The virus occasionaly redirects links to adverts or suspicious looking pages. I don't know how it was aquired. So far I've ran MBAM multiple times, CCleaner, Advanced SystemCare 4 multiple times, and IObit Malware Fighter multiple times. I followed the "How to fix Google Redirects" guide up until the point of using TDSSkiller, which I am unable to run.
Before I was hired (just recently), someone else had been brought in to fix the computer, and they infected the administrator account too.
Thank you in advance for any and all help.
Here is my OTL log:
OTL logfile created on: 6/23/2011 4:23:37 PM - Run 1
OTL by OldTimer - Version 3.2.24.1 Folder = C:\Documents and Settings\Administrator\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
509.98 Mb Total Physical Memory | 148.44 Mb Available Physical Memory | 29.11% Memory free
1.22 Gb Paging File | 0.84 Gb Available in Paging File | 68.98% Paging File free
Paging file location(s): C:\pagefile.sys 768 1536 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 37.20 Gb Total Space | 14.59 Gb Free Space | 39.22% Space Free | Partition Type: NTFS
Computer Name: CBU-2006031222 | User Name: Administrator | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - [2011/06/23 16:22:58 | 000,579,072 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Administrator\Desktop\OTL.exe
PRC - [2011/06/18 00:04:21 | 000,764,416 | ---- | M] (CrypKey Inc.) -- C:\WINDOWS\system32\xpsp4res32.exe
PRC - [2011/06/18 00:04:17 | 000,764,416 | ---- | M] (CrypKey Inc.) -- C:\WINDOWS\system32\msaudite32.exe
PRC - [2011/06/18 00:04:17 | 000,764,416 | ---- | M] (CrypKey Inc.) -- C:\WINDOWS\system32\mll_hp32.exe
PRC - [2011/06/01 14:10:00 | 000,821,080 | ---- | M] (IObit) -- C:\Program Files\IObit\IObit Malware Fighter\IMFsrv.exe
PRC - [2011/06/01 14:09:58 | 004,385,112 | ---- | M] (IObit) -- C:\Program Files\IObit\IObit Malware Fighter\IMF.exe
PRC - [2011/05/28 14:46:56 | 000,803,728 | ---- | M] (IObit) -- C:\Program Files\IObit\Advanced SystemCare 4\PMonitor.exe
PRC - [2011/05/28 14:46:56 | 000,412,560 | ---- | M] (IObit) -- C:\Program Files\IObit\Advanced SystemCare 4\ASCTray.exe
PRC - [2011/05/28 14:46:56 | 000,353,168 | ---- | M] (IObit) -- C:\Program Files\IObit\Advanced SystemCare 4\ASCService.exe
PRC - [2008/04/13 19:12:19 | 001,033,728 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe
PRC - [2007/10/16 21:50:00 | 000,144,704 | ---- | M] (McAfee, Inc.) -- C:\Program Files\McAfee\VirusScan Enterprise\Mcshield.exe
PRC - [2007/10/16 21:50:00 | 000,054,608 | ---- | M] (McAfee, Inc.) -- C:\Program Files\McAfee\VirusScan Enterprise\VsTskMgr.exe
========== Modules (SafeList) ==========
MOD - [2011/06/23 16:22:58 | 000,579,072 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Administrator\Desktop\OTL.exe
MOD - [2010/08/23 11:12:02 | 001,054,208 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.6028_x-ww_61e65202\comctl32.dll
MOD - [2008/04/13 19:12:05 | 000,005,632 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\security.dll
========== Win32 Services (SafeList) ==========
SRV - File not found [Auto | Stopped] -- -- (AOL ACS)
SRV - [2011/06/18 00:04:21 | 000,764,416 | ---- | M] (CrypKey Inc.) [Auto | Running] -- C:\WINDOWS\system32\xpsp4res32.exe -- (Schedule32)
SRV - [2011/06/18 00:04:17 | 000,764,416 | ---- | M] (CrypKey Inc.) [Auto | Running] -- C:\WINDOWS\system32\mll_hp32.exe -- (EapHost32)
SRV - [2011/06/01 14:10:00 | 000,821,080 | ---- | M] (IObit) [Auto | Running] -- C:\Program Files\IObit\IObit Malware Fighter\IMFsrv.exe -- (IMFservice)
SRV - [2011/05/28 14:46:56 | 000,353,168 | ---- | M] (IObit) [Auto | Running] -- C:\Program Files\IObit\Advanced SystemCare 4\ASCService.exe -- (AdvancedSystemCareService)
SRV - [2011/05/25 15:14:34 | 000,053,248 | ---- | M] (NOS Microsystems Ltd.) [On_Demand | Stopped] -- C:\Program Files\NOS\bin\getPlus_Helper_3004.dll -- (nosGetPlusHelper) getPlus®
SRV - [2007/10/25 11:03:28 | 000,103,744 | ---- | M] (McAfee, Inc.) [Unknown | Stopped] -- C:\Program Files\McAfee\Common Framework\FrameworkService.exe -- (McAfeeFramework)
SRV - [2007/10/16 21:50:00 | 000,144,704 | ---- | M] (McAfee, Inc.) [Unknown | Running] -- C:\Program Files\McAfee\VirusScan Enterprise\Mcshield.exe -- (McShield)
SRV - [2007/10/16 21:50:00 | 000,054,608 | ---- | M] (McAfee, Inc.) [Unknown | Running] -- C:\Program Files\McAfee\VirusScan Enterprise\VsTskMgr.exe -- (McTaskManager)
========== Driver Services (SafeList) ==========
DRV - [2011/04/27 19:18:34 | 000,239,472 | ---- | M] () [File_System | On_Demand | Running] -- C:\Program Files\IObit\IObit Malware Fighter\Drivers\wxp_x86\FileMonitor.sys -- (FileMonitor)
DRV - [2011/03/23 01:00:08 | 000,016,080 | ---- | M] (IObit.com) [Kernel | On_Demand | Running] -- C:\Program Files\IObit\IObit Malware Fighter\Drivers\wxp_x86\UrlFilter.sys -- (UrlFilter)
DRV - [2011/03/23 01:00:06 | 000,030,368 | ---- | M] (IObit.com) [Kernel | On_Demand | Running] -- C:\Program Files\IObit\IObit Malware Fighter\Drivers\wxp_x86\RegFilter.sys -- (RegFilter)
DRV - [2007/10/16 21:50:00 | 000,171,272 | ---- | M] (McAfee, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\mfehidk.sys -- (mfehidk)
DRV - [2007/10/16 21:50:00 | 000,072,680 | ---- | M] (McAfee, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\mfeavfk.sys -- (mfeavfk)
DRV - [2007/10/16 21:50:00 | 000,064,168 | ---- | M] (McAfee, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\mfeapfk.sys -- (mfeapfk)
DRV - [2007/10/16 21:50:00 | 000,051,944 | ---- | M] (McAfee, Inc.) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\mfetdik.sys -- (mfetdik)
DRV - [2007/10/16 21:50:00 | 000,033,960 | ---- | M] (McAfee, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\mfebopk.sys -- (mfebopk)
DRV - [2007/10/16 21:50:00 | 000,031,784 | ---- | M] (McAfee, Inc.) [Kernel | System | Running] -- C:\Program Files\McAfee\VirusScan Enterprise\mferkdk.sys -- (mferkdk)
DRV - [2003/11/17 16:59:20 | 000,212,224 | ---- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\HSFHWBS2.sys -- (HSFHWBS2)
DRV - [2003/11/17 16:58:02 | 000,680,704 | ---- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\HSF_CNXT.sys -- (winachsf)
DRV - [2003/11/17 16:56:26 | 001,042,432 | ---- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\HSF_DP.sys -- (HSF_DP)
DRV - [2003/01/10 16:13:04 | 000,033,588 | R--- | M] (America Online, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\wanatw4.sys -- (wanatw) WAN Miniport (ATW)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.msn.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,XMLHTTP_UUID_Default = E3 0C E1 17 B6 AD BF 4E B4 FA 1A 46 A3 E6 E6 21 [binary data]
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
O1 HOSTS File: ([2011/06/22 11:27:21 | 000,000,098 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2 - BHO: (no name) - {492499B4-9FDD-4A26-9A12-578BC31A0F8d} - Reg Error: Value error. File not found
O2 - BHO: (d0109716) - {526BBD62-6438-D33B-22A2-C6A2A9726DA9} - C:\WINDOWS\system32\MP43DECD32.dll (CrypKey Inc.)
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.7.6406.1642\swg.dll (Google Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - No CLSID value found.
O4 - HKLM..\Run: [IObit Malware Fighter] C:\Program Files\IObit\IObit Malware Fighter\IMF.exe (IObit)
O4 - HKCU..\Run: [Advanced SystemCare 4] C:\Program Files\IObit\Advanced SystemCare 4\ASCTray.exe (IObit)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Infodelivery present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Recovery present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O8 - Extra context menu item: Google Sidewiki... - C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_6CE5017F567343CA.dll (Google Inc.)
O9 - Extra 'Tools' menuitem : Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre6\bin\npjpi160_26.dll (Sun Microsystems, Inc.)
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://download.macr...director/sw.cab (Reg Error: Key error.)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://download.micr...heckControl.cab (Windows Genuine Advantage Validation Tool)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_26)
O16 - DPF: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_26)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_26)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.ad...Plus/1.6/gp.cab (get_atlcom Class)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 151.164.11.201 151.164.1.8
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = cold20.coldwellbankerunited.com
O20 - AppInit_DLLs: (C:\WINDOWS\system32\MP43DECD32.dll) - C:\WINDOWS\system32\MP43DECD32.dll (CrypKey Inc.)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2008/02/21 15:57:11 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
========== Files/Folders - Created Within 30 Days ==========
[2011/06/23 16:22:43 | 000,579,072 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\Administrator\Desktop\OTL.exe
[2011/06/23 16:09:55 | 000,349,696 | ---- | C] (CrypKey Inc.) -- C:\WINDOWS\System32\atmpvcno32.dll
[2011/06/23 12:19:55 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\IObit Malware Fighter
[2011/06/23 12:17:44 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\Advanced SystemCare 4
[2011/06/23 12:17:22 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Administrator\Application Data\IObit
[2011/06/23 12:17:15 | 000,000,000 | ---D | C] -- C:\Program Files\IObit
[2011/06/22 12:17:32 | 001,441,584 | ---- | C] (Kaspersky Lab ZAO) -- C:\Documents and Settings\Administrator\Desktop\tds.exe
[2011/06/22 12:11:47 | 000,000,000 | -H-D | C] -- C:\WINDOWS\PIF
[2011/06/22 11:39:11 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Administrator\Desktop\GooredFix Backups
[2011/06/22 11:26:41 | 000,000,000 | ---D | C] -- C:\_OTM
[2011/06/22 11:17:47 | 000,071,398 | ---- | C] (jpshortstuff) -- C:\Documents and Settings\Administrator\Desktop\GooredFix.exe
[2011/06/22 11:16:19 | 000,522,752 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\Administrator\Desktop\OTM.exe
[2011/06/22 10:56:15 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Administrator\My Documents\erunt
[2011/06/22 10:45:43 | 000,000,000 | ---D | C] -- C:\Program Files\HijackThis
[2011/06/22 10:37:33 | 000,092,672 | ---- | C] (Option^Explicit Software [email protected]) -- C:\Documents and Settings\Administrator\Desktop\KillBox.exe
[2011/06/22 10:37:18 | 000,000,000 | ---D | C] -- C:\!KillBox
[2011/06/22 10:27:28 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Sun
[2011/06/22 10:27:23 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Java
[2011/06/21 17:16:51 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Administrator\Application Data\Macromedia
[2011/06/21 17:09:35 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\Malwarebytes' Anti-Malware
[2011/06/21 17:06:13 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Administrator\Application Data\Malwarebytes
[2011/06/21 17:02:49 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Administrator\Application Data\Google
[2011/06/21 16:54:11 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Administrator\Local Settings\Application Data\Google
[2011/06/21 16:53:41 | 000,000,000 | ---D | C] -- C:\Program Files\Google
[2011/06/21 16:52:50 | 000,000,000 | ---D | C] -- C:\Program Files\NOS
[2011/06/21 16:49:28 | 000,000,000 | -HSD | C] -- C:\Documents and Settings\Administrator\PrivacIE
[2011/06/18 00:04:26 | 000,764,416 | ---- | C] (CrypKey Inc.) -- C:\WINDOWS\System32\msaudite32.exe
[2011/06/18 00:04:24 | 000,764,416 | ---- | C] (CrypKey Inc.) -- C:\WINDOWS\System32\xpsp4res32.exe
[2011/06/18 00:04:24 | 000,169,472 | ---- | C] (CrypKey Inc.) -- C:\WINDOWS\System32\MP43DECD32.dll
[2011/06/18 00:04:21 | 000,764,416 | ---- | C] (CrypKey Inc.) -- C:\WINDOWS\System32\mll_hp32.exe
[2011/06/16 14:16:48 | 000,000,000 | ---D | C] -- C:\Qoobox
[2011/06/16 12:57:47 | 000,039,984 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2011/06/16 12:57:44 | 000,000,000 | ---D | C] -- C:\Program Files\Malwarebytes' Anti-Malware
[2011/06/16 11:45:56 | 000,000,000 | -HSD | C] -- C:\RECYCLER
[2011/06/16 11:15:42 | 000,000,000 | ---D | C] -- C:\WINDOWS\temp
[2011/06/16 11:08:51 | 000,000,000 | ---D | C] -- C:\ComboFix
[1 C:\Documents and Settings\Administrator\Desktop\*.tmp files -> C:\Documents and Settings\Administrator\Desktop\*.tmp -> ]
[1 C:\Documents and Settings\Administrator\*.tmp files -> C:\Documents and Settings\Administrator\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2011/06/23 16:22:58 | 000,579,072 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Administrator\Desktop\OTL.exe
[2011/06/23 16:18:06 | 000,000,060 | ---- | M] () -- C:\WINDOWS\System32\70e3c044
[2011/06/23 16:17:34 | 000,005,537 | ---- | M] () -- C:\Documents and Settings\Administrator\Desktop\hijackthis2
[2011/06/23 16:13:14 | 000,013,646 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2011/06/23 16:10:45 | 000,000,896 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2011/06/23 16:10:45 | 000,000,286 | ---- | M] () -- C:\WINDOWS\tasks\ASC4_PerformanceMonitor.job
[2011/06/23 16:10:35 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2011/06/23 16:09:55 | 000,349,696 | ---- | M] (CrypKey Inc.) -- C:\WINDOWS\System32\atmpvcno32.dll
[2011/06/23 15:59:27 | 000,000,900 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2011/06/23 12:19:55 | 000,000,826 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\IObit Malware Fighter.lnk
[2011/06/23 12:17:48 | 000,000,896 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Quick Care.lnk
[2011/06/23 12:17:47 | 000,000,874 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Advanced SystemCare 4.lnk
[2011/06/22 12:17:37 | 001,441,584 | ---- | M] (Kaspersky Lab ZAO) -- C:\Documents and Settings\Administrator\Desktop\tds.exe
[2011/06/22 11:27:21 | 000,000,098 | ---- | M] () -- C:\WINDOWS\System32\drivers\etc\Hosts
[2011/06/22 11:18:41 | 001,309,375 | ---- | M] () -- C:\Documents and Settings\Administrator\My Documents\tdsskiller.zip
[2011/06/22 11:17:47 | 000,071,398 | ---- | M] (jpshortstuff) -- C:\Documents and Settings\Administrator\Desktop\GooredFix.exe
[2011/06/22 11:16:35 | 000,522,752 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Administrator\Desktop\OTM.exe
[2011/06/22 10:55:01 | 000,513,320 | ---- | M] () -- C:\Documents and Settings\Administrator\My Documents\erunt.zip
[2011/06/22 10:46:04 | 000,000,642 | ---- | M] () -- C:\Documents and Settings\Administrator\Desktop\Shortcut to HijackThis.lnk
[2011/06/22 10:37:33 | 000,092,672 | ---- | M] (Option^Explicit Software [email protected]) -- C:\Documents and Settings\Administrator\Desktop\KillBox.exe
[2011/06/21 17:09:36 | 000,000,784 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2011/06/21 16:58:50 | 000,001,734 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Adobe Reader X.lnk
[2011/06/21 16:45:26 | 000,118,152 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2011/06/18 00:04:26 | 000,000,097 | ---- | M] () -- C:\WINDOWS\System32\1523437620
[2011/06/18 00:04:24 | 000,169,472 | ---- | M] (CrypKey Inc.) -- C:\WINDOWS\System32\MP43DECD32.dll
[2011/06/18 00:04:21 | 000,764,416 | ---- | M] (CrypKey Inc.) -- C:\WINDOWS\System32\xpsp4res32.exe
[2011/06/18 00:04:17 | 000,764,416 | ---- | M] (CrypKey Inc.) -- C:\WINDOWS\System32\msaudite32.exe
[2011/06/18 00:04:17 | 000,764,416 | ---- | M] (CrypKey Inc.) -- C:\WINDOWS\System32\mll_hp32.exe
[2011/06/16 12:38:26 | 000,000,127 | ---- | M] () -- C:\WINDOWS\System32\MRT.INI
[2011/06/16 12:08:33 | 000,444,322 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat
[2011/06/16 12:08:33 | 000,072,198 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat
[2011/06/16 11:03:25 | 000,000,664 | ---- | M] () -- C:\WINDOWS\System32\d3d9caps.dat
[2011/06/16 10:57:58 | 000,000,168 | ---- | M] () -- C:\Documents and Settings\All Users\Application Data\~16703268
[2011/06/16 10:57:58 | 000,000,144 | ---- | M] () -- C:\Documents and Settings\All Users\Application Data\~16703268r
[2011/06/09 16:46:19 | 000,000,352 | ---- | M] () -- C:\Documents and Settings\All Users\Application Data\16703268
[2011/06/04 17:32:39 | 000,000,078 | ---- | M] () -- C:\WINDOWS\tkweb.ini
[2011/05/29 09:11:30 | 000,039,984 | ---- | M] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[1 C:\Documents and Settings\Administrator\Desktop\*.tmp files -> C:\Documents and Settings\Administrator\Desktop\*.tmp -> ]
[1 C:\Documents and Settings\Administrator\*.tmp files -> C:\Documents and Settings\Administrator\*.tmp -> ]
========== Files Created - No Company Name ==========
[2011/06/23 16:17:34 | 000,005,537 | ---- | C] () -- C:\Documents and Settings\Administrator\Desktop\hijackthis2
[2011/06/23 12:19:55 | 000,000,826 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\IObit Malware Fighter.lnk
[2011/06/23 12:18:26 | 000,000,286 | ---- | C] () -- C:\WINDOWS\tasks\ASC4_PerformanceMonitor.job
[2011/06/23 12:17:48 | 000,000,896 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Quick Care.lnk
[2011/06/23 12:17:47 | 000,000,874 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Advanced SystemCare 4.lnk
[2011/06/22 11:18:36 | 001,309,375 | ---- | C] () -- C:\Documents and Settings\Administrator\My Documents\tdsskiller.zip
[2011/06/22 10:54:49 | 000,513,320 | ---- | C] () -- C:\Documents and Settings\Administrator\My Documents\erunt.zip
[2011/06/22 10:46:04 | 000,000,642 | ---- | C] () -- C:\Documents and Settings\Administrator\Desktop\Shortcut to HijackThis.lnk
[2011/06/21 17:09:36 | 000,000,784 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2011/06/21 16:58:49 | 000,001,804 | ---- | C] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Adobe Reader X.lnk
[2011/06/21 16:58:49 | 000,001,734 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Adobe Reader X.lnk
[2011/06/21 16:54:17 | 000,000,900 | ---- | C] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2011/06/21 16:54:16 | 000,000,896 | ---- | C] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2011/06/21 16:45:26 | 000,118,152 | ---- | C] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2011/06/21 16:20:08 | 000,000,060 | ---- | C] () -- C:\WINDOWS\System32\70e3c044
[2011/06/18 00:04:21 | 000,000,097 | ---- | C] () -- C:\WINDOWS\System32\1523437620
[2011/06/16 11:13:51 | 000,001,537 | ---- | C] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Photo Story 3 for Windows.lnk
[2011/06/16 11:13:51 | 000,000,786 | ---- | C] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Windows Movie Maker.lnk
[2011/06/16 11:13:50 | 000,002,341 | ---- | C] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Adobe Acrobat 6.0 Standard.lnk
[2011/06/16 11:13:50 | 000,002,339 | ---- | C] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Acrobat Distiller 6.0.lnk
[2011/06/16 11:03:25 | 000,000,664 | ---- | C] () -- C:\WINDOWS\System32\d3d9caps.dat
[2011/06/10 11:00:52 | 000,000,144 | ---- | C] () -- C:\Documents and Settings\All Users\Application Data\~16703268r
[2011/06/10 11:00:51 | 000,000,168 | ---- | C] () -- C:\Documents and Settings\All Users\Application Data\~16703268
[2011/06/09 16:46:19 | 000,000,352 | ---- | C] () -- C:\Documents and Settings\All Users\Application Data\16703268
[2011/05/14 09:49:19 | 000,000,078 | ---- | C] () -- C:\WINDOWS\tkweb.ini
[2011/03/30 09:36:08 | 000,208,896 | ---- | C] () -- C:\WINDOWS\MBR.exe
[2011/03/30 09:36:05 | 000,256,512 | ---- | C] () -- C:\WINDOWS\PEV.exe
[2011/03/30 09:36:04 | 000,098,816 | ---- | C] () -- C:\WINDOWS\sed.exe
[2011/03/30 09:36:04 | 000,080,412 | ---- | C] () -- C:\WINDOWS\grep.exe
[2011/03/30 09:36:04 | 000,068,096 | ---- | C] () -- C:\WINDOWS\zip.exe
[2011/03/28 09:50:03 | 000,013,432 | -HS- | C] () -- C:\Documents and Settings\All Users\Application Data\5nfu81broaes3q06d
[2010/12/27 12:00:37 | 000,037,027 | ---- | C] () -- C:\WINDOWS\atmoUn.exe
[2010/06/09 13:51:59 | 000,172,128 | R--- | C] () -- C:\WINDOWS\_isusr32.dll
[2010/06/09 13:51:53 | 000,045,056 | ---- | C] () -- C:\WINDOWS\System32\_isusr2k.dll
[2010/06/09 13:51:35 | 000,000,231 | ---- | C] () -- C:\WINDOWS\System32\scnwpm.dat
[2009/08/03 15:07:42 | 000,403,816 | ---- | C] () -- C:\WINDOWS\System32\OGACheckControl.dll
[2009/08/03 15:07:42 | 000,230,768 | ---- | C] () -- C:\WINDOWS\System32\OGAEXEC.exe
[2009/06/11 03:06:07 | 000,000,127 | ---- | C] () -- C:\WINDOWS\System32\MRT.INI
[2008/05/09 12:30:44 | 000,135,168 | ---- | C] () -- C:\WINDOWS\System32\snmp_pp.dll
[2008/02/28 18:22:15 | 000,000,335 | ---- | C] () -- C:\WINDOWS\nsreg.dat
[2008/02/22 13:28:52 | 000,165,888 | ---- | C] () -- C:\WINDOWS\System32\hpgt53.dll
[2008/02/21 18:19:56 | 000,000,376 | ---- | C] () -- C:\WINDOWS\ODBC.INI
[2008/02/21 17:43:07 | 000,000,280 | ---- | C] () -- C:\WINDOWS\System32\epoPGPsdk.dll.sig
[2008/02/21 16:06:52 | 000,002,048 | --S- | C] () -- C:\WINDOWS\bootstat.dat
[2008/02/21 15:53:37 | 000,021,640 | ---- | C] () -- C:\WINDOWS\System32\emptyregdb.dat
[2008/02/21 13:57:06 | 000,000,155 | ---- | C] () -- C:\WINDOWS\hpbafd.ini
[2008/02/20 23:21:04 | 000,004,161 | ---- | C] () -- C:\WINDOWS\ODBCINST.INI
[2005/06/11 16:40:42 | 000,000,100 | ---- | C] () -- C:\WINDOWS\System32\SN0ELMON.dat
[2004/08/04 07:00:00 | 013,107,200 | ---- | C] () -- C:\WINDOWS\System32\oembios.bin
[2004/08/04 07:00:00 | 000,755,200 | ---- | C] () -- C:\WINDOWS\System32\ir50_32.dll
[2004/08/04 07:00:00 | 000,673,088 | ---- | C] () -- C:\WINDOWS\System32\mlang.dat
[2004/08/04 07:00:00 | 000,444,322 | ---- | C] () -- C:\WINDOWS\System32\perfh009.dat
[2004/08/04 07:00:00 | 000,338,432 | ---- | C] () -- C:\WINDOWS\System32\ir41_qcx.dll
[2004/08/04 07:00:00 | 000,272,128 | ---- | C] () -- C:\WINDOWS\System32\perfi009.dat
[2004/08/04 07:00:00 | 000,218,003 | ---- | C] () -- C:\WINDOWS\System32\dssec.dat
[2004/08/04 07:00:00 | 000,200,192 | ---- | C] () -- C:\WINDOWS\System32\ir50_qc.dll
[2004/08/04 07:00:00 | 000,183,808 | ---- | C] () -- C:\WINDOWS\System32\ir50_qcx.dll
[2004/08/04 07:00:00 | 000,120,320 | ---- | C] () -- C:\WINDOWS\System32\ir41_qc.dll
[2004/08/04 07:00:00 | 000,072,198 | ---- | C] () -- C:\WINDOWS\System32\perfc009.dat
[2004/08/04 07:00:00 | 000,046,258 | ---- | C] () -- C:\WINDOWS\System32\mib.bin
[2004/08/04 07:00:00 | 000,028,626 | ---- | C] () -- C:\WINDOWS\System32\perfd009.dat
[2004/08/04 07:00:00 | 000,004,569 | ---- | C] () -- C:\WINDOWS\System32\secupd.dat
[2004/08/04 07:00:00 | 000,004,461 | ---- | C] () -- C:\WINDOWS\System32\oembios.dat
[2004/08/04 07:00:00 | 000,001,804 | ---- | C] () -- C:\WINDOWS\System32\dcache.bin
[2004/08/04 07:00:00 | 000,000,741 | ---- | C] () -- C:\WINDOWS\System32\noise.dat
[2003/01/07 16:05:08 | 000,002,695 | ---- | C] () -- C:\WINDOWS\System32\OUTLPERF.INI
========== LOP Check ==========
[2011/06/23 12:19:48 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Administrator\Application Data\IObit
[2008/03/14 09:29:14 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\MSScanAppDataDir
[2009/06/09 15:50:10 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\SSScanAppDataDir
[2010/12/27 12:00:33 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Viewpoint
[2011/06/23 16:10:45 | 000,000,286 | ---- | M] () -- C:\WINDOWS\Tasks\ASC4_PerformanceMonitor.job
========== Purity Check ==========
< End of report >