At various times I’ve run (though not always with the latest virus definitions) MS Security Essentials, Symantec Endpoint Protection, Malwarebytes, Kaspersky Rescue Disk, HitmanPro and ComboFix (maybe not so wise?). In some cases I copied these solutions onto a USB drive or CD using another computer, and sometimes even booted from the other media. In other cases the software was already present on my hard drive. But none of these products has been able to remove the virus. (Unfortunately I’ve done a terrible job of documenting my exact steps, always expecting relief to be one keystroke away.)
Let me try to give a clear picture of my current situation:
If I boot Windows normally using any existing (i.e., pre-virus) account, the ICE Cyber Crime Center “ransom” screen appears several seconds after the “Loading your personal settings” message, rendering my system unusable. Clicking Ctrl+Alt+Del followed by the Task Manager button does nothing. The only real working option from that screen is “Shut Down”.
Booting into Safe Mode or Safe Mode with Networking is futile because the “Loading your personal settings” message is followed almost immediately by the message “Logging off”, followed by Windows shutdown.
Booting into Safe Mode with Command Prompt offers my one glimmer of hope --- the boot sequence actually opens a cmd.exe window, from which I have been able to run a variety of commands (except “explorer”, which causes the system to immediately shut down). I can cd over to windows\pchealth\helpctr\binaries and launch msconfig, from where I’ve been able to run System Restores (unfortunately, no relief) and experiment with Startup item settings (also no help).
From the cmd.exe window I am even able to run the “net user” command and create new Windows accounts. And I can boot Windows normally with these new accounts (though the system will run very slowly, like something in the background is chewing up CPU). Of course, a regular user account has limited authority… but, unfortunately, if I return to the command prompt window and add a newly-created account to the Administrators group, the account then acts like any other account in the grip of the virus when I boot Windows normally (ICE screen appears and cannot be defeated).
So… I’m caught in a no-man’s land where I can only logon as Administratror in Safe Mode with Command Prompt ---- which means no access to networking or the Internet. Conversely, I can launch Windows normally from a newly-created user account and enjoy Internet access --- but just not as an Administrator! So this “worst of both worlds scenario” is effectively keeping me from running up-to-date versions of most malware removal tools.
Can anyone please suggest another approach I might take to beat this thing? Some registry manipulation perhaps? (thankfully I can run regedit)
Thanks for your help!
(P.S. The OTL executable seems to have created a second file called Extras.Txt. Should I attach that file as well?)
OTL logfile created on: 6/23/2013 7:08:10 PM - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Documents and Settings\loutemp4\Desktop
Windows XP Media Center Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
2.00 Gb Total Physical Memory | 1.35 Gb Available Physical Memory | 67.39% Memory free
5.78 Gb Paging File | 5.26 Gb Available in Paging File | 91.07% Paging File free
Paging file location(s): C:\pagefile.sys 4024 4024 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 144.31 Gb Total Space | 97.30 Gb Free Space | 67.42% Space Free | Partition Type: NTFS
Drive F: | 6.67 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS
Drive G: | 7.47 Gb Total Space | 5.57 Gb Free Space | 74.52% Space Free | Partition Type: FAT32
Computer Name: D3XTMS81 | User Name: loutemp4 | NOT logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - [2013/06/23 19:07:27 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\loutemp4\Desktop\OTL.exe
PRC - [2013/01/27 12:11:06 | 000,947,152 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Microsoft Security Client\msseces.exe
PRC - [2013/01/09 03:02:32 | 002,103,128 | ---- | M] (Juniper Networks, Inc.) -- C:\Program Files\Common Files\Juniper Networks\JamUI\Pulse.exe
PRC - [2012/04/25 11:34:46 | 000,115,624 | ---- | M] (Symantec Corporation) -- C:\Program Files\Common Files\Symantec Shared\ccApp.exe
PRC - [2012/04/25 11:34:44 | 001,471,904 | ---- | M] (Symantec Corporation) -- C:\Program Files\Symantec\Symantec Endpoint Protection\SmcGui.exe
PRC - [2009/05/21 10:55:32 | 000,206,064 | ---- | M] (SupportSoft, Inc.) -- C:\Program Files\Dell Support Center\bin\sprtcmd.exe
PRC - [2008/04/13 20:12:19 | 001,033,728 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe
PRC - [2007/11/23 20:26:06 | 002,441,216 | ---- | M] (SEC) -- C:\Program Files\MagicTune Premium\MagicTune.exe
PRC - [2007/03/15 11:09:36 | 000,460,784 | ---- | M] (Gteko Ltd.) -- C:\Program Files\DellSupport\DSAgnt.exe
PRC - [2007/01/15 17:18:00 | 000,036,864 | ---- | M] () -- C:\Program Files\MagicTune Premium\GammaTray.exe
PRC - [2006/06/15 08:43:20 | 000,049,152 | ---- | M] (HP) -- C:\Program Files\HP\ToolBoxFX\bin\HPTLBXFX.exe
PRC - [2006/05/09 20:24:16 | 000,050,760 | ---- | M] (America Online, Inc.) -- C:\Program Files\Common Files\AOL\1133066293\ee\aolsoftware.exe
PRC - [2005/09/08 21:20:46 | 000,464,384 | ---- | M] (Musicmatch, Inc.) -- C:\Program Files\MUSICMATCH\Musicmatch Jukebox\mim.exe
PRC - [2005/09/08 21:20:46 | 000,102,400 | ---- | M] (Musicmatch, Inc.) -- C:\Program Files\MUSICMATCH\Musicmatch Jukebox\MMDiag.exe
PRC - [2004/10/04 17:05:04 | 001,044,577 | ---- | M] () -- C:\Program Files\NETGEAR\WG111 Configuration Utility\WG111CFG.exe
PRC - [2003/09/17 12:43:36 | 000,057,344 | ---- | M] (Creative Technology Ltd) -- C:\Program Files\Creative\Sound Blaster Live! 24-bit\Surround Mixer\CTSysVol.exe
========== Modules (No Company Name) ==========
MOD - [2013/01/10 09:42:07 | 005,450,752 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Xml\fe025743210c22bea2f009e1612c38bf\System.Xml.ni.dll
MOD - [2013/01/10 09:39:13 | 007,977,984 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System\aeac298c43c77d8860db8e7634d9f2eb\System.ni.dll
MOD - [2013/01/10 09:38:46 | 011,492,352 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\mscorlib\eab2340ead8e1a84bdf1a87868659979\mscorlib.ni.dll
MOD - [2013/01/10 09:14:47 | 003,391,488 | ---- | M] () -- c:\windows\assembly\nativeimages1_v1.1.4322\mscorlib\1.0.5000.0__b77a5c561934e089_5f3fff1c\mscorlib.dll
MOD - [2013/01/10 09:14:41 | 000,843,776 | ---- | M] () -- c:\windows\assembly\nativeimages1_v1.1.4322\system.drawing\1.0.5000.0__b03f5f7f11d50a3a_cff60f84\system.drawing.dll
MOD - [2013/01/10 09:14:29 | 002,088,960 | ---- | M] () -- c:\windows\assembly\nativeimages1_v1.1.4322\system.xml\1.0.5000.0__b77a5c561934e089_52286159\system.xml.dll
MOD - [2013/01/10 09:14:19 | 003,035,136 | ---- | M] () -- c:\windows\assembly\nativeimages1_v1.1.4322\system.windows.forms\1.0.5000.0__b77a5c561934e089_bd611a5d\system.windows.forms.dll
MOD - [2013/01/10 09:14:05 | 001,966,080 | ---- | M] () -- c:\windows\assembly\nativeimages1_v1.1.4322\system\1.0.5000.0__b77a5c561934e089_f223d44f\system.dll
MOD - [2013/01/10 09:13:40 | 001,232,896 | ---- | M] () -- c:\windows\assembly\gac\system\1.0.5000.0__b77a5c561934e089\system.dll
MOD - [2013/01/10 09:13:38 | 000,471,040 | ---- | M] () -- c:\windows\assembly\gac\system.drawing\1.0.5000.0__b03f5f7f11d50a3a\system.drawing.dll
MOD - [2013/01/10 09:13:34 | 002,064,384 | ---- | M] () -- c:\windows\assembly\gac\system.windows.forms\1.0.5000.0__b77a5c561934e089\system.windows.forms.dll
MOD - [2008/03/25 00:50:40 | 000,355,112 | ---- | M] () -- C:\WINDOWS\system32\msjetoledb40.dll
MOD - [2007/11/23 20:27:42 | 000,045,056 | ---- | M] () -- C:\Program Files\MagicTune Premium\VESADll.dll
MOD - [2007/11/23 20:27:38 | 000,045,056 | ---- | M] () -- C:\Program Files\MagicTune Premium\IProfile.dll
MOD - [2007/11/23 20:25:02 | 000,065,536 | ---- | M] () -- C:\Program Files\MagicTune Premium\MTResEng.dll
MOD - [2007/11/23 20:24:56 | 000,032,768 | ---- | M] () -- C:\Program Files\MagicTune Premium\HzZone.dll
MOD - [2007/11/23 20:24:52 | 000,040,960 | ---- | M] () -- C:\Program Files\MagicTune Premium\DProfile.dll
MOD - [2007/11/23 20:24:50 | 000,040,960 | ---- | M] () -- C:\Program Files\MagicTune Premium\EProfile.dll
MOD - [2007/11/23 20:24:46 | 000,036,864 | ---- | M] () -- C:\Program Files\MagicTune Premium\DeviceInterface.dll
MOD - [2007/11/23 20:24:42 | 000,032,768 | ---- | M] () -- C:\Program Files\MagicTune Premium\Highlight.dll
MOD - [2007/01/15 17:18:00 | 000,036,864 | ---- | M] () -- C:\Program Files\MagicTune Premium\GammaTray.exe
MOD - [2006/06/15 08:42:34 | 000,053,248 | ---- | M] () -- C:\Program Files\HP\ToolBoxFX\bin\NativeUtils.dll
MOD - [2005/09/01 09:51:14 | 000,122,880 | ---- | M] () -- C:\Program Files\MUSICMATCH\Musicmatch Jukebox\mmgit.dll
MOD - [2005/08/16 23:02:54 | 001,339,392 | ---- | M] () -- c:\windows\assembly\gac\system.xml\1.0.5000.0__b77a5c561934e089\system.xml.dll
MOD - [2005/08/16 23:02:54 | 000,323,584 | ---- | M] () -- c:\windows\assembly\gac\system.runtime.remoting\1.0.5000.0__b77a5c561934e089\system.runtime.remoting.dll
MOD - [2005/08/16 23:02:52 | 000,131,072 | ---- | M] () -- c:\windows\assembly\gac\system.runtime.serialization.formatters.soap\1.0.5000.0__b03f5f7f11d50a3a\system.runtime.serialization.formatters.soap.dll
MOD - [2004/10/04 17:05:04 | 001,044,577 | ---- | M] () -- C:\Program Files\NETGEAR\WG111 Configuration Utility\WG111CFG.exe
MOD - [2004/06/10 18:51:00 | 000,060,928 | ---- | M] () -- C:\WINDOWS\system32\P17.dll
MOD - [2003/09/23 03:00:00 | 000,106,496 | ---- | M] () -- C:\Program Files\Dell\ShareDLL\djbsdk.dll
========== Services (SafeList) ==========
SRV - File not found [Auto | Unknown] -- C:\Program Files\Alwil Software\Avast5\AvastSvc.exe -- (avast! Antivirus)
SRV - [2013/06/17 13:42:22 | 000,106,280 | ---- | M] (SurfRight B.V.) [Auto | Unknown] -- C:\Program Files\HitmanPro\hmpsched.exe -- (HitmanProScheduler)
SRV - [2013/06/12 08:24:14 | 000,256,904 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Unknown] -- C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc)
SRV - [2013/04/04 05:32:53 | 000,181,664 | ---- | M] (Oracle Corporation) [Auto | Unknown] -- C:\Program Files\Java\jre7\bin\jqs.exe -- (JavaQuickStarterService)
SRV - [2013/01/27 12:11:46 | 000,020,456 | ---- | M] (Microsoft Corporation) [Auto | Unknown] -- c:\Program Files\Microsoft Security Client\MsMpEng.exe -- (MsMpSvc)
SRV - [2013/01/09 00:48:30 | 000,162,136 | ---- | M] (Juniper Networks, Inc.) [Auto | Unknown] -- C:\Program Files\Common Files\Juniper Networks\JUNS\dsAccessService.exe -- (JuniperAccessService)
SRV - [2012/08/10 09:21:55 | 000,487,312 | ---- | M] () [On_Demand | Unknown] -- C:\WINDOWS\DOWNLO~1\DMService.exe -- (DMService)
SRV - [2012/04/25 11:34:46 | 000,108,456 | ---- | M] (Symantec Corporation) [Auto | Unknown] -- C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe -- (ccSetMgr)
SRV - [2012/04/25 11:34:46 | 000,108,456 | ---- | M] (Symantec Corporation) [Auto | Unknown] -- C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe -- (ccEvtMgr)
SRV - [2012/04/25 11:34:44 | 001,897,960 | ---- | M] (Symantec Corporation) [Auto | Unknown] -- C:\Program Files\Symantec\Symantec Endpoint Protection\Smc.exe -- (SmcService)
SRV - [2012/04/25 11:34:44 | 001,846,592 | ---- | M] (Symantec Corporation) [Auto | Unknown] -- C:\Program Files\Symantec\Symantec Endpoint Protection\Rtvscan.exe -- (Symantec AntiVirus)
SRV - [2012/04/25 11:34:44 | 000,357,808 | ---- | M] (Symantec Corporation) [Disabled | Unknown] -- C:\Program Files\Symantec\Symantec Endpoint Protection\SNAC.EXE -- (SNAC)
SRV - [2011/10/23 22:12:42 | 001,029,408 | ---- | M] (NETGEAR) [Auto | Unknown] -- C:\Program Files\NETGEAR Genie\bin\NETGEARGenieDaemon.exe -- (NETGEARGenieDaemon)
SRV - [2011/02/07 18:40:08 | 003,093,944 | ---- | M] (Symantec Corporation) [On_Demand | Unknown] -- C:\Program Files\Symantec\LiveUpdate\LuComServer_3_3.EXE -- (LiveUpdate)
SRV - [2011/02/07 18:40:08 | 000,558,520 | ---- | M] (Symantec Corporation) [Auto | Unknown] -- C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe -- (Automatic LiveUpdate Scheduler)
SRV - [2010/11/25 06:05:00 | 000,150,928 | ---- | M] (Microsoft Corporation) [Auto | Unknown] -- C:\Program Files\Microsoft Forefront UAG\Endpoint Components\3.1.0\uagqecsvc.exe -- (uagqecsvc)
SRV - [2009/09/29 09:17:50 | 000,013,088 | ---- | M] (Intuit Inc.) [Auto | Unknown] -- C:\Program Files\Common Files\Intuit\Update Service\IntuitUpdateService.exe -- (IntuitUpdateService)
SRV - [2008/08/13 18:32:40 | 000,201,968 | ---- | M] (SupportSoft, Inc.) [Auto | Unknown] -- C:\Program Files\Dell Support Center\bin\sprtsvc.exe -- (sprtsvc_dellsupportcenter)
SRV - [2008/04/13 20:12:09 | 000,088,576 | ---- | M] (Microsoft Corporation) [Unknown (-1) | Unknown] -- C:\WINDOWS\system32\wbem\wmiaprpl.dll -- (WmiApRpl)
SRV - [2007/08/23 16:05:18 | 000,045,056 | ---- | M] () [Auto | Unknown] -- C:\Program Files\MagicTune Premium\MagicTuneEngine.exe -- (MagicTuneEngine)
SRV - [2007/07/02 00:21:24 | 000,654,848 | ---- | M] (Macrovision Europe Ltd.) [On_Demand | Unknown] -- C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe -- (FLEXnet Licensing Service)
SRV - [2007/03/07 15:47:46 | 000,076,848 | ---- | M] () [On_Demand | Unknown] -- C:\Program Files\DellSupport\brkrsvc.exe -- (DSBrokerService)
SRV - [2007/01/04 17:38:08 | 000,024,652 | ---- | M] (Viewpoint Corporation) [Auto | Unknown] -- C:\Program Files\Viewpoint\Common\ViewpointService.exe -- (Viewpoint Manager Service)
SRV - [2004/11/02 16:59:50 | 000,316,544 | ---- | M] (Symantec Corporation) [Auto | Unknown] -- C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe -- (SymWSC)
========== Driver Services (SafeList) ==========
DRV - File not found [Kernel | On_Demand | Unknown] -- -- (WDICA)
DRV - File not found [Kernel | On_Demand | Unknown] -- system32\DRIVERS\wanatw4.sys -- (wanatw)
DRV - File not found [Kernel | On_Demand | Unknown] -- system32\DRIVERS\wg111v2.sys -- (RTLWUSB)
DRV - File not found [Kernel | On_Demand | Unknown] -- -- (PDRFRAME)
DRV - File not found [Kernel | On_Demand | Unknown] -- -- (PDRELI)
DRV - File not found [Kernel | On_Demand | Unknown] -- -- (PDFRAME)
DRV - File not found [Kernel | On_Demand | Unknown] -- -- (PDCOMP)
DRV - File not found [Kernel | System | Unknown] -- -- (PCIDump)
DRV - File not found [Kernel | On_Demand | Unknown] -- C:\WINDOWS\system32\Drivers\MmedFilter.sys -- (MmedFilter)
DRV - File not found [Kernel | System | Unknown] -- -- (lbrtfdc)
DRV - File not found [Kernel | On_Demand | Unknown] -- C:\DOCUME~1\default\LOCALS~1\Temp\krdpdre.sys -- (krdpdre)
DRV - File not found [Kernel | Auto | Unknown] -- C:\WINDOWS\system32\Drivers\DP.sys -- (DP1112)
DRV - File not found [Kernel | System | Unknown] -- -- (Changer)
DRV - File not found [Kernel | On_Demand | Unknown] -- C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\catchme.sys -- (catchme)
DRV - File not found [Kernel | On_Demand | Unknown] -- -- (bvrp_pci)
DRV - File not found [Kernel | System | Unknown] -- -- (aswTdi)
DRV - File not found [Kernel | System | Unknown] -- -- (aswSP)
DRV - File not found [File_System | System | Unknown] -- -- (aswSnx)
DRV - File not found [Kernel | System | Unknown] -- -- (aswRdr)
DRV - File not found [File_System | Auto | Unknown] -- -- (aswMon2)
DRV - File not found [File_System | Auto | Unknown] -- -- (aswFsBlk)
DRV - File not found [Kernel | System | Unknown] -- -- (Aavmker4)
DRV - [2013/06/20 22:59:58 | 000,040,776 | ---- | M] (Malwarebytes Corporation) [Kernel | On_Demand | Unknown] -- C:\WINDOWS\system32\drivers\mbamswissarmy.sys -- (MBAMSwissArmy)
DRV - [2013/05/21 04:00:00 | 001,611,992 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Unknown] -- C:\Program Files\Common Files\Symantec Shared\VirusDefs\20130623.002\NAVEX15.SYS -- (NAVEX15)
DRV - [2013/05/21 04:00:00 | 000,093,272 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Unknown] -- C:\Program Files\Common Files\Symantec Shared\VirusDefs\20130623.002\NAVENG.SYS -- (NAVENG)
DRV - [2012/12/07 05:15:38 | 000,091,248 | ---- | M] (Juniper Networks, Inc.) [Kernel | System | Unknown] -- C:\WINDOWS\system32\drivers\jnprTdi_730_29921.sys -- (jnprTdi_730_29921)
DRV - [2012/12/05 04:29:30 | 000,446,712 | ---- | M] (Juniper Networks, Inc.) [Kernel | On_Demand | Unknown] -- C:\WINDOWS\system32\drivers\jnprna5.sys -- (JNPRNA)
DRV - [2012/08/08 04:00:00 | 000,376,480 | ---- | M] (Symantec Corporation) [Kernel | System | Unknown] -- C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys -- (eeCtrl)
DRV - [2012/08/08 04:00:00 | 000,106,656 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Unknown] -- C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys -- (EraserUtilRebootDrv)
DRV - [2012/05/11 22:00:40 | 000,036,776 | ---- | M] (Juniper Networks, Inc.) [Kernel | On_Demand | Unknown] -- C:\WINDOWS\system32\drivers\jnprvamgr.sys -- (JnprVaMgr)
DRV - [2012/04/26 20:07:02 | 000,126,584 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Unknown] -- C:\WINDOWS\system32\drivers\SYMEVENT.SYS -- (SymEvent)
DRV - [2012/04/25 11:34:46 | 000,321,016 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Unknown] -- C:\WINDOWS\system32\drivers\srtspl.sys -- (SRTSPL)
DRV - [2012/04/25 11:34:46 | 000,287,352 | ---- | M] (Symantec Corporation) [File_System | System | Unknown] -- C:\WINDOWS\system32\drivers\srtsp.sys -- (SRTSP)
DRV - [2012/04/25 11:34:46 | 000,043,768 | ---- | M] (Symantec Corporation) [Kernel | System | Unknown] -- C:\WINDOWS\system32\drivers\srtspx.sys -- (SRTSPX)
DRV - [2012/04/25 11:34:40 | 000,421,424 | ---- | M] (Symantec Corporation) [Kernel | System | Unknown] -- C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCDrv.sys -- (SPBBCDrv)
DRV - [2012/04/25 11:34:40 | 000,188,080 | ---- | M] (Symantec Corporation) [Kernel | System | Unknown] -- C:\WINDOWS\system32\drivers\symtdi.sys -- (SYMTDI)
DRV - [2012/04/25 11:34:40 | 000,026,416 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Unknown] -- C:\WINDOWS\system32\drivers\symredrv.sys -- (SYMREDRV)
DRV - [2012/04/25 11:34:40 | 000,023,888 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Unknown] -- C:\WINDOWS\system32\drivers\COH_Mon.sys -- (COH_Mon)
DRV - [2010/12/16 15:43:22 | 000,084,336 | ---- | M] (Juniper Networks) [Kernel | System | Unknown] -- C:\WINDOWS\system32\drivers\NEOFLTR_700_17289.SYS -- (NEOFLTR_700_17289)
DRV - [2010/12/08 00:25:31 | 000,016,968 | ---- | M] () [Kernel | On_Demand | Unknown] -- C:\WINDOWS\system32\drivers\hitmanpro35.sys -- (hitmanpro35)
DRV - [2008/04/13 20:12:09 | 000,088,576 | ---- | M] (Microsoft Corporation) [Unknown (-1) | Unknown (-1) | Unknown] -- C:\WINDOWS\system32\wbem\wmiaprpl.dll -- (WmiApRpl)
DRV - [2007/11/23 20:19:14 | 000,013,056 | ---- | M] (Samsung Electronics, Inc. ) [Kernel | On_Demand | Unknown] -- C:\WINDOWS\system32\drivers\MTiCtwl.sys -- (MagicTune)
DRV - [2007/02/25 12:10:48 | 000,005,376 | ---- | M] (Gteko Ltd.) [Kernel | Auto | Unknown] -- C:\WINDOWS\system32\drivers\dsunidrv.sys -- (dsunidrv)
DRV - [2006/10/05 16:07:28 | 000,004,736 | ---- | M] (Gteko Ltd.) [Kernel | On_Demand | Unknown] -- C:\Program Files\DellSupport\GTAction\triggers\DSproct.sys -- (DSproct)
DRV - [2006/06/12 06:36:30 | 000,009,344 | ---- | M] (Hewlett Packard) [Kernel | On_Demand | Unknown] -- C:\WINDOWS\system32\drivers\hpfxbulk.sys -- (HPFXBULK)
DRV - [2005/08/04 06:10:18 | 001,273,344 | ---- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Unknown] -- C:\WINDOWS\system32\drivers\ati2mtag.sys -- (ati2mtag)
DRV - [2004/10/04 16:57:16 | 000,379,488 | ---- | M] (NETGEAR, Inc.) [Kernel | On_Demand | Unknown] -- C:\WINDOWS\system32\drivers\wg111nd5.sys -- (wg111nd5)
DRV - [2004/10/04 16:57:14 | 000,016,292 | ---- | M] (Printing Communications Assoc., Inc. (PCAUSA)) [Kernel | On_Demand | Unknown] -- C:\WINDOWS\system32\PCANDIS5.SYS -- (PCANDIS5)
DRV - [2004/10/04 16:57:12 | 000,015,781 | ---- | M] (Meetinghouse Data Communications) [Kernel | Auto | Unknown] -- C:\WINDOWS\system32\drivers\mdc8021x.sys -- (MDC8021X)
DRV - [2004/06/16 05:52:40 | 000,061,157 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Unknown] -- C:\WINDOWS\system32\drivers\IntelC53.sys -- (IntelC53)
DRV - [2004/06/09 19:16:00 | 000,840,960 | ---- | M] (Creative Technology Ltd.) [Kernel | On_Demand | Unknown] -- C:\WINDOWS\system32\drivers\P17.sys -- (P17)
DRV - [2004/03/06 06:15:34 | 000,647,929 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Unknown] -- C:\WINDOWS\system32\drivers\IntelC52.sys -- (IntelC52)
DRV - [2004/03/06 06:14:42 | 001,233,525 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Unknown] -- C:\WINDOWS\system32\drivers\IntelC51.sys -- (IntelC51)
DRV - [2004/03/06 06:13:38 | 000,037,048 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Unknown] -- C:\WINDOWS\system32\drivers\mohfilt.sys -- (mohfilt)
DRV - [2003/09/22 15:48:00 | 000,130,192 | ---- | M] (Creative Technology Ltd) [Kernel | On_Demand | Unknown] -- C:\WINDOWS\system32\drivers\ctsfm2k.sys -- (ctsfm2k)
DRV - [2003/09/22 15:47:00 | 000,178,672 | ---- | M] (Creative Technology Ltd.) [Kernel | On_Demand | Unknown] -- C:\WINDOWS\system32\drivers\ctoss2k.sys -- (ossrv)
DRV - [2003/03/05 20:19:00 | 000,015,840 | ---- | M] (Creative Technology Ltd.) [Kernel | Auto | Unknown] -- C:\WINDOWS\system32\drivers\Pfmodnt.sys -- (PfModNT)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://search.live.c...ferrer:source?}
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/myway
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,First Home Page = http://www.dell.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = http://bfc.myway.com...de_srchlft.html
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.dell4me.com/myway
IE - HKCU\..\URLSearchHook: {4D25F926-B9FE-4682-BF72-8AB8210D6D75} - No CLSID value found
IE - HKCU\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://search.live.c...Box&Form=IE8SRC
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
========== FireFox ==========
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\WINDOWS\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Browser Plugin,version=1.0.0: C:\Program Files\DivX\DivX Web Player\npdivx32.dll (DivX,Inc.)
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Player Plugin,version=1.0.0: C:\Program Files\DivX\DivX Player\npDivxPlayerPlugin.dll (DivX, Inc)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.21.2: C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\5.1.20125.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@real.com/nppl3260;version=6.0.12.46: C:\Program Files\Real\RealPlayer\Netscape6\nppl3260.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprjplug;version=1.0.3.46: C:\Program Files\Real\RealPlayer\Netscape6\nprjplug.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprpjplug;version=6.0.12.46: C:\Program Files\Real\RealPlayer\Netscape6\nprpjplug.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nsJSRealPlayerPlugin;version=: File not found
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.145\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.145\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@viewpoint.com/VMP: C:\Program Files\Viewpoint\Viewpoint Experience Technology\npViewpoint.dll ()
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
[2011/04/16 00:22:20 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions
[2010/05/22 20:13:24 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
[2010/09/21 23:35:40 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}
[2010/12/21 04:56:40 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}
[2008/06/18 03:43:04 | 000,086,016 | ---- | M] (Coupons, Inc.) -- C:\Program Files\mozilla firefox\plugins\npCouponPrinter.dll
[2010/07/17 05:00:04 | 000,423,656 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\mozilla firefox\plugins\npdeployJava1.dll
[2010/12/06 08:34:31 | 000,001,919 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\bing-zugo.xml
[2010/11/11 19:26:20 | 000,002,210 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\websearch.xml
========== Chrome ==========
CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:originalQueryForSuggestion}{google:assistedQueryStats}{google:searchFieldtrialParameter}{google:searchClient}{google:sourceId}{google:instantExtendedEnabledParameter}ie={inputEncoding}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client=chrome&q={searchTerms}&{google:cursorPosition}sugkey={google:suggestAPIKeyParameter}
CHR - Extension: Docs = C:\Documents and Settings\loutemp4\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.0.0.6_0\
CHR - Extension: Google Drive = C:\Documents and Settings\loutemp4\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.2_0\
CHR - Extension: YouTube = C:\Documents and Settings\loutemp4\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0\
CHR - Extension: Google Search = C:\Documents and Settings\loutemp4\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0\
CHR - Extension: Gmail = C:\Documents and Settings\loutemp4\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\
O1 HOSTS File: ([2013/06/20 13:38:57 | 000,000,027 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (RealPlayer Download and Record Plugin for Internet Explorer) - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll (RealPlayer)
O2 - BHO: (Spybot-S&D IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O2 - BHO: (DriveLetterAccess) - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll (Sonic Solutions)
O2 - BHO: (Java Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
O2 - BHO: (Java Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O4 - HKLM..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe (Apple Inc.)
O4 - HKLM..\Run: [ccApp] C:\Program Files\Common Files\Symantec Shared\ccApp.exe (Symantec Corporation)
O4 - HKLM..\Run: [combofix] C:\ComboFix\CF5139.3XE (Microsoft Corporation)
O4 - HKLM..\Run: [CTSysVol] C:\Program Files\Creative\Sound Blaster Live! 24-bit\Surround Mixer\CTSysVol.exe (Creative Technology Ltd)
O4 - HKLM..\Run: [DellSupportCenter] C:\Program Files\Dell Support Center\bin\sprtcmd.exe (SupportSoft, Inc.)
O4 - HKLM..\Run: [dscactivate] C:\Program Files\Dell Support Center\gs_agent\custom\dsca.exe ( )
O4 - HKLM..\Run: [HostManager] C:\Program Files\Common Files\AOL\1133066293\ee\aolsoftware.exe (America Online, Inc.)
O4 - HKLM..\Run: [hpbdfawep] C:\Program Files\HP\Dfawep\bin\hpbdfawep.exe ()
O4 - HKLM..\Run: [JunosPulse] C:\Program Files\Common Files\Juniper Networks\JamUI\Pulse.exe (Juniper Networks, Inc.)
O4 - HKLM..\Run: [MimBoot] C:\Program Files\MUSICMATCH\Musicmatch Jukebox\mimboot.exe (Musicmatch, Inc.)
O4 - HKLM..\Run: [MSC] c:\Program Files\Microsoft Security Client\msseces.exe (Microsoft Corporation)
O4 - HKLM..\Run: [P17Helper] C:\WINDOWS\System32\P17.dll ()
O4 - HKLM..\Run: [TkBellExe] C:\Program Files\Common Files\Real\Update_OB\realsched.exe (RealNetworks, Inc.)
O4 - HKLM..\Run: [ToolBoxFX] C:\Program Files\HP\ToolBoxFX\bin\HPTLBXFX.exe (HP)
O4 - HKLM..\Run: [UpdReg] C:\WINDOWS\Updreg.EXE (Creative Technology Ltd.)
O4 - HKLM..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u File not found
O4 - HKCU..\Run: [DellSupport] C:\Program Files\DellSupport\DSAgnt.exe (Gteko Ltd.)
O4 - HKCU..\Run: [OE_OEM] "C:\Program Files\Trend Micro\Internet Security 12\TMAS_OE\TMAS_OEMon.exe" File not found
O4 - HKLM..\RunOnce: [*Restore] C:\WINDOWS\System32\restore\rstrui.exe (Microsoft Corporation)
O4 - HKLM..\RunOnce: [combofix] C:\ComboFix\CF5139.3XE (Microsoft Corporation)
O4 - HKLM..\RunOnce: [Malwarebytes Anti-Malware] C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
O4 - HKLM..\RunOnceEx: [flags] Reg Error: Invalid data type. File not found
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\GammaTray.lnk = C:\Program Files\MagicTune Premium\GammaTray.exe ()
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Smart Wizard Wireless Settings.lnk = C:\Program Files\NETGEAR\WG111 Configuration Utility\WG111CFG.exe ()
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: InstallVisualStyle = C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles (Microsoft)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: InstallTheme = C:\WINDOWS\Resources\Themes\Royale.theme ()
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O9 - Extra 'Tools' menuitem : Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O15 - HKLM\..Trusted Domains: musicmatch.com ([online] https in Trusted sites)
O16 - DPF: {01A88BB1-1174-41EC-ACCB-963509EAE56B} http://support.dell....iler/SysPro.CAB (SysProWmi Class)
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} http://www.apple.com...ex/qtplugin.cab (QuickTime Object)
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://fpdownload.ma...director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://go.microsoft....k/?linkid=39204 (Windows Genuine Advantage Validation Tool)
O16 - DPF: {238F6F83-B8B4-11CF-8771-00A024541EE3} http://www.classlink...FILES/wfica.cab (Citrix ICA Client)
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} http://update.micros...b?1133059359261 (WUWebControl Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/...indows-i586.cab (Java Plug-in 10.21.2)
O16 - DPF: {8D9563A9-8D5F-459B-87F2-BA842255CB9A} https://owa.markelco.../WhlCompMgr.cab (Forefront UAG client components)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.ma...t/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {A5A76EA0-7B92-4707-9DBF-6F6FE56A6800} http://scan.networkm...-ship-WD.V1.cab (Pure Networks Security Scan)
O16 - DPF: {CAFEEFAC-0016-0000-0031-ABCDEFFEDCBA} Reg Error: Value error. (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0037-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_37)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 10.21.2)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.m...ash/swflash.cab (Shockwave Flash Object)
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} http://www.popcap.co...aploader_v6.cab (PopCapLoader Object)
O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} https://akamaicdn.we...bex/ieatgpc.cab (GpcContainer Class)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.ad...Plus/1.6/gp.cab (Reg Error: Key error.)
O16 - DPF: {E5F5D008-DD2C-4D32-977D-1A0ADF03058B} https://my.markelcor...perSetupSP1.cab (JuniperSetupControlXP Class)
O16 - DPF: {E856B973-45FD-4559-8F82-EAB539144667} http://pccheckup.del...ll/gtdownde.cab (Dell PC Checkup Installer Control)
O16 - DPF: {F27237D7-93C8-44C2-AC6E-D6057B9A918F} https://my.markelcor...SetupClient.cab (JuniperSetupClientControl Class)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{97A2D01D-706C-42BC-86B5-8D2B8A6093EF}: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{BC2022F4-FD03-4BF5-A57C-C7872A4A6CEE}: DhcpNameServer = 192.168.1.1
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) - C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O20 - Winlogon\Notify\WRNotifier: DllName - (WRLogonNTF.dll) - File not found
O24 - Desktop WallPaper: C:\Documents and Settings\loutemp4\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\loutemp4\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2005/08/16 06:43:04 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O32 - AutoRun File - [2008/05/06 08:26:23 | 000,000,309 | R--- | M] () - F:\autorun.inf -- [ CDFS ]
O33 - MountPoints2\{361ac05d-0e0d-11da-9aa9-806d6172696f}\Shell - "" = AutoRun
O33 - MountPoints2\{361ac05d-0e0d-11da-9aa9-806d6172696f}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{361ac05d-0e0d-11da-9aa9-806d6172696f}\Shell\AutoRun\command - "" = E:\setup.exe
O34 - HKLM BootExecute: (autocheck autochk *)
O34 - HKLM BootExecute: (SsiEfr.e)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = ComFile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
========== Files/Folders - Created Within 30 Days ==========
[2013/06/23 19:07:21 | 000,602,112 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\loutemp4\Desktop\OTL.exe
[2013/06/23 19:02:50 | 000,000,000 | ---D | C] -- C:\Documents and Settings\loutemp4\Application Data\Adobe
[2013/06/23 19:02:49 | 000,000,000 | -HSD | C] -- C:\Documents and Settings\loutemp4\PrivacIE
[2013/06/23 15:06:53 | 000,728,448 | ---- | C] (Enigma Software Group USA, LLC.) -- C:\Documents and Settings\loutemp4\My Documents\SpyHunter-Installer.exe
[2013/06/22 11:27:11 | 000,000,000 | ---D | C] -- C:\Documents and Settings\loutemp4\Local Settings\Application Data\Google
[2013/06/22 11:21:26 | 000,000,000 | ---D | C] -- C:\Documents and Settings\loutemp4\Local Settings\Application Data\BVRP Software
[2013/06/22 11:17:53 | 000,000,000 | ---D | C] -- C:\Documents and Settings\loutemp4\Local Settings\Application Data\AOL
[2013/06/22 11:17:47 | 000,000,000 | ---D | C] -- C:\Documents and Settings\loutemp4\Application Data\GTek
[2013/06/22 11:17:46 | 000,000,000 | ---D | C] -- C:\Documents and Settings\loutemp4\Local Settings\Application Data\Apple Computer
[2013/06/22 11:17:24 | 000,000,000 | ---D | C] -- C:\Documents and Settings\loutemp4\Local Settings\Application Data\SupportSoft
[2013/06/22 11:17:14 | 000,000,000 | ---D | C] -- C:\Documents and Settings\loutemp4\Application Data\HP
[2013/06/22 11:17:08 | 000,000,000 | ---D | C] -- C:\Documents and Settings\loutemp4\Application Data\Juniper Networks
[2013/06/22 11:17:02 | 000,000,000 | ---D | C] -- C:\Documents and Settings\loutemp4\Application Data\Real
[2013/06/22 11:15:44 | 000,000,000 | ---D | C] -- C:\Documents and Settings\loutemp4\Local Settings\Application Data\Symantec
[2013/06/22 11:15:21 | 000,000,000 | ---D | C] -- C:\Documents and Settings\loutemp4\Application Data\Macromedia
[2013/06/22 11:15:21 | 000,000,000 | ---D | C] -- C:\Documents and Settings\loutemp4\Application Data\Identities
[2013/06/22 11:15:21 | 000,000,000 | ---D | C] -- C:\Documents and Settings\loutemp4\Application Data\Creative
[2013/06/22 11:15:20 | 000,000,000 | --SD | C] -- C:\Documents and Settings\loutemp4\Application Data\Microsoft
[2013/06/22 11:15:20 | 000,000,000 | RH-D | C] -- C:\Documents and Settings\loutemp4\SendTo
[2013/06/22 11:15:20 | 000,000,000 | RH-D | C] -- C:\Documents and Settings\loutemp4\Recent
[2013/06/22 11:15:20 | 000,000,000 | RH-D | C] -- C:\Documents and Settings\loutemp4\Application Data
[2013/06/22 11:15:20 | 000,000,000 | R--D | C] -- C:\Documents and Settings\loutemp4\Start Menu\Programs\Startup
[2013/06/22 11:15:20 | 000,000,000 | R--D | C] -- C:\Documents and Settings\loutemp4\Start Menu
[2013/06/22 11:15:20 | 000,000,000 | R--D | C] -- C:\Documents and Settings\loutemp4\My Documents\My Pictures
[2013/06/22 11:15:20 | 000,000,000 | R--D | C] -- C:\Documents and Settings\loutemp4\My Documents\My Music
[2013/06/22 11:15:20 | 000,000,000 | R--D | C] -- C:\Documents and Settings\loutemp4\My Documents
[2013/06/22 11:15:20 | 000,000,000 | R--D | C] -- C:\Documents and Settings\loutemp4\Favorites
[2013/06/22 11:15:20 | 000,000,000 | R--D | C] -- C:\Documents and Settings\loutemp4\Start Menu\Programs\Accessories
[2013/06/22 11:15:20 | 000,000,000 | -HSD | C] -- C:\Documents and Settings\loutemp4\IETldCache
[2013/06/22 11:15:20 | 000,000,000 | -HSD | C] -- C:\Documents and Settings\loutemp4\Cookies
[2013/06/22 11:15:20 | 000,000,000 | -H-D | C] -- C:\Documents and Settings\loutemp4\Templates
[2013/06/22 11:15:20 | 000,000,000 | -H-D | C] -- C:\Documents and Settings\loutemp4\PrintHood
[2013/06/22 11:15:20 | 000,000,000 | -H-D | C] -- C:\Documents and Settings\loutemp4\NetHood
[2013/06/22 11:15:20 | 000,000,000 | -H-D | C] -- C:\Documents and Settings\loutemp4\Local Settings
[2013/06/22 11:15:20 | 000,000,000 | ---D | C] -- C:\Documents and Settings\loutemp4\Local Settings\Application Data\Wildtangent
[2013/06/22 11:15:20 | 000,000,000 | ---D | C] -- C:\Documents and Settings\loutemp4\Application Data\Sun
[2013/06/22 11:15:20 | 000,000,000 | ---D | C] -- C:\Documents and Settings\loutemp4\Local Settings\Application Data\Musicmatch
[2013/06/22 11:15:20 | 000,000,000 | ---D | C] -- C:\Documents and Settings\loutemp4\Local Settings\Application Data\Microsoft
[2013/06/22 11:15:20 | 000,000,000 | ---D | C] -- C:\Documents and Settings\loutemp4\Desktop
[2013/06/22 11:15:20 | 000,000,000 | ---D | C] -- C:\Documents and Settings\loutemp4\Start Menu\Programs\Dell Accessories
[2013/06/22 11:15:20 | 000,000,000 | ---D | C] -- C:\Documents and Settings\loutemp4\Start Menu\Programs\Dell
[2013/06/22 11:15:20 | 000,000,000 | ---D | C] -- C:\Documents and Settings\loutemp4\My Documents\CCWin
[2013/06/22 11:15:20 | 000,000,000 | ---D | C] -- C:\Documents and Settings\loutemp4\Local Settings\Application Data\ApplicationHistory
[2013/06/22 11:15:20 | 000,000,000 | ---D | C] -- C:\Documents and Settings\loutemp4\Local Settings\Application Data\{7148F0A6-6813-11D6-A77B-00B0D0142030}
[2013/06/20 22:47:15 | 000,040,776 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2013/06/20 22:35:43 | 000,000,000 | -HSD | C] -- C:\RECYCLER
[2013/06/20 18:08:05 | 010,285,040 | ---- | C] (Malwarebytes Corporation ) -- C:\mbam-setup-1.75.0.1300.exe
[2013/06/20 14:06:34 | 000,000,000 | ---D | C] -- C:\Kaspersky Rescue Disk 10.0
[2013/06/20 13:38:41 | 000,000,000 | ---D | C] -- C:\WINDOWS\temp
[2013/06/20 13:21:33 | 000,000,000 | --SD | C] -- C:\ComboFix
[2013/06/17 01:01:15 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\HitmanPro
[2013/06/17 01:01:14 | 000,000,000 | ---D | C] -- C:\Program Files\HitmanPro
[2013/06/17 01:01:13 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\HitmanPro
[28 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[2 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2013/06/23 19:07:27 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\loutemp4\Desktop\OTL.exe
[2013/06/23 18:43:00 | 000,000,888 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2013/06/23 18:24:00 | 000,000,830 | ---- | M] () -- C:\WINDOWS\tasks\Adobe Flash Player Updater.job
[2013/06/23 15:21:09 | 000,000,884 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2013/06/23 15:19:25 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2013/06/23 15:19:19 | 2145,538,048 | -HS- | M] () -- C:\hiberfil.sys
[2013/06/23 15:07:00 | 000,728,448 | ---- | M] (Enigma Software Group USA, LLC.) -- C:\Documents and Settings\loutemp4\My Documents\SpyHunter-Installer.exe
[2013/06/23 14:35:59 | 000,002,206 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2013/06/22 11:28:31 | 000,001,831 | ---- | M] () -- C:\Documents and Settings\loutemp4\Application Data\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk
[2013/06/22 11:28:31 | 000,001,813 | ---- | M] () -- C:\Documents and Settings\loutemp4\Desktop\Google Chrome.lnk
[2013/06/22 11:18:49 | 000,002,528 | ---- | M] () -- C:\Documents and Settings\loutemp4\Application Data\$_hpcst$.hpc
[2013/06/22 11:16:34 | 000,000,815 | ---- | M] () -- C:\Documents and Settings\loutemp4\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
[2013/06/22 11:16:22 | 000,000,782 | ---- | M] () -- C:\Documents and Settings\loutemp4\Desktop\Windows Media Player.lnk
[2013/06/22 11:16:12 | 000,001,478 | ---- | M] () -- C:\Documents and Settings\loutemp4\Application Data\Microsoft\Internet Explorer\Quick Launch\Media Center.lnk
[2013/06/20 22:59:58 | 000,040,776 | ---- | M] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2013/06/20 22:21:55 | 000,000,784 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Malwarebytes Anti-Malware.lnk
[2013/06/20 21:54:43 | 000,000,353 | -HS- | M] () -- C:\boot.ini
[2013/06/20 18:08:44 | 000,000,071 | ---- | M] () -- C:\.directory
[2013/06/20 18:08:10 | 010,285,040 | ---- | M] (Malwarebytes Corporation ) -- C:\mbam-setup-1.75.0.1300.exe
[2013/06/20 14:13:37 | 000,001,076 | ---- | M] () -- C:\WINDOWS\System32\.crusader
[2013/06/20 14:11:34 | 001,097,634 | ---- | M] () -- C:\Documents and Settings\All Users\Application Data\2433f433
[2013/06/20 13:38:57 | 000,000,027 | ---- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts
[2013/06/17 13:42:22 | 000,001,610 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\HitmanPro.lnk
[2013/06/13 08:48:07 | 000,001,374 | ---- | M] () -- C:\WINDOWS\imsins.BAK
[2013/06/05 11:02:00 | 000,000,284 | ---- | M] () -- C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[28 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[2 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
========== Files Created - No Company Name ==========
[2013/06/23 15:19:19 | 2145,538,048 | -HS- | C] () -- C:\hiberfil.sys
[2013/06/22 11:18:49 | 000,002,528 | ---- | C] () -- C:\Documents and Settings\loutemp4\Application Data\$_hpcst$.hpc
[2013/06/22 11:16:34 | 000,000,803 | ---- | C] () -- C:\Documents and Settings\loutemp4\Start Menu\Programs\Internet Explorer.lnk
[2013/06/22 11:16:33 | 000,001,831 | ---- | C] () -- C:\Documents and Settings\loutemp4\Application Data\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk
[2013/06/22 11:16:33 | 000,001,813 | ---- | C] () -- C:\Documents and Settings\loutemp4\Desktop\Google Chrome.lnk
[2013/06/22 11:16:22 | 000,000,788 | ---- | C] () -- C:\Documents and Settings\loutemp4\Start Menu\Programs\Windows Media Player.lnk
[2013/06/22 11:16:22 | 000,000,782 | ---- | C] () -- C:\Documents and Settings\loutemp4\Desktop\Windows Media Player.lnk
[2013/06/22 11:15:24 | 000,002,007 | ---- | C] () -- C:\Documents and Settings\loutemp4\Application Data\Microsoft\Internet Explorer\Quick Launch\Play Games.lnk
[2013/06/22 11:15:24 | 000,001,769 | ---- | C] () -- C:\Documents and Settings\loutemp4\Application Data\Microsoft\Internet Explorer\Quick Launch\Musicmatch Jukebox.lnk
[2013/06/22 11:15:24 | 000,001,478 | ---- | C] () -- C:\Documents and Settings\loutemp4\Application Data\Microsoft\Internet Explorer\Quick Launch\Media Center.lnk
[2013/06/22 11:15:24 | 000,000,815 | ---- | C] () -- C:\Documents and Settings\loutemp4\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
[2013/06/22 11:15:24 | 000,000,742 | ---- | C] () -- C:\Documents and Settings\loutemp4\Application Data\Microsoft\Internet Explorer\Quick Launch\QuickTime Player.lnk
[2013/06/22 11:15:24 | 000,000,669 | ---- | C] () -- C:\Documents and Settings\loutemp4\Application Data\Microsoft\Internet Explorer\Quick Launch\America Online 9.0.lnk
[2013/06/22 11:15:24 | 000,000,079 | ---- | C] () -- C:\Documents and Settings\loutemp4\Application Data\Microsoft\Internet Explorer\Quick Launch\Show Desktop.scf
[2013/06/22 11:15:23 | 000,001,298 | ---- | C] () -- C:\Documents and Settings\loutemp4\Desktop\Media Center.lnk
[2013/06/22 11:15:23 | 000,000,136 | ---- | C] () -- C:\Documents and Settings\loutemp4\Local Settings\Application Data\fusioncache.dat
[2013/06/22 11:15:21 | 000,001,503 | ---- | C] () -- C:\Documents and Settings\loutemp4\Start Menu\Programs\Remote Assistance.lnk
[2013/06/22 11:15:21 | 000,000,738 | ---- | C] () -- C:\Documents and Settings\loutemp4\Start Menu\Programs\Outlook Express.lnk
[2013/06/20 22:21:55 | 000,000,784 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Malwarebytes Anti-Malware.lnk
[2013/06/20 21:54:32 | 000,001,659 | ---- | C] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Smart Wizard Wireless Settings.lnk
[2013/06/20 21:54:32 | 000,000,513 | ---- | C] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Startup\GammaTray.lnk
[2013/06/20 18:08:44 | 000,000,071 | ---- | C] () -- C:\.directory
[2013/06/20 14:11:34 | 001,097,634 | ---- | C] () -- C:\Documents and Settings\All Users\Application Data\2433f433
[2013/06/17 01:01:20 | 000,001,610 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\HitmanPro.lnk
[2013/05/18 22:27:55 | 002,250,054 | ---- | C] () -- C:\Documents and Settings\All Users\Application Data\1.bmp
[2013/05/18 22:27:33 | 000,350,795 | ---- | C] () -- C:\Documents and Settings\All Users\Application Data\1.jpg
[2012/02/16 11:00:58 | 000,003,072 | ---- | C] () -- C:\WINDOWS\System32\iacenc.dll
[2005/12/28 23:34:41 | 000,001,347 | ---- | C] () -- C:\Documents and Settings\All Users\Application Data\QTSBandwidthCache
[2005/12/20 22:35:05 | 000,000,360 | ---- | C] () -- C:\Program Files\desktop.ica
========== ZeroAccess Check ==========
[2005/08/16 06:39:16 | 000,000,227 | RHS- | M] () -- C:\WINDOWS\assembly\Desktop.ini
[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shdocvw.dll -- [2009/04/29 00:46:52 | 001,499,136 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll -- [2009/02/09 08:10:48 | 000,473,600 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
"" = %systemroot%\system32\wbem\wbemess.dll -- [2008/04/13 20:12:08 | 000,273,920 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both
========== LOP Check ==========
[2010/08/26 20:11:18 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Alwil Software
[2007/06/19 21:48:37 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Citrix
[2005/08/16 22:54:52 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\DIGStream
[2008/10/19 21:59:26 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\EPSON
[2013/06/17 14:22:36 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\HitmanPro
[2012/05/09 11:08:13 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Juniper Networks
[2013/04/07 13:55:40 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\pdf995
[2006/07/23 20:44:37 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\PopCap
[2008/03/01 21:14:01 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\SupportSoft
[2013/03/16 10:10:57 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\TaxCut
[2007/02/28 19:02:35 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Viewpoint
[2013/06/22 11:17:08 | 000,000,000 | ---D | M] -- C:\Documents and Settings\loutemp4\Application Data\Juniper Networks
========== Purity Check ==========
< End of report >