Jump to content

Welcome to Geeks to Go - Register now for FREE

Geeks To Go is a helpful hub, where thousands of volunteer geeks quickly serve friendly answers and support. Check out the forums and get free advice from the experts. Register now to gain access to all of our features, it's FREE and only takes one minute. Once registered and logged in, you will be able to create topics, post replies to existing threads, give reputation to your fellow members, get your own private messenger, post status updates, manage your profile and so much more.

Create Account How it Works
Photo

Computer slow + Google redirects + windows opening on their own


  • Please log in to reply

#31
Leo2012

Leo2012

    Member

  • Topic Starter
  • Member
  • PipPip
  • 44 posts
https://www.virustot...sis/1327803083/
  • 0

Advertisements


#32
Leo2012

Leo2012

    Member

  • Topic Starter
  • Member
  • PipPip
  • 44 posts
When I watch videos on YouTube or play streaming music, the music comes out stuttering. I can tell there's something still running/happening in my computer.
  • 0

#33
Cookiegal

Cookiegal

    Visiting Consultant

  • Visiting Consultant
  • 887 posts
Please run SystemLook again with the following script and post the results:

:filefind
ipsec.*

  • 0

#34
Leo2012

Leo2012

    Member

  • Topic Starter
  • Member
  • PipPip
  • 44 posts
SystemLook 30.07.11 by jpshortstuff
Log created at 22:36 on 28/01/2012 by Ziad
Administrator - Elevation successful

========== filefind ==========

Searching for "ipsec.*"
C:\I386\IPSEC.SY_ --a---- 39956 bytes [20:01 21/07/2008] [12:00 14/04/2008] 831C0ED52C21602AE3F735A1F04055E1
C:\WINDOWS\system32\dllcache\ipsec.sys --a--c- 75264 bytes [20:04 21/07/2008] [05:49 14/04/2008] 23C74D75E36E7158768DD63D92789A91
C:\WINDOWS\system32\drivers\ipsec.sys --a---- 75264 bytes [20:04 21/07/2008] [05:49 14/04/2008] 23C74D75E36E7158768DD63D92789A91

-= EOF =-
  • 0

#35
Cookiegal

Cookiegal

    Visiting Consultant

  • Visiting Consultant
  • 887 posts
Please run OTL again as you did at the beginning and post the new log.
  • 0

#36
Leo2012

Leo2012

    Member

  • Topic Starter
  • Member
  • PipPip
  • 44 posts
OTL logfile created on: 1/29/2012 11:49:43 AM - Run 2
OTL by OldTimer - Version 3.2.31.0 Folder = C:\Documents and Settings\Ziad\Desktop
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

1014.36 Mb Total Physical Memory | 101.80 Mb Available Physical Memory | 10.04% Memory free
2.39 Gb Paging File | 1.48 Gb Available in Paging File | 62.09% Paging File free
Paging file location(s): C:\pagefile.sys 1524 3048 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 146.63 Gb Total Space | 106.47 Gb Free Space | 72.61% Space Free | Partition Type: NTFS

Computer Name: LENOVO-D4F96F23 | User Name: Ziad | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - [2012/01/29 11:02:26 | 000,492,840 | ---- | M] (eBay) -- C:\Program Files\tbh\base\bin\tbhSystray.exe
PRC - [2012/01/29 11:02:20 | 000,070,952 | ---- | M] () -- c:\Program Files\tbh\base\bin\tbhDaemon.exe
PRC - [2012/01/20 22:14:35 | 000,584,192 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Ziad\Desktop\OTL.exe
PRC - [2012/01/04 14:33:42 | 001,652,536 | ---- | M] (Trusteer Ltd.) -- C:\Program Files\Trusteer\Rapport\bin\RapportService.exe
PRC - [2012/01/04 14:33:42 | 000,931,640 | ---- | M] (Trusteer Ltd.) -- C:\Program Files\Trusteer\Rapport\bin\RapportMgmtService.exe
PRC - [2011/10/13 17:21:52 | 000,249,648 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Microsoft\BingBar\SeaPort.EXE
PRC - [2011/09/23 18:08:19 | 000,086,224 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Program Files\Avira\AntiVir Desktop\sched.exe
PRC - [2011/09/23 18:01:09 | 000,110,032 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Program Files\Avira\AntiVir Desktop\avguard.exe
PRC - [2011/09/23 11:38:21 | 000,258,512 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
PRC - [2011/09/16 02:34:43 | 000,080,336 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Program Files\Avira\AntiVir Desktop\avshadow.exe
PRC - [2011/08/23 21:20:18 | 000,887,976 | ---- | M] (Ask) -- C:\Program Files\Ask.com\Updater\Updater.exe
PRC - [2011/04/18 13:11:40 | 000,028,672 | ---- | M] (Lenovo Group Limited) -- c:\Program Files\Lenovo\System Update\SUService.exe
PRC - [2011/04/08 11:59:52 | 000,507,624 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\Common Files\Java\Java Update\jucheck.exe
PRC - [2009/10/22 16:57:44 | 000,070,952 | ---- | M] () -- C:\Program Files\tbh\monitor\bin\tbhMonitor.exe
PRC - [2009/04/20 21:02:55 | 000,323,584 | ---- | M] () -- C:\Program Files\Lenovo\VeriFaceIII\PManage.exe
PRC - [2009/01/16 19:56:42 | 000,604,776 | ---- | M] (Broadcom Corporation.) -- C:\Program Files\Lenovo\Bluetooth Software\BTTray.exe
PRC - [2009/01/16 19:56:42 | 000,346,720 | ---- | M] (Broadcom Corporation.) -- C:\Program Files\Lenovo\Bluetooth Software\bin\btwdins.exe
PRC - [2008/12/01 20:32:30 | 000,307,200 | -H-- | M] (DeviceVM) -- C:\QSTART.SYS\config\DVMExportService.exe
PRC - [2008/08/28 17:10:18 | 001,283,984 | ---- | M] (Lenovo (Beijing) Limited) -- C:\Program Files\Lenovo\Energy Management\Energy Management.exe
PRC - [2008/07/09 18:21:20 | 004,456,448 | ---- | M] (Lenovo(Beijing)Limited) -- C:\Program Files\Lenovo\Energy Management\utility.exe
PRC - [2008/04/23 05:08:13 | 000,483,328 | ---- | M] (Adobe Systems Inc.) -- C:\Program Files\Adobe\Acrobat 7.0\Distillr\acrotray.exe
PRC - [2008/04/14 07:00:00 | 001,033,728 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe
PRC - [2007/09/26 16:34:46 | 000,644,408 | ---- | M] (Lenovo Group Limited) -- C:\Program Files\Common Files\Lenovo\tvt_reg_monitor_svc.exe


========== Modules (No Company Name) ==========

MOD - [2012/01/29 11:02:20 | 000,070,952 | ---- | M] () -- c:\Program Files\tbh\base\bin\tbhDaemon.exe
MOD - [2011/11/10 16:11:00 | 000,557,056 | ---- | M] () -- C:\Program Files\Trusteer\Rapport\bin\js32.dll
MOD - [2011/10/12 07:06:00 | 000,212,992 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.ServiceProce#\abef85f2fb8ba830eda73e2d12e8d41e\System.ServiceProcess.ni.dll
MOD - [2011/10/12 07:05:40 | 000,998,400 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Management\90b90e700e59d73d6d692cf74e1ba16e\System.Management.ni.dll
MOD - [2011/10/12 06:48:59 | 005,450,752 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Xml\70cacc44f0b4257f6037eda7a59a0aeb\System.Xml.ni.dll
MOD - [2011/10/11 22:16:10 | 007,950,848 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System\af39f6e644af02873b9bae319f2bfb13\System.ni.dll
MOD - [2011/10/11 22:15:46 | 011,490,816 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\mscorlib\ca87ba84221991839abbe7d4bc9c6721\mscorlib.ni.dll
MOD - [2011/09/27 06:23:00 | 000,087,912 | ---- | M] () -- C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll
MOD - [2011/09/27 06:22:40 | 001,242,472 | ---- | M] () -- C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll
MOD - [2011/09/16 02:05:58 | 000,398,288 | ---- | M] () -- C:\Program Files\Avira\AntiVir Desktop\sqlite3.dll
MOD - [2011/08/07 09:44:07 | 000,516,368 | ---- | M] () -- C:\Documents and Settings\All Users\Application Data\Trusteer\Rapport\store\exts\RapportMS\28896\RapportMS.dll
MOD - [2009/10/22 16:57:44 | 000,070,952 | ---- | M] () -- C:\Program Files\tbh\monitor\bin\tbhMonitor.exe
MOD - [2009/04/20 21:02:59 | 009,338,880 | ---- | M] () -- C:\WINDOWS\system32\Facev.dll
MOD - [2009/04/20 21:02:59 | 000,036,352 | ---- | M] () -- C:\Program Files\Lenovo\VeriFaceIII\Time.dll
MOD - [2009/04/20 21:02:58 | 000,241,752 | ---- | M] () -- C:\WINDOWS\system32\IcnOvrly.dll
MOD - [2009/04/20 21:02:58 | 000,053,248 | ---- | M] () -- C:\WINDOWS\system32\FunFrm.dll
MOD - [2009/04/20 21:02:57 | 001,564,672 | ---- | M] () -- C:\WINDOWS\system32\MainOp.dll
MOD - [2009/04/20 21:02:57 | 000,221,184 | ---- | M] () -- C:\WINDOWS\system32\SetDev.dll
MOD - [2009/04/20 21:02:57 | 000,126,976 | ---- | M] () -- C:\WINDOWS\system32\VideoOp.dll
MOD - [2009/04/20 21:02:56 | 009,502,720 | ---- | M] () -- C:\WINDOWS\system32\FaceVerify.dll
MOD - [2009/04/20 21:02:56 | 001,167,360 | ---- | M] () -- C:\WINDOWS\system32\PicNotify.dll
MOD - [2009/04/20 21:02:56 | 000,974,848 | ---- | M] () -- C:\WINDOWS\system32\Apblend.dll
MOD - [2009/04/20 21:02:56 | 000,094,208 | ---- | M] () -- C:\WINDOWS\system32\Momo.dll
MOD - [2009/04/20 21:02:55 | 000,323,584 | ---- | M] () -- C:\Program Files\Lenovo\VeriFaceIII\PManage.exe
MOD - [2009/04/20 21:02:55 | 000,208,896 | ---- | M] () -- C:\WINDOWS\system32\image.dll
MOD - [2009/01/16 19:55:38 | 002,854,976 | ---- | M] () -- C:\WINDOWS\system32\btwicons.dll
MOD - [2009/01/16 19:53:32 | 000,069,697 | ---- | M] () -- C:\Program Files\Lenovo\Bluetooth Software\BTKeyInd.dll
MOD - [2008/05/21 19:33:22 | 000,045,056 | ---- | M] () -- C:\Program Files\Lenovo\Energy Management\KbdHook.dll
MOD - [2005/06/24 05:05:02 | 000,045,056 | ---- | M] () -- C:\Program Files\Lenovo\Energy Management\HookLib.dll


========== Win32 Services (SafeList) ==========

SRV - File not found [On_Demand | Stopped] -- -- (AppMgmt)
SRV - [2012/01/04 14:33:42 | 000,931,640 | ---- | M] (Trusteer Ltd.) [Auto | Running] -- C:\Program Files\Trusteer\Rapport\bin\RapportMgmtService.exe -- (RapportMgmtService)
SRV - [2011/10/21 15:23:42 | 000,196,176 | ---- | M] (Microsoft Corporation.) [Auto | Stopped] -- C:\Program Files\Microsoft\BingBar\BBSvc.EXE -- (BBSvc)
SRV - [2011/10/13 17:21:52 | 000,249,648 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files\Microsoft\BingBar\SeaPort.EXE -- (BBUpdate)
SRV - [2011/09/23 18:08:19 | 000,086,224 | ---- | M] (Avira Operations GmbH & Co. KG) [Auto | Running] -- C:\Program Files\Avira\AntiVir Desktop\sched.exe -- (AntiVirSchedulerService)
SRV - [2011/09/23 18:01:09 | 000,110,032 | ---- | M] (Avira Operations GmbH & Co. KG) [Auto | Running] -- C:\Program Files\Avira\AntiVir Desktop\avguard.exe -- (AntiVirService)
SRV - [2011/04/18 13:11:40 | 000,028,672 | ---- | M] (Lenovo Group Limited) [Auto | Running] -- c:\Program Files\Lenovo\System Update\SUService.exe -- (SUService)
SRV - [2010/01/25 08:22:56 | 000,245,760 | ---- | M] (Brother Industries, Ltd.) [On_Demand | Stopped] -- C:\Program Files\Browny02\BrYNSvc.exe -- (BrYNSvc)
SRV - [2009/10/22 16:57:44 | 000,070,952 | ---- | M] () [Auto | Running] -- C:\Program Files\tbh\monitor\bin\tbhMonitor.exe -- (tbhMonitor.exe)
SRV - [2009/01/16 19:56:42 | 000,346,720 | ---- | M] (Broadcom Corporation.) [Auto | Running] -- C:\Program Files\Lenovo\Bluetooth Software\bin\btwdins.exe -- (btwdins)
SRV - [2008/12/01 20:32:30 | 000,307,200 | -H-- | M] (DeviceVM) [Auto | Running] -- C:\QSTART.SYS\config\DVMExportService.exe -- (DvmMDES)
SRV - [2007/09/26 16:34:46 | 000,644,408 | ---- | M] (Lenovo Group Limited) [Auto | Running] -- C:\Program Files\Common Files\Lenovo\tvt_reg_monitor_svc.exe -- (ThinkVantage Registry Monitor Service)


========== Driver Services (SafeList) ==========

DRV - [2012/01/26 21:56:18 | 000,134,856 | ---- | M] (Avira GmbH) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\avipbb.sys -- (avipbb)
DRV - [2012/01/04 14:33:56 | 000,164,112 | ---- | M] (Trusteer Ltd.) [Kernel | System | Running] -- C:\Program Files\Trusteer\Rapport\bin\RapportPG.sys -- (RapportPG)
DRV - [2012/01/04 14:33:56 | 000,071,440 | ---- | M] (Trusteer Ltd.) [Kernel | System | Running] -- C:\Program Files\Trusteer\Rapport\bin\RapportEI.sys -- (RapportEI)
DRV - [2012/01/04 14:33:56 | 000,056,208 | ---- | M] (Trusteer Ltd.) [Kernel | Boot | Running] -- C:\WINDOWS\System32\Drivers\RapportKELL.sys -- (RapportKELL)
DRV - [2011/12/18 00:41:48 | 000,228,208 | ---- | M] () [Kernel | System | Running] -- C:\Documents and Settings\All Users\Application Data\Trusteer\Rapport\store\exts\RapportCerberus\34302\RapportCerberus32_34302.sys -- (RapportCerberus_34302)
DRV - [2011/09/15 23:55:04 | 000,036,000 | ---- | M] (Avira GmbH) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\avkmgr.sys -- (avkmgr)
DRV - [2011/09/15 23:55:03 | 000,074,640 | ---- | M] (Avira GmbH) [File_System | Auto | Running] -- C:\WINDOWS\system32\drivers\avgntflt.sys -- (avgntflt)
DRV - [2011/08/07 09:44:07 | 000,021,520 | ---- | M] (Trusteer Ltd.) [Kernel | On_Demand | Running] -- c:\Documents and Settings\All Users\Application Data\Trusteer\Rapport\store\exts\RapportMS\28896\RapportIaso.sys -- (RapportIaso)
DRV - [2010/06/17 15:14:27 | 000,028,520 | ---- | M] (Avira GmbH) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\ssmdrv.sys -- (ssmdrv)
DRV - [2009/11/12 16:42:16 | 000,032,768 | ---- | M] (AnchorFree Inc) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\taphss.sys -- (taphss)
DRV - [2009/09/07 04:48:06 | 000,005,632 | ---- | M] () [File_System | System | Running] -- C:\WINDOWS\System32\drivers\StarOpen.sys -- (StarOpen)
DRV - [2009/07/22 14:13:20 | 000,028,592 | ---- | M] (The OpenVPN Project) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\tap0901.sys -- (tap0901)
DRV - [2009/02/18 05:31:04 | 005,028,352 | ---- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\RtkHDAud.sys -- (IntcAzAudAddService) Service for Realtek HD Audio (WDM)
DRV - [2009/01/07 17:18:58 | 000,991,784 | ---- | M] (Broadcom Corporation.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\btkrnl.sys -- (BTKRNL)
DRV - [2008/10/30 15:19:14 | 000,047,272 | ---- | M] (Broadcom Corporation.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\btwusb.sys -- (BTWUSB)
DRV - [2008/09/10 21:14:48 | 001,386,624 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\BCMWL5.SYS -- (BCM43XX)
DRV - [2008/08/05 07:10:12 | 001,684,736 | ---- | M] (Creative) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\Ambfilt.sys -- (Ambfilt)
DRV - [2008/07/22 21:03:24 | 000,157,696 | ---- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\RTS5121.sys -- (RSUSBSTOR)
DRV - [2008/06/19 22:43:36 | 000,176,640 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\b57xp32.sys -- (b57w2k)
DRV - [2008/01/11 16:58:42 | 000,009,472 | ---- | M] (Lenovo Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\AcpiVpc.sys -- (ACPIVPC)
DRV - [2007/05/02 13:12:36 | 000,109,704 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ssm_mdm.sys -- (ssm_mdm)
DRV - [2007/05/02 13:12:36 | 000,015,112 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ssm_mdfl.sys -- (ssm_mdfl)
DRV - [2007/05/02 13:12:34 | 000,083,592 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ssm_bus.sys -- (ssm_bus) SAMSUNG Mobile USB Device II 1.0 driver (WDM)
DRV - [2007/02/19 00:56:46 | 000,021,376 | ---- | M] (Lenovo (United States) Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\psadd.sys -- (psadd)
DRV - [2006/01/04 02:41:48 | 001,389,056 | ---- | M] (Creative Technology Ltd.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\Monfilt.sys -- (Monfilt)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.msn.com/

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchDefaultBranded = 1
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.ca/
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..browser.search.param.yahoo-fr: "chrf-ytbm"
FF - prefs.js..browser.search.param.yahoo-fr-cjkt: "chrf-ytbm"
FF - prefs.js..browser.search.param.yahoo-type: "${8}"
FF - prefs.js..browser.startup.homepage: "http://www.google.ca"
FF - prefs.js..extensions.enabledItems: [email protected]:1.0
FF - prefs.js..extensions.enabledItems: {635abd67-4fe9-1b23-4f01-e679fa7484c1}:2.1.1.20091029021655
FF - prefs.js..extensions.enabledItems: [email protected]:3.9.1.100005
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA}:6.0.26
FF - prefs.js..network.proxy.no_proxies_on: "*.local"
FF - prefs.js..network.proxy.type: 0


FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\4.0.60831.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 9.0.1\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011/12/27 04:07:32 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 9.0.1\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011/06/22 17:59:21 | 000,000,000 | ---D | M]

[2010/04/23 03:11:21 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Ziad\Application Data\Mozilla\Extensions
[2012/01/26 22:38:26 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Ziad\Application Data\Mozilla\Firefox\Profiles\du0089co.default\extensions
[2010/04/28 23:32:45 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- C:\Documents and Settings\Ziad\Application Data\Mozilla\Firefox\Profiles\du0089co.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2012/01/26 22:38:26 | 000,000,000 | ---D | M] (Yahoo! Toolbar) -- C:\Documents and Settings\Ziad\Application Data\Mozilla\Firefox\Profiles\du0089co.default\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1}
[2012/01/14 20:47:42 | 000,000,000 | ---D | M] (Support.com Toolbar) -- C:\Documents and Settings\Ziad\Application Data\Mozilla\Firefox\Profiles\du0089co.default\extensions\[email protected]
[2011/12/27 04:07:32 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions
[2011/12/21 02:24:52 | 000,121,816 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\browsercomps.dll
[2011/05/04 03:52:23 | 000,476,904 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\mozilla firefox\plugins\npdeployJava1.dll
[2011/12/20 23:30:41 | 000,002,252 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\bing.xml
[2011/12/20 23:30:41 | 000,002,040 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\twitter.xml

O1 HOSTS File: ([2012/01/24 19:28:40 | 000,000,027 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (AcroIEHlprObj Class) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (Adobe PDF Conversion Toolbar Helper) - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O2 - BHO: (Bing Bar Helper) - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files\Microsoft\BingBar\BingExt.dll (Microsoft Corporation.)
O2 - BHO: (Support.com Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask)
O3 - HKLM\..\Toolbar: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O3 - HKLM\..\Toolbar: (Bing Bar) - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files\Microsoft\BingBar\BingExt.dll (Microsoft Corporation.)
O3 - HKLM\..\Toolbar: (Support.com Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask)
O3 - HKCU\..\Toolbar\WebBrowser: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O3 - HKCU\..\Toolbar\WebBrowser: (Support.com Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask)
O4 - HKLM..\Run: [Acrobat Assistant 7.0] C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe (Adobe Systems Inc.)
O4 - HKLM..\Run: [ApnUpdater] C:\Program Files\Ask.com\Updater\Updater.exe (Ask)
O4 - HKLM..\Run: [APSDaemon] C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [avgnt] C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Avira Operations GmbH & Co. KG)
O4 - HKLM..\Run: [BrStsMon00] C:\Program Files\Browny02\Brother\BrStMonW.exe (Brother Industries, Ltd.)
O4 - HKLM..\Run: [Energy Management] C:\Program Files\Lenovo\Energy Management\Energy Management.exe (Lenovo (Beijing) Limited)
O4 - HKLM..\Run: [EnergyUtility] C:\Program Files\Lenovo\Energy Management\utility.exe (Lenovo(Beijing)Limited)
O4 - HKLM..\Run: [tbhSystray] C:\Program Files\tbh\base\bin\tbhSystray.exe (eBay)
O4 - HKLM..\Run: [VeriFaceManager] C:\Program Files\Lenovo\VeriFaceIII\PManage.exe ()
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Acrobat Speed Launcher.lnk = C:\WINDOWS\Installer\{AC76BA86-1033-0000-7760-100000000002}\SC_Acrobat.exe ()
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Bluetooth.lnk = C:\Program Files\Lenovo\Bluetooth Software\BTTray.exe (Broadcom Corporation.)
O4 - Startup: C:\Documents and Settings\Ziad\Start Menu\Programs\Startup\Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe (Adobe Systems, Inc.)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O8 - Extra context menu item: Convert link target to Adobe PDF - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert link target to existing PDF - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert selected links to Adobe PDF - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert selected links to existing PDF - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert selection to Adobe PDF - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert selection to existing PDF - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert to Adobe PDF - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert to existing PDF - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000 File not found
O8 - Extra context menu item: Send to &Bluetooth Device... - C:\Program Files\Lenovo\Bluetooth Software\btsendto_ie_ctx.htm ()
O8 - Extra context menu item: Send To Bluetooth - C:\Program Files\Lenovo\Bluetooth Software\btsendto_ie.htm ()
O9 - Extra Button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\Lenovo\Bluetooth Software\btsendto_ie.htm ()
O9 - Extra 'Tools' menuitem : @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\Lenovo\Bluetooth Software\btsendto_ie.htm ()
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} http://upload.facebo...toUploader5.cab (Facebook Photo Uploader 5 Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_26)
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} http://messenger.zon...nt.cab56907.cab (MessengerStatsClient Class)
O16 - DPF: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_26)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_26)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.ad...Plus/1.6/gp.cab (Reg Error: Key error.)
O16 - DPF: {E77F23EB-E7AB-4502-8F37-247DBAF1A147} http://gfx1.hotmail....ol/MSNPUpld.cab (Windows Live Hotmail Photo Upload Tool)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 64.71.255.198
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{9C7FC3C5-27BA-47BA-B3A9-F3F4772D7DC8}: DhcpNameServer = 64.71.255.198
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O20 - HKLM Winlogon: Shell - (Explorer.exe) -C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) -C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O20 - Winlogon\Notify\PicNotify: DllName - (PicNotify.dll) - C:\WINDOWS\System32\PicNotify.dll ()
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2008/07/21 14:16:20 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = ComFile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*

========== Files/Folders - Created Within 30 Days ==========

[2012/01/29 11:02:54 | 000,000,000 | -H-D | C] -- C:\dvmexp
[2012/01/27 18:11:00 | 000,000,000 | ---D | C] -- C:\_OTS
[2012/01/26 19:13:46 | 000,646,144 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\Ziad\Desktop\OTS.exe
[2012/01/25 21:53:12 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Ziad\Application Data\Avira
[2012/01/25 21:52:13 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\Avira
[2012/01/25 21:50:12 | 000,028,520 | ---- | C] (Avira GmbH) -- C:\WINDOWS\System32\drivers\ssmdrv.sys
[2012/01/25 21:49:55 | 000,036,000 | ---- | C] (Avira GmbH) -- C:\WINDOWS\System32\drivers\avkmgr.sys
[2012/01/25 21:49:53 | 000,134,856 | ---- | C] (Avira GmbH) -- C:\WINDOWS\System32\drivers\avipbb.sys
[2012/01/25 21:49:52 | 000,074,640 | ---- | C] (Avira GmbH) -- C:\WINDOWS\System32\drivers\avgntflt.sys
[2012/01/25 21:48:48 | 000,000,000 | ---D | C] -- C:\Program Files\Avira
[2012/01/25 21:48:48 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Avira
[2012/01/25 21:24:18 | 000,000,000 | -HSD | C] -- C:\RECYCLER
[2012/01/25 21:23:02 | 006,189,952 | ---- | C] (Support.com ) -- C:\Documents and Settings\Ziad\Desktop\ARO2011_bt.exe
[2012/01/23 18:57:23 | 000,000,000 | RHSD | C] -- C:\cmdcons
[2012/01/23 18:51:21 | 000,518,144 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWREG.exe
[2012/01/23 18:51:21 | 000,406,528 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWSC.exe
[2012/01/23 18:51:21 | 000,212,480 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWXCACLS.exe
[2012/01/23 18:51:21 | 000,060,416 | ---- | C] (NirSoft) -- C:\WINDOWS\NIRCMD.exe
[2012/01/23 18:50:56 | 000,000,000 | ---D | C] -- C:\WINDOWS\ERDNT
[2012/01/23 18:28:18 | 000,000,000 | ---D | C] -- C:\Qoobox
[2012/01/23 18:25:20 | 004,388,468 | R--- | C] (Swearware) -- C:\Documents and Settings\Ziad\Desktop\Puppy.exe
[2012/01/22 21:55:10 | 000,000,000 | R--D | C] -- C:\Documents and Settings\Ziad\Start Menu\Programs\Administrative Tools
[2012/01/22 21:18:45 | 000,000,000 | ---D | C] -- C:\Documents and Settings\NetworkService\Local Settings\Application Data\Apple Computer
[2012/01/22 21:13:02 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Ziad\Start Menu\Programs\HiJackThis
[2012/01/22 20:24:34 | 000,000,000 | ---D | C] -- C:\Config.Msi
[2012/01/22 15:39:00 | 004,713,472 | ---- | C] (AVAST Software) -- C:\Documents and Settings\Ziad\Desktop\aswMBR.exe
[2012/01/21 20:38:04 | 000,000,000 | R--D | C] -- C:\Documents and Settings\All Users\Documents\My Videos
[2012/01/21 20:37:51 | 000,607,260 | R--- | C] (Swearware) -- C:\Documents and Settings\Ziad\Desktop\dds.scr
[2012/01/20 22:14:30 | 000,584,192 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\Ziad\Desktop\OTL.exe
[2012/01/19 20:08:08 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
[2012/01/16 20:07:34 | 000,101,720 | ---- | C] (Sunbelt Software) -- C:\WINDOWS\System32\drivers\SBREDrv.sys
[2012/01/16 19:52:52 | 000,000,000 | ---D | C] -- C:\Program Files\Toolbar Cleaner
[2012/01/16 19:51:06 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Lavasoft
[2012/01/16 19:02:46 | 000,000,000 | ---D | C] -- C:\Program Files\Trend Micro
[2012/01/14 22:00:52 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Ziad\Application Data\Malwarebytes
[2012/01/14 22:00:36 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Malwarebytes
[2012/01/14 12:35:19 | 000,000,000 | ---D | C] -- C:\Documents and Settings\NetworkService\Application Data\Sun
[2012/01/14 10:27:26 | 002,002,320 | ---- | C] (Trend Micro Inc.) -- C:\Documents and Settings\Ziad\Desktop\HousecallLauncher.exe
[2012/01/14 00:50:46 | 000,000,000 | ---D | C] -- C:\Documents and Settings\NetworkService\Application Data\Macromedia
[2012/01/14 00:50:45 | 000,000,000 | ---D | C] -- C:\Documents and Settings\NetworkService\Application Data\Adobe
[2012/01/04 14:33:56 | 000,056,208 | ---- | C] (Trusteer Ltd.) -- C:\WINDOWS\System32\drivers\RapportKELL.sys
[2012/01/01 22:09:06 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Ziad\Desktop\Lebanon Trip

========== Files - Modified Within 30 Days ==========

[2012/01/29 11:47:46 | 000,000,232 | ---- | M] () -- C:\WINDOWS\tasks\Scheduled Update for Ask Toolbar.job
[2012/01/29 11:03:18 | 000,002,335 | ---- | M] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Acrobat Speed Launcher.lnk
[2012/01/29 11:01:45 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2012/01/29 00:13:05 | 000,000,420 | -H-- | M] () -- C:\WINDOWS\tasks\User_Feed_Synchronization-{5257A20B-12A7-4819-AFB2-043DF76F23B7}.job
[2012/01/27 20:45:17 | 000,012,195 | ---- | M] () -- C:\Documents and Settings\Ziad\Desktop\hijackthis-Jan27
[2012/01/27 20:43:27 | 000,002,445 | ---- | M] () -- C:\Documents and Settings\Ziad\Desktop\HiJackThis.lnk
[2012/01/27 07:00:20 | 000,015,618 | ---- | M] () -- C:\Documents and Settings\Ziad\My Documents\Avira Message.JPG
[2012/01/26 21:56:18 | 000,134,856 | ---- | M] (Avira GmbH) -- C:\WINDOWS\System32\drivers\avipbb.sys
[2012/01/26 19:13:51 | 000,646,144 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Ziad\Desktop\OTS.exe
[2012/01/25 21:52:13 | 000,001,714 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Avira Control Center.lnk
[2012/01/25 21:38:13 | 082,885,256 | ---- | M] () -- C:\Documents and Settings\Ziad\Desktop\avira_free_antivirus_en.exe
[2012/01/25 21:23:26 | 006,189,952 | ---- | M] (Support.com ) -- C:\Documents and Settings\Ziad\Desktop\ARO2011_bt.exe
[2012/01/25 18:41:50 | 000,139,264 | ---- | M] () -- C:\Documents and Settings\Ziad\Desktop\SystemLook.exe
[2012/01/24 20:07:26 | 000,334,429 | ---- | M] () -- C:\Documents and Settings\Ziad\Desktop\FSS.exe
[2012/01/24 19:28:40 | 000,000,027 | ---- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts
[2012/01/23 18:57:37 | 000,000,327 | RHS- | M] () -- C:\boot.ini
[2012/01/23 18:38:56 | 000,000,664 | ---- | M] () -- C:\WINDOWS\System32\d3d9caps.dat
[2012/01/23 18:25:22 | 004,388,468 | R--- | M] (Swearware) -- C:\Documents and Settings\Ziad\Desktop\Puppy.exe
[2012/01/22 17:02:18 | 000,219,733 | ---- | M] () -- C:\Documents and Settings\Ziad\Desktop\ASW-screen shot.JPG
[2012/01/22 15:39:41 | 004,713,472 | ---- | M] (AVAST Software) -- C:\Documents and Settings\Ziad\Desktop\aswMBR.exe
[2012/01/21 20:44:12 | 000,302,592 | ---- | M] () -- C:\Documents and Settings\Ziad\Desktop\p5u8exhs.exe
[2012/01/21 20:37:53 | 000,607,260 | R--- | M] (Swearware) -- C:\Documents and Settings\Ziad\Desktop\dds.scr
[2012/01/20 22:14:35 | 000,584,192 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Ziad\Desktop\OTL.exe
[2012/01/20 21:47:20 | 000,013,590 | ---- | M] () -- C:\Documents and Settings\Ziad\Desktop\hijackthis-1-21-2012
[2012/01/16 20:07:33 | 000,101,720 | ---- | M] (Sunbelt Software) -- C:\WINDOWS\System32\drivers\SBREDrv.sys
[2012/01/14 12:02:19 | 000,026,178 | ---- | M] () -- C:\Documents and Settings\Ziad\Desktop\Script.JPG
[2012/01/14 10:47:42 | 000,213,518 | ---- | M] () -- C:\Documents and Settings\Ziad\Local Settings\Application Data\census.cache
[2012/01/14 10:47:24 | 000,202,510 | ---- | M] () -- C:\Documents and Settings\Ziad\Local Settings\Application Data\ars.cache
[2012/01/14 10:27:31 | 002,002,320 | ---- | M] (Trend Micro Inc.) -- C:\Documents and Settings\Ziad\Desktop\HousecallLauncher.exe
[2012/01/13 22:45:34 | 018,196,478 | ---- | M] () -- C:\Documents and Settings\Ziad\Desktop\Hedgehog Book.pdf
[2012/01/11 22:46:18 | 000,001,374 | ---- | M] () -- C:\WINDOWS\imsins.BAK
[2012/01/11 22:37:53 | 000,446,386 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat
[2012/01/11 22:37:53 | 000,073,426 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat
[2012/01/11 21:06:24 | 000,672,480 | ---- | M] () -- C:\Documents and Settings\Ziad\Desktop\Hedgehog Care.pdf
[2012/01/06 20:36:38 | 000,561,859 | ---- | M] () -- C:\Documents and Settings\Ziad\Desktop\Tropical_Fish-A_Beginners_Guide.pdf
[2012/01/04 14:33:56 | 000,056,208 | ---- | M] (Trusteer Ltd.) -- C:\WINDOWS\System32\drivers\RapportKELL.sys
[2011/12/30 13:17:03 | 000,002,278 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl

========== Files Created - No Company Name ==========

[2012/01/27 20:45:17 | 000,012,195 | ---- | C] () -- C:\Documents and Settings\Ziad\Desktop\hijackthis-Jan27
[2012/01/27 07:00:20 | 000,015,618 | ---- | C] () -- C:\Documents and Settings\Ziad\My Documents\Avira Message.JPG
[2012/01/25 21:52:13 | 000,001,714 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Avira Control Center.lnk
[2012/01/25 21:38:10 | 082,885,256 | ---- | C] () -- C:\Documents and Settings\Ziad\Desktop\avira_free_antivirus_en.exe
[2012/01/25 19:40:36 | 000,334,429 | ---- | C] () -- C:\Documents and Settings\Ziad\Desktop\FSS.exe
[2012/01/25 18:41:56 | 000,139,264 | ---- | C] () -- C:\Documents and Settings\Ziad\Desktop\SystemLook.exe
[2012/01/23 18:57:37 | 000,000,211 | ---- | C] () -- C:\Boot.bak
[2012/01/23 18:57:31 | 000,260,272 | RHS- | C] () -- C:\cmldr
[2012/01/23 18:51:21 | 000,256,000 | ---- | C] () -- C:\WINDOWS\PEV.exe
[2012/01/23 18:51:21 | 000,208,896 | ---- | C] () -- C:\WINDOWS\MBR.exe
[2012/01/23 18:51:21 | 000,098,816 | ---- | C] () -- C:\WINDOWS\sed.exe
[2012/01/23 18:51:21 | 000,080,412 | ---- | C] () -- C:\WINDOWS\grep.exe
[2012/01/23 18:51:21 | 000,068,096 | ---- | C] () -- C:\WINDOWS\zip.exe
[2012/01/22 17:02:17 | 000,219,733 | ---- | C] () -- C:\Documents and Settings\Ziad\Desktop\ASW-screen shot.JPG
[2012/01/21 20:44:11 | 000,302,592 | ---- | C] () -- C:\Documents and Settings\Ziad\Desktop\p5u8exhs.exe
[2012/01/20 21:47:17 | 000,013,590 | ---- | C] () -- C:\Documents and Settings\Ziad\Desktop\hijackthis-1-21-2012
[2012/01/16 19:02:47 | 000,002,445 | ---- | C] () -- C:\Documents and Settings\Ziad\Desktop\HiJackThis.lnk
[2012/01/15 12:17:11 | 000,000,664 | ---- | C] () -- C:\WINDOWS\System32\d3d9caps.dat
[2012/01/14 12:02:18 | 000,026,178 | ---- | C] () -- C:\Documents and Settings\Ziad\Desktop\Script.JPG
[2012/01/14 10:47:42 | 000,213,518 | ---- | C] () -- C:\Documents and Settings\Ziad\Local Settings\Application Data\census.cache
[2012/01/14 10:47:24 | 000,202,510 | ---- | C] () -- C:\Documents and Settings\Ziad\Local Settings\Application Data\ars.cache
[2012/01/13 22:37:18 | 018,196,478 | ---- | C] () -- C:\Documents and Settings\Ziad\Desktop\Hedgehog Book.pdf
[2012/01/11 21:06:24 | 000,672,480 | ---- | C] () -- C:\Documents and Settings\Ziad\Desktop\Hedgehog Care.pdf
[2012/01/06 20:36:38 | 000,561,859 | ---- | C] () -- C:\Documents and Settings\Ziad\Desktop\Tropical_Fish-A_Beginners_Guide.pdf
[2011/02/13 13:10:55 | 000,000,114 | ---- | C] () -- C:\WINDOWS\System32\BRLMW03A.INI
[2011/02/13 13:10:55 | 000,000,050 | ---- | C] () -- C:\WINDOWS\System32\BRADM10A.DAT
[2011/02/13 13:10:54 | 000,045,056 | ---- | C] () -- C:\WINDOWS\System32\BRTCPCON.DLL
[2010/12/20 21:26:53 | 000,053,248 | ---- | C] () -- C:\WINDOWS\System32\CommonDL.dll
[2010/12/20 21:26:53 | 000,002,413 | ---- | C] () -- C:\WINDOWS\System32\lgAxconfig.ini
[2010/12/09 05:37:18 | 000,000,000 | ---- | C] () -- C:\WINDOWS\System32\cd.dat
[2010/05/31 01:55:34 | 000,020,480 | ---- | C] () -- C:\Documents and Settings\Ziad\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/02/04 00:10:31 | 000,000,036 | ---- | C] () -- C:\Documents and Settings\Ziad\Local Settings\Application Data\housecall.guid.cache
[2009/10/06 22:44:47 | 000,000,000 | ---- | C] () -- C:\WINDOWS\nsreg.dat
[2009/09/07 04:49:42 | 000,000,000 | ---- | C] () -- C:\Documents and Settings\All Users\Application Data\LauncherAccess.dt
[2009/09/07 04:40:42 | 000,005,632 | ---- | C] () -- C:\WINDOWS\System32\drivers\StarOpen.sys
[2009/08/16 21:18:49 | 000,000,056 | -H-- | C] () -- C:\WINDOWS\System32\ezsidmv.dat
[2009/08/10 19:15:28 | 000,000,376 | ---- | C] () -- C:\WINDOWS\ODBC.INI
[2009/08/07 17:29:15 | 000,001,793 | ---- | C] () -- C:\WINDOWS\System32\fxsperf.ini
[2009/04/21 10:49:50 | 000,000,061 | ---- | C] () -- C:\WINDOWS\smscfg.ini
[2009/04/20 21:07:28 | 000,148,792 | ---- | C] () -- C:\WINDOWS\desktopset.exe
[2009/04/20 21:02:59 | 009,338,880 | ---- | C] () -- C:\WINDOWS\System32\Facev.dll
[2009/04/20 21:02:59 | 000,491,520 | ---- | C] () -- C:\WINDOWS\System32\picn.dll
[2009/04/20 21:02:59 | 000,208,896 | ---- | C] () -- C:\WINDOWS\System32\image.dll
[2009/04/20 21:02:58 | 000,655,360 | ---- | C] () -- C:\WINDOWS\System32\EncIcons.dll
[2009/04/20 21:02:58 | 000,241,752 | ---- | C] () -- C:\WINDOWS\System32\IcnOvrly.dll
[2009/04/20 21:02:58 | 000,053,248 | ---- | C] () -- C:\WINDOWS\System32\FunFrm.dll
[2009/04/20 21:02:57 | 000,507,904 | ---- | C] () -- C:\WINDOWS\System32\SimpleExt.dll
[2009/04/20 21:02:57 | 000,221,184 | ---- | C] () -- C:\WINDOWS\System32\SetDev.dll
[2009/04/20 21:02:57 | 000,126,976 | ---- | C] () -- C:\WINDOWS\System32\VideoOp.dll
[2009/04/20 21:02:56 | 009,502,720 | ---- | C] () -- C:\WINDOWS\System32\FaceVerify.dll
[2009/04/20 21:02:56 | 001,974,272 | ---- | C] () -- C:\WINDOWS\System32\Imagereog.dll
[2009/04/20 21:02:56 | 001,564,672 | ---- | C] () -- C:\WINDOWS\System32\MainOp.dll
[2009/04/20 21:02:56 | 001,167,360 | ---- | C] () -- C:\WINDOWS\System32\PicNotify.dll
[2009/04/20 21:02:56 | 000,094,208 | ---- | C] () -- C:\WINDOWS\System32\Momo.dll
[2009/04/20 21:02:56 | 000,049,152 | ---- | C] () -- C:\WINDOWS\System32\DevFilt.dll
[2009/04/20 21:02:55 | 000,974,848 | ---- | C] () -- C:\WINDOWS\System32\Apblend.dll
[2009/04/20 21:02:53 | 000,241,664 | ---- | C] () -- C:\WINDOWS\System32\3DImageRenderer.dll
[2009/04/20 20:54:53 | 000,147,456 | ---- | C] () -- C:\WINDOWS\System32\igfxCoIn_v4926.dll
[2009/04/20 20:53:24 | 000,000,008 | ---- | C] () -- C:\WINDOWS\System32\drivers\rtkhdaud.dat
[2009/04/20 20:48:07 | 000,000,138 | ---- | C] () -- C:\WINDOWS\System32\Softkbd.exe.config
[2009/01/16 19:55:38 | 002,854,976 | ---- | C] () -- C:\WINDOWS\System32\btwicons.dll
[2008/12/01 20:32:30 | 000,012,240 | ---- | C] () -- C:\WINDOWS\System32\dvmio.sys
[2008/07/21 16:08:39 | 000,004,670 | ---- | C] () -- C:\WINDOWS\System32\OEMINFO.INI
[2008/07/21 15:04:41 | 013,107,200 | ---- | C] () -- C:\WINDOWS\System32\oembios.bin
[2008/07/21 15:04:41 | 000,446,386 | ---- | C] () -- C:\WINDOWS\System32\perfh009.dat
[2008/07/21 15:04:41 | 000,272,128 | ---- | C] () -- C:\WINDOWS\System32\perfi009.dat
[2008/07/21 15:04:41 | 000,073,426 | ---- | C] () -- C:\WINDOWS\System32\perfc009.dat
[2008/07/21 15:04:41 | 000,028,626 | ---- | C] () -- C:\WINDOWS\System32\perfd009.dat
[2008/07/21 15:04:41 | 000,004,569 | ---- | C] () -- C:\WINDOWS\System32\secupd.dat
[2008/07/21 15:04:41 | 000,004,547 | ---- | C] () -- C:\WINDOWS\System32\oembios.dat
[2008/07/21 15:04:41 | 000,000,741 | ---- | C] () -- C:\WINDOWS\System32\noise.dat
[2008/07/21 15:04:40 | 000,673,088 | ---- | C] () -- C:\WINDOWS\System32\mlang.dat
[2008/07/21 15:04:40 | 000,046,258 | ---- | C] () -- C:\WINDOWS\System32\mib.bin
[2008/07/21 15:04:39 | 000,218,003 | ---- | C] () -- C:\WINDOWS\System32\dssec.dat
[2008/07/21 15:04:39 | 000,001,804 | ---- | C] () -- C:\WINDOWS\System32\Dcache.bin
[2008/07/21 14:18:03 | 000,002,048 | --S- | C] () -- C:\WINDOWS\bootstat.dat
[2008/07/21 14:14:44 | 000,021,640 | ---- | C] () -- C:\WINDOWS\System32\emptyregdb.dat
[2008/07/21 07:09:56 | 000,004,161 | ---- | C] () -- C:\WINDOWS\ODBCINST.INI
[2008/07/21 07:09:12 | 000,267,800 | ---- | C] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2001/11/14 14:56:00 | 001,802,240 | ---- | C] () -- C:\WINDOWS\System32\lcppn21.dll

< End of report >
  • 0

#37
Cookiegal

Cookiegal

    Visiting Consultant

  • Visiting Consultant
  • 887 posts
1. Please download The Avenger2 by Swandog46 to your Desktop.

  • Right-click on the Avenger.zip folder and select "Extract All..."
  • Follow the prompts and extract the Avenger folder to your desktop

2. Copy all the text contained in the code box below to your clipboard by highlighting it and pressing (Ctrl+C):

Folders to delete:
c:\windows\$NtUninstallKB7163$

Note: the above code was created specifically for this user. If you are not this user, do NOT follow these directions as they could damage the workings of your system.


3. Now, open the Avenger folder and start The Avenger program by clicking on its icon.

  • Right-click on the window under Input script here:, and select Paste.
  • You can also paste the text copied to the clipboard into this window by pressing (Ctrl+V).
  • Click on Execute
  • Answer "Yes" twice when prompted.

4. The Avenger will automatically do the following:

  • It will restart your computer. ( In cases where the code to execute contains "Drivers to Delete", The Avenger will actually restart your system twice.)
  • After the restart, it creates a log file that should open with the results of Avenger’s actions. This log file will be located at C:\avenger.txt
  • The Avenger will also have backed up all the files, etc., that you asked it to delete, and will have zipped them and moved the zip archives to C:\avenger\backup.zip.
5. Please copy/paste the content of C:\avenger.txt into your reply.
  • 0

#38
Leo2012

Leo2012

    Member

  • Topic Starter
  • Member
  • PipPip
  • 44 posts
Logfile of The Avenger Version 2.0, © by Swandog46
http://swandog46.geekstogo.com

Platform: Windows XP

*******************

Script file opened successfully.
Script file read successfully.

Backups directory opened successfully at C:\Avenger

*******************

Beginning to process script file:

Rootkit scan active.
No rootkits found!

Folder "c:\windows\$NtUninstallKB7163$" deleted successfully.

Completed script processing.

*******************

Finished! Terminate.
  • 0

#39
Cookiegal

Cookiegal

    Visiting Consultant

  • Visiting Consultant
  • 887 posts
That's good. Can you try running aswmbr again? Only this time, let's remove the one you have (drag it to the recycle bin) and download it again.

If you get a blue screen or freeze like last time can you capture screenshot if you can't get a log?

Please download aswMBR.exe and save it to your desktop.

Double click aswMBR.exe to start the tool. (Vista/Windows 7 users - right click to run as administrator)

Click Scan.

Upon completion of the scan, click Save log then save it to your desktop and post that log in your next reply for review.
Note - do NOT attempt any Fix yet.
  • 0

#40
Leo2012

Leo2012

    Member

  • Topic Starter
  • Member
  • PipPip
  • 44 posts
aswMBR version 0.9.9.1532 Copyright© 2011 AVAST Software
Run date: 2012-01-29 21:50:38
-----------------------------
21:50:38.359 OS Version: Windows 5.1.2600 Service Pack 3
21:50:38.421 Number of processors: 2 586 0x1C02
21:50:38.421 ComputerName: LENOVO-D4F96F23 UserName: Ziad
21:50:48.312 Initialize success
21:57:20.843 AVAST engine defs: 12012901
22:03:48.265 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP1T0L0-5
22:03:48.265 Disk 0 Vendor: WDC_WD1600BEVS-08VAT2 14.01A14 Size: 152627MB BusType: 3
22:03:48.296 Disk 0 MBR read successfully
22:03:48.296 Disk 0 MBR scan
22:03:48.515 Disk 0 unknown MBR code
22:03:48.531 Disk 0 Partition 1 80 (A) 07 HPFS/NTFS NTFS 150146 MB offset 16065
22:03:48.640 Disk 0 Partition 2 00 27 Hidden NTFS WinRE MSDOS5.0 2470 MB offset 307516230
22:03:48.671 Disk 0 scanning sectors +312576705
22:03:48.890 Disk 0 scanning C:\WINDOWS\system32\drivers
22:04:32.921 Service scanning
22:04:42.984 Modules scanning
22:05:28.031 Disk 0 trace - called modules:
22:05:28.046 ntkrnlpa.exe CLASSPNP.SYS disk.sys atapi.sys hal.dll pciide.sys
22:05:28.062 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x86d89ab8]
22:05:28.062 3 CLASSPNP.SYS[f754dfd7] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP1T0L0-5[0x86d1bb00]
22:05:32.765 AVAST engine scan C:\WINDOWS
22:07:16.953 AVAST engine scan C:\WINDOWS\system32
22:25:07.453 AVAST engine scan C:\WINDOWS\system32\drivers
22:25:58.125 AVAST engine scan C:\Documents and Settings\Ziad
22:54:00.093 Disk 0 MBR has been saved successfully to "C:\Documents and Settings\Ziad\Desktop\MBR.dat"
22:54:00.109 The log file has been saved successfully to "C:\Documents and Settings\Ziad\Desktop\aswMBR.txt"

Attached Thumbnails

  • Avira Message.JPG

  • 0

Advertisements


#41
Cookiegal

Cookiegal

    Visiting Consultant

  • Visiting Consultant
  • 887 posts
It looks like Avira didn't like aswmbr and that's probably why you were having problems with it. Did it blue screen this time around?

How are things with the system now?
  • 0

#42
Leo2012

Leo2012

    Member

  • Topic Starter
  • Member
  • PipPip
  • 44 posts
No blue screen but my computer takes a LONG time to start. And when it does, it takes a LONG time to open Firefox and Outlook.

It looks like there's something running in the background.

I got a couple of these messages today:

Attached Thumbnails

  • Script message.JPG

  • 0

#43
Cookiegal

Cookiegal

    Visiting Consultant

  • Visiting Consultant
  • 887 posts
Please run the following on-line scanner. Note that you must use Internet Explorer to perform the scan.

Note: If you're running a 64-bit system you have to choose the 32-bit option in IE. To do that, go to the Start Menu and right-click the Internet Explorer (32-bit) icon and then select 'Run as administrator' from the right-click menu.

http://www.eset.com/online-scanner

Accept the Terms of Use and then press the Start button

Allow the ActiveX control to be installed.

Put a check by Remove found threats and then run the scan.

When the scan is finished, you will see the results in a window.

A log.txt file is created here: C:\Program Files\EsetOnlineScanner\log.txt.

Open the log file with Notepad and copy and paste the contents here please.
  • 0

#44
Leo2012

Leo2012

    Member

  • Topic Starter
  • Member
  • PipPip
  • 44 posts
How do I know if I'm running a 64-bit system?
  • 0

#45
Cookiegal

Cookiegal

    Visiting Consultant

  • Visiting Consultant
  • 887 posts
I can tell from your logs that it's 32-bit.
  • 0






Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP