computer freezes and also has a redirector

jhooga

New Member
The computer starts up fine runs well but given a little bit it will slow down and the redirector comes in to play. I have done scans using malwarebytes and have found 2 trojans but even after removing them i still get the issues. Can someone help me find out where this is coming from?
 
1. If you don't have third party firewall installed, make sure, Windows firewall is ON:
- Windows XP, and Windows Vista/7 - Go Start>Control Panel. Double click Windows Firewall.

2. If you have an antivirus program, make sure, it's up to date. Run a full scan.
If you don't have any antivirus program installed - download, and install ONE of these:
- Avast free antivirus: http://www.avast.com...avast-home.html
or
- Avira free antivirus: http://www.free-av.c...load/index.html
Update it. Run a full scan.

3. Download Temp File Cleaner (TFC)
Double click on TFC.exe to run the program.
Click on Start button to begin cleaning process.
TFC will close all running programs, and it may ask you to restart computer.

*************************************************

Print these instructions out.

NOTE. If any of the programs listed below refuse to run, try renaming executive file to something else; for instance, rename mbam-setup.exe to scanner1.exe

STEP 1.
Download Malwarebytes' Anti-Malware: http://www.malwarebytes.org/mbam.php to your desktop.
(Malwarebytes is free to use as a manual scanner. Payment is only required if you wish to have it run and update automatically which is not necessary for our purposes)
***VERY IMPORTANT! Make sure, you update Malwarebytes before running the scan.***

* Double-click mbam-setup.exe and follow the prompts to install the program.
* At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
* If an update is found, it will download and install the latest version.
* Once the program has loaded, select Perform quick scan, then click Scan.
* When the scan is complete, click OK, then Show Results to view the results.
* Be sure that everything is checked, and click Remove Selected.
* When completed, a log will open in Notepad.
* Post the log back here.

The log can also be found here:
C:\Documents and Settings\Username\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\Logs\log-date.txt
or at:
C:\Program Files\Malwarebytes' Anti-Malware\Logs\log-date.txt


STEP 2.
Please download GMER from one of the following locations and save it to your desktop:
  • Main Mirror
    This version will download a randomly named file (Recommended)
  • Zipped Mirror
    This version will download a zip file you will need to extract first. If you use this mirror, please extract the zip file to your desktop.

  • Disconnect from the Internet and close all running programs.
  • Temporarily disable any real-time active protection so your security programs will not conflict with gmer's driver.
  • Double-click on the randomly named GMER file (i.e. n7gmo46c.exe) and allow the gmer.sys driver to load if asked.
  • Note: If you downloaded the zipped version, extract the file to its own folder such as C:\gmer and then double-click on gmer.exe.

    gmer_zip.gif

  • GMER will open to the Rootkit/Malware tab and perform an automatic quick scan when first run. (do not use the computer while the scan is in progress)
  • If you receive a WARNING!!! about rootkit activity and are asked to fully scan your system...click NO.
  • Now click the Scan button. If you see a rootkit warning window, click OK.
  • When the scan is finished, click the Save... button to save the scan results to your Desktop. Save the file as gmer.log.
  • Click the Copy button and paste the results into your next reply.
  • Exit GMER and be sure to re-enable your anti-virus, Firewall and any other security programs you had disabled.

IMPORTANT! If for some reason GMER refuses to run, try again.
If it still fails, try to UN-check "Devices" in right pane.
If still no joy, try to run it from Safe Mode.



STEP 3.
Download MBRCheck to your desktop

  • Double click MBRCheck.exe to run (Vista and Windows 7 users, right click and select Run as Administrator).
  • It will show a black screen with some data on it.
  • A report called MBRcheckxxxx.txt will be on your desktop
  • Open this report and post its content in your next reply.


STEP 4.

Please, download DDS, (a new and effective Hijackthis replacement) from one of the 2 mirrors and save it to your desktop.

Mirror 1
Mirror 2

* Disable any script blocking protection (if present)
* Double click the dds icon to run the tool.
* When done, DDS will open two logs:
1. DDS.txt
2. Attach.txt
* Save both reports to your desktop by clicking File>Save As in each log.

Include the contents of both logs in your new topic. The scan will instruct you to post Attach.txt as an attachment. No need for that though ..... just post it's contents as you would any other log.


Do not make any changes to your computer like installing programs, using other cleaning tools, etc., until it's officially declared clean!!!

Note. All topics will be locked after 10 days of inactivity.
 
Last edited:
gmer log the rest of the logs u asked for are coming
GMER 1.0.15.15530 - http://www.gmer.net
Rootkit scan 2011-02-09 11:33:47
Windows 5.1.2600 Service Pack 3 Harddisk0\DR0 -> \Device\Ide\IdePort2 WDC_WD1600AAJS-00PSA0 rev.05.06H05
Running: f7zr38nz.exe; Driver: C:\DOCUME~1\MANAGER\LOCALS~1\Temp\awldypow.sys


---- User code sections - GMER 1.0.15 ----

.text C:\WINDOWS\Explorer.EXE[172] ntdll.dll!NtProtectVirtualMemory 7C90D6EE 5 Bytes JMP 00C0000A
.text C:\WINDOWS\Explorer.EXE[172] ntdll.dll!NtWriteVirtualMemory 7C90DFAE 5 Bytes JMP 00D1000A
.text C:\WINDOWS\Explorer.EXE[172] ntdll.dll!KiUserExceptionDispatcher 7C90E47C 5 Bytes JMP 00BF000C
.text C:\WINDOWS\System32\svchost.exe[880] ntdll.dll!NtProtectVirtualMemory 7C90D6EE 5 Bytes JMP 00A5000A
.text C:\WINDOWS\System32\svchost.exe[880] ntdll.dll!NtWriteVirtualMemory 7C90DFAE 5 Bytes JMP 00A6000A
.text C:\WINDOWS\System32\svchost.exe[880] ntdll.dll!KiUserExceptionDispatcher 7C90E47C 5 Bytes JMP 00A4000C
.text C:\WINDOWS\System32\svchost.exe[880] USER32.dll!GetCursorPos 7E42974E 5 Bytes JMP 0087000A
.text C:\WINDOWS\System32\svchost.exe[880] ole32.dll!CoCreateInstance 774FF1AC 5 Bytes JMP 00F2000A

---- Disk sectors - GMER 1.0.15 ----

Disk \Device\Harddisk0\DR0 sector 62: rootkit-like behavior;
Disk \Device\Harddisk0\DR0 sector 63: rootkit-like behavior;

---- EOF - GMER 1.0.15 ----
 
mbrcheck log
MBRCheck, version 1.2.3
(c) 2010, AD

Command-line:
Windows Version: Windows XP Home Edition
Windows Information: Service Pack 3 (build 2600)
Logical Drives Mask: 0x000001ec

Kernel Drivers (total 117):
0x804D7000 \WINDOWS\system32\ntkrnlpa.exe
0x806E4000 \WINDOWS\system32\hal.dll
0x86CED000 \WINDOWS\system32\KDCOM.DLL
0xF78DC000 \WINDOWS\system32\BOOTVID.dll
0xF7399000 ACPI.sys
0xF79C8000 \WINDOWS\system32\DRIVERS\WMILIB.SYS
0xF7388000 pci.sys
0xF74C8000 isapnp.sys
0xF7A90000 pciide.sys
0xF7748000 \WINDOWS\system32\DRIVERS\PCIIDEX.SYS
0xF74D8000 MountMgr.sys
0xF7369000 ftdisk.sys
0xF7750000 PartMgr.sys
0xF74E8000 VolSnap.sys
0xF7351000 atapi.sys
0xF74F8000 disk.sys
0xF7508000 \WINDOWS\system32\DRIVERS\CLASSPNP.SYS
0xF7331000 fltmgr.sys
0xF731F000 sr.sys
0xF7518000 PxHelp20.sys
0xF7308000 KSecDD.sys
0xF727B000 Ntfs.sys
0xF724E000 NDIS.sys
0xF7234000 Mup.sys
0xF7668000 \SystemRoot\system32\DRIVERS\intelppm.sys
0xF68B0000 \SystemRoot\system32\DRIVERS\igxpmp32.sys
0xF689C000 \SystemRoot\system32\DRIVERS\VIDEOPRT.SYS
0xF6874000 \SystemRoot\system32\DRIVERS\HDAudBus.sys
0xF77E8000 \SystemRoot\system32\DRIVERS\usbuhci.sys
0xF6850000 \SystemRoot\system32\DRIVERS\USBPORT.SYS
0xF77F0000 \SystemRoot\system32\DRIVERS\usbehci.sys
0xF683C000 \SystemRoot\system32\DRIVERS\parport.sys
0xF7A04000 \SystemRoot\system32\DRIVERS\ASACPI.sys
0xF7678000 \SystemRoot\system32\DRIVERS\i8042prt.sys
0xF77F8000 \SystemRoot\system32\DRIVERS\kbdclass.sys
0xF7800000 \SystemRoot\system32\DRIVERS\mouclass.sys
0xF7688000 \SystemRoot\system32\DRIVERS\serial.sys
0xF79C4000 \SystemRoot\system32\DRIVERS\serenum.sys
0xF7698000 \SystemRoot\system32\DRIVERS\imapi.sys
0xF76A8000 \SystemRoot\system32\DRIVERS\cdrom.sys
0xF76B8000 \SystemRoot\system32\DRIVERS\redbook.sys
0xF6819000 \SystemRoot\system32\DRIVERS\ks.sys
0xF7B89000 \SystemRoot\system32\DRIVERS\audstub.sys
0xF76C8000 \SystemRoot\system32\DRIVERS\rasl2tp.sys
0xF720C000 \SystemRoot\system32\DRIVERS\ndistapi.sys
0xF6802000 \SystemRoot\system32\DRIVERS\ndiswan.sys
0xF76D8000 \SystemRoot\system32\DRIVERS\raspppoe.sys
0xF76E8000 \SystemRoot\system32\DRIVERS\raspptp.sys
0xF7808000 \SystemRoot\system32\DRIVERS\TDI.SYS
0xF67F1000 \SystemRoot\system32\DRIVERS\psched.sys
0xF76F8000 \SystemRoot\system32\DRIVERS\msgpc.sys
0xF7810000 \SystemRoot\system32\DRIVERS\ptilink.sys
0xF7818000 \SystemRoot\system32\DRIVERS\raspti.sys
0xF7708000 \SystemRoot\system32\DRIVERS\termdd.sys
0xF7A06000 \SystemRoot\system32\DRIVERS\swenum.sys
0xF6793000 \SystemRoot\system32\DRIVERS\update.sys
0xF7200000 \SystemRoot\system32\DRIVERS\mssmbios.sys
0xF75F8000 \SystemRoot\System32\Drivers\NDProxy.SYS
0xA7959000 \SystemRoot\system32\drivers\RtkHDAud.sys
0xA7935000 \SystemRoot\system32\drivers\portcls.sys
0xF7628000 \SystemRoot\system32\drivers\drmk.sys
0xAA363000 \SystemRoot\system32\DRIVERS\usbhub.sys
0xF7A5E000 \SystemRoot\system32\DRIVERS\USBD.SYS
0xA623D000 \SystemRoot\system32\DRIVERS\MpFilter.sys
0xF6246000 \SystemRoot\system32\DRIVERS\hidusb.sys
0xF64D3000 \SystemRoot\system32\DRIVERS\HIDCLASS.SYS
0xAA0EB000 \SystemRoot\system32\DRIVERS\HIDPARSE.SYS
0xF7A8C000 \SystemRoot\System32\Drivers\Fs_Rec.SYS
0xA5D7D000 \SystemRoot\System32\Drivers\Null.SYS
0xF7A8E000 \SystemRoot\System32\Drivers\Beep.SYS
0xF78C8000 \SystemRoot\System32\drivers\vga.sys
0xF79CA000 \SystemRoot\System32\Drivers\mnmdd.SYS
0xF79CC000 \SystemRoot\System32\DRIVERS\RDPCDD.sys
0xA7034000 \SystemRoot\System32\Drivers\Msfs.SYS
0xA702C000 \SystemRoot\System32\Drivers\Npfs.SYS
0xF623E000 \SystemRoot\system32\DRIVERS\rasacd.sys
0xA5C91000 \SystemRoot\system32\DRIVERS\ipsec.sys
0xA5C38000 \SystemRoot\system32\DRIVERS\tcpip.sys
0xA5C10000 \SystemRoot\system32\DRIVERS\netbt.sys
0xA5BEE000 \SystemRoot\System32\drivers\afd.sys
0xA6F5D000 \SystemRoot\system32\DRIVERS\netbios.sys
0xA5BC3000 \SystemRoot\system32\DRIVERS\rdbss.sys
0xA5B53000 \SystemRoot\system32\DRIVERS\mrxsmb.sys
0xA2688000 \??\c:\Documents and Settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{81984812-CECD-4A03-A9DF-FE86F558BDCB}\MpKsl9d53cb10.sys
0xA0F5F000 \SystemRoot\system32\DRIVERS\ipnat.sys
0xA2828000 \SystemRoot\system32\DRIVERS\wanarp.sys
0xA2678000 \SystemRoot\system32\DRIVERS\usbccgp.sys
0xA2818000 \SystemRoot\System32\Drivers\Fips.SYS
0xA2670000 \SystemRoot\system32\DRIVERS\USBSTOR.SYS
0xA2565000 \SystemRoot\system32\DRIVERS\kbdhid.sys
0xA19AF000 \SystemRoot\System32\Drivers\Cdfs.SYS
0xA2561000 \SystemRoot\system32\DRIVERS\usbscan.sys
0xA2660000 \SystemRoot\system32\DRIVERS\usbprint.sys
0xA0F47000 \SystemRoot\System32\Drivers\dump_atapi.sys
0xF7A34000 \SystemRoot\System32\Drivers\dump_WMILIB.SYS
0xBF800000 \SystemRoot\System32\win32k.sys
0xA254D000 \SystemRoot\System32\drivers\Dxapi.sys
0xA2658000 \SystemRoot\System32\watchdog.sys
0xBF000000 \SystemRoot\System32\drivers\dxg.sys
0xA5D3E000 \SystemRoot\System32\drivers\dxgthk.sys
0xBF024000 \SystemRoot\System32\igxpgd32.dll
0xBF012000 \SystemRoot\System32\igxprd32.dll
0xBF04D000 \SystemRoot\System32\igxpdv32.DLL
0xBF1AE000 \SystemRoot\System32\igxpdx32.DLL
0xBFFA0000 \SystemRoot\System32\ATMFD.DLL
0xA3C51000 \SystemRoot\system32\DRIVERS\ndisuio.sys
0xA0ECA000 \SystemRoot\system32\DRIVERS\mrxdav.sys
0xF7A7C000 \SystemRoot\System32\Drivers\ParVdm.SYS
0xA0DFA000 \SystemRoot\system32\DRIVERS\srv.sys
0xA0D6D000 \SystemRoot\system32\drivers\wdmaud.sys
0xF6A21000 \SystemRoot\system32\drivers\sysaudio.sys
0xA0804000 \SystemRoot\System32\Drivers\HTTP.sys
0xA04F1000 \??\C:\DOCUME~1\MANAGER\LOCALS~1\Temp\awldypow.sys
0xA04C6000 \SystemRoot\system32\drivers\kmixer.sys
0xAA3B3000 \SystemRoot\system32\DRIVERS\l251x86.sys
0xF7790000 \??\c:\Documents and Settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{004159DE-CF05-4208-841A-CC3F4B5AB84F}\MpKslf06e3aa2.sys
0x7C900000 \WINDOWS\system32\ntdll.dll

Processes (total 41):
0 System Idle Process
4 System
412 C:\WINDOWS\system32\smss.exe
460 csrss.exe
484 C:\WINDOWS\system32\winlogon.exe
532 C:\WINDOWS\system32\services.exe
552 C:\WINDOWS\system32\lsass.exe
724 C:\WINDOWS\system32\svchost.exe
800 svchost.exe
844 C:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe
880 C:\WINDOWS\system32\svchost.exe
980 svchost.exe
1032 svchost.exe
1172 C:\WINDOWS\system32\spoolsv.exe
1260 svchost.exe
1308 C:\Program Files\Starfield\offSyncService.exe
1404 C:\Program Files\Common Files\LightScribe\LSSrvc.exe
1520 C:\Program Files\CyberLink\Shared files\RichVideo.exe
1740 C:\WINDOWS\system32\svchost.exe
1832 wdfmgr.exe
1936 C:\Program Files\Viewpoint\Common\ViewpointService.exe
172 C:\WINDOWS\explorer.exe
1220 C:\WINDOWS\system32\igfxtray.exe
1296 C:\WINDOWS\system32\hkcmd.exe
1420 C:\WINDOWS\system32\igfxpers.exe
1432 C:\WINDOWS\RTHDCPL.exe
1556 C:\Program Files\Common Files\Real\Update_OB\realsched.exe
1564 C:\WINDOWS\system32\fonts\mru2\system\clocksvr.exe
1580 C:\Program Files\Microsoft Security Client\msseces.exe
1652 C:\WINDOWS\system32\lgbpd.exe
1668 C:\WINDOWS\system32\ctfmon.exe
1504 C:\Program Files\Starfield\starfieldupdate.exe
1688 C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
2352 alg.exe
3556 MpCmdRun.exe
3616 C:\Program Files\Microsoft Security Client\Antimalware\MpCmdRun.exe
3704 C:\WINDOWS\system32\wuauclt.exe
3768 C:\Program Files\Windows Live Toolbar\MSNTBUP.EXE
2372 C:\WINDOWS\system32\wuauclt.exe
1352 wmiprvse.exe
708 C:\Documents and Settings\MANAGER\Desktop\MBRCheck.exe

\\.\C: --> \\.\PhysicalDrive0 at offset 0x00000000`00007e00 (NTFS)

PhysicalDrive0 Model Number: WDCWD1600AAJS-00PSA0, Rev: 05.06H05

Size Device Name MBR Status
--------------------------------------------
149 GB \\.\PhysicalDrive0 Windows XP MBR code detected
SHA1: DA38B874B7713D1B51CBC449F4EF809B0DEC644A


Done!
 
attach.txt log

UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT

DDS (Ver_10-12-12.02)

Microsoft Windows XP Home Edition
Boot Device: \Device\HarddiskVolume1
Install Date: 12/3/2007 8:25:15 PM
System Uptime: 2/9/2011 11:10:12 AM (0 hours ago)

Motherboard: ASUSTeK Computer INC. | | P5GC-MX
Processor: Intel(R) Pentium(R) Dual CPU E2160 @ 1.80GHz | LGA 775 | 1800/200mhz

==== Disk Partitions =========================

C: is FIXED (NTFS) - 149 GiB total, 133.36 GiB free.
D: is CDROM ()
F: is Removable
G: is Removable
H: is Removable
I: is Removable

==== Disabled Device Manager Items =============

Class GUID: {4D36E96B-E325-11CE-BFC1-08002BE10318}
Description: Standard 101/102-Key or Microsoft Natural PS/2 Keyboard
Device ID: ACPI\PNP0303\4&2C575ACB&0
Manufacturer: (Standard keyboards)
Name: Standard 101/102-Key or Microsoft Natural PS/2 Keyboard
PNP Device ID: ACPI\PNP0303\4&2C575ACB&0
Service: i8042prt

==== System Restore Points ===================

RP1021: 11/11/2010 3:23:09 AM - System Checkpoint
RP1022: 11/12/2010 3:35:09 AM - System Checkpoint
RP1023: 11/13/2010 4:23:10 AM - System Checkpoint
RP1024: 11/14/2010 5:23:07 AM - System Checkpoint
RP1025: 11/15/2010 5:35:08 AM - System Checkpoint
RP1026: 11/16/2010 6:35:08 AM - System Checkpoint
RP1027: 11/17/2010 7:23:07 AM - System Checkpoint
RP1028: 11/18/2010 7:35:08 AM - System Checkpoint
RP1029: 11/19/2010 8:23:07 AM - System Checkpoint
RP1030: 11/20/2010 9:49:08 AM - System Checkpoint
RP1031: 12/3/2010 6:21:39 PM - System Checkpoint
RP1032: 12/6/2010 6:25:06 PM - System Checkpoint
RP1033: 12/7/2010 6:29:36 PM - System Checkpoint
RP1034: 12/15/2010 3:00:24 AM - Software Distribution Service 3.0
RP1035: 12/16/2010 3:25:51 AM - System Checkpoint
RP1036: 1/1/2011 3:00:16 AM - Software Distribution Service 3.0
RP1037: 1/2/2011 3:21:32 AM - System Checkpoint
RP1038: 1/3/2011 4:21:30 AM - System Checkpoint
RP1039: 1/4/2011 1:00:10 PM - System Checkpoint
RP1040: 1/4/2011 6:59:46 PM - Software Distribution Service 3.0
RP1041: 1/5/2011 7:25:29 PM - System Checkpoint
RP1042: 1/6/2011 8:25:29 PM - System Checkpoint
RP1043: 1/7/2011 9:25:28 PM - System Checkpoint
RP1044: 1/8/2011 9:40:22 PM - System Checkpoint
RP1045: 1/9/2011 10:28:21 PM - System Checkpoint
RP1046: 1/11/2011 12:00:45 PM - System Checkpoint
RP1047: 1/12/2011 6:20:17 PM - System Checkpoint
RP1048: 1/13/2011 3:00:14 AM - Software Distribution Service 3.0
RP1049: 1/14/2011 3:23:13 AM - System Checkpoint
RP1050: 1/15/2011 4:23:13 AM - System Checkpoint
RP1051: 1/16/2011 5:23:13 AM - System Checkpoint
RP1052: 1/17/2011 6:23:13 AM - System Checkpoint
RP1053: 1/18/2011 7:21:54 AM - System Checkpoint
RP1054: 1/19/2011 7:35:13 AM - System Checkpoint
RP1055: 1/20/2011 8:23:14 AM - System Checkpoint
RP1056: 1/21/2011 8:35:13 AM - System Checkpoint
RP1057: 1/22/2011 9:23:14 AM - System Checkpoint
RP1058: 1/23/2011 9:35:13 AM - System Checkpoint
RP1059: 1/24/2011 7:14:05 PM - System Checkpoint
RP1060: 1/25/2011 7:35:13 PM - System Checkpoint
RP1061: 1/26/2011 8:35:13 PM - System Checkpoint
RP1062: 1/27/2011 9:35:13 PM - System Checkpoint
RP1063: 1/28/2011 10:35:12 PM - System Checkpoint
RP1064: 1/29/2011 11:23:13 PM - System Checkpoint
RP1065: 1/30/2011 11:35:14 PM - System Checkpoint
RP1066: 2/1/2011 12:23:13 AM - System Checkpoint
RP1067: 2/2/2011 12:35:03 AM - System Checkpoint
RP1068: 2/3/2011 4:32:21 PM - Restore Operation
RP1069: 2/4/2011 5:32:18 PM - System Checkpoint
RP1070: 2/8/2011 6:22:44 PM - System Checkpoint

==== Hosts File Hijack ======================

Hosts: 172.16.32.146 www.squidoo.com
Hosts: 172.16.32.146 squidoo.com
Hosts: 172.16.32.146 ebayphonenumber.net
Hosts: 172.16.32.146 www.ebayphonenumber.net
Hosts: 172.16.32.146 askville.amazon.com
Hosts: 172.16.32.146 hubpages.com
Hosts: 172.16.32.146 www.hubpages.com
Hosts: 172.16.32.146 webcache.googleusercontent.com
Hosts: 172.16.32.146 cc.bingj.com
Hosts: 172.16.32.146 rds.yahoo.com
Hosts: 172.16.32.146 www.ebayphonesupport.com
Hosts: 172.16.32.146 ebayphonesupport.com
Hosts: 172.16.32.146 www.ebayphonenumbers.com
Hosts: 172.16.32.146 ebayphonenumbers.com
Hosts: 172.16.32.146 answercenter.ebay.com
Hosts: 172.16.32.146 cschatlb-na.corp.ebay.com
Hosts: 172.16.32.146 cschat1-na.corp.ebay.com
Hosts: 172.16.32.146 www.autocheck.com

==== Installed Programs ======================

Activation Assistant for the 2007 Microsoft Office suites
Adobe AIR
Adobe Flash Player 10 ActiveX
Adobe Reader 8.1.2
AIM 6
Ask Toolbar
Atheros Communications Inc.(R) L2 Fast Ethernet Driver
Canon iP1600
Canon MF6500 Series
Check Template
Compatibility Pack for the 2007 Office system
deskPDF 2.5 Professional Edition
Desktop Notifier
Docudesk GPL Ghostscript 8.15
Facebook Plug-In
FOX News Live Stream
Google Chrome
Google Earth
Google Update Helper
Google Updater
GoToMeeting 4.1.0.366
High Definition Audio Driver Package - KB888111
Highlight Viewer (Windows Live Toolbar)
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)
Hotfix for Windows XP (KB2158563)
Hotfix for Windows XP (KB2443685)
Hotfix for Windows XP (KB952287)
Hotfix for Windows XP (KB954550-v5)
Hotfix for Windows XP (KB961118)
Hotfix for Windows XP (KB970653-v3)
Hotfix for Windows XP (KB976098-v2)
Hotfix for Windows XP (KB979306)
Hotfix for Windows XP (KB981793)
Intel(R) Graphics Media Accelerator Driver
Intellex Player
LightScribe 1.4.136.1
Macrogaming SweetIM 2.1
Malwarebytes' Anti-Malware
Map Button (Windows Live Toolbar)
MessagePal
Microsoft .NET Framework 2.0 Service Pack 2
Microsoft .NET Framework 3.0 Service Pack 2
Microsoft .NET Framework 3.5 SP1
Microsoft Antimalware
Microsoft Application Error Reporting
Microsoft Internationalized Domain Names Mitigation APIs
Microsoft National Language Support Downlevel APIs
Microsoft Office Standard Edition 2003
Microsoft Security Client
Microsoft Security Essentials
Microsoft SQL Server 2005 Compact Edition [ENU]
Nero 7 Essentials
Picasa 3
POS-X Store Manager
Power Commander Control Center 3.2.0 (Test Build 1)
PowerDVD
RealPlayer
Realtek High Definition Audio Driver
RealUpgrade 1.0
Security Update for Microsoft .NET Framework 3.5 SP1 (KB2416473)
Security Update for Windows Internet Explorer 7 (KB2183461)
Security Update for Windows Internet Explorer 7 (KB2360131)
Security Update for Windows Internet Explorer 7 (KB2416400)
Security Update for Windows Internet Explorer 7 (KB938127-v2)
Security Update for Windows Internet Explorer 7 (KB969897)
Security Update for Windows Internet Explorer 7 (KB972260)
Security Update for Windows Internet Explorer 7 (KB974455)
Security Update for Windows Internet Explorer 7 (KB976325)
Security Update for Windows Internet Explorer 7 (KB978207)
Security Update for Windows Internet Explorer 7 (KB982381)
Security Update for Windows Media Player (KB2378111)
Security Update for Windows Media Player (KB911564)
Security Update for Windows Media Player (KB952069)
Security Update for Windows Media Player (KB954155)
Security Update for Windows Media Player (KB968816)
Security Update for Windows Media Player (KB973540)
Security Update for Windows Media Player (KB975558)
Security Update for Windows Media Player (KB978695)
Security Update for Windows Media Player (KB979402)
Security Update for Windows Media Player 6.4 (KB925398)
Security Update for Windows Media Player 9 (KB936782)
Security Update for Windows XP (KB2079403)
Security Update for Windows XP (KB2115168)
Security Update for Windows XP (KB2121546)
Security Update for Windows XP (KB2160329)
Security Update for Windows XP (KB2229593)
Security Update for Windows XP (KB2259922)
Security Update for Windows XP (KB2279986)
Security Update for Windows XP (KB2286198)
Security Update for Windows XP (KB2296011)
Security Update for Windows XP (KB2296199)
Security Update for Windows XP (KB2347290)
Security Update for Windows XP (KB2360937)
Security Update for Windows XP (KB2387149)
Security Update for Windows XP (KB2419632)
Security Update for Windows XP (KB2423089)
Security Update for Windows XP (KB2436673)
Security Update for Windows XP (KB2440591)
Security Update for Windows XP (KB2443105)
Security Update for Windows XP (KB923561)
Security Update for Windows XP (KB923689)
Security Update for Windows XP (KB923789)
Security Update for Windows XP (KB938464-v2)
Security Update for Windows XP (KB938464)
Security Update for Windows XP (KB941569)
Security Update for Windows XP (KB946648)
Security Update for Windows XP (KB950759)
Security Update for Windows XP (KB950760)
Security Update for Windows XP (KB950762)
Security Update for Windows XP (KB950974)
Security Update for Windows XP (KB951066)
Security Update for Windows XP (KB951376-v2)
Security Update for Windows XP (KB951376)
Security Update for Windows XP (KB951698)
Security Update for Windows XP (KB951748)
Security Update for Windows XP (KB952004)
Security Update for Windows XP (KB952954)
Security Update for Windows XP (KB953838)
Security Update for Windows XP (KB953839)
Security Update for Windows XP (KB954211)
Security Update for Windows XP (KB954459)
Security Update for Windows XP (KB954600)
Security Update for Windows XP (KB955069)
Security Update for Windows XP (KB956390)
Security Update for Windows XP (KB956391)
Security Update for Windows XP (KB956572)
Security Update for Windows XP (KB956744)
Security Update for Windows XP (KB956802)
Security Update for Windows XP (KB956803)
Security Update for Windows XP (KB956841)
Security Update for Windows XP (KB956844)
Security Update for Windows XP (KB957095)
Security Update for Windows XP (KB957097)
Security Update for Windows XP (KB958215)
Security Update for Windows XP (KB958644)
Security Update for Windows XP (KB958687)
Security Update for Windows XP (KB958690)
Security Update for Windows XP (KB958869)
Security Update for Windows XP (KB959426)
Security Update for Windows XP (KB960225)
Security Update for Windows XP (KB960714)
Security Update for Windows XP (KB960715)
Security Update for Windows XP (KB960803)
Security Update for Windows XP (KB960859)
Security Update for Windows XP (KB961371)
Security Update for Windows XP (KB961373)
Security Update for Windows XP (KB961501)
Security Update for Windows XP (KB963027)
Security Update for Windows XP (KB968537)
Security Update for Windows XP (KB969059)
Security Update for Windows XP (KB969897)
Security Update for Windows XP (KB969898)
Security Update for Windows XP (KB969947)
Security Update for Windows XP (KB970238)
Security Update for Windows XP (KB970430)
Security Update for Windows XP (KB971468)
Security Update for Windows XP (KB971486)
Security Update for Windows XP (KB971557)
Security Update for Windows XP (KB971633)
Security Update for Windows XP (KB971657)
Security Update for Windows XP (KB971961)
Security Update for Windows XP (KB972270)
Security Update for Windows XP (KB973346)
Security Update for Windows XP (KB973354)
Security Update for Windows XP (KB973507)
Security Update for Windows XP (KB973525)
Security Update for Windows XP (KB973869)
Security Update for Windows XP (KB973904)
Security Update for Windows XP (KB974112)
Security Update for Windows XP (KB974318)
Security Update for Windows XP (KB974392)
Security Update for Windows XP (KB974571)
Security Update for Windows XP (KB975025)
Security Update for Windows XP (KB975467)
Security Update for Windows XP (KB975560)
Security Update for Windows XP (KB975561)
Security Update for Windows XP (KB975562)
Security Update for Windows XP (KB975713)
Security Update for Windows XP (KB977165-v2)
Security Update for Windows XP (KB977816)
Security Update for Windows XP (KB977914)
Security Update for Windows XP (KB978037)
Security Update for Windows XP (KB978251)
Security Update for Windows XP (KB978262)
Security Update for Windows XP (KB978338)
Security Update for Windows XP (KB978542)
Security Update for Windows XP (KB978601)
Security Update for Windows XP (KB978706)
Security Update for Windows XP (KB979309)
Security Update for Windows XP (KB979482)
Security Update for Windows XP (KB979559)
Security Update for Windows XP (KB979683)
Security Update for Windows XP (KB979687)
Security Update for Windows XP (KB980195)
Security Update for Windows XP (KB980218)
Security Update for Windows XP (KB980232)
Security Update for Windows XP (KB980436)
Security Update for Windows XP (KB981322)
Security Update for Windows XP (KB981349)
Security Update for Windows XP (KB981852)
Security Update for Windows XP (KB981957)
Security Update for Windows XP (KB981997)
Security Update for Windows XP (KB982132)
Security Update for Windows XP (KB982214)
Security Update for Windows XP (KB982665)
Security Update for Windows XP (KB982802)
Smart Menus (Windows Live Toolbar)
Softwheels F&I System
Softwheels F&I System Protection Menu Setup Utility
SweetIM For Internet Explorer 3.0b
The Business Assistant
Update for Microsoft .NET Framework 3.5 SP1 (KB963707)
Update for Windows Internet Explorer 7 (KB976749)
Update for Windows Internet Explorer 7 (KB980182)
Update for Windows XP (KB2141007)
Update for Windows XP (KB2345886)
Update for Windows XP (KB2467659)
Update for Windows XP (KB951072-v2)
Update for Windows XP (KB951978)
Update for Windows XP (KB955759)
Update for Windows XP (KB955839)
Update for Windows XP (KB967715)
Update for Windows XP (KB968389)
Update for Windows XP (KB971737)
Update for Windows XP (KB973687)
Update for Windows XP (KB973815)
Viewpoint Media Player
WebFldrs XP
Windows Feature Pack for Storage (32-bit) - IMAPI update for Blu-Ray
Windows Imaging Component
Windows Internet Explorer 7
Windows Live Favorites for Windows Live Toolbar
Windows Live installer
Windows Live Mail
Windows Live Messenger
Windows Live Photo Gallery
Windows Live Sign-in Assistant
Windows Live Toolbar
Windows Live Toolbar Extension (Windows Live Toolbar)
Windows Live Writer
Windows Media Format Runtime
Windows XP Service Pack 3
Workspace Desktop

==== Event Viewer Messages From Past Week ========

2/9/2011 11:11:01 AM, error: System Error [1003] - Error code 1000007f, parameter1 0000000d, parameter2 00000000, parameter3 00000000, parameter4 00000000.
2/9/2011 11:09:45 AM, error: Microsoft Antimalware [2001] - Microsoft Antimalware has encountered an error trying to update signatures. New Signature Version: Previous Signature Version: 1.97.1055.0 Update Source: Microsoft Update Server Update Stage: Search Source Path: http://www.microsoft.com Signature Type: AntiVirus Update Type: Full User: NT AUTHORITY\SYSTEM Current Engine Version: Previous Engine Version: 1.1.6502.0 Error code: 0x8024402c Error description: An unexpected problem occurred while checking for updates. For information on installing or troubleshooting updates, see Help and Support.
2/9/2011 10:57:28 AM, error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: Fips intelppm MpFilter
2/9/2011 10:56:27 AM, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service EventSystem with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF}
2/8/2011 5:39:39 PM, error: Service Control Manager [7034] - The Application Layer Gateway Service service terminated unexpectedly. It has done this 1 time(s).
2/8/2011 10:30:55 AM, error: Microsoft Antimalware [2001] - Microsoft Antimalware has encountered an error trying to update signatures. New Signature Version: Previous Signature Version: 1.97.1055.0 Update Source: Microsoft Update Server Update Stage: Search Source Path: http://www.microsoft.com Signature Type: AntiVirus Update Type: Full User: NT AUTHORITY\SYSTEM Current Engine Version: Previous Engine Version: 1.1.6502.0 Error code: 0x80072efe Error description: The connection with the server was terminated abnormally
2/7/2011 2:41:06 PM, error: DCOM [10005] - DCOM got error "%1053" attempting to start the service EventSystem with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF}
2/7/2011 10:23:30 AM, error: Microsoft Antimalware [2001] - Microsoft Antimalware has encountered an error trying to update signatures. New Signature Version: Previous Signature Version: 1.97.1055.0 Update Source: Microsoft Update Server Update Stage: Search Source Path: http://www.microsoft.com Signature Type: AntiVirus Update Type: Full User: NT AUTHORITY\SYSTEM Current Engine Version: Previous Engine Version: 1.1.6502.0 Error code: 0x80072efe Error description: The connection with the server was terminated abnormally
2/5/2011 9:48:39 AM, error: Service Control Manager [7022] - The Automatic Updates service hung on starting.
2/5/2011 4:29:01 PM, error: Microsoft Antimalware [2001] - Microsoft Antimalware has encountered an error trying to update signatures. New Signature Version: Previous Signature Version: 1.97.1055.0 Update Source: Microsoft Update Server Update Stage: Search Source Path: http://www.microsoft.com Signature Type: AntiVirus Update Type: Full User: NT AUTHORITY\SYSTEM Current Engine Version: Previous Engine Version: 1.1.6502.0 Error code: 0x80072efe Error description: The connection with the server was terminated abnormally
2/4/2011 3:41:31 PM, error: Service Control Manager [7031] - The Google Software Updater service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 900000 milliseconds: Restart the service.
2/4/2011 3:28:35 PM, error: Microsoft Antimalware [2001] - Microsoft Antimalware has encountered an error trying to update signatures. New Signature Version: Previous Signature Version: 0.0.0.0 Update Source: Microsoft Update Server Update Stage: Search Source Path: http://www.microsoft.com Signature Type: AntiVirus Update Type: Full User: NT AUTHORITY\SYSTEM Current Engine Version: Previous Engine Version: 0.0.0.0 Error code: 0x80072efe Error description: The connection with the server was terminated abnormally
2/4/2011 2:41:41 PM, error: Service Control Manager [7009] - Timeout (30000 milliseconds) waiting for the Bwkokxdc service to connect.
2/3/2011 7:38:39 PM, error: BROWSER [8007] - The browser was unable to update the service status bits. The data is the error.
2/3/2011 4:50:47 PM, error: Service Control Manager [7034] - The NMIndexingService service terminated unexpectedly. It has done this 1 time(s).
2/3/2011 12:42:17 PM, error: Service Control Manager [7023] - The Application Management service terminated with the following error: The specified module could not be found.
2/3/2011 11:07:05 AM, error: Service Control Manager [7034] - The Bwkokxdc service terminated unexpectedly. It has done this 1 time(s).
2/3/2011 10:55:45 AM, error: Dhcp [1002] - The IP address lease 10.0.0.108 for the Network Card with network address 001BFCEC3D83 has been denied by the DHCP server 10.0.0.100 (The DHCP Server sent a DHCPNACK message).
2/2/2011 4:57:31 PM, error: Service Control Manager [7011] - Timeout (30000 milliseconds) waiting for a transaction response from the service.
2/2/2011 4:57:01 PM, error: Service Control Manager [7011] - Timeout (30000 milliseconds) waiting for a transaction response from the File Backup service.

==== End Of File ===========================


dds.txt log


DDS (Ver_10-12-12.02) - NTFSx86
Run by MANAGER at 11:37:19.18 on Wed 02/09/2011
Internet Explorer: 7.0.5730.13
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.1015.489 [GMT -8:00]

AV: Microsoft Security Essentials *Enabled/Updated* {EDB4FA23-53B8-4AFA-8C5D-99752CCA7095}

============== Running Processes ===============

C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
c:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
C:\WINDOWS\system32\spoolsv.exe
svchost.exe
C:\Program Files\Starfield\offSyncService.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\CyberLink\Shared files\RichVideo.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\system32\igfxpers.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\WINDOWS\system32\fonts\mru2\system\clocksvr.exe
C:\Program Files\Microsoft Security Client\msseces.exe
C:\WINDOWS\system32\lgbpd.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Starfield\StarfieldUpdate.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
c:\Program Files\Microsoft Security Client\Antimalware\MpCmdRun.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Windows Live Toolbar\MSNTBUP.EXE
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\MANAGER\Local Settings\Temporary Internet Files\Content.IE5\G0DOB21Y\dds[1].scr

============== Pseudo HJT Report ===============

uStart Page = hxxp://www.powertoys.com/
uSearch Page = hxxp://www.google.com
uSearch Bar = hxxp://www.google.com/ie
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
uInternet Connection Wizard,ShellNext = iexplore
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
mSearchAssistant = hxxp://www.google.com/ie
uURLSearchHooks: SweetIM For Internet Explorer: {bc4ffe41-de9f-46fa-b455-aad49b9f9938} - c:\program files\macrogaming\sweetimbarforie\toolbar.dll
mURLSearchHooks: SweetIM For Internet Explorer: {bc4ffe41-de9f-46fa-b455-aad49b9f9938} - c:\program files\macrogaming\sweetimbarforie\toolbar.dll
BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelper.dll
BHO: SWEETIE Class: {1a0aadcd-3a72-4b5f-900f-e3bb5a838e2a} - c:\progra~1\macrog~1\sweeti~1\toolbar.dll
BHO: {7E853D72-626A-48EC-A868-BA8D5E23E045} - No File
BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.6.5805.1910\swg.dll
BHO: Windows Live Toolbar Helper: {bdbd1dad-c946-4a17-adc1-64b5b4ff55d0} - c:\program files\windows live toolbar\msntb.dll
BHO: 1 (0x1) - No File
TB: SweetIM For Internet Explorer: {bc4ffe41-de9f-46fa-b455-aad49b9f9938} - c:\program files\macrogaming\sweetimbarforie\toolbar.dll
TB: Windows Live Toolbar: {bdad1dad-c946-4a17-adc1-64b5b4ff55d0} - c:\program files\windows live toolbar\msntb.dll
TB: Ask Toolbar: {3041d03e-fd4b-44e0-b742-2d9b88305f98} - c:\program files\askbardis\bar\bin\askBar.dll
uRun: [LGBLiveUpdate] c:\windows\system32\lgbpd.exe
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
uRun: [Starfield Updater] "c:\program files\starfield\StarfieldUpdate.exe"
uRun: [swg] "c:\program files\google\googletoolbarnotifier\GoogleToolbarNotifier.exe"
mRun: [IgfxTray] c:\windows\system32\igfxtray.exe
mRun: [HotKeysCmds] c:\windows\system32\hkcmd.exe
mRun: [Persistence] c:\windows\system32\igfxpers.exe
mRun: [RTHDCPL] RTHDCPL.EXE
mRun: [SkyTel] SkyTel.EXE
mRun: [Alcmtr] ALCMTR.EXE
mRun: [SofTek] c:\program files\softek software\lib\Updateexec.exe
mRun: [TkBellExe] "c:\program files\common files\real\update_ob\realsched.exe" -osboot
mRun: [SystemClockSvr] c:\windows\system32\fonts\mru2\system\clocksvr.exe
mRun: [MSC] "c:\program files\microsoft security client\msseces.exe" -hide -runkey
dRun: [msnmsgr] "c:\program files\windows live\messenger\msnmsgr.exe" /background
dRun: [yHXnrnwPQYDdJrS.exe] c:\documents and settings\all users\application data\yHXnrnwPQYDdJrS.exe
IE: &Windows Live Search - c:\program files\windows live toolbar\msntb.dll/search.htm
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: Add to Windows &Live Favorites - http://favorites.live.com/quickadd.aspx
IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office11\EXCEL.EXE/3000
IE: Google Sidewiki... - c:\program files\google\google toolbar\component\GoogleToolbarDynamic_mui_en_E11712C84EA7E12B.dll/cmsidewiki.html
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - c:\program files\windows live\writer\WriterBrowserExtension.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office11\REFIEBAR.DLL
DPF: Web-Based Email Tools - hxxp://email.secureserver.net/Download.CAB
DPF: {447F8438-8124-4369-905B-A249E13CBBFC} - hxxp://pre.liveglobalbid.com/lgbkc.cab
DPF: {7206EAAC-5CFA-43A3-9F61-E27E8E51E42F} - hxxp://npsports.liveblockauctions.com/container_repository/laiexec2.cab
DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} - hxxp://upload.facebook.com/controls/2009.07.28_v5.5.8.1/FacebookPhotoUploader55.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
Notify: igfxcui - igfxdev.dll
Hosts: 172.16.32.146 www.squidoo.com
Hosts: 172.16.32.146 squidoo.com
Hosts: 172.16.32.146 ebayphonenumber.net
Hosts: 172.16.32.146 www.ebayphonenumber.net
Hosts: 172.16.32.146 askville.amazon.com

Note: multiple HOSTS entries found. Please refer to Attach.txt

============= SERVICES / DRIVERS ===============

R1 MpFilter;Microsoft Malware Protection Driver;c:\windows\system32\drivers\MpFilter.sys [2010-10-24 165264]
R1 MpKsl9d53cb10;MpKsl9d53cb10;\??\c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{81984812-cecd-4a03-a9df-fe86f558bdcb}\mpksl9d53cb10.sys --> c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{81984812-cecd-4a03-a9df-fe86f558bdcb}\MpKsl9d53cb10.sys [?]
R1 MpKslf06e3aa2;MpKslf06e3aa2;c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{004159de-cf05-4208-841a-cc3f4b5ab84f}\MpKslf06e3aa2.sys [2011-2-9 28752]
R2 File Backup;File Backup Service;c:\program files\starfield\offSyncService.exe [2010-7-16 1215216]
R2 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\viewpoint\common\ViewpointService.exe [2008-1-9 24652]
S1 MpKsl19abeef7;MpKsl19abeef7;\??\c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{81984812-cecd-4a03-a9df-fe86f558bdcb}\mpksl19abeef7.sys --> c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{81984812-cecd-4a03-a9df-fe86f558bdcb}\MpKsl19abeef7.sys [?]
S2 gupdate;Google Update Service (gupdate);c:\program files\google\update\GoogleUpdate.exe [2009-12-21 135664]

=============== Created Last 30 ================

2011-02-09 19:34:14 28752 ----a-w- c:\docume~1\alluse~1\applic~1\microsoft\microsoft antimalware\definition updates\{004159de-cf05-4208-841a-cc3f4b5ab84f}\MpKslf06e3aa2.sys
2011-02-09 19:34:05 5890896 ----a-w- c:\docume~1\alluse~1\applic~1\microsoft\microsoft antimalware\definition updates\{004159de-cf05-4208-841a-cc3f4b5ab84f}\mpengine.dll
2011-02-07 20:28:57 377856 ----a-w- c:\docume~1\alluse~1\applic~1\MiKiuGqssiE.exe
2011-02-07 20:07:13 377856 ----a-w- c:\docume~1\alluse~1\applic~1\qpn7xOKw.exe
2011-02-07 20:07:10 422400 ----a-w- c:\docume~1\alluse~1\applic~1\iXMTiRKsRtiRxqG.dll
2011-02-07 20:07:08 457728 ----a-w- c:\docume~1\alluse~1\applic~1\yHXnrnwPQYDdJrS.exe
2011-02-04 23:35:21 222080 ------w- c:\windows\system32\MpSigStub.exe
2011-02-04 23:26:45 -------- d-----w- c:\program files\Microsoft Security Client
2011-02-04 22:42:59 -------- d-----w- c:\windows\pss
2011-02-04 00:33:44 -------- d-----w- c:\windows\system32\wbem\repository\FS
2011-02-04 00:33:44 -------- d-----w- c:\windows\system32\wbem\Repository
2011-02-04 00:33:28 -------- d-----w- c:\program files\FOX News Live
2011-02-04 00:33:27 -------- d-----w- c:\program files\MessagePal
2011-02-04 00:33:18 -------- d-----w- c:\program files\AskBarDis
2011-02-04 00:33:17 -------- d-----w- c:\docume~1\manager\locals~1\applic~1\AOL OCP
2011-02-04 00:33:11 -------- d-----w- c:\program files\AIM6
2011-01-12 21:35:39 -------- d-----w- c:\docume~1\manager\applic~1\Malwarebytes
2011-01-12 21:35:35 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2011-01-12 21:35:34 -------- d-----w- c:\docume~1\alluse~1\applic~1\Malwarebytes
2011-01-12 21:35:32 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
2011-01-12 21:35:32 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware

==================== Find3M ====================

2010-12-02 03:35:18 4280320 ----a-w- c:\windows\system32\GPhotos.scr
2010-11-18 18:12:44 81920 ----a-w- c:\windows\system32\isign32.dll

=================== ROOTKIT ====================

Stealth MBR rootkit/Mebroot/Sinowal/TDL4 detector 0.4.2 by Gmer, http://www.gmer.net
Windows 5.1.2600 Disk: WDC_WD1600AAJS-00PSA0 rev.05.06H05 -> Harddisk0\DR0 -> \Device\Ide\IdePort2 P2T0L0-e

device: opened successfully
user: MBR read successfully

Disk trace:
called modules: ntkrnlpa.exe CLASSPNP.SYS disk.sys ACPI.sys hal.dll >>UNKNOWN [0x86D635AF]<<
_asm { PUSH EBP; MOV EBP, ESP; PUSH ECX; MOV EAX, [EBP+0x8]; CMP EAX, [0x86d697b0]; MOV EAX, [0x86d6982c]; PUSH EBX; PUSH ESI; MOV ESI, [EBP+0xc]; MOV EBX, [ESI+0x60]; PUSH EDI; JNZ 0x20; MOV [EBP+0x8], EAX; }
1 ntkrnlpa!IofCallDriver[0x804EF1A6] -> \Device\Harddisk0\DR0[0x86DD6AB8]
3 CLASSPNP[0xF7508FD7] -> ntkrnlpa!IofCallDriver[0x804EF1A6] -> \Device\0000005e[0x86DD79E8]
5 ACPI[0xF739F620] -> ntkrnlpa!IofCallDriver[0x804EF1A6] -> [0x86D7C940]
\Driver\atapi[0x86DA6C08] -> IRP_MJ_CREATE -> 0x86D635AF
kernel: MBR read successfully
_asm { XOR AX, AX; MOV SS, AX; MOV SP, 0x7c00; STI ; PUSH AX; POP ES; PUSH AX; POP DS; CLD ; MOV SI, 0x7c1b; MOV DI, 0x61b; PUSH AX; PUSH DI; MOV CX, 0x1e5; REP MOVSB ; RETF ; MOV BP, 0x7be; MOV CL, 0x4; CMP [BP+0x0], CH; JL 0x2e; JNZ 0x3a; }
detected disk devices:
\Device\Ide\IdeDeviceP2T0L0-e -> \??\IDE#DiskWDC_WD1600AAJS-00PSA0___________________05.06H05#5&3003bd5e&0&0.0.0#{53f56307-b6bf-11d0-94f2-00a0c91efb8b} device not found
detected hooks:
\Driver\atapi DriverStartIo -> 0x86D633F5
user & kernel MBR OK
Warning: possible TDL3 rootkit infection !

============= FINISH: 11:38:25.82 ===============
 
Malwarebytes' Anti-Malware 1.50.1.1100
www.malwarebytes.org

Database version: 5722

Windows 5.1.2600 Service Pack 3
Internet Explorer 7.0.5730.13

2/9/2011 12:01:16 PM
mbam-log-2011-02-09 (12-01-16).txt

Scan type: Quick scan
Objects scanned: 183105
Time elapsed: 19 minute(s), 16 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 1
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 7

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\yHXnrnwPQYDdJrS.exe (Trojan.Agent) -> Value: yHXnrnwPQYDdJrS.exe -> Quarantined and deleted successfully.

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
c:\documents and settings\all users\application data\yhxnrnwpqyddjrs.exe (Trojan.Agent) -> Quarantined and deleted successfully.
c:\documents and settings\all users\application data\ixmtirksrtirxqg.dll (Trojan.Agent) -> Quarantined and deleted successfully.
c:\documents and settings\all users\application data\mikiugqssie.exe (Rogue.WindowsDisk) -> Quarantined and deleted successfully.
c:\documents and settings\all users\application data\qpn7xOKw.exe (Rogue.WindowsDisk) -> Quarantined and deleted successfully.
c:\WINDOWS\Temp\tmp1D.tmp (Trojan.Agent) -> Quarantined and deleted successfully.
c:\documents and settings\networkservice\local settings\temporary internet files\Content.IE5\UD6XG78P\media[1].rc (Trojan.Agent) -> Quarantined and deleted successfully.
c:\WINDOWS\Temp\internetexplorerupdate.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
 
You're infected with a rootkit.

Download TDSSKiller and save it to your desktop.

  • Extract (unzip) its contents to your desktop.
  • Open the TDSSKiller folder and doubleclick on TDSSKiller.exe to run the application, then on Start Scan.
  • If an infected file is detected, the default action will be Cure, click on Continue.
  • If a suspicious file is detected, the default action will be Skip, click on Continue.
  • It may ask you to reboot the computer to complete the process. Click on Reboot Now.
  • If no reboot is require, click on Report. A log file should appear. Please copy and paste the contents of that file here.
  • If a reboot is required, the report can also be found in your root directory (usually C:\ folder) in the form of TDSSKiller_xxxx_log.txt. Please copy and paste the contents of that file here.
 
2011/02/09 12:30:21.0765 1316 TDSS rootkit removing tool 2.4.16.0 Feb 1 2011 10:34:03
2011/02/09 12:30:22.0406 1316 ================================================================================
2011/02/09 12:30:22.0406 1316 SystemInfo:
2011/02/09 12:30:22.0406 1316
2011/02/09 12:30:22.0406 1316 OS Version: 5.1.2600 ServicePack: 3.0
2011/02/09 12:30:22.0406 1316 Product type: Workstation
2011/02/09 12:30:22.0406 1316 ComputerName: FINANCE
2011/02/09 12:30:22.0421 1316 UserName: MANAGER
2011/02/09 12:30:22.0421 1316 Windows directory: C:\WINDOWS
2011/02/09 12:30:22.0421 1316 System windows directory: C:\WINDOWS
2011/02/09 12:30:22.0421 1316 Processor architecture: Intel x86
2011/02/09 12:30:22.0421 1316 Number of processors: 2
2011/02/09 12:30:22.0421 1316 Page size: 0x1000
2011/02/09 12:30:22.0421 1316 Boot type: Normal boot
2011/02/09 12:30:22.0421 1316 ================================================================================
2011/02/09 12:30:23.0140 1316 Initialize success
2011/02/09 12:30:35.0781 0244 ================================================================================
2011/02/09 12:30:35.0781 0244 Scan started
2011/02/09 12:30:35.0781 0244 Mode: Manual;
2011/02/09 12:30:35.0781 0244 ================================================================================
2011/02/09 12:30:36.0078 0244 ACPI (8fd99680a539792a30e97944fdaecf17) C:\WINDOWS\system32\DRIVERS\ACPI.sys
2011/02/09 12:30:36.0125 0244 ACPIEC (9859c0f6936e723e4892d7141b1327d5) C:\WINDOWS\system32\drivers\ACPIEC.sys
2011/02/09 12:30:36.0171 0244 aec (8bed39e3c35d6a489438b8141717a557) C:\WINDOWS\system32\drivers\aec.sys
2011/02/09 12:30:36.0218 0244 AFD (7e775010ef291da96ad17ca4b17137d7) C:\WINDOWS\System32\drivers\afd.sys
2011/02/09 12:30:36.0421 0244 AsyncMac (b153affac761e7f5fcfa822b9c4e97bc) C:\WINDOWS\system32\DRIVERS\asyncmac.sys
2011/02/09 12:30:36.0437 0244 atapi (9f3a2f5aa6875c72bf062c712cfa2674) C:\WINDOWS\system32\DRIVERS\atapi.sys
2011/02/09 12:30:36.0484 0244 AtcL002 (ead4f7c4a9233bcb93ac75b788e7255d) C:\WINDOWS\system32\DRIVERS\l251x86.sys
2011/02/09 12:30:36.0546 0244 Atmarpc (9916c1225104ba14794209cfa8012159) C:\WINDOWS\system32\DRIVERS\atmarpc.sys
2011/02/09 12:30:36.0578 0244 audstub (d9f724aa26c010a217c97606b160ed68) C:\WINDOWS\system32\DRIVERS\audstub.sys
2011/02/09 12:30:36.0656 0244 Beep (da1f27d85e0d1525f6621372e7b685e9) C:\WINDOWS\system32\drivers\Beep.sys
2011/02/09 12:30:36.0703 0244 cbidf2k (90a673fc8e12a79afbed2576f6a7aaf9) C:\WINDOWS\system32\drivers\cbidf2k.sys
2011/02/09 12:30:36.0750 0244 Cdaudio (c1b486a7658353d33a10cc15211a873b) C:\WINDOWS\system32\drivers\Cdaudio.sys
2011/02/09 12:30:36.0796 0244 Cdfs (c885b02847f5d2fd45a24e219ed93b32) C:\WINDOWS\system32\drivers\Cdfs.sys
2011/02/09 12:30:36.0828 0244 Cdrom (1f4260cc5b42272d71f79e570a27a4fe) C:\WINDOWS\system32\DRIVERS\cdrom.sys
2011/02/09 12:30:36.0984 0244 Disk (044452051f3e02e7963599fc8f4f3e25) C:\WINDOWS\system32\DRIVERS\disk.sys
2011/02/09 12:30:37.0046 0244 dmboot (d992fe1274bde0f84ad826acae022a41) C:\WINDOWS\system32\drivers\dmboot.sys
2011/02/09 12:30:37.0078 0244 dmio (7c824cf7bbde77d95c08005717a95f6f) C:\WINDOWS\system32\drivers\dmio.sys
2011/02/09 12:30:37.0109 0244 dmload (e9317282a63ca4d188c0df5e09c6ac5f) C:\WINDOWS\system32\drivers\dmload.sys
2011/02/09 12:30:37.0125 0244 DMusic (8a208dfcf89792a484e76c40e5f50b45) C:\WINDOWS\system32\drivers\DMusic.sys
2011/02/09 12:30:37.0187 0244 drmkaud (8f5fcff8e8848afac920905fbd9d33c8) C:\WINDOWS\system32\drivers\drmkaud.sys
2011/02/09 12:30:37.0250 0244 Fastfat (38d332a6d56af32635675f132548343e) C:\WINDOWS\system32\drivers\Fastfat.sys
2011/02/09 12:30:37.0296 0244 Fdc (92cdd60b6730b9f50f6a1a0c1f8cdc81) C:\WINDOWS\system32\drivers\Fdc.sys
2011/02/09 12:30:37.0328 0244 Fips (d45926117eb9fa946a6af572fbe1caa3) C:\WINDOWS\system32\drivers\Fips.sys
2011/02/09 12:30:37.0343 0244 Flpydisk (9d27e7b80bfcdf1cdd9b555862d5e7f0) C:\WINDOWS\system32\drivers\Flpydisk.sys
2011/02/09 12:30:37.0390 0244 FltMgr (b2cf4b0786f8212cb92ed2b50c6db6b0) C:\WINDOWS\system32\drivers\fltmgr.sys
2011/02/09 12:30:37.0437 0244 Fs_Rec (3e1e2bd4f39b0e2b7dc4f4d2bcc2779a) C:\WINDOWS\system32\drivers\Fs_Rec.sys
2011/02/09 12:30:37.0453 0244 Ftdisk (6ac26732762483366c3969c9e4d2259d) C:\WINDOWS\system32\DRIVERS\ftdisk.sys
2011/02/09 12:30:37.0484 0244 Gpc (0a02c63c8b144bd8c86b103dee7c86a2) C:\WINDOWS\system32\DRIVERS\msgpc.sys
2011/02/09 12:30:37.0609 0244 HDAudBus (573c7d0a32852b48f3058cfd8026f511) C:\WINDOWS\system32\DRIVERS\HDAudBus.sys
2011/02/09 12:30:37.0640 0244 HidUsb (ccf82c5ec8a7326c3066de870c06daf1) C:\WINDOWS\system32\DRIVERS\hidusb.sys
2011/02/09 12:30:37.0718 0244 HTTP (f80a415ef82cd06ffaf0d971528ead38) C:\WINDOWS\system32\Drivers\HTTP.sys
2011/02/09 12:30:37.0781 0244 i8042prt (4a0b06aa8943c1e332520f7440c0aa30) C:\WINDOWS\system32\DRIVERS\i8042prt.sys
2011/02/09 12:30:37.0843 0244 ialm (6fcb904910da07c9dc2593d66438fa29) C:\WINDOWS\system32\DRIVERS\igxpmp32.sys
2011/02/09 12:30:37.0890 0244 Imapi (083a052659f5310dd8b6a6cb05edcf8e) C:\WINDOWS\system32\DRIVERS\imapi.sys
2011/02/09 12:30:38.0078 0244 IntcAzAudAddService (cdfd5a68a2e1caa89c5c0e0b3cb98731) C:\WINDOWS\system32\drivers\RtkHDAud.sys
2011/02/09 12:30:38.0234 0244 intelppm (8c953733d8f36eb2133f5bb58808b66b) C:\WINDOWS\system32\DRIVERS\intelppm.sys
2011/02/09 12:30:38.0265 0244 Ip6Fw (3bb22519a194418d5fec05d800a19ad0) C:\WINDOWS\system32\drivers\ip6fw.sys
2011/02/09 12:30:38.0328 0244 IpFilterDriver (731f22ba402ee4b62748adaf6363c182) C:\WINDOWS\system32\DRIVERS\ipfltdrv.sys
2011/02/09 12:30:38.0375 0244 IpInIp (b87ab476dcf76e72010632b5550955f5) C:\WINDOWS\system32\DRIVERS\ipinip.sys
2011/02/09 12:30:38.0453 0244 IpNat (cc748ea12c6effde940ee98098bf96bb) C:\WINDOWS\system32\DRIVERS\ipnat.sys
2011/02/09 12:30:38.0468 0244 IPSec (23c74d75e36e7158768dd63d92789a91) C:\WINDOWS\system32\DRIVERS\ipsec.sys
2011/02/09 12:30:38.0531 0244 IRENUM (c93c9ff7b04d772627a3646d89f7bf89) C:\WINDOWS\system32\DRIVERS\irenum.sys
2011/02/09 12:30:38.0578 0244 isapnp (05a299ec56e52649b1cf2fc52d20f2d7) C:\WINDOWS\system32\DRIVERS\isapnp.sys
2011/02/09 12:30:38.0609 0244 Kbdclass (463c1ec80cd17420a542b7f36a36f128) C:\WINDOWS\system32\DRIVERS\kbdclass.sys
2011/02/09 12:30:38.0656 0244 kbdhid (9ef487a186dea361aa06913a75b3fa99) C:\WINDOWS\system32\DRIVERS\kbdhid.sys
2011/02/09 12:30:38.0671 0244 kmixer (692bcf44383d056aed41b045a323d378) C:\WINDOWS\system32\drivers\kmixer.sys
2011/02/09 12:30:38.0703 0244 KSecDD (b467646c54cc746128904e1654c750c1) C:\WINDOWS\system32\drivers\KSecDD.sys
2011/02/09 12:30:38.0812 0244 mnmdd (4ae068242760a1fb6e1a44bf4e16afa6) C:\WINDOWS\system32\drivers\mnmdd.sys
2011/02/09 12:30:38.0843 0244 Modem (dfcbad3cec1c5f964962ae10e0bcc8e1) C:\WINDOWS\system32\drivers\Modem.sys
2011/02/09 12:30:38.0875 0244 Mouclass (35c9e97194c8cfb8430125f8dbc34d04) C:\WINDOWS\system32\DRIVERS\mouclass.sys
2011/02/09 12:30:38.0937 0244 mouhid (b1c303e17fb9d46e87a98e4ba6769685) C:\WINDOWS\system32\DRIVERS\mouhid.sys
2011/02/09 12:30:38.0953 0244 MountMgr (a80b9a0bad1b73637dbcbba7df72d3fd) C:\WINDOWS\system32\drivers\MountMgr.sys
2011/02/09 12:30:39.0000 0244 MpFilter (7e34bfa1a7b60bba1da03d677f16cd63) C:\WINDOWS\system32\DRIVERS\MpFilter.sys
2011/02/09 12:30:39.0171 0244 MpKslca38c8c2 (5f53edfead46fa7adb78eee9ecce8fdf) c:\Documents and Settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{004159DE-CF05-4208-841A-CC3F4B5AB84F}\MpKslca38c8c2.sys
2011/02/09 12:30:39.0234 0244 MRxDAV (11d42bb6206f33fbb3ba0288d3ef81bd) C:\WINDOWS\system32\DRIVERS\mrxdav.sys
2011/02/09 12:30:39.0265 0244 MRxSmb (f3aefb11abc521122b67095044169e98) C:\WINDOWS\system32\DRIVERS\mrxsmb.sys
2011/02/09 12:30:39.0328 0244 Msfs (c941ea2454ba8350021d774daf0f1027) C:\WINDOWS\system32\drivers\Msfs.sys
2011/02/09 12:30:39.0421 0244 MSKSSRV (d1575e71568f4d9e14ca56b7b0453bf1) C:\WINDOWS\system32\drivers\MSKSSRV.sys
2011/02/09 12:30:39.0468 0244 MSPCLOCK (325bb26842fc7ccc1fcce2c457317f3e) C:\WINDOWS\system32\drivers\MSPCLOCK.sys
2011/02/09 12:30:39.0500 0244 MSPQM (bad59648ba099da4a17680b39730cb3d) C:\WINDOWS\system32\drivers\MSPQM.sys
2011/02/09 12:30:39.0578 0244 mssmbios (af5f4f3f14a8ea2c26de30f7a1e17136) C:\WINDOWS\system32\DRIVERS\mssmbios.sys
2011/02/09 12:30:39.0625 0244 MTsensor (d48659bb24c48345d926ecb45c1ebdf5) C:\WINDOWS\system32\DRIVERS\ASACPI.sys
2011/02/09 12:30:39.0671 0244 Mup (2f625d11385b1a94360bfc70aaefdee1) C:\WINDOWS\system32\drivers\Mup.sys
2011/02/09 12:30:39.0718 0244 NDIS (1df7f42665c94b825322fae71721130d) C:\WINDOWS\system32\drivers\NDIS.sys
2011/02/09 12:30:39.0750 0244 NdisTapi (1ab3d00c991ab086e69db84b6c0ed78f) C:\WINDOWS\system32\DRIVERS\ndistapi.sys
2011/02/09 12:30:39.0796 0244 Ndisuio (f927a4434c5028758a842943ef1a3849) C:\WINDOWS\system32\DRIVERS\ndisuio.sys
2011/02/09 12:30:39.0812 0244 NdisWan (edc1531a49c80614b2cfda43ca8659ab) C:\WINDOWS\system32\DRIVERS\ndiswan.sys
2011/02/09 12:30:39.0843 0244 NDProxy (9282bd12dfb069d3889eb3fcc1000a9b) C:\WINDOWS\system32\drivers\NDProxy.sys
2011/02/09 12:30:39.0859 0244 NetBIOS (5d81cf9a2f1a3a756b66cf684911cdf0) C:\WINDOWS\system32\DRIVERS\netbios.sys
2011/02/09 12:30:39.0906 0244 NetBT (74b2b2f5bea5e9a3dc021d685551bd3d) C:\WINDOWS\system32\DRIVERS\netbt.sys
2011/02/09 12:30:39.0968 0244 Npfs (3182d64ae053d6fb034f44b6def8034a) C:\WINDOWS\system32\drivers\Npfs.sys
2011/02/09 12:30:40.0031 0244 Ntfs (78a08dd6a8d65e697c18e1db01c5cdca) C:\WINDOWS\system32\drivers\Ntfs.sys
2011/02/09 12:30:40.0093 0244 Null (73c1e1f395918bc2c6dd67af7591a3ad) C:\WINDOWS\system32\drivers\Null.sys
2011/02/09 12:30:40.0156 0244 NwlnkFlt (b305f3fad35083837ef46a0bbce2fc57) C:\WINDOWS\system32\DRIVERS\nwlnkflt.sys
2011/02/09 12:30:40.0218 0244 NwlnkFwd (c99b3415198d1aab7227f2c88fd664b9) C:\WINDOWS\system32\DRIVERS\nwlnkfwd.sys
2011/02/09 12:30:40.0265 0244 Parport (5575faf8f97ce5e713d108c2a58d7c7c) C:\WINDOWS\system32\DRIVERS\parport.sys
2011/02/09 12:30:40.0296 0244 PartMgr (beb3ba25197665d82ec7065b724171c6) C:\WINDOWS\system32\drivers\PartMgr.sys
2011/02/09 12:30:40.0328 0244 ParVdm (70e98b3fd8e963a6a46a2e6247e0bea1) C:\WINDOWS\system32\drivers\ParVdm.sys
2011/02/09 12:30:40.0343 0244 PCI (a219903ccf74233761d92bef471a07b1) C:\WINDOWS\system32\DRIVERS\pci.sys
2011/02/09 12:30:40.0390 0244 PCIIde (ccf5f451bb1a5a2a522a76e670000ff0) C:\WINDOWS\system32\DRIVERS\pciide.sys
2011/02/09 12:30:40.0421 0244 Pcmcia (9e89ef60e9ee05e3f2eef2da7397f1c1) C:\WINDOWS\system32\drivers\Pcmcia.sys
2011/02/09 12:30:40.0593 0244 PptpMiniport (efeec01b1d3cf84f16ddd24d9d9d8f99) C:\WINDOWS\system32\DRIVERS\raspptp.sys
2011/02/09 12:30:40.0609 0244 PSched (09298ec810b07e5d582cb3a3f9255424) C:\WINDOWS\system32\DRIVERS\psched.sys
2011/02/09 12:30:40.0640 0244 Ptilink (80d317bd1c3dbc5d4fe7b1678c60cadd) C:\WINDOWS\system32\DRIVERS\ptilink.sys
2011/02/09 12:30:40.0687 0244 PxHelp20 (49452bfcec22f36a7a9b9c2181bc3042) C:\WINDOWS\system32\Drivers\PxHelp20.sys
2011/02/09 12:30:40.0812 0244 RasAcd (fe0d99d6f31e4fad8159f690d68ded9c) C:\WINDOWS\system32\DRIVERS\rasacd.sys
2011/02/09 12:30:40.0828 0244 Rasl2tp (11b4a627bc9614b885c4969bfa5ff8a6) C:\WINDOWS\system32\DRIVERS\rasl2tp.sys
2011/02/09 12:30:40.0859 0244 RasPppoe (5bc962f2654137c9909c3d4603587dee) C:\WINDOWS\system32\DRIVERS\raspppoe.sys
2011/02/09 12:30:40.0890 0244 Raspti (fdbb1d60066fcfbb7452fd8f9829b242) C:\WINDOWS\system32\DRIVERS\raspti.sys
2011/02/09 12:30:40.0921 0244 Rdbss (7ad224ad1a1437fe28d89cf22b17780a) C:\WINDOWS\system32\DRIVERS\rdbss.sys
2011/02/09 12:30:40.0953 0244 RDPCDD (4912d5b403614ce99c28420f75353332) C:\WINDOWS\system32\DRIVERS\RDPCDD.sys
2011/02/09 12:30:41.0000 0244 RDPWD (6728e45b66f93c08f11de2e316fc70dd) C:\WINDOWS\system32\drivers\RDPWD.sys
2011/02/09 12:30:41.0031 0244 redbook (f828dd7e1419b6653894a8f97a0094c5) C:\WINDOWS\system32\DRIVERS\redbook.sys
2011/02/09 12:30:41.0109 0244 RT61 (581e74880aeb1dba1cb5ac8e6e6c0a69) C:\WINDOWS\system32\DRIVERS\RT61.sys
2011/02/09 12:30:41.0187 0244 Secdrv (90a3935d05b494a5a39d37e71f09a677) C:\WINDOWS\system32\DRIVERS\secdrv.sys
2011/02/09 12:30:41.0250 0244 serenum (0f29512ccd6bead730039fb4bd2c85ce) C:\WINDOWS\system32\DRIVERS\serenum.sys
2011/02/09 12:30:41.0296 0244 Serial (cca207a8896d4c6a0c9ce29a4ae411a7) C:\WINDOWS\system32\DRIVERS\serial.sys
2011/02/09 12:30:41.0343 0244 Sfloppy (8e6b8c671615d126fdc553d1e2de5562) C:\WINDOWS\system32\drivers\Sfloppy.sys
2011/02/09 12:30:41.0421 0244 SONYPVU1 (a1eceeaa5c5e74b2499eb51d38185b84) C:\WINDOWS\system32\DRIVERS\SONYPVU1.SYS
2011/02/09 12:30:41.0484 0244 splitter (ab8b92451ecb048a4d1de7c3ffcb4a9f) C:\WINDOWS\system32\drivers\splitter.sys
2011/02/09 12:30:41.0531 0244 sr (76bb022c2fb6902fd5bdd4f78fc13a5d) C:\WINDOWS\system32\DRIVERS\sr.sys
2011/02/09 12:30:41.0593 0244 Srv (0f6aefad3641a657e18081f52d0c15af) C:\WINDOWS\system32\DRIVERS\srv.sys
2011/02/09 12:30:41.0640 0244 swenum (3941d127aef12e93addf6fe6ee027e0f) C:\WINDOWS\system32\DRIVERS\swenum.sys
2011/02/09 12:30:41.0671 0244 swmidi (8ce882bcc6cf8a62f2b2323d95cb3d01) C:\WINDOWS\system32\drivers\swmidi.sys
2011/02/09 12:30:41.0781 0244 sysaudio (8b83f3ed0f1688b4958f77cd6d2bf290) C:\WINDOWS\system32\drivers\sysaudio.sys
2011/02/09 12:30:41.0859 0244 Tcpip (9aefa14bd6b182d61e3119fa5f436d3d) C:\WINDOWS\system32\DRIVERS\tcpip.sys
2011/02/09 12:30:41.0906 0244 TDPIPE (6471a66807f5e104e4885f5b67349397) C:\WINDOWS\system32\drivers\TDPIPE.sys
2011/02/09 12:30:41.0937 0244 TDTCP (c56b6d0402371cf3700eb322ef3aaf61) C:\WINDOWS\system32\drivers\TDTCP.sys
2011/02/09 12:30:42.0000 0244 TermDD (88155247177638048422893737429d9e) C:\WINDOWS\system32\DRIVERS\termdd.sys
2011/02/09 12:30:42.0078 0244 Udfs (5787b80c2e3c5e2f56c2a233d91fa2c9) C:\WINDOWS\system32\drivers\Udfs.sys
2011/02/09 12:30:42.0140 0244 Update (402ddc88356b1bac0ee3dd1580c76a31) C:\WINDOWS\system32\DRIVERS\update.sys
2011/02/09 12:30:42.0187 0244 usbccgp (173f317ce0db8e21322e71b7e60a27e8) C:\WINDOWS\system32\DRIVERS\usbccgp.sys
2011/02/09 12:30:42.0234 0244 usbehci (65dcf09d0e37d4c6b11b5b0b76d470a7) C:\WINDOWS\system32\DRIVERS\usbehci.sys
2011/02/09 12:30:42.0296 0244 usbhub (1ab3cdde553b6e064d2e754efe20285c) C:\WINDOWS\system32\DRIVERS\usbhub.sys
2011/02/09 12:30:42.0343 0244 usbprint (a717c8721046828520c9edf31288fc00) C:\WINDOWS\system32\DRIVERS\usbprint.sys
2011/02/09 12:30:42.0375 0244 usbscan (a0b8cf9deb1184fbdd20784a58fa75d4) C:\WINDOWS\system32\DRIVERS\usbscan.sys
2011/02/09 12:30:42.0437 0244 USBSTOR (a32426d9b14a089eaa1d922e0c5801a9) C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS
2011/02/09 12:30:42.0468 0244 usbuhci (26496f9dee2d787fc3e61ad54821ffe6) C:\WINDOWS\system32\DRIVERS\usbuhci.sys
2011/02/09 12:30:42.0484 0244 VgaSave (0d3a8fafceacd8b7625cd549757a7df1) C:\WINDOWS\System32\drivers\vga.sys
2011/02/09 12:30:42.0562 0244 VolSnap (4c8fcb5cc53aab716d810740fe59d025) C:\WINDOWS\system32\drivers\VolSnap.sys
2011/02/09 12:30:42.0609 0244 Wanarp (e20b95baedb550f32dd489265c1da1f6) C:\WINDOWS\system32\DRIVERS\wanarp.sys
2011/02/09 12:30:42.0656 0244 wdmaud (6768acf64b18196494413695f0c3a00f) C:\WINDOWS\system32\drivers\wdmaud.sys
2011/02/09 12:30:42.0750 0244 \HardDisk0 - detected Rootkit.Win32.TDSS.tdl4 (0)
2011/02/09 12:30:42.0765 0244 ================================================================================
2011/02/09 12:30:42.0765 0244 Scan finished
2011/02/09 12:30:42.0765 0244 ================================================================================
2011/02/09 12:30:42.0765 0628 Detected object count: 1
2011/02/09 12:30:58.0781 0628 \HardDisk0 - will be cured after reboot
2011/02/09 12:30:58.0781 0628 Rootkit.Win32.TDSS.tdl4(\HardDisk0) - User select action: Cure
2011/02/09 12:31:18.0937 3936 Deinitialize success
 
Good :)

How is redirection?

Please download ComboFix from Here or Here to your Desktop.

**Note: In the event you already have Combofix, this is a new version that I need you to download. It is important that it is saved directly to your desktop**

  1. Please, never rename Combofix unless instructed.
  2. Close any open browsers.
  3. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.
    • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before performing a scan. They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
    • Click on this link to see a list of programs that should be disabled. The list is not all inclusive. If yours is not listed and you don't know how to disable it, please ask.

    NOTE1. If Combofix asks you to install Recovery Console, please allow it.
    NOTE 2. If Combofix asks you to update the program, always do so.
    • Close any open browsers.
    • WARNING: Combofix will disconnect your machine from the Internet as soon as it starts
    • Please do not attempt to re-connect your machine back to the Internet until Combofix has completely finished.
    • If there is no internet connection after running Combofix, then restart your computer to restore back your connection.
  4. Double click on combofix.exe & follow the prompts.
  5. When finished, it will produce a report for you.
  6. Please post the "C:\ComboFix.txt"

**Note 1: Do not mouseclick combofix's window while it's running. That may cause it to stall
**Note 2 for AVG users: ComboFix will not run until AVG is uninstalled as a protective measure against the anti-virus. This is because AVG "falsely" detects ComboFix (or its embedded files) as a threat and may remove them resulting in the tool not working correctly which in turn can cause "unpredictable results". Since AVG cannot be effectively disabled before running ComboFix, the author recommends you to uninstall AVG first.
Use AppRemover to uninstall it: http://www.appremover.com/
We can reinstall it when we're done with CF.
**Note 3: If you receive an error "Illegal operation attempted on a registery key that has been marked for deletion", restart computer to fix the issue.



Make sure, you re-enable your security programs, when you're done with Combofix.

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

NOTE.
If, for some reason, Combofix refuses to run, try one of the following:

1. Run Combofix from Safe Mode.

2. Delete Combofix file, download fresh one, but rename combofix.exe to your_name.exe BEFORE saving it to your desktop.
Do NOT run it yet.

Please download and run the below tool named Rkill (courtesy of BleepingComputer.com) which may help allow other programs to run.

There are 4 different versions. If one of them won't run then download and try to run the other one.

Vista and Win7 users need to right click Rkill and choose Run as Administrator

You only need to get one of these to run, not all of them. You may get warnings from your antivirus about this tool, ignore them or shutdown your antivirus.

Rkill.com
Rkill.scr
Rkill.exe


  • Double-click on the Rkill desktop icon to run the tool.
  • If using Vista or Windows 7 right-click on it and choose Run As Administrator.
  • A black DOS box will briefly flash and then disappear. This is normal and indicates the tool ran successfully.
  • If not, delete the file, then download and use the one provided in Link 2.
  • If it does not work, repeat the process and attempt to use one of the remaining links until the tool runs.
  • Do not reboot until instructed.
  • If the tool does not run from any of the links provided, please let me know.


Once you've gotten one of them to run, immediately run your_name.exe by double clicking on it.

If normal mode still doesn't work, run BOTH tools from safe mode.

In case #2, please post BOTH logs, rKill and Combofix.

DO NOT make any other changes to your computer (like installing programs, using other cleaning tools, etc.), until it's officially declared clean!!!
 
ComboFix 11-02-09.02 - MANAGER 02/09/2011 12:44:55.1.2 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.1015.636 [GMT -8:00]
Running from: c:\documents and settings\MANAGER\Desktop\ComboFix.exe
AV: Microsoft Security Essentials *Disabled/Updated* {EDB4FA23-53B8-4AFA-8C5D-99752CCA7095}
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\windows\ST6UNST.000
c:\windows\system32\69821772
c:\windows\system32\69821772\cfg
c:\windows\system32\69821772\hst
c:\windows\system32\69821772\rng
c:\windows\system32\69821772\run
c:\windows\system32\69821772\tst
c:\windows\system32\69821772\var
c:\windows\system32\Ijl11.dll

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

-------\Service_usnjsvc


((((((((((((((((((((((((( Files Created from 2011-01-09 to 2011-02-09 )))))))))))))))))))))))))))))))
.

2011-02-09 19:34 . 2011-02-03 01:10 5890896 ----a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{004159DE-CF05-4208-841A-CC3F4B5AB84F}\mpengine.dll
2011-02-05 02:06 . 2011-02-09 05:25 -------- d-----w- c:\documents and settings\NetworkService\Local Settings\Application Data\Adobe
2011-02-04 23:35 . 2011-02-03 01:11 222080 ------w- c:\windows\system32\MpSigStub.exe
2011-02-04 23:26 . 2011-02-04 23:27 -------- d-----w- c:\program files\Microsoft Security Client
2011-02-04 00:33 . 2011-02-04 00:33 -------- d-----w- c:\windows\system32\wbem\Repository
2011-02-04 00:33 . 2011-02-04 00:33 -------- d-----w- c:\program files\FOX News Live
2011-02-04 00:33 . 2011-02-04 00:33 -------- d-----w- c:\program files\MessagePal
2011-02-04 00:33 . 2011-02-04 00:33 -------- d-----w- c:\program files\AskBarDis
2011-02-04 00:33 . 2011-02-04 00:33 -------- d-----w- c:\documents and settings\MANAGER\Local Settings\Application Data\AOL OCP
2011-02-04 00:33 . 2011-02-04 00:33 -------- d-----w- c:\program files\AIM6
2011-01-12 21:35 . 2011-01-12 21:35 -------- d-----w- c:\documents and settings\MANAGER\Application Data\Malwarebytes
2011-01-12 21:35 . 2010-12-21 02:09 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2011-01-12 21:35 . 2011-01-12 21:35 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2011-01-12 21:35 . 2011-01-12 21:35 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2011-01-12 21:35 . 2010-12-21 02:08 20952 ----a-w- c:\windows\system32\drivers\mbam.sys

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-12-02 03:35 . 2010-12-02 03:35 4280320 ----a-w- c:\windows\system32\GPhotos.scr
2010-11-18 18:12 . 2008-10-16 21:03 81920 ----a-w- c:\windows\system32\isign32.dll
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{3041d03e-fd4b-44e0-b742-2d9b88305f98}"= "c:\program files\AskBarDis\bar\bin\askBar.dll" [2008-07-18 279944]

[HKEY_CLASSES_ROOT\clsid\{3041d03e-fd4b-44e0-b742-2d9b88305f98}]
[HKEY_CLASSES_ROOT\TypeLib\{4b1c1e16-6b34-430e-b074-5928eca4c150}]

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{3041D03E-FD4B-44E0-B742-2D9B88305F98}"= "c:\program files\AskBarDis\bar\bin\askBar.dll" [2008-07-18 279944]

[HKEY_CLASSES_ROOT\clsid\{3041d03e-fd4b-44e0-b742-2d9b88305f98}]
[HKEY_CLASSES_ROOT\TypeLib\{4b1c1e16-6b34-430e-b074-5928eca4c150}]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"LGBLiveUpdate"="c:\windows\system32\lgbpd.exe" [2010-03-19 1043456]
"Starfield Updater"="c:\program files\Starfield\StarfieldUpdate.exe" [2010-10-14 32960]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-08-22 68856]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2006-10-05 98304]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2006-10-05 114688]
"Persistence"="c:\windows\system32\igfxpers.exe" [2006-10-05 94208]
"RTHDCPL"="RTHDCPL.EXE" [2007-04-10 16126464]
"SkyTel"="SkyTel.EXE" [2007-04-04 1822720]
"SofTek"="c:\program files\SofTek Software\lib\Updateexec.exe" [2008-02-27 211968]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2010-07-03 202256]
"SystemClockSvr"="c:\windows\system32\fonts\mru2\system\clocksvr.exe" [2005-08-09 118784]
"MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2010-11-30 997408]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2007-10-18 5724184]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^MessagePal.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\MessagePal.lnk
backup=c:\windows\pss\MessagePal.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}]
2006-12-24 01:05 143360 ----a-w- c:\program files\Common Files\Ahead\Lib\NMBgMonitor.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LanguageShortcut]
2006-05-18 18:29 49152 ----a-w- c:\program files\CyberLink\PowerDVD\Language\Language.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MsnMsgr]
2007-10-18 19:34 5724184 ----a-w- c:\program files\Windows Live\Messenger\msnmsgr.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
2006-01-12 22:40 155648 ----a-w- c:\program files\Common Files\Ahead\Lib\NeroCheck.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Picasa Media Detector]
2008-08-21 01:18 443968 ----a-w- c:\program files\Picasa2\PicasaMediaDetector.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RemoteControl]
2005-12-08 05:57 30208 ----a-w- c:\program files\CyberLink\PowerDVD\PDVDServ.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Starfield Updater]
2010-10-14 21:33 32960 ----a-w- c:\program files\Starfield\starfieldupdate.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SweetIM]
2008-01-03 04:15 103712 ----a-r- c:\program files\Macrogaming\SweetIM\SweetIM.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg]
2008-08-22 03:39 68856 ----a-w- c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SystemClockSvr]
2005-08-09 19:14 118784 ----a-w- c:\windows\system32\fonts\mru2\system\clocksvr.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\taskmgr]
2005-08-09 19:14 118784 ----a-w- c:\windows\system32\fonts\mru2\system\clocksvr.exe

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"c:\\Program Files\\SofTek Software\\Lib\\TBA.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Real\\RealPlayer\\realplay.exe"=
"c:\\Program Files\\Google\\Google Earth\\client\\googleearth.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=

R2 File Backup;File Backup Service;c:\program files\Starfield\offSyncService.exe [7/16/2010 12:47 PM 1215216]
R2 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\Viewpoint\Common\ViewpointService.exe [1/9/2008 8:54 AM 24652]
S1 MpKsl19abeef7;MpKsl19abeef7;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{81984812-CECD-4A03-A9DF-FE86F558BDCB}\MpKsl19abeef7.sys --> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{81984812-CECD-4A03-A9DF-FE86F558BDCB}\MpKsl19abeef7.sys [?]
S1 MpKsl43f7fd04;MpKsl43f7fd04;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{004159DE-CF05-4208-841A-CC3F4B5AB84F}\MpKsl43f7fd04.sys --> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{004159DE-CF05-4208-841A-CC3F4B5AB84F}\MpKsl43f7fd04.sys [?]
S2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [12/21/2009 11:39 AM 135664]
.
Contents of the 'Scheduled Tasks' folder

2011-02-09 c:\windows\Tasks\Check Updates for Windows Live Toolbar.job
- c:\program files\Windows Live Toolbar\MSNTBUP.EXE [2007-10-19 19:20]

2011-02-09 c:\windows\Tasks\Google Software Updater.job
- c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2007-12-06 05:52]

2011-02-09 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-12-21 19:39]

2011-02-09 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-12-21 19:39]

2011-02-09 c:\windows\Tasks\RealUpgradeLogonTaskS-1-5-21-3071955782-306273710-422076765-1007.job
- c:\program files\Real\RealUpgrade\realupgrade.exe [2010-06-03 10:02]

2011-02-07 c:\windows\Tasks\RealUpgradeScheduledTaskS-1-5-21-3071955782-306273710-422076765-1007.job
- c:\program files\Real\RealUpgrade\realupgrade.exe [2010-06-03 10:02]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.powertoys.com/
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
uInternet Connection Wizard,ShellNext = iexplore
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: &Windows Live Search - c:\program files\Windows Live Toolbar\msntb.dll/search.htm
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: Add to Windows &Live Favorites - http://favorites.live.com/quickadd.aspx
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
IE: Google Sidewiki... - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_E11712C84EA7E12B.dll/cmsidewiki.html
DPF: Web-Based Email Tools - hxxp://email.secureserver.net/Download.CAB
DPF: {7206EAAC-5CFA-43A3-9F61-E27E8E51E42F} - hxxp://npsports.liveblockauctions.com/container_repository/laiexec2.cab
.
- - - - ORPHANS REMOVED - - - -

MSConfigStartUp-Aim6 - ~c:\program files\AIM6\aim6.exe
MSConfigStartUp-Swqmdpoc - c:\windows\system32\beyuegeb.exe



**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2011-02-09 12:52
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10l_ActiveX.exe,-101"

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10l_ActiveX.exe"

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - - > 'explorer.exe'(3844)
c:\windows\system32\WININET.dll
c:\windows\system32\ieframe.dll
.
------------------------ Other Running Processes ------------------------
.
c:\program files\Microsoft Security Client\Antimalware\MsMpEng.exe
c:\program files\Common Files\LightScribe\LSSrvc.exe
c:\program files\CyberLink\Shared files\RichVideo.exe
c:\windows\system32\wdfmgr.exe
c:\windows\system32\wscntfy.exe
c:\windows\RTHDCPL.EXE
.
**************************************************************************
.
Completion time: 2011-02-09 12:56:30 - machine was rebooted
ComboFix-quarantined-files.txt 2011-02-09 20:56

Pre-Run: 143,112,380,416 bytes free
Post-Run: 143,995,944,960 bytes free

WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
UnsupportedDebug="do not select this" /debug
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Home Edition" /noexecute=optin /fastdetect

- - End Of File - - E5F86C5F0D37C5414AA1478EF4178A7B
 
You didn't say how is redirection.

Uninstall Ask Toolbar, known foistware.

=============================================================

Unless you installed Viewpoint Manager knowledgeably...
Go Start>Control Panel>Add\Remove (Programs and Features in Vista), and...
Uninstall any of the following programs associated with Viewpoint:
* Viewpoint Manager
* Viewpoint Media Player
* Viewpoint Toolbar
This program does not do anything bad such as deliver ads or spy on you, but it is considered foistware ("drive-by-install") as it is installed without your consent through programs like AOL, AIM, Compuserve, etc.

===============================================================

Combofix log looks good now....

Download OTL to your Desktop.


  • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • Click the Scan All Users checkbox.
  • Under the Custom Scan box paste this in:



netsvcs
drivers32
%SYSTEMDRIVE%\*.*
%systemroot%\Fonts\*.com
%systemroot%\Fonts\*.dll
%systemroot%\Fonts\*.ini
%systemroot%\Fonts\*.ini2
%systemroot%\Fonts\*.exe
%systemroot%\system32\spool\prtprocs\w32x86\*.*
%systemroot%\REPAIR\*.bak1
%systemroot%\REPAIR\*.ini
%systemroot%\system32\*.jpg
%systemroot%\*.jpg
%systemroot%\*.png
%systemroot%\*.scr
%systemroot%\*._sy
%APPDATA%\Adobe\Update\*.*
%ALLUSERSPROFILE%\Favorites\*.*
%APPDATA%\Microsoft\*.*
%PROGRAMFILES%\*.*
%APPDATA%\Update\*.*
%systemroot%\*. /mp /s
CREATERESTOREPOINT
%systemroot%\System32\config\*.sav
%PROGRAMFILES%\bak. /s
%systemroot%\system32\bak. /s
%ALLUSERSPROFILE%\Start Menu\*.lnk /x
%systemroot%\system32\config\systemprofile\*.dat /x
%systemroot%\*.config
%systemroot%\system32\*.db
%APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x
%USERPROFILE%\Desktop\*.exe
%PROGRAMFILES%\Common Files\*.*
%systemroot%\*.src
%systemroot%\install\*.*
%systemroot%\system32\DLL\*.*
%systemroot%\system32\HelpFiles\*.*
%systemroot%\system32\rundll\*.*
%systemroot%\winn32\*.*
%systemroot%\Java\*.*
%systemroot%\system32\test\*.*
%systemroot%\system32\Rundll32\*.*
%systemroot%\AppPatch\Custom\*.*
%APPDATA%\Roaming\Microsoft\Windows\Recent\*.lnk /x
%PROGRAMFILES%\PC-Doctor\Downloads\*.*
%PROGRAMFILES%\Internet Explorer\*.tmp
%PROGRAMFILES%\Internet Explorer\*.dat
%USERPROFILE%\My Documents\*.exe
%USERPROFILE%\*.exe
%systemroot%\ADDINS\*.*
%systemroot%\assembly\*.bak2
%systemroot%\Config\*.*
%systemroot%\REPAIR\*.bak2
%systemroot%\SECURITY\Database\*.sdb /x
%systemroot%\SYSTEM\*.bak2
%systemroot%\Web\*.bak2
%systemroot%\Driver Cache\*.*
%PROGRAMFILES%\Mozilla Firefox\0*.exe
%ProgramFiles%\Microsoft Common\*.*
%ProgramFiles%\TinyProxy.
%USERPROFILE%\Favorites\*.url /x
%systemroot%\system32\*.bk
%systemroot%\*.te
%systemroot%\system32\system32\*.*
%ALLUSERSPROFILE%\*.dat /x
%systemroot%\system32\drivers\*.rmv
dir /b "%systemroot%\system32\*.exe" | find /i " " /c
dir /b "%systemroot%\*.exe" | find /i " " /c
%PROGRAMFILES%\Microsoft\*.*
%systemroot%\System32\Wbem\proquota.exe
%PROGRAMFILES%\Mozilla Firefox\*.dat
%USERPROFILE%\Cookies\*.txt /x
%SystemRoot%\system32\fonts\*.*
%systemroot%\system32\winlog\*.*
%systemroot%\system32\Language\*.*
%systemroot%\system32\Settings\*.*
%systemroot%\system32\*.quo
%SYSTEMROOT%\AppPatch\*.exe
%SYSTEMROOT%\inf\*.exe
%SYSTEMROOT%\Installer\*.exe
%systemroot%\system32\config\*.bak2
%systemroot%\system32\Computers\*.*
%SystemRoot%\system32\Sound\*.*
%SystemRoot%\system32\SpecialImg\*.*
%SystemRoot%\system32\code\*.*
%SystemRoot%\system32\draft\*.*
%SystemRoot%\system32\MSSSys\*.*
%ProgramFiles%\Javascript\*.*
%systemroot%\pchealth\helpctr\System\*.exe /s
%systemroot%\Web\*.exe
%systemroot%\system32\msn\*.*
%systemroot%\system32\*.tro
%AppData%\Microsoft\Installer\msupdates\*.*
%ProgramFiles%\Messenger\*.*
%systemroot%\system32\systhem32\*.*
%systemroot%\system\*.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs
/md5start
/md5stop



  • Click the Quick Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
  • When the scan completes, it will open two notepad windows: OTL.txt and Extras.txt. These are saved in the same location as OTL.
  • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post them back here.
 
oops sorry but yea redirection seems to not be an issue anymore and computer is running better here is the otl log

OTL logfile created on: 2/9/2011 1:05:16 PM - Run 1
OTL by OldTimer - Version 3.2.20.6 Folder = C:\Documents and Settings\MANAGER\Desktop
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.13)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

1,015.00 Mb Total Physical Memory | 607.00 Mb Available Physical Memory | 60.00% Memory free
2.00 Gb Paging File | 2.00 Gb Available in Paging File | 84.00% Paging File free
Paging file location(s): C:\pagefile.sys 1524 3048 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 149.05 Gb Total Space | 134.14 Gb Free Space | 90.00% Space Free | Partition Type: NTFS
Drive T: | 74.45 Gb Total Space | 44.91 Gb Free Space | 60.32% Space Free | Partition Type: NTFS
Drive V: | 74.45 Gb Total Space | 44.91 Gb Free Space | 60.32% Space Free | Partition Type: NTFS
Drive W: | 74.45 Gb Total Space | 44.91 Gb Free Space | 60.32% Space Free | Partition Type: NTFS
Drive X: | 74.45 Gb Total Space | 44.91 Gb Free Space | 60.32% Space Free | Partition Type: NTFS
Drive Y: | 74.45 Gb Total Space | 44.91 Gb Free Space | 60.32% Space Free | Partition Type: NTFS
Drive Z: | 71.52 Gb Total Space | 50.97 Gb Free Space | 71.26% Space Free | Partition Type: NTFS

Computer Name: FINANCE | User Name: MANAGER | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - [2011/02/09 13:04:32 | 000,602,624 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\MANAGER\Desktop\OTL.exe
PRC - [2011/02/02 11:12:34 | 001,215,216 | ---- | M] (Starfield Technologies, Inc.) -- C:\Program Files\Starfield\offSyncService.exe
PRC - [2010/11/30 13:20:36 | 000,997,408 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Microsoft Security Client\msseces.exe
PRC - [2010/11/11 12:26:42 | 000,226,984 | ---- | M] (Microsoft Corporation) -- c:\Program Files\Microsoft Security Client\Antimalware\MpCmdRun.exe
PRC - [2010/11/11 12:26:40 | 000,011,736 | ---- | M] (Microsoft Corporation) -- c:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe
PRC - [2010/10/14 13:33:53 | 000,032,960 | ---- | M] () -- C:\Program Files\Starfield\starfieldupdate.exe
PRC - [2010/07/03 08:45:32 | 000,202,256 | ---- | M] (RealNetworks, Inc.) -- C:\Program Files\Common Files\Real\Update_OB\realsched.exe
PRC - [2010/03/19 09:29:48 | 001,043,456 | ---- | M] () -- C:\WINDOWS\system32\lgbpd.exe
PRC - [2008/08/21 19:39:35 | 000,068,856 | ---- | M] (Google Inc.) -- C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
PRC - [2008/04/13 16:12:19 | 001,033,728 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe
PRC - [2007/01/04 13:38:08 | 000,024,652 | ---- | M] (Viewpoint Corporation) -- C:\Program Files\Viewpoint\Common\ViewpointService.exe
PRC - [2005/08/09 11:14:04 | 000,118,784 | ---- | M] (System) -- C:\WINDOWS\system32\fonts\mru2\system\clocksvr.exe


========== Modules (SafeList) ==========

MOD - [2011/02/09 13:04:32 | 000,602,624 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\MANAGER\Desktop\OTL.exe
MOD - [2010/08/23 08:12:02 | 001,054,208 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.6028_x-ww_61e65202\comctl32.dll


========== Win32 Services (SafeList) ==========

SRV - File not found [Disabled | Stopped] -- -- (HidServ)
SRV - File not found [On_Demand | Stopped] -- -- (AppMgmt)
SRV - [2011/02/02 11:12:34 | 001,215,216 | ---- | M] (Starfield Technologies, Inc.) [Auto | Running] -- C:\Program Files\Starfield\offSyncService.exe -- (File Backup)
SRV - [2010/11/11 12:26:40 | 000,011,736 | ---- | M] (Microsoft Corporation) [Auto | Running] -- c:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe -- (MsMpSvc)
SRV - [2007/10/25 15:27:54 | 000,266,240 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files\Windows Live\installer\WLSetupSvc.exe -- (WLSetupSvc)
SRV - [2007/01/04 13:38:08 | 000,024,652 | ---- | M] (Viewpoint Corporation) [Auto | Running] -- C:\Program Files\Viewpoint\Common\ViewpointService.exe -- (Viewpoint Manager Service)


========== Driver Services (SafeList) ==========

DRV - File not found [Kernel | On_Demand | Running] -- -- (catchme)
DRV - [2011/02/09 12:58:05 | 000,028,752 | ---- | M] (Microsoft Corporation) [Kernel | System | Running] -- c:\Documents and Settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{E7587A8C-D7D5-40B2-8CEB-A0741312858F}\MpKsl845cf793.sys -- (MpKsl845cf793)
DRV - [2008/04/13 08:36:05 | 000,144,384 | ---- | M] (Windows (R) Server 2003 DDK provider) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\hdaudbus.sys -- (HDAudBus)
DRV - [2007/06/20 18:44:32 | 000,029,696 | R--- | M] (Atheros Communications) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\l251x86.sys -- (AtcL002)
DRV - [2007/04/10 03:04:40 | 004,397,568 | R--- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\RtkHDAud.sys -- (IntcAzAudAddService) Service for Realtek HD Audio (WDM)
DRV - [2006/10/05 07:24:00 | 001,181,824 | R--- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\igxpmp32.sys -- (ialm)
DRV - [2005/10/26 08:06:30 | 000,356,096 | R--- | M] (Ralink Technology Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\rt61.sys -- (RT61) Linksys Wireless-G PCI Adapter Driver(RT61)
DRV - [2004/08/12 18:56:20 | 000,005,810 | R--- | M] () [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\ASACPI.sys -- (MTsensor)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie


IE - HKU\.DEFAULT\..\URLSearchHook: {BC4FFE41-DE9F-46fa-B455-AAD49B9F9938} - C:\Program Files\Macrogaming\SweetIMBarForIE\toolbar.dll (Macrogaming)
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-18\..\URLSearchHook: {BC4FFE41-DE9F-46fa-B455-AAD49B9F9938} - C:\Program Files\Macrogaming\SweetIMBarForIE\toolbar.dll (Macrogaming)
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0



IE - HKU\S-1-5-21-3071955782-306273710-422076765-1007\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultName = Google
IE - HKU\S-1-5-21-3071955782-306273710-422076765-1007\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultURL = http://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
IE - HKU\S-1-5-21-3071955782-306273710-422076765-1007\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.powertoys.com/
IE - HKU\S-1-5-21-3071955782-306273710-422076765-1007\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie
IE - HKU\S-1-5-21-3071955782-306273710-422076765-1007\..\URLSearchHook: {BC4FFE41-DE9F-46fa-B455-AAD49B9F9938} - C:\Program Files\Macrogaming\SweetIMBarForIE\toolbar.dll (Macrogaming)
IE - HKU\S-1-5-21-3071955782-306273710-422076765-1007\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0


[2010/10/14 13:34:02 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\MANAGER\Application Data\Mozilla\Extensions
[2011/02/03 16:33:19 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\MANAGER\Application Data\Mozilla\Firefox\extensions
[2011/02/03 16:33:19 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\MANAGER\Application Data\Mozilla\Firefox\extensions\{E9A1DEE0-C623-4439-8932-001E7D17607D}

O1 HOSTS File: ([2011/02/09 12:52:24 | 000,000,027 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (SWEETIE Class) - {1A0AADCD-3A72-4b5f-900F-E3BB5A838E2A} - C:\Program Files\Macrogaming\SweetIMBarForIE\toolbar.dll (Macrogaming)
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - No CLSID value found.
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.6.5805.1910\swg.dll (Google Inc.)
O2 - BHO: (Windows Live Toolbar Helper) - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll (Microsoft Corporation)
O3 - HKLM\..\Toolbar: (Ask Toolbar) - {3041d03e-fd4b-44e0-b742-2d9b88305f98} - C:\Program Files\AskBarDis\bar\bin\askBar.dll (Ask.com)
O3 - HKLM\..\Toolbar: (SweetIM For Internet Explorer) - {BC4FFE41-DE9F-46fa-B455-AAD49B9F9938} - C:\Program Files\Macrogaming\SweetIMBarForIE\toolbar.dll (Macrogaming)
O3 - HKLM\..\Toolbar: (Windows Live Toolbar) - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll (Microsoft Corporation)
O3 - HKU\.DEFAULT\..\Toolbar\WebBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No CLSID value found.
O3 - HKU\.DEFAULT\..\Toolbar\WebBrowser: (SweetIM For Internet Explorer) - {BC4FFE41-DE9F-46FA-B455-AAD49B9F9938} - C:\Program Files\Macrogaming\SweetIMBarForIE\toolbar.dll (Macrogaming)
O3 - HKU\.DEFAULT\..\Toolbar\WebBrowser: (Windows Live Toolbar) - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll (Microsoft Corporation)
O3 - HKU\S-1-5-18\..\Toolbar\WebBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No CLSID value found.
O3 - HKU\S-1-5-18\..\Toolbar\WebBrowser: (SweetIM For Internet Explorer) - {BC4FFE41-DE9F-46FA-B455-AAD49B9F9938} - C:\Program Files\Macrogaming\SweetIMBarForIE\toolbar.dll (Macrogaming)
O3 - HKU\S-1-5-18\..\Toolbar\WebBrowser: (Windows Live Toolbar) - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll (Microsoft Corporation)
O3 - HKU\S-1-5-21-3071955782-306273710-422076765-1007\..\Toolbar\ShellBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No CLSID value found.
O3 - HKU\S-1-5-21-3071955782-306273710-422076765-1007\..\Toolbar\WebBrowser: (Ask Toolbar) - {3041D03E-FD4B-44E0-B742-2D9B88305F98} - C:\Program Files\AskBarDis\bar\bin\askBar.dll (Ask.com)
O3 - HKU\S-1-5-21-3071955782-306273710-422076765-1007\..\Toolbar\WebBrowser: (SweetIM For Internet Explorer) - {BC4FFE41-DE9F-46FA-B455-AAD49B9F9938} - C:\Program Files\Macrogaming\SweetIMBarForIE\toolbar.dll (Macrogaming)
O3 - HKU\S-1-5-21-3071955782-306273710-422076765-1007\..\Toolbar\WebBrowser: (Windows Live Toolbar) - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll (Microsoft Corporation)
O4 - HKLM..\Run: [MSC] c:\Program Files\Microsoft Security Client\msseces.exe (Microsoft Corporation)
O4 - HKLM..\Run: [SkyTel] C:\WINDOWS\SkyTel.exe (Realtek Semiconductor Corp.)
O4 - HKLM..\Run: [SofTek] C:\Program Files\SofTek Software\Lib\Updateexec.exe (SofTek Software Int'l Inc.)
O4 - HKLM..\Run: [SystemClockSvr] C:\WINDOWS\system32\fonts\mru2\system\clocksvr.exe (System)
O4 - HKLM..\Run: [TkBellExe] C:\Program Files\Common Files\Real\Update_OB\realsched.exe (RealNetworks, Inc.)
O4 - HKU\S-1-5-21-3071955782-306273710-422076765-1007..\Run: [LGBLiveUpdate] C:\WINDOWS\system32\lgbpd.exe ()
O4 - HKU\S-1-5-21-3071955782-306273710-422076765-1007..\Run: [Starfield Updater] C:\Program Files\Starfield\StarfieldUpdate.exe ()
O4 - HKU\S-1-5-21-3071955782-306273710-422076765-1007..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-21-3071955782-306273710-422076765-1007\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-3071955782-306273710-422076765-1007\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKU\S-1-5-21-3071955782-306273710-422076765-1007\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKU\S-1-5-21-3071955782-306273710-422076765-1007\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O8 - Extra context menu item: &Windows Live Search - C:\Program Files\Windows Live Toolbar\msntb.dll (Microsoft Corporation)
O8 - Extra context menu item: Add to Google Photos Screensa&ver - C:\WINDOWS\System32\GPhotos.scr (Google Inc.)
O9 - Extra Button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : &Blog This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation)
O16 - DPF: {447F8438-8124-4369-905B-A249E13CBBFC} http://pre.liveglobalbid.com/lgbkc.cab (LgbContent Control)
O16 - DPF: {7206EAAC-5CFA-43A3-9F61-E27E8E51E42F} http://npsports.liveblockauctions.com/container_repository/laiexec2.cab (laiExcuter Class)
O16 - DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} http://upload.facebook.com/controls/2009.07.28_v5.5.8.1/FacebookPhotoUploader55.cab (Facebook Photo Uploader 5 Control)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab (Shockwave Flash Object)
O16 - DPF: Web-Based Email Tools http://email.secureserver.net/Download.CAB (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 208.57.0.11
O18 - Protocol\Handler\wlmailhtml {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - C:\Program Files\Windows Live\Mail\mailcomm.dll (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\igfxcui: DllName - igfxdev.dll - C:\WINDOWS\System32\igfxdev.dll (Intel Corporation)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2008/10/16 13:06:05 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = ComFile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*

NetSvcs: 6to4 - File not found
NetSvcs: AppMgmt - File not found
NetSvcs: HidServ - File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found

Drivers32: msacm.iac2 - C:\WINDOWS\system32\iac25_32.ax (Intel Corporation)
Drivers32: msacm.l3acm - C:\WINDOWS\system32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.sl_anet - C:\WINDOWS\System32\sl_anet.acm (Sipro Lab Telecom Inc.)
Drivers32: msacm.trspch - C:\WINDOWS\System32\tssoft32.acm (DSP GROUP, INC.)
Drivers32: vidc.cvid - C:\WINDOWS\System32\iccvid.dll (Radius Inc.)
Drivers32: vidc.iv31 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv32 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv41 - C:\WINDOWS\System32\ir41_32.ax (Intel Corporation)
Drivers32: vidc.iv50 - C:\WINDOWS\System32\ir50_32.dll (Intel Corporation)

CREATERESTOREPOINT
Restore point Set: OTL Restore Point (16902109354000384)

========== Files/Folders - Created Within 30 Days ==========

[2011/02/09 13:04:24 | 000,602,624 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\MANAGER\Desktop\OTL.exe
[2011/02/09 12:58:19 | 000,000,000 | -HSD | C] -- C:\RECYCLER
[2011/02/09 12:56:32 | 000,000,000 | ---D | C] -- C:\WINDOWS\temp
[2011/02/09 12:42:59 | 000,000,000 | RHSD | C] -- C:\cmdcons
[2011/02/09 12:39:24 | 000,212,480 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWXCACLS.exe
[2011/02/09 12:39:24 | 000,161,792 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWREG.exe
[2011/02/09 12:39:24 | 000,136,704 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWSC.exe
[2011/02/09 12:39:24 | 000,031,232 | ---- | C] (NirSoft) -- C:\WINDOWS\NIRCMD.exe
[2011/02/09 12:39:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\ERDNT
[2011/02/09 12:39:13 | 000,000,000 | ---D | C] -- C:\Qoobox
[2011/02/09 11:10:31 | 000,000,000 | ---D | C] -- C:\WINDOWS\Minidump
[2011/02/07 10:51:00 | 000,000,000 | ---D | C] -- C:\Documents and Settings\NetworkService\Application Data\Real
[2011/02/04 18:06:28 | 000,000,000 | ---D | C] -- C:\Documents and Settings\NetworkService\Local Settings\Application Data\Adobe
[2011/02/04 15:26:45 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft Security Client
[2011/02/04 15:23:10 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Windows Genuine Advantage
[2011/02/04 14:42:59 | 000,000,000 | ---D | C] -- C:\WINDOWS\pss
[2011/02/03 16:33:28 | 000,000,000 | ---D | C] -- C:\Program Files\FOX News Live
[2011/02/03 16:33:27 | 000,000,000 | ---D | C] -- C:\Program Files\MessagePal
[2011/02/03 16:33:27 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\MessagePal
[2011/02/03 16:33:20 | 000,000,000 | ---D | C] -- C:\Config.Msi
[2011/02/03 16:33:18 | 000,000,000 | ---D | C] -- C:\Program Files\AskBarDis
[2011/02/03 16:33:17 | 000,000,000 | ---D | C] -- C:\Documents and Settings\MANAGER\Local Settings\Application Data\AOL OCP
[2011/02/03 16:33:17 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\AIM
[2011/02/03 16:33:11 | 000,000,000 | ---D | C] -- C:\Program Files\AIM6
[2011/02/03 15:53:04 | 000,000,000 | ---D | C] -- C:\Documents and Settings\MANAGER\My Documents\Pictures
[2011/02/03 15:53:03 | 000,000,000 | ---D | C] -- C:\Documents and Settings\MANAGER\My Documents\Forms
[2011/02/03 15:53:03 | 000,000,000 | ---D | C] -- C:\Documents and Settings\MANAGER\My Documents\Credit
[2011/02/03 12:46:10 | 000,000,000 | ---D | C] -- C:\Documents and Settings\LocalService\Application Data\Macromedia
[2011/02/02 15:47:47 | 000,000,000 | ---D | C] -- C:\Documents and Settings\NetworkService\Application Data\Macromedia
[2011/02/02 15:47:46 | 000,000,000 | ---D | C] -- C:\Documents and Settings\NetworkService\Application Data\Adobe
[2011/01/24 17:46:39 | 000,000,000 | ---D | C] -- C:\Documents and Settings\MANAGER\My Documents\xr50
[2011/01/20 12:24:27 | 000,000,000 | ---D | C] -- C:\Documents and Settings\MANAGER\My Documents\golf cart
[2011/01/12 13:35:39 | 000,000,000 | ---D | C] -- C:\Documents and Settings\MANAGER\Application Data\Malwarebytes
[2011/01/12 13:35:35 | 000,038,224 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2011/01/12 13:35:35 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\Malwarebytes' Anti-Malware
[2011/01/12 13:35:34 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Malwarebytes
[2011/01/12 13:35:32 | 000,020,952 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbam.sys
[2011/01/12 13:35:32 | 000,000,000 | ---D | C] -- C:\Program Files\Malwarebytes' Anti-Malware
[4 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2011/02/09 13:04:32 | 000,602,624 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\MANAGER\Desktop\OTL.exe
[2011/02/09 13:04:00 | 000,000,886 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2011/02/09 12:56:29 | 000,435,590 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat
[2011/02/09 12:56:29 | 000,068,360 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat
[2011/02/09 12:52:29 | 000,000,868 | ---- | M] () -- C:\WINDOWS\tasks\Google Software Updater.job
[2011/02/09 12:52:24 | 000,000,027 | ---- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts
[2011/02/09 12:52:18 | 000,000,882 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2011/02/09 12:52:18 | 000,000,282 | ---- | M] () -- C:\WINDOWS\tasks\RealUpgradeLogonTaskS-1-5-21-3071955782-306273710-422076765-1007.job
[2011/02/09 12:52:03 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2011/02/09 12:52:02 | 1064,554,496 | -HS- | M] () -- C:\hiberfil.sys
[2011/02/09 12:43:03 | 000,000,327 | RHS- | M] () -- C:\boot.ini
[2011/02/09 12:32:33 | 000,012,648 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2011/02/09 12:21:15 | 000,000,258 | ---- | M] () -- C:\WINDOWS\tasks\Check Updates for Windows Live Toolbar.job
[2011/02/09 12:19:12 | 000,000,664 | ---- | M] () -- C:\WINDOWS\System32\d3d9caps.dat
[2011/02/08 17:51:00 | 000,000,180 | ---- | M] () -- C:\Documents and Settings\MANAGER\Desktop\craigslist.url
[2011/02/08 15:20:47 | 000,014,519 | ---- | M] () -- C:\Documents and Settings\MANAGER\Desktop\New Cars, Used Cars, Blue Book Values & Car Prices - Kelley Blue Book (2).url
[2011/02/08 15:05:12 | 000,000,180 | ---- | M] () -- C:\Documents and Settings\MANAGER\Desktop\Model Finance Company.url
[2011/02/07 14:52:58 | 000,000,290 | ---- | M] () -- C:\WINDOWS\tasks\RealUpgradeScheduledTaskS-1-5-21-3071955782-306273710-422076765-1007.job
[2011/02/04 15:27:56 | 000,001,945 | ---- | M] () -- C:\WINDOWS\epplauncher.mif
[2011/02/04 14:53:12 | 000,000,211 | ---- | M] () -- C:\Boot.bak
[2011/02/03 15:51:54 | 000,019,738 | ---- | M] () -- C:\Documents and Settings\MANAGER\My Documents\MASTER.ini
[2011/02/03 15:51:54 | 000,001,622 | ---- | M] () -- C:\Documents and Settings\MANAGER\My Documents\eLink.sys
[2011/02/03 15:51:54 | 000,000,802 | ---- | M] () -- C:\Documents and Settings\MANAGER\My Documents\MBSF.DBF
[2011/02/03 15:51:49 | 000,016,946 | ---- | M] () -- C:\Documents and Settings\MANAGER\My Documents\TYPES.DBF
[2011/02/03 15:51:49 | 000,011,188 | ---- | M] () -- C:\Documents and Settings\MANAGER\My Documents\COMPANY.DBF
[2011/02/03 15:51:49 | 000,000,012 | ---- | M] () -- C:\Documents and Settings\MANAGER\My Documents\Sync.STP
[2011/02/03 15:51:49 | 000,000,010 | ---- | M] () -- C:\Documents and Settings\MANAGER\My Documents\aaindex.25
[2011/02/03 13:56:15 | 000,000,263 | ---- | M] () -- C:\Documents and Settings\MANAGER\Desktop\Fee Calculator.url
[2011/02/03 13:46:21 | 000,000,172 | ---- | M] () -- C:\Documents and Settings\MANAGER\Desktop\cycle trader log in.url
[2011/02/03 12:42:17 | 000,000,907 | ---- | M] () -- C:\Documents and Settings\MANAGER\My Documents\My Sharing Folders.lnk
[2011/02/03 12:41:56 | 000,000,268 | -H-- | M] () -- C:\sqmdata19.sqm
[2011/02/03 12:41:56 | 000,000,244 | -H-- | M] () -- C:\sqmnoopt19.sqm
[2011/02/03 11:43:37 | 003,710,256 | ---- | M] () -- C:\Documents and Settings\MANAGER\My Documents\CREDAPP.DBF
[2011/02/03 11:43:37 | 000,932,008 | ---- | M] () -- C:\Documents and Settings\MANAGER\My Documents\CUST.DBF
[2011/02/03 11:43:37 | 000,905,376 | ---- | M] () -- C:\Documents and Settings\MANAGER\My Documents\DEALS.DBF
[2011/02/03 11:43:37 | 000,632,048 | ---- | M] () -- C:\Documents and Settings\MANAGER\My Documents\AUTOINV.DBF
[2011/02/03 11:43:37 | 000,373,122 | ---- | M] () -- C:\Documents and Settings\MANAGER\My Documents\TMPAGREE.DBF
[2011/02/03 11:43:37 | 000,229,634 | ---- | M] () -- C:\Documents and Settings\MANAGER\My Documents\WARR.DBF
[2011/02/03 11:43:37 | 000,141,231 | ---- | M] () -- C:\Documents and Settings\MANAGER\My Documents\CUSFLDS.DBF
[2011/02/03 11:43:37 | 000,000,466 | ---- | M] () -- C:\Documents and Settings\MANAGER\My Documents\NEXTNO.DBF
[2011/02/03 11:37:57 | 000,060,928 | ---- | M] () -- C:\Documents and Settings\MANAGER\My Documents\DEALS.CDX
[2011/02/03 11:37:57 | 000,030,208 | ---- | M] () -- C:\Documents and Settings\MANAGER\My Documents\CUST.CDX
[2011/02/03 11:37:44 | 000,321,026 | ---- | M] () -- C:\Documents and Settings\MANAGER\My Documents\SYSLST.DBF
[2011/02/03 11:37:44 | 000,020,480 | ---- | M] () -- C:\Documents and Settings\MANAGER\My Documents\SYSLST.CDX
[2011/02/03 11:35:26 | 000,368,674 | ---- | M] () -- C:\Documents and Settings\MANAGER\My Documents\INSURE.DBF
[2011/02/03 11:35:26 | 000,240,602 | ---- | M] () -- C:\Documents and Settings\MANAGER\My Documents\ACCESS.DBF
[2011/02/03 11:35:26 | 000,008,192 | ---- | M] () -- C:\Documents and Settings\MANAGER\My Documents\CREDAPP.CDX
[2011/02/03 11:35:26 | 000,008,192 | ---- | M] () -- C:\Documents and Settings\MANAGER\My Documents\ACCESS.CDX
[2011/02/03 11:35:26 | 000,007,680 | ---- | M] () -- C:\Documents and Settings\MANAGER\My Documents\WARR.CDX
[2011/02/03 11:35:26 | 000,007,680 | ---- | M] () -- C:\Documents and Settings\MANAGER\My Documents\TMPAGREE.CDX
[2011/02/03 11:35:26 | 000,007,680 | ---- | M] () -- C:\Documents and Settings\MANAGER\My Documents\INSURE.CDX
[2011/02/03 11:03:25 | 000,291,332 | ---- | M] () -- C:\Documents and Settings\MANAGER\My Documents\ACT.DBF
[2011/02/03 11:03:25 | 000,000,075 | ---- | M] () -- C:\Documents and Settings\MANAGER\My Documents\ACTKEY.DBF
[2011/02/03 11:02:29 | 000,026,636 | ---- | M] () -- C:\Documents and Settings\MANAGER\My Documents\ACT_IOX.DBF
[2011/02/03 11:02:29 | 000,011,776 | ---- | M] () -- C:\Documents and Settings\MANAGER\My Documents\ACT_IOX.CDX
[2011/02/03 11:02:28 | 000,046,080 | ---- | M] () -- C:\Documents and Settings\MANAGER\My Documents\ACT.CDX
[2011/02/03 11:02:27 | 000,059,392 | ---- | M] () -- C:\Documents and Settings\MANAGER\My Documents\AUTOINV.CDX
[2011/02/03 11:02:26 | 000,006,144 | ---- | M] () -- C:\Documents and Settings\MANAGER\My Documents\CUSFLDS.CDX
[2011/02/03 10:46:57 | 000,000,268 | -H-- | M] () -- C:\sqmdata18.sqm
[2011/02/03 10:46:57 | 000,000,244 | -H-- | M] () -- C:\sqmnoopt18.sqm
[2011/02/02 17:38:33 | 000,000,268 | -H-- | M] () -- C:\sqmdata17.sqm
[2011/02/02 17:38:33 | 000,000,244 | -H-- | M] () -- C:\sqmnoopt17.sqm
[2011/02/02 16:06:20 | 000,000,268 | -H-- | M] () -- C:\sqmdata16.sqm
[2011/02/02 16:06:20 | 000,000,244 | -H-- | M] () -- C:\sqmnoopt16.sqm
[2011/02/02 15:58:32 | 000,000,268 | -H-- | M] () -- C:\sqmdata15.sqm
[2011/02/02 15:58:32 | 000,000,244 | -H-- | M] () -- C:\sqmnoopt15.sqm
[2011/02/02 15:56:42 | 000,000,268 | -H-- | M] () -- C:\sqmdata14.sqm
[2011/02/02 15:56:42 | 000,000,244 | -H-- | M] () -- C:\sqmnoopt14.sqm
[2011/02/01 15:01:41 | 000,000,143 | ---- | M] () -- C:\Documents and Settings\MANAGER\Desktop\National Powersport Auctions.url
[2011/01/31 10:30:28 | 000,029,021 | ---- | M] () -- C:\Documents and Settings\MANAGER\My Documents\FLDTRACK.DBF
[2011/01/29 16:58:26 | 000,016,384 | ---- | M] () -- C:\Documents and Settings\MANAGER\My Documents\FLDTRACK.CDX
[2011/01/24 16:39:55 | 000,000,255 | ---- | M] () -- C:\Documents and Settings\MANAGER\Desktop\release of liability dmv.url
[2011/01/20 12:26:32 | 000,000,038 | ---- | M] () -- C:\Documents and Settings\MANAGER\My Documents\.ini
[2011/01/12 17:26:12 | 000,000,069 | ---- | M] () -- C:\WINDOWS\NeroDigital.ini
[2011/01/12 14:49:29 | 000,000,268 | -H-- | M] () -- C:\sqmdata13.sqm
[2011/01/12 14:49:29 | 000,000,244 | -H-- | M] () -- C:\sqmnoopt13.sqm
[2011/01/12 13:35:35 | 000,000,784 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2011/01/10 18:59:29 | 000,000,268 | -H-- | M] () -- C:\sqmdata12.sqm
[2011/01/10 18:59:29 | 000,000,244 | -H-- | M] () -- C:\sqmnoopt12.sqm
[4 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]

========== Files Created - No Company Name ==========

[2011/02/09 12:43:03 | 000,000,211 | ---- | C] () -- C:\Boot.bak
[2011/02/09 12:43:01 | 000,260,272 | RHS- | C] () -- C:\cmldr
[2011/02/09 12:39:24 | 000,256,512 | ---- | C] () -- C:\WINDOWS\PEV.exe
[2011/02/09 12:39:24 | 000,098,816 | ---- | C] () -- C:\WINDOWS\sed.exe
[2011/02/09 12:39:24 | 000,089,088 | ---- | C] () -- C:\WINDOWS\MBR.exe
[2011/02/09 12:39:24 | 000,080,412 | ---- | C] () -- C:\WINDOWS\grep.exe
[2011/02/09 12:39:24 | 000,068,096 | ---- | C] () -- C:\WINDOWS\zip.exe
[2011/02/09 10:59:24 | 1064,554,496 | -HS- | C] () -- C:\hiberfil.sys
[2011/02/04 15:27:56 | 000,001,945 | ---- | C] () -- C:\WINDOWS\epplauncher.mif
[2011/02/04 15:27:04 | 000,001,680 | ---- | C] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Microsoft Security Essentials.lnk
[2011/02/03 16:48:05 | 000,000,180 | ---- | C] () -- C:\Documents and Settings\MANAGER\Desktop\craigslist.url
[2011/02/03 15:53:03 | 002,347,461 | ---- | C] () -- C:\Documents and Settings\MANAGER\My Documents\DMDEMODT.ZIP
[2011/02/03 15:53:03 | 000,932,008 | ---- | C] () -- C:\Documents and Settings\MANAGER\My Documents\CUST.DBF
[2011/02/03 15:53:03 | 000,905,376 | ---- | C] () -- C:\Documents and Settings\MANAGER\My Documents\DEALS.DBF
[2011/02/03 15:53:03 | 000,373,122 | ---- | C] () -- C:\Documents and Settings\MANAGER\My Documents\TMPAGREE.DBF
[2011/02/03 15:53:03 | 000,368,674 | ---- | C] () -- C:\Documents and Settings\MANAGER\My Documents\INSURE.DBF
[2011/02/03 15:53:03 | 000,321,026 | ---- | C] () -- C:\Documents and Settings\MANAGER\My Documents\SYSLST.DBF
[2011/02/03 15:53:03 | 000,276,449 | ---- | C] () -- C:\Documents and Settings\MANAGER\My Documents\DEALMAP.DBF
[2011/02/03 15:53:03 | 000,229,634 | ---- | C] () -- C:\Documents and Settings\MANAGER\My Documents\WARR.DBF
[2011/02/03 15:53:03 | 000,141,231 | ---- | C] () -- C:\Documents and Settings\MANAGER\My Documents\CUSFLDS.DBF
[2011/02/03 15:53:03 | 000,096,790 | ---- | C] () -- C:\Documents and Settings\MANAGER\My Documents\USESEC.DBF
[2011/02/03 15:53:03 | 000,085,907 | ---- | C] () -- C:\Documents and Settings\MANAGER\My Documents\MFILELIB.DBF
[2011/02/03 15:53:03 | 000,083,794 | ---- | C] () -- C:\Documents and Settings\MANAGER\My Documents\DEALMAP2.DBF
[2011/02/03 15:53:03 | 000,060,928 | ---- | C] () -- C:\Documents and Settings\MANAGER\My Documents\DEALS.CDX
[2011/02/03 15:53:03 | 000,038,912 | ---- | C] () -- C:\Documents and Settings\MANAGER\My Documents\DEALMAP.CDX
[2011/02/03 15:53:03 | 000,030,208 | ---- | C] () -- C:\Documents and Settings\MANAGER\My Documents\CUST.CDX
[2011/02/03 15:53:03 | 000,029,021 | ---- | C] () -- C:\Documents and Settings\MANAGER\My Documents\FLDTRACK.DBF
[2011/02/03 15:53:03 | 000,028,522 | ---- | C] () -- C:\Documents and Settings\MANAGER\My Documents\TPARTY.DBF
[2011/02/03 15:53:03 | 000,022,232 | ---- | C] () -- C:\Documents and Settings\MANAGER\My Documents\MAKE.DBF
[2011/02/03 15:53:03 | 000,021,504 | ---- | C] () -- C:\Documents and Settings\MANAGER\My Documents\DEALMAP2.CDX
[2011/02/03 15:53:03 | 000,020,480 | ---- | C] () -- C:\Documents and Settings\MANAGER\My Documents\SYSLST.CDX
[2011/02/03 15:53:03 | 000,019,738 | ---- | C] () -- C:\Documents and Settings\MANAGER\My Documents\MASTER.ini
[2011/02/03 15:53:03 | 000,018,730 | ---- | C] () -- C:\Documents and Settings\MANAGER\My Documents\LAW.DBF
[2011/02/03 15:53:03 | 000,017,408 | ---- | C] () -- C:\Documents and Settings\MANAGER\My Documents\MAKE.CDX
[2011/02/03 15:53:03 | 000,016,946 | ---- | C] () -- C:\Documents and Settings\MANAGER\My Documents\TYPES.DBF
[2011/02/03 15:53:03 | 000,016,384 | ---- | C] () -- C:\Documents and Settings\MANAGER\My Documents\FLDTRACK.CDX
[2011/02/03 15:53:03 | 000,015,360 | ---- | C] () -- C:\Documents and Settings\MANAGER\My Documents\INVOICE.CDX
[2011/02/03 15:53:03 | 000,013,450 | ---- | C] () -- C:\Documents and Settings\MANAGER\My Documents\INVOICE.DBF
[2011/02/03 15:53:03 | 000,013,426 | ---- | C] () -- C:\Documents and Settings\MANAGER\My Documents\RPTITEM.DBF
[2011/02/03 15:53:03 | 000,013,357 | ---- | C] () -- C:\Documents and Settings\MANAGER\My Documents\SCHED.fpt
[2011/02/03 15:53:03 | 000,012,800 | ---- | C] () -- C:\Documents and Settings\MANAGER\My Documents\USESEC.CDX
[2011/02/03 15:53:03 | 000,010,575 | ---- | C] () -- C:\Documents and Settings\MANAGER\My Documents\FCO.DBF
[2011/02/03 15:53:03 | 000,010,156 | ---- | C] () -- C:\Documents and Settings\MANAGER\My Documents\SCHED.DBF
[2011/02/03 15:53:03 | 000,009,216 | ---- | C] () -- C:\Documents and Settings\MANAGER\My Documents\TYPES.CDX
[2011/02/03 15:53:03 | 000,009,128 | ---- | C] () -- C:\Documents and Settings\MANAGER\My Documents\LS.ini
[2011/02/03 15:53:03 | 000,008,876 | ---- | C] () -- C:\Documents and Settings\MANAGER\My Documents\INQUIRY.DBF
[2011/02/03 15:53:03 | 000,008,408 | ---- | C] () -- C:\Documents and Settings\MANAGER\My Documents\kmoss.ini
[2011/02/03 15:53:03 | 000,007,680 | ---- | C] () -- C:\Documents and Settings\MANAGER\My Documents\WARR.CDX
[2011/02/03 15:53:03 | 000,007,680 | ---- | C] () -- C:\Documents and Settings\MANAGER\My Documents\TMPAGREE.CDX
[2011/02/03 15:53:03 | 000,007,680 | ---- | C] () -- C:\Documents and Settings\MANAGER\My Documents\SCHED.CDX
[2011/02/03 15:53:03 | 000,007,680 | ---- | C] () -- C:\Documents and Settings\MANAGER\My Documents\PARTS.CDX
[2011/02/03 15:53:03 | 000,007,680 | ---- | C] () -- C:\Documents and Settings\MANAGER\My Documents\INSURE.CDX
[2011/02/03 15:53:03 | 000,007,680 | ---- | C] () -- C:\Documents and Settings\MANAGER\My Documents\FORMSAVL.CDX
[2011/02/03 15:53:03 | 000,007,168 | ---- | C] () -- C:\Documents and Settings\MANAGER\My Documents\TPARTY.CDX
[2011/02/03 15:53:03 | 000,007,168 | ---- | C] () -- C:\Documents and Settings\MANAGER\My Documents\RPTITEM.CDX
[2011/02/03 15:53:03 | 000,006,974 | ---- | C] () -- C:\Documents and Settings\MANAGER\My Documents\ITEMS.DBF
[2011/02/03 15:53:03 | 000,006,144 | ---- | C] () -- C:\Documents and Settings\MANAGER\My Documents\STPICMAP.CDX
[2011/02/03 15:53:03 | 000,006,144 | ---- | C] () -- C:\Documents and Settings\MANAGER\My Documents\LEASE1.CDX
[2011/02/03 15:53:03 | 000,006,144 | ---- | C] () -- C:\Documents and Settings\MANAGER\My Documents\CUSFLDS.CDX
[2011/02/03 15:53:03 | 000,006,144 | ---- | C] () -- C:\Documents and Settings\MANAGER\My Documents\CREDIT.CDX
[2011/02/03 15:53:03 | 000,005,250 | ---- | C] () -- C:\Documents and Settings\MANAGER\My Documents\LEASE1.DBF
[2011/02/03 15:53:03 | 000,004,950 | ---- | C] () -- C:\Documents and Settings\MANAGER\My Documents\PARTS.DBF
[2011/02/03 15:53:03 | 000,004,946 | ---- | C] () -- C:\Documents and Settings\MANAGER\My Documents\SALES.DBF
[2011/02/03 15:53:03 | 000,004,785 | ---- | C] () -- C:\Documents and Settings\MANAGER\My Documents\FORMSAVL.DBF
[2011/02/03 15:53:03 | 000,004,608 | ---- | C] () -- C:\Documents and Settings\MANAGER\My Documents\TASKS.CDX
[2011/02/03 15:53:03 | 000,004,608 | ---- | C] () -- C:\Documents and Settings\MANAGER\My Documents\SRVPICS.CDX
[2011/02/03 15:53:03 | 000,004,608 | ---- | C] () -- C:\Documents and Settings\MANAGER\My Documents\SALES.CDX
[2011/02/03 15:53:03 | 000,004,608 | ---- | C] () -- C:\Documents and Settings\MANAGER\My Documents\RELATION.CDX
[2011/02/03 15:53:03 | 000,004,608 | ---- | C] () -- C:\Documents and Settings\MANAGER\My Documents\ITEMS.CDX
[2011/02/03 15:53:03 | 000,004,608 | ---- | C] () -- C:\Documents and Settings\MANAGER\My Documents\EPTRANS.CDX
[2011/02/03 15:53:03 | 000,004,273 | ---- | C] () -- C:\Documents and Settings\MANAGER\My Documents\PRSETA.DBF
[2011/02/03 15:53:03 | 000,004,215 | ---- | C] () -- C:\Documents and Settings\MANAGER\My Documents\SYSSET.DBF
[2011/02/03 15:53:03 | 000,003,072 | ---- | C] () -- C:\Documents and Settings\MANAGER\My Documents\VEHTYPE.CDX
[2011/02/03 15:53:03 | 000,003,072 | ---- | C] () -- C:\Documents and Settings\MANAGER\My Documents\UTIL1.CDX
[2011/02/03 15:53:03 | 000,003,072 | ---- | C] () -- C:\Documents and Settings\MANAGER\My Documents\TASKLIST.CDX
[2011/02/03 15:53:03 | 000,003,072 | ---- | C] () -- C:\Documents and Settings\MANAGER\My Documents\SEMAPHOR.CDX
[2011/02/03 15:53:03 | 000,003,072 | ---- | C] () -- C:\Documents and Settings\MANAGER\My Documents\RPTNAME.CDX
[2011/02/03 15:53:03 | 000,003,072 | ---- | C] () -- C:\Documents and Settings\MANAGER\My Documents\QBOX.CDX
[2011/02/03 15:53:03 | 000,003,072 | ---- | C] () -- C:\Documents and Settings\MANAGER\My Documents\PRMARGIN.CDX
[2011/02/03 15:53:03 | 000,003,072 | ---- | C] () -- C:\Documents and Settings\MANAGER\My Documents\POPINFO.CDX
[2011/02/03 15:53:03 | 000,003,072 | ---- | C] () -- C:\Documents and Settings\MANAGER\My Documents\POPDATA.CDX
[2011/02/03 15:53:03 | 000,003,072 | ---- | C] () -- C:\Documents and Settings\MANAGER\My Documents\OPTDEF.CDX
[2011/02/03 15:53:03 | 000,003,072 | ---- | C] () -- C:\Documents and Settings\MANAGER\My Documents\LEAADJ.CDX
[2011/02/03 15:53:03 | 000,003,072 | ---- | C] () -- C:\Documents and Settings\MANAGER\My Documents\LAW.CDX
[2011/02/03 15:53:03 | 000,003,072 | ---- | C] () -- C:\Documents and Settings\MANAGER\My Documents\INVUPLDT.CDX
[2011/02/03 15:53:03 | 000,003,072 | ---- | C] () -- C:\Documents and Settings\MANAGER\My Documents\INSSET.CDX
[2011/02/03 15:53:03 | 000,003,072 | ---- | C] () -- C:\Documents and Settings\MANAGER\My Documents\INQUIRY.CDX
[2011/02/03 15:53:03 | 000,003,072 | ---- | C] () -- C:\Documents and Settings\MANAGER\My Documents\GAR.CDX
[2011/02/03 15:53:03 | 000,002,770 | ---- | C] () -- C:\Documents and Settings\MANAGER\My Documents\OPTDEF.DBF
[2011/02/03 15:53:03 | 000,002,518 | ---- | C] () -- C:\Documents and Settings\MANAGER\My Documents\UTIL1.DBF
[2011/02/03 15:53:03 | 000,002,266 | ---- | C] () -- C:\Documents and Settings\MANAGER\My Documents\LS.DBF
[2011/02/03 15:53:03 | 000,002,098 | ---- | C] () -- C:\Documents and Settings\MANAGER\My Documents\CREDIT.DBF
[2011/02/03 15:53:03 | 000,001,898 | ---- | C] () -- C:\Documents and Settings\MANAGER\My Documents\PRMARGIN.DBF
[2011/02/03 15:53:03 | 000,001,887 | ---- | C] () -- C:\Documents and Settings\MANAGER\My Documents\RPTNAME.DBF
[2011/02/03 15:53:03 | 000,001,640 | ---- | C] () -- C:\Documents and Settings\MANAGER\My Documents\DW.ini
[2011/02/03 15:53:03 | 000,001,622 | ---- | C] () -- C:\Documents and Settings\MANAGER\My Documents\eLink.sys
[2011/02/03 15:53:03 | 000,001,422 | ---- | C] () -- C:\Documents and Settings\MANAGER\My Documents\VEHTYPE.DBF
[2011/02/03 15:53:03 | 000,001,012 | ---- | C] () -- C:\Documents and Settings\MANAGER\My Documents\INVOICE.fpt
[2011/02/03 15:53:03 | 000,000,802 | ---- | C] () -- C:\Documents and Settings\MANAGER\My Documents\MBSF.DBF
[2011/02/03 15:53:03 | 000,000,761 | ---- | C] () -- C:\Documents and Settings\MANAGER\My Documents\WOPTIONS.DBF
[2011/02/03 15:53:03 | 000,000,665 | ---- | C] () -- C:\Documents and Settings\MANAGER\My Documents\INVUPLDT.DBF
[2011/02/03 15:53:03 | 000,000,611 | ---- | C] () -- C:\Documents and Settings\MANAGER\My Documents\NUMCONV.DBF
[2011/02/03 15:53:03 | 000,000,538 | ---- | C] () -- C:\Documents and Settings\MANAGER\My Documents\TASKLIST.DBF
[2011/02/03 15:53:03 | 000,000,527 | ---- | C] () -- C:\Documents and Settings\MANAGER\My Documents\INVDEF.DBF
[2011/02/03 15:53:03 | 000,000,512 | ---- | C] () -- C:\Documents and Settings\MANAGER\My Documents\SALES.fpt
[2011/02/03 15:53:03 | 000,000,512 | ---- | C] () -- C:\Documents and Settings\MANAGER\My Documents\MFILELIB.fpt
[2011/02/03 15:53:03 | 000,000,482 | ---- | C] () -- C:\Documents and Settings\MANAGER\My Documents\TASKS.DBF
[2011/02/03 15:53:03 | 000,000,466 | ---- | C] () -- C:\Documents and Settings\MANAGER\My Documents\NEXTNO.DBF
[2011/02/03 15:53:03 | 000,000,442 | ---- | C] () -- C:\Documents and Settings\MANAGER\My Documents\LEADEF.DBF
[2011/02/03 15:53:03 | 000,000,418 | ---- | C] () -- C:\Documents and Settings\MANAGER\My Documents\INSSET.DBF
[2011/02/03 15:53:03 | 000,000,418 | ---- | C] () -- C:\Documents and Settings\MANAGER\My Documents\EPTRANS.DBF
[2011/02/03 15:53:03 | 000,000,322 | ---- | C] () -- C:\Documents and Settings\MANAGER\My Documents\WAR_PL.DBF
[2011/02/03 15:53:03 | 000,000,322 | ---- | C] () -- C:\Documents and Settings\MANAGER\My Documents\GAR.DBF
[2011/02/03 15:53:03 | 000,000,282 | ---- | C] () -- C:\Documents and Settings\MANAGER\My Documents\RELATION.DBF
[2011/02/03 15:53:03 | 000,000,258 | ---- | C] () -- C:\Documents and Settings\MANAGER\My Documents\QBOX.DBF
[2011/02/03 15:53:03 | 000,000,258 | ---- | C] () -- C:\Documents and Settings\MANAGER\My Documents\LOG.DBF
[2011/02/03 15:53:03 | 000,000,226 | ---- | C] () -- C:\Documents and Settings\MANAGER\My Documents\LEAADJ.DBF
[2011/02/03 15:53:03 | 000,000,198 | ---- | C] () -- C:\Documents and Settings\MANAGER\My Documents\SEMAPHOR.DBF
[2011/02/03 15:53:03 | 000,000,162 | ---- | C] () -- C:\Documents and Settings\MANAGER\My Documents\POPINFO.DBF
[2011/02/03 15:53:03 | 000,000,162 | ---- | C] () -- C:\Documents and Settings\MANAGER\My Documents\POPDATA.DBF
[2011/02/03 15:53:03 | 000,000,157 | ---- | C] () -- C:\Documents and Settings\MANAGER\My Documents\INDEXFLG.DBF
[2011/02/03 15:53:03 | 000,000,130 | ---- | C] () -- C:\Documents and Settings\MANAGER\My Documents\UNI.DBF
[2011/02/03 15:53:03 | 000,000,130 | ---- | C] () -- C:\Documents and Settings\MANAGER\My Documents\STPICMAP.DBF
[2011/02/03 15:53:03 | 000,000,130 | ---- | C] () -- C:\Documents and Settings\MANAGER\My Documents\SRVPICS.DBF
[2011/02/03 15:53:03 | 000,000,127 | ---- | C] () -- C:\Documents and Settings\MANAGER\My Documents\so.ini
[2011/02/03 15:53:03 | 000,000,117 | ---- | C] () -- C:\Documents and Settings\MANAGER\My Documents\NEXTDNO.DBF
[2011/02/03 15:53:03 | 000,000,075 | ---- | C] () -- C:\Documents and Settings\MANAGER\My Documents\LATEPROC.DBF
[2011/02/03 15:53:02 | 003,710,256 | ---- | C] () -- C:\Documents and Settings\MANAGER\My Documents\CREDAPP.DBF
[2011/02/03 15:53:02 | 000,632,048 | ---- | C] () -- C:\Documents and Settings\MANAGER\My Documents\AUTOINV.DBF
[2011/02/03 15:53:02 | 000,291,332 | ---- | C] () -- C:\Documents and Settings\MANAGER\My Documents\ACT.DBF
[2011/02/03 15:53:02 | 000,240,602 | ---- | C] () -- C:\Documents and Settings\MANAGER\My Documents\ACCESS.DBF
[2011/02/03 15:53:02 | 000,073,668 | ---- | C] () -- C:\Documents and Settings\MANAGER\My Documents\AUTOINV.fpt
[2011/02/03 15:53:02 | 000,062,813 | ---- | C] () -- C:\Documents and Settings\MANAGER\My Documents\CLIENTS.DBF
[2011/02/03 15:53:02 | 000,059,392 | ---- | C] () -- C:\Documents and Settings\MANAGER\My Documents\AUTOINV.CDX
[2011/02/03 15:53:02 | 000,046,080 | ---- | C] () -- C:\Documents and Settings\MANAGER\My Documents\ACT.CDX
[2011/02/03 15:53:02 | 000,026,636 | ---- | C] () -- C:\Documents and Settings\MANAGER\My Documents\ACT_IOX.DBF
[2011/02/03 15:53:02 | 000,012,345 | ---- | C] () -- C:\Documents and Settings\MANAGER\My Documents\CONVLOG.fpt
[2011/02/03 15:53:02 | 000,011,776 | ---- | C] () -- C:\Documents and Settings\MANAGER\My Documents\ACT_IOX.CDX
[2011/02/03 15:53:02 | 000,011,188 | ---- | C] () -- C:\Documents and Settings\MANAGER\My Documents\COMPANY.DBF
[2011/02/03 15:53:02 | 000,008,192 | ---- | C] () -- C:\Documents and Settings\MANAGER\My Documents\CREDAPP.CDX
[2011/02/03 15:53:02 | 000,008,192 | ---- | C] () -- C:\Documents and Settings\MANAGER\My Documents\ACCESS.CDX
[2011/02/03 15:53:02 | 000,006,890 | ---- | C] () -- C:\Documents and Settings\MANAGER\My Documents\CONVLOG.DBF
[2011/02/03 15:53:02 | 000,006,144 | ---- | C] () -- C:\Documents and Settings\MANAGER\My Documents\COUNTY.CDX
[2011/02/03 15:53:02 | 000,006,144 | ---- | C] () -- C:\Documents and Settings\MANAGER\My Documents\ADJUST.CDX
[2011/02/03 15:53:02 | 000,004,608 | ---- | C] () -- C:\Documents and Settings\MANAGER\My Documents\AUTOOPT.CDX
[2011/02/03 15:53:02 | 000,004,608 | ---- | C] () -- C:\Documents and Settings\MANAGER\My Documents\ASIOPMAP.CDX
[2011/02/03 15:53:02 | 000,003,276 | ---- | C] () -- C:\Documents and Settings\MANAGER\My Documents\B_G.DBF
[2011/02/03 15:53:02 | 000,003,072 | ---- | C] () -- C:\Documents and Settings\MANAGER\My Documents\CONVLOG.CDX
[2011/02/03 15:53:02 | 000,003,072 | ---- | C] () -- C:\Documents and Settings\MANAGER\My Documents\CONTACTS.CDX
[2011/02/03 15:53:02 | 000,003,072 | ---- | C] () -- C:\Documents and Settings\MANAGER\My Documents\COND.CDX
[2011/02/03 15:53:02 | 000,003,072 | ---- | C] () -- C:\Documents and Settings\MANAGER\My Documents\COMPANY.CDX
[2011/02/03 15:53:02 | 000,003,072 | ---- | C] () -- C:\Documents and Settings\MANAGER\My Documents\CLIENTS.CDX
[2011/02/03 15:53:02 | 000,003,072 | ---- | C] () -- C:\Documents and Settings\MANAGER\My Documents\BACKUPS.CDX
[2011/02/03 15:53:02 | 000,003,072 | ---- | C] () -- C:\Documents and Settings\MANAGER\My Documents\ASIJOUR.CDX
[2011/02/03 15:53:02 | 000,003,072 | ---- | C] () -- C:\Documents and Settings\MANAGER\My Documents\ACTDEL.CDX
[2011/02/03 15:53:02 | 000,002,594 | ---- | C] () -- C:\Documents and Settings\MANAGER\My Documents\CRAP.DBF
[2011/02/03 15:53:02 | 000,002,566 | ---- | C] () -- C:\Documents and Settings\MANAGER\My Documents\COND.DBF
[2011/02/03 15:53:02 | 000,002,178 | ---- | C] () -- C:\Documents and Settings\MANAGER\My Documents\ADJUST.DBF
[2011/02/03 15:53:02 | 000,001,762 | ---- | C] () -- C:\Documents and Settings\MANAGER\My Documents\AUC.DBF
[2011/02/03 15:53:02 | 000,000,887 | ---- | C] () -- C:\Documents and Settings\MANAGER\My Documents\ACCDEF.DBF
[2011/02/03 15:53:02 | 000,000,747 | ---- | C] () -- C:\Documents and Settings\MANAGER\My Documents\BACKUPS.DBF
[2011/02/03 15:53:02 | 000,000,704 | ---- | C] () -- C:\Documents and Settings\MANAGER\My Documents\ASIOPMAP.DBF
[2011/02/03 15:53:02 | 000,000,626 | ---- | C] () -- C:\Documents and Settings\MANAGER\My Documents\COUNTY.DBF
[2011/02/03 15:53:02 | 000,000,442 | ---- | C] () -- C:\Documents and Settings\MANAGER\My Documents\ASIJOUR.DBF
[2011/02/03 15:53:02 | 000,000,432 | ---- | C] () -- C:\Documents and Settings\MANAGER\My Documents\CLPREDPH.DBF
[2011/02/03 15:53:02 | 000,000,418 | ---- | C] () -- C:\Documents and Settings\MANAGER\My Documents\CONTACTS.DBF
[2011/02/03 15:53:02 | 000,000,356 | ---- | C] () -- C:\Documents and Settings\MANAGER\My Documents\BARCODE.DBF
[2011/02/03 15:53:02 | 000,000,342 | ---- | C] () -- C:\Documents and Settings\MANAGER\My Documents\ACCTSET.DBF
[2011/02/03 15:53:02 | 000,000,322 | ---- | C] () -- C:\Documents and Settings\MANAGER\My Documents\AUTOOPT.DBF
[2011/02/03 15:53:02 | 000,000,194 | ---- | C] () -- C:\Documents and Settings\MANAGER\My Documents\ACTDEL.DBF
[2011/02/03 15:53:02 | 000,000,075 | ---- | C] () -- C:\Documents and Settings\MANAGER\My Documents\ACTKEY.DBF
[2011/02/03 15:53:02 | 000,000,038 | ---- | C] () -- C:\Documents and Settings\MANAGER\My Documents\.ini
[2011/02/03 15:53:02 | 000,000,012 | ---- | C] () -- C:\Documents and Settings\MANAGER\My Documents\Sync.STP
[2011/02/03 15:53:02 | 000,000,010 | ---- | C] () -- C:\Documents and Settings\MANAGER\My Documents\aaindex.25
[2011/02/03 12:42:17 | 000,000,907 | ---- | C] () -- C:\Documents and Settings\MANAGER\My Documents\My Sharing Folders.lnk
[2011/02/02 15:48:32 | 000,000,664 | ---- | C] () -- C:\WINDOWS\System32\d3d9caps.dat
[2011/01/12 13:35:35 | 000,000,784 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2010/03/22 10:50:21 | 000,000,373 | ---- | C] () -- C:\WINDOWS\System32\CNCMFP20.INI
[2010/03/10 03:02:22 | 000,000,118 | ---- | C] () -- C:\WINDOWS\System32\MRT.INI
[2009/03/03 19:42:11 | 000,018,790 | ---- | C] () -- C:\WINDOWS\System32\ddmon.dll
[2008/11/30 11:30:32 | 000,007,168 | ---- | C] () -- C:\Documents and Settings\MANAGER\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2008/10/16 13:44:20 | 000,002,364 | ---- | C] () -- C:\WINDOWS\System32\oeminfo.ini
[2008/10/16 13:32:48 | 000,200,704 | R--- | C] () -- C:\WINDOWS\System32\igfxCoIn_v4704.dll
[2008/10/16 13:20:36 | 000,005,810 | R--- | C] () -- C:\WINDOWS\System32\drivers\ASACPI.sys
[2008/10/16 13:20:34 | 000,011,058 | ---- | C] () -- C:\WINDOWS\Ascd_tmp.ini
[2008/10/16 13:20:24 | 000,010,288 | ---- | C] () -- C:\WINDOWS\System32\drivers\ASUSHWIO.SYS
[2008/10/16 05:56:11 | 000,004,161 | ---- | C] () -- C:\WINDOWS\ODBCINST.INI
[2008/10/03 06:37:48 | 000,000,125 | ---- | C] () -- C:\WINDOWS\System32\ver.ini
[2008/10/03 06:37:42 | 000,229,376 | ---- | C] () -- C:\WINDOWS\System32\sdl.dll
[2008/10/03 06:37:42 | 000,159,744 | ---- | C] () -- C:\WINDOWS\System32\lgbskin.dll
[2008/10/03 06:37:42 | 000,086,016 | ---- | C] () -- C:\WINDOWS\System32\lgbsysinfo.dll.bak
[2008/10/03 06:37:42 | 000,086,016 | ---- | C] () -- C:\WINDOWS\System32\lgbsysinfo.dll
[2008/10/03 06:37:42 | 000,045,056 | ---- | C] () -- C:\WINDOWS\System32\xcon.dll
[2008/09/11 08:20:19 | 000,030,793 | ---- | C] () -- C:\WINDOWS\System32\crtslv.dll
[2008/03/22 08:27:02 | 000,139,264 | ---- | C] () -- C:\WINDOWS\System32\VideoLib.dll
[2008/03/22 08:26:59 | 000,905,290 | ---- | C] () -- C:\WINDOWS\System32\libmmd.dll
[2008/02/28 18:11:12 | 000,000,376 | ---- | C] () -- C:\WINDOWS\ODBC.INI
[2008/02/04 18:23:10 | 000,693,792 | ---- | C] () -- C:\WINDOWS\System32\OGACheckControl.DLL
[2008/01/18 21:08:07 | 000,008,704 | ---- | C] () -- C:\WINDOWS\System32\CNMVS75.DLL
[2007/12/26 09:21:14 | 000,000,069 | ---- | C] () -- C:\WINDOWS\NeroDigital.ini
[2007/12/04 15:46:41 | 000,028,672 | ---- | C] () -- C:\WINDOWS\System32\ZipHandler.dll
[2007/10/25 16:59:44 | 000,000,061 | ---- | C] () -- C:\WINDOWS\smscfg.ini
[2007/10/18 17:36:54 | 000,061,440 | ---- | C] () -- C:\WINDOWS\System32\deskMenu2.dll
[2007/03/05 21:22:30 | 000,024,576 | ---- | C] () -- C:\WINDOWS\System32\AMData4.dll
[2004/03/03 05:53:30 | 000,118,784 | ---- | C] () -- C:\WINDOWS\System32\BBAPI.dll
[2003/01/07 15:05:08 | 000,002,695 | ---- | C] () -- C:\WINDOWS\System32\OUTLPERF.INI

========== LOP Check ==========

[2008/09/11 08:52:13 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Bomgar-SCC-48C94191
[2008/10/03 06:35:57 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Bomgar-SCC-48D3EAAD
[2008/10/03 06:35:57 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Bomgar-SCC-48D7E0E8
[2008/10/07 12:02:22 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Bomgar-SCC-48EBBF49
[2008/10/09 14:09:33 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Bomgar-SCC-48EBC1E7
[2008/10/09 14:09:33 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Bomgar-SCC-48EBC226
[2008/10/09 14:09:34 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Bomgar-SCC-48EBC490
[2008/10/08 11:50:53 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Bomgar-SCC-48ED0F01
[2008/01/18 21:08:04 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Application Data\CanonBJ
[2008/01/09 08:54:00 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Viewpoint
[2007/10/18 15:43:04 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\{174892B1-CBE7-44F5-86FF-AB555EFD73A3}
[2008/01/09 08:54:21 | 000,000,000 | ---D | M] -- C:\Documents and Settings\MANAGER\Application Data\acccore
[2010/05/19 15:09:23 | 000,000,000 | ---D | M] -- C:\Documents and Settings\MANAGER\Application Data\Canon
[2009/03/03 19:44:15 | 000,000,000 | ---D | M] -- C:\Documents and Settings\MANAGER\Application Data\deskPDF
[2010/04/01 16:33:20 | 000,000,000 | ---D | M] -- C:\Documents and Settings\MANAGER\Application Data\Facebook
[2010/07/22 11:16:09 | 000,000,000 | ---D | M] -- C:\Documents and Settings\MANAGER\Application Data\FoxPlayerAIR.01F2E49DE175CC541F416F2DF78BDD5E63AD0096.1
[2008/01/18 10:32:25 | 000,000,000 | ---D | M] -- C:\Documents and Settings\MANAGER\Application Data\Viewpoint
[2011/02/09 12:21:15 | 000,000,258 | ---- | M] () -- C:\WINDOWS\Tasks\Check Updates for Windows Live Toolbar.job

========== Purity Check ==========



========== Custom Scans ==========


< %SYSTEMDRIVE%\*.* >
[2010/02/16 21:39:34 | 000,277,651 | ---- | M] () -- C:\ads_err.dbf
[2008/10/16 13:06:05 | 000,000,000 | ---- | M] () -- C:\AUTOEXEC.BAT
[2011/02/04 14:53:12 | 000,000,211 | ---- | M] () -- C:\Boot.bak
[2011/02/09 12:43:03 | 000,000,327 | RHS- | M] () -- C:\boot.ini
[2004/08/03 23:00:00 | 000,260,272 | RHS- | M] () -- C:\cmldr
[2011/02/09 12:56:30 | 000,013,890 | ---- | M] () -- C:\ComboFix.txt
[2008/10/16 13:06:05 | 000,000,000 | ---- | M] () -- C:\CONFIG.SYS
[2011/02/09 12:52:02 | 1064,554,496 | -HS- | M] () -- C:\hiberfil.sys
[2008/10/16 13:06:05 | 000,000,000 | RHS- | M] () -- C:\IO.SYS
[2008/11/26 09:53:16 | 000,001,204 | -H-- | M] () -- C:\IPH.PH
[2008/10/16 13:06:05 | 000,000,000 | RHS- | M] () -- C:\MSDOS.SYS
[2004/08/03 21:38:34 | 000,047,564 | RHS- | M] () -- C:\NTDETECT.COM
[2009/06/23 10:38:54 | 000,250,048 | RHS- | M] () -- C:\ntldr
[2011/02/09 12:52:01 | 1598,029,824 | -HS- | M] () -- C:\pagefile.sys
[2010/12/15 03:20:55 | 000,000,184 | -H-- | M] () -- C:\sqmdata00.sqm
[2010/12/16 09:54:45 | 000,000,232 | -H-- | M] () -- C:\sqmdata01.sqm
[2010/12/20 11:43:06 | 000,000,268 | -H-- | M] () -- C:\sqmdata02.sqm
[2010/12/20 11:43:09 | 000,000,244 | -H-- | M] () -- C:\sqmdata03.sqm
[2010/12/21 11:06:32 | 000,000,232 | -H-- | M] () -- C:\sqmdata04.sqm
[2010/12/28 18:06:53 | 000,000,268 | -H-- | M] () -- C:\sqmdata05.sqm
[2010/12/30 12:32:26 | 000,000,268 | -H-- | M] () -- C:\sqmdata06.sqm
[2010/12/30 12:32:32 | 000,000,244 | -H-- | M] () -- C:\sqmdata07.sqm
[2011/01/01 03:16:30 | 000,000,244 | -H-- | M] () -- C:\sqmdata08.sqm
[2011/01/03 10:13:12 | 000,000,232 | -H-- | M] () -- C:\sqmdata09.sqm
[2011/01/04 18:56:37 | 000,000,268 | -H-- | M] () -- C:\sqmdata10.sqm
[2011/01/08 13:55:03 | 000,000,268 | -H-- | M] () -- C:\sqmdata11.sqm
[2011/01/10 18:59:29 | 000,000,268 | -H-- | M] () -- C:\sqmdata12.sqm
[2011/01/12 14:49:29 | 000,000,268 | -H-- | M] () -- C:\sqmdata13.sqm
[2011/02/02 15:56:42 | 000,000,268 | -H-- | M] () -- C:\sqmdata14.sqm
[2011/02/02 15:58:32 | 000,000,268 | -H-- | M] () -- C:\sqmdata15.sqm
[2011/02/02 16:06:20 | 000,000,268 | -H-- | M] () -- C:\sqmdata16.sqm
[2011/02/02 17:38:33 | 000,000,268 | -H-- | M] () -- C:\sqmdata17.sqm
[2011/02/03 10:46:57 | 000,000,268 | -H-- | M] () -- C:\sqmdata18.sqm
[2011/02/03 12:41:56 | 000,000,268 | -H-- | M] () -- C:\sqmdata19.sqm
[2010/12/15 03:20:55 | 000,000,172 | -H-- | M] () -- C:\sqmnoopt00.sqm
[2010/12/16 09:54:45 | 000,000,244 | -H-- | M] () -- C:\sqmnoopt01.sqm
[2010/12/20 11:43:06 | 000,000,244 | -H-- | M] () -- C:\sqmnoopt02.sqm
[2010/12/20 11:43:09 | 000,000,244 | -H-- | M] () -- C:\sqmnoopt03.sqm
[2010/12/21 11:06:32 | 000,000,244 | -H-- | M] () -- C:\sqmnoopt04.sqm
[2010/12/28 18:06:53 | 000,000,244 | -H-- | M] () -- C:\sqmnoopt05.sqm
[2010/12/30 12:32:26 | 000,000,244 | -H-- | M] () -- C:\sqmnoopt06.sqm
[2010/12/30 12:32:32 | 000,000,244 | -H-- | M] () -- C:\sqmnoopt07.sqm
[2011/01/01 03:16:30 | 000,000,244 | -H-- | M] () -- C:\sqmnoopt08.sqm
[2011/01/03 10:13:12 | 000,000,244 | -H-- | M] () -- C:\sqmnoopt09.sqm
[2011/01/04 18:56:37 | 000,000,244 | -H-- | M] () -- C:\sqmnoopt10.sqm
[2011/01/08 13:55:03 | 000,000,244 | -H-- | M] () -- C:\sqmnoopt11.sqm
[2011/01/10 18:59:29 | 000,000,244 | -H-- | M] () -- C:\sqmnoopt12.sqm
[2011/01/12 14:49:29 | 000,000,244 | -H-- | M] () -- C:\sqmnoopt13.sqm
[2011/02/02 15:56:42 | 000,000,244 | -H-- | M] () -- C:\sqmnoopt14.sqm
[2011/02/02 15:58:32 | 000,000,244 | -H-- | M] () -- C:\sqmnoopt15.sqm
[2011/02/02 16:06:20 | 000,000,244 | -H-- | M] () -- C:\sqmnoopt16.sqm
[2011/02/02 17:38:33 | 000,000,244 | -H-- | M] () -- C:\sqmnoopt17.sqm
[2011/02/03 10:46:57 | 000,000,244 | -H-- | M] () -- C:\sqmnoopt18.sqm
[2011/02/03 12:41:56 | 000,000,244 | -H-- | M] () -- C:\sqmnoopt19.sqm
[2011/02/09 12:31:18 | 000,033,696 | ---- | M] () -- C:\TDSSKiller.2.4.16.0_09.02.2011_12.30.21_log.txt
 
OTL Extras logfile created on: 2/9/2011 1:05:16 PM - Run 1
OTL by OldTimer - Version 3.2.20.6 Folder = C:\Documents and Settings\MANAGER\Desktop
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.13)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

1,015.00 Mb Total Physical Memory | 607.00 Mb Available Physical Memory | 60.00% Memory free
2.00 Gb Paging File | 2.00 Gb Available in Paging File | 84.00% Paging File free
Paging file location(s): C:\pagefile.sys 1524 3048 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 149.05 Gb Total Space | 134.14 Gb Free Space | 90.00% Space Free | Partition Type: NTFS
Drive T: | 74.45 Gb Total Space | 44.91 Gb Free Space | 60.32% Space Free | Partition Type: NTFS
Drive V: | 74.45 Gb Total Space | 44.91 Gb Free Space | 60.32% Space Free | Partition Type: NTFS
Drive W: | 74.45 Gb Total Space | 44.91 Gb Free Space | 60.32% Space Free | Partition Type: NTFS
Drive X: | 74.45 Gb Total Space | 44.91 Gb Free Space | 60.32% Space Free | Partition Type: NTFS
Drive Y: | 74.45 Gb Total Space | 44.91 Gb Free Space | 60.32% Space Free | Partition Type: NTFS
Drive Z: | 71.52 Gb Total Space | 50.97 Gb Free Space | 71.26% Space Free | Partition Type: NTFS

Computer Name: FINANCE | User Name: MANAGER | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.cpl [@ = cplfile] -- rundll32.exe shell32.dll,Control_RunDLL "%1",%*
.url [@ = InternetShortcut] -- rundll32.exe ieframe.dll,OpenURL %l

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
cplfile [cplopen] -- rundll32.exe shell32.dll,Control_RunDLL "%1",%*
exefile [open] -- "%1" %*
InternetShortcut [open] -- rundll32.exe ieframe.dll,OpenURL %l
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] -- %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] -- %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

========== System Restore Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sr]
"Start" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SrService]
"Start" = 2

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile]

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0
"DoNotAllowExceptions" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
"139:TCP" = 139:TCP:*:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:*:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:*:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:*:Enabled:@xpsp2res.dll,-22002

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0
"DoNotAllowExceptions" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008
"139:TCP" = 139:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22002

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files\Common Files\AOL\Loader\aolload.exe" = C:\Program Files\Common Files\AOL\Loader\aolload.exe:*:Enabled:AOL Loader -- (AOL LLC)
"C:\Program Files\SofTek Software\Lib\TBA.exe" = C:\Program Files\SofTek Software\Lib\TBA.exe:*:Enabled:The Business Assistant -- (SofTek Software Int'l, Inc.)
"C:\Program Files\Real\RealPlayer\realplay.exe" = C:\Program Files\Real\RealPlayer\realplay.exe:*:Enabled:RealPlayer -- (RealNetworks, Inc.)
"C:\Program Files\Google\Google Earth\client\googleearth.exe" = C:\Program Files\Google\Google Earth\client\googleearth.exe:*:Enabled:Google Earth -- (Google)


========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{0A755762-EED8-47AB-A446-505766F93D43}" = Atheros Communications Inc.(R) L2 Fast Ethernet Driver
"{1028298A-31E5-4881-BF14-749E1822D95B}" = Desktop Notifier
"{15B48AFF-A36F-424B-BD47-30DC156F5FAB}" = The Business Assistant
"{184E7118-0295-43C4-B72C-1D54AA75AAF7}" = Windows Live Mail
"{2D4F6BE3-6FEF-4FE9-9D01-1406B220D08C}" = Windows Live Photo Gallery
"{341201D4-4F61-4ADB-987E-9CCE4D83A58D}" = Windows Live Toolbar Extension (Windows Live Toolbar)
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{3F873E63-1CA5-4bdb-A8C7-D97012496DE3}" = Canon MF6500 Series
"{4286E640-B5FB-11DF-AC4B-005056C00008}" = Google Earth
"{502358FB-0718-45BC-B142-7511F1694D58}" = Macrogaming SweetIM 2.1
"{508CE775-4BA4-4748-82DF-FE28DA9F03B0}" = Windows Live Messenger
"{65DA2EC9-0642-47E9-AAE2-B5267AA14D75}" = Activation Assistant for the 2007 Microsoft Office suites
"{6811CAA0-BF12-11D4-9EA1-0050BAE317E1}" = PowerDVD
"{68E9A0DF-ED47-11D5-A3F2-00A0CC5DF8D2}" = Intellex Player
"{73568F76-7A37-9DB4-73B1-11DCF1A2FC52}" = FOX News Live Stream
"{774088D4-0777-4D78-904D-E435B318F5D2}" = Microsoft Antimalware
"{7745B7A9-F323-4BB9-9811-01BF57A028DA}" = Map Button (Windows Live Toolbar)
"{77A776C4-D10F-416D-88F0-53F2D9DCD9B3}" = Microsoft Security Client
"{786C4AD1-DCBA-49A6-B0EF-B317A344BD66}" = Windows Live Favorites for Windows Live Toolbar
"{90120000-0020-0409-0000-0000000FF1CE}" = Compatibility Pack for the 2007 Office system
"{91120409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office Standard Edition 2003
"{9176251A-4CC1-4DDB-B343-B487195EB397}" = Windows Live Writer
"{9422C8EA-B0C6-4197-B8FC-DC797658CA00}" = Windows Live Sign-in Assistant
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{A5C4AD72-25FE-4899-B6DF-6D8DF63C93CF}" = Highlight Viewer (Windows Live Toolbar)
"{A7E4ECCA-4A8E-4258-8EC8-2DCCF5B11320}" = Windows Live installer
"{A87B11AC-4344-4E5D-8B12-8F471A87DAD9}" = LightScribe 1.4.136.1
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{AC76BA86-7AD7-1033-7B44-A81200000003}" = Adobe Reader 8.1.2
"{B194272D-1F92-46DF-99EB-8D5CE91CB4EC}" = Adobe AIR
"{B28B351F-1232-46EA-85EF-B8EA91641033}" = Nero 7 Essentials
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{D5A145FC-D00C-4F1A-9119-EB4D9D659750}" = Windows Live Toolbar
"{F084395C-40FB-4DB3-981C-B51E74E1E83D}" = Smart Menus (Windows Live Toolbar)
"{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU]
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{F4F4F84E-804F-4E9A-84D7-C34283F0088F}" = RealUpgrade 1.0
"{F6D63A65-BD23-46F3-B9A3-87F442423481}" = SweetIM For Internet Explorer 3.0b
"{FEFDE51B-FDFC-4122-A9B5-4B2CF593FE11}_is1" = MessagePal
"Activation Assistant for the 2007 Microsoft Office suites" = Activation Assistant for the 2007 Microsoft Office suites
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"AIM_6" = AIM 6
"Ask Toolbar_is1" = Ask Toolbar
"CANONBJ_Deinstall_CNMCP75.DLL" = Canon iP1600
"deskPDF 2.5 Professional_is1" = deskPDF 2.5 Professional Edition
"FoxPlayerAIR.01F2E49DE175CC541F416F2DF78BDD5E63AD0096.1" = FOX News Live Stream
"Google Chrome" = Google Chrome
"Google Updater" = Google Updater
"GPL Ghostscript_is1" = Docudesk GPL Ghostscript 8.15
"HDMI" = Intel(R) Graphics Media Accelerator Driver
"IDNMitigationAPIs" = Microsoft Internationalized Domain Names Mitigation APIs
"ie7" = Windows Internet Explorer 7
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Microsoft Security Client" = Microsoft Security Essentials
"NLSDownlevelMapping" = Microsoft National Language Support Downlevel APIs
"Picasa 3" = Picasa 3
"POS-X Store Manager" = POS-X Store Manager
"Power Commander 3 Usb_is1" = Power Commander Control Center 3.2.0 (Test Build 1)
"RealPlayer 12.0" = RealPlayer
"ST6UNST #1" = Softwheels F&I System
"ST6UNST #2" = Softwheels F&I System Protection Menu Setup Utility
"ViewpointMediaPlayer" = Viewpoint Media Player
"WIC" = Windows Imaging Component
"Windows Live Toolbar" = Windows Live Toolbar
"Windows Media Format Runtime" = Windows Media Format Runtime
"Windows XP Service Pack" = Windows XP Service Pack 3
"WW_Check_Template" = Check Template

========== HKEY_USERS Uninstall List ==========

[HKEY_USERS\S-1-5-21-3071955782-306273710-422076765-1007\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Facebook Plug-In" = Facebook Plug-In
"GoToMeeting" = GoToMeeting 4.1.0.366
"workspacedesktop" = Workspace Desktop

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 2/8/2011 6:04:34 PM | Computer Name = FINANCE | Source = Application Error | ID = 1000
Description = Faulting application svchost.exe, version 5.1.2600.5512, faulting
module mshtml.dll, version 7.0.6000.17093, fault address 0x0010728a.

Error - 2/8/2011 6:24:10 PM | Computer Name = FINANCE | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt>
with error: The connection with the server was terminated abnormally

Error - 2/8/2011 6:24:10 PM | Computer Name = FINANCE | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt>
with error: This network connection does not exist.

Error - 2/8/2011 8:27:54 PM | Computer Name = FINANCE | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt>
with error: The connection with the server was terminated abnormally

Error - 2/8/2011 8:27:55 PM | Computer Name = FINANCE | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt>
with error: This network connection does not exist.

Error - 2/9/2011 1:30:34 AM | Computer Name = FINANCE | Source = Application Error | ID = 1000
Description = Faulting application svchost.exe, version 5.1.2600.5512, faulting
module ntdll.dll, version 5.1.2600.5755, fault address 0x00023845.

Error - 2/9/2011 3:07:05 PM | Computer Name = FINANCE | Source = Application Error | ID = 1000
Description = Faulting application f7zr38nz.exe, version 1.0.15.15530, faulting
module f7zr38nz.exe, version 1.0.15.15530, fault address 0x00067789.

Error - 2/9/2011 3:09:47 PM | Computer Name = FINANCE | Source = MPSampleSubmission | ID = 5000
Description = EventType mptelemetry, P1 8024402c, P2 endsearch, P3 search, P4 3.0.8107.0,
P5 mpsigdwn.dll, P6 3.0.8107.0, P7 microsoft security essentials (edb4fa23-53b8-4afa-8c5d-99752cca7094),
P8 NIL, P9 NIL, P10 NIL.

Error - 2/9/2011 3:41:22 PM | Computer Name = FINANCE | Source = MPSampleSubmission | ID = 5000
Description = EventType mptelemetry, P1 80072efe, P2 endsearch, P3 search, P4 3.0.8107.0,
P5 mpsigdwn.dll, P6 3.0.8107.0, P7 microsoft security essentials (edb4fa23-53b8-4afa-8c5d-99752cca7094),
P8 NIL, P9 NIL, P10 NIL.

Error - 2/9/2011 3:47:52 PM | Computer Name = FINANCE | Source = Application Error | ID = 1000
Description = Faulting application , version 0.0.0.0, faulting module unknown, version
0.0.0.0, fault address 0x7c923845.

[ System Events ]
Error - 2/9/2011 2:56:27 PM | Computer Name = FINANCE | Source = DCOM | ID = 10005
Description = DCOM got error "%1084" attempting to start the service EventSystem
with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF}

Error - 2/9/2011 2:57:28 PM | Computer Name = FINANCE | Source = Service Control Manager | ID = 7026
Description = The following boot-start or system-start driver(s) failed to load:
Fips intelppm MpFilter

Error - 2/9/2011 2:58:46 PM | Computer Name = FINANCE | Source = DCOM | ID = 10005
Description = DCOM got error "%1084" attempting to start the service EventSystem
with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF}

Error - 2/9/2011 2:59:26 PM | Computer Name = FINANCE | Source = Dhcp | ID = 1002
Description = The IP address lease 10.0.0.108 for the Network Card with network
address 001BFCEC3D83 has been denied by the DHCP server 10.0.0.100 (The DHCP Server
sent a DHCPNACK message).

Error - 2/9/2011 3:09:45 PM | Computer Name = FINANCE | Source = Microsoft Antimalware | ID = 2001
Description = %%860 has encountered an error trying to update signatures. New Signature
Version: Previous Signature Version: 1.97.1055.0 Update Source: %%859 Update Stage:
%%852 Source Path: http://www.microsoft.com Signature Type: %%800 Update Type: %%803

User:
NT AUTHORITY\SYSTEM Current Engine Version: Previous Engine Version: 1.1.6502.0 Error
code: 0x8024402c Error description: An unexpected problem occurred while checking
for updates. For information on installing or troubleshooting updates, see Help
and Support.

Error - 2/9/2011 3:11:01 PM | Computer Name = FINANCE | Source = System Error | ID = 1003
Description = Error code 1000007f, parameter1 0000000d, parameter2 00000000, parameter3
00000000, parameter4 00000000.

Error - 2/9/2011 3:41:22 PM | Computer Name = FINANCE | Source = Microsoft Antimalware | ID = 2001
Description = %%860 has encountered an error trying to update signatures. New Signature
Version: Previous Signature Version: 1.97.1055.0 Update Source: %%859 Update Stage:
%%852 Source Path: Default URL Signature Type: %%800 Update Type: %%803 User: NT AUTHORITY\SYSTEM

Current
Engine Version: Previous Engine Version: 1.1.6502.0 Error code: 0x80072efe Error
description: The connection with the server was terminated abnormally

Error - 2/9/2011 4:05:16 PM | Computer Name = FINANCE | Source = Dhcp | ID = 1002
Description = The IP address lease 10.0.0.108 for the Network Card with network
address 001BFCEC3D83 has been denied by the DHCP server 10.0.0.100 (The DHCP Server
sent a DHCPNACK message).

Error - 2/9/2011 4:32:28 PM | Computer Name = FINANCE | Source = Dhcp | ID = 1002
Description = The IP address lease 10.0.0.108 for the Network Card with network
address 001BFCEC3D83 has been denied by the DHCP server 10.0.0.100 (The DHCP Server
sent a DHCPNACK message).

Error - 2/9/2011 4:52:04 PM | Computer Name = FINANCE | Source = Dhcp | ID = 1002
Description = The IP address lease 10.0.0.108 for the Network Card with network
address 001BFCEC3D83 has been denied by the DHCP server 10.0.0.100 (The DHCP Server
sent a DHCPNACK message).


< End of report >
 
Very good :)

1. Update your Java version here: http://www.java.com/en/download/installed.jsp

Note 1: UNCHECK any pre-checked toolbar and/or software offered with the Java update. The pre-checked toolbars/software are not part of the Java update.

Note 2: The Java Quick Starter (JQS.exe) adds a service to improve the initial startup time of Java applets and applications. If you don't want to run another extra service, go to Start > Control Panel > Java > Advanced > Miscellaneous and uncheck the box for Java Quick Starter. Click OK and restart your computer.

2. Now, we need to remove old Java version and its remnants...

Download JavaRa to your desktop and unzip it to its own folder

  • Run JavaRa.exe (Vista users! Right click on JavaRa.exe, click Run As Administrator), pick the language of your choice and click Select. Then click Remove Older Versions.
  • Accept any prompts.


===============================================================

Run OTL

  • Under the Custom Scans/Fixes box at the bottom, paste in the following

    Code:
    :OTL
    PRC - [2007/01/04 13:38:08 | 000,024,652 | ---- | M] (Viewpoint Corporation) -- C:\Program Files\Viewpoint\Common\ViewpointService.exe
    SRV - [2007/01/04 13:38:08 | 000,024,652 | ---- | M] (Viewpoint Corporation) [Auto | Running] -- C:\Program Files\Viewpoint\Common\ViewpointService.exe -- (Viewpoint Manager Service)
    O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - No CLSID value found.
    O3 - HKLM\..\Toolbar: (Ask Toolbar) - {3041d03e-fd4b-44e0-b742-2d9b88305f98} - C:\Program Files\AskBarDis\bar\bin\askBar.dll (Ask.com)
    O3 - HKU\.DEFAULT\..\Toolbar\WebBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No CLSID value found.
    O3 - HKU\S-1-5-18\..\Toolbar\WebBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No CLSID value found.
    O3 - HKU\S-1-5-21-3071955782-306273710-422076765-1007\..\Toolbar\ShellBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No CLSID value found.
    O3 - HKU\S-1-5-21-3071955782-306273710-422076765-1007\..\Toolbar\WebBrowser: (Ask Toolbar) - {3041D03E-FD4B-44E0-B742-2D9B88305F98} - C:\Program Files\AskBarDis\bar\bin\askBar.dll (Ask.com)
    O16 - DPF: Web-Based Email Tools http://email.secureserver.net/Download.CAB (Reg Error: Key error.)
    [2011/02/03 16:33:18 | 000,000,000 | ---D | C] -- C:\Program Files\AskBarDis
    [4 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
    [1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
    [2008/01/09 08:54:00 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Viewpoint
    [2008/01/18 10:32:25 | 000,000,000 | ---D | M] -- C:\Documents and Settings\MANAGER\Application Data\Viewpoint
    
    
    :Files
    C:\Program Files\Viewpoint
    
    :Commands
    [purity]
    [emptytemp]
    [emptyflash]
    [Reboot]
  • Then click the Run Fix button at the top
  • Let the program run unhindered, reboot the PC when it is done
  • You will get a log that shows the results of the fix. Please post it.


===============================================================

Last scans...

1. Download Security Check from HERE, and save it to your Desktop.

  • Double-click SecurityCheck.exe
  • Follow the onscreen instructions inside of the black box.
  • A Notepad document should open automatically called checkup.txt; please post the contents of that document.

    NOTE SecurityCheck may produce some false warning(s), so leave the results reading to me.



2. Download Temp File Cleaner (TFC)

  • Double click on TFC.exe to run the program.
  • Click on Start button to begin cleaning process.
  • TFC will close all running programs, and it may ask you to restart computer.



3. Please run a free online scan with the ESET Online Scanner


  • Disable your antivirus program
  • Tick the box next to YES, I accept the Terms of Use
  • Click Start
  • IMPORTANT! UN-check Remove found threats
  • Accept any security warnings from your browser.
  • Check Scan archives
  • Click Start
  • ESET will then download updates for itself, install itself, and begin scanning your computer. Please be patient as this can take some time.
  • When the scan completes, push List of found threats
  • Click on Export to text file , and save the file to your desktop using a unique name, such as ESETScan. Include the contents of this report in your next reply.
  • NOTE. If Eset won't find any threats, it won't produce any log.
 
Similar issue

I HAVE DONE EVERYTHING HE DID AND STILL HAVE A SIMILAR ISSUE, NOW IT WONT LOAD AT ALL, I PLUGGED THE HARD DRIVE IN TO A DIFFERENT COMPUTER AND IT WONT LOAD AT PRIMARY DRIVE OFF THE OS BUT I CAN SEE IT AS A SECONDARY DRIVE. HERE IS MY STORY.


I think I have a virus, every time my virus scan starts it starts like normal, then it either pauses it self or freezes. When it does this my whole computer freezes or runs so slow it takes 10+ min for anything to do anything. As well. I can’t get to the start menu or use any programs. I have to restart the computer. I have checked task manager and it doesn’t show anything running that would be slowing it down. Also when it does this I can’t stop of pause or cancel. I tried to do system restore, but they are all deleted. I saved a new restore point and it will stay there, but as soon as the scan starts the restore point gets deleted.
Can anyone Please help.
Thanks.
Kris
 
Back
Top