It appears I am infected with a search engine redirect virus. It is happening with I use IE, Firefox and Chrome. I tried following the steps located here: http://www.geekstogo...ogle-redirects/ but the TDSSKiller process does not find any problems. The search redirect seems to be taking me to "marvelous search" of some sort. Here is my OTL log. Thank you!
OTL logfile created on: 10/6/2011 2:18:41 PM - Run 1
OTL by OldTimer - Version 3.2.29.1 Folder = C:\Users\buich01\Desktop
64bit- Enterprise Edition (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7600.16385)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
3.87 Gb Total Physical Memory | 1.87 Gb Available Physical Memory | 48.36% Memory free
7.74 Gb Paging File | 5.58 Gb Available in Paging File | 72.07% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 232.53 Gb Total Space | 186.15 Gb Free Space | 80.05% Space Free | Partition Type: NTFS
Computer Name: BUICH01-WIN | User Name: buich01 | NOT logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan | Include 64bit Scans
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - [2011/10/06 14:17:57 | 000,582,656 | ---- | M] (OldTimer Tools) -- C:\Users\buich01\Desktop\OTL.exe
PRC - [2011/07/26 14:03:34 | 005,735,680 | ---- | M] (Microsoft Corporation) -- C:\Program Files (x86)\Microsoft Office Communicator\communicator.exe
PRC - [2011/05/25 02:09:14 | 002,214,504 | ---- | M] (NVIDIA Corporation) -- C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe
PRC - [2011/05/20 22:35:16 | 000,378,472 | ---- | M] (NVIDIA Corporation) -- C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
PRC - [2011/02/10 23:34:22 | 000,664,944 | ---- | M] (Juniper Networks) -- C:\Program Files (x86)\Juniper Networks\Common Files\dsNcService.exe
PRC - [2009/10/03 00:09:22 | 000,083,208 | ---- | M] (CA International Inc.) -- C:\Program Files (x86)\CA\DSM\bin\cfSysTray.exe
PRC - [2009/07/13 21:14:28 | 000,015,360 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\PING.EXE
PRC - [2009/01/23 17:36:50 | 000,159,744 | ---- | M] () -- C:\Program Files (x86)\CA\SC\Csam\SockAdapter\bin\CSAMPmux.exe
PRC - [2008/08/16 17:44:08 | 000,070,968 | ---- | M] (Citrix Systems, Inc.) -- C:\Program Files (x86)\Citrix\ICA Client\ssonsvr.exe
PRC - [2000/06/08 13:15:24 | 000,050,176 | ---- | M] () -- C:\Windows\LogWatNT.exe
========== Modules (No Company Name) ==========
MOD - [2011/06/07 12:28:06 | 000,987,136 | ---- | M] () -- C:\Program Files\CA\SharedComponents\lib\libetpki_openssl_crypto.dll
MOD - [2011/06/07 12:28:06 | 000,184,320 | ---- | M] () -- C:\Program Files\CA\SharedComponents\lib\libetpki_openssl_ssl.dll
MOD - [2010/03/24 21:17:36 | 008,794,464 | ---- | M] () -- C:\Program Files (x86)\Microsoft Office\Office14\1033\GrooveIntlResource.dll
MOD - [2010/02/28 02:55:42 | 001,040,736 | ---- | M] () -- C:\Program Files (x86)\Microsoft Office\Office14\ADDINS\UmOutlookAddin.dll
MOD - [2010/01/30 02:41:12 | 004,254,560 | ---- | M] () -- C:\Program Files (x86)\Common Files\microsoft shared\OFFICE14\Cultures\OFFICE.ODF
MOD - [2009/07/13 21:15:51 | 000,232,448 | ---- | M] () -- \\?\globalroot\systemroot\syswow64\mswsock.DLL
MOD - [2009/07/13 21:15:51 | 000,232,448 | ---- | M] () -- \\.\globalroot\systemroot\syswow64\mswsock.dll
========== Win32 Services (SafeList) ==========
SRV:64bit: - [2011/05/03 15:20:41 | 000,518,824 | ---- | M] (CA) [Auto | Running] -- C:\Program Files\CA\eTrustITM\InoTask.exe -- (InoTask)
SRV:64bit: - [2011/05/03 15:16:52 | 000,299,520 | ---- | M] (CA) [Auto | Running] -- C:\Program Files\CA\eTrustITM\InoRT.exe -- (InoRT)
SRV:64bit: - [2011/05/03 15:16:52 | 000,239,104 | ---- | M] (CA) [Auto | Running] -- C:\Program Files\CA\eTrustITM\InoRpc.exe -- (InoRPC)
SRV:64bit: - [2011/02/08 13:21:00 | 000,047,416 | ---- | M] (Mozy, Inc.) [Auto | Running] -- C:\Program Files\MozyPro\mozyprobackup.exe -- (mozyprobackup)
SRV:64bit: - [2009/07/13 21:41:27 | 001,011,712 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend)
SRV:64bit: - [2009/07/13 21:40:01 | 000,193,536 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\appmgmts.dll -- (AppMgmt)
SRV:64bit: - [2007/02/05 08:09:46 | 000,117,248 | ---- | M] (CA, Inc.) [Auto | Running] -- C:\Program Files\CA\SharedComponents\iTechnology\igateway.exe -- (iGateway)
SRV - [2011/05/25 02:09:14 | 002,214,504 | ---- | M] (NVIDIA Corporation) [Auto | Running] -- C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe -- (nvUpdatusService)
SRV - [2011/05/20 22:35:16 | 000,378,472 | ---- | M] (NVIDIA Corporation) [Auto | Running] -- C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe -- (Stereo Service)
SRV - [2011/02/10 23:34:22 | 000,664,944 | ---- | M] (Juniper Networks) [Auto | Running] -- C:\Program Files (x86)\Juniper Networks\Common Files\dsNcService.exe -- (dsNcService)
SRV - [2010/06/25 13:07:20 | 000,117,264 | ---- | M] (CACE Technologies, Inc.) [On_Demand | Stopped] -- C:\Program Files (x86)\WinPcap\rpcapd.exe -- (rpcapd) Remote Packet Capture Protocol v.0 (experimental)
SRV - [2009/10/03 00:09:22 | 000,195,848 | ---- | M] (CA International Inc.) [Auto | Stopped] -- C:\Program Files (x86)\CA\DSM\bin\caf.exe -- (caf)
SRV - [2009/06/11 16:35:40 | 000,181,512 | ---- | M] (CA, Inc.) [Auto | Stopped] -- C:\Program Files (x86)\CA\SC\CAM\bin\cam.exe -- (CA-MessageQueuing)
SRV - [2009/06/10 17:23:09 | 000,066,384 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32)
SRV - [2009/01/23 17:36:50 | 000,159,744 | ---- | M] () [Auto | Running] -- C:\Program Files (x86)\CA\SC\Csam\SockAdapter\bin\csampmux.exe -- (CA-SAM-Pmux)
SRV - [2000/06/08 13:15:24 | 000,050,176 | ---- | M] () [Auto | Running] -- C:\Windows\LogWatNT.exe -- (LogWatch)
========== Driver Services (SafeList) ==========
DRV:64bit: - [2011/05/25 02:09:17 | 000,174,184 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\nvhda64v.sys -- (NVHDA)
DRV:64bit: - [2011/03/11 02:22:41 | 000,107,904 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsata.sys -- (amdsata)
DRV:64bit: - [2011/03/11 02:22:40 | 000,027,008 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\amdxata.sys -- (amdxata)
DRV:64bit: - [2011/02/10 23:19:58 | 000,032,768 | ---- | M] (Juniper Networks) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\dsNcAdpt.sys -- (dsNcAdpt)
DRV:64bit: - [2011/02/08 13:20:52 | 000,066,552 | ---- | M] (Mozy, Inc.) [File_System | System | Running] -- C:\Windows\SysNative\drivers\mozypro.sys -- (mozyproFilter)
DRV:64bit: - [2010/10/28 07:42:32 | 000,315,568 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\e1c62x64.sys -- (e1cexpress) Intel®
DRV:64bit: - [2010/06/25 13:07:26 | 000,035,344 | ---- | M] (CACE Technologies, Inc.) [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\npf.sys -- (NPF)
DRV:64bit: - [2009/12/10 09:37:56 | 000,294,064 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\e1k62x64.sys -- (e1kexpress) Intel®
DRV:64bit: - [2009/10/03 00:11:30 | 000,037,904 | ---- | M] (CA International Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\rcSmCard.sys -- (rcSmCard)
DRV:64bit: - [2009/10/03 00:11:30 | 000,011,280 | ---- | M] (CA International Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\rcVidMpt.sys -- (rcVidCap)
DRV:64bit: - [2009/07/13 21:52:20 | 000,194,128 | ---- | M] (AMD Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsbs.sys -- (amdsbs)
DRV:64bit: - [2009/07/13 21:48:04 | 000,065,600 | ---- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\lsi_sas2.sys -- (LSI_SAS2)
DRV:64bit: - [2009/07/13 21:47:48 | 000,077,888 | ---- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\HpSAMD.sys -- (HpSAMD)
DRV:64bit: - [2009/07/13 21:45:55 | 000,024,656 | ---- | M] (Promise Technology) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\stexstor.sys -- (stexstor)
DRV:64bit: - [2009/07/13 19:31:10 | 000,109,056 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\sdbus.sys -- (sdbus)
DRV:64bit: - [2009/07/13 19:21:48 | 000,038,400 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\tpm.sys -- (TPM)
DRV:64bit: - [2009/06/23 15:28:54 | 000,056,344 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\HECIx64.sys -- (HECIx64) Intel®
DRV:64bit: - [2009/06/22 15:01:26 | 000,497,152 | ---- | M] (Analog Devices, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\ADIHdAud.sys -- (ADIHdAudAddService)
DRV:64bit: - [2009/06/10 17:01:11 | 001,485,312 | ---- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\VSTDPV6.SYS -- (SrvHsfV92)
DRV:64bit: - [2009/06/10 17:01:11 | 000,740,864 | ---- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\VSTCNXT6.SYS -- (SrvHsfWinac)
DRV:64bit: - [2009/06/10 17:01:11 | 000,292,864 | ---- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\VSTAZL6.SYS -- (SrvHsfHDA)
DRV:64bit: - [2009/06/10 16:37:05 | 006,108,416 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\igdkmd64.sys -- (igfx)
DRV:64bit: - [2009/06/10 16:34:33 | 003,286,016 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\evbda.sys -- (ebdrv)
DRV:64bit: - [2009/06/10 16:34:28 | 000,468,480 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\bxvbda.sys -- (b06bdrv)
DRV:64bit: - [2009/06/10 16:34:23 | 000,270,848 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\b57nd60a.sys -- (b57nd60a)
DRV:64bit: - [2009/06/10 16:31:59 | 000,031,232 | ---- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\hcw85cir.sys -- (hcw85cir)
DRV:64bit: - [2007/10/18 21:14:28 | 000,133,136 | ---- | M] (Computer Associates) [File_System | Auto | Running] -- C:\Windows\SysNative\drivers\ino_fltr.sys -- (INO_FLTR)
DRV:64bit: - [2007/08/06 22:06:56 | 000,031,760 | ---- | M] (Computer Associates) [File_System | Boot | Running] -- C:\Windows\SysNative\drivers\ino_flpy.sys -- (INO_FLPY)
DRV - [2009/07/13 21:19:10 | 000,019,008 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\SysWOW64\drivers\wimmount.sys -- (WIMMount)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://intranet.ca.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = https://one.ca.com/
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
========== FireFox ==========
FF:64bit: - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~1\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@nvidia.com/3DVision: C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation)
FF - HKLM\Software\MozillaPlugins\@nvidia.com/3DVisionStreaming: C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Users\buich01\AppData\Local\Google\Update\1.3.21.69\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Users\buich01\AppData\Local\Google\Update\1.3.21.69\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@yahoo.com/BrowserPlus,version=2.9.8: C:\Users\buich01\AppData\Local\Yahoo!\BrowserPlus\2.9.8\Plugins\npybrowserplus_2.9.8.dll (Yahoo! Inc.)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 7.0\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2011/10/05 19:51:30 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 7.0\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins
[2011/06/11 12:04:47 | 000,000,000 | ---D | M] (No name found) -- C:\Users\buich01\AppData\Roaming\mozilla\Extensions
[2011/06/08 13:45:18 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\Mozilla Firefox\extensions
[2011/10/05 19:51:30 | 000,134,104 | ---- | M] (Mozilla Foundation) -- C:\Program Files (x86)\mozilla firefox\components\browsercomps.dll
[2011/09/11 13:18:33 | 000,002,252 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\bing.xml
========== Chrome ==========
CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{google:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}sourceid=chrome&ie={inputEncoding}&q={searchTerms}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}client=chrome&hl={language}&q={searchTerms}
CHR - plugin: Shockwave Flash (Enabled) = C:\Users\buich01\AppData\Local\Google\Chrome\Application\14.0.835.202\gcswf32.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll
CHR - plugin: Java Deployment Toolkit 6.0.220.4 (Enabled) = C:\Program Files (x86)\Java\jre6\bin\new_plugin\npdeployJava1.dll
CHR - plugin: Java Platform SE 6 U22 (Enabled) = C:\Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll
CHR - plugin: Adobe Acrobat (Disabled) = C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Browser\nppdf32.dll
CHR - plugin: Microsoft Office 2010 (Enabled) = C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL
CHR - plugin: Microsoft Office 2010 (Enabled) = C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL
CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Users\buich01\AppData\Local\Google\Chrome\Application\14.0.835.202\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Users\buich01\AppData\Local\Google\Chrome\Application\14.0.835.202\pdf.dll
CHR - plugin: NVIDIA 3D Vision (Enabled) = C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll
CHR - plugin: NVIDIA 3D VISION (Enabled) = C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll
CHR - plugin: Google Update (Enabled) = C:\Users\buich01\AppData\Local\Google\Update\1.3.21.69\npGoogleUpdate3.dll
CHR - plugin: BrowserPlus (from Yahoo!) v2.9.8 (Enabled) = C:\Users\buich01\AppData\Local\Yahoo!\BrowserPlus\2.9.8\Plugins\npybrowserplus_2.9.8.dll
CHR - plugin: Default Plug-in (Enabled) = default_plugin
O1 HOSTS File: ([2011/10/06 13:45:25 | 000,000,098 | ---- | M]) - C:\Windows\SysNative\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O3:64bit: - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O4:64bit: - HKLM..\Run: [Realtime Monitor] C:\Program Files\CA\eTrustITM\realmon.exe (CA)
O4:64bit: - HKLM..\Run: [UPM-Info] C:\Windows\tools\UPM-Info.vbs ()
O4 - HKLM..\Run: [CAF_SystemTray] C:\Program Files (x86)\CA\DSM\bin\cfSysTray.exe (CA International Inc.)
O4 - HKLM..\Run: [Communicator] C:\Program Files (x86)\Microsoft Office Communicator\communicator.exe (Microsoft Corporation)
O4 - HKLM..\Run: [DsmSxplog] C:\Program Files (x86)\CA\DSM\Bin\sxpstub.exe (CA International Inc.)
O4 - HKCU..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun File not found
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\BrowserEmulation present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 255
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Main present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O10:64bit: - Protocol_Catalog9\Catalog_Entries\000000000001 - mmswsock.dll File not found
O10:64bit: - Protocol_Catalog9\Catalog_Entries\000000000002 - mmswsock.dll File not found
O10:64bit: - Protocol_Catalog9\Catalog_Entries\000000000003 - mmswsock.dll File not found
O10:64bit: - Protocol_Catalog9\Catalog_Entries\000000000004 - mmswsock.dll File not found
O10:64bit: - Protocol_Catalog9\Catalog_Entries\000000000005 - mmswsock.dll File not found
O10:64bit: - Protocol_Catalog9\Catalog_Entries\000000000006 - mmswsock.dll File not found
O10:64bit: - Protocol_Catalog9\Catalog_Entries\000000000007 - mmswsock.dll File not found
O10:64bit: - Protocol_Catalog9\Catalog_Entries\000000000008 - mmswsock.dll File not found
O10:64bit: - Protocol_Catalog9\Catalog_Entries\000000000009 - mmswsock.dll File not found
O10:64bit: - Protocol_Catalog9\Catalog_Entries\000000000010 - mmswsock.dll File not found
O10:64bit: - Protocol_Catalog9\Catalog_Entries\000000000011 - mmswsock.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - %SystemRoot%\system32\wshbth.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - %SystemRoot%\system32\wshbth.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - %SystemRoot%\system32\wshbth.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - %SystemRoot%\system32\wshbth.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - %SystemRoot%\system32\wshbth.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000006 - %SystemRoot%\system32\wshbth.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000007 - %SystemRoot%\system32\wshbth.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000008 - %SystemRoot%\system32\wshbth.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000009 - %SystemRoot%\system32\wshbth.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000010 - %SystemRoot%\system32\wshbth.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000011 - %SystemRoot%\system32\wshbth.dll File not found
O1364bit: - gopher Prefix: missing
O13 - gopher Prefix: missing
O15 - HKCU\..Trusted Domains: ca.com ([]* in Local intranet)
O15 - HKCU\..Trusted Domains: ca.com ([accountconnect] https in Trusted sites)
O15 - HKCU\..Trusted Domains: ca.com ([etrustpki] https in Trusted sites)
O15 - HKCU\..Trusted Domains: ca.com ([expenseit] http in Local intranet)
O15 - HKCU\..Trusted Domains: ca.com ([hrreports] http in Trusted sites)
O15 - HKCU\..Trusted Domains: ca.com ([hrreportsft] http in Trusted sites)
O15 - HKCU\..Trusted Domains: ca.com ([insight] http in Trusted sites)
O15 - HKCU\..Trusted Domains: ca.com ([insight] https in Trusted sites)
O15 - HKCU\..Trusted Domains: ca.com ([insightft] http in Trusted sites)
O15 - HKCU\..Trusted Domains: ca.com ([insightft] https in Trusted sites)
O15 - HKCU\..Trusted Domains: ca.com ([mrm] http in Trusted sites)
O15 - HKCU\..Trusted Domains: ca.com ([supportreports] http in Trusted sites)
O15 - HKCU\..Trusted Domains: ca.com ([usilws19] http in Trusted sites)
O15 - HKCU\..Trusted Domains: force.com ([]http in Trusted sites)
O15 - HKCU\..Trusted Domains: force.com ([]https in Trusted sites)
O15 - HKCU\..Trusted Domains: inciteknowledge.com ([]http in Trusted sites)
O15 - HKCU\..Trusted Domains: inciteknowledge.com ([]https in Trusted sites)
O15 - HKCU\..Trusted Domains: inciteknowledge.com ([home] http in Trusted sites)
O15 - HKCU\..Trusted Domains: inciteknowledge.com ([home] https in Trusted sites)
O15 - HKCU\..Trusted Domains: inciteknowledge.com ([www] http in Trusted sites)
O15 - HKCU\..Trusted Domains: inciteknowledge.com ([www] https in Trusted sites)
O15 - HKCU\..Trusted Domains: insight ([]http in Trusted sites)
O15 - HKCU\..Trusted Domains: insight ([]https in Trusted sites)
O15 - HKCU\..Trusted Domains: insightft ([]http in Trusted sites)
O15 - HKCU\..Trusted Domains: kadient.com ([]http in Trusted sites)
O15 - HKCU\..Trusted Domains: kadient.com ([]https in Trusted sites)
O15 - HKCU\..Trusted Domains: kadient.com ([www] http in Trusted sites)
O15 - HKCU\..Trusted Domains: kadient.com ([www] https in Trusted sites)
O15 - HKCU\..Trusted Domains: localhost ([]http in Local intranet)
O15 - HKCU\..Trusted Domains: mrm ([]http in Trusted sites)
O15 - HKCU\..Trusted Domains: mycareallies.com ([ca] http in Trusted sites)
O15 - HKCU\..Trusted Domains: mycareallies.com ([ca] https in Trusted sites)
O15 - HKCU\..Trusted Domains: qvidian.com ([]http in Trusted sites)
O15 - HKCU\..Trusted Domains: qvidian.com ([]https in Trusted sites)
O15 - HKCU\..Trusted Domains: qvidian.com ([www] http in Trusted sites)
O15 - HKCU\..Trusted Domains: qvidian.com ([www] https in Trusted sites)
O15 - HKCU\..Trusted Domains: salesforce.com ([]http in Trusted sites)
O15 - HKCU\..Trusted Domains: salesforce.com ([]https in Trusted sites)
O15 - HKCU\..Trusted Domains: salesforce.com ([na1] http in Trusted sites)
O15 - HKCU\..Trusted Domains: salesforce.com ([na1] https in Trusted sites)
O15 - HKCU\..Trusted Domains: supportreports ([]http in Trusted sites)
O15 - HKCU\..Trusted Domains: usilws19 ([]http in Trusted sites)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_22)
O16 - DPF: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_22)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_22)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_22)
O16 - DPF: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_22)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_22)
O16 - DPF: {F27237D7-93C8-44C2-AC6E-D6057B9A918F} https://caconnect.ca...SetupClient.cab (JuniperSetupClientControl Class)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 141.202.1.108 138.42.248.81
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = ca.com
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{FC18C43A-8E95-46C9-9C55-1B09F543A5DB}: DhcpNameServer = 141.202.1.108 138.42.248.81
O18:64bit: - Protocol\Handler\ms-help - No CLSID value found
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysNative\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20 - HKLM Winlogon: Shell - (explorer.exe) -C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (userinit.exe) -C:\Windows\SysWow64\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *)
O35:64bit: - HKLM\..comfile [open] -- "%1" %*
O35:64bit: - HKLM\..exefile [open] -- "%1" %*
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37:64bit: - HKLM\...com [@ = comfile] -- "%1" %*
O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
========== Files/Folders - Created Within 30 Days ==========
[2011/10/06 14:18:19 | 000,582,656 | ---- | C] (OldTimer Tools) -- C:\Users\buich01\Desktop\OTL.exe
[2011/10/06 14:01:54 | 000,071,398 | ---- | C] (jpshortstuff) -- C:\GooredFix.exe
[2011/10/06 13:58:24 | 000,111,408 | ---- | C] (Kaspersky Lab, GERT) -- C:\Windows\SysNative\drivers\69490877.sys
[2011/10/06 13:45:24 | 000,000,000 | ---D | C] -- C:\_OTM
[2011/10/06 13:32:17 | 000,000,000 | ---D | C] -- C:\erunt
[2011/10/02 16:13:11 | 000,000,000 | ---D | C] -- C:\Windows\system64
[2011/09/15 14:36:08 | 000,000,000 | ---D | C] -- C:\Users\buich01\Documents\Job Stuff
[2011/09/13 09:41:48 | 000,000,000 | ---D | C] -- C:\Users\buich01\Documents\Spectrum
========== Files - Modified Within 30 Days ==========
[2011/10/06 14:17:57 | 000,582,656 | ---- | M] (OldTimer Tools) -- C:\Users\buich01\Desktop\OTL.exe
[2011/10/06 14:11:03 | 000,000,008 | ---- | M] () -- C:\Windows\Proc.GIS
[2011/10/06 14:05:24 | 000,000,003 | ---- | M] () -- C:\Windows\MacNote.gis
[2011/10/06 14:03:20 | 000,005,102 | RHS- | M] () -- C:\Users\buich01\ntuser.pol
[2011/10/06 14:01:29 | 000,002,064 | -H-- | M] () -- C:\Users\buich01\Documents\Default.rdp
[2011/10/06 13:58:24 | 000,111,408 | ---- | M] (Kaspersky Lab, GERT) -- C:\Windows\SysNative\drivers\69490877.sys
[2011/10/06 13:56:43 | 000,012,288 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2011/10/06 13:56:43 | 000,012,288 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2011/10/06 13:53:43 | 002,987,174 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI
[2011/10/06 13:53:43 | 000,696,410 | ---- | M] () -- C:\Windows\SysNative\perfh00C.dat
[2011/10/06 13:53:43 | 000,618,646 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat
[2011/10/06 13:53:43 | 000,406,434 | ---- | M] () -- C:\Windows\SysNative\perfh012.dat
[2011/10/06 13:53:43 | 000,395,002 | ---- | M] () -- C:\Windows\SysNative\perfh011.dat
[2011/10/06 13:53:43 | 000,366,784 | ---- | M] () -- C:\Windows\SysNative\prfh0804.dat
[2011/10/06 13:53:43 | 000,128,462 | ---- | M] () -- C:\Windows\SysNative\perfc00C.dat
[2011/10/06 13:53:43 | 000,104,960 | ---- | M] () -- C:\Windows\SysNative\perfc011.dat
[2011/10/06 13:53:43 | 000,104,960 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat
[2011/10/06 13:53:43 | 000,103,248 | ---- | M] () -- C:\Windows\SysNative\perfc012.dat
[2011/10/06 13:53:43 | 000,102,820 | ---- | M] () -- C:\Windows\SysNative\prfc0804.dat
[2011/10/06 13:49:16 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2011/10/06 13:45:25 | 000,000,098 | ---- | M] () -- C:\Windows\SysNative\drivers\etc\Hosts
[2011/10/06 13:45:01 | 000,000,916 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-2129867641-919698055-327642922-270587UA.job
[2011/10/06 13:45:01 | 000,000,864 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-2129867641-919698055-327642922-270587Core.job
[2011/10/06 13:38:07 | 000,071,398 | ---- | M] (jpshortstuff) -- C:\GooredFix.exe
[2011/10/06 13:31:20 | 000,513,320 | ---- | M] () -- C:\erunt.zip
[2011/10/05 00:45:56 | 000,002,373 | ---- | M] () -- C:\Users\buich01\Desktop\Google Chrome.lnk
[2011/09/25 00:03:13 | 000,236,156 | ---- | M] () -- C:\Windows\subnets.prn
[2011/09/16 17:03:55 | 000,001,148 | -HS- | M] () -- C:\Users\buich01\AppData\Local\f6h4b4r487v
[2011/09/16 17:03:55 | 000,001,148 | -HS- | M] () -- C:\ProgramData\f6h4b4r487v
[2011/09/16 17:03:55 | 000,000,000 | ---- | M] () -- C:\ProgramData\xhpd.exe
[2011/09/16 17:03:55 | 000,000,000 | ---- | M] () -- C:\Users\buich01\AppData\Local\wpmo.exe
[2011/09/16 17:03:55 | 000,000,000 | ---- | M] () -- C:\Users\buich01\AppData\Local\voqx.exe
[2011/09/16 17:03:55 | 000,000,000 | ---- | M] () -- C:\ProgramData\psqe.exe
[2011/09/16 17:03:55 | 000,000,000 | ---- | M] () -- C:\Users\buich01\AppData\Local\jhrx.exe
[2011/09/16 17:03:55 | 000,000,000 | ---- | M] () -- C:\ProgramData\fwjt.exe
[2011/09/16 17:03:55 | 000,000,000 | ---- | M] () -- C:\ProgramData\fksj.exe
[2011/09/16 17:03:55 | 000,000,000 | ---- | M] () -- C:\Users\buich01\AppData\Local\aind.exe
[2011/09/16 10:41:43 | 000,035,412 | RHS- | M] () -- C:\ProgramData\ntuser.pol
[2011/09/06 16:22:09 | 000,000,000 | -H-- | M] () -- C:\Windows\SysNative\drivers\Msft_User_WpdMtpDr_01_09_00.Wdf
========== Files Created - No Company Name ==========
[2011/10/06 13:31:56 | 000,513,320 | ---- | C] () -- C:\erunt.zip
[2011/09/16 17:03:55 | 000,001,148 | -HS- | C] () -- C:\Users\buich01\AppData\Local\f6h4b4r487v
[2011/09/16 17:03:55 | 000,001,148 | -HS- | C] () -- C:\ProgramData\f6h4b4r487v
[2011/09/16 17:03:55 | 000,000,000 | ---- | C] () -- C:\ProgramData\xhpd.exe
[2011/09/16 17:03:55 | 000,000,000 | ---- | C] () -- C:\Users\buich01\AppData\Local\wpmo.exe
[2011/09/16 17:03:55 | 000,000,000 | ---- | C] () -- C:\Users\buich01\AppData\Local\voqx.exe
[2011/09/16 17:03:55 | 000,000,000 | ---- | C] () -- C:\ProgramData\psqe.exe
[2011/09/16 17:03:55 | 000,000,000 | ---- | C] () -- C:\Users\buich01\AppData\Local\jhrx.exe
[2011/09/16 17:03:55 | 000,000,000 | ---- | C] () -- C:\ProgramData\fwjt.exe
[2011/09/16 17:03:55 | 000,000,000 | ---- | C] () -- C:\ProgramData\fksj.exe
[2011/09/16 17:03:55 | 000,000,000 | ---- | C] () -- C:\Users\buich01\AppData\Local\aind.exe
[2011/09/06 16:22:09 | 000,000,000 | -H-- | C] () -- C:\Windows\SysNative\drivers\Msft_User_WpdMtpDr_01_09_00.Wdf
[2011/07/18 19:13:02 | 000,000,600 | ---- | C] () -- C:\Users\buich01\AppData\Local\PUTTY.RND
[2011/06/11 12:04:41 | 000,000,000 | ---- | C] () -- C:\Windows\nsreg.dat
[2011/06/07 12:27:01 | 000,190,976 | ---- | C] () -- C:\Windows\SysWow64\Tngremov.exe
[2011/06/07 12:19:57 | 003,050,896 | ---- | C] () -- C:\Windows\SysWow64\PerfStringBackup.INI
[2011/06/07 12:19:40 | 000,047,104 | ---- | C] () -- C:\Windows\KX16.DLL
[2011/05/20 22:35:28 | 000,304,744 | ---- | C] () -- C:\Windows\SysWow64\nvStreaming.exe
[2011/05/03 15:45:52 | 000,035,412 | RHS- | C] () -- C:\ProgramData\ntuser.pol
[2011/05/03 15:10:41 | 000,000,783 | ---- | C] () -- C:\Windows\{1B80FEE7-70AB-466B-8124-12570278E98D}_WiseFW.ini
[2011/05/03 14:44:42 | 000,000,051 | ---- | C] () -- C:\Windows\smsts.ini
[2010/06/25 13:03:12 | 000,053,299 | ---- | C] () -- C:\Windows\SysWow64\pthreadVC.dll
[2009/07/14 01:38:36 | 000,067,584 | --S- | C] () -- C:\Windows\bootstat.dat
[2009/07/13 22:35:51 | 000,000,741 | ---- | C] () -- C:\Windows\SysWow64\NOISE.DAT
[2009/07/13 22:34:42 | 000,215,943 | ---- | C] () -- C:\Windows\SysWow64\dssec.dat
[2009/07/13 20:10:29 | 000,043,131 | ---- | C] () -- C:\Windows\mib.bin
[2009/07/13 19:42:10 | 000,064,000 | ---- | C] () -- C:\Windows\SysWow64\BWContextHandler.dll
[2009/07/13 17:59:36 | 000,982,196 | ---- | C] () -- C:\Windows\SysWow64\igkrng500.bin
[2009/07/13 17:59:36 | 000,139,824 | ---- | C] () -- C:\Windows\SysWow64\igfcg500.bin
[2009/07/13 17:59:36 | 000,097,448 | ---- | C] () -- C:\Windows\SysWow64\igfcg500m.bin
[2009/07/13 17:59:35 | 000,417,344 | ---- | C] () -- C:\Windows\SysWow64\igcompkrng500.bin
[2009/07/13 17:03:59 | 000,364,544 | ---- | C] () -- C:\Windows\SysWow64\msjetoledb40.dll
[2009/06/10 17:26:10 | 000,673,088 | ---- | C] () -- C:\Windows\SysWow64\mlang.dat
[2009/01/23 17:36:10 | 000,007,680 | ---- | C] () -- C:\Windows\SysWow64\csamenc.dll
[2000/06/08 13:15:24 | 000,050,176 | ---- | C] () -- C:\Windows\LogWatNT.exe
========== LOP Check ==========
[2011/06/07 12:30:03 | 000,000,000 | ---D | M] -- C:\Users\buich01\AppData\Roaming\CA
[2011/06/07 12:20:28 | 000,000,000 | ---D | M] -- C:\Users\buich01\AppData\Roaming\Citrix
[2011/06/08 11:32:16 | 000,000,000 | ---D | M] -- C:\Users\buich01\AppData\Roaming\Hummingbird
[2011/05/03 15:17:04 | 000,000,000 | ---D | M] -- C:\Users\buich01\AppData\Roaming\Jolly Giant Software
[2011/06/07 14:57:12 | 000,000,000 | ---D | M] -- C:\Users\buich01\AppData\Roaming\Juniper Networks
[2011/07/18 19:26:49 | 000,000,000 | ---D | M] -- C:\Users\buich01\AppData\Roaming\Wireshark
[2009/07/14 01:08:49 | 000,010,330 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT
========== Purity Check ==========
========== Alternate Data Streams ==========
@Alternate Data Stream - 512 bytes -> C:\Windows\SysWow64\Tngremov.exe:CA_INOCULATEIT
@Alternate Data Stream - 512 bytes -> C:\Windows\SysWow64\Tngremo_.exe:CA_INOCULATEIT
@Alternate Data Stream - 512 bytes -> C:\Windows\KX95.DLL:CA_INOCULATEIT
@Alternate Data Stream - 512 bytes -> C:\Windows\KX32.DLL:CA_INOCULATEIT
@Alternate Data Stream - 512 bytes -> C:\Windows\KX16.DLL:CA_INOCULATEIT
@Alternate Data Stream - 512 bytes -> C:\Windows\KixFlag.gis:CA_INOCULATEIT
@Alternate Data Stream - 512 bytes -> C:\Windows\KIX32.EXE:CA_INOCULATEIT
< End of report >
Edited by ChrisInYork, 06 October 2011 - 12:25 PM.