Jump to content

Help! XP Security 2012 rogue


Recommended Posts

Hi Ali,

Here are the 2 logs;

OTL logfile created on: 04/07/2011 15:46:43 - Run 1

OTL by OldTimer - Version 3.2.25.0 Folder = C:\Documents and Settings\WASCP\My Documents\Downloads

Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation

Internet Explorer (Version = 7.0.5730.13)

Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy

1.96 Gb Total Physical Memory | 1.45 Gb Available Physical Memory | 73.97% Memory free

3.81 Gb Paging File | 3.47 Gb Available in Paging File | 91.21% Paging File free

Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files

Drive C: | 148.92 Gb Total Space | 131.01 Gb Free Space | 87.97% Space Free | Partition Type: NTFS

Computer Name: BOBCOLLINS | User Name: Bob Collins | Logged in as Administrator.

Boot Mode: Normal | Scan Mode: Current user | Quick Scan

Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - [2011/07/04 15:39:22 | 000,580,096 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\WASCP\My Documents\Downloads\OTL.scr

PRC - [2011/06/16 06:32:38 | 000,924,632 | ---- | M] (Mozilla Corporation) -- C:\Program Files\Mozilla Firefox\firefox.exe

PRC - [2008/06/10 05:27:04 | 000,144,784 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe

PRC - [2008/05/23 15:06:08 | 000,128,296 | ---- | M] (CyberLink Corp.) -- C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe

PRC - [2008/04/14 14:00:00 | 001,033,728 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe

PRC - [2007/06/12 18:09:14 | 000,408,344 | ---- | M] (Intel Corporation) -- C:\Program Files\Intel\AMT\atchk.exe

========== Modules (SafeList) ==========

MOD - [2011/07/04 15:39:22 | 000,580,096 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\WASCP\My Documents\Downloads\OTL.scr

MOD - [2010/08/23 18:12:02 | 001,054,208 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.6028_x-ww_61e65202\comctl32.dll

========== Win32 Services (SafeList) ==========

SRV - File not found [On_Demand | Stopped] -- -- (stllssvr)

SRV - File not found [Disabled | Stopped] -- -- (AMService)

SRV - [2007/10/03 16:45:02 | 000,358,936 | ---- | M] (Intel Corporation) [Disabled | Stopped] -- C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTmon.exe -- (IAANTMON) Intel®

SRV - [2007/06/12 18:09:16 | 002,521,880 | ---- | M] (Intel) [Disabled | Stopped] -- C:\Program Files\Intel\AMT\UNS.exe -- (UNS) Intel®

SRV - [2007/06/12 18:09:16 | 000,183,064 | ---- | M] (Intel Corporation) [Disabled | Stopped] -- C:\Program Files\Intel\AMT\atchksrv.exe -- (atchksrv) Intel®

SRV - [2007/06/12 18:09:14 | 000,109,336 | ---- | M] (Intel) [Disabled | Stopped] -- C:\Program Files\Intel\AMT\LMS.exe -- (LMS) Intel®

SRV - [2007/01/23 04:58:04 | 000,133,968 | ---- | M] (Intel Corporation) [Disabled | Stopped] -- C:\Program Files\Intel\ASF Agent\ASFAgent.exe -- (ASFAgent)

========== Driver Services (SafeList) ==========

DRV - [2007/09/25 04:12:48 | 000,392,960 | ---- | M] (Sensaura) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\senfilt.sys -- (SenFiltService)

DRV - [2007/07/24 03:42:12 | 000,045,056 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\HECI.sys -- (HECI) Intel®

DRV - [2007/07/23 16:05:20 | 000,009,104 | ---- | M] (Roxio) [File_System | Auto | Running] -- C:\WINDOWS\system32\drivers\DLADResM.SYS -- (DLADResM)

DRV - [2007/07/23 16:04:58 | 000,037,360 | ---- | M] (Roxio) [File_System | Auto | Running] -- C:\WINDOWS\system32\drivers\DLABMFSM.SYS -- (DLABMFSM)

DRV - [2007/07/23 16:04:56 | 000,098,448 | ---- | M] (Roxio) [File_System | Auto | Running] -- C:\WINDOWS\system32\drivers\DLAUDF_M.SYS -- (DLAUDF_M)

DRV - [2007/07/23 16:04:56 | 000,093,552 | ---- | M] (Roxio) [File_System | Auto | Running] -- C:\WINDOWS\system32\drivers\DLAUDFAM.SYS -- (DLAUDFAM)

DRV - [2007/07/23 16:04:54 | 000,027,216 | ---- | M] (Roxio) [File_System | Auto | Running] -- C:\WINDOWS\system32\drivers\DLAOPIOM.SYS -- (DLAOPIOM)

DRV - [2007/07/23 16:04:52 | 000,032,848 | ---- | M] (Roxio) [File_System | Auto | Running] -- C:\WINDOWS\system32\drivers\DLABOIOM.SYS -- (DLABOIOM)

DRV - [2007/07/23 16:04:52 | 000,016,304 | ---- | M] (Roxio) [File_System | Auto | Running] -- C:\WINDOWS\system32\drivers\DLAPoolM.SYS -- (DLAPoolM)

DRV - [2007/07/23 16:04:50 | 000,108,752 | ---- | M] (Roxio) [File_System | Auto | Running] -- C:\WINDOWS\system32\drivers\DLAIFS_M.SYS -- (DLAIFS_M)

DRV - [2007/07/23 15:49:44 | 000,030,064 | ---- | M] (Roxio) [File_System | System | Running] -- C:\WINDOWS\system32\drivers\DLARTL_M.SYS -- (DLARTL_M)

DRV - [2007/07/23 15:49:44 | 000,014,576 | ---- | M] (Roxio) [Kernel | Boot | Running] -- C:\WINDOWS\System32\Drivers\DLACDBHM.SYS -- (DLACDBHM)

DRV - [2007/01/23 04:45:44 | 000,042,832 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\Asfalrt.sys -- (AsfAlrt)

========== Standard Registry (SafeList) ==========

========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.thecollegespartnership.co.uk/content.asp?ContentID=1

IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..extensions.enabledItems: {1E73965B-8B48-48be-9C8D-68B920ABC1C4}:10.0.0.1374

FF - prefs.js..network.proxy.type: 0

FF - HKLM\software\mozilla\Firefox\Extensions\\{1E73965B-8B48-48be-9C8D-68B920ABC1C4}: C:\Program Files\AVG\AVG10\Firefox4\ [2011/06/03 08:20:10 | 000,000,000 | ---D | M]

FF - HKLM\software\mozilla\Mozilla Firefox 5.0\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011/07/01 17:03:45 | 000,000,000 | ---D | M]

FF - HKLM\software\mozilla\Mozilla Firefox 5.0\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins

[2011/06/24 10:24:42 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\WASCP\Application Data\Mozilla\Extensions

[2011/06/24 10:25:46 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\WASCP\Application Data\Mozilla\Firefox\Profiles\rfkfg9b9.default\extensions

[2011/06/24 10:25:46 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- C:\Documents and Settings\WASCP\Application Data\Mozilla\Firefox\Profiles\rfkfg9b9.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}

[2011/07/01 17:03:45 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions

File not found (No name found) --

[2011/06/16 06:32:38 | 000,142,296 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\browsercomps.dll

[2010/01/01 10:00:00 | 000,001,538 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\amazon-en-GB.xml

[2011/06/24 10:23:07 | 000,002,428 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\babylon.xml

[2010/01/01 10:00:00 | 000,002,252 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\bing.xml

[2010/01/01 10:00:00 | 000,000,947 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\chambers-en-GB.xml

[2010/01/01 10:00:00 | 000,001,180 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\eBay-en-GB.xml

[2010/01/01 10:00:00 | 000,001,135 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\yahoo-en-GB.xml

Hosts file not found

O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - File not found

O2 - BHO: (SSVHelper Class) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll (Sun Microsystems, Inc.)

O2 - BHO: (Skype Plug-In) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)

O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.7.6406.1642\swg.dll (Google Inc.)

O3 - HKLM\..\Toolbar: (no name) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - No CLSID value found.

O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {A057A204-BACC-4D26-9990-79A187E2698E} - No CLSID value found.

O4 - HKLM..\Run: [atchk] C:\Program Files\Intel\AMT\atchk.exe (Intel Corporation)

O4 - HKLM..\Run: [iAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe (Intel Corporation)

O4 - HKLM..\Run: [PDVDDXSrv] C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe (CyberLink Corp.)

O4 - HKLM..\Run: [sunJavaUpdateSched] C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe (Sun Microsystems, Inc.)

O4 - HKLM..\Run: [userFaultCheck] File not found

O4 - HKLM..\RunOnce: [AvgUninstallURL] C:\WINDOWS\System32\cmd.exe (Microsoft Corporation)

O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Infodelivery present

O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present

O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1

O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: LinkResolveIgnoreLinkInfo = 0

O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoResolveSearch = 1

O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863

O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323

O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0

O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present

O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323

O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: LinkResolveIgnoreLinkInfo = 0

O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863

O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0

O9 - Extra 'Tools' menuitem : Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\npjpi160_07.dll (Sun Microsystems, Inc.)

O9 - Extra Button: Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)

O9 - Extra 'Tools' menuitem : Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)

O15 - HKCU\..Trusted Domains: //@install.mar@/ ([]msni in My Computer)

O15 - HKCU\..Trusted Domains: //@mail.mar@/ ([]msni in Local intranet)

O15 - HKCU\..Trusted Domains: tribalhosted.co.uk ([csg2] https in Trusted sites)

O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} http://www.update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1228722288531 (WUWebControl Class)

O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab (Java Plug-in 1.6.0_07)

O16 - DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab (Java Plug-in 1.6.0_07)

O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab (Java Plug-in 1.6.0_07)

O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.2.1

O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)

O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)

O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)

O24 - Desktop WallPaper: C:\Documents and Settings\WASCP\Local Settings\Application Data\Microsoft\Wallpaper1.bmp

O24 - Desktop BackupWallPaper: C:\Documents and Settings\WASCP\Local Settings\Application Data\Microsoft\Wallpaper1.bmp

O32 - HKLM CDRom: AutoRun - 1

O32 - AutoRun File - [2008/04/25 23:29:32 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]

O34 - HKLM BootExecute: (autocheck autochk *) - File not found

O35 - HKLM\..comfile [open] -- "%1" %*

O35 - HKLM\..exefile [open] -- "%1" %*

O37 - HKLM\...com [@ = comfile] -- "%1" %*

O37 - HKLM\...exe [@ = exefile] -- "%1" %*

NetSvcs: 6to4 - File not found

NetSvcs: Ias - File not found

NetSvcs: Iprip - File not found

NetSvcs: Irmon - File not found

NetSvcs: NWCWorkstation - File not found

NetSvcs: Nwsapagent - File not found

NetSvcs: WmdmPmSp - File not found

CREATERESTOREPOINT

Restore point Set: OTL Restore Point

========== Files/Folders - Created Within 30 Days ==========

[2011/07/04 14:01:18 | 000,039,984 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbamswissarmy.sys

[2011/07/04 14:01:18 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\Malwarebytes' Anti-Malware

[2011/07/04 14:01:15 | 000,022,712 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbam.sys

[2011/07/04 14:01:15 | 000,000,000 | ---D | C] -- C:\Program Files\Malwarebytes' Anti-Malware

[2011/07/04 10:08:29 | 000,000,000 | ---D | C] -- C:\Program Files\ESET

[2011/07/04 10:00:21 | 000,000,000 | -HSD | C] -- C:\RECYCLER

[2011/07/01 17:39:12 | 000,000,000 | ---D | C] -- C:\Documents and Settings\WASCP\Desktop\Richies tools

[2011/07/01 17:28:46 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\avg9

[2011/07/01 16:23:41 | 000,000,000 | RHSD | C] -- C:\cmdcons

[2011/07/01 16:20:38 | 000,000,000 | ---D | C] -- C:\WINDOWS\ERDNT

[2011/07/01 16:15:10 | 000,000,000 | ---D | C] -- C:\Malwarebytes' Anti-Malware

[2011/07/01 15:16:57 | 000,000,000 | ---D | C] -- C:\Documents and Settings\WASCP\Application Data\Malwarebytes

[2011/07/01 15:16:52 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Malwarebytes

[2011/06/24 15:04:31 | 000,000,000 | ---D | C] -- C:\Program Files\win

[2011/06/24 10:24:24 | 000,000,000 | ---D | C] -- C:\Documents and Settings\WASCP\Local Settings\Application Data\Mozilla

[2011/06/24 10:24:24 | 000,000,000 | ---D | C] -- C:\Documents and Settings\WASCP\Application Data\Mozilla

[2011/06/24 10:23:07 | 000,000,000 | ---D | C] -- C:\Program Files\Mozilla Firefox

[2011/06/24 08:56:47 | 000,000,000 | ---D | C] -- C:\Program Files\Advanced PC Tweaker

[2011/06/23 11:54:11 | 000,000,000 | ---D | C] -- C:\Documents and Settings\WASCP\Application Data\MSNInstaller

[2011/06/23 10:48:50 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\NtmsData

[2011/06/21 12:26:48 | 000,000,000 | ---D | C] -- C:\Program Files\Spybot - Search & Destroy

[2011/06/21 12:26:48 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy

[2011/06/21 11:17:57 | 000,000,000 | ---D | C] -- C:\svest

[2011/06/20 13:06:09 | 000,000,000 | ---D | C] -- C:\Documents and Settings\NetworkService\Local Settings\Application Data\NVIDIA Corporation

[2011/06/10 08:22:59 | 000,000,000 | ---D | C] -- C:\found.000

[2011/06/08 14:53:31 | 000,000,000 | ---D | C] -- C:\Documents and Settings\NetworkService\Application Data\Google

========== Files - Modified Within 30 Days ==========

[2011/07/04 15:45:20 | 000,002,206 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl

[2011/07/04 15:45:07 | 000,000,892 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job

[2011/07/04 15:45:04 | 2101,964,800 | -HS- | M] () -- C:\hiberfil.sys

[2011/07/04 15:45:04 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat

[2011/07/04 14:42:02 | 000,000,896 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job

[2011/07/04 14:01:18 | 000,000,786 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk

[2011/07/04 12:45:25 | 000,267,800 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT

[2011/07/04 12:10:32 | 000,000,664 | ---- | M] () -- C:\WINDOWS\System32\d3d9caps.dat

[2011/07/04 11:27:44 | 000,001,731 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Adobe Reader 9.lnk

[2011/07/04 09:53:19 | 000,467,220 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat

[2011/07/04 09:53:19 | 000,080,310 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat

[2011/07/01 17:03:46 | 000,000,744 | ---- | M] () -- C:\Documents and Settings\WASCP\Application Data\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox.lnk

[2011/07/01 17:03:46 | 000,000,726 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Mozilla Firefox.lnk

[2011/07/01 16:23:45 | 000,000,327 | RHS- | M] () -- C:\boot.ini

[2011/06/24 12:12:25 | 000,000,512 | ---- | M] () -- C:\WINDOWS\tasks\One-Click Tweak.job

[2011/06/24 10:59:40 | 000,001,374 | ---- | M] () -- C:\WINDOWS\imsins.BAK

[2011/06/24 10:24:26 | 000,000,000 | ---- | M] () -- C:\WINDOWS\nsreg.dat

[2011/06/23 11:02:24 | 000,000,127 | ---- | M] () -- C:\WINDOWS\System32\MRT.INI

[2011/06/21 13:46:17 | 000,002,312 | ---- | M] () -- C:\WINDOWS\wininit.ini

========== Files Created - No Company Name ==========

[2011/07/04 15:45:04 | 2101,964,800 | -HS- | C] () -- C:\hiberfil.sys

[2011/07/04 14:01:18 | 000,000,786 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk

[2011/07/04 11:27:43 | 000,001,731 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Adobe Reader 9.lnk

[2011/07/01 17:03:46 | 000,000,744 | ---- | C] () -- C:\Documents and Settings\WASCP\Application Data\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox.lnk

[2011/07/01 17:03:46 | 000,000,732 | ---- | C] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Mozilla Firefox.lnk

[2011/07/01 17:03:46 | 000,000,726 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Mozilla Firefox.lnk

[2011/07/01 16:23:45 | 000,000,211 | ---- | C] () -- C:\Boot.bak

[2011/07/01 16:23:43 | 000,260,272 | RHS- | C] () -- C:\cmldr

[2011/06/24 10:24:26 | 000,000,000 | ---- | C] () -- C:\WINDOWS\nsreg.dat

[2011/06/24 08:57:01 | 000,000,512 | ---- | C] () -- C:\WINDOWS\tasks\One-Click Tweak.job

[2011/06/20 08:32:26 | 000,000,127 | ---- | C] () -- C:\WINDOWS\System32\MRT.INI

[2011/05/24 08:13:03 | 000,000,053 | ---- | C] () -- C:\WINDOWS\System32\urhtps.dat

[2011/05/11 15:01:39 | 000,000,664 | ---- | C] () -- C:\WINDOWS\System32\d3d9caps.dat

[2009/09/22 08:17:46 | 000,013,312 | ---- | C] () -- C:\Documents and Settings\WASCP\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini

[2009/03/30 11:07:16 | 000,038,433 | ---- | C] () -- C:\Documents and Settings\WASCP\Application Data\Comma Separated Values (Windows).ADR

[2009/01/29 12:49:45 | 000,000,056 | -H-- | C] () -- C:\WINDOWS\System32\ezsidmv.dat

[2008/10/16 20:44:45 | 000,077,824 | ---- | C] () -- C:\WINDOWS\setpwr32.exe

[2008/10/16 20:44:32 | 000,204,800 | ---- | C] () -- C:\WINDOWS\System32\igfxCoIn_v4837.dll

[2008/10/16 20:44:13 | 000,001,167 | ---- | C] () -- C:\WINDOWS\System32\OEMINFO.INI

[2008/10/16 12:00:05 | 000,000,061 | ---- | C] () -- C:\WINDOWS\smscfg.ini

[2008/10/16 11:56:13 | 000,002,312 | ---- | C] () -- C:\WINDOWS\wininit.ini

[2008/05/26 21:59:42 | 000,018,904 | ---- | C] () -- C:\WINDOWS\System32\structuredqueryschematrivial.bin

[2008/05/26 21:59:40 | 000,106,605 | ---- | C] () -- C:\WINDOWS\System32\structuredqueryschema.bin

[2008/04/25 23:31:41 | 000,002,048 | --S- | C] () -- C:\WINDOWS\bootstat.dat

[2008/04/25 23:27:18 | 000,021,640 | ---- | C] () -- C:\WINDOWS\System32\emptyregdb.dat

[2008/04/25 23:26:32 | 000,001,793 | ---- | C] () -- C:\WINDOWS\System32\fxsperf.ini

[2008/04/25 18:16:24 | 000,004,569 | ---- | C] () -- C:\WINDOWS\System32\secupd.dat

[2008/04/25 18:16:22 | 000,467,220 | ---- | C] () -- C:\WINDOWS\System32\perfh009.dat

[2008/04/25 18:16:22 | 000,272,128 | ---- | C] () -- C:\WINDOWS\System32\perfi009.dat

[2008/04/25 18:16:22 | 000,080,310 | ---- | C] () -- C:\WINDOWS\System32\perfc009.dat

[2008/04/25 18:16:22 | 000,028,626 | ---- | C] () -- C:\WINDOWS\System32\perfd009.dat

[2008/04/25 18:16:22 | 000,004,627 | ---- | C] () -- C:\WINDOWS\System32\oembios.dat

[2008/04/25 18:16:21 | 013,107,200 | ---- | C] () -- C:\WINDOWS\System32\oembios.bin

[2008/04/25 18:16:20 | 000,000,741 | ---- | C] () -- C:\WINDOWS\System32\noise.dat

[2008/04/25 18:16:18 | 000,673,088 | ---- | C] () -- C:\WINDOWS\System32\mlang.dat

[2008/04/25 18:16:18 | 000,046,258 | ---- | C] () -- C:\WINDOWS\System32\mib.bin

[2008/04/25 18:16:13 | 000,218,003 | ---- | C] () -- C:\WINDOWS\System32\dssec.dat

[2008/04/25 18:16:11 | 000,001,804 | ---- | C] () -- C:\WINDOWS\System32\Dcache.bin

[2008/04/25 11:22:39 | 000,004,161 | ---- | C] () -- C:\WINDOWS\ODBCINST.INI

[2008/04/25 11:21:52 | 000,267,800 | ---- | C] () -- C:\WINDOWS\System32\FNTCACHE.DAT

[2007/09/27 10:51:02 | 000,020,698 | ---- | C] () -- C:\WINDOWS\System32\idxcntrs.ini

[2007/09/27 10:48:48 | 000,030,628 | ---- | C] () -- C:\WINDOWS\System32\gsrvctr.ini

[2007/09/27 10:48:28 | 000,031,698 | ---- | C] () -- C:\WINDOWS\System32\gthrctr.ini

[2007/02/28 06:03:32 | 000,080,720 | ---- | C] () -- C:\WINDOWS\System32\AsfBios.dll

[2007/01/23 04:45:40 | 000,025,424 | ---- | C] () -- C:\WINDOWS\System32\drivers\netamsg.dll

========== LOP Check ==========

[2011/07/01 16:19:59 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\AVG10

[2011/07/04 12:44:34 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\avg9

[2010/10/22 07:56:24 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Application Data\Common Files

[2010/10/22 07:55:18 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\MFAData

[2011/07/04 11:26:20 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\TEMP

[2011/02/03 13:38:54 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\W3i

[2010/10/22 08:02:02 | 000,000,000 | ---D | M] -- C:\Documents and Settings\WASCP\Application Data\AVG10

[2011/05/13 08:29:40 | 000,000,000 | ---D | M] -- C:\Documents and Settings\WASCP\Application Data\Avidat

[2011/02/03 13:39:33 | 000,000,000 | ---D | M] -- C:\Documents and Settings\WASCP\Application Data\FinalTorrent

[2011/05/31 14:33:40 | 000,000,000 | ---D | M] -- C:\Documents and Settings\WASCP\Application Data\Geaw

[2009/02/12 09:36:16 | 000,000,000 | ---D | M] -- C:\Documents and Settings\WASCP\Application Data\ICAClient

[2011/06/24 08:26:00 | 000,000,000 | ---D | M] -- C:\Documents and Settings\WASCP\Application Data\MSNInstaller

[2010/10/26 10:54:21 | 000,000,000 | ---D | M] -- C:\Documents and Settings\WASCP\Application Data\Registry Mechanic

[2011/06/10 08:31:16 | 000,000,000 | ---D | M] -- C:\Documents and Settings\WASCP\Application Data\Vytea

[2009/03/30 10:52:10 | 000,000,000 | ---D | M] -- C:\Documents and Settings\WASCP\Application Data\Windows Desktop Search

[2009/07/01 09:40:09 | 000,000,000 | ---D | M] -- C:\Documents and Settings\WASCP\Application Data\Windows Search

[2011/06/24 12:12:25 | 000,000,512 | ---- | M] () -- C:\WINDOWS\Tasks\One-Click Tweak.job

========== Purity Check ==========

========== Custom Scans ==========

< %SYSTEMDRIVE%\*.exe >

< %systemroot%\*. /mp /s >

< hklm\software\clients\startmenuinternet|command /rs >

HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\FIREFOX.EXE\InstallInfo\\HideIconsCommand: "C:\Program Files\Mozilla Firefox\uninstall\helper.exe" /HideShortcuts [2011/06/16 06:32:40 | 000,712,976 | ---- | M] (Mozilla Corporation)

HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\FIREFOX.EXE\InstallInfo\\ShowIconsCommand: "C:\Program Files\Mozilla Firefox\uninstall\helper.exe" /ShowShortcuts [2011/06/16 06:32:40 | 000,712,976 | ---- | M] (Mozilla Corporation)

HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\FIREFOX.EXE\InstallInfo\\ReinstallCommand: "C:\Program Files\Mozilla Firefox\uninstall\helper.exe" /SetAsDefaultAppGlobal [2011/06/16 06:32:40 | 000,712,976 | ---- | M] (Mozilla Corporation)

HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\FIREFOX.EXE\shell\open\command\\: C:\Program Files\Mozilla Firefox\firefox.exe [2011/06/16 06:32:38 | 000,924,632 | ---- | M] (Mozilla Corporation)

HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\FIREFOX.EXE\shell\properties\command\\: "C:\Program Files\Mozilla Firefox\firefox.exe" -preferences [2011/06/16 06:32:38 | 000,924,632 | ---- | M] (Mozilla Corporation)

HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\FIREFOX.EXE\shell\safemode\command\\: "C:\Program Files\Mozilla Firefox\firefox.exe" -safe-mode [2011/06/16 06:32:38 | 000,924,632 | ---- | M] (Mozilla Corporation)

HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\Google Chrome\InstallInfo\\ShowIconsCommand: "C:\Program Files\Google\Chrome\Application\chrome.exe" --show-icons [2011/06/24 08:25:50 | 001,012,792 | ---- | M] (Google Inc.)

HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\Google Chrome\InstallInfo\\HideIconsCommand: "C:\Program Files\Google\Chrome\Application\chrome.exe" --hide-icons [2011/06/24 08:25:50 | 001,012,792 | ---- | M] (Google Inc.)

HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\Google Chrome\InstallInfo\\ReinstallCommand: "C:\Program Files\Google\Chrome\Application\chrome.exe" --make-default-browser [2011/06/24 08:25:50 | 001,012,792 | ---- | M] (Google Inc.)

HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\Google Chrome\shell\open\command\\: "C:\Program Files\Google\Chrome\Application\chrome.exe" [2011/06/24 08:25:50 | 001,012,792 | ---- | M] (Google Inc.)

HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\IEXPLORE.EXE\InstallInfo\\ReinstallCommand: "C:\WINDOWS\system32\ie4uinit.exe" -reinstall [2011/04/25 14:00:32 | 000,070,656 | ---- | M] (Microsoft Corporation)

HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\IEXPLORE.EXE\InstallInfo\\HideIconsCommand: "C:\WINDOWS\system32\ie4uinit.exe" -hide [2011/04/25 14:00:32 | 000,070,656 | ---- | M] (Microsoft Corporation)

HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\IEXPLORE.EXE\InstallInfo\\ShowIconsCommand: "C:\WINDOWS\system32\ie4uinit.exe" -show [2011/04/25 14:00:32 | 000,070,656 | ---- | M] (Microsoft Corporation)

HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\IEXPLORE.EXE\shell\open\command\\: "C:\Program Files\Internet Explorer\iexplore.exe" [2011/04/21 12:58:25 | 000,634,648 | ---- | M] (Microsoft Corporation)

HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\IEXPLORE.EXE\shell\open\command\\@: C:\Program Files (x86)\Internet Explorer\iexplore.exe

< hklm\software\clients\startmenuinternet|command /64 /rs >

HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\FIREFOX.EXE\InstallInfo\\HideIconsCommand: "C:\Program Files\Mozilla Firefox\uninstall\helper.exe" /HideShortcuts [2011/06/16 06:32:40 | 000,712,976 | ---- | M] (Mozilla Corporation)

HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\FIREFOX.EXE\InstallInfo\\ShowIconsCommand: "C:\Program Files\Mozilla Firefox\uninstall\helper.exe" /ShowShortcuts [2011/06/16 06:32:40 | 000,712,976 | ---- | M] (Mozilla Corporation)

HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\FIREFOX.EXE\InstallInfo\\ReinstallCommand: "C:\Program Files\Mozilla Firefox\uninstall\helper.exe" /SetAsDefaultAppGlobal [2011/06/16 06:32:40 | 000,712,976 | ---- | M] (Mozilla Corporation)

HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\FIREFOX.EXE\shell\open\command\\: C:\Program Files\Mozilla Firefox\firefox.exe [2011/06/16 06:32:38 | 000,924,632 | ---- | M] (Mozilla Corporation)

HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\FIREFOX.EXE\shell\properties\command\\: "C:\Program Files\Mozilla Firefox\firefox.exe" -preferences [2011/06/16 06:32:38 | 000,924,632 | ---- | M] (Mozilla Corporation)

HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\FIREFOX.EXE\shell\safemode\command\\: "C:\Program Files\Mozilla Firefox\firefox.exe" -safe-mode [2011/06/16 06:32:38 | 000,924,632 | ---- | M] (Mozilla Corporation)

HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\Google Chrome\InstallInfo\\ShowIconsCommand: "C:\Program Files\Google\Chrome\Application\chrome.exe" --show-icons [2011/06/24 08:25:50 | 001,012,792 | ---- | M] (Google Inc.)

HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\Google Chrome\InstallInfo\\HideIconsCommand: "C:\Program Files\Google\Chrome\Application\chrome.exe" --hide-icons [2011/06/24 08:25:50 | 001,012,792 | ---- | M] (Google Inc.)

HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\Google Chrome\InstallInfo\\ReinstallCommand: "C:\Program Files\Google\Chrome\Application\chrome.exe" --make-default-browser [2011/06/24 08:25:50 | 001,012,792 | ---- | M] (Google Inc.)

HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\Google Chrome\shell\open\command\\: "C:\Program Files\Google\Chrome\Application\chrome.exe" [2011/06/24 08:25:50 | 001,012,792 | ---- | M] (Google Inc.)

HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\IEXPLORE.EXE\InstallInfo\\ReinstallCommand: "C:\WINDOWS\system32\ie4uinit.exe" -reinstall [2011/04/25 14:00:32 | 000,070,656 | ---- | M] (Microsoft Corporation)

HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\IEXPLORE.EXE\InstallInfo\\HideIconsCommand: "C:\WINDOWS\system32\ie4uinit.exe" -hide [2011/04/25 14:00:32 | 000,070,656 | ---- | M] (Microsoft Corporation)

HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\IEXPLORE.EXE\InstallInfo\\ShowIconsCommand: "C:\WINDOWS\system32\ie4uinit.exe" -show [2011/04/25 14:00:32 | 000,070,656 | ---- | M] (Microsoft Corporation)

HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\IEXPLORE.EXE\shell\open\command\\: "C:\Program Files\Internet Explorer\iexplore.exe" [2011/04/21 12:58:25 | 000,634,648 | ---- | M] (Microsoft Corporation)

HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\IEXPLORE.EXE\shell\open\command\\@: C:\Program Files (x86)\Internet Explorer\iexplore.exe

========== Alternate Data Streams ==========

@Alternate Data Stream - 104 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:D1B5B4F1

< End of report >

OTL Extras logfile created on: 04/07/2011 15:46:43 - Run 1

OTL by OldTimer - Version 3.2.25.0 Folder = C:\Documents and Settings\WASCP\My Documents\Downloads

Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation

Internet Explorer (Version = 7.0.5730.13)

Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy

1.96 Gb Total Physical Memory | 1.45 Gb Available Physical Memory | 73.97% Memory free

3.81 Gb Paging File | 3.47 Gb Available in Paging File | 91.21% Paging File free

Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files

Drive C: | 148.92 Gb Total Space | 131.01 Gb Free Space | 87.97% Space Free | Partition Type: NTFS

Computer Name: BOBCOLLINS | User Name: Bob Collins | Logged in as Administrator.

Boot Mode: Normal | Scan Mode: Current user | Quick Scan

Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========

========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]

.cpl [@ = cplfile] -- rundll32.exe shell32.dll,Control_RunDLL "%1",%*

.url [@ = InternetShortcut] -- rundll32.exe ieframe.dll,OpenURL %l

[HKEY_CURRENT_USER\SOFTWARE\Classes\<extension>]

.html [@ = FirefoxHTML] -- C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]

batfile [open] -- "%1" %*

cmdfile [open] -- "%1" %*

comfile [open] -- "%1" %*

cplfile [cplopen] -- rundll32.exe shell32.dll,Control_RunDLL "%1",%*

exefile [open] -- "%1" %*

InternetShortcut [open] -- rundll32.exe ieframe.dll,OpenURL %l

piffile [open] -- "%1" %*

regfile [merge] -- Reg Error: Key error.

scrfile [config] -- "%1"

scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l

scrfile [open] -- "%1" /S

txtfile [edit] -- Reg Error: Key error.

Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1

Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)

Folder [open] -- %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)

Folder [explore] -- %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)

Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]

"FirstRunDisabled" = 1

"AntiVirusOverride" = 1

"FirewallOverride" = 1

"AntiVirusDisableNotify" = 0

"FirewallDisableNotify" = 0

"UpdatesDisableNotify" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

========== System Restore Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]

"DisableSR" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sr]

"Start" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SrService]

"Start" = 2

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile]

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]

"EnableFirewall" = 0

"DoNotAllowExceptions" = 0

"DisableNotifications" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]

"EnableFirewall" = 0

"DoNotAllowExceptions" = 0

"DisableNotifications" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]

"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007

"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008

"139:TCP" = 139:TCP:LocalSubNet:Disabled:@xpsp2res.dll,-22004

"445:TCP" = 445:TCP:LocalSubNet:Disabled:@xpsp2res.dll,-22005

"137:UDP" = 137:UDP:LocalSubNet:Disabled:@xpsp2res.dll,-22001

"138:UDP" = 138:UDP:LocalSubNet:Disabled:@xpsp2res.dll,-22002

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]

"C:\WINDOWS\Temp\ms0cfg32.exe" = C:\WINDOWS\Temp\ms0cfg32.exe:*:Enabled:Application Layer Gateway Service

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]

"C:\WINDOWS\system32\dpvsetup.exe" = C:\WINDOWS\system32\dpvsetup.exe:*:Enabled:Microsoft DirectPlay Voice Test -- (Microsoft Corporation)

========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]

"{00203668-8170-44A0-BE44-B632FA4D780F}" = Adobe AIR

"{0394CDC8-FABD-4ED8-B104-03393876DFDF}" = Roxio Creator Tools

"{07159635-9DFE-4105-BFC0-2817DB540C68}" = Roxio Activation Module

"{0D397393-9B50-4C52-84D5-77E344289F87}" = Roxio Creator Data

"{18455581-E099-4BA8-BC6B-F34B2F06600C}" = Google Toolbar for Internet Explorer

"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148

"{2318C2B1-4965-11d4-9B18-009027A5CD4F}" = Google Toolbar for Internet Explorer

"{2F4C24E6-CBD4-4AAC-B56F-C9FD44DE5668}" = Roxio Drag-to-Disc

"{30465B6C-B53F-49A1-9EBA-A3F187AD502E}" = Roxio Update Manager

"{3248F0A8-6813-11D6-A77B-00B0D0160070}" = Java 6 Update 7

"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP

"{4286E640-B5FB-11DF-AC4B-005056C00008}" = Google Earth

"{53183B25-FBDC-4B95-856A-DCDD69DFEE18}" = Intel® PRO Alerting Agent

"{619CDD8A-14B6-43A1-AB6C-0F4EE48CE048}" = Roxio Creator Copy

"{6675CA7F-E51B-4F6A-99D4-F8F0124C6EAA}" = Roxio Express Labeler 3

"{6811CAA0-BF12-11D4-9EA1-0050BAE317E1}" = PowerDVD

"{777CA40C-0206-4EF6-A0FC-618BF06BF8D0}" = Intel® PRO Network Connections 12.1.12.4

"{77DCDCE3-2DED-62F3-8154-05E745472D07}" = Acrobat.com

"{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable

"{83FFCFC7-88C6-41C6-8752-958A45325C82}" = Roxio Creator Audio

"{880AF49C-34F7-4285-A8AD-8F7A3D1C33DC}" = Roxio Creator BDAV Plugin

"{8D337F77-BE7F-41A2-A7CB-D5A63FD7049B}" = Sonic CinePlayer Decoder Pack

"{8E5E3330-6746-4A1D-A6BA-043E4D437A59}" = InstallIQ Updater

"{90120000-0010-0409-0000-0000000FF1CE}" = Microsoft Software Update for Web Folders (English) 12

"{90120000-0011-0000-0000-0000000FF1CE}" = Microsoft Office Professional Plus 2007

"{90120000-0015-0409-0000-0000000FF1CE}" = Microsoft Office Access MUI (English) 2007

"{90120000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2007

"{90120000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2007

"{90120000-0019-0409-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (English) 2007

"{90120000-001A-0409-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (English) 2007

"{90120000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2007

"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007

"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007

"{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007

"{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007

"{90120000-0044-0409-0000-0000000FF1CE}" = Microsoft Office InfoPath MUI (English) 2007

"{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007

"{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007

"{90120000-0117-0409-0000-0000000FF1CE}" = Microsoft Office Access Setup Metadata MUI (English) 2007

"{9068B2BE-D93A-4C0A-861C-5E35E2C0E09E}" = Intel® Matrix Storage Manager

"{92FD71D5-ED7E-40B2-8DF3-4B5E6F684367}" = Dell ETS Factory Installation

"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2

"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper

"{AC76BA86-7AD7-1033-7B44-A94000000001}" = Adobe Reader 9.4.5

"{BAF78226-3200-4DB4-BE33-4D922A799840}" = Windows Presentation Foundation

"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2

"{C49067A8-8212-4A82-A4D9-1519701644F0}" = Citrix Presentation Server Client - Web Only

"{C8B0680B-CDAE-4809-9F91-387B6DE00F7C}" = Roxio Creator DE

"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1

"{CD95D125-2992-4858-B3EF-5F6FB52FBAD6}" = Skype Toolbars

"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1

"{E633D396-5188-4E9D-8F6B-BFB8BF3467E8}" = Skype™ 5.0

"Adobe AIR" = Adobe AIR

"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX

"Advanced SystemCare 3_is1" = Advanced SystemCare 3

"com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Acrobat.com

"ESET Online Scanner" = ESET Online Scanner v3

"Google Chrome" = Google Chrome

"HDMI" = Intel® Graphics Media Accelerator Driver

"IDNMitigationAPIs" = Microsoft Internationalized Domain Names Mitigation APIs

"ie7" = Windows Internet Explorer 7

"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware version 1.51.0.1200

"MESOL" = Intel® Active Management Technology

"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1

"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1

"Mozilla Firefox 5.0 (x86 en-GB)" = Mozilla Firefox 5.0 (x86 en-GB)

"NLSDownlevelMapping" = Microsoft National Language Support Downlevel APIs

"PROPLUS" = Microsoft Office Professional Plus 2007

"XpsEPSC" = XML Paper Specification Shared Components Pack 1.0

========== Last 10 Event Log Errors ==========

[ Application Events ]

Error - 04/07/2011 09:02:04 | Computer Name = BOBCOLLINS | Source = Userenv | ID = 1041

Description = Windows cannot query DllName registry entry for {7B849a69-220F-451E-B3FE-2CB811AF94AE}

and it will not be loaded. This is most likely caused by a faulty registration.

Error - 04/07/2011 09:02:04 | Computer Name = BOBCOLLINS | Source = Userenv | ID = 1041

Description = Windows cannot query DllName registry entry for {CF7639F3-ABA2-41DB-97F2-81E2C5DBFC5D}

and it will not be loaded. This is most likely caused by a faulty registration.

Error - 04/07/2011 09:26:00 | Computer Name = BOBCOLLINS | Source = Userenv | ID = 1041

Description = Windows cannot query DllName registry entry for {7B849a69-220F-451E-B3FE-2CB811AF94AE}

and it will not be loaded. This is most likely caused by a faulty registration.

Error - 04/07/2011 09:26:01 | Computer Name = BOBCOLLINS | Source = Userenv | ID = 1041

Description = Windows cannot query DllName registry entry for {CF7639F3-ABA2-41DB-97F2-81E2C5DBFC5D}

and it will not be loaded. This is most likely caused by a faulty registration.

Error - 04/07/2011 09:26:01 | Computer Name = BOBCOLLINS | Source = Userenv | ID = 1041

Description = Windows cannot query DllName registry entry for {7B849a69-220F-451E-B3FE-2CB811AF94AE}

and it will not be loaded. This is most likely caused by a faulty registration.

Error - 04/07/2011 09:26:01 | Computer Name = BOBCOLLINS | Source = Userenv | ID = 1041

Description = Windows cannot query DllName registry entry for {CF7639F3-ABA2-41DB-97F2-81E2C5DBFC5D}

and it will not be loaded. This is most likely caused by a faulty registration.

Error - 04/07/2011 09:45:14 | Computer Name = BOBCOLLINS | Source = Userenv | ID = 1041

Description = Windows cannot query DllName registry entry for {7B849a69-220F-451E-B3FE-2CB811AF94AE}

and it will not be loaded. This is most likely caused by a faulty registration.

Error - 04/07/2011 09:45:14 | Computer Name = BOBCOLLINS | Source = Userenv | ID = 1041

Description = Windows cannot query DllName registry entry for {CF7639F3-ABA2-41DB-97F2-81E2C5DBFC5D}

and it will not be loaded. This is most likely caused by a faulty registration.

Error - 04/07/2011 09:45:14 | Computer Name = BOBCOLLINS | Source = Userenv | ID = 1041

Description = Windows cannot query DllName registry entry for {7B849a69-220F-451E-B3FE-2CB811AF94AE}

and it will not be loaded. This is most likely caused by a faulty registration.

Error - 04/07/2011 09:45:14 | Computer Name = BOBCOLLINS | Source = Userenv | ID = 1041

Description = Windows cannot query DllName registry entry for {CF7639F3-ABA2-41DB-97F2-81E2C5DBFC5D}

and it will not be loaded. This is most likely caused by a faulty registration.

[ Application Events ]

Error - 04/07/2011 09:02:04 | Computer Name = BOBCOLLINS | Source = Userenv | ID = 1041

Description = Windows cannot query DllName registry entry for {7B849a69-220F-451E-B3FE-2CB811AF94AE}

and it will not be loaded. This is most likely caused by a faulty registration.

Error - 04/07/2011 09:02:04 | Computer Name = BOBCOLLINS | Source = Userenv | ID = 1041

Description = Windows cannot query DllName registry entry for {CF7639F3-ABA2-41DB-97F2-81E2C5DBFC5D}

and it will not be loaded. This is most likely caused by a faulty registration.

Error - 04/07/2011 09:26:00 | Computer Name = BOBCOLLINS | Source = Userenv | ID = 1041

Description = Windows cannot query DllName registry entry for {7B849a69-220F-451E-B3FE-2CB811AF94AE}

and it will not be loaded. This is most likely caused by a faulty registration.

Error - 04/07/2011 09:26:01 | Computer Name = BOBCOLLINS | Source = Userenv | ID = 1041

Description = Windows cannot query DllName registry entry for {CF7639F3-ABA2-41DB-97F2-81E2C5DBFC5D}

and it will not be loaded. This is most likely caused by a faulty registration.

Error - 04/07/2011 09:26:01 | Computer Name = BOBCOLLINS | Source = Userenv | ID = 1041

Description = Windows cannot query DllName registry entry for {7B849a69-220F-451E-B3FE-2CB811AF94AE}

and it will not be loaded. This is most likely caused by a faulty registration.

Error - 04/07/2011 09:26:01 | Computer Name = BOBCOLLINS | Source = Userenv | ID = 1041

Description = Windows cannot query DllName registry entry for {CF7639F3-ABA2-41DB-97F2-81E2C5DBFC5D}

and it will not be loaded. This is most likely caused by a faulty registration.

Error - 04/07/2011 09:45:14 | Computer Name = BOBCOLLINS | Source = Userenv | ID = 1041

Description = Windows cannot query DllName registry entry for {7B849a69-220F-451E-B3FE-2CB811AF94AE}

and it will not be loaded. This is most likely caused by a faulty registration.

Error - 04/07/2011 09:45:14 | Computer Name = BOBCOLLINS | Source = Userenv | ID = 1041

Description = Windows cannot query DllName registry entry for {CF7639F3-ABA2-41DB-97F2-81E2C5DBFC5D}

and it will not be loaded. This is most likely caused by a faulty registration.

Error - 04/07/2011 09:45:14 | Computer Name = BOBCOLLINS | Source = Userenv | ID = 1041

Description = Windows cannot query DllName registry entry for {7B849a69-220F-451E-B3FE-2CB811AF94AE}

and it will not be loaded. This is most likely caused by a faulty registration.

Error - 04/07/2011 09:45:14 | Computer Name = BOBCOLLINS | Source = Userenv | ID = 1041

Description = Windows cannot query DllName registry entry for {CF7639F3-ABA2-41DB-97F2-81E2C5DBFC5D}

and it will not be loaded. This is most likely caused by a faulty registration.

[ OSession Events ]

Error - 02/06/2010 02:16:18 | Computer Name = BOBCOLLINS | Source = Microsoft Office 12 Sessions | ID = 7001

Description = ID: 6, Application Name: Microsoft Office Outlook, Application Version:

12.0.4518.1014, Microsoft Office Version: 12.0.4518.1014. This session lasted 1709894

seconds with 1980 seconds of active time. This session ended with a crash.

Error - 25/10/2010 02:50:57 | Computer Name = BOBCOLLINS | Source = Microsoft Office 12 Sessions | ID = 7001

Description = ID: 6, Application Name: Microsoft Office Outlook, Application Version:

12.0.4518.1014, Microsoft Office Version: 12.0.4518.1014. This session lasted 15

seconds with 0 seconds of active time. This session ended with a crash.

[ System Events ]

Error - 04/07/2011 09:24:56 | Computer Name = BOBCOLLINS | Source = DCOM | ID = 10005

Description = DCOM got error "%1084" attempting to start the service EventSystem

with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF}

Error - 04/07/2011 09:26:15 | Computer Name = BOBCOLLINS | Source = DCOM | ID = 10005

Description = DCOM got error "%1084" attempting to start the service EventSystem

with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF}

Error - 04/07/2011 09:27:37 | Computer Name = BOBCOLLINS | Source = Service Control Manager | ID = 7026

Description = The following boot-start or system-start driver(s) failed to load:

Fips intelppm

Error - 04/07/2011 09:28:31 | Computer Name = BOBCOLLINS | Source = DCOM | ID = 10005

Description = DCOM got error "%1084" attempting to start the service StiSvc with

arguments "" in order to run the server: {A1F4E726-8CF1-11D1-BF92-0060081ED811}

Error - 04/07/2011 09:36:31 | Computer Name = BOBCOLLINS | Source = DCOM | ID = 10005

Description = DCOM got error "%1084" attempting to start the service StiSvc with

arguments "" in order to run the server: {A1F4E726-8CF1-11D1-BF92-0060081ED811}

Error - 04/07/2011 09:36:55 | Computer Name = BOBCOLLINS | Source = DCOM | ID = 10005

Description = DCOM got error "%1084" attempting to start the service StiSvc with

arguments "" in order to run the server: {A1F4E726-8CF1-11D1-BF92-0060081ED811}

Error - 04/07/2011 09:40:14 | Computer Name = BOBCOLLINS | Source = DCOM | ID = 10005

Description = DCOM got error "%1084" attempting to start the service StiSvc with

arguments "" in order to run the server: {A1F4E726-8CF1-11D1-BF92-0060081ED811}

Error - 04/07/2011 09:41:55 | Computer Name = BOBCOLLINS | Source = DCOM | ID = 10005

Description = DCOM got error "%1084" attempting to start the service EventSystem

with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF}

Error - 04/07/2011 09:45:10 | Computer Name = BOBCOLLINS | Source = DCOM | ID = 10005

Description = DCOM got error "%1058" attempting to start the service WSearch with

arguments "" in order to run the server: {7D096C5F-AC08-4F1F-BEB7-5C22C517CE39}

Error - 04/07/2011 09:45:25 | Computer Name = BOBCOLLINS | Source = DCOM | ID = 10005

Description = DCOM got error "%1058" attempting to start the service WSearch with

arguments "" in order to run the server: {7D096C5F-AC08-4F1F-BEB7-5C22C517CE39}

< End of report >

Link to post
Share on other sites

  • Replies 77
  • Created
  • Last Reply

Top Posters In This Topic

Due to the lack of feedback this topic is closed to prevent others from posting here. If you need this topic reopened, please send a Private Message to any one of the moderating team members. Please include a link to this thread with your request. This applies only to the originator of this thread.

Other members who need assistance please start your own topic in a new thread. Thanks!

Link to post
Share on other sites

Hi Ali,

Apologies for the delay, but I have been out of office!

Here is the last mbam log you requested;

Malwarebytes' Anti-Malware 1.51.0.1200

www.malwarebytes.org

Database version: 7084

Windows 5.1.2600 Service Pack 3

Internet Explorer 7.0.5730.13

12/07/2011 14:18:48

mbam-log-2011-07-12 (14-18-45).txt

Scan type: Quick scan

Objects scanned: 197457

Time elapsed: 9 minute(s), 15 second(s)

Memory Processes Infected: 0

Memory Modules Infected: 0

Registry Keys Infected: 0

Registry Values Infected: 0

Registry Data Items Infected: 0

Folders Infected: 0

Files Infected: 1

Memory Processes Infected:

(No malicious items detected)

Memory Modules Infected:

(No malicious items detected)

Registry Keys Infected:

(No malicious items detected)

Registry Values Infected:

(No malicious items detected)

Registry Data Items Infected:

(No malicious items detected)

Folders Infected:

(No malicious items detected)

Files Infected:

c:\WINDOWS\Fonts\4tM870y.com (Malware.Generic) -> No action taken.

Link to post
Share on other sites

Hi Ali,

Here is a log of a full scan that I have just run.

All looks clear, which seems good. I do have the following problems;

1. On start-up (for a millesecond) multiple windows flicker on the screen

2. The machine keeps freezing up when running scans

3. Whilst running scans the Malware Window flickers and there seems to be another window that opens for a millesecind in the background.

Malwarebytes' Anti-Malware 1.51.0.1200

www.malwarebytes.org

Database version: 7084

Windows 5.1.2600 Service Pack 3

Internet Explorer 7.0.5730.13

12/07/2011 16:23:02

mbam-log-2011-07-12 (16-23-02).txt

Scan type: Full scan (C:\|)

Objects scanned: 222203

Time elapsed: 21 minute(s), 41 second(s)

Memory Processes Infected: 0

Memory Modules Infected: 0

Registry Keys Infected: 0

Registry Values Infected: 0

Registry Data Items Infected: 0

Folders Infected: 0

Files Infected: 0

Memory Processes Infected:

(No malicious items detected)

Memory Modules Infected:

(No malicious items detected)

Registry Keys Infected:

(No malicious items detected)

Registry Values Infected:

(No malicious items detected)

Registry Data Items Infected:

(No malicious items detected)

Folders Infected:

(No malicious items detected)

Files Infected:

(No malicious items detected)

Link to post
Share on other sites

Hi Ali,

Here is the log for the Quick scan;

OTL logfile created on: 13/07/2011 08:36:45 - Run 2

OTL by OldTimer - Version 3.2.25.0 Folder = C:\Documents and Settings\WASCP\Desktop

Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation

Internet Explorer (Version = 7.0.5730.13)

Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy

1.96 Gb Total Physical Memory | 1.49 Gb Available Physical Memory | 76.07% Memory free

3.81 Gb Paging File | 3.47 Gb Available in Paging File | 91.26% Paging File free

Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files

Drive C: | 148.92 Gb Total Space | 130.87 Gb Free Space | 87.88% Space Free | Partition Type: NTFS

Computer Name: BOBCOLLINS | User Name: Bob Collins | Logged in as Administrator.

Boot Mode: Normal | Scan Mode: Current user | Quick Scan

Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - [2011/07/12 15:32:26 | 000,039,948 | ---- | M] () -- C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe

PRC - [2011/07/12 09:12:23 | 000,039,940 | ---- | M] () -- C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe

PRC - [2011/07/12 09:12:23 | 000,039,940 | ---- | M] () -- C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe

PRC - [2011/07/12 09:12:23 | 000,039,940 | ---- | M] () -- C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe

PRC - [2011/07/12 09:12:23 | 000,039,940 | ---- | M] () -- C:\Program Files\Intel\AMT\atchk.exe

PRC - [2011/07/04 15:39:22 | 000,580,096 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\WASCP\Desktop\OTL.scr

PRC - [2011/06/08 06:02:26 | 000,037,296 | ---- | M] (Adobe Systems Incorporated) -- C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl .exe

PRC - [2009/02/19 15:57:11 | 000,039,408 | ---- | M] (Google Inc.) -- C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier .exe

PRC - [2009/01/26 15:31:16 | 002,144,088 | RHS- | M] (Safer Networking Limited) -- C:\Program Files\Spybot - Search & Destroy\TeaTimer .exe

PRC - [2008/06/10 05:27:04 | 000,144,784 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\Java\jre1.6.0_07\bin\jusched .exe

PRC - [2008/05/23 15:06:08 | 000,128,296 | ---- | M] (CyberLink Corp.) -- C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv .exe

PRC - [2008/04/14 14:00:00 | 001,033,728 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe

PRC - [2007/09/25 04:12:48 | 001,036,288 | ---- | M] (Analog Devices, Inc.) -- C:\Program Files\Analog Devices\Core\smax4pnp .exe

PRC - [2007/06/12 18:09:14 | 000,408,344 | ---- | M] (Intel Corporation) -- C:\Program Files\Intel\AMT\atchk .exe

========== Modules (SafeList) ==========

MOD - [2011/07/04 15:39:22 | 000,580,096 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\WASCP\Desktop\OTL.scr

MOD - [2010/08/23 18:12:02 | 001,054,208 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.6028_x-ww_61e65202\comctl32.dll

========== Win32 Services (SafeList) ==========

SRV - File not found [On_Demand | Stopped] -- -- (stllssvr)

SRV - File not found [Disabled | Stopped] -- -- (AMService)

SRV - [2007/10/03 16:45:02 | 000,358,936 | ---- | M] (Intel Corporation) [Disabled | Stopped] -- C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTmon.exe -- (IAANTMON) Intel®

SRV - [2007/06/12 18:09:16 | 002,521,880 | ---- | M] (Intel) [Disabled | Stopped] -- C:\Program Files\Intel\AMT\UNS.exe -- (UNS) Intel®

SRV - [2007/06/12 18:09:16 | 000,183,064 | ---- | M] (Intel Corporation) [Disabled | Stopped] -- C:\Program Files\Intel\AMT\atchksrv.exe -- (atchksrv) Intel®

SRV - [2007/06/12 18:09:14 | 000,109,336 | ---- | M] (Intel) [Disabled | Stopped] -- C:\Program Files\Intel\AMT\LMS.exe -- (LMS) Intel®

SRV - [2007/01/23 04:58:04 | 000,133,968 | ---- | M] (Intel Corporation) [Disabled | Stopped] -- C:\Program Files\Intel\ASF Agent\ASFAgent.exe -- (ASFAgent)

========== Driver Services (SafeList) ==========

DRV - [2007/09/25 04:12:48 | 000,392,960 | ---- | M] (Sensaura) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\senfilt.sys -- (SenFiltService)

DRV - [2007/07/24 03:42:12 | 000,045,056 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\HECI.sys -- (HECI) Intel®

DRV - [2007/07/23 16:05:20 | 000,009,104 | ---- | M] (Roxio) [File_System | Auto | Running] -- C:\WINDOWS\system32\drivers\DLADResM.SYS -- (DLADResM)

DRV - [2007/07/23 16:04:58 | 000,037,360 | ---- | M] (Roxio) [File_System | Auto | Running] -- C:\WINDOWS\system32\drivers\DLABMFSM.SYS -- (DLABMFSM)

DRV - [2007/07/23 16:04:56 | 000,098,448 | ---- | M] (Roxio) [File_System | Auto | Running] -- C:\WINDOWS\system32\drivers\DLAUDF_M.SYS -- (DLAUDF_M)

DRV - [2007/07/23 16:04:56 | 000,093,552 | ---- | M] (Roxio) [File_System | Auto | Running] -- C:\WINDOWS\system32\drivers\DLAUDFAM.SYS -- (DLAUDFAM)

DRV - [2007/07/23 16:04:54 | 000,027,216 | ---- | M] (Roxio) [File_System | Auto | Running] -- C:\WINDOWS\system32\drivers\DLAOPIOM.SYS -- (DLAOPIOM)

DRV - [2007/07/23 16:04:52 | 000,032,848 | ---- | M] (Roxio) [File_System | Auto | Running] -- C:\WINDOWS\system32\drivers\DLABOIOM.SYS -- (DLABOIOM)

DRV - [2007/07/23 16:04:52 | 000,016,304 | ---- | M] (Roxio) [File_System | Auto | Running] -- C:\WINDOWS\system32\drivers\DLAPoolM.SYS -- (DLAPoolM)

DRV - [2007/07/23 16:04:50 | 000,108,752 | ---- | M] (Roxio) [File_System | Auto | Running] -- C:\WINDOWS\system32\drivers\DLAIFS_M.SYS -- (DLAIFS_M)

DRV - [2007/07/23 15:49:44 | 000,030,064 | ---- | M] (Roxio) [File_System | System | Running] -- C:\WINDOWS\system32\drivers\DLARTL_M.SYS -- (DLARTL_M)

DRV - [2007/07/23 15:49:44 | 000,014,576 | ---- | M] (Roxio) [Kernel | Boot | Running] -- C:\WINDOWS\System32\Drivers\DLACDBHM.SYS -- (DLACDBHM)

DRV - [2007/01/23 04:45:44 | 000,042,832 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\Asfalrt.sys -- (AsfAlrt)

========== Standard Registry (SafeList) ==========

========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.thecollegespartnership.co.uk/content.asp?ContentID=1

IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..extensions.enabledItems: {1E73965B-8B48-48be-9C8D-68B920ABC1C4}:10.0.0.1374

FF - prefs.js..network.proxy.type: 0

FF - HKLM\software\mozilla\Firefox\Extensions\\{1E73965B-8B48-48be-9C8D-68B920ABC1C4}: C:\Program Files\AVG\AVG10\Firefox4\ [2011/06/03 08:20:10 | 000,000,000 | ---D | M]

FF - HKLM\software\mozilla\Mozilla Firefox 5.0\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011/07/01 17:03:45 | 000,000,000 | ---D | M]

FF - HKLM\software\mozilla\Mozilla Firefox 5.0\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins

[2011/06/24 10:24:42 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\WASCP\Application Data\Mozilla\Extensions

[2011/06/24 10:25:46 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\WASCP\Application Data\Mozilla\Firefox\Profiles\rfkfg9b9.default\extensions

[2011/06/24 10:25:46 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- C:\Documents and Settings\WASCP\Application Data\Mozilla\Firefox\Profiles\rfkfg9b9.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}

[2011/07/01 17:03:45 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions

File not found (No name found) --

[2011/06/16 06:32:38 | 000,142,296 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\browsercomps.dll

[2010/01/01 10:00:00 | 000,001,538 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\amazon-en-GB.xml

[2011/06/24 10:23:07 | 000,002,428 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\babylon.xml

[2010/01/01 10:00:00 | 000,002,252 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\bing.xml

[2010/01/01 10:00:00 | 000,000,947 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\chambers-en-GB.xml

[2010/01/01 10:00:00 | 000,001,180 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\eBay-en-GB.xml

[2010/01/01 10:00:00 | 000,001,135 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\yahoo-en-GB.xml

Hosts file not found

O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - File not found

O2 - BHO: (Spybot-S&D IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)

O2 - BHO: (SSVHelper Class) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll (Sun Microsystems, Inc.)

O2 - BHO: (Skype Plug-In) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)

O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.7.6406.1642\swg.dll (Google Inc.)

O3 - HKLM\..\Toolbar: (no name) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - No CLSID value found.

O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {A057A204-BACC-4D26-9990-79A187E2698E} - No CLSID value found.

O4 - HKLM..\Run: [atchk] C:\Program Files\Intel\AMT\atchk.exe ()

O4 - HKLM..\Run: [iAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe ()

O4 - HKLM..\Run: [PDVDDXSrv] C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe ()

O4 - HKLM..\Run: [sunJavaUpdateSched] C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe ()

O4 - HKCU..\Run: [iSUSPM] C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM .exe ()

O4 - HKCU..\Run: [spybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe ()

O4 - HKLM..\RunOnce: [AvgUninstallURL] C:\WINDOWS\System32\cmd.exe (Microsoft Corporation)

O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Infodelivery present

O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present

O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1

O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: LinkResolveIgnoreLinkInfo = 0

O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoResolveSearch = 1

O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863

O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323

O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0

O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present

O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323

O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: LinkResolveIgnoreLinkInfo = 0

O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863

O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0

O9 - Extra 'Tools' menuitem : Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\npjpi160_07.dll (Sun Microsystems, Inc.)

O9 - Extra Button: Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)

O9 - Extra 'Tools' menuitem : Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)

O9 - Extra 'Tools' menuitem : Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)

O15 - HKCU\..Trusted Domains: //@install.mar@/ ([]msni in My Computer)

O15 - HKCU\..Trusted Domains: //@mail.mar@/ ([]msni in Local intranet)

O15 - HKCU\..Trusted Domains: tribalhosted.co.uk ([csg2] https in Trusted sites)

O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} http://www.update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1228722288531 (WUWebControl Class)

O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab (Java Plug-in 1.6.0_07)

O16 - DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab (Java Plug-in 1.6.0_07)

O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab (Java Plug-in 1.6.0_07)

O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.2.1

O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)

O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)

O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)

O24 - Desktop WallPaper: C:\Documents and Settings\WASCP\Local Settings\Application Data\Microsoft\Wallpaper1.bmp

O24 - Desktop BackupWallPaper: C:\Documents and Settings\WASCP\Local Settings\Application Data\Microsoft\Wallpaper1.bmp

O32 - HKLM CDRom: AutoRun - 1

O32 - AutoRun File - [2008/04/25 23:29:32 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]

O34 - HKLM BootExecute: (autocheck autochk *) - File not found

O35 - HKLM\..comfile [open] -- "%1" %*

O35 - HKLM\..exefile [open] -- "%1" %*

O37 - HKLM\...com [@ = comfile] -- "%1" %*

O37 - HKLM\...exe [@ = exefile] -- "%1" %*

========== Files/Folders - Created Within 30 Days ==========

[2011/07/12 15:32:23 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\Spybot - Search & Destroy

[2011/07/12 09:13:29 | 000,000,000 | ---D | C] -- C:\Documents and Settings\NetworkService\Local Settings\Application Data\PowerDVD DX

[2011/07/12 09:13:19 | 000,000,000 | ---D | C] -- C:\Documents and Settings\NetworkService\Local Settings\Application Data\Identities

[2011/07/05 08:43:49 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\Google Earth

[2011/07/04 15:39:20 | 000,580,096 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\WASCP\Desktop\OTL.scr

[2011/07/04 14:01:18 | 000,039,984 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbamswissarmy.sys

[2011/07/04 14:01:18 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\Malwarebytes' Anti-Malware

[2011/07/04 14:01:15 | 000,022,712 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbam.sys

[2011/07/04 14:01:15 | 000,000,000 | ---D | C] -- C:\Program Files\Malwarebytes' Anti-Malware

[2011/07/04 10:08:29 | 000,000,000 | ---D | C] -- C:\Program Files\ESET

[2011/07/04 10:00:21 | 000,000,000 | -HSD | C] -- C:\RECYCLER

[2011/07/01 17:39:12 | 000,000,000 | ---D | C] -- C:\Documents and Settings\WASCP\Desktop\Richies tools

[2011/07/01 17:28:46 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\avg9

[2011/07/01 16:23:41 | 000,000,000 | RHSD | C] -- C:\cmdcons

[2011/07/01 16:20:38 | 000,000,000 | ---D | C] -- C:\WINDOWS\ERDNT

[2011/07/01 16:15:10 | 000,000,000 | ---D | C] -- C:\Malwarebytes' Anti-Malware

[2011/07/01 15:16:57 | 000,000,000 | ---D | C] -- C:\Documents and Settings\WASCP\Application Data\Malwarebytes

[2011/07/01 15:16:52 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Malwarebytes

[2011/06/24 15:04:31 | 000,000,000 | ---D | C] -- C:\Program Files\win

[2011/06/24 10:24:24 | 000,000,000 | ---D | C] -- C:\Documents and Settings\WASCP\Local Settings\Application Data\Mozilla

[2011/06/24 10:24:24 | 000,000,000 | ---D | C] -- C:\Documents and Settings\WASCP\Application Data\Mozilla

[2011/06/24 10:23:07 | 000,000,000 | ---D | C] -- C:\Program Files\Mozilla Firefox

[2011/06/24 08:56:47 | 000,000,000 | ---D | C] -- C:\Program Files\Advanced PC Tweaker

[2011/06/23 11:54:11 | 000,000,000 | ---D | C] -- C:\Documents and Settings\WASCP\Application Data\MSNInstaller

[2011/06/23 10:48:50 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\NtmsData

[2011/06/21 12:26:48 | 000,000,000 | ---D | C] -- C:\Program Files\Spybot - Search & Destroy

[2011/06/21 12:26:48 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy

[2011/06/21 11:17:57 | 000,000,000 | ---D | C] -- C:\svest

[2011/06/20 13:06:09 | 000,000,000 | ---D | C] -- C:\Documents and Settings\NetworkService\Local Settings\Application Data\NVIDIA Corporation

========== Files - Modified Within 30 Days ==========

[2011/07/13 08:36:17 | 000,002,206 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl

[2011/07/13 08:36:17 | 000,000,892 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job

[2011/07/13 08:35:55 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat

[2011/07/13 08:35:50 | 2101,964,800 | -HS- | M] () -- C:\hiberfil.sys

[2011/07/12 16:11:02 | 000,000,664 | ---- | M] () -- C:\WINDOWS\System32\d3d9caps.dat

[2011/07/12 15:43:00 | 000,000,342 | ---- | M] () -- C:\WINDOWS\tasks\At16.job

[2011/07/12 15:32:24 | 000,000,953 | ---- | M] () -- C:\Documents and Settings\WASCP\Application Data\Microsoft\Internet Explorer\Quick Launch\Spybot - Search & Destroy.lnk

[2011/07/12 15:32:23 | 000,000,935 | ---- | M] () -- C:\Documents and Settings\WASCP\Desktop\Spybot - Search & Destroy.lnk

[2011/07/12 13:42:00 | 000,000,896 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job

[2011/07/12 12:43:02 | 000,000,342 | ---- | M] () -- C:\WINDOWS\tasks\At13.job

[2011/07/12 11:43:03 | 000,000,342 | ---- | M] () -- C:\WINDOWS\tasks\At12.job

[2011/07/12 10:43:02 | 000,000,342 | ---- | M] () -- C:\WINDOWS\tasks\At11.job

[2011/07/12 09:43:02 | 000,000,342 | ---- | M] () -- C:\WINDOWS\tasks\At10.job

[2011/07/12 09:12:23 | 000,000,342 | ---- | M] () -- C:\WINDOWS\tasks\At9.job

[2011/07/12 09:12:23 | 000,000,342 | ---- | M] () -- C:\WINDOWS\tasks\At8.job

[2011/07/12 09:12:23 | 000,000,342 | ---- | M] () -- C:\WINDOWS\tasks\At7.job

[2011/07/12 09:12:23 | 000,000,342 | ---- | M] () -- C:\WINDOWS\tasks\At6.job

[2011/07/12 09:12:23 | 000,000,342 | ---- | M] () -- C:\WINDOWS\tasks\At5.job

[2011/07/12 09:12:23 | 000,000,342 | ---- | M] () -- C:\WINDOWS\tasks\At4.job

[2011/07/12 09:12:23 | 000,000,342 | ---- | M] () -- C:\WINDOWS\tasks\At3.job

[2011/07/12 09:12:23 | 000,000,342 | ---- | M] () -- C:\WINDOWS\tasks\At24.job

[2011/07/12 09:12:23 | 000,000,342 | ---- | M] () -- C:\WINDOWS\tasks\At23.job

[2011/07/12 09:12:23 | 000,000,342 | ---- | M] () -- C:\WINDOWS\tasks\At22.job

[2011/07/12 09:12:23 | 000,000,342 | ---- | M] () -- C:\WINDOWS\tasks\At21.job

[2011/07/12 09:12:23 | 000,000,342 | ---- | M] () -- C:\WINDOWS\tasks\At20.job

[2011/07/12 09:12:23 | 000,000,342 | ---- | M] () -- C:\WINDOWS\tasks\At2.job

[2011/07/12 09:12:23 | 000,000,342 | ---- | M] () -- C:\WINDOWS\tasks\At19.job

[2011/07/12 09:12:23 | 000,000,342 | ---- | M] () -- C:\WINDOWS\tasks\At18.job

[2011/07/12 09:12:23 | 000,000,342 | ---- | M] () -- C:\WINDOWS\tasks\At17.job

[2011/07/12 09:12:23 | 000,000,342 | ---- | M] () -- C:\WINDOWS\tasks\At15.job

[2011/07/12 09:12:23 | 000,000,342 | ---- | M] () -- C:\WINDOWS\tasks\At14.job

[2011/07/12 09:12:23 | 000,000,342 | ---- | M] () -- C:\WINDOWS\tasks\At1.job

[2011/07/11 13:55:41 | 000,000,572 | ---- | M] () -- C:\Documents and Settings\WASCP\My Documents\spider.sav

[2011/07/05 08:43:49 | 000,001,917 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Google Earth.lnk

[2011/07/04 15:39:22 | 000,580,096 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\WASCP\Desktop\OTL.scr

[2011/07/04 14:01:18 | 000,000,786 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk

[2011/07/04 12:45:25 | 000,267,800 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT

[2011/07/04 11:27:44 | 000,001,731 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Adobe Reader 9.lnk

[2011/07/04 09:53:19 | 000,467,220 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat

[2011/07/04 09:53:19 | 000,080,310 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat

[2011/07/01 17:03:46 | 000,000,744 | ---- | M] () -- C:\Documents and Settings\WASCP\Application Data\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox.lnk

[2011/07/01 17:03:46 | 000,000,726 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Mozilla Firefox.lnk

[2011/07/01 16:23:45 | 000,000,327 | RHS- | M] () -- C:\boot.ini

[2011/06/24 12:12:25 | 000,000,512 | ---- | M] () -- C:\WINDOWS\tasks\One-Click Tweak.job

[2011/06/24 10:59:40 | 000,001,374 | ---- | M] () -- C:\WINDOWS\imsins.BAK

[2011/06/24 10:24:26 | 000,000,000 | ---- | M] () -- C:\WINDOWS\nsreg.dat

[2011/06/23 11:02:24 | 000,000,127 | ---- | M] () -- C:\WINDOWS\System32\MRT.INI

[2011/06/21 13:46:17 | 000,002,312 | ---- | M] () -- C:\WINDOWS\wininit.ini

========== Files Created - No Company Name ==========

[2011/07/12 15:32:23 | 000,000,953 | ---- | C] () -- C:\Documents and Settings\WASCP\Application Data\Microsoft\Internet Explorer\Quick Launch\Spybot - Search & Destroy.lnk

[2011/07/12 15:32:23 | 000,000,935 | ---- | C] () -- C:\Documents and Settings\WASCP\Desktop\Spybot - Search & Destroy.lnk

[2011/07/12 09:12:23 | 000,000,342 | ---- | C] () -- C:\WINDOWS\tasks\At9.job

[2011/07/12 09:12:23 | 000,000,342 | ---- | C] () -- C:\WINDOWS\tasks\At8.job

[2011/07/12 09:12:23 | 000,000,342 | ---- | C] () -- C:\WINDOWS\tasks\At7.job

[2011/07/12 09:12:23 | 000,000,342 | ---- | C] () -- C:\WINDOWS\tasks\At6.job

[2011/07/12 09:12:23 | 000,000,342 | ---- | C] () -- C:\WINDOWS\tasks\At5.job

[2011/07/12 09:12:23 | 000,000,342 | ---- | C] () -- C:\WINDOWS\tasks\At4.job

[2011/07/12 09:12:23 | 000,000,342 | ---- | C] () -- C:\WINDOWS\tasks\At3.job

[2011/07/12 09:12:23 | 000,000,342 | ---- | C] () -- C:\WINDOWS\tasks\At24.job

[2011/07/12 09:12:23 | 000,000,342 | ---- | C] () -- C:\WINDOWS\tasks\At23.job

[2011/07/12 09:12:23 | 000,000,342 | ---- | C] () -- C:\WINDOWS\tasks\At22.job

[2011/07/12 09:12:23 | 000,000,342 | ---- | C] () -- C:\WINDOWS\tasks\At21.job

[2011/07/12 09:12:23 | 000,000,342 | ---- | C] () -- C:\WINDOWS\tasks\At20.job

[2011/07/12 09:12:23 | 000,000,342 | ---- | C] () -- C:\WINDOWS\tasks\At2.job

[2011/07/12 09:12:23 | 000,000,342 | ---- | C] () -- C:\WINDOWS\tasks\At19.job

[2011/07/12 09:12:23 | 000,000,342 | ---- | C] () -- C:\WINDOWS\tasks\At18.job

[2011/07/12 09:12:23 | 000,000,342 | ---- | C] () -- C:\WINDOWS\tasks\At17.job

[2011/07/12 09:12:23 | 000,000,342 | ---- | C] () -- C:\WINDOWS\tasks\At16.job

[2011/07/12 09:12:23 | 000,000,342 | ---- | C] () -- C:\WINDOWS\tasks\At15.job

[2011/07/12 09:12:23 | 000,000,342 | ---- | C] () -- C:\WINDOWS\tasks\At14.job

[2011/07/12 09:12:23 | 000,000,342 | ---- | C] () -- C:\WINDOWS\tasks\At13.job

[2011/07/12 09:12:23 | 000,000,342 | ---- | C] () -- C:\WINDOWS\tasks\At12.job

[2011/07/12 09:12:23 | 000,000,342 | ---- | C] () -- C:\WINDOWS\tasks\At11.job

[2011/07/12 09:12:23 | 000,000,342 | ---- | C] () -- C:\WINDOWS\tasks\At10.job

[2011/07/12 09:12:23 | 000,000,342 | ---- | C] () -- C:\WINDOWS\tasks\At1.job

[2011/07/05 08:43:49 | 000,001,917 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Google Earth.lnk

[2011/07/04 15:45:04 | 2101,964,800 | -HS- | C] () -- C:\hiberfil.sys

[2011/07/04 14:01:18 | 000,000,786 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk

[2011/07/04 11:27:43 | 000,001,731 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Adobe Reader 9.lnk

[2011/07/01 17:03:46 | 000,000,744 | ---- | C] () -- C:\Documents and Settings\WASCP\Application Data\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox.lnk

[2011/07/01 17:03:46 | 000,000,732 | ---- | C] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Mozilla Firefox.lnk

[2011/07/01 17:03:46 | 000,000,726 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Mozilla Firefox.lnk

[2011/07/01 16:23:45 | 000,000,211 | ---- | C] () -- C:\Boot.bak

[2011/07/01 16:23:43 | 000,260,272 | RHS- | C] () -- C:\cmldr

[2011/06/24 10:24:26 | 000,000,000 | ---- | C] () -- C:\WINDOWS\nsreg.dat

[2011/06/24 08:57:01 | 000,000,512 | ---- | C] () -- C:\WINDOWS\tasks\One-Click Tweak.job

[2011/06/20 08:32:26 | 000,000,127 | ---- | C] () -- C:\WINDOWS\System32\MRT.INI

[2011/05/24 08:13:03 | 000,000,053 | ---- | C] () -- C:\WINDOWS\System32\urhtps.dat

[2011/05/11 15:01:39 | 000,000,664 | ---- | C] () -- C:\WINDOWS\System32\d3d9caps.dat

[2009/09/22 08:17:46 | 000,013,312 | ---- | C] () -- C:\Documents and Settings\WASCP\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini

[2009/03/30 11:07:16 | 000,038,433 | ---- | C] () -- C:\Documents and Settings\WASCP\Application Data\Comma Separated Values (Windows).ADR

[2009/01/29 12:49:45 | 000,000,056 | -H-- | C] () -- C:\WINDOWS\System32\ezsidmv.dat

[2008/10/16 20:44:45 | 000,077,824 | ---- | C] () -- C:\WINDOWS\setpwr32.exe

[2008/10/16 20:44:32 | 000,204,800 | ---- | C] () -- C:\WINDOWS\System32\igfxCoIn_v4837.dll

[2008/10/16 20:44:13 | 000,001,167 | ---- | C] () -- C:\WINDOWS\System32\OEMINFO.INI

[2008/10/16 12:00:05 | 000,000,061 | ---- | C] () -- C:\WINDOWS\smscfg.ini

[2008/10/16 11:56:13 | 000,002,312 | ---- | C] () -- C:\WINDOWS\wininit.ini

[2008/05/26 21:59:42 | 000,018,904 | ---- | C] () -- C:\WINDOWS\System32\structuredqueryschematrivial.bin

[2008/05/26 21:59:40 | 000,106,605 | ---- | C] () -- C:\WINDOWS\System32\structuredqueryschema.bin

[2008/04/25 23:31:41 | 000,002,048 | --S- | C] () -- C:\WINDOWS\bootstat.dat

[2008/04/25 23:27:18 | 000,021,640 | ---- | C] () -- C:\WINDOWS\System32\emptyregdb.dat

[2008/04/25 23:26:32 | 000,001,793 | ---- | C] () -- C:\WINDOWS\System32\fxsperf.ini

[2008/04/25 18:16:24 | 000,004,569 | ---- | C] () -- C:\WINDOWS\System32\secupd.dat

[2008/04/25 18:16:22 | 000,467,220 | ---- | C] () -- C:\WINDOWS\System32\perfh009.dat

[2008/04/25 18:16:22 | 000,272,128 | ---- | C] () -- C:\WINDOWS\System32\perfi009.dat

[2008/04/25 18:16:22 | 000,080,310 | ---- | C] () -- C:\WINDOWS\System32\perfc009.dat

[2008/04/25 18:16:22 | 000,028,626 | ---- | C] () -- C:\WINDOWS\System32\perfd009.dat

[2008/04/25 18:16:22 | 000,004,627 | ---- | C] () -- C:\WINDOWS\System32\oembios.dat

[2008/04/25 18:16:21 | 013,107,200 | ---- | C] () -- C:\WINDOWS\System32\oembios.bin

[2008/04/25 18:16:20 | 000,000,741 | ---- | C] () -- C:\WINDOWS\System32\noise.dat

[2008/04/25 18:16:18 | 000,673,088 | ---- | C] () -- C:\WINDOWS\System32\mlang.dat

[2008/04/25 18:16:18 | 000,046,258 | ---- | C] () -- C:\WINDOWS\System32\mib.bin

[2008/04/25 18:16:13 | 000,218,003 | ---- | C] () -- C:\WINDOWS\System32\dssec.dat

[2008/04/25 18:16:11 | 000,001,804 | ---- | C] () -- C:\WINDOWS\System32\Dcache.bin

[2008/04/25 11:22:39 | 000,004,161 | ---- | C] () -- C:\WINDOWS\ODBCINST.INI

[2008/04/25 11:21:52 | 000,267,800 | ---- | C] () -- C:\WINDOWS\System32\FNTCACHE.DAT

[2007/09/27 10:51:02 | 000,020,698 | ---- | C] () -- C:\WINDOWS\System32\idxcntrs.ini

[2007/09/27 10:48:48 | 000,030,628 | ---- | C] () -- C:\WINDOWS\System32\gsrvctr.ini

[2007/09/27 10:48:28 | 000,031,698 | ---- | C] () -- C:\WINDOWS\System32\gthrctr.ini

[2007/02/28 06:03:32 | 000,080,720 | ---- | C] () -- C:\WINDOWS\System32\AsfBios.dll

[2007/01/23 04:45:40 | 000,025,424 | ---- | C] () -- C:\WINDOWS\System32\drivers\netamsg.dll

========== LOP Check ==========

[2011/07/01 16:19:59 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\AVG10

[2011/07/04 12:44:34 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\avg9

[2010/10/22 07:56:24 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Application Data\Common Files

[2010/10/22 07:55:18 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\MFAData

[2011/07/04 11:26:20 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\TEMP

[2011/02/03 13:38:54 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\W3i

[2010/10/22 08:02:02 | 000,000,000 | ---D | M] -- C:\Documents and Settings\WASCP\Application Data\AVG10

[2011/05/13 08:29:40 | 000,000,000 | ---D | M] -- C:\Documents and Settings\WASCP\Application Data\Avidat

[2011/02/03 13:39:33 | 000,000,000 | ---D | M] -- C:\Documents and Settings\WASCP\Application Data\FinalTorrent

[2011/05/31 14:33:40 | 000,000,000 | ---D | M] -- C:\Documents and Settings\WASCP\Application Data\Geaw

[2009/02/12 09:36:16 | 000,000,000 | ---D | M] -- C:\Documents and Settings\WASCP\Application Data\ICAClient

[2011/06/24 08:26:00 | 000,000,000 | ---D | M] -- C:\Documents and Settings\WASCP\Application Data\MSNInstaller

[2010/10/26 10:54:21 | 000,000,000 | ---D | M] -- C:\Documents and Settings\WASCP\Application Data\Registry Mechanic

[2011/06/10 08:31:16 | 000,000,000 | ---D | M] -- C:\Documents and Settings\WASCP\Application Data\Vytea

[2009/03/30 10:52:10 | 000,000,000 | ---D | M] -- C:\Documents and Settings\WASCP\Application Data\Windows Desktop Search

[2009/07/01 09:40:09 | 000,000,000 | ---D | M] -- C:\Documents and Settings\WASCP\Application Data\Windows Search

[2011/07/12 09:12:23 | 000,000,342 | ---- | M] () -- C:\WINDOWS\Tasks\At1.job

[2011/07/12 09:43:02 | 000,000,342 | ---- | M] () -- C:\WINDOWS\Tasks\At10.job

[2011/07/12 10:43:02 | 000,000,342 | ---- | M] () -- C:\WINDOWS\Tasks\At11.job

[2011/07/12 11:43:03 | 000,000,342 | ---- | M] () -- C:\WINDOWS\Tasks\At12.job

[2011/07/12 12:43:02 | 000,000,342 | ---- | M] () -- C:\WINDOWS\Tasks\At13.job

[2011/07/12 09:12:23 | 000,000,342 | ---- | M] () -- C:\WINDOWS\Tasks\At14.job

[2011/07/12 09:12:23 | 000,000,342 | ---- | M] () -- C:\WINDOWS\Tasks\At15.job

[2011/07/12 15:43:00 | 000,000,342 | ---- | M] () -- C:\WINDOWS\Tasks\At16.job

[2011/07/12 09:12:23 | 000,000,342 | ---- | M] () -- C:\WINDOWS\Tasks\At17.job

[2011/07/12 09:12:23 | 000,000,342 | ---- | M] () -- C:\WINDOWS\Tasks\At18.job

[2011/07/12 09:12:23 | 000,000,342 | ---- | M] () -- C:\WINDOWS\Tasks\At19.job

[2011/07/12 09:12:23 | 000,000,342 | ---- | M] () -- C:\WINDOWS\Tasks\At2.job

[2011/07/12 09:12:23 | 000,000,342 | ---- | M] () -- C:\WINDOWS\Tasks\At20.job

[2011/07/12 09:12:23 | 000,000,342 | ---- | M] () -- C:\WINDOWS\Tasks\At21.job

[2011/07/12 09:12:23 | 000,000,342 | ---- | M] () -- C:\WINDOWS\Tasks\At22.job

[2011/07/12 09:12:23 | 000,000,342 | ---- | M] () -- C:\WINDOWS\Tasks\At23.job

[2011/07/12 09:12:23 | 000,000,342 | ---- | M] () -- C:\WINDOWS\Tasks\At24.job

[2011/07/12 09:12:23 | 000,000,342 | ---- | M] () -- C:\WINDOWS\Tasks\At3.job

[2011/07/12 09:12:23 | 000,000,342 | ---- | M] () -- C:\WINDOWS\Tasks\At4.job

[2011/07/12 09:12:23 | 000,000,342 | ---- | M] () -- C:\WINDOWS\Tasks\At5.job

[2011/07/12 09:12:23 | 000,000,342 | ---- | M] () -- C:\WINDOWS\Tasks\At6.job

[2011/07/12 09:12:23 | 000,000,342 | ---- | M] () -- C:\WINDOWS\Tasks\At7.job

[2011/07/12 09:12:23 | 000,000,342 | ---- | M] () -- C:\WINDOWS\Tasks\At8.job

[2011/07/12 09:12:23 | 000,000,342 | ---- | M] () -- C:\WINDOWS\Tasks\At9.job

[2011/06/24 12:12:25 | 000,000,512 | ---- | M] () -- C:\WINDOWS\Tasks\One-Click Tweak.job

========== Purity Check ==========

========== Alternate Data Streams ==========

@Alternate Data Stream - 104 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:D1B5B4F1

< End of report >

Link to post
Share on other sites

hi

Step 1

Run OTL

  • Under the Custom Scans/Fixes box at the bottom, paste in the following
    :OTL
    O3 - HKLM\..\Toolbar: (no name) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - No CLSID value found.
    O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {A057A204-BACC-4D26-9990-79A187E2698E} - No CLSID value found.
    [2011/06/24 15:04:31 | 000,000,000 | ---D | C] -- C:\Program Files\win
    [2011/05/24 08:13:03 | 000,000,053 | ---- | C] () -- C:\WINDOWS\System32\urhtps.dat
    [2008/10/16 20:44:45 | 000,077,824 | ---- | C] () -- C:\WINDOWS\setpwr32.exe

    :Files
    C:\WINDOWS\tasks\At*.job

    :Commands
    [purity]
    [resethosts]
    [emptytemp]
    [EMPTYFLASH]
    [Reboot]


  • Then click the Run Fix button at the top
  • Let the program run unhindered, reboot the PC when it is done
  • Open OTL again and click the Quick Scan button. Post the log it produces in your next reply.

Step 2

Download ComboFix here :

Link 1

Link 2

* IMPORTANT !!! Save ComboFix.exe to your Desktop

  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. Here is a guide on how to disable them
    Click me
  • Double click on ComboFix.exe & follow the prompts.
  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.
  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.

RcAuto1.gif

Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

whatnext.png

Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt log in your next reply.

Things I would like to see in your reply:

  • OTL log
  • Combofix.txt

Link to post
Share on other sites

HI Ali,

Here are the 2 logs you requested;

OTL log;

OTL logfile created on: 13/07/2011 12:42:33 - Run 3

OTL by OldTimer - Version 3.2.25.0 Folder = C:\Documents and Settings\WASCP\Desktop

Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation

Internet Explorer (Version = 7.0.5730.13)

Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy

1.96 Gb Total Physical Memory | 1.55 Gb Available Physical Memory | 79.42% Memory free

3.81 Gb Paging File | 3.55 Gb Available in Paging File | 93.19% Paging File free

Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files

Drive C: | 148.92 Gb Total Space | 131.06 Gb Free Space | 88.01% Space Free | Partition Type: NTFS

Drive E: | 495.22 Mb Total Space | 284.27 Mb Free Space | 57.40% Space Free | Partition Type: FAT

Computer Name: BOBCOLLINS | User Name: Bob Collins | Logged in as Administrator.

Boot Mode: Normal | Scan Mode: Current user | Quick Scan

Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - [2011/07/12 15:32:26 | 000,039,948 | ---- | M] () -- C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe

PRC - [2011/07/12 09:12:23 | 000,039,940 | ---- | M] () -- C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe

PRC - [2011/07/12 09:12:23 | 000,039,940 | ---- | M] () -- C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe

PRC - [2011/07/12 09:12:23 | 000,039,940 | ---- | M] () -- C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe

PRC - [2011/07/12 09:12:23 | 000,039,940 | ---- | M] () -- C:\Program Files\Intel\AMT\atchk.exe

PRC - [2011/07/04 15:39:22 | 000,580,096 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\WASCP\Desktop\OTL.scr

PRC - [2011/06/08 06:02:26 | 000,037,296 | ---- | M] (Adobe Systems Incorporated) -- C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl .exe

PRC - [2008/06/10 05:27:04 | 000,144,784 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\Java\jre1.6.0_07\bin\jusched .exe

PRC - [2008/04/14 14:00:00 | 001,033,728 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe

PRC - [2007/09/25 04:12:48 | 001,036,288 | ---- | M] (Analog Devices, Inc.) -- C:\Program Files\Analog Devices\Core\smax4pnp .exe

PRC - [2007/06/12 18:09:14 | 000,408,344 | ---- | M] (Intel Corporation) -- C:\Program Files\Intel\AMT\atchk .exe

========== Modules (SafeList) ==========

MOD - [2011/07/04 15:39:22 | 000,580,096 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\WASCP\Desktop\OTL.scr

MOD - [2010/08/23 18:12:02 | 001,054,208 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.6028_x-ww_61e65202\comctl32.dll

========== Win32 Services (SafeList) ==========

SRV - File not found [On_Demand | Stopped] -- -- (stllssvr)

SRV - File not found [Disabled | Stopped] -- -- (AMService)

SRV - [2007/10/03 16:45:02 | 000,358,936 | ---- | M] (Intel Corporation) [Disabled | Stopped] -- C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTmon.exe -- (IAANTMON) Intel®

SRV - [2007/06/12 18:09:16 | 002,521,880 | ---- | M] (Intel) [Disabled | Stopped] -- C:\Program Files\Intel\AMT\UNS.exe -- (UNS) Intel®

SRV - [2007/06/12 18:09:16 | 000,183,064 | ---- | M] (Intel Corporation) [Disabled | Stopped] -- C:\Program Files\Intel\AMT\atchksrv.exe -- (atchksrv) Intel®

SRV - [2007/06/12 18:09:14 | 000,109,336 | ---- | M] (Intel) [Disabled | Stopped] -- C:\Program Files\Intel\AMT\LMS.exe -- (LMS) Intel®

SRV - [2007/01/23 04:58:04 | 000,133,968 | ---- | M] (Intel Corporation) [Disabled | Stopped] -- C:\Program Files\Intel\ASF Agent\ASFAgent.exe -- (ASFAgent)

========== Driver Services (SafeList) ==========

DRV - [2007/09/25 04:12:48 | 000,392,960 | ---- | M] (Sensaura) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\senfilt.sys -- (SenFiltService)

DRV - [2007/07/24 03:42:12 | 000,045,056 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\HECI.sys -- (HECI) Intel®

DRV - [2007/07/23 16:05:20 | 000,009,104 | ---- | M] (Roxio) [File_System | Auto | Running] -- C:\WINDOWS\system32\drivers\DLADResM.SYS -- (DLADResM)

DRV - [2007/07/23 16:04:58 | 000,037,360 | ---- | M] (Roxio) [File_System | Auto | Running] -- C:\WINDOWS\system32\drivers\DLABMFSM.SYS -- (DLABMFSM)

DRV - [2007/07/23 16:04:56 | 000,098,448 | ---- | M] (Roxio) [File_System | Auto | Running] -- C:\WINDOWS\system32\drivers\DLAUDF_M.SYS -- (DLAUDF_M)

DRV - [2007/07/23 16:04:56 | 000,093,552 | ---- | M] (Roxio) [File_System | Auto | Running] -- C:\WINDOWS\system32\drivers\DLAUDFAM.SYS -- (DLAUDFAM)

DRV - [2007/07/23 16:04:54 | 000,027,216 | ---- | M] (Roxio) [File_System | Auto | Running] -- C:\WINDOWS\system32\drivers\DLAOPIOM.SYS -- (DLAOPIOM)

DRV - [2007/07/23 16:04:52 | 000,032,848 | ---- | M] (Roxio) [File_System | Auto | Running] -- C:\WINDOWS\system32\drivers\DLABOIOM.SYS -- (DLABOIOM)

DRV - [2007/07/23 16:04:52 | 000,016,304 | ---- | M] (Roxio) [File_System | Auto | Running] -- C:\WINDOWS\system32\drivers\DLAPoolM.SYS -- (DLAPoolM)

DRV - [2007/07/23 16:04:50 | 000,108,752 | ---- | M] (Roxio) [File_System | Auto | Running] -- C:\WINDOWS\system32\drivers\DLAIFS_M.SYS -- (DLAIFS_M)

DRV - [2007/07/23 15:49:44 | 000,030,064 | ---- | M] (Roxio) [File_System | System | Running] -- C:\WINDOWS\system32\drivers\DLARTL_M.SYS -- (DLARTL_M)

DRV - [2007/07/23 15:49:44 | 000,014,576 | ---- | M] (Roxio) [Kernel | Boot | Running] -- C:\WINDOWS\System32\Drivers\DLACDBHM.SYS -- (DLACDBHM)

DRV - [2007/01/23 04:45:44 | 000,042,832 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\Asfalrt.sys -- (AsfAlrt)

========== Standard Registry (SafeList) ==========

========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.thecollegespartnership.co.uk/content.asp?ContentID=1

IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..extensions.enabledItems: {1E73965B-8B48-48be-9C8D-68B920ABC1C4}:10.0.0.1374

FF - prefs.js..network.proxy.type: 0

FF - HKLM\software\mozilla\Firefox\Extensions\\{1E73965B-8B48-48be-9C8D-68B920ABC1C4}: C:\Program Files\AVG\AVG10\Firefox4\ [2011/06/03 08:20:10 | 000,000,000 | ---D | M]

FF - HKLM\software\mozilla\Mozilla Firefox 5.0\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011/07/01 17:03:45 | 000,000,000 | ---D | M]

FF - HKLM\software\mozilla\Mozilla Firefox 5.0\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins

[2011/06/24 10:24:42 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\WASCP\Application Data\Mozilla\Extensions

[2011/06/24 10:25:46 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\WASCP\Application Data\Mozilla\Firefox\Profiles\rfkfg9b9.default\extensions

[2011/06/24 10:25:46 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- C:\Documents and Settings\WASCP\Application Data\Mozilla\Firefox\Profiles\rfkfg9b9.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}

[2011/07/01 17:03:45 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions

File not found (No name found) --

[2011/06/16 06:32:38 | 000,142,296 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\browsercomps.dll

[2010/01/01 10:00:00 | 000,001,538 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\amazon-en-GB.xml

[2011/06/24 10:23:07 | 000,002,428 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\babylon.xml

[2010/01/01 10:00:00 | 000,002,252 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\bing.xml

[2010/01/01 10:00:00 | 000,000,947 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\chambers-en-GB.xml

[2010/01/01 10:00:00 | 000,001,180 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\eBay-en-GB.xml

[2010/01/01 10:00:00 | 000,001,135 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\yahoo-en-GB.xml

O1 HOSTS File: ([2011/07/13 12:39:36 | 000,000,098 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\Hosts

O1 - Hosts: 127.0.0.1 localhost

O1 - Hosts: ::1 localhost

O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - File not found

O2 - BHO: (Spybot-S&D IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)

O2 - BHO: (SSVHelper Class) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll (Sun Microsystems, Inc.)

O2 - BHO: (Skype Plug-In) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)

O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.7.6406.1642\swg.dll (Google Inc.)

O4 - HKLM..\Run: [atchk] C:\Program Files\Intel\AMT\atchk.exe ()

O4 - HKLM..\Run: [iAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe ()

O4 - HKLM..\Run: [PDVDDXSrv] C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe ()

O4 - HKLM..\Run: [sunJavaUpdateSched] C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe ()

O4 - HKCU..\Run: [iSUSPM] C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM .exe ()

O4 - HKCU..\Run: [spybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe ()

O4 - HKLM..\RunOnce: [AvgUninstallURL] C:\WINDOWS\System32\cmd.exe (Microsoft Corporation)

O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Infodelivery present

O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present

O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1

O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: LinkResolveIgnoreLinkInfo = 0

O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoResolveSearch = 1

O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863

O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323

O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0

O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present

O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323

O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: LinkResolveIgnoreLinkInfo = 0

O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863

O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0

O9 - Extra 'Tools' menuitem : Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\npjpi160_07.dll (Sun Microsystems, Inc.)

O9 - Extra Button: Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)

O9 - Extra 'Tools' menuitem : Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)

O9 - Extra 'Tools' menuitem : Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)

O15 - HKCU\..Trusted Domains: //@install.mar@/ ([]msni in My Computer)

O15 - HKCU\..Trusted Domains: //@mail.mar@/ ([]msni in Local intranet)

O15 - HKCU\..Trusted Domains: tribalhosted.co.uk ([csg2] https in Trusted sites)

O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} http://www.update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1228722288531 (WUWebControl Class)

O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab (Java Plug-in 1.6.0_07)

O16 - DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab (Java Plug-in 1.6.0_07)

O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab (Java Plug-in 1.6.0_07)

O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.2.1

O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)

O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)

O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)

O24 - Desktop WallPaper: C:\Documents and Settings\WASCP\Local Settings\Application Data\Microsoft\Wallpaper1.bmp

O24 - Desktop BackupWallPaper: C:\Documents and Settings\WASCP\Local Settings\Application Data\Microsoft\Wallpaper1.bmp

O32 - HKLM CDRom: AutoRun - 1

O32 - AutoRun File - [2008/04/25 23:29:32 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]

O32 - AutoRun File - [2011/06/24 11:48:40 | 000,000,003 | RHS- | M] () - E:\autorun.inf -- [ FAT ]

O34 - HKLM BootExecute: (autocheck autochk *) - File not found

O35 - HKLM\..comfile [open] -- "%1" %*

O35 - HKLM\..exefile [open] -- "%1" %*

O37 - HKLM\...com [@ = comfile] -- "%1" %*

O37 - HKLM\...exe [@ = exefile] -- "%1" %*

========== Files/Folders - Created Within 30 Days ==========

[2011/07/13 12:39:35 | 000,000,000 | ---D | C] -- C:\_OTL

[2011/07/12 15:32:23 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\Spybot - Search & Destroy

[2011/07/12 09:13:29 | 000,000,000 | ---D | C] -- C:\Documents and Settings\NetworkService\Local Settings\Application Data\PowerDVD DX

[2011/07/12 09:13:19 | 000,000,000 | ---D | C] -- C:\Documents and Settings\NetworkService\Local Settings\Application Data\Identities

[2011/07/05 08:43:49 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\Google Earth

[2011/07/04 15:39:20 | 000,580,096 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\WASCP\Desktop\OTL.scr

[2011/07/04 14:01:18 | 000,039,984 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbamswissarmy.sys

[2011/07/04 14:01:18 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\Malwarebytes' Anti-Malware

[2011/07/04 14:01:15 | 000,022,712 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbam.sys

[2011/07/04 14:01:15 | 000,000,000 | ---D | C] -- C:\Program Files\Malwarebytes' Anti-Malware

[2011/07/04 10:08:29 | 000,000,000 | ---D | C] -- C:\Program Files\ESET

[2011/07/04 10:00:21 | 000,000,000 | -HSD | C] -- C:\RECYCLER

[2011/07/01 17:39:12 | 000,000,000 | ---D | C] -- C:\Documents and Settings\WASCP\Desktop\Richies tools

[2011/07/01 17:28:46 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\avg9

[2011/07/01 16:23:41 | 000,000,000 | RHSD | C] -- C:\cmdcons

[2011/07/01 16:20:38 | 000,000,000 | ---D | C] -- C:\WINDOWS\ERDNT

[2011/07/01 16:15:10 | 000,000,000 | ---D | C] -- C:\Malwarebytes' Anti-Malware

[2011/07/01 15:16:57 | 000,000,000 | ---D | C] -- C:\Documents and Settings\WASCP\Application Data\Malwarebytes

[2011/07/01 15:16:52 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Malwarebytes

[2011/06/24 10:24:24 | 000,000,000 | ---D | C] -- C:\Documents and Settings\WASCP\Local Settings\Application Data\Mozilla

[2011/06/24 10:24:24 | 000,000,000 | ---D | C] -- C:\Documents and Settings\WASCP\Application Data\Mozilla

[2011/06/24 10:23:07 | 000,000,000 | ---D | C] -- C:\Program Files\Mozilla Firefox

[2011/06/24 08:56:47 | 000,000,000 | ---D | C] -- C:\Program Files\Advanced PC Tweaker

[2011/06/23 11:54:11 | 000,000,000 | ---D | C] -- C:\Documents and Settings\WASCP\Application Data\MSNInstaller

[2011/06/23 10:48:50 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\NtmsData

[2011/06/21 12:26:48 | 000,000,000 | ---D | C] -- C:\Program Files\Spybot - Search & Destroy

[2011/06/21 12:26:48 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy

[2011/06/21 11:17:57 | 000,000,000 | ---D | C] -- C:\svest

[2011/06/20 13:06:09 | 000,000,000 | ---D | C] -- C:\Documents and Settings\NetworkService\Local Settings\Application Data\NVIDIA Corporation

========== Files - Modified Within 30 Days ==========

[2011/07/13 12:42:02 | 000,002,206 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl

[2011/07/13 12:42:00 | 000,000,896 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job

[2011/07/13 12:42:00 | 000,000,892 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job

[2011/07/13 12:41:47 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat

[2011/07/13 12:41:46 | 2101,964,800 | -HS- | M] () -- C:\hiberfil.sys

[2011/07/13 12:39:36 | 000,000,098 | ---- | M] () -- C:\WINDOWS\System32\drivers\etc\Hosts

[2011/07/13 12:30:36 | 000,267,800 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT

[2011/07/13 11:16:13 | 000,000,127 | ---- | M] () -- C:\WINDOWS\System32\MRT.INI

[2011/07/13 11:14:34 | 000,001,374 | ---- | M] () -- C:\WINDOWS\imsins.BAK

[2011/07/13 09:24:45 | 000,000,664 | ---- | M] () -- C:\WINDOWS\System32\d3d9caps.dat

[2011/07/12 15:32:24 | 000,000,953 | ---- | M] () -- C:\Documents and Settings\WASCP\Application Data\Microsoft\Internet Explorer\Quick Launch\Spybot - Search & Destroy.lnk

[2011/07/12 15:32:23 | 000,000,935 | ---- | M] () -- C:\Documents and Settings\WASCP\Desktop\Spybot - Search & Destroy.lnk

[2011/07/11 13:55:41 | 000,000,572 | ---- | M] () -- C:\Documents and Settings\WASCP\My Documents\spider.sav

[2011/07/05 08:43:49 | 000,001,917 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Google Earth.lnk

[2011/07/04 15:39:22 | 000,580,096 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\WASCP\Desktop\OTL.scr

[2011/07/04 14:01:18 | 000,000,786 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk

[2011/07/04 11:27:44 | 000,001,731 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Adobe Reader 9.lnk

[2011/07/04 09:53:19 | 000,467,220 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat

[2011/07/04 09:53:19 | 000,080,310 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat

[2011/07/01 17:03:46 | 000,000,744 | ---- | M] () -- C:\Documents and Settings\WASCP\Application Data\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox.lnk

[2011/07/01 17:03:46 | 000,000,726 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Mozilla Firefox.lnk

[2011/07/01 16:23:45 | 000,000,327 | RHS- | M] () -- C:\boot.ini

[2011/06/24 12:12:25 | 000,000,512 | ---- | M] () -- C:\WINDOWS\tasks\One-Click Tweak.job

[2011/06/24 10:24:26 | 000,000,000 | ---- | M] () -- C:\WINDOWS\nsreg.dat

[2011/06/21 13:46:17 | 000,002,312 | ---- | M] () -- C:\WINDOWS\wininit.ini

========== Files Created - No Company Name ==========

[2011/07/12 15:32:23 | 000,000,953 | ---- | C] () -- C:\Documents and Settings\WASCP\Application Data\Microsoft\Internet Explorer\Quick Launch\Spybot - Search & Destroy.lnk

[2011/07/12 15:32:23 | 000,000,935 | ---- | C] () -- C:\Documents and Settings\WASCP\Desktop\Spybot - Search & Destroy.lnk

[2011/07/05 08:43:49 | 000,001,917 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Google Earth.lnk

[2011/07/04 15:45:04 | 2101,964,800 | -HS- | C] () -- C:\hiberfil.sys

[2011/07/04 14:01:18 | 000,000,786 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk

[2011/07/04 11:27:43 | 000,001,731 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Adobe Reader 9.lnk

[2011/07/01 17:03:46 | 000,000,744 | ---- | C] () -- C:\Documents and Settings\WASCP\Application Data\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox.lnk

[2011/07/01 17:03:46 | 000,000,732 | ---- | C] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Mozilla Firefox.lnk

[2011/07/01 17:03:46 | 000,000,726 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Mozilla Firefox.lnk

[2011/07/01 16:23:45 | 000,000,211 | ---- | C] () -- C:\Boot.bak

[2011/07/01 16:23:43 | 000,260,272 | RHS- | C] () -- C:\cmldr

[2011/06/24 10:24:26 | 000,000,000 | ---- | C] () -- C:\WINDOWS\nsreg.dat

[2011/06/24 08:57:01 | 000,000,512 | ---- | C] () -- C:\WINDOWS\tasks\One-Click Tweak.job

[2011/06/20 08:32:26 | 000,000,127 | ---- | C] () -- C:\WINDOWS\System32\MRT.INI

[2011/05/11 15:01:39 | 000,000,664 | ---- | C] () -- C:\WINDOWS\System32\d3d9caps.dat

[2009/09/22 08:17:46 | 000,013,312 | ---- | C] () -- C:\Documents and Settings\WASCP\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini

[2009/03/30 11:07:16 | 000,038,433 | ---- | C] () -- C:\Documents and Settings\WASCP\Application Data\Comma Separated Values (Windows).ADR

[2009/01/29 12:49:45 | 000,000,056 | -H-- | C] () -- C:\WINDOWS\System32\ezsidmv.dat

[2008/10/16 20:44:32 | 000,204,800 | ---- | C] () -- C:\WINDOWS\System32\igfxCoIn_v4837.dll

[2008/10/16 20:44:13 | 000,001,167 | ---- | C] () -- C:\WINDOWS\System32\OEMINFO.INI

[2008/10/16 12:00:05 | 000,000,061 | ---- | C] () -- C:\WINDOWS\smscfg.ini

[2008/10/16 11:56:13 | 000,002,312 | ---- | C] () -- C:\WINDOWS\wininit.ini

[2008/05/26 21:59:42 | 000,018,904 | ---- | C] () -- C:\WINDOWS\System32\structuredqueryschematrivial.bin

[2008/05/26 21:59:40 | 000,106,605 | ---- | C] () -- C:\WINDOWS\System32\structuredqueryschema.bin

[2008/04/25 23:31:41 | 000,002,048 | --S- | C] () -- C:\WINDOWS\bootstat.dat

[2008/04/25 23:27:18 | 000,021,640 | ---- | C] () -- C:\WINDOWS\System32\emptyregdb.dat

[2008/04/25 23:26:32 | 000,001,793 | ---- | C] () -- C:\WINDOWS\System32\fxsperf.ini

[2008/04/25 18:16:24 | 000,004,569 | ---- | C] () -- C:\WINDOWS\System32\secupd.dat

[2008/04/25 18:16:22 | 000,467,220 | ---- | C] () -- C:\WINDOWS\System32\perfh009.dat

[2008/04/25 18:16:22 | 000,272,128 | ---- | C] () -- C:\WINDOWS\System32\perfi009.dat

[2008/04/25 18:16:22 | 000,080,310 | ---- | C] () -- C:\WINDOWS\System32\perfc009.dat

[2008/04/25 18:16:22 | 000,028,626 | ---- | C] () -- C:\WINDOWS\System32\perfd009.dat

[2008/04/25 18:16:22 | 000,004,627 | ---- | C] () -- C:\WINDOWS\System32\oembios.dat

[2008/04/25 18:16:21 | 013,107,200 | ---- | C] () -- C:\WINDOWS\System32\oembios.bin

[2008/04/25 18:16:20 | 000,000,741 | ---- | C] () -- C:\WINDOWS\System32\noise.dat

[2008/04/25 18:16:18 | 000,673,088 | ---- | C] () -- C:\WINDOWS\System32\mlang.dat

[2008/04/25 18:16:18 | 000,046,258 | ---- | C] () -- C:\WINDOWS\System32\mib.bin

[2008/04/25 18:16:13 | 000,218,003 | ---- | C] () -- C:\WINDOWS\System32\dssec.dat

[2008/04/25 18:16:11 | 000,001,804 | ---- | C] () -- C:\WINDOWS\System32\Dcache.bin

[2008/04/25 11:22:39 | 000,004,161 | ---- | C] () -- C:\WINDOWS\ODBCINST.INI

[2008/04/25 11:21:52 | 000,267,800 | ---- | C] () -- C:\WINDOWS\System32\FNTCACHE.DAT

[2007/09/27 10:51:02 | 000,020,698 | ---- | C] () -- C:\WINDOWS\System32\idxcntrs.ini

[2007/09/27 10:48:48 | 000,030,628 | ---- | C] () -- C:\WINDOWS\System32\gsrvctr.ini

[2007/09/27 10:48:28 | 000,031,698 | ---- | C] () -- C:\WINDOWS\System32\gthrctr.ini

[2007/02/28 06:03:32 | 000,080,720 | ---- | C] () -- C:\WINDOWS\System32\AsfBios.dll

[2007/01/23 04:45:40 | 000,025,424 | ---- | C] () -- C:\WINDOWS\System32\drivers\netamsg.dll

========== LOP Check ==========

[2011/07/01 16:19:59 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\AVG10

[2011/07/04 12:44:34 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\avg9

[2010/10/22 07:56:24 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Application Data\Common Files

[2010/10/22 07:55:18 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\MFAData

[2011/07/04 11:26:20 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\TEMP

[2011/02/03 13:38:54 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\W3i

[2010/10/22 08:02:02 | 000,000,000 | ---D | M] -- C:\Documents and Settings\WASCP\Application Data\AVG10

[2011/05/13 08:29:40 | 000,000,000 | ---D | M] -- C:\Documents and Settings\WASCP\Application Data\Avidat

[2011/02/03 13:39:33 | 000,000,000 | ---D | M] -- C:\Documents and Settings\WASCP\Application Data\FinalTorrent

[2011/05/31 14:33:40 | 000,000,000 | ---D | M] -- C:\Documents and Settings\WASCP\Application Data\Geaw

[2009/02/12 09:36:16 | 000,000,000 | ---D | M] -- C:\Documents and Settings\WASCP\Application Data\ICAClient

[2011/06/24 08:26:00 | 000,000,000 | ---D | M] -- C:\Documents and Settings\WASCP\Application Data\MSNInstaller

[2010/10/26 10:54:21 | 000,000,000 | ---D | M] -- C:\Documents and Settings\WASCP\Application Data\Registry Mechanic

[2011/06/10 08:31:16 | 000,000,000 | ---D | M] -- C:\Documents and Settings\WASCP\Application Data\Vytea

[2009/03/30 10:52:10 | 000,000,000 | ---D | M] -- C:\Documents and Settings\WASCP\Application Data\Windows Desktop Search

[2009/07/01 09:40:09 | 000,000,000 | ---D | M] -- C:\Documents and Settings\WASCP\Application Data\Windows Search

[2011/06/24 12:12:25 | 000,000,512 | ---- | M] () -- C:\WINDOWS\Tasks\One-Click Tweak.job

========== Purity Check ==========

========== Alternate Data Streams ==========

@Alternate Data Stream - 104 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:D1B5B4F1

< End of report >

COMBOFIX log

ComboFix 11-07-12.09 - Bob Collins 13/07/2011 12:52:42.2.2 - x86

Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2005.1481 [GMT 2:00]

Running from: c:\documents and settings\WASCP\My Documents\Downloads\ComboFix.exe

.

.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))

.

.

c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe

c:\program files\Analog Devices\Core\smax4pnp.exe

c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe

c:\program files\Intel\AMT\atchk.exe

c:\program files\Intel\Intel Matrix Storage Manager\Iaanotif.exe

c:\program files\Java\jre1.6.0_07\bin\jusched.exe

c:\windows\system32\config\systemprofile\Application Data\alot

.

.

((((((((((((((((((((((((( Files Created from 2011-06-13 to 2011-07-13 )))))))))))))))))))))))))))))))

.

.

2011-07-13 10:39 . 2011-07-13 10:39 -------- d-----w- C:\_OTL

2011-07-12 07:13 . 2011-07-12 07:13 -------- d-----w- c:\documents and settings\NetworkService\Local Settings\Application Data\PowerDVD DX

2011-07-12 07:13 . 2011-07-12 07:13 -------- d-----w- c:\documents and settings\NetworkService\Local Settings\Application Data\Identities

2011-07-04 12:01 . 2011-05-29 07:11 39984 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys

2011-07-04 12:01 . 2011-07-12 12:18 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware

2011-07-04 12:01 . 2011-05-29 07:11 22712 ----a-w- c:\windows\system32\drivers\mbam.sys

2011-07-04 08:08 . 2011-07-04 08:08 -------- d-----w- c:\program files\ESET

2011-07-01 15:28 . 2011-07-04 10:44 -------- d-----w- c:\documents and settings\All Users\Application Data\avg9

2011-07-01 14:15 . 2011-07-01 14:15 -------- d-----w- C:\Malwarebytes' Anti-Malware

2011-07-01 13:16 . 2011-07-01 13:16 -------- d-----w- c:\documents and settings\WASCP\Application Data\Malwarebytes

2011-07-01 13:16 . 2011-07-01 13:16 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes

2011-06-24 08:24 . 2011-06-24 08:24 -------- d-----w- c:\documents and settings\WASCP\Local Settings\Application Data\Mozilla

2011-06-24 06:56 . 2011-07-04 08:28 -------- d-----w- c:\program files\Advanced PC Tweaker

2011-06-23 09:54 . 2011-06-24 06:26 -------- d-----w- c:\documents and settings\WASCP\Application Data\MSNInstaller

2011-06-23 08:48 . 2011-06-23 08:50 -------- d-----w- c:\windows\system32\NtmsData

2011-06-21 10:26 . 2011-07-12 13:51 -------- d-----w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy

2011-06-21 10:26 . 2011-07-12 13:32 -------- d-----w- c:\program files\Spybot - Search & Destroy

2011-06-21 09:17 . 2011-06-21 09:17 -------- d-----w- C:\svest

2011-06-20 11:06 . 2011-06-20 11:06 -------- d-----w- c:\documents and settings\NetworkService\Local Settings\Application Data\NVIDIA Corporation

2011-06-20 06:31 . 2011-04-21 13:37 105472 -c----w- c:\windows\system32\dllcache\mup.sys

.

.

.

(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))

.

2011-06-02 14:02 . 2008-04-25 16:16 1858944 ----a-w- c:\windows\system32\win32k.sys

2011-05-02 15:31 . 2008-04-25 21:27 692736 ----a-w- c:\windows\system32\inetcomm.dll

2011-04-29 17:25 . 2008-04-25 16:16 151552 ----a-w- c:\windows\system32\schannel.dll

2011-04-29 16:19 . 2008-04-25 16:16 456320 ----a-w- c:\windows\system32\drivers\mrxsmb.sys

2011-04-26 11:07 . 2008-04-25 16:16 293376 ----a-w- c:\windows\system32\winsrv.dll

2011-04-26 11:07 . 2008-04-25 16:16 33280 ----a-w- c:\windows\system32\csrsrv.dll

2011-04-25 15:51 . 2008-04-25 16:16 832512 ----a-w- c:\windows\system32\wininet.dll

2011-04-25 15:51 . 2009-06-08 06:01 78336 ----a-w- c:\windows\system32\ieencode.dll

2011-04-25 15:51 . 2008-04-25 16:16 1830912 ----a-w- c:\windows\system32\inetcpl.cpl

2011-04-25 15:51 . 2008-04-25 16:16 17408 ----a-w- c:\windows\system32\corpol.dll

2011-04-25 12:01 . 2008-04-25 16:16 389120 ----a-w- c:\windows\system32\html.iec

2011-04-21 13:37 . 2008-04-25 16:16 105472 ----a-w- c:\windows\system32\drivers\mup.sys

2011-06-16 04:32 . 2011-07-01 15:03 142296 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll

.

<pre>
c:\program files\Adobe\Reader 9.0\Reader\Reader_sl .exe
c:\program files\Analog Devices\Core\smax4pnp .exe
c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM .exe
c:\program files\Common Files\InstallShield\UpdateService\ISUSPM .exe
c:\program files\Common Files\InstallShield\UpdateService\ISUSPM .exe
c:\program files\CyberLink\PowerDVD DX\PDVDDXSrv .exe
c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier .exe
c:\program files\Intel\AMT\atchk .exe
c:\program files\Intel\Intel Matrix Storage Manager\Iaanotif .exe
c:\program files\Java\jre1.6.0_07\bin\jusched .exe
c:\program files\Spybot - Search & Destroy\TeaTimer .exe
</pre>

.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))

.

.

*Note* empty entries & legit default entries are not shown

REGEDIT4

.

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"ISUSPM"="c:\program files\Common Files\InstallShield\UpdateService\ISUSPM .exe -scheduler" [X]

"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2011-07-12 39944]

"Skype"="c:\program files\Skype\Phone\Skype.exe" [2010-12-03 14944136]

"SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2011-07-12 39948]

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"SoundMAXPnP"="c:\program files\Analog Devices\Core\smax4pnp.exe" [N/A]

"IgfxTray"="c:\windows\system32\igfxtray.exe" [2007-06-28 141848]

"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2007-06-28 162328]

"Persistence"="c:\windows\system32\igfxpers.exe" [2007-06-28 137752]

"SunJavaUpdateSched"="c:\program files\Java\jre1.6.0_07\bin\jusched.exe" [N/A]

"IAAnotif"="c:\program files\Intel\Intel Matrix Storage Manager\Iaanotif.exe" [N/A]

"atchk"="c:\program files\Intel\AMT\atchk.exe" [N/A]

"PDVDDXSrv"="c:\program files\CyberLink\PowerDVD DX\PDVDDXSrv.exe" [2011-07-12 39940]

"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [N/A]

"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [N/A]

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]

"AvgUninstallURL"="start http://www.avg.com/ww.special-uninstallation-feedback-appf?lic=OQBBAFYARgBSAEUARQAtAFYAMABLAE0AQwAtAEUAOQBWAFUAVwAtAEUAVwAwAFYAQQAtAFUAVQAzAFgATAAtAEYARQBXADkANwA&inst=NwA3AC0ANgA2ADUANQA3ADgANQAzADkALQBUADEALQBCAEEAKwAxAC0AWABMACsAMQAtAFUAQwBBAEwATAArADEALQBVAEMAQQBMAEwAMgArADIALQBUAEIAOAArADIALQBGAEwAKwA5AC0ARABEAFQAKwAwAC0AWABPADkAKwAxAC0AWABPADMANgArADEA∏=90&ver=9.0.901" [?]

.

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]

"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]

.

c:\documents and settings\All Users\Start Menu\Programs\Startup\

Windows Search.lnk - c:\program files\Windows Desktop Search\WindowsSearch.exe [2008-5-26 123904]

.

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]

"DisableNotifications"= 1 (0x1)

.

S2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [15/10/2009 13:01 133104]

S3 AsfAlrt;AsfAlrt Service;c:\windows\system32\drivers\Asfalrt.sys [23/01/2007 04:45 42832]

S3 gupdatem;Google Update Service (gupdatem);c:\program files\Google\Update\GoogleUpdate.exe [15/10/2009 13:01 133104]

S4 AMService;AMService;c:\windows\TEMP\lkim\setup.exe run --> c:\windows\TEMP\lkim\setup.exe run [?]

S4 ASFAgent;ASF Agent;c:\program files\Intel\ASF Agent\ASFAgent.exe [23/01/2007 04:58 133968]

S4 UNS;Intel® Active Management Technology User Notification Service;c:\program files\Intel\AMT\UNS.exe [16/10/2008 11:55 2521880]

.

Contents of the 'Scheduled Tasks' folder

.

2011-07-13 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job

- c:\program files\Google\Update\GoogleUpdate.exe [2009-10-15 11:01]

.

2011-07-13 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job

- c:\program files\Google\Update\GoogleUpdate.exe [2009-10-15 11:01]

.

2011-06-24 c:\windows\Tasks\One-Click Tweak.job

- c:\program files\Advanced PC Tweaker\OneClick.exe [2011-06-24 09:14]

.

.

------- Supplementary Scan -------

.

uStart Page = hxxp://www.thecollegespartnership.co.uk/content.asp?ContentID=1

Trusted Zone: tribalhosted.co.uk\csg2

TCP: DhcpNameServer = 192.168.2.1

FF - ProfilePath - c:\documents and settings\WASCP\Application Data\Mozilla\Firefox\Profiles\rfkfg9b9.default\

FF - prefs.js: network.proxy.type - 0

.

.

**************************************************************************

.

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net

Rootkit scan 2011-07-13 13:01

Windows 5.1.2600 Service Pack 3 NTFS

.

scanning hidden processes ...

.

scanning hidden autostart entries ...

.

scanning hidden files ...

.

scan completed successfully

hidden files: 0

.

**************************************************************************

.

--------------------- DLLs Loaded Under Running Processes ---------------------

.

- - - - - - - > 'winlogon.exe'(732)

c:\windows\system32\WININET.dll

.

- - - - - - - > 'lsass.exe'(792)

c:\windows\system32\WININET.dll

.

Completion time: 2011-07-13 13:05:26

ComboFix-quarantined-files.txt 2011-07-13 11:05

.

Pre-Run: 140,695,080,960 bytes free

Post-Run: 140,598,337,536 bytes free

.

- - End Of File - - B813EF3A3A3DD92CDA1220BAECBF5B8B

Link to post
Share on other sites

hi

1. Close any open browsers.

2. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.

3. Open notepad and copy/paste the text in the quotebox below into it:

KillAll::

RenV::

c:\program files\Adobe\Reader 9.0\Reader\Reader_sl .exe

c:\program files\Analog Devices\Core\smax4pnp .exe

c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM .exe

c:\program files\Common Files\InstallShield\UpdateService\ISUSPM .exe

c:\program files\Common Files\InstallShield\UpdateService\ISUSPM .exe

c:\program files\CyberLink\PowerDVD DX\PDVDDXSrv .exe

c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier .exe

c:\program files\Intel\AMT\atchk .exe

c:\program files\Intel\Intel Matrix Storage Manager\Iaanotif .exe

c:\program files\Java\jre1.6.0_07\bin\jusched .exe

c:\program files\Spybot - Search & Destroy\TeaTimer .exe

Registry::

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]

"AvgUninstallURL"=-

Driver::

AMService

Save this as CFScript.txt, in the same location as ComboFix.exe

CFScriptB-4.gif

Refering to the picture above, drag CFScript into ComboFix.exe

When finished, it shall produce a log for you at C:\ComboFix.txt which I will require in your next reply.

Link to post
Share on other sites

Hi Ali,

Here is the ComboFix log you requested;

ComboFix 11-07-12.09 - Bob Collins 13/07/2011 14:20:53.3.2 - x86

Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2005.1489 [GMT 2:00]

Running from: c:\documents and settings\WASCP\My Documents\Downloads\ComboFix.exe

Command switches used :: c:\documents and settings\WASCP\Desktop\CFScript.txt

.

.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))

.

.

c:\program files\Common Files\InstallShield\UpdateService\ISUSPM.exe

c:\program files\Spybot - Search & Destroy\TeaTimer.exe

c:\windows\system32\sshnas21.dll

.

 <pre>
c:\program files\Common Files\InstallShield\UpdateService\ISUSPM .exe ---^> c:\program files\Common Files\InstallShield\UpdateService\ISUSPM.exe
</pre>

.

.

((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))

.

.

-------\Legacy_AMSERVICE

-------\Legacy_SSHNAS

-------\Service_AMService

-------\Service_SSHNAS

.

.

((((((((((((((((((((((((( Files Created from 2011-06-13 to 2011-07-13 )))))))))))))))))))))))))))))))

.

.

2011-07-13 10:39 . 2011-07-13 10:39 -------- d-----w- C:\_OTL

2011-07-12 07:13 . 2011-07-12 07:13 -------- d-----w- c:\documents and settings\NetworkService\Local Settings\Application Data\PowerDVD DX

2011-07-12 07:13 . 2011-07-12 07:13 -------- d-----w- c:\documents and settings\NetworkService\Local Settings\Application Data\Identities

2011-07-04 12:01 . 2011-05-29 07:11 39984 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys

2011-07-04 12:01 . 2011-07-12 12:18 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware

2011-07-04 12:01 . 2011-05-29 07:11 22712 ----a-w- c:\windows\system32\drivers\mbam.sys

2011-07-04 08:08 . 2011-07-04 08:08 -------- d-----w- c:\program files\ESET

2011-07-01 15:28 . 2011-07-04 10:44 -------- d-----w- c:\documents and settings\All Users\Application Data\avg9

2011-07-01 14:15 . 2011-07-01 14:15 -------- d-----w- C:\Malwarebytes' Anti-Malware

2011-07-01 13:16 . 2011-07-01 13:16 -------- d-----w- c:\documents and settings\WASCP\Application Data\Malwarebytes

2011-07-01 13:16 . 2011-07-01 13:16 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes

2011-06-24 08:24 . 2011-06-24 08:24 -------- d-----w- c:\documents and settings\WASCP\Local Settings\Application Data\Mozilla

2011-06-24 06:56 . 2011-07-04 08:28 -------- d-----w- c:\program files\Advanced PC Tweaker

2011-06-23 09:54 . 2011-06-24 06:26 -------- d-----w- c:\documents and settings\WASCP\Application Data\MSNInstaller

2011-06-23 08:48 . 2011-06-23 08:50 -------- d-----w- c:\windows\system32\NtmsData

2011-06-21 10:26 . 2011-07-13 12:27 -------- d-----w- c:\program files\Spybot - Search & Destroy

2011-06-21 10:26 . 2011-07-12 13:51 -------- d-----w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy

2011-06-21 09:17 . 2011-06-21 09:17 -------- d-----w- C:\svest

2011-06-20 11:06 . 2011-06-20 11:06 -------- d-----w- c:\documents and settings\NetworkService\Local Settings\Application Data\NVIDIA Corporation

2011-06-20 06:31 . 2011-04-21 13:37 105472 -c----w- c:\windows\system32\dllcache\mup.sys

.

.

.

(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))

.

2011-06-02 14:02 . 2008-04-25 16:16 1858944 ----a-w- c:\windows\system32\win32k.sys

2011-05-02 15:31 . 2008-04-25 21:27 692736 ----a-w- c:\windows\system32\inetcomm.dll

2011-04-29 17:25 . 2008-04-25 16:16 151552 ----a-w- c:\windows\system32\schannel.dll

2011-04-29 16:19 . 2008-04-25 16:16 456320 ----a-w- c:\windows\system32\drivers\mrxsmb.sys

2011-04-26 11:07 . 2008-04-25 16:16 293376 ----a-w- c:\windows\system32\winsrv.dll

2011-04-26 11:07 . 2008-04-25 16:16 33280 ----a-w- c:\windows\system32\csrsrv.dll

2011-04-25 15:51 . 2008-04-25 16:16 832512 ----a-w- c:\windows\system32\wininet.dll

2011-04-25 15:51 . 2009-06-08 06:01 78336 ----a-w- c:\windows\system32\ieencode.dll

2011-04-25 15:51 . 2008-04-25 16:16 1830912 ----a-w- c:\windows\system32\inetcpl.cpl

2011-04-25 15:51 . 2008-04-25 16:16 17408 ----a-w- c:\windows\system32\corpol.dll

2011-04-25 12:01 . 2008-04-25 16:16 389120 ----a-w- c:\windows\system32\html.iec

2011-04-21 13:37 . 2008-04-25 16:16 105472 ----a-w- c:\windows\system32\drivers\mup.sys

2011-06-16 04:32 . 2011-07-01 15:03 142296 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll

.

.

((((((((((((((((((((((((((((( SnapShot@2011-07-13_11.01.31 )))))))))))))))))))))))))))))))))))))))))

.

+ 2011-07-13 12:13 . 2011-07-13 12:13 32768 c:\windows\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat

+ 2008-12-02 16:08 . 2011-07-13 12:13 32768 c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat

- 2008-12-02 16:08 . 2011-07-05 06:43 32768 c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat

+ 2011-07-13 12:13 . 2011-07-13 12:13 16384 c:\windows\system32\config\systemprofile\Cookies\index.dat

- 2011-07-05 06:43 . 2011-07-05 06:43 16384 c:\windows\system32\config\systemprofile\Cookies\index.dat

.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))

.

.

*Note* empty entries & legit default entries are not shown

REGEDIT4

.

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"ISUSPM"="c:\program files\Common Files\InstallShield\UpdateService\ISUSPM .exe -scheduler" [X]

"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-02-19 39408]

"Skype"="c:\program files\Skype\Phone\Skype.exe" [2010-12-03 14944136]

"SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2009-01-26 2144088]

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"SoundMAXPnP"="c:\program files\Analog Devices\Core\smax4pnp.exe" [2007-09-25 1036288]

"IgfxTray"="c:\windows\system32\igfxtray.exe" [2007-06-28 141848]

"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2007-06-28 162328]

"Persistence"="c:\windows\system32\igfxpers.exe" [2007-06-28 137752]

"SunJavaUpdateSched"="c:\program files\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 144784]

"IAAnotif"="c:\program files\Intel\Intel Matrix Storage Manager\Iaanotif.exe" [2007-10-03 178712]

"atchk"="c:\program files\Intel\AMT\atchk.exe" [2007-06-12 408344]

"PDVDDXSrv"="c:\program files\CyberLink\PowerDVD DX\PDVDDXSrv.exe" [2008-05-23 128296]

"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2011-06-08 37296]

"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2011-03-30 937920]

.

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]

"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]

.

c:\documents and settings\All Users\Start Menu\Programs\Startup\

Windows Search.lnk - c:\program files\Windows Desktop Search\WindowsSearch.exe [2008-5-26 123904]

.

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]

"DisableNotifications"= 1 (0x1)

.

S2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [15/10/2009 13:01 133104]

S3 AsfAlrt;AsfAlrt Service;c:\windows\system32\drivers\Asfalrt.sys [23/01/2007 04:45 42832]

S3 gupdatem;Google Update Service (gupdatem);c:\program files\Google\Update\GoogleUpdate.exe [15/10/2009 13:01 133104]

S4 ASFAgent;ASF Agent;c:\program files\Intel\ASF Agent\ASFAgent.exe [23/01/2007 04:58 133968]

S4 UNS;Intel® Active Management Technology User Notification Service;c:\program files\Intel\AMT\UNS.exe [16/10/2008 11:55 2521880]

.

Contents of the 'Scheduled Tasks' folder

.

2011-07-13 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job

- c:\program files\Google\Update\GoogleUpdate.exe [2009-10-15 11:01]

.

2011-07-13 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job

- c:\program files\Google\Update\GoogleUpdate.exe [2009-10-15 11:01]

.

2011-06-24 c:\windows\Tasks\One-Click Tweak.job

- c:\program files\Advanced PC Tweaker\OneClick.exe [2011-06-24 09:14]

.

.

------- Supplementary Scan -------

.

uStart Page = hxxp://www.thecollegespartnership.co.uk/content.asp?ContentID=1

Trusted Zone: tribalhosted.co.uk\csg2

TCP: DhcpNameServer = 192.168.2.1

FF - ProfilePath - c:\documents and settings\WASCP\Application Data\Mozilla\Firefox\Profiles\rfkfg9b9.default\

FF - prefs.js: network.proxy.type - 0

.

.

**************************************************************************

.

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net

Rootkit scan 2011-07-13 14:32

Windows 5.1.2600 Service Pack 3 NTFS

.

scanning hidden processes ...

.

scanning hidden autostart entries ...

.

scanning hidden files ...

.

scan completed successfully

hidden files: 0

.

**************************************************************************

.

--------------------- DLLs Loaded Under Running Processes ---------------------

.

- - - - - - - > 'winlogon.exe'(736)

c:\windows\system32\WININET.dll

.

- - - - - - - > 'lsass.exe'(796)

c:\windows\system32\WININET.dll

.

- - - - - - - > 'explorer.exe'(3124)

c:\windows\system32\WININET.dll

c:\program files\Windows Desktop Search\deskbar.dll

c:\program files\Windows Desktop Search\en-us\dbres.dll.mui

c:\program files\Windows Desktop Search\dbres.dll

c:\program files\Windows Desktop Search\wordwheel.dll

c:\program files\Windows Desktop Search\en-us\msnlExtRes.dll.mui

c:\program files\Windows Desktop Search\msnlExtRes.dll

c:\windows\system32\IEFRAME.dll

.

------------------------ Other Running Processes ------------------------

.

c:\windows\system32\wscntfy.exe

c:\windows\system32\igfxsrvc.exe

.

**************************************************************************

.

Completion time: 2011-07-13 14:35:42 - machine was rebooted

ComboFix-quarantined-files.txt 2011-07-13 12:35

ComboFix2.txt 2011-07-13 11:05

.

Pre-Run: 140,672,847,872 bytes free

Post-Run: 140,581,056,512 bytes free

.

- - End Of File - - 56A9D67D926FE9A0A980FB5110799475

Link to post
Share on other sites

hi

Step 1

mbamicontw5.gif Please download Malwarebytes' Anti-Malware from Here.

Double Click mbam-setup.exe to install the application.

  • Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish,so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected.
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.

Extra Note:

If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process. If asked to restart the computer, please do so immediatly.

Step 2

Please run a free online scan with the ESET Online Scanner

Note: You will need to use Internet Explorer for this scan

  • Tick the box next to YES, I accept the Terms of Use
  • Click Start
  • When asked, allow the ActiveX control to install
  • Click Start
  • Make sure that the options Remove found threats and the option Scan unwanted applications is checked
  • Click Scan (This scan can take several hours, so please be patient)
  • Once the scan is completed, you may close the window
  • Use Notepad to open the logfile located at C:\Program Files\EsetOnlineScanner\log.txt
  • Copy and paste that log as a reply to this topic

Things i would like to see in your reply:

  • Malwarebytes Results.
  • Eset scanner report.
  • Update on how your computer is running

Link to post
Share on other sites

Hi Ali,

Apologies for the delay!!

Here are the 2 logs you required;

mbam log;

Malwarebytes' Anti-Malware 1.51.0.1200

www.malwarebytes.org

Database version: 7112

Windows 5.1.2600 Service Pack 3

Internet Explorer 7.0.5730.13

13/07/2011 16:00:22

mbam-log-2011-07-13 (16-00-22).txt

Scan type: Quick scan

Objects scanned: 178585

Time elapsed: 2 minute(s), 14 second(s)

Memory Processes Infected: 0

Memory Modules Infected: 0

Registry Keys Infected: 0

Registry Values Infected: 0

Registry Data Items Infected: 0

Folders Infected: 0

Files Infected: 0

Memory Processes Infected:

(No malicious items detected)

Memory Modules Infected:

(No malicious items detected)

Registry Keys Infected:

(No malicious items detected)

Registry Values Infected:

(No malicious items detected)

Registry Data Items Infected:

(No malicious items detected)

Folders Infected:

(No malicious items detected)

Files Infected:

(No malicious items detected)

The ESET log;

ESETSmartInstaller@High as downloader log:

all ok

# version=7

# OnlineScannerApp.exe=1.0.0.1

# OnlineScanner.ocx=1.0.0.6427

# api_version=3.0.2

# EOSSerial=37c36f419ee4c643886163ceb72161bf

# end=finished

# remove_checked=true

# archives_checked=false

# unwanted_checked=true

# unsafe_checked=false

# antistealth_checked=true

# utc_time=2011-07-04 08:41:03

# local_time=2011-07-04 10:41:03 (+0100, W. Europe Daylight Time)

# country="United Kingdom"

# lang=1033

# osver=5.1.2600 NT Service Pack 3

# compatibility_mode=1024 16777175 100 0 233379 233379 0 0

# compatibility_mode=2560 16777215 100 0 0 0 0 0

# compatibility_mode=8192 67108863 100 0 596 596 0 0

# scanned=44916

# found=44

# cleaned=44

# scan_time=1360

C:\Documents and Settings\WASCP\My Documents\Downloads\AdvancedPCTweaker (1).exe a variant of Win32/Adware.AdvPCTweak application (deleted - quarantined) 00000000000000000000000000000000 C

C:\Documents and Settings\WASCP\My Documents\Downloads\AdvancedPCTweaker (2).exe a variant of Win32/Adware.AdvPCTweak application (deleted - quarantined) 00000000000000000000000000000000 C

C:\Documents and Settings\WASCP\My Documents\Downloads\AdvancedPCTweaker (3).exe a variant of Win32/Adware.AdvPCTweak application (deleted - quarantined) 00000000000000000000000000000000 C

C:\Documents and Settings\WASCP\My Documents\Downloads\AdvancedPCTweaker (4).exe a variant of Win32/Adware.AdvPCTweak application (deleted - quarantined) 00000000000000000000000000000000 C

C:\Documents and Settings\WASCP\My Documents\Downloads\AdvancedPCTweaker (5).exe a variant of Win32/Adware.AdvPCTweak application (deleted - quarantined) 00000000000000000000000000000000 C

C:\Documents and Settings\WASCP\My Documents\Downloads\AdvancedPCTweaker (6).exe a variant of Win32/Adware.AdvPCTweak application (deleted - quarantined) 00000000000000000000000000000000 C

C:\Documents and Settings\WASCP\My Documents\Downloads\AdvancedPCTweaker (7).exe a variant of Win32/Adware.AdvPCTweak application (deleted - quarantined) 00000000000000000000000000000000 C

C:\Documents and Settings\WASCP\My Documents\Downloads\AdvancedPCTweaker (8).exe a variant of Win32/Adware.AdvPCTweak application (deleted - quarantined) 00000000000000000000000000000000 C

C:\Documents and Settings\WASCP\My Documents\Downloads\AdvancedPCTweaker (9).exe a variant of Win32/Adware.AdvPCTweak application (deleted - quarantined) 00000000000000000000000000000000 C

C:\Documents and Settings\WASCP\My Documents\Downloads\AdvancedPCTweaker.exe a variant of Win32/Adware.AdvPCTweak application (deleted - quarantined) 00000000000000000000000000000000 C

C:\Program Files\Advanced PC Tweaker\AdvancedPCTweaker.exe a variant of Win32/Adware.AdvPCTweak application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C

C:\Program Files\AVG\AVG10\Toolbar(2)\Firefox\avg@igeared\chrome\content\html\26_tabswelcome_ie7footer.htm Win32/Ramnit.A virus (cleaned - quarantined) 00000000000000000000000000000000 C

C:\Program Files\AVG\AVG10\Toolbar(2)\Firefox\avg@igeared\chrome\content\html\29_tabswelcome_ie7footer.htm Win32/Ramnit.A virus (cleaned - quarantined) 00000000000000000000000000000000 C

C:\Program Files\AVG\AVG10\Toolbar(2)\Firefox\avg@igeared\chrome\content\html\41_tabswelcome_ie7footer.htm Win32/Ramnit.A virus (cleaned - quarantined) 00000000000000000000000000000000 C

C:\Program Files\AVG\AVG10\Toolbar(2)\Firefox\avg@igeared\chrome\content\html\42_tabswelcome_ie7footer.htm Win32/Ramnit.A virus (cleaned - quarantined) 00000000000000000000000000000000 C

C:\Program Files\AVG\AVG10\Toolbar(2)\Firefox\avg@igeared\chrome\content\html\45_tabswelcome_ie7footer.htm Win32/Ramnit.A virus (cleaned - quarantined) 00000000000000000000000000000000 C

C:\Program Files\AVG\AVG10\Toolbar(2)\Firefox\avg@igeared\chrome\content\html\46_tabswelcome_ie7footer.htm Win32/Ramnit.A virus (cleaned - quarantined) 00000000000000000000000000000000 C

C:\Program Files\AVG\AVG10\Toolbar(2)\Firefox\avg@igeared\chrome\content\html\49_tabswelcome_ie7footer.htm Win32/Ramnit.A virus (cleaned - quarantined) 00000000000000000000000000000000 C

C:\Program Files\AVG\AVG10\Toolbar(2)\Firefox\avg@igeared\chrome\content\html\50_tabswelcome_ie7footer.htm Win32/Ramnit.A virus (cleaned - quarantined) 00000000000000000000000000000000 C

C:\Program Files\AVG\AVG10\Toolbar(2)\Firefox\avg@igeared\chrome\content\html\58_tabswelcome_ie7footer.htm Win32/Ramnit.A virus (cleaned - quarantined) 00000000000000000000000000000000 C

C:\Program Files\AVG\AVG10\Toolbar(2)\Firefox\avg@igeared\chrome\content\html\59_tabswelcome_ie7footer.htm Win32/Ramnit.A virus (cleaned - quarantined) 00000000000000000000000000000000 C

C:\Program Files\AVG\AVG10\Toolbar(2)\Firefox\avg@igeared\chrome\content\html\bubble_general.htm Win32/Ramnit.A virus (cleaned - quarantined) 00000000000000000000000000000000 C

C:\Program Files\AVG\AVG10\Toolbar(2)\Firefox\avg@igeared\chrome\content\html\Facebook_error.htm Win32/Ramnit.A virus (cleaned - quarantined) 00000000000000000000000000000000 C

C:\Program Files\AVG\AVG10\Toolbar(2)\Firefox\avg@igeared\chrome\content\html\Facebook_notifier.htm Win32/Ramnit.A virus (cleaned - quarantined) 00000000000000000000000000000000 C

C:\Program Files\AVG\AVG10\Toolbar(2)\Firefox\avg@igeared\chrome\content\html\Facebook_status.htm Win32/Ramnit.A virus (cleaned - quarantined) 00000000000000000000000000000000 C

C:\Program Files\AVG\AVG10\Toolbar(2)\Firefox\avg@igeared\chrome\content\html\rssreader_simple.htm Win32/Ramnit.A virus (cleaned - quarantined) 00000000000000000000000000000000 C

C:\Program Files\AVG\AVG10\Toolbar(2)\Firefox\avg@igeared\chrome\content\html\ssb_dangerous.html Win32/Ramnit.A virus (cleaned - quarantined) 00000000000000000000000000000000 C

C:\Program Files\AVG\AVG10\Toolbar(2)\Firefox\avg@igeared\chrome\content\html\ssb_questionable.html Win32/Ramnit.A virus (cleaned - quarantined) 00000000000000000000000000000000 C

C:\Program Files\AVG\AVG10\Toolbar(2)\Firefox\avg@igeared\chrome\content\html\ssb_risky.html Win32/Ramnit.A virus (cleaned - quarantined) 00000000000000000000000000000000 C

C:\Program Files\AVG\AVG10\Toolbar(2)\Firefox\avg@igeared\chrome\content\html\ssb_safe.html Win32/Ramnit.A virus (cleaned - quarantined) 00000000000000000000000000000000 C

C:\Program Files\AVG\AVG10\Toolbar(2)\Firefox\avg@igeared\chrome\content\html\ssb_unknown.html Win32/Ramnit.A virus (cleaned - quarantined) 00000000000000000000000000000000 C

C:\Program Files\AVG\AVG10\Toolbar(2)\Firefox\avg@igeared\chrome\content\html\ssb_waiting.html Win32/Ramnit.A virus (cleaned - quarantined) 00000000000000000000000000000000 C

C:\Program Files\AVG\AVG10\Toolbar(2)\Firefox\avg@igeared\chrome\content\html\tabswelcome_ie7footer.htm Win32/Ramnit.A virus (cleaned - quarantined) 00000000000000000000000000000000 C

C:\Program Files\AVG\AVG10\Toolbar(2)\Firefox\avg@igeared\chrome\content\html\weather_error.htm Win32/Ramnit.A virus (cleaned - quarantined) 00000000000000000000000000000000 C

C:\Qoobox\Quarantine\C\Documents and Settings\WASCP\Application Data\139.tmp.vir a variant of Win32/Injector.HFJ trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C

C:\Qoobox\Quarantine\C\Documents and Settings\WASCP\Application Data\13B.tmp.vir a variant of Win32/Injector.HFJ trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C

C:\Qoobox\Quarantine\C\Documents and Settings\WASCP\Application Data\82.tmp.vir a variant of Win32/Injector.HFJ trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C

C:\Qoobox\Quarantine\C\Documents and Settings\WASCP\Application Data\84.tmp.vir a variant of Win32/Injector.HFJ trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C

C:\Qoobox\Quarantine\C\Documents and Settings\WASCP\Application Data\8C.tmp.vir a variant of Win32/Injector.HIY trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C

C:\Qoobox\Quarantine\C\Documents and Settings\WASCP\Application Data\90.tmp.vir a variant of Win32/Injector.HIY trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C

C:\Qoobox\Quarantine\C\Documents and Settings\WASCP\Application Data\96.tmp.vir a variant of Win32/Injector.HIY trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C

C:\Qoobox\Quarantine\C\Documents and Settings\WASCP\Application Data\98.tmp.vir a variant of Win32/Injector.HIY trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C

C:\Qoobox\Quarantine\C\Documents and Settings\WASCP\Application Data\AF.tmp.vir a variant of Win32/Injector.HFJ trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C

C:\Qoobox\Quarantine\C\Documents and Settings\WASCP\Application Data\B9.tmp.vir a variant of Win32/Injector.HIY trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C

ESETSmartInstaller@High as downloader log:

all ok

ESETSmartInstaller@High as downloader log:

all ok

ESETSmartInstaller@High as downloader log:

all ok

esets_scanner_update returned -1 esets_gle=53251

# version=7

# OnlineScannerApp.exe=1.0.0.1

# OnlineScanner.ocx=1.0.0.6528

# api_version=3.0.2

# EOSSerial=37c36f419ee4c643886163ceb72161bf

# end=stopped

# remove_checked=true

# archives_checked=false

# unwanted_checked=true

# unsafe_checked=false

# antistealth_checked=true

# utc_time=2011-07-14 08:29:21

# local_time=2011-07-14 10:29:21 (+0100, W. Europe Daylight Time)

# country="United Kingdom"

# lang=1033

# osver=5.1.2600 NT Service Pack 3

# compatibility_mode=1024 16777215 100 0 1097109 1097109 0 0

# compatibility_mode=8192 67108863 100 0 864326 864326 0 0

# scanned=39778

# found=0

# cleaned=0

# scan_time=929

Link to post
Share on other sites

Hi Ali,

Sorted the problem with the isdi.dll fault by upgrading Intel Rapid storage technology driver from the Intel download centre.

The error message has gone and the machine is much faster!!

I will carry on using the machine checking for freezes!!

Link to post
Share on other sites

Guest
This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.

Back to top
×
×
  • Create New...

Important Information

This site uses cookies - We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.