This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Desktop Being Stubborn [Solved]

34 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 6:59:17 PM, on 6/14/2013
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
c:\Program Files\Microsoft Security Client\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Documents and Settings\Lew\My Documents\SASCORE.EXE
C:\Program Files\LSI SoftModem\agrsmsvc.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Java\jre7\bin\jqs.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Spybot - Search & Destroy 2\SDFSSvc.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Spybot - Search & Destroy 2\SDUpdate.exe
C:\Program Files\Spybot - Search & Destroy 2\SDUpdSvc.exe
C:\Program Files\Microsoft\BingBar\7.1.391.0\SeaPort.exe
C:\WINDOWS\Explorer.EXE
C:\HP\KBD\KBD.EXE
C:\Program Files\Microsoft Security Client\msseces.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\Real\RealPlayer\update\realsched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\honestech Audio Recorder 3.0 Plus\HTARLauncher.exe
C:\Documents and Settings\Lew\My Documents\HiJackThis\HiJackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://aol.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O2 - BHO: Java™ Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE
O4 - HKLM\..\Run: [MSC] "c:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Real\RealPlayer\update\realsched.exe" -osboot
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Spybot-S&D Cleaning] "C:\Program Files\Spybot - Search & Destroy 2\SDCleaner.exe" /autoclean
O4 - Startup: WKCALREM.LNK = ?
O4 - Global Startup: honestech Audio Recorder 3.0 Plus Launcher.lnk = C:\Program Files\honestech Audio Recorder 3.0 Plus\HTARLauncher.exe
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy 2\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy 2\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windowsupd…b?1347465718176
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftu…b?1347978180406
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} (OnlineScanner Control) - http://download.eset.com/special/eos/OnlineScanner.cab
O18 - Protocol: wot - {C2A44D6B-CB9F-4663-88A6-DF2F26E4D952} - C:\Program Files\WOT\WOT.dll
O20 - Winlogon Notify: SDWinLogon - SDWinLogon.dll (file missing)
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: SAS Core Service (!SASCORE) - SUPERAntiSpyware.com - C:\Documents and Settings\Lew\My Documents\SASCORE.EXE
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: Agere Modem Call Progress Audio (AgereModemAudio) - LSI Corporation - C:\Program Files\LSI SoftModem\agrsmsvc.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Oracle Corporation - C:\Program Files\Java\jre7\bin\jqs.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Spybot-S&D 2 Scanner Service (SDScannerService) - Safer-Networking Ltd. - C:\Program Files\Spybot - Search & Destroy 2\SDFSSvc.exe
O23 - Service: Spybot-S&D 2 Updating Service (SDUpdateService) - Safer-Networking Ltd. - C:\Program Files\Spybot - Search & Destroy 2\SDUpdSvc.exe
O23 - Service: Spybot-S&D 2 Security Center Service (SDWSCService) - Safer-Networking Ltd. - C:\Program Files\Spybot - Search & Destroy 2\SDWSCSvc.exe
O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe

–
End of file - 6067 bytes
Hello Lewg,

My name is OCD. I would be more than happy to take a look at your log and help you with solving any malware problems you might have. Logs can take a while to research, so please be patient and know that I am working hard to get you a clean and functional system back in your hands. I'd be grateful if you would note the following:
  • I will be working on your Malware issues, this may or may not, solve other issues you have with your machine.
  • The fixes are specific to your problem and should only be used for the issues on this machine.
  • Please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear.
  • It's often worth reading through these instructions and printing them for ease of reference.
  • If you don't know or understand something, please don't hesitate to say or ask!! It's better to be sure and safe than sorry.
  • Please reply to this thread. Do not start a new topic.
  • Copy and Paste logs directly into the reply window. DO NOT attach the logs unless specifically instructed to do so.
IMPORTANT NOTE : Please do not delete, download or install anything unless instructed to do so.

DO NOT use any TOOLS such as Combofix or HijackThis fixes without supervision. Doing so could make your system inoperable and could require a full reinstall of your Operating System and losing all your programs and data.

Please stay with this topic until I let you know that your system appears to be "All Clear"

Important: All tools MUST be run from the Desktop.

=========================

1. Security Check

Download Security Check by screen317 from here or here.
  • Save it to your Desktop.
    • Windows XP : Double click on the icon to run it.
    • Windows Vista, Windows 7 & 8 : Right click and select "Run as Administrator"
  • Follow the onscreen instructions inside of the black box.
  • A Notepad document should open automatically called checkup.txt; please post the contents of that document.

=========================

2. aswMBR

Download aswMBR.exe and save it to your desktop.
    • Windows XP : Double click on the icon to run it.
    • Windows Vista, Windows 7 & 8 : Right click and select "Run as Administrator"
  • When asked if you want to download Avast's virus definitions please select Yes.
  • Click Scan
  • Upon completion of the scan, click Save log and save it to your desktop, and post that log in your next reply for review. Note - do NOT attempt any Fix yet.
  • You will also notice another file created on the desktop named MBR.dat. Right click that file and select Send To>Compressed (zipped) file. Attach that zipped file in your next reply as well.

=========================


3. OTL

Download OTL to your desktop.
  • Make sure all other windows are closed and to let it run uninterrupted.
    • Windows XP : Double click on the icon to run it.
    • Windows Vista, Windows 7 & 8 : Right click and select "Run as Administrator"
  • When the window appears, underneath Output at the top change it to Minimal Output.
  • Check the boxes beside LOP Check and Purity Check.
  • Under Custom Scan paste this in

    netsvcs
    %SYSTEMDRIVE%\*.exe
    /md5start
    explorer.exe
    winlogon.exe
    Userinit.exe
    svchost.exe
    services.exe
    /md5stop
    %systemroot%\*. /rp /s
    %systemdrive%\$Recycle.Bin|@;true;true;true
    %USERPROFILE%\..|smtmp;true;true;true /FP
    %temp%\smtmp\*.* /s >
    BASESERVICES
    DRIVES
    CREATERESTOREPOINT

  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
    • When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.
    • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post it with your next reply.
    • You may need two posts to fit them both in.
=========================

In your next post please provide the following:
  • checkup.txt
  • aswMBR.txt
  • attach MBR.zip
  • OTL.txt
  • Extras.txt
Results of screen317's Security Check version 0.99.64
Windows XP Service Pack 3 x86
``````````````Antivirus/Firewall Check:``````````````
Windows Firewall Enabled!
ESET Online Scanner v3
Microsoft Security Essentials
`````````Anti-malware/Other Utilities Check:`````````
Spybot - Search & Destroy
Malwarebytes Anti-Malware version 1.75.0.1300
CCleaner
Java 7 Update 21
Adobe Flash Player 11.7.700.224
````````Process Check: objlist.exe by Laurent````````
Microsoft Security Essentials MSMpEng.exe
Microsoft Security Essentials msseces.exe
Spybot Teatimer.exe is disabled!
`````````````````System Health check`````````````````
Total Fragmentation on Drive C:: 3%
````````````````````End of Log``````````````````````



aswMBR version 0.9.9.1771 Copyright© 2011 AVAST Software
Run date: 2013-06-15 09:07:46
—————————–
09:07:46.640 OS Version: Windows 5.1.2600 Service Pack 3
09:07:46.640 Number of processors: 1 586 0x2F02
09:07:46.640 ComputerName: LEW-0CCC0E88CE3 UserName: Lew
09:07:47.625 Initialize success
09:17:40.015 AVAST engine defs: 13061300
09:18:41.203 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP2T0L0-e
09:18:41.203 Disk 0 Vendor: WDC_WD5000AAKX-001CA0 15.01H15 Size: 476940MB BusType: 3
09:18:41.359 Disk 0 MBR read successfully
09:18:41.359 Disk 0 MBR scan
09:18:41.406 Disk 0 Windows XP default MBR code
09:18:41.406 Disk 0 Partition 1 80 (A) 07 HPFS/NTFS NTFS 476929 MB offset 63
09:18:41.484 Disk 0 scanning sectors +976752000
09:18:41.578 Disk 0 scanning C:\WINDOWS\system32\drivers
09:19:04.375 Service scanning
09:19:13.562 Service MpKsl90c41d88 c:\Documents and Settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{3FA619F5-BF93-469A-A1A6-508803A0779C}\MpKsl90c41d88.sys **LOCKED** 32
09:19:25.609 Modules scanning
09:19:29.343 Disk 0 trace - called modules:
09:19:29.343 ntkrnlpa.exe CLASSPNP.SYS disk.sys ACPI.sys hal.dll atapi.sys pciide.sys PCIIDEX.SYS
09:19:29.843 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x858a9ab8]
09:19:29.843 3 CLASSPNP.SYS[f75d0fd7] -> nt!IofCallDriver -> \Device\00000067[0x85973f18]
09:19:29.843 5 ACPI.sys[f7447620] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP2T0L0-e[0x858aad98]
09:19:30.515 AVAST engine scan C:\WINDOWS
09:19:46.625 AVAST engine scan C:\WINDOWS\system32
09:24:03.406 AVAST engine scan C:\WINDOWS\system32\drivers
09:24:30.875 AVAST engine scan C:\Documents and Settings\Lew
09:37:37.656 AVAST engine scan C:\Documents and Settings\All Users
09:39:09.078 Scan finished successfully
09:41:42.859 Disk 0 MBR has been saved successfully to "C:\Documents and Settings\Lew\Desktop\MBR.dat"
09:41:42.890 The log file has been saved successfully to "C:\Documents and Settings\Lew\Desktop\aswMBR.log"


OTL logfile created on: 6/15/2013 9:44:04 AM - Run 4
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Documents and Settings\Lew\Desktop
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

958.48 Mb Total Physical Memory | 512.76 Mb Available Physical Memory | 53.50% Memory free
2.26 Gb Paging File | 1.88 Gb Available in Paging File | 83.04% Paging File free
Paging file location(s): C:\pagefile.sys 1440 2880 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 465.75 Gb Total Space | 398.70 Gb Free Space | 85.60% Space Free | Partition Type: NTFS
Drive D: | 202.83 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS

Computer Name: LEW-0CCC0E88CE3 | User Name: Lew | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Documents and Settings\Lew\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Java\jre7\bin\jqs.exe (Oracle Corporation)
PRC - c:\Program Files\Microsoft Security Client\MsMpEng.exe (Microsoft Corporation)
PRC - C:\Program Files\Microsoft Security Client\msseces.exe (Microsoft Corporation)
PRC - C:\Program Files\Spybot - Search & Destroy 2\SDUpdate.exe (Safer-Networking Ltd.)
PRC - C:\Program Files\Spybot - Search & Destroy 2\SDUpdSvc.exe (Safer-Networking Ltd.)
PRC - C:\Program Files\Spybot - Search & Destroy 2\SDFSSvc.exe (Safer-Networking Ltd.)
PRC - C:\Program Files\Real\RealPlayer\Update\realsched.exe (RealNetworks, Inc.)
PRC - C:\Program Files\honestech Audio Recorder 3.0 Plus\HTARLauncher.exe (Honest Technology)
PRC - C:\Documents and Settings\Lew\My Documents\SASCore.exe (SUPERAntiSpyware.com)
PRC - C:\Program Files\Microsoft\BingBar\7.1.391.0\SeaPort.EXE (Microsoft Corporation.)
PRC - C:\Program Files\LSI SoftModem\agrsmsvc.exe (LSI Corporation)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)


========== Modules (No Company Name) ==========

MOD - C:\Program Files\Spybot - Search & Destroy 2\snlFileFormats150.bpl ()
MOD - C:\Program Files\Spybot - Search & Destroy 2\snlThirdParty150.bpl ()
MOD - C:\Program Files\Spybot - Search & Destroy 2\VirtualTreesDXE150.bpl ()
MOD - C:\Program Files\Spybot - Search & Destroy 2\JSDialogPack150.bpl ()
MOD - C:\Program Files\Spybot - Search & Destroy 2\DEC150.bpl ()
MOD - C:\Program Files\Spybot - Search & Destroy 2\sqlite3.dll ()
MOD - C:\WINDOWS\system32\nvshell.dll ()


========== Services (SafeList) ==========

SRV - (SDWSCService) – C:\Program Files\Spybot File not found
SRV - (SDUpdateService) – C:\Program Files\Spybot File not found
SRV - (SDScannerService) – C:\Program Files\Spybot File not found
SRV - (AppMgmt) – %SystemRoot%\System32\appmgmts.dll File not found
SRV - (AdobeFlashPlayerUpdateSvc) – C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe (Adobe Systems Incorporated)
SRV - (JavaQuickStarterService) – C:\Program Files\Java\jre7\bin\jqs.exe (Oracle Corporation)
SRV - (MsMpSvc) – c:\Program Files\Microsoft Security Client\MsMpEng.exe (Microsoft Corporation)
SRV - (!SASCORE) – C:\Documents and Settings\Lew\My Documents\SASCore.exe (SUPERAntiSpyware.com)
SRV - (BBUpdate) – C:\Program Files\Microsoft\BingBar\7.1.391.0\SeaPort.EXE (Microsoft Corporation.)
SRV - (BBSvc) – C:\Program Files\Microsoft\BingBar\7.1.391.0\BBSvc.EXE (Microsoft Corporation.)
SRV - (AgereModemAudio) – C:\Program Files\LSI SoftModem\agrsmsvc.exe (LSI Corporation)


========== Driver Services (SafeList) ==========

DRV - (WDICA) – File not found
DRV - (PDRFRAME) – File not found
DRV - (PDRELI) – File not found
DRV - (PDFRAME) – File not found
DRV - (PDCOMP) – File not found
DRV - (PCIDump) – File not found
DRV - (lbrtfdc) – File not found
DRV - (i2omgmt) – File not found
DRV - (Changer) – File not found
DRV - (aswMBR) – C:\DOCUME~1\Lew\LOCALS~1\Temp\aswMBR.sys File not found
DRV - (MpKsl90c41d88) – c:\Documents and Settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{3FA619F5-BF93-469A-A1A6-508803A0779C}\MpKsl90c41d88.sys (Microsoft Corporation)
DRV - (SASKUTIL) – C:\Documents and Settings\Lew\My Documents\SASKUTIL.SYS (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (SASDIFSV) – C:\Documents and Settings\Lew\My Documents\SASDIFSV.SYS (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (WDC_SAM) – C:\WINDOWS\system32\drivers\wdcsam.sys (Western Digital Technologies)
DRV - (AgereSoftModem) – C:\WINDOWS\system32\drivers\AGRSM.sys (LSI Corporation)
DRV - (IntcAzAudAddService) – C:\WINDOWS\system32\drivers\RtkHDAud.sys (Realtek Semiconductor Corp.)
DRV - (FETNDISB) – C:\WINDOWS\system32\drivers\dlkfet5b.sys (D-Link )
DRV - (nvnetbus) – C:\WINDOWS\system32\drivers\nvnetbus.sys (NVIDIA Corporation)
DRV - (NVENETFD) – C:\WINDOWS\system32\drivers\NVENETFD.sys (NVIDIA Corporation)
DRV - (Ps2) – C:\WINDOWS\system32\drivers\PS2.sys (Hewlett-Packard Company)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://search.live.com/results.aspx?q={sea…ferrer:source?}

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://aol.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://www.msn.com/?ocid=iehp
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-us
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 90 52 84 B8 B5 E2 CD 01 [binary data]
IE - HKCU\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://search.live.com/results.aspx?q={sea…amp;Form=IE8SRC
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0


========== FireFox ==========

FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32_11_7_700_224.dll ()
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.21.2: C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\5.1.20125.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@real.com/nppl3260;version=15.0.6.14: C:\Program Files\Real\RealPlayer\Netscape6\nppl3260.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprjplug;version=15.0.6.14: C:\Program Files\Real\RealPlayer\Netscape6\nprjplug.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprpchromebrowserrecordext;version=15.0.6.14: C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprpchromebrowserrecordext.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprphtml5videoshim;version=15.0.6.14: C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprpplugin;version=15.0.6.14: C:\Program Files\Real\RealPlayer\Netscape6\nprpplugin.dll (RealPlayer)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@nds.com/PCShowPlugin: C:\Documents and Settings\Lew\Local Settings\Application Data\DIRECTV Player\npPCShowPlugin.dll File not found
FF - HKCU\Software\MozillaPlugins\@nds.com/PlayerPlugin: C:\Documents and Settings\Lew\Local Settings\Application Data\DIRECTV Player\npPlayerPlugin.dll (NDS)
FF - HKCU\Software\MozillaPlugins\NDS.com/PlayerPlugin: C:\Documents and Settings\Lew\Local Settings\Application Data\DIRECTV Player\npPlayerPlugin.dll (NDS)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{0153E448-190B-4987-BDE1-F256CADA672F}: C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext [2012/09/12 14:56:42 | 000,000,000 | —D | M]

[2012/09/14 17:47:46 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions

========== Chrome ==========

CHR - homepage: http://www.google.com/
CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{g
oogle:assistedQueryStats}{google:searchFieldtrialParameter}sourceid=chrome&ie={inputEncoding}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client=chrome&hl={language}&q={searchTerms}
CHR - homepage: http://www.google.com/
CHR - Extension: YouTube = C:\Documents and Settings\Lew\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0\
CHR - Extension: Google Search = C:\Documents and Settings\Lew\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0\
CHR - Extension: RealPlayer HTML5Video Downloader Extension = C:\Documents and Settings\Lew\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\jfmjfhklogoienhpfnppmbcbjfjnkonk\1.5_0\
CHR - Extension: Coupon Companion = C:\Documents and Settings\Lew\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\pbkdpahkifcigckmhiafindmaflfifgm\1.18.12_0\crossrider
CHR - Extension: Coupon Companion = C:\Documents and Settings\Lew\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\pbkdpahkifcigckmhiafindmaflfifgm\1.18.12_0\
CHR - Extension: Gmail = C:\Documents and Settings\Lew\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\

O1 HOSTS File: ([2012/09/20 10:30:46 | 000,000,027 | —- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (Java™ Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
O2 - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (WOT) - {71576546-354D-41C9-AAE8-31F2EC22BF0D} - C:\Program Files\WOT\WOT.dll ()
O4 - HKLM..\Run: [MSC] c:\Program Files\Microsoft Security Client\msseces.exe (Microsoft Corporation)
O4 - HKLM..\Run: [NvCplDaemon] C:\WINDOWS\System32\NvCpl.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [NvMediaCenter] C:\WINDOWS\System32\NvMcTray.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [TkBellExe] C:\Program Files\Real\RealPlayer\update\realsched.exe (RealNetworks, Inc.)
O4 - HKCU..\Run: [Spybot-S&D Cleaning] C:\Program Files\Spybot - Search & Destroy 2\SDCleaner.exe (Safer-Networking Ltd.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\honestech Audio Recorder 3.0 Plus Launcher.lnk = C:\Program Files\honestech Audio Recorder 3.0 Plus\HTARLauncher.exe (Honest Technology)
O4 - Startup: C:\Documents and Settings\Lew\Start Menu\Programs\Startup\WKCALREM.LNK = File not found
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O9 - Extra 'Tools' menuitem : Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy 2\SDHelper.dll (Safer-Networking Ltd.)
O15 - HKCU\..Trusted Domains: coastalbankofga.com ([]http in Local intranet)
O15 - HKCU\..Trusted Domains: ebay.com ([]http in Local intranet)
O15 - HKCU\..Trusted Domains: extendhealth.com ([]http in Local intranet)
O15 - HKCU\..Trusted Domains: extendhealth.com ([]https in Trusted sites)
O15 - HKCU\..Trusted Domains: fisherbuggies.com ([]http in Local intranet)
O15 - HKCU\..Trusted Domains: hulu.com ([www] http in Local intranet)
O15 - HKCU\..Trusted Domains: msn.com ([www] http in Local intranet)
O15 - HKCU\..Trusted Domains: shoptalkforums.com ([www] http in Local intranet)
O15 - HKCU\..Trusted Domains: thebrunswicknews.com ([]http in Local intranet)
O15 - HKCU\..Trusted Domains: usps.com ([]http in Local intranet)
O15 - HKCU\..Trusted Domains: usps.com ([]https in Trusted sites)
O15 - HKCU\..Trusted Domains: whatthetech.com ([forums] http in Local intranet)
O15 - HKCU\..Trusted Domains: yahoo.com ([www] http in Local intranet)
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} http://www.update.microsoft.com/windowsupd…b?1347465718176 (WUWebControl Class)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} http://www.update.microsoft.com/microsoftu…b?1347978180406 (MUWebControl Class)
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} http://download.eset.com/special/eos/OnlineScanner.cab (OnlineScanner Control)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.2.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{2E5072BA-3DCD-43F1-A347-7B3E0450AF88}: DhcpNameServer = 192.168.2.1
O18 - Protocol\Handler\wot {C2A44D6B-CB9F-4663-88A6-DF2F26E4D952} - C:\Program Files\WOT\WOT.dll ()
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) - C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O20 - Winlogon\Notify\SDWinLogon: DllName - (SDWinLogon.dll) - File not found
O28 - HKLM ShellExecuteHooks: {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - C:\Documents and Settings\Lew\My Documents\SASSEH.DLL (SuperAdBlocker.com)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2012/09/11 18:13:41 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)

NetSvcs: 6to4 - File not found
NetSvcs: AppMgmt - %SystemRoot%\System32\appmgmts.dll File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found

CREATERESTOREPOINT
Restore point Set: OTL Restore Point

========== Files/Folders - Created Within 30 Days ==========

[2013/06/15 09:06:05 | 000,602,112 | —- | C] (OldTimer Tools) – C:\Documents and Settings\Lew\Desktop\OTL.exe
[2013/06/15 09:05:41 | 004,745,728 | —- | C] (AVAST Software) – C:\Documents and Settings\Lew\Desktop\aswMBR.exe
[2013/06/10 19:06:18 | 000,000,000 | RH-D | C] – C:\Documents and Settings\Lew\Recent
[2013/06/10 14:11:33 | 000,000,000 | —D | C] – C:\Documents and Settings\Lew\My Documents\Makita LS1440 Miter Saw

========== Files - Modified Within 30 Days ==========

[2013/06/15 09:41:42 | 000,000,512 | —- | M] () – C:\Documents and Settings\Lew\Desktop\MBR.dat
[2013/06/15 09:40:00 | 000,000,830 | —- | M] () – C:\WINDOWS\tasks\Adobe Flash Player Updater.job
[2013/06/15 09:06:12 | 000,602,112 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Lew\Desktop\OTL.exe
[2013/06/15 09:05:45 | 004,745,728 | —- | M] (AVAST Software) – C:\Documents and Settings\Lew\Desktop\aswMBR.exe
[2013/06/15 08:59:18 | 000,000,274 | —- | M] () – C:\WINDOWS\tasks\RealUpgradeLogonTaskS-1-5-21-2052111302-861567501-725345543-1004.job
[2013/06/15 08:59:17 | 000,000,282 | —- | M] () – C:\WINDOWS\tasks\RealUpgradeScheduledTaskS-1-5-21-2052111302-861567501-725345543-1004.job
[2013/06/15 08:59:16 | 000,043,531 | —- | M] () – C:\WINDOWS\System32\nvapps.xml
[2013/06/15 08:59:08 | 000,013,646 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2013/06/15 08:59:02 | 000,000,366 | -H– | M] () – C:\WINDOWS\tasks\MpIdleTask.job
[2013/06/14 21:28:45 | 000,000,211 | —- | M] () – C:\Documents and Settings\Lew\Desktop\Google.url
[2013/06/14 21:24:41 | 000,000,620 | —- | M] () – C:\WINDOWS\tasks\Check for updates (Spybot - Search & Destroy).job
[2013/06/14 20:40:02 | 000,000,464 | —- | M] () – C:\WINDOWS\tasks\At2.job
[2013/06/14 19:21:41 | 000,000,384 | -H– | M] () – C:\WINDOWS\tasks\Microsoft Antimalware Scheduled Scan.job
[2013/06/14 19:11:35 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2013/06/14 19:06:29 | 000,000,279 | —- | M] () – C:\Documents and Settings\Lew\Desktop\Virus, Spyware & Malware Removal - What the Tech.url
[2013/06/14 18:56:56 | 000,000,208 | —- | M] () – C:\Documents and Settings\Lew\Desktop\Yahoo Mail Login.url
[2013/06/14 15:21:00 | 000,000,464 | —- | M] () – C:\WINDOWS\tasks\At3.job
[2013/06/14 14:00:00 | 000,000,464 | —- | M] () – C:\WINDOWS\tasks\At4.job
[2013/06/14 13:37:02 | 000,001,793 | —- | M] () – C:\Documents and Settings\Lew\Desktop\Rain Alarm.url
[2013/06/14 10:10:12 | 000,000,464 | —- | M] () – C:\WINDOWS\tasks\At1.job
[2013/06/13 08:29:43 | 000,000,253 | —- | M] () – C:\Documents and Settings\Lew\Desktop\Contact Brunswick Radio Station.url
[2013/06/12 14:41:03 | 000,692,104 | —- | M] (Adobe Systems Incorporated) – C:\WINDOWS\System32\FlashPlayerApp.exe
[2013/06/12 14:41:03 | 000,071,048 | —- | M] (Adobe Systems Incorporated) – C:\WINDOWS\System32\FlashPlayerCPLApp.cpl
[2013/06/12 11:25:08 | 000,000,241 | —- | M] () – C:\Documents and Settings\Lew\Desktop\craigslist Brunswick, GA.url
[2013/06/12 03:00:56 | 000,001,374 | —- | M] () – C:\WINDOWS\imsins.BAK
[2013/06/12 00:30:00 | 000,000,616 | —- | M] () – C:\WINDOWS\tasks\Refresh immunization (Spybot - Search & Destroy).job
[2013/06/11 12:30:56 | 000,000,473 | —- | M] () – C:\Documents and Settings\Lew\Desktop\Guy Noir - 2-9-2013 - YouTube.url
[2013/06/11 12:11:15 | 000,000,473 | —- | M] () – C:\Documents and Settings\Lew\Desktop\Café Boeuf - 9-15-2012 - YouTube.url
[2013/06/10 19:07:10 | 000,001,062 | —- | M] () – C:\Documents and Settings\Lew\My Documents\cc_20130610_190704.reg
[2013/06/08 16:08:11 | 000,000,353 | —- | M] () – C:\Documents and Settings\Lew\Desktop\Real American Airlines Boeing 767 cockpit JFK to LAX (not a simulator or reenactment) - YouTube.url
[2013/06/08 12:04:36 | 004,760,816 | —- | M] (SUPERAntiSpyware.com) – C:\Documents and Settings\Lew\My Documents\SUPERANTISPYWARE.EXE
[2013/06/06 08:26:45 | 000,004,578 | —- | M] () – C:\Documents and Settings\Lew\Application Data\wklnhst.dat
[2013/06/03 14:34:56 | 000,001,630 | —- | M] () – C:\Documents and Settings\Lew\Desktop\The Farmhouse Cottage in Memphis.url
[2013/06/03 13:25:14 | 000,010,752 | —- | M] () – C:\Documents and Settings\Lew\Desktop\Funeral Letter to Robin Deason.wps
[2013/06/03 07:07:25 | 000,001,212 | —- | M] () – C:\Documents and Settings\Lew\Desktop\ 7-Day Forecast for Latitude 31.21°N and Longitude 81.36°W.url
[2013/06/01 08:55:33 | 000,002,846 | —- | M] () – C:\Documents and Settings\Lew\Desktop\How to Use Environment Variables in Windows XP.url
[2013/06/01 08:54:55 | 000,002,138 | —- | M] () – C:\Documents and Settings\Lew\Desktop\98 Volkswagen beetle my radio is in safe mode - JustAnswer.url
[2013/06/01 00:30:00 | 000,000,446 | —- | M] () – C:\WINDOWS\tasks\Scan the system (Spybot - Search & Destroy).job
[2013/05/25 08:53:05 | 000,000,294 | —- | M] () – C:\Documents and Settings\Lew\Desktop\Controlling Bahiagrass in Warm-Season Turf.url
[2013/05/25 07:48:06 | 000,000,241 | —- | M] () – C:\Documents and Settings\Lew\Desktop\TDIClub.url
[2013/05/23 16:48:01 | 000,000,735 | —- | M] () – C:\Documents and Settings\Lew\Start Menu\Programs\Startup\WKCALREM.LNK
[2013/05/18 13:40:47 | 000,050,925 | —- | M] () – C:\Documents and Settings\Lew\My Documents\Genuine Nissan Parts - Search by Nissan VIN, Car Model or Nissan Part Number.htm
[2013/05/18 07:01:32 | 000,062,272 | —- | M] () – C:\Documents and Settings\Lew\My Documents\GEELY SERVICE MANUALS.mht
[2013/05/18 07:00:21 | 002,712,100 | —- | M] () – C:\Documents and Settings\Lew\My Documents\Geely Manual.pdf
[2013/05/17 18:34:56 | 000,000,353 | —- | M] () – C:\Documents and Settings\Lew\Desktop\Imax - Fires of Kuwait - FULL - 9 subtitles - YouTube.url
[2013/05/17 18:07:22 | 006,014,976 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\mshtml.dll
[2013/05/17 09:05:50 | 000,000,361 | RHS- | M] () – C:\boot.ini
[2013/05/16 16:39:19 | 000,006,054 | —- | M] () – C:\Documents and Settings\Lew\My Documents\cc_20130516_163913.reg

========== Files Created - No Company Name ==========

[2013/06/15 09:41:42 | 000,000,512 | —- | C] () – C:\Documents and Settings\Lew\Desktop\MBR.dat
[2013/06/14 19:06:29 | 000,000,279 | —- | C] () – C:\Documents and Settings\Lew\Desktop\Virus, Spyware & Malware Removal - What the Tech.url
[2013/06/12 03:00:55 | 000,001,374 | —- | C] () – C:\WINDOWS\imsins.BAK
[2013/06/11 12:30:56 | 000,000,473 | —- | C] () – C:\Documents and Settings\Lew\Desktop\Guy Noir - 2-9-2013 - YouTube.url
[2013/06/10 19:07:09 | 000,001,062 | —- | C] () – C:\Documents and Settings\Lew\My Documents\cc_20130610_190704.reg
[2013/06/08 16:08:11 | 000,000,353 | —- | C] () – C:\Documents and Settings\Lew\Desktop\Real American Airlines Boeing 767 cockpit JFK to LAX (not a simulator or reenactment) - YouTube.url
[2013/06/04 16:32:30 | 000,001,793 | —- | C] () – C:\Documents and Settings\Lew\Desktop\Rain Alarm.url
[2013/05/30 16:41:52 | 000,001,630 | —- | C] () – C:\Documents and Settings\Lew\Desktop\The Farmhouse Cottage in Memphis.url
[2013/05/30 11:25:08 | 000,010,752 | —- | C] () – C:\Documents and Settings\Lew\Desktop\Funeral Letter to Robin Deason.wps
[2013/05/25 08:53:05 | 000,000,294 | —- | C] () – C:\Documents and Settings\Lew\Desktop\Controlling Bahiagrass in Warm-Season Turf.url
[2013/05/23 16:48:01 | 000,000,735 | —- | C] () – C:\Documents and Settings\Lew\Start Menu\Programs\Startup\WKCALREM.LNK
[2013/05/18 13:40:47 | 000,050,925 | —- | C] () – C:\Documents and Settings\Lew\My Documents\Genuine Nissan Parts - Search by Nissan VIN, Car Model or Nissan Part Number.htm
[2013/05/18 07:01:31 | 000,062,272 | —- | C] () – C:\Documents and Settings\Lew\My Documents\GEELY SERVICE MANUALS.mht
[2013/05/18 07:00:21 | 002,712,100 | —- | C] () – C:\Documents and Settings\Lew\My Documents\Geely Manual.pdf
[2013/05/16 16:39:17 | 000,006,054 | —- | C] () – C:\Documents and Settings\Lew\My Documents\cc_20130516_163913.reg
[2013/03/05 09:55:19 | 000,000,089 | —- | C] () – C:\WINDOWS\Taxact07.ini
[2013/02/27 11:43:26 | 000,000,076 | —- | C] () – C:\WINDOWS\Taxact10.ini
[2013/02/13 10:13:53 | 000,000,105 | —- | C] () – C:\WINDOWS\Taxact06.ini
[2013/01/28 16:08:55 | 000,098,008 | —- | C] () – C:\Documents and Settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
[2013/01/09 11:35:43 | 000,000,061 | —- | C] () – C:\WINDOWS\TaxACT12.ini
[2012/10/07 11:14:25 | 000,000,754 | —- | C] () – C:\WINDOWS\WORDPAD.INI
[2012/10/03 09:41:29 | 000,000,000 | —- | C] () – C:\Documents and Settings\Lew\PROGDA.TA
[2012/09/20 16:50:07 | 000,013,312 | —- | C] () – C:\Documents and Settings\Lew\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2012/09/18 14:28:55 | 000,000,028 | —- | C] () – C:\WINDOWS\QFNOA.INI
[2012/09/18 14:28:50 | 000,000,030 | —- | C] () – C:\WINDOWS\INTURS.DAT
[2012/09/14 17:42:01 | 000,004,578 | —- | C] () – C:\Documents and Settings\Lew\Application Data\wklnhst.dat
[2012/09/14 12:18:32 | 000,000,107 | —- | C] () – C:\WINDOWS\QHI.INI
[2012/09/14 12:07:48 | 000,000,646 | —- | C] () – C:\WINDOWS\INTU_ONL.INI
[2012/09/14 11:59:56 | 000,000,832 | —- | C] () – C:\WINDOWS\WININIT.INI
[2012/09/14 11:59:52 | 000,001,545 | —- | C] () – C:\WINDOWS\QfnOnl.ini
[2012/09/14 11:59:52 | 000,000,120 | —- | C] () – C:\WINDOWS\QUICKEN.INI
[2012/09/14 11:59:50 | 000,000,252 | —- | C] () – C:\WINDOWS\ADDRBOOK.INI
[2012/09/14 11:59:48 | 000,008,256 | —- | C] () – C:\WINDOWS\QFNOADB.DAT
[2012/09/14 11:59:48 | 000,000,326 | —- | C] () – C:\WINDOWS\QDQICK.INI
[2012/09/14 11:59:45 | 000,000,054 | —- | C] () – C:\WINDOWS\QFP.INI
[2012/09/14 11:59:45 | 000,000,054 | —- | C] () – C:\WINDOWS\MFF.INI
[2012/09/14 08:25:34 | 000,000,000 | —- | C] () – C:\WINDOWS\NT.INI
[2012/09/12 12:02:40 | 000,003,072 | —- | C] () – C:\WINDOWS\System32\iacenc.dll
[2012/09/11 18:15:28 | 000,002,048 | –S- | C] () – C:\WINDOWS\bootstat.dat
[2012/09/11 18:10:59 | 000,021,640 | —- | C] () – C:\WINDOWS\System32\emptyregdb.dat
[2012/09/11 11:32:51 | 000,004,161 | —- | C] () – C:\WINDOWS\ODBCINST.INI
[2012/09/11 11:31:39 | 000,165,912 | —- | C] () – C:\WINDOWS\System32\FNTCACHE.DAT

========== ZeroAccess Check ==========

[2012/09/18 12:43:50 | 000,000,227 | RHS- | M] () – C:\WINDOWS\assembly\Desktop.ini

[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]

[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shdocvw.dll – [2012/06/28 17:33:05 | 001,510,400 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll – [2009/02/09 08:10:48 | 000,473,600 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
"" = %systemroot%\system32\wbem\wbemess.dll – [2008/04/14 05:42:10 | 000,273,920 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Both

========== LOP Check ==========

[2013/05/05 10:45:26 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\4Team
[2012/12/08 18:02:27 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Uninstall
[2012/12/15 15:58:09 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Western Digital
[2013/05/05 10:45:26 | 000,000,000 | —D | M] – C:\Documents and Settings\Lew\Application Data\4Team
[2012/09/16 09:27:51 | 000,000,000 | —D | M] – C:\Documents and Settings\Lew\Application Data\DTV
[2012/12/25 11:33:00 | 000,000,000 | —D | M] – C:\Documents and Settings\Lew\Application Data\ElevatedDiagnostics
[2012/10/01 09:30:09 | 000,000,000 | —D | M] – C:\Documents and Settings\Lew\Application Data\FCTB000100567
[2012/11/27 21:42:23 | 000,000,000 | —D | M] – C:\Documents and Settings\Lew\Application Data\FixCleaner
[2013/03/17 09:36:20 | 000,000,000 | —D | M] – C:\Documents and Settings\Lew\Application Data\Spotify
[2012/09/14 17:42:02 | 000,000,000 | —D | M] – C:\Documents and Settings\Lew\Application Data\Template
[2012/09/12 15:09:45 | 000,000,000 | —D | M] – C:\Documents and Settings\Lew\Application Data\WinBatch

========== Purity Check ==========



========== Custom Scans ==========

< %SYSTEMDRIVE%\*.exe >

< MD5 for: EXPLORER.EXE >
[2008/04/14 05:42:20 | 001,033,728 | —- | M] (Microsoft Corporation) MD5=12896823FB95BFB3DC9B46BCAEDC9923 – C:\WINDOWS\erdnt\cache\explorer.exe
[2008/04/14 05:42:20 | 001,033,728 | —- | M] (Microsoft Corporation) MD5=12896823FB95BFB3DC9B46BCAEDC9923 – C:\WINDOWS\explorer.exe
[2008/04/14 05:42:20 | 001,033,728 | —- | M] (Microsoft Corporation) MD5=12896823FB95BFB3DC9B46BCAEDC9923 – C:\WINDOWS\ServicePackFiles\i386\explorer.exe
[2006/02/28 08:00:00 | 001,032,192 | —- | M] (Microsoft Corporation) MD5=A0732187050030AE399B241436565E64 – C:\WINDOWS\$NtServicePackUninstall$\explorer.exe
[2012/11/13 15:07:52 | 003,906,584 | —- | M] (Safer-Networking Ltd.) MD5=E4A0900CF535888DDD85B10040CA3E34 – C:\Program Files\Spybot - Search & Destroy 2\explorer.exe

< MD5 for: SERVICES.EXE >
[2009/02/06 07:06:24 | 000,110,592 | —- | M] (Microsoft Corporation) MD5=020CEAAEDC8EB655B6506B8C70D53BB6 – C:\WINDOWS\$hf_mig$\KB956572\SP3QFE\services.exe
[2008/04/14 05:42:36 | 000,108,544 | —- | M] (Microsoft Corporation) MD5=0E776ED5F7CC9F94299E70461B7B8185 – C:\WINDOWS\$NtUninstallKB956572$\services.exe
[2008/04/14 05:42:36 | 000,108,544 | —- | M] (Microsoft Corporation) MD5=0E776ED5F7CC9F94299E70461B7B8185 – C:\WINDOWS\ServicePackFiles\i386\services.exe
[2009/02/06 07:11:05 | 000,110,592 | —- | M] (Microsoft Corporation) MD5=65DF52F5B8B6E9BBD183505225C37315 – C:\WINDOWS\erdnt\cache\services.exe
[2009/02/06 07:11:05 | 000,110,592 | —- | M] (Microsoft Corporation) MD5=65DF52F5B8B6E9BBD183505225C37315 – C:\WINDOWS\system32\dllcache\services.exe
[2009/02/06 07:11:05 | 000,110,592 | —- | M] (Microsoft Corporation) MD5=65DF52F5B8B6E9BBD183505225C37315 – C:\WINDOWS\system32\services.exe
[2006/02/28 08:00:00 | 000,108,032 | —- | M] (Microsoft Corporation) MD5=C6CE6EEC82F187615D1002BB3BB50ED4 – C:\WINDOWS\$NtServicePackUninstall$\services.exe

< MD5 for: SVCHOST.EXE >
[2008/04/14 05:42:38 | 000,014,336 | —- | M] (Microsoft Corporation) MD5=27C6D03BCDB8CFEB96B716F3D8BE3E18 – C:\WINDOWS\erdnt\cache\svchost.exe
[2008/04/14 05:42:38 | 000,014,336 | —- | M] (Microsoft Corporation) MD5=27C6D03BCDB8CFEB96B716F3D8BE3E18 – C:\WINDOWS\ServicePackFiles\i386\svchost.exe
[2008/04/14 05:42:38 | 000,014,336 | —- | M] (Microsoft Corporation) MD5=27C6D03BCDB8CFEB96B716F3D8BE3E18 – C:\WINDOWS\system32\svchost.exe
[2012/09/07 18:04:42 | 000,218,696 | —- | M] () MD5=4E0D8C9F83B7FD82393F7D8CCC27E7AE – C:\Documents and Settings\Lew\Desktop\All files from Flashdrive\Copy of Malwarbytes\Chameleon\svchost.exe
[2012/09/07 18:04:42 | 000,218,696 | —- | M] () MD5=4E0D8C9F83B7FD82393F7D8CCC27E7AE – C:\Documents and Settings\Lew\Desktop\All files from Flashdrive\Malwarbytes\Chameleon\svchost.exe
[2012/09/07 18:04:42 | 000,218,696 | —- | M] () MD5=4E0D8C9F83B7FD82393F7D8CCC27E7AE – C:\Documents and Settings\Lew\Desktop\All files from Flashdrive\USB20FD (E)\Copy of Malwarbytes\Chameleon\svchost.exe
[2012/09/07 18:04:42 | 000,218,696 | —- | M] () MD5=4E0D8C9F83B7FD82393F7D8CCC27E7AE – C:\Documents and Settings\Lew\Desktop\All files from Flashdrive\USB20FD (E)\Malwarbytes\Chameleon\svchost.exe
[2012/09/07 17:04:42 | 000,218,696 | —- | M] () MD5=4E0D8C9F83B7FD82393F7D8CCC27E7AE – C:\Program Files\Malwarbytes\Chameleon\svchost.exe
[2006/02/28 08:00:00 | 000,014,336 | —- | M] (Microsoft Corporation) MD5=8F078AE4ED187AAABC0A305146DE6716 – C:\WINDOWS\$NtServicePackUninstall$\svchost.exe
[2013/04/04 14:50:32 | 000,218,184 | —- | M] () MD5=B4C6E3889BB310CA7E974A04EC6E46AC – C:\Program Files\Malwarebytes' Anti-Malware\Chameleon\svchost.exe

< MD5 for: USERINIT.EXE >
[2006/02/28 08:00:00 | 000,024,576 | —- | M] (Microsoft Corporation) MD5=39B1FFB03C2296323832ACBAE50D2AFF – C:\WINDOWS\$NtServicePackUninstall$\userinit.exe
[2008/04/14 05:42:40 | 000,026,112 | —- | M] (Microsoft Corporation) MD5=A93AEE1928A9D7CE3E16D24EC7380F89 – C:\WINDOWS\erdnt\cache\userinit.exe
[2008/04/14 05:42:40 | 000,026,112 | —- | M] (Microsoft Corporation) MD5=A93AEE1928A9D7CE3E16D24EC7380F89 – C:\WINDOWS\ServicePackFiles\i386\userinit.exe
[2008/04/14 05:42:40 | 000,026,112 | —- | M] (Microsoft Corporation) MD5=A93AEE1928A9D7CE3E16D24EC7380F89 – C:\WINDOWS\system32\userinit.exe

< MD5 for: WINLOGON.EXE >
[2006/02/28 08:00:00 | 000,502,272 | —- | M] (Microsoft Corporation) MD5=01C3346C241652F43AED8E2149881BFE – C:\WINDOWS\$NtServicePackUninstall$\winlogon.exe
[2012/09/07 18:04:42 | 000,218,696 | —- | M] () MD5=4E0D8C9F83B7FD82393F7D8CCC27E7AE – C:\Documents and Settings\Lew\Desktop\All files from Flashdrive\Copy of Malwarbytes\Chameleon\winlogon.exe
[2012/09/07 18:04:42 | 000,218,696 | —- | M] () MD5=4E0D8C9F83B7FD82393F7D8CCC27E7AE – C:\Documents and Settings\Lew\Desktop\All files from Flashdrive\Malwarbytes\Chameleon\winlogon.exe
[2012/09/07 18:04:42 | 000,218,696 | —- | M] () MD5=4E0D8C9F83B7FD82393F7D8CCC27E7AE – C:\Documents and Settings\Lew\Desktop\All files from Flashdrive\USB20FD (E)\Copy of Malwarbytes\Chameleon\winlogon.exe
[2012/09/07 18:04:42 | 000,218,696 | —- | M] () MD5=4E0D8C9F83B7FD82393F7D8CCC27E7AE – C:\Documents and Settings\Lew\Desktop\All files from Flashdrive\USB20FD (E)\Malwarbytes\Chameleon\winlogon.exe
[2012/09/07 17:04:42 | 000,218,696 | —- | M] () MD5=4E0D8C9F83B7FD82393F7D8CCC27E7AE – C:\Program Files\Malwarbytes\Chameleon\winlogon.exe
[2013/04/04 14:50:32 | 000,218,184 | —- | M] () MD5=B4C6E3889BB310CA7E974A04EC6E46AC – C:\Program Files\Malwarebytes' Anti-Malware\Chameleon\winlogon.exe
[2008/04/14 05:42:40 | 000,507,904 | —- | M] (Microsoft Corporation) MD5=ED0EF0A136DEC83DF69F04118870003E – C:\WINDOWS\erdnt\cache\winlogon.exe
[2008/04/14 05:42:40 | 000,507,904 | —- | M] (Microsoft Corporation) MD5=ED0EF0A136DEC83DF69F04118870003E – C:\WINDOWS\ServicePackFiles\i386\winlogon.exe
[2008/04/14 05:42:40 | 000,507,904 | —- | M] (Microsoft Corporation) MD5=ED0EF0A136DEC83DF69F04118870003E – C:\WINDOWS\system32\winlogon.exe

< %systemroot%\*. /rp /s >

< %systemdrive%\$Recycle.Bin|@;true;true;true >

< %USERPROFILE%\..|smtmp;true;true;true /FP >

< %temp%\smtmp\*.* /s > >

========== Base Services ==========
SRV - [2008/04/14 05:42:14 | 000,044,544 | —- | M] (Microsoft Corporation) [On_Demand | Running] – C:\WINDOWS\system32\alg.exe – (ALG)
SRV - [2008/04/14 05:42:12 | 000,006,656 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\WINDOWS\system32\wuauserv.dll – (wuauserv)
SRV - [2008/04/14 05:42:04 | 000,409,088 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\WINDOWS\system32\qmgr.dll – (BITS)
SRV - [2012/07/06 09:58:51 | 000,078,336 | —- | M] (Microsoft Corporation) [Auto | Stopped] – C:\WINDOWS\system32\browser.dll – (Browser)
SRV - [2008/04/14 05:41:52 | 000,062,464 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\WINDOWS\system32\cryptsvc.dll – (CryptSvc)
SRV - [2008/04/14 05:41:52 | 000,126,976 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\WINDOWS\system32\dhcpcsvc.dll – (Dhcp)
SRV - [2009/04/20 13:17:26 | 000,045,568 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\WINDOWS\system32\dnsrslvr.dll – (Dnscache)
SRV - [2009/02/06 07:11:05 | 000,110,592 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\WINDOWS\system32\services.exe – (Eventlog)
SRV - [2008/04/14 05:41:54 | 000,033,792 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\WINDOWS\system32\eapsvc.dll – (EapHost)
SRV - [2009/07/27 19:17:41 | 000,135,168 | —- | M] (Microsoft Corporation) [On_Demand | Running] – C:\WINDOWS\system32\shsvcs.dll – (FastUserSwitchingCompatibility)
SRV - [2008/04/14 05:42:10 | 000,015,872 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\WINDOWS\system32\w3ssl.dll – (HTTPFilter)
SRV - [2008/04/14 06:41:56 | 000,021,504 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\WINDOWS\system32\hidserv.dll – (HidServ)
SRV - [2008/04/14 05:42:24 | 000,150,528 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\WINDOWS\system32\imapi.exe – (ImapiService)
SRV - [2008/04/14 05:42:26 | 000,013,312 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\WINDOWS\system32\lsass.exe – (PolicyAgent)
SRV - [2008/04/14 05:41:54 | 000,023,552 | —- | M] (Microsoft Corp.) [On_Demand | Stopped] – C:\WINDOWS\system32\dmserver.dll – (dmserver)
SRV - [2008/04/14 05:42:18 | 000,224,768 | —- | M] (Microsoft Corp., Veritas Software) [On_Demand | Stopped] – C:\WINDOWS\System32\dmadmin.exe – (dmadmin)
SRV - [2008/04/14 05:42:18 | 000,005,120 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\WINDOWS\System32\dllhost.exe – (SwPrv)
SRV - [2008/04/14 05:42:26 | 000,013,312 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\WINDOWS\system32\lsass.exe – (Netlogon)
SRV - [2008/04/14 05:42:02 | 000,198,144 | —- | M] (Microsoft Corporation) [On_Demand | Running] – C:\WINDOWS\system32\netman.dll – (Netman)
SRV - [2008/06/20 12:02:47 | 000,245,248 | —- | M] (Microsoft Corporation) [On_Demand | Running] – C:\WINDOWS\system32\mswsock.dll – (Nla)
SRV - [2009/02/06 07:11:05 | 000,110,592 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\WINDOWS\system32\services.exe – (PlugPlay)
SRV - [2010/08/17 09:17:06 | 000,058,880 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\WINDOWS\system32\spoolsv.exe – (Spooler)
SRV - [2008/04/14 05:42:26 | 000,013,312 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\WINDOWS\system32\lsass.exe – (ProtectedStorage)
SRV - [2008/04/14 05:42:04 | 000,088,576 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\WINDOWS\system32\rasauto.dll – (RasAuto)
SRV - [2008/04/14 05:42:04 | 000,186,368 | —- | M] (Microsoft Corporation) [On_Demand | Running] – C:\WINDOWS\system32\rasmans.dll – (RasMan)
SRV - [2009/02/09 08:10:48 | 000,401,408 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\WINDOWS\system32\rpcss.dll – (RpcSs)
SRV - [2008/04/14 05:42:04 | 000,435,200 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\WINDOWS\system32\ntmssvc.dll – (NtmsSvc)
SRV - [2008/04/14 05:42:06 | 000,018,944 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\WINDOWS\system32\seclogon.dll – (seclogon)
SRV - [2008/04/14 05:42:26 | 000,013,312 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\WINDOWS\system32\lsass.exe – (SamSs)
SRV - [2008/04/14 05:42:12 | 000,080,896 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\WINDOWS\system32\wscsvc.dll – (wscsvc)
SRV - [2010/08/27 01:57:43 | 000,099,840 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\WINDOWS\system32\srvsvc.dll – (lanmanserver)
SRV - [2009/07/27 19:17:41 | 000,135,168 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\WINDOWS\system32\shsvcs.dll – (ShellHWDetection)
SRV - [2008/04/14 05:42:08 | 000,171,008 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\WINDOWS\system32\srsvc.dll – (srservice)
SRV - [2008/04/14 05:42:06 | 000,192,512 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\WINDOWS\system32\schedsvc.dll – (Schedule)
SRV - [2008/04/14 05:41:58 | 000,013,824 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\WINDOWS\system32\lmhsvc.dll – (LmHosts)
SRV - [2008/04/14 05:42:08 | 000,249,856 | —- | M] (Microsoft Corporation) [On_Demand | Running] – C:\WINDOWS\system32\tapisrv.dll – (TapiSrv)
SRV - [2008/04/14 05:42:08 | 000,295,424 | —- | M] (Microsoft Corporation) [On_Demand | Running] – C:\WINDOWS\system32\termsrv.dll – (TermService)
SRV - [2009/07/27 19:17:41 | 000,135,168 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\WINDOWS\system32\shsvcs.dll – (Themes)
SRV - [2008/04/14 05:42:40 | 000,289,792 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\WINDOWS\system32\vssvc.exe – (VSS)
SRV - [2008/04/14 05:41:52 | 000,042,496 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\WINDOWS\system32\audiosrv.dll – (AudioSrv)
SRV - [2008/04/14 05:41:56 | 000,331,264 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\WINDOWS\system32\ipnathlp.dll – (SharedAccess)
SRV - [2008/04/14 05:42:10 | 000,333,824 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\WINDOWS\system32\wiaservc.dll – (stisvc)
SRV - [2008/04/14 05:42:30 | 000,078,848 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\WINDOWS\System32\msiexec.exe – (MSIServer)
SRV - [2008/04/14 05:42:10 | 000,144,896 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\WINDOWS\system32\wbem\wmisvc.dll – (winmgmt)
No service found with a name of Wmi
SRV - [2008/04/14 05:41:54 | 000,132,096 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\WINDOWS\system32\dot3svc.dll – (Dot3svc)
SRV - [2008/04/14 05:42:12 | 000,483,840 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\WINDOWS\system32\wzcsvc.dll – (WZCSVC)
SRV - [2009/06/10 02:14:49 | 000,132,096 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\WINDOWS\system32\wkssvc.dll – (lanmanworkstation)

========== Drive Information ==========

Physical Drives
—————

Drive: \\\\.\\PHYSICALDRIVE0 - Fixed\thard disk media
Interface type: IDE
Media Type: Fixed\thard disk media
Model: WDC WD5000AAKX-001CA0
Partitions: 1
Status: OK
Status Info: 0

Partitions
—————

DeviceID: Disk #0, Partition #0
PartitionType: Installable File System
Bootable: True
BootPartition: True
PrimaryPartition: True
Size: 466.00GB
Starting Offset: 32256
Hidden sectors: 0


< >
[2012/09/11 18:11:47 | 000,000,065 | RH– | C] () – C:\WINDOWS\Tasks\desktop.ini
[2012/09/11 18:18:10 | 000,000,006 | -H– | C] () – C:\WINDOWS\Tasks\SA.DAT
[2012/09/12 14:50:29 | 000,000,830 | —- | C] () – C:\WINDOWS\Tasks\Adobe Flash Player Updater.job
[2012/09/12 14:58:31 | 000,000,282 | —- | C] () – C:\WINDOWS\Tasks\RealUpgradeScheduledTaskS-1-5-21-2052111302-861567501-725345543-1004.job
[2012/09/12 14:58:32 | 000,000,274 | —- | C] () – C:\WINDOWS\Tasks\RealUpgradeLogonTaskS-1-5-21-2052111302-861567501-725345543-1004.job
[2012/09/18 15:21:42 | 000,000,464 | —- | C] () – C:\WINDOWS\Tasks\At1.job
[2012/09/18 15:21:42 | 000,000,464 | —- | C] () – C:\WINDOWS\Tasks\At2.job
[2012/09/18 15:21:42 | 000,000,464 | —- | C] () – C:\WINDOWS\Tasks\At3.job
[2012/09/18 15:21:42 | 000,000,464 | —- | C] () – C:\WINDOWS\Tasks\At4.job
[2012/11/21 17:17:41 | 000,000,332 | —- | C] () – C:\WINDOWS\Tasks\CandyUpdater.job.bak
[2012/11/24 15:32:47 | 000,000,446 | —- | C] () – C:\WINDOWS\Tasks\Scan the system (Spybot - Search & Destroy).job
[2012/11/24 15:32:47 | 000,000,616 | —- | C] () – C:\WINDOWS\Tasks\Refresh immunization (Spybot - Search & Destroy).job
[2012/11/24 15:32:47 | 000,000,620 | —- | C] () – C:\WINDOWS\Tasks\Check for updates (Spybot - Search & Destroy).job
[2012/11/27 21:42:16 | 000,000,434 | —- | C] () – C:\WINDOWS\Tasks\FixCleaner Scan.job.bak
[2013/02/27 04:10:48 | 000,000,366 | -H– | C] () – C:\WINDOWS\Tasks\MpIdleTask.job
[2013/02/27 04:10:56 | 000,000,384 | -H– | C] () – C:\WINDOWS\Tasks\Microsoft Antimalware Scheduled Scan.job

< >

========== Files - Unicode (All) ==========
[2013/02/21 16:34:50 | 000,000,353 | —- | M] ()(C:\Documents and Settings\Lew\Desktop\The ??st?n?ans (1984) - YouTube.url) – C:\Documents and Settings\Lew\Desktop\The Βọstọnịąns (1984) - YouTube.url
[2013/01/28 10:01:13 | 000,000,353 | —- | C] ()(C:\Documents and Settings\Lew\Desktop\The ??st?n?ans (1984) - YouTube.url) – C:\Documents and Settings\Lew\Desktop\The Βọstọnịąns (1984) - YouTube.url

========== Hard Links - Junction Points - Mount Points - Symbolic Links ==========
[C:\WINDOWS\assembly\GAC_32\System.EnterpriseServices\2.0.0.0__b03f5f7f11d50a3a] -> C:\WINDOWS\WinSxS\x86_System.EnterpriseServices_b03f5f7f11d50a3a_2.0.0.0_x-ww_7d5f3790 -> Junction
[C:\WINDOWS\assembly\GAC_MSIL\IEExecRemote\2.0.0.0__b03f5f7f11d50a3a] -> C:\WINDOWS\WinSxS\MSIL_IEExecRemote_b03f5f7f11d50a3a_2.0.0.0_x-ww_6e57c34e -> Junction

< End of report >

Must have missed the MBR.zip file. Will look again for it….
Hi Lewg,

Unfortunately some of the lag/freezing issues you may be encountering might be due to the fact that your computer has limited resources by today's standards.
Your computer's configuration (RAM - Random Access Memory) would be considered at the low end of what is needed to run at a smooth level.

958.48 Mb Total Physical Memory | 512.76 Mb Available Physical Memory | 53.50% Memory free

To help improve this situation you have a few options:
  • Upgrade to a new computer
  • Upgrade your current computers RAM
  • Move as much programs, data to an external hard drive
Obviously, these options come with a financial commitment.

=========================

1. RogueKiller

Download to your desktop RogueKiller (by tigzy)
  • Quit all programs
  • Double Click the desktop icon to start RogueKiller
  • Wait until Prescan has finished …
  • Click on Scan
  • Click the Report button, save the report to your desktop
=========================

2. Run OTL.exe

Windows Vista and Windows 7 users Right Click and select "Run as Administrator"
  • Copy/paste the following text written inside of the code box into the Custom Scans/Fixes box located at the bottom of OTL

    :OTL
    CHR - Extension: Coupon Companion = C:\Documents and Settings\Lew\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\pbkdpahkifcigckmhiafindmaflfifgm\1.18.12_0\crossrider
    CHR - Extension: Coupon Companion = C:\Documents and Settings\Lew\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\pbkdpahkifcigckmhiafindmaflfifgm\1.18.12_0\
    O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
    O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No CLSID value found.
    O15 - HKCU\..Trusted Domains: coastalbankofga.com ([]http in Local intranet)
    O15 - HKCU\..Trusted Domains: ebay.com ([]http in Local intranet)
    O15 - HKCU\..Trusted Domains: extendhealth.com ([]http in Local intranet)
    O15 - HKCU\..Trusted Domains: extendhealth.com ([]https in Trusted sites)
    O15 - HKCU\..Trusted Domains: fisherbuggies.com ([]http in Local intranet)
    O15 - HKCU\..Trusted Domains: hulu.com ([www] http in Local intranet)
    O15 - HKCU\..Trusted Domains: msn.com ([www] http in Local intranet)
    O15 - HKCU\..Trusted Domains: shoptalkforums.com ([www] http in Local intranet)
    O15 - HKCU\..Trusted Domains: thebrunswicknews.com ([]http in Local intranet)
    O15 - HKCU\..Trusted Domains: usps.com ([]http in Local intranet)
    O15 - HKCU\..Trusted Domains: usps.com ([]https in Trusted sites)
    O15 - HKCU\..Trusted Domains: whatthetech.com ([forums] http in Local intranet)
    O15 - HKCU\..Trusted Domains: yahoo.com ([www] http in Local intranet)
    [2013/06/14 20:40:02 | 000,000,464 | —- | M] () – C:\WINDOWS\tasks\At2.job
    [2013/06/14 15:21:00 | 000,000,464 | —- | M] () – C:\WINDOWS\tasks\At3.job
    [2013/06/14 14:00:00 | 000,000,464 | —- | M] () – C:\WINDOWS\tasks\At4.job
    [2013/06/14 10:10:12 | 000,000,464 | —- | M] () – C:\WINDOWS\tasks\At1.job
    
    :Commands
    [purity]
    [createrestorepoint]
    [emptyjava]
    [emptyflash]
    [Reboot]
  • Then click the Run Fix button at the top
  • Let the program run unhindered, reboot when it is done
=========================

3. AdwCleaner

Download AdwCleaner to your desktop.

  • Run AdwCleaner and select Delete
  • Once done it will ask to reboot, allow the reboot
  • On reboot a log will be produced, please attach the content of the log to your next reply
=========================

4. Re-run OTL (it should be located on your desktop).

Windows Vista and Windows 7 & 8 users Right Click and select "Run as Administrator" on the icon to run it.
  • Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output.
  • Uncheck the boxes beside LOP Check and Purity Check.
  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
  • When the scan completes, it will open one notepad window. OTL.Txt. (No Extras.txt will be produced)
    Note:The log can be located in the OTL. folder on you C:\ drive if they fail to open automatically.
  • Please copy (Edit->Select All, Edit->Copy) the contents of the file, and post it with your next reply.
=========================

In your next post please provide the following:
  • RKreport[1].txt
  • OTL fix log
  • AdwCleaner.txt
  • Fresh OTL.txt log
  • What symptoms are you experiencing?
Rogue Killer only created a Quarantine folder on my desktop. A debug file, and a RogueKiller.ini file, Plus a Physical D Drive Data file. Not sure if you got correct OTL log file. I ran it after posting all the fixes you wanted. I will repeat if you like.



OTL logfile created on: 6/15/2013 12:49:38 PM - Run 5
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Documents and Settings\Lew\Desktop
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

958.48 Mb Total Physical Memory | 533.67 Mb Available Physical Memory | 55.68% Memory free
2.26 Gb Paging File | 1.93 Gb Available in Paging File | 85.50% Paging File free
Paging file location(s): C:\pagefile.sys 1440 2880 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 465.75 Gb Total Space | 398.65 Gb Free Space | 85.59% Space Free | Partition Type: NTFS
Drive D: | 202.83 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS

Computer Name: LEW-0CCC0E88CE3 | User Name: Lew | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Documents and Settings\Lew\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Java\jre7\bin\jqs.exe (Oracle Corporation)
PRC - c:\Program Files\Microsoft Security Client\MsMpEng.exe (Microsoft Corporation)
PRC - C:\Program Files\Microsoft Security Client\msseces.exe (Microsoft Corporation)
PRC - C:\Program Files\Spybot - Search & Destroy 2\SDUpdate.exe (Safer-Networking Ltd.)
PRC - C:\Program Files\Spybot - Search & Destroy 2\SDUpdSvc.exe (Safer-Networking Ltd.)
PRC - C:\Program Files\Spybot - Search & Destroy 2\SDFSSvc.exe (Safer-Networking Ltd.)
PRC - C:\Program Files\Real\RealPlayer\Update\realsched.exe (RealNetworks, Inc.)
PRC - C:\Program Files\honestech Audio Recorder 3.0 Plus\HTARLauncher.exe (Honest Technology)
PRC - C:\Documents and Settings\Lew\My Documents\SASCore.exe (SUPERAntiSpyware.com)
PRC - C:\Program Files\Microsoft\BingBar\7.1.391.0\BBSvc.EXE (Microsoft Corporation.)
PRC - C:\Program Files\LSI SoftModem\agrsmsvc.exe (LSI Corporation)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)


========== Modules (No Company Name) ==========

MOD - C:\Program Files\Spybot - Search & Destroy 2\snlFileFormats150.bpl ()
MOD - C:\Program Files\Spybot - Search & Destroy 2\snlThirdParty150.bpl ()
MOD - C:\Program Files\Spybot - Search & Destroy 2\VirtualTreesDXE150.bpl ()
MOD - C:\Program Files\Spybot - Search & Destroy 2\JSDialogPack150.bpl ()
MOD - C:\Program Files\Spybot - Search & Destroy 2\DEC150.bpl ()
MOD - C:\Program Files\Spybot - Search & Destroy 2\sqlite3.dll ()


========== Services (SafeList) ==========

SRV - (SDWSCService) – C:\Program Files\Spybot File not found
SRV - (SDUpdateService) – C:\Program Files\Spybot File not found
SRV - (SDScannerService) – C:\Program Files\Spybot File not found
SRV - (AppMgmt) – %SystemRoot%\System32\appmgmts.dll File not found
SRV - (AdobeFlashPlayerUpdateSvc) – C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe (Adobe Systems Incorporated)
SRV - (JavaQuickStarterService) – C:\Program Files\Java\jre7\bin\jqs.exe (Oracle Corporation)
SRV - (MsMpSvc) – c:\Program Files\Microsoft Security Client\MsMpEng.exe (Microsoft Corporation)
SRV - (!SASCORE) – C:\Documents and Settings\Lew\My Documents\SASCore.exe (SUPERAntiSpyware.com)
SRV - (BBUpdate) – C:\Program Files\Microsoft\BingBar\7.1.391.0\SeaPort.EXE (Microsoft Corporation.)
SRV - (BBSvc) – C:\Program Files\Microsoft\BingBar\7.1.391.0\BBSvc.EXE (Microsoft Corporation.)
SRV - (AgereModemAudio) – C:\Program Files\LSI SoftModem\agrsmsvc.exe (LSI Corporation)


========== Driver Services (SafeList) ==========

DRV - (WDICA) – File not found
DRV - (PDRFRAME) – File not found
DRV - (PDRELI) – File not found
DRV - (PDFRAME) – File not found
DRV - (PDCOMP) – File not found
DRV - (PCIDump) – File not found
DRV - (lbrtfdc) – File not found
DRV - (i2omgmt) – File not found
DRV - (Changer) – File not found
DRV - (SASKUTIL) – C:\Documents and Settings\Lew\My Documents\SASKUTIL.SYS (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (SASDIFSV) – C:\Documents and Settings\Lew\My Documents\SASDIFSV.SYS (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (WDC_SAM) – C:\WINDOWS\system32\drivers\wdcsam.sys (Western Digital Technologies)
DRV - (AgereSoftModem) – C:\WINDOWS\system32\drivers\AGRSM.sys (LSI Corporation)
DRV - (IntcAzAudAddService) – C:\WINDOWS\system32\drivers\RtkHDAud.sys (Realtek Semiconductor Corp.)
DRV - (FETNDISB) – C:\WINDOWS\system32\drivers\dlkfet5b.sys (D-Link )
DRV - (nvnetbus) – C:\WINDOWS\system32\drivers\nvnetbus.sys (NVIDIA Corporation)
DRV - (NVENETFD) – C:\WINDOWS\system32\drivers\NVENETFD.sys (NVIDIA Corporation)
DRV - (Ps2) – C:\WINDOWS\system32\drivers\PS2.sys (Hewlett-Packard Company)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://search.live.com/results.aspx?q={sea…ferrer:source?}

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://aol.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://www.msn.com/?ocid=iehp
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-us
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 90 52 84 B8 B5 E2 CD 01 [binary data]
IE - HKCU\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://search.live.com/results.aspx?q={sea…amp;Form=IE8SRC
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0


========== FireFox ==========

FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32_11_7_700_224.dll ()
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.21.2: C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\5.1.20125.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@real.com/nppl3260;version=15.0.6.14: C:\Program Files\Real\RealPlayer\Netscape6\nppl3260.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprjplug;version=15.0.6.14: C:\Program Files\Real\RealPlayer\Netscape6\nprjplug.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprpchromebrowserrecordext;version=15.0.6.14: C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprpchromebrowserrecordext.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprphtml5videoshim;version=15.0.6.14: C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprpplugin;version=15.0.6.14: C:\Program Files\Real\RealPlayer\Netscape6\nprpplugin.dll (RealPlayer)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@nds.com/PCShowPlugin: C:\Documents and Settings\Lew\Local Settings\Application Data\DIRECTV Player\npPCShowPlugin.dll File not found
FF - HKCU\Software\MozillaPlugins\@nds.com/PlayerPlugin: C:\Documents and Settings\Lew\Local Settings\Application Data\DIRECTV Player\npPlayerPlugin.dll (NDS)
FF - HKCU\Software\MozillaPlugins\NDS.com/PlayerPlugin: C:\Documents and Settings\Lew\Local Settings\Application Data\DIRECTV Player\npPlayerPlugin.dll (NDS)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{0153E448-190B-4987-BDE1-F256CADA672F}: C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext [2012/09/12 14:56:42 | 000,000,000 | —D | M]

[2012/09/14 17:47:46 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions

========== Chrome ==========

CHR - Extension: No name found = C:\Documents and Settings\Lew\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0\
CHR - Extension: No name found = C:\Documents and Settings\Lew\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0\
CHR - Extension: No name found = C:\Documents and Settings\Lew\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\jfmjfhklogoienhpfnppmbcbjfjnkonk\1.5_0\
CHR - Extension: No name found = C:\Documents and Settings\Lew\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\

O1 HOSTS File: ([2012/09/20 10:30:46 | 000,000,027 | —- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (Java™ Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
O2 - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O3 - HKCU\..\Toolbar\WebBrowser: (WOT) - {71576546-354D-41C9-AAE8-31F2EC22BF0D} - C:\Program Files\WOT\WOT.dll ()
O4 - HKLM..\Run: [MSC] c:\Program Files\Microsoft Security Client\msseces.exe (Microsoft Corporation)
O4 - HKLM..\Run: [NvCplDaemon] C:\WINDOWS\System32\NvCpl.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [NvMediaCenter] C:\WINDOWS\System32\NvMcTray.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [TkBellExe] C:\Program Files\Real\RealPlayer\update\realsched.exe (RealNetworks, Inc.)
O4 - HKCU..\Run: [Spybot-S&D Cleaning] C:\Program Files\Spybot - Search & Destroy 2\SDCleaner.exe (Safer-Networking Ltd.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\honestech Audio Recorder 3.0 Plus Launcher.lnk = C:\Program Files\honestech Audio Recorder 3.0 Plus\HTARLauncher.exe (Honest Technology)
O4 - Startup: C:\Documents and Settings\Lew\Start Menu\Programs\Startup\WKCALREM.LNK = File not found
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O9 - Extra 'Tools' menuitem : Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy 2\SDHelper.dll (Safer-Networking Ltd.)
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} http://www.update.microsoft.com/windowsupd…b?1347465718176 (WUWebControl Class)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} http://www.update.microsoft.com/microsoftu…b?1347978180406 (MUWebControl Class)
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} http://download.eset.com/special/eos/OnlineScanner.cab (OnlineScanner Control)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.2.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{2E5072BA-3DCD-43F1-A347-7B3E0450AF88}: DhcpNameServer = 192.168.2.1
O18 - Protocol\Handler\wot {C2A44D6B-CB9F-4663-88A6-DF2F26E4D952} - C:\Program Files\WOT\WOT.dll ()
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) - C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O20 - Winlogon\Notify\SDWinLogon: DllName - (SDWinLogon.dll) - File not found
O28 - HKLM ShellExecuteHooks: {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - C:\Documents and Settings\Lew\My Documents\SASSEH.DLL (SuperAdBlocker.com)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2012/09/11 18:13:41 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)

========== Files/Folders - Created Within 30 Days ==========

[2013/06/15 12:29:57 | 000,000,000 | —D | C] – C:\_OTL
[2013/06/15 12:04:35 | 000,000,000 | —D | C] – C:\Documents and Settings\Lew\Desktop\RK_Quarantine
[2013/06/15 11:50:28 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Open It!
[2013/06/15 11:50:24 | 000,000,000 | —D | C] – C:\Program Files\OpenIt
[2013/06/15 11:50:09 | 000,000,000 | -H-D | C] – C:\Documents and Settings\All Users\Application Data\Common Files
[2013/06/15 11:49:29 | 000,000,000 | —D | C] – C:\Documents and Settings\Lew\Application Data\DSite
[2013/06/15 09:06:05 | 000,602,112 | —- | C] (OldTimer Tools) – C:\Documents and Settings\Lew\Desktop\OTL.exe
[2013/06/15 09:05:41 | 004,745,728 | —- | C] (AVAST Software) – C:\Documents and Settings\Lew\Desktop\aswMBR.exe
[2013/06/10 19:06:18 | 000,000,000 | RH-D | C] – C:\Documents and Settings\Lew\Recent
[2013/06/10 14:11:33 | 000,000,000 | —D | C] – C:\Documents and Settings\Lew\My Documents\Makita LS1440 Miter Saw

========== Files - Modified Within 30 Days ==========

[2013/06/15 12:46:25 | 000,000,274 | —- | M] () – C:\WINDOWS\tasks\RealUpgradeLogonTaskS-1-5-21-2052111302-861567501-725345543-1004.job
[2013/06/15 12:46:21 | 000,000,282 | —- | M] () – C:\WINDOWS\tasks\RealUpgradeScheduledTaskS-1-5-21-2052111302-861567501-725345543-1004.job
[2013/06/15 12:46:00 | 000,043,531 | —- | M] () – C:\WINDOWS\System32\nvapps.xml
[2013/06/15 12:45:28 | 000,000,620 | —- | M] () – C:\WINDOWS\tasks\Check for updates (Spybot - Search & Destroy).job
[2013/06/15 12:45:27 | 000,013,646 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2013/06/15 12:45:21 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2013/06/15 12:41:44 | 000,000,384 | -H– | M] () – C:\WINDOWS\tasks\Microsoft Antimalware Scheduled Scan.job
[2013/06/15 12:41:41 | 000,000,366 | -H– | M] () – C:\WINDOWS\tasks\MpIdleTask.job
[2013/06/15 12:40:15 | 000,000,830 | —- | M] () – C:\WINDOWS\tasks\Adobe Flash Player Updater.job
[2013/06/15 12:02:54 | 000,908,288 | —- | M] () – C:\Documents and Settings\Lew\Desktop\RogueKiller.exe
[2013/06/15 11:50:28 | 000,000,763 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Open It!.lnk
[2013/06/15 10:11:44 | 000,000,211 | —- | M] () – C:\Documents and Settings\Lew\Desktop\Google.url
[2013/06/15 09:41:42 | 000,000,512 | —- | M] () – C:\Documents and Settings\Lew\Desktop\MBR.dat
[2013/06/15 09:06:12 | 000,602,112 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Lew\Desktop\OTL.exe
[2013/06/15 09:05:45 | 004,745,728 | —- | M] (AVAST Software) – C:\Documents and Settings\Lew\Desktop\aswMBR.exe
[2013/06/14 19:06:29 | 000,000,279 | —- | M] () – C:\Documents and Settings\Lew\Desktop\Virus, Spyware & Malware Removal - What the Tech.url
[2013/06/14 18:56:56 | 000,000,208 | —- | M] () – C:\Documents and Settings\Lew\Desktop\Yahoo Mail Login.url
[2013/06/14 13:37:02 | 000,001,793 | —- | M] () – C:\Documents and Settings\Lew\Desktop\Rain Alarm.url
[2013/06/13 08:29:43 | 000,000,253 | —- | M] () – C:\Documents and Settings\Lew\Desktop\Contact Brunswick Radio Station.url
[2013/06/12 14:41:03 | 000,692,104 | —- | M] (Adobe Systems Incorporated) – C:\WINDOWS\System32\FlashPlayerApp.exe
[2013/06/12 14:41:03 | 000,071,048 | —- | M] (Adobe Systems Incorporated) – C:\WINDOWS\System32\FlashPlayerCPLApp.cpl
[2013/06/12 11:25:08 | 000,000,241 | —- | M] () – C:\Documents and Settings\Lew\Desktop\craigslist Brunswick, GA.url
[2013/06/12 03:00:56 | 000,001,374 | —- | M] () – C:\WINDOWS\imsins.BAK
[2013/06/12 00:30:00 | 000,000,616 | —- | M] () – C:\WINDOWS\tasks\Refresh immunization (Spybot - Search & Destroy).job
[2013/06/11 12:30:56 | 000,000,473 | —- | M] () – C:\Documents and Settings\Lew\Desktop\Guy Noir - 2-9-2013 - YouTube.url
[2013/06/11 12:11:15 | 000,000,473 | —- | M] () – C:\Documents and Settings\Lew\Desktop\Café Boeuf - 9-15-2012 - YouTube.url
[2013/06/10 19:07:10 | 000,001,062 | —- | M] () – C:\Documents and Settings\Lew\My Documents\cc_20130610_190704.reg
[2013/06/08 16:08:11 | 000,000,353 | —- | M] () – C:\Documents and Settings\Lew\Desktop\Real American Airlines Boeing 767 cockpit JFK to LAX (not a simulator or reenactment) - YouTube.url
[2013/06/08 12:04:36 | 004,760,816 | —- | M] (SUPERAntiSpyware.com) – C:\Documents and Settings\Lew\My Documents\SUPERANTISPYWARE.EXE
[2013/06/06 08:26:45 | 000,004,578 | —- | M] () – C:\Documents and Settings\Lew\Application Data\wklnhst.dat
[2013/06/03 14:34:56 | 000,001,630 | —- | M] () – C:\Documents and Settings\Lew\Desktop\The Farmhouse Cottage in Memphis.url
[2013/06/03 13:25:14 | 000,010,752 | —- | M] () – C:\Documents and Settings\Lew\Desktop\Funeral Letter to Robin Deason.wps
[2013/06/03 07:07:25 | 000,001,212 | —- | M] () – C:\Documents and Settings\Lew\Desktop\ 7-Day Forecast for Latitude 31.21°N and Longitude 81.36°W.url
[2013/06/01 08:55:33 | 000,002,846 | —- | M] () – C:\Documents and Settings\Lew\Desktop\How to Use Environment Variables in Windows XP.url
[2013/06/01 08:54:55 | 000,002,138 | —- | M] () – C:\Documents and Settings\Lew\Desktop\98 Volkswagen beetle my radio is in safe mode - JustAnswer.url
[2013/06/01 00:30:00 | 000,000,446 | —- | M] () – C:\WINDOWS\tasks\Scan the system (Spybot - Search & Destroy).job
[2013/05/25 08:53:05 | 000,000,294 | —- | M] () – C:\Documents and Settings\Lew\Desktop\Controlling Bahiagrass in Warm-Season Turf.url
[2013/05/25 07:48:06 | 000,000,241 | —- | M] () – C:\Documents and Settings\Lew\Desktop\TDIClub.url
[2013/05/23 16:48:01 | 000,000,735 | —- | M] () – C:\Documents and Settings\Lew\Start Menu\Programs\Startup\WKCALREM.LNK
[2013/05/18 13:40:47 | 000,050,925 | —- | M] () – C:\Documents and Settings\Lew\My Documents\Genuine Nissan Parts - Search by Nissan VIN, Car Model or Nissan Part Number.htm
[2013/05/18 07:01:32 | 000,062,272 | —- | M] () – C:\Documents and Settings\Lew\My Documents\GEELY SERVICE MANUALS.mht
[2013/05/18 07:00:21 | 002,712,100 | —- | M] () – C:\Documents and Settings\Lew\My Documents\Geely Manual.pdf
[2013/05/17 18:34:56 | 000,000,353 | —- | M] () – C:\Documents and Settings\Lew\Desktop\Imax - Fires of Kuwait - FULL - 9 subtitles - YouTube.url
[2013/05/17 18:07:22 | 006,014,976 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\mshtml.dll
[2013/05/17 09:05:50 | 000,000,361 | RHS- | M] () – C:\boot.ini
[2013/05/16 16:39:19 | 000,006,054 | —- | M] () – C:\Documents and Settings\Lew\My Documents\cc_20130516_163913.reg

========== Files Created - No Company Name ==========

[2013/06/15 12:02:26 | 000,908,288 | —- | C] () – C:\Documents and Settings\Lew\Desktop\RogueKiller.exe
[2013/06/15 11:50:28 | 000,000,763 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Open It!.lnk
[2013/06/15 09:41:42 | 000,000,512 | —- | C] () – C:\Documents and Settings\Lew\Desktop\MBR.dat
[2013/06/14 19:06:29 | 000,000,279 | —- | C] () – C:\Documents and Settings\Lew\Desktop\Virus, Spyware & Malware Removal - What the Tech.url
[2013/06/12 03:00:55 | 000,001,374 | —- | C] () – C:\WINDOWS\imsins.BAK
[2013/06/11 12:30:56 | 000,000,473 | —- | C] () – C:\Documents and Settings\Lew\Desktop\Guy Noir - 2-9-2013 - YouTube.url
[2013/06/10 19:07:09 | 000,001,062 | —- | C] () – C:\Documents and Settings\Lew\My Documents\cc_20130610_190704.reg
[2013/06/08 16:08:11 | 000,000,353 | —- | C] () – C:\Documents and Settings\Lew\Desktop\Real American Airlines Boeing 767 cockpit JFK to LAX (not a simulator or reenactment) - YouTube.url
[2013/06/04 16:32:30 | 000,001,793 | —- | C] () – C:\Documents and Settings\Lew\Desktop\Rain Alarm.url
[2013/05/30 16:41:52 | 000,001,630 | —- | C] () – C:\Documents and Settings\Lew\Desktop\The Farmhouse Cottage in Memphis.url
[2013/05/30 11:25:08 | 000,010,752 | —- | C] () – C:\Documents and Settings\Lew\Desktop\Funeral Letter to Robin Deason.wps
[2013/05/25 08:53:05 | 000,000,294 | —- | C] () – C:\Documents and Settings\Lew\Desktop\Controlling Bahiagrass in Warm-Season Turf.url
[2013/05/23 16:48:01 | 000,000,735 | —- | C] () – C:\Documents and Settings\Lew\Start Menu\Programs\Startup\WKCALREM.LNK
[2013/05/18 13:40:47 | 000,050,925 | —- | C] () – C:\Documents and Settings\Lew\My Documents\Genuine Nissan Parts - Search by Nissan VIN, Car Model or Nissan Part Number.htm
[2013/05/18 07:01:31 | 000,062,272 | —- | C] () – C:\Documents and Settings\Lew\My Documents\GEELY SERVICE MANUALS.mht
[2013/05/18 07:00:21 | 002,712,100 | —- | C] () – C:\Documents and Settings\Lew\My Documents\Geely Manual.pdf
[2013/05/16 16:39:17 | 000,006,054 | —- | C] () – C:\Documents and Settings\Lew\My Documents\cc_20130516_163913.reg
[2013/03/05 09:55:19 | 000,000,089 | —- | C] () – C:\WINDOWS\Taxact07.ini
[2013/02/27 11:43:26 | 000,000,076 | —- | C] () – C:\WINDOWS\Taxact10.ini
[2013/02/13 10:13:53 | 000,000,105 | —- | C] () – C:\WINDOWS\Taxact06.ini
[2013/01/28 16:08:55 | 000,098,008 | —- | C] () – C:\Documents and Settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
[2013/01/09 11:35:43 | 000,000,061 | —- | C] () – C:\WINDOWS\TaxACT12.ini
[2012/10/07 11:14:25 | 000,000,754 | —- | C] () – C:\WINDOWS\WORDPAD.INI
[2012/10/03 09:41:29 | 000,000,000 | —- | C] () – C:\Documents and Settings\Lew\PROGDA.TA
[2012/09/20 16:50:07 | 000,013,312 | —- | C] () – C:\Documents and Settings\Lew\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2012/09/18 14:28:55 | 000,000,028 | —- | C] () – C:\WINDOWS\QFNOA.INI
[2012/09/18 14:28:50 | 000,000,030 | —- | C] () – C:\WINDOWS\INTURS.DAT
[2012/09/14 17:42:01 | 000,004,578 | —- | C] () – C:\Documents and Settings\Lew\Application Data\wklnhst.dat
[2012/09/14 12:18:32 | 000,000,107 | —- | C] () – C:\WINDOWS\QHI.INI
[2012/09/14 12:07:48 | 000,000,646 | —- | C] () – C:\WINDOWS\INTU_ONL.INI
[2012/09/14 11:59:56 | 000,000,832 | —- | C] () – C:\WINDOWS\WININIT.INI
[2012/09/14 11:59:52 | 000,001,545 | —- | C] () – C:\WINDOWS\QfnOnl.ini
[2012/09/14 11:59:52 | 000,000,120 | —- | C] () – C:\WINDOWS\QUICKEN.INI
[2012/09/14 11:59:50 | 000,000,252 | —- | C] () – C:\WINDOWS\ADDRBOOK.INI
[2012/09/14 11:59:48 | 000,008,256 | —- | C] () – C:\WINDOWS\QFNOADB.DAT
[2012/09/14 11:59:48 | 000,000,326 | —- | C] () – C:\WINDOWS\QDQICK.INI
[2012/09/14 11:59:45 | 000,000,054 | —- | C] () – C:\WINDOWS\QFP.INI
[2012/09/14 11:59:45 | 000,000,054 | —- | C] () – C:\WINDOWS\MFF.INI
[2012/09/14 08:25:34 | 000,000,000 | —- | C] () – C:\WINDOWS\NT.INI
[2012/09/12 12:02:40 | 000,003,072 | —- | C] () – C:\WINDOWS\System32\iacenc.dll
[2012/09/11 18:15:28 | 000,002,048 | –S- | C] () – C:\WINDOWS\bootstat.dat
[2012/09/11 18:10:59 | 000,021,640 | —- | C] () – C:\WINDOWS\System32\emptyregdb.dat
[2012/09/11 11:32:51 | 000,004,161 | —- | C] () – C:\WINDOWS\ODBCINST.INI
[2012/09/11 11:31:39 | 000,165,912 | —- | C] () – C:\WINDOWS\System32\FNTCACHE.DAT

========== ZeroAccess Check ==========

[2012/09/18 12:43:50 | 000,000,227 | RHS- | M] () – C:\WINDOWS\assembly\Desktop.ini

[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]

[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shdocvw.dll – [2012/06/28 17:33:05 | 001,510,400 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll – [2009/02/09 08:10:48 | 000,473,600 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
"" = %systemroot%\system32\wbem\wbemess.dll – [2008/04/14 05:42:10 | 000,273,920 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Both

========== LOP Check ==========

[2013/05/05 10:45:26 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\4Team
[2013/06/15 11:50:09 | 000,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\Common Files
[2012/12/08 18:02:27 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Uninstall
[2012/12/15 15:58:09 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Western Digital
[2013/05/05 10:45:26 | 000,000,000 | —D | M] – C:\Documents and Settings\Lew\Application Data\4Team
[2013/06/15 11:49:29 | 000,000,000 | —D | M] – C:\Documents and Settings\Lew\Application Data\DSite
[2012/09/16 09:27:51 | 000,000,000 | —D | M] – C:\Documents and Settings\Lew\Application Data\DTV
[2012/12/25 11:33:00 | 000,000,000 | —D | M] – C:\Documents and Settings\Lew\Application Data\ElevatedDiagnostics
[2012/10/01 09:30:09 | 000,000,000 | —D | M] – C:\Documents and Settings\Lew\Application Data\FCTB000100567
[2012/11/27 21:42:23 | 000,000,000 | —D | M] – C:\Documents and Settings\Lew\Application Data\FixCleaner
[2013/03/17 09:36:20 | 000,000,000 | —D | M] – C:\Documents and Settings\Lew\Application Data\Spotify
[2012/09/14 17:42:02 | 000,000,000 | —D | M] – C:\Documents and Settings\Lew\Application Data\Template
[2012/09/12 15:09:45 | 000,000,000 | —D | M] – C:\Documents and Settings\Lew\Application Data\WinBatch

========== Purity Check ==========



========== Files - Unicode (All) ==========
[2013/02/21 16:34:50 | 000,000,353 | —- | M] ()(C:\Documents and Settings\Lew\Desktop\The ??st?n?ans (1984) - YouTube.url) – C:\Documents and Settings\Lew\Desktop\The Βọstọnịąns (1984) - YouTube.url
[2013/01/28 10:01:13 | 000,000,353 | —- | C] ()(C:\Documents and Settings\Lew\Desktop\The ??st?n?ans (1984) - YouTube.url) – C:\Documents and Settings\Lew\Desktop\The Βọstọnịąns (1984) - YouTube.url

< End of report >


# AdwCleaner v2.003 - Logfile created 06/15/2013 at 12:43:48
# Updated 23/09/2012 by Xplode
# Operating system : Microsoft Windows XP Service Pack 3 (32 bits)
# User : Lew - LEW-0CCC0E88CE3
# Boot Mode : Normal
# Running from : C:\Documents and Settings\Lew\My Documents\adwcleaner.exe
# Option [Delete]


***** [Services] *****


***** [Files / Folders] *****

File Deleted : C:\DOCUME~1\Lew\LOCALS~1\Temp\Uninstall.exe
File Deleted : C:\Documents and Settings\Lew\My Documents\Uninstall.exe

***** [Registry] *****

Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{95B7759C-8C7F-4BF1-B163-73684A933233}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{95B7759C-8C7F-4BF1-B163-73684A933233}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{F25AF245-4A81-40DC-92F9-E9021F207706}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{03E2A1F3-4402-4121-8B35-733216D61217}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{9E3B11F6-4179-4603-A71B-A55F4BCB0BEC}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{9C049BA6-EA47-4AC3-AED6-A66D8DC9E1D8}
Value Deleted : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39}]

***** [Internet Browsers] *****

-\\ Internet Explorer v8.0.6001.18702

[OK] Registry is clean.

-\\ Google Chrome v [Unable to get version]

File : C:\Documents and Settings\Lew\Local Settings\Application Data\Google\Chrome\User Data\Default\Preferences

Deleted [l.1] : icon_url ={"backup":{"_signature":"K+JdauYO+d9g2iNbQv7TaP6gVJwuahFJfe0MISUIXXo=","_version":4,"extensions":{"ids":["ahfgeienlihckogmohjhadlkjgocpleb","blpcfgokakmgnkcojhhkbfbldkacnbeo","coobgpohoikkiipiblmjeljniedjpjpf","jfmjfhklogoienhpfnppmbcbjfjnkonk","pbkdpahkifcigckmhiafindmaflfifgm","pjkljhegncpnkpknbcohdijeoejaedia"]},"homepage":"hxxp://www.google.com/","homepage_is_newtabpage":false,"session":{"urls_to_restore_on_startup":["hxxp://www.google.com/"]}},"browser":{"last_known_google_url":"hxxp://www.google.com/","last_prompted_google_url":"hxxp://www.google.com/","window_placement":{"bottom":854,"left":10,"maximized":false,"right":1060,"top":10,"work_area_bottom":864,"work_area_left":0,"work_area_right":1152,"work_area_top":0}},"countryid_at_install":21843,"default_apps_install_state":1,"default_search_provider":{"enabled":true,"encodings":"UTF-8","hxxp://www.google.com/favicon.ico","id":"2","instant_url":"{google:baseURL}webhp?{google:RLZ}sourceid=chrome-instant&ie={inputEncoding}{google:instantEnabledParameter}{searchTerms}","keyword":"google.com","name":"Google","prepopulate_id":"1","search_url":"{google:baseURL}search?q={searchTerms}&{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{g
oogle:assistedQueryStats}{google:searchFieldtrialParameter}sourceid=chrome&ie={inputEncoding}","suggest_url":"{google:baseSuggestURL}search?{google:searchFieldtrialParameter}client=chrome&hl={language}&q={searchTerms}"},"distribution":{"create_all_shortcuts":true,"do_not_launch_chrome":true,"import_history":false,"import_search_engine":false,"make_chrome_default":true,"ping_delay":-60,"skip_first_run_ui":false,"verbose_logging":false},"dns_prefetching":{"host_referral_list":[2,["hxxp://ad.bnmla.com/",["hxxp://ad.bnmla.com/",2.60370040,"hxxp://b.scorecardresearch.com/",2.60370040,"hxxp://cdn1.bnmla.com/",2.27338020,"hxxp://edge.quantserve.com/",2.27338020,"hxxp://pixel.quantserve.com/",2.27338020]],["hxxp://couponcp-a.akamaihd.net/",["hxxp://secure.trusted-serving.com/",3.924981199999999]],["hxxp://guru.sitescout.com/",["hxxp://guru.sitescout.com/",2.27338020,"hxxp://guru.sitescout.netdna-cdn.com/",2.93402060]],["hxxp://optimized-by.rubiconproject.com/",["hxxp://ad.yieldmanager.com/",2.27338020,"hxxp://ads.reduxmediagroup.com/",2.27338020,"hxxp://b.scorecardresearch.com/",2.60370040,"hxxp://beb.px.invitemedia.com/",2.27338020,"hxxp://ib.adnxs.com/",2.93402060,"hxxp://tap-cdn.rubiconproject.com/",2.60370040,"hxxp://tap2-cdn.rubiconproject.com/",2.60370040,"hxxp://view.atdmt.com/",2.60370040]],["hxxp://platform.twitter.com/",["hxxp://cdn.api.twitter.com/",2.27338020,"hxxp://p.twitter.com/",2.27338020]],["hxxp://secure.trusted-serving.com/",["hxxp://ad.bnmla.com/",2.60370040,"hxxp://guru.sitescout.com/",2.60370040,"hxxp://optimized-by.rubiconproject.com/",2.60370040,"hxxp://p.trusted-serving.com/",2.93402060]],["hxxp://tap2-cdn.rubiconproject.com/",["hxxp://ads.creative-serving.com/",2.60370040,"hxxp://d.xp1.ru4.com/",2.60370040,"hxxp://loadus.exelator.com/",3.264340799999999,"hxxp://m.xp1.ru4.com/",3.264340799999999,"hxxp://pcm3.map.pulsemgr.com/",2.27338020,"hxxp://pixel.exelator.com/",2.60370040,"hxxp://pixel.rubiconproject.com/",3.264340799999999,"hxxp://rp.gwallet.com/",2.27338020]],["hxxp://view.atdmt.com/",["hxxp://cdn.doubleverify.com/",2.27338020,"hxxp://choices.truste.com/",3.264340799999999,"hxxp://spe.atdmt.com/",2.27338020,"hxxps://choices.truste.com/",2.27338020]],["hxxp://www.bing.com/",["hxxp://www.msn.com/",2.60370040]],["hxxp://www.facebook.com/",["hxxp://static.ak.fbcdn.net/",2.60370040]],["hxxp://www.google.com/",["hxxp://ssl.gstatic.com/",2.2086570657060,"hxxp://www.google.com/",4.775984936953999]],["hxxp://www.msn.com/",["hxxp://col.stb00.s-msn.com/",2.27338020,"hxxp://col.stb01.s-msn.com/",2.60370040,"hxxp://couponcp-a.akamaihd.net/",5.576582199999999,"hxxp://d.textsrv.com/",2.27338020,"hxxp://static.ak.facebook.com/",3.264340799999999,"hxxp://www.facebook.com/",2.60370040,"hxxp://www.msn.com/",2.27338020,"hxxps://platform.twitter.com/",2.60370040,"hxxps://s-static.ak.facebook.com/",2.60370040,"hxxps://www.facebook.com/",2.60370040]],["hxxps://2542116.fls.doubleclick.net/",["hxxps://ad.yieldmanager.com/",3.813236985235999,"hxxps://cm.g.doubleclick.net/",2.5295730496120,"hxxps://cookex.amp.yahoo.com/",2.5295730496120,"hxxps://g-pixel.invitemedia.com/",2.5295730496120,"hxxps://googleads.g.doubleclick.net/",3.1714050174240,"hxxps://segment-pixel.invitemedia.com/",2.5295730496120,"hxxps://www.google.com/",2.5295730496120,"hxxps://www.googleadservices.com/",3.492321001330]],["hxxps://plusone.google.com/",["hxxps://plusone.google.com/",2.5295730496120]],["hxxps://www.google.com/",["hxxps://2542116.fls.doubleclick.net/",2.5295730496120,"hxxps://apis.google.com/",2.5295730496120,"hxxps://fls.doubleclick.net/",3.1714050174240,"hxxps://fonts.googleapis.com/",2.2086570657060,"hxxps://plusone.google.com/",2.5295730496120,"hxxps://ssl.google-analytics.com/",2.5295730496120,"hxxps://ssl.gstatic.com/",2.5295730496120,"hxxps://themes.googleusercontent.com/",3.1714050174240,"hxxps://tools.google.com/",2.2086570657060,"hxxps://www.google.com/",6.059648872577998]]],"startup_list":[1,"hxxp://ads1.msads.net/","hxxp://b.scorecardresearch.com/","hxxp://c.msn.com/","hxxp://col.stc.s-msn.com/","hxxp://col.stj.s-msn.com/","hxxp://rad.msn.com/","hxxp://udc.msn.com/","hxxp://view.atdmt.com/","hxxp://www.bing.com/","hxxp://www.msn.com/"]},"download":{"directory_upgrade":true},"extensions":{"alerts":{"initialized":true},"autoupdate":{"next_check":"12999539393566875"},"chrome_url_overrides":{"bookmarks":["chrome-extension://eemcgdkfndhakfknompkggombfjjjeno/main.html"]},"settings":{"ahfgeienlihckogmohjhadlkjgocpleb":{"active_permissions":{"api":["appNotifications","management","webstorePrivate"]},"app_launcher_ordinal":"n","page_ordinal":"n"},"blpcfgokakmgnkcojhhkbfbldkacnbeo":{"ack_external":true,"active_permissions":{"api":["appNotifications"]},"app_launcher_ordinal":"x","events":["runtime.onInstalled"],"from_bookmark":true,"from_webstore":true,"install_time":"12999538778542250","location":2,"manifest":{"app":{"launch":{"container":"tab","web_url":"hxxp://www.youtube.com/"},"web_content":{"enabled":true,"origin":"hxxp://www.youtube.com"}},"current_locale":"en_US","default_locale":"en","description":"The world's most popular online video community.","icons":{"128":"128.png"},"key":"MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDC/HotmFlyuz5FaHaIbVBhhL4BwbcUtsfWwzgUMpZt5ZsLB2nW/Y5xwNkkPANYGdVsJkT2GPpRRIKBO5QiJ7jPMa3EZtcZHpkygBlQLSjMhdrAKevpKgIl6YTkwzNvExY6r
zVDzeE9zqnIs33eppY4S5QcoALMxuSWlMKqgFQjHQIDAQAB","name":"YouTube","permissions":["appNotifications"],"update_url":"hxxp://clients2.google.com/service/update2/crx","version":"4.2.5"},"page_ordinal":"n","path":"blpcfgokakmgnkcojhhkbfbldkacnbeo\\4.2.5_0","state":1},"coobgpohoikkiipiblmjeljniedjpjpf":{"ack_external":true,"app_launcher_ordinal":"w","events":["runtime.onInstalled"],"from_bookmark":true,"from_webstore":true,"install_time":"12999538777779125","location":2,"manifest":{"app":{"launch":{"web_url":"hxxp://www.google.com/webhp?source=search_app"},"urls":["*://www.google.com/search","*://www.google.com/webhp","*://www.google.com/imgres"]},"current_locale":"en_US","default_locale":"en","description":"The fastest way to search the web.","icons":{"128":"128.png","16":"16.png","32":"32.png","48":"48.png"},"key":"MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDIiso3Loy5VJHL40shGhUl6it5ZG55XB9q/2EX6aa88jAxwPutbCgy5d9bm1YmBzLfSgpX4xcpgTU08ydWbd7b50fbkLsqWl1mRhxoqnN01kuNfv9Hb
z9dWWYd+O4ZfD3L2XZs0wQqo0y6k64n+qeLkUMd1MIhf6MR8Xz1SOA8pwIDAQAB","name":"Google Search","update_url":"hxxp://clients2.google.com/service/update2/crx","version":"0.0.0.19"},"page_ordinal":"n","path":"coobgpohoikkiipiblmjeljniedjpjpf\\0.0.0.19_0","state":1},"jfmjfhklogoienhpfnppmbcbjfjnkonk":{"ack_external":true,"active_permissions":{"api":["tabs"],"explicit_host":["hxxp://*/*","hxxps://*/*"],"scriptable_host":["hxxp://*/*","hxxps://*/*"]},"events":["runtime.onInstalled"],"from_bookmark":false,"from_webstore":false,"install_time":"12999538768707500","location":3,"manifest":{"background_page":"background.html","content_scripts":[{"js":["contentscript.js"],"matches":["hxxp://*/*","hxxps://*/*"],"run_at":"document_idle"}],"description":"RealPlayer HTML5Video Downloader Extension","key":"MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQCl0WKWTrid8Fh+tsoJPRheLc7tksPgH1NfLF7
9Fj3YKb0fk2Fip1eE/chfSnGWQkxe5Ck2r+ZPba7m+FWQhZDCE5EXvOTDoqi7TEvjccW5pMpW5wCUOLKQVSttgBwkY8EUYt40S
wtJ6HmLoPZfQmo9W3qAjnlhlF5AkY4jYgBv3QIDAQAB","name":"RealPlayer HTML5Video Downloader Extension","permissions":["tabs","hxxp://*/*","hxxps://*/*"],"version":"1.5"},"path":"jfmjfhklogoienhpfnppmbcbjfjnkonk\\1.5_0","state":1},"pbkdpahkifcigckmhiafindmaflfifgm":{"ack_external":true,"active_permissions":{"api":["contextMenus","cookies","notifications","tabs","unlimitedStorage","webRequest","webRequestBlocking","webRequestInternal"],"explicit_host":["hxxp://*/*","hxxps://*/*"],"scriptable_host":["hxxp://*/*","hxxps://*/*"]},"events":["runtime.onInstalled"],"from_bookmark":false,"from_webstore":false,"install_time":"12999538773754875","location":3,"manifest":{"background_page":"background.html","content_scripts":[{"all_frames":true,"js":["js/lib/util.js","js/api/cookie.js","js/api/push.js","js/api/chrome.js","js/api/message.js","js/lib/async_api.js","js/lib/app_api.js"],"matches":["hxxp://*/*","hxxps://*/*"],"run_at":"document_end"}],"description":"Coupon Companion","icons":{"128":"/icons/icon128.png","16":"/icons/icon16.png","48":"/icons/icon48.png"},"key":"MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDFDp/HcU8RMxFPeFZqoi4vLp1Mc2mNTUcbcHAmA0z8CB5Zf5KHUkgSWDRExcms50dW6gPSpaofDT9Ab+04juX
FwVPu5agENR37rkfhD9EBLT1D8+9GP8XCZfd/H7xOWa4qFnI1a7e2HLQSi/cCD44QoFVA/wkR/YBErvdikBk75wIDAQAB","name":"Coupon Companion","permissions":["hxxp://*/*","hxxps://*/*","tabs","cookies","notifications","contextMenus","webRequest","webRequestBlocking","unlimitedStorage"],"update_url":"hxxps://crossrider.cotssl.net/plugin/chrome/update/4493.xml","version":"1.18.12"},"path":"pbkdpahkifcigckmhiafindmaflfifgm\\1.18.12_0","state":1},"pjkljhegncpnkpknbcohdijeoejaedia":{"ack_external":true,"active_permissions":{"api":["notifications"]},"app_launcher_ordinal":"t","events":["runtime.onInstalled"],"from_bookmark":false,"from_webstore":true,"install_time":"12999538777263125","location":2,"manifest":{"app":{"launch":{"container":"tab","web_url":"hxxps://mail.google.com/mail/ca"},"urls":["*://mail.google.com/mail/ca"]},"current_locale":"en_US","default_locale":"en","description":"Fast, searchable email with less spam.","icons":{"128":"128.png"},"key":"MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDCuGglK43iAz3J9BEYK/Mz6ZhloIMMDqQSAaf3vJt4eHbTbSDsu4WdQ9dQDRcKlg8nwQdePBt0C3PSUBtiSNSS37Z3qEGfS7LCju
3h6pI1Yr9MQtxw+jUa7kXXIS09VV73pEFUT/F7c6Qe8L5ZxgAcBvXBh1Fie63qb02I9XQ/CQIDAQAB","name":"Gmail","options_page":"hxxps://mail.google.com/mail/ca/#settings","permissions":["notifications"],"update_url":"hxxp://clients2.google.com/service/update2/crx","version":"7"},"page_ordinal":"n","path":"pjkljhegncpnkpknbcohdijeoejaedia\\7_0","state":1}}},"first_run_tabs":["hxxp://www.google.com/","hxxp://welcome_page"],"homepage":"hxxp://www.google.com/","homepage_is_newtabpage":false,"net":{"hxxp_server_properties":{"servers":{"2542116.fls.doubleclick.net:443":{"settings":{"4":100},"supports_spdy":true},"apis.google.com:443":{"settings":{"4":100},"supports_spdy":true},"cm.g.doubleclick.net:443":{"settings":{"4":100},"supports_spdy":true},"fls.doubleclick.net:443":{"settings":{"4":100},"supports_spdy":true},"fonts.googleapis.com:443":{"settings":{"4":100},"supports_spdy":true},"googleads.g.doubleclick.net:443":{"settings":{"4":100},"supports_spdy":true},"plusone.google.com:443":{"settings":{"4":100},"supports_spdy":true},"ssl.google-analytics.com:443":{"settings":{"4":100},"supports_spdy":true},"ssl.gstatic.com:443":{"settings":{"4":100},"supports_spdy":true},"themes.googleusercontent.com:443":{"settings":{"4":100},"supports_spdy":true},"www.google.com:443":{"settings":{"4":100,"5":10},"supports_spdy":true},"www.googleadservices.com:443":{"settings":{"4":100},"supports_spdy":true}},"version":1}},"ntp":{"promo_resource_cache_update":"1355065170.03325"},"plugins":{"enabled_internal_pdf3":true,"enabled_nacl":true,"migrated_to_pepper_flash":true},"profile":{"avatar_index":0,"content_settings":{"clear_on_exit_migrated":true,"pref_version":1},"exited_cleanly":true,"name":"First user"},"session":{"restore_on_startup":null,"restore_on_startup_migrated":true,"urls_to_restore_on_startup":["hxxp://www.google.com/"]},"sync_promo":{"show_on_first_run_allowed":false}}

*************************

AdwCleaner[R25].txt - [1368 octets] - [10/04/2013 12:16:52]
AdwCleaner[S11].txt - [1439 octets] - [10/04/2013 12:17:09]
AdwCleaner[S13].txt - [14431 octets] - [15/06/2013 12:43:48]

########## EOF - C:\AdwCleaner[S13].txt - [14493 octets] ##########
Hi Lewg,

1. ComboFix

Refer to the ComboFix User's Guide

  • Download ComboFix from the following location:

    Link

    * IMPORTANT !!! Place ComboFix.exe on your Desktop
  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with ComboFix.
    You can get help on disabling your protection programs here
  • Double click on ComboFix.exe & follow the prompts.
  • Your desktop may go blank. This is normal. It will return when ComboFix is done. ComboFix may reboot your machine. This is normal.
  • When finished, it shall produce a log for you. Post that log in your next reply

    Note: Do not mouseclick combofix's window whilst it's running. That may cause it to stall.

    ———————————————————————————————
  • Ensure your AntiVirus and AntiSpyware applications are re-enabled.
    ———————————————————————————————
NOTE: If you encounter a message "illegal operation attempted on registry key that has been marked for deletion" and no programs will run - please just reboot and that will resolve that error.

=========================

2. Re-run RogueKiller

Right click and select "Run as Administrator"
  • Quit all programs
  • Wait until Prescan has finished …
  • Click on Scan, Do Not Fix Anything at this point.
  • Click the Report button, save the report to your desktop
=========================

In your next post please provide the following:
  • ComboFix.txt
  • RKreport.txt
  • How is the computer running, what issues are you experiencing?
I will try and run Roguekiller again. Will post results next.


ComboFix 13-06-15.01 - Lew 06/16/2013 8:01.4.1 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.958.516 [GMT -4:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
AV: Microsoft Security Essentials *Disabled/Updated* {EDB4FA23-53B8-4AFA-8C5D-99752CCA7095}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\windows\wininit.ini
.
.
((((((((((((((((((((((((( Files Created from 2013-05-16 to 2013-06-16 )))))))))))))))))))))))))))))))
.
.
2013-06-16 05:56 . 2013-06-16 05:56 60872 —-a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{922FE7B7-8990-4F5B-A33B-5E02450ADF17}\offreg.dll
2013-06-16 05:56 . 2013-06-16 05:56 29904 —-a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{922FE7B7-8990-4F5B-A33B-5E02450ADF17}\MpKsld72ce251.sys
2013-06-16 05:51 . 2013-05-13 06:19 7016152 —-a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{922FE7B7-8990-4F5B-A33B-5E02450ADF17}\mpengine.dll
2013-06-15 16:29 . 2013-06-15 16:29 ——– d—–w- C:\_OTL
2013-06-15 15:50 . 2013-06-15 15:50 ——– d—–w- c:\program files\OpenIt
2013-06-15 15:50 . 2013-06-15 15:50 ——– d–h–w- c:\documents and settings\All Users\Application Data\Common Files
2013-06-15 15:49 . 2013-06-15 15:49 ——– d—–w- c:\documents and settings\Lew\Application Data\DSite
2013-06-14 22:42 . 2013-05-13 06:19 7016152 —-a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2013-06-12 18:41 . 2012-09-12 18:50 71048 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2013-06-12 18:41 . 2012-09-12 18:50 692104 —-a-w- c:\windows\system32\FlashPlayerApp.exe
2013-05-07 22:30 . 2006-02-28 12:00 920064 —-a-w- c:\windows\system32\wininet.dll
2013-05-07 22:30 . 2006-02-28 12:00 43520 ——w- c:\windows\system32\licmgr10.dll
2013-05-07 22:30 . 2006-02-28 12:00 1469440 ——w- c:\windows\system32\inetcpl.cpl
2013-05-07 21:53 . 2006-02-28 12:00 385024 ——w- c:\windows\system32\html.iec
2013-05-03 01:26 . 2006-02-28 12:00 2193536 —-a-w- c:\windows\system32\ntoskrnl.exe
2013-05-03 00:38 . 2004-08-03 22:59 2070144 —-a-w- c:\windows\system32\ntkrnlpa.exe
2013-05-02 15:28 . 2012-09-13 19:26 238872 ——w- c:\windows\system32\MpSigStub.exe
2013-04-10 01:31 . 2006-02-28 12:00 1876352 —-a-w- c:\windows\system32\win32k.sys
2013-04-04 18:50 . 2012-10-01 14:11 22856 —-a-w- c:\windows\system32\drivers\mbam.sys
2013-04-04 09:35 . 2013-04-23 12:43 94112 —-a-w- c:\windows\system32\WindowsAccessBridge.dll
2013-03-26 16:43 . 2013-03-26 16:43 465280 —-a-r- c:\windows\system32\cpnprt2win32.cid
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Spybot-S&D Cleaning"="c:\program files\Spybot - Search & Destroy 2\SDCleaner.exe" [2012-11-13 3713032]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2006-05-09 7311360]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2006-05-09 86016]
"KBD"="c:\hp\KBD\KBD.EXE" [2005-02-02 61440]
"MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2013-01-27 947152]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2013-03-12 253816]
"TkBellExe"="c:\program files\Real\RealPlayer\update\realsched.exe" [2012-09-12 296096]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2013-04-04 958576]
.
c:\documents and settings\All Users\Start Menu\Programs\Startup\
honestech Audio Recorder 3.0 Plus Launcher.lnk - c:\program files\honestech Audio Recorder 3.0 Plus\HTARLauncher.exe [2013-3-26 386560]
.
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\documents and settings\Lew\My Documents\SASSEH.DLL" [2011-07-19 113024]
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk *\0\0sdnclean.exe
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\!SASCORE]
@=""
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"
.
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"Spotify"="c:\documents and settings\Lew\Application Data\Spotify\Spotify.exe" /uri spotify:autostart
"Spotify Web Helper"="c:\documents and settings\Lew\Application Data\Spotify\Data\SpotifyWebHelper.exe"
"SUPERAntiSpyware"=c:\documents and settings\Lew\My Documents\SUPERAntiSpyware.exe
"PCShowServer"="c:\documents and settings\Lew\Local Settings\Application Data\DIRECTV Player\PCShowServerPMWrapper.exe"
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
"TkBellExe"="c:\program files\Real\RealPlayer\update\realsched.exe" -osboot
"RTHDCPL"=RTHDCPL.EXE
"nwiz"=nwiz.exe /install
"SDTray"="c:\program files\Spybot - Search & Destroy 2\SDTray.exe"
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Documents and Settings\\Lew\\Application Data\\Spotify\\spotify.exe"=
"c:\\Program Files\\Spybot - Search & Destroy 2\\SDTray.exe"=
"c:\\Program Files\\Spybot - Search & Destroy 2\\SDFSSvc.exe"=
"c:\\Program Files\\Spybot - Search & Destroy 2\\SDUpdate.exe"=
"c:\\Program Files\\Spybot - Search & Destroy 2\\SDUpdSvc.exe"=
"c:\\WINDOWS\\system32\\dpvsetup.exe"=
.
R1 MpKsld72ce251;MpKsld72ce251;c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{922FE7B7-8990-4F5B-A33B-5E02450ADF17}\MpKsld72ce251.sys [6/16/2013 1:56 AM 29904]
R1 SASDIFSV;SASDIFSV;c:\documents and settings\Lew\My Documents\SASDIFSV.SYS [5/5/2013 10:22 AM 12880]
R1 SASKUTIL;SASKUTIL;c:\documents and settings\Lew\My Documents\SASKUTIL.SYS [5/5/2013 10:22 AM 67664]
R2 !SASCORE;SAS Core Service;c:\documents and settings\Lew\My Documents\SASCore.exe [7/11/2012 2:54 PM 116608]
R2 SDScannerService;Spybot-S&D 2 Scanner Service;c:\program files\Spybot - Search & Destroy 2\SDFSSvc.exe [11/24/2012 3:32 PM 1103392]
R3 BBUpdate;BBUpdate;c:\program files\Microsoft\BingBar\7.1.391.0\SeaPort.EXE [6/11/2012 4:22 PM 240208]
R3 SDUpdateService;Spybot-S&D 2 Updating Service;c:\program files\Spybot - Search & Destroy 2\SDUpdSvc.exe [11/24/2012 3:32 PM 1369624]
S2 BBSvc;BingBar Service;c:\program files\Microsoft\BingBar\7.1.391.0\BBSvc.EXE [6/11/2012 4:22 PM 193616]
S2 SDWSCService;Spybot-S&D 2 Security Center Service;c:\program files\Spybot - Search & Destroy 2\SDWSCSvc.exe [11/24/2012 3:32 PM 168384]
S3 WDC_SAM;WD SCSI Pass Thru driver;c:\windows\system32\drivers\wdcsam.sys [12/29/2012 12:50 PM 11520]
.
— Other Services/Drivers In Memory —
.
*NewlyCreated* - MPKSLD72CE251
.
Contents of the 'Scheduled Tasks' folder
.
2013-06-16 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-09-12 18:41]
.
2013-06-15 c:\windows\Tasks\Check for updates (Spybot - Search & Destroy).job
- c:\program files\Spybot - Search & Destroy 2\SDUpdate.exe [2012-11-24 19:08]
.
2013-06-16 c:\windows\Tasks\Microsoft Antimalware Scheduled Scan.job
- c:\program files\Microsoft Security Client\MpCmdRun.exe [2013-01-27 16:11]
.
2013-06-16 c:\windows\Tasks\MpIdleTask.job
- c:\program files\Microsoft Security Client\MpCmdRun.exe [2013-01-27 16:11]
.
2013-06-15 c:\windows\Tasks\RealUpgradeLogonTaskS-1-5-21-2052111302-861567501-725345543-1004.job
- c:\program files\Real\RealUpgrade\realupgrade.exe [2012-07-27 18:27]
.
2013-06-15 c:\windows\Tasks\RealUpgradeScheduledTaskS-1-5-21-2052111302-861567501-725345543-1004.job
- c:\program files\Real\RealUpgrade\realupgrade.exe [2012-07-27 18:27]
.
2013-06-12 c:\windows\Tasks\Refresh immunization (Spybot - Search & Destroy).job
- c:\program files\Spybot - Search & Destroy 2\SDImmunize.exe [2012-11-24 19:07]
.
2013-06-01 c:\windows\Tasks\Scan the system (Spybot - Search & Destroy).job
- c:\program files\Spybot - Search & Destroy 2\SDScan.exe [2012-11-24 19:07]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://aol.com/
uInternet Connection Wizard,ShellNext = iexplore
TCP: DhcpNameServer = 192.168.2.1
.
- - - - ORPHANS REMOVED - - - -
.
c:\documents and settings\Lew\Start Menu\Programs\Startup\WKCALREM.LNK - c:\program files\COMMON FILES\MICROSOFT SHARED\WORKS SHARED\WKCALREM.EXE
Notify-SDWinLogon - SDWinLogon.dll
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2013-06-16 08:06
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes …
.
scanning hidden autostart entries …
.
scanning hidden files …
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————
.
[HKEY_USERS\S-1-5-21-2052111302-861567501-725345543-1004\Software\Microsoft\SystemCertificates\AddressBook*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil32_11_7_700_224_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil32_11_7_700_224_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
Completion time: 2013-06-16 08:07:49
ComboFix-quarantined-files.txt 2013-06-16 12:07
.
Pre-Run: 427,954,188,288 bytes free
Post-Run: 428,146,556,928 bytes free
.
- - End Of File - - 082FDFD82814D64D49BF172ACFC48BDF
8F558EB6672622401DA993E1E865C861
I started Roguekiller again, and it just before finishing a window poped up that read, Opps! This program has crashed. Restart to create a Debug.log. The same thing happen when you asked me to d/load earlier and run. Not sure why this is happening. Will try it again.
Hi Lewg,

Delete the copy of RogueKiller you previously downloaded, and download a fresh copy.

=========================

1. RogueKiller

Download to your desktop RogueKiller (by tigzy)

Right click and select "Run as Administrator"
  • Quit all programs
  • Wait until Prescan has finished …
  • Click on Scan, Do Not Fix Anything at this point.
  • Click the Report button, save the report to your desktop
=========================

In your next post please provide the following:
  • RKreport[1].txt
  • How is the computer running?
Did as you said and removed Roguekiller, and d/loaded again. Ran it and it found a couple keys, but another window popped up saying the programs had crashed before. It will not complete the run nor produce a RKreport.txt file. I overlooked the security test. It's posted below. Sorry!

Results of screen317's Security Check version 0.99.24
Windows XP Service Pack 3 x86
Internet Explorer 8
``````````````````````````````
Antivirus/Firewall Check:

Windows Firewall Enabled!
ESET Online Scanner v3
Microsoft Security Essentials
```````````````````````````````
Anti-malware/Other Utilities Check:

Spybot - Search & Destroy
CCleaner
Java 7 Update 21
Out of date Java installed!
Adobe Flash Player 11.7.700.224
````````````````````````````````
Process Check:
objlist.exe by Laurent

Windows Defender MSMpEng.exe
Spybot Teatimer.exe is disabled!
Microsoft Security Essentials msseces.exe
``````````End of Log````````````
Hi Lewg,

1. rkill

Print out these instructions as we may need to close every window that is open later in the fix.

It is possible that the infection you are trying to remove will not allow you to download files on the infected computer. If this is the case, then you will need to download the files requested in this guide on another computer and then transfer them to the infected computer. You can transfer the files via a CD/DVD, external drive, or USB flash drive.

Do not reboot your computer after running rkill as the malware programs will start again.

Please download and run the following tool to help allow other programs to run. (courtesy of BleepingComputer.com)
There are 5 different versions. If one of them won't run then download and try to run the other one.
Vista, Windows 7 & 8 – Right click and select "Run as Administrator"
You only need to get one of them to run, not all of them.
  • rkill.exe
  • rkill.com
  • rkill.scr
  • WiNlOgOn.exe
  • uSeRiNiT.exe

Do not reboot your computer after running rkill as the malware programs will start again.

=========================

2. TDSSKiller

Please download TDSSKiller.zip
  • Extract it to your desktop
  • Double click TDSSKiller.exe
  • Press Start Scan
    • Only if Malicious objects are found then ensure Cure is selected
    • Then click Continue > Reboot now
  • Copy and paste the log in your next reply
    • A copy of the log will be saved automatically to the root of the drive (typically C:\)
=========================

In your next post please provide the following:
  • TDSSKiller log
  • How is the computer running?
Rkill 2.5.3 by Lawrence Abrams (Grinler)
http://www.bleepingcomputer.com/
Copyright 2008-2013 BleepingComputer.com
More Information about Rkill can be found at this link:
http://www.bleepingcomputer.com/forums/topic308364.html

Program started at: 06/17/2013 06:36:40 AM in x86 mode.
Windows Version: Microsoft Windows XP Service Pack 3

Checking for Windows services to stop:

* No malware services found to stop.

Checking for processes to terminate:

* C:\Documents and Settings\Lew\My Documents\SASCORE.EXE (PID: 1828) [UP-HEUR]

1 proccess terminated!

Checking Registry for malware related settings:

* No issues found in the Registry.

Resetting .EXE, .COM, & .BAT associations in the Windows Registry.

Performing miscellaneous checks:

* No issues found.

Checking Windows Service Integrity:

* RpcSs => %SystemRoot%\system32\svchost.exe -k rpcss [Incorrect ImagePath]

Searching for Missing Digital Signatures:

* No issues found.

Checking HOSTS File:

* HOSTS file entries found:

127.0.0.1 localhost

Program finished at: 06/17/2013 06:37:29 AM
Execution time: 0 hours(s), 0 minute(s), and 48 seconds(s)




Ran TDSkiller, no log was generated, however no threats were found.
Hi Lewg,

Disk Defragmenter for XP
  • Open My Computer.
  • Right-click the local disk volume that you want to defragment, and then click Properties.
  • On the Tools tab, click Defragment Now.
  • Click Defragment.
= = = = = = = = = = = = = = = = = = = =

Re-run rKill. (no need to post the log)

= = = = = = = = = = = = = = = = = = = =

Once again delete the copy of RogueKiller you have and download a fresh copy on another machine to a flash drive and transfer it to the infected computer and run a new scan.

= = = = = = = = = = = = = = = = = = = =

In your next post please provide the following:

  • RogueKiller log
  • How is the computer running at the moment?
Well, RK finally worked and left this file. C: has been defraged,

I left RK in my taskbar so, if you would like for me to hit the delete button on RK to dump the two key's found in the registery…..
HJ POL, and HJ DESK.

Let me know.

RogueKiller V8.6.1 [Jun 17 2013] by Tigzy
mail : tigzyRKgmailcom
Feedback : http://www.geekstogo.com/forum/files/file/413-roguekiller/
Website : http://tigzy.geekstogo.com/roguekiller.php
Blog : http://tigzyrk.blogspot.com/

Operating System : Windows XP (5.1.2600 Service Pack 3) 32 bits version
Started in : Normal mode
User : Lew [Admin rights]
Mode : Scan – Date : 06/17/2013 12:41:21
| ARK || FAK || MBR |

¤¤¤ Bad processes : 3 ¤¤¤
[SUSP PATH][DLL] explorer.exe – C:\Documents and Settings\Lew\My Documents\SASSEH.DLL [x] ->
[SUSP PATH][WHITELIST] explorer.exe – C:\Documents and Settings\Lew\My Documents\SASSEH.DLL [x] ->
[SUSP PATH] SASCore.exe – C:\Documents and Settings\Lew\My Documents\SASCore.exe [-] -> KILLED [TermProc]

¤¤¤ Registry Entries : 2 ¤¤¤
[HJ POL] HKLM\[…]\System : DisableRegistryTools (0) -> FOUND
[HJ DESK] HKLM\[…]\NewStartPanel : {20D04FE0-3AEA-1069-A2D8-08002B30309D} (1) -> FOUND

¤¤¤ Scheduled tasks : 0 ¤¤¤

¤¤¤ Startup Entries : 0 ¤¤¤

¤¤¤ Web browsers : 0 ¤¤¤

¤¤¤ Particular Files / Folders: ¤¤¤

¤¤¤ Driver : [LOADED] ¤¤¤

¤¤¤ External Hives: ¤¤¤

¤¤¤ Infection : ¤¤¤

¤¤¤ HOSTS File: ¤¤¤
–> %SystemRoot%\System32\drivers\etc\hosts


127.0.0.1 localhost


¤¤¤ MBR Check: ¤¤¤

+++++ PhysicalDrive0: WDC WD5000AAKX-001CA0 +++++
— User —
[MBR] 1e47df03fb239c0e2124f4f9c9035d58
[BSP] e4bf6df3666d1f680d9b89a0238c06ac : Windows XP MBR Code
Partition table:
0 - [ACTIVE] NTFS (0x07) [VISIBLE] Offset (sectors): 63 | Size: 476929 Mo
User = LL1 … OK!
User = LL2 … OK!

Finished : << RKreport[0]_S_06172013_124121.txt >>
Hi Lewg,

1. Re-run RogueKiller

Vista, Windows 7 & 8 – Right click and select "Run as Administrator"
  • Quit all programs
  • Wait until Prescan has finished …
  • Click on Scan.
  • After the scan has completed click on the Registry tab
  • Wait until the Status box shows "Scan Finished"
  • Click the Delete button
  • Wait until the Status box shows "Deleting Finished"
  • Click the Report button, save the report to your desktop
=========================

2. Re- run AdwCleaner

It should be on your desktop

Vista, Windows 7 & 8 – Right click and select "Run as Administrator".
  • Run AdwCleaner and select Delete
  • Once done it will ask to reboot, allow the reboot
  • On reboot a log will be produced, please attach the content of the log to your next reply
=========================

3. Junkware Removal Tool

[external image: Posted Image] Please download Junkware Removal Tool to your desktop.

Vista, Windows 7 & 8 – Right click and select "Run as Administrator".
  • Shut down your protection software now to avoid potential conflicts.
  • The tool will open and start scanning your system.
  • Please be patient as this can take a while to complete depending on your system's specifications.
  • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
  • Post the contents of JRT.txt into your next message.
=========================

In your next post please provide the following:
  • RKreport.txt
  • AdwCleaner.txt
  • JRT.txt
  • How is the computer running?

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI