Jump to content

Welcome to Geeks to Go - Register now for FREE

Need help with your computer or device? Want to learn new tech skills? You're in the right place!
Geeks to Go is a friendly community of tech experts who can solve any problem you have. Just create a free account and post your question. Our volunteers will reply quickly and guide you through the steps. Don't let tech troubles stop you. Join Geeks to Go now and get the support you need!

How it Works Create Account
Photo

badjoke infection


  • This topic is locked This topic is locked

#1
jhnb

jhnb

    Member

  • Member
  • PipPip
  • 17 posts
i recently took my laptop out of storage(4 months), it seemed to be working perfectly before this, i could get online and the machine was running ok considering its quite old. anyway, i booted it up and tried to log online but it wasnt showing my dongle to be registering. the dongle gets online perfectly fine on another computer so i know its something in my system. this was the same as what happened last year, it took quite a time to remove the infection then and it seemed to be fine. that was nearly a year ago but here is the thread:

http://www.geekstogo...d/page__st__30

so i tried tfc, cleared it all out but still nothing, i ran mbam but that showed nothing either. i have run an avg scan also nothing. as im unable to get online i came to a cyber cafe and DLed some tools onto a flash, i got kaspersky, avast, dr web, hijackthis, superantispyware and combofix(notused yet). so i run all the scans and when i ran kaspersky it showed quite a list of threats, i have attached a copy of the log. the badjoke thing that i had before was also on there, but i dont think kaspersky has removed it. i have also attached an otl log as i am unable to get online, i will have to get onto g2g whenever i can for now. i left superantispyware running a scan before i left this morning, i will get back with the results asap. i thank you guys in advance, you saved my neck last year and am still very grateful for that too.

Attached Thumbnails

  • kaspres.jpg

Attached Files

  • Attached File  OTL.Txt   62.98KB   127 downloads

Edited by jhnb, 11 May 2011 - 04:59 AM.

  • 0

Advertisements


#2
jhnb

jhnb

    Member

  • Topic Starter
  • Member
  • PipPip
  • 17 posts
just to add, if you could give me a list of all the tools i am likely to need and i can DL the installers onto a flash to use when i get home. i wont be able to DL anything at home for now. thanx

EDIT(today 5/11/11)** so sas removed 207 cookies and another 3 trojan infections, still couldnt get online so i ran dr web which also found a further 3 when i did a deep scan(took 4 hours but the quick scan returned nothing first), although 1 of them was an installer for graboid so i'm not sure if that was a false p or what. i have just installed an update copy of mbam onto my flash(dont know why i didnt think off it before) so i will try again with that when i get home. i've been surprised that mbam hasn't found anything as it usually does, but then it is 4 months out of date but then so is the infection. i've scanned with all the others again but none of them have found anything further so far. the machine will still not get online, it just shows the no modem connected symbol and no sim symbol. i will do another otl before i come back tomorrow and post a current log as things may have changed since the one i did yesterday.

thanks again.

EDIT(5/12/11)** just thought i'd post an up to date otl and i will put the sas log too, so you can see what infections it found.


SAS 1:

SUPERAntiSpyware Scan Log
http://www.superantispyware.com

Generated 05/10/2011 at 09:58 AM

Application Version : 4.52.1000

Core Rules Database Version : 7015
Trace Rules Database Version: 4827

Scan type : Complete Scan
Total Scan Time : 00:11:14

Memory items scanned : 402
Memory threats detected : 0
Registry items scanned : 5690
Registry threats detected : 6
File items scanned : 5
File threats detected : 1

Trojan.Agent/Gen
HKLM\System\ControlSet001\Services\utezmtyx
C:\WINDOWS\SYSTEM32\DRIVERS\UTEZMTYX.SYS
HKLM\System\ControlSet001\Enum\Root\LEGACY_utezmtyx
HKLM\System\ControlSet003\Services\utezmtyx
HKLM\System\ControlSet003\Enum\Root\LEGACY_utezmtyx
HKLM\System\CurrentControlSet\Services\utezmtyx
HKLM\System\CurrentControlSet\Enum\Root\LEGACY_utezmtyx

SAS2:

SUPERAntiSpyware Scan Log
http://www.superantispyware.com

Generated 05/10/2011 at 04:43 PM

Application Version : 4.52.1000

Core Rules Database Version : 7015
Trace Rules Database Version: 4827

Scan type : Complete Scan
Total Scan Time : 00:56:15

Memory items scanned : 388
Memory threats detected : 0
Registry items scanned : 5685
Registry threats detected : 0
File items scanned : 21718
File threats detected : 210

Adware.Tracking Cookie
.advertising.com [ C:\Documents and Settings\jhn barrett\Local Settings\Application Data\Google\Chrome\User Data\Default\Cookies ]
.atdmt.com [ C:\Documents and Settings\jhn barrett\Local Settings\Application Data\Google\Chrome\User Data\Default\Cookies ]
.imrworldwide.com [ C:\Documents and Settings\jhn barrett\Local Settings\Application Data\Google\Chrome\User Data\Default\Cookies ]
.imrworldwide.com [ C:\Documents and Settings\jhn barrett\Local Settings\Application Data\Google\Chrome\User Data\Default\Cookies ]
.atdmt.com [ C:\Documents and Settings\jhn barrett\Local Settings\Application Data\Google\Chrome\User Data\Default\Cookies ]
.mediaplex.com [ C:\Documents and Settings\jhn barrett\Local Settings\Application Data\Google\Chrome\User Data\Default\Cookies ]
.revsci.net [ C:\Documents and Settings\jhn barrett\Local Settings\Application Data\Google\Chrome\User Data\Default\Cookies ]
.invitemedia.com [ C:\Documents and Settings\jhn barrett\Local Settings\Application Data\Google\Chrome\User Data\Default\Cookies ]
ad.yieldmanager.com [ C:\Documents and Settings\jhn barrett\Local Settings\Application Data\Google\Chrome\User Data\Default\Cookies ]
.lfstmedia.com [ C:\Documents and Settings\jhn barrett\Local Settings\Application Data\Google\Chrome\User Data\Default\Cookies ]
.uk.at.atwola.com [ C:\Documents and Settings\jhn barrett\Local Settings\Application Data\Google\Chrome\User Data\Default\Cookies ]
.uk.at.atwola.com [ C:\Documents and Settings\jhn barrett\Local Settings\Application Data\Google\Chrome\User Data\Default\Cookies ]
.lfstmedia.com [ C:\Documents and Settings\jhn barrett\Local Settings\Application Data\Google\Chrome\User Data\Default\Cookies ]
.adbrite.com [ C:\Documents and Settings\jhn barrett\Local Settings\Application Data\Google\Chrome\User Data\Default\Cookies ]
.youporn.com [ C:\Documents and Settings\jhn barrett\Local Settings\Application Data\Google\Chrome\User Data\Default\Cookies ]
.youporn.com [ C:\Documents and Settings\jhn barrett\Local Settings\Application Data\Google\Chrome\User Data\Default\Cookies ]
.ero-advertising.com [ C:\Documents and Settings\jhn barrett\Local Settings\Application Data\Google\Chrome\User Data\Default\Cookies ]
.youporn.com [ C:\Documents and Settings\jhn barrett\Local Settings\Application Data\Google\Chrome\User Data\Default\Cookies ]
.youporn.com [ C:\Documents and Settings\jhn barrett\Local Settings\Application Data\Google\Chrome\User Data\Default\Cookies ]
ads.youporn.com [ C:\Documents and Settings\jhn barrett\Local Settings\Application Data\Google\Chrome\User Data\Default\Cookies ]
.youporn.com [ C:\Documents and Settings\jhn barrett\Local Settings\Application Data\Google\Chrome\User Data\Default\Cookies ]
.youporn.com [ C:\Documents and Settings\jhn barrett\Local Settings\Application Data\Google\Chrome\User Data\Default\Cookies ]
.scarleteen.com [ C:\Documents and Settings\jhn barrett\Local Settings\Application Data\Google\Chrome\User Data\Default\Cookies ]
.scarleteen.com [ C:\Documents and Settings\jhn barrett\Local Settings\Application Data\Google\Chrome\User Data\Default\Cookies ]
.scarleteen.com [ C:\Documents and Settings\jhn barrett\Local Settings\Application Data\Google\Chrome\User Data\Default\Cookies ]
.scarleteen.com [ C:\Documents and Settings\jhn barrett\Local Settings\Application Data\Google\Chrome\User Data\Default\Cookies ]
ad.yieldmanager.com [ C:\Documents and Settings\jhn barrett\Local Settings\Application Data\Google\Chrome\User Data\Default\Cookies ]
.adserver.adtechus.com [ C:\Documents and Settings\jhn barrett\Local Settings\Application Data\Google\Chrome\User Data\Default\Cookies ]
.kontera.com [ C:\Documents and Settings\jhn barrett\Local Settings\Application Data\Google\Chrome\User Data\Default\Cookies ]
.apmebf.com [ C:\Documents and Settings\jhn barrett\Local Settings\Application Data\Google\Chrome\User Data\Default\Cookies ]
.ru4.com [ C:\Documents and Settings\jhn barrett\Local Settings\Application Data\Google\Chrome\User Data\Default\Cookies ]
.ru4.com [ C:\Documents and Settings\jhn barrett\Local Settings\Application Data\Google\Chrome\User Data\Default\Cookies ]
.ru4.com [ C:\Documents and Settings\jhn barrett\Local Settings\Application Data\Google\Chrome\User Data\Default\Cookies ]
.ru4.com [ C:\Documents and Settings\jhn barrett\Local Settings\Application Data\Google\Chrome\User Data\Default\Cookies ]
.tacoda.at.atwola.com [ C:\Documents and Settings\jhn barrett\Local Settings\Application Data\Google\Chrome\User Data\Default\Cookies ]
.tacoda.at.atwola.com [ C:\Documents and Settings\jhn barrett\Local Settings\Application Data\Google\Chrome\User Data\Default\Cookies ]
.tacoda.at.atwola.com [ C:\Documents and Settings\jhn barrett\Local Settings\Application Data\Google\Chrome\User Data\Default\Cookies ]
.tacoda.at.atwola.com [ C:\Documents and Settings\jhn barrett\Local Settings\Application Data\Google\Chrome\User Data\Default\Cookies ]
.tacoda.at.atwola.com [ C:\Documents and Settings\jhn barrett\Local Settings\Application Data\Google\Chrome\User Data\Default\Cookies ]
.advertising.com [ C:\Documents and Settings\jhn barrett\Local Settings\Application Data\Google\Chrome\User Data\Default\Cookies ]
.at.atwola.com [ C:\Documents and Settings\jhn barrett\Local Settings\Application Data\Google\Chrome\User Data\Default\Cookies ]
.at.atwola.com [ C:\Documents and Settings\jhn barrett\Local Settings\Application Data\Google\Chrome\User Data\Default\Cookies ]
.richmedia.yahoo.com [ C:\Documents and Settings\jhn barrett\Local Settings\Application Data\Google\Chrome\User Data\Default\Cookies ]
.adinterax.com [ C:\Documents and Settings\jhn barrett\Local Settings\Application Data\Google\Chrome\User Data\Default\Cookies ]
.adinterax.com [ C:\Documents and Settings\jhn barrett\Local Settings\Application Data\Google\Chrome\User Data\Default\Cookies ]
.overture.com [ C:\Documents and Settings\jhn barrett\Local Settings\Application Data\Google\Chrome\User Data\Default\Cookies ]
.interclick.com [ C:\Documents and Settings\jhn barrett\Local Settings\Application Data\Google\Chrome\User Data\Default\Cookies ]
.interclick.com [ C:\Documents and Settings\jhn barrett\Local Settings\Application Data\Google\Chrome\User Data\Default\Cookies ]
.bs.serving-sys.com [ C:\Documents and Settings\jhn barrett\Local Settings\Application Data\Google\Chrome\User Data\Default\Cookies ]
.serving-sys.com [ C:\Documents and Settings\jhn barrett\Local Settings\Application Data\Google\Chrome\User Data\Default\Cookies ]
.serving-sys.com [ C:\Documents and Settings\jhn barrett\Local Settings\Application Data\Google\Chrome\User Data\Default\Cookies ]
.serving-sys.com [ C:\Documents and Settings\jhn barrett\Local Settings\Application Data\Google\Chrome\User Data\Default\Cookies ]
.serving-sys.com [ C:\Documents and Settings\jhn barrett\Local Settings\Application Data\Google\Chrome\User Data\Default\Cookies ]
.xiti.com [ C:\Documents and Settings\jhn barrett\Local Settings\Application Data\Google\Chrome\User Data\Default\Cookies ]
.estat.com [ C:\Documents and Settings\jhn barrett\Local Settings\Application Data\Google\Chrome\User Data\Default\Cookies ]
.adtech.de [ C:\Documents and Settings\jhn barrett\Local Settings\Application Data\Google\Chrome\User Data\Default\Cookies ]
.ru4.com [ C:\Documents and Settings\jhn barrett\Local Settings\Application Data\Google\Chrome\User Data\Default\Cookies ]
.actionporn.info [ C:\Documents and Settings\jhn barrett\Local Settings\Application Data\Google\Chrome\User Data\Default\Cookies ]
rts.pgmediaserve.com [ C:\Documents and Settings\jhn barrett\Local Settings\Application Data\Google\Chrome\User Data\Default\Cookies ]
rts.pgmediaserve.com [ C:\Documents and Settings\jhn barrett\Local Settings\Application Data\Google\Chrome\User Data\Default\Cookies ]
rts.pgmediaserve.com [ C:\Documents and Settings\jhn barrett\Local Settings\Application Data\Google\Chrome\User Data\Default\Cookies ]
.partypoker.com [ C:\Documents and Settings\jhn barrett\Local Settings\Application Data\Google\Chrome\User Data\Default\Cookies ]
.adultfriendfinder.com [ C:\Documents and Settings\jhn barrett\Local Settings\Application Data\Google\Chrome\User Data\Default\Cookies ]
ads.zeusclicks.com [ C:\Documents and Settings\jhn barrett\Local Settings\Application Data\Google\Chrome\User Data\Default\Cookies ]
ads.crakmedia.com [ C:\Documents and Settings\jhn barrett\Local Settings\Application Data\Google\Chrome\User Data\Default\Cookies ]
.advertising.com [ C:\Documents and Settings\jhn barrett\Local Settings\Application Data\Google\Chrome\User Data\Default\Cookies ]
ad.yieldmanager.com [ C:\Documents and Settings\jhn barrett\Local Settings\Application Data\Google\Chrome\User Data\Default\Cookies ]
.invitemedia.com [ C:\Documents and Settings\jhn barrett\Local Settings\Application Data\Google\Chrome\User Data\Default\Cookies ]
.adbrite.com [ C:\Documents and Settings\jhn barrett\Local Settings\Application Data\Google\Chrome\User Data\Default\Cookies ]
.adbrite.com [ C:\Documents and Settings\jhn barrett\Local Settings\Application Data\Google\Chrome\User Data\Default\Cookies ]
.adbrite.com [ C:\Documents and Settings\jhn barrett\Local Settings\Application Data\Google\Chrome\User Data\Default\Cookies ]
ads.ventivmedia.com [ C:\Documents and Settings\jhn barrett\Local Settings\Application Data\Google\Chrome\User Data\Default\Cookies ]
.adultfriendfinder.com [ C:\Documents and Settings\jhn barrett\Local Settings\Application Data\Google\Chrome\User Data\Default\Cookies ]
.adultadworld.com [ C:\Documents and Settings\jhn barrett\Local Settings\Application Data\Google\Chrome\User Data\Default\Cookies ]
.adultadworld.com [ C:\Documents and Settings\jhn barrett\Local Settings\Application Data\Google\Chrome\User Data\Default\Cookies ]
.adultadworld.com [ C:\Documents and Settings\jhn barrett\Local Settings\Application Data\Google\Chrome\User Data\Default\Cookies ]
.adultadworld.com [ C:\Documents and Settings\jhn barrett\Local Settings\Application Data\Google\Chrome\User Data\Default\Cookies ]
.adultadworld.com [ C:\Documents and Settings\jhn barrett\Local Settings\Application Data\Google\Chrome\User Data\Default\Cookies ]
.nextag.co.uk [ C:\Documents and Settings\jhn barrett\Local Settings\Application Data\Google\Chrome\User Data\Default\Cookies ]
.nextag.co.uk [ C:\Documents and Settings\jhn barrett\Local Settings\Application Data\Google\Chrome\User Data\Default\Cookies ]
.stats.imagereverb.com [ C:\Documents and Settings\jhn barrett\Local Settings\Application Data\Google\Chrome\User Data\Default\Cookies ]
.stats.imagereverb.com [ C:\Documents and Settings\jhn barrett\Local Settings\Application Data\Google\Chrome\User Data\Default\Cookies ]
.stats.imagereverb.com [ C:\Documents and Settings\jhn barrett\Local Settings\Application Data\Google\Chrome\User Data\Default\Cookies ]
.stats.imagereverb.com [ C:\Documents and Settings\jhn barrett\Local Settings\Application Data\Google\Chrome\User Data\Default\Cookies ]
.stats.imagereverb.com [ C:\Documents and Settings\jhn barrett\Local Settings\Application Data\Google\Chrome\User Data\Default\Cookies ]
.ero-advertising.com [ C:\Documents and Settings\jhn barrett\Local Settings\Application Data\Google\Chrome\User Data\Default\Cookies ]
.ero-advertising.com [ C:\Documents and Settings\jhn barrett\Local Settings\Application Data\Google\Chrome\User Data\Default\Cookies ]
.ero-advertising.com [ C:\Documents and Settings\jhn barrett\Local Settings\Application Data\Google\Chrome\User Data\Default\Cookies ]
.ero-advertising.com [ C:\Documents and Settings\jhn barrett\Local Settings\Application Data\Google\Chrome\User Data\Default\Cookies ]
.stats.imagereverb.com [ C:\Documents and Settings\jhn barrett\Local Settings\Application Data\Google\Chrome\User Data\Default\Cookies ]
.adultfriendfinder.com [ C:\Documents and Settings\jhn barrett\Local Settings\Application Data\Google\Chrome\User Data\Default\Cookies ]
.adultfriendfinder.com [ C:\Documents and Settings\jhn barrett\Local Settings\Application Data\Google\Chrome\User Data\Default\Cookies ]
.adultfriendfinder.com [ C:\Documents and Settings\jhn barrett\Local Settings\Application Data\Google\Chrome\User Data\Default\Cookies ]
.adultfriendfinder.com [ C:\Documents and Settings\jhn barrett\Local Settings\Application Data\Google\Chrome\User Data\Default\Cookies ]
.adultfriendfinder.com [ C:\Documents and Settings\jhn barrett\Local Settings\Application Data\Google\Chrome\User Data\Default\Cookies ]
.adultfriendfinder.com [ C:\Documents and Settings\jhn barrett\Local Settings\Application Data\Google\Chrome\User Data\Default\Cookies ]
.adultfriendfinder.com [ C:\Documents and Settings\jhn barrett\Local Settings\Application Data\Google\Chrome\User Data\Default\Cookies ]
.adultfriendfinder.com [ C:\Documents and Settings\jhn barrett\Local Settings\Application Data\Google\Chrome\User Data\Default\Cookies ]
.adultfriendfinder.com [ C:\Documents and Settings\jhn barrett\Local Settings\Application Data\Google\Chrome\User Data\Default\Cookies ]
.invitemedia.com [ C:\Documents and Settings\jhn barrett\Local Settings\Application Data\Google\Chrome\User Data\Default\Cookies ]
ad.yieldmanager.com [ C:\Documents and Settings\jhn barrett\Local Settings\Application Data\Google\Chrome\User Data\Default\Cookies ]
.beachstreetmedia.com [ C:\Documents and Settings\jhn barrett\Local Settings\Application Data\Google\Chrome\User Data\Default\Cookies ]
.serving-sys.com [ C:\Documents and Settings\jhn barrett\Local Settings\Application Data\Google\Chrome\User Data\Default\Cookies ]
fidelity.rotator.hadj7.adjuggler.net [ C:\Documents and Settings\jhn barrett\Local Settings\Application Data\Google\Chrome\User Data\Default\Cookies ]
.specificclick.net [ C:\Documents and Settings\jhn barrett\Local Settings\Application Data\Google\Chrome\User Data\Default\Cookies ]
.specificclick.net [ C:\Documents and Settings\jhn barrett\Local Settings\Application Data\Google\Chrome\User Data\Default\Cookies ]
.specificclick.net [ C:\Documents and Settings\jhn barrett\Local Settings\Application Data\Google\Chrome\User Data\Default\Cookies ]
.specificclick.net [ C:\Documents and Settings\jhn barrett\Local Settings\Application Data\Google\Chrome\User Data\Default\Cookies ]
.stats.complex.com [ C:\Documents and Settings\jhn barrett\Local Settings\Application Data\Google\Chrome\User Data\Default\Cookies ]
.stats.complex.com [ C:\Documents and Settings\jhn barrett\Local Settings\Application Data\Google\Chrome\User Data\Default\Cookies ]
.stats.complex.com [ C:\Documents and Settings\jhn barrett\Local Settings\Application Data\Google\Chrome\User Data\Default\Cookies ]
.content.yieldmanager.com [ C:\Documents and Settings\jhn barrett\Local Settings\Application Data\Google\Chrome\User Data\Default\Cookies ]
.content.yieldmanager.com [ C:\Documents and Settings\jhn barrett\Local Settings\Application Data\Google\Chrome\User Data\Default\Cookies ]
.pro-market.net [ C:\Documents and Settings\jhn barrett\Local Settings\Application Data\Google\Chrome\User Data\Default\Cookies ]
counters.gigya.com [ C:\Documents and Settings\jhn barrett\Local Settings\Application Data\Google\Chrome\User Data\Default\Cookies ]
s05.flagcounter.com [ C:\Documents and Settings\jhn barrett\Local Settings\Application Data\Google\Chrome\User Data\Default\Cookies ]
.media6degrees.com [ C:\Documents and Settings\jhn barrett\Local Settings\Application Data\Google\Chrome\User Data\Default\Cookies ]
.revsci.net [ C:\Documents and Settings\jhn barrett\Local Settings\Application Data\Google\Chrome\User Data\Default\Cookies ]
.adviva.net [ C:\Documents and Settings\jhn barrett\Local Settings\Application Data\Google\Chrome\User Data\Default\Cookies ]
.adviva.net [ C:\Documents and Settings\jhn barrett\Local Settings\Application Data\Google\Chrome\User Data\Default\Cookies ]
.zedo.com [ C:\Documents and Settings\jhn barrett\Local Settings\Application Data\Google\Chrome\User Data\Default\Cookies ]
.zedo.com [ C:\Documents and Settings\jhn barrett\Local Settings\Application Data\Google\Chrome\User Data\Default\Cookies ]
.zedo.com [ C:\Documents and Settings\jhn barrett\Local Settings\Application Data\Google\Chrome\User Data\Default\Cookies ]
.yadro.ru [ C:\Documents and Settings\jhn barrett\Local Settings\Application Data\Google\Chrome\User Data\Default\Cookies ]
.questionmarket.com [ C:\Documents and Settings\jhn barrett\Local Settings\Application Data\Google\Chrome\User Data\Default\Cookies ]
.questionmarket.com [ C:\Documents and Settings\jhn barrett\Local Settings\Application Data\Google\Chrome\User Data\Default\Cookies ]
.kantarmedia.com [ C:\Documents and Settings\jhn barrett\Local Settings\Application Data\Google\Chrome\User Data\Default\Cookies ]
.kantarmedia.com [ C:\Documents and Settings\jhn barrett\Local Settings\Application Data\Google\Chrome\User Data\Default\Cookies ]
.revsci.net [ C:\Documents and Settings\jhn barrett\Local Settings\Application Data\Google\Chrome\User Data\Default\Cookies ]
.adfarm1.adition.com [ C:\Documents and Settings\jhn barrett\Local Settings\Application Data\Google\Chrome\User Data\Default\Cookies ]
adfarm1.adition.com [ C:\Documents and Settings\jhn barrett\Local Settings\Application Data\Google\Chrome\User Data\Default\Cookies ]
.click2sell.eu [ C:\Documents and Settings\jhn barrett\Local Settings\Application Data\Google\Chrome\User Data\Default\Cookies ]
.ru4.com [ C:\Documents and Settings\jhn barrett\Local Settings\Application Data\Google\Chrome\User Data\Default\Cookies ]
.mediaplex.com [ C:\Documents and Settings\jhn barrett\Local Settings\Application Data\Google\Chrome\User Data\Default\Cookies ]
.mediaplex.com [ C:\Documents and Settings\jhn barrett\Local Settings\Application Data\Google\Chrome\User Data\Default\Cookies ]
.mediabrandsww.com [ C:\Documents and Settings\jhn barrett\Local Settings\Application Data\Google\Chrome\User Data\Default\Cookies ]
user.lucidmedia.com [ C:\Documents and Settings\jhn barrett\Local Settings\Application Data\Google\Chrome\User Data\Default\Cookies ]
.adecn.com [ C:\Documents and Settings\jhn barrett\Local Settings\Application Data\Google\Chrome\User Data\Default\Cookies ]
ad.yieldmanager.com [ C:\Documents and Settings\jhn barrett\Local Settings\Application Data\Google\Chrome\User Data\Default\Cookies ]
.adbrite.com [ C:\Documents and Settings\jhn barrett\Local Settings\Application Data\Google\Chrome\User Data\Default\Cookies ]
.adxpose.com [ C:\Documents and Settings\jhn barrett\Local Settings\Application Data\Google\Chrome\User Data\Default\Cookies ]
.doubleclick.net [ C:\Documents and Settings\jhn barrett\Local Settings\Application Data\Google\Chrome\User Data\Default\Cookies ]
.yieldmanager.net [ C:\Documents and Settings\jhn barrett\Local Settings\Application Data\Google\Chrome\User Data\Default\Cookies ]
.adbrite.com [ C:\Documents and Settings\jhn barrett\Local Settings\Application Data\Google\Chrome\User Data\Default\Cookies ]
.invitemedia.com [ C:\Documents and Settings\jhn barrett\Local Settings\Application Data\Google\Chrome\User Data\Default\Cookies ]
.invitemedia.com [ C:\Documents and Settings\jhn barrett\Local Settings\Application Data\Google\Chrome\User Data\Default\Cookies ]
.zedo.com [ C:\Documents and Settings\jhn barrett\Local Settings\Application Data\Google\Chrome\User Data\Default\Cookies ]
.zedo.com [ C:\Documents and Settings\jhn barrett\Local Settings\Application Data\Google\Chrome\User Data\Default\Cookies ]
.fastclick.net [ C:\Documents and Settings\jhn barrett\Local Settings\Application Data\Google\Chrome\User Data\Default\Cookies ]
.virginmedia.com [ C:\Documents and Settings\jhn barrett\Local Settings\Application Data\Google\Chrome\User Data\Default\Cookies ]
www.virginmedia.com [ C:\Documents and Settings\jhn barrett\Local Settings\Application Data\Google\Chrome\User Data\Default\Cookies ]
www.virginmedia.com [ C:\Documents and Settings\jhn barrett\Local Settings\Application Data\Google\Chrome\User Data\Default\Cookies ]
.virginmedia.com [ C:\Documents and Settings\jhn barrett\Local Settings\Application Data\Google\Chrome\User Data\Default\Cookies ]
.revsci.net [ C:\Documents and Settings\jhn barrett\Local Settings\Application Data\Google\Chrome\User Data\Default\Cookies ]
www.virginmedia.com [ C:\Documents and Settings\jhn barrett\Local Settings\Application Data\Google\Chrome\User Data\Default\Cookies ]
.flavourmediagroup.com [ C:\Documents and Settings\jhn barrett\Local Settings\Application Data\Google\Chrome\User Data\Default\Cookies ]
.flavourmediagroup.com [ C:\Documents and Settings\jhn barrett\Local Settings\Application Data\Google\Chrome\User Data\Default\Cookies ]
.flavourmediagroup.com [ C:\Documents and Settings\jhn barrett\Local Settings\Application Data\Google\Chrome\User Data\Default\Cookies ]
www.flavourmediagroup.com [ C:\Documents and Settings\jhn barrett\Local Settings\Application Data\Google\Chrome\User Data\Default\Cookies ]
.collective-media.net [ C:\Documents and Settings\jhn barrett\Local Settings\Application Data\Google\Chrome\User Data\Default\Cookies ]
.collective-media.net [ C:\Documents and Settings\jhn barrett\Local Settings\Application Data\Google\Chrome\User Data\Default\Cookies ]
.collective-media.net [ C:\Documents and Settings\jhn barrett\Local Settings\Application Data\Google\Chrome\User Data\Default\Cookies ]
.collective-media.net [ C:\Documents and Settings\jhn barrett\Local Settings\Application Data\Google\Chrome\User Data\Default\Cookies ]
.collective-media.net [ C:\Documents and Settings\jhn barrett\Local Settings\Application Data\Google\Chrome\User Data\Default\Cookies ]
.media6degrees.com [ C:\Documents and Settings\jhn barrett\Local Settings\Application Data\Google\Chrome\User Data\Default\Cookies ]
.collective-media.net [ C:\Documents and Settings\jhn barrett\Local Settings\Application Data\Google\Chrome\User Data\Default\Cookies ]
.tribalfusion.com [ C:\Documents and Settings\jhn barrett\Local Settings\Application Data\Google\Chrome\User Data\Default\Cookies ]
.media6degrees.com [ C:\Documents and Settings\jhn barrett\Local Settings\Application Data\Google\Chrome\User Data\Default\Cookies ]
.media6degrees.com [ C:\Documents and Settings\jhn barrett\Local Settings\Application Data\Google\Chrome\User Data\Default\Cookies ]
.media6degrees.com [ C:\Documents and Settings\jhn barrett\Local Settings\Application Data\Google\Chrome\User Data\Default\Cookies ]
.media6degrees.com [ C:\Documents and Settings\jhn barrett\Local Settings\Application Data\Google\Chrome\User Data\Default\Cookies ]
.serving-sys.com [ C:\Documents and Settings\jhn barrett\Local Settings\Application Data\Google\Chrome\User Data\Default\Cookies ]
.serving-sys.com [ C:\Documents and Settings\jhn barrett\Local Settings\Application Data\Google\Chrome\User Data\Default\Cookies ]
.bs.serving-sys.com [ C:\Documents and Settings\jhn barrett\Local Settings\Application Data\Google\Chrome\User Data\Default\Cookies ]
.advertising.com [ C:\Documents and Settings\jhn barrett\Local Settings\Application Data\Google\Chrome\User Data\Default\Cookies ]
.advertising.com [ C:\Documents and Settings\jhn barrett\Local Settings\Application Data\Google\Chrome\User Data\Default\Cookies ]
.advertising.com [ C:\Documents and Settings\jhn barrett\Local Settings\Application Data\Google\Chrome\User Data\Default\Cookies ]
.advertising.com [ C:\Documents and Settings\jhn barrett\Local Settings\Application Data\Google\Chrome\User Data\Default\Cookies ]
.virginmedia.com [ C:\Documents and Settings\jhn barrett\Local Settings\Application Data\Google\Chrome\User Data\Default\Cookies ]
.virginmedia.com [ C:\Documents and Settings\jhn barrett\Local Settings\Application Data\Google\Chrome\User Data\Default\Cookies ]
.revsci.net [ C:\Documents and Settings\jhn barrett\Local Settings\Application Data\Google\Chrome\User Data\Default\Cookies ]
.revsci.net [ C:\Documents and Settings\jhn barrett\Local Settings\Application Data\Google\Chrome\User Data\Default\Cookies ]
.revsci.net [ C:\Documents and Settings\jhn barrett\Local Settings\Application Data\Google\Chrome\User Data\Default\Cookies ]
.revsci.net [ C:\Documents and Settings\jhn barrett\Local Settings\Application Data\Google\Chrome\User Data\Default\Cookies ]
.virginmedia.com [ C:\Documents and Settings\jhn barrett\Local Settings\Application Data\Google\Chrome\User Data\Default\Cookies ]
ad.yieldmanager.com [ C:\Documents and Settings\jhn barrett\Local Settings\Application Data\Google\Chrome\User Data\Default\Cookies ]
.zedo.com [ C:\Documents and Settings\jhn barrett\Local Settings\Application Data\Google\Chrome\User Data\Default\Cookies ]
.zedo.com [ C:\Documents and Settings\jhn barrett\Local Settings\Application Data\Google\Chrome\User Data\Default\Cookies ]
.zedo.com [ C:\Documents and Settings\jhn barrett\Local Settings\Application Data\Google\Chrome\User Data\Default\Cookies ]
.statcounter.com [ C:\Documents and Settings\jhn barrett\Local Settings\Application Data\Google\Chrome\User Data\Default\Cookies ]
.invitemedia.com [ C:\Documents and Settings\jhn barrett\Local Settings\Application Data\Google\Chrome\User Data\Default\Cookies ]
.invitemedia.com [ C:\Documents and Settings\jhn barrett\Local Settings\Application Data\Google\Chrome\User Data\Default\Cookies ]
.invitemedia.com [ C:\Documents and Settings\jhn barrett\Local Settings\Application Data\Google\Chrome\User Data\Default\Cookies ]
.invitemedia.com [ C:\Documents and Settings\jhn barrett\Local Settings\Application Data\Google\Chrome\User Data\Default\Cookies ]
.fastclick.net [ C:\Documents and Settings\jhn barrett\Local Settings\Application Data\Google\Chrome\User Data\Default\Cookies ]
.fastclick.net [ C:\Documents and Settings\jhn barrett\Local Settings\Application Data\Google\Chrome\User Data\Default\Cookies ]
.fastclick.net [ C:\Documents and Settings\jhn barrett\Local Settings\Application Data\Google\Chrome\User Data\Default\Cookies ]
.adbrite.com [ C:\Documents and Settings\jhn barrett\Local Settings\Application Data\Google\Chrome\User Data\Default\Cookies ]
.adbrite.com [ C:\Documents and Settings\jhn barrett\Local Settings\Application Data\Google\Chrome\User Data\Default\Cookies ]
.adbrite.com [ C:\Documents and Settings\jhn barrett\Local Settings\Application Data\Google\Chrome\User Data\Default\Cookies ]
.etargetnet.com [ C:\Documents and Settings\jhn barrett\Local Settings\Application Data\Google\Chrome\User Data\Default\Cookies ]
.toplist.sk [ C:\Documents and Settings\jhn barrett\Local Settings\Application Data\Google\Chrome\User Data\Default\Cookies ]
ad.yieldmanager.com [ C:\Documents and Settings\jhn barrett\Local Settings\Application Data\Google\Chrome\User Data\Default\Cookies ]
ad.yieldmanager.com [ C:\Documents and Settings\jhn barrett\Local Settings\Application Data\Google\Chrome\User Data\Default\Cookies ]
ad.yieldmanager.com [ C:\Documents and Settings\jhn barrett\Local Settings\Application Data\Google\Chrome\User Data\Default\Cookies ]
ad.yieldmanager.com [ C:\Documents and Settings\jhn barrett\Local Settings\Application Data\Google\Chrome\User Data\Default\Cookies ]
sk.search.etargetnet.com [ C:\Documents and Settings\jhn barrett\Local Settings\Application Data\Google\Chrome\User Data\Default\Cookies ]

Trojan.Agent/Gen
C:\SYSTEM VOLUME INFORMATION\_RESTORE{B1345870-9C57-4F74-84F2-0A7BFF5F33FC}\RP239\A0131690.SYS

Trojan.Vundo-Variant/F
C:\WINDOWS\SYSTEM32\AZIPCONTMN.DLL
C:\WINDOWS\SYSTEM32\SYSFOLDERAZIPCNT.DLL




OTL:

OTL logfile created on: 5/12/2011 9:33:18 AM - Run 3
OTL by OldTimer - Version 3.2.4.1 Folder = C:\Documents and Settings\jhn barrett\Desktop\Virus Removal Tools
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

251.00 Mb Total Physical Memory | 63.00 Mb Available Physical Memory | 25.00% Memory free
610.00 Mb Paging File | 415.00 Mb Available in Paging File | 68.00% Paging File free
Paging file location(s): C:\pagefile.sys 372 744 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 37.25 Gb Total Space | 14.65 Gb Free Space | 39.32% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
Drive E: | 3.91 Gb Total Space | 2.96 Gb Free Space | 75.58% Space Free | Partition Type: FAT32
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: J-C4E7983211AD4
Current User Name: jhn barrett
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: On
Skip Microsoft Files: On
File Age = 90 Days
Output = Standard
Quick Scan

========== Processes (SafeList) ==========

PRC - [2011/05/05 03:42:04 | 002,424,192 | ---- | M] (SUPERAntiSpyware.com) -- C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
PRC - [2011/04/19 03:25:12 | 003,460,784 | ---- | M] (AVAST Software) -- C:\Program Files\AVAST Software\Avast\AvastUI.exe
PRC - [2011/04/19 03:25:10 | 000,042,184 | ---- | M] (AVAST Software) -- C:\Program Files\AVAST Software\Avast\AvastSvc.exe
PRC - [2010/07/18 00:34:41 | 000,202,256 | ---- | M] (RealNetworks, Inc.) -- C:\Program Files\Common Files\Real\Update_OB\realsched.exe
PRC - [2010/06/03 10:50:58 | 001,144,104 | ---- | M] () -- C:\Program Files\DivX\DivX Update\DivXUpdate.exe
PRC - [2010/05/04 18:44:08 | 000,570,880 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\jhn barrett\Desktop\Virus Removal Tools\OTL.exe
PRC - [2008/11/10 06:48:14 | 000,602,392 | ---- | M] (Yahoo! Inc.) -- C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe
PRC - [2008/04/14 10:12:19 | 001,033,728 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe
PRC - [2004/07/02 02:23:32 | 000,067,584 | R--- | M] (Realtek Semiconductor Corp.) -- C:\WINDOWS\SOUNDMAN.EXE


========== Modules (SafeList) ==========

MOD - [2011/04/19 03:25:09 | 000,199,792 | ---- | M] (AVAST Software) -- C:\Program Files\AVAST Software\Avast\snxhk.dll
MOD - [2010/08/24 02:12:02 | 001,054,208 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.6028_x-ww_61e65202\comctl32.dll
MOD - [2010/05/04 18:44:08 | 000,570,880 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\jhn barrett\Desktop\Virus Removal Tools\OTL.exe
MOD - [2008/04/14 10:10:20 | 000,110,592 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\msscript.ocx


========== Win32 Services (SafeList) ==========

SRV - [2011/04/19 03:25:10 | 000,042,184 | ---- | M] (AVAST Software) [Auto | Running] -- C:\Program Files\AVAST Software\Avast\AvastSvc.exe -- (avast! Antivirus)
SRV - [2008/11/10 06:48:14 | 000,602,392 | ---- | M] (Yahoo! Inc.) [Auto | Running] -- C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe -- (YahooAUService)


========== Driver Services (SafeList) ==========

DRV - [2011/04/19 03:17:46 | 000,441,176 | ---- | M] (AVAST Software) [File_System | System | Running] -- C:\WINDOWS\system32\drivers\aswSnx.sys -- (aswSnx)
DRV - [2011/04/19 03:17:34 | 000,307,288 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\aswSP.sys -- (aswSP)
DRV - [2011/04/19 03:16:18 | 000,049,240 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\aswTdi.sys -- (aswTdi)
DRV - [2011/04/19 03:16:06 | 000,102,488 | ---- | M] (AVAST Software) [File_System | Auto | Running] -- C:\WINDOWS\system32\drivers\aswmon2.sys -- (aswMon2)
DRV - [2011/04/19 03:13:21 | 000,025,432 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\aswRdr.sys -- (aswRdr)
DRV - [2011/04/19 03:13:02 | 000,030,680 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\aavmker4.sys -- (Aavmker4)
DRV - [2011/04/19 03:12:58 | 000,019,544 | ---- | M] (AVAST Software) [File_System | Auto | Running] -- C:\WINDOWS\system32\drivers\aswFsBlk.sys -- (aswFsBlk)
DRV - [2010/05/11 04:41:30 | 000,067,656 | ---- | M] (SUPERAdBlocker.com and SUPERAntiSpyware.com) [Kernel | System | Running] -- C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS -- (SASKUTIL)
DRV - [2010/03/27 05:07:02 | 000,032,768 | ---- | M] (AnchorFree Inc) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\taphss.sys -- (taphss)
DRV - [2010/02/18 04:25:48 | 000,012,872 | ---- | M] (SUPERAdBlocker.com and SUPERAntiSpyware.com) [Kernel | System | Running] -- C:\Program Files\SUPERAntiSpyware\sasdifsv.sys -- (SASDIFSV)
DRV - [2009/04/10 15:58:02 | 000,105,344 | ---- | M] (Onda Communication) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ONDAusbser6k.sys -- (ONDAusbser6k)
DRV - [2009/04/10 15:58:02 | 000,105,344 | ---- | M] (Onda Communication) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\ONDAusbnmea.sys -- (ONDAusbnmea)
DRV - [2009/04/10 15:58:02 | 000,105,344 | ---- | M] (Onda Communication) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ONDAusbmdm6k.sys -- (ONDAusbmdm6k)
DRV - [2009/03/25 15:29:52 | 000,130,432 | ---- | M] (Realtek Semiconductor Corporation ) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\Rtnicxp.sys -- (RTL8023xp)
DRV - [2008/01/17 16:50:34 | 000,100,864 | ---- | M] (ZTE Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\ZTEusbser6k.sys -- (ZTEusbser6k)
DRV - [2008/01/17 16:50:34 | 000,100,864 | ---- | M] (ZTE Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ZTEusbnmea.sys -- (ZTEusbnmea)
DRV - [2008/01/17 16:50:34 | 000,100,864 | ---- | M] (ZTE Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\ZTEusbmdm6k.sys -- (ZTEusbmdm6k)
DRV - [2006/02/22 02:32:04 | 000,143,904 | ---- | M] (Winbond Electronics Corp.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\W33ND.SYS -- (W33ND)
DRV - [2004/08/04 08:31:34 | 000,020,992 | ---- | M] (Realtek Semiconductor Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\RTL8139.sys -- (rtl8139) Realtek RTL8139(A/B/C)
DRV - [2004/07/22 22:50:16 | 001,268,234 | R--- | M] (Agere Systems) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\AGRSM.sys -- (AgereSoftModem)
DRV - [2004/07/01 22:49:00 | 000,626,977 | R--- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\ALCXWDM.SYS -- (ALCXWDM) Service for Realtek AC97 Audio (WDM)
DRV - [2004/02/24 18:08:52 | 000,400,384 | R--- | M] (Sensaura) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\ALCXSENS.SYS -- (ALCXSENS)
DRV - [2003/02/26 22:38:40 | 000,037,888 | ---- | M] (Winbond Electronics Corp.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\wbfirdma.sys -- (WBFIRDMA)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========


IE - HKCU\..\URLSearchHook: {e9911ec6-1bcc-40b0-9993-e0eea7f6953f} - C:\Program Files\DVDVideoSoft\tbDVDV.dll (Conduit Ltd.)
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..browser.search.defaultthis.engineName: " "
FF - prefs.js..browser.search.defaulturl: "http://search.condui...={searchTerms}"
FF - prefs.js..browser.search.param.yahoo-fr: "chrf-ytbm"
FF - prefs.js..browser.search.param.yahoo-fr-cjkt: "chrf-ytbm"
FF - prefs.js..browser.search.param.yahoo-type: "${8}"
FF - prefs.js..browser.search.selectedEngine: " "
FF - prefs.js..extensions.enabledItems: {ABDE892B-13A8-4d1b-88E6-365A6E755758}:1.1.5
FF - prefs.js..extensions.enabledItems: [email protected]:1.2
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}:6.0.20
FF - prefs.js..extensions.enabledItems: [email protected]:1.0
FF - prefs.js..extensions.enabledItems: [email protected]:1.5.2
FF - prefs.js..extensions.enabledItems: {00bf7b9c-acd2-4080-bea8-b1c41987070f}:2.6.0.15
FF - prefs.js..extensions.enabledItems: [email protected]:1.0
FF - prefs.js..extensions.enabledItems: {635abd67-4fe9-1b23-4f01-e679fa7484c1}:2.1.1.20091029021655
FF - prefs.js..extensions.enabledItems: [email protected]:1.10.01
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}:6.0.22
FF - prefs.js..extensions.enabledItems: [email protected]:3.2.5.2
FF - prefs.js..extensions.enabledItems: {bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}:3.2.5.2
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}:6.0.23
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}:6.0.24
FF - prefs.js..extensions.enabledItems: [email protected]:20110101


FF - HKLM\software\mozilla\Firefox\Extensions\\{ABDE892B-13A8-4d1b-88E6-365A6E755758}: C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext [2010/07/18 00:40:08 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\[email protected]: C:\Program Files\AVAST Software\Avast\WebRep\FF [2011/05/09 20:11:27 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\K-Meleon\Extensions\\Plugins: C:\Program Files\K-Meleon\Plugins [2010/07/18 00:41:46 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\K-Meleon\Extensions\\Components: C:\Program Files\K-Meleon\Components [2010/07/18 09:31:37 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.12\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010/10/28 00:00:05 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.12\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010/11/02 20:27:21 | 000,000,000 | ---D | M]

[2010/04/14 09:52:30 | 000,000,000 | ---D | M] -- C:\Documents and Settings\jhn barrett\Application Data\Mozilla\Extensions
[2010/04/08 11:42:36 | 000,000,000 | ---D | M] -- C:\Documents and Settings\jhn barrett\Application Data\Mozilla\Extensions\[email protected]
[2011/05/11 16:04:34 | 000,000,000 | ---D | M] -- C:\Documents and Settings\jhn barrett\Application Data\Mozilla\Firefox\Profiles\i34ihir7.default\extensions
[2010/05/19 19:14:29 | 000,000,000 | ---D | M] (TranslatorBar 1 Toolbar) -- C:\Documents and Settings\jhn barrett\Application Data\Mozilla\Firefox\Profiles\i34ihir7.default\extensions\{00bf7b9c-acd2-4080-bea8-b1c41987070f}
[2010/10/25 17:37:44 | 000,000,000 | ---D | M] (Yahoo! Toolbar) -- C:\Documents and Settings\jhn barrett\Application Data\Mozilla\Firefox\Profiles\i34ihir7.default\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1}
[2009/12/11 21:47:13 | 000,000,000 | ---D | M] (uTorrentBar Community Toolbar) -- C:\Documents and Settings\jhn barrett\Application Data\Mozilla\Firefox\Profiles\i34ihir7.default\extensions\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}
[2010/04/25 02:58:25 | 000,000,000 | ---D | M] (Hotspot Shield Toolbar) -- C:\Documents and Settings\jhn barrett\Application Data\Mozilla\Firefox\Profiles\i34ihir7.default\extensions\{c95a4e8e-816d-4655-8c79-d736da1adb6d}
[2009/12/11 21:47:18 | 000,000,000 | ---D | M] -- C:\Documents and Settings\jhn barrett\Application Data\Mozilla\Firefox\Profiles\i34ihir7.default\extensions\[email protected]
[2010/10/29 01:18:43 | 000,000,000 | ---D | M] -- C:\Documents and Settings\jhn barrett\Application Data\Mozilla\Firefox\Profiles\i34ihir7.default\extensions\[email protected]
[2010/05/04 15:21:23 | 000,000,000 | ---D | M] -- C:\Documents and Settings\jhn barrett\Application Data\Mozilla\Firefox\Profiles\i34ihir7.default\extensions\[email protected]
[2010/07/22 07:17:54 | 000,000,000 | ---D | M] -- C:\Documents and Settings\jhn barrett\Application Data\Mozilla\Firefox\Profiles\i34ihir7.default\extensions\[email protected]
[2010/05/26 07:03:29 | 000,000,000 | ---D | M] -- C:\Documents and Settings\jhn barrett\Application Data\Mozilla\Firefox\Profiles\i34ihir7.default\extensions\[email protected]
[2009/12/11 21:47:13 | 000,000,863 | ---- | M] () -- C:\Documents and Settings\jhn barrett\Application Data\Mozilla\Firefox\Profiles\i34ihir7.default\searchplugins\conduit.xml
[2011/05/11 16:04:34 | 000,000,000 | ---D | M] -- C:\Program Files\Mozilla Firefox\extensions
[2010/04/18 06:10:16 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
[2010/11/11 01:14:10 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}
[2010/12/17 00:29:59 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}
[2011/05/07 18:05:13 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}
[2010/11/12 17:53:06 | 000,472,808 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\Mozilla Firefox\plugins\npdeployJava1.dll

O1 HOSTS File: ([2010/04/08 06:03:14 | 000,000,789 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (&Yahoo! Toolbar Helper) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.)
O2 - BHO: (RealPlayer Download and Record Plugin for Internet Explorer) - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll (RealPlayer)
O2 - BHO: (Conduit Engine) - {30F9B915-B755-4826-820B-08FBA6BD249D} - C:\Program Files\ConduitEngine\ConduitEngine.dll (Conduit Ltd.)
O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG9\avgssie.dll File not found
O2 - BHO: (avast! WebRep) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
O2 - BHO: (AVG Security Toolbar BHO) - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dll File not found
O2 - BHO: (DVDVideoSoft Toolbar) - {e9911ec6-1bcc-40b0-9993-e0eea7f6953f} - C:\Program Files\DVDVideoSoft\tbDVDV.dll (Conduit Ltd.)
O2 - BHO: (Yontoo Layers) - {FD72061E-9FDE-484D-A58A-0BAB4151CAD8} - C:\Program Files\Yontoo Layers Client\YontooIEClient.dll (Yontoo Technology, Inc.)
O2 - BHO: (SingleInstance Class) - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files\Yahoo!\Companion\Installs\cpn\YTSingleInstance.dll (Yahoo! Inc)
O3 - HKLM\..\Toolbar: (Conduit Engine) - {30F9B915-B755-4826-820B-08FBA6BD249D} - C:\Program Files\ConduitEngine\ConduitEngine.dll (Conduit Ltd.)
O3 - HKLM\..\Toolbar: (Show Xmlbar Toolbar) - {6B896ADB-4A82-46e2-858C-13134782CE34} - C:\Program Files\Xmlbar\Tudou Downloader\IEBar\xbietb.dll (Xmlbar.com)
O3 - HKLM\..\Toolbar: (avast! WebRep) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
O3 - HKLM\..\Toolbar: (AVG Security Toolbar) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - C:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dll File not found
O3 - HKLM\..\Toolbar: (DVDVideoSoft Toolbar) - {e9911ec6-1bcc-40b0-9993-e0eea7f6953f} - C:\Program Files\DVDVideoSoft\tbDVDV.dll (Conduit Ltd.)
O3 - HKLM\..\Toolbar: (Yahoo! Toolbar) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.)
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (AVG Security Toolbar) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - C:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dll File not found
O3 - HKCU\..\Toolbar\WebBrowser: (DVDVideoSoft Toolbar) - {E9911EC6-1BCC-40B0-9993-E0EEA7F6953F} - C:\Program Files\DVDVideoSoft\tbDVDV.dll (Conduit Ltd.)
O4 - HKLM..\Run: [avast] C:\Program Files\AVAST Software\Avast\avastUI.exe (AVAST Software)
O4 - HKLM..\Run: [DivXUpdate] C:\Program Files\DivX\DivX Update\DivXUpdate.exe ()
O4 - HKLM..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe (Ahead Software Gmbh)
O4 - HKLM..\Run: [SoundMan] C:\WINDOWS\SOUNDMAN.EXE (Realtek Semiconductor Corp.)
O4 - HKLM..\Run: [TkBellExe] C:\Program Files\Common Files\Real\Update_OB\realsched.exe (RealNetworks, Inc.)
O4 - HKCU..\Run: [KasperskyPasswordManager] C:\DOCUME~1\JHNBAR~1\LOCALS~1\Temp\Rar$EX06.652\Kaspersky.Password.Manager.4.0.0.133.Eng\stpass.exe File not found
O4 - HKCU..\Run: [msnmsgr] C:\Program Files\Windows Live\Messenger\msnmsgr.exe File not found
O4 - HKCU..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe (SUPERAntiSpyware.com)
O4 - HKLM..\RunOnce: [AvgUninstallURL] C:\WINDOWS\System32\cmd.exe (Microsoft Corporation)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoControlPanel = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 36
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = FF FF FF FF [binary data]
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoControlPanel = 0
O9 - Extra Button: Run TudouDownloader - {612F6E5C-B314-4bab-93D1-D266AAFBE700} - C:\Program Files\Xmlbar\Tudou Downloader\TudouDownloader(xmlbar).exe (Xmlbar.com, Inc.)
O9 - Extra 'Tools' menuitem : Tudou Downloader - {612F6E5C-B314-4bab-93D1-D266AAFBE700} - C:\Program Files\Xmlbar\Tudou Downloader\TudouDownloader(xmlbar).exe (Xmlbar.com, Inc.)
O16 - DPF: {05CA9FB0-3E3E-4B36-BF41-0E3A5CAA8CD8} http://go.microsoft....k/?linkid=58813 (Office Genuine Advantage Validation Tool)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://go.microsoft....k/?linkid=39204 (Windows Genuine Advantage Validation Tool)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} http://www.update.mi...b?1273029714116 (MUWebControl Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_23)
O16 - DPF: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_23)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_23)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.ad...Plus/1.6/gp.cab (Reg Error: Key error.)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\!SASWinLogon: DllName - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL (SUPERAntiSpyware.com)
O20 - Winlogon\Notify\igfxcui: DllName - igfxsrvc.dll - C:\WINDOWS\System32\igfxsrvc.dll (Intel Corporation)
O20 - Winlogon\Notify\igfxtcui: DllName - C:\documents and settings\all users\application data\jhn barrett\UpdateLogon.dll - C:\documents and settings\all users\application data\jhn barrett\UpdateLogon.dll File not found
O24 - Desktop WallPaper: C:\Documents and Settings\jhn barrett\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\jhn barrett\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O28 - HKLM ShellExecuteHooks: {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - C:\Program Files\SUPERAntiSpyware\SASSEH.DLL (SuperAdBlocker.com)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2010/03/21 03:29:50 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O32 - AutoRun File - [2010/03/26 09:02:30 | 000,000,000 | RHSD | M] - C:\autorun.inf -- [ NTFS ]
O33 - MountPoints2\{28e18500-bfa8-11df-aaa1-0040d0726735}\Shell - "" = AutoRun
O33 - MountPoints2\{28e18500-bfa8-11df-aaa1-0040d0726735}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{28e18500-bfa8-11df-aaa1-0040d0726735}\Shell\AutoRun\command - "" = E:\AutoRun.exe -- File not found
O33 - MountPoints2\F\Shell - "" = AutoRun
O33 - MountPoints2\F\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\F\Shell\AutoRun\command - "" = F:\AutoRun.exe -- File not found
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*

========== Files/Folders - Created Within 90 Days ==========

[2011/05/11 16:26:28 | 000,000,000 | ---D | C] -- C:\Program Files\Sophos
[2011/05/11 16:06:19 | 000,000,000 | ---D | C] -- C:\Avenger
[2011/05/11 15:58:36 | 000,000,000 | ---D | C] -- C:\Documents and Settings\jhn barrett\Application Data\SPE
[2011/05/11 15:47:11 | 000,038,224 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2011/05/11 15:46:54 | 000,020,952 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbam.sys
[2011/05/11 15:41:25 | 000,000,000 | ---D | C] -- C:\Program Files\Malwarebytes' Anti-Malware
[2011/05/11 02:22:41 | 000,000,000 | ---D | C] -- C:\Documents and Settings\jhn barrett\Desktop\Virus Removal Tool
[2011/05/09 20:12:39 | 000,019,544 | ---- | C] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswFsBlk.sys
[2011/05/09 20:12:38 | 000,307,288 | ---- | C] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswSP.sys
[2011/05/09 20:12:32 | 000,025,432 | ---- | C] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswRdr.sys
[2011/05/09 20:12:31 | 000,441,176 | ---- | C] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswSnx.sys
[2011/05/09 20:12:31 | 000,049,240 | ---- | C] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswTdi.sys
[2011/05/09 20:12:30 | 000,102,488 | ---- | C] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswmon2.sys
[2011/05/09 20:12:30 | 000,096,344 | ---- | C] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswmon.sys
[2011/05/09 20:12:28 | 000,030,680 | ---- | C] (AVAST Software) -- C:\WINDOWS\System32\drivers\aavmker4.sys
[2011/05/09 20:11:21 | 000,040,112 | ---- | C] (AVAST Software) -- C:\WINDOWS\avastSS.scr
[2011/05/09 20:11:20 | 000,199,304 | ---- | C] (AVAST Software) -- C:\WINDOWS\System32\aswBoot.exe
[2011/05/09 20:10:45 | 000,000,000 | ---D | C] -- C:\Program Files\AVAST Software
[2011/05/09 20:10:45 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\AVAST Software
[2011/05/09 16:23:58 | 000,000,000 | ---D | C] -- C:\Documents and Settings\jhn barrett\Application Data\SUPERAntiSpyware.com
[2011/05/09 16:23:58 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
[2011/05/09 16:23:02 | 000,000,000 | ---D | C] -- C:\Program Files\SUPERAntiSpyware
[2011/05/08 06:22:25 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\TEMP
[2011/05/07 18:46:59 | 000,100,864 | ---- | C] (ZTE Corporation) -- C:\WINDOWS\System32\drivers\ZTEusbser6k.sys
[2011/05/07 18:46:59 | 000,100,864 | ---- | C] (ZTE Corporation) -- C:\WINDOWS\System32\drivers\ZTEusbnmea.sys
[2011/05/07 18:46:59 | 000,100,864 | ---- | C] (ZTE Corporation) -- C:\WINDOWS\System32\drivers\ZTEusbmdm6k.sys
[2011/05/07 18:46:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\SupportApp
[2011/05/07 18:46:15 | 000,000,000 | ---D | C] -- C:\Program Files\ZTE Mobile Connection
[2011/05/07 18:46:06 | 000,000,000 | -H-D | C] -- C:\Program Files\InstallShield Installation Information
[2011/05/07 18:05:10 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Java
[2011/05/07 18:05:09 | 000,000,000 | ---D | C] -- C:\Config.Msi
[2011/05/07 12:18:33 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\SupportApp(2)
[2011/05/07 12:18:15 | 000,000,000 | ---D | C] -- C:\Program Files\InstallShield Installation Information(2)
[2011/03/01 18:30:41 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\NOS
[2011/02/28 20:24:18 | 000,000,000 | ---D | C] -- C:\a5d3f12fc97f2c0c1c6f10f66abb
[2011/02/28 18:29:34 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Java(2)
[2011/02/28 18:11:35 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\McAfee
[1 C:\Documents and Settings\jhn barrett\*.tmp files -> C:\Documents and Settings\jhn barrett\*.tmp -> ]

========== Files - Modified Within 90 Days ==========

[2011/05/12 09:30:37 | 000,000,882 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2011/05/12 09:30:36 | 000,000,290 | ---- | M] () -- C:\WINDOWS\tasks\RealUpgradeLogonTaskS-1-5-21-220523388-507921405-1343024091-1004.job
[2011/05/12 09:30:36 | 000,000,006 | -H-- | M] () -- C:\WINDOWS\tasks\SA.DAT
[2011/05/12 09:30:02 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2011/05/12 09:28:40 | 007,340,032 | ---- | M] () -- C:\Documents and Settings\jhn barrett\ntuser.dat
[2011/05/12 09:28:40 | 000,000,178 | -HS- | M] () -- C:\Documents and Settings\jhn barrett\ntuser.ini
[2011/05/12 09:04:05 | 000,000,886 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2011/05/12 03:57:07 | 000,021,775 | ---- | M] () -- C:\Documents and Settings\jhn barrett\.recently-used.xbel
[2011/05/11 21:46:32 | 000,041,034 | ---- | M] () -- C:\Documents and Settings\jhn barrett\Application Data\wklnhst.dat
[2011/05/11 15:47:12 | 000,000,784 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2011/05/11 01:27:03 | 000,020,480 | ---- | M] () -- C:\Documents and Settings\jhn barrett\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/05/10 19:45:05 | 000,000,298 | ---- | M] () -- C:\WINDOWS\tasks\RealUpgradeScheduledTaskS-1-5-21-220523388-507921405-1343024091-1004.job
[2011/05/09 22:19:21 | 000,217,145 | ---- | M] () -- C:\Documents and Settings\jhn barrett\Desktop\kaspres.jpg
[2011/05/09 20:12:40 | 000,001,689 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\avast! Free Antivirus.lnk
[2011/05/09 20:12:30 | 000,002,625 | ---- | M] () -- C:\WINDOWS\System32\CONFIG.NT
[2011/05/09 16:23:26 | 000,001,678 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\SUPERAntiSpyware Free Edition.lnk
[2011/05/09 15:42:58 | 000,000,116 | ---- | M] () -- C:\WINDOWS\NeroDigital.ini
[2011/05/07 18:46:47 | 000,001,617 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\ZTE Mobile Connection.lnk
[2011/05/07 18:19:39 | 000,433,800 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat
[2011/05/07 18:19:38 | 000,068,232 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat
[2011/05/07 18:19:34 | 000,510,402 | ---- | M] () -- C:\WINDOWS\System32\PerfStringBackup.INI
[2011/05/07 18:08:43 | 000,191,384 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2011/05/07 18:01:19 | 005,284,890 | -H-- | M] () -- C:\Documents and Settings\jhn barrett\Local Settings\Application Data\IconCache.db
[2011/05/07 13:14:56 | 000,002,206 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2011/04/19 03:25:12 | 000,040,112 | ---- | M] (AVAST Software) -- C:\WINDOWS\avastSS.scr
[2011/04/19 03:25:10 | 000,199,304 | ---- | M] (AVAST Software) -- C:\WINDOWS\System32\aswBoot.exe
[2011/04/19 03:17:46 | 000,441,176 | ---- | M] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswSnx.sys
[2011/04/19 03:17:34 | 000,307,288 | ---- | M] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswSP.sys
[2011/04/19 03:16:18 | 000,049,240 | ---- | M] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswTdi.sys
[2011/04/19 03:16:06 | 000,102,488 | ---- | M] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswmon2.sys
[2011/04/19 03:16:02 | 000,096,344 | ---- | M] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswmon.sys
[2011/04/19 03:13:21 | 000,025,432 | ---- | M] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswRdr.sys
[2011/04/19 03:13:02 | 000,030,680 | ---- | M] (AVAST Software) -- C:\WINDOWS\System32\drivers\aavmker4.sys
[2011/04/19 03:12:58 | 000,019,544 | ---- | M] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswFsBlk.sys
[2011/03/01 12:43:52 | 000,000,284 | ---- | M] () -- C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2011/03/01 00:18:41 | 000,001,355 | ---- | M] () -- C:\WINDOWS\imsins.BAK
[1 C:\Documents and Settings\jhn barrett\*.tmp files -> C:\Documents and Settings\jhn barrett\*.tmp -> ]

========== Files Created - No Company Name ==========

[2011/05/12 03:57:07 | 000,021,775 | ---- | C] () -- C:\Documents and Settings\jhn barrett\.recently-used.xbel
[2011/05/11 15:47:12 | 000,000,784 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2011/05/09 22:19:20 | 000,217,145 | ---- | C] () -- C:\Documents and Settings\jhn barrett\Desktop\kaspres.jpg
[2011/05/09 20:12:40 | 000,001,689 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\avast! Free Antivirus.lnk
[2011/05/09 16:23:26 | 000,001,678 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\SUPERAntiSpyware Free Edition.lnk
[2011/05/07 18:46:14 | 000,001,617 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\ZTE Mobile Connection.lnk
[2011/03/01 14:15:28 | 000,000,290 | ---- | C] () -- C:\WINDOWS\tasks\RealUpgradeLogonTaskS-1-5-21-220523388-507921405-1343024091-1004.job
[2010/11/26 08:15:21 | 000,075,264 | ---- | C] () -- C:\WINDOWS\System32\ztvunacev2.dll
[2010/11/26 08:15:19 | 000,156,160 | ---- | C] () -- C:\WINDOWS\System32\ztvunrar3.dll
[2010/11/26 08:14:58 | 000,178,176 | ---- | C] () -- C:\WINDOWS\System32\7-zip32.dll
[2010/04/22 02:43:03 | 000,000,116 | ---- | C] () -- C:\WINDOWS\NeroDigital.ini
[2010/04/08 22:38:40 | 000,015,944 | ---- | C] () -- C:\WINDOWS\System32\drivers\hitmanpro35.sys
[2010/03/21 07:45:13 | 000,000,025 | ---- | C] () -- C:\WINDOWS\cdplayer.ini
[2010/03/21 04:01:00 | 000,155,648 | R--- | C] () -- C:\WINDOWS\System32\RTLCPAPI.dll
[2009/08/04 01:07:42 | 000,403,816 | ---- | C] () -- C:\WINDOWS\System32\OGACheckControl.DLL
[2009/03/03 21:18:04 | 000,073,728 | ---- | C] () -- C:\WINDOWS\System32\RtNicProp32.dll

========== LOP Check ==========

[2010/03/25 11:15:00 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Alwil Software
[2011/05/09 20:10:45 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\AVAST Software
[2010/04/28 04:28:31 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\AVG Security Toolbar
[2010/04/11 10:12:04 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\FileCure
[2010/04/09 07:57:05 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Hitman Pro
[2011/05/09 17:13:25 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\jhn barrett
[2010/10/23 23:10:38 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\MFAData
[2011/05/08 05:39:44 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Tarma Installer
[2011/05/09 15:33:24 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\TEMP
[2010/04/06 22:18:19 | 000,000,000 | ---D | M] -- C:\Documents and Settings\jhn barrett\Application Data\1&1
[2010/05/25 10:38:46 | 000,000,000 | ---D | M] -- C:\Documents and Settings\jhn barrett\Application Data\Facebook
[2011/05/12 03:57:11 | 000,000,000 | ---D | M] -- C:\Documents and Settings\jhn barrett\Application Data\gtk-2.0
[2010/03/21 04:38:27 | 000,000,000 | ---D | M] -- C:\Documents and Settings\jhn barrett\Application Data\K-Meleon
[2010/03/24 16:08:46 | 000,000,000 | ---D | M] -- C:\Documents and Settings\jhn barrett\Application Data\Participatory Culture Foundation
[2011/05/11 15:58:36 | 000,000,000 | ---D | M] -- C:\Documents and Settings\jhn barrett\Application Data\SPE
[2010/03/21 09:44:48 | 000,000,000 | ---D | M] -- C:\Documents and Settings\jhn barrett\Application Data\Template
[2010/04/30 05:03:12 | 000,000,000 | ---D | M] -- C:\Documents and Settings\jhn barrett\Application Data\Tudou Downloader(xmlbar)

========== Purity Check ==========



========== Alternate Data Streams ==========

@Alternate Data Stream - 125 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:5C321E34
< End of report >

Edited by jhnb, 12 May 2011 - 04:27 AM.

  • 0

#3
sempai

sempai

    Trusted Helper

  • Malware Removal
  • 785 posts
Hi,

Please do not make any changes or run any other tools from now on unless I instructed you to do so, this may hinder the cleaning process of your machine.

Does your dongle comes with software/driver installer? Does uninstall and reinstalling it helps?

The OTL log that you posted is way too old, I need to see a fresh log so please run a new OTL scan and post the new report for my review.
  • 0

#4
jhnb

jhnb

    Member

  • Topic Starter
  • Member
  • PipPip
  • 17 posts
the otl log is recent, i run it right after i posted, note i had to edit to add it on. its the date on my computer that is wrong and i never bothered to change it. i think a virus may have even changed it but not too sure. the dongle does come with its own software, it installs automatically when you plug it in. un and re-installing it makes little difference tho. when the problem first resurfaced it wouldn't allow me online at all for a good week or so, in the end i bought a new dongle because it seemed the software on the old one had been somehow corrupted, at the moment its very indiscriminate, sometimes it gets online no problem, other times it gets online but is very slow as if i'm downloading a large file. other times i cannot get online all day or more at a time.

p.s. if i dont answer for a day or two then it is probably because of this, i will answer asap tho.

thanks.


done new otl anyway(just ignore the date)


OTL logfile created on: 6/27/2011 3:15:52 AM - Run 5
OTL by OldTimer - Version 3.2.4.1 Folder = C:\Documents and Settings\jhn barrett\Desktop\Virus Removal Tools
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

251.00 Mb Total Physical Memory | 66.00 Mb Available Physical Memory | 26.00% Memory free
982.00 Mb Paging File | 458.00 Mb Available in Paging File | 47.00% Paging File free
Paging file location(s): C:\pagefile.sys 744 744 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 37.25 Gb Total Space | 3.38 Gb Free Space | 9.06% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
Drive F: | 22.99 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: J-C4E7983211AD4
Current User Name: jhn barrett
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Standard

========== Processes (SafeList) ==========

PRC - [2011/05/19 14:54:13 | 000,016,856 | ---- | M] (Mozilla Corporation) -- C:\Program Files\Mozilla Firefox\plugin-container.exe
PRC - [2011/05/19 14:53:41 | 000,912,344 | ---- | M] (Mozilla Corporation) -- C:\Program Files\Mozilla Firefox\firefox.exe
PRC - [2011/05/10 22:10:58 | 003,459,712 | ---- | M] (AVAST Software) -- C:\Program Files\AVAST Software\Avast\AvastUI.exe
PRC - [2011/05/10 22:10:57 | 000,042,184 | ---- | M] (AVAST Software) -- C:\Program Files\AVAST Software\Avast\AvastSvc.exe
PRC - [2011/05/05 03:42:04 | 002,424,192 | ---- | M] (SUPERAntiSpyware.com) -- C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
PRC - [2010/07/18 00:34:41 | 000,202,256 | ---- | M] (RealNetworks, Inc.) -- C:\Program Files\Common Files\Real\Update_OB\realsched.exe
PRC - [2010/06/03 10:50:58 | 001,144,104 | ---- | M] () -- C:\Program Files\DivX\DivX Update\DivXUpdate.exe
PRC - [2010/05/04 18:44:08 | 000,570,880 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\jhn barrett\Desktop\Virus Removal Tools\OTL.exe
PRC - [2010/01/28 13:48:00 | 010,035,448 | ---- | M] (3Connect) -- C:\Program Files\3 Mobile Broadband\3Connect\Wilog.exe
PRC - [2010/01/28 13:47:44 | 001,737,464 | ---- | M] () -- C:\Program Files\3 Mobile Broadband\3Connect\BecHelperService.exe
PRC - [2008/11/10 06:48:14 | 000,602,392 | ---- | M] (Yahoo! Inc.) -- C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe
PRC - [2008/04/14 10:12:19 | 001,033,728 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe
PRC - [2004/07/02 02:23:32 | 000,067,584 | R--- | M] (Realtek Semiconductor Corp.) -- C:\WINDOWS\SOUNDMAN.EXE


========== Modules (SafeList) ==========

MOD - [2011/05/10 22:10:55 | 000,199,792 | ---- | M] (AVAST Software) -- C:\Program Files\AVAST Software\Avast\snxhk.dll
MOD - [2010/08/24 02:12:02 | 001,054,208 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.6028_x-ww_61e65202\comctl32.dll
MOD - [2010/05/04 18:44:08 | 000,570,880 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\jhn barrett\Desktop\Virus Removal Tools\OTL.exe
MOD - [2008/04/14 10:10:20 | 000,110,592 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\msscript.ocx


========== Win32 Services (SafeList) ==========

SRV - [2011/05/10 22:10:57 | 000,042,184 | ---- | M] (AVAST Software) [Auto | Running] -- C:\Program Files\AVAST Software\Avast\AvastSvc.exe -- (avast! Antivirus)
SRV - [2010/01/28 13:47:44 | 001,737,464 | ---- | M] () [Auto | Running] -- C:\Program Files\3 Mobile Broadband\3Connect\BecHelperService.exe -- (BecHelperService)
SRV - [2008/11/10 06:48:14 | 000,602,392 | ---- | M] (Yahoo! Inc.) [Auto | Running] -- C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe -- (YahooAUService)


========== Driver Services (SafeList) ==========

DRV - [2011/05/10 22:03:54 | 000,441,176 | ---- | M] (AVAST Software) [File_System | System | Running] -- C:\WINDOWS\system32\drivers\aswSnx.sys -- (aswSnx)
DRV - [2011/05/10 22:03:44 | 000,307,928 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\aswSP.sys -- (aswSP)
DRV - [2011/05/10 22:02:37 | 000,049,240 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\aswTdi.sys -- (aswTdi)
DRV - [2011/05/10 22:02:25 | 000,102,616 | ---- | M] (AVAST Software) [File_System | Auto | Running] -- C:\WINDOWS\system32\drivers\aswmon2.sys -- (aswMon2)
DRV - [2011/05/10 21:59:56 | 000,025,432 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\aswRdr.sys -- (aswRdr)
DRV - [2011/05/10 21:59:37 | 000,030,808 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\aavmker4.sys -- (Aavmker4)
DRV - [2011/05/10 21:59:35 | 000,019,544 | ---- | M] (AVAST Software) [File_System | Auto | Running] -- C:\WINDOWS\system32\drivers\aswFsBlk.sys -- (aswFsBlk)
DRV - [2010/05/11 04:41:30 | 000,067,656 | ---- | M] (SUPERAdBlocker.com and SUPERAntiSpyware.com) [Kernel | System | Running] -- C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS -- (SASKUTIL)
DRV - [2010/03/27 05:07:02 | 000,032,768 | ---- | M] (AnchorFree Inc) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\taphss.sys -- (taphss)
DRV - [2010/02/18 04:25:48 | 000,012,872 | ---- | M] (SUPERAdBlocker.com and SUPERAntiSpyware.com) [Kernel | System | Running] -- C:\Program Files\SUPERAntiSpyware\sasdifsv.sys -- (SASDIFSV)
DRV - [2010/01/28 13:35:24 | 000,010,240 | ---- | M] () [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\mdvrmng.sys -- (mdvrmng)
DRV - [2010/01/19 21:49:50 | 000,105,088 | ---- | M] (ZTE Incorporated) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\ZTEusbser6k.sys -- (ZTEusbser6k)
DRV - [2010/01/19 21:49:50 | 000,105,088 | ---- | M] (ZTE Incorporated) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\ZTEusbnmea.sys -- (ZTEusbnmea)
DRV - [2010/01/19 21:49:50 | 000,105,088 | ---- | M] (ZTE Incorporated) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\ZTEusbmdm6k.sys -- (ZTEusbmdm6k)
DRV - [2010/01/19 21:49:50 | 000,009,216 | ---- | M] (ZTE Incorporated) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\massfilter.sys -- (massfilter)
DRV - [2009/10/22 13:54:18 | 000,037,392 | ---- | M] (Kaspersky Lab) [Kernel | Boot | Running] -- C:\WINDOWS\system32\DRIVERS\83480662.sys -- (83480662)
DRV - [2009/10/09 23:31:10 | 000,315,408 | ---- | M] (Kaspersky Lab) [File_System | System | Running] -- C:\WINDOWS\system32\drivers\8348066.sys -- (setup_9.0.0.722_17.06.2011_18-59drv)
DRV - [2009/09/25 17:59:42 | 000,128,016 | ---- | M] (Kaspersky Lab) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\83480661.sys -- (83480661)
DRV - [2009/04/10 15:58:02 | 000,105,344 | ---- | M] (Onda Communication) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ONDAusbser6k.sys -- (ONDAusbser6k)
DRV - [2009/04/10 15:58:02 | 000,105,344 | ---- | M] (Onda Communication) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ONDAusbnmea.sys -- (ONDAusbnmea)
DRV - [2009/04/10 15:58:02 | 000,105,344 | ---- | M] (Onda Communication) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ONDAusbmdm6k.sys -- (ONDAusbmdm6k)
DRV - [2009/03/25 15:29:52 | 000,130,432 | ---- | M] (Realtek Semiconductor Corporation ) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\Rtnicxp.sys -- (RTL8023xp)
DRV - [2006/02/22 02:32:04 | 000,143,904 | ---- | M] (Winbond Electronics Corp.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\W33ND.SYS -- (W33ND)
DRV - [2004/08/04 08:31:34 | 000,020,992 | ---- | M] (Realtek Semiconductor Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\RTL8139.sys -- (rtl8139) Realtek RTL8139(A/B/C)
DRV - [2004/07/22 22:50:16 | 001,268,234 | R--- | M] (Agere Systems) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\AGRSM.sys -- (AgereSoftModem)
DRV - [2004/07/01 22:49:00 | 000,626,977 | R--- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\ALCXWDM.SYS -- (ALCXWDM) Service for Realtek AC97 Audio (WDM)
DRV - [2004/02/24 18:08:52 | 000,400,384 | R--- | M] (Sensaura) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\ALCXSENS.SYS -- (ALCXSENS)
DRV - [2003/02/26 22:38:40 | 000,037,888 | ---- | M] (Winbond Electronics Corp.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\wbfirdma.sys -- (WBFIRDMA)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========


IE - HKCU\..\URLSearchHook: {e9911ec6-1bcc-40b0-9993-e0eea7f6953f} - C:\Program Files\DVDVideoSoft\tbDVDV.dll (Conduit Ltd.)
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..browser.search.defaultthis.engineName: " "
FF - prefs.js..browser.search.defaulturl: "http://search.condui...={searchTerms}"
FF - prefs.js..browser.search.param.yahoo-fr: "chrf-ytbm"
FF - prefs.js..browser.search.param.yahoo-fr-cjkt: "chrf-ytbm"
FF - prefs.js..browser.search.param.yahoo-type: "${8}"
FF - prefs.js..browser.search.update: false
FF - prefs.js..extensions.enabledItems: {ABDE892B-13A8-4d1b-88E6-365A6E755758}:14.0.3
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}:6.0.20
FF - prefs.js..extensions.enabledItems: {00bf7b9c-acd2-4080-bea8-b1c41987070f}:2.6.0.15
FF - prefs.js..extensions.enabledItems: [email protected]:1.0
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}:6.0.22
FF - prefs.js..extensions.enabledItems: [email protected]:3.2.5.2
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}:6.0.23
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}:6.0.24
FF - prefs.js..extensions.enabledItems: [email protected]:1.0


FF - HKLM\software\mozilla\Firefox\Extensions\\{ABDE892B-13A8-4d1b-88E6-365A6E755758}: C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext [2011/06/07 20:54:52 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\[email protected]: C:\Program Files\AVAST Software\Avast\WebRep\FF [2011/06/07 20:49:40 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\K-Meleon\Extensions\\Plugins: C:\Program Files\K-Meleon\Plugins [2011/06/07 20:55:11 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\K-Meleon\Extensions\\Components: C:\Program Files\K-Meleon\Components [2011/06/09 19:39:11 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.17\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011/05/26 19:40:16 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.17\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011/06/07 20:55:11 | 000,000,000 | ---D | M]

[2010/04/14 09:52:30 | 000,000,000 | ---D | M] -- C:\Documents and Settings\jhn barrett\Application Data\Mozilla\Extensions
[2010/04/08 11:42:36 | 000,000,000 | ---D | M] -- C:\Documents and Settings\jhn barrett\Application Data\Mozilla\Extensions\[email protected]
[2011/06/07 20:56:20 | 000,000,000 | ---D | M] -- C:\Documents and Settings\jhn barrett\Application Data\Mozilla\Firefox\Profiles\i34ihir7.default\extensions
[2010/05/19 19:14:29 | 000,000,000 | ---D | M] (TranslatorBar 1 Toolbar) -- C:\Documents and Settings\jhn barrett\Application Data\Mozilla\Firefox\Profiles\i34ihir7.default\extensions\{00bf7b9c-acd2-4080-bea8-b1c41987070f}
[2011/05/15 04:14:52 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\jhn barrett\Application Data\Mozilla\Firefox\Profiles\i34ihir7.default\extensions\{ACAA314B-EEBA-48e4-AD47-84E31C44796C}
[2009/12/11 21:47:13 | 000,000,000 | ---D | M] (uTorrentBar Community Toolbar) -- C:\Documents and Settings\jhn barrett\Application Data\Mozilla\Firefox\Profiles\i34ihir7.default\extensions\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}
[2010/04/25 02:58:25 | 000,000,000 | ---D | M] (Hotspot Shield Toolbar) -- C:\Documents and Settings\jhn barrett\Application Data\Mozilla\Firefox\Profiles\i34ihir7.default\extensions\{c95a4e8e-816d-4655-8c79-d736da1adb6d}
[2009/12/11 21:47:18 | 000,000,000 | ---D | M] -- C:\Documents and Settings\jhn barrett\Application Data\Mozilla\Firefox\Profiles\i34ihir7.default\extensions\[email protected]
[2010/07/22 07:17:54 | 000,000,000 | ---D | M] -- C:\Documents and Settings\jhn barrett\Application Data\Mozilla\Firefox\Profiles\i34ihir7.default\extensions\[email protected]
[2010/05/26 07:03:29 | 000,000,000 | ---D | M] -- C:\Documents and Settings\jhn barrett\Application Data\Mozilla\Firefox\Profiles\i34ihir7.default\extensions\[email protected]
[2010/04/21 13:08:16 | 000,000,933 | ---- | M] () -- C:\Documents and Settings\jhn barrett\Application Data\Mozilla\Firefox\Profiles\i34ihir7.default\searchplugins\conduit.xml
[2011/06/07 20:56:20 | 000,000,000 | ---D | M] -- C:\Program Files\Mozilla Firefox\extensions
[2010/04/18 06:10:16 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
[2010/11/11 01:14:10 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}
[2010/12/17 00:29:59 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}
[2011/05/07 18:05:13 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}
[2010/11/12 17:53:06 | 000,472,808 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\Mozilla Firefox\plugins\npdeployJava1.dll

O1 HOSTS File: ([2010/04/08 06:03:14 | 000,000,789 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (&Yahoo! Toolbar Helper) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.)
O2 - BHO: (RealPlayer Download and Record Plugin for Internet Explorer) - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll (RealPlayer)
O2 - BHO: (Conduit Engine) - {30F9B915-B755-4826-820B-08FBA6BD249D} - C:\Program Files\ConduitEngine\ConduitEngine.dll (Conduit Ltd.)
O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG9\avgssie.dll File not found
O2 - BHO: (avast! WebRep) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
O2 - BHO: (AVG Security Toolbar BHO) - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dll File not found
O2 - BHO: (DVDVideoSoft Toolbar) - {e9911ec6-1bcc-40b0-9993-e0eea7f6953f} - C:\Program Files\DVDVideoSoft\tbDVDV.dll (Conduit Ltd.)
O2 - BHO: (Yontoo Layers) - {FD72061E-9FDE-484D-A58A-0BAB4151CAD8} - C:\Program Files\Yontoo Layers Client\YontooIEClient.dll (Yontoo Technology, Inc.)
O2 - BHO: (SingleInstance Class) - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files\Yahoo!\Companion\Installs\cpn\YTSingleInstance.dll (Yahoo! Inc)
O3 - HKLM\..\Toolbar: (Conduit Engine) - {30F9B915-B755-4826-820B-08FBA6BD249D} - C:\Program Files\ConduitEngine\ConduitEngine.dll (Conduit Ltd.)
O3 - HKLM\..\Toolbar: (Show Xmlbar Toolbar) - {6B896ADB-4A82-46e2-858C-13134782CE34} - C:\Program Files\Xmlbar\Tudou Downloader\IEBar\xbietb.dll (Xmlbar.com)
O3 - HKLM\..\Toolbar: (avast! WebRep) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
O3 - HKLM\..\Toolbar: (AVG Security Toolbar) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - C:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dll File not found
O3 - HKLM\..\Toolbar: (DVDVideoSoft Toolbar) - {e9911ec6-1bcc-40b0-9993-e0eea7f6953f} - C:\Program Files\DVDVideoSoft\tbDVDV.dll (Conduit Ltd.)
O3 - HKLM\..\Toolbar: (Yahoo! Toolbar) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.)
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (AVG Security Toolbar) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - C:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dll File not found
O3 - HKCU\..\Toolbar\WebBrowser: (DVDVideoSoft Toolbar) - {E9911EC6-1BCC-40B0-9993-E0EEA7F6953F} - C:\Program Files\DVDVideoSoft\tbDVDV.dll (Conduit Ltd.)
O4 - HKLM..\Run: [avast] C:\Program Files\AVAST Software\Avast\avastUI.exe (AVAST Software)
O4 - HKLM..\Run: [DivXUpdate] C:\Program Files\DivX\DivX Update\DivXUpdate.exe ()
O4 - HKLM..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe (Ahead Software Gmbh)
O4 - HKLM..\Run: [SoundMan] C:\WINDOWS\SOUNDMAN.EXE (Realtek Semiconductor Corp.)
O4 - HKLM..\Run: [TkBellExe] C:\Program Files\Common Files\Real\Update_OB\realsched.exe (RealNetworks, Inc.)
O4 - HKCU..\Run: [KasperskyPasswordManager] C:\DOCUME~1\JHNBAR~1\LOCALS~1\Temp\Rar$EX06.652\Kaspersky.Password.Manager.4.0.0.133.Eng\stpass.exe File not found
O4 - HKCU..\Run: [msnmsgr] C:\Program Files\Windows Live\Messenger\msnmsgr.exe File not found
O4 - HKCU..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe (SUPERAntiSpyware.com)
O4 - HKLM..\RunOnce: [AvgUninstallURL] C:\WINDOWS\System32\cmd.exe (Microsoft Corporation)
O4 - Startup: C:\Documents and Settings\jhn barrett\Start Menu\Programs\Startup\setup_9.0.0.722_17.06.2011_18-59.lnk = C:\Documents and Settings\jhn barrett\Desktop\Virus Removal Tool1\setup_9.0.0.722_17.06.2011_18-59\startup.exe ()
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoControlPanel = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 36
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = FF FF FF FF [binary data]
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoControlPanel = 0
O8 - Extra context menu item: Free YouTube Download - C:\Documents and Settings\jhn barrett\Application Data\DVDVideoSoftIEHelpers\freeyoutubedownload.htm ()
O8 - Extra context menu item: Free YouTube to MP3 Converter - C:\Documents and Settings\jhn barrett\Application Data\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm ()
O9 - Extra Button: Run TudouDownloader - {612F6E5C-B314-4bab-93D1-D266AAFBE700} - C:\Program Files\Xmlbar\Tudou Downloader\TudouDownloader(xmlbar).exe (Xmlbar.com, Inc.)
O9 - Extra 'Tools' menuitem : Tudou Downloader - {612F6E5C-B314-4bab-93D1-D266AAFBE700} - C:\Program Files\Xmlbar\Tudou Downloader\TudouDownloader(xmlbar).exe (Xmlbar.com, Inc.)
O16 - DPF: {05CA9FB0-3E3E-4B36-BF41-0E3A5CAA8CD8} http://go.microsoft....k/?linkid=58813 (Office Genuine Advantage Validation Tool)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://go.microsoft....k/?linkid=39204 (Windows Genuine Advantage Validation Tool)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} http://www.update.mi...b?1273029714116 (MUWebControl Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_23)
O16 - DPF: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_23)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_23)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.ad...Plus/1.6/gp.cab (Reg Error: Key error.)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\!SASWinLogon: DllName - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL (SUPERAntiSpyware.com)
O20 - Winlogon\Notify\igfxcui: DllName - igfxsrvc.dll - C:\WINDOWS\System32\igfxsrvc.dll (Intel Corporation)
O20 - Winlogon\Notify\igfxtcui: DllName - C:\documents and settings\all users\application data\jhn barrett\UpdateLogon.dll - C:\documents and settings\all users\application data\jhn barrett\UpdateLogon.dll File not found
O28 - HKLM ShellExecuteHooks: {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - C:\Program Files\SUPERAntiSpyware\SASSEH.DLL (SuperAdBlocker.com)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2010/03/21 03:29:50 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O32 - AutoRun File - [2010/03/26 09:02:30 | 000,000,000 | RHSD | M] - C:\autorun.inf -- [ NTFS ]
O32 - AutoRun File - [2010/02/10 03:11:34 | 000,084,288 | R--- | M] (Birdstep) - F:\Autorun.exe -- [ CDFS ]
O32 - AutoRun File - [2010/02/10 03:11:34 | 000,027,750 | R--- | M] () - F:\Autorun.ico -- [ CDFS ]
O32 - AutoRun File - [2010/02/10 03:11:34 | 000,000,047 | R--- | M] () - F:\Autorun.inf -- [ CDFS ]
O33 - MountPoints2\{898e0893-7df0-11e0-ab76-0040d0726735}\Shell - "" = AutoRun
O33 - MountPoints2\{898e0893-7df0-11e0-ab76-0040d0726735}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{898e0893-7df0-11e0-ab76-0040d0726735}\Shell\AutoRun\command - "" = F:\Autorun.exe -- [2010/02/10 03:11:34 | 000,084,288 | R--- | M] (Birdstep)
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*

========== Files/Folders - Created Within 30 Days ==========

[2011/06/22 20:31:16 | 000,000,000 | ---D | C] -- C:\Documents and Settings\jhn barrett\My Documents\Vuze Downloads
[2011/06/22 20:13:19 | 000,000,000 | ---D | C] -- C:\Documents and Settings\jhn barrett\Application Data\Azureus
[2011/06/22 20:07:49 | 000,000,000 | ---D | C] -- C:\Program Files\Vuze
[2011/06/09 17:57:57 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Common Files
[2011/06/09 12:30:57 | 000,037,392 | ---- | C] (Kaspersky Lab) -- C:\WINDOWS\System32\drivers\83480662.sys
[2011/06/09 12:30:56 | 000,315,408 | ---- | C] (Kaspersky Lab) -- C:\WINDOWS\System32\drivers\8348066.sys
[2011/06/09 12:30:56 | 000,128,016 | ---- | C] (Kaspersky Lab) -- C:\WINDOWS\System32\drivers\83480661.sys
[2011/06/09 12:30:48 | 000,000,000 | ---D | C] -- C:\Documents and Settings\jhn barrett\Desktop\Virus Removal Tool1
[2011/06/07 20:55:14 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\xing shared
[2011/06/07 20:49:27 | 000,000,000 | ---D | C] -- C:\Avenger
[2011/06/07 20:49:22 | 000,000,000 | ---D | C] -- C:\Documents and Settings\jhn barrett\Desktop\Virus Removal Tool
[2011/06/01 08:30:50 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft CAPICOM 2.1.0.2
[1 C:\Documents and Settings\jhn barrett\Local Settings\Application Data\*.tmp files -> C:\Documents and Settings\jhn barrett\Local Settings\Application Data\*.tmp -> ]
[1 C:\Documents and Settings\jhn barrett\*.tmp files -> C:\Documents and Settings\jhn barrett\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2011/06/27 03:16:13 | 000,000,886 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2011/06/26 21:29:15 | 000,000,006 | -H-- | M] () -- C:\WINDOWS\tasks\SA.DAT
[2011/06/26 21:27:49 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2011/06/26 17:18:19 | 008,388,608 | ---- | M] () -- C:\Documents and Settings\jhn barrett\ntuser.dat
[2011/06/26 17:18:19 | 000,000,178 | -HS- | M] () -- C:\Documents and Settings\jhn barrett\ntuser.ini
[2011/06/25 15:16:17 | 000,000,882 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2011/06/24 20:28:56 | 000,000,290 | ---- | M] () -- C:\WINDOWS\tasks\RealUpgradeLogonTaskS-1-5-21-220523388-507921405-1343024091-1004.job
[2011/06/22 20:12:14 | 000,001,505 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Vuze.lnk
[2011/06/21 14:22:01 | 000,050,955 | ---- | M] () -- C:\Documents and Settings\jhn barrett\Desktop\new-york-county-map.gif
[2011/06/21 13:47:20 | 000,000,284 | ---- | M] () -- C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2011/06/19 21:15:02 | 000,000,298 | ---- | M] () -- C:\WINDOWS\tasks\RealUpgradeScheduledTaskS-1-5-21-220523388-507921405-1343024091-1004.job
[2011/06/18 11:51:14 | 000,059,568 | ---- | M] () -- C:\Documents and Settings\jhn barrett\.recently-used.xbel
[2011/06/18 07:19:31 | 000,404,640 | ---- | M] (Adobe Systems Incorporated) -- C:\WINDOWS\System32\FlashPlayerCPLApp.cpl
[2011/06/09 12:40:05 | 000,002,269 | ---- | M] () -- C:\Documents and Settings\jhn barrett\Start Menu\Programs\Startup\setup_9.0.0.722_17.06.2011_18-59.lnk
[2011/06/08 19:32:24 | 000,001,813 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Google Chrome.lnk
[2011/06/08 09:07:34 | 000,280,355 | ---- | M] () -- C:\Documents and Settings\jhn barrett\Desktop\buffalo2.jpg
[2011/06/08 08:56:52 | 000,209,236 | ---- | M] () -- C:\Documents and Settings\jhn barrett\Desktop\buffalo1.jpg
[2011/06/06 11:53:33 | 000,001,689 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\avast! Free Antivirus.lnk
[2011/06/06 11:53:24 | 000,002,625 | ---- | M] () -- C:\WINDOWS\System32\CONFIG.NT
[2011/06/06 09:48:06 | 003,120,180 | ---- | M] () -- C:\Documents and Settings\jhn barrett\Desktop\newdrweb.exe.part
[2011/06/06 09:08:03 | 000,002,206 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2011/06/04 19:39:39 | 000,191,384 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2011/06/04 19:20:23 | 006,847,534 | -H-- | M] () -- C:\Documents and Settings\jhn barrett\Local Settings\Application Data\IconCache.db
[2011/06/02 12:48:39 | 000,551,465 | ---- | M] () -- C:\Documents and Settings\jhn barrett\Desktop\mizhelena.pdf
[2011/06/01 12:32:59 | 000,433,800 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat
[2011/06/01 12:32:59 | 000,068,232 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat
[2011/06/01 09:06:41 | 000,000,000 | ---- | M] () -- C:\Documents and Settings\jhn barrett\Local Settings\Application Data\{3E68389F-0EE2-423C-A72F-122C74EC3FD4}
[2011/06/01 08:48:21 | 000,001,355 | ---- | M] () -- C:\WINDOWS\imsins.BAK
[2011/05/30 12:02:37 | 000,089,698 | ---- | M] () -- C:\Documents and Settings\jhn barrett\My Documents\MassiveSuccess.pdf
[1 C:\Documents and Settings\jhn barrett\Local Settings\Application Data\*.tmp files -> C:\Documents and Settings\jhn barrett\Local Settings\Application Data\*.tmp -> ]
[1 C:\Documents and Settings\jhn barrett\*.tmp files -> C:\Documents and Settings\jhn barrett\*.tmp -> ]

========== Files Created - No Company Name ==========

[2011/06/22 20:12:14 | 000,001,505 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Vuze.lnk
[2011/06/21 14:21:54 | 000,050,955 | ---- | C] () -- C:\Documents and Settings\jhn barrett\Desktop\new-york-county-map.gif
[2011/06/18 11:51:14 | 000,059,568 | ---- | C] () -- C:\Documents and Settings\jhn barrett\.recently-used.xbel
[2011/06/09 12:40:06 | 000,002,269 | ---- | C] () -- C:\Documents and Settings\jhn barrett\Start Menu\Programs\Startup\setup_9.0.0.722_17.06.2011_18-59.lnk
[2011/06/08 09:07:33 | 000,280,355 | ---- | C] () -- C:\Documents and Settings\jhn barrett\Desktop\buffalo2.jpg
[2011/06/08 08:56:51 | 000,209,236 | ---- | C] () -- C:\Documents and Settings\jhn barrett\Desktop\buffalo1.jpg
[2011/06/07 10:39:41 | 000,000,290 | ---- | C] () -- C:\WINDOWS\tasks\RealUpgradeLogonTaskS-1-5-21-220523388-507921405-1343024091-1004.job
[2011/06/07 02:26:08 | 008,388,608 | ---- | C] () -- C:\Documents and Settings\jhn barrett\ntuser.dat
[2011/06/06 09:41:57 | 003,120,180 | ---- | C] () -- C:\Documents and Settings\jhn barrett\Desktop\newdrweb.exe.part
[2011/06/02 12:48:39 | 000,551,465 | ---- | C] () -- C:\Documents and Settings\jhn barrett\Desktop\mizhelena.pdf
[2011/06/01 09:06:41 | 000,000,000 | ---- | C] () -- C:\Documents and Settings\jhn barrett\Local Settings\Application Data\{3E68389F-0EE2-423C-A72F-122C74EC3FD4}
[2011/05/30 12:02:14 | 000,089,698 | ---- | C] () -- C:\Documents and Settings\jhn barrett\My Documents\MassiveSuccess.pdf
[2011/05/14 16:14:49 | 000,010,240 | ---- | C] () -- C:\WINDOWS\System32\drivers\mdvrmng.sys
[2010/11/26 08:15:21 | 000,075,264 | ---- | C] () -- C:\WINDOWS\System32\ztvunacev2.dll
[2010/11/26 08:15:19 | 000,156,160 | ---- | C] () -- C:\WINDOWS\System32\ztvunrar3.dll
[2010/11/26 08:14:58 | 000,178,176 | ---- | C] () -- C:\WINDOWS\System32\7-zip32.dll
[2010/04/22 02:43:03 | 000,000,116 | ---- | C] () -- C:\WINDOWS\NeroDigital.ini
[2010/04/08 22:38:40 | 000,017,480 | ---- | C] () -- C:\WINDOWS\System32\drivers\hitmanpro35.sys
[2010/03/21 07:45:13 | 000,000,025 | ---- | C] () -- C:\WINDOWS\cdplayer.ini
[2010/03/21 04:01:00 | 000,155,648 | R--- | C] () -- C:\WINDOWS\System32\RTLCPAPI.dll
[2010/01/19 21:49:54 | 000,466,944 | ---- | C] () -- C:\WINDOWS\System32\RemoveDevice.dll
[2009/08/04 01:07:42 | 000,403,816 | ---- | C] () -- C:\WINDOWS\System32\OGACheckControl.DLL
[2009/03/03 21:18:04 | 000,073,728 | ---- | C] () -- C:\WINDOWS\System32\RtNicProp32.dll

========== Alternate Data Streams ==========

@Alternate Data Stream - 125 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:5C321E34
< End of report >
  • 0

#5
sempai

sempai

    Trusted Helper

  • Malware Removal
  • 785 posts
Sounds like a poor internet reception to me, but let's see.


1. Go to Control Panel > Add Remove Programs and uninstall Vuze.


2. Please reopen OTL on your desktop.
  • Copy and Paste the following code into the Custom Scan/Fixes text box.

    :OTL
    O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG9\avgssie.dll File not found
    O2 - BHO: (AVG Security Toolbar BHO) - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dll File not found
    O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
    O3 - HKCU\..\Toolbar\WebBrowser: (AVG Security Toolbar) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - C:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dll File not found
    O4 - HKCU..\Run: [msnmsgr] C:\Program Files\Windows Live\Messenger\msnmsgr.exe File not found
    O20 - Winlogon\Notify\igfxtcui: DllName - C:\documents and settings\all users\application data\jhn barrett\UpdateLogon.dll - C:\documents and settings\all users\application data\jhn barrett\UpdateLogon.dll File not found
    
    :Files
    ipconfig /flushdns /c
    
    :Commands
    [EMPTYTEMP] 
    
  • Push the Run Fix button.
  • OTL may ask to reboot the machine. Please do so if asked.
  • A massage box "Fix complete! Click OK to open the fix log." will pop-up.
  • Click the OK button and a report will open.
  • Copy and Paste that report in your next reply.

  • 0

#6
jhnb

jhnb

    Member

  • Topic Starter
  • Member
  • PipPip
  • 17 posts
ok done it. let me know if or what to do next.

thanks.



All processes killed
========== OTL ==========
Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{A3BC75A2-1F87-4686-AA43-5347D756017C}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A3BC75A2-1F87-4686-AA43-5347D756017C}\ deleted successfully.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\Locked deleted successfully.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{CCC7A320-B3CA-4199-B1A6-9F516DD69829} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CCC7A320-B3CA-4199-B1A6-9F516DD69829}\ deleted successfully.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\msnmsgr deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxtcui\ deleted successfully.
========== FILES ==========
< ipconfig /flushdns /c >
Windows IP Configuration
Successfully flushed the DNS Resolver Cache.
C:\Documents and Settings\jhn barrett\Desktop\Virus Removal Tools\cmd.bat deleted successfully.
C:\Documents and Settings\jhn barrett\Desktop\Virus Removal Tools\cmd.txt deleted successfully.
========== COMMANDS ==========

[EMPTYTEMP]

User: Administrator
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes

User: All Users

User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes

User: jhn barrett
->Temp folder emptied: 33780680 bytes
->Temporary Internet Files folder emptied: 27279335 bytes
->Java cache emptied: 0 bytes
->FireFox cache emptied: 94700393 bytes
->Google Chrome cache emptied: 0 bytes
->Flash cache emptied: 22991 bytes

User: LocalService
->Temp folder emptied: 66016 bytes
->Temporary Internet Files folder emptied: 33170 bytes

User: NetworkService
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes

%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32\dllcache .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 98304 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 334 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 0 bytes
RecycleBin emptied: 61470 bytes

Total Files Cleaned = 149.00 mb


OTL by OldTimer - Version 3.2.4.1 log created on 06272011_165044

Files\Folders moved on Reboot...
File\Folder C:\WINDOWS\temp\_avast_\Webshlock.txt not found!

Registry entries deleted on Reboot...
  • 0

#7
jhnb

jhnb

    Member

  • Topic Starter
  • Member
  • PipPip
  • 17 posts
just thought i should add that i have used this service provider(3 broadband) for about 3 years and its always been very good on reception in this area. i do however notice that when the broadband goes slow or doesn't load pages that the computer also slows, sometimes considerably. the dongle software actually starts firefox automatically when i click online but sometimes it can take upto 15 minutes before firefox actually opens on the screen. you can see it has started in task manager processes but it just takes forever to actually appear on the screen.
  • 0

#8
sempai

sempai

    Trusted Helper

  • Malware Removal
  • 785 posts
Download Combofix (by Subs) from any of the links below, make sure that you save it to your desktop.

Link 1
Link 2

  • It's important to temporary disable your anti-virus and anti-malware programs so they do not interfere with the running of ComboFix. See HERE
  • Close any open windows, including this one.
  • Double click on ComboFix.exe & follow the prompts.
  • ComboFix will check to see if the Microsoft Windows Recovery Console is installed.

*It's strongly recommended to have this pre-installed on your machine before doing any malware removal.
*The Windows Recovery Console will allow you to boot up into a special recovery (repair) mode.
*This allows us to more easily help you should your computer have a problem after an attempted removal of malware.

  • If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures. If you did not have it installed, you will see the prompt below. Choose YES.

Posted Image


  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console.
  • When prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.
  • Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

Posted Image


  • Click on Yes, to continue scanning for malware.
  • When finished, it will produce a report for you. Please post the contents of the log (C:\ComboFix.txt).

Important notes:

  • Leave your computer alone while ComboFix is running.
  • ComboFix will restart your computer if malware is found; allow it to do so.
  • ComboFix may reset a number of Internet Explorer's settings, including making I-E the default browser.
  • Please do not mouseclick combofix's window while its running because it may call it to stall.
  • ComboFix SHOULD NOT be used unless requested by a forum helper. See HERE.


  • 0

#9
jhnb

jhnb

    Member

  • Topic Starter
  • Member
  • PipPip
  • 17 posts
ok combofix done, here's the log.



ComboFix 11-06-28.04 - jhn barrett 06/28/2011 15:36:14.9.1 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.251.9 [GMT 10:00]
Running from: c:\documents and settings\jhn barrett\Desktop\ComboFix.exe
AV: avast! Antivirus *Disabled/Updated* {7591DB91-41F0-48A3-B128-1A293FD8233D}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\documents and settings\All Users\Application Data\Tarma Installer
c:\documents and settings\All Users\Application Data\Tarma Installer\{889DF117-14D1-44EE-9F31-C5FB5D47F68B}\_Setup.dll
c:\documents and settings\All Users\Application Data\Tarma Installer\{889DF117-14D1-44EE-9F31-C5FB5D47F68B}\_Setupx.dll
c:\documents and settings\All Users\Application Data\Tarma Installer\{889DF117-14D1-44EE-9F31-C5FB5D47F68B}\Setup.dat
c:\documents and settings\All Users\Application Data\Tarma Installer\{889DF117-14D1-44EE-9F31-C5FB5D47F68B}\Setup.exe
c:\documents and settings\All Users\Application Data\Tarma Installer\{889DF117-14D1-44EE-9F31-C5FB5D47F68B}\Setup.ico
C:\install.exe
c:\windows\system32\587182039
.
.
((((((((((((((((((((((((( Files Created from 2011-05-28 to 2011-06-28 )))))))))))))))))))))))))))))))
.
.
2011-06-27 06:50 . 2011-06-27 06:50 -------- d-----w- C:\_OTL
2011-06-22 10:13 . 2011-06-22 15:45 -------- d-----w- c:\documents and settings\jhn barrett\Application Data\Azureus
2011-06-09 07:57 . 2011-06-09 07:57 -------- d-----w- c:\documents and settings\All Users\Application Data\Common Files
2011-06-09 02:30 . 2009-10-22 03:54 37392 ----a-w- c:\windows\system32\drivers\83480662.sys
2011-06-09 02:30 . 2009-10-09 13:31 315408 ----a-w- c:\windows\system32\drivers\8348066.sys
2011-06-09 02:30 . 2009-09-25 07:59 128016 ----a-w- c:\windows\system32\drivers\83480661.sys
2011-06-07 10:57 . 2011-06-07 10:57 -------- d-----w- c:\windows\system32\wbem\Repository
2011-06-07 10:55 . 2011-06-07 10:55 -------- d-----w- c:\program files\Common Files\xing shared
2011-05-31 22:30 . 2011-06-07 10:53 -------- d-----w- c:\program files\Microsoft CAPICOM 2.1.0.2
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-06-17 21:19 . 2011-05-19 09:46 404640 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2011-05-26 09:55 . 2011-05-26 09:55 0 ---ha-w- c:\documents and settings\jhn barrett\Local Settings\Application Data\BIT2C.tmp
2011-05-19 05:20 . 2010-04-08 12:38 17480 ----a-w- c:\windows\system32\drivers\hitmanpro35.sys
2011-05-10 12:10 . 2011-05-09 10:11 40112 ----a-w- c:\windows\avastSS.scr
2011-05-10 12:10 . 2011-05-09 10:11 199304 ----a-w- c:\windows\system32\aswBoot.exe
2011-05-10 12:03 . 2011-05-09 10:12 441176 ----a-w- c:\windows\system32\drivers\aswSnx.sys
2011-05-10 12:03 . 2011-05-09 10:12 307928 ----a-w- c:\windows\system32\drivers\aswSP.sys
2011-05-10 12:02 . 2011-05-09 10:12 49240 ----a-w- c:\windows\system32\drivers\aswTdi.sys
2011-05-10 12:02 . 2011-05-09 10:12 102616 ----a-w- c:\windows\system32\drivers\aswmon2.sys
2011-05-10 12:02 . 2011-05-09 10:12 96344 ----a-w- c:\windows\system32\drivers\aswmon.sys
2011-05-10 11:59 . 2011-05-09 10:12 25432 ----a-w- c:\windows\system32\drivers\aswRdr.sys
2011-05-10 11:59 . 2011-05-09 10:12 30808 ----a-w- c:\windows\system32\drivers\aavmker4.sys
2011-05-10 11:59 . 2011-05-09 10:12 19544 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys
2010-04-08 02:07 203776 --sh--w- c:\windows\system32\unrar.exe
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{e9911ec6-1bcc-40b0-9993-e0eea7f6953f}"= "c:\program files\DVDVideoSoft\tbDVDV.dll" [2010-03-09 2355224]
.
[HKEY_CLASSES_ROOT\clsid\{e9911ec6-1bcc-40b0-9993-e0eea7f6953f}]
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{30F9B915-B755-4826-820B-08FBA6BD249D}]
2010-10-18 01:26 3908192 ----a-w- c:\program files\ConduitEngine\ConduitEngine.dll
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{e9911ec6-1bcc-40b0-9993-e0eea7f6953f}]
2010-03-09 01:06 2355224 ----a-w- c:\program files\DVDVideoSoft\tbDVDV.dll
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{FD72061E-9FDE-484D-A58A-0BAB4151CAD8}]
2010-10-14 17:56 194912 ------w- c:\program files\Yontoo Layers Client\YontooIEClient.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{6B896ADB-4A82-46e2-858C-13134782CE34}"= "c:\program files\Xmlbar\Tudou Downloader\IEBar\xbietb.dll" [2009-12-15 413696]
"{e9911ec6-1bcc-40b0-9993-e0eea7f6953f}"= "c:\program files\DVDVideoSoft\tbDVDV.dll" [2010-03-09 2355224]
"{30F9B915-B755-4826-820B-08FBA6BD249D}"= "c:\program files\ConduitEngine\ConduitEngine.dll" [2010-10-18 3908192]
.
[HKEY_CLASSES_ROOT\clsid\{6b896adb-4a82-46e2-858c-13134782ce34}]
[HKEY_CLASSES_ROOT\XBIEBar.XBIEBarObj.1]
[HKEY_CLASSES_ROOT\TypeLib\{D4FB30ED-7DDB-4e2c-A7F2-C7B905D5D771}]
[HKEY_CLASSES_ROOT\XBIEBar.XBIEBarObj]
.
[HKEY_CLASSES_ROOT\clsid\{e9911ec6-1bcc-40b0-9993-e0eea7f6953f}]
.
[HKEY_CLASSES_ROOT\clsid\{30f9b915-b755-4826-820b-08fba6bd249d}]
.
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{E9911EC6-1BCC-40B0-9993-E0EEA7F6953F}"= "c:\program files\DVDVideoSoft\tbDVDV.dll" [2010-03-09 2355224]
.
[HKEY_CLASSES_ROOT\clsid\{e9911ec6-1bcc-40b0-9993-e0eea7f6953f}]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast]
@="{472083B0-C522-11CF-8763-00608CC02F24}"
[HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}]
2011-05-10 12:10 122512 ----a-w- c:\program files\AVAST Software\Avast\ashShell.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SUPERAntiSpyware"="c:\program files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2011-05-04 2424192]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2004-07-01 155648]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2004-07-01 118784]
"SoundMan"="SOUNDMAN.EXE" [2004-07-01 67584]
"AGRSMMSG"="AGRSMMSG.exe" [2004-07-22 88361]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2010-04-04 36272]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-09-21 932288]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2010-03-17 421888]
"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648]
"DivXUpdate"="c:\program files\DivX\DivX Update\DivXUpdate.exe" [2010-06-03 1144104]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2010-07-17 202256]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-05-14 248552]
"avast"="c:\program files\AVAST Software\Avast\avastUI.exe" [2011-05-10 3459712]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
"AvgUninstallURL"="start http:" [X]
.
c:\documents and settings\Administrator\Start Menu\Programs\Startup\
setup_9.0.0.722_23.03.2010_14-47.lnk - c:\documents and settings\jhn barrett\Desktop\Virus Removal Tool\setup_9.0.0.722_23.03.2010_14-47\startup.exe [N/A]
.
c:\documents and settings\jhn barrett\Start Menu\Programs\Startup\
setup_9.0.0.722_17.06.2011_18-59.lnk - c:\documents and settings\jhn barrett\Desktop\Virus Removal Tool1\setup_9.0.0.722_17.06.2011_18-59\startup.exe [2011-6-9 72208]
.
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2009-09-03 22:21 548352 ----a-w- c:\program files\SUPERAntiSpyware\SASWINLO.DLL
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
"FirewallOverride"=dword:00000001
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"DisableNotifications"= 1 (0x1)
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"c:\\WINDOWS\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"9991:TCP"= 9991:TCP:PORT2
"9999:TCP"= 9999:TCP:PORT1
"1013:TCP"= 1013:TCP:BS
"61270:TCP"= 61270:TCP:FD
"51845:TCP"= 51845:TCP:FD
"58062:TCP"= 58062:TCP:FD
"49969:TCP"= 49969:TCP:FD
"26602:TCP"= 26602:TCP:FD
"29740:TCP"= 29740:TCP:FD
"22019:TCP"= 22019:TCP:FD
"36829:TCP"= 36829:TCP:FD
"33732:TCP"= 33732:TCP:FD
"46376:TCP"= 46376:TCP:FD
"3836:TCP"= 3836:TCP:umbwtoct
"23956:TCP"= 23956:TCP:FD
"25032:TCP"= 25032:TCP:FD
"47617:TCP"= 47617:TCP:FD
"3720:TCP"= 3720:TCP:FD
"47853:TCP"= 47853:TCP:FD
"28112:TCP"= 28112:TCP:FD
"30525:TCP"= 30525:TCP:FD
.
R0 42442922;42442922 Boot Guard Driver;c:\windows\system32\DRIVERS\42442922.sys [x]
R2 gupdate1cad11f24ae2c00;Google Update Service (gupdate1cad11f24ae2c00);c:\program files\Google\Update\GoogleUpdate.exe [2010-03-31 133104]
R3 gupdatem;Google Update Service (gupdatem);c:\program files\Google\Update\GoogleUpdate.exe [2010-03-31 133104]
R3 massfilter;ZTE Mass Storage Filter Driver;c:\windows\system32\drivers\massfilter.sys [2010-01-19 9216]
R3 MEMSWEEP2;MEMSWEEP2;c:\windows\system32\D.tmp [x]
R3 ONDAusbmdm6k;ONDA Proprietary USB Driver;c:\windows\system32\DRIVERS\ONDAusbmdm6k.sys [2009-04-10 105344]
R3 ONDAusbnmea;ONDA NMEA Port;c:\windows\system32\DRIVERS\ONDAusbnmea.sys [2009-04-10 105344]
R3 ONDAusbser6k;ONDA Diagnostic Port;c:\windows\system32\DRIVERS\ONDAusbser6k.sys [2009-04-10 105344]
S0 83480662;83480662 Boot Guard Driver;c:\windows\system32\DRIVERS\83480662.sys [2009-10-22 37392]
S1 83480661;83480661;c:\windows\system32\DRIVERS\83480661.sys [2009-09-25 128016]
S1 aswSnx;aswSnx; [x]
S1 aswSP;aswSP; [x]
S1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\SASDIFSV.SYS [2010-02-17 12872]
S1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [2010-05-10 67656]
S1 setup_9.0.0.722_17.06.2011_18-59drv;setup_9.0.0.722_17.06.2011_18-59drv;c:\windows\system32\DRIVERS\8348066.sys [2009-10-09 315408]
S2 aswFsBlk;aswFsBlk; [x]
S2 BecHelperService;BecHelperService;c:\program files\3 Mobile Broadband\3Connect\BecHelperService.exe [2010-01-28 1737464]
S3 W33ND;W89C33 mPCI 802.11 Wireless LAN Adapter Driver;c:\windows\system32\DRIVERS\W33ND.SYS [2006-02-21 143904]
S3 WBFIRDMA;Winbond Infrared Device Driver;c:\windows\system32\DRIVERS\wbfirdma.sys [2003-02-26 37888]
.
.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
.
.
Contents of the 'Scheduled Tasks' folder
.
2011-06-28 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 11:34]
.
2011-06-28 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-03-31 22:11]
.
2011-06-28 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-03-31 22:11]
.
2011-06-28 c:\windows\Tasks\RealUpgradeLogonTaskS-1-5-21-220523388-507921405-1343024091-1004.job
- c:\program files\Real\RealUpgrade\realupgrade.exe [2011-05-26 17:02]
.
2011-06-27 c:\windows\Tasks\RealUpgradeScheduledTaskS-1-5-21-220523388-507921405-1343024091-1004.job
- c:\program files\Real\RealUpgrade\realupgrade.exe [2011-05-26 17:02]
.
.
------- Supplementary Scan -------
.
IE: Free YouTube Download - c:\documents and settings\jhn barrett\Application Data\DVDVideoSoftIEHelpers\freeyoutubedownload.htm
IE: Free YouTube to MP3 Converter - c:\documents and settings\jhn barrett\Application Data\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm
IE: {{612F6E5C-B314-4bab-93D1-D266AAFBE700} - c:\program files\Xmlbar\Tudou Downloader\TudouDownloader(xmlbar).exe
FF - ProfilePath - c:\documents and settings\jhn barrett\Application Data\Mozilla\Firefox\Profiles\i34ihir7.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2786678&SearchSource=3&q={searchTerms}
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}
FF - Ext: Java Quick Starter: [email protected] - c:\program files\Java\jre6\lib\deploy\jqs\ff
FF - Ext: TranslatorBar 1 Toolbar: {00bf7b9c-acd2-4080-bea8-b1c41987070f} - %profile%\extensions\{00bf7b9c-acd2-4080-bea8-b1c41987070f}
FF - Ext: TinEye Reverse Image Search: [email protected] - %profile%\extensions\[email protected]
FF - Ext: Conduit Engine : [email protected] - %profile%\extensions\[email protected]
FF - user.js: yahoo.ytff.general.dontshowhpoffer - true
.
- - - - ORPHANS REMOVED - - - -
.
Toolbar-{CCC7A320-B3CA-4199-B1A6-9F516DD69829} - (no file)
WebBrowser-{D4027C7F-154A-4066-A1AD-4243D8127440} - (no file)
AddRemove-{889DF117-14D1-44EE-9F31-C5FB5D47F68B} - c:\docume~1\ALLUSE~1\APPLIC~1\TARMAI~1\{889DF~1\Setup.exe
AddRemove-Adobe Acrobat Connect Add-in - c:\documents and settings\jhn barrett\Application Data\Macromedia\Flash Player\www.macromedia.com\bin\connectaddin\connectaddin.exe
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2011-06-28 15:51
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes ...
.
scanning hidden autostart entries ...
.
scanning hidden files ...
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\MEMSWEEP2]
"ImagePath"="\??\c:\windows\system32\D.tmp"
.
--------------------- DLLs Loaded Under Running Processes ---------------------
.
- - - - - - - > 'winlogon.exe'(916)
c:\program files\SUPERAntiSpyware\SASWINLO.DLL
c:\windows\system32\WININET.dll
.
Completion time: 2011-06-28 16:03:06
ComboFix-quarantined-files.txt 2011-06-28 06:02
.
Pre-Run: 3,768,557,568 bytes free
Post-Run: 3,716,022,272 bytes free
.
- - End Of File - - 31CD5404FBE40DB8131DC63CE66E3025
  • 0

#10
sempai

sempai

    Trusted Helper

  • Malware Removal
  • 785 posts
We need to execute a ComboFix script.

1. Close any open browsers.

2. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.

3. Open notepad and copy-paste the text in the code box below into it:

Registry::
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"9991:TCP"=-
"9999:TCP"=-
"1013:TCP"=-
"61270:TCP"=-
"51845:TCP"=-
"58062:TCP"=-
"49969:TCP"=-
"26602:TCP"=-
"29740:TCP"=-
"22019:TCP"=-
"36829:TCP"=-
"33732:TCP"=-
"46376:TCP"=-
"3836:TCP"=-
"23956:TCP"=-
"25032:TCP"=-
"47617:TCP"=-
"3720:TCP"=-
"47853:TCP"=-
"28112:TCP"=-
"30525:TCP"=-
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000000
"FirewallOverride"=dword:00000000

4. Save this as CFScript.txt, in the same location as ComboFix.exe


Posted Image

5. Refering to the picture above, drag CFScript into ComboFix.exe

6. When finished, it shall produce a log for you at C:\ComboFix.txt which I will require in your next reply.


  • 0

Advertisements


#11
jhnb

jhnb

    Member

  • Topic Starter
  • Member
  • PipPip
  • 17 posts
k, doing it now.
  • 0

#12
jhnb

jhnb

    Member

  • Topic Starter
  • Member
  • PipPip
  • 17 posts
ok, here it is. thanks for writing the code for the fix.



ComboFix 11-06-28.04 - jhn barrett 06/29/2011 11:50:00.10.1 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.251.6 [GMT 10:00]
Running from: c:\documents and settings\jhn barrett\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\jhn barrett\Desktop\CFScript.txt
AV: avast! Antivirus *Disabled/Updated* {7591DB91-41F0-48A3-B128-1A293FD8233D}
.
.
((((((((((((((((((((((((( Files Created from 2011-05-28 to 2011-06-29 )))))))))))))))))))))))))))))))
.
.
2011-06-27 06:50 . 2011-06-27 06:50 -------- d-----w- C:\_OTL
2011-06-22 10:13 . 2011-06-22 15:45 -------- d-----w- c:\documents and settings\jhn barrett\Application Data\Azureus
2011-06-09 07:57 . 2011-06-09 07:57 -------- d-----w- c:\documents and settings\All Users\Application Data\Common Files
2011-06-09 02:30 . 2009-10-22 03:54 37392 ----a-w- c:\windows\system32\drivers\83480662.sys
2011-06-09 02:30 . 2009-10-09 13:31 315408 ----a-w- c:\windows\system32\drivers\8348066.sys
2011-06-09 02:30 . 2009-09-25 07:59 128016 ----a-w- c:\windows\system32\drivers\83480661.sys
2011-06-07 10:57 . 2011-06-07 10:57 -------- d-----w- c:\windows\system32\wbem\Repository
2011-06-07 10:55 . 2011-06-07 10:55 -------- d-----w- c:\program files\Common Files\xing shared
2011-05-31 22:30 . 2011-06-07 10:53 -------- d-----w- c:\program files\Microsoft CAPICOM 2.1.0.2
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-06-17 21:19 . 2011-05-19 09:46 404640 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2011-05-26 09:55 . 2011-05-26 09:55 0 ---ha-w- c:\documents and settings\jhn barrett\Local Settings\Application Data\BIT2C.tmp
2011-05-19 05:20 . 2010-04-08 12:38 17480 ----a-w- c:\windows\system32\drivers\hitmanpro35.sys
2011-05-10 12:10 . 2011-05-09 10:11 40112 ----a-w- c:\windows\avastSS.scr
2011-05-10 12:10 . 2011-05-09 10:11 199304 ----a-w- c:\windows\system32\aswBoot.exe
2011-05-10 12:03 . 2011-05-09 10:12 441176 ----a-w- c:\windows\system32\drivers\aswSnx.sys
2011-05-10 12:03 . 2011-05-09 10:12 307928 ----a-w- c:\windows\system32\drivers\aswSP.sys
2011-05-10 12:02 . 2011-05-09 10:12 49240 ----a-w- c:\windows\system32\drivers\aswTdi.sys
2011-05-10 12:02 . 2011-05-09 10:12 102616 ----a-w- c:\windows\system32\drivers\aswmon2.sys
2011-05-10 12:02 . 2011-05-09 10:12 96344 ----a-w- c:\windows\system32\drivers\aswmon.sys
2011-05-10 11:59 . 2011-05-09 10:12 25432 ----a-w- c:\windows\system32\drivers\aswRdr.sys
2011-05-10 11:59 . 2011-05-09 10:12 30808 ----a-w- c:\windows\system32\drivers\aavmker4.sys
2011-05-10 11:59 . 2011-05-09 10:12 19544 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys
2010-04-08 02:07 203776 --sh--w- c:\windows\system32\unrar.exe
.
.
((((((((((((((((((((((((((((( SnapShot@2011-06-28_05.51.23 )))))))))))))))))))))))))))))))))))))))))
.
+ 2011-06-28 08:38 . 2011-06-28 08:38 16384 c:\windows\temp\Perflib_Perfdata_c8c.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{e9911ec6-1bcc-40b0-9993-e0eea7f6953f}"= "c:\program files\DVDVideoSoft\tbDVDV.dll" [2010-03-09 2355224]
.
[HKEY_CLASSES_ROOT\clsid\{e9911ec6-1bcc-40b0-9993-e0eea7f6953f}]
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{30F9B915-B755-4826-820B-08FBA6BD249D}]
2010-10-18 01:26 3908192 ----a-w- c:\program files\ConduitEngine\ConduitEngine.dll
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{e9911ec6-1bcc-40b0-9993-e0eea7f6953f}]
2010-03-09 01:06 2355224 ----a-w- c:\program files\DVDVideoSoft\tbDVDV.dll
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{FD72061E-9FDE-484D-A58A-0BAB4151CAD8}]
2010-10-14 17:56 194912 ------w- c:\program files\Yontoo Layers Client\YontooIEClient.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{6B896ADB-4A82-46e2-858C-13134782CE34}"= "c:\program files\Xmlbar\Tudou Downloader\IEBar\xbietb.dll" [2009-12-15 413696]
"{e9911ec6-1bcc-40b0-9993-e0eea7f6953f}"= "c:\program files\DVDVideoSoft\tbDVDV.dll" [2010-03-09 2355224]
"{30F9B915-B755-4826-820B-08FBA6BD249D}"= "c:\program files\ConduitEngine\ConduitEngine.dll" [2010-10-18 3908192]
.
[HKEY_CLASSES_ROOT\clsid\{6b896adb-4a82-46e2-858c-13134782ce34}]
[HKEY_CLASSES_ROOT\XBIEBar.XBIEBarObj.1]
[HKEY_CLASSES_ROOT\TypeLib\{D4FB30ED-7DDB-4e2c-A7F2-C7B905D5D771}]
[HKEY_CLASSES_ROOT\XBIEBar.XBIEBarObj]
.
[HKEY_CLASSES_ROOT\clsid\{e9911ec6-1bcc-40b0-9993-e0eea7f6953f}]
.
[HKEY_CLASSES_ROOT\clsid\{30f9b915-b755-4826-820b-08fba6bd249d}]
.
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{E9911EC6-1BCC-40B0-9993-E0EEA7F6953F}"= "c:\program files\DVDVideoSoft\tbDVDV.dll" [2010-03-09 2355224]
.
[HKEY_CLASSES_ROOT\clsid\{e9911ec6-1bcc-40b0-9993-e0eea7f6953f}]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast]
@="{472083B0-C522-11CF-8763-00608CC02F24}"
[HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}]
2011-05-10 12:10 122512 ----a-w- c:\program files\AVAST Software\Avast\ashShell.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SUPERAntiSpyware"="c:\program files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2011-05-04 2424192]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2004-07-01 155648]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2004-07-01 118784]
"SoundMan"="SOUNDMAN.EXE" [2004-07-01 67584]
"AGRSMMSG"="AGRSMMSG.exe" [2004-07-22 88361]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2010-04-04 36272]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-09-21 932288]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2010-03-17 421888]
"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648]
"DivXUpdate"="c:\program files\DivX\DivX Update\DivXUpdate.exe" [2010-06-03 1144104]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2010-07-17 202256]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-05-14 248552]
"avast"="c:\program files\AVAST Software\Avast\avastUI.exe" [2011-05-10 3459712]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
"AvgUninstallURL"="start http:" [X]
.
c:\documents and settings\Administrator\Start Menu\Programs\Startup\
setup_9.0.0.722_23.03.2010_14-47.lnk - c:\documents and settings\jhn barrett\Desktop\Virus Removal Tool\setup_9.0.0.722_23.03.2010_14-47\startup.exe [N/A]
.
c:\documents and settings\jhn barrett\Start Menu\Programs\Startup\
setup_9.0.0.722_17.06.2011_18-59.lnk - c:\documents and settings\jhn barrett\Desktop\Virus Removal Tool1\setup_9.0.0.722_17.06.2011_18-59\startup.exe [2011-6-9 72208]
.
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2009-09-03 22:21 548352 ----a-w- c:\program files\SUPERAntiSpyware\SASWINLO.DLL
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"DisableNotifications"= 1 (0x1)
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"c:\\WINDOWS\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
.
R0 83480662;83480662 Boot Guard Driver;c:\windows\system32\drivers\83480662.sys [6/9/2011 12:30 PM 37392]
R1 83480661;83480661;c:\windows\system32\drivers\83480661.sys [6/9/2011 12:30 PM 128016]
R1 aswSnx;aswSnx;c:\windows\system32\drivers\aswSnx.sys [5/9/2011 8:12 PM 441176]
R1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [5/9/2011 8:12 PM 307928]
R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys [2/18/2010 4:25 AM 12872]
R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [5/11/2010 4:41 AM 67656]
R1 setup_9.0.0.722_17.06.2011_18-59drv;setup_9.0.0.722_17.06.2011_18-59drv;c:\windows\system32\drivers\8348066.sys [6/9/2011 12:30 PM 315408]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [5/9/2011 8:12 PM 19544]
R2 BecHelperService;BecHelperService;c:\program files\3 Mobile Broadband\3Connect\BecHelperService.exe [5/14/2011 4:15 PM 1737464]
R3 W33ND;W89C33 mPCI 802.11 Wireless LAN Adapter Driver;c:\windows\system32\drivers\W33ND.SYS [2/22/2006 2:32 AM 143904]
R3 WBFIRDMA;Winbond Infrared Device Driver;c:\windows\system32\drivers\wbfirdma.sys [3/21/2010 3:18 AM 37888]
S0 42442922;42442922 Boot Guard Driver;c:\windows\system32\DRIVERS\42442922.sys --> c:\windows\system32\DRIVERS\42442922.sys [?]
S2 gupdate1cad11f24ae2c00;Google Update Service (gupdate1cad11f24ae2c00);c:\program files\Google\Update\GoogleUpdate.exe [4/1/2010 8:11 AM 133104]
S3 gupdatem;Google Update Service (gupdatem);c:\program files\Google\Update\GoogleUpdate.exe [4/1/2010 8:11 AM 133104]
S3 massfilter;ZTE Mass Storage Filter Driver;c:\windows\system32\drivers\massfilter.sys [5/14/2011 4:15 PM 9216]
S3 MEMSWEEP2;MEMSWEEP2;\??\c:\windows\system32\D.tmp --> c:\windows\system32\D.tmp [?]
S3 ONDAusbmdm6k;ONDA Proprietary USB Driver;c:\windows\system32\drivers\ONDAusbmdm6k.sys [4/10/2009 3:58 PM 105344]
S3 ONDAusbnmea;ONDA NMEA Port;c:\windows\system32\drivers\ONDAusbnmea.sys [4/10/2009 3:58 PM 105344]
S3 ONDAusbser6k;ONDA Diagnostic Port;c:\windows\system32\drivers\ONDAusbser6k.sys [4/10/2009 3:58 PM 105344]
.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
.
.
Contents of the 'Scheduled Tasks' folder
.
2011-06-28 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 11:34]
.
2011-06-28 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-03-31 22:11]
.
2011-06-29 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-03-31 22:11]
.
2011-06-28 c:\windows\Tasks\RealUpgradeLogonTaskS-1-5-21-220523388-507921405-1343024091-1004.job
- c:\program files\Real\RealUpgrade\realupgrade.exe [2011-05-26 17:02]
.
2011-06-27 c:\windows\Tasks\RealUpgradeScheduledTaskS-1-5-21-220523388-507921405-1343024091-1004.job
- c:\program files\Real\RealUpgrade\realupgrade.exe [2011-05-26 17:02]
.
.
------- Supplementary Scan -------
.
IE: Free YouTube Download - c:\documents and settings\jhn barrett\Application Data\DVDVideoSoftIEHelpers\freeyoutubedownload.htm
IE: Free YouTube to MP3 Converter - c:\documents and settings\jhn barrett\Application Data\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm
IE: {{612F6E5C-B314-4bab-93D1-D266AAFBE700} - c:\program files\Xmlbar\Tudou Downloader\TudouDownloader(xmlbar).exe
FF - ProfilePath - c:\documents and settings\jhn barrett\Application Data\Mozilla\Firefox\Profiles\i34ihir7.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2786678&SearchSource=3&q={searchTerms}
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}
FF - Ext: Java Quick Starter: [email protected] - c:\program files\Java\jre6\lib\deploy\jqs\ff
FF - Ext: TranslatorBar 1 Toolbar: {00bf7b9c-acd2-4080-bea8-b1c41987070f} - %profile%\extensions\{00bf7b9c-acd2-4080-bea8-b1c41987070f}
FF - Ext: TinEye Reverse Image Search: [email protected] - %profile%\extensions\[email protected]
FF - Ext: Conduit Engine : [email protected] - %profile%\extensions\[email protected]
FF - user.js: yahoo.ytff.general.dontshowhpoffer - true
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2011-06-29 12:05
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes ...
.
scanning hidden autostart entries ...
.
scanning hidden files ...
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\MEMSWEEP2]
"ImagePath"="\??\c:\windows\system32\D.tmp"
.
--------------------- DLLs Loaded Under Running Processes ---------------------
.
- - - - - - - > 'winlogon.exe'(920)
c:\program files\SUPERAntiSpyware\SASWINLO.DLL
c:\windows\system32\WININET.dll
.
- - - - - - - > 'explorer.exe'(1044)
c:\windows\system32\WININET.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
.
Completion time: 2011-06-29 12:12:02
ComboFix-quarantined-files.txt 2011-06-29 02:11
ComboFix2.txt 2011-06-28 06:03
.
Pre-Run: 3,503,476,736 bytes free
Post-Run: 3,490,312,192 bytes free
.
- - End Of File - - 54CB7F75B253B320DD120378F544A18F
  • 0

#13
sempai

sempai

    Trusted Helper

  • Malware Removal
  • 785 posts
How's the computer running now?
  • 0

#14
jhnb

jhnb

    Member

  • Topic Starter
  • Member
  • PipPip
  • 17 posts
its a little hard to say as it hasn't been constant over the last month or so, it kinda comes and goes. like i said before sometimes it will work pretty well and other times it won't. at the moment i'm not having too much trouble getting online, maybe the occasional 'page couldn't be loaded', it is still rather slow when i open firefox tho, it can take up to 10 minutes before it actually opens which it has never done before recently. and since doing the combofix it has reset ie to default so now when i go online it opens that instead of ff, i have now noticed that ie doesnt seem to work properly, it doesn't load any pages or any notice to say it can't load pages or why, and half of the browser appears to be missing. i'll take a screenshot and show you. it looks like it has space where some kind of toolbar should be too, that could easily be from DLing software and not unticking the box to add, i couldn't say for sure because i cant see the tolbar anyway. i couldn't even say how long ie has been like this as i never use it.

should i try another otl and send the log?

Edited by jhnb, 30 June 2011 - 10:42 AM.

  • 0

#15
jhnb

jhnb

    Member

  • Topic Starter
  • Member
  • PipPip
  • 17 posts
i know its been a while but i don't remember ie looking like this



Posted Image
  • 0






Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP