This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Need Gracious HELP! again! [Closed]

14 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Roommate gave me a printer/scanner to use, YAHOO!!! Wait, download driver, WTF? Fine. Downloaded driver and have no use of scanner/printer and super slow computer. I tried running some driver scanners from previous help from WHAT THE TECH, then this happened… My pc was off. I turned it on. I had sound but the screen was black. No sign of life except the initial start of DELL and Windows screens. I tried this again, but also pushing F8 to run in safe mode. Safe Mode worked, but no internet…. SHUCKS! Tried again in SAFE MODE (with Networks)… THERE WE GO! wait, SHUUUUCKS!!!! no sound sad.gif Any of you fellows out there got an IDEA OF SOLUTIONS? I'm running in safe mode with networks at the moment. Let's talk. Thanks for your helps. -Alexander Lee
OTL logfile created on: 4/29/2013 9:38:45 PM - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Documents and Settings\lointusk\My Documents\Downloads
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

1.25 Gb Total Physical Memory | 0.74 Gb Available Physical Memory | 59.61% Memory free
2.98 Gb Paging File | 2.63 Gb Available in Paging File | 88.27% Paging File free
Paging file location(s): C:\pagefile.sys 1920 3840 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 38.28 Gb Total Space | 2.37 Gb Free Space | 6.20% Space Free | Partition Type: NTFS

Computer Name: COMPUTURD | User Name: lointusk | Logged in as Administrator.
Boot Mode: SafeMode with Networking | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Documents and Settings\lointusk\My Documents\Downloads\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
PRC - c:\Program Files\Microsoft Security Client\MsMpEng.exe (Microsoft Corporation)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)


========== Modules (No Company Name) ==========

MOD - C:\Program Files\Mozilla Firefox\mozjs.dll ()
MOD - C:\WINDOWS\system32\Macromed\Flash\NPSWF32_11_6_602_180.dll ()
MOD - C:\WINDOWS\system32\msdmo.dll ()


========== Services (SafeList) ==========

SRV - (HidServ) – %SystemRoot%\System32\hidserv.dll File not found
SRV - (ERSvc) – %SystemRoot%\System32\ersvc.dll File not found
SRV - (CiSvc) – C:\WINDOWS\system32\cisvc.exe File not found
SRV - (AdobeFlashPlayerUpdateSvc) – C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe (Adobe Systems Incorporated)
SRV - (MozillaMaintenance) – C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe (Mozilla Foundation)
SRV - (CltMngSvc) – C:\Program Files\SearchProtect\bin\CltMngSvc.exe (Conduit)
SRV - (McComponentHostService) – C:\Program Files\McAfee Security Scan\3.0.318\McCHSvc.exe (McAfee, Inc.)
SRV - (MsMpSvc) – c:\Program Files\Microsoft Security Client\MsMpEng.exe (Microsoft Corporation)
SRV - (NMSAccess) – C:\Program Files\CDBurnerXP\NMSAccessU.exe ()
SRV - (FolderSize) – C:\Program Files\FolderSize\FolderSizeSvc.exe (Brio)


========== Driver Services (SafeList) ==========

DRV - (WDICA) – File not found
DRV - (PDRFRAME) – File not found
DRV - (PDRELI) – File not found
DRV - (PDFRAME) – File not found
DRV - (PDCOMP) – File not found
DRV - (PCIDump) – File not found
DRV - (lbrtfdc) – File not found
DRV - (i2omgmt) – File not found
DRV - (Changer) – File not found
DRV - (catchme) – C:\DOCUME~1\lointusk\LOCALS~1\Temp\catchme.sys File not found
DRV - (MpKsl665f91f5) – c:\Documents and Settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{CCAEA136-05A8-4064-9BEB-3538D6C593AD}\MpKsl665f91f5.sys (Microsoft Corporation)
DRV - (StarOpen) – C:\WINDOWS\System32\drivers\StarOpen.sys ()
DRV - (WUSB54GPV4SRV) – C:\WINDOWS\system32\drivers\rt2500usb.sys (Ralink Technology Inc.)
DRV - (BCM43XX) – C:\WINDOWS\system32\drivers\BCMWL5.SYS (Broadcom Corporation)
DRV - (senfilt) – C:\WINDOWS\system32\drivers\senfilt.sys (Creative Technology Ltd.)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\..\SearchScopes,DefaultScope =
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://search.live.com/results.aspx?q={sea…ferrer:source?}

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-us
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 46 98 52 4A 45 43 CD 01 [binary data]
IE - HKCU\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM;=IE8SRC
IE - HKCU\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM;=IE8SRC
IE - HKCU\..\SearchScopes\{91607fa7-3c2f-4f90-93e3-d5337a6b0ac2}: "URL" = playbryte/search/redirect/?type=default&user;_id=1d4ec9c4-187b-4ef8-8e2f-9687c95b71c2&query;={searchTerms}
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..browser.search.defaultthis.engineName: "WhiteSmoke New Customized Web Search"
FF - prefs.js..browser.search.defaulturl: "http://search.conduit.com/ResultsExt.aspx?ctid=CT3289847&CUI;=UN12486887918752630&UM;=2&SearchSource;=3&q;={searchTerms}"
FF - prefs.js..browser.search.selectedEngine: "Google"
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "google.com"
FF - prefs.js..extensions.enabledAddons: %7B972ce4c6-7e08-4474-a285-3208198ce6fd%7D:20.0.1
FF - prefs.js..keyword.URL: "http://search.conduit.com/ResultsExt.aspx?ctid=CT3289847&SearchSource;=2&CUI;=UN12486887918752630&UM;=2&q;="
FF - user.js - File not found

FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32_11_6_602_180.dll ()
FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF - HKLM\Software\MozillaPlugins\@mcafee.com/McAfeeMssPlugin: C:\Program Files\McAfee Security Scan\3.0.318\npMcAfeeMss.dll (McAfee, Inc.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\5.1.20125.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@real.com/nppl3260;version=6.0.12.448: C:\Program Files\Real Alternative\browser\plugins\nppl3260.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprpjplug;version=6.0.12.448: C:\Program Files\Real Alternative\browser\plugins\nprpjplug.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nsJSRealPlayerPlugin;version=: File not found
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.135\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.135\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@videolan.org/vlc,version=1.0.3: C:\Program Files\VideoLAN\VLC\npvlc.dll (the VideoLAN Team)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Documents and Settings\lointusk\Local Settings\Application Data\Google\Update\1.3.21.135\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Documents and Settings\lointusk\Local Settings\Application Data\Google\Update\1.3.21.135\npGoogleUpdate3.dll (Google Inc.)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 20.0.1\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2013/04/19 20:47:42 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 20.0.1\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2013/04/14 19:56:53 | 000,000,000 | —D | M]

[2012/11/29 11:02:26 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\lointusk\Application Data\Mozilla\Extensions
[2013/04/20 07:58:32 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\lointusk\Application Data\Mozilla\Firefox\Profiles\p2g3ajml.default\extensions
[2013/04/19 20:44:10 | 000,000,000 | —D | M] (GetSavin) – C:\Documents and Settings\lointusk\Application Data\Mozilla\Firefox\Profiles\p2g3ajml.default\extensions\getsavin@jetpack
[2013/04/19 20:46:05 | 000,001,005 | —- | M] () – C:\Documents and Settings\lointusk\Application Data\Mozilla\Firefox\Profiles\p2g3ajml.default\searchplugins\conduit.xml
[2013/02/24 12:29:59 | 000,001,001 | —- | M] () – C:\Documents and Settings\lointusk\Application Data\Mozilla\Firefox\Profiles\p2g3ajml.default\searchplugins\torrentz-search.xml
[2013/04/14 19:55:03 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions
[2013/04/14 19:54:43 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\distribution\extensions
[2013/04/14 19:55:01 | 000,000,000 | —D | M] (Yahoo! Toolbar) – C:\Program Files\Mozilla Firefox\distribution\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1}
[2013/04/14 19:59:51 | 000,263,064 | —- | M] (Mozilla Foundation) – C:\Program Files\mozilla firefox\components\browsercomps.dll
[2013/04/14 19:57:59 | 000,002,465 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\bing.xml
[2013/04/14 19:57:59 | 000,002,086 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\twitter.xml

========== Chrome ==========

CHR - homepage:
CHR - default_search_provider: ()
CHR - default_search_provider: search_url =
CHR - default_search_provider: suggest_url =
CHR - homepage:
CHR - Extension: No name found = C:\Documents and Settings\lointusk\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\igdhbblpcellaljokkpfhcjlagemhgjl\6.16.5.1_0\
CHR - Extension: No name found = C:\Documents and Settings\lointusk\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\mjildcbkilmkddbbpbjljljdmmlfeppl\5.0_0\
CHR - Extension: No name found = C:\Documents and Settings\lointusk\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\mmlkabjddkpgkgfhdhpimhcbonapngoh\10.14.40.128_0\

O1 HOSTS File: ([2013/02/18 14:34:44 | 000,000,027 | —- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (MSS+ Identifier) - {0E8A89AD-95D7-40EB-8D9D-083EF7066A01} - C:\Program Files\McAfee Security Scan\3.0.318\McAfeeMSS_IE.dll (McAfee, Inc.)
O2 - BHO: (GetSavin 5.0) - {60636320-7D7A-476D-9136-5A9FC07C90EE} - C:\Documents and Settings\lointusk\Local Settings\Application Data\getsavin\ie\getsavin_1366425601.dll ()
O4 - HKLM..\Run: [MSC] c:\Program Files\Microsoft Security Client\msseces.exe (Microsoft Corporation)
O4 - HKLM..\Run: [SearchProtectAll] C:\Program Files\SearchProtect\bin\cltmng.exe (Conduit)
O4 - HKCU..\Run: [DAEMON Tools] C:\Program Files\DAEMON Tools\daemon.exe (DT Soft Ltd.)
O4 - HKCU..\Run: [SearchProtect] C:\Documents and Settings\lointusk\Application Data\SearchProtect\bin\cltmng.exe (Conduit)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\HiCDEject.lnk = C:\Program Files\HiCDEject\HiCDEject.exe ()
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\McAfee Security Scan Plus.lnk = C:\Program Files\McAfee Security Scan\3.0.318\SSScheduler.exe (McAfee, Inc.)
O4 - Startup: C:\Documents and Settings\lointusk\Start Menu\Programs\Startup\Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe (Adobe Systems, Inc.)
O4 - Startup: C:\Documents and Settings\lointusk\Start Menu\Programs\Startup\Dropbox.lnk = C:\Documents and Settings\lointusk\Application Data\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSMHelp = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoResolveTrack = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: LinkResolveIgnoreLinkInfo = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoResolveSearch = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSMConfigurePrograms = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O16 - DPF: {31435657-9980-0010-8000-00AA00389B71} http://download.microsoft.com/download/e/2…78f/wvc1dmo.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.0.1 [removed]
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{3C2F8020-1F67-43A0-B7E4-678FBBA60FBA}: NameServer = 192.168.0.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{58FA7B8E-4E10-4456-906A-8DF7B9D15259}: NameServer = 192.168.0.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{595FCF1C-C74B-46AE-B3B1-6CD47E0297D6}: NameServer = 192.168.0.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{6A9C593A-3C2B-4D4A-9DBD-6DB76CA920C6}: NameServer = 192.168.0.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{8DF4D200-5EF5-45C5-B945-C7DFAE8DE4FA}: NameServer = 192.168.0.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{9F9D5D91-3B90-408F-94E8-D822F7C38B25}: NameServer = 192.168.0.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{D1874624-8B82-4C99-BB6B-1D0A82580750}: DhcpNameServer = 192.168.0.1 [removed]
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) - C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O28 - HKLM ShellExecuteHooks: {AEB6717E-7E19-11d0-97EE-00C04FD91972} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009/10/10 11:04:25 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = ComFile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)

NetSvcs: 6to4 - File not found
NetSvcs: HidServ - %SystemRoot%\System32\hidserv.dll File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found

Drivers32: msacm.ac3acm - C:\WINDOWS\System32\ac3acm.acm (fccHandler)
Drivers32: msacm.iac2 - C:\WINDOWS\system32\iac25_32.ax (Intel Corporation)
Drivers32: msacm.l3acm - C:\WINDOWS\system32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.lameacm - C:\WINDOWS\System32\lameACM.acm (http://www.mp3dev.org/)
Drivers32: msacm.sl_anet - C:\WINDOWS\System32\sl_anet.acm (Sipro Lab Telecom Inc.)
Drivers32: msacm.trspch - C:\WINDOWS\System32\tssoft32.acm (DSP GROUP, INC.)
Drivers32: vidc.cvid - C:\WINDOWS\System32\iccvid.dll (Radius Inc.)
Drivers32: VIDC.FFDS - C:\WINDOWS\System32\ff_vfw.dll ()
Drivers32: vidc.iv31 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv32 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv41 - C:\WINDOWS\System32\ir41_32.ax (Intel Corporation)
Drivers32: vidc.iv50 - C:\WINDOWS\System32\ir50_32.dll (Intel Corporation)
Drivers32: VIDC.XVID - C:\WINDOWS\System32\xvidvfw.dll ()
Drivers32: VIDC.YV12 - C:\WINDOWS\System32\yv12vfw.dll (www.helixcommunity.org)

CREATERESTOREPOINT
Unable to start System Restore Service. Error code 10

========== Files/Folders - Created Within 30 Days ==========

[2013/04/28 09:15:52 | 000,000,000 | —D | C] – C:\WINDOWS\temp
[2013/04/28 09:04:00 | 000,000,000 | —D | C] – C:\ComboFix
[2013/04/28 08:56:19 | 000,000,000 | —D | C] – C:\TDSSKiller_Quarantine
[2013/04/23 18:50:32 | 000,000,000 | —D | C] – C:\Documents and Settings\lointusk\Desktop\Driver Scanners
[2013/04/20 01:35:11 | 000,000,000 | —D | C] – C:\drivers
[2013/04/19 21:05:12 | 000,000,000 | —D | C] – C:\Program Files\Microsoft.NET
[2013/04/19 20:49:48 | 000,000,000 | —D | C] – C:\Documents and Settings\lointusk\Application Data\SwvUpdater
[2013/04/19 20:47:34 | 000,000,000 | —D | C] – C:\Program Files\SearchProtect
[2013/04/19 20:46:06 | 000,000,000 | —D | C] – C:\Documents and Settings\lointusk\Application Data\SearchProtect
[2013/04/19 20:44:04 | 000,000,000 | —D | C] – C:\Documents and Settings\lointusk\Local Settings\Application Data\getsavin
[2013/04/19 20:00:49 | 000,025,856 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\usbprint.sys
[2013/04/15 03:16:42 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Microsoft Silverlight
[2013/04/14 21:32:32 | 000,012,928 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\usb8023x.sys
[2013/04/14 21:32:32 | 000,012,928 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\usb8023.sys
[2013/04/14 19:54:00 | 000,000,000 | —D | C] – C:\Program Files\Mozilla Firefox
[2 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2013/04/29 21:10:05 | 000,000,664 | —- | M] () – C:\WINDOWS\System32\d3d9caps.dat
[2013/04/29 20:37:30 | 000,000,366 | -H– | M] () – C:\WINDOWS\tasks\MpIdleTask.job
[2013/04/29 20:27:50 | 000,002,206 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2013/04/29 20:27:23 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2013/04/29 20:26:21 | 000,000,886 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2013/04/29 20:26:17 | 000,000,408 | —- | M] () – C:\WINDOWS\tasks\AmiUpdXp.job
[2013/04/27 16:07:00 | 000,000,990 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1482476501-1123561945-1644491937-1001UA.job
[2013/04/27 16:07:00 | 000,000,938 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1482476501-1123561945-1644491937-1001Core.job
[2013/04/27 15:43:00 | 000,000,830 | —- | M] () – C:\WINDOWS\tasks\Adobe Flash Player Updater.job
[2013/04/27 15:28:00 | 000,000,890 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2013/04/27 02:02:55 | 000,081,496 | —- | M] () – C:\WINDOWS\System32\nvapps.xml
[2013/04/25 02:28:30 | 000,144,490 | —- | M] () – C:\Documents and Settings\lointusk\Desktop\bottle.png
[2013/04/21 03:33:25 | 000,470,384 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2013/04/21 03:33:25 | 000,074,718 | —- | M] () – C:\WINDOWS\System32\perfc009.dat
[2013/04/20 07:52:56 | 000,000,830 | —- | M] () – C:\WINDOWS\System32\InstallUtil.InstallLog
[2013/04/19 21:43:47 | 000,693,976 | —- | M] (Adobe Systems Incorporated) – C:\WINDOWS\System32\FlashPlayerApp.exe
[2013/04/19 21:43:46 | 000,073,432 | —- | M] (Adobe Systems Incorporated) – C:\WINDOWS\System32\FlashPlayerCPLApp.cpl
[2013/04/19 20:49:09 | 000,000,009 | —- | M] () – C:\end
[2013/04/15 04:07:28 | 000,171,488 | —- | M] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2013/04/15 03:51:06 | 000,001,374 | —- | M] () – C:\WINDOWS\imsins.BAK
[2013/04/14 16:18:21 | 000,002,327 | —- | M] () – C:\Documents and Settings\lointusk\Application Data\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk
[2013/04/14 16:18:20 | 000,002,309 | —- | M] () – C:\Documents and Settings\lointusk\Desktop\Google Chrome.lnk
[2013/04/14 16:10:03 | 000,001,037 | —- | M] () – C:\Documents and Settings\lointusk\Start Menu\Programs\Startup\Dropbox.lnk
[2013/04/14 16:07:45 | 000,001,027 | —- | M] () – C:\Documents and Settings\lointusk\Desktop\Dropbox.lnk
[2013/04/02 04:33:22 | 000,237,088 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\MpSigStub.exe
[2 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]

========== Files Created - No Company Name ==========

[2013/04/25 02:27:46 | 000,144,490 | —- | C] () – C:\Documents and Settings\lointusk\Desktop\bottle.png
[2013/04/20 01:52:00 | 000,157,622 | —- | C] () – C:\Documents and Settings\LocalService\Local Settings\Application Data\WPFFontCache_v0400-S-1-5-21-1482476501-1123561945-1644491937-1001-0.dat
[2013/04/20 01:51:57 | 000,157,622 | —- | C] () – C:\Documents and Settings\LocalService\Local Settings\Application Data\WPFFontCache_v0400-System.dat
[2013/04/19 21:33:34 | 000,000,830 | —- | C] () – C:\WINDOWS\System32\InstallUtil.InstallLog
[2013/04/19 20:49:49 | 000,000,408 | —- | C] () – C:\WINDOWS\tasks\AmiUpdXp.job
[2013/04/19 20:43:16 | 000,000,009 | —- | C] () – C:\end
[2013/02/24 13:05:31 | 000,016,384 | —- | C] () – C:\WINDOWS\System32\FileOps.exe
[2013/02/14 19:15:31 | 000,256,000 | —- | C] () – C:\WINDOWS\PEV.exe
[2013/02/14 19:15:31 | 000,208,896 | —- | C] () – C:\WINDOWS\MBR.exe
[2013/02/14 19:15:31 | 000,098,816 | —- | C] () – C:\WINDOWS\sed.exe
[2013/02/14 19:15:31 | 000,080,412 | —- | C] () – C:\WINDOWS\grep.exe
[2013/02/14 19:15:31 | 000,068,096 | —- | C] () – C:\WINDOWS\zip.exe
[2012/12/29 14:42:26 | 000,000,000 | —- | C] () – C:\WINDOWS\iPlayer.INI
[2012/06/05 11:55:23 | 000,000,376 | —- | C] () – C:\WINDOWS\ODBC.INI
[2012/03/25 11:32:22 | 000,000,016 | —- | C] () – C:\WINDOWS\System32\msvcsv60.dll
[2012/03/25 11:32:22 | 000,000,016 | —- | C] () – C:\WINDOWS\msocreg32.dat
[2012/03/01 20:09:23 | 000,003,072 | —- | C] () – C:\WINDOWS\System32\iacenc.dll
[2009/11/07 10:11:36 | 000,005,120 | —- | C] () – C:\Documents and Settings\lointusk\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini

========== ZeroAccess Check ==========

[2010/02/15 14:52:41 | 000,000,227 | RHS- | M] () – C:\WINDOWS\assembly\Desktop.ini

[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]

[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shdocvw.dll – [2009/03/02 17:04:03 | 001,499,136 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll – [2009/02/09 06:10:48 | 000,473,600 | R— | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
"" = %systemroot%\system32\wbem\wbemess.dll – [2008/04/14 06:00:00 | 000,273,920 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Both

========== LOP Check ==========

[2013/02/07 13:17:01 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Cakewalk
[2010/08/17 20:55:49 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Canneverbe Limited
[2010/01/13 21:21:31 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Soulseek
[2012/07/30 22:43:53 | 000,000,000 | —D | M] – C:\Documents and Settings\lointusk\Application Data\Audacity
[2012/03/25 11:31:09 | 000,000,000 | —D | M] – C:\Documents and Settings\lointusk\Application Data\Cakewalk
[2010/08/17 20:55:50 | 000,000,000 | —D | M] – C:\Documents and Settings\lointusk\Application Data\Canneverbe Limited
[2009/10/10 11:34:36 | 000,000,000 | —D | M] – C:\Documents and Settings\lointusk\Application Data\DAEMON Tools Lite
[2013/04/28 08:47:12 | 000,000,000 | —D | M] – C:\Documents and Settings\lointusk\Application Data\Dropbox
[2010/01/15 20:57:03 | 000,000,000 | —D | M] – C:\Documents and Settings\lointusk\Application Data\IrfanView
[2013/04/19 20:47:36 | 000,000,000 | —D | M] – C:\Documents and Settings\lointusk\Application Data\SearchProtect
[2013/04/19 20:49:48 | 000,000,000 | —D | M] – C:\Documents and Settings\lointusk\Application Data\SwvUpdater
[2013/02/27 09:38:38 | 000,000,000 | —D | M] – C:\Documents and Settings\lointusk\Application Data\uTorrent

========== Purity Check ==========



========== Custom Scans ==========

< %USERPROFILE%\..|smtmp;true;true;true /FP >

< %temp%\smtmp\*.* /s > >

< MD5 for: EXPLORER.EXE >
[2009/08/05 13:51:10 | 001,033,728 | —- | M] (Microsoft Corporation) MD5=2BB75B7F548D82A099125D0C5971DE7D – C:\WINDOWS\erdnt\cache\explorer.exe
[2009/08/05 13:51:10 | 001,033,728 | —- | M] (Microsoft Corporation) MD5=2BB75B7F548D82A099125D0C5971DE7D – C:\WINDOWS\explorer.exe

< MD5 for: EXPLORER.SCF >
[2008/04/14 06:00:00 | 000,000,080 | —- | M] () MD5=A3975A7D2C98B30A2AE010754FFB9392 – C:\WINDOWS\explorer.scf

< MD5 for: IEXPLORE.EXE >
[2009/08/05 15:05:56 | 000,638,816 | —- | M] (Microsoft Corporation) MD5=B60DDDD2D63CE41CB8C487FCFBB6419E – C:\Program Files\Internet Explorer\IEXPLORE.EXE
[2009/08/05 15:05:56 | 000,638,816 | —- | M] (Microsoft Corporation) MD5=B60DDDD2D63CE41CB8C487FCFBB6419E – C:\WINDOWS\erdnt\cache\IEXPLORE.EXE

< MD5 for: IEXPLORE.EXE.MUI >
[2009/08/05 15:06:21 | 000,012,288 | —- | M] (Microsoft Corporation) MD5=943030B55FDB56FB8B8FCC086071E119 – C:\Program Files\Internet Explorer\en-US\iexplore.exe.mui
[2009/08/05 15:06:21 | 000,012,288 | —- | M] (Microsoft Corporation) MD5=943030B55FDB56FB8B8FCC086071E119 – C:\Program Files\Internet Explorer\iexplore.exe.mui

< MD5 for: IEXPLORE.EXE-0A31FE70.PF >
[2013/04/27 16:23:54 | 000,013,616 | —- | M] () MD5=5D93803BD8EABDDE4183D267D910EC93 – C:\WINDOWS\Prefetch\IEXPLORE.EXE-0A31FE70.pf

< MD5 for: IEXPLORE.EXE-12915967.PF >
[2013/04/27 16:23:53 | 000,018,618 | —- | M] () MD5=B87697A4B3F85123FE3F0A43C88B60CC – C:\WINDOWS\Prefetch\IEXPLORE.EXE-12915967.pf

< MD5 for: IEXPLORE.EXE-12BBAE74.PF >
[2013/04/27 16:23:59 | 000,011,056 | —- | M] () MD5=D1AEF55C6388EB037D93A991E2D042CF – C:\WINDOWS\Prefetch\IEXPLORE.EXE-12BBAE74.pf

< MD5 for: IEXPLORE.EXE-27122324.PF >
[2013/04/23 09:37:01 | 000,100,914 | —- | M] () MD5=4EB515C54186BEA87D670F633EF984F1 – C:\WINDOWS\Prefetch\IEXPLORE.EXE-27122324.pf

< MD5 for: SERVICES >
[2008/04/14 06:00:00 | 000,007,116 | —- | M] () MD5=95826940E657FE0567A8EC0F2A6AD11A – C:\WINDOWS\system32\drivers\etc\services

< MD5 for: SERVICES.EXE >
[2009/02/06 05:06:24 | 000,110,592 | —- | M] (Microsoft Corporation) MD5=020CEAAEDC8EB655B6506B8C70D53BB6 – C:\WINDOWS\$hf_mig$\KB956572\SP3QFE\services.exe
[2009/02/06 05:11:05 | 000,110,592 | —- | M] (Microsoft Corporation) MD5=65DF52F5B8B6E9BBD183505225C37315 – C:\WINDOWS\erdnt\cache\services.exe
[2009/02/06 05:11:05 | 000,110,592 | —- | M] (Microsoft Corporation) MD5=65DF52F5B8B6E9BBD183505225C37315 – C:\WINDOWS\system32\dllcache\services.exe
[2009/02/06 05:11:05 | 000,110,592 | —- | M] (Microsoft Corporation) MD5=65DF52F5B8B6E9BBD183505225C37315 – C:\WINDOWS\system32\services.exe

< MD5 for: SERVICES.LNK >
[2009/10/10 11:04:32 | 000,001,602 | —- | M] () MD5=4BB19AB821AE937C8C2450F9037B0EF4 – C:\Documents and Settings\All Users\Start Menu\Programs\Administrative Tools\Services.lnk

< MD5 for: SERVICES.MSC >
[2008/04/14 06:00:00 | 000,033,464 | —- | M] () MD5=E8089AA2A6F7FEE89B38C1F2D77BA6C6 – C:\WINDOWS\system32\services.msc

< MD5 for: SERVICES.SBS >
[2009/07/07 01:45:50 | 000,031,755 | —- | M] () MD5=3254FEEC54BAB3EC6AF180367EFEC6F5 – C:\Program Files\Spybot - Search & Destroy\Includes\Services.sbs

< MD5 for: WINLOGON.EXE >
[2008/04/14 06:00:00 | 000,507,904 | —- | M] (Microsoft Corporation) MD5=ED0EF0A136DEC83DF69F04118870003E – C:\WINDOWS\erdnt\cache\winlogon.exe
[2008/04/14 06:00:00 | 000,507,904 | —- | M] (Microsoft Corporation) MD5=ED0EF0A136DEC83DF69F04118870003E – C:\WINDOWS\system32\winlogon.exe

< %SYSTEMDRIVE%\*.* >
[2013/02/08 11:40:20 | 000,019,583 | —- | M] () – C:\AdwCleaner[S1].txt
[2009/10/10 11:04:25 | 000,000,000 | —- | M] () – C:\AUTOEXEC.BAT
[2010/04/21 14:24:49 | 000,000,211 | —- | M] () – C:\Boot.bak
[2013/02/14 19:20:22 | 000,000,327 | RHS- | M] () – C:\boot.ini
[2004/08/04 00:00:00 | 000,260,272 | RHS- | M] () – C:\cmldr
[2013/04/28 09:15:50 | 000,013,614 | —- | M] () – C:\ComboFix.txt
[2009/10/10 11:04:25 | 000,000,000 | —- | M] () – C:\CONFIG.SYS
[2013/04/19 20:49:09 | 000,000,009 | —- | M] () – C:\end
[2009/10/10 11:04:25 | 000,000,000 | RHS- | M] () – C:\IO.SYS
[2009/10/10 11:04:25 | 000,000,000 | RHS- | M] () – C:\MSDOS.SYS
[2008/04/14 06:00:00 | 000,047,564 | RHS- | M] () – C:\NTDETECT.COM
[2008/04/14 06:00:00 | 000,250,048 | RHS- | M] () – C:\ntldr
[2013/04/29 20:27:16 | 2013,265,920 | -HS- | M] () – C:\pagefile.sys
[2013/02/10 00:01:05 | 000,075,376 | —- | M] () – C:\TDSSKiller.2.8.15.0_09.02.2013_13.35.48_log.txt
[2013/04/28 08:57:24 | 000,076,728 | —- | M] () – C:\TDSSKiller.2.8.15.0_28.04.2013_08.54.29_log.txt

< %systemroot%\Fonts\*.com >
[2006/04/18 14:39:28 | 000,026,040 | —- | M] () – C:\WINDOWS\Fonts\GlobalMonospace.CompositeFont
[2006/06/29 13:53:56 | 000,026,489 | —- | M] () – C:\WINDOWS\Fonts\GlobalSansSerif.CompositeFont
[2006/04/18 14:39:28 | 000,029,779 | —- | M] () – C:\WINDOWS\Fonts\GlobalSerif.CompositeFont
[2006/06/29 13:58:52 | 000,030,808 | —- | M] () – C:\WINDOWS\Fonts\GlobalUserInterface.CompositeFont

< %systemroot%\Fonts\*.dll >

< %systemroot%\Fonts\*.ini >
[2009/10/10 11:03:55 | 000,000,067 | -HS- | M] () – C:\WINDOWS\Fonts\desktop.ini

< %systemroot%\Fonts\*.ini2 >

< %systemroot%\Fonts\*.exe >

< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2008/07/06 06:06:10 | 000,089,088 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\filterpipelineprintproc.dll
[2008/07/06 04:50:03 | 000,597,504 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\printfilterpipelinesvc.exe

< %systemroot%\REPAIR\*.bak1 >

< %systemroot%\REPAIR\*.ini >

< %systemroot%\system32\*.jpg >

< %systemroot%\*.jpg >

< %systemroot%\*.png >

< %systemroot%\*.scr >

< %systemroot%\*._sy >

< %APPDATA%\Adobe\Update\*.* >

< %ALLUSERSPROFILE%\Favorites\*.* >

< %APPDATA%\Microsoft\*.* >

< %PROGRAMFILES%\*.* >

< %APPDATA%\Update\*.* >

< %systemroot%\*. /mp /s >

< %systemroot%\System32\config\*.sav >
[2009/10/10 06:48:24 | 000,098,304 | —- | M] () – C:\WINDOWS\System32\config\default.sav
[2009/10/10 06:48:24 | 001,069,056 | —- | M] () – C:\WINDOWS\System32\config\software.sav
[2009/10/10 06:48:24 | 000,843,776 | —- | M] () – C:\WINDOWS\System32\config\system.sav

< %PROGRAMFILES%\bak. /s >

< %systemroot%\system32\bak. /s >

< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >
[2009/10/10 11:04:32 | 000,000,231 | -HS- | M] () – C:\Documents and Settings\All Users\Start Menu\desktop.ini

< %systemroot%\system32\config\systemprofile\*.dat /x >

< %systemroot%\*.config >

< %systemroot%\system32\*.db >

< %PROGRAMFILES%\Internet Explorer\*.dat >

< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2009/10/10 11:18:40 | 000,000,060 | -HS- | M] () – C:\Documents and Settings\lointusk\Application Data\Microsoft\Internet Explorer\Quick Launch\desktop.ini
[2009/10/10 11:18:40 | 000,000,079 | —- | M] () – C:\Documents and Settings\lointusk\Application Data\Microsoft\Internet Explorer\Quick Launch\Show Desktop.scf

< %USERPROFILE%\Desktop\*.exe >

< %PROGRAMFILES%\Common Files\*.* >

< %systemroot%\*.src >

< %systemroot%\install\*.* >

< %systemroot%\system32\DLL\*.* >

< %systemroot%\system32\HelpFiles\*.* >

< %systemroot%\system32\rundll\*.* >

< %systemroot%\winn32\*.* >

< %systemroot%\Java\*.* >

< %systemroot%\system32\test\*.* >

< %systemroot%\system32\Rundll32\*.* >

< %systemroot%\AppPatch\Custom\*.* >

< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >

< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2013-04-21 09:36:45

< End of report >


OTL Extras logfile created on: 4/29/2013 9:38:45 PM - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Documents and Settings\lointusk\My Documents\Downloads
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

1.25 Gb Total Physical Memory | 0.74 Gb Available Physical Memory | 59.61% Memory free
2.98 Gb Paging File | 2.63 Gb Available in Paging File | 88.27% Paging File free
Paging file location(s): C:\pagefile.sys 1920 3840 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 38.28 Gb Total Space | 2.37 Gb Free Space | 6.20% Space Free | Partition Type: NTFS

Computer Name: COMPUTURD | User Name: lointusk | Logged in as Administrator.
Boot Mode: SafeMode with Networking | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*
.url [@ = InternetShortcut] – rundll32.exe ieframe.dll,OpenURL %l

[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.html [@ = ChromeHTML] – Reg Error: Key error. File not found

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*
exefile [open] – "%1" %*
InternetShortcut [open] – rundll32.exe ieframe.dll,OpenURL %l
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistVLC] – "C:\Program Files\VideoLAN\VLC\vlc.exe" –started-from-file –playlist-enqueue "%1" ()
Directory [cmd] – cmd.exe /k cd "%L" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] – "C:\Program Files\VideoLAN\VLC\vlc.exe" –started-from-file –no-playlist-enqueue "%1" ()
Folder [open] – %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 1
"FirewallOverride" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

========== System Restore Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sr]
"Start" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SrService]
"Start" = 2

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile]

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 0
"DoNotAllowExceptions" = 0
"DisableNotifications" = 0
"DisableUnicastResponsesToMulticastBroadcast" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
"139:TCP" = 139:TCP:*:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:*:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:*:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:*:Enabled:@xpsp2res.dll,-22002

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DoNotAllowExceptions" = 0
"DisableNotifications" = 0
"DisableUnicastResponsesToMulticastBroadcast" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"139:TCP" = 139:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22002

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
"%windir%\Network Diagnostic\xpnetdiag.exe" = %windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000 – (Microsoft Corporation)
"%windir%\system32\sessmgr.exe" = %windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019 – (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"%windir%\Network Diagnostic\xpnetdiag.exe" = %windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000 – (Microsoft Corporation)
"%windir%\system32\sessmgr.exe" = %windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019 – (Microsoft Corporation)
"C:\Program Files\utorrent\utorrent.exe" = C:\Program Files\utorrent\utorrent.exe:*:Enabled:µTorrent – (BitTorrent, Inc.)
"C:\Documents and Settings\lointusk\Application Data\Dropbox\bin\Dropbox.exe" = C:\Documents and Settings\lointusk\Application Data\Dropbox\bin\Dropbox.exe:*:Enabled:Dropbox – (Dropbox, Inc.)


========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{0001B4FD-9EA3-4D90-A79E-FD14BA3AB01D}" = PDFCreator
"{236BB7C4-4419-42FD-0409-1E257A25E34D}" = Adobe Photoshop CS2
"{34B32B70-8081-11E2-89AF-B8AC6F98CCE3}" = Google Earth Plug-in
"{390DD8BB-BB57-4942-A029-2D913E4E9D74}" = Microsoft Security Client
"{3C3901C5-3455-3E0A-A214-0B093A5070A6}" = Microsoft .NET Framework 4 Client Profile
"{62DC441E-0FD3-4606-9D9B-90FE325B29E5}" = Foxit Reader
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{786C5747-1033-0000-B58E-000000000001}" = Adobe Stock Photos 1.0
"{7E265513-8CDA-4631-B696-F40D983F3B07}_is1" = CDBurnerXP
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8A708DD8-A5E6-11D4-A706-000629E95E20}" = Intel® Extreme Graphics 2 Driver
"{8EDBA74D-0686-4C99-BFDD-F894678E5B39}" = Adobe Common File Installer
"{90120000-0020-0409-0000-0000000FF1CE}" = Compatibility Pack for the 2007 Office system
"{90280409-6000-11D3-8CFE-0050048383C9}" = Microsoft Office XP Professional with FrontPage
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{99C91FC5-DB5B-4AA0-BB70-5D89C5A4DF96}" = Software Version Updater
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{B2F5D08C-7E79-4FCD-AAF4-57AD35FF0601}" = Adobe Illustrator CS2
"{B4092C6D-E886-4CB2-BA68-FE5A88D31DE6}_is1" = Spybot - Search & Destroy
"{B74D4E10-1033-0000-0000-000000000001}" = Adobe Bridge 1.0
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{C9E4932C-8417-4E4C-A0E3-EE534810AB4D}" = ClearType Tuning Control Panel Applet
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{D6DE02C7-1F47-11D4-9515-00105AE4B89A}" = Paint Shop Pro 7 Evaluation
"{E91E8912-769D-42F0-8408-0E329443BABC}" = Ralink Wireless LAN
"{E9787678-1033-0000-8E67-000000000001}" = Adobe Help Center 1.0
"{F0A37341-D692-11D4-A984-009027EC0A9C}" = SoundMAX
"{FC8D21C8-7B29-4104-ADB0-FEE9CA1C7922}" = Folder Size for Windows
"7-Zip" = 7-Zip 4.65
"Adobe Flash Player ActiveX" = Adobe Flash Player 11 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 11 Plugin
"Adobe Illustrator CS2" = Adobe Illustrator CS2
"Adobe Photoshop CS2 - {236BB7C4-4419-42FD-0409-1E257A25E34D}" = Adobe Photoshop CS2
"Adobe SVG Viewer" = Adobe SVG Viewer 3.0
"AviSynth" = AviSynth 2.5
"CPUID CPU-Z_is1" = CPUID CPU-Z 1.52.1
"Driver Cleaner Pro" = DH Driver Cleaner Professional Edition
"DVD Decrypter" = DVD Decrypter (Remove Only)
"ESET Online Scanner" = ESET Online Scanner v3
"Final Fantasy VII_is1" = Final Fantasy VII - Ultima Edition
"GetSavin" = GetSavin
"HiCDEject" = HiCDEject
"KLiteCodecPack_is1" = K-Lite Codec Pack 5.1.0 (Full)
"McAfee Security Scan" = McAfee Security Scan Plus
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"Microsoft Security Client" = Microsoft Security Essentials
"Mozilla Firefox 20.0.1 (x86 en-US)" = Mozilla Firefox 20.0.1 (x86 en-US)
"MozillaMaintenanceService" = Mozilla Maintenance Service
"MSCompPackV1" = Microsoft Compression Client Pack 1.0 for Windows XP
"PROSet" = Intel® PRO Network Adapters and Drivers
"RealAlt_is1" = Real Alternative 2.0.0 Lite
"SearchProtect" = Search Protect by conduit
"TransText" = TransText
"Unlocker" = Unlocker 1.8.7
"uTorrent" = µTorrent
"VLC media player" = VLC media player 1.0.3
"Windows Media Format Runtime" = Windows Media Format 11 runtime
"Windows Media Player" = Windows Media Player 11
"WMFDist11" = Windows Media Format 11 runtime
"wmp11" = Windows Media Player 11
"Wudf01000" = Microsoft User-Mode Driver Framework Feature Pack 1.0

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Dropbox" = Dropbox
"Google Chrome" = Google Chrome

========== Last 20 Event Log Errors ==========

[ Application Events ]
Error - 11/29/2012 12:52:22 PM | Computer Name = FROGPUTER | Source = MPSampleSubmission | ID = 5000
Description = EventType mptelemetry, P1 0x80070003, P2 moac, P3 cachereset, P4 4.1.522.0,
P5 unspecified, P6 unspecified, P7 unspecified, P8 NIL, P9 NIL, P10 NIL.

Error - 12/29/2012 4:42:12 PM | Computer Name = FROGPUTER | Source = MPSampleSubmission | ID = 5000
Description = EventType mptelemetry, P1 2152759308, P2 unspecified, P3 scanfile,
P4 4.1.522.0, P5 microsoft security essentials (edb4fa23-53b8-4afa-8c5d-99752cca7094),
P6 unspecified, P7 unspecified, P8 NIL, P9 NIL, P10 NIL.

Error - 2/7/2013 11:12:42 AM | Computer Name = FROGPUTER | Source = FolderSize | ID = 0
Description =

Error - 2/7/2013 11:12:43 AM | Computer Name = FROGPUTER | Source = FolderSize | ID = 0
Description =

Error - 2/7/2013 12:30:05 PM | Computer Name = FROGPUTER | Source = Microsoft Security Client | ID = 5000
Description =

Error - 2/24/2013 3:37:02 PM | Computer Name = FROGPUTER | Source = FolderSize | ID = 0
Description =

Error - 2/24/2013 3:37:09 PM | Computer Name = FROGPUTER | Source = FolderSize | ID = 0
Description =

Error - 2/24/2013 3:45:19 PM | Computer Name = FROGPUTER | Source = MsiInstaller | ID = 11706
Description =

Error - 4/19/2013 10:49:41 PM | Computer Name = FROGPUTER | Source = CltMngSvc | ID = 1000
Description =

[ System Events ]
Error - 4/28/2013 11:49:32 AM | Computer Name = FROGPUTER | Source = DCOM | ID = 10005
Description = DCOM got error "%1084" attempting to start the service EventSystem
with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF}

Error - 4/28/2013 11:50:44 AM | Computer Name = FROGPUTER | Source = Service Control Manager | ID = 7026
Description = The following boot-start or system-start driver(s) failed to load:
Fips intelppm MpFilter

Error - 4/29/2013 1:14:15 AM | Computer Name = FROGPUTER | Source = Service Control Manager | ID = 7000
Description = The helpsvc service failed to start due to the following error: %%2

Error - 4/29/2013 10:20:24 PM | Computer Name = FROGPUTER | Source = Service Control Manager | ID = 7000
Description = The helpsvc service failed to start due to the following error: %%2

Error - 4/29/2013 10:26:20 PM | Computer Name = COMPUTURD | Source = Service Control Manager | ID = 7000
Description = The helpsvc service failed to start due to the following error: %%2

Error - 4/29/2013 10:27:54 PM | Computer Name = COMPUTURD | Source = DCOM | ID = 10005
Description = DCOM got error "%1084" attempting to start the service EventSystem
with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF}

Error - 4/29/2013 10:29:11 PM | Computer Name = COMPUTURD | Source = Service Control Manager | ID = 7026
Description = The following boot-start or system-start driver(s) failed to load:
Fips intelppm MpFilter

Error - 4/29/2013 10:38:17 PM | Computer Name = COMPUTURD | Source = DCOM | ID = 10005
Description = DCOM got error "%1084" attempting to start the service wuauserv with
arguments "" in order to run the server: {E60687F7-01A1-40AA-86AC-DB1CBF673334}

Error - 4/29/2013 10:38:17 PM | Computer Name = COMPUTURD | Source = DCOM | ID = 10005
Description = DCOM got error "%1084" attempting to start the service wuauserv with
arguments "" in order to run the server: {E60687F7-01A1-40AA-86AC-DB1CBF673334}

Error - 4/29/2013 10:38:17 PM | Computer Name = COMPUTURD | Source = Microsoft Antimalware | ID = 2001
Description = %%860 has encountered an error trying to update signatures. New Signature
Version: Previous Signature Version: 1.149.667.0 Update Source: %%859 Update Stage:
%%852 Source Path: Default URL Signature Type: %%800 Update Type: %%803 User: NT AUTHORITY\SYSTEM

Current
Engine Version: Previous Engine Version: 1.1.9402.0 Error code: 0x8007043c Error
description: This service cannot be started in Safe Mode


< End of report >
Hi and Welcome!! Alexwiec :)

My name is Robybel.

I would be more than happy to take a look at your log and help you with solving any malware problems you might have. Logs can take a while to research, so please be patient and know that I am working hard to get you a clean and functional system back in your hands. I'd be grateful if you would note the following:
  • I will be working on your Malware issues, this may or may not, solve other issues you have with your machine.
  • The fixes are specific to your problem and should only be used for the issues on this machine.
  • Please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear.
  • It's often worth reading through these instructions and printing them for ease of reference.
  • If you don't know or understand something, please don't hesitate to say or ask!! It's better to be sure and safe than sorry.
  • Please reply to this thread. Do not start a new topic.

IMPORTANT NOTE : Please do not delete, download or install anything unless instructed to do so.
DO NOT use any TOOLS such as Combofix or HijackThis fixes without supervision. Doing so could make your system inoperable and could require a full reinstall of your Operating System and losing all your programs and data.


Vista and Windows 7 users:

These tools MUST be run from the executable. (.exe) every time you run them
with Admin Rights (Right click, choose "Run as Administrator")


Stay with this topic until I give you the all clean post.

Having said that….Let's get going!! ;)

===============================

Please reply to this post ;)
I read some directions about downloading FRST to a flash drive. I did that last night and planned on continuing with its directions but those directions are NO WHERE to be found. What should be done from here?
Hi Alexwiec ;)

I read some directions about downloading FRST to a flash drive. I did that last night and planned on continuing with its directions but those directions are NO WHERE to be found.

FRST don't work with XP.


Reboot into Safe Mode with Networking

How to enter safe mode(XP/Vista)
Using the F8 Method

Restart your computer.
When the machine first starts again it will generally list some equipment that is installed in your machine, amount of memory, hard drives installed etc. At this point you should gently tap the F8 key repeatedly until you are presented with a Windows XP Advanced Options menu.
Select the option for Safe Mode with Networking using the arrow keys.
Then press enter on your keyboard to boot into Safe Mode.


NEXT

Please read through these instructions to familarize yourself with what to expect when this tool runs

Refer to the ComboFix User's Guide

Download ComboFix from one of these locations:

Link 1
Link 2


* IMPORTANT- Save ComboFix.exe to your Desktop

====================================================

Disable your AntiVirus and AntiSpyware applications as they will interfere with our tools and the removal. If you are unsure how to do this, please refer to our sticky topic How to disable your security applications

====================================================


Double click on ComboFix.exe & follow the prompts.

  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.


[external image: Posted Image]


Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:


[external image: Posted Image]


Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply for further review.
I reopen the thread

alexwiec

Please subscribe to this thread to get immediate notification of replies as soon as they are posted.

To do this, click Options, then click Subscribe to this Thread. Under the Forum Subscription: Virus, Spyware & Malware Removal: title, make sure it is set to Immediate email Notification, then click Proceed.
Please be patient with me during this time.

Please reply to this post
C:\ComboFix.txt

ComboFix 13-05-18.04 - lointusk 05/20/2013 3:00.8.1 - x86 NETWORK
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1278.840 [GMT -6:00]
Running from: c:\documents and settings\[removed]\My Documents\Downloads\ComboFix.exe
AV: Microsoft Security Essentials *Disabled/Updated* {EDB4FA23-53B8-4AFA-8C5D-99752CCA7095}
.
.
((((((((((((((((((((((((( Files Created from 2013-04-20 to 2013-05-20 )))))))))))))))))))))))))))))))
.
.
2013-05-20 04:14 . 2013-05-13 06:19 7016152 —-a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{5D524554-8714-4565-99DF-0842C228C48D}\mpengine.dll
2013-05-03 05:08 . 2013-05-03 05:08 ——– d—–w- c:\documents and settings\lointusk\Local Settings\Application Data\Conduit
2013-04-28 14:56 . 2013-04-28 14:56 ——– d—–w- C:\TDSSKiller_Quarantine
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2013-04-20 03:43 . 2013-02-18 07:14 693976 —-a-w- c:\windows\system32\FlashPlayerApp.exe
2013-04-20 03:43 . 2013-02-18 07:14 73432 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2013-04-10 03:08 . 2006-01-05 05:02 6906960 —-a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
2013-04-02 10:33 . 2012-11-29 16:55 237088 ——w- c:\windows\system32\MpSigStub.exe
2013-03-08 08:35 . 2009-08-05 19:55 293376 —-a-w- c:\windows\system32\winsrv.dll
2013-03-07 01:28 . 2009-02-06 11:08 2193408 —-a-w- c:\windows\system32\ntoskrnl.exe
2013-03-07 00:50 . 2009-02-07 23:02 2070016 —-a-w- c:\windows\system32\ntkrnlpa.exe
2013-03-02 02:05 . 2009-07-03 17:06 920064 —-a-w- c:\windows\system32\wininet.dll
2013-03-02 02:05 . 2009-08-05 21:06 43520 —-a-w- c:\windows\system32\licmgr10.dll
2013-03-02 02:05 . 2009-07-03 17:06 1469440 —-a-w- c:\windows\system32\inetcpl.cpl
2013-03-02 01:25 . 2009-04-17 12:26 1867264 —-a-w- c:\windows\system32\win32k.sys
2013-03-02 01:08 . 2009-03-08 02:35 385024 —-a-w- c:\windows\system32\html.iec
2013-02-27 05:31 . 2009-10-19 18:06 2691072 —-a-w- c:\windows\system32\mstscax.dll
2013-02-27 05:31 . 2009-10-10 17:00 36864 —-a-w- c:\windows\system32\tsgqec.dll
2013-02-27 05:31 . 2009-10-10 17:00 131072 —-a-w- c:\windows\system32\aaclient.dll
2013-04-15 01:59 . 2013-04-15 01:59 263064 —-a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1]
@="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}]
2012-11-13 23:32 129272 —-a-w- c:\documents and settings\lointusk\Application Data\Dropbox\bin\DropboxExt.17.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2]
@="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}]
2012-11-13 23:32 129272 —-a-w- c:\documents and settings\lointusk\Application Data\Dropbox\bin\DropboxExt.17.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3]
@="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}]
2012-11-13 23:32 129272 —-a-w- c:\documents and settings\lointusk\Application Data\Dropbox\bin\DropboxExt.17.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt4]
@="{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}]
2012-11-13 23:32 129272 —-a-w- c:\documents and settings\lointusk\Application Data\Dropbox\bin\DropboxExt.17.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DAEMON Tools"="c:\program files\DAEMON Tools\daemon.exe" [2007-04-03 165784]
"SearchProtect"="c:\documents and settings\lointusk\Application Data\SearchProtect\bin\cltmng.exe" [2013-04-11 2730784]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2013-01-27 947152]
"SearchProtectAll"="c:\program files\SearchProtect\bin\cltmng.exe" [2013-04-11 2730784]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"_nltide_3"="advpack.dll" [2009-08-05 128512]
.
c:\documents and settings\lointusk\Start Menu\Programs\Startup\
Adobe Gamma.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2005-3-16 113664]
Dropbox.lnk - c:\documents and settings\lointusk\Application Data\Dropbox\bin\Dropbox.exe [2013-3-12 29106336]
.
c:\documents and settings\All Users\Start Menu\Programs\Startup\
HiCDEject.lnk - c:\program files\HiCDEject\HiCDEject.exe [2001-2-13 9248]
McAfee Security Scan Plus.lnk - c:\program files\McAfee Security Scan\3.0.318\SSScheduler.exe [2013-2-5 272248]
.
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoResolveTrack"= 1 (0x1)
"NoSMConfigurePrograms"= 1 (0x1)
.
[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"NoSMHelp"= 1 (0x1)
"ForceClassicControlPanel"= 1 (0x1)
"NoResolveTrack"= 1 (0x1)
"NoSMConfigurePrograms"= 1 (0x1)
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"
.
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"Google Update"="c:\documents and settings\lointusk\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" /c
"ctfmon.exe"=c:\windows\system32\ctfmon.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"SoundMAXPnP"=c:\program files\Analog Devices\Core\smax4pnp.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"DisableUnicastResponsesToMulticastBroadcast"= 0 (0x0)
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\utorrent\\utorrent.exe"=
"c:\\Documents and Settings\\lointusk\\Application Data\\Dropbox\\bin\\Dropbox.exe"=
.
S1 MpKsl665f91f5;MpKsl665f91f5;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{CCAEA136-05A8-4064-9BEB-3538D6C593AD}\MpKsl665f91f5.sys –> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{CCAEA136-05A8-4064-9BEB-3538D6C593AD}\MpKsl665f91f5.sys [?]
S2 CltMngSvc;Search Protect by Conduit Updater;c:\program files\SearchProtect\bin\CltMngSvc.exe [4/11/2013 8:28 AM 93984]
S3 McComponentHostService;McAfee Security Scan Component Host Service;c:\program files\McAfee Security Scan\3.0.318\McCHSvc.exe [2/5/2013 9:48 AM 235216]
.
Contents of the 'Scheduled Tasks' folder
.
2013-04-27 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2013-02-18 03:43]
.
2006-01-05 c:\windows\Tasks\AmiUpdXp.job
- c:\documents and settings\lointusk\Application Data\SwvUpdater\Updater.exe [2013-04-20 02:44]
.
2013-04-30 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-07-26 06:32]
.
2013-04-27 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-07-26 06:32]
.
2013-04-27 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1482476501-1123561945-1644491937-1001Core.job
- c:\documents and settings\lointusk\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2010-05-02 19:27]
.
2013-04-27 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1482476501-1123561945-1644491937-1001UA.job
- c:\documents and settings\lointusk\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2010-05-02 19:27]
.
2013-05-20 c:\windows\Tasks\MpIdleTask.job
- c:\program files\Microsoft Security Client\MpCmdRun.exe [2013-01-27 18:11]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.google.com
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office10\EXCEL.EXE/3000
TCP: DhcpNameServer = 192.168.0.1 [removed]
TCP: Interfaces\{3C2F8020-1F67-43A0-B7E4-678FBBA60FBA}: NameServer = 192.168.0.1
TCP: Interfaces\{58FA7B8E-4E10-4456-906A-8DF7B9D15259}: NameServer = 192.168.0.1
TCP: Interfaces\{595FCF1C-C74B-46AE-B3B1-6CD47E0297D6}: NameServer = 192.168.0.1
TCP: Interfaces\{6A9C593A-3C2B-4D4A-9DBD-6DB76CA920C6}: NameServer = 192.168.0.1
TCP: Interfaces\{8DF4D200-5EF5-45C5-B945-C7DFAE8DE4FA}: NameServer = 192.168.0.1
TCP: Interfaces\{9F9D5D91-3B90-408F-94E8-D822F7C38B25}: NameServer = 192.168.0.1
FF - ProfilePath - c:\documents and settings\lointusk\Application Data\Mozilla\Firefox\Profiles\p2g3ajml.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT3289847&CUI=UN12486887918752630&UM=2&SearchSource=3&q={searchTerms}
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - google.com
FF - prefs.js: keyword.URL - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT3289847&SearchSource=2&CUI=UN12486887918752630&UM=2&q=
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2013-05-20 03:05
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes …
.
scanning hidden autostart entries …
.
scanning hidden files …
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil32_11_6_602_180_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil32_11_6_602_180_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
——————— DLLs Loaded Under Running Processes ———————
.
- - - - - - - > 'explorer.exe'(1396)
c:\windows\system32\WININET.dll
c:\documents and settings\lointusk\Application Data\Dropbox\bin\DropboxExt.17.dll
.
Completion time: 2013-05-20 03:07:40
ComboFix-quarantined-files.txt 2013-05-20 09:07
ComboFix2.txt 2013-04-28 15:15
ComboFix3.txt 2013-02-18 20:36
ComboFix4.txt 2013-02-16 23:05
ComboFix5.txt 2013-05-20 08:58
.
Pre-Run: 2,365,804,544 bytes free
Post-Run: 2,354,745,344 bytes free
.
- - End Of File - - 3A261CE6AE1C11E545738E6A24E74E23
Hi alexwiec

Welcome back

Download Security Check by screen317 from here or here.
  • Save it to your Desktop.
  • Double click SecurityCheck.exe and follow the onscreen instructions inside of the black box.
  • A Notepad document should open automatically called checkup.txt; please post the contents of that document.

Next

AdwCleaner

  • Please download AdwCleaner by Xplode onto your desktop.
  • Close all open programs and internet browsers.
  • Double click on AdwCleaner.exe to run the tool.
  • Click on Delete.
  • Confirm each time with Ok.
  • Your computer will be rebooted automatically. A text file will open after the restart.
  • Please post the content of that logfile with your next answer.
  • You can find the logfile at C:\AdwCleaner[S1].txt as well.

Next


  • Download RogueKiller and save it to your desktop.
  • Quit all other programs
  • Start RogueKiller.exe
  • Wait until the Prescan has finished …
  • Click on Scan
    [external image: Posted Image]
  • Wait for the end of the scan
  • A report will be created on your desktop.
  • Click on the Delete button
    [external image: Posted Image]
  • Next click on the ShortcutsFix
    [external image: Posted Image]
  • another report will be created on your desktop.

Please post: All RKreport.txt text files located on your desktop.

On your next reply please post :
  • checkup.txt
  • AdwCleaner[S1].txt
  • All RKreport.txt

Let me know if you have any problems in performing with the steps above or any questions you may have.

Good Day!
Results of screen317's Security Check version 0.99.63
Windows XP Service Pack 3 x86
Internet Explorer 8
``````````````Antivirus/Firewall Check:``````````````
Windows Security Center service is not running! This report may not be accurate!
Windows Firewall Enabled!
Please wait while WMIC is being installed.d
i
s
p
l
a
y
N
a
m
e
ECHO is off.
M
i
c
r
o
s
o
f
t
ECHO is off.
S
e
c
u
r
i
t
y
ECHO is off.
E
s
e
n
t
i
a
l
s
ECHO is off.
Antivirus up to date! (On Access scanning disabled!)
`````````Anti-malware/Other Utilities Check:`````````
Spybot - Search & Destroy
DH Driver Cleaner Professional Edition
Adobe Flash Player 11.6.602.180
Mozilla Firefox (20.0.1)
````````Process Check: objlist.exe by Laurent````````
Microsoft Security Essentials MSMpEng.exe
`````````````````System Health check`````````````````
Total Fragmentation on Drive C:: 12% Defragment your hard drive soon! (Do NOT defrag if SSD!)
````````````````````End of Log``````````````````````
# AdwCleaner v2.111 - Logfile created 02/08/2013 at 10:39:38 # Updated 05/02/2013 by Xplode # Operating system : Microsoft Windows XP Service Pack 3 (32 bits) # User : lointusk - FROGPUTER # Boot Mode : Normal # Running from : C:\Documents and Settings\lointusk\My Documents\Downloads\AdwCleaner.exe # Option [Delete] ***** [Services] ***** ***** [Files / Folders] ***** File Deleted : C:\Documents and Settings\lointusk\Application Data\Mozilla\Firefox\Profiles\p2g3ajml.default\searchplugins\Conduit.xml File Deleted : C:\END Folder Deleted : C:\Documents and Settings\All Users\Application Data\Trymedia Folder Deleted : C:\Documents and Settings\lointusk\Application Data\Mozilla\Firefox\Profiles\p2g3ajml.default\Smartbar Folder Deleted : C:\Documents and Settings\lointusk\Application Data\PerformerSoft Folder Deleted : C:\Documents and Settings\lointusk\Local Settings\Application Data\Conduit Folder Deleted : C:\Program Files\Conduit Folder Deleted : C:\Program Files\file scout ***** [Registry] ***** Key Deleted : HKCU\Software\Conduit Key Deleted : HKCU\Software\ConduitSearchScopes Key Deleted : HKCU\Software\Cr_Installer Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{AFDBDDAA-5D3F-42EE-B79C-185A7020515B} Key Deleted : HKCU\Software\SmartBar Key Deleted : HKCU\Software\Softonic Key Deleted : HKLM\SOFTWARE\Classes\AppID\{D616A4A2-7B38-4DBC-9093-6FE7A4A21B17} Key Deleted : HKLM\SOFTWARE\Classes\Toolbar.CT3227981 Key Deleted : HKLM\Software\Conduit Key Deleted : HKLM\SYSTEM\CurrentControlSet\Services\Eventlog\Application\WajamUpdater Value Deleted : HKCU\Software\Microsoft\Internet Explorer\New Windows\Allow [*.crossrider.com] Value Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion [adv_i] Value Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\New Windows\Allow [*.crossrider.com] Value Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion [adv_i] ***** [Internet Browsers] ***** -\\ Internet Explorer v8.0.6001.18702 Replaced : [HKCU\Software\Microsoft\Internet Explorer\Main - Start Page] = hxxp://search.conduit.com?SearchSource=10&CUI=UN19366646962045124&ctid=CT3227981 –> hxxp://www.google.com -\\ Mozilla Firefox v18.0.2 (en-US) File : C:\Documents and Settings\lointusk\Application Data\Mozilla\Firefox\Profiles\p2g3ajml.default\prefs.js Deleted : user_pref("CT3227981.1000082.isPlayDisplay", "true"); Deleted : user_pref("CT3227981.1000082.state", "{\"state\":\"stopped\",\"text\":\"1.FM (Cou…\",\"description[…] Deleted : user_pref("CT3227981.ENABALE_HISTORY", "{\"dataType\":\"string\",\"data\":\"true\"}"); Deleted : user_pref("CT3227981.ENABLE_RETURN_WEB_SEARCH_ON_THE_PAGE", "{\"dataType\":\"string\",\"data\":\"tru[…] Deleted : user_pref("CT3227981.FirstTime", "true"); Deleted : user_pref("CT3227981.FirstTimeFF3", "true"); Deleted : user_pref("CT3227981.LoginRevertSettingsEnabled", true); Deleted : user_pref("CT3227981.PG_ENABLE", "dHJ1ZQ=="); Deleted : user_pref("CT3227981.PG_ENABLE.enc", "dHJ1ZQ=="); Deleted : user_pref("CT3227981.RevertSettingsEnabled", true); Deleted : user_pref("CT3227981.SearchFromAddressBarUrl", "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT322[…] Deleted : user_pref("CT3227981.UserID", "UN18800627841166447"); Deleted : user_pref("CT3227981.addressBarTakeOverEnabledInHidden", "true"); Deleted : user_pref("CT3227981.autoDisableScopes", -1); Deleted : user_pref("CT3227981.bDay_InstallDate.enc", "Ny0x"); Deleted : user_pref("CT3227981.bDay_InstallFromToolbar.enc", "eWVz"); Deleted : user_pref("CT3227981.browser.search.defaultthis.engineName", "true"); Deleted : user_pref("CT3227981.cbfirsttime.enc", "VGh1IEZlYiAwNyAyMDEzIDAwOjI3OjUwIEdNVC0wNzAwIChNb3VudGFpbiBT[…] Deleted : user_pref("CT3227981.defaultSearch", "true"); Deleted : user_pref("CT3227981.embeddedsData", "[{\"appId\":\"129837882913311618\",\"apiPermissions\":{\"cross[…] Deleted : user_pref("CT3227981.enableAlerts", "always"); Deleted : user_pref("CT3227981.enableFix404ByUser", "FALSE"); Deleted : user_pref("CT3227981.enableSearchFromAddressBar", "true"); Deleted : user_pref("CT3227981.firstTimeDialogOpened", "true"); Deleted : user_pref("CT3227981.fixPageNotFoundError", "true"); Deleted : user_pref("CT3227981.fixPageNotFoundErrorByUser", "true"); Deleted : user_pref("CT3227981.fixPageNotFoundErrorInHidden", "true"); Deleted : user_pref("CT3227981.fixUrls", true); Deleted : user_pref("CT3227981.harvest_last_targeted_visit_absolutelyrics.com.enc", "bnVsbA=="); Deleted : user_pref("CT3227981.harvest_last_targeted_visit_azlyrics.com.enc", "bnVsbA=="); Deleted : user_pref("CT3227981.harvest_last_targeted_visit_bollywoodlyrics.com.enc", "bnVsbA=="); Deleted : user_pref("CT3227981.harvest_last_targeted_visit_cowboylyrics.org.enc", "bnVsbA=="); Deleted : user_pref("CT3227981.harvest_last_targeted_visit_darklyrics.com.enc", "bnVsbA=="); Deleted : user_pref("CT3227981.harvest_last_targeted_visit_elyrics.net.enc", "bnVsbA=="); Deleted : user_pref("CT3227981.harvest_last_targeted_visit_hindilyrix.com.enc", "bnVsbA=="); Deleted : user_pref("CT3227981.harvest_last_targeted_visit_hitslyrics.com.enc", "bnVsbA=="); Deleted : user_pref("CT3227981.harvest_last_targeted_visit_leoslyrics.com.enc", "bnVsbA=="); Deleted : user_pref("CT3227981.harvest_last_targeted_visit_letssingit.com.enc", "bnVsbA=="); Deleted : user_pref("CT3227981.harvest_last_targeted_visit_lyred.com.enc", "bnVsbA=="); Deleted : user_pref("CT3227981.harvest_last_targeted_visit_lyricinterpretations.com.enc", "bnVsbA=="); Deleted : user_pref("CT3227981.harvest_last_targeted_visit_lyrics-p.com.enc", "bnVsbA=="); Deleted : user_pref("CT3227981.harvest_last_targeted_visit_lyrics.com.enc", "bnVsbA=="); Deleted : user_pref("CT3227981.harvest_last_targeted_visit_lyricsdepot.com.enc", "bnVsbA=="); Deleted : user_pref("CT3227981.harvest_last_targeted_visit_lyricsfind.com.enc", "bnVsbA=="); Deleted : user_pref("CT3227981.harvest_last_targeted_visit_lyricsfreak.com.enc", "bnVsbA=="); Deleted : user_pref("CT3227981.harvest_last_targeted_visit_lyricsmania.com.enc", "bnVsbA=="); Deleted : user_pref("CT3227981.harvest_last_targeted_visit_lyricsmode.com.enc", "bnVsbA=="); Deleted : user_pref("CT3227981.harvest_last_targeted_visit_lyricsocean.com.enc", "bnVsbA=="); Deleted : user_pref("CT3227981.harvest_last_targeted_visit_lyricsondemand.com.enc", "bnVsbA=="); Deleted : user_pref("CT3227981.harvest_last_targeted_visit_lyricsoverload.com.enc", "bnVsbA=="); Deleted : user_pref("CT3227981.harvest_last_targeted_visit_lyricsplanet.com.enc", "bnVsbA=="); Deleted : user_pref("CT3227981.harvest_last_targeted_visit_metrolyrics.com.enc", "bnVsbA=="); Deleted : user_pref("CT3227981.harvest_last_targeted_visit_mp3lyrics.org.enc", "bnVsbA=="); Deleted : user_pref("CT3227981.harvest_last_targeted_visit_nomorelyrics.net.enc", "bnVsbA=="); Deleted : user_pref("CT3227981.harvest_last_targeted_visit_oldielyrics.com.enc", "bnVsbA=="); Deleted : user_pref("CT3227981.harvest_last_targeted_visit_onlylyrics.com.enc", "bnVsbA=="); Deleted : user_pref("CT3227981.harvest_last_targeted_visit_plyrics.com.enc", "bnVsbA=="); Deleted : user_pref("CT3227981.harvest_last_targeted_visit_rapgenius.com.enc", "bnVsbA=="); Deleted : user_pref("CT3227981.harvest_last_targeted_visit_songlyrics.com.enc", "bnVsbA=="); Deleted : user_pref("CT3227981.harvest_last_targeted_visit_songmeanings.net.enc", "bnVsbA=="); Deleted : user_pref("CT3227981.harvest_last_targeted_visit_stlyrics.com.enc", "bnVsbA=="); Deleted : user_pref("CT3227981.harvest_last_targeted_visit_sweetslyrics.com.enc", "bnVsbA=="); Deleted : user_pref("CT3227981.harvest_last_targeted_visit_thelyricarchive.com.enc", "bnVsbA=="); Deleted : user_pref("CT3227981.harvest_last_targeted_visit_uplyrics.com.enc", "bnVsbA=="); Deleted : user_pref("CT3227981.harvest_last_targeted_visit_urbanlyrics.com.enc", "bnVsbA=="); Deleted : user_pref("CT3227981.harvest_post_urls_absolutelyrics.com.enc", "bnVsbA=="); Deleted : user_pref("CT3227981.harvest_post_urls_azlyrics.com.enc", "bnVsbA=="); Deleted : user_pref("CT3227981.harvest_post_urls_bollywoodlyrics.com.enc", "bnVsbA=="); Deleted : user_pref("CT3227981.harvest_post_urls_cowboylyrics.org.enc", "bnVsbA=="); Deleted : user_pref("CT3227981.harvest_post_urls_darklyrics.com.enc", "bnVsbA=="); Deleted : user_pref("CT3227981.harvest_post_urls_elyrics.net.enc", "bnVsbA=="); Deleted : user_pref("CT3227981.harvest_post_urls_hindilyrix.com.enc", "bnVsbA=="); Deleted : user_pref("CT3227981.harvest_post_urls_hitslyrics.com.enc", "bnVsbA=="); Deleted : user_pref("CT3227981.harvest_post_urls_leoslyrics.com.enc", "bnVsbA=="); Deleted : user_pref("CT3227981.harvest_post_urls_letssingit.com.enc", "bnVsbA=="); Deleted : user_pref("CT3227981.harvest_post_urls_lyred.com.enc", "bnVsbA=="); Deleted : user_pref("CT3227981.harvest_post_urls_lyricinterpretations.com.enc", "bnVsbA=="); Deleted : user_pref("CT3227981.harvest_post_urls_lyrics-p.com.enc", "bnVsbA=="); Deleted : user_pref("CT3227981.harvest_post_urls_lyrics.com.enc", "bnVsbA=="); Deleted : user_pref("CT3227981.harvest_post_urls_lyricsdepot.com.enc", "bnVsbA=="); Deleted : user_pref("CT3227981.harvest_post_urls_lyricsfind.com.enc", "bnVsbA=="); Deleted : user_pref("CT3227981.harvest_post_urls_lyricsfreak.com.enc", "bnVsbA=="); Deleted : user_pref("CT3227981.harvest_post_urls_lyricsmania.com.enc", "bnVsbA=="); Deleted : user_pref("CT3227981.harvest_post_urls_lyricsmode.com.enc", "bnVsbA=="); Deleted : user_pref("CT3227981.harvest_post_urls_lyricsocean.com.enc", "bnVsbA=="); Deleted : user_pref("CT3227981.harvest_post_urls_lyricsondemand.com.enc", "bnVsbA=="); Deleted : user_pref("CT3227981.harvest_post_urls_lyricsoverload.com.enc", "bnVsbA=="); Deleted : user_pref("CT3227981.harvest_post_urls_lyricsplanet.com.enc", "bnVsbA=="); Deleted : user_pref("CT3227981.harvest_post_urls_metrolyrics.com.enc", "bnVsbA=="); Deleted : user_pref("CT3227981.harvest_post_urls_mp3lyrics.org.enc", "bnVsbA=="); Deleted : user_pref("CT3227981.harvest_post_urls_nomorelyrics.net.enc", "bnVsbA=="); Deleted : user_pref("CT3227981.harvest_post_urls_oldielyrics.com.enc", "bnVsbA=="); Deleted : user_pref("CT3227981.harvest_post_urls_onlylyrics.com.enc", "bnVsbA=="); Deleted : user_pref("CT3227981.harvest_post_urls_plyrics.com.enc", "bnVsbA=="); Deleted : user_pref("CT3227981.harvest_post_urls_rapgenius.com.enc", "bnVsbA=="); Deleted : user_pref("CT3227981.harvest_post_urls_songlyrics.com.enc", "bnVsbA=="); Deleted : user_pref("CT3227981.harvest_post_urls_songmeanings.net.enc", "bnVsbA=="); Deleted : user_pref("CT3227981.harvest_post_urls_stlyrics.com.enc", "bnVsbA=="); Deleted : user_pref("CT3227981.harvest_post_urls_sweetslyrics.com.enc", "bnVsbA=="); Deleted : user_pref("CT3227981.harvest_post_urls_thelyricarchive.com.enc", "bnVsbA=="); Deleted : user_pref("CT3227981.harvest_post_urls_uplyrics.com.enc", "bnVsbA=="); Deleted : user_pref("CT3227981.harvest_post_urls_urbanlyrics.com.enc", "bnVsbA=="); Deleted : user_pref("CT3227981.harvest_recent.enc", "W1siaHR0cHM6Ly93d3cuZ29vZ2xlLmNvbS9zZWFyY2g/cT1tcytwYWlud[…] Deleted : user_pref("CT3227981.installDate", "7/2/2013 0:25:35"); Deleted : user_pref("CT3227981.installId", "installbrain"); Deleted : user_pref("CT3227981.installType", "conduitnsisintegration"); Deleted : user_pref("CT3227981.isCheckedStartAsHidden", true); Deleted : user_pref("CT3227981.isEnableAllDialogs", "{\"dataType\":\"string\",\"data\":\"true\"}"); Deleted : user_pref("CT3227981.isFirstTimeToolbarLoading", "false"); Deleted : user_pref("CT3227981.isToolbarShrinked", "{\"dataType\":\"string\",\"data\":\"false\"}"); Deleted : user_pref("CT3227981.keyword", "true"); Deleted : user_pref("CT3227981.lastNewTabSettings", "{\"isEnabled\":true,\"newTabUrl\":\"hxxp://search.conduit[…] Deleted : user_pref("CT3227981.lastVersion", "10.14.42.7"); Deleted : user_pref("CT3227981.mam_gk_AdOptimizer_appState.enc", "b24="); Deleted : user_pref("CT3227981.mam_gk_Coming_Up_Next_appState.enc", "b24="); Deleted : user_pref("CT3227981.mam_gk_CouponBuddy_appState.enc", "b24="); Deleted : user_pref("CT3227981.mam_gk_PriceGong_appState.enc", "b24="); Deleted : user_pref("CT3227981.mam_gk_appsData.enc", "eyJhcHBzIjpbeyJpZCI6IlByaWNlR29uZyIsInVybCI6Imh0dHA6Ly9z[…] Deleted : user_pref("CT3227981.mam_gk_appsDefaultEnabled.enc", "bnVsbA=="); Deleted : user_pref("CT3227981.mam_gk_configuration.enc", "eyJjb25maWd1cmF0aW9uIjpbeyJpZCI6IlByaWNlR29uZyIsImN[…] Deleted : user_pref("CT3227981.mam_gk_currentVersion.enc", "MS4yLjAuMTI="); Deleted : user_pref("CT3227981.mam_gk_eventsCache.enc", "eyI0YTEyNzU5Ni0wYzc0LTRhYTgtOWZkNS1iNTM2M2JhYjA2MDciO[…] Deleted : user_pref("CT3227981.mam_gk_first_time.enc", "MQ=="); Deleted : user_pref("CT3227981.mam_gk_gadgetOpen.enc", "MQ=="); Deleted : user_pref("CT3227981.mam_gk_installer_preapproved.enc", "ZmFsc2U="); Deleted : user_pref("CT3227981.mam_gk_lastLoginTime.enc", "MTM2MDIyMjA1Njk2OA=="); Deleted : user_pref("CT3227981.mam_gk_localization.enc", "eyJnYWRnZXRDb250ZW50UG9saWN5Ijp7IlRleHQiOiJDb250ZW50[…] Deleted : user_pref("CT3227981.mam_gk_pgUnloadedOnce.enc", "dHJ1ZQ=="); Deleted : user_pref("CT3227981.mam_gk_settings1.2.0.12.enc", "eyJTdGF0dXMiOiJzdWNjZWVkZWQiLCJEYXRhIjp7ImludGVy[…] Deleted : user_pref("CT3227981.mam_gk_showCloseButton.enc", "dHJ1ZQ=="); Deleted : user_pref("CT3227981.mam_gk_showWelcomeGadget.enc", "ZmFsc2U="); Deleted : user_pref("CT3227981.mam_gk_userId.enc", "MDAzNGE2OTktYjQ0NC00NzBiLTlhYWYtZjJjMDE2ZDQwNjU5"); Deleted : user_pref("CT3227981.mam_gk_user_apps_selection.enc", ""); Deleted : user_pref("CT3227981.migrateAppsAndComponents", true); Deleted : user_pref("CT3227981.myThings_app_locale.enc", "VVM="); Deleted : user_pref("CT3227981.navigationAliasesJson", "{\"EB_SEARCH_TERM\":\"\",\"EB_MAIN_FRAME_URL\":\"about[…] Deleted : user_pref("CT3227981.openThankYouPage", "false"); Deleted : user_pref("CT3227981.openUninstallPage", "true"); Deleted : user_pref("CT3227981.revertSettingsEnabled", "false"); Deleted : user_pref("CT3227981.sac-periodic-reports.enc", "eyJ5dHRfcGluZ18wIjpbMTM2MDIyMjA3MTE1MSw0MzIwMDAwMF1[…] Deleted : user_pref("CT3227981.sac-user-ab-groups.enc", "eyJsZWZ0aGFuZF9kZXNpZ24iOjk4LCJ0cmlnZ2VyIjo5NH0="); Deleted : user_pref("CT3227981.sac-user-id.enc", "ImIwNjhjZWY5LWYxNzctNDk3Yy05ODQ5LWMzMTM5M2M1NmE0MSI="); Deleted : user_pref("CT3227981.sac-yt-first-ping.enc", "MTM2MDIyMjA3MTEzNg=="); Deleted : user_pref("CT3227981.search.searchAppId", "129837882913311618"); Deleted : user_pref("CT3227981.search.searchCount", "0"); Deleted : user_pref("CT3227981.searchInNewTabEnabledByUser", "true"); Deleted : user_pref("CT3227981.searchInNewTabEnabledInHidden", "true"); Deleted : user_pref("CT3227981.selectToSearchBoxEnabled", "{\"dataType\":\"string\",\"data\":\"true\"}"); Deleted : user_pref("CT3227981.serviceLayer_service_login_isFirstLoginInvoked", "{\"dataType\":\"boolean\",\"d[…] Deleted : user_pref("CT3227981.serviceLayer_service_login_loginCount", "{\"dataType\":\"number\",\"data\":\"4\[…] Deleted : user_pref("CT3227981.serviceLayer_service_toolbarGrouping_activeCTID", "{\"dataType\":\"string\",\"d[…] Deleted : user_pref("CT3227981.serviceLayer_service_toolbarGrouping_activeDownloadUrl", "{\"dataType\":\"strin[…] Deleted : user_pref("CT3227981.serviceLayer_service_toolbarGrouping_activeToolbarName", "{\"dataType\":\"strin[…] Deleted : user_pref("CT3227981.serviceLayer_service_toolbarGrouping_invoked", "{\"dataType\":\"string\",\"data[…] Deleted : user_pref("CT3227981.serviceLayer_services_appTrackingFirstTime_lastUpdate", "1360222023505"); Deleted : user_pref("CT3227981.serviceLayer_services_appsMetadata_lastUpdate", "1360222023191"); Deleted : user_pref("CT3227981.serviceLayer_services_gottenAppsContextMenu_lastUpdate", "1360222022776"); Deleted : user_pref("CT3227981.serviceLayer_services_login_10.14.42.7_lastUpdate", "1360222024239"); Deleted : user_pref("CT3227981.serviceLayer_services_otherAppsContextMenu_lastUpdate", "1360222023000"); Deleted : user_pref("CT3227981.serviceLayer_services_searchAPI_lastUpdate", "1360221971581"); Deleted : user_pref("CT3227981.serviceLayer_services_serviceMap_lastUpdate", "1360221970791"); Deleted : user_pref("CT3227981.serviceLayer_services_toolbarContextMenu_lastUpdate", "1360222022411"); Deleted : user_pref("CT3227981.serviceLayer_services_toolbarSettings_lastUpdate", "1360221971202"); Deleted : user_pref("CT3227981.serviceLayer_services_translation_lastUpdate", "1360222023299"); Deleted : user_pref("CT3227981.settingsINI", true); Deleted : user_pref("CT3227981.shouldFirstTimeDialog", "false"); Deleted : user_pref("CT3227981.smartbar.CTID", "CT3227981"); Deleted : user_pref("CT3227981.smartbar.Uninstall", "0"); Deleted : user_pref("CT3227981.smartbar.homepage", "true"); Deleted : user_pref("CT3227981.smartbar.toolbarName", "appbario7 "); Deleted : user_pref("CT3227981.startPage", "true"); Deleted : user_pref("CT3227981.toolbarBornServerTime", "7-2-2013"); Deleted : user_pref("CT3227981.toolbarCurrentServerTime", "7-2-2013"); Deleted : user_pref("CT3227981.toolbarDisabled", "true"); Deleted : user_pref("CT3227981.url_history0001.enc", "aHR0cHM6Ly93d3cuZ29vZ2xlLmNvbTo6OmNsaWNraGFuZGxlcjo6OjEz[…] Deleted : user_pref("CT3227981.ytt-mam-test-uid-odc.enc", "NzYwMjdkMzQtNmE0Ny00MmIwLTk2OWItZWVhMThlMTYzY2E0"); Deleted : user_pref("CT3227981.ytt-mam-test-uid-ol.enc", "OWNiMjRlZTctNWNiNi00Y2E2LWEzYmQtNTk2Y2JlNDE5MDlk"); Deleted : user_pref("CT3227981_Firefox.csv", "[{\"from\":\"Abs Layer\",\"action\":\"loading toolbar\",\"time\"[…] Deleted : user_pref("Smartbar.ConduitHomepagesList", "hxxp://search.conduit.com/?ctid=CT3227981&SearchSource=1[…] Deleted : user_pref("Smartbar.ConduitSearchEngineList", "appbario7 Customized Web Search"); Deleted : user_pref("Smartbar.ConduitSearchUrlList", "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT3227981[…] Deleted : user_pref("Smartbar.SearchFromAddressBarSavedUrl", ""); Deleted : user_pref("Smartbar.keywordURLSelectedCTID", "CT3227981"); Deleted : user_pref("browser.search.defaultthis.engineName", "appbario7 Customized Web Search"); Deleted : user_pref("browser.search.defaulturl", "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT3227981&Sea[…] Deleted : user_pref("ct3227981.UserID", "UN18800627841166447"); Deleted : user_pref("keyword.URL", "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT3227981&SearchSource=2&CU[…] Deleted : user_pref("smartbar.conduitHomepageList", "hxxp://search.conduit.com/?ctid=CT3227981&SearchSource=13[…] Deleted : user_pref("smartbar.conduitSearchAddressUrlList", "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT[…] Deleted : user_pref("smartbar.originalHomepage", "about:home"); Deleted : user_pref("smartbar.originalSearchAddressUrl", ""); Deleted : user_pref("smartbar.originalSearchEngine", "Google"); -\\ Google Chrome v24.0.1312.57 File : C:\Documents and Settings\lointusk\Local Settings\Application Data\Google\Chrome\User Data\Default\Preferences Deleted [l.19] : urls_to_restore_on_startup = [ "hxxp://search.conduit.com/?CUI=UN34305538161159317&ctid=CT[…] Deleted [l.2149] : urls_to_restore_on_startup = [ "hxxp://search.conduit.com/?CUI=UN34305538161159317&ctid=CT322[…] ************************* AdwCleaner[S1].txt - [19452 octets] - [08/02/2013 10:39:38] ########## EOF - C:\AdwCleaner[S1].txt - [19513 octets] ##########

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI