Jump to content

Welcome to Geeks to Go - Register now for FREE

Need help with your computer or device? Want to learn new tech skills? You're in the right place!
Geeks to Go is a friendly community of tech experts who can solve any problem you have. Just create a free account and post your question. Our volunteers will reply quickly and guide you through the steps. Don't let tech troubles stop you. Join Geeks to Go now and get the support you need!

How it Works Create Account
Photo

Google Redirecting & Audio Ads Playing In Background


  • Please log in to reply

#1
Laura Rod

Laura Rod

    New Member

  • Member
  • Pip
  • 6 posts
For about 24 hours, I have been experiencing Google redirecting every page I click after searching. Also, every now and then, a random audio ad will begin playing through my speakers, with no visible programs or videos open. I was infected with the "Windows Recovery" virus last night but managed to get rid of it using Malwarebytes' Anti-Malware and I believe that it is no longer on my system. I tried the same program, as well as Spybot, to get rid of the Google redirecting and random audio ads but was unsuccessful. I am unsure whether they are somehow connected but I would really appreciate help to be rid of them both. Thank you for reading.

Here is my OTL log:

OTL logfile created on: 4/19/2011 5:16:21 PM - Run 1
OTL by OldTimer - Version 3.2.22.3 Folder = C:\Users\Kristen\Downloads
Home Premium Edition (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7600.16385)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

2.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 56.00% Memory free
4.00 Gb Paging File | 3.00 Gb Available in Paging File | 71.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\windows | %ProgramFiles% = C:\Program Files
Drive C: | 221.15 Gb Total Space | 114.93 Gb Free Space | 51.97% Space Free | Partition Type: NTFS

Computer Name: KRISTEN-PC | User Name: Kristen | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - [2011/04/19 17:15:55 | 000,580,608 | ---- | M] (OldTimer Tools) -- C:\Users\Kristen\Downloads\OTL.exe
PRC - [2011/03/23 18:09:24 | 000,912,344 | ---- | M] (Mozilla Corporation) -- C:\Program Files\Mozilla Firefox\firefox.exe
PRC - [2011/02/25 10:46:22 | 000,249,648 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Microsoft\BingBar\SeaPort.EXE
PRC - [2011/01/08 08:48:12 | 000,108,080 | ---- | M] () -- C:\Program Files\Hotspot Shield\bin\openvpntray.exe
PRC - [2011/01/08 08:46:06 | 000,271,408 | ---- | M] () -- C:\Program Files\Hotspot Shield\bin\openvpnas.exe
PRC - [2011/01/06 04:30:36 | 000,352,304 | ---- | M] (AnchorFree Inc.) -- C:\Program Files\Hotspot Shield\HssWPR\hsssrv.exe
PRC - [2010/10/16 04:42:14 | 000,326,704 | ---- | M] () -- C:\Program Files\Hotspot Shield\bin\hsswd.exe
PRC - [2010/06/27 02:09:18 | 000,167,936 | ---- | M] (Applian Technologies, Inc.) -- C:\Program Files\Freecorder\FLVSrvc.exe
PRC - [2010/03/11 08:44:56 | 000,496,184 | ---- | M] (Conexant Systems, Inc.) -- C:\Program Files\CONEXANT\cAudioFilterAgent\cAudioFilterAgent.exe
PRC - [2010/02/24 18:54:48 | 002,454,840 | ---- | M] (TOSHIBA CORPORATION.) -- C:\Program Files\TOSHIBA\TOSHIBA Web Camera Application\TWebCamera.exe
PRC - [2010/02/23 06:23:50 | 000,304,496 | ---- | M] (TOSHIBA CORPORATION) -- C:\Program Files\TOSHIBA\ConfigFree\NDSTray.exe
PRC - [2010/02/06 10:41:00 | 000,111,960 | ---- | M] (TOSHIBA Corporation) -- C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSmartSrv.exe
PRC - [2010/02/06 10:40:44 | 001,021,272 | ---- | M] (TOSHIBA Corporation) -- C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSENotify.exe
PRC - [2010/01/29 09:44:24 | 000,185,712 | ---- | M] (TOSHIBA CORPORATION) -- C:\Program Files\TOSHIBA\ConfigFree\CFIWmxSvcs.exe
PRC - [2010/01/15 22:49:20 | 000,255,536 | ---- | M] (McAfee, Inc.) -- C:\Program Files\McAfee Security Scan\2.0.181\SSScheduler.exe
PRC - [2009/11/06 15:04:20 | 000,468,320 | ---- | M] (TOSHIBA Corporation) -- C:\Program Files\TOSHIBA\Power Saver\TosCoSrv.exe
PRC - [2009/10/31 15:45:39 | 002,614,272 | ---- | M] (Microsoft Corporation) -- C:\Windows\explorer.exe
PRC - [2009/10/07 02:23:12 | 001,294,136 | ---- | M] (TOSHIBA Corporation) -- C:\Program Files\TOSHIBA\TOSHIBA Service Station\ToshibaServiceStation.exe
PRC - [2009/10/07 02:21:50 | 000,051,512 | ---- | M] (TOSHIBA Corporation) -- C:\Program Files\TOSHIBA\TOSHIBA Service Station\TMachInfo.exe
PRC - [2009/09/30 16:59:26 | 000,049,152 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\taskhost.exe
PRC - [2009/07/29 13:26:42 | 000,062,848 | ---- | M] (TOSHIBA CORPORATION) -- C:\Program Files\TOSHIBA\ConfigFree\CFSwMgr.exe
PRC - [2009/07/29 08:43:04 | 000,128,344 | ---- | M] (TOSHIBA Corporation) -- C:\Windows\System32\TODDSrv.exe
PRC - [2009/03/11 11:51:20 | 000,046,448 | ---- | M] (TOSHIBA CORPORATION) -- C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
PRC - [2009/02/21 02:46:52 | 000,030,312 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Microsoft Small Business\Business Contact Manager\BcmSqlStartupSvc.exe
PRC - [2009/01/26 15:31:16 | 002,144,088 | RHS- | M] (Safer Networking Limited) -- C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe


========== Modules (SafeList) ==========

MOD - [2011/04/19 17:15:55 | 000,580,608 | ---- | M] (OldTimer Tools) -- C:\Users\Kristen\Downloads\OTL.exe
MOD - [2010/08/21 15:21:32 | 001,680,896 | ---- | M] (Microsoft Corporation) -- C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7600.16661_none_420fe3fa2b8113bd\comctl32.dll


========== Win32 Services (SafeList) ==========

SRV - [2011/03/30 12:22:38 | 003,229,784 | ---- | M] () [Auto | Running] -- c:\Program Files\Common Files\Akamai\netsession_win_a35e6b9.dll -- (Akamai)
SRV - [2011/02/28 18:44:14 | 000,183,560 | ---- | M] (Microsoft Corporation.) [On_Demand | Stopped] -- C:\Program Files\Microsoft\BingBar\BBSvc.EXE -- (BBSvc)
SRV - [2011/02/25 10:46:22 | 000,249,648 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files\Microsoft\BingBar\SeaPort.EXE -- (SeaPort)
SRV - [2011/01/08 08:48:18 | 000,057,640 | ---- | M] () [On_Demand | Stopped] -- C:\Program Files\Hotspot Shield\bin\HssTrayService.exe -- (HssTrayService)
SRV - [2011/01/08 08:46:06 | 000,271,408 | ---- | M] () [Auto | Running] -- C:\Program Files\Hotspot Shield\bin\openvpnas.exe -- (HotspotShieldService)
SRV - [2011/01/06 04:30:36 | 000,352,304 | ---- | M] (AnchorFree Inc.) [Auto | Running] -- C:\Program Files\Hotspot Shield\HssWPR\hsssrv.exe -- (HssSrv)
SRV - [2010/10/16 04:42:14 | 000,326,704 | ---- | M] () [Auto | Running] -- C:\Program Files\Hotspot Shield\bin\hsswd.exe -- (HssWd)
SRV - [2010/10/10 08:19:37 | 001,343,400 | ---- | M] (Microsoft Corporation) [Unknown | Stopped] -- C:\Windows\System32\Wat\WatAdminSvc.exe -- (WatAdminSvc)
SRV - [2010/02/19 12:37:14 | 000,517,096 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe -- (SwitchBoard)
SRV - [2010/02/06 10:41:00 | 000,111,960 | ---- | M] (TOSHIBA Corporation) [On_Demand | Running] -- C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSmartSrv.exe -- (TOSHIBA HDD SSD Alert Service)
SRV - [2010/01/29 09:44:24 | 000,185,712 | ---- | M] (TOSHIBA CORPORATION) [Auto | Running] -- C:\Program Files\TOSHIBA\ConfigFree\CFIWmxSvcs.exe -- (cfWiMAXService)
SRV - [2010/01/15 22:49:20 | 000,227,232 | ---- | M] (McAfee, Inc.) [On_Demand | Stopped] -- C:\Program Files\McAfee Security Scan\2.0.181\McCHSvc.exe -- (McComponentHostService)
SRV - [2009/12/04 12:30:18 | 000,238,328 | ---- | M] (WildTangent, Inc.) [On_Demand | Stopped] -- C:\Program Files\TOSHIBA Games\TOSHIBA Game Console\GameConsoleService.exe -- (GameConsoleService)
SRV - [2009/11/06 15:04:20 | 000,468,320 | ---- | M] (TOSHIBA Corporation) [Auto | Running] -- C:\Program Files\TOSHIBA\Power Saver\TosCoSrv.exe -- (TosCoSrv)
SRV - [2009/10/07 02:21:50 | 000,051,512 | ---- | M] (TOSHIBA Corporation) [On_Demand | Running] -- C:\Program Files\TOSHIBA\TOSHIBA Service Station\TMachInfo.exe -- (TMachInfo)
SRV - [2009/07/29 08:43:04 | 000,128,344 | ---- | M] (TOSHIBA Corporation) [Auto | Running] -- C:\Windows\System32\TODDSrv.exe -- (TODDSrv)
SRV - [2009/07/14 11:16:13 | 000,025,088 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\sensrsvc.dll -- (SensrSvc)
SRV - [2009/07/14 11:15:41 | 000,680,960 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend)
SRV - [2009/03/11 11:51:20 | 000,046,448 | ---- | M] (TOSHIBA CORPORATION) [Auto | Running] -- C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe -- (ConfigFree Service)
SRV - [2009/02/21 02:46:52 | 000,030,312 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files\Microsoft Small Business\Business Contact Manager\BcmSqlStartupSvc.exe -- (BcmSqlStartupSvc)


========== Driver Services (SafeList) ==========

DRV - [2010/09/23 05:19:02 | 000,037,376 | ---- | M] (AnchorFree Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\HssDrv.sys -- (HssDrv)
DRV - [2010/09/23 05:19:02 | 000,032,768 | ---- | M] (AnchorFree Inc) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\taphss.sys -- (taphss)
DRV - [2010/03/05 10:53:06 | 000,067,624 | ---- | M] (Atheros Communications, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\L1C62x86.sys -- (L1C)
DRV - [2010/02/02 03:29:46 | 000,182,304 | ---- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\RtsUStor.sys -- (RSUSBSTOR)
DRV - [2010/01/19 10:45:00 | 000,514,104 | ---- | M] (Conexant Systems Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\CHDRT32.sys -- (CnxtHdAudService)
DRV - [2009/11/07 05:53:58 | 001,227,776 | ---- | M] (Atheros Communications, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\athr.sys -- (athr)
DRV - [2009/07/31 10:45:56 | 000,022,912 | ---- | M] (TOSHIBA Corporation.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\tdcmdpst.sys -- (tdcmdpst)
DRV - [2009/07/15 08:28:42 | 000,023,512 | ---- | M] (TOSHIBA Corporation) [Kernel | Boot | Running] -- C:\windows\system32\DRIVERS\TVALZ_O.SYS -- (TVALZ)
DRV - [2009/07/14 09:52:10 | 000,014,336 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\vwifimp.sys -- (vwifimp)
DRV - [2009/07/14 09:51:11 | 000,034,944 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\winusb.sys -- (WinUsb)
DRV - [2009/07/08 01:53:06 | 000,007,680 | ---- | M] (TOSHIBA Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\FwLnk.sys -- (FwLnk)
DRV - [2009/06/23 10:04:58 | 000,024,064 | ---- | M] (TOSHIBA Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\PGEffect.sys -- (PGEffect)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========


IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = <local>
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = http=127.0.0.1:55414

========== FireFox ==========

FF - prefs.js..browser.search.selectedEngine: "eBay"
FF - prefs.js..extensions.enabledItems: {1392b8d2-5c05-419f-a8f6-b9f15a596612}:3.3.3.2
FF - prefs.js..extensions.enabledItems: {ACAA314B-EEBA-48e4-AD47-84E31C44796C}:1.0.1
FF - prefs.js..extensions.enabledItems: {e968fc70-8f95-4ab9-9e79-304de2a71ee1}:0.7.3
FF - prefs.js..extensions.enabledItems: [email protected]:3.3.3.2
FF - prefs.js..network.proxy.http: "127.0.0.1"
FF - prefs.js..network.proxy.http_port: 55414
FF - prefs.js..network.proxy.no_proxies_on: "*.local"
FF - prefs.js..network.proxy.type: 0

FF - HKLM\software\mozilla\Mozilla Firefox 3.6.16\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011/03/23 18:09:25 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.16\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011/04/02 08:09:54 | 000,000,000 | ---D | M]

[2010/10/08 16:02:39 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Kristen\AppData\Roaming\Mozilla\Extensions
[2011/04/18 22:11:36 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Kristen\AppData\Roaming\Mozilla\Firefox\Profiles\4phcayjv.default\extensions
[2011/03/27 08:33:04 | 000,000,000 | ---D | M] (Freecorder Community Toolbar) -- C:\Users\Kristen\AppData\Roaming\Mozilla\Firefox\Profiles\4phcayjv.default\extensions\{1392b8d2-5c05-419f-a8f6-b9f15a596612}
[2010/10/08 17:02:58 | 000,000,000 | ---D | M] ("DVDVideoSoft Menu") -- C:\Users\Kristen\AppData\Roaming\Mozilla\Firefox\Profiles\4phcayjv.default\extensions\{ACAA314B-EEBA-48e4-AD47-84E31C44796C}
[2011/01/07 09:15:35 | 000,000,000 | ---D | M] (User Agent Switcher) -- C:\Users\Kristen\AppData\Roaming\Mozilla\Firefox\Profiles\4phcayjv.default\extensions\{e968fc70-8f95-4ab9-9e79-304de2a71ee1}
[2011/03/27 08:33:03 | 000,000,000 | ---D | M] (Conduit Engine) -- C:\Users\Kristen\AppData\Roaming\Mozilla\Firefox\Profiles\4phcayjv.default\extensions\[email protected]
[2011/04/10 12:19:58 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions
[2011/03/06 18:47:39 | 000,000,000 | ---D | M] (afurladvisor) -- C:\Program Files\Mozilla Firefox\extensions\[email protected]

O1 HOSTS File: ([2011/04/19 16:36:13 | 000,000,027 | ---- | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (Spybot-S&D IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O2 - BHO: (Skype Plug-In) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O2 - BHO: (Bing Bar Helper) - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files\Microsoft\BingBar\BingExt.dll (Microsoft Corporation.)
O2 - BHO: (TOSHIBA Media Controller Plug-in) - {F3C88694-EFFA-4d78-B409-54B7B2535B14} - C:\Program Files\TOSHIBA\TOSHIBA Media Controller Plug-in\TOSHIBAMediaControllerIE.dll (<TOSHIBA>)
O3 - HKLM\..\Toolbar: (Bing Bar) - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files\Microsoft\BingBar\BingExt.dll (Microsoft Corporation.)
O4 - HKLM..\Run: [AdobeAAMUpdater-1.0] C:\Program Files\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [AdobeCS5ServiceManager] C:\Program Files\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [cAudioFilterAgent] C:\Program Files\CONEXANT\cAudioFilterAgent\cAudioFilterAgent.exe (Conexant Systems, Inc.)
O4 - HKLM..\Run: [Freecorder FLV Service] C:\Program Files\Freecorder\FLVSrvc.exe (Applian Technologies, Inc.)
O4 - HKLM..\Run: [Malwarebytes' Anti-Malware (reboot)] C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe (Malwarebytes Corporation)
O4 - HKLM..\Run: [SmartAudio] C:\Program Files\CONEXANT\SAII\SAIICpl.exe ()
O4 - HKLM..\Run: [SwitchBoard] C:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [ToshibaServiceStation] C:\Program Files\TOSHIBA\TOSHIBA Service Station\ToshibaServiceStation.exe (TOSHIBA Corporation)
O4 - HKLM..\Run: [TosSENotify] C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosWaitSrv.exe (TOSHIBA Corporation)
O4 - HKLM..\Run: [TosVolRegulator] C:\Program Files\TOSHIBA\TosVolRegulator\TosVolRegulator.exe (TOSHIBA Corporation)
O4 - HKLM..\Run: [TWebCamera] C:\Program Files\TOSHIBA\TOSHIBA Web Camera Application\TWebCamera.exe (TOSHIBA CORPORATION.)
O4 - HKCU..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe (Safer Networking Limited)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O8 - Extra context menu item: Free YouTube Download - C:\Users\Kristen\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubedownload.htm ()
O8 - Extra context menu item: Free YouTube to Mp3 Converter - C:\Users\Kristen\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm ()
O9 - Extra Button: Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_17)
O16 - DPF: {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_17)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_17)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.ad...Plus/1.6/gp.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 10.0.0.138
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\windows\System32\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O28 - HKLM ShellExecuteHooks: {AEB6717E-7E19-11d0-97EE-00C04FD91972} - Reg Error: Key error. File not found
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009/06/11 07:42:20 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = ComFile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*

========== Files/Folders - Created Within 30 Days ==========

[2011/04/19 17:01:30 | 000,000,000 | -HSD | C] -- C:\$RECYCLE.BIN
[2011/04/19 16:51:24 | 000,212,480 | ---- | C] (SteelWerX) -- C:\windows\SWXCACLS.exe
[2011/04/19 16:50:48 | 000,000,000 | ---D | C] -- C:\Users\Kristen\AppData\Local\{A9B40FD4-8712-44F8-9644-CF66F34871E3}
[2011/04/19 16:28:22 | 000,161,792 | ---- | C] (SteelWerX) -- C:\windows\SWREG.exe
[2011/04/19 16:28:22 | 000,136,704 | ---- | C] (SteelWerX) -- C:\windows\SWSC.exe
[2011/04/19 16:28:22 | 000,031,232 | ---- | C] (NirSoft) -- C:\windows\NIRCMD.exe
[2011/04/19 16:28:16 | 000,000,000 | ---D | C] -- C:\windows\ERDNT
[2011/04/19 16:27:46 | 000,000,000 | ---D | C] -- C:\Qoobox
[2011/04/19 14:39:26 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Spybot - Search & Destroy
[2011/04/19 14:39:21 | 000,000,000 | ---D | C] -- C:\ProgramData\Spybot - Search & Destroy
[2011/04/19 14:39:21 | 000,000,000 | ---D | C] -- C:\Program Files\Spybot - Search & Destroy
[2011/04/19 14:24:53 | 000,000,000 | ---D | C] -- C:\Users\Kristen\AppData\Local\{B5775D39-EEAC-4CAB-810F-6F7B8FB47466}
[2011/04/19 14:18:39 | 000,000,000 | ---D | C] -- C:\Users\Kristen\AppData\Local\{F0BD2BCC-8D13-4AF8-862C-F501978F30C7}
[2011/04/19 14:18:26 | 000,000,000 | ---D | C] -- C:\Users\Kristen\AppData\Local\{D94FB190-7E7D-46ED-A401-D9058918D1EA}
[2011/04/19 14:02:27 | 000,000,000 | ---D | C] -- C:\Users\Kristen\AppData\Local\{0F44CE73-E2AA-49AB-B8B1-C4420B4B821B}
[2011/04/18 22:17:19 | 000,000,000 | ---D | C] -- C:\Program Files\GridinSoft Trojan Killer
[2011/04/18 22:10:36 | 000,000,000 | ---D | C] -- C:\Users\Kristen\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows Recovery
[2011/04/18 14:35:31 | 000,000,000 | ---D | C] -- C:\Users\Kristen\AppData\Local\{86ACD97C-E277-4868-99A7-D32F9047DAA6}
[2011/04/17 11:18:49 | 000,000,000 | ---D | C] -- C:\Users\Kristen\AppData\Local\{FF1E239F-D0AD-4070-8F0B-F0BFDBED9E54}
[2011/04/16 11:48:12 | 000,000,000 | ---D | C] -- C:\Users\Kristen\AppData\Local\{A038802B-138A-4533-B157-4F2D8A084C88}
[2011/04/15 20:42:30 | 000,000,000 | ---D | C] -- C:\Users\Kristen\AppData\Local\{FE2232FD-2ADA-4181-B27C-660D3B02CA4A}
[2011/04/15 20:38:37 | 000,000,000 | ---D | C] -- C:\Users\Kristen\AppData\Local\{78361B1E-E27A-487B-AA6F-2D836FA43C7A}
[2011/04/15 16:54:10 | 000,000,000 | ---D | C] -- C:\Users\Kristen\AppData\Local\{5DE978FE-66FC-4180-98AA-40FA00D2DF79}
[2011/04/15 15:03:45 | 000,000,000 | ---D | C] -- C:\Users\Kristen\AppData\Local\{2089FAE0-C99D-41DB-8833-E9CBD7C9432C}
[2011/04/15 11:20:25 | 000,000,000 | ---D | C] -- C:\Users\Kristen\AppData\Local\{7E316640-8D06-4C9C-AB5E-A5593153A852}
[2011/04/14 17:27:22 | 000,000,000 | ---D | C] -- C:\Users\Kristen\AppData\Local\{DEDBFE91-1547-4E61-BA88-2F5E0E8F2D1F}
[2011/04/14 10:39:45 | 000,000,000 | ---D | C] -- C:\Users\Kristen\AppData\Local\{2CB06E14-DB91-415B-BBFC-B62D20D42FEC}
[2011/04/13 18:07:23 | 000,000,000 | ---D | C] -- C:\Users\Kristen\AppData\Local\{D1D61518-7945-4BBE-A2BA-0F9D6D97EE13}
[2011/04/12 10:21:15 | 000,000,000 | ---D | C] -- C:\Users\Kristen\AppData\Local\{1F741E9D-BCCC-4419-9AB6-5FAFF04DDAD0}
[2011/04/12 09:28:37 | 000,000,000 | ---D | C] -- C:\Users\Kristen\AppData\Local\{88AF8CBF-B588-4B68-83D1-6A2B2F1C1EFB}
[2011/04/11 08:20:12 | 000,000,000 | ---D | C] -- C:\Users\Kristen\AppData\Local\{AC30813B-B8F9-4A6E-9E1D-F11639DE238A}
[2011/04/10 09:24:03 | 000,000,000 | ---D | C] -- C:\Users\Kristen\AppData\Local\{FC9D5D99-4C07-4BCA-89D9-E46F13CE4019}
[2011/04/09 09:19:44 | 000,000,000 | ---D | C] -- C:\Users\Kristen\AppData\Local\{6A09E996-D07D-42FD-A76A-F7D018A8517C}
[2011/04/08 08:55:54 | 000,000,000 | ---D | C] -- C:\Users\Kristen\AppData\Local\{12552A31-AA60-41D7-931A-F57424D87B4C}
[2011/04/07 12:17:15 | 000,000,000 | ---D | C] -- C:\Users\Kristen\AppData\Roaming\DVDVideoSoft
[2011/04/07 09:35:48 | 000,000,000 | ---D | C] -- C:\Users\Kristen\AppData\Local\{1E10E506-9314-40E4-BF0B-B2F6E38F40B3}
[2011/04/06 08:06:05 | 000,000,000 | ---D | C] -- C:\Users\Kristen\AppData\Local\{5ACB0938-1DED-4793-978A-D55E07F23637}
[2011/04/05 16:13:40 | 000,000,000 | ---D | C] -- C:\Users\Kristen\AppData\Local\{146760D9-0E0B-49AF-8230-64AB89252756}
[2011/04/05 06:39:08 | 000,000,000 | ---D | C] -- C:\Users\Kristen\AppData\Local\{FE7C8B5F-DCD3-4EB9-B804-2FEAE86F598B}
[2011/04/04 18:42:56 | 000,000,000 | ---D | C] -- C:\Users\Kristen\AppData\Roaming\Windows Live Writer
[2011/04/04 18:42:56 | 000,000,000 | ---D | C] -- C:\Users\Kristen\AppData\Local\Windows Live Writer
[2011/04/04 17:38:33 | 000,000,000 | ---D | C] -- C:\Users\Kristen\AppData\Local\{6E14C585-CAFE-4963-AED3-DD4FD3EF0A91}
[2011/04/04 17:37:08 | 000,000,000 | ---D | C] -- C:\windows\en
[2011/04/04 17:34:33 | 000,000,000 | R--D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Live
[2011/04/04 17:33:27 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft SQL Server Compact Edition
[2011/04/04 16:34:25 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft
[2011/03/29 20:34:11 | 000,000,000 | ---D | C] -- C:\bc0d563d27c038cb3fc2eaa579
[2011/03/29 20:34:01 | 000,000,000 | ---D | C] -- C:\1953de4a71e910cb982a
[2010/02/21 01:35:04 | 000,004,096 | ---- | C] ( ) -- C:\windows\System32\IGFXDEVLib.dll

========== Files - Modified Within 30 Days ==========

[2011/04/19 17:12:23 | 000,016,304 | -H-- | M] () -- C:\windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2011/04/19 17:12:23 | 000,016,304 | -H-- | M] () -- C:\windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2011/04/19 17:05:06 | 000,067,584 | --S- | M] () -- C:\windows\bootstat.dat
[2011/04/19 17:05:02 | 1506,779,136 | -HS- | M] () -- C:\hiberfil.sys
[2011/04/19 16:49:35 | 000,000,000 | ---- | M] () -- C:\windows\System32\cd.dat
[2011/04/19 16:49:20 | 276,565,340 | ---- | M] () -- C:\windows\MEMORY.DMP
[2011/04/19 16:36:13 | 000,000,027 | ---- | M] () -- C:\windows\System32\drivers\etc\hosts
[2011/04/19 16:20:30 | 000,717,520 | ---- | M] () -- C:\windows\System32\perfh009.dat
[2011/04/19 16:20:30 | 000,143,214 | ---- | M] () -- C:\windows\System32\perfc009.dat
[2011/04/19 14:39:27 | 000,001,255 | ---- | M] () -- C:\Users\Kristen\Application Data\Microsoft\Internet Explorer\Quick Launch\Spybot - Search & Destroy.lnk
[2011/04/19 14:39:27 | 000,001,231 | ---- | M] () -- C:\Users\Kristen\Desktop\Spybot - Search & Destroy.lnk
[2011/04/18 22:10:38 | 000,000,192 | ---- | M] () -- C:\ProgramData\~36626184
[2011/04/18 22:10:38 | 000,000,160 | ---- | M] () -- C:\ProgramData\~36626184r
[2011/04/18 22:10:34 | 000,000,336 | ---- | M] () -- C:\ProgramData\36626184
[2011/04/18 09:40:27 | 004,433,103 | ---- | M] () -- C:\Users\Kristen\Documents\20 Track 20.mp3
[2011/04/17 20:23:02 | 000,001,456 | ---- | M] () -- C:\Users\Kristen\AppData\Local\Adobe Save for Web 12.0 Prefs
[2011/04/17 10:41:00 | 003,765,888 | ---- | M] () -- C:\windows\System32\FNTCACHE.DAT
[2011/04/10 12:49:05 | 000,003,879 | ---- | M] () -- C:\Users\Kristen\AppData\Roaming\9668.C4D
[2011/04/10 12:16:24 | 000,000,120 | ---- | M] () -- C:\Users\Kristen\AppData\Local\Mvaseqacola.dat
[2011/04/10 12:16:24 | 000,000,000 | ---- | M] () -- C:\Users\Kristen\AppData\Local\Oreni.bin
[2011/04/07 12:17:57 | 000,001,212 | ---- | M] () -- C:\Users\Kristen\Desktop\DVDVideoSoft Free Studio.lnk
[2011/04/04 16:54:13 | 000,000,020 | ---- | M] () -- C:\windows\pó_
[2011/03/30 16:54:06 | 000,000,132 | ---- | M] () -- C:\Users\Kristen\AppData\Roaming\Adobe IllExport Filter CS5 Prefs
[2011/03/29 15:28:39 | 000,020,307 | ---- | M] () -- C:\Users\Kristen\Documents\300_mormon.jpg

========== Files Created - No Company Name ==========

[2011/04/19 16:49:35 | 000,000,000 | ---- | C] () -- C:\windows\System32\cd.dat
[2011/04/19 16:28:22 | 000,256,512 | ---- | C] () -- C:\windows\PEV.exe
[2011/04/19 16:28:22 | 000,098,816 | ---- | C] () -- C:\windows\sed.exe
[2011/04/19 16:28:22 | 000,089,088 | ---- | C] () -- C:\windows\MBR.exe
[2011/04/19 16:28:22 | 000,080,412 | ---- | C] () -- C:\windows\grep.exe
[2011/04/19 16:28:22 | 000,068,096 | ---- | C] () -- C:\windows\zip.exe
[2011/04/19 14:39:27 | 000,001,255 | ---- | C] () -- C:\Users\Kristen\Application Data\Microsoft\Internet Explorer\Quick Launch\Spybot - Search & Destroy.lnk
[2011/04/19 14:39:27 | 000,001,231 | ---- | C] () -- C:\Users\Kristen\Desktop\Spybot - Search & Destroy.lnk
[2011/04/18 22:10:38 | 000,000,192 | ---- | C] () -- C:\ProgramData\~36626184
[2011/04/18 22:10:38 | 000,000,160 | ---- | C] () -- C:\ProgramData\~36626184r
[2011/04/18 22:10:34 | 000,000,336 | ---- | C] () -- C:\ProgramData\36626184
[2011/04/18 09:36:24 | 004,433,103 | ---- | C] () -- C:\Users\Kristen\Documents\20 Track 20.mp3
[2011/04/10 12:16:24 | 000,000,120 | ---- | C] () -- C:\Users\Kristen\AppData\Local\Mvaseqacola.dat
[2011/04/10 12:16:24 | 000,000,000 | ---- | C] () -- C:\Users\Kristen\AppData\Local\Oreni.bin
[2011/04/10 12:03:16 | 000,003,879 | ---- | C] () -- C:\Users\Kristen\AppData\Roaming\9668.C4D
[2011/04/04 17:34:21 | 000,001,262 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Live Movie Maker.lnk
[2011/04/04 17:33:49 | 000,001,331 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Live Photo Gallery.lnk
[2011/04/04 17:33:13 | 000,001,415 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Live Mail.lnk
[2011/04/04 17:32:58 | 000,002,443 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Live Messenger.lnk
[2011/04/04 16:54:12 | 000,000,020 | ---- | C] () -- C:\windows\pó_
[2011/03/30 16:54:06 | 000,000,132 | ---- | C] () -- C:\Users\Kristen\AppData\Roaming\Adobe IllExport Filter CS5 Prefs
[2011/03/29 15:28:37 | 000,020,307 | ---- | C] () -- C:\Users\Kristen\Documents\300_mormon.jpg
[2011/01/08 11:11:19 | 000,000,132 | ---- | C] () -- C:\Users\Kristen\AppData\Roaming\Adobe GIF Format CS5 Prefs
[2011/01/02 20:10:13 | 000,000,132 | ---- | C] () -- C:\Users\Kristen\AppData\Roaming\Adobe PNG Format CS5 Prefs
[2010/12/31 20:28:45 | 000,001,456 | ---- | C] () -- C:\Users\Kristen\AppData\Local\Adobe Save for Web 12.0 Prefs
[2010/10/15 15:32:49 | 000,000,056 | ---- | C] () -- C:\ProgramData\ezsidmv.dat
[2010/10/08 14:57:02 | 000,000,857 | ---- | C] () -- C:\Program Files\Downloads.lnk
[2010/06/02 02:21:20 | 000,000,000 | ---- | C] () -- C:\windows\NDSTray.INI
[2010/02/21 02:16:08 | 000,439,308 | ---- | C] () -- C:\windows\System32\igcompkrng500.bin
[2010/02/21 02:16:06 | 000,982,240 | ---- | C] () -- C:\windows\System32\igkrng500.bin
[2010/02/21 02:16:06 | 000,092,356 | ---- | C] () -- C:\windows\System32\igfcg500m.bin
[2010/02/21 01:32:46 | 000,000,151 | ---- | C] () -- C:\windows\System32\GfxUI.exe.config
[2010/02/21 01:27:36 | 000,208,896 | ---- | C] () -- C:\windows\System32\iglhsip32.dll
[2010/02/21 01:27:36 | 000,143,360 | ---- | C] () -- C:\windows\System32\iglhcp32.dll
[2009/07/14 14:57:37 | 000,067,584 | --S- | C] () -- C:\windows\bootstat.dat
[2009/07/14 14:33:53 | 003,765,888 | ---- | C] () -- C:\windows\System32\FNTCACHE.DAT
[2009/07/14 12:05:48 | 000,717,520 | ---- | C] () -- C:\windows\System32\perfh009.dat
[2009/07/14 12:05:48 | 000,291,294 | ---- | C] () -- C:\windows\System32\perfi009.dat
[2009/07/14 12:05:48 | 000,143,214 | ---- | C] () -- C:\windows\System32\perfc009.dat
[2009/07/14 12:05:48 | 000,031,548 | ---- | C] () -- C:\windows\System32\perfd009.dat
[2009/07/14 12:05:05 | 000,000,741 | ---- | C] () -- C:\windows\System32\NOISE.DAT
[2009/07/14 12:04:11 | 000,215,943 | ---- | C] () -- C:\windows\System32\dssec.dat
[2009/07/14 09:55:01 | 000,043,131 | ---- | C] () -- C:\windows\mib.bin
[2009/07/14 09:51:43 | 000,073,728 | ---- | C] () -- C:\windows\System32\BthpanContextHandler.dll
[2009/07/14 09:42:10 | 000,064,000 | ---- | C] () -- C:\windows\System32\BWContextHandler.dll
[2009/07/14 08:09:19 | 000,139,824 | ---- | C] () -- C:\windows\System32\igfcg500.bin
[2009/06/11 07:26:10 | 000,673,088 | ---- | C] () -- C:\windows\System32\mlang.dat

========== LOP Check ==========

[2011/03/04 20:02:20 | 000,000,000 | ---D | M] -- C:\Users\Kristen\AppData\Roaming\Dropbox
[2011/04/07 12:17:39 | 000,000,000 | ---D | M] -- C:\Users\Kristen\AppData\Roaming\DVDVideoSoft
[2011/04/07 12:18:00 | 000,000,000 | ---D | M] -- C:\Users\Kristen\AppData\Roaming\DVDVideoSoftIEHelpers
[2010/11/08 15:34:51 | 000,000,000 | ---D | M] -- C:\Users\Kristen\AppData\Roaming\Jasc
[2011/03/14 16:23:21 | 000,000,000 | ---D | M] -- C:\Users\Kristen\AppData\Roaming\NCH Swift Sound
[2010/12/30 09:45:15 | 000,000,000 | ---D | M] -- C:\Users\Kristen\AppData\Roaming\StageManager.BD092818F67280F4B42B04877600987F0111B594.1
[2010/10/08 15:30:52 | 000,000,000 | ---D | M] -- C:\Users\Kristen\AppData\Roaming\Tific
[2010/10/08 15:11:55 | 000,000,000 | ---D | M] -- C:\Users\Kristen\AppData\Roaming\Toshiba
[2011/04/19 16:26:20 | 000,000,000 | ---D | M] -- C:\Users\Kristen\AppData\Roaming\uTorrent
[2011/04/17 11:20:44 | 000,000,000 | ---D | M] -- C:\Users\Kristen\AppData\Roaming\Windows Live Writer
[2011/04/19 16:49:34 | 000,032,612 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT

========== Purity Check ==========



< End of report >
  • 0

Advertisements


#2
RKinner

RKinner

    Malware Expert

  • Expert
  • 24,598 posts
  • MVP
Disable Spybot's TeaTimer to make sure it won't interfere with fixes. You can re-enable it when you're clean again:

* Run Spybot-S&D in Advanced Mode
* If it is not already set to do this, go to the Mode menu
select
Advanced Mode
* On the left hand side, click on Tools
* Then click on the Resident icon in the list
* Uncheck
Resident TeaTimer
and OK any prompts.
* Restart your computer


Copy the text in the code box by highlighting and Ctrl + c



:OTL
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = http=127.0.0.1:55414
FF - prefs.js..network.proxy.http: "127.0.0.1"
FF - prefs.js..network.proxy.http_port: 55414
[2011/03/27 08:33:03 | 000,000,000 | ---D | M] (Conduit Engine) -- C:\Users\Kristen\AppData\Roaming\Mozilla\Firefox\Profiles\4phcayjv.default\extensions\[email protected]
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_17)
O16 - DPF: {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_17)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_17)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.ad...Plus/1.6/gp.cab (Reg Error: Key error.)
O28 - HKLM ShellExecuteHooks: {AEB6717E-7E19-11d0-97EE-00C04FD91972} - Reg Error: Key error. File not found
[2011/04/19 14:24:53 | 000,000,000 | ---D | C] -- C:\Users\Kristen\AppData\Local\{B5775D39-EEAC-4CAB-810F-6F7B8FB47466}
[2011/04/19 14:18:39 | 000,000,000 | ---D | C] -- C:\Users\Kristen\AppData\Local\{F0BD2BCC-8D13-4AF8-862C-F501978F30C7}
[2011/04/19 14:18:26 | 000,000,000 | ---D | C] -- C:\Users\Kristen\AppData\Local\{D94FB190-7E7D-46ED-A401-D9058918D1EA}
[2011/04/19 14:02:27 | 000,000,000 | ---D | C] -- C:\Users\Kristen\AppData\Local\{0F44CE73-E2AA-49AB-B8B1-C4420B4B821B}
[2011/04/18 22:17:19 | 000,000,000 | ---D | C] -- C:\Program Files\GridinSoft Trojan Killer
[2011/04/18 22:10:36 | 000,000,000 | ---D | C] -- C:\Users\Kristen\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows Recovery
[2011/04/18 14:35:31 | 000,000,000 | ---D | C] -- C:\Users\Kristen\AppData\Local\{86ACD97C-E277-4868-99A7-D32F9047DAA6}
[2011/04/17 11:18:49 | 000,000,000 | ---D | C] -- C:\Users\Kristen\AppData\Local\{FF1E239F-D0AD-4070-8F0B-F0BFDBED9E54}
[2011/04/16 11:48:12 | 000,000,000 | ---D | C] -- C:\Users\Kristen\AppData\Local\{A038802B-138A-4533-B157-4F2D8A084C88}
[2011/04/15 20:42:30 | 000,000,000 | ---D | C] -- C:\Users\Kristen\AppData\Local\{FE2232FD-2ADA-4181-B27C-660D3B02CA4A}
[2011/04/15 20:38:37 | 000,000,000 | ---D | C] -- C:\Users\Kristen\AppData\Local\{78361B1E-E27A-487B-AA6F-2D836FA43C7A}
[2011/04/15 16:54:10 | 000,000,000 | ---D | C] -- C:\Users\Kristen\AppData\Local\{5DE978FE-66FC-4180-98AA-40FA00D2DF79}
[2011/04/15 15:03:45 | 000,000,000 | ---D | C] -- C:\Users\Kristen\AppData\Local\{2089FAE0-C99D-41DB-8833-E9CBD7C9432C}
[2011/04/15 11:20:25 | 000,000,000 | ---D | C] -- C:\Users\Kristen\AppData\Local\{7E316640-8D06-4C9C-AB5E-A5593153A852}
[2011/04/14 17:27:22 | 000,000,000 | ---D | C] -- C:\Users\Kristen\AppData\Local\{DEDBFE91-1547-4E61-BA88-2F5E0E8F2D1F}
[2011/04/14 10:39:45 | 000,000,000 | ---D | C] -- C:\Users\Kristen\AppData\Local\{2CB06E14-DB91-415B-BBFC-B62D20D42FEC}
[2011/04/13 18:07:23 | 000,000,000 | ---D | C] -- C:\Users\Kristen\AppData\Local\{D1D61518-7945-4BBE-A2BA-0F9D6D97EE13}
[2011/04/12 10:21:15 | 000,000,000 | ---D | C] -- C:\Users\Kristen\AppData\Local\{1F741E9D-BCCC-4419-9AB6-5FAFF04DDAD0}
[2011/04/12 09:28:37 | 000,000,000 | ---D | C] -- C:\Users\Kristen\AppData\Local\{88AF8CBF-B588-4B68-83D1-6A2B2F1C1EFB}
[2011/04/11 08:20:12 | 000,000,000 | ---D | C] -- C:\Users\Kristen\AppData\Local\{AC30813B-B8F9-4A6E-9E1D-F11639DE238A}
[2011/04/10 09:24:03 | 000,000,000 | ---D | C] -- C:\Users\Kristen\AppData\Local\{FC9D5D99-4C07-4BCA-89D9-E46F13CE4019}
[2011/04/09 09:19:44 | 000,000,000 | ---D | C] -- C:\Users\Kristen\AppData\Local\{6A09E996-D07D-42FD-A76A-F7D018A8517C}
[2011/04/08 08:55:54 | 000,000,000 | ---D | C] -- C:\Users\Kristen\AppData\Local\{12552A31-AA60-41D7-931A-F57424D87B4C}
[2011/04/07 09:35:48 | 000,000,000 | ---D | C] -- C:\Users\Kristen\AppData\Local\{1E10E506-9314-40E4-BF0B-B2F6E38F40B3}
[2011/04/06 08:06:05 | 000,000,000 | ---D | C] -- C:\Users\Kristen\AppData\Local\{5ACB0938-1DED-4793-978A-D55E07F23637}
[2011/04/05 16:13:40 | 000,000,000 | ---D | C] -- C:\Users\Kristen\AppData\Local\{146760D9-0E0B-49AF-8230-64AB89252756}
[2011/04/05 06:39:08 | 000,000,000 | ---D | C] -- C:\Users\Kristen\AppData\Local\{FE7C8B5F-DCD3-4EB9-B804-2FEAE86F598B}
[2011/04/04 17:38:33 | 000,000,000 | ---D | C] -- C:\Users\Kristen\AppData\Local\{6E14C585-CAFE-4963-AED3-DD4FD3EF0A91}
[2011/04/18 22:10:38 | 000,000,192 | ---- | M] () -- C:\ProgramData\~36626184
[2011/04/18 22:10:38 | 000,000,160 | ---- | M] () -- C:\ProgramData\~36626184r
[2011/04/18 22:10:34 | 000,000,336 | ---- | M] () -- C:\ProgramData\36626184
[2011/04/10 12:49:05 | 000,003,879 | ---- | M] () -- C:\Users\Kristen\AppData\Roaming\9668.C4D
[2011/04/10 12:16:24 | 000,000,120 | ---- | M] () -- C:\Users\Kristen\AppData\Local\Mvaseqacola.dat
[2011/04/10 12:16:24 | 000,000,000 | ---- | M] () -- C:\Users\Kristen\AppData\Local\Oreni.bin
[2011/04/04 16:54:13 | 000,000,020 | ---- | M] () -- C:\windows\pó_


:Commands
[RESETHOSTS]
[purity]
[emptytemp]
[Reboot]

then run OTL by Right clicking and Run As Administrator and Under the Custom Scans/Fixes box at the bottom, paste (ctrl +v) the text. Verify that you got it all and Then click the Run Fix button at the top
Let the program run unhindered, OTL will reboot the PC when it is done. Save the log and copy and paste it to a reply.

Open OTL by Right clicking and Run As Administrator again and select the All option in the Extra Registry group then the Run Scan button. Post the two logs it produces in your next reply.

Malwarebytes' Anti-Malware
:!: If you have a previous version of MalwareBytes', remove it via Add or Remove Programs and download a fresh copy. :!:

http://www.malwarebytes.org/mbam.php

SAVE Malwarebytes' Anti-Malware to your desktop.

* Right-click mbam-setup.exe and Run As Administrator and follow the prompts to install the program.
* At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
* If an update is found, it will download and install the latest version.
* Once the program has loaded, select Perform full scan, then click Scan.
* When the scan is complete, click OK, then Show Results to view the results.

* Be sure that everything is checked, and click Remove Selected.

* When completed, a log will open in Notepad. Please save it to a convenient location.
* The log can also be found here:
C:\Documents and Settings\Username\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\Logs\mbam-log-date (time).txt
* Post that log back here.



ComboFix
:!: If you have a previous version of Combofix.exe, delete it and download a fresh copy. :!:

:!: It must be saved to your desktop, do not run it :!:

:!: Disable your Antivirus software when downloading or running Combofix. If it has Script Blocking features, please disable these as well. See: http://www.bleepingc...opic114351.html


Download and Rename this file -- (call it george.exe ) to your Desktop -- from either of these two sources:
http://download.blee...Bs/ComboFix.exe
http://subs.geekstogo.com/ComboFix.exe

Right click on george Run As Administrator to start the program.



* :!: Important: Have no other programs running. Your Task Bar should be clear of any program entries including your Browser.


* A window may open with a series of Disclaimers. Accept the Disclaimers to start the fix. Allow it to install the Recovery Console then Continue. When the scan completes Notepad will open with with your results log open. Do a File, Exit and answer 'Yes' to save changes.


A caution - Do not run Combofix more than once. Do not touch your mouse/keyboard until the scan has completed, as this may cause the process to stall or your computer to lock. The scan will temporarily disable your desktop, and if interrupted may leave your desktop disabled. If this occurs, please reboot to restore the desktop. Even when ComboFix appears to be doing nothing, look at your Drive light. If it is flashing, Combofix is still at work.

A file will be created at => C:\Combofix.txt. I'll need to see that in your reply.

Download TDSSKiller:
http://support.kaspe.../tdsskiller.exe
Save it to your desktop then right click and Run as Administrator

If TDSSKiller alerts you that the system needs to reboot, please consent.
When done, a log file should be created on your C: drive named "TDSSKiller.txt" please copy and paste the contents in your next reply.

Download

http://ad13.geekstogo.com/MBRCheck.exe

Save it and run it by Right clicking and Run As Administrator. It will produce a log MBRCheck(date).txt on your desktop. Copy and paste it into a reply.

I don't think your hotspot shield is an anti-virus.

Install the free Avast:

http://www.avast.com...ivirus-download

Save it and run it by by Right clicking and Run As Administrator

Once you have it installed and it has updated:
Click on the Avast ball. Then click on Scan Computer, then on
Boot-Time Scan then on Settings. Change the Ask at the bottom to Move to Chest. OK then Schedule Now. Reboot and let it run a scan. It may take hours.
Once it finishes it should load windows. Click on the Avast ball and then on Scan Logs, select the Boot-time scan report then View Results. How many did it find?

How is your PC now?

Ron
  • 0

#3
Laura Rod

Laura Rod

    New Member

  • Topic Starter
  • Member
  • Pip
  • 6 posts
After installing TDSSKiller, whenever I attempted to open the program, nothing would happen. It didn't appear to be open on my task manager either. However, I attached the rest of the logs. Upon running Avast, it found one virus that was apparently in a WMA file. Google is still redirecting me and the audios are still happening. I apologize for this difficulty, but I really appreciate your help.

Attached Files


  • 0

#4
RKinner

RKinner

    Malware Expert

  • Expert
  • 24,598 posts
  • MVP
please do not attach your logs. It makes them too hard to read, Copy and Paste them.


Can you delete these folders?

C:\Users\Kristen\AppData\Local\{D04EE98D-473C-4ABA-9A56-99B82BAD870C}
C:\Users\Kristen\AppData\Local\{EF0C895D-47BC-4AD4-9C27-240611DB1224}
C:\Users\Kristen\AppData\Local\{D2A60139-4A1F-42DE-8A11-154E0A64D59D}
C:\Users\Kristen\AppData\Local\{A9B40FD4-8712-44F8-9644-CF66F34871E3}

You may have some new folders in
C:\Users\Kristen\AppData\Local
That have the same format. Delete them too.

We really need tdsskiller for this. Try it again now that Avast has removed a virus. Make sure you right click and run as administrator.

If that won't work then: Try booting into Safe Mode with Networking
http://www.computerh...sues/chsafe.htm
and redownload and run tdsskiller. Right click on it and Run As Administrator (if the option is available in Safe Mode) otherwise just run it.

Ron
  • 0

#5
Laura Rod

Laura Rod

    New Member

  • Topic Starter
  • Member
  • Pip
  • 6 posts
My apologizes. I will copy and paste them next time.

I tried what you said and still no luck with opening tdsskiller.
  • 0

#6
RKinner

RKinner

    Malware Expert

  • Expert
  • 24,598 posts
  • MVP
Run OTL, Quick Scan and copy and paste the log. Let me see how it looks now.

Ron
  • 0

#7
Laura Rod

Laura Rod

    New Member

  • Topic Starter
  • Member
  • Pip
  • 6 posts
OTL logfile created on: 5/2/2011 8:20:34 PM - Run 3
OTL by OldTimer - Version 3.2.22.3 Folder = C:\Users\Kristen\Downloads
Home Premium Edition (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7600.16385)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

2.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 48.00% Memory free
4.00 Gb Paging File | 3.00 Gb Available in Paging File | 70.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\windows | %ProgramFiles% = C:\Program Files
Drive C: | 221.15 Gb Total Space | 111.01 Gb Free Space | 50.20% Space Free | Partition Type: NTFS

Computer Name: KRISTEN-PC | User Name: Kristen | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - [2011/04/19 17:15:55 | 000,580,608 | ---- | M] (OldTimer Tools) -- C:\Users\Kristen\Downloads\OTL.exe
PRC - [2011/02/26 15:33:07 | 002,614,784 | ---- | M] (Microsoft Corporation) -- C:\Windows\explorer.exe
PRC - [2011/02/25 10:46:22 | 000,249,648 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Microsoft\BingBar\SeaPort.EXE
PRC - [2011/02/17 06:21:58 | 002,190,688 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG10\avgtray.exe
PRC - [2011/02/15 05:38:06 | 007,421,280 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSAgent.exe
PRC - [2011/02/11 06:25:52 | 001,080,672 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG10\avgnsx.exe
PRC - [2011/02/10 07:55:18 | 001,148,256 | ---- | M] () -- C:\Program Files\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSMonitor.exe
PRC - [2011/02/08 05:33:42 | 000,269,520 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG10\avgwdsvc.exe
PRC - [2011/02/08 05:33:20 | 000,658,784 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG10\avgrsx.exe
PRC - [2011/02/08 05:32:48 | 000,351,072 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG10\avgcsrvx.exe
PRC - [2011/02/08 05:32:46 | 000,656,736 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG10\avgchsvx.exe
PRC - [2010/06/27 02:09:18 | 000,167,936 | ---- | M] (Applian Technologies, Inc.) -- C:\Program Files\Freecorder\FLVSrvc.exe
PRC - [2010/03/11 08:44:56 | 000,496,184 | ---- | M] (Conexant Systems, Inc.) -- C:\Program Files\CONEXANT\cAudioFilterAgent\cAudioFilterAgent.exe
PRC - [2010/02/24 18:54:48 | 002,454,840 | ---- | M] (TOSHIBA CORPORATION.) -- C:\Program Files\TOSHIBA\TOSHIBA Web Camera Application\TWebCamera.exe
PRC - [2010/02/23 06:23:50 | 000,304,496 | ---- | M] (TOSHIBA CORPORATION) -- C:\Program Files\TOSHIBA\ConfigFree\NDSTray.exe
PRC - [2010/02/06 10:41:00 | 000,111,960 | ---- | M] (TOSHIBA Corporation) -- C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSmartSrv.exe
PRC - [2010/02/06 10:40:44 | 001,021,272 | ---- | M] (TOSHIBA Corporation) -- C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSENotify.exe
PRC - [2010/01/29 09:44:24 | 000,185,712 | ---- | M] (TOSHIBA CORPORATION) -- C:\Program Files\TOSHIBA\ConfigFree\CFIWmxSvcs.exe
PRC - [2009/11/06 15:04:20 | 000,468,320 | ---- | M] (TOSHIBA Corporation) -- C:\Program Files\TOSHIBA\Power Saver\TosCoSrv.exe
PRC - [2009/10/07 02:23:12 | 001,294,136 | ---- | M] (TOSHIBA Corporation) -- C:\Program Files\TOSHIBA\TOSHIBA Service Station\ToshibaServiceStation.exe
PRC - [2009/10/07 02:21:50 | 000,051,512 | ---- | M] (TOSHIBA Corporation) -- C:\Program Files\TOSHIBA\TOSHIBA Service Station\TMachInfo.exe
PRC - [2009/09/30 16:59:26 | 000,049,152 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\taskhost.exe
PRC - [2009/07/29 13:26:42 | 000,062,848 | ---- | M] (TOSHIBA CORPORATION) -- C:\Program Files\TOSHIBA\ConfigFree\CFSwMgr.exe
PRC - [2009/07/29 08:43:04 | 000,128,344 | ---- | M] (TOSHIBA Corporation) -- C:\Windows\System32\TODDSrv.exe
PRC - [2009/07/14 11:14:15 | 000,271,360 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\conhost.exe
PRC - [2009/03/11 11:51:20 | 000,046,448 | ---- | M] (TOSHIBA CORPORATION) -- C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
PRC - [2009/02/21 02:46:52 | 000,030,312 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Microsoft Small Business\Business Contact Manager\BcmSqlStartupSvc.exe


========== Modules (SafeList) ==========

MOD - [2011/04/19 17:15:55 | 000,580,608 | ---- | M] (OldTimer Tools) -- C:\Users\Kristen\Downloads\OTL.exe
MOD - [2010/08/21 15:21:32 | 001,680,896 | ---- | M] (Microsoft Corporation) -- C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7600.16661_none_420fe3fa2b8113bd\comctl32.dll


========== Win32 Services (SafeList) ==========

SRV - [2011/04/29 15:36:07 | 003,229,784 | ---- | M] () [Auto | Running] -- c:\Program Files\Common Files\Akamai\netsession_win_a35e6b9.dll -- (Akamai)
SRV - [2011/02/28 18:44:14 | 000,183,560 | ---- | M] (Microsoft Corporation.) [On_Demand | Stopped] -- C:\Program Files\Microsoft\BingBar\BBSvc.EXE -- (BBSvc)
SRV - [2011/02/25 10:46:22 | 000,249,648 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files\Microsoft\BingBar\SeaPort.EXE -- (SeaPort)
SRV - [2011/02/15 05:38:06 | 007,421,280 | ---- | M] (AVG Technologies CZ, s.r.o.) [Auto | Running] -- C:\Program Files\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSAgent.exe -- (AVGIDSAgent)
SRV - [2011/02/08 05:33:42 | 000,269,520 | ---- | M] (AVG Technologies CZ, s.r.o.) [Auto | Running] -- C:\Program Files\AVG\AVG10\avgwdsvc.exe -- (avgwd)
SRV - [2010/10/10 08:19:37 | 001,343,400 | ---- | M] (Microsoft Corporation) [Unknown | Stopped] -- C:\Windows\System32\Wat\WatAdminSvc.exe -- (WatAdminSvc)
SRV - [2010/02/19 12:37:14 | 000,517,096 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe -- (SwitchBoard)
SRV - [2010/02/06 10:41:00 | 000,111,960 | ---- | M] (TOSHIBA Corporation) [On_Demand | Running] -- C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSmartSrv.exe -- (TOSHIBA HDD SSD Alert Service)
SRV - [2010/01/29 09:44:24 | 000,185,712 | ---- | M] (TOSHIBA CORPORATION) [Auto | Running] -- C:\Program Files\TOSHIBA\ConfigFree\CFIWmxSvcs.exe -- (cfWiMAXService)
SRV - [2009/12/04 12:30:18 | 000,238,328 | ---- | M] (WildTangent, Inc.) [On_Demand | Stopped] -- C:\Program Files\TOSHIBA Games\TOSHIBA Game Console\GameConsoleService.exe -- (GameConsoleService)
SRV - [2009/11/06 15:04:20 | 000,468,320 | ---- | M] (TOSHIBA Corporation) [Auto | Running] -- C:\Program Files\TOSHIBA\Power Saver\TosCoSrv.exe -- (TosCoSrv)
SRV - [2009/10/07 02:21:50 | 000,051,512 | ---- | M] (TOSHIBA Corporation) [On_Demand | Running] -- C:\Program Files\TOSHIBA\TOSHIBA Service Station\TMachInfo.exe -- (TMachInfo)
SRV - [2009/07/29 08:43:04 | 000,128,344 | ---- | M] (TOSHIBA Corporation) [Auto | Running] -- C:\Windows\System32\TODDSrv.exe -- (TODDSrv)
SRV - [2009/07/14 11:16:13 | 000,025,088 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\sensrsvc.dll -- (SensrSvc)
SRV - [2009/03/11 11:51:20 | 000,046,448 | ---- | M] (TOSHIBA CORPORATION) [Auto | Running] -- C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe -- (ConfigFree Service)
SRV - [2009/02/21 02:46:52 | 000,030,312 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files\Microsoft Small Business\Business Contact Manager\BcmSqlStartupSvc.exe -- (BcmSqlStartupSvc)


========== Driver Services (SafeList) ==========

DRV - [2011/03/30 17:17:06 | 000,134,480 | ---- | M] (AVG Technologies CZ, s.r.o. ) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\AVGIDSDriver.sys -- (AVGIDSDriver)
DRV - [2011/03/01 14:25:18 | 000,034,896 | ---- | M] (AVG Technologies CZ, s.r.o.) [File_System | System | Running] -- C:\Windows\System32\drivers\avgmfx86.sys -- (Avgmfx86)
DRV - [2011/02/22 08:12:50 | 000,022,992 | ---- | M] (AVG Technologies CZ, s.r.o. ) [Kernel | Boot | Running] -- C:\windows\system32\DRIVERS\AVGIDSEH.Sys -- (AVGIDSEH)
DRV - [2011/02/10 07:54:00 | 000,296,400 | ---- | M] (AVG Technologies CZ, s.r.o.) [Kernel | System | Running] -- C:\Windows\System32\drivers\avgtdix.sys -- (Avgtdix)
DRV - [2011/02/10 07:53:42 | 000,021,968 | ---- | M] (AVG Technologies CZ, s.r.o. ) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\AVGIDSShim.sys -- (AVGIDSShim)
DRV - [2011/02/10 07:53:40 | 000,024,144 | ---- | M] (AVG Technologies CZ, s.r.o. ) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\AVGIDSFilter.sys -- (AVGIDSFilter)
DRV - [2011/01/19 04:32:56 | 000,032,464 | ---- | M] (AVG Technologies CZ, s.r.o.) [File_System | Boot | Running] -- C:\windows\system32\DRIVERS\avgrkx86.sys -- (Avgrkx86)
DRV - [2011/01/07 06:41:46 | 000,248,656 | ---- | M] (AVG Technologies CZ, s.r.o.) [Kernel | System | Running] -- C:\Windows\System32\drivers\avgldx86.sys -- (Avgldx86)
DRV - [2010/09/23 05:19:02 | 000,032,768 | ---- | M] (AnchorFree Inc) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\taphss.sys -- (taphss)
DRV - [2010/03/05 10:53:06 | 000,067,624 | ---- | M] (Atheros Communications, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\L1C62x86.sys -- (L1C)
DRV - [2010/02/02 03:29:46 | 000,182,304 | ---- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\RtsUStor.sys -- (RSUSBSTOR)
DRV - [2010/01/19 10:45:00 | 000,514,104 | ---- | M] (Conexant Systems Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\CHDRT32.sys -- (CnxtHdAudService)
DRV - [2009/11/07 05:53:58 | 001,227,776 | ---- | M] (Atheros Communications, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\athr.sys -- (athr)
DRV - [2009/07/31 10:45:56 | 000,022,912 | ---- | M] (TOSHIBA Corporation.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\tdcmdpst.sys -- (tdcmdpst)
DRV - [2009/07/15 08:28:42 | 000,023,512 | ---- | M] (TOSHIBA Corporation) [Kernel | Boot | Running] -- C:\windows\system32\DRIVERS\TVALZ_O.SYS -- (TVALZ)
DRV - [2009/07/14 09:52:10 | 000,014,336 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\vwifimp.sys -- (vwifimp)
DRV - [2009/07/14 09:51:11 | 000,034,944 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\winusb.sys -- (WinUsb)
DRV - [2009/07/08 01:53:06 | 000,007,680 | ---- | M] (TOSHIBA Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\FwLnk.sys -- (FwLnk)
DRV - [2009/06/23 10:04:58 | 000,024,064 | ---- | M] (TOSHIBA Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\PGEffect.sys -- (PGEffect)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========


IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = <local>;*.local

========== FireFox ==========

FF - prefs.js..browser.search.selectedEngine: "eBay"
FF - prefs.js..extensions.enabledItems: {1392b8d2-5c05-419f-a8f6-b9f15a596612}:3.3.3.2
FF - prefs.js..extensions.enabledItems: {ACAA314B-EEBA-48e4-AD47-84E31C44796C}:1.0.1
FF - prefs.js..extensions.enabledItems: {e968fc70-8f95-4ab9-9e79-304de2a71ee1}:0.7.3
FF - prefs.js..extensions.enabledItems: {1E73965B-8B48-48be-9C8D-68B920ABC1C4}:10.0.0.1319
FF - prefs.js..network.proxy.no_proxies_on: "*.local"
FF - prefs.js..network.proxy.type: 0

FF - HKLM\software\mozilla\Firefox\Extensions\\{1E73965B-8B48-48be-9C8D-68B920ABC1C4}: C:\Program Files\AVG\AVG10\Firefox4\ [2011/04/21 19:38:30 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.17\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011/04/30 17:13:26 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.17\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011/04/30 17:13:26 | 000,000,000 | ---D | M]

[2010/10/08 16:02:39 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Kristen\AppData\Roaming\Mozilla\Extensions
[2011/05/02 18:31:45 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Kristen\AppData\Roaming\Mozilla\Firefox\Profiles\4phcayjv.default\extensions
[2011/03/27 08:33:04 | 000,000,000 | ---D | M] (Freecorder Community Toolbar) -- C:\Users\Kristen\AppData\Roaming\Mozilla\Firefox\Profiles\4phcayjv.default\extensions\{1392b8d2-5c05-419f-a8f6-b9f15a596612}
[2010/10/08 17:02:58 | 000,000,000 | ---D | M] ("DVDVideoSoft Menu") -- C:\Users\Kristen\AppData\Roaming\Mozilla\Firefox\Profiles\4phcayjv.default\extensions\{ACAA314B-EEBA-48e4-AD47-84E31C44796C}
[2011/01/07 09:15:35 | 000,000,000 | ---D | M] (User Agent Switcher) -- C:\Users\Kristen\AppData\Roaming\Mozilla\Firefox\Profiles\4phcayjv.default\extensions\{e968fc70-8f95-4ab9-9e79-304de2a71ee1}
[2011/04/19 17:38:52 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions
[2011/04/21 19:38:30 | 000,000,000 | ---D | M] (AVG Safe Search) -- C:\PROGRAM FILES\AVG\AVG10\FIREFOX4

O1 HOSTS File: ([2011/04/21 14:31:55 | 000,000,098 | ---- | M]) - C:\Windows\System32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG10\avgssie.dll (AVG Technologies CZ, s.r.o.)
O2 - BHO: (Skype Plug-In) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O2 - BHO: (Bing Bar Helper) - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files\Microsoft\BingBar\BingExt.dll (Microsoft Corporation.)
O2 - BHO: (TOSHIBA Media Controller Plug-in) - {F3C88694-EFFA-4d78-B409-54B7B2535B14} - C:\Program Files\TOSHIBA\TOSHIBA Media Controller Plug-in\TOSHIBAMediaControllerIE.dll (<TOSHIBA>)
O3 - HKLM\..\Toolbar: (Bing Bar) - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files\Microsoft\BingBar\BingExt.dll (Microsoft Corporation.)
O4 - HKLM..\Run: [AdobeAAMUpdater-1.0] C:\Program Files\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [AdobeCS5ServiceManager] C:\Program Files\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [AVG_TRAY] C:\Program Files\AVG\AVG10\avgtray.exe (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [cAudioFilterAgent] C:\Program Files\CONEXANT\cAudioFilterAgent\cAudioFilterAgent.exe (Conexant Systems, Inc.)
O4 - HKLM..\Run: [Freecorder FLV Service] C:\Program Files\Freecorder\FLVSrvc.exe (Applian Technologies, Inc.)
O4 - HKLM..\Run: [Malwarebytes' Anti-Malware (reboot)] C:\Users\Kristen\Desktop\Malwarebytes' Anti-Malware\mbam.exe (Malwarebytes Corporation)
O4 - HKLM..\Run: [SmartAudio] C:\Program Files\CONEXANT\SAII\SAIICpl.exe ()
O4 - HKLM..\Run: [SwitchBoard] C:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [ToshibaServiceStation] C:\Program Files\TOSHIBA\TOSHIBA Service Station\ToshibaServiceStation.exe (TOSHIBA Corporation)
O4 - HKLM..\Run: [TosSENotify] C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosWaitSrv.exe (TOSHIBA Corporation)
O4 - HKLM..\Run: [TosVolRegulator] C:\Program Files\TOSHIBA\TosVolRegulator\TosVolRegulator.exe (TOSHIBA Corporation)
O4 - HKLM..\Run: [TWebCamera] C:\Program Files\TOSHIBA\TOSHIBA Web Camera Application\TWebCamera.exe (TOSHIBA CORPORATION.)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HideSCAHealth = 1
O8 - Extra context menu item: Free YouTube Download - C:\Users\Kristen\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubedownload.htm ()
O8 - Extra context menu item: Free YouTube to Mp3 Converter - C:\Users\Kristen\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm ()
O9 - Extra Button: Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000009 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 10.0.0.138
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG10\avgpp.dll (AVG Technologies CZ, s.r.o.)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\windows\System32\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O28 - HKLM ShellExecuteHooks: {AEB6717E-7E19-11d0-97EE-00C04FD91972} - Reg Error: Key error. File not found
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009/06/11 07:42:20 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O34 - HKLM BootExecute: (C:\PROGRA~1\AVG\AVG10\avgchsvx.exe /sync) - C:\Program Files\AVG\AVG10\avgchsvx.exe (AVG Technologies CZ, s.r.o.)
O34 - HKLM BootExecute: (C:\PROGRA~1\AVG\AVG10\avgrsx.exe /sync /restart) - C:\Program Files\AVG\AVG10\avgrsx.exe (AVG Technologies CZ, s.r.o.)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = ComFile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*

========== Files/Folders - Created Within 30 Days ==========

[2011/05/02 18:23:34 | 000,000,000 | -H-D | C] -- C:\$AVG
[2011/05/02 17:19:27 | 000,000,000 | ---D | C] -- C:\Users\Kristen\AppData\Local\{8E509629-1A3D-4043-83F2-2D1E28FFA67F}
[2011/05/02 16:33:38 | 000,000,000 | ---D | C] -- C:\Users\Kristen\AppData\Local\{E263E743-CCB9-4FAC-8DCA-F4B891D671C6}
[2011/05/01 11:19:05 | 000,000,000 | ---D | C] -- C:\Users\Kristen\AppData\Local\{974B2322-E161-4CED-A669-35F4067C1DAB}
[2011/04/30 11:43:29 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes
[2011/04/30 11:36:53 | 000,000,000 | ---D | C] -- C:\Program Files\iPod
[2011/04/30 11:36:34 | 000,000,000 | ---D | C] -- C:\Program Files\iTunes
[2011/04/30 11:24:03 | 000,000,000 | ---D | C] -- C:\Program Files\Bonjour
[2011/04/30 11:21:15 | 000,000,000 | -HSD | C] -- C:\Config.Msi
[2011/04/30 11:13:21 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\QuickTime
[2011/04/30 10:40:33 | 000,000,000 | ---D | C] -- C:\Program Files\QuickTime
[2011/04/30 09:18:30 | 000,000,000 | ---D | C] -- C:\Users\Kristen\Desktop\Malwarebytes' Anti-Malware
[2011/04/30 08:54:15 | 000,000,000 | ---D | C] -- C:\Users\Kristen\AppData\Local\{4721D940-7AF7-4B03-8412-68C4BECA2B21}
[2011/04/21 20:57:01 | 000,000,000 | ---D | C] -- C:\Users\Kristen\AppData\Roaming\AVG
[2011/04/21 20:56:38 | 000,000,000 | ---D | C] -- C:\ProgramData\TEMP
[2011/04/21 20:56:32 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVG PC Tuneup 2011
[2011/04/21 19:42:57 | 000,000,000 | ---D | C] -- C:\Users\Kristen\AppData\Roaming\AVG10
[2011/04/21 19:38:50 | 000,000,000 | -H-D | C] -- C:\ProgramData\Common Files
[2011/04/21 19:37:22 | 000,000,000 | ---D | C] -- C:\ProgramData\AVG10
[2011/04/21 19:37:22 | 000,000,000 | ---D | C] -- C:\windows\System32\drivers\AVG
[2011/04/21 19:36:21 | 000,000,000 | ---D | C] -- C:\Program Files\AVG
[2011/04/21 19:22:33 | 000,000,000 | ---D | C] -- C:\ProgramData\MFAData
[2011/04/21 19:17:13 | 005,497,592 | ---- | C] (AVG Technologies) -- C:\Users\Kristen\Desktop\avg_free_stb_all_2011_1321_cnet.exe
[2011/04/21 17:05:29 | 000,000,000 | ---D | C] -- C:\ProgramData\AVAST Software
[2011/04/21 17:05:29 | 000,000,000 | ---D | C] -- C:\Program Files\AVAST Software
[2011/04/21 16:46:36 | 000,000,000 | ---D | C] -- C:\windows\temp
[2011/04/21 16:45:28 | 000,000,000 | -HSD | C] -- C:\$RECYCLE.BIN
[2011/04/21 16:37:43 | 000,212,480 | ---- | C] (SteelWerX) -- C:\windows\SWXCACLS.exe
[2011/04/21 14:45:36 | 000,038,224 | ---- | C] (Malwarebytes Corporation) -- C:\windows\System32\drivers\mbamswissarmy.sys
[2011/04/21 14:45:36 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2011/04/21 14:45:33 | 000,000,000 | ---D | C] -- C:\Program Files\Malwarebytes' Anti-Malware
[2011/04/21 14:31:49 | 000,000,000 | ---D | C] -- C:\_OTL
[2011/04/19 16:28:22 | 000,161,792 | ---- | C] (SteelWerX) -- C:\windows\SWREG.exe
[2011/04/19 16:28:22 | 000,136,704 | ---- | C] (SteelWerX) -- C:\windows\SWSC.exe
[2011/04/19 16:28:22 | 000,031,232 | ---- | C] (NirSoft) -- C:\windows\NIRCMD.exe
[2011/04/19 16:28:16 | 000,000,000 | ---D | C] -- C:\windows\ERDNT
[2011/04/19 16:27:46 | 000,000,000 | ---D | C] -- C:\Qoobox
[2011/04/19 14:39:21 | 000,000,000 | ---D | C] -- C:\ProgramData\Spybot - Search & Destroy
[2011/04/07 12:17:15 | 000,000,000 | ---D | C] -- C:\Users\Kristen\AppData\Roaming\DVDVideoSoft
[2011/04/04 18:42:56 | 000,000,000 | ---D | C] -- C:\Users\Kristen\AppData\Roaming\Windows Live Writer
[2011/04/04 18:42:56 | 000,000,000 | ---D | C] -- C:\Users\Kristen\AppData\Local\Windows Live Writer
[2011/04/04 17:37:08 | 000,000,000 | ---D | C] -- C:\windows\en
[2011/04/04 17:34:33 | 000,000,000 | R--D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Live
[2011/04/04 17:33:27 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft SQL Server Compact Edition
[2011/04/04 16:34:25 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft
[2010/02/21 01:35:04 | 000,004,096 | ---- | C] ( ) -- C:\windows\System32\IGFXDEVLib.dll

========== Files - Modified Within 30 Days ==========

[2011/05/02 20:06:03 | 000,717,520 | ---- | M] () -- C:\windows\System32\perfh009.dat
[2011/05/02 20:06:03 | 000,143,214 | ---- | M] () -- C:\windows\System32\perfc009.dat
[2011/05/02 20:04:24 | 000,067,584 | --S- | M] () -- C:\windows\bootstat.dat
[2011/05/02 16:40:28 | 000,016,304 | -H-- | M] () -- C:\windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2011/05/02 16:40:28 | 000,016,304 | -H-- | M] () -- C:\windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2011/05/02 16:38:32 | 113,928,874 | ---- | M] () -- C:\windows\System32\drivers\AVG\incavi.avm
[2011/05/02 16:32:20 | 1506,779,136 | -HS- | M] () -- C:\hiberfil.sys
[2011/05/01 20:48:50 | 000,036,190 | ---- | M] () -- C:\Users\Kristen\Documents\Douglas-Hodge-La-Cage-Aux-Folles -New-Broadway-Cast-Recording.jpg
[2011/05/01 20:41:15 | 008,361,531 | ---- | M] () -- C:\Users\Kristen\Documents\22 Track 22.mp3
[2011/04/30 22:33:34 | 245,857,628 | ---- | M] () -- C:\windows\MEMORY.DMP
[2011/04/30 14:40:34 | 000,039,429 | ---- | M] () -- C:\Users\Kristen\Documents\rannels7.jpg
[2011/04/30 14:39:33 | 000,038,842 | ---- | M] () -- C:\Users\Kristen\Documents\rannels4.jpg
[2011/04/30 14:39:26 | 000,040,236 | ---- | M] () -- C:\Users\Kristen\Documents\rannels5.jpg
[2011/04/30 13:22:41 | 000,008,789 | ---- | M] () -- C:\Users\Kristen\Documents\images.jpg
[2011/04/30 11:43:29 | 000,001,764 | ---- | M] () -- C:\Users\Public\Desktop\iTunes.lnk
[2011/04/30 11:13:21 | 000,001,826 | ---- | M] () -- C:\Users\Public\Desktop\QuickTime Player.lnk
[2011/04/30 09:18:34 | 000,000,766 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2011/04/30 09:17:01 | 000,009,156 | -HS- | M] () -- C:\Users\Kristen\AppData\Local\5f2ph51m052ajruj700xx2hor734170i6dmv3o246y7n4n4
[2011/04/30 09:17:01 | 000,009,156 | -HS- | M] () -- C:\ProgramData\5f2ph51m052ajruj700xx2hor734170i6dmv3o246y7n4n4
[2011/04/28 20:28:52 | 000,094,282 | ---- | M] () -- C:\Users\Kristen\Documents\5.160698.jpg
[2011/04/28 18:58:50 | 000,169,144 | ---- | M] () -- C:\windows\System32\drivers\AVG\iavichjg.avm
[2011/04/28 15:49:35 | 000,160,089 | ---- | M] () -- C:\Users\Kristen\Documents\tn-500_bww-60.jpg
[2011/04/27 15:14:44 | 000,000,934 | ---- | M] () -- C:\Users\Public\Desktop\AVG 2011.lnk
[2011/04/26 15:39:22 | 000,493,921 | ---- | M] () -- C:\Users\Kristen\Documents\tumblr_liqte5BjnV1qbwghg.gif
[2011/04/26 15:38:01 | 000,496,730 | ---- | M] () -- C:\Users\Kristen\Documents\tumblr_ljevncNrIt1qbiysno1_500.gif
[2011/04/26 15:36:21 | 000,409,110 | ---- | M] () -- C:\Users\Kristen\Documents\tumblr_liql01jRkJ1qbwghg.gif
[2011/04/26 11:08:30 | 000,470,858 | ---- | M] () -- C:\Users\Kristen\Documents\tumblr_lk87l8qI2e1qgvpw5o1_400.gif
[2011/04/23 11:35:53 | 000,110,775 | ---- | M] () -- C:\Users\Kristen\Documents\eighteen.gif
[2011/04/23 11:34:55 | 004,799,866 | ---- | M] () -- C:\Users\Kristen\Documents\18-tittle-o.gif
[2011/04/21 20:56:34 | 000,001,150 | ---- | M] () -- C:\Users\Kristen\Desktop\AVG PC Tuneup 2011.lnk
[2011/04/21 19:18:24 | 005,497,592 | ---- | M] (AVG Technologies) -- C:\Users\Kristen\Desktop\avg_free_stb_all_2011_1321_cnet.exe
[2011/04/21 17:05:46 | 000,002,577 | ---- | M] () -- C:\windows\System32\config.nt
[2011/04/21 14:31:55 | 000,000,098 | ---- | M] () -- C:\windows\System32\drivers\etc\Hosts
[2011/04/19 16:49:35 | 000,000,000 | ---- | M] () -- C:\windows\System32\cd.dat
[2011/04/17 20:23:02 | 000,001,456 | ---- | M] () -- C:\Users\Kristen\AppData\Local\Adobe Save for Web 12.0 Prefs
[2011/04/17 10:41:00 | 003,765,888 | ---- | M] () -- C:\windows\System32\FNTCACHE.DAT
[2011/04/07 12:17:57 | 000,001,212 | ---- | M] () -- C:\Users\Kristen\Desktop\DVDVideoSoft Free Studio.lnk

========== Files Created - No Company Name ==========

[2011/05/02 16:38:32 | 113,928,874 | ---- | C] () -- C:\windows\System32\drivers\AVG\incavi.avm
[2011/05/01 20:48:49 | 000,036,190 | ---- | C] () -- C:\Users\Kristen\Documents\Douglas-Hodge-La-Cage-Aux-Folles -New-Broadway-Cast-Recording.jpg
[2011/05/01 20:40:56 | 008,361,531 | ---- | C] () -- C:\Users\Kristen\Documents\22 Track 22.mp3
[2011/04/30 14:40:34 | 000,039,429 | ---- | C] () -- C:\Users\Kristen\Documents\rannels7.jpg
[2011/04/30 14:39:33 | 000,038,842 | ---- | C] () -- C:\Users\Kristen\Documents\rannels4.jpg
[2011/04/30 14:39:26 | 000,040,236 | ---- | C] () -- C:\Users\Kristen\Documents\rannels5.jpg
[2011/04/30 13:22:40 | 000,008,789 | ---- | C] () -- C:\Users\Kristen\Documents\images.jpg
[2011/04/30 11:43:29 | 000,001,764 | ---- | C] () -- C:\Users\Public\Desktop\iTunes.lnk
[2011/04/30 11:13:21 | 000,001,826 | ---- | C] () -- C:\Users\Public\Desktop\QuickTime Player.lnk
[2011/04/30 09:18:34 | 000,000,766 | ---- | C] () -- C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2011/04/29 18:34:07 | 000,009,156 | -HS- | C] () -- C:\Users\Kristen\AppData\Local\5f2ph51m052ajruj700xx2hor734170i6dmv3o246y7n4n4
[2011/04/29 18:34:07 | 000,009,156 | -HS- | C] () -- C:\ProgramData\5f2ph51m052ajruj700xx2hor734170i6dmv3o246y7n4n4
[2011/04/28 20:28:46 | 000,094,282 | ---- | C] () -- C:\Users\Kristen\Documents\5.160698.jpg
[2011/04/28 18:58:50 | 000,169,144 | ---- | C] () -- C:\windows\System32\drivers\AVG\iavichjg.avm
[2011/04/28 15:49:34 | 000,160,089 | ---- | C] () -- C:\Users\Kristen\Documents\tn-500_bww-60.jpg
[2011/04/26 15:39:21 | 000,493,921 | ---- | C] () -- C:\Users\Kristen\Documents\tumblr_liqte5BjnV1qbwghg.gif
[2011/04/26 15:38:01 | 000,496,730 | ---- | C] () -- C:\Users\Kristen\Documents\tumblr_ljevncNrIt1qbiysno1_500.gif
[2011/04/26 15:36:19 | 000,409,110 | ---- | C] () -- C:\Users\Kristen\Documents\tumblr_liql01jRkJ1qbwghg.gif
[2011/04/26 11:08:29 | 000,470,858 | ---- | C] () -- C:\Users\Kristen\Documents\tumblr_lk87l8qI2e1qgvpw5o1_400.gif
[2011/04/23 11:35:53 | 000,110,775 | ---- | C] () -- C:\Users\Kristen\Documents\eighteen.gif
[2011/04/23 11:33:02 | 004,799,866 | ---- | C] () -- C:\Users\Kristen\Documents\18-tittle-o.gif
[2011/04/21 20:56:34 | 000,001,150 | ---- | C] () -- C:\Users\Kristen\Desktop\AVG PC Tuneup 2011.lnk
[2011/04/21 19:38:35 | 000,000,934 | ---- | C] () -- C:\Users\Public\Desktop\AVG 2011.lnk
[2011/04/19 16:49:35 | 000,000,000 | ---- | C] () -- C:\windows\System32\cd.dat
[2011/04/19 16:28:22 | 000,256,512 | ---- | C] () -- C:\windows\PEV.exe
[2011/04/19 16:28:22 | 000,098,816 | ---- | C] () -- C:\windows\sed.exe
[2011/04/19 16:28:22 | 000,089,088 | ---- | C] () -- C:\windows\MBR.exe
[2011/04/19 16:28:22 | 000,080,412 | ---- | C] () -- C:\windows\grep.exe
[2011/04/19 16:28:22 | 000,068,096 | ---- | C] () -- C:\windows\zip.exe
[2011/04/04 17:34:21 | 000,001,262 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Live Movie Maker.lnk
[2011/04/04 17:33:49 | 000,001,331 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Live Photo Gallery.lnk
[2011/04/04 17:33:13 | 000,001,415 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Live Mail.lnk
[2011/04/04 17:32:58 | 000,002,443 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Live Messenger.lnk
[2011/03/30 16:54:06 | 000,000,132 | ---- | C] () -- C:\Users\Kristen\AppData\Roaming\Adobe IllExport Filter CS5 Prefs
[2011/01/08 11:11:19 | 000,000,132 | ---- | C] () -- C:\Users\Kristen\AppData\Roaming\Adobe GIF Format CS5 Prefs
[2011/01/02 20:10:13 | 000,000,132 | ---- | C] () -- C:\Users\Kristen\AppData\Roaming\Adobe PNG Format CS5 Prefs
[2010/12/31 20:28:45 | 000,001,456 | ---- | C] () -- C:\Users\Kristen\AppData\Local\Adobe Save for Web 12.0 Prefs
[2010/10/15 15:32:49 | 000,000,056 | ---- | C] () -- C:\ProgramData\ezsidmv.dat
[2010/10/08 14:57:02 | 000,000,857 | ---- | C] () -- C:\Program Files\Downloads.lnk
[2010/06/02 02:21:20 | 000,000,000 | ---- | C] () -- C:\windows\NDSTray.INI
[2010/02/21 02:16:08 | 000,439,308 | ---- | C] () -- C:\windows\System32\igcompkrng500.bin
[2010/02/21 02:16:06 | 000,982,240 | ---- | C] () -- C:\windows\System32\igkrng500.bin
[2010/02/21 02:16:06 | 000,092,356 | ---- | C] () -- C:\windows\System32\igfcg500m.bin
[2010/02/21 01:32:46 | 000,000,151 | ---- | C] () -- C:\windows\System32\GfxUI.exe.config
[2010/02/21 01:27:36 | 000,208,896 | ---- | C] () -- C:\windows\System32\iglhsip32.dll
[2010/02/21 01:27:36 | 000,143,360 | ---- | C] () -- C:\windows\System32\iglhcp32.dll
[2009/07/14 14:57:37 | 000,067,584 | --S- | C] () -- C:\windows\bootstat.dat
[2009/07/14 14:33:53 | 003,765,888 | ---- | C] () -- C:\windows\System32\FNTCACHE.DAT
[2009/07/14 12:05:48 | 000,717,520 | ---- | C] () -- C:\windows\System32\perfh009.dat
[2009/07/14 12:05:48 | 000,291,294 | ---- | C] () -- C:\windows\System32\perfi009.dat
[2009/07/14 12:05:48 | 000,143,214 | ---- | C] () -- C:\windows\System32\perfc009.dat
[2009/07/14 12:05:48 | 000,031,548 | ---- | C] () -- C:\windows\System32\perfd009.dat
[2009/07/14 12:05:05 | 000,000,741 | ---- | C] () -- C:\windows\System32\NOISE.DAT
[2009/07/14 12:04:11 | 000,215,943 | ---- | C] () -- C:\windows\System32\dssec.dat
[2009/07/14 09:55:01 | 000,043,131 | ---- | C] () -- C:\windows\mib.bin
[2009/07/14 09:51:43 | 000,073,728 | ---- | C] () -- C:\windows\System32\BthpanContextHandler.dll
[2009/07/14 09:42:10 | 000,064,000 | ---- | C] () -- C:\windows\System32\BWContextHandler.dll
[2009/07/14 08:09:19 | 000,139,824 | ---- | C] () -- C:\windows\System32\igfcg500.bin
[2009/06/11 07:26:10 | 000,673,088 | ---- | C] () -- C:\windows\System32\mlang.dat

========== LOP Check ==========

[2011/04/21 21:16:46 | 000,000,000 | ---D | M] -- C:\Users\Kristen\AppData\Roaming\AVG
[2011/04/21 19:42:57 | 000,000,000 | ---D | M] -- C:\Users\Kristen\AppData\Roaming\AVG10
[2011/03/04 20:02:20 | 000,000,000 | ---D | M] -- C:\Users\Kristen\AppData\Roaming\Dropbox
[2011/04/07 12:17:39 | 000,000,000 | ---D | M] -- C:\Users\Kristen\AppData\Roaming\DVDVideoSoft
[2011/04/07 12:18:00 | 000,000,000 | ---D | M] -- C:\Users\Kristen\AppData\Roaming\DVDVideoSoftIEHelpers
[2010/11/08 15:34:51 | 000,000,000 | ---D | M] -- C:\Users\Kristen\AppData\Roaming\Jasc
[2011/03/14 16:23:21 | 000,000,000 | ---D | M] -- C:\Users\Kristen\AppData\Roaming\NCH Swift Sound
[2010/12/30 09:45:15 | 000,000,000 | ---D | M] -- C:\Users\Kristen\AppData\Roaming\StageManager.BD092818F67280F4B42B04877600987F0111B594.1
[2010/10/08 15:30:52 | 000,000,000 | ---D | M] -- C:\Users\Kristen\AppData\Roaming\Tific
[2010/10/08 15:11:55 | 000,000,000 | ---D | M] -- C:\Users\Kristen\AppData\Roaming\Toshiba
[2011/04/19 16:26:20 | 000,000,000 | ---D | M] -- C:\Users\Kristen\AppData\Roaming\uTorrent
[2011/04/17 11:20:44 | 000,000,000 | ---D | M] -- C:\Users\Kristen\AppData\Roaming\Windows Live Writer
[2011/04/19 16:49:34 | 000,032,612 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT

========== Purity Check ==========



========== Alternate Data Streams ==========

@Alternate Data Stream - 146 bytes -> C:\ProgramData\TEMP:0B4227B4

< End of report >
  • 0

#8
RKinner

RKinner

    Malware Expert

  • Expert
  • 24,598 posts
  • MVP
Got a new tool to fight the infection that is keeping tdsskiller from running:

Download aswMBR.exe ( 511KB ) to your desktop.

Double click the aswMBR.exe to run it

Click the "Scan" button to start scan
Posted Image

On completion of the scan (Note if the Fix button is enabled and tell me) click save log, save it to your desktop and post in your next reply
Posted Image

Ron
  • 0

#9
Laura Rod

Laura Rod

    New Member

  • Topic Starter
  • Member
  • Pip
  • 6 posts
The fix button was not enabled. Here is the log:

aswMBR version 0.9.5.256 Copyright© 2011 AVAST Software
Run date: 2011-05-05 18:11:21
-----------------------------
18:11:21.647 OS Version: Windows 6.1.7600
18:11:21.647 Number of processors: 2 586 0x170A
18:11:21.649 ComputerName: KRISTEN-PC UserName: Kristen
18:11:25.995 Initialize success
18:11:48.975 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-1
18:11:48.975 Disk 0 Vendor: TOSHIBA_ GJ00 Size: 238475MB BusType: 3
18:11:48.990 Disk 0 MBR read successfully
18:11:49.006 Disk 0 MBR scan
18:11:49.006 Disk 0 unknown MBR code
18:11:49.006 Disk 0 scanning sectors +488396800
18:11:49.037 Disk 0 scanning C:\windows\system32\drivers
18:11:55.027 Service scanning
18:11:55.948 Disk 0 trace - called modules:
18:11:55.979 ntkrnlpa.exe CLASSPNP.SYS disk.sys >>UNKNOWN [0x862ed1ed]<<
18:11:55.995 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x862c18d0]
18:11:55.995 3 CLASSPNP.SYS[88d9359e] -> nt!IofCallDriver -> \Device\Ide\IAAStorageDevice-1[0x85884028]
18:11:55.995 \Driver\iaStor[0x8587a970] -> IRP_MJ_INTERNAL_DEVICE_CONTROL -> 0x862ed1ed
18:11:56.010 Scan finished successfully
18:12:11.392 Disk 0 MBR has been saved successfully to "C:\Users\Kristen\Documents\MBR.dat"
18:12:11.392 The log file has been saved successfully to "C:\Users\Kristen\Documents\aswMBR.txt"
  • 0

#10
RKinner

RKinner

    Malware Expert

  • Expert
  • 24,598 posts
  • MVP
Do not install any programs that I don't tell you to install until we are done. It's hard to paint a moving train.

Please uninstall AVG 2011, Download save and run the AVG removal tool
http://download.avg....6_2011_1184.exe
and reinstall Avast.

Copy the text in the code box by highlighting and Ctrl + c


:OTL
FF - prefs.js..extensions.enabledItems: {1E73965B-8B48-48be-9C8D-68B920ABC1C4}:10.0.0.1319
[2011/03/27 08:33:04 | 000,000,000 | ---D | M] (Freecorder Community Toolbar) -- C:\Users\Kristen\AppData\Roaming\Mozilla\Firefox\Profiles\4phcayjv.default\extensions\{1392b8d2-5c05-419f-a8f6-b9f15a596612}
[2011/05/02 17:19:27 | 000,000,000 | ---D | C] -- C:\Users\Kristen\AppData\Local\{8E509629-1A3D-4043-83F2-2D1E28FFA67F}
[2011/05/02 16:33:38 | 000,000,000 | ---D | C] -- C:\Users\Kristen\AppData\Local\{E263E743-CCB9-4FAC-8DCA-F4B891D671C6}
[2011/05/01 11:19:05 | 000,000,000 | ---D | C] -- C:\Users\Kristen\AppData\Local\{974B2322-E161-4CED-A669-35F4067C1DAB}
[2011/04/29 18:34:07 | 000,009,156 | -HS- | C] () -- C:\Users\Kristen\AppData\Local\5f2ph51m052ajruj700xx2hor734170i6dmv3o246y7n4n4
[2011/04/29 18:34:07 | 000,009,156 | -HS- | C] () -- C:\ProgramData\5f2ph51m052ajruj700xx2hor734170i6dmv3o246y7n4n4

:Files
C:\Users\Kristen\AppData\Local\{8E509629-1A3D-4043-83F2-2D1E28FFA67F}
C:\Users\Kristen\AppData\Local\{E263E743-CCB9-4FAC-8DCA-F4B891D671C6}
C:\Users\Kristen\AppData\Local\{974B2322-E161-4CED-A669-35F4067C1DAB}
C:\Users\Kristen\AppData\Local\5f2ph51m052ajruj700xx2hor734170i6dmv3o246y7n4n4
C:\ProgramData\5f2ph51m052ajruj700xx2hor734170i6dmv3o246y7n4n4

:Commands
[purity]
[emptytemp]
[Reboot]

then run OTL (Right click and Run As Administrator) and Under the Custom Scans/Fixes box at the bottom, paste (ctrl +v) the text. Verify that you got it all and Then click the Run Fix button at the top
Let the program run unhindered, OTL will reboot the PC when it is done. Save the log and copy and paste it to a reply.

Open OTL again (Right click and Run As Administrator) and select either the Use SafeList or All option in the Extra Registry group then the Run Scan button. Post the two logs it produces in your next reply.

aswMBR found a nasty mbr virus. Normally we would have to do a fixmbr which is a risky thing to do especially if you have a Dell/HP/Compaq but I've had some luck with the Avast boot-time scan removing it. Try running it twice.

Once you have it reinstalled and it has updated:

Click on the Avast ball. Then click on Scan Computer, then on
Boot-Time Scan then on Settings. Change the Ask at the bottom to Move to Chest. OK then Schedule Now. Reboot and let it run a scan. It may take hours.
Once it finishes it should load windows. Then click on Scan Computer, then on
Boot-Time Scan then Schedule Now. Reboot and let it run a scan. After windows comes back, Click on the Avast ball and then on Scan Logs, select the latest Boot-time scan report then View Results. How many did it find? Hopefully it is now not finding any more.

Now try running aswMBR again and post the results.

Will TDSSKiller run now?

Ron
  • 0

#11
Laura Rod

Laura Rod

    New Member

  • Topic Starter
  • Member
  • Pip
  • 6 posts
First OTL log:

All processes killed
========== OTL ==========
Prefs.js: {1E73965B-8B48-48be-9C8D-68B920ABC1C4}:10.0.0.1319 removed from extensions.enabledItems
C:\Users\Kristen\AppData\Roaming\Mozilla\Firefox\Profiles\4phcayjv.default\extensions\{1392b8d2-5c05-419f-a8f6-b9f15a596612}\searchplugin folder moved successfully.
C:\Users\Kristen\AppData\Roaming\Mozilla\Firefox\Profiles\4phcayjv.default\extensions\{1392b8d2-5c05-419f-a8f6-b9f15a596612}\META-INF folder moved successfully.
C:\Users\Kristen\AppData\Roaming\Mozilla\Firefox\Profiles\4phcayjv.default\extensions\{1392b8d2-5c05-419f-a8f6-b9f15a596612}\lib folder moved successfully.
C:\Users\Kristen\AppData\Roaming\Mozilla\Firefox\Profiles\4phcayjv.default\extensions\{1392b8d2-5c05-419f-a8f6-b9f15a596612}\defaults folder moved successfully.
C:\Users\Kristen\AppData\Roaming\Mozilla\Firefox\Profiles\4phcayjv.default\extensions\{1392b8d2-5c05-419f-a8f6-b9f15a596612}\components folder moved successfully.
C:\Users\Kristen\AppData\Roaming\Mozilla\Firefox\Profiles\4phcayjv.default\extensions\{1392b8d2-5c05-419f-a8f6-b9f15a596612}\chrome folder moved successfully.
C:\Users\Kristen\AppData\Roaming\Mozilla\Firefox\Profiles\4phcayjv.default\extensions\{1392b8d2-5c05-419f-a8f6-b9f15a596612} folder moved successfully.
C:\Users\Kristen\AppData\Local\{8E509629-1A3D-4043-83F2-2D1E28FFA67F} folder moved successfully.
C:\Users\Kristen\AppData\Local\{E263E743-CCB9-4FAC-8DCA-F4B891D671C6} folder moved successfully.
C:\Users\Kristen\AppData\Local\{974B2322-E161-4CED-A669-35F4067C1DAB} folder moved successfully.
C:\Users\Kristen\AppData\Local\5f2ph51m052ajruj700xx2hor734170i6dmv3o246y7n4n4 moved successfully.
C:\ProgramData\5f2ph51m052ajruj700xx2hor734170i6dmv3o246y7n4n4 moved successfully.
========== FILES ==========
File\Folder C:\Users\Kristen\AppData\Local\{8E509629-1A3D-4043-83F2-2D1E28FFA67F} not found.
File\Folder C:\Users\Kristen\AppData\Local\{E263E743-CCB9-4FAC-8DCA-F4B891D671C6} not found.
File\Folder C:\Users\Kristen\AppData\Local\{974B2322-E161-4CED-A669-35F4067C1DAB} not found.
File\Folder C:\Users\Kristen\AppData\Local\5f2ph51m052ajruj700xx2hor734170i6dmv3o246y7n4n4 not found.
File\Folder C:\ProgramData\5f2ph51m052ajruj700xx2hor734170i6dmv3o246y7n4n4 not found.
========== COMMANDS ==========

[EMPTYTEMP]

User: All Users

User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Flash cache emptied: 0 bytes

User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Flash cache emptied: 0 bytes

User: Kristen
->Temp folder emptied: 8827930 bytes
->Temporary Internet Files folder emptied: 67709696 bytes
->Java cache emptied: 425333 bytes
->FireFox cache emptied: 88155318 bytes
->Flash cache emptied: 49948 bytes

User: Public
->Temp folder emptied: 0 bytes

%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 1044903 bytes
RecycleBin emptied: 0 bytes

Total Files Cleaned = 159.00 mb


OTL by OldTimer - Version 3.2.22.3 log created on 05062011_164520

Files\Folders moved on Reboot...
File move failed. C:\windows\temp\_avast_\Webshlock.txt scheduled to be moved on reboot.
File\Folder C:\windows\temp\_asw_aisI.tm~a04156\setup.lok not found!

Registry entries deleted on Reboot...

Second OTL log:

OTL logfile created on: 5/6/2011 4:50:19 PM - Run 4
OTL by OldTimer - Version 3.2.22.3 Folder = C:\Users\Kristen\Downloads
Home Premium Edition (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7600.16385)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

2.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 57.00% Memory free
4.00 Gb Paging File | 3.00 Gb Available in Paging File | 78.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\windows | %ProgramFiles% = C:\Program Files
Drive C: | 221.15 Gb Total Space | 112.01 Gb Free Space | 50.65% Space Free | Partition Type: NTFS

Computer Name: KRISTEN-PC | User Name: Kristen | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - [2011/04/19 17:15:55 | 000,580,608 | ---- | M] (OldTimer Tools) -- C:\Users\Kristen\Downloads\OTL.exe
PRC - [2011/04/19 03:25:12 | 003,460,784 | ---- | M] (AVAST Software) -- C:\Program Files\AVAST Software\Avast\AvastUI.exe
PRC - [2011/04/19 03:25:10 | 000,042,184 | ---- | M] (AVAST Software) -- C:\Program Files\AVAST Software\Avast\AvastSvc.exe
PRC - [2011/02/26 15:33:07 | 002,614,784 | ---- | M] (Microsoft Corporation) -- C:\Windows\explorer.exe
PRC - [2011/02/25 10:46:22 | 000,249,648 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Microsoft\BingBar\SeaPort.EXE
PRC - [2010/06/27 02:09:18 | 000,167,936 | ---- | M] (Applian Technologies, Inc.) -- C:\Program Files\Freecorder\FLVSrvc.exe
PRC - [2010/03/11 08:44:56 | 000,496,184 | ---- | M] (Conexant Systems, Inc.) -- C:\Program Files\CONEXANT\cAudioFilterAgent\cAudioFilterAgent.exe
PRC - [2010/02/24 18:54:48 | 002,454,840 | ---- | M] (TOSHIBA CORPORATION.) -- C:\Program Files\TOSHIBA\TOSHIBA Web Camera Application\TWebCamera.exe
PRC - [2010/02/23 06:23:50 | 000,304,496 | ---- | M] (TOSHIBA CORPORATION) -- C:\Program Files\TOSHIBA\ConfigFree\NDSTray.exe
PRC - [2010/02/06 10:41:18 | 000,611,672 | ---- | M] (TOSHIBA Corporation) -- C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosWaitSrv.exe
PRC - [2010/01/29 09:44:24 | 000,185,712 | ---- | M] (TOSHIBA CORPORATION) -- C:\Program Files\TOSHIBA\ConfigFree\CFIWmxSvcs.exe
PRC - [2009/11/12 07:31:32 | 000,022,840 | ---- | M] (TOSHIBA Corporation) -- C:\Program Files\TOSHIBA\TosVolRegulator\TosVolRegulator.exe
PRC - [2009/11/06 15:04:20 | 000,468,320 | ---- | M] (TOSHIBA Corporation) -- C:\Program Files\TOSHIBA\Power Saver\TosCoSrv.exe
PRC - [2009/10/07 02:23:12 | 001,294,136 | ---- | M] (TOSHIBA Corporation) -- C:\Program Files\TOSHIBA\TOSHIBA Service Station\ToshibaServiceStation.exe
PRC - [2009/10/07 02:21:50 | 000,051,512 | ---- | M] (TOSHIBA Corporation) -- C:\Program Files\TOSHIBA\TOSHIBA Service Station\TMachInfo.exe
PRC - [2009/09/30 16:59:26 | 000,049,152 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\taskhost.exe
PRC - [2009/07/29 13:26:42 | 000,062,848 | ---- | M] (TOSHIBA CORPORATION) -- C:\Program Files\TOSHIBA\ConfigFree\CFSwMgr.exe
PRC - [2009/07/29 08:43:04 | 000,128,344 | ---- | M] (TOSHIBA Corporation) -- C:\Windows\System32\TODDSrv.exe
PRC - [2009/03/11 11:51:20 | 000,046,448 | ---- | M] (TOSHIBA CORPORATION) -- C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
PRC - [2009/02/21 02:46:52 | 000,030,312 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Microsoft Small Business\Business Contact Manager\BcmSqlStartupSvc.exe


========== Modules (SafeList) ==========

MOD - [2011/04/19 17:15:55 | 000,580,608 | ---- | M] (OldTimer Tools) -- C:\Users\Kristen\Downloads\OTL.exe
MOD - [2011/04/19 03:25:09 | 000,199,792 | ---- | M] (AVAST Software) -- C:\Program Files\AVAST Software\Avast\snxhk.dll
MOD - [2010/08/21 15:21:32 | 001,680,896 | ---- | M] (Microsoft Corporation) -- C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7600.16661_none_420fe3fa2b8113bd\comctl32.dll


========== Win32 Services (SafeList) ==========

SRV - [2011/05/03 15:49:25 | 003,274,328 | ---- | M] () [Auto | Running] -- c:\Program Files\Common Files\Akamai\netsession_win_3f211bc.dll -- (Akamai)
SRV - [2011/04/19 03:25:10 | 000,042,184 | ---- | M] (AVAST Software) [Auto | Running] -- C:\Program Files\AVAST Software\Avast\AvastSvc.exe -- (avast! Antivirus)
SRV - [2011/02/28 18:44:14 | 000,183,560 | ---- | M] (Microsoft Corporation.) [On_Demand | Stopped] -- C:\Program Files\Microsoft\BingBar\BBSvc.EXE -- (BBSvc)
SRV - [2011/02/25 10:46:22 | 000,249,648 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files\Microsoft\BingBar\SeaPort.EXE -- (SeaPort)
SRV - [2010/10/10 08:19:37 | 001,343,400 | ---- | M] (Microsoft Corporation) [Unknown | Stopped] -- C:\Windows\System32\Wat\WatAdminSvc.exe -- (WatAdminSvc)
SRV - [2010/02/19 12:37:14 | 000,517,096 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe -- (SwitchBoard)
SRV - [2010/02/06 10:41:00 | 000,111,960 | ---- | M] (TOSHIBA Corporation) [On_Demand | Stopped] -- C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSmartSrv.exe -- (TOSHIBA HDD SSD Alert Service)
SRV - [2010/01/29 09:44:24 | 000,185,712 | ---- | M] (TOSHIBA CORPORATION) [Auto | Running] -- C:\Program Files\TOSHIBA\ConfigFree\CFIWmxSvcs.exe -- (cfWiMAXService)
SRV - [2009/12/04 12:30:18 | 000,238,328 | ---- | M] (WildTangent, Inc.) [On_Demand | Stopped] -- C:\Program Files\TOSHIBA Games\TOSHIBA Game Console\GameConsoleService.exe -- (GameConsoleService)
SRV - [2009/11/06 15:04:20 | 000,468,320 | ---- | M] (TOSHIBA Corporation) [Auto | Running] -- C:\Program Files\TOSHIBA\Power Saver\TosCoSrv.exe -- (TosCoSrv)
SRV - [2009/10/07 02:21:50 | 000,051,512 | ---- | M] (TOSHIBA Corporation) [On_Demand | Running] -- C:\Program Files\TOSHIBA\TOSHIBA Service Station\TMachInfo.exe -- (TMachInfo)
SRV - [2009/07/29 08:43:04 | 000,128,344 | ---- | M] (TOSHIBA Corporation) [Auto | Running] -- C:\Windows\System32\TODDSrv.exe -- (TODDSrv)
SRV - [2009/07/14 11:16:13 | 000,025,088 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\sensrsvc.dll -- (SensrSvc)
SRV - [2009/03/11 11:51:20 | 000,046,448 | ---- | M] (TOSHIBA CORPORATION) [Auto | Running] -- C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe -- (ConfigFree Service)
SRV - [2009/02/21 02:46:52 | 000,030,312 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files\Microsoft Small Business\Business Contact Manager\BcmSqlStartupSvc.exe -- (BcmSqlStartupSvc)


========== Driver Services (SafeList) ==========

DRV - [2011/04/19 03:17:46 | 000,441,176 | ---- | M] (AVAST Software) [File_System | System | Running] -- C:\windows\System32\drivers\aswSnx.sys -- (aswSnx)
DRV - [2011/04/19 03:17:34 | 000,307,288 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\windows\System32\drivers\aswSP.sys -- (aswSP)
DRV - [2011/04/19 03:16:18 | 000,049,240 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\windows\System32\drivers\aswTdi.sys -- (aswTdi)
DRV - [2011/04/19 03:13:21 | 000,025,432 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\windows\System32\drivers\aswRdr.sys -- (aswRdr)
DRV - [2011/04/19 03:13:09 | 000,053,592 | ---- | M] (AVAST Software) [File_System | Auto | Running] -- C:\Windows\System32\drivers\aswMonFlt.sys -- (aswMonFlt)
DRV - [2011/04/19 03:12:58 | 000,019,544 | ---- | M] (AVAST Software) [File_System | Auto | Running] -- C:\windows\System32\drivers\aswFsBlk.sys -- (aswFsBlk)
DRV - [2010/09/23 05:19:02 | 000,032,768 | ---- | M] (AnchorFree Inc) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\taphss.sys -- (taphss)
DRV - [2010/03/05 10:53:06 | 000,067,624 | ---- | M] (Atheros Communications, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\L1C62x86.sys -- (L1C)
DRV - [2010/02/02 03:29:46 | 000,182,304 | ---- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\RtsUStor.sys -- (RSUSBSTOR)
DRV - [2010/01/19 10:45:00 | 000,514,104 | ---- | M] (Conexant Systems Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\CHDRT32.sys -- (CnxtHdAudService)
DRV - [2009/11/07 05:53:58 | 001,227,776 | ---- | M] (Atheros Communications, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\athr.sys -- (athr)
DRV - [2009/07/31 10:45:56 | 000,022,912 | ---- | M] (TOSHIBA Corporation.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\tdcmdpst.sys -- (tdcmdpst)
DRV - [2009/07/15 08:28:42 | 000,023,512 | ---- | M] (TOSHIBA Corporation) [Kernel | Boot | Running] -- C:\windows\system32\DRIVERS\TVALZ_O.SYS -- (TVALZ)
DRV - [2009/07/14 09:52:10 | 000,014,336 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\vwifimp.sys -- (vwifimp)
DRV - [2009/07/14 09:51:11 | 000,034,944 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\winusb.sys -- (WinUsb)
DRV - [2009/07/08 01:53:06 | 000,007,680 | ---- | M] (TOSHIBA Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\FwLnk.sys -- (FwLnk)
DRV - [2009/06/23 10:04:58 | 000,024,064 | ---- | M] (TOSHIBA Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\PGEffect.sys -- (PGEffect)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========


IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = <local>;*.local

========== FireFox ==========

FF - prefs.js..browser.search.selectedEngine: "eBay"
FF - prefs.js..extensions.enabledItems: {ACAA314B-EEBA-48e4-AD47-84E31C44796C}:1.0.1
FF - prefs.js..extensions.enabledItems: {e968fc70-8f95-4ab9-9e79-304de2a71ee1}:0.7.3
FF - prefs.js..extensions.enabledItems: {1E73965B-8B48-48be-9C8D-68B920ABC1C4}:10.0.0.1319

FF - HKLM\software\mozilla\Firefox\Extensions\\{1E73965B-8B48-48be-9C8D-68B920ABC1C4}: C:\Program Files\AVG\AVG10\Firefox4\ [2011/04/21 19:38:30 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.17\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011/04/30 17:13:26 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.17\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011/04/30 17:13:26 | 000,000,000 | ---D | M]

[2010/10/08 16:02:39 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Kristen\AppData\Roaming\Mozilla\Extensions
[2011/05/06 16:48:58 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Kristen\AppData\Roaming\Mozilla\Firefox\Profiles\4phcayjv.default\extensions
[2010/10/08 17:02:58 | 000,000,000 | ---D | M] ("DVDVideoSoft Menu") -- C:\Users\Kristen\AppData\Roaming\Mozilla\Firefox\Profiles\4phcayjv.default\extensions\{ACAA314B-EEBA-48e4-AD47-84E31C44796C}
[2011/01/07 09:15:35 | 000,000,000 | ---D | M] (User Agent Switcher) -- C:\Users\Kristen\AppData\Roaming\Mozilla\Firefox\Profiles\4phcayjv.default\extensions\{e968fc70-8f95-4ab9-9e79-304de2a71ee1}
[2011/04/19 17:38:52 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions
[2011/04/21 19:38:30 | 000,000,000 | ---D | M] (AVG Safe Search) -- C:\PROGRAM FILES\AVG\AVG10\FIREFOX4

O1 HOSTS File: ([2011/04/21 14:31:55 | 000,000,098 | ---- | M]) - C:\Windows\System32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2 - BHO: (no name) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - No CLSID value found.
O2 - BHO: (avast! WebRep) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
O2 - BHO: (Skype Plug-In) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O2 - BHO: (Bing Bar Helper) - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files\Microsoft\BingBar\BingExt.dll (Microsoft Corporation.)
O2 - BHO: (TOSHIBA Media Controller Plug-in) - {F3C88694-EFFA-4d78-B409-54B7B2535B14} - C:\Program Files\TOSHIBA\TOSHIBA Media Controller Plug-in\TOSHIBAMediaControllerIE.dll (<TOSHIBA>)
O3 - HKLM\..\Toolbar: (Bing Bar) - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files\Microsoft\BingBar\BingExt.dll (Microsoft Corporation.)
O3 - HKLM\..\Toolbar: (avast! WebRep) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
O4 - HKLM..\Run: [AdobeAAMUpdater-1.0] C:\Program Files\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [AdobeCS5ServiceManager] C:\Program Files\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [avast] C:\Program Files\AVAST Software\Avast\avastUI.exe (AVAST Software)
O4 - HKLM..\Run: [cAudioFilterAgent] C:\Program Files\CONEXANT\cAudioFilterAgent\cAudioFilterAgent.exe (Conexant Systems, Inc.)
O4 - HKLM..\Run: [Freecorder FLV Service] C:\Program Files\Freecorder\FLVSrvc.exe (Applian Technologies, Inc.)
O4 - HKLM..\Run: [Malwarebytes' Anti-Malware (reboot)] C:\Users\Kristen\Desktop\Malwarebytes' Anti-Malware\mbam.exe (Malwarebytes Corporation)
O4 - HKLM..\Run: [SmartAudio] C:\Program Files\CONEXANT\SAII\SAIICpl.exe ()
O4 - HKLM..\Run: [SwitchBoard] C:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [ToshibaServiceStation] C:\Program Files\TOSHIBA\TOSHIBA Service Station\ToshibaServiceStation.exe (TOSHIBA Corporation)
O4 - HKLM..\Run: [TosSENotify] C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosWaitSrv.exe (TOSHIBA Corporation)
O4 - HKLM..\Run: [TosVolRegulator] C:\Program Files\TOSHIBA\TosVolRegulator\TosVolRegulator.exe (TOSHIBA Corporation)
O4 - HKLM..\Run: [TWebCamera] C:\Program Files\TOSHIBA\TOSHIBA Web Camera Application\TWebCamera.exe (TOSHIBA CORPORATION.)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HideSCAHealth = 1
O8 - Extra context menu item: Free YouTube Download - C:\Users\Kristen\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubedownload.htm ()
O8 - Extra context menu item: Free YouTube to Mp3 Converter - C:\Users\Kristen\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm ()
O9 - Extra Button: Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000009 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 10.0.0.138
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\windows\System32\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O28 - HKLM ShellExecuteHooks: {AEB6717E-7E19-11d0-97EE-00C04FD91972} - Reg Error: Key error. File not found
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009/06/11 07:42:20 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O35 - HKCU\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = ComFile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKCU\...exe [@ = exefile] -- "%1" %*

========== Files/Folders - Created Within 30 Days ==========

[2011/05/06 16:43:22 | 000,307,288 | ---- | C] (AVAST Software) -- C:\windows\System32\drivers\aswSP.sys
[2011/05/06 16:43:22 | 000,019,544 | ---- | C] (AVAST Software) -- C:\windows\System32\drivers\aswFsBlk.sys
[2011/05/06 16:43:22 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\avast! Free Antivirus
[2011/05/06 16:43:20 | 000,441,176 | ---- | C] (AVAST Software) -- C:\windows\System32\drivers\aswSnx.sys
[2011/05/06 16:43:20 | 000,053,592 | ---- | C] (AVAST Software) -- C:\windows\System32\drivers\aswMonFlt.sys
[2011/05/06 16:43:20 | 000,049,240 | ---- | C] (AVAST Software) -- C:\windows\System32\drivers\aswTdi.sys
[2011/05/06 16:43:20 | 000,025,432 | ---- | C] (AVAST Software) -- C:\windows\System32\drivers\aswRdr.sys
[2011/05/06 16:43:07 | 000,199,304 | ---- | C] (AVAST Software) -- C:\windows\System32\aswBoot.exe
[2011/05/06 16:43:07 | 000,040,112 | ---- | C] (AVAST Software) -- C:\windows\avastSS.scr
[2011/05/06 13:12:00 | 000,000,000 | ---D | C] -- C:\Users\Kristen\AppData\Local\{038D2EB3-91FE-4250-BCB7-5FB17F321E29}
[2011/05/05 12:50:32 | 000,000,000 | ---D | C] -- C:\Users\Kristen\AppData\Local\{502A66C5-D4B4-4B61-B691-B2ECAD62A79C}
[2011/05/04 07:44:52 | 000,000,000 | ---D | C] -- C:\Users\Kristen\AppData\Local\{B4653880-4CD2-47AA-8B31-931A8C5E636E}
[2011/05/03 15:50:23 | 000,000,000 | ---D | C] -- C:\Users\Kristen\AppData\Local\{F6EC0949-ED62-406D-91B3-1578F2F76A32}
[2011/05/02 18:23:34 | 000,000,000 | -H-D | C] -- C:\$AVG
[2011/04/30 11:43:29 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes
[2011/04/30 11:36:53 | 000,000,000 | ---D | C] -- C:\Program Files\iPod
[2011/04/30 11:36:34 | 000,000,000 | ---D | C] -- C:\Program Files\iTunes
[2011/04/30 11:24:03 | 000,000,000 | ---D | C] -- C:\Program Files\Bonjour
[2011/04/30 11:13:21 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\QuickTime
[2011/04/30 10:40:33 | 000,000,000 | ---D | C] -- C:\Program Files\QuickTime
[2011/04/30 09:18:30 | 000,000,000 | ---D | C] -- C:\Users\Kristen\Desktop\Malwarebytes' Anti-Malware
[2011/04/30 08:54:15 | 000,000,000 | ---D | C] -- C:\Users\Kristen\AppData\Local\{4721D940-7AF7-4B03-8412-68C4BECA2B21}
[2011/04/28 08:08:24 | 001,686,016 | ---- | C] (Microsoft Corporation) -- C:\windows\System32\esent.dll
[2011/04/28 08:08:24 | 000,146,304 | ---- | C] (Microsoft Corporation) -- C:\windows\System32\drivers\storport.sys
[2011/04/28 08:08:24 | 000,074,240 | ---- | C] (Microsoft Corporation) -- C:\windows\System32\fsutil.exe
[2011/04/28 08:08:18 | 000,031,232 | ---- | C] (Microsoft Corporation) -- C:\windows\System32\prevhost.exe
[2011/04/28 08:08:17 | 000,442,880 | ---- | C] (Microsoft Corporation) -- C:\windows\System32\XpsPrint.dll
[2011/04/28 08:08:16 | 002,614,784 | ---- | C] (Microsoft Corporation) -- C:\windows\explorer.exe
[2011/04/21 20:57:01 | 000,000,000 | ---D | C] -- C:\Users\Kristen\AppData\Roaming\AVG
[2011/04/21 20:56:38 | 000,000,000 | ---D | C] -- C:\ProgramData\TEMP
[2011/04/21 20:56:32 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVG PC Tuneup 2011
[2011/04/21 19:42:57 | 000,000,000 | ---D | C] -- C:\Users\Kristen\AppData\Roaming\AVG10
[2011/04/21 19:38:50 | 000,000,000 | -H-D | C] -- C:\ProgramData\Common Files
[2011/04/21 19:36:21 | 000,000,000 | ---D | C] -- C:\Program Files\AVG
[2011/04/21 19:22:33 | 000,000,000 | ---D | C] -- C:\ProgramData\MFAData
[2011/04/21 17:05:29 | 000,000,000 | ---D | C] -- C:\ProgramData\AVAST Software
[2011/04/21 17:05:29 | 000,000,000 | ---D | C] -- C:\Program Files\AVAST Software
[2011/04/21 16:46:36 | 000,000,000 | ---D | C] -- C:\windows\temp
[2011/04/21 16:45:28 | 000,000,000 | -HSD | C] -- C:\$RECYCLE.BIN
[2011/04/21 16:37:43 | 000,212,480 | ---- | C] (SteelWerX) -- C:\windows\SWXCACLS.exe
[2011/04/21 14:45:36 | 000,038,224 | ---- | C] (Malwarebytes Corporation) -- C:\windows\System32\drivers\mbamswissarmy.sys
[2011/04/21 14:45:36 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2011/04/21 14:45:33 | 000,000,000 | ---D | C] -- C:\Program Files\Malwarebytes' Anti-Malware
[2011/04/21 14:31:49 | 000,000,000 | ---D | C] -- C:\_OTL
[2011/04/19 16:28:22 | 000,161,792 | ---- | C] (SteelWerX) -- C:\windows\SWREG.exe
[2011/04/19 16:28:22 | 000,136,704 | ---- | C] (SteelWerX) -- C:\windows\SWSC.exe
[2011/04/19 16:28:22 | 000,031,232 | ---- | C] (NirSoft) -- C:\windows\NIRCMD.exe
[2011/04/19 16:28:16 | 000,000,000 | ---D | C] -- C:\windows\ERDNT
[2011/04/19 16:27:46 | 000,000,000 | ---D | C] -- C:\Qoobox
[2011/04/19 14:39:21 | 000,000,000 | ---D | C] -- C:\ProgramData\Spybot - Search & Destroy
[2011/04/15 10:28:17 | 000,716,800 | ---- | C] (Microsoft Corporation) -- C:\windows\System32\jscript.dll
[2011/04/15 10:28:17 | 000,428,032 | ---- | C] (Microsoft Corporation) -- C:\windows\System32\vbscript.dll
[2011/04/15 10:28:15 | 000,028,672 | ---- | C] (Microsoft Corporation) -- C:\windows\System32\dnscacheugc.exe
[2011/04/15 10:28:13 | 000,294,912 | ---- | C] (Adobe Systems Incorporated) -- C:\windows\System32\atmfd.dll
[2011/04/15 10:28:13 | 000,034,304 | ---- | C] (Adobe Systems) -- C:\windows\System32\atmlib.dll
[2011/04/15 10:28:00 | 000,606,208 | ---- | C] (Microsoft Corporation) -- C:\windows\System32\mstime.dll
[2011/04/15 10:28:00 | 000,599,040 | ---- | C] (Microsoft Corporation) -- C:\windows\System32\msfeeds.dll
[2011/04/15 10:28:00 | 000,381,440 | ---- | C] (Microsoft Corporation) -- C:\windows\System32\iedkcs32.dll
[2011/04/15 10:28:00 | 000,185,856 | ---- | C] (Microsoft Corporation) -- C:\windows\System32\iepeers.dll
[2011/04/15 10:28:00 | 000,176,640 | ---- | C] (Microsoft Corporation) -- C:\windows\System32\ieui.dll
[2011/04/15 10:27:59 | 001,638,912 | ---- | C] (Microsoft Corporation) -- C:\windows\System32\mshtml.tlb
[2011/04/15 10:27:59 | 000,386,048 | ---- | C] (Microsoft Corporation) -- C:\windows\System32\html.iec
[2011/04/15 10:27:59 | 000,064,512 | ---- | C] (Microsoft Corporation) -- C:\windows\System32\msfeedsbs.dll
[2011/04/15 10:27:59 | 000,048,128 | ---- | C] (Microsoft Corporation) -- C:\windows\System32\jsproxy.dll
[2011/04/15 10:27:59 | 000,044,544 | ---- | C] (Microsoft Corporation) -- C:\windows\System32\licmgr10.dll
[2011/04/15 10:27:59 | 000,012,800 | ---- | C] (Microsoft Corporation) -- C:\windows\System32\msfeedssync.exe
[2011/04/15 10:27:47 | 002,331,136 | ---- | C] (Microsoft Corporation) -- C:\windows\System32\win32k.sys
[2011/04/15 10:27:47 | 000,191,488 | ---- | C] (Microsoft Corporation) -- C:\windows\System32\FXSCOVER.exe
[2011/04/15 10:27:46 | 000,288,256 | ---- | C] (Microsoft Corporation) -- C:\windows\System32\XpsGdiConverter.dll
[2011/04/15 10:27:44 | 001,137,664 | ---- | C] (Microsoft Corporation) -- C:\windows\System32\mfc42.dll
[2011/04/15 10:27:43 | 001,164,288 | ---- | C] (Microsoft Corporation) -- C:\windows\System32\mfc42u.dll
[2011/04/07 12:17:15 | 000,000,000 | ---D | C] -- C:\Users\Kristen\AppData\Roaming\DVDVideoSoft
[2010/02/21 01:35:04 | 000,004,096 | ---- | C] ( ) -- C:\windows\System32\IGFXDEVLib.dll

========== Files - Modified Within 30 Days ==========

[2011/05/06 16:47:26 | 000,067,584 | --S- | M] () -- C:\windows\bootstat.dat
[2011/05/06 16:47:20 | 1506,779,136 | -HS- | M] () -- C:\hiberfil.sys
[2011/05/06 16:44:30 | 000,016,304 | -H-- | M] () -- C:\windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2011/05/06 16:44:30 | 000,016,304 | -H-- | M] () -- C:\windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2011/05/06 16:43:22 | 000,002,009 | ---- | M] () -- C:\Users\Public\Desktop\avast! Free Antivirus.lnk
[2011/05/06 16:43:20 | 000,002,577 | ---- | M] () -- C:\windows\System32\config.nt
[2011/05/06 15:57:15 | 000,717,520 | ---- | M] () -- C:\windows\System32\perfh009.dat
[2011/05/06 15:57:15 | 000,143,214 | ---- | M] () -- C:\windows\System32\perfc009.dat
[2011/05/05 18:12:11 | 000,000,512 | ---- | M] () -- C:\Users\Kristen\Documents\MBR.dat
[2011/05/05 17:03:50 | 000,061,715 | ---- | M] () -- C:\Users\Kristen\Documents\Andrew+Rannells+65th+Annual+Tony+Awards+Meet+Ui7ATWbrbwvl.jpg
[2011/05/05 13:53:18 | 000,064,524 | ---- | M] () -- C:\Users\Kristen\Documents\3.162598.jpg
[2011/05/05 13:53:13 | 000,048,686 | ---- | M] () -- C:\Users\Kristen\Documents\6.162604.jpg
[2011/05/05 13:51:50 | 000,042,682 | ---- | M] () -- C:\Users\Kristen\Documents\484ysc.jpg
[2011/05/04 20:35:03 | 000,006,193 | ---- | M] () -- C:\Users\Kristen\Documents\la-cage-aux-folles-new-broadway-cast-recording-kelsey-grammer-douglas-hodge-cd-cover-art.jpg
[2011/05/04 20:29:34 | 006,619,211 | ---- | M] () -- C:\Users\Kristen\Documents\19 Track 19.mp3
[2011/05/04 20:26:57 | 005,039,359 | ---- | M] () -- C:\Users\Kristen\Documents\2-20 Lot's Wife.mp3
[2011/05/04 14:56:06 | 000,179,609 | ---- | M] () -- C:\Users\Kristen\Documents\tn-500_rannellswm199020412.jpg
[2011/05/03 19:31:43 | 000,001,124 | -HS- | M] () -- C:\Users\Kristen\AppData\Local\43w6lxpv7oi544k68hcx16hdbx
[2011/05/03 19:31:43 | 000,001,124 | -HS- | M] () -- C:\ProgramData\43w6lxpv7oi544k68hcx16hdbx
[2011/05/03 19:05:28 | 000,012,692 | ---- | M] () -- C:\Users\Kristen\Documents\folder.jpg
[2011/05/03 19:05:02 | 000,042,225 | ---- | M] () -- C:\Users\Kristen\Documents\tumblr_lk9syiVATL1qz8s52.jpg
[2011/05/01 20:48:50 | 000,036,190 | ---- | M] () -- C:\Users\Kristen\Documents\Douglas-Hodge-La-Cage-Aux-Folles -New-Broadway-Cast-Recording.jpg
[2011/05/01 20:41:15 | 008,361,531 | ---- | M] () -- C:\Users\Kristen\Documents\22 Track 22.mp3
[2011/04/30 22:33:34 | 245,857,628 | ---- | M] () -- C:\windows\MEMORY.DMP
[2011/04/30 14:40:34 | 000,039,429 | ---- | M] () -- C:\Users\Kristen\Documents\rannels7.jpg
[2011/04/30 14:39:33 | 000,038,842 | ---- | M] () -- C:\Users\Kristen\Documents\rannels4.jpg
[2011/04/30 14:39:26 | 000,040,236 | ---- | M] () -- C:\Users\Kristen\Documents\rannels5.jpg
[2011/04/30 13:22:41 | 000,008,789 | ---- | M] () -- C:\Users\Kristen\Documents\images.jpg
[2011/04/30 11:43:29 | 000,001,764 | ---- | M] () -- C:\Users\Public\Desktop\iTunes.lnk
[2011/04/30 11:13:21 | 000,001,826 | ---- | M] () -- C:\Users\Public\Desktop\QuickTime Player.lnk
[2011/04/30 09:18:34 | 000,000,766 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2011/04/28 20:28:52 | 000,094,282 | ---- | M] () -- C:\Users\Kristen\Documents\5.160698.jpg
[2011/04/28 15:49:35 | 000,160,089 | ---- | M] () -- C:\Users\Kristen\Documents\tn-500_bww-60.jpg
[2011/04/26 15:39:22 | 000,493,921 | ---- | M] () -- C:\Users\Kristen\Documents\tumblr_liqte5BjnV1qbwghg.gif
[2011/04/26 15:38:01 | 000,496,730 | ---- | M] () -- C:\Users\Kristen\Documents\tumblr_ljevncNrIt1qbiysno1_500.gif
[2011/04/26 15:36:21 | 000,409,110 | ---- | M] () -- C:\Users\Kristen\Documents\tumblr_liql01jRkJ1qbwghg.gif
[2011/04/26 11:08:30 | 000,470,858 | ---- | M] () -- C:\Users\Kristen\Documents\tumblr_lk87l8qI2e1qgvpw5o1_400.gif
[2011/04/23 11:35:53 | 000,110,775 | ---- | M] () -- C:\Users\Kristen\Documents\eighteen.gif
[2011/04/23 11:34:55 | 004,799,866 | ---- | M] () -- C:\Users\Kristen\Documents\18-tittle-o.gif
[2011/04/21 20:56:34 | 000,001,150 | ---- | M] () -- C:\Users\Kristen\Desktop\AVG PC Tuneup 2011.lnk
[2011/04/21 14:31:55 | 000,000,098 | ---- | M] () -- C:\windows\System32\drivers\etc\Hosts
[2011/04/19 16:49:35 | 000,000,000 | ---- | M] () -- C:\windows\System32\cd.dat
[2011/04/19 03:25:12 | 000,040,112 | ---- | M] (AVAST Software) -- C:\windows\avastSS.scr
[2011/04/19 03:25:10 | 000,199,304 | ---- | M] (AVAST Software) -- C:\windows\System32\aswBoot.exe
[2011/04/19 03:17:46 | 000,441,176 | ---- | M] (AVAST Software) -- C:\windows\System32\drivers\aswSnx.sys
[2011/04/19 03:17:34 | 000,307,288 | ---- | M] (AVAST Software) -- C:\windows\System32\drivers\aswSP.sys
[2011/04/19 03:16:18 | 000,049,240 | ---- | M] (AVAST Software) -- C:\windows\System32\drivers\aswTdi.sys
[2011/04/19 03:13:21 | 000,025,432 | ---- | M] (AVAST Software) -- C:\windows\System32\drivers\aswRdr.sys
[2011/04/19 03:13:09 | 000,053,592 | ---- | M] (AVAST Software) -- C:\windows\System32\drivers\aswMonFlt.sys
[2011/04/19 03:12:58 | 000,019,544 | ---- | M] (AVAST Software) -- C:\windows\System32\drivers\aswFsBlk.sys
[2011/04/17 20:23:02 | 000,001,456 | ---- | M] () -- C:\Users\Kristen\AppData\Local\Adobe Save for Web 12.0 Prefs
[2011/04/17 10:41:00 | 003,765,888 | ---- | M] () -- C:\windows\System32\FNTCACHE.DAT
[2011/04/07 12:17:57 | 000,001,212 | ---- | M] () -- C:\Users\Kristen\Desktop\DVDVideoSoft Free Studio.lnk

========== Files Created - No Company Name ==========

[2011/05/06 16:43:22 | 000,002,009 | ---- | C] () -- C:\Users\Public\Desktop\avast! Free Antivirus.lnk
[2011/05/05 18:12:11 | 000,000,512 | ---- | C] () -- C:\Users\Kristen\Documents\MBR.dat
[2011/05/05 17:03:49 | 000,061,715 | ---- | C] () -- C:\Users\Kristen\Documents\Andrew+Rannells+65th+Annual+Tony+Awards+Meet+Ui7ATWbrbwvl.jpg
[2011/05/05 13:53:18 | 000,064,524 | ---- | C] () -- C:\Users\Kristen\Documents\3.162598.jpg
[2011/05/05 13:53:13 | 000,048,686 | ---- | C] () -- C:\Users\Kristen\Documents\6.162604.jpg
[2011/05/05 13:51:49 | 000,042,682 | ---- | C] () -- C:\Users\Kristen\Documents\484ysc.jpg
[2011/05/04 20:35:03 | 000,006,193 | ---- | C] () -- C:\Users\Kristen\Documents\la-cage-aux-folles-new-broadway-cast-recording-kelsey-grammer-douglas-hodge-cd-cover-art.jpg
[2011/05/04 20:27:59 | 006,619,211 | ---- | C] () -- C:\Users\Kristen\Documents\19 Track 19.mp3
[2011/05/04 20:19:30 | 005,039,359 | ---- | C] () -- C:\Users\Kristen\Documents\2-20 Lot's Wife.mp3
[2011/05/04 14:55:59 | 000,179,609 | ---- | C] () -- C:\Users\Kristen\Documents\tn-500_rannellswm199020412.jpg
[2011/05/03 19:31:43 | 000,001,124 | -HS- | C] () -- C:\Users\Kristen\AppData\Local\43w6lxpv7oi544k68hcx16hdbx
[2011/05/03 19:31:43 | 000,001,124 | -HS- | C] () -- C:\ProgramData\43w6lxpv7oi544k68hcx16hdbx
[2011/05/03 19:05:27 | 000,012,692 | ---- | C] () -- C:\Users\Kristen\Documents\folder.jpg
[2011/05/03 19:04:56 | 000,042,225 | ---- | C] () -- C:\Users\Kristen\Documents\tumblr_lk9syiVATL1qz8s52.jpg
[2011/05/01 20:48:49 | 000,036,190 | ---- | C] () -- C:\Users\Kristen\Documents\Douglas-Hodge-La-Cage-Aux-Folles -New-Broadway-Cast-Recording.jpg
[2011/05/01 20:40:56 | 008,361,531 | ---- | C] () -- C:\Users\Kristen\Documents\22 Track 22.mp3
[2011/04/30 14:40:34 | 000,039,429 | ---- | C] () -- C:\Users\Kristen\Documents\rannels7.jpg
[2011/04/30 14:39:33 | 000,038,842 | ---- | C] () -- C:\Users\Kristen\Documents\rannels4.jpg
[2011/04/30 14:39:26 | 000,040,236 | ---- | C] () -- C:\Users\Kristen\Documents\rannels5.jpg
[2011/04/30 13:22:40 | 000,008,789 | ---- | C] () -- C:\Users\Kristen\Documents\images.jpg
[2011/04/30 11:43:29 | 000,001,764 | ---- | C] () -- C:\Users\Public\Desktop\iTunes.lnk
[2011/04/30 11:13:21 | 000,001,826 | ---- | C] () -- C:\Users\Public\Desktop\QuickTime Player.lnk
[2011/04/30 09:18:34 | 000,000,766 | ---- | C] () -- C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2011/04/28 20:28:46 | 000,094,282 | ---- | C] () -- C:\Users\Kristen\Documents\5.160698.jpg
[2011/04/28 15:49:34 | 000,160,089 | ---- | C] () -- C:\Users\Kristen\Documents\tn-500_bww-60.jpg
[2011/04/26 15:39:21 | 000,493,921 | ---- | C] () -- C:\Users\Kristen\Documents\tumblr_liqte5BjnV1qbwghg.gif
[2011/04/26 15:38:01 | 000,496,730 | ---- | C] () -- C:\Users\Kristen\Documents\tumblr_ljevncNrIt1qbiysno1_500.gif
[2011/04/26 15:36:19 | 000,409,110 | ---- | C] () -- C:\Users\Kristen\Documents\tumblr_liql01jRkJ1qbwghg.gif
[2011/04/26 11:08:29 | 000,470,858 | ---- | C] () -- C:\Users\Kristen\Documents\tumblr_lk87l8qI2e1qgvpw5o1_400.gif
[2011/04/23 11:35:53 | 000,110,775 | ---- | C] () -- C:\Users\Kristen\Documents\eighteen.gif
[2011/04/23 11:33:02 | 004,799,866 | ---- | C] () -- C:\Users\Kristen\Documents\18-tittle-o.gif
[2011/04/21 20:56:34 | 000,001,150 | ---- | C] () -- C:\Users\Kristen\Desktop\AVG PC Tuneup 2011.lnk
[2011/04/19 16:49:35 | 000,000,000 | ---- | C] () -- C:\windows\System32\cd.dat
[2011/04/19 16:28:22 | 000,256,512 | ---- | C] () -- C:\windows\PEV.exe
[2011/04/19 16:28:22 | 000,098,816 | ---- | C] () -- C:\windows\sed.exe
[2011/04/19 16:28:22 | 000,089,088 | ---- | C] () -- C:\windows\MBR.exe
[2011/04/19 16:28:22 | 000,080,412 | ---- | C] () -- C:\windows\grep.exe
[2011/04/19 16:28:22 | 000,068,096 | ---- | C] () -- C:\windows\zip.exe
[2011/03/30 16:54:06 | 000,000,132 | ---- | C] () -- C:\Users\Kristen\AppData\Roaming\Adobe IllExport Filter CS5 Prefs
[2011/01/08 11:11:19 | 000,000,132 | ---- | C] () -- C:\Users\Kristen\AppData\Roaming\Adobe GIF Format CS5 Prefs
[2011/01/02 20:10:13 | 000,000,132 | ---- | C] () -- C:\Users\Kristen\AppData\Roaming\Adobe PNG Format CS5 Prefs
[2010/12/31 20:28:45 | 000,001,456 | ---- | C] () -- C:\Users\Kristen\AppData\Local\Adobe Save for Web 12.0 Prefs
[2010/10/15 15:32:49 | 000,000,056 | ---- | C] () -- C:\ProgramData\ezsidmv.dat
[2010/10/08 14:57:02 | 000,000,857 | ---- | C] () -- C:\Program Files\Downloads.lnk
[2010/06/02 02:21:20 | 000,000,000 | ---- | C] () -- C:\windows\NDSTray.INI
[2010/02/21 02:16:08 | 000,439,308 | ---- | C] () -- C:\windows\System32\igcompkrng500.bin
[2010/02/21 02:16:06 | 000,982,240 | ---- | C] () -- C:\windows\System32\igkrng500.bin
[2010/02/21 02:16:06 | 000,092,356 | ---- | C] () -- C:\windows\System32\igfcg500m.bin
[2010/02/21 01:32:46 | 000,000,151 | ---- | C] () -- C:\windows\System32\GfxUI.exe.config
[2010/02/21 01:27:36 | 000,208,896 | ---- | C] () -- C:\windows\System32\iglhsip32.dll
[2010/02/21 01:27:36 | 000,143,360 | ---- | C] () -- C:\windows\System32\iglhcp32.dll
[2009/07/14 14:57:37 | 000,067,584 | --S- | C] () -- C:\windows\bootstat.dat
[2009/07/14 14:33:53 | 003,765,888 | ---- | C] () -- C:\windows\System32\FNTCACHE.DAT
[2009/07/14 12:05:48 | 000,717,520 | ---- | C] () -- C:\windows\System32\perfh009.dat
[2009/07/14 12:05:48 | 000,291,294 | ---- | C] () -- C:\windows\System32\perfi009.dat
[2009/07/14 12:05:48 | 000,143,214 | ---- | C] () -- C:\windows\System32\perfc009.dat
[2009/07/14 12:05:48 | 000,031,548 | ---- | C] () -- C:\windows\System32\perfd009.dat
[2009/07/14 12:05:05 | 000,000,741 | ---- | C] () -- C:\windows\System32\NOISE.DAT
[2009/07/14 12:04:11 | 000,215,943 | ---- | C] () -- C:\windows\System32\dssec.dat
[2009/07/14 09:55:01 | 000,043,131 | ---- | C] () -- C:\windows\mib.bin
[2009/07/14 09:51:43 | 000,073,728 | ---- | C] () -- C:\windows\System32\BthpanContextHandler.dll
[2009/07/14 09:42:10 | 000,064,000 | ---- | C] () -- C:\windows\System32\BWContextHandler.dll
[2009/07/14 08:09:19 | 000,139,824 | ---- | C] () -- C:\windows\System32\igfcg500.bin
[2009/06/11 07:26:10 | 000,673,088 | ---- | C] () -- C:\windows\System32\mlang.dat

========== Alternate Data Streams ==========

@Alternate Data Stream - 146 bytes -> C:\ProgramData\TEMP:0B4227B4

< End of report >

I ran Avast two times and both times it found nothing.

aswMBR log:

aswMBR version 0.9.5.256 Copyright© 2011 AVAST Software
Run date: 2011-05-06 19:11:35
-----------------------------
19:11:35.667 OS Version: Windows 6.1.7600
19:11:35.667 Number of processors: 2 586 0x170A
19:11:35.667 ComputerName: KRISTEN-PC UserName: Kristen
19:11:37.539 Initialize success
19:11:41.875 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-1
19:11:41.875 Disk 0 Vendor: TOSHIBA_ GJ00 Size: 238475MB BusType: 3
19:11:41.938 Disk 0 MBR read successfully
19:11:41.938 Disk 0 MBR scan
19:11:41.953 Disk 0 unknown MBR code
19:11:41.953 Disk 0 scanning sectors +488396800
19:11:41.985 Disk 0 scanning C:\windows\system32\drivers
19:11:46.852 Service scanning
19:11:47.803 Disk 0 trace - called modules:
19:11:47.835 ntkrnlpa.exe CLASSPNP.SYS disk.sys >>UNKNOWN [0x862eb1ed]<<
19:11:47.850 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x862bf990]
19:11:47.850 3 CLASSPNP.SYS[88dbb59e] -> nt!IofCallDriver -> \Device\Ide\IAAStorageDevice-1[0x85883028]
19:11:47.850 \Driver\iaStor[0x8587bbd0] -> IRP_MJ_INTERNAL_DEVICE_CONTROL -> 0x862eb1ed
19:11:47.866 Scan finished successfully
19:11:57.647 Disk 0 MBR has been saved successfully to "C:\Users\Kristen\Documents\MBR.dat"
19:11:57.678 The log file has been saved successfully to "C:\Users\Kristen\Documents\aswMBR.txt"

I still can't open TDSSKiller.
  • 0

#12
RKinner

RKinner

    Malware Expert

  • Expert
  • 24,598 posts
  • MVP
Copy the text between the lines of stars by highlighting and Ctrl + c.

******************************************

Killall::

DirLook::
C:\Program Files\Common
%user%\library

File::
C:\Users\Kristen\AppData\Local\43w6lxpv7oi544k68hcx16hdbx
C:\ProgramData\43w6lxpv7oi544k68hcx16hdbx


Folder::
C:\Users\Kristen\AppData\Local\{038D2EB3-91FE-4250-BCB7-5FB17F321E29}
C:\Users\Kristen\AppData\Local\{502A66C5-D4B4-4B61-B691-B2ECAD62A79C}
C:\Users\Kristen\AppData\Local\{B4653880-4CD2-47AA-8B31-931A8C5E636E}
C:\Users\Kristen\AppData\Local\{F6EC0949-ED62-406D-91B3-1578F2F76A32}
C:\Users\Kristen\AppData\Local\{4721D940-7AF7-4B03-8412-68C4BECA2B21}
C:\$AVG

RootKit::
C:\Users\Kristen\AppData\Local\43w6lxpv7oi544k68hcx16hdbx
C:\ProgramData\43w6lxpv7oi544k68hcx16hdbx



******************************************

Now open notepad (Start, Run, notepad, OK) and Ctrl + V to paste the text into Notepad. Make sure you got it all then File, SAVE AS, (to your Desktop), CFScript , OK. Close notepad. (Overwrite the old one if it's still there.) You should see a file CFScript.txt on your desktop.

Pause your anti-virus.

Drag it over to george and let it start as before.

Post the new log.

I'm afraid we may need to repair the MBR which is always a bit risky. What make and model PC is this? Do you have the win 7 disk?



Ron
  • 0






Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP