Jump to content

Welcome to Geeks to Go - Register now for FREE

Need help with your computer or device? Want to learn new tech skills? You're in the right place!
Geeks to Go is a friendly community of tech experts who can solve any problem you have. Just create a free account and post your question. Our volunteers will reply quickly and guide you through the steps. Don't let tech troubles stop you. Join Geeks to Go now and get the support you need!

How it Works Create Account
Photo

Windows XP Recovery & PHYSICALDRIVE woes [Closed] [Solved] [Closed


  • This topic is locked This topic is locked

#1
Boomrad

Boomrad

    Member

  • Member
  • PipPip
  • 17 posts
First off, thank you!
Some nasty little thing(s) causing windows to freak out on start-up, hide most files and programs, disable update-ability on Avast! and Malwarebytes', restrict capacity to download new files, and generally run amok through my system tearing everything apart. Trying to deal with this for some time now.
An Avast! security recommendation pops up immediately after logging into Windows, upon taking action 'Windows XP Recovery' begins an automatic system scan along with a flurry of error messages suggesting a system reboot, ultimately causing my Dellosaurus to overheat and crash... :/ Help please? I appreciate it!

OTL logfile created on: 10/31/2011 5:16:20 PM - Run 2
OTL by OldTimer - Version 3.2.31.0 Folder = C:\Documents and Settings\Matthew\My Documents\Downloads
Windows XP Home Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 6.0.2900.2180)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

894.02 Mb Total Physical Memory | 495.64 Mb Available Physical Memory | 55.44% Memory free
2.12 Gb Paging File | 1.78 Gb Available in Paging File | 84.32% Paging File free
Paging file location(s): C:\pagefile.sys 1344 2688 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 52.21 Gb Total Space | 0.06 Gb Free Space | 0.12% Space Free | Partition Type: NTFS

Computer Name: DH9QL3C1 | User Name: Matthew | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - [2011/10/31 17:16:08 | 000,584,192 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Matthew\My Documents\Downloads\OTL(2).scr
PRC - [2011/09/27 23:56:56 | 000,912,344 | -H-- | M] (Mozilla Corporation) -- C:\Program Files\Mozilla Firefox\firefox.exe
PRC - [2011/07/12 15:18:35 | 000,046,208 | -H-- | M] (CenturyLink Inc) -- C:\Program Files\CenturyLink\Desktop\CenturyLinkTouchPointAgent.exe
PRC - [2011/02/23 08:04:20 | 003,451,496 | ---- | M] (AVAST Software) -- C:\Program Files\AVAST Software\Avast\AvastUI.exe
PRC - [2011/02/23 08:04:19 | 000,042,184 | ---- | M] (AVAST Software) -- C:\Program Files\AVAST Software\Avast\AvastSvc.exe
PRC - [2008/01/08 12:02:16 | 001,213,728 | -H-- | M] (SupportSoft, Inc.) -- C:\Program Files\Common Files\supportsoft\bin\sprtlisten.exe
PRC - [2007/07/24 13:17:31 | 001,174,152 | -H-- | M] (Symantec Corporation) -- C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
PRC - [2007/06/13 03:23:07 | 001,033,216 | -H-- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe
PRC - [2006/08/23 15:13:28 | 000,380,928 | -H-- | M] (Dell Inc.) -- C:\Program Files\Dell\QuickSet\NicConfigSvc.exe


========== Modules (No Company Name) ==========

MOD - [2011/09/27 23:56:56 | 001,015,256 | -H-- | M] () -- C:\Program Files\Mozilla Firefox\js3250.dll
MOD - [2011/06/14 15:20:37 | 000,064,512 | -H-- | M] () -- C:\WINDOWS\eventvdm.dll
MOD - [2011/02/24 02:55:49 | 000,844,288 | ---- | M] () -- C:\Program Files\AVAST Software\Avast\defs\11022400\algo.dll
MOD - [2011/02/23 08:04:14 | 000,144,672 | ---- | M] () -- C:\Program Files\AVAST Software\Avast\aswDld.dll
MOD - [2010/11/11 19:51:23 | 005,971,408 | -H-- | M] () -- C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll
MOD - [2010/06/11 18:48:36 | 000,971,264 | -H-- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Configuration\631b3eba1ba5bd3c3f027f34011cadeb\System.Configuration.ni.dll
MOD - [2010/06/11 18:15:22 | 012,430,848 | -H-- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\2dfe045e4b1577fdea9a2f456db0afc2\System.Windows.Forms.ni.dll
MOD - [2010/06/08 20:37:37 | 001,840,640 | -H-- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Web.Services\8ef8d556899a4a10b7f288a80925489f\System.Web.Services.ni.dll
MOD - [2010/06/08 20:34:45 | 000,998,400 | -H-- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Management\16670b6870746e5a8dc4a73a76a90bed\System.Management.ni.dll
MOD - [2010/06/08 20:21:53 | 005,450,752 | -H-- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Xml\563a54b98adb70fae862974042298348\System.Xml.ni.dll
MOD - [2010/06/08 20:20:55 | 001,587,200 | -H-- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Drawing\f3440ea00eb3c40dc073b2fe03843638\System.Drawing.ni.dll
MOD - [2010/06/08 20:15:25 | 007,949,824 | -H-- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System\37217abe2c5164e59aba251860f4c79e\System.ni.dll
MOD - [2009/10/15 02:21:38 | 011,486,720 | -H-- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\mscorlib\7124a40b9998f7b63c86bd1a2125ce26\mscorlib.ni.dll
MOD - [2005/12/19 14:08:30 | 000,757,760 | -H-- | M] () -- C:\WINDOWS\system32\bcm1xsup.dll


========== Win32 Services (SafeList) ==========

SRV - File not found [On_Demand | Stopped] -- -- (SupportSoft RemoteAssist)
SRV - File not found [Disabled | Stopped] -- -- (HidServ)
SRV - File not found [Auto | Stopped] -- -- (Automatic LiveUpdate Scheduler)
SRV - File not found [On_Demand | Stopped] -- -- (AppMgmt)
SRV - [2011/02/23 08:04:19 | 000,042,184 | ---- | M] (AVAST Software) [Auto | Running] -- C:\Program Files\AVAST Software\Avast\AvastSvc.exe -- (avast! Antivirus)
SRV - [2008/01/08 12:02:16 | 001,213,728 | -H-- | M] (SupportSoft, Inc.) [Auto | Running] -- C:\Program Files\Common Files\supportsoft\bin\sprtlisten.exe -- (sprtlisten)
SRV - [2007/07/24 13:17:31 | 001,174,152 | -H-- | M] (Symantec Corporation) [Auto | Running] -- C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe -- (Symantec Core LC)
SRV - [2006/08/23 15:13:28 | 000,380,928 | -H-- | M] (Dell Inc.) [Auto | Running] -- C:\Program Files\Dell\QuickSet\NicConfigSvc.exe -- (NICCONFIGSVC)


========== Driver Services (SafeList) ==========

DRV - [2011/02/23 07:56:55 | 000,371,544 | ---- | M] (AVAST Software) [File_System | System | Running] -- C:\WINDOWS\System32\drivers\aswSnx.sys -- (aswSnx)
DRV - [2011/02/23 07:56:45 | 000,301,528 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\aswSP.sys -- (aswSP)
DRV - [2011/02/23 07:55:49 | 000,049,240 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\aswTdi.sys -- (aswTdi)
DRV - [2011/02/23 07:55:47 | 000,102,232 | ---- | M] (AVAST Software) [File_System | Auto | Running] -- C:\WINDOWS\System32\drivers\aswmon2.sys -- (aswMon2)
DRV - [2011/02/23 07:55:10 | 000,025,432 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\aswRdr.sys -- (aswRdr)
DRV - [2011/02/23 07:54:57 | 000,030,680 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\aavmker4.sys -- (Aavmker4)
DRV - [2011/02/23 07:54:55 | 000,019,544 | ---- | M] (AVAST Software) [File_System | Auto | Running] -- C:\WINDOWS\System32\drivers\aswFsBlk.sys -- (aswFsBlk)
DRV - [2006/11/14 14:41:34 | 000,010,344 | -H-- | M] (Symantec Corporation) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\symlcbrd.sys -- (symlcbrd)
DRV - [2006/09/23 01:56:40 | 001,681,920 | -H-- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\ati2mtag.sys -- (ati2mtag)
DRV - [2006/09/22 10:06:26 | 001,171,464 | -H-- | M] (SigmaTel, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\sthda.sys -- (STHDA)
DRV - [2006/08/17 12:55:16 | 000,044,544 | -H-- | M] (Broadcom Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\bcm4sbxp.sys -- (bcm4sbxp)
DRV - [2006/07/01 21:39:40 | 000,036,864 | -H-- | M] (Advanced Micro Devices) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\AmdK8.sys -- (AmdK8)
DRV - [2006/01/10 11:07:58 | 000,004,864 | -H-- | M] (GTek Technologies Ltd.) [Kernel | On_Demand | Stopped] -- C:\Program Files\Dell Support\GTAction\triggers\DSproct.sys -- (DSproct)
DRV - [2005/11/02 18:24:34 | 000,424,320 | -H-- | M] (Broadcom Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\BCMWL5.SYS -- (BCM43XX)
DRV - [2005/08/12 16:50:46 | 000,016,128 | -H-- | M] (Dell Inc) [Kernel | System | Running] -- C:\WINDOWS\SYSTEM32\DRIVERS\APPDRV.SYS -- (APPDRV)
DRV - [2005/07/14 22:58:14 | 000,028,544 | -H-- | M] (REDC) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\rimmptsk.sys -- (rimmptsk)
DRV - [2004/06/09 08:29:56 | 000,006,977 | -H-- | M] (Gteko Ltd.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\DDMI2.sys -- (SDDMI2)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell.com
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.google.com/ie
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.dell.com
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Page_URL = www.google.com/ig/dell?hl=en&client=dell-usuk&channel=us&ibd=4061114
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Start Page = www.google.com/ig/dell?hl=en&client=dell-usuk&channel=us&ibd=4061114

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://qwest.live.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultName = Google
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultURL = http://www.google.co...ie=utf8&oe=utf8
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = qwest.live.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 1
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = <local>
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = http=127.0.0.1:56808

========== FireFox ==========

FF - prefs.js..browser.startup.homepage: "http://marriedtothesea.com/"
FF - prefs.js..extensions.enabledItems: {0538E3E3-7E9B-4d49-8831-A227C80A7AD3}:2.0.2
FF - prefs.js..extensions.enabledItems: [email protected]:1.0
FF - prefs.js..extensions.enabledItems: {7EC8EF17-B3B5-4943-8AF5-B91B0863BB75}:1.0
FF - prefs.js..extensions.enabledItems: {AC2F4FDB-87C1-48E6-8868-C375623AF577}:1.9.1
FF - prefs.js..extensions.enabledItems: {AB2CE124-6272-4b12-94A9-7303C7397BD1}:5.0.0.6778
FF - prefs.js..extensions.enabledItems: [email protected]:20110101
FF - prefs.js..network.proxy.http: "127.0.0.1"
FF - prefs.js..network.proxy.http_port: 56808
FF - prefs.js..network.proxy.type: 4


FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Browser Plugin,version=1.0.0: C:\Program Files\DivX\DivX Web Player\npdivx32.dll (DivX,Inc.)
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Content Upload Plugin,version=1.0.0: C:\Program Files\DivX\DivX Content Uploader\npUpload.dll (DivX,Inc.)
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Player Plugin,version=1.0.0: C:\Program Files\DivX\DivX Player\npDivxPlayerPlugin.dll (DivX, Inc)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\4.0.60129.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@movenetworks.com/Quantum Media Player: C:\Documents and Settings\Josh\Application Data\Move Networks\plugins\npqmp071503000010.dll (Move Networks)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\extensions\\{7EC8EF17-B3B5-4943-8AF5-B91B0863BB75}: C:\Documents and Settings\Matthew\Local Settings\Application Data\{7EC8EF17-B3B5-4943-8AF5-B91B0863BB75} [2009/04/22 17:01:43 | 000,000,000 | -H-D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\extensions\\{AC2F4FDB-87C1-48E6-8868-C375623AF577}: C:\Documents and Settings\Josh\Local Settings\Application Data\{AC2F4FDB-87C1-48E6-8868-C375623AF577} [2009/09/23 22:35:57 | 000,000,000 | -H-D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\extensions\\[email protected]: C:\Program Files\AVAST Software\Avast\WebRep\FF [2011/04/17 18:45:00 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 3.6.23\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011/10/06 22:25:52 | 000,000,000 | -H-D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 3.6.23\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011/09/27 23:57:08 | 000,000,000 | -H-D | M]

[2009/03/11 16:37:31 | 000,000,000 | -H-D | M] (No name found) -- C:\Documents and Settings\Matthew\Application Data\Mozilla\Extensions
[2009/03/11 16:37:31 | 000,000,000 | -H-D | M] (No name found) -- C:\Documents and Settings\Matthew\Application Data\Mozilla\Extensions\[email protected]
[2011/10/30 03:37:05 | 000,000,000 | -H-D | M] (No name found) -- C:\Documents and Settings\Matthew\Application Data\Mozilla\Firefox\Profiles\xn4cc6wh.default\extensions
[2010/09/23 23:26:42 | 000,000,000 | -H-D | M] (Forecastfox Weather) -- C:\Documents and Settings\Matthew\Application Data\Mozilla\Firefox\Profiles\xn4cc6wh.default\extensions\{0538E3E3-7E9B-4d49-8831-A227C80A7AD3}
[2009/09/04 01:19:35 | 000,000,000 | -H-D | M] (Microsoft .NET Framework Assistant) -- C:\Documents and Settings\Matthew\Application Data\Mozilla\Firefox\Profiles\xn4cc6wh.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2009/07/24 03:29:49 | 000,000,000 | -H-D | M] (MidnightFox) -- C:\Documents and Settings\Matthew\Application Data\Mozilla\Firefox\Profiles\xn4cc6wh.default\extensions\{66871bd1-5ba2-4739-b485-2a15f5969bd8}
[2007/05/03 01:01:30 | 000,007,431 | -H-- | M] () -- C:\Documents and Settings\Matthew\Application Data\Mozilla\Firefox\Profiles\xn4cc6wh.default\searchplugins\dictionarycom.xml
[2008/06/24 01:02:01 | 000,000,908 | -H-- | M] () -- C:\Documents and Settings\Matthew\Application Data\Mozilla\Firefox\Profiles\xn4cc6wh.default\searchplugins\imdb.xml
[2008/06/24 01:02:01 | 000,001,108 | -H-- | M] () -- C:\Documents and Settings\Matthew\Application Data\Mozilla\Firefox\Profiles\xn4cc6wh.default\searchplugins\wikipedia-en.xml
[2008/06/02 12:57:27 | 000,001,628 | -H-- | M] () -- C:\Documents and Settings\Matthew\Application Data\Mozilla\Firefox\Profiles\xn4cc6wh.default\searchplugins\youtube.xml
[2011/10/30 03:37:05 | 000,000,000 | -H-D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions
[2010/11/26 19:30:41 | 000,000,000 | -H-D | M] (Skype extension) -- C:\Program Files\Mozilla Firefox\extensions\{AB2CE124-6272-4b12-94A9-7303C7397BD1}
[2009/09/23 22:35:57 | 000,000,000 | -H-D | M] (XULRunner) -- C:\DOCUMENTS AND SETTINGS\JOSH\LOCAL SETTINGS\APPLICATION DATA\{AC2F4FDB-87C1-48E6-8868-C375623AF577}
[2009/04/22 17:01:43 | 000,000,000 | -H-D | M] (XUL Cache) -- C:\DOCUMENTS AND SETTINGS\MATTHEW\LOCAL SETTINGS\APPLICATION DATA\{7EC8EF17-B3B5-4943-8AF5-B91B0863BB75}
[2011/04/17 18:45:00 | 000,000,000 | ---D | M] (avast! WebRep) -- C:\PROGRAM FILES\AVAST SOFTWARE\AVAST\WEBREP\FF
[2009/03/11 16:31:48 | 000,000,000 | -H-D | M] (Java Quick Starter) -- C:\PROGRAM FILES\JAVA\JRE6\LIB\DEPLOY\JQS\FF
[2006/01/18 12:50:00 | 000,319,488 | -H-- | M] ( ) -- C:\Program Files\mozilla firefox\plugins\npsnapfish.dll

========== Chrome ==========

CHR - default_search_provider: Google ()
CHR - default_search_provider: search_url = {google:baseURL}search?{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}sourceid=chrome&ie={inputEncoding}&q={searchTerms}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?client=chrome&hl={language}&q={searchTerms}

Hosts file not found
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (avast! WebRep) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll ()
O2 - BHO: (Skype Plug-In) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O2 - BHO: (Windows Live Toolbar Helper) - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll (Microsoft Corporation)
O3 - HKLM\..\Toolbar: (avast! WebRep) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll ()
O3 - HKLM\..\Toolbar: (Windows Live Toolbar) - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll (Microsoft Corporation)
O3 - HKCU\..\Toolbar\ShellBrowser: (Windows Live Toolbar) - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll (Microsoft Corporation)
O3 - HKCU\..\Toolbar\WebBrowser: (Windows Live Toolbar) - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll (Microsoft Corporation)
O4 - HKLM..\Run: [avast] C:\Program Files\AVAST Software\Avast\avastUI.exe (AVAST Software)
O4 - HKLM..\Run: [CenturyLinkTouchPointAgent] C:\Program Files\CenturyLink\Desktop\CenturyLinkTouchPointAgent.exe (CenturyLink Inc)
O4 - HKLM..\Run: [conhost] C:\Documents and Settings\Matthew\Application Data\Microsoft\conhost.exe ()
O4 - HKCU..\Run: [DellSupport] C:\Program Files\Dell Support\DSAgnt.exe (Gteko Ltd.)
O4 - HKCU..\Run: [KcGKxXpEJYTtjJY] C:\Documents and Settings\All Users\Application Data\KcGKxXpEJYTtjJY.exe (Microsoft Corporation)
O4 - HKCU..\Run: [ModemOnHold] C:\Program Files\NetWaiting\netwaiting.exe ()
O4 - HKCU..\Run: [Rbexeju] rundll32.exe "C:\WINDOWS\wsecuil.dll",Startup File not found
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Main present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\PhishingFilter present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoControlPanel = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoControlPanel = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoWindowsUpdate = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDesktop = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableTaskMgr = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableProfileQuota = 1
O8 - Extra context menu item: &Windows Live Search - C:\Program Files\Windows Live Toolbar\msntb.dll (Microsoft Corporation)
O8 - Extra context menu item: Add to Windows &Live Favorites - http://favorites.liv...m/quickadd.aspx File not found
O9 - Extra Button: Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O16 - DPF: {00000161-0000-0010-8000-00AA00389B71} http://codecs.micros...386/msaudio.cab (Reg Error: Key error.)
O16 - DPF: {31435657-9980-0010-8000-00AA00389B71} http://download.micr...78f/wvc1dmo.cab (Reg Error: Key error.)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_15)
O16 - DPF: {95D88B35-A521-472B-A182-BB1A98356421} http://asp.mathxl.co...nstallAsst2.cab (Pearson Installation Assistant 2)
O16 - DPF: {CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_15)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_15)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.m...ash/swflash.cab (Shockwave Flash Object)
O16 - DPF: {E6D23284-0E9B-417D-A782-03E4487FC947} http://asp.mathxl.co.../MathPlayer.cab (Pearson MathXL Player)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.0.1 205.171.3.25
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{07A7D238-0106-4F39-A5C7-4BE4E4E64956}: DhcpNameServer = 192.168.0.1 205.171.3.25
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O20 - HKLM Winlogon: Shell - (Explorer.exe) -C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) -C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O20 - Winlogon\Notify\AtiExtEvent: DllName - (Ati2evxx.dll) - C:\WINDOWS\System32\ati2evxx.dll (ATI Technologies Inc.)
O24 - Desktop WallPaper: C:\Documents and Settings\Matthew\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Matthew\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O28 - HKLM ShellExecuteHooks: {091EB208-39DD-417D-A5DD-7E2C2D8FB9CB} - C:\Program Files\Windows Defender\MpShHook.dll (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2004/08/10 12:04:08 | 000,000,000 | -H-- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O35 - HKCU\..exefile [open] -- "%1" %*
O36 - AppCertDlls: bcmwnet - (C:\WINDOWS\system32\evenntsd.dll) - File not found
O36 - AppCertDlls: bcmwnet1 - (C:\WINDOWS\eventvdm.dll) -C:\WINDOWS\eventvdm.dll ()
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKCU\...exe [@ = exefile] -- "%1" %*

========== Files/Folders - Created Within 30 Days ==========

[2011/10/31 00:14:16 | 000,000,000 | RH-D | C] -- C:\Documents and Settings\Matthew\Recent
[2011/10/13 23:01:53 | 000,000,000 | -H-D | C] -- C:\Documents and Settings\Matthew\My Documents\cornish - matt aguayo
[2011/08/28 01:55:17 | 000,816,128 | -H-- | C] (Heaventools Software) -- C:\Documents and Settings\All Users\Application Data\defender.exe
[2011/06/03 14:23:47 | 000,333,824 | -H-- | C] (Microsoft Corporation) -- C:\Documents and Settings\All Users\Application Data\16244516.exe
[2011/06/03 14:14:35 | 000,419,328 | -H-- | C] (Microsoft Corporation) -- C:\Documents and Settings\All Users\Application Data\KcGKxXpEJYTtjJY.exe
[2 C:\Documents and Settings\Matthew\My Documents\*.tmp files -> C:\Documents and Settings\Matthew\My Documents\*.tmp -> ]
[1 C:\Documents and Settings\All Users\Application Data\*.tmp files -> C:\Documents and Settings\All Users\Application Data\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2011/10/31 17:13:22 | 000,002,206 | -H-- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2011/10/31 17:12:02 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2011/10/31 17:11:57 | 937,521,152 | -HS- | M] () -- C:\hiberfil.sys
[2011/10/15 15:26:27 | 000,000,099 | -H-- | M] () -- C:\Documents and Settings\Matthew\Desktop\fix.reg
[2 C:\Documents and Settings\Matthew\My Documents\*.tmp files -> C:\Documents and Settings\Matthew\My Documents\*.tmp -> ]
[1 C:\Documents and Settings\All Users\Application Data\*.tmp files -> C:\Documents and Settings\All Users\Application Data\*.tmp -> ]

========== Files Created - No Company Name ==========

[2011/10/15 15:26:27 | 000,000,099 | -H-- | C] () -- C:\Documents and Settings\Matthew\Desktop\fix.reg
[2011/10/10 01:27:02 | 937,521,152 | -HS- | C] () -- C:\hiberfil.sys
[2011/09/13 23:28:38 | 000,185,856 | -H-- | C] () -- C:\Documents and Settings\Matthew\Application Data\dwm.exe
[2011/09/11 13:51:46 | 000,186,368 | -H-- | C] () -- C:\Documents and Settings\Matthew\Application Data\dwmu.exe
[2011/06/16 03:33:44 | 000,050,984 | -H-- | C] () -- C:\Documents and Settings\Matthew\Application Data\2752.1AC
[2011/06/14 15:20:37 | 000,064,512 | -H-- | C] () -- C:\WINDOWS\eventvdm.dll
[2011/06/14 15:20:02 | 000,064,512 | -H-- | C] () -- C:\WINDOWS\System32\eventvdm.dll
[2011/06/03 14:25:02 | 000,000,152 | -H-- | C] () -- C:\Documents and Settings\All Users\Application Data\~16244516r
[2011/06/03 14:25:02 | 000,000,136 | -H-- | C] () -- C:\Documents and Settings\All Users\Application Data\~16244516
[2011/06/03 14:24:07 | 000,000,336 | -H-- | C] () -- C:\Documents and Settings\All Users\Application Data\16244516
[2011/04/17 17:53:52 | 000,015,962 | -HS- | C] () -- C:\Documents and Settings\Matthew\Local Settings\Application Data\1ro18l3y70b46o6kj0v70
[2011/04/17 17:53:52 | 000,015,962 | -HS- | C] () -- C:\Documents and Settings\All Users\Application Data\1ro18l3y70b46o6kj0v70
[2011/03/06 21:20:48 | 000,015,870 | -HS- | C] () -- C:\Documents and Settings\Matthew\Local Settings\Application Data\.))S](VL)0[(+
[2011/03/06 21:20:48 | 000,015,870 | -HS- | C] () -- C:\Documents and Settings\All Users\Application Data\.))S](VL)0[(+
[2011/02/06 17:26:21 | 000,000,012 | -H-- | C] () -- C:\Documents and Settings\Matthew\Application Data\kuhzmn.dat
[2010/11/26 19:31:48 | 000,000,056 | -H-- | C] () -- C:\WINDOWS\System32\ezsidmv.dat
[2010/01/12 14:48:28 | 000,042,824 | -H-- | C] () -- C:\WINDOWS\System32\mlfcache.dat
[2009/06/30 00:20:16 | 000,002,713 | -HS- | C] () -- C:\WINDOWS\System32\tuzatazo.exe
[2009/06/26 12:36:48 | 000,002,713 | -HS- | C] () -- C:\WINDOWS\System32\telemize.exe
[2009/06/24 21:34:35 | 000,002,713 | -HS- | C] () -- C:\WINDOWS\System32\dapotado.exe
[2009/06/09 22:54:22 | 000,002,713 | -HS- | C] () -- C:\WINDOWS\System32\gufipato.exe
[2009/06/08 13:31:37 | 000,000,000 | -H-- | C] () -- C:\Documents and Settings\All Users\Application Data\91142176.ini
[2009/06/04 23:33:33 | 000,001,324 | -H-- | C] () -- C:\WINDOWS\System32\d3d9caps.dat
[2009/04/22 17:01:44 | 000,000,000 | -H-- | C] () -- C:\WINDOWS\Thubexi.bin
[2009/04/22 17:01:40 | 000,000,120 | -H-- | C] () -- C:\WINDOWS\Byazigere.dat
[2007/04/22 17:15:29 | 003,596,288 | -H-- | C] () -- C:\WINDOWS\System32\qt-dx331.dll
[2007/04/22 17:01:47 | 000,012,288 | -H-- | C] () -- C:\WINDOWS\System32\DivXWMPExtType.dll
[2007/02/02 13:59:03 | 000,018,494 | -H-- | C] () -- C:\Documents and Settings\Matthew\Application Data\wklnhst.dat
[2007/01/24 19:28:48 | 000,071,680 | -H-- | C] () -- C:\Documents and Settings\Matthew\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2007/01/15 21:04:35 | 000,002,828 | -HS- | C] () -- C:\WINDOWS\System32\KGyGaAvL.sys
[2007/01/15 21:04:35 | 000,000,088 | RHS- | C] () -- C:\WINDOWS\System32\7FD562AE33.sys
[2007/01/05 11:28:28 | 000,001,938 | -H-- | C] () -- C:\WINDOWS\mozver.dat
[2006/11/27 23:41:19 | 000,001,359 | -H-- | C] () -- C:\Documents and Settings\All Users\Application Data\QTSBandwidthCache
[2006/11/27 15:12:02 | 000,000,000 | -H-- | C] () -- C:\WINDOWS\nsreg.dat
[2006/11/23 14:58:33 | 000,000,130 | -H-- | C] () -- C:\Documents and Settings\Matthew\Local Settings\Application Data\fusioncache.dat
[2006/11/14 14:55:00 | 000,000,061 | -H-- | C] () -- C:\WINDOWS\smscfg.ini
[2006/11/14 14:38:20 | 000,000,376 | -H-- | C] () -- C:\WINDOWS\ODBC.INI
[2006/11/14 14:27:50 | 000,000,004 | -H-- | C] () -- C:\Documents and Settings\All Users\Application Data\QSLLPSVCShare
[2006/11/14 14:02:18 | 000,086,016 | -H-- | C] () -- C:\WINDOWS\System32\preflib.dll
[2006/11/14 14:02:18 | 000,018,944 | -H-- | C] () -- C:\WINDOWS\System32\WLTRYSVC.EXE
[2006/11/14 14:02:12 | 000,757,760 | -H-- | C] () -- C:\WINDOWS\System32\bcm1xsup.dll
[2006/11/14 14:01:54 | 000,133,246 | -H-- | C] () -- C:\WINDOWS\System32\atiicdxx.dat
[2006/11/14 14:01:52 | 000,049,152 | -H-- | C] () -- C:\WINDOWS\setpwrcg.exe
[2006/11/14 14:01:50 | 000,000,390 | -H-- | C] () -- C:\WINDOWS\System32\OEMINFO.INI
[2004/08/10 12:12:05 | 000,000,780 | -H-- | C] () -- C:\WINDOWS\orun32.ini
[2004/08/10 12:07:31 | 000,002,048 | --S- | C] () -- C:\WINDOWS\bootstat.dat
[2004/08/10 12:02:15 | 000,021,640 | -H-- | C] () -- C:\WINDOWS\System32\emptyregdb.dat
[2004/08/10 11:57:52 | 000,004,161 | -H-- | C] () -- C:\WINDOWS\ODBCINST.INI
[2004/08/10 11:57:15 | 000,219,248 | -H-- | C] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2004/08/10 11:51:21 | 000,004,569 | -H-- | C] () -- C:\WINDOWS\System32\secupd.dat
[2004/08/10 11:51:20 | 000,443,034 | -H-- | C] () -- C:\WINDOWS\System32\perfh009.dat
[2004/08/10 11:51:20 | 000,272,128 | -H-- | C] () -- C:\WINDOWS\System32\perfi009.dat
[2004/08/10 11:51:20 | 000,072,134 | -H-- | C] () -- C:\WINDOWS\System32\perfc009.dat
[2004/08/10 11:51:20 | 000,028,626 | -H-- | C] () -- C:\WINDOWS\System32\perfd009.dat
[2004/08/10 11:51:18 | 000,004,627 | -H-- | C] () -- C:\WINDOWS\System32\oembios.dat
[2004/08/10 11:51:17 | 013,107,200 | -H-- | C] () -- C:\WINDOWS\System32\oembios.bin
[2004/08/10 11:51:16 | 000,000,741 | -H-- | C] () -- C:\WINDOWS\System32\noise.dat
[2004/08/10 11:51:12 | 000,673,088 | -H-- | C] () -- C:\WINDOWS\System32\mlang.dat
[2004/08/10 11:51:11 | 000,046,258 | -H-- | C] () -- C:\WINDOWS\System32\mib.bin
[2004/08/10 11:51:05 | 000,218,003 | -H-- | C] () -- C:\WINDOWS\System32\dssec.dat
[2004/08/10 11:50:56 | 000,001,788 | -H-- | C] () -- C:\WINDOWS\System32\Dcache.bin

========== LOP Check ==========

[2010/11/12 17:02:32 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Application Data\Alwil Software
[2011/04/17 18:44:48 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Application Data\AVAST Software
[2011/02/24 18:37:51 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Application Data\bKnPeJc06511
[2009/07/13 12:32:55 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Application Data\butazaji
[2008/01/27 15:25:33 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Application Data\CanonBJ
[2011/10/31 02:24:14 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Application Data\CenturyLink
[2009/07/13 12:33:07 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Application Data\kapidapu
[2009/07/13 12:33:07 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Application Data\lejiwafe
[2009/07/13 12:33:18 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Application Data\narudoku
[2009/07/13 12:33:18 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Application Data\pejonavi
[2009/07/13 12:33:18 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Application Data\redivegi
[2009/07/13 12:33:18 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Application Data\rurileka
[2009/07/13 12:33:24 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Application Data\tokurepa
[2009/07/13 12:33:24 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Application Data\tomatofi
[2009/07/13 12:33:24 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Application Data\vozizowu
[2009/07/13 12:33:24 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Application Data\wepozara
[2009/07/13 12:33:24 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Application Data\woyevepa
[2007/04/16 10:19:25 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Application Data\YAHOO
[2009/12/09 00:03:50 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Application Data\{755AC846-7372-4AC8-8550-C52491DAA8BD}
[2009/07/03 14:09:58 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Application Data\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906}
[2011/02/08 20:54:17 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\Matthew\Application Data\Aharoq
[2011/02/12 22:04:29 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\Matthew\Application Data\Amtor
[2011/10/09 15:55:35 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\Matthew\Application Data\Azureus
[2008/04/14 23:06:04 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\Matthew\Application Data\CVS
[2011/02/12 11:51:21 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\Matthew\Application Data\Evyc
[2007/08/20 11:58:04 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\Matthew\Application Data\iPodSoft
[2010/11/03 00:27:41 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\Matthew\Application Data\LimeWire
[2011/02/06 17:31:42 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\Matthew\Application Data\Mapui
[2007/01/09 20:03:20 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\Matthew\Application Data\Purple Ghost Software, Inc
[2007/05/05 22:20:15 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\Matthew\Application Data\SecondLife
[2008/02/21 18:58:46 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\Matthew\Application Data\Snapfish
[2008/09/28 01:43:48 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\Matthew\Application Data\yoclient

========== Purity Check ==========



< End of report >
  • 0

Advertisements


#2
Essexboy

Essexboy

    GeekU Moderator

  • Retired Staff
  • 69,964 posts
Hi there lets get everything back together again for you... Please do not empty your temporary files until I do the first one

Download RogueKiller to your desktop

  • Quit all running programs
  • For Vista/Seven, right click -> run as administrator, for XP simply run RogueKiller.exe
  • When prompted, type 6 and validate
  • The RKreport.txt shall be generated next to the executable.
  • If the program is blocked, do not hesitate to try several times. If it really does not work (it could happen), rename it to winlogon.exe
Please post the contents of the RKreport.txt in your next Reply.

THEN

Warning This fix is only relevant for this system and no other, using on another computer may cause problems

Be advised that when the fix commences it will shut down all running processes and you may lose the desktop and icons, they will return on reboot

Run OTL
  • Under the Custom Scans/Fixes box at the bottom, paste in the following

    :OTL
    IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 1
    IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = <local>
    IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = http=127.0.0.1:56808
    FF - prefs.js..network.proxy.http: "127.0.0.1"
    FF - prefs.js..network.proxy.http_port: 56808
    FF - prefs.js..network.proxy.type: 4
    [2009/09/23 22:35:57 | 000,000,000 | -H-D | M] (XULRunner) -- C:\DOCUMENTS AND SETTINGS\JOSH\LOCAL SETTINGS\APPLICATION DATA\{AC2F4FDB-87C1-48E6-8868-C375623AF577}
    [2009/04/22 17:01:43 | 000,000,000 | -H-D | M] (XUL Cache) -- C:\DOCUMENTS AND SETTINGS\MATTHEW\LOCAL SETTINGS\APPLICATION DATA\{7EC8EF17-B3B5-4943-8AF5-B91B0863BB75}
    O4 - HKLM..\Run: [conhost] C:\Documents and Settings\Matthew\Application Data\Microsoft\conhost.exe ()
    O4 - HKCU..\Run: [KcGKxXpEJYTtjJY] C:\Documents and Settings\All Users\Application Data\KcGKxXpEJYTtjJY.exe (Microsoft Corporation)
    O4 - HKCU..\Run: [Rbexeju] rundll32.exe "C:\WINDOWS\wsecuil.dll",Startup File not found
    O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDesktop = 1
    O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableTaskMgr = 1
    O36 - AppCertDlls: bcmwnet - (C:\WINDOWS\system32\evenntsd.dll) - File not found
    O36 - AppCertDlls: bcmwnet1 - (C:\WINDOWS\eventvdm.dll) -C:\WINDOWS\eventvdm.dll ()
    [2011/08/28 01:55:17 | 000,816,128 | -H-- | C] (Heaventools Software) -- C:\Documents and Settings\All Users\Application Data\defender.exe
    [2011/06/03 14:23:47 | 000,333,824 | -H-- | C] (Microsoft Corporation) -- C:\Documents and Settings\All Users\Application Data\16244516.exe
    [2011/06/03 14:14:35 | 000,419,328 | -H-- | C] (Microsoft Corporation) -- C:\Documents and Settings\All Users\Application Data\KcGKxXpEJYTtjJY.exe
    [2011/09/13 23:28:38 | 000,185,856 | -H-- | C] () -- C:\Documents and Settings\Matthew\Application Data\dwm.exe
    [2011/09/11 13:51:46 | 000,186,368 | -H-- | C] () -- C:\Documents and Settings\Matthew\Application Data\dwmu.exe
    [2011/06/16 03:33:44 | 000,050,984 | -H-- | C] () -- C:\Documents and Settings\Matthew\Application Data\2752.1AC
    [2011/06/14 15:20:37 | 000,064,512 | -H-- | C] () -- C:\WINDOWS\eventvdm.dll
    [2011/06/14 15:20:02 | 000,064,512 | -H-- | C] () -- C:\WINDOWS\System32\eventvdm.dll
    [2011/06/03 14:25:02 | 000,000,152 | -H-- | C] () -- C:\Documents and Settings\All Users\Application Data\~16244516r
    [2011/06/03 14:25:02 | 000,000,136 | -H-- | C] () -- C:\Documents and Settings\All Users\Application Data\~16244516
    [2011/06/03 14:24:07 | 000,000,336 | -H-- | C] () -- C:\Documents and Settings\All Users\Application Data\16244516
    [2011/04/17 17:53:52 | 000,015,962 | -HS- | C] () -- C:\Documents and Settings\Matthew\Local Settings\Application Data\1ro18l3y70b46o6kj0v70
    [2011/04/17 17:53:52 | 000,015,962 | -HS- | C] () -- C:\Documents and Settings\All Users\Application Data\1ro18l3y70b46o6kj0v70
    [2011/03/06 21:20:48 | 000,015,870 | -HS- | C] () -- C:\Documents and Settings\Matthew\Local Settings\Application Data\.))S](VL)0[(+
    [2011/03/06 21:20:48 | 000,015,870 | -HS- | C] () -- C:\Documents and Settings\All Users\Application Data\.))S](VL)0[(+
    [2011/02/06 17:26:21 | 000,000,012 | -H-- | C] () -- C:\Documents and Settings\Matthew\Application Data\kuhzmn.dat
    [2009/06/30 00:20:16 | 000,002,713 | -HS- | C] () -- C:\WINDOWS\System32\tuzatazo.exe
    [2009/06/26 12:36:48 | 000,002,713 | -HS- | C] () -- C:\WINDOWS\System32\telemize.exe
    [2009/06/24 21:34:35 | 000,002,713 | -HS- | C] () -- C:\WINDOWS\System32\dapotado.exe
    [2009/06/09 22:54:22 | 000,002,713 | -HS- | C] () -- C:\WINDOWS\System32\gufipato.exe
    [2009/06/08 13:31:37 | 000,000,000 | -H-- | C] () -- C:\Documents and Settings\All Users\Application Data\91142176.ini
    [2011/02/24 18:37:51 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Application Data\bKnPeJc06511
    [2009/07/13 12:32:55 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Application Data\butazaji
    [2009/07/13 12:33:07 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Application Data\kapidapu
    [2009/07/13 12:33:07 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Application Data\lejiwafe
    [2009/07/13 12:33:18 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Application Data\narudoku
    [2009/07/13 12:33:18 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Application Data\pejonavi
    [2009/07/13 12:33:18 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Application Data\redivegi
    [2009/07/13 12:33:18 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Application Data\rurileka
    [2009/07/13 12:33:24 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Application Data\tokurepa
    [2009/07/13 12:33:24 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Application Data\tomatofi
    [2009/07/13 12:33:24 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Application Data\vozizowu
    [2009/07/13 12:33:24 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Application Data\wepozara
    [2009/07/13 12:33:24 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Application Data\woyevepa

    :Files
    ipconfig /flushdns /c

    :Commands
    [purity]
    [resethosts]
    [EMPTYFLASH]
    [CREATERESTOREPOINT]
    [Reboot]

  • Then click the Run Fix button at the top
  • Let the program run unhindered, reboot the PC when it is done
  • Open OTL again and click the Quick Scan button. Post the log it produces in your next reply.

  • 0

#3
Boomrad

Boomrad

    Member

  • Topic Starter
  • Member
  • PipPip
  • 17 posts
Sorry, everything moves like molasses and the connection resets when I attempt to post anything so I'm forced to do a bit of hopping back and forth between desktops. I've followed the instructions above and here is the info as requested, thanks again:

RogueKiller V6.1.6 [11/01/2011] by Tigzy
mail: tigzyRK<at>gmail<dot>com
Feedback: http://www.geekstogo...13-roguekiller/
Blog: http://tigzyrk.blogspot.com

Operating System: Windows XP (5.1.2600 Service Pack 2) 32 bits version
Started in : Normal mode
User: Matthew [Admin rights]
Mode: Shortcuts HJfix -- Date : 11/01/2011 15:16:40

Bad processes: 2
[SUSP PATH] eventvdm.dll -- C:\WINDOWS\eventvdm.dll -> UNLOADED
[SUSP PATH] eventvdm.dll -- C:\WINDOWS\eventvdm.dll -> UNLOADED

Driver: [LOADED]

File attributes restored:
Desktop: Success 0 / Fail 0
Quick launch: Success 0 / Fail 0
Programs: Success 0 / Fail 0
Start menu: Success 0 / Fail 0
User folder: Success 9645 / Fail 0
My documents: Success 0 / Fail 0
My favorites: Success 0 / Fail 0
My pictures: Success 0 / Fail 0
My music: Success 0 / Fail 0
My videos: Success 0 / Fail 0
Local drives: Success 36168 / Fail 0
Backup: [FOUND] Success 0 / Fail 166

Drives:
[C:] \Device\HarddiskVolume2 -- 0x3 --> Restored
[D:] \Device\CdRom0 -- 0x5 --> Skipped

Finished : << RKreport[1].txt >>
RKreport[1].txt






OTL logfile created on: 11/1/2011 3:37:22 PM - Run 3
OTL by OldTimer - Version 3.2.31.0 Folder = C:\Documents and Settings\Matthew\My Documents\Downloads
Windows XP Home Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 6.0.2900.2180)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

894.02 Mb Total Physical Memory | 420.64 Mb Available Physical Memory | 47.05% Memory free
2.12 Gb Paging File | 1.73 Gb Available in Paging File | 82.01% Paging File free
Paging file location(s): C:\pagefile.sys 1344 2688 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 52.21 Gb Total Space | 0.08 Gb Free Space | 0.16% Space Free | Partition Type: NTFS

Computer Name: DH9QL3C1 | User Name: Matthew | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - [2011/10/31 17:16:08 | 000,584,192 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Matthew\My Documents\Downloads\OTL(2).scr
PRC - [2011/09/27 23:56:56 | 000,912,344 | ---- | M] (Mozilla Corporation) -- C:\Program Files\Mozilla Firefox\firefox.exe
PRC - [2011/07/12 15:18:35 | 000,046,208 | ---- | M] (CenturyLink Inc) -- C:\Program Files\CenturyLink\Desktop\CenturyLinkTouchPointAgent.exe
PRC - [2011/02/23 08:04:20 | 003,451,496 | ---- | M] (AVAST Software) -- C:\Program Files\AVAST Software\Avast\AvastUI.exe
PRC - [2011/02/23 08:04:19 | 000,042,184 | ---- | M] (AVAST Software) -- C:\Program Files\AVAST Software\Avast\AvastSvc.exe
PRC - [2008/01/08 12:02:16 | 001,213,728 | ---- | M] (SupportSoft, Inc.) -- C:\Program Files\Common Files\supportsoft\bin\sprtlisten.exe
PRC - [2007/07/24 13:17:31 | 001,174,152 | ---- | M] (Symantec Corporation) -- C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
PRC - [2007/06/13 03:23:07 | 001,033,216 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe
PRC - [2006/08/23 15:13:28 | 000,380,928 | ---- | M] (Dell Inc.) -- C:\Program Files\Dell\QuickSet\NicConfigSvc.exe


========== Modules (No Company Name) ==========

MOD - [2011/09/27 23:56:56 | 001,015,256 | ---- | M] () -- C:\Program Files\Mozilla Firefox\js3250.dll
MOD - [2011/06/14 15:20:37 | 000,064,512 | ---- | M] () -- C:\WINDOWS\eventvdm.dll
MOD - [2011/02/24 02:55:49 | 000,844,288 | ---- | M] () -- C:\Program Files\AVAST Software\Avast\defs\11022400\algo.dll
MOD - [2011/02/23 08:04:14 | 000,144,672 | ---- | M] () -- C:\Program Files\AVAST Software\Avast\aswDld.dll
MOD - [2010/11/11 19:51:23 | 005,971,408 | ---- | M] () -- C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll
MOD - [2010/06/11 18:48:36 | 000,971,264 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Configuration\631b3eba1ba5bd3c3f027f34011cadeb\System.Configuration.ni.dll
MOD - [2010/06/11 18:15:22 | 012,430,848 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\2dfe045e4b1577fdea9a2f456db0afc2\System.Windows.Forms.ni.dll
MOD - [2010/06/08 20:37:37 | 001,840,640 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Web.Services\8ef8d556899a4a10b7f288a80925489f\System.Web.Services.ni.dll
MOD - [2010/06/08 20:34:45 | 000,998,400 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Management\16670b6870746e5a8dc4a73a76a90bed\System.Management.ni.dll
MOD - [2010/06/08 20:21:53 | 005,450,752 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Xml\563a54b98adb70fae862974042298348\System.Xml.ni.dll
MOD - [2010/06/08 20:20:55 | 001,587,200 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Drawing\f3440ea00eb3c40dc073b2fe03843638\System.Drawing.ni.dll
MOD - [2010/06/08 20:15:25 | 007,949,824 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System\37217abe2c5164e59aba251860f4c79e\System.ni.dll
MOD - [2009/10/15 02:21:38 | 011,486,720 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\mscorlib\7124a40b9998f7b63c86bd1a2125ce26\mscorlib.ni.dll
MOD - [2005/12/19 14:08:30 | 000,757,760 | ---- | M] () -- C:\WINDOWS\system32\bcm1xsup.dll


========== Win32 Services (SafeList) ==========

SRV - File not found [On_Demand | Stopped] -- -- (SupportSoft RemoteAssist)
SRV - File not found [Disabled | Stopped] -- -- (HidServ)
SRV - File not found [Auto | Stopped] -- -- (Automatic LiveUpdate Scheduler)
SRV - File not found [On_Demand | Stopped] -- -- (AppMgmt)
SRV - [2011/02/23 08:04:19 | 000,042,184 | ---- | M] (AVAST Software) [Auto | Running] -- C:\Program Files\AVAST Software\Avast\AvastSvc.exe -- (avast! Antivirus)
SRV - [2008/01/08 12:02:16 | 001,213,728 | ---- | M] (SupportSoft, Inc.) [Auto | Running] -- C:\Program Files\Common Files\supportsoft\bin\sprtlisten.exe -- (sprtlisten)
SRV - [2007/07/24 13:17:31 | 001,174,152 | ---- | M] (Symantec Corporation) [Auto | Running] -- C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe -- (Symantec Core LC)
SRV - [2006/08/23 15:13:28 | 000,380,928 | ---- | M] (Dell Inc.) [Auto | Running] -- C:\Program Files\Dell\QuickSet\NicConfigSvc.exe -- (NICCONFIGSVC)


========== Driver Services (SafeList) ==========

DRV - [2011/02/23 07:56:55 | 000,371,544 | ---- | M] (AVAST Software) [File_System | System | Running] -- C:\WINDOWS\System32\drivers\aswSnx.sys -- (aswSnx)
DRV - [2011/02/23 07:56:45 | 000,301,528 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\aswSP.sys -- (aswSP)
DRV - [2011/02/23 07:55:49 | 000,049,240 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\aswTdi.sys -- (aswTdi)
DRV - [2011/02/23 07:55:47 | 000,102,232 | ---- | M] (AVAST Software) [File_System | Auto | Running] -- C:\WINDOWS\System32\drivers\aswmon2.sys -- (aswMon2)
DRV - [2011/02/23 07:55:10 | 000,025,432 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\aswRdr.sys -- (aswRdr)
DRV - [2011/02/23 07:54:57 | 000,030,680 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\aavmker4.sys -- (Aavmker4)
DRV - [2011/02/23 07:54:55 | 000,019,544 | ---- | M] (AVAST Software) [File_System | Auto | Running] -- C:\WINDOWS\System32\drivers\aswFsBlk.sys -- (aswFsBlk)
DRV - [2006/11/14 14:41:34 | 000,010,344 | ---- | M] (Symantec Corporation) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\symlcbrd.sys -- (symlcbrd)
DRV - [2006/09/23 01:56:40 | 001,681,920 | ---- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\ati2mtag.sys -- (ati2mtag)
DRV - [2006/09/22 10:06:26 | 001,171,464 | ---- | M] (SigmaTel, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\sthda.sys -- (STHDA)
DRV - [2006/08/17 12:55:16 | 000,044,544 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\bcm4sbxp.sys -- (bcm4sbxp)
DRV - [2006/07/01 21:39:40 | 000,036,864 | ---- | M] (Advanced Micro Devices) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\AmdK8.sys -- (AmdK8)
DRV - [2006/01/10 11:07:58 | 000,004,864 | ---- | M] (GTek Technologies Ltd.) [Kernel | On_Demand | Stopped] -- C:\Program Files\Dell Support\GTAction\triggers\DSproct.sys -- (DSproct)
DRV - [2005/11/02 18:24:34 | 000,424,320 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\BCMWL5.SYS -- (BCM43XX)
DRV - [2005/08/12 16:50:46 | 000,016,128 | ---- | M] (Dell Inc) [Kernel | System | Running] -- C:\WINDOWS\SYSTEM32\DRIVERS\APPDRV.SYS -- (APPDRV)
DRV - [2005/07/14 22:58:14 | 000,028,544 | ---- | M] (REDC) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\rimmptsk.sys -- (rimmptsk)
DRV - [2004/06/09 08:29:56 | 000,006,977 | ---- | M] (Gteko Ltd.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\DDMI2.sys -- (SDDMI2)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell.com
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.google.com/ie
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.dell.com
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Page_URL = www.google.com/ig/dell?hl=en&client=dell-usuk&channel=us&ibd=4061114
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Start Page = www.google.com/ig/dell?hl=en&client=dell-usuk&channel=us&ibd=4061114

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://qwest.live.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultName = Google
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultURL = http://www.google.co...ie=utf8&oe=utf8
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = qwest.live.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 1
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = <local>
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = http=127.0.0.1:56808

========== FireFox ==========

FF - prefs.js..browser.startup.homepage: "http://marriedtothesea.com/"
FF - prefs.js..extensions.enabledItems: {0538E3E3-7E9B-4d49-8831-A227C80A7AD3}:2.0.2
FF - prefs.js..extensions.enabledItems: [email protected]:1.0
FF - prefs.js..extensions.enabledItems: {7EC8EF17-B3B5-4943-8AF5-B91B0863BB75}:1.0
FF - prefs.js..extensions.enabledItems: {AC2F4FDB-87C1-48E6-8868-C375623AF577}:1.9.1
FF - prefs.js..extensions.enabledItems: {AB2CE124-6272-4b12-94A9-7303C7397BD1}:5.0.0.6778
FF - prefs.js..extensions.enabledItems: [email protected]:20110101
FF - prefs.js..network.proxy.http: "127.0.0.1"
FF - prefs.js..network.proxy.http_port: 56808
FF - prefs.js..network.proxy.type: 4


FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Browser Plugin,version=1.0.0: C:\Program Files\DivX\DivX Web Player\npdivx32.dll (DivX,Inc.)
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Content Upload Plugin,version=1.0.0: C:\Program Files\DivX\DivX Content Uploader\npUpload.dll (DivX,Inc.)
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Player Plugin,version=1.0.0: C:\Program Files\DivX\DivX Player\npDivxPlayerPlugin.dll (DivX, Inc)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\4.0.60129.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@movenetworks.com/Quantum Media Player: C:\Documents and Settings\Josh\Application Data\Move Networks\plugins\npqmp071503000010.dll (Move Networks)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\extensions\\{7EC8EF17-B3B5-4943-8AF5-B91B0863BB75}: C:\Documents and Settings\Matthew\Local Settings\Application Data\{7EC8EF17-B3B5-4943-8AF5-B91B0863BB75} [2009/04/22 17:01:43 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\extensions\\{AC2F4FDB-87C1-48E6-8868-C375623AF577}: C:\Documents and Settings\Josh\Local Settings\Application Data\{AC2F4FDB-87C1-48E6-8868-C375623AF577} [2009/09/23 22:35:57 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\extensions\\[email protected]: C:\Program Files\AVAST Software\Avast\WebRep\FF [2011/04/17 18:45:00 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 3.6.23\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011/10/06 22:25:52 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 3.6.23\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011/09/27 23:57:08 | 000,000,000 | ---D | M]

[2009/03/11 16:37:31 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Matthew\Application Data\Mozilla\Extensions
[2009/03/11 16:37:31 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Matthew\Application Data\Mozilla\Extensions\[email protected]
[2011/10/31 17:24:00 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Matthew\Application Data\Mozilla\Firefox\Profiles\xn4cc6wh.default\extensions
[2010/09/23 23:26:42 | 000,000,000 | ---D | M] (Forecastfox Weather) -- C:\Documents and Settings\Matthew\Application Data\Mozilla\Firefox\Profiles\xn4cc6wh.default\extensions\{0538E3E3-7E9B-4d49-8831-A227C80A7AD3}
[2009/09/04 01:19:35 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- C:\Documents and Settings\Matthew\Application Data\Mozilla\Firefox\Profiles\xn4cc6wh.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2009/07/24 03:29:49 | 000,000,000 | ---D | M] (MidnightFox) -- C:\Documents and Settings\Matthew\Application Data\Mozilla\Firefox\Profiles\xn4cc6wh.default\extensions\{66871bd1-5ba2-4739-b485-2a15f5969bd8}
[2007/05/03 01:01:30 | 000,007,431 | ---- | M] () -- C:\Documents and Settings\Matthew\Application Data\Mozilla\Firefox\Profiles\xn4cc6wh.default\searchplugins\dictionarycom.xml
[2008/06/24 01:02:01 | 000,000,908 | ---- | M] () -- C:\Documents and Settings\Matthew\Application Data\Mozilla\Firefox\Profiles\xn4cc6wh.default\searchplugins\imdb.xml
[2008/06/24 01:02:01 | 000,001,108 | ---- | M] () -- C:\Documents and Settings\Matthew\Application Data\Mozilla\Firefox\Profiles\xn4cc6wh.default\searchplugins\wikipedia-en.xml
[2008/06/02 12:57:27 | 000,001,628 | ---- | M] () -- C:\Documents and Settings\Matthew\Application Data\Mozilla\Firefox\Profiles\xn4cc6wh.default\searchplugins\youtube.xml
[2011/10/31 17:24:00 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions
[2010/11/26 19:30:41 | 000,000,000 | ---D | M] (Skype extension) -- C:\Program Files\Mozilla Firefox\extensions\{AB2CE124-6272-4b12-94A9-7303C7397BD1}
[2009/09/23 22:35:57 | 000,000,000 | ---D | M] (XULRunner) -- C:\DOCUMENTS AND SETTINGS\JOSH\LOCAL SETTINGS\APPLICATION DATA\{AC2F4FDB-87C1-48E6-8868-C375623AF577}
[2009/04/22 17:01:43 | 000,000,000 | ---D | M] (XUL Cache) -- C:\DOCUMENTS AND SETTINGS\MATTHEW\LOCAL SETTINGS\APPLICATION DATA\{7EC8EF17-B3B5-4943-8AF5-B91B0863BB75}
[2011/04/17 18:45:00 | 000,000,000 | ---D | M] (avast! WebRep) -- C:\PROGRAM FILES\AVAST SOFTWARE\AVAST\WEBREP\FF
[2009/03/11 16:31:48 | 000,000,000 | ---D | M] (Java Quick Starter) -- C:\PROGRAM FILES\JAVA\JRE6\LIB\DEPLOY\JQS\FF
[2006/01/18 12:50:00 | 000,319,488 | ---- | M] ( ) -- C:\Program Files\mozilla firefox\plugins\npsnapfish.dll

========== Chrome ==========

CHR - default_search_provider: Google ()
CHR - default_search_provider: search_url = {google:baseURL}search?{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}sourceid=chrome&ie={inputEncoding}&q={searchTerms}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?client=chrome&hl={language}&q={searchTerms}

Hosts file not found
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (avast! WebRep) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll ()
O2 - BHO: (Skype Plug-In) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O2 - BHO: (Windows Live Toolbar Helper) - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll (Microsoft Corporation)
O3 - HKLM\..\Toolbar: (avast! WebRep) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll ()
O3 - HKLM\..\Toolbar: (Windows Live Toolbar) - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll (Microsoft Corporation)
O3 - HKCU\..\Toolbar\ShellBrowser: (Windows Live Toolbar) - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll (Microsoft Corporation)
O3 - HKCU\..\Toolbar\WebBrowser: (Windows Live Toolbar) - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll (Microsoft Corporation)
O4 - HKLM..\Run: [avast] C:\Program Files\AVAST Software\Avast\avastUI.exe (AVAST Software)
O4 - HKLM..\Run: [CenturyLinkTouchPointAgent] C:\Program Files\CenturyLink\Desktop\CenturyLinkTouchPointAgent.exe (CenturyLink Inc)
O4 - HKLM..\Run: [conhost] C:\Documents and Settings\Matthew\Application Data\Microsoft\conhost.exe ()
O4 - HKCU..\Run: [DellSupport] C:\Program Files\Dell Support\DSAgnt.exe (Gteko Ltd.)
O4 - HKCU..\Run: [KcGKxXpEJYTtjJY] C:\Documents and Settings\All Users\Application Data\KcGKxXpEJYTtjJY.exe (Microsoft Corporation)
O4 - HKCU..\Run: [ModemOnHold] C:\Program Files\NetWaiting\netwaiting.exe ()
O4 - HKCU..\Run: [Rbexeju] rundll32.exe "C:\WINDOWS\wsecuil.dll",Startup File not found
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe (Adobe Systems Incorporated)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\GigaTribe.lnk = File not found
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE (Microsoft Corporation)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Main present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\PhishingFilter present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoControlPanel = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoControlPanel = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoWindowsUpdate = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDesktop = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableTaskMgr = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableProfileQuota = 1
O8 - Extra context menu item: &Windows Live Search - C:\Program Files\Windows Live Toolbar\msntb.dll (Microsoft Corporation)
O8 - Extra context menu item: Add to Windows &Live Favorites - http://favorites.liv...m/quickadd.aspx File not found
O9 - Extra Button: Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O16 - DPF: {00000161-0000-0010-8000-00AA00389B71} http://codecs.micros...386/msaudio.cab (Reg Error: Key error.)
O16 - DPF: {31435657-9980-0010-8000-00AA00389B71} http://download.micr...78f/wvc1dmo.cab (Reg Error: Key error.)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_15)
O16 - DPF: {95D88B35-A521-472B-A182-BB1A98356421} http://asp.mathxl.co...nstallAsst2.cab (Pearson Installation Assistant 2)
O16 - DPF: {CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_15)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_15)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.m...ash/swflash.cab (Shockwave Flash Object)
O16 - DPF: {E6D23284-0E9B-417D-A782-03E4487FC947} http://asp.mathxl.co.../MathPlayer.cab (Pearson MathXL Player)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.0.1 205.171.3.25
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{3588A12F-AE15-4D4A-86A9-26ACA9D1CCA9}: DhcpNameServer = 192.168.0.1 205.171.3.25
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O20 - HKLM Winlogon: Shell - (Explorer.exe) -C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) -C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O20 - Winlogon\Notify\AtiExtEvent: DllName - (Ati2evxx.dll) - C:\WINDOWS\System32\ati2evxx.dll (ATI Technologies Inc.)
O24 - Desktop WallPaper: C:\Documents and Settings\Matthew\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Matthew\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O28 - HKLM ShellExecuteHooks: {091EB208-39DD-417D-A5DD-7E2C2D8FB9CB} - C:\Program Files\Windows Defender\MpShHook.dll (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2004/08/10 12:04:08 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O35 - HKCU\..exefile [open] -- "%1" %*
O36 - AppCertDlls: bcmwnet - (C:\WINDOWS\system32\evenntsd.dll) - File not found
O36 - AppCertDlls: bcmwnet1 - (C:\WINDOWS\eventvdm.dll) -C:\WINDOWS\eventvdm.dll ()
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKCU\...exe [@ = exefile] -- "%1" %*

========== Files/Folders - Created Within 30 Days ==========

[2011/11/01 14:59:20 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\Qwest
[2011/11/01 14:59:20 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\Malwarebytes' Anti-Malware
[2011/11/01 14:56:02 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Matthew\Desktop\RK_Quarantine
[2011/10/31 00:14:16 | 000,000,000 | R--D | C] -- C:\Documents and Settings\Matthew\Recent
[2011/10/13 23:01:53 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Matthew\My Documents\cornish - matt aguayo
[2011/08/28 01:55:17 | 000,816,128 | ---- | C] (Heaventools Software) -- C:\Documents and Settings\All Users\Application Data\defender.exe
[2011/06/03 14:23:47 | 000,333,824 | ---- | C] (Microsoft Corporation) -- C:\Documents and Settings\All Users\Application Data\16244516.exe
[2011/06/03 14:14:35 | 000,419,328 | ---- | C] (Microsoft Corporation) -- C:\Documents and Settings\All Users\Application Data\KcGKxXpEJYTtjJY.exe
[2 C:\Documents and Settings\Matthew\My Documents\*.tmp files -> C:\Documents and Settings\Matthew\My Documents\*.tmp -> ]
[1 C:\Documents and Settings\All Users\Application Data\*.tmp files -> C:\Documents and Settings\All Users\Application Data\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2011/11/01 15:32:52 | 000,002,206 | -H-- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2011/11/01 15:31:27 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2011/11/01 15:31:21 | 937,521,152 | -HS- | M] () -- C:\hiberfil.sys
[2011/10/15 15:26:27 | 000,000,099 | ---- | M] () -- C:\Documents and Settings\Matthew\Desktop\fix.reg
[2 C:\Documents and Settings\Matthew\My Documents\*.tmp files -> C:\Documents and Settings\Matthew\My Documents\*.tmp -> ]
[1 C:\Documents and Settings\All Users\Application Data\*.tmp files -> C:\Documents and Settings\All Users\Application Data\*.tmp -> ]

========== Files Created - No Company Name ==========

[2011/11/01 14:59:21 | 000,002,265 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Skype.lnk
[2011/11/01 14:59:21 | 000,002,155 | ---- | C] () -- C:\Documents and Settings\Matthew\Application Data\Microsoft\Internet Explorer\Quick Launch\iTunes.lnk
[2011/11/01 14:59:21 | 000,002,137 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\iTunes.lnk
[2011/11/01 14:59:21 | 000,001,689 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\avast! Free Antivirus.lnk
[2011/11/01 14:59:21 | 000,001,620 | ---- | C] () -- C:\Documents and Settings\Matthew\Application Data\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox.lnk
[2011/11/01 14:59:21 | 000,001,602 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Firefox.lnk
[2011/11/01 14:59:21 | 000,000,955 | ---- | C] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Windows Defender.lnk
[2011/11/01 14:59:21 | 000,000,793 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Security Protection.lnk
[2011/11/01 14:59:21 | 000,000,690 | ---- | C] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Windows Movie Maker.lnk
[2011/11/01 14:59:21 | 000,000,609 | ---- | C] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Windows Messenger.lnk
[2011/11/01 14:59:21 | 000,000,079 | ---- | C] () -- C:\Documents and Settings\Matthew\Application Data\Microsoft\Internet Explorer\Quick Launch\Show Desktop.scf
[2011/11/01 14:59:20 | 000,002,465 | ---- | C] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Microsoft PowerPoint.lnk
[2011/11/01 14:59:20 | 000,001,890 | ---- | C] () -- C:\Documents and Settings\All Users\Start Menu\Programs\MSN.lnk
[2011/11/01 14:59:20 | 000,001,775 | ---- | C] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Microsoft Office PowerPoint Viewer 2003.lnk
[2011/11/01 14:59:20 | 000,001,757 | ---- | C] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk
[2011/11/01 14:59:20 | 000,001,725 | ---- | C] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk
[2011/11/01 14:59:20 | 000,001,701 | ---- | C] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Microsoft Works Task Launcher.lnk
[2011/11/01 14:59:20 | 000,001,690 | ---- | C] () -- C:\Documents and Settings\All Users\Start Menu\Programs\PowerDVD.lnk
[2011/11/01 14:59:20 | 000,000,652 | ---- | C] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Startup\GigaTribe.lnk
[2011/11/01 14:59:20 | 000,000,493 | ---- | C] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Digital Line Detect.lnk
[2011/11/01 14:59:18 | 000,001,830 | ---- | C] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Apple Software Update.lnk
[2011/11/01 14:59:18 | 000,001,810 | ---- | C] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Adobe Reader 7.0.lnk
[2011/10/15 15:26:27 | 000,000,099 | ---- | C] () -- C:\Documents and Settings\Matthew\Desktop\fix.reg
[2011/10/10 01:27:02 | 937,521,152 | -HS- | C] () -- C:\hiberfil.sys
[2011/09/13 23:28:38 | 000,185,856 | ---- | C] () -- C:\Documents and Settings\Matthew\Application Data\dwm.exe
[2011/09/11 13:51:46 | 000,186,368 | ---- | C] () -- C:\Documents and Settings\Matthew\Application Data\dwmu.exe
[2011/06/16 03:33:44 | 000,050,984 | ---- | C] () -- C:\Documents and Settings\Matthew\Application Data\2752.1AC
[2011/06/14 15:20:37 | 000,064,512 | ---- | C] () -- C:\WINDOWS\eventvdm.dll
[2011/06/14 15:20:02 | 000,064,512 | ---- | C] () -- C:\WINDOWS\System32\eventvdm.dll
[2011/06/03 14:25:02 | 000,000,152 | -H-- | C] () -- C:\Documents and Settings\All Users\Application Data\~16244516r
[2011/06/03 14:25:02 | 000,000,136 | -H-- | C] () -- C:\Documents and Settings\All Users\Application Data\~16244516
[2011/06/03 14:24:07 | 000,000,336 | ---- | C] () -- C:\Documents and Settings\All Users\Application Data\16244516
[2011/04/17 17:53:52 | 000,015,962 | --S- | C] () -- C:\Documents and Settings\Matthew\Local Settings\Application Data\1ro18l3y70b46o6kj0v70
[2011/04/17 17:53:52 | 000,015,962 | --S- | C] () -- C:\Documents and Settings\All Users\Application Data\1ro18l3y70b46o6kj0v70
[2011/03/06 21:20:48 | 000,015,870 | --S- | C] () -- C:\Documents and Settings\Matthew\Local Settings\Application Data\.))S](VL)0[(+
[2011/03/06 21:20:48 | 000,015,870 | --S- | C] () -- C:\Documents and Settings\All Users\Application Data\.))S](VL)0[(+
[2011/02/06 17:26:21 | 000,000,012 | ---- | C] () -- C:\Documents and Settings\Matthew\Application Data\kuhzmn.dat
[2010/11/26 19:31:48 | 000,000,056 | ---- | C] () -- C:\WINDOWS\System32\ezsidmv.dat
[2010/01/12 14:48:28 | 000,042,824 | ---- | C] () -- C:\WINDOWS\System32\mlfcache.dat
[2009/06/30 00:20:16 | 000,002,713 | --S- | C] () -- C:\WINDOWS\System32\tuzatazo.exe
[2009/06/26 12:36:48 | 000,002,713 | --S- | C] () -- C:\WINDOWS\System32\telemize.exe
[2009/06/24 21:34:35 | 000,002,713 | --S- | C] () -- C:\WINDOWS\System32\dapotado.exe
[2009/06/09 22:54:22 | 000,002,713 | --S- | C] () -- C:\WINDOWS\System32\gufipato.exe
[2009/06/08 13:31:37 | 000,000,000 | -H-- | C] () -- C:\Documents and Settings\All Users\Application Data\91142176.ini
[2009/06/04 23:33:33 | 000,001,324 | ---- | C] () -- C:\WINDOWS\System32\d3d9caps.dat
[2009/04/22 17:01:44 | 000,000,000 | ---- | C] () -- C:\WINDOWS\Thubexi.bin
[2009/04/22 17:01:40 | 000,000,120 | ---- | C] () -- C:\WINDOWS\Byazigere.dat
[2007/04/22 17:15:29 | 003,596,288 | ---- | C] () -- C:\WINDOWS\System32\qt-dx331.dll
[2007/04/22 17:01:47 | 000,012,288 | ---- | C] () -- C:\WINDOWS\System32\DivXWMPExtType.dll
[2007/02/02 13:59:03 | 000,018,494 | ---- | C] () -- C:\Documents and Settings\Matthew\Application Data\wklnhst.dat
[2007/01/24 19:28:48 | 000,071,680 | -H-- | C] () -- C:\Documents and Settings\Matthew\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2007/01/15 21:04:35 | 000,002,828 | --S- | C] () -- C:\WINDOWS\System32\KGyGaAvL.sys
[2007/01/15 21:04:35 | 000,000,088 | R-S- | C] () -- C:\WINDOWS\System32\7FD562AE33.sys
[2007/01/05 11:28:28 | 000,001,938 | ---- | C] () -- C:\WINDOWS\mozver.dat
[2006/11/27 23:41:19 | 000,001,359 | ---- | C] () -- C:\Documents and Settings\All Users\Application Data\QTSBandwidthCache
[2006/11/27 15:12:02 | 000,000,000 | ---- | C] () -- C:\WINDOWS\nsreg.dat
[2006/11/23 14:58:33 | 000,000,130 | ---- | C] () -- C:\Documents and Settings\Matthew\Local Settings\Application Data\fusioncache.dat
[2006/11/14 14:55:00 | 000,000,061 | -H-- | C] () -- C:\WINDOWS\smscfg.ini
[2006/11/14 14:38:20 | 000,000,376 | ---- | C] () -- C:\WINDOWS\ODBC.INI
[2006/11/14 14:27:50 | 000,000,004 | ---- | C] () -- C:\Documents and Settings\All Users\Application Data\QSLLPSVCShare
[2006/11/14 14:02:18 | 000,086,016 | ---- | C] () -- C:\WINDOWS\System32\preflib.dll
[2006/11/14 14:02:18 | 000,018,944 | ---- | C] () -- C:\WINDOWS\System32\WLTRYSVC.EXE
[2006/11/14 14:02:12 | 000,757,760 | ---- | C] () -- C:\WINDOWS\System32\bcm1xsup.dll
[2006/11/14 14:01:54 | 000,133,246 | ---- | C] () -- C:\WINDOWS\System32\atiicdxx.dat
[2006/11/14 14:01:52 | 000,049,152 | ---- | C] () -- C:\WINDOWS\setpwrcg.exe
[2006/11/14 14:01:50 | 000,000,390 | ---- | C] () -- C:\WINDOWS\System32\OEMINFO.INI
[2004/08/10 12:12:05 | 000,000,780 | -H-- | C] () -- C:\WINDOWS\orun32.ini
[2004/08/10 12:07:31 | 000,002,048 | --S- | C] () -- C:\WINDOWS\bootstat.dat
[2004/08/10 12:02:15 | 000,021,640 | ---- | C] () -- C:\WINDOWS\System32\emptyregdb.dat
[2004/08/10 11:57:52 | 000,004,161 | ---- | C] () -- C:\WINDOWS\ODBCINST.INI
[2004/08/10 11:57:15 | 000,219,248 | ---- | C] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2004/08/10 11:51:21 | 000,004,569 | ---- | C] () -- C:\WINDOWS\System32\secupd.dat
[2004/08/10 11:51:20 | 000,443,034 | ---- | C] () -- C:\WINDOWS\System32\perfh009.dat
[2004/08/10 11:51:20 | 000,272,128 | ---- | C] () -- C:\WINDOWS\System32\perfi009.dat
[2004/08/10 11:51:20 | 000,072,134 | ---- | C] () -- C:\WINDOWS\System32\perfc009.dat
[2004/08/10 11:51:20 | 000,028,626 | ---- | C] () -- C:\WINDOWS\System32\perfd009.dat
[2004/08/10 11:51:18 | 000,004,627 | ---- | C] () -- C:\WINDOWS\System32\oembios.dat
[2004/08/10 11:51:17 | 013,107,200 | ---- | C] () -- C:\WINDOWS\System32\oembios.bin
[2004/08/10 11:51:16 | 000,000,741 | ---- | C] () -- C:\WINDOWS\System32\noise.dat
[2004/08/10 11:51:12 | 000,673,088 | ---- | C] () -- C:\WINDOWS\System32\mlang.dat
[2004/08/10 11:51:11 | 000,046,258 | ---- | C] () -- C:\WINDOWS\System32\mib.bin
[2004/08/10 11:51:05 | 000,218,003 | ---- | C] () -- C:\WINDOWS\System32\dssec.dat
[2004/08/10 11:50:56 | 000,001,788 | ---- | C] () -- C:\WINDOWS\System32\Dcache.bin

========== LOP Check ==========

[2010/11/12 17:02:32 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Alwil Software
[2011/04/17 18:44:48 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\AVAST Software
[2011/02/24 18:37:51 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\bKnPeJc06511
[2009/07/13 12:32:55 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\butazaji
[2008/01/27 15:25:33 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\CanonBJ
[2011/10/31 02:24:14 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\CenturyLink
[2009/07/13 12:33:07 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\kapidapu
[2009/07/13 12:33:07 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\lejiwafe
[2009/07/13 12:33:18 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\narudoku
[2009/07/13 12:33:18 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\pejonavi
[2009/07/13 12:33:18 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\redivegi
[2009/07/13 12:33:18 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\rurileka
[2009/07/13 12:33:24 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\tokurepa
[2009/07/13 12:33:24 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\tomatofi
[2009/07/13 12:33:24 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\vozizowu
[2009/07/13 12:33:24 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\wepozara
[2009/07/13 12:33:24 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\woyevepa
[2007/04/16 10:19:25 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\YAHOO
[2009/12/09 00:03:50 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\{755AC846-7372-4AC8-8550-C52491DAA8BD}
[2009/07/03 14:09:58 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906}
[2011/02/08 20:54:17 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Matthew\Application Data\Aharoq
[2011/02/12 22:04:29 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Matthew\Application Data\Amtor
[2011/10/09 15:55:35 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Matthew\Application Data\Azureus
[2008/04/14 23:06:04 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Matthew\Application Data\CVS
[2011/02/12 11:51:21 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Matthew\Application Data\Evyc
[2007/08/20 11:58:04 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Matthew\Application Data\iPodSoft
[2010/11/03 00:27:41 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Matthew\Application Data\LimeWire
[2011/02/06 17:31:42 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Matthew\Application Data\Mapui
[2007/01/09 20:03:20 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Matthew\Application Data\Purple Ghost Software, Inc
[2007/05/05 22:20:15 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Matthew\Application Data\SecondLife
[2008/02/21 18:58:46 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Matthew\Application Data\Snapfish
[2008/09/28 01:43:48 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Matthew\Application Data\yoclient

========== Purity Check ==========



< End of report >
  • 0

#4
Essexboy

Essexboy

    GeekU Moderator

  • Retired Staff
  • 69,964 posts
That did not appear to take - lets try one more time and then hit it harder. Have all your folders returned ?

Warning This fix is only relevant for this system and no other, using on another computer may cause problems

Be advised that when the fix commences it will shut down all running processes and you may lose the desktop and icons, they will return on reboot

Run OTL
  • Under the Custom Scans/Fixes box at the bottom, paste in the following

    :OTL
    IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 1
    IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = <local>
    IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = http=127.0.0.1:56808
    FF - prefs.js..network.proxy.http: "127.0.0.1"
    FF - prefs.js..network.proxy.http_port: 56808
    FF - prefs.js..network.proxy.type: 4
    [2009/09/23 22:35:57 | 000,000,000 | ---D | M] (XULRunner) -- C:\DOCUMENTS AND SETTINGS\JOSH\LOCAL SETTINGS\APPLICATION DATA\{AC2F4FDB-87C1-48E6-8868-C375623AF577}
    [2009/04/22 17:01:43 | 000,000,000 | ---D | M] (XUL Cache) -- C:\DOCUMENTS AND SETTINGS\MATTHEW\LOCAL SETTINGS\APPLICATION DATA\{7EC8EF17-B3B5-4943-8AF5-B91B0863BB75}
    O4 - HKLM..\Run: [conhost] C:\Documents and Settings\Matthew\Application Data\Microsoft\conhost.exe ()
    O4 - HKCU..\Run: [KcGKxXpEJYTtjJY] C:\Documents and Settings\All Users\Application Data\KcGKxXpEJYTtjJY.exe (Microsoft Corporation)
    O4 - HKCU..\Run: [Rbexeju] rundll32.exe "C:\WINDOWS\wsecuil.dll",Startup File not found
    O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDesktop = 1
    O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableTaskMgr = 1
    O16 - DPF: {00000161-0000-0010-8000-00AA00389B71} http://codecs.micros...386/msaudio.cab (Reg Error: Key error.)
    O16 - DPF: {31435657-9980-0010-8000-00AA00389B71} http://download.micr...78f/wvc1dmo.cab (Reg Error: Key error.)
    O16 - DPF: {CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Reg Error: Key error.)
    O36 - AppCertDlls: bcmwnet - (C:\WINDOWS\system32\evenntsd.dll) - File not found
    O36 - AppCertDlls: bcmwnet1 - (C:\WINDOWS\eventvdm.dll) -C:\WINDOWS\eventvdm.dll ()
    [2011/08/28 01:55:17 | 000,816,128 | ---- | C] (Heaventools Software) -- C:\Documents and Settings\All Users\Application Data\defender.exe
    [2011/06/03 14:23:47 | 000,333,824 | ---- | C] (Microsoft Corporation) -- C:\Documents and Settings\All Users\Application Data\16244516.exe
    [2011/06/03 14:14:35 | 000,419,328 | ---- | C] (Microsoft Corporation) -- C:\Documents and Settings\All Users\Application Data\KcGKxXpEJYTtjJY.exe
    [2011/11/01 14:59:21 | 000,000,955 | ---- | C] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Windows Defender.lnk
    [2011/11/01 14:59:21 | 000,000,793 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Security Protection.lnk
    [2011/09/13 23:28:38 | 000,185,856 | ---- | C] () -- C:\Documents and Settings\Matthew\Application Data\dwm.exe
    [2011/09/11 13:51:46 | 000,186,368 | ---- | C] () -- C:\Documents and Settings\Matthew\Application Data\dwmu.exe
    [2011/06/16 03:33:44 | 000,050,984 | ---- | C] () -- C:\Documents and Settings\Matthew\Application Data\2752.1AC
    [2011/06/14 15:20:37 | 000,064,512 | ---- | C] () -- C:\WINDOWS\eventvdm.dll
    [2011/06/14 15:20:02 | 000,064,512 | ---- | C] () -- C:\WINDOWS\System32\eventvdm.dll
    [2011/06/03 14:25:02 | 000,000,152 | -H-- | C] () -- C:\Documents and Settings\All Users\Application Data\~16244516r
    [2011/06/03 14:25:02 | 000,000,136 | -H-- | C] () -- C:\Documents and Settings\All Users\Application Data\~16244516
    [2011/06/03 14:24:07 | 000,000,336 | ---- | C] () -- C:\Documents and Settings\All Users\Application Data\16244516
    [2011/04/17 17:53:52 | 000,015,962 | --S- | C] () -- C:\Documents and Settings\Matthew\Local Settings\Application Data\1ro18l3y70b46o6kj0v70
    [2011/04/17 17:53:52 | 000,015,962 | --S- | C] () -- C:\Documents and Settings\All Users\Application Data\1ro18l3y70b46o6kj0v70
    [2011/03/06 21:20:48 | 000,015,870 | --S- | C] () -- C:\Documents and Settings\Matthew\Local Settings\Application Data\.))S](VL)0[(+
    [2011/03/06 21:20:48 | 000,015,870 | --S- | C] () -- C:\Documents and Settings\All Users\Application Data\.))S](VL)0[(+
    [2011/02/06 17:26:21 | 000,000,012 | ---- | C] () -- C:\Documents and Settings\Matthew\Application Data\kuhzmn.dat
    [2009/06/30 00:20:16 | 000,002,713 | --S- | C] () -- C:\WINDOWS\System32\tuzatazo.exe
    [2009/06/26 12:36:48 | 000,002,713 | --S- | C] () -- C:\WINDOWS\System32\telemize.exe
    [2009/06/24 21:34:35 | 000,002,713 | --S- | C] () -- C:\WINDOWS\System32\dapotado.exe
    [2009/06/09 22:54:22 | 000,002,713 | --S- | C] () -- C:\WINDOWS\System32\gufipato.exe
    [2009/06/08 13:31:37 | 000,000,000 | -H-- | C] () -- C:\Documents and Settings\All Users\Application Data\91142176.ini
    [2009/04/22 17:01:44 | 000,000,000 | ---- | C] () -- C:\WINDOWS\Thubexi.bin
    [2009/04/22 17:01:40 | 000,000,120 | ---- | C] () -- C:\WINDOWS\Byazigere.dat
    [2011/02/24 18:37:51 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\bKnPeJc06511
    [2009/07/13 12:32:55 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\butazaji
    [2008/01/27 15:25:33 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\CanonBJ
    [2011/10/31 02:24:14 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\CenturyLink
    [2009/07/13 12:33:07 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\kapidapu
    [2009/07/13 12:33:07 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\lejiwafe
    [2009/07/13 12:33:18 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\narudoku
    [2009/07/13 12:33:18 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\pejonavi
    [2009/07/13 12:33:18 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\redivegi
    [2009/07/13 12:33:18 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\rurileka
    [2009/07/13 12:33:24 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\tokurepa
    [2009/07/13 12:33:24 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\tomatofi
    [2009/07/13 12:33:24 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\vozizowu
    [2009/07/13 12:33:24 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\wepozara
    [2009/07/13 12:33:24 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\woyevepa
    [2011/02/08 20:54:17 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Matthew\Application Data\Aharoq

    :Files
    ipconfig /flushdns /c

    :Commands
    [purity]
    [resethosts]
    [EMPTYFLASH]
    [CREATERESTOREPOINT]
    [Reboot]

  • Then click the Run Fix button at the top
  • Let the program run unhindered, reboot the PC when it is done
  • Open OTL again and click the Quick Scan button. Post the log it produces in your next reply.


THEN

Please download Malwarebytes' Anti-Malware

Double Click mbam-setup.exe to install the application.
  • Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish, so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected.
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.
Extra Note:
If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts, click OK to either and let MBAM proceed with the disinfection process, if asked to restart the computer, please do so immediately.
  • 0

#5
Boomrad

Boomrad

    Member

  • Topic Starter
  • Member
  • PipPip
  • 17 posts
Alright, so my files and desktop icons have definitely returned, thanks for that! However, something is still disabling my internet connection upon login and the same Avast! Security screen continues to pop up recommending opening a 'netwaiting' file in the sandbox, not much happens upon doing so. Avast! is also finding a rootkit named "MBR: \\.\PHYSICALDRIVE0" and continues to do so regardless of how many times I delete it and reboot. I ran Malwarebytes' before receiving your second response during which it found 26 infected files, which were all deleted. I've run a second scan since the OTL fix just be thorough and have included the log, which found no infections. Thankyouthankyouthankyou for your time and support!

mbam-log-2011-11-03 (00-49-25).txt

Scan type: Quick scan
Objects scanned: 200836
Time elapsed: 10 minute(s), 51 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)

OTL logfile created on: 11/3/2011 12:29:06 AM - Run 4
OTL by OldTimer - Version 3.2.31.0 Folder = C:\Documents and Settings\Matthew\My Documents\Downloads
Windows XP Home Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 6.0.2900.2180)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

894.02 Mb Total Physical Memory | 525.79 Mb Available Physical Memory | 58.81% Memory free
2.12 Gb Paging File | 1.82 Gb Available in Paging File | 86.05% Paging File free
Paging file location(s): C:\pagefile.sys 1344 2688 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 52.21 Gb Total Space | 0.07 Gb Free Space | 0.14% Space Free | Partition Type: NTFS

Computer Name: DH9QL3C1 | User Name: Matthew | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - [2011/10/31 17:16:08 | 000,584,192 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Matthew\My Documents\Downloads\OTL(2).scr
PRC - [2011/07/12 15:18:35 | 000,046,208 | ---- | M] (CenturyLink Inc) -- C:\Program Files\CenturyLink\Desktop\CenturyLinkTouchPointAgent.exe
PRC - [2011/02/23 08:04:20 | 003,451,496 | ---- | M] (AVAST Software) -- C:\Program Files\AVAST Software\Avast\AvastUI.exe
PRC - [2011/02/23 08:04:19 | 000,042,184 | ---- | M] (AVAST Software) -- C:\Program Files\AVAST Software\Avast\AvastSvc.exe
PRC - [2008/01/08 12:02:16 | 001,213,728 | ---- | M] (SupportSoft, Inc.) -- C:\Program Files\Common Files\supportsoft\bin\sprtlisten.exe
PRC - [2007/07/24 13:17:31 | 001,174,152 | ---- | M] (Symantec Corporation) -- C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
PRC - [2007/06/13 03:23:07 | 001,033,216 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe
PRC - [2006/08/23 15:13:28 | 000,380,928 | ---- | M] (Dell Inc.) -- C:\Program Files\Dell\QuickSet\NicConfigSvc.exe


========== Modules (No Company Name) ==========

MOD - [2011/06/14 15:20:37 | 000,064,512 | ---- | M] () -- C:\WINDOWS\eventvdm.dll
MOD - [2011/02/24 02:55:49 | 000,844,288 | ---- | M] () -- C:\Program Files\AVAST Software\Avast\defs\11022400\algo.dll
MOD - [2011/02/23 08:04:14 | 000,144,672 | ---- | M] () -- C:\Program Files\AVAST Software\Avast\aswDld.dll
MOD - [2010/06/11 18:48:36 | 000,971,264 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Configuration\631b3eba1ba5bd3c3f027f34011cadeb\System.Configuration.ni.dll
MOD - [2010/06/11 18:15:22 | 012,430,848 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\2dfe045e4b1577fdea9a2f456db0afc2\System.Windows.Forms.ni.dll
MOD - [2010/06/08 20:37:37 | 001,840,640 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Web.Services\8ef8d556899a4a10b7f288a80925489f\System.Web.Services.ni.dll
MOD - [2010/06/08 20:34:45 | 000,998,400 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Management\16670b6870746e5a8dc4a73a76a90bed\System.Management.ni.dll
MOD - [2010/06/08 20:34:42 | 000,311,296 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Runtime.Seri#\3231473e2ec4451c8f218930fda80d19\System.Runtime.Serialization.Formatters.Soap.ni.dll
MOD - [2010/06/08 20:21:53 | 005,450,752 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Xml\563a54b98adb70fae862974042298348\System.Xml.ni.dll
MOD - [2010/06/08 20:20:55 | 001,587,200 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Drawing\f3440ea00eb3c40dc073b2fe03843638\System.Drawing.ni.dll
MOD - [2010/06/08 20:15:25 | 007,949,824 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System\37217abe2c5164e59aba251860f4c79e\System.ni.dll
MOD - [2009/10/15 02:21:38 | 011,486,720 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\mscorlib\7124a40b9998f7b63c86bd1a2125ce26\mscorlib.ni.dll
MOD - [2005/12/19 14:08:30 | 000,757,760 | ---- | M] () -- C:\WINDOWS\system32\bcm1xsup.dll


========== Win32 Services (SafeList) ==========

SRV - File not found [On_Demand | Stopped] -- -- (SupportSoft RemoteAssist)
SRV - File not found [Disabled | Stopped] -- -- (HidServ)
SRV - File not found [Auto | Stopped] -- -- (Automatic LiveUpdate Scheduler)
SRV - File not found [On_Demand | Stopped] -- -- (AppMgmt)
SRV - [2011/02/23 08:04:19 | 000,042,184 | ---- | M] (AVAST Software) [Auto | Running] -- C:\Program Files\AVAST Software\Avast\AvastSvc.exe -- (avast! Antivirus)
SRV - [2008/01/08 12:02:16 | 001,213,728 | ---- | M] (SupportSoft, Inc.) [Auto | Running] -- C:\Program Files\Common Files\supportsoft\bin\sprtlisten.exe -- (sprtlisten)
SRV - [2007/07/24 13:17:31 | 001,174,152 | ---- | M] (Symantec Corporation) [Auto | Running] -- C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe -- (Symantec Core LC)
SRV - [2006/08/23 15:13:28 | 000,380,928 | ---- | M] (Dell Inc.) [Auto | Running] -- C:\Program Files\Dell\QuickSet\NicConfigSvc.exe -- (NICCONFIGSVC)


========== Driver Services (SafeList) ==========

DRV - [2011/11/03 00:30:55 | 000,041,272 | ---- | M] (Malwarebytes Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\mbamswissarmy.sys -- (MBAMSwissArmy)
DRV - [2011/02/23 07:56:55 | 000,371,544 | ---- | M] (AVAST Software) [File_System | System | Running] -- C:\WINDOWS\System32\drivers\aswSnx.sys -- (aswSnx)
DRV - [2011/02/23 07:56:45 | 000,301,528 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\aswSP.sys -- (aswSP)
DRV - [2011/02/23 07:55:49 | 000,049,240 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\aswTdi.sys -- (aswTdi)
DRV - [2011/02/23 07:55:47 | 000,102,232 | ---- | M] (AVAST Software) [File_System | Auto | Running] -- C:\WINDOWS\System32\drivers\aswmon2.sys -- (aswMon2)
DRV - [2011/02/23 07:55:10 | 000,025,432 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\aswRdr.sys -- (aswRdr)
DRV - [2011/02/23 07:54:57 | 000,030,680 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\aavmker4.sys -- (Aavmker4)
DRV - [2011/02/23 07:54:55 | 000,019,544 | ---- | M] (AVAST Software) [File_System | Auto | Running] -- C:\WINDOWS\System32\drivers\aswFsBlk.sys -- (aswFsBlk)
DRV - [2006/11/14 14:41:34 | 000,010,344 | ---- | M] (Symantec Corporation) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\symlcbrd.sys -- (symlcbrd)
DRV - [2006/09/23 01:56:40 | 001,681,920 | ---- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\ati2mtag.sys -- (ati2mtag)
DRV - [2006/09/22 10:06:26 | 001,171,464 | ---- | M] (SigmaTel, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\sthda.sys -- (STHDA)
DRV - [2006/08/17 12:55:16 | 000,044,544 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\bcm4sbxp.sys -- (bcm4sbxp)
DRV - [2006/07/01 21:39:40 | 000,036,864 | ---- | M] (Advanced Micro Devices) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\AmdK8.sys -- (AmdK8)
DRV - [2006/01/10 11:07:58 | 000,004,864 | ---- | M] (GTek Technologies Ltd.) [Kernel | On_Demand | Stopped] -- C:\Program Files\Dell Support\GTAction\triggers\DSproct.sys -- (DSproct)
DRV - [2005/11/02 18:24:34 | 000,424,320 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\BCMWL5.SYS -- (BCM43XX)
DRV - [2005/08/12 16:50:46 | 000,016,128 | ---- | M] (Dell Inc) [Kernel | System | Running] -- C:\WINDOWS\SYSTEM32\DRIVERS\APPDRV.SYS -- (APPDRV)
DRV - [2005/07/14 22:58:14 | 000,028,544 | ---- | M] (REDC) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\rimmptsk.sys -- (rimmptsk)
DRV - [2004/06/09 08:29:56 | 000,006,977 | ---- | M] (Gteko Ltd.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\DDMI2.sys -- (SDDMI2)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell.com
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.google.com/ie
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.dell.com
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Page_URL = www.google.com/ig/dell?hl=en&client=dell-usuk&channel=us&ibd=4061114
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Start Page = www.google.com/ig/dell?hl=en&client=dell-usuk&channel=us&ibd=4061114

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://qwest.live.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultName = Google
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultURL = http://www.google.co...ie=utf8&oe=utf8
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = qwest.live.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 1
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = <local>

========== FireFox ==========

FF - prefs.js..browser.startup.homepage: "http://marriedtothesea.com/"
FF - prefs.js..extensions.enabledItems: {0538E3E3-7E9B-4d49-8831-A227C80A7AD3}:2.0.2
FF - prefs.js..extensions.enabledItems: [email protected]:1.0
FF - prefs.js..extensions.enabledItems: {7EC8EF17-B3B5-4943-8AF5-B91B0863BB75}:1.0
FF - prefs.js..extensions.enabledItems: {AC2F4FDB-87C1-48E6-8868-C375623AF577}:1.9.1
FF - prefs.js..extensions.enabledItems: {AB2CE124-6272-4b12-94A9-7303C7397BD1}:5.0.0.6778
FF - prefs.js..extensions.enabledItems: [email protected]:20110101
FF - prefs.js..network.proxy.http: "127.0.0.1"
FF - prefs.js..network.proxy.http_port: 56808
FF - prefs.js..network.proxy.type: 4


FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Browser Plugin,version=1.0.0: C:\Program Files\DivX\DivX Web Player\npdivx32.dll (DivX,Inc.)
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Content Upload Plugin,version=1.0.0: C:\Program Files\DivX\DivX Content Uploader\npUpload.dll (DivX,Inc.)
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Player Plugin,version=1.0.0: C:\Program Files\DivX\DivX Player\npDivxPlayerPlugin.dll (DivX, Inc)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\4.0.60129.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@movenetworks.com/Quantum Media Player: C:\Documents and Settings\Josh\Application Data\Move Networks\plugins\npqmp071503000010.dll (Move Networks)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\extensions\\{7EC8EF17-B3B5-4943-8AF5-B91B0863BB75}: C:\Documents and Settings\Matthew\Local Settings\Application Data\{7EC8EF17-B3B5-4943-8AF5-B91B0863BB75} [2009/04/22 17:01:43 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\extensions\\{AC2F4FDB-87C1-48E6-8868-C375623AF577}: C:\Documents and Settings\Josh\Local Settings\Application Data\{AC2F4FDB-87C1-48E6-8868-C375623AF577} [2009/09/23 22:35:57 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\extensions\\[email protected]: C:\Program Files\AVAST Software\Avast\WebRep\FF [2011/04/17 18:45:00 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 3.6.23\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011/10/06 22:25:52 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 3.6.23\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011/09/27 23:57:08 | 000,000,000 | ---D | M]

[2009/03/11 16:37:31 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Matthew\Application Data\Mozilla\Extensions
[2009/03/11 16:37:31 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Matthew\Application Data\Mozilla\Extensions\[email protected]
[2011/11/01 17:33:45 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Matthew\Application Data\Mozilla\Firefox\Profiles\xn4cc6wh.default\extensions
[2010/09/23 23:26:42 | 000,000,000 | ---D | M] (Forecastfox Weather) -- C:\Documents and Settings\Matthew\Application Data\Mozilla\Firefox\Profiles\xn4cc6wh.default\extensions\{0538E3E3-7E9B-4d49-8831-A227C80A7AD3}
[2009/09/04 01:19:35 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- C:\Documents and Settings\Matthew\Application Data\Mozilla\Firefox\Profiles\xn4cc6wh.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2009/07/24 03:29:49 | 000,000,000 | ---D | M] (MidnightFox) -- C:\Documents and Settings\Matthew\Application Data\Mozilla\Firefox\Profiles\xn4cc6wh.default\extensions\{66871bd1-5ba2-4739-b485-2a15f5969bd8}
[2007/05/03 01:01:30 | 000,007,431 | ---- | M] () -- C:\Documents and Settings\Matthew\Application Data\Mozilla\Firefox\Profiles\xn4cc6wh.default\searchplugins\dictionarycom.xml
[2008/06/24 01:02:01 | 000,000,908 | ---- | M] () -- C:\Documents and Settings\Matthew\Application Data\Mozilla\Firefox\Profiles\xn4cc6wh.default\searchplugins\imdb.xml
[2008/06/24 01:02:01 | 000,001,108 | ---- | M] () -- C:\Documents and Settings\Matthew\Application Data\Mozilla\Firefox\Profiles\xn4cc6wh.default\searchplugins\wikipedia-en.xml
[2008/06/02 12:57:27 | 000,001,628 | ---- | M] () -- C:\Documents and Settings\Matthew\Application Data\Mozilla\Firefox\Profiles\xn4cc6wh.default\searchplugins\youtube.xml
[2011/11/01 17:33:45 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions
[2010/11/26 19:30:41 | 000,000,000 | ---D | M] (Skype extension) -- C:\Program Files\Mozilla Firefox\extensions\{AB2CE124-6272-4b12-94A9-7303C7397BD1}
[2009/09/23 22:35:57 | 000,000,000 | ---D | M] (XULRunner) -- C:\DOCUMENTS AND SETTINGS\JOSH\LOCAL SETTINGS\APPLICATION DATA\{AC2F4FDB-87C1-48E6-8868-C375623AF577}
[2009/04/22 17:01:43 | 000,000,000 | ---D | M] (XUL Cache) -- C:\DOCUMENTS AND SETTINGS\MATTHEW\LOCAL SETTINGS\APPLICATION DATA\{7EC8EF17-B3B5-4943-8AF5-B91B0863BB75}
[2011/04/17 18:45:00 | 000,000,000 | ---D | M] (avast! WebRep) -- C:\PROGRAM FILES\AVAST SOFTWARE\AVAST\WEBREP\FF
[2009/03/11 16:31:48 | 000,000,000 | ---D | M] (Java Quick Starter) -- C:\PROGRAM FILES\JAVA\JRE6\LIB\DEPLOY\JQS\FF
[2006/01/18 12:50:00 | 000,319,488 | ---- | M] ( ) -- C:\Program Files\mozilla firefox\plugins\npsnapfish.dll

========== Chrome ==========

CHR - default_search_provider: Google ()
CHR - default_search_provider: search_url = {google:baseURL}search?{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}sourceid=chrome&ie={inputEncoding}&q={searchTerms}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?client=chrome&hl={language}&q={searchTerms}

Hosts file not found
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (avast! WebRep) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll ()
O2 - BHO: (Skype Plug-In) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O2 - BHO: (Windows Live Toolbar Helper) - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll (Microsoft Corporation)
O3 - HKLM\..\Toolbar: (avast! WebRep) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll ()
O3 - HKLM\..\Toolbar: (Windows Live Toolbar) - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll (Microsoft Corporation)
O3 - HKCU\..\Toolbar\ShellBrowser: (Windows Live Toolbar) - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll (Microsoft Corporation)
O3 - HKCU\..\Toolbar\WebBrowser: (Windows Live Toolbar) - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll (Microsoft Corporation)
O4 - HKLM..\Run: [avast] C:\Program Files\AVAST Software\Avast\avastUI.exe (AVAST Software)
O4 - HKLM..\Run: [CenturyLinkTouchPointAgent] C:\Program Files\CenturyLink\Desktop\CenturyLinkTouchPointAgent.exe (CenturyLink Inc)
O4 - HKCU..\Run: [DellSupport] C:\Program Files\Dell Support\DSAgnt.exe (Gteko Ltd.)
O4 - HKCU..\Run: [ModemOnHold] C:\Program Files\NetWaiting\netwaiting.exe ()
O4 - HKCU..\Run: [Rbexeju] rundll32.exe "C:\WINDOWS\wsecuil.dll",Startup File not found
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe (Adobe Systems Incorporated)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\GigaTribe.lnk = File not found
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE (Microsoft Corporation)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Main present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\PhishingFilter present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoControlPanel = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoControlPanel = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoWindowsUpdate = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDesktop = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableProfileQuota = 1
O8 - Extra context menu item: &Windows Live Search - C:\Program Files\Windows Live Toolbar\msntb.dll (Microsoft Corporation)
O8 - Extra context menu item: Add to Windows &Live Favorites - http://favorites.liv...m/quickadd.aspx File not found
O9 - Extra Button: Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O16 - DPF: {00000161-0000-0010-8000-00AA00389B71} http://codecs.micros...386/msaudio.cab (Reg Error: Key error.)
O16 - DPF: {31435657-9980-0010-8000-00AA00389B71} http://download.micr...78f/wvc1dmo.cab (Reg Error: Key error.)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_15)
O16 - DPF: {95D88B35-A521-472B-A182-BB1A98356421} http://asp.mathxl.co...nstallAsst2.cab (Pearson Installation Assistant 2)
O16 - DPF: {CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_15)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_15)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.m...ash/swflash.cab (Shockwave Flash Object)
O16 - DPF: {E6D23284-0E9B-417D-A782-03E4487FC947} http://asp.mathxl.co.../MathPlayer.cab (Pearson MathXL Player)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.0.1 205.171.3.25
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{07A7D238-0106-4F39-A5C7-4BE4E4E64956}: DhcpNameServer = 192.168.0.1 205.171.3.25
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{3588A12F-AE15-4D4A-86A9-26ACA9D1CCA9}: DhcpNameServer = 192.168.0.1 205.171.3.25
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O20 - HKLM Winlogon: Shell - (Explorer.exe) -C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) -C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O20 - Winlogon\Notify\AtiExtEvent: DllName - (Ati2evxx.dll) - C:\WINDOWS\System32\ati2evxx.dll (ATI Technologies Inc.)
O24 - Desktop WallPaper: C:\Documents and Settings\Matthew\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Matthew\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O28 - HKLM ShellExecuteHooks: {091EB208-39DD-417D-A5DD-7E2C2D8FB9CB} - C:\Program Files\Windows Defender\MpShHook.dll (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2004/08/10 12:04:08 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O35 - HKCU\..exefile [open] -- "%1" %*
O36 - AppCertDlls: bcmwnet - (C:\WINDOWS\system32\evenntsd.dll) - File not found
O36 - AppCertDlls: bcmwnet1 - (C:\WINDOWS\eventvdm.dll) -C:\WINDOWS\eventvdm.dll ()
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKCU\...exe [@ = exefile] -- "%1" %*

========== Files/Folders - Created Within 30 Days ==========

[2011/11/03 00:30:07 | 000,041,272 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2011/11/01 14:59:20 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\Qwest
[2011/11/01 14:59:20 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\Malwarebytes' Anti-Malware
[2011/11/01 14:56:02 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Matthew\Desktop\RK_Quarantine
[2011/10/31 00:14:16 | 000,000,000 | R--D | C] -- C:\Documents and Settings\Matthew\Recent
[2011/10/13 23:01:53 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Matthew\My Documents\cornish - matt aguayo
[2 C:\Documents and Settings\Matthew\My Documents\*.tmp files -> C:\Documents and Settings\Matthew\My Documents\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2011/11/03 00:30:55 | 000,041,272 | ---- | M] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2011/11/03 00:28:03 | 000,002,206 | -H-- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2011/11/03 00:27:06 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2011/11/03 00:27:01 | 937,521,152 | -HS- | M] () -- C:\hiberfil.sys
[2011/10/15 15:26:27 | 000,000,099 | ---- | M] () -- C:\Documents and Settings\Matthew\Desktop\fix.reg
[2 C:\Documents and Settings\Matthew\My Documents\*.tmp files -> C:\Documents and Settings\Matthew\My Documents\*.tmp -> ]

========== Files Created - No Company Name ==========

[2011/11/01 14:59:21 | 000,002,265 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Skype.lnk
[2011/11/01 14:59:21 | 000,002,155 | ---- | C] () -- C:\Documents and Settings\Matthew\Application Data\Microsoft\Internet Explorer\Quick Launch\iTunes.lnk
[2011/11/01 14:59:21 | 000,002,137 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\iTunes.lnk
[2011/11/01 14:59:21 | 000,001,689 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\avast! Free Antivirus.lnk
[2011/11/01 14:59:21 | 000,001,620 | ---- | C] () -- C:\Documents and Settings\Matthew\Application Data\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox.lnk
[2011/11/01 14:59:21 | 000,001,602 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Firefox.lnk
[2011/11/01 14:59:21 | 000,000,955 | ---- | C] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Windows Defender.lnk
[2011/11/01 14:59:21 | 000,000,793 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Security Protection.lnk
[2011/11/01 14:59:21 | 000,000,690 | ---- | C] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Windows Movie Maker.lnk
[2011/11/01 14:59:21 | 000,000,609 | ---- | C] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Windows Messenger.lnk
[2011/11/01 14:59:21 | 000,000,079 | ---- | C] () -- C:\Documents and Settings\Matthew\Application Data\Microsoft\Internet Explorer\Quick Launch\Show Desktop.scf
[2011/11/01 14:59:20 | 000,002,465 | ---- | C] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Microsoft PowerPoint.lnk
[2011/11/01 14:59:20 | 000,001,890 | ---- | C] () -- C:\Documents and Settings\All Users\Start Menu\Programs\MSN.lnk
[2011/11/01 14:59:20 | 000,001,775 | ---- | C] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Microsoft Office PowerPoint Viewer 2003.lnk
[2011/11/01 14:59:20 | 000,001,757 | ---- | C] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk
[2011/11/01 14:59:20 | 000,001,725 | ---- | C] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk
[2011/11/01 14:59:20 | 000,001,701 | ---- | C] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Microsoft Works Task Launcher.lnk
[2011/11/01 14:59:20 | 000,001,690 | ---- | C] () -- C:\Documents and Settings\All Users\Start Menu\Programs\PowerDVD.lnk
[2011/11/01 14:59:20 | 000,000,652 | ---- | C] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Startup\GigaTribe.lnk
[2011/11/01 14:59:20 | 000,000,493 | ---- | C] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Digital Line Detect.lnk
[2011/11/01 14:59:18 | 000,001,830 | ---- | C] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Apple Software Update.lnk
[2011/11/01 14:59:18 | 000,001,810 | ---- | C] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Adobe Reader 7.0.lnk
[2011/10/15 15:26:27 | 000,000,099 | ---- | C] () -- C:\Documents and Settings\Matthew\Desktop\fix.reg
[2011/10/10 01:27:02 | 937,521,152 | -HS- | C] () -- C:\hiberfil.sys
[2011/06/16 03:33:44 | 000,050,984 | ---- | C] () -- C:\Documents and Settings\Matthew\Application Data\2752.1AC
[2011/06/14 15:20:37 | 000,064,512 | ---- | C] () -- C:\WINDOWS\eventvdm.dll
[2011/06/14 15:20:02 | 000,064,512 | ---- | C] () -- C:\WINDOWS\System32\eventvdm.dll
[2011/06/03 14:25:02 | 000,000,152 | -H-- | C] () -- C:\Documents and Settings\All Users\Application Data\~16244516r
[2011/06/03 14:25:02 | 000,000,136 | -H-- | C] () -- C:\Documents and Settings\All Users\Application Data\~16244516
[2011/06/03 14:24:07 | 000,000,336 | ---- | C] () -- C:\Documents and Settings\All Users\Application Data\16244516
[2011/04/17 17:53:52 | 000,015,962 | --S- | C] () -- C:\Documents and Settings\Matthew\Local Settings\Application Data\1ro18l3y70b46o6kj0v70
[2011/04/17 17:53:52 | 000,015,962 | --S- | C] () -- C:\Documents and Settings\All Users\Application Data\1ro18l3y70b46o6kj0v70
[2011/03/06 21:20:48 | 000,015,870 | --S- | C] () -- C:\Documents and Settings\Matthew\Local Settings\Application Data\.))S](VL)0[(+
[2011/03/06 21:20:48 | 000,015,870 | --S- | C] () -- C:\Documents and Settings\All Users\Application Data\.))S](VL)0[(+
[2011/02/06 17:26:21 | 000,000,012 | ---- | C] () -- C:\Documents and Settings\Matthew\Application Data\kuhzmn.dat
[2010/11/26 19:31:48 | 000,000,056 | ---- | C] () -- C:\WINDOWS\System32\ezsidmv.dat
[2010/01/12 14:48:28 | 000,042,824 | ---- | C] () -- C:\WINDOWS\System32\mlfcache.dat
[2009/06/30 00:20:16 | 000,002,713 | --S- | C] () -- C:\WINDOWS\System32\tuzatazo.exe
[2009/06/26 12:36:48 | 000,002,713 | --S- | C] () -- C:\WINDOWS\System32\telemize.exe
[2009/06/24 21:34:35 | 000,002,713 | --S- | C] () -- C:\WINDOWS\System32\dapotado.exe
[2009/06/09 22:54:22 | 000,002,713 | --S- | C] () -- C:\WINDOWS\System32\gufipato.exe
[2009/06/08 13:31:37 | 000,000,000 | -H-- | C] () -- C:\Documents and Settings\All Users\Application Data\91142176.ini
[2009/06/04 23:33:33 | 000,001,324 | ---- | C] () -- C:\WINDOWS\System32\d3d9caps.dat
[2009/04/22 17:01:44 | 000,000,000 | ---- | C] () -- C:\WINDOWS\Thubexi.bin
[2009/04/22 17:01:40 | 000,000,120 | ---- | C] () -- C:\WINDOWS\Byazigere.dat
[2007/04/22 17:15:29 | 003,596,288 | ---- | C] () -- C:\WINDOWS\System32\qt-dx331.dll
[2007/04/22 17:01:47 | 000,012,288 | ---- | C] () -- C:\WINDOWS\System32\DivXWMPExtType.dll
[2007/02/02 13:59:03 | 000,018,494 | ---- | C] () -- C:\Documents and Settings\Matthew\Application Data\wklnhst.dat
[2007/01/24 19:28:48 | 000,071,680 | -H-- | C] () -- C:\Documents and Settings\Matthew\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2007/01/15 21:04:35 | 000,002,828 | --S- | C] () -- C:\WINDOWS\System32\KGyGaAvL.sys
[2007/01/15 21:04:35 | 000,000,088 | R-S- | C] () -- C:\WINDOWS\System32\7FD562AE33.sys
[2007/01/05 11:28:28 | 000,001,938 | ---- | C] () -- C:\WINDOWS\mozver.dat
[2006/11/27 23:41:19 | 000,001,359 | ---- | C] () -- C:\Documents and Settings\All Users\Application Data\QTSBandwidthCache
[2006/11/27 15:12:02 | 000,000,000 | ---- | C] () -- C:\WINDOWS\nsreg.dat
[2006/11/23 14:58:33 | 000,000,130 | ---- | C] () -- C:\Documents and Settings\Matthew\Local Settings\Application Data\fusioncache.dat
[2006/11/14 14:55:00 | 000,000,061 | -H-- | C] () -- C:\WINDOWS\smscfg.ini
[2006/11/14 14:38:20 | 000,000,376 | ---- | C] () -- C:\WINDOWS\ODBC.INI
[2006/11/14 14:27:50 | 000,000,004 | ---- | C] () -- C:\Documents and Settings\All Users\Application Data\QSLLPSVCShare
[2006/11/14 14:02:18 | 000,086,016 | ---- | C] () -- C:\WINDOWS\System32\preflib.dll
[2006/11/14 14:02:18 | 000,018,944 | ---- | C] () -- C:\WINDOWS\System32\WLTRYSVC.EXE
[2006/11/14 14:02:12 | 000,757,760 | ---- | C] () -- C:\WINDOWS\System32\bcm1xsup.dll
[2006/11/14 14:01:54 | 000,133,246 | ---- | C] () -- C:\WINDOWS\System32\atiicdxx.dat
[2006/11/14 14:01:52 | 000,049,152 | ---- | C] () -- C:\WINDOWS\setpwrcg.exe
[2006/11/14 14:01:50 | 000,000,390 | ---- | C] () -- C:\WINDOWS\System32\OEMINFO.INI
[2004/08/10 12:12:05 | 000,000,780 | -H-- | C] () -- C:\WINDOWS\orun32.ini
[2004/08/10 12:07:31 | 000,002,048 | --S- | C] () -- C:\WINDOWS\bootstat.dat
[2004/08/10 12:02:15 | 000,021,640 | ---- | C] () -- C:\WINDOWS\System32\emptyregdb.dat
[2004/08/10 11:57:52 | 000,004,161 | ---- | C] () -- C:\WINDOWS\ODBCINST.INI
[2004/08/10 11:57:15 | 000,219,248 | ---- | C] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2004/08/10 11:51:21 | 000,004,569 | ---- | C] () -- C:\WINDOWS\System32\secupd.dat
[2004/08/10 11:51:20 | 000,443,034 | ---- | C] () -- C:\WINDOWS\System32\perfh009.dat
[2004/08/10 11:51:20 | 000,272,128 | ---- | C] () -- C:\WINDOWS\System32\perfi009.dat
[2004/08/10 11:51:20 | 000,072,134 | ---- | C] () -- C:\WINDOWS\System32\perfc009.dat
[2004/08/10 11:51:20 | 000,028,626 | ---- | C] () -- C:\WINDOWS\System32\perfd009.dat
[2004/08/10 11:51:18 | 000,004,627 | ---- | C] () -- C:\WINDOWS\System32\oembios.dat
[2004/08/10 11:51:17 | 013,107,200 | ---- | C] () -- C:\WINDOWS\System32\oembios.bin
[2004/08/10 11:51:16 | 000,000,741 | ---- | C] () -- C:\WINDOWS\System32\noise.dat
[2004/08/10 11:51:12 | 000,673,088 | ---- | C] () -- C:\WINDOWS\System32\mlang.dat
[2004/08/10 11:51:11 | 000,046,258 | ---- | C] () -- C:\WINDOWS\System32\mib.bin
[2004/08/10 11:51:05 | 000,218,003 | ---- | C] () -- C:\WINDOWS\System32\dssec.dat
[2004/08/10 11:50:56 | 000,001,788 | ---- | C] () -- C:\WINDOWS\System32\Dcache.bin

========== LOP Check ==========

[2010/11/12 17:02:32 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Alwil Software
[2011/04/17 18:44:48 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\AVAST Software
[2011/02/24 18:37:51 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\bKnPeJc06511
[2009/07/13 12:32:55 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\butazaji
[2008/01/27 15:25:33 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\CanonBJ
[2011/10/31 02:24:14 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\CenturyLink
[2009/07/13 12:33:07 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\kapidapu
[2009/07/13 12:33:07 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\lejiwafe
[2009/07/13 12:33:18 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\narudoku
[2009/07/13 12:33:18 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\pejonavi
[2009/07/13 12:33:18 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\redivegi
[2009/07/13 12:33:18 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\rurileka
[2009/07/13 12:33:24 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\tokurepa
[2009/07/13 12:33:24 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\tomatofi
[2009/07/13 12:33:24 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\vozizowu
[2009/07/13 12:33:24 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\wepozara
[2009/07/13 12:33:24 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\woyevepa
[2007/04/16 10:19:25 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\YAHOO
[2009/12/09 00:03:50 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\{755AC846-7372-4AC8-8550-C52491DAA8BD}
[2009/07/03 14:09:58 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906}
[2011/02/08 20:54:17 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Matthew\Application Data\Aharoq
[2011/02/12 22:04:29 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Matthew\Application Data\Amtor
[2011/10/09 15:55:35 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Matthew\Application Data\Azureus
[2008/04/14 23:06:04 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Matthew\Application Data\CVS
[2011/02/12 11:51:21 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Matthew\Application Data\Evyc
[2007/08/20 11:58:04 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Matthew\Application Data\iPodSoft
[2010/11/03 00:27:41 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Matthew\Application Data\LimeWire
[2011/02/06 17:31:42 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Matthew\Application Data\Mapui
[2007/01/09 20:03:20 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Matthew\Application Data\Purple Ghost Software, Inc
[2007/05/05 22:20:15 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Matthew\Application Data\SecondLife
[2008/02/21 18:58:46 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Matthew\Application Data\Snapfish
[2008/09/28 01:43:48 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Matthew\Application Data\yoclient

========== Purity Check ==========



< End of report >

Attached Files

  • Attached File  OTL.Txt   73.05KB   88 downloads

  • 0

#6
Essexboy

Essexboy

    GeekU Moderator

  • Retired Staff
  • 69,964 posts
OK lets cure that next

Warning This fix is only relevant for this system and no other, using on another computer may cause problems

Be advised that when the fix commences it will shut down all running processes and you may lose the desktop and icons, they will return on reboot

Run OTL
  • Under the Custom Scans/Fixes box at the bottom, paste in the following

    :OTL
    [2009/09/23 22:35:57 | 000,000,000 | ---D | M] (XULRunner) -- C:\DOCUMENTS AND SETTINGS\JOSH\LOCAL SETTINGS\APPLICATION DATA\{AC2F4FDB-87C1-48E6-8868-C375623AF577}
    [2009/04/22 17:01:43 | 000,000,000 | ---D | M] (XUL Cache) -- C:\DOCUMENTS AND SETTINGS\MATTHEW\LOCAL SETTINGS\APPLICATION DATA\{7EC8EF17-B3B5-4943-8AF5-B91B0863BB75}
    FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\extensions\\{7EC8EF17-B3B5-4943-8AF5-B91B0863BB75}: C:\Documents and Settings\Matthew\Local Settings\Application Data\{7EC8EF17-B3B5-4943-8AF5-B91B0863BB75} [2009/04/22 17:01:43 | 000,000,000 | ---D | M]
    FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\extensions\\{AC2F4FDB-87C1-48E6-8868-C375623AF577}: C:\Documents and Settings\Josh\Local Settings\Application Data\{AC2F4FDB-87C1-48E6-8868-C375623AF577} [2009/09/23 22:35:57 | 000,000,000 | ---D | M]
    O4 - HKCU..\Run: [Rbexeju] rundll32.exe "C:\WINDOWS\wsecuil.dll",Startup File not found
    O36 - AppCertDlls: bcmwnet - (C:\WINDOWS\system32\evenntsd.dll) - File not found
    O36 - AppCertDlls: bcmwnet1 - (C:\WINDOWS\eventvdm.dll) -C:\WINDOWS\eventvdm.dll ()
    [2011/11/01 14:59:21 | 000,000,793 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Security Protection.lnk
    [2011/06/03 14:25:02 | 000,000,152 | -H-- | C] () -- C:\Documents and Settings\All Users\Application Data\~16244516r
    [2011/06/03 14:25:02 | 000,000,136 | -H-- | C] () -- C:\Documents and Settings\All Users\Application Data\~16244516
    [2011/06/03 14:24:07 | 000,000,336 | ---- | C] () -- C:\Documents and Settings\All Users\Application Data\16244516
    [2011/04/17 17:53:52 | 000,015,962 | --S- | C] () -- C:\Documents and Settings\Matthew\Local Settings\Application Data\1ro18l3y70b46o6kj0v70
    [2011/04/17 17:53:52 | 000,015,962 | --S- | C] () -- C:\Documents and Settings\All Users\Application Data\1ro18l3y70b46o6kj0v70
    [2011/03/06 21:20:48 | 000,015,870 | --S- | C] () -- C:\Documents and Settings\Matthew\Local Settings\Application Data\.))S](VL)0[(+
    [2011/03/06 21:20:48 | 000,015,870 | --S- | C] () -- C:\Documents and Settings\All Users\Application Data\.))S](VL)0[(+
    [2011/02/06 17:26:21 | 000,000,012 | ---- | C] () -- C:\Documents and Settings\Matthew\Application Data\kuhzmn.dat
    [2009/06/30 00:20:16 | 000,002,713 | --S- | C] () -- C:\WINDOWS\System32\tuzatazo.exe
    [2009/06/26 12:36:48 | 000,002,713 | --S- | C] () -- C:\WINDOWS\System32\telemize.exe
    [2009/06/24 21:34:35 | 000,002,713 | --S- | C] () -- C:\WINDOWS\System32\dapotado.exe
    [2009/06/09 22:54:22 | 000,002,713 | --S- | C] () -- C:\WINDOWS\System32\gufipato.exe
    [2009/06/08 13:31:37 | 000,000,000 | -H-- | C] () -- C:\Documents and Settings\All Users\Application Data\91142176.ini
    [2011/02/24 18:37:51 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\bKnPeJc06511
    [2009/07/13 12:32:55 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\butazaji
    [2008/01/27 15:25:33 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\CanonBJ
    [2011/10/31 02:24:14 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\CenturyLink
    [2009/07/13 12:33:07 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\kapidapu
    [2009/07/13 12:33:07 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\lejiwafe
    [2009/07/13 12:33:18 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\narudoku
    [2009/07/13 12:33:18 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\pejonavi
    [2009/07/13 12:33:18 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\redivegi
    [2009/07/13 12:33:18 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\rurileka
    [2009/07/13 12:33:24 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\tokurepa
    [2009/07/13 12:33:24 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\tomatofi
    [2009/07/13 12:33:24 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\vozizowu
    [2009/07/13 12:33:24 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\wepozara
    [2009/07/13 12:33:24 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\woyevepa

    :Files
    ipconfig /flushdns /c

    :Commands
    [purity]
    [resethosts]
    [emptytemp]
    [EMPTYFLASH]
    [CREATERESTOREPOINT]
    [Reboot]

  • Then click the Run Fix button at the top
  • Let the program run unhindered, reboot the PC when it is done
  • Open OTL again and click the Quick Scan button. Post the log it produces in your next reply.

THEN

Download the latest version of TDSSKiller from here and save it to your Desktop.


  • Doubleclick on TDSSKiller.exe to run the application, then click on Change parameters.

    Posted Image
  • Check the boxes beside Verify Driver Digital Signature and Detect TDLFS file system, then click OK.

    Posted Image
  • Click the Start Scan button.

    Posted Image
  • If a suspicious object is detected, the default action will be Skip, click on Continue.

    Posted Image
  • If malicious objects are found, they will show in the Scan results and offer three (3) options.
  • Ensure Cure is selected, then click Continue => Reboot now to finish the cleaning process.

    Posted Image
  • Note: If Cure is not available, please choose Skip instead, do not choose Delete unless instructed.

A report will be created in your root directory, (usually C:\ folder) in the form of "TDSSKiller.[Version]_[Date]_[Time]_log.txt". Please copy and paste its contents on your next reply.
  • 0

#7
Boomrad

Boomrad

    Member

  • Topic Starter
  • Member
  • PipPip
  • 17 posts
Awesome! This seems to have taken care of the rootkits Avast had been finding. I'm still getting a security recommendation and being disconnected from any network about 4 seconds after login, manually restoring... Thank you, you're fantastic!


OTL logfile created on: 11/5/2011 11:45:27 PM - Run 4
OTL by OldTimer - Version 3.2.31.0 Folder = C:\Documents and Settings\Matthew\My Documents\Downloads
Windows XP Home Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 6.0.2900.2180)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

894.04 Mb Total Physical Memory | 498.11 Mb Available Physical Memory | 55.71% Memory free
2.12 Gb Paging File | 1.79 Gb Available in Paging File | 84.70% Paging File free
Paging file location(s): C:\pagefile.sys 1344 2688 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 52.21 Gb Total Space | 0.07 Gb Free Space | 0.13% Space Free | Partition Type: NTFS

Computer Name: DH9QL3C1 | User Name: Matthew | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - [2011/10/31 00:46:33 | 000,584,192 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Matthew\My Documents\Downloads\OTL.scr
PRC - [2011/07/12 15:18:35 | 000,046,208 | ---- | M] (CenturyLink Inc) -- C:\Program Files\CenturyLink\Desktop\CenturyLinkTouchPointAgent.exe
PRC - [2011/02/23 08:08:04 | 003,250,664 | ---- | M] (AVAST Software) -- C:\Program Files\AVAST Software\Avast\Setup\avast.setup
PRC - [2011/02/23 08:04:20 | 003,451,496 | ---- | M] (AVAST Software) -- C:\Program Files\AVAST Software\Avast\AvastUI.exe
PRC - [2011/02/23 08:04:19 | 000,042,184 | ---- | M] (AVAST Software) -- C:\Program Files\AVAST Software\Avast\AvastSvc.exe
PRC - [2008/01/08 12:02:16 | 001,213,728 | ---- | M] (SupportSoft, Inc.) -- C:\Program Files\Common Files\supportsoft\bin\sprtlisten.exe
PRC - [2007/07/24 13:17:31 | 001,174,152 | ---- | M] (Symantec Corporation) -- C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
PRC - [2007/06/13 03:23:07 | 001,033,216 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe
PRC - [2006/08/23 15:13:28 | 000,380,928 | ---- | M] (Dell Inc.) -- C:\Program Files\Dell\QuickSet\NicConfigSvc.exe
PRC - [2006/07/16 20:29:54 | 000,389,120 | ---- | M] (Gteko Ltd.) -- C:\Program Files\Dell Support\DSAgnt.exe
PRC - [2005/09/23 21:05:26 | 000,029,696 | ---- | M] (Adobe Systems Incorporated) -- C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe


========== Modules (No Company Name) ==========

MOD - [2011/06/14 15:20:37 | 000,064,512 | ---- | M] () -- C:\WINDOWS\eventvdm.dll
MOD - [2011/02/24 02:55:49 | 000,844,288 | ---- | M] () -- C:\Program Files\AVAST Software\Avast\defs\11022400\algo.dll
MOD - [2011/02/23 08:07:19 | 000,190,000 | ---- | M] () -- C:\Program Files\AVAST Software\Avast\Setup\setiface.dll
MOD - [2011/02/23 08:04:14 | 000,144,672 | ---- | M] () -- C:\Program Files\AVAST Software\Avast\aswDld.dll
MOD - [2010/06/11 18:48:36 | 000,971,264 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Configuration\631b3eba1ba5bd3c3f027f34011cadeb\System.Configuration.ni.dll
MOD - [2010/06/11 18:15:22 | 012,430,848 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\2dfe045e4b1577fdea9a2f456db0afc2\System.Windows.Forms.ni.dll
MOD - [2010/06/08 20:37:37 | 001,840,640 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Web.Services\8ef8d556899a4a10b7f288a80925489f\System.Web.Services.ni.dll
MOD - [2010/06/08 20:34:45 | 000,998,400 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Management\16670b6870746e5a8dc4a73a76a90bed\System.Management.ni.dll
MOD - [2010/06/08 20:34:42 | 000,311,296 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Runtime.Seri#\3231473e2ec4451c8f218930fda80d19\System.Runtime.Serialization.Formatters.Soap.ni.dll
MOD - [2010/06/08 20:21:53 | 005,450,752 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Xml\563a54b98adb70fae862974042298348\System.Xml.ni.dll
MOD - [2010/06/08 20:20:55 | 001,587,200 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Drawing\f3440ea00eb3c40dc073b2fe03843638\System.Drawing.ni.dll
MOD - [2010/06/08 20:15:25 | 007,949,824 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System\37217abe2c5164e59aba251860f4c79e\System.ni.dll
MOD - [2009/10/15 02:21:38 | 011,486,720 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\mscorlib\7124a40b9998f7b63c86bd1a2125ce26\mscorlib.ni.dll
MOD - [2005/12/19 14:08:30 | 000,757,760 | ---- | M] () -- C:\WINDOWS\system32\bcm1xsup.dll
MOD - [2004/08/04 04:00:00 | 000,059,904 | ---- | M] () -- C:\WINDOWS\system32\devenum.dll
MOD - [2004/08/04 04:00:00 | 000,014,336 | ---- | M] () -- C:\WINDOWS\system32\msdmo.dll


========== Win32 Services (SafeList) ==========

SRV - File not found [On_Demand | Stopped] -- -- (SupportSoft RemoteAssist)
SRV - File not found [Disabled | Stopped] -- -- (HidServ)
SRV - File not found [Auto | Stopped] -- -- (Automatic LiveUpdate Scheduler)
SRV - File not found [On_Demand | Stopped] -- -- (AppMgmt)
SRV - [2011/02/23 08:04:19 | 000,042,184 | ---- | M] (AVAST Software) [Auto | Running] -- C:\Program Files\AVAST Software\Avast\AvastSvc.exe -- (avast! Antivirus)
SRV - [2008/01/08 12:02:16 | 001,213,728 | ---- | M] (SupportSoft, Inc.) [Auto | Running] -- C:\Program Files\Common Files\supportsoft\bin\sprtlisten.exe -- (sprtlisten)
SRV - [2007/07/24 13:17:31 | 001,174,152 | ---- | M] (Symantec Corporation) [Auto | Running] -- C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe -- (Symantec Core LC)
SRV - [2006/08/23 15:13:28 | 000,380,928 | ---- | M] (Dell Inc.) [Auto | Running] -- C:\Program Files\Dell\QuickSet\NicConfigSvc.exe -- (NICCONFIGSVC)


========== Driver Services (SafeList) ==========

DRV - [2011/02/23 07:56:55 | 000,371,544 | ---- | M] (AVAST Software) [File_System | System | Running] -- C:\WINDOWS\System32\drivers\aswSnx.sys -- (aswSnx)
DRV - [2011/02/23 07:56:45 | 000,301,528 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\aswSP.sys -- (aswSP)
DRV - [2011/02/23 07:55:49 | 000,049,240 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\aswTdi.sys -- (aswTdi)
DRV - [2011/02/23 07:55:47 | 000,102,232 | ---- | M] (AVAST Software) [File_System | Auto | Running] -- C:\WINDOWS\System32\drivers\aswmon2.sys -- (aswMon2)
DRV - [2011/02/23 07:55:10 | 000,025,432 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\aswRdr.sys -- (aswRdr)
DRV - [2011/02/23 07:54:57 | 000,030,680 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\aavmker4.sys -- (Aavmker4)
DRV - [2011/02/23 07:54:55 | 000,019,544 | ---- | M] (AVAST Software) [File_System | Auto | Running] -- C:\WINDOWS\System32\drivers\aswFsBlk.sys -- (aswFsBlk)
DRV - [2006/11/14 14:41:34 | 000,010,344 | ---- | M] (Symantec Corporation) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\symlcbrd.sys -- (symlcbrd)
DRV - [2006/09/23 01:56:40 | 001,681,920 | ---- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\ati2mtag.sys -- (ati2mtag)
DRV - [2006/09/22 10:06:26 | 001,171,464 | ---- | M] (SigmaTel, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\sthda.sys -- (STHDA)
DRV - [2006/08/17 12:55:16 | 000,044,544 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\bcm4sbxp.sys -- (bcm4sbxp)
DRV - [2006/07/01 21:39:40 | 000,036,864 | ---- | M] (Advanced Micro Devices) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\AmdK8.sys -- (AmdK8)
DRV - [2006/01/10 11:07:58 | 000,004,864 | ---- | M] (GTek Technologies Ltd.) [Kernel | On_Demand | Stopped] -- C:\Program Files\Dell Support\GTAction\triggers\DSproct.sys -- (DSproct)
DRV - [2005/11/02 18:24:34 | 000,424,320 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\BCMWL5.SYS -- (BCM43XX)
DRV - [2005/08/12 16:50:46 | 000,016,128 | ---- | M] (Dell Inc) [Kernel | System | Running] -- C:\WINDOWS\SYSTEM32\DRIVERS\APPDRV.SYS -- (APPDRV)
DRV - [2005/07/14 22:58:14 | 000,028,544 | ---- | M] (REDC) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\rimmptsk.sys -- (rimmptsk)
DRV - [2004/06/09 08:29:56 | 000,006,977 | ---- | M] (Gteko Ltd.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\DDMI2.sys -- (SDDMI2)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell.com
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.google.com/ie
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.dell.com
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Page_URL = www.google.com/ig/dell?hl=en&client=dell-usuk&channel=us&ibd=4061114
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Start Page = www.google.com/ig/dell?hl=en&client=dell-usuk&channel=us&ibd=4061114

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://qwest.live.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultName = Google
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultURL = http://www.google.co...ie=utf8&oe=utf8
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = qwest.live.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 1
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = <local>

========== FireFox ==========

FF - prefs.js..browser.startup.homepage: "http://marriedtothesea.com/"
FF - prefs.js..extensions.enabledItems: {0538E3E3-7E9B-4d49-8831-A227C80A7AD3}:2.0.2
FF - prefs.js..extensions.enabledItems: [email protected]:1.0
FF - prefs.js..extensions.enabledItems: {7EC8EF17-B3B5-4943-8AF5-B91B0863BB75}:1.0
FF - prefs.js..extensions.enabledItems: {AC2F4FDB-87C1-48E6-8868-C375623AF577}:1.9.1
FF - prefs.js..extensions.enabledItems: {AB2CE124-6272-4b12-94A9-7303C7397BD1}:5.0.0.6778
FF - prefs.js..extensions.enabledItems: [email protected]:20110101
FF - prefs.js..network.proxy.http: "127.0.0.1"
FF - prefs.js..network.proxy.http_port: 56808
FF - prefs.js..network.proxy.type: 4


FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Browser Plugin,version=1.0.0: C:\Program Files\DivX\DivX Web Player\npdivx32.dll (DivX,Inc.)
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Content Upload Plugin,version=1.0.0: C:\Program Files\DivX\DivX Content Uploader\npUpload.dll (DivX,Inc.)
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Player Plugin,version=1.0.0: C:\Program Files\DivX\DivX Player\npDivxPlayerPlugin.dll (DivX, Inc)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\4.0.60129.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@movenetworks.com/Quantum Media Player: C:\Documents and Settings\Josh\Application Data\Move Networks\plugins\npqmp071503000010.dll (Move Networks)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\extensions\\{7EC8EF17-B3B5-4943-8AF5-B91B0863BB75}: C:\Documents and Settings\Matthew\Local Settings\Application Data\{7EC8EF17-B3B5-4943-8AF5-B91B0863BB75} [2009/04/22 17:01:43 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\extensions\\{AC2F4FDB-87C1-48E6-8868-C375623AF577}: C:\Documents and Settings\Josh\Local Settings\Application Data\{AC2F4FDB-87C1-48E6-8868-C375623AF577} [2009/09/23 22:35:57 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\extensions\\[email protected]: C:\Program Files\AVAST Software\Avast\WebRep\FF [2011/04/17 18:45:00 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 3.6.23\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011/10/06 22:25:52 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 3.6.23\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011/09/27 23:57:08 | 000,000,000 | ---D | M]

[2009/03/11 16:37:31 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Matthew\Application Data\Mozilla\Extensions
[2009/03/11 16:37:31 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Matthew\Application Data\Mozilla\Extensions\[email protected]
[2011/11/05 02:38:01 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Matthew\Application Data\Mozilla\Firefox\Profiles\xn4cc6wh.default\extensions
[2010/09/23 23:26:42 | 000,000,000 | ---D | M] (Forecastfox Weather) -- C:\Documents and Settings\Matthew\Application Data\Mozilla\Firefox\Profiles\xn4cc6wh.default\extensions\{0538E3E3-7E9B-4d49-8831-A227C80A7AD3}
[2009/09/04 01:19:35 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- C:\Documents and Settings\Matthew\Application Data\Mozilla\Firefox\Profiles\xn4cc6wh.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2009/07/24 03:29:49 | 000,000,000 | ---D | M] (MidnightFox) -- C:\Documents and Settings\Matthew\Application Data\Mozilla\Firefox\Profiles\xn4cc6wh.default\extensions\{66871bd1-5ba2-4739-b485-2a15f5969bd8}
[2007/05/03 01:01:30 | 000,007,431 | ---- | M] () -- C:\Documents and Settings\Matthew\Application Data\Mozilla\Firefox\Profiles\xn4cc6wh.default\searchplugins\dictionarycom.xml
[2008/06/24 01:02:01 | 000,000,908 | ---- | M] () -- C:\Documents and Settings\Matthew\Application Data\Mozilla\Firefox\Profiles\xn4cc6wh.default\searchplugins\imdb.xml
[2008/06/24 01:02:01 | 000,001,108 | ---- | M] () -- C:\Documents and Settings\Matthew\Application Data\Mozilla\Firefox\Profiles\xn4cc6wh.default\searchplugins\wikipedia-en.xml
[2008/06/02 12:57:27 | 000,001,628 | ---- | M] () -- C:\Documents and Settings\Matthew\Application Data\Mozilla\Firefox\Profiles\xn4cc6wh.default\searchplugins\youtube.xml
[2011/11/05 02:38:01 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions
[2010/11/26 19:30:41 | 000,000,000 | ---D | M] (Skype extension) -- C:\Program Files\Mozilla Firefox\extensions\{AB2CE124-6272-4b12-94A9-7303C7397BD1}
[2009/09/23 22:35:57 | 000,000,000 | ---D | M] (XULRunner) -- C:\DOCUMENTS AND SETTINGS\JOSH\LOCAL SETTINGS\APPLICATION DATA\{AC2F4FDB-87C1-48E6-8868-C375623AF577}
[2009/04/22 17:01:43 | 000,000,000 | ---D | M] (XUL Cache) -- C:\DOCUMENTS AND SETTINGS\MATTHEW\LOCAL SETTINGS\APPLICATION DATA\{7EC8EF17-B3B5-4943-8AF5-B91B0863BB75}
[2011/04/17 18:45:00 | 000,000,000 | ---D | M] (avast! WebRep) -- C:\PROGRAM FILES\AVAST SOFTWARE\AVAST\WEBREP\FF
[2009/03/11 16:31:48 | 000,000,000 | ---D | M] (Java Quick Starter) -- C:\PROGRAM FILES\JAVA\JRE6\LIB\DEPLOY\JQS\FF
[2006/01/18 12:50:00 | 000,319,488 | ---- | M] ( ) -- C:\Program Files\mozilla firefox\plugins\npsnapfish.dll

========== Chrome ==========

CHR - default_search_provider: Google ()
CHR - default_search_provider: search_url = {google:baseURL}search?{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}sourceid=chrome&ie={inputEncoding}&q={searchTerms}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?client=chrome&hl={language}&q={searchTerms}

Hosts file not found
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (avast! WebRep) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll ()
O2 - BHO: (Skype Plug-In) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O2 - BHO: (Windows Live Toolbar Helper) - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll (Microsoft Corporation)
O3 - HKLM\..\Toolbar: (avast! WebRep) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll ()
O3 - HKLM\..\Toolbar: (Windows Live Toolbar) - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll (Microsoft Corporation)
O3 - HKCU\..\Toolbar\ShellBrowser: (Windows Live Toolbar) - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll (Microsoft Corporation)
O3 - HKCU\..\Toolbar\WebBrowser: (Windows Live Toolbar) - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll (Microsoft Corporation)
O4 - HKLM..\Run: [avast] C:\Program Files\AVAST Software\Avast\avastUI.exe (AVAST Software)
O4 - HKLM..\Run: [CenturyLinkTouchPointAgent] C:\Program Files\CenturyLink\Desktop\CenturyLinkTouchPointAgent.exe (CenturyLink Inc)
O4 - HKCU..\Run: [DellSupport] C:\Program Files\Dell Support\DSAgnt.exe (Gteko Ltd.)
O4 - HKCU..\Run: [ModemOnHold] C:\Program Files\NetWaiting\netwaiting.exe ()
O4 - HKCU..\Run: [Rbexeju] rundll32.exe "C:\WINDOWS\wsecuil.dll",Startup File not found
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe (Adobe Systems Incorporated)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\GigaTribe.lnk = File not found
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE (Microsoft Corporation)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Main present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\PhishingFilter present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoControlPanel = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoControlPanel = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoWindowsUpdate = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDesktop = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableProfileQuota = 1
O8 - Extra context menu item: &Windows Live Search - C:\Program Files\Windows Live Toolbar\msntb.dll (Microsoft Corporation)
O8 - Extra context menu item: Add to Windows &Live Favorites - http://favorites.liv...m/quickadd.aspx File not found
O9 - Extra Button: Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O16 - DPF: {00000161-0000-0010-8000-00AA00389B71} http://codecs.micros...386/msaudio.cab (Reg Error: Key error.)
O16 - DPF: {31435657-9980-0010-8000-00AA00389B71} http://download.micr...78f/wvc1dmo.cab (Reg Error: Key error.)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_15)
O16 - DPF: {95D88B35-A521-472B-A182-BB1A98356421} http://asp.mathxl.co...nstallAsst2.cab (Pearson Installation Assistant 2)
O16 - DPF: {CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_15)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_15)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.m...ash/swflash.cab (Shockwave Flash Object)
O16 - DPF: {E6D23284-0E9B-417D-A782-03E4487FC947} http://asp.mathxl.co.../MathPlayer.cab (Pearson MathXL Player)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.0.1 205.171.3.25
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{07A7D238-0106-4F39-A5C7-4BE4E4E64956}: DhcpNameServer = 192.168.0.1 205.171.3.25
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{3588A12F-AE15-4D4A-86A9-26ACA9D1CCA9}: DhcpNameServer = 192.168.0.1 205.171.3.25
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O20 - HKLM Winlogon: Shell - (Explorer.exe) -C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) -C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O20 - Winlogon\Notify\AtiExtEvent: DllName - (Ati2evxx.dll) - C:\WINDOWS\System32\ati2evxx.dll (ATI Technologies Inc.)
O24 - Desktop WallPaper: C:\Documents and Settings\Matthew\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Matthew\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O28 - HKLM ShellExecuteHooks: {091EB208-39DD-417D-A5DD-7E2C2D8FB9CB} - C:\Program Files\Windows Defender\MpShHook.dll (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2004/08/10 12:04:08 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O35 - HKCU\..exefile [open] -- "%1" %*
O36 - AppCertDlls: bcmwnet - (C:\WINDOWS\system32\evenntsd.dll) - File not found
O36 - AppCertDlls: bcmwnet1 - (C:\WINDOWS\eventvdm.dll) -C:\WINDOWS\eventvdm.dll ()
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKCU\...exe [@ = exefile] -- "%1" %*

========== Files/Folders - Created Within 30 Days ==========

[2011/11/01 14:59:20 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\Qwest
[2011/11/01 14:59:20 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\Malwarebytes' Anti-Malware
[2011/11/01 14:56:02 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Matthew\Desktop\RK_Quarantine
[2011/10/31 00:14:16 | 000,000,000 | R--D | C] -- C:\Documents and Settings\Matthew\Recent
[2011/10/13 23:01:53 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Matthew\My Documents\cornish - matt aguayo
[2 C:\Documents and Settings\Matthew\My Documents\*.tmp files -> C:\Documents and Settings\Matthew\My Documents\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2011/11/05 23:43:31 | 000,002,206 | -H-- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2011/11/05 23:42:15 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2011/11/05 23:42:11 | 937,537,536 | -HS- | M] () -- C:\hiberfil.sys
[2011/10/15 15:26:27 | 000,000,099 | ---- | M] () -- C:\Documents and Settings\Matthew\Desktop\fix.reg
[2 C:\Documents and Settings\Matthew\My Documents\*.tmp files -> C:\Documents and Settings\Matthew\My Documents\*.tmp -> ]

========== Files Created - No Company Name ==========

[2011/11/01 14:59:21 | 000,002,265 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Skype.lnk
[2011/11/01 14:59:21 | 000,002,155 | ---- | C] () -- C:\Documents and Settings\Matthew\Application Data\Microsoft\Internet Explorer\Quick Launch\iTunes.lnk
[2011/11/01 14:59:21 | 000,002,137 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\iTunes.lnk
[2011/11/01 14:59:21 | 000,001,689 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\avast! Free Antivirus.lnk
[2011/11/01 14:59:21 | 000,001,620 | ---- | C] () -- C:\Documents and Settings\Matthew\Application Data\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox.lnk
[2011/11/01 14:59:21 | 000,001,602 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Firefox.lnk
[2011/11/01 14:59:21 | 000,000,955 | ---- | C] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Windows Defender.lnk
[2011/11/01 14:59:21 | 000,000,793 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Security Protection.lnk
[2011/11/01 14:59:21 | 000,000,690 | ---- | C] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Windows Movie Maker.lnk
[2011/11/01 14:59:21 | 000,000,609 | ---- | C] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Windows Messenger.lnk
[2011/11/01 14:59:21 | 000,000,079 | ---- | C] () -- C:\Documents and Settings\Matthew\Application Data\Microsoft\Internet Explorer\Quick Launch\Show Desktop.scf
[2011/11/01 14:59:20 | 000,002,465 | ---- | C] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Microsoft PowerPoint.lnk
[2011/11/01 14:59:20 | 000,001,890 | ---- | C] () -- C:\Documents and Settings\All Users\Start Menu\Programs\MSN.lnk
[2011/11/01 14:59:20 | 000,001,775 | ---- | C] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Microsoft Office PowerPoint Viewer 2003.lnk
[2011/11/01 14:59:20 | 000,001,757 | ---- | C] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk
[2011/11/01 14:59:20 | 000,001,725 | ---- | C] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk
[2011/11/01 14:59:20 | 000,001,701 | ---- | C] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Microsoft Works Task Launcher.lnk
[2011/11/01 14:59:20 | 000,001,690 | ---- | C] () -- C:\Documents and Settings\All Users\Start Menu\Programs\PowerDVD.lnk
[2011/11/01 14:59:20 | 000,000,652 | ---- | C] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Startup\GigaTribe.lnk
[2011/11/01 14:59:20 | 000,000,493 | ---- | C] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Digital Line Detect.lnk
[2011/11/01 14:59:18 | 000,001,830 | ---- | C] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Apple Software Update.lnk
[2011/11/01 14:59:18 | 000,001,810 | ---- | C] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Adobe Reader 7.0.lnk
[2011/10/15 15:26:27 | 000,000,099 | ---- | C] () -- C:\Documents and Settings\Matthew\Desktop\fix.reg
[2011/10/10 01:27:02 | 937,537,536 | -HS- | C] () -- C:\hiberfil.sys
[2011/06/16 03:33:44 | 000,050,984 | ---- | C] () -- C:\Documents and Settings\Matthew\Application Data\2752.1AC
[2011/06/14 15:20:37 | 000,064,512 | ---- | C] () -- C:\WINDOWS\eventvdm.dll
[2011/06/14 15:20:02 | 000,064,512 | ---- | C] () -- C:\WINDOWS\System32\eventvdm.dll
[2011/06/03 14:25:02 | 000,000,152 | -H-- | C] () -- C:\Documents and Settings\All Users\Application Data\~16244516r
[2011/06/03 14:25:02 | 000,000,136 | -H-- | C] () -- C:\Documents and Settings\All Users\Application Data\~16244516
[2011/06/03 14:24:07 | 000,000,336 | ---- | C] () -- C:\Documents and Settings\All Users\Application Data\16244516
[2011/04/17 17:53:52 | 000,015,962 | --S- | C] () -- C:\Documents and Settings\Matthew\Local Settings\Application Data\1ro18l3y70b46o6kj0v70
[2011/04/17 17:53:52 | 000,015,962 | --S- | C] () -- C:\Documents and Settings\All Users\Application Data\1ro18l3y70b46o6kj0v70
[2011/03/06 21:20:48 | 000,015,870 | --S- | C] () -- C:\Documents and Settings\Matthew\Local Settings\Application Data\.))S](VL)0[(+
[2011/03/06 21:20:48 | 000,015,870 | --S- | C] () -- C:\Documents and Settings\All Users\Application Data\.))S](VL)0[(+
[2011/02/06 17:26:21 | 000,000,012 | ---- | C] () -- C:\Documents and Settings\Matthew\Application Data\kuhzmn.dat
[2010/11/26 19:31:48 | 000,000,056 | ---- | C] () -- C:\WINDOWS\System32\ezsidmv.dat
[2010/01/12 14:48:28 | 000,042,824 | ---- | C] () -- C:\WINDOWS\System32\mlfcache.dat
[2009/06/30 00:20:16 | 000,002,713 | --S- | C] () -- C:\WINDOWS\System32\tuzatazo.exe
[2009/06/26 12:36:48 | 000,002,713 | --S- | C] () -- C:\WINDOWS\System32\telemize.exe
[2009/06/24 21:34:35 | 000,002,713 | --S- | C] () -- C:\WINDOWS\System32\dapotado.exe
[2009/06/09 22:54:22 | 000,002,713 | --S- | C] () -- C:\WINDOWS\System32\gufipato.exe
[2009/06/08 13:31:37 | 000,000,000 | -H-- | C] () -- C:\Documents and Settings\All Users\Application Data\91142176.ini
[2009/06/04 23:33:33 | 000,001,324 | ---- | C] () -- C:\WINDOWS\System32\d3d9caps.dat
[2009/04/22 17:01:44 | 000,000,000 | ---- | C] () -- C:\WINDOWS\Thubexi.bin
[2009/04/22 17:01:40 | 000,000,120 | ---- | C] () -- C:\WINDOWS\Byazigere.dat
[2007/04/22 17:15:29 | 003,596,288 | ---- | C] () -- C:\WINDOWS\System32\qt-dx331.dll
[2007/04/22 17:01:47 | 000,012,288 | ---- | C] () -- C:\WINDOWS\System32\DivXWMPExtType.dll
[2007/02/02 13:59:03 | 000,018,494 | ---- | C] () -- C:\Documents and Settings\Matthew\Application Data\wklnhst.dat
[2007/01/24 19:28:48 | 000,071,680 | -H-- | C] () -- C:\Documents and Settings\Matthew\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2007/01/15 21:04:35 | 000,002,828 | --S- | C] () -- C:\WINDOWS\System32\KGyGaAvL.sys
[2007/01/15 21:04:35 | 000,000,088 | R-S- | C] () -- C:\WINDOWS\System32\7FD562AE33.sys
[2007/01/05 11:28:28 | 000,001,938 | ---- | C] () -- C:\WINDOWS\mozver.dat
[2006/11/27 23:41:19 | 000,001,359 | ---- | C] () -- C:\Documents and Settings\All Users\Application Data\QTSBandwidthCache
[2006/11/27 15:12:02 | 000,000,000 | ---- | C] () -- C:\WINDOWS\nsreg.dat
[2006/11/23 14:58:33 | 000,000,130 | ---- | C] () -- C:\Documents and Settings\Matthew\Local Settings\Application Data\fusioncache.dat
[2006/11/14 14:55:00 | 000,000,061 | -H-- | C] () -- C:\WINDOWS\smscfg.ini
[2006/11/14 14:38:20 | 000,000,376 | ---- | C] () -- C:\WINDOWS\ODBC.INI
[2006/11/14 14:27:50 | 000,000,004 | ---- | C] () -- C:\Documents and Settings\All Users\Application Data\QSLLPSVCShare
[2006/11/14 14:02:18 | 000,086,016 | ---- | C] () -- C:\WINDOWS\System32\preflib.dll
[2006/11/14 14:02:18 | 000,018,944 | ---- | C] () -- C:\WINDOWS\System32\WLTRYSVC.EXE
[2006/11/14 14:02:12 | 000,757,760 | ---- | C] () -- C:\WINDOWS\System32\bcm1xsup.dll
[2006/11/14 14:01:54 | 000,133,246 | ---- | C] () -- C:\WINDOWS\System32\atiicdxx.dat
[2006/11/14 14:01:52 | 000,049,152 | ---- | C] () -- C:\WINDOWS\setpwrcg.exe
[2006/11/14 14:01:50 | 000,000,390 | ---- | C] () -- C:\WINDOWS\System32\OEMINFO.INI
[2004/08/10 12:12:05 | 000,000,780 | -H-- | C] () -- C:\WINDOWS\orun32.ini
[2004/08/10 12:07:31 | 000,002,048 | --S- | C] () -- C:\WINDOWS\bootstat.dat
[2004/08/10 12:02:15 | 000,021,640 | ---- | C] () -- C:\WINDOWS\System32\emptyregdb.dat
[2004/08/10 11:57:52 | 000,004,161 | ---- | C] () -- C:\WINDOWS\ODBCINST.INI
[2004/08/10 11:57:15 | 000,219,248 | ---- | C] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2004/08/10 11:51:21 | 000,004,569 | ---- | C] () -- C:\WINDOWS\System32\secupd.dat
[2004/08/10 11:51:20 | 000,443,034 | ---- | C] () -- C:\WINDOWS\System32\perfh009.dat
[2004/08/10 11:51:20 | 000,272,128 | ---- | C] () -- C:\WINDOWS\System32\perfi009.dat
[2004/08/10 11:51:20 | 000,072,134 | ---- | C] () -- C:\WINDOWS\System32\perfc009.dat
[2004/08/10 11:51:20 | 000,028,626 | ---- | C] () -- C:\WINDOWS\System32\perfd009.dat
[2004/08/10 11:51:18 | 000,004,627 | ---- | C] () -- C:\WINDOWS\System32\oembios.dat
[2004/08/10 11:51:17 | 013,107,200 | ---- | C] () -- C:\WINDOWS\System32\oembios.bin
[2004/08/10 11:51:16 | 000,000,741 | ---- | C] () -- C:\WINDOWS\System32\noise.dat
[2004/08/10 11:51:12 | 000,673,088 | ---- | C] () -- C:\WINDOWS\System32\mlang.dat
[2004/08/10 11:51:11 | 000,046,258 | ---- | C] () -- C:\WINDOWS\System32\mib.bin
[2004/08/10 11:51:05 | 000,218,003 | ---- | C] () -- C:\WINDOWS\System32\dssec.dat
[2004/08/10 11:50:56 | 000,001,788 | ---- | C] () -- C:\WINDOWS\System32\Dcache.bin

========== LOP Check ==========

[2010/11/12 17:02:32 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Alwil Software
[2011/04/17 18:44:48 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\AVAST Software
[2011/02/24 18:37:51 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\bKnPeJc06511
[2009/07/13 12:32:55 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\butazaji
[2008/01/27 15:25:33 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\CanonBJ
[2011/10/31 02:24:14 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\CenturyLink
[2009/07/13 12:33:07 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\kapidapu
[2009/07/13 12:33:07 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\lejiwafe
[2009/07/13 12:33:18 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\narudoku
[2009/07/13 12:33:18 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\pejonavi
[2009/07/13 12:33:18 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\redivegi
[2009/07/13 12:33:18 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\rurileka
[2009/07/13 12:33:24 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\tokurepa
[2009/07/13 12:33:24 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\tomatofi
[2009/07/13 12:33:24 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\vozizowu
[2009/07/13 12:33:24 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\wepozara
[2009/07/13 12:33:24 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\woyevepa
[2007/04/16 10:19:25 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\YAHOO
[2009/12/09 00:03:50 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\{755AC846-7372-4AC8-8550-C52491DAA8BD}
[2009/07/03 14:09:58 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906}
[2011/02/08 20:54:17 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Matthew\Application Data\Aharoq
[2011/02/12 22:04:29 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Matthew\Application Data\Amtor
[2011/10/09 15:55:35 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Matthew\Application Data\Azureus
[2008/04/14 23:06:04 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Matthew\Application Data\CVS
[2011/02/12 11:51:21 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Matthew\Application Data\Evyc
[2007/08/20 11:58:04 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Matthew\Application Data\iPodSoft
[2010/11/03 00:27:41 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Matthew\Application Data\LimeWire
[2011/02/06 17:31:42 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Matthew\Application Data\Mapui
[2007/01/09 20:03:20 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Matthew\Application Data\Purple Ghost Software, Inc
[2007/05/05 22:20:15 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Matthew\Application Data\SecondLife
[2008/02/21 18:58:46 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Matthew\Application Data\Snapfish
[2008/09/28 01:43:48 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Matthew\Application Data\yoclient

========== Purity Check ==========



< End of report >




02:21:32.0687 2684 TDSS rootkit removing tool 2.6.15.0 Nov 3 2011 17:15:49
02:21:33.0156 2684 ============================================================
02:21:33.0156 2684 Current date / time: 2011/11/05 02:21:33.0156
02:21:33.0156 2684 SystemInfo:
02:21:33.0156 2684
02:21:33.0156 2684 OS Version: 5.1.2600 ServicePack: 2.0
02:21:33.0156 2684 Product type: Workstation
02:21:33.0156 2684 ComputerName: DH9QL3C1
02:21:33.0156 2684 UserName: Matthew
02:21:33.0156 2684 Windows directory: C:\WINDOWS
02:21:33.0156 2684 System windows directory: C:\WINDOWS
02:21:33.0156 2684 Processor architecture: Intel x86
02:21:33.0156 2684 Number of processors: 1
02:21:33.0156 2684 Page size: 0x1000
02:21:33.0156 2684 Boot type: Normal boot
02:21:33.0156 2684 ============================================================
02:21:33.0218 2684 Initialize success
02:22:07.0203 3236 ============================================================
02:22:07.0203 3236 Scan started
02:22:07.0203 3236 Mode: Manual; SigCheck; TDLFS;
02:22:07.0203 3236 ============================================================
02:22:07.0953 3236 Aavmker4 (83631291adf2887cffc786d034d3fa15) C:\WINDOWS\system32\drivers\Aavmker4.sys
02:22:08.0171 3236 Aavmker4 - ok
02:22:08.0203 3236 Abiosdsk - ok
02:22:08.0250 3236 abp480n5 (6abb91494fe6c59089b9336452ab2ea3) C:\WINDOWS\system32\DRIVERS\ABP480N5.SYS
02:22:08.0953 3236 abp480n5 - ok
02:22:09.0312 3236 ACPI (a10c7534f7223f4a73a948967d00e69b) C:\WINDOWS\system32\DRIVERS\ACPI.sys
02:22:09.0671 3236 ACPI - ok
02:22:09.0875 3236 ACPIEC (9859c0f6936e723e4892d7141b1327d5) C:\WINDOWS\system32\DRIVERS\ACPIEC.sys
02:22:10.0062 3236 ACPIEC - ok
02:22:10.0125 3236 adpu160m (9a11864873da202c996558b2106b0bbc) C:\WINDOWS\system32\DRIVERS\adpu160m.sys
02:22:10.0765 3236 adpu160m - ok
02:22:10.0921 3236 aec - ok
02:22:11.0078 3236 AFD (55e6e1c51b6d30e54335750955453702) C:\WINDOWS\System32\drivers\afd.sys
02:22:11.0125 3236 AFD - ok
02:22:11.0218 3236 agp440 (2c428fa0c3e3a01ed93c9b2a27d8d4bb) C:\WINDOWS\system32\DRIVERS\agp440.sys
02:22:11.0484 3236 agp440 - ok
02:22:11.0578 3236 agpCPQ (67288b07d6aba6c1267b626e67bc56fd) C:\WINDOWS\system32\DRIVERS\agpCPQ.sys
02:22:11.0812 3236 agpCPQ - ok
02:22:11.0921 3236 Aha154x (c23ea9b5f46c7f7910db3eab648ff013) C:\WINDOWS\system32\DRIVERS\aha154x.sys
02:22:12.0031 3236 Aha154x - ok
02:22:12.0062 3236 aic78u2 (19dd0fb48b0c18892f70e2e7d61a1529) C:\WINDOWS\system32\DRIVERS\aic78u2.sys
02:22:12.0281 3236 aic78u2 - ok
02:22:12.0390 3236 aic78xx (b7fe594a7468aa0132deb03fb8e34326) C:\WINDOWS\system32\DRIVERS\aic78xx.sys
02:22:12.0562 3236 aic78xx - ok
02:22:12.0703 3236 AliIde (1140ab9938809700b46bb88e46d72a96) C:\WINDOWS\system32\DRIVERS\aliide.sys
02:22:12.0890 3236 AliIde - ok
02:22:12.0937 3236 alim1541 (f312b7cef21eff52fa23056b9d815fad) C:\WINDOWS\system32\DRIVERS\alim1541.sys
02:22:13.0156 3236 alim1541 - ok
02:22:13.0312 3236 amdagp (675c16a3c1f8482f85ee4a97fc0dde3d) C:\WINDOWS\system32\DRIVERS\amdagp.sys
02:22:13.0546 3236 amdagp - ok
02:22:13.0796 3236 AmdK8 (efbb0956baed786e137351b5ca272aef) C:\WINDOWS\system32\DRIVERS\AmdK8.sys
02:22:13.0828 3236 AmdK8 - ok
02:22:13.0890 3236 amsint (79f5add8d24bd6893f2903a3e2f3fad6) C:\WINDOWS\system32\DRIVERS\amsint.sys
02:22:14.0000 3236 amsint - ok
02:22:14.0312 3236 APPDRV (ec94e05b76d033b74394e7b2175103cf) C:\WINDOWS\SYSTEM32\DRIVERS\APPDRV.SYS
02:22:14.0359 3236 APPDRV ( UnsignedFile.Multi.Generic ) - warning
02:22:14.0359 3236 APPDRV - detected UnsignedFile.Multi.Generic (1)
02:22:14.0453 3236 asc (62d318e9a0c8fc9b780008e724283707) C:\WINDOWS\system32\DRIVERS\asc.sys
02:22:14.0796 3236 asc - ok
02:22:14.0890 3236 asc3350p (69eb0cc7714b32896ccbfd5edcbea447) C:\WINDOWS\system32\DRIVERS\asc3350p.sys
02:22:15.0000 3236 asc3350p - ok
02:22:15.0125 3236 asc3550 (5d8de112aa0254b907861e9e9c31d597) C:\WINDOWS\system32\DRIVERS\asc3550.sys
02:22:15.0328 3236 asc3550 - ok
02:22:15.0468 3236 aswFsBlk (1c2e6bb4fe8621b1b863855b02bc33eb) C:\WINDOWS\system32\drivers\aswFsBlk.sys
02:22:15.0468 3236 aswFsBlk - ok
02:22:15.0500 3236 aswMon2 (452d0ecd14fa02f9b061f42c8a30dd49) C:\WINDOWS\system32\drivers\aswMon2.sys
02:22:15.0515 3236 aswMon2 - ok
02:22:15.0562 3236 aswRdr (b6a9373619d851be80fb5f1b5eed0d4e) C:\WINDOWS\system32\drivers\aswRdr.sys
02:22:15.0578 3236 aswRdr - ok
02:22:15.0781 3236 aswSnx (9be41c1ae8bc481eb662d85c98d979c2) C:\WINDOWS\system32\drivers\aswSnx.sys
02:22:15.0796 3236 aswSnx - ok
02:22:15.0921 3236 aswSP (4b1a54ba2bc5873a774df6b70ab8b0b3) C:\WINDOWS\system32\drivers\aswSP.sys
02:22:15.0937 3236 aswSP - ok
02:22:15.0968 3236 aswTdi (c7f1cea32766184911293f4e1ee653f5) C:\WINDOWS\system32\drivers\aswTdi.sys
02:22:15.0968 3236 aswTdi - ok
02:22:16.0078 3236 AsyncMac (02000abf34af4c218c35d257024807d6) C:\WINDOWS\system32\DRIVERS\asyncmac.sys
02:22:16.0328 3236 AsyncMac - ok
02:22:16.0390 3236 atapi (cdfe4411a69c224bd1d11b2da92dac51) C:\WINDOWS\system32\DRIVERS\atapi.sys
02:22:16.0562 3236 atapi - ok
02:22:16.0609 3236 Atdisk - ok
02:22:16.0812 3236 ati2mtag (9e050c4e49a26ff181b70bec61ae048e) C:\WINDOWS\system32\DRIVERS\ati2mtag.sys
02:22:16.0968 3236 ati2mtag - ok
02:22:17.0234 3236 Atmarpc (ec88da854ab7d7752ec8be11a741bb7f) C:\WINDOWS\system32\DRIVERS\atmarpc.sys
02:22:17.0453 3236 Atmarpc - ok
02:22:17.0484 3236 audstub (d9f724aa26c010a217c97606b160ed68) C:\WINDOWS\system32\DRIVERS\audstub.sys
02:22:17.0656 3236 audstub - ok
02:22:17.0750 3236 BCM43XX (30d20fc98bcfd52e1da778cf19b223d4) C:\WINDOWS\system32\DRIVERS\bcmwl5.sys
02:22:17.0812 3236 BCM43XX - ok
02:22:17.0968 3236 bcm4sbxp (6489310d11971f6ba6c7f49be0baf6e0) C:\WINDOWS\system32\DRIVERS\bcm4sbxp.sys
02:22:18.0031 3236 bcm4sbxp - ok
02:22:18.0156 3236 Beep (da1f27d85e0d1525f6621372e7b685e9) C:\WINDOWS\system32\drivers\Beep.sys
02:22:18.0390 3236 Beep - ok
02:22:18.0671 3236 cbidf (90a673fc8e12a79afbed2576f6a7aaf9) C:\WINDOWS\system32\DRIVERS\cbidf2k.sys
02:22:18.0906 3236 cbidf - ok
02:22:19.0000 3236 cbidf2k (90a673fc8e12a79afbed2576f6a7aaf9) C:\WINDOWS\system32\drivers\cbidf2k.sys
02:22:19.0187 3236 cbidf2k - ok
02:22:19.0421 3236 CCDECODE (6163ed60b684bab19d3352ab22fc48b2) C:\WINDOWS\system32\DRIVERS\CCDECODE.sys
02:22:19.0656 3236 CCDECODE - ok
02:22:19.0875 3236 cd20xrnt (f3ec03299634490e97bbce94cd2954c7) C:\WINDOWS\system32\DRIVERS\cd20xrnt.sys
02:22:20.0015 3236 cd20xrnt - ok
02:22:20.0406 3236 Cdaudio (c1b486a7658353d33a10cc15211a873b) C:\WINDOWS\system32\drivers\Cdaudio.sys
02:22:20.0781 3236 Cdaudio - ok
02:22:21.0234 3236 Cdfs (cd7d5152df32b47f4e36f710b35aae02) C:\WINDOWS\system32\drivers\Cdfs.sys
02:22:21.0484 3236 Cdfs - ok
02:22:21.0703 3236 Cdrom (af9c19b3100fe010496b1a27181fbf72) C:\WINDOWS\system32\DRIVERS\cdrom.sys
02:22:22.0093 3236 Cdrom - ok
02:22:22.0359 3236 Changer - ok
02:22:22.0562 3236 CmBatt (4266be808f85826aedf3c64c1e240203) C:\WINDOWS\system32\DRIVERS\CmBatt.sys
02:22:22.0937 3236 CmBatt - ok
02:22:23.0187 3236 CmdIde (e5dcb56c533014ecbc556a8357c929d5) C:\WINDOWS\system32\DRIVERS\cmdide.sys
02:22:23.0500 3236 CmdIde - ok
02:22:23.0625 3236 Compbatt (df1b1a24bf52d0ebc01ed4ece8979f50) C:\WINDOWS\system32\DRIVERS\compbatt.sys
02:22:23.0843 3236 Compbatt - ok
02:22:24.0218 3236 Cpqarray (3ee529119eed34cd212a215e8c40d4b6) C:\WINDOWS\system32\DRIVERS\cpqarray.sys
02:22:24.0484 3236 Cpqarray - ok
02:22:24.0750 3236 dac2w2k (e550e7418984b65a78299d248f0a7f36) C:\WINDOWS\system32\DRIVERS\dac2w2k.sys
02:22:24.0968 3236 dac2w2k - ok
02:22:25.0250 3236 dac960nt (683789caa3864eb46125ae86ff677d34) C:\WINDOWS\system32\DRIVERS\dac960nt.sys
02:22:25.0531 3236 dac960nt - ok
02:22:25.0781 3236 Disk (00ca44e4534865f8a3b64f7c0984bff0) C:\WINDOWS\system32\DRIVERS\disk.sys
02:22:26.0000 3236 Disk - ok
02:22:26.0203 3236 dmboot (c0fbb516e06e243f0cf31f597e7ebf7d) C:\WINDOWS\system32\drivers\dmboot.sys
02:22:26.0515 3236 dmboot - ok
02:22:26.0750 3236 dmio (f5e7b358a732d09f4bcf2824b88b9e28) C:\WINDOWS\system32\drivers\dmio.sys
02:22:27.0000 3236 dmio - ok
02:22:27.0156 3236 dmload (e9317282a63ca4d188c0df5e09c6ac5f) C:\WINDOWS\system32\drivers\dmload.sys
02:22:27.0390 3236 dmload - ok
02:22:27.0671 3236 DMusic (a6f881284ac1150e37d9ae47ff601267) C:\WINDOWS\system32\drivers\DMusic.sys
02:22:27.0906 3236 DMusic - ok
02:22:28.0031 3236 dpti2o (40f3b93b4e5b0126f2f5c0a7a5e22660) C:\WINDOWS\system32\DRIVERS\dpti2o.sys
02:22:28.0265 3236 dpti2o - ok
02:22:28.0718 3236 drmkaud (1ed4dbbae9f5d558dbba4cc450e3eb2e) C:\WINDOWS\system32\drivers\drmkaud.sys
02:22:28.0953 3236 drmkaud - ok
02:22:29.0171 3236 DSproct (2ac2372ffad9adc85672cc8e8ae14be9) C:\Program Files\Dell Support\GTAction\triggers\DSproct.sys
02:22:29.0218 3236 DSproct ( UnsignedFile.Multi.Generic ) - warning
02:22:29.0218 3236 DSproct - detected UnsignedFile.Multi.Generic (1)
02:22:29.0453 3236 E100B (3fca03cbca11269f973b70fa483c88ef) C:\WINDOWS\system32\DRIVERS\e100b325.sys
02:22:29.0843 3236 E100B - ok
02:22:30.0031 3236 Fastfat (3117f595e9615e04f05a54fc15a03b20) C:\WINDOWS\system32\drivers\Fastfat.sys
02:22:30.0250 3236 Fastfat - ok
02:22:30.0500 3236 Fdc (ced2e8396a8838e59d8fd529c680e02c) C:\WINDOWS\system32\DRIVERS\fdc.sys
02:22:30.0734 3236 Fdc - ok
02:22:30.0890 3236 Fips (e153ab8a11de5452bcf5ac7652dbf3ed) C:\WINDOWS\system32\drivers\Fips.sys
02:22:31.0140 3236 Fips - ok
02:22:31.0296 3236 Flpydisk (0dd1de43115b93f4d85e889d7a86f548) C:\WINDOWS\system32\DRIVERS\flpydisk.sys
02:22:31.0500 3236 Flpydisk - ok
02:22:31.0671 3236 FltMgr (3d234fb6d6ee875eb009864a299bea29) C:\WINDOWS\system32\DRIVERS\fltMgr.sys
02:22:32.0187 3236 FltMgr - ok
02:22:32.0328 3236 Fs_Rec (3e1e2bd4f39b0e2b7dc4f4d2bcc2779a) C:\WINDOWS\system32\drivers\Fs_Rec.sys
02:22:32.0515 3236 Fs_Rec - ok
02:22:32.0656 3236 Ftdisk (6ac26732762483366c3969c9e4d2259d) C:\WINDOWS\system32\DRIVERS\ftdisk.sys
02:22:32.0921 3236 Ftdisk - ok
02:22:33.0046 3236 GEARAspiWDM (8182ff89c65e4d38b2de4bb0fb18564e) C:\WINDOWS\system32\Drivers\GEARAspiWDM.sys
02:22:33.0062 3236 GEARAspiWDM - ok
02:22:33.0484 3236 Gpc (c0f1d4a21de5a415df8170616703debf) C:\WINDOWS\system32\DRIVERS\msgpc.sys
02:22:33.0718 3236 Gpc - ok
02:22:33.0875 3236 HDAudBus (e31363d186b3e1d7c4e9117884a6aee5) C:\WINDOWS\system32\DRIVERS\HDAudBus.sys
02:22:33.0937 3236 HDAudBus - ok
02:22:34.0312 3236 hpn (b028377dea0546a5fcfba928a8aefae0) C:\WINDOWS\system32\DRIVERS\hpn.sys
02:22:34.0656 3236 hpn - ok
02:22:34.0937 3236 HPZid412 (d03d10f7ded688fecf50f8fbf1ea9b8a) C:\WINDOWS\system32\DRIVERS\HPZid412.sys
02:22:35.0000 3236 HPZid412 - ok
02:22:35.0218 3236 HPZius12 (abcb05ccdbf03000354b9553820e39f8) C:\WINDOWS\system32\DRIVERS\HPZius12.sys
02:22:35.0328 3236 HPZius12 - ok
02:22:35.0656 3236 HSF_DPV (e8ec1767ea315a39a0dd8989952ca0e9) C:\WINDOWS\system32\DRIVERS\HSX_DPV.sys
02:22:36.0265 3236 HSF_DPV - ok
02:22:36.0593 3236 HSXHWAZL (61478fa42ee04562e7f11f4dca87e9c8) C:\WINDOWS\system32\DRIVERS\HSXHWAZL.sys
02:22:36.0687 3236 HSXHWAZL - ok
02:22:36.0843 3236 HTTP (9f8b0f4276f618964fd118be4289b7cd) C:\WINDOWS\system32\Drivers\HTTP.sys
02:22:36.0937 3236 HTTP - ok
02:22:37.0156 3236 i2omgmt (8f09f91b5c91363b77bcd15599570f2c) C:\WINDOWS\system32\drivers\i2omgmt.sys
02:22:37.0890 3236 i2omgmt - ok
02:22:38.0421 3236 i2omp (ed6bf9e441fdea13292a6d30a64a24c3) C:\WINDOWS\system32\DRIVERS\i2omp.sys
02:22:38.0937 3236 i2omp - ok
02:22:39.0562 3236 i8042prt (5502b58eef7486ee6f93f3f164dcb808) C:\WINDOWS\system32\DRIVERS\i8042prt.sys
02:22:40.0015 3236 i8042prt - ok
02:22:40.0234 3236 Imapi (f8aa320c6a0409c0380e5d8a99d76ec6) C:\WINDOWS\system32\DRIVERS\imapi.sys
02:22:40.0531 3236 Imapi - ok
02:22:40.0812 3236 ini910u (4a40e045faee58631fd8d91afc620719) C:\WINDOWS\system32\DRIVERS\ini910u.sys
02:22:41.0015 3236 ini910u - ok
02:22:41.0187 3236 IntelIde (2d722b2b54ab55b2fa475eb58d7b2aad) C:\WINDOWS\system32\DRIVERS\intelide.sys
02:22:41.0406 3236 IntelIde - ok
02:22:41.0531 3236 intelppm (279fb78702454dff2bb445f238c048d2) C:\WINDOWS\system32\DRIVERS\intelppm.sys
02:22:41.0750 3236 intelppm - ok
02:22:41.0937 3236 Ip6Fw (4448006b6bc60e6c027932cfc38d6855) C:\WINDOWS\system32\DRIVERS\Ip6Fw.sys
02:22:42.0140 3236 Ip6Fw - ok
02:22:42.0468 3236 IpFilterDriver (731f22ba402ee4b62748adaf6363c182) C:\WINDOWS\system32\DRIVERS\ipfltdrv.sys
02:22:42.0718 3236 IpFilterDriver - ok
02:22:42.0875 3236 IpInIp (e1ec7f5da720b640cd8fb8424f1b14bb) C:\WINDOWS\system32\DRIVERS\ipinip.sys
02:22:43.0078 3236 IpInIp - ok
02:22:43.0484 3236 IpNat (e2168cbc7098ffe963c6f23f472a3593) C:\WINDOWS\system32\DRIVERS\ipnat.sys
02:22:44.0015 3236 IpNat - ok
02:22:44.0203 3236 IPSec (64537aa5c003a6afeee1df819062d0d1) C:\WINDOWS\system32\DRIVERS\ipsec.sys
02:22:44.0390 3236 IPSec - ok
02:22:44.0640 3236 IRENUM (50708daa1b1cbb7d6ac1cf8f56a24410) C:\WINDOWS\system32\DRIVERS\irenum.sys
02:22:44.0781 3236 IRENUM - ok
02:22:45.0171 3236 isapnp (e504f706ccb699c2596e9a3da1596e87) C:\WINDOWS\system32\DRIVERS\isapnp.sys
02:22:45.0375 3236 isapnp - ok
02:22:45.0921 3236 Kbdclass (ebdee8a2ee5393890a1acee971c4c246) C:\WINDOWS\system32\DRIVERS\kbdclass.sys
02:22:46.0296 3236 Kbdclass - ok
02:22:46.0828 3236 kmixer (ba5deda4d934e6288c2f66caf58d2562) C:\WINDOWS\system32\drivers\kmixer.sys
02:22:47.0453 3236 kmixer - ok
02:22:47.0859 3236 KSecDD (1be7cc2535d760ae4d481576eb789f24) C:\WINDOWS\system32\drivers\KSecDD.sys
02:22:47.0937 3236 KSecDD - ok
02:22:48.0421 3236 lbrtfdc - ok
02:22:48.0578 3236 mdmxsdk (e246a32c445056996074a397da56e815) C:\WINDOWS\system32\DRIVERS\mdmxsdk.sys
02:22:48.0671 3236 mdmxsdk - ok
02:22:49.0140 3236 mnmdd (4ae068242760a1fb6e1a44bf4e16afa6) C:\WINDOWS\system32\drivers\mnmdd.sys
02:22:49.0625 3236 mnmdd - ok
02:22:50.0062 3236 Modem (6fc6f9d7acc36dca9b914565a3aeda05) C:\WINDOWS\system32\drivers\Modem.sys
02:22:50.0281 3236 Modem - ok
02:22:50.0703 3236 Mouclass (34e1f0031153e491910e12551400192c) C:\WINDOWS\system32\DRIVERS\mouclass.sys
02:22:50.0937 3236 Mouclass - ok
02:22:51.0234 3236 MountMgr (65653f3b4477f3c63e68a9659f85ee2e) C:\WINDOWS\system32\drivers\MountMgr.sys
02:22:51.0593 3236 MountMgr - ok
02:22:51.0828 3236 mraid35x (3f4bb95e5a44f3be34824e8e7caf0737) C:\WINDOWS\system32\DRIVERS\mraid35x.sys
02:22:52.0000 3236 mraid35x - ok
02:22:52.0296 3236 MRxDAV (29414447eb5bde2f8397dc965dbb3156) C:\WINDOWS\system32\DRIVERS\mrxdav.sys
02:22:52.0968 3236 MRxDAV - ok
02:22:53.0421 3236 MRxSmb (fb6c89bb3ce282b08bdb1e3c179e1c39) C:\WINDOWS\system32\DRIVERS\mrxsmb.sys
02:22:53.0562 3236 MRxSmb - ok
02:22:53.0812 3236 Msfs (561b3a4333ca2dbdba28b5b956822519) C:\WINDOWS\system32\drivers\Msfs.sys
02:22:54.0218 3236 Msfs - ok
02:22:54.0328 3236 MSKSSRV (ae431a8dd3c1d0d0610cdbac16057ad0) C:\WINDOWS\system32\drivers\MSKSSRV.sys
02:22:54.0531 3236 MSKSSRV - ok
02:22:54.0843 3236 MSPCLOCK (13e75fef9dfeb08eeded9d0246e1f448) C:\WINDOWS\system32\drivers\MSPCLOCK.sys
02:22:55.0031 3236 MSPCLOCK - ok
02:22:55.0156 3236 MSPQM (1988a33ff19242576c3d0ef9ce785da7) C:\WINDOWS\system32\drivers\MSPQM.sys
02:22:55.0375 3236 MSPQM - ok
02:22:55.0562 3236 mssmbios (469541f8bfd2b32659d5d463a6714bce) C:\WINDOWS\system32\DRIVERS\mssmbios.sys
02:22:55.0812 3236 mssmbios - ok
02:22:56.0015 3236 MSTEE (bf13612142995096ab084f2db7f40f77) C:\WINDOWS\system32\drivers\MSTEE.sys
02:22:56.0234 3236 MSTEE - ok
02:22:56.0531 3236 Mup (82035e0f41c2dd05ae41d27fe6cf7de1) C:\WINDOWS\system32\drivers\Mup.sys
02:22:57.0421 3236 Mup - ok
02:22:57.0515 3236 NABTSFEC (5c8dc6429c43dc6177c1fa5b76290d1a) C:\WINDOWS\system32\DRIVERS\NABTSFEC.sys
02:22:57.0828 3236 NABTSFEC - ok
02:22:58.0109 3236 NDIS (558635d3af1c7546d26067d5d9b6959e) C:\WINDOWS\system32\drivers\NDIS.sys
02:22:58.0296 3236 NDIS - ok
02:22:58.0437 3236 NdisIP (520ce427a8b298f54112857bcf6bde15) C:\WINDOWS\system32\DRIVERS\NdisIP.sys
02:22:58.0656 3236 NdisIP - ok
02:22:58.0859 3236 NdisTapi (08d43bbdacdf23f34d79e44ed35c1b4c) C:\WINDOWS\system32\DRIVERS\ndistapi.sys
02:22:59.0109 3236 NdisTapi - ok
02:22:59.0203 3236 Ndisuio (34d6cd56409da9a7ed573e1c90a308bf) C:\WINDOWS\system32\DRIVERS\ndisuio.sys
02:22:59.0437 3236 Ndisuio - ok
02:22:59.0500 3236 NdisWan (0b90e255a9490166ab368cd55a529893) C:\WINDOWS\system32\DRIVERS\ndiswan.sys
02:22:59.0734 3236 NdisWan - ok
02:22:59.0859 3236 NDProxy (59fc3fb44d2669bc144fd87826bb571f) C:\WINDOWS\system32\drivers\NDProxy.sys
02:23:00.0078 3236 NDProxy - ok
02:23:00.0156 3236 NetBIOS (3a2aca8fc1d7786902ca434998d7ceb4) C:\WINDOWS\system32\DRIVERS\netbios.sys
02:23:00.0468 3236 NetBIOS - ok
02:23:00.0593 3236 NetBT (0c80e410cd2f47134407ee7dd19cc86b) C:\WINDOWS\system32\DRIVERS\netbt.sys
02:23:00.0828 3236 NetBT - ok
02:23:01.0000 3236 Npfs (4f601bcb8f64ea3ac0994f98fed03f8e) C:\WINDOWS\system32\drivers\Npfs.sys
02:23:01.0203 3236 Npfs - ok
02:23:01.0500 3236 Ntfs (19a811ef5f1ed5c926a028ce107ff1af) C:\WINDOWS\system32\drivers\Ntfs.sys
02:23:02.0125 3236 Ntfs - ok
02:23:02.0359 3236 Null (73c1e1f395918bc2c6dd67af7591a3ad) C:\WINDOWS\system32\drivers\Null.sys
02:23:02.0546 3236 Null - ok
02:23:02.0828 3236 nv (2b298519edbfcf451d43e0f1e8f1006d) C:\WINDOWS\system32\DRIVERS\nv4_mini.sys
02:23:03.0765 3236 nv - ok
02:23:03.0875 3236 NwlnkFlt (b305f3fad35083837ef46a0bbce2fc57) C:\WINDOWS\system32\DRIVERS\nwlnkflt.sys
02:23:04.0062 3236 NwlnkFlt - ok
02:23:04.0156 3236 NwlnkFwd (c99b3415198d1aab7227f2c88fd664b9) C:\WINDOWS\system32\DRIVERS\nwlnkfwd.sys
02:23:04.0375 3236 NwlnkFwd - ok
02:23:04.0593 3236 Parport (29744eb4ce659dfe3b4122deb45bc478) C:\WINDOWS\system32\DRIVERS\parport.sys
02:23:04.0796 3236 Parport - ok
02:23:04.0921 3236 PartMgr (3334430c29dc338092f79c38ef7b4cd0) C:\WINDOWS\system32\drivers\PartMgr.sys
02:23:05.0140 3236 PartMgr - ok
02:23:05.0265 3236 ParVdm (70e98b3fd8e963a6a46a2e6247e0bea1) C:\WINDOWS\system32\drivers\ParVdm.sys
02:23:05.0453 3236 ParVdm - ok
02:23:05.0531 3236 PCI (8086d9979234b603ad5bc2f5d890b234) C:\WINDOWS\system32\DRIVERS\pci.sys
02:23:05.0703 3236 PCI - ok
02:23:05.0796 3236 PCIDump - ok
02:23:05.0875 3236 PCIIde (ccf5f451bb1a5a2a522a76e670000ff0) C:\WINDOWS\system32\DRIVERS\pciide.sys
02:23:06.0078 3236 PCIIde - ok
02:23:06.0343 3236 Pcmcia (82a087207decec8456fbe8537947d579) C:\WINDOWS\system32\drivers\Pcmcia.sys
02:23:06.0546 3236 Pcmcia - ok
02:23:06.0640 3236 PDCOMP - ok
02:23:06.0734 3236 PDFRAME - ok
02:23:06.0750 3236 PDRELI - ok
02:23:06.0765 3236 PDRFRAME - ok
02:23:06.0843 3236 perc2 (6c14b9c19ba84f73d3a86dba11133101) C:\WINDOWS\system32\DRIVERS\perc2.sys
02:23:07.0468 3236 perc2 - ok
02:23:07.0687 3236 perc2hib (f50f7c27f131afe7beba13e14a3b9416) C:\WINDOWS\system32\DRIVERS\perc2hib.sys
02:23:08.0015 3236 perc2hib - ok
02:23:08.0046 3236 podhrzwb - ok
02:23:08.0109 3236 PptpMiniport (1c5cc65aac0783c344f16353e60b72ac) C:\WINDOWS\system32\DRIVERS\raspptp.sys
02:23:08.0328 3236 PptpMiniport - ok
02:23:08.0609 3236 Processor (0d97d88720a4087ec93af7dbb303b30a) C:\WINDOWS\system32\DRIVERS\processr.sys
02:23:09.0015 3236 Processor - ok
02:23:09.0484 3236 PSched (48671f327553dcf1d27f6197f622a668) C:\WINDOWS\system32\DRIVERS\psched.sys
02:23:09.0890 3236 PSched - ok
02:23:09.0968 3236 Ptilink (80d317bd1c3dbc5d4fe7b1678c60cadd) C:\WINDOWS\system32\DRIVERS\ptilink.sys
02:23:10.0265 3236 Ptilink - ok
02:23:10.0359 3236 PxHelp20 (1962166e0ceb740704f30fa55ad3d509) C:\WINDOWS\system32\Drivers\PxHelp20.sys
02:23:10.0437 3236 PxHelp20 ( UnsignedFile.Multi.Generic ) - warning
02:23:10.0437 3236 PxHelp20 - detected UnsignedFile.Multi.Generic (1)
02:23:10.0500 3236 ql1080 (0a63fb54039eb5662433caba3b26dba7) C:\WINDOWS\system32\DRIVERS\ql1080.sys
02:23:10.0812 3236 ql1080 - ok
02:23:10.0890 3236 Ql10wnt (6503449e1d43a0ff0201ad5cb1b8c706) C:\WINDOWS\system32\DRIVERS\ql10wnt.sys
02:23:11.0265 3236 Ql10wnt - ok
02:23:11.0312 3236 ql12160 (156ed0ef20c15114ca097a34a30d8a01) C:\WINDOWS\system32\DRIVERS\ql12160.sys
02:23:11.0484 3236 ql12160 - ok
02:23:11.0515 3236 ql1240 (70f016bebde6d29e864c1230a07cc5e6) C:\WINDOWS\system32\DRIVERS\ql1240.sys
02:23:11.0734 3236 ql1240 - ok
02:23:11.0781 3236 ql1280 (907f0aeea6bc451011611e732bd31fcf) C:\WINDOWS\system32\DRIVERS\ql1280.sys
02:23:11.0953 3236 ql1280 - ok
02:23:11.0984 3236 RasAcd (fe0d99d6f31e4fad8159f690d68ded9c) C:\WINDOWS\system32\DRIVERS\rasacd.sys
02:23:12.0140 3236 RasAcd - ok
02:23:12.0171 3236 Rasl2tp (98faeb4a4dcf812ba1c6fca4aa3e115c) C:\WINDOWS\system32\DRIVERS\rasl2tp.sys
02:23:12.0328 3236 Rasl2tp - ok
02:23:12.0359 3236 RasPppoe (7306eeed8895454cbed4669be9f79faa) C:\WINDOWS\system32\DRIVERS\raspppoe.sys
02:23:12.0500 3236 RasPppoe - ok
02:23:12.0546 3236 Raspti (fdbb1d60066fcfbb7452fd8f9829b242) C:\WINDOWS\system32\DRIVERS\raspti.sys
02:23:12.0718 3236 Raspti - ok
02:23:12.0796 3236 Rdbss (03b965b1ca47f6ef60eb5e51cb50e0af) C:\WINDOWS\system32\DRIVERS\rdbss.sys
02:23:13.0328 3236 Rdbss - ok
02:23:13.0359 3236 RDPCDD (4912d5b403614ce99c28420f75353332) C:\WINDOWS\system32\DRIVERS\RDPCDD.sys
02:23:13.0500 3236 RDPCDD - ok
02:23:13.0625 3236 rdpdr (a2cae2c60bc37e0751ef9dda7ceaf4ad) C:\WINDOWS\system32\DRIVERS\rdpdr.sys
02:23:13.0843 3236 rdpdr - ok
02:23:13.0937 3236 RDPWD (b54cd38a9ebfbf2b3561426e3fe26f62) C:\WINDOWS\system32\drivers\RDPWD.sys
02:23:14.0453 3236 RDPWD - ok
02:23:14.0515 3236 redbook (b31b4588e4086d8d84adbf9845c2402b) C:\WINDOWS\system32\DRIVERS\redbook.sys
02:23:14.0687 3236 redbook - ok
02:23:14.0750 3236 rimmptsk (24ed7af20651f9fa1f249482e7c1f165) C:\WINDOWS\system32\DRIVERS\rimmptsk.sys
02:23:14.0781 3236 rimmptsk - ok
02:23:14.0859 3236 sdbus (02fc71b020ec8700ee8a46c58bc6f276) C:\WINDOWS\system32\DRIVERS\sdbus.sys
02:23:15.0796 3236 sdbus - ok
02:23:15.0968 3236 SDDMI2 (8edd7b9e4a4b4c16e2dab9188caa861b) C:\WINDOWS\system32\DDMI2.sys
02:23:16.0015 3236 SDDMI2 ( UnsignedFile.Multi.Generic ) - warning
02:23:16.0015 3236 SDDMI2 - detected UnsignedFile.Multi.Generic (1)
02:23:16.0109 3236 Secdrv (90a3935d05b494a5a39d37e71f09a677) C:\WINDOWS\system32\DRIVERS\secdrv.sys
02:23:17.0109 3236 Secdrv - ok
02:23:17.0171 3236 serenum (a2d868aeeff612e70e213c451a70cafb) C:\WINDOWS\system32\DRIVERS\serenum.sys
02:23:17.0531 3236 serenum - ok
02:23:17.0578 3236 Serial (cd9404d115a00d249f70a371b46d5a26) C:\WINDOWS\system32\DRIVERS\serial.sys
02:23:17.0750 3236 Serial - ok
02:23:17.0828 3236 Sfloppy (0d13b6df6e9e101013a7afb0ce629fe0) C:\WINDOWS\system32\drivers\Sfloppy.sys
02:23:18.0000 3236 Sfloppy - ok
02:23:18.0062 3236 Simbad - ok
02:23:18.0109 3236 sisagp (732d859b286da692119f286b21a2a114) C:\WINDOWS\system32\DRIVERS\sisagp.sys
02:23:18.0281 3236 sisagp - ok
02:23:18.0375 3236 SLIP (5caeed86821fa2c6139e32e9e05ccdc9) C:\WINDOWS\system32\DRIVERS\SLIP.sys
02:23:18.0546 3236 SLIP - ok
02:23:18.0593 3236 Sparrow (83c0f71f86d3bdaf915685f3d568b20e) C:\WINDOWS\system32\DRIVERS\sparrow.sys
02:23:18.0703 3236 Sparrow - ok
02:23:18.0781 3236 splitter (0ce218578fff5f4f7e4201539c45c78f) C:\WINDOWS\system32\drivers\splitter.sys
02:23:19.0281 3236 splitter - ok
02:23:19.0328 3236 sr (e41b6d037d6cd08461470af04500dc24) C:\WINDOWS\system32\DRIVERS\sr.sys
02:23:19.0453 3236 sr - ok
02:23:19.0531 3236 Srv (7a4f147cc6b133f905f6e65e2f8669fb) C:\WINDOWS\system32\DRIVERS\srv.sys
02:23:19.0562 3236 Srv - ok
02:23:19.0640 3236 STHDA (8990440e4b2a7ca5a56a1833b03741fd) C:\WINDOWS\system32\drivers\sthda.sys
02:23:19.0734 3236 STHDA - ok
02:23:19.0812 3236 streamip (284c57df5dc7abca656bc2b96a667afb) C:\WINDOWS\system32\DRIVERS\StreamIP.sys
02:23:20.0000 3236 streamip - ok
02:23:20.0062 3236 swenum (03c1bae4766e2450219d20b993d6e046) C:\WINDOWS\system32\DRIVERS\swenum.sys
02:23:20.0234 3236 swenum - ok
02:23:20.0296 3236 swmidi (94abc808fc4b6d7d2bbf42b85e25bb4d) C:\WINDOWS\system32\drivers\swmidi.sys
02:23:20.0453 3236 swmidi - ok
02:23:20.0546 3236 symc810 (1ff3217614018630d0a6758630fc698c) C:\WINDOWS\system32\DRIVERS\symc810.sys
02:23:20.0703 3236 symc810 - ok
02:23:20.0734 3236 symc8xx (070e001d95cf725186ef8b20335f933c) C:\WINDOWS\system32\DRIVERS\symc8xx.sys
02:23:20.0906 3236 symc8xx - ok
02:23:20.0937 3236 symlcbrd (b226f8a4d780acdf76145b58bb791d5b) C:\WINDOWS\system32\drivers\symlcbrd.sys
02:23:20.0953 3236 symlcbrd - ok
02:23:20.0968 3236 sym_hi (80ac1c4abbe2df3b738bf15517a51f2c) C:\WINDOWS\system32\DRIVERS\sym_hi.sys
02:23:21.0140 3236 sym_hi - ok
02:23:21.0187 3236 sym_u3 (bf4fab949a382a8e105f46ebb4937058) C:\WINDOWS\system32\DRIVERS\sym_u3.sys
02:23:21.0359 3236 sym_u3 - ok
02:23:21.0437 3236 SynTP (fa2daa32bed908023272a0f77d625dae) C:\WINDOWS\system32\DRIVERS\SynTP.sys
02:23:21.0484 3236 SynTP - ok
02:23:21.0562 3236 sysaudio (650ad082d46bac0e64c9c0e0928492fd) C:\WINDOWS\system32\drivers\sysaudio.sys
02:23:21.0734 3236 sysaudio - ok
02:23:21.0843 3236 Tcpip (2a5554fc5b1e04e131230e3ce035c3f9) C:\WINDOWS\system32\DRIVERS\tcpip.sys
02:23:21.0953 3236 Tcpip - ok
02:23:22.0062 3236 TDPIPE (38d437cf2d98965f239b0abcd66dcb0f) C:\WINDOWS\system32\drivers\TDPIPE.sys
02:23:22.0234 3236 TDPIPE - ok
02:23:22.0312 3236 TDTCP (ed0580af02502d00ad8c4c066b156be9) C:\WINDOWS\system32\drivers\TDTCP.sys
02:23:22.0468 3236 TDTCP - ok
02:23:22.0515 3236 TermDD (a540a99c281d933f3d69d55e48727f47) C:\WINDOWS\system32\DRIVERS\termdd.sys
02:23:22.0671 3236 TermDD - ok
02:23:22.0750 3236 TosIde (f2790f6af01321b172aa62f8e1e187d9) C:\WINDOWS\system32\DRIVERS\toside.sys
02:23:22.0906 3236 TosIde - ok
02:23:22.0984 3236 Udfs (12f70256f140cd7d52c58c7048fde657) C:\WINDOWS\system32\drivers\Udfs.sys
02:23:23.0156 3236 Udfs - ok
02:23:23.0218 3236 ultra (1b698a51cd528d8da4ffaed66dfc51b9) C:\WINDOWS\system32\DRIVERS\ultra.sys
02:23:23.0328 3236 ultra - ok
02:23:23.0390 3236 Update (aff2e5045961bbc0a602bb6f95eb1345) C:\WINDOWS\system32\DRIVERS\update.sys
02:23:23.0562 3236 Update - ok
02:23:23.0640 3236 USBAAPL - ok
02:23:23.0734 3236 usbccgp (bffd9f120cc63bcbaa3d840f3eef9f79) C:\WINDOWS\system32\DRIVERS\usbccgp.sys
02:23:23.0906 3236 usbccgp - ok
02:23:23.0937 3236 usbehci (708579b01fed227aadb393cb0c3b4a2c) C:\WINDOWS\system32\DRIVERS\usbehci.sys
02:23:24.0453 3236 usbehci - ok
02:23:24.0484 3236 usbhub (c72f40947f92cea56a8fb532edf025f1) C:\WINDOWS\system32\DRIVERS\usbhub.sys
02:23:24.0656 3236 usbhub - ok
02:23:24.0671 3236 usbohci (bdfe799a8531bad8a5a985821fe78760) C:\WINDOWS\system32\DRIVERS\usbohci.sys
02:23:24.0843 3236 usbohci - ok
02:23:24.0875 3236 usbprint (a42369b7cd8886cd7c70f33da6fcbcf5) C:\WINDOWS\system32\DRIVERS\usbprint.sys
02:23:25.0046 3236 usbprint - ok
02:23:25.0125 3236 usbscan (a6bc71402f4f7dd5b77fd7f4a8ddba85) C:\WINDOWS\system32\DRIVERS\usbscan.sys
02:23:25.0296 3236 usbscan - ok
02:23:25.0375 3236 USBSTOR (6cd7b22193718f1d17a47a1cd6d37e75) C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS
02:23:25.0546 3236 USBSTOR - ok
02:23:25.0625 3236 usbuhci (f8fd1400092e23c8f2f31406ef06167b) C:\WINDOWS\system32\DRIVERS\usbuhci.sys
02:23:25.0781 3236 usbuhci - ok
02:23:25.0890 3236 usbvideo (8968ff3973a883c49e8b564200f565b9) C:\WINDOWS\system32\Drivers\usbvideo.sys
02:23:26.0062 3236 usbvideo - ok
02:23:26.0109 3236 VgaSave (8a60edd72b4ea5aea8202daf0e427925) C:\WINDOWS\System32\drivers\vga.sys
02:23:26.0296 3236 VgaSave - ok
02:23:26.0390 3236 viaagp (d92e7c8a30cfd14d8e15b5f7f032151b) C:\WINDOWS\system32\DRIVERS\viaagp.sys
02:23:26.0562 3236 viaagp - ok
02:23:26.0593 3236 ViaIde (59cb1338ad3654417bea49636457f65d) C:\WINDOWS\system32\DRIVERS\viaide.sys
02:23:26.0781 3236 ViaIde - ok
02:23:26.0843 3236 VolSnap (ee4660083deba849ff6c485d944b379b) C:\WINDOWS\system32\drivers\VolSnap.sys
02:23:27.0000 3236 VolSnap - ok
02:23:27.0078 3236 Wanarp (984ef0b9788abf89974cfed4bfbaacbc) C:\WINDOWS\system32\DRIVERS\wanarp.sys
02:23:27.0250 3236 Wanarp - ok
02:23:27.0312 3236 WDICA - ok
02:23:27.0343 3236 wdmaud (efd235ca22b57c81118c1aeb4798f1c1) C:\WINDOWS\system32\drivers\wdmaud.sys
02:23:27.0859 3236 wdmaud - ok
02:23:27.0953 3236 winachsf (ba6b6fb242a6ba4068c8b763063beb63) C:\WINDOWS\system32\DRIVERS\HSX_CNXT.sys
02:23:28.0015 3236 winachsf - ok
02:23:28.0156 3236 WSTCODEC (d5842484f05e12121c511aa93f6439ec) C:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS
02:23:28.0328 3236 WSTCODEC - ok
02:23:28.0437 3236 WudfPf (f15feafffbb3644ccc80c5da584e6311) C:\WINDOWS\system32\DRIVERS\WudfPf.sys
02:23:28.0468 3236 WudfPf - ok
02:23:28.0515 3236 WudfRd (28b524262bce6de1f7ef9f510ba3985b) C:\WINDOWS\system32\DRIVERS\wudfrd.sys
02:23:28.0531 3236 WudfRd - ok
02:23:28.0609 3236 MBR (0x1B8) (3e3a57c3edd4ef2b3344bdfa5be57750) \Device\Harddisk0\DR0
02:23:28.0609 3236 \Device\Harddisk0\DR0 ( Rootkit.Win32.TDSS.tdl4 ) - infected
02:23:28.0609 3236 \Device\Harddisk0\DR0 - detected Rootkit.Win32.TDSS.tdl4 (0)
02:23:28.0656 3236 \Device\Harddisk0\DR0 ( TDSS File System ) - warning
02:23:28.0656 3236 \Device\Harddisk0\DR0 - detected TDSS File System (1)
02:23:28.0687 3236 Boot (0x1200) (0f91edacb7bc2e09459859f3f7b3c484) \Device\Harddisk0\DR0\Partition0
02:23:28.0687 3236 \Device\Harddisk0\DR0\Partition0 - ok
02:23:28.0703 3236 ============================================================
02:23:28.0703 3236 Scan finished
02:23:28.0703 3236 ============================================================
02:23:28.0812 3248 Detected object count: 6
02:23:28.0812 3248 Actual detected object count: 6
02:23:40.0484 3248 APPDRV ( UnsignedFile.Multi.Generic ) - skipped by user
02:23:40.0484 3248 APPDRV ( UnsignedFile.Multi.Generic ) - User select action: Skip
02:23:40.0484 3248 DSproct ( UnsignedFile.Multi.Generic ) - skipped by user
02:23:40.0484 3248 DSproct ( UnsignedFile.Multi.Generic ) - User select action: Skip
02:23:40.0484 3248 PxHelp20 ( UnsignedFile.Multi.Generic ) - skipped by user
02:23:40.0484 3248 PxHelp20 ( UnsignedFile.Multi.Generic ) - User select action: Skip
02:23:40.0500 3248 SDDMI2 ( UnsignedFile.Multi.Generic ) - skipped by user
02:23:40.0500 3248 SDDMI2 ( UnsignedFile.Multi.Generic ) - User select action: Skip
02:23:40.0500 3248 \Device\Harddisk0\DR0 ( Rootkit.Win32.TDSS.tdl4 ) - will be cured on reboot
02:23:40.0500 3248 \Device\Harddisk0\DR0 - ok
02:23:40.0500 3248 \Device\Harddisk0\DR0 ( Rootkit.Win32.TDSS.tdl4 ) - User select action: Cure
02:23:40.0500 3248 \Device\Harddisk0\DR0 ( TDSS File System ) - skipped by user
02:23:40.0500 3248 \Device\Harddisk0\DR0 ( TDSS File System ) - User select action: Skip
02:23:51.0187 0960 Deinitialize success
  • 0

#8
Essexboy

Essexboy

    GeekU Moderator

  • Retired Staff
  • 69,964 posts
Lets see if we can cure that next, as some files that I have removed are respawning


Download ComboFix from one of the following locations:
Link 1
Link 2

VERY IMPORTANT !!! Save ComboFix.exe to your Desktop

* IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here

  • Double click on ComboFix.exe & follow the prompts.
  • Accept the disclaimer and allow to update if it asks, also allow the recovery console to be installed

    Posted Image

    Posted Image
  • When finished, it shall produce a log for you.
  • Please include the C:\ComboFix.txt in your next reply.

Notes:
1. Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. Do not "re-run" Combofix. If you have a problem, reply back for further instructions.


Please make sure you include the combo fix log in your next reply as well as describe how your computer is running now
  • 0

#9
Boomrad

Boomrad

    Member

  • Topic Starter
  • Member
  • PipPip
  • 17 posts
Things seem to be running much better... I absent-mindedly told Combofix not to install the recovery console though, not sure how much of an effect that has on the clean-up overall. :/ Here's the log and, as always, allow me to express my thanks; this time in haiku:

My system was shot
Yet your wizardry prevails
Geek on, magic man!

ComboFix 11-11-07.02 - Matthew 11/07/2011 0:13.1.1 - x86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.894.405 [GMT -7:00]
Running from: c:\documents and settings\Matthew\My Documents\Downloads\ComboFix.exe
AV: avast! Antivirus *Disabled/Outdated* {7591DB91-41F0-48A3-B128-1A293FD8233D}
FW: Norton Internet Worm Protection *Disabled* {990F9400-4CEE-43EA-A83A-D013ADD8EA6E}
.
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\documents and settings\All Users\Application Data\91142176.ini
c:\documents and settings\All Users\Desktop\Security Protection.lnk
c:\documents and settings\Josh\Local Settings\Application Data\{AC2F4FDB-87C1-48E6-8868-C375623AF577}
c:\documents and settings\Josh\Local Settings\Application Data\{AC2F4FDB-87C1-48E6-8868-C375623AF577}\chrome.manifest
c:\documents and settings\Josh\Local Settings\Application Data\{AC2F4FDB-87C1-48E6-8868-C375623AF577}\chrome\content\_cfg.js
c:\documents and settings\Josh\Local Settings\Application Data\{AC2F4FDB-87C1-48E6-8868-C375623AF577}\chrome\content\overlay.xul
c:\documents and settings\Josh\Local Settings\Application Data\{AC2F4FDB-87C1-48E6-8868-C375623AF577}\install.rdf
c:\documents and settings\Matthew\Application Data\2752.1AC
c:\documents and settings\Matthew\Application Data\iniasd.txt
c:\documents and settings\Matthew\Local Settings\Application Data\{7EC8EF17-B3B5-4943-8AF5-B91B0863BB75}
c:\documents and settings\Matthew\Local Settings\Application Data\{7EC8EF17-B3B5-4943-8AF5-B91B0863BB75}\chrome.manifest
c:\documents and settings\Matthew\Local Settings\Application Data\{7EC8EF17-B3B5-4943-8AF5-B91B0863BB75}\chrome\content\_cfg.js
c:\documents and settings\Matthew\Local Settings\Application Data\{7EC8EF17-B3B5-4943-8AF5-B91B0863BB75}\chrome\content\c.js
c:\documents and settings\Matthew\Local Settings\Application Data\{7EC8EF17-B3B5-4943-8AF5-B91B0863BB75}\chrome\content\overlay.xul
c:\documents and settings\Matthew\Local Settings\Application Data\{7EC8EF17-B3B5-4943-8AF5-B91B0863BB75}\install.rdf
c:\documents and settings\Matthew\My Documents\~WRL1439.tmp
c:\documents and settings\Matthew\My Documents\~WRL3719.tmp
c:\documents and settings\Matthew\Start Menu\Programs\Windows XP Recovery
c:\documents and settings\Matthew\Start Menu\Programs\Windows XP Recovery\Uninstall Windows XP Recovery.lnk
c:\documents and settings\Matthew\Start Menu\Programs\Windows XP Recovery\Windows XP Recovery.lnk
c:\documents and settings\Matthew\WINDOWS
.
c:\windows\system32\proquota.exe was missing
Restored copy from - c:\i386\proquota.exe
.
.
((((((((((((((((((((((((( Files Created from 2011-10-07 to 2011-11-07 )))))))))))))))))))))))))))))))
.
.
2011-11-07 07:23 . 2004-08-04 11:00 50176 ----a-w- c:\windows\system32\proquota.exe
2011-11-07 07:23 . 2004-08-04 11:00 50176 ----a-w- c:\windows\system32\dllcache\proquota.exe
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-09-01 00:00 . 2010-07-16 22:44 22216 ----a-w- c:\windows\system32\drivers\mbam.sys
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast]
@="{472083B0-C522-11CF-8763-00608CC02F24}"
[HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}]
2011-02-23 15:04 122512 ----a-w- c:\program files\AVAST Software\Avast\ashShell.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ModemOnHold"="c:\program files\NetWaiting\NetWaiting.exe" [2003-09-10 20480]
"DellSupport"="c:\program files\Dell Support\DSAgnt.exe" [2006-07-17 389120]
"Skype"="c:\program files\Skype\Phone\Skype.exe" [2010-10-11 14940040]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2009-11-11 417792]
"avast"="c:\program files\AVAST Software\Avast\avastUI.exe" [2011-02-23 3451496]
"CenturyLinkTouchPointAgent"="c:\program files\CenturyLink\Desktop\CenturyLinkTouchPointAgent.exe" [2011-07-12 46208]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"DWQueuedReporting"="c:\progra~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2007-02-26 437160]
.
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-9-23 29696]
Digital Line Detect.lnk - c:\program files\Digital Line Detect\DLG.exe [2006-11-14 24576]
GigaTribe.lnk - c:\program files\GigaTribe\gigatribe.exe [N/A]
Microsoft Office.lnk - c:\program files\Microsoft Office\Office\OSA9.EXE [2000-1-21 65588]
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
"FirewallOverride"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
"DisableNotifications"= 1 (0x1)
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Qwest\\QuickConnect\\QuickConnect.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\Azureus\\Azureus.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\Program Files\\Skype\\Plugin Manager\\skypePM.exe"=
"c:\\Program Files\\Java\\jre6\\bin\\java.exe"=
.
R1 aswSnx;aswSnx;c:\windows\system32\drivers\aswSnx.sys [4/17/2011 6:45 PM 371544]
R1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [4/17/2011 6:45 PM 301528]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [4/17/2011 6:45 PM 19544]
R2 sprtlisten;SupportSoft Listener Service;c:\program files\Common Files\supportsoft\bin\sprtlisten.exe [1/8/2008 12:02 PM 1213728]
S0 podhrzwb;podhrzwb;c:\windows\system32\drivers\gtkqbo.sys --> c:\windows\system32\drivers\gtkqbo.sys [?]
.
--- Other Services/Drivers In Memory ---
.
*NewlyCreated* - WUAUSERV
.
.
------- Supplementary Scan -------
.
uStart Page = qwest.live.com
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
mStart Page = hxxp://www.dell.com
uInternet Settings,ProxyOverride = <local>
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: &Windows Live Search - c:\program files\Windows Live Toolbar\msntb.dll/search.htm
IE: Add to Windows &Live Favorites - http://favorites.liv...m/quickadd.aspx
TCP: DhcpNameServer = 192.168.0.1 205.171.3.25
FF - ProfilePath - c:\documents and settings\Matthew\Application Data\Mozilla\Firefox\Profiles\xn4cc6wh.default\
FF - prefs.js: browser.startup.homepage - hxxp://marriedtothesea.com/
FF - prefs.js: network.proxy.http - 127.0.0.1
FF - prefs.js: network.proxy.http_port - 56808
FF - prefs.js: network.proxy.type - 4
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: Skype extension: {AB2CE124-6272-4b12-94A9-7303C7397BD1} - c:\program files\Mozilla Firefox\extensions\{AB2CE124-6272-4b12-94A9-7303C7397BD1}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA}
FF - Ext: Forecastfox Weather: {0538E3E3-7E9B-4d49-8831-A227C80A7AD3} - %profile%\extensions\{0538E3E3-7E9B-4d49-8831-A227C80A7AD3}
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - %profile%\extensions\{20a82645-c095-46ed-80e3-08825760534b}
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
FF - Ext: Java Quick Starter: [email protected] - c:\program files\Java\jre6\lib\deploy\jqs\ff
FF - Ext: avast! WebRep: [email protected] - c:\program files\AVAST Software\Avast\WebRep\FF
FF - user.js: network.cookie.cookieBehavior - 0
FF - user.js: privacy.clearOnShutdown.cookies - false
FF - user.js: security.warn_viewing_mixed - false
FF - user.js: security.warn_viewing_mixed.show_once - false
FF - user.js: security.warn_submit_insecure - false
FF - user.js: security.warn_submit_insecure.show_once - false
.
- - - - ORPHANS REMOVED - - - -
.
HKCU-Run-Rbexeju - c:\windows\wsecuil.dll
SafeBoot-WinDefend
AddRemove-ShockwaveFlash - c:\windows\system32\Macromed\Flash\FlashUtil9b.exe
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2011-11-07 00:27
Windows 5.1.2600 Service Pack 2 NTFS
.
scanning hidden processes ...
.
scanning hidden autostart entries ...
.
scanning hidden files ...
.
.
C:\## aswSnx private storage
.
scan completed successfully
hidden files: 1
.
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
.
- - - - - - - > 'winlogon.exe'(824)
c:\windows\system32\Ati2evxx.dll
.
- - - - - - - > 'explorer.exe'(792)
c:\program files\iTunes\iTunesMiniPlayer.dll
c:\program files\iTunes\iTunesMiniPlayer.Resources\en.lproj\iTunesMiniPlayerLocalized.dll
c:\program files\iTunes\iTunesMiniPlayer.Resources\iTunesMiniPlayer.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Other Running Processes ------------------------
.
c:\windows\system32\Ati2evxx.exe
c:\windows\system32\Ati2evxx.exe
c:\windows\System32\WLTRYSVC.EXE
c:\windows\System32\bcmwltry.exe
c:\program files\AVAST Software\Avast\AvastSvc.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Dell\QuickSet\NICCONFIGSVC.exe
c:\program files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
c:\program files\Skype\Plugin Manager\skypePM.exe
.
**************************************************************************
.
Completion time: 2011-11-07 00:34:08 - machine was rebooted
ComboFix-quarantined-files.txt 2011-11-07 07:33
.
Pre-Run: 176,443,392 bytes free
Post-Run: 3,509,854,208 bytes free
.
- - End Of File - - E287C2CD27AD9F6D1DE5BD28A9E2B265
  • 0

#10
Essexboy

Essexboy

    GeekU Moderator

  • Retired Staff
  • 69,964 posts
OK one more to go before we do an orphan sweep. Allow combofix to install the recovery console and update if it asks

1. Close any open browsers.
2. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.
3. Open notepad and copy/paste the text in the quotebox below into it:

File::
c:\windows\system32\drivers\gtkqbo.sys

Driver::
podhrzwb

Save this as CFScript.txt, in the same location as ComboFix.exe
Posted Image

Refering to the picture above, drag CFScript into ComboFix.exeWhen finished, it shall produce a log for you at C:\ComboFix.txt which I will require in your next reply.

THEN

Please download Malwarebytes' Anti-Malware

Double Click mbam-setup.exe to install the application.
  • Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish, so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected.
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.
Extra Note:
If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts, click OK to either and let MBAM proceed with the disinfection process, if asked to restart the computer, please do so immediately.
  • 0

Advertisements


#11
Boomrad

Boomrad

    Member

  • Topic Starter
  • Member
  • PipPip
  • 17 posts
It's strange, I'm still being forced to manually connect to any wireless network upon login, but perhaps this has nothing to do with malware as everything else is now completely functional. Here are the logs, and thank you ever so much.

ComboFix 11-11-09.02 - Matthew 11/09/2011 19:48:24.2.1 - x86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.894.489 [GMT -7:00]
Running from: c:\documents and settings\Matthew\My Documents\Downloads\ComboFix.exe
Command switches used :: c:\documents and settings\Matthew\Desktop\CFScript.txt
AV: avast! Antivirus *Disabled/Outdated* {7591DB91-41F0-48A3-B128-1A293FD8233D}
FW: Norton Internet Worm Protection *Disabled* {990F9400-4CEE-43EA-A83A-D013ADD8EA6E}
.
FILE ::
"c:\windows\system32\drivers\gtkqbo.sys"
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
-------\Service_podhrzwb
.
.
((((((((((((((((((((((((( Files Created from 2011-10-10 to 2011-11-10 )))))))))))))))))))))))))))))))
.
.
2011-11-07 07:23 . 2004-08-04 11:00 50176 ----a-w- c:\windows\system32\proquota.exe
2011-11-07 07:23 . 2004-08-04 11:00 50176 ----a-w- c:\windows\system32\dllcache\proquota.exe
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-09-01 00:00 . 2010-07-16 22:44 22216 ----a-w- c:\windows\system32\drivers\mbam.sys
.
.
((((((((((((((((((((((((((((( SnapShot@2011-11-07_07.28.02 )))))))))))))))))))))))))))))))))))))))))
.
+ 2011-11-10 02:59 . 2011-11-10 02:59 16384 c:\windows\Temp\Perflib_Perfdata_7f8.dat
+ 2011-02-27 07:13 . 2011-11-08 09:03 49152 c:\windows\Installer\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}\ConfigIcon.dll
- 2011-02-27 07:13 . 2011-02-27 07:13 49152 c:\windows\Installer\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}\ConfigIcon.dll
+ 2010-02-26 07:11 . 2011-10-05 17:09 48324552 c:\windows\system32\MRT.exe
+ 2011-11-08 09:01 . 2011-11-08 09:01 20333568 c:\windows\Installer\83bf2.msp
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast]
@="{472083B0-C522-11CF-8763-00608CC02F24}"
[HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}]
2011-02-23 15:04 122512 ----a-w- c:\program files\AVAST Software\Avast\ashShell.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ModemOnHold"="c:\program files\NetWaiting\NetWaiting.exe" [2003-09-10 20480]
"DellSupport"="c:\program files\Dell Support\DSAgnt.exe" [2006-07-17 389120]
"Skype"="c:\program files\Skype\Phone\Skype.exe" [2010-10-11 14940040]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2009-11-11 417792]
"avast"="c:\program files\AVAST Software\Avast\avastUI.exe" [2011-02-23 3451496]
"CenturyLinkTouchPointAgent"="c:\program files\CenturyLink\Desktop\CenturyLinkTouchPointAgent.exe" [2011-07-12 46208]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"DWQueuedReporting"="c:\progra~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2007-02-26 437160]
.
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-9-23 29696]
Digital Line Detect.lnk - c:\program files\Digital Line Detect\DLG.exe [2006-11-14 24576]
GigaTribe.lnk - c:\program files\GigaTribe\gigatribe.exe [N/A]
Microsoft Office.lnk - c:\program files\Microsoft Office\Office\OSA9.EXE [2000-1-21 65588]
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
"FirewallOverride"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
"DisableNotifications"= 1 (0x1)
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Qwest\\QuickConnect\\QuickConnect.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\Azureus\\Azureus.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\Program Files\\Skype\\Plugin Manager\\skypePM.exe"=
"c:\\Program Files\\Java\\jre6\\bin\\java.exe"=
.
R1 aswSnx;aswSnx;c:\windows\system32\drivers\aswSnx.sys [4/17/2011 6:45 PM 371544]
R1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [4/17/2011 6:45 PM 301528]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [4/17/2011 6:45 PM 19544]
R2 sprtlisten;SupportSoft Listener Service;c:\program files\Common Files\supportsoft\bin\sprtlisten.exe [1/8/2008 12:02 PM 1213728]
.
.
------- Supplementary Scan -------
.
uStart Page = qwest.live.com
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
mStart Page = hxxp://www.dell.com
uInternet Settings,ProxyOverride = <local>
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: &Windows Live Search - c:\program files\Windows Live Toolbar\msntb.dll/search.htm
IE: Add to Windows &Live Favorites - http://favorites.liv...m/quickadd.aspx
TCP: DhcpNameServer = 192.168.0.1 205.171.3.25
FF - ProfilePath - c:\documents and settings\Matthew\Application Data\Mozilla\Firefox\Profiles\xn4cc6wh.default\
FF - prefs.js: browser.startup.homepage - hxxp://marriedtothesea.com/
FF - prefs.js: network.proxy.http - 127.0.0.1
FF - prefs.js: network.proxy.http_port - 56808
FF - prefs.js: network.proxy.type - 4
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: Skype extension: {AB2CE124-6272-4b12-94A9-7303C7397BD1} - c:\program files\Mozilla Firefox\extensions\{AB2CE124-6272-4b12-94A9-7303C7397BD1}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA}
FF - Ext: Forecastfox Weather: {0538E3E3-7E9B-4d49-8831-A227C80A7AD3} - %profile%\extensions\{0538E3E3-7E9B-4d49-8831-A227C80A7AD3}
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - %profile%\extensions\{20a82645-c095-46ed-80e3-08825760534b}
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
FF - Ext: Java Quick Starter: [email protected] - c:\program files\Java\jre6\lib\deploy\jqs\ff
FF - Ext: avast! WebRep: [email protected] - c:\program files\AVAST Software\Avast\WebRep\FF
FF - user.js: network.cookie.cookieBehavior - 0
FF - user.js: privacy.clearOnShutdown.cookies - false
FF - user.js: security.warn_viewing_mixed - false
FF - user.js: security.warn_viewing_mixed.show_once - false
FF - user.js: security.warn_submit_insecure - false
FF - user.js: security.warn_submit_insecure.show_once - false
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2011-11-09 20:26
Windows 5.1.2600 Service Pack 2 NTFS
.
scanning hidden processes ...
.
scanning hidden autostart entries ...
.
scanning hidden files ...
.
.
C:\## aswSnx private storage
.
scan completed successfully
hidden files: 1
.
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
.
- - - - - - - > 'winlogon.exe'(824)
c:\windows\system32\Ati2evxx.dll
.
- - - - - - - > 'explorer.exe'(3148)
c:\program files\iTunes\iTunesMiniPlayer.dll
c:\program files\iTunes\iTunesMiniPlayer.Resources\en.lproj\iTunesMiniPlayerLocalized.dll
c:\program files\iTunes\iTunesMiniPlayer.Resources\iTunesMiniPlayer.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Other Running Processes ------------------------
.
c:\windows\system32\Ati2evxx.exe
c:\windows\system32\Ati2evxx.exe
c:\windows\System32\WLTRYSVC.EXE
c:\windows\System32\bcmwltry.exe
c:\program files\AVAST Software\Avast\AvastSvc.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Dell\QuickSet\NICCONFIGSVC.exe
c:\program files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
c:\program files\Skype\Plugin Manager\skypePM.exe
.
**************************************************************************
.
Completion time: 2011-11-09 20:32:59 - machine was rebooted
ComboFix-quarantined-files.txt 2011-11-10 03:32
ComboFix2.txt 2011-11-07 07:34
.
Pre-Run: 3,431,280,640 bytes free
Post-Run: 3,394,555,904 bytes free
.
WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
UnsupportedDebug="do not select this" /debug
multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Microsoft Windows XP Home Edition" /noexecute=optin /fastdetect
.
- - End Of File - - 59D4549A67E3DCDBE3E1FFEBCEC14BC1



Malwarebytes' Anti-Malware 1.51.2.1300
www.malwarebytes.org

Database version: 8129

Windows 5.1.2600 Service Pack 2
Internet Explorer 6.0.2900.2180

11/9/2011 8:54:11 PM
mbam-log-2011-11-09 (20-54-11).txt

Scan type: Quick scan
Objects scanned: 200121
Time elapsed: 6 minute(s), 56 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)
  • 0

#12
Essexboy

Essexboy

    GeekU Moderator

  • Retired Staff
  • 69,964 posts
Ok next we will reset the Firefox proxy settings

Firefox connection settings

To check your Firefox proxy settings:

At the top of the Firefox window, click on the Edit menu and select Preferences....
Select the Advanced panel.
Select the Network tab.
In the Connection section, click Settings....
Change your proxy settings:
Select No Proxy.
Close the Connection Settings window.
Click OK to close the Options windowClick Close to close the Preferences windowClose the Preferences window.

For the wireless autostart it sounds as though zero config is not set - There is a step by step guide here... Let me know if that works

Subject to no further problems :)

I will remove my tools now and give some recommendations, but, I would like you to run for 24 hours or so and come back if you have any problems

Now the best part of the day ----- Your log now appears clean :)

A good workman always cleans up after himself so..The following will implement some cleanup procedures as well as reset System Restore points:

Run OTL
  • Under the Custom Scans/Fixes box at the bottom, paste in the following

    :Commands
    [resethosts]
    [purity]
    [emptytemp]
    [EMPTYFLASH]
    [CLEARALLRESTOREPOINTS]
    [Reboot]

  • Then click the Run Fix button at the top
  • Let the program run unhindered, reboot the PC when it is done

Remove ComboFix
  • Hold down the Windows key + R on your keyboard. This will display the Run dialogue box
  • In the Run box, type in ComboFix /Uninstall
    (Notice the space between the "x" and "/")
    then click OK

    Posted Image
  • Follow the prompts on the screen
  • A message should appear confirming that ComboFix was uninstalled

Run OTL and hit the cleanup button. It will remove all the programmes we have used plus itself.

We will now confirm that your hidden files are set to that, as some of the tools I use will change that
  • Click Start.
  • Open My Computer.
  • Select the Tools menu and click Folder Options.
  • Select the View Tab.
  • Under the Hidden files and folders heading select Do not show hidden files and folders.
  • Click Yes to confirm.
  • Click OK.

Posted Image Your Java is out of date.
Older versions have vulnerabilities that malware can use to infect your system.
Please follow these steps to remove older version of Java components and upgrade the application.

Upgrading Java:
  • Go to this site and click Do I have Java
  • It will check your current version and then offer to update to the latest version


Now that you are clean, to help protect your computer in the future I recommend that you get the following free programmes:

Posted Image Malwarebytes.

Update and run weekly to keep your system clean

Download and install FileHippo update checker and run it monthly it will show you which programmes on your system need updating and give a download link

It is critical to have both a firewall and anti virus to protect your system and to keep them updated. To keep your operating system up to date visit
To learn more about how to protect yourself while on the internet read our little guide How did I get infected in the first place ?Keep safe :yes:
  • 0

#13
Essexboy

Essexboy

    GeekU Moderator

  • Retired Staff
  • 69,964 posts
Since this issue appears to be resolved ... this Topic has been closed. Glad we could help. :)

If you're the topic starter, and need this topic reopened, please contact a staff member with the address of the thread.

Everyone else please begin a New Topic.
  • 0

#14
Essexboy

Essexboy

    GeekU Moderator

  • Retired Staff
  • 69,964 posts
We will use an mobile operating system called xPUD, and a script called rst.sh to restore your computer.

On the clean computer.

Creating a bootable USB using xPUD
  • Please download the following files and save it to the desktop
  • Insert the USB device to make bootable to the computer. (Make sure that no other USB's are inserted)
  • Double-click on unetbootin.exe to run
  • Select Disk Image, ISO and in the space provided, enter the path location of xpud-0.9.2.iso (ex. C:\Documents and Settings\yourusername\Desktop\xpud-0.9.2.iso)
  • Select USB Drive type and the drive letter assigned to your USB stick.
  • Click "OK" and wait until the program finishes. You now have a bootable xPUD.
  • Download the following tool and save it inside the bootable USB

Please note: if you prefer to create a bootable CD using xPUD, you may download the ISO image found here and burn it to a CD.



On the infected computer.
  • Reboot your system using the xPUD bootable USB you just created.
    Note : If you do not know how to set your computer to boot from USB follow the steps here
  • Your system should now display a xPUD desktop.
  • Select on the File icon; on the right pane click on the "mnt" folder and highlight "sdb1" - this is your USB device.

    sda1,2...usually corresponds to your HDD
    sdb1 is likely your USB

  • Click on the "Tool" menu and select Open Terminal
    Posted Image
  • In the open terminal window, type in the following:

    bash rst.sh
  • Press "Enter" and let it run uninterrupted.
    (The program lists available Restore Points and will save a report enum.log located in the USB drive.)
  • The program is finished when it say's "Done".
  • Type "Exit" to close the terminal window.
  • Please attached the enum.log file in your reply. (You may remove your USB drive when transferring log to a clean computer).

Please note: If you have an ethernet connection you can access the internet by way of xPUD (Firefox). You can perform all these steps on your sick computer. When you download the download will reside in the Download folder. It can be found under the File tab also. You can similarly access our thread by way of this OS too so you can send the logs that way.
  • 0

#15
Boomrad

Boomrad

    Member

  • Topic Starter
  • Member
  • PipPip
  • 17 posts
Ok, steps followed... things seem successful thus far, thank you again for helping me through this. As per your question, there were no power outages that I know of, and though I've had to manually shut down the system several times (ie holding down the power button), I've never pulled the plug while it was running. I've included the enum.log here, though it appears to be blank. Not quite sure if that means there are no restore points, or that I didn't do something exactly right. :/ Hope you can help!
Thanksandthanksandeverthanks!

Attached Files

  • Attached File  enum.log   592bytes   155 downloads

  • 0






Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP