Hi etavares,Thanks for your reply.
As for this;
We apologize for the delay in responding to your request for help.
Thanks anyway, however, an apology isn't necessary, I know you guys get overloaded,from time to time, and it takes awhile to catch up. Besides I'm not one to complain about free help
I know it's not the normal thing to do once you open a topic here, however, things had gotten so bad that I had to do a lot of uninstalling, and defrag my C:\ drive since my original post.
I have now reinstalled Malwarebytes, and SUPERAntiSpyware, both of which I couldn't update until I had ran them in safe mode with networking. I was able to get them to update and run a scan the first time I did that.
But since I did that the first time I haven't been able to get them to update like that again. So whatever EVIL little creature is hiding in my machine is a quick learner.
I noticed in a couple of the MBAM logs that not only was I being blocked from updating, but that the program version and data base had been moved BACK to earlier versions.stopped.
I know the same thing is happening with my COMODO Anti-Virus program too. It will update in safe mode with networking BUT it won't run a scan there. Thwn when I boot back into normal mode my virus database has been reset to 5 Jan, 2010.
Malwarebytes, and SAS have both detected, quarantined, and removed at least one Trojan each, along with a tub full of tracking cookies.
Anyway here are the fresh logs that you asked for.
OTL logfile created on: 11/14/2010 6:10:59 AM - Run 4
OTL by OldTimer - Version 3.2.17.3 Folder = C:\Documents and Settings\ADMIN\Desktop
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.11)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
126.00 Mb Total Physical Memory | 34.00 Mb Available Physical Memory | 27.00% Memory free
3.00 Gb Paging File | 2.00 Gb Available in Paging File | 89.00% Paging File free
Paging file location(s): C:\pagefile.sys 2500 2500 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 51.05 Gb Total Space | 35.77 Gb Free Space | 70.08% Space Free | Partition Type: NTFS
Drive D: | 4.87 Gb Total Space | 0.92 Gb Free Space | 18.87% Space Free | Partition Type: FAT32
Drive E: | 678.41 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS
Computer Name: WENDYS-BOX | User Name: ADMIN | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ========== PRC - [2010/11/14 05:46:05 | 000,575,488 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\ADMIN\Desktop\OTL.exe
PRC - [2010/10/30 19:30:12 | 001,797,880 | ---- | M] () -- C:\Program Files\Comodo\Comodo Internet Security\cfp.exe
PRC - [2010/05/25 19:10:34 | 005,475,403 | ---- | M] () -- C:\Program Files\Vidalia Bundle\Vidalia\vidalia.exe
PRC - [2010/05/17 14:57:18 | 002,162,176 | ---- | M] () -- C:\Program Files\Vidalia Bundle\Tor\tor.exe
PRC - [2010/02/01 00:45:22 | 000,181,248 | ---- | M] () -- C:\Program Files\Vidalia Bundle\Polipo\polipo.exe
PRC - [2009/05/03 04:07:22 | 000,278,264 | ---- | M] (COMODO) -- C:\Program Files\Comodo\SafeSurf\cssurf.exe
PRC - [2009/05/03 04:03:00 | 000,614,136 | ---- | M] () -- C:\Program Files\Comodo\Comodo Internet Security\cmdagent.exe
PRC - [2008/04/14 00:12:19 | 001,033,728 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe
PRC - [2006/01/18 20:53:30 | 000,071,168 | ---- | M] () -- C:\WINDOWS\system32\LxrJD31s.exe
PRC - [2005/03/14 11:05:02 | 000,069,632 | ---- | M] (HP) -- C:\WINDOWS\system32\HPZipm12.exe
PRC - [2002/03/16 05:51:02 | 000,028,672 | ---- | M] () -- C:\WINDOWS\system32\S3apphk.exe
========== Modules (SafeList) ========== MOD - [2010/11/14 05:46:05 | 000,575,488 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\ADMIN\Desktop\OTL.exe
MOD - [2010/08/23 16:12:02 | 001,054,208 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.6028_x-ww_61e65202\comctl32.dll
MOD - [2002/03/16 05:51:02 | 000,045,056 | ---- | M] (S3 Graphics, Inc.) -- C:\WINDOWS\system32\S3appdll.dll
MOD - [2001/11/11 15:41:07 | 000,106,547 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Common Files\SunnComm Shared\msscript.OCX
========== Win32 Services (SafeList) ========== SRV - File not found [Auto | Stopped] -- C:\SANDBOXIE\SbieSvc.exe -- (SbieSvc)
SRV - File not found [On_Demand | Stopped] -- C:\DOCUME~1\ADMIN\LOCALS~1\Temp\ODETJ.exe -- (ODETJ)
SRV - File not found [On_Demand | Stopped] -- C:\WINDOWS\System32\appmgmts.dll -- (AppMgmt)
SRV - [2009/05/03 04:03:00 | 000,614,136 | ---- | M] () [Auto | Running] -- C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe -- (cmdAgent)
SRV - [2006/01/18 20:53:30 | 000,071,168 | ---- | M] () [Auto | Running] -- C:\WINDOWS\System32\LxrJD31s.exe -- (LxrJD31s)
SRV - [2005/03/14 11:05:02 | 000,069,632 | ---- | M] (HP) [Auto | Running] -- C:\WINDOWS\system32\HPZipm12.exe -- (Pml Driver HPZ12)
========== Driver Services (SafeList) ========== DRV - File not found [Kernel | On_Demand | Stopped] -- C:\SANDBOXIE\SbieDrv.sys -- (SbieDrv)
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\WINDOWS\System32\DRIVERS\FREEDOM.SYS -- (Freedom)
DRV - [2010/05/10 18:41:30 | 000,067,656 | ---- | M] (SUPERAdBlocker.com and SUPERAntiSpyware.com) [Kernel | System | Running] -- C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS -- (SASKUTIL)
DRV - [2010/02/17 18:25:48 | 000,012,872 | ---- | M] (SUPERAdBlocker.com and SUPERAntiSpyware.com) [Kernel | System | Running] -- C:\Program Files\SUPERAntiSpyware\sasdifsv.sys -- (SASDIFSV)
DRV - [2009/06/09 02:29:49 | 000,027,136 | ---- | M] (NCH Swift Sound) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\nchssvad.sys -- (NCHSSVAD)
DRV - [2009/06/03 05:45:18 | 000,217,536 | ---- | M] (TrueCrypt Foundation) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\truecrypt.sys -- (truecrypt)
DRV - [2009/05/03 04:03:10 | 000,099,856 | ---- | M] (COMODO) [File_System | System | Running] -- C:\WINDOWS\system32\drivers\cmdguard.sys -- (cmdGuard)
DRV - [2009/05/03 04:03:10 | 000,079,504 | ---- | M] (COMODO) [Kernel | Boot | Running] -- C:\WINDOWS\System32\DRIVERS\inspect.sys -- (Inspect)
DRV - [2009/05/03 04:03:10 | 000,031,504 | ---- | M] (COMODO) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\cmdhlp.sys -- (cmdHlp)
DRV - [2008/04/13 18:56:49 | 000,012,800 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\usb8023.sys -- (USB_RNDIS)
DRV - [2008/04/13 18:45:29 | 000,010,624 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\gameenum.sys -- (gameenum)
DRV - [2006/01/18 20:53:30 | 000,069,824 | ---- | M] () [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\LxrJD31d.sys -- (LxrJD31d)
DRV - [2005/04/13 22:31:30 | 000,239,488 | ---- | M] (Ralink Technology Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\rt2500usb.sys -- (WUSB54GPV4SRV)
DRV - [2004/10/08 01:16:04 | 000,035,840 | ---- | M] (Oak Technology Inc.) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\AFS2K.SYS -- (AFS2K)
DRV - [2004/08/04 05:31:32 | 000,020,992 | ---- | M] (Realtek Semiconductor Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\rtl8139.sys -- (rtl8139) Realtek RTL8139(A/B/C)
DRV - [2003/03/31 20:29:00 | 000,625,537 | ---- | M] (LT) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\ltmdmnt.sys -- (ltmodem5)
DRV - [2002/03/27 01:20:22 | 000,013,780 | ---- | M] (Padus, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\pfc.sys -- (pfc)
DRV - [2002/03/21 05:35:56 | 000,144,860 | ---- | M] (VIA Technologies, Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\trid3dm.sys -- (trid3d)
DRV - [2002/03/19 09:18:26 | 000,187,520 | ---- | M] (Silicon Integrated Systems Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\sisgrp.sys -- (SiS315)
DRV - [2002/03/14 17:25:00 | 000,094,679 | ---- | M] (VERITAS Software, Inc.) [File_System | Auto | Running] -- C:\WINDOWS\system32\dla\tfsnudfa.sys -- (tfsnudfa)
DRV - [2002/03/14 17:25:00 | 000,088,758 | ---- | M] (VERITAS Software, Inc.) [File_System | Auto | Running] -- C:\WINDOWS\system32\dla\tfsnudf.sys -- (tfsnudf)
DRV - [2002/03/14 17:25:00 | 000,052,758 | ---- | M] (VERITAS Software, Inc.) [File_System | Auto | Running] -- C:\WINDOWS\system32\dla\tfsnifs.sys -- (tfsnifs)
DRV - [2002/03/14 17:25:00 | 000,034,743 | ---- | M] (VERITAS Software, Inc.) [File_System | Auto | Running] -- C:\WINDOWS\system32\dla\tfsncofs.sys -- (tfsncofs)
DRV - [2002/03/14 17:25:00 | 000,023,607 | ---- | M] (VERITAS Software, Inc.) [File_System | Auto | Running] -- C:\WINDOWS\system32\dla\tfsnboio.sys -- (tfsnboio)
DRV - [2002/03/14 17:25:00 | 000,013,847 | ---- | M] (VERITAS Software, Inc.) [File_System | Auto | Running] -- C:\WINDOWS\system32\dla\tfsnopio.sys -- (tfsnopio)
DRV - [2002/03/14 17:25:00 | 000,006,327 | ---- | M] (VERITAS Software, Inc.) [File_System | Auto | Running] -- C:\WINDOWS\system32\dla\tfsnpool.sys -- (tfsnpool)
DRV - [2002/03/14 17:25:00 | 000,004,119 | ---- | M] (VERITAS Software, Inc.) [File_System | Auto | Running] -- C:\WINDOWS\system32\dla\tfsndrct.sys -- (tfsndrct)
DRV - [2002/03/14 17:25:00 | 000,002,203 | ---- | M] (VERITAS Software, Inc.) [File_System | Auto | Running] -- C:\WINDOWS\system32\dla\tfsndres.sys -- (tfsndres)
DRV - [2002/03/09 23:53:00 | 000,909,501 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\nv4_mini.sys -- (nv)
DRV - [2002/02/15 17:21:00 | 000,078,048 | ---- | M] (VERITAS Software, Inc.) [Kernel | Boot | Running] -- C:\WINDOWS\system32\drivers\drvmcdb.sys -- (drvmcdb)
DRV - [2002/02/12 16:56:00 | 000,040,096 | ---- | M] (VERITAS Software, Inc.) [File_System | Auto | Running] -- C:\WINDOWS\system32\drivers\drvnddm.sys -- (drvnddm)
DRV - [2002/01/29 07:04:04 | 000,005,589 | ---- | M] (VERITAS Software, Inc.) [File_System | System | Running] -- C:\WINDOWS\system32\drivers\sscdbhk5.sys -- (sscdbhk5)
DRV - [2002/01/29 07:03:18 | 000,022,963 | ---- | M] (VERITAS Software, Inc.) [File_System | System | Running] -- C:\WINDOWS\system32\drivers\ssrtln.sys -- (ssrtln)
DRV - [2001/12/27 10:52:58 | 000,027,136 | ---- | M] (Silicon Integrated Systems Corporation) [Kernel | Boot | Running] -- C:\WINDOWS\System32\DRIVERS\SISAGP.sys -- (SISAGP)
DRV - [2001/12/08 04:26:00 | 000,013,502 | ---- | M] (NVIDIA Corporation) [Kernel | Boot | Running] -- C:\WINDOWS\System32\DRIVERS\nv_agp.sys -- (nv_agp)
DRV - [2001/08/18 04:00:04 | 000,002,944 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\msmpu401.sys -- (ms_mpu401)
DRV - [2001/08/17 19:50:26 | 000,731,648 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\nv4.sys -- (nv4)
DRV - [2001/08/08 20:13:36 | 000,158,140 | ---- | M] (Intel® Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\i81xnt5.sys -- (i81x)
DRV - [2001/08/08 20:13:30 | 000,012,479 | ---- | M] (Intel® Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\wADV01nt.sys -- (iAimFP0)
DRV - [2001/08/08 20:13:30 | 000,012,031 | ---- | M] (Intel® Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\wADV02NT.sys -- (iAimFP1)
DRV - [2001/08/08 20:13:30 | 000,011,679 | ---- | M] (Intel® Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\wADV05NT.sys -- (iAimFP2)
DRV - [2001/08/08 20:13:28 | 000,019,359 | ---- | M] (Intel® Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\wVchNTxx.sys -- (iAimFP4)
DRV - [2001/08/08 20:13:28 | 000,011,999 | ---- | M] (Intel® Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\wSiINTxx.sys -- (iAimFP3)
DRV - [2001/08/08 20:13:26 | 000,033,503 | ---- | M] (Intel® Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\wATV04nt.sys -- (iAimTV3)
DRV - [2001/08/08 20:13:24 | 000,029,215 | ---- | M] (Intel® Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\wATV01nt.sys -- (iAimTV0)
DRV - [2001/08/08 20:13:24 | 000,023,519 | ---- | M] (Intel® Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\wCh7xxNT.sys -- (iAimTV4)
DRV - [2001/08/08 20:13:24 | 000,019,199 | ---- | M] (Intel® Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\wATV02NT.sys -- (iAimTV1)
DRV - [2001/06/19 14:20:14 | 000,037,408 | ---- | M] () [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\SbcpHid.sys -- (SbcpHid)
DRV - [2001/06/04 20:00:00 | 000,014,112 | ---- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\PS2.sys -- (Ps2)
========== Standard Registry (SafeList) ========== ========== Internet Explorer ========== IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-2647865256-2038945071-357464061-1008\SOFTWARE\Microsoft\Internet Explorer\Main,SearchDefaultBranded = 1
IE - HKU\S-1-5-21-2647865256-2038945071-357464061-1008\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultName = Live Search
IE - HKU\S-1-5-21-2647865256-2038945071-357464061-1008\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultURL =
http://search.live.com/results.aspx?q={searchTerms}&src={referrer:source?}IE - HKU\S-1-5-21-2647865256-2038945071-357464061-1008\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://my.att.net/IE - HKU\S-1-5-21-2647865256-2038945071-357464061-1008\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 1
IE - HKU\S-1-5-21-2647865256-2038945071-357464061-1008\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = ftp=localhost:8118;http=localhost:8118;https=localhost:8118;socks=localhost:9050
========== FireFox ========== FF - prefs.js..browser.search.selectedEngine: "Google"
FF - prefs.js..browser.search.suggest.enabled: false
FF - prefs.js..browser.startup.homepage: "
http://my.att.net/"FF - prefs.js..extensions.enabledItems: toolbar@duckduckgo.com:1.2.0
FF - prefs.js..extensions.enabledItems: {a7c6cf7f-112c-4500-a7ea-39801a327e5f}:1.0.4
FF - prefs.js..extensions.enabledItems: jqs@sun.com:1.0
FF - prefs.js..extensions.enabledItems: {e0204bd5-9d31-402b-a99d-a6aa8ffebdca}:1.2.1
FF - prefs.js..network.proxy.http: "127.0.0.1"
FF - prefs.js..network.proxy.http_port: 8118
FF - prefs.js..network.proxy.socks: "127.0.0.1"
FF - prefs.js..network.proxy.socks_port: 9050
FF - prefs.js..network.proxy.socks_remote_dns: true
FF - prefs.js..network.proxy.ssl: "127.0.0.1"
FF - prefs.js..network.proxy.ssl_port: 8118
FF - prefs.js..network.proxy.type: 1
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.12\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010/11/08 10:53:10 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.12\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010/10/29 07:09:01 | 000,000,000 | ---D | M]
[2009/05/10 05:46:51 | 000,000,000 | ---D | M] -- C:\Documents and Settings\ADMIN\Application Data\Mozilla\Extensions
[2009/05/03 04:07:03 | 000,000,000 | ---D | M] -- C:\Documents and Settings\ADMIN\Application Data\Mozilla\Firefox\extensions
[2009/05/03 04:07:05 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\ADMIN\Application Data\Mozilla\Firefox\extensions\{E9A1DEE0-C623-4439-8932-001E7D17607D}
[2009/07/27 21:16:33 | 000,000,000 | ---D | M] -- C:\Documents and Settings\ADMIN\Application Data\Mozilla\Firefox\Profiles\6j74vj6s.default\extensions
[2009/06/06 20:14:18 | 000,000,000 | ---D | M] (FireFTP) -- C:\Documents and Settings\ADMIN\Application Data\Mozilla\Firefox\Profiles\6j74vj6s.default\extensions\{a7c6cf7f-112c-4500-a7ea-39801a327e5f}
[2009/05/10 07:47:22 | 000,000,000 | ---D | M] (Torbutton) -- C:\Documents and Settings\ADMIN\Application Data\Mozilla\Firefox\Profiles\6j74vj6s.default\extensions\{e0204bd5-9d31-402b-a99d-a6aa8ffebdca}
[2009/05/21 00:29:18 | 000,000,000 | ---D | M] -- C:\Documents and Settings\ADMIN\Application Data\Mozilla\Firefox\Profiles\6j74vj6s.default\extensions\toolbar@duckduckgo.com
[2010/11/14 03:36:42 | 000,000,000 | ---D | M] -- C:\Documents and Settings\ADMIN\Application Data\Mozilla\Firefox\Profiles\udeoiorw.ADMIN\extensions
[2010/11/11 04:36:19 | 000,000,000 | ---D | M] (Flagfox) -- C:\Documents and Settings\ADMIN\Application Data\Mozilla\Firefox\Profiles\udeoiorw.ADMIN\extensions\{1018e4d6-728f-4b20-ad56-37578a4de76b}
[2009/11/02 09:57:58 | 000,000,000 | ---D | M] (Dr.Web anti-virus link checker) -- C:\Documents and Settings\ADMIN\Application Data\Mozilla\Firefox\Profiles\udeoiorw.ADMIN\extensions\{6614d11d-d21d-b211-ae23-815234e1ebb5}
[2010/02/24 00:26:11 | 000,000,000 | ---D | M] (CookieCuller) -- C:\Documents and Settings\ADMIN\Application Data\Mozilla\Firefox\Profiles\udeoiorw.ADMIN\extensions\{99B98C2C-7274-45a3-A640-D9DF1A1C8460}
[2010/11/08 01:44:44 | 000,000,000 | ---D | M] (FireFTP) -- C:\Documents and Settings\ADMIN\Application Data\Mozilla\Firefox\Profiles\udeoiorw.ADMIN\extensions\{a7c6cf7f-112c-4500-a7ea-39801a327e5f}
[2010/11/11 04:36:25 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\ADMIN\Application Data\Mozilla\Firefox\Profiles\udeoiorw.ADMIN\extensions\{AE93811A-5C9A-4d34-8462-F7B864FC4696}
[2010/11/01 04:55:21 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\ADMIN\Application Data\Mozilla\Firefox\Profiles\udeoiorw.ADMIN\extensions\{e001c731-5e37-4538-a5cb-8168736a2360}
[2010/11/07 23:58:27 | 000,000,000 | ---D | M] (Torbutton) -- C:\Documents and Settings\ADMIN\Application Data\Mozilla\Firefox\Profiles\udeoiorw.ADMIN\extensions\{e0204bd5-9d31-402b-a99d-a6aa8ffebdca}
[2010/11/11 04:36:23 | 000,000,000 | ---D | M] (Download Manager Tweak) -- C:\Documents and Settings\ADMIN\Application Data\Mozilla\Firefox\Profiles\udeoiorw.ADMIN\extensions\{F8A55C97-3DB6-4961-A81D-0DE0080E53CB}
[2009/07/22 06:33:04 | 000,000,000 | ---D | M] -- C:\Documents and Settings\ADMIN\Application Data\Mozilla\Firefox\Profiles\udeoiorw.ADMIN\extensions\toolbar@duckduckgo.com
[2010/11/14 03:36:42 | 000,000,000 | ---D | M] -- C:\Program Files\Mozilla Firefox\extensions
[2010/10/22 05:35:59 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}
[2009/05/03 05:30:04 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions\{e0204bd5-9d31-402b-a99d-a6aa8ffebdca}
[2010/09/15 03:50:38 | 000,472,808 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\Mozilla Firefox\plugins\npdeployJava1.dll
[2006/06/17 13:11:43 | 000,090,112 | ---- | M] () -- C:\Program Files\Mozilla Firefox\plugins\NpPopup.dll
O1 HOSTS File: ([2010/03/01 17:33:31 | 000,000,789 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - No CLSID value found.
O2 - BHO: (AcroIEHlprObj Class) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx ()
O2 - BHO: (no name) - {201f27d4-3704-41d6-89c1-aa35e39143ed} - No CLSID value found.
O2 - BHO: (MSN Search Toolbar Helper) - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Toolbar Suite\TB\02.05.0001.1119\en-us\msntb.dll File not found
O3 - HKLM\..\Toolbar: (&hp toolkit) - {B2847E28-5D7D-4DEB-8B67-05D28BCF79F5} - C:\hp\EXPLOREBAR\HPTOOLKT.DLL (Hewlett-Packard Company)
O3 - HKLM\..\Toolbar: (MSN Search Toolbar) - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Toolbar Suite\TB\02.05.0001.1119\en-us\msntb.dll File not found
O3 - HKU\S-1-5-21-2647865256-2038945071-357464061-1008\..\Toolbar\ShellBrowser: (no name) - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - No CLSID value found.
O3 - HKU\S-1-5-21-2647865256-2038945071-357464061-1008\..\Toolbar\ShellBrowser: (&hp toolkit) - {B2847E28-5D7D-4DEB-8B67-05D28BCF79F5} - C:\hp\EXPLOREBAR\HPTOOLKT.DLL (Hewlett-Packard Company)
O3 - HKU\S-1-5-21-2647865256-2038945071-357464061-1008\..\Toolbar\WebBrowser: (&hp toolkit) - {B2847E28-5D7D-4DEB-8B67-05D28BCF79F5} - C:\hp\EXPLOREBAR\HPTOOLKT.DLL (Hewlett-Packard Company)
O4 - HKLM..\Run: [COMODO Internet Security] C:\Program Files\Comodo\Comodo Internet Security\cfp.exe ()
O4 - HKLM..\Run: [COMODO SafeSurf] C:\Program Files\COMODO\SafeSurf\cssurf.exe (COMODO)
O4 - HKLM..\Run: [nwiz] C:\WINDOWS\System32\nwiz.exe (NVIDIA Corporation)
O4 - HKLM..\Run: [PreloadApp] c:\hp\drivers\printers\photosmart\hphprld.exe ()
O4 - HKLM..\Run: [PS2] C:\WINDOWS\system32\ps2.EXE (Hewlett-Packard Company)
O4 - HKLM..\Run: [Recguard] C:\WINDOWS\SMINST\Recguard.exe ()
O4 - HKLM..\Run: [S3apphk] C:\WINDOWS\System32\S3apphk.exe ()
O4 - HKU\S-1-5-21-2647865256-2038945071-357464061-1008..\Run: [Microsoft Works Update Detection] c:\Program Files\Microsoft Works\WkDetect.exe File not found
O4 - HKU\S-1-5-21-2647865256-2038945071-357464061-1008..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe File not found
O4 - HKU\S-1-5-21-2647865256-2038945071-357464061-1008..\Run: [Vidalia] C:\Program Files\Vidalia Bundle\Vidalia\vidalia.exe ()
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\CallWave.lnk = C:\Program Files\CallWave\IAM.exe (CallWave, Inc.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\CallWave.lnk.disabled ()
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Windows Desktop Search.lnk = C:\Program Files\MSN Toolbar Suite\DS\02.05.0001.1119\en-us\bin\WindowsSearch.exe File not found
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoControlPanel = 0
O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-21-2647865256-2038945071-357464061-1008\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-2647865256-2038945071-357464061-1008\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O8 - Extra context menu item: &ieSpell Options - C:\Program Files\ieSpell\iespell.dll (Red Egg Software)
O8 - Extra context menu item: Check &Spelling - C:\Program Files\ieSpell\iespell.dll (Red Egg Software)
O8 - Extra context menu item: ImTranslator - C:\Program Files\Smart Link\ImTranslator for IE\startup.html ()
O8 - Extra context menu item: Lookup on Merriam Webster - C:\Program Files\ieSpell\Merriam Webster.HTM ()
O8 - Extra context menu item: Lookup on Wikipedia - C:\Program Files\ieSpell\wikipedia.HTM ()
O9 - Extra Button: ieSpell - {0E17D5B7-9F5D-4fee-9DF6-CA6EE38B68A8} - C:\Program Files\ieSpell\iespell.dll (Red Egg Software)
O9 - Extra 'Tools' menuitem : ieSpell - {0E17D5B7-9F5D-4fee-9DF6-CA6EE38B68A8} - C:\Program Files\ieSpell\iespell.dll (Red Egg Software)
O9 - Extra 'Tools' menuitem : ieSpell Options - {1606D6F9-9D3B-4aea-A025-ED5B2FD488E7} - C:\Program Files\ieSpell\iespell.dll (Red Egg Software)
O12 - Plugin for: .spop - C:\Program Files\Internet Explorer\PLUGINS\NPDocBox.dll (InterTrust Technologies Corporation, Inc.)
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000}
http://download.macromedia.com/pub/shockwave/cabs/director/sw.cab (Reg Error: Key error.)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700}
http://go.microsoft.com/fwlink/?linkid=39204 (Windows Genuine Advantage Validation Tool)
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE}
http://security.symantec.com/sscv6/SharedContent/vc/bin/AvSniff.cab (Symantec AntiVirus scanner)
O16 - DPF: {33564D57-9980-0010-8000-00AA00389B71}
http://download.microsoft.com/download/D/0/D/D0DD87DA-994F-4334-8B55-AF2E4D98ED0C/wmv9dmo.cab (Reg Error: Key error.)
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5}
http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab (Symantec RuFSI Utility Class)
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5}
http://download.eset.com/special/eos/OnlineScanner.cab (Reg Error: Key error.)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93}
http://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab (Java Plug-in 1.6.0_22)
O16 - DPF: {9191F686-7F0A-441D-8A98-2FE3AC1BD913}
http://acs.pandasoftware.com/activescan/cabs/as2stubie.cab (ActiveScan 2.0 Installer Class)
O16 - DPF: {BB383206-6DA1-4E80-B62A-3DF950FCC697}
http://ak.imgag.com/imgag/cp/install/AxCtp2.cab (Create & Print ActiveX Plug-in)
O16 - DPF: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab (Java Plug-in 1.6.0_22)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab (Java Plug-in 1.6.0_22)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000}
http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab (Shockwave Flash Object)
O16 - DPF: Microsoft XML Parser for Java file://C:\WINDOWS\Java\classes\xmldso.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.254 192.168.1.254
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\!SASWinLogon: DllName - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL (SUPERAntiSpyware.com)
O20 - Winlogon\Notify\igfxcui: DllName - igfxsrvc.dll - C:\WINDOWS\System32\igfxsrvc.dll (Intel Corporation)
O24 - Desktop WallPaper: C:\Documents and Settings\ADMIN\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\ADMIN\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O28 - HKLM ShellExecuteHooks: {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - C:\Program Files\SUPERAntiSpyware\SASSEH.DLL (SuperAdBlocker.com)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2002/04/20 04:16:39 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O32 - AutoRun File - [2009/06/18 06:24:46 | 000,000,000 | ---D | M] - C:\AutoRuns -- [ NTFS ]
O32 - AutoRun File - [2001/07/28 07:07:38 | 000,000,000 | ---- | M] () - D:\AUTOEXEC.BAT -- [ FAT32 ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKU\S-1-5-21-2647865256-2038945071-357464061-1008\...com [@ = comfile] -- Reg Error: Key error. File not found
NetSvcs: 6to4 - File not found
NetSvcs: AppMgmt - C:\WINDOWS\System32\appmgmts.dll File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found
MsConfig - StartUpFolder: C:^Documents and Settings^ADMIN^Start Menu^Programs^Startup^setup_9.0.0.722_02.11.2010_10-07.lnk - C:\Documents and Settings\ADMIN\Desktop\Virus Removal Tool\setup_9.0.0.722_02.11.2010_10-07\startup.exe - ()
MsConfig - State: "system.ini" - 0
MsConfig - State: "win.ini" - 0
MsConfig - State: "bootini" - 0
MsConfig - State: "services" - 0
MsConfig - State: "startup" - 0
Drivers32: midi - C:\WINDOWS\System32\wdmaud.drv (Microsoft Corporation)
Drivers32: midi1 - C:\WINDOWS\System32\wdmaud.drv (Microsoft Corporation)
Drivers32: midi2 - C:\WINDOWS\System32\wdmaud.drv (Microsoft Corporation)
Drivers32: midi3 - C:\WINDOWS\System32\wdmaud.drv (Microsoft Corporation)
Drivers32: midimapper - C:\WINDOWS\System32\midimap.dll (Microsoft Corporation)
Drivers32: mixer - C:\WINDOWS\System32\wdmaud.drv (Microsoft Corporation)
Drivers32: mixer1 - C:\WINDOWS\System32\wdmaud.drv (Microsoft Corporation)
Drivers32: mixer2 - C:\WINDOWS\System32\wdmaud.drv (Microsoft Corporation)
Drivers32: msacm.iac2 - C:\WINDOWS\system32\iac25_32.ax (Intel Corporation)
Drivers32: msacm.imaadpcm - C:\WINDOWS\System32\imaadp32.acm (Microsoft Corporation)
Drivers32: msacm.l3acm - C:\WINDOWS\system32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.msadpcm - C:\WINDOWS\System32\msadp32.acm (Microsoft Corporation)
Drivers32: msacm.msaudio1 - C:\WINDOWS\System32\msaud32.acm (Microsoft Corporation)
Drivers32: msacm.msg711 - C:\WINDOWS\System32\msg711.acm (Microsoft Corporation)
Drivers32: msacm.msg723 - C:\WINDOWS\System32\msg723.acm (Microsoft Corporation)
Drivers32: msacm.msgsm610 - C:\WINDOWS\System32\msgsm32.acm (Microsoft Corporation)
Drivers32: msacm.sl_anet - C:\WINDOWS\System32\sl_anet.acm (Sipro Lab Telecom Inc.)
Drivers32: msacm.trspch - C:\WINDOWS\System32\tssoft32.acm (DSP GROUP, INC.)
Drivers32: vidc.cvid - C:\WINDOWS\System32\iccvid.dll (Radius Inc.)
Drivers32: vidc.I420 - C:\WINDOWS\System32\msh263.drv (Microsoft Corporation)
Drivers32: vidc.iv31 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv32 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv41 - C:\WINDOWS\System32\ir41_32.ax (Intel Corporation)
Drivers32: vidc.iv50 - C:\WINDOWS\System32\ir50_32.dll (Intel Corporation)
Drivers32: vidc.iyuv - C:\WINDOWS\System32\iyuv_32.dll (Microsoft Corporation)
Drivers32: vidc.M261 - C:\WINDOWS\System32\msh261.drv (Microsoft Corporation)
Drivers32: vidc.M263 - C:\WINDOWS\System32\msh263.drv (Microsoft Corporation)
Drivers32: vidc.mrle - C:\WINDOWS\System32\msrle32.dll (Microsoft Corporation)
Drivers32: vidc.msvc - C:\WINDOWS\System32\msvidc32.dll (Microsoft Corporation)
Drivers32: vidc.uyvy - C:\WINDOWS\System32\msyuv.dll (Microsoft Corporation)
Drivers32: vidc.yuy2 - C:\WINDOWS\System32\msyuv.dll (Microsoft Corporation)
Drivers32: vidc.yvu9 - C:\WINDOWS\System32\tsbyuv.dll (Microsoft Corporation)
Drivers32: vidc.yvyu - C:\WINDOWS\System32\msyuv.dll (Microsoft Corporation)
Drivers32: wave - C:\WINDOWS\System32\wdmaud.drv (Microsoft Corporation)
Drivers32: wave1 - C:\WINDOWS\System32\wdmaud.drv (Microsoft Corporation)
Drivers32: wave2 - C:\WINDOWS\System32\wdmaud.drv (Microsoft Corporation)
Drivers32: wavemapper - C:\WINDOWS\System32\msacm32.drv (Microsoft Corporation)
CREATERESTOREPOINT
Restore point Set: OTL Restore Point (16902053519425536)
========== Files/Folders - Created Within 30 Days ========== [2010/11/14 05:46:05 | 000,575,488 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\ADMIN\Desktop\OTL.exe
[2010/11/14 05:12:14 | 000,000,000 | ---D | C] -- C:\Documents and Settings\ADMIN\Desktop\BLEEPINCCOMPUTER FIX 13 NOV
[2010/11/14 03:19:57 | 000,000,000 | ---D | C] -- C:\Documents and Settings\ADMIN\Desktop\MBAM LOGS QUARANTINE KEEP
[2010/11/13 10:50:22 | 000,000,000 | ---D | C] -- C:\WINDOWS\LastGood
[2010/11/13 09:12:13 | 000,000,000 | ---D | C] -- C:\Documents and Settings\ADMIN\Desktop\GnuPG
[2010/11/13 08:59:16 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\{CFBD8779-FAAB-4357-84F2-1EC8619FADA6}
[2010/11/13 01:44:33 | 000,000,000 | ---D | C] -- C:\Documents and Settings\ADMIN\Desktop\sams luck DELETE
[2010/11/12 01:38:07 | 000,000,000 | ---D | C] -- C:\Documents and Settings\ADMIN\Local Settings\Application Data\PackageAware
[2010/11/10 20:59:08 | 000,000,000 | ---D | C] -- C:\Documents and Settings\ADMIN\Application Data\SUPERAntiSpyware.com
[2010/11/10 20:57:57 | 000,000,000 | ---D | C] -- C:\Program Files\SUPERAntiSpyware
[2010/11/10 10:32:34 | 000,000,000 | RH-D | C] -- C:\Documents and Settings\ADMIN\Recent
[2010/11/10 09:32:11 | 000,000,000 | ---D | C] -- C:\Documents and Settings\ADMIN\Application Data\MSN Search Toolbar
[2010/11/07 23:45:40 | 000,000,000 | ---D | C] -- C:\Documents and Settings\ADMIN\Application Data\Tor
[2010/11/07 23:45:28 | 000,000,000 | ---D | C] -- C:\Documents and Settings\ADMIN\Application Data\Vidalia
[2010/11/07 23:45:11 | 000,000,000 | ---D | C] -- C:\Program Files\Vidalia Bundle
[2010/11/07 02:41:30 | 000,000,000 | ---D | C] -- C:\## aswSnx private storage
[2010/11/02 10:58:47 | 000,315,408 | ---- | C] (Kaspersky Lab) -- C:\WINDOWS\System32\drivers\1748698.sys
[2010/11/02 10:58:47 | 000,128,016 | ---- | C] (Kaspersky Lab) -- C:\WINDOWS\System32\drivers\17486981.sys
[2010/11/02 10:58:47 | 000,037,392 | ---- | C] (Kaspersky Lab) -- C:\WINDOWS\System32\drivers\17486982.sys
[2010/11/02 10:58:46 | 000,000,000 | ---D | C] -- C:\Documents and Settings\ADMIN\Desktop\Virus Removal Tool
[2010/11/01 05:20:48 | 000,000,000 | ---D | C] -- C:\Documents and Settings\ADMIN\Application Data\QuickScan
[2010/10/31 06:58:50 | 000,000,000 | ---D | C] -- C:\Documents and Settings\ADMIN\Desktop\DESKTOP DOWNLOAD FOLDER
[2010/10/30 23:46:25 | 000,037,392 | ---- | C] (Kaspersky Lab) -- C:\WINDOWS\System32\drivers\87109712.sys
[2010/10/30 23:44:26 | 000,315,408 | ---- | C] (Kaspersky Lab) -- C:\WINDOWS\System32\drivers\8710971.sys
[2010/10/30 06:28:16 | 000,000,000 | ---D | C] -- C:\Documents and Settings\ADMIN\My Documents\Downloads
[2010/10/28 01:15:54 | 000,000,000 | ---D | C] -- C:\VKBOMBirus Removal Tool
[2010/10/27 00:21:01 | 000,038,848 | ---- | C] (AVAST Software) -- C:\WINDOWS\avastSS.scr
[2010/10/27 00:20:30 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Alwil Software
[2010/10/26 08:05:21 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Kaspersky Lab Setup Files
[2010/10/25 18:46:59 | 002,424,560 | ---- | C] (SUPERAntiSpyware.com) -- C:\Documents and Settings\ADMIN\Desktop\SUPERAntiSpyware.exe
[2010/10/25 02:36:56 | 000,000,000 | ---D | C] -- C:\Documents and Settings\ADMIN\Desktop\BC FIX 24 OCT 2010
[2010/10/23 02:54:05 | 000,000,000 | ---D | C] -- C:\Documents and Settings\ADMIN\Desktop\ATT&T EMAIL
[2010/10/22 05:40:41 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Sun
[2010/10/22 05:40:29 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Java
[2010/10/17 06:53:33 | 000,000,000 | ---D | C] -- C:\Documents and Settings\ADMIN\My Documents\MALWARE LOGS
[2010/10/16 01:13:53 | 000,000,000 | ---D | C] -- C:\Documents and Settings\ADMIN\My Documents\MY SCANNED STUFF
========== Files - Modified Within 30 Days ========== [2010/11/14 05:53:50 | 000,050,477 | ---- | M] () -- C:\Documents and Settings\ADMIN\Desktop\Defogger.exe
[2010/11/14 05:46:05 | 000,575,488 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\ADMIN\Desktop\OTL.exe
[2010/11/14 05:33:44 | 000,288,107 | ---- | M] () -- C:\Documents and Settings\ADMIN\Desktop\gmer.zip
[2010/11/13 10:55:29 | 000,000,186 | ---- | M] () -- C:\WINDOWS\System\hpsysdrv.DAT
[2010/11/13 10:46:26 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2010/11/13 01:17:36 | 000,027,163 | ---- | M] () -- C:\Documents and Settings\ADMIN\My Documents\COMODO LOG 8
[2010/11/12 07:12:20 | 000,002,577 | ---- | M] () -- C:\WINDOWS\System32\CONFIG.NT
[2010/11/11 10:25:39 | 000,000,284 | -HS- | M] () -- C:\BOOT.INI
[2010/11/11 07:48:36 | 000,033,583 | ---- | M] () -- C:\Documents and Settings\ADMIN\My Documents\COMODO LOG 7
[2010/11/11 00:05:44 | 002,424,560 | ---- | M] (SUPERAntiSpyware.com) -- C:\Documents and Settings\ADMIN\Desktop\SUPERAntiSpyware.exe
[2010/11/07 07:02:51 | 000,025,600 | ---- | M] () -- C:\Documents and Settings\ADMIN\Desktop\LETTER.wps
[2010/11/07 00:14:39 | 000,001,476 | ---- | M] () -- C:\Documents and Settings\ADMIN\Desktop\CallWave.lnk
[2010/11/07 00:14:38 | 000,001,492 | ---- | M] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Startup\CallWave.lnk
[2010/11/06 06:01:58 | 000,000,538 | ---- | M] () -- C:\Documents and Settings\ADMIN\My Documents\cc_20101106_060149.reg
[2010/11/06 06:00:37 | 000,004,634 | ---- | M] () -- C:\Documents and Settings\ADMIN\My Documents\cc_20101106_055935.reg
[2010/11/04 20:48:25 | 000,001,514 | ---- | M] () -- C:\Documents and Settings\ADMIN\Desktop\Paint (2).lnk
[2010/11/02 11:03:16 | 000,313,276 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat
[2010/11/02 11:03:16 | 000,040,868 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat
[2010/11/02 10:43:34 | 000,016,384 | ---- | M] () -- C:\Documents and Settings\ADMIN\My Documents\VOTE POST.wps
[2010/11/01 05:21:32 | 000,000,775 | ---- | M] () -- C:\Documents and Settings\ADMIN\Desktop\QuickScan Folder.lnk
[2010/10/31 03:44:29 | 000,020,992 | ---- | M] () -- C:\Documents and Settings\ADMIN\Desktop\SPELL CHECK.wps
[2010/10/31 03:18:15 | 000,000,000 | ---- | M] () -- C:\Documents and Settings\ADMIN\defogger_reenable
[2010/10/30 19:15:03 | 000,000,850 | ---- | M] () -- C:\Documents and Settings\ADMIN\Desktop\COMODO Internet Security.lnk
[2010/10/28 01:21:22 | 000,002,165 | ---- | M] () -- C:\Documents and Settings\ADMIN\Desktop\Start.lnk
[2010/10/25 22:42:16 | 000,016,558 | ---- | M] () -- C:\Documents and Settings\ADMIN\My Documents\EVIL LITTLE CREATURES.htm
========== Files Created - No Company Name ========== [2010/11/14 05:53:46 | 000,050,477 | ---- | C] () -- C:\Documents and Settings\ADMIN\Desktop\Defogger.exe
[2010/11/14 05:33:13 | 000,288,107 | ---- | C] () -- C:\Documents and Settings\ADMIN\Desktop\gmer.zip
[2010/11/13 01:17:36 | 000,027,163 | ---- | C] () -- C:\Documents and Settings\ADMIN\My Documents\COMODO LOG 8
[2010/11/11 07:48:36 | 000,033,583 | ---- | C] () -- C:\Documents and Settings\ADMIN\My Documents\COMODO LOG 7
[2010/11/07 00:14:39 | 000,001,476 | ---- | C] () -- C:\Documents and Settings\ADMIN\Desktop\CallWave.lnk
[2010/11/07 00:14:36 | 000,001,492 | ---- | C] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Startup\CallWave.lnk
[2010/11/06 06:01:54 | 000,000,538 | ---- | C] () -- C:\Documents and Settings\ADMIN\My Documents\cc_20101106_060149.reg
[2010/11/06 05:59:51 | 000,004,634 | ---- | C] () -- C:\Documents and Settings\ADMIN\My Documents\cc_20101106_055935.reg
[2010/11/02 23:56:33 | 000,001,819 | ---- | C] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk
[2010/11/02 23:56:33 | 000,001,492 | ---- | C] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Startup\CallWave.lnk.disabled
[2010/11/02 23:56:31 | 000,002,180 | ---- | C] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Windows Desktop Search.lnk
[2010/11/02 10:43:33 | 000,016,384 | ---- | C] () -- C:\Documents and Settings\ADMIN\My Documents\VOTE POST.wps
[2010/11/01 05:21:20 | 000,000,775 | ---- | C] () -- C:\Documents and Settings\ADMIN\Desktop\QuickScan Folder.lnk
[2010/10/31 03:18:15 | 000,000,000 | ---- | C] () -- C:\Documents and Settings\ADMIN\defogger_reenable
[2010/10/30 19:36:55 | 000,002,165 | ---- | C] () -- C:\Documents and Settings\ADMIN\Desktop\Start.lnk
[2010/10/25 22:42:15 | 000,016,558 | ---- | C] () -- C:\Documents and Settings\ADMIN\My Documents\EVIL LITTLE CREATURES.htm
[2009/11/02 05:39:06 | 000,000,754 | ---- | C] () -- C:\WINDOWS\WORDPAD.INI
[2009/06/08 02:55:20 | 000,004,608 | ---- | C] () -- C:\Documents and Settings\ADMIN\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009/06/06 01:35:17 | 000,077,824 | R--- | C] () -- C:\WINDOWS\System32\hpzids01.dll
[2009/06/06 00:40:36 | 000,003,188 | ---- | C] () -- C:\Documents and Settings\All Users\Application Data\hpzinstall.log
[2009/06/03 04:30:05 | 000,087,552 | ---- | C] () -- C:\WINDOWS\System32\cpwmon2k.dll
[2009/05/25 01:55:49 | 000,010,240 | ---- | C] () -- C:\WINDOWS\System32\vidx16.dll
[2009/05/25 01:50:36 | 000,000,021 | ---- | C] () -- C:\WINDOWS\CS_setup.ini
[2009/05/09 05:09:23 | 000,006,048 | ---- | C] () -- C:\WINDOWS\System32\MCC16.dll
[2009/05/09 05:06:40 | 000,040,448 | ---- | C] () -- C:\WINDOWS\System32\BJAXSecurityManager.dll
[2009/05/09 05:05:39 | 000,086,016 | ---- | C] () -- C:\WINDOWS\System32\BJInstaller.dll
[2009/05/03 03:28:22 | 000,143,096 | ---- | C] () -- C:\WINDOWS\System32\guard32.dll
[2009/05/03 03:15:05 | 000,000,057 | ---- | C] () -- C:\WINDOWS\dcmvwr.INI
[2009/05/03 02:29:50 | 000,000,058 | ---- | C] () -- C:\WINDOWS\BGH 2005 SS 1.ini
[2006/05/29 13:47:31 | 000,000,060 | ---- | C] () -- C:\WINDOWS\SIERRA.INI
[2006/05/29 13:47:29 | 000,000,055 | ---- | C] () -- C:\WINDOWS\KA.INI
[2006/02/21 15:22:46 | 008,940,869 | ---- | C] () -- C:\Program Files\Adobe.zip
[2006/02/02 15:04:29 | 000,363,520 | ---- | C] () -- C:\WINDOWS\System32\psisdecd.dll
[2006/02/01 23:06:51 | 000,094,208 | ---- | C] () -- C:\WINDOWS\System32\GTW32N50.dll
[2006/01/18 20:45:15 | 000,000,000 | ---- | C] () -- C:\WINDOWS\JDSecure31.INI
[2006/01/18 20:45:09 | 000,249,856 | ---- | C] () -- C:\WINDOWS\System32\LxrJD31.dll
[2006/01/18 20:45:09 | 000,069,824 | ---- | C] () -- C:\WINDOWS\System32\drivers\LxrJD31d.sys
[2006/01/18 20:45:09 | 000,061,440 | ---- | C] () -- C:\WINDOWS\System32\LxrJD20Sat.dll
[2005/12/30 21:10:01 | 000,000,024 | ---- | C] () -- C:\WINDOWS\Disney.ini
[2005/12/30 03:02:33 | 000,000,044 | ---- | C] () -- C:\WINDOWS\System32\msssc.dll
[2002/04/26 03:23:36 | 000,000,061 | ---- | C] () -- C:\WINDOWS\smscfg.ini
[2002/04/21 00:24:15 | 000,377,600 | ---- | C] () -- C:\WINDOWS\System32\BOCOLE.DLL
[2002/04/21 00:24:15 | 000,167,456 | ---- | C] () -- C:\WINDOWS\System32\Bocof.dll
[2002/04/21 00:16:42 | 000,045,056 | ---- | C] () -- C:\WINDOWS\System32\hpREG.DLL
[2002/04/21 00:16:42 | 000,024,576 | ---- | C] () -- C:\WINDOWS\System32\syscontr.dll
[2002/04/20 06:28:06 | 000,004,478 | ---- | C] () -- C:\WINDOWS\wininit.ini
[2002/04/20 06:19:46 | 000,019,968 | ---- | C] () -- C:\WINDOWS\System32\cpuinf32.dll
[2002/04/20 05:26:01 | 000,249,921 | ---- | C] () -- C:\WINDOWS\System32\PythonCOM15.dll
[2002/04/20 05:26:01 | 000,065,536 | ---- | C] () -- C:\WINDOWS\System32\PyWinTypes15.dll
[2002/04/20 05:25:32 | 000,016,896 | ---- | C] () -- C:\WINDOWS\System32\bcbmm.dll
[2002/04/20 04:20:31 | 000,000,799 | ---- | C] () -- C:\WINDOWS\orun32.ini
[2002/04/20 04:04:05 | 000,000,666 | ---- | C] () -- C:\WINDOWS\System32\oeminfo.ini
[2002/04/19 21:08:55 | 000,004,161 | ---- | C] () -- C:\WINDOWS\ODBCINST.INI
[2002/03/30 01:49:26 | 000,000,000 | ---- | C] () -- C:\WINDOWS\System32\px.ini
[2002/03/27 21:37:52 | 000,262,144 | ---- | C] () -- C:\WINDOWS\System32\shpshftr.dll
[2002/03/12 10:25:02 | 000,028,672 | ---- | C] () -- C:\WINDOWS\System32\igfxdgps.dll
[2001/09/01 05:33:58 | 000,425,984 | ---- | C] () -- C:\WINDOWS\System32\VxDMDcDlg.dll
[2001/08/08 20:13:22 | 000,012,351 | ---- | C] () -- C:\WINDOWS\System32\i81xcoin.dll
[2001/07/06 15:30:00 | 000,003,399 | ---- | C] () -- C:\WINDOWS\System32\hptcpmon.ini
[2001/06/19 14:20:14 | 000,037,408 | ---- | C] () -- C:\WINDOWS\System32\drivers\SbcpHid.sys
[1997/06/18 06:00:00 | 001,672,976 | ---- | C] () -- C:\WINDOWS\System32\MSO97V.DLL
[1997/06/18 06:00:00 | 000,022,016 | ---- | C] () -- C:\WINDOWS\System32\DOCOBJ.DLL
[1997/06/18 06:00:00 | 000,012,288 | ---- | C] () -- C:\WINDOWS\System32\HLINKPRX.DLL
========== LOP Check ========== [2009/06/22 00:37:57 | 000,000,000 | ---D | M] -- C:\Documents and Settings\ADMIN\Application Data\Auslogics
[2009/05/10 19:18:16 | 000,000,000 | ---D | M] -- C:\Documents and Settings\ADMIN\Application Data\ieSpell
[2010/10/16 00:52:39 | 000,000,000 | ---D | M] -- C:\Documents and Settings\ADMIN\Application Data\Image Zone Express
[2002/04/20 06:04:24 | 000,000,000 | ---D | M] -- C:\Documents and Settings\ADMIN\Application Data\InterTrust
[2010/11/10 09:32:50 | 000,000,000 | ---D | M] -- C:\Documents and Settings\ADMIN\Application Data\MSN Search Toolbar
[2010/11/13 07:47:15 | 000,000,000 | ---D | M] -- C:\Documents and Settings\ADMIN\Application Data\NCH Swift Sound
[2009/11/03 01:45:25 | 000,000,000 | ---D | M] -- C:\Documents and Settings\ADMIN\Application Data\OpenOffice.org
[2010/11/02 08:55:59 | 000,000,000 | ---D | M] -- C:\Documents and Settings\ADMIN\Application Data\QuickScan
[2009/05/04 02:10:08 | 000,000,000 | ---D | M] -- C:\Documents and Settings\ADMIN\Application Data\Template
[2009/06/03 06:04:21 | 000,000,000 | ---D | M] -- C:\Documents and Settings\ADMIN\Application Data\TrueCrypt
[2002/04/20 06:23:48 | 000,000,000 | ---D | M] -- C:\Documents and Settings\ADMIN\Application Data\VERITAS
[2002/04/20 06:04:24 | 000,000,000 | ---D | M] -- C:\Documents and Settings\ADMIN WEB BROWSING\Application Data\InterTrust
[2010/11/10 00:43:37 | 000,000,000 | ---D | M] -- C:\Documents and Settings\ADMIN WEB BROWSING\Application Data\MSN Search Toolbar
[2002/04/20 06:23:48 | 000,000,000 | ---D | M] -- C:\Documents and Settings\ADMIN WEB BROWSING\Application Data\VERITAS
[2010/10/27 00:20:30 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Alwil Software
[2009/05/03 03:52:34 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Avg7
[2006/02/19 10:32:42 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\MSN Search Toolbar
[2010/08/05 21:26:45 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\NCH Swift Sound
[2006/07/20 12:58:43 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\WildTangent
[2010/11/13 08:59:16 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\{CFBD8779-FAAB-4357-84F2-1EC8619FADA6}
[2002/04/20 06:04:24 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Default User\Application Data\InterTrust
[2002/04/20 06:23:48 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Default User\Application Data\VERITAS
========== Purity Check ========== ========== Custom Scans ========== < %systemroot%\system32\*.dll /lockedfiles > < %systemroot%\system32\*.sys /90 >[2010/08/31 13:42:52 | 001,852,800 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\win32k.sys
< %systemroot%\Tasks\*.job /lockedfiles > < %systemroot%\System32\config\*.sav >[2002/04/19 21:07:21 | 000,090,112 | ---- | M] () -- C:\WINDOWS\system32\config\default.sav
[2002/04/19 21:07:21 | 000,606,208 | ---- | M] () -- C:\WINDOWS\system32\config\software.sav
[2002/04/19 21:07:21 | 000,376,832 | ---- | M] () -- C:\WINDOWS\system32\config\system.sav
< %SYSTEMDRIVE%\*.* >[2002/04/20 04:16:39 | 000,000,000 | ---- | M] () -- C:\AUTOEXEC.BAT
[2009/05/09 05:14:20 | 019,624,680 | ---- | M] () -- C:\BellSouthIW.re~
[2009/06/10 01:53:35 | 000,000,200 | ---- | M] () -- C:\Boot.bak
[2010/11/11 10:25:39 | 000,000,284 | -HS- | M] () -- C:\BOOT.INI
[2009/06/28 07:34:25 | 000,000,700 | ---- | M] () -- C:\Bug.txt
[2004/08/03 22:00:00 | 000,260,272 | ---- | M] () -- C:\cmldr
[2002/04/20 04:16:39 | 000,000,000 | ---- | M] () -- C:\CONFIG.SYS
[2009/11/28 03:55:54 | 000,000,000 | ---- | M] () -- C:\Documents
[2002/04/26 02:45:35 | 000,012,919 | ---- | M] () -- C:\FINIS_IT.TXT
[2002/04/20 04:16:39 | 000,000,000 | RHS- | M] () -- C:\IO.SYS
[2010/01/28 01:41:45 | 002,854,351 | ---- | M] () -- C:\Microburner.log
[2002/04/20 04:16:39 | 000,000,000 | RHS- | M] () -- C:\MSDOS.SYS
[2006/02/23 18:55:46 | 000,047,564 | RHS- | M] () -- C:\NTDETECT.COM
[2009/05/16 20:24:39 | 000,250,048 | RHS- | M] () -- C:\ntldr
[2010/11/13 10:46:22 | 2621,440,000 | -HS- | M] () -- C:\pagefile.sys
< %systemroot%\system32\Spool\prtprocs\w32x86\*.dll >[2005/10/14 21:41:46 | 000,072,192 | ---- | M] (Hewlett-Packard Corporation) -- C:\WINDOWS\system32\spool\prtprocs\w32x86\hpzpp43a.dll
< %systemroot%\*. /mp /s > < HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU > ========== Alternate Data Streams ========== @Alternate Data Stream - 88 bytes -> C:\Program Files\Comodo\Comodo Internet Security\cfp.exe:SummaryInformation
@Alternate Data Stream - 88 bytes -> C:\Documents and Settings\ADMIN\Desktop\SUPERAntiSpyware.exe:SummaryInformation
@Alternate Data Stream - 88 bytes -> C:\Documents and Settings\ADMIN\Desktop\mbk622n2.exe:SummaryInformation
< End of report >
For the GMER log, I don't know if I had the program set right when I ran it. I understood the instructions to say UN check the little box for C:\ drive so that is what I did. Then while it was running I noticed in the picture in the preparation guide that is was shown ticked. Let me know if I need to tick that C:\ box and run it again.
OTL logfile created on: 11/14/2010 6:10:59 AM - Run 4
OTL by OldTimer - Version 3.2.17.3 Folder = C:\Documents and Settings\ADMIN\Desktop
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.11)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
126.00 Mb Total Physical Memory | 34.00 Mb Available Physical Memory | 27.00% Memory free
3.00 Gb Paging File | 2.00 Gb Available in Paging File | 89.00% Paging File free
Paging file location(s): C:\pagefile.sys 2500 2500 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 51.05 Gb Total Space | 35.77 Gb Free Space | 70.08% Space Free | Partition Type: NTFS
Drive D: | 4.87 Gb Total Space | 0.92 Gb Free Space | 18.87% Space Free | Partition Type: FAT32
Drive E: | 678.41 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS
Computer Name: WENDYS-BOX | User Name: ADMIN | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ========== PRC - [2010/11/14 05:46:05 | 000,575,488 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\ADMIN\Desktop\OTL.exe
PRC - [2010/10/30 19:30:12 | 001,797,880 | ---- | M] () -- C:\Program Files\Comodo\Comodo Internet Security\cfp.exe
PRC - [2010/05/25 19:10:34 | 005,475,403 | ---- | M] () -- C:\Program Files\Vidalia Bundle\Vidalia\vidalia.exe
PRC - [2010/05/17 14:57:18 | 002,162,176 | ---- | M] () -- C:\Program Files\Vidalia Bundle\Tor\tor.exe
PRC - [2010/02/01 00:45:22 | 000,181,248 | ---- | M] () -- C:\Program Files\Vidalia Bundle\Polipo\polipo.exe
PRC - [2009/05/03 04:07:22 | 000,278,264 | ---- | M] (COMODO) -- C:\Program Files\Comodo\SafeSurf\cssurf.exe
PRC - [2009/05/03 04:03:00 | 000,614,136 | ---- | M] () -- C:\Program Files\Comodo\Comodo Internet Security\cmdagent.exe
PRC - [2008/04/14 00:12:19 | 001,033,728 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe
PRC - [2006/01/18 20:53:30 | 000,071,168 | ---- | M] () -- C:\WINDOWS\system32\LxrJD31s.exe
PRC - [2005/03/14 11:05:02 | 000,069,632 | ---- | M] (HP) -- C:\WINDOWS\system32\HPZipm12.exe
PRC - [2002/03/16 05:51:02 | 000,028,672 | ---- | M] () -- C:\WINDOWS\system32\S3apphk.exe
========== Modules (SafeList) ========== MOD - [2010/11/14 05:46:05 | 000,575,488 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\ADMIN\Desktop\OTL.exe
MOD - [2010/08/23 16:12:02 | 001,054,208 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.6028_x-ww_61e65202\comctl32.dll
MOD - [2002/03/16 05:51:02 | 000,045,056 | ---- | M] (S3 Graphics, Inc.) -- C:\WINDOWS\system32\S3appdll.dll
MOD - [2001/11/11 15:41:07 | 000,106,547 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Common Files\SunnComm Shared\msscript.OCX
========== Win32 Services (SafeList) ========== SRV - File not found [Auto | Stopped] -- C:\SANDBOXIE\SbieSvc.exe -- (SbieSvc)
SRV - File not found [On_Demand | Stopped] -- C:\DOCUME~1\ADMIN\LOCALS~1\Temp\ODETJ.exe -- (ODETJ)
SRV - File not found [On_Demand | Stopped] -- C:\WINDOWS\System32\appmgmts.dll -- (AppMgmt)
SRV - [2009/05/03 04:03:00 | 000,614,136 | ---- | M] () [Auto | Running] -- C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe -- (cmdAgent)
SRV - [2006/01/18 20:53:30 | 000,071,168 | ---- | M] () [Auto | Running] -- C:\WINDOWS\System32\LxrJD31s.exe -- (LxrJD31s)
SRV - [2005/03/14 11:05:02 | 000,069,632 | ---- | M] (HP) [Auto | Running] -- C:\WINDOWS\system32\HPZipm12.exe -- (Pml Driver HPZ12)
========== Driver Services (SafeList) ========== DRV - File not found [Kernel | On_Demand | Stopped] -- C:\SANDBOXIE\SbieDrv.sys -- (SbieDrv)
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\WINDOWS\System32\DRIVERS\FREEDOM.SYS -- (Freedom)
DRV - [2010/05/10 18:41:30 | 000,067,656 | ---- | M] (SUPERAdBlocker.com and SUPERAntiSpyware.com) [Kernel | System | Running] -- C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS -- (SASKUTIL)
DRV - [2010/02/17 18:25:48 | 000,012,872 | ---- | M] (SUPERAdBlocker.com and SUPERAntiSpyware.com) [Kernel | System | Running] -- C:\Program Files\SUPERAntiSpyware\sasdifsv.sys -- (SASDIFSV)
DRV - [2009/06/09 02:29:49 | 000,027,136 | ---- | M] (NCH Swift Sound) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\nchssvad.sys -- (NCHSSVAD)
DRV - [2009/06/03 05:45:18 | 000,217,536 | ---- | M] (TrueCrypt Foundation) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\truecrypt.sys -- (truecrypt)
DRV - [2009/05/03 04:03:10 | 000,099,856 | ---- | M] (COMODO) [File_System | System | Running] -- C:\WINDOWS\system32\drivers\cmdguard.sys -- (cmdGuard)
DRV - [2009/05/03 04:03:10 | 000,079,504 | ---- | M] (COMODO) [Kernel | Boot | Running] -- C:\WINDOWS\System32\DRIVERS\inspect.sys -- (Inspect)
DRV - [2009/05/03 04:03:10 | 000,031,504 | ---- | M] (COMODO) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\cmdhlp.sys -- (cmdHlp)
DRV - [2008/04/13 18:56:49 | 000,012,800 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\usb8023.sys -- (USB_RNDIS)
DRV - [2008/04/13 18:45:29 | 000,010,624 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\gameenum.sys -- (gameenum)
DRV - [2006/01/18 20:53:30 | 000,069,824 | ---- | M] () [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\LxrJD31d.sys -- (LxrJD31d)
DRV - [2005/04/13 22:31:30 | 000,239,488 | ---- | M] (Ralink Technology Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\rt2500usb.sys -- (WUSB54GPV4SRV)
DRV - [2004/10/08 01:16:04 | 000,035,840 | ---- | M] (Oak Technology Inc.) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\AFS2K.SYS -- (AFS2K)
DRV - [2004/08/04 05:31:32 | 000,020,992 | ---- | M] (Realtek Semiconductor Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\rtl8139.sys -- (rtl8139) Realtek RTL8139(A/B/C)
DRV - [2003/03/31 20:29:00 | 000,625,537 | ---- | M] (LT) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\ltmdmnt.sys -- (ltmodem5)
DRV - [2002/03/27 01:20:22 | 000,013,780 | ---- | M] (Padus, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\pfc.sys -- (pfc)
DRV - [2002/03/21 05:35:56 | 000,144,860 | ---- | M] (VIA Technologies, Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\trid3dm.sys -- (trid3d)
DRV - [2002/03/19 09:18:26 | 000,187,520 | ---- | M] (Silicon Integrated Systems Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\sisgrp.sys -- (SiS315)
DRV - [2002/03/14 17:25:00 | 000,094,679 | ---- | M] (VERITAS Software, Inc.) [File_System | Auto | Running] -- C:\WINDOWS\system32\dla\tfsnudfa.sys -- (tfsnudfa)
DRV - [2002/03/14 17:25:00 | 000,088,758 | ---- | M] (VERITAS Software, Inc.) [File_System | Auto | Running] -- C:\WINDOWS\system32\dla\tfsnudf.sys -- (tfsnudf)
DRV - [2002/03/14 17:25:00 | 000,052,758 | ---- | M] (VERITAS Software, Inc.) [File_System | Auto | Running] -- C:\WINDOWS\system32\dla\tfsnifs.sys -- (tfsnifs)
DRV - [2002/03/14 17:25:00 | 000,034,743 | ---- | M] (VERITAS Software, Inc.) [File_System | Auto | Running] -- C:\WINDOWS\system32\dla\tfsncofs.sys -- (tfsncofs)
DRV - [2002/03/14 17:25:00 | 000,023,607 | ---- | M] (VERITAS Software, Inc.) [File_System | Auto | Running] -- C:\WINDOWS\system32\dla\tfsnboio.sys -- (tfsnboio)
DRV - [2002/03/14 17:25:00 | 000,013,847 | ---- | M] (VERITAS Software, Inc.) [File_System | Auto | Running] -- C:\WINDOWS\system32\dla\tfsnopio.sys -- (tfsnopio)
DRV - [2002/03/14 17:25:00 | 000,006,327 | ---- | M] (VERITAS Software, Inc.) [File_System | Auto | Running] -- C:\WINDOWS\system32\dla\tfsnpool.sys -- (tfsnpool)
DRV - [2002/03/14 17:25:00 | 000,004,119 | ---- | M] (VERITAS Software, Inc.) [File_System | Auto | Running] -- C:\WINDOWS\system32\dla\tfsndrct.sys -- (tfsndrct)
DRV - [2002/03/14 17:25:00 | 000,002,203 | ---- | M] (VERITAS Software, Inc.) [File_System | Auto | Running] -- C:\WINDOWS\system32\dla\tfsndres.sys -- (tfsndres)
DRV - [2002/03/09 23:53:00 | 000,909,501 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\nv4_mini.sys -- (nv)
DRV - [2002/02/15 17:21:00 | 000,078,048 | ---- | M] (VERITAS Software, Inc.) [Kernel | Boot | Running] -- C:\WINDOWS\system32\drivers\drvmcdb.sys -- (drvmcdb)
DRV - [2002/02/12 16:56:00 | 000,040,096 | ---- | M] (VERITAS Software, Inc.) [File_System | Auto | Running] -- C:\WINDOWS\system32\drivers\drvnddm.sys -- (drvnddm)
DRV - [2002/01/29 07:04:04 | 000,005,589 | ---- | M] (VERITAS Software, Inc.) [File_System | System | Running] -- C:\WINDOWS\system32\drivers\sscdbhk5.sys -- (sscdbhk5)
DRV - [2002/01/29 07:03:18 | 000,022,963 | ---- | M] (VERITAS Software, Inc.) [File_System | System | Running] -- C:\WINDOWS\system32\drivers\ssrtln.sys -- (ssrtln)
DRV - [2001/12/27 10:52:58 | 000,027,136 | ---- | M] (Silicon Integrated Systems Corporation) [Kernel | Boot | Running] -- C:\WINDOWS\System32\DRIVERS\SISAGP.sys -- (SISAGP)
DRV - [2001/12/08 04:26:00 | 000,013,502 | ---- | M] (NVIDIA Corporation) [Kernel | Boot | Running] -- C:\WINDOWS\System32\DRIVERS\nv_agp.sys -- (nv_agp)
DRV - [2001/08/18 04:00:04 | 000,002,944 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\msmpu401.sys -- (ms_mpu401)
DRV - [2001/08/17 19:50:26 | 000,731,648 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\nv4.sys -- (nv4)
DRV - [2001/08/08 20:13:36 | 000,158,140 | ---- | M] (Intel® Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\i81xnt5.sys -- (i81x)
DRV - [2001/08/08 20:13:30 | 000,012,479 | ---- | M] (Intel® Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\wADV01nt.sys -- (iAimFP0)
DRV - [2001/08/08 20:13:30 | 000,012,031 | ---- | M] (Intel® Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\wADV02NT.sys -- (iAimFP1)
DRV - [2001/08/08 20:13:30 | 000,011,679 | ---- | M] (Intel® Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\wADV05NT.sys -- (iAimFP2)
DRV - [2001/08/08 20:13:28 | 000,019,359 | ---- | M] (Intel® Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\wVchNTxx.sys -- (iAimFP4)
DRV - [2001/08/08 20:13:28 | 000,011,999 | ---- | M] (Intel® Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\wSiINTxx.sys -- (iAimFP3)
DRV - [2001/08/08 20:13:26 | 000,033,503 | ---- | M] (Intel® Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\wATV04nt.sys -- (iAimTV3)
DRV - [2001/08/08 20:13:24 | 000,029,215 | ---- | M] (Intel® Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\wATV01nt.sys -- (iAimTV0)
DRV - [2001/08/08 20:13:24 | 000,023,519 | ---- | M] (Intel® Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\wCh7xxNT.sys -- (iAimTV4)
DRV - [2001/08/08 20:13:24 | 000,019,199 | ---- | M] (Intel® Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\wATV02NT.sys -- (iAimTV1)
DRV - [2001/06/19 14:20:14 | 000,037,408 | ---- | M] () [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\SbcpHid.sys -- (SbcpHid)
DRV - [2001/06/04 20:00:00 | 000,014,112 | ---- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\PS2.sys -- (Ps2)
========== Standard Registry (SafeList) ========== ========== Internet Explorer ========== IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-2647865256-2038945071-357464061-1008\SOFTWARE\Microsoft\Internet Explorer\Main,SearchDefaultBranded = 1
IE - HKU\S-1-5-21-2647865256-2038945071-357464061-1008\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultName = Live Search
IE - HKU\S-1-5-21-2647865256-2038945071-357464061-1008\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultURL =
http://search.live.com/results.aspx?q={searchTerms}&src={referrer:source?}IE - HKU\S-1-5-21-2647865256-2038945071-357464061-1008\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://my.att.net/IE - HKU\S-1-5-21-2647865256-2038945071-357464061-1008\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 1
IE - HKU\S-1-5-21-2647865256-2038945071-357464061-1008\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = ftp=localhost:8118;http=localhost:8118;https=localhost:8118;socks=localhost:9050
========== FireFox ========== FF - prefs.js..browser.search.selectedEngine: "Google"
FF - prefs.js..browser.search.suggest.enabled: false
FF - prefs.js..browser.startup.homepage: "
http://my.att.net/"FF - prefs.js..extensions.enabledItems: toolbar@duckduckgo.com:1.2.0
FF - prefs.js..extensions.enabledItems: {a7c6cf7f-112c-4500-a7ea-39801a327e5f}:1.0.4
FF - prefs.js..extensions.enabledItems: jqs@sun.com:1.0
FF - prefs.js..extensions.enabledItems: {e0204bd5-9d31-402b-a99d-a6aa8ffebdca}:1.2.1
FF - prefs.js..network.proxy.http: "127.0.0.1"
FF - prefs.js..network.proxy.http_port: 8118
FF - prefs.js..network.proxy.socks: "127.0.0.1"
FF - prefs.js..network.proxy.socks_port: 9050
FF - prefs.js..network.proxy.socks_remote_dns: true
FF - prefs.js..network.proxy.ssl: "127.0.0.1"
FF - prefs.js..network.proxy.ssl_port: 8118
FF - prefs.js..network.proxy.type: 1
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.12\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010/11/08 10:53:10 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.12\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010/10/29 07:09:01 | 000,000,000 | ---D | M]
[2009/05/10 05:46:51 | 000,000,000 | ---D | M] -- C:\Documents and Settings\ADMIN\Application Data\Mozilla\Extensions
[2009/05/03 04:07:03 | 000,000,000 | ---D | M] -- C:\Documents and Settings\ADMIN\Application Data\Mozilla\Firefox\extensions
[2009/05/03 04:07:05 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\ADMIN\Application Data\Mozilla\Firefox\extensions\{E9A1DEE0-C623-4439-8932-001E7D17607D}
[2009/07/27 21:16:33 | 000,000,000 | ---D | M] -- C:\Documents and Settings\ADMIN\Application Data\Mozilla\Firefox\Profiles\6j74vj6s.default\extensions
[2009/06/06 20:14:18 | 000,000,000 | ---D | M] (FireFTP) -- C:\Documents and Settings\ADMIN\Application Data\Mozilla\Firefox\Profiles\6j74vj6s.default\extensions\{a7c6cf7f-112c-4500-a7ea-39801a327e5f}
[2009/05/10 07:47:22 | 000,000,000 | ---D | M] (Torbutton) -- C:\Documents and Settings\ADMIN\Application Data\Mozilla\Firefox\Profiles\6j74vj6s.default\extensions\{e0204bd5-9d31-402b-a99d-a6aa8ffebdca}
[2009/05/21 00:29:18 | 000,000,000 | ---D | M] -- C:\Documents and Settings\ADMIN\Application Data\Mozilla\Firefox\Profiles\6j74vj6s.default\extensions\toolbar@duckduckgo.com
[2010/11/14 03:36:42 | 000,000,000 | ---D | M] -- C:\Documents and Settings\ADMIN\Application Data\Mozilla\Firefox\Profiles\udeoiorw.ADMIN\extensions
[2010/11/11 04:36:19 | 000,000,000 | ---D | M] (Flagfox) -- C:\Documents and Settings\ADMIN\Application Data\Mozilla\Firefox\Profiles\udeoiorw.ADMIN\extensions\{1018e4d6-728f-4b20-ad56-37578a4de76b}
[2009/11/02 09:57:58 | 000,000,000 | ---D | M] (Dr.Web anti-virus link checker) -- C:\Documents and Settings\ADMIN\Application Data\Mozilla\Firefox\Profiles\udeoiorw.ADMIN\extensions\{6614d11d-d21d-b211-ae23-815234e1ebb5}
[2010/02/24 00:26:11 | 000,000,000 | ---D | M] (CookieCuller) -- C:\Documents and Settings\ADMIN\Application Data\Mozilla\Firefox\Profiles\udeoiorw.ADMIN\extensions\{99B98C2C-7274-45a3-A640-D9DF1A1C8460}
[2010/11/08 01:44:44 | 000,000,000 | ---D | M] (FireFTP) -- C:\Documents and Settings\ADMIN\Application Data\Mozilla\Firefox\Profiles\udeoiorw.ADMIN\extensions\{a7c6cf7f-112c-4500-a7ea-39801a327e5f}
[2010/11/11 04:36:25 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\ADMIN\Application Data\Mozilla\Firefox\Profiles\udeoiorw.ADMIN\extensions\{AE93811A-5C9A-4d34-8462-F7B864FC4696}
[2010/11/01 04:55:21 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\ADMIN\Application Data\Mozilla\Firefox\Profiles\udeoiorw.ADMIN\extensions\{e001c731-5e37-4538-a5cb-8168736a2360}
[2010/11/07 23:58:27 | 000,000,000 | ---D | M] (Torbutton) -- C:\Documents and Settings\ADMIN\Application Data\Mozilla\Firefox\Profiles\udeoiorw.ADMIN\extensions\{e0204bd5-9d31-402b-a99d-a6aa8ffebdca}
[2010/11/11 04:36:23 | 000,000,000 | ---D | M] (Download Manager Tweak) -- C:\Documents and Settings\ADMIN\Application Data\Mozilla\Firefox\Profiles\udeoiorw.ADMIN\extensions\{F8A55C97-3DB6-4961-A81D-0DE0080E53CB}
[2009/07/22 06:33:04 | 000,000,000 | ---D | M] -- C:\Documents and Settings\ADMIN\Application Data\Mozilla\Firefox\Profiles\udeoiorw.ADMIN\extensions\toolbar@duckduckgo.com
[2010/11/14 03:36:42 | 000,000,000 | ---D | M] -- C:\Program Files\Mozilla Firefox\extensions
[2010/10/22 05:35:59 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}
[2009/05/03 05:30:04 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions\{e0204bd5-9d31-402b-a99d-a6aa8ffebdca}
[2010/09/15 03:50:38 | 000,472,808 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\Mozilla Firefox\plugins\npdeployJava1.dll
[2006/06/17 13:11:43 | 000,090,112 | ---- | M] () -- C:\Program Files\Mozilla Firefox\plugins\NpPopup.dll
O1 HOSTS File: ([2010/03/01 17:33:31 | 000,000,789 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - No CLSID value found.
O2 - BHO: (AcroIEHlprObj Class) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx ()
O2 - BHO: (no name) - {201f27d4-3704-41d6-89c1-aa35e39143ed} - No CLSID value found.
O2 - BHO: (MSN Search Toolbar Helper) - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Toolbar Suite\TB\02.05.0001.1119\en-us\msntb.dll File not found
O3 - HKLM\..\Toolbar: (&hp toolkit) - {B2847E28-5D7D-4DEB-8B67-05D28BCF79F5} - C:\hp\EXPLOREBAR\HPTOOLKT.DLL (Hewlett-Packard Company)
O3 - HKLM\..\Toolbar: (MSN Search Toolbar) - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Toolbar Suite\TB\02.05.0001.1119\en-us\msntb.dll File not found
O3 - HKU\S-1-5-21-2647865256-2038945071-357464061-1008\..\Toolbar\ShellBrowser: (no name) - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - No CLSID value found.
O3 - HKU\S-1-5-21-2647865256-2038945071-357464061-1008\..\Toolbar\ShellBrowser: (&hp toolkit) - {B2847E28-5D7D-4DEB-8B67-05D28BCF79F5} - C:\hp\EXPLOREBAR\HPTOOLKT.DLL (Hewlett-Packard Company)
O3 - HKU\S-1-5-21-2647865256-2038945071-357464061-1008\..\Toolbar\WebBrowser: (&hp toolkit) - {B2847E28-5D7D-4DEB-8B67-05D28BCF79F5} - C:\hp\EXPLOREBAR\HPTOOLKT.DLL (Hewlett-Packard Company)
O4 - HKLM..\Run: [COMODO Internet Security] C:\Program Files\Comodo\Comodo Internet Security\cfp.exe ()
O4 - HKLM..\Run: [COMODO SafeSurf] C:\Program Files\COMODO\SafeSurf\cssurf.exe (COMODO)
O4 - HKLM..\Run: [nwiz] C:\WINDOWS\System32\nwiz.exe (NVIDIA Corporation)
O4 - HKLM..\Run: [PreloadApp] c:\hp\drivers\printers\photosmart\hphprld.exe ()
O4 - HKLM..\Run: [PS2] C:\WINDOWS\system32\ps2.EXE (Hewlett-Packard Company)
O4 - HKLM..\Run: [Recguard] C:\WINDOWS\SMINST\Recguard.exe ()
O4 - HKLM..\Run: [S3apphk] C:\WINDOWS\System32\S3apphk.exe ()
O4 - HKU\S-1-5-21-2647865256-2038945071-357464061-1008..\Run: [Microsoft Works Update Detection] c:\Program Files\Microsoft Works\WkDetect.exe File not found
O4 - HKU\S-1-5-21-2647865256-2038945071-357464061-1008..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe File not found
O4 - HKU\S-1-5-21-2647865256-2038945071-357464061-1008..\Run: [Vidalia] C:\Program Files\Vidalia Bundle\Vidalia\vidalia.exe ()
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\CallWave.lnk = C:\Program Files\CallWave\IAM.exe (CallWave, Inc.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\CallWave.lnk.disabled ()
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Windows Desktop Search.lnk = C:\Program Files\MSN Toolbar Suite\DS\02.05.0001.1119\en-us\bin\WindowsSearch.exe File not found
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoControlPanel = 0
O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-21-2647865256-2038945071-357464061-1008\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-2647865256-2038945071-357464061-1008\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O8 - Extra context menu item: &ieSpell Options - C:\Program Files\ieSpell\iespell.dll (Red Egg Software)
O8 - Extra context menu item: Check &Spelling - C:\Program Files\ieSpell\iespell.dll (Red Egg Software)
O8 - Extra context menu item: ImTranslator - C:\Program Files\Smart Link\ImTranslator for IE\startup.html ()
O8 - Extra context menu item: Lookup on Merriam Webster - C:\Program Files\ieSpell\Merriam Webster.HTM ()
O8 - Extra context menu item: Lookup on Wikipedia - C:\Program Files\ieSpell\wikipedia.HTM ()
O9 - Extra Button: ieSpell - {0E17D5B7-9F5D-4fee-9DF6-CA6EE38B68A8} - C:\Program Files\ieSpell\iespell.dll (Red Egg Software)
O9 - Extra 'Tools' menuitem : ieSpell - {0E17D5B7-9F5D-4fee-9DF6-CA6EE38B68A8} - C:\Program Files\ieSpell\iespell.dll (Red Egg Software)
O9 - Extra 'Tools' menuitem : ieSpell Options - {1606D6F9-9D3B-4aea-A025-ED5B2FD488E7} - C:\Program Files\ieSpell\iespell.dll (Red Egg Software)
O12 - Plugin for: .spop - C:\Program Files\Internet Explorer\PLUGINS\NPDocBox.dll (InterTrust Technologies Corporation, Inc.)
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000}
http://download.macromedia.com/pub/shockwave/cabs/director/sw.cab (Reg Error: Key error.)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700}
http://go.microsoft.com/fwlink/?linkid=39204 (Windows Genuine Advantage Validation Tool)
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE}
http://security.symantec.com/sscv6/SharedContent/vc/bin/AvSniff.cab (Symantec AntiVirus scanner)
O16 - DPF: {33564D57-9980-0010-8000-00AA00389B71}
http://download.microsoft.com/download/D/0/D/D0DD87DA-994F-4334-8B55-AF2E4D98ED0C/wmv9dmo.cab (Reg Error: Key error.)
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5}
http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab (Symantec RuFSI Utility Class)
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5}
http://download.eset.com/special/eos/OnlineScanner.cab (Reg Error: Key error.)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93}
http://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab (Java Plug-in 1.6.0_22)
O16 - DPF: {9191F686-7F0A-441D-8A98-2FE3AC1BD913}
http://acs.pandasoftware.com/activescan/cabs/as2stubie.cab (ActiveScan 2.0 Installer Class)
O16 - DPF: {BB383206-6DA1-4E80-B62A-3DF950FCC697}
http://ak.imgag.com/imgag/cp/install/AxCtp2.cab (Create & Print ActiveX Plug-in)
O16 - DPF: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab (Java Plug-in 1.6.0_22)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab (Java Plug-in 1.6.0_22)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000}
http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab (Shockwave Flash Object)
O16 - DPF: Microsoft XML Parser for Java file://C:\WINDOWS\Java\classes\xmldso.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.254 192.168.1.254
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\!SASWinLogon: DllName - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL (SUPERAntiSpyware.com)
O20 - Winlogon\Notify\igfxcui: DllName - igfxsrvc.dll - C:\WINDOWS\System32\igfxsrvc.dll (Intel Corporation)
O24 - Desktop WallPaper: C:\Documents and Settings\ADMIN\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\ADMIN\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O28 - HKLM ShellExecuteHooks: {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - C:\Program Files\SUPERAntiSpyware\SASSEH.DLL (SuperAdBlocker.com)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2002/04/20 04:16:39 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O32 - AutoRun File - [2009/06/18 06:24:46 | 000,000,000 | ---D | M] - C:\AutoRuns -- [ NTFS ]
O32 - AutoRun File - [2001/07/28 07:07:38 | 000,000,000 | ---- | M] () - D:\AUTOEXEC.BAT -- [ FAT32 ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKU\S-1-5-21-2647865256-2038945071-357464061-1008\...com [@ = comfile] -- Reg Error: Key error. File not found
NetSvcs: 6to4 - File not found
NetSvcs: AppMgmt - C:\WINDOWS\System32\appmgmts.dll File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found
MsConfig - StartUpFolder: C:^Documents and Settings^ADMIN^Start Menu^Programs^Startup^setup_9.0.0.722_02.11.2010_10-07.lnk - C:\Documents and Settings\ADMIN\Desktop\Virus Removal Tool\setup_9.0.0.722_02.11.2010_10-07\startup.exe - ()
MsConfig - State: "system.ini" - 0
MsConfig - State: "win.ini" - 0
MsConfig - State: "bootini" - 0
MsConfig - State: "services" - 0
MsConfig - State: "startup" - 0
Drivers32: midi - C:\WINDOWS\System32\wdmaud.drv (Microsoft Corporation)
Drivers32: midi1 - C:\WINDOWS\System32\wdmaud.drv (Microsoft Corporation)
Drivers32: midi2 - C:\WINDOWS\System32\wdmaud.drv (Microsoft Corporation)
Drivers32: midi3 - C:\WINDOWS\System32\wdmaud.drv (Microsoft Corporation)
Drivers32: midimapper - C:\WINDOWS\System32\midimap.dll (Microsoft Corporation)
Drivers32: mixer - C:\WINDOWS\System32\wdmaud.drv (Microsoft Corporation)
Drivers32: mixer1 - C:\WINDOWS\System32\wdmaud.drv (Microsoft Corporation)
Drivers32: mixer2 - C:\WINDOWS\System32\wdmaud.drv (Microsoft Corporation)
Drivers32: msacm.iac2 - C:\WINDOWS\system32\iac25_32.ax (Intel Corporation)
Drivers32: msacm.imaadpcm - C:\WINDOWS\System32\imaadp32.acm (Microsoft Corporation)
Drivers32: msacm.l3acm - C:\WINDOWS\system32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.msadpcm - C:\WINDOWS\System32\msadp32.acm (Microsoft Corporation)
Drivers32: msacm.msaudio1 - C:\WINDOWS\System32\msaud32.acm (Microsoft Corporation)
Drivers32: msacm.msg711 - C:\WINDOWS\System32\msg711.acm (Microsoft Corporation)
Drivers32: msacm.msg723 - C:\WINDOWS\System32\msg723.acm (Microsoft Corporation)
Drivers32: msacm.msgsm610 - C:\WINDOWS\System32\msgsm32.acm (Microsoft Corporation)
Drivers32: msacm.sl_anet - C:\WINDOWS\System32\sl_anet.acm (Sipro Lab Telecom Inc.)
Drivers32: msacm.trspch - C:\WINDOWS\System32\tssoft32.acm (DSP GROUP, INC.)
Drivers32: vidc.cvid - C:\WINDOWS\System32\iccvid.dll (Radius Inc.)
Drivers32: vidc.I420 - C:\WINDOWS\System32\msh263.drv (Microsoft Corporation)
Drivers32: vidc.iv31 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv32 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv41 - C:\WINDOWS\System32\ir41_32.ax (Intel Corporation)
Drivers32: vidc.iv50 - C:\WINDOWS\System32\ir50_32.dll (Intel Corporation)
Drivers32: vidc.iyuv - C:\WINDOWS\System32\iyuv_32.dll (Microsoft Corporation)
Drivers32: vidc.M261 - C:\WINDOWS\System32\msh261.drv (Microsoft Corporation)
Drivers32: vidc.M263 - C:\WINDOWS\System32\msh263.drv (Microsoft Corporation)
Drivers32: vidc.mrle - C:\WINDOWS\System32\msrle32.dll (Microsoft Corporation)
Drivers32: vidc.msvc - C:\WINDOWS\System32\msvidc32.dll (Microsoft Corporation)
Drivers32: vidc.uyvy - C:\WINDOWS\System32\msyuv.dll (Microsoft Corporation)
Drivers32: vidc.yuy2 - C:\WINDOWS\System32\msyuv.dll (Microsoft Corporation)
Drivers32: vidc.yvu9 - C:\WINDOWS\System32\tsbyuv.dll (Microsoft Corporation)
Drivers32: vidc.yvyu - C:\WINDOWS\System32\msyuv.dll (Microsoft Corporation)
Drivers32: wave - C:\WINDOWS\System32\wdmaud.drv (Microsoft Corporation)
Drivers32: wave1 - C:\WINDOWS\System32\wdmaud.drv (Microsoft Corporation)
Drivers32: wave2 - C:\WINDOWS\System32\wdmaud.drv (Microsoft Corporation)
Drivers32: wavemapper - C:\WINDOWS\System32\msacm32.drv (Microsoft Corporation)
CREATERESTOREPOINT
Restore point Set: OTL Restore Point (16902053519425536)
========== Files/Folders - Created Within 30 Days ========== [2010/11/14 05:46:05 | 000,575,488 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\ADMIN\Desktop\OTL.exe
[2010/11/14 05:12:14 | 000,000,000 | ---D | C] -- C:\Documents and Settings\ADMIN\Desktop\BLEEPINCCOMPUTER FIX 13 NOV
[2010/11/14 03:19:57 | 000,000,000 | ---D | C] -- C:\Documents and Settings\ADMIN\Desktop\MBAM LOGS QUARANTINE KEEP
[2010/11/13 10:50:22 | 000,000,000 | ---D | C] -- C:\WINDOWS\LastGood
[2010/11/13 09:12:13 | 000,000,000 | ---D | C] -- C:\Documents and Settings\ADMIN\Desktop\GnuPG
[2010/11/13 08:59:16 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\{CFBD8779-FAAB-4357-84F2-1EC8619FADA6}
[2010/11/13 01:44:33 | 000,000,000 | ---D | C] -- C:\Documents and Settings\ADMIN\Desktop\sams luck DELETE
[2010/11/12 01:38:07 | 000,000,000 | ---D | C] -- C:\Documents and Settings\ADMIN\Local Settings\Application Data\PackageAware
[2010/11/10 20:59:08 | 000,000,000 | ---D | C] -- C:\Documents and Settings\ADMIN\Application Data\SUPERAntiSpyware.com
[2010/11/10 20:57:57 | 000,000,000 | ---D | C] -- C:\Program Files\SUPERAntiSpyware
[2010/11/10 10:32:34 | 000,000,000 | RH-D | C] -- C:\Documents and Settings\ADMIN\Recent
[2010/11/10 09:32:11 | 000,000,000 | ---D | C] -- C:\Documents and Settings\ADMIN\Application Data\MSN Search Toolbar
[2010/11/07 23:45:40 | 000,000,000 | ---D | C] -- C:\Documents and Settings\ADMIN\Application Data\Tor
[2010/11/07 23:45:28 | 000,000,000 | ---D | C] -- C:\Documents and Settings\ADMIN\Application Data\Vidalia
[2010/11/07 23:45:11 | 000,000,000 | ---D | C] -- C:\Program Files\Vidalia Bundle
[2010/11/07 02:41:30 | 000,000,000 | ---D | C] -- C:\## aswSnx private storage
[2010/11/02 10:58:47 | 000,315,408 | ---- | C] (Kaspersky Lab) -- C:\WINDOWS\System32\drivers\1748698.sys
[2010/11/02 10:58:47 | 000,128,016 | ---- | C] (Kaspersky Lab) -- C:\WINDOWS\System32\drivers\17486981.sys
[2010/11/02 10:58:47 | 000,037,392 | ---- | C] (Kaspersky Lab) -- C:\WINDOWS\System32\drivers\17486982.sys
[2010/11/02 10:58:46 | 000,000,000 | ---D | C] -- C:\Documents and Settings\ADMIN\Desktop\Virus Removal Tool
[2010/11/01 05:20:48 | 000,000,000 | ---D | C] -- C:\Documents and Settings\ADMIN\Application Data\QuickScan
[2010/10/31 06:58:50 | 000,000,000 | ---D | C] -- C:\Documents and Settings\ADMIN\Desktop\DESKTOP DOWNLOAD FOLDER
[2010/10/30 23:46:25 | 000,037,392 | ---- | C] (Kaspersky Lab) -- C:\WINDOWS\System32\drivers\87109712.sys
[2010/10/30 23:44:26 | 000,315,408 | ---- | C] (Kaspersky Lab) -- C:\WINDOWS\System32\drivers\8710971.sys
[2010/10/30 06:28:16 | 000,000,000 | ---D | C] -- C:\Documents and Settings\ADMIN\My Documents\Downloads
[2010/10/28 01:15:54 | 000,000,000 | ---D | C] -- C:\VKBOMBirus Removal Tool
[2010/10/27 00:21:01 | 000,038,848 | ---- | C] (AVAST Software) -- C:\WINDOWS\avastSS.scr
[2010/10/27 00:20:30 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Alwil Software
[2010/10/26 08:05:21 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Kaspersky Lab Setup Files
[2010/10/25 18:46:59 | 002,424,560 | ---- | C] (SUPERAntiSpyware.com) -- C:\Documents and Settings\ADMIN\Desktop\SUPERAntiSpyware.exe
[2010/10/25 02:36:56 | 000,000,000 | ---D | C] -- C:\Documents and Settings\ADMIN\Desktop\BC FIX 24 OCT 2010
[2010/10/23 02:54:05 | 000,000,000 | ---D | C] -- C:\Documents and Settings\ADMIN\Desktop\ATT&T EMAIL
[2010/10/22 05:40:41 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Sun
[2010/10/22 05:40:29 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Java
[2010/10/17 06:53:33 | 000,000,000 | ---D | C] -- C:\Documents and Settings\ADMIN\My Documents\MALWARE LOGS
[2010/10/16 01:13:53 | 000,000,000 | ---D | C] -- C:\Documents and Settings\ADMIN\My Documents\MY SCANNED STUFF
========== Files - Modified Within 30 Days ========== [2010/11/14 05:53:50 | 000,050,477 | ---- | M] () -- C:\Documents and Settings\ADMIN\Desktop\Defogger.exe
[2010/11/14 05:46:05 | 000,575,488 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\ADMIN\Desktop\OTL.exe
[2010/11/14 05:33:44 | 000,288,107 | ---- | M] () -- C:\Documents and Settings\ADMIN\Desktop\gmer.zip
[2010/11/13 10:55:29 | 000,000,186 | ---- | M] () -- C:\WINDOWS\System\hpsysdrv.DAT
[2010/11/13 10:46:26 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2010/11/13 01:17:36 | 000,027,163 | ---- | M] () -- C:\Documents and Settings\ADMIN\My Documents\COMODO LOG 8
[2010/11/12 07:12:20 | 000,002,577 | ---- | M] () -- C:\WINDOWS\System32\CONFIG.NT
[2010/11/11 10:25:39 | 000,000,284 | -HS- | M] () -- C:\BOOT.INI
[2010/11/11 07:48:36 | 000,033,583 | ---- | M] () -- C:\Documents and Settings\ADMIN\My Documents\COMODO LOG 7
[2010/11/11 00:05:44 | 002,424,560 | ---- | M] (SUPERAntiSpyware.com) -- C:\Documents and Settings\ADMIN\Desktop\SUPERAntiSpyware.exe
[2010/11/07 07:02:51 | 000,025,600 | ---- | M] () -- C:\Documents and Settings\ADMIN\Desktop\LETTER.wps
[2010/11/07 00:14:39 | 000,001,476 | ---- | M] () -- C:\Documents and Settings\ADMIN\Desktop\CallWave.lnk
[2010/11/07 00:14:38 | 000,001,492 | ---- | M] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Startup\CallWave.lnk
[2010/11/06 06:01:58 | 000,000,538 | ---- | M] () -- C:\Documents and Settings\ADMIN\My Documents\cc_20101106_060149.reg
[2010/11/06 06:00:37 | 000,004,634 | ---- | M] () -- C:\Documents and Settings\ADMIN\My Documents\cc_20101106_055935.reg
[2010/11/04 20:48:25 | 000,001,514 | ---- | M] () -- C:\Documents and Settings\ADMIN\Desktop\Paint (2).lnk
[2010/11/02 11:03:16 | 000,313,276 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat
[2010/11/02 11:03:16 | 000,040,868 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat
[2010/11/02 10:43:34 | 000,016,384 | ---- | M] () -- C:\Documents and Settings\ADMIN\My Documents\VOTE POST.wps
[2010/11/01 05:21:32 | 000,000,775 | ---- | M] () -- C:\Documents and Settings\ADMIN\Desktop\QuickScan Folder.lnk
[2010/10/31 03:44:29 | 000,020,992 | ---- | M] () -- C:\Documents and Settings\ADMIN\Desktop\SPELL CHECK.wps
[2010/10/31 03:18:15 | 000,000,000 | ---- | M] () -- C:\Documents and Settings\ADMIN\defogger_reenable
[2010/10/30 19:15:03 | 000,000,850 | ---- | M] () -- C:\Documents and Settings\ADMIN\Desktop\COMODO Internet Security.lnk
[2010/10/28 01:21:22 | 000,002,165 | ---- | M] () -- C:\Documents and Settings\ADMIN\Desktop\Start.lnk
[2010/10/25 22:42:16 | 000,016,558 | ---- | M] () -- C:\Documents and Settings\ADMIN\My Documents\EVIL LITTLE CREATURES.htm
========== Files Created - No Company Name ========== [2010/11/14 05:53:46 | 000,050,477 | ---- | C] () -- C:\Documents and Settings\ADMIN\Desktop\Defogger.exe
[2010/11/14 05:33:13 | 000,288,107 | ---- | C] () -- C:\Documents and Settings\ADMIN\Desktop\gmer.zip
[2010/11/13 01:17:36 | 000,027,163 | ---- | C] () -- C:\Documents and Settings\ADMIN\My Documents\COMODO LOG 8
[2010/11/11 07:48:36 | 000,033,583 | ---- | C] () -- C:\Documents and Settings\ADMIN\My Documents\COMODO LOG 7
[2010/11/07 00:14:39 | 000,001,476 | ---- | C] () -- C:\Documents and Settings\ADMIN\Desktop\CallWave.lnk
[2010/11/07 00:14:36 | 000,001,492 | ---- | C] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Startup\CallWave.lnk
[2010/11/06 06:01:54 | 000,000,538 | ---- | C] () -- C:\Documents and Settings\ADMIN\My Documents\cc_20101106_060149.reg
[2010/11/06 05:59:51 | 000,004,634 | ---- | C] () -- C:\Documents and Settings\ADMIN\My Documents\cc_20101106_055935.reg
[2010/11/02 23:56:33 | 000,001,819 | ---- | C] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk
[2010/11/02 23:56:33 | 000,001,492 | ---- | C] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Startup\CallWave.lnk.disabled
[2010/11/02 23:56:31 | 000,002,180 | ---- | C] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Windows Desktop Search.lnk
[2010/11/02 10:43:33 | 000,016,384 | ---- | C] () -- C:\Documents and Settings\ADMIN\My Documents\VOTE POST.wps
[2010/11/01 05:21:20 | 000,000,775 | ---- | C] () -- C:\Documents and Settings\ADMIN\Desktop\QuickScan Folder.lnk
[2010/10/31 03:18:15 | 000,000,000 | ---- | C] () -- C:\Documents and Settings\ADMIN\defogger_reenable
[2010/10/30 19:36:55 | 000,002,165 | ---- | C] () -- C:\Documents and Settings\ADMIN\Desktop\Start.lnk
[2010/10/25 22:42:15 | 000,016,558 | ---- | C] () -- C:\Documents and Settings\ADMIN\My Documents\EVIL LITTLE CREATURES.htm
[2009/11/02 05:39:06 | 000,000,754 | ---- | C] () -- C:\WINDOWS\WORDPAD.INI
[2009/06/08 02:55:20 | 000,004,608 | ---- | C] () -- C:\Documents and Settings\ADMIN\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009/06/06 01:35:17 | 000,077,824 | R--- | C] () -- C:\WINDOWS\System32\hpzids01.dll
[2009/06/06 00:40:36 | 000,003,188 | ---- | C] () -- C:\Documents and Settings\All Users\Application Data\hpzinstall.log
[2009/06/03 04:30:05 | 000,087,552 | ---- | C] () -- C:\WINDOWS\System32\cpwmon2k.dll
[2009/05/25 01:55:49 | 000,010,240 | ---- | C] () -- C:\WINDOWS\System32\vidx16.dll
[2009/05/25 01:50:36 | 000,000,021 | ---- | C] () -- C:\WINDOWS\CS_setup.ini
[2009/05/09 05:09:23 | 000,006,048 | ---- | C] () -- C:\WINDOWS\System32\MCC16.dll
[2009/05/09 05:06:40 | 000,040,448 | ---- | C] () -- C:\WINDOWS\System32\BJAXSecurityManager.dll
[2009/05/09 05:05:39 | 000,086,016 | ---- | C] () -- C:\WINDOWS\System32\BJInstaller.dll
[2009/05/03 03:28:22 | 000,143,096 | ---- | C] () -- C:\WINDOWS\System32\guard32.dll
[2009/05/03 03:15:05 | 000,000,057 | ---- | C] () -- C:\WINDOWS\dcmvwr.INI
[2009/05/03 02:29:50 | 000,000,058 | ---- | C] () -- C:\WINDOWS\BGH 2005 SS 1.ini
[2006/05/29 13:47:31 | 000,000,060 | ---- | C] () -- C:\WINDOWS\SIERRA.INI
[2006/05/29 13:47:29 | 000,000,055 | ---- | C] () -- C:\WINDOWS\KA.INI
[2006/02/21 15:22:46 | 008,940,869 | ---- | C] () -- C:\Program Files\Adobe.zip
[2006/02/02 15:04:29 | 000,363,520 | ---- | C] () -- C:\WINDOWS\System32\psisdecd.dll
[2006/02/01 23:06:51 | 000,094,208 | ---- | C] () -- C:\WINDOWS\System32\GTW32N50.dll
[2006/01/18 20:45:15 | 000,000,000 | ---- | C] () -- C:\WINDOWS\JDSecure31.INI
[2006/01/18 20:45:09 | 000,249,856 | ---- | C] () -- C:\WINDOWS\System32\LxrJD31.dll
[2006/01/18 20:45:09 | 000,069,824 | ---- | C] () -- C:\WINDOWS\System32\drivers\LxrJD31d.sys
[2006/01/18 20:45:09 | 000,061,440 | ---- | C] () -- C:\WINDOWS\System32\LxrJD20Sat.dll
[2005/12/30 21:10:01 | 000,000,024 | ---- | C] () -- C:\WINDOWS\Disney.ini
[2005/12/30 03:02:33 | 000,000,044 | ---- | C] () -- C:\WINDOWS\System32\msssc.dll
[2002/04/26 03:23:36 | 000,000,061 | ---- | C] () -- C:\WINDOWS\smscfg.ini
[2002/04/21 00:24:15 | 000,377,600 | ---- | C] () -- C:\WINDOWS\System32\BOCOLE.DLL
[2002/04/21 00:24:15 | 000,167,456 | ---- | C] () -- C:\WINDOWS\System32\Bocof.dll
[2002/04/21 00:16:42 | 000,045,056 | ---- | C] () -- C:\WINDOWS\System32\hpREG.DLL
[2002/04/21 00:16:42 | 000,024,576 | ---- | C] () -- C:\WINDOWS\System32\syscontr.dll
[2002/04/20 06:28:06 | 000,004,478 | ---- | C] () -- C:\WINDOWS\wininit.ini
[2002/04/20 06:19:46 | 000,019,968 | ---- | C] () -- C:\WINDOWS\System32\cpuinf32.dll
[2002/04/20 05:26:01 | 000,249,921 | ---- | C] () -- C:\WINDOWS\System32\PythonCOM15.dll
[2002/04/20 05:26:01 | 000,065,536 | ---- | C] () -- C:\WINDOWS\System32\PyWinTypes15.dll
[2002/04/20 05:25:32 | 000,016,896 | ---- | C] () -- C:\WINDOWS\System32\bcbmm.dll
[2002/04/20 04:20:31 | 000,000,799 | ---- | C] () -- C:\WINDOWS\orun32.ini
[2002/04/20 04:04:05 | 000,000,666 | ---- | C] () -- C:\WINDOWS\System32\oeminfo.ini
[2002/04/19 21:08:55 | 000,004,161 | ---- | C] () -- C:\WINDOWS\ODBCINST.INI
[2002/03/30 01:49:26 | 000,000,000 | ---- | C] () -- C:\WINDOWS\System32\px.ini
[2002/03/27 21:37:52 | 000,262,144 | ---- | C] () -- C:\WINDOWS\System32\shpshftr.dll
[2002/03/12 10:25:02 | 000,028,672 | ---- | C] () -- C:\WINDOWS\System32\igfxdgps.dll
[2001/09/01 05:33:58 | 000,425,984 | ---- | C] () -- C:\WINDOWS\System32\VxDMDcDlg.dll
[2001/08/08 20:13:22 | 000,012,351 | ---- | C] () -- C:\WINDOWS\System32\i81xcoin.dll
[2001/07/06 15:30:00 | 000,003,399 | ---- | C] () -- C:\WINDOWS\System32\hptcpmon.ini
[2001/06/19 14:20:14 | 000,037,408 | ---- | C] () -- C:\WINDOWS\System32\drivers\SbcpHid.sys
[1997/06/18 06:00:00 | 001,672,976 | ---- | C] () -- C:\WINDOWS\System32\MSO97V.DLL
[1997/06/18 06:00:00 | 000,022,016 | ---- | C] () -- C:\WINDOWS\System32\DOCOBJ.DLL
[1997/06/18 06:00:00 | 000,012,288 | ---- | C] () -- C:\WINDOWS\System32\HLINKPRX.DLL
========== LOP Check ========== [2009/06/22 00:37:57 | 000,000,000 | ---D | M] -- C:\Documents and Settings\ADMIN\Application Data\Auslogics
[2009/05/10 19:18:16 | 000,000,000 | ---D | M] -- C:\Documents and Settings\ADMIN\Application Data\ieSpell
[2010/10/16 00:52:39 | 000,000,000 | ---D | M] -- C:\Documents and Settings\ADMIN\Application Data\Image Zone Express
[2002/04/20 06:04:24 | 000,000,000 | ---D | M] -- C:\Documents and Settings\ADMIN\Application Data\InterTrust
[2010/11/10 09:32:50 | 000,000,000 | ---D | M] -- C:\Documents and Settings\ADMIN\Application Data\MSN Search Toolbar
[2010/11/13 07:47:15 | 000,000,000 | ---D | M] -- C:\Documents and Settings\ADMIN\Application Data\NCH Swift Sound
[2009/11/03 01:45:25 | 000,000,000 | ---D | M] -- C:\Documents and Settings\ADMIN\Application Data\OpenOffice.org
[2010/11/02 08:55:59 | 000,000,000 | ---D | M] -- C:\Documents and Settings\ADMIN\Application Data\QuickScan
[2009/05/04 02:10:08 | 000,000,000 | ---D | M] -- C:\Documents and Settings\ADMIN\Application Data\Template
[2009/06/03 06:04:21 | 000,000,000 | ---D | M] -- C:\Documents and Settings\ADMIN\Application Data\TrueCrypt
[2002/04/20 06:23:48 | 000,000,000 | ---D | M] -- C:\Documents and Settings\ADMIN\Application Data\VERITAS
[2002/04/20 06:04:24 | 000,000,000 | ---D | M] -- C:\Documents and Settings\ADMIN WEB BROWSING\Application Data\InterTrust
[2010/11/10 00:43:37 | 000,000,000 | ---D | M] -- C:\Documents and Settings\ADMIN WEB BROWSING\Application Data\MSN Search Toolbar
[2002/04/20 06:23:48 | 000,000,000 | ---D | M] -- C:\Documents and Settings\ADMIN WEB BROWSING\Application Data\VERITAS
[2010/10/27 00:20:30 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Alwil Software
[2009/05/03 03:52:34 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Avg7
[2006/02/19 10:32:42 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\MSN Search Toolbar
[2010/08/05 21:26:45 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\NCH Swift Sound
[2006/07/20 12:58:43 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\WildTangent
[2010/11/13 08:59:16 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\{CFBD8779-FAAB-4357-84F2-1EC8619FADA6}
[2002/04/20 06:04:24 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Default User\Application Data\InterTrust
[2002/04/20 06:23:48 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Default User\Application Data\VERITAS
========== Purity Check ========== ========== Custom Scans ========== < %systemroot%\system32\*.dll /lockedfiles > < %systemroot%\system32\*.sys /90 >[2010/08/31 13:42:52 | 001,852,800 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\win32k.sys
< %systemroot%\Tasks\*.job /lockedfiles > < %systemroot%\System32\config\*.sav >[2002/04/19 21:07:21 | 000,090,112 | ---- | M] () -- C:\WINDOWS\system32\config\default.sav
[2002/04/19 21:07:21 | 000,606,208 | ---- | M] () -- C:\WINDOWS\system32\config\software.sav
[2002/04/19 21:07:21 | 000,376,832 | ---- | M] () -- C:\WINDOWS\system32\config\system.sav
< %SYSTEMDRIVE%\*.* >[2002/04/20 04:16:39 | 000,000,000 | ---- | M] () -- C:\AUTOEXEC.BAT
[2009/05/09 05:14:20 | 019,624,680 | ---- | M] () -- C:\BellSouthIW.re~
[2009/06/10 01:53:35 | 000,000,200 | ---- | M] () -- C:\Boot.bak
[2010/11/11 10:25:39 | 000,000,284 | -HS- | M] () -- C:\BOOT.INI
[2009/06/28 07:34:25 | 000,000,700 | ---- | M] () -- C:\Bug.txt
[2004/08/03 22:00:00 | 000,260,272 | ---- | M] () -- C:\cmldr
[2002/04/20 04:16:39 | 000,000,000 | ---- | M] () -- C:\CONFIG.SYS
[2009/11/28 03:55:54 | 000,000,000 | ---- | M] () -- C:\Documents
[2002/04/26 02:45:35 | 000,012,919 | ---- | M] () -- C:\FINIS_IT.TXT
[2002/04/20 04:16:39 | 000,000,000 | RHS- | M] () -- C:\IO.SYS
[2010/01/28 01:41:45 | 002,854,351 | ---- | M] () -- C:\Microburner.log
[2002/04/20 04:16:39 | 000,000,000 | RHS- | M] () -- C:\MSDOS.SYS
[2006/02/23 18:55:46 | 000,047,564 | RHS- | M] () -- C:\NTDETECT.COM
[2009/05/16 20:24:39 | 000,250,048 | RHS- | M] () -- C:\ntldr
[2010/11/13 10:46:22 | 2621,440,000 | -HS- | M] () -- C:\pagefile.sys
< %systemroot%\system32\Spool\prtprocs\w32x86\*.dll >[2005/10/14 21:41:46 | 000,072,192 | ---- | M] (Hewlett-Packard Corporation) -- C:\WINDOWS\system32\spool\prtprocs\w32x86\hpzpp43a.dll
< %systemroot%\*. /mp /s > < HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU > ========== Alternate Data Streams ========== @Alternate Data Stream - 88 bytes -> C:\Program Files\Comodo\Comodo Internet Security\cfp.exe:SummaryInformation
@Alternate Data Stream - 88 bytes -> C:\Documents and Settings\ADMIN\Desktop\SUPERAntiSpyware.exe:SummaryInformation
@Alternate Data Stream - 88 bytes -> C:\Documents and Settings\ADMIN\Desktop\mbk622n2.exe:SummaryInformation
< End of report >
GMER 1.0.15.15530 -
http://www.gmer.netRootkit scan 2010-11-14 10:25:43
Windows 5.1.2600 Service Pack 3 Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-3 SAMSUNG_SV6003H rev.QQ100-07
Running: gmer.exe; Driver: C:\DOCUME~1\ADMIN\LOCALS~1\Temp\fwdiqkog.sys
---- System - GMER 1.0.15 ----
SSDT \SystemRoot\System32\DRIVERS\cmdguard.sys (COMODO Internet Security Sandbox Driver/COMODO) ZwAdjustPrivilegesToken [0xF7FB97B6]
SSDT \SystemRoot\System32\DRIVERS\cmdguard.sys (COMODO Internet Security Sandbox Driver/COMODO) ZwConnectPort [0xF7FB8D16]
SSDT \SystemRoot\System32\DRIVERS\cmdguard.sys (COMODO Internet Security Sandbox Driver/COMODO) ZwCreateFile [0xF7FB9372]
SSDT \SystemRoot\System32\DRIVERS\cmdguard.sys (COMODO Internet Security Sandbox Driver/COMODO) ZwCreateKey [0xF7FB9F80]
SSDT \SystemRoot\System32\DRIVERS\cmdguard.sys (COMODO Internet Security Sandbox Driver/COMODO) ZwCreatePort [0xF7FB8A70]
SSDT \SystemRoot\System32\DRIVERS\cmdguard.sys (COMODO Internet Security Sandbox Driver/COMODO) ZwCreateSection [0xF7FBAC70]
SSDT \SystemRoot\System32\DRIVERS\cmdguard.sys (COMODO Internet Security Sandbox Driver/COMODO) ZwCreateSymbolicLinkObject [0xF7FB999C]
SSDT \SystemRoot\System32\DRIVERS\cmdguard.sys (COMODO Internet Security Sandbox Driver/COMODO) ZwCreateThread [0xF7FB8646]
SSDT \SystemRoot\System32\DRIVERS\cmdguard.sys (COMODO Internet Security Sandbox Driver/COMODO) ZwDeleteKey [0xF7FB9BEA]
SSDT \SystemRoot\System32\DRIVERS\cmdguard.sys (COMODO Internet Security Sandbox Driver/COMODO) ZwDeleteValueKey [0xF7FB9D9A]
SSDT \SystemRoot\System32\DRIVERS\cmdguard.sys (COMODO Internet Security Sandbox Driver/COMODO) ZwDuplicateObject [0xF7FB84F8]
SSDT \SystemRoot\System32\DRIVERS\cmdguard.sys (COMODO Internet Security Sandbox Driver/COMODO) ZwLoadDriver [0xF7FBA8F2]
SSDT \SystemRoot\System32\DRIVERS\cmdguard.sys (COMODO Internet Security Sandbox Driver/COMODO) ZwMakeTemporaryObject [0xF7FB8F5C]
SSDT \SystemRoot\System32\DRIVERS\cmdguard.sys (COMODO Internet Security Sandbox Driver/COMODO) ZwOpenFile [0xF7FB95AA]
SSDT \SystemRoot\System32\DRIVERS\cmdguard.sys (COMODO Internet Security Sandbox Driver/COMODO) ZwOpenProcess [0xF7FB8228]
SSDT \SystemRoot\System32\DRIVERS\cmdguard.sys (COMODO Internet Security Sandbox Driver/COMODO) ZwOpenSection [0xF7FB91EC]
SSDT \SystemRoot\System32\DRIVERS\cmdguard.sys (COMODO Internet Security Sandbox Driver/COMODO) ZwOpenThread [0xF7FB83A0]
SSDT \SystemRoot\System32\DRIVERS\cmdguard.sys (COMODO Internet Security Sandbox Driver/COMODO) ZwRenameKey [0xF7FBA346]
SSDT \SystemRoot\System32\DRIVERS\cmdguard.sys (COMODO Internet Security Sandbox Driver/COMODO) ZwRequestWaitReplyPort [0xF7FB8B8E]
SSDT \SystemRoot\System32\DRIVERS\cmdguard.sys (COMODO Internet Security Sandbox Driver/COMODO) ZwSecureConnectPort [0xF7FBA6AA]
SSDT \SystemRoot\System32\DRIVERS\cmdguard.sys (COMODO Internet Security Sandbox Driver/COMODO) ZwSetSystemInformation [0xF7FBAAA0]
SSDT \SystemRoot\System32\DRIVERS\cmdguard.sys (COMODO Internet Security Sandbox Driver/COMODO) ZwSetValueKey [0xF7FBA146]
SSDT \SystemRoot\System32\DRIVERS\cmdguard.sys (COMODO Internet Security Sandbox Driver/COMODO) ZwShutdownSystem [0xF7FB8EF6]
SSDT \SystemRoot\System32\DRIVERS\cmdguard.sys (COMODO Internet Security Sandbox Driver/COMODO) ZwSystemDebugControl [0xF7FB90E0]
SSDT \SystemRoot\System32\DRIVERS\cmdguard.sys (COMODO Internet Security Sandbox Driver/COMODO) ZwTerminateProcess [0xF7FB893A]
SSDT \SystemRoot\System32\DRIVERS\cmdguard.sys (COMODO Internet Security Sandbox Driver/COMODO) ZwTerminateThread [0xF7FB8808]
---- Kernel code sections - GMER 1.0.15 ----
.text ntoskrnl.exe!_abnormal_termination + 148 804E27B4 4 Bytes JMP 27F7FB9B
---- User code sections - GMER 1.0.15 ----
.text C:\Program Files\Mozilla Firefox\firefox.exe[1060] ntdll.dll!LdrLoadDll 7C9163C3 5 Bytes JMP 004013F0 C:\Program Files\Mozilla Firefox\firefox.exe (Firefox/Mozilla Corporation)
---- Disk sectors - GMER 1.0.15 ----
Disk \Device\Harddisk0\DR0 sector 01: copy of MBR
Disk \Device\Harddisk0\DR0 sector 02: copy of MBR
Disk \Device\Harddisk0\DR0 sector 03: copy of MBR
Disk \Device\Harddisk0\DR0 sector 04: copy of MBR
Disk \Device\Harddisk0\DR0 sector 05: copy of MBR
Disk \Device\Harddisk0\DR0 sector 06: copy of MBR
Disk \Device\Harddisk0\DR0 sector 07: copy of MBR
Disk \Device\Harddisk0\DR0 sector 08: copy of MBR
Disk \Device\Harddisk0\DR0 sector 09: copy of MBR
Disk \Device\Harddisk0\DR0 sector 10: copy of MBR
Disk \Device\Harddisk0\DR0 sector 11: copy of MBR
Disk \Device\Harddisk0\DR0 sector 12: copy of MBR
Disk \Device\Harddisk0\DR0 sector 13: copy of MBR
Disk \Device\Harddisk0\DR0 sector 14: copy of MBR
Disk \Device\Harddisk0\DR0 sector 15: copy of MBR
Disk \Device\Harddisk0\DR0 sector 16: copy of MBR
Disk \Device\Harddisk0\DR0 sector 17: copy of MBR
Disk \Device\Harddisk0\DR0 sector 18: copy of MBR
Disk \Device\Harddisk0\DR0 sector 19: copy of MBR
Disk \Device\Harddisk0\DR0 sector 20: copy of MBR
Disk \Device\Harddisk0\DR0 sector 21: copy of MBR
Disk \Device\Harddisk0\DR0 sector 22: copy of MBR
Disk \Device\Harddisk0\DR0 sector 23: copy of MBR
Disk \Device\Harddisk0\DR0 sector 24: copy of MBR
Disk \Device\Harddisk0\DR0 sector 25: copy of MBR
Disk \Device\Harddisk0\DR0 sector 26: copy of MBR
Disk \Device\Harddisk0\DR0 sector 27: copy of MBR
Disk \Device\Harddisk0\DR0 sector 28: copy of MBR
Disk \Device\Harddisk0\DR0 sector 29: copy of MBR
Disk \Device\Harddisk0\DR0 sector 30: copy of MBR
Disk \Device\Harddisk0\DR0 sector 31: copy of MBR
Disk \Device\Harddisk0\DR0 sector 32: copy of MBR
Disk \Device\Harddisk0\DR0 sector 33: copy of MBR
Disk \Device\Harddisk0\DR0 sector 34: copy of MBR
Disk \Device\Harddisk0\DR0 sector 35: copy of MBR
Disk \Device\Harddisk0\DR0 sector 36: copy of MBR
Disk \Device\Harddisk0\DR0 sector 37: copy of MBR
Disk \Device\Harddisk0\DR0 sector 38: copy of MBR
Disk \Device\Harddisk0\DR0 sector 39: copy of MBR
Disk \Device\Harddisk0\DR0 sector 40: copy of MBR
Disk \Device\Harddisk0\DR0 sector 41: copy of MBR
Disk \Device\Harddisk0\DR0 sector 42: copy of MBR
Disk \Device\Harddisk0\DR0 sector 43: copy of MBR
Disk \Device\Harddisk0\DR0 sector 44: copy of MBR
Disk \Device\Harddisk0\DR0 sector 45: copy of MBR
Disk \Device\Harddisk0\DR0 sector 46: copy of MBR
Disk \Device\Harddisk0\DR0 sector 47: copy of MBR
Disk \Device\Harddisk0\DR0 sector 48: copy of MBR
Disk \Device\Harddisk0\DR0 sector 49: copy of MBR
Disk \Device\Harddisk0\DR0 sector 50: copy of MBR
Disk \Device\Harddisk0\DR0 sector 51: copy of MBR
Disk \Device\Harddisk0\DR0 sector 52: copy of MBR
Disk \Device\Harddisk0\DR0 sector 53: copy of MBR
Disk \Device\Harddisk0\DR0 sector 54: copy of MBR
Disk \Device\Harddisk0\DR0 sector 55: copy of MBR
Disk \Device\Harddisk0\DR0 sector 56: copy of MBR
Disk \Device\Harddisk0\DR0 sector 57: copy of MBR
Disk \Device\Harddisk0\DR0 sector 58: copy of MBR
Disk \Device\Harddisk0\DR0 sector 59: copy of MBR
Disk \Device\Harddisk0\DR0 sector 60: copy of MBR
Disk \Device\Harddisk0\DR0 sector 61: copy of MBR
Disk \Device\Harddisk0\DR0 sector 62: rootkit-like behavior; copy of MBR
Disk \Device\Harddisk0\DR0 sector 63: rootkit-like behavior; copy of MBR
---- EOF - GMER 1.0.15 ----
See anything that looks EVIL in any of that stuff?
Thanks for your time.
Wendy
TRUST NO ONE...! EXCEPT For The Beloved Computer Geek Helping You In The MALWARE FORUMS.
Do Unto Others Before They Have A Chance To Do Unto You.
HP Pavilion 512n [Rescued from a pile of trash on the side of the road] 128 MB SDRAM, 60 GB Hard Drive, Windows XP, Home Edition, SP3, COMODO Anti Vitus and Firewall.