Malwarebytes log:
Malwarebytes Anti-Malware (Trial) 1.65.1.1000
www.malwarebytes.org
Database version: v2012.11.07.03
Windows XP Service Pack 3 x86 NTFS
Internet Explorer 7.0.5730.13
Owner :: OWNER-NUA4EKA61 [administrator]
Protection: Disabled
11/07/2012 3:42:25 AM
mbam-log-2012-11-07 (04-40-14).txt
Scan type: Quick scan
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
Scan options disabled: P2P
Objects scanned: 210013
Time elapsed: 57 minute(s), 16 second(s)
Memory Processes Detected: 0
(No malicious items detected)
Memory Modules Detected: 0
(No malicious items detected)
Registry Keys Detected: 10
HKCR\AppID\{186E19A3-B909-4F48-B687-BB81EB8BC7CE} (Trojan.BHO) -> No action taken.
HKCR\Typelib\{1D085C0A-E4F4-4F66-BDBF-4BE51015BFC3} (PUP.Funmoods) -> No action taken.
HKCR\Interface\{0D80F1C5-D17B-4177-AC68-955F3EF9F191} (PUP.Funmoods) -> No action taken.
HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{517E0D3E-17A4-4592-926E-A082DB43B7D3} (PUP.FaceTheme) -> No action taken.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{517E0D3E-17A4-4592-926E-A082DB43B7D3} (PUP.FaceTheme) -> No action taken.
HKCU\SOFTWARE\Fun Web Products (PUP.MyWebSearch) -> No action taken.
HKCU\Software\Google\Chrome\Extensions\bbjciahceamgodcoidkjpchnokgfpphh (PUP.Funmoods) -> No action taken.
HKLM\SOFTWARE\Google\Chrome\Extensions\bbjciahceamgodcoidkjpchnokgfpphh (PUP.Funmoods) -> No action taken.
HKLM\SOFTWARE\Google\Chrome\Extensions\kincjchfokkeneeofpeefomkikfkiedl (PUP.FCTPlugin) -> No action taken.
HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\RunDll32Policy\f3ScrCtr.dll (PUP.MyWebSearch) -> No action taken.
Registry Values Detected: 0
(No malicious items detected)
Registry Data Items Detected: 0
(No malicious items detected)
Folders Detected: 1
D:\Documents and Settings\Owner\Application Data\hellomoto (Trojan.Ransom.FGen) -> No action taken.
Files Detected: 2
D:\Documents and Settings\Owner\Application Data\hellomoto\TujP.dat (Trojan.Ransom.FGen) -> No action taken.
D:\Documents and Settings\Owner\Application Data\hellomoto\BukF.dat (Trojan.Ransom.FGen) -> No action taken.
(end)
__________________________________________________________________________________________________________________
Superantispyware Log:
SUPERAntiSpyware Scan Log
http://www.superantispyware.com
Generated 11/07/2012 at 05:42 AM
Application Version : 5.6.1014
Core Rules Database Version : 9542
Trace Rules Database Version: 7354
Scan type : Quick Scan
Total Scan Time : 00:48:40
Operating System Information
Windows XP Home Edition 32-bit, Service Pack 3 (Build 5.01.2600)
Administrator
Memory items scanned : 361
Memory threats detected : 0
Registry items scanned : 31545
Registry threats detected : 0
File items scanned : 6262
File threats detected : 2
Adware.Tracking Cookie
D:\Documents and Settings\Owner\Cookies\VVIG8QXZ.txt [ /ads.pubmatic.com ]
D:\Documents and Settings\Owner\Cookies\A1ONSRSH.txt [ /invitemedia.com ]
______________________________________________________________________________________________________________________________
Eset Log:
D:\Documents and Settings\Owner\Local Settings\Application Data\chromeupdate.crx JS/Redirector.NCG trojan deleted - quarantined
D:\Qoobox\Quarantine\D\DOCUME~1\Owner\LOCALS~1\Temp\NODEE3E.tmp.vir a variant of Win32/Medfos.DY trojan cleaned by deleting - quarantined
D:\Qoobox\Quarantine\D\RECYCLER\S-1-5-21-1229272821-436374069-839522115-1003\$01ce833422ee1c056e2e42e8fe3697a9\n.vir Win32/Sirefef.EV trojan cleaned by deleting - quarantined
D:\System Volume Information\_restore{E56F58A2-2BDA-45D7-AF87-7C6656A19FC4}\RP1140\A0081052.dll a variant of Win32/Adware.Facetheme.E application cleaned by deleting - quarantined
D:\System Volume Information\_restore{E56F58A2-2BDA-45D7-AF87-7C6656A19FC4}\RP1150\A0082838.ini Win32/Sirefef.EZ trojan cleaned by deleting - quarantined
_______________________________________________________________________________________________________________________________________
Minitoolbox Log:
MiniToolBox by Farbar Version: 07-11-2012
Ran by Owner (administrator) on 07-11-2012 at 18:50:17
Microsoft Windows XP Home Edition Service Pack 3 (X86)
Boot Mode: Normal
***************************************************************************
========================= IE Proxy Settings: ==============================
Proxy is not enabled.
No Proxy Server is set.
========================= FF Proxy Settings: ==============================
========================= Hosts content: =================================
127.0.0.1 localhost
========================= IP Configuration: ================================
NVIDIA nForce Networking Controller = Local Area Connection (Connected)
# ----------------------------------
# Interface IP Configuration
# ----------------------------------
pushd interface ip
# Interface IP Configuration for "Local Area Connection"
set address name="Local Area Connection" source=dhcp
set dns name="Local Area Connection" source=dhcp register=PRIMARY
set wins name="Local Area Connection" source=dhcp
popd
# End of interface IP configuration
Windows IP Configuration
Host Name . . . . . . . . . . . . : owner-nua4eka61
Primary Dns Suffix . . . . . . . :
Node Type . . . . . . . . . . . . : Unknown
IP Routing Enabled. . . . . . . . : No
WINS Proxy Enabled. . . . . . . . : No
DNS Suffix Search List. . . . . . : hsd1.ga.comcast.net.
Ethernet adapter Local Area Connection:
Connection-specific DNS Suffix . : hsd1.ga.comcast.net.
Description . . . . . . . . . . . : NVIDIA nForce Networking Controller
Physical Address. . . . . . . . . : 00-18-F3-A6-28-D4
Dhcp Enabled. . . . . . . . . . . : Yes
Autoconfiguration Enabled . . . . : Yes
IP Address. . . . . . . . . . . . : 98.251.117.225
Subnet Mask . . . . . . . . . . . : 255.255.255.0
Default Gateway . . . . . . . . . : 98.251.117.1
DHCP Server . . . . . . . . . . . : 69.252.196.132
DNS Servers . . . . . . . . . . . : 75.75.75.75
75.75.76.76
Lease Obtained. . . . . . . . . . : Wednesday, November 07, 2012 4:49:34 AM
Lease Expires . . . . . . . . . . : Friday, November 09, 2012 9:52:14 PM
Server: cdns01.comcast.net
Address: 75.75.75.75
Name: google.com
Addresses: 74.125.137.113, 74.125.137.139, 74.125.137.101, 74.125.137.100
74.125.137.102, 74.125.137.138
Pinging google.com [74.125.139.139] with 32 bytes of data:
Reply from 74.125.139.139: bytes=32 time=12ms TTL=48
Reply from 74.125.139.139: bytes=32 time=12ms TTL=48
Ping statistics for 74.125.139.139:
Packets: Sent = 2, Received = 2, Lost = 0 (0% loss),
Approximate round trip times in milli-seconds:
Minimum = 12ms, Maximum = 12ms, Average = 12ms
Server: cdns01.comcast.net
Address: 75.75.75.75
Name: yahoo.com
Addresses: 72.30.38.140, 98.139.183.24, 98.138.253.109
Pinging yahoo.com [98.139.183.24] with 32 bytes of data:
Reply from 98.139.183.24: bytes=32 time=119ms TTL=49
Reply from 98.139.183.24: bytes=32 time=82ms TTL=51
Ping statistics for 98.139.183.24:
Packets: Sent = 2, Received = 2, Lost = 0 (0% loss),
Approximate round trip times in milli-seconds:
Minimum = 82ms, Maximum = 119ms, Average = 100ms
Server: cdns01.comcast.net
Address: 75.75.75.75
Name: bleepingcomputer.com
Address: 208.43.87.2
Pinging bleepingcomputer.com [208.43.87.2] with 32 bytes of data:
Reply from 208.43.87.2: Destination host unreachable.
Reply from 208.43.87.2: Destination host unreachable.
Ping statistics for 208.43.87.2:
Packets: Sent = 2, Received = 2, Lost = 0 (0% loss),
Approximate round trip times in milli-seconds:
Minimum = 0ms, Maximum = 0ms, Average = 0ms
Pinging 127.0.0.1 with 32 bytes of data:
Reply from 127.0.0.1: bytes=32 time<1ms TTL=128
Reply from 127.0.0.1: bytes=32 time<1ms TTL=128
Ping statistics for 127.0.0.1:
Packets: Sent = 2, Received = 2, Lost = 0 (0% loss),
Approximate round trip times in milli-seconds:
Minimum = 0ms, Maximum = 0ms, Average = 0ms
===========================================================================
Interface List
0x1 ........................... MS TCP Loopback interface
0x2 ...00 18 f3 a6 28 d4 ...... NVIDIA nForce Networking Controller
===========================================================================
===========================================================================
Active Routes:
Network Destination Netmask Gateway Interface Metric
0.0.0.0 0.0.0.0 98.251.117.1 98.251.117.225 20
98.251.117.0 255.255.255.0 98.251.117.225 98.251.117.225 20
98.251.117.225 255.255.255.255 127.0.0.1 127.0.0.1 20
98.255.255.255 255.255.255.255 98.251.117.225 98.251.117.225 20
127.0.0.0 255.0.0.0 127.0.0.1 127.0.0.1 1
169.254.0.0 255.255.0.0 98.251.117.225 98.251.117.225 20
224.0.0.0 240.0.0.0 98.251.117.225 98.251.117.225 20
255.255.255.255 255.255.255.255 98.251.117.225 98.251.117.225 1
Default Gateway: 98.251.117.1
===========================================================================
Persistent Routes:
None
========================= Winsock entries =====================================
Catalog5 01 D:\Windows\System32\mswsock.dll [245248] (Microsoft Corporation)
Catalog5 02 D:\Windows\System32\winrnr.dll [16896] (Microsoft Corporation)
Catalog5 03 D:\Windows\System32\mswsock.dll [245248] (Microsoft Corporation)
Catalog5 04 D:\Program Files\Bonjour\mdnsNSP.dll [121704] (Apple Inc.)
Catalog9 01 D:\Windows\system32\mswsock.dll [245248] (Microsoft Corporation)
Catalog9 02 D:\Windows\system32\mswsock.dll [245248] (Microsoft Corporation)
Catalog9 03 D:\Windows\system32\mswsock.dll [245248] (Microsoft Corporation)
Catalog9 04 D:\Windows\system32\mswsock.dll [245248] (Microsoft Corporation)
Catalog9 05 D:\Windows\system32\mswsock.dll [245248] (Microsoft Corporation)
Catalog9 06 D:\Windows\system32\mswsock.dll [245248] (Microsoft Corporation)
Catalog9 07 D:\Windows\system32\mswsock.dll [245248] (Microsoft Corporation)
Catalog9 08 D:\Windows\system32\mswsock.dll [245248] (Microsoft Corporation)
Catalog9 09 D:\Windows\system32\mswsock.dll [245248] (Microsoft Corporation)
Catalog9 10 D:\Windows\system32\mswsock.dll [245248] (Microsoft Corporation)
Catalog9 11 D:\Windows\system32\mswsock.dll [245248] (Microsoft Corporation)
Catalog9 12 D:\Windows\system32\mswsock.dll [245248] (Microsoft Corporation)
Catalog9 13 D:\Windows\system32\mswsock.dll [245248] (Microsoft Corporation)
Catalog9 14 D:\Windows\system32\rsvpsp.dll [92672] (Microsoft Corporation)
Catalog9 15 D:\Windows\system32\rsvpsp.dll [92672] (Microsoft Corporation)
========================= Event log errors: ===============================
Application errors:
==================
Error: (11/07/2012 05:32:03 AM) (Source: ESENT) (User: )
Description: Catalog Database (824) Database D:\WINDOWS\system32\CatRoot2\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\catdb was partially detached. Error -1032 encountered updating database headers.
Error: (11/07/2012 05:32:03 AM) (Source: ESENT) (User: )
Description: Catalog Database (824) Unable to write a shadowed header for file D:\WINDOWS\system32\CatRoot2\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\catdb. Error -1032.
Error: (11/07/2012 05:32:03 AM) (Source: ESENT) (User: )
Description: svchost (824) An attempt to open the file "D:\WINDOWS\system32\CatRoot2\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\catdb" for read / write access failed with system error 32 (0x00000020): "The process cannot access the file because it is being used by another process. ". The open file operation will fail with error -1032 (0xfffffbf8).
Error: (10/31/2012 11:19:09 PM) (Source: MsiInstaller) (User: OWNER-NUA4EKA61)
Description: Product: Avatar - Legends of The Arena -- Error 1606.Could not access network location :.
Error: (10/31/2012 11:19:08 PM) (Source: MsiInstaller) (User: OWNER-NUA4EKA61)
Description: Product: Avatar - Legends of The Arena -- Error 1606.Could not access network location :.
Error: (10/31/2012 10:58:44 PM) (Source: ESENT) (User: )
Description: svchost (840) An attempt to open the file "D:\WINDOWS\system32\CatRoot2\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\catdb" for read / write access failed with system error 32 (0x00000020): "The process cannot access the file because it is being used by another process. ". The open file operation will fail with error -1032 (0xfffffbf8).
Error: (10/31/2012 10:56:45 PM) (Source: MsiInstaller) (User: OWNER-NUA4EKA61)
Description: Product: Java 6 Update 15 -- Error 1606.Could not access network location :.
Error: (10/31/2012 10:56:44 PM) (Source: MsiInstaller) (User: OWNER-NUA4EKA61)
Description: Product: Java 6 Update 15 -- Error 1606.Could not access network location :.
Error: (10/31/2012 10:56:41 PM) (Source: MsiInstaller) (User: OWNER-NUA4EKA61)
Description: Product: Java 6 Update 15 -- Error 1606.Could not access network location :.
Error: (10/30/2012 09:57:21 PM) (Source: Bonjour Service) (User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 30652250
System errors:
=============
Error: (11/07/2012 04:49:44 AM) (Source: 0) (User: )
Description: 0xC0000001HarddiskVolume2
Error: (11/07/2012 02:14:07 AM) (Source: DCOM) (User: OWNER-NUA4EKA61)
Description: The server {2692A9D5-61DF-46D5-A5A1-A6CCA921D578} did not register with DCOM within the required timeout.
Error: (10/31/2012 11:22:15 PM) (Source: Service Control Manager) (User: )
Description: The Application Management service terminated with the following error:
%%126
Error: (10/31/2012 11:22:15 PM) (Source: Service Control Manager) (User: )
Description: The Application Management service terminated with the following error:
%%126
Error: (10/31/2012 11:22:15 PM) (Source: Service Control Manager) (User: )
Description: The Application Management service terminated with the following error:
%%126
Error: (10/31/2012 11:22:15 PM) (Source: Service Control Manager) (User: )
Description: The Application Management service terminated with the following error:
%%126
Error: (10/31/2012 11:22:15 PM) (Source: Service Control Manager) (User: )
Description: The Application Management service terminated with the following error:
%%126
Error: (10/31/2012 11:22:14 PM) (Source: Service Control Manager) (User: )
Description: The Application Management service terminated with the following error:
%%126
Error: (10/31/2012 11:22:14 PM) (Source: Service Control Manager) (User: )
Description: The Application Management service terminated with the following error:
%%126
Error: (10/31/2012 11:22:14 PM) (Source: Service Control Manager) (User: )
Description: The Application Management service terminated with the following error:
%%126
Microsoft Office Sessions:
=========================
Error: (11/07/2012 05:32:03 AM) (Source: ESENT)(User: )
Description: Catalog Database824D:\WINDOWS\system32\CatRoot2\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\catdb-1032
Error: (11/07/2012 05:32:03 AM) (Source: ESENT)(User: )
Description: Catalog Database824D:\WINDOWS\system32\CatRoot2\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\catdb-1032
Error: (11/07/2012 05:32:03 AM) (Source: ESENT)(User: )
Description: svchost824D:\WINDOWS\system32\CatRoot2\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\catdb-1032 (0xfffffbf8)32 (0x00000020)The process cannot access the file because it is being used by another process.
Error: (10/31/2012 11:19:09 PM) (Source: MsiInstaller)(User: OWNER-NUA4EKA61)
Description: Product: Avatar - Legends of The Arena -- Error 1606.Could not access network location :.(NULL)(NULL)(NULL)
Error: (10/31/2012 11:19:08 PM) (Source: MsiInstaller)(User: OWNER-NUA4EKA61)
Description: Product: Avatar - Legends of The Arena -- Error 1606.Could not access network location :.(NULL)(NULL)(NULL)
Error: (10/31/2012 10:58:44 PM) (Source: ESENT)(User: )
Description: svchost840D:\WINDOWS\system32\CatRoot2\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\catdb-1032 (0xfffffbf8)32 (0x00000020)The process cannot access the file because it is being used by another process.
Error: (10/31/2012 10:56:45 PM) (Source: MsiInstaller)(User: OWNER-NUA4EKA61)
Description: Product: Java 6 Update 15 -- Error 1606.Could not access network location :.(NULL)(NULL)(NULL)
Error: (10/31/2012 10:56:44 PM) (Source: MsiInstaller)(User: OWNER-NUA4EKA61)
Description: Product: Java 6 Update 15 -- Error 1606.Could not access network location :.(NULL)(NULL)(NULL)
Error: (10/31/2012 10:56:41 PM) (Source: MsiInstaller)(User: OWNER-NUA4EKA61)
Description: Product: Java 6 Update 15 -- Error 1606.Could not access network location :.(NULL)(NULL)(NULL)
Error: (10/30/2012 09:57:21 PM) (Source: Bonjour Service)(User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 30652250
=========================== Installed Programs ============================
Acrobat.com (Version: 1.7.186)
Adobe AIR (Version: 1.5.1.8210)
Adobe Flash Player 10 Plugin (Version: 10.3.181.26)
Adobe Flash Player 11 ActiveX (Version: 11.4.402.278)
Adobe Reader X (10.1.4) (Version: 10.1.4)
Adobe Shockwave Player 11.6 (Version: 11.6.7.637)
Apple Application Support (Version: 2.1.9)
Apple Mobile Device Support (Version: 5.2.0.6)
Apple Software Update (Version: 2.1.3.127)
Avatar - Legends of The Arena (Version: 1.03.0008)
Bonjour (Version: 3.0.0.10)
Compatibility Pack for the 2007 Office system (Version: 12.0.6612.1000)
Data Fax SoftModem with SmartCP
ESET Online Scanner v3
iTunes (Version: 10.6.3.25)
Java Auto Updater (Version: 2.1.6.0)
Java 6 Update 15 (Version: 6.0.150)
Java 7 Update 5 (Version: 7.0.50)
Java SE Runtime Environment 6 Update 1 (Version: 1.6.0.10)
JavaFX 2.1.1 (Version: 2.1.1)
Learn2 Player (Uninstall Only)
Lexmark 2300 Series
Malwarebytes Anti-Malware version 1.65.1.1000 (Version: 1.65.1.1000)
Microsoft Application Error Reporting (Version: 12.0.6012.5000)
Microsoft Choice Guard (Version: 2.0.48.0)
Microsoft Internationalized Domain Names Mitigation APIs
Microsoft National Language Support Downlevel APIs
Microsoft Office File Validation Add-In (Version: 14.0.5130.5003)
Microsoft Office Professional Edition 2003 (Version: 11.0.8173.0)
Microsoft VC9 runtime libraries (Version: 1.0.0)
Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053 (Version: 8.0.50727.4053)
Microsoft Visual C++ 2005 Redistributable (Version: 8.0.56336)
Microsoft Visual C++ 2005 Redistributable (Version: 8.0.61001)
Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148 (Version: 9.0.30729.4148)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (Version: 9.0.30729)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (Version: 9.0.30729.6161)
Mozilla Firefox 16.0.2 (x86 en-US) (Version: 16.0.2)
MSVCRT (Version: 14.0.1468.721)
NVIDIA Drivers
Photo Notifier and Animation Creator (Version: 1.0.0.1009)
QuickTime (Version: 7.72.80.56)
RealPlayer Basic
Realtek High Definition Audio Driver
Segoe UI (Version: 14.0.4327.805)
SUPERAntiSpyware (Version: 5.6.1014)
swMSM (Version: 12.0.0.1)
Unity Web Player (Version: 2.1.0f5_16147)
UnThreat Free AntiVirus Installer (Version: 4.2.33.0)
Update for Windows XP (KB2141007) (Version: 1)
Update for Windows XP (KB2345886) (Version: 1)
Update for Windows XP (KB2467659) (Version: 1)
Update for Windows XP (KB2541763) (Version: 1)
Update for Windows XP (KB2607712) (Version: 1)
Update for Windows XP (KB2616676) (Version: 1)
Update for Windows XP (KB2641690) (Version: 1)
Update for Windows XP (KB2661254-v2) (Version: 2)
Update for Windows XP (KB2718704) (Version: 1)
Update for Windows XP (KB2736233) (Version: 1)
Update for Windows XP (KB2749655) (Version: 1)
Update for Windows XP (KB951072-v2) (Version: 2)
Update for Windows XP (KB951978) (Version: 1)
Update for Windows XP (KB955759) (Version: 1)
Update for Windows XP (KB955839) (Version: 1)
Update for Windows XP (KB961503) (Version: 1)
Update for Windows XP (KB967715) (Version: 1)
Update for Windows XP (KB968389) (Version: 1)
Update for Windows XP (KB971029) (Version: 1)
Update for Windows XP (KB971737) (Version: 1)
Update for Windows XP (KB973687) (Version: 1)
Update for Windows XP (KB973815) (Version: 1)
Viewpoint Media Player
WebFldrs XP (Version: 9.50.5318)
Windows Live Call (Version: 14.0.8117.0416)
Windows Live Communications Platform (Version: 14.0.8117.416)
Windows Live Essentials (Version: 14.0.8117.0416)
Windows Live Essentials (Version: 14.0.8117.416)
Windows Live Messenger (Version: 14.0.8117.0416)
Windows XP Service Pack 3 (Version: 20080414.031525)
========================= Memory info: ===================================
Percentage of memory in use: 71%
Total physical RAM: 446.48 MB
Available physical RAM: 129.41 MB
Total Pagefile: 1053.91 MB
Available Pagefile: 701.31 MB
Total Virtual: 2047.88 MB
Available Virtual: 1974.55 MB
========================= Partitions: =====================================
1 Drive c: (RECOVERY(D)) (Fixed) (Total:7.3 GB) (Free:0.34 GB) FAT32
2 Drive d: () (Fixed) (Total:104.46 GB) (Free:87.42 GB) NTFS
========================= Users: ========================================
User accounts for \\OWNER-NUA4EKA61
Administrator Guest HelpAssistant
Owner SUPPORT_388945a0
**** End of log ****
___________________________________________________________________________________________________________________________
AdWare Cleaner Log:
# AdwCleaner v2.007 - Logfile created 11/07/2012 at 18:55:04
# Updated 06/11/2012 by Xplode
# Operating system : Microsoft Windows XP Service Pack 3 (32 bits)
# User : Owner - OWNER-NUA4EKA61
# Boot Mode : Normal
# Running from : D:\Documents and Settings\Owner\My Documents\Downloads\adwcleaner.exe
# Option [Delete]
***** [Services] *****
***** [Files / Folders] *****
File Deleted : D:\WINDOWS\system32\conduitEngine.tmp
Folder Deleted : D:\Documents and Settings\All Users\Application Data\Viewpoint
Folder Deleted : D:\Documents and Settings\Owner\Local Settings\Application Data\APN
Folder Deleted : D:\Documents and Settings\Owner\Local Settings\Application Data\Conduit
Folder Deleted : D:\Program Files\Viewpoint
***** [Registry] *****
Key Deleted : HKCU\Software\AppDataLow\Software\IncrediMail_MediaBar_2
Key Deleted : HKCU\Software\FCTB000060231
Key Deleted : HKCU\Software\IM
Key Deleted : HKCU\Software\ImInstaller
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{1CB20BF0-BBAE-40A7-93F4-6435FF3D0411}
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{C04B7D22-5AEC-4561-8F49-27F6269208F6}
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{CF739809-1C6C-47C0-85B9-569DBB141420}
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{CFF4DB9B-135F-47C0-9269-B4C6572FD61A}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{79A765E1-C399-405B-85AF-466F52E918B0}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{1CB20BF0-BBAE-40A7-93F4-6435FF3D0411}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{201F27D4-3704-41D6-89C1-AA35E39143ED}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{3041D03E-FD4B-44E0-B742-2D9B88305F98}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{4B3803EA-5230-4DC3-A7FC-33638F3D3542}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{CCB69577-088B-4004-9ED8-FF5BCC83A039}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{D3D233D5-9F6D-436C-B6C7-E63F77503B30}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{D7E97865-918F-41E4-9CD0-25AB1C574CE8}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{DB35C569-5624-4CFC-8043-E5139F55A073}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{042DA63B-0933-403D-9395-B49307691690}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{1CB20BF0-BBAE-40A7-93F4-6435FF3D0411}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{201F27D4-3704-41D6-89C1-AA35E39143ED}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{3041D03E-FD4B-44E0-B742-2D9B88305F98}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{4B3803EA-5230-4DC3-A7FC-33638F3D3542}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{7B089B94-D1DC-4C6B-87E1-8156E22C1D96}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{8736C681-37A0-40C6-A0F0-4C083409151C}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{CCB69577-088B-4004-9ED8-FF5BCC83A039}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{D3D233D5-9F6D-436C-B6C7-E63F77503B30}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{D7E97865-918F-41E4-9CD0-25AB1C574CE8}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{DB35C569-5624-4CFC-8043-E5139F55A073}
Key Deleted : HKLM\Software\AskBarDis
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{09C554C3-109B-483C-A06B-F14172F1A947}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{4E1E9D45-8BF9-4139-915C-9F83CC3D5921}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{B12E99ED-69BD-437C-86BE-C862B9E5444D}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{D7EE8177-D51E-4F89-92B6-83EA2EC40800}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{EA28B360-05E0-4F93-8150-02891F1D8D3C}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\escort.DLL
Key Deleted : HKLM\SOFTWARE\Classes\AppID\escortApp.DLL
Key Deleted : HKLM\SOFTWARE\Classes\AppID\escortEng.DLL
Key Deleted : HKLM\SOFTWARE\Classes\AppID\escorTlbr.DLL
Key Deleted : HKLM\SOFTWARE\Classes\AxMetaStream.MetaStreamCtl
Key Deleted : HKLM\SOFTWARE\Classes\AxMetaStream.MetaStreamCtl.1
Key Deleted : HKLM\SOFTWARE\Classes\AxMetaStream.MetaStreamCtlSecondary
Key Deleted : HKLM\SOFTWARE\Classes\AxMetaStream.MetaStreamCtlSecondary.1
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{03F998B2-0E00-11D3-A498-00104B6EB52E}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{042DA63B-0933-403D-9395-B49307691690}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{1B00725B-C455-4DE6-BFB6-AD540AD427CD}
Key Deleted : HKLM\SOFTWARE\Classes\Conduit.Engine
Key Deleted : HKLM\SOFTWARE\Classes\escort.escortIEPane
Key Deleted : HKLM\SOFTWARE\Classes\escort.escortIEPane.1
Key Deleted : HKLM\SOFTWARE\Classes\f
Key Deleted : HKLM\SOFTWARE\Classes\funmoods.dskBnd
Key Deleted : HKLM\SOFTWARE\Classes\funmoods.dskBnd.1
Key Deleted : HKLM\SOFTWARE\Classes\funmoods.funmoodsHlpr
Key Deleted : HKLM\SOFTWARE\Classes\funmoods.funmoodsHlpr.1
Key Deleted : HKLM\SOFTWARE\Classes\funmoodsApp.appCore
Key Deleted : HKLM\SOFTWARE\Classes\funmoodsApp.appCore.1
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{23C70BCA-6E23-4A65-AD2E-1389062074F1}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{23D8EEF7-0E13-4000-B9C4-6603C1E912D1}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{295CACB4-51F5-46FD-914E-C72BAAE1B672}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{2CE5C4B9-6DBE-4528-96FA-C9FF38EF1762}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{34C1FDF7-02C1-4F23-B393-F48B16E071D1}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{54291324-7A3D-4F11-B707-3FB6A2C97BD9}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{59C63F11-D4E5-46E7-9B8A-EE158DCA83A8}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{5DA22CBD-0029-4A09-B757-CF0FAFC488ED}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{77A6E7D4-4A83-4A9B-A2A0-EF3B125DC29D}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{C0585B2F-74D7-4734-88DE-6C150C5D4036}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{CA17D76B-F91D-4659-A7FD-A9F7ED375CDD}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{D8242E89-2F81-484A-AE5B-BA8CAD5B7347}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{EF0588D6-1621-4A75-B8BE-F4BC34794136}
Key Deleted : HKLM\SOFTWARE\Classes\Toolbar.CT2724386
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{4E1E9D45-8BF9-4139-915C-9F83CC3D5921}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{9DBB28C1-1925-11D3-A498-00104B6EB52E}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{D7EE8177-D51E-4F89-92B6-83EA2EC40800}
Key Deleted : HKLM\Software\Conduit
Key Deleted : HKLM\SOFTWARE\FCTB000060231
Key Deleted : HKLM\Software\ImInstaller
Key Deleted : HKLM\Software\MetaStream
Key Deleted : HKLM\SOFTWARE\Microsoft\Active Setup\Installed Components\{03F998B2-0E00-11D3-A498-00104B6EB52E}
Key Deleted : HKLM\SOFTWARE\Microsoft\Active Setup\Installed Components\{1B00725B-C455-4DE6-BFB6-AD540AD427CD}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{86D4B82A-ABED-442A-BE86-96357B70F4FE}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\conduitEngine
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\ViewpointMediaPlayer
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\ViewpointMediaPlayer
Key Deleted : HKLM\SOFTWARE\MozillaPlugins\@viewpoint.com/VMP
Key Deleted : HKLM\Software\Viewpoint
Value Deleted : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{4B3803EA-5230-4DC3-A7FC-33638F3D3542}]
Value Deleted : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{D7E97865-918F-41E4-9CD0-25AB1C574CE8}]
***** [Internet Browsers] *****
-\\ Internet Explorer v7.0.5730.13
Replaced : [HKCU\Software\Microsoft\Internet Explorer\Main - Start Page] = hxxp://start.funmoods.com/?f=1&a=adknlg&chnl=adknlg&cd=2XzuyEtN2Y1L1QzutDtDtCzz0FtA0AyCtBzz0DyEyCyB0A0EtN0D0Tzu0CtByDzytN1L2XzutBtFtCtFtCtFtAtCtB&cr=1832659496 --> hxxp://www.google.com
-\\ Mozilla Firefox v16.0.2 (en-US)
Profile name : default
File : D:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\r1nkutwy.default\prefs.js
[OK] File is clean.
*************************
AdwCleaner[R1].txt - [9059 octets] - [07/11/2012 18:54:15]
AdwCleaner[S1].txt - [8605 octets] - [07/11/2012 18:55:04]
########## EOF - D:\AdwCleaner[S1].txt - [8665 octets] ##########
_______________________________________________________________________________________________________________________________
Norman Malware Cleaner:
Norman Malware Cleaner v2.06.01
Copyright © 1990 - 2012, Norman ASA.
Norman Scanner Engine Version: 7.00.12
nvcbin.def: Version: 7.00.1794, Date: 2012/11/07 08:23:42, Variants: 15286090
nvcmacro.def: Version: 0.00.00, Date: 1969/12/31 19:00:00, Variants: 0
Operating System: Windows XP Service Pack 3
Switches: /iagree /cleanrootkit /nomt
Scan started: 2012/11/07 19:58:32
Running pre-scan cleanup routine...
Number of malicious objects found: 0
Number of malicious objects cleaned: 0
Scanning time: 1s
Scanning system for active rootkit activity...
Number of malicious objects found: 0
Number of malicious objects cleaned: 0
Number of malicious files found: 0
Number of malicious files cleaned: 0
Scanning time: 0s
Scanning running processes and process memory...
Number of objects found: 1116
Number of objects scanned: 1116
Number of objects not scanned: 0
Number of malicious memory objects found: 0
Number of malicious objects cleaned: 0
Number of malicious files found: 0
Number of malicious files cleaned: 0
Scanning time: 1m 23s
Scanning system for FakeAV...
Number of malicious objects found: 0
Number of malicious objects cleaned: 0
Number of malicious files found: 0
Number of malicious files cleaned: 0
Scanning time: 0s
Running full scan...
C:\I386\APPS\APP27103\SUPPORT\TOOLS\MSRDPCLI.EXE/noname.cab/instmsia.exe/noname.cab/instmsi.msi/file30: Not scanned: 0x00000001
C:\I386\APPS\APP27103\SUPPORT\TOOLS\MSRDPCLI.EXE/noname.cab/instmsiw.exe/noname.cab/instmsi.msi/file30: Not scanned: 0x00000001
D:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat: Error opening file for read: 0x00000020
D:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG: Error opening file for read: 0x00000020
D:\Documents and Settings\LocalService\NTUSER.DAT: Error opening file for read: 0x00000020
D:\Documents and Settings\LocalService\ntuser.dat.LOG: Error opening file for read: 0x00000020
D:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat: Error opening file for read: 0x00000020
D:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG: Error opening file for read: 0x00000020
D:\Documents and Settings\NetworkService\NTUSER.DAT: Error opening file for read: 0x00000020
D:\Documents and Settings\NetworkService\ntuser.dat.LOG: Error opening file for read: 0x00000020
D:\Documents and Settings\Owner\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat: Error opening file for read: 0x00000020
D:\Documents and Settings\Owner\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG: Error opening file for read: 0x00000020
D:\Documents and Settings\Owner\NTUSER.DAT: Error opening file for read: 0x00000020
D:\Documents and Settings\Owner\ntuser.dat.LOG: Error opening file for read: 0x00000020
D:\WINDOWS\system32\config\default: Error opening file for read: 0x00000020
D:\WINDOWS\system32\config\default.LOG: Error opening file for read: 0x00000020
D:\WINDOWS\system32\config\SAM: Error opening file for read: 0x00000020
D:\WINDOWS\system32\config\SAM.LOG: Error opening file for read: 0x00000020
D:\WINDOWS\system32\config\SECURITY: Error opening file for read: 0x00000020
D:\WINDOWS\system32\config\SECURITY.LOG: Error opening file for read: 0x00000020
D:\WINDOWS\system32\config\software: Error opening file for read: 0x00000020
D:\WINDOWS\system32\config\software.LOG: Error opening file for read: 0x00000020
D:\WINDOWS\system32\config\system: Error opening file for read: 0x00000020
D:\WINDOWS\system32\config\system.LOG: Error opening file for read: 0x00000020
D:\WINDOWS\Temp\Perflib_Perfdata_6dc.dat: Error opening file for read: 0x00000020
Number of files found: 65891
Number of archives unpacked: 10408
Number of objects found: 505010
Number of objects scanned: 504985
Number of objects not scanned: 25
Number of malicious objects found: 0
Number of malicious objects cleaned: 0
Number of malicious files found: 0
Number of malicious files cleaned: 0
Scanning time: 2h 40m 47s
Running post-scan cleanup routine...
Number of malicious objects found: 0
Number of malicious objects cleaned: 0
Scanning time: 1s
Results:
Total number of files found: 65891
Total number of archives unpacked: 10408
Total number of objects found: 506126
Total number of objects scanned: 506101
Total number of objects not scanned: 25
Total number of malicious objects found: 0
Total scanning time: 2h 42m 12s
______________________________________________________________________________________________________________________________________
I don't know if there will be any further instructions from you other than to shoot this dinosaur but for what it's worth, it's running better already. Thank you.