Bios inaccessible, windows XP not booting. (homeland security lock variant)

Inactive
By jomon324
Jul 2, 2013
Topic Status:
Not open for further replies.
  1. Hey everyone. I came here once with ThinkPoint infecting my computer. You guys helped me kill it. Now I need your pro knowledge once again please.

    PART 1

    My Dad's having a ton of trouble with his desktop computer. It got attacked by what he called a "variant" of the "Homeland Security" malware. He was browsing the internet and Malwarebytes started to say 14 malware removed, 18 malware removed, and escalated once more until it ceased to function while Avast antivirus simultaneously brought up an orange flag for less than half a second, and as the background changed to orange and the word "Avast" began to appear, the computer shut off.

    This is the second attack his desktop has endured. The first attack was FBI ransomware, but that was eradicated with the help of using F8 to launch "safe mode with support" and disabling questionable applications from the desktop using Task Manager and shutting the programs off. He then used Malwarebytes Anti Malware and Auslogics Pro's advanced tools to clean the registry. He then used Auslogics Task Manager to expand all programs (inactive programs included), and then using the ability of Auslogics Task Manager to hover his cursor over every program individually and cause an internet search to run on whatever program his cursor is hovering over, so that he can gain information about it and then potentially delete it if it was the malware.

    He also used a website that he cannot remember the name of, but which contained information specifically listing how to remove the FBI malware from the registry. There were around six program listings in total that he searched for, and couldn't find because they had already been eradicated by either Auslogics or Malwarebytes Anti Malware. When he rebooted his computer, everything seemed to be fine. He rebooted 6 times (to check and see if a DOS program which apparently runs every fifth boot of your computer was running) and everything seemed to be fine and working normally.

    That brings us to now: PART 2

    While his computer seemed to be working fine, a few weeks later (now), his computer was attacked a second time. This time, the phrase "Homeland Security something something" appeared, and my dad tried to look up on his tablet how to remove the malware/virus. The tablet said this is another, more advanced, version of the FBI malware. It warned that attempting to reboot your computer or pressing Ctrl+Alt+Del while the screen showed the malware splash screen would result in the malware launching a rootkit, which my dad unfortunately didn't get to see as he was panicked and hit Ctrl+Alt+Del while still reading on his tablet.

    Now his computer won't even boot to DOS.

    I need your help please. Having a pro would be utmost appreciated.

    ((( NOTE: )))
    In the time it takes you to have read this, I am going to attempt to create a Bootable USB stick using a Centron 4GB Datastick PRO, and having the USB Stick equipped with UNetbootin: link for reference ( http://unetbootin.sourceforge.net/unetbootin-windows-latest.exe ) which I got from ( lifehacker.com/the-complete-guide-to-saving-your-windows-system-with-a-thumb-drive )

    Thank you so much for your time reading this post and I thank you in advance for any help I might receive on this topic. I'm also hoping to convince my dad to become active on the TechSpot Virus and Malware Removal forums so he can be more educated on the subject and be able to deal with things like this much easier. My apologies for any run-on sentences, as I was asking my dad for play-by-play information and typing it as he said it so you guys have the most accurate stuff to work with.
  2. Broni

    Broni Malware Annihilator Posts: 45,269   +243

    You abandoned this topic in the past: http://www.techspot.com/community/t...n-exe-both-infected-using-taskmanager.155340/
    If it happens again you won't be eligible to receive any more help in malware removal forum.

    Please, observe following rules:
    • Read all of my instructions very carefully. Your mistakes during cleaning process may have very serious consequences, like unbootable computer.
    • If you're stuck, or you're not sure about certain step, always ask before doing anything else.
    • Please refrain from running any tools, fixes or applying any changes to your computer other than those I suggest.
    • Never run more than one scan at a time.
    • Keep updating me regarding your computer behavior, good, or bad.
    • The cleaning process, once started, has to be completed. Even if your computer appears to act better, it may still be infected. Once the computer is totally clean, I'll certainly let you know.
    • If you leave the topic without explanation in the middle of a cleaning process, you may not be eligible to receive any more help in malware removal forum.
    • I close my topics if you have not replied in 5 days. If you need more time, simply let me know. If I closed your topic and you need it to be reopened, simply PM me.

    ===============================================

    Let's see, if we can look at your computer booting from an external source.

    Please download OTLPE (filesize 120,9 MB)

    • When downloaded double click on OTLPENet.exe and make sure there is a blank CD in your CD drive. This will automatically create a bootable CD.
    • Reboot your system using the boot CD you just created.
      • Note : If you do not know how to set your computer to boot from CD follow the steps here
    • Your system should now display a REATOGO-X-PE desktop.
    • Depending on your type of internet connection, you should be able to get online as well so you can access this topic more easily.
    • Double-click on the OTLPE icon.
    • When asked Do you wish to load the remote registry, select Yes
    • When asked Do you wish to load remote user profile(s) for scanning, select Yes
    • Ensure the box Automatically Load All Remaining Users" is checked and press OK
    • OTL should now start.
    • Press Run Scan to start the scan.
    • When finished, the file will be saved in drive C:\OTL.txt
    • Copy this file to your USB drive if you do not have internet connection on this system
    • Please post the contents of the OTL.txt file in your reply.
  3. jomon324

    jomon324 Newcomer, in training Topic Starter Posts: 40

    Whoa, I apologize for abandoning the Bamital topic. I must have misread the rules or just lost my common sense for a day, because I thought that if no replies were left on a topic it would be considered resolved. I now realize how stupid that sounds. This is a side note and may sound quite pretentious, but is there a way I can remove that strike from my account? I'd really rather not be locked out of receiving (and potentially being able to give) help on this forum.

    I should also clarify, the computer I am typing this from is my own computer, not the infected one which is my father's. His computer is unable to even get to bios, which sounds a lot like "Your mistakes during cleaning process may have very serious consequences, like unbootable computer."

    I have one question about the OTLPE process: does the burnable media have to be a CD, or can it be a DVD+/-? His computer has a drive that can read DVDs, and at the moment I only have DVDs to burn to. I can get CDs if DVDs are unusable in the process.

    I apologize if I sound rude here. I am a little tired at the moment, and I am trying to organize my words so they don't sound rude, but rereading them makes them sound worse.

    Mr. Broni, I will try to use the OTLPE program at the earliest available time tomorrow, as my dad is asleep at the time I am writing this (11:55pm EST).
  4. Broni

    Broni Malware Annihilator Posts: 45,269   +243

    CD would be better.
  5. jomon324

    jomon324 Newcomer, in training Topic Starter Posts: 40

    Mr. Broni, I was just able to download the OTLPE program and burned a CD with it (we went out and bought a few blank CDs), and when we tried to start the computer using the OTLPE program, it didn't work.

    The computer power light turned on, I heard the disc spinning, but the monitor never turned on. We also began to rapidly press F2 and DEL immediately upon turning the computer on with the disc in the CD drive, and the monitor never turned on but remained in standby mode. The monitor is connected to the computer properly, but it seems that the signal for the monitor to display images is not being sent.

    My ignorance here might be appalling, but here goes: my dad wants to try removing the hard drive and turning on the computer to force it to start the BIOS from the motherboard. I don't have any knowledge as to if this will work or not, but I figure you probably know what he's saying more than I do.
  6. Broni

    Broni Malware Annihilator Posts: 45,269   +243

    It may be video card or video chip issue.
    Can you connect this very monitor to some other computer to see if the monitor is OK?
  7. jomon324

    jomon324 Newcomer, in training Topic Starter Posts: 40

    I will do so at my earliest availability and respond back. Things got a little busier today than usual.
    (edited at 9:38pm EST due to forgotten punctuation.)
  8. Broni

    Broni Malware Annihilator Posts: 45,269   +243

  9. jomon324

    jomon324 Newcomer, in training Topic Starter Posts: 40

    Turns out the video card was fine, and somehow my dad got the PC to start from the CD Drive. He thought it had started from the USB stick (which is where the Ubuntu thing I had was), but just to be safe I told him not to touch anything.

    Anyway, here are the contents of the OTL.txt file created when we ran OTLPE (in multiple parts due to 50000 character limit)

    (PART 1)
    OTL logfile created on: 7/4/2013 2:48:46 PM - Run
    OTLPE by OldTimer - Version 3.1.48.0 Folder = X:\Programs\OTLPE
    Microsoft Windows XP Service Pack 3 (Version = 5.1.2600) - Type = SYSTEM
    Internet Explorer (Version = 8.0.6001.18702)
    Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

    2.00 Gb Total Physical Memory | 2.00 Gb Available Physical Memory | 86.00% Memory free
    2.00 Gb Paging File | 2.00 Gb Available in Paging File | 97.00% Paging File free
    Paging file location(s): C:\pagefile.sys 1524 3048 [binary data]

    %SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
    Drive C: | 70.13 Gb Total Space | 1.38 Gb Free Space | 1.96% Space Free | Partition Type: NTFS
    Drive D: | 3.76 Gb Total Space | 3.06 Gb Free Space | 81.46% Space Free | Partition Type: FAT32
    Drive X: | 436.59 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS

    Computer Name: REATOGO | User Name: SYSTEM
    Boot Mode: Normal | Scan Mode: All users
    Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
    Using ControlSet: ControlSet001

    ========== Win32 Services (SafeList) ==========

    SRV - File not found [Disabled] -- -- (PsaSrv)
    SRV - [2013/06/26 23:39:36 | 000,159,744 | ---- | M] (Microsoft Corporation) [Auto] -- C:\Documents and Settings\All Users\Application Data\rlqv.dat -- (winmgmt)
    SRV - [2013/06/18 10:21:21 | 000,117,144 | ---- | M] (Mozilla Foundation) [On_Demand] -- C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe -- (MozillaMaintenance)
    SRV - [2013/06/12 10:32:39 | 000,256,904 | ---- | M] (Adobe Systems Incorporated) [On_Demand] -- C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc)
    SRV - [2013/05/09 04:58:30 | 000,046,808 | ---- | M] (AVAST Software) [Auto] -- C:\Program Files\AVAST Software\Avast\AvastSvc.exe -- (avast! Antivirus)
    SRV - [2013/05/09 04:58:27 | 000,137,960 | ---- | M] (AVAST Software) [Auto] -- C:\Program Files\AVAST Software\Avast\afwServ.exe -- (avast! Firewall)
    SRV - [2013/04/04 14:50:32 | 000,701,512 | ---- | M] (Malwarebytes Corporation) [Auto] -- C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe -- (MBAMService)
    SRV - [2013/04/04 14:50:32 | 000,418,376 | ---- | M] (Malwarebytes Corporation) [Auto] -- C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe -- (MBAMScheduler)
    SRV - [2013/03/27 22:53:22 | 000,990,896 | ---- | M] () [Auto] -- C:\Program Files\Common Files\AVG Secure Search\vToolbarUpdater\15.0.0\ToolbarUpdater.exe -- (vToolbarUpdater15.0.0)
    SRV - [2013/03/10 17:58:59 | 000,170,912 | ---- | M] (Oracle Corporation) [Auto] -- C:\Program Files\Java\jre7\bin\jqs.exe -- (JavaQuickStarterService)
    SRV - [2012/04/13 12:37:08 | 000,078,336 | ---- | M] (Dassault Systèmes) [On_Demand] -- C:\Program Files\Dassault Systemes\DraftSight\bin\dsHttpApiService.exe -- (DraftSight API Service)
    SRV - [2010/12/08 18:31:06 | 000,628,736 | ---- | M] (Nokia) [On_Demand] -- C:\Program Files\PC Connectivity Solution\ServiceLayer.exe -- (ServiceLayer)
    SRV - [2010/05/18 18:13:58 | 000,935,208 | ---- | M] (Nero AG) [Auto] -- C:\Program Files\Common Files\Nero\Nero BackItUp 4\NBService.exe -- (Nero BackItUp Scheduler 4.0)
    SRV - [2010/01/21 23:33:04 | 001,992,128 | ---- | M] (Seagull Scientific) [Auto] -- C:\Program Files\Seagull\BarTender Suite\BarTender\CmdrSrv.exe -- (Commander Service)
    SRV - [2010/01/21 23:14:32 | 000,042,392 | ---- | M] (Seagull Scientific, Inc.) [Disabled] -- C:\Program Files\Seagull\BarTender Suite\System\BtSystem.Service.exe -- (BarTender System Service)
    SRV - [2010/01/21 23:13:26 | 000,239,000 | ---- | M] (Seagull Scientific, Inc.) [Auto] -- C:\Program Files\Seagull\BarTender Suite\Printer Maestro\Maestro.Service.exe -- (Maestro)
    SRV - [2009/11/19 15:26:54 | 000,455,944 | ---- | M] () [On_Demand] -- C:\Program Files\Flip Video\FlipShare\FlipShareService.exe -- (FlipShare Service)
    SRV - [2005/09/23 10:01:16 | 002,799,808 | ---- | M] (Microsoft Corporation) [Disabled] -- C:\Program Files\Microsoft Visual Studio 8\Common7\IDE\Remote Debugger\x86\msvsmon.exe -- (msvsmon80)
    SRV - [2005/01/27 21:45:02 | 000,040,551 | ---- | M] (UPEK Inc.) [Auto] -- C:\Program Files\Common Files\Virtual Token\vtserver.exe -- (vtserver)
    SRV - [2004/12/16 08:49:44 | 000,385,024 | ---- | M] () [Disabled] -- C:\Program Files\IBM\IBM Rapid Restore Ultra\rrpcsb.exe -- (IBM Rapid Restore Ultra Service)
  10. jomon324

    jomon324 Newcomer, in training Topic Starter Posts: 40

    (PART 2)


    ========== Driver Services (SafeList) ==========

    DRV - File not found [Kernel | On_Demand] -- -- (WDICA)
    DRV - File not found [Kernel | Auto] -- -- (SSPORT)
    DRV - File not found [Kernel | On_Demand] -- -- (PDRFRAME)
    DRV - File not found [Kernel | On_Demand] -- -- (PDRELI)
    DRV - File not found [Kernel | On_Demand] -- -- (PDFRAME)
    DRV - File not found [Kernel | On_Demand] -- -- (PDCOMP)
    DRV - File not found [Kernel | System] -- -- (PCIDump)
    DRV - File not found [Kernel | System] -- -- (lbrtfdc)
    DRV - File not found [Kernel | Auto] -- -- (EGATHDRV)
    DRV - File not found [Kernel | Auto] -- -- (DgiVecp)
    DRV - File not found [Kernel | Auto] -- -- (Crypto)
    DRV - File not found [Kernel | System] -- -- (Changer)
    DRV - [2013/06/26 15:08:10 | 000,770,344 | ---- | M] (AVAST Software) [File_System | System] -- C:\WINDOWS\System32\drivers\aswSnx.sys -- (aswSnx)
    DRV - [2013/06/26 15:08:10 | 000,369,456 | ---- | M] (AVAST Software) [Kernel | System] -- C:\WINDOWS\System32\drivers\aswSP.sys -- (aswSP)
    DRV - [2013/05/09 04:59:10 | 000,174,664 | ---- | M] () [Kernel | Boot] -- C:\WINDOWS\System32\drivers\aswVmm.sys -- (aswVmm)
    DRV - [2013/05/09 04:59:10 | 000,056,080 | ---- | M] (AVAST Software) [Kernel | System] -- C:\WINDOWS\System32\drivers\aswTdi.sys -- (aswTdi)
    DRV - [2013/05/09 04:59:10 | 000,049,376 | ---- | M] () [Kernel | Boot] -- C:\WINDOWS\System32\drivers\aswRvrt.sys -- (aswRvrt)
    DRV - [2013/05/09 04:59:09 | 000,204,784 | ---- | M] (AVAST Software) [Kernel | Boot] -- C:\WINDOWS\system32\drivers\aswNdis2.sys -- (aswNdis2)
    DRV - [2013/05/09 04:59:09 | 000,066,336 | ---- | M] (AVAST Software) [File_System | Auto] -- C:\WINDOWS\system32\drivers\aswMonFlt.sys -- (aswMonFlt)
    DRV - [2013/05/09 04:59:09 | 000,049,760 | ---- | M] (AVAST Software) [Kernel | System] -- C:\WINDOWS\System32\drivers\aswRdr.sys -- (AswRdr)
    DRV - [2013/05/09 04:59:09 | 000,021,576 | ---- | M] (AVAST Software) [Kernel | System] -- C:\WINDOWS\System32\drivers\aswKbd.sys -- (aswKbd)
    DRV - [2013/05/09 04:59:08 | 000,104,752 | ---- | M] (AVAST Software) [Kernel | System] -- C:\WINDOWS\System32\drivers\aswFW.sys -- (aswFW)
    DRV - [2013/05/09 04:59:08 | 000,029,816 | ---- | M] (AVAST Software) [File_System | Auto] -- C:\WINDOWS\System32\drivers\aswFsBlk.sys -- (aswFsBlk)
    DRV - [2013/04/04 14:50:32 | 000,022,856 | ---- | M] (Malwarebytes Corporation) [File_System | On_Demand] -- C:\WINDOWS\system32\drivers\mbam.sys -- (MBAMProtector)
    DRV - [2013/03/27 22:53:22 | 000,033,624 | ---- | M] (AVG Technologies) [Kernel | System] -- C:\WINDOWS\system32\drivers\avgtpx86.sys -- (avgtp)
    DRV - [2013/03/13 14:01:58 | 000,012,112 | ---- | M] (ALWIL Software) [Kernel | Boot] -- C:\WINDOWS\system32\drivers\aswNdis.sys -- (aswNdis)
    DRV - [2011/10/07 13:52:18 | 000,021,504 | ---- | M] (http://libusb-win32.sourceforge.net) [Kernel | On_Demand] -- C:\WINDOWS\system32\drivers\libusb0.sys -- (libusb0)
    DRV - [2011/07/10 17:33:26 | 000,016,976 | ---- | M] (AVG Technologies CZ, s.r.o. ) [Kernel | On_Demand] -- C:\WINDOWS\system32\drivers\WINDRVR6.SYS -- (WinDriver6)
    DRV - [2011/05/10 11:06:14 | 000,018,432 | ---- | M] (Apple Inc.) [Kernel | On_Demand] -- C:\WINDOWS\system32\drivers\netaapl.sys -- (Netaapl)
    DRV - [2010/09/20 12:23:48 | 000,041,744 | ---- | M] () [Kernel | Auto] -- C:\WINDOWS\System32\drivers\PciSx.SYS -- (PciSx)
    DRV - [2010/07/30 18:16:46 | 000,008,192 | ---- | M] (Nokia) [Kernel | On_Demand] -- C:\WINDOWS\system32\drivers\usbser_lowerfltj.sys -- (UsbserFilt)
    DRV - [2010/07/30 18:16:44 | 000,008,192 | ---- | M] (Nokia) [Kernel | On_Demand] -- C:\WINDOWS\system32\drivers\usbser_lowerflt.sys -- (upperdev)
    DRV - [2010/07/30 18:16:42 | 000,023,040 | ---- | M] (Nokia) [Kernel | On_Demand] -- C:\WINDOWS\system32\drivers\ccdcmbo.sys -- (nmwcdc)
    DRV - [2010/07/30 18:16:38 | 000,018,048 | ---- | M] (Nokia) [Kernel | On_Demand] -- C:\WINDOWS\system32\drivers\ccdcmb.sys -- (nmwcd)
    DRV - [2009/12/18 14:58:52 | 000,011,336 | ---- | M] () [Kernel | On_Demand] -- C:\Program Files\SystemRequirementsLab\cpudrv.sys -- (cpudrv)
    DRV - [2009/01/16 13:35:28 | 000,013,184 | ---- | M] (IBM Corporation) [Kernel | On_Demand] -- C:\WINDOWS\system32\drivers\psadd.sys -- (psadd)
    DRV - [2008/08/26 13:26:12 | 000,018,816 | ---- | M] (Nokia) [Kernel | On_Demand] -- C:\WINDOWS\system32\drivers\pccsmcfd.sys -- (pccsmcfd)
    DRV - [2007/10/12 04:52:36 | 001,312,768 | R--- | M] (C-Media Inc) [Kernel | On_Demand] -- C:\WINDOWS\system32\drivers\CM108.sys -- (USBPNPA)
    DRV - [2006/11/22 14:01:48 | 000,693,760 | ---- | M] (Aladdin Knowledge Systems Ltd.) [Kernel | Auto] -- C:\WINDOWS\system32\drivers\hardlock.sys -- (Hardlock)
    DRV - [2006/11/22 14:01:48 | 000,100,096 | ---- | M] (Aladdin Knowledge Systems Ltd.) [Kernel | On_Demand] -- C:\WINDOWS\system32\drivers\aksusb.sys -- (aksusb)
    DRV - [2006/11/22 14:01:46 | 000,327,168 | ---- | M] (Aladdin Knowledge Systems Ltd.) [Kernel | On_Demand] -- C:\WINDOWS\system32\drivers\akshasp.sys -- (akshasp)
    DRV - [2005/02/05 07:51:00 | 000,392,832 | ---- | M] (Sensaura) [Kernel | On_Demand] -- C:\WINDOWS\system32\drivers\senfilt.sys -- (senfilt)
    DRV - [2005/01/27 21:42:24 | 000,003,328 | ---- | M] (UPEK Inc.) [Kernel | Auto] -- C:\WINDOWS\system32\smihlp.sys -- (SmiHlp)
    DRV - [2004/12/16 08:12:20 | 000,063,616 | ---- | M] (IBM) [Kernel | Auto] -- C:\WINDOWS\system32\drivers\ibmfilter.sys -- (ibmfilter)
    DRV - [2004/12/06 21:55:20 | 000,126,720 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand] -- C:\WINDOWS\system32\drivers\b57xp32.sys -- (b57w2k)
    DRV - [2004/06/28 00:08:56 | 000,042,752 | R--- | M] (Prolific Technology Inc.) [Kernel | On_Demand] -- C:\WINDOWS\system32\drivers\ser2pl.sys -- (Ser2pl)
    DRV - [2004/05/19 17:41:26 | 000,013,757 | ---- | M] (National Semiconductor Corp.) [Kernel | On_Demand] -- C:\WINDOWS\system32\drivers\NscTpmDD.sys -- (portio)
    DRV - [2004/01/28 18:03:26 | 000,021,456 | ---- | M] (Texas Instruments Incorporated) [Kernel | On_Demand] -- C:\WINDOWS\system32\drivers\SilvrLnk.sys -- (SilverLink) Texas Instruments SilverLink (USB GraphLink)


    ========== Standard Registry (SafeList) ==========


    ========== Internet Explorer ==========



    IE - HKU\.DEFAULT\..\URLSearchHook: {A3BC75A2-1F87-4686-AA43-5347D756017C} - Reg Error: Key error. File not found
    IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0




    IE - HKU\PM_ON_C\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.bing.com
    IE - HKU\PM_ON_C\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
    IE - HKU\PM_ON_C\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local;<local>


    FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32_11_7_700_224.dll ()
    FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\WINDOWS\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
    FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=:
    FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
    FF - HKLM\Software\MozillaPlugins\@avg.com/AVG SiteSafety plugin,version=11.0.0.1,application/x-avg-sitesafety-plugin: File not found
    FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.17.2: C:\WINDOWS\system32\npdeployJava1.dll (Oracle Corporation)
    FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.17.2: C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
    FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files\Microsoft Silverlight\4.0.50826.0\npctrl.dll ( Microsoft Corporation)
    FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\Program Files\Microsoft Office\Office14\NPAUTHZ.DLL (Microsoft Corporation)
    FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\Program Files\Microsoft Office\Office14\NPSPWRAP.DLL (Microsoft Corporation)
    FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
    FF - HKLM\Software\MozillaPlugins\@real.com/nppl3260;version=6.0.12.448: C:\Program Files\Real\RealPlayer\Netscape6\nppl3260.dll (RealNetworks, Inc.)
    FF - HKLM\Software\MozillaPlugins\@real.com/nprjplug;version=1.0.3.448: C:\Program Files\Real\RealPlayer\Netscape6\nprjplug.dll (RealNetworks, Inc.)
    FF - HKLM\Software\MozillaPlugins\@real.com/nprpjplug;version=6.0.12.448: C:\Program Files\Real\RealPlayer\Netscape6\nprpjplug.dll (RealNetworks, Inc.)
    FF - HKLM\Software\MozillaPlugins\@real.com/nsJSRealPlayerPlugin;version=:
    FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)

    FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\avg@toolbar: C:\Documents and Settings\All Users\Application Data\AVG Secure Search\FireFoxExt\15.0.0.2
    FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\jqs@sun.com: C:\Program Files\Java\jre1.6.0_20\lib\deploy\jqs\ff [2010/11/02 21:55:08 | 000,000,000 | ---D | M]
    FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\wrc@avast.com: C:\Program Files\AVAST Software\Avast\WebRep\FF [2013/05/15 09:04:57 | 000,000,000 | ---D | M]
    FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 22.0\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2013/05/14 19:45:27 | 000,000,000 | ---D | M]
    FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 22.0\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2013/05/15 09:55:39 | 000,000,000 | ---D | M]
    FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 17.0.7\extensions\\Components: C:\Program Files\Mozilla Thunderbird\components [2013/06/25 21:51:48 | 000,000,000 | ---D | M]
    FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 17.0.7\extensions\\Plugins: C:\Program Files\Mozilla Thunderbird\plugins

    [2013/05/14 19:45:27 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions
    [2013/05/14 19:45:27 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\browser\extensions
    [2013/06/26 08:36:13 | 000,000,000 | ---D | M] (Default) -- C:\Program Files\Mozilla Firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
    [2009/11/06 12:37:19 | 000,091,552 | ---- | M] (Coupons, Inc.) -- C:\Program Files\mozilla firefox\plugins\npCouponPrinter.dll
    [2009/11/06 12:37:20 | 000,091,552 | ---- | M] (Coupons, Inc.) -- C:\Program Files\mozilla firefox\plugins\npMozCouponPrinter.dll
    [2013/04/18 00:05:05 | 000,003,714 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\avg-secure-search.xml

    O1 HOSTS File: ([2004/08/04 09:00:00 | 000,000,734 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
    O1 - Hosts: 127.0.0.1 localhost
    O2 - BHO: (RealPlayer Download and Record Plugin for Internet Explorer) - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll (RealPlayer)
    O2 - BHO: (DriveLetterAccess) - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll (Sonic Solutions)
    O2 - BHO: (avast! Online Security) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
    O2 - BHO: (Office Document Cache Handler) - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
    O2 - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
    O2 - BHO: (JQSIEStartDetectorImpl Class) - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre1.6.0_20\lib\deploy\jqs\ie\jqs_plugin.dll (Sun Microsystems, Inc.)
    O2 - BHO: (no name) - AutorunsDisabled - No CLSID value found.
    O3 - HKLM\..\Toolbar: (avast! Online Security) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
    O3 - HKU\Administrator_ON_C\..\Toolbar\ShellBrowser: (no name) - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - No CLSID value found.
    O3 - HKU\PM_ON_C\..\Toolbar\WebBrowser: (no name) - {E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39} - No CLSID value found.
    O4 - HKLM..\Run: [avast] C:\Program Files\AVAST Software\Avast\avastUI.exe (AVAST Software)
    O4 - HKLM..\Run: [Samsung PanelMgr] C:\WINDOWS\Samsung\PanelMgr\SSMMgr.exe ()
    O4 - HKLM..\Run: [TkBellExe] C:\Program Files\Common Files\Real\Update_OB\realsched.exe (RealNetworks, Inc.)
    O4 - HKU\Administrator_ON_C..\Run: [ibmmessages] C:\Program Files\IBM\Messages By IBM\ibmmessages.exe (IBM)
    O4 - HKU\PM_ON_C..\Run: [Mozilla Firefox] C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
    O4 - HKU\Administrator_ON_C..\RunOnce: [spchecker] File not found
    O4 - Startup: C:\Documents and Settings\PM\Start Menu\Programs\Startup\Dropbox.lnk = File not found
    O4 - Startup: C:\Documents and Settings\PM\Start Menu\Programs\Startup\msconfig.lnk = X:\I386\SYSTEM32\RUNDLL32.EXE (Microsoft Corporation)
    O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
    O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
    O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 255
    O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: AllowLegacyWebView = 1
    O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: AllowUnhashedWebView = 1
    O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableStatusMessages = 1
    O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: VerboseStatus = 0
    O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
    O7 - HKU\Administrator_ON_C\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
    O7 - HKU\LocalService_ON_C\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
    O7 - HKU\NetworkService_ON_C\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
    O7 - HKU\PM_ON_C\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 255
    O9 - Extra Button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
    O9 - Extra 'Tools' menuitem : Se&nd to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
    O9 - Extra Button: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll (Microsoft Corporation)
    O9 - Extra 'Tools' menuitem : OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll (Microsoft Corporation)
    O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
    O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://download.macromedia.com/pub/shockwave/cabs/director/sw.cab (Shockwave ActiveX Control)
    O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://go.microsoft.com/fwlink/?linkid=39204 (Windows Genuine Advantage Validation Tool)
    O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1251646956562 (WUWebControl Class)
    O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab (Reg Error: Value error.)
    O16 - DPF: {CAFEEFAC-0014-0002-0000-ABCDEFFEDCBA} http://java.sun.com/products/plugin/1.4.2/jinstall-142-win.cab (Reg Error: Key error.)
    O16 - DPF: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab (Java Plug-in 1.6.0_20)
    O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab (Java Plug-in 1.6.0_20)
    O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
    O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 72.240.13.7 72.240.13.6
    O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - File not found
    O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
    O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
    O20 - Winlogon\Notify\psfus: DllName - C:\Program Files\IBM fingerprint software\psfus.dll - C:\Program Files\IBM fingerprint software\psfus.dll (UPEK Inc.)
    O24 - Desktop WallPaper: C:\WINDOWS\Web\Wallpaper\Bliss.bmp
    O24 - Desktop BackupWallPaper: C:\WINDOWS\Web\Wallpaper\Bliss.bmp
    O28 - HKLM ShellExecuteHooks: {56F9679E-7826-4C84-81F3-532071A8BCC5} - C:\Program Files\Windows Desktop Search\MsnlNamespaceMgr.dll (Microsoft Corporation)
    O32 - HKLM CDRom: AutoRun - 1
    O32 - AutoRun File - [2009/08/30 04:37:42 | 000,000,000 | -H-- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
    O32 - AutoRun File - [2013/02/13 18:22:46 | 000,000,134 | ---- | M] () - D:\autorun.inf -- [ FAT32 ]
    O32 - AutoRun File - [2006/03/24 07:06:41 | 000,000,053 | R--- | M] () - X:\AUTORUN.INF -- [ CDFS ]
    O34 - HKLM BootExecute: (autocheck autochk *) - File not found
    O35 - HKLM\..comfile [open] -- "%1" %*
    O35 - HKLM\..exefile [open] -- "%1" %*
    O36 - AppCertDlls: ntsdutou - (C:\WINDOWS\system32\dosxRRUN.dll) - File not found
    O37 - HKLM\...com [@ = comfile] -- "%1" %*
    O37 - HKLM\...exe [@ = exefile] -- "%1" %*
  11. jomon324

    jomon324 Newcomer, in training Topic Starter Posts: 40

    (PART 3)

    ========== Files/Folders - Created Within 30 Days ==========

    [2013/06/26 23:39:36 | 000,159,744 | ---- | C] (Microsoft Corporation) -- C:\Documents and Settings\All Users\Application Data\rlqv.dat
    [2013/06/26 23:39:35 | 000,033,280 | ---- | C] (Microsoft Corporation) -- C:\Documents and Settings\All Users\Application Data\rundll32.exe
    [2013/06/25 21:51:48 | 000,000,000 | ---D | C] -- C:\Program Files\Mozilla Thunderbird
    [2013/06/22 22:19:57 | 000,000,000 | ---D | C] -- C:\Documents and Settings\PM\Application Data\vlc
    [2013/06/16 01:27:41 | 000,000,000 | ---D | C] -- C:\Documents and Settings\PM\My Documents\Graboid
    [2013/06/16 01:19:41 | 000,000,000 | ---D | C] -- C:\Documents and Settings\PM\Local Settings\Application Data\Graboid_Inc
    [2013/06/16 01:19:41 | 000,000,000 | ---D | C] -- C:\Documents and Settings\PM\Local Settings\Application Data\Graboid Inc
    [2013/06/16 01:19:39 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Graboid Inc
    [2013/06/16 01:19:39 | 000,000,000 | ---D | C] -- C:\Documents and Settings\PM\Local Settings\Application Data\Graboid
    [2013/06/16 01:19:38 | 000,000,000 | ---D | C] -- C:\Documents and Settings\PM\Local Settings\Application Data\Geckofx
    [2013/06/16 01:18:58 | 000,000,000 | ---D | C] -- C:\Documents and Settings\PM\Start Menu\Programs\Graboid Video
    [2013/06/16 01:18:31 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\VideoLAN
    [2013/06/16 01:18:03 | 000,000,000 | ---D | C] -- C:\Program Files\VideoLAN
    [2013/06/16 01:17:52 | 000,000,000 | ---D | C] -- C:\Program Files\Graboid
    [2013/06/16 01:16:41 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Package Cache
    [2013/06/16 00:58:23 | 000,000,000 | ---D | C] -- C:\Documents and Settings\PM\Local Settings\Application Data\iLivid
    [2013/06/14 11:40:10 | 000,000,000 | ---D | C] -- C:\Documents and Settings\PM\Application Data\DriverCure
    [2013/06/14 11:40:09 | 000,000,000 | ---D | C] -- C:\Documents and Settings\PM\Application Data\SpeedyPC Software
    [2013/06/14 11:39:58 | 000,000,000 | ---D | C] -- C:\Documents and Settings\PM\Start Menu\Programs\SpeedyPC Software
    [2013/06/14 11:39:52 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\SpeedyPC Software
    [2013/06/14 11:39:47 | 000,000,000 | ---D | C] -- C:\Program Files\SpeedyPC Software
    [2013/06/14 11:39:47 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\SpeedyPC Software
    [2013/06/12 15:50:12 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\APN
    [2013/06/12 15:43:24 | 000,000,000 | ---D | C] -- C:\Documents and Settings\PM\Local Settings\Application Data\DriverTuner
    [2013/06/12 15:43:09 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\DriverTuner
    [2013/06/12 15:43:05 | 000,000,000 | ---D | C] -- C:\Program Files\DriverTuner
    [2010/09/07 16:39:20 | 000,150,392 | ---- | C] (Sysinternals - www.sysinternals.com) -- C:\Documents and Settings\PM\junction.exe
    [2009/09/19 04:43:04 | 000,089,680 | ---- | C] (Microsoft Corporation) -- C:\Documents and Settings\PM\MSSSerif120.fon
    [3 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
    [2 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
    [1 C:\Documents and Settings\All Users\Application Data\*.tmp files -> C:\Documents and Settings\All Users\Application Data\*.tmp -> ]

    ========== Files - Modified Within 30 Days ==========

    [2013/06/26 23:58:28 | 095,023,320 | ---- | M] () -- C:\Documents and Settings\All Users\Application Data\vqlr.pad
    [2013/06/26 23:57:21 | 000,000,364 | -H-- | M] () -- C:\WINDOWS\tasks\avast! Emergency Update.job
    [2013/06/26 23:55:25 | 000,001,170 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
    [2013/06/26 23:55:07 | 000,000,664 | ---- | M] () -- C:\WINDOWS\System32\d3d9caps.dat
    [2013/06/26 23:52:12 | 000,000,486 | ---- | M] () -- C:\WINDOWS\tasks\SpeedyPC Update Version3 Startup Task.job
    [2013/06/26 23:51:03 | 000,000,402 | ---- | M] () -- C:\WINDOWS\tasks\Auslogics BoostSpeed Integrator Start On PM Logon.job
    [2013/06/26 23:51:01 | 000,000,400 | ---- | M] () -- C:\WINDOWS\tasks\RNUpgradeHelperLogonPrompt_PM.job
    [2013/06/26 23:49:58 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
    [2013/06/26 23:49:55 | 2137,575,424 | -HS- | M] () -- C:\hiberfil.sys
    [2013/06/26 23:39:51 | 000,000,790 | ---- | M] () -- C:\Documents and Settings\PM\Start Menu\Programs\Startup\msconfig.lnk
    [2013/06/26 23:39:36 | 000,159,744 | ---- | M] (Microsoft Corporation) -- C:\Documents and Settings\All Users\Application Data\rlqv.dat
    [2013/06/26 23:39:36 | 000,033,280 | ---- | M] (Microsoft Corporation) -- C:\Documents and Settings\All Users\Application Data\rundll32.exe
    [2013/06/26 23:33:07 | 000,002,577 | ---- | M] () -- C:\WINDOWS\System32\CONFIG.NT
    [2013/06/26 23:32:00 | 000,000,830 | ---- | M] () -- C:\WINDOWS\tasks\Adobe Flash Player Updater.job
    [2013/06/26 18:00:00 | 000,000,462 | ---- | M] () -- C:\WINDOWS\tasks\SpeedyPC Registration3.job
    [2013/06/26 15:08:10 | 000,770,344 | ---- | M] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswSnx.sys
    [2013/06/26 15:08:10 | 000,369,456 | ---- | M] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswSP.sys
    [2013/06/26 15:08:10 | 000,000,175 | ---- | M] () -- C:\WINDOWS\System32\drivers\aswSP.sys.sum
    [2013/06/26 15:08:10 | 000,000,175 | ---- | M] () -- C:\WINDOWS\System32\drivers\aswSnx.sys.sum
    [2013/06/26 08:36:18 | 000,000,742 | ---- | M] () -- C:\Documents and Settings\PM\Application Data\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox.lnk
    [2013/06/26 08:36:18 | 000,000,730 | ---- | M] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Mozilla Firefox.lnk
    [2013/06/26 08:36:18 | 000,000,724 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Mozilla Firefox.lnk
    [2013/06/25 16:01:01 | 000,000,284 | ---- | M] () -- C:\WINDOWS\tasks\AppleSoftwareUpdate.job
    [2013/06/25 08:24:02 | 000,000,394 | ---- | M] () -- C:\WINDOWS\tasks\ReclaimerUpdateFiles_PM.job
    [2013/06/24 11:25:02 | 000,000,390 | ---- | M] () -- C:\WINDOWS\tasks\ReclaimerUpdateXML_PM.job
    [2013/06/24 01:06:36 | 000,000,390 | ---- | M] () -- C:\WINDOWS\tasks\SpeedyPC Pro.job
    [2013/06/23 21:39:32 | 000,000,069 | ---- | M] () -- C:\WINDOWS\NeroDigital.ini
    [2013/06/16 01:18:58 | 000,000,912 | ---- | M] () -- C:\Documents and Settings\PM\Desktop\Graboid Video.lnk
    [2013/06/16 01:18:32 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Start Menu\Programs\VideoLAN
    [2013/06/16 01:07:34 | 000,000,968 | ---- | M] () -- C:\Documents and Settings\PM\Application Data\Microsoft\Internet Explorer\Quick Launch\iLivid.lnk
    [2013/06/14 11:39:57 | 000,000,434 | ---- | M] () -- C:\WINDOWS\tasks\SpeedyPC Update Version3.job
    [2013/06/13 01:02:44 | 001,258,800 | ---- | M] () -- C:\Documents and Settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
    [2013/06/12 15:43:11 | 000,000,736 | ---- | M] () -- C:\Documents and Settings\PM\Application Data\Microsoft\Internet Explorer\Quick Launch\DriverTuner.lnk
    [2013/06/12 15:43:11 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Start Menu\Programs\DriverTuner
    [2013/06/12 10:32:38 | 000,692,104 | ---- | M] (Adobe Systems Incorporated) -- C:\WINDOWS\System32\FlashPlayerApp.exe
    [2013/06/12 10:32:38 | 000,071,048 | ---- | M] (Adobe Systems Incorporated) -- C:\WINDOWS\System32\FlashPlayerCPLApp.cpl
    [2013/06/12 05:02:39 | 000,000,244 | ---- | M] () -- C:\Documents and Settings\PM\Application Data\default.rss
    [2013/06/10 10:29:39 | 000,015,672 | ---- | M] () -- C:\Documents and Settings\PM\Desktop\PL10908x-1.pdf
    [3 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
    [2 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
    [1 C:\Documents and Settings\All Users\Application Data\*.tmp files -> C:\Documents and Settings\All Users\Application Data\*.tmp -> ]
  12. jomon324

    jomon324 Newcomer, in training Topic Starter Posts: 40

    (PART 4 - FINAL PART)

    ========== Files Created - No Company Name ==========

    [2013/06/26 23:39:51 | 000,000,790 | ---- | C] () -- C:\Documents and Settings\PM\Start Menu\Programs\Startup\msconfig.lnk
    [2013/06/26 23:39:41 | 095,023,320 | ---- | C] () -- C:\Documents and Settings\All Users\Application Data\vqlr.pad
    [2013/06/26 15:08:10 | 000,000,175 | ---- | C] () -- C:\WINDOWS\System32\drivers\aswSP.sys.sum
    [2013/06/26 15:08:10 | 000,000,175 | ---- | C] () -- C:\WINDOWS\System32\drivers\aswSnx.sys.sum
    [2013/06/17 11:20:01 | 000,000,400 | ---- | C] () -- C:\WINDOWS\tasks\RNUpgradeHelperLogonPrompt_PM.job
    [2013/06/17 11:20:00 | 000,000,394 | ---- | C] () -- C:\WINDOWS\tasks\ReclaimerUpdateFiles_PM.job
    [2013/06/17 11:20:00 | 000,000,390 | ---- | C] () -- C:\WINDOWS\tasks\ReclaimerUpdateXML_PM.job
    [2013/06/16 01:18:58 | 000,000,912 | ---- | C] () -- C:\Documents and Settings\PM\Desktop\Graboid Video.lnk
    [2013/06/16 01:02:07 | 000,000,968 | ---- | C] () -- C:\Documents and Settings\PM\Application Data\Microsoft\Internet Explorer\Quick Launch\iLivid.lnk
    [2013/06/14 11:40:13 | 000,000,462 | ---- | C] () -- C:\WINDOWS\tasks\SpeedyPC Registration3.job
    [2013/06/14 11:39:57 | 000,000,486 | ---- | C] () -- C:\WINDOWS\tasks\SpeedyPC Update Version3 Startup Task.job
    [2013/06/14 11:39:56 | 000,000,434 | ---- | C] () -- C:\WINDOWS\tasks\SpeedyPC Update Version3.job
    [2013/06/14 11:39:54 | 000,000,390 | ---- | C] () -- C:\WINDOWS\tasks\SpeedyPC Pro.job
    [2013/06/12 15:43:11 | 000,000,736 | ---- | C] () -- C:\Documents and Settings\PM\Application Data\Microsoft\Internet Explorer\Quick Launch\DriverTuner.lnk
    [2013/06/10 10:29:37 | 000,015,672 | ---- | C] () -- C:\Documents and Settings\PM\Desktop\PL10908x-1.pdf
    [2013/05/15 09:05:25 | 000,174,664 | ---- | C] () -- C:\WINDOWS\System32\drivers\aswVmm.sys
    [2013/05/15 09:05:25 | 000,049,376 | ---- | C] () -- C:\WINDOWS\System32\drivers\aswRvrt.sys
    [2013/04/15 11:51:37 | 000,005,632 | ---- | C] () -- C:\WINDOWS\System32\CNMVS2F.DLL
    [2013/02/27 09:34:00 | 000,000,036 | ---- | C] () -- C:\Documents and Settings\All Users\Application Data\InstallAlibre.config
    [2012/03/26 21:01:34 | 000,000,004 | ---- | C] () -- C:\Documents and Settings\PM\Local Settings\Application Data\pcdit.dat
    [2011/07/10 17:26:01 | 000,041,744 | ---- | C] () -- C:\WINDOWS\System32\drivers\PciSx.sys
    [2011/06/23 12:31:21 | 000,012,752 | -HS- | C] () -- C:\Documents and Settings\PM\Local Settings\Application Data\v34614kokdn87ld5p5m0sj75hs41572n7x508nstf75
    [2011/06/23 12:31:21 | 000,012,752 | -HS- | C] () -- C:\Documents and Settings\All Users\Application Data\v34614kokdn87ld5p5m0sj75hs41572n7x508nstf75
    [2011/06/05 13:32:51 | 000,001,368 | -HS- | C] () -- C:\Documents and Settings\PM\Local Settings\Application Data\6u88x86ou15wp2u
    [2011/06/05 13:32:51 | 000,001,368 | -HS- | C] () -- C:\Documents and Settings\All Users\Application Data\6u88x86ou15wp2u
    [2011/05/31 14:20:50 | 000,000,000 | ---- | C] () -- C:\WINDOWS\SETUP32.INI
    [2011/05/03 01:55:36 | 000,005,114 | ---- | C] () -- C:\Documents and Settings\PM\_viminfo
    [2011/04/26 21:00:11 | 000,072,080 | ---- | C] () -- C:\Documents and Settings\PM\g2mdlhlpx.exe
    [2011/04/26 14:54:50 | 000,000,173 | ---- | C] () -- C:\Documents and Settings\PM\Local Settings\Application Data\msmathematics.qat.PM
    [2011/04/18 23:57:36 | 000,069,228 | -H-- | C] () -- C:\WINDOWS\System32\mlfcache.dat
    [2010/12/24 23:11:48 | 000,004,111 | ---- | C] () -- C:\Documents and Settings\All Users\Application Data\ojobkspa.ako
    [2010/12/01 20:34:29 | 000,000,161 | ---- | C] () -- C:\WINDOWS\Cm108.ini.cfl
    [2010/12/01 20:34:28 | 000,045,056 | R--- | C] () -- C:\WINDOWS\System32\CM108rm.dll
    [2010/12/01 20:33:45 | 000,002,584 | R--- | C] () -- C:\WINDOWS\Cm108.ini.cfg
    [2010/11/07 22:38:26 | 000,000,601 | ---- | C] () -- C:\WINDOWS\hpomdl43.dat.temp
    [2010/08/31 02:03:23 | 001,258,800 | ---- | C] () -- C:\Documents and Settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
    [2010/08/22 22:05:24 | 000,000,037 | ---- | C] () -- C:\WINDOWS\cdplayer.ini
    [2010/06/17 11:16:56 | 000,003,821 | ---- | C] () -- C:\WINDOWS\scad3.INI
    [2010/05/07 08:53:09 | 000,000,000 | ---- | C] () -- C:\Documents and Settings\PM\Application Data\downloads.m3u
    [2010/04/09 17:39:57 | 000,000,244 | ---- | C] () -- C:\Documents and Settings\PM\Application Data\default.rss
    [2010/04/09 14:51:16 | 000,000,664 | ---- | C] () -- C:\WINDOWS\System32\d3d9caps.dat
    [2010/04/07 23:09:16 | 000,000,069 | ---- | C] () -- C:\WINDOWS\NeroDigital.ini
    [2010/03/20 11:39:08 | 000,024,576 | ---- | C] () -- C:\WINDOWS\System32\hdsuinst.exe
    [2010/03/20 11:39:07 | 000,164,864 | ---- | C] () -- C:\WINDOWS\System32\UNWISE.EXE
    [2010/03/09 23:16:36 | 000,204,800 | ---- | C] () -- C:\WINDOWS\System32\igfxCoIn_v4764.dll
    [2010/03/07 00:50:37 | 000,482,408 | ---- | C] () -- C:\WINDOWS\ssndii.exe
    [2010/03/07 00:48:48 | 000,022,723 | ---- | C] () -- C:\WINDOWS\System32\cl31cl3.dll
    [2009/09/24 07:18:22 | 000,000,056 | -H-- | C] () -- C:\WINDOWS\System32\ezsidmv.dat
    [2009/09/22 23:07:07 | 000,000,247 | ---- | C] () -- C:\Documents and Settings\PM\Application Data\AnimatedKnotsPrefs
    [2009/08/30 17:12:20 | 000,089,088 | ---- | C] () -- C:\Documents and Settings\PM\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
    [2009/08/30 16:36:40 | 000,000,000 | ---- | C] () -- C:\WINDOWS\nsreg.dat
    [2009/08/30 14:18:41 | 000,116,224 | ---- | C] () -- C:\WINDOWS\System32\pdfcmnnt.dll
    [2009/08/30 04:37:39 | 000,000,125 | ---- | C] () -- C:\Documents and Settings\PM\Local Settings\Application Data\fusioncache.dat
    [2009/01/16 14:16:10 | 000,002,481 | ---- | C] () -- C:\WINDOWS\System32\OEMINFO.INI
    [2009/01/16 13:40:57 | 000,000,061 | ---- | C] () -- C:\WINDOWS\smscfg.ini
    [2009/01/16 13:35:29 | 000,032,256 | ---- | C] () -- C:\WINDOWS\System32\drivers\psasrv.exe
    [2009/01/16 13:29:22 | 000,000,138 | ---- | C] () -- C:\WINDOWS\wininit.ini
    [2009/01/16 13:28:10 | 000,204,800 | ---- | C] () -- C:\WINDOWS\System32\IVIresizeW7.dll
    [2009/01/16 13:28:10 | 000,200,704 | ---- | C] () -- C:\WINDOWS\System32\IVIresizeA6.dll
    [2009/01/16 13:28:10 | 000,192,512 | ---- | C] () -- C:\WINDOWS\System32\IVIresizeP6.dll
    [2009/01/16 13:28:10 | 000,192,512 | ---- | C] () -- C:\WINDOWS\System32\IVIresizeM6.dll
    [2009/01/16 13:28:10 | 000,188,416 | ---- | C] () -- C:\WINDOWS\System32\IVIresizePX.dll
    [2009/01/16 13:28:10 | 000,020,480 | ---- | C] () -- C:\WINDOWS\System32\IVIresize.dll
    [2009/01/16 13:25:39 | 000,000,136 | ---- | C] () -- C:\Documents and Settings\Administrator\Local Settings\Application Data\fusioncache.dat
    [2009/01/16 13:23:55 | 000,040,960 | ---- | C] () -- C:\WINDOWS\System32\SKDAEMON.EXE
    [2009/01/16 13:23:49 | 000,077,824 | ---- | C] () -- C:\WINDOWS\System32\SynTPCoI.dll
    [2008/05/27 01:59:42 | 000,018,904 | ---- | C] () -- C:\WINDOWS\System32\structuredqueryschematrivial.bin
    [2008/05/27 01:59:40 | 000,106,605 | ---- | C] () -- C:\WINDOWS\System32\structuredqueryschema.bin
    [2008/02/19 02:33:34 | 000,446,352 | ---- | C] () -- C:\WINDOWS\System32\OpenQuicktimeLib.dll
    [2007/09/27 14:51:02 | 000,020,698 | ---- | C] () -- C:\WINDOWS\System32\idxcntrs.ini
    [2007/09/27 14:48:48 | 000,030,628 | ---- | C] () -- C:\WINDOWS\System32\gsrvctr.ini
    [2007/09/27 14:48:28 | 000,031,698 | ---- | C] () -- C:\WINDOWS\System32\gthrctr.ini
    [2007/08/21 23:46:34 | 000,059,160 | ---- | C] () -- C:\WINDOWS\System32\zlib.dll
    [2005/04/04 11:59:00 | 000,017,920 | ---- | C] () -- C:\WINDOWS\System32\implode.dll
    [2005/01/20 00:53:06 | 000,000,000 | ---- | C] () -- C:\WINDOWS\System32\px.ini
    [2004/12/16 07:41:58 | 000,045,056 | ---- | C] () -- C:\WINDOWS\System32\pwdmon.dll
    [2004/12/16 07:41:58 | 000,019,853 | ---- | C] () -- C:\WINDOWS\ibmprc.ini
    [2004/11/09 05:02:00 | 000,110,592 | ---- | C] () -- C:\WINDOWS\desktopset.exe
    [2004/08/09 15:03:43 | 000,000,882 | ---- | C] () -- C:\WINDOWS\orun32.ini
    [2004/08/09 15:01:40 | 000,002,048 | --S- | C] () -- C:\WINDOWS\bootstat.dat
    [2004/08/09 14:51:56 | 000,021,640 | ---- | C] () -- C:\WINDOWS\System32\emptyregdb.dat
    [2004/08/09 14:46:20 | 000,004,161 | ---- | C] () -- C:\WINDOWS\ODBCINST.INI
    [2004/08/09 14:45:31 | 000,322,728 | ---- | C] () -- C:\WINDOWS\System32\FNTCACHE.DAT
    [2004/01/09 10:10:32 | 000,143,360 | ---- | C] () -- C:\WINDOWS\System32\AIBMRUNL.dll
    [2001/08/23 11:26:08 | 013,107,200 | ---- | C] () -- C:\WINDOWS\System32\OEMBIOS.BIN
    [2001/08/23 11:24:30 | 000,004,524 | ---- | C] () -- C:\WINDOWS\System32\OEMBIOS.DAT
    [1980/01/01 04:00:00 | 000,673,088 | ---- | C] () -- C:\WINDOWS\System32\mlang.dat
    [1980/01/01 04:00:00 | 000,547,430 | ---- | C] () -- C:\WINDOWS\System32\perfh009.dat
    [1980/01/01 04:00:00 | 000,272,128 | ---- | C] () -- C:\WINDOWS\System32\perfi009.dat
    [1980/01/01 04:00:00 | 000,218,003 | ---- | C] () -- C:\WINDOWS\System32\dssec.dat
    [1980/01/01 04:00:00 | 000,103,402 | ---- | C] () -- C:\WINDOWS\System32\perfc009.dat
    [1980/01/01 04:00:00 | 000,046,258 | ---- | C] () -- C:\WINDOWS\System32\mib.bin
    [1980/01/01 04:00:00 | 000,028,626 | ---- | C] () -- C:\WINDOWS\System32\perfd009.dat
    [1980/01/01 04:00:00 | 000,013,576 | ---- | C] () -- C:\WINDOWS\System32\syscorecfg256.dll
    [1980/01/01 04:00:00 | 000,004,569 | ---- | C] () -- C:\WINDOWS\System32\secupd.dat
    [1980/01/01 04:00:00 | 000,001,804 | ---- | C] () -- C:\WINDOWS\System32\dcache.bin
    [1980/01/01 04:00:00 | 000,000,741 | ---- | C] () -- C:\WINDOWS\System32\noise.dat

    ========== LOP Check ==========

    [2013/04/18 00:06:27 | 000,000,000 | ---D | M] -- C:\WINDOWS\system32\config\systemprofile\Application Data\AVG2013
    [2009/01/16 13:29:40 | 000,000,000 | ---D | M] -- C:\WINDOWS\system32\config\systemprofile\Application Data\IBM
    [2009/01/16 13:29:40 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Administrator\Application Data\IBM
    [2010/05/30 16:41:25 | 000,000,000 | ---D | M] -- C:\Documents and Settings\PM\Application Data\.algor
    [2010/12/06 20:11:26 | 000,000,000 | ---D | M] -- C:\Documents and Settings\PM\Application Data\.anki
    [2010/05/18 00:01:32 | 000,000,000 | ---D | M] -- C:\Documents and Settings\PM\Application Data\.matplotlib
    [2013/05/26 09:51:51 | 000,000,000 | ---D | M] -- C:\Documents and Settings\PM\Application Data\Alibre Design
    [2013/02/27 09:43:24 | 000,000,000 | ---D | M] -- C:\Documents and Settings\PM\Application Data\Alibre, Inc
    [2012/06/21 08:48:09 | 000,000,000 | ---D | M] -- C:\Documents and Settings\PM\Application Data\Auslogics
    [2010/11/10 01:57:20 | 000,000,000 | ---D | M] -- C:\Documents and Settings\PM\Application Data\AVG
    [2011/12/18 20:40:21 | 000,000,000 | ---D | M] -- C:\Documents and Settings\PM\Application Data\AVG Secure Search
    [2013/03/28 20:31:18 | 000,000,000 | ---D | M] -- C:\Documents and Settings\PM\Application Data\AVG2013
    [2009/11/11 03:54:56 | 000,000,000 | ---D | M] -- C:\Documents and Settings\PM\Application Data\AVG9
    [2009/10/07 21:47:28 | 000,000,000 | ---D | M] -- C:\Documents and Settings\PM\Application Data\com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
    [2011/12/02 17:53:50 | 000,000,000 | ---D | M] -- C:\Documents and Settings\PM\Application Data\Com.CreativeMindsCoding.IFS
    [2010/02/06 22:15:12 | 000,000,000 | ---D | M] -- C:\Documents and Settings\PM\Application Data\Costco Photo Viewer US
    [2012/05/02 19:00:36 | 000,000,000 | ---D | M] -- C:\Documents and Settings\PM\Application Data\DassaultSystemes
    [2012/06/07 01:36:50 | 000,000,000 | ---D | M] -- C:\Documents and Settings\PM\Application Data\DraftSight
    [2013/06/14 11:40:10 | 000,000,000 | ---D | M] -- C:\Documents and Settings\PM\Application Data\DriverCure
    [2013/06/26 23:55:06 | 000,000,000 | ---D | M] -- C:\Documents and Settings\PM\Application Data\Dropbox
    [2009/08/30 12:11:17 | 000,000,000 | ---D | M] -- C:\Documents and Settings\PM\Application Data\IBM
    [2011/01/13 05:51:58 | 000,000,000 | ---D | M] -- C:\Documents and Settings\PM\Application Data\Intersil
    [2009/12/19 21:51:06 | 000,000,000 | ---D | M] -- C:\Documents and Settings\PM\Application Data\InterVideo
    [2009/09/19 04:43:04 | 000,000,000 | ---D | M] -- C:\Documents and Settings\PM\Application Data\Leadertech
    [2011/06/05 16:37:51 | 000,000,000 | ---D | M] -- C:\Documents and Settings\PM\Application Data\licenses
    [2010/12/24 23:11:53 | 000,000,000 | ---D | M] -- C:\Documents and Settings\PM\Application Data\MOVAVI
    [2011/06/01 08:21:30 | 000,000,000 | ---D | M] -- C:\Documents and Settings\PM\Application Data\NCH Swift Sound
    [2011/12/03 10:00:21 | 000,000,000 | ---D | M] -- C:\Documents and Settings\PM\Application Data\Nokia
    [2011/12/03 10:00:21 | 000,000,000 | ---D | M] -- C:\Documents and Settings\PM\Application Data\Nokia Ovi Suite
    [2010/11/02 22:00:22 | 000,000,000 | ---D | M] -- C:\Documents and Settings\PM\Application Data\OpenOffice.org
    [2011/06/24 18:53:14 | 000,000,000 | ---D | M] -- C:\Documents and Settings\PM\Application Data\OverDrive
    [2011/01/12 14:31:51 | 000,000,000 | ---D | M] -- C:\Documents and Settings\PM\Application Data\PC Suite
    [2011/06/05 16:39:25 | 000,000,000 | ---D | M] -- C:\Documents and Settings\PM\Application Data\PCMM2009
    [2011/06/05 16:37:44 | 000,000,000 | ---D | M] -- C:\Documents and Settings\PM\Application Data\PCMM2011
    [2009/10/07 21:36:40 | 000,000,000 | ---D | M] -- C:\Documents and Settings\PM\Application Data\PDFCreator
    [2013/06/14 11:40:09 | 000,000,000 | ---D | M] -- C:\Documents and Settings\PM\Application Data\SpeedyPC Software
    [2010/03/09 23:15:39 | 000,000,000 | ---D | M] -- C:\Documents and Settings\PM\Application Data\SystemRequirementsLab
    [2010/07/19 16:48:23 | 000,000,000 | ---D | M] -- C:\Documents and Settings\PM\Application Data\Thunderbird
    [2013/04/18 00:05:42 | 000,000,000 | ---D | M] -- C:\Documents and Settings\PM\Application Data\TuneUp Software
    [2013/04/07 19:14:33 | 000,000,000 | ---D | M] -- C:\Documents and Settings\PM\Application Data\uTorrent
    [2011/02/15 15:24:56 | 000,000,000 | ---D | M] -- C:\Documents and Settings\PM\Application Data\webex
    [2009/12/18 02:57:45 | 000,000,000 | ---D | M] -- C:\Documents and Settings\PM\Application Data\Windows Desktop Search
    [2009/12/18 02:58:08 | 000,000,000 | ---D | M] -- C:\Documents and Settings\PM\Application Data\Windows Search
    [2011/05/23 17:01:42 | 000,000,000 | ---D | M] -- C:\Documents and Settings\PM\Application Data\YouSendIt
    [2013/02/26 17:18:08 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\188F1432-103A-4ffb-80F1-36B633C5C9E1
    [2013/02/27 09:42:47 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Alibre Design
    [2010/04/14 17:42:26 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Alibre Motion
    [2011/10/05 12:10:53 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Alibre Part Library
    [2013/06/12 15:50:12 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\APN
    [2013/03/10 17:59:40 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Ask
    [2011/07/30 13:00:21 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Auslogics
    [2013/05/15 09:03:59 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\AVAST Software
    [2010/11/10 02:00:43 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\AVG
    [2013/02/28 18:07:30 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\AVG Secure Search
    [2013/04/18 19:00:38 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\AVG2012
    [2013/05/15 09:02:41 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\AVG2013
    [2009/11/11 03:50:54 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\avg9
    [2011/04/14 14:34:44 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\bEl06511aBiNa06511
    [2010/11/10 01:26:45 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Application Data\Common Files
    [2012/07/04 11:16:50 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Dassault Systemes
    [2012/05/02 19:00:36 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\DassaultSystemes
    [2009/08/30 16:26:21 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Downloaded Installations
    [2012/03/09 19:59:25 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Driver Manager
    [2012/03/09 19:57:34 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Driver Tool
    [2011/06/20 12:34:43 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\eJ06504KgGlC06504
    [2009/11/21 21:02:49 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Flip Video
    [2013/06/16 01:19:39 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Graboid Inc
    [2011/05/05 13:53:04 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\hO06511CeFmP06511
    [2009/01/16 13:27:54 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\ibm
    [2011/12/03 09:59:20 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Installations
    [2009/10/05 23:39:58 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Application Data\Machinist ToolBox
    [2011/06/14 11:48:04 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\MecSoft Corporation
    [2013/05/15 09:03:16 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\MFAData
    [2011/06/05 05:16:50 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\NCH Swift Sound
    [2010/12/03 15:44:27 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Nokia
    [2010/07/10 13:24:02 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\NokiaInstallerCache
    [2013/06/16 01:17:50 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Package Cache
    [2011/01/12 14:31:30 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\PC Suite
    [2010/02/11 00:29:14 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Seagull
    [2010/02/11 00:27:38 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Seagull Security
    [2013/06/14 11:39:53 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\SpeedyPC Software
    [2013/06/26 23:58:22 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\TEMP
    [2011/04/18 23:38:41 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
    [2013/06/26 23:51:03 | 000,000,402 | ---- | M] () -- C:\WINDOWS\Tasks\Auslogics BoostSpeed Integrator Start On PM Logon.job
    [2013/06/26 23:57:21 | 000,000,364 | -H-- | M] () -- C:\WINDOWS\Tasks\avast! Emergency Update.job
    [2013/06/25 08:24:02 | 000,000,394 | ---- | M] () -- C:\WINDOWS\Tasks\ReclaimerUpdateFiles_PM.job
    [2013/06/24 11:25:02 | 000,000,390 | ---- | M] () -- C:\WINDOWS\Tasks\ReclaimerUpdateXML_PM.job
    [2013/06/26 23:51:01 | 000,000,400 | ---- | M] () -- C:\WINDOWS\Tasks\RNUpgradeHelperLogonPrompt_PM.job
    [2013/06/24 01:06:36 | 000,000,390 | ---- | M] () -- C:\WINDOWS\Tasks\SpeedyPC Pro.job
    [2013/06/26 18:00:00 | 000,000,462 | ---- | M] () -- C:\WINDOWS\Tasks\SpeedyPC Registration3.job
    [2013/06/26 23:52:12 | 000,000,486 | ---- | M] () -- C:\WINDOWS\Tasks\SpeedyPC Update Version3 Startup Task.job
    [2013/06/14 11:39:57 | 000,000,434 | ---- | M] () -- C:\WINDOWS\Tasks\SpeedyPC Update Version3.job

    ========== Purity Check ==========



    ========== Alternate Data Streams ==========

    @Alternate Data Stream - 200 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:07BF512B
    @Alternate Data Stream - 152 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:679ABA25
    @Alternate Data Stream - 137 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:0B4227B4
    < End of report >
  13. Broni

    Broni Malware Annihilator Posts: 45,269   +243

    Do this on the computer you are posting from:
    Copy the text in the codebox below:


    Code:
    :OTL
    SRV - File not found [Disabled] -- -- (PsaSrv)
    SRV - [2013/06/26 23:39:36 | 000,159,744 | ---- | M] (Microsoft Corporation) [Auto] -- C:\Documents and Settings\All Users\Application Data\rlqv.dat -- (winmgmt)
    DRV - File not found [Kernel | On_Demand] -- -- (WDICA)
    DRV - File not found [Kernel | Auto] -- -- (SSPORT)
    DRV - File not found [Kernel | On_Demand] -- -- (PDRFRAME)
    DRV - File not found [Kernel | On_Demand] -- -- (PDRELI)
    DRV - File not found [Kernel | On_Demand] -- -- (PDFRAME)
    DRV - File not found [Kernel | On_Demand] -- -- (PDCOMP)
    DRV - File not found [Kernel | System] -- -- (PCIDump)
    DRV - File not found [Kernel | System] -- -- (lbrtfdc)
    DRV - File not found [Kernel | Auto] -- -- (EGATHDRV)
    DRV - File not found [Kernel | Auto] -- -- (DgiVecp)
    DRV - File not found [Kernel | Auto] -- -- (Crypto)
    DRV - File not found [Kernel | System] -- -- (Changer)
    IE - HKU\.DEFAULT\..\URLSearchHook: {A3BC75A2-1F87-4686-AA43-5347D756017C} - Reg Error: Key error. File not found
    IE - HKU\PM_ON_C\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local;<local>
    O2 - BHO: (no name) - AutorunsDisabled - No CLSID value found.
    O3 - HKU\Administrator_ON_C\..\Toolbar\ShellBrowser: (no name) - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - No CLSID value found.
    O3 - HKU\PM_ON_C\..\Toolbar\WebBrowser: (no name) - {E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39} - No CLSID value found.
    O4 - HKU\Administrator_ON_C..\RunOnce: [spchecker] File not found
    O4 - Startup: C:\Documents and Settings\PM\Start Menu\Programs\Startup\Dropbox.lnk = File not found
    O4 - Startup: C:\Documents and Settings\PM\Start Menu\Programs\Startup\msconfig.lnk = X:\I386\SYSTEM32\RUNDLL32.EXE (Microsoft Corporation)
    O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab (Reg Error: Value error.)
    O16 - DPF: {CAFEEFAC-0014-0002-0000-ABCDEFFEDCBA} http://java.sun.com/products/plugin/1.4.2/jinstall-142-win.cab (Reg Error: Key error.)
    O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
    O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - File not found
    O36 - AppCertDlls: ntsdutou - (C:\WINDOWS\system32\dosxRRUN.dll) - File not found
    [2013/06/26 23:39:35 | 000,033,280 | ---- | C] (Microsoft Corporation) -- C:\Documents and Settings\All Users\Application Data\rundll32.exe
    [2013/06/26 23:39:51 | 000,000,790 | ---- | C] () -- C:\Documents and Settings\PM\Start Menu\Programs\Startup\msconfig.lnk
    [2013/06/26 23:39:41 | 095,023,320 | ---- | C] () -- C:\Documents and Settings\All Users\Application Data\vqlr.pad
    [2011/06/23 12:31:21 | 000,012,752 | -HS- | C] () -- C:\Documents and Settings\PM\Local Settings\Application Data\v34614kokdn87ld5p5m0sj75hs41572n7x508nstf75
    [2011/06/23 12:31:21 | 000,012,752 | -HS- | C] () -- C:\Documents and Settings\All Users\Application Data\v34614kokdn87ld5p5m0sj75hs41572n7x508nstf75
    [2011/06/05 13:32:51 | 000,001,368 | -HS- | C] () -- C:\Documents and Settings\PM\Local Settings\Application Data\6u88x86ou15wp2u
    [2011/06/05 13:32:51 | 000,001,368 | -HS- | C] () -- C:\Documents and Settings\All Users\Application Data\6u88x86ou15wp2u
    @Alternate Data Stream - 200 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:07BF512B
    @Alternate Data Stream - 152 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:679ABA25
    @Alternate Data Stream - 137 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:0B4227B4
    
    :Services
    
    :Reg
    
    :Files
    C:\Documents and Settings\All Users\Application Data\rlqv.dat 
    
    :Commands
    [purity]
    
    Open Notepad and paste it.
    Save the document as Fix.txt on to a USB flash drive


    On the infected computer the following...

    Run OTLPE

    • Insert USB stick and find the file Fix.txt. Drag the file Fix.txt and drop it under the Custom Scans/Fixes box at the bottom.
      • (The content of Fix.txt should appear in the box)
    • Then click the Run Fix button at the top
    • Let the program run unhindered, reboot the PC when it is done
    • Post the log produced (you'll need to transfer it with USB stick)
    • Remove the CD and shut down computer manually.
    • Attempt to reboot normally into Windows.
     
  14. jomon324

    jomon324 Newcomer, in training Topic Starter Posts: 40

    I copy-pasted the code and saved it to a USB stick as Fix.txt, then did the drag and drop into OTLPE and ran the fix. It said the fix ran completely and said to finish the process a reboot was necessary and brought up a dialog box asking me if I would like to reboot. I clicked "yes" and nothing happened. I then tried to reboot using Task Manager with Ctrl+Alt+Del, but for some reason I couldn't find the restart option in it. I then just opened the start menu and went to "Shut Down" and chose "Restart" from the drop-down menu and hit OK. everything behind the shutdown menu faded to gray, but nothing else changed. I moved the cursor over to "Cancel" and clicked it once, then multiple times as the first time didn't seem to register. Everything was frozen except the mouse. I did a hard reset by holding the power button, and upon restarting the computer, it automatically rebooted into the portable desktop on the CD. No log seems to have been created.

    I did my best to follow your instructions, and I am sorry if I messed up.
  15. Broni

    Broni Malware Annihilator Posts: 45,269   +243

    Remove CD and see if you can start in normal or safe mode.

    If not post new OTLPE log.
  16. jomon324

    jomon324 Newcomer, in training Topic Starter Posts: 40

    Log just produced from my dad turning on the computer normally, though "Speedy PC" and "realplay.exe" (two instances of realplay.exe along with realplayer update) appeared, and Avast! noticed them and had us quarantine them. They were really long filenames like "aosdmfoamisjglajsekrmdlgiermg"

    Also our sewer just flooded, so things are a little complicated now as this computer is only a few feet away from urine and fecal matter in sewer water.

    This is the log produced. I put it in a code box 'cuz I didn't know what else to do to avoid the 50000 character limit.

    Sorry for the late responses and thank you so much for your continued help.

    Code:
    ========== OTL ==========
    Registry key HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\PsaSrv deleted successfully.
    Registry key HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\winmgmt deleted successfully.
    C:\Documents and Settings\All Users\Application Data\rlqv.dat moved successfully.
    Registry key HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\WDICA deleted successfully.
    Registry key HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\SSPORT deleted successfully.
    Registry key HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\PDRFRAME deleted successfully.
    Registry key HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\PDRELI deleted successfully.
    Registry key HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\PDFRAME deleted successfully.
    Registry key HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\PDCOMP deleted successfully.
    Registry key HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\PCIDump deleted successfully.
    Registry key HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\lbrtfdc deleted successfully.
    Registry key HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\EGATHDRV deleted successfully.
    Registry key HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\DgiVecp deleted successfully.
    Registry key HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Crypto deleted successfully.
    Registry key HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Changer deleted successfully.
    Registry value HKEY_USERS\.DEFAULT\Software\Microsoft\Internet Explorer\URLSearchHooks\\{A3BC75A2-1F87-4686-AA43-5347D756017C} deleted successfully.
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A3BC75A2-1F87-4686-AA43-5347D756017C}\ not found.
    HKU\PM_ON_C\Software\Microsoft\Windows\CurrentVersion\Internet Settings\\ProxyOverride| /E : value set successfully!
    Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\AutorunsDisabled\ deleted successfully.
    Registry value HKEY_USERS\Administrator_ON_C\Software\Microsoft\Internet Explorer\Toolbar\ShellBrowser\\{42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} deleted successfully.
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6}\ not found.
    Registry value HKEY_USERS\PM_ON_C\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39} deleted successfully.
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39}\ deleted successfully.
    Registry value HKEY_USERS\Administrator_ON_C\Software\Microsoft\Windows\CurrentVersion\RunOnce\\spchecker deleted successfully.
    C:\Documents and Settings\PM\Start Menu\Programs\Startup\Dropbox.lnk moved successfully.
    C:\Documents and Settings\PM\Start Menu\Programs\Startup\msconfig.lnk moved successfully.
    File move failed. X:\I386\SYSTEM32\RUNDLL32.EXE scheduled to be moved on reboot.
    Starting removal of ActiveX control {8AD9C840-044E-11D1-B3E9-00805F499D93}
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{8AD9C840-044E-11D1-B3E9-00805F499D93}\ deleted successfully.
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8AD9C840-044E-11D1-B3E9-00805F499D93}\ deleted successfully.
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{8AD9C840-044E-11D1-B3E9-00805F499D93}\ not found.
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8AD9C840-044E-11D1-B3E9-00805F499D93}\ not found.
    Registry key HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Active Setup\Installed Components\{8AD9C840-044E-11D1-B3E9-00805F499D93}\ not found.
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8AD9C840-044E-11D1-B3E9-00805F499D93}\ not found.
    Registry key HKEY_USERS\Administrator_ON_C\SOFTWARE\Microsoft\Active Setup\Installed Components\{8AD9C840-044E-11D1-B3E9-00805F499D93}\ not found.
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8AD9C840-044E-11D1-B3E9-00805F499D93}\ not found.
    Registry key HKEY_USERS\LocalService_ON_C\SOFTWARE\Microsoft\Active Setup\Installed Components\{8AD9C840-044E-11D1-B3E9-00805F499D93}\ not found.
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8AD9C840-044E-11D1-B3E9-00805F499D93}\ not found.
    Registry key HKEY_USERS\NetworkService_ON_C\SOFTWARE\Microsoft\Active Setup\Installed Components\{8AD9C840-044E-11D1-B3E9-00805F499D93}\ not found.
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8AD9C840-044E-11D1-B3E9-00805F499D93}\ not found.
    Registry key HKEY_USERS\PM_ON_C\SOFTWARE\Microsoft\Active Setup\Installed Components\{8AD9C840-044E-11D1-B3E9-00805F499D93}\ not found.
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8AD9C840-044E-11D1-B3E9-00805F499D93}\ not found.
    Registry key HKEY_USERS\systemprofile_ON_C\SOFTWARE\Microsoft\Active Setup\Installed Components\{8AD9C840-044E-11D1-B3E9-00805F499D93}\ not found.
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8AD9C840-044E-11D1-B3E9-00805F499D93}\ not found.
    Starting removal of ActiveX control {CAFEEFAC-0014-0002-0000-ABCDEFFEDCBA}
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{CAFEEFAC-0014-0002-0000-ABCDEFFEDCBA}\ deleted successfully.
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CAFEEFAC-0014-0002-0000-ABCDEFFEDCBA}\ not found.
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{CAFEEFAC-0014-0002-0000-ABCDEFFEDCBA}\ not found.
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CAFEEFAC-0014-0002-0000-ABCDEFFEDCBA}\ not found.
    Registry key HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Active Setup\Installed Components\{CAFEEFAC-0014-0002-0000-ABCDEFFEDCBA}\ not found.
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CAFEEFAC-0014-0002-0000-ABCDEFFEDCBA}\ not found.
    Registry key HKEY_USERS\Administrator_ON_C\SOFTWARE\Microsoft\Active Setup\Installed Components\{CAFEEFAC-0014-0002-0000-ABCDEFFEDCBA}\ not found.
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CAFEEFAC-0014-0002-0000-ABCDEFFEDCBA}\ not found.
    Registry key HKEY_USERS\LocalService_ON_C\SOFTWARE\Microsoft\Active Setup\Installed Components\{CAFEEFAC-0014-0002-0000-ABCDEFFEDCBA}\ not found.
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CAFEEFAC-0014-0002-0000-ABCDEFFEDCBA}\ not found.
    Registry key HKEY_USERS\NetworkService_ON_C\SOFTWARE\Microsoft\Active Setup\Installed Components\{CAFEEFAC-0014-0002-0000-ABCDEFFEDCBA}\ not found.
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CAFEEFAC-0014-0002-0000-ABCDEFFEDCBA}\ not found.
    Registry key HKEY_USERS\PM_ON_C\SOFTWARE\Microsoft\Active Setup\Installed Components\{CAFEEFAC-0014-0002-0000-ABCDEFFEDCBA}\ not found.
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CAFEEFAC-0014-0002-0000-ABCDEFFEDCBA}\ not found.
    Registry key HKEY_USERS\systemprofile_ON_C\SOFTWARE\Microsoft\Active Setup\Installed Components\{CAFEEFAC-0014-0002-0000-ABCDEFFEDCBA}\ not found.
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CAFEEFAC-0014-0002-0000-ABCDEFFEDCBA}\ not found.
    Starting removal of ActiveX control {E2883E8F-472F-4FB0-9522-AC9BF37916A7}
    C:\WINDOWS\Downloaded Program Files\gp.inf not found.
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{E2883E8F-472F-4FB0-9522-AC9BF37916A7}\ deleted successfully.
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E2883E8F-472F-4FB0-9522-AC9BF37916A7}\ not found.
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{E2883E8F-472F-4FB0-9522-AC9BF37916A7}\ not found.
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E2883E8F-472F-4FB0-9522-AC9BF37916A7}\ not found.
    Registry key HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Active Setup\Installed Components\{E2883E8F-472F-4FB0-9522-AC9BF37916A7}\ not found.
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E2883E8F-472F-4FB0-9522-AC9BF37916A7}\ not found.
    Registry key HKEY_USERS\Administrator_ON_C\SOFTWARE\Microsoft\Active Setup\Installed Components\{E2883E8F-472F-4FB0-9522-AC9BF37916A7}\ not found.
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E2883E8F-472F-4FB0-9522-AC9BF37916A7}\ not found.
    Registry key HKEY_USERS\LocalService_ON_C\SOFTWARE\Microsoft\Active Setup\Installed Components\{E2883E8F-472F-4FB0-9522-AC9BF37916A7}\ not found.
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E2883E8F-472F-4FB0-9522-AC9BF37916A7}\ not found.
    Registry key HKEY_USERS\NetworkService_ON_C\SOFTWARE\Microsoft\Active Setup\Installed Components\{E2883E8F-472F-4FB0-9522-AC9BF37916A7}\ not found.
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E2883E8F-472F-4FB0-9522-AC9BF37916A7}\ not found.
    Registry key HKEY_USERS\PM_ON_C\SOFTWARE\Microsoft\Active Setup\Installed Components\{E2883E8F-472F-4FB0-9522-AC9BF37916A7}\ not found.
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E2883E8F-472F-4FB0-9522-AC9BF37916A7}\ not found.
    Registry key HKEY_USERS\systemprofile_ON_C\SOFTWARE\Microsoft\Active Setup\Installed Components\{E2883E8F-472F-4FB0-9522-AC9BF37916A7}\ not found.
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E2883E8F-472F-4FB0-9522-AC9BF37916A7}\ not found.
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\linkscanner\ deleted successfully.
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{F274614C-63F8-47D5-A4D1-FBDDE494F8D1}\ deleted successfully.
    File {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - File not found not found.
    Registry value HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Session Manager\AppCertDlls\\ntsdutou deleted successfully.
    C:\Documents and Settings\All Users\Application Data\rundll32.exe moved successfully.
    File C:\Documents and Settings\PM\Start Menu\Programs\Startup\msconfig.lnk not found.
    C:\Documents and Settings\All Users\Application Data\vqlr.pad moved successfully.
    C:\Documents and Settings\PM\Local Settings\Application Data\v34614kokdn87ld5p5m0sj75hs41572n7x508nstf75 moved successfully.
    C:\Documents and Settings\All Users\Application Data\v34614kokdn87ld5p5m0sj75hs41572n7x508nstf75 moved successfully.
    C:\Documents and Settings\PM\Local Settings\Application Data\6u88x86ou15wp2u moved successfully.
    C:\Documents and Settings\All Users\Application Data\6u88x86ou15wp2u moved successfully.
    ADS C:\Documents and Settings\All Users\Application Data\TEMP:07BF512B deleted successfully.
    ADS C:\Documents and Settings\All Users\Application Data\TEMP:679ABA25 deleted successfully.
    ADS C:\Documents and Settings\All Users\Application Data\TEMP:0B4227B4 deleted successfully.
    ========== SERVICES/DRIVERS ==========
    ========== REGISTRY ==========
    ========== FILES ==========
    File\Folder C:\Documents and Settings\All Users\Application Data\rlqv.dat not found.
    ========== COMMANDS ==========
     
    OTLPE by OldTimer - Version 3.1.48.0 log created on 07052013_131445
     
    Files\Folders moved on Reboot...
    File\Folder X:\I386\SYSTEM32\RUNDLL32.EXE not found!
     
    Registry entries deleted on Reboot...
    
  17. Broni

    Broni Malware Annihilator Posts: 45,269   +243

    Next time split any log between couple of replies.

    Are you saying that the computer booted normally?

    If so...

    Please, complete all steps listed here: http://www.techspot.com/vb/topic58138.html
    Make sure, you PASTE all logs. If some log exceeds 50,000 characters post limit, split it between couple of replies.
    Attached logs won't be reviewed.
  18. jomon324

    jomon324 Newcomer, in training Topic Starter Posts: 40

    I will try those steps at my closest availability, though I'm not sure when that will be.

    The basement flooded even worse, so I can't physically reach the computer. I know it's safe and working because I can see it from the stairs though.

    Repairmen are coming by today to see the conditions and hopefully get everything straightened out.

    I actually find it kind of funny that problems are piling up like this. Our house isn't the only one which got problems like this yesterday. It rained so hard that most of the sewers backed up.

     ̄\(O_o)/ ̄
  19. Broni

    Broni Malware Annihilator Posts: 45,269   +243

    I'm really sorry about your situation.
    Take your time :)
  20. jomon324

    jomon324 Newcomer, in training Topic Starter Posts: 40

    Ok, things have settled down quite a bit and I am now able to say some stuff about my dad's computer. The computer was able to start up normally due to OTLPE, and a log was saved. My dad was able to run both Avast and Malwarebytes Anti-Malware (in succession, not simultaneously) and I think I saw him doing a boot-scan with avast. He said it came up with something like 40,000+ errors, but that it ran for about 5 hours and fixed everything. I wasn't able to get to the computer immediately after he scanned it because it was something like 2am and waking other members of the house was not an option.

    When I next get the chance, I will locate the logs from OTLPE, Avast, and Malwarebytes, and post them.

    Thanks again for all the help^^
  21. Broni

    Broni Malware Annihilator Posts: 45,269   +243

    Very good :)

    Post those logs and ask your dad not to run any other tools until we check his computer thoroughly.

    Then....

    [​IMG] Download DDS by sUBs from one of the following links. Save it to your desktop.
    • Double click on the DDS icon, allow it to run.
    • A small box will open, with an explaination about the tool. No input is needed, the scan is running.
    • Notepad will open with the results.
    • Follow the instructions that pop up for posting the results.
    • Close the program window, and delete the program from your desktop.
    Please note: You may have to disable any script protection running if the scan fails to run. After downloading the tool, disconnect from the internet and disable all antivirus protection. Run the scan, enable your A/V and reconnect to the internet.

    Information on A/V control HERE

    [​IMG] Download RogueKiller for 32bit or Roguekiller for 64bit to your Desktop.
    • Close all the running programs
    • Windows Vista/7 users: right click on RogueKiller.exe, click Run as Administrator
    • Otherwise just double-click on RogueKiller.exe
    • Pre-scan will start. Let it finish.
    • Click on SCAN button.
    • Wait until the Status box shows Scan Finished
    • Click on Delete.
    • Wait until the Status box shows Deleting Finished.
    • Click on Report and copy/paste the content of the Notepad into your next reply.
    • RKreport.txt could also be found on your desktop.
    • If more than one log is produced post all logs.
    • If RogueKiller has been blocked, do not hesitate to try a few times more. If really won't run, rename it to winlogon.exe (or winlogon.com) and try again

    [​IMG] Create new restore point before proceeding with the next step....
    How to:
    - Windows 8: http://www.vikitech.com/11302/system-restore-windows-8
    - Windows 7: http://www.howtogeek.com/howto/3195/create-a-system-restore-point-in-windows-7/
    - Vista: http://www.howtogeek.com/howto/wind...tore-point-for-windows-vistas-system-restore/
    - XP: http://support.microsoft.com/kb/948247

    Download Malwarebytes Anti-Rootkit (MBAR) from HERE
    • Unzip downloaded file.
    • Open the folder where the contents were unzipped and run mbar.exe
    • Follow the instructions in the wizard to update and allow the program to scan your computer for threats.
    • Click on the Cleanup button to remove any threats and reboot if prompted to do so.
    • Wait while the system shuts down and the cleanup process is performed.
    • Perform another scan with Malwarebytes Anti-Rootkit to verify that no threats remain. If they do, then click Cleanup once more and repeat the process.
    • When done, please post the two logs produced they will be in the MBAR folder..... mbar-log-xxxxx.txt and system-log.txt
  22. Broni

    Broni Malware Annihilator Posts: 45,269   +243

    Still with me?
  23. jomon324

    jomon324 Newcomer, in training Topic Starter Posts: 40

    Yes, sorry! Um, been kinda busy, but I'll see what I can do today. I knew I had forgotten something, but I wasn't sure what. ><
  24. Broni

    Broni Malware Annihilator Posts: 45,269   +243

  25. jomon324

    jomon324 Newcomer, in training Topic Starter Posts: 40

    Hurk. Turns out we were up trying to put in our new water heater until about 11:30 last night, and then we both started to not walk straight due to fatigue, so we went to bed.

    I'm hoping I can run the tools today.
Topic Status:
Not open for further replies.


Add New Comment

TechSpot Members
Login or sign up for free,
it takes about 30 seconds.
You may also...


Get complete access to the TechSpot community. Join thousands of technology enthusiasts that contribute and share knowledge in our forum. Get a private inbox, upload your own photo gallery and more.