This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Extremely slow computer [Solved]

10 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Again, terribly sorry. I've been real busy lately and haven't been keeping up with the computer fixing process. Hopefully this will be the last one. The computer is still running a bit sluggish, but it is definitely better than before where it was nearly impossible to do any task under 30 minutes.



Old topic




Second OTL scan:


OTL logfile created on: 10/27/2012 2:23:01 AM - Run 2
OTL by OldTimer - Version 3.2.69.0 Folder = E:\homework
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

988.42 Mb Total Physical Memory | 339.54 Mb Available Physical Memory | 34.35% Memory free
2.32 Gb Paging File | 1.70 Gb Available in Paging File | 73.55% Paging File free
Paging file location(s): C:\pagefile.sys 1476 2952 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 149.05 Gb Total Space | 131.27 Gb Free Space | 88.07% Space Free | Partition Type: NTFS
Drive E: | 953.00 Mb Total Space | 278.94 Mb Free Space | 29.27% Space Free | Partition Type: FAT

Computer Name: P-EE951AC334294 | User Name: Anna | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - E:\homework\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Constant Guard Protection Suite\IDVaultSvc.exe (White Sky, Inc.)
PRC - C:\Program Files\Constant Guard Protection Suite\IDVault.exe (White Sky, Inc.)
PRC - C:\Program Files\Oracle\JavaFX 2.1 Runtime\bin\jqs.exe (Oracle Corporation)
PRC - C:\Program Files\Common Files\LogiShrd\LVMVFM\UMVPFSrv.exe (Logitech Inc.)
PRC - C:\Program Files\Logitech\LWS\Webcam Software\LWS.exe (Logitech Inc.)
PRC - C:\Program Files\Logitech\LWS\Webcam Software\CameraHelperShell.exe ()
PRC - C:\Program Files\Common Files\LogiShrd\LQCVFX\COCIManager.exe ()
PRC - C:\Program Files\SFT\GuardedID\GIDD.exe (StrikeForce Technologies Inc.)
PRC - C:\Program Files\Norton Security Suite\Engine\5.2.2.3\ccsvchst.exe (Symantec Corporation)
PRC - C:\WINDOWS\system32\nlssrv32.exe (Nalpeiron Ltd.)
PRC - C:\Program Files\Gigabyte\EasySaver\essvr.exe ()
PRC - C:\Program Files\DeviceVM\Browser Configuration Utility\BCUService.exe (DeviceVM, Inc.)
PRC - C:\Program Files\DeviceVM\Browser Configuration Utility\BCU.exe (DeviceVM, Inc.)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\WINDOWS\system32\PSIService.exe ()
PRC - C:\Program Files\Palm\Hotsync.exe (PalmSource, Inc)


========== Modules (No Company Name) ==========

MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.WorkflowServ#\bd5bd406670d483b82bd51249eee59e3\System.WorkflowServices.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Web.Services\e70343406253e43964f9fe1f42cfbd7c\System.Web.Services.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Web\dbc413807cb7360b3e26ef3ca1d54f9a\System.Web.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.ServiceProce#\8b84bb74d7724e147a642a1d5358feb7\System.ServiceProcess.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.ServiceModel#\97d635f5c656ae43d94b55e67fc4ab50\System.ServiceModel.Web.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Management\9080c8e8e7b6dfb502c1328673d636f8\System.Management.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Configuratio#\badd66e1d2b8416e9bb868ad059203c6\System.Configuration.Install.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Security\129b15861e200613ff78ae15581f9093\System.Security.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Configuration\3d5b7368bde0f65aa15d9f46b498cc89\System.Configuration.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\SMDiagnostics\660c4d6dd69ef22bc05587e1998cd135\SMDiagnostics.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.ServiceModel\bc254d2fa26664898ae21d45643bc194\System.ServiceModel.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Runtime.Seri#\505e12638acd6fdb22e1fd2d4c6fc232\System.Runtime.Serialization.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.IdentityModel\e09496ddb2bf6f3b69707924f2e6b5ff\System.IdentityModel.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\WindowsFormsIntegra#\86e11a59f02b2dda27ec2e7cba351744\WindowsFormsIntegration.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\UIAutomationProvider\f121ccced1aa14badb316d8d9be5154d\UIAutomationProvider.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Xml\3bba1b8b0b5ef0be238b011cc7a0575e\System.Xml.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\01abbadafaf265d9f4ac9bbb247acb98\System.Windows.Forms.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Drawing\d86f2038209a4cf0d0f5b30f6375c9b2\System.Drawing.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Data\12c6fe8d4dd78f9bddf847d3b2821c03\System.Data.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\8b873631a0855fb6aa0ad25f1d9de7fe\PresentationFramework.Luna.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\e4ecfaaf5417aceecb7fa8abddf06113\PresentationFramework.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\PresentationCore\f33e2a4d9b385234406fa2d662f78875\PresentationCore.ni.dll ()
MOD - C:\WINDOWS\assembly\GAC_32\System.Data\2.0.0.0__b77a5c561934e089\System.Data.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\WindowsBase\6d8bef0d008389874e55c0308f0c18e5\WindowsBase.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System\e4b5afc4da43b1c576f9322f9f2e1bfe\System.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\mscorlib\e337c89bc9f81b69d7237aa70e935900\mscorlib.ni.dll ()
MOD - C:\Program Files\Constant Guard Protection Suite\IdVaultCore.XmlSerializers.dll ()
MOD - C:\Program Files\Constant Guard Protection Suite\sqlite3.dll ()
MOD - C:\Program Files\Common Files\LogiShrd\LWSPlugins\LWS\Applets\CameraHelper\DevManagerCore.dll ()
MOD - C:\Program Files\Logitech\LWS\Webcam Software\CameraHelperShell.exe ()
MOD - C:\Program Files\Common Files\LogiShrd\LQCVFX\COCIManager.exe ()
MOD - C:\Program Files\Logitech\LWS\Webcam Software\QTXml4.dll ()
MOD - C:\Program Files\Logitech\LWS\Webcam Software\ImageFormats\QJpeg4.dll ()
MOD - C:\Program Files\Logitech\LWS\Webcam Software\ImageFormats\QGif4.dll ()
MOD - C:\Program Files\Logitech\LWS\Webcam Software\QTGui4.dll ()
MOD - C:\Program Files\Logitech\LWS\Webcam Software\QTCore4.dll ()
MOD - C:\Program Files\Gigabyte\EasySaver\essvr.exe ()
MOD - C:\Program Files\DeviceVM\Browser Configuration Utility\sqlite3.dll ()
MOD - C:\WINDOWS\system32\EasyHook32.dll ()
MOD - C:\Program Files\Gigabyte\EasySaver\ycc.dll ()
MOD - C:\WINDOWS\system32\PSIService.exe ()


========== Services (SafeList) ==========

SRV - (AppMgmt) – %SystemRoot%\System32\appmgmts.dll File not found
SRV - (MozillaMaintenance) – C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe (Mozilla Foundation)
SRV - (IDVaultSvc) – C:\Program Files\Constant Guard Protection Suite\IDVaultSvc.exe (White Sky, Inc.)
SRV - (SkypeUpdate) – C:\Program Files\Skype\Updater\Updater.exe (Skype Technologies)
SRV - (JavaQuickStarterService) – C:\Program Files\Oracle\JavaFX 2.1 Runtime\bin\jqs.exe (Oracle Corporation)
SRV - (UMVPFSrv) – C:\Program Files\Common Files\LogiShrd\LVMVFM\UMVPFSrv.exe (Logitech Inc.)
SRV - (N360) – C:\Program Files\Norton Security Suite\Engine\5.2.2.3\ccSvcHst.exe (Symantec Corporation)
SRV - (nlsX86cc) – C:\WINDOWS\system32\nlssrv32.exe (Nalpeiron Ltd.)
SRV - (ES lite Service) – C:\Program Files\Gigabyte\EasySaver\essvr.exe ()
SRV - (BCUService) – C:\Program Files\DeviceVM\Browser Configuration Utility\BCUService.exe (DeviceVM, Inc.)
SRV - (ProtexisLicensing) – C:\WINDOWS\system32\PSIService.exe ()


========== Driver Services (SafeList) ==========

DRV - (WDICA) – File not found
DRV - (PDRFRAME) – File not found
DRV - (PDRELI) – File not found
DRV - (PDFRAME) – File not found
DRV - (PDCOMP) – File not found
DRV - (PCIDump) – File not found
DRV - (lbrtfdc) – File not found
DRV - (i2omgmt) – File not found
DRV - (Changer) – File not found
DRV - (gdrv) – C:\WINDOWS\gdrv.sys (Windows ® 2000 DDK provider)
DRV - (NAVEX15) – C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_5.0.0.125\Definitions\VirusDefs\20120923.008\NAVEX15.SYS (Symantec Corporation)
DRV - (NAVENG) – C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_5.0.0.125\Definitions\VirusDefs\20120923.008\NAVENG.SYS (Symantec Corporation)
DRV - (IDSxpx86) – C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_5.0.0.125\Definitions\IPSDefs\20120921.001\IDSXpx86.sys (Symantec Corporation)
DRV - (BHDrvx86) – C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_5.0.0.125\Definitions\BASHDefs\20120919.001\BHDrvx86.sys (Symantec Corporation)
DRV - (eeCtrl) – C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys (Symantec Corporation)
DRV - (EraserUtilRebootDrv) – C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys (Symantec Corporation)
DRV - (LVUVC) – C:\WINDOWS\system32\drivers\lvuvc.sys (Logitech Inc.)
DRV - (LVRS) – C:\WINDOWS\system32\drivers\lvrs.sys (Logitech Inc.)
DRV - (PalmUSBD) – C:\WINDOWS\system32\drivers\PalmUSBD.sys (PalmSource, Inc.)
DRV - (SymEvent) – C:\WINDOWS\system32\drivers\SYMEVENT.SYS (Symantec Corporation)
DRV - (GIDv2) – C:\WINDOWS\System32\drivers\gidv2.sys (StrikeForce Technologies, Inc.)
DRV - (SYMTDI) – C:\WINDOWS\system32\drivers\N360\0502020.003\symtdi.sys (Symantec Corporation)
DRV - (SRTSP) – C:\WINDOWS\system32\drivers\N360\0502020.003\srtsp.sys (Symantec Corporation)
DRV - (SRTSPX) – C:\WINDOWS\system32\drivers\N360\0502020.003\srtspx.sys (Symantec Corporation)
DRV - (SymEFA) – C:\WINDOWS\system32\drivers\N360\0502020.003\symefa.sys (Symantec Corporation)
DRV - (SymDS) – C:\WINDOWS\system32\drivers\N360\0502020.003\symds.sys (Symantec Corporation)
DRV - (SymIRON) – C:\WINDOWS\system32\drivers\N360\0502020.003\ironx86.sys (Symantec Corporation)
DRV - (RTL8192su) – C:\WINDOWS\system32\drivers\RTL8192su.sys (Realtek Semiconductor Corporation )
DRV - (IntcAzAudAddService) – C:\WINDOWS\system32\drivers\RtkHDAud.sys (Realtek Semiconductor Corp.)
DRV - (RTLE8023xp) – C:\WINDOWS\system32\drivers\Rtenicxp.sys (Realtek Semiconductor Corporation )
DRV - (Monfilt) – C:\WINDOWS\system32\drivers\Monfilt.sys (Creative Technology Ltd.)
DRV - (Ambfilt) – C:\WINDOWS\system32\drivers\Ambfilt.sys (Creative)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://search.live.com/results.aspx?q={sea…ferrer:source?}

IE - HKCU\..\URLSearchHook: {BC86E1AB-EDA5-4059-938F-CE307B0C6F0A} - C:\Program Files\DeviceVM\Browser Configuration Utility\AddressBarSearch.dll (DeviceVM, Inc.)
IE - HKCU\..\SearchScopes,DefaultScope = {0A65ED42-75AD-4bbe-8E8B-EF542DC9B1AD}
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://search.live.com/results.aspx?q={sea…amp;Form=IE8SRC
IE - HKCU\..\SearchScopes\{0A65ED42-75AD-4bbe-8E8B-EF542DC9B1AD}: "URL" = http://search.yahoo.com/search?p={searchTe…m&type=IEBD
IE - HKCU\..\SearchScopes\{3725716F-C2A9-4c1e-968D-23988B72A3A6}: "URL" = http://www.google.com/custom?client=pub-37…q={searchTerms}
IE - HKCU\..\SearchScopes\{AFBCB7E0-F91A-4951-9F31-58FEE57A25C4}: "URL" = http://www.ask.com/web?q={SEARCHTERMS}&…eo=US&ver=5
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..browser.startup.homepage: "http://www.google.com/firefox"
FF - prefs.js..extensions.enabledAddons: [removed]:0.79.1
FF - prefs.js..extensions.enabledAddons: {84625510-7e5d-11e0-a411-0800200c9a66}:1.15
FF - prefs.js..extensions.enabledAddons: {BBDA0591-3099-440a-AA10-41764D9DB4DB}:[removed] - 1
FF - prefs.js..extensions.enabledAddons: {2D3F3651-74B9-4795-BDEC-6DA2F431CB62}:2011.7.12.1
FF - prefs.js..extensions.enabledItems: {82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}:5.6.0.8442
FF - prefs.js..extensions.enabledItems: {BBDA0591-3099-440a-AA10-41764D9DB4DB}:10.1.0.68 - 1
FF - prefs.js..extensions.enabledItems: [removed]:0.79.1
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA}:6.0.29
FF - prefs.js..extensions.enabledItems: [removed]:1.0
FF - prefs.js..extensions.enabledItems: {a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7}:20120302
FF - prefs.js..extensions.enabledItems: {5A170DD3-63CA-4c58-93B7-DE9FF536C2FF}:1.8.81
FF - user.js - File not found

FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32_11_4_402_265.dll ()
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.5.1: C:\WINDOWS\system32\npDeployJava1.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.5.1: C:\Program Files\Oracle\JavaFX 2.1 Runtime\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\5.0.61118.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{BBDA0591-3099-440a-AA10-41764D9DB4DB}: C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_5.0.0.125\IPSFFPlgn\ [2012/02/16 04:22:31 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{2D3F3651-74B9-4795-BDEC-6DA2F431CB62}: C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_5.0.0.125\coFFPlgn_2011_7_12_1 [2012/10/27 02:18:28 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{6D5C8FC4-DE46-41bf-9092-93F0F78E9115}: C:\Documents and Settings\All Users\Application Data\Norton\{78CA3BF0-9C3B-40e1-B46D-38C877EF059A}\NSM_2.2.0.28\coFFFw\
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 15.0\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2012/09/24 05:13:01 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 15.0\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins

[2011/08/14 00:48:19 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Anna\Application Data\Mozilla\Extensions
[2012/10/24 02:20:12 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Anna\Application Data\Mozilla\Firefox\Profiles\jomfg8s5.default\extensions
[2011/09/12 01:22:39 | 000,000,000 | —D | M] (Microsoft .NET Framework Assistant) – C:\Documents and Settings\Anna\Application Data\Mozilla\Firefox\Profiles\jomfg8s5.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2012/08/20 12:07:31 | 000,000,000 | —D | M] (WOT) – C:\Documents and Settings\Anna\Application Data\Mozilla\Firefox\Profiles\jomfg8s5.default\extensions\{a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7}(2)
[2011/11/19 22:19:38 | 000,000,000 | —D | M] (OptimizeGoogle) – C:\Documents and Settings\Anna\Application Data\Mozilla\Firefox\Profiles\jomfg8s5.default\extensions\[removed]
[2012/10/16 04:47:06 | 000,672,576 | —- | M] () (No name found) – C:\Documents and Settings\Anna\Application Data\Mozilla\Firefox\Profiles\jomfg8s5.default\extensions\{5A170DD3-63CA-4c58-93B7-DE9FF536C2FF}.xpi
[2012/09/01 00:49:14 | 000,036,056 | —- | M] () (No name found) – C:\Documents and Settings\Anna\Application Data\Mozilla\Firefox\Profiles\jomfg8s5.default\extensions\{84625510-7e5d-11e0-a411-0800200c9a66}.xpi
[2011/07/28 02:05:20 | 000,002,468 | —- | M] () – C:\Documents and Settings\Anna\Application Data\Mozilla\Firefox\Profiles\jomfg8s5.default\searchplugins\safesearch.xml
[2012/10/26 22:48:02 | 000,002,112 | —- | M] () – C:\Documents and Settings\Anna\Application Data\Mozilla\Firefox\Profiles\jomfg8s5.default\searchplugins\wot-safe-search.xml
[2012/09/24 05:12:53 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions
[2012/09/24 05:12:53 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}
[2012/10/25 02:44:35 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\updated\extensions
[2012/10/25 02:44:35 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\updated\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}
[2012/10/25 02:44:44 | 000,000,000 | —D | M] (Default) – C:\Program Files\Mozilla Firefox\updated\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
[2012/10/27 02:18:28 | 000,000,000 | —D | M] (Norton Toolbar) – C:\DOCUMENTS AND SETTINGS\ALL USERS\APPLICATION DATA\NORTON\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_5.0.0.125\COFFPLGN_2011_7_12_1
[2012/02/16 04:22:31 | 000,000,000 | —D | M] (Symantec Intrusion Prevention) – C:\DOCUMENTS AND SETTINGS\ALL USERS\APPLICATION DATA\NORTON\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_5.0.0.125\IPSFFPLGN
[2012/09/24 05:13:01 | 000,266,720 | —- | M] (Mozilla Foundation) – C:\Program Files\mozilla firefox\components\browsercomps.dll
[2012/09/24 05:12:57 | 000,002,465 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\bing.xml
[2012/09/24 05:12:57 | 000,002,253 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\twitter.xml

O1 HOSTS File: ([2004/08/04 08:00:00 | 000,000,734 | —- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (Symantec NCO BHO) - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files\Norton Security Suite\Engine\5.2.2.3\coieplg.dll (Symantec Corporation)
O2 - BHO: (Symantec Intrusion Prevention) - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files\Norton Security Suite\Engine\5.2.2.3\ips\ipsbho.dll (Symantec Corporation)
O2 - BHO: (Java™ Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Oracle\JavaFX 2.1 Runtime\bin\ssv.dll (Oracle Corporation)
O2 - BHO: (Skype Browser Helper) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O2 - BHO: (Constant Guard Protection Suite (COM)) - {B84CDBE7-1B46-494B-A188-01D4C52DEB61} - C:\Documents and Settings\All Users\Application Data\White Sky, Inc\ID Vault\IEBHO1.1.730.1\NativeBHO.dll (WhiteSky)
O2 - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Oracle\JavaFX 2.1 Runtime\bin\jp2ssv.dll (Oracle Corporation)
O3 - HKLM\..\Toolbar: (Norton Toolbar) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Norton Security Suite\Engine\5.2.2.3\coieplg.dll (Symantec Corporation)
O3 - HKCU\..\Toolbar\WebBrowser: (Norton Toolbar) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Norton Security Suite\Engine\5.2.2.3\coieplg.dll (Symantec Corporation)
O4 - HKLM..\Run: [BCU] C:\Program Files\DeviceVM\Browser Configuration Utility\BCU.exe (DeviceVM, Inc.)
O4 - HKLM..\Run: [GIDDesktop] C:\Program Files\SFT\GuardedID\gidd.exe (StrikeForce Technologies Inc.)
O4 - HKLM..\Run: [LWS] C:\Program Files\Logitech\LWS\Webcam Software\LWS.exe (Logitech Inc.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Constant Guard.lnk = C:\Program Files\Constant Guard Protection Suite\IDVault.exe (White Sky, Inc.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\HOTSYNCSHORTCUTNAME.lnk = C:\Program Files\Palm\Hotsync.exe (PalmSource, Inc)
O4 - Startup: C:\Documents and Settings\Anna\Start Menu\Programs\Startup\Palm Registration.lnk = C:\Program Files\Palm\register.exe (Palm/Leader Technologies)
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O9 - Extra Button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} http://update.microsoft.com/windowsupdate/…b?1311645391250 (WUWebControl Class)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 75.75.75.75 75.75.76.76
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{AB065480-E775-4735-BD9F-CE0EDD8DCA77}: DhcpNameServer = 75.75.75.75 75.75.76.76
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) - C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O20 - Winlogon\Notify\GIDLogonXP: DllName - (GIDLogonXP.dll) - C:\WINDOWS\System32\GIDLogonXP.dll (StrikeForce Technologies Inc)
O24 - Desktop WallPaper: C:\WINDOWS\Coffee Bean.bmp
O24 - Desktop BackupWallPaper: C:\WINDOWS\Coffee Bean.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2011/07/24 23:41:50 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)

========== Files/Folders - Created Within 30 Days ==========

[2012/10/27 02:20:55 | 000,275,696 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\mucltui.dll
[2012/10/27 02:20:54 | 000,000,000 | —D | C] – C:\WINDOWS\LastGood
[2012/10/20 15:56:56 | 000,000,000 | —D | C] – C:\TDSSKiller_Quarantine
[2012/10/18 17:10:10 | 000,000,000 | —D | C] – C:\Documents and Settings\Anna\Desktop\RK_Quarantine
[2012/10/14 22:46:22 | 000,000,000 | —D | C] – C:\Documents and Settings\LocalService\Application Data\Adobe
[2012/10/13 10:56:50 | 000,000,000 | —D | C] – C:\Documents and Settings\Anna\Application Data\Tific
[2012/10/13 10:56:40 | 000,000,000 | —D | C] – C:\Documents and Settings\Anna\Local Settings\Application Data\Symantec
[2012/10/11 00:15:02 | 000,000,000 | —D | C] – C:\Documents and Settings\Anna\Local Settings\Application Data\Identities
[2012/10/04 07:00:03 | 000,000,000 | —D | C] – C:\Documents and Settings\Anna\My Documents\Videos
[2012/10/04 06:52:00 | 000,000,000 | —D | C] – C:\Documents and Settings\Anna\My Documents\150RACH_
[2012/10/04 06:51:04 | 000,000,000 | —D | C] – C:\Documents and Settings\Anna\My Documents\149RACH_
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2012/10/27 02:18:26 | 000,017,488 | —- | M] (Windows ® 2000 DDK provider) – C:\WINDOWS\gdrv.sys
[2012/10/27 02:18:22 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2012/10/27 02:17:21 | 000,000,211 | -HS- | M] () – C:\boot.ini
[2012/10/26 16:45:00 | 000,001,324 | —- | M] () – C:\WINDOWS\System32\d3d9caps.dat
[2012/10/26 12:58:30 | 000,244,123 | —- | M] () – C:\Documents and Settings\Anna\Desktop\beast_library.jpg
[2012/10/26 00:09:43 | 000,041,176 | —- | M] () – C:\Documents and Settings\Anna\Desktop\beauty-and-the-beast.jpg
[2012/10/26 00:06:44 | 000,043,191 | —- | M] () – C:\Documents and Settings\Anna\Desktop\beauty-and-the-beast-bitches-love-libraries.jpg
[2012/10/26 00:06:02 | 000,156,495 | —- | M] () – C:\Documents and Settings\Anna\Desktop\forest_scene_by_therueroyale-d32r72z.jpg
[2012/10/25 05:01:31 | 001,440,054 | —- | M] () – C:\Documents and Settings\Anna\Desktop\locusts.bmp
[2012/10/24 21:04:52 | 000,013,646 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2012/10/24 14:51:14 | 000,016,896 | —- | M] () – C:\Documents and Settings\Anna\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2012/10/24 02:47:16 | 000,048,942 | —- | M] () – C:\Documents and Settings\Anna\My Documents\60976898624A1E7449F45A58CFA_h316_w628_m4_cYkoMkSPp.jpg
[2012/10/24 02:46:44 | 000,072,837 | —- | M] () – C:\Documents and Settings\Anna\My Documents\2D4B57898F3B285FCA43464116FBB9_h316_w628_m4_cUNlDCdpE.jpg
[2012/10/22 05:31:43 | 000,498,458 | —- | M] () – C:\Documents and Settings\Anna\My Documents\tumblr_mbsiwfsvDV1r4t7nto1_500.gif
[2012/10/19 13:48:46 | 000,024,074 | —- | M] () – C:\Documents and Settings\Anna\Desktop\spanishdesert.jpg
[2012/10/18 17:08:18 | 000,429,490 | —- | M] () – C:\Documents and Settings\Anna\Desktop\Image4.pspimage
[2012/10/17 09:04:21 | 003,853,959 | —- | M] () – C:\Documents and Settings\Anna\Desktop\sirbraddyford2.pspimage
[2012/10/14 11:55:54 | 000,009,099 | —- | M] () – C:\Documents and Settings\Anna\Desktop\red.jpg
[2012/10/13 11:01:19 | 000,000,757 | —- | M] () – C:\Documents and Settings\Anna\Start Menu\Programs\Startup\Palm Registration.lnk
[2012/10/11 18:34:21 | 000,078,728 | —- | M] () – C:\Documents and Settings\Anna\Desktop\lol.jpg
[2012/10/11 18:29:48 | 000,042,537 | —- | M] () – C:\Documents and Settings\Anna\My Documents\4.gif
[2012/10/11 18:27:34 | 000,041,302 | —- | M] () – C:\Documents and Settings\Anna\My Documents\3.gif
[2012/10/11 18:26:51 | 000,056,421 | —- | M] () – C:\Documents and Settings\Anna\My Documents\2.gif
[2012/10/11 18:26:35 | 000,042,342 | —- | M] () – C:\Documents and Settings\Anna\My Documents\1.gif
[2012/10/11 00:12:57 | 000,068,084 | —- | M] () – C:\Documents and Settings\Anna\Desktop\11-grand-central-station-_1.jpg
[2012/10/09 22:44:22 | 000,091,822 | —- | M] () – C:\Documents and Settings\Anna\Desktop\Daniel-Del-Orfano_The-Long-Goodbye.jpg
[2012/10/09 22:18:45 | 000,172,017 | —- | M] () – C:\Documents and Settings\Anna\Desktop\Warehouse_Pan.jpg
[2012/10/09 22:02:09 | 000,173,991 | —- | M] () – C:\Documents and Settings\Anna\Desktop\sunshineresized.jpg
[2012/10/09 22:01:00 | 000,521,013 | —- | M] () – C:\Documents and Settings\Anna\Desktop\sunshine.jpg
[2012/10/09 21:58:45 | 000,251,184 | —- | M] () – C:\Documents and Settings\Anna\Desktop\meowmeow.jpg
[2012/10/09 21:12:42 | 007,415,240 | —- | M] () – C:\Documents and Settings\Anna\Desktop\Image3.pspimage
[2012/10/08 04:03:40 | 000,026,183 | —- | M] () – C:\Documents and Settings\Anna\My Documents\tumblr_maj9qwPy3N1rd50lho1_500.jpg
[2012/10/07 23:15:53 | 001,015,501 | —- | M] () – C:\Documents and Settings\Anna\My Documents\tumblr_maktuytrHx1qi989qo1_250.gif
[2012/10/07 23:14:39 | 000,123,962 | —- | M] () – C:\Documents and Settings\Anna\My Documents\tumblr_mamawcULP81r1cpy3o2_500.jpg
[2012/10/07 23:14:30 | 000,096,473 | —- | M] () – C:\Documents and Settings\Anna\My Documents\tumblr_mamawcULP81r1cpy3o1_500.jpg
[2012/10/07 23:14:14 | 000,025,051 | —- | M] () – C:\Documents and Settings\Anna\My Documents\tumblr_mambo1f4gs1qlx7xzo1_500.jpg
[2012/10/07 23:13:45 | 000,430,022 | —- | M] () – C:\Documents and Settings\Anna\My Documents\tumblr_mamgy7OZjZ1qg0b67.gif
[2012/10/07 23:11:20 | 000,508,905 | —- | M] () – C:\Documents and Settings\Anna\My Documents\tumblr_lfs7m8hRKa1qbxoeqo1_500.gif
[2012/10/07 23:10:28 | 000,159,719 | —- | M] () – C:\Documents and Settings\Anna\My Documents\tumblr_lty1gm3EC71r5avb2o1_500.jpg
[2012/10/07 23:07:41 | 000,390,682 | —- | M] () – C:\Documents and Settings\Anna\My Documents\tumblr_mavv3oPDSA1r384au.gif
[2012/10/07 23:07:10 | 000,510,894 | —- | M] () – C:\Documents and Settings\Anna\My Documents\tumblr_mavvz6Rxkf1qeef72.gif
[2012/10/07 23:04:05 | 000,495,726 | —- | M] () – C:\Documents and Settings\Anna\My Documents\tumblr_lrow55omdm1qeq4tyo3_r1_250.gif
[2012/10/07 22:53:30 | 000,789,712 | —- | M] () – C:\Documents and Settings\Anna\My Documents\tumblr_m88yczhtoE1rqfz4co1_500.gif
[2012/10/07 22:53:21 | 000,926,183 | —- | M] () – C:\Documents and Settings\Anna\My Documents\tumblr_m88yczhtoE1rqfz4co3_500.gif
[2012/10/07 20:46:32 | 000,447,437 | —- | M] () – C:\Documents and Settings\Anna\Desktop\tumblr_mb664rjOXz1r384au.gif
[2012/10/07 13:15:51 | 000,901,150 | —- | M] () – C:\Documents and Settings\Anna\Desktop\rachelfarns.pspimage
[2012/10/07 13:15:25 | 000,045,807 | —- | M] () – C:\Documents and Settings\Anna\Desktop\HGfarnsworth.jpg
[2012/10/07 08:26:51 | 000,115,234 | —- | M] () – C:\Documents and Settings\Anna\Desktop\fbendless wonder.png
[2012/10/07 08:26:38 | 000,044,207 | —- | M] () – C:\Documents and Settings\Anna\Desktop\fbendless wonder.jpg
[2012/10/07 05:49:56 | 000,296,448 | —- | M] () – C:\WINDOWS\Xenofex.ini
[2012/10/06 11:28:13 | 000,044,368 | —- | M] () – C:\Documents and Settings\Anna\Desktop\rachelfarns.jpg
[2012/10/06 11:27:56 | 000,045,807 | —- | M] () – C:\Documents and Settings\Anna\Desktop\HGfarns.jpg
[2012/10/06 11:01:59 | 000,334,205 | —- | M] () – C:\Documents and Settings\Anna\Desktop\w13_s2e3-vet-pete-myka.jpg
[2012/10/06 08:30:35 | 000,129,632 | —- | M] () – C:\Documents and Settings\Anna\Desktop\farnsworth .jpg
[2012/10/06 08:13:13 | 001,019,590 | —- | M] () – C:\Documents and Settings\Anna\My Documents\tumblr_m6yyhxFkqr1qbu8fp.gif
[2012/10/06 08:11:49 | 001,022,541 | —- | M] () – C:\Documents and Settings\Anna\My Documents\tumblr_m70t42zmEZ1qzjk2so7_400.gif
[2012/10/06 08:11:17 | 000,865,642 | —- | M] () – C:\Documents and Settings\Anna\My Documents\tumblr_m4sexrqh5j1rqfz4co1_500.gif
[2012/10/06 08:10:09 | 000,300,130 | —- | M] () – C:\Documents and Settings\Anna\Desktop\tumblr_m8ry6lovov1qacf3wo1_r1_500.png
[2012/10/06 07:37:16 | 000,158,402 | —- | M] () – C:\Documents and Settings\Anna\Desktop\tumblr_mb4aoxU4AI1r1cpy3o1_500.jpg
[2012/10/06 04:16:18 | 000,081,583 | —- | M] () – C:\Documents and Settings\Anna\Desktop\lovelovelove.jpg
[2012/10/06 02:35:25 | 000,121,741 | —- | M] () – C:\Documents and Settings\Anna\Desktop\return-of-hg-wells.jpg
[2012/10/06 01:31:37 | 000,016,283 | —- | M] () – C:\Documents and Settings\Anna\Desktop\Carnival Queen Make-Up.JPG
[2012/10/05 22:54:57 | 000,126,771 | —- | M] () – C:\Documents and Settings\Anna\Desktop\farnsworth-idealhero-4.jpg
[2012/10/05 21:56:07 | 002,265,284 | —- | M] () – C:\Documents and Settings\Anna\Desktop\farnsworth empty.pspimage
[2012/10/05 21:08:01 | 001,351,669 | —- | M] () – C:\Documents and Settings\Anna\Desktop\Farnsworth.pspimage
[2012/10/04 05:24:43 | 000,147,280 | —- | M] () – C:\Documents and Settings\Anna\Desktop\525917_10151183062704449_1697597416_n.jpg
[2012/10/01 23:12:44 | 001,021,823 | —- | M] () – C:\Documents and Settings\Anna\My Documents\tumblr_lz94cuXDVL1qde33io1_500.gif
[2012/10/01 23:11:47 | 001,001,913 | —- | M] () – C:\Documents and Settings\Anna\My Documents\tumblr_m45rfvwyl91qde33io1_500.gif
[2012/09/30 19:40:01 | 000,004,953 | —- | M] () – C:\Documents and Settings\Anna\Desktop\Drusie.rtf
[2012/09/28 15:14:58 | 000,075,924 | —- | M] () – C:\Documents and Settings\Anna\Desktop\Incorrect answer.jpg
[2012/09/28 13:37:34 | 000,262,346 | —- | M] () – C:\Documents and Settings\Anna\Desktop\wallpaper_cast_03_1920_129011579697.jpg
[2012/09/28 12:31:40 | 000,036,673 | —- | M] () – C:\Documents and Settings\Anna\Desktop\Image72.jpg
[2012/09/28 12:15:15 | 000,037,178 | —- | M] () – C:\Documents and Settings\Anna\Desktop\Image7.jpg
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]

========== Files Created - No Company Name ==========

[2012/10/26 12:58:30 | 000,244,123 | —- | C] () – C:\Documents and Settings\Anna\Desktop\beast_library.jpg
[2012/10/26 00:09:42 | 000,041,176 | —- | C] () – C:\Documents and Settings\Anna\Desktop\beauty-and-the-beast.jpg
[2012/10/26 00:06:44 | 000,043,191 | —- | C] () – C:\Documents and Settings\Anna\Desktop\beauty-and-the-beast-bitches-love-libraries.jpg
[2012/10/26 00:06:01 | 000,156,495 | —- | C] () – C:\Documents and Settings\Anna\Desktop\forest_scene_by_therueroyale-d32r72z.jpg
[2012/10/25 05:01:31 | 001,440,054 | —- | C] () – C:\Documents and Settings\Anna\Desktop\locusts.bmp
[2012/10/24 02:47:16 | 000,048,942 | —- | C] () – C:\Documents and Settings\Anna\My Documents\60976898624A1E7449F45A58CFA_h316_w628_m4_cYkoMkSPp.jpg
[2012/10/24 02:46:44 | 000,072,837 | —- | C] () – C:\Documents and Settings\Anna\My Documents\2D4B57898F3B285FCA43464116FBB9_h316_w628_m4_cUNlDCdpE.jpg
[2012/10/22 05:31:42 | 000,498,458 | —- | C] () – C:\Documents and Settings\Anna\My Documents\tumblr_mbsiwfsvDV1r4t7nto1_500.gif
[2012/10/19 13:48:46 | 000,024,074 | —- | C] () – C:\Documents and Settings\Anna\Desktop\spanishdesert.jpg
[2012/10/18 17:08:17 | 000,429,490 | —- | C] () – C:\Documents and Settings\Anna\Desktop\Image4.pspimage
[2012/10/17 09:04:20 | 003,853,959 | —- | C] () – C:\Documents and Settings\Anna\Desktop\sirbraddyford2.pspimage
[2012/10/14 11:55:54 | 000,009,099 | —- | C] () – C:\Documents and Settings\Anna\Desktop\red.jpg
[2012/10/11 18:34:21 | 000,078,728 | —- | C] () – C:\Documents and Settings\Anna\Desktop\lol.jpg
[2012/10/11 18:29:48 | 000,042,537 | —- | C] () – C:\Documents and Settings\Anna\My Documents\4.gif
[2012/10/11 18:27:34 | 000,041,302 | —- | C] () – C:\Documents and Settings\Anna\My Documents\3.gif
[2012/10/11 18:26:51 | 000,056,421 | —- | C] () – C:\Documents and Settings\Anna\My Documents\2.gif
[2012/10/11 18:26:35 | 000,042,342 | —- | C] () – C:\Documents and Settings\Anna\My Documents\1.gif
[2012/10/11 00:12:56 | 000,068,084 | —- | C] () – C:\Documents and Settings\Anna\Desktop\11-grand-central-station-_1.jpg
[2012/10/09 22:44:22 | 000,091,822 | —- | C] () – C:\Documents and Settings\Anna\Desktop\Daniel-Del-Orfano_The-Long-Goodbye.jpg
[2012/10/09 22:18:44 | 000,172,017 | —- | C] () – C:\Documents and Settings\Anna\Desktop\Warehouse_Pan.jpg
[2012/10/09 22:02:09 | 000,173,991 | —- | C] () – C:\Documents and Settings\Anna\Desktop\sunshineresized.jpg
[2012/10/09 22:01:00 | 000,521,013 | —- | C] () – C:\Documents and Settings\Anna\Desktop\sunshine.jpg
[2012/10/09 21:58:44 | 000,251,184 | —- | C] () – C:\Documents and Settings\Anna\Desktop\meowmeow.jpg
[2012/10/09 21:12:40 | 007,415,240 | —- | C] () – C:\Documents and Settings\Anna\Desktop\Image3.pspimage
[2012/10/08 04:03:39 | 000,026,183 | —- | C] () – C:\Documents and Settings\Anna\My Documents\tumblr_maj9qwPy3N1rd50lho1_500.jpg
[2012/10/07 23:15:52 | 001,015,501 | —- | C] () – C:\Documents and Settings\Anna\My Documents\tumblr_maktuytrHx1qi989qo1_250.gif
[2012/10/07 23:14:39 | 000,123,962 | —- | C] () – C:\Documents and Settings\Anna\My Documents\tumblr_mamawcULP81r1cpy3o2_500.jpg
[2012/10/07 23:14:29 | 000,096,473 | —- | C] () – C:\Documents and Settings\Anna\My Documents\tumblr_mamawcULP81r1cpy3o1_500.jpg
[2012/10/07 23:14:14 | 000,025,051 | —- | C] () – C:\Documents and Settings\Anna\My Documents\tumblr_mambo1f4gs1qlx7xzo1_500.jpg
[2012/10/07 23:13:45 | 000,430,022 | —- | C] () – C:\Documents and Settings\Anna\My Documents\tumblr_mamgy7OZjZ1qg0b67.gif
[2012/10/07 23:11:20 | 000,508,905 | —- | C] () – C:\Documents and Settings\Anna\My Documents\tumblr_lfs7m8hRKa1qbxoeqo1_500.gif
[2012/10/07 23:10:28 | 000,159,719 | —- | C] () – C:\Documents and Settings\Anna\My Documents\tumblr_lty1gm3EC71r5avb2o1_500.jpg
[2012/10/07 23:07:40 | 000,390,682 | —- | C] () – C:\Documents and Settings\Anna\My Documents\tumblr_mavv3oPDSA1r384au.gif
[2012/10/07 23:07:10 | 000,510,894 | —- | C] () – C:\Documents and Settings\Anna\My Documents\tumblr_mavvz6Rxkf1qeef72.gif
[2012/10/07 23:04:05 | 000,495,726 | —- | C] () – C:\Documents and Settings\Anna\My Documents\tumblr_lrow55omdm1qeq4tyo3_r1_250.gif
[2012/10/07 22:53:30 | 000,789,712 | —- | C] () – C:\Documents and Settings\Anna\My Documents\tumblr_m88yczhtoE1rqfz4co1_500.gif
[2012/10/07 22:53:21 | 000,926,183 | —- | C] () – C:\Documents and Settings\Anna\My Documents\tumblr_m88yczhtoE1rqfz4co3_500.gif
[2012/10/07 20:46:32 | 000,447,437 | —- | C] () – C:\Documents and Settings\Anna\Desktop\tumblr_mb664rjOXz1r384au.gif
[2012/10/07 13:15:50 | 000,901,150 | —- | C] () – C:\Documents and Settings\Anna\Desktop\rachelfarns.pspimage
[2012/10/07 13:15:25 | 000,045,807 | —- | C] () – C:\Documents and Settings\Anna\Desktop\HGfarnsworth.jpg
[2012/10/07 08:26:51 | 000,115,234 | —- | C] () – C:\Documents and Settings\Anna\Desktop\fbendless wonder.png
[2012/10/07 08:26:38 | 000,044,207 | —- | C] () – C:\Documents and Settings\Anna\Desktop\fbendless wonder.jpg
[2012/10/06 11:28:13 | 000,044,368 | —- | C] () – C:\Documents and Settings\Anna\Desktop\rachelfarns.jpg
[2012/10/06 11:27:56 | 000,045,807 | —- | C] () – C:\Documents and Settings\Anna\Desktop\HGfarns.jpg
[2012/10/06 11:01:59 | 000,334,205 | —- | C] () – C:\Documents and Settings\Anna\Desktop\w13_s2e3-vet-pete-myka.jpg
[2012/10/06 08:30:35 | 000,129,632 | —- | C] () – C:\Documents and Settings\Anna\Desktop\farnsworth .jpg
[2012/10/06 08:13:13 | 001,019,590 | —- | C] () – C:\Documents and Settings\Anna\My Documents\tumblr_m6yyhxFkqr1qbu8fp.gif
[2012/10/06 08:11:49 | 001,022,541 | —- | C] () – C:\Documents and Settings\Anna\My Documents\tumblr_m70t42zmEZ1qzjk2so7_400.gif
[2012/10/06 08:11:17 | 000,865,642 | —- | C] () – C:\Documents and Settings\Anna\My Documents\tumblr_m4sexrqh5j1rqfz4co1_500.gif
[2012/10/06 08:10:08 | 000,300,130 | —- | C] () – C:\Documents and Settings\Anna\Desktop\tumblr_m8ry6lovov1qacf3wo1_r1_500.png
[2012/10/06 07:37:15 | 000,158,402 | —- | C] () – C:\Documents and Settings\Anna\Desktop\tumblr_mb4aoxU4AI1r1cpy3o1_500.jpg
[2012/10/06 04:16:18 | 000,081,583 | —- | C] () – C:\Documents and Settings\Anna\Desktop\lovelovelove.jpg
[2012/10/06 02:35:24 | 000,121,741 | —- | C] () – C:\Documents and Settings\Anna\Desktop\return-of-hg-wells.jpg
[2012/10/06 01:31:37 | 000,016,283 | —- | C] () – C:\Documents and Settings\Anna\Desktop\Carnival Queen Make-Up.JPG
[2012/10/05 22:54:56 | 000,126,771 | —- | C] () – C:\Documents and Settings\Anna\Desktop\farnsworth-idealhero-4.jpg
[2012/10/05 21:56:06 | 002,265,284 | —- | C] () – C:\Documents and Settings\Anna\Desktop\farnsworth empty.pspimage
[2012/10/05 21:08:01 | 001,351,669 | —- | C] () – C:\Documents and Settings\Anna\Desktop\Farnsworth.pspimage
[2012/10/04 05:24:42 | 000,147,280 | —- | C] () – C:\Documents and Settings\Anna\Desktop\525917_10151183062704449_1697597416_n.jpg
[2012/10/01 23:12:43 | 001,021,823 | —- | C] () – C:\Documents and Settings\Anna\My Documents\tumblr_lz94cuXDVL1qde33io1_500.gif
[2012/10/01 23:11:46 | 001,001,913 | —- | C] () – C:\Documents and Settings\Anna\My Documents\tumblr_m45rfvwyl91qde33io1_500.gif
[2012/09/30 19:39:12 | 000,004,953 | —- | C] () – C:\Documents and Settings\Anna\Desktop\Drusie.rtf
[2012/09/28 15:14:58 | 000,075,924 | —- | C] () – C:\Documents and Settings\Anna\Desktop\Incorrect answer.jpg
[2012/09/28 13:37:34 | 000,262,346 | —- | C] () – C:\Documents and Settings\Anna\Desktop\wallpaper_cast_03_1920_129011579697.jpg
[2012/09/28 12:31:40 | 000,036,673 | —- | C] () – C:\Documents and Settings\Anna\Desktop\Image72.jpg
[2012/09/28 12:15:15 | 000,037,178 | —- | C] () – C:\Documents and Settings\Anna\Desktop\Image7.jpg
[2012/08/23 01:42:11 | 000,107,520 | —- | C] () – C:\WINDOWS\System32\libgcc_s_dw2-1.dll
[2012/08/23 01:39:11 | 000,015,960 | —- | C] () – C:\WINDOWS\System32\mingwm10.dll
[2012/08/23 01:16:34 | 004,325,376 | —- | C] () – C:\WINDOWS\System32\QtGui4.dll
[2012/08/21 03:18:29 | 000,317,288 | —- | C] () – C:\Documents and Settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
[2012/04/29 14:41:54 | 000,296,448 | —- | C] () – C:\WINDOWS\Xenofex.ini
[2012/03/25 11:41:34 | 000,000,060 | —- | C] () – C:\Documents and Settings\Anna\jagex_cl_runescape_LIVE.dat
[2012/03/25 11:41:34 | 000,000,024 | —- | C] () – C:\Documents and Settings\Anna\random.dat
[2012/02/15 07:07:54 | 000,003,072 | —- | C] () – C:\WINDOWS\System32\iacenc.dll
[2011/10/15 03:43:33 | 000,000,000 | —- | C] () – C:\WINDOWS\QuickInstall.INI
[2011/10/11 11:56:04 | 000,016,896 | —- | C] () – C:\Documents and Settings\Anna\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/08/28 19:45:39 | 000,000,952 | -HS- | C] () – C:\WINDOWS\System32\KGyGaAvL.sys
[2011/08/12 12:20:14 | 000,015,896 | —- | C] () – C:\WINDOWS\System32\drivers\iKeyLFT2.dll
[2011/07/27 00:54:01 | 000,000,000 | —- | C] () – C:\WINDOWS\nsreg.dat
[2011/07/26 00:22:07 | 000,001,324 | —- | C] () – C:\WINDOWS\System32\d3d9caps.dat
[2011/07/25 01:09:37 | 000,073,728 | R— | C] () – C:\WINDOWS\System32\RtNicProp32.dll
[2011/07/25 01:08:47 | 000,004,096 | R— | C] ( ) – C:\WINDOWS\System32\IGFXDEVLib.dll
[2011/07/25 01:08:43 | 000,982,224 | R— | C] () – C:\WINDOWS\System32\igkrng500.bin
[2011/07/25 01:08:43 | 000,439,336 | R— | C] () – C:\WINDOWS\System32\igcompkrng500.bin
[2011/07/25 00:59:32 | 000,207,400 | R— | C] () – C:\WINDOWS\GSetup.exe
[2011/07/25 00:59:32 | 000,000,010 | —- | C] () – C:\WINDOWS\GSetup.ini
[2011/07/24 23:49:09 | 000,002,048 | –S- | C] () – C:\WINDOWS\bootstat.dat
[2011/07/24 23:35:53 | 000,021,640 | —- | C] () – C:\WINDOWS\System32\emptyregdb.dat
[2011/07/24 18:21:58 | 000,004,161 | —- | C] () – C:\WINDOWS\ODBCINST.INI
[2011/07/24 18:18:57 | 000,095,072 | —- | C] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2011/04/01 01:07:02 | 010,920,984 | —- | C] () – C:\WINDOWS\System32\LogiDPP.dll
[2011/04/01 01:07:02 | 000,104,472 | —- | C] () – C:\WINDOWS\System32\LogiDPPApp.exe
[2011/04/01 01:06:56 | 000,336,408 | —- | C] () – C:\WINDOWS\System32\DevManagerCore.dll
[2011/04/01 00:56:00 | 000,028,418 | —- | C] () – C:\WINDOWS\System32\lvcoinst.ini

========== ZeroAccess Check ==========

[2011/07/25 01:02:50 | 000,000,227 | RHS- | M] () – C:\WINDOWS\assembly\Desktop.ini

[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]

[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shdocvw.dll – [2008/04/13 20:12:05 | 001,499,136 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = C:\WINDOWS\system32\wbem\fastprox.dll – [2009/02/09 08:10:48 | 000,473,600 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
"" = C:\WINDOWS\system32\wbem\wbemess.dll – [2008/04/13 20:12:08 | 000,273,920 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Both

< End of report >





Second Roguekiller scan:


RogueKiller V8.2.0 [10/22/2012] by Tigzy
mail: tigzyRKgmailcom
Feedback: http://www.geekstogo.com/forum/files/file/413-roguekiller/
Website: http://tigzy.geekstogo.com/roguekiller.php
Blog: http://tigzyrk.blogspot.com

Operating System: Windows XP (5.1.2600 Service Pack 3) 32 bits version
Started in : Normal mode
User : Anna [Admin rights]
Mode : Scan – Date : 10/27/2012 02:46:53

¤¤¤ Bad processes : 0 ¤¤¤

¤¤¤ Registry Entries : 1 ¤¤¤
[HJ DESK] HKLM\[…]\NewStartPanel : {20D04FE0-3AEA-1069-A2D8-08002B30309D} (1) -> FOUND

¤¤¤ Particular Files / Folders: ¤¤¤

¤¤¤ Driver : [LOADED] ¤¤¤
SSDT[12] : NtAlertResumeThread @ 0x805D4BDC -> HOOKED (Unknown @ 0x85D211C0)
SSDT[13] : NtAlertThread @ 0x805D4B8C -> HOOKED (Unknown @ 0x85D1A0A8)
SSDT[17] : NtAllocateVirtualMemory @ 0x805A8AC2 -> HOOKED (Unknown @ 0x85B6BCC0)
SSDT[19] : NtAssignProcessToJobObject @ 0x805D66A0 -> HOOKED (Unknown @ 0x85BA8E90)
SSDT[31] : NtConnectPort @ 0x805A45D8 -> HOOKED (Unknown @ 0x85332838)
SSDT[43] : NtCreateMutant @ 0x8061758E -> HOOKED (Unknown @ 0x85ACA0C0)
SSDT[52] : NtCreateSymbolicLinkObject @ 0x805C3A02 -> HOOKED (Unknown @ 0x85AC3130)
SSDT[53] : NtCreateThread @ 0x805D1038 -> HOOKED (Unknown @ 0x85BE4460)
SSDT[57] : NtDebugActiveProcess @ 0x80643A1C -> HOOKED (Unknown @ 0x85D580A8)
SSDT[68] : NtDuplicateObject @ 0x805BE010 -> HOOKED (Unknown @ 0x85F76D30)
SSDT[83] : NtFreeVirtualMemory @ 0x805B2FBA -> HOOKED (Unknown @ 0x85CEF2A8)
SSDT[89] : NtImpersonateAnonymousToken @ 0x805F9258 -> HOOKED (Unknown @ 0x85FE91F8)
SSDT[91] : NtImpersonateThread @ 0x805D7860 -> HOOKED (Unknown @ 0x85F6A1C0)
SSDT[97] : NtLoadDriver @ 0x80584172 -> HOOKED (Unknown @ 0x8561C060)
SSDT[108] : NtMapViewOfSection @ 0x805B2042 -> HOOKED (Unknown @ 0x85BE7810)
SSDT[114] : NtOpenEvent @ 0x8060EF4C -> HOOKED (Unknown @ 0x85D1FE48)
SSDT[122] : NtOpenProcess @ 0x805CB456 -> HOOKED (Unknown @ 0x85CEF3C8)
SSDT[123] : NtOpenProcessToken @ 0x805EDF26 -> HOOKED (Unknown @ 0x85F81470)
SSDT[125] : NtOpenSection @ 0x805AA3F4 -> HOOKED (Unknown @ 0x85D26480)
SSDT[128] : NtOpenThread @ 0x805CB6E2 -> HOOKED (Unknown @ 0x85D031E8)
SSDT[137] : NtProtectVirtualMemory @ 0x805B8426 -> HOOKED (Unknown @ 0x85B0B268)
SSDT[206] : NtResumeThread @ 0x805D4A18 -> HOOKED (Unknown @ 0x85D1F1C8)
SSDT[213] : NtSetContextThread @ 0x805D2C1A -> HOOKED (Unknown @ 0x85D24800)
SSDT[228] : NtSetInformationProcess @ 0x805CDEA0 -> HOOKED (Unknown @ 0x85CEF0F8)
SSDT[240] : NtSetSystemInformation @ 0x8060FC04 -> HOOKED (Unknown @ 0x85D275E0)
SSDT[253] : NtSuspendProcess @ 0x805D4AE0 -> HOOKED (Unknown @ 0x85D0F640)
SSDT[254] : NtSuspendThread @ 0x805D4952 -> HOOKED (Unknown @ 0x85F19728)
SSDT[257] : NtTerminateProcess @ 0x805D22D8 -> HOOKED (Unknown @ 0x85B61FD0)
SSDT[258] : NtTerminateThread @ 0x805D24D2 -> HOOKED (Unknown @ 0x85D54B40)
SSDT[267] : NtUnmapViewOfSection @ 0x805B2E50 -> HOOKED (Unknown @ 0x85D2D658)
SSDT[277] : NtWriteVirtualMemory @ 0x805B43D4 -> HOOKED (Unknown @ 0x85B8A0B8)
S_SSDT[307] : NtUserAttachThreadInput -> HOOKED (Unknown @ 0x85BA1A80)
S_SSDT[383] : NtUserGetAsyncKeyState -> HOOKED (Unknown @ 0x85BA50D0)
S_SSDT[414] : NtUserGetKeyboardState -> HOOKED (Unknown @ 0x85BA56A8)
S_SSDT[416] : NtUserGetKeyState -> HOOKED (Unknown @ 0x85BA4E90)
S_SSDT[428] : NtUserGetRawInputData -> HOOKED (Unknown @ 0x85D3B990)
S_SSDT[460] : NtUserMessageCall -> HOOKED (Unknown @ 0x85A73238)
S_SSDT[475] : NtUserPostMessage -> HOOKED (Unknown @ 0x85C0A648)
S_SSDT[476] : NtUserPostThreadMessage -> HOOKED (Unknown @ 0x852891B0)
S_SSDT[549] : NtUserSetWindowsHookEx -> HOOKED (Unknown @ 0x85D181D0)
S_SSDT[552] : NtUserSetWinEventHook -> HOOKED (Unknown @ 0x85D200B0)

¤¤¤ HOSTS File: ¤¤¤
–> C:\WINDOWS\system32\drivers\etc\hosts

127.0.0.1 localhost


¤¤¤ MBR Check: ¤¤¤

+++++ PhysicalDrive0: SAMSUNG SP1614N +++++
— User —
[MBR] 3a33b5c3bfd5886a8678f64d459b5db7
[BSP] a75b20bb05e18eda5a0213cb968b814a : Windows XP MBR Code
Partition table:
0 - [ACTIVE] NTFS (0x07) [VISIBLE] Offset (sectors): 63 | Size: 152625 Mo
User = LL1 … OK!
User = LL2 … OK!

+++++ PhysicalDrive1: Kingston DataTraveler 2.0 USB Device +++++
— User —
[MBR] b24c72d06a8ffcc127048ae80a73b708
[BSP] f1a6a8365d3ebae60ca5a197dc1f168b : MBR Code unknown
Partition table:
0 - [XXXXXX] UNKNOWN (0x72) [VISIBLE] Offset (sectors): 778135908 | Size: 557377 Mo
1 - [XXXXXX] UNKNOWN (0x65) [VISIBLE] Offset (sectors): 168689522 | Size: 945326 Mo
2 - [XXXXXX] UNKNOWN (0x79) [VISIBLE] Offset (sectors): 1869881465 | Size: 945326 Mo
3 - [XXXXXX] UNKNOWN (0x0d) [VISIBLE] Offset (sectors): 0 | Size: 1775989 Mo
User = LL1 … OK!
Error reading LL2 MBR!

Finished : << RKreport[2].txt >>
RKreport[1].txt ; RKreport[2].txt
Hi Saquin,

[external image: Posted Image]
Download GMER Rootkit Scanner from here or here.
  • Extract the contents of the zipped file to desktop.
  • Double click GMER.exe. If asked to allow gmer.sys driver to load, please consent .
  • If it gives you a warning about rootkit activity and asks if you want to run scan…click on NO.

    [external image: Posted Image]
    Click the image to enlarge it
  • In the right panel, you will see several boxes that have been checked. Uncheck the following …
    • IAT/EAT
    • Drives/Partition other than Systemdrive (typically C:\)
    • Show All (don't miss this one)
  • Then click the Scan button & wait for it to finish.
  • Once done click on the [Save..] button, and in the File name area, type in "Gmer.txt" or it will save as a .log file which cannot be uploaded to your post.
  • Save it where you can easily find it, such as your desktop, and attach it in your reply.
**Caution**Rootkit scans often produce false positives. Do NOT take any action on any "<— ROOKIT" entries.

In your next post please provide the following:
  • Gmer.txt
  • Tell me how your computer is running at the moment, any issues?
The computer now won't turn on. I had to force it off by the power after it completely froze up after I logged into my Sister's desktop to find the CPU completely overburdened after she was running IE+two security programs, and now it just won't come back on at all. I never got a chance to run another GMER. Any suggestions?
Hi Saquin,

The computer now won't turn on. I had to force it off by the power after it completely froze up after I logged into my Sister's desktop to find the CPU completely overburdened after she was running IE+two security programs, and now it just won't come back on at all. I never got a chance to run another GMER. Any suggestions?

  • Can you explain in more detail what the computer will / will not do?
    • i.e … won't power up at all, powers up but you can't log on
  • What brand & model is the computer?
  • Was the computer exposed to any power surges from hurricane Sandy?
Finally the storm issue is mostly over. Sorry for the absence.


GMER 1.0.15.15641 - http://www.gmer.net
Rootkit scan 2012-11-04 02:48:50
Windows 5.1.2600 Service Pack 3 Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T1L0-c rev.
Running: gmer.exe; Driver: C:\DOCUME~1\Anna\LOCALS~1\Temp\kfldakod.sys


—- System - GMER 1.0.15 —-

SSDT 85B4A8C0 ZwAlertResumeThread
SSDT 85B25428 ZwAlertThread
SSDT 85B47230 ZwAllocateVirtualMemory
SSDT 85399408 ZwAssignProcessToJobObject
SSDT 853A9750 ZwConnectPort
SSDT \??\C:\WINDOWS\system32\Drivers\SYMEVENT.SYS (Symantec Event Library/Symantec Corporation) ZwCreateKey [0xA9DB7980]
SSDT 85ADE188 ZwCreateMutant
SSDT 85BA1938 ZwCreateSymbolicLinkObject
SSDT 854370B0 ZwCreateThread
SSDT 85B4B800 ZwDebugActiveProcess
SSDT \??\C:\WINDOWS\system32\Drivers\SYMEVENT.SYS (Symantec Event Library/Symantec Corporation) ZwDeleteKey [0xA9DB7C00]
SSDT \??\C:\WINDOWS\system32\Drivers\SYMEVENT.SYS (Symantec Event Library/Symantec Corporation) ZwDeleteValueKey [0xA9DB7F10]
SSDT 85B25460 ZwDuplicateObject
SSDT 85AD9DB0 ZwFreeVirtualMemory
SSDT 85B35360 ZwImpersonateAnonymousToken
SSDT 85B3CD58 ZwImpersonateThread
SSDT 85B447B0 ZwLoadDriver
SSDT 852DD1E8 ZwMapViewOfSection
SSDT 85B499E8 ZwOpenEvent
SSDT 85B5C4E0 ZwOpenProcess
SSDT 85B401F0 ZwOpenProcessToken
SSDT 85B1C390 ZwOpenSection
SSDT 85ADA558 ZwOpenThread
SSDT 85B84A70 ZwProtectVirtualMemory
SSDT \??\C:\WINDOWS\system32\Drivers\SYMEVENT.SYS (Symantec Event Library/Symantec Corporation) ZwRenameKey [0xA9DB8400]
SSDT 85ADA520 ZwResumeThread
SSDT 852041E0 ZwSetContextThread
SSDT 85D04420 ZwSetInformationProcess
SSDT 85A684F0 ZwSetSystemInformation
SSDT \??\C:\WINDOWS\system32\Drivers\SYMEVENT.SYS (Symantec Event Library/Symantec Corporation) ZwSetValueKey [0xA9DB8160]
SSDT 85B5FBC8 ZwSuspendProcess
SSDT 85B5C4A8 ZwSuspendThread
SSDT 85ADF498 ZwTerminateProcess
SSDT 85A5DBF8 ZwTerminateThread
SSDT 85A76A40 ZwUnmapViewOfSection
SSDT 85B35398 ZwWriteVirtualMemory

—- Kernel code sections - GMER 1.0.15 —-

.text ntkrnlpa.exe!ZwCallbackReturn + 2D8C 80504684 4 Bytes CALL F8D5745A
.text ntkrnlpa.exe!ZwCallbackReturn + 2DA4 8050469C 4 Bytes [E8, 99, B4, 85]
? SYMDS.SYS The system cannot find the file specified. !
? SYMEFA.SYS The system cannot find the file specified. !

—- User code sections - GMER 1.0.15 —-

.text C:\Program Files\Palm\Hotsync.exe[2060] msvcrt.dll!??2@YAPAXI@Z 77C29CC5 5 Bytes JMP 0A93C080 C:\Program Files\Palm\SHW32.DLL (Memory Management Library for Win32/MicroQuill Software Publishing, Inc.)
.text C:\Program Files\Palm\Hotsync.exe[2060] msvcrt.dll!??3@YAXPAX@Z 77C29CDD 5 Bytes JMP 0A93C0E0 C:\Program Files\Palm\SHW32.DLL (Memory Management Library for Win32/MicroQuill Software Publishing, Inc.)
.text C:\Program Files\Palm\Hotsync.exe[2060] msvcrt.dll!?set_new_handler@@YAP6AXXZP6AXXZ@Z 77C29D9F 5 Bytes JMP 0A93C110 C:\Program Files\Palm\SHW32.DLL (Memory Management Library for Win32/MicroQuill Software Publishing, Inc.)
.text C:\Program Files\Palm\Hotsync.exe[2060] msvcrt.dll!_aligned_offset_malloc 77C29DAF 5 Bytes JMP 0A93BFE0 C:\Program Files\Palm\SHW32.DLL (Memory Management Library for Win32/MicroQuill Software Publishing, Inc.)
.text C:\Program Files\Palm\Hotsync.exe[2060] msvcrt.dll!_aligned_free 77C29E33 5 Bytes JMP 0A93C0E0 C:\Program Files\Palm\SHW32.DLL (Memory Management Library for Win32/MicroQuill Software Publishing, Inc.)
.text C:\Program Files\Palm\Hotsync.exe[2060] msvcrt.dll!_aligned_malloc 77C29E52 5 Bytes JMP 0A93BFC0 C:\Program Files\Palm\SHW32.DLL (Memory Management Library for Win32/MicroQuill Software Publishing, Inc.)
.text C:\Program Files\Palm\Hotsync.exe[2060] msvcrt.dll!_aligned_offset_realloc 77C29E6E 5 Bytes JMP 0A93C020 C:\Program Files\Palm\SHW32.DLL (Memory Management Library for Win32/MicroQuill Software Publishing, Inc.)
.text C:\Program Files\Palm\Hotsync.exe[2060] msvcrt.dll!_aligned_realloc 77C29FC6 5 Bytes JMP 0A93C000 C:\Program Files\Palm\SHW32.DLL (Memory Management Library for Win32/MicroQuill Software Publishing, Inc.)
.text C:\Program Files\Palm\Hotsync.exe[2060] msvcrt.dll!_expand 77C29FE5 5 Bytes JMP 0A93BFA0 C:\Program Files\Palm\SHW32.DLL (Memory Management Library for Win32/MicroQuill Software Publishing, Inc.)
.text C:\Program Files\Palm\Hotsync.exe[2060] msvcrt.dll!_heapadd 77C2BC9F 5 Bytes JMP 0A93C160 C:\Program Files\Palm\SHW32.DLL (Memory Management Library for Win32/MicroQuill Software Publishing, Inc.)
.text C:\Program Files\Palm\Hotsync.exe[2060] msvcrt.dll!_heapchk 77C2BCB3 5 Bytes JMP 0A93C170 C:\Program Files\Palm\SHW32.DLL (Memory Management Library for Win32/MicroQuill Software Publishing, Inc.)
.text C:\Program Files\Palm\Hotsync.exe[2060] msvcrt.dll!_heapset + 1 77C2BD83 4 Bytes JMP 0A93C191 C:\Program Files\Palm\SHW32.DLL (Memory Management Library for Win32/MicroQuill Software Publishing, Inc.)
.text C:\Program Files\Palm\Hotsync.exe[2060] msvcrt.dll!_heapmin 77C2BD8C 5 Bytes JMP 0A93C260 C:\Program Files\Palm\SHW32.DLL (Memory Management Library for Win32/MicroQuill Software Publishing, Inc.)
.text C:\Program Files\Palm\Hotsync.exe[2060] msvcrt.dll!_heapused 77C2BE3A 5 Bytes JMP 0A93C230 C:\Program Files\Palm\SHW32.DLL (Memory Management Library for Win32/MicroQuill Software Publishing, Inc.)
.text C:\Program Files\Palm\Hotsync.exe[2060] msvcrt.dll!_heapwalk 77C2BE4D 5 Bytes JMP 0A93C1A0 C:\Program Files\Palm\SHW32.DLL (Memory Management Library for Win32/MicroQuill Software Publishing, Inc.)
.text C:\Program Files\Palm\Hotsync.exe[2060] msvcrt.dll!_msize 77C2BF6C 5 Bytes JMP 0A93BEB0 C:\Program Files\Palm\SHW32.DLL (Memory Management Library for Win32/MicroQuill Software Publishing, Inc.)
.text C:\Program Files\Palm\Hotsync.exe[2060] msvcrt.dll!calloc 77C2C0C3 5 Bytes JMP 0A93BE50 C:\Program Files\Palm\SHW32.DLL (Memory Management Library for Win32/MicroQuill Software Publishing, Inc.)
.text C:\Program Files\Palm\Hotsync.exe[2060] msvcrt.dll!free 77C2C21B 5 Bytes JMP 0A93C0E0 C:\Program Files\Palm\SHW32.DLL (Memory Management Library for Win32/MicroQuill Software Publishing, Inc.)
.text C:\Program Files\Palm\Hotsync.exe[2060] msvcrt.dll!malloc 77C2C407 5 Bytes JMP 0A93BE10 C:\Program Files\Palm\SHW32.DLL (Memory Management Library for Win32/MicroQuill Software Publishing, Inc.)
.text C:\Program Files\Palm\Hotsync.exe[2060] msvcrt.dll!realloc 77C2C437 5 Bytes JMP 0A93BE90 C:\Program Files\Palm\SHW32.DLL (Memory Management Library for Win32/MicroQuill Software Publishing, Inc.)

—- Devices - GMER 1.0.15 —-

Device Ntfs.sys (NT File System Driver/Microsoft Corporation)
Device Fastfat.SYS (Fast FAT File System Driver/Microsoft Corporation)

AttachedDevice \Driver\Tcpip \Device\Ip SYMTDI.SYS (Network Dispatch Driver/Symantec Corporation)
AttachedDevice \Driver\Tcpip \Device\Tcp SYMTDI.SYS (Network Dispatch Driver/Symantec Corporation)
AttachedDevice \Driver\Tcpip \Device\Udp SYMTDI.SYS (Network Dispatch Driver/Symantec Corporation)
AttachedDevice \Driver\Tcpip \Device\RawIp SYMTDI.SYS (Network Dispatch Driver/Symantec Corporation)

Device mrxsmb.sys (Windows NT SMB Minirdr/Microsoft Corporation)

AttachedDevice fltmgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)

—- Disk sectors - GMER 1.0.15 —-

Disk \Device\Harddisk0\DR0 sector 00: rootkit-like behavior

—- EOF - GMER 1.0.15 —-
Hi Saguin,

Please download MBRCheck.exe to your desktop.
  • Be sure to disable your security programs
  • Double click on the file to run it (Vista and Windows 7 users will have to confirm the UAC prompt)
  • A window will open on your desktop
  • if an unknown bootcode is found you will have further options available to you, at this time press N then press Enter twice.
  • If nothing unusual is found just press Enter
  • A .txt file named MBRCheck_mm.dd.yy_hh.mm.ss should appear on your desktop.
  • Please post the contents of that file.
MBRCheck, version 1.2.3 © 2010, AD Command-line: Windows Version: Windows XP Home Edition Windows Information: Service Pack 3 (build 2600) Logical Drives Mask: 0x0000001d Kernel Drivers (total 129): 0x804D7000 \WINDOWS\system32\ntkrnlpa.exe 0x806E5000 \WINDOWS\system32\hal.dll 0xF7A2C000 \WINDOWS\system32\KDCOM.DLL 0xF793C000 \WINDOWS\system32\BOOTVID.dll 0xF73FD000 ACPI.sys 0xF7A2E000 \WINDOWS\system32\DRIVERS\WMILIB.SYS 0xF73EC000 pci.sys 0xF752C000 isapnp.sys 0xF7AF4000 pciide.sys 0xF77AC000 \WINDOWS\system32\DRIVERS\PCIIDEX.SYS 0xF753C000 MountMgr.sys 0xF73CD000 ftdisk.sys 0xF77B4000 PartMgr.sys 0xF754C000 VolSnap.sys 0xF73B5000 atapi.sys 0xF755C000 disk.sys 0xF756C000 \WINDOWS\system32\DRIVERS\CLASSPNP.SYS 0xF7395000 fltmgr.sys 0xF733E000 SYMDS.SYS 0xF732C000 sr.sys 0xF7271000 SYMEFA.SYS 0xF725A000 KSecDD.sys 0xF71CD000 Ntfs.sys 0xF71A0000 NDIS.sys 0xF7186000 Mup.sys 0xF76DC000 \SystemRoot\system32\DRIVERS\intelppm.sys 0xF6892000 \SystemRoot\system32\DRIVERS\igxpmp32.sys 0xF687E000 \SystemRoot\system32\DRIVERS\VIDEOPRT.SYS 0xF6856000 \SystemRoot\system32\DRIVERS\HDAudBus.sys 0xF682A000 \SystemRoot\system32\DRIVERS\Rtenicxp.sys 0xF7854000 \SystemRoot\system32\DRIVERS\usbuhci.sys 0xF6806000 \SystemRoot\system32\DRIVERS\USBPORT.SYS 0xF785C000 \SystemRoot\system32\DRIVERS\usbehci.sys 0xF7864000 \SystemRoot\system32\DRIVERS\fdc.sys 0xF76EC000 \SystemRoot\system32\DRIVERS\serial.sys 0xF7A08000 \SystemRoot\system32\DRIVERS\serenum.sys 0xF67F2000 \SystemRoot\system32\DRIVERS\parport.sys 0xF76FC000 \SystemRoot\system32\DRIVERS\i8042prt.sys 0xF786C000 \SystemRoot\System32\Drivers\GIDv2.SYS 0xF7874000 \SystemRoot\system32\DRIVERS\kbdclass.sys 0xF770C000 \SystemRoot\system32\DRIVERS\imapi.sys 0xF771C000 \SystemRoot\system32\DRIVERS\cdrom.sys 0xF772C000 \SystemRoot\system32\DRIVERS\redbook.sys 0xF67CF000 \SystemRoot\system32\DRIVERS\ks.sys 0xF787C000 \SystemRoot\system32\DRIVERS\GEARAspiWDM.sys 0xF7B1F000 \SystemRoot\system32\DRIVERS\audstub.sys 0xF773C000 \SystemRoot\system32\DRIVERS\rasl2tp.sys 0xF7A10000 \SystemRoot\system32\DRIVERS\ndistapi.sys 0xF67B8000 \SystemRoot\system32\DRIVERS\ndiswan.sys 0xF774C000 \SystemRoot\system32\DRIVERS\raspppoe.sys 0xF775C000 \SystemRoot\system32\DRIVERS\raspptp.sys 0xF7884000 \SystemRoot\system32\DRIVERS\TDI.SYS 0xF67A7000 \SystemRoot\system32\DRIVERS\psched.sys 0xF776C000 \SystemRoot\system32\DRIVERS\msgpc.sys 0xF788C000 \SystemRoot\system32\DRIVERS\ptilink.sys 0xF7894000 \SystemRoot\system32\DRIVERS\raspti.sys 0xF777C000 \SystemRoot\system32\DRIVERS\termdd.sys 0xF789C000 \SystemRoot\system32\DRIVERS\mouclass.sys 0xF7A58000 \SystemRoot\system32\DRIVERS\swenum.sys 0xF6749000 \SystemRoot\system32\DRIVERS\update.sys 0xF7A1C000 \SystemRoot\system32\DRIVERS\mssmbios.sys 0xF778C000 \SystemRoot\System32\Drivers\NDProxy.SYS 0xAA00E000 \SystemRoot\system32\drivers\RtkHDAud.sys 0xA9FEA000 \SystemRoot\system32\drivers\portcls.sys 0xF759C000 \SystemRoot\system32\drivers\drmk.sys 0xF75AC000 \SystemRoot\system32\DRIVERS\usbhub.sys 0xF7A5C000 \SystemRoot\system32\DRIVERS\USBD.SYS 0xF78B4000 \SystemRoot\system32\DRIVERS\flpydisk.sys 0xF7A5E000 \SystemRoot\System32\Drivers\Fs_Rec.SYS 0xF7BEC000 \SystemRoot\System32\Drivers\Null.SYS 0xF7A60000 \SystemRoot\System32\Drivers\Beep.SYS 0xF78C4000 \SystemRoot\system32\DRIVERS\HIDPARSE.SYS 0xF78CC000 \SystemRoot\System32\drivers\vga.sys 0xF7A62000 \SystemRoot\System32\Drivers\mnmdd.SYS 0xF7A64000 \SystemRoot\System32\DRIVERS\RDPCDD.sys 0xF78D4000 \SystemRoot\System32\Drivers\Msfs.SYS 0xF78DC000 \SystemRoot\System32\Drivers\Npfs.SYS 0xF6A6D000 \SystemRoot\system32\DRIVERS\rasacd.sys 0xA9EC7000 \SystemRoot\system32\DRIVERS\ipsec.sys 0xA9E6E000 \SystemRoot\system32\DRIVERS\tcpip.sys 0xA9DED000 \SystemRoot\System32\Drivers\N360\0502020.003\SYMTDI.SYS 0xA9DC7000 \SystemRoot\system32\DRIVERS\ipnat.sys 0xF75CC000 \SystemRoot\system32\DRIVERS\wanarp.sys 0xA9DA1000 \??\C:\WINDOWS\system32\Drivers\SYMEVENT.SYS 0xF79F8000 \SystemRoot\system32\DRIVERS\hidusb.sys 0xF761C000 \SystemRoot\system32\DRIVERS\HIDCLASS.SYS 0xA9D1A000 \SystemRoot\system32\DRIVERS\netbt.sys 0xA9CF8000 \SystemRoot\System32\drivers\afd.sys 0xF762C000 \SystemRoot\system32\DRIVERS\netbios.sys 0xA9CD4000 \SystemRoot\system32\drivers\N360\0502020.003\Ironx86.SYS 0xF763C000 \SystemRoot\system32\drivers\N360\0502020.003\SRTSPX.SYS 0xA9CA9000 \SystemRoot\system32\DRIVERS\rdbss.sys 0xA9C39000 \SystemRoot\system32\DRIVERS\mrxsmb.sys 0xF764C000 \SystemRoot\System32\Drivers\Fips.SYS 0xA9BDA000 \??\C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys 0xA9BBC000 \??\C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys 0xF792C000 \SystemRoot\system32\DRIVERS\USBSTOR.SYS 0xA9EFE000 \SystemRoot\system32\DRIVERS\mouhid.sys 0xF769C000 \SystemRoot\System32\Drivers\Cdfs.SYS 0xA9A10000 \SystemRoot\System32\Drivers\Fastfat.SYS 0xA99F8000 \SystemRoot\System32\Drivers\dump_atapi.sys 0xF7A9C000 \SystemRoot\System32\Drivers\dump_WMILIB.SYS 0xBF800000 \SystemRoot\System32\win32k.sys 0xA9E4A000 \SystemRoot\System32\drivers\Dxapi.sys 0xF7804000 \SystemRoot\System32\watchdog.sys 0xBF000000 \SystemRoot\System32\drivers\dxg.sys 0xF7C5E000 \SystemRoot\System32\drivers\dxgthk.sys 0xBF024000 \SystemRoot\System32\igxpgd32.dll 0xBF012000 \SystemRoot\System32\igxprd32.dll 0xBF05A000 \SystemRoot\System32\igxpdv32.DLL 0xBF36D000 \SystemRoot\System32\igxpdx32.DLL 0xBF71C000 \SystemRoot\System32\ATMFD.DLL 0xA98B8000 \SystemRoot\system32\DRIVERS\ndisuio.sys 0xA965B000 \SystemRoot\system32\DRIVERS\mrxdav.sys 0xF7AD8000 \SystemRoot\System32\Drivers\ParVdm.SYS 0xA94EB000 \SystemRoot\system32\DRIVERS\srv.sys 0xA90F5000 \SystemRoot\System32\Drivers\N360\0502020.003\SRTSP.SYS 0xA91CF000 \??\C:\WINDOWS\gdrv.sys 0xA8D65000 \SystemRoot\system32\drivers\wdmaud.sys 0xA9333000 \SystemRoot\system32\drivers\sysaudio.sys 0xA8A04000 \SystemRoot\System32\Drivers\HTTP.sys 0xA503E000 \??\C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_5.0.0.125\Definitions\IPSDefs\20121102.001\IDSxpx86.sys 0xA41F4000 \??\C:\DOCUME~1\Anna\LOCALS~1\Temp\kfldakod.sys 0xA4137000 \SystemRoot\system32\DRIVERS\RTL8192su.sys 0xA3429000 \??\C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_5.0.0.125\Definitions\BASHDefs\20121030.002\BHDrvx86.sys 0xA1F9A000 \??\C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_5.0.0.125\Definitions\VirusDefs\20121105.009\NAVEX15.SYS 0xA1E86000 \??\C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_5.0.0.125\Definitions\VirusDefs\20121105.009\NAVENG.SYS 0xA1E5B000 \SystemRoot\system32\drivers\kmixer.sys 0x7C900000 \WINDOWS\system32\ntdll.dll Processes (total 48): 0 System Idle Process 4 System 612 C:\WINDOWS\system32\smss.exe 844 csrss.exe 868 C:\WINDOWS\system32\winlogon.exe 912 C:\WINDOWS\system32\services.exe 924 C:\WINDOWS\system32\lsass.exe 1084 C:\WINDOWS\system32\svchost.exe 1176 svchost.exe 1216 C:\WINDOWS\system32\svchost.exe 1332 svchost.exe 1404 svchost.exe 1696 C:\WINDOWS\system32\spoolsv.exe 1740 C:\Program Files\Common Files\LogiShrd\LVMVFM\UMVPFSrv.exe 1788 svchost.exe 1820 C:\Program Files\DeviceVM\Browser Configuration Utility\BCUService.exe 1844 C:\Program Files\Gigabyte\EasySaver\essvr.exe 1860 PresentationFontCache.exe 1904 C:\Program Files\Oracle\JavaFX 2.1 Runtime\bin\jqs.exe 1940 C:\Program Files\Norton Security Suite\Engine\5.2.2.3\ccsvchst.exe 1992 C:\WINDOWS\system32\nlssrv32.exe 2028 C:\WINDOWS\system32\PSIService.exe 192 C:\WINDOWS\system32\svchost.exe 404 C:\Program Files\Constant Guard Protection Suite\IDVaultSvc.exe 736 alg.exe 3008 C:\Program Files\Norton Security Suite\Engine\5.2.2.3\ccsvchst.exe 3180 C:\WINDOWS\explorer.exe 3504 C:\Program Files\DeviceVM\Browser Configuration Utility\BCU.exe 2788 C:\WINDOWS\RTHDCPL.EXE 3640 C:\WINDOWS\system32\igfxtray.exe 3500 C:\WINDOWS\system32\hkcmd.exe 1000 C:\WINDOWS\system32\igfxsrvc.exe 3784 C:\WINDOWS\system32\igfxpers.exe 3168 C:\Program Files\SFT\GuardedID\GIDD.exe 3928 C:\WINDOWS\system32\svchost.exe 2004 C:\Program Files\Common Files\Java\Java Update\jusched.exe 828 C:\WINDOWS\system32\ctfmon.exe 1264 C:\Program Files\Messenger\msmsgs.exe 1300 C:\WINDOWS\system32\wuauclt.exe 1584 C:\Program Files\Constant Guard Protection Suite\IDVault.exe 2060 C:\Program Files\Palm\Hotsync.exe 2756 C:\Program Files\Logitech\LWS\Webcam Software\CameraHelperShell.exe 2900 C:\Program Files\Common Files\LogiShrd\LQCVFX\COCIManager.exe 3792 C:\Program Files\Common Files\Java\Java Update\jucheck.exe 2956 C:\Program Files\Internet Explorer\iexplore.exe 2536 C:\Program Files\Internet Explorer\iexplore.exe 5924 E:\homework\MBRCheck.exe 3788 C:\Program Files\Mozilla Firefox\firefox.exe \\.\C: –> \\.\PhysicalDrive0 at offset 0x00000000`00007e00 (NTFS) PhysicalDrive0 Model Number: SAMSUNGSP1614N, Rev: TM100-24 Size Device Name MBR Status ——————————————– 149 GB \\.\PhysicalDrive0 Windows XP MBR code detected SHA1: DA38B874B7713D1B51CBC449F4EF809B0DEC644A Done!
Hi Saquin,
  • Re-run OTL (it should be located on your desktop).
  • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output.
  • Uncheck the boxes beside LOP Check and Purity Check.
  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
  • When the scan completes, it will open one notepad window. OTL.Txt.
    Note:The log can be located in the OTL. folder on you C:\ drive if they fail to open automatically.
  • Please copy (Edit->Select All, Edit->Copy) the contents of the file, and post it with your next reply.
Next

Locate Malwarebytes' Anti-Malware (it should be on your desktop).
  • Double - click the MBAM icon to launch the program.
  • Once the program has loaded, select the Update tab to get the latest updates before performing the scan.
  • Select Perform quick scan, then click Scan.

    [external image: Posted Image]

  • When the scan is complete, click OK, then Show Results to view the results.
  • Be sure that everything is checked, and click Remove Selected .
  • When completed, a log will open in Notepad. Please save it to a convenient location and post the results.
  • Note: If you receive a notice that some of the items couldn't be removed, that they have been added to the delete on reboot list, please reboot.
Next

Please run Eset Online Scanner

Administrator rights are required to run ESET Online Scanner
  • Place a check mark in the box YES, I accept the Terms Of Use
  • Click the Start button.
  • Now click the Install button.
  • Click Start. The scanner engine will initialize and update.
  • Do Not place a check mark in the box beside Remove found threats.
  • Click the Scan button. The scan will now run, please be patient.
  • When the scan finishes click the Details tab.
  • Copy and paste the contents of the C:\Program Files\ESET\log.txt into your next reply.
In your next post please provide the following:
  • OTL.txt
  • MBAM log
  • ESET log
OTL logfile created on: 11/9/2012 5:00:22 AM - Run 3
OTL by OldTimer - Version 3.2.69.0 Folder = E:\homework
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

988.42 Mb Total Physical Memory | 463.41 Mb Available Physical Memory | 46.88% Memory free
2.32 Gb Paging File | 1.55 Gb Available in Paging File | 66.87% Paging File free
Paging file location(s): C:\pagefile.sys 1476 2952 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 149.05 Gb Total Space | 130.99 Gb Free Space | 87.88% Space Free | Partition Type: NTFS
Drive E: | 953.00 Mb Total Space | 278.72 Mb Free Space | 29.25% Space Free | Partition Type: FAT

Computer Name: P-EE951AC334294 | User Name: Anna | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - E:\homework\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Constant Guard Protection Suite\IDVaultSvc.exe (White Sky, Inc.)
PRC - C:\Program Files\Constant Guard Protection Suite\IDVault.exe (White Sky, Inc.)
PRC - C:\Program Files\Oracle\JavaFX 2.1 Runtime\bin\jqs.exe (Oracle Corporation)
PRC - C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe (Malwarebytes Corporation)
PRC - C:\Program Files\Common Files\LogiShrd\LVMVFM\UMVPFSrv.exe (Logitech Inc.)
PRC - C:\Program Files\Common Files\Java\Java Update\jucheck.exe (Sun Microsystems, Inc.)
PRC - C:\Program Files\Logitech\LWS\Webcam Software\CameraHelperShell.exe ()
PRC - C:\Program Files\Common Files\LogiShrd\LQCVFX\COCIManager.exe ()
PRC - C:\Program Files\SFT\GuardedID\GIDD.exe (StrikeForce Technologies Inc.)
PRC - C:\Program Files\Norton Security Suite\Engine\5.2.2.3\ccsvchst.exe (Symantec Corporation)
PRC - C:\WINDOWS\system32\nlssrv32.exe (Nalpeiron Ltd.)
PRC - C:\Program Files\Gigabyte\EasySaver\essvr.exe ()
PRC - C:\Program Files\DeviceVM\Browser Configuration Utility\BCUService.exe (DeviceVM, Inc.)
PRC - C:\Program Files\DeviceVM\Browser Configuration Utility\BCU.exe (DeviceVM, Inc.)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\WINDOWS\system32\PSIService.exe ()
PRC - C:\Program Files\Palm\Hotsync.exe (PalmSource, Inc)


========== Modules (No Company Name) ==========

MOD - C:\Program Files\Constant Guard Protection Suite\IdVaultCore.XmlSerializers.dll ()
MOD - C:\Program Files\Constant Guard Protection Suite\sqlite3.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.WorkflowServ#\bd5bd406670d483b82bd51249eee59e3\System.WorkflowServices.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Web.Services\e70343406253e43964f9fe1f42cfbd7c\System.Web.Services.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Web\dbc413807cb7360b3e26ef3ca1d54f9a\System.Web.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Transactions\41f6f6dd0c8427d4a8e6fd3915505a6b\System.Transactions.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.ServiceProce#\8b84bb74d7724e147a642a1d5358feb7\System.ServiceProcess.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.ServiceModel#\97d635f5c656ae43d94b55e67fc4ab50\System.ServiceModel.Web.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Management\9080c8e8e7b6dfb502c1328673d636f8\System.Management.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Configuratio#\badd66e1d2b8416e9bb868ad059203c6\System.Configuration.Install.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Security\129b15861e200613ff78ae15581f9093\System.Security.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Configuration\3d5b7368bde0f65aa15d9f46b498cc89\System.Configuration.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\SMDiagnostics\660c4d6dd69ef22bc05587e1998cd135\SMDiagnostics.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.ServiceModel\bc254d2fa26664898ae21d45643bc194\System.ServiceModel.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Runtime.Seri#\505e12638acd6fdb22e1fd2d4c6fc232\System.Runtime.Serialization.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.IdentityModel\e09496ddb2bf6f3b69707924f2e6b5ff\System.IdentityModel.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\WindowsFormsIntegra#\86e11a59f02b2dda27ec2e7cba351744\WindowsFormsIntegration.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\UIAutomationProvider\f121ccced1aa14badb316d8d9be5154d\UIAutomationProvider.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Xml\3bba1b8b0b5ef0be238b011cc7a0575e\System.Xml.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\01abbadafaf265d9f4ac9bbb247acb98\System.Windows.Forms.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Drawing\d86f2038209a4cf0d0f5b30f6375c9b2\System.Drawing.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Data\12c6fe8d4dd78f9bddf847d3b2821c03\System.Data.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\8b873631a0855fb6aa0ad25f1d9de7fe\PresentationFramework.Luna.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\e4ecfaaf5417aceecb7fa8abddf06113\PresentationFramework.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\PresentationCore\f33e2a4d9b385234406fa2d662f78875\PresentationCore.ni.dll ()
MOD - C:\WINDOWS\assembly\GAC_32\System.Data\2.0.0.0__b77a5c561934e089\System.Data.dll ()
MOD - C:\WINDOWS\assembly\GAC_32\System.Transactions\2.0.0.0__b77a5c561934e089\System.Transactions.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\WindowsBase\6d8bef0d008389874e55c0308f0c18e5\WindowsBase.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System\e4b5afc4da43b1c576f9322f9f2e1bfe\System.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\mscorlib\e337c89bc9f81b69d7237aa70e935900\mscorlib.ni.dll ()
MOD - C:\Program Files\Common Files\LogiShrd\LWSPlugins\LWS\Applets\CameraHelper\DevManagerCore.dll ()
MOD - C:\Program Files\Logitech\LWS\Webcam Software\CameraHelperShell.exe ()
MOD - C:\Program Files\Common Files\LogiShrd\LQCVFX\COCIManager.exe ()
MOD - C:\Program Files\Logitech\LWS\Webcam Software\QTXml4.dll ()
MOD - C:\Program Files\Logitech\LWS\Webcam Software\ImageFormats\QJpeg4.dll ()
MOD - C:\Program Files\Logitech\LWS\Webcam Software\ImageFormats\QGif4.dll ()
MOD - C:\Program Files\Logitech\LWS\Webcam Software\QTGui4.dll ()
MOD - C:\Program Files\Logitech\LWS\Webcam Software\QTCore4.dll ()
MOD - C:\Program Files\Gigabyte\EasySaver\essvr.exe ()
MOD - C:\Program Files\DeviceVM\Browser Configuration Utility\sqlite3.dll ()
MOD - C:\WINDOWS\system32\EasyHook32.dll ()
MOD - C:\Program Files\Gigabyte\EasySaver\ycc.dll ()
MOD - C:\WINDOWS\system32\msdmo.dll ()
MOD - C:\WINDOWS\system32\PSIService.exe ()


========== Services (SafeList) ==========

SRV - (AppMgmt) – %SystemRoot%\System32\appmgmts.dll File not found
SRV - (MozillaMaintenance) – C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe (Mozilla Foundation)
SRV - (IDVaultSvc) – C:\Program Files\Constant Guard Protection Suite\IDVaultSvc.exe (White Sky, Inc.)
SRV - (SkypeUpdate) – C:\Program Files\Skype\Updater\Updater.exe (Skype Technologies)
SRV - (JavaQuickStarterService) – C:\Program Files\Oracle\JavaFX 2.1 Runtime\bin\jqs.exe (Oracle Corporation)
SRV - (UMVPFSrv) – C:\Program Files\Common Files\LogiShrd\LVMVFM\UMVPFSrv.exe (Logitech Inc.)
SRV - (N360) – C:\Program Files\Norton Security Suite\Engine\5.2.2.3\ccSvcHst.exe (Symantec Corporation)
SRV - (nlsX86cc) – C:\WINDOWS\system32\nlssrv32.exe (Nalpeiron Ltd.)
SRV - (ES lite Service) – C:\Program Files\Gigabyte\EasySaver\essvr.exe ()
SRV - (BCUService) – C:\Program Files\DeviceVM\Browser Configuration Utility\BCUService.exe (DeviceVM, Inc.)
SRV - (ProtexisLicensing) – C:\WINDOWS\system32\PSIService.exe ()


========== Driver Services (SafeList) ==========

DRV - (WDICA) – File not found
DRV - (PDRFRAME) – File not found
DRV - (PDRELI) – File not found
DRV - (PDFRAME) – File not found
DRV - (PDCOMP) – File not found
DRV - (PCIDump) – File not found
DRV - (lbrtfdc) – File not found
DRV - (kfldakod) – C:\DOCUME~1\Anna\LOCALS~1\Temp\kfldakod.sys File not found
DRV - (i2omgmt) – File not found
DRV - (Changer) – File not found
DRV - (MBAMSwissArmy) – C:\WINDOWS\system32\drivers\mbamswissarmy.sys (Malwarebytes Corporation)
DRV - (gdrv) – C:\WINDOWS\gdrv.sys (Windows ® 2000 DDK provider)
DRV - (NAVEX15) – C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_5.0.0.125\Definitions\VirusDefs\20121108.019\NAVEX15.SYS (Symantec Corporation)
DRV - (NAVENG) – C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_5.0.0.125\Definitions\VirusDefs\20121108.019\NAVENG.SYS (Symantec Corporation)
DRV - (IDSxpx86) – C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_5.0.0.125\Definitions\IPSDefs\20121108.001\IDSXpx86.sys (Symantec Corporation)
DRV - (BHDrvx86) – C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_5.0.0.125\Definitions\BASHDefs\20121030.002\BHDrvx86.sys (Symantec Corporation)
DRV - (eeCtrl) – C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys (Symantec Corporation)
DRV - (EraserUtilRebootDrv) – C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys (Symantec Corporation)
DRV - (LVUVC) – C:\WINDOWS\system32\drivers\lvuvc.sys (Logitech Inc.)
DRV - (LVRS) – C:\WINDOWS\system32\drivers\lvrs.sys (Logitech Inc.)
DRV - (PalmUSBD) – C:\WINDOWS\system32\drivers\PalmUSBD.sys (PalmSource, Inc.)
DRV - (SymEvent) – C:\WINDOWS\system32\drivers\SYMEVENT.SYS (Symantec Corporation)
DRV - (GIDv2) – C:\WINDOWS\System32\drivers\gidv2.sys (StrikeForce Technologies, Inc.)
DRV - (SYMTDI) – C:\WINDOWS\system32\drivers\N360\0502020.003\symtdi.sys (Symantec Corporation)
DRV - (SRTSP) – C:\WINDOWS\system32\drivers\N360\0502020.003\srtsp.sys (Symantec Corporation)
DRV - (SRTSPX) – C:\WINDOWS\system32\drivers\N360\0502020.003\srtspx.sys (Symantec Corporation)
DRV - (SymEFA) – C:\WINDOWS\system32\drivers\N360\0502020.003\symefa.sys (Symantec Corporation)
DRV - (SymDS) – C:\WINDOWS\system32\drivers\N360\0502020.003\symds.sys (Symantec Corporation)
DRV - (SymIRON) – C:\WINDOWS\system32\drivers\N360\0502020.003\ironx86.sys (Symantec Corporation)
DRV - (RTL8192su) – C:\WINDOWS\system32\drivers\RTL8192su.sys (Realtek Semiconductor Corporation )
DRV - (IntcAzAudAddService) – C:\WINDOWS\system32\drivers\RtkHDAud.sys (Realtek Semiconductor Corp.)
DRV - (RTLE8023xp) – C:\WINDOWS\system32\drivers\Rtenicxp.sys (Realtek Semiconductor Corporation )
DRV - (Monfilt) – C:\WINDOWS\system32\drivers\Monfilt.sys (Creative Technology Ltd.)
DRV - (Ambfilt) – C:\WINDOWS\system32\drivers\Ambfilt.sys (Creative)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://search.live.com/results.aspx?q={sea…ferrer:source?}

IE - HKCU\..\URLSearchHook: {BC86E1AB-EDA5-4059-938F-CE307B0C6F0A} - C:\Program Files\DeviceVM\Browser Configuration Utility\AddressBarSearch.dll (DeviceVM, Inc.)
IE - HKCU\..\SearchScopes,DefaultScope = {0A65ED42-75AD-4bbe-8E8B-EF542DC9B1AD}
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://search.live.com/results.aspx?q={sea…amp;Form=IE8SRC
IE - HKCU\..\SearchScopes\{0A65ED42-75AD-4bbe-8E8B-EF542DC9B1AD}: "URL" = http://search.yahoo.com/search?p={searchTe…m&type=IEBD
IE - HKCU\..\SearchScopes\{3725716F-C2A9-4c1e-968D-23988B72A3A6}: "URL" = http://www.google.com/custom?client=pub-37…q={searchTerms}
IE - HKCU\..\SearchScopes\{AFBCB7E0-F91A-4951-9F31-58FEE57A25C4}: "URL" = http://www.ask.com/web?q={SEARCHTERMS}&…eo=US&ver=5
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..browser.startup.homepage: "http://www.google.com/firefox"
FF - prefs.js..extensions.enabledAddons: [removed]:0.79.1
FF - prefs.js..extensions.enabledAddons: {84625510-7e5d-11e0-a411-0800200c9a66}:1.15
FF - prefs.js..extensions.enabledAddons: {2D3F3651-74B9-4795-BDEC-6DA2F431CB62}:2011.7.13.2
FF - prefs.js..extensions.enabledAddons: {BBDA0591-3099-440a-AA10-41764D9DB4DB}:[removed] - 2
FF - prefs.js..extensions.enabledItems: {82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}:5.6.0.8442
FF - prefs.js..extensions.enabledItems: {BBDA0591-3099-440a-AA10-41764D9DB4DB}:10.1.0.68 - 1
FF - prefs.js..extensions.enabledItems: [removed]:0.79.1
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA}:6.0.29
FF - prefs.js..extensions.enabledItems: [removed]:1.0
FF - prefs.js..extensions.enabledItems: {a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7}:20120302
FF - prefs.js..extensions.enabledItems: {5A170DD3-63CA-4c58-93B7-DE9FF536C2FF}:1.8.81
FF - user.js - File not found

FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32_11_4_402_265.dll ()
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.5.1: C:\WINDOWS\system32\npDeployJava1.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.5.1: C:\Program Files\Oracle\JavaFX 2.1 Runtime\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\5.1.10411.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{BBDA0591-3099-440a-AA10-41764D9DB4DB}: C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_5.0.0.125\IPSFFPlgn\ [2012/02/16 03:22:31 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{2D3F3651-74B9-4795-BDEC-6DA2F431CB62}: C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_5.0.0.125\coFFPlgn_2011_7_13_2 [2012/10/31 07:32:30 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{6D5C8FC4-DE46-41bf-9092-93F0F78E9115}: C:\Documents and Settings\All Users\Application Data\Norton\{78CA3BF0-9C3B-40e1-B46D-38C877EF059A}\NSM_2.2.0.28\coFFFw\
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 15.0\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2012/10/28 06:32:38 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 15.0\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins

[2011/08/13 23:48:19 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Anna\Application Data\Mozilla\Extensions
[2012/10/24 01:20:12 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Anna\Application Data\Mozilla\Firefox\Profiles\jomfg8s5.default\extensions
[2011/09/12 00:22:39 | 000,000,000 | —D | M] (Microsoft .NET Framework Assistant) – C:\Documents and Settings\Anna\Application Data\Mozilla\Firefox\Profiles\jomfg8s5.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2012/08/20 11:07:31 | 000,000,000 | —D | M] (WOT) – C:\Documents and Settings\Anna\Application Data\Mozilla\Firefox\Profiles\jomfg8s5.default\extensions\{a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7}(2)
[2011/11/19 21:19:38 | 000,000,000 | —D | M] (OptimizeGoogle) – C:\Documents and Settings\Anna\Application Data\Mozilla\Firefox\Profiles\jomfg8s5.default\extensions\[removed]
[2012/10/16 03:47:06 | 000,672,576 | —- | M] () (No name found) – C:\Documents and Settings\Anna\Application Data\Mozilla\Firefox\Profiles\jomfg8s5.default\extensions\{5A170DD3-63CA-4c58-93B7-DE9FF536C2FF}.xpi
[2012/08/31 23:49:14 | 000,036,056 | —- | M] () (No name found) – C:\Documents and Settings\Anna\Application Data\Mozilla\Firefox\Profiles\jomfg8s5.default\extensions\{84625510-7e5d-11e0-a411-0800200c9a66}.xpi
[2011/07/28 01:05:20 | 000,002,468 | —- | M] () – C:\Documents and Settings\Anna\Application Data\Mozilla\Firefox\Profiles\jomfg8s5.default\searchplugins\safesearch.xml
[2012/11/03 01:55:32 | 000,002,112 | —- | M] () – C:\Documents and Settings\Anna\Application Data\Mozilla\Firefox\Profiles\jomfg8s5.default\searchplugins\wot-safe-search.xml
[2012/10/28 06:31:50 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions
[2012/10/28 06:31:50 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}
[2012/10/31 07:32:30 | 000,000,000 | —D | M] (Norton Toolbar) – C:\DOCUMENTS AND SETTINGS\ALL USERS\APPLICATION DATA\NORTON\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_5.0.0.125\COFFPLGN_2011_7_13_2
[2012/02/16 03:22:31 | 000,000,000 | —D | M] (Symantec Intrusion Prevention) – C:\DOCUMENTS AND SETTINGS\ALL USERS\APPLICATION DATA\NORTON\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_5.0.0.125\IPSFFPLGN
[2012/10/28 06:32:38 | 000,261,600 | —- | M] (Mozilla Foundation) – C:\Program Files\mozilla firefox\components\browsercomps.dll
[2012/09/24 04:12:57 | 000,002,465 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\bing.xml
[2012/10/28 06:32:23 | 000,002,058 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\twitter.xml

O1 HOSTS File: ([2004/08/04 07:00:00 | 000,000,734 | —- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (Symantec NCO BHO) - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files\Norton Security Suite\Engine\5.2.2.3\coieplg.dll (Symantec Corporation)
O2 - BHO: (Symantec Intrusion Prevention) - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files\Norton Security Suite\Engine\5.2.2.3\ips\ipsbho.dll (Symantec Corporation)
O2 - BHO: (Java™ Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Oracle\JavaFX 2.1 Runtime\bin\ssv.dll (Oracle Corporation)
O2 - BHO: (Skype Browser Helper) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O2 - BHO: (Constant Guard Protection Suite) - {B84CDBE7-1B46-494B-A188-01D4C52DEB61} - C:\Documents and Settings\All Users\Application Data\White Sky, Inc\ID Vault\IEBHO1.12.829.1\NativeBHO.dll (WhiteSky)
O2 - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Oracle\JavaFX 2.1 Runtime\bin\jp2ssv.dll (Oracle Corporation)
O3 - HKLM\..\Toolbar: (Norton Toolbar) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Norton Security Suite\Engine\5.2.2.3\coieplg.dll (Symantec Corporation)
O3 - HKCU\..\Toolbar\WebBrowser: (Norton Toolbar) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Norton Security Suite\Engine\5.2.2.3\coieplg.dll (Symantec Corporation)
O4 - HKLM..\Run: [BCU] C:\Program Files\DeviceVM\Browser Configuration Utility\BCU.exe (DeviceVM, Inc.)
O4 - HKLM..\Run: [GIDDesktop] C:\Program Files\SFT\GuardedID\gidd.exe (StrikeForce Technologies Inc.)
O4 - HKLM..\Run: [LWS] C:\Program Files\Logitech\LWS\Webcam Software\LWS.exe (Logitech Inc.)
O4 - HKCU..\RunOnce: [FlashPlayerUpdate] C:\WINDOWS\System32\Macromed\Flash\FlashUtil32_11_4_402_265_Plugin.exe (Adobe Systems Incorporated)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Constant Guard.lnk = C:\Program Files\Constant Guard Protection Suite\IDVault.exe (White Sky, Inc.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\HOTSYNCSHORTCUTNAME.lnk = C:\Program Files\Palm\Hotsync.exe (PalmSource, Inc)
O4 - Startup: C:\Documents and Settings\Anna\Start Menu\Programs\Startup\Palm Registration.lnk = C:\Program Files\Palm\register.exe (Palm/Leader Technologies)
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O9 - Extra Button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} http://update.microsoft.com/windowsupdate/…b?1311645391250 (WUWebControl Class)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 75.75.75.75 75.75.76.76
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{AB065480-E775-4735-BD9F-CE0EDD8DCA77}: DhcpNameServer = 75.75.75.75 75.75.76.76
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) - C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O20 - Winlogon\Notify\GIDLogonXP: DllName - (GIDLogonXP.dll) - C:\WINDOWS\System32\GIDLogonXP.dll (StrikeForce Technologies Inc)
O24 - Desktop WallPaper: C:\WINDOWS\Coffee Bean.bmp
O24 - Desktop BackupWallPaper: C:\WINDOWS\Coffee Bean.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2011/07/24 22:41:50 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)

========== Files/Folders - Created Within 30 Days ==========

[2012/11/09 04:54:35 | 000,040,776 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2012/11/03 10:46:12 | 000,000,000 | —D | C] – C:\Documents and Settings\Anna\Desktop\kitten's editz & phewtews
[2012/11/03 10:39:44 | 000,000,000 | —D | C] – C:\Documents and Settings\Anna\Desktop\warehouse 13 & st0of
[2012/10/28 06:31:43 | 000,000,000 | —D | C] – C:\Program Files\Mozilla Firefox
[2012/10/27 17:33:59 | 000,000,000 | —D | C] – C:\Documents and Settings\Anna\Local Settings\Application Data\White_Sky,_Inc
[2012/10/27 01:20:55 | 000,275,696 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\mucltui.dll
[2012/10/20 14:56:56 | 000,000,000 | —D | C] – C:\TDSSKiller_Quarantine
[2012/10/18 16:10:10 | 000,000,000 | —D | C] – C:\Documents and Settings\Anna\Desktop\RK_Quarantine
[2012/10/14 21:46:22 | 000,000,000 | —D | C] – C:\Documents and Settings\LocalService\Application Data\Adobe
[2012/10/13 09:56:50 | 000,000,000 | —D | C] – C:\Documents and Settings\Anna\Application Data\Tific
[2012/10/13 09:56:40 | 000,000,000 | —D | C] – C:\Documents and Settings\Anna\Local Settings\Application Data\Symantec
[2012/10/10 23:15:02 | 000,000,000 | —D | C] – C:\Documents and Settings\Anna\Local Settings\Application Data\Identities
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2012/11/09 04:57:22 | 000,030,976 | —- | M] () – C:\{A0EB2E57-D532-48D3-9FD9-A56B2DB9EF1E}
[2012/11/09 04:54:35 | 000,040,776 | —- | M] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2012/11/07 11:06:15 | 000,044,944 | —- | M] () – C:\Documents and Settings\Anna\Desktop\Darla Karnes.jpg
[2012/11/06 16:09:32 | 000,016,896 | —- | M] () – C:\Documents and Settings\Anna\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2012/11/05 21:59:44 | 000,013,646 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2012/11/05 20:11:30 | 000,523,577 | —- | M] () – C:\Documents and Settings\Anna\My Documents\tumblr_lyovwdpg9T1qgyazf.gif
[2012/11/05 12:41:14 | 000,523,577 | —- | M] () – C:\Documents and Settings\Anna\Desktop\tumblr_lyovwdpg9T1qgyazf.gif
[2012/11/03 17:21:58 | 000,062,047 | —- | M] () – C:\Documents and Settings\Anna\Desktop\539940_620715955950_1926955227_n.jpg
[2012/11/03 09:52:38 | 000,220,494 | —- | M] () – C:\Documents and Settings\Anna\Desktop\subliminal LOVE.JPG
[2012/10/31 07:42:30 | 000,000,211 | -HS- | M] () – C:\boot.ini
[2012/10/31 07:32:29 | 000,017,488 | —- | M] (Windows ® 2000 DDK provider) – C:\WINDOWS\gdrv.sys
[2012/10/31 07:32:24 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2012/10/27 17:32:59 | 000,000,952 | -HS- | M] () – C:\WINDOWS\System32\KGyGaAvL.sys
[2012/10/27 17:32:33 | 000,001,943 | —- | M] () – C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Constant Guard.lnk
[2012/10/27 17:32:32 | 000,001,931 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Constant Guard.lnk
[2012/10/27 17:29:31 | 000,000,757 | —- | M] () – C:\Documents and Settings\Anna\Start Menu\Programs\Startup\Palm Registration.lnk
[2012/10/27 02:06:39 | 000,001,393 | —- | M] () – C:\WINDOWS\imsins.BAK
[2012/10/26 15:45:00 | 000,001,324 | —- | M] () – C:\WINDOWS\System32\d3d9caps.dat
[2012/10/25 23:06:02 | 000,156,495 | —- | M] () – C:\Documents and Settings\Anna\Desktop\forest_scene_by_therueroyale-d32r72z.jpg
[2012/10/25 04:01:31 | 001,440,054 | —- | M] () – C:\Documents and Settings\Anna\Desktop\locusts.bmp
[2012/10/24 01:47:16 | 000,048,942 | —- | M] () – C:\Documents and Settings\Anna\My Documents\60976898624A1E7449F45A58CFA_h316_w628_m4_cYkoMkSPp.jpg
[2012/10/24 01:46:44 | 000,072,837 | —- | M] () – C:\Documents and Settings\Anna\My Documents\2D4B57898F3B285FCA43464116FBB9_h316_w628_m4_cUNlDCdpE.jpg
[2012/10/22 04:31:43 | 000,498,458 | —- | M] () – C:\Documents and Settings\Anna\My Documents\tumblr_mbsiwfsvDV1r4t7nto1_500.gif
[2012/10/19 12:48:46 | 000,024,074 | —- | M] () – C:\Documents and Settings\Anna\Desktop\spanishdesert.jpg
[2012/10/18 16:08:18 | 000,429,490 | —- | M] () – C:\Documents and Settings\Anna\Desktop\Image4.pspimage
[2012/10/14 10:55:54 | 000,009,099 | —- | M] () – C:\Documents and Settings\Anna\Desktop\red.jpg
[2012/10/11 17:29:48 | 000,042,537 | —- | M] () – C:\Documents and Settings\Anna\My Documents\4.gif
[2012/10/11 17:27:34 | 000,041,302 | —- | M] () – C:\Documents and Settings\Anna\My Documents\3.gif
[2012/10/11 17:26:51 | 000,056,421 | —- | M] () – C:\Documents and Settings\Anna\My Documents\2.gif
[2012/10/11 17:26:35 | 000,042,342 | —- | M] () – C:\Documents and Settings\Anna\My Documents\1.gif
[2012/10/10 23:12:57 | 000,068,084 | —- | M] () – C:\Documents and Settings\Anna\Desktop\11-grand-central-station-_1.jpg
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]

========== Files Created - No Company Name ==========

[2012/11/09 04:57:22 | 000,030,976 | —- | C] () – C:\{A0EB2E57-D532-48D3-9FD9-A56B2DB9EF1E}
[2012/11/07 11:06:14 | 000,044,944 | —- | C] () – C:\Documents and Settings\Anna\Desktop\Darla Karnes.jpg
[2012/11/05 20:11:23 | 000,523,577 | —- | C] () – C:\Documents and Settings\Anna\My Documents\tumblr_lyovwdpg9T1qgyazf.gif
[2012/11/05 12:41:13 | 000,523,577 | —- | C] () – C:\Documents and Settings\Anna\Desktop\tumblr_lyovwdpg9T1qgyazf.gif
[2012/11/03 17:21:53 | 000,062,047 | —- | C] () – C:\Documents and Settings\Anna\Desktop\539940_620715955950_1926955227_n.jpg
[2012/11/03 09:52:38 | 000,220,494 | —- | C] () – C:\Documents and Settings\Anna\Desktop\subliminal LOVE.JPG
[2012/10/25 23:06:01 | 000,156,495 | —- | C] () – C:\Documents and Settings\Anna\Desktop\forest_scene_by_therueroyale-d32r72z.jpg
[2012/10/25 04:01:31 | 001,440,054 | —- | C] () – C:\Documents and Settings\Anna\Desktop\locusts.bmp
[2012/10/24 01:47:16 | 000,048,942 | —- | C] () – C:\Documents and Settings\Anna\My Documents\60976898624A1E7449F45A58CFA_h316_w628_m4_cYkoMkSPp.jpg
[2012/10/24 01:46:44 | 000,072,837 | —- | C] () – C:\Documents and Settings\Anna\My Documents\2D4B57898F3B285FCA43464116FBB9_h316_w628_m4_cUNlDCdpE.jpg
[2012/10/22 04:31:42 | 000,498,458 | —- | C] () – C:\Documents and Settings\Anna\My Documents\tumblr_mbsiwfsvDV1r4t7nto1_500.gif
[2012/10/19 12:48:46 | 000,024,074 | —- | C] () – C:\Documents and Settings\Anna\Desktop\spanishdesert.jpg
[2012/10/18 16:08:17 | 000,429,490 | —- | C] () – C:\Documents and Settings\Anna\Desktop\Image4.pspimage
[2012/10/14 10:55:54 | 000,009,099 | —- | C] () – C:\Documents and Settings\Anna\Desktop\red.jpg
[2012/10/11 17:29:48 | 000,042,537 | —- | C] () – C:\Documents and Settings\Anna\My Documents\4.gif
[2012/10/11 17:27:34 | 000,041,302 | —- | C] () – C:\Documents and Settings\Anna\My Documents\3.gif
[2012/10/11 17:26:51 | 000,056,421 | —- | C] () – C:\Documents and Settings\Anna\My Documents\2.gif
[2012/10/11 17:26:35 | 000,042,342 | —- | C] () – C:\Documents and Settings\Anna\My Documents\1.gif
[2012/10/10 23:12:56 | 000,068,084 | —- | C] () – C:\Documents and Settings\Anna\Desktop\11-grand-central-station-_1.jpg
[2012/08/23 00:42:11 | 000,107,520 | —- | C] () – C:\WINDOWS\System32\libgcc_s_dw2-1.dll
[2012/08/23 00:39:11 | 000,015,960 | —- | C] () – C:\WINDOWS\System32\mingwm10.dll
[2012/08/23 00:16:34 | 004,325,376 | —- | C] () – C:\WINDOWS\System32\QtGui4.dll
[2012/08/21 02:18:29 | 000,317,288 | —- | C] () – C:\Documents and Settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
[2012/04/29 13:41:54 | 000,296,448 | —- | C] () – C:\WINDOWS\Xenofex.ini
[2012/03/25 10:41:34 | 000,000,060 | —- | C] () – C:\Documents and Settings\Anna\jagex_cl_runescape_LIVE.dat
[2012/03/25 10:41:34 | 000,000,024 | —- | C] () – C:\Documents and Settings\Anna\random.dat
[2012/02/15 06:07:54 | 000,003,072 | —- | C] () – C:\WINDOWS\System32\iacenc.dll
[2011/10/15 02:43:33 | 000,000,000 | —- | C] () – C:\WINDOWS\QuickInstall.INI
[2011/10/11 10:56:04 | 000,016,896 | —- | C] () – C:\Documents and Settings\Anna\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/08/28 18:45:39 | 000,000,952 | -HS- | C] () – C:\WINDOWS\System32\KGyGaAvL.sys
[2011/08/12 11:20:14 | 000,015,896 | —- | C] () – C:\WINDOWS\System32\drivers\iKeyLFT2.dll
[2011/07/26 23:54:01 | 000,000,000 | —- | C] () – C:\WINDOWS\nsreg.dat
[2011/07/25 23:22:07 | 000,001,324 | —- | C] () – C:\WINDOWS\System32\d3d9caps.dat
[2011/07/25 00:09:37 | 000,073,728 | R— | C] () – C:\WINDOWS\System32\RtNicProp32.dll
[2011/07/25 00:08:47 | 000,004,096 | R— | C] ( ) – C:\WINDOWS\System32\IGFXDEVLib.dll
[2011/07/25 00:08:43 | 000,982,224 | R— | C] () – C:\WINDOWS\System32\igkrng500.bin
[2011/07/25 00:08:43 | 000,439,336 | R— | C] () – C:\WINDOWS\System32\igcompkrng500.bin
[2011/07/24 23:59:32 | 000,207,400 | R— | C] () – C:\WINDOWS\GSetup.exe
[2011/07/24 23:59:32 | 000,000,010 | —- | C] () – C:\WINDOWS\GSetup.ini
[2011/07/24 22:49:09 | 000,002,048 | –S- | C] () – C:\WINDOWS\bootstat.dat
[2011/07/24 22:35:53 | 000,021,640 | —- | C] () – C:\WINDOWS\System32\emptyregdb.dat
[2011/07/24 17:21:58 | 000,004,161 | —- | C] () – C:\WINDOWS\ODBCINST.INI
[2011/07/24 17:18:57 | 000,095,072 | —- | C] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2011/04/01 00:07:02 | 010,920,984 | —- | C] () – C:\WINDOWS\System32\LogiDPP.dll
[2011/04/01 00:07:02 | 000,104,472 | —- | C] () – C:\WINDOWS\System32\LogiDPPApp.exe
[2011/04/01 00:06:56 | 000,336,408 | —- | C] () – C:\WINDOWS\System32\DevManagerCore.dll
[2011/03/31 23:56:00 | 000,028,418 | —- | C] () – C:\WINDOWS\System32\lvcoinst.ini

========== ZeroAccess Check ==========

[2011/07/25 00:02:50 | 000,000,227 | RHS- | M] () – C:\WINDOWS\assembly\Desktop.ini

[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]

[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shdocvw.dll – [2008/04/13 19:12:05 | 001,499,136 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = C:\WINDOWS\system32\wbem\fastprox.dll – [2009/02/09 07:10:48 | 000,473,600 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
"" = C:\WINDOWS\system32\wbem\wbemess.dll – [2008/04/13 19:12:08 | 000,273,920 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Both

< End of report >



Malwarebytes Anti-Malware 1.65.1.1000
www.malwarebytes.org

Database version: v2012.11.09.04

Windows XP Service Pack 3 x86 NTFS
Internet Explorer 8.0.6001.18702
Anna :: P-EE951AC334294 [limited]

11/9/2012 5:11:29 AM
mbam-log-2012-11-09 (05-11-29).txt

Scan type: Quick scan
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
Scan options disabled: P2P
Objects scanned: 251134
Time elapsed: 4 minute(s), 47 second(s)

Memory Processes Detected: 0
(No malicious items detected)

Memory Modules Detected: 0
(No malicious items detected)

Registry Keys Detected: 0
(No malicious items detected)

Registry Values Detected: 0
(No malicious items detected)

Registry Data Items Detected: 0
(No malicious items detected)

Folders Detected: 0
(No malicious items detected)

Files Detected: 0
(No malicious items detected)

(end)



ESETSmartInstaller@High as downloader log:
all ok
# version=7
# OnlineScannerApp.exe=1.0.0.1
# OnlineScanner.ocx=1.0.0.6583
# api_version=3.0.2
# EOSSerial=eb715b4a2c06d84f80ed6d762aadb853
# end=finished
# remove_checked=false
# archives_checked=false
# unwanted_checked=true
# unsafe_checked=false
# antistealth_checked=true
# utc_time=2012-11-09 10:58:15
# local_time=2012-11-09 05:58:15 (-0500, Eastern Standard Time)
# country="United States"
# lang=1033
# osver=5.1.2600 NT Service Pack 3
# compatibility_mode=512 16777215 100 0 0 0 0 0
# compatibility_mode=3589 16777173 80 84 173959 103033346 0 0
# compatibility_mode=8192 67108863 100 0 0 0 0 0
# scanned=43429
# found=3
# cleaned=0
# scan_time=1449
C:\TDSSKiller_Quarantine\20.10.2012_15.55.53\mbr0000\tdlfs0000\tsk0001.dta a variant of Win32/Olmarik.AYI trojan (unable to clean) 00000000000000000000000000000000 I
C:\TDSSKiller_Quarantine\20.10.2012_15.55.53\mbr0000\tdlfs0000\tsk0008.dta Win32/Olmarik.AFK trojan (unable to clean) 00000000000000000000000000000000 I
C:\TDSSKiller_Quarantine\20.10.2012_15.55.53\mbr0000\tdlfs0000\tsk0012.dta a variant of Win32/Olmarik.AYI trojan (unable to clean) 00000000000000000000000000000000 I
Hi Saguin,

Download AdwCleaner from here and save it to your desktop.
  • Run AdwCleaner and select Delete
  • Once done it will ask to reboot, allow the reboot
  • On reboot a log will be produced, please attach the content of the log to your next reply
In your next post please provide the following:
  • AdwCleaner log
  • Any remaining issues?

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI