Malware and Trojans plus Windows Vista Updates problems [Closed], Malware and Trojans plus Windows Vista Updates problems |
![]() ![]() |
Malware and Trojans plus Windows Vista Updates problems [Closed], Malware and Trojans plus Windows Vista Updates problems |
Nov 1 2009, 01:47 PM
Post
#1
|
|
|
New Member ![]() Posts: 5 OS: Windows Vista |
I am working to repair my aunts PC. I used most of the advice given in your forums on removal and I think I've gotten most of the culprits. However, I am still having problems getting windows updates to "install". Vista SP2 finally installed but other security updates failed.
I am including latest MBAM, RootRepeal, and OTL logs. Thanks for the awesome job you guys do! BEFORE USING YOUR CLEANING GUIDE: Malwarebytes' Anti-Malware 1.41 Database version: 3053 Windows 6.0.6001 Service Pack 1 10/29/2009 12:17:45 PM mbam-log-2009-10-29 (12-17-45).txt Scan type: Quick Scan Objects scanned: 106454 Time elapsed: 8 minute(s), 0 second(s) Memory Processes Infected: 4 Memory Modules Infected: 2 Registry Keys Infected: 99 Registry Values Infected: 10 Registry Data Items Infected: 0 Folders Infected: 28 Files Infected: 184 Memory Processes Infected: C:\ProgramData\05613621\05613621.exe (Rogue.Multiple.H) -> Unloaded process successfully. C:\Windows\ld15.exe (Worm.Koobface) -> Unloaded process successfully. C:\Windows\pp12.exe (Trojan.Agent) -> Unloaded process successfully. C:\Program Files\Gamevance\gamevance32.exe (Adware.Gamevance) -> Unloaded process successfully. Memory Modules Infected: c:\Windows\System32\fio32.dll (Worm.KoobFace) -> Delete on reboot. C:\Program Files\Gamevance\gamevancelib32.dll (Adware.Gamevance) -> Delete on reboot. Registry Keys Infected: HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\fioo32 (Worm.KoobFace) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\fioo32 (Worm.KoobFace) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\aimactivexdll.aimhelper (Adware.DoubleD) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\TypeLib\{d335d84d-61d8-4b5f-9c4e-067dc8b27ed5} (Adware.DoubleD) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\Interface\{42c23154-00fa-4a93-9de9-3eb523cffff6} (Adware.DoubleD) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\CLSID\{2e8e2100-98cb-4aac-9480-63a281acaff5} (Adware.DoubleD) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\aimactivexdll.aimhelper.1 (Adware.DoubleD) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\explorerbar.funexplorer (Adware.DoubleD) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\TypeLib\{ac5ab953-ed25-4f9c-87f0-b086b0178ffa} (Adware.DoubleD) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\Interface\{6160f76a-1992-4b17-a32d-0c706d159105} (Adware.DoubleD) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\CLSID\{25b8d58c-b0cb-46b0-ba64-05b3804e4e86} (Adware.DoubleD) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{25b8d58c-b0cb-46b0-ba64-05b3804e4e86} (Adware.DoubleD) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{25b8d58c-b0cb-46b0-ba64-05b3804e4e86} (Adware.DoubleD) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\explorerbar.funexplorer.1 (Adware.DoubleD) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\explorerbar.funredirector (Adware.DoubleD) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\TypeLib\{883dfc00-8a21-411d-956c-73a4e4b7d16f} (Adware.DoubleD) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\Interface\{480098c6-f6ad-4c61-9b5c-2bae228a34d1} (Adware.DoubleD) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\CLSID\{cdbfb47b-58a8-4111-bf95-06178dce326d} (Adware.DoubleD) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{cdbfb47b-58a8-4111-bf95-06178dce326d} (Adware.DoubleD) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{cdbfb47b-58a8-4111-bf95-06178dce326d} (Adware.DoubleD) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\explorerbar.funredirector.1 (Adware.DoubleD) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\oeactivexdll.desktopbuttonhandler (Adware.DoubleD) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\TypeLib\{0514c9b0-e4c6-4d6b-a3a6-b38bc280b115} (Adware.DoubleD) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\Interface\{3fb17508-0bf4-4fde-845a-323a1052957c} (Adware.DoubleD) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\Interface\{803e73fe-cb73-4d49-8aff-653fd6f44171} (Adware.DoubleD) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\CLSID\{3fb17508-0bf4-4fde-845a-323a1052957c} (Adware.DoubleD) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\CLSID\{51b67a88-02d0-43cb-8d12-5ca3e2d4cf49} (Adware.DoubleD) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\CLSID\{d44cc2fb-77b8-48a5-a5dc-f961f2d258fb} (Adware.DoubleD) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\oeactivexdll.desktopbuttonhandler.1 (Adware.DoubleD) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\oeactivexdll.desktopoeaddin1 (Adware.DoubleD) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\oeactivexdll.desktopoeaddin1.1 (Adware.DoubleD) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\Interface\{2e9937fc-cf2f-4f56-af54-5a6a3dd375cc} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\Interface\{741de825-a6f0-4497-9aa6-8023cf9b0fff} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\Interface\{877f3eab-4462-44df-8475-6064eafd7fbf} (Adware.DoubleD) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\Interface\{cf54be1c-9359-4395-8533-1657cf209cfe} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\TypeLib\{5297e905-1dfb-4a9c-9871-a4f95fd58945} (Adware.DoubleD) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\Interface\{95b92d92-8b7d-4a19-a3f1-43113b4dbcaf} (Adware.DoubleD) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\CLSID\{5617eca9-488d-4ba2-8562-9710b9ab78d2} (Adware.DoubleD) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{5617eca9-488d-4ba2-8562-9710b9ab78d2} (Adware.DoubleD) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\{5617eca9-488d-4ba2-8562-9710b9ab78d2} (Adware.DoubleD) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\AppID\{57aba38e-6535-48f3-99fd-efdc62137c78} (Adware.DoubleD) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\CLSID\{35b8d58c-b0cb-46b0-ba64-05b3804e4e86} (Adware.DoubleD) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\TypeLib\{c28a0312-c403-417b-a425-a915bc0519cd} (Adware.DoubleD) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{35b8d58c-b0cb-46b0-ba64-05b3804e4e86} (Adware.DoubleD) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{35b8d58c-b0cb-46b0-ba64-05b3804e4e86} (Adware.DoubleD) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\CLSID\{147a976f-eee1-4377-8ea7-4716e4cdd239} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\CLSID\{a4730ebe-43a6-443e-9776-36915d323ad3} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\Typelib\{d518921a-4a03-425e-9873-b9a71756821e} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{56256a51-b582-467e-b8d4-7786eda79ae0} (Trojan.Vundo) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{00a6faf1-072e-44cf-8957-5838f569a31d} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{00a6faf6-072e-44cf-8957-5838f569a31d} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{07b18ea1-a523-4961-b6bb-170de4475cca} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{07b18ea9-a523-4961-b6bb-170de4475cca} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{07b18eab-a523-4961-b6bb-170de4475cca} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{25560540-9571-4d7b-9389-0f166788785a} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{9ff05104-b030-46fc-94b8-81276e4e27df} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{1d4db7d2-6ec9-47a3-bd87-1e41684e07bb} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{59c7fc09-1c83-4648-b3e6-003d2bbc7481} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{68af847f-6e91-45dd-9b68-d6a12c30e5d7} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{9170b96c-28d4-4626-8358-27e6caeef907} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{d1a71fa0-ff48-48dd-9b6d-7a13a3e42127} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{ddb1968e-ead6-40fd-8dae-ff14757f60c7} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{f138d901-86f0-4383-99b6-9cdd406036da} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{56256a51-b582-467e-b8d4-7786eda79ae0} (Trojan.Vundo) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{bb05bd70-4605-4829-93fc-ad80d8cc5b66} (Rogue.PerformanceCenter) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\TypeLib\{497dddb6-6eee-4561-9621-b77dc82c1f84} (Rogue.Ascentive) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\Interface\{4e980492-027b-47f1-a7ab-ab086dacbb9e} (Rogue.Ascentive) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\Interface\{5ead8321-fcbb-4c3f-888c-ac373d366c3f} (Rogue.Ascentive) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\CLSID\{31f3cf6e-a71a-4daa-852b-39ac230940b4} (Rogue.Ascentive) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\TypeLib\{22c12739-c111-44c6-9bb7-f335c2a9be2a} (Adware.DoubleD) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\Interface\{edb1a56e-2224-4c79-a4bd-42a39c6e4608} (Adware.DoubleD) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\CLSID\{27ff1ee8-8ccc-49e1-b801-f212e3744e80} (Adware.DoubleD) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\TypeLib\{014c4232-6904-47b9-9144-7e0fb7277444} (Adware.Gamevance) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\Interface\{0ab02d6c-f605-425f-b7cb-b9e96c9faf1e} (Adware.Gamevance) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\Interface\{32864a05-9d09-472c-abd0-081818ec713b} (Adware.Gamevance) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\CLSID\{beac7dc8-e106-4c6a-931e-5a42e7362883} (Adware.Gamevance) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{beac7dc8-e106-4c6a-931e-5a42e7362883} (Adware.Gamevance) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{beac7dc8-e106-4c6a-931e-5a42e7362883} (Adware.Gamevance) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\gamevance (Adware.Gamevance) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\System\CurrentControlSet\Servises (Malware.Trace) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\fio32 (Worm.KoobFace) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\System\CurrentControlSet\Enum\Root\LEGACY_FIO32 (Worm.KoobFace) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\AppID\AIMActiveXDLL.dll (Adware.DoubleD) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\popcaploader.popcaploaderctrl2 (Adware.PopCap) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\popcaploader.popcaploaderctrl2.1 (Adware.PopCap) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\gvtl (Malware.Trace) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\MyWebSearch (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\DoubleD (Adware.DoubleD) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Fun Web Products (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\FunWebProducts (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Media Access Startup (Adware.DoubleD) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\RunDll32Policy\f3ScrCtr.dll (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Multimedia\WMPlayer\Schemes\f3pss (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{16b6279b-9ff5-41fb-8bf9-404324f5dd1f}}_is1 (Adware.DoubleD) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{c5096216-7703-409e-b85a-8a6ee7395128}}_is1 (Adware.DoubleD) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\MyWebSearch (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\MenuExt\&Funband Serach (Adware.DoubleD) -> Quarantined and deleted successfully. HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Internet Explorer\MenuExt\&Funband Serach (Adware.DoubleD) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\SfX (Rootkit.Agent) -> Quarantined and deleted successfully. Registry Values Infected: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\05613621 (Rogue.Multiple.H) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\27352524 (Rogue.Multiple.H) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\sysldtray (Worm.Koobface) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\pp (Trojan.Agent) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar\{5617eca9-488d-4ba2-8562-9710b9ab78d2} (Adware.DoubleD) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla\Firefox\Extensions\{0ba0192d-94a5-45e3-b2b8-3ec5a1a0b5ec} (Adware.DoubleD) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla\Firefox\Extensions\{2224e955-00e9-4613-a844-ce69fccaae91} (Adware.DoubleD) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs\C:\Windows\System32\SysRestore.dll (Rogue.Ascentive) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\fioo32 (Worm.KoobFace) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Gamevance (Adware.Gamevance) -> Quarantined and deleted successfully. Registry Data Items Infected: (No malicious items detected) Folders Infected: C:\ProgramData\05613621 (Rogue.Multiple.H) -> Quarantined and deleted successfully. C:\ProgramData\27352524 (Rogue.Multiple.H) -> Quarantined and deleted successfully. C:\Program Files\DoubleD (Adware.DoubleD) -> Quarantined and deleted successfully. C:\Program Files\DoubleD\GamingHarbor Toolbar (Adware.DoubleD) -> Quarantined and deleted successfully. C:\Program Files\DoubleD\GamingHarbor Toolbar\4.2.4.23050 (Adware.DoubleD) -> Quarantined and deleted successfully. C:\Program Files\DoubleD\GamingHarbor Toolbar\4.2.4.23050\Cache (Adware.DoubleD) -> Quarantined and deleted successfully. C:\Program Files\DoubleD\GamingHarbor Toolbar\4.2.4.23050\Data (Adware.DoubleD) -> Quarantined and deleted successfully. C:\Program Files\DoubleD\GamingHarbor Toolbar\4.2.4.23050\Icons (Adware.DoubleD) -> Quarantined and deleted successfully. C:\Program Files\DoubleD\GamingHarbor Toolbar\4.2.4.23050\Skins (Adware.DoubleD) -> Quarantined and deleted successfully. C:\Program Files\Gamevance (Adware.Gamevance) -> Quarantined and deleted successfully. C:\Program Files\Internet Saving Optimizer (Adware.DoubleD) -> Quarantined and deleted successfully. C:\Program Files\Internet Saving Optimizer\3.7.2.4650 (Adware.DoubleD) -> Quarantined and deleted successfully. C:\Program Files\Internet Saving Optimizer\3.7.2.4650\Data (Adware.DoubleD) -> Quarantined and deleted successfully. C:\Program Files\Internet Saving Optimizer\3.7.2.4650\FF (Adware.DoubleD) -> Quarantined and deleted successfully. C:\Program Files\Internet Saving Optimizer\3.7.2.4650\FF\chrome (Adware.DoubleD) -> Quarantined and deleted successfully. C:\Program Files\Internet Saving Optimizer\3.7.2.4650\FF\chrome\content (Adware.DoubleD) -> Quarantined and deleted successfully. C:\Program Files\Internet Saving Optimizer\3.7.2.4650\FF\components (Adware.DoubleD) -> Quarantined and deleted successfully. C:\Program Files\Media Access Startup (Adware.DoubleD) -> Quarantined and deleted successfully. C:\Program Files\Media Access Startup\2.0.0.1050 (Adware.DoubleD) -> Quarantined and deleted successfully. C:\Program Files\Media Access Startup\2.0.0.1050\Data (Adware.DoubleD) -> Quarantined and deleted successfully. C:\Program Files\Media Access Startup\2.0.0.1050\FF (Adware.DoubleD) -> Quarantined and deleted successfully. C:\Program Files\Media Access Startup\2.0.0.1050\FF\chrome (Adware.DoubleD) -> Quarantined and deleted successfully. C:\Program Files\Media Access Startup\2.0.0.1050\FF\chrome\content (Adware.DoubleD) -> Quarantined and deleted successfully. C:\Program Files\Media Access Startup\2.0.0.1050\FF\components (Adware.DoubleD) -> Quarantined and deleted successfully. C:\Program Files\System Search Dispatcher (Adware.DoubleD) -> Quarantined and deleted successfully. C:\Program Files\System Search Dispatcher\1.4.1.1010 (Adware.DoubleD) -> Quarantined and deleted successfully. C:\Program Files\System Search Dispatcher\1.4.1.1010\Data (Adware.DoubleD) -> Quarantined and deleted successfully. C:\Program Files\Common Files\TSUninstall (Rogue.TotalSecurity) -> Quarantined and deleted successfully. Files Infected: C:\ProgramData\05613621\05613621.exe (Rogue.Multiple.H) -> Quarantined and deleted successfully. C:\ProgramData\27352524\27352524.exe (Rogue.Multiple.H) -> Quarantined and deleted successfully. c:\Windows\System32\fio32.dll (Worm.KoobFace) -> Delete on reboot. C:\Windows\ld15.exe (Worm.Koobface) -> Quarantined and deleted successfully. C:\Windows\pp12.exe (Trojan.Agent) -> Quarantined and deleted successfully. C:\Program Files\DoubleD\GamingHarbor Toolbar\4.2.4.23050\AIMActiveXDLL.dll (Adware.DoubleD) -> Quarantined and deleted successfully. C:\Program Files\Media Access Startup\2.0.0.1050\HPIEAddOn.dll (Adware.DoubleD) -> Quarantined and deleted successfully. C:\Program Files\System Search Dispatcher\1.4.1.1010\ssd.dll (Adware.DoubleD) -> Quarantined and deleted successfully. C:\Program Files\DoubleD\GamingHarbor Toolbar\4.2.4.23050\OEActiveXDLL.dll (Adware.DoubleD) -> Quarantined and deleted successfully. C:\Program Files\DoubleD\GamingHarbor Toolbar\4.2.4.23050\stb0.dll (Adware.DoubleD) -> Quarantined and deleted successfully. C:\Program Files\Internet Saving Optimizer\3.7.2.4650\NPIEAddOn.dll (Adware.DoubleD) -> Quarantined and deleted successfully. C:\Windows\System32\SysRestore.dll (Rogue.Ascentive) -> Quarantined and deleted successfully. C:\Windows\System32\drivers\fio32.sys (Worm.KoobFace) -> Quarantined and deleted successfully. C:\Users\Emma B. Sykes\AppData\Local\Temp\zpskon_1256752495.exe (Trojan.Backdoor) -> Quarantined and deleted successfully. C:\Users\Mariska Sykes\AppData\Local\Temp\dogpile_sub_installer.exe (Trojan.Dropper) -> Quarantined and deleted successfully. C:\Users\Emma B. Sykes\downloads\setup.exe (Worm.Koobface) -> Quarantined and deleted successfully. C:\Windows\freddy72.exe (Trojan.Backdoor) -> Quarantined and deleted successfully. C:\Windows\rdr_1256496045.exe (Trojan.Agent) -> Quarantined and deleted successfully. C:\Windows\rdr_1256747297.exe (Trojan.Agent) -> Quarantined and deleted successfully. C:\Windows\rdr_1256831118.exe (Trojan.Agent) -> Quarantined and deleted successfully. C:\Windows\rdr_1256832111.exe (Trojan.Agent) -> Quarantined and deleted successfully. C:\Windows\rdr_1256832128.exe (Worm.Koobface) -> Quarantined and deleted successfully. C:\Program Files\DoubleD\GamingHarbor Toolbar\4.2.4.23050\AxGifAnimator.dll (Adware.DoubleD) -> Quarantined and deleted successfully. C:\Program Files\DoubleD\GamingHarbor Toolbar\4.2.4.23050\gdiplus.dll (Adware.DoubleD) -> Quarantined and deleted successfully. C:\Program Files\DoubleD\GamingHarbor Toolbar\4.2.4.23050\HookAPINT.dll (Adware.DoubleD) -> Quarantined and deleted successfully. C:\Program Files\DoubleD\GamingHarbor Toolbar\4.2.4.23050\mfc80.dll (Adware.DoubleD) -> Quarantined and deleted successfully. C:\Program Files\DoubleD\GamingHarbor Toolbar\4.2.4.23050\Microsoft.VC80.CRT.manifest (Adware.DoubleD) -> Quarantined and deleted successfully. C:\Program Files\DoubleD\GamingHarbor Toolbar\4.2.4.23050\Microsoft.VC80.MFC.manifest (Adware.DoubleD) -> Quarantined and deleted successfully. C:\Program Files\DoubleD\GamingHarbor Toolbar\4.2.4.23050\msvcr80.dll (Adware.DoubleD) -> Quarantined and deleted successfully. C:\Program Files\DoubleD\GamingHarbor Toolbar\4.2.4.23050\MyDll.dll (Adware.DoubleD) -> Quarantined and deleted successfully. C:\Program Files\DoubleD\GamingHarbor Toolbar\4.2.4.23050\ProductInfo.dll (Adware.DoubleD) -> Quarantined and deleted successfully. C:\Program Files\DoubleD\GamingHarbor Toolbar\4.2.4.23050\Riched20Smiley.dll (Adware.DoubleD) -> Quarantined and deleted successfully. C:\Program Files\DoubleD\GamingHarbor Toolbar\4.2.4.23050\SkinCrafterDll.dll (Adware.DoubleD) -> Quarantined and deleted successfully. C:\Program Files\DoubleD\GamingHarbor Toolbar\4.2.4.23050\stbAol.dll (Adware.DoubleD) -> Quarantined and deleted successfully. C:\Program Files\DoubleD\GamingHarbor Toolbar\4.2.4.23050\stbapp.dll (Adware.DoubleD) -> Quarantined and deleted successfully. C:\Program Files\DoubleD\GamingHarbor Toolbar\4.2.4.23050\stbapp.exe (Adware.DoubleD) -> Quarantined and deleted successfully. C:\Program Files\DoubleD\GamingHarbor Toolbar\4.2.4.23050\stbappHelper.exe (Adware.DoubleD) -> Quarantined and deleted successfully. C:\Program Files\DoubleD\GamingHarbor Toolbar\4.2.4.23050\stbasst.exe (Adware.DoubleD) -> Quarantined and deleted successfully. C:\Program Files\DoubleD\GamingHarbor Toolbar\4.2.4.23050\stbdl.exe (Adware.DoubleD) -> Quarantined and deleted successfully. C:\Program Files\DoubleD\GamingHarbor Toolbar\4.2.4.23050\stbIE.dll (Adware.DoubleD) -> Quarantined and deleted successfully. C:\Program Files\DoubleD\GamingHarbor Toolbar\4.2.4.23050\stbMsn.dll (Adware.DoubleD) -> Quarantined and deleted successfully. C:\Program Files\DoubleD\GamingHarbor Toolbar\4.2.4.23050\stbOL.dll (Adware.DoubleD) -> Quarantined and deleted successfully. C:\Program Files\DoubleD\GamingHarbor Toolbar\4.2.4.23050\stbOLEX.dll (Adware.DoubleD) -> Quarantined and deleted successfully. C:\Program Files\DoubleD\GamingHarbor Toolbar\4.2.4.23050\stbsvc.exe (Adware.DoubleD) -> Quarantined and deleted successfully. C:\Program Files\DoubleD\GamingHarbor Toolbar\4.2.4.23050\stbYahoo8.dll (Adware.DoubleD) -> Quarantined and deleted successfully. C:\Program Files\DoubleD\GamingHarbor Toolbar\4.2.4.23050\stbYahoo9.dll (Adware.DoubleD) -> Quarantined and deleted successfully. C:\Program Files\DoubleD\GamingHarbor Toolbar\4.2.4.23050\Cache\248d6576afce4ee94af42d7350131106.gif (Adware.DoubleD) -> Quarantined and deleted successfully. C:\Program Files\DoubleD\GamingHarbor Toolbar\4.2.4.23050\Cache\24a70fb875fab686b6b3c217612bc07c.gif (Adware.DoubleD) -> Quarantined and deleted successfully. C:\Program Files\DoubleD\GamingHarbor Toolbar\4.2.4.23050\Cache\2afcf6f3f2e19cc42d7f72f3b18b26ef.gif (Adware.DoubleD) -> Quarantined and deleted successfully. C:\Program Files\DoubleD\GamingHarbor Toolbar\4.2.4.23050\Cache\50bffa6936b3e661971a58e3c8bdf4cb.gif (Adware.DoubleD) -> Quarantined and deleted successfully. C:\Program Files\DoubleD\GamingHarbor Toolbar\4.2.4.23050\Cache\default1.dat (Adware.DoubleD) -> Quarantined and deleted successfully. C:\Program Files\DoubleD\GamingHarbor Toolbar\4.2.4.23050\Cache\loading.dat (Adware.DoubleD) -> Quarantined and deleted successfully. C:\Program Files\DoubleD\GamingHarbor Toolbar\4.2.4.23050\Cache\loading.gif (Adware.DoubleD) -> Quarantined and deleted successfully. C:\Program Files\DoubleD\GamingHarbor Toolbar\4.2.4.23050\Data\Module_Cursor.mx (Adware.DoubleD) -> Quarantined and deleted successfully. C:\Program Files\DoubleD\GamingHarbor Toolbar\4.2.4.23050\Data\Module_DailyVideo.mx (Adware.DoubleD) -> Quarantined and deleted successfully. C:\Program Files\DoubleD\GamingHarbor Toolbar\4.2.4.23050\Data\Module_Game.mx (Adware.DoubleD) -> Quarantined and deleted successfully. C:\Program Files\DoubleD\GamingHarbor Toolbar\4.2.4.23050\Data\Module_Glitter.mx (Adware.DoubleD) -> Quarantined and deleted successfully. C:\Program Files\DoubleD\GamingHarbor Toolbar\4.2.4.23050\Data\Module_Logo.mx (Adware.DoubleD) -> Quarantined and deleted successfully. C:\Program Files\DoubleD\GamingHarbor Toolbar\4.2.4.23050\Data\Module_Option.mx (Adware.DoubleD) -> Quarantined and deleted successfully. C:\Program Files\DoubleD\GamingHarbor Toolbar\4.2.4.23050\Data\Module_Recipe.mx (Adware.DoubleD) -> Quarantined and deleted successfully. C:\Program Files\DoubleD\GamingHarbor Toolbar\4.2.4.23050\Data\Module_Ringtone.mx (Adware.DoubleD) -> Quarantined and deleted successfully. C:\Program Files\DoubleD\GamingHarbor Toolbar\4.2.4.23050\Data\Module_Screensaver.mx (Adware.DoubleD) -> Quarantined and deleted successfully. C:\Program Files\DoubleD\GamingHarbor Toolbar\4.2.4.23050\Data\Module_Search.mx (Adware.DoubleD) -> Quarantined and deleted successfully. C:\Program Files\DoubleD\GamingHarbor Toolbar\4.2.4.23050\Data\Module_Smiley.mx (Adware.DoubleD) -> Quarantined and deleted successfully. C:\Program Files\DoubleD\GamingHarbor Toolbar\4.2.4.23050\Data\Module_Smiley_Config.mx (Adware.DoubleD) -> Quarantined and deleted successfully. C:\Program Files\DoubleD\GamingHarbor Toolbar\4.2.4.23050\Data\Module_Smiley_TellAFriend.mx (Adware.DoubleD) -> Quarantined and deleted successfully. C:\Program Files\DoubleD\GamingHarbor Toolbar\4.2.4.23050\Data\Module_Wallpaper.mx (Adware.DoubleD) -> Quarantined and deleted successfully. C:\Program Files\DoubleD\GamingHarbor Toolbar\4.2.4.23050\Data\Module_Web.mx (Adware.DoubleD) -> Quarantined and deleted successfully. C:\Program Files\DoubleD\GamingHarbor Toolbar\4.2.4.23050\Data\pixel.mx (Adware.DoubleD) -> Quarantined and deleted successfully. C:\Program Files\DoubleD\GamingHarbor Toolbar\4.2.4.23050\Data\ProductInfo.mx (Adware.DoubleD) -> Quarantined and deleted successfully. C:\Program Files\DoubleD\GamingHarbor Toolbar\4.2.4.23050\Data\profile.mx (Adware.DoubleD) -> Quarantined and deleted successfully. C:\Program Files\DoubleD\GamingHarbor Toolbar\4.2.4.23050\Data\SearchEngineList.mx (Adware.DoubleD) -> Quarantined and deleted successfully. C:\Program Files\DoubleD\GamingHarbor Toolbar\4.2.4.23050\Data\tbcore.mx (Adware.DoubleD) -> Quarantined and deleted successfully. C:\Program Files\DoubleD\GamingHarbor Toolbar\4.2.4.23050\Data\ToolbarLayout.mx (Adware.DoubleD) -> Quarantined and deleted successfully. C:\Program Files\DoubleD\GamingHarbor Toolbar\4.2.4.23050\Data\UpdateCentre.mx (Adware.DoubleD) -> Quarantined and deleted successfully. C:\Program Files\DoubleD\GamingHarbor Toolbar\4.2.4.23050\Data\UpdateCentreBk.mx (Adware.DoubleD) -> Quarantined and deleted successfully. C:\Program Files\DoubleD\GamingHarbor Toolbar\4.2.4.23050\Data\URLDynamic.mx (Adware.DoubleD) -> Quarantined and deleted successfully. C:\Program Files\DoubleD\GamingHarbor Toolbar\4.2.4.23050\Data\URLStatic.mx (Adware.DoubleD) -> Quarantined and deleted successfully. C:\Program Files\DoubleD\GamingHarbor Toolbar\4.2.4.23050\Icons\About.mg (Adware.DoubleD) -> Quarantined and deleted successfully. C:\Program Files\DoubleD\GamingHarbor Toolbar\4.2.4.23050\Icons\Component_ComboBox.mg (Adware.DoubleD) -> Quarantined and deleted successfully. C:\Program Files\DoubleD\GamingHarbor Toolbar\4.2.4.23050\Icons\Module_Cursor.mg (Adware.DoubleD) -> Quarantined and deleted successfully. C:\Program Files\DoubleD\GamingHarbor Toolbar\4.2.4.23050\Icons\Module_Cursor.png (Adware.DoubleD) -> Quarantined and deleted successfully. C:\Program Files\DoubleD\GamingHarbor Toolbar\4.2.4.23050\Icons\Module_DailyVideo.mg (Adware.DoubleD) -> Quarantined and deleted successfully. C:\Program Files\DoubleD\GamingHarbor Toolbar\4.2.4.23050\Icons\Module_Game.mg (Adware.DoubleD) -> Quarantined and deleted successfully. C:\Program Files\DoubleD\GamingHarbor Toolbar\4.2.4.23050\Icons\Module_Glitter.mg (Adware.DoubleD) -> Quarantined and deleted successfully. C:\Program Files\DoubleD\GamingHarbor Toolbar\4.2.4.23050\Icons\Module_Glitter.png (Adware.DoubleD) -> Quarantined and deleted successfully. C:\Program Files\DoubleD\GamingHarbor Toolbar\4.2.4.23050\Icons\Module_Logo.mg (Adware.DoubleD) -> Quarantined and deleted successfully. C:\Program Files\DoubleD\GamingHarbor Toolbar\4.2.4.23050\Icons\Module_Option.mg (Adware.DoubleD) -> Quarantined and deleted successfully. C:\Program Files\DoubleD\GamingHarbor Toolbar\4.2.4.23050\Icons\Module_Recipe.mg (Adware.DoubleD) -> Quarantined and deleted successfully. C:\Program Files\DoubleD\GamingHarbor Toolbar\4.2.4.23050\Icons\Module_Ringtone.mg (Adware.DoubleD) -> Quarantined and deleted successfully. C:\Program Files\DoubleD\GamingHarbor Toolbar\4.2.4.23050\Icons\Module_Screensaver.mg (Adware.DoubleD) -> Quarantined and deleted successfully. C:\Program Files\DoubleD\GamingHarbor Toolbar\4.2.4.23050\Icons\Module_Search.mg (Adware.DoubleD) -> Quarantined and deleted successfully. C:\Program Files\DoubleD\GamingHarbor Toolbar\4.2.4.23050\Icons\Module_Smiley.mg (Adware.DoubleD) -> Quarantined and deleted successfully. C:\Program Files\DoubleD\GamingHarbor Toolbar\4.2.4.23050\Icons\Module_Smiley.png (Adware.DoubleD) -> Quarantined and deleted successfully. C:\Program Files\DoubleD\GamingHarbor Toolbar\4.2.4.23050\Icons\Module_Wallpaper.mg (Adware.DoubleD) -> Quarantined and deleted successfully. C:\Program Files\DoubleD\GamingHarbor Toolbar\4.2.4.23050\Icons\Module_Web.mg (Adware.DoubleD) -> Quarantined and deleted successfully. C:\Program Files\DoubleD\GamingHarbor Toolbar\4.2.4.23050\Icons\TBBtnDefault.png (Adware.DoubleD) -> Quarantined and deleted successfully. C:\Program Files\DoubleD\GamingHarbor Toolbar\4.2.4.23050\Icons\TBBtnDisplay.bmp (Adware.DoubleD) -> Quarantined and deleted successfully. C:\Program Files\DoubleD\GamingHarbor Toolbar\4.2.4.23050\Icons\TBBtnDisplay.png (Adware.DoubleD) -> Quarantined and deleted successfully. C:\Program Files\DoubleD\GamingHarbor Toolbar\4.2.4.23050\Icons\TBBtnDisplay18.bmp (Adware.DoubleD) -> Quarantined and deleted successfully. C:\Program Files\DoubleD\GamingHarbor Toolbar\4.2.4.23050\Icons\TBBtnDisplay20.bmp (Adware.DoubleD) -> Quarantined and deleted successfully. C:\Program Files\DoubleD\GamingHarbor Toolbar\4.2.4.23050\Icons\TBBtnGlitters.bmp (Adware.DoubleD) -> Quarantined and deleted successfully. C:\Program Files\DoubleD\GamingHarbor Toolbar\4.2.4.23050\Icons\TBBtnGlitters.png (Adware.DoubleD) -> Quarantined and deleted successfully. C:\Program Files\DoubleD\GamingHarbor Toolbar\4.2.4.23050\Icons\TBBtnGlitters18.bmp (Adware.DoubleD) -> Quarantined and deleted successfully. C:\Program Files\DoubleD\GamingHarbor Toolbar\4.2.4.23050\Icons\TBBtnGlitters20.bmp (Adware.DoubleD) -> Quarantined and deleted successfully. C:\Program Files\DoubleD\GamingHarbor Toolbar\4.2.4.23050\Icons\TBBtnOption.png (Adware.DoubleD) -> Quarantined and deleted successfully. C:\Program Files\DoubleD\GamingHarbor Toolbar\4.2.4.23050\Icons\TBBtnSmiley.bmp (Adware.DoubleD) -> Quarantined and deleted successfully. C:\Program Files\DoubleD\GamingHarbor Toolbar\4.2.4.23050\Icons\TBBtnSmiley.png (Adware.DoubleD) -> Quarantined and deleted successfully. C:\Program Files\DoubleD\GamingHarbor Toolbar\4.2.4.23050\Icons\TBBtnSmiley18.bmp (Adware.DoubleD) -> Quarantined and deleted successfully. C:\Program Files\DoubleD\GamingHarbor Toolbar\4.2.4.23050\Icons\TBBtnSmiley20.bmp (Adware.DoubleD) -> Quarantined and deleted successfully. C:\Program Files\DoubleD\GamingHarbor Toolbar\4.2.4.23050\Icons\TBBtnTellFd.bmp (Adware.DoubleD) -> Quarantined and deleted successfully. C:\Program Files\DoubleD\GamingHarbor Toolbar\4.2.4.23050\Icons\TBBtnTellFd.png (Adware.DoubleD) -> Quarantined and deleted successfully. C:\Program Files\DoubleD\GamingHarbor Toolbar\4.2.4.23050\Icons\TBBtnTellFd18.bmp (Adware.DoubleD) -> Quarantined and deleted successfully. C:\Program Files\DoubleD\GamingHarbor Toolbar\4.2.4.23050\Icons\TBBtnTellFd20.bmp (Adware.DoubleD) -> Quarantined and deleted successfully. C:\Program Files\DoubleD\GamingHarbor Toolbar\4.2.4.23050\Icons\TBBtnWink.bmp (Adware.DoubleD) -> Quarantined and deleted successfully. C:\Program Files\DoubleD\GamingHarbor Toolbar\4.2.4.23050\Icons\TBBtnWink.png (Adware.DoubleD) -> Quarantined and deleted successfully. C:\Program Files\DoubleD\GamingHarbor Toolbar\4.2.4.23050\Icons\TBBtnWink18.bmp (Adware.DoubleD) -> Quarantined and deleted successfully. C:\Program Files\DoubleD\GamingHarbor Toolbar\4.2.4.23050\Icons\TBBtnWink20.bmp (Adware.DoubleD) -> Quarantined and deleted successfully. C:\Program Files\DoubleD\GamingHarbor Toolbar\4.2.4.23050\Skins\myskin1.skf (Adware.DoubleD) -> Quarantined and deleted successfully. C:\Program Files\DoubleD\GamingHarbor Toolbar\4.2.4.23050\Skins\myskin2.skf (Adware.DoubleD) -> Quarantined and deleted successfully. C:\Program Files\DoubleD\GamingHarbor Toolbar\4.2.4.23050\Skins\myskin3.skf (Adware.DoubleD) -> Quarantined and deleted successfully. C:\Program Files\DoubleD\GamingHarbor Toolbar\4.2.4.23050\Skins\myskin4.skf (Adware.DoubleD) -> Quarantined and deleted successfully. C:\Program Files\DoubleD\GamingHarbor Toolbar\4.2.4.23050\Skins\TellafriendSkin.skf (Adware.DoubleD) -> Quarantined and deleted successfully. C:\Program Files\DoubleD\GamingHarbor Toolbar\4.2.4.23050\Skins\TellafriendSkin_s.skf (Adware.DoubleD) -> Quarantined and deleted successfully. C:\Program Files\DoubleD\GamingHarbor Toolbar\4.2.4.23050\Skins\ToastSkin.skf (Adware.DoubleD) -> Quarantined and deleted successfully. C:\Program Files\Gamevance\ars.cfg (Adware.Gamevance) -> Quarantined and deleted successfully. C:\Program Files\Gamevance\gamevance32.exe (Adware.Gamevance) -> Quarantined and deleted successfully. C:\Program Files\Gamevance\gamevancelib32.dll (Adware.Gamevance) -> Quarantined and deleted successfully. C:\Program Files\Gamevance\gvtl.dll (Adware.Gamevance) -> Quarantined and deleted successfully. C:\Program Files\Gamevance\gvun.exe (Adware.Gamevance) -> Quarantined and deleted successfully. C:\Program Files\Gamevance\icon.ico (Adware.Gamevance) -> Quarantined and deleted successfully. C:\Program Files\Internet Saving Optimizer\3.7.2.4650\adwpx.exe (Adware.DoubleD) -> Quarantined and deleted successfully. C:\Program Files\Internet Saving Optimizer\3.7.2.4650\NPCommon.dll (Adware.DoubleD) -> Quarantined and deleted successfully. C:\Program Files\Internet Saving Optimizer\3.7.2.4650\unins000.dat (Adware.DoubleD) -> Quarantined and deleted successfully. C:\Program Files\Internet Saving Optimizer\3.7.2.4650\unins000.exe (Adware.DoubleD) -> Quarantined and deleted successfully. C:\Program Files\Internet Saving Optimizer\3.7.2.4650\Data\config.md (Adware.DoubleD) -> Quarantined and deleted successfully. C:\Program Files\Internet Saving Optimizer\3.7.2.4650\FF\chrome.manifest (Adware.DoubleD) -> Quarantined and deleted successfully. C:\Program Files\Internet Saving Optimizer\3.7.2.4650\FF\install.rdf (Adware.DoubleD) -> Quarantined and deleted successfully. C:\Program Files\Internet Saving Optimizer\3.7.2.4650\FF\chrome\NPAddOn.jar (Adware.DoubleD) -> Quarantined and deleted successfully. C:\Program Files\Internet Saving Optimizer\3.7.2.4650\FF\chrome\content\NPAddOn.js (Adware.DoubleD) -> Quarantined and deleted successfully. C:\Program Files\Internet Saving Optimizer\3.7.2.4650\FF\chrome\content\NPAddOn.xul (Adware.DoubleD) -> Quarantined and deleted successfully. C:\Program Files\Internet Saving Optimizer\3.7.2.4650\FF\components\NPFFAddOn.dll (Adware.DoubleD) -> Quarantined and deleted successfully. C:\Program Files\Internet Saving Optimizer\3.7.2.4650\FF\components\NPFFAddOn.xpt (Adware.DoubleD) -> Quarantined and deleted successfully. C:\Program Files\Internet Saving Optimizer\3.7.2.4650\FF\components\NPFFHelperComponent.js (Adware.DoubleD) -> Quarantined and deleted successfully. C:\Program Files\Media Access Startup\2.0.0.1050\HPCommon.dll (Adware.DoubleD) -> Quarantined and deleted successfully. C:\Program Files\Media Access Startup\2.0.0.1050\hppx.exe (Adware.DoubleD) -> Quarantined and deleted successfully. C:\Program Files\Media Access Startup\2.0.0.1050\MAHelper.exe (Adware.DoubleD) -> Quarantined and deleted successfully. C:\Program Files\Media Access Startup\2.0.0.1050\unins000.dat (Adware.DoubleD) -> Quarantined and deleted successfully. C:\Program Files\Media Access Startup\2.0.0.1050\unins000.exe (Adware.DoubleD) -> Quarantined and deleted successfully. C:\Program Files\Media Access Startup\2.0.0.1050\Data\config.md (Adware.DoubleD) -> Quarantined and deleted successfully. C:\Program Files\Media Access Startup\2.0.0.1050\FF\chrome.manifest (Adware.DoubleD) -> Quarantined and deleted successfully. C:\Program Files\Media Access Startup\2.0.0.1050\FF\install.rdf (Adware.DoubleD) -> Quarantined and deleted successfully. C:\Program Files\Media Access Startup\2.0.0.1050\FF\chrome\HPAddOn.jar (Adware.DoubleD) -> Quarantined and deleted successfully. C:\Program Files\Media Access Startup\2.0.0.1050\FF\chrome\content\HPAddOn.js (Adware.DoubleD) -> Quarantined and deleted successfully. C:\Program Files\Media Access Startup\2.0.0.1050\FF\chrome\content\HPAddOn.xul (Adware.DoubleD) -> Quarantined and deleted successfully. C:\Program Files\Media Access Startup\2.0.0.1050\FF\components\HPFFAddOn.dll (Adware.DoubleD) -> Quarantined and deleted successfully. C:\Program Files\Media Access Startup\2.0.0.1050\FF\components\HPFFAddOn.xpt (Adware.DoubleD) -> Quarantined and deleted successfully. C:\Program Files\Media Access Startup\2.0.0.1050\FF\components\HPFFHelperComponent.js (Adware.DoubleD) -> Quarantined and deleted successfully. C:\Program Files\System Search Dispatcher\1.4.1.1010\unins000.dat (Adware.DoubleD) -> Quarantined and deleted successfully. C:\Program Files\System Search Dispatcher\1.4.1.1010\unins000.exe (Adware.DoubleD) -> Quarantined and deleted successfully. C:\Program Files\System Search Dispatcher\1.4.1.1010\Data\eacore.mx (Adware.DoubleD) -> Quarantined and deleted successfully. C:\Program Files\System Search Dispatcher\1.4.1.1010\Data\URLDynamic.mx (Adware.DoubleD) -> Quarantined and deleted successfully. C:\Program Files\System Search Dispatcher\1.4.1.1010\Data\URLStatic.mx (Adware.DoubleD) -> Quarantined and deleted successfully. C:\Program Files\Common Files\TSUninstall\Uninstall.lnk (Rogue.TotalSecurity) -> Quarantined and deleted successfully. C:\Windows\rdr_1256088947.exe (Worm.KoobFace) -> Quarantined and deleted successfully. C:\Windows\rdr_1256088950.exe (Worm.KoobFace) -> Quarantined and deleted successfully. C:\Windows\rdr_1256088976.exe (Worm.KoobFace) -> Quarantined and deleted successfully. C:\Windows\010112010146116101.xxe (KoobFace.Trace) -> Quarantined and deleted successfully. C:\Windows\0101120101464955.xxe (KoobFace.Trace) -> Quarantined and deleted successfully. C:\Windows\0101120101465055.xxe (KoobFace.Trace) -> Quarantined and deleted successfully. C:\Users\Emma B. Sykes\Desktop\Security Tool.LNK (Rogue.SecurityTool) -> Quarantined and deleted successfully. C:\Users\Mariska Sykes\Desktop\Security Tool.LNK (Rogue.SecurityTool) -> Quarantined and deleted successfully. C:\Users\Emma B. Sykes\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Security Tool.LNK (Rogue.SecurityTool) -> Quarantined and deleted successfully. C:\Users\Mariska Sykes\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Security Tool.LNK (Rogue.SecurityTool) -> Quarantined and deleted successfully. C:\Windows\fdgg34353edfgdfdf (KoobFace.Trace) -> Quarantined and deleted successfully. C:\ProgramData\Microsoft\Windows\Start Menu\TS\Computer Scan.lnk (Rogue.TotalSecurity) -> Quarantined and deleted successfully. C:\ProgramData\Microsoft\Windows\Start Menu\TS\Help.lnk (Rogue.TotalSecurity) -> Quarantined and deleted successfully. C:\ProgramData\Microsoft\Windows\Start Menu\TS\Registration.lnk (Rogue.TotalSecurity) -> Quarantined and deleted successfully. C:\ProgramData\Microsoft\Windows\Start Menu\TS\Security Center.lnk (Rogue.TotalSecurity) -> Quarantined and deleted successfully. C:\ProgramData\Microsoft\Windows\Start Menu\TS\Settings.lnk (Rogue.TotalSecurity) -> Quarantined and deleted successfully. C:\ProgramData\Microsoft\Windows\Start Menu\TS\Total Security.lnk (Rogue.TotalSecurity) -> Quarantined and deleted successfully. C:\ProgramData\Microsoft\Windows\Start Menu\TS\Update.lnk (Rogue.TotalSecurity) -> Quarantined and deleted successfully. C:\Users\Emma B. Sykes\AppData\Local\Temp\zpskon_1256096045.exe (Worm.Koobface) -> Quarantined and deleted successfully. C:\Users\Emma B. Sykes\AppData\Local\Temp\zpskon_1256101074.exe (Worm.Koobface) -> Quarantined and deleted successfully. AFTER USING YOUR CLEANING GUIDE: Malwarebytes' Anti-Malware 1.41 Database version: 3074 Windows 6.0.6002 Service Pack 2 11/1/2009 6:28:29 AM mbam-log-2009-11-01 (06-28-29).txt Scan type: Full Scan (C:\|D:\|) Objects scanned: 391781 Time elapsed: 2 hour(s), 3 minute(s), 12 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 0 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 0 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: (No malicious items detected) Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: (No malicious items detected) ROOT REPEAL ROOTREPEAL © AD, 2007-2009 ================================================== Scan Start Time: 2009/11/01 13:03 Program Version: Version 1.3.5.0 Windows Version: Windows Vista SP2 ================================================== Drivers ------------------- Name: dump_atapi.sys Image Path: C:\Windows\System32\Drivers\dump_atapi.sys Address: 0x8C57F000 Size: 32768 File Visible: No Signed: - Status: - Name: dump_dumpata.sys Image Path: C:\Windows\System32\Drivers\dump_dumpata.sys Address: 0x8C574000 Size: 45056 File Visible: No Signed: - Status: - Name: rootrepeal.sys Image Path: C:\Windows\system32\drivers\rootrepeal.sys Address: 0xA53F0000 Size: 49152 File Visible: No Signed: - Status: - Processes ------------------- Path: System PID: 4 Status: Locked to the Windows API! Path: C:\Windows\System32\audiodg.exe PID: 1256 Status: Locked to the Windows API! SSDT ------------------- #: 078 Function Name: NtCreateThread Status: Hooked by "<unknown>" at address 0x8a1d94b4 #: 194 Function Name: NtOpenProcess Status: Hooked by "<unknown>" at address 0x8a1d94a0 #: 201 Function Name: NtOpenThread Status: Hooked by "<unknown>" at address 0x8a1d94a5 #: 334 Function Name: NtTerminateProcess Status: Hooked by "<unknown>" at address 0x8a1d94af ==EOF== OTL: OTL logfile created on: 11/1/2009 1:09:35 PM - Run 1 OTL by OldTimer - Version 3.1.1.8 Folder = C:\ATF Windows Vista Home Basic Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation Internet Explorer (Version = 8.0.6001.18828) Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy 1.99 Gb Total Physical Memory | 1.42 Gb Available Physical Memory | 71.20% Memory free 4.00 Gb Paging File | 3.32 Gb Available in Paging File | 82.99% Paging File free Paging file location(s): ?:\pagefile.sys [binary data] %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files Drive C: | 64.45 Gb Total Space | 31.09 Gb Free Space | 48.24% Space Free | Partition Type: NTFS Drive D: | 10.00 Gb Total Space | 6.79 Gb Free Space | 67.85% Space Free | Partition Type: NTFS E: Drive not present or media not loaded F: Drive not present or media not loaded G: Drive not present or media not loaded H: Drive not present or media not loaded I: Drive not present or media not loaded Computer Name: EMMA-PC Current User Name: Emma B. Sykes Logged in as Administrator. Current Boot Mode: Normal Scan Mode: All users Company Name Whitelist: On Skip Microsoft Files: On File Age = 14 Days Output = Standard Quick Scan ========== Processes (SafeList) ========== PRC - [2009/11/01 13:00:47 | 00,528,384 | ---- | M] (OldTimer Tools) -- C:\ATF\OTL.exe PRC - [2009/09/02 18:26:24 | 00,039,408 | ---- | M] (Google Inc.) -- C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe PRC - [2009/09/02 15:39:20 | 00,149,280 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\Java\jre6\bin\jusched.exe PRC - [2009/07/21 13:34:33 | 00,185,089 | ---- | M] (Avira GmbH) -- C:\Program Files\Avira\AntiVir Desktop\avguard.exe PRC - [2009/05/21 10:13:58 | 00,206,064 | ---- | M] (SupportSoft, Inc.) -- C:\Program Files\Dell Support Center\bin\sprtcmd.exe PRC - [2009/05/19 10:36:18 | 00,240,512 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe PRC - [2009/05/13 15:48:22 | 00,108,289 | ---- | M] (Avira GmbH) -- C:\Program Files\Avira\AntiVir Desktop\sched.exe PRC - [2009/04/11 00:27:36 | 02,926,592 | ---- | M] (Microsoft Corporation) -- C:\Windows\explorer.exe PRC - [2009/03/02 12:08:47 | 00,209,153 | ---- | M] (Avira GmbH) -- C:\Program Files\Avira\AntiVir Desktop\avgnt.exe PRC - [2008/10/07 09:23:46 | 00,111,856 | ---- | M] (Yahoo! Inc) -- C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe PRC - [2008/08/13 23:04:44 | 00,201,968 | ---- | M] (SupportSoft, Inc.) -- C:\Program Files\Dell Support Center\bin\sprtsvc.exe PRC - [2008/02/26 09:57:28 | 00,128,296 | ---- | M] (CyberLink Corp.) -- C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe PRC - [2008/02/11 19:13:10 | 00,256,536 | ---- | M] (Intel Corporation) -- C:\Windows\System32\igfxsrvc.exe PRC - [2008/02/11 19:13:08 | 00,133,656 | ---- | M] (Intel Corporation) -- C:\Windows\System32\igfxpers.exe PRC - [2008/02/11 19:13:02 | 00,166,424 | ---- | M] (Intel Corporation) -- C:\Windows\System32\hkcmd.exe PRC - [2008/01/20 20:35:20 | 00,896,512 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Windows Media Player\wmpnetwk.exe PRC - [2008/01/20 20:35:20 | 00,202,240 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Windows Media Player\wmpnscfg.exe PRC - [2007/11/20 15:36:25 | 01,454,592 | ---- | M] (Motive Communications, Inc.) -- C:\Program Files\HughesNetTools\1\McciTrayApp_SSR.exe PRC - [2007/10/15 15:34:44 | 00,303,104 | ---- | M] (Motive Communications, Inc.) -- C:\Program Files\Common Files\Motive\McciCMService.exe PRC - [2007/05/14 03:03:20 | 04,452,352 | ---- | M] (Realtek Semiconductor) -- C:\Windows\RtHDVCpl.exe PRC - [2003/06/19 22:25:00 | 00,322,120 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Common Files\microsoft shared\VS7Debug\mdm.exe ========== Win32 Services (SafeList) ========== SRV - File not found -- SRV - File not found -- SRV - File not found -- SRV - [2009/09/24 19:27:04 | 00,793,088 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\FntCache.dll SRV - [2009/09/02 18:28:31 | 00,133,104 | ---- | M] (Google Inc.) -- C:\Program Files\Google\Update\GoogleUpdate.exe SRV - [2009/09/02 18:26:19 | 00,194,032 | ---- | M] (Google) -- C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe SRV - [2009/07/21 13:34:33 | 00,185,089 | ---- | M] (Avira GmbH) -- C:\Program Files\Avira\AntiVir Desktop\avguard.exe SRV - [2009/05/19 10:36:18 | 00,240,512 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe SRV - [2009/05/13 15:48:22 | 00,108,289 | ---- | M] (Avira GmbH) -- C:\Program Files\Avira\AntiVir Desktop\sched.exe SRV - [2009/03/29 22:42:14 | 00,066,368 | ---- | M] (Microsoft Corporation) -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe SRV - [2009/02/18 12:39:20 | 00,043,904 | ---- | M] (Microsoft Corporation) -- C:\Windows\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe SRV - [2009/02/18 12:38:43 | 00,129,880 | ---- | M] (Microsoft Corporation) -- C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe SRV - [2009/02/18 12:38:42 | 00,879,448 | ---- | M] (Microsoft Corporation) -- C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe SRV - [2008/10/02 19:20:50 | 00,242,424 | ---- | M] (WildTangent, Inc.) -- C:\Program Files\Dell Games\Dell Game Console\GameConsoleService.exe SRV - [2008/08/13 23:04:44 | 00,201,968 | ---- | M] (SupportSoft, Inc.) -- C:\Program Files\Dell Support Center\bin\sprtsvc.exe SRV - [2008/07/22 17:47:41 | 00,029,744 | ---- | M] (Google) -- C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe SRV - [2008/01/20 20:35:20 | 00,896,512 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Windows Media Player\wmpnetwk.exe SRV - [2008/01/20 20:33:00 | 00,272,952 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Windows Defender\MpSvc.dll SRV - [2007/10/15 15:34:44 | 00,303,104 | ---- | M] (Motive Communications, Inc.) -- C:\Program Files\Common Files\Motive\McciCMService.exe SRV - [2007/07/11 08:33:28 | 00,069,632 | R--- | M] (MicroVision Development, Inc.) -- C:\Program Files\Common Files\SureThing Shared\stllssvr.exe SRV - [2003/06/19 22:25:00 | 00,322,120 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe ========== Modules (SafeList) ========== MOD - [2009/11/01 13:00:47 | 00,528,384 | ---- | M] (OldTimer Tools) -- C:\ATF\OTL.exe MOD - [2009/04/11 00:28:25 | 00,017,408 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\vdmdbg.dll MOD - [2009/04/11 00:28:21 | 02,241,536 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\msi.dll MOD - [2009/04/11 00:21:38 | 01,686,016 | ---- | M] (Microsoft Corporation) -- C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6002.18005_none_5cb72f96088b0de0\comctl32.dll MOD - [2008/01/20 20:33:54 | 00,038,912 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\sfc_os.dll MOD - [2007/10/15 15:28:59 | 00,454,144 | ---- | M] (Motive Communications, Inc.) -- C:\Program Files\Common Files\Motive\McciContextHook_6-1-0_DSR.dll MOD - [2006/11/02 03:46:13 | 00,004,608 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\sfc.dll MOD - [2006/11/02 03:46:07 | 00,015,872 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\msiltcfg.dll ========== Standard Registry (SafeList) ========== ========== Internet Explorer ========== IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = [binary data] IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:NoAdd-ons IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\System32\blank.htm IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:SecurityRisk IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157 IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomizeSearch = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = IE - HKU\.DEFAULT\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKU\S-1-5-18\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKU\S-1-5-20\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKU\S-1-5-21-1696485601-562263704-4103742560-1002\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.msn.com IE - HKU\S-1-5-21-1696485601-562263704-4103742560-1002\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = www.bing.com [binary data] IE - HKU\S-1-5-21-1696485601-562263704-4103742560-1002\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\system32\blank.htm IE - HKU\S-1-5-21-1696485601-562263704-4103742560-1002\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 IE - HKU\S-1-5-21-1696485601-562263704-4103742560-1002\SOFTWARE\Microsoft\Internet Explorer\Main,SearchDefaultBranded = 1 IE - HKU\S-1-5-21-1696485601-562263704-4103742560-1002\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/ IE - HKU\S-1-5-21-1696485601-562263704-4103742560-1002\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1 IE - HKU\S-1-5-21-1696485601-562263704-4103742560-1002\..\URLSearchHook: {00A6FAF6-072E-44cf-8957-5838F569A31D} - Reg Error: Key error. File not found IE - HKU\S-1-5-21-1696485601-562263704-4103742560-1002\..\URLSearchHook: {1CB20BF0-BBAE-40A7-93F4-6435FF3D0411} - Reg Error: Key error. File not found IE - HKU\S-1-5-21-1696485601-562263704-4103742560-1002\S-1-5-21-1696485601-562263704-4103742560-1002\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKU\S-1-5-21-1696485601-562263704-4103742560-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.msn.com IE - HKU\S-1-5-21-1696485601-562263704-4103742560-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = www.bing.com [binary data] IE - HKU\S-1-5-21-1696485601-562263704-4103742560-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\system32\blank.htm IE - HKU\S-1-5-21-1696485601-562263704-4103742560-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 IE - HKU\S-1-5-21-1696485601-562263704-4103742560-1003\SOFTWARE\Microsoft\Internet Explorer\Main,SearchDefaultBranded = 1 IE - HKU\S-1-5-21-1696485601-562263704-4103742560-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Secondary Start Pages = www.bing.com [binary data] IE - HKU\S-1-5-21-1696485601-562263704-4103742560-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.msn.com IE - HKU\S-1-5-21-1696485601-562263704-4103742560-1003\..\URLSearchHook: {00A6FAF6-072E-44cf-8957-5838F569A31D} - Reg Error: Key error. File not found IE - HKU\S-1-5-21-1696485601-562263704-4103742560-1003\S-1-5-21-1696485601-562263704-4103742560-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKU\S-1-5-21-1696485601-562263704-4103742560-1005\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.msn.com IE - HKU\S-1-5-21-1696485601-562263704-4103742560-1005\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = www.bing.com [binary data] IE - HKU\S-1-5-21-1696485601-562263704-4103742560-1005\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\system32\blank.htm IE - HKU\S-1-5-21-1696485601-562263704-4103742560-1005\SOFTWARE\Microsoft\Internet Explorer\Main,Page_Transitions = 1 IE - HKU\S-1-5-21-1696485601-562263704-4103742560-1005\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = IE - HKU\S-1-5-21-1696485601-562263704-4103742560-1005\SOFTWARE\Microsoft\Internet Explorer\Main,SearchDefaultBranded = 1 IE - HKU\S-1-5-21-1696485601-562263704-4103742560-1005\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/ IE - HKU\S-1-5-21-1696485601-562263704-4103742560-1005\..\URLSearchHook: {1CB20BF0-BBAE-40A7-93F4-6435FF3D0411} - Reg Error: Key error. File not found IE - HKU\S-1-5-21-1696485601-562263704-4103742560-1005\S-1-5-21-1696485601-562263704-4103742560-1005\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 FF - HKLM\software\mozilla\Firefox\Extensions\\{20a82645-c095-46ed-80e3-08825760534b}: c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\ File not found O1 HOSTS File: (761 bytes) - C:\Windows\System32\drivers\etc\hosts O1 - Hosts: 127.0.0.1 localhost O1 - Hosts: ::1 localhost O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - No CLSID value found. O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated) O2 - BHO: (no name) - {1CB20BF0-BBAE-40A7-93F4-6435FF3D0411} - No CLSID value found. O2 - BHO: (Search Helper) - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll (Microsoft Corporation) O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.3.4501.1418\swg.dll (Google Inc.) O2 - BHO: (CBrowserHelperObject Object) - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files\Dell\BAE\BAE.dll (Dell Inc.) O2 - BHO: (MSN Toolbar Helper) - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files\MSN\Toolbar\3.0.1125.0\msneshellx.dll (Microsoft Corp.) O2 - BHO: (Java Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.) O3 - HKLM\..\Toolbar: (MSN Toolbar) - {1E61ED7C-7CB8-49d6-B9E9-AB4C880C8414} - C:\Program Files\MSN\Toolbar\3.0.1125.0\msneshellx.dll (Microsoft Corp.) O3 - HKU\S-1-5-21-1696485601-562263704-4103742560-1002\..\Toolbar\WebBrowser: (no name) - {07B18EA9-A523-4961-B6BB-170DE4475CCA} - No CLSID value found. O3 - HKU\S-1-5-21-1696485601-562263704-4103742560-1002\..\Toolbar\WebBrowser: (no name) - {1BB22D38-A411-4B13-A746-C2A4F4EC7344} - No CLSID value found. O3 - HKU\S-1-5-21-1696485601-562263704-4103742560-1002\..\Toolbar\WebBrowser: (no name) - {4B3803EA-5230-4DC3-A7FC-33638F3D3542} - No CLSID value found. O3 - HKU\S-1-5-21-1696485601-562263704-4103742560-1002\..\Toolbar\WebBrowser: (no name) - {604BC32A-9680-40D1-9AC6-E06B23A1BA4C} - No CLSID value found. O3 - HKU\S-1-5-21-1696485601-562263704-4103742560-1002\..\Toolbar\WebBrowser: (no name) - {C53FE659-316A-4F56-A194-A5BE491BE866} - No CLSID value found. O3 - HKU\S-1-5-21-1696485601-562263704-4103742560-1002\..\Toolbar\WebBrowser: (no name) - {D7E97865-918F-41E4-9CD0-25AB1C574CE8} - No CLSID value found. O3 - HKU\S-1-5-21-1696485601-562263704-4103742560-1003\..\Toolbar\WebBrowser: (no name) - {07B18EA9-A523-4961-B6BB-170DE4475CCA} - No CLSID value found. O3 - HKU\S-1-5-21-1696485601-562263704-4103742560-1003\..\Toolbar\WebBrowser: (no name) - {1BB22D38-A411-4B13-A746-C2A4F4EC7344} - No CLSID value found. O3 - HKU\S-1-5-21-1696485601-562263704-4103742560-1003\..\Toolbar\WebBrowser: (no name) - {3041D03E-FD4B-44E0-B742-2D9B88305F98} - No CLSID value found. O3 - HKU\S-1-5-21-1696485601-562263704-4103742560-1003\..\Toolbar\WebBrowser: (no name) - {4B3803EA-5230-4DC3-A7FC-33638F3D3542} - No CLSID value found. O3 - HKU\S-1-5-21-1696485601-562263704-4103742560-1003\..\Toolbar\WebBrowser: (no name) - {604BC32A-9680-40D1-9AC6-E06B23A1BA4C} - No CLSID value found. O3 - HKU\S-1-5-21-1696485601-562263704-4103742560-1003\..\Toolbar\WebBrowser: (no name) - {C53FE659-316A-4F56-A194-A5BE491BE866} - No CLSID value found. O3 - HKU\S-1-5-21-1696485601-562263704-4103742560-1003\..\Toolbar\WebBrowser: (no name) - {D7E97865-918F-41E4-9CD0-25AB1C574CE8} - No CLSID value found. O3 - HKU\S-1-5-21-1696485601-562263704-4103742560-1005\..\Toolbar\WebBrowser: (no name) - {4B3803EA-5230-4DC3-A7FC-33638F3D3542} - No CLSID value found. O3 - HKU\S-1-5-21-1696485601-562263704-4103742560-1005\..\Toolbar\WebBrowser: (no name) - {604BC32A-9680-40D1-9AC6-E06B23A1BA4C} - No CLSID value found. O3 - HKU\S-1-5-21-1696485601-562263704-4103742560-1005\..\Toolbar\WebBrowser: (no name) - {D7E97865-918F-41E4-9CD0-25AB1C574CE8} - No CLSID value found. O4 - HKLM..\Run: [Adobe Reader Speed Launcher] C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe (Adobe Systems Incorporated) O4 - HKLM..\Run: [avgnt] C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Avira GmbH) O4 - HKLM..\Run: [DellSupportCenter] C:\Program Files\Dell Support Center\bin\sprtcmd.exe (SupportSoft, Inc.) O4 - HKLM..\Run: [dscactivate] C:\Program Files\Dell Support Center\gs_agent\custom\dsca.exe ( ) O4 - HKLM..\Run: [FBSSA] C:\Program Files\SGPSA\ie3sh.exe File not found O4 - HKLM..\Run: [Google Desktop Search] C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe (Google) O4 - HKLM..\Run: [HotKeysCmds] C:\Windows\System32\hkcmd.exe (Intel Corporation) O4 - HKLM..\Run: [HughesNetTools_McciTrayApp] C:\Program Files\HughesNetTools\1\McciTrayApp_SSR.exe (Motive Communications, Inc.) O4 - HKLM..\Run: [IgfxTray] C:\Windows\System32\igfxtray.exe (Intel Corporation) O4 - HKLM..\Run: [Malwarebytes Anti-Malware (reboot)] C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe (Malwarebytes Corporation) O4 - HKLM..\Run: [Malwarebytes Anti-Malware (rootkit-scan)] C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe (Malwarebytes Corporation) O4 - HKLM..\Run: [Microsoft Default Manager] C:\Program Files\Microsoft\Search Enhancement Pack\Default Manager\DefMgr.exe (Microsoft Corp.) O4 - HKLM..\Run: [PDVDDXSrv] C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe (CyberLink Corp.) O4 - HKLM..\Run: [Persistence] C:\Windows\System32\igfxpers.exe (Intel Corporation) O4 - HKLM..\Run: [RtHDVCpl] C:\Windows\RtHDVCpl.exe (Realtek Semiconductor) O4 - HKLM..\Run: [Spyware Striker Pro] C:\Program Files\Ascentive\Spyware Striker\SpywareStriker.exe File not found O4 - HKLM..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre6\bin\jusched.exe (Sun Microsystems, Inc.) O4 - HKLM..\Run: [Windows Defender] C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation) O4 - HKLM..\Run: [YSearchProtection] C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe (Yahoo! Inc) O4 - HKU\S-1-5-19..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe (Microsoft Corporation) O4 - HKU\S-1-5-19..\Run: [WindowsWelcomeCenter] C:\Windows\System32\oobefldr.dll (Microsoft Corporation) O4 - HKU\S-1-5-20..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe (Microsoft Corporation) O4 - HKU\S-1-5-20..\Run: [WindowsWelcomeCenter] C:\Windows\System32\oobefldr.dll (Microsoft Corporation) O4 - HKU\S-1-5-21-1696485601-562263704-4103742560-1002..\Run: [CSmileys] C:\PROGRA~1\Crawler\Smileys\CSmileysIM.exe File not found O4 - HKU\S-1-5-21-1696485601-562263704-4103742560-1002..\Run: [DW6] C:\Program Files\The Weather Channel FW\Desktop\DesktopWeather.exe (The Weather Channel Interactive, Inc.) O4 - HKU\S-1-5-21-1696485601-562263704-4103742560-1002..\Run: [PC SpeedScan Pro] C:\Program Files\Ascentive\PC SpeedScan Pro\PCSpeedScan.exe File not found O4 - HKU\S-1-5-21-1696485601-562263704-4103742560-1002..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.) O4 - HKU\S-1-5-21-1696485601-562263704-4103742560-1002..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\wmpnscfg.exe (Microsoft Corporation) O4 - HKU\S-1-5-21-1696485601-562263704-4103742560-1005..\Run: [cdloader] C:\Users\Emma B. Sykes\AppData\Roaming\mjusbsp\cdloader2.exe (magicJack L.P.) O4 - HKU\S-1-5-21-1696485601-562263704-4103742560-1005..\Run: [DW6] File not found O4 - HKU\S-1-5-21-1696485601-562263704-4103742560-1005..\Run: [PC SpeedScan Pro] C:\Program Files\Ascentive\PC SpeedScan Pro\PCSpeedScan.exe File not found O4 - HKU\S-1-5-21-1696485601-562263704-4103742560-1005..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.) O4 - HKU\S-1-5-21-1696485601-562263704-4103742560-1005..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\wmpnscfg.exe (Microsoft Corporation) O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Toolbars present O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: BindDirectlyToPropertySetStorage = 0 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 0 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 1 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableInstallerDetection = 1 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableSecureUIAPaths = 1 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableVirtualization = 1 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 1 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ValidateAdminCodeSignatures = 0 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption = O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext = O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: scforceoption = 0 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: FilterAdministratorToken = 0 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableUIADesktopToggle = 0 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_TEXT = 1 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_BITMAP = 2 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_OEMTEXT = 7 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_DIB = 8 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_PALETTE = 9 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_UNICODETEXT = 13 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_DIBV5 = 17 O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Control Panel present O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Restrictions present O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Control Panel present O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Restrictions present O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Control Panel present O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Restrictions present O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Control Panel present O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Restrictions present O7 - HKU\S-1-5-21-1696485601-562263704-4103742560-1002\Software\Policies\Microsoft\Internet Explorer\Control Panel present O7 - HKU\S-1-5-21-1696485601-562263704-4103742560-1002\Software\Policies\Microsoft\Internet Explorer\Restrictions present O7 - HKU\S-1-5-21-1696485601-562263704-4103742560-1002\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145 O7 - HKU\S-1-5-21-1696485601-562263704-4103742560-1002\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: LogonHoursAction = 2 O7 - HKU\S-1-5-21-1696485601-562263704-4103742560-1002\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DontDisplayLogonHoursWarnings = 1 O7 - HKU\S-1-5-21-1696485601-562263704-4103742560-1003\Software\Policies\Microsoft\Internet Explorer\Control Panel present O7 - HKU\S-1-5-21-1696485601-562263704-4103742560-1003\Software\Policies\Microsoft\Internet Explorer\Restrictions present O7 - HKU\S-1-5-21-1696485601-562263704-4103742560-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145 O7 - HKU\S-1-5-21-1696485601-562263704-4103742560-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: LogonHoursAction = 2 O7 - HKU\S-1-5-21-1696485601-562263704-4103742560-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DontDisplayLogonHoursWarnings = 1 O7 - HKU\S-1-5-21-1696485601-562263704-4103742560-1005\Software\Policies\Microsoft\Internet Explorer\Control Panel present O7 - HKU\S-1-5-21-1696485601-562263704-4103742560-1005\Software\Policies\Microsoft\Internet Explorer\Restrictions present O7 - HKU\S-1-5-21-1696485601-562263704-4103742560-1005\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145 O7 - HKU\S-1-5-21-1696485601-562263704-4103742560-1005\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: LogonHoursAction = 2 O7 - HKU\S-1-5-21-1696485601-562263704-4103742560-1005\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DontDisplayLogonHoursWarnings = 1 O7 - HKU\S-1-5-21-1696485601-562263704-4103742560-1005_Classes\Software\Policies\Microsoft\Internet Explorer\Control Panel present O7 - HKU\S-1-5-21-1696485601-562263704-4103742560-1005_Classes\Software\Policies\Microsoft\Internet Explorer\Restrictions present O8 - Extra context menu item: Crawler Search - File not found O8 - Extra context menu item: E&xport to Microsoft Excel - C:\Program Files\Microsoft Office\Office10\EXCEL.EXE (Microsoft Corporation) O13 - gopher Prefix: missing O15 - HKU\S-1-5-21-1696485601-562263704-4103742560-1002\..Trusted Ranges: GD ([http] in Local intranet) O15 - HKU\S-1-5-21-1696485601-562263704-4103742560-1003\..Trusted Ranges: GD ([http] in Local intranet) O15 - HKU\S-1-5-21-1696485601-562263704-4103742560-1005\..Trusted Ranges: GD ([http] in Local intranet) O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://download.macromedia.com/pub/shockwa...director/sw.cab (Shockwave ActiveX Control) O16 - DPF: {1A1F56AA-3401-46F9-B277-D57F3421F821} http://www.worldwinner.com/games/v47/share...GamesLoader.cab (FunGamesLoader Object) O16 - DPF: {22492231-AEF0-49FC-9180-CE8969AB1273} http://download.sp.f-secure.com/ols/f-secu.../fslauncher.cab (F-Secure Online Scanner Launcher) O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} http://download.divx.com/player/DivXBrowserPlugin.cab (DivXBrowserPlugin Object) O16 - DPF: {8A94C905-FF9D-43B6-8708-F0F22D22B1CB} http://www.worldwinner.com/games/shared/wwlaunch.cab (Wwlaunch Control) O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-...indows-i586.cab (Java Plug-in 1.6.0_15) O16 - DPF: {BFF1950D-B1B4-4AE8-B842-B2CCF06D9A1B} http://www.gamehouse.com/realarcade-webgam...zylomplayer.cab (Zylom Games Player) O16 - DPF: {CAEAFE12-7726-4C39-B620-2601216CFBB5} http://phughescw.hughes.motive.com/wizlet/.../Mcci_6-1-0.cab (McciContext Class) O16 - DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-...indows-i586.cab (Java Plug-in 1.6.0_05) O16 - DPF: {CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-...indows-i586.cab (Java Plug-in 1.6.0_15) O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-...indows-i586.cab (Java Plug-in 1.6.0_15) O16 - DPF: {D410AFBD-4E26-4D5F-840F-0412D6F6BB8D} http://games.bigfishgames.com/en_sandscrip...pt.1.0.0.21.cab (CPlayFirstSandScriptControl Object) O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} http://www.gamehouse.com/realarcade-webgam...opcaploader.cab (PopCapLoader Object) O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.) O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.254 O18 - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation) O18 - Protocol\Handler\http\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation) O18 - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation) O18 - Protocol\Handler\https\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation) O18 - Protocol\Handler\msdaipp - No CLSID value found O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation) O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation) O18 - Protocol\Handler\ms-itss {0A9007C0-4076-11D3-8789-0000F8105754} - C:\Program Files\Common Files\microsoft shared\Information Retrieval\MSITSS.DLL (Microsoft Corporation) O18 - Protocol\Handler\mso-offdap {3D9F03FA-7A94-11D3-BE81-0050048385D1} - C:\Program Files\Common Files\microsoft shared\Web Components\10\OWC10.DLL (Microsoft Corporation) O20 - AppInit_DLLs: (C:\PROGRA~1\Google\GOOGLE~2\GOEC62~1.DLL) - C:\Program Files\Google\Google Desktop Search\GoogleDesktopNetwork3.dll (Google) O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation) O20 - Winlogon\Notify\igfxcui: DllName - igfxdev.dll - C:\Windows\System32\igfxdev.dll (Intel Corporation) O31 - SafeBoot: AlternateShell - cmd.exe O32 - HKLM CDRom: AutoRun - 1 O32 - AutoRun File - [2006/09/18 15:43:36 | 00,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ] O33 - MountPoints2\{e4e22101-b544-11de-a569-00219b04d3db}\Shell\AutoRun\command - "" = H:\autorun.exe -- File not found O33 - MountPoints2\{e4e22101-b544-11de-a569-00219b04d3db}\Shell\phone\command - "" = H:\autorun.exe -- File not found O34 - HKLM BootExecute: (autocheck) - File not found O34 - HKLM BootExecute: (autochk) - C:\Windows\System32\autochk.exe (Microsoft Corporation) O34 - HKLM BootExecute: (*) - File not found O35 - comfile [open] -- "%1" %* File not found O35 - exefile [open] -- "%1" %* File not found NetSvcs: FastUserSwitchingCompatibility - File not found NetSvcs: Ias - C:\Windows\System32\ias [2008/01/20 20:46:39 | 00,000,000 | ---D | M] NetSvcs: Irmon - C:\Windows\System32\irmon.dll (Microsoft Corporation) NetSvcs: Nla - File not found NetSvcs: Ntmssvc - File not found NetSvcs: NWCWorkstation - File not found NetSvcs: Nwsapagent - File not found NetSvcs: SRService - File not found NetSvcs: Wmi - C:\Windows\System32\wmi.dll (Microsoft Corporation) NetSvcs: WmdmPmSp - File not found NetSvcs: LogonHours - File not found NetSvcs: PCAudit - File not found NetSvcs: helpsvc - File not found NetSvcs: uploadmgr - File not found ========== Files/Folders - Created Within 14 Days ========== [2009/10/31 22:35:02 | 00,000,000 | ---D | C] -- C:\Program Files\Windows Portable Devices [2009/10/31 10:09:37 | 00,000,000 | ---D | C] -- C:\Windows\System32\eu-ES [2009/10/31 10:09:37 | 00,000,000 | ---D | C] -- C:\Windows\System32\ca-ES [2009/10/31 10:09:35 | 00,000,000 | ---D | C] -- C:\Windows\System32\vi-VN [2009/10/30 11:55:27 | 00,000,000 | ---D | C] -- C:\ProgramData\F-Secure [2009/10/30 11:55:27 | 00,000,000 | ---D | C] -- C:\ProgramData\F-Secure [2009/10/30 08:11:04 | 00,000,000 | ---D | C] -- C:\411fa47e3ddbc54545a8 [2009/10/29 12:52:26 | 00,096,104 | ---- | C] (Avira GmbH) -- C:\Windows\System32\drivers\avipbb.sys [2009/10/29 12:52:26 | 00,055,656 | ---- | C] (Avira GmbH) -- C:\Windows\System32\drivers\avgntflt.sys [2009/10/29 12:52:26 | 00,028,520 | ---- | C] (Avira GmbH) -- C:\Windows\System32\drivers\ssmdrv.sys [2009/10/29 12:52:24 | 00,000,000 | ---D | C] -- C:\ProgramData\Avira [2009/10/29 12:52:24 | 00,000,000 | ---D | C] -- C:\ProgramData\Avira [2009/10/29 12:52:24 | 00,000,000 | ---D | C] -- C:\Program Files\Avira [2009/10/29 11:50:26 | 00,000,000 | ---D | C] -- C:\Windows\System32\EventProviders [2009/10/29 11:45:48 | 00,000,000 | ---D | C] -- C:\ATF [2009/10/29 09:43:36 | 00,000,000 | ---D | C] -- C:\Users\Emma B. Sykes\AppData\Roaming\Malwarebytes [2009/10/29 09:43:31 | 00,019,160 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbam.sys [2009/10/29 09:43:29 | 00,038,224 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbamswissarmy.sys [2009/10/29 09:43:28 | 00,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes [2009/10/29 09:43:28 | 00,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes [2009/10/29 09:43:27 | 00,000,000 | ---D | C] -- C:\Program Files\Malwarebytes' Anti-Malware [2009/10/20 02:18:20 | 00,000,000 | ---D | C] -- C:\Users\Emma B. Sykes\Documents\Downloads ========== Files - Modified Within 14 Days ========== [2009/11/01 13:11:00 | 00,000,420 | -H-- | M] () -- C:\Windows\tasks\User_Feed_Synchronization-{5AAC805B-6979-433A-BA29-982C8F3E14C3}.job [2009/11/01 13:09:42 | 01,048,576 | -HS- | M] () -- C:\Users\Emma B. Sykes\NTUSER.DAT [2009/11/01 13:09:00 | 00,000,442 | -H-- | M] () -- C:\Windows\tasks\User_Feed_Synchronization-{EA5721F5-911A-40BB-849B-2B7900281668}.job [2009/11/01 13:05:44 | 00,003,616 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0 [2009/11/01 13:05:44 | 00,003,616 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0 [2009/11/01 12:48:01 | 00,000,886 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job [2009/11/01 12:41:15 | 00,000,868 | ---- | M] () -- C:\Windows\tasks\Google Software Updater.job [2009/11/01 12:02:21 | 00,067,584 | --S- | M] () -- C:\Windows\bootstat.dat [2009/10/31 23:48:02 | 00,000,882 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job [2009/10/31 23:05:34 | 00,000,006 | -H-- | M] () -- C:\Windows\tasks\SA.DAT [2009/10/31 23:05:12 | 21,361,33632 | -HS- | M] () -- C:\hiberfil.sys [2009/10/31 23:04:20 | 00,524,288 | -HS- | M] () -- C:\Users\Emma B. Sykes\NTUSER.DAT{d8932e6d-6a6f-11db-b6ab-a038f15a5785}.TMContainer00000000000000000001.regtrans-ms [2009/10/31 23:04:20 | 00,065,536 | -HS- | M] () -- C:\Users\Emma B. Sykes\NTUSER.DAT{d8932e6d-6a6f-11db-b6ab-a038f15a5785}.TM.blf [2009/10/31 22:44:51 | 00,595,446 | ---- | M] () -- C:\Windows\System32\perfh009.dat [2009/10/31 22:44:51 | 00,101,144 | ---- | M] () -- C:\Windows\System32\perfc009.dat [2009/10/31 22:44:50 | 00,690,960 | ---- | M] () -- C:\Windows\System32\PerfStringBackup.INI [2009/10/31 22:34:40 | 00,000,000 | -H-- | M] () -- C:\Windows\System32\drivers\Msft_User_WpdFs_01_07_00.Wdf [2009/10/31 20:16:11 | 01,673,014 | -H-- | M] () -- C:\Users\Emma B. Sykes\AppData\Local\IconCache.db [2009/10/31 17:00:00 | 00,000,440 | ---- | M] () -- C:\Windows\tasks\ParetoLogic Registration.job [2009/10/31 10:45:12 | 00,005,216 | ---- | M] () -- C:\Users\Emma B. Sykes\AppData\Local\d3d9caps.dat [2009/10/31 10:15:01 | 00,248,032 | ---- | M] () -- C:\Windows\System32\FNTCACHE.DAT [2009/10/30 12:57:39 | 00,000,488 | ---- | M] () -- C:\Users\Emma B. Sykes\Desktop\TFC - Shortcut.lnk [2009/10/30 11:31:03 | 13,905,3260 | ---- | M] () -- C:\Windows\MEMORY.DMP [2009/10/29 14:25:01 | 00,000,534 | ---- | M] () -- C:\Users\Emma B. Sykes\Desktop\ATF-Cleaner - Shortcut.lnk [2009/10/29 12:52:34 | 00,001,849 | ---- | M] () -- C:\Users\Public\Desktop\Avira AntiVir Control Center.lnk [2009/10/29 12:15:40 | 13,296,672 | -HS- | M] () -- C:\Windows\System32\drivers\fidbox.dat [2009/10/29 12:15:40 | 00,180,200 | -HS- | M] () -- C:\Windows\System32\drivers\fidbox.idx [2009/10/29 10:17:17 | 00,000,000 | ---- | M] () -- C:\Windows\System32\null [2009/10/29 09:43:32 | 00,000,820 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk [2009/10/25 08:17:57 | 00,000,923 | ---- | M] () -- C:\Users\Emma B. Sykes\Desktop\magicJack.lnk ========== Files Created - No Company Name ========== [2009/10/31 22:34:40 | 00,000,000 | -H-- | C] () -- C:\Windows\System32\drivers\Msft_User_WpdFs_01_07_00.Wdf [2009/10/31 10:45:11 | 00,005,216 | ---- | C] () -- C:\Users\Emma B. Sykes\AppData\Local\d3d9caps.dat [2009/10/30 12:57:39 | 00,000,488 | ---- | C] () -- C:\Users\Emma B. Sykes\Desktop\TFC - Shortcut.lnk [2009/10/29 14:25:01 | 00,000,534 | ---- | C] () -- C:\Users\Emma B. Sykes\Desktop\ATF-Cleaner - Shortcut.lnk [2009/10/29 12:52:34 | 00,001,849 | ---- | C] () -- C:\Users\Public\Desktop\Avira AntiVir Control Center.lnk [2009/10/29 09:43:32 | 00,000,820 | ---- | C] () -- C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk [2009/10/20 13:46:51 | 00,130,008 | ---- | C] () -- C:\Windows\System32\systemsf.ebd [2009/10/20 13:46:49 | 00,009,239 | ---- | C] () -- C:\Windows\System32\spcinstrumentation.man [2009/10/20 13:46:43 | 00,442,788 | ---- | C] () -- C:\Windows\System32\dot3.tmf [2009/10/20 13:46:42 | 00,117,248 | ---- | C] () -- C:\Windows\System32\EhStorAuthn.dll [2009/10/20 13:46:42 | 00,107,612 | ---- | C] () -- C:\Windows\System32\StructuredQuerySchema.bin [2009/10/20 13:46:40 | 03,662,128 | ---- | C] () -- C:\Windows\System32\locale.nls [2009/10/20 13:46:39 | 00,392,170 | ---- | C] () -- C:\Windows\System32\onex.tmf [2009/10/20 13:46:35 | 00,344,698 | ---- | C] () -- C:\Windows\System32\eaphost.tmf [2009/10/20 13:46:23 | 00,208,966 | ---- | C] () -- C:\Windows\System32\WFP.TMF [2009/10/20 13:46:21 | 00,092,918 | ---- | C] () -- C:\Windows\System32\slmgr.vbs [2009/10/20 13:45:56 | 00,009,212 | ---- | C] () -- C:\Windows\System32\RacUR.xml [2009/10/18 10:28:53 | 01,673,014 | -H-- | C] () -- C:\Users\Emma B. Sykes\AppData\Local\IconCache.db [2009/10/15 02:06:00 | 00,000,197 | ---- | C] () -- C:\Windows\System32\MRT.INI [2009/10/10 14:49:02 | 00,030,941 | ---- | C] () -- C:\Users\Emma B. Sykes\AppData\Roaming\UserTile.png [2009/10/03 15:07:54 | 00,054,600 | ---- | C] () -- C:\Users\Emma B. Sykes\AppData\Local\GDIPFONTCACHEV1.DAT [2009/09/30 16:57:14 | 00,000,432 | ---- | C] () -- C:\Windows\System32\iolo.ini [2009/09/30 16:53:08 | 00,126,976 | ---- | C] () -- C:\Windows\System32\iavlsp.dll [2009/09/30 16:45:37 | 00,008,337 | ---- | C] () -- C:\ProgramData\LUUnInstall.LiveUpdate [2009/09/30 16:20:35 | 00,074,703 | ---- | C] () -- C:\Windows\System32\mfc45.dll [2009/09/26 14:39:38 | 00,307,200 | ---- | C] () -- C:\Windows\System32\AscSQLite.dll [2009/09/05 20:44:58 | 00,223,232 | ---- | C] () -- C:\Windows\System32\sqlite3.dll [2009/09/05 20:44:57 | 00,086,016 | ---- | C] () -- C:\Windows\System32\SQLiteWrapper.dll [2009/08/03 14:07:42 | 00,403,816 | ---- | C] () -- C:\Windows\System32\OGACheckControl.dll [2009/05/25 14:42:28 | 00,320,000 | ---- | C] () -- C:\Windows\System32\roboex32.dll [2009/03/15 19:18:57 | 00,000,049 | ---- | C] () -- C:\Windows\Masque.INI [2008/07/26 16:01:18 | 00,000,376 | ---- | C] () -- C:\Windows\ODBC.INI [2008/07/22 20:29:07 | 01,238,832 | ---- | C] () -- C:\Windows\System32\igmedkrn.dll [2008/07/22 20:29:07 | 00,147,456 | ---- | C] () -- C:\Windows\System32\igfxCoIn_v1322.dll [2008/07/22 20:29:07 | 00,104,636 | ---- | C] () -- C:\Windows\System32\igmedcompkrn.dll [2008/02/11 18:55:18 | 00,147,456 | ---- | C] () -- C:\Windows\System32\igfxCoIn_v1437.dll [2006/11/02 06:48:00 | 00,000,174 | -HS- | C] () -- C:\Program Files\desktop.ini [2006/11/02 06:35:51 | 00,037,665 | ---- | C] () -- C:\Windows\Fonts\GlobalUserInterface.CompositeFont [2006/11/02 06:35:51 | 00,029,779 | ---- | C] () -- C:\Windows\Fonts\GlobalSerif.CompositeFont [2006/11/02 06:35:51 | 00,026,489 | ---- | C] () -- C:\Windows\Fonts\GlobalSansSerif.CompositeFont [2006/11/02 06:35:51 | 00,026,040 | ---- | C] () -- C:\Windows\Fonts\GlobalMonospace.CompositeFont [2006/11/02 04:25:44 | 00,159,744 | ---- | C] () -- C:\Windows\System32\atitmmxx.dll [2006/11/02 04:23:31 | 00,000,319 | ---- | C] () -- C:\Windows\win.ini [2006/11/02 04:23:31 | 00,000,219 | ---- | C] () -- C:\Windows\system.ini [2006/11/02 01:40:29 | 00,013,750 | ---- | C] () -- C:\Windows\System32\pacerprf.ini ========== LOP Check ========== [2009/10/03 15:08:07 | 00,000,000 | ---D | M] -- C:\Users\Emma B. Sykes\AppData\Roaming\iolo [2009/10/10 16:28:47 | 00,000,000 | ---D | M] -- C:\Users\Emma B. Sykes\AppData\Roaming\magicJackOutlookAddIn [2009/10/25 08:17:56 | 00,000,000 | ---D | M] -- C:\Users\Emma B. Sykes\AppData\Roaming\mjusbsp [2009/10/10 14:48:57 | 00,000,000 | ---D | M] -- C:\Users\Emma B. Sykes\AppData\Roaming\PeerNetworking [2009/10/17 12:32:00 | 00,000,000 | ---D | M] -- C:\Users\Emma B. Sykes\AppData\Roaming\VTExtra [2009/10/02 21:18:33 | 00,000,000 | ---D | M] -- C:\Users\Jessie J. Sykes\AppData\Roaming\iolo [2009/10/09 17:50:25 | 00,000,000 | ---D | M] -- C:\Users\Jessie J. Sykes\AppData\Roaming\WildTangent [2009/09/30 16:33:15 | 00,000,000 | ---D | M] -- C:\Users\Mariska Sykes\AppData\Roaming\iolo [2009/06/26 14:11:10 | 00,000,000 | ---D | M] -- C:\Users\Mariska Sykes\AppData\Roaming\PeerNetworking [2009/10/04 11:31:18 | 00,000,000 | ---D | M] -- C:\Users\Mariska Sykes\AppData\Roaming\PlayFirst [2009/10/05 18:03:08 | 00,000,000 | ---D | M] -- C:\Users\Mariska Sykes\AppData\Roaming\W Photo Studio [2009/09/05 18:49:25 | 00,000,000 | ---D | M] -- C:\Users\Mariska Sykes\AppData\Roaming\Walgreens [2009/06/26 11:52:56 | 00,000,000 | ---D | M] -- C:\Users\Mariska Sykes\AppData\Roaming\WildTangent [2009/10/31 17:00:00 | 00,000,440 | ---- | M] () -- C:\Windows\Tasks\ParetoLogic Registration.job [2009/10/31 23:05:34 | 00,000,006 | -H-- | M] () -- C:\Windows\Tasks\SA.DAT [2009/10/31 23:04:26 | 00,032,614 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT [2009/11/01 13:11:00 | 00,000,420 | -H-- | M] () -- C:\Windows\Tasks\User_Feed_Synchronization-{5AAC805B-6979-433A-BA29-982C8F3E14C3}.job [2009/11/01 13:09:00 | 00,000,442 | -H-- | M] () -- C:\Windows\Tasks\User_Feed_Synchronization-{EA5721F5-911A-40BB-849B-2B7900281668}.job ========== Purity Check ========== ========== Custom Scans ========== < %SYSTEMDRIVE%\*.exe > < %SYSTEMDRIVE%\eventlog.dll /s /md5 > < %SYSTEMDRIVE%\scecli.dll /s /md5 > [2009/04/11 00:28:24 | 00,177,152 | ---- | M] (Microsoft Corporation) MD5=8FC182167381E9915651267044105EE1 -- C:\Windows\System32\scecli.dll [2008/01/20 20:34:39 | 00,177,152 | ---- | M] (Microsoft Corporation) MD5=28B84EB538F7E8A0FE8B9299D591E0B9 -- C:\Windows\winsxs\x86_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.0.6001.18000_none_380de25bd91b6f12\scecli.dll [2009/04/11 00:28:24 | 00,177,152 | ---- | M] (Microsoft Corporation) MD5=8FC182167381E9915651267044105EE1 -- C:\Windows\winsxs\x86_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.0.6002.18005_none_39f95b67d63d3a5e\scecli.dll < %SYSTEMDRIVE%\netlogon.dll /s /md5 > [2009/04/11 00:28:23 | 00,592,896 | ---- | M] (Microsoft Corporation) MD5=95DAECF0FB120A7B5DA679CC54E37DDE -- C:\Windows\System32\netlogon.dll [2008/01/20 20:33:41 | 00,592,384 | ---- | M] (Microsoft Corporation) MD5=A8EFC0B6E75B789F7FD3BA5025D4E37F -- C:\Windows\winsxs\x86_microsoft-windows-security-netlogon_31bf3856ad364e35_6.0.6001.18000_none_fdb7b74337f9e857\netlogon.dll [2009/04/11 00:28:23 | 00,592,896 | ---- | M] (Microsoft Corporation) MD5=95DAECF0FB120A7B5DA679CC54E37DDE -- C:\Windows\winsxs\x86_microsoft-windows-security-netlogon_31bf3856ad364e35_6.0.6002.18005_none_ffa3304f351bb3a3\netlogon.dll < %SYSTEMDRIVE%\cngaudit.dll /s /md5 > [2006/11/02 03:46:03 | 00,011,776 | ---- | M] (Microsoft Corporation) MD5=7F15B4953378C8B5161D65C26D5FED4D -- C:\Windows\System32\cngaudit.dll [2006/11/02 03:46:03 | 00,011,776 | ---- | M] (Microsoft Corporation) MD5=7F15B4953378C8B5161D65C26D5FED4D -- C:\Windows\winsxs\x86_microsoft-windows-cngaudit-dll_31bf3856ad364e35_6.0.6000.16386_none_e62d292932a96ce6\cngaudit.dll < %SYSTEMDRIVE%\sceclt.dll /s /md5 > < %SYSTEMDRIVE%\ntelogon.dll /s /md5 > < %SYSTEMDRIVE%\logevent.dll /s /md5 > < %SYSTEMDRIVE%\iaStor.sys /s /md5 > [2007/05/14 03:08:48 | 00,304,920 | ---- | M] (Intel Corporation) MD5=997E8F5939F2D12CD9F2E6B395724C16 -- C:\Drivers\storage\R154092\iastor.sys [2007/05/14 03:08:48 | 00,304,920 | ---- | M] (Intel Corporation) MD5=997E8F5939F2D12CD9F2E6B395724C16 -- C:\Windows\System32\drivers\iaStor.sys [2007/05/14 03:08:48 | 00,304,920 | ---- | M] (Intel Corporation) MD5=997E8F5939F2D12CD9F2E6B395724C16 -- C:\Windows\System32\DriverStore\FileRepository\iaahci.inf_3a63e5a6\iaStor.sys [2007/05/14 03:08:48 | 00,304,920 | ---- | M] (Intel Corporation) MD5=997E8F5939F2D12CD9F2E6B395724C16 -- C:\Windows\System32\DriverStore\FileRepository\iastor.inf_5f6e7be5\iaStor.sys < %SYSTEMDRIVE%\nvstor.sys /s /md5 > [2008/01/20 20:32:47 | 00,045,112 | ---- | M] (NVIDIA Corporation) MD5=ABED0C09758D1D97DB0042DBB2688177 -- C:\Windows\System32\drivers\nvstor.sys [2008/01/20 20:32:47 | 00,045,112 | ---- | M] (NVIDIA Corporation) MD5=ABED0C09758D1D97DB0042DBB2688177 -- C:\Windows\System32\DriverStore\FileRepository\nvraid.inf_31c3d71d\nvstor.sys [2006/11/02 03:50:13 | 00,040,040 | ---- | M] (NVIDIA Corporation) MD5=9E0BA19A28C498A6D323D065DB76DFFC -- C:\Windows\System32\DriverStore\FileRepository\nvraid.inf_733654ff\nvstor.sys [2008/01/20 20:32:47 | 00,045,112 | ---- | M] (NVIDIA Corporation) MD5=ABED0C09758D1D97DB0042DBB2688177 -- C:\Windows\winsxs\x86_nvraid.inf_31bf3856ad364e35_6.0.6001.18000_none_39dac327befea467\nvstor.sys < %SYSTEMDRIVE%\atapi.sys /s /md5 > [2009/04/11 00:32:26 | 00,019,944 | ---- | M] (Microsoft Corporation) MD5=1F05B78AB91C9075565A9D8A4B880BC4 -- C:\Windows\System32\drivers\atapi.sys [2009/04/11 00:32:26 | 00,019,944 | ---- | M] (Microsoft Corporation) MD5=1F05B78AB91C9075565A9D8A4B880BC4 -- C:\Windows\System32\DriverStore\FileRepository\mshdc.inf_b12d8e84\atapi.sys [2006/11/02 03:49:36 | 00,019,048 | ---- | M] (Microsoft Corporation) MD5=4F4FCB8B6EA06784FB6D475B7EC7300F -- C:\Windows\System32\DriverStore\FileRepository\mshdc.inf_c6c2e699\atapi.sys [2008/01/20 20:32:21 | 00,021,560 | ---- | M] (Microsoft Corporation) MD5=2D9C903DC76A66813D350A562DE40ED9 -- C:\Windows\System32\DriverStore\FileRepository\mshdc.inf_cc18792d\atapi.sys [2008/01/20 20:32:21 | 00,021,560 | ---- | M] (Microsoft Corporation) MD5=2D9C903DC76A66813D350A562DE40ED9 -- C:\Windows\winsxs\x86_mshdc.inf_31bf3856ad364e35_6.0.6001.18000_none_dd38281a2189ce9c\atapi.sys [2009/04/11 00:32:26 | 00,019,944 | ---- | M] (Microsoft Corporation) MD5=1F05B78AB91C9075565A9D8A4B880BC4 -- C:\Windows\winsxs\x86_mshdc.inf_31bf3856ad364e35_6.0.6002.18005_none_df23a1261eab99e8\atapi.sys < %SYSTEMDRIVE%\IdeChnDr.sys /s /md5 > < %SYSTEMDRIVE%\viasraid.sys /s /md5 > < %SYSTEMDRIVE%\AGP440.sys /s /md5 > [2008/01/20 20:32:22 | 00,056,376 | ---- | M] (Microsoft Corporation) MD5=13F9E33747E6B41A3FF305C37DB0D360 -- C:\Windows\System32\drivers\AGP440.sys [2008/01/20 20:32:22 | 00,056,376 | ---- | M] (Microsoft Corporation) MD5=13F9E33747E6B41A3FF305C37DB0D360 -- C:\Windows\System32\DriverStore\FileRepository\machine.inf_51b95d75\AGP440.sys [2006/11/02 03:49:52 | 00,053,864 | ---- | M] (Microsoft Corporation) MD5=EF23439CDD587F64C2C1B8825CEAD7D8 -- C:\Windows\System32\DriverStore\FileRepository\machine.inf_920a2c1f\AGP440.sys [2008/01/20 20:32:22 | 00,056,376 | ---- | M] (Microsoft Corporation) MD5=13F9E33747E6B41A3FF305C37DB0D360 -- C:\Windows\System32\DriverStore\FileRepository\machine.inf_f750e484\AGP440.sys [2008/01/20 20:32:22 | 00,056,376 | ---- | M] (Microsoft Corporation) MD5=13F9E33747E6B41A3FF305C37DB0D360 -- C:\Windows\winsxs\x86_machine.inf_31bf3856ad364e35_6.0.6001.18000_none_ba12ed3bbeb0d97a\AGP440.sys [2008/01/20 20:32:22 | 00,056,376 | ---- | M] (Microsoft Corporation) MD5=13F9E33747E6B41A3FF305C37DB0D360 -- C:\Windows\winsxs\x86_machine.inf_31bf3856ad364e35_6.0.6002.18005_none_bbfe6647bbd2a4c6\AGP440.sys < %SYSTEMDRIVE%\vaxscsi.sys /s /md5 > < > ========== Alternate Data Streams ========== @Alternate Data Stream - 124 bytes -> C:\ProgramData\TEMP:ED2998F5 @Alternate Data Stream - 118 bytes -> C:\ProgramData\TEMP:35A81752 @Alternate Data Stream - 117 bytes -> C:\ProgramData\TEMP:B67A5784 @Alternate Data Stream - 115 bytes -> C:\ProgramData\TEMP:58C9BCAC @Alternate Data Stream - 108 bytes -> C:\ProgramData\TEMP:5FBC2BC4 < End of report > OTL EXTRAS: OTL Extras logfile created on: 11/1/2009 1:09:35 PM - Run 1 OTL by OldTimer - Version 3.1.1.8 Folder = C:\ATF Windows Vista Home Basic Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation Internet Explorer (Version = 8.0.6001.18828) Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy 1.99 Gb Total Physical Memory | 1.42 Gb Available Physical Memory | 71.20% Memory free 4.00 Gb Paging File | 3.32 Gb Available in Paging File | 82.99% Paging File free Paging file location(s): ?:\pagefile.sys [binary data] %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files Drive C: | 64.45 Gb Total Space | 31.09 Gb Free Space | 48.24% Space Free | Partition Type: NTFS Drive D: | 10.00 Gb Total Space | 6.79 Gb Free Space | 67.85% Space Free | Partition Type: NTFS E: Drive not present or media not loaded F: Drive not present or media not loaded G: Drive not present or media not loaded H: Drive not present or media not loaded I: Drive not present or media not loaded Computer Name: EMMA-PC Current User Name: Emma Logged in as Administrator. Current Boot Mode: Normal Scan Mode: All users Company Name Whitelist: On Skip Microsoft Files: On File Age = 14 Days Output = Standard Quick Scan ========== Extra Registry (SafeList) ========== ========== File Associations ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>] .chm [@ = chm.file] -- "%SystemRoot%\hh.exe" %1 .cpl [@ = cplfile] -- C:\Windows\System32\control.exe (Microsoft Corporation) .hlp [@ = hlpfile] -- C:\Windows\winhlp32.exe (Microsoft Corporation) .html [@ = htmlfile] -- C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation) ========== Shell Spawning ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command] batfile [open] -- "%1" %* File not found chm.file [open] -- "%SystemRoot%\hh.exe" %1 File not found cmdfile [open] -- "%1" %* File not found comfile [open] -- "%1" %* File not found cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation) exefile [open] -- "%1" %* File not found helpfile [open] -- Reg Error: Key error. hlpfile [open] -- %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation) htmlfile [edit] -- "C:\Program Files\Microsoft Office\Office10\msohtmed.exe" %1 (Microsoft Corporation) htmlfile [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" -nohome (Microsoft Corporation) htmlfile [opennew] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) htmlfile [print] -- "C:\Program Files\Microsoft Office\Office10\msohtmed.exe" /p %1 (Microsoft Corporation) http [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" -nohome (Microsoft Corporation) https [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" -nohome (Microsoft Corporation) inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation) piffile [open] -- "%1" %* File not found regfile [merge] -- Reg Error: Key error. scrfile [config] -- "%1" File not found scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation) scrfile [open] -- "%1" /S File not found txtfile [edit] -- Reg Error: Key error. Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1 File not found Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation) Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Folder [open] -- %SystemRoot%\Explorer.exe /separate,/idlist,%I,%L (Microsoft Corporation) Folder [explore] -- %SystemRoot%\Explorer.exe /separate,/e,/idlist,%I,%L (Microsoft Corporation) Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Applications\iexplore.exe [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] -- "C:\Program Files\Internet Explorer\iexplore.exe" (Microsoft Corporation) ========== Security Center Settings ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center] "cval" = 1 "UacDisableNotify" = 1 "InternetSettingsDisableNotify" = 1 "AutoUpdateDisableNotify" = 1 "AntiVirusDisableNotify" = "AntiVirusOverride" = "FirewallDisableNotify" = "FirewallOverride" = "FirstRunDisabled" = "UpdatesDisableNotify" = [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring] "DisableMonitoring" = 1 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus] "DisableMonitoring" = 1 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall] "DisableMonitoring" = 1 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc] "AntiVirusOverride" = 1 "AntiSpywareOverride" = 1 "FirewallOverride" = 0 "VistaSp1" = Reg Error: Unknown registry data type -- File not found "VistaSp2" = Reg Error: Unknown registry data type -- File not found [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\S-1-5-21-1696485601-562263704-4103742560-1002] "EnableNotifications" = 0 "EnableNotificationsRef" = 1 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile] "EnableFirewall" = 1 "DisableNotifications" = 0 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile] "EnableFirewall" = 1 "DisableNotifications" = 0 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile] "EnableFirewall" = 1 "DisableNotifications" = 0 ========== Authorized Applications List ========== ========== Vista Active Open Ports Exception List ========== [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{052DD06E-C6C3-4245-852A-42FDC721D1C8}" = lport=3702 | protocol=17 | dir=in | svc=fdphost | app=%systemroot%\system32\svchost.exe | "{0823E779-E6D6-48E2-9BE4-715BE2C0066E}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe | "{0A376387-6713-46D4-AA2E-C49BD49BA884}" = lport=2177 | protocol=6 | dir=in | svc=qwave | app=c:\windows\system32\svchost.exe | "{0CE719B0-D95F-42E3-A458-102D520901B0}" = rport=3702 | protocol=17 | dir=out | svc=fdphost | app=%systemroot%\system32\svchost.exe | "{130BEC69-4BAF-4F2E-BD9B-12967FDC97C5}" = lport=445 | protocol=6 | dir=in | app=system | "{16B5EB76-70E9-4392-9541-2991E2E152F8}" = lport=1723 | protocol=6 | dir=in | app=system | "{1BD3FD47-3E71-4E7C-B461-20E88A2AA858}" = lport=3540 | protocol=17 | dir=in | svc=pnrpsvc | app=%systemroot%\system32\svchost.exe | "{1C2D3A35-9006-4B43-AB8C-65002BCD5DB3}" = lport=3702 | protocol=17 | dir=in | app=%systemroot%\system32\p2phost.exe | "{20151EE4-F8C6-4BCC-AC5A-273948F9ED3C}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=c:\windows\system32\spoolsv.exe | "{23A73F34-3F6E-41B6-87FA-51C5A0895EC6}" = lport=3540 | protocol=17 | dir=in | svc=pnrpsvc | app=%systemroot%\system32\svchost.exe | "{25D87381-4176-4AF3-A4D9-2F68335CA881}" = lport=80 | protocol=6 | dir=in | app=system | "{2A483CF9-F9FB-405F-9435-E71244102C19}" = lport=2869 | protocol=6 | dir=in | app=system | "{2FCA0CD9-F0D2-4B02-A323-6EEBBF5B6645}" = rport=3540 | protocol=17 | dir=out | svc=pnrpsvc | app=%systemroot%\system32\svchost.exe | "{387151DD-9989-447D-ACA0-2ED90EDDB3BE}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe | "{392599EC-EB16-448A-98D7-A1327463FDEF}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | app=c:\windows\system32\svchost.exe | "{3E978E73-02CF-4542-A4FF-AF898B862F1E}" = rport=3702 | protocol=17 | dir=out | svc=fdrespub | app=%systemroot%\system32\svchost.exe | "{3EA3F557-05B6-4619-9B55-A0B737B26EE8}" = rport=1701 | protocol=17 | dir=out | app=system | "{4010D38D-F708-4555-9796-F9680847D2CE}" = lport=137 | protocol=17 | dir=in | app=system | "{47B3E24E-C20F-40BF-90BA-59B73DDDD844}" = lport=2869 | protocol=6 | dir=in | app=system | "{4AB9DB25-2125-400D-8192-0CA8D6244679}" = lport=135 | protocol=6 | dir=in | svc=rpcss | app=c:\windows\system32\svchost.exe | "{4D58135B-A021-47A7-B436-C5B92FE17C60}" = rport=3702 | protocol=17 | dir=out | app=%systemroot%\system32\p2phost.exe | "{59F94095-481A-4660-8A69-F56921D6A346}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe | "{5A4F2A5B-7FAA-4EBB-9FB6-910F5223F68F}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=c:\windows\system32\svchost.exe | "{5CD91B6E-1437-482F-86CF-7308A73AB834}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | app=c:\windows\system32\svchost.exe | "{5D550959-A384-4F59-8949-C2F66D2F0E4D}" = rport=1723 | protocol=6 | dir=out | app=system | "{6E5E76F4-F2C8-4E2C-93CB-AF3F7299213E}" = rport=139 | protocol=6 | dir=out | app=system | "{775F0E8A-B3DE-443B-A066-A24A40C58BC3}" = rport=2177 | protocol=6 | dir=out | svc=qwave | app=c:\windows\system32\svchost.exe | "{77A3A415-A0C7-4722-83BC-236886B95926}" = lport=rpc | protocol=6 | dir=in | app=c:\windows\system32\services.exe | "{7DF52286-3A49-43F8-BED1-2AFBE9DC4A4B}" = lport=rpc | protocol=6 | dir=in | app=c:\windows\system32\vdsldr.exe | "{7ECCDA39-A8F8-4E49-8339-8EE61B1B23A2}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=file and printer sharing (spooler service - rpc-epmap) | "{817AEB13-60F6-474F-81C9-23E48A9553C3}" = lport=rpc | protocol=6 | dir=in | svc=vds | app=c:\windows\system32\vds.exe | "{8275C3E2-1204-4700-B038-B8D64248A40E}" = lport=rpc | protocol=6 | dir=in | svc=ktmrm | app=c:\windows\system32\svchost.exe | "{82F0E762-884D-4FF1-BAAA-65F63E39AA63}" = lport=3702 | protocol=17 | dir=in | svc=fdrespub | app=%systemroot%\system32\svchost.exe | "{87214BE5-B668-48B8-943C-9909B147B0B0}" = rport=10243 | protocol=6 | dir=out | app=system | "{8A92B145-58CC-4DA7-B69E-170C396F2468}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe | "{8C62F4B6-94AF-4607-85B8-0A031F535B2A}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe | "{9734CC1D-BCB5-4652-ADA0-FF5C4BB8B772}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe | "{9B75C531-5865-4719-A37D-D21CA3F47042}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=c:\windows\system32\svchost.exe | "{A3DDE308-3086-4C11-9E0D-1D4C90B18C35}" = lport=138 | protocol=17 | dir=in | app=system | "{A4291EB9-8D75-4599-8E5B-C479BCD2D237}" = lport=1701 | protocol=17 | dir=in | app=system | "{A950CCB2-BB69-4C57-A8CA-8217B0D003AE}" = lport=10243 | protocol=6 | dir=in | app=system | "{B242DA49-5EC6-477F-9423-A6330C2E5B8B}" = rport=2177 | protocol=17 | dir=out | svc=qwave | app=c:\windows\system32\svchost.exe | "{B51348F7-88D3-4BE3-B2CC-FD36FB539630}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=c:\windows\system32\svchost.exe | "{B5998AB9-EAFF-4A59-9F05-87B7899B5961}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=c:\windows\system32\svchost.exe | "{B5F6815D-EE90-4062-A664-5E67E75A9B5A}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | app=c:\windows\system32\svchost.exe | "{C4F5213E-5DD0-4BCB-A900-FDE3B0ABB370}" = lport=rpc | protocol=6 | dir=in | svc=policyagent | app=c:\windows\system32\svchost.exe | "{C679ECC0-7EAB-466B-8E9B-C41F29867127}" = lport=2177 | protocol=17 | dir=in | svc=qwave | app=c:\windows\system32\svchost.exe | "{CA6797C4-E055-4D5A-9248-A3A130DD1314}" = lport=443 | protocol=6 | dir=in | app=system | "{CBF10962-F0DA-47BC-97AB-89DB386118D0}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | app=c:\windows\system32\svchost.exe | "{D3C25C97-BB61-4818-8B96-DB4AFB96DCD2}" = rport=137 | protocol=17 | dir=out | app=system | "{E02DCCB3-2F37-4E4B-9303-008AB2D55E18}" = lport=445 | protocol=6 | dir=in | app=system | "{E057D77B-2BBE-4AA4-8D4E-1E5EE6C07D57}" = lport=3702 | protocol=17 | dir=in | app=%systemroot%\system32\p2phost.exe | "{E0EA46F2-BB01-45D7-A29D-48FE03DEC7B6}" = rport=3702 | protocol=17 | dir=out | app=%systemroot%\system32\p2phost.exe | "{E3F68573-97AD-487B-BD85-DC046D1AC00F}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe | "{EB9B1B0F-9D5D-4967-BBEF-E7D9357AC1DD}" = rport=138 | protocol=17 | dir=out | app=system | "{EE3A9CC3-6A5B-4507-A81A-E0E37766938E}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe | "{F554622D-C017-49F2-AB35-006CB17C9601}" = lport=rpc | protocol=6 | dir=in | svc=schedule | app=c:\windows\system32\svchost.exe | "{F5A2E225-9025-446F-BFA9-3DE0B9C66F1D}" = rport=3540 | protocol=17 | dir=out | svc=pnrpsvc | app=%systemroot%\system32\svchost.exe | "{FA35A6E3-3851-4A76-BBE1-2215C00F5B58}" = lport=139 | protocol=6 | dir=in | app=system | "{FD36F8E7-82C7-4F17-B405-9203A325B1FB}" = rport=445 | protocol=6 | dir=out | app=system | "{FF3AEFE3-936D-49B9-A981-D3648B3BEF6A}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | app=c:\windows\system32\svchost.exe | ========== Vista Active Application Exception List ========== [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{0BF78AA7-DCF9-485D-927C-41D17184447F}" = protocol=17 | dir=in | app=c:\program files\iolo\antivirus\ioloav.exe | "{0E31AA0A-F189-4D59-8EBD-082023F08581}" = protocol=1 | dir=in | name=file and printer sharing (echo request - icmpv4-in) | "{0F5D52B5-4021-480F-936A-CFD3BE77B90B}" = protocol=6 | dir=out | app=%systemroot%\system32\p2phost.exe | "{14CF4BEE-FE65-4603-A3EA-FCB2AC1EB9DB}" = protocol=6 | dir=out | app=c:\windows\system32\msra.exe | "{1E544957-1E28-4D7C-9A98-4EA93C67AA19}" = protocol=6 | dir=in | app=c:\windows\system32\plasrv.exe | "{269E972A-B422-4BA0-A908-796F3FD07063}" = protocol=17 | dir=out | app=c:\program files\windows media player\wmpnetwk.exe | "{2DA5B83C-40C7-46DA-8902-C6F8578E78AA}" = protocol=1 | dir=out | name=file and printer sharing (echo request - icmpv4-out) | "{351B6E94-2FB8-4212-BF5D-B1B7E1433526}" = protocol=58 | dir=out | name=file and printer sharing (echo request - icmpv6-out) | "{41AE9F7F-0300-4018-A224-7347D393928B}" = protocol=6 | dir=out | svc=upnphost | app=c:\windows\system32\svchost.exe | "{43B0443C-10A2-4B52-AC1A-8A65CDC1BF6F}" = protocol=17 | dir=in | app=c:\users\emma b. sykes\appdata\roaming\mjusbsp\magicjack.exe | "{487829C5-086F-451B-BB36-8EC098C5D70B}" = protocol=6 | dir=in | app=%systemroot%\system32\p2phost.exe | "{5672B34A-9E68-4DD0-9716-3504D98D0FF3}" = protocol=6 | dir=in | app=c:\program files\windows media player\wmpnetwk.exe | "{57B1A930-0376-451A-95D3-4E15AED7FB75}" = protocol=17 | dir=in | app=c:\program files\windows media player\wmplayer.exe | "{638CC116-40A0-489A-A0DC-108F64D0E214}" = protocol=17 | dir=in | app=c:\program files\windows media player\wmplayer.exe | "{655E03D3-D97D-4B7C-AAEC-39D593927266}" = protocol=17 | dir=in | app=c:\program files\dogpile toolbar\troubleshooter.exe | "{7058CDE8-D996-454A-A427-62212563E4D3}" = protocol=6 | dir=in | app=c:\windows\system32\msdtc.exe | "{796CACD3-2833-4D2C-9678-02D5486EF2D0}" = protocol=6 | dir=out | app=c:\program files\windows media player\wmplayer.exe | "{8583B6DB-856E-4EFC-8F24-2CAE3CE871BB}" = dir=in | app=c:\program files\cyberlink\powerdvd dx\powerdvd.exe | "{8839C7C8-D290-460C-AFCD-D16E75F32AE1}" = protocol=6 | dir=out | app=system | "{8D73116B-6716-407B-9391-948C13557CA2}" = protocol=17 | dir=out | app=c:\program files\windows media player\wmplayer.exe | "{925FABEB-BBB6-4313-B842-F83E6D3D865A}" = protocol=6 | dir=in | app=c:\users\emma b. sykes\appdata\roaming\mjusbsp\magicjack.exe | "{92AB825B-7F4E-416A-BB6F-DD743C4396B1}" = protocol=6 | dir=out | app=c:\windows\system32\msdtc.exe | "{9541C736-D565-4163-8677-FF64667DB4BA}" = protocol=6 | dir=out | app=system | "{984299C7-29F9-44AE-9AEA-B7667A4E5889}" = protocol=6 | dir=in | app=c:\program files\dogpile toolbar\troubleshooter.exe | "{9CE4E8E0-C845-4DE9-811D-F54E7664F24A}" = protocol=17 | dir=in | app=c:\program files\windows media player\wmpnetwk.exe | "{A48BFEE5-A3D3-4D3D-816B-FED7D9E98E89}" = protocol=17 | dir=in | app=c:\program files\iolo\antivirus\iavemailscanner.exe | "{B77BFCA0-B2BC-4C1D-AD00-F8D2BB513C9F}" = protocol=17 | dir=in | app=c:\program files\dogpile toolbar\toolbarupdate.exe | "{C2327328-6BFB-43E0-BEB7-637C6DD0ABA5}" = protocol=58 | dir=in | name=file and printer sharing (echo request - icmpv6-in) | "{C66B5A7D-183A-4A53-B347-28CAE382B58A}" = protocol=17 | dir=out | app=c:\program files\windows media player\wmplayer.exe | "{C8715675-B5CF-44BC-A19B-E8F10328304A}" = protocol=6 | dir=out | app=c:\program files\windows media player\wmplayer.exe | "{CB2911BE-FFE2-400D-A174-7ABF76D5B680}" = protocol=6 | dir=out | svc=upnphost | app=c:\windows\system32\svchost.exe | "{CBFD07D3-97DF-4CE9-B931-4BF5E148B3A3}" = protocol=6 | dir=in | app=c:\windows\system32\msra.exe | "{DBAEC280-1ED9-4603-B9B5-258475919BD4}" = dir=in | app=c:\program files\cyberlink\powerdvd dx\pdvddxsrv.exe | "{E30405EB-81E9-4A80-A789-734F26C84797}" = protocol=6 | dir=out | svc=upnphost | app=c:\windows\system32\svchost.exe | "{ED705D2B-F444-4159-9D10-DE51FA37F730}" = protocol=6 | dir=in | app=c:\program files\iolo\antivirus\iavemailscanner.exe | "{ED750459-B68F-4304-82ED-512CC6488EEC}" = protocol=6 | dir=in | app=c:\program files\dogpile toolbar\toolbarupdate.exe | "{EDD87036-225E-45FA-B961-50C0117A90AD}" = protocol=6 | dir=in | app=c:\program files\iolo\antivirus\ioloav.exe | "{F15E3AF0-A701-4CAC-8496-4E75612EC7F2}" = protocol=6 | dir=in | app=%systemroot%\system32\p2phost.exe | "{F59C710D-8739-4BA0-A724-70A0ADC8AE81}" = protocol=6 | dir=out | app=c:\program files\windows media player\wmpnetwk.exe | "{F7030A9F-38FB-45D9-A03B-DAF8620E0234}" = protocol=6 | dir=out | app=%systemroot%\system32\p2phost.exe | "{FC5A0D9D-70EB-4BB4-AB15-5451954D57A7}" = protocol=6 | dir=out | app=c:\windows\system32\wudfhost.exe | "{FCF29EFB-C55E-4B66-AD38-D85E9EDAB8B7}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe | "TCP Query User{4884C5AB-6010-4D81-9F64-ED94BC0F4BC2}C:\program files\internet explorer\iexplore.exe" = protocol=6 | dir=in | app=c:\program files\internet explorer\iexplore.exe | "TCP Query User{FFFF2755-99DB-45CE-9CF8-89241DCCDBB8}C:\users\emma b. sykes\appdata\roaming\mjusbsp\magicjack.exe" = protocol=6 | dir=in | app=c:\users\emma b. sykes\appdata\roaming\mjusbsp\magicjack.exe | "UDP Query User{31BF42A6-5E6F-4058-8B5C-21333DF1C017}C:\program files\internet explorer\iexplore.exe" = protocol=17 | dir=in | app=c:\program files\internet explorer\iexplore.exe | "UDP Query User{9F9E654A-4754-4713-BE07-2633F91A964D}C:\users\emma b. sykes\appdata\roaming\mjusbsp\magicjack.exe" = protocol=17 | dir=in | app=c:\users\emma b. sykes\appdata\roaming\mjusbsp\magicjack.exe | ========== HKEY_LOCAL_MACHINE Uninstall List ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}" = Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148 "{0394CDC8-FABD-4ED8-B104-03393876DFDF}" = Roxio Creator Tools "{07159635-9DFE-4105-BFC0-2817DB540C68}" = Roxio Activation Module "{0D397393-9B50-4C52-84D5-77E344289F87}" = Roxio Creator Data "{13F3917B56CD4C25848BDC69916971BB}" = DivX Converter "{18D10072035C4515918F7E37EAFAACFC}" = AutoUpdate "{26A24AE4-039D-4CA4-87B4-2F83216015FF}" = Java 6 Update 15 "{30465B6C-B53F-49A1-9EBA-A3F187AD502E}" = Roxio Update Manager "{3248F0A8-6813-11D6-A77B-00B0D0160050}" = Java 6 Update 5 "{37F964E4-9C3F-4066-B933-1747D3AC6737}" = Personal Entertainment Launcher "{3FC7CBBC4C1E11DCA1A752EA55D89593}" = DivX Version Checker "{4CBA3D4C-8F51-4D60-B27E-F6B641C571E7}" = Microsoft Search Enhancement Pack "{619CDD8A-14B6-43A1-AB6C-0F4EE48CE048}" = Roxio Creator Copy "{62230596-37E5-4618-A329-0D21F529A86F}" = Browser Address Error Redirector "{6675CA7F-E51B-4F6A-99D4-F8F0124C6EAA}" = Roxio Express Labeler 3 "{6811CAA0-BF12-11D4-9EA1-0050BAE317E1}" = PowerDVD "{6B7B6D4D-8F9B-4CB3-8CA4-BCA9CC4C1A22}" = EDocs "{75685CA8-0B74-45BB-9C64-744A0FB79EDC}" = Business Tools Launcher "{767CC44C-9BBC-438D-BAD3-FD4595DD148B}" = VC80CRTRedist - 8.0.50727.762 "{777CA40C-0206-4EF6-A0FC-618BF06BF8D0}" = Intel® PRO Network Connections 12.1.11.0 "{7B63B2922B174135AFC0E1377DD81EC2}" = DivX Codec "{7DB9F1E5-9ACB-410D-A7DC-7A3D023CE045}" = Dell Getting Started Guide "{83FFCFC7-88C6-41C6-8752-958A45325C82}" = Roxio Creator Audio "{880AF49C-34F7-4285-A8AD-8F7A3D1C33DC}" = Roxio Creator BDAV Plugin "{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight "{8ADFC4160D694100B5B8A22DE9DCABD9}" = DivX Player "{8D337F77-BE7F-41A2-A7CB-D5A63FD7049B}" = Sonic CinePlayer Decoder Pack "{90280409-6000-11D3-8CFE-0050048383C9}" = Microsoft Office XP Professional with FrontPage "{98177940-C048-4831-A279-F3888B1E2C7F}" = InstallMgr "{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 "{A8AC89BA-D8CB-4372-9743-1C54D23286B0}" = MSN Toolbar "{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper "{A96E97134CA649888820BCDE5E300BBD}" = H.264 Decoder "{AAC389499AEF40428987B3D30CFC76C9}" = MKV Splitter "{AC76BA86-7AD7-1033-7B44-A81200000003}" = Adobe Reader 8.1.2 "{AEF9DC35ADDF4825B049ACBFD1C6EB37}" = AAC Decoder "{B13A7C41581B411290FBC0395694E2A9}" = DivX Converter "{B2544A03-10D0-4E5E-BA69-0362FFC20D18}" = OGA Notifier 2.0.0048.0 "{B6EF6DCE-078E-4952-A7FA-352A9C349EB0}" = MSN Toolbar "{B7050CBDB2504B34BC2A9CA0A692CC29}" = DivX Web Player "{B7148D71-0A8F-4501-96B4-4E1CC67F874E}" = Microsoft Default Manager "{B8ABB25D-1E30-4ED7-A3CE-0F8BED439647}" = Product Support Launcher "{C8B0680B-CDAE-4809-9F91-387B6DE00F7C}" = Roxio Creator DE "{CBF3C503-946E-45EA-B347-EACC41781989}" = W Photo Studio "{CC016F21-3970-11DE-B878-005056806466}" = Google Earth "{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1 "{E3BFEE55-39E2-4BE0-B966-89FE583822C1}" = Dell Support Center (Support Software) "{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver "Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX "Avira AntiVir Desktop" = Avira AntiVir Personal - Free Antivirus "Best of Slots II" = Best of Slots II "ClassicBoard" = Milton Bradley Classic Board Games "DivX Plus DirectShow Filters" = DivX Plus DirectShow Filters "Google Chrome" = Google Chrome "Google Desktop" = Google Desktop "Google Updater" = Google Updater "HDMI" = Intel® Graphics Media Accelerator Driver "HughesNetTools" = HughesNetTools "LANGMaster eduExplorer" = LANGMaster eduExplorer "Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware "Masque Casino Games" = Masque Casino Games "Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1 "PROSetDX" = Intel® PRO Network Connections 12.1.11.0 "QuickTime" = QuickTime "RealArcade" = RealArcade "Rushmore Casino" = Rushmore Casino "Slots_is1" = Slots 1.0 "The Weather Channel Desktop 6" = The Weather Channel Desktop 6 "WildTangent dell Master Uninstall" = WildTangent Games "Yahoo! Search Defender" = Yahoo! Search Protection ========== HKEY_USERS Uninstall List ========== [HKEY_USERS\S-1-5-21-1696485601-562263704-4103742560-1005\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "magicJack Outlook Add-In" = magicJack Outlook Add-In 1.0.3.521 ========== Last 10 Event Log Errors ========== [ Application Events ] Error - 10/30/2009 6:33:31 PM | Computer Name = emma-PC | Source = WinMgmt | ID = 10 Description = Error - 10/30/2009 7:05:06 PM | Computer Name = emma-PC | Source = SPP | ID = 16387 Description = Error - 10/30/2009 7:05:06 PM | Computer Name = emma-PC | Source = System Restore | ID = 8193 Description = Error - 10/30/2009 7:05:06 PM | Computer Name = emma-PC | Source = System Restore | ID = 8210 Description = Error - 10/30/2009 11:04:24 PM | Computer Name = emma-PC | Source = WinMgmt | ID = 10 Description = Error - 10/31/2009 7:57:25 AM | Computer Name = emma-PC | Source = WinMgmt | ID = 10 Description = Error - 10/31/2009 9:43:44 AM | Computer Name = emma-PC | Source = WinMgmt | ID = 10 Description = Error - 10/31/2009 11:46:45 AM | Computer Name = emma-PC | Source = WinMgmt | ID = 10 Description = Error - 10/31/2009 12:15:35 PM | Computer Name = emma-PC | Source = WinMgmt | ID = 10 Description = Error - 10/31/2009 12:16:30 PM | Computer Name = emma-PC | Source = WinMgmt | ID = 10 Description = ========== Last 10 Event Log Errors ========== Error reading Event Logs: The Event Service is not operating properly or the Event Logs are corrupt! < End of report > PLEASE HELP! This post has been edited by shayspace: Nov 2 2009, 10:26 PM |
|
|
Nov 1 2009, 06:41 PM
Post
#2
|
|
![]() GeekU Teacher Posts: 35,078 From: Dublin OS: XP |
hi
Please download GooredFix from one of the locations below and save it to your Desktop Download Mirror #1 Download Mirror #2
Download ComboFix from one of these locations: Link 1 Link 2 * IMPORTANT !!! Save ComboFix.exe to your Desktop
**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures. ![]() Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message: ![]() Click on Yes, to continue scanning for malware. When finished, it shall produce a log for you. Please include the C:\ComboFix.txt log in your next reply. |
|
|
Nov 2 2009, 07:21 AM
Post
#3
|
|
|
New Member ![]() Posts: 5 OS: Windows Vista |
Here's the GooredFix Log:
GooredFix by jpshortstuff (24.09.09.1) Log created at 07:19 on 02/11/2009 (Emma B. Sykes) Firefox version [Unable to determine] ========== GooredScan ========== ========== GooredLog ========== C:\Program Files\Mozilla Firefox\extensions\ (none) [HKEY_LOCAL_MACHINE\Software\Mozilla\Firefox\Extensions] "{20a82645-c095-46ed-80e3-08825760534b}"="c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\" [08:13 04/09/2009] ---------- Old Logs ---------- GooredFix[13.17.42_02-11-2009].txt -=E.O.F=- |
|
|
Nov 2 2009, 09:09 AM
Post
#4
|
|
|
New Member ![]() Posts: 5 OS: Windows Vista |
ComboFix Log
ComboFix 09-11-01.04 - Emma B. Sykes 11/02/2009 8:54.2.2 - NTFSx86 Microsoft® Windows Vista™ Home Basic 6.0.6002.2.1252.1.1033.18.2036.1355 [GMT -6:00] Running from: c:\users\Emma B. Sykes\Desktop\ComboFix.exe SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46} . ((((((((((((((((((((((((( Files Created from 2009-10-02 to 2009-11-02 ))))))))))))))))))))))))))))))) . 2009-11-02 15:03 . 2009-11-02 15:03 -------- d-----w- c:\users\Emma B. Sykes\AppData\Local\temp 2009-11-02 15:03 . 2009-11-02 15:03 -------- d-----w- c:\users\Public\AppData\Local\temp 2009-11-02 15:03 . 2009-11-02 15:03 -------- d-----w- c:\users\Mariska Sykes\AppData\Local\temp 2009-11-02 15:03 . 2009-11-02 15:03 -------- d-----w- c:\users\Jessie J. Sykes\AppData\Local\temp 2009-11-02 15:03 . 2009-11-02 15:03 -------- d-----w- c:\users\Default\AppData\Local\temp 2009-11-02 13:06 . 2009-11-02 14:46 -------- d-----w- c:\users\Emma B. Sykes\Tracing 2009-11-02 08:06 . 2009-08-06 04:48 54632 ----a-w- c:\windows\system32\drivers\fssfltr.sys 2009-11-02 08:05 . 2009-11-02 08:05 -------- d-----w- c:\program files\Microsoft Sync Framework 2009-11-02 08:05 . 2006-11-29 19:06 3426072 ----a-w- c:\windows\system32\d3dx9_32.dll 2009-11-02 08:04 . 2009-11-02 08:04 -------- d-----w- c:\program files\Microsoft SQL Server Compact Edition 2009-11-02 08:03 . 2009-11-02 08:03 -------- d-----w- c:\program files\Windows Live SkyDrive 2009-11-02 08:03 . 2009-11-02 08:06 -------- d-----w- c:\program files\Windows Live 2009-11-02 08:03 . 2009-11-02 08:03 -------- d-----w- c:\windows\PCHEALTH 2009-11-02 05:25 . 2009-11-02 05:25 -------- d-----w- c:\program files\Common Files\Windows Live 2009-11-02 00:14 . 2009-11-02 00:14 -------- d-----w- c:\windows\CheckSur 2009-11-01 04:35 . 2009-11-01 04:35 -------- d-----w- c:\program files\Windows Portable Devices 2009-11-01 04:20 . 2009-10-01 01:02 30208 ----a-w- c:\windows\system32\WPDShextAutoplay.exe 2009-11-01 04:20 . 2009-10-01 01:02 31232 ----a-w- c:\windows\system32\BthMtpContextHandler.dll 2009-11-01 04:20 . 2009-10-01 01:01 81920 ----a-w- c:\windows\system32\wpdbusenum.dll 2009-11-01 04:20 . 2009-10-01 01:01 60928 ----a-w- c:\windows\system32\PortableDeviceConnectApi.dll 2009-11-01 04:20 . 2009-10-01 01:02 2537472 ----a-w- c:\windows\system32\wpdshext.dll 2009-11-01 04:20 . 2009-10-01 01:01 546816 ----a-w- c:\windows\system32\wpd_ci.dll 2009-11-01 04:20 . 2009-10-01 01:02 334848 ----a-w- c:\windows\system32\PortableDeviceApi.dll 2009-11-01 04:20 . 2009-10-01 01:02 87552 ----a-w- c:\windows\system32\WPDShServiceObj.dll 2009-11-01 04:20 . 2009-10-01 01:01 160256 ----a-w- c:\windows\system32\PortableDeviceTypes.dll 2009-11-01 04:20 . 2009-10-01 01:01 350208 ----a-w- c:\windows\system32\WPDSp.dll 2009-11-01 04:20 . 2009-10-01 01:01 196608 ----a-w- c:\windows\system32\PortableDeviceWMDRM.dll 2009-11-01 04:20 . 2009-10-01 01:01 100864 ----a-w- c:\windows\system32\PortableDeviceClassExtension.dll 2009-11-01 04:19 . 2009-10-08 21:07 4096 ----a-w- c:\windows\system32\oleaccrc.dll 2009-11-01 04:19 . 2009-10-08 21:08 234496 ----a-w- c:\windows\system32\oleacc.dll 2009-11-01 04:19 . 2009-10-08 21:08 555520 ----a-w- c:\windows\system32\UIAutomationCore.dll 2009-10-31 16:45 . 2009-10-31 16:45 5216 ----a-w- c:\users\Emma B. Sykes\AppData\Local\d3d9caps.dat 2009-10-31 16:09 . 2009-10-31 16:11 -------- d-----w- c:\windows\system32\ca-ES 2009-10-31 16:09 . 2009-10-31 16:10 -------- d-----w- c:\windows\system32\eu-ES 2009-10-31 16:09 . 2009-10-31 16:10 -------- d-----w- c:\windows\system32\vi-VN 2009-10-30 17:55 . 2009-10-30 17:55 -------- d-----w- c:\programdata\F-Secure 2009-10-30 14:11 . 2009-10-30 14:11 -------- d-----w- C:\411fa47e3ddbc54545a8 2009-10-30 06:26 . 2009-10-01 15:29 195440 ------w- c:\windows\system32\MpSigStub.exe 2009-10-29 18:52 . 2009-07-28 21:33 55656 ----a-w- c:\windows\system32\drivers\avgntflt.sys 2009-10-29 18:52 . 2009-03-30 15:33 96104 ----a-w- c:\windows\system32\drivers\avipbb.sys 2009-10-29 18:52 . 2009-10-29 18:52 -------- d-----w- c:\programdata\Avira 2009-10-29 18:52 . 2009-10-29 18:52 -------- d-----w- c:\program files\Avira 2009-10-29 17:50 . 2009-10-29 17:50 -------- d-----w- c:\windows\system32\EventProviders 2009-10-29 17:45 . 2009-11-02 00:36 -------- d-----w- C:\ATF 2009-10-29 15:43 . 2009-10-29 15:43 -------- d-----w- c:\users\Emma B. Sykes\AppData\Roaming\Malwarebytes 2009-10-29 15:43 . 2009-09-10 19:53 19160 ----a-w- c:\windows\system32\drivers\mbam.sys 2009-10-29 15:43 . 2009-09-10 19:54 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys 2009-10-29 15:43 . 2009-10-29 15:43 -------- d-----w- c:\programdata\Malwarebytes 2009-10-29 15:43 . 2009-10-29 15:49 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware 2009-10-28 16:24 . 2009-09-10 14:58 310784 ----a-w- c:\windows\system32\unregmp2.exe 2009-10-28 16:24 . 2009-09-10 14:59 8147456 ----a-w- c:\windows\system32\wmploc.DLL 2009-10-24 03:00 . 2009-10-24 03:00 -------- d-----w- c:\users\Mariska Sykes\AppData\Roaming\Roxio 2009-10-20 19:46 . 2009-04-11 06:28 324608 ----a-w- c:\windows\system32\sdohlp.dll 2009-10-20 19:45 . 2009-04-11 06:28 34304 ----a-w- c:\windows\system32\wshbth.dll 2009-10-20 13:12 . 2009-08-07 02:24 44768 ----a-w- c:\windows\system32\wups2.dll 2009-10-20 13:12 . 2009-08-07 02:24 53472 ----a-w- c:\windows\system32\wuauclt.exe 2009-10-20 13:12 . 2009-08-07 02:23 1929952 ----a-w- c:\windows\system32\wuaueng.dll 2009-10-20 13:12 . 2009-08-07 01:45 2421760 ----a-w- c:\windows\system32\wucltux.dll 2009-10-20 13:11 . 2009-08-07 02:24 35552 ----a-w- c:\windows\system32\wups.dll 2009-10-20 13:11 . 2009-08-07 02:23 575704 ----a-w- c:\windows\system32\wuapi.dll 2009-10-20 13:11 . 2009-08-07 01:44 87552 ----a-w- c:\windows\system32\wudriver.dll 2009-10-20 13:11 . 2009-08-07 00:23 171608 ----a-w- c:\windows\system32\wuwebv.dll 2009-10-20 13:11 . 2009-08-06 23:44 33792 ----a-w- c:\windows\system32\wuapp.exe 2009-10-17 18:21 . 2009-10-17 18:32 -------- d-----w- c:\users\Emma B. Sykes\AppData\Roaming\VTExtra 2009-10-17 18:15 . 2009-10-17 18:21 -------- d-----w- c:\users\Emma B. Sykes\AppData\Local\VTShared 2009-10-17 18:15 . 2009-10-29 18:00 -------- d-----w- c:\users\Emma B. Sykes\AppData\Local\VIPSlotsCasino 2009-10-17 17:57 . 2009-10-17 17:57 -------- d-----w- c:\users\Emma B. Sykes\Office Genuine Advantage 2009-10-15 20:21 . 2009-10-15 20:21 -------- d-----w- c:\users\Mariska Sykes\AppData\Local\The Weather Channel 2009-10-15 16:10 . 2009-10-15 16:10 680 ----a-w- c:\users\Mariska Sykes\AppData\Local\d3d9caps.dat 2009-10-14 09:06 . 2009-09-10 16:48 218624 ----a-w- c:\windows\system32\msv1_0.dll 2009-10-14 09:06 . 2009-08-04 12:34 3600456 ----a-w- c:\windows\system32\ntkrnlpa.exe 2009-10-14 09:06 . 2009-08-04 12:34 3548216 ----a-w- c:\windows\system32\ntoskrnl.exe 2009-10-14 09:04 . 2009-09-04 12:24 61440 ----a-w- c:\windows\system32\msasn1.dll 2009-10-14 09:04 . 2009-09-14 09:29 144896 ----a-w- c:\windows\system32\drivers\srv2.sys 2009-10-14 09:04 . 2009-04-02 12:37 604672 ----a-w- c:\windows\system32\WMSPDMOD.DLL 2009-10-10 22:28 . 2009-10-10 22:28 -------- d-----w- c:\users\Emma B. Sykes\AppData\Roaming\magicJackOutlookAddIn 2009-10-10 20:48 . 2009-10-10 20:48 -------- d-----w- c:\users\Emma B. Sykes\AppData\Roaming\PeerNetworking 2009-10-10 20:47 . 2009-10-10 20:47 -------- d-----w- c:\users\Emma B. Sykes\AppData\Local\The Weather Channel 2009-10-10 20:39 . 2009-10-10 20:39 -------- d-----w- c:\users\Emma B. Sykes\AppData\Roaming\Motive 2009-10-10 20:30 . 2009-10-10 20:30 -------- d-----w- c:\users\Emma B. Sykes\AppData\Local\tjnet 2009-10-10 19:38 . 2009-10-25 14:17 -------- d-----w- c:\users\Emma B. Sykes\AppData\Roaming\mjusbsp 2009-10-10 15:04 . 2009-10-10 15:04 -------- d-----w- c:\program files\MSN Toolbar Installer 2009-10-09 23:50 . 2009-10-09 23:50 -------- d-----w- c:\users\Jessie J. Sykes\AppData\Roaming\WildTangent 2009-10-09 23:46 . 2009-10-09 23:46 -------- d-----w- c:\users\Jessie J. Sykes\Office Genuine Advantage 2009-10-07 19:33 . 2009-10-07 19:33 -------- d-----w- c:\users\Jessie J. Sykes\AppData\Local\MigWiz 2009-10-07 17:16 . 2009-10-07 19:33 680 ----a-w- c:\users\Jessie J. Sykes\AppData\Local\d3d9caps.dat 2009-10-06 21:21 . 2009-10-06 21:21 -------- d-----w- c:\users\Jessie J. Sykes\AppData\Roaming\CyberLink 2009-10-06 16:01 . 2009-10-06 16:01 -------- d-----w- c:\users\Jessie J. Sykes\AppData\Local\The Weather Channel 2009-10-04 17:31 . 2009-10-04 17:31 -------- d-----w- c:\users\Mariska Sykes\AppData\Roaming\PlayFirst 2009-10-03 21:08 . 2009-10-03 21:08 -------- d-----w- c:\users\Emma B. Sykes\AppData\Roaming\yahoo! 2009-10-03 21:08 . 2009-10-03 21:08 -------- d-----w- c:\users\Emma B. Sykes\AppData\Roaming\iolo 2009-10-03 21:08 . 2009-10-03 21:08 -------- d-----w- c:\users\Emma B. Sykes\AppData\Local\SupportSoft 2009-10-03 21:08 . 2009-10-20 08:17 -------- d-----w- c:\users\Emma B. Sykes\AppData\Local\Google 2009-10-03 21:07 . 2009-10-03 21:07 -------- d-----w- c:\users\Emma B. Sykes\AppData\Local\PowerDVD DX 2009-10-03 21:07 . 2009-10-12 18:34 54600 ----a-w- c:\users\Emma B. Sykes\AppData\Local\GDIPFONTCACHEV1.DAT 2009-10-03 18:51 . 2009-10-03 18:51 -------- d-----w- c:\users\Mariska Sykes\AppData\Roaming\DivX 2009-10-03 18:25 . 2009-10-03 18:49 -------- d-----w- c:\program files\DivX 2009-10-03 18:25 . 2009-10-03 18:49 -------- d-----w- c:\program files\Common Files\DivX Shared . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2009-11-02 05:24 . 2009-09-02 21:43 -------- d-----w- c:\program files\Microsoft 2009-11-01 04:34 . 2009-11-01 04:34 0 ---ha-w- c:\windows\system32\drivers\Msft_User_WpdFs_01_07_00.Wdf 2009-10-31 16:11 . 2006-11-02 12:35 -------- d-----w- c:\program files\Windows Calendar 2009-10-31 16:11 . 2006-11-02 11:18 -------- d-----w- c:\program files\Windows Mail 2009-10-31 16:11 . 2006-11-02 12:35 -------- d-----w- c:\program files\Windows Sidebar 2009-10-31 16:11 . 2006-11-02 12:35 -------- d-----w- c:\program files\Windows Collaboration 2009-10-31 16:11 . 2006-11-02 12:35 -------- d-----w- c:\program files\Windows Photo Gallery 2009-10-31 16:11 . 2006-11-02 12:35 -------- d-----w- c:\program files\Windows Defender 2009-10-30 02:30 . 2008-09-12 20:12 -------- d-----w- c:\program files\Rushmore Casino 2009-10-30 00:36 . 2009-09-08 20:50 -------- d-----w- c:\program files\Sukoku 2009-10-29 18:15 . 2009-10-02 00:31 180200 --sha-w- c:\windows\system32\drivers\fidbox.idx 2009-10-29 18:15 . 2009-10-02 00:31 13296672 --sha-w- c:\windows\system32\drivers\fidbox.dat 2009-10-29 18:05 . 2008-08-09 01:41 -------- d-----w- c:\programdata\Symantec 2009-10-29 18:05 . 2008-08-09 01:40 -------- d-----w- c:\program files\Common Files\Symantec Shared 2009-10-29 18:03 . 2009-09-02 21:34 -------- d-----w- c:\program files\AOL Games 2009-10-29 18:03 . 2008-07-22 23:44 -------- d--h--w- c:\program files\InstallShield Installation Information 2009-10-29 17:41 . 2008-07-26 14:04 -------- d-----w- c:\program files\PlayFirst 2009-10-29 17:40 . 2009-10-02 00:11 -------- d-----w- c:\program files\Common Files\ParetoLogic 2009-10-29 17:40 . 2009-10-02 00:11 -------- d-----w- c:\programdata\ParetoLogic 2009-10-24 02:43 . 2009-10-03 03:18 54600 ----a-w- c:\users\Jessie J. Sykes\AppData\Local\GDIPFONTCACHEV1.DAT 2009-10-15 08:06 . 2009-09-26 20:24 -------- d-----w- c:\program files\TS 2009-10-12 04:13 . 2009-06-25 05:10 54600 ----a-w- c:\users\Mariska Sykes\AppData\Local\GDIPFONTCACHEV1.DAT 2009-10-06 00:03 . 2009-09-06 00:48 -------- d-----w- c:\users\Mariska Sykes\AppData\Roaming\W Photo Studio 2009-10-03 20:03 . 2009-10-03 03:00 -------- d-----w- c:\program files\Microsoft Silverlight 2009-10-03 03:18 . 2009-10-03 03:18 -------- d-----w- c:\users\Jessie J. Sykes\AppData\Roaming\iolo 2009-10-03 03:18 . 2009-10-03 03:18 -------- d-----w- c:\users\Jessie J. Sykes\AppData\Roaming\yahoo! 2009-10-02 00:11 . 2009-10-02 00:11 -------- d-----w- c:\programdata\ParetoLogic Anti-Virus PLUS 2009-10-01 00:12 . 2009-09-30 22:20 -------- d-----w- c:\programdata\iolo 2009-09-30 22:49 . 2008-07-28 22:02 -------- d-----w- c:\program files\Yahoo! 2009-09-30 22:47 . 2008-08-09 01:40 -------- d-----w- c:\programdata\Yahoo! 2009-09-30 22:47 . 2008-08-09 01:41 -------- d-----w- c:\program files\Symantec 2009-09-30 22:33 . 2009-09-30 22:20 -------- d-----w- c:\users\Mariska Sykes\AppData\Roaming\iolo 2009-09-30 22:20 . 2009-09-30 22:20 74703 ----a-w- c:\windows\system32\mfc45.dll 2009-09-27 08:00 . 2009-09-27 08:00 -------- d-----w- c:\program files\MSXML 4.0 2009-09-27 06:24 . 2009-05-25 22:02 -------- d-----w- c:\program files\AcidCrew Software 2009-09-26 21:26 . 2009-09-26 21:26 -------- d-----w- c:\programdata\Fenomen Games 2009-09-26 20:40 . 2009-09-26 20:40 -------- d-----w- c:\programdata\Sunbelt Software 2009-09-26 20:40 . 2009-09-26 20:40 -------- d-----w- c:\programdata\Ascentive 2009-09-25 02:10 . 2009-11-01 04:21 974848 ----a-w- c:\windows\system32\WindowsCodecs.dll 2009-09-25 02:07 . 2009-11-01 04:21 189440 ----a-w- c:\windows\system32\WindowsCodecsExt.dll 2009-09-25 02:04 . 2009-11-01 04:21 321024 ----a-w- c:\windows\system32\PhotoMetadataHandler.dll 2009-09-25 01:49 . 2009-11-01 04:21 1554432 ----a-w- c:\windows\system32\xpsservices.dll 2009-09-25 01:48 . 2009-11-01 04:21 351232 ----a-w- c:\windows\system32\XpsPrint.dll 2009-09-25 01:38 . 2009-11-01 04:21 847360 ----a-w- c:\windows\system32\OpcServices.dll 2009-09-25 01:36 . 2009-11-01 04:21 280064 ----a-w- c:\windows\system32\XpsGdiConverter.dll 2009-09-25 01:35 . 2009-11-01 04:21 135680 ----a-w- c:\windows\system32\XpsRasterService.dll 2009-09-25 01:33 . 2009-11-01 04:21 195584 ----a-w- c:\windows\system32\dxdiagn.dll 2009-09-25 01:33 . 2009-11-01 04:21 829440 ----a-w- c:\windows\system32\d3d10warp.dll 2009-09-25 01:33 . 2009-11-01 04:21 369664 ----a-w- c:\windows\system32\WMPhoto.dll 2009-09-25 01:32 . 2009-11-01 04:21 252928 ----a-w- c:\windows\system32\dxdiag.exe 2009-09-25 01:31 . 2009-11-01 04:21 519680 ----a-w- c:\windows\system32\d3d11.dll 2009-09-25 01:31 . 2009-11-01 04:21 486912 ----a-w- c:\windows\system32\d3d10level9.dll 2009-09-25 01:31 . 2009-11-01 04:21 161280 ----a-w- c:\windows\system32\d3d10_1.dll 2009-09-25 01:31 . 2009-11-01 04:21 218112 ----a-w- c:\windows\system32\d3d10_1core.dll 2009-09-25 01:31 . 2009-11-01 04:21 1030144 ----a-w- c:\windows\system32\d3d10.dll 2009-09-25 01:31 . 2009-11-01 04:21 828928 ----a-w- c:\windows\system32\d2d1.dll 2009-09-25 01:30 . 2009-11-01 04:21 481792 ----a-w- c:\windows\system32\dxgi.dll 2009-09-25 01:30 . 2009-11-01 04:21 190464 ----a-w- c:\windows\system32\d3d10core.dll 2009-09-25 01:27 . 2009-11-01 04:21 634880 ----a-w- c:\windows\system32\drivers\dxgkrnl.sys 2009-09-25 01:27 . 2009-11-01 04:21 37888 ----a-w- c:\windows\system32\cdd.dll 2009-09-25 01:27 . 2009-11-01 04:21 793088 ----a-w- c:\windows\system32\FntCache.dll 2009-09-25 01:27 . 2009-11-01 04:21 1064448 ----a-w- c:\windows\system32\DWrite.dll 2009-09-24 22:54 . 2009-11-01 04:21 258048 ----a-w- c:\windows\system32\winspool.drv 2009-09-24 22:54 . 2009-11-01 04:21 667648 ----a-w- c:\windows\system32\printfilterpipelinesvc.exe 2009-09-24 22:54 . 2009-11-01 04:21 26112 ----a-w- c:\windows\system32\printfilterpipelineprxy.dll 2009-09-10 02:01 . 2009-11-01 04:21 3023360 ----a-w- c:\windows\system32\UIRibbon.dll 2009-09-10 02:00 . 2009-11-01 04:21 1164800 ----a-w- c:\windows\system32\UIRibbonRes.dll 2009-09-10 02:00 . 2009-11-01 04:21 92672 ----a-w- c:\windows\system32\UIAnimation.dll 2009-09-06 00:49 . 2009-09-06 00:49 -------- d-----w- c:\users\Mariska Sykes\AppData\Roaming\Walgreens 2009-09-04 20:54 . 2009-09-04 20:54 -------- d-----w- c:\programdata\Trymedia 2009-09-04 11:38 . 2009-09-04 11:38 -------- d-----w- c:\programdata\Office Genuine Advantage 2009-09-02 21:39 . 2009-09-02 21:39 411368 ----a-w- c:\windows\system32\deploytk.dll 2009-08-29 00:27 . 2009-09-02 03:03 4240384 ----a-w- c:\windows\system32\GameUXLegacyGDFs.dll 2009-08-29 00:14 . 2009-09-02 03:03 28672 ----a-w- c:\windows\system32\Apphlpdm.dll 2009-08-27 05:22 . 2009-10-14 09:05 916480 ----a-w- c:\windows\system32\wininet.dll 2009-08-27 05:17 . 2009-10-14 09:05 71680 ----a-w- c:\windows\system32\iesetup.dll 2009-08-27 05:17 . 2009-10-14 09:05 109056 ----a-w- c:\windows\system32\iesysprep.dll 2009-08-27 03:42 . 2009-10-14 09:05 133632 ----a-w- c:\windows\system32\ieUnatt.exe 2009-08-20 20:09 . 2009-08-20 20:09 1193832 ----a-w- c:\windows\system32\FM20.DLL 2009-08-14 16:27 . 2009-09-27 06:35 904776 ----a-w- c:\windows\system32\drivers\tcpip.sys 2009-08-14 15:53 . 2009-09-27 06:35 17920 ----a-w- c:\windows\system32\netevent.dll 2009-08-14 13:49 . 2009-09-27 06:35 9728 ----a-w- c:\windows\system32\TCPSVCS.EXE 2009-08-14 13:49 . 2009-09-27 06:35 17920 ----a-w- c:\windows\system32\ROUTE.EXE 2009-08-14 13:49 . 2009-09-27 06:35 11264 ----a-w- c:\windows\system32\MRINFO.EXE 2009-08-14 13:49 . 2009-09-27 06:35 27136 ----a-w- c:\windows\system32\NETSTAT.EXE 2009-08-14 13:49 . 2009-09-27 06:35 19968 ----a-w- c:\windows\system32\ARP.EXE 2009-08-14 13:49 . 2009-09-27 06:35 8704 ----a-w- c:\windows\system32\HOSTNAME.EXE 2009-08-14 13:49 . 2009-09-27 06:35 10240 ----a-w- c:\windows\system32\finger.exe 2009-08-14 13:48 . 2009-09-27 06:35 30720 ----a-w- c:\windows\system32\drivers\tcpipreg.sys 2009-08-14 13:48 . 2009-09-27 06:35 105984 ----a-w- c:\windows\system32\netiohlp.dll 2008-07-23 02:28 . 2008-07-23 02:27 8192 --sha-w- c:\windows\Users\Default\NTUSER.DAT . ((((((((((((((((((((((((((((( SnapShot@2009-11-02_13.35.53 ))))))))))))))))))))))))))))))))))))))))) . + 2006-11-02 13:02 . 2009-11-02 14:46 71826 c:\windows\System32\WDI\BootPerformanceDiagnostics_SystemData.bin + 2008-07-26 01:32 . 2009-11-02 14:45 32768 c:\windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat - 2008-07-26 01:32 . 2009-11-02 13:13 32768 c:\windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat + 2008-07-26 01:32 . 2009-11-02 14:45 98304 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat - 2008-07-26 01:32 . 2009-11-02 13:13 98304 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat + 2008-07-26 01:32 . 2009-11-02 14:45 32768 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat - 2008-07-26 01:32 . 2009-11-02 13:13 32768 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat + 2009-10-03 21:15 . 2009-11-02 14:46 6046 c:\windows\System32\WDI\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-1696485601-562263704-4103742560-1005_UserData.bin + 2009-11-02 13:08 . 2009-11-02 14:44 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat - 2009-11-02 13:08 . 2009-11-02 13:08 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat - 2009-11-02 13:08 . 2009-11-02 13:08 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat + 2009-11-02 13:08 . 2009-11-02 14:44 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat + 2008-07-26 03:03 . 2009-11-02 14:38 264250 c:\windows\System32\WDI\SuspendPerformanceDiagnostics_SystemData_FastS4.bin + 2006-11-02 10:33 . 2009-11-02 14:51 595446 c:\windows\System32\perfh009.dat - 2006-11-02 10:33 . 2009-11-02 13:15 595446 c:\windows\System32\perfh009.dat + 2006-11-02 10:33 . 2009-11-02 14:51 101144 c:\windows\System32\perfc009.dat - 2006-11-02 10:33 . 2009-11-02 13:15 101144 c:\windows\System32\perfc009.dat . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "cdloader"="c:\users\Emma B. Sykes\AppData\Roaming\mjusbsp\cdloader2.exe" [2009-08-01 50520] "WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2008-01-21 202240] "msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2009-07-26 3883856] "swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-09-03 39408] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "YSearchProtection"="c:\program files\Yahoo!\Search Protection\SearchProtection.exe" [2008-10-07 111856] "SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-09-02 149280] "Persistence"="c:\windows\system32\igfxpers.exe" [2008-02-12 133656] "PDVDDXSrv"="c:\program files\CyberLink\PowerDVD DX\PDVDDXSrv.exe" [2008-02-26 128296] "Microsoft Default Manager"="c:\program files\Microsoft\Search Enhancement Pack\Default Manager\DefMgr.exe" [2009-02-03 233304] "IgfxTray"="c:\windows\system32\igfxtray.exe" [2008-02-12 141848] "HughesNetTools_McciTrayApp"="c:\program files\HughesNetTools\1\McciTrayApp_SSR.exe" [2007-11-20 1454592] "HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2008-02-12 166424] "dscactivate"="c:\program files\Dell Support Center\gs_agent\custom\dsca.exe" [2008-03-11 16384] "DellSupportCenter"="c:\program files\Dell Support Center\bin\sprtcmd.exe" [2009-05-21 206064] "Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-12 39792] "avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2009-03-02 209153] "Malwarebytes Anti-Malware (rootkit-scan)"="c:\program files\Malwarebytes' Anti-Malware\mbam.exe" [2009-09-10 1312080] "RtHDVCpl"="RtHDVCpl.exe" - c:\windows\RtHDVCpl.exe [2007-05-14 4452352] [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "EnableUIADesktopToggle"= 0 (0x0) [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows] "AppInit_DLLs"=c:\progra~1\Google\GOOGLE~2\GoogleDesktopNetwork3.dll [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32] "aux1"=wdmaud.drv [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend] @="Service" [HKEY_LOCAL_MACHINE\software\microsoft\security center] "AntiVirusOverride"="" "FirewallOverride"="" [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring] "DisableMonitoring"=dword:00000001 [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus] "DisableMonitoring"=dword:00000001 [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall] "DisableMonitoring"=dword:00000001 [HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc] "VistaSp2"=hex(b):4a,6c,e0,ca,c4,58,ca,01 [HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc\S-1-5-21-1696485601-562263704-4103742560-1002] "EnableNotificationsRef"=dword:00000001 R1 ElRawDisk;ElRawDisk;c:\windows\System32\drivers\elrawdsk.sys [9/30/2009 4:53 PM 12800] R2 AntiVirSchedulerService;Avira AntiVir Scheduler;c:\program files\Avira\AntiVir Desktop\sched.exe [10/29/2009 12:52 PM 108289] S2 gupdate1ca2c2d7ef35911;Google Update Service (gupdate1ca2c2d7ef35911);c:\program files\Google\Update\GoogleUpdate.exe [9/2/2009 6:28 PM 133104] S2 ioloProductUpdate;iolo Product Update Service;c:\program files\iolo\common\lib\ioloServiceManager.exe --> c:\program files\iolo\common\lib\ioloServiceManager.exe [?] S2 wlidsvc;Windows Live ID Sign-in Assistant;c:\program files\Common Files\microsoft shared\Windows Live\WLIDSVC.EXE [3/30/2009 4:28 PM 1533808] S3 FontCache;Windows Font Cache Service;c:\windows\system32\svchost.exe -k LocalServiceAndNoImpersonation [1/20/2008 8:33 PM 21504] S3 fssfltr;FssFltr;c:\windows\System32\drivers\fssfltr.sys [11/2/2009 2:06 AM 54632] S3 fsssvc;Windows Live Family Safety Service;c:\program files\Windows Live\Family Safety\fsssvc.exe [8/5/2009 10:48 PM 704864] --- Other Services/Drivers In Memory --- *Deregistered* - mbr *Deregistered* - PROCEXP113 [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost] LocalServiceNoNetwork REG_MULTI_SZ PLA DPS BFE mpssvc LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache . Contents of the 'Scheduled Tasks' folder 2009-11-02 c:\windows\Tasks\Google Software Updater.job - c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2009-09-03 00:26] 2009-11-02 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job - c:\program files\Google\Update\GoogleUpdate.exe [2009-09-03 00:28] 2009-11-02 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job - c:\program files\Google\Update\GoogleUpdate.exe [2009-09-03 00:28] 2009-11-02 c:\windows\Tasks\User_Feed_Synchronization-{5AAC805B-6979-433A-BA29-982C8F3E14C3}.job - c:\windows\system32\msfeedssync.exe [2009-10-14 03:41] 2009-11-02 c:\windows\Tasks\User_Feed_Synchronization-{EA5721F5-911A-40BB-849B-2B7900281668}.job - c:\windows\system32\msfeedssync.exe [2009-10-14 03:41] . . ------- Supplementary Scan ------- . uStart Page = hxxp://www.yahoo.com/ IE: Crawler Search - tbr:iemenu IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office10\EXCEL.EXE/3000 DPF: {BFF1950D-B1B4-4AE8-B842-B2CCF06D9A1B} - hxxp://www.gamehouse.com/realarcade-webgames/zylom/zylomplayer.cab DPF: {CAEAFE12-7726-4C39-B620-2601216CFBB5} - hxxp://phughescw.hughes.motive.com/wizlet/spaceway/static/controls/Mcci_6-1-0.cab DPF: {D410AFBD-4E26-4D5F-840F-0412D6F6BB8D} - hxxp://games.bigfishgames.com/en_sandscript/online/SandScript.1.0.0.21.cab . ************************************************************************** catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2009-11-02 09:03 Windows 6.0.6002 Service Pack 2 NTFS scanning hidden processes ... scanning hidden autostart entries ... scanning hidden files ... scan completed successfully hidden files: 0 ************************************************************************** . Completion time: 2009-11-02 9:04 ComboFix-quarantined-files.txt 2009-11-02 15:04 ComboFix2.txt 2009-11-02 13:37 Pre-Run: 30,824,349,696 bytes free Post-Run: 30,790,467,584 bytes free - - End Of File - - ECFDB194FA834811EF65C3D8BA301D63 |
|
|
Nov 2 2009, 03:20 PM
Post
#5
|
|
![]() GeekU Teacher Posts: 35,078 From: Dublin OS: XP |
hi
Download TFC to your desktop
Please download Malwarebytes' Anti-Malware from Here Double Click mbam-setup.exe to install the application.
Extra Note: If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process,if asked to restart the computer,please do so immediatly. Go to Kaspersky website and perform an online antivirus scan.
|
|
|
Nov 2 2009, 05:59 PM
Post
#6
|
|
|
New Member ![]() Posts: 5 OS: Windows Vista |
Malwarebytes' Anti-Malware 1.41
Database version: 3089 Windows 6.0.6002 Service Pack 2 11/2/2009 5:57:35 PM mbam-log-2009-11-02 (17-57-35).txt Scan type: Full Scan (C:\|D:\|) Objects scanned: 395651 Time elapsed: 1 hour(s), 37 minute(s), 41 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 0 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 0 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: (No malicious items detected) Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: (No malicious items detected) |
|
|
Nov 2 2009, 10:08 PM
Post
#7
|
|
|
New Member ![]() Posts: 5 OS: Windows Vista |
--------------------------------------------------------------------------------
KASPERSKY ONLINE SCANNER 7.0: scan report Monday, November 2, 2009 Operating system: Microsoft Windows Vista Home Basic Edition, 32-bit Service Pack 2 (build 6002) Kaspersky Online Scanner version: 7.0.26.13 Last database update: Monday, November 02, 2009 22:52:39 Records in database: 3115681 -------------------------------------------------------------------------------- Scan settings: scan using the following database: extended Scan archives: yes Scan e-mail databases: yes Scan area - My Computer: C:\ D:\ E:\ F:\ Scan statistics: Objects scanned: 281633 Threats found: 0 Infected objects found: 0 Suspicious objects found: 0 Scan duration: 03:04:53 No threats found. Scanned area is clean. Selected area has been scanned. Does this mean we got them all? If so, why am I still having problems with windows security updates, even though I have disabled windows defender and anti-virus program? This post has been edited by shayspace: Nov 2 2009, 10:22 PM |
|
|
Nov 3 2009, 09:44 AM
Post
#8
|
|
![]() GeekU Teacher Posts: 35,078 From: Dublin OS: XP |
open OTL click quick scan post that log
for your windows problem do this Please download Dial-A-Fix. Unzip the folder found in the archive to a place you can remember. For example: C:\DialAFix Then follow the steps below.
Note that ticking a box might tick others too. Leave them ticked! |
|
|
Nov 6 2009, 02:15 PM
Post
#9
|
|
![]() GeekU Teacher Posts: 35,078 From: Dublin OS: XP |
Due to lack of feedback, this topic has been closed.
If you need this topic reopened, please contact a staff member. This applies only to the original topic starter. Everyone else please begin a New Topic. |
|
|
![]() ![]() |
Similar Topics
| Topic Title | Replies / Views | Topic Information | |||||
|---|---|---|---|---|---|---|---|
![]() |
2 / 402 | 19th May 2006 - 05:44 AM melissa.cjohns started - last by Armodeluxe |
|||||
![]() |
8 / 339 | 2nd December 2008 - 06:19 PM rr3118 started - last by SpySentinel |
|||||
![]() |
3 / 282 | 14th August 2009 - 11:14 AM gmc01 started - last by Essexboy |
|||||
![]() |
1 / 136 | 17th September 2009 - 05:50 AM exepro started - last by rev_olie |
|||||
|
Time is now: 20th November 2009 - 08:01 PM |
Advertisements do not imply our endorsement of that product or service. The forum is run by volunteers who donate their time and expertise. We make every attempt to ensure that the help and advice posted is accurate and will not cause harm to your computer. However, we do not guarantee that they are accurate and they are to be used at your own risk. All trademarks mentioned on this page are the property of their respective owners.
© Geeks to Go, Inc. | All Rights Reserved | Privacy Policy | Advertising