TechSpot

Need help with computer cleanup

By vunruh
Nov 3, 2010
  1. I ran a security analyzer and need to know which files I need to remove. Here is my log report, please help.

    [HJT log removed - Broni]
     

    Attached Files:

  2. Broni

    Broni Malware Annihilator Posts: 52,895   +344

    Welcome aboard [​IMG]

    Please, complete all steps listed here: http://www.techspot.com/vb/topic58138.html
    Make sure, you PASTE all logs. If some log exceeds 50,000 characters post limit, split it between couple of replies.
    Attached logs won't be reviewed.
     
  3. vunruh

    vunruh TS Rookie Topic Starter Posts: 25

    log reports

    Malwarebytes' Anti-Malware 1.46
    www.malwarebytes.org

    Database version: 5038

    Windows 5.1.2600 Service Pack 3
    Internet Explorer 8.0.6001.18702

    11/3/2010 5:25:48 PM
    mbam-log-2010-11-03 (17-25-48).txt

    Scan type: Quick scan
    Objects scanned: 137960
    Time elapsed: 9 minute(s), 8 second(s)

    Memory Processes Infected: 0
    Memory Modules Infected: 0
    Registry Keys Infected: 10
    Registry Values Infected: 2
    Registry Data Items Infected: 4
    Folders Infected: 5
    Files Infected: 18

    Memory Processes Infected:
    (No malicious items detected)

    Memory Modules Infected:
    (No malicious items detected)

    Registry Keys Infected:
    HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{56256a51-b582-467e-b8d4-7786eda79ae0} (Trojan.Vundo) -> Quarantined and deleted successfully.
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{56256a51-b582-467e-b8d4-7786eda79ae0} (Trojan.Vundo) -> Quarantined and deleted successfully.
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{90b5a95a-afd5-4d11-b9bd-a69d53d22226} (Adware.Hotbar) -> Quarantined and deleted successfully.
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{8109fd3d-d891-4f80-8339-50a4913ace6f} (Adware.Zango) -> Quarantined and deleted successfully.
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{bb05bd70-4605-4829-93fc-ad80d8cc5b66} (Rogue.PerformanceCenter) -> Quarantined and deleted successfully.
    HKEY_CURRENT_USER\SOFTWARE\DealAssistant (Trojan.Agent) -> Quarantined and deleted successfully.
    HKEY_CURRENT_USER\Software\IEBarProperties (Adware.Mirar) -> Quarantined and deleted successfully.
    HKEY_CURRENT_USER\SOFTWARE\The Weather Channel (Adware.Hotbar) -> Quarantined and deleted successfully.
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Multimedia\WMPlayer\Schemes\f3pss (Adware.MyWebSearch) -> Quarantined and deleted successfully.
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Weather Services (Adware.Hotbar) -> Quarantined and deleted successfully.

    Registry Values Infected:
    HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\MenuExt\&Search\(default) (Adware.Hotbar) -> Quarantined and deleted successfully.
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Control Panel\Cpls\wxfw.dll (Adware.Hotbar) -> Quarantined and deleted successfully.

    Registry Data Items Infected:
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\AntiVirusDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\FirewallDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
    HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Main\Search Bar (Hijack.SearchPage) -> Bad: (http://www.mirarsearch.com/?useie5=1&q=) Good: (http://www.google.com) -> Quarantined and deleted successfully.
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Main\Search Bar (Hijack.SearchPage) -> Bad: (http://www.mirarsearch.com/?useie5=1&q=) Good: (http://www.google.com) -> Quarantined and deleted successfully.

    Folders Infected:
    C:\Documents and Settings\Voneta\Application Data\DealAssistant (Trojan.Agent) -> Quarantined and deleted successfully.
    C:\Documents and Settings\All Users\Application Data\Starware337 (Adware.Starware) -> Quarantined and deleted successfully.
    C:\Documents and Settings\All Users\Application Data\Starware337\buttons (Adware.Starware) -> Quarantined and deleted successfully.
    C:\Documents and Settings\All Users\Application Data\Starware337\contexts (Adware.Starware) -> Quarantined and deleted successfully.
    C:\Program Files\Starware337 (Adware.Starware) -> Quarantined and deleted successfully.

    Files Infected:
    C:\Documents and Settings\Voneta\Desktop\MediaPlayerUpgrade.exe (Adware.Mirar) -> Quarantined and deleted successfully.
    C:\Documents and Settings\Voneta\Application Data\DealAssistant\config.cfg (Trojan.Agent) -> Quarantined and deleted successfully.
    C:\Documents and Settings\All Users\Application Data\Starware337\buttons\723_button_1b_def.bmp (Adware.Starware) -> Quarantined and deleted successfully.
    C:\Documents and Settings\All Users\Application Data\Starware337\buttons\723_button_1b_over.bmp (Adware.Starware) -> Quarantined and deleted successfully.
    C:\Documents and Settings\All Users\Application Data\Starware337\buttons\726_button_1b_def.bmp (Adware.Starware) -> Quarantined and deleted successfully.
    C:\Documents and Settings\All Users\Application Data\Starware337\buttons\FindIt.bmp (Adware.Starware) -> Quarantined and deleted successfully.
    C:\Documents and Settings\All Users\Application Data\Starware337\buttons\FindItHot.bmp (Adware.Starware) -> Quarantined and deleted successfully.
    C:\Documents and Settings\All Users\Application Data\Starware337\buttons\findithotxp.png (Adware.Starware) -> Quarantined and deleted successfully.
    C:\Documents and Settings\All Users\Application Data\Starware337\buttons\finditxp.png (Adware.Starware) -> Quarantined and deleted successfully.
    C:\Documents and Settings\All Users\Application Data\Starware337\buttons\logo.bmp (Adware.Starware) -> Quarantined and deleted successfully.
    C:\Documents and Settings\All Users\Application Data\Starware337\buttons\logoxp.bmp (Adware.Starware) -> Quarantined and deleted successfully.
    C:\Documents and Settings\All Users\Application Data\Starware337\buttons\Reference.bmp (Adware.Starware) -> Quarantined and deleted successfully.
    C:\Documents and Settings\All Users\Application Data\Starware337\buttons\ReferenceHot.bmp (Adware.Starware) -> Quarantined and deleted successfully.
    C:\Documents and Settings\All Users\Application Data\Starware337\buttons\referencehotxp.png (Adware.Starware) -> Quarantined and deleted successfully.
    C:\Documents and Settings\All Users\Application Data\Starware337\buttons\referencexp.png (Adware.Starware) -> Quarantined and deleted successfully.
    C:\Documents and Settings\All Users\Application Data\Starware337\contexts\error.xml (Adware.Starware) -> Quarantined and deleted successfully.
    C:\Documents and Settings\All Users\Application Data\Starware337\contexts\related.xml (Adware.Starware) -> Quarantined and deleted successfully.
    C:\Documents and Settings\All Users\Application Data\Starware337\contexts\travel.xml (Adware.Starware) -> Quarantined and deleted successfully.


    ER 1.0.15.15477 - http://www.gmer.net
    Rootkit scan 2010-11-03 18:33:23
    Windows 5.1.2600 Service Pack 3
    Running: GMER.exe; Driver: C:\DOCUME~1\Voneta\LOCALS~1\Temp\fxtdapob.sys


    ---- System - GMER 1.0.15 ----

    SSDT F7ED5366 ZwCreateKey
    SSDT F7ED535C ZwCreateThread
    SSDT F7ED536B ZwDeleteKey
    SSDT F7ED5375 ZwDeleteValueKey
    SSDT F7ED537A ZwLoadKey
    SSDT F7ED5348 ZwOpenProcess
    SSDT F7ED534D ZwOpenThread
    SSDT F7ED5384 ZwReplaceKey
    SSDT F7ED537F ZwRestoreKey
    SSDT F7ED5370 ZwSetValueKey

    ---- Kernel code sections - GMER 1.0.15 ----

    .text ntoskrnl.exe!_abnormal_termination + 148 804E27B4 1 Byte [6B]
    ? tgxi.sys The system cannot find the file specified. !

    ---- Devices - GMER 1.0.15 ----

    AttachedDevice \FileSystem\Fastfat \Fat fltmgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)

    ---- EOF - GMER 1.0.15 ----



    UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
    IF REQUESTED, ZIP IT UP & ATTACH IT

    DDS (Ver_10-11-03.01)

    Microsoft Windows XP Home Edition
    Boot Device: \Device\HarddiskVolume1
    Install Date: 7/5/2006 11:17:25 AM
    System Uptime: 11/3/2010 5:28:14 PM (1 hours ago)

    Motherboard: Dell Computer Corporation | | Dimension 4300
    Processor: Intel(R) Pentium(R) 4 CPU 1.60GHz | Microprocessor | 1594/100mhz

    ==== Disk Partitions =========================

    A: is Removable
    C: is FIXED (NTFS) - 128 GiB total, 111.66 GiB free.
    D: is CDROM ()
    E: is CDROM ()
    F: is Removable
    G: is Removable

    ==== Disabled Device Manager Items =============

    ==== System Restore Points ===================

    RP953: 8/11/2010 7:02:06 PM - System Checkpoint
    RP954: 8/11/2010 9:33:34 PM - Software Distribution Service 3.0
    RP955: 8/15/2010 6:23:22 PM - System Checkpoint
    RP956: 8/18/2010 9:47:51 AM - System Checkpoint
    RP957: 8/19/2010 12:09:20 PM - System Checkpoint
    RP958: 8/20/2010 12:34:59 PM - System Checkpoint
    RP959: 8/23/2010 8:42:38 AM - System Checkpoint
    RP960: 8/24/2010 3:00:49 PM - System Checkpoint
    RP961: 9/7/2010 9:07:27 AM - System Checkpoint
    RP962: 9/19/2010 11:00:04 AM - Software Distribution Service 3.0
    RP963: 9/28/2010 2:30:22 PM - Installed Java(TM) 6 Update 21
    RP964: 9/29/2010 11:07:16 AM - Software Distribution Service 3.0
    RP965: 9/30/2010 6:18:24 PM - System Checkpoint
    RP966: 10/7/2010 9:09:53 AM - System Checkpoint
    RP967: 10/10/2010 11:58:21 AM - Software Distribution Service 3.0
    RP968: 10/14/2010 6:04:06 PM - Software Distribution Service 3.0
    RP969: 11/2/2010 11:53:22 AM - System Checkpoint
    RP970: 11/3/2010 12:41:17 PM - System Checkpoint
    RP971: 11/3/2010 2:06:32 PM - Advanced SystemCare RestorePoint
    RP972: 11/3/2010 3:42:30 PM - Removed Creative ZEN V Series (R2)
    RP973: 11/3/2010 3:43:45 PM - Removed Ask Toolbar.

    ==== Installed Programs ======================


    Acrobat.com
    Adobe AIR
    Adobe Download Manager 2.0 (Remove Only)
    Adobe Flash Player 10 ActiveX
    Adobe Flash Player 10 Plugin
    Adobe Reader 9.4.0
    Adobe Shockwave Player
    Adobe® Photoshop® Album Starter Edition 3.0
    Advanced SystemCare 3
    AiO_Scan_CDA
    AiOSoftwareNPI
    AirPlus G
    ANIO Service
    ANIWZCS2 Service
    AnswerWorks 4.0 Runtime - English
    AnswerWorks 5.0 English Runtime
    ATI Display Driver
    Avira AntiVir Personal - Free Antivirus
    BufferChm
    C6100
    c6100_Help
    Compatibility Pack for the 2007 Office system
    Conduit Engine
    Coupon Printer for Windows
    CP_CalendarTemplates1
    cp_OnlineProjectsConfig
    CP_Package_Basic1
    CP_Panorama1Config
    cp_PosterPrintConfig
    Creative Removable Disk Manager
    Creative System Information
    CueTour
    CustomerResearchQFolder
    D-Link PCI Fast Ethernet Adapter
    Destinations
    DeviceManagementQFolder
    DocProc
    DocProcQFolder
    DocumentViewer
    DocumentViewerQFolder
    Easy CD Creator 5 Basic
    eSupportQFolder
    Fax_CDA
    FullDPAppQFolder
    getPlus(R) for Adobe
    Google Toolbar for Internet Explorer
    Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)
    Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)
    Hotfix for Windows Media Format 11 SDK (KB929399)
    Hotfix for Windows Media Player 11 (KB939683)
    Hotfix for Windows XP (KB2158563)
    Hotfix for Windows XP (KB952287)
    Hotfix for Windows XP (KB954550-v5)
    Hotfix for Windows XP (KB961118)
    Hotfix for Windows XP (KB970653-v3)
    Hotfix for Windows XP (KB976098-v2)
    Hotfix for Windows XP (KB979306)
    Hotfix for Windows XP (KB981793)
    HP Customer Participation Program 7.0
    HP Document Viewer 7.0
    HP Driver Diagnostics
    HP Imaging Device Functions 7.0
    hp instant support
    HP Photosmart Premier Software 6.5
    HP Photosmart, Officejet and Deskjet 7.0.A
    HP Product Assistant
    hp psc 700 series
    HP Solution Center 7.0
    HP Update
    HPPhotoSmartExpress
    HPProductAssistant
    HPSSupply
    InstantShareDevices
    InstantShareDevicesMFC
    Java Auto Updater
    Java(TM) 6 Update 21
    LG USB Modem driver
    Malwarebytes' Anti-Malware
    MarketResearch
    Microsoft .NET Framework 1.1
    Microsoft .NET Framework 1.1 Security Update (KB2416447)
    Microsoft .NET Framework 1.1 Security Update (KB979906)
    Microsoft .NET Framework 2.0 Service Pack 2
    Microsoft .NET Framework 3.0 Service Pack 2
    Microsoft .NET Framework 3.5 SP1
    Microsoft Compression Client Pack 1.0 for Windows XP
    Microsoft Office 2000 Disc 2
    Microsoft Office 2000 Professional
    Microsoft User-Mode Driver Framework Feature Pack 1.0
    Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
    Mirar
    NewCopy_CDA
    OCR Software by I.R.I.S 7.0
    Online Radio 1.1 Toolbar
    PanoStandAlone
    PhotoGallery
    ProductContextNPI
    QuickTime
    RandMap
    Readme
    Scan
    ScannerCopy
    Security Update for Microsoft .NET Framework 3.5 SP1 (KB2416473)
    Security Update for Windows Internet Explorer 8 (KB2183461)
    Security Update for Windows Internet Explorer 8 (KB2360131)
    Security Update for Windows Internet Explorer 8 (KB969897)
    Security Update for Windows Internet Explorer 8 (KB971961)
    Security Update for Windows Internet Explorer 8 (KB972260)
    Security Update for Windows Internet Explorer 8 (KB974455)
    Security Update for Windows Internet Explorer 8 (KB976325)
    Security Update for Windows Internet Explorer 8 (KB978207)
    Security Update for Windows Internet Explorer 8 (KB981332)
    Security Update for Windows Internet Explorer 8 (KB982381)
    Security Update for Windows Media Player (KB2378111)
    Security Update for Windows Media Player (KB911564)
    Security Update for Windows Media Player (KB952069)
    Security Update for Windows Media Player (KB954155)
    Security Update for Windows Media Player (KB968816)
    Security Update for Windows Media Player (KB973540)
    Security Update for Windows Media Player (KB975558)
    Security Update for Windows Media Player (KB978695)
    Security Update for Windows Media Player 10 (KB917734)
    Security Update for Windows Media Player 10 (KB936782)
    Security Update for Windows Media Player 11 (KB954154)
    Security Update for Windows Media Player 6.4 (KB925398)
    Security Update for Windows Media Player 9 (KB917734)
    Security Update for Windows XP (KB2079403)
    Security Update for Windows XP (KB2115168)
    Security Update for Windows XP (KB2121546)
    Security Update for Windows XP (KB2160329)
    Security Update for Windows XP (KB2229593)
    Security Update for Windows XP (KB2259922)
    Security Update for Windows XP (KB2279986)
    Security Update for Windows XP (KB2286198)
    Security Update for Windows XP (KB2296011)
    Security Update for Windows XP (KB2347290)
    Security Update for Windows XP (KB2360937)
    Security Update for Windows XP (KB2387149)
    Security Update for Windows XP (KB923561)
    Security Update for Windows XP (KB923689)
    Security Update for Windows XP (KB938464)
    Security Update for Windows XP (KB941569)
    Security Update for Windows XP (KB946648)
    Security Update for Windows XP (KB950759)
    Security Update for Windows XP (KB950760)
    Security Update for Windows XP (KB950762)
    Security Update for Windows XP (KB950974)
    Security Update for Windows XP (KB951066)
    Security Update for Windows XP (KB951376-v2)
    Security Update for Windows XP (KB951376)
    Security Update for Windows XP (KB951698)
    Security Update for Windows XP (KB951748)
    Security Update for Windows XP (KB952004)
    Security Update for Windows XP (KB952954)
    Security Update for Windows XP (KB953838)
    Security Update for Windows XP (KB953839)
    Security Update for Windows XP (KB954211)
    Security Update for Windows XP (KB954459)
    Security Update for Windows XP (KB954600)
    Security Update for Windows XP (KB955069)
    Security Update for Windows XP (KB956390)
    Security Update for Windows XP (KB956391)
    Security Update for Windows XP (KB956572)
    Security Update for Windows XP (KB956744)
    Security Update for Windows XP (KB956802)
    Security Update for Windows XP (KB956803)
    Security Update for Windows XP (KB956841)
    Security Update for Windows XP (KB956844)
    Security Update for Windows XP (KB957095)
    Security Update for Windows XP (KB957097)
    Security Update for Windows XP (KB958215)
    Security Update for Windows XP (KB958644)
    Security Update for Windows XP (KB958687)
    Security Update for Windows XP (KB958690)
    Security Update for Windows XP (KB958869)
    Security Update for Windows XP (KB959426)
    Security Update for Windows XP (KB960225)
    Security Update for Windows XP (KB960714)
    Security Update for Windows XP (KB960715)
    Security Update for Windows XP (KB960803)
    Security Update for Windows XP (KB960859)
    Security Update for Windows XP (KB961371)
    Security Update for Windows XP (KB961373)
    Security Update for Windows XP (KB961501)
    Security Update for Windows XP (KB963027)
    Security Update for Windows XP (KB968537)
    Security Update for Windows XP (KB969059)
    Security Update for Windows XP (KB969897)
    Security Update for Windows XP (KB969898)
    Security Update for Windows XP (KB969947)
    Security Update for Windows XP (KB970238)
    Security Update for Windows XP (KB970430)
    Security Update for Windows XP (KB971468)
    Security Update for Windows XP (KB971486)
    Security Update for Windows XP (KB971557)
    Security Update for Windows XP (KB971633)
    Security Update for Windows XP (KB971657)
    Security Update for Windows XP (KB972270)
    Security Update for Windows XP (KB973346)
    Security Update for Windows XP (KB973354)
    Security Update for Windows XP (KB973507)
    Security Update for Windows XP (KB973525)
    Security Update for Windows XP (KB973869)
    Security Update for Windows XP (KB973904)
    Security Update for Windows XP (KB974112)
    Security Update for Windows XP (KB974318)
    Security Update for Windows XP (KB974392)
    Security Update for Windows XP (KB974571)
    Security Update for Windows XP (KB975025)
    Security Update for Windows XP (KB975467)
    Security Update for Windows XP (KB975560)
    Security Update for Windows XP (KB975561)
    Security Update for Windows XP (KB975562)
    Security Update for Windows XP (KB975713)
    Security Update for Windows XP (KB977165)
    Security Update for Windows XP (KB977816)
    Security Update for Windows XP (KB977914)
    Security Update for Windows XP (KB978037)
    Security Update for Windows XP (KB978251)
    Security Update for Windows XP (KB978262)
    Security Update for Windows XP (KB978338)
    Security Update for Windows XP (KB978542)
    Security Update for Windows XP (KB978601)
    Security Update for Windows XP (KB978706)
    Security Update for Windows XP (KB979309)
    Security Update for Windows XP (KB979482)
    Security Update for Windows XP (KB979559)
    Security Update for Windows XP (KB979683)
    Security Update for Windows XP (KB979687)
    Security Update for Windows XP (KB980195)
    Security Update for Windows XP (KB980218)
    Security Update for Windows XP (KB980232)
    Security Update for Windows XP (KB980436)
    Security Update for Windows XP (KB981322)
    Security Update for Windows XP (KB981852)
    Security Update for Windows XP (KB981957)
    Security Update for Windows XP (KB981997)
    Security Update for Windows XP (KB982132)
    Security Update for Windows XP (KB982214)
    Security Update for Windows XP (KB982665)
    Security Update for Windows XP (KB982802)
    Shop for HP Supplies
    SkinsHP1
    SlideShow
    Smart Defrag
    SolutionCenter
    Sonic_PrimoSDK
    Status
    SUPERAntiSpyware Free Edition
    The Weather Channel Desktop 6
    The Weather Channel Toolbar
    Toolbox
    TrayApp
    TurboTax 2008
    TurboTax 2008 wcoiper
    TurboTax 2008 WinPerFedFormset
    TurboTax 2008 WinPerProgramHelp
    TurboTax 2008 WinPerReleaseEngine
    TurboTax 2008 WinPerTaxSupport
    TurboTax 2008 WinPerUserEducation
    TurboTax 2008 wrapper
    TurboTax 2009
    TurboTax 2009 wcaiper
    TurboTax 2009 wcoiper
    TurboTax 2009 WinPerFedFormset
    TurboTax 2009 WinPerReleaseEngine
    TurboTax 2009 WinPerTaxSupport
    TurboTax 2009 wrapper
    TurboTax Deluxe 2007
    TurboTax ItsDeductible 2006
    Unload
    Update for Microsoft .NET Framework 3.5 SP1 (KB963707)
    Update for Windows Internet Explorer 8 (KB971180)
    Update for Windows Internet Explorer 8 (KB976662)
    Update for Windows Internet Explorer 8 (KB976749)
    Update for Windows Internet Explorer 8 (KB980182)
    Update for Windows XP (KB2141007)
    Update for Windows XP (KB2345886)
    Update for Windows XP (KB951072-v2)
    Update for Windows XP (KB951978)
    Update for Windows XP (KB955759)
    Update for Windows XP (KB955839)
    Update for Windows XP (KB967715)
    Update for Windows XP (KB968389)
    Update for Windows XP (KB971737)
    Update for Windows XP (KB973687)
    Update for Windows XP (KB973815)
    V CAST Music Manager
    Viewpoint Manager (Remove Only)
    Viewpoint Media Player
    WebFldrs XP
    WebReg
    WexTech AnswerWorks
    Windows Genuine Advantage Notifications (KB905474)
    Windows Internet Explorer 8
    Windows Media Format 11 runtime
    Windows Media Player 10 Hotfix - KB895316
    Windows Media Player 11
    Windows XP Service Pack 3

    ==== Event Viewer Messages From Past Week ========

    11/3/2010 5:33:56 PM, error: SideBySide [59] - Resolve Partial Assembly failed for Microsoft.VC90.CRT. Reference error message: The referenced assembly is not installed on your system. .
    11/3/2010 5:33:56 PM, error: SideBySide [59] - Generate Activation Context failed for C:\DOCUME~1\Voneta\LOCALS~1\Temp\RarSFX0\redist.dll. Reference error message: The operation completed successfully. .
    11/3/2010 5:33:56 PM, error: SideBySide [32] - Dependent Assembly Microsoft.VC90.CRT could not be found and Last Error was The referenced assembly is not installed on your system.
    11/3/2010 5:28:46 PM, error: sr [1] - The System Restore filter encountered the unexpected error '0xC0000001' while processing the file '' on the volume 'HarddiskVolume1'. It has stopped monitoring the volume.
    11/3/2010 4:09:53 PM, error: Service Control Manager [7000] - The SASDIFSV service failed to start due to the following error: Cannot create a file when that file already exists.
    11/3/2010 3:43:51 PM, error: Service Control Manager [7023] - The Application Management service terminated with the following error: The specified module could not be found.
    11/2/2010 11:01:40 AM, error: Service Control Manager [7011] - Timeout (30000 milliseconds) waiting for a transaction response from the stisvc service.
    10/28/2010 9:36:44 PM, error: SideBySide [59] - Resolve Partial Assembly failed for Microsoft.VC80.MFCLOC. Reference error message: The referenced assembly is not installed on your system. .
    10/28/2010 9:36:44 PM, error: SideBySide [59] - Generate Activation Context failed for C:\WINDOWS\WinSxS\x86_Microsoft.VC80.MFC_1fc8b3b9a1e18e3b_8.0.50727.91_x-ww_decbdf0c\MFC80.DLL. Reference error message: The operation completed successfully. .
    10/28/2010 9:36:44 PM, error: SideBySide [32] - Dependent Assembly Microsoft.VC80.MFCLOC could not be found and Last Error was The referenced assembly is not installed on your system.

    ==== End Of File ===========================
     

    Attached Files:

  4. vunruh

    vunruh TS Rookie Topic Starter Posts: 25

    I hope I did this right. If not please let me know.

    Thank you for your help.
     
  5. Broni

    Broni Malware Annihilator Posts: 52,895   +344

    Please, observe forum's rule regarding pasting ALL logs.


    UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
    IF REQUESTED, ZIP IT UP & ATTACH IT

    DDS (Ver_10-11-03.01)

    Microsoft Windows XP Home Edition
    Boot Device: \Device\HarddiskVolume1
    Install Date: 7/5/2006 11:17:25 AM
    System Uptime: 11/3/2010 5:28:14 PM (1 hours ago)

    Motherboard: Dell Computer Corporation | | Dimension 4300
    Processor: Intel(R) Pentium(R) 4 CPU 1.60GHz | Microprocessor | 1594/100mhz

    ==== Disk Partitions =========================

    A: is Removable
    C: is FIXED (NTFS) - 128 GiB total, 111.66 GiB free.
    D: is CDROM ()
    E: is CDROM ()
    F: is Removable
    G: is Removable

    ==== Disabled Device Manager Items =============

    ==== System Restore Points ===================

    RP953: 8/11/2010 7:02:06 PM - System Checkpoint
    RP954: 8/11/2010 9:33:34 PM - Software Distribution Service 3.0
    RP955: 8/15/2010 6:23:22 PM - System Checkpoint
    RP956: 8/18/2010 9:47:51 AM - System Checkpoint
    RP957: 8/19/2010 12:09:20 PM - System Checkpoint
    RP958: 8/20/2010 12:34:59 PM - System Checkpoint
    RP959: 8/23/2010 8:42:38 AM - System Checkpoint
    RP960: 8/24/2010 3:00:49 PM - System Checkpoint
    RP961: 9/7/2010 9:07:27 AM - System Checkpoint
    RP962: 9/19/2010 11:00:04 AM - Software Distribution Service 3.0
    RP963: 9/28/2010 2:30:22 PM - Installed Java(TM) 6 Update 21
    RP964: 9/29/2010 11:07:16 AM - Software Distribution Service 3.0
    RP965: 9/30/2010 6:18:24 PM - System Checkpoint
    RP966: 10/7/2010 9:09:53 AM - System Checkpoint
    RP967: 10/10/2010 11:58:21 AM - Software Distribution Service 3.0
    RP968: 10/14/2010 6:04:06 PM - Software Distribution Service 3.0
    RP969: 11/2/2010 11:53:22 AM - System Checkpoint
    RP970: 11/3/2010 12:41:17 PM - System Checkpoint
    RP971: 11/3/2010 2:06:32 PM - Advanced SystemCare RestorePoint
    RP972: 11/3/2010 3:42:30 PM - Removed Creative ZEN V Series (R2)
    RP973: 11/3/2010 3:43:45 PM - Removed Ask Toolbar.

    ==== Installed Programs ======================


    Acrobat.com
    Adobe AIR
    Adobe Download Manager 2.0 (Remove Only)
    Adobe Flash Player 10 ActiveX
    Adobe Flash Player 10 Plugin
    Adobe Reader 9.4.0
    Adobe Shockwave Player
    Adobe® Photoshop® Album Starter Edition 3.0
    Advanced SystemCare 3
    AiO_Scan_CDA
    AiOSoftwareNPI
    AirPlus G
    ANIO Service
    ANIWZCS2 Service
    AnswerWorks 4.0 Runtime - English
    AnswerWorks 5.0 English Runtime
    ATI Display Driver
    Avira AntiVir Personal - Free Antivirus
    BufferChm
    C6100
    c6100_Help
    Compatibility Pack for the 2007 Office system
    Conduit Engine
    Coupon Printer for Windows
    CP_CalendarTemplates1
    cp_OnlineProjectsConfig
    CP_Package_Basic1
    CP_Panorama1Config
    cp_PosterPrintConfig
    Creative Removable Disk Manager
    Creative System Information
    CueTour
    CustomerResearchQFolder
    D-Link PCI Fast Ethernet Adapter
    Destinations
    DeviceManagementQFolder
    DocProc
    DocProcQFolder
    DocumentViewer
    DocumentViewerQFolder
    Easy CD Creator 5 Basic
    eSupportQFolder
    Fax_CDA
    FullDPAppQFolder
    getPlus(R) for Adobe
    Google Toolbar for Internet Explorer
    Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)
    Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)
    Hotfix for Windows Media Format 11 SDK (KB929399)
    Hotfix for Windows Media Player 11 (KB939683)
    Hotfix for Windows XP (KB2158563)
    Hotfix for Windows XP (KB952287)
    Hotfix for Windows XP (KB954550-v5)
    Hotfix for Windows XP (KB961118)
    Hotfix for Windows XP (KB970653-v3)
    Hotfix for Windows XP (KB976098-v2)
    Hotfix for Windows XP (KB979306)
    Hotfix for Windows XP (KB981793)
    HP Customer Participation Program 7.0
    HP Document Viewer 7.0
    HP Driver Diagnostics
    HP Imaging Device Functions 7.0
    hp instant support
    HP Photosmart Premier Software 6.5
    HP Photosmart, Officejet and Deskjet 7.0.A
    HP Product Assistant
    hp psc 700 series
    HP Solution Center 7.0
    HP Update
    HPPhotoSmartExpress
    HPProductAssistant
    HPSSupply
    InstantShareDevices
    InstantShareDevicesMFC
    Java Auto Updater
    Java(TM) 6 Update 21
    LG USB Modem driver
    Malwarebytes' Anti-Malware
    MarketResearch
    Microsoft .NET Framework 1.1
    Microsoft .NET Framework 1.1 Security Update (KB2416447)
    Microsoft .NET Framework 1.1 Security Update (KB979906)
    Microsoft .NET Framework 2.0 Service Pack 2
    Microsoft .NET Framework 3.0 Service Pack 2
    Microsoft .NET Framework 3.5 SP1
    Microsoft Compression Client Pack 1.0 for Windows XP
    Microsoft Office 2000 Disc 2
    Microsoft Office 2000 Professional
    Microsoft User-Mode Driver Framework Feature Pack 1.0
    Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
    Mirar
    NewCopy_CDA
    OCR Software by I.R.I.S 7.0
    Online Radio 1.1 Toolbar
    PanoStandAlone
    PhotoGallery
    ProductContextNPI
    QuickTime
    RandMap
    Readme
    Scan
    ScannerCopy
    Security Update for Microsoft .NET Framework 3.5 SP1 (KB2416473)
    Security Update for Windows Internet Explorer 8 (KB2183461)
    Security Update for Windows Internet Explorer 8 (KB2360131)
    Security Update for Windows Internet Explorer 8 (KB969897)
    Security Update for Windows Internet Explorer 8 (KB971961)
    Security Update for Windows Internet Explorer 8 (KB972260)
    Security Update for Windows Internet Explorer 8 (KB974455)
    Security Update for Windows Internet Explorer 8 (KB976325)
    Security Update for Windows Internet Explorer 8 (KB978207)
    Security Update for Windows Internet Explorer 8 (KB981332)
    Security Update for Windows Internet Explorer 8 (KB982381)
    Security Update for Windows Media Player (KB2378111)
    Security Update for Windows Media Player (KB911564)
    Security Update for Windows Media Player (KB952069)
    Security Update for Windows Media Player (KB954155)
    Security Update for Windows Media Player (KB968816)
    Security Update for Windows Media Player (KB973540)
    Security Update for Windows Media Player (KB975558)
    Security Update for Windows Media Player (KB978695)
    Security Update for Windows Media Player 10 (KB917734)
    Security Update for Windows Media Player 10 (KB936782)
    Security Update for Windows Media Player 11 (KB954154)
    Security Update for Windows Media Player 6.4 (KB925398)
    Security Update for Windows Media Player 9 (KB917734)
    Security Update for Windows XP (KB2079403)
    Security Update for Windows XP (KB2115168)
    Security Update for Windows XP (KB2121546)
    Security Update for Windows XP (KB2160329)
    Security Update for Windows XP (KB2229593)
    Security Update for Windows XP (KB2259922)
    Security Update for Windows XP (KB2279986)
    Security Update for Windows XP (KB2286198)
    Security Update for Windows XP (KB2296011)
    Security Update for Windows XP (KB2347290)
    Security Update for Windows XP (KB2360937)
    Security Update for Windows XP (KB2387149)
    Security Update for Windows XP (KB923561)
    Security Update for Windows XP (KB923689)
    Security Update for Windows XP (KB938464)
    Security Update for Windows XP (KB941569)
    Security Update for Windows XP (KB946648)
    Security Update for Windows XP (KB950759)
    Security Update for Windows XP (KB950760)
    Security Update for Windows XP (KB950762)
    Security Update for Windows XP (KB950974)
    Security Update for Windows XP (KB951066)
    Security Update for Windows XP (KB951376-v2)
    Security Update for Windows XP (KB951376)
    Security Update for Windows XP (KB951698)
    Security Update for Windows XP (KB951748)
    Security Update for Windows XP (KB952004)
    Security Update for Windows XP (KB952954)
    Security Update for Windows XP (KB953838)
    Security Update for Windows XP (KB953839)
    Security Update for Windows XP (KB954211)
    Security Update for Windows XP (KB954459)
    Security Update for Windows XP (KB954600)
    Security Update for Windows XP (KB955069)
    Security Update for Windows XP (KB956390)
    Security Update for Windows XP (KB956391)
    Security Update for Windows XP (KB956572)
    Security Update for Windows XP (KB956744)
    Security Update for Windows XP (KB956802)
    Security Update for Windows XP (KB956803)
    Security Update for Windows XP (KB956841)
    Security Update for Windows XP (KB956844)
    Security Update for Windows XP (KB957095)
    Security Update for Windows XP (KB957097)
    Security Update for Windows XP (KB958215)
    Security Update for Windows XP (KB958644)
    Security Update for Windows XP (KB958687)
    Security Update for Windows XP (KB958690)
    Security Update for Windows XP (KB958869)
    Security Update for Windows XP (KB959426)
    Security Update for Windows XP (KB960225)
    Security Update for Windows XP (KB960714)
    Security Update for Windows XP (KB960715)
    Security Update for Windows XP (KB960803)
    Security Update for Windows XP (KB960859)
    Security Update for Windows XP (KB961371)
    Security Update for Windows XP (KB961373)
    Security Update for Windows XP (KB961501)
    Security Update for Windows XP (KB963027)
    Security Update for Windows XP (KB968537)
    Security Update for Windows XP (KB969059)
    Security Update for Windows XP (KB969897)
    Security Update for Windows XP (KB969898)
    Security Update for Windows XP (KB969947)
    Security Update for Windows XP (KB970238)
    Security Update for Windows XP (KB970430)
    Security Update for Windows XP (KB971468)
    Security Update for Windows XP (KB971486)
    Security Update for Windows XP (KB971557)
    Security Update for Windows XP (KB971633)
    Security Update for Windows XP (KB971657)
    Security Update for Windows XP (KB972270)
    Security Update for Windows XP (KB973346)
    Security Update for Windows XP (KB973354)
    Security Update for Windows XP (KB973507)
    Security Update for Windows XP (KB973525)
    Security Update for Windows XP (KB973869)
    Security Update for Windows XP (KB973904)
    Security Update for Windows XP (KB974112)
    Security Update for Windows XP (KB974318)
    Security Update for Windows XP (KB974392)
    Security Update for Windows XP (KB974571)
    Security Update for Windows XP (KB975025)
    Security Update for Windows XP (KB975467)
    Security Update for Windows XP (KB975560)
    Security Update for Windows XP (KB975561)
    Security Update for Windows XP (KB975562)
    Security Update for Windows XP (KB975713)
    Security Update for Windows XP (KB977165)
    Security Update for Windows XP (KB977816)
    Security Update for Windows XP (KB977914)
    Security Update for Windows XP (KB978037)
    Security Update for Windows XP (KB978251)
    Security Update for Windows XP (KB978262)
    Security Update for Windows XP (KB978338)
    Security Update for Windows XP (KB978542)
    Security Update for Windows XP (KB978601)
    Security Update for Windows XP (KB978706)
    Security Update for Windows XP (KB979309)
    Security Update for Windows XP (KB979482)
    Security Update for Windows XP (KB979559)
    Security Update for Windows XP (KB979683)
    Security Update for Windows XP (KB979687)
    Security Update for Windows XP (KB980195)
    Security Update for Windows XP (KB980218)
    Security Update for Windows XP (KB980232)
    Security Update for Windows XP (KB980436)
    Security Update for Windows XP (KB981322)
    Security Update for Windows XP (KB981852)
    Security Update for Windows XP (KB981957)
    Security Update for Windows XP (KB981997)
    Security Update for Windows XP (KB982132)
    Security Update for Windows XP (KB982214)
    Security Update for Windows XP (KB982665)
    Security Update for Windows XP (KB982802)
    Shop for HP Supplies
    SkinsHP1
    SlideShow
    Smart Defrag
    SolutionCenter
    Sonic_PrimoSDK
    Status
    SUPERAntiSpyware Free Edition
    The Weather Channel Desktop 6
    The Weather Channel Toolbar
    Toolbox
    TrayApp
    TurboTax 2008
    TurboTax 2008 wcoiper
    TurboTax 2008 WinPerFedFormset
    TurboTax 2008 WinPerProgramHelp
    TurboTax 2008 WinPerReleaseEngine
    TurboTax 2008 WinPerTaxSupport
    TurboTax 2008 WinPerUserEducation
    TurboTax 2008 wrapper
    TurboTax 2009
    TurboTax 2009 wcaiper
    TurboTax 2009 wcoiper
    TurboTax 2009 WinPerFedFormset
    TurboTax 2009 WinPerReleaseEngine
    TurboTax 2009 WinPerTaxSupport
    TurboTax 2009 wrapper
    TurboTax Deluxe 2007
    TurboTax ItsDeductible 2006
    Unload
    Update for Microsoft .NET Framework 3.5 SP1 (KB963707)
    Update for Windows Internet Explorer 8 (KB971180)
    Update for Windows Internet Explorer 8 (KB976662)
    Update for Windows Internet Explorer 8 (KB976749)
    Update for Windows Internet Explorer 8 (KB980182)
    Update for Windows XP (KB2141007)
    Update for Windows XP (KB2345886)
    Update for Windows XP (KB951072-v2)
    Update for Windows XP (KB951978)
    Update for Windows XP (KB955759)
    Update for Windows XP (KB955839)
    Update for Windows XP (KB967715)
    Update for Windows XP (KB968389)
    Update for Windows XP (KB971737)
    Update for Windows XP (KB973687)
    Update for Windows XP (KB973815)
    V CAST Music Manager
    Viewpoint Manager (Remove Only)
    Viewpoint Media Player
    WebFldrs XP
    WebReg
    WexTech AnswerWorks
    Windows Genuine Advantage Notifications (KB905474)
    Windows Internet Explorer 8
    Windows Media Format 11 runtime
    Windows Media Player 10 Hotfix - KB895316
    Windows Media Player 11
    Windows XP Service Pack 3

    ==== Event Viewer Messages From Past Week ========

    11/3/2010 5:33:56 PM, error: SideBySide [59] - Resolve Partial Assembly failed for Microsoft.VC90.CRT. Reference error message: The referenced assembly is not installed on your system. .
    11/3/2010 5:33:56 PM, error: SideBySide [59] - Generate Activation Context failed for C:\DOCUME~1\Voneta\LOCALS~1\Temp\RarSFX0\redist.dll. Reference error message: The operation completed successfully. .
    11/3/2010 5:33:56 PM, error: SideBySide [32] - Dependent Assembly Microsoft.VC90.CRT could not be found and Last Error was The referenced assembly is not installed on your system.
    11/3/2010 5:28:46 PM, error: sr [1] - The System Restore filter encountered the unexpected error '0xC0000001' while processing the file '' on the volume 'HarddiskVolume1'. It has stopped monitoring the volume.
    11/3/2010 4:09:53 PM, error: Service Control Manager [7000] - The SASDIFSV service failed to start due to the following error: Cannot create a file when that file already exists.
    11/3/2010 3:43:51 PM, error: Service Control Manager [7023] - The Application Management service terminated with the following error: The specified module could not be found.
    11/2/2010 11:01:40 AM, error: Service Control Manager [7011] - Timeout (30000 milliseconds) waiting for a transaction response from the stisvc service.
    10/28/2010 9:36:44 PM, error: SideBySide [59] - Resolve Partial Assembly failed for Microsoft.VC80.MFCLOC. Reference error message: The referenced assembly is not installed on your system. .
    10/28/2010 9:36:44 PM, error: SideBySide [59] - Generate Activation Context failed for C:\WINDOWS\WinSxS\x86_Microsoft.VC80.MFC_1fc8b3b9a1e18e3b_8.0.50727.91_x-ww_decbdf0c\MFC80.DLL. Reference error message: The operation completed successfully. .
    10/28/2010 9:36:44 PM, error: SideBySide [32] - Dependent Assembly Microsoft.VC80.MFCLOC could not be found and Last Error was The referenced assembly is not installed on your system.

    ==== End Of File ===========================
     
  6. Broni

    Broni Malware Annihilator Posts: 52,895   +344

    Download MBRCheck to your desktop

    Double click MBRCheck.exe to run (Vista and Windows 7 users, right click and select Run as Administrator).
    It will show a black screen with some data on it.
    Enter N to exit.
    A report called MBRcheckxxxx.txt will be on your desktop
    Open this report and post its content in your next reply.

    =====================================================================

    Please download ComboFix from Here or Here to your Desktop.

    **Note: In the event you already have Combofix, this is a new version that I need you to download. It is important that it is saved directly to your desktop**
    1. Please, never rename Combofix unless instructed.
    2. Close any open browsers.
    3. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.
      • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before performing a scan. They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
      • Click on this link to see a list of programs that should be disabled. The list is not all inclusive. If yours is not listed and you don't know how to disable it, please ask.
      NOTE1. If Combofix asks you to install Recovery Console, please allow it.
      NOTE 2. If Combofix asks you to update the program, always do so.
      • Close any open browsers.
      • WARNING: Combofix will disconnect your machine from the Internet as soon as it starts
      • Please do not attempt to re-connect your machine back to the Internet until Combofix has completely finished.
      • If there is no internet connection after running Combofix, then restart your computer to restore back your connection.
    4. Double click on combofix.exe & follow the prompts.
    5. When finished, it will produce a report for you.
    6. Please post the "C:\ComboFix.txt"
    **Note: Do not mouseclick combofix's window while it's running. That may cause it to stall**

    Make sure, you re-enable your security programs, when you're done with Combofix.

    DO NOT make any other changes to your computer (like installing programs, using other cleaning tools, etc.), until it's officially declared clean!!!
     
  7. vunruh

    vunruh TS Rookie Topic Starter Posts: 25

    disabling anti-virus

    I am having trouble disabling the anti-virus we put on (Avira) can you advise me how to get this disabled so that it doesn't conflect with ComboFix.

    Thank you

    Voneta
     
  8. Broni

    Broni Malware Annihilator Posts: 52,895   +344

  9. vunruh

    vunruh TS Rookie Topic Starter Posts: 25

    Thank you for your help. I'll finish last request
     
  10. Broni

    Broni Malware Annihilator Posts: 52,895   +344

    OK :)...............
     
  11. vunruh

    vunruh TS Rookie Topic Starter Posts: 25

    error message

    I know you said not to change the name. I haven't but I keep getting an error message saying I can't save as Combofix(1) so it looks like it is already on my system but I don't see it. I went into control panel to see and delete first one and it's not there. I was just going to delete and start over but now I don't know what to do.

    Sorry I'm feeling so stupid
     
  12. Broni

    Broni Malware Annihilator Posts: 52,895   +344

    That's not your fault. Most likely, some infection is doing it.
    However, I want to see MBRCheck log first.
     
  13. vunruh

    vunruh TS Rookie Topic Starter Posts: 25

    MBRCheck, version 1.2.3
    (c) 2010, AD

    Command-line:
    Windows Version: Windows XP Home Edition
    Windows Information: Service Pack 3 (build 2600)
    Logical Drives Mask: 0x0000007d

    Kernel Drivers (total 132):
    0x804D7000 \WINDOWS\system32\ntoskrnl.exe
    0x806EE000 \WINDOWS\system32\hal.dll
    0xF7D29000 \WINDOWS\system32\KDCOM.DLL
    0xF7C39000 \WINDOWS\system32\BOOTVID.dll
    0xF7829000 tgxi.sys
    0xF77DA000 ACPI.sys
    0xF7D2B000 \WINDOWS\System32\DRIVERS\WMILIB.SYS
    0xF77C9000 pci.sys
    0xF7839000 isapnp.sys
    0xF7D2D000 intelide.sys
    0xF7AA9000 \WINDOWS\System32\DRIVERS\PCIIDEX.SYS
    0xF7849000 MountMgr.sys
    0xF77AA000 ftdisk.sys
    0xF7AB1000 PartMgr.sys
    0xF7859000 VolSnap.sys
    0xF7792000 atapi.sys
    0xF7869000 disk.sys
    0xF7879000 \WINDOWS\System32\DRIVERS\CLASSPNP.SYS
    0xF7772000 fltmgr.sys
    0xF7760000 sr.sys
    0xF7889000 PxHelp20.sys
    0xF7749000 KSecDD.sys
    0xF7736000 WudfPf.sys
    0xF76A9000 Ntfs.sys
    0xF767C000 NDIS.sys
    0xF7662000 Mup.sys
    0xF7899000 agp440.sys
    0xF7A89000 \SystemRoot\System32\DRIVERS\processr.sys
    0xF6E83000 \SystemRoot\System32\DRIVERS\ati2mtaa.sys
    0xF6E6F000 \SystemRoot\System32\DRIVERS\VIDEOPRT.SYS
    0xF7A99000 \SystemRoot\system32\DRIVERS\dlkfet5b.sys
    0xF6DC4000 \SystemRoot\system32\DRIVERS\winachcf.sys
    0xF7B41000 \SystemRoot\System32\Drivers\Modem.SYS
    0xF7B49000 \SystemRoot\System32\DRIVERS\fdc.sys
    0xF78B9000 \SystemRoot\System32\DRIVERS\i8042prt.sys
    0xF7B51000 \SystemRoot\System32\DRIVERS\kbdclass.sys
    0xF78C9000 \SystemRoot\System32\DRIVERS\serial.sys
    0xF7D1D000 \SystemRoot\System32\DRIVERS\serenum.sys
    0xF6DB0000 \SystemRoot\System32\DRIVERS\parport.sys
    0xF78D9000 \SystemRoot\System32\DRIVERS\cdrom.sys
    0xF78E9000 \SystemRoot\System32\DRIVERS\redbook.sys
    0xF6D8D000 \SystemRoot\System32\DRIVERS\ks.sys
    0xF6D7A000 \SystemRoot\System32\Drivers\pwd_2K.SYS
    0xF7B59000 \SystemRoot\system32\drivers\ImapiRox.sys
    0xF7B61000 \SystemRoot\System32\DRIVERS\usbuhci.sys
    0xF6D13000 \SystemRoot\System32\DRIVERS\USBPORT.SYS
    0xF6CFB000 \SystemRoot\system32\drivers\ac97intc.sys
    0xF6CD7000 \SystemRoot\system32\drivers\portcls.sys
    0xF78F9000 \SystemRoot\system32\drivers\drmk.sys
    0xF7E86000 \SystemRoot\System32\DRIVERS\audstub.sys
    0xF7909000 \SystemRoot\System32\DRIVERS\rasl2tp.sys
    0xF762D000 \SystemRoot\System32\DRIVERS\ndistapi.sys
    0xF6CC0000 \SystemRoot\System32\DRIVERS\ndiswan.sys
    0xF7919000 \SystemRoot\System32\DRIVERS\raspppoe.sys
    0xF7929000 \SystemRoot\System32\DRIVERS\raspptp.sys
    0xF7B69000 \SystemRoot\System32\DRIVERS\TDI.SYS
    0xF6CAF000 \SystemRoot\System32\DRIVERS\psched.sys
    0xF7939000 \SystemRoot\System32\DRIVERS\msgpc.sys
    0xF7B79000 \SystemRoot\System32\DRIVERS\ptilink.sys
    0xF7B81000 \SystemRoot\System32\DRIVERS\raspti.sys
    0xF7959000 \SystemRoot\System32\DRIVERS\termdd.sys
    0xF7B89000 \SystemRoot\System32\DRIVERS\mouclass.sys
    0xF7D5D000 \SystemRoot\System32\DRIVERS\swenum.sys
    0xF5EF1000 \SystemRoot\System32\DRIVERS\update.sys
    0xF761D000 \SystemRoot\System32\DRIVERS\mssmbios.sys
    0xF7B91000 \SystemRoot\System32\Drivers\mmc_2K.SYS
    0xF7969000 \SystemRoot\System32\Drivers\NDProxy.SYS
    0xF7999000 \SystemRoot\System32\DRIVERS\usbhub.sys
    0xF7D7F000 \SystemRoot\System32\DRIVERS\USBD.SYS
    0xF7BA1000 \SystemRoot\System32\DRIVERS\flpydisk.sys
    0xF7E38000 \SystemRoot\System32\Drivers\Cdr4_xp.SYS
    0xF7E39000 \SystemRoot\System32\Drivers\Cdralw2k.SYS
    0xF7D81000 \SystemRoot\System32\Drivers\Fs_Rec.SYS
    0xF7E3A000 \SystemRoot\System32\Drivers\Null.SYS
    0xF7D83000 \SystemRoot\System32\Drivers\Beep.SYS
    0xF7BB1000 \SystemRoot\System32\drivers\vga.sys
    0xF7D85000 \SystemRoot\System32\Drivers\mnmdd.SYS
    0xF7D87000 \SystemRoot\System32\DRIVERS\RDPCDD.sys
    0xF2E30000 \SystemRoot\System32\Drivers\cdudf_xp.SYS
    0xF7BB9000 \SystemRoot\System32\Drivers\Msfs.SYS
    0xF7BC1000 \SystemRoot\System32\Drivers\Npfs.SYS
    0xF2DEB000 \SystemRoot\System32\Drivers\UdfReadr_xp.SYS
    0xF6ED8000 \SystemRoot\System32\DRIVERS\rasacd.sys
    0xF2DC6000 \SystemRoot\System32\DRIVERS\ipsec.sys
    0xF2D6D000 \SystemRoot\System32\DRIVERS\tcpip.sys
    0xF2D45000 \SystemRoot\System32\DRIVERS\netbt.sys
    0xF2D23000 \SystemRoot\System32\drivers\afd.sys
    0xF79B9000 \SystemRoot\System32\DRIVERS\netbios.sys
    0xF2D01000 \??\C:\Program Files\SUPERAntiSpyware\SASKUTIL.sys
    0xF7BC9000 \??\C:\Program Files\SUPERAntiSpyware\SASDIFSV.SYS
    0xF2CD6000 \SystemRoot\System32\DRIVERS\rdbss.sys
    0xF2C3E000 \SystemRoot\System32\DRIVERS\mrxsmb.sys
    0xF79C9000 \SystemRoot\System32\Drivers\Fips.SYS
    0xF2C18000 \SystemRoot\System32\DRIVERS\ipnat.sys
    0xF79D9000 \SystemRoot\System32\DRIVERS\wanarp.sys
    0xF7CE9000 \SystemRoot\system32\DRIVERS\KID_USB.sys
    0xF7CED000 \SystemRoot\System32\DRIVERS\hidusb.sys
    0xF79E9000 \SystemRoot\System32\DRIVERS\HIDCLASS.SYS
    0xF7BD9000 \SystemRoot\System32\DRIVERS\HIDPARSE.SYS
    0xF7BE1000 \SystemRoot\system32\DRIVERS\usbccgp.sys
    0xF7A19000 \SystemRoot\System32\Drivers\Cdfs.SYS
    0xF7BF1000 \SystemRoot\system32\DRIVERS\USBSTOR.SYS
    0xF7CF5000 \SystemRoot\System32\DRIVERS\mouhid.sys
    0xF2B5F000 \SystemRoot\system32\DRIVERS\KMW_SYS.sys
    0xF7D91000 \SystemRoot\system32\DRIVERS\KID_LIB.sys
    0xF7CF9000 \SystemRoot\system32\DRIVERS\usbscan.sys
    0xF7BF9000 \SystemRoot\system32\DRIVERS\usbprint.sys
    0xF7C01000 \SystemRoot\system32\DRIVERS\HPZius12.sys
    0xF7A29000 \SystemRoot\system32\DRIVERS\HPZid412.sys
    0xF7D09000 \SystemRoot\system32\DRIVERS\HPZipr12.sys
    0xBF800000 \SystemRoot\System32\win32k.sys
    0xF2EA9000 \SystemRoot\System32\drivers\Dxapi.sys
    0xF7C11000 \SystemRoot\System32\watchdog.sys
    0xBF000000 \SystemRoot\System32\drivers\dxg.sys
    0xF7EC4000 \SystemRoot\System32\drivers\dxgthk.sys
    0xBF012000 \SystemRoot\System32\ati2dvaa.dll
    0xBFFA0000 \SystemRoot\System32\ATMFD.DLL
    0xF1A23000 \SystemRoot\System32\DRIVERS\ndisuio.sys
    0xF186B000 \SystemRoot\System32\Drivers\Fastfat.SYS
    0xF183E000 \SystemRoot\System32\DRIVERS\mrxdav.sys
    0xF7DE7000 \SystemRoot\System32\Drivers\ParVdm.SYS
    0xF7AF1000 \??\C:\WINDOWS\System32\ANIO.SYS
    0xF16F6000 \SystemRoot\System32\DRIVERS\srv.sys
    0xF13E9000 \SystemRoot\system32\drivers\wdmaud.sys
    0xF7949000 \SystemRoot\system32\drivers\sysaudio.sys
    0xF10D2000 \SystemRoot\System32\Drivers\HTTP.sys
    0xF0A11000 \SystemRoot\system32\DRIVERS\avipbb.sys
    0xF7DB7000 \??\C:\Program Files\Avira\AntiVir Desktop\avgio.sys
    0xF09FC000 \SystemRoot\system32\DRIVERS\avgntflt.sys
    0xF096A000 \??\C:\DOCUME~1\Voneta\LOCALS~1\Temp\fxtdapob.sys
    0xF7AE1000 \??\C:\DOCUME~1\Voneta\LOCALS~1\Temp\mbr.sys
    0x7C900000 \WINDOWS\system32\ntdll.dll

    Processes (total 38):
    0 System Idle Process
    4 System
    556 C:\WINDOWS\system32\smss.exe
    620 csrss.exe
    644 C:\WINDOWS\system32\winlogon.exe
    688 C:\WINDOWS\system32\services.exe
    700 C:\WINDOWS\system32\lsass.exe
    856 C:\WINDOWS\system32\svchost.exe
    936 svchost.exe
    1028 C:\WINDOWS\system32\svchost.exe
    1064 C:\WINDOWS\system32\svchost.exe
    1196 svchost.exe
    1236 svchost.exe
    1428 C:\WINDOWS\system32\spoolsv.exe
    1536 svchost.exe
    1608 C:\Program Files\Common Files\Intuit\Update Service\IntuitUpdateService.exe
    1660 C:\Program Files\Java\jre6\bin\jqs.exe
    1696 C:\WINDOWS\system32\HPZipm12.exe
    1796 C:\WINDOWS\system32\svchost.exe
    424 alg.exe
    1496 C:\WINDOWS\explorer.exe
    1940 C:\WINDOWS\system32\exshow95.exe
    1956 C:\Program Files\Hp\HP Software Update\hpwuschd2.exe
    196 C:\Program Files\Common Files\Java\Java Update\jusched.exe
    260 C:\WINDOWS\system32\ctfmon.exe
    1572 C:\Program Files\IObit\Advanced SystemCare 3\AWC.exe
    304 C:\WINDOWS\system32\exshow.exe
    312 C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
    468 C:\Program Files\Hewlett-Packard\AiO\hp psc 700 series\Bin\hpobrt07.exe
    2132 C:\PROGRA~1\HEWLET~1\AiO\Shared\Bin\hpoevm07.exe
    2212 C:\Program Files\Hewlett-Packard\AiO\Shared\Bin\hposts07.exe
    3804 C:\Program Files\Avira\AntiVir Desktop\avguard.exe
    3824 C:\Program Files\Avira\AntiVir Desktop\avshadow.exe
    3932 C:\Program Files\Avira\AntiVir Desktop\sched.exe
    3976 C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
    3084 C:\Program Files\Internet Explorer\iexplore.exe
    3160 C:\Program Files\Internet Explorer\iexplore.exe
    3016 C:\Documents and Settings\Voneta\Local Settings\Temporary Internet Files\Content.IE5\5GS2IW04\MBRCheck[1].exe

    \\.\C: --> \\.\PhysicalDrive0 at offset 0x00000000`00007e00 (NTFS)

    PhysicalDrive0 Model Number: Maxtor6L300R0, Rev: BAJ41G20

    Size Device Name MBR Status
    --------------------------------------------
    279 GB \\.\PhysicalDrive0 Windows XP MBR code detected
    SHA1: DA38B874B7713D1B51CBC449F4EF809B0DEC644A


    Done!
     
  14. Broni

    Broni Malware Annihilator Posts: 52,895   +344

    That looks good :)

    Now...

    Delete your Combofix file, download fresh one, but rename combofix.exe to broni.exe BEFORE saving it to your desktop.
    Do NOT run it yet.

    Please download and run the below tool named Rkill (courtesy of BleepingComputer.com) which may help allow other programs to run.

    There are 4 different versions. If one of them won't run then download and try to run the other one.

    Vista and Win7 users need to right click Rkill and choose Run as Administrator

    You only need to get one of these to run, not all of them. You may get warnings from your antivirus about this tool, ignore them or shutdown your antivirus.

    * Rkill.com
    * Rkill.scr
    * Rkill.pif
    * Rkill.exe


    • * Double-click on the Rkill desktop icon to run the tool.
      * If using Vista or Windows 7 right-click on it and choose Run As Administrator.
      * A black DOS box will briefly flash and then disappear. This is normal and indicates the tool ran successfully.
      * If not, delete the file, then download and use the one provided in Link 2.
      * If it does not work, repeat the process and attempt to use one of the remaining links until the tool runs.
      * Do not reboot until instructed.
      * If the tool does not run from any of the links provided, please let me know.

    Now, run broni.exe
     
  15. vunruh

    vunruh TS Rookie Topic Starter Posts: 25

    I don't think it ever saved it. it didn't ask me anything just told me that I can't save as combofix(1) then I click ok and it's gone. meanwhile I'll down load Rkill.com
     
  16. vunruh

    vunruh TS Rookie Topic Starter Posts: 25

    ok

    I think Rkill worked right. It kinda did it's own thing. It didn't put it on the desktop and I didn't have to do anything and the DDS box popped up and then went to a log. Please advise me to what I need to do to get the combofix working. Should I just try downloading it again?
     
  17. Broni

    Broni Malware Annihilator Posts: 52,895   +344

    Yes....
     
  18. vunruh

    vunruh TS Rookie Topic Starter Posts: 25

    Okay, I have the combofix saved as broni.exe on my desktop now what
     
  19. Broni

    Broni Malware Annihilator Posts: 52,895   +344

    Double click on broni.exe to run it.
     
  20. vunruh

    vunruh TS Rookie Topic Starter Posts: 25

    Combofix Log

    ComboFix 10-11-02.06 - Voneta 11/03/2010 21:33:57.2.1 - x86
    Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.383.212 [GMT -6:00]
    Running from: c:\documents and settings\Voneta\Desktop\broni.exe
    AV: AntiVir Desktop *On-access scanning disabled* (Updated) {AD166499-45F9-482A-A743-FDD3350758C7}
    .

    ((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
    .

    c:\windows\Downloaded Program Files\ODCTOOLS

    .
    ((((((((((((((((((((((((( Files Created from 2010-10-04 to 2010-11-04 )))))))))))))))))))))))))))))))
    .

    2010-11-04 02:11 . 2010-11-04 02:11 -------- d-----w- c:\documents and settings\Voneta\Application Data\Avira
    2010-11-03 23:37 . 2010-11-03 23:37 -------- d-sh--w- c:\documents and settings\LocalService\IETldCache
    2010-11-03 23:35 . 2010-08-02 22:10 60936 ----a-w- c:\windows\system32\drivers\avgntflt.sys
    2010-11-03 23:35 . 2010-08-02 22:10 126856 ----a-w- c:\windows\system32\drivers\avipbb.sys
    2010-11-03 23:35 . 2010-06-17 21:27 45416 ----a-w- c:\windows\system32\drivers\avgntdd.sys
    2010-11-03 23:35 . 2010-06-17 21:27 22360 ----a-w- c:\windows\system32\drivers\avgntmgr.sys
    2010-11-03 23:35 . 2010-11-03 23:35 -------- d-----w- c:\program files\Avira
    2010-11-03 23:35 . 2010-11-03 23:35 -------- d-----w- c:\documents and settings\All Users\Application Data\Avira
    2010-11-03 23:12 . 2010-11-03 23:12 -------- d-----w- c:\documents and settings\Voneta\Application Data\Malwarebytes
    2010-11-03 23:12 . 2010-04-29 21:39 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
    2010-11-03 23:12 . 2010-11-03 23:12 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
    2010-11-03 23:12 . 2010-04-29 21:39 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
    2010-11-03 23:12 . 2010-11-03 23:25 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
    2010-11-03 15:50 . 2010-11-03 15:50 -------- d-----w- c:\documents and settings\Voneta\Application Data\Registry Mechanic
    2010-11-03 15:47 . 2010-11-03 21:44 -------- d---a-w- c:\documents and settings\All Users\Application Data\TEMP
    2010-10-29 22:17 . 2010-10-29 22:17 -------- d-----w- c:\program files\Conduit
    2010-10-29 22:17 . 2010-10-29 22:17 -------- d-----w- c:\documents and settings\Voneta\Local Settings\Application Data\Conduit
    2010-10-29 22:17 . 2010-10-29 22:17 -------- d-----w- c:\documents and settings\Voneta\Local Settings\Application Data\Online_Radio_1.1
    2010-10-29 22:17 . 2010-10-29 22:17 -------- d-----w- c:\program files\Online_Radio_1.1
    2010-10-29 22:17 . 2010-10-29 22:17 -------- d-----w- c:\documents and settings\Voneta\Local Settings\Application Data\Temp
    2010-10-14 23:20 . 2010-09-18 06:53 974848 -c----w- c:\windows\system32\dllcache\mfc42.dll
    2010-10-14 23:20 . 2010-09-18 06:53 953856 -c----w- c:\windows\system32\dllcache\mfc40u.dll
    2010-10-14 23:20 . 2010-08-23 16:12 617472 -c----w- c:\windows\system32\dllcache\comctl32.dll

    .
    (((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    2010-11-04 03:21 . 2007-05-24 16:11 7304 ----a-w- c:\windows\TMP0001.TMP
    2010-09-18 18:23 . 2001-08-18 12:00 974848 ----a-w- c:\windows\system32\mfc42u.dll
    2010-09-18 06:53 . 2001-08-18 12:00 974848 ----a-w- c:\windows\system32\mfc42.dll
    2010-09-18 06:53 . 2001-08-18 12:00 954368 ----a-w- c:\windows\system32\mfc40.dll
    2010-09-18 06:53 . 2001-08-18 12:00 953856 ----a-w- c:\windows\system32\mfc40u.dll
    2010-09-10 05:58 . 2004-01-08 21:23 916480 ----a-w- c:\windows\system32\wininet.dll
    2010-09-10 05:58 . 2001-08-18 12:00 43520 ----a-w- c:\windows\system32\licmgr10.dll
    2010-09-10 05:58 . 2001-08-18 12:00 1469440 ------w- c:\windows\system32\inetcpl.cpl
    2010-09-01 11:51 . 2001-08-18 12:00 285824 ----a-w- c:\windows\system32\atmfd.dll
    2010-08-31 13:42 . 2001-08-18 12:00 1852800 ----a-w- c:\windows\system32\win32k.sys
    2010-08-27 08:02 . 2001-08-18 12:00 119808 ----a-w- c:\windows\system32\t2embed.dll
    2010-08-27 05:57 . 2001-08-18 12:00 99840 ----a-w- c:\windows\system32\srvsvc.dll
    2010-08-26 13:39 . 2001-08-18 12:00 357248 ----a-w- c:\windows\system32\drivers\srv.sys
    2010-08-26 12:52 . 2009-04-15 03:41 5120 ----a-w- c:\windows\system32\xpsp4res.dll
    2010-08-23 16:12 . 2001-08-18 12:00 617472 ----a-w- c:\windows\system32\comctl32.dll
    2010-08-17 13:17 . 2001-08-18 12:00 58880 ----a-w- c:\windows\system32\spoolsv.exe
    2010-08-16 08:45 . 2006-07-17 20:42 590848 ----a-w- c:\windows\system32\rpcrt4.dll
    .

    ((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    *Note* empty entries & legit default entries are not shown
    REGEDIT4

    [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
    "{343db173-0e5a-4f2a-b7bb-71a49085d70e}"= "c:\program files\Online_Radio_1.1\tbOnli.dll" [2010-10-18 3908192]

    [HKEY_CLASSES_ROOT\clsid\{343db173-0e5a-4f2a-b7bb-71a49085d70e}]

    [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{30F9B915-B755-4826-820B-08FBA6BD249D}]
    2010-10-18 18:26 3908192 ----a-w- c:\program files\ConduitEngine\ConduitEngine.dll

    [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{343db173-0e5a-4f2a-b7bb-71a49085d70e}]
    2010-10-18 18:26 3908192 ----a-w- c:\program files\Online_Radio_1.1\tbOnli.dll

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
    "{343db173-0e5a-4f2a-b7bb-71a49085d70e}"= "c:\program files\Online_Radio_1.1\tbOnli.dll" [2010-10-18 3908192]
    "{30F9B915-B755-4826-820B-08FBA6BD249D}"= "c:\program files\ConduitEngine\ConduitEngine.dll" [2010-10-18 3908192]

    [HKEY_CLASSES_ROOT\clsid\{343db173-0e5a-4f2a-b7bb-71a49085d70e}]

    [HKEY_CLASSES_ROOT\clsid\{30f9b915-b755-4826-820b-08fba6bd249d}]

    [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
    "{343DB173-0E5A-4F2A-B7BB-71A49085D70E}"= "c:\program files\Online_Radio_1.1\tbOnli.dll" [2010-10-18 3908192]

    [HKEY_CLASSES_ROOT\clsid\{343db173-0e5a-4f2a-b7bb-71a49085d70e}]

    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "Advanced SystemCare 3"="c:\program files\IObit\Advanced SystemCare 3\AWC.exe" [2010-09-29 2407632]
    "swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-01-27 39408]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "EXSHOW95.EXE"="EXSHOW95.EXE" [2001-09-07 45056]
    "HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2010-03-12 49208]
    "QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2007-11-14 286720]
    "SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-05-14 248552]
    "avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2010-08-02 281768]

    c:\documents and settings\All Users\Start Menu\Programs\Startup\
    HPAiODevice(hp psc 700 series) - 1.lnk - c:\program files\Hewlett-Packard\AiO\hp psc 700 series\Bin\hpobrt07.exe [2002-4-30 487484]
    Microsoft Office.lnk - c:\program files\Microsoft Office\Office\OSA9.EXE [1999-2-17 65588]

    [hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
    "{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]

    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
    2009-09-03 21:21 548352 ----a-w- c:\program files\SUPERAntiSpyware\SASWINLO.dll

    [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
    path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk
    backup=c:\windows\pss\Adobe Reader Speed Launch.lnkCommon Startup

    [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk]
    path=c:\documents and settings\All Users\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk
    backup=c:\windows\pss\HP Digital Imaging Monitor.lnkCommon Startup

    [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HP Photosmart Premier Fast Start.lnk]
    path=c:\documents and settings\All Users\Start Menu\Programs\Startup\HP Photosmart Premier Fast Start.lnk
    backup=c:\windows\pss\HP Photosmart Premier Fast Start.lnkCommon Startup

    [HKLM\~\startupfolder\C:^Documents and Settings^Voneta^Start Menu^Programs^Startup^MEMonitor.lnk]
    path=c:\documents and settings\Voneta\Start Menu\Programs\Startup\MEMonitor.lnk
    backup=c:\windows\pss\MEMonitor.lnkStartup

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AdaptecDirectCD]
    2001-09-04 21:31 655360 ----a-w- c:\program files\Adaptec\Easy CD Creator 5\DirectCD\Directcd.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
    2010-09-21 05:07 932288 ----a-r- c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Photo Downloader]
    2005-06-07 05:46 57344 ----a-w- c:\program files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
    2010-09-23 10:47 35760 ----a-w- c:\program files\Adobe\Reader 9.0\Reader\reader_sl.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ANIWZCS2Service]
    2004-10-22 19:42 45056 ----a-w- c:\program files\ANI\ANIWZCS2 Service\WZCSLDR2.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\D-Link AirPlus G]
    2004-11-19 15:15 1216512 ----a-w- c:\program files\D-Link\AirPlus G\AirGCFG.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DW6]
    2008-06-10 22:18 785520 ----a-w- c:\program files\The Weather Channel FW\Desktop\DesktopWeather.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
    2008-04-14 00:12 1695232 ----a-w- c:\program files\Messenger\msmsgs.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Performance Center]
    2008-04-29 19:14 3239936 ----a-w- c:\program files\Ascentive\Performance Center\ApcMain.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
    2007-11-14 01:17 286720 ----a-w- c:\program files\QuickTime\qttask.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SUPERAntiSpyware]
    2010-11-03 22:09 2424560 ----a-w- c:\program files\SUPERAntiSpyware\SUPERANTISPYWARE.EXE

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg]
    2009-01-27 04:59 39408 ----a-w- c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
    "Viewpoint Manager Service"=2 (0x2)

    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
    "%windir%\\system32\\sessmgr.exe"=
    "c:\\Program Files\\Hp\\Digital Imaging\\bin\\hpqtra08.exe"=
    "c:\\Program Files\\Hp\\Digital Imaging\\bin\\hpqste08.exe"=
    "c:\\Program Files\\Hp\\Digital Imaging\\bin\\hpofxm08.exe"=
    "c:\\Program Files\\Hp\\Digital Imaging\\bin\\hposfx08.exe"=
    "c:\\Program Files\\Hp\\Digital Imaging\\bin\\hposid01.exe"=
    "c:\\Program Files\\Hp\\Digital Imaging\\bin\\hpqscnvw.exe"=
    "c:\\Program Files\\Hp\\Digital Imaging\\bin\\hpqkygrp.exe"=
    "c:\\Program Files\\Hp\\Digital Imaging\\bin\\hpqCopy.exe"=
    "c:\\Program Files\\Hp\\Digital Imaging\\bin\\hpfccopy.exe"=
    "c:\\Program Files\\Hp\\Digital Imaging\\bin\\hpzwiz01.exe"=
    "c:\\Program Files\\Hp\\Digital Imaging\\Unload\\HpqPhUnl.exe"=
    "c:\\Program Files\\Hp\\Digital Imaging\\Unload\\HpqDIA.exe"=
    "c:\\Program Files\\Hp\\Digital Imaging\\bin\\hpoews01.exe"=
    "c:\\Program Files\\Hp\\Digital Imaging\\bin\\hpqnrs08.exe"=
    "%windir%\\Network Diagnostic\\xpnetdiag.exe"=

    R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\SASDIFSV.SYS [1/5/2010 8:56 AM 12872]
    R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [1/5/2010 8:56 AM 67656]
    R2 AntiVirSchedulerService;Avira AntiVir Scheduler;c:\program files\Avira\AntiVir Desktop\sched.exe [11/3/2010 5:35 PM 135336]
    R3 KID_USB;Kensington Input Devices USB filter driver;c:\windows\system32\drivers\KID_USB.sys [9/5/2001 11:42 AM 16344]
    S3 SASENUM;SASENUM;c:\program files\SUPERAntiSpyware\SASENUM.SYS [1/5/2010 8:56 AM 12872]
    S4 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\Viewpoint\Common\ViewpointService.exe [1/10/2007 11:02 PM 24652]

    --- Other Services/Drivers In Memory ---

    *NewlyCreated* - SSMDRV

    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
    getPlusHelper REG_MULTI_SZ getPlusHelper
    .
    Contents of the 'Scheduled Tasks' folder

    2010-01-25 c:\windows\Tasks\SmartDefrag.job
    - c:\program files\IObit\IObit SmartDefrag\IObit SmartDefrag.exe [2010-01-25 22:30]
    .
    .
    ------- Supplementary Scan -------
    .
    uStart Page = hxxp://www.comcast.net/
    mSearch Bar = hxxp://www.google.com
    uInternet Settings,ProxyOverride = 127.0.0.1
    uSearchAssistant = hxxp://www.google.com/ie
    uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
    Trusted Zone: intuit.com\ttlc
    Trusted Zone: turbotax.com
    TCP: {96F34F16-9EB1-4B98-B092-5AD6678002A4} = 68.8.69.146,68.87.85.98
    DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
    .
    - - - - ORPHANS REMOVED - - - -

    Toolbar-{F6510A6A-1962-4548-9454-38C4D4E54FCA} - (no file)
    WebBrowser-{F6510A6A-1962-4548-9454-38C4D4E54FCA} - (no file)
    WebBrowser-{D4027C7F-154A-4066-A1AD-4243D8127440} - (no file)
    SafeBoot-mcmscsvc
    SafeBoot-MCODS
    MSConfigStartUp-CTSyncU - c:\program files\Creative\Sync Manager Unicode\CTSyncU.exe
    MSConfigStartUp-DealAssistant - c:\documents and settings\Voneta\Application Data\DealAssistant\dealassistant.exe
    MSConfigStartUp-iTunesHelper - c:\program files\iTunes\iTunesHelper.exe
    MSConfigStartUp-SfKg6wIPuSpdcduD7 - c:\documents and settings\Voneta\Application Data\Microsoft\Windows\pmmwmf.exe
    MSConfigStartUp-SunJavaUpdateSched - c:\program files\Java\jre1.6.0_03\bin\jusched.exe



    **************************************************************************

    catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
    Rootkit scan 2010-11-03 21:42
    Windows 5.1.2600 Service Pack 3 NTFS

    scanning hidden processes ...

    scanning hidden autostart entries ...

    scanning hidden files ...

    scan completed successfully
    hidden files: 0

    **************************************************************************
    .
    --------------------- LOCKED REGISTRY KEYS ---------------------

    [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
    @Denied: (A 2) (Everyone)
    @="FlashBroker"
    "LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10k_ActiveX.exe,-101"

    [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
    "Enabled"=dword:00000001

    [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
    @="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10k_ActiveX.exe"

    [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
    @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"

    [HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
    @Denied: (A 2) (Everyone)
    @="IFlashBroker4"

    [HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
    @="{00020424-0000-0000-C000-000000000046}"

    [HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
    @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
    "Version"="1.0"
    .
    --------------------- DLLs Loaded Under Running Processes ---------------------

    - - - - - - - > 'winlogon.exe'(644)
    c:\program files\SUPERAntiSpyware\SASWINLO.dll
    c:\windows\system32\WININET.dll

    - - - - - - - > 'explorer.exe'(3388)
    c:\windows\system32\WININET.dll
    c:\windows\system32\SHW95DLL.DLL
    c:\windows\system32\WOW32.dll
    c:\windows\system32\ieframe.dll
    c:\windows\system32\webcheck.dll
    c:\windows\system32\WPDShServiceObj.dll
    c:\windows\system32\PortableDeviceTypes.dll
    c:\windows\system32\PortableDeviceApi.dll
    .
    Completion time: 2010-11-03 21:46:02
    ComboFix-quarantined-files.txt 2010-11-04 03:45

    Pre-Run: 121,212,678,144 bytes free
    Post-Run: 121,435,422,720 bytes free
     
  21. vunruh

    vunruh TS Rookie Topic Starter Posts: 25

    I'll catch up with you tomorrow. I'm computered out and need to go to bed.

    Thank you for all your help today.
    Voneta
     
  22. Broni

    Broni Malware Annihilator Posts: 52,895   +344

    It looks good :)

    Unless you installed Viewpoint Manager knowledgeably...
    Go Start>Control Panel>Add\Remove (Programs and Features in Vista), and...
    Uninstall any of the following programs associated with Viewpoint:
    * Viewpoint Manager
    * Viewpoint Media Player
    * Viewpoint Toolbar
    This program does not do anything bad such as deliver ads or spy on you, but it is considered foistware ("drive-by-install") as it is installed without your consent through programs like AOL, AIM, Compuserve, etc.

    ==============================================================

    Download OTL to your Desktop.

    • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
    • Under the Custom Scan box paste this in:


    netsvcs
    drivers32
    %SYSTEMDRIVE%\*.*
    %systemroot%\Fonts\*.com
    %systemroot%\Fonts\*.dll
    %systemroot%\Fonts\*.ini
    %systemroot%\Fonts\*.ini2
    %systemroot%\Fonts\*.exe
    %systemroot%\system32\spool\prtprocs\w32x86\*.*
    %systemroot%\REPAIR\*.bak1
    %systemroot%\REPAIR\*.ini
    %systemroot%\system32\*.jpg
    %systemroot%\*.jpg
    %systemroot%\*.png
    %systemroot%\*.scr
    %systemroot%\*._sy
    %APPDATA%\Adobe\Update\*.*
    %ALLUSERSPROFILE%\Favorites\*.*
    %APPDATA%\Microsoft\*.*
    %PROGRAMFILES%\*.*
    %APPDATA%\Update\*.*
    %systemroot%\*. /mp /s
    CREATERESTOREPOINT
    %systemroot%\System32\config\*.sav
    %PROGRAMFILES%\bak. /s
    %systemroot%\system32\bak. /s
    %ALLUSERSPROFILE%\Start Menu\*.lnk /x
    %systemroot%\system32\config\systemprofile\*.dat /x
    %systemroot%\*.config
    %systemroot%\system32\*.db
    %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x
    %USERPROFILE%\Desktop\*.exe
    %PROGRAMFILES%\Common Files\*.*
    %systemroot%\*.src
    %systemroot%\install\*.*
    %systemroot%\system32\DLL\*.*
    %systemroot%\system32\HelpFiles\*.*
    %systemroot%\system32\rundll\*.*
    %systemroot%\winn32\*.*
    %systemroot%\Java\*.*
    %systemroot%\system32\test\*.*
    %systemroot%\system32\Rundll32\*.*
    %systemroot%\AppPatch\Custom\*.*
    %APPDATA%\Roaming\Microsoft\Windows\Recent\*.lnk /x
    %PROGRAMFILES%\PC-Doctor\Downloads\*.*
    %PROGRAMFILES%\Internet Explorer\*.tmp
    %PROGRAMFILES%\Internet Explorer\*.dat
    %USERPROFILE%\My Documents\*.exe
    %USERPROFILE%\*.exe
    %systemroot%\ADDINS\*.*
    %systemroot%\assembly\*.bak2
    %systemroot%\Config\*.*
    %systemroot%\REPAIR\*.bak2
    %systemroot%\SECURITY\Database\*.sdb /x
    %systemroot%\SYSTEM\*.bak2
    %systemroot%\Web\*.bak2
    %systemroot%\Driver Cache\*.*
    %PROGRAMFILES%\Mozilla Firefox\0*.exe
    %ProgramFiles%\Microsoft Common\*.*
    %ProgramFiles%\TinyProxy.
    %USERPROFILE%\Favorites\*.url /x
    %systemroot%\system32\*.bk
    %systemroot%\*.te
    %systemroot%\system32\system32\*.*
    %ALLUSERSPROFILE%\*.dat /x
    %systemroot%\system32\drivers\*.rmv
    dir /b "%systemroot%\system32\*.exe" | find /i " " /c
    dir /b "%systemroot%\*.exe" | find /i " " /c
    %PROGRAMFILES%\Microsoft\*.*
    %systemroot%\System32\Wbem\proquota.exe
    %PROGRAMFILES%\Mozilla Firefox\*.dat
    %USERPROFILE%\Cookies\*.txt /x
    %SystemRoot%\system32\fonts\*.*
    %systemroot%\system32\winlog\*.*
    %systemroot%\system32\Language\*.*
    %systemroot%\system32\Settings\*.*
    %systemroot%\system32\*.quo
    %SYSTEMROOT%\AppPatch\*.exe
    %SYSTEMROOT%\inf\*.exe
    %SYSTEMROOT%\Installer\*.exe
    %systemroot%\system32\config\*.bak2
    %systemroot%\system32\Computers\*.*
    %SystemRoot%\system32\Sound\*.*
    %SystemRoot%\system32\SpecialImg\*.*
    %SystemRoot%\system32\code\*.*
    %SystemRoot%\system32\draft\*.*
    %SystemRoot%\system32\MSSSys\*.*
    %ProgramFiles%\Javascript\*.*
    %systemroot%\pchealth\helpctr\System\*.exe /s
    %systemroot%\Web\*.exe
    %systemroot%\system32\msn\*.*
    %systemroot%\system32\*.tro
    %AppData%\Microsoft\Installer\msupdates\*.*
    %ProgramFiles%\Messenger\*.*
    %systemroot%\system32\systhem32\*.*
    %systemroot%\system\*.exe
    HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs
    /md5start
    /md5stop


    • Click the Quick Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
    • When the scan completes, it will open two notepad windows: OTL.txt and Extras.txt. These are saved in the same location as OTL.
    • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post them back here.
     
  23. vunruh

    vunruh TS Rookie Topic Starter Posts: 25

    OTL Logs

    OTL logfile created on: 11/3/2010 10:01:58 PM - Run 1
    OTL by OldTimer - Version 3.2.17.2 Folder = C:\Documents and Settings\Voneta\Desktop
    Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
    Internet Explorer (Version = 8.0.6001.18702)
    Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

    383.00 Mb Total Physical Memory | 118.00 Mb Available Physical Memory | 31.00% Memory free
    920.00 Mb Paging File | 475.00 Mb Available in Paging File | 52.00% Paging File free
    Paging file location(s): C:\pagefile.sys 576 1152 [binary data]

    %SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
    Drive C: | 127.99 Gb Total Space | 113.12 Gb Free Space | 88.38% Space Free | Partition Type: NTFS
    Drive F: | 244.63 Mb Total Space | 236.19 Mb Free Space | 96.55% Space Free | Partition Type: FAT

    Computer Name: UNRUH | User Name: Voneta | Logged in as Administrator.
    Boot Mode: Normal | Scan Mode: Current user | Quick Scan
    Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days

    ========== Processes (SafeList) ==========

    PRC - [2010/11/03 22:00:43 | 000,576,000 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Voneta\Desktop\OTL.exe
    PRC - [2010/09/28 21:33:02 | 002,407,632 | ---- | M] (IObit) -- C:\Program Files\IObit\Advanced SystemCare 3\AWC.exe
    PRC - [2010/08/02 16:10:00 | 000,135,336 | ---- | M] (Avira GmbH) -- C:\Program Files\Avira\AntiVir Desktop\sched.exe
    PRC - [2010/08/02 16:09:55 | 000,281,768 | ---- | M] (Avira GmbH) -- C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
    PRC - [2010/08/02 16:09:55 | 000,267,944 | ---- | M] (Avira GmbH) -- C:\Program Files\Avira\AntiVir Desktop\avguard.exe
    PRC - [2010/01/14 22:11:00 | 000,076,968 | ---- | M] (Avira GmbH) -- C:\Program Files\Avira\AntiVir Desktop\avshadow.exe
    PRC - [2009/09/29 10:17:50 | 000,013,088 | ---- | M] (Intuit Inc.) -- C:\Program Files\Common Files\Intuit\Update Service\IntuitUpdateService.exe
    PRC - [2009/01/26 22:59:08 | 000,039,408 | ---- | M] (Google Inc.) -- C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
    PRC - [2008/04/13 18:12:19 | 001,033,728 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe
    PRC - [2007/08/09 01:27:52 | 000,073,728 | ---- | M] (HP) -- C:\WINDOWS\system32\HPZipm12.exe
    PRC - [2002/04/30 18:59:48 | 000,290,816 | ---- | M] (Hewlett-Packard Co.) -- C:\Program Files\Hewlett-Packard\AiO\Shared\Bin\hposts07.exe
    PRC - [2002/04/30 18:46:44 | 000,299,008 | ---- | M] (Hewlett-Packard Co.) -- C:\Program Files\Hewlett-Packard\AiO\Shared\Bin\hpoevm07.exe
    PRC - [2002/04/30 18:26:44 | 000,487,484 | ---- | M] (Hewlett-Packard Co.) -- C:\Program Files\Hewlett-Packard\AiO\hp psc 700 series\Bin\hpobrt07.exe
    PRC - [2001/09/07 16:18:28 | 000,045,056 | ---- | M] (Kensington Technology Group) -- C:\WINDOWS\system32\exshow95.exe
    PRC - [2001/09/07 16:17:52 | 000,376,832 | ---- | M] (Kensington Technology Group) -- C:\WINDOWS\system32\exshow.exe


    ========== Modules (SafeList) ==========

    MOD - [2010/11/03 22:00:43 | 000,576,000 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Voneta\Desktop\OTL.exe
    MOD - [2010/08/23 10:12:02 | 001,054,208 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.6028_x-ww_61e65202\comctl32.dll
    MOD - [2008/04/13 18:12:30 | 000,420,864 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\ntvdm.exe
    MOD - [2008/04/13 18:12:10 | 000,264,192 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\wow32.dll
    MOD - [2001/09/07 16:22:30 | 000,122,880 | ---- | M] (Kensington Technology Group) -- C:\WINDOWS\system32\shw95dll.dll
    MOD - [2001/08/18 06:00:00 | 000,052,224 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\tsappcmp.dll


    ========== Win32 Services (SafeList) ==========

    SRV - File not found [Disabled | Stopped] -- C:\WINDOWS\System32\hidserv.dll -- (HidServ)
    SRV - File not found [On_Demand | Stopped] -- C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe -- (gusvc)
    SRV - File not found [On_Demand | Stopped] -- C:\WINDOWS\System32\appmgmts.dll -- (AppMgmt)
    SRV - [2010/08/02 16:10:00 | 000,135,336 | ---- | M] (Avira GmbH) [Auto | Running] -- C:\Program Files\Avira\AntiVir Desktop\sched.exe -- (AntiVirSchedulerService)
    SRV - [2010/08/02 16:09:55 | 000,267,944 | ---- | M] (Avira GmbH) [Auto | Running] -- C:\Program Files\Avira\AntiVir Desktop\avguard.exe -- (AntiVirService)
    SRV - [2010/03/29 08:51:54 | 000,068,000 | ---- | M] (NOS Microsystems Ltd.) [On_Demand | Stopped] -- C:\Program Files\NOS\bin\getPlus_Helper.dll -- (getPlusHelper) getPlus(R)
    SRV - [2009/09/29 10:17:50 | 000,013,088 | ---- | M] (Intuit Inc.) [Auto | Running] -- C:\Program Files\Common Files\Intuit\Update Service\IntuitUpdateService.exe -- (IntuitUpdateService)
    SRV - [2007/08/09 01:27:52 | 000,073,728 | ---- | M] (HP) [Auto | Running] -- C:\WINDOWS\system32\HPZipm12.exe -- (Pml Driver HPZ12)
    SRV - [2007/01/04 15:38:08 | 000,024,652 | ---- | M] (Viewpoint Corporation) [Disabled | Stopped] -- C:\Program Files\Viewpoint\Common\ViewpointService.exe -- (Viewpoint Manager Service)
    SRV - [2004/10/22 13:42:44 | 000,049,152 | ---- | M] (Alpha Networks Inc.) [Auto | Stopped] -- C:\Program Files\ANI\ANIWZCS2 Service\ANIWZCSdS.exe -- (ANIWZCSdService)


    ========== Driver Services (SafeList) ==========

    DRV - File not found [Kernel | On_Demand | Running] -- C:\DOCUME~1\Voneta\LOCALS~1\Temp\catchme.sys -- (catchme)
    DRV - [2010/08/02 16:10:08 | 000,126,856 | ---- | M] (Avira GmbH) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\avipbb.sys -- (avipbb)
    DRV - [2010/08/02 16:10:08 | 000,060,936 | ---- | M] (Avira GmbH) [File_System | Auto | Running] -- C:\WINDOWS\system32\drivers\avgntflt.sys -- (avgntflt)
    DRV - [2010/06/17 15:27:22 | 000,028,520 | ---- | M] (Avira GmbH) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\ssmdrv.sys -- (ssmdrv)
    DRV - [2010/06/17 15:27:12 | 000,011,608 | ---- | M] (Avira GmbH) [Kernel | System | Running] -- C:\Program Files\Avira\AntiVir Desktop\avgio.sys -- (avgio)
    DRV - [2010/06/07 11:11:07 | 000,067,656 | ---- | M] (SUPERAdBlocker.com and SUPERAntiSpyware.com) [Kernel | System | Running] -- C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS -- (SASKUTIL)
    DRV - [2010/02/19 15:33:38 | 000,012,872 | ---- | M] (SUPERAdBlocker.com and SUPERAntiSpyware.com) [Kernel | System | Running] -- C:\Program Files\SUPERAntiSpyware\SASDIFSV.SYS -- (SASDIFSV)
    DRV - [2010/02/19 15:33:38 | 000,012,872 | ---- | M] ( SUPERAdBlocker.com and SUPERAntiSpyware.com) [Kernel | On_Demand | Stopped] -- C:\Program Files\SUPERAntiSpyware\SASENUM.SYS -- (SASENUM)
    DRV - [2007/04/09 10:56:22 | 000,021,248 | ---- | M] (LG Electronics Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\lgusbdiag.sys -- (UsbDiag)
    DRV - [2007/04/09 10:55:08 | 000,022,912 | ---- | M] (LG Electronics Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\lgusbmodem.sys -- (USBModem)
    DRV - [2007/04/09 10:53:24 | 000,012,672 | ---- | M] (LG Electronics Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\lgusbbus.sys -- (usbbus)
    DRV - [2005/08/19 04:00:00 | 000,002,560 | ---- | M] (Sonic Solutions) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\cdralw2k.sys -- (Cdralw2k)
    DRV - [2005/08/19 04:00:00 | 000,002,432 | ---- | M] (Sonic Solutions) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\cdr4_xp.sys -- (Cdr4_xp)
    DRV - [2004/12/01 19:33:00 | 000,043,008 | R--- | M] (D-Link ) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\dlkfet5b.sys -- (FETNDISB)
    DRV - [2004/08/05 13:25:38 | 000,381,312 | ---- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\PRISMA02.sys -- (PRISM_A02) D-Link Wireless 802.11b/g Driver (USB)
    DRV - [2004/07/27 11:20:46 | 000,028,205 | ---- | M] (Alpha Networks Inc.) [Kernel | Auto | Running] -- C:\WINDOWS\system32\ANIO.sys -- (ANIO)
    DRV - [2004/03/26 13:08:54 | 000,122,112 | ---- | M] (Cisco-Linksys LLC.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\vnet58lx.sys -- (FVNETusb)
    DRV - [2002/01/11 00:22:10 | 000,295,168 | ---- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\ati2mtaa.sys -- (ati2mtaa)
    DRV - [2001/09/10 10:43:46 | 000,205,824 | ---- | M] (Roxio) [File_System | System | Running] -- C:\WINDOWS\System32\drivers\udfreadr_xp.sys -- (UdfReadr_xp)
    DRV - [2001/09/07 17:10:02 | 000,158,872 | ---- | M] (Kensington Technology Group) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\KMW_SYS.sys -- (KMW_SYS)
    DRV - [2001/09/05 11:42:14 | 000,016,344 | ---- | M] (Kensington Technology Group) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\KID_USB.sys -- (KID_USB)
    DRV - [2001/09/04 16:37:08 | 000,233,344 | ---- | M] (Roxio) [File_System | System | Running] -- C:\WINDOWS\System32\drivers\cdudf_xp.sys -- (cdudf_xp)
    DRV - [2001/09/04 15:39:50 | 000,017,990 | ---- | M] (Roxio) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\System32\drivers\Dvd_2k.sys -- (dvd_2K)
    DRV - [2001/09/04 15:39:40 | 000,019,702 | ---- | M] (Roxio) [Kernel | On_Demand | Running] -- C:\WINDOWS\System32\drivers\Mmc_2k.sys -- (mmc_2K)
    DRV - [2001/09/04 15:39:28 | 000,078,454 | ---- | M] (Roxio) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\pwd_2K.sys -- (pwd_2K)
    DRV - [2001/08/20 11:59:38 | 000,025,472 | ---- | M] (Roxio Inc.) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\imapiRox.sys -- (Imapi)
    DRV - [2001/08/17 07:28:02 | 000,907,456 | ---- | M] (Conexant) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\HCF_MSFT.sys -- (HCF_MSFT)
    DRV - [2001/08/17 06:48:52 | 000,281,856 | ---- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ati2mpaa.sys -- (ati2mpaa)
    DRV - [2001/08/17 06:20:04 | 000,096,256 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\ac97intc.sys -- (ac97intc) Intel(r) 82801 Audio Driver Install Service (WDM)
    DRV - [2001/08/13 17:17:34 | 000,737,973 | ---- | M] (Conexant) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\winachcf.sys -- (Winachcf)


    ========== Standard Registry (SafeList) ==========


    ========== Internet Explorer ==========

    IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie

    IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.comcast.net/
    IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie
    IE - HKCU\..\URLSearchHook: {343db173-0e5a-4f2a-b7bb-71a49085d70e} - C:\Program Files\Online_Radio_1.1\tbOnli.dll (Conduit Ltd.)
    IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
    IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = 127.0.0.1


    [2009/04/05 21:11:42 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Voneta\Application Data\Mozilla\Extensions
    [2009/04/05 21:11:42 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Voneta\Application Data\Mozilla\Extensions\mozswing@mozswing.org

    O1 HOSTS File: ([2001/08/18 06:00:00 | 000,000,734 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
    O1 - Hosts: 127.0.0.1 localhost
    O2 - BHO: (Conduit Engine) - {30F9B915-B755-4826-820B-08FBA6BD249D} - C:\Program Files\ConduitEngine\ConduitEngine.dll (Conduit Ltd.)
    O2 - BHO: (Online Radio 1.1 Toolbar) - {343db173-0e5a-4f2a-b7bb-71a49085d70e} - C:\Program Files\Online_Radio_1.1\tbOnli.dll (Conduit Ltd.)
    O2 - BHO: (TwcToolbarBhoApp Class) - {AA1F9DDB-E605-4ba6-81D4-E427DEE012AD} - C:\WINDOWS\system32\TwcToolbarBho.dll ()
    O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.6.5612.1312\swg.dll (Google Inc.)
    O3 - HKLM\..\Toolbar: (The Weather Channel Toolbar) - {2E5E800E-6AC0-411E-940A-369530A35E43} - C:\WINDOWS\system32\TwcToolbarIe7.dll ()
    O3 - HKLM\..\Toolbar: (Conduit Engine) - {30F9B915-B755-4826-820B-08FBA6BD249D} - C:\Program Files\ConduitEngine\ConduitEngine.dll (Conduit Ltd.)
    O3 - HKLM\..\Toolbar: (Online Radio 1.1 Toolbar) - {343db173-0e5a-4f2a-b7bb-71a49085d70e} - C:\Program Files\Online_Radio_1.1\tbOnli.dll (Conduit Ltd.)
    O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No CLSID value found.
    O3 - HKCU\..\Toolbar\WebBrowser: (Online Radio 1.1 Toolbar) - {343DB173-0E5A-4F2A-B7BB-71A49085D70E} - C:\Program Files\Online_Radio_1.1\tbOnli.dll (Conduit Ltd.)
    O4 - HKLM..\Run: [avgnt] C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Avira GmbH)
    O4 - HKLM..\Run: [EXSHOW95.EXE] C:\WINDOWS\System32\exshow95.exe (Kensington Technology Group)
    O4 - HKCU..\Run: [Advanced SystemCare 3] C:\Program Files\IObit\Advanced SystemCare 3\AWC.exe (IObit)
    O4 - HKCU..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.)
    O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\HPAiODevice(hp psc 700 series) - 1.lnk = C:\Program Files\Hewlett-Packard\AiO\hp psc 700 series\Bin\hpobrt07.exe (Hewlett-Packard Co.)
    O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE (Microsoft Corporation)
    O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Infodelivery present
    O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
    O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
    O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: LinkResolveIgnoreLinkInfo = 0
    O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoResolveSearch = 1
    O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
    O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
    O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
    O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
    O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
    O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: LinkResolveIgnoreLinkInfo = 0
    O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
    O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
    O9 - Extra Button: The Weather Channel - {2E5E800E-6AC0-411E-940A-369530A35E43} - Reg Error: Key error. File not found
    O9 - Extra 'Tools' menuitem : The Weather Channel - {2E5E800E-6AC0-411E-940A-369530A35E43} - Reg Error: Value error. File not found
    O15 - HKCU\..Trusted Domains: ([]msn in My Computer)
    O15 - HKCU\..Trusted Domains: intuit.com ([ttlc] https in Trusted sites)
    O15 - HKCU\..Trusted Domains: turbotax.com ([]https in Trusted sites)
    O16 - DPF: {02BCC737-B171-4746-94C9-0D8A0B2C0089} http://office.microsoft.com/templates/ieawsdc.cab (Microsoft Office Template and Media Control)
    O16 - DPF: {0742B9EF-8C83-41CA-BFBA-830A59E23533} https://support.microsoft.com/OAS/ActiveX/MSDcode.cab (Microsoft Data Collection Control)
    O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://download.macromedia.com/pub/shockwave/cabs/director/sw.cab (Shockwave ActiveX Control)
    O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} http://download.mcafee.com/molbin/shared/mcinsctl/4,0,0,101/mcinsctl.cab (Reg Error: Value error.)
    O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1180022601328 (MUWebControl Class)
    O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab (Java Plug-in 1.6.0_21)
    O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} http://download.mcafee.com/molbin/shared/mcgdmgr/1,0,0,26/mcgdmgr.cab (Reg Error: Value error.)
    O16 - DPF: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab (Java Plug-in 1.6.0_21)
    O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab (Java Plug-in 1.6.0_21)
    O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Value error.)
    O16 - DPF: Microsoft XML Parser for Java file://C:\WINDOWS\Java\classes\xmldso.cab (Reg Error: Key error.)
    O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 68.87.85.102 68.87.69.150
    O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
    O20 - Winlogon\Notify\!SASWinLogon: DllName - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll (SUPERAntiSpyware.com)
    O24 - Desktop WallPaper: C:\Documents and Settings\Voneta\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
    O24 - Desktop BackupWallPaper: C:\Documents and Settings\Voneta\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
    O28 - HKLM ShellExecuteHooks: {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - C:\Program Files\SUPERAntiSpyware\SASSEH.DLL (SuperAdBlocker.com)
    O32 - HKLM CDRom: AutoRun - 1
    O32 - AutoRun File - [2006/07/05 11:15:06 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
    O34 - HKLM BootExecute: (autocheck autochk *) - File not found
    O35 - HKLM\..comfile [open] -- "%1" %*
    O35 - HKLM\..exefile [open] -- "%1" %*
    O37 - HKLM\...com [@ = ComFile] -- "%1" %*
    O37 - HKLM\...exe [@ = exefile] -- "%1" %*

    NetSvcs: 6to4 - File not found
    NetSvcs: AppMgmt - C:\WINDOWS\System32\appmgmts.dll File not found
    NetSvcs: HidServ - C:\WINDOWS\System32\hidserv.dll File not found
    NetSvcs: Ias - File not found
    NetSvcs: Iprip - File not found
    NetSvcs: Irmon - File not found
    NetSvcs: NWCWorkstation - File not found
    NetSvcs: Nwsapagent - File not found
    NetSvcs: WmdmPmSp - File not found

    Drivers32: msacm.iac2 - C:\WINDOWS\system32\iac25_32.ax (Intel Corporation)
    Drivers32: msacm.l3acm - C:\WINDOWS\System32\L3CODECX.ACM (Fraunhofer Institut Integrierte Schaltungen IIS)
    Drivers32: msacm.sl_anet - C:\WINDOWS\System32\sl_anet.acm (Sipro Lab Telecom Inc.)
    Drivers32: msacm.trspch - C:\WINDOWS\System32\tssoft32.acm (DSP GROUP, INC.)
    Drivers32: vidc.cvid - C:\WINDOWS\System32\iccvid.dll (Radius Inc.)
    Drivers32: vidc.iv31 - C:\WINDOWS\System32\ir32_32.dll ()
    Drivers32: vidc.iv32 - C:\WINDOWS\System32\ir32_32.dll ()
    Drivers32: vidc.iv41 - C:\WINDOWS\System32\ir41_32.ax ()
    Drivers32: vidc.iv50 - C:\WINDOWS\System32\ir50_32.dll ()
    Drivers32: vidc.LEAD - LCODCCMP.DLL File not found
    Drivers32: VIDC.WMV3 - C:\WINDOWS\System32\wmv9vcm.dll (Microsoft Corporation)

    CREATERESTOREPOINT
    Restore point Set: OTL Restore Point (56590025235628032)

    ========== Files/Folders - Created Within 30 Days ==========

    [2010/11/03 22:00:35 | 000,576,000 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\Voneta\Desktop\OTL.exe
    [2010/11/03 21:13:30 | 000,000,000 | RHSD | C] -- C:\cmdcons
    [2010/11/03 21:11:11 | 000,212,480 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWXCACLS.exe
    [2010/11/03 21:11:11 | 000,161,792 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWREG.exe
    [2010/11/03 21:11:11 | 000,136,704 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWSC.exe
    [2010/11/03 21:11:11 | 000,031,232 | ---- | C] (NirSoft) -- C:\WINDOWS\NIRCMD.exe
    [2010/11/03 21:10:52 | 000,000,000 | ---D | C] -- C:\WINDOWS\ERDNT
    [2010/11/03 20:11:53 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Voneta\Application Data\Avira
    [2010/11/03 19:49:46 | 000,000,000 | ---D | C] -- C:\Qoobox
    [2010/11/03 17:35:46 | 000,028,520 | ---- | C] (Avira GmbH) -- C:\WINDOWS\System32\drivers\ssmdrv.sys
    [2010/11/03 17:35:43 | 000,126,856 | ---- | C] (Avira GmbH) -- C:\WINDOWS\System32\drivers\avipbb.sys
    [2010/11/03 17:35:43 | 000,060,936 | ---- | C] (Avira GmbH) -- C:\WINDOWS\System32\drivers\avgntflt.sys
    [2010/11/03 17:35:43 | 000,045,416 | ---- | C] (Avira GmbH) -- C:\WINDOWS\System32\drivers\avgntdd.sys
    [2010/11/03 17:35:43 | 000,022,360 | ---- | C] (Avira GmbH) -- C:\WINDOWS\System32\drivers\avgntmgr.sys
    [2010/11/03 17:35:38 | 000,000,000 | ---D | C] -- C:\Program Files\Avira
    [2010/11/03 17:35:38 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Avira
    [2010/11/03 17:12:52 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Voneta\Application Data\Malwarebytes
    [2010/11/03 17:12:34 | 000,038,224 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbamswissarmy.sys
    [2010/11/03 17:12:32 | 000,020,952 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbam.sys
    [2010/11/03 17:12:32 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Malwarebytes
    [2010/11/03 17:12:31 | 000,000,000 | ---D | C] -- C:\Program Files\Malwarebytes' Anti-Malware
    [2010/11/03 09:50:27 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Voneta\Application Data\Registry Mechanic
    [2010/11/03 09:47:24 | 000,000,000 | ---D | C] -- C:\Program Files\Registry Mechanic
    [2010/11/03 09:47:22 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\TEMP
    [2010/10/29 16:17:24 | 000,000,000 | ---D | C] -- C:\Program Files\Conduit
    [2010/10/29 16:17:24 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Voneta\Local Settings\Application Data\Conduit
    [2010/10/29 16:17:23 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Voneta\Local Settings\Application Data\Online_Radio_1.1
    [2010/10/29 16:17:20 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Voneta\Local Settings\Application Data\ConduitEngine
    [2010/10/29 16:17:19 | 000,000,000 | ---D | C] -- C:\Program Files\ConduitEngine
    [2010/10/29 16:17:17 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Voneta\Local Settings\Application Data\Temp
    [2010/10/29 16:17:17 | 000,000,000 | ---D | C] -- C:\Program Files\Online_Radio_1.1
    [6 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
    [1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]

    ========== Files - Modified Within 30 Days ==========

    [2010/11/03 22:00:43 | 000,576,000 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Voneta\Desktop\OTL.exe
    [2010/11/03 21:26:41 | 003,901,988 | R--- | M] () -- C:\Documents and Settings\Voneta\Desktop\broni.exe
    [2010/11/03 21:23:53 | 000,002,206 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
    [2010/11/03 21:21:25 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
    [2010/11/03 21:13:37 | 000,000,327 | RHS- | M] () -- C:\boot.ini
    [2010/11/03 20:54:17 | 000,364,032 | ---- | M] () -- C:\Documents and Settings\Voneta\My Documents\rkill.exe
    [2010/11/03 18:36:29 | 000,088,064 | ---- | M] () -- C:\WINDOWS\MBR.exe
    [2010/11/03 17:42:47 | 000,294,912 | ---- | M] () -- C:\Documents and Settings\Voneta\My Documents\GMER.exe
    [2010/11/03 17:36:09 | 000,001,707 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Avira AntiVir Control Center.lnk
    [2010/11/03 17:12:37 | 000,000,696 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
    [2010/11/03 16:06:20 | 000,000,211 | ---- | M] () -- C:\Boot.bak
    [2010/11/03 14:05:33 | 000,000,874 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Advanced SystemCare.lnk
    [2010/11/02 10:23:23 | 000,023,552 | ---- | M] () -- C:\Documents and Settings\Voneta\My Documents\zebs invoice.xls
    [2010/11/02 09:53:42 | 000,001,729 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Adobe Reader 9.lnk
    [2010/10/16 09:49:32 | 000,273,376 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT
    [2010/10/14 18:10:48 | 000,001,393 | ---- | M] () -- C:\WINDOWS\imsins.BAK
    [2010/10/10 12:06:53 | 000,440,684 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat
    [2010/10/10 12:06:53 | 000,071,002 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat
    [6 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
    [1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]

    ========== Files Created - No Company Name ==========

    [2010/11/03 21:26:40 | 003,901,988 | R--- | C] () -- C:\Documents and Settings\Voneta\Desktop\broni.exe
    [2010/11/03 21:13:37 | 000,000,211 | ---- | C] () -- C:\Boot.bak
    [2010/11/03 21:13:32 | 000,260,272 | RHS- | C] () -- C:\cmldr
    [2010/11/03 21:11:11 | 000,256,512 | ---- | C] () -- C:\WINDOWS\PEV.exe
    [2010/11/03 21:11:11 | 000,098,816 | ---- | C] () -- C:\WINDOWS\sed.exe
    [2010/11/03 21:11:11 | 000,088,064 | ---- | C] () -- C:\WINDOWS\MBR.exe
    [2010/11/03 21:11:11 | 000,080,412 | ---- | C] () -- C:\WINDOWS\grep.exe
    [2010/11/03 21:11:11 | 000,068,096 | ---- | C] () -- C:\WINDOWS\zip.exe
    [2010/11/03 20:54:14 | 000,364,032 | ---- | C] () -- C:\Documents and Settings\Voneta\My Documents\rkill.exe
    [2010/11/03 17:42:43 | 000,294,912 | ---- | C] () -- C:\Documents and Settings\Voneta\My Documents\GMER.exe
    [2010/11/03 17:36:09 | 000,001,707 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Avira AntiVir Control Center.lnk
    [2010/11/03 17:12:37 | 000,000,696 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
    [2010/11/03 14:05:33 | 000,000,874 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Advanced SystemCare.lnk
    [2010/11/02 09:53:42 | 000,001,729 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Adobe Reader 9.lnk
    [2010/08/19 11:26:03 | 000,156,000 | ---- | C] () -- C:\Documents and Settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
    [2008/07/26 22:44:10 | 000,011,776 | ---- | C] () -- C:\Documents and Settings\Voneta\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
    [2008/03/05 18:21:05 | 000,049,152 | ---- | C] () -- C:\WINDOWS\System32\VZWDLManager.dll
    [2008/02/26 19:29:06 | 000,000,129 | ---- | C] () -- C:\Documents and Settings\Voneta\Local Settings\Application Data\fusioncache.dat
    [2008/02/25 17:20:26 | 000,077,824 | R--- | C] () -- C:\WINDOWS\System32\HPZIDS01.dll
    [2008/02/25 17:11:34 | 000,002,067 | ---- | C] () -- C:\Documents and Settings\All Users\Application Data\hpzinstall.log
    [2007/06/16 16:14:55 | 000,061,440 | R--- | C] () -- C:\WINDOWS\System32\vuins32.dll
    [2007/04/26 17:54:23 | 000,262,144 | ---- | C] () -- C:\WINDOWS\System32\TwcToolbarIe7.dll
    [2007/04/26 17:54:23 | 000,077,824 | ---- | C] () -- C:\WINDOWS\System32\TwcToolbarBho.dll
    [2007/02/10 15:15:14 | 000,000,029 | ---- | C] () -- C:\WINDOWS\atid.ini
    [2007/02/09 10:54:45 | 000,000,020 | ---- | C] () -- C:\WINDOWS\Hposcv07.INI
    [2006/10/05 16:04:37 | 000,000,607 | ---- | C] () -- C:\WINDOWS\cdplayer.ini
    [2006/07/09 08:42:48 | 000,002,063 | ---- | C] () -- C:\Documents and Settings\Voneta\Application Data\AdobeDLM.log
    [2006/07/09 08:42:48 | 000,000,006 | ---- | C] () -- C:\Documents and Settings\Voneta\Application Data\dm.ini
    [2006/07/05 13:15:58 | 000,000,376 | ---- | C] () -- C:\WINDOWS\ODBC.INI
    [2006/07/05 11:34:50 | 000,000,006 | ---- | C] () -- C:\Documents and Settings\All Users\Application Data\DirectCDUserName.txt
    [2006/07/05 05:04:26 | 000,004,161 | ---- | C] () -- C:\WINDOWS\ODBCINST.INI
    [2006/01/12 17:09:14 | 000,090,112 | ---- | C] () -- C:\WINDOWS\System32\DXFLib.dll
    [2006/01/12 17:08:06 | 000,143,360 | ---- | C] () -- C:\WINDOWS\System32\opcode.dll
    [2001/08/18 06:00:00 | 000,755,200 | ---- | C] () -- C:\WINDOWS\System32\ir50_32.dll
    [2001/08/18 06:00:00 | 000,338,432 | ---- | C] () -- C:\WINDOWS\System32\ir41_qcx.dll
    [2001/08/18 06:00:00 | 000,200,192 | ---- | C] () -- C:\WINDOWS\System32\ir50_qc.dll
    [2001/08/18 06:00:00 | 000,183,808 | ---- | C] () -- C:\WINDOWS\System32\ir50_qcx.dll
    [2001/08/18 06:00:00 | 000,120,320 | ---- | C] () -- C:\WINDOWS\System32\ir41_qc.dll
    [2001/08/10 13:14:16 | 000,028,672 | ---- | C] () -- C:\WINDOWS\System32\ImapiRoxPS.dll
    [2001/07/07 04:00:00 | 000,003,399 | ---- | C] () -- C:\WINDOWS\System32\hptcpmon.ini
    [2001/05/29 11:23:34 | 000,002,918 | ---- | C] () -- C:\WINDOWS\System32\kid_inst.dll
    [1999/01/22 12:46:58 | 000,065,536 | ---- | C] () -- C:\WINDOWS\System32\MSRTEDIT.DLL
    [1998/01/12 02:00:00 | 000,040,448 | ---- | C] () -- C:\WINDOWS\System32\REGOBJ.DLL

    ========== LOP Check ==========

    [2006/07/05 13:43:55 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\SBT
    [2010/11/03 15:44:30 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\TEMP
    [2007/03/12 20:01:51 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Viewpoint
    [2007/07/24 10:17:26 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Voneta\Application Data\Aim
    [2009/03/23 11:32:22 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Voneta\Application Data\com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
    [2010/11/03 15:32:00 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Voneta\Application Data\IObit
    [2006/12/20 13:16:12 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Voneta\Application Data\Leadertech
    [2010/11/03 09:50:27 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Voneta\Application Data\Registry Mechanic
    [2007/02/15 20:35:53 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Voneta\Application Data\Viewpoint

    ========== Purity Check ==========



    ========== Custom Scans ==========


    < %SYSTEMDRIVE%\*.* >
    [2006/07/05 11:15:06 | 000,000,000 | ---- | M] () -- C:\AUTOEXEC.BAT
    [2010/11/03 16:06:20 | 000,000,211 | ---- | M] () -- C:\Boot.bak
    [2010/11/03 21:13:37 | 000,000,327 | RHS- | M] () -- C:\boot.ini
    [2004/08/03 23:00:00 | 000,260,272 | RHS- | M] () -- C:\cmldr
    [2010/11/03 21:46:03 | 000,016,541 | ---- | M] () -- C:\ComboFix.txt
    [2006/07/05 11:15:06 | 000,000,000 | ---- | M] () -- C:\CONFIG.SYS
    [2006/07/05 11:15:06 | 000,000,000 | RHS- | M] () -- C:\IO.SYS
    [2007/02/10 15:17:42 | 000,001,490 | -H-- | M] () -- C:\IPH.PH
    [2008/07/11 23:33:47 | 000,011,635 | ---- | M] () -- C:\mombi.log
    [2006/07/05 11:15:06 | 000,000,000 | RHS- | M] () -- C:\MSDOS.SYS
    [2006/07/30 14:03:14 | 000,047,564 | RHS- | M] () -- C:\NTDETECT.COM
    [2008/09/03 17:29:51 | 000,250,048 | RHS- | M] () -- C:\ntldr
    [2010/11/03 21:21:22 | 603,979,776 | -HS- | M] () -- C:\pagefile.sys
    [2010/11/03 20:56:35 | 000,000,399 | ---- | M] () -- C:\rkill.log
    [2007/06/06 23:05:37 | 000,066,324 | ---- | M] () -- C:\VETlog.dmp
    [2007/06/06 23:05:37 | 000,001,364 | ---- | M] () -- C:\VETlog.txt

    < %systemroot%\Fonts\*.com >
    [2006/04/18 15:39:28 | 000,026,040 | ---- | M] () -- C:\WINDOWS\Fonts\GlobalMonospace.CompositeFont
    [2006/06/29 14:53:56 | 000,026,489 | ---- | M] () -- C:\WINDOWS\Fonts\GlobalSansSerif.CompositeFont
    [2006/04/18 15:39:28 | 000,029,779 | ---- | M] () -- C:\WINDOWS\Fonts\GlobalSerif.CompositeFont
    [2006/06/29 14:58:52 | 000,030,808 | ---- | M] () -- C:\WINDOWS\Fonts\GlobalUserInterface.CompositeFont

    < %systemroot%\Fonts\*.dll >
    [2006/02/19 04:28:56 | 000,012,288 | ---- | M] (Hewlett-Packard Development Company, L.P.) -- C:\WINDOWS\Fonts\RandFont.dll

    < %systemroot%\Fonts\*.ini >
    [2006/07/05 11:14:36 | 000,000,067 | -HS- | M] () -- C:\WINDOWS\Fonts\desktop.ini

    < %systemroot%\Fonts\*.ini2 >

    < %systemroot%\Fonts\*.exe >

    < %systemroot%\system32\spool\prtprocs\w32x86\*.* >
    [2008/07/06 06:06:10 | 000,089,088 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\spool\prtprocs\w32x86\filterpipelineprintproc.dll
    [2006/04/10 15:02:32 | 000,074,240 | ---- | M] (Hewlett-Packard Corporation) -- C:\WINDOWS\system32\spool\prtprocs\w32x86\hpzpp054.dll
    [2008/07/06 04:50:03 | 000,597,504 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\spool\prtprocs\w32x86\printfilterpipelinesvc.exe

    < %systemroot%\REPAIR\*.bak1 >

    < %systemroot%\REPAIR\*.ini >

    < %systemroot%\system32\*.jpg >

    < %systemroot%\*.jpg >

    < %systemroot%\*.png >

    < %systemroot%\*.scr >

    < %systemroot%\*._sy >

    < %APPDATA%\Adobe\Update\*.* >

    < %ALLUSERSPROFILE%\Favorites\*.* >

    < %APPDATA%\Microsoft\*.* >
    [2007/02/09 09:57:15 | 000,001,602 | -H-- | M] () -- C:\Documents and Settings\Voneta\Application Data\Microsoft\LastFlashConfig.WFC

    < %PROGRAMFILES%\*.* >

    < %APPDATA%\Update\*.* >

    < %systemroot%\*. /mp /s >

    < %systemroot%\System32\config\*.sav >
    [2006/07/05 05:02:43 | 000,090,112 | ---- | M] () -- C:\WINDOWS\system32\config\default.sav
    [2006/07/05 05:02:43 | 000,606,208 | ---- | M] () -- C:\WINDOWS\system32\config\software.sav
    [2006/07/05 05:02:42 | 000,385,024 | ---- | M] () -- C:\WINDOWS\system32\config\system.sav

    < %PROGRAMFILES%\bak. /s >

    < %systemroot%\system32\bak. /s >

    < %ALLUSERSPROFILE%\Start Menu\*.lnk /x >
    [2008/09/03 17:39:58 | 000,000,272 | -HS- | M] () -- C:\Documents and Settings\All Users\Start Menu\desktop.ini

    < %systemroot%\system32\config\systemprofile\*.dat /x >

    < %systemroot%\*.config >

    < %systemroot%\system32\*.db >

    < %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
    [2008/09/04 09:06:35 | 000,000,177 | -HS- | M] () -- C:\Documents and Settings\Voneta\Application Data\Microsoft\Internet Explorer\Quick Launch\desktop.ini
    [2006/07/05 11:26:33 | 000,000,079 | ---- | M] () -- C:\Documents and Settings\Voneta\Application Data\Microsoft\Internet Explorer\Quick Launch\Show Desktop.scf

    < %USERPROFILE%\Desktop\*.exe >
    [2007/02/09 10:52:24 | 040,110,272 | ---- | M] (Hewlett-Packard Company ) -- C:\Documents and Settings\Voneta\Desktop\a1403_05_enu_xp.exe
    [2009/10/13 10:50:07 | 021,290,704 | ---- | M] ( ) -- C:\Documents and Settings\Voneta\Desktop\AdbeRdr708_en_US.exe
    [2010/11/03 21:26:41 | 003,901,988 | R--- | M] () -- C:\Documents and Settings\Voneta\Desktop\broni.exe
    [2010/01/25 16:02:45 | 004,018,552 | ---- | M] (IObit ) -- C:\Documents and Settings\Voneta\Desktop\DefragSetup.exe
    [2006/12/11 22:12:05 | 000,407,672 | ---- | M] (AOL LLC.) -- C:\Documents and Settings\Voneta\Desktop\Install_AIM.exe
    [2007/05/24 10:39:25 | 001,134,216 | ---- | M] (Microsoft Corporation) -- C:\Documents and Settings\Voneta\Desktop\install_flash_player_active_x.exe
    [2010/11/03 22:00:43 | 000,576,000 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Voneta\Desktop\OTL.exe
    [2009/10/13 10:45:34 | 007,050,552 | ---- | M] (Adobe Systems, Inc. ) -- C:\Documents and Settings\Voneta\Desktop\psa30se_en_us.exe
    [2006/12/13 09:34:32 | 019,666,504 | ---- | M] (Apple Computer, Inc.) -- C:\Documents and Settings\Voneta\Desktop\QuickTimeInstaller.exe
    [2010/01/25 15:21:04 | 007,520,288 | ---- | M] () -- C:\Documents and Settings\Voneta\Desktop\SUPERAntiSpyware.exe

    < %PROGRAMFILES%\Common Files\*.* >

    < %systemroot%\*.src >

    < %systemroot%\install\*.* >

    < %systemroot%\system32\DLL\*.* >

    < %systemroot%\system32\HelpFiles\*.* >

    < %systemroot%\system32\rundll\*.* >

    < %systemroot%\winn32\*.* >

    < %systemroot%\Java\*.* >

    < %systemroot%\system32\test\*.* >

    < %systemroot%\system32\Rundll32\*.* >

    < %systemroot%\AppPatch\Custom\*.* >

    < %APPDATA%\Roaming\Microsoft\Windows\Recent\*.lnk /x >

    < %PROGRAMFILES%\PC-Doctor\Downloads\*.* >

    < %PROGRAMFILES%\Internet Explorer\*.tmp >

    < %PROGRAMFILES%\Internet Explorer\*.dat >

    < %USERPROFILE%\My Documents\*.exe >
    [2010/11/03 17:42:47 | 000,294,912 | ---- | M] () -- C:\Documents and Settings\Voneta\My Documents\GMER.exe
    [2010/11/03 20:54:17 | 000,364,032 | ---- | M] () -- C:\Documents and Settings\Voneta\My Documents\rkill.exe

    < %USERPROFILE%\*.exe >

    < %systemroot%\ADDINS\*.* >

    < %systemroot%\assembly\*.bak2 >

    < %systemroot%\Config\*.* >

    < %systemroot%\REPAIR\*.bak2 >

    < %systemroot%\SECURITY\Database\*.sdb /x >

    < %systemroot%\SYSTEM\*.bak2 >

    < %systemroot%\Web\*.bak2 >

    < %systemroot%\Driver Cache\*.* >

    < %PROGRAMFILES%\Mozilla Firefox\0*.exe >

    < %ProgramFiles%\Microsoft Common\*.* >

    < %ProgramFiles%\TinyProxy. >

    < %USERPROFILE%\Favorites\*.url /x >
    [2008/09/04 09:06:36 | 000,000,122 | -HS- | M] () -- C:\Documents and Settings\Voneta\Favorites\Desktop.ini

    < %systemroot%\system32\*.bk >

    < %systemroot%\*.te >

    < %systemroot%\system32\system32\*.* >

    < %ALLUSERSPROFILE%\*.dat /x >

    < %systemroot%\system32\drivers\*.rmv >

    < dir /b "%systemroot%\system32\*.exe" | find /i " " /c >

    < dir /b "%systemroot%\*.exe" | find /i " " /c >

    < %PROGRAMFILES%\Microsoft\*.* >

    < %systemroot%\System32\Wbem\proquota.exe >

    < %PROGRAMFILES%\Mozilla Firefox\*.dat >

    < %USERPROFILE%\Cookies\*.txt /x >
    [2010/06/03 10:57:37 | 000,000,067 | -HS- | M] () -- C:\Documents and Settings\Voneta\Cookies\desktop.ini
    [2010/11/03 22:05:03 | 000,360,448 | ---- | M] () -- C:\Documents and Settings\Voneta\Cookies\index.dat

    < %SystemRoot%\system32\fonts\*.* >

    < %systemroot%\system32\winlog\*.* >

    < %systemroot%\system32\Language\*.* >

    < %systemroot%\system32\Settings\*.* >

    < %systemroot%\system32\*.quo >

    < %SYSTEMROOT%\AppPatch\*.exe >

    < %SYSTEMROOT%\inf\*.exe >
    [2007/06/26 22:10:26 | 000,317,440 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\inf\unregmp2.exe

    < %SYSTEMROOT%\Installer\*.exe >

    < %systemroot%\system32\config\*.bak2 >

    < %systemroot%\system32\Computers\*.* >

    < %SystemRoot%\system32\Sound\*.* >

    < %SystemRoot%\system32\SpecialImg\*.* >

    < %SystemRoot%\system32\code\*.* >

    < %SystemRoot%\system32\draft\*.* >

    < %SystemRoot%\system32\MSSSys\*.* >

    < %ProgramFiles%\Javascript\*.* >

    < %systemroot%\pchealth\helpctr\System\*.exe /s >

    < %systemroot%\Web\*.exe >

    < %systemroot%\system32\msn\*.* >

    < %systemroot%\system32\*.tro >

    < %AppData%\Microsoft\Installer\msupdates\*.* >

    < %ProgramFiles%\Messenger\*.* >
    [2001/05/02 15:24:18 | 000,004,821 | ---- | M] () -- C:\Program Files\Messenger\blogo.gif
    [2008/04/13 18:11:51 | 000,033,792 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Messenger\custsat.dll
    [2004/07/17 12:41:08 | 000,004,821 | ---- | M] () -- C:\Program Files\Messenger\logowin.gif
    [2001/03/07 06:00:26 | 000,007,047 | ---- | M] () -- C:\Program Files\Messenger\lvback.gif
    [2001/05/22 13:06:52 | 000,000,866 | ---- | M] () -- C:\Program Files\Messenger\mailtmpl.txt
    [2008/05/02 08:01:49 | 000,083,968 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Messenger\msgsc.dll
    [2008/04/13 11:30:28 | 000,180,224 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Messenger\msgslang.dll
    [2008/04/13 18:12:28 | 001,695,232 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Messenger\msmsgs.exe
    [2001/02/01 06:00:26 | 000,000,685 | ---- | M] () -- C:\Program Files\Messenger\msmsgs.exe.manifest
    [2001/08/01 21:58:12 | 000,016,415 | ---- | M] () -- C:\Program Files\Messenger\msmsgsin.exe
    [2004/07/17 12:41:08 | 000,002,882 | ---- | M] () -- C:\Program Files\Messenger\newalert.wav
    [2004/07/17 12:41:08 | 000,006,156 | ---- | M] () -- C:\Program Files\Messenger\newemail.wav
    [2004/07/17 12:41:08 | 000,006,160 | ---- | M] () -- C:\Program Files\Messenger\online.wav
    [2000/12/05 13:10:32 | 000,004,454 | ---- | M] () -- C:\Program Files\Messenger\type.wav
    [2004/07/17 12:41:04 | 000,115,981 | ---- | M] () -- C:\Program Files\Messenger\xpmsgr.chm

    < %systemroot%\system32\systhem32\*.* >

    < %systemroot%\system\*.exe >

    < HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >

    < HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\ Auto Update\Results\Install|LastSuccessTime /rs >


    < >

    ========== Alternate Data Streams ==========

    @Alternate Data Stream - 88 bytes -> C:\Documents and Settings\Voneta\Desktop\install_flash_player_active_x.exe:SummaryInformation
    @Alternate Data Stream - 104 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:D1B5B4F1

    < End of report >
     
  24. vunruh

    vunruh TS Rookie Topic Starter Posts: 25

    extras.txt

    OTL Extras logfile created on: 11/3/2010 10:01:58 PM - Run 1
    OTL by OldTimer - Version 3.2.17.2 Folder = C:\Documents and Settings\Voneta\Desktop
    Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
    Internet Explorer (Version = 8.0.6001.18702)
    Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

    383.00 Mb Total Physical Memory | 118.00 Mb Available Physical Memory | 31.00% Memory free
    920.00 Mb Paging File | 475.00 Mb Available in Paging File | 52.00% Paging File free
    Paging file location(s): C:\pagefile.sys 576 1152 [binary data]

    %SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
    Drive C: | 127.99 Gb Total Space | 113.12 Gb Free Space | 88.38% Space Free | Partition Type: NTFS
    Drive F: | 244.63 Mb Total Space | 236.19 Mb Free Space | 96.55% Space Free | Partition Type: FAT

    Computer Name: UNRUH | User Name: Voneta | Logged in as Administrator.
    Boot Mode: Normal | Scan Mode: Current user | Quick Scan
    Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days

    ========== Extra Registry (SafeList) ==========


    ========== File Associations ==========

    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]

    ========== Shell Spawning ==========

    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
    batfile [open] -- "%1" %*
    cmdfile [open] -- "%1" %*
    comfile [open] -- "%1" %*
    exefile [open] -- "%1" %*
    htmlfile [edit] -- "C:\Program Files\Microsoft Office\Office\msohtmed.exe" %1 (Microsoft Corporation)
    piffile [open] -- "%1" %*
    regfile [merge] -- Reg Error: Key error.
    scrfile [config] -- "%1"
    scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
    scrfile [open] -- "%1" /S
    txtfile [edit] -- Reg Error: Key error.
    Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
    Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
    Folder [open] -- %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
    Folder [explore] -- %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
    Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)

    ========== Security Center Settings ==========

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
    "UpdatesDisableNotify" = 0
    "AntiVirusOverride" = 0
    "FirewallOverride" = 0
    "AntiVirusDisableNotify" = 0
    "FirewallDisableNotify" = 0

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

    ========== System Restore Settings ==========

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
    "DisableSR" = 0

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sr]
    "Start" = 0

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SrService]
    "Start" = 2

    ========== Firewall Settings ==========

    [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile]

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
    "EnableFirewall" = 1
    "DoNotAllowExceptions" = 0
    "DisableNotifications" = 0

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
    "1900:UDP" = 1900:UDP:LocalSubNet:Enabled:mad:xpsp2res.dll,-22007
    "2869:TCP" = 2869:TCP:LocalSubNet:Enabled:mad:xpsp2res.dll,-22008
    "139:TCP" = 139:TCP:LocalSubNet:Disabled:mad:xpsp2res.dll,-22004
    "445:TCP" = 445:TCP:LocalSubNet:Disabled:mad:xpsp2res.dll,-22005
    "137:UDP" = 137:UDP:LocalSubNet:Disabled:mad:xpsp2res.dll,-22001
    "138:UDP" = 138:UDP:LocalSubNet:Disabled:mad:xpsp2res.dll,-22002

    ========== Authorized Applications List ==========

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
    "C:\Program Files\TurboTax\Deluxe 2007\32bit\ttax.exe" = C:\Program Files\TurboTax\Deluxe 2007\32bit\ttax.exe:LocalSubNet:Enabled:TurboTax -- (Intuit, Inc.)
    "C:\Program Files\TurboTax\Deluxe 2007\32bit\updatemgr.exe" = C:\Program Files\TurboTax\Deluxe 2007\32bit\updatemgr.exe:LocalSubNet:Enabled:TurboTax Update Manager -- (Intuit, Inc.)
    "C:\Program Files\Hp\Digital Imaging\bin\hpofxm08.exe" = C:\Program Files\Hp\Digital Imaging\bin\hpofxm08.exe:*:Enabled:hpofxm08.exe -- (Hewlett-Packard Development Company, L.P.)
    "C:\Program Files\Hp\Digital Imaging\bin\hposfx08.exe" = C:\Program Files\Hp\Digital Imaging\bin\hposfx08.exe:*:Enabled:hposfx08.exe -- (Hewlett-Packard Development Company, L.P.)
    "C:\Program Files\Hp\Digital Imaging\bin\hposid01.exe" = C:\Program Files\Hp\Digital Imaging\bin\hposid01.exe:*:Enabled:hposid01.exe -- (Hewlett-Packard Development Company, L.P.)
    "C:\Program Files\Hp\Digital Imaging\bin\hpqCopy.exe" = C:\Program Files\Hp\Digital Imaging\bin\hpqCopy.exe:*:Enabled:hpqcopy.exe -- (Hewlett-Packard Development Company, L.P.)
    "C:\Program Files\Hp\Digital Imaging\bin\hpfccopy.exe" = C:\Program Files\Hp\Digital Imaging\bin\hpfccopy.exe:*:Enabled:hpfccopy.exe -- (Hewlett-Packard)
    "C:\Program Files\Hp\Digital Imaging\bin\hpzwiz01.exe" = C:\Program Files\Hp\Digital Imaging\bin\hpzwiz01.exe:*:Enabled:hpzwiz01.exe -- (Hewlett-Packard Development Company, L.P.)
    "C:\Program Files\Hp\Digital Imaging\Unload\HpqPhUnl.exe" = C:\Program Files\Hp\Digital Imaging\Unload\HpqPhUnl.exe:*:Enabled:hpqphunl.exe -- (Hewlett-Packard)
    "C:\Program Files\Hp\Digital Imaging\Unload\HpqDIA.exe" = C:\Program Files\Hp\Digital Imaging\Unload\HpqDIA.exe:*:Enabled:hpqdia.exe -- ( )
    "C:\Program Files\Hp\Digital Imaging\bin\hpoews01.exe" = C:\Program Files\Hp\Digital Imaging\bin\hpoews01.exe:*:Enabled:hpoews01.exe -- (Hewlett-Packard Development Company, L.P.)
    "C:\Program Files\Common Files\Intuit\Update Service\IntuitUpdateService.exe" = C:\Program Files\Common Files\Intuit\Update Service\IntuitUpdateService.exe:LocalSubNet:Disabled:Intuit Update Shared Downloads Server -- (Intuit Inc.)


    ========== HKEY_LOCAL_MACHINE Uninstall List ==========

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
    "{00010409-78E1-11D2-B60F-006097C998E7}" = Microsoft Office 2000 Professional
    "{00040409-78E1-11D2-B60F-006097C998E7}" = Microsoft Office 2000 Disc 2
    "{0A65A3BD-54B5-4d0d-B084-7688507813F5}" = SlideShow
    "{15C0AF59-4877-49B6-B8C6-A61CE54515F5}" = cp_OnlineProjectsConfig
    "{16BE87BC-69F5-4D36-8CF0-E1CB3ACD5ED3}" = HP Driver Diagnostics
    "{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
    "{2318C2B1-4965-11d4-9B18-009027A5CD4F}" = Google Toolbar for Internet Explorer
    "{2376813B-2E5A-4641-B7B3-A0D5ADB55229}" = HPPhotoSmartExpress
    "{26A24AE4-039D-4CA4-87B4-2F83216016FF}" = Java(TM) 6 Update 21
    "{287ECFA4-719A-2143-A09B-D6A12DE54E40}" = Acrobat.com
    "{29521505-F489-4822-ADFA-32C6DEE4F114}" = TurboTax 2008 WinPerUserEducation
    "{2B7E4354-0492-460A-BDB1-1F59EE141025}" = AirPlus G
    "{2F58D60D-2BFD-4467-9B4D-64E7355C329D}" = Sonic_PrimoSDK
    "{30D298A8-8588-48B3-A3FB-2BE6E6AB1245}" = TurboTax 2008 wcoiper
    "{33BF0960-DBA3-4187-B6CC-C969FCFA2D25}" = SkinsHP1
    "{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
    "{360EDFB0-EAA2-012B-AD16-000000000000}" = TurboTax 2009 wcaiper
    "{363790D2-DA98-41DD-9C9F-69FA36B169DE}" = PanoStandAlone
    "{36518E00-EAA2-012B-AD27-000000000000}" = TurboTax 2009 wcoiper
    "{36FDBE6E-6684-462B-AE98-9A39A1B200CC}" = HP Product Assistant
    "{3881DB80-EAA2-012B-ADAE-000000000000}" = TurboTax 2009 WinPerFedFormset
    "{38975F50-EAA2-012B-ADB4-000000000000}" = TurboTax 2009 WinPerReleaseEngine
    "{38A34630-EAA2-012B-ADB6-000000000000}" = TurboTax 2009 WinPerTaxSupport
    "{3C5A81D0-EAA2-012B-AE9F-000000000000}" = TurboTax 2009 wrapper
    "{41E776A5-9B12-416D-9A12-B4F7B044EBED}" = CP_Package_Basic1
    "{45B8A76B-57EC-4242-B019-066400CD8428}" = BufferChm
    "{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
    "{4BDFD2CE-6329-42E4-9801-9B3D1F10D79B}" = Adobe® Photoshop® Album Starter Edition 3.0
    "{4C590030-7469-453E-8589-D15DA9D03F52}" = ANIWZCS2 Service
    "{4EA684E9-5C81-4033-A696-3019EC57AC3A}" = HPProductAssistant
    "{50D8FFDD-90CD-4859-841F-AA1961C7767A}" = QuickTime
    "{53EE9E42-CECB-4C92-BF76-9CA65DAF8F1C}" = FullDPAppQFolder
    "{609F7AC8-C510-11D4-A788-009027ABA5D0}" = Easy CD Creator 5 Basic
    "{66910000-8B30-4973-A159-6371345AFFA5}" = WebReg
    "{6696D9A4-28A8-4F5A-8E9A-2E8974C8C39C}" = RandMap
    "{66E6CE0C-5A1E-430C-B40A-0C90FF1804A8}" = eSupportQFolder
    "{68763C27-235D-4165-A961-FDEA228CE504}" = AiOSoftwareNPI
    "{6909F917-5499-482e-9AA1-FAD06A99F231}" = Toolbox
    "{6F5E2F4A-377D-4700-B0E3-8F7F7507EA15}" = CustomerResearchQFolder
    "{736C803C-DD3B-4015-BC51-AFB9E67B9076}" = Readme
    "{7570F1CA-016D-46AC-B586-CD74645EFB52}" = TurboTax 2008 WinPerFedFormset
    "{7B5CE976-C7A9-4E38-A7F3-6C8EF025DD8E}" = ANIO Service
    "{7C03270C-4FAB-4F5C-B10D-52FEDA190790}" = DocumentViewerQFolder
    "{7DD9A065-2C86-4A9F-A5FF-796EC1B99DCA}" = AnswerWorks 4.0 Runtime - English
    "{7E7B7865-6C80-4373-8BC1-C2EB9431F9DE}" = ProductContextNPI
    "{8331C3EA-0C91-43AA-A4D4-27221C631139}" = Status
    "{87E2B986-07E8-477a-93DC-AF0B6758B192}" = DocProcQFolder
    "{88214092-836F-4E22-A5AC-569AC9EE6A0F}" = TurboTax 2008 WinPerReleaseEngine
    "{8A4CE7FD-9657-4B06-9943-E1819F3D5D67}" = DocProc
    "{8CE4E6E9-9D55-43FB-9DDB-688C976BFC05}" = Unload
    "{90120000-0020-0409-0000-0000000FF1CE}" = Compatibility Pack for the 2007 Office system
    "{996512CF-F35B-48DE-9291-557FA5316967}" = ScannerCopy
    "{9E5A03E3-6246-4920-9630-0527D5DA9B07}" = AnswerWorks 5.0 English Runtime
    "{A29800BA-0BF1-4E63-9F31-DF05A87F4104}" = InstantShareDevices
    "{A2BCA9F1-566C-4805-97D1-7FDC93386723}" = Adobe AIR
    "{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
    "{AB5D51AE-EBC3-438D-872C-705C7C2084B0}" = DeviceManagementQFolder
    "{AC76BA86-7AD7-1033-7B44-A94000000001}" = Adobe Reader 9.4.0
    "{AFF1EA96-9C23-4249-B7D4-CD4B54D4582F}" = TurboTax ItsDeductible 2006
    "{B0069CFA-5BB9-4C03-B1C6-89CE290E5AFE}" = HP Update
    "{B1DB1AD8-C07E-4052-81A1-D2930232BA70}" = TurboTax 2008 wrapper
    "{B2157760-AA3C-4E2E-BFE6-D20BC52495D9}" = cp_PosterPrintConfig
    "{B23726CF-68BF-41A6-A4EB-72F12F87FE05}" = TurboTax 2008 WinPerTaxSupport
    "{B3B4CD34-6C20-4b28-A231-FEC55B42C579}" = c6100_Help
    "{B6286A44-7505-471A-A72B-04EC2DB2F442}" = CueTour
    "{B69CFE29-FD03-4E0A-87A7-6ED97F98E5B3}" = CP_Panorama1Config
    "{B8DBED1E-8BC3-4d08-B94A-F9D7D88E9BBF}" = HPSSupply
    "{BDBE2F3E-42DB-4d4a-8CB1-19BA765DBC6C}" = HP Photosmart, Officejet and Deskjet 7.0.A
    "{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
    "{C1C6767D-B395-43CB-BF99-051B58B86DA6}" = PhotoGallery
    "{C3ABE126-2BB2-4246-BFE1-6797679B3579}" = LG USB Modem driver
    "{C7F54CF8-D6FB-4E0A-93A3-E68AE0D6C476}" = SolutionCenter
    "{C8574AE5-370F-4246-A301-B85A2CC89A5E}" = C6100
    "{C8753E28-2680-49BF-BD48-DD38FD086EFE}" = AiO_Scan_CDA
    "{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
    "{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}" = SUPERAntiSpyware Free Edition
    "{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
    "{CF40ACC5-E1BB-4aff-AC72-04C2F616BCA7}" = getPlus(R) for Adobe
    "{DBC20735-34E6-4E97-A9E5-2066B66B243D}" = TrayApp
    "{E1B80DEE-A795-4258-8445-074C06AE3AB8}" = MarketResearch
    "{E6D9BC25-0DBC-4368-8E4A-7DEE80661CD9}" = TurboTax 2008 WinPerProgramHelp
    "{EA2BEBD6-87B9-41E5-95AC-7E4C165A9475}" = WexTech AnswerWorks
    "{ECA1A3B6-898F-4DCE-9F04-714CF3BA126B}" = Adobe Flash Player 10 Plugin
    "{ED2C557E-9C18-41FF-B58E-A05EEF0B3B5F}" = CP_CalendarTemplates1
    "{F157460F-720E-482f-8625-AD7843891E5F}" = InstantShareDevicesMFC
    "{F3760724-B29D-465B-BC53-E5D72095BCC4}" = Scan
    "{F6076EF9-08E1-442F-B6A2-BFB61B295A14}" = Fax_CDA
    "{F6510A6A-1962-4548-9454-38C4D4E54FCA}" = Mirar
    "{FB15E224-67C3-491F-9F5C-F257BC418412}" = Destinations
    "{FBB980B0-63F8-4B48-8D65-90F1D9F81D9F}" = NewCopy_CDA
    "{FE7E1DD7-EBCE-4696-ADE2-22BDBF2372DA}" = DocumentViewer
    "Adobe AIR" = Adobe AIR
    "Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
    "Adobe Shockwave Player" = Adobe Shockwave Player
    "AdobeESD" = Adobe Download Manager 2.0 (Remove Only)
    "Advanced SystemCare 3_is1" = Advanced SystemCare 3
    "ATI Display Driver" = ATI Display Driver
    "Avira AntiVir Desktop" = Avira AntiVir Personal - Free Antivirus
    "conduitEngine" = Conduit Engine
    "Coupon Printer for Windows4.0" = Coupon Printer for Windows
    "Creative Removable Disk Manager" = Creative Removable Disk Manager
    "HP Document Viewer" = HP Document Viewer 7.0
    "HP Imaging Device Functions" = HP Imaging Device Functions 7.0
    "hp instant support" = hp instant support
    "HP Photo & Imaging" = HP Photosmart Premier Software 6.5
    "hp psc 700 series 1171040869" = hp psc 700 series
    "HP Solution Center & Imaging Support Tools" = HP Solution Center 7.0
    "HPExtendedCapabilities" = HP Customer Participation Program 7.0
    "HPOCR" = OCR Software by I.R.I.S 7.0
    "ie8" = Windows Internet Explorer 8
    "InstallShield_{2B7E4354-0492-460A-BDB1-1F59EE141025}" = AirPlus G
    "Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
    "Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
    "Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
    "MSCompPackV1" = Microsoft Compression Client Pack 1.0 for Windows XP
    "Online_Radio_1.1 Toolbar" = Online Radio 1.1 Toolbar
    "Shop for HP Supplies" = Shop for HP Supplies
    "Smart Defrag_is1" = Smart Defrag
    "SysInfo" = Creative System Information
    "The Weather Channel Desktop 6" = The Weather Channel Desktop 6
    "The Weather Channel Toolbar" = The Weather Channel Toolbar
    "TurboTax 2008" = TurboTax 2008
    "TurboTax 2009" = TurboTax 2009
    "TurboTax Deluxe 2007" = TurboTax Deluxe 2007
    "VCast Music Essentials Manager" = V CAST Music Manager
    "Viewpoint Manager" = Viewpoint Manager (Remove Only)
    "ViewpointMediaPlayer" = Viewpoint Media Player
    "VN_VUIns_Rhine_D-Link" = D-Link PCI Fast Ethernet Adapter
    "Windows Media Format Runtime" = Windows Media Format 11 runtime
    "Windows Media Player" = Windows Media Player 11
    "Windows XP Service Pack" = Windows XP Service Pack 3
    "WMFDist11" = Windows Media Format 11 runtime
    "wmp11" = Windows Media Player 11
    "Wudf01000" = Microsoft User-Mode Driver Framework Feature Pack 1.0

    ========== Last 10 Event Log Errors ==========

    [ Application Events ]
    Error - 11/1/2010 5:05:19 PM | Computer Name = UNRUH | Source = Application Error | ID = 1000
    Description = Faulting application iexplore.exe, version 8.0.6001.18702, faulting
    module limewi~4.dll, version 5.1.0.1000, fault address 0x0005d09d.

    Error - 11/1/2010 5:05:33 PM | Computer Name = UNRUH | Source = Application Error | ID = 1000
    Description = Faulting application iexplore.exe, version 8.0.6001.18702, faulting
    module limewi~4.dll, version 5.1.0.1000, fault address 0x0005d09d.

    Error - 11/1/2010 5:05:47 PM | Computer Name = UNRUH | Source = Application Error | ID = 1000
    Description = Faulting application iexplore.exe, version 8.0.6001.18702, faulting
    module limewi~4.dll, version 5.1.0.1000, fault address 0x0005d09d.

    Error - 11/1/2010 5:05:54 PM | Computer Name = UNRUH | Source = Application Error | ID = 1000
    Description = Faulting application iexplore.exe, version 8.0.6001.18702, faulting
    module limewi~4.dll, version 5.1.0.1000, fault address 0x0005d09d.

    Error - 11/2/2010 3:57:38 PM | Computer Name = UNRUH | Source = Application Error | ID = 1000
    Description = Faulting application iexplore.exe, version 8.0.6001.18702, faulting
    module limewi~4.dll, version 5.1.0.1000, fault address 0x0008c807.

    Error - 11/2/2010 4:02:12 PM | Computer Name = UNRUH | Source = Application Error | ID = 1000
    Description = Faulting application winword.exe, version 9.0.0.2717, faulting module
    mso9.dll, version 9.0.0.2720, fault address 0x0000fad5.

    Error - 11/3/2010 7:36:51 PM | Computer Name = UNRUH | Source = crypt32 | ID = 131083
    Description = Failed extract of third-party root list from auto update cab at: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>
    with error: A required certificate is not within its validity period when verifying
    against the current system clock or the timestamp in the signed file.

    Error - 11/3/2010 7:36:51 PM | Computer Name = UNRUH | Source = crypt32 | ID = 131083
    Description = Failed extract of third-party root list from auto update cab at: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>
    with error: A required certificate is not within its validity period when verifying
    against the current system clock or the timestamp in the signed file.

    Error - 11/3/2010 11:15:11 PM | Computer Name = UNRUH | Source = Application Error | ID = 1000
    Description = Faulting application explorer.exe, version 6.0.2900.5512, faulting
    module unknown, version 0.0.0.0, fault address 0x715b9e59.

    Error - 11/3/2010 11:16:29 PM | Computer Name = UNRUH | Source = Application Error | ID = 1000
    Description = Faulting application explorer.exe, version 6.0.2900.5512, faulting
    module unknown, version 0.0.0.0, fault address 0x715b9e59.

    [ System Events ]
    Error - 11/3/2010 5:43:59 PM | Computer Name = UNRUH | Source = Service Control Manager | ID = 7023
    Description = The Application Management service terminated with the following error:
    %%126

    Error - 11/3/2010 5:43:59 PM | Computer Name = UNRUH | Source = Service Control Manager | ID = 7023
    Description = The Application Management service terminated with the following error:
    %%126

    Error - 11/3/2010 5:43:59 PM | Computer Name = UNRUH | Source = Service Control Manager | ID = 7023
    Description = The Application Management service terminated with the following error:
    %%126

    Error - 11/3/2010 5:44:00 PM | Computer Name = UNRUH | Source = Service Control Manager | ID = 7023
    Description = The Application Management service terminated with the following error:
    %%126

    Error - 11/3/2010 6:09:53 PM | Computer Name = UNRUH | Source = Service Control Manager | ID = 7000
    Description = The SASDIFSV service failed to start due to the following error: %%183

    Error - 11/3/2010 6:10:50 PM | Computer Name = UNRUH | Source = Service Control Manager | ID = 7000
    Description = The SASDIFSV service failed to start due to the following error: %%183

    Error - 11/3/2010 7:28:46 PM | Computer Name = UNRUH | Source = sr | ID = 1
    Description = The System Restore filter encountered the unexpected error '0xC0000001'
    while processing the file '' on the volume 'HarddiskVolume1'. It has stopped monitoring
    the volume.

    Error - 11/3/2010 7:33:56 PM | Computer Name = UNRUH | Source = SideBySide | ID = 16842784
    Description = Dependent Assembly Microsoft.VC90.CRT could not be found and Last
    Error was The referenced assembly is not installed on your system.

    Error - 11/3/2010 7:33:56 PM | Computer Name = UNRUH | Source = SideBySide | ID = 16842811
    Description = Resolve Partial Assembly failed for Microsoft.VC90.CRT. Reference error
    message: The referenced assembly is not installed on your system. .

    Error - 11/3/2010 7:33:56 PM | Computer Name = UNRUH | Source = SideBySide | ID = 16842811
    Description = Generate Activation Context failed for C:\DOCUME~1\Voneta\LOCALS~1\Temp\RarSFX0\redist.dll.
    Reference
    error message: The operation completed successfully. .


    < End of report >
     
  25. Broni

    Broni Malware Annihilator Posts: 52,895   +344

    You have very little of RAM. Your computer would run much better, if you get more RAM.

    =========================================================================

    Update your Java version here: http://www.java.com/en/download/installed.jsp

    Note 1: UNCHECK any pre-checked toolbar and/or software offered with the Java update. The pre-checked toolbars/software are not part of the Java update.

    Note 2: The Java Quick Starter (JQS.exe) adds a service to improve the initial startup time of Java applets and applications. If you don't want to run another extra service, go to Start > Control Panel > Java > Advanced > Miscellaneous and uncheck the box for Java Quick Starter. Click OK and restart your computer.

    Now, we need to remove old Java version and its remnants...

    Download JavaRa to your desktop and unzip it to its own folder
    • Run JavaRa.exe (Vista users! Right click on JavaRa.exe, click Run As Administrator), pick the language of your choice and click Select. Then click Remove Older Versions.
    • Accept any prompts.

    ======================================================================

    Run OTL
    • Under the Custom Scans/Fixes box at the bottom, paste in the following

      Code:
      :OTL
      O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No CLSID value found.
      O9 - Extra Button: The Weather Channel - {2E5E800E-6AC0-411E-940A-369530A35E43} - Reg Error: Key error. File not found
      O9 - Extra 'Tools' menuitem : The Weather Channel - {2E5E800E-6AC0-411E-940A-369530A35E43} - Reg Error: Value error. File not found
      O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} http://download.mcafee.com/molbin/sh...1/mcinsctl.cab (Reg Error: Value error.)
      O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} http://download.mcafee.com/molbin/sh...26/mcgdmgr.cab (Reg Error: Value error.)
      O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Value error.)
      O16 - DPF: Microsoft XML Parser for Java file://C:\WINDOWS\Java\classes\xmldso.cab (Reg Error: Key error.)
      [6 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
      [1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
      [2007/03/12 20:01:51 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Viewpoint
      [2010/11/03 09:50:27 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Voneta\Application Data\Registry Mechanic
      [2007/02/15 20:35:53 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Voneta\Application Data\Viewpoint
      @Alternate Data Stream - 88 bytes -> C:\Documents and Settings\Voneta\Desktop\install_flash_player_active_x.exe:SummaryInformati on
      @Alternate Data Stream - 104 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:D1B5B4F1
      
      
      :Services
      
      :Reg
      
      :Files
      
      :Commands
      [purity]
      [emptytemp]
      [emptyflash]
      [Reboot]
      
    • Then click the Run Fix button at the top
    • Let the program run unhindered, reboot the PC when it is done
    • You will get a log that shows the results of the fix. Please post it.

    ========================================================================

    Last scans...

    1. Download Security Check from HERE, and save it to your Desktop.
    • Double-click SecurityCheck.exe
    • Follow the onscreen instructions inside of the black box.
    • A Notepad document should open automatically called checkup.txt; please post the contents of that document.

      NOTE SecurityCheck may produce some false warning(s), so leave the results reading to me.


    2. Download Temp File Cleaner (TFC)
    • Double click on TFC.exe to run the program.
    • Click on Start button to begin cleaning process.
    • TFC will close all running programs, and it may ask you to restart computer.


    3. Please run a free online scan with the ESET Online Scanner

    • Disable your antivirus program
    • Tick the box next to YES, I accept the Terms of Use
    • Click Start
    • IMPORTANT! UN-check Remove found threats
    • Accept any security warnings from your browser.
    • Check Scan archives
    • Click Start
    • ESET will then download updates for itself, install itself, and begin scanning your computer. Please be patient as this can take some time.
    • When the scan completes, push List of found threats
    • Click on Export to text file , and save the file to your desktop using a unique name, such as ESETScan. Include the contents of this report in your next reply.
    • NOTE. If Eset won't find any threats, it won't produce any log.
     
Topic Status:
Not open for further replies.

Similar Topics

Add New Comment

You need to be a member to leave a comment. Join thousands of tech enthusiasts and participate.
TechSpot Account You may also...