This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

browser and firewall/antivirus hijacked

8 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hello,

My Zonealarm antivirus/firewall keeps switching from on to off and my ie keeps changing from yahoo to aboutblank and or google.
Also I noticed 3 folders on my external drive F that were not there before they are titled " RECYCLER" " SYSTEM VOLUME INFORMATION" & "THUMBS.DB" These folders are not bright yellow like other folders I have created , they are faded in color.
I am having a lot of difficulty logging in to this site and my yahoo e-mail the page is redirected or messages appear stating that I used an incorrect user name and or password.
I have posted the HJT, OTL and DDS scan results.



Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 5:30:58 PM, on 1/6/2013
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\CheckPoint\ZAForceField\IswSvc.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\Explorer.EXE
C:\Program Files\CheckPoint\ZAForceField\ForceField.exe
C:\WINDOWS\system32\CTsvcCDA.exe
C:\Program Files\Creative\Shared Files\CTDevSrv.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\CheckPoint\ZoneAlarm\zatray.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\spider.exe
C:\Program Files\CheckPoint\ZoneAlarm\vsmon.exe
C:\Documents and Settings\user1\Desktop\Unused Desktop Shortcuts\HiJackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Java™ Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: ZoneAlarm Security Engine Registrar - {8A4A36C2-0535-4D2C-BD3D-496CB7EED6E3} - C:\Program Files\CheckPoint\ZAForceField\TrustChecker\bin\TrustCheckerIEPlugin.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: ZoneAlarm Security Engine - {EE2AC4E5-B0B0-4EC6-88A9-BCA1A32AB107} - C:\Program Files\CheckPoint\ZAForceField\TrustChecker\bin\TrustCheckerIEPlugin.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [ISW] C:\Program Files\CheckPoint\ZAForceField\ForceField.exe /icon="hidden"
O4 - HKLM\..\Run: [ZoneAlarm] "C:\Program Files\CheckPoint\ZoneAlarm\zatray.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {4B54A9DE-EF1C-4EBE-A328-7C28EA3B433A} (Bitdefender QuickScan Control) - http://quickscan.bitdefender.com/qsax/qsax.cab
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} - http://download.bitdefender.com/resources/scan8/oscan8.cab
O16 - DPF: {6C269571-C6D7-4818-BCA4-32A035E8C884} - http://www.creative.com/softwareupdate/su/…101/CTSUEng.cab
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} (OnlineScanner Control) - http://download.eset.com/special/eos/OnlineScanner.cab
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} (get_atlcom Class) - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} - http://www.creative.com/softwareupdate/su/…15106/CTPID.cab
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\System32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\System32\browseui.dll
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.exe
O23 - Service: CT Device Query service (CTDevice_Srv) - Creative Technology Ltd - C:\Program Files\Creative\Shared Files\CTDevSrv.exe
O23 - Service: Google Update Service (gupdate) (gupdate) - Unknown owner - C:\Program Files\Google\Update\GoogleUpdate.exe (file missing)
O23 - Service: Google Update Service (gupdatem) (gupdatem) - Unknown owner - C:\Program Files\Google\Update\GoogleUpdate.exe (file missing)
O23 - Service: ZoneAlarm LTD Toolbar IswSvc (IswSvc) - Check Point Software Technologies - C:\Program Files\CheckPoint\ZAForceField\IswSvc.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Check Point Software Technologies LTD - C:\Program Files\CheckPoint\ZoneAlarm\vsmon.exe

–
End of file - 5749 bytes




OTL logfile created on: 1/6/2013 5:48:21 PM - Run 4
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Documents and Settings\user1\My Documents
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

1.25 Gb Total Physical Memory | 0.82 Gb Available Physical Memory | 65.59% Memory free
1.84 Gb Paging File | 1.51 Gb Available in Paging File | 82.16% Paging File free
Paging file location(s): C:\pagefile.sys 756 1512 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 18.64 Gb Total Space | 1.77 Gb Free Space | 9.49% Space Free | Partition Type: NTFS
Drive F: | 931.51 Gb Total Space | 673.42 Gb Free Space | 72.29% Space Free | Partition Type: NTFS

Computer Name: COMPAQ-033HB3B9 | User Name: user1 | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Documents and Settings\user1\My Documents\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\CheckPoint\ZoneAlarm\vsmon.exe (Check Point Software Technologies LTD)
PRC - C:\Program Files\CheckPoint\ZoneAlarm\zatray.exe (Check Point Software Technologies LTD)
PRC - C:\Program Files\CheckPoint\ZAForceField\ISWSVC.exe (Check Point Software Technologies)
PRC - C:\Program Files\CheckPoint\ZAForceField\ForceField.exe (Check Point Software Technologies)
PRC - C:\WINDOWS\system32\spider.exe (Microsoft Corporation)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Creative\Shared Files\CTDevSrv.exe (Creative Technology Ltd)
PRC - C:\WINDOWS\system32\HPZipm12.exe (HP)
PRC - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe (Analog Devices, Inc.)


========== Modules (No Company Name) ==========

MOD - C:\WINDOWS\system32\nview.dll ()
MOD - C:\WINDOWS\system32\nvshell.dll ()
MOD - C:\WINDOWS\system32\spool\prtprocs\w32x86\LXCZPP5C.DLL ()


========== Services (SafeList) ==========

SRV - (gupdatem) – C:\Program Files\Google\Update\GoogleUpdate.exe /medsvc File not found
SRV - (gupdate) – C:\Program Files\Google\Update\GoogleUpdate.exe /svc File not found
SRV - (vsmon) – C:\Program Files\CheckPoint\ZoneAlarm\vsmon.exe (Check Point Software Technologies LTD)
SRV - (IswSvc) – C:\Program Files\CheckPoint\ZAForceField\ISWSVC.exe (Check Point Software Technologies)
SRV - (nosGetPlusHelper) – C:\Program Files\NOS\bin\getPlus_Helper_3004.dll (NOS Microsystems Ltd.)
SRV - (getPlusHelper) – C:\Program Files\NOS\bin\getPlus_Helper.dll (NOS Microsystems Ltd.)
SRV - (CTDevice_Srv) – C:\Program Files\Creative\Shared Files\CTDevSrv.exe (Creative Technology Ltd)
SRV - (Pml Driver HPZ12) – C:\WINDOWS\system32\HPZipm12.exe (HP)
SRV - (SoundMAX Agent Service (default) – C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe (Analog Devices, Inc.)


========== Driver Services (SafeList) ==========

DRV - (WDICA) – File not found
DRV - (Trufos) – C:\Program Files\Common Files\BitDefender\BitDefender Threat Scanner\trufos.sys File not found
DRV - (Profos) – C:\Program Files\Common Files\BitDefender\BitDefender Threat Scanner\profos.sys File not found
DRV - (PID_08A0) – system32\DRIVERS\LV302AV.SYS File not found
DRV - (PDRFRAME) – File not found
DRV - (PDRELI) – File not found
DRV - (PDFRAME) – File not found
DRV - (PDCOMP) – File not found
DRV - (PCIDump) – File not found
DRV - (mbr) – C:\DOCUME~1\user1\LOCALS~1\Temp\mbr.sys File not found
DRV - (lbrtfdc) – File not found
DRV - (i2omgmt) – File not found
DRV - (ddxgb) – C:\DOCUME~1\user1\LOCALS~1\Temp\ddxgb.sys File not found
DRV - (Changer) – File not found
DRV - (Vsdatant) – C:\WINDOWS\system32\vsdatant.sys (Check Point Software Technologies LTD)
DRV - (ISWKL) – C:\Program Files\CheckPoint\ZAForceField\ISWKL.sys (Check Point Software Technologies)
DRV - (KLIF) – C:\WINDOWS\system32\drivers\klif.sys (Kaspersky Lab)
DRV - (KL1) – C:\WINDOWS\system32\drivers\kl1.sys (Kaspersky Lab ZAO)
DRV - (kl2) – C:\WINDOWS\system32\drivers\kl2.sys (Kaspersky Lab ZAO)
DRV - (MaRdPnp) – C:\WINDOWS\system32\drivers\mardp2k.sys (Mobile Action Technology Inc.)
DRV - (MaVctrl) – C:\WINDOWS\system32\drivers\MaVc2K.sys (Mobile Action Technology Inc.)
DRV - (sfsync02) – C:\WINDOWS\system32\drivers\sfsync02.sys (Protection Technology)
DRV - (sfdrv01) – C:\WINDOWS\system32\drivers\sfdrv01.sys (Protection Technology)
DRV - (LVUSBSta) – C:\WINDOWS\system32\drivers\LVUSBSta.sys (Logitech Inc.)
DRV - (sfhlp02) – C:\WINDOWS\system32\drivers\sfhlp02.sys (Protection Technology)
DRV - (MA8512M) – C:\WINDOWS\system32\drivers\MA8512M.sys (Mobile Action Technology Inc.)
DRV - (MA8512U) – C:\WINDOWS\system32\drivers\MA8512U.sys (Mobile Action Technology Inc.)
DRV - (MadgeTRN) – C:\WINDOWS\system32\drivers\mdgndis5.sys (Madge Networks Ltd)
DRV - (ADM8511) – C:\WINDOWS\system32\drivers\ADM8511.SYS (ADMtek Incorporated)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie
IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://search.live.com/results.aspx?q={sea…ferrer:source?}

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://yahoo.com/
IE - HKCU\..\SearchScopes,DefaultScope = {E619C875-313B-4010-A055-5CFFF1585A43}
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://search.live.com/results.aspx?q={sea…amp;Form=IE8SRC
IE - HKCU\..\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}: "URL" = http://search.conduit.com/ResultsExt.aspx?…;ctid=CT2611275
IE - HKCU\..\SearchScopes\{E619C875-313B-4010-A055-5CFFF1585A43}: "URL" = http://search.zonealarm.com/search?Source=…erms}&r=687
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0


========== FireFox ==========

FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\WINDOWS\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@checkpoint.com/FFApi: C:\Program Files\CheckPoint\ZAForceField\TrustChecker\bin\npFFApi.dll ()
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\5.1.10411.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@nosltd.com/getPlus+®,version=1.6.2.97: C:\Program Files\NOS\bin\np_gp.dll (NOS Microsystems Ltd.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.123\npGoogleUpdate3.dll File not found
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.123\npGoogleUpdate3.dll File not found
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{FFB96CC1-7EB3-449D-B827-DB661701C6BB}: C:\Program Files\CheckPoint\ZAForceField\TrustChecker [2012/11/26 19:30:17 | 000,000,000 | —D | M]

[2009/08/13 14:52:32 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\user1\Application Data\Mozilla\Extensions
[2009/08/13 14:52:32 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\user1\Application Data\Mozilla\Extensions\[removed]

O1 HOSTS File: ([2008/07/13 17:31:43 | 000,250,896 | R— | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: 127.0.0.1 www.007guard.com
O1 - Hosts: 127.0.0.1 007guard.com
O1 - Hosts: 127.0.0.1 008i.com
O1 - Hosts: 127.0.0.1 www.008k.com
O1 - Hosts: 127.0.0.1 008k.com
O1 - Hosts: 127.0.0.1 www.00hq.com
O1 - Hosts: 127.0.0.1 00hq.com
O1 - Hosts: 127.0.0.1 010402.com
O1 - Hosts: 127.0.0.1 www.032439.com
O1 - Hosts: 127.0.0.1 032439.com
O1 - Hosts: 127.0.0.1 www.1001-search.info
O1 - Hosts: 127.0.0.1 1001-search.info
O1 - Hosts: 127.0.0.1 www.100888290cs.com
O1 - Hosts: 127.0.0.1 100888290cs.com
O1 - Hosts: 127.0.0.1 www.100sexlinks.com
O1 - Hosts: 127.0.0.1 100sexlinks.com
O1 - Hosts: 127.0.0.1 www.10sek.com
O1 - Hosts: 127.0.0.1 10sek.com
O1 - Hosts: 127.0.0.1 www.123topsearch.com
O1 - Hosts: 127.0.0.1 123topsearch.com
O1 - Hosts: 127.0.0.1 www.132.com
O1 - Hosts: 127.0.0.1 132.com
O1 - Hosts: 127.0.0.1 www.136136.net
O1 - Hosts: 127.0.0.1 136136.net
O1 - Hosts: 8770 more lines…
O2 - BHO: (Java™ Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (ZoneAlarm Security Engine Registrar) - {8A4A36C2-0535-4D2C-BD3D-496CB7EED6E3} - C:\Program Files\CheckPoint\ZAForceField\TrustChecker\bin\TrustCheckerIEPlugin.dll (Check Point Software Technologies)
O3 - HKLM\..\Toolbar: (ZoneAlarm Security Engine) - {EE2AC4E5-B0B0-4EC6-88A9-BCA1A32AB107} - C:\Program Files\CheckPoint\ZAForceField\TrustChecker\bin\TrustCheckerIEPlugin.dll (Check Point Software Technologies)
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (ZoneAlarm Security Engine) - {EE2AC4E5-B0B0-4EC6-88A9-BCA1A32AB107} - C:\Program Files\CheckPoint\ZAForceField\TrustChecker\bin\TrustCheckerIEPlugin.dll (Check Point Software Technologies)
O4 - HKLM..\Run: [ISW] C:\Program Files\CheckPoint\ZAForceField\ForceField.exe (Check Point Software Technologies)
O4 - HKLM..\Run: [NvCplDaemon] C:\WINDOWS\System32\NvCpl.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [NvMediaCenter] C:\WINDOWS\System32\NvMcTray.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [nwiz] C:\WINDOWS\System32\nwiz.exe ()
O4 - HKLM..\Run: [ZoneAlarm] C:\Program Files\CheckPoint\ZoneAlarm\zatray.exe (Check Point Software Technologies LTD)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 255
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: HideLegacyLogonScripts = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: HideLogoffScripts = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: RunLogonScriptSync = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: RunStartupScriptSync = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: HideStartupScripts = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: MaxRecentDocs = 2
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: HideLegacyLogonScripts = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: HideLogoffScripts = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: RunLogonScriptSync = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: RunStartupScriptSync = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: HideStartupScripts = 0
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://download.macromedia.com/pub/shockwa…director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://go.microsoft.com/fwlink/?linkid=39204 (Windows Genuine Advantage Validation Tool)
O16 - DPF: {4B54A9DE-EF1C-4EBE-A328-7C28EA3B433A} http://quickscan.bitdefender.com/qsax/qsax.cab (Bitdefender QuickScan Control)
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} http://download.bitdefender.com/resources/scan8/oscan8.cab (Reg Error: Key error.)
O16 - DPF: {6C269571-C6D7-4818-BCA4-32A035E8C884} http://www.creative.com/softwareupdate/su/…101/CTSUEng.cab (Reg Error: Key error.)
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} http://download.eset.com/special/eos/OnlineScanner.cab (OnlineScanner Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_30)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get/flash…r/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0030-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_30)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_30)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload.macromedia.com/get/flash…ent/swflash.cab (Shockwave Flash Object)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (get_atlcom Class)
O16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} http://www.creative.com/softwareupdate/su/…15106/CTPID.cab (Reg Error: Key error.)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) - C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O20 - Winlogon\Notify\AtiExtEvent: DllName - (Reg Error: Value error.) - Reg Error: Value error. File not found
O20 - Winlogon\Notify\igfxcui: DllName - (igfxsrvc.dll) - C:\WINDOWS\System32\igfxsrvc.dll (Intel Corporation)
O24 - Desktop WallPaper: C:\Documents and Settings\user1\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\user1\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006/07/25 12:11:17 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = ComFile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)

NetSvcs: 6to4 - File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: Sharedaccess - File not found
NetSvcs: WmdmPmSp - File not found

Drivers32: MIDI1 - C:\WINDOWS\System32\Syncor11.dll (SoundMAX)
Drivers32: msacm.l3acm - C:\WINDOWS\system32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.sl_anet - C:\WINDOWS\System32\sl_anet.acm (Sipro Lab Telecom Inc.)
Drivers32: msacm.trspch - C:\WINDOWS\System32\tssoft32.acm (DSP GROUP, INC.)
Drivers32: MSVideo - C:\WINDOWS\System32\vfwwdm32.dll (Microsoft Corporation)
Drivers32: MSVideo8 - C:\WINDOWS\System32\vfwwdm32.dll (Microsoft Corporation)
Drivers32: vidc.cvid - C:\WINDOWS\System32\iccvid.dll (Radius Inc.)
Drivers32: VIDC.I420 - C:\WINDOWS\System32\lvcodec2.dll (Logitech Inc.)
Drivers32: vidc.iv31 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv32 - C:\WINDOWS\System32\ir32_32.dll ()

CREATERESTOREPOINT
Restore point Set: OTL Restore Point

========== Files/Folders - Created Within 30 Days ==========

[2013/01/05 11:45:20 | 000,000,000 | R–D | C] – C:\Documents and Settings\All Users\Documents\My Videos
[2013/01/05 11:45:20 | 000,000,000 | R–D | C] – C:\Documents and Settings\All Users\Documents\My Pictures
[2013/01/05 10:58:49 | 000,050,688 | —- | C] (Atribune.org) – C:\Documents and Settings\user1\My Documents\ATF_Cleaner.exe
[2013/01/05 10:56:58 | 000,602,112 | —- | C] (OldTimer Tools) – C:\Documents and Settings\user1\My Documents\OTL.exe
[2013/01/05 10:56:32 | 000,688,992 | R— | C] (Swearware) – C:\Documents and Settings\user1\My Documents\dds.scr
[2013/01/05 10:21:37 | 000,000,000 | —D | C] – C:\Documents and Settings\user1\Downloads
[2013/01/05 09:56:17 | 000,000,000 | —D | C] – C:\Documents and Settings\user1\Application Data\QuickScan
[2013/01/05 09:49:39 | 000,000,000 | —D | C] – C:\Program Files\Panda Security
[2012/12/20 02:21:57 | 000,000,000 | RH-D | C] – C:\Documents and Settings\user1\Recent
[2012/12/19 19:06:24 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\iolo
[2012/12/19 19:02:13 | 000,000,000 | —D | C] – C:\Documents and Settings\user1\Application Data\#ISW.FS#
[1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2013/01/06 09:37:36 | 000,001,374 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2013/01/06 09:37:29 | 000,201,151 | —- | M] () – C:\WINDOWS\System32\nvapps.xml
[2013/01/06 09:36:55 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2013/01/05 13:53:23 | 000,000,000 | —- | M] () – C:\WINDOWS\MEMORY.DMP
[2013/01/05 10:58:49 | 000,050,688 | —- | M] (Atribune.org) – C:\Documents and Settings\user1\My Documents\ATF_Cleaner.exe
[2013/01/05 10:57:02 | 000,602,112 | —- | M] (OldTimer Tools) – C:\Documents and Settings\user1\My Documents\OTL.exe
[2013/01/05 10:56:33 | 000,688,992 | R— | M] (Swearware) – C:\Documents and Settings\user1\My Documents\dds.scr
[2013/01/05 10:41:55 | 000,224,120 | —- | M] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2012/12/23 06:04:02 | 000,001,520 | -HS- | M] () – C:\Documents and Settings\user1\Local Settings\Application Data\1pb78m8n6he1l1565b3k36w7o7of8ksb88y53s63tpqg0vl
[2012/12/23 06:04:02 | 000,001,520 | -HS- | M] () – C:\Documents and Settings\All Users\Application Data\1pb78m8n6he1l1565b3k36w7o7of8ksb88y53s63tpqg0vl
[2012/12/19 19:06:38 | 000,074,703 | —- | M] () – C:\WINDOWS\System32\mfc45.dll
[2012/12/16 06:23:59 | 000,290,560 | —- | M] (Adobe Systems Incorporated) – C:\WINDOWS\System32\dllcache\atmfd.dll
[2012/12/16 06:23:59 | 000,290,560 | —- | M] (Adobe Systems Incorporated) – C:\WINDOWS\System32\atmfd.dll
[2012/12/14 04:25:55 | 000,001,393 | —- | M] () – C:\WINDOWS\imsins.BAK
[1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]

========== Files Created - No Company Name ==========

[2012/12/23 06:04:01 | 000,001,520 | -HS- | C] () – C:\Documents and Settings\user1\Local Settings\Application Data\1pb78m8n6he1l1565b3k36w7o7of8ksb88y53s63tpqg0vl
[2012/12/23 06:04:01 | 000,001,520 | -HS- | C] () – C:\Documents and Settings\All Users\Application Data\1pb78m8n6he1l1565b3k36w7o7of8ksb88y53s63tpqg0vl
[2012/12/19 19:06:38 | 000,074,703 | —- | C] () – C:\WINDOWS\System32\mfc45.dll
[2012/11/19 11:41:49 | 000,000,552 | —- | C] () – C:\WINDOWS\System32\d3d8caps.dat
[2012/11/19 11:28:34 | 000,000,664 | —- | C] () – C:\WINDOWS\System32\d3d9caps.dat
[2012/05/13 23:29:25 | 000,000,397 | —- | C] () – C:\WINDOWS\CODUO.ini
[2012/05/13 23:06:43 | 000,000,766 | —- | C] () – C:\WINDOWS\COD.INI
[2012/05/13 22:40:29 | 000,000,263 | —- | C] () – C:\WINDOWS\game.ini
[2012/02/19 23:03:58 | 000,003,072 | —- | C] () – C:\WINDOWS\System32\iacenc.dll
[2012/01/08 21:29:05 | 000,000,376 | —- | C] () – C:\WINDOWS\ODBC.INI
[2011/07/31 18:45:42 | 000,000,000 | —- | C] () – C:\WINDOWS\nsreg.dat
[2011/04/01 10:13:54 | 000,043,520 | —- | C] () – C:\WINDOWS\System32\CmdLineExt03.dll
[2011/03/31 20:21:16 | 000,000,000 | —- | C] () – C:\WINDOWS\PowerReg.dat
[2010/10/10 19:51:26 | 000,000,036 | —- | C] () – C:\Documents and Settings\user1\Local Settings\Application Data\housecall.guid.cache
[2006/09/12 13:21:38 | 000,056,832 | —- | C] () – C:\Documents and Settings\user1\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini

========== ZeroAccess Check ==========

[2012/12/23 06:03:46 | 000,002,048 | -HS- | M] () – C:\RECYCLER\S-1-5-18\$3bee44a7a72cc4f4b79e244279d08397\@
[2012/12/23 06:03:46 | 000,000,000 | -HSD | M] – C:\RECYCLER\S-1-5-18\$3bee44a7a72cc4f4b79e244279d08397\L
[2012/12/23 06:03:46 | 000,000,000 | -HSD | M] – C:\RECYCLER\S-1-5-18\$3bee44a7a72cc4f4b79e244279d08397\U
[2009/04/10 16:52:07 | 000,000,227 | RHS- | M] () – C:\WINDOWS\assembly\Desktop.ini

[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]

[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]
"ThreadingModel" = Both
"" = shell32.dll – [2012/06/08 08:26:20 | 008,462,848 | —- | M] (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\System32\shdocvw.dll – [2009/12/21 23:21:02 | 001,509,888 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = fastprox.dll – [2009/02/09 06:10:48 | 000,473,600 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
"" = C:\WINDOWS\System32\wbem\wbemess.dll – [2008/04/13 18:12:08 | 000,273,920 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Both

========== LOP Check ==========

[2010/10/26 22:14:38 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Alwil Software
[2012/11/26 19:26:42 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\AVAST Software
[2007/12/12 14:06:59 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\BVRP Software
[2012/11/26 19:12:45 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\CheckPoint
[2008/06/18 10:17:00 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Friends Games
[2011/04/01 19:05:10 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Funcom
[2012/12/20 02:22:50 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\iolo
[2010/08/25 15:38:33 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\magicJack
[2008/12/13 09:40:26 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\MailFrontier
[2010/10/26 19:18:30 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\MFAData
[2012/02/20 16:52:08 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\MumboJumbo
[2008/06/20 18:10:47 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\NeoEdge Networks
[2008/05/02 23:41:32 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Oberon Media
[2008/06/21 16:55:45 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\PlayFirst
[2008/06/19 15:01:27 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\SecretsOfOlympus
[2012/04/01 22:48:24 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TEMP
[2008/06/17 12:06:58 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TERMINAL Studio
[2012/12/19 19:04:16 | 000,000,000 | —D | M] – C:\Documents and Settings\user1\Application Data\#ISW.FS#
[2008/06/17 15:54:26 | 000,000,000 | —D | M] – C:\Documents and Settings\user1\Application Data\7Wonders
[2010/02/07 14:26:45 | 000,000,000 | —D | M] – C:\Documents and Settings\user1\Application Data\Big Fish
[2009/05/20 16:53:24 | 000,000,000 | —D | M] – C:\Documents and Settings\user1\Application Data\Big Fish Games
[2012/03/28 02:35:29 | 000,000,000 | —D | M] – C:\Documents and Settings\user1\Application Data\CheckPoint
[2008/05/07 12:11:34 | 000,000,000 | —D | M] – C:\Documents and Settings\user1\Application Data\ChessBase
[2008/07/24 18:56:37 | 000,000,000 | —D | M] – C:\Documents and Settings\user1\Application Data\Disney Mix It Plug-in
[2009/10/12 14:52:13 | 000,000,000 | —D | M] – C:\Documents and Settings\user1\Application Data\Eyeblaster
[2009/09/25 15:08:48 | 000,000,000 | —D | M] – C:\Documents and Settings\user1\Application Data\Gearbox Software
[2009/07/19 20:54:47 | 000,000,000 | —D | M] – C:\Documents and Settings\user1\Application Data\Groove Games
[2008/03/20 19:11:13 | 000,000,000 | —D | M] – C:\Documents and Settings\user1\Application Data\Leadertech
[2007/12/08 18:07:21 | 000,000,000 | —D | M] – C:\Documents and Settings\user1\Application Data\Paltalk
[2008/06/21 16:59:01 | 000,000,000 | —D | M] – C:\Documents and Settings\user1\Application Data\PlayFirst
[2013/01/05 09:56:55 | 000,000,000 | —D | M] – C:\Documents and Settings\user1\Application Data\QuickScan
[2010/11/22 09:30:27 | 000,000,000 | —D | M] – C:\Documents and Settings\user1\Application Data\Registry Mechanic
[2008/01/12 21:50:10 | 000,000,000 | —D | M] – C:\Documents and Settings\user1\Application Data\Simple Star
[2008/01/12 22:04:42 | 000,000,000 | —D | M] – C:\Documents and Settings\user1\Application Data\Snapfish
[2011/01/18 13:33:45 | 000,000,000 | —D | M] – C:\Documents and Settings\user1\Application Data\TweakNow PowerPack 2010
[2010/11/22 10:17:10 | 000,000,000 | —D | M] – C:\Documents and Settings\user1\Application Data\TweakNow PowerPack Professional
[2012/06/19 11:16:35 | 000,000,000 | —D | M] – C:\Documents and Settings\user1\Application Data\VS Revo Group

========== Purity Check ==========



========== Custom Scans ==========

< %USERPROFILE%\..|smtmp;true;true;true /FP >

< %temp%\smtmp\*.* /s > >

< MD5 for: EXPLORER.EXE >
[2008/04/13 18:12:19 | 001,033,728 | —- | M] (Microsoft Corporation) MD5=12896823FB95BFB3DC9B46BCAEDC9923 – C:\WINDOWS\explorer.exe
[2008/04/13 18:12:19 | 001,033,728 | —- | M] (Microsoft Corporation) MD5=12896823FB95BFB3DC9B46BCAEDC9923 – C:\WINDOWS\ServicePackFiles\i386\explorer.exe
[2007/06/13 05:26:03 | 001,033,216 | —- | M] (Microsoft Corporation) MD5=7712DF0CDDE3A5AC89843E61CD5B3658 – C:\WINDOWS\$hf_mig$\KB938828\SP2QFE\explorer.exe
[2007/06/13 04:23:07 | 001,033,216 | —- | M] (Microsoft Corporation) MD5=97BD6515465659FF8F3B7BE375B2EA87 – C:\WINDOWS\$NtServicePackUninstall$\explorer.exe
[2004/08/03 23:56:50 | 001,032,192 | —- | M] (Microsoft Corporation) MD5=A0732187050030AE399B241436565E64 – C:\WINDOWS\$NtUninstallKB938828$\explorer.exe
[2008/04/29 09:42:08 | 000,090,624 | —- | M] () MD5=FBB39A4487E11F64DCFFD36AEC2D2216 – C:\Program Files\CheckPoint\ZAForceField\Heuristics\explorer.exe

< MD5 for: EXPLORER.EXE.000 >
[2004/08/03 23:56:50 | 001,032,192 | —- | M] (Microsoft Corporation) MD5=A0732187050030AE399B241436565E64 – C:\WINDOWS\$NtServicePackUninstall$\explorer.exe.000

< MD5 for: EXPLORER.SCF >
[2003/03/31 08:00:00 | 000,000,080 | —- | M] () MD5=A3975A7D2C98B30A2AE010754FFB9392 – C:\WINDOWS\explorer.scf

< MD5 for: IEXPLORE.CHM >
[2009/02/21 01:21:24 | 000,529,818 | —- | M] () MD5=1435F4731719DF5F57D17DC38196245D – C:\WINDOWS\Help\iexplore.chm
[2004/07/17 10:40:18 | 000,204,810 | —- | M] () MD5=60858526AAD1CC55F5F0055B8E3B66FE – C:\WINDOWS\ie8\iexplore.chm
[2004/07/17 10:40:18 | 000,204,810 | —- | M] () MD5=60858526AAD1CC55F5F0055B8E3B66FE – C:\WINDOWS\ServicePackFiles\i386\iexplore.chm

< MD5 for: IEXPLORE.EXE >
[2008/04/13 18:12:22 | 000,093,184 | —- | M] (Microsoft Corporation) MD5=55794B97A7FAABD2910873C85274F409 – C:\WINDOWS\ie8\iexplore.exe
[2008/04/13 18:12:22 | 000,093,184 | —- | M] (Microsoft Corporation) MD5=55794B97A7FAABD2910873C85274F409 – C:\WINDOWS\ServicePackFiles\i386\iexplore.exe
[2012/09/29 18:54:26 | 000,218,184 | —- | M] () MD5=8846E87210AD131CF71E3E2E49F647B0 – C:\Program Files\Malwarebytes' Anti-Malware\Chameleon\iexplore.exe
[2009/03/08 14:09:26 | 000,638,816 | —- | M] (Microsoft Corporation) MD5=B60DDDD2D63CE41CB8C487FCFBB6419E – C:\Program Files\Internet Explorer\iexplore.exe
[2009/03/08 14:09:26 | 000,638,816 | —- | M] (Microsoft Corporation) MD5=B60DDDD2D63CE41CB8C487FCFBB6419E – C:\WINDOWS\system32\dllcache\iexplore.exe
[2004/08/03 23:56:52 | 000,093,184 | —- | M] (Microsoft Corporation) MD5=E7484514C0464642BE7B4DC2689354C8 – C:\WINDOWS\$NtServicePackUninstall$\iexplore.exe
[2008/04/29 09:42:08 | 000,090,624 | —- | M] () MD5=FBB39A4487E11F64DCFFD36AEC2D2216 – C:\Program Files\CheckPoint\ZAForceField\Heuristics\iexplore.exe

< MD5 for: IEXPLORE.EXE.MUI >
[2009/03/08 14:21:44 | 000,012,288 | —- | M] (Microsoft Corporation) MD5=943030B55FDB56FB8B8FCC086071E119 – C:\Program Files\Internet Explorer\en-US\iexplore.exe.mui
[2009/03/08 14:21:44 | 000,012,288 | —- | M] (Microsoft Corporation) MD5=943030B55FDB56FB8B8FCC086071E119 – C:\Program Files\Internet Explorer\iexplore.exe.mui

< MD5 for: IEXPLORE.EXE-27122324.PF >
[2013/01/06 17:45:58 | 000,081,478 | —- | M] () MD5=E8F72278058B39034A1230C42C7BA178 – C:\WINDOWS\Prefetch\IEXPLORE.EXE-27122324.pf

< MD5 for: IEXPLORE.HLP >
[2003/03/31 08:00:00 | 000,180,335 | —- | M] () MD5=3F19AF1B745140DAFAC6F78F561A3C62 – C:\WINDOWS\Help\iexplore.hlp

< MD5 for: SERVICES >
[2003/03/31 08:00:00 | 000,007,116 | —- | M] () MD5=95826940E657FE0567A8EC0F2A6AD11A – C:\WINDOWS\system32\drivers\etc\services

< MD5 for: SERVICES.CFG >
[2012/04/03 23:53:54 | 000,585,987 | —- | M] () MD5=7BAB089A4F862C6BC86E0201D5BF1779 – C:\Program Files\Adobe\Reader 10.0\Reader\Services\Services.cfg
[2011/06/06 12:55:30 | 000,584,045 | R— | M] () MD5=B82DD53FA8C260DDD7FDC42182DB816E – C:\WINDOWS\Installer\$PatchCache$\Managed\68AB67CA7DA73301B744AA0100000010\10.1.0\services.cfg

< MD5 for: SERVICES.EXE >
[2009/02/06 05:06:24 | 000,110,592 | —- | M] (Microsoft Corporation) MD5=020CEAAEDC8EB655B6506B8C70D53BB6 – C:\WINDOWS\$hf_mig$\KB956572\SP3QFE\services.exe
[2008/04/13 18:12:34 | 000,108,544 | —- | M] (Microsoft Corporation) MD5=0E776ED5F7CC9F94299E70461B7B8185 – C:\WINDOWS\$NtUninstallKB956572$\services.exe
[2008/04/13 18:12:34 | 000,108,544 | —- | M] (Microsoft Corporation) MD5=0E776ED5F7CC9F94299E70461B7B8185 – C:\WINDOWS\ServicePackFiles\i386\services.exe
[2009/02/06 05:11:05 | 000,110,592 | —- | M] (Microsoft Corporation) MD5=65DF52F5B8B6E9BBD183505225C37315 – C:\WINDOWS\system32\dllcache\services.exe
[2009/02/06 05:11:05 | 000,110,592 | —- | M] (Microsoft Corporation) MD5=65DF52F5B8B6E9BBD183505225C37315 – C:\WINDOWS\system32\services.exe
[2004/08/03 23:56:56 | 000,108,032 | —- | M] (Microsoft Corporation) MD5=C6CE6EEC82F187615D1002BB3BB50ED4 – C:\WINDOWS\$NtServicePackUninstall$\services.exe

< MD5 for: SERVICES.LNK >
[2008/08/14 22:01:17 | 000,001,602 | —- | M] () MD5=E6B546BBAFBBF9C748355BC676CBFFBC – C:\Documents and Settings\All Users\Start Menu\Programs\Administrative Tools\Services.lnk

< MD5 for: SERVICES.MSC >
[2003/03/31 08:00:00 | 000,033,464 | —- | M] () MD5=E8089AA2A6F7FEE89B38C1F2D77BA6C6 – C:\WINDOWS\system32\services.msc

< MD5 for: WINLOGON.EXE >
[2004/08/03 23:56:58 | 000,502,272 | —- | M] (Microsoft Corporation) MD5=01C3346C241652F43AED8E2149881BFE – C:\WINDOWS\$NtServicePackUninstall$\winlogon.exe
[2012/09/29 18:54:26 | 000,218,184 | —- | M] () MD5=8846E87210AD131CF71E3E2E49F647B0 – C:\Program Files\Malwarebytes' Anti-Malware\Chameleon\winlogon.exe
[2008/04/13 18:12:39 | 000,507,904 | —- | M] (Microsoft Corporation) MD5=ED0EF0A136DEC83DF69F04118870003E – C:\WINDOWS\ServicePackFiles\i386\winlogon.exe
[2008/04/13 18:12:39 | 000,507,904 | —- | M] (Microsoft Corporation) MD5=ED0EF0A136DEC83DF69F04118870003E – C:\WINDOWS\system32\winlogon.exe
[2008/07/01 07:17:12 | 000,090,624 | —- | M] () MD5=FBB39A4487E11F64DCFFD36AEC2D2216 – C:\Program Files\CheckPoint\ZAForceField\Heuristics\winlogon.exe

< %SYSTEMDRIVE%\*.* >
[2006/07/25 12:11:17 | 000,000,000 | —- | M] () – C:\AUTOEXEC.BAT
[2010/11/22 00:15:29 | 000,000,211 | RHS- | M] () – C:\boot.ini
[2006/07/25 12:11:17 | 000,000,000 | —- | M] () – C:\CONFIG.SYS
[2006/07/25 12:11:17 | 000,000,000 | RHS- | M] () – C:\IO.SYS
[2006/07/25 12:11:17 | 000,000,000 | RHS- | M] () – C:\MSDOS.SYS
[2006/07/26 13:37:01 | 000,047,564 | RHS- | M] () – C:\NTDETECT.COM
[2008/05/16 20:34:17 | 000,250,048 | RHS- | M] () – C:\ntldr
[2013/01/06 09:36:51 | 792,723,456 | -HS- | M] () – C:\pagefile.sys
[2001/05/24 12:59:30 | 000,162,304 | —- | M] () – C:\UNWISE.EXE

< %systemroot%\Fonts\*.com >
[2006/04/18 14:39:28 | 000,026,040 | —- | M] () – C:\WINDOWS\Fonts\GlobalMonospace.CompositeFont
[2006/06/29 13:53:56 | 000,026,489 | —- | M] () – C:\WINDOWS\Fonts\GlobalSansSerif.CompositeFont
[2006/04/18 14:39:28 | 000,029,779 | —- | M] () – C:\WINDOWS\Fonts\GlobalSerif.CompositeFont
[2006/06/29 13:58:52 | 000,030,808 | —- | M] () – C:\WINDOWS\Fonts\GlobalUserInterface.CompositeFont

< %systemroot%\Fonts\*.dll >

< %systemroot%\Fonts\*.ini >
[2006/07/25 12:10:53 | 000,000,067 | -HS- | M] () – C:\WINDOWS\Fonts\desktop.ini

< %systemroot%\Fonts\*.ini2 >

< %systemroot%\Fonts\*.exe >

< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2008/07/06 06:06:10 | 000,089,088 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\filterpipelineprintproc.dll
[2006/01/18 22:33:38 | 000,078,336 | —- | M] () – C:\WINDOWS\system32\spool\prtprocs\w32x86\LXCZPP5C.DLL
[2003/06/18 17:31:48 | 000,018,944 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\mdippr.dll
[2008/07/06 04:50:03 | 000,597,504 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\printfilterpipelinesvc.exe
[2002/05/14 16:50:34 | 000,011,264 | —- | M] (BVRP Software) – C:\WINDOWS\system32\spool\prtprocs\w32x86\wfxprint2000.dll

< %systemroot%\REPAIR\*.bak1 >

< %systemroot%\REPAIR\*.ini >

< %systemroot%\system32\*.jpg >

< %systemroot%\*.jpg >

< %systemroot%\*.png >

< %systemroot%\*.scr >

< %systemroot%\*._sy >

< %APPDATA%\Adobe\Update\*.* >

< %ALLUSERSPROFILE%\Favorites\*.* >

< %APPDATA%\Microsoft\*.* >

< %PROGRAMFILES%\*.* >

< %APPDATA%\Update\*.* >

< %systemroot%\*. /mp /s >

< %systemroot%\System32\config\*.sav >
[2006/07/25 06:47:42 | 000,094,208 | —- | M] () – C:\WINDOWS\System32\config\default.sav
[2006/07/25 06:47:42 | 000,626,688 | —- | M] () – C:\WINDOWS\System32\config\software.sav
[2006/07/25 06:47:41 | 000,401,408 | —- | M] () – C:\WINDOWS\System32\config\system.sav

< %PROGRAMFILES%\bak. /s >

< %systemroot%\system32\bak. /s >

< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >
[2008/05/16 20:42:09 | 000,000,272 | -HS- | M] () – C:\Documents and Settings\All Users\Start Menu\desktop.ini

< %systemroot%\system32\config\systemprofile\*.dat /x >

< %systemroot%\*.config >

< %systemroot%\system32\*.db >

< %PROGRAMFILES%\Internet Explorer\*.dat >

< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2008/05/16 21:05:02 | 000,000,177 | -HS- | M] () – C:\Documents and Settings\user1\Application Data\Microsoft\Internet Explorer\Quick Launch\desktop.ini
[2006/07/25 12:16:51 | 000,000,079 | —- | M] () – C:\Documents and Settings\user1\Application Data\Microsoft\Internet Explorer\Quick Launch\Show Desktop.scf

< %USERPROFILE%\Desktop\*.exe >

< %PROGRAMFILES%\Common Files\*.* >

< %systemroot%\*.src >

< %systemroot%\install\*.* >

< %systemroot%\system32\DLL\*.* >

< %systemroot%\system32\HelpFiles\*.* >

< %systemroot%\system32\rundll\*.* >

< %systemroot%\winn32\*.* >

< %systemroot%\Java\*.* >

< %systemroot%\system32\test\*.* >

< %systemroot%\system32\Rundll32\*.* >

< %systemroot%\AppPatch\Custom\*.* >

< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >

< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2012-12-23 00:49:44

< >
[2006/07/25 12:08:57 | 000,000,065 | RH– | C] () – C:\WINDOWS\Tasks\desktop.ini
[2006/07/25 12:11:06 | 000,000,006 | -H– | C] () – C:\WINDOWS\Tasks\SA.DAT

========== Alternate Data Streams ==========

@Alternate Data Stream - 156 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:90D89144

< End of report >





DDS (Ver_2012-11-20.01) - NTFS_x86
Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 1.6.0_30
Run by [removed] at 18:04:57 on 2013-01-06
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1279.830 [GMT -6:00]
.
AV: ZoneAlarm Free Firewall Antivirus *Enabled/Updated* {5D467B10-818C-4CAB-9FF7-6893B5B8F3CF}
FW: ZoneAlarm Free Firewall Firewall *Enabled*
.
============== Running Processes ================
.
C:\Program Files\CheckPoint\ZAForceField\IswSvc.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\Explorer.EXE
C:\Program Files\CheckPoint\ZAForceField\ForceField.exe
C:\WINDOWS\system32\CTsvcCDA.exe
C:\Program Files\Creative\Shared Files\CTDevSrv.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\spider.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
C:\WINDOWS\System32\svchost.exe -k NetworkService
C:\WINDOWS\system32\svchost.exe -k LocalService
C:\WINDOWS\System32\svchost.exe -k LocalService
C:\WINDOWS\System32\svchost.exe -k imgsvc
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://yahoo.com/
uInternet Connection Wizard,ShellNext = iexplore
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
BHO: Adobe PDF Link Helper: {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: Java™ Plug-In SSV Helper: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - c:\program files\java\jre6\bin\ssv.dll
BHO: ZoneAlarm Security Engine Registrar: {8A4A36C2-0535-4D2C-BD3D-496CB7EED6E3} - c:\program files\checkpoint\zaforcefield\trustchecker\bin\TrustCheckerIEPlugin.dll
BHO: Java™ Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
TB: ZoneAlarm Security Engine: {EE2AC4E5-B0B0-4EC6-88A9-BCA1A32AB107} - c:\program files\checkpoint\zaforcefield\trustchecker\bin\TrustCheckerIEPlugin.dll
TB: ZoneAlarm Security Engine: {EE2AC4E5-B0B0-4EC6-88A9-BCA1A32AB107} - c:\program files\checkpoint\zaforcefield\trustchecker\bin\TrustCheckerIEPlugin.dll
EB: {32683183-48a0-441b-a342-7c2a440a9478} -
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup
mRun: [nwiz] nwiz.exe /install
mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime
mRun: [NvMediaCenter] RUNDLL32.EXE c:\windows\system32\NvMcTray.dll,NvTaskbarInit
mRun: [ISW] c:\program files\checkpoint\zaforcefield\ForceField.exe /icon="hidden"
mRun: [ZoneAlarm] "c:\program files\checkpoint\zonealarm\zatray.exe"
uPolicies-Explorer: NoDriveTypeAutoRun = dword:145
uPolicies-Explorer: NoDrives = dword:0
uPolicies-Explorer: MaxRecentDocs = dword:2
mPolicies-Explorer: NoDriveAutoRun = dword:67108863
mPolicies-Explorer: NoDriveTypeAutoRun = dword:255
mPolicies-Explorer: NoDrives = dword:0
mPolicies-Windows\System: Allow-LogonScript-NetbiosDisabled = dword:1
mPolicies-Explorer: NoDriveTypeAutoRun = dword:145
.
INFO: HKCU has more than 50 listed domains.
If you wish to scan all of them, select the 'Force scan all domains' option.
.
.
INFO: HKLM has more than 50 listed domains.
If you wish to scan all of them, select the 'Force scan all domains' option.
.
DPF: {166B1BCA-3F9C-11CF-8075-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
DPF: {17492023-C23A-453E-A040-C7C580BBF700} - hxxp://go.microsoft.com/fwlink/?linkid=39204
DPF: {4B54A9DE-EF1C-4EBE-A328-7C28EA3B433A} - hxxp://quickscan.bitdefender.com/qsax/qsax.cab
DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} - hxxp://download.bitdefender.com/resources/scan8/oscan8.cab
DPF: {6C269571-C6D7-4818-BCA4-32A035E8C884} - hxxp://www.creative.com/softwareupdate/su/ocx/15101/CTSUEng.cab
DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} - hxxp://download.eset.com/special/eos/OnlineScanner.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_30-windows-i586.cab
DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab
DPF: {CAFEEFAC-0016-0000-0030-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_30-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_30-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/swflash.cab
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} - hxxp://www.creative.com/softwareupdate/su/ocx/15106/CTPID.cab
Notify: AtiExtEvent -
Notify: igfxcui - igfxsrvc.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
.
============= SERVICES / DRIVERS ===============
.
R0 KL1;kl1;c:\windows\system32\drivers\kl1.sys [2012-11-26 133208]
R1 kl2;kl2;c:\windows\system32\drivers\kl2.sys [2012-11-26 11352]
R1 KLIF;Kaspersky Lab Driver;c:\windows\system32\drivers\klif.sys [2012-11-26 485808]
R1 Vsdatant;vsdatant;c:\windows\system32\vsdatant.sys [2012-10-9 526640]
R2 ISWKL;ZoneAlarm LTD Toolbar ISWKL;c:\program files\checkpoint\zaforcefield\ISWKL.sys [2012-8-30 27056]
R2 IswSvc;ZoneAlarm LTD Toolbar IswSvc;c:\program files\checkpoint\zaforcefield\ISWSVC.exe [2012-8-30 497320]
R2 vsmon;TrueVector Internet Monitor;c:\program files\checkpoint\zonealarm\vsmon.exe -service –> c:\program files\checkpoint\zonealarm\vsmon.exe -service [?]
S3 ADM8511;ADMtek ADM8511/AN986 USB To Fast Ethernet Converter;c:\windows\system32\drivers\ADM8511.SYS [2006-7-25 20160]
S3 MA8512M;MA8512M;c:\windows\system32\drivers\MA8512M.sys [2008-8-3 25300]
S3 MA8512U;MA8512U;c:\windows\system32\drivers\MA8512U.sys [2008-8-3 49106]
S3 MadgeTRN;Madge Token-Ring Adapter NDIS5 Driver;c:\windows\system32\drivers\mdgndis5.sys [2006-7-28 164586]
S3 nosGetPlusHelper;getPlus® Helper 3004;c:\windows\system32\svchost.exe -k nosGetPlusHelper [2003-3-31 14336]
.
=============== File Associations ===============
.
FileExt: .reg: regfile=regedit.exe "%1" %*
.
=============== Created Last 30 ================
.
2013-01-05 16:21:37 ——– d—–w- c:\documents and settings\user1\Downloads
2013-01-05 15:56:17 ——– d—–w- c:\documents and settings\user1\application data\QuickScan
2013-01-05 15:49:39 ——– d—–w- c:\program files\Panda Security
2012-12-20 01:06:38 74703 —-a-w- c:\windows\system32\mfc45.dll
2012-12-20 01:06:24 ——– d—–w- c:\documents and settings\all users\application data\iolo
2012-12-20 01:02:13 ——– d—–w- c:\documents and settings\user1\application data\#ISW.FS#
.
==================== Find3M ====================
.
2012-12-16 12:23:59 290560 —-a-w- c:\windows\system32\atmfd.dll
2012-11-13 01:25:12 1866368 —-a-w- c:\windows\system32\win32k.sys
2012-11-02 02:02:42 375296 —-a-w- c:\windows\system32\dpnet.dll
2012-11-01 12:17:54 916992 —-a-w- c:\windows\system32\wininet.dll
2012-11-01 12:17:54 43520 —-a-w- c:\windows\system32\licmgr10.dll
2012-11-01 12:17:54 1469440 ——w- c:\windows\system32\inetcpl.cpl
2012-11-01 00:35:34 385024 —-a-w- c:\windows\system32\html.iec
.
============= FINISH: 18:05:39.17 ===============
Hello,
Welcome to WhatTheTech. My name is mowman, and I will be helping you fix your problems.

If you do not make a reply in 3 days, we will have to close your topic.

You may want to keep the link to this topic in your favorites. Alternatively, you can click the Options button at the top bar of this topic and Track this topic. The topics you are tracking can be found by clicking on My Topics at the top of any page.

Please take note of some guidelines for this fix:

•Refrain from making any changes to your computer including installing/uninstall programs, deleting files, modifying the registry, and running scanners or tools. Doing so could cause changes to the directions I have to give you and prolong the time required. Further more, you should not be taking any advice relating to this computer from any other source throughout the course of this fix.
•If you do not understand any step(s) provided, please do not hesitate to ask before continuing. I would much rather clarify instructions or explain them differently than have something important broken.
•Even if things appear to be better, it might not mean we are finished. Please continue to follow my instructions and reply back until I give you the "all clean". We do not want to clean you part-way, only to have the system re-infect itself.
•Please reply using the button in the lower right hand corner of your screen. Do not start a new topic. The logs that you post should be pasted directly into the reply.
Only attach them if requested or if they do not fit into the post





Please download TDSSKiller.zip
  • Extract it to your desktop
  • Double click TDSSKiller.exe
  • Press Start Scan
    • Only if Malicious objects are found then ensure Cure is selected
      If suspicious objects are found select skip
    • Then click Continue > Reboot now
  • Copy and paste the log in your next reply
    • A copy of the log will be saved automatically to the root of the drive (typically C:\)








Download ComboFix from one of these locations:

Link 1
Link 2


* IMPORTANT !!! Save ComboFix.exe to your Desktop


  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools
  • See this Link for programs that need to be disabled and instruction on how to disable them.
  • Remember to re-enable them when we're done.

  • Double click on ComboFix.exe & follow the prompts.

  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.


[external image: Posted Image]



Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]


Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.

*If there is no internet connection when Combofix has completely finished then restart your computer to restore back the connections.
NOTE: If you encounter a message "illegal operation attempted on registry key that has been marked for deletion" and no programs will run - please just reboot and that will resolve that error
Mowman,

Had a lot of difficulty getting the combofix and tdsskiller to be saved to desktop and even run them. When ready to run the programs the pc would shut down, screen would blink or change but I got it done

18:36:25.0984 3656 TDSS rootkit removing tool 2.8.15.0 Oct 31 2012 21:47:35
18:36:26.0015 3656 ============================================================
18:36:26.0015 3656 Current date / time: 2013/01/08 18:36:26.0015
18:36:26.0015 3656 SystemInfo:
18:36:26.0015 3656
18:36:26.0015 3656 OS Version: 5.1.2600 ServicePack: 3.0
18:36:26.0015 3656 Product type: Workstation
18:36:26.0015 3656 ComputerName: COMPAQ-033HB3B9
18:36:26.0031 3656 UserName: user1
18:36:26.0031 3656 Windows directory: C:\WINDOWS
18:36:26.0031 3656 System windows directory: C:\WINDOWS
18:36:26.0031 3656 Processor architecture: Intel x86
18:36:26.0031 3656 Number of processors: 1
18:36:26.0031 3656 Page size: 0x1000
18:36:26.0031 3656 Boot type: Normal boot
18:36:26.0031 3656 ============================================================
18:36:27.0890 3656 Drive \Device\Harddisk0\DR0 - Size: 0x4A94F0000 (18.65 Gb), SectorSize: 0x200, Cylinders: 0xA1A, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xF0, Type 'K0', Flags 0x00000054
18:36:27.0890 3656 ============================================================
18:36:27.0890 3656 \Device\Harddisk0\DR0:
18:36:27.0890 3656 MBR partitions:
18:36:27.0890 3656 \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x3F, BlocksNum 0x2546451
18:36:27.0890 3656 ============================================================
18:36:27.0906 3656 C: <-> \Device\Harddisk0\DR0\Partition1
18:36:27.0921 3656 ============================================================
18:36:27.0921 3656 Initialize success
18:36:27.0921 3656 ============================================================
18:36:51.0109 4008 ============================================================
18:36:51.0109 4008 Scan started
18:36:51.0109 4008 Mode: Manual;
18:36:51.0109 4008 ============================================================
18:36:51.0265 4008 ================ Scan system memory ========================
18:36:51.0265 4008 System memory - ok
18:36:51.0281 4008 ================ Scan services =============================
18:36:51.0421 4008 Abiosdsk - ok
18:36:51.0437 4008 abp480n5 - ok
18:36:51.0484 4008 [ 8FD99680A539792A30E97944FDAECF17 ] ACPI C:\WINDOWS\system32\DRIVERS\ACPI.sys
18:36:51.0500 4008 ACPI - ok
18:36:51.0546 4008 [ 9859C0F6936E723E4892D7141B1327D5 ] ACPIEC C:\WINDOWS\system32\drivers\ACPIEC.sys
18:36:51.0546 4008 ACPIEC - ok
18:36:51.0593 4008 [ B05F2367F62552A2DE7E3C352B7B9885 ] ADM8511 C:\WINDOWS\system32\DRIVERS\ADM8511.SYS
18:36:51.0593 4008 ADM8511 - ok
18:36:51.0609 4008 adpu160m - ok
18:36:51.0671 4008 [ E696E749BEDCDA8B23757B8B5EA93780 ] aeaudio C:\WINDOWS\system32\drivers\aeaudio.sys
18:36:51.0671 4008 aeaudio - ok
18:36:51.0703 4008 [ 8BED39E3C35D6A489438B8141717A557 ] aec C:\WINDOWS\system32\drivers\aec.sys
18:36:51.0703 4008 aec - ok
18:36:51.0750 4008 [ 1E44BC1E83D8FD2305F8D452DB109CF9 ] AFD C:\WINDOWS\System32\drivers\afd.sys
18:36:51.0765 4008 AFD - ok
18:36:51.0796 4008 [ 08FD04AA961BDC77FB983F328334E3D7 ] agp440 C:\WINDOWS\system32\DRIVERS\agp440.sys
18:36:51.0796 4008 agp440 - ok
18:36:51.0812 4008 Aha154x - ok
18:36:51.0843 4008 aic78u2 - ok
18:36:51.0859 4008 aic78xx - ok
18:36:51.0890 4008 [ A9A3DAA780CA6C9671A19D52456705B4 ] Alerter C:\WINDOWS\system32\alrsvc.dll
18:36:51.0906 4008 Alerter - ok
18:36:51.0937 4008 [ 8C515081584A38AA007909CD02020B3D ] ALG C:\WINDOWS\System32\alg.exe
18:36:51.0937 4008 ALG - ok
18:36:51.0953 4008 AliIde - ok
18:36:51.0984 4008 amsint - ok
18:36:52.0015 4008 [ D8849F77C0B66226335A59D26CB4EDC6 ] AppMgmt C:\WINDOWS\System32\appmgmts.dll
18:36:52.0031 4008 AppMgmt - ok
18:36:52.0046 4008 asc - ok
18:36:52.0062 4008 asc3350p - ok
18:36:52.0093 4008 asc3550 - ok
18:36:52.0187 4008 [ 0E5E4957549056E2BF2C49F4F6B601AD ] aspnet_state C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe
18:36:52.0296 4008 aspnet_state - ok
18:36:52.0328 4008 [ B153AFFAC761E7F5FCFA822B9C4E97BC ] AsyncMac C:\WINDOWS\system32\DRIVERS\asyncmac.sys
18:36:52.0343 4008 AsyncMac - ok
18:36:52.0375 4008 [ 9F3A2F5AA6875C72BF062C712CFA2674 ] atapi C:\WINDOWS\system32\DRIVERS\atapi.sys
18:36:52.0375 4008 atapi - ok
18:36:52.0390 4008 Atdisk - ok
18:36:52.0437 4008 [ 9916C1225104BA14794209CFA8012159 ] Atmarpc C:\WINDOWS\system32\DRIVERS\atmarpc.sys
18:36:52.0437 4008 Atmarpc - ok
18:36:52.0484 4008 [ DEF7A7882BEC100FE0B2CE2549188F9D ] AudioSrv C:\WINDOWS\System32\audiosrv.dll
18:36:52.0484 4008 AudioSrv - ok
18:36:52.0515 4008 [ D9F724AA26C010A217C97606B160ED68 ] audstub C:\WINDOWS\system32\DRIVERS\audstub.sys
18:36:52.0515 4008 audstub - ok
18:36:52.0578 4008 [ DA1F27D85E0D1525F6621372E7B685E9 ] Beep C:\WINDOWS\system32\drivers\Beep.sys
18:36:52.0578 4008 Beep - ok
18:36:52.0640 4008 [ 574738F61FCA2935F5265DC4E5691314 ] BITS C:\WINDOWS\system32\qmgr.dll
18:36:52.0703 4008 BITS - ok
18:36:52.0750 4008 [ CFD4E51402DA9838B5A04AE680AF54A0 ] Browser C:\WINDOWS\System32\browser.dll
18:36:52.0750 4008 Browser - ok
18:36:52.0843 4008 catchme - ok
18:36:52.0890 4008 [ 90A673FC8E12A79AFBED2576F6A7AAF9 ] cbidf2k C:\WINDOWS\system32\drivers\cbidf2k.sys
18:36:52.0890 4008 cbidf2k - ok
18:36:52.0937 4008 [ 0BE5AEF125BE881C4F854C554F2B025C ] CCDECODE C:\WINDOWS\system32\DRIVERS\CCDECODE.sys
18:36:52.0937 4008 CCDECODE - ok
18:36:52.0968 4008 cd20xrnt - ok
18:36:53.0015 4008 [ C1B486A7658353D33A10CC15211A873B ] Cdaudio C:\WINDOWS\system32\drivers\Cdaudio.sys
18:36:53.0015 4008 Cdaudio - ok
18:36:53.0046 4008 [ C885B02847F5D2FD45A24E219ED93B32 ] Cdfs C:\WINDOWS\system32\drivers\Cdfs.sys
18:36:53.0046 4008 Cdfs - ok
18:36:53.0078 4008 [ 1F4260CC5B42272D71F79E570A27A4FE ] Cdrom C:\WINDOWS\system32\DRIVERS\cdrom.sys
18:36:53.0078 4008 Cdrom - ok
18:36:53.0109 4008 Changer - ok
18:36:53.0156 4008 [ 1CFE720EB8D93A7158A4EBC3AB178BDE ] CiSvc C:\WINDOWS\system32\cisvc.exe
18:36:53.0156 4008 CiSvc - ok
18:36:53.0187 4008 [ 34CBE729F38138217F9C80212A2A0C82 ] ClipSrv C:\WINDOWS\system32\clipsrv.exe
18:36:53.0187 4008 ClipSrv - ok
18:36:53.0234 4008 [ D87ACAED61E417BBA546CED5E7E36D9C ] clr_optimization_v2.0.50727_32 C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
18:36:53.0375 4008 clr_optimization_v2.0.50727_32 - ok
18:36:53.0390 4008 CmdIde - ok
18:36:53.0421 4008 COMSysApp - ok
18:36:53.0453 4008 Cpqarray - ok
18:36:53.0515 4008 [ 3C8B6609712F4FF78E521F6DCFC4032B ] Creative Service for CDROM Access C:\WINDOWS\system32\CTsvcCDA.exe
18:36:53.0531 4008 Creative Service for CDROM Access - ok
18:36:53.0578 4008 [ 3D4E199942E29207970E04315D02AD3B ] CryptSvc C:\WINDOWS\System32\cryptsvc.dll
18:36:53.0578 4008 CryptSvc - ok
18:36:53.0703 4008 [ A5BEA0E5C297F5F3835638A87E512FBA ] CTDevice_Srv C:\Program Files\Creative\Shared Files\CTDevSrv.exe
18:36:53.0703 4008 CTDevice_Srv - ok
18:36:53.0718 4008 dac2w2k - ok
18:36:53.0750 4008 dac960nt - ok
18:36:53.0796 4008 [ 6B27A5C03DFB94B4245739065431322C ] DcomLaunch C:\WINDOWS\system32\rpcss.dll
18:36:53.0828 4008 DcomLaunch - ok
18:36:53.0843 4008 ddxgb - ok
18:36:53.0890 4008 [ 5E38D7684A49CACFB752B046357E0589 ] Dhcp C:\WINDOWS\System32\dhcpcsvc.dll
18:36:53.0890 4008 Dhcp - ok
18:36:53.0921 4008 [ 044452051F3E02E7963599FC8F4F3E25 ] Disk C:\WINDOWS\system32\DRIVERS\disk.sys
18:36:53.0921 4008 Disk - ok
18:36:53.0937 4008 dmadmin - ok
18:36:54.0000 4008 [ D992FE1274BDE0F84AD826ACAE022A41 ] dmboot C:\WINDOWS\system32\drivers\dmboot.sys
18:36:54.0046 4008 dmboot - ok
18:36:54.0062 4008 dmio - ok
18:36:54.0109 4008 [ E9317282A63CA4D188C0DF5E09C6AC5F ] dmload C:\WINDOWS\system32\drivers\dmload.sys
18:36:54.0109 4008 dmload - ok
18:36:54.0156 4008 [ 57EDEC2E5F59F0335E92F35184BC8631 ] dmserver C:\WINDOWS\System32\dmserver.dll
18:36:54.0171 4008 dmserver - ok
18:36:54.0218 4008 [ 8A208DFCF89792A484E76C40E5F50B45 ] DMusic C:\WINDOWS\system32\drivers\DMusic.sys
18:36:54.0218 4008 DMusic - ok
18:36:54.0265 4008 [ 5F7E24FA9EAB896051FFB87F840730D2 ] Dnscache C:\WINDOWS\System32\dnsrslvr.dll
18:36:54.0265 4008 Dnscache - ok
18:36:54.0312 4008 [ 0F0F6E687E5E15579EF4DA8DD6945814 ] Dot3svc C:\WINDOWS\System32\dot3svc.dll
18:36:54.0328 4008 Dot3svc - ok
18:36:54.0343 4008 dpti2o - ok
18:36:54.0359 4008 [ 8F5FCFF8E8848AFAC920905FBD9D33C8 ] drmkaud C:\WINDOWS\system32\drivers\drmkaud.sys
18:36:54.0359 4008 drmkaud - ok
18:36:54.0406 4008 [ D57A8FC800B501AC05B10D00F66D127A ] E100B C:\WINDOWS\system32\DRIVERS\e100b325.sys
18:36:54.0437 4008 E100B - ok
18:36:54.0500 4008 [ 2187855A7703ADEF0CEF9EE4285182CC ] EapHost C:\WINDOWS\System32\eapsvc.dll
18:36:54.0500 4008 EapHost - ok
18:36:54.0546 4008 [ BC93B4A066477954555966D77FEC9ECB ] ERSvc C:\WINDOWS\System32\ersvc.dll
18:36:54.0546 4008 ERSvc - ok
18:36:54.0593 4008 [ 65DF52F5B8B6E9BBD183505225C37315 ] Eventlog C:\WINDOWS\system32\services.exe
18:36:54.0609 4008 Eventlog - ok
18:36:54.0656 4008 [ D4991D98F2DB73C60D042F1AEF79EFAE ] EventSystem C:\WINDOWS\System32\es.dll
18:36:54.0671 4008 EventSystem - ok
18:36:54.0718 4008 [ 38D332A6D56AF32635675F132548343E ] Fastfat C:\WINDOWS\system32\drivers\Fastfat.sys
18:36:54.0718 4008 Fastfat - ok
18:36:54.0765 4008 [ 99BC0B50F511924348BE19C7C7313BBF ] FastUserSwitchingCompatibility C:\WINDOWS\System32\shsvcs.dll
18:36:54.0781 4008 FastUserSwitchingCompatibility - ok
18:36:54.0812 4008 [ 92CDD60B6730B9F50F6A1A0C1F8CDC81 ] Fdc C:\WINDOWS\system32\DRIVERS\fdc.sys
18:36:54.0812 4008 Fdc - ok
18:36:54.0843 4008 [ D45926117EB9FA946A6AF572FBE1CAA3 ] Fips C:\WINDOWS\system32\drivers\Fips.sys
18:36:54.0843 4008 Fips - ok
18:36:54.0875 4008 [ 9D27E7B80BFCDF1CDD9B555862D5E7F0 ] Flpydisk C:\WINDOWS\system32\DRIVERS\flpydisk.sys
18:36:54.0875 4008 Flpydisk - ok
18:36:54.0937 4008 [ B2CF4B0786F8212CB92ED2B50C6DB6B0 ] FltMgr C:\WINDOWS\system32\drivers\fltmgr.sys
18:36:54.0937 4008 FltMgr - ok
18:36:55.0015 4008 [ 8BA7C024070F2B7FDD98ED8A4BA41789 ] FontCache3.0.0.0 C:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe
18:36:55.0015 4008 FontCache3.0.0.0 - ok
18:36:55.0046 4008 [ 3E1E2BD4F39B0E2B7DC4F4D2BCC2779A ] Fs_Rec C:\WINDOWS\system32\drivers\Fs_Rec.sys
18:36:55.0046 4008 Fs_Rec - ok
18:36:55.0078 4008 [ 6AC26732762483366C3969C9E4D2259D ] Ftdisk C:\WINDOWS\system32\DRIVERS\ftdisk.sys
18:36:55.0078 4008 Ftdisk - ok
18:36:55.0140 4008 [ 0879DC7444A201DF84E69C5DD5083D61 ] getPlusHelper C:\Program Files\NOS\bin\getPlus_Helper.dll
18:36:55.0156 4008 getPlusHelper - ok
18:36:55.0187 4008 [ 0A02C63C8B144BD8C86B103DEE7C86A2 ] Gpc C:\WINDOWS\system32\DRIVERS\msgpc.sys
18:36:55.0203 4008 Gpc - ok
18:36:55.0218 4008 gupdate - ok
18:36:55.0234 4008 gupdatem - ok
18:36:55.0296 4008 [ 4FCCA060DFE0C51A09DD5C3843888BCD ] helpsvc C:\WINDOWS\PCHealth\HelpCtr\Binaries\pchsvc.dll
18:36:55.0296 4008 helpsvc - ok
18:36:55.0328 4008 [ DEB04DA35CC871B6D309B77E1443C796 ] HidServ C:\WINDOWS\System32\hidserv.dll
18:36:55.0343 4008 HidServ - ok
18:36:55.0359 4008 [ CCF82C5EC8A7326C3066DE870C06DAF1 ] HidUsb C:\WINDOWS\system32\DRIVERS\hidusb.sys
18:36:55.0359 4008 HidUsb - ok
18:36:55.0406 4008 [ 8878BD685E490239777BFE51320B88E9 ] hkmsvc C:\WINDOWS\System32\kmsvc.dll
18:36:55.0406 4008 hkmsvc - ok
18:36:55.0437 4008 hpn - ok
18:36:55.0484 4008 [ 9F1D80908658EB7F1BF70809E0B51470 ] HPZid412 C:\WINDOWS\system32\DRIVERS\HPZid412.sys
18:36:55.0484 4008 HPZid412 - ok
18:36:55.0500 4008 [ F7E3E9D50F9CD3DE28085A8FDAA0A1C3 ] HPZipr12 C:\WINDOWS\system32\DRIVERS\HPZipr12.sys
18:36:55.0515 4008 HPZipr12 - ok
18:36:55.0531 4008 [ CF1B7951B4EC8D13F3C93B74BB2B461B ] HPZius12 C:\WINDOWS\system32\DRIVERS\HPZius12.sys
18:36:55.0531 4008 HPZius12 - ok
18:36:55.0578 4008 [ F80A415EF82CD06FFAF0D971528EAD38 ] HTTP C:\WINDOWS\system32\Drivers\HTTP.sys
18:36:55.0609 4008 HTTP - ok
18:36:55.0656 4008 [ 6100A808600F44D999CEBDEF8841C7A3 ] HTTPFilter C:\WINDOWS\System32\w3ssl.dll
18:36:55.0687 4008 HTTPFilter - ok
18:36:55.0703 4008 i2omgmt - ok
18:36:55.0718 4008 i2omp - ok
18:36:55.0765 4008 [ 4A0B06AA8943C1E332520F7440C0AA30 ] i8042prt C:\WINDOWS\system32\DRIVERS\i8042prt.sys
18:36:55.0765 4008 i8042prt - ok
18:36:55.0843 4008 [ 44B7D5A4F2BD9FE21AEA0BB0BACE38C4 ] ialm C:\WINDOWS\system32\DRIVERS\ialmnt5.sys
18:36:55.0875 4008 ialm - ok
18:36:55.0984 4008 [ C01AC32DC5C03076CFB852CB5DA5229C ] idsvc C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe
18:36:56.0015 4008 idsvc - ok
18:36:56.0046 4008 [ 083A052659F5310DD8B6A6CB05EDCF8E ] Imapi C:\WINDOWS\system32\DRIVERS\imapi.sys
18:36:56.0046 4008 Imapi - ok
18:36:56.0093 4008 [ 30DEAF54A9755BB8546168CFE8A6B5E1 ] ImapiService C:\WINDOWS\system32\imapi.exe
18:36:56.0109 4008 ImapiService - ok
18:36:56.0140 4008 ini910u - ok
18:36:56.0171 4008 [ B5466A9250342A7AA0CD1FBA13420678 ] IntelIde C:\WINDOWS\system32\DRIVERS\intelide.sys
18:36:56.0171 4008 IntelIde - ok
18:36:56.0218 4008 [ 8C953733D8F36EB2133F5BB58808B66B ] intelppm C:\WINDOWS\system32\DRIVERS\intelppm.sys
18:36:56.0234 4008 intelppm - ok
18:36:56.0265 4008 [ 3BB22519A194418D5FEC05D800A19AD0 ] ip6fw C:\WINDOWS\system32\drivers\ip6fw.sys
18:36:56.0281 4008 ip6fw - ok
18:36:56.0328 4008 [ 731F22BA402EE4B62748ADAF6363C182 ] IpFilterDriver C:\WINDOWS\system32\DRIVERS\ipfltdrv.sys
18:36:56.0328 4008 IpFilterDriver - ok
18:36:56.0390 4008 [ B87AB476DCF76E72010632B5550955F5 ] IpInIp C:\WINDOWS\system32\DRIVERS\ipinip.sys
18:36:56.0390 4008 IpInIp - ok
18:36:56.0406 4008 [ CC748EA12C6EFFDE940EE98098BF96BB ] IpNat C:\WINDOWS\system32\DRIVERS\ipnat.sys
18:36:56.0421 4008 IpNat - ok
18:36:56.0468 4008 [ 23C74D75E36E7158768DD63D92789A91 ] IPSec C:\WINDOWS\system32\DRIVERS\ipsec.sys
18:36:56.0484 4008 IPSec - ok
18:36:56.0500 4008 [ C93C9FF7B04D772627A3646D89F7BF89 ] IRENUM C:\WINDOWS\system32\DRIVERS\irenum.sys
18:36:56.0500 4008 IRENUM - ok
18:36:56.0546 4008 [ 05A299EC56E52649B1CF2FC52D20F2D7 ] isapnp C:\WINDOWS\system32\DRIVERS\isapnp.sys
18:36:56.0546 4008 isapnp - ok
18:36:56.0625 4008 [ 6ED8D475BF2F950F3262942F630B3A20 ] ISWKL C:\Program Files\CheckPoint\ZAForceField\ISWKL.sys
18:36:56.0625 4008 ISWKL - ok
18:36:56.0671 4008 [ 8A698B79EDF2BA40E42ADD764F43FAA7 ] IswSvc C:\Program Files\CheckPoint\ZAForceField\IswSvc.exe
18:36:56.0687 4008 IswSvc - ok
18:36:56.0781 4008 [ 9AA67569D5257462E230767510B0C815 ] JavaQuickStarterService C:\Program Files\Java\jre6\bin\jqs.exe
18:36:56.0781 4008 JavaQuickStarterService - ok
18:36:56.0812 4008 [ 463C1EC80CD17420A542B7F36A36F128 ] Kbdclass C:\WINDOWS\system32\DRIVERS\kbdclass.sys
18:36:56.0812 4008 Kbdclass - ok
18:36:56.0843 4008 [ 9EF487A186DEA361AA06913A75B3FA99 ] kbdhid C:\WINDOWS\system32\DRIVERS\kbdhid.sys
18:36:56.0859 4008 kbdhid - ok
18:36:56.0921 4008 [ 186B54479D98E48AEE0E9ADA4B3C4D31 ] KL1 C:\WINDOWS\system32\DRIVERS\kl1.sys
18:36:56.0921 4008 KL1 - ok
18:36:56.0953 4008 [ BF485BFBA13C0AB116701FD9C55324D0 ] kl2 C:\WINDOWS\system32\DRIVERS\kl2.sys
18:36:56.0953 4008 kl2 - ok
18:36:57.0015 4008 [ 1267FC6F43F2868127A01E9766BF51A7 ] KLIF C:\WINDOWS\system32\DRIVERS\klif.sys
18:36:57.0015 4008 KLIF - ok
18:36:57.0062 4008 [ 692BCF44383D056AED41B045A323D378 ] kmixer C:\WINDOWS\system32\drivers\kmixer.sys
18:36:57.0062 4008 kmixer - ok
18:36:57.0109 4008 [ B467646C54CC746128904E1654C750C1 ] KSecDD C:\WINDOWS\system32\drivers\KSecDD.sys
18:36:57.0125 4008 KSecDD - ok
18:36:57.0171 4008 [ 3A7C3CBE5D96B8AE96CE81F0B22FB527 ] lanmanserver C:\WINDOWS\System32\srvsvc.dll
18:36:57.0187 4008 lanmanserver - ok
18:36:57.0234 4008 [ A8888A5327621856C0CEC4E385F69309 ] lanmanworkstation C:\WINDOWS\System32\wkssvc.dll
18:36:57.0250 4008 lanmanworkstation - ok
18:36:57.0265 4008 lbrtfdc - ok
18:36:57.0328 4008 [ A1043645D16915DF12A6F2E049922A18 ] LexBceS C:\WINDOWS\system32\LEXBCES.EXE
18:36:57.0343 4008 LexBceS - ok
18:36:57.0390 4008 [ A7DB739AE99A796D91580147E919CC59 ] LmHosts C:\WINDOWS\System32\lmhsvc.dll
18:36:57.0390 4008 LmHosts - ok
18:36:57.0437 4008 [ C5EFBD05A5195402121711A6EBBB271F ] LVUSBSta C:\WINDOWS\system32\DRIVERS\LVUSBSta.sys
18:36:57.0437 4008 LVUSBSta - ok
18:36:57.0500 4008 [ B7F88D160F8DAF09140D241B19087BD8 ] MA8512M C:\WINDOWS\system32\DRIVERS\MA8512M.sys
18:36:57.0500 4008 MA8512M - ok
18:36:57.0531 4008 [ 3B3C6978D2BC808C884B8F0F5D3A3F56 ] MA8512U C:\WINDOWS\system32\DRIVERS\MA8512U.sys
18:36:57.0531 4008 MA8512U - ok
18:36:57.0578 4008 [ 2DEDAA32406555930EFE616A1C9F46E1 ] MadgeTRN C:\WINDOWS\system32\DRIVERS\mdgndis5.sys
18:36:57.0593 4008 MadgeTRN - ok
18:36:57.0625 4008 [ B51E7EAB4BAF13B492AA3299BCF52A35 ] MaRdPnp C:\WINDOWS\system32\DRIVERS\MaRdP2K.sys
18:36:57.0625 4008 MaRdPnp - ok
18:36:57.0656 4008 [ 1B467FB39D6EE0E7F1970EEE5FC07121 ] MaVctrl C:\WINDOWS\system32\DRIVERS\MaVc2K.sys
18:36:57.0656 4008 MaVctrl - ok
18:36:57.0703 4008 [ 986B1FF5814366D71E0AC5755C88F2D3 ] Messenger C:\WINDOWS\System32\msgsvc.dll
18:36:57.0703 4008 Messenger - ok
18:36:57.0750 4008 [ 4AE068242760A1FB6E1A44BF4E16AFA6 ] mnmdd C:\WINDOWS\system32\drivers\mnmdd.sys
18:36:57.0750 4008 mnmdd - ok
18:36:57.0796 4008 [ D18F1F0C101D06A1C1ADF26EED16FCDD ] mnmsrvc C:\WINDOWS\System32\mnmsrvc.exe
18:36:57.0796 4008 mnmsrvc - ok
18:36:57.0843 4008 [ DFCBAD3CEC1C5F964962AE10E0BCC8E1 ] Modem C:\WINDOWS\system32\drivers\Modem.sys
18:36:57.0843 4008 Modem - ok
18:36:57.0890 4008 [ 35C9E97194C8CFB8430125F8DBC34D04 ] Mouclass C:\WINDOWS\system32\DRIVERS\mouclass.sys
18:36:57.0890 4008 Mouclass - ok
18:36:57.0937 4008 [ B1C303E17FB9D46E87A98E4BA6769685 ] mouhid C:\WINDOWS\system32\DRIVERS\mouhid.sys
18:36:57.0937 4008 mouhid - ok
18:36:57.0984 4008 [ A80B9A0BAD1B73637DBCBBA7DF72D3FD ] MountMgr C:\WINDOWS\system32\drivers\MountMgr.sys
18:36:57.0984 4008 MountMgr - ok
18:36:58.0000 4008 mraid35x - ok
18:36:58.0031 4008 [ 11D42BB6206F33FBB3BA0288D3EF81BD ] MRxDAV C:\WINDOWS\system32\DRIVERS\mrxdav.sys
18:36:58.0031 4008 MRxDAV - ok
18:36:58.0093 4008 [ 7D304A5EB4344EBEEAB53A2FE3FFB9F0 ] MRxSmb C:\WINDOWS\system32\DRIVERS\mrxsmb.sys
18:36:58.0109 4008 MRxSmb - ok
18:36:58.0171 4008 [ A137F1470499A205ABBB9AAFB3B6F2B1 ] MSDTC C:\WINDOWS\System32\msdtc.exe
18:36:58.0171 4008 MSDTC - ok
18:36:58.0203 4008 [ C941EA2454BA8350021D774DAF0F1027 ] Msfs C:\WINDOWS\system32\drivers\Msfs.sys
18:36:58.0203 4008 Msfs - ok
18:36:58.0234 4008 MSIServer - ok
18:36:58.0265 4008 [ D1575E71568F4D9E14CA56B7B0453BF1 ] MSKSSRV C:\WINDOWS\system32\drivers\MSKSSRV.sys
18:36:58.0281 4008 MSKSSRV - ok
18:36:58.0296 4008 [ 325BB26842FC7CCC1FCCE2C457317F3E ] MSPCLOCK C:\WINDOWS\system32\drivers\MSPCLOCK.sys
18:36:58.0296 4008 MSPCLOCK - ok
18:36:58.0312 4008 [ BAD59648BA099DA4A17680B39730CB3D ] MSPQM C:\WINDOWS\system32\drivers\MSPQM.sys
18:36:58.0328 4008 MSPQM - ok
18:36:58.0359 4008 [ AF5F4F3F14A8EA2C26DE30F7A1E17136 ] mssmbios C:\WINDOWS\system32\DRIVERS\mssmbios.sys
18:36:58.0359 4008 mssmbios - ok
18:36:58.0406 4008 [ E53736A9E30C45FA9E7B5EAC55056D1D ] MSTEE C:\WINDOWS\system32\drivers\MSTEE.sys
18:36:58.0406 4008 MSTEE - ok
18:36:58.0453 4008 [ DE6A75F5C270E756C5508D94B6CF68F5 ] Mup C:\WINDOWS\system32\drivers\Mup.sys
18:36:58.0453 4008 Mup - ok
18:36:58.0484 4008 [ 5B50F1B2A2ED47D560577B221DA734DB ] NABTSFEC C:\WINDOWS\system32\DRIVERS\NABTSFEC.sys
18:36:58.0484 4008 NABTSFEC - ok
18:36:58.0546 4008 [ 0102140028FAD045756796E1C685D695 ] napagent C:\WINDOWS\System32\qagentrt.dll
18:36:58.0546 4008 napagent - ok
18:36:58.0593 4008 [ 1DF7F42665C94B825322FAE71721130D ] NDIS C:\WINDOWS\system32\drivers\NDIS.sys
18:36:58.0593 4008 NDIS - ok
18:36:58.0640 4008 [ 0109C4F3850DFBAB279542515386AE22 ] NdisTapi C:\WINDOWS\system32\DRIVERS\ndistapi.sys
18:36:58.0640 4008 NdisTapi - ok
18:36:58.0687 4008 [ F927A4434C5028758A842943EF1A3849 ] Ndisuio C:\WINDOWS\system32\DRIVERS\ndisuio.sys
18:36:58.0687 4008 Ndisuio - ok
18:36:58.0718 4008 [ EDC1531A49C80614B2CFDA43CA8659AB ] NdisWan C:\WINDOWS\system32\DRIVERS\ndiswan.sys
18:36:58.0718 4008 NdisWan - ok
18:36:58.0781 4008 [ 9282BD12DFB069D3889EB3FCC1000A9B ] NDProxy C:\WINDOWS\system32\drivers\NDProxy.sys
18:36:58.0781 4008 NDProxy - ok
18:36:58.0828 4008 [ 5D81CF9A2F1A3A756B66CF684911CDF0 ] NetBIOS C:\WINDOWS\system32\DRIVERS\netbios.sys
18:36:58.0843 4008 NetBIOS - ok
18:36:58.0875 4008 [ 74B2B2F5BEA5E9A3DC021D685551BD3D ] NetBT C:\WINDOWS\system32\DRIVERS\netbt.sys
18:36:58.0890 4008 NetBT - ok
18:36:58.0937 4008 [ B857BA82860D7FF85AE29B095645563B ] NetDDE C:\WINDOWS\system32\netdde.exe
18:36:58.0937 4008 NetDDE - ok
18:36:58.0968 4008 [ B857BA82860D7FF85AE29B095645563B ] NetDDEdsdm C:\WINDOWS\system32\netdde.exe
18:36:58.0968 4008 NetDDEdsdm - ok
18:36:59.0015 4008 [ BF2466B3E18E970D8A976FB95FC1CA85 ] Netlogon C:\WINDOWS\system32\lsass.exe
18:36:59.0015 4008 Netlogon - ok
18:36:59.0046 4008 [ 13E67B55B3ABD7BF3FE7AAE5A0F9A9DE ] Netman C:\WINDOWS\System32\netman.dll
18:36:59.0062 4008 Netman - ok
18:36:59.0093 4008 [ D34612C5D02D026535B3095D620626AE ] NetTcpPortSharing C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe
18:36:59.0109 4008 NetTcpPortSharing - ok
18:36:59.0140 4008 [ 943337D786A56729263071623BBB9DE5 ] Nla C:\WINDOWS\System32\mswsock.dll
18:36:59.0156 4008 Nla - ok
18:36:59.0187 4008 [ 431ADA51E9D032F533548688CE5A2A24 ] nosGetPlusHelper C:\Program Files\NOS\bin\getPlus_Helper_3004.dll
18:36:59.0203 4008 nosGetPlusHelper - ok
18:36:59.0234 4008 [ 3182D64AE053D6FB034F44B6DEF8034A ] Npfs C:\WINDOWS\system32\drivers\Npfs.sys
18:36:59.0234 4008 Npfs - ok
18:36:59.0312 4008 [ 78A08DD6A8D65E697C18E1DB01C5CDCA ] Ntfs C:\WINDOWS\system32\drivers\Ntfs.sys
18:36:59.0328 4008 Ntfs - ok
18:36:59.0359 4008 [ BF2466B3E18E970D8A976FB95FC1CA85 ] NtLmSsp C:\WINDOWS\System32\lsass.exe
18:36:59.0359 4008 NtLmSsp - ok
18:36:59.0437 4008 [ 156F64A3345BD23C600655FB4D10BC08 ] NtmsSvc C:\WINDOWS\system32\ntmssvc.dll
18:36:59.0468 4008 NtmsSvc - ok
18:36:59.0500 4008 [ 73C1E1F395918BC2C6DD67AF7591A3AD ] Null C:\WINDOWS\system32\drivers\Null.sys
18:36:59.0500 4008 Null - ok
18:36:59.0812 4008 [ 83780F3A86D2804912F22F6E37CD2254 ] nv C:\WINDOWS\system32\DRIVERS\nv4_mini.sys
18:37:00.0062 4008 nv - ok
18:37:00.0093 4008 [ 42321AC5448078131903B272E6C49024 ] NVSvc C:\WINDOWS\system32\nvsvc32.exe
18:37:00.0109 4008 NVSvc - ok
18:37:00.0140 4008 [ B305F3FAD35083837EF46A0BBCE2FC57 ] NwlnkFlt C:\WINDOWS\system32\DRIVERS\nwlnkflt.sys
18:37:00.0156 4008 NwlnkFlt - ok
18:37:00.0171 4008 [ C99B3415198D1AAB7227F2C88FD664B9 ] NwlnkFwd C:\WINDOWS\system32\DRIVERS\nwlnkfwd.sys
18:37:00.0171 4008 NwlnkFwd - ok
18:37:00.0218 4008 [ 5575FAF8F97CE5E713D108C2A58D7C7C ] Parport C:\WINDOWS\system32\DRIVERS\parport.sys
18:37:00.0218 4008 Parport - ok
18:37:00.0265 4008 [ BEB3BA25197665D82EC7065B724171C6 ] PartMgr C:\WINDOWS\system32\drivers\PartMgr.sys
18:37:00.0281 4008 PartMgr - ok
18:37:00.0312 4008 [ 70E98B3FD8E963A6A46A2E6247E0BEA1 ] ParVdm C:\WINDOWS\system32\drivers\ParVdm.sys
18:37:00.0328 4008 ParVdm - ok
18:37:00.0343 4008 [ A219903CCF74233761D92BEF471A07B1 ] PCI C:\WINDOWS\system32\DRIVERS\pci.sys
18:37:00.0343 4008 PCI - ok
18:37:00.0375 4008 PCIDump - ok
18:37:00.0406 4008 [ CCF5F451BB1A5A2A522A76E670000FF0 ] PCIIde C:\WINDOWS\system32\drivers\PCIIde.sys
18:37:00.0406 4008 PCIIde - ok
18:37:00.0453 4008 [ 9E89EF60E9EE05E3F2EEF2DA7397F1C1 ] Pcmcia C:\WINDOWS\system32\drivers\Pcmcia.sys
18:37:00.0453 4008 Pcmcia - ok
18:37:00.0468 4008 PDCOMP - ok
18:37:00.0500 4008 PDFRAME - ok
18:37:00.0515 4008 PDRELI - ok
18:37:00.0531 4008 PDRFRAME - ok
18:37:00.0562 4008 perc2 - ok
18:37:00.0578 4008 perc2hib - ok
18:37:00.0640 4008 PID_08A0 - ok
18:37:00.0687 4008 [ 65DF52F5B8B6E9BBD183505225C37315 ] PlugPlay C:\WINDOWS\system32\services.exe
18:37:00.0687 4008 PlugPlay - ok
18:37:00.0734 4008 [ 9D84376931440F3679BEEF2A414FA493 ] Pml Driver HPZ12 C:\WINDOWS\system32\HPZipm12.exe
18:37:00.0750 4008 Pml Driver HPZ12 - ok
18:37:00.0765 4008 [ BF2466B3E18E970D8A976FB95FC1CA85 ] PolicyAgent C:\WINDOWS\system32\lsass.exe
18:37:00.0765 4008 PolicyAgent - ok
18:37:00.0812 4008 [ EFEEC01B1D3CF84F16DDD24D9D9D8F99 ] PptpMiniport C:\WINDOWS\system32\DRIVERS\raspptp.sys
18:37:00.0812 4008 PptpMiniport - ok
18:37:00.0843 4008 [ A32BEBAF723557681BFC6BD93E98BD26 ] Processor C:\WINDOWS\system32\DRIVERS\processr.sys
18:37:00.0843 4008 Processor - ok
18:37:00.0890 4008 Profos - ok
18:37:00.0906 4008 [ BF2466B3E18E970D8A976FB95FC1CA85 ] ProtectedStorage C:\WINDOWS\system32\lsass.exe
18:37:00.0906 4008 ProtectedStorage - ok
18:37:00.0921 4008 [ 09298EC810B07E5D582CB3A3F9255424 ] PSched C:\WINDOWS\system32\DRIVERS\psched.sys
18:37:00.0937 4008 PSched - ok
18:37:00.0968 4008 [ 80D317BD1C3DBC5D4FE7B1678C60CADD ] Ptilink C:\WINDOWS\system32\DRIVERS\ptilink.sys
18:37:00.0968 4008 Ptilink - ok
18:37:00.0984 4008 ql1080 - ok
18:37:01.0000 4008 Ql10wnt - ok
18:37:01.0015 4008 ql12160 - ok
18:37:01.0046 4008 ql1240 - ok
18:37:01.0062 4008 ql1280 - ok
18:37:01.0078 4008 [ FE0D99D6F31E4FAD8159F690D68DED9C ] RasAcd C:\WINDOWS\system32\DRIVERS\rasacd.sys
18:37:01.0078 4008 RasAcd - ok
18:37:01.0125 4008 [ AD188BE7BDF94E8DF4CA0A55C00A5073 ] RasAuto C:\WINDOWS\System32\rasauto.dll
18:37:01.0140 4008 RasAuto - ok
18:37:01.0171 4008 [ 11B4A627BC9614B885C4969BFA5FF8A6 ] Rasl2tp C:\WINDOWS\system32\DRIVERS\rasl2tp.sys
18:37:01.0171 4008 Rasl2tp - ok
18:37:01.0218 4008 [ 76A9A3CBEADD68CC57CDA5E1D7448235 ] RasMan C:\WINDOWS\System32\rasmans.dll
18:37:01.0234 4008 RasMan - ok
18:37:01.0265 4008 [ 5BC962F2654137C9909C3D4603587DEE ] RasPppoe C:\WINDOWS\system32\DRIVERS\raspppoe.sys
18:37:01.0265 4008 RasPppoe - ok
18:37:01.0296 4008 [ FDBB1D60066FCFBB7452FD8F9829B242 ] Raspti C:\WINDOWS\system32\DRIVERS\raspti.sys
18:37:01.0296 4008 Raspti - ok
18:37:01.0312 4008 [ 7AD224AD1A1437FE28D89CF22B17780A ] Rdbss C:\WINDOWS\system32\DRIVERS\rdbss.sys
18:37:01.0328 4008 Rdbss - ok
18:37:01.0343 4008 [ 4912D5B403614CE99C28420F75353332 ] RDPCDD C:\WINDOWS\system32\DRIVERS\RDPCDD.sys
18:37:01.0359 4008 RDPCDD - ok
18:37:01.0406 4008 [ 15CABD0F7C00C47C70124907916AF3F1 ] rdpdr C:\WINDOWS\system32\DRIVERS\rdpdr.sys
18:37:01.0421 4008 rdpdr - ok
18:37:01.0484 4008 [ 43AF5212BD8FB5BA6EED9754358BD8F7 ] RDPWD C:\WINDOWS\system32\drivers\RDPWD.sys
18:37:01.0500 4008 RDPWD - ok
18:37:01.0546 4008 [ 3C37BF86641BDA977C3BF8A840F3B7FA ] RDSessMgr C:\WINDOWS\system32\sessmgr.exe
18:37:01.0546 4008 RDSessMgr - ok
18:37:01.0578 4008 [ F828DD7E1419B6653894A8F97A0094C5 ] redbook C:\WINDOWS\system32\DRIVERS\redbook.sys
18:37:01.0593 4008 redbook - ok
18:37:01.0640 4008 [ 7E699FF5F59B5D9DE5390E3C34C67CF5 ] RemoteAccess C:\WINDOWS\System32\mprdim.dll
18:37:01.0640 4008 RemoteAccess - ok
18:37:01.0687 4008 [ 5B19B557B0C188210A56A6B699D90B8F ] RemoteRegistry C:\WINDOWS\system32\regsvc.dll
18:37:01.0687 4008 RemoteRegistry - ok
18:37:01.0734 4008 [ AAED593F84AFA419BBAE8572AF87CF6A ] RpcLocator C:\WINDOWS\System32\locator.exe
18:37:01.0734 4008 RpcLocator - ok
18:37:01.0781 4008 [ 6B27A5C03DFB94B4245739065431322C ] RpcSs C:\WINDOWS\System32\rpcss.dll
18:37:01.0781 4008 RpcSs - ok
18:37:01.0843 4008 [ 471B3F9741D762ABE75E9DEEA4787E47 ] RSVP C:\WINDOWS\System32\rsvp.exe
18:37:01.0843 4008 RSVP - ok
18:37:01.0875 4008 [ BF2466B3E18E970D8A976FB95FC1CA85 ] SamSs C:\WINDOWS\system32\lsass.exe
18:37:01.0875 4008 SamSs - ok
18:37:01.0937 4008 [ 86D007E7A654B9A71D1D7D856B104353 ] SCardSvr C:\WINDOWS\System32\SCardSvr.exe
18:37:01.0937 4008 SCardSvr - ok
18:37:01.0984 4008 [ 0A9A7365A1CA4319AA7C1D6CD8E4EAFA ] Schedule C:\WINDOWS\system32\schedsvc.dll
18:37:02.0000 4008 Schedule - ok
18:37:02.0062 4008 [ 07F7F501AD50DE2BA2D5842D9B6D6155 ] Secdrv C:\WINDOWS\system32\DRIVERS\secdrv.sys
18:37:02.0062 4008 Secdrv - ok
18:37:02.0093 4008 [ CBE612E2BB6A10E3563336191EDA1250 ] seclogon C:\WINDOWS\System32\seclogon.dll
18:37:02.0093 4008 seclogon - ok
18:37:02.0125 4008 [ 7FDD5D0684ECA8C1F68B4D99D124DCD0 ] SENS C:\WINDOWS\system32\sens.dll
18:37:02.0125 4008 SENS - ok
18:37:02.0156 4008 [ 0F29512CCD6BEAD730039FB4BD2C85CE ] serenum C:\WINDOWS\system32\DRIVERS\serenum.sys
18:37:02.0156 4008 serenum - ok
18:37:02.0218 4008 [ CCA207A8896D4C6A0C9CE29A4AE411A7 ] Serial C:\WINDOWS\system32\DRIVERS\serial.sys
18:37:02.0218 4008 Serial - ok
18:37:02.0296 4008 [ 4C0D673281178CB496011A2E28571FC8 ] sfdrv01 C:\WINDOWS\system32\drivers\sfdrv01.sys
18:37:02.0296 4008 sfdrv01 - ok
18:37:02.0328 4008 [ 15BE2B5E4DC5B8623CF167720682ABC9 ] sfhlp02 C:\WINDOWS\system32\drivers\sfhlp02.sys
18:37:02.0328 4008 sfhlp02 - ok
18:37:02.0375 4008 [ 8E6B8C671615D126FDC553D1E2DE5562 ] Sfloppy C:\WINDOWS\system32\drivers\Sfloppy.sys
18:37:02.0390 4008 Sfloppy - ok
18:37:02.0437 4008 [ EFEBBC1D13FDB77A6AF4EDDFC7232EDF ] sfsync02 C:\WINDOWS\system32\drivers\sfsync02.sys
18:37:02.0437 4008 sfsync02 - ok
18:37:02.0500 4008 [ 83F41D0D89645D7235C051AB1D9523AC ] SharedAccess C:\WINDOWS\System32\ipnathlp.dll
18:37:02.0500 4008 SharedAccess - ok
18:37:02.0546 4008 [ 99BC0B50F511924348BE19C7C7313BBF ] ShellHWDetection C:\WINDOWS\System32\shsvcs.dll
18:37:02.0546 4008 ShellHWDetection - ok
18:37:02.0562 4008 Simbad - ok
18:37:02.0593 4008 [ 866D538EBE33709A5C9F5C62B73B7D14 ] SLIP C:\WINDOWS\system32\DRIVERS\SLIP.sys
18:37:02.0593 4008 SLIP - ok
18:37:02.0718 4008 [ FA3368A7039F5ABAA4B933703AC34763 ] smwdm C:\WINDOWS\system32\drivers\smwdm.sys
18:37:02.0750 4008 smwdm - ok
18:37:02.0812 4008 [ 3978F082274F723AD5A0A8058C2417DD ] SoundMAX Agent Service (default) C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
18:37:02.0812 4008 SoundMAX Agent Service (default) - ok
18:37:02.0828 4008 Sparrow - ok
18:37:02.0859 4008 [ AB8B92451ECB048A4D1DE7C3FFCB4A9F ] splitter C:\WINDOWS\system32\drivers\splitter.sys
18:37:02.0859 4008 splitter - ok
18:37:02.0906 4008 [ 60784F891563FB1B767F70117FC2428F ] Spooler C:\WINDOWS\system32\spoolsv.exe
18:37:02.0906 4008 Spooler - ok
18:37:02.0968 4008 [ 76BB022C2FB6902FD5BDD4F78FC13A5D ] sr C:\WINDOWS\system32\DRIVERS\sr.sys
18:37:02.0968 4008 sr - ok
18:37:03.0015 4008 [ 3805DF0AC4296A34BA4BF93B346CC378 ] srservice C:\WINDOWS\system32\srsvc.dll
18:37:03.0031 4008 srservice - ok
18:37:03.0093 4008 [ 47DDFC2F003F7F9F0592C6874962A2E7 ] Srv C:\WINDOWS\system32\DRIVERS\srv.sys
18:37:03.0093 4008 Srv - ok
18:37:03.0140 4008 [ 0A5679B3714EDAB99E357057EE88FCA6 ] SSDPSRV C:\WINDOWS\System32\ssdpsrv.dll
18:37:03.0140 4008 SSDPSRV - ok
18:37:03.0187 4008 [ A9573045BAA16EAB9B1085205B82F1ED ] StillCam C:\WINDOWS\system32\DRIVERS\serscan.sys
18:37:03.0187 4008 StillCam - ok
18:37:03.0234 4008 [ 8BAD69CBAC032D4BBACFCE0306174C30 ] stisvc C:\WINDOWS\system32\wiaservc.dll
18:37:03.0250 4008 stisvc - ok
18:37:03.0281 4008 [ 77813007BA6265C4B6098187E6ED79D2 ] streamip C:\WINDOWS\system32\DRIVERS\StreamIP.sys
18:37:03.0281 4008 streamip - ok
18:37:03.0328 4008 [ 3941D127AEF12E93ADDF6FE6EE027E0F ] swenum C:\WINDOWS\system32\DRIVERS\swenum.sys
18:37:03.0328 4008 swenum - ok
18:37:03.0359 4008 [ 8CE882BCC6CF8A62F2B2323D95CB3D01 ] swmidi C:\WINDOWS\system32\drivers\swmidi.sys
18:37:03.0375 4008 swmidi - ok
18:37:03.0390 4008 SwPrv - ok
18:37:03.0421 4008 symc810 - ok
18:37:03.0453 4008 symc8xx - ok
18:37:03.0468 4008 sym_hi - ok
18:37:03.0500 4008 sym_u3 - ok
18:37:03.0515 4008 [ 8B83F3ED0F1688B4958F77CD6D2BF290 ] sysaudio C:\WINDOWS\system32\drivers\sysaudio.sys
18:37:03.0515 4008 sysaudio - ok
18:37:03.0562 4008 [ C7ABBC59B43274B1109DF6B24D617051 ] SysmonLog C:\WINDOWS\system32\smlogsvc.exe
18:37:03.0578 4008 SysmonLog - ok
18:37:03.0625 4008 [ 3CB78C17BB664637787C9A1C98F79C38 ] TapiSrv C:\WINDOWS\System32\tapisrv.dll
18:37:03.0640 4008 TapiSrv - ok
18:37:03.0687 4008 [ 9AEFA14BD6B182D61E3119FA5F436D3D ] Tcpip C:\WINDOWS\system32\DRIVERS\tcpip.sys
18:37:03.0703 4008 Tcpip - ok
18:37:03.0765 4008 [ 6471A66807F5E104E4885F5B67349397 ] TDPIPE C:\WINDOWS\system32\drivers\TDPIPE.sys
18:37:03.0765 4008 TDPIPE - ok
18:37:03.0796 4008 [ C56B6D0402371CF3700EB322EF3AAF61 ] TDTCP C:\WINDOWS\system32\drivers\TDTCP.sys
18:37:03.0796 4008 TDTCP - ok
18:37:03.0828 4008 [ 88155247177638048422893737429D9E ] TermDD C:\WINDOWS\system32\DRIVERS\termdd.sys
18:37:03.0828 4008 TermDD - ok
18:37:03.0890 4008 [ FF3477C03BE7201C294C35F684B3479F ] TermService C:\WINDOWS\System32\termsrv.dll
18:37:03.0906 4008 TermService - ok
18:37:03.0953 4008 [ 99BC0B50F511924348BE19C7C7313BBF ] Themes C:\WINDOWS\System32\shsvcs.dll
18:37:03.0953 4008 Themes - ok
18:37:04.0000 4008 [ DB7205804759FF62C34E3EFD8A4CC76A ] TlntSvr C:\WINDOWS\System32\tlntsvr.exe
18:37:04.0015 4008 TlntSvr - ok
18:37:04.0031 4008 TosIde - ok
18:37:04.0062 4008 [ 55BCA12F7F523D35CA3CB833C725F54E ] TrkWks C:\WINDOWS\system32\trkwks.dll
18:37:04.0078 4008 TrkWks - ok
18:37:04.0093 4008 Trufos - ok
18:37:04.0125 4008 [ 5787B80C2E3C5E2F56C2A233D91FA2C9 ] Udfs C:\WINDOWS\system32\drivers\Udfs.sys
18:37:04.0140 4008 Udfs - ok
18:37:04.0140 4008 ultra - ok
18:37:04.0203 4008 [ 402DDC88356B1BAC0EE3DD1580C76A31 ] Update C:\WINDOWS\system32\DRIVERS\update.sys
18:37:04.0234 4008 Update - ok
18:37:04.0296 4008 [ 1EBAFEB9A3FBDC41B8D9C7F0F687AD91 ] upnphost C:\WINDOWS\System32\upnphost.dll
18:37:04.0296 4008 upnphost - ok
18:37:04.0328 4008 [ 05365FB38FCA1E98F7A566AAAF5D1815 ] UPS C:\WINDOWS\System32\ups.exe
18:37:04.0343 4008 UPS - ok
18:37:04.0390 4008 [ E919708DB44ED8543A7C017953148330 ] usbaudio C:\WINDOWS\system32\drivers\usbaudio.sys
18:37:04.0390 4008 usbaudio - ok
18:37:04.0421 4008 [ 173F317CE0DB8E21322E71B7E60A27E8 ] usbccgp C:\WINDOWS\system32\DRIVERS\usbccgp.sys
18:37:04.0421 4008 usbccgp - ok
18:37:04.0437 4008 [ 65DCF09D0E37D4C6B11B5B0B76D470A7 ] usbehci C:\WINDOWS\system32\DRIVERS\usbehci.sys
18:37:04.0453 4008 usbehci - ok
18:37:04.0468 4008 [ 1AB3CDDE553B6E064D2E754EFE20285C ] usbhub C:\WINDOWS\system32\DRIVERS\usbhub.sys
18:37:04.0468 4008 usbhub - ok
18:37:04.0500 4008 [ A717C8721046828520C9EDF31288FC00 ] usbprint C:\WINDOWS\system32\DRIVERS\usbprint.sys
18:37:04.0500 4008 usbprint - ok
18:37:04.0531 4008 [ A0B8CF9DEB1184FBDD20784A58FA75D4 ] usbscan C:\WINDOWS\system32\DRIVERS\usbscan.sys
18:37:04.0531 4008 usbscan - ok
18:37:04.0562 4008 [ A32426D9B14A089EAA1D922E0C5801A9 ] USBSTOR C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS
18:37:04.0562 4008 USBSTOR - ok
18:37:04.0593 4008 [ 26496F9DEE2D787FC3E61AD54821FFE6 ] usbuhci C:\WINDOWS\system32\DRIVERS\usbuhci.sys
18:37:04.0593 4008 usbuhci - ok
18:37:04.0609 4008 [ 0D3A8FAFCEACD8B7625CD549757A7DF1 ] VgaSave C:\WINDOWS\System32\drivers\vga.sys
18:37:04.0609 4008 VgaSave - ok
18:37:04.0625 4008 ViaIde - ok
18:37:04.0671 4008 [ 4C8FCB5CC53AAB716D810740FE59D025 ] VolSnap C:\WINDOWS\system32\drivers\VolSnap.sys
18:37:04.0671 4008 VolSnap - ok
18:37:04.0750 4008 [ 2B1B0DC0CC6A3B1D811834BD52BE05D8 ] Vsdatant C:\WINDOWS\system32\vsdatant.sys
18:37:04.0765 4008 Vsdatant - ok
18:37:04.0796 4008 vsmon - ok
18:37:04.0859 4008 [ 7A9DB3A67C333BF0BD42E42B8596854B ] VSS C:\WINDOWS\System32\vssvc.exe
18:37:04.0875 4008 VSS - ok
18:37:04.0921 4008 [ 54AF4B1D5459500EF0937F6D33B1914F ] W32Time C:\WINDOWS\system32\w32time.dll
18:37:04.0937 4008 W32Time - ok
18:37:04.0984 4008 [ E20B95BAEDB550F32DD489265C1DA1F6 ] Wanarp C:\WINDOWS\system32\DRIVERS\wanarp.sys
18:37:04.0984 4008 Wanarp - ok
18:37:05.0000 4008 WDICA - ok
18:37:05.0031 4008 [ 6768ACF64B18196494413695F0C3A00F ] wdmaud C:\WINDOWS\system32\drivers\wdmaud.sys
18:37:05.0031 4008 wdmaud - ok
18:37:05.0078 4008 [ 77A354E28153AD2D5E120A5A8687BC06 ] WebClient C:\WINDOWS\System32\webclnt.dll
18:37:05.0078 4008 WebClient - ok
18:37:05.0171 4008 [ 2D0E4ED081963804CCC196A0929275B5 ] winmgmt C:\WINDOWS\system32\wbem\WMIsvc.dll
18:37:05.0171 4008 winmgmt - ok
18:37:05.0250 4008 [ C51B4A5C05A5475708E3C81C7765B71D ] WmdmPmSN C:\WINDOWS\system32\MsPMSNSv.dll
18:37:05.0265 4008 WmdmPmSN - ok
18:37:05.0328 4008 [ E76F8807070ED04E7408A86D6D3A6137 ] Wmi C:\WINDOWS\System32\advapi32.dll
18:37:05.0343 4008 Wmi - ok
18:37:05.0406 4008 [ E0673F1106E62A68D2257E376079F821 ] WmiApSrv C:\WINDOWS\System32\wbem\wmiapsrv.exe
18:37:05.0421 4008 WmiApSrv - ok
18:37:05.0515 4008 [ F74E3D9A7FA9556C3BBB14D4E5E63D3B ] WMPNetworkSvc C:\Program Files\Windows Media Player\WMPNetwk.exe
18:37:05.0562 4008 WMPNetworkSvc - ok
18:37:05.0593 4008 [ 6ABE6E225ADB5A751622A9CC3BC19CE8 ] WS2IFSL C:\WINDOWS\System32\drivers\ws2ifsl.sys
18:37:05.0593 4008 WS2IFSL - ok
18:37:05.0640 4008 [ 7C278E6408D1DCE642230C0585A854D5 ] wscsvc C:\WINDOWS\system32\wscsvc.dll
18:37:05.0656 4008 wscsvc - ok
18:37:05.0671 4008 [ C98B39829C2BBD34E454150633C62C78 ] WSTCODEC C:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS
18:37:05.0687 4008 WSTCODEC - ok
18:37:05.0703 4008 [ 35321FB577CDC98CE3EB3A3EB9E4610A ] wuauserv C:\WINDOWS\system32\wuauserv.dll
18:37:05.0734 4008 wuauserv - ok
18:37:05.0765 4008 [ F15FEAFFFBB3644CCC80C5DA584E6311 ] WudfPf C:\WINDOWS\system32\DRIVERS\WudfPf.sys
18:37:05.0765 4008 WudfPf - ok
18:37:05.0812 4008 [ 28B524262BCE6DE1F7EF9F510BA3985B ] WudfRd C:\WINDOWS\system32\DRIVERS\wudfrd.sys
18:37:05.0812 4008 WudfRd - ok
18:37:05.0843 4008 [ 05231C04253C5BC30B26CBAAE680ED89 ] WudfSvc C:\WINDOWS\System32\WUDFSvc.dll
18:37:05.0859 4008 WudfSvc - ok
18:37:05.0906 4008 [ 81DC3F549F44B1C1FFF022DEC9ECF30B ] WZCSVC C:\WINDOWS\System32\wzcsvc.dll
18:37:05.0937 4008 WZCSVC - ok
18:37:06.0000 4008 [ 295D21F14C335B53CB8154E5B1F892B9 ] xmlprov C:\WINDOWS\System32\xmlprov.dll
18:37:06.0031 4008 xmlprov - ok
18:37:06.0078 4008 ================ Scan global ===============================
18:37:06.0109 4008 [ 42F1F4C0AFB08410E5F02D4B13EBB623 ] C:\WINDOWS\system32\basesrv.dll
18:37:06.0156 4008 [ 8C7DCA4B158BF16894120786A7A5F366 ] C:\WINDOWS\system32\winsrv.dll
18:37:06.0203 4008 [ 8C7DCA4B158BF16894120786A7A5F366 ] C:\WINDOWS\system32\winsrv.dll
18:37:06.0234 4008 [ 65DF52F5B8B6E9BBD183505225C37315 ] C:\WINDOWS\system32\services.exe
18:37:06.0234 4008 [Global] - ok
18:37:06.0250 4008 ================ Scan MBR ==================================
18:37:06.0265 4008 [ 8F558EB6672622401DA993E1E865C861 ] \Device\Harddisk0\DR0
18:37:06.0453 4008 \Device\Harddisk0\DR0 - ok
18:37:06.0453 4008 ================ Scan VBR ==================================
18:37:06.0468 4008 [ CC5950EFB1572741AC16C03C1E6BABD5 ] \Device\Harddisk0\DR0\Partition1
18:37:06.0484 4008 \Device\Harddisk0\DR0\Partition1 - ok
18:37:06.0484 4008 ============================================================
18:37:06.0484 4008 Scan finished
18:37:06.0484 4008 ============================================================
18:37:06.0515 4088 Detected object count: 0
18:37:06.0515 4088 Actual detected object count: 0
18:38:03.0968 3624 Deinitialize success






ComboFix 13-01-06.01 - user1 01/07/2013 21:24:09.5.1 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1279.908 [GMT -6:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
AV: ZoneAlarm Free Firewall Antivirus *Disabled/Updated* {5D467B10-818C-4CAB-9FF7-6893B5B8F3CF}
FW: ZoneAlarm Free Firewall Firewall *Disabled* {829BDA32-94B3-44F4-8446-F8FCFF809F8B}
.
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\documents and settings\All Users\Application Data\1pb78m8n6he1l1565b3k36w7o7of8ksb88y53s63tpqg0vl
c:\documents and settings\All Users\Application Data\TEMP
c:\documents and settings\user1\Templates\1pb78m8n6he1l1565b3k36w7o7of8ksb88y53s63tpqg0vl
c:\documents and settings\user1\WINDOWS
.
.
((((((((((((((((((((((((( Files Created from 2012-12-08 to 2013-01-08 )))))))))))))))))))))))))))))))
.
.
2013-01-05 16:21 . 2013-01-05 16:21 ——– d—–w- c:\documents and settings\user1\Downloads
2013-01-05 15:56 . 2013-01-05 15:56 ——– d—–w- c:\documents and settings\user1\Application Data\QuickScan
2013-01-05 15:49 . 2013-01-05 16:14 ——– d—–w- c:\program files\Panda Security
2012-12-20 01:06 . 2012-12-20 01:06 74703 —-a-w- c:\windows\system32\mfc45.dll
2012-12-20 01:06 . 2012-12-20 08:22 ——– d—–w- c:\documents and settings\All Users\Application Data\iolo
2012-12-20 01:02 . 2012-12-20 01:04 ——– d—–w- c:\documents and settings\user1\Application Data\#ISW.FS#
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-12-16 12:23 . 2003-03-31 14:00 290560 —-a-w- c:\windows\system32\atmfd.dll
2012-11-13 01:25 . 2003-03-31 14:00 1866368 —-a-w- c:\windows\system32\win32k.sys
2012-11-02 02:02 . 2003-03-31 14:00 375296 —-a-w- c:\windows\system32\dpnet.dll
2012-11-01 12:17 . 2003-03-31 14:00 916992 —-a-w- c:\windows\system32\wininet.dll
2012-11-01 12:17 . 2003-03-31 14:00 43520 —-a-w- c:\windows\system32\licmgr10.dll
2012-11-01 12:17 . 2003-03-31 14:00 1469440 ——w- c:\windows\system32\inetcpl.cpl
2012-11-01 00:35 . 2006-07-26 19:41 385024 —-a-w- c:\windows\system32\html.iec
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-10-07 13574144]
"nwiz"="nwiz.exe" [2008-10-07 1630208]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2009-11-11 417792]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2008-10-07 86016]
"ZoneAlarm"="c:\program files\CheckPoint\ZoneAlarm\zatray.exe" [2012-10-09 73392]
.
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"MaxRecentDocs"= 2 (0x2)
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
"FirewallOverride"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\ZoneLabsFirewall]
"DisableMonitoring"=dword:00000001
.
R1 kl2;kl2;c:\windows\system32\drivers\kl2.sys [11/26/2012 7:41 PM 11352]
R2 ISWKL;ZoneAlarm LTD Toolbar ISWKL;c:\program files\CheckPoint\ZAForceField\ISWKL.sys [8/30/2012 5:03 AM 27056]
R2 IswSvc;ZoneAlarm LTD Toolbar IswSvc;c:\program files\CheckPoint\ZAForceField\ISWSVC.exe [8/30/2012 5:03 AM 497320]
S3 ADM8511;ADMtek ADM8511/AN986 USB To Fast Ethernet Converter;c:\windows\system32\drivers\ADM8511.SYS [7/25/2006 3:40 PM 20160]
S3 MA8512M;MA8512M;c:\windows\system32\drivers\MA8512M.sys [8/3/2008 4:58 PM 25300]
S3 MA8512U;MA8512U;c:\windows\system32\drivers\MA8512U.sys [8/3/2008 4:58 PM 49106]
S3 MadgeTRN;Madge Token-Ring Adapter NDIS5 Driver;c:\windows\system32\drivers\mdgndis5.sys [7/28/2006 2:55 PM 164586]
S3 nosGetPlusHelper;getPlus® Helper 3004;c:\windows\System32\svchost.exe -k nosGetPlusHelper [3/31/2003 8:00 AM 14336]
.
— Other Services/Drivers In Memory —
.
*NewlyCreated* - 22164201
*Deregistered* - 22164201
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
getPlusHelper REG_MULTI_SZ getPlusHelper
nosGetPlusHelper REG_MULTI_SZ nosGetPlusHelper
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://yahoo.com/
uInternet Connection Wizard,ShellNext = iexplore
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
.
- - - - ORPHANS REMOVED - - - -
.
HKLM-Run-ISW - (no file)
Notify-AtiExtEvent - (no file)
AddRemove-Zombie Bowl-O-Rama - h:\zombie bowl-o-rama\MumboJumbo\Zombie Bowl-O-Rama\uninstall.exe
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2013-01-07 21:35
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes …
.
scanning hidden autostart entries …
.
scanning hidden files …
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————
.
[HKEY_USERS\S-1-5-21-839522115-2146812355-725345543-1003\Software\Microsoft\SystemCertificates\AddressBook*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
.
——————— DLLs Loaded Under Running Processes ———————
.
- - - - - - - > 'winlogon.exe'(712)
c:\program files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll
.
- - - - - - - > 'lsass.exe'(772)
c:\program files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll
.
Completion time: 2013-01-07 21:40:05
ComboFix-quarantined-files.txt 2013-01-08 03:40
.
Pre-Run: 1,798,922,240 bytes free
Post-Run: 3,588,726,784 bytes free
.
- - End Of File - - 59EC0B25CB9FED5EAB0FBC5D218DA509
Download RogueKiller and save it on your Desktop.
  • Quit all programs.
  • Start RogueKiller.exe. For Vista or Windows 7, right-click on the program, select Run as Administrator to start, then when prompted, press Allow to run.
  • Wait until Pre-scan has finished.
  • Click on Scan.
  • Wait for the scan to complete.
  • When the scan completes, close the program.
  • The report has been created on the Desktop.
  • Please post the contents of the RKreport.txt file located on your Desktop.
rogue killer results

ogueKiller V8.4.3 [Jan 8 2013] by Tigzy
mail : tigzyRKgmailcom
Feedback : http://www.geekstogo.com/forum/files/file/413-roguekiller/
Website : http://tigzy.geekstogo.com/roguekiller.php
Blog : http://tigzyrk.blogspot.com/

Operating System : Windows XP (5.1.2600 Service Pack 3) 32 bits version
Started in : Normal mode
User : user1 [Admin rights]
Mode : Scan – Date : 01/09/2013 21:09:49

¤¤¤ Bad processes : 0 ¤¤¤

¤¤¤ Registry Entries : 2 ¤¤¤
[HJPOL] HKLM\[…]\System : DisableRegistryTools (0) -> FOUND
[HJ DESK] HKLM\[…]\NewStartPanel : {20D04FE0-3AEA-1069-A2D8-08002B30309D} (1) -> FOUND

¤¤¤ Particular Files / Folders: ¤¤¤

¤¤¤ Driver : [LOADED] ¤¤¤
IRP[IRP_MJ_INTERNAL_DEVICE_CONTROL] : atapi.sys -> HOOKED ([MAJOR] sfsync02.sys @ 0xF76188B4)

¤¤¤ HOSTS File: ¤¤¤
–> C:\WINDOWS\system32\drivers\etc\hosts

127.0.0.1 localhost


¤¤¤ MBR Check: ¤¤¤

+++++ PhysicalDrive0: ST320011A +++++
— User —
[MBR] 92176bc272b58027e0157b3103e79463
[BSP] f6d0cc87b240da46b1bd9f157f49f69f : Windows XP MBR Code
Partition table:
0 - [ACTIVE] NTFS (0x07) [VISIBLE] Offset (sectors): 63 | Size: 19084 Mo
User = LL1 … OK!
User = LL2 … OK!

+++++ PhysicalDrive1: STECH Simple Drive USB Device +++++
— User —
[MBR] 89473feb4b5862e6e2830a8f39781cc5
[BSP] f81a9ad84e4d9d6f1a1d261e3c4987aa : Windows XP MBR Code
Partition table:
0 - [XXXXXX] NTFS (0x07) [VISIBLE] Offset (sectors): 63 | Size: 953867 Mo
User = LL1 … OK!
Error reading LL2 MBR!

Finished : << RKreport[1]_S_01092013_02d2109.txt >>
RKreport[1]_S_01092013_02d2109.txt
Please download AdwCleaner from here and save it to your desktop.
  • Right click on AdwCleaner.exe and click "Run as Administrator" to run the tool.
  • Click on Delete.
A logfile will automatically open after the scan has finished.

Please post the content of that logfile in your reply.

You can find the logfile at C:\AdwCleaner[Rn].txt as well - (n is the scan number.)










Please download Malwarebytes Free from Here or Here

  • Double-click mbam-setup.exe and follow the prompts to install the program.
  • At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select Perform quick scan, then click Scan.
    [external image: Posted Image]
  • When the scan is complete, click OK, then Show Results to view the results.
  • Be sure that everything is checked, and click Remove Selected .
  • When completed, a log will open in Notepad. Please save it to a convenient location and post the results.
  • Note: If you receive a notice that some of the items couldn't be removed, that they have been added to the delete on reboot list, please reboot.
Post the log please
















Next

ESET Online Scanner
I'd like us to scan your machine with ESET Online Scan

Note: It is recommended to disable on-board anti-virus program and anti-spyware programs while performing scans so there are no conflicts and it will speed up scan time.
Please don't go surfing while your resident protection is disabled!
Once the scan is finished remember to re-enable your anti-virus along with your anti-spyware programs.



  • Hold down Control and click on the following link to open ESET OnlineScan in a new window.
    ESET OnlineScan
  • Click the [external image: Posted Image] button.
  • For alternate browsers only: (Microsoft Internet Explorer users can skip these steps)
    • Click on [external image: Posted Image] to download the ESET Smart Installer. Save it to your desktop.
    • Double click on the [external image: Posted Image] icon on your desktop.
  • Check [external image: Posted Image]
  • Click the Start button.
  • Accept any security warnings from your browser.
  • Check [external image: Posted Image]
  • Make sure that the option "Remove found threats" is not checked
  • Push the Start button.
  • ESET will then download updates for itself, install itself, and begin
    scanning your computer. Please be patient as this can take some time.
  • When the scan completes, push [external image: Posted Image]
  • Push [external image: Posted Image], and save the file to your desktop using a unique name, such as
    ESETScan. Include the contents of this report in your next reply.
  • Push the Back button.
  • Push Finish
http://www.eset.com/onlinescan/




Also tell me how the computer is running now.
Mowman, eset online scan states no threats found. My computer keeps rebooting on its own, and the zone alarm antivirus isnt working at all. Can i remove zonealarm? and use something else? Are there any programs that I can remove from my computer? I also keep getting a microsoft whas encountered a problem and needs to shut down. adwcleaner abd malwarebytes results below, Malwarebytes Anti-Malware 1.70.0.1100 www.malwarebytes.org Database version: v2012.12.14.11 Windows XP Service Pack 3 x86 NTFS Internet Explorer 8.0.6001.18702 user1 :: COMPAQ-033HB3B9 [administrator] 1/13/2013 4:24:49 PM mbam-log-2013-01-13 (16-24-49).txt Scan type: Quick scan Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM | P2P Scan options disabled: Objects scanned: 187878 Time elapsed: 4 minute(s), 31 second(s) Memory Processes Detected: 0 (No malicious items detected) Memory Modules Detected: 0 (No malicious items detected) Registry Keys Detected: 0 (No malicious items detected) Registry Values Detected: 0 (No malicious items detected) Registry Data Items Detected: 0 (No malicious items detected) Folders Detected: 0 (No malicious items detected) Files Detected: 0 (No malicious items detected) (end) # AdwCleaner v2.105 - Logfile created 01/13/2013 at 16:36:56 # Updated 08/01/2013 by Xplode # Operating system : Microsoft Windows XP Service Pack 3 (32 bits) # User : user1 - COMPAQ-033HB3B9 # Boot Mode : Normal # Running from : C:\Documents and Settings\user1\Desktop\adwcleaner.exe # Option [Search] ***** [Services] ***** ***** [Files / Folders] ***** ***** [Registry] ***** ***** [Internet Browsers] ***** -\\ Internet Explorer v8.0.6001.18702 [OK] Registry is clean. ************************* AdwCleaner[R1].txt - [1085 octets] - [13/01/2013 15:51:41] AdwCleaner[R2].txt - [597 octets] - [13/01/2013 16:36:56] AdwCleaner[S2].txt - [999 octets] - [13/01/2013 15:53:14] ########## EOF - C:\AdwCleaner[R2].txt - [715 octets] ##########
Yes you can remove zonealarm and try something else, i use Avira free, if you install this run a full scan and remove anything it finds. http://www.avira.com/en/avira-free-antivirus



Run OTL.exe
  • Copy/paste the following text written inside of the code box into the Custom Scans/Fixes box located at the bottom of OTL

    :Services
    
    :Otl
    [2012/12/23 06:03:46 | 000,002,048 | -HS- | M] () – C:\RECYCLER\S-1-5-18\$3bee44a7a72cc4f4b79e244279d08397\@
    [2012/12/23 06:03:46 | 000,000,000 | -HSD | M] – C:\RECYCLER\S-1-5-18\$3bee44a7a72cc4f4b79e244279d08397\L
    [2012/12/23 06:03:46 | 000,000,000 | -HSD | M] – C:\RECYCLER\S-1-5-18\$3bee44a7a72cc4f4b79e244279d08397\U
    @Alternate Data Stream - 156 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:90D89144
    
    :Commands
    [emptytemp]
    [Reboot]
  • Then click the Run Fix button at the top
  • Let the program run unhindered, reboot when it is done
  • Then post a new OTL log ( don't check the boxes beside LOP Check or Purity this time )







  • Download aswMBR.exe ( 511KB ) to your desktop.
  • Double click the aswMBR.exe to run it
  • Click the Scan button to start scan
  • On completion of the scan click Save Log, save it to your Desktop and post in your next reply
Here's the latest scan results



aswMBR version 0.9.9.1707 Copyright© 2011 AVAST Software
Run date: 2013-01-13 21:30:51
—————————–
21:30:51.875 OS Version: Windows 5.1.2600 Service Pack 3
21:30:51.875 Number of processors: 1 586 0x204
21:30:51.875 ComputerName: COMPAQ-033HB3B9 UserName: user1
21:30:52.687 Initialize success
21:31:12.921 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-3
21:31:12.921 Disk 0 Vendor: ST320011A 3.10 Size: 19092MB BusType: 3
21:31:12.953 Disk 0 MBR read successfully
21:31:12.953 Disk 0 MBR scan
21:31:12.953 Disk 0 Windows XP default MBR code
21:31:12.953 Disk 0 Partition 1 80 (A) 07 HPFS/NTFS NTFS 19084 MB offset 63
21:31:12.953 Disk 0 scanning sectors +39085200
21:31:13.000 Disk 0 scanning C:\WINDOWS\system32\drivers
21:31:19.312 Service scanning
21:31:30.328 Modules scanning
21:31:36.562 Disk 0 trace - called modules:
21:31:36.578 ntoskrnl.exe CLASSPNP.SYS disk.sys ACPI.sys hal.dll sfsync02.sys atapi.sys intelide.sys PCIIDEX.SYS
21:31:36.593 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x8a119ab8]
21:31:36.593 3 CLASSPNP.SYS[f7647fd7] -> nt!IofCallDriver -> \Device\0000005d[0x8a1ecf18]
21:31:37.093 5 ACPI.sys[f75ae620] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP0T0L0-3[0x8a228d98]
21:31:37.093 \Driver\atapi[0x8a11d760] -> IRP_MJ_INTERNAL_DEVICE_CONTROL -> sfsync02.sys[0xf76188b4]
21:31:37.093 Scan finished successfully
21:31:51.609 Disk 0 MBR has been saved successfully to "C:\Documents and Settings\user1\Desktop\MBR.dat"
21:31:51.609 The log file has been saved successfully to "C:\Documents and Settings\user1\Desktop\aswMBR.txt"


OTL logfile created on: 1/13/2013 9:17:19 PM - Run 5
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Documents and Settings\user1\My Documents
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

1.25 Gb Total Physical Memory | 0.80 Gb Available Physical Memory | 64.36% Memory free
1.84 Gb Paging File | 1.60 Gb Available in Paging File | 86.99% Paging File free
Paging file location(s): C:\pagefile.sys 756 1512 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 18.64 Gb Total Space | 2.22 Gb Free Space | 11.90% Space Free | Partition Type: NTFS

Computer Name: COMPAQ-033HB3B9 | User Name: user1 | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - [2013/01/05 10:57:02 | 000,602,112 | —- | M] (OldTimer Tools) – C:\Documents and Settings\user1\My Documents\OTL.exe
PRC - [2008/04/13 18:12:19 | 001,033,728 | —- | M] (Microsoft Corporation) – C:\WINDOWS\explorer.exe
PRC - [2007/04/02 14:15:40 | 000,061,440 | —- | M] (Creative Technology Ltd) – C:\Program Files\Creative\Shared Files\CTDevSrv.exe
PRC - [2004/09/29 11:14:36 | 000,069,632 | —- | M] (HP) – C:\WINDOWS\system32\HPZipm12.exe
PRC - [2002/09/20 15:50:10 | 000,045,056 | —- | M] (Analog Devices, Inc.) – C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe


========== Modules (No Company Name) ==========

MOD - [2008/10/06 23:33:00 | 001,486,848 | —- | M] () – C:\WINDOWS\system32\nview.dll
MOD - [2008/10/06 23:33:00 | 000,466,944 | —- | M] () – C:\WINDOWS\system32\nvshell.dll
MOD - [2006/01/18 22:33:38 | 000,078,336 | —- | M] () – C:\WINDOWS\system32\spool\prtprocs\w32x86\LXCZPP5C.DLL


========== Services (SafeList) ==========

SRV - File not found [On_Demand | Stopped] – C:\Program Files\Google\Update\GoogleUpdate.exe /medsvc – (gupdatem)
SRV - File not found [Auto | Stopped] – C:\Program Files\Google\Update\GoogleUpdate.exe /svc – (gupdate)
SRV - [2010/11/29 10:41:26 | 000,058,944 | —- | M] (NOS Microsystems Ltd.) [On_Demand | Stopped] – C:\Program Files\NOS\bin\getPlus_Helper_3004.dll – (nosGetPlusHelper)
SRV - [2010/03/29 07:51:54 | 000,068,000 | —- | M] (NOS Microsystems Ltd.) [On_Demand | Stopped] – C:\Program Files\NOS\bin\getPlus_Helper.dll – (getPlusHelper)
SRV - [2007/04/02 14:15:40 | 000,061,440 | —- | M] (Creative Technology Ltd) [Auto | Running] – C:\Program Files\Creative\Shared Files\CTDevSrv.exe – (CTDevice_Srv)
SRV - [2004/09/29 11:14:36 | 000,069,632 | —- | M] (HP) [Auto | Running] – C:\WINDOWS\system32\HPZipm12.exe – (Pml Driver HPZ12)
SRV - [2002/09/20 15:50:10 | 000,045,056 | —- | M] (Analog Devices, Inc.) [Auto | Running] – C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe – (SoundMAX Agent Service (default)


========== Driver Services (SafeList) ==========

DRV - File not found [Kernel | On_Demand | Stopped] – – (WDICA)
DRV - File not found [Kernel | On_Demand | Stopped] – C:\Program Files\Common Files\BitDefender\BitDefender Threat Scanner\trufos.sys – (Trufos)
DRV - File not found [Kernel | On_Demand | Stopped] – C:\Program Files\Common Files\BitDefender\BitDefender Threat Scanner\profos.sys – (Profos)
DRV - File not found [Kernel | On_Demand | Stopped] – system32\DRIVERS\LV302AV.SYS – (PID_08A0)
DRV - File not found [Kernel | On_Demand | Stopped] – – (PDRFRAME)
DRV - File not found [Kernel | On_Demand | Stopped] – – (PDRELI)
DRV - File not found [Kernel | On_Demand | Stopped] – – (PDFRAME)
DRV - File not found [Kernel | On_Demand | Stopped] – – (PDCOMP)
DRV - File not found [Kernel | System | Stopped] – – (PCIDump)
DRV - File not found [Kernel | System | Stopped] – – (lbrtfdc)
DRV - File not found [Kernel | System | Stopped] – – (i2omgmt)
DRV - File not found [Kernel | On_Demand | Stopped] – C:\DOCUME~1\user1\LOCALS~1\Temp\ddxgb.sys – (ddxgb)
DRV - File not found [Kernel | System | Stopped] – – (Changer)
DRV - File not found [Kernel | On_Demand | Stopped] – C:\DOCUME~1\user1\LOCALS~1\Temp\catchme.sys – (catchme)
DRV - [2005/08/17 21:44:50 | 000,049,867 | R— | M] (Mobile Action Technology Inc.) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\mardp2k.sys – (MaRdPnp)
DRV - [2005/08/17 21:44:44 | 000,011,473 | R— | M] (Mobile Action Technology Inc.) [Kernel | Auto | Running] – C:\WINDOWS\system32\drivers\MaVc2K.sys – (MaVctrl)
DRV - [2005/08/10 08:06:28 | 000,019,968 | —- | M] (Protection Technology) [Kernel | Boot | Running] – C:\WINDOWS\system32\drivers\sfsync02.sys – (sfsync02)
DRV - [2005/08/10 06:44:04 | 000,050,688 | —- | M] (Protection Technology) [Kernel | Boot | Running] – C:\WINDOWS\system32\drivers\sfdrv01.sys – (sfdrv01)
DRV - [2005/05/27 03:31:28 | 000,022,016 | R— | M] (Logitech Inc.) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\LVUSBSta.sys – (LVUSBSta)
DRV - [2005/05/16 07:20:39 | 000,006,656 | —- | M] (Protection Technology) [Kernel | Boot | Running] – C:\WINDOWS\system32\drivers\sfhlp02.sys – (sfhlp02)
DRV - [2004/09/16 03:11:02 | 000,025,300 | R— | M] (Mobile Action Technology Inc.) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\MA8512M.sys – (MA8512M)
DRV - [2004/09/16 03:11:00 | 000,049,106 | R— | M] (Mobile Action Technology Inc.) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\MA8512U.sys – (MA8512U)
DRV - [2001/08/17 11:12:26 | 000,164,586 | —- | M] (Madge Networks Ltd) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\mdgndis5.sys – (MadgeTRN)
DRV - [2001/08/17 11:11:18 | 000,020,160 | —- | M] (ADMtek Incorporated) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\ADM8511.SYS – (ADM8511)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie
IE - HKLM\..\SearchScopes,DefaultScope =
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://search.live.com/results.aspx?q={sea…ferrer:source?}

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://yahoo.com/
IE - HKCU\..\SearchScopes,DefaultScope = {E619C875-313B-4010-A055-5CFFF1585A43}
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKCU\..\SearchScopes\{E619C875-313B-4010-A055-5CFFF1585A43}: "URL" = http://search.zonealarm.com/search?Source=…erms}&r=687
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0


========== FireFox ==========

FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\WINDOWS\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@checkpoint.com/FFApi: C:\Program Files\CheckPoint\ZAForceField\TrustChecker\bin\npFFApi.dll File not found
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\5.1.10411.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@nosltd.com/getPlus+®,version=1.6.2.97: C:\Program Files\NOS\bin\np_gp.dll (NOS Microsystems Ltd.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.123\npGoogleUpdate3.dll File not found
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.123\npGoogleUpdate3.dll File not found
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)


[2009/08/13 14:52:32 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\user1\Application Data\Mozilla\Extensions
[2009/08/13 14:52:32 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\user1\Application Data\Mozilla\Extensions\[removed]

O1 HOSTS File: ([2013/01/11 22:43:59 | 000,000,019 | —- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (Java™ Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {EE2AC4E5-B0B0-4EC6-88A9-BCA1A32AB107} - No CLSID value found.
O4 - HKLM..\Run: [NvCplDaemon] C:\WINDOWS\System32\NvCpl.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [NvMediaCenter] C:\WINDOWS\System32\NvMcTray.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [nwiz] C:\WINDOWS\System32\nwiz.exe ()
O4 - HKLM..\Run: [ZoneAlarm Installer] "C:\Program Files\CheckPoint\Install\Launcher.exe" "C:\Program Files\CheckPoint\Install\Install.exe" /r /c "C:\Program Files\CheckPoint\Install\Install.xml" File not found
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: MaxRecentDocs = 2
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://download.macromedia.com/pub/shockwa…director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://go.microsoft.com/fwlink/?linkid=39204 (Windows Genuine Advantage Validation Tool)
O16 - DPF: {4B54A9DE-EF1C-4EBE-A328-7C28EA3B433A} http://quickscan.bitdefender.com/qsax/qsax.cab (Bitdefender QuickScan Control)
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} http://download.bitdefender.com/resources/scan8/oscan8.cab (Reg Error: Key error.)
O16 - DPF: {6C269571-C6D7-4818-BCA4-32A035E8C884} http://www.creative.com/softwareupdate/su/…101/CTSUEng.cab (Reg Error: Key error.)
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} http://download.eset.com/special/eos/OnlineScanner.cab (OnlineScanner Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_30)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get/flash…r/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0030-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_30)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_30)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload.macromedia.com/get/flash…ent/swflash.cab (Shockwave Flash Object)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (get_atlcom Class)
O16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} http://www.creative.com/softwareupdate/su/…15106/CTPID.cab (Reg Error: Key error.)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) - C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O20 - Winlogon\Notify\igfxcui: DllName - (igfxsrvc.dll) - C:\WINDOWS\System32\igfxsrvc.dll (Intel Corporation)
O24 - Desktop WallPaper: C:\Documents and Settings\user1\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\user1\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006/07/25 12:11:17 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = ComFile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)

========== Files/Folders - Created Within 30 Days ==========

[2013/01/13 20:37:05 | 004,732,416 | —- | C] (AVAST Software) – C:\Documents and Settings\user1\Desktop\aswMBR.exe
[2013/01/13 15:37:27 | 010,156,344 | —- | C] (Malwarebytes Corporation ) – C:\Documents and Settings\user1\Desktop\mbam-setup-1.70.0.1100.exe
[2013/01/09 18:45:42 | 000,000,000 | —D | C] – C:\Documents and Settings\user1\Desktop\RK_Quarantine
[2013/01/08 18:38:36 | 000,000,000 | -HSD | C] – C:\RECYCLER
[2013/01/07 21:18:27 | 000,518,144 | —- | C] (SteelWerX) – C:\WINDOWS\SWREG.exe
[2013/01/07 21:18:27 | 000,406,528 | —- | C] (SteelWerX) – C:\WINDOWS\SWSC.exe
[2013/01/07 21:18:27 | 000,212,480 | —- | C] (SteelWerX) – C:\WINDOWS\SWXCACLS.exe
[2013/01/07 21:18:27 | 000,060,416 | —- | C] (NirSoft) – C:\WINDOWS\NIRCMD.exe
[2013/01/07 21:17:12 | 005,019,184 | R— | C] (Swearware) – C:\Documents and Settings\user1\Desktop\ComboFix.exe
[2013/01/07 21:11:03 | 000,000,000 | —D | C] – C:\Qoobox
[2013/01/05 11:45:20 | 000,000,000 | R–D | C] – C:\Documents and Settings\All Users\Documents\My Videos
[2013/01/05 11:45:20 | 000,000,000 | R–D | C] – C:\Documents and Settings\All Users\Documents\My Pictures
[2013/01/05 10:58:49 | 000,050,688 | —- | C] (Atribune.org) – C:\Documents and Settings\user1\My Documents\ATF_Cleaner.exe
[2013/01/05 10:56:58 | 000,602,112 | —- | C] (OldTimer Tools) – C:\Documents and Settings\user1\My Documents\OTL.exe
[2013/01/05 10:56:32 | 000,688,992 | R— | C] (Swearware) – C:\Documents and Settings\user1\My Documents\dds.scr
[2013/01/05 10:21:37 | 000,000,000 | —D | C] – C:\Documents and Settings\user1\Downloads
[2013/01/05 09:56:17 | 000,000,000 | —D | C] – C:\Documents and Settings\user1\Application Data\QuickScan
[2013/01/05 09:49:39 | 000,000,000 | —D | C] – C:\Program Files\Panda Security
[2012/12/20 02:21:57 | 000,000,000 | RH-D | C] – C:\Documents and Settings\user1\Recent
[2012/12/19 19:06:24 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\iolo
[2 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2013/01/13 21:13:55 | 000,001,881 | —- | M] () – C:\Documents and Settings\user1\Desktop\Resume ZoneAlarm Security Install.lnk
[2013/01/13 20:37:05 | 004,732,416 | —- | M] (AVAST Software) – C:\Documents and Settings\user1\Desktop\aswMBR.exe
[2013/01/13 20:35:23 | 105,603,488 | —- | M] () – C:\Documents and Settings\user1\Desktop\avira_free_antivirus_en.exe
[2013/01/13 16:06:43 | 000,201,151 | —- | M] () – C:\WINDOWS\System32\nvapps.xml
[2013/01/13 16:06:28 | 000,001,374 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2013/01/13 16:05:55 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2013/01/13 16:04:32 | 000,000,784 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes Anti-Malware.lnk
[2013/01/13 15:38:12 | 010,156,344 | —- | M] (Malwarebytes Corporation ) – C:\Documents and Settings\user1\Desktop\mbam-setup-1.70.0.1100.exe
[2013/01/13 15:36:09 | 000,554,087 | —- | M] () – C:\Documents and Settings\user1\Desktop\adwcleaner.exe
[2013/01/13 15:29:23 | 000,000,000 | —- | M] () – C:\WINDOWS\MEMORY.DMP
[2013/01/11 22:43:59 | 000,000,019 | —- | M] () – C:\WINDOWS\System32\drivers\etc\hosts
[2013/01/09 18:30:43 | 000,764,416 | —- | M] () – C:\Documents and Settings\user1\Desktop\RogueKiller.exe
[2013/01/07 21:17:12 | 005,019,184 | R— | M] (Swearware) – C:\Documents and Settings\user1\Desktop\ComboFix.exe
[2013/01/07 20:59:47 | 002,213,976 | —- | M] (Kaspersky Lab ZAO) – C:\Documents and Settings\user1\Desktop\TDSSKiller.exe
[2013/01/07 20:43:33 | 002,195,061 | —- | M] () – C:\Documents and Settings\user1\Desktop\tdsskiller.zip
[2013/01/05 10:58:49 | 000,050,688 | —- | M] (Atribune.org) – C:\Documents and Settings\user1\My Documents\ATF_Cleaner.exe
[2013/01/05 10:57:02 | 000,602,112 | —- | M] (OldTimer Tools) – C:\Documents and Settings\user1\My Documents\OTL.exe
[2013/01/05 10:56:33 | 000,688,992 | R— | M] (Swearware) – C:\Documents and Settings\user1\My Documents\dds.scr
[2013/01/05 10:41:55 | 000,224,120 | —- | M] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2012/12/23 06:04:02 | 000,001,520 | -HS- | M] () – C:\Documents and Settings\user1\Local Settings\Application Data\1pb78m8n6he1l1565b3k36w7o7of8ksb88y53s63tpqg0vl
[2012/12/19 19:06:38 | 000,074,703 | —- | M] () – C:\WINDOWS\System32\mfc45.dll
[2012/12/16 06:23:59 | 000,290,560 | —- | M] (Adobe Systems Incorporated) – C:\WINDOWS\System32\dllcache\atmfd.dll
[2012/12/16 06:23:59 | 000,290,560 | —- | M] (Adobe Systems Incorporated) – C:\WINDOWS\System32\atmfd.dll
[2 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]

========== Files Created - No Company Name ==========

[2013/01/13 21:13:55 | 000,001,881 | —- | C] () – C:\Documents and Settings\user1\Desktop\Resume ZoneAlarm Security Install.lnk
[2013/01/13 20:35:15 | 105,603,488 | —- | C] () – C:\Documents and Settings\user1\Desktop\avira_free_antivirus_en.exe
[2013/01/13 15:36:07 | 000,554,087 | —- | C] () – C:\Documents and Settings\user1\Desktop\adwcleaner.exe
[2013/01/09 18:30:38 | 000,764,416 | —- | C] () – C:\Documents and Settings\user1\Desktop\RogueKiller.exe
[2013/01/07 21:18:27 | 000,256,000 | —- | C] () – C:\WINDOWS\PEV.exe
[2013/01/07 21:18:27 | 000,208,896 | —- | C] () – C:\WINDOWS\MBR.exe
[2013/01/07 21:18:27 | 000,098,816 | —- | C] () – C:\WINDOWS\sed.exe
[2013/01/07 21:18:27 | 000,080,412 | —- | C] () – C:\WINDOWS\grep.exe
[2013/01/07 21:18:27 | 000,068,096 | —- | C] () – C:\WINDOWS\zip.exe
[2013/01/07 20:43:33 | 002,195,061 | —- | C] () – C:\Documents and Settings\user1\Desktop\tdsskiller.zip
[2012/12/23 06:04:01 | 000,001,520 | -HS- | C] () – C:\Documents and Settings\user1\Local Settings\Application Data\1pb78m8n6he1l1565b3k36w7o7of8ksb88y53s63tpqg0vl
[2012/12/19 19:06:38 | 000,074,703 | —- | C] () – C:\WINDOWS\System32\mfc45.dll
[2012/11/19 11:41:49 | 000,000,552 | —- | C] () – C:\WINDOWS\System32\d3d8caps.dat
[2012/11/19 11:28:34 | 000,000,664 | —- | C] () – C:\WINDOWS\System32\d3d9caps.dat
[2012/05/13 23:29:25 | 000,000,397 | —- | C] () – C:\WINDOWS\CODUO.ini
[2012/05/13 23:06:43 | 000,000,766 | —- | C] () – C:\WINDOWS\COD.INI
[2012/05/13 22:40:29 | 000,000,263 | —- | C] () – C:\WINDOWS\game.ini
[2012/02/19 23:03:58 | 000,003,072 | —- | C] () – C:\WINDOWS\System32\iacenc.dll
[2012/01/08 21:29:05 | 000,000,376 | —- | C] () – C:\WINDOWS\ODBC.INI
[2011/07/31 18:45:42 | 000,000,000 | —- | C] () – C:\WINDOWS\nsreg.dat
[2011/04/01 10:13:54 | 000,043,520 | —- | C] () – C:\WINDOWS\System32\CmdLineExt03.dll
[2011/03/31 20:21:16 | 000,000,000 | —- | C] () – C:\WINDOWS\PowerReg.dat
[2010/10/10 19:51:26 | 000,000,036 | —- | C] () – C:\Documents and Settings\user1\Local Settings\Application Data\housecall.guid.cache
[2006/09/12 13:21:38 | 000,056,832 | —- | C] () – C:\Documents and Settings\user1\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini

========== ZeroAccess Check ==========

[2009/04/10 16:52:07 | 000,000,227 | RHS- | M] () – C:\WINDOWS\assembly\Desktop.ini

[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]

[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shdocvw.dll – [2009/12/21 23:21:02 | 001,509,888 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll – [2009/02/09 06:10:48 | 000,473,600 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
"" = %systemroot%\system32\wbem\wbemess.dll – [2008/04/13 18:12:08 | 000,273,920 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Both

========== Custom Scans ==========

< :Services >

< >

< :Otl >

< [2012/12/23 06:03:46 | 000,002,048 | -HS- | M] () – C:\RECYCLER\S-1-5-18\$3bee44a7a72cc4f4b79e244279d08397\@ >
Invalid Switch: 23 06:03:46 | 000,002,048 | -HS- | M] () – C:\RECYCLER\S-1-5-18\$3bee44a7a72cc4f4b79e244279d08397\@

< [2012/12/23 06:03:46 | 000,000,000 | -HSD | M] – C:\RECYCLER\S-1-5-18\$3bee44a7a72cc4f4b79e244279d08397\L >
Invalid Switch: 23 06:03:46 | 000,000,000 | -HSD | M] – C:\RECYCLER\S-1-5-18\$3bee44a7a72cc4f4b79e244279d08397\L

< [2012/12/23 06:03:46 | 000,000,000 | -HSD | M] – C:\RECYCLER\S-1-5-18\$3bee44a7a72cc4f4b79e244279d08397\U >
Invalid Switch: 23 06:03:46 | 000,000,000 | -HSD | M] – C:\RECYCLER\S-1-5-18\$3bee44a7a72cc4f4b79e244279d08397\U

< @Alternate Data Stream - 156 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:90D89144 >

< >

< :Commands >

< [emptytemp] >

< [Reboot] >

< >

< End of report >
You made a mistake when running the OTL fix, you need to click run fix, not run scan, new fix below.



Run OTL.exe
  • Copy/paste the following text written inside of the code box into the Custom Scans/Fixes box located at the bottom of OTL

    :Services
    
    :Otl
    [2012/12/23 06:04:02 | 000,001,520 | -HS- | M] () – C:\Documents and Settings\user1\Local Settings\Application Data\1pb78m8n6he1l1565b3k36w7o7of8ksb88y53s63tpqg0vl
    [2012/12/23 06:03:46 | 000,002,048 | -HS- | M] () – C:\RECYCLER\S-1-5-18\$3bee44a7a72cc4f4b79e244279d08397\@
    [2012/12/23 06:03:46 | 000,000,000 | -HSD | M] – C:\RECYCLER\S-1-5-18\$3bee44a7a72cc4f4b79e244279d08397\L
    [2012/12/23 06:03:46 | 000,000,000 | -HSD | M] – C:\RECYCLER\S-1-5-18\$3bee44a7a72cc4f4b79e244279d08397\U
    @Alternate Data Stream - 156 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:90D89144
    
    :Commands
    [emptytemp]
    [Reboot]



  • Then click the Run Fix button at the top
  • Let the program run unhindered, reboot when it is done
  • Then post a new OTL log ( don't check the boxes beside LOP Check or Purity this time )




For a new antivirus try Micosoft security essentials. http://www.microsoft.com/en-gb/security/pc-security/mse.aspx
the run fix seems to have gotten rid of the recycler folder in my external drive. I would like to free up some space on the c drive - what can I safely remove? I will give the microsoft antivirus a try here is the otl scan result; All processes killed ========== SERVICES/DRIVERS ========== ========== OTL ========== C:\Documents and Settings\user1\Local Settings\Application Data\1pb78m8n6he1l1565b3k36w7o7of8ksb88y53s63tpqg0vl moved successfully. File C:\RECYCLER\S-1-5-18\$3bee44a7a72cc4f4b79e244279d08397\@ not found. Folder C:\RECYCLER\S-1-5-18\$3bee44a7a72cc4f4b79e244279d08397\L\ not found. Folder C:\RECYCLER\S-1-5-18\$3bee44a7a72cc4f4b79e244279d08397\U\ not found. Unable to delete ADS C:\Documents and Settings\All Users\Application Data\TEMP:90D89144 . ========== COMMANDS ========== [EMPTYTEMP] User: All Users User: Default User ->Temporary Internet Files folder emptied: 67 bytes ->Flash cache emptied: 56502 bytes User: LocalService ->Temp folder emptied: 2057640 bytes ->Temporary Internet Files folder emptied: 33170 bytes User: NetworkService ->Temp folder emptied: 1984664 bytes ->Temporary Internet Files folder emptied: 33170 bytes User: user1 ->Temp folder emptied: 3920841 bytes ->Temporary Internet Files folder emptied: 7397239 bytes ->Java cache emptied: 10682514 bytes ->Flash cache emptied: 470 bytes %systemdrive% .tmp files removed: 0 bytes %systemroot% .tmp files removed: 1720520 bytes %systemroot%\System32 .tmp files removed: 0 bytes %systemroot%\System32\dllcache .tmp files removed: 0 bytes %systemroot%\System32\drivers .tmp files removed: 0 bytes Windows Temp folder emptied: 107173 bytes %systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 0 bytes %systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 33170 bytes RecycleBin emptied: 0 bytes Total Files Cleaned = 27.00 mb OTL by OldTimer - Version 3.2.69.0 log created on 01142013_191518 Files\Folders moved on Reboot… PendingFileRenameOperations files… Registry entries deleted on Reboot…

I would like to free up some space on the c drive - what can I safely remove?

I am unsure of what you mean here we will remove all the tools we have used once we are finished, or do you mean other stuff?

If this is the case run otl again, under extra registry change it to use safe list and post both logs, how is it running now?
pc appears to be better i will post the otl after i run safe list. Been under the weather for few days hence slow response/post time
I get a message from microsoft stating that "an operating error has occuredand microsoft internet explorer has to close down" the screen will blink and then bring me back to what i was viewing, this has happened as frequently before we ran all the programs to remove whatever was infecting my pc but it still occurs.

Here is the otl results

OTL Extras logfile created on: 1/20/2013 3:11:43 PM - Run 7
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Documents and Settings\user1\My Documents
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

1.25 Gb Total Physical Memory | 0.87 Gb Available Physical Memory | 69.74% Memory free
1.85 Gb Paging File | 1.65 Gb Available in Paging File | 89.55% Paging File free
Paging file location(s): C:\pagefile.sys 756 1512 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 18.64 Gb Total Space | 2.19 Gb Free Space | 11.76% Space Free | Partition Type: NTFS

Computer Name: COMPAQ-033HB3B9 | User Name: user1 | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*
.url [@ = InternetShortcut] – rundll32.exe ieframe.dll,OpenURL %l

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*
exefile [open] – "%1" %*
InternetShortcut [open] – rundll32.exe ieframe.dll,OpenURL %l
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 1
"FirewallOverride" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

========== System Restore Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sr]
"Start" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SrService]
"Start" = 2

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile]

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0
"DoNotAllowExceptions" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0
"DoNotAllowExceptions" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
"%windir%\system32\sessmgr.exe" = %windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019 – (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"%windir%\system32\sessmgr.exe" = %windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019 – (Microsoft Corporation)


========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{02E89EFC-7B07-4D5A-AA03-9EC0902914EE}" = VC 9.0 Runtime
"{1451DE6B-ABE1-4F62-BE9A-B363A17588A2}" = QuickTime
"{14AA72DA-DB40-4A34-93A6-401A81D7AF9E}" = Unreal Anthology
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{26A24AE4-039D-4CA4-87B4-2F83216011FF}" = Java™ 6 Update 30
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{3FA365DF-2D68-45ED-8F83-8C8A33E65143}" = Apple Application Support
"{46C045BF-2B3F-4BC4-8E4C-00E0CF8BD9DB}" = Adobe AIR
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{612C34C7-5E90-47D8-9B5C-0F717DD82726}" = swMSM
"{6956856F-B6B3-4BE0-BA0B-8F495BE32033}" = Apple Software Update
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8A708DD8-A5E6-11D4-A706-000629E95E20}" = Intel® Extreme Graphics Driver
"{95120000-003F-0409-0000-0000000FF1CE}" = Microsoft Office Excel Viewer
"{95120000-00AF-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint Viewer 2007 (English)
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{98EABC7F-B1A1-43A5-B505-5B4EC3908DCD}" = Microsoft Security Client
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{A040AC77-C1AA-4CC9-8931-9F648AF178F6}" = VC 9.0 Runtime
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{A918DE8A-98C8-0800-0000-0000000C0001}" = Sanyo PM8200 USB - Handset Manager V8
"{A918DE8A-98C8-0800-0001-000000000000}" = Multimedia Samples
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{AC76BA86-7AD7-1033-7B44-AA1000000001}" = Adobe Reader X (10.1.3)
"{BE6890C7-31EF-478C-812E-1E2899ABFCA9}" = Broadcom 570x Driver Installer
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{D0A05794-48C2-4424-A15A-9F20FCFDD374}" = Call of Duty® 2
"{D1696920-9794-4BBC-8A30-7A88763DE5A2}" = ABBYY FineReader 5.0 Sprint
"{E2883E8F-472F-4fb0-9522-AC9BF37916A7}" = Adobe Download Manager
"{F0A37341-D692-11D4-A984-009027EC0A9C}" = SoundMAX
"{F45298E5-0083-426F-A668-1A2C5F04B8A0}" = FaxTools
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Adobe Shockwave Player" = Adobe Shockwave Player 11.6
"Adobe SVG Viewer" = Adobe SVG Viewer 3.0
"Creative Media Lite" = Creative Media Lite
"ESET Online Scanner" = ESET Online Scanner v3
"ie8" = Windows Internet Explorer 8
"InstallShield_{BE6890C7-31EF-478C-812E-1E2899ABFCA9}" = Broadcom 570x Driver Installer
"InstallShield_{D0A05794-48C2-4424-A15A-9F20FCFDD374}" = Call of Duty® 2
"Lexmark 1200 Series" = Lexmark 1200 Series
"Malwarebytes' Anti-Malware_is1" = Malwarebytes Anti-Malware version 1.70.0.1100
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Microsoft Security Client" = Microsoft Security Essentials
"MSCompPackV1" = Microsoft Compression Client Pack 1.0 for Windows XP
"NVIDIA Drivers" = NVIDIA Drivers
"PROSet" = Intel® PRO Network Connections Drivers
"Windows Media Format Runtime" = Windows Media Format 11 runtime
"Windows Media Player" = Windows Media Player 11
"Windows XP Service Pack" = Windows XP Service Pack 3
"WMFDist11" = Windows Media Format 11 runtime
"wmp11" = Windows Media Player 11
"Wudf01000" = Microsoft User-Mode Driver Framework Feature Pack 1.0
"YInstHelper" = Yahoo! Install Manager
"ZENStoneUG" = Creative ZEN Stone User's Guide
"ZoneAlarm LTD Toolbar" = ZoneAlarm LTD Toolbar

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"notify" = License Manager

========== Last 20 Event Log Errors ==========

[ Application Events ]
Error - 1/20/2013 4:54:50 PM | Computer Name = COMPAQ-033HB3B9 | Source = Microsoft Security Client Setup | ID = 100
Description = HRESULT:0x80096010 Description:Can't complete the Setup Wizard. An
error has prevented Setup Wizard from continuing. Please restart your computer and
try again. Error code:0x80096010. The digital signature of the object did not verify.

Error - 1/20/2013 4:54:54 PM | Computer Name = COMPAQ-033HB3B9 | Source = Microsoft Security Client Setup | ID = 100
Description = HRESULT:0x80096010 Description:Can't complete the Setup Wizard. An
error has prevented Setup Wizard from continuing. Please restart your computer and
try again. Error code:0x80096010. The digital signature of the object did not verify.

Error - 1/20/2013 4:56:03 PM | Computer Name = COMPAQ-033HB3B9 | Source = Microsoft Security Client Setup | ID = 100
Description = HRESULT:0x80096010 Description:Can't complete the Setup Wizard. An
error has prevented Setup Wizard from continuing. Please restart your computer and
try again. Error code:0x80096010. The digital signature of the object did not verify.

Error - 1/20/2013 4:56:06 PM | Computer Name = COMPAQ-033HB3B9 | Source = Microsoft Security Client Setup | ID = 100
Description = HRESULT:0x80096010 Description:Can't complete the Setup Wizard. An
error has prevented Setup Wizard from continuing. Please restart your computer and
try again. Error code:0x80096010. The digital signature of the object did not verify.

Error - 1/20/2013 4:56:09 PM | Computer Name = COMPAQ-033HB3B9 | Source = Microsoft Security Client Setup | ID = 100
Description = HRESULT:0x80096010 Description:Can't complete the Setup Wizard. An
error has prevented Setup Wizard from continuing. Please restart your computer and
try again. Error code:0x80096010. The digital signature of the object did not verify.

Error - 1/20/2013 4:57:14 PM | Computer Name = COMPAQ-033HB3B9 | Source = Microsoft Security Client Setup | ID = 100
Description = HRESULT:0x80096010 Description:Can't complete the Setup Wizard. An
error has prevented Setup Wizard from continuing. Please restart your computer and
try again. Error code:0x80096010. The digital signature of the object did not verify.

Error - 1/20/2013 4:57:18 PM | Computer Name = COMPAQ-033HB3B9 | Source = Microsoft Security Client Setup | ID = 100
Description = HRESULT:0x80096010 Description:Can't complete the Setup Wizard. An
error has prevented Setup Wizard from continuing. Please restart your computer and
try again. Error code:0x80096010. The digital signature of the object did not verify.

Error - 1/20/2013 4:59:45 PM | Computer Name = COMPAQ-033HB3B9 | Source = Microsoft Security Client Setup | ID = 100
Description = HRESULT:0x80096010 Description:Can't complete the Setup Wizard. An
error has prevented Setup Wizard from continuing. Please restart your computer and
try again. Error code:0x80096010. The digital signature of the object did not verify.

Error - 1/20/2013 4:59:48 PM | Computer Name = COMPAQ-033HB3B9 | Source = Microsoft Security Client Setup | ID = 100
Description = HRESULT:0x80096010 Description:Can't complete the Setup Wizard. An
error has prevented Setup Wizard from continuing. Please restart your computer and
try again. Error code:0x80096010. The digital signature of the object did not verify.

Error - 1/20/2013 4:59:50 PM | Computer Name = COMPAQ-033HB3B9 | Source = Microsoft Security Client Setup | ID = 100
Description = HRESULT:0x80096010 Description:Can't complete the Setup Wizard. An
error has prevented Setup Wizard from continuing. Please restart your computer and
try again. Error code:0x80096010. The digital signature of the object did not verify.

[ System Events ]
Error - 1/20/2013 4:30:36 PM | Computer Name = COMPAQ-033HB3B9 | Source = Service Control Manager | ID = 7000
Description = The Google Update Service (gupdate) service failed to start due to
the following error: %%3

Error - 1/20/2013 4:30:36 PM | Computer Name = COMPAQ-033HB3B9 | Source = Service Control Manager | ID = 7026
Description = The following boot-start or system-start driver(s) failed to load:
i8042prt

Error - 1/20/2013 4:53:10 PM | Computer Name = COMPAQ-033HB3B9 | Source = Microsoft Antimalware | ID = 2001
Description = %%860 has encountered an error trying to update signatures. New Signature
Version: Previous Signature Version: 0.0.0.0 Update Source: %%859 Update Stage: %%852

Source
Path: http://www.microsoft.com Signature Type: %%800 Update Type: %%803 User: NT AUTHORITY\SYSTEM

Current
Engine Version: Previous Engine Version: 0.0.0.0 Error code: 0x8024402c Error description:
An unexpected problem occurred while checking for updates. For information on installing
or troubleshooting updates, see Help and Support.

Error - 1/20/2013 4:53:10 PM | Computer Name = COMPAQ-033HB3B9 | Source = Microsoft Antimalware | ID = 2001
Description = %%860 has encountered an error trying to update signatures. New Signature
Version: Previous Signature Version: 0.0.0.0 Update Source: %%851 Update Stage: %%852

Source
Path: http://go.microsoft.com/fwlink/?LinkID=121…5D-99752CCA7094

Signature
Type: %%800 Update Type: %%803 User: NT AUTHORITY\NETWORK SERVICE Current Engine Version:
Previous Engine Version: 0.0.0.0 Error code: 0x80072ee7 Error description: The server
name or address could not be resolved

Error - 1/20/2013 4:53:10 PM | Computer Name = COMPAQ-033HB3B9 | Source = Microsoft Antimalware | ID = 2001
Description = %%860 has encountered an error trying to update signatures. New Signature
Version: Previous Signature Version: 0.0.0.0 Update Source: %%851 Update Stage: %%852

Source
Path: http://go.microsoft.com/fwlink/?LinkID=121…5D-99752CCA7094

Signature
Type: %%801 Update Type: %%803 User: NT AUTHORITY\NETWORK SERVICE Current Engine Version:
Previous Engine Version: 0.0.0.0 Error code: 0x80072ee7 Error description: The server
name or address could not be resolved

Error - 1/20/2013 4:53:10 PM | Computer Name = COMPAQ-033HB3B9 | Source = Microsoft Antimalware | ID = 2001
Description = %%860 has encountered an error trying to update signatures. New Signature
Version: Previous Signature Version: 0.0.0.0 Update Source: %%851 Update Stage: %%852

Source
Path: http://go.microsoft.com/fwlink/?LinkID=121…5D-99752CCA7094

Signature
Type: %%800 Update Type: %%803 User: NT AUTHORITY\NETWORK SERVICE Current Engine Version:
Previous Engine Version: 0.0.0.0 Error code: 0x80072ee7 Error description: The server
name or address could not be resolved

Error - 1/20/2013 4:58:11 PM | Computer Name = COMPAQ-033HB3B9 | Source = Microsoft Antimalware | ID = 2001
Description = %%860 has encountered an error trying to update signatures. New Signature
Version: Previous Signature Version: 0.0.0.0 Update Source: %%859 Update Stage: %%852

Source
Path: http://www.microsoft.com Signature Type: %%800 Update Type: %%803 User: NT AUTHORITY\SYSTEM

Current
Engine Version: Previous Engine Version: 0.0.0.0 Error code: 0x8024402c Error description:
An unexpected problem occurred while checking for updates. For information on installing
or troubleshooting updates, see Help and Support.

Error - 1/20/2013 5:03:11 PM | Computer Name = COMPAQ-033HB3B9 | Source = Microsoft Antimalware | ID = 2001
Description = %%860 has encountered an error trying to update signatures. New Signature
Version: Previous Signature Version: 0.0.0.0 Update Source: %%851 Update Stage: %%852

Source
Path: http://go.microsoft.com/fwlink/?LinkID=121…5D-99752CCA7094

Signature
Type: %%800 Update Type: %%803 User: NT AUTHORITY\NETWORK SERVICE Current Engine Version:
Previous Engine Version: 0.0.0.0 Error code: 0x80072ee7 Error description: The server
name or address could not be resolved

Error - 1/20/2013 5:03:11 PM | Computer Name = COMPAQ-033HB3B9 | Source = Microsoft Antimalware | ID = 2001
Description = %%860 has encountered an error trying to update signatures. New Signature
Version: Previous Signature Version: 0.0.0.0 Update Source: %%851 Update Stage: %%852

Source
Path: http://go.microsoft.com/fwlink/?LinkID=121…5D-99752CCA7094

Signature
Type: %%801 Update Type: %%803 User: NT AUTHORITY\NETWORK SERVICE Current Engine Version:
Previous Engine Version: 0.0.0.0 Error code: 0x80072ee7 Error description: The server
name or address could not be resolved

Error - 1/20/2013 5:03:11 PM | Computer Name = COMPAQ-033HB3B9 | Source = Microsoft Antimalware | ID = 2001
Description = %%860 has encountered an error trying to update signatures. New Signature
Version: Previous Signature Version: 0.0.0.0 Update Source: %%851 Update Stage: %%852

Source
Path: http://go.microsoft.com/fwlink/?LinkID=121…5D-99752CCA7094

Signature
Type: %%800 Update Type: %%803 User: NT AUTHORITY\NETWORK SERVICE Current Engine Version:
Previous Engine Version: 0.0.0.0 Error code: 0x80072ee7 Error description: The server
name or address could not be resolved


< End of report >

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI