This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

eset found one! [Closed]

8 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Machine has been running awfully lately. Progs not running, BSODs, etc. Ran an eset scan which identified a trojan: olmarik.ayo.
Plz help.

btw, recently opened another case that was closed due to inactivity. it was not because i had slept on it, but because i didn't receive any emails notifying me of the response. it's possible it got caught in a spam folder. i promise to check back on the forum regularly whether or not i receive an email.

Here's my hijackthis!

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 2:58:56 PM, on 12/11/2012
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
c:\drivers\audio\r267815\payload\wdm\stacsv.exe
C:\Program Files\Broadcom Corporation\Broadcom USH Host Components\CV\bin\HostControlService.exe
C:\Program Files\Broadcom Corporation\Broadcom USH Host Components\CV\bin\HostStorageService.exe
C:\Program Files\Dell\Dell ControlPoint\Connection Manager\SMManager.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Program Files\Intel\ASF Agent\ASFAgent.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
C:\Program Files\Dell\Dell ControlPoint\DCPButtonSvc.exe
C:\Program Files\Dell\Dell ControlPoint\System Manager\DCPSysMgrSvc.exe
C:\WINDOWS\system32\HPSIsvc.exe
C:\Program Files\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe
C:\Program Files\Java\jre7\bin\jqs.exe
C:\Program Files\McAfee\SiteAdvisor Enterprise\McSACore.exe
C:\WINDOWS\system32\mfevtps.exe
C:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe
C:\Program Files\McAfee\Managed VirusScan\Agent\myAgtSvc.exe
C:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe
C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Wave Systems Corp\Trusted Drive Manager\TdmService.exe
C:\Program Files\Xobni\XobniService.exe
C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe
C:\Program Files\Common Files\McAfee\SystemCore\mcshield.exe
C:\WINDOWS\system32\WgaTray.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\WIDCOMM\Bluetooth Software\BtTray.exe
C:\PROGRA~1\WIDCOMM\BLUETO~1\BTSTAC~1.EXE
C:\Program Files\DellTPad\Apoint.exe
C:\WINDOWS\system32\AESTFltr.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\OA001Mon.exe
C:\Program Files\DellTPad\ApMsgFwd.exe
C:\Program Files\Intel\Intel® Rapid Storage Technology\IAStorIcon.exe
C:\Program Files\DellTPad\HidFind.exe
C:\Program Files\DellTPad\Apntex.exe
C:\Program Files\Wave Systems Corp\Services Manager\Docmgr\bin\WavXDocMgr.exe
C:\Program Files\Wave Systems Corp\SecureUpgrade.exe
C:\Program Files\Dell\Dell ControlPoint\Dell.ControlPoint.exe
C:\Program Files\Dell\Dell ControlPoint\Connection Manager\Dell.UCM.exe
C:\Program Files\McAfee\Managed VirusScan\DesktopUI\XTray.exe
C:\Program Files\Logitech\SetPointP\SetPoint.exe
C:\Program Files\ACT\Act for Windows\Act.Outlook.Service.exe
C:\Program Files\Adobe\Acrobat 9.0\Acrobat\Acrotray.exe
C:\Program Files\Yahoo!\Common\YMailAdvisor.exe
C:\Program Files\Dell Webcam\Dell Webcam Central\WebcamDell.exe
C:\program files\real\realplayer\update\realsched.exe
C:\Program Files\IDT\WDM\sttray.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Microsoft ActiveSync\wcescomm.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Common Files\LogiShrd\KHAL3\KHALMNPR.EXE
C:\Program Files\Dell\Dell ControlPoint\System Manager\DCPSysMgr.exe
C:\PROGRA~1\MI3AA1~1\rapimgr.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Common Files\Java\Java Update\jucheck.exe
C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE
C:\Program Files\Microsoft Office\Office12\EXCEL.EXE
C:\Program Files\ESET\ESET Online Scanner\OnlineCmdLineScanner.exe
F:\JZpersonal\system tools\HijackThis.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Yahoo!\Companion\Installs\cpn0\ytbb.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R3 - URLSearchHook: YTNavAssistPlugin Class - {81017EA9-9AA8-4A6A-9734-7AF40E7D593F} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll
O2 - BHO: Java™ Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\Common Files\McAfee\SystemCore\ScriptSn.20120711094233.dll
O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll
O2 - BHO: McAfee SiteAdvisor BHO - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - C:\Program Files\McAfee\SiteAdvisor Enterprise\McIEPlg.dll
O2 - BHO: Act.UI.InternetExplorer.Plugins.AttachFile.CAttachFile - {D5233FCD-D258-4903-89B8-FB1568E7413D} - mscoree.dll (file missing)
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll
O2 - BHO: SmartSelect - {F4971EE7-DAA0-4053-9964-665D8EE6A077} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll
O2 - BHO: SingleInstance Class - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\YTSingleInstance.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll
O3 - Toolbar: McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - C:\Program Files\McAfee\SiteAdvisor Enterprise\McIEPlg.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O4 - HKLM\..\Run: [Apoint] C:\Program Files\DellTPad\Apoint.exe
O4 - HKLM\..\Run: [AESTFltr] %SystemRoot%\system32\AESTFltr.exe /NoDlg
O4 - HKLM\..\Run: [nwiz] nwiz.exe /installquiet
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NVHotkey] rundll32.exe nvHotkey.dll,Start
O4 - HKLM\..\Run: [OA001Mon] C:\WINDOWS\OA001Mon.exe
O4 - HKLM\..\Run: [IAStorIcon] C:\Program Files\Intel\Intel® Rapid Storage Technology\IAStorIcon.exe
O4 - HKLM\..\Run: [ChangeTPMAuth] C:\Program Files\Wave Systems Corp\Common\ChangeTPMAuth.exe /T:NTRU12
O4 - HKLM\..\Run: [WavXMgr] C:\Program Files\Wave Systems Corp\Services Manager\Docmgr\bin\WavXDocMgr.exe
O4 - HKLM\..\Run: [SecureUpgrade] C:\Program Files\Wave Systems Corp\SecureUpgrade.exe
O4 - HKLM\..\Run: [EmbassySecurityCheck] "C:\Program Files\Wave Systems Corp\EMBASSY Security Setup\EMBASSYSecurityCheck.exe"
O4 - HKLM\..\Run: [DellControlPoint] "C:\Program Files\Dell\Dell ControlPoint\Dell.ControlPoint.exe"
O4 - HKLM\..\Run: [DCPstrApp] C:\Program Files\Dell\Dell ControlPoint\Security Manager\SecurityDeviceInfoSetRegistryString.exe
O4 - HKLM\..\Run: [DellConnectionManager] "C:\Program Files\Dell\Dell ControlPoint\Connection Manager\Dell.UCM.exe"
O4 - HKLM\..\Run: [MVS Splash] "C:\Program Files\McAfee\Managed VirusScan\DesktopUI\XTray.exe"
O4 - HKLM\..\Run: [EvtMgr6] C:\Program Files\Logitech\SetPointP\SetPoint.exe /launchGaming
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [Act.Outlook.Service] "C:\Program Files\ACT\Act for Windows\Act.Outlook.Service.exe"
O4 - HKLM\..\Run: [Act! Preloader] "C:\Program Files\ACT\Act for Windows\ActSage.exe" -preload
O4 - HKLM\..\Run: [Adobe Acrobat Speed Launcher] "C:\Program Files\Adobe\Acrobat 9.0\Acrobat\Acrobat_sl.exe"
O4 - HKLM\..\Run: [Acrobat Assistant 8.0] "C:\Program Files\Adobe\Acrobat 9.0\Acrobat\Acrotray.exe"
O4 - HKLM\..\Run: [YMailAdvisor] "C:\Program Files\Yahoo!\Common\YMailAdvisor.exe"
O4 - HKLM\..\Run: [Synchronization Manager] %SystemRoot%\system32\mobsync.exe /logon
O4 - HKLM\..\Run: [Dell Webcam Central] "C:\Program Files\Dell Webcam\Dell Webcam Central\WebcamDell.exe" /mode2
O4 - HKLM\..\Run: [TkBellExe] "C:\program files\real\realplayer\update\realsched.exe" -osboot
O4 - HKLM\..\Run: [SysTrayApp] %ProgramFiles%\IDT\WDM\sttray.exe
O4 - HKLM\..\Run: [APSDaemon] "C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\wcescomm.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: Bluetooth.lnk = ?
O4 - Global Startup: Dell ControlPoint System Manager.lnk = C:\Program Files\Dell\Dell ControlPoint\System Manager\DCPSysMgr.exe
O8 - Extra context menu item: Append Link Target to Existing PDF - res://C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Append to Existing PDF - res://C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert Link Target to Adobe PDF - res://C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Send to &Bluetooth Device… - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
O8 - Extra context menu item: Send To Bluetooth - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra 'Tools' menuitem: Create Mobile Favorite… - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra button: Attach Web page to ACT! contact - {6F431AC3-364A-478b-BBDB-89C7CE1B18F6} - mscoree.dll (file missing)
O9 - Extra 'Tools' menuitem: Attach Web page to ACT! contact… - {6F431AC3-364A-478b-BBDB-89C7CE1B18F6} - mscoree.dll (file missing)
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O15 - Trusted Zone: http://*.mcafee.com (HKLM)
O15 - Trusted Zone: http://betavscan.mcafeeasap.com (HKLM)
O15 - Trusted Zone: http://vs.mcafeeasap.com (HKLM)
O15 - Trusted Zone: http://www.mcafeeasap.com (HKLM)
O15 - ESC Trusted Zone: http://*.mcafee.com (HKLM)
O15 - ESC Trusted Zone: http://betavscan.mcafeeasap.com (HKLM)
O15 - ESC Trusted Zone: http://vs.mcafeeasap.com (HKLM)
O15 - ESC Trusted Zone: http://www.mcafeeasap.com (HKLM)
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/microsoftu…b?1343242725201
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftu…b?1343242718342
O16 - DPF: {72C23FEC-3AF9-48FC-9597-241A8EBDFE0A} (InstallShield International Setup Player) - http://www.trimble.com/datatransfer/v155/isetupml.cab
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} (OnlineScanner Control) - http://download.eset.com/special/eos/OnlineScanner.cab
O16 - DPF: {C1FDEE68-98D5-4F42-A4DD-D0BECF5077EB} (EPUImageControl Class) - http://tools.ebayimg.com/eps/wl/activex/eB…l_v1-0-31-0.cab
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = waypoint.local
O17 - HKLM\Software\..\Telephony: DomainName = waypoint.local
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = waypoint.local
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = waypoint.local
O17 - HKLM\System\CS3\Services\Tcpip\Parameters: Domain = waypoint.local
O18 - Protocol: dssrequest - {5513F07E-936B-4E52-9B00-067394E91CC5} - C:\Program Files\McAfee\SiteAdvisor Enterprise\McIEPlg.dll
O18 - Protocol: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - C:\Program Files\McAfee\SiteAdvisor Enterprise\McIEPlg.dll
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: ACT! Scheduler - Sage Software, Inc. - C:\Program Files\ACT\Act for Windows\Act.Scheduler.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: ASF Agent (ASFAgent) - Intel Corporation - C:\Program Files\Intel\ASF Agent\ASFAgent.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
O23 - Service: Dell ControlPoint Button Service (buttonsvc32) - Dell Inc. - C:\Program Files\Dell\Dell ControlPoint\DCPButtonSvc.exe
O23 - Service: Credential Vault Host Control Service - Broadcom Corporation - C:\Program Files\Broadcom Corporation\Broadcom USH Host Components\CV\bin\HostControlService.exe
O23 - Service: Credential Vault Host Storage - Broadcom Corporation - C:\Program Files\Broadcom Corporation\Broadcom USH Host Components\CV\bin\HostStorageService.exe
O23 - Service: Dell ControlPoint System Manager (dcpsysmgrsvc) - Dell Inc. - C:\Program Files\Dell\Dell ControlPoint\System Manager\DCPSysMgrSvc.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Update Service (gupdatem) (gupdatem) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: HP SI Service (HPSIService) - HP - C:\WINDOWS\system32\HPSIsvc.exe
O23 - Service: Intel® Rapid Storage Technology (IAStorDataMgrSvc) - Intel Corporation - C:\Program Files\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Oracle Corporation - C:\Program Files\Java\jre7\bin\jqs.exe
O23 - Service: Logitech Bluetooth Service (LBTServ) - Logitech, Inc. - C:\Program Files\Common Files\LogiShrd\Bluetooth\lbtserv.exe
O23 - Service: McAfee SiteAdvisor Enterprise Service - McAfee, Inc. - C:\Program Files\McAfee\SiteAdvisor Enterprise\McSACore.exe
O23 - Service: McAfee McShield (McShield) - McAfee, Inc. - C:\Program Files\Common Files\McAfee\SystemCore\\mcshield.exe
O23 - Service: McAfee Validation Trust Protection Service (mfevtp) - McAfee, Inc. - C:\WINDOWS\system32\mfevtps.exe
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: McAfee Virus and Spyware Protection Service (myAgtSvc) - McAfee, Inc. - C:\Program Files\McAfee\Managed VirusScan\Agent\myAgtSvc.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Protexis Licensing V2 (PSI_SVC_2) - Protexis Inc. - C:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe
O23 - Service: McAfee Peer Distribution Service (RumorServer) - McAfee, Inc. - C:\Program Files\McAfee\Managed VirusScan\Agent\myAgtSvc.exe
O23 - Service: SecureStorageService - Wave Systems Corp. - C:\Program Files\Wave Systems Corp\Secure Storage Manager\SecureStorageService.exe
O23 - Service: Smith Micro Connection Manager Service (SMManager) - Smith Micro Software, Inc. - C:\Program Files\Dell\Dell ControlPoint\Connection Manager\SMManager.exe
O23 - Service: Audio Service (STacSV) - IDT, Inc. - c:\drivers\audio\r267815\payload\wdm\stacsv.exe
O23 - Service: NTRU TSS v1.2.1.27 TCS (tcsd_win32.exe) - Unknown owner - C:\Program Files\NTRU Cryptosystems\NTRU TCG Software Stack\bin\tcsd_win32.exe
O23 - Service: TdmService - Wave Systems Corp. - C:\Program Files\Wave Systems Corp\Trusted Drive Manager\TdmService.exe
O23 - Service: Trimble Positions License Service - Unknown owner - C:\Program Files\Trimble\Trimble Positions License Manager\TrimblePositionsLicenseService.exe
O23 - Service: XobniService - Xobni Corporation - C:\Program Files\Xobni\XobniService.exe
O23 - Service: Yahoo! Updater (YahooAUService) - Yahoo! Inc. - C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe

–
End of file - 19325 bytes
:welcome:

Please download Malwarebytes from Here or Here

  • Double-click mbam-setup.exe and follow the prompts to install the program.
  • At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select Perform quick scan, then click Scan.
    [external image: Posted Image]
  • When the scan is complete, click OK, then Show Results to view the results.
  • Be sure that everything is checked, and click Remove Selected .
  • When completed, a log will open in Notepad. Please save it to a convenient location and post the results.
  • Note: If you receive a notice that some of the items couldn't be removed, that they have been added to the delete on reboot list, please reboot.
Post the report please





aswMBR Log

Important! Please do not perform any fix options offered in aswMBR

Please download aswMBR to your desktop.


  • Double click the aswMBR icon to run it.
  • Click the Scan button to start scan.
  • If you are asked to update the Avast Virus database please allow it to do so.
  • When it finishes, press the Save Log button, save the logfile to your desktop and post its contents in your next reply.

[external image: Posted Image]






OTL by OldTimer
  • Download OTL to your desktop.
  • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output.
  • Click the "Scan All Users" checkbox.
  • Check the boxes beside LOP Check and Purity Check.
  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
  • When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt.
    Note:These logs can be located in the OTL. folder on you C:\ drive if they fail to open automatically.
  • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post it with your next reply. You may need two posts to fit them both in.
ran malwarbytes and it found one trojan. during remove machine locked up. had to physically shut down so i don't know if remove was completed and don't have a log. rebooted machine and am rerunning mbam now. will post upon completion (hopefully) thx for you assistance!
well, the second mbam scan found nothing. guess that's a good think (or not?). couldn't locate the log from the first scan. seems it didn't get saved. anyhow, here's the log from the new scan: Malwarebytes Anti-Malware 1.65.1.1000 www.malwarebytes.org Database version: v2012.12.13.07 Windows XP Service Pack 3 x86 NTFS Internet Explorer 8.0.6001.18702 jzipkin :: C4LHXH1 [administrator] 12/13/2012 10:12:39 AM mbam-log-2012-12-13 (10-12-39).txt Scan type: Quick scan Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM Scan options disabled: P2P Objects scanned: 381678 Time elapsed: 20 minute(s), 35 second(s) Memory Processes Detected: 0 (No malicious items detected) Memory Modules Detected: 0 (No malicious items detected) Registry Keys Detected: 0 (No malicious items detected) Registry Values Detected: 0 (No malicious items detected) Registry Data Items Detected: 0 (No malicious items detected) Folders Detected: 0 (No malicious items detected) Files Detected: 0 (No malicious items detected) (end)
aswMBR version 0.9.9.1707 Copyright© 2011 AVAST Software Run date: 2012-12-13 10:40:55 —————————– 10:40:55.354 OS Version: Windows 5.1.2600 Service Pack 3 10:40:55.354 Number of processors: 2 586 0x1706 10:40:55.354 ComputerName: C4LHXH1 UserName: jzipkin 10:40:57.304 Initialize success 10:42:08.416 AVAST engine defs: 12121301 10:42:15.297 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-1 10:42:15.297 Disk 0 Vendor: ST916031 D005 Size: 152627MB BusType: 8 10:42:15.297 Disk 0 MBR read error 0 10:42:15.297 Disk 0 MBR scan 10:42:15.390 Disk 0 unknown MBR code 10:42:15.390 MBR BIOS signature not found 0 10:42:15.406 Disk 0 scanning sectors +312576705 10:42:15.499 Disk 0 scanning C:\WINDOWS\system32\drivers 10:43:10.056 Service scanning 10:44:37.269 Modules scanning 10:44:45.887 Disk 0 trace - called modules: 10:44:45.887 ntkrnlpa.exe CLASSPNP.SYS disk.sys >>UNKNOWN [0x894c04b1]<< 10:44:45.902 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x8b893868] 10:44:46.398 3 CLASSPNP.SYS[b80f8fd7] -> nt!IofCallDriver -> [0x89268d38] 10:44:46.398 \Driver\iaStor[0x894e74b0] -> IRP_MJ_CREATE -> 0x894c04b1 10:44:47.111 AVAST engine scan C:\WINDOWS 10:45:03.029 AVAST engine scan C:\WINDOWS\system32 10:52:20.477 AVAST engine scan C:\WINDOWS\system32\drivers 10:52:52.846 AVAST engine scan C:\Documents and Settings\jzipkin 11:00:21.441 File: C:\Documents and Settings\jzipkin\Local Settings\temp\757896488.tmp **INFECTED** Win32:Kryptik-KFB [Trj] 11:12:07.445 AVAST engine scan C:\Documents and Settings\All Users 11:16:06.571 Scan finished successfully 11:19:19.123 Disk 0 MBR has been saved successfully to "C:\Documents and Settings\jzipkin\Desktop\MBR.dat" 11:19:19.138 The log file has been saved successfully to "C:\Documents and Settings\jzipkin\Desktop\aswMBR.txt"
Here's the OTL.txt. Extras.txt did not open, nor can I locate it.


OTL logfile created on: 12/13/2012 11:22:20 AM - Run 6
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Documents and Settings\jzipkin\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

3.49 Gb Total Physical Memory | 2.65 Gb Available Physical Memory | 75.83% Memory free
5.32 Gb Paging File | 4.18 Gb Available in Paging File | 78.43% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 148.99 Gb Total Space | 95.23 Gb Free Space | 63.92% Space Free | Partition Type: NTFS
Drive U: | 226.44 Gb Total Space | 58.01 Gb Free Space | 25.62% Space Free | Partition Type: NTFS
Drive W: | 226.44 Gb Total Space | 58.01 Gb Free Space | 25.62% Space Free | Partition Type: NTFS
Drive X: | 226.44 Gb Total Space | 58.01 Gb Free Space | 25.62% Space Free | Partition Type: NTFS
Drive Y: | 226.44 Gb Total Space | 58.01 Gb Free Space | 25.62% Space Free | Partition Type: NTFS
Drive Z: | 226.44 Gb Total Space | 58.01 Gb Free Space | 25.62% Space Free | Partition Type: NTFS

Computer Name: C4LHXH1 | User Name: jzipkin | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Documents and Settings\jzipkin\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Yahoo!\Companion\Installs\cpn0\ytbb.exe (Yahoo! Inc.)
PRC - C:\Program Files\Java\jre7\bin\jqs.exe (Oracle Corporation)
PRC - C:\Program Files\Trimble\Trimble Positions License Manager\TrimblePositionsLicenseService.exe ()
PRC - C:\Program Files\Adobe\Acrobat 9.0\Acrobat\acrotray.exe (Adobe Systems Inc.)
PRC - C:\Program Files\McAfee\Managed VirusScan\DesktopUI\XTray.exe (McAfee, Inc.)
PRC - C:\Program Files\McAfee\Managed VirusScan\Agent\myAgtSvc.exe (McAfee, Inc.)
PRC - C:\WINDOWS\system32\mfevtps.exe (McAfee, Inc.)
PRC - C:\Program Files\Common Files\McAfee\SystemCore\mfeann.exe (McAfee, Inc.)
PRC - C:\Program Files\Common Files\McAfee\SystemCore\mcshield.exe (McAfee, Inc.)
PRC - C:\Program Files\real\realplayer\Update\realsched.exe (RealNetworks, Inc.)
PRC - C:\Program Files\McAfee\SiteAdvisor Enterprise\McSACore.exe (McAfee, Inc.)
PRC - C:\WINDOWS\system32\HPSIsvc.exe (HP)
PRC - C:\Program Files\Logitech\SetPointP\SetPoint.exe (Logitech, Inc.)
PRC - C:\Program Files\Common Files\LogiShrd\KHAL3\KHALMNPR.exe (Logitech, Inc.)
PRC - C:\Program Files\Xobni\XobniService.exe (Xobni Corporation)
PRC - C:\Program Files\IDT\WDM\sttray.exe (IDT, Inc.)
PRC - c:\drivers\audio\R267815\payload\WDM\stacsv.exe (IDT, Inc.)
PRC - C:\WINDOWS\system32\AESTFltr.exe (Andrea Electronics Corporation)
PRC - C:\Program Files\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe (Intel Corporation)
PRC - C:\Program Files\Intel\Intel® Rapid Storage Technology\IAStorIcon.exe (Intel Corporation)
PRC - C:\Program Files\DellTPad\Apoint.exe (Alps Electric Co., Ltd.)
PRC - C:\Program Files\DellTPad\ApMsgFwd.exe (Alps Electric Co., Ltd.)
PRC - C:\WINDOWS\OA001Mon.exe (Creative Technology Ltd.)
PRC - C:\Program Files\Yahoo!\Common\YMailAdvisor.exe (Yahoo! Inc.)
PRC - C:\Program Files\ACT\Act for Windows\Act.Outlook.Service.exe (Sage Software, Inc.)
PRC - C:\Program Files\DellTPad\ApntEx.exe (Alps Electric Co., Ltd.)
PRC - C:\Program Files\DellTPad\hidfind.exe (Alps Electric Co., Ltd.)
PRC - C:\Program Files\Broadcom Corporation\Broadcom USH Host Components\CV\bin\HostStorageService.exe (Broadcom Corporation)
PRC - C:\Program Files\Broadcom Corporation\Broadcom USH Host Components\CV\bin\HostControlService.exe (Broadcom Corporation)
PRC - C:\Program Files\Dell\Dell ControlPoint\System Manager\DCPSysMgrSvc.exe (Dell Inc.)
PRC - C:\Program Files\Dell\Dell ControlPoint\System Manager\DCPSysMgr.exe (Dell Inc.)
PRC - C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe (Yahoo! Inc.)
PRC - C:\Program Files\Dell Webcam\Dell Webcam Central\WebcamDell.exe (Creative Technology Ltd.)
PRC - C:\Program Files\Dell\Dell ControlPoint\Connection Manager\Dell.UCM.exe (Smith Micro Software, Inc.)
PRC - C:\Program Files\Dell\Dell ControlPoint\Connection Manager\SMManager.exe (Smith Micro Software, Inc.)
PRC - C:\Program Files\Dell\Dell ControlPoint\DCPButtonSvc.exe (Dell Inc.)
PRC - C:\Program Files\Dell\Dell ControlPoint\Dell.ControlPoint.exe (Dell, Inc.)
PRC - C:\Program Files\WIDCOMM\Bluetooth Software\BTStackServer.exe (Broadcom Corporation.)
PRC - C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe (Broadcom Corporation.)
PRC - C:\Program Files\Wave Systems Corp\SecureUpgrade.exe (Wave Systems Corp.)
PRC - C:\Program Files\Wave Systems Corp\Trusted Drive Manager\TdmService.exe (Wave Systems Corp.)
PRC - C:\Program Files\Wave Systems Corp\Services Manager\DocMgr\bin\WavXDocMgr.exe (Wave Systems Corp.)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe (Protexis Inc.)
PRC - C:\Program Files\Intel\ASF Agent\ASFAgent.exe (Intel Corporation)


========== Modules (No Company Name) ==========

MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Genghis\c2b370b50cb728427415a168a0b94d0f\Genghis.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\IsdiInterop\15cbe7033fa44ed901f788e8d1edd131\IsdiInterop.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Management\d8ca3b9fefcda19eeecd55c239f504ba\System.Management.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\IAStorUtil\bc6961b5ff084c43cd155d345cf32b30\IAStorUtil.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\IAStorDataMgr\405aaa333051d6495921998ae300c2bf\IAStorDataMgr.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\IAStorDataMgrSvc\18514c5a20732f18d8baec6149e2f7e1\IAStorDataMgrSvc.ni.exe ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Act.Shared.Windows.#\20a528888517f9e64b7916d97f16260e\Act.Shared.Windows.Forms.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Act.Shared.Win32\4851889156d11c1906c0fb180baf46d6\Act.Shared.Win32.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Act.Shared.Utilities\3f4d07d0ffea9815d3eed978847cc5a9\Act.Shared.Utilities.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Act.Shared.LicProvi#\3750b6a7783df980e05a81310ca9d642\Act.Shared.LicProvider.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Act.Shared.Images\023b81af18a1f2848a3a103a7a8d27f7\Act.Shared.Images.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Act.Shared.Licensing\dae44b7ac058dbd9fee6772a4d463a41\Act.Shared.Licensing.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Act.Shared.Diagnost#\59932b284366cb1cbc507dfdd8809af8\Act.Shared.Diagnostics.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Act.Shared.Config\c274b408125cf8eb5ce7a85da5b3e32c\Act.Shared.Config.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Act.Shared.Collecti#\fab77578614fa43ba20fc21c5510af5c\Act.Shared.Collections.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Act.Framework\c65671a596f270fdf8e003fcce98e251\Act.Framework.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Act.Data.Resources\eda40e793c845eed0fe8ef2f4285801b\Act.Data.Resources.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Act.Data.ActDb\1c73e3a2150419412706c036da96309b\Act.Data.ActDb.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Act.Data\cb1c47070815ca680bd450c094f071b9\Act.Data.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.ServiceProce#\31b7eef43a23e7c6e93594be583f3d08\System.ServiceProcess.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Web\b809681da85a58046cb39f268b6697ad\System.Web.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Runtime.Remo#\d7ec47c4afad694faa491abd6b45928a\System.Runtime.Remoting.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.EnterpriseSe#\18a9c594469dc027497b448fb945aaca\System.EnterpriseServices.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Transactions\43b92a8dac90d1d6426274274abb69a6\System.Transactions.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Data\d309c7e5107b3aed78e097659f94543b\System.Data.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\6585a5fcaaa1b49b9a1bd9ca5c5c306e\System.Windows.Forms.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Drawing\da4bcb702feb770ce40cf1371b0c4d02\System.Drawing.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\WindowsBase\e42848e8620740a16ef83db124a05803\WindowsBase.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Xml\d35b50eb6bb7b1bfb6592419d9feba47\System.Xml.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Configuration\41cac4885974d07de06f0b4fec9883f0\System.Configuration.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System\90ad0c96693527ae685ff40019bb33b0\System.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\mscorlib\3add69b075f3da012fb97ce00cd795c0\mscorlib.ni.dll ()
MOD - C:\WINDOWS\assembly\GAC_32\System.Data\2.0.0.0__b77a5c561934e089\System.Data.dll ()
MOD - C:\WINDOWS\assembly\GAC_32\System.Transactions\2.0.0.0__b77a5c561934e089\System.Transactions.dll ()
MOD - C:\Program Files\Trimble\Trimble Positions License Manager\TrimblePositionsLicenseService.exe ()
MOD - C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll ()
MOD - C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll ()
MOD - C:\WINDOWS\system32\HP1100LM.DLL ()
MOD - C:\WINDOWS\system32\spool\prtprocs\w32x86\HP1100PP.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\Act.Outlook.Service.Shared\11.1.183.0__ebf6b2ff4d0a08aa\Act.Outlook.Service.Shared.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\Act.Outlook.Service.Desktop\11.1.183.0__ebf6b2ff4d0a08aa\Act.Outlook.Service.Desktop.dll ()
MOD - C:\WINDOWS\assembly\GAC_32\Act.Outlook.Message.Reader\11.1.183.0__ebf6b2ff4d0a08aa\Act.Outlook.Message.Reader.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\Act.Outlook.Service.AppCommon\11.1.183.0__ebf6b2ff4d0a08aa\Act.Outlook.Service.AppCommon.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\Act.Outlook.Service.Interfaces\11.1.183.0__ebf6b2ff4d0a08aa\Act.Outlook.Service.Interfaces.dll ()
MOD - C:\Program Files\Intel\Intel® Rapid Storage Technology\IsdiInterop.dll ()
MOD - C:\Program Files\Adobe\Acrobat 9.0\Acrobat\AcroTray.DEU ()
MOD - C:\Program Files\Adobe\Acrobat 9.0\Acrobat\AcroTray.FRA ()
MOD - C:\Program Files\Dell\Dell ControlPoint\Connection Manager\UCMPlugin\SmithMicro.Common.dll ()
MOD - C:\Program Files\Dell\Dell ControlPoint\Connection Manager\SMProfileManager.dll ()
MOD - C:\Program Files\Dell\Dell ControlPoint\Connection Manager\Dell.SharedUI.dll ()
MOD - C:\Program Files\Dell\Dell ControlPoint\Connection Manager\SMMessages.dll ()
MOD - C:\Program Files\Dell\Dell ControlPoint\Connection Manager\SmithMicro.AsyncOperations.dll ()
MOD - C:\Program Files\Dell\Dell ControlPoint\Connection Manager\VpnWrapper.dll ()
MOD - C:\Program Files\Dell\Dell ControlPoint\Connection Manager\SmithMicro.VpnController.dll ()
MOD - C:\Program Files\Dell\Dell ControlPoint\Connection Manager\SmithMicro.Application.dll ()
MOD - C:\Program Files\Dell\Dell ControlPoint\Connection Manager\SmithMicro.Message.dll ()
MOD - C:\Program Files\Dell\Dell ControlPoint\Connection Manager\SmithMicro.Common.dll ()
MOD - C:\WINDOWS\system32\DELG1L3.DLL ()
MOD - C:\Program Files\Dell\Dell ControlPoint\Dell.DcpPlugin.dll ()
MOD - C:\Program Files\Dell\Dell ControlPoint\SmithMicro.Common.dll ()
MOD - C:\WINDOWS\system32\btwicons.dll ()
MOD - C:\WINDOWS\system32\Wavx_ESC_Logging.dll ()
MOD - C:\WINDOWS\system32\wxvault.dll ()
MOD - C:\Program Files\ACT\Act for Windows\PSIClient.dll ()
MOD - C:\WINDOWS\system32\msdmo.dll ()
MOD - C:\Program Files\NTRU Cryptosystems\NTRU TCG Software Stack\bin\TspPopup_ENU.dll ()


========== Services (SafeList) ==========

SRV - (slee_503_service) – %systemroot%\system32\AMDPCI.dll File not found
SRV - (pavprsrv) – %systemroot%\system32\rasacd.dll File not found
SRV - (nwcworkstation) – %systemroot%\system32\yats32.dll File not found
SRV - (idebusdr) – %systemroot%\system32\dlbu_device.dll File not found
SRV - (AdobeFlashPlayerUpdateSvc) – C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe (Adobe Systems Incorporated)
SRV - (MozillaMaintenance) – C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe (Mozilla Foundation)
SRV - (JavaQuickStarterService) – C:\Program Files\Java\jre7\bin\jqs.exe (Oracle Corporation)
SRV - (Trimble Positions License Service) – C:\Program Files\Trimble\Trimble Positions License Manager\TrimblePositionsLicenseService.exe ()
SRV - (RumorServer) – C:\Program Files\McAfee\Managed VirusScan\Agent\myAgtSvc.exe (McAfee, Inc.)
SRV - (myAgtSvc) – C:\Program Files\McAfee\Managed VirusScan\Agent\myAgtSvc.exe (McAfee, Inc.)
SRV - (mfevtp) – C:\WINDOWS\system32\mfevtps.exe (McAfee, Inc.)
SRV - (McShield) – C:\Program Files\Common Files\McAfee\SystemCore\\mcshield.exe ()
SRV - (McAfee SiteAdvisor Enterprise Service) – C:\Program Files\McAfee\SiteAdvisor Enterprise\McSACore.exe (McAfee, Inc.)
SRV - (HPSIService) – C:\WINDOWS\system32\HPSIsvc.exe (HP)
SRV - (FLEXnet Licensing Service) – C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe (Macrovision Europe Ltd.)
SRV - (XobniService) – C:\Program Files\Xobni\XobniService.exe (Xobni Corporation)
SRV - (LBTServ) – C:\Program Files\Common Files\LogiShrd\Bluetooth\LBTServ.exe (Logitech, Inc.)
SRV - (STacSV) – c:\drivers\audio\R267815\payload\WDM\stacsv.exe (IDT, Inc.)
SRV - (IAStorDataMgrSvc) – C:\Program Files\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe (Intel Corporation)
SRV - (ACT! Scheduler) – C:\Program Files\ACT\Act for Windows\Act.Scheduler.exe (Sage Software, Inc.)
SRV - (Credential Vault Host Storage) – C:\Program Files\Broadcom Corporation\Broadcom USH Host Components\CV\bin\HostStorageService.exe (Broadcom Corporation)
SRV - (Credential Vault Host Control Service) – C:\Program Files\Broadcom Corporation\Broadcom USH Host Components\CV\bin\HostControlService.exe (Broadcom Corporation)
SRV - (dcpsysmgrsvc) – C:\Program Files\Dell\Dell ControlPoint\System Manager\DCPSysMgrSvc.exe (Dell Inc.)
SRV - (YahooAUService) – C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe (Yahoo! Inc.)
SRV - (SMManager) – C:\Program Files\Dell\Dell ControlPoint\Connection Manager\SMManager.exe (Smith Micro Software, Inc.)
SRV - (buttonsvc32) – C:\Program Files\Dell\Dell ControlPoint\DCPButtonSvc.exe (Dell Inc.)
SRV - (TdmService) – C:\Program Files\Wave Systems Corp\Trusted Drive Manager\TdmService.exe (Wave Systems Corp.)
SRV - (SecureStorageService) – C:\Program Files\Wave Systems Corp\Secure Storage Manager\SecureStorageService.exe (Wave Systems Corp.)
SRV - (tcsd_win32.exe) – C:\Program Files\NTRU Cryptosystems\NTRU TCG Software Stack\bin\tcsd_win32.exe ()
SRV - (PSI_SVC_2) – C:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe (Protexis Inc.)
SRV - (ASFAgent) – C:\Program Files\Intel\ASF Agent\ASFAgent.exe (Intel Corporation)


========== Driver Services (SafeList) ==========

DRV - (WDICA) – File not found
DRV - (TRMUSB5K) – system32\drivers\TRMUSB5K.sys File not found
DRV - (PDRFRAME) – File not found
DRV - (PDRELI) – File not found
DRV - (PDFRAME) – File not found
DRV - (PDCOMP) – File not found
DRV - (PCIDump) – File not found
DRV - (mfeavfk01) – File not found
DRV - (lbrtfdc) – File not found
DRV - (Changer) – File not found
DRV - (CFcatchme) – C:\DOCUME~1\jzipkin\LOCALS~1\Temp\CFcatchme.sys File not found
DRV - (catchme) – C:\ComboFix\catchme.sys File not found
DRV - (aswMBR) – C:\DOCUME~1\jzipkin\LOCALS~1\Temp\aswMBR.sys File not found
DRV - (mfehidk) – C:\WINDOWS\system32\drivers\mfehidk.sys (McAfee, Inc.)
DRV - (MfeAVFK) – C:\WINDOWS\system32\drivers\mfeavfk.sys (McAfee, Inc.)
DRV - (mfeapfk) – C:\WINDOWS\system32\drivers\mfeapfk.sys (McAfee, Inc.)
DRV - (mfetdi2k) – C:\WINDOWS\system32\drivers\mfetdi2k.sys (McAfee, Inc.)
DRV - (mferkdet) – C:\WINDOWS\system32\drivers\mferkdet.sys (McAfee, Inc.)
DRV - (MfeBOPK) – C:\WINDOWS\system32\drivers\mfebopk.sys (McAfee, Inc.)
DRV - (RsFx0105) – C:\WINDOWS\system32\drivers\RsFx0105.sys (Microsoft Corporation)
DRV - (NWADI) – C:\WINDOWS\system32\drivers\NWADIenum.sys (Novatel Wireless Inc)
DRV - (NWUSBPort2_000) – C:\WINDOWS\system32\drivers\nwusbser2_000.sys (Novatel Wireless Inc.)
DRV - (NWUSBPort_000) – C:\WINDOWS\system32\drivers\nwusbser_000.sys (Novatel Wireless Inc.)
DRV - (NWUSBModem_000) – C:\WINDOWS\system32\drivers\nwusbmdm_000.sys (Novatel Wireless Inc.)
DRV - (NWUSBCDFIL) – C:\WINDOWS\system32\drivers\NwUsbCdFil.sys (Novatel Wireless Inc.)
DRV - (SMSIVZAM5) – C:\Program Files\Verizon Wireless\VZAccess Manager\SMSIVZAM5.sys (Smith Micro Inc.)
DRV - (STHDA) – C:\WINDOWS\system32\drivers\sthda.sys (IDT, Inc.)
DRV - (AESTAud) – C:\WINDOWS\system32\drivers\AESTAud.sys (Andrea Electronics Corporation)
DRV - (LMouFilt) – C:\WINDOWS\system32\drivers\LMouFilt.Sys (Logitech, Inc.)
DRV - (LHidFilt) – C:\WINDOWS\system32\drivers\LHidFilt.Sys (Logitech, Inc.)
DRV - (LBeepKE) – C:\WINDOWS\system32\drivers\LBeepKE.sys (Logitech, Inc.)
DRV - (ApfiltrService) – C:\WINDOWS\system32\drivers\Apfiltr.sys (Alps Electric Co., Ltd.)
DRV - (OA001Vid) – C:\WINDOWS\system32\drivers\OA001Vid.sys (Creative Technology Ltd.)
DRV - (mfetdik) – C:\WINDOWS\system32\drivers\mfetdik.sys (McAfee, Inc.)
DRV - (MfeRKDK) – C:\WINDOWS\system32\drivers\mferkdk.sys (McAfee, Inc.)
DRV - (NAL) – C:\WINDOWS\system32\drivers\iqvw32.sys (Intel Corporation )
DRV - (e1yexpress) – C:\WINDOWS\system32\drivers\e1y5132.sys (Intel Corporation)
DRV - (OA001Afx) – C:\WINDOWS\system32\drivers\OA001Afx.sys (Creative Technology Ltd.)
DRV - (rimmptsk) – C:\WINDOWS\system32\drivers\rimmptsk.sys (REDC)
DRV - (OA001Ufd) – C:\WINDOWS\system32\drivers\OA001Ufd.sys (Creative Technology Ltd.)
DRV - (cvusbdrv) – C:\WINDOWS\system32\drivers\cvusbdrv.sys (Broadcom Corporation)
DRV - (USBCCID) – C:\WINDOWS\system32\drivers\usbccid.sys (Microsoft Corporation)
DRV - (CCIDFILTER) – C:\WINDOWS\system32\drivers\ccidflt.sys (Broadcom Corporation)
DRV - (BCM43XX) – C:\WINDOWS\system32\drivers\BCMWL5.SYS (Broadcom Corporation)
DRV - (btwmodem) – C:\WINDOWS\system32\drivers\btwmodem.sys (Broadcom Corporation.)
DRV - (btwhid) – C:\WINDOWS\system32\drivers\btwhid.sys (Broadcom Corporation.)
DRV - (BTWDNDIS) – C:\WINDOWS\system32\drivers\btwdndis.sys (Broadcom Corporation.)
DRV - (BTDriver) – C:\WINDOWS\system32\drivers\btport.sys (Broadcom Corporation.)
DRV - (BTKRNL) – C:\WINDOWS\system32\drivers\btkrnl.sys (Broadcom Corporation.)
DRV - (btaudio) – C:\WINDOWS\system32\drivers\btaudio.sys (Broadcom Corporation.)
DRV - (BTWUSB) – C:\WINDOWS\system32\drivers\btwusb.sys (Broadcom Corporation.)
DRV - (WavxDMgr) – C:\WINDOWS\system32\drivers\WavxDMgr.sys (Wave Systems Corp.)
DRV - (PBADRV) – C:\WINDOWS\system32\drivers\PBADRV.sys (Dell Inc)
DRV - (USA19H) – C:\WINDOWS\system32\drivers\USA19H2k.sys (Keyspan)
DRV - (USA19H2KP) – C:\WINDOWS\system32\drivers\USA19H2kp.sys (Keyspan)
DRV - (TrmbTS) – C:\WINDOWS\system32\drivers\TrmbTS.sys (Trimble AB, Sweden)
DRV - (PCASp50) – C:\WINDOWS\system32\drivers\PCASp50.sys (Printing Communications Assoc., Inc. (PCAUSA))
DRV - (WinDriver6) – C:\WINDOWS\system32\drivers\windrvr6.sys (Jungo)
DRV - (Sentinel) – C:\WINDOWS\system32\drivers\sentinel.sys (Rainbow Technologies, Inc.)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Help_Page = http://support.dell.com/support/index.aspx…;l=en&s=gen
IE - HKLM\..\SearchScopes,DefaultScope = {9BB47C17-9C68-4BB3-B188-DD9AF0FD2410}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://search.live.com/results.aspx?q={sea…ferrer:source?}
IE - HKLM\..\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2410}: "URL" = http://dts.search-results.com/sr?src=ieb&a;…q={searchTerms}


IE - HKU\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = about:blank
IE - HKU\.DEFAULT\..\URLSearchHook: {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - C:\Program Files\McAfee\SiteAdvisor Enterprise\McIEPlg.dll (McAfee, Inc.)
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local

IE - HKU\S-1-5-18\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = about:blank
IE - HKU\S-1-5-18\..\URLSearchHook: {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - C:\Program Files\McAfee\SiteAdvisor Enterprise\McIEPlg.dll (McAfee, Inc.)
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local



IE - HKU\S-1-5-21-308600077-3542235570-3293604796-1145\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://my.yahoo.com/
IE - HKU\S-1-5-21-308600077-3542235570-3293604796-1145\..\URLSearchHook: {81017EA9-9AA8-4A6A-9734-7AF40E7D593F} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll (Yahoo! Inc.)
IE - HKU\S-1-5-21-308600077-3542235570-3293604796-1145\..\SearchScopes,DefaultScope = {1866F458-8483-4815-BAD5-D7640059E447}
IE - HKU\S-1-5-21-308600077-3542235570-3293604796-1145\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}…amp;FORM=IE8SRC
IE - HKU\S-1-5-21-308600077-3542235570-3293604796-1145\..\SearchScopes\{1866F458-8483-4815-BAD5-D7640059E447}: "URL" = http://www.google.com/search?q={searchTerm…utputEncoding?}
IE - HKU\S-1-5-21-308600077-3542235570-3293604796-1145\..\SearchScopes\{7AB1F9F9-BDC2-46CC-9008-2CB7C62AB53E}: "URL" = http://search.yahoo.com/search?p={searchTe…ge?}&fr=ie8
IE - HKU\S-1-5-21-308600077-3542235570-3293604796-1145\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-308600077-3542235570-3293604796-1145\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local

========== FireFox ==========

FF - prefs.js..browser.startup.homepage: "http://my.yahoo.com/"
FF - prefs.js..extensions.enabledAddons: %7B635abd67-4fe9-1b23-4f01-e679fa7484c1%7D:2.5.1.20121008104707
FF - prefs.js..extensions.enabledAddons: %7B972ce4c6-7e08-4474-a285-3208198ce6fd%7D:17.0.1
FF - user.js - File not found

FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32_11_5_502_135.dll ()
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\WINDOWS\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.7.2: C:\WINDOWS\system32\npDeployJava1.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.7.2: C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\4.1.10329.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@real.com/nppl3260;version=12.0.1.647: c:\program files\real\realplayer\Netscape6\nppl3260.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprjplug;version=12.0.1.647: c:\program files\real\realplayer\Netscape6\nprjplug.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprpchromebrowserrecordext;version=12.0.1.652: C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprpchromebrowserrecordext.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprphtml5videoshim;version=12.0.1.652: C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprpjplug;version=12.0.1.647: c:\program files\real\realplayer\Netscape6\nprpjplug.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nsJSRealPlayerPlugin;version=: File not found
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@veetle.com/vbp;version=0.9.17: C:\Program Files\Veetle\VLCBroadcast\npvbp.dll File not found
FF - HKLM\Software\MozillaPlugins\@videolan.org/vlc,version=2.0.4: C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF - HKLM\Software\MozillaPlugins\Adobe Acrobat: C:\Program Files\Adobe\Acrobat 9.0\Acrobat\Air\nppdf32.dll (Adobe Systems Inc.)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@unity3d.com/UnityPlayer,version=1.0: C:\Documents and Settings\jzipkin\Local Settings\Application Data\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS)
FF - HKCU\Software\MozillaPlugins\@yahoo.com/BrowserPlus,version=2.9.8: C:\Documents and Settings\jzipkin\Local Settings\Application Data\Yahoo!\BrowserPlus\2.9.8\Plugins\npybrowserplus_2.9.8.dll (Yahoo! Inc.)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{ABDE892B-13A8-4d1b-88E6-365A6E755758}: C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext [2011/06/29 10:23:39 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{B7082FAA-CB62-4872-9106-E42DD88EDE45}: C:\Program Files\McAfee\SiteAdvisor Enterprise\ [2011/08/23 12:10:08 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{D19CA586-DD6C-4a0a-96F8-14644F340D60}: C:\Program Files\Common Files\McAfee\SystemCore [2012/09/21 20:19:19 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 17.0.1\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2012/12/03 15:10:17 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 17.0.1\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins

[2012/12/03 15:10:39 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\jzipkin\Application Data\Mozilla\Extensions
[2012/12/03 15:13:40 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\jzipkin\Application Data\Mozilla\Firefox\Profiles\3ek6r8ua.default\extensions
[2012/12/03 15:13:40 | 000,000,000 | —D | M] (Yahoo! Toolbar) – C:\Documents and Settings\jzipkin\Application Data\Mozilla\Firefox\Profiles\3ek6r8ua.default\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1}
[2012/12/03 15:10:17 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions
[2012/11/29 03:27:51 | 000,262,112 | —- | M] (Mozilla Foundation) – C:\Program Files\mozilla firefox\components\browsercomps.dll
[2012/11/29 03:27:12 | 000,002,465 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\bing.xml
[2012/11/29 03:27:12 | 000,002,058 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\twitter.xml

O1 HOSTS File: ([2012/06/22 09:43:28 | 000,000,027 | —- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (&Yahoo! Toolbar Helper) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll (Yahoo! Inc.)
O2 - BHO: (RealPlayer Download and Record Plugin for Internet Explorer) - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll (RealPlayer)
O2 - BHO: (Java™ Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
O2 - BHO: (scriptproxy) - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\Common Files\McAfee\SystemCore\ScriptSn.20120711094233.dll (McAfee, Inc.)
O2 - BHO: (Adobe PDF Conversion Toolbar Helper) - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O2 - BHO: (McAfee SiteAdvisor BHO) - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - C:\Program Files\McAfee\SiteAdvisor Enterprise\McIEPlg.dll (McAfee, Inc.)
O2 - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O2 - BHO: (SmartSelect Class) - {F4971EE7-DAA0-4053-9964-665D8EE6A077} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O2 - BHO: (SingleInstance Class) - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\YTSingleInstance.dll (Yahoo! Inc)
O3 - HKLM\..\Toolbar: (McAfee SiteAdvisor Toolbar) - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - C:\Program Files\McAfee\SiteAdvisor Enterprise\McIEPlg.dll (McAfee, Inc.)
O3 - HKLM\..\Toolbar: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O3 - HKLM\..\Toolbar: (Yahoo! Toolbar) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll (Yahoo! Inc.)
O3 - HKU\S-1-5-21-308600077-3542235570-3293604796-1145\..\Toolbar\WebBrowser: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O4 - HKLM..\Run: [Acrobat Assistant 8.0] C:\Program Files\Adobe\Acrobat 9.0\Acrobat\Acrotray.exe (Adobe Systems Inc.)
O4 - HKLM..\Run: [Act! Preloader] C:\Program Files\ACT\Act for Windows\ActSage.exe (Sage Software, Inc.)
O4 - HKLM..\Run: [Act.Outlook.Service] C:\Program Files\ACT\Act for Windows\Act.Outlook.Service.exe (Sage Software, Inc.)
O4 - HKLM..\Run: [Adobe Acrobat Speed Launcher] C:\Program Files\Adobe\Acrobat 9.0\Acrobat\Acrobat_sl.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [AESTFltr] C:\WINDOWS\System32\AESTFltr.exe (Andrea Electronics Corporation)
O4 - HKLM..\Run: [Apoint] C:\Program Files\DellTPad\Apoint.exe (Alps Electric Co., Ltd.)
O4 - HKLM..\Run: [APSDaemon] C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [ChangeTPMAuth] C:\Program Files\Wave Systems Corp\Common\ChangeTPMAuth.exe (Wave Systems Corp.)
O4 - HKLM..\Run: [DCPstrApp] C:\Program Files\Dell\Dell ControlPoint\Security Manager\SecurityDeviceInfoSetRegistryString.exe (Broadcom Corporation)
O4 - HKLM..\Run: [Dell Webcam Central] C:\Program Files\Dell Webcam\Dell Webcam Central\WebcamDell.exe (Creative Technology Ltd.)
O4 - HKLM..\Run: [DellConnectionManager] C:\Program Files\Dell\Dell ControlPoint\Connection Manager\Dell.UCM.exe (Smith Micro Software, Inc.)
O4 - HKLM..\Run: [DellControlPoint] C:\Program Files\Dell\Dell ControlPoint\Dell.ControlPoint.exe (Dell, Inc.)
O4 - HKLM..\Run: [EmbassySecurityCheck] C:\Program Files\Wave Systems Corp\EMBASSY Security Setup\EMBASSYSecurityCheck.exe (Wave Systems Corp.)
O4 - HKLM..\Run: [EvtMgr6] C:\Program Files\Logitech\SetPointP\SetPoint.exe (Logitech, Inc.)
O4 - HKLM..\Run: [IAStorIcon] C:\Program Files\Intel\Intel® Rapid Storage Technology\IAStorIcon.exe (Intel Corporation)
O4 - HKLM..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k File not found
O4 - HKLM..\Run: [MVS Splash] C:\Program Files\McAfee\Managed VirusScan\DesktopUI\XTray.exe (McAfee, Inc.)
O4 - HKLM..\Run: [NvCplDaemon] C:\WINDOWS\System32\NvCpl.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [NVHotkey] C:\WINDOWS\System32\nvhotkey.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [NvMediaCenter] C:\WINDOWS\System32\NvMcTray.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [nwiz] C:\WINDOWS\System32\nwiz.exe ()
O4 - HKLM..\Run: [OA001Mon] C:\WINDOWS\OA001Mon.exe (Creative Technology Ltd.)
O4 - HKLM..\Run: [SecureUpgrade] C:\Program Files\Wave Systems Corp\SecureUpgrade.exe (Wave Systems Corp.)
O4 - HKLM..\Run: [SysTrayApp] C:\Program Files\IDT\WDM\sttray.exe (IDT, Inc.)
O4 - HKLM..\Run: [TkBellExe] C:\program files\real\realplayer\update\realsched.exe (RealNetworks, Inc.)
O4 - HKLM..\Run: [WavXMgr] C:\Program Files\Wave Systems Corp\Services Manager\DocMgr\bin\WavXDocMgr.exe (Wave Systems Corp.)
O4 - HKLM..\Run: [YMailAdvisor] C:\Program Files\Yahoo!\Common\YMailAdvisor.exe (Yahoo! Inc.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Bluetooth.lnk = C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe (Broadcom Corporation.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Dell ControlPoint System Manager.lnk = C:\Program Files\Dell\Dell ControlPoint\System Manager\DCPSysMgr.exe (Dell Inc.)
O4 - Startup: C:\Documents and Settings\ataylor.WAYPOINT.000\Start Menu\Programs\Startup\Logitech . Product Registration.lnk = C:\Program Files\Common Files\LogiShrd\eReg\SetPoint\eReg.exe (Leader Technologies/Logitech)
O4 - Startup: C:\Documents and Settings\McAfeeMVSUser\Start Menu\Programs\Startup\Windows Search.lnk = File not found
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoWelcomeScreen = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoControlPanel = 0
O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-308600077-3542235570-3293604796-1145\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-308600077-3542235570-3293604796-1145\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKU\S-1-5-21-308600077-3542235570-3293604796-1145\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKU\S-1-5-21-308600077-3542235570-3293604796-1145\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O8 - Extra context menu item: Append Link Target to Existing PDF - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Append to Existing PDF - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert Link Target to Adobe PDF - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert to Adobe PDF - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Send to &Bluetooth Device… - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm ()
O8 - Extra context menu item: Send To Bluetooth - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O9 - Extra Button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O9 - Extra 'Tools' menuitem : @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O15 - HKLM\..Trusted Domains: //about.htm/ ([]myui in Trusted sites)
O15 - HKLM\..Trusted Domains: //Exclude.htm/ ([]myui in Trusted sites)
O15 - HKLM\..Trusted Domains: //LanguageSelection.htm/ ([]myui in Trusted sites)
O15 - HKLM\..Trusted Domains: //Message.htm/ ([]myui in Trusted sites)
O15 - HKLM\..Trusted Domains: //MyAgttryCmd.htm/ ([]myui in Trusted sites)
O15 - HKLM\..Trusted Domains: //MyAgttryNag.htm/ ([]myui in Trusted sites)
O15 - HKLM\..Trusted Domains: //MyNotification.htm/ ([]myui in Trusted sites)
O15 - HKLM\..Trusted Domains: //NOCLessUpdate.htm/ ([]myui in Trusted sites)
O15 - HKLM\..Trusted Domains: //quarantine.htm/ ([]myui in Trusted sites)
O15 - HKLM\..Trusted Domains: //ScanNow.htm/ ([]myui in Trusted sites)
O15 - HKLM\..Trusted Domains: //strings.vbs/ ([]myui in Trusted sites)
O15 - HKLM\..Trusted Domains: //Template.htm/ ([]myui in Trusted sites)
O15 - HKLM\..Trusted Domains: //Update.htm/ ([]myui in Trusted sites)
O15 - HKLM\..Trusted Domains: //VirFound.htm/ ([]myui in Trusted sites)
O15 - HKLM\..Trusted Domains: mcafee.com ([*]http in Trusted sites)

O15 - HKLM\..Trusted Domains: mcafee.com ([*]https in Trusted sites)

O15 - HKLM\..Trusted Domains: mcafeeasap.com ([betavscan] http in Trusted sites)
O15 - HKLM\..Trusted Domains: mcafeeasap.com ([betavscan] https in Trusted sites)
O15 - HKLM\..Trusted Domains: mcafeeasap.com ([vs] http in Trusted sites)
O15 - HKLM\..Trusted Domains: mcafeeasap.com ([vs] https in Trusted sites)
O15 - HKLM\..Trusted Domains: mcafeeasap.com ([www] http in Trusted sites)
O15 - HKLM\..Trusted Domains: mcafeeasap.com ([www] https in Trusted sites)
O16 - DPF: {02BCC737-B171-4746-94C9-0D8A0B2C0089} http://office.microsoft.com/sites/production/ieawsdc32.cab (Microsoft Office Template and Media Control)
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://download.macromedia.com/pub/shockwa…director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} C:\Program Files\Yahoo!\Common\Yinsthelper.dll (Installation Support)
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} http://www.update.microsoft.com/microsoftu…b?1343242725201 (WUWebControl Class)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} http://www.update.microsoft.com/microsoftu…b?1343242718342 (MUWebControl Class)
O16 - DPF: {72C23FEC-3AF9-48FC-9597-241A8EBDFE0A} http://www.trimble.com/datatransfer/v155/isetupml.cab (InstallShield International Setup Player)
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} http://download.eset.com/special/eos/OnlineScanner.cab (OnlineScanner Control)
O16 - DPF: {C1FDEE68-98D5-4F42-A4DD-D0BECF5077EB} http://tools.ebayimg.com/eps/wl/activex/eB…l_v1-0-31-0.cab (EPUImageControl Class)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 10.0.0.11
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = waypoint.local
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{3EC90BA7-13DA-43D8-B7BC-EF802309F89E}: DhcpNameServer = 10.0.0.11
O18 - Protocol\Handler\dssrequest {5513F07E-936B-4E52-9B00-067394E91CC5} - C:\Program Files\McAfee\SiteAdvisor Enterprise\McIEPlg.dll (McAfee, Inc.)
O18 - Protocol\Handler\myrm {4D034FC3-013F-4b95-B544-44D49ABE3E76} - C:\Program Files\McAfee\Managed VirusScan\Agent\MyRmProt5.0.0.811.dll (McAfee, Inc.)
O18 - Protocol\Handler\sacore {5513F07E-936B-4E52-9B00-067394E91CC5} - C:\Program Files\McAfee\SiteAdvisor Enterprise\McIEPlg.dll (McAfee, Inc.)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) - C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O20 - Winlogon\Notify\LBTWlgn: DllName - (c:\program files\common files\logishrd\bluetooth\LBTWlgn.dll) - c:\Program Files\Common Files\LogiShrd\Bluetooth\LBTWLgn.dll (Logitech, Inc.)
O24 - Desktop WallPaper: C:\Documents and Settings\jzipkin\Application Data\Mozilla\Firefox\Desktop Background.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\jzipkin\Application Data\Mozilla\Firefox\Desktop Background.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2008/04/25 16:29:32 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = ComFile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)

========== Files/Folders - Created Within 30 Days ==========

[2012/12/13 09:34:59 | 004,732,416 | —- | C] (AVAST Software) – C:\Documents and Settings\jzipkin\Desktop\aswMBR.exe
[2012/12/13 09:34:55 | 000,602,112 | —- | C] (OldTimer Tools) – C:\Documents and Settings\jzipkin\Desktop\OTL.exe
[2012/12/13 09:34:39 | 010,669,952 | —- | C] (Malwarebytes Corporation ) – C:\Documents and Settings\jzipkin\Desktop\mbam-setup-1.65.1.1000.exe
[2012/12/12 14:54:13 | 000,000,000 | —D | C] – C:\Documents and Settings\jzipkin\Desktop\My Mobile
[2012/12/03 15:10:24 | 000,000,000 | —D | C] – C:\Documents and Settings\jzipkin\Local Settings\Application Data\Mozilla
[2012/12/03 15:10:24 | 000,000,000 | —D | C] – C:\Documents and Settings\jzipkin\Application Data\Mozilla
[2012/12/03 15:10:19 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Mozilla
[2012/12/03 15:10:18 | 000,000,000 | —D | C] – C:\Program Files\Mozilla Maintenance Service
[2012/12/03 15:10:13 | 000,000,000 | —D | C] – C:\Program Files\Mozilla Firefox
[2012/12/03 12:04:13 | 000,000,000 | RH-D | C] – C:\Documents and Settings\jzipkin\Recent
[2012/12/03 11:54:36 | 000,000,000 | —D | C] – C:\Config.Msi
[2012/11/14 16:10:33 | 000,000,000 | —D | C] – C:\Documents and Settings\jzipkin\Application Data\Help

========== Files - Modified Within 30 Days ==========

[2012/12/13 11:24:01 | 000,000,830 | —- | M] () – C:\WINDOWS\tasks\Adobe Flash Player Updater.job
[2012/12/13 11:19:19 | 000,000,512 | —- | M] () – C:\Documents and Settings\jzipkin\Desktop\MBR.dat
[2012/12/13 10:37:00 | 000,000,888 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2012/12/13 10:27:26 | 000,000,290 | —- | M] () – C:\WINDOWS\tasks\RealUpgradeScheduledTaskS-1-5-21-308600077-3542235570-3293604796-1145.job
[2012/12/13 10:27:26 | 000,000,282 | —- | M] () – C:\WINDOWS\tasks\RealUpgradeLogonTaskS-1-5-21-308600077-3542235570-3293604796-1145.job
[2012/12/13 10:14:51 | 000,001,994 | -HS- | M] () – C:\Documents and Settings\All Users\Application Data\KGyGaAvL.sys
[2012/12/13 10:13:04 | 000,622,018 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2012/12/13 10:13:04 | 000,133,952 | —- | M] () – C:\WINDOWS\System32\perfc009.dat
[2012/12/13 10:10:16 | 000,000,000 | —- | M] () – C:\Documents and Settings\jzipkin\Local Settings\Application Data\WavXMapDrive.bat
[2012/12/13 10:10:10 | 000,243,584 | —- | M] () – C:\WINDOWS\System32\NvApps.xml
[2012/12/13 10:10:09 | 000,203,633 | —- | M] () – C:\WINDOWS\System32\nvModes.001
[2012/12/13 10:09:45 | 000,000,884 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2012/12/13 10:09:31 | 000,001,158 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2012/12/13 10:06:12 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2012/12/13 10:06:00 | 3745,406,976 | -HS- | M] () – C:\hiberfil.sys
[2012/12/13 09:40:54 | 000,002,539 | —- | M] () – C:\Documents and Settings\jzipkin\Application Data\Microsoft\Internet Explorer\Quick Launch\Microsoft Office Outlook 2007.lnk
[2012/12/13 09:34:57 | 004,732,416 | —- | M] (AVAST Software) – C:\Documents and Settings\jzipkin\Desktop\aswMBR.exe
[2012/12/13 09:34:56 | 000,602,112 | —- | M] (OldTimer Tools) – C:\Documents and Settings\jzipkin\Desktop\OTL.exe
[2012/12/13 09:34:46 | 010,669,952 | —- | M] (Malwarebytes Corporation ) – C:\Documents and Settings\jzipkin\Desktop\mbam-setup-1.65.1.1000.exe
[2012/12/12 12:24:31 | 000,697,272 | —- | M] (Adobe Systems Incorporated) – C:\WINDOWS\System32\FlashPlayerApp.exe
[2012/12/12 12:24:31 | 000,073,656 | —- | M] (Adobe Systems Incorporated) – C:\WINDOWS\System32\FlashPlayerCPLApp.cpl
[2012/12/03 15:10:20 | 000,000,743 | —- | M] () – C:\Documents and Settings\jzipkin\Application Data\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox.lnk
[2012/12/03 11:42:55 | 000,000,664 | —- | M] () – C:\WINDOWS\System32\d3d9caps.dat
[2012/11/29 16:11:47 | 000,000,143 | —- | M] () – C:\WINDOWS\TRIMSURV.INI
[2012/11/28 13:05:46 | 000,415,856 | —- | M] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2012/11/28 12:50:43 | 000,000,793 | —- | M] () – C:\Documents and Settings\jzipkin\Application Data\Microsoft\Internet Explorer\Quick Launch\Microsoft Office Outlook.lnk
[2012/11/27 14:33:45 | 000,389,392 | —- | M] () – C:\Documents and Settings\jzipkin\Desktop\CR-1211-TSC3-01 (2).pdf
[2012/11/26 12:01:14 | 000,001,441 | —- | M] () – C:\scu.dat

========== Files Created - No Company Name ==========

[2012/12/13 11:19:19 | 000,000,512 | —- | C] () – C:\Documents and Settings\jzipkin\Desktop\MBR.dat
[2012/12/03 15:10:20 | 000,000,743 | —- | C] () – C:\Documents and Settings\jzipkin\Application Data\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox.lnk
[2012/12/03 15:10:20 | 000,000,731 | —- | C] () – C:\Documents and Settings\All Users\Start Menu\Programs\Mozilla Firefox.lnk
[2012/11/27 14:33:45 | 000,389,392 | —- | C] () – C:\Documents and Settings\jzipkin\Desktop\CR-1211-TSC3-01 (2).pdf
[2012/11/26 10:03:09 | 000,001,441 | —- | C] () – C:\scu.dat
[2012/10/30 11:09:08 | 000,000,000 | —- | C] () – C:\Documents and Settings\jzipkin\Application Data\PFO.waf
[2012/10/19 15:53:33 | 000,000,057 | —- | C] () – C:\WINDOWS\ArcPad.INI
[2012/07/25 15:55:18 | 000,240,680 | —- | C] () – C:\Documents and Settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
[2012/07/05 13:22:58 | 000,003,072 | —- | C] () – C:\WINDOWS\System32\iacenc.dll
[2012/06/22 09:45:01 | 000,000,008 | RHS- | C] () – C:\Documents and Settings\All Users\Application Data\8615B8621C.sys
[2012/06/06 10:08:44 | 000,256,000 | —- | C] () – C:\WINDOWS\PEV.exe
[2012/06/06 10:08:44 | 000,208,896 | —- | C] () – C:\WINDOWS\MBR.exe
[2012/06/06 10:08:44 | 000,098,816 | —- | C] () – C:\WINDOWS\sed.exe
[2012/06/06 10:08:44 | 000,080,412 | —- | C] () – C:\WINDOWS\grep.exe
[2012/06/06 10:08:44 | 000,068,096 | —- | C] () – C:\WINDOWS\zip.exe
[2012/05/25 10:49:01 | 000,484,352 | —- | C] () – C:\WINDOWS\System32\lame_enc.dll
[2012/03/21 08:57:40 | 000,270,848 | —- | C] () – C:\WINDOWS\System32\unwise32.exe
[2012/03/20 04:08:54 | 000,041,472 | —- | C] () – C:\WINDOWS\System32\TCC Explorer.exe
[2011/12/29 15:47:18 | 001,511,424 | —- | C] () – C:\WINDOWS\System32\HP1100SM.EXE
[2011/12/29 15:47:18 | 000,151,552 | —- | C] () – C:\WINDOWS\System32\HP1100LM.DLL
[2011/12/29 15:46:46 | 000,284,160 | —- | C] () – C:\WINDOWS\System32\mvhlewsi.DLL
[2011/12/29 15:46:38 | 000,047,104 | —- | C] () – C:\WINDOWS\System32\HP1100SMs.dll
[2011/11/04 15:18:01 | 000,000,664 | —- | C] () – C:\WINDOWS\System32\d3d9caps.dat
[2011/10/25 11:36:01 | 000,000,133 | —- | C] () – C:\Documents and Settings\All Users\Application Data\Microsoft.SqlServer.Compact.351.32.bc
[2011/07/29 08:26:25 | 000,015,188 | -HS- | C] () – C:\Documents and Settings\jzipkin\Local Settings\Application Data\4jt08j3453lv6eerv3ryh58wlpwkbx274umkyc5s2batk27
[2011/07/29 08:26:25 | 000,015,188 | -HS- | C] () – C:\Documents and Settings\All Users\Application Data\4jt08j3453lv6eerv3ryh58wlpwkbx274umkyc5s2batk27
[2010/11/29 14:01:51 | 000,008,704 | —- | C] () – C:\Documents and Settings\jzipkin\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/07/27 08:29:43 | 000,002,528 | —- | C] () – C:\Documents and Settings\jzipkin\Application Data\$_hpcst$.hpc
[2010/07/26 13:14:03 | 000,001,994 | -HS- | C] () – C:\Documents and Settings\All Users\Application Data\KGyGaAvL.sys
[2010/07/23 13:25:35 | 000,000,260 | —- | C] () – C:\Documents and Settings\jzipkin\aimsproxy.properties
[2010/07/23 13:25:35 | 000,000,202 | —- | C] () – C:\Documents and Settings\jzipkin\aimsclient.properties
[2010/07/23 13:25:35 | 000,000,080 | —- | C] () – C:\Documents and Settings\jzipkin\Favorites.axl
[2010/07/23 13:20:07 | 000,000,000 | —- | C] () – C:\Documents and Settings\jzipkin\Local Settings\Application Data\WavXMapDrive.bat
[2010/07/22 12:53:07 | 000,013,498 | RHS- | C] () – C:\Documents and Settings\All Users\ntuser.pol

========== ZeroAccess Check ==========

[2008/04/25 16:34:35 | 000,000,227 | RHS- | M] () – C:\WINDOWS\assembly\Desktop.ini
[2010/07/26 13:13:36 | 000,000,000 | —D | M] – C:\WINDOWS\assembly\GAC_MSIL\Act.Outlook.Service.Desktop

[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]

[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shdocvw.dll – [2010/04/16 11:09:07 | 001,509,888 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = C:\WINDOWS\system32\wbem\fastprox.dll – [2009/02/09 07:10:48 | 000,473,600 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
"" = %systemroot%\system32\wbem\wbemess.dll – [2008/04/14 07:00:00 | 000,273,920 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Both

========== LOP Check ==========

[2010/07/22 12:24:17 | 000,000,000 | —D | M] – C:\Documents and Settings\Administrator\Application Data\Wave Systems Corp
[2012/10/04 20:26:50 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\188F1432-103A-4ffb-80F1-36B633C5C9E1
[2010/07/26 14:22:44 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\ACT
[2010/07/22 12:19:11 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\AT&T
[2011/07/28 12:00:49 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Avery
[2011/11/23 20:16:28 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\CanonBJ
[2012/09/13 14:24:46 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\ESRI
[2010/07/22 12:14:04 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\NTRU Cryptosystems
[2012/07/30 09:50:28 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\RentMaster
[2012/10/18 10:49:29 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Trimble
[2010/07/22 12:17:05 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Wave Systems Corp
[2010/08/23 10:22:08 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\WEngineLite
[2012/05/25 10:28:35 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
[2010/07/22 12:47:44 | 000,000,000 | —D | M] – C:\Documents and Settings\ATaylor\Application Data\Wave Systems Corp
[2010/07/22 12:47:46 | 000,000,000 | —D | M] – C:\Documents and Settings\ATaylor.WAYPOINT\Application Data\Wave Systems Corp
[2010/07/26 13:03:54 | 000,000,000 | —D | M] – C:\Documents and Settings\ataylor.WAYPOINT.000\Application Data\ACT
[2010/07/26 13:14:02 | 000,000,000 | —D | M] – C:\Documents and Settings\ataylor.WAYPOINT.000\Application Data\IsolatedStorage
[2010/07/26 10:20:14 | 000,000,000 | —D | M] – C:\Documents and Settings\ataylor.WAYPOINT.000\Application Data\Leadertech
[2010/07/26 10:27:18 | 000,000,000 | —D | M] – C:\Documents and Settings\ataylor.WAYPOINT.000\Application Data\Trimble
[2010/07/22 12:24:17 | 000,000,000 | —D | M] – C:\Documents and Settings\ataylor.WAYPOINT.000\Application Data\Wave Systems Corp
[2010/07/22 12:24:17 | 000,000,000 | —D | M] – C:\Documents and Settings\Default User\Application Data\Wave Systems Corp
[2010/07/26 14:51:57 | 000,000,000 | —D | M] – C:\Documents and Settings\jzipkin\Application Data\ACT
[2011/07/28 12:03:45 | 000,000,000 | —D | M] – C:\Documents and Settings\jzipkin\Application Data\Avery
[2012/03/21 10:03:33 | 000,000,000 | —D | M] – C:\Documents and Settings\jzipkin\Application Data\esri
[2012/05/25 10:47:23 | 000,000,000 | —D | M] – C:\Documents and Settings\jzipkin\Application Data\FreeAudioPack
[2010/07/27 12:53:58 | 000,000,000 | —D | M] – C:\Documents and Settings\jzipkin\Application Data\IsolatedStorage
[2010/08/13 14:56:44 | 000,000,000 | —D | M] – C:\Documents and Settings\jzipkin\Application Data\Leadertech
[2012/04/30 10:32:45 | 000,000,000 | —D | M] – C:\Documents and Settings\jzipkin\Application Data\Oracle
[2012/07/19 11:57:55 | 000,000,000 | —D | M] – C:\Documents and Settings\jzipkin\Application Data\PeaZip
[2012/05/25 10:47:48 | 000,000,000 | —D | M] – C:\Documents and Settings\jzipkin\Application Data\searchquband
[2012/10/04 10:18:14 | 000,000,000 | —D | M] – C:\Documents and Settings\jzipkin\Application Data\Smith Micro
[2012/09/26 11:13:30 | 000,000,000 | —D | M] – C:\Documents and Settings\jzipkin\Application Data\Trimble
[2012/05/14 15:49:54 | 000,000,000 | —D | M] – C:\Documents and Settings\jzipkin\Application Data\Unity
[2010/07/22 12:24:17 | 000,000,000 | —D | M] – C:\Documents and Settings\jzipkin\Application Data\Wave Systems Corp
[2011/05/19 10:03:53 | 000,000,000 | —D | M] – C:\Documents and Settings\jzipkin\Application Data\webex
[2010/07/22 12:53:02 | 000,000,000 | —D | M] – C:\Documents and Settings\jzipkin.WAYPOINT\Application Data\ACT
[2010/07/22 12:53:01 | 000,000,000 | —D | M] – C:\Documents and Settings\jzipkin.WAYPOINT\Application Data\esri
[2010/07/22 12:53:01 | 000,000,000 | —D | M] – C:\Documents and Settings\jzipkin.WAYPOINT\Application Data\IsolatedStorage
[2010/07/22 12:53:01 | 000,000,000 | —D | M] – C:\Documents and Settings\jzipkin.WAYPOINT\Application Data\Leadertech
[2010/07/22 12:52:03 | 000,000,000 | —D | M] – C:\Documents and Settings\jzipkin.WAYPOINT\Application Data\ntr
[2010/07/22 12:52:03 | 000,000,000 | —D | M] – C:\Documents and Settings\jzipkin.WAYPOINT\Application Data\Sirius
[2010/07/22 12:52:03 | 000,000,000 | —D | M] – C:\Documents and Settings\jzipkin.WAYPOINT\Application Data\StreamTorrent
[2010/07/22 12:52:01 | 000,000,000 | —D | M] – C:\Documents and Settings\jzipkin.WAYPOINT\Application Data\Trimble
[2010/07/22 12:24:17 | 000,000,000 | —D | M] – C:\Documents and Settings\jzipkin.WAYPOINT\Application Data\Wave Systems Corp
[2010/07/22 12:52:01 | 000,000,000 | —D | M] – C:\Documents and Settings\jzipkin.WAYPOINT\Application Data\webex
[2010/07/22 12:52:01 | 000,000,000 | —D | M] – C:\Documents and Settings\jzipkin.WAYPOINT\Application Data\Windows Search
[2012/09/13 14:26:59 | 000,000,000 | —D | M] – C:\Documents and Settings\LocalService\Application Data\Trimble
[2012/09/17 09:57:25 | 000,000,000 | —D | M] – C:\Documents and Settings\NetworkService\Application Data\Trimble

========== Purity Check ==========



< End of report >
Hi,

I need to look over your OTL log more closely , in the meantime do this.

Open Malwarebytes and go to the Logs tab and open the one you ran first that locked up your system and copy and paste it in this thread for me to see.

Then do this

Open OTL.exe
  • Copy/paste the following text written inside of the code box into the Custom Scans/Fixes box located at the bottom of OTL

    :processes
    killallprocesses
    
    :OTL
    
    
    :Services
    
    :Reg
    
    :Files
    ipconfig /flushdns /c
    
    
    :Commands
    [purity]
    [resethosts]
    [emptytemp]
    [start explorer]
    [Reboot]
  • Then click the Run Fix button at the top. <–Not run Scan
  • Let the program run unhindered, reboot when it is done
  • Then post the results of the log it produces



Then run aswMBR one more time and post the NEW log please
the only recent log in mbam was the one that i posted. seems the one from the first scan never got written.

here's the OTL log:

All processes killed
========== PROCESSES ==========
========== OTL ==========
========== SERVICES/DRIVERS ==========
========== REGISTRY ==========
========== FILES ==========
< ipconfig /flushdns /c >
Windows IP Configuration
Successfully flushed the DNS Resolver Cache.
C:\Documents and Settings\jzipkin\Desktop\cmd.bat deleted successfully.
C:\Documents and Settings\jzipkin\Desktop\cmd.txt deleted successfully.
========== COMMANDS ==========
C:\WINDOWS\System32\drivers\etc\Hosts moved successfully.
HOSTS file reset successfully

[EMPTYTEMP]

User: Administrator
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes

User: All Users

User: ATaylor
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes

User: ATaylor.WAYPOINT
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes

User: ataylor.WAYPOINT.000
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Flash cache emptied: 0 bytes

User: ATAYLO~1~000

User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Flash cache emptied: 0 bytes

User: jzipkin
->Temp folder emptied: 812479438 bytes
->Temporary Internet Files folder emptied: 329706963 bytes
->Java cache emptied: 0 bytes
->FireFox cache emptied: 24335977 bytes
->Flash cache emptied: 7171 bytes

User: jzipkin.WAYPOINT
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Java cache emptied: 0 bytes
->Flash cache emptied: 0 bytes

User: LocalService
->Temp folder emptied: 32768 bytes
->Temporary Internet Files folder emptied: 33036 bytes

User: McAfeeMVSUser
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes

User: McAfeeMVSUser.C4LHXH1
->Temp folder emptied: 49632 bytes
->Temporary Internet Files folder emptied: 33170 bytes
->Flash cache emptied: 0 bytes

User: NetworkService
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 10295531 bytes
->Flash cache emptied: 921 bytes

%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32\dllcache .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 6894539 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 0 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 0 bytes
RecycleBin emptied: 5916288 bytes

Total Files Cleaned = 1,135.00 mb


OTL by OldTimer - Version 3.2.69.0 log created on 12132012_122254

Files\Folders moved on Reboot…
C:\Documents and Settings\jzipkin\Local Settings\Temp\ExchangePerflog_8484fa31987a805bcfcccd43.dat moved successfully.
C:\Documents and Settings\jzipkin\Local Settings\Temp\WCESLog.log moved successfully.
C:\Documents and Settings\jzipkin\Local Settings\Temp\~DF1AE6.tmp moved successfully.
C:\Documents and Settings\jzipkin\Local Settings\Temp\~DFCCBD.tmp moved successfully.
C:\Documents and Settings\jzipkin\Local Settings\Temp\~DFFC40.tmp moved successfully.
C:\Documents and Settings\jzipkin\Local Settings\Temporary Internet Files\Content.Word\~WRS{213E21A7-B600-424F-B0A6-6118F5398DD3}.tmp moved successfully.
C:\Documents and Settings\jzipkin\Local Settings\Temporary Internet Files\Content.IE5\TMNLD2AY\facebook[1].htm moved successfully.
C:\Documents and Settings\jzipkin\Local Settings\Temporary Internet Files\Content.IE5\N6GBCB9S\froocross[1].css moved successfully.
C:\Documents and Settings\jzipkin\Local Settings\Temporary Internet Files\Content.IE5\N6GBCB9S\iframe[1].htm moved successfully.
C:\Documents and Settings\jzipkin\Local Settings\Temporary Internet Files\Content.IE5\L091VAW1\681[1].html moved successfully.
C:\Documents and Settings\jzipkin\Local Settings\Temporary Internet Files\Content.IE5\L091VAW1\ebay_sell_hub[1].html moved successfully.
C:\Documents and Settings\jzipkin\Local Settings\Temporary Internet Files\Content.IE5\JS8DFIYV\51123-9[1].htm moved successfully.
C:\Documents and Settings\jzipkin\Local Settings\Temporary Internet Files\Content.IE5\JS8DFIYV\;eb_trk=290381;pr=23;xp=23;np=23;uz=12205;fbi=6000;sbi=6028;fbo=58058;sbo=1
71961;fse=382;sse=159043;fvi=12576;svi=11748;cg=8b9f241f13b0a56ca6358685fdb2f8af;
[3].htm moved successfully.
C:\Documents and Settings\jzipkin\Local Settings\Temporary Internet Files\Content.IE5\JS8DFIYV\index[2].php moved successfully.
C:\Documents and Settings\jzipkin\Local Settings\Temporary Internet Files\Content.IE5\JS8DFIYV\index[3].php moved successfully.
C:\Documents and Settings\jzipkin\Local Settings\Temporary Internet Files\Content.IE5\JS8DFIYV\index[4].php moved successfully.
C:\Documents and Settings\jzipkin\Local Settings\Temporary Internet Files\Content.IE5\JS8DFIYV\search[3].txt moved successfully.
C:\Documents and Settings\jzipkin\Local Settings\Temporary Internet Files\Content.IE5\JS8DFIYV\xd_arbiter[2].htm moved successfully.
C:\Documents and Settings\jzipkin\Local Settings\Temporary Internet Files\Content.IE5\G6J8EL4V\;eb_trk=172592;pr=23;xp=23;np=23;uz=12205;fbi=6000;sbi=6028;fbo=58058;sbo=1
71961;fse=382;sse=159043;fvi=12576;svi=11748;cg=8b9f241f13b0a56ca6358685fdb2f8af;
[5].htm moved successfully.
C:\Documents and Settings\jzipkin\Local Settings\Temporary Internet Files\Content.IE5\G6J8EL4V\eBayISAPI[1].dll moved successfully.
C:\Documents and Settings\jzipkin\Local Settings\Temporary Internet Files\Content.IE5\G6J8EL4V\eBayISAPI[1].html moved successfully.
C:\Documents and Settings\jzipkin\Local Settings\Temporary Internet Files\Content.IE5\CK54NUKI\13b0a56ca6358685fdb2f8af;kw=trimble,xrt,field,kit,,proxrt,gpsglonass,receiv
er,zephyr,antenna,accessories;lkw=1978+monte+1978+monte+1978+monte+marine+carpet;
[1].htm moved successfully.
C:\Documents and Settings\jzipkin\Local Settings\Temporary Internet Files\Content.IE5\CK54NUKI\eBayISAPI[1].html moved successfully.
C:\Documents and Settings\jzipkin\Local Settings\Temporary Internet Files\Content.IE5\CK54NUKI\rsa[1].txt moved successfully.
C:\Documents and Settings\jzipkin\Local Settings\Temporary Internet Files\Content.IE5\4P8X83PP\eBayISAPI[1].txt moved successfully.
C:\Documents and Settings\jzipkin\Local Settings\Temporary Internet Files\Content.IE5\4P8X83PP\eBayISAPI[3].txt moved successfully.
C:\Documents and Settings\jzipkin\Local Settings\Temporary Internet Files\Content.IE5\4P8X83PP\eBayISAPI[4].txt moved successfully.
C:\Documents and Settings\jzipkin\Local Settings\Temporary Internet Files\Content.IE5\4P8X83PP\order[1].htm moved successfully.
C:\Documents and Settings\jzipkin\Local Settings\Temporary Internet Files\Content.IE5\4P8X83PP\order[2].htm moved successfully.
C:\Documents and Settings\jzipkin\Local Settings\Temporary Internet Files\Content.IE5\4P8X83PP\xd_arbiter[1].htm moved successfully.
C:\Documents and Settings\jzipkin\Local Settings\Temporary Internet Files\AntiPhishing\2CEDBFBC-DBA8-43AA-B1FD-CC8E6316E3E2.dat moved successfully.
C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\PVLPG0BP\ajs[1].php moved successfully.
C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\PVLPG0BP\api[1].htm moved successfully.
C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\PVLPG0BP\dd_Roundies[1].js moved successfully.
C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\PVLPG0BP\jstag[1] moved successfully.
C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\PVLPG0BP\pg-v1.3[1].css moved successfully.
C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\PVLPG0BP\st[1] moved successfully.
C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\PVLPG0BP\widgets[1].js moved successfully.
C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\G0OM93Z4\1354286738067_32946198834155[2].htm moved successfully.
C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\G0OM93Z4\findwhat[2].txt moved successfully.
C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\G0OM93Z4\stepcarousel[1].js moved successfully.
C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\G0OM93Z4\style-gourmetrecipe-v1.3[1].css moved successfully.
C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\81TSANQE\flowplayer-3.2.11.min[1].js moved successfully.
C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\81TSANQE\layout_gourmetrecipe[1].css moved successfully.
C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\81TSANQE\results[3].htm moved successfully.
C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\81TSANQE\stepcarousel[1].css moved successfully.
C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\81TSANQE\style_gourmetrecipe_ie[1].css moved successfully.
C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\81TSANQE\template[1].css moved successfully.
C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\1ZE57VEA\api[1].htm moved successfully.
C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\1ZE57VEA\Carpaccio-of-salmon-and-wolf-with-tender-herbs[1].txt moved successfully.
C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\1ZE57VEA\mypodstudios_com[1].txt moved successfully.
C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\1ZE57VEA\sharethis[1].js moved successfully.
C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\1ZE57VEA\vote[1].js moved successfully.
File\Folder C:\WINDOWS\temp\Perflib_Perfdata_cd8.dat not found!

PendingFileRenameOperations files…

Registry entries deleted on Reboot…
Ok, lets see a new aswMBR log please


You need to enable windows to show all files and folders, instructions Here

Go to VirusTotal and submit this file for analysis, just use the browse feature and then Send File, if it says this file has been checked before, have them recheck it. When the scan is done just copy and paste the link back to this forum for me to see.

C:\Documents and Settings\All Users\Application Data\8615B8621C.sys <–This file

If the site is busy you can try this one
http://virusscan.jotti.org/en
aswMBR version 0.9.9.1707 Copyright© 2011 AVAST Software Run date: 2012-12-13 10:40:55 —————————– 10:40:55.354 OS Version: Windows 5.1.2600 Service Pack 3 10:40:55.354 Number of processors: 2 586 0x1706 10:40:55.354 ComputerName: C4LHXH1 UserName: jzipkin 10:40:57.304 Initialize success 10:42:08.416 AVAST engine defs: 12121301 10:42:15.297 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-1 10:42:15.297 Disk 0 Vendor: ST916031 D005 Size: 152627MB BusType: 8 10:42:15.297 Disk 0 MBR read error 0 10:42:15.297 Disk 0 MBR scan 10:42:15.390 Disk 0 unknown MBR code 10:42:15.390 MBR BIOS signature not found 0 10:42:15.406 Disk 0 scanning sectors +312576705 10:42:15.499 Disk 0 scanning C:\WINDOWS\system32\drivers 10:43:10.056 Service scanning 10:44:37.269 Modules scanning 10:44:45.887 Disk 0 trace - called modules: 10:44:45.887 ntkrnlpa.exe CLASSPNP.SYS disk.sys >>UNKNOWN [0x894c04b1]<< 10:44:45.902 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x8b893868] 10:44:46.398 3 CLASSPNP.SYS[b80f8fd7] -> nt!IofCallDriver -> [0x89268d38] 10:44:46.398 \Driver\iaStor[0x894e74b0] -> IRP_MJ_CREATE -> 0x894c04b1 10:44:47.111 AVAST engine scan C:\WINDOWS 10:45:03.029 AVAST engine scan C:\WINDOWS\system32 10:52:20.477 AVAST engine scan C:\WINDOWS\system32\drivers 10:52:52.846 AVAST engine scan C:\Documents and Settings\jzipkin 11:00:21.441 File: C:\Documents and Settings\jzipkin\Local Settings\temp\757896488.tmp **INFECTED** Win32:Kryptik-KFB [Trj] 11:12:07.445 AVAST engine scan C:\Documents and Settings\All Users 11:16:06.571 Scan finished successfully 11:19:19.123 Disk 0 MBR has been saved successfully to "C:\Documents and Settings\jzipkin\Desktop\MBR.dat" 11:19:19.138 The log file has been saved successfully to "C:\Documents and Settings\jzipkin\Desktop\aswMBR.txt" aswMBR version 0.9.9.1707 Copyright© 2011 AVAST Software Run date: 2012-12-13 13:46:31 —————————– 13:46:31.542 OS Version: Windows 5.1.2600 Service Pack 3 13:46:31.542 Number of processors: 2 586 0x1706 13:46:31.542 ComputerName: C4LHXH1 UserName: jzipkin 13:46:33.364 Initialize success 13:47:02.087 AVAST engine defs: 12121301 13:47:14.852 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-1 13:47:14.852 Disk 0 Vendor: ST916031 D005 Size: 152627MB BusType: 8 13:47:14.868 Disk 0 MBR read error 0 13:47:14.868 Disk 0 MBR scan 13:47:14.961 Disk 0 unknown MBR code 13:47:14.961 MBR BIOS signature not found 0 13:47:14.961 Disk 0 scanning sectors +312576705 13:47:15.101 Disk 0 scanning C:\WINDOWS\system32\drivers 13:48:02.023 Service scanning 13:48:58.846 Modules scanning 13:49:08.825 Disk 0 trace - called modules: 13:49:08.825 ntkrnlpa.exe CLASSPNP.SYS disk.sys >>UNKNOWN [0x89cf74b1]<< 13:49:08.825 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x8b8e7030] 13:49:08.825 3 CLASSPNP.SYS[b80e8fd7] -> nt!IofCallDriver -> [0x89dc8388] 13:49:08.825 \Driver\iaStor[0x89cb2a20] -> IRP_MJ_CREATE -> 0x89cf74b1 13:49:09.494 AVAST engine scan C:\WINDOWS 13:49:36.022 AVAST engine scan C:\WINDOWS\system32 13:57:43.555 AVAST engine scan C:\WINDOWS\system32\drivers 13:58:19.953 AVAST engine scan C:\Documents and Settings\jzipkin 13:59:38.892 Disk 0 MBR has been saved successfully to "C:\Documents and Settings\jzipkin\Desktop\MBR.dat" 13:59:38.892 The log file has been saved successfully to "C:\Documents and Settings\jzipkin\Desktop\aswMBR.txt"
Hi, The malicious file that aswMBR found was in your temp directory and when we ran the OTL fix it removed it. Looks like the file you uploaded was ok What are you experiencing now, any browser redirects, unwanted pop up windows or things of that nature ?
still acting poorly. Out of town without it for a few days. Should be able to get to it tomorrow nite. Will post then.
You didnt answer my question

What are you experiencing now, any browser redirects, unwanted pop up windows or things of that nature ?





still acting poorly

Just because your computer is acting poorly doesn't mean its infected. Could be a plain old windows problem. We dont know yet. Telling me its acting poorly is really not telling me anything.
I realize that was not an answer to your question. I was out of town at a family affair and only had a quick moment to tap out a response on my ipad. Sorry i couldnt go into more detail. No, i am not experiencing any redirects or popups, or any of the standard signs of infection. I beleive i've pinpointed my problem to Adobe Acrobat. I'm runnin v9 and it seems that i'm experiencing my BSOD moments after opening or closing a .pdf I've tried running the repair function, but it still did it. Is there any chance this is virus/makware related or is it just simply a corrupt install? Would and uninstall/reinstall be sufficient or no? Thx.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI