1)ran OTL; the log is below
2)did not run ERUNT because the download site said it was not for VISTA.
3)ran OTM: logs are below
4)ran GooredFix: logs are below
5)TDSSKiller would not install. I tried several times and it always stopped at 80% - the error message is below.
Any advice on how to proceed would be greatly appreciated.
Thanks
Tom
-----BEGIN TDSSKiller Error Mesage:----------------------------------------------
TDSS rootkit removing tool has stopped working
Problem signature:
Problem Event Name: BEX
Application Name: TDSSKiller.exe
Application Version: 2.4.18.0
Application Timestamp: 4d621d9c
Fault Module Name: TDSSKiller.exe
Fault Module Version: 2.4.18.0
Fault Module Timestamp: 4d621d9c
Exception Offset: 00055e49
Exception Code: c0000409
Exception Data: 00000000
OS Version: 6.0.6000.2.0.0.256.6
Locale ID: 1033
Additional Information 1: ce8c
Additional Information 2: dc9a101f8fcc6675f457071cf59eed65
Additional Information 3: e300
Additional Information 4: 486a5f8bfc817dae7554e7633eb8d941
-----END of TDSKiller error message---------------------------------------------------------
-----BEGIN OTM Log--------------------------------------------------------------------------
All processes killed
========== FILES ==========
< ipconfig /flushdns /c >
Windows IP Configuration
Successfully flushed the DNS Resolver Cache.
C:\____________Bredirect Geeks to go\cmd.bat deleted successfully.
C:\____________Bredirect Geeks to go\cmd.txt deleted successfully.
========== COMMANDS ==========
C:\Windows\System32\drivers\etc\Hosts moved successfully.
HOSTS file reset successfully
[EMPTYTEMP]
User: All Users
User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Flash cache emptied: 56504 bytes
User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Flash cache emptied: 0 bytes
User: Public
User: __
->Temp folder emptied: 575634256 bytes
->Temporary Internet Files folder emptied: 19271820 bytes
->Java cache emptied: 7116463 bytes
->FireFox cache emptied: 54629078 bytes
->Flash cache emptied: 409481 bytes
%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 4215988 bytes
%systemroot%\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 115756288 bytes
%systemroot%\system32\config\systemprofile\AppData\LocalLow\Sun\Java\Deployment folder emptied: 11870 bytes
RecycleBin emptied: 0 bytes
Total Files Cleaned = 741.00 mb
Error creating restore point.
OTM by OldTimer - Version 3.1.17.2 log created on 02262011_080801
Files moved on Reboot...
C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\LLWT234Y\5338464b5255316d2f646341424a3767[2].htm moved successfully.
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\LLWT234Y\default[1].htm not found!
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\LLWT234Y\login[1].htm not found!
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\LLWT234Y\prototype[1].js not found!
C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\J1ND1VPZ\latestnews4[1].htm moved successfully.
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\J1ND1VPZ\tvshows[1].htm not found!
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\HF4QMJCG\1478890373[1] not found!
Registry entries deleted on Reboot...
-----END OTM Log file---------------------------------------------------------------------------------------
-----BEGIN Goored Log File----------------------------------------------------------------------------------
GooredFix by jpshortstuff (03.07.10.1)
Log created at 10:19 on 26/02/2011 (__)
Firefox version 3.6.12 (en-US)
========== GooredScan ==========
(none)
========== GooredLog ==========
C:\Program Files\Mozilla Firefox\extensions\
{972ce4c6-7e08-4474-a285-3208198ce6fd} [12:42 01/11/2010]
{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} [15:54 02/10/2010]
C:\Users\__\Application Data\Mozilla\Firefox\Profiles\yfgeg5n5.default\extensions\
(none)
[HKEY_LOCAL_MACHINE\Software\Mozilla\Firefox\Extensions]
(none)
-=E.O.F=-
------END GooredFix log file-----------------------------------------------------------------------
-----Begin OTL Log--------------------------------------------------------------------------------
OTL logfile created on: 2/25/2011 9:29:03 PM - Run 1
OTL by OldTimer - Version 3.2.22.0 Folder = C:\____________Bredirect Geeks to go
Windows Vista Business Edition (Version = 6.0.6000) - Type = NTWorkstation
Internet Explorer (Version = 7.0.6000.16764)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
3.00 Gb Total Physical Memory | 2.00 Gb Available Physical Memory | 70.00% Memory free
7.00 Gb Paging File | 6.00 Gb Available in Paging File | 86.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 107.21 Gb Total Space | 7.11 Gb Free Space | 6.63% Space Free | Partition Type: NTFS
Drive D: | 2.00 Gb Total Space | 1.40 Gb Free Space | 70.09% Space Free | Partition Type: NTFS
Computer Name: __LAPTOP | User Name: __ | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - [2011/02/25 21:22:18 | 000,580,608 | ---- | M] (OldTimer Tools) -- C:\____________Bredirect Geeks to go\OTL.exe
PRC - [2010/10/27 01:10:00 | 000,912,344 | ---- | M] (Mozilla Corporation) -- C:\Program Files\Mozilla Firefox\firefox.exe
PRC - [2008/10/29 01:20:29 | 002,923,520 | ---- | M] (Microsoft Corporation) -- C:\Windows\explorer.exe
PRC - [2008/05/28 10:37:33 | 000,611,664 | ---- | M] (Lavasoft) -- C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
PRC - [2007/10/09 12:55:58 | 000,665,600 | ---- | M] (SSC Localization Group) -- C:\Program Files\Epson-SSC Service Utility\ssc_serv.exe
PRC - [2007/08/21 10:33:14 | 000,554,616 | ---- | M] (Symantec Corporation) -- C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
PRC - [2007/08/21 10:32:40 | 000,108,648 | ---- | M] (Symantec Corporation) -- C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
PRC - [2007/08/21 10:31:44 | 000,047,712 | ---- | M] (Symantec Corporation) -- C:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe
PRC - [2007/06/27 05:17:02 | 000,405,504 | ---- | M] (SigmaTel, Inc.) -- C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe
PRC - [2007/06/27 05:17:00 | 000,094,208 | ---- | M] (SigmaTel, Inc.) -- C:\Windows\System32\stacsv.exe
PRC - [2007/05/25 12:38:46 | 000,112,176 | ---- | M] (SingleClick Systems) -- C:\Program Files\Dell Network Assistant\hnm_svc.exe
PRC - [2007/05/11 01:57:30 | 000,040,960 | ---- | M] (Alps Electric Co., Ltd.) -- C:\Program Files\DellTPad\hidfind.exe
PRC - [2007/05/11 01:57:26 | 000,159,744 | ---- | M] (Alps Electric Co., Ltd.) -- C:\Program Files\DellTPad\Apoint.exe
PRC - [2007/05/11 01:57:24 | 000,050,736 | ---- | M] (Alps Electric Co., Ltd.) -- C:\Program Files\DellTPad\ApMsgFwd.exe
PRC - [2007/05/11 01:57:24 | 000,040,960 | ---- | M] (Alps Electric Co., Ltd.) -- C:\Program Files\DellTPad\ApntEx.exe
PRC - [2007/04/16 17:10:26 | 000,184,320 | ---- | M] (CyberLink Corp.) -- C:\Program Files\Dell\MediaDirect\PCMService.exe
PRC - [2006/11/03 18:55:50 | 000,703,280 | ---- | M] (Broadcom Corporation.) -- C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
PRC - [2006/11/03 18:55:48 | 001,583,920 | ---- | M] (Broadcom Corporation.) -- c:\Program Files\WIDCOMM\Bluetooth Software\BTStackServer.exe
PRC - [2006/11/02 04:45:59 | 000,116,736 | ---- | M] () -- \\?\C:\Windows\System32\wbem\WMIADAP.EXE
========== Modules (SafeList) ==========
MOD - [2011/02/25 21:22:18 | 000,580,608 | ---- | M] (OldTimer Tools) -- C:\____________Bredirect Geeks to go\OTL.exe
MOD - [2006/11/02 04:38:57 | 001,648,128 | ---- | M] (Microsoft Corporation) -- C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6000.16386_none_5d07289e07e1d100\comctl32.dll
MOD - [2004/08/25 18:23:14 | 000,102,400 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Windows Script Control\msscript.ocx
========== Win32 Services (SafeList) ==========
SRV - [2009/02/26 14:11:41 | 000,655,624 | ---- | M] (Acresso Software Inc.) [On_Demand | Stopped] -- C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe -- (FLEXnet Licensing Service)
SRV - [2008/05/28 10:37:33 | 000,611,664 | ---- | M] (Lavasoft) [Auto | Running] -- C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe -- (aawservice)
SRV - [2008/01/16 11:00:28 | 000,069,632 | ---- | M] (Macromedia) [On_Demand | Stopped] -- C:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe -- (Macromedia Licensing Service)
SRV - [2008/01/09 13:47:34 | 000,265,912 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend)
SRV - [2008/01/09 06:20:05 | 001,174,664 | ---- | M] (Symantec Corporation) [On_Demand | Stopped] -- C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe -- (Symantec Core LC)
SRV - [2007/08/21 10:33:14 | 002,918,008 | ---- | M] (Symantec Corporation) [On_Demand | Stopped] -- C:\Program Files\Symantec\LiveUpdate\LuComServer_3_2.EXE -- (LiveUpdate)
SRV - [2007/08/21 10:33:14 | 000,554,616 | ---- | M] (Symantec Corporation) [Auto | Running] -- C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe -- (Automatic LiveUpdate Scheduler)
SRV - [2007/08/21 10:32:40 | 000,108,648 | ---- | M] (Symantec Corporation) [Auto | Running] -- C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe -- (CLTNetCnService)
SRV - [2007/08/21 10:32:40 | 000,108,648 | ---- | M] (Symantec Corporation) [Auto | Running] -- C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe -- (ccSetMgr)
SRV - [2007/08/21 10:32:40 | 000,108,648 | ---- | M] (Symantec Corporation) [Auto | Running] -- C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe -- (ccEvtMgr)
SRV - [2007/08/21 10:31:44 | 000,047,712 | ---- | M] (Symantec Corporation) [Auto | Running] -- C:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe -- (SymAppCore)
SRV - [2007/08/21 10:30:40 | 000,049,248 | ---- | M] (Symantec Corporation) [On_Demand | Stopped] -- C:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe -- (comHost)
SRV - [2007/08/21 10:29:56 | 000,080,504 | ---- | M] (Symantec Corporation) [On_Demand | Stopped] -- C:\Program Files\Norton Internet Security\isPwdSvc.exe -- (ISPwdSvc)
SRV - [2007/06/27 05:17:00 | 000,094,208 | ---- | M] (SigmaTel, Inc.) [Auto | Running] -- C:\Windows\System32\stacsv.exe -- (STacSV)
SRV - [2007/05/25 12:38:46 | 000,112,176 | ---- | M] (SingleClick Systems) [Auto | Running] -- C:\Program Files\Dell Network Assistant\hnm_svc.exe -- (hnmsvc)
========== Driver Services (SafeList) ==========
DRV - [2008/07/07 11:23:56 | 000,020,480 | ---- | M] (Novatel Wireless Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\NwUsbCdFil.sys -- (NWUSBCDFIL)
DRV - [2008/06/02 15:28:50 | 000,222,720 | ---- | M] (Novatel Wireless Inc) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\NWADIenum.sys -- (NWADI)
DRV - [2008/05/09 10:08:40 | 000,174,336 | ---- | M] (Novatel Wireless Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\nwusbser2.sys -- (NWUSBPort2)
DRV - [2008/05/09 10:08:40 | 000,174,336 | ---- | M] (Novatel Wireless Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\nwusbser.sys -- (NWUSBPort)
DRV - [2008/05/09 10:08:40 | 000,174,336 | ---- | M] (Novatel Wireless Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\nwusbmdm.sys -- (NWUSBModem)
DRV - [2008/03/27 07:14:08 | 000,116,992 | ---- | M] (Mars Semiconductor Corp.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\mr97310c.sys -- (mr97310c)
DRV - [2008/01/09 06:21:26 | 000,115,000 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\SYMEVENT.SYS -- (SymEvent)
DRV - [2007/11/25 02:00:00 | 000,865,904 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Stopped] -- C:\ProgramData\Symantec\Definitions\VirusDefs\20071125.006\NAVEX15.SYS -- (NAVEX15)
DRV - [2007/11/25 02:00:00 | 000,395,312 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys -- (eeCtrl)
DRV - [2007/11/25 02:00:00 | 000,081,232 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Stopped] -- C:\ProgramData\Symantec\Definitions\VirusDefs\20071125.006\NAVENG.SYS -- (NAVENG)
DRV - [2007/08/21 10:34:30 | 000,191,544 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\Windows\System32\Drivers\SYMTDI.SYS -- (SYMTDI)
DRV - [2007/08/21 10:34:28 | 000,027,576 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\Drivers\SYMREDRV.SYS -- (SYMREDRV)
DRV - [2007/08/21 10:34:14 | 000,276,792 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\srtspl.sys -- (SRTSPL)
DRV - [2007/08/21 10:34:14 | 000,025,400 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\Windows\System32\drivers\srtspx.sys -- (SRTSPX)
DRV - [2007/08/21 10:34:12 | 000,247,608 | ---- | M] (Symantec Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\System32\drivers\srtsp.sys -- (SRTSP)
DRV - [2007/08/21 10:34:00 | 000,417,592 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Stopped] -- C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCDrv.sys -- (SPBBCDrv)
DRV - [2007/08/21 10:29:48 | 000,212,280 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Stopped] -- C:\ProgramData\Symantec\Definitions\SymcData\idsdefs\20070108.003\IDSvix86.sys -- (IDSvix86)
DRV - [2007/06/27 05:17:04 | 000,326,656 | ---- | M] (SigmaTel, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\stwrt.sys -- (STHDA)
DRV - [2007/05/11 01:57:22 | 000,157,184 | ---- | M] (Alps Electric Co., Ltd.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\Apfiltr.sys -- (ApfiltrService)
DRV - [2007/04/29 01:34:36 | 000,037,376 | ---- | M] (REDC) [Kernel | Auto | Running] -- C:\Windows\System32\drivers\rixdptsk.sys -- (rismxdp)
DRV - [2007/04/29 01:34:34 | 000,043,520 | ---- | M] (REDC) [Kernel | Auto | Running] -- C:\Windows\System32\drivers\rimsptsk.sys -- (rimsptsk)
DRV - [2007/04/29 01:34:34 | 000,032,256 | ---- | M] (REDC) [Kernel | Auto | Running] -- C:\Windows\System32\drivers\rimmptsk.sys -- (rimmptsk)
DRV - [2007/04/29 00:24:30 | 000,008,192 | ---- | M] (Conexant Systems, Inc.) [Kernel | Auto | Running] -- C:\Windows\System32\drivers\XAudio.sys -- (XAudio)
DRV - [2006/12/18 20:01:20 | 000,012,672 | ---- | M] (SingleClick Systems) [Kernel | Auto | Running] -- C:\Windows\System32\drivers\packet.sys -- (Packet)
DRV - [2006/11/16 13:36:28 | 000,020,480 | ---- | M] (Printing Communications Assoc., Inc. (PCAUSA)) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\DNISP50.sys -- (DNISp50)
DRV - [2006/11/16 13:36:18 | 000,021,504 | ---- | M] (Printing Communications Assoc., Inc. (PCAUSA)) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\DNIMP50.sys -- (DNIMp50)
DRV - [2006/11/02 02:36:43 | 002,028,032 | ---- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\atikmdag.sys -- (R300)
DRV - [2006/11/02 02:30:55 | 000,200,704 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\e1e6032.sys -- (e1express) Intel®
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
========== FireFox ==========
FF - prefs.js..browser.startup.homepage: "http://www.yahoo.com"
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}:6.0.21
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.12\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010/11/01 07:42:31 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.12\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010/11/01 07:42:27 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Thunderbird 3.1.6\extensions\\Components: C:\Program Files\Mozilla Thunderbird\components [2010/11/01 07:56:49 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Thunderbird 3.1.6\extensions\\Plugins: C:\Program Files\Mozilla Thunderbird\plugins
[2010/11/01 07:56:50 | 000,000,000 | ---D | M] (No name found) -- C:\Users\__\AppData\Roaming\Mozilla\Extensions
[2010/11/01 07:56:50 | 000,000,000 | ---D | M] (No name found) -- C:\Users\__\AppData\Roaming\Mozilla\Extensions\{3550f703-e582-4d05-9a08-453d09bdfdc6}
[2008/01/16 11:09:37 | 000,000,000 | ---D | M] (No name found) -- C:\Users\__\AppData\Roaming\Mozilla\Firefox\Profiles\yfgeg5n5.default\extensions
[2011/02/25 08:49:24 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions
[2010/10/02 10:54:28 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}
[2010/10/02 10:54:08 | 000,423,656 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\Mozilla Firefox\plugins\npdeployJava1.dll
O1 HOSTS File: ([2011/02/25 10:49:55 | 000,000,734 | ---- | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (SnagIt Toolbar Loader) - {00C6482D-C502-44C8-8409-FCE54AD9C208} - C:\Program Files\TechSmith\SnagIt 8\SnagItBHO.dll (TechSmith Corporation)
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (no name) - {1E8A6170-7264-4D0F-BEAE-D42A53123C75} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.5\NppBHO.dll (Symantec Corporation)
O2 - BHO: (CBrowserHelperObject Object) - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files\Dell\BAE\BAE.dll (Dell Inc.)
O3 - HKLM\..\Toolbar: (SnagIt) - {8FF5E183-ABDE-46EB-B09E-D2AAB95CABE3} - C:\Program Files\TechSmith\SnagIt 8\SnagItIEAddin.dll (TechSmith Corporation)
O3 - HKLM\..\Toolbar: (Show Norton Toolbar) - {90222687-F593-4738-B738-FBEE9C7B26DF} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.5\UIBHO.dll (Symantec Corporation)
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {8FF5E180-ABDE-46EB-B09E-D2AAB95CABE3} - No CLSID value found.
O4 - HKLM..\Run: [AdobeAAMUpdater-1.0] C:\Program Files\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [AdobeCS4ServiceManager] C:\Program Files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [AdobeCS5ServiceManager] C:\Program Files\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [Apoint] C:\Program Files\DellTPad\Apoint.exe (Alps Electric Co., Ltd.)
O4 - HKLM..\Run: [PCMService] C:\Program Files\Dell\MediaDirect\PCMService.exe (CyberLink Corp.)
O4 - HKLM..\Run: [SigmatelSysTrayApp] C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe (SigmaTel, Inc.)
O4 - HKLM..\Run: [SSC Service Utility] C:\Program Files\Epson-SSC Service Utility\ssc_serv.exe (SSC Localization Group)
O4 - HKCU..\Run: [EPSON Stylus Photo R2400 (Copy 1)] C:\Windows\System32\spool\DRIVERS\W32X86\3\E_FATI9SA.EXE (SEIKO EPSON CORPORATION)
O4 - Startup: C:\Users\__\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\MRU-Blaster Silent Clean.lnk = C:\Program Files\MRU-Blaster\mrublaster.exe ()
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: ClearRecentProgForNewUserInStartMenu = 1
O8 - Extra context menu item: Send image to &Bluetooth Device... - c:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm ()
O8 - Extra context menu item: Send page to &Bluetooth Device... - c:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O9 - Extra Button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - c:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O9 - Extra 'Tools' menuitem : @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - c:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Computer, Inc.)
O13 - gopher Prefix: missing
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_21)
O16 - DPF: {CAFEEFAC-0016-0000-0000-ABCDEFFEDCBA} Reg Error: Value error. (Java Plug-in 1.6.0)
O16 - DPF: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_21)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_21)
O16 - DPF: {FFBB3F3B-0A5A-4106-BE53-DFE1E2340CB1} http://dlm.tools.aka...vex-2.2.1.6.cab (DownloadManager Control)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Windows\Web\Wallpaper\dellwall1.jpg
O24 - Desktop BackupWallPaper: C:\Windows\Web\Wallpaper\dellwall1.jpg
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006/09/18 16:43:36 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
O33 - MountPoints2\{4e6ed4a6-724b-11de-a391-001c26f3b730}\Shell - "" = AutoRun
O33 - MountPoints2\{4e6ed4a6-724b-11de-a391-001c26f3b730}\Shell\AutoRun\command - "" = F:\VZAccess_Manager.exe /z detect
O33 - MountPoints2\{79debd9a-a6ec-11df-8900-8cca535beeb0}\Shell - "" = AutoRun
O33 - MountPoints2\{79debd9a-a6ec-11df-8900-8cca535beeb0}\Shell\AutoRun\command - "" = "G:\WD SmartWare.exe" autoplay=true
O33 - MountPoints2\{7a460ede-068a-11df-badd-001c26f3b730}\Shell - "" = AutoRun
O33 - MountPoints2\{7a460ede-068a-11df-badd-001c26f3b730}\Shell\AutoRun\command - "" = "F:\WD SmartWare.exe" autoplay=true
O33 - MountPoints2\{8543c142-9025-11de-9178-001c26f3b730}\Shell - "" = AutoRun
O33 - MountPoints2\{8543c142-9025-11de-9178-001c26f3b730}\Shell\AutoRun\command - "" = F:\LapNetWizard.exe
O33 - MountPoints2\{a9e36b46-706d-11de-8c4d-001c26f3b730}\Shell - "" = AutoRun
O33 - MountPoints2\{a9e36b46-706d-11de-8c4d-001c26f3b730}\Shell\AutoRun\command - "" = F:\VZAccess_Manager.exe /z detect
O33 - MountPoints2\{dd62fda1-7198-11de-abcc-001c26f3b730}\Shell - "" = AutoRun
O33 - MountPoints2\{dd62fda1-7198-11de-abcc-001c26f3b730}\Shell\AutoRun\command - "" = F:\VZAccess_Manager.exe /z detect
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O34 - HKLM BootExecute: (lsdelete) - C:\Windows\System32\lsdelete.exe ()
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
========== Files/Folders - Created Within 30 Days ==========
[2011/02/25 21:21:57 | 000,000,000 | ---D | C] -- C:\____________Bredirect Geeks to go
[2011/02/13 10:21:44 | 000,000,000 | ---D | C] -- C:\________________________________zillow
[2011/01/31 11:53:35 | 000,000,000 | ---D | C] -- C:\LIH Guide 2011
========== Files - Modified Within 30 Days ==========
[2011/02/25 21:31:01 | 011,350,468 | ---- | M] () -- C:\Windows\System32\perfh009.dat
[2011/02/25 21:31:01 | 003,983,608 | ---- | M] () -- C:\Windows\System32\perfc009.dat
[2011/02/25 21:27:06 | 000,000,114 | ---- | M] () -- C:\Users\__\Desktop\geeksToGo.url
[2011/02/25 21:24:37 | 000,000,458 | ---- | M] () -- C:\Windows\tasks\SDMsgUpdate (TE).job
[2011/02/25 21:23:53 | 000,003,456 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2011/02/25 21:23:53 | 000,003,456 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2011/02/25 21:23:44 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2011/02/25 21:23:32 | 3747,807,232 | -HS- | M] () -- C:\hiberfil.sys
[2011/02/25 21:23:31 | 260,009,053 | ---- | M] () -- C:\Windows\MEMORY.DMP
[2011/02/25 19:00:12 | 000,000,012 | ---- | M] () -- C:\Windows\bthservsdp.dat
[2011/02/25 08:23:41 | 000,000,205 | ---- | M] () -- C:\Users\__\Application Data\Microsoft\Internet Explorer\Quick Launch\New Internet Shortcut.url
[2011/02/15 16:13:37 | 000,000,123 | ---- | M] () -- C:\Users\__\Application Data\Microsoft\Internet Explorer\Quick Launch\HHS.com.url
[2011/02/15 15:39:38 | 000,000,123 | ---- | M] () -- C:\Users\__\Desktop\HHS.com.url
[2011/02/14 14:16:18 | 000,000,111 | ---- | M] () -- C:\Users\__\Desktop\Zillow qw12 accabonac.url
[2011/02/12 09:02:38 | 000,000,119 | ---- | M] () -- C:\Users\__\Desktop\New Internet Shortcut.url
========== Files Created - No Company Name ==========
[2011/02/25 21:26:22 | 000,000,114 | ---- | C] () -- C:\Users\__\Desktop\geeksToGo.url
[2011/02/15 16:13:37 | 000,000,123 | ---- | C] () -- C:\Users\__\Application Data\Microsoft\Internet Explorer\Quick Launch\HHS.com.url
[2011/02/15 15:39:17 | 000,000,123 | ---- | C] () -- C:\Users\__\Desktop\HHS.com.url
[2011/02/14 14:15:40 | 000,000,111 | ---- | C] () -- C:\Users\__\Desktop\Zillow qw12 accabonac.url
[2011/02/12 09:02:43 | 000,000,205 | ---- | C] () -- C:\Users\__\Application Data\Microsoft\Internet Explorer\Quick Launch\New Internet Shortcut.url
[2011/02/12 09:02:22 | 000,000,119 | ---- | C] () -- C:\Users\__\Desktop\New Internet Shortcut.url
[2010/12/04 08:42:42 | 000,020,000 | -H-- | C] () -- C:\ProgramData\T09F8
[2009/09/28 09:16:10 | 000,000,236 | ---- | C] () -- C:\Users\__\AppData\Roaming\wklnhst.dat
[2009/09/02 08:10:10 | 000,000,037 | ---- | C] () -- C:\Windows\marscam.ini
[2008/10/25 06:56:06 | 000,024,206 | ---- | C] () -- C:\Users\__\AppData\Roaming\UserTile.png
[2008/10/07 10:40:24 | 000,000,195 | ---- | C] () -- C:\Windows\cdplayer.ini
[2008/05/16 10:58:04 | 000,012,632 | ---- | C] () -- C:\Windows\System32\lsdelete.exe
[2008/01/16 11:57:41 | 000,000,268 | R--- | C] () -- C:\ProgramData\Pipe Organ
[2008/01/16 11:57:41 | 000,000,268 | R--- | C] () -- C:\Users\__\AppData\Roaming\Piano Hard
[2008/01/16 11:57:41 | 000,000,020 | -H-- | C] () -- C:\ProgramData\PKP_DLdw.DAT
[2008/01/16 11:57:41 | 000,000,012 | R--- | C] () -- C:\ProgramData\Pop Kit
[2008/01/16 11:29:48 | 000,042,483 | ---- | C] () -- C:\Windows\ICCCODES.DAT
[2008/01/16 11:29:48 | 000,039,095 | ---- | C] () -- C:\Windows\Iccsigs.dat
[2008/01/16 11:29:48 | 000,000,156 | ---- | C] () -- C:\Windows\KPCMS.INI
[2008/01/16 11:29:37 | 000,210,944 | ---- | C] () -- C:\Windows\System32\MSVCRT10.DLL
[2008/01/16 11:09:38 | 000,000,000 | ---- | C] () -- C:\Windows\nsreg.dat
[2008/01/15 15:27:36 | 000,016,384 | ---- | C] () -- C:\Windows\System32\FileOps.exe
[2008/01/15 12:09:49 | 000,000,376 | ---- | C] () -- C:\Windows\ODBC.INI
[2008/01/15 12:08:12 | 000,090,112 | ---- | C] () -- C:\Users\__\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2008/01/15 10:52:41 | 000,006,324 | ---- | C] () -- C:\Users\__\AppData\Local\d3d9caps.dat
[2008/01/09 13:56:34 | 000,910,304 | ---- | C] () -- C:\Windows\System32\igmedkrn.dll
[2008/01/09 13:56:34 | 000,249,856 | ---- | C] () -- C:\Windows\System32\igfxTMM.dll
[2008/01/09 13:56:34 | 000,204,800 | ---- | C] () -- C:\Windows\System32\igfxCoIn_v1272.dll
[2008/01/09 13:56:27 | 000,016,480 | ---- | C] () -- C:\Windows\System32\rixdicon.dll
[2008/01/09 13:45:53 | 000,013,576 | ---- | C] () -- C:\Windows\System32\syscorecfg256.dll
[2008/01/09 06:24:25 | 000,000,859 | ---- | C] () -- C:\Windows\{0240BDFB-2995-4A3F-8C96-18D41282B716}_WiseFW.ini
[2008/01/09 06:12:07 | 000,065,536 | ---- | C] () -- C:\Windows\System32\bcmwlrmt.dll
[2008/01/09 06:12:07 | 000,024,064 | ---- | C] () -- C:\Windows\System32\WLTRYSVC.EXE
[2008/01/09 06:03:27 | 000,000,012 | ---- | C] () -- C:\Windows\bthservsdp.dat
[2006/11/09 23:45:20 | 000,000,000 | ---- | C] () -- C:\Windows\System32\atiicdxx.dat
[2006/11/03 18:25:56 | 000,389,120 | ---- | C] () -- C:\Windows\System32\btwhidcs.dll
[2006/11/02 07:56:48 | 000,067,584 | --S- | C] () -- C:\Windows\bootstat.dat
[2006/11/02 07:47:43 | 001,492,512 | ---- | C] () -- C:\Windows\System32\FNTCACHE.DAT
[2006/11/02 07:36:36 | 000,063,488 | ---- | C] () -- C:\Windows\System32\PrintBrmUi.exe
[2006/11/02 05:33:01 | 011,336,876 | ---- | C] () -- C:\Windows\System32\perfh009.dat
[2006/11/02 05:33:01 | 003,978,614 | ---- | C] () -- C:\Windows\System32\perfc009.dat
[2006/11/02 05:33:01 | 000,287,440 | ---- | C] () -- C:\Windows\System32\perfi009.dat
[2006/11/02 05:33:01 | 000,030,674 | ---- | C] () -- C:\Windows\System32\perfd009.dat
[2006/11/02 05:25:44 | 000,159,744 | ---- | C] () -- C:\Windows\System32\atitmmxx.dll
[2006/11/02 05:23:21 | 000,215,943 | ---- | C] () -- C:\Windows\System32\dssec.dat
[2006/11/02 03:58:30 | 000,043,131 | ---- | C] () -- C:\Windows\mib.bin
[2006/11/02 03:19:00 | 000,000,741 | ---- | C] () -- C:\Windows\System32\NOISE.DAT
[2006/11/02 02:40:29 | 000,013,750 | ---- | C] () -- C:\Windows\System32\pacerprf.ini
[2006/11/02 02:25:31 | 000,673,088 | ---- | C] () -- C:\Windows\System32\mlang.dat
[2006/11/02 02:22:43 | 000,099,999 | ---- | C] () -- C:\Windows\System32\StructuredQuerySchema.bin
[2006/11/02 02:22:43 | 000,018,271 | ---- | C] () -- C:\Windows\System32\StructuredQuerySchemaTrivial.bin
[2002/06/02 14:05:00 | 000,038,912 | ---- | C] () -- C:\Windows\System32\XD_Strt.dll
[2001/11/14 13:56:00 | 001,802,240 | ---- | C] () -- C:\Windows\System32\lcppn21.dll
[2001/10/12 10:58:20 | 000,028,672 | ---- | C] () -- C:\Windows\System32\mr310exd.dll
[2001/10/12 10:57:18 | 000,036,864 | ---- | C] () -- C:\Windows\System32\mr310exv.dll
[2000/12/07 10:13:58 | 000,015,164 | ---- | C] () -- C:\Windows\mr310twc.ini
[1999/12/07 00:00:00 | 000,024,976 | ---- | C] () -- C:\Windows\twain_16.dll
[1999/01/22 21:46:58 | 000,065,536 | ---- | C] () -- C:\Windows\System32\MSRTEDIT.DLL
========== LOP Check ==========
[2010/10/13 09:02:24 | 000,000,000 | ---D | M] -- C:\Users\__\AppData\Roaming\Axon2009
[2010/09/29 07:56:53 | 000,000,000 | ---D | M] -- C:\Users\__\AppData\Roaming\chc.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
[2009/12/31 09:00:30 | 000,000,000 | ---D | M] -- C:\Users\__\AppData\Roaming\e-Campaign
[2008/09/08 08:57:17 | 000,000,000 | ---D | M] -- C:\Users\__\AppData\Roaming\GlobalSCAPE
[2009/02/14 15:50:22 | 000,000,000 | ---D | M] -- C:\Users\__\AppData\Roaming\Goodsol
[2010/12/04 08:50:53 | 000,000,000 | ---D | M] -- C:\Users\__\AppData\Roaming\Lasersoft Imaging
[2010/02/25 15:00:53 | 000,000,000 | ---D | M] -- C:\Users\__\AppData\Roaming\Nikon
[2008/07/13 17:50:32 | 000,000,000 | ---D | M] -- C:\Users\__\AppData\Roaming\NwDocx
[2008/10/25 06:56:06 | 000,000,000 | ---D | M] -- C:\Users\__\AppData\Roaming\PeerNetworking
[2009/07/18 16:59:06 | 000,000,000 | ---D | M] -- C:\Users\__\AppData\Roaming\SmartDraw
[2009/09/28 09:16:16 | 000,000,000 | ---D | M] -- C:\Users\__\AppData\Roaming\Template
[2010/11/01 07:56:49 | 000,000,000 | ---D | M] -- C:\Users\__\AppData\Roaming\Thunderbird
[2008/04/09 18:44:03 | 000,000,000 | ---D | M] -- C:\Users\__\AppData\Roaming\vusbsp
[2010/10/25 10:04:38 | 000,000,000 | ---D | M] -- C:\Users\__\AppData\Roaming\Western Digital
[2011/02/25 19:00:12 | 000,032,548 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT
[2011/02/25 21:24:37 | 000,000,458 | ---- | M] () -- C:\Windows\Tasks\SDMsgUpdate (TE).job
========== Purity Check ==========
========== Alternate Data Streams ==========
@Alternate Data Stream - 113 bytes -> C:\ProgramData\TEMP:62E2D794
< End of report >
-----END of OTL Log-------------------------------------------------------------------------------
Edited by tom96, 26 February 2011 - 12:40 PM.