This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

"Quibuy"-malware [Solved]

23 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I recently acquired a Google re-direct malware that sometimes sends me to a site named "Quibuy"–sometimes other site(s)–sometimes to where I tried to go via the Google search. Using Windows XP Pro with SP-3. AVG-Free and Malwarebytes have been ineffective. Also, in my Toolbar there is a new "block" of space titled simply "SEARCH". Is there help available for this 'stinker'? Using Firefox 21.0. Think I picked this up when upgrading FlashPlayer??? Thanks, Sam
Hello shadow5,

My name is OCD. I would be more than happy to take a look at your log and help you with solving any malware problems you might have. Logs can take a while to research, so please be patient and know that I am working hard to get you a clean and functional system back in your hands. I'd be grateful if you would note the following:
  • I will be working on your Malware issues, this may or may not, solve other issues you have with your machine.
  • The fixes are specific to your problem and should only be used for the issues on this machine.
  • Please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear.
  • It's often worth reading through these instructions and printing them for ease of reference.
  • If you don't know or understand something, please don't hesitate to say or ask!! It's better to be sure and safe than sorry.
  • Please reply to this thread. Do not start a new topic.
  • Copy and Paste logs directly into the reply window. DO NOT attach the logs unless specifically instructed to do so.
IMPORTANT NOTE : Please do not delete, download or install anything unless instructed to do so.

DO NOT use any TOOLS such as Combofix or HijackThis fixes without supervision. Doing so could make your system inoperable and could require a full reinstall of your Operating System and losing all your programs and data.

Important Note for Vista and Windows 7 & 8 users:

These tools MUST be run from the executable.(.exe) every time you run them with Admin Rights (Right click, choose "Run as Administrator")

Please stay with this topic until I let you know that your system appears to be "All Clear"

=========================

1. aswMBR

Download aswMBR.exe and save it to your desktop.
    • Windows XP : Double click on the icon to run it.
    • Windows Vista, Windows 7 & 8 : Right click and select "Run as Administrator"
  • When asked if you want to download Avast's virus definitions please select Yes.
  • Click Scan
  • Upon completion of the scan, click Save log and save it to your desktop, and post that log in your next reply for review. Note - do NOT attempt any Fix yet.
  • You will also notice another file created on the desktop named MBR.dat. Right click that file and select Send To>Compressed (zipped) file. Attach that zipped file in your next reply as well.

=========================

2. OTL

Download OTL to your desktop.
  • Make sure all other windows are closed and to let it run uninterrupted.
    • Windows XP : Double click on the icon to run it.
    • Windows Vista, Windows 7 & 8 : Right click and select "Run as Administrator"
  • When the window appears, underneath Output at the top change it to Minimal Output.
  • Check the boxes beside LOP Check and Purity Check.
  • Under Custom Scan paste this in

    netsvcs
    %SYSTEMDRIVE%\*.exe
    /md5start
    explorer.exe
    winlogon.exe
    Userinit.exe
    svchost.exe
    services.exe
    /md5stop
    %systemroot%\*. /rp /s
    %systemdrive%\$Recycle.Bin|@;true;true;true
    %USERPROFILE%\..|smtmp;true;true;true /FP
    %temp%\smtmp\*.* /s >
    BASESERVICES
    DRIVES
    CREATERESTOREPOINT

  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
    • When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.
    • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post it with your next reply.
    • You may need two posts to fit them both in.
=========================

In your next post please provide the following:
  • aswMBR.txt
  • attach MBR.zip
  • OTL.txt
  • Extras.txt
Thanks for response and offer to help. Your requests follow:
aswMBR version 0.9.9.1771 Copyright© 2011 AVAST Software
Run date: 2013-05-29 17:27:58
—————————–
17:27:58.078 OS Version: Windows 5.1.2600 Service Pack 3
17:27:58.078 Number of processors: 2 586 0x1706
17:27:58.078 ComputerName: OWNER-59AC86FE7 UserName: Administrator
17:27:59.031 Initialize success
17:30:03.890 AVAST engine defs: 13052901
17:30:27.281 Disk 0 \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP4T0L0-12
17:30:27.281 Disk 0 Vendor: WDC_WD5000AADS-00M2B0 01.00A01 Size: 476938MB BusType: 3
17:30:27.281 Disk 1 (boot) \Device\Harddisk1\DR1 -> \Device\Ide\IdeDeviceP2T0L0-1f
17:30:27.281 Disk 1 Vendor: WDC_WD2500JS-00NCB1 10.02E01 Size: 238474MB BusType: 3
17:30:27.390 Disk 1 MBR read successfully
17:30:27.390 Disk 1 MBR scan
17:30:27.421 Disk 1 Windows XP default MBR code
17:30:27.421 Disk 1 Partition 1 80 (A) 07 HPFS/NTFS NTFS 238472 MB offset 63
17:30:27.437 Disk 1 scanning sectors +488392065
17:30:27.484 Disk 1 scanning C:\WINDOWS\system32\drivers
17:30:33.500 Service scanning
17:30:46.187 Modules scanning
17:30:50.015 Disk 1 trace - called modules:
17:30:50.015 ntkrnlpa.exe CLASSPNP.SYS disk.sys ACPI.sys hal.dll atapi.sys pciide.sys PCIIDEX.SYS
17:30:50.031 1 nt!IofCallDriver -> \Device\Harddisk1\DR1[0x8a869030]
17:30:50.031 3 CLASSPNP.SYS[b80e8fd7] -> nt!IofCallDriver -> \Device\0000006c[0x8a8961e0]
17:30:50.031 5 ACPI.sys[b7f7f620] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP2T0L0-1f[0x8a7dad98]
17:30:50.968 AVAST engine scan C:\WINDOWS
17:31:03.765 AVAST engine scan C:\WINDOWS\system32
17:32:37.875 AVAST engine scan C:\WINDOWS\system32\drivers
17:32:46.203 AVAST engine scan C:\Documents and Settings\Administrator
19:18:28.890 AVAST engine scan C:\Documents and Settings\All Users
19:19:56.265 Scan finished successfully
19:20:55.359 Disk 1 MBR has been saved successfully to "C:\Documents and Settings\Administrator\Desktop\MBR.dat"
19:20:55.359 The log file has been saved successfully to "C:\Documents and Settings\Administrator\Desktop\aswMBR.txt"

OTL logfile created on: 5/29/2013 7:26:31 PM - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Documents and Settings\Administrator\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

3.50 Gb Total Physical Memory | 2.42 Gb Available Physical Memory | 69.14% Memory free
6.84 Gb Paging File | 5.97 Gb Available in Paging File | 87.39% Paging File free
Paging file location(s): C:\pagefile.sys 0 0 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 232.88 Gb Total Space | 114.49 Gb Free Space | 49.16% Space Free | Partition Type: NTFS
Drive F: | 465.76 Gb Total Space | 268.71 Gb Free Space | 57.69% Space Free | Partition Type: NTFS

Computer Name: OWNER-59AC86FE7 | User Name: Administrator | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Documents and Settings\Administrator\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\AVG\AVG2013\avgidsagent.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG2013\avgui.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG2013\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG2013\avgnsx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG2013\avgrsx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG2013\avgemcx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG2013\avgcsrvx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe (NVIDIA Corporation)
PRC - C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe (Malwarebytes Corporation)
PRC - C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
PRC - C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe (Malwarebytes Corporation)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Acronis\TrueImageHome\TimounterMonitor.exe (Acronis)
PRC - C:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exe (Acronis)
PRC - C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe (Acronis)
PRC - C:\Program Files\Acronis\TrueImageHome\TrueImageMonitor.exe (Acronis)
PRC - C:\WINDOWS\system32\HPZipm12.exe (HP)
PRC - C:\Program Files\Ahead\InCD\InCD.exe (Ahead Software AG)
PRC - C:\Program Files\Ahead\InCD\incdsrv.exe (AHEAD Software)


========== Modules (No Company Name) ==========

MOD - c:\windows\assembly\nativeimages1_v1.1.4322\mscorlib\1.0.5000.0__b77a5c561934e089_63022737\mscorlib.dll ()
MOD - c:\windows\assembly\nativeimages1_v1.1.4322\system.drawing\1.0.5000.0__b03f5f7f11d50a3a_a9db4250\system.drawing.dll ()
MOD - c:\windows\assembly\nativeimages1_v1.1.4322\system.xml\1.0.5000.0__b77a5c561934e089_6a7af65d\system.xml.dll ()
MOD - c:\windows\assembly\nativeimages1_v1.1.4322\system.windows.forms\1.0.5000.0__b77a5c561934e089_ea1855d9\system.windows.forms.dll ()
MOD - c:\windows\assembly\nativeimages1_v1.1.4322\system\1.0.5000.0__b77a5c561934e089_7eddb414\system.dll ()
MOD - c:\windows\assembly\gac\system\1.0.5000.0__b77a5c561934e089\system.dll ()
MOD - c:\windows\assembly\gac\system.drawing\1.0.5000.0__b03f5f7f11d50a3a\system.drawing.dll ()
MOD - c:\windows\assembly\gac\system.windows.forms\1.0.5000.0__b77a5c561934e089\system.windows.forms.dll ()
MOD - c:\windows\assembly\gac\system.xml\1.0.5000.0__b77a5c561934e089\system.xml.dll ()
MOD - c:\windows\assembly\gac\hpqietpz\3.0.0.0__a53cf5803f4c3827\hpqietpz.dll ()
MOD - c:\windows\assembly\gac\hpqcprsc\3.0.0.0__a53cf5803f4c3827\hpqcprsc.dll ()
MOD - c:\windows\assembly\gac\hpqcprsc.resources\3.0.0.0_en_a53cf5803f4c3827\hpqcprsc.resources.dll ()
MOD - c:\windows\assembly\gac\hpqisrtb\4.0.0.0__a53cf5803f4c3827\hpqisrtb.dll ()
MOD - c:\windows\assembly\gac\lead.wrapper\13.0.0.66__9cf889f53ea9b907\lead.wrapper.dll ()
MOD - c:\windows\assembly\gac\lead.drawing\13.0.0.66__9cf889f53ea9b907\lead.drawing.dll ()
MOD - c:\windows\assembly\gac\lead\13.0.0.66__9cf889f53ea9b907\lead.dll ()
MOD - c:\windows\assembly\gac\lead.windows.forms\13.0.0.66__9cf889f53ea9b907\lead.windows.forms.dll ()
MOD - c:\windows\assembly\gac\hpqtray\3.0.0.0__a53cf5803f4c3827\hpqtray.dll ()
MOD - c:\windows\assembly\gac\hpqtray.resources\3.0.0.0_en_a53cf5803f4c3827\hpqtray.resources.dll ()
MOD - c:\windows\assembly\gac\hpqimgrc\3.0.0.0__a53cf5803f4c3827\hpqimgrc.dll ()
MOD - c:\windows\assembly\gac\hpqgldlg\3.0.0.0__a53cf5803f4c3827\hpqgldlg.dll ()
MOD - c:\windows\assembly\gac\hpqthumb\3.0.0.0__a53cf5803f4c3827\hpqthumb.dll ()
MOD - c:\windows\assembly\gac\hpqfmrsc\3.0.0.0__a53cf5803f4c3827\hpqfmrsc.dll ()
MOD - c:\windows\assembly\gac\hpqasset\3.0.0.0__a53cf5803f4c3827\hpqasset.dll ()
MOD - c:\windows\assembly\gac\hpqiface\3.0.0.0__a53cf5803f4c3827\hpqiface.dll ()
MOD - c:\windows\assembly\gac\interop.hpqimgr\1.0.0.0__a53cf5803f4c3827\interop.hpqimgr.dll ()
MOD - c:\windows\assembly\gac\hpqfmrsc.resources\3.0.0.0_en_a53cf5803f4c3827\hpqfmrsc.resources.dll ()
MOD - c:\windows\assembly\gac\hpqcmctl\3.0.0.0__a53cf5803f4c3827\hpqcmctl.dll ()
MOD - c:\windows\assembly\gac\hpqccrsc\3.0.0.0__a53cf5803f4c3827\hpqccrsc.dll ()
MOD - c:\windows\assembly\gac\hpqutils\3.0.0.0__a53cf5803f4c3827\hpqutils.dll ()
MOD - c:\windows\assembly\gac\hpqgskin\3.0.0.0__a53cf5803f4c3827\hpqgskin.dll ()
MOD - c:\windows\assembly\gac\interop.hpqcxm08\3.0.0.0__a53cf5803f4c3827\interop.hpqcxm08.dll ()
MOD - c:\windows\assembly\gac\hpqptfnd\3.0.0.0__a53cf5803f4c3827\hpqptfnd.dll ()
MOD - c:\windows\assembly\gac\accessibility\1.0.5000.0__b03f5f7f11d50a3a\accessibility.dll ()
MOD - C:\Program Files\WinRAR\RarExt.dll ()
MOD - C:\Program Files\Common Files\Acronis\Common\gc.dll ()


========== Services (SafeList) ==========

SRV - (MozillaMaintenance) – C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe (Mozilla Foundation)
SRV - (AVGIDSAgent) – C:\Program Files\AVG\AVG2013\avgidsagent.exe (AVG Technologies CZ, s.r.o.)
SRV - (avgwd) – C:\Program Files\AVG\AVG2013\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
SRV - (nvUpdatusService) – C:\Program Files\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe (NVIDIA Corporation)
SRV - (MBAMService) – C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe (Malwarebytes Corporation)
SRV - (MBAMScheduler) – C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe (Malwarebytes Corporation)
SRV - (AcrSch2Svc) – C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe (Acronis)
SRV - (Pml Driver HPZ12) – C:\WINDOWS\system32\HPZipm12.exe (HP)
SRV - (InCDsrv) – C:\Program Files\Ahead\InCD\incdsrv.exe (AHEAD Software)


========== Driver Services (SafeList) ==========

DRV - (WDICA) – File not found
DRV - (PDRFRAME) – File not found
DRV - (PDRELI) – File not found
DRV - (PDFRAME) – File not found
DRV - (PDCOMP) – File not found
DRV - (PCIDump) – File not found
DRV - (mrtRate) – File not found
DRV - (lbrtfdc) – File not found
DRV - (i2omgmt) – File not found
DRV - (Changer) – File not found
DRV - (aswMBR) – C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\aswMBR.sys File not found
DRV - (AVGIDSDriver) – C:\WINDOWS\system32\drivers\avgidsdriverx.sys (AVG Technologies CZ, s.r.o.)
DRV - (Avgtdix) – C:\WINDOWS\system32\drivers\avgtdix.sys (AVG Technologies CZ, s.r.o.)
DRV - (AVGIDSShim) – C:\WINDOWS\system32\drivers\avgidsshimx.sys (AVG Technologies CZ, s.r.o.)
DRV - (Avgmfx86) – C:\WINDOWS\system32\drivers\avgmfx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (Avglogx) – C:\WINDOWS\system32\drivers\avglogx.sys (AVG Technologies CZ, s.r.o.)
DRV - (AVGIDSHX) – C:\WINDOWS\system32\drivers\avgidshx.sys (AVG Technologies CZ, s.r.o.)
DRV - (Avgldx86) – C:\WINDOWS\system32\drivers\avgldx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (Avgrkx86) – C:\WINDOWS\system32\drivers\avgrkx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (timounter) – C:\WINDOWS\system32\drivers\timntr.sys (Acronis)
DRV - (tifsfilter) – C:\WINDOWS\system32\drivers\tifsfilt.sys (Acronis)
DRV - (snapman) – C:\WINDOWS\system32\drivers\snapman.sys (Acronis)
DRV - (MBAMProtector) – C:\WINDOWS\system32\drivers\mbam.sys (Malwarebytes Corporation)
DRV - (IntcAzAudAddService) – C:\WINDOWS\system32\drivers\RtkHDAud.sys (Realtek Semiconductor Corp.)
DRV - (RTLE8023xp) – C:\WINDOWS\system32\drivers\Rtenicxp.sys (Realtek Semiconductor Corporation )
DRV - (Monfilt) – C:\WINDOWS\system32\drivers\Monfilt.sys (Creative Technology Ltd.)
DRV - (Ambfilt) – C:\WINDOWS\system32\drivers\Ambfilt.sys (Creative)
DRV - (InCDPass) – C:\WINDOWS\system32\drivers\incdpass.sys (Ahead Software)
DRV - (InCDrec) – C:\WINDOWS\System32\drivers\incdrec.sys (Ahead Software AG)
DRV - (InCDfs) – C:\WINDOWS\System32\drivers\incdfs.sys (Ahead Software)
DRV - (USB-100) – C:\WINDOWS\system32\drivers\RTL8150.SYS (Realtek )


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://search.live.com/results.aspx?q={sea…ferrer:source?}

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.google.com/ie
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = http://www.google.com/ie
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.wyff4.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie
IE - HKCU\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}…amp;FORM=IE8SRC
IE - HKCU\..\SearchScopes\{67BD5838-CB1E-4393-A46F-2CED7C53F8E9}: "URL" = http://www.google.com/search?q={searchTerm…tf8&oe;=utf8
IE - HKCU\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.com/search?q={searcerms}…amp;FORM=IE8SRC
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "http://www.wyff4.com/"
FF - prefs.js..extensions.enabledAddons: addon%40defaulttab.com:2.0
FF - prefs.js..extensions.enabledAddons: %7B972ce4c6-7e08-4474-a285-3208198ce6fd%7D:21.0


FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32_11_5_502_146.dll ()
FF - HKLM\Software\MozillaPlugins\@google.com/npPicasa3,version=3.0.0: C:\Program Files\Google\Picasa3\npPicasa3.dll (Google, Inc.)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 20.0.1\extensions\\Components: C:\Program Files\Mozilla Firefox\components
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 20.0.1\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins

[2013/01/11 19:09:39 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Administrator\Application Data\Mozilla\Extensions
[2013/05/24 00:39:31 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\se9y2xik.default\extensions
[2013/05/24 00:39:20 | 000,000,000 | —D | M] (DownloadTerms) – C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\se9y2xik.default\extensions\[removed]
[2013/05/24 00:39:30 | 000,029,621 | —- | M] () (No name found) – C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\se9y2xik.default\extensions\[removed]
[2013/05/29 17:19:52 | 000,001,997 | —- | M] () – C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\se9y2xik.default\searchplugins\search.xml
[2013/05/25 01:51:54 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\browser\extensions
[2013/05/25 01:51:54 | 000,000,000 | —D | M] (Default) – C:\Program Files\Mozilla Firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}

O1 HOSTS File: ([2008/04/14 08:00:00 | 000,000,734 | —- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O4 - HKLM..\Run: [Acronis Scheduler2 Service] C:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exe (Acronis)
O4 - HKLM..\Run: [AcronisTimounterMonitor] C:\Program Files\Acronis\TrueImageHome\TimounterMonitor.exe (Acronis)
O4 - HKLM..\Run: [APSDaemon] C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [AVG_UI] C:\Program Files\AVG\AVG2013\avgui.exe (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [InCD] C:\Program Files\Ahead\InCD\InCD.exe (Ahead Software AG)
O4 - HKLM..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe (Ahead Software Gmbh)
O4 - HKLM..\Run: [NvCplDaemon] C:\WINDOWS\System32\NvCpl.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [NvMediaCenter] C:\WINDOWS\System32\nvmctray.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [nwiz] C:\Program Files\NVIDIA Corporation\nview\nwiz.exe ()
O4 - HKLM..\Run: [TrueImageMonitor.exe] C:\Program Files\Acronis\TrueImageHome\TrueImageMonitor.exe (Acronis)
O4 - HKCU..\Run: [ROC_ROC_APR2013_AV] C:\Documents and Settings\Administrator\Application Data\AVG April 2013 Campaign\AVG-Secure-Search-Update.exe /PROMPT –mid bd60c22bbefe5042c4884c1e19ef3768-259577303c4ffd1a0dd2239fbf839e4a4285025a –CMPID ROC_APR2013_AV –CMPIDEXTRA 2013 File not found
O4 - HKCU..\RunOnce: [FlashPlayerUpdate] C:\WINDOWS\System32\Macromed\Flash\FlashUtil32_11_5_502_146_Plugin.exe (Adobe Systems Incorporated)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Billminder.lnk = C:\Program Files\Quicken\billmind.exe (Intuit)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\HP Image Zone Fast Start.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe (Hewlett-Packard Co.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Quicken Scheduled Updates.lnk = C:\Program Files\Quicken\bagent.exe (Intuit Inc.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Quicken Startup.lnk = C:\Program Files\Quicken\QWDLLS.EXE (Intuit)
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O8 - Extra context menu item: Add to Google Photos Screensa&ver; - C:\WINDOWS\System32\GPhotos.scr (Google Inc.)
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} http://windowsupdate.microsoft.com/windows…b?1357777321906 (WUWebControl Class)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.254
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{DBFBB6A8-DCB4-4E08-8E64-F7E27F8D3437}: DhcpNameServer = 192.168.1.254
O18 - Protocol\Handler\cetihpz {CF184AD3-CDCB-4168-A3F7-8E447D129300} - C:\Program Files\HP\hpcoretech\comp\hpuiprot.dll (Hewlett-Packard Company)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) - C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Documents and Settings\Administrator\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Administrator\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O30 - LSA: Authentication Packages - (relog_ap) - C:\WINDOWS\System32\relog_ap.dll (Acronis)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2013/01/09 19:32:11 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O32 - AutoRun File - [2009/11/30 14:58:29 | 000,000,000 | —- | M] () - F:\AUTOEXEC.BAT – [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O34 - HKLM BootExecute: (C:\PROGRA~1\AVG\AVG2013\avgrsx.exe /sync /restart)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)

NetSvcs: 6to4 - File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found

CREATERESTOREPOINT
Restore point Set: OTL Restore Point

========== Files/Folders - Created Within 30 Days ==========

[2013/05/29 17:22:47 | 000,602,112 | —- | C] (OldTimer Tools) – C:\Documents and Settings\Administrator\Desktop\OTL.exe
[2013/05/29 17:20:48 | 004,745,728 | —- | C] (AVAST Software) – C:\Documents and Settings\Administrator\Desktop\aswMBR.exe
[2013/05/25 01:51:45 | 000,000,000 | —D | C] – C:\Program Files\Mozilla Firefox
[2013/05/25 01:32:17 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\AVG
[2013/05/24 00:45:44 | 000,000,000 | —D | C] – C:\Program Files\Uninstaller
[2013/05/24 00:44:58 | 000,000,000 | —D | C] – C:\Documents and Settings\Administrator\Application Data\player
[2013/05/24 00:41:14 | 000,000,000 | —D | C] – C:\Program Files\Microsoft.NET
[2013/05/24 00:39:37 | 000,000,000 | —D | C] – C:\Program Files\DefaultTab
[2013/05/24 00:39:31 | 000,000,000 | —D | C] – C:\Documents and Settings\Administrator\Application Data\DefaultTab
[2013/05/24 00:39:15 | 000,000,000 | —D | C] – C:\Documents and Settings\Administrator\Local Settings\Application Data\DownloadTerms
[2013/05/13 13:31:05 | 000,000,000 | —D | C] – C:\Documents and Settings\Administrator\My Documents\MORGAN $6K JULY'13 PROMISSORY NOTE
[2013/05/13 12:57:51 | 000,000,000 | —D | C] – C:\Documents and Settings\Administrator\Start Menu\Programs\Parsons Technology
[2013/05/13 12:40:41 | 000,000,000 | —D | C] – C:\WINDOWS\System32\Parsons
[2013/05/13 12:40:38 | 000,146,976 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\MFCOLEUI.DLL
[2013/05/13 12:40:37 | 000,010,736 | —- | C] (Blue Sky Software Corp.) – C:\WINDOWS\System32\RHMMPLAY.DLL
[2013/05/13 12:40:30 | 000,000,000 | —D | C] – C:\Program Files\Parsons Technology
[7 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2013/05/29 19:22:12 | 000,000,499 | —- | M] () – C:\Documents and Settings\Administrator\Desktop\MBR.zip
[2013/05/29 19:20:55 | 000,000,512 | —- | M] () – C:\Documents and Settings\Administrator\Desktop\MBR.dat
[2013/05/29 19:17:53 | 000,000,438 | -H– | M] () – C:\WINDOWS\tasks\User_Feed_Synchronization-{BF0383E8-AAC2-4B96-BC72-182AF1754472}.job
[2013/05/29 17:22:48 | 000,602,112 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Administrator\Desktop\OTL.exe
[2013/05/29 17:22:16 | 004,745,728 | —- | M] (AVAST Software) – C:\Documents and Settings\Administrator\Desktop\aswMBR.exe
[2013/05/29 17:19:53 | 000,003,182 | —- | M] () – C:\WINDOWS\System32\nvAppTimestamps
[2013/05/28 20:55:10 | 000,001,178 | —- | M] () – C:\WINDOWS\QUICKEN.INI
[2013/05/25 01:32:17 | 000,000,702 | —- | M] () – C:\Documents and Settings\All Users\Desktop\AVG 2013.lnk
[2013/05/25 01:24:42 | 000,013,646 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2013/05/25 01:24:02 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2013/05/24 14:52:00 | 000,000,284 | —- | M] () – C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2013/05/24 11:12:53 | 000,045,386 | —- | M] () – C:\Documents and Settings\Administrator\Desktop\3G13Na3Hd5I85G55F3d5n0ca9cedf2791186b.jpg
[2013/05/24 00:44:37 | 000,464,474 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2013/05/24 00:44:37 | 000,079,302 | —- | M] () – C:\WINDOWS\System32\perfc009.dat
[2013/05/22 18:04:22 | 000,204,680 | —- | M] () – C:\Documents and Settings\Administrator\Desktop\LATE HAGERTY 21999939-1.PDF
[2013/05/15 03:18:55 | 000,263,024 | —- | M] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2013/05/15 03:02:24 | 000,001,374 | —- | M] () – C:\WINDOWS\imsins.BAK
[2013/05/14 15:15:21 | 000,000,233 | —- | M] () – C:\WINDOWS\qwimp.ini
[2013/05/13 12:57:51 | 000,000,884 | —- | M] () – C:\Documents and Settings\Administrator\Desktop\Quicken Family Lawyer Deluxe.lnk
[2013/05/13 12:57:51 | 000,000,177 | —- | M] () – C:\WINDOWS\PARSONS.INI
[2013/05/10 09:38:33 | 000,000,572 | —- | M] () – C:\Documents and Settings\Administrator\My Documents\spider.sav
[2013/05/07 00:27:31 | 006,015,488 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\mshtml.dll
[7 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]

========== Files Created - No Company Name ==========

[2013/05/29 19:22:12 | 000,000,499 | —- | C] () – C:\Documents and Settings\Administrator\Desktop\MBR.zip
[2013/05/29 19:20:55 | 000,000,512 | —- | C] () – C:\Documents and Settings\Administrator\Desktop\MBR.dat
[2013/05/24 11:12:53 | 000,045,386 | —- | C] () – C:\Documents and Settings\Administrator\Desktop\3G13Na3Hd5I85G55F3d5n0ca9cedf2791186b.jpg
[2013/05/22 18:04:22 | 000,204,680 | —- | C] () – C:\Documents and Settings\Administrator\Desktop\LATE HAGERTY 21999939-1.PDF
[2013/05/13 12:57:51 | 000,000,884 | —- | C] () – C:\Documents and Settings\Administrator\Desktop\Quicken Family Lawyer Deluxe.lnk
[2013/05/13 12:57:51 | 000,000,177 | —- | C] () – C:\WINDOWS\PARSONS.INI
[2013/02/28 15:26:39 | 000,003,584 | —- | C] () – C:\Documents and Settings\Administrator\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2013/02/02 16:49:25 | 000,000,048 | —- | C] () – C:\WINDOWS\PickList.ini
[2013/02/02 16:49:25 | 000,000,000 | —- | C] () – C:\WINDOWS\od5.ini
[2013/01/23 17:38:37 | 000,000,000 | —- | C] () – C:\WINDOWS\ADDRBOOK.INI
[2013/01/14 10:45:23 | 000,104,549 | —- | C] () – C:\WINDOWS\hpoins04.dat
[2013/01/14 10:45:23 | 000,017,176 | —- | C] () – C:\WINDOWS\hpomdl04.dat
[2013/01/14 10:42:39 | 000,104,156 | —- | C] () – C:\WINDOWS\hpoins04.dat.temp
[2013/01/14 10:42:39 | 000,017,176 | —- | C] () – C:\WINDOWS\hpomdl04.dat.temp
[2013/01/11 18:53:20 | 000,000,136 | —- | C] () – C:\Documents and Settings\Administrator\Local Settings\Application Data\fusioncache.dat
[2013/01/11 18:34:57 | 000,000,214 | —- | C] () – C:\WINDOWS\HP_48BitScanUpdatePatch.ini
[2013/01/11 18:09:46 | 000,000,233 | —- | C] () – C:\WINDOWS\qwimp.ini
[2013/01/11 18:07:29 | 000,001,178 | —- | C] () – C:\WINDOWS\QUICKEN.INI
[2013/01/11 18:07:29 | 000,000,052 | —- | C] () – C:\WINDOWS\intuprof.ini
[2013/01/09 20:36:39 | 000,003,072 | —- | C] () – C:\WINDOWS\System32\iacenc.dll
[2013/01/09 20:03:04 | 001,079,188 | —- | C] () – C:\WINDOWS\System32\nvdrsdb1.bin
[2013/01/09 20:03:04 | 001,079,188 | —- | C] () – C:\WINDOWS\System32\nvdrsdb0.bin
[2013/01/09 20:03:04 | 000,000,001 | —- | C] () – C:\WINDOWS\System32\nvdrssel.bin
[2013/01/09 20:02:53 | 002,287,232 | —- | C] () – C:\WINDOWS\System32\nvdata.data
[2013/01/09 19:55:00 | 000,025,548 | —- | C] () – C:\WINDOWS\System32\drivers\RTAIODAT.DAT
[2013/01/09 19:33:59 | 000,002,048 | –S- | C] () – C:\WINDOWS\bootstat.dat
[2013/01/09 19:29:14 | 000,021,640 | —- | C] () – C:\WINDOWS\System32\emptyregdb.dat
[2013/01/09 14:19:56 | 000,004,161 | —- | C] () – C:\WINDOWS\ODBCINST.INI
[2013/01/09 14:18:28 | 000,263,024 | —- | C] () – C:\WINDOWS\System32\FNTCACHE.DAT

========== ZeroAccess Check ==========

[2013/01/11 18:24:45 | 000,000,227 | RHS- | M] () – C:\WINDOWS\assembly\Desktop.ini

[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]

[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shdocvw.dll – [2008/04/14 08:00:00 | 001,499,136 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = C:\WINDOWS\system32\wbem\fastprox.dll – [2009/02/09 08:10:48 | 000,473,600 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
"" = C:\WINDOWS\system32\wbem\wbemess.dll – [2008/04/14 08:00:00 | 000,273,920 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Both

========== LOP Check ==========

[2013/01/23 19:45:05 | 000,000,000 | —D | M] – C:\Documents and Settings\Administrator\Application Data\Acronis
[2013/03/14 06:49:14 | 000,000,000 | —D | M] – C:\Documents and Settings\Administrator\Application Data\AVG2013
[2013/05/24 00:39:31 | 000,000,000 | —D | M] – C:\Documents and Settings\Administrator\Application Data\DefaultTab
[2013/05/25 01:20:27 | 000,000,000 | —D | M] – C:\Documents and Settings\Administrator\Application Data\player
[2013/03/14 06:48:11 | 000,000,000 | —D | M] – C:\Documents and Settings\Administrator\Application Data\TuneUp Software
[2013/01/14 03:51:54 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Acronis
[2013/03/14 06:48:39 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\AVG2013
[2013/03/14 06:37:14 | 000,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\Common Files
[2013/05/29 00:35:14 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\MFAData
[2013/05/29 16:48:42 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TEMP

========== Purity Check ==========



========== Custom Scans ==========

< %SYSTEMDRIVE%\*.exe >

< MD5 for: EXPLORER.EXE >
[2008/04/14 08:00:00 | 001,033,728 | —- | M] (Microsoft Corporation) MD5=12896823FB95BFB3DC9B46BCAEDC9923 – C:\WINDOWS\explorer.exe
[2008/04/14 08:00:00 | 001,033,728 | —- | M] (Microsoft Corporation) MD5=12896823FB95BFB3DC9B46BCAEDC9923 – C:\WINDOWS\system32\dllcache\explorer.exe

< MD5 for: SERVICES.EXE >
[2009/02/06 07:06:24 | 000,110,592 | —- | M] (Microsoft Corporation) MD5=020CEAAEDC8EB655B6506B8C70D53BB6 – C:\WINDOWS\$hf_mig$\KB956572\SP3QFE\services.exe
[2008/04/14 08:00:00 | 000,108,544 | —- | M] (Microsoft Corporation) MD5=0E776ED5F7CC9F94299E70461B7B8185 – C:\WINDOWS\$NtUninstallKB956572$\services.exe
[2009/02/06 07:11:05 | 000,110,592 | —- | M] (Microsoft Corporation) MD5=65DF52F5B8B6E9BBD183505225C37315 – C:\WINDOWS\system32\dllcache\services.exe
[2009/02/06 07:11:05 | 000,110,592 | —- | M] (Microsoft Corporation) MD5=65DF52F5B8B6E9BBD183505225C37315 – C:\WINDOWS\system32\services.exe

< MD5 for: SVCHOST.EXE >
[2012/12/14 16:49:28 | 000,216,424 | —- | M] () MD5=22101A85B3CA2FE2BE05FE9A61A7A83D – C:\Program Files\Malwarebytes' Anti-Malware\Chameleon\svchost.exe
[2008/04/14 08:00:00 | 000,014,336 | —- | M] (Microsoft Corporation) MD5=27C6D03BCDB8CFEB96B716F3D8BE3E18 – C:\WINDOWS\system32\dllcache\svchost.exe
[2008/04/14 08:00:00 | 000,014,336 | —- | M] (Microsoft Corporation) MD5=27C6D03BCDB8CFEB96B716F3D8BE3E18 – C:\WINDOWS\system32\svchost.exe

< MD5 for: USERINIT.EXE >
[2008/04/14 08:00:00 | 000,026,112 | —- | M] (Microsoft Corporation) MD5=A93AEE1928A9D7CE3E16D24EC7380F89 – C:\WINDOWS\system32\dllcache\userinit.exe
[2008/04/14 08:00:00 | 000,026,112 | —- | M] (Microsoft Corporation) MD5=A93AEE1928A9D7CE3E16D24EC7380F89 – C:\WINDOWS\system32\userinit.exe

< MD5 for: WINLOGON.EXE >
[2012/12/14 16:49:28 | 000,216,424 | —- | M] () MD5=22101A85B3CA2FE2BE05FE9A61A7A83D – C:\Program Files\Malwarebytes' Anti-Malware\Chameleon\winlogon.exe
[2008/04/14 08:00:00 | 000,507,904 | —- | M] (Microsoft Corporation) MD5=ED0EF0A136DEC83DF69F04118870003E – C:\WINDOWS\system32\dllcache\winlogon.exe
[2008/04/14 08:00:00 | 000,507,904 | —- | M] (Microsoft Corporation) MD5=ED0EF0A136DEC83DF69F04118870003E – C:\WINDOWS\system32\winlogon.exe

< %systemroot%\*. /rp /s >

< %systemdrive%\$Recycle.Bin|@;true;true;true >

< %USERPROFILE%\..|smtmp;true;true;true /FP >

< %temp%\smtmp\*.* /s > >

========== Base Services ==========
SRV - [2008/04/14 08:00:00 | 000,044,544 | —- | M] (Microsoft Corporation) [On_Demand | Running] – C:\WINDOWS\system32\alg.exe – (ALG)
SRV - [2008/04/14 08:00:00 | 000,006,656 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\WINDOWS\system32\wuauserv.dll – (wuauserv)
SRV - [2008/04/14 08:00:00 | 000,409,088 | —- | M] (Microsoft Corporation) [On_Demand | Running] – C:\WINDOWS\system32\qmgr.dll – (BITS)
SRV - [2012/07/06 09:58:51 | 000,078,336 | —- | M] (Microsoft Corporation) [Auto | Stopped] – C:\WINDOWS\system32\browser.dll – (Browser)
SRV - [2008/04/14 08:00:00 | 000,062,464 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\WINDOWS\system32\cryptsvc.dll – (CryptSvc)
SRV - [2008/04/14 08:00:00 | 000,126,976 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\WINDOWS\system32\dhcpcsvc.dll – (Dhcp)
SRV - [2009/04/20 13:17:26 | 000,045,568 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\WINDOWS\system32\dnsrslvr.dll – (Dnscache)
SRV - [2009/02/06 07:11:05 | 000,110,592 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\WINDOWS\system32\services.exe – (Eventlog)
SRV - [2008/04/14 08:00:00 | 000,033,792 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\WINDOWS\system32\eapsvc.dll – (EapHost)
SRV - [2009/07/27 19:17:41 | 000,135,168 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\WINDOWS\system32\shsvcs.dll – (FastUserSwitchingCompatibility)
SRV - [2008/04/14 08:00:00 | 000,015,872 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\WINDOWS\system32\w3ssl.dll – (HTTPFilter)
SRV - [2008/04/14 06:41:56 | 000,021,504 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\WINDOWS\system32\hidserv.dll – (HidServ)
SRV - [2008/04/14 08:00:00 | 000,150,528 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\WINDOWS\system32\imapi.exe – (ImapiService)
SRV - [2008/04/14 08:00:00 | 000,013,312 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\WINDOWS\system32\lsass.exe – (PolicyAgent)
SRV - [2008/04/14 08:00:00 | 000,023,552 | —- | M] (Microsoft Corp.) [Auto | Running] – C:\WINDOWS\system32\dmserver.dll – (dmserver)
SRV - [2008/04/14 08:00:00 | 000,224,768 | —- | M] (Microsoft Corp., Veritas Software) [On_Demand | Stopped] – C:\WINDOWS\System32\dmadmin.exe – (dmadmin)
SRV - [2008/04/14 08:00:00 | 000,005,120 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\WINDOWS\System32\dllhost.exe – (SwPrv)
SRV - [2008/04/14 08:00:00 | 000,013,312 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\WINDOWS\system32\lsass.exe – (Netlogon)
SRV - [2008/04/14 08:00:00 | 000,198,144 | —- | M] (Microsoft Corporation) [On_Demand | Running] – C:\WINDOWS\system32\netman.dll – (Netman)
SRV - [2008/06/20 12:02:47 | 000,245,248 | —- | M] (Microsoft Corporation) [On_Demand | Running] – C:\WINDOWS\system32\mswsock.dll – (Nla)
SRV - [2009/02/06 07:11:05 | 000,110,592 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\WINDOWS\system32\services.exe – (PlugPlay)
SRV - [2010/08/17 09:17:06 | 000,058,880 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\WINDOWS\system32\spoolsv.exe – (Spooler)
SRV - [2008/04/14 08:00:00 | 000,013,312 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\WINDOWS\system32\lsass.exe – (ProtectedStorage)
SRV - [2008/04/14 08:00:00 | 000,088,576 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\WINDOWS\system32\rasauto.dll – (RasAuto)
SRV - [2008/04/14 08:00:00 | 000,186,368 | —- | M] (Microsoft Corporation) [On_Demand | Running] – C:\WINDOWS\system32\rasmans.dll – (RasMan)
SRV - [2009/02/09 08:10:48 | 000,401,408 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\WINDOWS\system32\rpcss.dll – (RpcSs)
SRV - [2008/04/14 08:00:00 | 000,435,200 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\WINDOWS\system32\ntmssvc.dll – (NtmsSvc)
SRV - [2008/04/14 08:00:00 | 000,018,944 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\WINDOWS\system32\seclogon.dll – (seclogon)
SRV - [2008/04/14 08:00:00 | 000,013,312 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\WINDOWS\system32\lsass.exe – (SamSs)
SRV - [2008/04/14 08:00:00 | 000,080,896 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\WINDOWS\system32\wscsvc.dll – (wscsvc)
SRV - [2010/08/27 01:57:43 | 000,099,840 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\WINDOWS\system32\srvsvc.dll – (LanmanServer)
SRV - [2009/07/27 19:17:41 | 000,135,168 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\WINDOWS\system32\shsvcs.dll – (ShellHWDetection)
SRV - [2008/04/14 08:00:00 | 000,171,008 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\WINDOWS\system32\srsvc.dll – (srservice)
SRV - [2008/04/14 08:00:00 | 000,192,512 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\WINDOWS\system32\schedsvc.dll – (Schedule)
SRV - [2008/04/14 08:00:00 | 000,013,824 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\WINDOWS\system32\lmhsvc.dll – (LmHosts)
SRV - [2008/04/14 08:00:00 | 000,249,856 | —- | M] (Microsoft Corporation) [On_Demand | Running] – C:\WINDOWS\system32\tapisrv.dll – (TapiSrv)
SRV - [2008/04/14 08:00:00 | 000,295,424 | —- | M] (Microsoft Corporation) [On_Demand | Running] – C:\WINDOWS\system32\termsrv.dll – (TermService)
SRV - [2009/07/27 19:17:41 | 000,135,168 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\WINDOWS\system32\shsvcs.dll – (Themes)
SRV - [2008/04/14 08:00:00 | 000,289,792 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\WINDOWS\system32\vssvc.exe – (VSS)
SRV - [2008/04/14 08:00:00 | 000,042,496 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\WINDOWS\system32\audiosrv.dll – (AudioSrv)
SRV - [2008/04/14 08:00:00 | 000,331,264 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\WINDOWS\system32\ipnathlp.dll – (SharedAccess)
SRV - [2008/04/14 08:00:00 | 000,333,824 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\WINDOWS\system32\wiaservc.dll – (stisvc)
SRV - [2008/04/14 08:00:00 | 000,078,848 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\WINDOWS\System32\msiexec.exe – (MSIServer)
SRV - [2008/04/14 08:00:00 | 000,144,896 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\WINDOWS\system32\wbem\wmisvc.dll – (winmgmt)
SRV - [2009/02/09 08:10:48 | 000,617,472 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\WINDOWS\system32\advapi32.dll – (Wmi)
SRV - [2008/04/14 08:00:00 | 000,132,096 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\WINDOWS\system32\dot3svc.dll – (Dot3svc)
SRV - [2008/04/14 08:00:00 | 000,483,840 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\WINDOWS\system32\wzcsvc.dll – (WZCSVC)
SRV - [2009/06/10 02:14:49 | 000,132,096 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\WINDOWS\system32\wkssvc.dll – (lanmanworkstation)

========== Drive Information ==========

Physical Drives
—————

Drive: \\\\.\\PHYSICALDRIVE0 - Fixed\thard disk media
Interface type: IDE
Media Type: Fixed\thard disk media
Model: WDC WD5000AADS-00M2B0
Partitions: 1
Status: OK
Status Info: 0

Drive: \\\\.\\PHYSICALDRIVE1 - Fixed\thard disk media
Interface type: IDE
Media Type: Fixed\thard disk media
Model: WDC WD2500JS-00NCB1
Partitions: 1
Status: OK
Status Info: 0

Drive: \\\\.\\PHYSICALDRIVE2 -
Interface type: USB
Media Type:
Model: HP psc 2410 USB Device
Partitions: 0
Status: OK
Status Info: 0

Partitions
—————

DeviceID: Disk #0, Partition #0
PartitionType: Installable File System
Bootable: True
BootPartition: True
PrimaryPartition: True
Size: 466.00GB
Starting Offset: 32256
Hidden sectors: 0


DeviceID: Disk #1, Partition #0
PartitionType: Installable File System
Bootable: True
BootPartition: True
PrimaryPartition: True
Size: 233.00GB
Starting Offset: 32256
Hidden sectors: 0


========== Alternate Data Streams ==========

@Alternate Data Stream - 88 bytes -> C:\Documents and Settings\Administrator\My Documents\ADDYS VIA 500GB HD ON 1-12-2013.WAB:SummaryInformation
@Alternate Data Stream - 121 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:31780AFE

< End of report >

OTL Extras logfile created on: 5/29/2013 7:26:31 PM - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Documents and Settings\Administrator\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

3.50 Gb Total Physical Memory | 2.42 Gb Available Physical Memory | 69.14% Memory free
6.84 Gb Paging File | 5.97 Gb Available in Paging File | 87.39% Paging File free
Paging file location(s): C:\pagefile.sys 0 0 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 232.88 Gb Total Space | 114.49 Gb Free Space | 49.16% Space Free | Partition Type: NTFS
Drive F: | 465.76 Gb Total Space | 268.71 Gb Free Space | 57.69% Space Free | Partition Type: NTFS

Computer Name: OWNER-59AC86FE7 | User Name: Administrator | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*

[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.html [@ = FirefoxHTML] – C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*
exefile [open] – "%1" %*
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

========== System Restore Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sr]
"Start" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SrService]
"Start" = 2

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
"%windir%\Network Diagnostic\xpnetdiag.exe" = %windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000 – (Microsoft Corporation)
"%windir%\system32\sessmgr.exe" = %windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019 – (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"%windir%\Network Diagnostic\xpnetdiag.exe" = %windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000 – (Microsoft Corporation)
"%windir%\system32\sessmgr.exe" = %windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019 – (Microsoft Corporation)
"C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE" = C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE:*:Enabled:Microsoft Office Outlook – (Microsoft Corporation)
"C:\Program Files\Microsoft Office\Office12\GROOVE.EXE" = C:\Program Files\Microsoft Office\Office12\GROOVE.EXE:*:Enabled:Microsoft Office Groove – (Microsoft Corporation)
"C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE" = C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE:*:Enabled:Microsoft Office OneNote – (Microsoft Corporation)
"C:\Program Files\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe" = C:\Program Files\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe:*:Enabled:Daemonu.exe – (NVIDIA Corporation)
"C:\Program Files\Common Files\Apple\Apple Application Support\WebKit2WebProcess.exe" = C:\Program Files\Common Files\Apple\Apple Application Support\WebKit2WebProcess.exe:*:Enabled:WebKit – (Apple Inc.)
"C:\Program Files\AVG\AVG2013\avgmfapx.exe" = C:\Program Files\AVG\AVG2013\avgmfapx.exe:*:Enabled:AVG Installer – (AVG Technologies CZ, s.r.o.)
"C:\Program Files\AVG\AVG2013\avgnsx.exe" = C:\Program Files\AVG\AVG2013\avgnsx.exe:*:Enabled:Online Shield – (AVG Technologies CZ, s.r.o.)
"C:\Program Files\AVG\AVG2013\avgdiagex.exe" = C:\Program Files\AVG\AVG2013\avgdiagex.exe:*:Enabled:AVG Diagnostics 2013 – (AVG Technologies CZ, s.r.o.)
"C:\Program Files\AVG\AVG2013\avgemcx.exe" = C:\Program Files\AVG\AVG2013\avgemcx.exe:*:Enabled:Personal Email Scanner – (AVG Technologies CZ, s.r.o.)


========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{193DD0DC-004A-4545-A301-E4A7335C8E41}" = 2400
"{1F63ED0B-EDD2-4037-B6AB-1358C624AF48}" = Scan
"{21E75254-410E-49C4-8981-2E1A2A2221F2}" = HP Diagnostic Assistant
"{2405665A-16C9-4D3A-B70E-F006220E1472}" = Overland
"{267868CE-6DFF-40F7-9C58-C01119B7B117}" = Fax
"{2BBC9458-07CA-4843-848B-5C8146E5EFA8}" = CreativeProjects
"{2D974D26-BA8F-4A0B-B7EE-3F563AF79746}" = Quicken 2003 Deluxe
"{34A59AC3-6C5C-4A09-A7F5-369A37176C8A}" = AiOSoftware
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{3AE681E0-4E8D-453F-950A-48534D3C0724}" = Copy
"{3CF78481-FB7B-4B51-99A2-D5E0CD0B3AAF}" = HPSystemDiagnostics
"{41254D7B-EADF-4078-AE4A-BD73B300EE86}" = Unload
"{419CF344-3D94-4DAD-99C8-EA7B00E5EA8B}" = Acronis True Image Home
"{457791C5-D702-4143-A7B2-2744BE9573F2}" = HP Software Update
"{597D73A8-5FDB-4bc1-9893-40B54459F1BC}" = ProductContext
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{72E67064-A144-42A6-BC85-12276B2D5D42}" = 2400_2500Help
"{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}" = Apple Software Update
"{8777AC6D-89F9-4793-8266-DE406F343E89}" = QFolder
"{8B922CF8-8A6C-41CE-A858-F1755D7F5D29}" = NVIDIA PhysX
"{8B957F8D-FBDE-4DB4-99E7-192487575050}" = 23_24_2500Tour
"{90120000-0010-0409-0000-0000000FF1CE}" = Microsoft Software Update for Web Folders (English) 12
"{90120000-0015-0409-0000-0000000FF1CE}" = Microsoft Office Access MUI (English) 2007
"{90120000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2007
"{90120000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2007
"{90120000-0019-0409-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (English) 2007
"{90120000-001A-0409-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (English) 2007
"{90120000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007
"{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007
"{90120000-0030-0000-0000-0000000FF1CE}" = Microsoft Office Enterprise 2007
"{90120000-0044-0409-0000-0000000FF1CE}" = Microsoft Office InfoPath MUI (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007
"{90120000-00A1-0409-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2007
"{90120000-00BA-0409-0000-0000000FF1CE}" = Microsoft Office Groove MUI (English) 2007
"{90120000-0114-0409-0000-0000000FF1CE}" = Microsoft Office Groove Setup Metadata MUI (English) 2007
"{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007
"{90120000-0117-0409-0000-0000000FF1CE}" = Microsoft Office Access Setup Metadata MUI (English) 2007
"{981FB376-8418-4EA8-BBED-9DE5AA63E7D5}" = SkinsHP1
"{9AD84892-7664-479C-8F95-7A25B964B04D}" = 2400_2500trb
"{9CB2512B-3EC4-43DF-8002-46BDAB5EDD1B}" = QuickProjects
"{9EEBF8D5-8712-4D1D-88F4-4CDC2D270BC3}" = PrintScreen
"{A1062847-0846-427A-92A1-BB8251A91E91}" = HP PSC & OfficeJet 4.2
"{A1DCC235-DACC-4E1F-8D11-D630634B4AEF}" = PhotoGallery
"{A2500497-FD32-493e-B8E5-28D6728DBEF5}" = Readme
"{A4EA3AB4-E78C-4286-96DF-26035507CE55}" = AiO_Scan
"{AC76BA86-7AD7-1033-7B44-AB0000000001}" = Adobe Reader XI (11.0.03)
"{AF0CE7C0-A3E4-4D73-988B-B29187EC6E9A}" = QuickTime
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.ControlPanel" = NVIDIA Control Panel 314.07
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver" = NVIDIA Graphics Driver 314.07
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.NView" = NVIDIA nView 136.53
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX" = NVIDIA PhysX System Software 9.12.1031
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Update" = NVIDIA Update 1.12.12
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_installer" = NVIDIA Install Application
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_NVIDIA.Update" = NVIDIA Update Components
"{B32C75F2-7495-4D01-9431-C11E97D66F8C}" = DocProc
"{B3A1BF34-A336-450D-BC3E-3A854AD270A0}" = AVG 2013
"{B3D5D4E0-E965-41C4-ABFD-A7B1AD0663C2}" = Director
"{B45D9FEE-1AF4-46F3-9A83-2545F81547F5}" = CreativeProjectsTemplates
"{B56D5B09-C4FB-4EA0-8EAD-7BC3E2715A2D}" = DocumentViewer
"{BCC992E5-5C81-4066-9B55-03DC10B24D21}" = InstantShare
"{BF018D2F-C788-4AB1-AB95-1280EAB8F13E}" = TrayApp
"{C9BED750-1211-4480-B1A5-718A3BE15525}" = REALTEK GbE & FE Ethernet PCI-E NIC Driver
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{DEE76D44-8D7C-4A32-8FAE-A813817631FC}" = AVG 2013
"{EC8673DA-F96B-497E-B2DB-BC7B029FD680}" = BufferChm
"{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}" = Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{F4F47155-5B4D-42AA-97F8-490BC52EA7F3}" = Destinations
"{F5266D28-E0B2-4130-BFC5-EE155AD514DC}" = Apple Application Support
"{F65787F3-B356-45EC-8DD0-0E6758EDBCEE}" = WebReg
"{FF26F7EA-BCEE-478C-9A1B-6B4F88717D73}" = CueTour
"Adobe Flash Player ActiveX" = Adobe Flash Player 11 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 11 Plugin
"AtomTime Pro_is1" = AtomTime Pro 3.1d
"AVG" = AVG 2013
"ENTERPRISE" = Microsoft Office Enterprise 2007
"HP Photo & Imaging" = HP Image Zone 4.2
"IDNMitigationAPIs" = Microsoft Internationalized Domain Names Mitigation APIs
"ie7" = Windows Internet Explorer 7
"ie8" = Windows Internet Explorer 8
"InCD!UninstallKey" = InCD
"InstallShield_{2D974D26-BA8F-4A0B-B7EE-3F563AF79746}" = Quicken 2003 Deluxe
"Malwarebytes' Anti-Malware_is1" = Malwarebytes Anti-Malware version 1.70.0.1100
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"Mozilla Firefox 20.0.1 (x86 en-US)" = Mozilla Firefox 20.0.1 (x86 en-US)
"MozillaMaintenanceService" = Mozilla Maintenance Service
"Nero - Burning Rom!UninstallKey" = Nero OEM
"NLSDownlevelMapping" = Microsoft National Language Support Downlevel APIs
"Picasa 3" = Picasa 3
"Quicken Family Lawyer Deluxe" = Family Lawyer Deluxe 8.0
"WinRAR archiver" = WinRAR archiver
"WinZip" = WinZip

========== Last 20 Event Log Errors ==========

[ Application Events ]
Error - 3/16/2013 1:30:21 AM | Computer Name = OWNER-59AC86FE7 | Source = ESENT | ID = 490
Description = svchost (1244) An attempt to open the file "C:\WINDOWS\system32\CatRoot2\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\catdb"
for read / write access failed with system error 32 (0x00000020): "The process
cannot access the file because it is being used by another process. ". The open
file operation will fail with error -1032 (0xfffffbf8).

Error - 3/16/2013 1:30:22 AM | Computer Name = OWNER-59AC86FE7 | Source = ESENT | ID = 490
Description = svchost (1244) An attempt to open the file "C:\WINDOWS\system32\CatRoot2\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\catdb"
for read / write access failed with system error 32 (0x00000020): "The process
cannot access the file because it is being used by another process. ". The open
file operation will fail with error -1032 (0xfffffbf8).

Error - 3/16/2013 1:30:23 AM | Computer Name = OWNER-59AC86FE7 | Source = ESENT | ID = 490
Description = svchost (1244) An attempt to open the file "C:\WINDOWS\system32\CatRoot2\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\catdb"
for read / write access failed with system error 32 (0x00000020): "The process
cannot access the file because it is being used by another process. ". The open
file operation will fail with error -1032 (0xfffffbf8).

Error - 3/16/2013 1:30:24 AM | Computer Name = OWNER-59AC86FE7 | Source = ESENT | ID = 490
Description = svchost (1244) An attempt to open the file "C:\WINDOWS\system32\CatRoot2\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\catdb"
for read / write access failed with system error 32 (0x00000020): "The process
cannot access the file because it is being used by another process. ". The open
file operation will fail with error -1032 (0xfffffbf8).

Error - 3/16/2013 1:30:25 AM | Computer Name = OWNER-59AC86FE7 | Source = ESENT | ID = 490
Description = svchost (1244) An attempt to open the file "C:\WINDOWS\system32\CatRoot2\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\catdb"
for read / write access failed with system error 32 (0x00000020): "The process
cannot access the file because it is being used by another process. ". The open
file operation will fail with error -1032 (0xfffffbf8).

Error - 3/16/2013 1:30:26 AM | Computer Name = OWNER-59AC86FE7 | Source = ESENT | ID = 490
Description = svchost (1244) An attempt to open the file "C:\WINDOWS\system32\CatRoot2\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\catdb"
for read / write access failed with system error 32 (0x00000020): "The process
cannot access the file because it is being used by another process. ". The open
file operation will fail with error -1032 (0xfffffbf8).

Error - 3/16/2013 1:30:28 AM | Computer Name = OWNER-59AC86FE7 | Source = ESENT | ID = 490
Description = svchost (1244) An attempt to open the file "C:\WINDOWS\system32\CatRoot2\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\catdb"
for read / write access failed with system error 32 (0x00000020): "The process
cannot access the file because it is being used by another process. ". The open
file operation will fail with error -1032 (0xfffffbf8).

Error - 4/29/2013 8:41:32 PM | Computer Name = OWNER-59AC86FE7 | Source = Application Error | ID = 1000
Description = Faulting application msimn.exe, version 6.0.2900.5512, faulting module
unknown, version 0.0.0.0, fault address 0x007b3265.

Error - 5/13/2013 12:44:31 PM | Computer Name = OWNER-59AC86FE7 | Source = Application Hang | ID = 1002
Description = Hanging application ntvdm.exe, version 5.1.2600.5512, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.

Error - 5/13/2013 12:47:37 PM | Computer Name = OWNER-59AC86FE7 | Source = Application Hang | ID = 1002
Description = Hanging application ntvdm.exe, version 5.1.2600.5512, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.

[ System Events ]
Error - 5/10/2013 6:57:54 AM | Computer Name = OWNER-59AC86FE7 | Source = Service Control Manager | ID = 7038
Description = The nvUpdatusService service was unable to log on as .\UpdatusUser
with the currently configured password due to the following error: %%1330 To ensure
that the service is configured properly, use the Services snap-in in Microsoft Management
Console
(MMC).

Error - 5/10/2013 6:57:54 AM | Computer Name = OWNER-59AC86FE7 | Source = Service Control Manager | ID = 7000
Description = The NVIDIA Update Service Daemon service failed to start due to the
following error: %%1069

Error - 5/10/2013 6:58:04 AM | Computer Name = OWNER-59AC86FE7 | Source = sr | ID = 1
Description = The System Restore filter encountered the unexpected error '0xC0000001'
while processing the file '' on the volume 'HarddiskVolume1'. It has stopped monitoring
the volume.

Error - 5/15/2013 3:19:09 AM | Computer Name = OWNER-59AC86FE7 | Source = Service Control Manager | ID = 7000
Description = The mrtRate service failed to start due to the following error: %%2

Error - 5/15/2013 3:19:09 AM | Computer Name = OWNER-59AC86FE7 | Source = Service Control Manager | ID = 7038
Description = The nvUpdatusService service was unable to log on as .\UpdatusUser
with the currently configured password due to the following error: %%1330 To ensure
that the service is configured properly, use the Services snap-in in Microsoft Management
Console
(MMC).

Error - 5/15/2013 3:19:09 AM | Computer Name = OWNER-59AC86FE7 | Source = Service Control Manager | ID = 7000
Description = The NVIDIA Update Service Daemon service failed to start due to the
following error: %%1069

Error - 5/21/2013 6:45:00 AM | Computer Name = OWNER-59AC86FE7 | Source = sr | ID = 1
Description = The System Restore filter encountered the unexpected error '0xC0000001'
while processing the file '' on the volume 'HarddiskVolume1'. It has stopped monitoring
the volume.

Error - 5/21/2013 6:45:05 AM | Computer Name = OWNER-59AC86FE7 | Source = Service Control Manager | ID = 7000
Description = The mrtRate service failed to start due to the following error: %%2

Error - 5/21/2013 6:45:05 AM | Computer Name = OWNER-59AC86FE7 | Source = Service Control Manager | ID = 7038
Description = The nvUpdatusService service was unable to log on as .\UpdatusUser
with the currently configured password due to the following error: %%1330 To ensure
that the service is configured properly, use the Services snap-in in Microsoft Management
Console
(MMC).

Error - 5/21/2013 6:45:05 AM | Computer Name = OWNER-59AC86FE7 | Source = Service Control Manager | ID = 7000
Description = The NVIDIA Update Service Daemon service failed to start due to the
following error: %%1069


< End of report >
Hi shadow5,

1. TDSSKiller

Please download TDSSKiller.zip
  • Extract it to your desktop
  • Double click TDSSKiller.exe
  • Press Start Scan
    • Only if Malicious objects are found then ensure Cure is selected
    • Then click Continue > Reboot now
  • Copy and paste the log in your next reply
    • A copy of the log will be saved automatically to the root of the drive (typically C:\)
=========================

In your next post please provide the following:
  • TDSSKiller log
No malicious objects were found. Here is the TDSSKiller log: 20:57:30.0140 1440 TDSS rootkit removing tool 2.8.16.0 Feb 11 2013 18:50:42 20:57:30.0546 1440 ============================================================ 20:57:30.0546 1440 Current date / time: 2013/05/29 20:57:30.0546 20:57:30.0546 1440 SystemInfo: 20:57:30.0546 1440 20:57:30.0546 1440 OS Version: 5.1.2600 ServicePack: 3.0 20:57:30.0546 1440 Product type: Workstation 20:57:30.0546 1440 ComputerName: OWNER-59AC86FE7 20:57:30.0546 1440 UserName: Administrator 20:57:30.0546 1440 Windows directory: C:\WINDOWS 20:57:30.0546 1440 System windows directory: C:\WINDOWS 20:57:30.0546 1440 Processor architecture: Intel x86 20:57:30.0546 1440 Number of processors: 2 20:57:30.0546 1440 Page size: 0x1000 20:57:30.0546 1440 Boot type: Normal boot 20:57:30.0546 1440 ============================================================ 20:57:31.0655 1440 Drive \Device\Harddisk1\DR1 - Size: 0x3A38A25E00 (232.88 Gb), SectorSize: 0x200, Cylinders: 0x76C1, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000054 20:57:31.0671 1440 Drive \Device\Harddisk0\DR0 - Size: 0x7470AFDE00 (465.76 Gb), SectorSize: 0x200, Cylinders: 0xED81, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000054 20:57:31.0796 1440 ============================================================ 20:57:31.0796 1440 \Device\Harddisk1\DR1: 20:57:31.0796 1440 MBR partitions: 20:57:31.0796 1440 \Device\Harddisk1\DR1\Partition1: MBR, Type 0x7, StartLBA 0x3F, BlocksNum 0x1D1C4542 20:57:31.0796 1440 \Device\Harddisk0\DR0: 20:57:31.0796 1440 MBR partitions: 20:57:31.0796 1440 \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x3F, BlocksNum 0x3A384C02 20:57:31.0796 1440 ============================================================ 20:57:31.0827 1440 C: <-> \Device\Harddisk1\DR1\Partition1 20:57:31.0843 1440 F: <-> \Device\Harddisk0\DR0\Partition1 20:57:31.0843 1440 ============================================================ 20:57:31.0843 1440 Initialize success 20:57:31.0843 1440 ============================================================ 20:57:54.0296 3516 ============================================================ 20:57:54.0296 3516 Scan started 20:57:54.0296 3516 Mode: Manual; 20:57:54.0296 3516 ============================================================ 20:57:55.0108 3516 ================ Scan system memory ======================== 20:57:55.0108 3516 System memory - ok 20:57:55.0108 3516 ================ Scan services ============================= 20:57:55.0140 3516 Abiosdsk - ok 20:57:55.0155 3516 abp480n5 - ok 20:57:55.0186 3516 [ 8FD99680A539792A30E97944FDAECF17 ] ACPI C:\WINDOWS\system32\DRIVERS\ACPI.sys 20:57:55.0186 3516 ACPI - ok 20:57:55.0218 3516 [ 9859C0F6936E723E4892D7141B1327D5 ] ACPIEC C:\WINDOWS\system32\drivers\ACPIEC.sys 20:57:55.0233 3516 ACPIEC - ok 20:57:55.0265 3516 [ 46A5CBB09B8F0C46F8CBE9210E5E3BE2 ] AcrSch2Svc C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe 20:57:55.0280 3516 AcrSch2Svc - ok 20:57:55.0280 3516 adpu160m - ok 20:57:55.0327 3516 [ 8BED39E3C35D6A489438B8141717A557 ] aec C:\WINDOWS\system32\drivers\aec.sys 20:57:55.0327 3516 aec - ok 20:57:55.0374 3516 [ 1E44BC1E83D8FD2305F8D452DB109CF9 ] AFD C:\WINDOWS\System32\drivers\afd.sys 20:57:55.0374 3516 AFD - ok 20:57:55.0374 3516 Aha154x - ok 20:57:55.0374 3516 aic78u2 - ok 20:57:55.0374 3516 aic78xx - ok 20:57:55.0405 3516 [ A9A3DAA780CA6C9671A19D52456705B4 ] Alerter C:\WINDOWS\system32\alrsvc.dll 20:57:55.0405 3516 Alerter - ok 20:57:55.0421 3516 [ 8C515081584A38AA007909CD02020B3D ] ALG C:\WINDOWS\System32\alg.exe 20:57:55.0421 3516 ALG - ok 20:57:55.0421 3516 AliIde - ok 20:57:55.0483 3516 [ 267FC636801EDC5AB28E14036349E3BE ] Ambfilt C:\WINDOWS\system32\drivers\Ambfilt.sys 20:57:55.0530 3516 Ambfilt - ok 20:57:55.0530 3516 amsint - ok 20:57:55.0546 3516 [ D8849F77C0B66226335A59D26CB4EDC6 ] AppMgmt C:\WINDOWS\System32\appmgmts.dll 20:57:55.0546 3516 AppMgmt - ok 20:57:55.0546 3516 asc - ok 20:57:55.0546 3516 asc3350p - ok 20:57:55.0546 3516 asc3550 - ok 20:57:55.0624 3516 [ E1A1206A4FB19B675E947B29CCD25FBA ] aspnet_state C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\aspnet_state.exe 20:57:55.0624 3516 aspnet_state - ok 20:57:55.0640 3516 [ B153AFFAC761E7F5FCFA822B9C4E97BC ] AsyncMac C:\WINDOWS\system32\DRIVERS\asyncmac.sys 20:57:55.0640 3516 AsyncMac - ok 20:57:55.0655 3516 [ 9F3A2F5AA6875C72BF062C712CFA2674 ] atapi C:\WINDOWS\system32\DRIVERS\atapi.sys 20:57:55.0655 3516 atapi - ok 20:57:55.0655 3516 Atdisk - ok 20:57:55.0671 3516 [ 9916C1225104BA14794209CFA8012159 ] Atmarpc C:\WINDOWS\system32\DRIVERS\atmarpc.sys 20:57:55.0671 3516 Atmarpc - ok 20:57:55.0686 3516 [ DEF7A7882BEC100FE0B2CE2549188F9D ] AudioSrv C:\WINDOWS\System32\audiosrv.dll 20:57:55.0686 3516 AudioSrv - ok 20:57:55.0718 3516 [ D9F724AA26C010A217C97606B160ED68 ] audstub C:\WINDOWS\system32\DRIVERS\audstub.sys 20:57:55.0718 3516 audstub - ok 20:57:55.0905 3516 [ 50185186719134FA8F307D269106A51C ] AVGIDSAgent C:\Program Files\AVG\AVG2013\avgidsagent.exe 20:57:56.0030 3516 AVGIDSAgent - ok 20:57:56.0061 3516 [ 4750A2A188D39034F5DDDDAE1BF38BF8 ] AVGIDSDriver C:\WINDOWS\system32\DRIVERS\avgidsdriverx.sys 20:57:56.0061 3516 AVGIDSDriver - ok 20:57:56.0093 3516 [ B0DEF92F4E1E6B9242E6C8FAB82703F7 ] AVGIDSHX C:\WINDOWS\system32\DRIVERS\avgidshx.sys 20:57:56.0093 3516 AVGIDSHX - ok 20:57:56.0124 3516 [ A426B2DC795531D99E2EE1952AEC051A ] AVGIDSShim C:\WINDOWS\system32\DRIVERS\avgidsshimx.sys 20:57:56.0124 3516 AVGIDSShim - ok 20:57:56.0124 3516 [ 08FA13787D77A75DC413E27FD92B44E8 ] Avgldx86 C:\WINDOWS\system32\DRIVERS\avgldx86.sys 20:57:56.0124 3516 Avgldx86 - ok 20:57:56.0155 3516 [ 3E587EE55C70E6DB78A98D7121D3052E ] Avglogx C:\WINDOWS\system32\DRIVERS\avglogx.sys 20:57:56.0155 3516 Avglogx - ok 20:57:56.0155 3516 [ 5AC56B2CF8EE751796C5A8FC5C631B66 ] Avgmfx86 C:\WINDOWS\system32\DRIVERS\avgmfx86.sys 20:57:56.0155 3516 Avgmfx86 - ok 20:57:56.0155 3516 [ C29E6070396E437FDE184D739CCBA2C7 ] Avgrkx86 C:\WINDOWS\system32\DRIVERS\avgrkx86.sys 20:57:56.0155 3516 Avgrkx86 - ok 20:57:56.0202 3516 [ 14370FB29526F593C04FA48B5D69F7F0 ] Avgtdix C:\WINDOWS\system32\DRIVERS\avgtdix.sys 20:57:56.0202 3516 Avgtdix - ok 20:57:56.0249 3516 [ 3A0977CB68AF13E2579E47EB8984056B ] avgwd C:\Program Files\AVG\AVG2013\avgwdsvc.exe 20:57:56.0249 3516 avgwd - ok 20:57:56.0296 3516 [ DA1F27D85E0D1525F6621372E7B685E9 ] Beep C:\WINDOWS\system32\drivers\Beep.sys 20:57:56.0296 3516 Beep - ok 20:57:56.0327 3516 [ 574738F61FCA2935F5265DC4E5691314 ] BITS C:\WINDOWS\system32\qmgr.dll 20:57:56.0343 3516 BITS - ok 20:57:56.0390 3516 [ CFD4E51402DA9838B5A04AE680AF54A0 ] Browser C:\WINDOWS\System32\browser.dll 20:57:56.0390 3516 Browser - ok 20:57:56.0405 3516 [ 90A673FC8E12A79AFBED2576F6A7AAF9 ] cbidf2k C:\WINDOWS\system32\drivers\cbidf2k.sys 20:57:56.0421 3516 cbidf2k - ok 20:57:56.0421 3516 cd20xrnt - ok 20:57:56.0436 3516 [ C1B486A7658353D33A10CC15211A873B ] Cdaudio C:\WINDOWS\system32\drivers\Cdaudio.sys 20:57:56.0436 3516 Cdaudio - ok 20:57:56.0483 3516 [ C885B02847F5D2FD45A24E219ED93B32 ] Cdfs C:\WINDOWS\system32\drivers\Cdfs.sys 20:57:56.0483 3516 Cdfs - ok 20:57:56.0515 3516 [ 1F4260CC5B42272D71F79E570A27A4FE ] Cdrom C:\WINDOWS\system32\DRIVERS\cdrom.sys 20:57:56.0515 3516 Cdrom - ok 20:57:56.0515 3516 Changer - ok 20:57:56.0546 3516 [ 1CFE720EB8D93A7158A4EBC3AB178BDE ] CiSvc C:\WINDOWS\system32\cisvc.exe 20:57:56.0546 3516 CiSvc - ok 20:57:56.0546 3516 [ 34CBE729F38138217F9C80212A2A0C82 ] ClipSrv C:\WINDOWS\system32\clipsrv.exe 20:57:56.0546 3516 ClipSrv - ok 20:57:56.0546 3516 CmdIde - ok 20:57:56.0546 3516 COMSysApp - ok 20:57:56.0546 3516 Cpqarray - ok 20:57:56.0577 3516 [ 3D4E199942E29207970E04315D02AD3B ] CryptSvc C:\WINDOWS\System32\cryptsvc.dll 20:57:56.0577 3516 CryptSvc - ok 20:57:56.0577 3516 dac2w2k - ok 20:57:56.0577 3516 dac960nt - ok 20:57:56.0624 3516 [ 6B27A5C03DFB94B4245739065431322C ] DcomLaunch C:\WINDOWS\system32\rpcss.dll 20:57:56.0655 3516 DcomLaunch - ok 20:57:56.0671 3516 [ 5E38D7684A49CACFB752B046357E0589 ] Dhcp C:\WINDOWS\System32\dhcpcsvc.dll 20:57:56.0671 3516 Dhcp - ok 20:57:56.0686 3516 [ 044452051F3E02E7963599FC8F4F3E25 ] Disk C:\WINDOWS\system32\DRIVERS\disk.sys 20:57:56.0686 3516 Disk - ok 20:57:56.0686 3516 dmadmin - ok 20:57:56.0718 3516 [ D992FE1274BDE0F84AD826ACAE022A41 ] dmboot C:\WINDOWS\system32\drivers\dmboot.sys 20:57:56.0749 3516 dmboot - ok 20:57:56.0780 3516 [ 7C824CF7BBDE77D95C08005717A95F6F ] dmio C:\WINDOWS\system32\drivers\dmio.sys 20:57:56.0780 3516 dmio - ok 20:57:56.0796 3516 [ E9317282A63CA4D188C0DF5E09C6AC5F ] dmload C:\WINDOWS\system32\drivers\dmload.sys 20:57:56.0796 3516 dmload - ok 20:57:56.0796 3516 [ 57EDEC2E5F59F0335E92F35184BC8631 ] dmserver C:\WINDOWS\System32\dmserver.dll 20:57:56.0796 3516 dmserver - ok 20:57:56.0843 3516 [ 8A208DFCF89792A484E76C40E5F50B45 ] DMusic C:\WINDOWS\system32\drivers\DMusic.sys 20:57:56.0843 3516 DMusic - ok 20:57:56.0858 3516 [ 5F7E24FA9EAB896051FFB87F840730D2 ] Dnscache C:\WINDOWS\System32\dnsrslvr.dll 20:57:56.0858 3516 Dnscache - ok 20:57:56.0874 3516 [ 0F0F6E687E5E15579EF4DA8DD6945814 ] Dot3svc C:\WINDOWS\System32\dot3svc.dll 20:57:56.0874 3516 Dot3svc - ok 20:57:56.0874 3516 dpti2o - ok 20:57:56.0890 3516 [ 8F5FCFF8E8848AFAC920905FBD9D33C8 ] drmkaud C:\WINDOWS\system32\drivers\drmkaud.sys 20:57:56.0890 3516 drmkaud - ok 20:57:56.0921 3516 [ 2187855A7703ADEF0CEF9EE4285182CC ] EapHost C:\WINDOWS\System32\eapsvc.dll 20:57:56.0921 3516 EapHost - ok 20:57:56.0921 3516 [ BC93B4A066477954555966D77FEC9ECB ] ERSvc C:\WINDOWS\System32\ersvc.dll 20:57:56.0921 3516 ERSvc - ok 20:57:56.0952 3516 [ 65DF52F5B8B6E9BBD183505225C37315 ] Eventlog C:\WINDOWS\system32\services.exe 20:57:56.0952 3516 Eventlog - ok 20:57:56.0999 3516 [ D4991D98F2DB73C60D042F1AEF79EFAE ] EventSystem C:\WINDOWS\system32\es.dll 20:57:56.0999 3516 EventSystem - ok 20:57:57.0015 3516 [ 38D332A6D56AF32635675F132548343E ] Fastfat C:\WINDOWS\system32\drivers\Fastfat.sys 20:57:57.0015 3516 Fastfat - ok 20:57:57.0061 3516 [ 99BC0B50F511924348BE19C7C7313BBF ] FastUserSwitchingCompatibility C:\WINDOWS\System32\shsvcs.dll 20:57:57.0061 3516 FastUserSwitchingCompatibility - ok 20:57:57.0061 3516 [ 92CDD60B6730B9F50F6A1A0C1F8CDC81 ] Fdc C:\WINDOWS\system32\DRIVERS\fdc.sys 20:57:57.0061 3516 Fdc - ok 20:57:57.0077 3516 [ D45926117EB9FA946A6AF572FBE1CAA3 ] Fips C:\WINDOWS\system32\drivers\Fips.sys 20:57:57.0077 3516 Fips - ok 20:57:57.0077 3516 [ 9D27E7B80BFCDF1CDD9B555862D5E7F0 ] Flpydisk C:\WINDOWS\system32\DRIVERS\flpydisk.sys 20:57:57.0077 3516 Flpydisk - ok 20:57:57.0124 3516 [ B2CF4B0786F8212CB92ED2B50C6DB6B0 ] FltMgr C:\WINDOWS\system32\DRIVERS\fltMgr.sys 20:57:57.0124 3516 FltMgr - ok 20:57:57.0124 3516 [ 3E1E2BD4F39B0E2B7DC4F4D2BCC2779A ] Fs_Rec C:\WINDOWS\system32\drivers\Fs_Rec.sys 20:57:57.0124 3516 Fs_Rec - ok 20:57:57.0140 3516 [ 6AC26732762483366C3969C9E4D2259D ] Ftdisk C:\WINDOWS\system32\DRIVERS\ftdisk.sys 20:57:57.0140 3516 Ftdisk - ok 20:57:57.0140 3516 [ 0A02C63C8B144BD8C86B103DEE7C86A2 ] Gpc C:\WINDOWS\system32\DRIVERS\msgpc.sys 20:57:57.0140 3516 Gpc - ok 20:57:57.0186 3516 [ C1B577B2169900F4CF7190C39F085794 ] gusvc C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe 20:57:57.0186 3516 gusvc - ok 20:57:57.0218 3516 [ 573C7D0A32852B48F3058CFD8026F511 ] HDAudBus C:\WINDOWS\system32\DRIVERS\HDAudBus.sys 20:57:57.0218 3516 HDAudBus - ok 20:57:57.0265 3516 [ 4FCCA060DFE0C51A09DD5C3843888BCD ] helpsvc C:\WINDOWS\PCHealth\HelpCtr\Binaries\pchsvc.dll 20:57:57.0265 3516 helpsvc - ok 20:57:57.0280 3516 [ DEB04DA35CC871B6D309B77E1443C796 ] HidServ C:\WINDOWS\System32\hidserv.dll 20:57:57.0280 3516 HidServ - ok 20:57:57.0311 3516 [ CCF82C5EC8A7326C3066DE870C06DAF1 ] HidUsb C:\WINDOWS\system32\DRIVERS\hidusb.sys 20:57:57.0311 3516 HidUsb - ok 20:57:57.0343 3516 [ 8878BD685E490239777BFE51320B88E9 ] hkmsvc C:\WINDOWS\System32\kmsvc.dll 20:57:57.0343 3516 hkmsvc - ok 20:57:57.0343 3516 hpn - ok 20:57:57.0358 3516 [ 5FABA4775D4C61E55EC669D643FFC71F ] HPZid412 C:\WINDOWS\system32\DRIVERS\HPZid412.sys 20:57:57.0358 3516 HPZid412 - ok 20:57:57.0374 3516 [ A3C43980EE1F1BEAC778B44EA65DBDD4 ] HPZipr12 C:\WINDOWS\system32\DRIVERS\HPZipr12.sys 20:57:57.0374 3516 HPZipr12 - ok 20:57:57.0390 3516 [ 2906949BD4E206F2BB0DD1896CE9F66F ] HPZius12 C:\WINDOWS\system32\DRIVERS\HPZius12.sys 20:57:57.0390 3516 HPZius12 - ok 20:57:57.0421 3516 [ F80A415EF82CD06FFAF0D971528EAD38 ] HTTP C:\WINDOWS\system32\Drivers\HTTP.sys 20:57:57.0421 3516 HTTP - ok 20:57:57.0468 3516 [ 6100A808600F44D999CEBDEF8841C7A3 ] HTTPFilter C:\WINDOWS\System32\w3ssl.dll 20:57:57.0468 3516 HTTPFilter - ok 20:57:57.0468 3516 i2omgmt - ok 20:57:57.0468 3516 i2omp - ok 20:57:57.0499 3516 [ 4A0B06AA8943C1E332520F7440C0AA30 ] i8042prt C:\WINDOWS\system32\DRIVERS\i8042prt.sys 20:57:57.0515 3516 i8042prt - ok 20:57:57.0515 3516 [ 083A052659F5310DD8B6A6CB05EDCF8E ] Imapi C:\WINDOWS\system32\DRIVERS\imapi.sys 20:57:57.0515 3516 Imapi - ok 20:57:57.0546 3516 [ 30DEAF54A9755BB8546168CFE8A6B5E1 ] ImapiService C:\WINDOWS\system32\imapi.exe 20:57:57.0546 3516 ImapiService - ok 20:57:57.0561 3516 [ D7DC964355FDEDE9F1CE1F155250FD73 ] InCDfs C:\WINDOWS\system32\drivers\InCDfs.sys 20:57:57.0561 3516 InCDfs - ok 20:57:57.0577 3516 [ 2106862CD0195042CDE78CD05B89A6A7 ] InCDPass C:\WINDOWS\system32\DRIVERS\InCDPass.sys 20:57:57.0577 3516 InCDPass - ok 20:57:57.0577 3516 [ 65B3AA08CB3C22393FADEF29E060DB02 ] InCDrec C:\WINDOWS\system32\drivers\InCDrec.sys 20:57:57.0577 3516 InCDrec - ok 20:57:57.0640 3516 [ BE3F8B8012F5614448E72CF44B55DD03 ] InCDsrv C:\Program Files\Ahead\InCD\InCDsrv.exe 20:57:57.0671 3516 InCDsrv - ok 20:57:57.0671 3516 ini910u - ok 20:57:57.0874 3516 [ 063DD51CBDC37B8668E09148E0A118BC ] IntcAzAudAddService C:\WINDOWS\system32\drivers\RtkHDAud.sys 20:57:58.0030 3516 IntcAzAudAddService - ok 20:57:58.0030 3516 IntelIde - ok 20:57:58.0061 3516 [ 8C953733D8F36EB2133F5BB58808B66B ] intelppm C:\WINDOWS\system32\DRIVERS\intelppm.sys 20:57:58.0061 3516 intelppm - ok 20:57:58.0093 3516 [ 3BB22519A194418D5FEC05D800A19AD0 ] Ip6Fw C:\WINDOWS\system32\DRIVERS\Ip6Fw.sys 20:57:58.0093 3516 Ip6Fw - ok 20:57:58.0108 3516 [ 731F22BA402EE4B62748ADAF6363C182 ] IpFilterDriver C:\WINDOWS\system32\DRIVERS\ipfltdrv.sys 20:57:58.0108 3516 IpFilterDriver - ok 20:57:58.0108 3516 [ B87AB476DCF76E72010632B5550955F5 ] IpInIp C:\WINDOWS\system32\DRIVERS\ipinip.sys 20:57:58.0108 3516 IpInIp - ok 20:57:58.0124 3516 [ CC748EA12C6EFFDE940EE98098BF96BB ] IpNat C:\WINDOWS\system32\DRIVERS\ipnat.sys 20:57:58.0124 3516 IpNat - ok 20:57:58.0155 3516 [ 23C74D75E36E7158768DD63D92789A91 ] IPSec C:\WINDOWS\system32\DRIVERS\ipsec.sys 20:57:58.0155 3516 IPSec - ok 20:57:58.0202 3516 [ C93C9FF7B04D772627A3646D89F7BF89 ] IRENUM C:\WINDOWS\system32\DRIVERS\irenum.sys 20:57:58.0202 3516 IRENUM - ok 20:57:58.0218 3516 [ 05A299EC56E52649B1CF2FC52D20F2D7 ] isapnp C:\WINDOWS\system32\DRIVERS\isapnp.sys 20:57:58.0218 3516 isapnp - ok 20:57:58.0233 3516 [ 463C1EC80CD17420A542B7F36A36F128 ] Kbdclass C:\WINDOWS\system32\DRIVERS\kbdclass.sys 20:57:58.0233 3516 Kbdclass - ok 20:57:58.0249 3516 [ 9EF487A186DEA361AA06913A75B3FA99 ] kbdhid C:\WINDOWS\system32\DRIVERS\kbdhid.sys 20:57:58.0249 3516 kbdhid - ok 20:57:58.0265 3516 [ 692BCF44383D056AED41B045A323D378 ] kmixer C:\WINDOWS\system32\drivers\kmixer.sys 20:57:58.0280 3516 kmixer - ok 20:57:58.0296 3516 [ B467646C54CC746128904E1654C750C1 ] KSecDD C:\WINDOWS\system32\drivers\KSecDD.sys 20:57:58.0296 3516 KSecDD - ok 20:57:58.0327 3516 [ 3A7C3CBE5D96B8AE96CE81F0B22FB527 ] LanmanServer C:\WINDOWS\System32\srvsvc.dll 20:57:58.0327 3516 LanmanServer - ok 20:57:58.0358 3516 [ A8888A5327621856C0CEC4E385F69309 ] lanmanworkstation C:\WINDOWS\System32\wkssvc.dll 20:57:58.0374 3516 lanmanworkstation - ok 20:57:58.0374 3516 lbrtfdc - ok 20:57:58.0405 3516 [ A7DB739AE99A796D91580147E919CC59 ] LmHosts C:\WINDOWS\System32\lmhsvc.dll 20:57:58.0405 3516 LmHosts - ok 20:57:58.0421 3516 [ 629CABB0421668C9D3D402A3C3D77E14 ] MBAMProtector C:\WINDOWS\system32\drivers\mbam.sys 20:57:58.0421 3516 MBAMProtector - ok 20:57:58.0468 3516 [ 1ACAA67676E9E7BDA5E0C41B6E0DECAF ] MBAMScheduler C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe 20:57:58.0483 3516 MBAMScheduler - ok 20:57:58.0499 3516 [ 916B8954AC3E06DC9E898AFFB41F3FB6 ] MBAMService C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe 20:57:58.0530 3516 MBAMService - ok 20:57:58.0546 3516 [ 986B1FF5814366D71E0AC5755C88F2D3 ] Messenger C:\WINDOWS\System32\msgsvc.dll 20:57:58.0561 3516 Messenger - ok 20:57:58.0624 3516 [ FAFE367D032ED82E9332B4C741A20216 ] Microsoft Office Groove Audit Service C:\Program Files\Microsoft Office\Office12\GrooveAuditService.exe 20:57:58.0624 3516 Microsoft Office Groove Audit Service - ok 20:57:58.0671 3516 [ 4AE068242760A1FB6E1A44BF4E16AFA6 ] mnmdd C:\WINDOWS\system32\drivers\mnmdd.sys 20:57:58.0671 3516 mnmdd - ok 20:57:58.0686 3516 [ D18F1F0C101D06A1C1ADF26EED16FCDD ] mnmsrvc C:\WINDOWS\system32\mnmsrvc.exe 20:57:58.0686 3516 mnmsrvc - ok 20:57:58.0718 3516 [ DFCBAD3CEC1C5F964962AE10E0BCC8E1 ] Modem C:\WINDOWS\system32\drivers\Modem.sys 20:57:58.0718 3516 Modem - ok 20:57:58.0765 3516 [ C7D9F9717916B34C1B00DD4834AF485C ] Monfilt C:\WINDOWS\system32\drivers\Monfilt.sys 20:57:58.0796 3516 Monfilt - ok 20:57:58.0796 3516 [ 35C9E97194C8CFB8430125F8DBC34D04 ] Mouclass C:\WINDOWS\system32\DRIVERS\mouclass.sys 20:57:58.0796 3516 Mouclass - ok 20:57:58.0827 3516 [ B1C303E17FB9D46E87A98E4BA6769685 ] mouhid C:\WINDOWS\system32\DRIVERS\mouhid.sys 20:57:58.0827 3516 mouhid - ok 20:57:58.0858 3516 [ A80B9A0BAD1B73637DBCBBA7DF72D3FD ] MountMgr C:\WINDOWS\system32\drivers\MountMgr.sys 20:57:58.0858 3516 MountMgr - ok 20:57:58.0905 3516 [ 825BF0E46B4470A463AEB641480C5FCA ] MozillaMaintenance C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe 20:57:58.0905 3516 MozillaMaintenance - ok 20:57:58.0905 3516 mraid35x - ok 20:57:58.0921 3516 mrtRate - ok 20:57:58.0921 3516 [ 11D42BB6206F33FBB3BA0288D3EF81BD ] MRxDAV C:\WINDOWS\system32\DRIVERS\mrxdav.sys 20:57:58.0921 3516 MRxDAV - ok 20:57:58.0968 3516 [ 7D304A5EB4344EBEEAB53A2FE3FFB9F0 ] MRxSmb C:\WINDOWS\system32\DRIVERS\mrxsmb.sys 20:57:58.0983 3516 MRxSmb - ok 20:57:59.0015 3516 [ A137F1470499A205ABBB9AAFB3B6F2B1 ] MSDTC C:\WINDOWS\system32\msdtc.exe 20:57:59.0030 3516 MSDTC - ok 20:57:59.0030 3516 [ C941EA2454BA8350021D774DAF0F1027 ] Msfs C:\WINDOWS\system32\drivers\Msfs.sys 20:57:59.0030 3516 Msfs - ok 20:57:59.0030 3516 MSIServer - ok 20:57:59.0046 3516 [ D1575E71568F4D9E14CA56B7B0453BF1 ] MSKSSRV C:\WINDOWS\system32\drivers\MSKSSRV.sys 20:57:59.0046 3516 MSKSSRV - ok 20:57:59.0077 3516 [ 325BB26842FC7CCC1FCCE2C457317F3E ] MSPCLOCK C:\WINDOWS\system32\drivers\MSPCLOCK.sys 20:57:59.0077 3516 MSPCLOCK - ok 20:57:59.0077 3516 [ BAD59648BA099DA4A17680B39730CB3D ] MSPQM C:\WINDOWS\system32\drivers\MSPQM.sys 20:57:59.0077 3516 MSPQM - ok 20:57:59.0108 3516 [ AF5F4F3F14A8EA2C26DE30F7A1E17136 ] mssmbios C:\WINDOWS\system32\DRIVERS\mssmbios.sys 20:57:59.0108 3516 mssmbios - ok 20:57:59.0124 3516 [ DE6A75F5C270E756C5508D94B6CF68F5 ] Mup C:\WINDOWS\system32\drivers\Mup.sys 20:57:59.0124 3516 Mup - ok 20:57:59.0155 3516 [ 0102140028FAD045756796E1C685D695 ] napagent C:\WINDOWS\System32\qagentrt.dll 20:57:59.0155 3516 napagent - ok 20:57:59.0171 3516 [ 1DF7F42665C94B825322FAE71721130D ] NDIS C:\WINDOWS\system32\drivers\NDIS.sys 20:57:59.0186 3516 NDIS - ok 20:57:59.0186 3516 [ 0109C4F3850DFBAB279542515386AE22 ] NdisTapi C:\WINDOWS\system32\DRIVERS\ndistapi.sys 20:57:59.0186 3516 NdisTapi - ok 20:57:59.0218 3516 [ F927A4434C5028758A842943EF1A3849 ] Ndisuio C:\WINDOWS\system32\DRIVERS\ndisuio.sys 20:57:59.0218 3516 Ndisuio - ok 20:57:59.0233 3516 [ EDC1531A49C80614B2CFDA43CA8659AB ] NdisWan C:\WINDOWS\system32\DRIVERS\ndiswan.sys 20:57:59.0233 3516 NdisWan - ok 20:57:59.0249 3516 [ 9282BD12DFB069D3889EB3FCC1000A9B ] NDProxy C:\WINDOWS\system32\drivers\NDProxy.sys 20:57:59.0249 3516 NDProxy - ok 20:57:59.0249 3516 [ 5D81CF9A2F1A3A756B66CF684911CDF0 ] NetBIOS C:\WINDOWS\system32\DRIVERS\netbios.sys 20:57:59.0249 3516 NetBIOS - ok 20:57:59.0280 3516 [ 74B2B2F5BEA5E9A3DC021D685551BD3D ] NetBT C:\WINDOWS\system32\DRIVERS\netbt.sys 20:57:59.0280 3516 NetBT - ok 20:57:59.0311 3516 [ B857BA82860D7FF85AE29B095645563B ] NetDDE C:\WINDOWS\system32\netdde.exe 20:57:59.0311 3516 NetDDE - ok 20:57:59.0311 3516 [ B857BA82860D7FF85AE29B095645563B ] NetDDEdsdm C:\WINDOWS\system32\netdde.exe 20:57:59.0311 3516 NetDDEdsdm - ok 20:57:59.0343 3516 [ BF2466B3E18E970D8A976FB95FC1CA85 ] Netlogon C:\WINDOWS\system32\lsass.exe 20:57:59.0343 3516 Netlogon - ok 20:57:59.0390 3516 [ 13E67B55B3ABD7BF3FE7AAE5A0F9A9DE ] Netman C:\WINDOWS\System32\netman.dll 20:57:59.0390 3516 Netman - ok 20:57:59.0390 3516 [ 943337D786A56729263071623BBB9DE5 ] Nla C:\WINDOWS\System32\mswsock.dll 20:57:59.0405 3516 Nla - ok 20:57:59.0405 3516 [ 3182D64AE053D6FB034F44B6DEF8034A ] Npfs C:\WINDOWS\system32\drivers\Npfs.sys 20:57:59.0405 3516 Npfs - ok 20:57:59.0436 3516 [ 78A08DD6A8D65E697C18E1DB01C5CDCA ] Ntfs C:\WINDOWS\system32\drivers\Ntfs.sys 20:57:59.0452 3516 Ntfs - ok 20:57:59.0452 3516 [ BF2466B3E18E970D8A976FB95FC1CA85 ] NtLmSsp C:\WINDOWS\system32\lsass.exe 20:57:59.0452 3516 NtLmSsp - ok 20:57:59.0483 3516 [ 156F64A3345BD23C600655FB4D10BC08 ] NtmsSvc C:\WINDOWS\system32\ntmssvc.dll 20:57:59.0499 3516 NtmsSvc - ok 20:57:59.0515 3516 [ 73C1E1F395918BC2C6DD67AF7591A3AD ] Null C:\WINDOWS\system32\drivers\Null.sys 20:57:59.0515 3516 Null - ok 20:57:59.0843 3516 [ CADFF8601B10D406DAAF56C6ACA36502 ] nv C:\WINDOWS\system32\DRIVERS\nv4_mini.sys 20:58:00.0108 3516 nv - ok 20:58:00.0140 3516 [ 9E95E0F8EDE1CCEBF70D9E388D467814 ] NVSvc C:\WINDOWS\system32\nvsvc32.exe 20:58:00.0140 3516 NVSvc - ok 20:58:00.0233 3516 [ 0B2B188B73EA97B2506D0A4BE819D48C ] nvUpdatusService C:\Program Files\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe 20:58:00.0265 3516 nvUpdatusService - ok 20:58:00.0311 3516 [ B305F3FAD35083837EF46A0BBCE2FC57 ] NwlnkFlt C:\WINDOWS\system32\DRIVERS\nwlnkflt.sys 20:58:00.0311 3516 NwlnkFlt - ok 20:58:00.0311 3516 [ C99B3415198D1AAB7227F2C88FD664B9 ] NwlnkFwd C:\WINDOWS\system32\DRIVERS\nwlnkfwd.sys 20:58:00.0311 3516 NwlnkFwd - ok 20:58:00.0405 3516 [ 84DE1DD996B48B05ACE31AD015FA108A ] odserv C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE 20:58:00.0421 3516 odserv - ok 20:58:00.0452 3516 [ 5A432A042DAE460ABE7199B758E8606C ] ose C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE 20:58:00.0452 3516 ose - ok 20:58:00.0468 3516 [ 5575FAF8F97CE5E713D108C2A58D7C7C ] Parport C:\WINDOWS\system32\DRIVERS\parport.sys 20:58:00.0468 3516 Parport - ok 20:58:00.0468 3516 [ BEB3BA25197665D82EC7065B724171C6 ] PartMgr C:\WINDOWS\system32\drivers\PartMgr.sys 20:58:00.0468 3516 PartMgr - ok 20:58:00.0515 3516 [ 70E98B3FD8E963A6A46A2E6247E0BEA1 ] ParVdm C:\WINDOWS\system32\drivers\ParVdm.sys 20:58:00.0515 3516 ParVdm - ok 20:58:00.0530 3516 [ A219903CCF74233761D92BEF471A07B1 ] PCI C:\WINDOWS\system32\DRIVERS\pci.sys 20:58:00.0530 3516 PCI - ok 20:58:00.0530 3516 PCIDump - ok 20:58:00.0530 3516 [ CCF5F451BB1A5A2A522A76E670000FF0 ] PCIIde C:\WINDOWS\system32\DRIVERS\pciide.sys 20:58:00.0530 3516 PCIIde - ok 20:58:00.0546 3516 [ 9E89EF60E9EE05E3F2EEF2DA7397F1C1 ] Pcmcia C:\WINDOWS\system32\drivers\Pcmcia.sys 20:58:00.0546 3516 Pcmcia - ok 20:58:00.0546 3516 PDCOMP - ok 20:58:00.0546 3516 PDFRAME - ok 20:58:00.0546 3516 PDRELI - ok 20:58:00.0546 3516 PDRFRAME - ok 20:58:00.0561 3516 perc2 - ok 20:58:00.0561 3516 perc2hib - ok 20:58:00.0593 3516 [ 65DF52F5B8B6E9BBD183505225C37315 ] PlugPlay C:\WINDOWS\system32\services.exe 20:58:00.0593 3516 PlugPlay - ok 20:58:00.0624 3516 [ 901C43516504CBE582E4C4193E00876A ] Pml Driver HPZ12 C:\WINDOWS\system32\HPZipm12.exe 20:58:00.0624 3516 Pml Driver HPZ12 - ok 20:58:00.0624 3516 [ BF2466B3E18E970D8A976FB95FC1CA85 ] PolicyAgent C:\WINDOWS\system32\lsass.exe 20:58:00.0624 3516 PolicyAgent - ok 20:58:00.0640 3516 [ EFEEC01B1D3CF84F16DDD24D9D9D8F99 ] PptpMiniport C:\WINDOWS\system32\DRIVERS\raspptp.sys 20:58:00.0640 3516 PptpMiniport - ok 20:58:00.0640 3516 [ BF2466B3E18E970D8A976FB95FC1CA85 ] ProtectedStorage C:\WINDOWS\system32\lsass.exe 20:58:00.0640 3516 ProtectedStorage - ok 20:58:00.0640 3516 [ 09298EC810B07E5D582CB3A3F9255424 ] PSched C:\WINDOWS\system32\DRIVERS\psched.sys 20:58:00.0640 3516 PSched - ok 20:58:00.0640 3516 [ 80D317BD1C3DBC5D4FE7B1678C60CADD ] Ptilink C:\WINDOWS\system32\DRIVERS\ptilink.sys 20:58:00.0640 3516 Ptilink - ok 20:58:00.0640 3516 ql1080 - ok 20:58:00.0640 3516 Ql10wnt - ok 20:58:00.0640 3516 ql12160 - ok 20:58:00.0655 3516 ql1240 - ok 20:58:00.0655 3516 ql1280 - ok 20:58:00.0686 3516 [ FE0D99D6F31E4FAD8159F690D68DED9C ] RasAcd C:\WINDOWS\system32\DRIVERS\rasacd.sys 20:58:00.0686 3516 RasAcd - ok 20:58:00.0718 3516 [ AD188BE7BDF94E8DF4CA0A55C00A5073 ] RasAuto C:\WINDOWS\System32\rasauto.dll 20:58:00.0718 3516 RasAuto - ok 20:58:00.0718 3516 [ 11B4A627BC9614B885C4969BFA5FF8A6 ] Rasl2tp C:\WINDOWS\system32\DRIVERS\rasl2tp.sys 20:58:00.0718 3516 Rasl2tp - ok 20:58:00.0733 3516 [ 76A9A3CBEADD68CC57CDA5E1D7448235 ] RasMan C:\WINDOWS\System32\rasmans.dll 20:58:00.0733 3516 RasMan - ok 20:58:00.0733 3516 [ 5BC962F2654137C9909C3D4603587DEE ] RasPppoe C:\WINDOWS\system32\DRIVERS\raspppoe.sys 20:58:00.0749 3516 RasPppoe - ok 20:58:00.0749 3516 [ FDBB1D60066FCFBB7452FD8F9829B242 ] Raspti C:\WINDOWS\system32\DRIVERS\raspti.sys 20:58:00.0749 3516 Raspti - ok 20:58:00.0780 3516 [ 7AD224AD1A1437FE28D89CF22B17780A ] Rdbss C:\WINDOWS\system32\DRIVERS\rdbss.sys 20:58:00.0780 3516 Rdbss - ok 20:58:00.0796 3516 [ 4912D5B403614CE99C28420F75353332 ] RDPCDD C:\WINDOWS\system32\DRIVERS\RDPCDD.sys 20:58:00.0796 3516 RDPCDD - ok 20:58:00.0843 3516 [ 15CABD0F7C00C47C70124907916AF3F1 ] rdpdr C:\WINDOWS\system32\DRIVERS\rdpdr.sys 20:58:00.0843 3516 rdpdr - ok 20:58:00.0890 3516 [ 43AF5212BD8FB5BA6EED9754358BD8F7 ] RDPWD C:\WINDOWS\system32\drivers\RDPWD.sys 20:58:00.0890 3516 RDPWD - ok 20:58:00.0921 3516 [ 3C37BF86641BDA977C3BF8A840F3B7FA ] RDSessMgr C:\WINDOWS\system32\sessmgr.exe 20:58:00.0936 3516 RDSessMgr - ok 20:58:00.0952 3516 [ F828DD7E1419B6653894A8F97A0094C5 ] redbook C:\WINDOWS\system32\DRIVERS\redbook.sys 20:58:00.0952 3516 redbook - ok 20:58:00.0983 3516 [ 7E699FF5F59B5D9DE5390E3C34C67CF5 ] RemoteAccess C:\WINDOWS\System32\mprdim.dll 20:58:00.0983 3516 RemoteAccess - ok 20:58:01.0015 3516 [ 5B19B557B0C188210A56A6B699D90B8F ] RemoteRegistry C:\WINDOWS\system32\regsvc.dll 20:58:01.0015 3516 RemoteRegistry - ok 20:58:01.0046 3516 [ AAED593F84AFA419BBAE8572AF87CF6A ] RpcLocator C:\WINDOWS\system32\locator.exe 20:58:01.0046 3516 RpcLocator - ok 20:58:01.0077 3516 [ 6B27A5C03DFB94B4245739065431322C ] RpcSs C:\WINDOWS\system32\rpcss.dll 20:58:01.0077 3516 RpcSs - ok 20:58:01.0124 3516 [ 471B3F9741D762ABE75E9DEEA4787E47 ] RSVP C:\WINDOWS\system32\rsvp.exe 20:58:01.0124 3516 RSVP - ok 20:58:01.0155 3516 [ EB6CAF7C5FCCB50C3E62F878640E082E ] RTLE8023xp C:\WINDOWS\system32\DRIVERS\Rtenicxp.sys 20:58:01.0171 3516 RTLE8023xp - ok 20:58:01.0171 3516 [ BF2466B3E18E970D8A976FB95FC1CA85 ] SamSs C:\WINDOWS\system32\lsass.exe 20:58:01.0171 3516 SamSs - ok 20:58:01.0202 3516 [ 86D007E7A654B9A71D1D7D856B104353 ] SCardSvr C:\WINDOWS\System32\SCardSvr.exe 20:58:01.0202 3516 SCardSvr - ok 20:58:01.0233 3516 [ 0A9A7365A1CA4319AA7C1D6CD8E4EAFA ] Schedule C:\WINDOWS\system32\schedsvc.dll 20:58:01.0249 3516 Schedule - ok 20:58:01.0265 3516 [ 90A3935D05B494A5A39D37E71F09A677 ] Secdrv C:\WINDOWS\system32\DRIVERS\secdrv.sys 20:58:01.0265 3516 Secdrv - ok 20:58:01.0265 3516 [ CBE612E2BB6A10E3563336191EDA1250 ] seclogon C:\WINDOWS\System32\seclogon.dll 20:58:01.0265 3516 seclogon - ok 20:58:01.0280 3516 [ 7FDD5D0684ECA8C1F68B4D99D124DCD0 ] SENS C:\WINDOWS\system32\sens.dll 20:58:01.0280 3516 SENS - ok 20:58:01.0296 3516 [ 0F29512CCD6BEAD730039FB4BD2C85CE ] serenum C:\WINDOWS\system32\DRIVERS\serenum.sys 20:58:01.0296 3516 serenum - ok 20:58:01.0296 3516 [ CCA207A8896D4C6A0C9CE29A4AE411A7 ] Serial C:\WINDOWS\system32\DRIVERS\serial.sys 20:58:01.0296 3516 Serial - ok 20:58:01.0296 3516 [ 8E6B8C671615D126FDC553D1E2DE5562 ] Sfloppy C:\WINDOWS\system32\drivers\Sfloppy.sys 20:58:01.0296 3516 Sfloppy - ok 20:58:01.0311 3516 [ 83F41D0D89645D7235C051AB1D9523AC ] SharedAccess C:\WINDOWS\System32\ipnathlp.dll 20:58:01.0327 3516 SharedAccess - ok 20:58:01.0327 3516 [ 99BC0B50F511924348BE19C7C7313BBF ] ShellHWDetection C:\WINDOWS\System32\shsvcs.dll 20:58:01.0343 3516 ShellHWDetection - ok 20:58:01.0343 3516 Simbad - ok 20:58:01.0374 3516 [ E78C98378A071CE4D48A7C514FA98FA1 ] snapman C:\WINDOWS\system32\DRIVERS\snapman.sys 20:58:01.0374 3516 snapman - ok 20:58:01.0374 3516 Sparrow - ok 20:58:01.0421 3516 [ AB8B92451ECB048A4D1DE7C3FFCB4A9F ] splitter C:\WINDOWS\system32\drivers\splitter.sys 20:58:01.0421 3516 splitter - ok 20:58:01.0452 3516 [ 60784F891563FB1B767F70117FC2428F ] Spooler C:\WINDOWS\system32\spoolsv.exe 20:58:01.0468 3516 Spooler - ok 20:58:01.0483 3516 [ 76BB022C2FB6902FD5BDD4F78FC13A5D ] sr C:\WINDOWS\system32\DRIVERS\sr.sys 20:58:01.0483 3516 sr - ok 20:58:01.0515 3516 [ 3805DF0AC4296A34BA4BF93B346CC378 ] srservice C:\WINDOWS\system32\srsvc.dll 20:58:01.0515 3516 srservice - ok 20:58:01.0561 3516 [ 47DDFC2F003F7F9F0592C6874962A2E7 ] Srv C:\WINDOWS\system32\DRIVERS\srv.sys 20:58:01.0561 3516 Srv - ok 20:58:01.0608 3516 [ 0A5679B3714EDAB99E357057EE88FCA6 ] SSDPSRV C:\WINDOWS\System32\ssdpsrv.dll 20:58:01.0608 3516 SSDPSRV - ok 20:58:01.0655 3516 [ 8BAD69CBAC032D4BBACFCE0306174C30 ] stisvc C:\WINDOWS\system32\wiaservc.dll 20:58:01.0671 3516 stisvc - ok 20:58:01.0671 3516 [ 3941D127AEF12E93ADDF6FE6EE027E0F ] swenum C:\WINDOWS\system32\DRIVERS\swenum.sys 20:58:01.0671 3516 swenum - ok 20:58:01.0686 3516 [ 8CE882BCC6CF8A62F2B2323D95CB3D01 ] swmidi C:\WINDOWS\system32\drivers\swmidi.sys 20:58:01.0686 3516 swmidi - ok 20:58:01.0686 3516 SwPrv - ok 20:58:01.0686 3516 symc810 - ok 20:58:01.0686 3516 symc8xx - ok 20:58:01.0686 3516 sym_hi - ok 20:58:01.0702 3516 sym_u3 - ok 20:58:01.0702 3516 [ 8B83F3ED0F1688B4958F77CD6D2BF290 ] sysaudio C:\WINDOWS\system32\drivers\sysaudio.sys 20:58:01.0702 3516 sysaudio - ok 20:58:01.0749 3516 [ C7ABBC59B43274B1109DF6B24D617051 ] SysmonLog C:\WINDOWS\system32\smlogsvc.exe 20:58:01.0749 3516 SysmonLog - ok 20:58:01.0780 3516 [ 3CB78C17BB664637787C9A1C98F79C38 ] TapiSrv C:\WINDOWS\System32\tapisrv.dll 20:58:01.0796 3516 TapiSrv - ok 20:58:01.0827 3516 [ 9AEFA14BD6B182D61E3119FA5F436D3D ] Tcpip C:\WINDOWS\system32\DRIVERS\tcpip.sys 20:58:01.0843 3516 Tcpip - ok 20:58:01.0874 3516 [ 6471A66807F5E104E4885F5B67349397 ] TDPIPE C:\WINDOWS\system32\drivers\TDPIPE.sys 20:58:01.0874 3516 TDPIPE - ok 20:58:01.0874 3516 [ C56B6D0402371CF3700EB322EF3AAF61 ] TDTCP C:\WINDOWS\system32\drivers\TDTCP.sys 20:58:01.0874 3516 TDTCP - ok 20:58:01.0874 3516 [ 88155247177638048422893737429D9E ] TermDD C:\WINDOWS\system32\DRIVERS\termdd.sys 20:58:01.0874 3516 TermDD - ok 20:58:01.0905 3516 [ FF3477C03BE7201C294C35F684B3479F ] TermService C:\WINDOWS\System32\termsrv.dll 20:58:01.0905 3516 TermService - ok 20:58:01.0905 3516 [ 99BC0B50F511924348BE19C7C7313BBF ] Themes C:\WINDOWS\System32\shsvcs.dll 20:58:01.0921 3516 Themes - ok 20:58:01.0921 3516 [ B84B82C0CBEB1B0D7EB7A946BADE5830 ] tifsfilter C:\WINDOWS\system32\DRIVERS\tifsfilt.sys 20:58:01.0921 3516 tifsfilter - ok 20:58:01.0952 3516 [ 74711884439BDF9CCF446C79CB05FAC0 ] timounter C:\WINDOWS\system32\DRIVERS\timntr.sys 20:58:01.0952 3516 timounter - ok 20:58:01.0983 3516 [ DB7205804759FF62C34E3EFD8A4CC76A ] TlntSvr C:\WINDOWS\system32\tlntsvr.exe 20:58:01.0983 3516 TlntSvr - ok 20:58:01.0983 3516 TosIde - ok 20:58:02.0015 3516 [ 55BCA12F7F523D35CA3CB833C725F54E ] TrkWks C:\WINDOWS\system32\trkwks.dll 20:58:02.0015 3516 TrkWks - ok 20:58:02.0061 3516 [ 5787B80C2E3C5E2F56C2A233D91FA2C9 ] Udfs C:\WINDOWS\system32\drivers\Udfs.sys 20:58:02.0061 3516 Udfs - ok 20:58:02.0061 3516 ultra - ok 20:58:02.0108 3516 [ 402DDC88356B1BAC0EE3DD1580C76A31 ] Update C:\WINDOWS\system32\DRIVERS\update.sys 20:58:02.0108 3516 Update - ok 20:58:02.0140 3516 [ 1EBAFEB9A3FBDC41B8D9C7F0F687AD91 ] upnphost C:\WINDOWS\System32\upnphost.dll 20:58:02.0140 3516 upnphost - ok 20:58:02.0155 3516 [ 05365FB38FCA1E98F7A566AAAF5D1815 ] UPS C:\WINDOWS\System32\ups.exe 20:58:02.0155 3516 UPS - ok 20:58:02.0186 3516 [ 2A3FA9FF6EC8485C98C179131E8A41A7 ] USB-100 C:\WINDOWS\system32\DRIVERS\RTL8150.SYS 20:58:02.0186 3516 USB-100 - ok 20:58:02.0218 3516 [ 173F317CE0DB8E21322E71B7E60A27E8 ] usbccgp C:\WINDOWS\system32\DRIVERS\usbccgp.sys 20:58:02.0218 3516 usbccgp - ok 20:58:02.0265 3516 [ 65DCF09D0E37D4C6B11B5B0B76D470A7 ] usbehci C:\WINDOWS\system32\DRIVERS\usbehci.sys 20:58:02.0265 3516 usbehci - ok 20:58:02.0265 3516 [ 1AB3CDDE553B6E064D2E754EFE20285C ] usbhub C:\WINDOWS\system32\DRIVERS\usbhub.sys 20:58:02.0265 3516 usbhub - ok 20:58:02.0265 3516 [ A717C8721046828520C9EDF31288FC00 ] usbprint C:\WINDOWS\system32\DRIVERS\usbprint.sys 20:58:02.0265 3516 usbprint - ok 20:58:02.0280 3516 [ A0B8CF9DEB1184FBDD20784A58FA75D4 ] usbscan C:\WINDOWS\system32\DRIVERS\usbscan.sys 20:58:02.0280 3516 usbscan - ok 20:58:02.0296 3516 [ A32426D9B14A089EAA1D922E0C5801A9 ] usbstor C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS 20:58:02.0296 3516 usbstor - ok 20:58:02.0311 3516 [ 26496F9DEE2D787FC3E61AD54821FFE6 ] usbuhci C:\WINDOWS\system32\DRIVERS\usbuhci.sys 20:58:02.0311 3516 usbuhci - ok 20:58:02.0327 3516 [ 0D3A8FAFCEACD8B7625CD549757A7DF1 ] VgaSave C:\WINDOWS\System32\drivers\vga.sys 20:58:02.0327 3516 VgaSave - ok 20:58:02.0327 3516 ViaIde - ok 20:58:02.0327 3516 [ 4C8FCB5CC53AAB716D810740FE59D025 ] VolSnap C:\WINDOWS\system32\drivers\VolSnap.sys 20:58:02.0327 3516 VolSnap - ok 20:58:02.0358 3516 [ 7A9DB3A67C333BF0BD42E42B8596854B ] VSS C:\WINDOWS\System32\vssvc.exe 20:58:02.0374 3516 VSS - ok 20:58:02.0390 3516 [ 54AF4B1D5459500EF0937F6D33B1914F ] W32Time C:\WINDOWS\system32\w32time.dll 20:58:02.0390 3516 W32Time - ok 20:58:02.0390 3516 [ E20B95BAEDB550F32DD489265C1DA1F6 ] Wanarp C:\WINDOWS\system32\DRIVERS\wanarp.sys 20:58:02.0405 3516 Wanarp - ok 20:58:02.0405 3516 WDICA - ok 20:58:02.0405 3516 [ 6768ACF64B18196494413695F0C3A00F ] wdmaud C:\WINDOWS\system32\drivers\wdmaud.sys 20:58:02.0405 3516 wdmaud - ok 20:58:02.0421 3516 [ 77A354E28153AD2D5E120A5A8687BC06 ] WebClient C:\WINDOWS\System32\webclnt.dll 20:58:02.0421 3516 WebClient - ok 20:58:02.0499 3516 [ 2D0E4ED081963804CCC196A0929275B5 ] winmgmt C:\WINDOWS\system32\wbem\WMIsvc.dll 20:58:02.0499 3516 winmgmt - ok 20:58:02.0530 3516 [ C7E39EA41233E9F5B86C8DA3A9F1E4A8 ] WmdmPmSN C:\WINDOWS\system32\mspmsnsv.dll 20:58:02.0530 3516 WmdmPmSN - ok 20:58:02.0561 3516 [ E76F8807070ED04E7408A86D6D3A6137 ] Wmi C:\WINDOWS\System32\advapi32.dll 20:58:02.0577 3516 Wmi - ok 20:58:02.0640 3516 [ E0673F1106E62A68D2257E376079F821 ] WmiApSrv C:\WINDOWS\system32\wbem\wmiapsrv.exe 20:58:02.0640 3516 WmiApSrv - ok 20:58:02.0655 3516 [ 7C278E6408D1DCE642230C0585A854D5 ] wscsvc C:\WINDOWS\system32\wscsvc.dll 20:58:02.0655 3516 wscsvc - ok 20:58:02.0702 3516 [ 35321FB577CDC98CE3EB3A3EB9E4610A ] wuauserv C:\WINDOWS\system32\wuauserv.dll 20:58:02.0702 3516 wuauserv - ok 20:58:02.0718 3516 [ 81DC3F549F44B1C1FFF022DEC9ECF30B ] WZCSVC C:\WINDOWS\System32\wzcsvc.dll 20:58:02.0733 3516 WZCSVC - ok 20:58:02.0749 3516 [ 295D21F14C335B53CB8154E5B1F892B9 ] xmlprov C:\WINDOWS\System32\xmlprov.dll 20:58:02.0749 3516 xmlprov - ok 20:58:02.0749 3516 ================ Scan global =============================== 20:58:02.0796 3516 [ 42F1F4C0AFB08410E5F02D4B13EBB623 ] C:\WINDOWS\system32\basesrv.dll 20:58:02.0827 3516 [ 69AE2B2E6968C316536E5B10B9702E63 ] C:\WINDOWS\system32\winsrv.dll 20:58:02.0843 3516 [ 69AE2B2E6968C316536E5B10B9702E63 ] C:\WINDOWS\system32\winsrv.dll 20:58:02.0874 3516 [ 65DF52F5B8B6E9BBD183505225C37315 ] C:\WINDOWS\system32\services.exe 20:58:02.0874 3516 [Global] - ok 20:58:02.0874 3516 ================ Scan MBR ================================== 20:58:02.0890 3516 [ 8F558EB6672622401DA993E1E865C861 ] \Device\Harddisk1\DR1 20:58:03.0061 3516 \Device\Harddisk1\DR1 - ok 20:58:03.0061 3516 [ 8F558EB6672622401DA993E1E865C861 ] \Device\Harddisk0\DR0 20:58:03.0186 3516 \Device\Harddisk0\DR0 - ok 20:58:03.0186 3516 ================ Scan VBR ================================== 20:58:03.0186 3516 [ D825D4DACF1D595C3ED093560BA98885 ] \Device\Harddisk1\DR1\Partition1 20:58:03.0186 3516 \Device\Harddisk1\DR1\Partition1 - ok 20:58:03.0186 3516 [ B607DCCADF629D6942DD138FD58DEA85 ] \Device\Harddisk0\DR0\Partition1 20:58:03.0186 3516 \Device\Harddisk0\DR0\Partition1 - ok 20:58:03.0186 3516 ============================================================ 20:58:03.0186 3516 Scan finished 20:58:03.0186 3516 ============================================================ 20:58:03.0186 3640 Detected object count: 0 20:58:03.0186 3640 Actual detected object count: 0
Hi shadow5,

1. AdwCleaner

Download AdwCleaner and save it to your desktop.
  • Run AdwCleaner and select Delete
  • Once done it will ask to reboot, allow the reboot
  • On reboot a log will be produced, please attach the content of the log to your next reply
=========================

2. ComboFix

Refer to the ComboFix User's Guide

  • Download ComboFix from the following location:

    Link

    * IMPORTANT !!! Place ComboFix.exe on your Desktop
  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with ComboFix.
    You can get help on disabling your protection programs here
  • Double click on ComboFix.exe & follow the prompts.
  • Your desktop may go blank. This is normal. It will return when ComboFix is done. ComboFix may reboot your machine. This is normal.
  • When finished, it shall produce a log for you. Post that log in your next reply

    Note: Do not mouseclick combofix's window whilst it's running. That may cause it to stall.

    ———————————————————————————————
  • Ensure your AntiVirus and AntiSpyware applications are re-enabled.
    ———————————————————————————————
NOTE: If you encounter a message "illegal operation attempted on registry key that has been marked for deletion" and no programs will run - please just reboot and that will resolve that error.

=========================
In your next post please provide the following:
  • AdwCleaner[S1].txt
  • Combofix.txt
Following are texts from AdwCleaner and Combofix:
# AdwCleaner v2.301 - Logfile created 05/29/2013 at 21:54:25
# Updated 16/05/2013 by Xplode
# Operating system : Microsoft Windows XP Service Pack 3 (32 bits)
# User : Administrator - OWNER-59AC86FE7
# Boot Mode : Normal
# Running from : C:\Documents and Settings\Administrator\Desktop\AdwCleaner.exe
# Option [Delete]


***** [Services] *****


***** [Files / Folders] *****

File Deleted : C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\se9y2xik.default\extensions\[removed]
File Deleted : C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\se9y2xik.default\searchplugins\search.xml
Folder Deleted : C:\Documents and Settings\Administrator\Application Data\DefaultTab
Folder Deleted : C:\Program Files\DefaultTab

***** [Registry] *****

Key Deleted : HKCU\Software\Default Tab
Key Deleted : HKLM\Software\AVG Secure Search
Key Deleted : HKLM\Software\AVG Security Toolbar

***** [Internet Browsers] *****

-\\ Internet Explorer v8.0.6001.18702

[OK] Registry is clean.

-\\ Mozilla Firefox v20.0.1 (en-US)

File : C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\se9y2xik.default\prefs.js

C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\se9y2xik.default\user.js … Deleted !

[OK] File is clean.

*************************

AdwCleaner[R1].txt - [1558 octets] - [29/05/2013 21:52:48]
AdwCleaner[S1].txt - [1478 octets] - [29/05/2013 21:54:25]

########## EOF - C:\AdwCleaner[S1].txt - [1538 octets] ##########

ComboFix 13-05-30.01 - Administrator 05/29/2013 22:08:12.1.2 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.3582.2854 [GMT -4:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
AV: AVG AntiVirus Free Edition 2013 *Disabled/Updated* {17DDD097-36FF-435F-9E1B-52D74245D6BF}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\documents and settings\All Users\Application Data\TEMP
c:\windows\~GLC0000.TMP
c:\windows\~GLC0001.TMP
c:\windows\~GLH0000.TMP
c:\windows\~GLH0001.TMP
c:\windows\system32\URTTemp
c:\windows\system32\URTTemp\fusion.dll
c:\windows\system32\URTTemp\mscoree.dll
c:\windows\system32\URTTemp\mscoree.dll.local
c:\windows\system32\URTTemp\mscorsn.dll
c:\windows\system32\URTTemp\mscorwks.dll
c:\windows\system32\URTTemp\msvcr71.dll
c:\windows\system32\URTTemp\regtlib.exe
.
.
((((((((((((((((((((((((( Files Created from 2013-04-28 to 2013-05-30 )))))))))))))))))))))))))))))))
.
.
2013-05-30 00:56 . 2013-05-30 00:56 ——– d—–w- C:\unzipped
2013-05-25 05:22 . 2013-05-25 05:22 ——– d—–w- c:\windows\system32\wbem\Repository
2013-05-24 04:45 . 2013-05-25 05:20 ——– d—–w- c:\program files\Uninstaller
2013-05-24 04:44 . 2013-05-25 05:20 ——– d—–w- c:\documents and settings\Administrator\Application Data\player
2013-05-24 04:41 . 2013-05-24 04:41 ——– d—–w- c:\program files\Microsoft.NET
2013-05-24 04:39 . 2013-05-25 05:20 ——– d—–w- c:\documents and settings\Administrator\Local Settings\Application Data\DownloadTerms
2013-05-13 16:40 . 2013-05-13 16:40 ——– d—–w- c:\windows\system32\Parsons
2013-05-13 16:40 . 1995-04-27 02:33 146976 —-a-w- c:\windows\system32\MFCOLEUI.DLL
2013-05-13 16:40 . 1995-01-03 10:52 10736 —-a-w- c:\windows\system32\RHMMPLAY.DLL
2013-05-13 16:40 . 2013-05-13 16:40 ——– d—–w- c:\program files\Parsons Technology
2013-05-11 10:37 . 2013-05-11 10:37 209472 —-a-w- c:\program files\Internet Explorer\Plugins\nppdf32.dll
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2013-04-16 22:17 . 2008-04-14 12:00 920064 —-a-w- c:\windows\system32\wininet.dll
2013-04-16 22:17 . 2008-04-14 12:00 43520 —-a-w- c:\windows\system32\licmgr10.dll
2013-04-16 22:17 . 2008-04-14 12:00 1469440 —-a-w- c:\windows\system32\inetcpl.cpl
2013-04-12 23:28 . 2008-04-14 12:00 385024 —-a-w- c:\windows\system32\html.iec
2013-04-10 01:31 . 2008-04-14 12:00 1876352 —-a-w- c:\windows\system32\win32k.sys
2013-04-02 14:09 . 2013-04-02 14:09 4550656 —-a-w- c:\windows\system32\GPhotos.scr
2013-03-29 06:53 . 2013-02-27 03:40 208184 —-a-w- c:\windows\system32\drivers\avgidsdriverx.sys
2013-03-21 07:08 . 2013-02-14 07:52 182072 —-a-w- c:\windows\system32\drivers\avgtdix.sys
2013-03-08 08:36 . 2008-04-14 12:00 293376 —-a-w- c:\windows\system32\winsrv.dll
2013-03-07 01:32 . 2008-04-14 12:00 2149888 —-a-w- c:\windows\system32\ntoskrnl.exe
2013-03-07 00:50 . 2008-04-14 00:01 2028544 —-a-w- c:\windows\system32\ntkrnlpa.exe
2013-03-01 14:32 . 2013-03-01 14:32 22328 —-a-w- c:\windows\system32\drivers\avgidsshimx.sys
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RTHDCPL"="RTHDCPL.EXE" [2012-06-06 20065936]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2013-04-04 958576]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2006-10-27 31016]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2004-02-12 49152]
"TrueImageMonitor.exe"="c:\program files\Acronis\TrueImageHome\TrueImageMonitor.exe" [2007-02-16 1169776]
"AcronisTimounterMonitor"="c:\program files\Acronis\TrueImageHome\TimounterMonitor.exe" [2007-02-16 1945960]
"Acronis Scheduler2 Service"="c:\program files\Common Files\Acronis\Schedule2\schedhlp.exe" [2007-02-16 149024]
"HP Component Manager"="c:\program files\HP\hpcoretech\hpcmpmgr.exe" [2004-05-12 241664]
"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648]
"InCD"="c:\program files\Ahead\InCD\InCD.exe" [2003-11-25 1232946]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2013-02-10 15664416]
"NvMediaCenter"="NvMCTray.dll" [2013-02-10 223008]
"nwiz"="c:\program files\NVIDIA Corporation\nview\nwiz.exe" [2013-02-10 1982312]
"APSDaemon"="c:\program files\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2012-10-12 59280]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2012-10-25 421888]
"AVG_UI"="c:\program files\AVG\AVG2013\avgui.exe" [2013-04-29 4408368]
.
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Billminder.lnk - c:\program files\Quicken\billmind.exe [2002-7-30 36864]
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2004-5-28 241664]
HP Image Zone Fast Start.lnk - c:\program files\HP\Digital Imaging\bin\hpqthb08.exe [2004-5-29 53248]
Quicken Scheduled Updates.lnk - c:\program files\Quicken\bagent.exe [2002-7-30 53248]
Quicken Startup.lnk - c:\program files\Quicken\QWDLLS.EXE [2002-7-30 36864]
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk *\0c:\progra~1\AVG\AVG2013\avgrsx.exe /sync /restart
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\Program Files\\NVIDIA Corporation\\NVIDIA Update Core\\daemonu.exe"=
"c:\\Program Files\\Common Files\\Apple\\Apple Application Support\\WebKit2WebProcess.exe"=
"c:\\Program Files\\AVG\\AVG2013\\avgmfapx.exe"=
"c:\\Program Files\\AVG\\AVG2013\\avgnsx.exe"=
"c:\\Program Files\\AVG\\AVG2013\\avgdiagex.exe"=
"c:\\Program Files\\AVG\\AVG2013\\avgemcx.exe"=
.
R0 AVGIDSHX;AVGIDSHX;c:\windows\system32\drivers\avgidshx.sys [2/8/2013 4:37 AM 60216]
R0 Avglogx;AVG Logging Driver;c:\windows\system32\drivers\avglogx.sys [2/8/2013 4:37 AM 245048]
R0 Avgrkx86;AVG Anti-Rootkit Driver;c:\windows\system32\drivers\avgrkx86.sys [2/8/2013 4:37 AM 39224]
R1 AVGIDSDriver;AVGIDSDriver;c:\windows\system32\drivers\avgidsdriverx.sys [2/26/2013 11:40 PM 208184]
R1 AVGIDSShim;AVGIDSShim;c:\windows\system32\drivers\avgidsshimx.sys [3/1/2013 10:32 AM 22328]
R1 Avgldx86;AVG AVI Loader Driver;c:\windows\system32\drivers\avgldx86.sys [2/8/2013 4:37 AM 170808]
R1 Avgtdix;AVG TDI Driver;c:\windows\system32\drivers\avgtdix.sys [2/14/2013 3:52 AM 182072]
R2 avgwd;AVG WatchDog;c:\program files\AVG\AVG2013\avgwdsvc.exe [4/18/2013 4:34 AM 283136]
R2 MBAMScheduler;MBAMScheduler;c:\program files\Malwarebytes' Anti-Malware\mbamscheduler.exe [3/29/2013 4:41 PM 398184]
R2 MBAMService;MBAMService;c:\program files\Malwarebytes' Anti-Malware\mbamservice.exe [3/29/2013 4:41 PM 682344]
R3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [3/29/2013 4:41 PM 21104]
S2 AVGIDSAgent;AVGIDSAgent;c:\program files\AVG\AVG2013\avgidsagent.exe [5/14/2013 12:54 AM 4937264]
S2 mrtRate;mrtRate; [x]
S3 Ambfilt;Ambfilt;c:\windows\system32\drivers\Ambfilt.sys [1/9/2013 7:54 PM 1691480]
S3 USB-100;Realtek RTL8150 USB 10/100 Fast Ethernet Adapter;c:\windows\system32\drivers\RTL8150.SYS [4/18/2012 4:02 PM 26505]
.
Contents of the 'Scheduled Tasks' folder
.
2013-05-24 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2011-06-01 22:57]
.
2013-05-30 c:\windows\Tasks\User_Feed_Synchronization-{BF0383E8-AAC2-4B96-BC72-182AF1754472}.job
- c:\windows\system32\msfeedssync.exe [2007-08-13 09:31]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.wyff4.com/
uDefault_Search_URL = hxxp://www.google.com/ie
uInternet Connection Wizard,ShellNext = hxxp://www.driverint.com/RealtekDrivers/WDM_R270.zip
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
TCP: DhcpNameServer = 192.168.1.254
FF - ProfilePath - c:\documents and settings\Administrator\Application Data\Mozilla\Firefox\Profiles\se9y2xik.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.wyff4.com/
FF - ExtSQL: 2013-05-23 00:00; [removed]; c:\documents and settings\Administrator\Application Data\Mozilla\Firefox\Profiles\se9y2xik.default\extensions\[removed]
FF - ExtSQL: 2013-05-24 00:39; [removed]; c:\documents and settings\Administrator\Application Data\Mozilla\Firefox\Profiles\se9y2xik.default\extensions\[removed]
.
- - - - ORPHANS REMOVED - - - -
.
HKCU-Run-ROC_ROC_APR2013_AV - c:\documents and settings\Administrator\Application Data\AVG April 2013 Campaign\AVG-Secure-Search-Update.exe
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2013-05-29 22:13
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes …
.
scanning hidden autostart entries …
.
scanning hidden files …
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————
.
[HKEY_USERS\S-1-5-21-1123561945-854245398-1417001333-500\Software\Microsoft\Internet Explorer\User Preferences]
@Denied: (2) (Administrator)
"88D7D0879DAB32E14DE5B3A805A34F98AFF34F5977"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,3a,d1,96,48,5a,37,4b,47,95,df,7c,\
"2D53CFFC5C1A3DD2E97B7979AC2A92BD59BC839E81"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,3a,d1,96,48,5a,37,4b,47,95,df,7c,\
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil32_11_5_502_146_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil32_11_5_502_146_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
——————— DLLs Loaded Under Running Processes ———————
.
- - - - - - - > 'lsass.exe'(1144)
c:\windows\system32\relog_ap.dll
.
Completion time: 2013-05-29 22:14:25
ComboFix-quarantined-files.txt 2013-05-30 02:14
.
Pre-Run: 126,989,246,464 bytes free
Post-Run: 128,590,077,952 bytes free
.
WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
UnsupportedDebug="do not select this" /debug
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect
.
- - End Of File - - 829C7FA9A39949406BAD852D3532306F
Hello shadow5,

1. OTL

Re-run OTL (it should be located on your desktop).
  • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output.
  • Uncheck the boxes beside LOP Check and Purity Check.
  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
  • When the scan completes, it will open one notepad window. OTL.Txt.
    Note:The log can be located in the OTL. folder on you C:\ drive if they fail to open automatically.
  • Please copy (Edit->Select All, Edit->Copy) the contents of the file, and post it with your next reply.
=========================

In your next post please provide the following:
  • OTL.txt
  • How is the computer running?
Here is the last OTL.txt:
OTL logfile created on: 5/29/2013 11:06:45 PM - Run 2
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Documents and Settings\Administrator\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

3.50 Gb Total Physical Memory | 2.75 Gb Available Physical Memory | 78.64% Memory free
6.84 Gb Paging File | 6.22 Gb Available in Paging File | 91.04% Paging File free
Paging file location(s): C:\pagefile.sys 0 0 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 232.88 Gb Total Space | 119.79 Gb Free Space | 51.44% Space Free | Partition Type: NTFS
Drive F: | 465.76 Gb Total Space | 272.68 Gb Free Space | 58.55% Space Free | Partition Type: NTFS

Computer Name: OWNER-59AC86FE7 | User Name: Administrator | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Documents and Settings\Administrator\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\AVG\AVG2013\avgidsagent.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG2013\avgui.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG2013\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG2013\avgnsx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG2013\avgrsx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG2013\avgemcx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG2013\avgcsrvx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe (NVIDIA Corporation)
PRC - C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe (Malwarebytes Corporation)
PRC - C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
PRC - C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe (Malwarebytes Corporation)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Acronis\TrueImageHome\TimounterMonitor.exe (Acronis)
PRC - C:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exe (Acronis)
PRC - C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe (Acronis)
PRC - C:\Program Files\Acronis\TrueImageHome\TrueImageMonitor.exe (Acronis)
PRC - C:\WINDOWS\system32\HPZipm12.exe (HP)
PRC - C:\Program Files\Ahead\InCD\InCD.exe (Ahead Software AG)
PRC - C:\Program Files\Ahead\InCD\incdsrv.exe (AHEAD Software)


========== Modules (No Company Name) ==========

MOD - c:\windows\assembly\nativeimages1_v1.1.4322\mscorlib\1.0.5000.0__b77a5c561934e089_63022737\mscorlib.dll ()
MOD - c:\windows\assembly\nativeimages1_v1.1.4322\system.drawing\1.0.5000.0__b03f5f7f11d50a3a_a9db4250\system.drawing.dll ()
MOD - c:\windows\assembly\nativeimages1_v1.1.4322\system.xml\1.0.5000.0__b77a5c561934e089_6a7af65d\system.xml.dll ()
MOD - c:\windows\assembly\nativeimages1_v1.1.4322\system.windows.forms\1.0.5000.0__b77a5c561934e089_ea1855d9\system.windows.forms.dll ()
MOD - c:\windows\assembly\nativeimages1_v1.1.4322\system\1.0.5000.0__b77a5c561934e089_7eddb414\system.dll ()
MOD - c:\windows\assembly\gac\system\1.0.5000.0__b77a5c561934e089\system.dll ()
MOD - c:\windows\assembly\gac\system.drawing\1.0.5000.0__b03f5f7f11d50a3a\system.drawing.dll ()
MOD - c:\windows\assembly\gac\system.windows.forms\1.0.5000.0__b77a5c561934e089\system.windows.forms.dll ()
MOD - c:\windows\assembly\gac\system.xml\1.0.5000.0__b77a5c561934e089\system.xml.dll ()
MOD - c:\windows\assembly\gac\hpqietpz\3.0.0.0__a53cf5803f4c3827\hpqietpz.dll ()
MOD - c:\windows\assembly\gac\hpqcprsc\3.0.0.0__a53cf5803f4c3827\hpqcprsc.dll ()
MOD - c:\windows\assembly\gac\hpqcprsc.resources\3.0.0.0_en_a53cf5803f4c3827\hpqcprsc.resources.dll ()
MOD - c:\windows\assembly\gac\hpqisrtb\4.0.0.0__a53cf5803f4c3827\hpqisrtb.dll ()
MOD - c:\windows\assembly\gac\lead.wrapper\13.0.0.66__9cf889f53ea9b907\lead.wrapper.dll ()
MOD - c:\windows\assembly\gac\lead.drawing\13.0.0.66__9cf889f53ea9b907\lead.drawing.dll ()
MOD - c:\windows\assembly\gac\lead\13.0.0.66__9cf889f53ea9b907\lead.dll ()
MOD - c:\windows\assembly\gac\lead.windows.forms\13.0.0.66__9cf889f53ea9b907\lead.windows.forms.dll ()
MOD - c:\windows\assembly\gac\hpqtray\3.0.0.0__a53cf5803f4c3827\hpqtray.dll ()
MOD - c:\windows\assembly\gac\hpqtray.resources\3.0.0.0_en_a53cf5803f4c3827\hpqtray.resources.dll ()
MOD - c:\windows\assembly\gac\hpqimgrc\3.0.0.0__a53cf5803f4c3827\hpqimgrc.dll ()
MOD - c:\windows\assembly\gac\hpqgldlg\3.0.0.0__a53cf5803f4c3827\hpqgldlg.dll ()
MOD - c:\windows\assembly\gac\hpqthumb\3.0.0.0__a53cf5803f4c3827\hpqthumb.dll ()
MOD - c:\windows\assembly\gac\hpqfmrsc\3.0.0.0__a53cf5803f4c3827\hpqfmrsc.dll ()
MOD - c:\windows\assembly\gac\hpqasset\3.0.0.0__a53cf5803f4c3827\hpqasset.dll ()
MOD - c:\windows\assembly\gac\hpqiface\3.0.0.0__a53cf5803f4c3827\hpqiface.dll ()
MOD - c:\windows\assembly\gac\interop.hpqimgr\1.0.0.0__a53cf5803f4c3827\interop.hpqimgr.dll ()
MOD - c:\windows\assembly\gac\hpqfmrsc.resources\3.0.0.0_en_a53cf5803f4c3827\hpqfmrsc.resources.dll ()
MOD - c:\windows\assembly\gac\hpqcmctl\3.0.0.0__a53cf5803f4c3827\hpqcmctl.dll ()
MOD - c:\windows\assembly\gac\hpqccrsc\3.0.0.0__a53cf5803f4c3827\hpqccrsc.dll ()
MOD - c:\windows\assembly\gac\hpqutils\3.0.0.0__a53cf5803f4c3827\hpqutils.dll ()
MOD - c:\windows\assembly\gac\hpqgskin\3.0.0.0__a53cf5803f4c3827\hpqgskin.dll ()
MOD - c:\windows\assembly\gac\interop.hpqcxm08\3.0.0.0__a53cf5803f4c3827\interop.hpqcxm08.dll ()
MOD - c:\windows\assembly\gac\hpqptfnd\3.0.0.0__a53cf5803f4c3827\hpqptfnd.dll ()
MOD - c:\windows\assembly\gac\accessibility\1.0.5000.0__b03f5f7f11d50a3a\accessibility.dll ()
MOD - C:\Program Files\Common Files\Acronis\Common\gc.dll ()


========== Services (SafeList) ==========

SRV - (MozillaMaintenance) – C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe (Mozilla Foundation)
SRV - (AVGIDSAgent) – C:\Program Files\AVG\AVG2013\avgidsagent.exe (AVG Technologies CZ, s.r.o.)
SRV - (avgwd) – C:\Program Files\AVG\AVG2013\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
SRV - (nvUpdatusService) – C:\Program Files\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe (NVIDIA Corporation)
SRV - (MBAMService) – C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe (Malwarebytes Corporation)
SRV - (MBAMScheduler) – C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe (Malwarebytes Corporation)
SRV - (AcrSch2Svc) – C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe (Acronis)
SRV - (Pml Driver HPZ12) – C:\WINDOWS\system32\HPZipm12.exe (HP)
SRV - (InCDsrv) – C:\Program Files\Ahead\InCD\incdsrv.exe (AHEAD Software)


========== Driver Services (SafeList) ==========

DRV - (WDICA) – File not found
DRV - (PDRFRAME) – File not found
DRV - (PDRELI) – File not found
DRV - (PDFRAME) – File not found
DRV - (PDCOMP) – File not found
DRV - (PCIDump) – File not found
DRV - (mrtRate) – File not found
DRV - (mbr) – C:\ComboFix\mbr.sys File not found
DRV - (lbrtfdc) – File not found
DRV - (i2omgmt) – File not found
DRV - (Changer) – File not found
DRV - (catchme) – C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\catchme.sys File not found
DRV - (AVGIDSDriver) – C:\WINDOWS\system32\drivers\avgidsdriverx.sys (AVG Technologies CZ, s.r.o.)
DRV - (Avgtdix) – C:\WINDOWS\system32\drivers\avgtdix.sys (AVG Technologies CZ, s.r.o.)
DRV - (AVGIDSShim) – C:\WINDOWS\system32\drivers\avgidsshimx.sys (AVG Technologies CZ, s.r.o.)
DRV - (Avgmfx86) – C:\WINDOWS\system32\drivers\avgmfx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (Avglogx) – C:\WINDOWS\system32\drivers\avglogx.sys (AVG Technologies CZ, s.r.o.)
DRV - (AVGIDSHX) – C:\WINDOWS\system32\drivers\avgidshx.sys (AVG Technologies CZ, s.r.o.)
DRV - (Avgldx86) – C:\WINDOWS\system32\drivers\avgldx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (Avgrkx86) – C:\WINDOWS\system32\drivers\avgrkx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (timounter) – C:\WINDOWS\system32\drivers\timntr.sys (Acronis)
DRV - (tifsfilter) – C:\WINDOWS\system32\drivers\tifsfilt.sys (Acronis)
DRV - (snapman) – C:\WINDOWS\system32\drivers\snapman.sys (Acronis)
DRV - (MBAMProtector) – C:\WINDOWS\system32\drivers\mbam.sys (Malwarebytes Corporation)
DRV - (IntcAzAudAddService) – C:\WINDOWS\system32\drivers\RtkHDAud.sys (Realtek Semiconductor Corp.)
DRV - (RTLE8023xp) – C:\WINDOWS\system32\drivers\Rtenicxp.sys (Realtek Semiconductor Corporation )
DRV - (Monfilt) – C:\WINDOWS\system32\drivers\Monfilt.sys (Creative Technology Ltd.)
DRV - (Ambfilt) – C:\WINDOWS\system32\drivers\Ambfilt.sys (Creative)
DRV - (InCDPass) – C:\WINDOWS\system32\drivers\incdpass.sys (Ahead Software)
DRV - (InCDrec) – C:\WINDOWS\System32\drivers\incdrec.sys (Ahead Software AG)
DRV - (InCDfs) – C:\WINDOWS\System32\drivers\incdfs.sys (Ahead Software)
DRV - (USB-100) – C:\WINDOWS\system32\drivers\RTL8150.SYS (Realtek )


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\..\SearchScopes,DefaultScope =
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://search.live.com/results.aspx?q={sea…ferrer:source?}

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.google.com/ie
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.wyff4.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie
IE - HKCU\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}…amp;FORM=IE8SRC
IE - HKCU\..\SearchScopes\{67BD5838-CB1E-4393-A46F-2CED7C53F8E9}: "URL" = http://www.google.com/search?q={searchTerm…tf8&oe=utf8
IE - HKCU\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "http://www.wyff4.com/"
FF - prefs.js..extensions.enabledAddons: addon%40defaulttab.com:2.0
FF - prefs.js..extensions.enabledAddons: %7B972ce4c6-7e08-4474-a285-3208198ce6fd%7D:21.0
FF - user.js - File not found

FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32_11_5_502_146.dll ()
FF - HKLM\Software\MozillaPlugins\@google.com/npPicasa3,version=3.0.0: C:\Program Files\Google\Picasa3\npPicasa3.dll (Google, Inc.)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 20.0.1\extensions\\Components: C:\Program Files\Mozilla Firefox\components
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 20.0.1\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins

[2013/01/11 19:09:39 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Administrator\Application Data\Mozilla\Extensions
[2013/05/29 21:54:49 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\se9y2xik.default\extensions
[2013/05/24 00:39:20 | 000,000,000 | —D | M] (DownloadTerms) – C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\se9y2xik.default\extensions\[removed]
[2013/05/25 01:51:54 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\browser\extensions
[2013/05/25 01:51:54 | 000,000,000 | —D | M] (Default) – C:\Program Files\Mozilla Firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
File not found (No name found) – C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\SE9Y2XIK.DEFAULT\EXTENSIONS\[removed]

O1 HOSTS File: ([2013/05/29 22:13:29 | 000,000,027 | —- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O4 - HKLM..\Run: [Acronis Scheduler2 Service] C:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exe (Acronis)
O4 - HKLM..\Run: [AcronisTimounterMonitor] C:\Program Files\Acronis\TrueImageHome\TimounterMonitor.exe (Acronis)
O4 - HKLM..\Run: [APSDaemon] C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [AVG_UI] C:\Program Files\AVG\AVG2013\avgui.exe (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [InCD] C:\Program Files\Ahead\InCD\InCD.exe (Ahead Software AG)
O4 - HKLM..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe (Ahead Software Gmbh)
O4 - HKLM..\Run: [NvCplDaemon] C:\WINDOWS\System32\NvCpl.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [NvMediaCenter] C:\WINDOWS\System32\nvmctray.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [nwiz] C:\Program Files\NVIDIA Corporation\nview\nwiz.exe ()
O4 - HKLM..\Run: [TrueImageMonitor.exe] C:\Program Files\Acronis\TrueImageHome\TrueImageMonitor.exe (Acronis)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Billminder.lnk = C:\Program Files\Quicken\billmind.exe (Intuit)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\HP Image Zone Fast Start.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe (Hewlett-Packard Co.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Quicken Scheduled Updates.lnk = C:\Program Files\Quicken\bagent.exe (Intuit Inc.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Quicken Startup.lnk = C:\Program Files\Quicken\QWDLLS.EXE (Intuit)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O8 - Extra context menu item: Add to Google Photos Screensa&ver - C:\WINDOWS\System32\GPhotos.scr (Google Inc.)
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} http://windowsupdate.microsoft.com/windows…b?1357777321906 (WUWebControl Class)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.254
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{DBFBB6A8-DCB4-4E08-8E64-F7E27F8D3437}: DhcpNameServer = 192.168.1.254
O18 - Protocol\Handler\cetihpz {CF184AD3-CDCB-4168-A3F7-8E447D129300} - C:\Program Files\HP\hpcoretech\comp\hpuiprot.dll (Hewlett-Packard Company)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) - C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Documents and Settings\Administrator\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Administrator\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O30 - LSA: Authentication Packages - (relog_ap) - C:\WINDOWS\System32\relog_ap.dll (Acronis)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2013/01/09 19:32:11 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O32 - AutoRun File - [2009/11/30 14:58:29 | 000,000,000 | —- | M] () - F:\AUTOEXEC.BAT – [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O34 - HKLM BootExecute: (C:\PROGRA~1\AVG\AVG2013\avgrsx.exe /sync /restart)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = ComFile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)

========== Files/Folders - Created Within 30 Days ==========

[2013/05/29 22:14:26 | 000,000,000 | —D | C] – C:\WINDOWS\temp
[2013/05/29 22:06:27 | 000,000,000 | RHSD | C] – C:\cmdcons
[2013/05/29 22:04:19 | 000,518,144 | —- | C] (SteelWerX) – C:\WINDOWS\SWREG.exe
[2013/05/29 22:04:19 | 000,406,528 | —- | C] (SteelWerX) – C:\WINDOWS\SWSC.exe
[2013/05/29 22:04:19 | 000,212,480 | —- | C] (SteelWerX) – C:\WINDOWS\SWXCACLS.exe
[2013/05/29 22:04:19 | 000,060,416 | —- | C] (NirSoft) – C:\WINDOWS\NIRCMD.exe
[2013/05/29 22:04:08 | 000,000,000 | —D | C] – C:\Qoobox
[2013/05/29 22:04:06 | 000,000,000 | R–D | C] – C:\Documents and Settings\Administrator\My Documents\My Videos
[2013/05/29 22:04:06 | 000,000,000 | R–D | C] – C:\Documents and Settings\Administrator\Start Menu\Programs\Administrative Tools
[2013/05/29 22:03:58 | 000,000,000 | —D | C] – C:\WINDOWS\erdnt
[2013/05/29 21:47:07 | 005,075,099 | R— | C] (Swearware) – C:\Documents and Settings\Administrator\Desktop\ComboFix.exe
[2013/05/29 20:56:31 | 000,000,000 | —D | C] – C:\unzipped
[2013/05/29 17:22:47 | 000,602,112 | —- | C] (OldTimer Tools) – C:\Documents and Settings\Administrator\Desktop\OTL.exe
[2013/05/29 17:20:48 | 004,745,728 | —- | C] (AVAST Software) – C:\Documents and Settings\Administrator\Desktop\aswMBR.exe
[2013/05/25 01:51:45 | 000,000,000 | —D | C] – C:\Program Files\Mozilla Firefox
[2013/05/25 01:32:17 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\AVG
[2013/05/24 00:45:44 | 000,000,000 | —D | C] – C:\Program Files\Uninstaller
[2013/05/24 00:44:58 | 000,000,000 | —D | C] – C:\Documents and Settings\Administrator\Application Data\player
[2013/05/24 00:41:14 | 000,000,000 | —D | C] – C:\Program Files\Microsoft.NET
[2013/05/24 00:39:15 | 000,000,000 | —D | C] – C:\Documents and Settings\Administrator\Local Settings\Application Data\DownloadTerms
[2013/05/13 13:31:05 | 000,000,000 | —D | C] – C:\Documents and Settings\Administrator\My Documents\MORGAN $6K JULY'13 PROMISSORY NOTE
[2013/05/13 12:57:51 | 000,000,000 | —D | C] – C:\Documents and Settings\Administrator\Start Menu\Programs\Parsons Technology
[2013/05/13 12:40:41 | 000,000,000 | —D | C] – C:\WINDOWS\System32\Parsons
[2013/05/13 12:40:38 | 000,146,976 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\MFCOLEUI.DLL
[2013/05/13 12:40:37 | 000,010,736 | —- | C] (Blue Sky Software Corp.) – C:\WINDOWS\System32\RHMMPLAY.DLL
[2013/05/13 12:40:30 | 000,000,000 | —D | C] – C:\Program Files\Parsons Technology
[3 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2013/05/29 23:01:02 | 000,003,182 | —- | M] () – C:\WINDOWS\System32\nvAppTimestamps
[2013/05/29 22:18:34 | 000,000,438 | -H– | M] () – C:\WINDOWS\tasks\User_Feed_Synchronization-{BF0383E8-AAC2-4B96-BC72-182AF1754472}.job
[2013/05/29 22:13:29 | 000,000,027 | —- | M] () – C:\WINDOWS\System32\drivers\etc\hosts
[2013/05/29 22:06:31 | 000,000,327 | RHS- | M] () – C:\boot.ini
[2013/05/29 21:57:14 | 000,013,646 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2013/05/29 21:56:41 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2013/05/29 21:47:07 | 005,075,099 | R— | M] (Swearware) – C:\Documents and Settings\Administrator\Desktop\ComboFix.exe
[2013/05/29 21:42:30 | 000,632,031 | —- | M] () – C:\Documents and Settings\Administrator\Desktop\AdwCleaner.exe
[2013/05/29 20:51:54 | 002,218,636 | —- | M] () – C:\Documents and Settings\Administrator\Desktop\tdsskiller.zip
[2013/05/29 19:22:12 | 000,000,499 | —- | M] () – C:\Documents and Settings\Administrator\Desktop\MBR–attach file as such.zip
[2013/05/29 19:20:55 | 000,000,512 | —- | M] () – C:\Documents and Settings\Administrator\Desktop\MBR.dat
[2013/05/29 17:22:48 | 000,602,112 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Administrator\Desktop\OTL.exe
[2013/05/29 17:22:16 | 004,745,728 | —- | M] (AVAST Software) – C:\Documents and Settings\Administrator\Desktop\aswMBR.exe
[2013/05/28 20:55:10 | 000,001,178 | —- | M] () – C:\WINDOWS\QUICKEN.INI
[2013/05/25 01:32:17 | 000,000,702 | —- | M] () – C:\Documents and Settings\All Users\Desktop\AVG 2013.lnk
[2013/05/24 14:52:00 | 000,000,284 | —- | M] () – C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2013/05/24 11:12:53 | 000,045,386 | —- | M] () – C:\Documents and Settings\Administrator\Desktop\3G13Na3Hd5I85G55F3d5n0ca9cedf2791186b.jpg
[2013/05/24 00:44:37 | 000,464,474 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2013/05/24 00:44:37 | 000,079,302 | —- | M] () – C:\WINDOWS\System32\perfc009.dat
[2013/05/22 18:04:22 | 000,204,680 | —- | M] () – C:\Documents and Settings\Administrator\Desktop\LATE HAGERTY 21999939-1.PDF
[2013/05/15 03:18:55 | 000,263,024 | —- | M] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2013/05/15 03:02:24 | 000,001,374 | —- | M] () – C:\WINDOWS\imsins.BAK
[2013/05/14 15:15:21 | 000,000,233 | —- | M] () – C:\WINDOWS\qwimp.ini
[2013/05/13 12:57:51 | 000,000,884 | —- | M] () – C:\Documents and Settings\Administrator\Desktop\Quicken Family Lawyer Deluxe.lnk
[2013/05/13 12:57:51 | 000,000,177 | —- | M] () – C:\WINDOWS\PARSONS.INI
[2013/05/10 09:38:33 | 000,000,572 | —- | M] () – C:\Documents and Settings\Administrator\My Documents\spider.sav
[2013/05/07 00:27:31 | 006,015,488 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\mshtml.dll
[3 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]

========== Files Created - No Company Name ==========

[2013/05/29 22:06:31 | 000,000,211 | —- | C] () – C:\Boot.bak
[2013/05/29 22:06:28 | 000,260,272 | RHS- | C] () – C:\cmldr
[2013/05/29 22:04:19 | 000,256,000 | —- | C] () – C:\WINDOWS\PEV.exe
[2013/05/29 22:04:19 | 000,208,896 | —- | C] () – C:\WINDOWS\MBR.exe
[2013/05/29 22:04:19 | 000,098,816 | —- | C] () – C:\WINDOWS\sed.exe
[2013/05/29 22:04:19 | 000,080,412 | —- | C] () – C:\WINDOWS\grep.exe
[2013/05/29 22:04:19 | 000,068,096 | —- | C] () – C:\WINDOWS\zip.exe
[2013/05/29 21:42:30 | 000,632,031 | —- | C] () – C:\Documents and Settings\Administrator\Desktop\AdwCleaner.exe
[2013/05/29 20:51:53 | 002,218,636 | —- | C] () – C:\Documents and Settings\Administrator\Desktop\tdsskiller.zip
[2013/05/29 19:22:12 | 000,000,499 | —- | C] () – C:\Documents and Settings\Administrator\Desktop\MBR–attach file as such.zip
[2013/05/29 19:20:55 | 000,000,512 | —- | C] () – C:\Documents and Settings\Administrator\Desktop\MBR.dat
[2013/05/24 11:12:53 | 000,045,386 | —- | C] () – C:\Documents and Settings\Administrator\Desktop\3G13Na3Hd5I85G55F3d5n0ca9cedf2791186b.jpg
[2013/05/22 18:04:22 | 000,204,680 | —- | C] () – C:\Documents and Settings\Administrator\Desktop\LATE HAGERTY 21999939-1.PDF
[2013/05/13 12:57:51 | 000,000,884 | —- | C] () – C:\Documents and Settings\Administrator\Desktop\Quicken Family Lawyer Deluxe.lnk
[2013/05/13 12:57:51 | 000,000,177 | —- | C] () – C:\WINDOWS\PARSONS.INI
[2013/02/28 15:26:39 | 000,003,584 | —- | C] () – C:\Documents and Settings\Administrator\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2013/02/02 16:49:25 | 000,000,048 | —- | C] () – C:\WINDOWS\PickList.ini
[2013/02/02 16:49:25 | 000,000,000 | —- | C] () – C:\WINDOWS\od5.ini
[2013/01/23 17:38:37 | 000,000,000 | —- | C] () – C:\WINDOWS\ADDRBOOK.INI
[2013/01/14 10:45:23 | 000,104,549 | —- | C] () – C:\WINDOWS\hpoins04.dat
[2013/01/14 10:45:23 | 000,017,176 | —- | C] () – C:\WINDOWS\hpomdl04.dat
[2013/01/14 10:42:39 | 000,104,156 | —- | C] () – C:\WINDOWS\hpoins04.dat.temp
[2013/01/14 10:42:39 | 000,017,176 | —- | C] () – C:\WINDOWS\hpomdl04.dat.temp
[2013/01/11 18:53:20 | 000,000,136 | —- | C] () – C:\Documents and Settings\Administrator\Local Settings\Application Data\fusioncache.dat
[2013/01/11 18:34:57 | 000,000,214 | —- | C] () – C:\WINDOWS\HP_48BitScanUpdatePatch.ini
[2013/01/11 18:09:46 | 000,000,233 | —- | C] () – C:\WINDOWS\qwimp.ini
[2013/01/11 18:07:29 | 000,001,178 | —- | C] () – C:\WINDOWS\QUICKEN.INI
[2013/01/11 18:07:29 | 000,000,052 | —- | C] () – C:\WINDOWS\intuprof.ini
[2013/01/09 20:36:39 | 000,003,072 | —- | C] () – C:\WINDOWS\System32\iacenc.dll
[2013/01/09 20:03:04 | 001,079,188 | —- | C] () – C:\WINDOWS\System32\nvdrsdb1.bin
[2013/01/09 20:03:04 | 001,079,188 | —- | C] () – C:\WINDOWS\System32\nvdrsdb0.bin
[2013/01/09 20:03:04 | 000,000,001 | —- | C] () – C:\WINDOWS\System32\nvdrssel.bin
[2013/01/09 20:02:53 | 002,287,232 | —- | C] () – C:\WINDOWS\System32\nvdata.data
[2013/01/09 19:55:00 | 000,025,548 | —- | C] () – C:\WINDOWS\System32\drivers\RTAIODAT.DAT
[2013/01/09 19:33:59 | 000,002,048 | –S- | C] () – C:\WINDOWS\bootstat.dat
[2013/01/09 19:29:14 | 000,021,640 | —- | C] () – C:\WINDOWS\System32\emptyregdb.dat
[2013/01/09 14:19:56 | 000,004,161 | —- | C] () – C:\WINDOWS\ODBCINST.INI
[2013/01/09 14:18:28 | 000,263,024 | —- | C] () – C:\WINDOWS\System32\FNTCACHE.DAT

========== ZeroAccess Check ==========

[2013/01/11 18:24:45 | 000,000,227 | RHS- | M] () – C:\WINDOWS\assembly\Desktop.ini

[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]

[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shdocvw.dll – [2008/04/14 08:00:00 | 001,499,136 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll – [2009/02/09 08:10:48 | 000,473,600 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
"" = %systemroot%\system32\wbem\wbemess.dll – [2008/04/14 08:00:00 | 000,273,920 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Both

========== Alternate Data Streams ==========

@Alternate Data Stream - 88 bytes -> C:\Documents and Settings\Administrator\My Documents\ADDYS VIA 500GB HD ON 1-12-2013.WAB:SummaryInformation

< End of report >

Computer looks fine–however I have not run any apps as of yet; waiting for you to tell me to try.
Thank you,
Sam
Hello shadow5,

1. Disable Extensions in Firefox
  • At the top of the Firefox window, click on the Firefox button (Tools menu in Windows XP), and then click Add-ons. The Add-ons Manager tab will open.
  • In the Add-ons Manager tab, select the Extensions or Appearance panel.
  • Select the add-on you wish to remove.
    • Default Tab (if present)
  • Click the Remove button.
  • Click Restart now if it pops up. Your tabs will be saved and restored after the restart.
=========================

2. Run OTL.exe

Windows Vista and Windows 7 & 8 users Right Click and select "Run as Administrator"
  • Copy/paste the following text written inside of the code box into the Custom Scans/Fixes box located at the bottom of OTL

    :OTL
    FF - prefs.js..extensions.enabledAddons: addon%40defaulttab.com:2.0
    [2013/05/24 00:39:20 | 000,000,000 | —D | M] (DownloadTerms) – C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\se9y2xik.default\extensions\[removed]
    [2013/05/14 15:15:21 | 000,000,233 | —- | M] () – C:\WINDOWS\qwimp.ini
    
    :Files
    C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\SE9Y2XIK.DEFAULT\EXTENSIONS\[removed]
    
    :Commands
    [purity]
    [createrestorepoint]
    [emptyflash]
    [emptyjava]
    [Reboot]
  • Then click the Run Fix button at the top
  • Let the program run unhindered, reboot when it is done
=========================

3. Malwarebytes' Anti-Malware

Locate Malwarebytes' Anti-Malware (it should be on your desktop).
If not, download it here

Windows Vista and Windows 7 & 8 users Right Click and select "Run as Administrator"
  • Double click mbam-setup.exe and follow the prompts to run the program..
  • Once the program has loaded, select the Update tab to get the latest updates before performing the scan.
  • Select Perform quick scan, then click Scan.

    [external image: Posted Image]

  • When the scan is complete, click OK, then Show Results to view the results.
  • Be sure that everything is checked, EXCEPT items in System Restore as shown in this sample: and click Remove Selected .

    [external image: Posted Image]
  • When completed, a log will open in Notepad. Please save it to a convenient location and post the results.
  • Note: If you receive a notice that some of the items couldn't be removed, that they have been added to the delete on reboot list, please reboot.
=========================

4. ESET Online Scanner

*Note:
  • It is recommended to disable on-board antivirus program and anti-spyware programs while performing scans so there are no conflicts and it will speed up scan time.
  • Please don't go surfing while your resident protection is disabled!
  • Once the scan is finished remember to re-enable your antivirus along with your anti-spyware programs.
** You need to run your browser with Administrator Rights, to do so right click your browsers short cut and select "Run as Administrator".

= = = = = = = = = = = = = = = = = = = =

Go here to run ESET Online Scanner

(Note: You can use Internet Explorer or FireFox for this scan. If you use FireFox you will be asked to install an additional component. Please allow this.)

  • Tick the box next to YES, I accept the Terms of Use.
  • Click Start
  • When asked, allow the activex control to install
  • Disable your Antivirus software. You can usually do this with its Notfication Tray icon near the clock
  • Click Start
  • Make sure that the option "Remove found threats" is Unchecked, and the option "Scan unwanted applications" is Checked.
  • Click Scan.
  • Wait for the scan to finish.
  • When the scan completes, click List of found threats
  • click Export to Text file and save the file to your desktop using a unique name, such as ESETScan.
  • Include the contents of this report in your next reply

    Note - when ESET doesn't find any threats, no report will be created.
  • Push the back button.
  • Push Finish
  • Re-enable your Antivirus software.
=========================

In your next post please provide the following:
  • OTL.txt
  • MBAM.txt
  • ESET's log.txt
  • Feel free to test the machine :)
OTL, MBAM, and ESETScan txts follow, in same order:

OTL logfile created on: 5/29/2013 11:06:45 PM - Run 2
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Documents and Settings\Administrator\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

3.50 Gb Total Physical Memory | 2.75 Gb Available Physical Memory | 78.64% Memory free
6.84 Gb Paging File | 6.22 Gb Available in Paging File | 91.04% Paging File free
Paging file location(s): C:\pagefile.sys 0 0 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 232.88 Gb Total Space | 119.79 Gb Free Space | 51.44% Space Free | Partition Type: NTFS
Drive F: | 465.76 Gb Total Space | 272.68 Gb Free Space | 58.55% Space Free | Partition Type: NTFS

Computer Name: OWNER-59AC86FE7 | User Name: Administrator | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Documents and Settings\Administrator\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\AVG\AVG2013\avgidsagent.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG2013\avgui.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG2013\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG2013\avgnsx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG2013\avgrsx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG2013\avgemcx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG2013\avgcsrvx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe (NVIDIA Corporation)
PRC - C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe (Malwarebytes Corporation)
PRC - C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
PRC - C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe (Malwarebytes Corporation)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Acronis\TrueImageHome\TimounterMonitor.exe (Acronis)
PRC - C:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exe (Acronis)
PRC - C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe (Acronis)
PRC - C:\Program Files\Acronis\TrueImageHome\TrueImageMonitor.exe (Acronis)
PRC - C:\WINDOWS\system32\HPZipm12.exe (HP)
PRC - C:\Program Files\Ahead\InCD\InCD.exe (Ahead Software AG)
PRC - C:\Program Files\Ahead\InCD\incdsrv.exe (AHEAD Software)


========== Modules (No Company Name) ==========

MOD - c:\windows\assembly\nativeimages1_v1.1.4322\mscorlib\1.0.5000.0__b77a5c561934e089_63022737\mscorlib.dll ()
MOD - c:\windows\assembly\nativeimages1_v1.1.4322\system.drawing\1.0.5000.0__b03f5f7f11d50a3a_a9db4250\system.drawing.dll ()
MOD - c:\windows\assembly\nativeimages1_v1.1.4322\system.xml\1.0.5000.0__b77a5c561934e089_6a7af65d\system.xml.dll ()
MOD - c:\windows\assembly\nativeimages1_v1.1.4322\system.windows.forms\1.0.5000.0__b77a5c561934e089_ea1855d9\system.windows.forms.dll ()
MOD - c:\windows\assembly\nativeimages1_v1.1.4322\system\1.0.5000.0__b77a5c561934e089_7eddb414\system.dll ()
MOD - c:\windows\assembly\gac\system\1.0.5000.0__b77a5c561934e089\system.dll ()
MOD - c:\windows\assembly\gac\system.drawing\1.0.5000.0__b03f5f7f11d50a3a\system.drawing.dll ()
MOD - c:\windows\assembly\gac\system.windows.forms\1.0.5000.0__b77a5c561934e089\system.windows.forms.dll ()
MOD - c:\windows\assembly\gac\system.xml\1.0.5000.0__b77a5c561934e089\system.xml.dll ()
MOD - c:\windows\assembly\gac\hpqietpz\3.0.0.0__a53cf5803f4c3827\hpqietpz.dll ()
MOD - c:\windows\assembly\gac\hpqcprsc\3.0.0.0__a53cf5803f4c3827\hpqcprsc.dll ()
MOD - c:\windows\assembly\gac\hpqcprsc.resources\3.0.0.0_en_a53cf5803f4c3827\hpqcprsc.resources.dll ()
MOD - c:\windows\assembly\gac\hpqisrtb\4.0.0.0__a53cf5803f4c3827\hpqisrtb.dll ()
MOD - c:\windows\assembly\gac\lead.wrapper\13.0.0.66__9cf889f53ea9b907\lead.wrapper.dll ()
MOD - c:\windows\assembly\gac\lead.drawing\13.0.0.66__9cf889f53ea9b907\lead.drawing.dll ()
MOD - c:\windows\assembly\gac\lead\13.0.0.66__9cf889f53ea9b907\lead.dll ()
MOD - c:\windows\assembly\gac\lead.windows.forms\13.0.0.66__9cf889f53ea9b907\lead.windows.forms.dll ()
MOD - c:\windows\assembly\gac\hpqtray\3.0.0.0__a53cf5803f4c3827\hpqtray.dll ()
MOD - c:\windows\assembly\gac\hpqtray.resources\3.0.0.0_en_a53cf5803f4c3827\hpqtray.resources.dll ()
MOD - c:\windows\assembly\gac\hpqimgrc\3.0.0.0__a53cf5803f4c3827\hpqimgrc.dll ()
MOD - c:\windows\assembly\gac\hpqgldlg\3.0.0.0__a53cf5803f4c3827\hpqgldlg.dll ()
MOD - c:\windows\assembly\gac\hpqthumb\3.0.0.0__a53cf5803f4c3827\hpqthumb.dll ()
MOD - c:\windows\assembly\gac\hpqfmrsc\3.0.0.0__a53cf5803f4c3827\hpqfmrsc.dll ()
MOD - c:\windows\assembly\gac\hpqasset\3.0.0.0__a53cf5803f4c3827\hpqasset.dll ()
MOD - c:\windows\assembly\gac\hpqiface\3.0.0.0__a53cf5803f4c3827\hpqiface.dll ()
MOD - c:\windows\assembly\gac\interop.hpqimgr\1.0.0.0__a53cf5803f4c3827\interop.hpqimgr.dll ()
MOD - c:\windows\assembly\gac\hpqfmrsc.resources\3.0.0.0_en_a53cf5803f4c3827\hpqfmrsc.resources.dll ()
MOD - c:\windows\assembly\gac\hpqcmctl\3.0.0.0__a53cf5803f4c3827\hpqcmctl.dll ()
MOD - c:\windows\assembly\gac\hpqccrsc\3.0.0.0__a53cf5803f4c3827\hpqccrsc.dll ()
MOD - c:\windows\assembly\gac\hpqutils\3.0.0.0__a53cf5803f4c3827\hpqutils.dll ()
MOD - c:\windows\assembly\gac\hpqgskin\3.0.0.0__a53cf5803f4c3827\hpqgskin.dll ()
MOD - c:\windows\assembly\gac\interop.hpqcxm08\3.0.0.0__a53cf5803f4c3827\interop.hpqcxm08.dll ()
MOD - c:\windows\assembly\gac\hpqptfnd\3.0.0.0__a53cf5803f4c3827\hpqptfnd.dll ()
MOD - c:\windows\assembly\gac\accessibility\1.0.5000.0__b03f5f7f11d50a3a\accessibility.dll ()
MOD - C:\Program Files\Common Files\Acronis\Common\gc.dll ()


========== Services (SafeList) ==========

SRV - (MozillaMaintenance) – C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe (Mozilla Foundation)
SRV - (AVGIDSAgent) – C:\Program Files\AVG\AVG2013\avgidsagent.exe (AVG Technologies CZ, s.r.o.)
SRV - (avgwd) – C:\Program Files\AVG\AVG2013\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
SRV - (nvUpdatusService) – C:\Program Files\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe (NVIDIA Corporation)
SRV - (MBAMService) – C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe (Malwarebytes Corporation)
SRV - (MBAMScheduler) – C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe (Malwarebytes Corporation)
SRV - (AcrSch2Svc) – C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe (Acronis)
SRV - (Pml Driver HPZ12) – C:\WINDOWS\system32\HPZipm12.exe (HP)
SRV - (InCDsrv) – C:\Program Files\Ahead\InCD\incdsrv.exe (AHEAD Software)


========== Driver Services (SafeList) ==========

DRV - (WDICA) – File not found
DRV - (PDRFRAME) – File not found
DRV - (PDRELI) – File not found
DRV - (PDFRAME) – File not found
DRV - (PDCOMP) – File not found
DRV - (PCIDump) – File not found
DRV - (mrtRate) – File not found
DRV - (mbr) – C:\ComboFix\mbr.sys File not found
DRV - (lbrtfdc) – File not found
DRV - (i2omgmt) – File not found
DRV - (Changer) – File not found
DRV - (catchme) – C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\catchme.sys File not found
DRV - (AVGIDSDriver) – C:\WINDOWS\system32\drivers\avgidsdriverx.sys (AVG Technologies CZ, s.r.o.)
DRV - (Avgtdix) – C:\WINDOWS\system32\drivers\avgtdix.sys (AVG Technologies CZ, s.r.o.)
DRV - (AVGIDSShim) – C:\WINDOWS\system32\drivers\avgidsshimx.sys (AVG Technologies CZ, s.r.o.)
DRV - (Avgmfx86) – C:\WINDOWS\system32\drivers\avgmfx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (Avglogx) – C:\WINDOWS\system32\drivers\avglogx.sys (AVG Technologies CZ, s.r.o.)
DRV - (AVGIDSHX) – C:\WINDOWS\system32\drivers\avgidshx.sys (AVG Technologies CZ, s.r.o.)
DRV - (Avgldx86) – C:\WINDOWS\system32\drivers\avgldx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (Avgrkx86) – C:\WINDOWS\system32\drivers\avgrkx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (timounter) – C:\WINDOWS\system32\drivers\timntr.sys (Acronis)
DRV - (tifsfilter) – C:\WINDOWS\system32\drivers\tifsfilt.sys (Acronis)
DRV - (snapman) – C:\WINDOWS\system32\drivers\snapman.sys (Acronis)
DRV - (MBAMProtector) – C:\WINDOWS\system32\drivers\mbam.sys (Malwarebytes Corporation)
DRV - (IntcAzAudAddService) – C:\WINDOWS\system32\drivers\RtkHDAud.sys (Realtek Semiconductor Corp.)
DRV - (RTLE8023xp) – C:\WINDOWS\system32\drivers\Rtenicxp.sys (Realtek Semiconductor Corporation )
DRV - (Monfilt) – C:\WINDOWS\system32\drivers\Monfilt.sys (Creative Technology Ltd.)
DRV - (Ambfilt) – C:\WINDOWS\system32\drivers\Ambfilt.sys (Creative)
DRV - (InCDPass) – C:\WINDOWS\system32\drivers\incdpass.sys (Ahead Software)
DRV - (InCDrec) – C:\WINDOWS\System32\drivers\incdrec.sys (Ahead Software AG)
DRV - (InCDfs) – C:\WINDOWS\System32\drivers\incdfs.sys (Ahead Software)
DRV - (USB-100) – C:\WINDOWS\system32\drivers\RTL8150.SYS (Realtek )


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\..\SearchScopes,DefaultScope =
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://search.live.com/results.aspx?q={sea…ferrer:source?}

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.google.com/ie
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.wyff4.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie
IE - HKCU\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}…amp;FORM=IE8SRC
IE - HKCU\..\SearchScopes\{67BD5838-CB1E-4393-A46F-2CED7C53F8E9}: "URL" = http://www.google.com/search?q={searchTerm…tf8&oe=utf8
IE - HKCU\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "http://www.wyff4.com/"
FF - prefs.js..extensions.enabledAddons: addon%40defaulttab.com:2.0
FF - prefs.js..extensions.enabledAddons: %7B972ce4c6-7e08-4474-a285-3208198ce6fd%7D:21.0
FF - user.js - File not found

FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32_11_5_502_146.dll ()
FF - HKLM\Software\MozillaPlugins\@google.com/npPicasa3,version=3.0.0: C:\Program Files\Google\Picasa3\npPicasa3.dll (Google, Inc.)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 20.0.1\extensions\\Components: C:\Program Files\Mozilla Firefox\components
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 20.0.1\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins

[2013/01/11 19:09:39 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Administrator\Application Data\Mozilla\Extensions
[2013/05/29 21:54:49 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\se9y2xik.default\extensions
[2013/05/24 00:39:20 | 000,000,000 | —D | M] (DownloadTerms) – C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\se9y2xik.default\extensions\[removed]
[2013/05/25 01:51:54 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\browser\extensions
[2013/05/25 01:51:54 | 000,000,000 | —D | M] (Default) – C:\Program Files\Mozilla Firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
File not found (No name found) – C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\SE9Y2XIK.DEFAULT\EXTENSIONS\[removed]

O1 HOSTS File: ([2013/05/29 22:13:29 | 000,000,027 | —- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O4 - HKLM..\Run: [Acronis Scheduler2 Service] C:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exe (Acronis)
O4 - HKLM..\Run: [AcronisTimounterMonitor] C:\Program Files\Acronis\TrueImageHome\TimounterMonitor.exe (Acronis)
O4 - HKLM..\Run: [APSDaemon] C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [AVG_UI] C:\Program Files\AVG\AVG2013\avgui.exe (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [InCD] C:\Program Files\Ahead\InCD\InCD.exe (Ahead Software AG)
O4 - HKLM..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe (Ahead Software Gmbh)
O4 - HKLM..\Run: [NvCplDaemon] C:\WINDOWS\System32\NvCpl.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [NvMediaCenter] C:\WINDOWS\System32\nvmctray.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [nwiz] C:\Program Files\NVIDIA Corporation\nview\nwiz.exe ()
O4 - HKLM..\Run: [TrueImageMonitor.exe] C:\Program Files\Acronis\TrueImageHome\TrueImageMonitor.exe (Acronis)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Billminder.lnk = C:\Program Files\Quicken\billmind.exe (Intuit)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\HP Image Zone Fast Start.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe (Hewlett-Packard Co.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Quicken Scheduled Updates.lnk = C:\Program Files\Quicken\bagent.exe (Intuit Inc.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Quicken Startup.lnk = C:\Program Files\Quicken\QWDLLS.EXE (Intuit)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O8 - Extra context menu item: Add to Google Photos Screensa&ver - C:\WINDOWS\System32\GPhotos.scr (Google Inc.)
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} http://windowsupdate.microsoft.com/windows…b?1357777321906 (WUWebControl Class)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.254
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{DBFBB6A8-DCB4-4E08-8E64-F7E27F8D3437}: DhcpNameServer = 192.168.1.254
O18 - Protocol\Handler\cetihpz {CF184AD3-CDCB-4168-A3F7-8E447D129300} - C:\Program Files\HP\hpcoretech\comp\hpuiprot.dll (Hewlett-Packard Company)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) - C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Documents and Settings\Administrator\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Administrator\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O30 - LSA: Authentication Packages - (relog_ap) - C:\WINDOWS\System32\relog_ap.dll (Acronis)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2013/01/09 19:32:11 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O32 - AutoRun File - [2009/11/30 14:58:29 | 000,000,000 | —- | M] () - F:\AUTOEXEC.BAT – [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O34 - HKLM BootExecute: (C:\PROGRA~1\AVG\AVG2013\avgrsx.exe /sync /restart)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = ComFile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)

========== Files/Folders - Created Within 30 Days ==========

[2013/05/29 22:14:26 | 000,000,000 | —D | C] – C:\WINDOWS\temp
[2013/05/29 22:06:27 | 000,000,000 | RHSD | C] – C:\cmdcons
[2013/05/29 22:04:19 | 000,518,144 | —- | C] (SteelWerX) – C:\WINDOWS\SWREG.exe
[2013/05/29 22:04:19 | 000,406,528 | —- | C] (SteelWerX) – C:\WINDOWS\SWSC.exe
[2013/05/29 22:04:19 | 000,212,480 | —- | C] (SteelWerX) – C:\WINDOWS\SWXCACLS.exe
[2013/05/29 22:04:19 | 000,060,416 | —- | C] (NirSoft) – C:\WINDOWS\NIRCMD.exe
[2013/05/29 22:04:08 | 000,000,000 | —D | C] – C:\Qoobox
[2013/05/29 22:04:06 | 000,000,000 | R–D | C] – C:\Documents and Settings\Administrator\My Documents\My Videos
[2013/05/29 22:04:06 | 000,000,000 | R–D | C] – C:\Documents and Settings\Administrator\Start Menu\Programs\Administrative Tools
[2013/05/29 22:03:58 | 000,000,000 | —D | C] – C:\WINDOWS\erdnt
[2013/05/29 21:47:07 | 005,075,099 | R— | C] (Swearware) – C:\Documents and Settings\Administrator\Desktop\ComboFix.exe
[2013/05/29 20:56:31 | 000,000,000 | —D | C] – C:\unzipped
[2013/05/29 17:22:47 | 000,602,112 | —- | C] (OldTimer Tools) – C:\Documents and Settings\Administrator\Desktop\OTL.exe
[2013/05/29 17:20:48 | 004,745,728 | —- | C] (AVAST Software) – C:\Documents and Settings\Administrator\Desktop\aswMBR.exe
[2013/05/25 01:51:45 | 000,000,000 | —D | C] – C:\Program Files\Mozilla Firefox
[2013/05/25 01:32:17 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\AVG
[2013/05/24 00:45:44 | 000,000,000 | —D | C] – C:\Program Files\Uninstaller
[2013/05/24 00:44:58 | 000,000,000 | —D | C] – C:\Documents and Settings\Administrator\Application Data\player
[2013/05/24 00:41:14 | 000,000,000 | —D | C] – C:\Program Files\Microsoft.NET
[2013/05/24 00:39:15 | 000,000,000 | —D | C] – C:\Documents and Settings\Administrator\Local Settings\Application Data\DownloadTerms
[2013/05/13 13:31:05 | 000,000,000 | —D | C] – C:\Documents and Settings\Administrator\My Documents\MORGAN $6K JULY'13 PROMISSORY NOTE
[2013/05/13 12:57:51 | 000,000,000 | —D | C] – C:\Documents and Settings\Administrator\Start Menu\Programs\Parsons Technology
[2013/05/13 12:40:41 | 000,000,000 | —D | C] – C:\WINDOWS\System32\Parsons
[2013/05/13 12:40:38 | 000,146,976 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\MFCOLEUI.DLL
[2013/05/13 12:40:37 | 000,010,736 | —- | C] (Blue Sky Software Corp.) – C:\WINDOWS\System32\RHMMPLAY.DLL
[2013/05/13 12:40:30 | 000,000,000 | —D | C] – C:\Program Files\Parsons Technology
[3 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2013/05/29 23:01:02 | 000,003,182 | —- | M] () – C:\WINDOWS\System32\nvAppTimestamps
[2013/05/29 22:18:34 | 000,000,438 | -H– | M] () – C:\WINDOWS\tasks\User_Feed_Synchronization-{BF0383E8-AAC2-4B96-BC72-182AF1754472}.job
[2013/05/29 22:13:29 | 000,000,027 | —- | M] () – C:\WINDOWS\System32\drivers\etc\hosts
[2013/05/29 22:06:31 | 000,000,327 | RHS- | M] () – C:\boot.ini
[2013/05/29 21:57:14 | 000,013,646 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2013/05/29 21:56:41 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2013/05/29 21:47:07 | 005,075,099 | R— | M] (Swearware) – C:\Documents and Settings\Administrator\Desktop\ComboFix.exe
[2013/05/29 21:42:30 | 000,632,031 | —- | M] () – C:\Documents and Settings\Administrator\Desktop\AdwCleaner.exe
[2013/05/29 20:51:54 | 002,218,636 | —- | M] () – C:\Documents and Settings\Administrator\Desktop\tdsskiller.zip
[2013/05/29 19:22:12 | 000,000,499 | —- | M] () – C:\Documents and Settings\Administrator\Desktop\MBR–attach file as such.zip
[2013/05/29 19:20:55 | 000,000,512 | —- | M] () – C:\Documents and Settings\Administrator\Desktop\MBR.dat
[2013/05/29 17:22:48 | 000,602,112 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Administrator\Desktop\OTL.exe
[2013/05/29 17:22:16 | 004,745,728 | —- | M] (AVAST Software) – C:\Documents and Settings\Administrator\Desktop\aswMBR.exe
[2013/05/28 20:55:10 | 000,001,178 | —- | M] () – C:\WINDOWS\QUICKEN.INI
[2013/05/25 01:32:17 | 000,000,702 | —- | M] () – C:\Documents and Settings\All Users\Desktop\AVG 2013.lnk
[2013/05/24 14:52:00 | 000,000,284 | —- | M] () – C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2013/05/24 11:12:53 | 000,045,386 | —- | M] () – C:\Documents and Settings\Administrator\Desktop\3G13Na3Hd5I85G55F3d5n0ca9cedf2791186b.jpg
[2013/05/24 00:44:37 | 000,464,474 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2013/05/24 00:44:37 | 000,079,302 | —- | M] () – C:\WINDOWS\System32\perfc009.dat
[2013/05/22 18:04:22 | 000,204,680 | —- | M] () – C:\Documents and Settings\Administrator\Desktop\LATE HAGERTY 21999939-1.PDF
[2013/05/15 03:18:55 | 000,263,024 | —- | M] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2013/05/15 03:02:24 | 000,001,374 | —- | M] () – C:\WINDOWS\imsins.BAK
[2013/05/14 15:15:21 | 000,000,233 | —- | M] () – C:\WINDOWS\qwimp.ini
[2013/05/13 12:57:51 | 000,000,884 | —- | M] () – C:\Documents and Settings\Administrator\Desktop\Quicken Family Lawyer Deluxe.lnk
[2013/05/13 12:57:51 | 000,000,177 | —- | M] () – C:\WINDOWS\PARSONS.INI
[2013/05/10 09:38:33 | 000,000,572 | —- | M] () – C:\Documents and Settings\Administrator\My Documents\spider.sav
[2013/05/07 00:27:31 | 006,015,488 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\mshtml.dll
[3 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]

========== Files Created - No Company Name ==========

[2013/05/29 22:06:31 | 000,000,211 | —- | C] () – C:\Boot.bak
[2013/05/29 22:06:28 | 000,260,272 | RHS- | C] () – C:\cmldr
[2013/05/29 22:04:19 | 000,256,000 | —- | C] () – C:\WINDOWS\PEV.exe
[2013/05/29 22:04:19 | 000,208,896 | —- | C] () – C:\WINDOWS\MBR.exe
[2013/05/29 22:04:19 | 000,098,816 | —- | C] () – C:\WINDOWS\sed.exe
[2013/05/29 22:04:19 | 000,080,412 | —- | C] () – C:\WINDOWS\grep.exe
[2013/05/29 22:04:19 | 000,068,096 | —- | C] () – C:\WINDOWS\zip.exe
[2013/05/29 21:42:30 | 000,632,031 | —- | C] () – C:\Documents and Settings\Administrator\Desktop\AdwCleaner.exe
[2013/05/29 20:51:53 | 002,218,636 | —- | C] () – C:\Documents and Settings\Administrator\Desktop\tdsskiller.zip
[2013/05/29 19:22:12 | 000,000,499 | —- | C] () – C:\Documents and Settings\Administrator\Desktop\MBR–attach file as such.zip
[2013/05/29 19:20:55 | 000,000,512 | —- | C] () – C:\Documents and Settings\Administrator\Desktop\MBR.dat
[2013/05/24 11:12:53 | 000,045,386 | —- | C] () – C:\Documents and Settings\Administrator\Desktop\3G13Na3Hd5I85G55F3d5n0ca9cedf2791186b.jpg
[2013/05/22 18:04:22 | 000,204,680 | —- | C] () – C:\Documents and Settings\Administrator\Desktop\LATE HAGERTY 21999939-1.PDF
[2013/05/13 12:57:51 | 000,000,884 | —- | C] () – C:\Documents and Settings\Administrator\Desktop\Quicken Family Lawyer Deluxe.lnk
[2013/05/13 12:57:51 | 000,000,177 | —- | C] () – C:\WINDOWS\PARSONS.INI
[2013/02/28 15:26:39 | 000,003,584 | —- | C] () – C:\Documents and Settings\Administrator\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2013/02/02 16:49:25 | 000,000,048 | —- | C] () – C:\WINDOWS\PickList.ini
[2013/02/02 16:49:25 | 000,000,000 | —- | C] () – C:\WINDOWS\od5.ini
[2013/01/23 17:38:37 | 000,000,000 | —- | C] () – C:\WINDOWS\ADDRBOOK.INI
[2013/01/14 10:45:23 | 000,104,549 | —- | C] () – C:\WINDOWS\hpoins04.dat
[2013/01/14 10:45:23 | 000,017,176 | —- | C] () – C:\WINDOWS\hpomdl04.dat
[2013/01/14 10:42:39 | 000,104,156 | —- | C] () – C:\WINDOWS\hpoins04.dat.temp
[2013/01/14 10:42:39 | 000,017,176 | —- | C] () – C:\WINDOWS\hpomdl04.dat.temp
[2013/01/11 18:53:20 | 000,000,136 | —- | C] () – C:\Documents and Settings\Administrator\Local Settings\Application Data\fusioncache.dat
[2013/01/11 18:34:57 | 000,000,214 | —- | C] () – C:\WINDOWS\HP_48BitScanUpdatePatch.ini
[2013/01/11 18:09:46 | 000,000,233 | —- | C] () – C:\WINDOWS\qwimp.ini
[2013/01/11 18:07:29 | 000,001,178 | —- | C] () – C:\WINDOWS\QUICKEN.INI
[2013/01/11 18:07:29 | 000,000,052 | —- | C] () – C:\WINDOWS\intuprof.ini
[2013/01/09 20:36:39 | 000,003,072 | —- | C] () – C:\WINDOWS\System32\iacenc.dll
[2013/01/09 20:03:04 | 001,079,188 | —- | C] () – C:\WINDOWS\System32\nvdrsdb1.bin
[2013/01/09 20:03:04 | 001,079,188 | —- | C] () – C:\WINDOWS\System32\nvdrsdb0.bin
[2013/01/09 20:03:04 | 000,000,001 | —- | C] () – C:\WINDOWS\System32\nvdrssel.bin
[2013/01/09 20:02:53 | 002,287,232 | —- | C] () – C:\WINDOWS\System32\nvdata.data
[2013/01/09 19:55:00 | 000,025,548 | —- | C] () – C:\WINDOWS\System32\drivers\RTAIODAT.DAT
[2013/01/09 19:33:59 | 000,002,048 | –S- | C] () – C:\WINDOWS\bootstat.dat
[2013/01/09 19:29:14 | 000,021,640 | —- | C] () – C:\WINDOWS\System32\emptyregdb.dat
[2013/01/09 14:19:56 | 000,004,161 | —- | C] () – C:\WINDOWS\ODBCINST.INI
[2013/01/09 14:18:28 | 000,263,024 | —- | C] () – C:\WINDOWS\System32\FNTCACHE.DAT

========== ZeroAccess Check ==========

[2013/01/11 18:24:45 | 000,000,227 | RHS- | M] () – C:\WINDOWS\assembly\Desktop.ini

[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]

[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shdocvw.dll – [2008/04/14 08:00:00 | 001,499,136 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll – [2009/02/09 08:10:48 | 000,473,600 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
"" = %systemroot%\system32\wbem\wbemess.dll – [2008/04/14 08:00:00 | 000,273,920 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Both

========== Alternate Data Streams ==========

@Alternate Data Stream - 88 bytes -> C:\Documents and Settings\Administrator\My Documents\ADDYS VIA 500GB HD ON 1-12-2013.WAB:SummaryInformation

< End of report >

Malwarebytes Anti-Malware 1.75.0.1300
www.malwarebytes.org

Database version: v2013.05.29.08

Windows XP Service Pack 3 x86 NTFS
Internet Explorer 8.0.6001.18702
Administrator :: OWNER-59AC86FE7 [administrator]

5/30/2013 12:13:01 AM
mbam-log-2013-05-30 (00-13-01).txt

Scan type: Quick scan
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
Scan options disabled: P2P
Objects scanned: 225381
Time elapsed: 3 minute(s), 34 second(s)

Memory Processes Detected: 0
(No malicious items detected)

Memory Modules Detected: 0
(No malicious items detected)

Registry Keys Detected: 0
(No malicious items detected)

Registry Values Detected: 0
(No malicious items detected)

Registry Data Items Detected: 0
(No malicious items detected)

Folders Detected: 0
(No malicious items detected)

Files Detected: 0
(No malicious items detected)

(end)

C:\Documents and Settings\Administrator\My Documents\Downloads\iLividSetup-r486-n-bf(1).exe Win32/Toolbar.SearchSuite application
C:\Documents and Settings\Administrator\My Documents\Downloads\iLividSetup-r486-n-bf(2).exe Win32/Toolbar.SearchSuite application
C:\Documents and Settings\Administrator\My Documents\Downloads\iLividSetup-r486-n-bf.exe Win32/Toolbar.SearchSuite application
C:\System Volume Information\_restore{D0DDEC82-1B6C-4144-B97E-CEB3B72A8318}\RP153\A0010923.dll Win64/Toolbar.DefaultTab.A application
C:\System Volume Information\_restore{D0DDEC82-1B6C-4144-B97E-CEB3B72A8318}\RP153\A0010924.exe Win64/Toolbar.DefaultTab.A application
C:\System Volume Information\_restore{D0DDEC82-1B6C-4144-B97E-CEB3B72A8318}\RP153\A0010928.dll Win32/Toolbar.DefaultTab.A application
C:\System Volume Information\_restore{D0DDEC82-1B6C-4144-B97E-CEB3B72A8318}\RP153\A0010929.exe Win32/Toolbar.DefaultTab.A application
C:\System Volume Information\_restore{D0DDEC82-1B6C-4144-B97E-CEB3B72A8318}\RP153\A0010930.dll Win32/Toolbar.DefaultTab.A application
C:\System Volume Information\_restore{D0DDEC82-1B6C-4144-B97E-CEB3B72A8318}\RP158\A0011683.exe Win32/Toolbar.DefaultTab.A application
F:\Documents and Settings\USER\Local Settings\Temp\air1065.exe multiple threats
For Info, I just browsed a few sites in Firefox, and a drop-down box appeared with 4 lines: LINE-1: Some plugins have been deactivated for your safety. LINE-2: Adobe Flash Activate LINE-3(grayed out):Outdated Version Check for Updates LINE-4: Activate All Plugins What should I do about this dropdown and about accepting any of these options? Else, all looks good, including the Toolbar's "old look". Thanks, Sam
Hi shadow5,

Some of the add-ons you had installed were malicious in nature, and were removed. Some remnants might still be lurking.

Can you give me a list of the add-ons that are listed?

=========================

1. Disable Extensions in Firefox
  • At the top of the Firefox window, click on the Firefox button (Tools menu in Windows XP), and then click Add-ons. The Add-ons Manager tab will open.
  • In the Add-ons Manager tab, select the Extensions or Appearance panel.
  • Select the add-on you wish to remove.
    • DownloadTerms
  • Click the Remove button.
  • Click Restart now if it pops up. Your tabs will be saved and restored after the restart.
=========================

2. Run OTL.exe

Windows Vista and Windows 7 users Right Click and select "Run as Administrator"
  • Copy/paste the following text written inside of the code box into the Custom Scans/Fixes box located at the bottom of OTL

    :OTL
    FF - prefs.js..extensions.enabledAddons: addon%40defaulttab.com:2.0
    File not found (No name found) – C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\SE9Y2XIK.DEFAULT\EXTENSIONS\[removed]
    [2013/05/24 00:39:20 | 000,000,000 | —D | M] (DownloadTerms) – C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\se9y2xik.default\extensions\[removed]
    [2013/05/14 15:15:21 | 000,000,233 | —- | M] () – C:\WINDOWS\qwimp.ini
    
    :Files
    C:\Documents and Settings\Administrator\My Documents\Downloads\iLividSetup-r486-n-bf(1).exe
    C:\Documents and Settings\Administrator\My Documents\Downloads\iLividSetup-r486-n-bf(2).exe
    C:\Documents and Settings\Administrator\My Documents\Downloads\iLividSetup-r486-n-bf.exe
    F:\Documents and Settings\USER\Local Settings\Temp\air1065.exe
    
    :Services
    
    :Reg
    
    :Commands
    [purity]
    [createrestorepoint]
    [emptytemp]
    [Reboot]
  • Then click the Run Fix button at the top
  • Let the program run unhindered, reboot when it is done
=========================

In your next post please provide the following:
  • OTL fix.txt log
  • How is the computer running, any remaining issues?
Hi shadow5,

What should I do about this dropdown and about accepting any of these options?

Are those items from the drop-down menu options? Can you only select 1?
When I press ADDONS in Firefox Tools, it shows in left column [different from Int. Explorer] : "Get Add-ons"; "Extensions"; "Appearance"; and "Plugins". Extensions has nothing in it. Appearance has "Default 21.0…The Default Theme" which shows to have been updated May 25, 2013. Under "Plugins" it shows seemingly normal things, as: (1) Adobe Acrobat [removed], (2) MS DRM 9.0.0.4503, (3) Picasa 3.0.0.0, etc., with each one having to its right 2 choice-blocks, "Options" and "Disable". There is one suspicious one: "Shockwave Flash 11.5.502.146". This one is shadowed in pink and has a red triangle with a '!' inside it. Beside this triangle it says "Shockwave Flash is known vulnerable and should be updated". It hilights an option saying "Update Now". In lower part of hilight it says "Shockwave Flash 11.5r502"; and at its right are 2 choices: "Options" and "Disable". What should I do here, DISABLE? or UPDATE? Trying to run OTL.exe: I opened it, pasted in your Code, as instructed, and hit "Run Fix" at the top. At bottom of the box, it said "Killing Processes. DO NOT INTERRUPT". After letting it run for almost 60 minutes, it seemed to not be doing anything, so I shut down computer–had to hard boot. I re-tried, but this time I disabled my anti-virus–after running about 45 minutes, I shut down comp. again, as it seemed to not be doing anything. How long should this "Run Fix" take to complete its action? While it was "running", all desktop items were missing except my 'desktop-background-picture'. I seem to recall that all problems started after I finally agreed to "Update" after being nagged, for approx. 30 days, by a window telling me to update "Shockwave Flash"–not real sure, tho', about that association. Overall the comp. seems to operate ok; except like when I go to my home page (a local tv-site) and some other sites I go to, I get a (shadowed) screen telling me to update "Shockwave Flash". What to do here–press Update? Thanks, Sam

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI