - C:\Program Files\SpywareGuard\spywareguard.dll ()


========== Services (SafeList) ==========

SRV - (MBAMSwissArmy) – File not found
SRV - (Lavasoft Ad-Aware Service) – C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe File not found
SRV - (HidServ) – %SystemRoot%\System32\hidserv.dll File not found
SRV - (AppMgmt) – %SystemRoot%\System32\appmgmts.dll File not found
SRV - (N360) – C:\Program Files\Norton Security Suite\Engine\6.3.0.14\ccSvcHst.exe (Symantec Corporation)
SRV - (AdvancedSystemCareService5) – C:\Program Files\IObit\Advanced SystemCare 5\ASCService.exe (IObit)
SRV - (Bjmcmng) – C:\Program Files\Canon\BJCard\Bjmcmng.exe (CANON INC.)


========== Driver Services (SafeList) ==========

DRV - (WDICA) – File not found
DRV - (PDRFRAME) – File not found
DRV - (PDRELI) – File not found
DRV - (PDFRAME) – File not found
DRV - (PDCOMP) – File not found
DRV - (PCIDump) – File not found
DRV - (lbrtfdc) – File not found
DRV - (i2omgmt) – File not found
DRV - (Changer) – File not found
DRV - (catchme) – C:\DOCUME~1\OWNER~2.PET\LOCALS~1\Temp\catchme.sys File not found
DRV - (NAVEX15) – C:\Documents and Settings\All Users.WINDOWS\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_6.0.0.145\Definitions\VirusDefs\20121008.009\NAVEX15.SYS (Symantec Corporation)
DRV - (NAVENG) – C:\Documents and Settings\All Users.WINDOWS\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_6.0.0.145\Definitions\VirusDefs\20121008.009\NAVENG.SYS (Symantec Corporation)
DRV - (IDSxpx86) – C:\Documents and Settings\All Users.WINDOWS\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_6.0.0.145\Definitions\IPSDefs\20121005.002\IDSXpx86.sys (Symantec Corporation)
DRV - (BHDrvx86) – C:\Documents and Settings\All Users.WINDOWS\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_6.0.0.145\Definitions\BASHDefs\20120928.001\BHDrvx86.sys (Symantec Corporation)
DRV - (eeCtrl) – C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys (Symantec Corporation)
DRV - (EraserUtilRebootDrv) – C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys (Symantec Corporation)
DRV - (SRTSP) – C:\WINDOWS\system32\drivers\N360\0603000.00E\srtsp.sys (Symantec Corporation)
DRV - (SRTSPX) – C:\WINDOWS\system32\drivers\N360\0603000.00E\srtspx.sys (Symantec Corporation)
DRV - (ccSet_N360) – C:\WINDOWS\system32\drivers\N360\0603000.00E\ccsetx86.sys (Symantec Corporation)
DRV - (SymEvent) – C:\WINDOWS\system32\drivers\SYMEVENT.SYS (Symantec Corporation)
DRV - (SymEFA) – C:\WINDOWS\system32\drivers\N360\0603000.00E\symefa.sys (Symantec Corporation)
DRV - (SYMTDI) – C:\WINDOWS\system32\drivers\N360\0603000.00E\symtdi.sys (Symantec Corporation)
DRV - (SymIRON) – C:\WINDOWS\system32\drivers\N360\0603000.00E\ironx86.sys (Symantec Corporation)
DRV - (SymDS) – C:\WINDOWS\system32\drivers\N360\0603000.00E\symds.sys (Symantec Corporation)
DRV - (GIDv2) – C:\WINDOWS\System32\drivers\gidv2.sys (StrikeForce Technologies, Inc.)
DRV - (mfehidk) – C:\WINDOWS\system32\drivers\mfehidk.sys (McAfee, Inc.)
DRV - (mfeavfk) – C:\WINDOWS\system32\drivers\mfeavfk.sys (McAfee, Inc.)
DRV - (mfesmfk) – C:\WINDOWS\system32\drivers\mfesmfk.sys (McAfee, Inc.)
DRV - (mfebopk) – C:\WINDOWS\system32\drivers\mfebopk.sys (McAfee, Inc.)
DRV - (mferkdk) – C:\WINDOWS\system32\drivers\mferkdk.sys (McAfee, Inc.)
DRV - (Lbd) – C:\WINDOWS\system32\drivers\Lbd.sys (Lavasoft AB)
DRV - (LMouFlt2) – C:\WINDOWS\system32\drivers\LMouFlt2.Sys (Logitech, Inc.)
DRV - (L8042pr2) – C:\WINDOWS\system32\drivers\L8042pr2.Sys (Logitech, Inc.)
DRV - (PRISM_A02) – C:\WINDOWS\system32\drivers\PRISMA02.sys (GlobespanVirata, Inc.)
DRV - (bcm4sbxp) – C:\WINDOWS\system32\drivers\bcm4sbxp.sys (Broadcom Corporation)
DRV - (OMCI) – C:\WINDOWS\system32\drivers\omci.sys (Dell Computer Corporation)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://search.live.com/results.aspx?q={sea…ferrer:source?}
IE - HKLM\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 1
IE - HKLM\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local;
IE - HKLM\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = http=localhost:7171

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
IE - HKCU\..\SearchScopes,DefaultScope = {95B7759C-8C7F-4BF1-B163-73684A933233}
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://search.live.com/results.aspx?q={sea…amp;Form=IE8SRC
IE - HKCU\..\SearchScopes\{95B7759C-8C7F-4BF1-B163-73684A933233}: "URL" = http://isearch.avg.com/search?cid={BBDF9D0…mp;d=2012-05-06 01:00:18&v;=11.0.0.9&sap;=dsp&q;={searchTerms}
IE - HKCU\..\SearchScopes\{AFBCB7E0-F91A-4951-9F31-58FEE57A25C4}: "URL" = http://www.ask.com/web?q={SEARCHTERMS}&…eo=US&ver;=6
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..browser.search.defaultenginename: "AVG Secure Search"
FF - prefs.js..browser.startup.homepage: "http://mystart.incredibar.com/mb119?a=6PQqwKDwVP&i;=26"
FF - prefs.js..extensions.enabledItems: [removed]:1.5.0
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}:6.0.20
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}:6.0.21
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0025-ABCDEFFEDCBA}:6.0.25
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA}:6.0.26
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0030-ABCDEFFEDCBA}:6.0.30
FF - prefs.js..extensions.enabledItems: [removed]:1.0
FF - prefs.js..extensions.enabledItems: {BBDA0591-3099-440a-AA10-41764D9DB4DB}:10.1.1.8 - 4
FF - prefs.js..keyword.URL: "http://isearch.avg.com/search?cid=%7Ba5ea3c20-188b-49ed-b665-db350aefac21%7D∣=2c4218cf9b1f8cdb73ebc76c13893d49-59affc265ded83ee52c593f95f03fcb30425c566&ds;=AVG&v;=11.0.0.9⟨=en≺=pr&d;=2012-05-06%2001%3A00%3A18&sap;=ku&q;="


FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{BBDA0591-3099-440a-AA10-41764D9DB4DB}: C:\Documents and Settings\All Users.WINDOWS\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_6.0.0.145\IPSFFPlgn\ [2012/06/06 15:10:41 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{2D3F3651-74B9-4795-BDEC-6DA2F431CB62}: C:\Documents and Settings\All Users.WINDOWS\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_6.0.0.145\coFFPlgn\ [2012/10/08 19:49:59 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 3.0.19\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2012/06/10 11:28:29 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 3.0.19\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2012/06/10 11:28:29 | 000,000,000 | —D | M]

[2010/07/11 14:16:14 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Owner.PETE-05CK9PEMS6\Application Data\Mozilla\Extensions
[2010/07/11 14:16:14 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Owner.PETE-05CK9PEMS6\Application Data\Mozilla\Extensions\[removed]
[2012/09/13 20:43:59 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Owner.PETE-05CK9PEMS6\Application Data\Mozilla\Firefox\Profiles\qjys52r7.default\extensions
[2012/09/13 20:43:59 | 000,000,000 | —D | M] (Microsoft .NET Framework Assistant) – C:\Documents and Settings\Owner.PETE-05CK9PEMS6\Application Data\Mozilla\Firefox\Profiles\qjys52r7.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2012/03/06 21:03:57 | 000,000,000 | —D | M] (Incredibar Toolbar) – C:\Documents and Settings\Owner.PETE-05CK9PEMS6\Application Data\Mozilla\Firefox\Profiles\qjys52r7.default\extensions\[removed]
[2012/03/06 21:03:23 | 000,002,203 | —- | M] () – C:\Documents and Settings\Owner.PETE-05CK9PEMS6\Application Data\Mozilla\Firefox\Profiles\qjys52r7.default\searchplugins\MyStart Search.xml
[2012/09/13 09:52:33 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions
[2010/06/10 08:52:26 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
[2010/09/23 09:04:56 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}
[2011/04/23 13:10:38 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0025-ABCDEFFEDCBA}
[2011/06/11 10:57:48 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA}
[2012/01/15 10:34:59 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0030-ABCDEFFEDCBA}
[2012/06/06 15:10:41 | 000,000,000 | —D | M] (Norton Vulnerability Protection) – C:\DOCUMENTS AND SETTINGS\ALL USERS.WINDOWS\APPLICATION DATA\NORTON\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_6.0.0.145\IPSFFPLGN
[2011/04/23 13:10:19 | 000,000,000 | —D | M] (Java Quick Starter) – C:\PROGRAM FILES\JAVA\JRE6\LIB\DEPLOY\JQS\FF
[2011/11/10 06:54:13 | 000,476,904 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files\mozilla firefox\plugins\npdeployJava1.dll
[2012/05/06 01:00:02 | 000,003,747 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\avg-secure-search.xml

O1 HOSTS File: ([2012/04/12 16:53:59 | 000,000,886 | RH– | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 93.113.196.118 www.google.com
O1 - Hosts: 93.113.196.119 www.bing.com
O2 - BHO: (SpywareGuardDLBLOCK.CBrowserHelper) - {4A368E80-174F-4872-96B5-0B27DDD11DB2} - C:\Program Files\SpywareGuard\dlprotect.dll ()
O2 - BHO: (Norton Identity Protection) - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files\Norton Security Suite\Engine\6.3.0.14\coieplg.dll (Symantec Corporation)
O2 - BHO: (Norton Vulnerability Protection) - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files\Norton Security Suite\Engine\6.3.0.14\ips\ipsbho.dll (Symantec Corporation)
O2 - BHO: (Incredibar.com Helper Object) - {6E13DDE1-2B6E-46CE-8B66-DC8BF36F6B99} - C:\Program Files\Incredibar.com\incredibar\1.5.3.27\bh\incredibar.dll (Montera Technologeis LTD)
O2 - BHO: (Java™ Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (WOT Helper) - {C920E44A-7F78-4E64-BDD7-A57026E7FEB7} - C:\Program Files\WOT\WOT.dll ()
O3 - HKLM\..\Toolbar: (WOT) - {71576546-354D-41c9-AAE8-31F2EC22BF0D} - C:\Program Files\WOT\WOT.dll ()
O3 - HKLM\..\Toolbar: (Norton Toolbar) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Norton Security Suite\Engine\6.3.0.14\coieplg.dll (Symantec Corporation)
O3 - HKLM\..\Toolbar: (Incredibar Toolbar) - {F9639E4A-801B-4843-AEE3-03D9DA199E77} - C:\Program Files\Incredibar.com\incredibar\1.5.3.27\incredibarTlbr.dll (Montera Technologeis LTD)
O3 - HKCU\..\Toolbar\WebBrowser: (WOT) - {71576546-354D-41C9-AAE8-31F2EC22BF0D} - C:\Program Files\WOT\WOT.dll ()
O3 - HKCU\..\Toolbar\WebBrowser: (Norton Toolbar) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Norton Security Suite\Engine\6.3.0.14\coieplg.dll (Symantec Corporation)
O4 - HKLM..\Run: [GIDDesktop] C:\Program Files\SFT\GuardedID\gidd.exe (StrikeForce Technologies Inc.)
O4 - HKLM..\Run: [MMTray] C:\Program Files\Musicmatch\Musicmatch Jukebox\mm_tray.exe (Musicmatch, Inc.)
O4 - HKCU..\Run: [Advanced SystemCare 5] C:\Program Files\IObit\Advanced SystemCare 5\ASCTray.exe (IObit)
O4 - HKLM..\RunOnce: [AvgUninstallURL] C:\WINDOWS\System32\cmd.exe (Microsoft Corporation)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O16 - DPF: {01012101-5E80-11D8-9E86-0007E96C65AE} http://www.comcastsupport.com/oneclickfix/tgctlsr.cab (SupportSoft Script Runner Class)
O16 - DPF: {31435657-9980-0010-8000-00AA00389B71} http://download.microsoft.com/download/e/2…78f/wvc1dmo.cab (Reg Error: Key error.)
O16 - DPF: {33564D57-0000-0010-8000-00AA00389B71} http://download.microsoft.com/download/F/6…922/wmv9VCM.CAB (Reg Error: Key error.)
O16 - DPF: {33564D57-9980-0010-8000-00AA00389B71} http://download.microsoft.com/download/D/0…D0C/wmv9dmo.cab (Reg Error: Key error.)
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} http://update.microsoft.com/windowsupdate/…b?1136593632451 (WUWebControl Class)
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} http://download.eset.com/special/eos-beta/OnlineScanner.cab (Reg Error: Key error.)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_30)
O16 - DPF: {CAFEEFAC-0016-0000-0030-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_30)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_30)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab (Shockwave Flash Object)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 75.75.75.75 75.75.76.76
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{45D6A31F-96C2-4D92-B3F2-4ADBAE67D96B}: DhcpNameServer = [removed] [removed]
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{5479463A-91E8-4138-B3CE-765B64CB7D71}: DhcpNameServer = 75.75.75.75 75.75.76.76
O18 - Protocol\Handler\wot {C2A44D6B-CB9F-4663-88A6-DF2F26E4D952} - C:\Program Files\WOT\WOT.dll ()
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) - C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O20 - Winlogon\Notify\GIDLogonXP: DllName - (GIDLogonXP.dll) - C:\WINDOWS\System32\GIDLogonXP.dll (StrikeForce Technologies Inc)
O20 - Winlogon\Notify\igfxcui: DllName - (igfxsrvc.dll) - C:\WINDOWS\System32\igfxsrvc.dll (Intel Corporation)
O24 - Desktop WallPaper: C:\Documents and Settings\Owner.PETE-05CK9PEMS6\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Owner.PETE-05CK9PEMS6\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O28 - HKLM ShellExecuteHooks: {81559C35-8464-49F7-BB0E-07A383BEF910} - C:\Program Files\SpywareGuard\spywareguard.dll ()
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2005/12/31 15:30:52 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O34 - HKLM BootExecute: (lsdelete)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)

NetSvcs: 6to4 - File not found
NetSvcs: AppMgmt - %SystemRoot%\System32\appmgmts.dll File not found
NetSvcs: HidServ - %SystemRoot%\System32\hidserv.dll File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found

Drivers32: msacm.iac2 - C:\WINDOWS\System32\iac25_32.ax (Intel Corporation)
Drivers32: msacm.l3acm - C:\WINDOWS\system32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.sl_anet - C:\WINDOWS\System32\sl_anet.acm (Sipro Lab Telecom Inc.)
Drivers32: msacm.trspch - C:\WINDOWS\System32\tssoft32.acm (DSP GROUP, INC.)
Drivers32: vidc.cvid - C:\WINDOWS\System32\iccvid.dll (Radius Inc.)
Drivers32: vidc.iv31 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv32 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv41 - C:\WINDOWS\System32\ir41_32.ax (Intel Corporation)
Drivers32: vidc.iv50 - C:\WINDOWS\System32\ir50_32.dll (Intel Corporation)
Drivers32: VIDC.WMV3 - C:\WINDOWS\System32\wmv9vcm.dll (Microsoft Corporation)

CREATERESTOREPOINT
Restore point Set: OTL Restore Point

========== Files/Folders - Created Within 30 Days ==========

[2012/10/08 20:07:20 | 000,602,112 | —- | C] (OldTimer Tools) – C:\Documents and Settings\Owner.PETE-05CK9PEMS6\Desktop\OTL.exe
[2012/09/23 13:57:52 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users.WINDOWS\Application Data\IObit
[2012/09/23 13:56:53 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users.WINDOWS\Start Menu\Programs\Advanced SystemCare 5
[2012/09/23 13:55:11 | 027,669,608 | —- | C] (IObit ) – C:\Documents and Settings\Owner.PETE-05CK9PEMS6\Desktop\asc-setup.exe
[2012/09/23 13:54:13 | 000,000,000 | RH-D | C] – C:\Documents and Settings\Owner.PETE-05CK9PEMS6\Recent
[2012/09/23 13:52:32 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users.WINDOWS\Start Menu\Programs\CCleaner
[2012/09/23 13:52:29 | 000,000,000 | —D | C] – C:\Program Files\CCleaner
[2012/09/23 13:51:31 | 003,927,560 | —- | C] (Piriform Ltd) – C:\Documents and Settings\Owner.PETE-05CK9PEMS6\Desktop\ccsetup322.exe

========== Files - Modified Within 30 Days ==========

[2012/10/08 20:07:20 | 000,602,112 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Owner.PETE-05CK9PEMS6\Desktop\OTL.exe
[2012/10/08 19:49:06 | 000,002,206 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2012/10/08 19:48:46 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2012/10/08 18:06:46 | 000,000,784 | —- | M] () – C:\Documents and Settings\All Users.WINDOWS\Desktop\Malwarebytes Anti-Malware.lnk
[2012/10/08 17:51:36 | 000,000,422 | -H– | M] () – C:\WINDOWS\tasks\User_Feed_Synchronization-{96E858C2-BB80-4CA6-A945-5D7F401AA939}.job
[2012/10/04 07:07:00 | 000,000,472 | —- | M] () – C:\WINDOWS\tasks\Ad-Aware Update (Weekly).job
[2012/09/23 13:57:09 | 000,000,925 | —- | M] () – C:\Documents and Settings\All Users.WINDOWS\Desktop\Uninstaller.lnk
[2012/09/23 13:57:08 | 000,000,874 | —- | M] () – C:\Documents and Settings\All Users.WINDOWS\Desktop\Advanced SystemCare 5.lnk
[2012/09/23 13:57:01 | 000,000,892 | —- | M] () – C:\Documents and Settings\Owner.PETE-05CK9PEMS6\Application Data\Microsoft\Internet Explorer\Quick Launch\Advanced SystemCare 5.lnk
[2012/09/23 13:55:19 | 027,669,608 | —- | M] (IObit ) – C:\Documents and Settings\Owner.PETE-05CK9PEMS6\Desktop\asc-setup.exe
[2012/09/23 13:52:31 | 000,000,682 | —- | M] () – C:\Documents and Settings\All Users.WINDOWS\Desktop\CCleaner.lnk
[2012/09/23 13:51:33 | 003,927,560 | —- | M] (Piriform Ltd) – C:\Documents and Settings\Owner.PETE-05CK9PEMS6\Desktop\ccsetup322.exe

========== Files Created - No Company Name ==========

[2012/10/08 18:06:46 | 000,000,784 | —- | C] () – C:\Documents and Settings\All Users.WINDOWS\Desktop\Malwarebytes Anti-Malware.lnk
[2012/09/23 13:57:09 | 000,000,925 | —- | C] () – C:\Documents and Settings\All Users.WINDOWS\Desktop\Uninstaller.lnk
[2012/09/23 13:57:08 | 000,000,874 | —- | C] () – C:\Documents and Settings\All Users.WINDOWS\Desktop\Advanced SystemCare 5.lnk
[2012/09/23 13:57:00 | 000,000,892 | —- | C] () – C:\Documents and Settings\Owner.PETE-05CK9PEMS6\Application Data\Microsoft\Internet Explorer\Quick Launch\Advanced SystemCare 5.lnk
[2012/09/23 13:52:31 | 000,000,682 | —- | C] () – C:\Documents and Settings\All Users.WINDOWS\Desktop\CCleaner.lnk
[2012/02/15 07:24:01 | 000,003,072 | —- | C] () – C:\WINDOWS\System32\iacenc.dll
[2011/04/20 19:21:31 | 000,000,160 | —- | C] () – C:\Documents and Settings\All Users.WINDOWS\Application Data\~18014004
[2011/04/20 19:21:31 | 000,000,120 | —- | C] () – C:\Documents and Settings\All Users.WINDOWS\Application Data\~18014004r
[2011/04/20 19:19:48 | 000,000,392 | —- | C] () – C:\Documents and Settings\All Users.WINDOWS\Application Data\18014004
[2009/02/06 19:55:45 | 000,076,288 | —- | C] () – C:\Documents and Settings\Owner.PETE-05CK9PEMS6\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini

========== ZeroAccess Check ==========

[2012/07/04 14:15:49 | 000,000,227 | RHS- | M] () – C:\WINDOWS\assembly\Desktop.ini

[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]

[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\System32\shdocvw.dll – [2008/04/13 20:12:05 | 001,499,136 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = C:\WINDOWS\System32\wbem\fastprox.dll – [2009/02/09 08:10:48 | 000,473,600 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
"" = C:\WINDOWS\System32\wbem\wbemess.dll – [2008/04/13 20:12:08 | 000,273,920 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Both

========== LOP Check ==========

[2012/06/13 03:26:33 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users.WINDOWS\Application Data\AVG2012
[2010/10/16 09:16:02 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users.WINDOWS\Application Data\avg9
[2010/10/16 09:30:31 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users.WINDOWS\Application Data\Common Files
[2012/03/06 21:02:35 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users.WINDOWS\Application Data\InstallMate
[2012/09/23 13:57:52 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users.WINDOWS\Application Data\IObit
[2012/07/04 14:46:00 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users.WINDOWS\Application Data\IsolatedStorage
[2009/01/23 21:15:39 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users.WINDOWS\Application Data\MailFrontier
[2012/06/06 15:07:38 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users.WINDOWS\Application Data\MFAData
[2009/06/06 07:59:38 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users.WINDOWS\Application Data\TEMP
[2012/07/04 14:12:21 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users.WINDOWS\Application Data\White Sky, Inc
[2009/06/06 08:11:58 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users.WINDOWS\Application Data\WinZip
[2010/06/11 08:52:08 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner.PETE-05CK9PEMS6\Application Data\Auslogics
[2011/09/24 13:20:31 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner.PETE-05CK9PEMS6\Application Data\AVG2012
[2012/07/06 22:29:34 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner.PETE-05CK9PEMS6\Application Data\ID Vault
[2012/06/06 15:14:05 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner.PETE-05CK9PEMS6\Application Data\Incredibar.com
[2012/09/23 13:57:34 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner.PETE-05CK9PEMS6\Application Data\IObit
[2006/03/19 19:48:06 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner.PETE-05CK9PEMS6\Application Data\Musicmatch
[2012/03/06 21:14:32 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner.PETE-05CK9PEMS6\Application Data\TweakNow PowerPack 2011

========== Purity Check ==========



========== Custom Scans ==========

< %USERPROFILE%\..|smtmp;true;true;true /FP >

< %temp%\smtmp\*.* /s > >

< MD5 for: EXPLORER.EXE >
[2008/04/13 20:12:19 | 001,033,728 | —- | M] (Microsoft Corporation) MD5=12896823FB95BFB3DC9B46BCAEDC9923 – C:\WINDOWS\ERDNT\cache\explorer.exe
[2008/04/13 20:12:19 | 001,033,728 | —- | M] (Microsoft Corporation) MD5=12896823FB95BFB3DC9B46BCAEDC9923 – C:\WINDOWS\explorer.exe
[2008/04/13 20:12:19 | 001,033,728 | —- | M] (Microsoft Corporation) MD5=12896823FB95BFB3DC9B46BCAEDC9923 – C:\WINDOWS\ServicePackFiles\i386\explorer.exe
[2007/06/13 07:26:03 | 001,033,216 | —- | M] (Microsoft Corporation) MD5=7712DF0CDDE3A5AC89843E61CD5B3658 – C:\WINDOWS\$hf_mig$\KB938828\SP2QFE\explorer.exe
[2007/06/13 06:23:07 | 001,033,216 | —- | M] (Microsoft Corporation) MD5=97BD6515465659FF8F3B7BE375B2EA87 – C:\WINDOWS\$NtServicePackUninstall$\explorer.exe
[2004/08/04 03:56:49 | 001,032,192 | —- | M] (Microsoft Corporation) MD5=A0732187050030AE399B241436565E64 – C:\WINDOWS\$NtUninstallKB938828$\explorer.exe

< MD5 for: EXPLORER.EXE.000 >
[2004/08/04 03:56:49 | 001,032,192 | —- | M] (Microsoft Corporation) MD5=A0732187050030AE399B241436565E64 – C:\WINDOWS\$NtServicePackUninstall$\explorer.exe.000

< MD5 for: EXPLORER.EXE-02121B1A.PF >
[2012/10/08 18:02:32 | 000,016,612 | —- | M] () MD5=4D6B5463AD171C3CF008FADB42D8A209 – C:\WINDOWS\Prefetch\EXPLORER.EXE-02121B1A.pf

< MD5 for: EXPLORER.SCF >
[2003/07/16 16:28:12 | 000,000,080 | —- | M] () MD5=A3975A7D2C98B30A2AE010754FFB9392 – C:\WINDOWS\explorer.scf

< MD5 for: IEXPLORE.CHM >
[2009/02/21 01:21:24 | 000,529,818 | —- | M] () MD5=1435F4731719DF5F57D17DC38196245D – C:\WINDOWS\Help\iexplore.chm
[2004/07/17 14:40:16 | 000,204,810 | —- | M] () MD5=60858526AAD1CC55F5F0055B8E3B66FE – C:\WINDOWS\ie7\iexplore.chm
[2004/07/17 14:40:16 | 000,204,810 | —- | M] () MD5=60858526AAD1CC55F5F0055B8E3B66FE – C:\WINDOWS\ServicePackFiles\i386\iexplore.chm
[2006/09/01 08:43:50 | 000,503,758 | —- | M] () MD5=652E46500C149D1DC948BF9CEA8C4933 – C:\WINDOWS\ie8\iexplore.chm

< MD5 for: IEXPLORE.CHW >
[2009/05/31 17:23:40 | 000,153,185 | —- | M] () MD5=00B4E1AA5457FC749D8F6D38DDAF0A15 – C:\WINDOWS\Help\iexplore.chw

< MD5 for: IEXPLORE.EXE >
[2008/12/19 01:25:25 | 000,634,024 | —- | M] (Microsoft Corporation) MD5=030D78FE84A086ED376EFCBD2D72C522 – C:\WINDOWS\ie7updates\KB963027-IE7\iexplore.exe
[2008/10/15 02:34:58 | 000,633,632 | —- | M] (Microsoft Corporation) MD5=056C927CF7207857E8B34F7A8FFD9B9E – C:\WINDOWS\$hf_mig$\KB958215-IE7\SP2QFE\iexplore.exe
[2007/04/24 10:26:26 | 000,625,152 | —- | M] (Microsoft Corporation) MD5=10BDB55982586A432A3951EB19A26009 – C:\WINDOWS\ie7updates\KB937143-IE7\iexplore.exe
[2008/12/19 01:25:30 | 000,634,024 | —- | M] (Microsoft Corporation) MD5=15E8A89499741D5CF59A9CF6463A4339 – C:\WINDOWS\$hf_mig$\KB961260-IE7\SP2QFE\iexplore.exe
[2008/04/22 04:02:46 | 000,625,664 | —- | M] (Microsoft Corporation) MD5=197B7E4030CFBD8D2979D375E1787AA2 – C:\WINDOWS\$hf_mig$\KB950759-IE7\SP2QFE\iexplore.exe
[2008/08/23 01:56:15 | 000,635,848 | —- | M] (Microsoft Corporation) MD5=1F03216084447F990AE797317D0A6E70 – C:\WINDOWS\ie7updates\KB958215-IE7\iexplore.exe
[2008/04/22 03:40:18 | 000,625,664 | —- | M] (Microsoft Corporation) MD5=232B22817B90AE0AFF2D189E3E3735AC – C:\WINDOWS\ie7updates\KB953838-IE7\iexplore.exe
[2007/12/06 07:01:25 | 000,625,664 | —- | M] (Microsoft Corporation) MD5=2703D940A62B731AA220529DD7331A78 – C:\WINDOWS\ie7updates\KB947864-IE7\iexplore.exe
[2007/06/27 04:27:30 | 000,625,152 | —- | M] (Microsoft Corporation) MD5=275CEE268B9E5D82474C43D5D249D111 – C:\WINDOWS\ie7updates\KB939653-IE7\iexplore.exe
[2008/02/29 04:55:46 | 000,625,664 | —- | M] (Microsoft Corporation) MD5=2D0E5592AB5A46C27DAF7CCAFF4F5B59 – C:\WINDOWS\ie7updates\KB950759-IE7\iexplore.exe
[2007/08/17 06:21:21 | 000,625,152 | —- | M] (Microsoft Corporation) MD5=3AC2BC667DA0AF2C968E96E1630F5AB5 – C:\WINDOWS\ie7updates\KB942615-IE7\iexplore.exe
[2012/09/07 17:04:42 | 000,218,696 | —- | M] () MD5=4E0D8C9F83B7FD82393F7D8CCC27E7AE – C:\Program Files\Malwarebytes' Anti-Malware\Chameleon\iexplore.exe
[2006/10/17 13:04:40 | 000,622,080 | —- | M] (Microsoft Corporation) MD5=5334D4461AA92A7B008755FE6D13C5F2 – C:\WINDOWS\ie7updates\KB928090-IE7\iexplore.exe
[2007/08/17 06:12:49 | 000,625,152 | —- | M] (Microsoft Corporation) MD5=5577D0E3AC2F9F035ACD81B44AF5F511 – C:\WINDOWS\$hf_mig$\KB939653-IE7\SP2QFE\iexplore.exe
[2008/04/13 20:12:22 | 000,093,184 | —- | M] (Microsoft Corporation) MD5=55794B97A7FAABD2910873C85274F409 – C:\WINDOWS\ServicePackFiles\i386\iexplore.exe
[2007/10/10 04:16:56 | 000,625,664 | —- | M] (Microsoft Corporation) MD5=632BDE0179847234433CA50945442ACB – C:\WINDOWS\$hf_mig$\KB942615-IE7\SP2QFE\iexplore.exe
[2008/06/23 05:20:52 | 000,625,664 | —- | M] (Microsoft Corporation) MD5=64E376A47763DAEABCDA14BD5B6EA286 – C:\WINDOWS\ie7updates\KB956390-IE7\iexplore.exe
[2007/02/21 04:00:58 | 000,623,616 | —- | M] (Microsoft Corporation) MD5=683DDE71BCF03B501B912D20CB93B549 – C:\WINDOWS\ie7updates\KB933566-IE7\iexplore.exe
[2008/02/22 05:40:22 | 000,625,664 | —- | M] (Microsoft Corporation) MD5=6E0888626E0CAC79F57149814E22DB4D – C:\WINDOWS\$hf_mig$\KB947864-IE7\SP2QFE\iexplore.exe
[2007/12/06 04:34:45 | 000,625,664 | —- | M] (Microsoft Corporation) MD5=809D17D8FA0FDAEE07778CD821CAFFDE – C:\WINDOWS\$hf_mig$\KB944533-IE7\SP2QFE\iexplore.exe
[2007/01/08 19:08:42 | 000,623,616 | —- | M] (Microsoft Corporation) MD5=93A6A4F5293AE19E3B37021AABCF0902 – C:\WINDOWS\ie7updates\KB931768-IE7\iexplore.exe
[2007/04/24 10:20:41 | 000,625,152 | —- | M] (Microsoft Corporation) MD5=9B3516C1F30DA17ADD3818573047D63C – C:\WINDOWS\$hf_mig$\KB933566-IE7\SP2QFE\iexplore.exe
[2008/10/15 03:06:26 | 000,633,632 | —- | M] (Microsoft Corporation) MD5=9D3DB9ADFABD2F0BC778EC03250A3ABB – C:\WINDOWS\ie7updates\KB961260-IE7\iexplore.exe
[2009/02/28 00:54:41 | 000,636,072 | —- | M] (Microsoft Corporation) MD5=A251068640DDB69FD7805B57D89D7FF7 – C:\WINDOWS\ie8\iexplore.exe
[2009/03/08 14:09:26 | 000,638,816 | —- | M] (Microsoft Corporation) MD5=B60DDDD2D63CE41CB8C487FCFBB6419E – C:\Program Files\Internet Explorer\iexplore.exe
[2009/03/08 14:09:26 | 000,638,816 | —- | M] (Microsoft Corporation) MD5=B60DDDD2D63CE41CB8C487FCFBB6419E – C:\WINDOWS\ERDNT\cache\iexplore.exe
[2009/03/08 14:09:26 | 000,638,816 | —- | M] (Microsoft Corporation) MD5=B60DDDD2D63CE41CB8C487FCFBB6419E – C:\WINDOWS\system32\dllcache\iexplore.exe
[2009/02/28 00:54:44 | 000,636,088 | —- | M] (Microsoft Corporation) MD5=BCD8E48709BE4A79606F0B6E8E9A6162 – C:\WINDOWS\$hf_mig$\KB963027-IE7\SP3QFE\iexplore.exe
[2007/06/27 05:16:52 | 000,625,152 | —- | M] (Microsoft Corporation) MD5=BD8502DFD53FC24FB8D6929DC46B8C2C – C:\WINDOWS\$hf_mig$\KB937143-IE7\SP2QFE\iexplore.exe
[2008/06/23 04:23:52 | 000,625,664 | —- | M] (Microsoft Corporation) MD5=C52A9EF571E91535EB78DB4B8B95EA07 – C:\WINDOWS\$hf_mig$\KB953838-IE7\SP2QFE\iexplore.exe
[2007/02/28 02:51:34 | 000,625,152 | —- | M] (Microsoft Corporation) MD5=D321092F8529CDAE843D6E24E3CAC6CB – C:\WINDOWS\$hf_mig$\KB931768-IE7\SP2QFE\iexplore.exe
[2004/08/04 03:56:50 | 000,093,184 | —- | M] (Microsoft Corporation) MD5=E7484514C0464642BE7B4DC2689354C8 – C:\WINDOWS\$NtServicePackUninstall$\iexplore.exe
[2004/08/04 03:56:50 | 000,093,184 | —- | M] (Microsoft Corporation) MD5=E7484514C0464642BE7B4DC2689354C8 – C:\WINDOWS\ie7\iexplore.exe
[2008/08/23 01:56:16 | 000,635,848 | —- | M] (Microsoft Corporation) MD5=E8305C30D35E85D6657ED3E9934CB302 – C:\WINDOWS\$hf_mig$\KB956390-IE7\SP2QFE\iexplore.exe
[2007/10/10 06:59:52 | 000,625,152 | —- | M] (Microsoft Corporation) MD5=E854D02E4231F704D9BE782A424E6D8B – C:\WINDOWS\ie7updates\KB944533-IE7\iexplore.exe

< MD5 for: IEXPLORE.EXE.MUI >
[2009/03/08 14:21:44 | 000,012,288 | —- | M] (Microsoft Corporation) MD5=943030B55FDB56FB8B8FCC086071E119 – C:\Program Files\Internet Explorer\en-US\iexplore.exe.mui
[2009/03/08 14:21:44 | 000,012,288 | —- | M] (Microsoft Corporation) MD5=943030B55FDB56FB8B8FCC086071E119 – C:\Program Files\Internet Explorer\iexplore.exe.mui
[2006/10/17 13:04:26 | 000,573,440 | —- | M] (Microsoft Corporation) MD5=E83C9C1F9DD9D47BB44871BFC7E69DDD – C:\WINDOWS\ie8\iexplore.exe.mui

< MD5 for: IEXPLORE.EXE-2D97EBE6.PF >
[2012/10/08 19:50:21 | 000,147,158 | —- | M] () MD5=4E58DD04967BE1E3380F430B1F56BE34 – C:\WINDOWS\Prefetch\IEXPLORE.EXE-2D97EBE6.pf

< MD5 for: IEXPLORE.HLP >
[2003/07/16 16:30:14 | 000,180,335 | —- | M] () MD5=3F19AF1B745140DAFAC6F78F561A3C62 – C:\WINDOWS\Help\iexplore.hlp

< MD5 for: SERVICES >
[2003/07/16 16:44:24 | 000,007,116 | —- | M] () MD5=95826940E657FE0567A8EC0F2A6AD11A – C:\WINDOWS\system32\drivers\etc\services

< MD5 for: SERVICES.DLL >
[2003/10/06 13:05:42 | 000,018,944 | —- | M] () MD5=FD3C2F44D7C48F2AFC8BBC11840205D8 – C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\services.dll

< MD5 for: SERVICES.EXE >
[2009/02/06 07:06:24 | 000,110,592 | —- | M] (Microsoft Corporation) MD5=020CEAAEDC8EB655B6506B8C70D53BB6 – C:\WINDOWS\$hf_mig$\KB956572\SP3QFE\services.exe
[2008/04/13 20:12:34 | 000,108,544 | —- | M] (Microsoft Corporation) MD5=0E776ED5F7CC9F94299E70461B7B8185 – C:\WINDOWS\$NtUninstallKB956572$\services.exe
[2008/04/13 20:12:34 | 000,108,544 | —- | M] (Microsoft Corporation) MD5=0E776ED5F7CC9F94299E70461B7B8185 – C:\WINDOWS\ServicePackFiles\i386\services.exe
[2009/02/06 07:11:05 | 000,110,592 | —- | M] (Microsoft Corporation) MD5=65DF52F5B8B6E9BBD183505225C37315 – C:\WINDOWS\ERDNT\cache\services.exe
[2009/02/06 07:11:05 | 000,110,592 | —- | M] (Microsoft Corporation) MD5=65DF52F5B8B6E9BBD183505225C37315 – C:\WINDOWS\system32\dllcache\services.exe
[2009/02/06 07:11:05 | 000,110,592 | —- | M] (Microsoft Corporation) MD5=65DF52F5B8B6E9BBD183505225C37315 – C:\WINDOWS\system32\services.exe
[2004/08/04 03:56:55 | 000,108,032 | —- | M] (Microsoft Corporation) MD5=C6CE6EEC82F187615D1002BB3BB50ED4 – C:\WINDOWS\$NtServicePackUninstall$\services.exe

< MD5 for: SERVICES.LNK >
[2006/01/06 00:08:58 | 000,001,602 | —- | M] () MD5=61F177100FA890CBCF458E4AD8E55EAE – C:\Documents and Settings\All Users.WINDOWS\Start Menu\Programs\Administrative Tools\Services.lnk
[2004/06/23 15:02:58 | 000,001,602 | —- | M] () MD5=680BE74FE1F07B9535B91A1DC135F965 – C:\Documents and Settings\All Users\Start Menu\Programs\Administrative Tools\Services.lnk

< MD5 for: SERVICES.MSC >
[2003/07/16 16:44:24 | 000,033,464 | —- | M] () MD5=E8089AA2A6F7FEE89B38C1F2D77BA6C6 – C:\WINDOWS\system32\services.msc

< MD5 for: WINLOGON.EXE >
[2004/08/04 03:56:57 | 000,502,272 | —- | M] (Microsoft Corporation) MD5=01C3346C241652F43AED8E2149881BFE – C:\WINDOWS\$NtServicePackUninstall$\winlogon.exe
[2012/09/07 17:04:42 | 000,218,696 | —- | M] () MD5=4E0D8C9F83B7FD82393F7D8CCC27E7AE – C:\Program Files\Malwarebytes' Anti-Malware\Chameleon\winlogon.exe
[2008/04/13 20:12:39 | 000,507,904 | —- | M] (Microsoft Corporation) MD5=ED0EF0A136DEC83DF69F04118870003E – C:\WINDOWS\ERDNT\cache\winlogon.exe
[2008/04/13 20:12:39 | 000,507,904 | —- | M] (Microsoft Corporation) MD5=ED0EF0A136DEC83DF69F04118870003E – C:\WINDOWS\ServicePackFiles\i386\winlogon.exe
[2008/04/13 20:12:39 | 000,507,904 | —- | M] (Microsoft Corporation) MD5=ED0EF0A136DEC83DF69F04118870003E – C:\WINDOWS\system32\winlogon.exe

< %SYSTEMDRIVE%\*.* >
[2011/04/14 03:25:04 | 000,066,524 | —- | M] () – C:\aaw7boot.log
[2005/12/31 15:30:52 | 000,000,000 | —- | M] () – C:\AUTOEXEC.BAT
[2008/05/15 16:10:32 | 000,000,211 | —- | M] () – C:\Boot.bak
[2012/03/06 23:18:28 | 000,000,281 | RHS- | M] () – C:\boot.ini
[2004/08/03 23:00:00 | 000,260,272 | —- | M] () – C:\cmldr
[2011/04/23 12:41:53 | 000,009,797 | —- | M] () – C:\ComboFix.txt
[2004/06/23 15:02:54 | 000,000,000 | —- | M] () – C:\CONFIG.SYS
[2004/06/23 15:02:54 | 000,000,000 | RHS- | M] () – C:\IO.SYS
[2009/05/26 21:24:42 | 000,008,814 | —- | M] () – C:\JavaRa.log
[2004/06/23 15:02:54 | 000,000,000 | RHS- | M] () – C:\MSDOS.SYS
[2006/01/06 00:29:46 | 000,000,174 | —- | M] () – C:\mw.log
[2006/01/27 20:46:49 | 000,047,564 | RHS- | M] () – C:\NTDETECT.COM
[2008/09/29 16:35:49 | 000,250,048 | RHS- | M] () – C:\ntldr
[2012/10/08 19:48:43 | 1006,632,960 | -HS- | M] () – C:\pagefile.sys
[2010/06/10 13:55:18 | 000,000,385 | —- | M] () – C:\rkill.log
[2010/01/06 18:32:50 | 000,002,239 | —- | M] () – C:\rollback.ini
[2005/12/30 19:41:25 | 000,001,512 | —- | M] () – C:\smitfiles.txt
[2005/10/31 11:56:00 | 000,700,416 | —- | M] (LimeWire) – C:\StubInstaller.exe
[2012/03/06 21:04:07 | 000,000,448 | —- | M] () – C:\user.js
[2006/01/01 01:04:18 | 000,000,161 | —- | M] () – C:\w.bat

< %systemroot%\Fonts\*.com >

< %systemroot%\Fonts\*.dll >

< %systemroot%\Fonts\*.ini >
[2006/01/06 00:08:23 | 000,000,067 | -HS- | M] () – C:\WINDOWS\Fonts\desktop.ini

< %systemroot%\Fonts\*.ini2 >

< %systemroot%\Fonts\*.exe >

< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2002/02/12 01:00:00 | 000,013,824 | —- | M] (CANON INC.) – C:\WINDOWS\system32\spool\prtprocs\w32x86\CNMPD43.DLL
[2002/02/12 01:00:00 | 000,043,008 | —- | M] (CANON INC.) – C:\WINDOWS\system32\spool\prtprocs\w32x86\CNMPP43.DLL
[2008/07/06 08:06:10 | 000,089,088 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\filterpipelineprintproc.dll
[2008/07/06 06:50:03 | 000,597,504 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\printfilterpipelinesvc.exe

< %systemroot%\REPAIR\*.bak1 >

< %systemroot%\REPAIR\*.ini >

< %systemroot%\system32\*.jpg >

< %systemroot%\*.jpg >

< %systemroot%\*.png >

< %systemroot%\*.scr >

< %systemroot%\*._sy >

< %APPDATA%\Adobe\Update\*.* >

< %ALLUSERSPROFILE%\Favorites\*.* >

< %APPDATA%\Microsoft\*.* >

< %PROGRAMFILES%\*.* >

< %APPDATA%\Update\*.* >

< %systemroot%\*. /mp /s >

< %systemroot%\System32\config\*.sav >
[2006/01/05 15:50:58 | 000,094,208 | —- | M] () – C:\WINDOWS\System32\config\default.sav
[2006/01/05 15:50:58 | 000,602,112 | —- | M] () – C:\WINDOWS\System32\config\software.sav
[2006/01/05 15:50:58 | 000,389,120 | —- | M] () – C:\WINDOWS\System32\config\system.sav

< %PROGRAMFILES%\bak. /s >

< %systemroot%\system32\bak. /s >

< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >
[2008/09/29 16:49:11 | 000,000,272 | -HS- | M] () – C:\Documents and Settings\All Users.WINDOWS\Start Menu\desktop.ini

< %systemroot%\system32\config\systemprofile\*.dat /x >

< %systemroot%\*.config >

< %systemroot%\system32\*.db >

< %PROGRAMFILES%\Internet Explorer\*.dat >

< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2006/01/27 21:54:11 | 000,000,177 | -HS- | M] () – C:\Documents and Settings\Owner.PETE-05CK9PEMS6\Application Data\Microsoft\Internet Explorer\Quick Launch\desktop.ini
[2006/01/06 00:18:02 | 000,000,079 | —- | M] () – C:\Documents and Settings\Owner.PETE-05CK9PEMS6\Application Data\Microsoft\Internet Explorer\Quick Launch\Show Desktop.scf

< %USERPROFILE%\Desktop\*.exe >
[2012/09/23 13:55:19 | 027,669,608 | —- | M] (IObit ) – C:\Documents and Settings\Owner.PETE-05CK9PEMS6\Desktop\asc-setup.exe
[2009/05/28 19:11:47 | 000,050,688 | —- | M] (Atribune.org) – C:\Documents and Settings\Owner.PETE-05CK9PEMS6\Desktop\ATF-Cleaner.exe
[2011/04/23 14:09:42 | 005,497,592 | —- | M] (AVG Technologies) – C:\Documents and Settings\Owner.PETE-05CK9PEMS6\Desktop\avg_free_stb_all_2011_1321_cnet.exe
[2012/09/23 13:51:33 | 003,927,560 | —- | M] (Piriform Ltd) – C:\Documents and Settings\Owner.PETE-05CK9PEMS6\Desktop\ccsetup322.exe
[2012/01/19 11:51:20 | 000,776,208 | —- | M] (Adobe Systems Incorporated) – C:\Documents and Settings\Owner.PETE-05CK9PEMS6\Desktop\install_flashplayer11x32ax_gtba_aih.exe
[2011/04/23 13:06:00 | 016,537,376 | —- | M] (Sun Microsystems, Inc.) – C:\Documents and Settings\Owner.PETE-05CK9PEMS6\Desktop\jre-6u25-windows-i586.exe
[2011/05/04 09:43:12 | 007,734,208 | —- | M] (Malwarebytes Corporation ) – C:\Documents and Settings\Owner.PETE-05CK9PEMS6\Desktop\mbam-setup-1.50.1.1100.exe
[2012/03/06 21:49:12 | 009,852,544 | —- | M] (Malwarebytes Corporation ) – C:\Documents and Settings\Owner.PETE-05CK9PEMS6\Desktop\mbam-setup-1.51.2.1300.exe
[2012/10/08 20:07:20 | 000,602,112 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Owner.PETE-05CK9PEMS6\Desktop\OTL.exe
[2012/01/15 10:37:29 | 009,504,840 | —- | M] (TweakNow.com ) – C:\Documents and Settings\Owner.PETE-05CK9PEMS6\Desktop\PowerPack347.exe

< %PROGRAMFILES%\Common Files\*.* >

< %systemroot%\*.src >

< %systemroot%\install\*.* >

< %systemroot%\system32\DLL\*.* >

< %systemroot%\system32\HelpFiles\*.* >

< %systemroot%\system32\rundll\*.* >

< %systemroot%\winn32\*.* >

< %systemroot%\Java\*.* >

< %systemroot%\system32\test\*.* >

< %systemroot%\system32\Rundll32\*.* >

< %systemroot%\AppPatch\Custom\*.* >

< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >

< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2012-09-23 07:03:39

< >
[2006/01/06 00:06:32 | 000,000,065 | R— | C] () – C:\WINDOWS\Tasks\desktop.ini
[2006/01/06 00:08:36 | 000,000,006 | -H– | C] () – C:\WINDOWS\Tasks\SA.DAT
[2009/05/21 07:07:33 | 000,000,472 | —- | C] () – C:\WINDOWS\Tasks\Ad-Aware Update (Weekly).job
[2009/10/01 17:48:09 | 000,000,422 | -H– | C] () – C:\WINDOWS\Tasks\User_Feed_Synchronization-{96E858C2-BB80-4CA6-A945-5D7F401AA939}.job

< >

========== Hard Links - Junction Points - Mount Points - Symbolic Links ==========
[C:\WINDOWS\$NtUninstallKB12858$] -> Error: Cannot create file handle -> Unknown point type

========== Alternate Data Streams ==========

@Alternate Data Stream - 125 bytes -> C:\Documents and Settings\All Users.WINDOWS\Application Data\TEMP:5C321E34

< End of report >
——————

only this scan came up. computer painfully slow.
Hello pfilighera,

It's me again, OCD. I would be more than happy to take a look at your log and help you with solving any malware problems you might have. Logs can take a while to research, so please be patient and know that I am working hard to get you a clean and functional system back in your hands. I'd be grateful if you would note the following:

Please be advised, as I am still in training, all my replies to you will be checked for accuracy by one of our experts to ensure that I am giving you the best possible advise, this will be a team effort. This may cause a delay, but I will do my best to keep it as short as possible. Please bear with me, I will post back to you as soon as I can.
  • I will be working on your Malware issues, this may or may not, solve other issues you have with your machine.
  • The fixes are specific to your problem and should only be used for the issues on this machine.
  • Please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear.
  • It's often worth reading through these instructions and printing them for ease of reference.
  • If you don't know or understand something, please don't hesitate to say or ask!! It's better to be sure and safe than sorry.
  • Please reply to this thread. Do not start a new topic.
IMPORTANT NOTE : Please do not delete, download or install anything unless instructed to do so.

DO NOT use any TOOLS such as Combofix or HijackThis fixes without supervision. Doing so could make your system inoperable and could require a full reinstall of your Operating System and losing all your programs and data.

Important Note for Vista and Windows 7 users:

These tools MUST be run from the executable.(.exe) every time you run them with Admin Rights (Right click, choose "Run as Administrator")

Please stay with this topic until I let you know that your system appears to be "All Clear"
Hi pfilighera,

Let's see if we can get your husband's computer running better.

Follow the steps below to locate the Malwarebytes' log from the most recent scan.
  • Open Malwarebytes' select the Logs tab, the locate the most recent log, highlight it and click Open
  • Copy and Paste the log into your next reply.
Next

P2P - I see you have/had P2P software Limewire installed on your machine. We are not here to pass judgment on file-sharing as a concept. However, we will warn you that engaging in this activity and having this kind of software installed on your machine will always make you more susceptible to re-infections and possibly Identity Theft. It likely contributed to your current situation. This page will give you further information.

Please note: Even if you are using a "safe" P2P program, it is only the program that is safe. You will be sharing files from uncertified sources, and these are often infected. The bad guys use P2P filesharing as a major conduit to spread their wares.

I would strongly recommend that you uninstall these now. You can do so via Control Panel >> Add or Remove Programs.

Next

Download AdwCleaner from here and save it to your desktop.
Windows Vista and Windows 7 users Right Click and select "Run as Administrator"
  • Run AdwCleaner and select Delete
  • Once done it will ask to reboot, allow the reboot
  • On reboot a log will be produced, please attach the content of the log to your next reply
Next

Run OTL.exe
Windows Vista and Windows 7 users Right Click and select "Run as Administrator"
  • Copy/paste the following text written inside of the code box into the Custom Scans/Fixes box located at the bottom of OTL

    :Files
    C:\StubInstaller.exe
    
    :Commands
    [purity]
    [createrestorepoint]
    [resethosts]
    [emptytemp]
    [Reboot]
  • Then click the Run Fix button at the top
  • Let the program run unhindered, reboot when it is done
  • Then post a new OTL log ( don't check the boxes beside LOP Check or Purity this time )
Next

Please download aswMBR to your desktop.
  • Double click the aswMBR icon to run it.
    Windows Vista and Windows 7 users Right Click and select "Run as Administrator"
  • Click the Scan button to start scan.
  • When it finishes, press the save log button, save the log file to your desktop.
[external image: Posted Image]
Click the image to enlarge it

In your next post please provide the following:
  • MBAM log
  • AdwCleaner log
  • OTL.txt
  • aswMBR log
Thank you for your help. This is an amazing site. # AdwCleaner v2.004 - Logfile created 10/12/2012 at 20:29:59 # Updated 06/10/2012 by Xplode # Operating system : Microsoft Windows XP Service Pack 3 (32 bits) # User : Owner - PETE-05CK9PEMS6 # Boot Mode : Normal # Running from : C:\Documents and Settings\Owner.PETE-05CK9PEMS6\Desktop\AdwCleaner.exe # Option [Delete] ***** [Services] ***** ***** [Files / Folders] ***** File Deleted : C:\Program Files\Mozilla Firefox\.autoreg File Deleted : C:\Program Files\Mozilla Firefox\searchplugins\avg-secure-search.xml File Deleted : C:\user.js Folder Deleted : C:\Documents and Settings\All Users.WINDOWS\Application Data\InstallMate Folder Deleted : C:\Program Files\incredibar.com Folder Deleted : C:\Program Files\Viewpoint ***** [Registry] ***** Key Deleted : HKCU\Software\IGearSettings Key Deleted : HKCU\Software\IM Key Deleted : HKCU\Software\ImInstaller Key Deleted : HKCU\Software\incredibar.com Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{95B7759C-8C7F-4BF1-B163-73684A933233} Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{6E13DDE1-2B6E-46CE-8B66-DC8BF36F6B99} Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{95B7759C-8C7F-4BF1-B163-73684A933233} Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{F9639E4A-801B-4843-AEE3-03D9DA199E77} Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{6E13DDE1-2B6E-46CE-8B66-DC8BF36F6B99} Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{F25AF245-4A81-40DC-92F9-E9021F207706} Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{F9639E4A-801B-4843-AEE3-03D9DA199E77} Key Deleted : HKLM\SOFTWARE\Classes\AppID\{09C554C3-109B-483C-A06B-F14172F1A947} Key Deleted : HKLM\SOFTWARE\Classes\AppID\{4E1E9D45-8BF9-4139-915C-9F83CC3D5921} Key Deleted : HKLM\SOFTWARE\Classes\AppID\{608D3067-77E8-463D-9084-908966806826} Key Deleted : HKLM\SOFTWARE\Classes\AppID\{B12E99ED-69BD-437C-86BE-C862B9E5444D} Key Deleted : HKLM\SOFTWARE\Classes\AppID\{CFE8AAFD-A0F3-4329-84E9-6B679EC93EC2} Key Deleted : HKLM\SOFTWARE\Classes\AppID\{D7EE8177-D51E-4F89-92B6-83EA2EC40800} Key Deleted : HKLM\SOFTWARE\Classes\AppID\escort.DLL Key Deleted : HKLM\SOFTWARE\Classes\AppID\escortApp.DLL Key Deleted : HKLM\SOFTWARE\Classes\AppID\escortEng.DLL Key Deleted : HKLM\SOFTWARE\Classes\AppID\escorTlbr.DLL Key Deleted : HKLM\SOFTWARE\Classes\AppID\esrv.EXE Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{6E13DDE1-2B6E-46CE-8B66-DC8BF36F6B99} Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{C01315C7-B4E2-4864-B43D-5FAFC414D179} Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{C1545464-C77C-4130-A572-1C619E2895FE} Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39} Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{ED0E67AD-926C-4008-87E5-03CF72AA2A7E} Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{EF7FEC6D-451B-4452-9D26-7E10C6B5DB6E} Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{F9639E4A-801B-4843-AEE3-03D9DA199E77} Key Deleted : HKLM\SOFTWARE\Classes\escort.escortIEPane Key Deleted : HKLM\SOFTWARE\Classes\escort.escortIEPane.1 Key Deleted : HKLM\SOFTWARE\Classes\escort.escrtBtn.1 Key Deleted : HKLM\SOFTWARE\Classes\esrv.IncredibarESrvc Key Deleted : HKLM\SOFTWARE\Classes\esrv.IncredibarESrvc.1 Key Deleted : HKLM\SOFTWARE\Classes\I Key Deleted : HKLM\SOFTWARE\Classes\Incredibar.dskBnd Key Deleted : HKLM\SOFTWARE\Classes\Incredibar.dskBnd.1 Key Deleted : HKLM\SOFTWARE\Classes\Incredibar.IncredibarHlpr Key Deleted : HKLM\SOFTWARE\Classes\Incredibar.IncredibarHlpr.1 Key Deleted : HKLM\SOFTWARE\Classes\IncredibarApp.appCore Key Deleted : HKLM\SOFTWARE\Classes\IncredibarApp.appCore.1 Key Deleted : HKLM\SOFTWARE\Classes\Interface\{03E2A1F3-4402-4121-8B35-733216D61217} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{22B0769F-794B-4422-AC84-47B123C8986D} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{255E0B2A-D747-4EEF-B7CE-159D73A3656D} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{28ED590D-F5ED-4E05-A87F-1D759F1C6169} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{45D5B93F-E2ED-4AF2-915E-DCDDBDA8C33C} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{771B99AB-636F-4A11-9039-8DFEB927B061} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{9E3B11F6-4179-4603-A71B-A55F4BCB0BEC} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{A8321AA2-2227-40C7-8525-6C2F4E1B0EBE} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{AA41A731-6814-4A70-A6F1-C0A20FBBFBD5} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{ABBB8A9E-D8AF-40D1-94BE-5175077465FC} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{BF737694-56F6-46FA-9FDC-FA99A5B25FAD} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{CFCD164E-8AC9-478E-9ECC-B616A932016C} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{D5961CC0-B442-4567-8030-67E241EF4CC2} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{E450067F-1C93-41A7-928E-07E5C2EEC680} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{F0356CB6-4AB7-425B-A31C-0369E0CB5E81} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{F977D9F2-4BDC-44A6-B508-7C0284C61EED} Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{48C9C8B0-A546-46C1-A81F-47A31E623E9D} Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{4E1E9D45-8BF9-4139-915C-9F83CC3D5921} Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{9C049BA6-EA47-4AC3-AED6-A66D8DC9E1D8} Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{CFE8AAFD-A0F3-4329-84E9-6B679EC93EC2} Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{D7EE8177-D51E-4F89-92B6-83EA2EC40800} Key Deleted : HKLM\Software\incredibar.com Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{74C36554-31F0-49DD-8857-ED6A64DF45BE} Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\incredibar Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{6E13DDE1-2B6E-46CE-8B66-DC8BF36F6B99} Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\incredibar Value Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{F9639E4A-801B-4843-AEE3-03D9DA199E77}] ***** [Internet Browsers] ***** -\\ Internet Explorer v8.0.6001.18702 [OK] Registry is clean. -\\ Mozilla Firefox v3.0.19 (en-US) ************************* AdwCleaner[S1].txt - [6525 octets] - [12/10/2012 20:29:59] ########## EOF - C:\AdwCleaner[S1].txt - [6585 octets] ########## ——————————- Malwarebytes Anti-Malware 1.65.0.1400 www.malwarebytes.org Database version: v2012.10.08.08 Windows XP Service Pack 3 x86 NTFS Internet Explorer 8.0.6001.18702 Owner :: PETE-05CK9PEMS6 [limited] 10/8/2012 6:08:49 PM mbam-log-2012-10-08 (18-08-49).txt Scan type: Full scan (C:\|) Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM Scan options disabled: P2P Objects scanned: 426680 Time elapsed: 1 hour(s), 33 minute(s), 43 second(s) Memory Processes Detected: 0 (No malicious items detected) Memory Modules Detected: 0 (No malicious items detected) Registry Keys Detected: 0 (No malicious items detected) Registry Values Detected: 1 HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run| (Trojan.Zbot) -> Data: C:\DOCUME~1\OWNER~2.PET\LOCALS~1\Temp\irb700.exe -> Quarantined and deleted successfully. Registry Data Items Detected: 0 (No malicious items detected) Folders Detected: 0 (No malicious items detected) Files Detected: 1 C:\Documents and Settings\Owner.PETE-05CK9PEMS6\Local Settings\temp\irb700.exe (Trojan.Zbot) -> Quarantined and deleted successfully. (end) ————————————- i will send other results upon reboot of otl.
By the way, i went to control panel, add/remove programs, and limewire wasn't there. if there is pieces of it around, i don't know how to get rid of them. All processes killed ========== FILES ========== C:\StubInstaller.exe moved successfully. ========== COMMANDS ========== Restore point Set: OTL Restore Point C:\WINDOWS\System32\drivers\etc\Hosts moved successfully. HOSTS file reset successfully [EMPTYTEMP] User: Administrator ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes User: Administrator.PETE-05CK9PEMS6 ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes User: All Users User: All Users.WINDOWS User: Default User ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes User: Default User.WINDOWS ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 33170 bytes User: LocalService ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes ->Flash cache emptied: 0 bytes User: LocalService.NT AUTHORITY ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes User: LocalService.NT AUTHORITY.000 ->Temp folder emptied: 66016 bytes ->Temporary Internet Files folder emptied: 33170 bytes ->Flash cache emptied: 0 bytes User: NetworkService ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes User: NetworkService.NT AUTHORITY ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes User: NetworkService.NT AUTHORITY.000 ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 33170 bytes ->Flash cache emptied: 0 bytes User: Owner ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes ->Flash cache emptied: 0 bytes User: Owner.PETE-05CK9PEMS6 ->Temp folder emptied: 353497 bytes ->Temporary Internet Files folder emptied: 173741087 bytes ->Java cache emptied: 31385 bytes ->FireFox cache emptied: 3239128 bytes ->Flash cache emptied: 1581 bytes User: Owner.PETE-OZKKR0BYRK ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes %systemdrive% .tmp files removed: 0 bytes %systemroot% .tmp files removed: 0 bytes %systemroot%\System32 .tmp files removed: 0 bytes %systemroot%\System32\dllcache .tmp files removed: 0 bytes %systemroot%\System32\drivers .tmp files removed: 0 bytes Windows Temp folder emptied: 23828 bytes %systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 124321870 bytes %systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 0 bytes RecycleBin emptied: 10446203 bytes Total Files Cleaned = 298.00 mb OTL by OldTimer - Version 3.2.69.0 log created on 10122012_204247 Files\Folders moved on Reboot… C:\Documents and Settings\Owner.PETE-05CK9PEMS6\Local Settings\Temporary Internet Files\Content.IE5\WR70GWL5\index[2].htm moved successfully. C:\Documents and Settings\Owner.PETE-05CK9PEMS6\Local Settings\Temporary Internet Files\Content.IE5\8H0R7H53\iframe[1].htm moved successfully. C:\WINDOWS\temp\Perflib_Perfdata_294.dat moved successfully. PendingFileRenameOperations files… Registry entries deleted on Reboot… ————————————– aswMBR version 0.9.9.1665 Copyright© 2011 AVAST Software Run date: 2012-10-12 20:49:03 —————————– 20:49:03.890 OS Version: Windows 5.1.2600 Service Pack 3 20:49:03.890 Number of processors: 1 586 0x209 20:49:03.890 ComputerName: PETE-05CK9PEMS6 UserName: Owner 20:49:05.000 Initialize success 20:49:50.968 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-3 20:49:50.968 Disk 0 Vendor: Size: 0MB BusType: 0 20:49:50.984 Disk 0 MBR read successfully 20:49:50.984 Disk 0 MBR scan 20:49:50.984 Disk 0 Windows XP default MBR code 20:49:50.984 Disk 0 MBR hidden 20:49:50.984 Disk 0 Partition 1 00 DE Dell Utility Dell 4.1 39 MB offset 63 20:49:51.000 Disk 0 Partition 2 80 (A) 07 HPFS/NTFS NTFS 38099 MB offset 80325 20:49:51.046 Disk 0 scanning C:\WINDOWS\system32\drivers 20:50:12.000 Service scanning 20:50:30.734 Modules scanning 20:50:55.234 Disk 0 trace - called modules: 20:50:55.250 ntoskrnl.exe CLASSPNP.SYS disk.sys atapi.sys hal.dll pciide.sys PCIIDEX.SYS 20:50:55.250 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x82b83ab8] 20:50:55.781 3 CLASSPNP.SYS[f8c26fd7] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP0T0L0-3[0x82b5fb00] 20:50:55.781 Scan finished successfully 20:51:09.265 Disk 0 MBR has been saved successfully to "C:\Documents and Settings\Owner.PETE-05CK9PEMS6\Desktop\MBR.dat" 20:51:09.281 The log file has been saved successfully to "C:\Documents and Settings\Owner.PETE-05CK9PEMS6\Desktop\aswMBR.txt"
Hi pfilighera,

Don't worry about Limewire. The leftover file was removed during the previous step. :thumbup:

Please run Eset Online Scanner

Administrator rights are required to run ESET Online Scanner
  • Place a check mark in the box YES, I accept the Terms Of Use
  • Click the Start button.
  • Now click the Install button.
  • Click Start. The scanner engine will initialize and update.
  • Do Not place a check mark in the box beside Remove found threats.
  • Click the Scan button. The scan will now run, please be patient.
  • When the scan finishes click the Details tab.
  • Copy and paste the contents of the C:\Program Files\ESET\log.txt into your next reply.
Next
  • Re-run OTL (it should be located on your desktop).
  • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output.
  • Uncheck the boxes beside LOP Check and Purity Check.
  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
  • When the scan completes, it will open one notepad window. OTL.Txt.
    Note:The log can be located in the OTL. folder on you C:\ drive if they fail to open automatically.
  • Please copy (Edit->Select All, Edit->Copy) the contents of the file, and post it with your next reply.
In your next post please provide the following:
  • ESET log.txt
  • OTL.txt
  • How is the computer running at the moment, any remaining issues?
OTL logfile created on: 10/14/2012 10:54:32 AM - Run 3
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Documents and Settings\Owner.PETE-05CK9PEMS6\Desktop
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

638.00 Mb Total Physical Memory | 271.96 Mb Available Physical Memory | 42.63% Memory free
1.52 Gb Paging File | 1.12 Gb Available in Paging File | 73.27% Paging File free
Paging file location(s): C:\pagefile.sys 960 1920 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 37.21 Gb Total Space | 22.33 Gb Free Space | 60.01% Space Free | Partition Type: NTFS

Computer Name: PETE-05CK9PEMS6 | User Name: Owner | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Program Files\Java\jre7\bin\jqs.exe (Oracle Corporation)
PRC - C:\Documents and Settings\Owner.PETE-05CK9PEMS6\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Norton Security Suite\Engine\6.4.0.9\ccsvchst.exe (Symantec Corporation)
PRC - C:\Program Files\IObit\Advanced SystemCare 5\ASCTray.exe (IObit)
PRC - C:\Program Files\IObit\Advanced SystemCare 5\ASCService.exe (IObit)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe (Musicmatch, Inc.)
PRC - C:\Program Files\Canon\BJCard\Bjmcmng.exe (CANON INC.)


========== Modules (No Company Name) ==========

MOD - C:\Program Files\IObit\Advanced SystemCare 5\madexcept_.bpl ()
MOD - C:\Program Files\IObit\Advanced SystemCare 5\madbasic_.bpl ()
MOD - C:\Program Files\IObit\Advanced SystemCare 5\maddisAsm_.bpl ()
MOD - C:\Program Files\SpywareGuard\spywareguard.dll ()


========== Services (SafeList) ==========

SRV - (Lavasoft Ad-Aware Service) – C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe File not found
SRV - (HidServ) – %SystemRoot%\System32\hidserv.dll File not found
SRV - (AppMgmt) – %SystemRoot%\System32\appmgmts.dll File not found
SRV - (AdobeFlashPlayerUpdateSvc) – C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe (Adobe Systems Incorporated)
SRV - (JavaQuickStarterService) – C:\Program Files\Java\jre7\bin\jqs.exe (Oracle Corporation)
SRV - (MozillaMaintenance) – C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe (Mozilla Foundation)
SRV - (N360) – C:\Program Files\Norton Security Suite\Engine\6.4.0.9\ccSvcHst.exe (Symantec Corporation)
SRV - (AdvancedSystemCareService5) – C:\Program Files\IObit\Advanced SystemCare 5\ASCService.exe (IObit)
SRV - (Bjmcmng) – C:\Program Files\Canon\BJCard\Bjmcmng.exe (CANON INC.)


========== Driver Services (SafeList) ==========

DRV - (WDICA) – File not found
DRV - (PDRFRAME) – File not found
DRV - (PDRELI) – File not found
DRV - (PDFRAME) – File not found
DRV - (PDCOMP) – File not found
DRV - (PCIDump) – File not found
DRV - (lbrtfdc) – File not found
DRV - (i2omgmt) – File not found
DRV - (Changer) – File not found
DRV - (catchme) – C:\DOCUME~1\OWNER~2.PET\LOCALS~1\Temp\catchme.sys File not found
DRV - (NAVEX15) – C:\Documents and Settings\All Users.WINDOWS\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_6.0.0.145\Definitions\VirusDefs\20121013.007\NAVEX15.SYS (Symantec Corporation)
DRV - (NAVENG) – C:\Documents and Settings\All Users.WINDOWS\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_6.0.0.145\Definitions\VirusDefs\20121013.007\NAVENG.SYS (Symantec Corporation)
DRV - (IDSxpx86) – C:\Documents and Settings\All Users.WINDOWS\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_6.0.0.145\Definitions\IPSDefs\20121012.001\IDSXpx86.sys (Symantec Corporation)
DRV - (BHDrvx86) – C:\Documents and Settings\All Users.WINDOWS\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_6.0.0.145\Definitions\BASHDefs\20120928.001\BHDrvx86.sys (Symantec Corporation)
DRV - (eeCtrl) – C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys (Symantec Corporation)
DRV - (EraserUtilRebootDrv) – C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys (Symantec Corporation)
DRV - (SRTSP) – C:\WINDOWS\system32\drivers\N360\0604000.009\srtsp.sys (Symantec Corporation)
DRV - (SRTSPX) – C:\WINDOWS\system32\drivers\N360\0604000.009\srtspx.sys (Symantec Corporation)
DRV - (ccSet_N360) – C:\WINDOWS\system32\drivers\N360\0604000.009\ccsetx86.sys (Symantec Corporation)
DRV - (SymEvent) – C:\WINDOWS\system32\drivers\SYMEVENT.SYS (Symantec Corporation)
DRV - (SymEFA) – C:\WINDOWS\system32\drivers\N360\0604000.009\symefa.sys (Symantec Corporation)
DRV - (SYMTDI) – C:\WINDOWS\system32\drivers\N360\0604000.009\symtdi.sys (Symantec Corporation)
DRV - (SymIRON) – C:\WINDOWS\system32\drivers\N360\0604000.009\ironx86.sys (Symantec Corporation)
DRV - (SymDS) – C:\WINDOWS\system32\drivers\N360\0604000.009\symds.sys (Symantec Corporation)
DRV - (GIDv2) – C:\WINDOWS\System32\drivers\gidv2.sys (StrikeForce Technologies, Inc.)
DRV - (mfehidk) – C:\WINDOWS\system32\drivers\mfehidk.sys (McAfee, Inc.)
DRV - (mfeavfk) – C:\WINDOWS\system32\drivers\mfeavfk.sys (McAfee, Inc.)
DRV - (mfesmfk) – C:\WINDOWS\system32\drivers\mfesmfk.sys (McAfee, Inc.)
DRV - (mfebopk) – C:\WINDOWS\system32\drivers\mfebopk.sys (McAfee, Inc.)
DRV - (mferkdk) – C:\WINDOWS\system32\drivers\mferkdk.sys (McAfee, Inc.)
DRV - (Lbd) – C:\WINDOWS\system32\drivers\Lbd.sys (Lavasoft AB)
DRV - (LMouFlt2) – C:\WINDOWS\system32\drivers\LMouFlt2.Sys (Logitech, Inc.)
DRV - (L8042pr2) – C:\WINDOWS\system32\drivers\L8042pr2.Sys (Logitech, Inc.)
DRV - (PRISM_A02) – C:\WINDOWS\system32\drivers\PRISMA02.sys (GlobespanVirata, Inc.)
DRV - (bcm4sbxp) – C:\WINDOWS\system32\drivers\bcm4sbxp.sys (Broadcom Corporation)
DRV - (OMCI) – C:\WINDOWS\system32\drivers\omci.sys (Dell Computer Corporation)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\..\SearchScopes,DefaultScope =
IE - HKLM\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 1
IE - HKLM\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local;
IE - HKLM\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = http=localhost:7171

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
IE - HKCU\..\SearchScopes,DefaultScope = {AFBCB7E0-F91A-4951-9F31-58FEE57A25C4}
IE - HKCU\..\SearchScopes\{AFBCB7E0-F91A-4951-9F31-58FEE57A25C4}: "URL" = http://www.ask.com/web?q={SEARCHTERMS}&…eo=US&ver;=6
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..browser.search.defaultenginename: "AVG Secure Search"
FF - prefs.js..browser.startup.homepage: "http://yahoo.com/"
FF - prefs.js..extensions.enabledAddons: {BBDA0591-3099-440a-AA10-41764D9DB4DB}:11.1.1.5 - 2
FF - prefs.js..extensions.enabledAddons: {2D3F3651-74B9-4795-BDEC-6DA2F431CB62}:2012.5.7.2
FF - prefs.js..extensions.enabledItems: [removed]:1.5.0
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}:6.0.20
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}:6.0.21
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0025-ABCDEFFEDCBA}:6.0.25
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA}:6.0.26
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0030-ABCDEFFEDCBA}:6.0.30
FF - prefs.js..extensions.enabledItems: [removed]:1.0
FF - prefs.js..extensions.enabledItems: {BBDA0591-3099-440a-AA10-41764D9DB4DB}:10.1.1.8 - 4
FF - prefs.js..keyword.URL: "http://isearch.avg.com/search?cid=%7Ba5ea3c20-188b-49ed-b665-db350aefac21%7D∣=2c4218cf9b1f8cdb73ebc76c13893d49-59affc265ded83ee52c593f95f03fcb30425c566&ds;=AVG&v;=11.0.0.9⟨=en≺=pr&d;=2012-05-06%2001%3A00%3A18&sap;=ku&q;="


FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32_11_4_402_287.dll ()
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.7.2: C:\WINDOWS\system32\npDeployJava1.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.7.2: C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{BBDA0591-3099-440a-AA10-41764D9DB4DB}: C:\Documents and Settings\All Users.WINDOWS\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_6.0.0.145\IPSFFPlgn\ [2012/06/06 15:10:41 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{2D3F3651-74B9-4795-BDEC-6DA2F431CB62}: C:\Documents and Settings\All Users.WINDOWS\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_6.0.0.145\coFFPlgn\ [2012/10/13 17:09:45 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 16.0.1\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2012/10/13 09:31:42 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 16.0.1\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2012/10/13 09:28:18 | 000,000,000 | —D | M]

[2010/07/11 14:16:14 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Owner.PETE-05CK9PEMS6\Application Data\Mozilla\Extensions
[2010/07/11 14:16:14 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Owner.PETE-05CK9PEMS6\Application Data\Mozilla\Extensions\[removed]
[2012/10/13 09:27:41 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Owner.PETE-05CK9PEMS6\Application Data\Mozilla\Firefox\Profiles\qjys52r7.default\extensions
[2012/10/13 09:22:47 | 000,000,000 | —D | M] (Yahoo! Toolbar) – C:\Documents and Settings\Owner.PETE-05CK9PEMS6\Application Data\Mozilla\Firefox\Profiles\qjys52r7.default\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1}
[2012/03/06 21:03:57 | 000,000,000 | —D | M] (Incredibar Toolbar) – C:\Documents and Settings\Owner.PETE-05CK9PEMS6\Application Data\Mozilla\Firefox\Profiles\qjys52r7.default\extensions\[removed]
[2012/10/13 09:27:40 | 000,020,591 | —- | M] () (No name found) – C:\Documents and Settings\Owner.PETE-05CK9PEMS6\Application Data\Mozilla\Firefox\Profiles\qjys52r7.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}.xpi
[2012/03/06 21:03:23 | 000,002,203 | —- | M] () – C:\Documents and Settings\Owner.PETE-05CK9PEMS6\Application Data\Mozilla\Firefox\Profiles\qjys52r7.default\searchplugins\MyStart Search.xml
[2012/10/13 09:31:40 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions
[2012/10/13 09:31:40 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\distribution\extensions
[2012/10/13 09:31:40 | 000,000,000 | —D | M] (Yahoo! Toolbar) – C:\Program Files\Mozilla Firefox\distribution\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1}
[2012/10/13 17:09:45 | 000,000,000 | —D | M] (Norton Toolbar) – C:\DOCUMENTS AND SETTINGS\ALL USERS.WINDOWS\APPLICATION DATA\NORTON\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_6.0.0.145\COFFPLGN
[2012/06/06 15:10:41 | 000,000,000 | —D | M] (Norton Vulnerability Protection) – C:\DOCUMENTS AND SETTINGS\ALL USERS.WINDOWS\APPLICATION DATA\NORTON\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_6.0.0.145\IPSFFPLGN
[2012/10/10 21:06:18 | 000,261,600 | —- | M] (Mozilla Foundation) – C:\Program Files\mozilla firefox\components\browsercomps.dll
[2012/10/10 21:05:38 | 000,002,465 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\bing.xml
[2012/10/10 21:05:38 | 000,002,058 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\twitter.xml

O1 HOSTS File: ([2012/10/12 20:43:05 | 000,000,098 | —- | M]) - C:\WINDOWS\system32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2 - BHO: (SpywareGuardDLBLOCK.CBrowserHelper) - {4A368E80-174F-4872-96B5-0B27DDD11DB2} - C:\Program Files\SpywareGuard\dlprotect.dll ()
O2 - BHO: (Norton Identity Protection) - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files\Norton Security Suite\Engine\6.4.0.9\coieplg.dll (Symantec Corporation)
O2 - BHO: (Norton Vulnerability Protection) - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files\Norton Security Suite\Engine\6.4.0.9\ips\ipsbho.dll (Symantec Corporation)
O2 - BHO: (Java™ Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
O2 - BHO: (WOT Helper) - {C920E44A-7F78-4E64-BDD7-A57026E7FEB7} - C:\Program Files\WOT\WOT.dll ()
O2 - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O3 - HKLM\..\Toolbar: (WOT) - {71576546-354D-41c9-AAE8-31F2EC22BF0D} - C:\Program Files\WOT\WOT.dll ()
O3 - HKLM\..\Toolbar: (Norton Toolbar) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Norton Security Suite\Engine\6.4.0.9\coieplg.dll (Symantec Corporation)
O3 - HKCU\..\Toolbar\WebBrowser: (WOT) - {71576546-354D-41C9-AAE8-31F2EC22BF0D} - C:\Program Files\WOT\WOT.dll ()
O3 - HKCU\..\Toolbar\WebBrowser: (Norton Toolbar) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Norton Security Suite\Engine\6.4.0.9\coieplg.dll (Symantec Corporation)
O4 - HKLM..\Run: [GIDDesktop] C:\Program Files\SFT\GuardedID\gidd.exe (StrikeForce Technologies Inc.)
O4 - HKLM..\Run: [MMTray] C:\Program Files\Musicmatch\Musicmatch Jukebox\mm_tray.exe (Musicmatch, Inc.)
O4 - HKCU..\Run: [Advanced SystemCare 5] C:\Program Files\IObit\Advanced SystemCare 5\ASCTray.exe (IObit)
O4 - HKLM..\RunOnce: [AvgUninstallURL] C:\WINDOWS\System32\cmd.exe (Microsoft Corporation)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O16 - DPF: {01012101-5E80-11D8-9E86-0007E96C65AE} http://www.comcastsupport.com/oneclickfix/tgctlsr.cab (SupportSoft Script Runner Class)
O16 - DPF: {31435657-9980-0010-8000-00AA00389B71} http://download.microsoft.com/download/e/2…78f/wvc1dmo.cab (Reg Error: Key error.)
O16 - DPF: {33564D57-0000-0010-8000-00AA00389B71} http://download.microsoft.com/download/F/6…922/wmv9VCM.CAB (Reg Error: Key error.)
O16 - DPF: {33564D57-9980-0010-8000-00AA00389B71} http://download.microsoft.com/download/D/0…D0C/wmv9dmo.cab (Reg Error: Key error.)
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} http://update.microsoft.com/windowsupdate/…b?1136593632451 (WUWebControl Class)
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} http://download.eset.com/special/eos-beta/OnlineScanner.cab (OnlineScanner Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Reg Error: Value error.)
O16 - DPF: {CAFEEFAC-0016-0000-0030-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_30)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_30)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab (Shockwave Flash Object)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 75.75.75.75 75.75.76.76
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{45D6A31F-96C2-4D92-B3F2-4ADBAE67D96B}: DhcpNameServer = [removed] [removed]
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{5479463A-91E8-4138-B3CE-765B64CB7D71}: DhcpNameServer = 75.75.75.75 75.75.76.76
O18 - Protocol\Handler\wot {C2A44D6B-CB9F-4663-88A6-DF2F26E4D952} - C:\Program Files\WOT\WOT.dll ()
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) - C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O20 - Winlogon\Notify\GIDLogonXP: DllName - (GIDLogonXP.dll) - C:\WINDOWS\System32\GIDLogonXP.dll (StrikeForce Technologies Inc)
O20 - Winlogon\Notify\igfxcui: DllName - (igfxsrvc.dll) - C:\WINDOWS\System32\igfxsrvc.dll (Intel Corporation)
O24 - Desktop WallPaper: C:\Documents and Settings\Owner.PETE-05CK9PEMS6\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Owner.PETE-05CK9PEMS6\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O28 - HKLM ShellExecuteHooks: {81559C35-8464-49F7-BB0E-07A383BEF910} - C:\Program Files\SpywareGuard\spywareguard.dll ()
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2005/12/31 15:30:52 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O34 - HKLM BootExecute: (lsdelete)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)

========== Files/Folders - Created Within 30 Days ==========

[2012/10/14 08:55:35 | 009,575,864 | —- | C] (Adobe Systems Incorporated) – C:\WINDOWS\System32\FlashPlayerInstaller.exe
[2012/10/14 08:44:41 | 000,000,000 | —D | C] – C:\Program Files\ESET
[2012/10/14 08:39:40 | 000,696,760 | —- | C] (Adobe Systems Incorporated) – C:\WINDOWS\System32\FlashPlayerApp.exe
[2012/10/14 08:38:49 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users.WINDOWS\Application Data\Adobe
[2012/10/13 16:20:52 | 000,000,000 | —D | C] – C:\Documents and Settings\Owner.PETE-05CK9PEMS6\Local Settings\Application Data\Sun
[2012/10/13 09:28:18 | 000,821,736 | —- | C] (Oracle Corporation) – C:\WINDOWS\System32\npDeployJava1.dll
[2012/10/13 09:28:18 | 000,246,760 | —- | C] (Oracle Corporation) – C:\WINDOWS\System32\javaws.exe
[2012/10/13 09:27:27 | 000,174,056 | —- | C] (Oracle Corporation) – C:\WINDOWS\System32\javaw.exe
[2012/10/13 09:27:27 | 000,174,056 | —- | C] (Oracle Corporation) – C:\WINDOWS\System32\java.exe
[2012/10/13 09:27:27 | 000,093,672 | —- | C] (Oracle Corporation) – C:\WINDOWS\System32\WindowsAccessBridge.dll
[2012/10/13 09:24:48 | 000,000,000 | —D | C] – C:\Documents and Settings\Owner.PETE-05CK9PEMS6\My Documents\Downloads
[2012/10/13 09:22:19 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users.WINDOWS\Application Data\Mozilla
[2012/10/13 09:22:16 | 000,000,000 | —D | C] – C:\Program Files\Mozilla Maintenance Service
[2012/10/13 09:19:13 | 018,494,856 | —- | C] (Mozilla) – C:\Documents and Settings\Owner.PETE-05CK9PEMS6\Desktop\Firefox Setup 16.0.1.exe
[2012/10/12 20:48:29 | 004,731,392 | —- | C] (AVAST Software) – C:\Documents and Settings\Owner.PETE-05CK9PEMS6\Desktop\aswMBR.exe
[2012/10/12 20:42:47 | 000,000,000 | —D | C] – C:\_OTL
[2012/10/08 20:07:20 | 000,602,112 | —- | C] (OldTimer Tools) – C:\Documents and Settings\Owner.PETE-05CK9PEMS6\Desktop\OTL.exe
[2012/09/23 13:57:52 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users.WINDOWS\Application Data\IObit
[2012/09/23 13:56:53 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users.WINDOWS\Start Menu\Programs\Advanced SystemCare 5
[2012/09/23 13:55:11 | 027,669,608 | —- | C] (IObit ) – C:\Documents and Settings\Owner.PETE-05CK9PEMS6\Desktop\asc-setup.exe
[2012/09/23 13:54:13 | 000,000,000 | RH-D | C] – C:\Documents and Settings\Owner.PETE-05CK9PEMS6\Recent
[2012/09/23 13:52:32 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users.WINDOWS\Start Menu\Programs\CCleaner
[2012/09/23 13:52:29 | 000,000,000 | —D | C] – C:\Program Files\CCleaner
[2012/09/23 13:51:31 | 003,927,560 | —- | C] (Piriform Ltd) – C:\Documents and Settings\Owner.PETE-05CK9PEMS6\Desktop\ccsetup322.exe

========== Files - Modified Within 30 Days ==========

[2012/10/14 10:54:53 | 000,000,830 | —- | M] () – C:\WINDOWS\tasks\Adobe Flash Player Updater.job
[2012/10/14 08:57:55 | 000,696,760 | —- | M] (Adobe Systems Incorporated) – C:\WINDOWS\System32\FlashPlayerApp.exe
[2012/10/14 08:57:54 | 000,073,656 | —- | M] (Adobe Systems Incorporated) – C:\WINDOWS\System32\FlashPlayerCPLApp.cpl
[2012/10/14 08:55:40 | 009,575,864 | —- | M] (Adobe Systems Incorporated) – C:\WINDOWS\System32\FlashPlayerInstaller.exe
[2012/10/13 21:17:31 | 000,000,422 | -H– | M] () – C:\WINDOWS\tasks\User_Feed_Synchronization-{96E858C2-BB80-4CA6-A945-5D7F401AA939}.job
[2012/10/13 17:08:44 | 000,002,206 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2012/10/13 17:08:22 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2012/10/13 09:31:45 | 000,000,742 | —- | M] () – C:\Documents and Settings\Owner.PETE-05CK9PEMS6\Application Data\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox.lnk
[2012/10/13 09:31:45 | 000,000,724 | —- | M] () – C:\Documents and Settings\All Users.WINDOWS\Desktop\Mozilla Firefox.lnk
[2012/10/13 09:26:50 | 000,093,672 | —- | M] (Oracle Corporation) – C:\WINDOWS\System32\WindowsAccessBridge.dll
[2012/10/13 09:26:47 | 000,246,760 | —- | M] (Oracle Corporation) – C:\WINDOWS\System32\javaws.exe
[2012/10/13 09:26:47 | 000,174,056 | —- | M] (Oracle Corporation) – C:\WINDOWS\System32\javaw.exe
[2012/10/13 09:26:47 | 000,174,056 | —- | M] (Oracle Corporation) – C:\WINDOWS\System32\java.exe
[2012/10/13 09:26:47 | 000,143,872 | —- | M] (Oracle Corporation) – C:\WINDOWS\System32\javacpl.cpl
[2012/10/13 09:26:46 | 000,821,736 | —- | M] (Oracle Corporation) – C:\WINDOWS\System32\npDeployJava1.dll
[2012/10/13 09:26:46 | 000,746,984 | —- | M] (Oracle Corporation) – C:\WINDOWS\System32\deployJava1.dll
[2012/10/13 09:19:20 | 018,494,856 | —- | M] (Mozilla) – C:\Documents and Settings\Owner.PETE-05CK9PEMS6\Desktop\Firefox Setup 16.0.1.exe
[2012/10/12 20:51:09 | 000,000,512 | —- | M] () – C:\Documents and Settings\Owner.PETE-05CK9PEMS6\Desktop\MBR.dat
[2012/10/12 20:48:29 | 004,731,392 | —- | M] (AVAST Software) – C:\Documents and Settings\Owner.PETE-05CK9PEMS6\Desktop\aswMBR.exe
[2012/10/12 20:43:05 | 000,000,098 | —- | M] () – C:\WINDOWS\System32\drivers\etc\Hosts
[2012/10/12 20:28:12 | 000,538,327 | —- | M] () – C:\Documents and Settings\Owner.PETE-05CK9PEMS6\Desktop\AdwCleaner.exe
[2012/10/11 07:07:00 | 000,000,472 | —- | M] () – C:\WINDOWS\tasks\Ad-Aware Update (Weekly).job
[2012/10/10 23:45:13 | 000,031,776 | —- | M] () – C:\{3CAB558C-0424-4399-AC7E-182613966719}
[2012/10/10 03:57:51 | 000,001,920 | —- | M] () – C:\Documents and Settings\All Users.WINDOWS\Desktop\Norton Security Suite.LNK
[2012/10/10 03:57:20 | 000,693,941 | —- | M] () – C:\WINDOWS\System32\drivers\N360\0604000.009\Cat.DB
[2012/10/10 03:56:40 | 000,009,103 | —- | M] () – C:\WINDOWS\System32\drivers\N360\0604000.009\VT20121002.018
[2012/10/10 03:08:34 | 000,001,393 | —- | M] () – C:\WINDOWS\imsins.BAK
[2012/10/08 20:07:20 | 000,602,112 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Owner.PETE-05CK9PEMS6\Desktop\OTL.exe
[2012/10/08 18:06:46 | 000,000,784 | —- | M] () – C:\Documents and Settings\All Users.WINDOWS\Desktop\Malwarebytes Anti-Malware.lnk
[2012/10/01 15:45:02 | 000,000,172 | —- | M] () – C:\WINDOWS\System32\drivers\N360\0604000.009\isolate.ini
[2012/09/23 13:57:09 | 000,000,925 | —- | M] () – C:\Documents and Settings\All Users.WINDOWS\Desktop\Uninstaller.lnk
[2012/09/23 13:57:08 | 000,000,874 | —- | M] () – C:\Documents and Settings\All Users.WINDOWS\Desktop\Advanced SystemCare 5.lnk
[2012/09/23 13:57:01 | 000,000,892 | —- | M] () – C:\Documents and Settings\Owner.PETE-05CK9PEMS6\Application Data\Microsoft\Internet Explorer\Quick Launch\Advanced SystemCare 5.lnk
[2012/09/23 13:55:19 | 027,669,608 | —- | M] (IObit ) – C:\Documents and Settings\Owner.PETE-05CK9PEMS6\Desktop\asc-setup.exe
[2012/09/23 13:52:31 | 000,000,682 | —- | M] () – C:\Documents and Settings\All Users.WINDOWS\Desktop\CCleaner.lnk
[2012/09/23 13:51:33 | 003,927,560 | —- | M] (Piriform Ltd) – C:\Documents and Settings\Owner.PETE-05CK9PEMS6\Desktop\ccsetup322.exe

========== Files Created - No Company Name ==========

[2012/10/14 08:39:43 | 000,000,830 | —- | C] () – C:\WINDOWS\tasks\Adobe Flash Player Updater.job
[2012/10/13 09:22:23 | 000,000,724 | —- | C] () – C:\Documents and Settings\All Users.WINDOWS\Desktop\Mozilla Firefox.lnk
[2012/10/13 09:22:22 | 000,000,730 | —- | C] () – C:\Documents and Settings\All Users.WINDOWS\Start Menu\Programs\Mozilla Firefox.lnk
[2012/10/12 20:51:09 | 000,000,512 | —- | C] () – C:\Documents and Settings\Owner.PETE-05CK9PEMS6\Desktop\MBR.dat
[2012/10/12 20:28:12 | 000,538,327 | —- | C] () – C:\Documents and Settings\Owner.PETE-05CK9PEMS6\Desktop\AdwCleaner.exe
[2012/10/10 23:45:13 | 000,031,776 | —- | C] () – C:\{3CAB558C-0424-4399-AC7E-182613966719}
[2012/10/10 03:57:51 | 000,001,920 | —- | C] () – C:\Documents and Settings\All Users.WINDOWS\Desktop\Norton Security Suite.LNK
[2012/10/10 03:06:59 | 000,001,393 | —- | C] () – C:\WINDOWS\imsins.BAK
[2012/10/08 18:06:46 | 000,000,784 | —- | C] () – C:\Documents and Settings\All Users.WINDOWS\Desktop\Malwarebytes Anti-Malware.lnk
[2012/09/23 13:57:09 | 000,000,925 | —- | C] () – C:\Documents and Settings\All Users.WINDOWS\Desktop\Uninstaller.lnk
[2012/09/23 13:57:08 | 000,000,874 | —- | C] () – C:\Documents and Settings\All Users.WINDOWS\Desktop\Advanced SystemCare 5.lnk
[2012/09/23 13:57:00 | 000,000,892 | —- | C] () – C:\Documents and Settings\Owner.PETE-05CK9PEMS6\Application Data\Microsoft\Internet Explorer\Quick Launch\Advanced SystemCare 5.lnk
[2012/09/23 13:52:31 | 000,000,682 | —- | C] () – C:\Documents and Settings\All Users.WINDOWS\Desktop\CCleaner.lnk
[2012/02/15 07:24:01 | 000,003,072 | —- | C] () – C:\WINDOWS\System32\iacenc.dll
[2011/04/20 19:21:31 | 000,000,160 | —- | C] () – C:\Documents and Settings\All Users.WINDOWS\Application Data\~18014004
[2011/04/20 19:21:31 | 000,000,120 | —- | C] () – C:\Documents and Settings\All Users.WINDOWS\Application Data\~18014004r
[2011/04/20 19:19:48 | 000,000,392 | —- | C] () – C:\Documents and Settings\All Users.WINDOWS\Application Data\18014004
[2009/02/06 19:55:45 | 000,076,288 | —- | C] () – C:\Documents and Settings\Owner.PETE-05CK9PEMS6\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini

========== ZeroAccess Check ==========

[2012/07/04 14:15:49 | 000,000,227 | RHS- | M] () – C:\WINDOWS\assembly\Desktop.ini

[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]

[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\System32\shdocvw.dll – [2008/04/13 20:12:05 | 001,499,136 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = C:\WINDOWS\System32\wbem\fastprox.dll – [2009/02/09 08:10:48 | 000,473,600 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
"" = C:\WINDOWS\System32\wbem\wbemess.dll – [2008/04/13 20:12:08 | 000,273,920 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Both

========== Hard Links - Junction Points - Mount Points - Symbolic Links ==========
[C:\WINDOWS\$NtUninstallKB12858$] -> Error: Cannot create file handle -> Unknown point type

========== Alternate Data Streams ==========

@Alternate Data Stream - 125 bytes -> C:\Documents and Settings\All Users.WINDOWS\Application Data\TEMP:5C321E34

< End of report >
———————————————————-

ESETSmartInstaller@High as downloader log:
all ok
# version=7
# OnlineScannerApp.exe=1.0.0.1
# OnlineScanner.ocx=1.0.0.6583
# api_version=3.0.2
# EOSSerial=61c8c4595b33e94d875760d419fa2cc0
# end=finished
# remove_checked=false
# archives_checked=false
# unwanted_checked=true
# unsafe_checked=false
# antistealth_checked=true
# utc_time=2012-10-14 02:33:35
# local_time=2012-10-14 10:33:35 (-0500, Eastern Daylight Time)
# country="United States"
# lang=1033
# osver=5.1.2600 NT Service Pack 3
# compatibility_mode=1024 16777215 100 0 32412987 32412987 0 0
# compatibility_mode=3589 16777213 80 74 0 100795292 0 0
# compatibility_mode=8192 67108863 100 0 0 0 0 0
# scanned=49787
# found=1
# cleaned=0
# scan_time=6019
C:\_OTL\MovedFiles\10122012_204247\C_WINDOWS\System32\drivers\etc\hosts Win32/Qhost trojan (unable to clean) 00000000000000000000000000000000 I
—————————————————-

I am using firefox when working on this computer and , though it takes longer to launch, is much quicker than ie. i did notice something was found on the one scan. let me know what you think.
Hi pfilighera,

The file found during the ESET scan is in a quarantine folder and will be removed when we clean up at the end of the process.

Next

Run OTL.exe
  • Copy/paste the following text written inside of the code box into the Custom Scans/Fixes box located at the bottom of OTL

    :OTL
    FF - prefs.js..browser.search.defaultenginename: "AVG Secure Search"
    FF - prefs.js..extensions.enabledItems: [removed]:1.5.0
    FF - prefs.js..keyword.URL: "http://isearch.avg.com/search?cid=%7Ba5ea3c20-188b-49ed-b665-db350aefac21%7D&mid=2c4218cf9b1f8cdb73ebc76c13893d49-59affc265ded83ee52c593f95f03fcb30425c566&ds=AVG&v=11.0.0.9&lang=en&pr=pr&d=2012-05-06%2001%3A00%3A18&sap=ku&q="
    [2012/03/06 21:03:57 | 000,000,000 | —D | M] (Incredibar Toolbar) – C:\Documents and Settings\Owner.PETE-05CK9PEMS6\Application Data\Mozilla\Firefox\Profiles\qjys52r7.default\extensions\[removed]
    [2012/03/06 21:03:23 | 000,002,203 | —- | M] () – C:\Documents and Settings\Owner.PETE-05CK9PEMS6\Application Data\Mozilla\Firefox\Profiles\qjys52r7.default\searchplugins\MyStart Search.xml
    [2011/04/20 19:21:31 | 000,000,160 | —- | C] () – C:\Documents and Settings\All Users.WINDOWS\Application Data\~18014004
    [2011/04/20 19:21:31 | 000,000,120 | —- | C] () – C:\Documents and Settings\All Users.WINDOWS\Application Data\~18014004r
    [2011/04/20 19:19:48 | 000,000,392 | —- | C] () – C:\Documents and Settings\All Users.WINDOWS\Application Data\18014004
    
    :Commands
    [purity]
    [createrestorepoint]
    [emptytemp]
    [Reboot]
  • Then click the Run Fix button at the top
  • Let the program run unhindered, reboot when it is done
  • Then post a new OTL log ( don't check the boxes beside LOP Check or Purity this time )

In your next post please provide the following:
  • OTL.txt
  • Tell me how your computer is running at the moment, any remaining issues?
All processes killed ========== OTL ========== Prefs.js: "AVG Secure Search" removed from browser.search.defaultenginename Prefs.js: [removed]:1.5.0 removed from extensions.enabledItems Prefs.js: "http://isearch.avg.com/search?cid=%7Ba5ea3c20-188b-49ed-b665-db350aefac21%7D&mid=2c4218cf9b1f8cdb73ebc76c13893d49-59affc265ded83ee52c593f95f03fcb30425c566&ds=AVG&v=11.0.0.9&lang=en&pr=pr&d=2012-05-06%2001%3A00%3A18&sap=ku&q=" removed from keyword.URL C:\Documents and Settings\Owner.PETE-05CK9PEMS6\Application Data\Mozilla\Firefox\Profiles\qjys52r7.default\extensions\[removed]\defaults\preferences folder moved successfully. C:\Documents and Settings\Owner.PETE-05CK9PEMS6\Application Data\Mozilla\Firefox\Profiles\qjys52r7.default\extensions\[removed]\defaults folder moved successfully. C:\Documents and Settings\Owner.PETE-05CK9PEMS6\Application Data\Mozilla\Firefox\Profiles\qjys52r7.default\extensions\[removed]\content\imgs\flgs folder moved successfully. C:\Documents and Settings\Owner.PETE-05CK9PEMS6\Application Data\Mozilla\Firefox\Profiles\qjys52r7.default\extensions\[removed]\content\imgs folder moved successfully. C:\Documents and Settings\Owner.PETE-05CK9PEMS6\Application Data\Mozilla\Firefox\Profiles\qjys52r7.default\extensions\[removed]\content folder moved successfully. C:\Documents and Settings\Owner.PETE-05CK9PEMS6\Application Data\Mozilla\Firefox\Profiles\qjys52r7.default\extensions\[removed] folder moved successfully. C:\Documents and Settings\Owner.PETE-05CK9PEMS6\Application Data\Mozilla\Firefox\Profiles\qjys52r7.default\searchplugins\MyStart Search.xml moved successfully. C:\Documents and Settings\All Users.WINDOWS\Application Data\~18014004 moved successfully. C:\Documents and Settings\All Users.WINDOWS\Application Data\~18014004r moved successfully. C:\Documents and Settings\All Users.WINDOWS\Application Data\18014004 moved successfully. ========== COMMANDS ========== Restore point Set: OTL Restore Point [EMPTYTEMP] User: Administrator ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes User: Administrator.PETE-05CK9PEMS6 ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes User: All Users User: All Users.WINDOWS User: Default User ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes User: Default User.WINDOWS ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes User: LocalService ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes ->Flash cache emptied: 0 bytes User: LocalService.NT AUTHORITY ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes User: LocalService.NT AUTHORITY.000 ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 33170 bytes ->Flash cache emptied: 0 bytes User: NetworkService ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes User: NetworkService.NT AUTHORITY ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes User: NetworkService.NT AUTHORITY.000 ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 33170 bytes ->Flash cache emptied: 0 bytes User: Owner ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes ->Flash cache emptied: 0 bytes User: Owner.PETE-05CK9PEMS6 ->Temp folder emptied: 1054 bytes ->Temporary Internet Files folder emptied: 149883679 bytes ->Java cache emptied: 0 bytes ->FireFox cache emptied: 60512181 bytes ->Flash cache emptied: 2106 bytes User: Owner.PETE-OZKKR0BYRK ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes %systemdrive% .tmp files removed: 0 bytes %systemroot% .tmp files removed: 0 bytes %systemroot%\System32 .tmp files removed: 0 bytes %systemroot%\System32\dllcache .tmp files removed: 0 bytes %systemroot%\System32\drivers .tmp files removed: 0 bytes Windows Temp folder emptied: 16639 bytes %systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 0 bytes %systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 0 bytes RecycleBin emptied: 333 bytes Total Files Cleaned = 201.00 mb OTL by OldTimer - Version 3.2.69.0 log created on 10152012_200139 Files\Folders moved on Reboot… File\Folder C:\WINDOWS\temp\Perflib_Perfdata_784.dat not found! PendingFileRenameOperations files… Registry entries deleted on Reboot… ————————————————————————————— No issues to speak of. Will wait for your response.
Hi pfilighera,

Download and run ComboFix (select one of the following locations)

Link 1
Link 2

* IMPORTANT !!! Save ComboFix.exe to your Desktop
  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools
  • See this Link for programs that need to be disabled and instruction on how to disable them.
    (remember to re-enable them when we're done)
  • Double click on ComboFix.exe & follow the prompts.
  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.
  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.
**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue its malware removal procedures.

[external image: Posted Image]


Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]


Click on Yes, to continue scanning for malware.

Note: Do not mouse-click combofix's window while it is running. That may cause it to stall.

When finished, it will produce a log. Please include the ComboFix.txt in your next reply. It can be found at C:\ComboFix.txt
having some trouble w/ combofix. doesn't seem to let me save it. just starts to run and then internet connection is lost. not sure what's going on but will try again tomorrow night or saturday. internet fine in living room. sorry for delay.
Hi pfilighera,

Download Combofix from any of the links provided in my previous post but rename it to pfiligheracf.exe before saving it to your desktop.

Just post when you can.
yes. just figured out that downloading is different in foxfire than in ie. did save combofix to desktop. took a long time to scan because rootkit.zeroaccess apparantly has imbedded itself on the ip. Anyway, the log is as follows:

ComboFix 12-10-22.02 - Owner 10/22/2012 21:38:27.12.1 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.638.439 [GMT -4:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
AV: Norton Security Suite *Disabled/Updated* {E10A9785-9598-4754-B552-92431C1C35F8}
FW: Norton Security Suite *Disabled* {7C21A4C9-F61F-4AC4-B722-A6E19C16F220}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\documents and settings\All Users.WINDOWS\Application Data\TEMP
C:\w.bat
c:\windows\$NtUninstallKB12858$
c:\windows\$NtUninstallKB12858$\3021056496
c:\windows\system32\64dlls.exe
c:\windows\system32\dllcache\wmpvis.dll
c:\windows\system32\FlashPlayerInstaller.exe
.
.
((((((((((((((((((((((((( Files Created from 2012-09-23 to 2012-10-23 )))))))))))))))))))))))))))))))
.
.
2012-10-20 12:53 . 2012-10-20 12:53 ——– d—–w- C:\N360_BACKUP
2012-10-14 12:44 . 2012-10-14 12:44 ——– d—–w- c:\program files\ESET
2012-10-14 12:39 . 2012-10-14 12:57 696760 —-a-w- c:\windows\system32\FlashPlayerApp.exe
2012-10-13 20:20 . 2012-10-13 20:20 ——– d—–w- c:\documents and settings\Owner.PETE-05CK9PEMS6\Local Settings\Application Data\Sun
2012-10-13 13:31 . 2012-10-11 08:39 65536 —-a-w- c:\program files\Mozilla Firefox\distribution\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1}\components\XPATLCOM.dll
2012-10-13 13:31 . 2012-10-11 01:06 261600 —-a-w- c:\program files\Mozilla Firefox\components\browsercomps.dll
2012-10-13 13:28 . 2012-10-13 13:26 821736 —-a-w- c:\windows\system32\npDeployJava1.dll
2012-10-13 13:27 . 2012-10-13 13:26 93672 —-a-w- c:\windows\system32\WindowsAccessBridge.dll
2012-10-13 00:42 . 2012-10-13 00:42 ——– d—–w- C:\_OTL
2012-10-09 19:43 . 2012-10-16 00:39 ——– d—–w- c:\windows\system32\drivers\N360\0604000.009
2012-10-07 20:03 . 2012-10-07 20:03 ——– d—–w- c:\windows\system32\config\systemprofile\Application Data\IObit
2012-09-23 17:57 . 2012-09-23 17:57 ——– d—–w- c:\documents and settings\All Users.WINDOWS\Application Data\IObit
2012-09-23 17:52 . 2012-09-23 17:52 ——– d—–w- c:\program files\CCleaner
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-10-14 12:57 . 2012-01-19 15:45 73656 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2012-10-13 13:26 . 2011-04-23 17:10 143872 —-a-w- c:\windows\system32\javacpl.cpl
2012-10-13 13:26 . 2010-06-10 12:52 746984 —-a-w- c:\windows\system32\deployJava1.dll
2012-09-07 21:04 . 2009-05-24 23:52 22856 —-a-w- c:\windows\system32\drivers\mbam.sys
2012-08-28 15:14 . 2005-10-21 20:51 916992 —-a-w- c:\windows\system32\wininet.dll
2012-08-28 15:14 . 2003-07-16 20:32 43520 —-a-w- c:\windows\system32\licmgr10.dll
2012-08-28 15:14 . 2003-07-16 20:30 1469440 —-a-w- c:\windows\system32\inetcpl.cpl
2012-08-28 12:07 . 2004-08-04 05:59 385024 —-a-w- c:\windows\system32\html.iec
2012-08-24 13:53 . 2003-07-16 20:51 177664 —-a-w- c:\windows\system32\wintrust.dll
2012-08-21 13:29 . 2003-07-16 20:39 2192896 —-a-w- c:\windows\system32\ntoskrnl.exe
2012-08-21 12:58 . 2002-08-29 01:04 2069632 —-a-w- c:\windows\system32\ntkrnlpa.exe
2012-10-11 01:06 . 2012-10-13 13:31 261600 —-a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Advanced SystemCare 5"="c:\program files\IObit\Advanced SystemCare 5\ASCTray.exe" [2012-05-28 288128]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MMTray"="c:\program files\Musicmatch\Musicmatch Jukebox\mm_tray.exe" [2006-01-19 110592]
"GIDDesktop"="c:\program files\SFT\GuardedID\gidd.exe" [2011-07-05 395528]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2012-07-03 252848]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
"AvgUninstallURL"="start http://www.avg.com/ww.special-uninstallati...10.0.1321" [?]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\GIDLogonXP]
2011-07-05 14:25 53528 —-a-w- c:\windows\system32\GIDLogonXP.dll
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
@="Service"
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users.WINDOWS^Start Menu^Programs^Startup^D-link AirPlus G DWL-G120 Wireless USB.lnk]
path=c:\documents and settings\All Users.WINDOWS\Start Menu\Programs\Startup\D-link AirPlus G DWL-G120 Wireless USB.lnk
backup=c:\windows\pss\D-link AirPlus G DWL-G120 Wireless USB.lnkCommon Startup
.
[HKLM\~\startupfolder\C:^Documents and Settings^Owner.PETE-05CK9PEMS6^Start Menu^Programs^Startup^SpywareGuard.lnk]
path=c:\documents and settings\Owner.PETE-05CK9PEMS6\Start Menu\Programs\Startup\SpywareGuard.lnk
backup=c:\windows\pss\SpywareGuard.lnkStartup
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BJLaunchEXE]
2002-03-14 14:41 630784 —-a-w- c:\program files\Canon\BJCard\BJLaunch.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
2008-04-14 00:12 15360 —-a-w- c:\windows\system32\ctfmon.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HotKeysCmds]
2005-10-19 12:59 126976 —-a-w- c:\windows\system32\hkcmd.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IgfxTray]
2005-10-19 12:59 155648 —-a-w- c:\windows\system32\igfxtray.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Logitech Utility]
2003-11-26 17:50 19968 ——w- c:\windows\LOGI_MWX.EXE
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MimBoot]
2006-01-19 16:06 11776 —-a-w- c:\progra~1\MUSICM~1\MUSICM~1\mimboot.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MMTray]
2006-01-19 16:06 110592 —-a-w- c:\program files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
2008-04-14 00:12 1695232 —-a-w- c:\program files\Messenger\msmsgs.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
2012-07-03 13:04 252848 —-a-w- c:\program files\Common Files\Java\Java Update\jusched.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
.
R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [5/21/2009 7:07 AM 64160]
R0 SymDS;Symantec Data Store;c:\windows\system32\drivers\N360\0604000.009\symds.sys [10/9/2012 3:43 PM 340088]
R0 SymEFA;Symantec Extended File Attributes;c:\windows\system32\drivers\N360\0604000.009\symefa.sys [10/9/2012 3:43 PM 924320]
R1 BHDrvx86;BHDrvx86;c:\documents and settings\All Users.WINDOWS\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_6.0.0.145\Definitions\BASHDefs\20120928.001\BHDrvx86.sys [10/1/2012 12:36 PM 995488]
R1 ccSet_N360;Norton Security Suite Settings Manager;c:\windows\system32\drivers\N360\0604000.009\ccsetx86.sys [10/9/2012 3:43 PM 132768]
R1 GIDv2;GIDv2;c:\windows\system32\drivers\gidv2.sys [7/4/2012 2:40 PM 25232]
R1 SymIRON;Symantec Iron Driver;c:\windows\system32\drivers\N360\0604000.009\ironx86.sys [10/9/2012 3:43 PM 149624]
R2 AdvancedSystemCareService5;Advanced SystemCare Service 5;c:\program files\IObit\Advanced SystemCare 5\ASCService.exe [9/23/2012 1:56 PM 913792]
R2 N360;Norton Security Suite;c:\program files\Norton Security Suite\Engine\6.4.0.9\ccsvchst.exe [10/9/2012 3:43 PM 138272]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [10/8/2012 6:12 PM 106656]
R3 IDSxpx86;IDSxpx86;c:\documents and settings\All Users.WINDOWS\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_6.0.0.145\Definitions\IPSDefs\20121020.002\IDSXpx86.sys [10/22/2012 7:49 PM 373728]
S2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;"c:\program files\Lavasoft\Ad-Aware\AAWService.exe" –> c:\program files\Lavasoft\Ad-Aware\AAWService.exe [?]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [10/14/2012 8:39 AM 250808]
S3 MozillaMaintenance;Mozilla Maintenance Service;c:\program files\Mozilla Maintenance Service\maintenanceservice.exe [10/13/2012 9:22 AM 115168]
.
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{9191979D-821C-4EA8-B021-2DA1D859A7C5}-3Reg]
2011-07-05 14:26 435976 —-a-w- c:\program files\SFT\GuardedID\GIDI.exe
.
Contents of the 'Scheduled Tasks' folder
.
2012-10-22 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-10-14 12:59]
.
2012-10-22 c:\windows\Tasks\User_Feed_Synchronization-{96E858C2-BB80-4CA6-A945-5D7F401AA939}.job
- c:\windows\system32\msfeedssync.exe [2006-10-17 08:31]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.yahoo.com/
TCP: DhcpNameServer = 75.75.75.75 75.75.76.76
FF - ProfilePath - c:\documents and settings\Owner.PETE-05CK9PEMS6\Application Data\Mozilla\Firefox\Profiles\qjys52r7.default\
FF - prefs.js: browser.startup.homepage - hxxp://yahoo.com/
FF - ExtSQL: 2012-09-13 20:43; {20a82645-c095-46ed-80e3-08825760534b}; c:\documents and settings\Owner.PETE-05CK9PEMS6\Application Data\Mozilla\Firefox\Profiles\qjys52r7.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}.xpi
FF - ExtSQL: 2012-10-12 20:46; {2D3F3651-74B9-4795-BDEC-6DA2F431CB62}; c:\documents and settings\All Users.WINDOWS\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_6.0.0.145\coFFPlgn
FF - ExtSQL: 2012-10-12 21:09; {BBDA0591-3099-440a-AA10-41764D9DB4DB}; c:\documents and settings\All Users.WINDOWS\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_6.0.0.145\IPSFFPlgn
FF - ExtSQL: 2012-10-13 09:22; {635abd67-4fe9-1b23-4f01-e679fa7484c1}; c:\documents and settings\Owner.PETE-05CK9PEMS6\Application Data\Mozilla\Firefox\Profiles\qjys52r7.default\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1}
FF - ExtSQL: !HIDDEN! 2012-07-06 10:25; {20a82645-c095-46ed-80e3-08825760534b}; c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
FF - user.js: extensions.incredibar_i.newTab - false
FF - user.js: extensions.incredibar_i.tlbrSrchUrl - hxxp://mystart.Incredibar.com/?a=6PQqwKDwVP&loc=IB_TB&i=26&search=
FF - user.js: extensions.incredibar_i.id - 103ded2f000000000000000f1f4aa51e
FF - user.js: extensions.incredibar_i.hardId - 103ded2f000000000000000f1f4aa51e
FF - user.js: extensions.incredibar_i.instlDay - 15406
FF - user.js: extensions.incredibar_i.vrsn - [removed]
FF - user.js: extensions.incredibar_i.vrsni - [removed]
FF - user.js: extensions.incredibar_i.vrsnTs - 1.5.3.2720:03
FF - user.js: extensions.incredibar_i.prtnrId - Incredibar
FF - user.js: extensions.incredibar_i.prdct - incredibar
FF - user.js: extensions.incredibar_i.aflt - orgnl
FF - user.js: extensions.incredibar_i.smplGrp - none
FF - user.js: extensions.incredibar_i.tlbrId - base
FF - user.js: extensions.incredibar_i.instlRef -
FF - user.js: extensions.incredibar_i.dfltLng -
FF - user.js: extensions.incredibar_i.excTlbr - false
FF - user.js: extensions.incredibar_i.ms_url_id -
FF - user.js: extensions.incredibar_i.upn2 - 6PQqwKDwVP
FF - user.js: extensions.incredibar_i.upn2n - 92542495433442473
FF - user.js: extensions.incredibar_i.productid - 26
FF - user.js: extensions.incredibar_i.installerproductid - 26
FF - user.js: extensions.incredibar_i.did - 10606
FF - user.js: extensions.incredibar_i.ppd - 9
.
- - - - ORPHANS REMOVED - - - -
.
MSConfigStartUp-Ad-Watch - c:\program files\Lavasoft\Ad-Aware\AAWTray.exe
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2012-10-22 22:00
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes …
.
scanning hidden autostart entries …
.
scanning hidden files …
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
Stealth MBR rootkit/Mebroot/Sinowal/TDL4 detector 0.4.2 by Gmer, http://www.gmer.net
Windows 5.1.2600
.
CreateFile("\\.\PHYSICALDRIVE0"): The process cannot access the file because it is being used by another process.
device: opened successfully
user: error reading MBR
kernel: MBR read successfully
user != kernel MBR !!!
.
**************************************************************************
.
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\N360]
"ImagePath"="\"c:\program files\Norton Security Suite\Engine\6.4.0.9\ccSvcHst.exe\" /s \"N360\" /m \"c:\program files\Norton Security Suite\Engine\6.4.0.9\diMaster.dll\" /prefetch:1"
.
——————— LOCKED REGISTRY KEYS ———————
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil32_11_4_402_287_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil32_11_4_402_287_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
——————— DLLs Loaded Under Running Processes ———————
.
- - - - - - - > 'winlogon.exe'(644)
c:\windows\system32\GIDLogonXP.dll
c:\windows\system32\GIDHookLogon.dll
c:\windows\system32\GIDBIN1.dll
c:\windows\system32\WININET.dll
.
- - - - - - - > 'explorer.exe'(3108)
c:\windows\system32\WININET.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
———————— Other Running Processes ————————
.
c:\program files\Canon\BJCard\Bjmcmng.exe
c:\program files\Java\jre7\bin\jqs.exe
c:\program files\Common Files\Java\Java Update\jucheck.exe
.
**************************************************************************
.
Completion time: 2012-10-22 22:12:39 - machine was rebooted
ComboFix-quarantined-files.txt 2012-10-23 02:12
ComboFix2.txt 2011-04-23 16:41
.
Pre-Run: 22,283,022,336 bytes free
Post-Run: 22,937,100,288 bytes free
.
- - End Of File - - 6ED1DCF4BC9AF9F2EE627E0DC6421A8F
————————————————————————————————————-

some problems with email opening. not sure if that's an issue for you. the computer stalled a couple of times and ran slow. i'm sure that's a common symptom.
Hi pfilighera,

Run OTL.exe
  • Copy/paste the following text written inside of the code box into the Custom Scans/Fixes box located at the bottom of OTL

    :OTL
    FF - user.js: extensions.incredibar_i.newTab - false
    FF - user.js: extensions.incredibar_i.tlbrSrchUrl - hxxp://mystart.Incredibar.com/?a=6PQqwKDwVP&loc=IB_TB&i=26&search=
    FF - user.js: extensions.incredibar_i.id - 103ded2f000000000000000f1f4aa51e
    FF - user.js: extensions.incredibar_i.hardId - 103ded2f000000000000000f1f4aa51e
    FF - user.js: extensions.incredibar_i.instlDay - 15406
    FF - user.js: extensions.incredibar_i.vrsn - [removed]
    FF - user.js: extensions.incredibar_i.vrsni - [removed]
    FF - user.js: extensions.incredibar_i.vrsnTs - 1.5.3.2720:03
    FF - user.js: extensions.incredibar_i.prtnrId - Incredibar
    FF - user.js: extensions.incredibar_i.prdct - incredibar
    FF - user.js: extensions.incredibar_i.aflt - orgnl
    FF - user.js: extensions.incredibar_i.smplGrp - none
    FF - user.js: extensions.incredibar_i.tlbrId - base
    FF - user.js: extensions.incredibar_i.instlRef -
    FF - user.js: extensions.incredibar_i.dfltLng -
    FF - user.js: extensions.incredibar_i.excTlbr - false
    FF - user.js: extensions.incredibar_i.ms_url_id -
    FF - user.js: extensions.incredibar_i.upn2 - 6PQqwKDwVP
    FF - user.js: extensions.incredibar_i.upn2n - 92542495433442473
    FF - user.js: extensions.incredibar_i.productid - 26
    FF - user.js: extensions.incredibar_i.installerproductid - 26
    FF - user.js: extensions.incredibar_i.did - 10606
    FF - user.js: extensions.incredibar_i.ppd - 9
    
    :Commands
    [purity]
    [emptytemp]
    [createrestorepoint]
    [Reboot]
  • Then click the Run Fix button at the top
  • Let the program run unhindered, reboot when it is done
  • Then post a new OTL log ( don't check the boxes beside LOP Check or Purity this time )
Next

[external image: Posted Image]
Download GMER Rootkit Scanner from here or here.
  • Extract the contents of the zipped file to desktop.
  • Double click GMER.exe. If asked to allow gmer.sys driver to load, please consent .
  • If it gives you a warning about rootkit activity and asks if you want to run scan…click on NO.

    [external image: Posted Image]
    Click the image to enlarge it
  • In the right panel, you will see several boxes that have been checked. Uncheck the following …
    • IAT/EAT
    • Drives/Partition other than Systemdrive (typically C:\)
    • Show All (don't miss this one)
  • Then click the Scan button & wait for it to finish.
  • Once done click on the [Save..] button, and in the File name area, type in "Gmer.txt" or it will save as a .log file which cannot be uploaded to your post.
  • Save it where you can easily find it, such as your desktop, and attach it in your reply.
**Caution**Rootkit scans often produce false positives. Do NOT take any action on any "<— ROOKIT" entries.

In your next post please provide the following:
  • OTL.txt
  • Gmer.txt
  • Tell me how your computer is running at the moment

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI