This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

virus protection and firewall wont work [Closed]

14 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hello,

I am helping my spouse with his computer and i noticed that the windows essential virus protection and the armor firewall weren't at the bottom of the screen and i can't turn them on and i can't reinstall them. i get error codes. please advise. i did run malwarebytes this am, found a few things to remove, but still can't get any virus protection to work. not sure how long they have been turned off.

OTL logfile created on: 9/29/2013 1:20:58 PM - Run 6
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Documents and Settings\Owner.PETE-05CK9PEMS6\Desktop
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

638.00 Mb Total Physical Memory | 334.94 Mb Available Physical Memory | 52.50% Memory free
1.52 Gb Paging File | 1.28 Gb Available in Paging File | 84.05% Paging File free
Paging file location(s): C:\pagefile.sys 960 1920 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 37.21 Gb Total Space | 22.33 Gb Free Space | 60.02% Space Free | Partition Type: NTFS

Computer Name: PETE-05CK9PEMS6 | User Name: Owner | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Documents and Settings\Owner.PETE-05CK9PEMS6\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\MyTurboPC.com\MyTurboPC\mtpc.exe (MyTurboPC.com)
PRC - C:\Program Files\Norton Security Suite\Engine\20.2.0.19\ccsvchst.exe (Symantec Corporation)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)


========== Modules (No Company Name) ==========

MOD - C:\Program Files\MyTurboPC.com\MyTurboPC\Utility.pxt ()
MOD - C:\Program Files\MyTurboPC.com\MyTurboPC\CommonLoggingExtension.pxt ()
MOD - C:\Program Files\MyTurboPC.com\MyTurboPC\CommonSpecialist.pxt ()
MOD - C:\Program Files\MyTurboPC.com\MyTurboPC\RegHookSpecialist.pxt ()
MOD - C:\Program Files\MyTurboPC.com\MyTurboPC\ExtensionManager.dll ()
MOD - C:\Program Files\IObit\Advanced SystemCare 5\ASCv5ExtMenu.dll ()
MOD - C:\Program Files\MyTurboPC.com\MyTurboPC\7ZipDLL.dll ()
MOD - C:\Program Files\MyTurboPC.com\MyTurboPC\LiteUnzip.dll ()
MOD - C:\Program Files\MyTurboPC.com\MyTurboPC\LiteZip.dll ()
MOD - C:\Program Files\SpywareGuard\spywareguard.dll ()


========== Services (SafeList) ==========

SRV - (winmgmt) – C:\DOCUME~1\OWNER~2.PET\5820406.dll File not found
SRV - (Lavasoft Ad-Aware Service) – C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe File not found
SRV - (HidServ) – %SystemRoot%\System32\hidserv.dll File not found
SRV - (etadpug) – C:\Program Files\Google\Desktop\Install\{827827d9-f288-6f9a-9c86-56eb7c983fff}\ \ \ﯹ๛\{827827d9-f288-6f9a-9c86-56eb7c983fff}\GoogleUpdate.exe < [WARNING: C:\Program Files\Google\Desktop\Install\{827827d9-f288-6f9a-9c86-56eb7c983fff}\ \ \???\{827827d9-f288-6f9a-9c86-56eb7c983fff}\GoogleUpdate.exe <] File not found
SRV - (AppMgmt) – %SystemRoot%\System32\appmgmts.dll File not found
SRV - (AdobeFlashPlayerUpdateSvc) – C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe (Adobe Systems Incorporated)
SRV - (MsMpSvc) – c:\Program Files\Microsoft Security Client\MsMpEng.exe ()
SRV - (JavaQuickStarterService) – C:\Program Files\Java\jre7\bin\jqs.exe (Oracle Corporation)
SRV - (N360) – C:\Program Files\Norton Security Suite\Engine\20.2.0.19\ccSvcHst.exe (Symantec Corporation)
SRV - (SvcOnlineArmor) – C:\Program Files\Online Armor\oasrv.exe (Emsisoft GmbH)
SRV - (OAcat) – C:\Program Files\Online Armor\oacat.exe (Emsisoft GmbH)
SRV - (AdvancedSystemCareService5) – C:\Program Files\IObit\Advanced SystemCare 5\ASCService.exe (IObit)
SRV - (Bjmcmng) – C:\Program Files\Canon\BJCard\Bjmcmng.exe (CANON INC.)


========== Driver Services (SafeList) ==========

DRV - (WDICA) – File not found
DRV - (PDRFRAME) – File not found
DRV - (PDRELI) – File not found
DRV - (PDFRAME) – File not found
DRV - (PDCOMP) – File not found
DRV - (PCIDump) – File not found
DRV - (NAVEX15) – C:\Documents and Settings\All Users.WINDOWS\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_20.1.0.24\Definitions\VirusDefs\20130331.016\NAVEX15.SYS File not found
DRV - (NAVENG) – C:\Documents and Settings\All Users.WINDOWS\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_20.1.0.24\Definitions\VirusDefs\20130331.016\NAVENG.SYS File not found
DRV - (lbrtfdc) – File not found
DRV - (IDSxpx86) – C:\Documents and Settings\All Users.WINDOWS\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_20.1.0.24\Definitions\IPSDefs\20130329.001\IDSxpx86.sys File not found
DRV - (i2omgmt) – File not found
DRV - (Changer) – File not found
DRV - (catchme) – C:\ComboFix\catchme.sys File not found
DRV - (BHDrvx86) – C:\Documents and Settings\All Users.WINDOWS\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_20.1.0.24\Definitions\BASHDefs\20130322.001\BHDrvx86.sys File not found
DRV - (5613) – C:\DOCUME~1\OWNER~2.PET\LOCALS~1\Temp\5613.sys File not found
DRV - (eeCtrl) – C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys (Symantec Corporation)
DRV - (SymEvent) – C:\WINDOWS\system32\drivers\SYMEVENT.SYS (Symantec Corporation)
DRV - (SRTSP) – C:\WINDOWS\system32\drivers\N360\1402000.013\srtsp.sys (Symantec Corporation)
DRV - (SymEFA) – C:\WINDOWS\system32\drivers\N360\1402000.013\symefa.sys (Symantec Corporation)
DRV - (SymDS) – C:\WINDOWS\system32\drivers\N360\1402000.013\symds.sys (Symantec Corporation)
DRV - (ccSet_N360) – C:\WINDOWS\system32\drivers\N360\1402000.013\ccsetx86.sys (Symantec Corporation)
DRV - (oahlpXX) – C:\WINDOWS\system32\drivers\oahlp32.sys ()
DRV - (OAnet) – C:\WINDOWS\system32\drivers\OAnet.sys (Emsisoft)
DRV - (OAmon) – C:\WINDOWS\system32\drivers\OAmon.sys (Emsisoft)
DRV - (OADevice) – C:\WINDOWS\system32\drivers\OADriver.sys ()
DRV - (SymIRON) – C:\WINDOWS\system32\drivers\N360\1402000.013\ironx86.sys (Symantec Corporation)
DRV - (SYMTDI) – C:\WINDOWS\system32\drivers\N360\1402000.013\symtdi.sys (Symantec Corporation)
DRV - (SRTSPX) – C:\WINDOWS\system32\drivers\N360\1402000.013\srtspx.sys (Symantec Corporation)
DRV - (GIDv2) – C:\WINDOWS\System32\drivers\gidv2.sys (StrikeForce Technologies, Inc.)
DRV - (mfehidk) – C:\WINDOWS\system32\drivers\mfehidk.sys (McAfee, Inc.)
DRV - (mfeavfk) – C:\WINDOWS\system32\drivers\mfeavfk.sys (McAfee, Inc.)
DRV - (mfesmfk) – C:\WINDOWS\system32\drivers\mfesmfk.sys (McAfee, Inc.)
DRV - (mfebopk) – C:\WINDOWS\system32\drivers\mfebopk.sys (McAfee, Inc.)
DRV - (mferkdk) – C:\WINDOWS\system32\drivers\mferkdk.sys (McAfee, Inc.)
DRV - (Lbd) – C:\WINDOWS\system32\drivers\Lbd.sys (Lavasoft AB)
DRV - (LMouFlt2) – C:\WINDOWS\system32\drivers\LMouFlt2.Sys (Logitech, Inc.)
DRV - (L8042pr2) – C:\WINDOWS\system32\drivers\L8042pr2.Sys (Logitech, Inc.)
DRV - (PRISM_A02) – C:\WINDOWS\system32\drivers\PRISMA02.sys (GlobespanVirata, Inc.)
DRV - (bcm4sbxp) – C:\WINDOWS\system32\drivers\bcm4sbxp.sys (Broadcom Corporation)
DRV - (OMCI) – C:\WINDOWS\system32\drivers\omci.sys (Dell Computer Corporation)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\..\SearchScopes,DefaultScope =
IE - HKLM\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 1
IE - HKLM\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local;
IE - HKLM\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = http=localhost:7171

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
IE - HKCU\..\SearchScopes,DefaultScope = {AFBCB7E0-F91A-4951-9F31-58FEE57A25C4}
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..browser.search.defaultenginename: ""
FF - prefs.js..browser.startup.homepage: "http://yahoo.com/"
FF - prefs.js..extensions.enabledAddons: {2D3F3651-74B9-4795-BDEC-6DA2F431CB62}:2012.5.8.4
FF - prefs.js..extensions.enabledAddons: {BBDA0591-3099-440a-AA10-41764D9DB4DB}:11.1.1.5 - 3
FF - user.js - File not found

FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32_11_8_800_168.dll ()
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.21.2: C:\WINDOWS\system32\npDeployJava1.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.21.2: C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{BBDA0591-3099-440a-AA10-41764D9DB4DB}: C:\Documents and Settings\All Users.WINDOWS\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_20.1.0.24\IPSFFPlgn\
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{2D3F3651-74B9-4795-BDEC-6DA2F431CB62}: C:\Documents and Settings\All Users.WINDOWS\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_20.1.0.24\coFFPlgn\

[2010/07/11 14:16:14 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Owner.PETE-05CK9PEMS6\Application Data\Mozilla\Extensions
[2010/07/11 14:16:14 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Owner.PETE-05CK9PEMS6\Application Data\Mozilla\Extensions\[removed]
[2013/04/02 16:18:45 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Owner.PETE-05CK9PEMS6\Application Data\Mozilla\Firefox\Profiles\qjys52r7.default\extensions
[2012/10/16 11:33:24 | 000,000,000 | —D | M] (Yahoo! Toolbar) – C:\Documents and Settings\Owner.PETE-05CK9PEMS6\Application Data\Mozilla\Firefox\Profiles\qjys52r7.default\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1}
[2013/03/17 18:20:17 | 000,000,000 | —D | M] (Advanced SystemCare Surfing Protection) – C:\Documents and Settings\Owner.PETE-05CK9PEMS6\Application Data\Mozilla\Firefox\Profiles\qjys52r7.default\extensions\[removed]
[2013/04/23 20:17:29 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Owner.PETE-05CK9PEMS6\Application Data\Mozilla\Firefox\Profiles\qjys52r7.default\extensions\idvaultaddin@whitesky
[2012/10/13 09:27:40 | 000,020,591 | —- | M] () (No name found) – C:\Documents and Settings\Owner.PETE-05CK9PEMS6\Application Data\Mozilla\Firefox\Profiles\qjys52r7.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}.xpi
File not found (No name found) – C:\DOCUMENTS AND SETTINGS\ALL USERS.WINDOWS\APPLICATION DATA\NORTON\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_6.0.0.145\COFFPLGN
File not found (No name found) – C:\DOCUMENTS AND SETTINGS\ALL USERS.WINDOWS\APPLICATION DATA\NORTON\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_6.0.0.145\IPSFFPLGN

O1 HOSTS File: ([2013/09/24 17:55:20 | 000,001,397 | RHS- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O1 - Hosts: 199.193.118.246 www.google-analytics.com.
O1 - Hosts: 199.193.118.246 connect.facebook.net.
O1 - Hosts: 199.193.118.246 platform.twitter.com.
O1 - Hosts: 93.115.241.27 www.google-analytics.com.
O1 - Hosts: 93.115.241.27 connect.facebook.net.
O1 - Hosts: 93.115.241.27 platform.twitter.com.
O2 - BHO: (SpywareGuardDLBLOCK.CBrowserHelper) - {4A368E80-174F-4872-96B5-0B27DDD11DB2} - C:\Program Files\SpywareGuard\dlprotect.dll ()
O2 - BHO: (Norton Identity Protection) - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files\Norton Security Suite\Engine\20.2.0.19\coieplg.dll (Symantec Corporation)
O2 - BHO: (Norton Vulnerability Protection) - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files\Norton Security Suite\Engine\20.2.0.19\ips\ipsbho.dll (Symantec Corporation)
O2 - BHO: (Java™ Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
O2 - BHO: (WOT Helper) - {C920E44A-7F78-4E64-BDD7-A57026E7FEB7} - C:\Program Files\WOT\WOT.dll ()
O2 - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O3 - HKLM\..\Toolbar: (WOT) - {71576546-354D-41c9-AAE8-31F2EC22BF0D} - C:\Program Files\WOT\WOT.dll ()
O3 - HKLM\..\Toolbar: (Norton Toolbar) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Norton Security Suite\Engine\20.2.0.19\coieplg.dll (Symantec Corporation)
O3 - HKCU\..\Toolbar\WebBrowser: (WOT) - {71576546-354D-41C9-AAE8-31F2EC22BF0D} - C:\Program Files\WOT\WOT.dll ()
O3 - HKCU\..\Toolbar\WebBrowser: (Norton Toolbar) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Norton Security Suite\Engine\20.2.0.19\coieplg.dll (Symantec Corporation)
O4 - HKCU..\Run: [Google Update] Reg Error: Value error. File not found
O4 - HKLM..\RunOnce: [AvgUninstallURL] C:\WINDOWS\System32\cmd.exe (Microsoft Corporation)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O16 - DPF: {01012101-5E80-11D8-9E86-0007E96C65AE} http://www.comcastsupport.com/oneclickfix/tgctlsr.cab (SupportSoft Script Runner Class)
O16 - DPF: {31435657-9980-0010-8000-00AA00389B71} http://download.microsoft.com/download/e/2…78f/wvc1dmo.cab (Reg Error: Key error.)
O16 - DPF: {33564D57-0000-0010-8000-00AA00389B71} http://download.microsoft.com/download/F/6…922/wmv9VCM.CAB (Reg Error: Key error.)
O16 - DPF: {33564D57-9980-0010-8000-00AA00389B71} http://download.microsoft.com/download/D/0…D0C/wmv9dmo.cab (Reg Error: Key error.)
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} http://update.microsoft.com/windowsupdate/…b?1136593632451 (WUWebControl Class)
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} http://download.eset.com/special/eos-beta/OnlineScanner.cab (Reg Error: Key error.)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 10.21.2)
O16 - DPF: {CAFEEFAC-0016-0000-0030-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_30)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 10.21.2)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab (Shockwave Flash Object)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 75.75.75.75 75.75.76.76
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{45D6A31F-96C2-4D92-B3F2-4ADBAE67D96B}: DhcpNameServer = [removed] [removed]
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{5479463A-91E8-4138-B3CE-765B64CB7D71}: DhcpNameServer = 75.75.75.75 75.75.76.76
O18 - Protocol\Handler\wot {C2A44D6B-CB9F-4663-88A6-DF2F26E4D952} - C:\Program Files\WOT\WOT.dll ()
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) - C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O20 - Winlogon\Notify\GIDLogonXP: DllName - (GIDLogonXP.dll) - C:\WINDOWS\System32\GIDLogonXP.dll (StrikeForce Technologies Inc)
O20 - Winlogon\Notify\igfxcui: DllName - (igfxsrvc.dll) - C:\WINDOWS\System32\igfxsrvc.dll (Intel Corporation)
O24 - Desktop WallPaper: C:\Documents and Settings\Owner.PETE-05CK9PEMS6\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Owner.PETE-05CK9PEMS6\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O28 - HKLM ShellExecuteHooks: {4F07DA45-8170-4859-9B5F-037EF2970034} - C:\Program Files\Online Armor\oaevent.dll (Emsisoft GmbH)
O28 - HKLM ShellExecuteHooks: {81559C35-8464-49F7-BB0E-07A383BEF910} - C:\Program Files\SpywareGuard\spywareguard.dll ()
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2005/12/31 15:30:52 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O34 - HKLM BootExecute: (lsdelete)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = ComFile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)

NetSvcs: 6to4 - File not found
NetSvcs: AppMgmt - %SystemRoot%\System32\appmgmts.dll File not found
NetSvcs: HidServ - %SystemRoot%\System32\hidserv.dll File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: Remoteaccess - File not found
NetSvcs: Sharedaccess - File not found
NetSvcs: WmdmPmSp - File not found
NetSvcs: winmgmt - C:\DOCUME~1\OWNER~2.PET\5820406.dll File not found

Drivers32: msacm.iac2 - C:\WINDOWS\System32\iac25_32.ax (Intel Corporation)
Drivers32: msacm.l3acm - C:\WINDOWS\system32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.sl_anet - C:\WINDOWS\System32\sl_anet.acm (Sipro Lab Telecom Inc.)
Drivers32: msacm.trspch - C:\WINDOWS\System32\tssoft32.acm (DSP GROUP, INC.)
Drivers32: vidc.cvid - C:\WINDOWS\System32\iccvid.dll (Radius Inc.)
Drivers32: vidc.iv31 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv32 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv41 - C:\WINDOWS\System32\ir41_32.ax (Intel Corporation)
Drivers32: vidc.iv50 - C:\WINDOWS\System32\ir50_32.dll (Intel Corporation)
Drivers32: VIDC.WMV3 - C:\WINDOWS\System32\wmv9vcm.dll (Microsoft Corporation)

CREATERESTOREPOINT
System Restore Service not available.

========== Files/Folders - Created Within 30 Days ==========

[2013/09/29 13:09:03 | 000,000,000 | —D | C] – C:\Documents and Settings\Owner.PETE-05CK9PEMS6\Application Data\DriverCure
[2013/09/29 13:09:02 | 000,000,000 | —D | C] – C:\Documents and Settings\Owner.PETE-05CK9PEMS6\Application Data\MyTurboPC.com
[2013/09/29 13:07:52 | 000,000,000 | —D | C] – C:\Documents and Settings\Owner.PETE-05CK9PEMS6\Start Menu\Programs\MyTurboPC.com
[2013/09/29 13:07:40 | 000,000,000 | —D | C] – C:\Program Files\Common Files\MyTurboPC.com
[2013/09/29 13:07:35 | 000,000,000 | —D | C] – C:\Program Files\MyTurboPC.com
[2013/09/29 13:07:35 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users.WINDOWS\Application Data\MyTurboPC.com
[2013/09/24 16:53:37 | 000,000,000 | —D | C] – C:\Program Files\Google
[2013/09/13 12:54:15 | 003,723,656 | —- | C] (Adobe Systems Incorporated) – C:\WINDOWS\System32\FlashPlayerInstaller.exe
[2 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2013/09/29 13:18:26 | 000,602,112 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Owner.PETE-05CK9PEMS6\Desktop\OTL.exe
[2013/09/29 13:13:02 | 000,002,206 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2013/09/29 13:11:54 | 000,000,268 | —- | M] () – C:\WINDOWS\tasks\ASC6_PerformanceMonitor.job
[2013/09/29 13:11:47 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2013/09/29 13:10:08 | 000,000,452 | —- | M] () – C:\WINDOWS\tasks\MyTurboPC.com Registration3.job
[2013/09/29 13:07:52 | 000,000,813 | —- | M] () – C:\Documents and Settings\Owner.PETE-05CK9PEMS6\Desktop\MyTurboPC.lnk
[2013/09/29 13:07:52 | 000,000,416 | —- | M] () – C:\WINDOWS\tasks\MyTurboPC.com Update3.job
[2013/09/29 13:07:50 | 000,000,370 | —- | M] () – C:\WINDOWS\tasks\MyTurboPC.job
[2013/09/29 12:54:15 | 000,000,830 | —- | M] () – C:\WINDOWS\tasks\Adobe Flash Player Updater.job
[2013/09/29 12:48:31 | 000,001,954 | —- | M] () – C:\WINDOWS\epplauncher.mif
[2013/09/29 08:30:31 | 011,233,112 | —- | M] (Microsoft Corporation) – C:\Documents and Settings\Owner.PETE-05CK9PEMS6\Desktop\mseinstall.exe
[2013/09/29 04:33:38 | 000,000,384 | -H– | M] () – C:\WINDOWS\tasks\Microsoft Antimalware Scheduled Scan.job
[2013/09/29 01:39:15 | 000,000,422 | -H– | M] () – C:\WINDOWS\tasks\User_Feed_Synchronization-{96E858C2-BB80-4CA6-A945-5D7F401AA939}.job
[2013/09/27 21:12:58 | 000,000,000 | —- | M] () – C:\Documents and Settings\Owner.PETE-05CK9PEMS6\Desktop\image1.jpeg
[2013/09/27 21:11:50 | 000,000,000 | —- | M] () – C:\Documents and Settings\Owner.PETE-05CK9PEMS6\image (8).jpeg
[2013/09/27 21:11:15 | 000,000,000 | —- | M] () – C:\Documents and Settings\Owner.PETE-05CK9PEMS6\image (7).jpeg
[2013/09/27 21:11:03 | 000,000,000 | —- | M] () – C:\Documents and Settings\Owner.PETE-05CK9PEMS6\image (6).jpeg
[2013/09/27 21:10:56 | 000,000,000 | —- | M] () – C:\Documents and Settings\Owner.PETE-05CK9PEMS6\image (5).jpeg
[2013/09/27 21:08:47 | 000,000,000 | —- | M] () – C:\Documents and Settings\Owner.PETE-05CK9PEMS6\image (4).jpeg
[2013/09/27 21:08:43 | 000,000,000 | —- | M] () – C:\Documents and Settings\Owner.PETE-05CK9PEMS6\image (3).jpeg
[2013/09/27 21:08:37 | 000,000,000 | —- | M] () – C:\Documents and Settings\Owner.PETE-05CK9PEMS6\image (2).jpeg
[2013/09/27 21:08:33 | 000,000,000 | —- | M] () – C:\Documents and Settings\Owner.PETE-05CK9PEMS6\image (1).jpeg
[2013/09/27 21:08:20 | 000,000,000 | —- | M] () – C:\Documents and Settings\Owner.PETE-05CK9PEMS6\image.jpeg
[2013/09/24 17:55:20 | 000,001,397 | RHS- | M] () – C:\WINDOWS\System32\drivers\etc\hosts
[2013/09/24 16:55:03 | 000,062,720 | —- | M] () – C:\WINDOWS\System32\drivers\b660883d10b7f0b1.sys
[2013/09/19 18:58:03 | 000,692,616 | —- | M] (Adobe Systems Incorporated) – C:\WINDOWS\System32\FlashPlayerApp.exe
[2013/09/19 18:58:02 | 000,071,048 | —- | M] (Adobe Systems Incorporated) – C:\WINDOWS\System32\FlashPlayerCPLApp.cpl
[2013/09/19 18:57:23 | 003,723,656 | —- | M] (Adobe Systems Incorporated) – C:\WINDOWS\System32\FlashPlayerInstaller.exe
[2013/09/13 03:33:09 | 000,095,072 | —- | M] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2013/09/13 03:13:48 | 000,001,374 | —- | M] () – C:\WINDOWS\imsins.BAK
[2 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]

========== Files Created - No Company Name ==========

[2013/09/29 13:10:07 | 000,000,452 | —- | C] () – C:\WINDOWS\tasks\MyTurboPC.com Registration3.job
[2013/09/29 13:07:51 | 000,000,813 | —- | C] () – C:\Documents and Settings\Owner.PETE-05CK9PEMS6\Desktop\MyTurboPC.lnk
[2013/09/29 13:07:51 | 000,000,416 | —- | C] () – C:\WINDOWS\tasks\MyTurboPC.com Update3.job
[2013/09/29 13:07:49 | 000,000,370 | —- | C] () – C:\WINDOWS\tasks\MyTurboPC.job
[2013/09/27 21:12:58 | 000,000,000 | —- | C] () – C:\Documents and Settings\Owner.PETE-05CK9PEMS6\Desktop\image1.jpeg
[2013/09/27 21:11:50 | 000,000,000 | —- | C] () – C:\Documents and Settings\Owner.PETE-05CK9PEMS6\image (8).jpeg
[2013/09/27 21:11:15 | 000,000,000 | —- | C] () – C:\Documents and Settings\Owner.PETE-05CK9PEMS6\image (7).jpeg
[2013/09/27 21:11:03 | 000,000,000 | —- | C] () – C:\Documents and Settings\Owner.PETE-05CK9PEMS6\image (6).jpeg
[2013/09/27 21:10:56 | 000,000,000 | —- | C] () – C:\Documents and Settings\Owner.PETE-05CK9PEMS6\image (5).jpeg
[2013/09/27 21:08:47 | 000,000,000 | —- | C] () – C:\Documents and Settings\Owner.PETE-05CK9PEMS6\image (4).jpeg
[2013/09/27 21:08:43 | 000,000,000 | —- | C] () – C:\Documents and Settings\Owner.PETE-05CK9PEMS6\image (3).jpeg
[2013/09/27 21:08:37 | 000,000,000 | —- | C] () – C:\Documents and Settings\Owner.PETE-05CK9PEMS6\image (2).jpeg
[2013/09/27 21:08:33 | 000,000,000 | —- | C] () – C:\Documents and Settings\Owner.PETE-05CK9PEMS6\image (1).jpeg
[2013/09/27 21:08:20 | 000,000,000 | —- | C] () – C:\Documents and Settings\Owner.PETE-05CK9PEMS6\image.jpeg
[2013/09/24 16:55:03 | 000,062,720 | —- | C] () – C:\WINDOWS\System32\drivers\b660883d10b7f0b1.sys
[2013/05/31 08:28:26 | 000,044,992 | —- | C] () – C:\WINDOWS\System32\drivers\oahlp32.sys
[2013/05/31 08:28:26 | 000,031,920 | —- | C] () – C:\WINDOWS\System32\drivers\OAnet.sys
[2013/05/31 08:28:26 | 000,027,648 | —- | C] () – C:\WINDOWS\System32\drivers\OAmon.sys
[2013/05/31 08:28:25 | 000,208,320 | —- | C] () – C:\WINDOWS\System32\drivers\OADriver.sys
[2013/04/19 12:26:14 | 095,023,320 | —- | C] () – C:\Documents and Settings\All Users.WINDOWS\Application Data\l04z6.pad
[2013/03/17 19:35:51 | 000,142,496 | —- | C] () – C:\WINDOWS\System32\drivers\SYMEVENT.SYS
[2013/02/21 06:24:49 | 095,023,320 | —- | C] () – C:\Documents and Settings\All Users.WINDOWS\Application Data\6040285.pad
[2012/10/18 19:51:10 | 000,256,000 | —- | C] () – C:\WINDOWS\PEV.exe
[2012/10/18 19:51:10 | 000,208,896 | —- | C] () – C:\WINDOWS\MBR.exe
[2012/10/18 19:51:10 | 000,098,816 | —- | C] () – C:\WINDOWS\sed.exe
[2012/10/18 19:51:10 | 000,080,412 | —- | C] () – C:\WINDOWS\grep.exe
[2012/10/18 19:51:10 | 000,068,096 | —- | C] () – C:\WINDOWS\zip.exe
[2012/07/04 14:40:15 | 000,025,232 | —- | C] () – C:\WINDOWS\System32\drivers\gidv2.sys
[2012/06/13 03:05:49 | 000,064,512 | —- | C] () – C:\WINDOWS\System32\drivers\serial.sys
[2012/02/15 07:24:01 | 000,003,072 | —- | C] () – C:\WINDOWS\System32\iacenc.dll
[2009/02/06 19:55:45 | 000,076,288 | —- | C] () – C:\Documents and Settings\Owner.PETE-05CK9PEMS6\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini

========== ZeroAccess Check ==========

[2012/07/04 14:15:49 | 000,000,227 | RHS- | M] () – C:\WINDOWS\assembly\Desktop.ini

[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]

[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shdocvw.dll – [2008/04/13 20:12:05 | 001,499,136 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll – [2009/02/09 08:10:48 | 000,473,600 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
"" = %systemroot%\system32\wbem\wbemess.dll – [2008/04/13 20:12:08 | 000,273,920 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Both

========== LOP Check ==========

[2012/06/13 03:26:33 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users.WINDOWS\Application Data\AVG2012
[2010/10/16 09:16:02 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users.WINDOWS\Application Data\avg9
[2010/10/16 09:30:31 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users.WINDOWS\Application Data\Common Files
[2013/03/17 18:20:17 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users.WINDOWS\Application Data\IObit
[2012/07/04 14:46:00 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users.WINDOWS\Application Data\IsolatedStorage
[2009/01/23 21:15:39 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users.WINDOWS\Application Data\MailFrontier
[2013/09/29 12:44:08 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users.WINDOWS\Application Data\MFAData
[2013/09/29 13:07:35 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users.WINDOWS\Application Data\MyTurboPC.com
[2013/05/31 08:48:06 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users.WINDOWS\Application Data\OnlineArmor
[2013/04/02 18:09:12 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users.WINDOWS\Application Data\Privacyware
[2012/07/04 14:12:21 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users.WINDOWS\Application Data\White Sky, Inc
[2009/06/06 08:11:58 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users.WINDOWS\Application Data\WinZip
[2010/06/11 08:52:08 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner.PETE-05CK9PEMS6\Application Data\Auslogics
[2011/09/24 13:20:31 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner.PETE-05CK9PEMS6\Application Data\AVG2012
[2013/09/29 13:09:03 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner.PETE-05CK9PEMS6\Application Data\DriverCure
[2013/04/02 16:45:40 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner.PETE-05CK9PEMS6\Application Data\ID Vault
[2012/06/06 15:14:05 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner.PETE-05CK9PEMS6\Application Data\Incredibar.com
[2013/03/17 16:36:04 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner.PETE-05CK9PEMS6\Application Data\IObit
[2006/03/19 19:48:06 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner.PETE-05CK9PEMS6\Application Data\Musicmatch
[2013/09/29 13:09:02 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner.PETE-05CK9PEMS6\Application Data\MyTurboPC.com
[2013/05/31 08:29:59 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner.PETE-05CK9PEMS6\Application Data\OnlineArmor
[2012/03/06 21:14:32 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner.PETE-05CK9PEMS6\Application Data\TweakNow PowerPack 2011

========== Purity Check ==========



========== Custom Scans ==========

< %USERPROFILE%\..|smtmp;true;true;true /FP >

< %temp%\smtmp\*.* /s > >

< MD5 for: EXPLORER.EXE >
[2008/04/13 20:12:19 | 001,033,728 | —- | M] (Microsoft Corporation) MD5=12896823FB95BFB3DC9B46BCAEDC9923 – C:\WINDOWS\ERDNT\cache\explorer.exe
[2008/04/13 20:12:19 | 001,033,728 | —- | M] (Microsoft Corporation) MD5=12896823FB95BFB3DC9B46BCAEDC9923 – C:\WINDOWS\explorer.exe
[2008/04/13 20:12:19 | 001,033,728 | —- | M] (Microsoft Corporation) MD5=12896823FB95BFB3DC9B46BCAEDC9923 – C:\WINDOWS\ServicePackFiles\i386\explorer.exe
[2007/06/13 07:26:03 | 001,033,216 | —- | M] (Microsoft Corporation) MD5=7712DF0CDDE3A5AC89843E61CD5B3658 – C:\WINDOWS\$hf_mig$\KB938828\SP2QFE\explorer.exe
[2007/06/13 06:23:07 | 001,033,216 | —- | M] (Microsoft Corporation) MD5=97BD6515465659FF8F3B7BE375B2EA87 – C:\WINDOWS\$NtServicePackUninstall$\explorer.exe
[2004/08/04 03:56:49 | 001,032,192 | —- | M] (Microsoft Corporation) MD5=A0732187050030AE399B241436565E64 – C:\WINDOWS\$NtUninstallKB938828$\explorer.exe

< MD5 for: EXPLORER.EXE.000 >
[2004/08/04 03:56:49 | 001,032,192 | —- | M] (Microsoft Corporation) MD5=A0732187050030AE399B241436565E64 – C:\WINDOWS\$NtServicePackUninstall$\explorer.exe.000

< MD5 for: EXPLORER.SCF >
[2003/07/16 16:28:12 | 000,000,080 | —- | M] () MD5=A3975A7D2C98B30A2AE010754FFB9392 – C:\WINDOWS\explorer.scf

< MD5 for: IEXPLORE.CHM >
[2009/02/21 01:21:24 | 000,529,818 | —- | M] () MD5=1435F4731719DF5F57D17DC38196245D – C:\WINDOWS\Help\iexplore.chm
[2004/07/17 14:40:16 | 000,204,810 | —- | M] () MD5=60858526AAD1CC55F5F0055B8E3B66FE – C:\WINDOWS\ie7\iexplore.chm
[2004/07/17 14:40:16 | 000,204,810 | —- | M] () MD5=60858526AAD1CC55F5F0055B8E3B66FE – C:\WINDOWS\ServicePackFiles\i386\iexplore.chm
[2006/09/01 08:43:50 | 000,503,758 | —- | M] () MD5=652E46500C149D1DC948BF9CEA8C4933 – C:\WINDOWS\ie8\iexplore.chm

< MD5 for: IEXPLORE.CHW >
[2009/05/31 17:23:40 | 000,153,185 | —- | M] () MD5=00B4E1AA5457FC749D8F6D38DDAF0A15 – C:\WINDOWS\Help\iexplore.chw

< MD5 for: IEXPLORE.EXE >
[2008/12/19 01:25:25 | 000,634,024 | —- | M] (Microsoft Corporation) MD5=030D78FE84A086ED376EFCBD2D72C522 – C:\WINDOWS\ie7updates\KB963027-IE7\iexplore.exe
[2008/10/15 02:34:58 | 000,633,632 | —- | M] (Microsoft Corporation) MD5=056C927CF7207857E8B34F7A8FFD9B9E – C:\WINDOWS\$hf_mig$\KB958215-IE7\SP2QFE\iexplore.exe
[2007/04/24 10:26:26 | 000,625,152 | —- | M] (Microsoft Corporation) MD5=10BDB55982586A432A3951EB19A26009 – C:\WINDOWS\ie7updates\KB937143-IE7\iexplore.exe
[2008/12/19 01:25:30 | 000,634,024 | —- | M] (Microsoft Corporation) MD5=15E8A89499741D5CF59A9CF6463A4339 – C:\WINDOWS\$hf_mig$\KB961260-IE7\SP2QFE\iexplore.exe
[2008/04/22 04:02:46 | 000,625,664 | —- | M] (Microsoft Corporation) MD5=197B7E4030CFBD8D2979D375E1787AA2 – C:\WINDOWS\$hf_mig$\KB950759-IE7\SP2QFE\iexplore.exe
[2008/08/23 01:56:15 | 000,635,848 | —- | M] (Microsoft Corporation) MD5=1F03216084447F990AE797317D0A6E70 – C:\WINDOWS\ie7updates\KB958215-IE7\iexplore.exe
[2012/12/14 17:49:28 | 000,216,424 | —- | M] () MD5=22101A85B3CA2FE2BE05FE9A61A7A83D – C:\Program Files\Malwarebytes' Anti-Malware\Chameleon\iexplore.exe
[2008/04/22 03:40:18 | 000,625,664 | —- | M] (Microsoft Corporation) MD5=232B22817B90AE0AFF2D189E3E3735AC – C:\WINDOWS\ie7updates\KB953838-IE7\iexplore.exe
[2007/12/06 07:01:25 | 000,625,664 | —- | M] (Microsoft Corporation) MD5=2703D940A62B731AA220529DD7331A78 – C:\WINDOWS\ie7updates\KB947864-IE7\iexplore.exe
[2007/06/27 04:27:30 | 000,625,152 | —- | M] (Microsoft Corporation) MD5=275CEE268B9E5D82474C43D5D249D111 – C:\WINDOWS\ie7updates\KB939653-IE7\iexplore.exe
[2008/02/29 04:55:46 | 000,625,664 | —- | M] (Microsoft Corporation) MD5=2D0E5592AB5A46C27DAF7CCAFF4F5B59 – C:\WINDOWS\ie7updates\KB950759-IE7\iexplore.exe
[2007/08/17 06:21:21 | 000,625,152 | —- | M] (Microsoft Corporation) MD5=3AC2BC667DA0AF2C968E96E1630F5AB5 – C:\WINDOWS\ie7updates\KB942615-IE7\iexplore.exe
[2006/10/17 13:04:40 | 000,622,080 | —- | M] (Microsoft Corporation) MD5=5334D4461AA92A7B008755FE6D13C5F2 – C:\WINDOWS\ie7updates\KB928090-IE7\iexplore.exe
[2007/08/17 06:12:49 | 000,625,152 | —- | M] (Microsoft Corporation) MD5=5577D0E3AC2F9F035ACD81B44AF5F511 – C:\WINDOWS\$hf_mig$\KB939653-IE7\SP2QFE\iexplore.exe
[2008/04/13 20:12:22 | 000,093,184 | —- | M] (Microsoft Corporation) MD5=55794B97A7FAABD2910873C85274F409 – C:\WINDOWS\ServicePackFiles\i386\iexplore.exe
[2007/10/10 04:16:56 | 000,625,664 | —- | M] (Microsoft Corporation) MD5=632BDE0179847234433CA50945442ACB – C:\WINDOWS\$hf_mig$\KB942615-IE7\SP2QFE\iexplore.exe
[2008/06/23 05:20:52 | 000,625,664 | —- | M] (Microsoft Corporation) MD5=64E376A47763DAEABCDA14BD5B6EA286 – C:\WINDOWS\ie7updates\KB956390-IE7\iexplore.exe
[2007/02/21 04:00:58 | 000,623,616 | —- | M] (Microsoft Corporation) MD5=683DDE71BCF03B501B912D20CB93B549 – C:\WINDOWS\ie7updates\KB933566-IE7\iexplore.exe
[2008/02/22 05:40:22 | 000,625,664 | —- | M] (Microsoft Corporation) MD5=6E0888626E0CAC79F57149814E22DB4D – C:\WINDOWS\$hf_mig$\KB947864-IE7\SP2QFE\iexplore.exe
[2007/12/06 04:34:45 | 000,625,664 | —- | M] (Microsoft Corporation) MD5=809D17D8FA0FDAEE07778CD821CAFFDE – C:\WINDOWS\$hf_mig$\KB944533-IE7\SP2QFE\iexplore.exe
[2007/01/08 19:08:42 | 000,623,616 | —- | M] (Microsoft Corporation) MD5=93A6A4F5293AE19E3B37021AABCF0902 – C:\WINDOWS\ie7updates\KB931768-IE7\iexplore.exe
[2007/04/24 10:20:41 | 000,625,152 | —- | M] (Microsoft Corporation) MD5=9B3516C1F30DA17ADD3818573047D63C – C:\WINDOWS\$hf_mig$\KB933566-IE7\SP2QFE\iexplore.exe
[2008/10/15 03:06:26 | 000,633,632 | —- | M] (Microsoft Corporation) MD5=9D3DB9ADFABD2F0BC778EC03250A3ABB – C:\WINDOWS\ie7updates\KB961260-IE7\iexplore.exe
[2009/02/28 00:54:41 | 000,636,072 | —- | M] (Microsoft Corporation) MD5=A251068640DDB69FD7805B57D89D7FF7 – C:\WINDOWS\ie8\iexplore.exe
[2009/03/08 14:09:26 | 000,638,816 | —- | M] (Microsoft Corporation) MD5=B60DDDD2D63CE41CB8C487FCFBB6419E – C:\Program Files\Internet Explorer\iexplore.exe
[2009/03/08 14:09:26 | 000,638,816 | —- | M] (Microsoft Corporation) MD5=B60DDDD2D63CE41CB8C487FCFBB6419E – C:\WINDOWS\ERDNT\cache\iexplore.exe
[2009/03/08 14:09:26 | 000,638,816 | —- | M] (Microsoft Corporation) MD5=B60DDDD2D63CE41CB8C487FCFBB6419E – C:\WINDOWS\system32\dllcache\iexplore.exe
[2009/02/28 00:54:44 | 000,636,088 | —- | M] (Microsoft Corporation) MD5=BCD8E48709BE4A79606F0B6E8E9A6162 – C:\WINDOWS\$hf_mig$\KB963027-IE7\SP3QFE\iexplore.exe
[2007/06/27 05:16:52 | 000,625,152 | —- | M] (Microsoft Corporation) MD5=BD8502DFD53FC24FB8D6929DC46B8C2C – C:\WINDOWS\$hf_mig$\KB937143-IE7\SP2QFE\iexplore.exe
[2008/06/23 04:23:52 | 000,625,664 | —- | M] (Microsoft Corporation) MD5=C52A9EF571E91535EB78DB4B8B95EA07 – C:\WINDOWS\$hf_mig$\KB953838-IE7\SP2QFE\iexplore.exe
[2007/02/28 02:51:34 | 000,625,152 | —- | M] (Microsoft Corporation) MD5=D321092F8529CDAE843D6E24E3CAC6CB – C:\WINDOWS\$hf_mig$\KB931768-IE7\SP2QFE\iexplore.exe
[2004/08/04 03:56:50 | 000,093,184 | —- | M] (Microsoft Corporation) MD5=E7484514C0464642BE7B4DC2689354C8 – C:\WINDOWS\$NtServicePackUninstall$\iexplore.exe
[2004/08/04 03:56:50 | 000,093,184 | —- | M] (Microsoft Corporation) MD5=E7484514C0464642BE7B4DC2689354C8 – C:\WINDOWS\ie7\iexplore.exe
[2008/08/23 01:56:16 | 000,635,848 | —- | M] (Microsoft Corporation) MD5=E8305C30D35E85D6657ED3E9934CB302 – C:\WINDOWS\$hf_mig$\KB956390-IE7\SP2QFE\iexplore.exe
[2007/10/10 06:59:52 | 000,625,152 | —- | M] (Microsoft Corporation) MD5=E854D02E4231F704D9BE782A424E6D8B – C:\WINDOWS\ie7updates\KB944533-IE7\iexplore.exe

< MD5 for: IEXPLORE.EXE.MUI >
[2009/03/08 14:21:44 | 000,012,288 | —- | M] (Microsoft Corporation) MD5=943030B55FDB56FB8B8FCC086071E119 – C:\Program Files\Internet Explorer\en-US\iexplore.exe.mui
[2009/03/08 14:21:44 | 000,012,288 | —- | M] (Microsoft Corporation) MD5=943030B55FDB56FB8B8FCC086071E119 – C:\Program Files\Internet Explorer\iexplore.exe.mui
[2006/10/17 13:04:26 | 000,573,440 | —- | M] (Microsoft Corporation) MD5=E83C9C1F9DD9D47BB44871BFC7E69DDD – C:\WINDOWS\ie8\iexplore.exe.mui

< MD5 for: IEXPLORE.EXE-2D97EBE6.PF >
[2013/09/29 13:16:01 | 000,098,660 | —- | M] () MD5=D653FB189A12EFEF3F712A9E28225FAF – C:\WINDOWS\Prefetch\IEXPLORE.EXE-2D97EBE6.pf

< MD5 for: IEXPLORE.HLP >
[2003/07/16 16:30:14 | 000,180,335 | —- | M] () MD5=3F19AF1B745140DAFAC6F78F561A3C62 – C:\WINDOWS\Help\iexplore.hlp

< MD5 for: SERVICES >
[2003/07/16 16:44:24 | 000,007,116 | —- | M] () MD5=95826940E657FE0567A8EC0F2A6AD11A – C:\WINDOWS\system32\drivers\etc\services

< MD5 for: SERVICES.DLL >
[2003/10/06 13:05:42 | 000,018,944 | —- | M] () MD5=FD3C2F44D7C48F2AFC8BBC11840205D8 – C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\services.dll

< MD5 for: SERVICES.EXE >
[2009/02/06 07:06:24 | 000,110,592 | —- | M] (Microsoft Corporation) MD5=020CEAAEDC8EB655B6506B8C70D53BB6 – C:\WINDOWS\$hf_mig$\KB956572\SP3QFE\services.exe
[2008/04/13 20:12:34 | 000,108,544 | —- | M] (Microsoft Corporation) MD5=0E776ED5F7CC9F94299E70461B7B8185 – C:\WINDOWS\$NtUninstallKB956572$\services.exe
[2008/04/13 20:12:34 | 000,108,544 | —- | M] (Microsoft Corporation) MD5=0E776ED5F7CC9F94299E70461B7B8185 – C:\WINDOWS\ServicePackFiles\i386\services.exe
[2009/02/06 07:11:05 | 000,110,592 | —- | M] (Microsoft Corporation) MD5=65DF52F5B8B6E9BBD183505225C37315 – C:\WINDOWS\ERDNT\cache\services.exe
[2009/02/06 07:11:05 | 000,110,592 | —- | M] (Microsoft Corporation) MD5=65DF52F5B8B6E9BBD183505225C37315 – C:\WINDOWS\system32\dllcache\services.exe
[2009/02/06 07:11:05 | 000,110,592 | —- | M] (Microsoft Corporation) MD5=65DF52F5B8B6E9BBD183505225C37315 – C:\WINDOWS\system32\services.exe
[2004/08/04 03:56:55 | 000,108,032 | —- | M] (Microsoft Corporation) MD5=C6CE6EEC82F187615D1002BB3BB50ED4 – C:\WINDOWS\$NtServicePackUninstall$\services.exe

< MD5 for: SERVICES.LNK >
[2006/01/06 00:08:58 | 000,001,602 | —- | M] () MD5=61F177100FA890CBCF458E4AD8E55EAE – C:\Documents and Settings\All Users.WINDOWS\Start Menu\Programs\Administrative Tools\Services.lnk
[2004/06/23 15:02:58 | 000,001,602 | —- | M] () MD5=680BE74FE1F07B9535B91A1DC135F965 – C:\Documents and Settings\All Users\Start Menu\Programs\Administrative Tools\Services.lnk

< MD5 for: SERVICES.MSC >
[2003/07/16 16:44:24 | 000,033,464 | —- | M] () MD5=E8089AA2A6F7FEE89B38C1F2D77BA6C6 – C:\WINDOWS\system32\services.msc

< MD5 for: WINLOGON.EXE >
[2004/08/04 03:56:57 | 000,502,272 | —- | M] (Microsoft Corporation) MD5=01C3346C241652F43AED8E2149881BFE – C:\WINDOWS\$NtServicePackUninstall$\winlogon.exe
[2012/12/14 17:49:28 | 000,216,424 | —- | M] () MD5=22101A85B3CA2FE2BE05FE9A61A7A83D – C:\Program Files\Malwarebytes' Anti-Malware\Chameleon\winlogon.exe
[2008/04/13 20:12:39 | 000,507,904 | —- | M] (Microsoft Corporation) MD5=ED0EF0A136DEC83DF69F04118870003E – C:\WINDOWS\ERDNT\cache\winlogon.exe
[2008/04/13 20:12:39 | 000,507,904 | —- | M] (Microsoft Corporation) MD5=ED0EF0A136DEC83DF69F04118870003E – C:\WINDOWS\ServicePackFiles\i386\winlogon.exe
[2008/04/13 20:12:39 | 000,507,904 | —- | M] (Microsoft Corporation) MD5=ED0EF0A136DEC83DF69F04118870003E – C:\WINDOWS\system32\winlogon.exe

< %SYSTEMDRIVE%\*.* >
[2011/04/14 03:25:04 | 000,066,524 | —- | M] () – C:\aaw7boot.log
[2012/10/12 20:30:05 | 000,006,654 | —- | M] () – C:\AdwCleaner[S1].txt
[2005/12/31 15:30:52 | 000,000,000 | —- | M] () – C:\AUTOEXEC.BAT
[2008/05/15 16:10:32 | 000,000,211 | —- | M] () – C:\Boot.bak
[2012/03/06 23:18:28 | 000,000,281 | RHS- | M] () – C:\boot.ini
[2004/08/03 23:00:00 | 000,260,272 | —- | M] () – C:\cmldr
[2012/10/22 22:12:40 | 000,016,053 | —- | M] () – C:\ComboFix.txt
[2004/06/23 15:02:54 | 000,000,000 | —- | M] () – C:\CONFIG.SYS
[2013/02/21 06:33:46 | 000,000,182 | —- | M] () – C:\drwtsn32.log
[2004/06/23 15:02:54 | 000,000,000 | RHS- | M] () – C:\IO.SYS
[2009/05/26 21:24:42 | 000,008,814 | —- | M] () – C:\JavaRa.log
[2004/06/23 15:02:54 | 000,000,000 | RHS- | M] () – C:\MSDOS.SYS
[2006/01/06 00:29:46 | 000,000,174 | —- | M] () – C:\mw.log
[2006/01/27 20:46:49 | 000,047,564 | RHS- | M] () – C:\NTDETECT.COM
[2008/09/29 16:35:49 | 000,250,048 | RHS- | M] () – C:\ntldr
[2013/09/29 13:11:32 | 1006,632,960 | -HS- | M] () – C:\pagefile.sys
[2010/06/10 13:55:18 | 000,000,385 | —- | M] () – C:\rkill.log
[2010/01/06 18:32:50 | 000,002,239 | —- | M] () – C:\rollback.ini
[2005/12/30 19:41:25 | 000,001,512 | —- | M] () – C:\smitfiles.txt
[2012/10/25 20:38:24 | 000,079,514 | —- | M] () – C:\TDSSKiller.2.8.13.0_25.10.2012_20.35.58_log.txt
[2012/10/25 21:06:36 | 000,003,412 | —- | M] () – C:\TDSSKiller.2.8.13.0_25.10.2012_21.05.20_log.txt
[2012/10/25 21:11:52 | 000,003,412 | —- | M] () – C:\TDSSKiller.2.8.13.0_25.10.2012_21.11.24_log.txt
[2012/10/28 09:09:36 | 000,079,514 | —- | M] () – C:\TDSSKiller.2.8.13.0_28.10.2012_09.06.22_log.txt
[2012/11/06 17:06:55 | 000,031,816 | —- | M] () – C:\{0F965B62-B635-4ABE-A5E1-8777DD9208D6}
[2012/11/03 04:38:13 | 000,032,096 | —- | M] () – C:\{104EF115-17E4-42F3-A4A8-073F1BB5854B}
[2012/10/31 17:43:17 | 000,032,144 | —- | M] () – C:\{2EF32154-D389-4EE7-888C-72CE6353A6B7}
[2012/10/10 23:45:13 | 000,031,776 | —- | M] () – C:\{3CAB558C-0424-4399-AC7E-182613966719}
[2013/03/08 04:39:40 | 000,033,376 | —- | M] () – C:\{5D48279C-082F-4796-8A19-DDF1B97192A6}
[2012/11/03 05:06:37 | 000,032,256 | —- | M] () – C:\{5EDAF753-B854-4D94-A952-35C6EA497E53}
[2012/12/26 17:41:57 | 000,032,568 | —- | M] () – C:\{6448E133-C6E1-4F40-99AA-F68C3073008A}
[2013/02/25 12:01:20 | 000,031,920 | —- | M] () – C:\{AA80D7A4-F196-4A4F-8959-07671B597D00}
[2013/03/03 03:32:57 | 000,032,728 | —- | M] () – C:\{AAA5D437-BD88-4957-84AA-F625EF3C997F}
[2012/12/27 00:21:01 | 000,031,888 | —- | M] () – C:\{B4089FB0-9E92-4BF4-9D7A-C8C720C58D9C}
[2013/02/25 12:37:26 | 000,033,296 | —- | M] () – C:\{B5EAAE70-CD2C-4514-A34D-5532D05FD675}
[2012/10/31 10:40:58 | 000,032,408 | —- | M] () – C:\{BB64D130-35BB-4983-8332-C15F15D0DD78}
[2012/10/22 20:18:41 | 000,002,608 | —- | M] () – C:\{C14588FA-2D5F-401D-B9FF-FBD3B8BDFB0C}
[2012/10/25 17:01:02 | 000,002,608 | —- | M] () – C:\{C6D62A8E-7509-4558-81FB-F118214A5C0F}
[2012/11/05 00:41:02 | 000,032,080 | —- | M] () – C:\{CF641E0E-D774-46A2-9D74-15C385994FF4}
[2012/10/19 15:02:13 | 000,031,704 | —- | M] () – C:\{D1179989-863E-4374-ABF6-3EACA2F2FD20}
[2013/02/26 04:49:24 | 000,033,216 | —- | M] () – C:\{D90118D2-3CCC-4E8F-AAB3-8309FDBE40BD}
[2013/03/08 05:24:37 | 000,033,368 | —- | M] () – C:\{D9D0D70F-C25A-4E72-950A-DB4122D3B896}
[2012/10/19 14:04:38 | 000,031,696 | —- | M] () – C:\{F765599A-AF2E-4919-8ECD-E0D9E979E54F}

< %systemroot%\Fonts\*.com >

< %systemroot%\Fonts\*.dll >

< %systemroot%\Fonts\*.ini >
[2006/01/06 00:08:23 | 000,000,067 | -HS- | M] () – C:\WINDOWS\Fonts\desktop.ini

< %systemroot%\Fonts\*.ini2 >

< %systemroot%\Fonts\*.exe >

< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2002/02/12 01:00:00 | 000,013,824 | —- | M] (CANON INC.) – C:\WINDOWS\system32\spool\prtprocs\w32x86\CNMPD43.DLL
[2002/02/12 01:00:00 | 000,043,008 | —- | M] (CANON INC.) – C:\WINDOWS\system32\spool\prtprocs\w32x86\CNMPP43.DLL
[2008/07/06 08:06:10 | 000,089,088 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\filterpipelineprintproc.dll
[2008/07/06 06:50:03 | 000,597,504 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\printfilterpipelinesvc.exe

< %systemroot%\REPAIR\*.bak1 >

< %systemroot%\REPAIR\*.ini >

< %systemroot%\system32\*.jpg >

< %systemroot%\*.jpg >

< %systemroot%\*.png >

< %systemroot%\*.scr >

< %systemroot%\*._sy >

< %APPDATA%\Adobe\Update\*.* >

< %ALLUSERSPROFILE%\Favorites\*.* >

< %APPDATA%\Microsoft\*.* >

< %PROGRAMFILES%\*.* >

< %APPDATA%\Update\*.* >

< %systemroot%\*. /mp /s >

< dir "%systemdrive%\*" /S /A:L /C >
Volume in drive C has no label.
Volume Serial Number is 103D-ED2F
Directory of C:\Program Files\Microsoft Security Client
07/29/2013 09:50 PM Backup
01/20/2013 03:58 PM DbgHelp.dll
07/29/2013 09:47 PM Drivers
07/29/2013 09:47 PM en-us
06/20/2013 08:08 PM EppManifest.dll
01/20/2013 03:58 PM LegitLib.dll
06/20/2013 07:04 PM MpAsDesc.dll
06/20/2013 05:46 PM MpClient.dll
06/20/2013 06:05 PM MpCmdRun.exe
06/20/2013 05:46 PM MpCommu.dll
06/20/2013 06:40 PM mpevmsg.dll
06/20/2013 05:46 PM MpOAv.dll
06/20/2013 05:46 PM MpRTP.dll
06/20/2013 05:46 PM MpSvc.dll
06/20/2013 05:46 PM MsMpCom.dll
06/20/2013 06:05 PM MsMpEng.exe
06/20/2013 05:46 PM MsMpLics.dll
06/20/2013 05:51 PM MsMpRes.dll
06/20/2013 05:25 PM msseces.exe
06/20/2013 05:25 PM MsseWat.dll
06/20/2013 06:05 PM Setup.exe
06/20/2013 05:51 PM SetupRes.dll
06/20/2013 05:51 PM shellext.dll
01/20/2013 03:58 PM SqmApi.dll
01/20/2013 03:58 PM SymSrv.dll
01/20/2013 03:58 PM SymSrv.yes
23 File(s) 8,478,777 bytes
Directory of C:\WINDOWS\assembly\GAC_32\System.EnterpriseServices
08/15/2013 03:07 AM 2.0.0.0__b03f5f7f11d50a3a
0 File(s) 0 bytes
Directory of C:\WINDOWS\assembly\GAC_MSIL\IEExecRemote
08/15/2013 03:07 AM 2.0.0.0__b03f5f7f11d50a3a
0 File(s) 0 bytes
Total Files Listed:
23 File(s) 8,478,777 bytes
5 Dir(s) 23,977,873,408 bytes free

< %systemroot%\System32\config\*.sav >
[2006/01/05 15:50:58 | 000,094,208 | —- | M] () – C:\WINDOWS\System32\config\default.sav
[2006/01/05 15:50:58 | 000,602,112 | —- | M] () – C:\WINDOWS\System32\config\software.sav
[2006/01/05 15:50:58 | 000,389,120 | —- | M] () – C:\WINDOWS\System32\config\system.sav

< %PROGRAMFILES%\bak. /s >

< %systemroot%\system32\bak. /s >

< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >
[2008/09/29 16:49:11 | 000,000,272 | -HS- | M] () – C:\Documents and Settings\All Users.WINDOWS\Start Menu\desktop.ini

< %systemroot%\system32\config\systemprofile\*.dat /x >

< %systemroot%\*.config >

< %systemroot%\system32\*.db >

< %PROGRAMFILES%\Internet Explorer\*.dat >

< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2006/01/27 21:54:11 | 000,000,177 | -HS- | M] () – C:\Documents and Settings\Owner.PETE-05CK9PEMS6\Application Data\Microsoft\Internet Explorer\Quick Launch\desktop.ini
[2006/01/06 00:18:02 | 000,000,079 | —- | M] () – C:\Documents and Settings\Owner.PETE-05CK9PEMS6\Application Data\Microsoft\Internet Explorer\Quick Launch\Show Desktop.scf

< %USERPROFILE%\Desktop\*.exe >
[2012/10/12 20:28:12 | 000,538,327 | —- | M] () – C:\Documents and Settings\Owner.PETE-05CK9PEMS6\Desktop\AdwCleaner.exe
[2012/09/23 13:55:19 | 027,669,608 | —- | M] (IObit ) – C:\Documents and Settings\Owner.PETE-05CK9PEMS6\Desktop\asc-setup.exe
[2012/10/12 20:48:29 | 004,731,392 | —- | M] (AVAST Software) – C:\Documents and Settings\Owner.PETE-05CK9PEMS6\Desktop\aswMBR.exe
[2009/05/28 19:11:47 | 000,050,688 | —- | M] (Atribune.org) – C:\Documents and Settings\Owner.PETE-05CK9PEMS6\Desktop\ATF-Cleaner.exe
[2011/04/23 14:09:42 | 005,497,592 | —- | M] (AVG Technologies) – C:\Documents and Settings\Owner.PETE-05CK9PEMS6\Desktop\avg_free_stb_all_2011_1321_cnet.exe
[2012/09/23 13:51:33 | 003,927,560 | —- | M] (Piriform Ltd) – C:\Documents and Settings\Owner.PETE-05CK9PEMS6\Desktop\ccsetup322.exe
[2012/10/22 20:37:39 | 004,987,615 | R— | M] (Swearware) – C:\Documents and Settings\Owner.PETE-05CK9PEMS6\Desktop\ComboFix.exe
[2012/10/13 09:19:20 | 018,494,856 | —- | M] (Mozilla) – C:\Documents and Settings\Owner.PETE-05CK9PEMS6\Desktop\Firefox Setup 16.0.1.exe
[2012/01/19 11:51:20 | 000,776,208 | —- | M] (Adobe Systems Incorporated) – C:\Documents and Settings\Owner.PETE-05CK9PEMS6\Desktop\install_flashplayer11x32ax_gtba_aih.exe
[2011/04/23 13:06:00 | 016,537,376 | —- | M] (Sun Microsystems, Inc.) – C:\Documents and Settings\Owner.PETE-05CK9PEMS6\Desktop\jre-6u25-windows-i586.exe
[2011/05/04 09:43:12 | 007,734,208 | —- | M] (Malwarebytes Corporation ) – C:\Documents and Settings\Owner.PETE-05CK9PEMS6\Desktop\mbam-setup-1.50.1.1100.exe
[2012/03/06 21:49:12 | 009,852,544 | —- | M] (Malwarebytes Corporation ) – C:\Documents and Settings\Owner.PETE-05CK9PEMS6\Desktop\mbam-setup-1.51.2.1300.exe
[2013/09/29 08:30:31 | 011,233,112 | —- | M] (Microsoft Corporation) – C:\Documents and Settings\Owner.PETE-05CK9PEMS6\Desktop\mseinstall.exe
[2013/03/17 19:12:36 | 000,866,592 | —- | M] () – C:\Documents and Settings\Owner.PETE-05CK9PEMS6\Desktop\Norton_Removal_Tool.exe
[2013/05/31 08:25:51 | 030,185,256 | —- | M] (Emsisoft GmbH ) – C:\Documents and Settings\Owner.PETE-05CK9PEMS6\Desktop\OnlineArmorSetup.exe
[2013/09/29 13:18:26 | 000,602,112 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Owner.PETE-05CK9PEMS6\Desktop\OTL.exe
[2012/01/15 10:37:29 | 009,504,840 | —- | M] (TweakNow.com ) – C:\Documents and Settings\Owner.PETE-05CK9PEMS6\Desktop\PowerPack347.exe
[2012/10/12 17:27:22 | 002,213,464 | —- | M] (Kaspersky Lab ZAO) – C:\Documents and Settings\Owner.PETE-05CK9PEMS6\Desktop\TDSSKiller.exe

< %PROGRAMFILES%\Common Files\*.* >

< %systemroot%\*.src >

< %systemroot%\install\*.* >

< %systemroot%\system32\DLL\*.* >

< %systemroot%\system32\HelpFiles\*.* >

< %systemroot%\system32\rundll\*.* >

< %systemroot%\winn32\*.* >

< %systemroot%\Java\*.* >

< %systemroot%\system32\test\*.* >

< %systemroot%\system32\Rundll32\*.* >

< %systemroot%\AppPatch\Custom\*.* >

< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >

< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2013-09-13 07:15:53

< >
[2006/01/06 00:06:32 | 000,000,065 | R— | C] () – C:\WINDOWS\Tasks\desktop.ini
[2006/01/06 00:08:36 | 000,000,006 | -H– | C] () – C:\WINDOWS\Tasks\SA.DAT
[2009/10/01 17:48:09 | 000,000,422 | -H– | C] () – C:\WINDOWS\Tasks\User_Feed_Synchronization-{96E858C2-BB80-4CA6-A945-5D7F401AA939}.job
[2012/10/14 08:39:43 | 000,000,830 | —- | C] () – C:\WINDOWS\Tasks\Adobe Flash Player Updater.job
[2013/03/13 04:03:04 | 000,000,268 | —- | C] () – C:\WINDOWS\Tasks\ASC6_PerformanceMonitor.job
[2013/07/29 21:59:16 | 000,000,384 | -H– | C] () – C:\WINDOWS\Tasks\Microsoft Antimalware Scheduled Scan.job
[2013/09/29 13:07:49 | 000,000,370 | —- | C] () – C:\WINDOWS\Tasks\MyTurboPC.job
[2013/09/29 13:07:51 | 000,000,416 | —- | C] () – C:\WINDOWS\Tasks\MyTurboPC.com Update3.job
[2013/09/29 13:10:07 | 000,000,452 | —- | C] () – C:\WINDOWS\Tasks\MyTurboPC.com Registration3.job

< >

< End of report >
—————

Can't locate the extras.txt file..

Thanks,

Polly

:welcome:

Hello pfilighera,

my name is Jo and I will help you with your computer problems.


Please be advised that I am currently in training, so my responses will need to be approved by one of our experts before I post them. This is only to ensure you are receiving accurate instructions. It may cause a delay in my replies.


Please follow these guidelines:
  • Logs can take a while to research, so please be patient.
  • Read and follow the instructions in the sequence they are posted.
  • print or copy & save instructions.
  • Do not install / uninstall any applications, unless otherwise instructed.
  • Use only that tools you have been instructed to use.
  • Copy and Paste the log files inside your post, unless otherwise instructed.
  • Ask for clarification, if you have any questions.
  • Stay with this topic ‘til you get the “all clean” post.
  • My first language is not english. So please do not use slang or idioms. It could be hard for me to read. Thanks for your understanding.
I will return as soon as possible with more instructions.
Hello pfilighera,

1. Download Security Check by screen317 from here or here.
  • Save it to your Desktop.
  • Double click SecurityCheck.exe and follow the onscreen instructions inside of the black box.
  • A Notepad document should open automatically called checkup.txt; please post the contents of that document.

2. Please download AdwCleaner by Xplode and save to your Desktop.
  • double-click AdwCleaner.exe
  • Click on the Scan button.
  • AdwCleaner will begin…be patient as the scan may take some time to complete.
    The actual line should say "Pending. Please uncheck elements you do not want to remove" => scan is complete.
  • After the scan has finished, click on the Report button…a logfile (AdwCleaner[R0].txt) will open in Notepad for review.
  • The contents of the log file may be confusing. Unless you see a program name that you know should not be removed, don't worry about it.
    If you see an entry you want to keep, let me know about it.
  • Copy and paste the contents of that logfile in your next reply.
  • A copy of all logfiles are saved in the C:\AdwCleaner folder which was created when running the tool.

3. Please download Malwarebytes Anti-Rootkit and save it to your desktop.
  • Be sure to print out and follow the instructions provided on that same page.
  • Caution: This is a beta version so please be sure to read the disclaimer and back up all your data before using.
  • Scan your system for malware
  • If malware is found, please go to the MBAR folder and then copy/paste the contents of the MBAR-log-***.txt file to your next reply.
If there is no malware found, please let me know as well.
Results of screen317's Security Check version 0.99.74
Windows XP Service Pack 3 x86
Internet Explorer 8
``````````````Antivirus/Firewall Check:``````````````
Windows Security Center service is not running! This report may not be accurate!
Online Armor 6.0
`````````Anti-malware/Other Utilities Check:`````````
SpywareBlaster 4.2
SpywareGuard v2.2
Malwarebytes Anti-Malware version 1.70.0.1100
Out of date Malwarebytes Anti-Malware installed!
CCleaner
Java™ 6 Update 30
Java 7 Update 21
Java version out of Date!
Adobe Flash Player 11.8.800.168
````````Process Check: objlist.exe by Laurent````````
`````````````````System Health check`````````````````
Total Fragmentation on Drive C:: 7%
````````````````````End of Log``````````````````````


————————————————————

# AdwCleaner v3.006 - Report created 06/10/2013 at 15:43:31
# Updated 01/10/2013 by Xplode
# Operating System : Microsoft Windows XP Service Pack 3 (32 bits)
# Username : Owner - PETE-05CK9PEMS6
# Running from : C:\Documents and Settings\Owner.PETE-05CK9PEMS6\Desktop\AdwCleaner.exe
# Option : Scan

***** [ Services ] *****


***** [ Files / Folders ] *****

Folder Found C:\Program Files\iMesh Applications

***** [ Shortcuts ] *****


***** [ Registry ] *****

Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0}
Key Found : HKCU\Software\YahooPartnerToolbar

***** [ Browsers ] *****

-\\ Internet Explorer v8.0.6001.18702


-\\ Mozilla Firefox v

*************************

AdwCleaner[R0].txt - [769 octets] - [06/10/2013 15:43:31]

########## EOF - C:\AdwCleaner\AdwCleaner[R0].txt - [828 octets] ##########

———————————————-

There are 2 logs for the 2 times I did the clean up.

Malwarebytes Anti-Rootkit BETA 1.07.0.1005
www.malwarebytes.org

Database version: v2013.10.06.04

Windows XP Service Pack 3 x86 NTFS
Internet Explorer 8.0.6001.18702
:: PETE-05CK9PEMS6 [administrator]

10/6/2013 4:18:59 PM
mbar-log-2013-10-06 (16-18-59).txt

Scan type: Quick scan
Scan options enabled: Anti-Rootkit | Drivers | MBR | Physical Sectors | Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken
Scan options disabled:
Objects scanned: 401470
Time elapsed: 1 hour(s), 10 minute(s), 28 second(s)

Memory Processes Detected: 0
(No malicious items detected)

Memory Modules Detected: 0
(No malicious items detected)

Registry Keys Detected: 1
HKLM\SYSTEM\CURRENTCONTROLSET\ENUM\ROOT\LEGACY_*202EETADPUG (Rootkit.0Access) -> Delete on reboot.

Registry Values Detected: 0
(No malicious items detected)

Registry Data Items Detected: 0
(No malicious items detected)

Folders Detected: 15
C:\RECYCLER\S-1-5-21-854245398-1547161642-839522115-1003\$827827d9f2886f9a9c8656eb7c983fff (Trojan.Siredef.C) -> Delete on reboot.
C:\Documents and Settings\Owner.PETE-05CK9PEMS6\Local Settings\Application Data\Google\Desktop\Install\{827827d9-f288-6f9a-9c86-56eb7c983fff}\❤≸⋙ (Trojan.0Access) -> Delete on reboot.
C:\Documents and Settings\Owner.PETE-05CK9PEMS6\Local Settings\Application Data\Google\Desktop\Install\{827827d9-f288-6f9a-9c86-56eb7c983fff}\❤≸⋙\Ⱒ☠⍨ (Trojan.0Access) -> Delete on reboot.
C:\Documents and Settings\Owner.PETE-05CK9PEMS6\Local Settings\Application Data\Google\Desktop\Install\{827827d9-f288-6f9a-9c86-56eb7c983fff}\❤≸⋙\Ⱒ☠⍨\ﯹ๛ (Trojan.0Access) -> Delete on reboot.
C:\Documents and Settings\Owner.PETE-05CK9PEMS6\Local Settings\Application Data\Google\Desktop\Install\{827827d9-f288-6f9a-9c86-56eb7c983fff}\❤≸⋙\Ⱒ☠⍨\ﯹ๛\{827827d9-f288-6f9a-9c86-56eb7c983fff} (Trojan.0Access) -> Delete on reboot.
C:\Documents and Settings\Owner.PETE-05CK9PEMS6\Local Settings\Application Data\Google\Desktop\Install\{827827d9-f288-6f9a-9c86-56eb7c983fff}\❤≸⋙\Ⱒ☠⍨\ﯹ๛\{827827d9-f288-6f9a-9c86-56eb7c983fff}\L (Trojan.0Access) -> Delete on reboot.
C:\Documents and Settings\Owner.PETE-05CK9PEMS6\Local Settings\Application Data\Google\Desktop\Install\{827827d9-f288-6f9a-9c86-56eb7c983fff}\❤≸⋙\Ⱒ☠⍨\ﯹ๛\{827827d9-f288-6f9a-9c86-56eb7c983fff}\U (Trojan.0Access) -> Delete on reboot.
C:\Documents and Settings\Owner.PETE-05CK9PEMS6\Local Settings\Application Data\Google\Desktop\Install\{827827d9-f288-6f9a-9c86-56eb7c983fff} (Trojan.0Access) -> Delete on reboot.
c:\program files\google\desktop\install\{827827d9-f288-6f9a-9c86-56eb7c983fff}\ (Trojan.0Access) -> Delete on reboot.
c:\program files\google\desktop\install\{827827d9-f288-6f9a-9c86-56eb7c983fff}\ \ (Trojan.0Access) -> Delete on reboot.
c:\program files\google\desktop\install\{827827d9-f288-6f9a-9c86-56eb7c983fff}\ \ \ﯹ๛ (Trojan.0Access) -> Delete on reboot.
c:\program files\google\desktop\install\{827827d9-f288-6f9a-9c86-56eb7c983fff}\ \ \ﯹ๛\{827827d9-f288-6f9a-9c86-56eb7c983fff} (Trojan.0Access) -> Delete on reboot.
c:\program files\google\desktop\install\{827827d9-f288-6f9a-9c86-56eb7c983fff}\ \ \ﯹ๛\{827827d9-f288-6f9a-9c86-56eb7c983fff}\l (Trojan.0Access) -> Delete on reboot.
c:\program files\google\desktop\install\{827827d9-f288-6f9a-9c86-56eb7c983fff}\ \ \ﯹ๛\{827827d9-f288-6f9a-9c86-56eb7c983fff}\u (Trojan.0Access) -> Delete on reboot.
C:\Program Files\Google\Desktop\Install\{827827d9-f288-6f9a-9c86-56eb7c983fff} (Trojan.0Access) -> Delete on reboot.

Files Detected: 12
C:\RECYCLER\S-1-5-21-854245398-1547161642-839522115-1003\$827827d9f2886f9a9c8656eb7c983fff\@ (Trojan.Siredef.C) -> Delete on reboot.
C:\WINDOWS\assembly\GAC\Desktop.ini (Rootkit.0access) -> Delete on reboot.
C:\Documents and Settings\Owner.PETE-05CK9PEMS6\Local Settings\Application Data\Google\Desktop\Install\{827827d9-f288-6f9a-9c86-56eb7c983fff}\❤≸⋙\Ⱒ☠⍨\ﯹ๛\{827827d9-f288-6f9a-9c86-56eb7c983fff}\@ (Trojan.0Access) -> Delete on reboot.
c:\program files\google\desktop\install\{827827d9-f288-6f9a-9c86-56eb7c983fff}\ \ \ﯹ๛\{827827d9-f288-6f9a-9c86-56eb7c983fff}\@ (Trojan.0Access) -> Delete on reboot.
c:\program files\google\desktop\install\{827827d9-f288-6f9a-9c86-56eb7c983fff}\ \ \ﯹ๛\{827827d9-f288-6f9a-9c86-56eb7c983fff}\l\00000004.@ (Trojan.0Access) -> Delete on reboot.
c:\program files\google\desktop\install\{827827d9-f288-6f9a-9c86-56eb7c983fff}\ \ \ﯹ๛\{827827d9-f288-6f9a-9c86-56eb7c983fff}\l\201d3dde (Trojan.0Access) -> Delete on reboot.
c:\program files\google\desktop\install\{827827d9-f288-6f9a-9c86-56eb7c983fff}\ \ \ﯹ๛\{827827d9-f288-6f9a-9c86-56eb7c983fff}\l\76603ac3 (Trojan.0Access) -> Delete on reboot.
c:\program files\google\desktop\install\{827827d9-f288-6f9a-9c86-56eb7c983fff}\ \ \ﯹ๛\{827827d9-f288-6f9a-9c86-56eb7c983fff}\u\00000001.@ (Trojan.0Access) -> Delete on reboot.
c:\program files\google\desktop\install\{827827d9-f288-6f9a-9c86-56eb7c983fff}\ \ \ﯹ๛\{827827d9-f288-6f9a-9c86-56eb7c983fff}\u\00000002.@ (Trojan.0Access) -> Delete on reboot.
c:\program files\google\desktop\install\{827827d9-f288-6f9a-9c86-56eb7c983fff}\ \ \ﯹ๛\{827827d9-f288-6f9a-9c86-56eb7c983fff}\u\00000008.@ (Trojan.0Access) -> Delete on reboot.
c:\program files\google\desktop\install\{827827d9-f288-6f9a-9c86-56eb7c983fff}\ \ \ﯹ๛\{827827d9-f288-6f9a-9c86-56eb7c983fff}\u\80000001.@ (Trojan.0Access) -> Delete on reboot.
c:\program files\google\desktop\install\{827827d9-f288-6f9a-9c86-56eb7c983fff}\ \ \ﯹ๛\{827827d9-f288-6f9a-9c86-56eb7c983fff}\u\80000032.@ (Trojan.0Access) -> Delete on reboot.

Physical Sectors Detected: 0
(No malicious items detected)

(end)
—————————

Malwarebytes Anti-Rootkit BETA 1.07.0.1005
www.malwarebytes.org

Database version: v2013.10.06.05

Windows XP Service Pack 3 x86 NTFS
Internet Explorer 8.0.6001.18702
:: PETE-05CK9PEMS6 [administrator]

10/6/2013 6:01:20 PM
mbar-log-2013-10-06 (18-01-20).txt

Scan type: Quick scan
Scan options enabled: Anti-Rootkit | Drivers | MBR | Physical Sectors | Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken
Scan options disabled:
Objects scanned: 401481
Time elapsed: 1 hour(s), 10 minute(s), 27 second(s)

Memory Processes Detected: 0
(No malicious items detected)

Memory Modules Detected: 0
(No malicious items detected)

Registry Keys Detected: 1
HKLM\SYSTEM\CURRENTCONTROLSET\ENUM\ROOT\LEGACY_*202EETADPUG (Rootkit.0Access) -> Delete on reboot.

Registry Values Detected: 0
(No malicious items detected)

Registry Data Items Detected: 0
(No malicious items detected)

Folders Detected: 0
(No malicious items detected)

Files Detected: 0
(No malicious items detected)

Physical Sectors Detected: 0
(No malicious items detected)

(end)
————————

I still can't turn back on the firewall and the security essential program. Thank you so much for your assistance. I will wait for further assistance.
Hello pfilighera,


your computer appears to have been infected by malware with a backdoor (ZeroAccess). These programs have the ability to steal passwords and other information from your system. If you use your computer for sensitive purposes such as internet banking then I recommend you take the following steps immediately:
Use another, uninfected computer to change all your internet passwords, especially ones with financial implications such as banks, paypal, ebay, etc. You should also change the passwords for any other site you use.
Call your bank(s), credit card company or any other institution which may be affected and advise them that your login/password or credit card information may have been stolen and ask what steps to take with regard to your account.
Consider what other private information could possibly have been taken from your computer and take appropriate steps.

This infection can almost certainly be cleaned, but as the malware could be configured to run any program a remote attacker requires, it will be impossible to be 100% sure that the machine is clean, if this is unacceptable to you then you should consider reformatting the system partition and reinstalling Windows as this is the only 100% sure answer.

If you wish to reformat then please let me know in your next response, I'll now continue with instructions for cleaning.

————————————

1. Tweaking.com Registry Backup
  • Download the tool found here to your Desktop so it is easy to find.
  • Double click on the file you just downloaded to install it to your system.
  • Once the tool is installed, double-click on the Tweaking.com Registry Backup icon

    *Note:* The tool should automatically open to the Backup Registry
    tab.
  • Press Backup Now
  • When the back up is complete, the tool will tell you that Successful */* Files Backed Up
  • You have now successfully backed up your Registry.

2. Now please go to the MBAR folder and then run the "fixdamage.exe" tool that's inside the mbar\plugins folder.


3. Run OTL.exe
  • Copy/paste the following text written inside of the code box into the Custom Scans/Fixes box located at the bottom of OTL

    :OTL
    O4 - HKCU..\Run: [Google Update] Reg Error: Value error. File not found
    IE - HKLM\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 1 
    IE - HKLM\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = http=localhost:7171 
    
    
    :Services
    5613
    etadpug
    
    :Files
    C:\DOCUME~1\OWNER~2.PET\LOCALS~1\Temp\5613.sys 
    C:\Program Files\Google\Desktop\Install\{827827d9-f288-6f9a-9c86-56eb7c983fff}
    C:\WINDOWS\System32\drivers\b660883d10b7f0b1.sys 
    
    
    :Commands
    [resethosts]
    [Purity]
    [EmptyTemp]
    [Emptyflash]
    [createrestorepoint] 
    [Reboot]
  • Then click the Run Fix button at the top
  • Let the program run unhindered, reboot when it is done
  • Then post a new OTL log ( don't check the boxes beside LOP Check or Purity this time )

4. Please download Farbar Service Scanner and run it on the computer with the issue.
  • Make sure "Include All Files" option remains checked.
  • Press "Scan".
  • It will create a log (FSS.txt) in the same directory the tool is run.
  • Please copy and paste the log to your reply.
All processes killed ========== OTL ========== Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\Google Update not found. HKLM\Software\Microsoft\Windows\CurrentVersion\Internet Settings\\ProxyEnable|dword:0 /E : value set successfully! HKLM\Software\Microsoft\Windows\CurrentVersion\Internet Settings\\ProxyServer| /E : value set successfully! ========== SERVICES/DRIVERS ========== Service 5613 stopped successfully! Service 5613 deleted successfully! Error: No service named etadpug was found to stop! Service\Driver key etadpug not found. ========== FILES ========== File\Folder C:\DOCUME~1\OWNER~2.PET\LOCALS~1\Temp\5613.sys not found. File\Folder C:\Program Files\Google\Desktop\Install\{827827d9-f288-6f9a-9c86-56eb7c983fff} not found. File move failed. C:\WINDOWS\System32\drivers\b660883d10b7f0b1.sys scheduled to be moved on reboot. ========== COMMANDS ========== C:\WINDOWS\System32\drivers\etc\Hosts moved successfully. HOSTS file reset successfully Farbar Service Scanner Version: 13-09-2013 Ran by [removed] (administrator) on 07-10-2013 at 20:19:41 Running from "C:\Documents and Settings\Owner.PETE-05CK9PEMS6\Desktop" Microsoft Windows XP Service Pack 3 (X86) Boot Mode: Normal **************************************************************** Internet Services: ============ Connection Status: ============== Localhost is accessible. LAN connected. Google IP is accessible. Google.com is accessible. Yahoo.com is accessible. Windows Firewall: ============= sharedaccess Service is not running. Checking service configuration: The start type of sharedaccess service is OK. The ImagePath of sharedaccess service is OK. The ServiceDll of sharedaccess service is OK. winmgmt Service is not running. Checking service configuration: The start type of winmgmt service is OK. The ImagePath of winmgmt service is OK. The ServiceDll of winmgmt: "C:\DOCUME~1\OWNER~2.PET\5820406.dll". Firewall Disabled Policy: ================== System Restore: ============ System Restore Disabled Policy: ======================== Security Center: ============ wscsvc Service is not running. Checking service configuration: The start type of wscsvc service is OK. The ImagePath of wscsvc service is OK. The ServiceDll of wscsvc service is OK. winmgmt Service is not running. Checking service configuration: The start type of winmgmt service is OK. The ImagePath of winmgmt service is OK. The ServiceDll of winmgmt: "C:\DOCUME~1\OWNER~2.PET\5820406.dll". Windows Update: ============ wuauserv Service is not running. Checking service configuration: The start type of wuauserv service is OK. The ImagePath of wuauserv service is OK. The ServiceDll of wuauserv: "C:\WINDOWS\system32\wuauserv.dll". BITS Service is not running. Checking service configuration: The start type of BITS service is OK. The ImagePath of BITS service is OK. The ServiceDll of BITS: "C:\WINDOWS\system32\qmgr.dll". Windows Autoupdate Disabled Policy: ============================ Other Services: ============== Checking Start type of PolicyAgent: ATTENTION!=====> Unable to open PolicyAgent registry key. The service key does not exist. Checking ImagePath of PolicyAgent: ATTENTION!=====> Unable to open PolicyAgent registry key. The service key does not exist. Checking Start type of RemoteAccess: ATTENTION!=====> Unable to open RemoteAccess registry key. The service key does not exist. Checking ImagePath of RemoteAccess: ATTENTION!=====> Unable to open RemoteAccess registry key. The service key does not exist. Checking ServiceDll of RemoteAccess: ATTENTION!=====> Unable to open RemoteAccess registry key. The service key does not exist. File Check: ======== C:\WINDOWS\system32\dhcpcsvc.dll => MD5 is legit C:\WINDOWS\system32\Drivers\afd.sys => MD5 is legit C:\WINDOWS\system32\Drivers\netbt.sys => MD5 is legit C:\WINDOWS\system32\Drivers\tcpip.sys => MD5 is legit C:\WINDOWS\system32\Drivers\ipsec.sys => MD5 is legit C:\WINDOWS\system32\dnsrslvr.dll => MD5 is legit C:\WINDOWS\system32\ipnathlp.dll => MD5 is legit C:\WINDOWS\system32\netman.dll => MD5 is legit C:\WINDOWS\system32\wbem\WMIsvc.dll => MD5 is legit C:\WINDOWS\system32\srsvc.dll => MD5 is legit C:\WINDOWS\system32\Drivers\sr.sys => MD5 is legit C:\WINDOWS\system32\wscsvc.dll => MD5 is legit C:\WINDOWS\system32\wbem\WMIsvc.dll => MD5 is legit C:\WINDOWS\system32\wuauserv.dll => MD5 is legit C:\WINDOWS\system32\qmgr.dll => MD5 is legit C:\WINDOWS\system32\es.dll => MD5 is legit C:\WINDOWS\system32\cryptsvc.dll => MD5 is legit C:\WINDOWS\system32\svchost.exe => MD5 is legit C:\WINDOWS\system32\rpcss.dll => MD5 is legit C:\WINDOWS\system32\services.exe => MD5 is legit Extra List: ======= Gpc(3) IPSec(5) NetBT(6) OAmon(16) SYMTDI(15) Tcpip(4) 0x07000000050000000300000004000000100000000F0000000600000007000000 IpSec Tag value is correct. **** End of log **** Let me know what to do next. thanks again. [EMPTYTEMP] User: Administrator ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes User: Administrator.PETE-05CK9PEMS6 ->Temp folder emptied: 327680 bytes ->Temporary Internet Files folder emptied: 74141 bytes User: All Users User: All Users.WINDOWS User: Default User ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes User: Default User.WINDOWS ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 67 bytes User: LocalService ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes ->Flash cache emptied: 0 bytes User: LocalService.NT AUTHORITY ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes User: LocalService.NT AUTHORITY.000 ->Temp folder emptied: 66016 bytes ->Temporary Internet Files folder emptied: 500166331 bytes ->Flash cache emptied: 24126 bytes User: NetworkService ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes User: NetworkService.NT AUTHORITY ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes User: NetworkService.NT AUTHORITY.000 ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 32902 bytes ->Flash cache emptied: 0 bytes User: Owner ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes ->Flash cache emptied: 0 bytes User: Owner.PETE-05CK9PEMS6 ->Temp folder emptied: 9182607 bytes ->Temporary Internet Files folder emptied: 152180223 bytes ->Java cache emptied: 151409 bytes ->FireFox cache emptied: 60457577 bytes ->Flash cache emptied: 2470 bytes User: Owner.PETE-OZKKR0BYRK ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes %systemdrive% .tmp files removed: 0 bytes %systemroot% .tmp files removed: 0 bytes %systemroot%\System32 .tmp files removed: 0 bytes %systemroot%\System32\dllcache .tmp files removed: 0 bytes %systemroot%\System32\drivers .tmp files removed: 0 bytes Windows Temp folder emptied: 664 bytes %systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 156635852 bytes %systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 0 bytes RecycleBin emptied: 26431 bytes Total Files Cleaned = 839.00 mb [EMPTYFLASH] User: Administrator User: Administrator.PETE-05CK9PEMS6 User: All Users User: All Users.WINDOWS User: Default User User: Default User.WINDOWS User: LocalService ->Flash cache emptied: 0 bytes User: LocalService.NT AUTHORITY User: LocalService.NT AUTHORITY.000 ->Flash cache emptied: 0 bytes User: NetworkService User: NetworkService.NT AUTHORITY User: NetworkService.NT AUTHORITY.000 ->Flash cache emptied: 0 bytes User: Owner ->Flash cache emptied: 0 bytes User: Owner.PETE-05CK9PEMS6 ->Flash cache emptied: 0 bytes User: Owner.PETE-OZKKR0BYRK Total Flash Files Cleaned = 0.00 mb System Restore Service not available. Error: Unable to interpret <[Reboot> in the current context! OTL by OldTimer - Version 3.2.69.0 log created on 10072013_200446 Files\Folders moved on Reboot… File move failed. C:\WINDOWS\System32\drivers\b660883d10b7f0b1.sys scheduled to be moved on reboot. C:\Documents and Settings\Owner.PETE-05CK9PEMS6\Local Settings\Temp\JavaDeployReg.log moved successfully. C:\Documents and Settings\Owner.PETE-05CK9PEMS6\Local Settings\Temporary Internet Files\Content.IE5\VY2KUFGE\AdDisplayTrackerServlet[2].htm moved successfully. C:\Documents and Settings\Owner.PETE-05CK9PEMS6\Local Settings\Temporary Internet Files\Content.IE5\VY2KUFGE\AdDisplayTrackerServlet[3].htm moved successfully. C:\Documents and Settings\Owner.PETE-05CK9PEMS6\Local Settings\Temporary Internet Files\Content.IE5\VY2KUFGE\ads[2].htm moved successfully. C:\Documents and Settings\Owner.PETE-05CK9PEMS6\Local Settings\Temporary Internet Files\Content.IE5\VY2KUFGE\ddc[1].htm moved successfully. C:\Documents and Settings\Owner.PETE-05CK9PEMS6\Local Settings\Temporary Internet Files\Content.IE5\VY2KUFGE\fpi[2].htm moved successfully. C:\Documents and Settings\Owner.PETE-05CK9PEMS6\Local Settings\Temporary Internet Files\Content.IE5\VY2KUFGE\p-01-0VIaSjnOLg[2].gif moved successfully. C:\Documents and Settings\Owner.PETE-05CK9PEMS6\Local Settings\Temporary Internet Files\Content.IE5\VY2KUFGE\Pug[1].htm moved successfully. C:\Documents and Settings\Owner.PETE-05CK9PEMS6\Local Settings\Temporary Internet Files\Content.IE5\VY2KUFGE\si[3].htm moved successfully. C:\Documents and Settings\Owner.PETE-05CK9PEMS6\Local Settings\Temporary Internet Files\Content.IE5\UPDD8FBL\beacon[1].htm moved successfully. C:\Documents and Settings\Owner.PETE-05CK9PEMS6\Local Settings\Temporary Internet Files\Content.IE5\UPDD8FBL\iframe[1].html moved successfully. C:\Documents and Settings\Owner.PETE-05CK9PEMS6\Local Settings\Temporary Internet Files\Content.IE5\UPDD8FBL\meta[1].htm moved successfully. C:\Documents and Settings\Owner.PETE-05CK9PEMS6\Local Settings\Temporary Internet Files\Content.IE5\UPDD8FBL\p-01-0VIaSjnOLg[3].gif moved successfully. C:\Documents and Settings\Owner.PETE-05CK9PEMS6\Local Settings\Temporary Internet Files\Content.IE5\UPDD8FBL\p-01-0VIaSjnOLg[4].gif moved successfully. C:\Documents and Settings\Owner.PETE-05CK9PEMS6\Local Settings\Temporary Internet Files\Content.IE5\UPDD8FBL\si[4].htm moved successfully. C:\Documents and Settings\Owner.PETE-05CK9PEMS6\Local Settings\Temporary Internet Files\Content.IE5\UL82QTAT\46805253-48c5-4400-8ca5-e0bd3caf91d9[1] moved successfully. C:\Documents and Settings\Owner.PETE-05CK9PEMS6\Local Settings\Temporary Internet Files\Content.IE5\UL82QTAT\AdDisplayTrackerServlet[3].htm moved successfully. C:\Documents and Settings\Owner.PETE-05CK9PEMS6\Local Settings\Temporary Internet Files\Content.IE5\UL82QTAT\AdDisplayTrackerServlet[4].htm moved successfully. C:\Documents and Settings\Owner.PETE-05CK9PEMS6\Local Settings\Temporary Internet Files\Content.IE5\UL82QTAT\beacon[2].htm moved successfully. C:\Documents and Settings\Owner.PETE-05CK9PEMS6\Local Settings\Temporary Internet Files\Content.IE5\UL82QTAT\beacon[3].htm moved successfully. C:\Documents and Settings\Owner.PETE-05CK9PEMS6\Local Settings\Temporary Internet Files\Content.IE5\UL82QTAT\fpi[1].htm moved successfully. C:\Documents and Settings\Owner.PETE-05CK9PEMS6\Local Settings\Temporary Internet Files\Content.IE5\UL82QTAT\fpi[2].htm moved successfully. C:\Documents and Settings\Owner.PETE-05CK9PEMS6\Local Settings\Temporary Internet Files\Content.IE5\UL82QTAT\index[1].htm moved successfully. C:\Documents and Settings\Owner.PETE-05CK9PEMS6\Local Settings\Temporary Internet Files\Content.IE5\UL82QTAT\net[1].htm moved successfully. C:\Documents and Settings\Owner.PETE-05CK9PEMS6\Local Settings\Temporary Internet Files\Content.IE5\UL82QTAT\net[2].htm moved successfully. C:\Documents and Settings\Owner.PETE-05CK9PEMS6\Local Settings\Temporary Internet Files\Content.IE5\UL82QTAT\rt=ifr[1].htm moved successfully. C:\Documents and Settings\Owner.PETE-05CK9PEMS6\Local Settings\Temporary Internet Files\Content.IE5\UL82QTAT\showad[1].htm moved successfully. C:\Documents and Settings\Owner.PETE-05CK9PEMS6\Local Settings\Temporary Internet Files\Content.IE5\UL82QTAT\zrt_lookup[1].html moved successfully. C:\Documents and Settings\Owner.PETE-05CK9PEMS6\Local Settings\Temporary Internet Files\Content.IE5\N7THXT5V\AdDisplayTrackerServlet[3].htm moved successfully. C:\Documents and Settings\Owner.PETE-05CK9PEMS6\Local Settings\Temporary Internet Files\Content.IE5\N7THXT5V\AdDisplayTrackerServlet[4].htm moved successfully. C:\Documents and Settings\Owner.PETE-05CK9PEMS6\Local Settings\Temporary Internet Files\Content.IE5\N7THXT5V\AdDisplayTrackerServlet[5].htm moved successfully. C:\Documents and Settings\Owner.PETE-05CK9PEMS6\Local Settings\Temporary Internet Files\Content.IE5\N7THXT5V\AdDisplayTrackerServlet[6].htm moved successfully. C:\Documents and Settings\Owner.PETE-05CK9PEMS6\Local Settings\Temporary Internet Files\Content.IE5\N7THXT5V\ads[6].htm moved successfully. C:\Documents and Settings\Owner.PETE-05CK9PEMS6\Local Settings\Temporary Internet Files\Content.IE5\N7THXT5V\fpi[1].htm moved successfully. C:\Documents and Settings\Owner.PETE-05CK9PEMS6\Local Settings\Temporary Internet Files\Content.IE5\N7THXT5V\net[2].htm moved successfully. C:\Documents and Settings\Owner.PETE-05CK9PEMS6\Local Settings\Temporary Internet Files\Content.IE5\N7THXT5V\p-01-0VIaSjnOLg[3].gif moved successfully. C:\Documents and Settings\Owner.PETE-05CK9PEMS6\Local Settings\Temporary Internet Files\Content.IE5\N7THXT5V\p-01-0VIaSjnOLg[4].gif moved successfully. C:\Documents and Settings\Owner.PETE-05CK9PEMS6\Local Settings\Temporary Internet Files\Content.IE5\N7THXT5V\pixel[1].htm moved successfully. C:\Documents and Settings\Owner.PETE-05CK9PEMS6\Local Settings\Temporary Internet Files\Content.IE5\N7THXT5V\pixel[1].png moved successfully. C:\Documents and Settings\Owner.PETE-05CK9PEMS6\Local Settings\Temporary Internet Files\Content.IE5\N7THXT5V\Pug[1].gif moved successfully. C:\Documents and Settings\Owner.PETE-05CK9PEMS6\Local Settings\Temporary Internet Files\Content.IE5\N7THXT5V\SPug[1].htm moved successfully. PendingFileRenameOperations files… Registry entries deleted on Reboot…
Hello pfilighera,


Download ComboFix from the following location:
Link

VERY IMPORTANT !!! Save ComboFix.exe to your Desktop

* IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here
  • Double click on ComboFix.exe & follow the prompts.
As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.
**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.

[external image: Posted Image]

  • Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]

  • Click on Yes, to continue scanning for malware.
When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.
Notes:
1. Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. Do not "re-run" Combofix. If you have a problem, reply back for further instructions.
ComboFix 13-10-09.01 - Owner 10/10/2013 2:31.13.1 - x86
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\documents and settings\All Users.WINDOWS\Application Data\l04z6.pad
c:\documents and settings\Owner\Application Data\uns.tmp
c:\windows\system32\drivers\b660883d10b7f0b1.sys
c:\windows\system32\drivers\etc\hosts.txt
.
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
——-\Legacy_SYSHOST32
——-\Legacy_b660883d10b7f0b1
——-\Service_b660883d10b7f0b1
.
.
((((((((((((((((((((((((( Files Created from 2013-09-10 to 2013-10-10 )))))))))))))))))))))))))))))))
.
.
2013-10-07 23:55 . 2013-10-07 23:55 ——– d—–w- C:\RegBackup
2013-10-07 23:54 . 2013-10-07 23:54 ——– d—–w- c:\program files\Tweaking.com
2013-10-06 19:43 . 2013-10-06 19:44 ——– d—–w- C:\AdwCleaner
2013-10-06 12:53 . 2013-10-06 12:53 ——– d—–w- c:\documents and settings\Administrator.PETE-05CK9PEMS6\Application Data\Malwarebytes
2013-10-06 12:53 . 2013-10-06 12:53 ——– d-sh–w- c:\documents and settings\Administrator.PETE-05CK9PEMS6\PrivacIE
2013-10-06 12:51 . 2013-10-06 12:51 ——– d-sh–w- c:\documents and settings\Administrator.PETE-05CK9PEMS6\IETldCache
2013-09-29 17:09 . 2013-09-29 17:09 ——– d—–w- c:\documents and settings\Owner.PETE-05CK9PEMS6\Application Data\DriverCure
2013-09-29 17:09 . 2013-09-29 17:09 ——– d—–w- c:\documents and settings\Owner.PETE-05CK9PEMS6\Application Data\MyTurboPC.com
2013-09-29 17:07 . 2013-10-03 00:06 ——– d—–w- c:\documents and settings\All Users.WINDOWS\Application Data\MyTurboPC.com
2013-09-24 20:53 . 2013-09-24 20:53 ——– d—–w- c:\program files\Google
2013-09-24 07:46 . 2013-09-05 05:02 7328304 —-a-w- c:\documents and settings\All Users.WINDOWS\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{CD83B699-2EC0-46F7-8F38-D0B4382352C5}\mpengine.dll
2013-09-23 07:46 . 2013-09-05 05:02 7328304 —-a-w- c:\documents and settings\All Users.WINDOWS\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
2013-09-13 16:54 . 2013-09-19 22:57 3723656 —-a-w- c:\windows\system32\FlashPlayerInstaller.exe
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2013-09-19 22:58 . 2012-10-14 12:39 692616 —-a-w- c:\windows\system32\FlashPlayerApp.exe
2013-09-19 22:58 . 2012-01-19 15:45 71048 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2013-08-09 01:56 . 2003-07-16 20:48 386560 —-a-w- c:\windows\system32\themeui.dll
2013-08-08 06:05 . 2005-10-21 20:51 920064 —-a-w- c:\windows\system32\wininet.dll
2013-08-08 06:05 . 2003-07-16 20:32 43520 —-a-w- c:\windows\system32\licmgr10.dll
2013-08-08 06:05 . 2003-07-16 20:30 1469440 —-a-w- c:\windows\system32\inetcpl.cpl
2013-08-08 06:05 . 2003-07-16 20:25 18944 —-a-w- c:\windows\system32\corpol.dll
2013-08-08 01:27 . 2003-07-16 20:51 1877760 —-a-w- c:\windows\system32\win32k.sys
2013-08-08 00:02 . 2004-08-04 05:59 385024 —-a-w- c:\windows\system32\html.iec
2013-08-05 13:30 . 2005-07-26 04:31 1289728 —-a-w- c:\windows\system32\ole32.dll
2013-08-03 18:18 . 2006-10-19 01:47 1543680 ——w- c:\windows\system32\wmvdecod.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MMTray"="c:\program files\Musicmatch\Musicmatch Jukebox\mm_tray.exe" [2006-01-19 110592]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
"AvgUninstallURL"="start http://www.avg.com/ww.special-uninstallati...10.0.1321" [?]
.
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{4F07DA45-8170-4859-9B5F-037EF2970034}"= "c:\progra~1\ONLINE~2\oaevent.dll" [2012-10-02 366440]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\GIDLogonXP]
2011-07-05 14:25 53528 —-a-w- c:\windows\system32\GIDLogonXP.dll
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
@="Service"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users.WINDOWS^Start Menu^Programs^Startup^D-link AirPlus G DWL-G120 Wireless USB.lnk]
path=c:\documents and settings\All Users.WINDOWS\Start Menu\Programs\Startup\D-link AirPlus G DWL-G120 Wireless USB.lnk
backup=c:\windows\pss\D-link AirPlus G DWL-G120 Wireless USB.lnkCommon Startup
.
[HKLM\~\startupfolder\C:^Documents and Settings^Owner.PETE-05CK9PEMS6^Start Menu^Programs^Startup^SpywareGuard.lnk]
path=c:\documents and settings\Owner.PETE-05CK9PEMS6\Start Menu\Programs\Startup\SpywareGuard.lnk
backup=c:\windows\pss\SpywareGuard.lnkStartup
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Advanced SystemCare 5]
2012-05-28 19:56 288128 —-a-w- c:\program files\IObit\Advanced SystemCare 5\ASCTray.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BJLaunchEXE]
2002-03-14 14:41 630784 —-a-w- c:\program files\Canon\BJCard\BJLaunch.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
2008-04-14 00:12 15360 —-a-w- c:\windows\system32\ctfmon.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\GIDDesktop]
2011-07-05 14:24 395528 —-a-w- c:\program files\SFT\GuardedID\GIDD.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HotKeysCmds]
2005-10-19 12:59 126976 —-a-w- c:\windows\system32\hkcmd.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IgfxTray]
2005-10-19 12:59 155648 —-a-w- c:\windows\system32\igfxtray.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Logitech Utility]
2003-11-26 17:50 19968 ——w- c:\windows\LOGI_MWX.EXE
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MimBoot]
2006-01-19 16:06 11776 —-a-w- c:\progra~1\MUSICM~1\MUSICM~1\mimboot.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MMTray]
2006-01-19 16:06 110592 —-a-w- c:\program files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSC]
2013-06-20 21:25 995176 —-a-we c:\program files\Microsoft Security Client\msseces.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
2008-04-14 00:12 1695232 —-a-w- c:\program files\Messenger\msmsgs.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
2013-03-12 11:32 253816 —-a-w- c:\program files\Common Files\Java\Java Update\jusched.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"?etadpug"=2 (0x2)
"WMPNetworkSvc"=3 (0x3)
"SvcOnlineArmor"=3 (0x3)
"OAcat"=2 (0x2)
"N360"=2 (0x2)
"MsMpSvc"=2 (0x2)
"Lavasoft Ad-Aware Service"=2 (0x2)
"JavaQuickStarterService"=2 (0x2)
"idsvc"=3 (0x3)
"Bjmcmng"=2 (0x2)
"AdvancedSystemCareService5"=2 (0x2)
"AdobeFlashPlayerUpdateSvc"=3 (0x3)
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
.
R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [5/21/2009 7:07 AM 64160]
R0 SymDS;Symantec Data Store;c:\windows\system32\drivers\N360\1402000.013\symds.sys [3/17/2013 8:18 PM 368288]
R0 SymEFA;Symantec Extended File Attributes;c:\windows\system32\drivers\N360\1402000.013\symefa.sys [3/17/2013 8:18 PM 927904]
R1 GIDv2;GIDv2;c:\windows\system32\drivers\gidv2.sys [7/4/2012 2:40 PM 25232]
R1 OADevice;OADriver;c:\windows\system32\drivers\OADriver.sys [5/31/2013 8:28 AM 208320]
R1 oahlpXX;Online Armor helper driver;c:\windows\system32\drivers\oahlp32.sys [5/31/2013 8:28 AM 44992]
R1 OAmon;OAmon;c:\windows\system32\drivers\OAmon.sys [5/31/2013 8:28 AM 27648]
R1 OAnet;OAnet;c:\windows\system32\drivers\OAnet.sys [5/31/2013 8:28 AM 31920]
S1 BHDrvx86;BHDrvx86;\??\c:\documents and settings\All Users.WINDOWS\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_20.1.0.24\Definitions\BASHDefs\20130322.001\BHDrvx86.sys –> c:\documents and settings\All Users.WINDOWS\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_20.1.0.24\Definitions\BASHDefs\20130322.001\BHDrvx86.sys [?]
S1 ccSet_N360;Norton Security Suite Settings Manager;c:\windows\system32\drivers\N360\1402000.013\ccsetx86.sys [3/17/2013 8:18 PM 134304]
S1 SymIRON;Symantec Iron Driver;c:\windows\system32\drivers\N360\1402000.013\ironx86.sys [3/17/2013 8:18 PM 175264]
S3 CFcatchme;CFcatchme;\??\c:\combofix\CFcatchme.sys –> c:\combofix\CFcatchme.sys [?]
S3 IDSxpx86;IDSxpx86;\??\c:\documents and settings\All Users.WINDOWS\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_20.1.0.24\Definitions\IPSDefs\20130329.001\IDSxpx86.sys –> c:\documents and settings\All Users.WINDOWS\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_20.1.0.24\Definitions\IPSDefs\20130329.001\IDSxpx86.sys [?]
S4 AdvancedSystemCareService5;Advanced SystemCare Service 5;c:\program files\IObit\Advanced SystemCare 5\ASCService.exe [9/23/2012 1:56 PM 913792]
.
— Other Services/Drivers In Memory —
.
*NewlyCreated* - POLICYAGENT
.
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{9191979D-821C-4EA8-B021-2DA1D859A7C5}-3Reg]
2011-07-05 14:26 435976 —-a-w- c:\program files\SFT\GuardedID\GIDI.exe
.
Contents of the 'Scheduled Tasks' folder
.
2013-10-10 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-10-14 22:58]
.
2013-10-06 c:\windows\Tasks\Microsoft Antimalware Scheduled Scan.job
- c:\program files\Microsoft Security Client\MpCmdRun.exe [2013-06-20 22:05]
.
2013-10-09 c:\windows\Tasks\User_Feed_Synchronization-{96E858C2-BB80-4CA6-A945-5D7F401AA939}.job
- c:\windows\system32\msfeedssync.exe [2006-10-17 08:31]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.yahoo.com/
TCP: DhcpNameServer = 75.75.75.75 75.75.76.76
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2013-10-10 02:50
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes …
.
scanning hidden autostart entries …
.
scanning hidden files …
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\N360]
"ImagePath"="\"c:\program files\Norton Security Suite\Engine\20.2.0.19\ccSvcHst.exe\" /s \"N360\" /m \"c:\program files\Norton Security Suite\Engine\20.2.0.19\diMaster.dll\" /prefetch:1"
.
——————— LOCKED REGISTRY KEYS ———————
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil32_11_8_800_175_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil32_11_8_800_175_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
——————— DLLs Loaded Under Running Processes ———————
.
- - - - - - - > 'winlogon.exe'(440)
c:\windows\system32\GIDLogonXP.dll
c:\windows\system32\GIDHookLogon.dll
c:\windows\system32\GIDBIN1.dll
c:\windows\system32\WININET.dll
.
- - - - - - - > 'explorer.exe'(1396)
c:\windows\system32\WININET.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
———————— Other Running Processes ————————
.
c:\program files\Norton Security Suite\Engine\20.2.0.19\ccSvcHst.exe
.
**************************************************************************
.
Completion time: 2013-10-10 03:05:58 - machine was rebooted
ComboFix-quarantined-files.txt 2013-10-10 07:05
ComboFix2.txt 2012-10-23 02:12
ComboFix3.txt 2011-04-23 16:41
.
Pre-Run: 23,837,122,560 bytes free
Post-Run: 23,828,922,368 bytes free
.
- - End Of File - - AF20771077DFBA9F243D19DAB8C7041F
8F558EB6672622401DA993E1E865C861
Hello pfilighera,


Run OTL.exe
  • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output.
  • Check the boxes beside LOP Check and Purity Check.
  • Under Custom Scan paste this in

    netsvcs
    dir "%systemdrive%\*" /S /A:L /C
    CREATERESTOREPOINT

  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
  • When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.
  • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post it with your next reply.
  • You may need two posts to fit them both in.

———————————–

Run Farbar Service Scanner again.
  • Make sure "Include All Files" option remains checked.
  • Press "Scan".
  • It will create a log (FSS.txt) in the same directory the tool is run.
  • Please copy and paste the log to your reply.
OTL logfile created on: 10/11/2013 7:15:46 PM - Run 7
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Documents and Settings\Owner.PETE-05CK9PEMS6\Desktop
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

638.00 Mb Total Physical Memory | 162.62 Mb Available Physical Memory | 25.49% Memory free
1.52 Gb Paging File | 0.91 Gb Available in Paging File | 60.07% Paging File free
Paging file location(s): C:\pagefile.sys 960 1920 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 37.21 Gb Total Space | 21.72 Gb Free Space | 58.37% Space Free | Partition Type: NTFS

Computer Name: PETE-05CK9PEMS6 | User Name: Owner | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Documents and Settings\Owner.PETE-05CK9PEMS6\Desktop\OTL.exe (OldTimer Tools)
PRC - c:\Program Files\Microsoft Security Client\MsMpEng.exe (Microsoft Corporation)
PRC - C:\Program Files\Microsoft Security Client\msseces.exe (Microsoft Corporation)
PRC - C:\Program Files\Norton Security Suite\Engine\20.2.0.19\ccsvchst.exe (Symantec Corporation)
PRC - C:\Program Files\Online Armor\oahlp.exe (Emsisoft GmbH)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe (Musicmatch, Inc.)


========== Modules (No Company Name) ==========

MOD - C:\Program Files\Java\jre7\bin\jp2iexp.dll ()
MOD - C:\Program Files\Java\jre7\bin\jp2native.dll ()
MOD - C:\Program Files\SpywareGuard\spywareguard.dll ()


========== Services (SafeList) ==========

SRV - (Lavasoft Ad-Aware Service) – C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe File not found
SRV - (HidServ) – %SystemRoot%\System32\hidserv.dll File not found
SRV - (AppMgmt) – %SystemRoot%\System32\appmgmts.dll File not found
SRV - (AdobeFlashPlayerUpdateSvc) – C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe (Adobe Systems Incorporated)
SRV - (MsMpSvc) – c:\Program Files\Microsoft Security Client\MsMpEng.exe (Microsoft Corporation)
SRV - (JavaQuickStarterService) – C:\Program Files\Java\jre7\bin\jqs.exe (Oracle Corporation)
SRV - (N360) – C:\Program Files\Norton Security Suite\Engine\20.2.0.19\ccSvcHst.exe (Symantec Corporation)
SRV - (SvcOnlineArmor) – C:\Program Files\Online Armor\oasrv.exe (Emsisoft GmbH)
SRV - (OAcat) – C:\Program Files\Online Armor\oacat.exe (Emsisoft GmbH)
SRV - (AdvancedSystemCareService5) – C:\Program Files\IObit\Advanced SystemCare 5\ASCService.exe (IObit)
SRV - (Bjmcmng) – C:\Program Files\Canon\BJCard\Bjmcmng.exe (CANON INC.)


========== Driver Services (SafeList) ==========

DRV - (WDICA) – File not found
DRV - (PDRFRAME) – File not found
DRV - (PDRELI) – File not found
DRV - (PDFRAME) – File not found
DRV - (PDCOMP) – File not found
DRV - (PCIDump) – File not found
DRV - (NAVEX15) – C:\Documents and Settings\All Users.WINDOWS\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_20.1.0.24\Definitions\VirusDefs\20130331.016\NAVEX15.SYS File not found
DRV - (NAVENG) – C:\Documents and Settings\All Users.WINDOWS\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_20.1.0.24\Definitions\VirusDefs\20130331.016\NAVENG.SYS File not found
DRV - (lbrtfdc) – File not found
DRV - (IDSxpx86) – C:\Documents and Settings\All Users.WINDOWS\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_20.1.0.24\Definitions\IPSDefs\20130329.001\IDSxpx86.sys File not found
DRV - (i2omgmt) – File not found
DRV - (Changer) – File not found
DRV - (CFcatchme) – C:\ComboFix\CFcatchme.sys File not found
DRV - (catchme) – C:\ComboFix\catchme.sys File not found
DRV - (BHDrvx86) – C:\Documents and Settings\All Users.WINDOWS\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_20.1.0.24\Definitions\BASHDefs\20130322.001\BHDrvx86.sys File not found
DRV - (eeCtrl) – C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys (Symantec Corporation)
DRV - (SymEvent) – C:\WINDOWS\system32\drivers\SYMEVENT.SYS (Symantec Corporation)
DRV - (SRTSP) – C:\WINDOWS\system32\drivers\N360\1402000.013\srtsp.sys (Symantec Corporation)
DRV - (SymEFA) – C:\WINDOWS\system32\drivers\N360\1402000.013\symefa.sys (Symantec Corporation)
DRV - (SymDS) – C:\WINDOWS\system32\drivers\N360\1402000.013\symds.sys (Symantec Corporation)
DRV - (ccSet_N360) – C:\WINDOWS\system32\drivers\N360\1402000.013\ccsetx86.sys (Symantec Corporation)
DRV - (oahlpXX) – C:\WINDOWS\system32\drivers\oahlp32.sys ()
DRV - (OAnet) – C:\WINDOWS\system32\drivers\OAnet.sys (Emsisoft)
DRV - (OAmon) – C:\WINDOWS\system32\drivers\OAmon.sys (Emsisoft)
DRV - (OADevice) – C:\WINDOWS\system32\drivers\OADriver.sys ()
DRV - (SymIRON) – C:\WINDOWS\system32\drivers\N360\1402000.013\ironx86.sys (Symantec Corporation)
DRV - (SYMTDI) – C:\WINDOWS\system32\drivers\N360\1402000.013\symtdi.sys (Symantec Corporation)
DRV - (SRTSPX) – C:\WINDOWS\system32\drivers\N360\1402000.013\srtspx.sys (Symantec Corporation)
DRV - (GIDv2) – C:\WINDOWS\System32\drivers\gidv2.sys (StrikeForce Technologies, Inc.)
DRV - (mfehidk) – C:\WINDOWS\system32\drivers\mfehidk.sys (McAfee, Inc.)
DRV - (mfeavfk) – C:\WINDOWS\system32\drivers\mfeavfk.sys (McAfee, Inc.)
DRV - (mfesmfk) – C:\WINDOWS\system32\drivers\mfesmfk.sys (McAfee, Inc.)
DRV - (mfebopk) – C:\WINDOWS\system32\drivers\mfebopk.sys (McAfee, Inc.)
DRV - (mferkdk) – C:\WINDOWS\system32\drivers\mferkdk.sys (McAfee, Inc.)
DRV - (Lbd) – C:\WINDOWS\system32\drivers\Lbd.sys (Lavasoft AB)
DRV - (LMouFlt2) – C:\WINDOWS\system32\drivers\LMouFlt2.Sys (Logitech, Inc.)
DRV - (L8042pr2) – C:\WINDOWS\system32\drivers\L8042pr2.Sys (Logitech, Inc.)
DRV - (PRISM_A02) – C:\WINDOWS\system32\drivers\PRISMA02.sys (GlobespanVirata, Inc.)
DRV - (bcm4sbxp) – C:\WINDOWS\system32\drivers\bcm4sbxp.sys (Broadcom Corporation)
DRV - (OMCI) – C:\WINDOWS\system32\drivers\omci.sys (Dell Computer Corporation)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\..\SearchScopes,DefaultScope =
IE - HKLM\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKLM\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local;
IE - HKLM\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" =

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
IE - HKCU\..\SearchScopes,DefaultScope =
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..browser.search.defaultenginename: ""
FF - prefs.js..browser.startup.homepage: "http://yahoo.com/"
FF - prefs.js..extensions.enabledAddons: {2D3F3651-74B9-4795-BDEC-6DA2F431CB62}:2012.5.8.4
FF - prefs.js..extensions.enabledAddons: {BBDA0591-3099-440a-AA10-41764D9DB4DB}:11.1.1.5 - 3
FF - user.js - File not found

FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32_11_8_800_168.dll ()
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.21.2: C:\WINDOWS\system32\npDeployJava1.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.21.2: C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{BBDA0591-3099-440a-AA10-41764D9DB4DB}: C:\Documents and Settings\All Users.WINDOWS\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_20.1.0.24\IPSFFPlgn\
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{2D3F3651-74B9-4795-BDEC-6DA2F431CB62}: C:\Documents and Settings\All Users.WINDOWS\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_20.1.0.24\coFFPlgn\

[2010/07/11 14:16:14 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Owner.PETE-05CK9PEMS6\Application Data\Mozilla\Extensions
[2010/07/11 14:16:14 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Owner.PETE-05CK9PEMS6\Application Data\Mozilla\Extensions\[removed]
[2013/04/02 16:18:45 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Owner.PETE-05CK9PEMS6\Application Data\Mozilla\Firefox\Profiles\qjys52r7.default\extensions
[2012/10/16 11:33:24 | 000,000,000 | —D | M] (Yahoo! Toolbar) – C:\Documents and Settings\Owner.PETE-05CK9PEMS6\Application Data\Mozilla\Firefox\Profiles\qjys52r7.default\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1}
[2013/03/17 18:20:17 | 000,000,000 | —D | M] (Advanced SystemCare Surfing Protection) – C:\Documents and Settings\Owner.PETE-05CK9PEMS6\Application Data\Mozilla\Firefox\Profiles\qjys52r7.default\extensions\[removed]
[2013/04/23 20:17:29 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Owner.PETE-05CK9PEMS6\Application Data\Mozilla\Firefox\Profiles\qjys52r7.default\extensions\idvaultaddin@whitesky
[2012/10/13 09:27:40 | 000,020,591 | —- | M] () (No name found) – C:\Documents and Settings\Owner.PETE-05CK9PEMS6\Application Data\Mozilla\Firefox\Profiles\qjys52r7.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}.xpi
File not found (No name found) – C:\DOCUMENTS AND SETTINGS\ALL USERS.WINDOWS\APPLICATION DATA\NORTON\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_6.0.0.145\COFFPLGN
File not found (No name found) – C:\DOCUMENTS AND SETTINGS\ALL USERS.WINDOWS\APPLICATION DATA\NORTON\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_6.0.0.145\IPSFFPLGN

O1 HOSTS File: ([2013/10/10 02:50:22 | 000,000,027 | —- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (SpywareGuardDLBLOCK.CBrowserHelper) - {4A368E80-174F-4872-96B5-0B27DDD11DB2} - C:\Program Files\SpywareGuard\dlprotect.dll ()
O2 - BHO: (Norton Identity Protection) - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files\Norton Security Suite\Engine\20.2.0.19\coieplg.dll (Symantec Corporation)
O2 - BHO: (Norton Vulnerability Protection) - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files\Norton Security Suite\Engine\20.2.0.19\ips\ipsbho.dll (Symantec Corporation)
O2 - BHO: (Java™ Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
O2 - BHO: (WOT Helper) - {C920E44A-7F78-4E64-BDD7-A57026E7FEB7} - C:\Program Files\WOT\WOT.dll ()
O2 - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O3 - HKLM\..\Toolbar: (WOT) - {71576546-354D-41c9-AAE8-31F2EC22BF0D} - C:\Program Files\WOT\WOT.dll ()
O3 - HKLM\..\Toolbar: (Norton Toolbar) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Norton Security Suite\Engine\20.2.0.19\coieplg.dll (Symantec Corporation)
O3 - HKCU\..\Toolbar\WebBrowser: (WOT) - {71576546-354D-41C9-AAE8-31F2EC22BF0D} - C:\Program Files\WOT\WOT.dll ()
O3 - HKCU\..\Toolbar\WebBrowser: (Norton Toolbar) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Norton Security Suite\Engine\20.2.0.19\coieplg.dll (Symantec Corporation)
O4 - HKLM..\Run: [MMTray] C:\Program Files\Musicmatch\Musicmatch Jukebox\mm_tray.exe (Musicmatch, Inc.)
O4 - HKLM..\RunOnce: [AvgUninstallURL] C:\WINDOWS\System32\cmd.exe (Microsoft Corporation)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O16 - DPF: {01012101-5E80-11D8-9E86-0007E96C65AE} http://www.comcastsupport.com/oneclickfix/tgctlsr.cab (SupportSoft Script Runner Class)
O16 - DPF: {31435657-9980-0010-8000-00AA00389B71} http://download.microsoft.com/download/e/2…78f/wvc1dmo.cab (Reg Error: Key error.)
O16 - DPF: {33564D57-0000-0010-8000-00AA00389B71} http://download.microsoft.com/download/F/6…922/wmv9VCM.CAB (Reg Error: Key error.)
O16 - DPF: {33564D57-9980-0010-8000-00AA00389B71} http://download.microsoft.com/download/D/0…D0C/wmv9dmo.cab (Reg Error: Key error.)
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} http://update.microsoft.com/windowsupdate/…b?1136593632451 (WUWebControl Class)
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} http://download.eset.com/special/eos-beta/OnlineScanner.cab (Reg Error: Key error.)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 10.21.2)
O16 - DPF: {CAFEEFAC-0016-0000-0030-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_30)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 10.21.2)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab (Shockwave Flash Object)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 75.75.75.75 75.75.76.76
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{45D6A31F-96C2-4D92-B3F2-4ADBAE67D96B}: DhcpNameServer = [removed] [removed]
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{5479463A-91E8-4138-B3CE-765B64CB7D71}: DhcpNameServer = 75.75.75.75 75.75.76.76
O18 - Protocol\Handler\wot {C2A44D6B-CB9F-4663-88A6-DF2F26E4D952} - C:\Program Files\WOT\WOT.dll ()
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) - C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O20 - Winlogon\Notify\GIDLogonXP: DllName - (GIDLogonXP.dll) - C:\WINDOWS\System32\GIDLogonXP.dll (StrikeForce Technologies Inc)
O20 - Winlogon\Notify\igfxcui: DllName - (igfxsrvc.dll) - C:\WINDOWS\System32\igfxsrvc.dll (Intel Corporation)
O24 - Desktop WallPaper: C:\Documents and Settings\Owner.PETE-05CK9PEMS6\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Owner.PETE-05CK9PEMS6\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O28 - HKLM ShellExecuteHooks: {4F07DA45-8170-4859-9B5F-037EF2970034} - C:\Program Files\Online Armor\oaevent.dll (Emsisoft GmbH)
O28 - HKLM ShellExecuteHooks: {81559C35-8464-49F7-BB0E-07A383BEF910} - C:\Program Files\SpywareGuard\spywareguard.dll ()
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2005/12/31 15:30:52 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O34 - HKLM BootExecute: (lsdelete)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = ComFile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)

NetSvcs: 6to4 - File not found
NetSvcs: AppMgmt - %SystemRoot%\System32\appmgmts.dll File not found
NetSvcs: HidServ - %SystemRoot%\System32\hidserv.dll File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found

CREATERESTOREPOINT
Restore point Set: OTL Restore Point

========== Files/Folders - Created Within 30 Days ==========

[2013/10/10 06:27:34 | 000,025,088 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\hidparse.sys
[2013/10/10 06:27:34 | 000,014,976 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\usbscan.sys
[2013/10/10 06:27:33 | 000,123,008 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\usbvideo.sys
[2013/10/10 06:27:33 | 000,060,160 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\usbaudio.sys
[2013/10/10 06:26:40 | 000,144,128 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\usbport.sys
[2013/10/10 06:26:40 | 000,032,384 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\usbccgp.sys
[2013/10/10 06:26:40 | 000,030,336 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\usbehci.sys
[2013/10/10 06:26:40 | 000,005,376 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\usbd.sys
[2013/10/10 03:06:04 | 000,000,000 | —D | C] – C:\WINDOWS\temp
[2013/10/07 20:18:17 | 000,358,923 | —- | C] (Farbar) – C:\Documents and Settings\Owner.PETE-05CK9PEMS6\Desktop\FSS.exe
[2013/10/07 19:55:46 | 000,000,000 | —D | C] – C:\RegBackup
[2013/10/07 19:54:57 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users.WINDOWS\Start Menu\Programs\Tweaking.com
[2013/10/07 19:54:56 | 000,000,000 | —D | C] – C:\Program Files\Tweaking.com
[2013/10/06 16:14:41 | 000,000,000 | —D | C] – C:\Documents and Settings\Owner.PETE-05CK9PEMS6\Desktop\mbar
[2013/10/06 16:07:55 | 012,907,592 | —- | C] (Malwarebytes Corp.) – C:\Documents and Settings\Owner.PETE-05CK9PEMS6\Desktop\mbar-1.07.0.1005.exe
[2013/10/06 15:43:03 | 000,000,000 | —D | C] – C:\AdwCleaner
[2013/09/29 13:09:03 | 000,000,000 | —D | C] – C:\Documents and Settings\Owner.PETE-05CK9PEMS6\Application Data\DriverCure
[2013/09/29 13:09:02 | 000,000,000 | —D | C] – C:\Documents and Settings\Owner.PETE-05CK9PEMS6\Application Data\MyTurboPC.com
[2013/09/29 13:07:35 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users.WINDOWS\Application Data\MyTurboPC.com
[2013/09/24 16:53:37 | 000,000,000 | —D | C] – C:\Program Files\Google
[2013/09/13 12:54:15 | 003,723,656 | —- | C] (Adobe Systems Incorporated) – C:\WINDOWS\System32\FlashPlayerInstaller.exe

========== Files - Modified Within 30 Days ==========

[2013/10/11 18:54:16 | 000,000,830 | —- | M] () – C:\WINDOWS\tasks\Adobe Flash Player Updater.job
[2013/10/11 12:38:20 | 000,000,422 | -H– | M] () – C:\WINDOWS\tasks\User_Feed_Synchronization-{96E858C2-BB80-4CA6-A945-5D7F401AA939}.job
[2013/10/10 17:54:16 | 000,000,384 | -H– | M] () – C:\WINDOWS\tasks\Microsoft Antimalware Scheduled Scan.job
[2013/10/10 17:44:49 | 000,002,206 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2013/10/10 17:43:35 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2013/10/10 17:43:28 | 000,095,072 | —- | M] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2013/10/10 08:21:57 | 000,426,498 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2013/10/10 08:21:57 | 000,065,508 | —- | M] () – C:\WINDOWS\System32\perfc009.dat
[2013/10/10 08:14:12 | 000,001,393 | —- | M] () – C:\WINDOWS\imsins.BAK
[2013/10/10 02:50:22 | 000,000,027 | —- | M] () – C:\WINDOWS\System32\drivers\etc\hosts
[2013/10/09 19:59:57 | 005,131,844 | R— | M] (Swearware) – C:\Documents and Settings\Owner.PETE-05CK9PEMS6\Desktop\ComboFix.exe
[2013/10/07 20:18:18 | 000,358,923 | —- | M] (Farbar) – C:\Documents and Settings\Owner.PETE-05CK9PEMS6\Desktop\FSS.exe
[2013/10/07 19:54:57 | 000,001,876 | —- | M] () – C:\Documents and Settings\All Users.WINDOWS\Desktop\Tweaking.com - Registry Backup.lnk
[2013/10/07 19:53:50 | 003,859,661 | —- | M] () – C:\Documents and Settings\Owner.PETE-05CK9PEMS6\Desktop\tweaking.com_registry_backup_setup.exe
[2013/10/06 17:28:52 | 000,000,335 | —- | M] () – C:\local.conf
[2013/10/06 16:08:06 | 012,907,592 | —- | M] (Malwarebytes Corp.) – C:\Documents and Settings\Owner.PETE-05CK9PEMS6\Desktop\mbar-1.07.0.1005.exe
[2013/10/06 15:41:54 | 001,045,226 | —- | M] () – C:\Documents and Settings\Owner.PETE-05CK9PEMS6\Desktop\AdwCleaner.exe
[2013/10/06 15:35:05 | 000,891,167 | —- | M] () – C:\Documents and Settings\Owner.PETE-05CK9PEMS6\Desktop\SecurityCheck.exe
[2013/10/05 20:57:43 | 000,000,664 | —- | M] () – C:\WINDOWS\System32\d3d9caps.dat
[2013/09/29 13:18:26 | 000,602,112 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Owner.PETE-05CK9PEMS6\Desktop\OTL.exe
[2013/09/29 12:48:31 | 000,001,954 | —- | M] () – C:\WINDOWS\epplauncher.mif
[2013/09/29 08:30:31 | 011,233,112 | —- | M] (Microsoft Corporation) – C:\Documents and Settings\Owner.PETE-05CK9PEMS6\Desktop\mseinstall.exe
[2013/09/27 21:12:58 | 000,000,000 | —- | M] () – C:\Documents and Settings\Owner.PETE-05CK9PEMS6\Desktop\image1.jpeg
[2013/09/27 21:11:50 | 000,000,000 | —- | M] () – C:\Documents and Settings\Owner.PETE-05CK9PEMS6\image (8).jpeg
[2013/09/27 21:11:15 | 000,000,000 | —- | M] () – C:\Documents and Settings\Owner.PETE-05CK9PEMS6\image (7).jpeg
[2013/09/27 21:11:03 | 000,000,000 | —- | M] () – C:\Documents and Settings\Owner.PETE-05CK9PEMS6\image (6).jpeg
[2013/09/27 21:10:56 | 000,000,000 | —- | M] () – C:\Documents and Settings\Owner.PETE-05CK9PEMS6\image (5).jpeg
[2013/09/27 21:08:47 | 000,000,000 | —- | M] () – C:\Documents and Settings\Owner.PETE-05CK9PEMS6\image (4).jpeg
[2013/09/27 21:08:43 | 000,000,000 | —- | M] () – C:\Documents and Settings\Owner.PETE-05CK9PEMS6\image (3).jpeg
[2013/09/27 21:08:37 | 000,000,000 | —- | M] () – C:\Documents and Settings\Owner.PETE-05CK9PEMS6\image (2).jpeg
[2013/09/27 21:08:33 | 000,000,000 | —- | M] () – C:\Documents and Settings\Owner.PETE-05CK9PEMS6\image (1).jpeg
[2013/09/27 21:08:20 | 000,000,000 | —- | M] () – C:\Documents and Settings\Owner.PETE-05CK9PEMS6\image.jpeg
[2013/09/23 23:36:50 | 000,174,592 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\ie4uinit.exe
[2013/09/23 23:36:50 | 000,174,592 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\ie4uinit.exe
[2013/09/23 14:33:58 | 001,215,488 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\urlmon.dll
[2013/09/23 14:33:58 | 000,920,064 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\wininet.dll
[2013/09/23 14:33:58 | 000,759,296 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\vgx.dll
[2013/09/23 14:33:58 | 000,611,840 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\mstime.dll
[2013/09/23 14:33:58 | 000,611,840 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\mstime.dll
[2013/09/23 14:33:58 | 000,206,848 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\occache.dll
[2013/09/23 14:33:58 | 000,105,984 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\url.dll
[2013/09/23 14:33:58 | 000,105,984 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\url.dll
[2013/09/23 14:33:58 | 000,067,072 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\mshtmled.dll
[2013/09/23 14:33:57 | 011,113,472 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\ieframe.dll
[2013/09/23 14:33:57 | 006,017,536 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\mshtml.dll
[2013/09/23 14:33:57 | 002,006,016 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\iertutil.dll
[2013/09/23 14:33:57 | 001,469,440 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\inetcpl.cpl
[2013/09/23 14:33:57 | 001,469,440 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\inetcpl.cpl
[2013/09/23 14:33:57 | 000,630,272 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\msfeeds.dll
[2013/09/23 14:33:57 | 000,630,272 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\msfeeds.dll
[2013/09/23 14:33:57 | 000,522,240 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\jsdbgui.dll
[2013/09/23 14:33:57 | 000,184,320 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\iepeers.dll
[2013/09/23 14:33:57 | 000,184,320 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\iepeers.dll
[2013/09/23 14:33:57 | 000,055,296 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\msfeedsbs.dll
[2013/09/23 14:33:57 | 000,055,296 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\msfeedsbs.dll
[2013/09/23 14:33:57 | 000,043,520 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\licmgr10.dll
[2013/09/23 14:33:57 | 000,043,520 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\licmgr10.dll
[2013/09/23 14:33:57 | 000,025,600 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\jsproxy.dll
[2013/09/23 14:33:57 | 000,025,600 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\jsproxy.dll
[2013/09/23 14:33:56 | 000,743,424 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\iedvtool.dll
[2013/09/23 14:33:56 | 000,387,584 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\iedkcs32.dll
[2013/09/23 14:33:56 | 000,387,584 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\iedkcs32.dll
[2013/09/23 14:33:56 | 000,018,944 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\corpol.dll
[2013/09/23 14:33:56 | 000,018,944 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\corpol.dll
[2013/09/23 14:06:48 | 000,385,024 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\html.iec
[2013/09/19 18:58:03 | 000,692,616 | —- | M] (Adobe Systems Incorporated) – C:\WINDOWS\System32\FlashPlayerApp.exe
[2013/09/19 18:58:02 | 000,071,048 | —- | M] (Adobe Systems Incorporated) – C:\WINDOWS\System32\FlashPlayerCPLApp.cpl
[2013/09/19 18:57:23 | 003,723,656 | —- | M] (Adobe Systems Incorporated) – C:\WINDOWS\System32\FlashPlayerInstaller.exe

========== Files Created - No Company Name ==========

[2013/10/07 19:54:57 | 000,001,876 | —- | C] () – C:\Documents and Settings\All Users.WINDOWS\Desktop\Tweaking.com - Registry Backup.lnk
[2013/10/07 19:53:45 | 003,859,661 | —- | C] () – C:\Documents and Settings\Owner.PETE-05CK9PEMS6\Desktop\tweaking.com_registry_backup_setup.exe
[2013/10/06 16:18:01 | 000,000,335 | —- | C] () – C:\local.conf
[2013/10/06 15:35:03 | 000,891,167 | —- | C] () – C:\Documents and Settings\Owner.PETE-05CK9PEMS6\Desktop\SecurityCheck.exe
[2013/10/05 14:12:34 | 000,000,664 | —- | C] () – C:\WINDOWS\System32\d3d9caps.dat
[2013/09/27 21:12:58 | 000,000,000 | —- | C] () – C:\Documents and Settings\Owner.PETE-05CK9PEMS6\Desktop\image1.jpeg
[2013/09/27 21:11:50 | 000,000,000 | —- | C] () – C:\Documents and Settings\Owner.PETE-05CK9PEMS6\image (8).jpeg
[2013/09/27 21:11:15 | 000,000,000 | —- | C] () – C:\Documents and Settings\Owner.PETE-05CK9PEMS6\image (7).jpeg
[2013/09/27 21:11:03 | 000,000,000 | —- | C] () – C:\Documents and Settings\Owner.PETE-05CK9PEMS6\image (6).jpeg
[2013/09/27 21:10:56 | 000,000,000 | —- | C] () – C:\Documents and Settings\Owner.PETE-05CK9PEMS6\image (5).jpeg
[2013/09/27 21:08:47 | 000,000,000 | —- | C] () – C:\Documents and Settings\Owner.PETE-05CK9PEMS6\image (4).jpeg
[2013/09/27 21:08:43 | 000,000,000 | —- | C] () – C:\Documents and Settings\Owner.PETE-05CK9PEMS6\image (3).jpeg
[2013/09/27 21:08:37 | 000,000,000 | —- | C] () – C:\Documents and Settings\Owner.PETE-05CK9PEMS6\image (2).jpeg
[2013/09/27 21:08:33 | 000,000,000 | —- | C] () – C:\Documents and Settings\Owner.PETE-05CK9PEMS6\image (1).jpeg
[2013/09/27 21:08:20 | 000,000,000 | —- | C] () – C:\Documents and Settings\Owner.PETE-05CK9PEMS6\image.jpeg
[2013/05/31 08:28:26 | 000,044,992 | —- | C] () – C:\WINDOWS\System32\drivers\oahlp32.sys
[2013/05/31 08:28:25 | 000,208,320 | —- | C] () – C:\WINDOWS\System32\drivers\OADriver.sys
[2013/02/21 06:24:49 | 095,023,320 | —- | C] () – C:\Documents and Settings\All Users.WINDOWS\Application Data\6040285.pad
[2012/10/18 19:51:10 | 000,256,000 | —- | C] () – C:\WINDOWS\PEV.exe
[2012/10/18 19:51:10 | 000,208,896 | —- | C] () – C:\WINDOWS\MBR.exe
[2012/10/18 19:51:10 | 000,098,816 | —- | C] () – C:\WINDOWS\sed.exe
[2012/10/18 19:51:10 | 000,080,412 | —- | C] () – C:\WINDOWS\grep.exe
[2012/10/18 19:51:10 | 000,068,096 | —- | C] () – C:\WINDOWS\zip.exe
[2012/02/15 07:24:01 | 000,003,072 | —- | C] () – C:\WINDOWS\System32\iacenc.dll
[2009/02/06 19:55:45 | 000,076,288 | —- | C] () – C:\Documents and Settings\Owner.PETE-05CK9PEMS6\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini

========== ZeroAccess Check ==========

[2012/07/04 14:15:49 | 000,000,227 | RHS- | M] () – C:\WINDOWS\assembly\Desktop.ini

[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]

[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shdocvw.dll – [2008/04/13 20:12:05 | 001,499,136 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll – [2009/02/09 08:10:48 | 000,473,600 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
"" = %systemroot%\system32\wbem\wbemess.dll – [2008/04/13 20:12:08 | 000,273,920 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Both

========== LOP Check ==========

[2012/06/13 03:26:33 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users.WINDOWS\Application Data\AVG2012
[2010/10/16 09:16:02 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users.WINDOWS\Application Data\avg9
[2010/10/16 09:30:31 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users.WINDOWS\Application Data\Common Files
[2013/03/17 18:20:17 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users.WINDOWS\Application Data\IObit
[2012/07/04 14:46:00 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users.WINDOWS\Application Data\IsolatedStorage
[2009/01/23 21:15:39 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users.WINDOWS\Application Data\MailFrontier
[2013/09/29 12:44:08 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users.WINDOWS\Application Data\MFAData
[2013/10/02 20:06:30 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users.WINDOWS\Application Data\MyTurboPC.com
[2013/05/31 08:48:06 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users.WINDOWS\Application Data\OnlineArmor
[2013/04/02 18:09:12 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users.WINDOWS\Application Data\Privacyware
[2012/07/04 14:12:21 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users.WINDOWS\Application Data\White Sky, Inc
[2009/06/06 08:11:58 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users.WINDOWS\Application Data\WinZip
[2010/06/11 08:52:08 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner.PETE-05CK9PEMS6\Application Data\Auslogics
[2011/09/24 13:20:31 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner.PETE-05CK9PEMS6\Application Data\AVG2012
[2013/09/29 13:09:03 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner.PETE-05CK9PEMS6\Application Data\DriverCure
[2013/04/02 16:45:40 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner.PETE-05CK9PEMS6\Application Data\ID Vault
[2012/06/06 15:14:05 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner.PETE-05CK9PEMS6\Application Data\Incredibar.com
[2013/03/17 16:36:04 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner.PETE-05CK9PEMS6\Application Data\IObit
[2006/03/19 19:48:06 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner.PETE-05CK9PEMS6\Application Data\Musicmatch
[2013/09/29 13:09:02 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner.PETE-05CK9PEMS6\Application Data\MyTurboPC.com
[2013/05/31 08:29:59 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner.PETE-05CK9PEMS6\Application Data\OnlineArmor
[2012/03/06 21:14:32 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner.PETE-05CK9PEMS6\Application Data\TweakNow PowerPack 2011

========== Purity Check ==========



========== Custom Scans ==========

< dir "%systemdrive%\*" /S /A:L /C >
Volume in drive C has no label.
Volume Serial Number is 103D-ED2F
Directory of C:\WINDOWS\assembly\GAC_32\System.EnterpriseServices
10/10/2013 08:20 AM 2.0.0.0__b03f5f7f11d50a3a
0 File(s) 0 bytes
Directory of C:\WINDOWS\assembly\GAC_MSIL\IEExecRemote
10/10/2013 08:20 AM 2.0.0.0__b03f5f7f11d50a3a
0 File(s) 0 bytes
Total Files Listed:
0 File(s) 0 bytes
2 Dir(s) 23,297,679,360 bytes free

< End of report >

I did a search for extras.txt and nothing was found. the other file you asked for automatically displayed.

Farbar Service Scanner Version: 13-09-2013
Ran by [removed] (administrator) on 11-10-2013 at 19:42:19
Running from "C:\Documents and Settings\Owner.PETE-05CK9PEMS6\Desktop"
Microsoft Windows XP Home Edition Service Pack 3 (X86)
Boot Mode: Normal
****************************************************************

Internet Services:
============

Connection Status:
==============
Localhost is accessible.
LAN connected.
Google IP is accessible.
Google.com is accessible.
Yahoo.com is accessible.


Windows Firewall:
=============

Firewall Disabled Policy:
==================


System Restore:
============

System Restore Disabled Policy:
========================


Security Center:
============


Windows Update:
============

Windows Autoupdate Disabled Policy:
============================


Other Services:
==============
Checking ServiceDll of RemoteAccess: ATTENTION!=====> Unable to open RemoteAccess registry key. The service key does not exist.



File Check:
========
C:\WINDOWS\system32\dhcpcsvc.dll => MD5 is legit
C:\WINDOWS\system32\Drivers\afd.sys => MD5 is legit
C:\WINDOWS\system32\Drivers\netbt.sys => MD5 is legit
C:\WINDOWS\system32\Drivers\tcpip.sys => MD5 is legit
C:\WINDOWS\system32\Drivers\ipsec.sys => MD5 is legit
C:\WINDOWS\system32\dnsrslvr.dll => MD5 is legit
C:\WINDOWS\system32\ipnathlp.dll => MD5 is legit
C:\WINDOWS\system32\netman.dll => MD5 is legit
C:\WINDOWS\system32\wbem\WMIsvc.dll => MD5 is legit
C:\WINDOWS\system32\srsvc.dll => MD5 is legit
C:\WINDOWS\system32\Drivers\sr.sys => MD5 is legit
C:\WINDOWS\system32\wscsvc.dll => MD5 is legit
C:\WINDOWS\system32\wbem\WMIsvc.dll => MD5 is legit
C:\WINDOWS\system32\wuauserv.dll => MD5 is legit
C:\WINDOWS\system32\qmgr.dll => MD5 is legit
C:\WINDOWS\system32\es.dll => MD5 is legit
C:\WINDOWS\system32\cryptsvc.dll => MD5 is legit
C:\WINDOWS\system32\svchost.exe => MD5 is legit
C:\WINDOWS\system32\rpcss.dll => MD5 is legit
C:\WINDOWS\system32\services.exe => MD5 is legit

Extra List:
=======
Gpc(3) IPSec(5) NetBT(6) OAmon(16) SYMTDI(15) Tcpip(4)
0x07000000050000000300000004000000100000000F0000000600000007000000
IpSec Tag value is correct.

**** End of log ****
Hello pfilighera,


please download the following file and save it to your Desktop:
(Direct links only available)

RemoteAccess:

Restart the computer.


———————————

Run OTL.exe
  • Copy/paste the following text written inside of the code box into the Custom Scans/Fixes box located at the bottom of OTL

    :OTL
    [2012/11/06 17:06:55 | 000,031,816 | —- | M] () – C:\{0F965B62-B635-4ABE-A5E1-8777DD9208D6}
    [2012/11/03 04:38:13 | 000,032,096 | —- | M] () – C:\{104EF115-17E4-42F3-A4A8-073F1BB5854B}
    [2012/10/31 17:43:17 | 000,032,144 | —- | M] () – C:\{2EF32154-D389-4EE7-888C-72CE6353A6B7}
    [2012/10/10 23:45:13 | 000,031,776 | —- | M] () – C:\{3CAB558C-0424-4399-AC7E-182613966719}
    [2013/03/08 04:39:40 | 000,033,376 | —- | M] () – C:\{5D48279C-082F-4796-8A19-DDF1B97192A6}
    [2012/11/03 05:06:37 | 000,032,256 | —- | M] () – C:\{5EDAF753-B854-4D94-A952-35C6EA497E53}
    [2012/12/26 17:41:57 | 000,032,568 | —- | M] () – C:\{6448E133-C6E1-4F40-99AA-F68C3073008A}
    [2013/02/25 12:01:20 | 000,031,920 | —- | M] () – C:\{AA80D7A4-F196-4A4F-8959-07671B597D00}
    [2013/03/03 03:32:57 | 000,032,728 | —- | M] () – C:\{AAA5D437-BD88-4957-84AA-F625EF3C997F}
    [2012/12/27 00:21:01 | 000,031,888 | —- | M] () – C:\{B4089FB0-9E92-4BF4-9D7A-C8C720C58D9C}
    [2013/02/25 12:37:26 | 000,033,296 | —- | M] () – C:\{B5EAAE70-CD2C-4514-A34D-5532D05FD675}
    [2012/10/31 10:40:58 | 000,032,408 | —- | M] () – C:\{BB64D130-35BB-4983-8332-C15F15D0DD78}
    [2012/10/22 20:18:41 | 000,002,608 | —- | M] () – C:\{C14588FA-2D5F-401D-B9FF-FBD3B8BDFB0C}
    [2012/10/25 17:01:02 | 000,002,608 | —- | M] () – C:\{C6D62A8E-7509-4558-81FB-F118214A5C0F}
    [2012/11/05 00:41:02 | 000,032,080 | —- | M] () – C:\{CF641E0E-D774-46A2-9D74-15C385994FF4}
    [2012/10/19 15:02:13 | 000,031,704 | —- | M] () – C:\{D1179989-863E-4374-ABF6-3EACA2F2FD20}
    [2013/02/26 04:49:24 | 000,033,216 | —- | M] () – C:\{D90118D2-3CCC-4E8F-AAB3-8309FDBE40BD}
    [2013/03/08 05:24:37 | 000,033,368 | —- | M] () – C:\{D9D0D70F-C25A-4E72-950A-DB4122D3B896}
    [2012/10/19 14:04:38 | 000,031,696 | —- | M] () – C:\{F765599A-AF2E-4919-8ECD-E0D9E979E54F}
    
    :Reg
    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
    "?etadpug"=-
     
    :Commands
    [emptytemp]
    [Reboot]
  • Then click the Run Fix button at the top
  • Let the program run unhindered, reboot when it is done
  • Then post Fix OTL log as well as a new OTL log by rerunning it after reboot without custom scans script.

———————————–

Run Security Check again.
  • Double click SecurityCheck.exe and follow the onscreen instructions inside of the black box.
  • A Notepad document should open automatically called checkup.txt; please post the contents of that document.
OTL logfile created on: 10/13/2013 1:54:09 PM - Run 8
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Documents and Settings\Owner.PETE-05CK9PEMS6\Desktop
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

638.00 Mb Total Physical Memory | 278.10 Mb Available Physical Memory | 43.59% Memory free
1.52 Gb Paging File | 1.21 Gb Available in Paging File | 79.48% Paging File free
Paging file location(s): C:\pagefile.sys 960 1920 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 37.21 Gb Total Space | 21.80 Gb Free Space | 58.60% Space Free | Partition Type: NTFS

Computer Name: PETE-05CK9PEMS6 | User Name: Owner | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Documents and Settings\Owner.PETE-05CK9PEMS6\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe (Adobe Systems Incorporated)
PRC - c:\Program Files\Microsoft Security Client\MsMpEng.exe (Microsoft Corporation)
PRC - C:\Program Files\Norton Security Suite\Engine\20.2.0.19\ccsvchst.exe (Symantec Corporation)
PRC - C:\Program Files\Outlook Express\msimn.exe (Microsoft Corporation)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe (Musicmatch, Inc.)


========== Modules (No Company Name) ==========

MOD - C:\Program Files\SpywareGuard\spywareguard.dll ()


========== Services (SafeList) ==========

SRV - (Lavasoft Ad-Aware Service) – C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe File not found
SRV - (HidServ) – %SystemRoot%\System32\hidserv.dll File not found
SRV - (AppMgmt) – %SystemRoot%\System32\appmgmts.dll File not found
SRV - (AdobeFlashPlayerUpdateSvc) – C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe (Adobe Systems Incorporated)
SRV - (MsMpSvc) – c:\Program Files\Microsoft Security Client\MsMpEng.exe (Microsoft Corporation)
SRV - (JavaQuickStarterService) – C:\Program Files\Java\jre7\bin\jqs.exe (Oracle Corporation)
SRV - (N360) – C:\Program Files\Norton Security Suite\Engine\20.2.0.19\ccSvcHst.exe (Symantec Corporation)
SRV - (SvcOnlineArmor) – C:\Program Files\Online Armor\oasrv.exe (Emsisoft GmbH)
SRV - (OAcat) – C:\Program Files\Online Armor\oacat.exe (Emsisoft GmbH)
SRV - (AdvancedSystemCareService5) – C:\Program Files\IObit\Advanced SystemCare 5\ASCService.exe (IObit)
SRV - (Bjmcmng) – C:\Program Files\Canon\BJCard\Bjmcmng.exe (CANON INC.)


========== Driver Services (SafeList) ==========

DRV - (WDICA) – File not found
DRV - (PDRFRAME) – File not found
DRV - (PDRELI) – File not found
DRV - (PDFRAME) – File not found
DRV - (PDCOMP) – File not found
DRV - (PCIDump) – File not found
DRV - (NAVEX15) – C:\Documents and Settings\All Users.WINDOWS\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_20.1.0.24\Definitions\VirusDefs\20130331.016\NAVEX15.SYS File not found
DRV - (NAVENG) – C:\Documents and Settings\All Users.WINDOWS\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_20.1.0.24\Definitions\VirusDefs\20130331.016\NAVENG.SYS File not found
DRV - (MpKslb03e90c5) – c:\Documents and Settings\All Users.WINDOWS\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{A9AD291C-4824-4365-82BA-EAC5CB037AE7}\MpKslb03e90c5.sys File not found
DRV - (lbrtfdc) – File not found
DRV - (IDSxpx86) – C:\Documents and Settings\All Users.WINDOWS\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_20.1.0.24\Definitions\IPSDefs\20130329.001\IDSxpx86.sys File not found
DRV - (i2omgmt) – File not found
DRV - (Changer) – File not found
DRV - (CFcatchme) – C:\ComboFix\CFcatchme.sys File not found
DRV - (catchme) – C:\ComboFix\catchme.sys File not found
DRV - (BHDrvx86) – C:\Documents and Settings\All Users.WINDOWS\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_20.1.0.24\Definitions\BASHDefs\20130322.001\BHDrvx86.sys File not found
DRV - (eeCtrl) – C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys (Symantec Corporation)
DRV - (SymEvent) – C:\WINDOWS\system32\drivers\SYMEVENT.SYS (Symantec Corporation)
DRV - (SRTSP) – C:\WINDOWS\system32\drivers\N360\1402000.013\srtsp.sys (Symantec Corporation)
DRV - (SymEFA) – C:\WINDOWS\system32\drivers\N360\1402000.013\symefa.sys (Symantec Corporation)
DRV - (SymDS) – C:\WINDOWS\system32\drivers\N360\1402000.013\symds.sys (Symantec Corporation)
DRV - (ccSet_N360) – C:\WINDOWS\system32\drivers\N360\1402000.013\ccsetx86.sys (Symantec Corporation)
DRV - (oahlpXX) – C:\WINDOWS\system32\drivers\oahlp32.sys ()
DRV - (OAnet) – C:\WINDOWS\system32\drivers\OAnet.sys (Emsisoft)
DRV - (OAmon) – C:\WINDOWS\system32\drivers\OAmon.sys (Emsisoft)
DRV - (OADevice) – C:\WINDOWS\system32\drivers\OADriver.sys ()
DRV - (SymIRON) – C:\WINDOWS\system32\drivers\N360\1402000.013\ironx86.sys (Symantec Corporation)
DRV - (SYMTDI) – C:\WINDOWS\system32\drivers\N360\1402000.013\symtdi.sys (Symantec Corporation)
DRV - (SRTSPX) – C:\WINDOWS\system32\drivers\N360\1402000.013\srtspx.sys (Symantec Corporation)
DRV - (GIDv2) – C:\WINDOWS\System32\drivers\gidv2.sys (StrikeForce Technologies, Inc.)
DRV - (mfehidk) – C:\WINDOWS\system32\drivers\mfehidk.sys (McAfee, Inc.)
DRV - (mfeavfk) – C:\WINDOWS\system32\drivers\mfeavfk.sys (McAfee, Inc.)
DRV - (mfesmfk) – C:\WINDOWS\system32\drivers\mfesmfk.sys (McAfee, Inc.)
DRV - (mfebopk) – C:\WINDOWS\system32\drivers\mfebopk.sys (McAfee, Inc.)
DRV - (mferkdk) – C:\WINDOWS\system32\drivers\mferkdk.sys (McAfee, Inc.)
DRV - (Lbd) – C:\WINDOWS\system32\drivers\Lbd.sys (Lavasoft AB)
DRV - (LMouFlt2) – C:\WINDOWS\system32\drivers\LMouFlt2.Sys (Logitech, Inc.)
DRV - (L8042pr2) – C:\WINDOWS\system32\drivers\L8042pr2.Sys (Logitech, Inc.)
DRV - (PRISM_A02) – C:\WINDOWS\system32\drivers\PRISMA02.sys (GlobespanVirata, Inc.)
DRV - (bcm4sbxp) – C:\WINDOWS\system32\drivers\bcm4sbxp.sys (Broadcom Corporation)
DRV - (OMCI) – C:\WINDOWS\system32\drivers\omci.sys (Dell Computer Corporation)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\..\SearchScopes,DefaultScope =
IE - HKLM\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKLM\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local;
IE - HKLM\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" =

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
IE - HKCU\..\SearchScopes,DefaultScope =
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..browser.search.defaultenginename: ""
FF - prefs.js..browser.startup.homepage: "http://yahoo.com/"
FF - prefs.js..extensions.enabledAddons: {2D3F3651-74B9-4795-BDEC-6DA2F431CB62}:2012.5.8.4
FF - prefs.js..extensions.enabledAddons: {BBDA0591-3099-440a-AA10-41764D9DB4DB}:11.1.1.5 - 3
FF - user.js - File not found

FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32_11_8_800_168.dll ()
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.21.2: C:\WINDOWS\system32\npDeployJava1.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.21.2: C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{BBDA0591-3099-440a-AA10-41764D9DB4DB}: C:\Documents and Settings\All Users.WINDOWS\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_20.1.0.24\IPSFFPlgn\
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{2D3F3651-74B9-4795-BDEC-6DA2F431CB62}: C:\Documents and Settings\All Users.WINDOWS\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_20.1.0.24\coFFPlgn\

[2010/07/11 14:16:14 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Owner.PETE-05CK9PEMS6\Application Data\Mozilla\Extensions
[2010/07/11 14:16:14 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Owner.PETE-05CK9PEMS6\Application Data\Mozilla\Extensions\[removed]
[2013/04/02 16:18:45 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Owner.PETE-05CK9PEMS6\Application Data\Mozilla\Firefox\Profiles\qjys52r7.default\extensions
[2012/10/16 11:33:24 | 000,000,000 | —D | M] (Yahoo! Toolbar) – C:\Documents and Settings\Owner.PETE-05CK9PEMS6\Application Data\Mozilla\Firefox\Profiles\qjys52r7.default\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1}
[2013/03/17 18:20:17 | 000,000,000 | —D | M] (Advanced SystemCare Surfing Protection) – C:\Documents and Settings\Owner.PETE-05CK9PEMS6\Application Data\Mozilla\Firefox\Profiles\qjys52r7.default\extensions\[removed]
[2013/04/23 20:17:29 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Owner.PETE-05CK9PEMS6\Application Data\Mozilla\Firefox\Profiles\qjys52r7.default\extensions\idvaultaddin@whitesky
[2012/10/13 09:27:40 | 000,020,591 | —- | M] () (No name found) – C:\Documents and Settings\Owner.PETE-05CK9PEMS6\Application Data\Mozilla\Firefox\Profiles\qjys52r7.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}.xpi
File not found (No name found) – C:\DOCUMENTS AND SETTINGS\ALL USERS.WINDOWS\APPLICATION DATA\NORTON\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_6.0.0.145\COFFPLGN
File not found (No name found) – C:\DOCUMENTS AND SETTINGS\ALL USERS.WINDOWS\APPLICATION DATA\NORTON\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_6.0.0.145\IPSFFPLGN

O1 HOSTS File: ([2013/10/10 02:50:22 | 000,000,027 | —- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (SpywareGuardDLBLOCK.CBrowserHelper) - {4A368E80-174F-4872-96B5-0B27DDD11DB2} - C:\Program Files\SpywareGuard\dlprotect.dll ()
O2 - BHO: (Norton Identity Protection) - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files\Norton Security Suite\Engine\20.2.0.19\coieplg.dll (Symantec Corporation)
O2 - BHO: (Norton Vulnerability Protection) - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files\Norton Security Suite\Engine\20.2.0.19\ips\ipsbho.dll (Symantec Corporation)
O2 - BHO: (Java™ Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
O2 - BHO: (WOT Helper) - {C920E44A-7F78-4E64-BDD7-A57026E7FEB7} - C:\Program Files\WOT\WOT.dll ()
O2 - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O3 - HKLM\..\Toolbar: (WOT) - {71576546-354D-41c9-AAE8-31F2EC22BF0D} - C:\Program Files\WOT\WOT.dll ()
O3 - HKLM\..\Toolbar: (Norton Toolbar) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Norton Security Suite\Engine\20.2.0.19\coieplg.dll (Symantec Corporation)
O3 - HKCU\..\Toolbar\WebBrowser: (WOT) - {71576546-354D-41C9-AAE8-31F2EC22BF0D} - C:\Program Files\WOT\WOT.dll ()
O3 - HKCU\..\Toolbar\WebBrowser: (Norton Toolbar) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Norton Security Suite\Engine\20.2.0.19\coieplg.dll (Symantec Corporation)
O4 - HKLM..\Run: [MMTray] C:\Program Files\Musicmatch\Musicmatch Jukebox\mm_tray.exe (Musicmatch, Inc.)
O4 - HKLM..\RunOnce: [AvgUninstallURL] C:\WINDOWS\System32\cmd.exe (Microsoft Corporation)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O16 - DPF: {01012101-5E80-11D8-9E86-0007E96C65AE} http://www.comcastsupport.com/oneclickfix/tgctlsr.cab (SupportSoft Script Runner Class)
O16 - DPF: {31435657-9980-0010-8000-00AA00389B71} http://download.microsoft.com/download/e/2…78f/wvc1dmo.cab (Reg Error: Key error.)
O16 - DPF: {33564D57-0000-0010-8000-00AA00389B71} http://download.microsoft.com/download/F/6…922/wmv9VCM.CAB (Reg Error: Key error.)
O16 - DPF: {33564D57-9980-0010-8000-00AA00389B71} http://download.microsoft.com/download/D/0…D0C/wmv9dmo.cab (Reg Error: Key error.)
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} http://update.microsoft.com/windowsupdate/…b?1136593632451 (WUWebControl Class)
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} http://download.eset.com/special/eos-beta/OnlineScanner.cab (Reg Error: Key error.)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 10.21.2)
O16 - DPF: {CAFEEFAC-0016-0000-0030-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_30)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 10.21.2)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab (Shockwave Flash Object)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 75.75.75.75 75.75.76.76
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{45D6A31F-96C2-4D92-B3F2-4ADBAE67D96B}: DhcpNameServer = [removed] [removed]
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{5479463A-91E8-4138-B3CE-765B64CB7D71}: DhcpNameServer = 75.75.75.75 75.75.76.76
O18 - Protocol\Handler\wot {C2A44D6B-CB9F-4663-88A6-DF2F26E4D952} - C:\Program Files\WOT\WOT.dll ()
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) - C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O20 - Winlogon\Notify\GIDLogonXP: DllName - (GIDLogonXP.dll) - C:\WINDOWS\System32\GIDLogonXP.dll (StrikeForce Technologies Inc)
O20 - Winlogon\Notify\igfxcui: DllName - (igfxsrvc.dll) - C:\WINDOWS\System32\igfxsrvc.dll (Intel Corporation)
O24 - Desktop WallPaper: C:\Documents and Settings\Owner.PETE-05CK9PEMS6\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Owner.PETE-05CK9PEMS6\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O28 - HKLM ShellExecuteHooks: {4F07DA45-8170-4859-9B5F-037EF2970034} - C:\Program Files\Online Armor\oaevent.dll (Emsisoft GmbH)
O28 - HKLM ShellExecuteHooks: {81559C35-8464-49F7-BB0E-07A383BEF910} - C:\Program Files\SpywareGuard\spywareguard.dll ()
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2005/12/31 15:30:52 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O34 - HKLM BootExecute: (lsdelete)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = ComFile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)

========== Files/Folders - Created Within 30 Days ==========

[2013/10/11 19:38:06 | 000,000,000 | -HSD | C] – C:\RECYCLER
[2013/10/10 06:27:34 | 000,025,088 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\hidparse.sys
[2013/10/10 06:27:34 | 000,014,976 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\usbscan.sys
[2013/10/10 06:27:33 | 000,123,008 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\usbvideo.sys
[2013/10/10 06:27:33 | 000,060,160 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\usbaudio.sys
[2013/10/10 06:26:40 | 000,144,128 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\usbport.sys
[2013/10/10 06:26:40 | 000,032,384 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\usbccgp.sys
[2013/10/10 06:26:40 | 000,030,336 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\usbehci.sys
[2013/10/10 06:26:40 | 000,005,376 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\usbd.sys
[2013/10/10 03:06:04 | 000,000,000 | —D | C] – C:\WINDOWS\temp
[2013/10/07 20:18:17 | 000,358,923 | —- | C] (Farbar) – C:\Documents and Settings\Owner.PETE-05CK9PEMS6\Desktop\FSS.exe
[2013/10/07 19:55:46 | 000,000,000 | —D | C] – C:\RegBackup
[2013/10/07 19:54:57 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users.WINDOWS\Start Menu\Programs\Tweaking.com
[2013/10/07 19:54:56 | 000,000,000 | —D | C] – C:\Program Files\Tweaking.com
[2013/10/06 16:14:41 | 000,000,000 | —D | C] – C:\Documents and Settings\Owner.PETE-05CK9PEMS6\Desktop\mbar
[2013/10/06 16:07:55 | 012,907,592 | —- | C] (Malwarebytes Corp.) – C:\Documents and Settings\Owner.PETE-05CK9PEMS6\Desktop\mbar-1.07.0.1005.exe
[2013/10/06 15:43:03 | 000,000,000 | —D | C] – C:\AdwCleaner
[2013/09/29 13:09:03 | 000,000,000 | —D | C] – C:\Documents and Settings\Owner.PETE-05CK9PEMS6\Application Data\DriverCure
[2013/09/29 13:09:02 | 000,000,000 | —D | C] – C:\Documents and Settings\Owner.PETE-05CK9PEMS6\Application Data\MyTurboPC.com
[2013/09/29 13:07:35 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users.WINDOWS\Application Data\MyTurboPC.com
[2013/09/24 16:53:37 | 000,000,000 | —D | C] – C:\Program Files\Google

========== Files - Modified Within 30 Days ==========

[2013/10/13 14:00:12 | 000,000,384 | -H– | M] () – C:\WINDOWS\tasks\Microsoft Antimalware Scheduled Scan.job
[2013/10/13 13:54:15 | 000,000,830 | —- | M] () – C:\WINDOWS\tasks\Adobe Flash Player Updater.job
[2013/10/13 13:50:26 | 000,002,206 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2013/10/13 13:49:41 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2013/10/13 13:25:59 | 000,023,596 | —- | M] () – C:\Documents and Settings\Owner.PETE-05CK9PEMS6\Desktop\RemoteAccess.reg
[2013/10/13 13:21:53 | 000,000,422 | -H– | M] () – C:\WINDOWS\tasks\User_Feed_Synchronization-{96E858C2-BB80-4CA6-A945-5D7F401AA939}.job
[2013/10/10 17:43:28 | 000,095,072 | —- | M] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2013/10/10 08:21:57 | 000,426,498 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2013/10/10 08:21:57 | 000,065,508 | —- | M] () – C:\WINDOWS\System32\perfc009.dat
[2013/10/10 08:14:12 | 000,001,393 | —- | M] () – C:\WINDOWS\imsins.BAK
[2013/10/10 02:50:22 | 000,000,027 | —- | M] () – C:\WINDOWS\System32\drivers\etc\hosts
[2013/10/09 19:59:57 | 005,131,844 | R— | M] (Swearware) – C:\Documents and Settings\Owner.PETE-05CK9PEMS6\Desktop\ComboFix.exe
[2013/10/07 20:18:18 | 000,358,923 | —- | M] (Farbar) – C:\Documents and Settings\Owner.PETE-05CK9PEMS6\Desktop\FSS.exe
[2013/10/07 19:54:57 | 000,001,876 | —- | M] () – C:\Documents and Settings\All Users.WINDOWS\Desktop\Tweaking.com - Registry Backup.lnk
[2013/10/07 19:53:50 | 003,859,661 | —- | M] () – C:\Documents and Settings\Owner.PETE-05CK9PEMS6\Desktop\tweaking.com_registry_backup_setup.exe
[2013/10/06 17:28:52 | 000,000,335 | —- | M] () – C:\local.conf
[2013/10/06 16:08:06 | 012,907,592 | —- | M] (Malwarebytes Corp.) – C:\Documents and Settings\Owner.PETE-05CK9PEMS6\Desktop\mbar-1.07.0.1005.exe
[2013/10/06 15:41:54 | 001,045,226 | —- | M] () – C:\Documents and Settings\Owner.PETE-05CK9PEMS6\Desktop\AdwCleaner.exe
[2013/10/06 15:35:05 | 000,891,167 | —- | M] () – C:\Documents and Settings\Owner.PETE-05CK9PEMS6\Desktop\SecurityCheck.exe
[2013/10/05 20:57:43 | 000,000,664 | —- | M] () – C:\WINDOWS\System32\d3d9caps.dat
[2013/09/29 13:18:26 | 000,602,112 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Owner.PETE-05CK9PEMS6\Desktop\OTL.exe
[2013/09/29 12:48:31 | 000,001,954 | —- | M] () – C:\WINDOWS\epplauncher.mif
[2013/09/29 08:30:31 | 011,233,112 | —- | M] (Microsoft Corporation) – C:\Documents and Settings\Owner.PETE-05CK9PEMS6\Desktop\mseinstall.exe
[2013/09/27 21:12:58 | 000,000,000 | —- | M] () – C:\Documents and Settings\Owner.PETE-05CK9PEMS6\Desktop\image1.jpeg
[2013/09/27 21:11:50 | 000,000,000 | —- | M] () – C:\Documents and Settings\Owner.PETE-05CK9PEMS6\image (8).jpeg
[2013/09/27 21:11:15 | 000,000,000 | —- | M] () – C:\Documents and Settings\Owner.PETE-05CK9PEMS6\image (7).jpeg
[2013/09/27 21:11:03 | 000,000,000 | —- | M] () – C:\Documents and Settings\Owner.PETE-05CK9PEMS6\image (6).jpeg
[2013/09/27 21:10:56 | 000,000,000 | —- | M] () – C:\Documents and Settings\Owner.PETE-05CK9PEMS6\image (5).jpeg
[2013/09/27 21:08:47 | 000,000,000 | —- | M] () – C:\Documents and Settings\Owner.PETE-05CK9PEMS6\image (4).jpeg
[2013/09/27 21:08:43 | 000,000,000 | —- | M] () – C:\Documents and Settings\Owner.PETE-05CK9PEMS6\image (3).jpeg
[2013/09/27 21:08:37 | 000,000,000 | —- | M] () – C:\Documents and Settings\Owner.PETE-05CK9PEMS6\image (2).jpeg
[2013/09/27 21:08:33 | 000,000,000 | —- | M] () – C:\Documents and Settings\Owner.PETE-05CK9PEMS6\image (1).jpeg
[2013/09/27 21:08:20 | 000,000,000 | —- | M] () – C:\Documents and Settings\Owner.PETE-05CK9PEMS6\image.jpeg
[2013/09/23 23:36:50 | 000,174,592 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\ie4uinit.exe
[2013/09/23 23:36:50 | 000,174,592 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\ie4uinit.exe
[2013/09/23 14:33:58 | 001,215,488 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\urlmon.dll
[2013/09/23 14:33:58 | 000,920,064 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\wininet.dll
[2013/09/23 14:33:58 | 000,759,296 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\vgx.dll
[2013/09/23 14:33:58 | 000,611,840 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\mstime.dll
[2013/09/23 14:33:58 | 000,611,840 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\mstime.dll
[2013/09/23 14:33:58 | 000,206,848 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\occache.dll
[2013/09/23 14:33:58 | 000,105,984 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\url.dll
[2013/09/23 14:33:58 | 000,105,984 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\url.dll
[2013/09/23 14:33:58 | 000,067,072 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\mshtmled.dll
[2013/09/23 14:33:57 | 011,113,472 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\ieframe.dll
[2013/09/23 14:33:57 | 006,017,536 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\mshtml.dll
[2013/09/23 14:33:57 | 002,006,016 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\iertutil.dll
[2013/09/23 14:33:57 | 001,469,440 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\inetcpl.cpl
[2013/09/23 14:33:57 | 001,469,440 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\inetcpl.cpl
[2013/09/23 14:33:57 | 000,630,272 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\msfeeds.dll
[2013/09/23 14:33:57 | 000,630,272 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\msfeeds.dll
[2013/09/23 14:33:57 | 000,522,240 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\jsdbgui.dll
[2013/09/23 14:33:57 | 000,184,320 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\iepeers.dll
[2013/09/23 14:33:57 | 000,184,320 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\iepeers.dll
[2013/09/23 14:33:57 | 000,055,296 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\msfeedsbs.dll
[2013/09/23 14:33:57 | 000,055,296 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\msfeedsbs.dll
[2013/09/23 14:33:57 | 000,043,520 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\licmgr10.dll
[2013/09/23 14:33:57 | 000,043,520 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\licmgr10.dll
[2013/09/23 14:33:57 | 000,025,600 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\jsproxy.dll
[2013/09/23 14:33:57 | 000,025,600 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\jsproxy.dll
[2013/09/23 14:33:56 | 000,743,424 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\iedvtool.dll
[2013/09/23 14:33:56 | 000,387,584 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\iedkcs32.dll
[2013/09/23 14:33:56 | 000,387,584 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\iedkcs32.dll
[2013/09/23 14:33:56 | 000,018,944 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\corpol.dll
[2013/09/23 14:33:56 | 000,018,944 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\corpol.dll
[2013/09/23 14:06:48 | 000,385,024 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\html.iec
[2013/09/19 18:58:03 | 000,692,616 | —- | M] (Adobe Systems Incorporated) – C:\WINDOWS\System32\FlashPlayerApp.exe
[2013/09/19 18:58:02 | 000,071,048 | —- | M] (Adobe Systems Incorporated) – C:\WINDOWS\System32\FlashPlayerCPLApp.cpl
[2013/09/19 18:57:23 | 003,723,656 | —- | M] (Adobe Systems Incorporated) – C:\WINDOWS\System32\FlashPlayerInstaller.exe

========== Files Created - No Company Name ==========

[2013/10/13 13:26:08 | 000,023,596 | —- | C] () – C:\Documents and Settings\Owner.PETE-05CK9PEMS6\Desktop\RemoteAccess.reg
[2013/10/07 19:54:57 | 000,001,876 | —- | C] () – C:\Documents and Settings\All Users.WINDOWS\Desktop\Tweaking.com - Registry Backup.lnk
[2013/10/07 19:53:45 | 003,859,661 | —- | C] () – C:\Documents and Settings\Owner.PETE-05CK9PEMS6\Desktop\tweaking.com_registry_backup_setup.exe
[2013/10/06 16:18:01 | 000,000,335 | —- | C] () – C:\local.conf
[2013/10/06 15:35:03 | 000,891,167 | —- | C] () – C:\Documents and Settings\Owner.PETE-05CK9PEMS6\Desktop\SecurityCheck.exe
[2013/10/05 14:12:34 | 000,000,664 | —- | C] () – C:\WINDOWS\System32\d3d9caps.dat
[2013/09/27 21:12:58 | 000,000,000 | —- | C] () – C:\Documents and Settings\Owner.PETE-05CK9PEMS6\Desktop\image1.jpeg
[2013/09/27 21:11:50 | 000,000,000 | —- | C] () – C:\Documents and Settings\Owner.PETE-05CK9PEMS6\image (8).jpeg
[2013/09/27 21:11:15 | 000,000,000 | —- | C] () – C:\Documents and Settings\Owner.PETE-05CK9PEMS6\image (7).jpeg
[2013/09/27 21:11:03 | 000,000,000 | —- | C] () – C:\Documents and Settings\Owner.PETE-05CK9PEMS6\image (6).jpeg
[2013/09/27 21:10:56 | 000,000,000 | —- | C] () – C:\Documents and Settings\Owner.PETE-05CK9PEMS6\image (5).jpeg
[2013/09/27 21:08:47 | 000,000,000 | —- | C] () – C:\Documents and Settings\Owner.PETE-05CK9PEMS6\image (4).jpeg
[2013/09/27 21:08:43 | 000,000,000 | —- | C] () – C:\Documents and Settings\Owner.PETE-05CK9PEMS6\image (3).jpeg
[2013/09/27 21:08:37 | 000,000,000 | —- | C] () – C:\Documents and Settings\Owner.PETE-05CK9PEMS6\image (2).jpeg
[2013/09/27 21:08:33 | 000,000,000 | —- | C] () – C:\Documents and Settings\Owner.PETE-05CK9PEMS6\image (1).jpeg
[2013/09/27 21:08:20 | 000,000,000 | —- | C] () – C:\Documents and Settings\Owner.PETE-05CK9PEMS6\image.jpeg
[2013/05/31 08:28:26 | 000,044,992 | —- | C] () – C:\WINDOWS\System32\drivers\oahlp32.sys
[2013/05/31 08:28:25 | 000,208,320 | —- | C] () – C:\WINDOWS\System32\drivers\OADriver.sys
[2012/10/18 19:51:10 | 000,256,000 | —- | C] () – C:\WINDOWS\PEV.exe
[2012/10/18 19:51:10 | 000,208,896 | —- | C] () – C:\WINDOWS\MBR.exe
[2012/10/18 19:51:10 | 000,098,816 | —- | C] () – C:\WINDOWS\sed.exe
[2012/10/18 19:51:10 | 000,080,412 | —- | C] () – C:\WINDOWS\grep.exe
[2012/10/18 19:51:10 | 000,068,096 | —- | C] () – C:\WINDOWS\zip.exe
[2012/02/15 07:24:01 | 000,003,072 | —- | C] () – C:\WINDOWS\System32\iacenc.dll
[2009/02/06 19:55:45 | 000,076,288 | —- | C] () – C:\Documents and Settings\Owner.PETE-05CK9PEMS6\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini

========== ZeroAccess Check ==========

[2012/07/04 14:15:49 | 000,000,227 | RHS- | M] () – C:\WINDOWS\assembly\Desktop.ini

[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]

[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shdocvw.dll – [2008/04/13 20:12:05 | 001,499,136 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll – [2009/02/09 08:10:48 | 000,473,600 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
"" = %systemroot%\system32\wbem\wbemess.dll – [2008/04/13 20:12:08 | 000,273,920 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Both

< End of report >


All processes killed
========== OTL ==========
C:\{0F965B62-B635-4ABE-A5E1-8777DD9208D6} moved successfully.
C:\{104EF115-17E4-42F3-A4A8-073F1BB5854B} moved successfully.
C:\{2EF32154-D389-4EE7-888C-72CE6353A6B7} moved successfully.
C:\{3CAB558C-0424-4399-AC7E-182613966719} moved successfully.
C:\{5D48279C-082F-4796-8A19-DDF1B97192A6} moved successfully.
C:\{5EDAF753-B854-4D94-A952-35C6EA497E53} moved successfully.
C:\{6448E133-C6E1-4F40-99AA-F68C3073008A} moved successfully.
C:\{AA80D7A4-F196-4A4F-8959-07671B597D00} moved successfully.
C:\{AAA5D437-BD88-4957-84AA-F625EF3C997F} moved successfully.
C:\{B4089FB0-9E92-4BF4-9D7A-C8C720C58D9C} moved successfully.
C:\{B5EAAE70-CD2C-4514-A34D-5532D05FD675} moved successfully.
C:\{BB64D130-35BB-4983-8332-C15F15D0DD78} moved successfully.
C:\{C14588FA-2D5F-401D-B9FF-FBD3B8BDFB0C} moved successfully.
C:\{C6D62A8E-7509-4558-81FB-F118214A5C0F} moved successfully.
C:\{CF641E0E-D774-46A2-9D74-15C385994FF4} moved successfully.
C:\{D1179989-863E-4374-ABF6-3EACA2F2FD20} moved successfully.
C:\{D90118D2-3CCC-4E8F-AAB3-8309FDBE40BD} moved successfully.
C:\{D9D0D70F-C25A-4E72-950A-DB4122D3B896} moved successfully.
C:\{F765599A-AF2E-4919-8ECD-E0D9E979E54F} moved successfully.
========== REGISTRY ==========
Registry value HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services\\?etadpug not found.
========== COMMANDS ==========

[EMPTYTEMP]

User: Administrator
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes

User: Administrator.PETE-05CK9PEMS6
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes

User: All Users

User: All Users.WINDOWS

User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes

User: Default User.WINDOWS
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes

User: LocalService
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Flash cache emptied: 0 bytes

User: LocalService.NT AUTHORITY
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes

User: LocalService.NT AUTHORITY.000
->Temp folder emptied: 66016 bytes
->Temporary Internet Files folder emptied: 32902 bytes
->Flash cache emptied: 0 bytes

User: NetworkService
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes

User: NetworkService.NT AUTHORITY
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes

User: NetworkService.NT AUTHORITY.000
->Temp folder emptied: 26144 bytes
->Temporary Internet Files folder emptied: 33170 bytes
->Flash cache emptied: 0 bytes

User: Owner
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Flash cache emptied: 0 bytes

User: Owner.PETE-05CK9PEMS6
->Temp folder emptied: 19177461 bytes
->Temporary Internet Files folder emptied: 428290982 bytes
->Java cache emptied: 0 bytes
->FireFox cache emptied: 0 bytes
->Flash cache emptied: 506 bytes

User: Owner.PETE-OZKKR0BYRK
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes

%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32\dllcache .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 42254 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 1776908 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 0 bytes
RecycleBin emptied: 0 bytes

Total Files Cleaned = 429.00 mb


OTL by OldTimer - Version 3.2.69.0 log created on 10132013_133309

Files\Folders moved on Reboot…
C:\Documents and Settings\Owner.PETE-05CK9PEMS6\Local Settings\Temp\JavaDeployReg.log moved successfully.
C:\Documents and Settings\Owner.PETE-05CK9PEMS6\Local Settings\Temporary Internet Files\Content.IE5\P5UUYSC5\ddc[3].htm moved successfully.
C:\Documents and Settings\Owner.PETE-05CK9PEMS6\Local Settings\Temporary Internet Files\Content.IE5\K871SKY3\0R6iPVh2QL_799878439[1].htm moved successfully.
C:\Documents and Settings\Owner.PETE-05CK9PEMS6\Local Settings\Temporary Internet Files\Content.IE5\K871SKY3\beacon[1].htm moved successfully.
C:\Documents and Settings\Owner.PETE-05CK9PEMS6\Local Settings\Temporary Internet Files\Content.IE5\K871SKY3\index[1].htm moved successfully.
C:\Documents and Settings\Owner.PETE-05CK9PEMS6\Local Settings\Temporary Internet Files\Content.IE5\J6J5QIYD\beacon[2].htm moved successfully.
C:\Documents and Settings\Owner.PETE-05CK9PEMS6\Local Settings\Temporary Internet Files\Content.IE5\J6J5QIYD\beacon[3].htm moved successfully.
C:\Documents and Settings\Owner.PETE-05CK9PEMS6\Local Settings\Temporary Internet Files\Content.IE5\J6J5QIYD\zrt_lookup[1].html moved successfully.
C:\Documents and Settings\Owner.PETE-05CK9PEMS6\Local Settings\Temporary Internet Files\Content.IE5\GIDJTOCT\7580879449477645[1].htm moved successfully.
C:\Documents and Settings\Owner.PETE-05CK9PEMS6\Local Settings\Temporary Internet Files\Content.IE5\GIDJTOCT\si[2].htm moved successfully.
C:\Documents and Settings\Owner.PETE-05CK9PEMS6\Local Settings\Temporary Internet Files\Content.IE5\GASNTEUQ\ads[3].htm moved successfully.
C:\Documents and Settings\Owner.PETE-05CK9PEMS6\Local Settings\Temporary Internet Files\Content.IE5\GASNTEUQ\ba[1].htm moved successfully.
C:\Documents and Settings\Owner.PETE-05CK9PEMS6\Local Settings\Temporary Internet Files\Content.IE5\GASNTEUQ\si[2].htm moved successfully.
C:\Documents and Settings\Owner.PETE-05CK9PEMS6\Local Settings\Temporary Internet Files\Content.IE5\CX61P7W4\ads[1].htm moved successfully.
C:\Documents and Settings\Owner.PETE-05CK9PEMS6\Local Settings\Temporary Internet Files\Content.IE5\AO0ACYMN\cms-2c[2].htm moved successfully.
C:\Documents and Settings\Owner.PETE-05CK9PEMS6\Local Settings\Temporary Internet Files\Content.IE5\AO0ACYMN\iframe[1].html moved successfully.

PendingFileRenameOperations files…

Registry entries deleted on Reboot…


I hope i understood your directions. I ran an otl scan after the otl fix. the fix is listed second.

Results of screen317's Security Check version 0.99.74
Windows XP Service Pack 3 x86
Internet Explorer 8
``````````````Antivirus/Firewall Check:``````````````
Windows Firewall Enabled!
Online Armor 6.0
`````````Anti-malware/Other Utilities Check:`````````
SpywareBlaster 4.2
SpywareGuard v2.2
Malwarebytes Anti-Malware version 1.70.0.1100
Out of date Malwarebytes Anti-Malware installed!
CCleaner
Java™ 6 Update 30
Java 7 Update 21
Java version out of Date!
Adobe Flash Player 11.8.800.168
````````Process Check: objlist.exe by Laurent````````
Norton ccSvcHst.exe
Microsoft Security Essentials MSMpEng.exe
`````````````````System Health check`````````````````
Total Fragmentation on Drive C:: 6%
````````````````````End of Log``````````````````````
Hello pfilighera,

I hope i understood your directions. I ran an otl scan after the otl fix. the fix is listed second.

you're working good.

[external image: Posted Image] Please download MiniToolBox, save it to your desktop and run it.

Checkmark the following checkboxes:
  • Flush DNS
  • Report IE Proxy Settings
  • Reset IE Proxy Settings
  • List IP configuration
  • List Winsock Entries
  • List last 10 Event Viewer log
  • List Installed Programs
  • List Devices
  • List Users, Partitions and Memory size.
Click Go and post the result (Result.txt).
A copy of Result.txt will be saved in the same directory the tool is run.

———————————

Double click on AdwCleaner.exe to run the tool again.
  • Click on the Scan button.
  • AdwCleaner will begin to scan your computer like it did before.
  • When the scan has finished, the actual line should say "Pending. Please uncheck elements you do not want to remove". Look through the scan results and uncheck any entries that you do not wish to remove.
  • This time, click on the Clean button.
  • Press OK when asked to close all programs and follow the onscreen prompts.
  • Press OK again to allow AdwCleaner to restart the computer and complete the removal process.
  • After rebooting, a logfile report (AdwCleaner[S0].txt) will open automatically.
  • Copy and paste the contents of that logfile in your next reply.
  • A copy of that logfile will also be saved in the C:\AdwCleaner folder.

———————————

Please download Junkware Removal Tool from HERE and save it to your desktop.
  • Shutdown your antivirus to avoid any potential conflicts.
  • Double-mouse click JRT.exe and run it.
  • JRT will begin to backup your registry and start scanning your system.
  • Please be patient as this can take a while to complete depending on your system's specifications.
  • On completion, the log JRT.txt is saved on your desktop and will automatically open.
Post the contents of JRT.txt into your next reply.

———————————

Run Farbar Service Scanner again.
  • Make sure "Include All Files" option remains checked.
  • Press "Scan".
  • It will create a log (FSS.txt) in the same directory the tool is run.
  • Please copy and paste the log to your reply.
tried to work on his computer tonite doing what you have asked for. performed the mini tool box and then couldn't find my adwcleaner on the computer. moved on to Junkware removal and as soon as it was done, the internet was lost. I checked my computer as we are connected and mine is fine. I checked the wire connecting the two and it seems solid. i turned off and on the router. On the internet page, it says something about diagnose internet problem (or something close) and if i click on it, nothing happens. I checked the network connection page and it appears that we have incoming and outgoing. What do you suggest?
Hello pfilighera,

did you reboot the computer?
If not please try it now.

# Running from : C:\Documents and Settings\Owner.PETE-05CK9PEMS6\Desktop\AdwCleaner.exe

If it is not there, you need to download it again!

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI