Jump to content

Welcome to Geeks to Go - Register now for FREE

Geeks To Go is a helpful hub, where thousands of volunteer geeks quickly serve friendly answers and support. Check out the forums and get free advice from the experts. Register now to gain access to all of our features, it's FREE and only takes one minute. Once registered and logged in, you will be able to create topics, post replies to existing threads, give reputation to your fellow members, get your own private messenger, post status updates, manage your profile and so much more.

Create Account How it Works
Photo

The Redirect Virus [Solved]


  • This topic is locked This topic is locked

#76
krystine

krystine

    Member

  • Topic Starter
  • Member
  • PipPip
  • 54 posts
I left the unresponding program open because I was afraid something might get messed up if I closed it during a fix but suddenly it went back to normal the fix was complete. So here's the log I guess haha

[Registry - Safe List]
C:\Users\Krystine\AppData\Roaming\Mozilla\Firefox\Profiles\y53eic8b.default\extensions\{9f94fab0-58a2-11dd-ae16-0800200c9a66}\mozapps\extensions folder moved successfully.
64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ created successfully.
64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ created successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ created successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ created successfully.
Registry key HKEY_USERS\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ not found.
Unable to create registry key HKEY_USERS\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ .
Registry key HKEY_USERS\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ not found.
Unable to create registry key HKEY_USERS\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ .
Registry key HKEY_USERS\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ not found.
Unable to create registry key HKEY_USERS\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ .
Registry key HKEY_USERS\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ not found.
Unable to create registry key HKEY_USERS\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ .
Registry key HKEY_USERS\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ not found.
Unable to create registry key HKEY_USERS\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ .
Registry key HKEY_USERS\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ not found.
Unable to create registry key HKEY_USERS\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ .
[Files/Folders - Created Within 30 Days]
C:\32788R22FWJFW\N_ folder moved successfully.
C:\32788R22FWJFW\License folder moved successfully.
C:\32788R22FWJFW\EN-US folder moved successfully.
C:\32788R22FWJFW folder moved successfully.
[Files/Folders - Modified Within 30 Days]
C:\Windows\tasks\{22116563-108C-42c0-A7CE-60161B75E508}.job moved successfully.
C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-3969533455-2505683156-2406357703-1001UA.job moved successfully.
C:\Windows\SysWow64\drivers\Normandy.sys moved successfully.
C:\Users\Krystine\Desktop\RKUnhookerLE.EXE moved successfully.
[Files - No Company Name]
File C:\Windows\SysWow64\drivers\Normandy.sys not found!
File C:\Users\Krystine\Desktop\RKUnhookerLE.EXE not found!
C:\Users\Krystine\AppData\Roaming\inst.exe moved successfully.
< End of fix log >
OTS by OldTimer - Version 3.1.36.0 fix logfile created on 09072010_184940


edit: I don't think my post showed up before you posted that. By the way, my symptoms did not change after the fix.

Edited by krystine, 07 September 2010 - 05:31 PM.

  • 0

Advertisements


#77
emeraldnzl

emeraldnzl

    GeekU Instructor

  • GeekU Moderator
  • 20,033 posts
Okay let's do that part using Microsofts Mr Fixit. After that run the new script for OTS shown below.

Now

Go to the link below:

http://windows.micro...orer-8-settings

Scroll down to an click on To Reset Internet Explorer Automatically

Click on Mr Fixit and follow the instructions.

Posted Image

Next

Start OTS. Copy/Paste the information in the quotebox below into the pane where it says "Paste fix here" and then click the Run Fix button.

[Registry - Safe List]
< FireFox Extensions [User Folders] > -> 
YY -> No name found   -> C:\Users\Krystine\AppData\Roaming\Mozilla\Firefox\Profiles\y53eic8b.default\extensions\{9f94fab0-58a2-11dd-ae16-0800200c9a66}\mozapps\extensions
[Files/Folders - Modified Within 30 Days]
NY ->  {22116563-108C-42c0-A7CE-60161B75E508}.job -> C:\Windows\tasks\{22116563-108C-42c0-A7CE-60161B75E508}.job
NY ->  GoogleUpdateTaskUserS-1-5-21-3969533455-2505683156-2406357703-1001UA.job -> C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-3969533455-2505683156-2406357703-1001UA.job
NY ->  Normandy.sys -> C:\Windows\SysWow64\drivers\Normandy.sys
NY ->  RKUnhookerLE.EXE -> C:\Users\Krystine\Desktop\RKUnhookerLE.EXE
[Files - No Company Name]
NY ->  inst.exe -> C:\Users\Krystine\AppData\Roaming\inst.exe

The fix should only take a very short time. When the fix is completed a message box will popup telling you that it is finished. Click the Ok button and Notepad will open with a log of actions taken during the fix. Post that information back here for review.
  • 0

#78
emeraldnzl

emeraldnzl

    GeekU Instructor

  • GeekU Moderator
  • 20,033 posts
Oh I see we have cross posted. Ignore my last post. :)
  • 0

#79
krystine

krystine

    Member

  • Topic Starter
  • Member
  • PipPip
  • 54 posts
Not sure if you saw my edit or not because we got all jumbled up but I was just saying that my symptoms did not change after the fix, but I'm unsure as to whether it worked because it was frozen for about 10 minutes
  • 0

#80
emeraldnzl

emeraldnzl

    GeekU Instructor

  • GeekU Moderator
  • 20,033 posts
Hello again krystine,

This time we are going to try another approach with uninstalling an re-installing Firefox. We want to remove your Firefox profile data and settings. Before we do this we want to backup your bookmarks.

To back up your bookmarks:

In Firefox go to History > Show all History > Import and Backup (toolbar along the top) > Export HTML... and save it to your desktop.

Later when you re-install FF you can reverse the process and Import HTML... when the Wizard comes up just import the HTML file you had saved earlier.

Now

Go to the link below for instructions on how to remove Firefox:

http://kb.mozillazin...install_firefox

Look under the heading On Windows

Follow the instructions there On Windows Vista and in particular follow this instruction - see the bolded part:

Starting in Firefox 3, the uninstaller includes the option, "Remove my Firefox personal data and customizations". This will also remove your Firefox user profile data (bookmarks, passwords, cookies, extensions, preferences, etc.).

If the uninstall fails, as it may in some cases, continue on with the rest of the uninstall instructions.

Once you have remove Firefox entirely then download a new copy and re-install. After that, follow the instruction above to import your bookmarks back.

Firefox may be downloaded from Here.
  • 0

#81
krystine

krystine

    Member

  • Topic Starter
  • Member
  • PipPip
  • 54 posts
I think I followed the steps successfully but I still have the bug ):
  • 0

#82
emeraldnzl

emeraldnzl

    GeekU Instructor

  • GeekU Moderator
  • 20,033 posts
Hmm... starting to run low on ideas here. :)

Let's have another look at an OTL scan:

  • Close all windows and open OTL again.
  • Click Run Scan and let the program run uninterrupted
  • It will produce a log for you. Post the log here.

  • 0

#83
krystine

krystine

    Member

  • Topic Starter
  • Member
  • PipPip
  • 54 posts
OTL logfile created on: 9/7/2010 9:48:28 PM - Run 5
OTL by OldTimer - Version 3.2.11.0 Folder = C:\Users\Krystine\Desktop
64bit- Ultimate Edition (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7600.16385)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

6.00 Gb Total Physical Memory | 5.00 Gb Available Physical Memory | 76.00% Memory free
12.00 Gb Paging File | 10.00 Gb Available in Paging File | 87.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 581.52 Gb Total Space | 274.37 Gb Free Space | 47.18% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Drive M: | 1.86 Gb Total Space | 1.86 Gb Free Space | 100.00% Space Free | Partition Type: FAT32

Computer Name: KRYSTINE-PC
Current User Name: Krystine
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Include 64bit Scans
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Standard

========== Processes (SafeList) ==========

PRC - [2010/09/02 00:28:38 | 000,574,976 | ---- | M] (OldTimer Tools) -- C:\Users\Krystine\Desktop\OTL.exe
PRC - [2010/07/21 08:01:34 | 000,921,952 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files (x86)\AVG\AVG9\avgemc.exe
PRC - [2010/07/16 08:30:20 | 002,065,760 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files (x86)\AVG\AVG9\avgtray.exe
PRC - [2010/07/16 08:30:17 | 000,308,136 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files (x86)\AVG\AVG9\avgwdsvc.exe
PRC - [2010/07/16 08:29:53 | 000,723,296 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files (x86)\AVG\AVG9\avgcsrvx.exe
PRC - [2010/06/02 20:50:58 | 001,144,104 | ---- | M] () -- C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe
PRC - [2010/03/19 10:49:20 | 000,144,672 | ---- | M] (Apple Inc.) -- C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
PRC - [2009/10/30 07:57:08 | 000,369,200 | ---- | M] (DT Soft Ltd) -- C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe
PRC - [2009/07/26 17:44:34 | 003,883,856 | ---- | M] (Microsoft Corporation) -- C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe
PRC - [2009/07/13 21:14:42 | 000,010,240 | ---- | M] (Microsoft Corporation) -- C:\Program Files (x86)\Common Files\microsoft shared\ink\TabTip32.exe
PRC - [2009/01/26 16:31:16 | 002,144,088 | RHS- | M] (Safer Networking Limited) -- C:\Program Files (x86)\Spybot - Search & Destroy\TeaTimer.exe


========== Modules (SafeList) ==========

MOD - [2010/09/02 00:28:38 | 000,574,976 | ---- | M] (OldTimer Tools) -- C:\Users\Krystine\Desktop\OTL.exe
MOD - [2009/07/13 21:16:16 | 000,348,160 | ---- | M] (Microsoft Corporation) -- C:\Program Files (x86)\Common Files\microsoft shared\ink\tiptsf.dll
MOD - [2009/07/13 21:14:10 | 000,095,232 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\msscript.ocx
MOD - [2009/07/13 21:03:50 | 001,680,896 | ---- | M] (Microsoft Corporation) -- C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7600.16385_none_421189da2b7fabfc\comctl32.dll


========== Win32 Services (SafeList) ==========

SRV:64bit: - [2009/11/23 16:53:58 | 000,127,784 | ---- | M] (Wacom Technology, Corp.) [Auto | Running] -- C:\Program Files\WTouch\WTouchService.exe -- (WTouchService)
SRV:64bit: - [2009/11/23 16:53:54 | 005,556,520 | ---- | M] (Wacom Technology, Corp.) [Auto | Running] -- C:\Windows\SysNative\Pen_Tablet.exe -- (TabletServicePen)
SRV:64bit: - [2009/08/18 03:36:20 | 000,203,264 | ---- | M] (AMD) [Auto | Running] -- C:\Windows\SysNative\atiesrxx.exe -- (AMD External Events Utility)
SRV:64bit: - [2009/07/13 21:41:56 | 000,195,072 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\umrdp.dll -- (UmRdpService)
SRV:64bit: - [2009/07/13 21:41:53 | 001,361,920 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\PeerDistSvc.dll -- (PeerDistSvc)
SRV:64bit: - [2009/07/13 21:41:27 | 001,011,712 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend)
SRV:64bit: - [2009/07/13 21:40:24 | 000,689,152 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\cscsvc.dll -- (CscService)
SRV:64bit: - [2009/07/13 21:40:01 | 000,193,536 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\appmgmts.dll -- (AppMgmt)
SRV - [2010/07/21 08:01:34 | 000,921,952 | ---- | M] (AVG Technologies CZ, s.r.o.) [Auto | Running] -- C:\Program Files (x86)\AVG\AVG9\avgemc.exe -- (avg9emc)
SRV - [2010/07/16 08:30:17 | 000,308,136 | ---- | M] (AVG Technologies CZ, s.r.o.) [Auto | Running] -- C:\Program Files (x86)\AVG\AVG9\avgwdsvc.exe -- (avg9wd)
SRV - [2010/03/19 10:49:20 | 000,144,672 | ---- | M] (Apple Inc.) [Auto | Running] -- C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe -- (Apple Mobile Device)
SRV - [2010/01/21 17:51:12 | 030,963,576 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files (x86)\Microsoft Office\Office14\GROOVE.EXE -- (Microsoft SharePoint Workspace Audit Service)


========== Driver Services (SafeList) ==========

DRV:64bit: - [2010/07/16 08:30:19 | 000,317,520 | ---- | M] (AVG Technologies CZ, s.r.o.) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\avgtdia.sys -- (AvgTdiA)
DRV:64bit: - [2010/07/16 08:29:54 | 000,269,904 | ---- | M] (AVG Technologies CZ, s.r.o.) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\avgldx64.sys -- (AvgLdx64)
DRV:64bit: - [2010/06/03 08:22:09 | 000,035,536 | ---- | M] (AVG Technologies CZ, s.r.o.) [File_System | System | Running] -- C:\Windows\SysNative\drivers\avgmfx64.sys -- (AvgMfx64)
DRV:64bit: - [2009/12/04 19:11:36 | 000,834,544 | ---- | M] () [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\sptd.sys -- (sptd)
DRV:64bit: - [2009/10/16 02:33:06 | 000,050,176 | ---- | M] (Apple, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\usbaapl64.sys -- (USBAAPL64)
DRV:64bit: - [2009/08/27 16:06:34 | 000,018,216 | ---- | M] (Wacom Technology) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\wacmoumonitor.sys -- (wacmoumonitor)
DRV:64bit: - [2009/08/18 04:48:48 | 006,037,504 | ---- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\atikmdag.sys -- (atikmdag)
DRV:64bit: - [2009/07/13 21:52:21 | 000,106,576 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsata.sys -- (amdsata)
DRV:64bit: - [2009/07/13 21:52:21 | 000,028,752 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\amdxata.sys -- (amdxata)
DRV:64bit: - [2009/07/13 21:52:20 | 000,194,128 | ---- | M] (AMD Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsbs.sys -- (amdsbs)
DRV:64bit: - [2009/07/13 21:48:04 | 000,065,600 | ---- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\lsi_sas2.sys -- (LSI_SAS2)
DRV:64bit: - [2009/07/13 21:47:48 | 000,077,888 | ---- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\HpSAMD.sys -- (HpSAMD)
DRV:64bit: - [2009/07/13 21:45:55 | 000,200,272 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\vmbus.sys -- (vmbus)
DRV:64bit: - [2009/07/13 21:45:55 | 000,046,672 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\vmstorfl.sys -- (storflt)
DRV:64bit: - [2009/07/13 21:45:55 | 000,034,896 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\storvsc.sys -- (storvsc)
DRV:64bit: - [2009/07/13 21:45:55 | 000,024,656 | ---- | M] (Promise Technology) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\stexstor.sys -- (stexstor)
DRV:64bit: - [2009/07/13 20:10:47 | 000,011,264 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\rootmdm.sys -- (ROOTMODEM)
DRV:64bit: - [2009/07/13 19:42:58 | 000,006,656 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\vms3cap.sys -- (s3cap)
DRV:64bit: - [2009/07/13 19:42:44 | 000,021,760 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\VMBusHID.sys -- (VMBusHID)
DRV:64bit: - [2009/07/13 19:24:27 | 000,514,048 | ---- | M] (Microsoft Corporation) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\csc.sys -- (CSC)
DRV:64bit: - [2009/06/19 13:47:52 | 000,382,464 | ---- | M] (Ralink Technology Corp.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\netr7064.sys -- (rt70x64)
DRV:64bit: - [2009/06/10 16:38:56 | 000,000,308 | ---- | M] () [File_System | On_Demand | Running] -- C:\Windows\SysNative\wbem\ntfs.mof -- (Ntfs)
DRV:64bit: - [2009/06/10 16:35:02 | 000,281,088 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\e1y60x64.sys -- (e1yexpress) Intel®
DRV:64bit: - [2009/06/10 16:34:33 | 003,286,016 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\evbda.sys -- (ebdrv)
DRV:64bit: - [2009/06/10 16:34:28 | 000,468,480 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\bxvbda.sys -- (b06bdrv)
DRV:64bit: - [2009/06/10 16:34:23 | 000,270,848 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\b57nd60a.sys -- (b57nd60a)
DRV:64bit: - [2009/06/10 16:31:59 | 000,031,232 | ---- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\hcw85cir.sys -- (hcw85cir)
DRV:64bit: - [2009/05/20 12:54:06 | 000,015,656 | ---- | M] (Wacom Technology) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\wacomvhid.sys -- (wacomvhid)
DRV:64bit: - [2009/05/18 15:17:08 | 000,034,152 | ---- | M] (GEAR Software Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\GEARAspiWDM.sys -- (GEARAspiWDM)
DRV:64bit: - [2009/01/09 16:02:08 | 000,031,744 | ---- | M] (Research in Motion Ltd) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\RimSerial_AMD64.sys -- (RimVSerPort)
DRV:64bit: - [2007/05/14 16:06:18 | 000,027,520 | ---- | M] (Research In Motion Limited) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\RimUsb_AMD64.sys -- (RimUsb)
DRV:64bit: - [2007/02/16 11:12:36 | 000,012,848 | ---- | M] (Wacom Technology) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\wacommousefilter.sys -- (wacommousefilter)
DRV - [2007/02/07 14:27:46 | 000,014,104 | ---- | M] (Windows ® Server 2003 DDK provider) [Kernel | Boot | Running] -- C:\Windows\SysWOW64\speedfan.sys -- (speedfan)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://ca.msn.com/iat/us_ca.aspx
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-us
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = BA FA 5E 9C 22 4E CB 01 [binary data]
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local

========== FireFox ==========


FF - HKLM\software\mozilla\Mozilla Firefox 3.6.9\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2010/09/07 20:19:18 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.9\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2010/09/07 20:19:12 | 000,000,000 | ---D | M]

[2010/09/07 20:26:08 | 000,000,000 | ---D | M] -- C:\Users\Krystine\AppData\Roaming\Mozilla\Extensions
[2010/09/07 20:26:08 | 000,000,000 | ---D | M] -- C:\Users\Krystine\AppData\Roaming\Mozilla\Firefox\Profiles\bqgu3cw6.default\extensions
[2010/09/07 20:19:12 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Mozilla Firefox\extensions

O1 HOSTS File: ([2010/09/07 20:37:17 | 000,000,045 | ---- | M]) - C:\Windows\SysNative\drivers\etc\Hosts
O1 - Hosts: റㄊ㜲〮〮ㄮ瘠污摩瑡潩⹮汳⹳業牣獯景⹴潣൭
O2:64bit: - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files (x86)\AVG\AVG9\avgssiea.dll (AVG Technologies CZ, s.r.o.)
O2:64bit: - BHO: (Groove GFS Browser Helper) - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
O2:64bit: - BHO: (Office Document Cache Handler) - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files (x86)\AVG\AVG9\avgssie.dll (AVG Technologies CZ, s.r.o.)
O2 - BHO: (Spybot-S&D IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files (x86)\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O2 - BHO: (Groove GFS Browser Helper) - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files (x86)\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
O2 - BHO: (Skype add-on for Internet Explorer) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O4 - HKLM..\Run: [AVG9_TRAY] C:\Program Files (x86)\AVG\AVG9\avgtray.exe (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [BCSSync] C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe (Microsoft Corporation)
O4 - HKLM..\Run: [DivXUpdate] C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe ()
O4 - HKLM..\Run: [StartCCC] C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.)
O4 - HKCU..\Run: [DAEMON Tools Lite] C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe (DT Soft Ltd)
O4 - HKCU..\Run: [ISUSPM] C:\Program Files (x86)\Common Files\InstallShield\UpdateService\ISUSPM.exe File not found
O4 - HKCU..\Run: [msnmsgr] C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe (Microsoft Corporation)
O4 - HKCU..\Run: [SpybotSD TeaTimer] C:\Program Files (x86)\Spybot - Search & Destroy\TeaTimer.exe (Safer Networking Limited)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 0
O8:64bit: - Extra context menu item: Se&nd to OneNote - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
O8 - Extra context menu item: Se&nd to OneNote - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Se&nd to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll (Microsoft Corporation)
O9 - Extra Button: Skype add-on for Internet Explorer - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Skype add-on for Internet Explorer - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files (x86)\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O13 - gopher Prefix: missing
O13 - gopher Prefix: missing
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_17)
O16 - DPF: {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_17)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_17)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.ad...Plus/1.6/gp.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.0.1
O18:64bit: - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files (x86)\AVG\AVG9\avgppa.dll (AVG Technologies CZ, s.r.o.)
O18:64bit: - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - Reg Error: Key error. File not found
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files (x86)\AVG\AVG9\avgpp.dll (AVG Technologies CZ, s.r.o.)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O18 - Protocol\Filter\text/xml {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\microsoft shared\OFFICE14\MSOXMLMF.DLL (Microsoft Corporation)
O20:64bit: - AppInit_DLLs: (avgrssta.dll) - C:\Windows\SysNative\avgrssta.dll (AVG Technologies CZ, s.r.o.)
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysNative\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysWow64\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found.
O28:64bit: - HKLM ShellExecuteHooks: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
O28 - HKLM ShellExecuteHooks: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\Program Files (x86)\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35:64bit: - HKLM\..comfile [open] -- "%1" %*
O35:64bit: - HKLM\..exefile [open] -- "%1" %*
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37:64bit: - HKLM\...com [@ = comfile] -- "%1" %*
O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*

========== Files/Folders - Created Within 30 Days ==========

[2010/09/07 21:44:23 | 000,000,000 | ---D | C] -- C:\ProgramData\Hewlett-Packard
[2010/09/07 20:26:03 | 000,000,000 | ---D | C] -- C:\Users\Krystine\AppData\Roaming\Mozilla
[2010/09/07 20:19:11 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Mozilla Firefox
[2010/09/07 18:49:40 | 000,000,000 | ---D | C] -- C:\_OTS
[2010/09/07 11:18:06 | 000,641,024 | ---- | C] (OldTimer Tools) -- C:\Users\Krystine\Desktop\OTS.exe
[2010/09/05 12:29:35 | 000,574,976 | ---- | C] (OldTimer Tools) -- C:\Users\Krystine\Desktop\OTL.exe
[2010/09/01 18:15:46 | 000,000,000 | ---D | C] -- C:\Users\Krystine\AppData\Roaming\SUPERAntiSpyware.com
[2010/09/01 18:15:46 | 000,000,000 | ---D | C] -- C:\ProgramData\SUPERAntiSpyware.com
[2010/09/01 18:15:41 | 000,000,000 | ---D | C] -- C:\ProgramData\!SASCORE
[2010/09/01 18:15:40 | 000,000,000 | ---D | C] -- C:\Program Files\SUPERAntiSpyware
[2010/09/01 18:08:50 | 000,000,000 | ---D | C] -- C:\_OTL
[2010/08/31 17:57:10 | 000,000,000 | ---D | C] -- C:\ProgramData\Kaspersky Lab
[2010/08/30 18:28:44 | 000,000,000 | ---D | C] -- C:\ProgramData\Sun
[2010/08/30 18:28:43 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Java
[2010/08/29 20:41:15 | 000,000,000 | ---D | C] -- C:\Users\Krystine\AppData\Local\Google
[2010/08/29 17:17:44 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\ESET
[2010/08/27 16:47:50 | 000,000,000 | ---D | C] -- C:\ProgramData\2DBoy
[2010/08/27 16:47:36 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\WorldOfGoo
[2010/08/26 16:06:42 | 000,000,000 | ---D | C] -- C:\Windows\ERDNT
[2010/08/26 15:48:48 | 000,000,000 | ---D | C] -- C:\Program Files\HijackThis
[2010/08/26 15:24:45 | 000,000,000 | ---D | C] -- C:\Users\Krystine\AppData\Roaming\Malwarebytes
[2010/08/26 15:24:44 | 000,015,504 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\SysWow64\drivers\mbam.sys
[2010/08/26 15:24:42 | 000,038,496 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\SysWow64\drivers\mbamswissarmy.sys
[2010/08/26 15:24:41 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Malwarebytes' Anti-Malware
[2010/08/26 15:24:41 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes
[2010/08/26 15:10:58 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\CCleaner
[2010/08/25 20:45:45 | 000,000,000 | ---D | C] -- C:\TDSSKiller_Quarantine
[2010/08/23 17:42:22 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Delta
[2010/08/12 20:32:09 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\DESIGNER
[2010/08/12 20:22:49 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Microsoft Synchronization Services
[2010/08/12 20:22:25 | 000,000,000 | ---D | C] -- C:\Windows\PCHEALTH
[2010/08/12 20:22:25 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Microsoft.NET
[2010/08/12 20:22:25 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Microsoft Sync Framework
[2010/08/12 20:22:25 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Microsoft SQL Server Compact Edition
[2010/08/12 20:16:56 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Microsoft Analysis Services
[2010/04/16 17:53:56 | 001,117,491 | ---- | C] (DVD Shrink ) -- C:\Program Files (x86)\dvdshrink32setup.exe
[2009/12/16 16:47:12 | 000,082,816 | ---- | C] (VSO Software) -- C:\Users\Krystine\AppData\Roaming\pcouffin.sys
[2009/12/04 17:24:58 | 003,139,840 | ---- | C] (WindSolutions) -- C:\Program Files\CopyTrans.exe

========== Files - Modified Within 30 Days ==========

[2010/09/07 21:47:53 | 000,717,892 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI
[2010/09/07 21:47:53 | 000,618,026 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat
[2010/09/07 21:47:53 | 000,104,340 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat
[2010/09/07 21:43:37 | 000,000,006 | -H-- | M] () -- C:\Windows\tasks\SA.DAT
[2010/09/07 21:43:34 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2010/09/07 21:43:28 | 536,195,071 | -HS- | M] () -- C:\hiberfil.sys
[2010/09/07 21:04:54 | 007,864,320 | -HS- | M] () -- C:\Users\Krystine\ntuser.dat
[2010/09/07 21:04:52 | 005,786,493 | -H-- | M] () -- C:\Users\Krystine\AppData\Local\IconCache.db
[2010/09/07 20:46:00 | 000,000,868 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-3969533455-2505683156-2406357703-1001Core.job
[2010/09/07 20:42:47 | 000,014,016 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2010/09/07 20:42:47 | 000,014,016 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2010/09/07 20:38:18 | 000,012,526 | ---- | M] () -- C:\Users\Public\Documents\Yeah yeah.docx
[2010/09/07 20:37:17 | 000,000,045 | ---- | M] () -- C:\Windows\SysNative\drivers\etc\Hosts
[2010/09/07 20:19:13 | 000,001,967 | ---- | M] () -- C:\Users\Krystine\Application Data\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox.lnk
[2010/09/07 13:56:52 | 000,017,231 | ---- | M] () -- C:\Users\Public\Documents\Final Schedule for real 2010-11.docx
[2010/09/07 12:23:13 | 064,372,577 | ---- | M] () -- C:\Windows\SysNative\drivers\Avg\incavi.avm
[2010/09/07 11:18:06 | 000,641,024 | ---- | M] (OldTimer Tools) -- C:\Users\Krystine\Desktop\OTS.exe
[2010/09/06 20:20:26 | 000,001,441 | ---- | M] () -- C:\Users\Krystine\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
[2010/09/06 18:03:08 | 000,080,384 | ---- | M] () -- C:\Users\Krystine\Desktop\MBRCheck.exe
[2010/09/05 20:16:46 | 000,524,288 | -HS- | M] () -- C:\Users\Krystine\ntuser.dat{fe1bca48-b6b2-11df-b00f-0025113d5e33}.TMContainer00000000000000000002.regtrans-ms
[2010/09/05 20:16:46 | 000,524,288 | -HS- | M] () -- C:\Users\Krystine\ntuser.dat{fe1bca48-b6b2-11df-b00f-0025113d5e33}.TMContainer00000000000000000001.regtrans-ms
[2010/09/05 20:16:46 | 000,065,536 | -HS- | M] () -- C:\Users\Krystine\ntuser.dat{fe1bca48-b6b2-11df-b00f-0025113d5e33}.TM.blf
[2010/09/02 00:28:38 | 000,574,976 | ---- | M] (OldTimer Tools) -- C:\Users\Krystine\Desktop\OTL.exe
[2010/09/01 21:36:21 | 000,524,288 | -HS- | M] () -- C:\Users\Krystine\ntuser.dat{b09e2749-b625-11df-9521-0025113d5e33}.TMContainer00000000000000000002.regtrans-ms
[2010/09/01 21:36:21 | 000,524,288 | -HS- | M] () -- C:\Users\Krystine\ntuser.dat{b09e2749-b625-11df-9521-0025113d5e33}.TMContainer00000000000000000001.regtrans-ms
[2010/09/01 21:36:21 | 000,065,536 | -HS- | M] () -- C:\Users\Krystine\ntuser.dat{b09e2749-b625-11df-9521-0025113d5e33}.TM.blf
[2010/09/01 18:15:08 | 000,013,409 | ---- | M] () -- C:\Users\Public\Documents\otl fix.docx
[2010/09/01 17:51:45 | 000,078,336 | ---- | M] () -- C:\Users\Krystine\Documents\Final Schedule 2010-11.doc
[2010/08/27 20:49:38 | 000,000,069 | ---- | M] () -- C:\Windows\MONOLITH.INI
[2010/08/27 20:49:33 | 000,000,622 | ---- | M] () -- C:\Windows\win.ini
[2010/08/27 16:47:43 | 000,001,921 | ---- | M] () -- C:\Users\Public\Desktop\World of Goo.lnk
[2010/08/26 16:45:06 | 000,018,655 | ---- | M] () -- C:\Users\Public\Documents\OTL Extras.docx
[2010/08/26 16:44:36 | 000,024,780 | ---- | M] () -- C:\Users\Public\Documents\OTL.docx
[2010/08/26 16:21:36 | 000,013,180 | ---- | M] () -- C:\Users\Public\Documents\first goored.docx
[2010/08/26 16:19:41 | 000,013,631 | ---- | M] () -- C:\Users\Public\Documents\second OTM.docx
[2010/08/26 16:15:20 | 000,013,664 | ---- | M] () -- C:\Users\Public\Documents\first OTM.docx
[2010/08/26 15:24:44 | 000,001,013 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2010/08/23 19:40:44 | 000,000,834 | ---- | M] () -- C:\Users\Krystine\Desktop\PSX emulator.lnk
[2010/08/12 20:57:06 | 000,108,840 | ---- | M] () -- C:\Users\Krystine\AppData\Local\GDIPFONTCACHEV1.DAT
[2010/08/12 20:55:26 | 000,415,616 | ---- | M] () -- C:\Windows\SysNative\FNTCACHE.DAT
[2010/08/11 20:58:19 | 000,032,768 | ---- | M] () -- C:\Users\Krystine\Documents\resume - old.doc
[2010/08/11 20:46:20 | 000,030,208 | ---- | M] () -- C:\Users\Krystine\Documents\cover letter outline.doc

========== Files Created - No Company Name ==========

[2010/09/07 20:38:18 | 000,012,526 | ---- | C] () -- C:\Users\Public\Documents\Yeah yeah.docx
[2010/09/07 20:35:46 | 028,135,936 | ---- | C] () -- C:\w7lxe.exe
[2010/09/07 20:19:13 | 000,001,967 | ---- | C] () -- C:\Users\Krystine\Application Data\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox.lnk
[2010/09/06 20:20:26 | 000,001,441 | ---- | C] () -- C:\Users\Krystine\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
[2010/09/06 18:03:07 | 000,080,384 | ---- | C] () -- C:\Users\Krystine\Desktop\MBRCheck.exe
[2010/09/04 17:04:18 | 000,524,288 | -HS- | C] () -- C:\Users\Krystine\ntuser.dat{fe1bca48-b6b2-11df-b00f-0025113d5e33}.TMContainer00000000000000000002.regtrans-ms
[2010/09/04 17:04:18 | 000,524,288 | -HS- | C] () -- C:\Users\Krystine\ntuser.dat{fe1bca48-b6b2-11df-b00f-0025113d5e33}.TMContainer00000000000000000001.regtrans-ms
[2010/09/04 17:04:18 | 000,065,536 | -HS- | C] () -- C:\Users\Krystine\ntuser.dat{fe1bca48-b6b2-11df-b00f-0025113d5e33}.TM.blf
[2010/09/01 20:39:28 | 000,524,288 | -HS- | C] () -- C:\Users\Krystine\ntuser.dat{b09e2749-b625-11df-9521-0025113d5e33}.TMContainer00000000000000000002.regtrans-ms
[2010/09/01 20:39:28 | 000,524,288 | -HS- | C] () -- C:\Users\Krystine\ntuser.dat{b09e2749-b625-11df-9521-0025113d5e33}.TMContainer00000000000000000001.regtrans-ms
[2010/09/01 20:39:28 | 000,065,536 | -HS- | C] () -- C:\Users\Krystine\ntuser.dat{b09e2749-b625-11df-9521-0025113d5e33}.TM.blf
[2010/09/01 18:15:07 | 000,013,409 | ---- | C] () -- C:\Users\Public\Documents\otl fix.docx
[2010/09/01 17:42:21 | 000,017,231 | ---- | C] () -- C:\Users\Public\Documents\Final Schedule for real 2010-11.docx
[2010/08/29 20:41:16 | 000,000,868 | ---- | C] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-3969533455-2505683156-2406357703-1001Core.job
[2010/08/27 20:47:12 | 000,000,069 | ---- | C] () -- C:\Windows\MONOLITH.INI
[2010/08/27 16:47:43 | 000,001,921 | ---- | C] () -- C:\Users\Public\Desktop\World of Goo.lnk
[2010/08/26 16:45:05 | 000,018,655 | ---- | C] () -- C:\Users\Public\Documents\OTL Extras.docx
[2010/08/26 16:44:35 | 000,024,780 | ---- | C] () -- C:\Users\Public\Documents\OTL.docx
[2010/08/26 16:21:35 | 000,013,180 | ---- | C] () -- C:\Users\Public\Documents\first goored.docx
[2010/08/26 16:19:39 | 000,013,631 | ---- | C] () -- C:\Users\Public\Documents\second OTM.docx
[2010/08/26 16:15:18 | 000,013,664 | ---- | C] () -- C:\Users\Public\Documents\first OTM.docx
[2010/08/26 15:24:44 | 000,001,013 | ---- | C] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2010/08/23 19:40:44 | 000,000,834 | ---- | C] () -- C:\Users\Krystine\Desktop\PSX emulator.lnk
[2010/08/11 20:46:17 | 000,030,208 | ---- | C] () -- C:\Users\Krystine\Documents\cover letter outline.doc
[2009/12/16 16:47:49 | 000,001,041 | ---- | C] () -- C:\Users\Krystine\AppData\Roaming\vso_ts_preview.xml
[2009/12/16 16:47:21 | 000,000,033 | ---- | C] () -- C:\Users\Krystine\AppData\Roaming\pcouffin.log
[2009/12/16 16:47:12 | 000,007,859 | ---- | C] () -- C:\Users\Krystine\AppData\Roaming\pcouffin.cat
[2009/12/16 16:47:12 | 000,001,167 | ---- | C] () -- C:\Users\Krystine\AppData\Roaming\pcouffin.inf
[2009/12/15 20:55:10 | 000,730,638 | ---- | C] () -- C:\Windows\SysWow64\PerfStringBackup.INI
[2009/12/11 01:19:40 | 000,001,169 | ---- | C] () -- C:\Program Files\Serail & Readme.bat
[2009/12/04 17:24:58 | 000,013,425 | ---- | C] () -- C:\Program Files\License Agreement.rtf
[2009/12/04 17:24:58 | 000,000,652 | ---- | C] () -- C:\Program Files\CopyTrans.ris
[2009/12/04 17:24:58 | 000,000,603 | ---- | C] () -- C:\Program Files\INSTALLATION_PROCEDURE.txt
[2009/12/04 15:36:36 | 000,000,017 | ---- | C] () -- C:\Users\Krystine\AppData\Local\resmon.resmoncfg
[2009/07/13 19:42:10 | 000,064,000 | ---- | C] () -- C:\Windows\SysWow64\BWContextHandler.dll
[2009/07/13 17:03:59 | 000,364,544 | ---- | C] () -- C:\Windows\SysWow64\msjetoledb40.dll
< End of report >


I'm starting to think I should just put all my personal files on an external hard drive and reformat :)

Edited by emeraldnzl, 21 February 2012 - 03:26 PM.
privacy

  • 0

#84
emeraldnzl

emeraldnzl

    GeekU Instructor

  • GeekU Moderator
  • 20,033 posts
Hello krystine,

I'm starting to think I should just put all my personal files on an external hard drive and reformat


Must be getting frustrating. Still haven't quite exhausted all avenues though if you are happy to continue. :)

Now

One thought that occurred to me is that sometimes Spybot Search & Destroy can get compromised. Let's try uninstalling it. We can re-install it later.

After that

Please run OTL.exe
  • Under the Custom Scans/Fixes box at the bottom, paste in the following

    :Commands
    [resethosts]
    [Reboot]
  • Then click the Run Fix button at the top
  • Let the program run unhindered, reboot when it is done
  • It will produce a log for you on reboot, please post that log in your next reply.

Finally

  • Double click on the OTL icon to run it. Make sure all other windows are closed to let it run uninterrupted.
  • Under the Custom Scan box paste this in:
    netsvcs
    drivers32
    %SYSTEMDRIVE%\*.*
    %systemroot%\Fonts\*.com
    %systemroot%\Fonts\*.dll
    %systemroot%\Fonts\*.ini
    %systemroot%\Fonts\*.ini2
    %systemroot%\Fonts\*.exe
    %systemroot%\system32\spool\prtprocs\w32x86\*.*
    %systemroot%\REPAIR\*.bak1
    %systemroot%\REPAIR\*.ini
    %systemroot%\system32\*.jpg
    %systemroot%\*.jpg
    %systemroot%\*.png
    %systemroot%\*.scr
    %systemroot%\*._sy
    %APPDATA%\Adobe\Update\*.*
    %ALLUSERSPROFILE%\Favorites\*.*
    %APPDATA%\Microsoft\*.*
    %PROGRAMFILES%\*.*
    %APPDATA%\Update\*.*
    %systemroot%\*. /mp /s
    %systemroot%\System32\config\*.sav
    %PROGRAMFILES%\bak. /s
    %systemroot%\system32\bak. /s
    %ALLUSERSPROFILE%\Start Menu\*.lnk /x
    %systemroot%\system32\config\systemprofile\*.dat /x
    %systemroot%\*.config
    %systemroot%\system32\*.db
    %PROGRAMFILES%\Internet Explorer\*.dat
    %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x
    %USERPROFILE%\Desktop\*.exe
    %PROGRAMFILES%\Common Files\*.*
    %systemroot%\*.src
    %systemroot%\install\*.*
    %systemroot%\system32\DLL\*.*
    %systemroot%\system32\HelpFiles\*.*
    %systemroot%\system32\rundll\*.*
    %systemroot%\winn32\*.*
    %systemroot%\Java\*.*
    %systemroot%\system32\test\*.*
    %systemroot%\system32\Rundll32\*.*
    %systemroot%\AppPatch\Custom\*.*
    %APPDATA%\Roaming\Microsoft\Windows\Recent\*.lnk /x
    %PROGRAMFILES%\Spybot - Search & Destroy\*.*
    %PROGRAMFILES%\Internet Explorer\*.tmp
    %PROGRAMFILES%\Internet Explorer\*.dat
    %USERPROFILE%\My Documents\*.exe
    %USERPROFILE%\*.exe
    %PROGRAMFILES%\Mozilla Firefox\firefox.exe /md5
    %PROGRAMFILES%\Internet Explorer\iexplore.exe /md5
    %systemroot%\ADDINS\*.*
    %systemroot%\assembly\*.bak2
    %systemroot%\Config\*.*
    %systemroot%\REPAIR\*.bak2
    %systemroot%\SECURITY\Database\*.sdb /x
    %systemroot%\SYSTEM\*.bak2
    %systemroot%\Web\*.bak2
    %systemroot%\Driver Cache\*.*
    %PROGRAMFILES%\Mozilla Firefox\0*.exe
    /md5start
    eventlog.dll
    scecli.dll
    netlogon.dll
    cngaudit.dll
    sceclt.dll
    ntelogon.dll
    logevent.dll
    iaStor.sys
    nvstor.sys
    atapi.sys
    IdeChnDr.sys
    viasraid.sys
    AGP440.sys
    vaxscsi.sys
    nvatabus.sys
    viamraid.sys
    nvata.sys
    nvgts.sys
    iastorv.sys
    ViPrt.sys
    eNetHook.dll
    ahcix86.sys
    KR10N.sys
    nvstor32.sys
    ahcix86s.sys
    nvrd32.sys
    symmpi.sys
    adp3132.sys
    mv61xx.sys
    disk.sys
    /md5stop
    
    
  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan won't take long.
When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.
Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and paste them into your reply.

When you come back please post
  • OTL fix log
  • OTL scan log

  • 0

#85
krystine

krystine

    Member

  • Topic Starter
  • Member
  • PipPip
  • 54 posts
The extras log didn't pop up with the other one and it wasn't in the OTL folder. Here are the other two though

FIX:
========== COMMANDS ==========
C:\Windows\System32\drivers\etc\Hosts moved successfully.
HOSTS file reset successfully

OTL by OldTimer - Version 3.2.11.0 log created on 09072010_222132

OTL.txt
OTL logfile created on: 9/7/2010 10:25:15 PM - Run 6
OTL by OldTimer - Version 3.2.11.0 Folder = C:\Users\Krystine\Desktop
64bit- Ultimate Edition (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7600.16385)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

6.00 Gb Total Physical Memory | 5.00 Gb Available Physical Memory | 80.00% Memory free
12.00 Gb Paging File | 11.00 Gb Available in Paging File | 89.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 581.52 Gb Total Space | 274.43 Gb Free Space | 47.19% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Drive M: | 1.86 Gb Total Space | 1.86 Gb Free Space | 100.00% Space Free | Partition Type: FAT32

Computer Name: KRYSTINE-PC
Current User Name: Krystine
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Include 64bit Scans
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Standard

========== Processes (SafeList) ==========

PRC - [2010/09/02 00:28:38 | 000,574,976 | ---- | M] (OldTimer Tools) -- C:\Users\Krystine\Desktop\OTL.exe
PRC - [2010/07/21 08:01:34 | 000,921,952 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files (x86)\AVG\AVG9\avgemc.exe
PRC - [2010/07/16 08:30:20 | 002,065,760 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files (x86)\AVG\AVG9\avgtray.exe
PRC - [2010/07/16 08:30:17 | 000,308,136 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files (x86)\AVG\AVG9\avgwdsvc.exe
PRC - [2010/07/16 08:29:53 | 000,723,296 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files (x86)\AVG\AVG9\avgcsrvx.exe
PRC - [2010/06/02 20:50:58 | 001,144,104 | ---- | M] () -- C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe
PRC - [2010/03/19 10:49:20 | 000,144,672 | ---- | M] (Apple Inc.) -- C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
PRC - [2009/10/30 07:57:08 | 000,369,200 | ---- | M] (DT Soft Ltd) -- C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe
PRC - [2009/07/13 21:14:42 | 000,010,240 | ---- | M] (Microsoft Corporation) -- C:\Program Files (x86)\Common Files\microsoft shared\ink\TabTip32.exe


========== Modules (SafeList) ==========

MOD - [2010/09/02 00:28:38 | 000,574,976 | ---- | M] (OldTimer Tools) -- C:\Users\Krystine\Desktop\OTL.exe
MOD - [2009/07/13 21:16:16 | 000,348,160 | ---- | M] (Microsoft Corporation) -- C:\Program Files (x86)\Common Files\microsoft shared\ink\tiptsf.dll
MOD - [2009/07/13 21:14:10 | 000,095,232 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\msscript.ocx
MOD - [2009/07/13 21:03:50 | 001,680,896 | ---- | M] (Microsoft Corporation) -- C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7600.16385_none_421189da2b7fabfc\comctl32.dll


========== Win32 Services (SafeList) ==========

SRV:64bit: - [2009/11/23 16:53:58 | 000,127,784 | ---- | M] (Wacom Technology, Corp.) [Auto | Running] -- C:\Program Files\WTouch\WTouchService.exe -- (WTouchService)
SRV:64bit: - [2009/11/23 16:53:54 | 005,556,520 | ---- | M] (Wacom Technology, Corp.) [Auto | Running] -- C:\Windows\SysNative\Pen_Tablet.exe -- (TabletServicePen)
SRV:64bit: - [2009/08/18 03:36:20 | 000,203,264 | ---- | M] (AMD) [Auto | Running] -- C:\Windows\SysNative\atiesrxx.exe -- (AMD External Events Utility)
SRV:64bit: - [2009/07/13 21:41:56 | 000,195,072 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\umrdp.dll -- (UmRdpService)
SRV:64bit: - [2009/07/13 21:41:53 | 001,361,920 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\PeerDistSvc.dll -- (PeerDistSvc)
SRV:64bit: - [2009/07/13 21:41:27 | 001,011,712 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend)
SRV:64bit: - [2009/07/13 21:40:24 | 000,689,152 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\cscsvc.dll -- (CscService)
SRV:64bit: - [2009/07/13 21:40:01 | 000,193,536 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\appmgmts.dll -- (AppMgmt)
SRV - [2010/07/21 08:01:34 | 000,921,952 | ---- | M] (AVG Technologies CZ, s.r.o.) [Auto | Running] -- C:\Program Files (x86)\AVG\AVG9\avgemc.exe -- (avg9emc)
SRV - [2010/07/16 08:30:17 | 000,308,136 | ---- | M] (AVG Technologies CZ, s.r.o.) [Auto | Running] -- C:\Program Files (x86)\AVG\AVG9\avgwdsvc.exe -- (avg9wd)
SRV - [2010/03/19 10:49:20 | 000,144,672 | ---- | M] (Apple Inc.) [Auto | Running] -- C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe -- (Apple Mobile Device)
SRV - [2010/01/21 17:51:12 | 030,963,576 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files (x86)\Microsoft Office\Office14\GROOVE.EXE -- (Microsoft SharePoint Workspace Audit Service)


========== Driver Services (SafeList) ==========

DRV:64bit: - [2010/07/16 08:30:19 | 000,317,520 | ---- | M] (AVG Technologies CZ, s.r.o.) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\avgtdia.sys -- (AvgTdiA)
DRV:64bit: - [2010/07/16 08:29:54 | 000,269,904 | ---- | M] (AVG Technologies CZ, s.r.o.) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\avgldx64.sys -- (AvgLdx64)
DRV:64bit: - [2010/06/03 08:22:09 | 000,035,536 | ---- | M] (AVG Technologies CZ, s.r.o.) [File_System | System | Running] -- C:\Windows\SysNative\drivers\avgmfx64.sys -- (AvgMfx64)
DRV:64bit: - [2009/12/04 19:11:36 | 000,834,544 | ---- | M] () [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\sptd.sys -- (sptd)
DRV:64bit: - [2009/10/16 02:33:06 | 000,050,176 | ---- | M] (Apple, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\usbaapl64.sys -- (USBAAPL64)
DRV:64bit: - [2009/08/27 16:06:34 | 000,018,216 | ---- | M] (Wacom Technology) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\wacmoumonitor.sys -- (wacmoumonitor)
DRV:64bit: - [2009/08/18 04:48:48 | 006,037,504 | ---- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\atikmdag.sys -- (atikmdag)
DRV:64bit: - [2009/07/13 21:52:21 | 000,106,576 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsata.sys -- (amdsata)
DRV:64bit: - [2009/07/13 21:52:21 | 000,028,752 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\amdxata.sys -- (amdxata)
DRV:64bit: - [2009/07/13 21:52:20 | 000,194,128 | ---- | M] (AMD Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsbs.sys -- (amdsbs)
DRV:64bit: - [2009/07/13 21:48:04 | 000,065,600 | ---- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\lsi_sas2.sys -- (LSI_SAS2)
DRV:64bit: - [2009/07/13 21:47:48 | 000,077,888 | ---- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\HpSAMD.sys -- (HpSAMD)
DRV:64bit: - [2009/07/13 21:45:55 | 000,200,272 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\vmbus.sys -- (vmbus)
DRV:64bit: - [2009/07/13 21:45:55 | 000,046,672 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\vmstorfl.sys -- (storflt)
DRV:64bit: - [2009/07/13 21:45:55 | 000,034,896 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\storvsc.sys -- (storvsc)
DRV:64bit: - [2009/07/13 21:45:55 | 000,024,656 | ---- | M] (Promise Technology) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\stexstor.sys -- (stexstor)
DRV:64bit: - [2009/07/13 20:10:47 | 000,011,264 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\rootmdm.sys -- (ROOTMODEM)
DRV:64bit: - [2009/07/13 19:42:58 | 000,006,656 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\vms3cap.sys -- (s3cap)
DRV:64bit: - [2009/07/13 19:42:44 | 000,021,760 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\VMBusHID.sys -- (VMBusHID)
DRV:64bit: - [2009/07/13 19:24:27 | 000,514,048 | ---- | M] (Microsoft Corporation) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\csc.sys -- (CSC)
DRV:64bit: - [2009/06/19 13:47:52 | 000,382,464 | ---- | M] (Ralink Technology Corp.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\netr7064.sys -- (rt70x64)
DRV:64bit: - [2009/06/10 16:38:56 | 000,000,308 | ---- | M] () [File_System | On_Demand | Running] -- C:\Windows\SysNative\wbem\ntfs.mof -- (Ntfs)
DRV:64bit: - [2009/06/10 16:35:02 | 000,281,088 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\e1y60x64.sys -- (e1yexpress) Intel®
DRV:64bit: - [2009/06/10 16:34:33 | 003,286,016 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\evbda.sys -- (ebdrv)
DRV:64bit: - [2009/06/10 16:34:28 | 000,468,480 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\bxvbda.sys -- (b06bdrv)
DRV:64bit: - [2009/06/10 16:34:23 | 000,270,848 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\b57nd60a.sys -- (b57nd60a)
DRV:64bit: - [2009/06/10 16:31:59 | 000,031,232 | ---- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\hcw85cir.sys -- (hcw85cir)
DRV:64bit: - [2009/05/20 12:54:06 | 000,015,656 | ---- | M] (Wacom Technology) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\wacomvhid.sys -- (wacomvhid)
DRV:64bit: - [2009/05/18 15:17:08 | 000,034,152 | ---- | M] (GEAR Software Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\GEARAspiWDM.sys -- (GEARAspiWDM)
DRV:64bit: - [2009/01/09 16:02:08 | 000,031,744 | ---- | M] (Research in Motion Ltd) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\RimSerial_AMD64.sys -- (RimVSerPort)
DRV:64bit: - [2007/05/14 16:06:18 | 000,027,520 | ---- | M] (Research In Motion Limited) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\RimUsb_AMD64.sys -- (RimUsb)
DRV:64bit: - [2007/02/16 11:12:36 | 000,012,848 | ---- | M] (Wacom Technology) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\wacommousefilter.sys -- (wacommousefilter)
DRV - [2007/02/07 14:27:46 | 000,014,104 | ---- | M] (Windows ® Server 2003 DDK provider) [Kernel | Boot | Running] -- C:\Windows\SysWOW64\speedfan.sys -- (speedfan)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://ca.msn.com/iat/us_ca.aspx
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-us
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = BA FA 5E 9C 22 4E CB 01 [binary data]
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local

========== FireFox ==========


FF - HKLM\software\mozilla\Mozilla Firefox 3.6.9\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2010/09/07 20:19:18 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.9\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2010/09/07 20:19:12 | 000,000,000 | ---D | M]

[2010/09/07 20:26:08 | 000,000,000 | ---D | M] -- C:\Users\Krystine\AppData\Roaming\Mozilla\Extensions
[2010/09/07 20:26:08 | 000,000,000 | ---D | M] -- C:\Users\Krystine\AppData\Roaming\Mozilla\Firefox\Profiles\bqgu3cw6.default\extensions
[2010/09/07 20:19:12 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Mozilla Firefox\extensions

O1 HOSTS File: ([2010/09/07 22:21:32 | 000,000,098 | ---- | M]) - C:\Windows\SysNative\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2:64bit: - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files (x86)\AVG\AVG9\avgssiea.dll (AVG Technologies CZ, s.r.o.)
O2:64bit: - BHO: (Groove GFS Browser Helper) - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
O2:64bit: - BHO: (Office Document Cache Handler) - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files (x86)\AVG\AVG9\avgssie.dll (AVG Technologies CZ, s.r.o.)
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O2 - BHO: (Groove GFS Browser Helper) - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files (x86)\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
O2 - BHO: (Skype add-on for Internet Explorer) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O4 - HKLM..\Run: [AVG9_TRAY] C:\Program Files (x86)\AVG\AVG9\avgtray.exe (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [BCSSync] C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe (Microsoft Corporation)
O4 - HKLM..\Run: [DivXUpdate] C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe ()
O4 - HKLM..\Run: [StartCCC] C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.)
O4 - HKCU..\Run: [DAEMON Tools Lite] C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe (DT Soft Ltd)
O4 - HKCU..\Run: [ISUSPM] C:\Program Files (x86)\Common Files\InstallShield\UpdateService\ISUSPM.exe File not found
O4 - HKCU..\Run: [msnmsgr] C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe (Microsoft Corporation)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 0
O8:64bit: - Extra context menu item: Se&nd to OneNote - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
O8 - Extra context menu item: Se&nd to OneNote - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Se&nd to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll (Microsoft Corporation)
O9 - Extra Button: Skype add-on for Internet Explorer - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Skype add-on for Internet Explorer - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O13 - gopher Prefix: missing
O13 - gopher Prefix: missing
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_17)
O16 - DPF: {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_17)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_17)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.ad...Plus/1.6/gp.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.0.1
O18:64bit: - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files (x86)\AVG\AVG9\avgppa.dll (AVG Technologies CZ, s.r.o.)
O18:64bit: - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - Reg Error: Key error. File not found
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files (x86)\AVG\AVG9\avgpp.dll (AVG Technologies CZ, s.r.o.)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O18 - Protocol\Filter\text/xml {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\microsoft shared\OFFICE14\MSOXMLMF.DLL (Microsoft Corporation)
O20:64bit: - AppInit_DLLs: (avgrssta.dll) - C:\Windows\SysNative\avgrssta.dll (AVG Technologies CZ, s.r.o.)
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysNative\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysWow64\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found.
O28:64bit: - HKLM ShellExecuteHooks: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
O28 - HKLM ShellExecuteHooks: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\Program Files (x86)\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35:64bit: - HKLM\..comfile [open] -- "%1" %*
O35:64bit: - HKLM\..exefile [open] -- "%1" %*
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37:64bit: - HKLM\...com [@ = comfile] -- "%1" %*
O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*

NetSvcs:64bit: AppMgmt - C:\Windows\SysNative\appmgmts.dll (Microsoft Corporation)

Drivers32:64bit: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.l3acm - C:\Windows\SysWOW64\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: vidc.cvid - C:\Windows\SysWow64\iccvid.dll (Radius Inc.)
Drivers32: vidc.DIVX - C:\Windows\SysWow64\DivX.dll (DivX, Inc.)
Drivers32: vidc.VP60 - C:\Windows\SysWOW64\vp6vfw.dll (On2.com)
Drivers32: vidc.VP61 - C:\Windows\SysWOW64\vp6vfw.dll (On2.com)
Drivers32: vidc.yv12 - C:\Windows\SysWow64\DivX.dll (DivX, Inc.)

========== Files/Folders - Created Within 30 Days ==========

[2010/09/07 21:44:23 | 000,000,000 | ---D | C] -- C:\ProgramData\Hewlett-Packard
[2010/09/07 20:26:03 | 000,000,000 | ---D | C] -- C:\Users\Krystine\AppData\Roaming\Mozilla
[2010/09/07 20:19:11 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Mozilla Firefox
[2010/09/07 18:49:40 | 000,000,000 | ---D | C] -- C:\_OTS
[2010/09/07 11:18:06 | 000,641,024 | ---- | C] (OldTimer Tools) -- C:\Users\Krystine\Desktop\OTS.exe
[2010/09/05 12:29:35 | 000,574,976 | ---- | C] (OldTimer Tools) -- C:\Users\Krystine\Desktop\OTL.exe
[2010/09/01 18:15:46 | 000,000,000 | ---D | C] -- C:\Users\Krystine\AppData\Roaming\SUPERAntiSpyware.com
[2010/09/01 18:15:46 | 000,000,000 | ---D | C] -- C:\ProgramData\SUPERAntiSpyware.com
[2010/09/01 18:15:41 | 000,000,000 | ---D | C] -- C:\ProgramData\!SASCORE
[2010/09/01 18:15:40 | 000,000,000 | ---D | C] -- C:\Program Files\SUPERAntiSpyware
[2010/09/01 18:08:50 | 000,000,000 | ---D | C] -- C:\_OTL
[2010/08/31 17:57:10 | 000,000,000 | ---D | C] -- C:\ProgramData\Kaspersky Lab
[2010/08/30 18:28:44 | 000,000,000 | ---D | C] -- C:\ProgramData\Sun
[2010/08/30 18:28:43 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Java
[2010/08/29 20:41:15 | 000,000,000 | ---D | C] -- C:\Users\Krystine\AppData\Local\Google
[2010/08/29 17:17:44 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\ESET
[2010/08/27 16:47:50 | 000,000,000 | ---D | C] -- C:\ProgramData\2DBoy
[2010/08/27 16:47:36 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\WorldOfGoo
[2010/08/26 16:06:42 | 000,000,000 | ---D | C] -- C:\Windows\ERDNT
[2010/08/26 15:48:48 | 000,000,000 | ---D | C] -- C:\Program Files\HijackThis
[2010/08/26 15:24:45 | 000,000,000 | ---D | C] -- C:\Users\Krystine\AppData\Roaming\Malwarebytes
[2010/08/26 15:24:44 | 000,015,504 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\SysWow64\drivers\mbam.sys
[2010/08/26 15:24:42 | 000,038,496 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\SysWow64\drivers\mbamswissarmy.sys
[2010/08/26 15:24:41 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Malwarebytes' Anti-Malware
[2010/08/26 15:24:41 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes
[2010/08/26 15:10:58 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\CCleaner
[2010/08/25 20:45:45 | 000,000,000 | ---D | C] -- C:\TDSSKiller_Quarantine
[2010/08/23 17:42:22 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Delta
[2010/08/12 20:32:09 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\DESIGNER
[2010/08/12 20:22:49 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Microsoft Synchronization Services
[2010/08/12 20:22:25 | 000,000,000 | ---D | C] -- C:\Windows\PCHEALTH
[2010/08/12 20:22:25 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Microsoft.NET
[2010/08/12 20:22:25 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Microsoft Sync Framework
[2010/08/12 20:22:25 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Microsoft SQL Server Compact Edition
[2010/08/12 20:16:56 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Microsoft Analysis Services
[2010/04/16 17:53:56 | 001,117,491 | ---- | C] (DVD Shrink ) -- C:\Program Files (x86)\dvdshrink32setup.exe
[2009/12/16 16:47:12 | 000,082,816 | ---- | C] (VSO Software) -- C:\Users\Krystine\AppData\Roaming\pcouffin.sys
[2009/12/04 17:24:58 | 003,139,840 | ---- | C] (WindSolutions) -- C:\Program Files\CopyTrans.exe

========== Files - Modified Within 30 Days ==========

[2010/09/07 22:22:27 | 000,000,006 | -H-- | M] () -- C:\Windows\tasks\SA.DAT
[2010/09/07 22:22:25 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2010/09/07 22:22:19 | 536,195,071 | -HS- | M] () -- C:\hiberfil.sys
[2010/09/07 22:21:36 | 007,864,320 | -HS- | M] () -- C:\Users\Krystine\ntuser.dat
[2010/09/07 22:21:32 | 000,000,098 | ---- | M] () -- C:\Windows\SysNative\drivers\etc\Hosts
[2010/09/07 22:19:35 | 005,812,847 | -H-- | M] () -- C:\Users\Krystine\AppData\Local\IconCache.db
[2010/09/07 22:16:21 | 000,717,892 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI
[2010/09/07 22:16:21 | 000,618,026 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat
[2010/09/07 22:16:21 | 000,104,340 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat
[2010/09/07 21:50:43 | 000,014,016 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2010/09/07 21:50:43 | 000,014,016 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2010/09/07 20:46:00 | 000,000,868 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-3969533455-2505683156-2406357703-1001Core.job
[2010/09/07 20:38:18 | 000,012,526 | ---- | M] () -- C:\Users\Public\Documents\Yeah yeah.docx
[2010/09/07 20:19:13 | 000,001,967 | ---- | M] () -- C:\Users\Krystine\Application Data\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox.lnk
[2010/09/07 13:56:52 | 000,017,231 | ---- | M] () -- C:\Users\Public\Documents\Final Schedule for real 2010-11.docx
[2010/09/07 12:23:13 | 064,372,577 | ---- | M] () -- C:\Windows\SysNative\drivers\Avg\incavi.avm
[2010/09/07 11:18:06 | 000,641,024 | ---- | M] (OldTimer Tools) -- C:\Users\Krystine\Desktop\OTS.exe
[2010/09/06 20:20:26 | 000,001,441 | ---- | M] () -- C:\Users\Krystine\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
[2010/09/06 18:03:08 | 000,080,384 | ---- | M] () -- C:\Users\Krystine\Desktop\MBRCheck.exe
[2010/09/05 20:16:46 | 000,524,288 | -HS- | M] () -- C:\Users\Krystine\ntuser.dat{fe1bca48-b6b2-11df-b00f-0025113d5e33}.TMContainer00000000000000000002.regtrans-ms
[2010/09/05 20:16:46 | 000,524,288 | -HS- | M] () -- C:\Users\Krystine\ntuser.dat{fe1bca48-b6b2-11df-b00f-0025113d5e33}.TMContainer00000000000000000001.regtrans-ms
[2010/09/05 20:16:46 | 000,065,536 | -HS- | M] () -- C:\Users\Krystine\ntuser.dat{fe1bca48-b6b2-11df-b00f-0025113d5e33}.TM.blf
[2010/09/02 00:28:38 | 000,574,976 | ---- | M] (OldTimer Tools) -- C:\Users\Krystine\Desktop\OTL.exe
[2010/09/01 21:36:21 | 000,524,288 | -HS- | M] () -- C:\Users\Krystine\ntuser.dat{b09e2749-b625-11df-9521-0025113d5e33}.TMContainer00000000000000000002.regtrans-ms
[2010/09/01 21:36:21 | 000,524,288 | -HS- | M] () -- C:\Users\Krystine\ntuser.dat{b09e2749-b625-11df-9521-0025113d5e33}.TMContainer00000000000000000001.regtrans-ms
[2010/09/01 21:36:21 | 000,065,536 | -HS- | M] () -- C:\Users\Krystine\ntuser.dat{b09e2749-b625-11df-9521-0025113d5e33}.TM.blf
[2010/09/01 18:15:08 | 000,013,409 | ---- | M] () -- C:\Users\Public\Documents\otl fix.docx
[2010/09/01 17:51:45 | 000,078,336 | ---- | M] () -- C:\Users\Krystine\Documents\Final Schedule 2010-11.doc
[2010/08/27 20:49:38 | 000,000,069 | ---- | M] () -- C:\Windows\MONOLITH.INI
[2010/08/27 20:49:33 | 000,000,622 | ---- | M] () -- C:\Windows\win.ini
[2010/08/27 16:47:43 | 000,001,921 | ---- | M] () -- C:\Users\Public\Desktop\World of Goo.lnk
[2010/08/26 16:45:06 | 000,018,655 | ---- | M] () -- C:\Users\Public\Documents\OTL Extras.docx
[2010/08/26 16:44:36 | 000,024,780 | ---- | M] () -- C:\Users\Public\Documents\OTL.docx
[2010/08/26 16:21:36 | 000,013,180 | ---- | M] () -- C:\Users\Public\Documents\first goored.docx
[2010/08/26 16:19:41 | 000,013,631 | ---- | M] () -- C:\Users\Public\Documents\second OTM.docx
[2010/08/26 16:15:20 | 000,013,664 | ---- | M] () -- C:\Users\Public\Documents\first OTM.docx
[2010/08/26 15:24:44 | 000,001,013 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2010/08/23 19:40:44 | 000,000,834 | ---- | M] () -- C:\Users\Krystine\Desktop\PSX emulator.lnk
[2010/08/12 20:57:06 | 000,108,840 | ---- | M] () -- C:\Users\Krystine\AppData\Local\GDIPFONTCACHEV1.DAT
[2010/08/12 20:55:26 | 000,415,616 | ---- | M] () -- C:\Windows\SysNative\FNTCACHE.DAT
[2010/08/11 20:58:19 | 000,032,768 | ---- | M] () -- C:\Users\Krystine\Documents\resume - old.doc
[2010/08/11 20:46:20 | 000,030,208 | ---- | M] () -- C:\Users\Krystine\Documents\cover letter outline.doc

========== Files Created - No Company Name ==========

[2010/09/07 20:38:18 | 000,012,526 | ---- | C] () -- C:\Users\Public\Documents\Yeah yeah.docx
[2010/09/07 20:35:46 | 028,135,936 | ---- | C] () -- C:\w7lxe.exe
[2010/09/07 20:19:13 | 000,001,967 | ---- | C] () -- C:\Users\Krystine\Application Data\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox.lnk
[2010/09/06 20:20:26 | 000,001,441 | ---- | C] () -- C:\Users\Krystine\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
[2010/09/06 18:03:07 | 000,080,384 | ---- | C] () -- C:\Users\Krystine\Desktop\MBRCheck.exe
[2010/09/04 17:04:18 | 000,524,288 | -HS- | C] () -- C:\Users\Krystine\ntuser.dat{fe1bca48-b6b2-11df-b00f-0025113d5e33}.TMContainer00000000000000000002.regtrans-ms
[2010/09/04 17:04:18 | 000,524,288 | -HS- | C] () -- C:\Users\Krystine\ntuser.dat{fe1bca48-b6b2-11df-b00f-0025113d5e33}.TMContainer00000000000000000001.regtrans-ms
[2010/09/04 17:04:18 | 000,065,536 | -HS- | C] () -- C:\Users\Krystine\ntuser.dat{fe1bca48-b6b2-11df-b00f-0025113d5e33}.TM.blf
[2010/09/01 20:39:28 | 000,524,288 | -HS- | C] () -- C:\Users\Krystine\ntuser.dat{b09e2749-b625-11df-9521-0025113d5e33}.TMContainer00000000000000000002.regtrans-ms
[2010/09/01 20:39:28 | 000,524,288 | -HS- | C] () -- C:\Users\Krystine\ntuser.dat{b09e2749-b625-11df-9521-0025113d5e33}.TMContainer00000000000000000001.regtrans-ms
[2010/09/01 20:39:28 | 000,065,536 | -HS- | C] () -- C:\Users\Krystine\ntuser.dat{b09e2749-b625-11df-9521-0025113d5e33}.TM.blf
[2010/09/01 18:15:07 | 000,013,409 | ---- | C] () -- C:\Users\Public\Documents\otl fix.docx
[2010/09/01 17:42:21 | 000,017,231 | ---- | C] () -- C:\Users\Public\Documents\Final Schedule for real 2010-11.docx
[2010/08/29 20:41:16 | 000,000,868 | ---- | C] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-3969533455-2505683156-2406357703-1001Core.job
[2010/08/27 20:47:12 | 000,000,069 | ---- | C] () -- C:\Windows\MONOLITH.INI
[2010/08/27 16:47:43 | 000,001,921 | ---- | C] () -- C:\Users\Public\Desktop\World of Goo.lnk
[2010/08/26 16:45:05 | 000,018,655 | ---- | C] () -- C:\Users\Public\Documents\OTL Extras.docx
[2010/08/26 16:44:35 | 000,024,780 | ---- | C] () -- C:\Users\Public\Documents\OTL.docx
[2010/08/26 16:21:35 | 000,013,180 | ---- | C] () -- C:\Users\Public\Documents\first goored.docx
[2010/08/26 16:19:39 | 000,013,631 | ---- | C] () -- C:\Users\Public\Documents\second OTM.docx
[2010/08/26 16:15:18 | 000,013,664 | ---- | C] () -- C:\Users\Public\Documents\first OTM.docx
[2010/08/26 15:24:44 | 000,001,013 | ---- | C] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2010/08/23 19:40:44 | 000,000,834 | ---- | C] () -- C:\Users\Krystine\Desktop\PSX emulator.lnk
[2010/08/11 20:46:17 | 000,030,208 | ---- | C] () -- C:\Users\Krystine\Documents\cover letter outline.doc
[2009/12/16 16:47:49 | 000,001,041 | ---- | C] () -- C:\Users\Krystine\AppData\Roaming\vso_ts_preview.xml
[2009/12/16 16:47:21 | 000,000,033 | ---- | C] () -- C:\Users\Krystine\AppData\Roaming\pcouffin.log
[2009/12/16 16:47:12 | 000,007,859 | ---- | C] () -- C:\Users\Krystine\AppData\Roaming\pcouffin.cat
[2009/12/16 16:47:12 | 000,001,167 | ---- | C] () -- C:\Users\Krystine\AppData\Roaming\pcouffin.inf
[2009/12/15 20:55:10 | 000,730,638 | ---- | C] () -- C:\Windows\SysWow64\PerfStringBackup.INI
[2009/12/11 01:19:40 | 000,001,169 | ---- | C] () -- C:\Program Files\Serail & Readme.bat
[2009/12/04 17:24:58 | 000,013,425 | ---- | C] () -- C:\Program Files\License Agreement.rtf
[2009/12/04 17:24:58 | 000,000,652 | ---- | C] () -- C:\Program Files\CopyTrans.ris
[2009/12/04 17:24:58 | 000,000,603 | ---- | C] () -- C:\Program Files\INSTALLATION_PROCEDURE.txt
[2009/12/04 15:36:36 | 000,000,017 | ---- | C] () -- C:\Users\Krystine\AppData\Local\resmon.resmoncfg
[2009/07/13 19:42:10 | 000,064,000 | ---- | C] () -- C:\Windows\SysWow64\BWContextHandler.dll
[2009/07/13 17:03:59 | 000,364,544 | ---- | C] () -- C:\Windows\SysWow64\msjetoledb40.dll

========== Custom Scans ==========


< %SYSTEMDRIVE%\*.* >
[2009/07/13 21:38:58 | 000,383,562 | RHS- | M] () -- C:\bootmgr
[2009/12/04 18:11:15 | 000,008,192 | RHS- | M] () -- C:\BOOTSECT.BAK
[2010/08/23 17:43:07 | 000,000,741 | ---- | M] () -- C:\deltaStartup.log
[2009/12/04 15:46:23 | 000,203,316 | RHS- | M] () -- C:\grldr
[2010/09/07 22:22:19 | 536,195,071 | -HS- | M] () -- C:\hiberfil.sys
[2006/12/02 00:37:14 | 000,904,704 | ---- | M] (Microsoft Corporation) -- C:\msdia80.dll
[2010/09/07 22:22:23 | 2146,586,623 | -HS- | M] () -- C:\pagefile.sys
[2010/09/01 17:15:21 | 000,061,762 | ---- | M] () -- C:\TDSSKiller.2.4.1.4_01.09.2010_17.14.51_log.txt
[2010/09/01 17:16:36 | 000,061,762 | ---- | M] () -- C:\TDSSKiller.2.4.1.4_01.09.2010_17.15.30_log.txt
[2010/05/22 07:58:47 | 028,135,936 | ---- | M] () -- C:\w7lxe.exe
[2009/12/04 15:46:40 | 000,000,003 | RHS- | M] () -- C:\win7ldr

< %systemroot%\Fonts\*.com >
[2009/07/14 01:32:31 | 000,026,040 | ---- | M] () -- C:\Windows\Fonts\GlobalMonospace.CompositeFont
[2009/07/14 01:32:31 | 000,026,489 | ---- | M] () -- C:\Windows\Fonts\GlobalSansSerif.CompositeFont
[2009/07/14 01:32:31 | 000,029,779 | ---- | M] () -- C:\Windows\Fonts\GlobalSerif.CompositeFont
[2009/07/14 01:32:31 | 000,043,318 | ---- | M] () -- C:\Windows\Fonts\GlobalUserInterface.CompositeFont

< %systemroot%\Fonts\*.dll >

< %systemroot%\Fonts\*.ini >
[2009/06/10 16:49:50 | 000,000,065 | ---- | M] () -- C:\Windows\Fonts\desktop.ini

< %systemroot%\Fonts\*.ini2 >

< %systemroot%\Fonts\*.exe >

< %systemroot%\system32\spool\prtprocs\w32x86\*.* >

< %systemroot%\REPAIR\*.bak1 >

< %systemroot%\REPAIR\*.ini >

< %systemroot%\system32\*.jpg >

< %systemroot%\*.jpg >

< %systemroot%\*.png >

< %systemroot%\*.scr >

< %systemroot%\*._sy >

< %APPDATA%\Adobe\Update\*.* >

< %ALLUSERSPROFILE%\Favorites\*.* >

< %APPDATA%\Microsoft\*.* >

< %PROGRAMFILES%\*.* >
[2009/07/14 00:54:24 | 000,000,174 | -HS- | M] () -- C:\Program Files (x86)\desktop.ini
[2004/07/26 03:16:40 | 001,117,491 | ---- | M] (DVD Shrink ) -- C:\Program Files (x86)\dvdshrink32setup.exe

< %APPDATA%\Update\*.* >

< %systemroot%\*. /mp /s >

< %systemroot%\System32\config\*.sav >

< %PROGRAMFILES%\bak. /s >

< %systemroot%\system32\bak. /s >

< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >

< %systemroot%\system32\config\systemprofile\*.dat /x >

< %systemroot%\*.config >

< %systemroot%\system32\*.db >

< %PROGRAMFILES%\Internet Explorer\*.dat >

< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2010/09/06 20:20:26 | 000,000,221 | -HS- | M] () -- C:\Users\Krystine\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\desktop.ini

< %USERPROFILE%\Desktop\*.exe >
[2010/09/06 18:03:08 | 000,080,384 | ---- | M] () -- C:\Users\Krystine\Desktop\MBRCheck.exe
[2010/09/02 00:28:38 | 000,574,976 | ---- | M] (OldTimer Tools) -- C:\Users\Krystine\Desktop\OTL.exe
[2010/09/07 11:18:06 | 000,641,024 | ---- | M] (OldTimer Tools) -- C:\Users\Krystine\Desktop\OTS.exe

< %PROGRAMFILES%\Common Files\*.* >

< %systemroot%\*.src >

< %systemroot%\install\*.* >

< %systemroot%\system32\DLL\*.* >

< %systemroot%\system32\HelpFiles\*.* >

< %systemroot%\system32\rundll\*.* >

< %systemroot%\winn32\*.* >

< %systemroot%\Java\*.* >

< %systemroot%\system32\test\*.* >

< %systemroot%\system32\Rundll32\*.* >

< %systemroot%\AppPatch\Custom\*.* >

< %APPDATA%\Roaming\Microsoft\Windows\Recent\*.lnk /x >

< %PROGRAMFILES%\Spybot - Search & Destroy\*.* >

< %PROGRAMFILES%\Internet Explorer\*.tmp >

< %PROGRAMFILES%\Internet Explorer\*.dat >

< %USERPROFILE%\My Documents\*.exe >

< %USERPROFILE%\*.exe >

< %PROGRAMFILES%\Mozilla Firefox\firefox.exe /md5 >
[2010/08/24 22:31:10 | 000,910,296 | ---- | M] (Mozilla Corporation) MD5=EAD58ECEFDD5E1611CCB202ED568A4FA -- C:\Program Files (x86)\Mozilla Firefox\firefox.exe

< %PROGRAMFILES%\Internet Explorer\iexplore.exe /md5 >
[2009/07/13 21:17:29 | 000,673,048 | ---- | M] (Microsoft Corporation) MD5=2C32E3E596CFE660353753EABEFB0540 -- C:\Program Files (x86)\Internet Explorer\iexplore.exe

< %systemroot%\ADDINS\*.* >
[2009/06/10 17:20:04 | 000,000,802 | ---- | M] () -- C:\Windows\addins\FXSEXT.ecf

< %systemroot%\assembly\*.bak2 >

< %systemroot%\Config\*.* >

< %systemroot%\REPAIR\*.bak2 >

< %systemroot%\SECURITY\Database\*.sdb /x >

< %systemroot%\SYSTEM\*.bak2 >

< %systemroot%\Web\*.bak2 >

< %systemroot%\Driver Cache\*.* >

< %PROGRAMFILES%\Mozilla Firefox\0*.exe >


< MD5 for: AGP440.SYS >
[2009/07/13 21:52:21 | 000,061,008 | ---- | M] (Microsoft Corporation) MD5=608C14DBA7299D8CB6ED035A68A15799 -- C:\Windows\SysWow64\DriverStore\FileRepository\machine.inf_amd64_neutral_9e6bb86c3b39a3e9\AGP440.sys
[2009/07/13 21:52:21 | 000,061,008 | ---- | M] (Microsoft Corporation) MD5=608C14DBA7299D8CB6ED035A68A15799 -- C:\Windows\winsxs\amd64_machine.inf_31bf3856ad364e35_6.1.7600.16385_none_1607dee2d861e021\AGP440.sys

< MD5 for: ATAPI.SYS >
[2009/07/13 21:52:21 | 000,024,128 | ---- | M] (Microsoft Corporation) MD5=02062C0B390B7729EDC9E69C680A6F3C -- C:\Windows\SysWow64\DriverStore\FileRepository\mshdc.inf_amd64_neutral_a69a58a4286f0b22\atapi.sys
[2009/07/13 21:52:21 | 000,024,128 | ---- | M] (Microsoft Corporation) MD5=02062C0B390B7729EDC9E69C680A6F3C -- C:\Windows\winsxs\amd64_mshdc.inf_31bf3856ad364e35_6.1.7600.16385_none_392d19c13b3ad543\atapi.sys

< MD5 for: CNGAUDIT.DLL >
[2009/07/13 21:15:06 | 000,012,288 | ---- | M] (Microsoft Corporation) MD5=50BA656134F78AF64E4DD3C8B6FEFD7E -- C:\Windows\SysWOW64\cngaudit.dll
[2009/07/13 21:15:06 | 000,012,288 | ---- | M] (Microsoft Corporation) MD5=50BA656134F78AF64E4DD3C8B6FEFD7E -- C:\Windows\SysWOW64\cngaudit.dll
[2009/07/13 21:15:06 | 000,012,288 | ---- | M] (Microsoft Corporation) MD5=50BA656134F78AF64E4DD3C8B6FEFD7E -- C:\Windows\winsxs\x86_microsoft-windows-cngaudit-dll_31bf3856ad364e35_6.1.7600.16385_none_e83a414890e8132b\cngaudit.dll
[2009/07/13 21:40:20 | 000,018,944 | ---- | M] (Microsoft Corporation) MD5=86FE1B1F8FD42CD0DB641AB1CDB13093 -- C:\Windows\winsxs\amd64_microsoft-windows-cngaudit-dll_31bf3856ad364e35_6.1.7600.16385_none_4458dccc49458461\cngaudit.dll

< MD5 for: DISK.SYS >
[2009/07/13 21:47:48 | 000,073,280 | ---- | M] (Microsoft Corporation) MD5=9819EEE8B5EA3784EC4AF3B137A5244C -- C:\Windows\SysWow64\DriverStore\FileRepository\disk.inf_amd64_neutral_10ce25bbc5a9cc43\disk.sys
[2009/07/13 21:47:48 | 000,073,280 | ---- | M] (Microsoft Corporation) MD5=9819EEE8B5EA3784EC4AF3B137A5244C -- C:\Windows\winsxs\amd64_disk.inf_31bf3856ad364e35_6.1.7600.16385_none_55bb738b8ddd8a01\disk.sys

< MD5 for: IASTORV.SYS >
[2009/07/13 21:48:04 | 000,410,688 | ---- | M] (Intel Corporation) MD5=D83EFB6FD45DF9D55E9A1AFC63640D50 -- C:\Windows\SysWow64\DriverStore\FileRepository\iastorv.inf_amd64_neutral_18cccb83b34e1453\iaStorV.sys
[2009/07/13 21:48:04 | 000,410,688 | ---- | M] (Intel Corporation) MD5=D83EFB6FD45DF9D55E9A1AFC63640D50 -- C:\Windows\winsxs\amd64_iastorv.inf_31bf3856ad364e35_6.1.7600.16385_none_0b06441fa1790136\iaStorV.sys

< MD5 for: NETLOGON.DLL >
[2009/07/13 21:41:52 | 000,692,736 | ---- | M] (Microsoft Corporation) MD5=956D030D375F207B22FB111E06EF9C35 -- C:\Windows\winsxs\amd64_microsoft-windows-security-netlogon_31bf3856ad364e35_6.1.7600.16385_none_59aca8ea51aaeefe\netlogon.dll
[2009/07/13 21:16:02 | 000,563,712 | ---- | M] (Microsoft Corporation) MD5=EAA75D9000B71F10EEC04D2AE6C60E81 -- C:\Windows\SysWOW64\netlogon.dll
[2009/07/13 21:16:02 | 000,563,712 | ---- | M] (Microsoft Corporation) MD5=EAA75D9000B71F10EEC04D2AE6C60E81 -- C:\Windows\SysWOW64\netlogon.dll
[2009/07/13 21:16:02 | 000,563,712 | ---- | M] (Microsoft Corporation) MD5=EAA75D9000B71F10EEC04D2AE6C60E81 -- C:\Windows\winsxs\wow64_microsoft-windows-security-netlogon_31bf3856ad364e35_6.1.7600.16385_none_6401533c860bb0f9\netlogon.dll

< MD5 for: NVSTOR.SYS >
[2009/07/13 21:45:45 | 000,167,488 | ---- | M] (NVIDIA Corporation) MD5=477DC4D6DEB99BE37084C9AC6D013DA1 -- C:\Windows\SysWow64\DriverStore\FileRepository\nvraid.inf_amd64_neutral_5bde3fe2945bce9e\nvstor.sys
[2009/07/13 21:45:45 | 000,167,488 | ---- | M] (NVIDIA Corporation) MD5=477DC4D6DEB99BE37084C9AC6D013DA1 -- C:\Windows\winsxs\amd64_nvraid.inf_31bf3856ad364e35_6.1.7600.16385_none_95cfb4ced8afab0e\nvstor.sys

< MD5 for: SCECLI.DLL >
[2009/07/13 21:16:13 | 000,175,616 | ---- | M] (Microsoft Corporation) MD5=26073302DAEA83CC5B944C546D6B47D2 -- C:\Windows\SysWOW64\scecli.dll
[2009/07/13 21:16:13 | 000,175,616 | ---- | M] (Microsoft Corporation) MD5=26073302DAEA83CC5B944C546D6B47D2 -- C:\Windows\SysWOW64\scecli.dll
[2009/07/13 21:16:13 | 000,175,616 | ---- | M] (Microsoft Corporation) MD5=26073302DAEA83CC5B944C546D6B47D2 -- C:\Windows\winsxs\wow64_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.1.7600.16385_none_9e577e55272d37b4\scecli.dll
[2009/07/13 21:41:53 | 000,232,448 | ---- | M] (Microsoft Corporation) MD5=398712DDDAEFB85EDF61DF6A07B65C79 -- C:\Windows\winsxs\amd64_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.1.7600.16385_none_9402d402f2cc75b9\scecli.dll
< End of report >
  • 0

Advertisements


#86
emeraldnzl

emeraldnzl

    GeekU Instructor

  • GeekU Moderator
  • 20,033 posts
Hello krystine,

  • C:\Windows\addins\FXSEXT.ecf
  • Click on the Upload button
  • Once the Scan is completed, click on the "Copy to Clipboard" button. This will copy the link of the report into the Clipboard.
  • Paste the contents of the Clipboard in your next reply.
do the same with these ones:

C:\Users\Public\Desktop\World of Goo.lnk
C:\Program Files\desktop.ini
C:\Windows\Fonts\desktop.ini
C:\w7lxe.exe
C:\Windows\MONOLITH.INI

  • 0

#87
krystine

krystine

    Member

  • Topic Starter
  • Member
  • PipPip
  • 54 posts
Not sure if it matters but world of goo and w7lxe.exe are files that were put on after the symptoms showed up. Should I still scan them?

edit: I have my machine at a friends right now and he doesn't want me to connect to the internet with it so I don't think I'll be able to do the scans. Do you think he is just being paranoid?

Edited by krystine, 07 September 2010 - 09:14 PM.

  • 0

#88
emeraldnzl

emeraldnzl

    GeekU Instructor

  • GeekU Moderator
  • 20,033 posts

I have my machine at a friends right now and he doesn't want me to connect to the internet with it so I don't think I'll be able to do the scans. Do you think he is just being paranoid?


Answer to that is I don't really know. At one stage you did have a ukranian domain in your domain addresses. That is usually a sign of a nasty infection. We removed that long ago but you still seem to be having a redirection problem.

It does seem to me that what you have left is related to tracking ware rather than the malicious variety but I don't really know.

Because your machine is a 64bit OS we can't run a number of tools that would likely fix the problem fairly quickly. Unfortunately we are looking for a needle in a haystack. Trial and error I am afraid.

Not sure if it matters but world of goo and w7lxe.exe are files that were put on after the symptoms showed up. Should I still scan them?


You can leave those two for now then. Really just checking ones I am not sure of. :)
  • 0

#89
krystine

krystine

    Member

  • Topic Starter
  • Member
  • PipPip
  • 54 posts
okay well i will have to leave the online scan until tomorrow when i am home at my own tainted router :) i'll post back then.
  • 0

#90
emeraldnzl

emeraldnzl

    GeekU Instructor

  • GeekU Moderator
  • 20,033 posts
Okie dokie :)
  • 0






Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP