Jump to content

Recommended Posts

Posted

My wife's Dell Studio one, running Vista home hangs where even basic internal programs like word or 'restore' wont work or just 'not responding'. I have tried a vista disk 'repair' and it did allow me to see that device driver had no X's against any hardware. The MS fireguard was in operation all the time.

 

The problem is that It wont go on the net to download any antiviral ware or anything else that will help me to detox the thing.

 

I do have this machine running and my wife has a laptop that works fine.

I do have the Vista 'installation disk' that came with it so I am prepared for a re-installation if that's necessary.

Cheers

jim

  • Replies 25
  • Created
  • Last Reply

Top Posters In This Topic

Posted (edited)

Hi Jim, to help things along till one of our security guys gets to you and to save a bit of time, please follow everything below, Because you are not able to connect the machine to the net, download the items to another machine and transfer them using a memory stick, or pen drive or similar.--

 

Step 1

Download TFC by OldTimer to your desktop

  • Please double-click TFC.exe to run it. (Note: If you are running on Vista, right-click on the file and choose Run As Administrator).
  • It will close all programs when run, so make sure you have saved all your work before you begin.
  • Click the Start button to begin the process. Depending on how often you clean temp files, execution time should be anywhere from a few seconds to a minute or two. Let it run uninterrupted to completion.
  • Once it's finished it should reboot your machine. If it does not, please manually reboot the machine yourself to ensure a complete clean.

 

Step 2

Please download Malwarebytes Anti-Malware and save it to your desktop.

  • Make sure you are connected to the Internet.
  • Double-click on Download_mbam-setup.exe to install the application.
  • When the installation begins, follow the prompts and do not make any changes to default settings.
  • When installation has finished, make sure you leave both of these checked:
    • Update Malwarebytes' Anti-Malware
    • Launch Malwarebytes' Anti-Malware

     

    [*]Then click Finish.

    [*]MBAM will automatically start and you will be asked to update the program before performing a scan. If an update is found, the program will automatically update itself. Press the OK button to close that box and continue. If you encounter any problems while downloading the updates, manually download them from here and just double-click on mbam-rules.exe to install.

    [*]On the Scanner tab:

    • Make sure the "Perform Full Scan" option is selected.
    • Then click on the Scan button.

     

    [*]If asked to select the drives to scan, leave all the drives selected and click on the Start Scan button.

    [*]The scan will begin and "Scan in progress" will show at the top. It may take some time to complete so please be patient.

    [*]When the scan is finished, a message box will say "The scan completed successfully. Click 'Show Results' to display all objects found".

    [*]Click OK to close the message box and continue with the removal process.

    [*]Back at the main Scanner screen, click on the Show Results button to see a list of any malware that was found.

    [*]Make sure that everything is checked, and click Remove Selected.

    [*]When removal is completed, a log report will open in Notepad and you may be prompted to restart your computer. (see Note below)

    [*]The log is automatically saved and can be viewed by clicking the Logs tab in MBAM.

    [*]Copy and paste the contents of that report in your next reply and exit MBAM.

Note: If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts. Click OK to either and let MBAM proceed with the disinfection process. If asked to restart the computer, please do so immediately. Failure to reboot will prevent MBAM from removing all the malware.

 

 

Step 3

  • Download OTL to your desktop.
    if you have problems, try this download link:
    OTL
  • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output.
  • Check the boxes beside LOP Check and Purity Check

.

 

.

http://img.photobucket.com/albums/v708/starbuck50/new/newOtl2.png

  • Now copy the lines in the codebox below.
    Code:
    netsvcs
    msconfig
    %SYSTEMDRIVE%\*.exe
    /md5start
    eventlog.dll
    scecli.dll
    netlogon.dll
    cngaudit.dll
    sceclt.dll
    ntelogon.dll
    logevent.dll
    iaStor.sys
    nvstor.sys
    atapi.sys
    IdeChnDr.sys
    viasraid.sys
    AGP440.sys
    vaxscsi.sys
    nvatabus.sys
    viamraid.sys
    nvata.sys
    nvgts.sys
    iastorv.sys
    ViPrt.sys
    eNetHook.dll
    ahcix86.sys
    KR10N.sys
    nvstor32.sys
    ahcix86s.sys
    nvrd32.sys
    symmpi.sys
    adp3132.sys
    /md5stop
    %systemroot%\*. /mp /s
    %systemroot%\system32\*.dll /lockedfiles
    %systemroot%\Tasks\*.job /lockedfiles
    %systemroot%\system32\drivers\*.sys /lockedfiles
    CREATERESTOREPOINT
  • right click in the Custom Scans/Fixes window (under the blue bar) and choose Paste.
     
    http://img.photobucket.com/albums/v708/starbuck50/new%20forum/scan-fix.png
    .
  • Click the Run Scan button.
     
    http://img.photobucket.com/albums/v708/starbuck50/runscan.png
  • Do not change any settings unless otherwise told to do so. The scan wont take long.
  • When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.
  • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post them with your next reply.

 

In your next reply, please submit:

MBAM scan report

Both reports from OTL

 

 

Thanks.

Edited by Starbuck

 

Need help with your computer problems? Then why not join Free PC Help. Register

here

 

If Free PC Help has helped you then please consider a donation. Click here

 

We are all members helping other members.

Please return here where you may be able to help someone else.

After all, no one knows everything and you may have the answer that someone needs.

 

 

 

--------------------------------------------------------------------

I have installed Windows, now how do I install the curtains? :D

http://i7.photobucket.com/albums/y282/plasticpig/Nev2.gif

  • ExTS Admin
Posted

Hi mij,

 

Have you tried to access the internet using 'safe mode with networking'?

If it will connect that way.... try and download the programs that 'plastic nev' asked for directly to the infected system.

Member of:

UNITE

Posted
Hi mij,

 

Have you tried to access the internet using 'safe mode with networking'?

If it will connect that way.... try and download the programs that 'plastic nev' asked for directly to the infected system.

 

Thanks for that 'cuz it worked! Wossmore I was able to get to restore point and go back a month ago - before all these troubles began. That enabled it to boot back up in normal mode and connect online.

 

Ok am going through the detox anyway but nowt found so far.

I will post the files as requested.

cheers

jim

:)

  • ExTS Admin
Posted (edited)

Hi mij,

 

Glad to hear you had a bit of success with the problem.

 

Still post the:

MBAM scan report and both reports from OTL and i'll take a look and see if there's any leftovers on the system for you.

 

Ok am going through the detox anyway
I like that term, sounds good :thumb: Edited by Starbuck

Member of:

UNITE

Posted

transferred for vista

 

Hi mij,

 

Glad to hear you had a bit of success with the problem.

 

Still post the:

MBAM scan report and both reports from OTL and i'll take a look and see if there's any leftovers on the system for you.

 

I like that term, sounds good :thumb:

 

Even with the restored registry of the 27th june (a month ago) it still found a trojan 'bredolab' Malware bytes sorted it though.

Here are the logs, I've included the first mbam one as well as the second.

I hope they are in the right order - no doubt you'll let me know if they are not.

Cheers

jim

 

PS Shouldn't I have an OTF file log or sumpin? I dunno, I'm not used to this stuff.

 

 

Malwarebytes' Anti-Malware 1.44

Database version: 3615

Windows 6.0.6001 Service Pack 1

Internet Explorer 7.0.6001.18000

22/01/2010 19:01:38

mbam-log-2010-01-22 (19-01-38).txt

Scan type: Full Scan (C:\|D:\|)

Objects scanned: 318389

Time elapsed: 58 minute(s), 24 second(s)

Memory Processes Infected: 0

Memory Modules Infected: 0

Registry Keys Infected: 0

Registry Values Infected: 0

Registry Data Items Infected: 1

Folders Infected: 0

Files Infected: 2

Memory Processes Infected:

(No malicious items detected)

Memory Modules Infected:

(No malicious items detected)

Registry Keys Infected:

(No malicious items detected)

Registry Values Infected:

(No malicious items detected)

Registry Data Items Infected:

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoActiveDesktopChanges (Hijack.DisplayProperties) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.

Folders Infected:

(No malicious items detected)

Files Infected:

C:\$Recycle.Bin\S-1-5-21-3210984195-2674545727-4288912263-1000\$RMPNVYT.exe (Rogue.Installer) -> Quarantined and deleted successfully.

C:\Users\Helen\AppData\Roaming\avdrn.dat (Malware.Trace) -> Quarantined and deleted successfully.

 

Malwarebytes' Anti-Malware 1.46

www.malwarebytes.org

Database version: 4374

Windows 6.0.6001 Service Pack 1

Internet Explorer 7.0.6001.18000

31/07/2010 20:08:03

mbam-log-2010-07-31 (20-08-03).txt

Scan type: Full scan (C:\|D:\|)

Objects scanned: 229203

Time elapsed: 37 minute(s), 57 second(s)

Memory Processes Infected: 0

Memory Modules Infected: 0

Registry Keys Infected: 0

Registry Values Infected: 0

Registry Data Items Infected: 0

Folders Infected: 0

Files Infected: 1

Memory Processes Infected:

(No malicious items detected)

Memory Modules Infected:

(No malicious items detected)

Registry Keys Infected:

(No malicious items detected)

Registry Values Infected:

(No malicious items detected)

Registry Data Items Infected:

(No malicious items detected)

Folders Infected:

(No malicious items detected)

Files Infected:

C:\Program Files (x86)\Trend Micro\HijackThis\backups\backup-20100122-120940-917-rarype32.exe (Trojan.Bredolab) -> Quarantined and deleted successfully.

 

OTL logfile created on: 31/07/2010 17:54:39 - Run 1

OTL by OldTimer - Version 3.2.9.1 Folder = C:\Users\Helen\Desktop

64bit-Windows Vista Home Premium Edition Service Pack 1 (Version = 6.0.6001) - Type = NTWorkstation

Internet Explorer (Version = 7.0.6001.18000)

Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy

 

3.00 Gb Total Physical Memory | 2.00 Gb Available Physical Memory | 60.00% Memory free

6.00 Gb Paging File | 4.00 Gb Available in Paging File | 74.00% Paging File free

Paging file location(s): ?:\pagefile.sys [binary data]

 

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)

Drive C: | 451.07 Gb Total Space | 361.34 Gb Free Space | 80.11% Space Free | Partition Type: NTFS

Drive D: | 14.65 Gb Total Space | 13.59 Gb Free Space | 92.74% Space Free | Partition Type: NTFS

E: Drive not present or media not loaded

F: Drive not present or media not loaded

G: Drive not present or media not loaded

H: Drive not present or media not loaded

I: Drive not present or media not loaded

 

Computer Name: HELEN-PC

Current User Name: Helen

Logged in as Administrator.

 

Current Boot Mode: Normal

Scan Mode: Current user

Include 64bit Scans

Company Name Whitelist: Off

Skip Microsoft Files: Off

File Age = 30 Days

Output = Minimal

 

========== Processes (SafeList) ==========

 

PRC - C:\Users\Helen\Desktop\OTL.exe (OldTimer Tools)

PRC - C:\Program Files (x86)\Trusteer\Rapport\bin\RapportService.exe (Trusteer Ltd.)

PRC - C:\Program Files (x86)\Trusteer\Rapport\bin\RapportMgmtService.exe (Trusteer Ltd.)

PRC - C:\Program Files (x86)\TomTom HOME 2\TomTomHOMEService.exe (TomTom)

PRC - C:\Program Files (x86)\TomTom HOME 2\TomTomHOMERunner.exe (TomTom)

PRC - C:\Program Files (x86)\Spybot - Search & Destroy\TeaTimer.exe (Safer-Networking Ltd.)

PRC - C:\Program Files (x86)\Spybot - Search & Destroy\SDWinSec.exe (Safer Networking Ltd.)

PRC - C:\Program Files (x86)\Dell\OSD\AIO_OSD.exe (Dell Corporation)

PRC - C:\Program Files (x86)\Dell\OSD\OSDSvr.exe ()

PRC - C:\Program Files (x86)\Dell V505\dldwmsdmon.exe ()

PRC - C:\Program Files (x86)\Dell V505\dldwmon.exe ()

PRC - C:\Program Files (x86)\CyberLink\PowerDVD DX\PDVDDXSrv.exe (CyberLink Corp.)

PRC - C:\Program Files (x86)\Common Files\microsoft shared\ink\TabTip32.exe (Microsoft Corporation)

 

 

========== Modules (SafeList) ==========

 

MOD - C:\Users\Helen\Desktop\OTL.exe (OldTimer Tools)

MOD - C:\Program Files (x86)\Trusteer\Rapport\bin\rooksbas.dll (Trusteer Ltd.)

MOD - C:\Program Files (x86)\Common Files\microsoft shared\ink\tiptsf.dll (Microsoft Corporation)

MOD - C:\Windows\SysWOW64\msscript.ocx (Microsoft Corporation)

MOD - C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6001.18000_none_5cdbaa5a083979cc\comctl32.dll (Microsoft Corporation)

 

 

========== Win32 Services (SafeList) ==========

 

SRV:64bit: - (CSIScanner) -- C:\Program Files\Prevx\prevx.exe (Prevx)

SRV:64bit: - (wltrysvc) -- C:\Windows\SysNative\WLTRYSVC.EXE ()

SRV:64bit: - (AERTFilters) -- C:\Program Files\Realtek\Audio\HDA\AERTSr64.exe (Andrea Electronics Corporation)

SRV:64bit: - (dldwCATSCustConnectService) -- C:\Windows\SysNative\spool\DRIVERS\x64\3\\dldwserv.exe ()

SRV:64bit: - (dldw_device) -- C:\Windows\SysNative\dldwcoms.exe ()

SRV:64bit: - (WinDefend) -- C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)

SRV - (RapportLaunService) -- C:\Program Files (x86)\Trusteer\Rapport\bin\RapportLaunService64.exe (Trusteer Ltd.)

SRV - (RapportMgmtService) -- C:\Program Files (x86)\Trusteer\Rapport\bin\RapportMgmtService.exe (Trusteer Ltd.)

SRV - (GoToAssist) -- C:\Program Files (x86)\Citrix\GoToAssist\514\g2aservice.exe (Citrix Online, a division of Citrix Systems, Inc.)

SRV - (TomTomHOMEService) -- C:\Program Files (x86)\TomTom HOME 2\TomTomHOMEService.exe (TomTom)

SRV - (SBSDWSCService) -- C:\Program Files (x86)\Spybot - Search & Destroy\SDWinSec.exe (Safer Networking Ltd.)

SRV - (FOXOSDService) -- C:\Program Files (x86)\Dell\OSD\OSDSvr.exe ()

SRV - (dldw_device) -- C:\Windows\SysWow64\dldwcoms.exe ( )

 

 

========== Driver Services (SafeList) ==========

 

DRV:64bit: - (NwlnkFwd) -- C:\Windows\SysNative\DRIVERS\nwlnkfwd.sys File not found

DRV:64bit: - (NwlnkFlt) -- C:\Windows\SysNative\DRIVERS\nwlnkflt.sys File not found

DRV:64bit: - (IpInIp) -- C:\Windows\SysNative\DRIVERS\ipinip.sys File not found

DRV:64bit: - (pxrts) -- C:\Windows\SysNative\drivers\pxrts.sys ()

DRV:64bit: - (pxscan) -- C:\Windows\SysNative\drivers\pxscan.sys ()

DRV:64bit: - (pxkbf) -- C:\Windows\SysNative\drivers\pxkbf.sys ()

DRV:64bit: - (FXOSDDRV) -- C:\Windows\SysNative\DRIVERS\FxOSDdrv64.sys ()

DRV:64bit: - (BCM42RLY) -- C:\Windows\SysNative\drivers\BCM42RLY.sys ()

DRV:64bit: - (BCM43XX) -- C:\Windows\SysNative\DRIVERS\bcmwl664.sys ()

DRV:64bit: - (CtClsFlt) -- C:\Windows\SysNative\DRIVERS\CtClsFlt.sys ()

DRV:64bit: - (nvamacpi) -- C:\Windows\SysNative\DRIVERS\NVAMACPI.sys ()

DRV:64bit: - (b57nd60a) -- C:\Windows\SysNative\DRIVERS\b57nd60a.sys ()

DRV:64bit: - (WSDPrintDevice) -- C:\Windows\SysNative\DRIVERS\WSDPrint.sys ()

DRV:64bit: - (PxHlpa64) -- C:\Windows\SysNative\Drivers\PxHlpa64.sys ()

DRV:64bit: - (Ntfs) -- C:\Windows\SysNative\Wbem\ntfs.mof ()

DRV - (RapportPG64) -- C:\Program Files (x86)\Trusteer\Rapport\bin\RapportPG64.sys (Trusteer Ltd.)

DRV - (RapportKE64) -- C:\Program Files (x86)\Trusteer\Rapport\bin\RapportKE64.sys (Trusteer Ltd.)

 

 

========== Standard Registry (SafeList) ==========

 

 

========== Internet Explorer ==========

 

IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm

 

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = about:blank

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1

IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

 

 

[2010/03/13 12:17:54 | 000,000,000 | ---D | M] -- C:\Users\Helen\AppData\Roaming\mozilla\Extensions

[2010/03/13 12:17:54 | 000,000,000 | ---D | M] -- C:\Users\Helen\AppData\Roaming\mozilla\Extensions\home2@tomtom.com

 

O1 HOSTS File: ([2010/03/30 01:24:59 | 000,380,983 | R--- | M]) - C:\Windows\SysNative\drivers\etc\Hosts

O1 - Hosts: 127.0.0.1 localhost

O1 - Hosts: ::1 localhost

O1 - Hosts: 127.0.0.1 007guard.com - 007guard and Windows Vista

O1 - Hosts: 127.0.0.1 007guard.com

O1 - Hosts: 127.0.0.1 008i.com

O1 - Hosts: 127.0.0.1 008k.com

O1 - Hosts: 127.0.0.1 008k.com

O1 - Hosts: 127.0.0.1 00hq.com

O1 - Hosts: 127.0.0.1 00hq.com

O1 - Hosts: 127.0.0.1 010402.com

O1 - Hosts: 127.0.0.1 www.032439.com

O1 - Hosts: 127.0.0.1 032439.com

O1 - Hosts: 127.0.0.1 0scan.com

O1 - Hosts: 127.0.0.1 0scan.com

O1 - Hosts: 127.0.0.1 1000gratisproben.com

O1 - Hosts: 127.0.0.1 www.1000gratisproben.com

O1 - Hosts: 127.0.0.1 1001namen.com

O1 - Hosts: 127.0.0.1 1001namen.com

O1 - Hosts: 127.0.0.1 100888290cs.com

O1 - Hosts: 127.0.0.1 www.100888290cs.com

O1 - Hosts: 127.0.0.1 100sexlinks.com

O1 - Hosts: 127.0.0.1 100sexlinks.com

O1 - Hosts: 127.0.0.1 10sek.com

O1 - Hosts: 127.0.0.1 10sek.com

O1 - Hosts: 127.0.0.1 www.1-2005-search.com

O1 - Hosts: 13125 more lines...

O2 - BHO: (Spybot-S&D IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files (x86)\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)

O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {472734EA-242A-422B-ADF8-83D1E48CC825} - No CLSID value found.

O4:64bit: - HKLM..\Run: [broadcom Wireless Manager UI] C:\Windows\SysNative\WLTRAY.exe ()

O4:64bit: - HKLM..\Run: [dldwamon] C:\Program Files (x86)\Dell V505\dldwamon.exe ()

O4:64bit: - HKLM..\Run: [dldwmon.exe] C:\Program Files (x86)\Dell V505\dldwmon.exe ()

O4:64bit: - HKLM..\Run: [NvCplDaemon] C:\Windows\SysNative\NvCpl.DLL ()

O4:64bit: - HKLM..\Run: [NvMediaCenter] C:\Windows\SysNative\NvMcTray.DLL ()

O4:64bit: - HKLM..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Realtek Semiconductor)

O4:64bit: - HKLM..\Run: [skytel] C:\Program Files\Realtek\Audio\HDA\Skytel.exe File not found

O4:64bit: - HKLM..\Run: [Windows Defender] C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)

O4 - HKLM..\Run: [Dell V505] C:\Program Files (x86)\Dell V505\fm3032.exe ()

O4 - HKLM..\Run: [PDVDDXSrv] C:\Program Files (x86)\CyberLink\PowerDVD DX\PDVDDXSrv.exe (CyberLink Corp.)

O4 - HKCU..\Run: [spybotSD TeaTimer] C:\Program Files (x86)\Spybot - Search & Destroy\TeaTimer.exe (Safer-Networking Ltd.)

O4 - HKCU..\Run: [TomTomHOME.exe] C:\Program Files (x86)\TomTom HOME 2\TomTomHOMERunner.exe (TomTom)

O4 - HKCU..\Run: [WMPNSCFG] C:\Program Files (x86)\Windows Media Player\WMPNSCFG.exe File not found

O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1

O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0

O9 - Extra Button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)

O9 - Extra 'Tools' menuitem : S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)

O9 - Extra 'Tools' menuitem : Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files (x86)\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)

O13 - gopher Prefix: missing

O13 - gopher Prefix: missing

O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab (Reg Error: Key error.)

O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)

O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.254

O18:64bit: - Protocol\Handler\belarc {6318E0AB-2E93-11D1-B8ED-00608CC9A71F} - Reg Error: Key error. File not found

O18:64bit: - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - Reg Error: Key error. File not found

O18 - Protocol\Handler\belarc {6318E0AB-2E93-11D1-B8ED-00608CC9A71F} - C:\Program Files (x86)\Belarc\Advisor\System\BAVoilaX.dll (Belarc, Inc.)

O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)

O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)

O20:64bit: - Winlogon\Notify\GoToAssist: DllName - Reg Error: Key error. - C:\Program Files (x86)\Citrix\GoToAssist\514\G2AWinLogon_x64.dll File not found

O32 - HKLM CDRom: AutoRun - 1

O33 - MountPoints2\{9e4670ed-127e-11df-9ed4-0024e80c7d96}\Shell\AutoRun\command - "" = G:\setup.exe -- File not found

O33 - MountPoints2\{a1420bea-2e91-11df-bb67-0024e80c7d96}\Shell\AutoRun\command - "" = G:\InstallTomTomHOME.exe -- File not found

O33 - MountPoints2\{e1d32dda-ac7b-1e55-b16e-806e6f6e6963}\Shell - "" = AutoRun

O34 - HKLM BootExecute: (autocheck autochk *) - File not found

O35:64bit: - HKLM\..comfile [open] -- "%1" %*

O35:64bit: - HKLM\..exefile [open] -- "%1" %*

O35 - HKLM\..comfile [open] -- "%1" %*

O35 - HKLM\..exefile [open] -- "%1" %*

O37:64bit: - HKLM\...com [@ = comfile] -- "%1" %*

O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %*

O37 - HKLM\...com [@ = comfile] -- "%1" %*

O37 - HKLM\...exe [@ = exefile] -- "%1" %*

 

========== Files/Folders - Created Within 30 Days ==========

 

[8509/06/13 02:43:19 | 000,000,000 | ---D | C] -- C:\Windows\Panther

[8509/06/13 02:42:50 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\OEM

[8509/06/12 19:46:10 | 000,000,000 | ---D | C] -- C:\Windows\Debug

[8509/06/12 17:49:19 | 000,000,000 | ---D | C] -- C:\Windows\SoftwareDistribution

[8509/06/12 17:44:12 | 000,000,000 | ---D | C] -- C:\Windows\Prefetch

[2010/07/31 17:51:55 | 000,574,976 | ---- | C] (OldTimer Tools) -- C:\Users\Helen\Desktop\OTL.exe

[2010/07/31 17:48:07 | 000,060,928 | ---- | C] (Prevx) -- C:\Windows\SysWow64\PxSecure.dll

[2010/07/31 17:48:05 | 000,000,000 | ---D | C] -- C:\Program Files\Prevx

[2010/07/31 17:47:44 | 000,000,000 | ---D | C] -- C:\ProgramData\PrevxCSI

[2010/07/31 11:54:53 | 000,000,000 | ---D | C] -- C:\Users\Helen\Documents\Dell WebCam Central

[2010/02/11 13:38:08 | 000,364,544 | ---- | C] ( ) -- C:\Windows\SysWow64\dldwinpa.dll

[2010/02/11 13:38:08 | 000,339,968 | ---- | C] ( ) -- C:\Windows\SysWow64\dldwiesc.dll

[2010/02/11 13:38:06 | 000,651,264 | ---- | C] ( ) -- C:\Windows\SysWow64\dldwpmui.dll

[2010/02/11 13:38:04 | 000,851,968 | ---- | C] ( ) -- C:\Windows\SysWow64\dldwusb1.dll

[2010/02/11 13:38:03 | 001,069,056 | ---- | C] ( ) -- C:\Windows\SysWow64\dldwserv.dll

[2010/02/11 13:38:02 | 000,577,536 | ---- | C] ( ) -- C:\Windows\SysWow64\dldwlmpm.dll

[2010/02/11 13:38:01 | 000,679,936 | ---- | C] ( ) -- C:\Windows\SysWow64\dldwhbn3.dll

[2010/02/11 13:38:00 | 000,376,832 | ---- | C] ( ) -- C:\Windows\SysWow64\dldwcomm.dll

[2010/02/11 13:37:59 | 000,765,952 | ---- | C] ( ) -- C:\Windows\SysWow64\dldwcomc.dll

[1 C:\ProgramData\*.tmp files -> C:\ProgramData\*.tmp -> ]

[1 C:\ProgramData\*.tmp files -> C:\ProgramData\*.tmp -> ]

 

========== Files - Modified Within 30 Days ==========

 

[8509/06/12 17:52:05 | 000,047,092 | ---- | M] () -- C:\Windows\SysNative\license.rtf

[8509/06/12 17:51:28 | 000,000,000 | -H-- | M] () -- C:\Windows\SysNative\drivers\Msft_User_WpdFs_01_00_00.Wdf

[2010/07/31 17:52:46 | 007,340,032 | -HS- | M] () -- C:\Users\Helen\ntuser.dat

[2010/07/31 17:51:57 | 000,574,976 | ---- | M] (OldTimer Tools) -- C:\Users\Helen\Desktop\OTL.exe

[2010/07/31 17:48:07 | 000,060,928 | ---- | M] (Prevx) -- C:\Windows\SysWow64\PxSecure.dll

[2010/07/31 17:48:06 | 000,056,320 | ---- | M] () -- C:\Windows\SysNative\drivers\pxrts.sys

[2010/07/31 17:48:06 | 000,034,696 | ---- | M] () -- C:\Windows\SysNative\drivers\pxscan.sys

[2010/07/31 17:48:06 | 000,022,336 | ---- | M] () -- C:\Windows\SysNative\drivers\pxkbf.sys

[2010/07/31 17:47:53 | 000,000,050 | ---- | M] () -- C:\Windows\wininit.ini

[2010/07/31 17:46:58 | 000,000,217 | ---- | M] () -- C:\Users\Helen\Desktop\Google.url

[2010/07/31 17:40:19 | 000,690,960 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI

[2010/07/31 17:40:19 | 000,599,764 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat

[2010/07/31 17:40:19 | 000,105,270 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat

[2010/07/31 17:35:32 | 000,065,536 | ---- | M] () -- C:\Windows\SysNative\Ikeext.etl

[2010/07/31 17:35:30 | 000,000,890 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job

[2010/07/31 17:35:27 | 000,003,616 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0

[2010/07/31 17:35:26 | 000,003,616 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0

[2010/07/31 17:35:24 | 000,000,006 | -H-- | M] () -- C:\Windows\tasks\SA.DAT

[2010/07/31 17:35:17 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat

[2010/07/31 17:34:44 | 000,524,288 | -HS- | M] () -- C:\Users\Helen\ntuser.dat{bd1e410d-9cbe-11df-b61d-0024e80c7d96}.TMContainer00000000000000000002.regtrans-ms

[2010/07/31 17:34:44 | 000,524,288 | -HS- | M] () -- C:\Users\Helen\ntuser.dat{bd1e410d-9cbe-11df-b61d-0024e80c7d96}.TMContainer00000000000000000001.regtrans-ms

[2010/07/31 17:34:44 | 000,065,536 | -HS- | M] () -- C:\Users\Helen\ntuser.dat{bd1e410d-9cbe-11df-b61d-0024e80c7d96}.TM.blf

[2010/07/31 17:34:34 | 001,418,804 | -H-- | M] () -- C:\Users\Helen\AppData\Local\IconCache.db

[2010/07/31 17:31:00 | 000,000,894 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job

[2010/07/31 17:21:04 | 000,524,288 | -HS- | M] () -- C:\Users\Helen\NTUSER.DAT{bef7d13c-9b13-11df-83ed-0024e80c7d96}.TMContainer00000000000000000001.regtrans-ms

[2010/07/31 17:21:04 | 000,065,536 | -HS- | M] () -- C:\Users\Helen\NTUSER.DAT{bef7d13c-9b13-11df-83ed-0024e80c7d96}.TM.blf

[2010/07/30 11:42:24 | 000,000,211 | ---- | M] () -- C:\Users\Helen\Desktop\Runbox.url

[2010/07/30 01:47:38 | 000,524,288 | -HS- | M] () -- C:\Users\Helen\NTUSER.DAT{bef7d13c-9b13-11df-83ed-0024e80c7d96}.TMContainer00000000000000000002.regtrans-ms

[2010/07/30 01:47:07 | 000,032,768 | ---- | M] () -- C:\Users\Helen\Desktop\celtic card2.docx.doc

[2010/07/29 22:11:04 | 000,002,826 | ---- | M] () -- C:\Users\Helen\Desktop\Ancestry.url

[2010/07/29 22:04:24 | 000,000,208 | ---- | M] () -- C:\Users\Helen\Desktop\BBC - Homepage.url

[2010/07/29 14:35:44 | 000,034,304 | ---- | M] () -- C:\Users\Helen\Desktop\Our Branch of Bennisons.doc

[2010/07/29 12:32:26 | 000,524,288 | -HS- | M] () -- C:\Users\Helen\NTUSER.DAT{f0f03d89-0deb-11df-b0f6-0024e80c7d96}.TMContainer00000000000000000001.regtrans-ms

[2010/07/29 12:32:26 | 000,065,536 | -HS- | M] () -- C:\Users\Helen\NTUSER.DAT{f0f03d89-0deb-11df-b0f6-0024e80c7d96}.TM.blf

[2010/07/26 23:06:43 | 000,000,000 | ---- | M] () -- C:\Users\Helen\Desktop\john bennison 1911

[2010/07/25 16:46:23 | 001,146,091 | ---- | M] () -- C:\Users\Helen\Desktop\011074.pdf

[2010/07/25 00:53:13 | 000,030,720 | ---- | M] () -- C:\Users\Helen\Desktop\MRI scanning.doc

[2010/07/23 14:04:11 | 000,595,264 | ---- | M] () -- C:\Users\Helen\Desktop\HIS10_Coronary_angioplasty_0509.pdf

[2010/07/13 12:10:48 | 000,735,435 | ---- | M] () -- C:\Users\Helen\Desktop\Extras_Page.pdf

[2010/07/13 12:10:39 | 000,797,067 | ---- | M] () -- C:\Users\Helen\Desktop\Directions_to_Mimosa_.pdf

[2010/07/13 12:10:29 | 000,794,036 | ---- | M] () -- C:\Users\Helen\Desktop\Directions_to_Century_Wharf.pdf

[2010/07/13 12:10:14 | 000,075,729 | ---- | M] () -- C:\Users\Helen\Desktop\TermsOfBusinessMain.pdf

[2010/07/13 12:10:06 | 000,242,087 | ---- | M] () -- C:\Users\Helen\Desktop\receipt_12934_20100713-00003.pdf

[2010/07/13 12:09:57 | 000,243,042 | ---- | M] () -- C:\Users\Helen\Desktop\invoice_10194_20100713-00003.pdf

[2010/07/13 12:09:46 | 000,258,734 | ---- | M] () -- C:\Users\Helen\Desktop\checkinLetterManaged20100713-00003.pdf

[2010/07/03 19:21:49 | 000,327,052 | ---- | M] () -- C:\Users\Helen\Documents\03-07-2010 19;21;24.rtf

[1 C:\ProgramData\*.tmp files -> C:\ProgramData\*.tmp -> ]

[1 C:\ProgramData\*.tmp files -> C:\ProgramData\*.tmp -> ]

 

========== Files Created - No Company Name ==========

 

[8509/06/12 17:51:28 | 000,000,000 | -H-- | C] () -- C:\Windows\SysNative\drivers\Msft_User_WpdFs_01_00_00.Wdf

[2010/07/31 17:48:06 | 000,056,320 | ---- | C] () -- C:\Windows\SysNative\drivers\pxrts.sys

[2010/07/31 17:48:06 | 000,034,696 | ---- | C] () -- C:\Windows\SysNative\drivers\pxscan.sys

[2010/07/31 17:48:06 | 000,022,336 | ---- | C] () -- C:\Windows\SysNative\drivers\pxkbf.sys

[2010/07/31 17:47:44 | 000,000,050 | ---- | C] () -- C:\Windows\wininit.ini

[2010/07/31 17:23:53 | 000,524,288 | -HS- | C] () -- C:\Users\Helen\ntuser.dat{bd1e410d-9cbe-11df-b61d-0024e80c7d96}.TMContainer00000000000000000002.regtrans-ms

[2010/07/31 17:23:53 | 000,524,288 | -HS- | C] () -- C:\Users\Helen\ntuser.dat{bd1e410d-9cbe-11df-b61d-0024e80c7d96}.TMContainer00000000000000000001.regtrans-ms

[2010/07/31 17:23:53 | 000,065,536 | -HS- | C] () -- C:\Users\Helen\ntuser.dat{bd1e410d-9cbe-11df-b61d-0024e80c7d96}.TM.blf

[2010/07/29 22:38:46 | 000,032,768 | ---- | C] () -- C:\Users\Helen\Desktop\celtic card2.docx.doc

[2010/07/29 14:19:50 | 000,524,288 | -HS- | C] () -- C:\Users\Helen\NTUSER.DAT{bef7d13c-9b13-11df-83ed-0024e80c7d96}.TMContainer00000000000000000002.regtrans-ms

[2010/07/29 14:19:50 | 000,524,288 | -HS- | C] () -- C:\Users\Helen\NTUSER.DAT{bef7d13c-9b13-11df-83ed-0024e80c7d96}.TMContainer00000000000000000001.regtrans-ms

[2010/07/29 14:19:50 | 000,065,536 | -HS- | C] () -- C:\Users\Helen\NTUSER.DAT{bef7d13c-9b13-11df-83ed-0024e80c7d96}.TM.blf

[2010/07/29 01:32:11 | 000,034,304 | ---- | C] () -- C:\Users\Helen\Desktop\Our Branch of Bennisons.doc

[2010/07/26 23:06:36 | 000,000,000 | ---- | C] () -- C:\Users\Helen\Desktop\john bennison 1911

[2010/07/25 16:46:22 | 001,146,091 | ---- | C] () -- C:\Users\Helen\Desktop\011074.pdf

[2010/07/24 16:23:46 | 000,030,720 | ---- | C] () -- C:\Users\Helen\Desktop\MRI scanning.doc

[2010/07/23 14:04:09 | 000,595,264 | ---- | C] () -- C:\Users\Helen\Desktop\HIS10_Coronary_angioplasty_0509.pdf

[2010/07/13 12:10:47 | 000,735,435 | ---- | C] () -- C:\Users\Helen\Desktop\Extras_Page.pdf

[2010/07/13 12:10:38 | 000,797,067 | ---- | C] () -- C:\Users\Helen\Desktop\Directions_to_Mimosa_.pdf

[2010/07/13 12:10:28 | 000,794,036 | ---- | C] () -- C:\Users\Helen\Desktop\Directions_to_Century_Wharf.pdf

[2010/07/13 12:10:14 | 000,075,729 | ---- | C] () -- C:\Users\Helen\Desktop\TermsOfBusinessMain.pdf

[2010/07/13 12:10:06 | 000,242,087 | ---- | C] () -- C:\Users\Helen\Desktop\receipt_12934_20100713-00003.pdf

[2010/07/13 12:09:57 | 000,243,042 | ---- | C] () -- C:\Users\Helen\Desktop\invoice_10194_20100713-00003.pdf

[2010/07/13 12:09:45 | 000,258,734 | ---- | C] () -- C:\Users\Helen\Desktop\checkinLetterManaged20100713-00003.pdf

[2010/07/03 19:21:48 | 000,327,052 | ---- | C] () -- C:\Users\Helen\Documents\03-07-2010 19;21;24.rtf

[2010/02/11 13:38:08 | 000,389,120 | ---- | C] () -- C:\Windows\SysWow64\DLDWinst.dll

[2010/02/11 13:38:08 | 000,335,872 | ---- | C] () -- C:\Windows\SysWow64\dldwcomx.dll

[2010/02/11 13:38:07 | 000,147,456 | ---- | C] () -- C:\Windows\SysWow64\dldwjswr.dll

[2010/02/11 13:38:07 | 000,106,496 | ---- | C] () -- C:\Windows\SysWow64\dldwinsr.dll

[2010/02/11 13:38:07 | 000,036,864 | ---- | C] () -- C:\Windows\SysWow64\dldwcur.dll

[2010/02/11 13:38:06 | 000,520,192 | ---- | C] () -- C:\Windows\SysWow64\dldwutil.dll

[2010/02/11 13:38:06 | 000,180,224 | ---- | C] () -- C:\Windows\SysWow64\dldwinsb.dll

[2010/02/11 13:38:06 | 000,176,128 | ---- | C] () -- C:\Windows\SysWow64\dldwins.dll

[2010/02/11 13:38:05 | 000,086,016 | ---- | C] () -- C:\Windows\SysWow64\dldwcub.dll

[2010/02/11 13:38:04 | 000,077,824 | ---- | C] () -- C:\Windows\SysWow64\dldwcu.dll

[2010/02/11 13:37:59 | 000,077,906 | ---- | C] () -- C:\Windows\SysWow64\DLDWcfg.dll

[2010/02/01 14:23:28 | 000,327,168 | ---- | C] () -- C:\Windows\SysWow64\cutil32.dll

[2008/05/07 21:42:00 | 001,036,288 | ---- | C] () -- C:\Windows\SysWow64\dldwdrs.dll

[2008/04/23 08:53:14 | 000,081,920 | ---- | C] () -- C:\Windows\SysWow64\dldwcaps.dll

[2008/02/26 20:24:06 | 000,069,632 | ---- | C] () -- C:\Windows\SysWow64\dldwcnv4.dll

[2008/01/21 03:50:05 | 000,060,124 | ---- | C] () -- C:\Windows\SysWow64\tcpmon.ini

[2008/01/21 03:49:49 | 000,368,640 | ---- | C] () -- C:\Windows\SysWow64\msjetoledb40.dll

 

========== Alternate Data Streams ==========

 

@Alternate Data Stream - 115 bytes -> C:\ProgramData\TEMP:A8ADE5D8

@Alternate Data Stream - 109 bytes -> C:\ProgramData\TEMP:DFC5A2B2

< End of report >

 

OTL logfile created on: 31/07/2010 17:54:39 - Run 1

OTL by OldTimer - Version 3.2.9.1 Folder = C:\Users\Helen\Desktop

64bit-Windows Vista Home Premium Edition Service Pack 1 (Version = 6.0.6001) - Type = NTWorkstation

Internet Explorer (Version = 7.0.6001.18000)

Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy

 

3.00 Gb Total Physical Memory | 2.00 Gb Available Physical Memory | 60.00% Memory free

6.00 Gb Paging File | 4.00 Gb Available in Paging File | 74.00% Paging File free

Paging file location(s): ?:\pagefile.sys [binary data]

 

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)

Drive C: | 451.07 Gb Total Space | 361.34 Gb Free Space | 80.11% Space Free | Partition Type: NTFS

Drive D: | 14.65 Gb Total Space | 13.59 Gb Free Space | 92.74% Space Free | Partition Type: NTFS

E: Drive not present or media not loaded

F: Drive not present or media not loaded

G: Drive not present or media not loaded

H: Drive not present or media not loaded

I: Drive not present or media not loaded

 

Computer Name: HELEN-PC

Current User Name: Helen

Logged in as Administrator.

 

Current Boot Mode: Normal

Scan Mode: Current user

Include 64bit Scans

Company Name Whitelist: Off

Skip Microsoft Files: Off

File Age = 30 Days

Output = Minimal

 

========== Processes (SafeList) ==========

 

PRC - C:\Users\Helen\Desktop\OTL.exe (OldTimer Tools)

PRC - C:\Program Files (x86)\Trusteer\Rapport\bin\RapportService.exe (Trusteer Ltd.)

PRC - C:\Program Files (x86)\Trusteer\Rapport\bin\RapportMgmtService.exe (Trusteer Ltd.)

PRC - C:\Program Files (x86)\TomTom HOME 2\TomTomHOMEService.exe (TomTom)

PRC - C:\Program Files (x86)\TomTom HOME 2\TomTomHOMERunner.exe (TomTom)

PRC - C:\Program Files (x86)\Spybot - Search & Destroy\TeaTimer.exe (Safer-Networking Ltd.)

PRC - C:\Program Files (x86)\Spybot - Search & Destroy\SDWinSec.exe (Safer Networking Ltd.)

PRC - C:\Program Files (x86)\Dell\OSD\AIO_OSD.exe (Dell Corporation)

PRC - C:\Program Files (x86)\Dell\OSD\OSDSvr.exe ()

PRC - C:\Program Files (x86)\Dell V505\dldwmsdmon.exe ()

PRC - C:\Program Files (x86)\Dell V505\dldwmon.exe ()

PRC - C:\Program Files (x86)\CyberLink\PowerDVD DX\PDVDDXSrv.exe (CyberLink Corp.)

PRC - C:\Program Files (x86)\Common Files\microsoft shared\ink\TabTip32.exe (Microsoft Corporation)

 

 

========== Modules (SafeList) ==========

 

MOD - C:\Users\Helen\Desktop\OTL.exe (OldTimer Tools)

MOD - C:\Program Files (x86)\Trusteer\Rapport\bin\rooksbas.dll (Trusteer Ltd.)

MOD - C:\Program Files (x86)\Common Files\microsoft shared\ink\tiptsf.dll (Microsoft Corporation)

MOD - C:\Windows\SysWOW64\msscript.ocx (Microsoft Corporation)

MOD - C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6001.18000_none_5cdbaa5a083979cc\comctl32.dll (Microsoft Corporation)

 

 

========== Win32 Services (SafeList) ==========

 

SRV:64bit: - (CSIScanner) -- C:\Program Files\Prevx\prevx.exe (Prevx)

SRV:64bit: - (wltrysvc) -- C:\Windows\SysNative\WLTRYSVC.EXE ()

SRV:64bit: - (AERTFilters) -- C:\Program Files\Realtek\Audio\HDA\AERTSr64.exe (Andrea Electronics Corporation)

SRV:64bit: - (dldwCATSCustConnectService) -- C:\Windows\SysNative\spool\DRIVERS\x64\3\\dldwserv.exe ()

SRV:64bit: - (dldw_device) -- C:\Windows\SysNative\dldwcoms.exe ()

SRV:64bit: - (WinDefend) -- C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)

SRV - (RapportLaunService) -- C:\Program Files (x86)\Trusteer\Rapport\bin\RapportLaunService64.exe (Trusteer Ltd.)

SRV - (RapportMgmtService) -- C:\Program Files (x86)\Trusteer\Rapport\bin\RapportMgmtService.exe (Trusteer Ltd.)

SRV - (GoToAssist) -- C:\Program Files (x86)\Citrix\GoToAssist\514\g2aservice.exe (Citrix Online, a division of Citrix Systems, Inc.)

SRV - (TomTomHOMEService) -- C:\Program Files (x86)\TomTom HOME 2\TomTomHOMEService.exe (TomTom)

SRV - (SBSDWSCService) -- C:\Program Files (x86)\Spybot - Search & Destroy\SDWinSec.exe (Safer Networking Ltd.)

SRV - (FOXOSDService) -- C:\Program Files (x86)\Dell\OSD\OSDSvr.exe ()

SRV - (dldw_device) -- C:\Windows\SysWow64\dldwcoms.exe ( )

 

 

========== Driver Services (SafeList) ==========

 

DRV:64bit: - (NwlnkFwd) -- C:\Windows\SysNative\DRIVERS\nwlnkfwd.sys File not found

DRV:64bit: - (NwlnkFlt) -- C:\Windows\SysNative\DRIVERS\nwlnkflt.sys File not found

DRV:64bit: - (IpInIp) -- C:\Windows\SysNative\DRIVERS\ipinip.sys File not found

DRV:64bit: - (pxrts) -- C:\Windows\SysNative\drivers\pxrts.sys ()

DRV:64bit: - (pxscan) -- C:\Windows\SysNative\drivers\pxscan.sys ()

DRV:64bit: - (pxkbf) -- C:\Windows\SysNative\drivers\pxkbf.sys ()

DRV:64bit: - (FXOSDDRV) -- C:\Windows\SysNative\DRIVERS\FxOSDdrv64.sys ()

DRV:64bit: - (BCM42RLY) -- C:\Windows\SysNative\drivers\BCM42RLY.sys ()

DRV:64bit: - (BCM43XX) -- C:\Windows\SysNative\DRIVERS\bcmwl664.sys ()

DRV:64bit: - (CtClsFlt) -- C:\Windows\SysNative\DRIVERS\CtClsFlt.sys ()

DRV:64bit: - (nvamacpi) -- C:\Windows\SysNative\DRIVERS\NVAMACPI.sys ()

DRV:64bit: - (b57nd60a) -- C:\Windows\SysNative\DRIVERS\b57nd60a.sys ()

DRV:64bit: - (WSDPrintDevice) -- C:\Windows\SysNative\DRIVERS\WSDPrint.sys ()

DRV:64bit: - (PxHlpa64) -- C:\Windows\SysNative\Drivers\PxHlpa64.sys ()

DRV:64bit: - (Ntfs) -- C:\Windows\SysNative\Wbem\ntfs.mof ()

DRV - (RapportPG64) -- C:\Program Files (x86)\Trusteer\Rapport\bin\RapportPG64.sys (Trusteer Ltd.)

DRV - (RapportKE64) -- C:\Program Files (x86)\Trusteer\Rapport\bin\RapportKE64.sys (Trusteer Ltd.)

 

 

========== Standard Registry (SafeList) ==========

 

 

========== Internet Explorer ==========

 

IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm

 

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = about:blank

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1

IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

 

 

[2010/03/13 12:17:54 | 000,000,000 | ---D | M] -- C:\Users\Helen\AppData\Roaming\mozilla\Extensions

[2010/03/13 12:17:54 | 000,000,000 | ---D | M] -- C:\Users\Helen\AppData\Roaming\mozilla\Extensions\home2@tomtom.com

 

O1 HOSTS File: ([2010/03/30 01:24:59 | 000,380,983 | R--- | M]) - C:\Windows\SysNative\drivers\etc\Hosts

O1 - Hosts: 127.0.0.1 localhost

O1 - Hosts: ::1 localhost

O1 - Hosts: 127.0.0.1 007guard.com - 007guard and Windows Vista

O1 - Hosts: 127.0.0.1 007guard.com

O1 - Hosts: 127.0.0.1 008i.com

O1 - Hosts: 127.0.0.1 008k.com

O1 - Hosts: 127.0.0.1 008k.com

O1 - Hosts: 127.0.0.1 00hq.com

O1 - Hosts: 127.0.0.1 00hq.com

O1 - Hosts: 127.0.0.1 010402.com

O1 - Hosts: 127.0.0.1 www.032439.com

O1 - Hosts: 127.0.0.1 032439.com

O1 - Hosts: 127.0.0.1 0scan.com

O1 - Hosts: 127.0.0.1 0scan.com

O1 - Hosts: 127.0.0.1 1000gratisproben.com

O1 - Hosts: 127.0.0.1 www.1000gratisproben.com

O1 - Hosts: 127.0.0.1 1001namen.com

O1 - Hosts: 127.0.0.1 1001namen.com

O1 - Hosts: 127.0.0.1 100888290cs.com

O1 - Hosts: 127.0.0.1 www.100888290cs.com

O1 - Hosts: 127.0.0.1 100sexlinks.com

O1 - Hosts: 127.0.0.1 100sexlinks.com

O1 - Hosts: 127.0.0.1 10sek.com

O1 - Hosts: 127.0.0.1 10sek.com

O1 - Hosts: 127.0.0.1 www.1-2005-search.com

O1 - Hosts: 13125 more lines...

O2 - BHO: (Spybot-S&D IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files (x86)\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)

O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {472734EA-242A-422B-ADF8-83D1E48CC825} - No CLSID value found.

O4:64bit: - HKLM..\Run: [broadcom Wireless Manager UI] C:\Windows\SysNative\WLTRAY.exe ()

O4:64bit: - HKLM..\Run: [dldwamon] C:\Program Files (x86)\Dell V505\dldwamon.exe ()

O4:64bit: - HKLM..\Run: [dldwmon.exe] C:\Program Files (x86)\Dell V505\dldwmon.exe ()

O4:64bit: - HKLM..\Run: [NvCplDaemon] C:\Windows\SysNative\NvCpl.DLL ()

O4:64bit: - HKLM..\Run: [NvMediaCenter] C:\Windows\SysNative\NvMcTray.DLL ()

O4:64bit: - HKLM..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Realtek Semiconductor)

O4:64bit: - HKLM..\Run: [skytel] C:\Program Files\Realtek\Audio\HDA\Skytel.exe File not found

O4:64bit: - HKLM..\Run: [Windows Defender] C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)

O4 - HKLM..\Run: [Dell V505] C:\Program Files (x86)\Dell V505\fm3032.exe ()

O4 - HKLM..\Run: [PDVDDXSrv] C:\Program Files (x86)\CyberLink\PowerDVD DX\PDVDDXSrv.exe (CyberLink Corp.)

O4 - HKCU..\Run: [spybotSD TeaTimer] C:\Program Files (x86)\Spybot - Search & Destroy\TeaTimer.exe (Safer-Networking Ltd.)

O4 - HKCU..\Run: [TomTomHOME.exe] C:\Program Files (x86)\TomTom HOME 2\TomTomHOMERunner.exe (TomTom)

O4 - HKCU..\Run: [WMPNSCFG] C:\Program Files (x86)\Windows Media Player\WMPNSCFG.exe File not found

O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1

O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0

O9 - Extra Button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)

O9 - Extra 'Tools' menuitem : S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)

O9 - Extra 'Tools' menuitem : Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files (x86)\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)

O13 - gopher Prefix: missing

O13 - gopher Prefix: missing

O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab (Reg Error: Key error.)

O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)

O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.254

O18:64bit: - Protocol\Handler\belarc {6318E0AB-2E93-11D1-B8ED-00608CC9A71F} - Reg Error: Key error. File not found

O18:64bit: - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - Reg Error: Key error. File not found

O18 - Protocol\Handler\belarc {6318E0AB-2E93-11D1-B8ED-00608CC9A71F} - C:\Program Files (x86)\Belarc\Advisor\System\BAVoilaX.dll (Belarc, Inc.)

O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)

O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)

O20:64bit: - Winlogon\Notify\GoToAssist: DllName - Reg Error: Key error. - C:\Program Files (x86)\Citrix\GoToAssist\514\G2AWinLogon_x64.dll File not found

O32 - HKLM CDRom: AutoRun - 1

O33 - MountPoints2\{9e4670ed-127e-11df-9ed4-0024e80c7d96}\Shell\AutoRun\command - "" = G:\setup.exe -- File not found

O33 - MountPoints2\{a1420bea-2e91-11df-bb67-0024e80c7d96}\Shell\AutoRun\command - "" = G:\InstallTomTomHOME.exe -- File not found

O33 - MountPoints2\{e1d32dda-ac7b-1e55-b16e-806e6f6e6963}\Shell - "" = AutoRun

O34 - HKLM BootExecute: (autocheck autochk *) - File not found

O35:64bit: - HKLM\..comfile [open] -- "%1" %*

O35:64bit: - HKLM\..exefile [open] -- "%1" %*

O35 - HKLM\..comfile [open] -- "%1" %*

O35 - HKLM\..exefile [open] -- "%1" %*

O37:64bit: - HKLM\...com [@ = comfile] -- "%1" %*

O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %*

O37 - HKLM\...com [@ = comfile] -- "%1" %*

O37 - HKLM\...exe [@ = exefile] -- "%1" %*

 

========== Files/Folders - Created Within 30 Days ==========

 

[8509/06/13 02:43:19 | 000,000,000 | ---D | C] -- C:\Windows\Panther

[8509/06/13 02:42:50 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\OEM

[8509/06/12 19:46:10 | 000,000,000 | ---D | C] -- C:\Windows\Debug

[8509/06/12 17:49:19 | 000,000,000 | ---D | C] -- C:\Windows\SoftwareDistribution

[8509/06/12 17:44:12 | 000,000,000 | ---D | C] -- C:\Windows\Prefetch

[2010/07/31 17:51:55 | 000,574,976 | ---- | C] (OldTimer Tools) -- C:\Users\Helen\Desktop\OTL.exe

[2010/07/31 17:48:07 | 000,060,928 | ---- | C] (Prevx) -- C:\Windows\SysWow64\PxSecure.dll

[2010/07/31 17:48:05 | 000,000,000 | ---D | C] -- C:\Program Files\Prevx

[2010/07/31 17:47:44 | 000,000,000 | ---D | C] -- C:\ProgramData\PrevxCSI

[2010/07/31 11:54:53 | 000,000,000 | ---D | C] -- C:\Users\Helen\Documents\Dell WebCam Central

[2010/02/11 13:38:08 | 000,364,544 | ---- | C] ( ) -- C:\Windows\SysWow64\dldwinpa.dll

[2010/02/11 13:38:08 | 000,339,968 | ---- | C] ( ) -- C:\Windows\SysWow64\dldwiesc.dll

[2010/02/11 13:38:06 | 000,651,264 | ---- | C] ( ) -- C:\Windows\SysWow64\dldwpmui.dll

[2010/02/11 13:38:04 | 000,851,968 | ---- | C] ( ) -- C:\Windows\SysWow64\dldwusb1.dll

[2010/02/11 13:38:03 | 001,069,056 | ---- | C] ( ) -- C:\Windows\SysWow64\dldwserv.dll

[2010/02/11 13:38:02 | 000,577,536 | ---- | C] ( ) -- C:\Windows\SysWow64\dldwlmpm.dll

[2010/02/11 13:38:01 | 000,679,936 | ---- | C] ( ) -- C:\Windows\SysWow64\dldwhbn3.dll

[2010/02/11 13:38:00 | 000,376,832 | ---- | C] ( ) -- C:\Windows\SysWow64\dldwcomm.dll

[2010/02/11 13:37:59 | 000,765,952 | ---- | C] ( ) -- C:\Windows\SysWow64\dldwcomc.dll

[1 C:\ProgramData\*.tmp files -> C:\ProgramData\*.tmp -> ]

[1 C:\ProgramData\*.tmp files -> C:\ProgramData\*.tmp -> ]

 

========== Files - Modified Within 30 Days ==========

 

[8509/06/12 17:52:05 | 000,047,092 | ---- | M] () -- C:\Windows\SysNative\license.rtf

[8509/06/12 17:51:28 | 000,000,000 | -H-- | M] () -- C:\Windows\SysNative\drivers\Msft_User_WpdFs_01_00_00.Wdf

[2010/07/31 17:52:46 | 007,340,032 | -HS- | M] () -- C:\Users\Helen\ntuser.dat

[2010/07/31 17:51:57 | 000,574,976 | ---- | M] (OldTimer Tools) -- C:\Users\Helen\Desktop\OTL.exe

[2010/07/31 17:48:07 | 000,060,928 | ---- | M] (Prevx) -- C:\Windows\SysWow64\PxSecure.dll

[2010/07/31 17:48:06 | 000,056,320 | ---- | M] () -- C:\Windows\SysNative\drivers\pxrts.sys

[2010/07/31 17:48:06 | 000,034,696 | ---- | M] () -- C:\Windows\SysNative\drivers\pxscan.sys

[2010/07/31 17:48:06 | 000,022,336 | ---- | M] () -- C:\Windows\SysNative\drivers\pxkbf.sys

[2010/07/31 17:47:53 | 000,000,050 | ---- | M] () -- C:\Windows\wininit.ini

[2010/07/31 17:46:58 | 000,000,217 | ---- | M] () -- C:\Users\Helen\Desktop\Google.url

[2010/07/31 17:40:19 | 000,690,960 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI

[2010/07/31 17:40:19 | 000,599,764 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat

[2010/07/31 17:40:19 | 000,105,270 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat

[2010/07/31 17:35:32 | 000,065,536 | ---- | M] () -- C:\Windows\SysNative\Ikeext.etl

[2010/07/31 17:35:30 | 000,000,890 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job

[2010/07/31 17:35:27 | 000,003,616 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0

[2010/07/31 17:35:26 | 000,003,616 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0

[2010/07/31 17:35:24 | 000,000,006 | -H-- | M] () -- C:\Windows\tasks\SA.DAT

[2010/07/31 17:35:17 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat

[2010/07/31 17:34:44 | 000,524,288 | -HS- | M] () -- C:\Users\Helen\ntuser.dat{bd1e410d-9cbe-11df-b61d-0024e80c7d96}.TMContainer00000000000000000002.regtrans-ms

[2010/07/31 17:34:44 | 000,524,288 | -HS- | M] () -- C:\Users\Helen\ntuser.dat{bd1e410d-9cbe-11df-b61d-0024e80c7d96}.TMContainer00000000000000000001.regtrans-ms

[2010/07/31 17:34:44 | 000,065,536 | -HS- | M] () -- C:\Users\Helen\ntuser.dat{bd1e410d-9cbe-11df-b61d-0024e80c7d96}.TM.blf

[2010/07/31 17:34:34 | 001,418,804 | -H-- | M] () -- C:\Users\Helen\AppData\Local\IconCache.db

[2010/07/31 17:31:00 | 000,000,894 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job

[2010/07/31 17:21:04 | 000,524,288 | -HS- | M] () -- C:\Users\Helen\NTUSER.DAT{bef7d13c-9b13-11df-83ed-0024e80c7d96}.TMContainer00000000000000000001.regtrans-ms

[2010/07/31 17:21:04 | 000,065,536 | -HS- | M] () -- C:\Users\Helen\NTUSER.DAT{bef7d13c-9b13-11df-83ed-0024e80c7d96}.TM.blf

[2010/07/30 11:42:24 | 000,000,211 | ---- | M] () -- C:\Users\Helen\Desktop\Runbox.url

[2010/07/30 01:47:38 | 000,524,288 | -HS- | M] () -- C:\Users\Helen\NTUSER.DAT{bef7d13c-9b13-11df-83ed-0024e80c7d96}.TMContainer00000000000000000002.regtrans-ms

[2010/07/30 01:47:07 | 000,032,768 | ---- | M] () -- C:\Users\Helen\Desktop\celtic card2.docx.doc

[2010/07/29 22:11:04 | 000,002,826 | ---- | M] () -- C:\Users\Helen\Desktop\Ancestry.url

[2010/07/29 22:04:24 | 000,000,208 | ---- | M] () -- C:\Users\Helen\Desktop\BBC - Homepage.url

[2010/07/29 14:35:44 | 000,034,304 | ---- | M] () -- C:\Users\Helen\Desktop\Our Branch of Bennisons.doc

[2010/07/29 12:32:26 | 000,524,288 | -HS- | M] () -- C:\Users\Helen\NTUSER.DAT{f0f03d89-0deb-11df-b0f6-0024e80c7d96}.TMContainer00000000000000000001.regtrans-ms

[2010/07/29 12:32:26 | 000,065,536 | -HS- | M] () -- C:\Users\Helen\NTUSER.DAT{f0f03d89-0deb-11df-b0f6-0024e80c7d96}.TM.blf

[2010/07/26 23:06:43 | 000,000,000 | ---- | M] () -- C:\Users\Helen\Desktop\john bennison 1911

[2010/07/25 16:46:23 | 001,146,091 | ---- | M] () -- C:\Users\Helen\Desktop\011074.pdf

[2010/07/25 00:53:13 | 000,030,720 | ---- | M] () -- C:\Users\Helen\Desktop\MRI scanning.doc

[2010/07/23 14:04:11 | 000,595,264 | ---- | M] () -- C:\Users\Helen\Desktop\HIS10_Coronary_angioplasty_0509.pdf

[2010/07/13 12:10:48 | 000,735,435 | ---- | M] () -- C:\Users\Helen\Desktop\Extras_Page.pdf

[2010/07/13 12:10:39 | 000,797,067 | ---- | M] () -- C:\Users\Helen\Desktop\Directions_to_Mimosa_.pdf

[2010/07/13 12:10:29 | 000,794,036 | ---- | M] () -- C:\Users\Helen\Desktop\Directions_to_Century_Wharf.pdf

[2010/07/13 12:10:14 | 000,075,729 | ---- | M] () -- C:\Users\Helen\Desktop\TermsOfBusinessMain.pdf

[2010/07/13 12:10:06 | 000,242,087 | ---- | M] () -- C:\Users\Helen\Desktop\receipt_12934_20100713-00003.pdf

[2010/07/13 12:09:57 | 000,243,042 | ---- | M] () -- C:\Users\Helen\Desktop\invoice_10194_20100713-00003.pdf

[2010/07/13 12:09:46 | 000,258,734 | ---- | M] () -- C:\Users\Helen\Desktop\checkinLetterManaged20100713-00003.pdf

[2010/07/03 19:21:49 | 000,327,052 | ---- | M] () -- C:\Users\Helen\Documents\03-07-2010 19;21;24.rtf

[1 C:\ProgramData\*.tmp files -> C:\ProgramData\*.tmp -> ]

[1 C:\ProgramData\*.tmp files -> C:\ProgramData\*.tmp -> ]

 

========== Files Created - No Company Name ==========

 

[8509/06/12 17:51:28 | 000,000,000 | -H-- | C] () -- C:\Windows\SysNative\drivers\Msft_User_WpdFs_01_00_00.Wdf

[2010/07/31 17:48:06 | 000,056,320 | ---- | C] () -- C:\Windows\SysNative\drivers\pxrts.sys

[2010/07/31 17:48:06 | 000,034,696 | ---- | C] () -- C:\Windows\SysNative\drivers\pxscan.sys

[2010/07/31 17:48:06 | 000,022,336 | ---- | C] () -- C:\Windows\SysNative\drivers\pxkbf.sys

[2010/07/31 17:47:44 | 000,000,050 | ---- | C] () -- C:\Windows\wininit.ini

[2010/07/31 17:23:53 | 000,524,288 | -HS- | C] () -- C:\Users\Helen\ntuser.dat{bd1e410d-9cbe-11df-b61d-0024e80c7d96}.TMContainer00000000000000000002.regtrans-ms

[2010/07/31 17:23:53 | 000,524,288 | -HS- | C] () -- C:\Users\Helen\ntuser.dat{bd1e410d-9cbe-11df-b61d-0024e80c7d96}.TMContainer00000000000000000001.regtrans-ms

[2010/07/31 17:23:53 | 000,065,536 | -HS- | C] () -- C:\Users\Helen\ntuser.dat{bd1e410d-9cbe-11df-b61d-0024e80c7d96}.TM.blf

[2010/07/29 22:38:46 | 000,032,768 | ---- | C] () -- C:\Users\Helen\Desktop\celtic card2.docx.doc

[2010/07/29 14:19:50 | 000,524,288 | -HS- | C] () -- C:\Users\Helen\NTUSER.DAT{bef7d13c-9b13-11df-83ed-0024e80c7d96}.TMContainer00000000000000000002.regtrans-ms

[2010/07/29 14:19:50 | 000,524,288 | -HS- | C] () -- C:\Users\Helen\NTUSER.DAT{bef7d13c-9b13-11df-83ed-0024e80c7d96}.TMContainer00000000000000000001.regtrans-ms

[2010/07/29 14:19:50 | 000,065,536 | -HS- | C] () -- C:\Users\Helen\NTUSER.DAT{bef7d13c-9b13-11df-83ed-0024e80c7d96}.TM.blf

[2010/07/29 01:32:11 | 000,034,304 | ---- | C] () -- C:\Users\Helen\Desktop\Our Branch of Bennisons.doc

[2010/07/26 23:06:36 | 000,000,000 | ---- | C] () -- C:\Users\Helen\Desktop\john bennison 1911

[2010/07/25 16:46:22 | 001,146,091 | ---- | C] () -- C:\Users\Helen\Desktop\011074.pdf

[2010/07/24 16:23:46 | 000,030,720 | ---- | C] () -- C:\Users\Helen\Desktop\MRI scanning.doc

[2010/07/23 14:04:09 | 000,595,264 | ---- | C] () -- C:\Users\Helen\Desktop\HIS10_Coronary_angioplasty_0509.pdf

[2010/07/13 12:10:47 | 000,735,435 | ---- | C] () -- C:\Users\Helen\Desktop\Extras_Page.pdf

[2010/07/13 12:10:38 | 000,797,067 | ---- | C] () -- C:\Users\Helen\Desktop\Directions_to_Mimosa_.pdf

[2010/07/13 12:10:28 | 000,794,036 | ---- | C] () -- C:\Users\Helen\Desktop\Directions_to_Century_Wharf.pdf

[2010/07/13 12:10:14 | 000,075,729 | ---- | C] () -- C:\Users\Helen\Desktop\TermsOfBusinessMain.pdf

[2010/07/13 12:10:06 | 000,242,087 | ---- | C] () -- C:\Users\Helen\Desktop\receipt_12934_20100713-00003.pdf

[2010/07/13 12:09:57 | 000,243,042 | ---- | C] () -- C:\Users\Helen\Desktop\invoice_10194_20100713-00003.pdf

[2010/07/13 12:09:45 | 000,258,734 | ---- | C] () -- C:\Users\Helen\Desktop\checkinLetterManaged20100713-00003.pdf

[2010/07/03 19:21:48 | 000,327,052 | ---- | C] () -- C:\Users\Helen\Documents\03-07-2010 19;21;24.rtf

[2010/02/11 13:38:08 | 000,389,120 | ---- | C] () -- C:\Windows\SysWow64\DLDWinst.dll

[2010/02/11 13:38:08 | 000,335,872 | ---- | C] () -- C:\Windows\SysWow64\dldwcomx.dll

[2010/02/11 13:38:07 | 000,147,456 | ---- | C] () -- C:\Windows\SysWow64\dldwjswr.dll

[2010/02/11 13:38:07 | 000,106,496 | ---- | C] () -- C:\Windows\SysWow64\dldwinsr.dll

[2010/02/11 13:38:07 | 000,036,864 | ---- | C] () -- C:\Windows\SysWow64\dldwcur.dll

[2010/02/11 13:38:06 | 000,520,192 | ---- | C] () -- C:\Windows\SysWow64\dldwutil.dll

[2010/02/11 13:38:06 | 000,180,224 | ---- | C] () -- C:\Windows\SysWow64\dldwinsb.dll

[2010/02/11 13:38:06 | 000,176,128 | ---- | C] () -- C:\Windows\SysWow64\dldwins.dll

[2010/02/11 13:38:05 | 000,086,016 | ---- | C] () -- C:\Windows\SysWow64\dldwcub.dll

[2010/02/11 13:38:04 | 000,077,824 | ---- | C] () -- C:\Windows\SysWow64\dldwcu.dll

[2010/02/11 13:37:59 | 000,077,906 | ---- | C] () -- C:\Windows\SysWow64\DLDWcfg.dll

[2010/02/01 14:23:28 | 000,327,168 | ---- | C] () -- C:\Windows\SysWow64\cutil32.dll

[2008/05/07 21:42:00 | 001,036,288 | ---- | C] () -- C:\Windows\SysWow64\dldwdrs.dll

[2008/04/23 08:53:14 | 000,081,920 | ---- | C] () -- C:\Windows\SysWow64\dldwcaps.dll

[2008/02/26 20:24:06 | 000,069,632 | ---- | C] () -- C:\Windows\SysWow64\dldwcnv4.dll

[2008/01/21 03:50:05 | 000,060,124 | ---- | C] () -- C:\Windows\SysWow64\tcpmon.ini

[2008/01/21 03:49:49 | 000,368,640 | ---- | C] () -- C:\Windows\SysWow64\msjetoledb40.dll

 

========== Alternate Data Streams ==========

 

@Alternate Data Stream - 115 bytes -> C:\ProgramData\TEMP:A8ADE5D8

@Alternate Data Stream - 109 bytes -> C:\ProgramData\TEMP:DFC5A2B2

< End of report >

  • ExTS Admin
Posted

Hi Jim,

 

Even with the restored registry of the 27th june (a month ago) it still found a trojan 'bredolab' Malware bytes sorted it though.
Don't worry too much about that.

Files Infected:

C:\Program Files (x86)\Trend Micro\HijackThis\backups\backup-20100122-120940-917-rarype32.exe (Trojan.Bredolab) -> Quarantined and deleted successfully.

It's just something MBAM found in your Hjt backups.

 

PS Shouldn't I have an OTF file log or sumpin? I dunno, I'm not used to this stuff.
If you are referring to the extra.txt .... have a look here:

C:\Users\Helen\Desktop

 

There was a slight problem with the main OTL report as it didn't show the 'custom scans'

 

Please run OTL again.

this time copy the lines in bold below:

 

netsvcs

msconfig

%SYSTEMDRIVE%\*.exe

/md5start

eventlog.dll

scecli.dll

netlogon.dll

cngaudit.dll

sceclt.dll

ntelogon.dll

logevent.dll

iaStor.sys

nvstor.sys

atapi.sys

IdeChnDr.sys

viasraid.sys

AGP440.sys

vaxscsi.sys

nvatabus.sys

viamraid.sys

nvata.sys

nvgts.sys

iastorv.sys

ViPrt.sys

eNetHook.dll

ahcix86.sys

KR10N.sys

nvstor32.sys

ahcix86s.sys

nvrd32.sys

symmpi.sys

adp3132.sys

/md5stop

%systemroot%\*. /mp /s

%systemroot%\system32\*.dll /lockedfiles

%systemroot%\Tasks\*.job /lockedfiles

%systemroot%\system32\drivers\*.sys /lockedfiles

CREATERESTOREPOINT

  • right click in the Custom Scans/Fixes window (under the blue bar) and choose Paste.
     
    http://img.photobucket.com/albums/v708/starbuck50/new%20forum/scan-fix.png
    .
  • Click the Run Scan button.
     
    http://img.photobucket.com/albums/v708/starbuck50/runscan.png
     
  • Do not change any settings unless otherwise told to do so. The scan wont take long.

 

This scan will only produce the main.txt.

 

Please post that along with the extras.txt found at:

C:\Users\Helen\Desktop

 

Thanks

Member of:

UNITE

Posted
Hi Jim,

 

.snipped>

 

Please post that along with the extras.txt found at:

C:\Users\Helen\Desktop

 

Thanks

 

OK done that and log below.

Cheers

jim

 

OTL logfile created on: 01/08/2010 07:15:26 - Run 2

OTL by OldTimer - Version 3.2.9.1 Folder = C:\Users\Helen\Desktop\computer rescue tools

64bit-Windows Vista Home Premium Edition Service Pack 1 (Version = 6.0.6001) - Type = NTWorkstation

Internet Explorer (Version = 7.0.6001.18000)

Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy

 

3.00 Gb Total Physical Memory | 2.00 Gb Available Physical Memory | 56.00% Memory free

6.00 Gb Paging File | 4.00 Gb Available in Paging File | 73.00% Paging File free

Paging file location(s): ?:\pagefile.sys [binary data]

 

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)

Drive C: | 451.07 Gb Total Space | 360.59 Gb Free Space | 79.94% Space Free | Partition Type: NTFS

Drive D: | 14.65 Gb Total Space | 13.59 Gb Free Space | 92.74% Space Free | Partition Type: NTFS

E: Drive not present or media not loaded

F: Drive not present or media not loaded

G: Drive not present or media not loaded

H: Drive not present or media not loaded

I: Drive not present or media not loaded

 

Computer Name: HELEN-PC

Current User Name: Helen

Logged in as Administrator.

 

Current Boot Mode: Normal

Scan Mode: Current user

Include 64bit Scans

Company Name Whitelist: Off

Skip Microsoft Files: Off

File Age = 30 Days

Output = Minimal

 

========== Processes (SafeList) ==========

 

PRC - C:\Users\Helen\Desktop\computer rescue tools\OTL.exe (OldTimer Tools)

PRC - C:\Program Files (x86)\Trusteer\Rapport\bin\RapportService.exe (Trusteer Ltd.)

PRC - C:\Program Files (x86)\Trusteer\Rapport\bin\RapportMgmtService.exe (Trusteer Ltd.)

PRC - C:\Program Files (x86)\TomTom HOME 2\TomTomHOMEService.exe (TomTom)

PRC - C:\Program Files (x86)\TomTom HOME 2\TomTomHOMERunner.exe (TomTom)

PRC - C:\Program Files (x86)\Spybot - Search & Destroy\TeaTimer.exe (Safer-Networking Ltd.)

PRC - C:\Program Files (x86)\Spybot - Search & Destroy\SDWinSec.exe (Safer Networking Ltd.)

PRC - C:\Program Files (x86)\Dell\OSD\AIO_OSD.exe (Dell Corporation)

PRC - C:\Program Files (x86)\Dell\OSD\OSDSvr.exe ()

PRC - C:\Program Files (x86)\Dell V505\dldwmsdmon.exe ()

PRC - C:\Program Files (x86)\Dell V505\dldwmon.exe ()

PRC - C:\Program Files (x86)\CyberLink\PowerDVD DX\PDVDDXSrv.exe (CyberLink Corp.)

PRC - C:\Program Files (x86)\Common Files\microsoft shared\ink\TabTip32.exe (Microsoft Corporation)

 

 

========== Modules (SafeList) ==========

 

MOD - C:\Users\Helen\Desktop\computer rescue tools\OTL.exe (OldTimer Tools)

MOD - C:\Program Files (x86)\Trusteer\Rapport\bin\rooksbas.dll (Trusteer Ltd.)

MOD - C:\Program Files (x86)\Common Files\microsoft shared\ink\tiptsf.dll (Microsoft Corporation)

MOD - C:\Windows\SysWOW64\msscript.ocx (Microsoft Corporation)

MOD - C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6001.18000_none_5cdbaa5a083979cc\comctl32.dll (Microsoft Corporation)

 

 

========== Win32 Services (SafeList) ==========

 

SRV:64bit: - (CSIScanner) -- C:\Program Files\Prevx\prevx.exe (Prevx)

SRV:64bit: - (wltrysvc) -- C:\Windows\SysNative\WLTRYSVC.EXE ()

SRV:64bit: - (AERTFilters) -- C:\Program Files\Realtek\Audio\HDA\AERTSr64.exe (Andrea Electronics Corporation)

SRV:64bit: - (dldwCATSCustConnectService) -- C:\Windows\SysNative\spool\DRIVERS\x64\3\\dldwserv.exe ()

SRV:64bit: - (dldw_device) -- C:\Windows\SysNative\dldwcoms.exe ()

SRV:64bit: - (WinDefend) -- C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)

SRV - (RapportLaunService) -- C:\Program Files (x86)\Trusteer\Rapport\bin\RapportLaunService64.exe (Trusteer Ltd.)

SRV - (RapportMgmtService) -- C:\Program Files (x86)\Trusteer\Rapport\bin\RapportMgmtService.exe (Trusteer Ltd.)

SRV - (GoToAssist) -- C:\Program Files (x86)\Citrix\GoToAssist\514\g2aservice.exe (Citrix Online, a division of Citrix Systems, Inc.)

SRV - (TomTomHOMEService) -- C:\Program Files (x86)\TomTom HOME 2\TomTomHOMEService.exe (TomTom)

SRV - (SBSDWSCService) -- C:\Program Files (x86)\Spybot - Search & Destroy\SDWinSec.exe (Safer Networking Ltd.)

SRV - (FOXOSDService) -- C:\Program Files (x86)\Dell\OSD\OSDSvr.exe ()

SRV - (dldw_device) -- C:\Windows\SysWow64\dldwcoms.exe ( )

 

 

========== Driver Services (SafeList) ==========

 

DRV:64bit: - (NwlnkFwd) -- C:\Windows\SysNative\DRIVERS\nwlnkfwd.sys File not found

DRV:64bit: - (NwlnkFlt) -- C:\Windows\SysNative\DRIVERS\nwlnkflt.sys File not found

DRV:64bit: - (IpInIp) -- C:\Windows\SysNative\DRIVERS\ipinip.sys File not found

DRV:64bit: - (pxrts) -- C:\Windows\SysNative\drivers\pxrts.sys ()

DRV:64bit: - (pxscan) -- C:\Windows\SysNative\drivers\pxscan.sys ()

DRV:64bit: - (pxkbf) -- C:\Windows\SysNative\drivers\pxkbf.sys ()

DRV:64bit: - (FXOSDDRV) -- C:\Windows\SysNative\DRIVERS\FxOSDdrv64.sys ()

DRV:64bit: - (BCM42RLY) -- C:\Windows\SysNative\drivers\BCM42RLY.sys ()

DRV:64bit: - (BCM43XX) -- C:\Windows\SysNative\DRIVERS\bcmwl664.sys ()

DRV:64bit: - (CtClsFlt) -- C:\Windows\SysNative\DRIVERS\CtClsFlt.sys ()

DRV:64bit: - (nvamacpi) -- C:\Windows\SysNative\DRIVERS\NVAMACPI.sys ()

DRV:64bit: - (b57nd60a) -- C:\Windows\SysNative\DRIVERS\b57nd60a.sys ()

DRV:64bit: - (WSDPrintDevice) -- C:\Windows\SysNative\DRIVERS\WSDPrint.sys ()

DRV:64bit: - (PxHlpa64) -- C:\Windows\SysNative\Drivers\PxHlpa64.sys ()

DRV:64bit: - (Ntfs) -- C:\Windows\SysNative\Wbem\ntfs.mof ()

DRV - (RapportKE64) -- C:\Program Files (x86)\Trusteer\Rapport\bin\RapportKE64.sys (Trusteer Ltd.)

DRV - (RapportPG64) -- C:\Program Files (x86)\Trusteer\Rapport\bin\RapportPG64.sys (Trusteer Ltd.)

 

 

========== Standard Registry (SafeList) ==========

 

 

========== Internet Explorer ==========

 

IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm

 

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = about:blank

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1

IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

 

 

[2010/03/13 12:17:54 | 000,000,000 | ---D | M] -- C:\Users\Helen\AppData\Roaming\mozilla\Extensions

[2010/03/13 12:17:54 | 000,000,000 | ---D | M] -- C:\Users\Helen\AppData\Roaming\mozilla\Extensions\home2@tomtom.com

 

O1 HOSTS File: ([2010/03/30 01:24:59 | 000,380,983 | R--- | M]) - C:\Windows\SysNative\drivers\etc\Hosts

O1 - Hosts: 127.0.0.1 localhost

O1 - Hosts: ::1 localhost

O1 - Hosts: 127.0.0.1 007guard.com - 007guard and Windows Vista

O1 - Hosts: 127.0.0.1 007guard.com

O1 - Hosts: 127.0.0.1 008i.com

O1 - Hosts: 127.0.0.1 008k.com

O1 - Hosts: 127.0.0.1 008k.com

O1 - Hosts: 127.0.0.1 00hq.com

O1 - Hosts: 127.0.0.1 00hq.com

O1 - Hosts: 127.0.0.1 010402.com

O1 - Hosts: 127.0.0.1 www.032439.com

O1 - Hosts: 127.0.0.1 032439.com

O1 - Hosts: 127.0.0.1 0scan.com

O1 - Hosts: 127.0.0.1 0scan.com

O1 - Hosts: 127.0.0.1 1000gratisproben.com

O1 - Hosts: 127.0.0.1 www.1000gratisproben.com

O1 - Hosts: 127.0.0.1 1001namen.com

O1 - Hosts: 127.0.0.1 1001namen.com

O1 - Hosts: 127.0.0.1 100888290cs.com

O1 - Hosts: 127.0.0.1 www.100888290cs.com

O1 - Hosts: 127.0.0.1 100sexlinks.com

O1 - Hosts: 127.0.0.1 100sexlinks.com

O1 - Hosts: 127.0.0.1 10sek.com

O1 - Hosts: 127.0.0.1 10sek.com

O1 - Hosts: 127.0.0.1 www.1-2005-search.com

O1 - Hosts: 13125 more lines...

O2 - BHO: (Spybot-S&D IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files (x86)\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)

O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {472734EA-242A-422B-ADF8-83D1E48CC825} - No CLSID value found.

O4:64bit: - HKLM..\Run: [broadcom Wireless Manager UI] C:\Windows\SysNative\WLTRAY.exe ()

O4:64bit: - HKLM..\Run: [dldwamon] C:\Program Files (x86)\Dell V505\dldwamon.exe ()

O4:64bit: - HKLM..\Run: [dldwmon.exe] C:\Program Files (x86)\Dell V505\dldwmon.exe ()

O4:64bit: - HKLM..\Run: [NvCplDaemon] C:\Windows\SysNative\NvCpl.DLL ()

O4:64bit: - HKLM..\Run: [NvMediaCenter] C:\Windows\SysNative\NvMcTray.DLL ()

O4:64bit: - HKLM..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Realtek Semiconductor)

O4:64bit: - HKLM..\Run: [skytel] C:\Program Files\Realtek\Audio\HDA\Skytel.exe File not found

O4:64bit: - HKLM..\Run: [Windows Defender] C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)

O4 - HKLM..\Run: [Dell V505] C:\Program Files (x86)\Dell V505\fm3032.exe ()

O4 - HKLM..\Run: [PDVDDXSrv] C:\Program Files (x86)\CyberLink\PowerDVD DX\PDVDDXSrv.exe (CyberLink Corp.)

O4 - HKCU..\Run: [spybotSD TeaTimer] C:\Program Files (x86)\Spybot - Search & Destroy\TeaTimer.exe (Safer-Networking Ltd.)

O4 - HKCU..\Run: [TomTomHOME.exe] C:\Program Files (x86)\TomTom HOME 2\TomTomHOMERunner.exe (TomTom)

O4 - HKCU..\Run: [WMPNSCFG] C:\Program Files (x86)\Windows Media Player\WMPNSCFG.exe File not found

O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1

O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0

O9 - Extra Button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)

O9 - Extra 'Tools' menuitem : S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)

O9 - Extra 'Tools' menuitem : Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files (x86)\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)

O13 - gopher Prefix: missing

O13 - gopher Prefix: missing

O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab (Reg Error: Key error.)

O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)

O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.254

O18:64bit: - Protocol\Handler\belarc {6318E0AB-2E93-11D1-B8ED-00608CC9A71F} - Reg Error: Key error. File not found

O18:64bit: - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - Reg Error: Key error. File not found

O18 - Protocol\Handler\belarc {6318E0AB-2E93-11D1-B8ED-00608CC9A71F} - C:\Program Files (x86)\Belarc\Advisor\System\BAVoilaX.dll (Belarc, Inc.)

O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)

O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)

O20:64bit: - Winlogon\Notify\GoToAssist: DllName - Reg Error: Key error. - C:\Program Files (x86)\Citrix\GoToAssist\514\G2AWinLogon_x64.dll File not found

O32 - HKLM CDRom: AutoRun - 1

O33 - MountPoints2\{9e4670ed-127e-11df-9ed4-0024e80c7d96}\Shell\AutoRun\command - "" = G:\setup.exe -- File not found

O33 - MountPoints2\{a1420bea-2e91-11df-bb67-0024e80c7d96}\Shell\AutoRun\command - "" = G:\InstallTomTomHOME.exe -- File not found

O33 - MountPoints2\{e1d32dda-ac7b-1e55-b16e-806e6f6e6963}\Shell - "" = AutoRun

O34 - HKLM BootExecute: (autocheck autochk *) - File not found

O35:64bit: - HKLM\..comfile [open] -- "%1" %*

O35:64bit: - HKLM\..exefile [open] -- "%1" %*

O35 - HKLM\..comfile [open] -- "%1" %*

O35 - HKLM\..exefile [open] -- "%1" %*

O37:64bit: - HKLM\...com [@ = comfile] -- "%1" %*

O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %*

O37 - HKLM\...com [@ = comfile] -- "%1" %*

O37 - HKLM\...exe [@ = exefile] -- "%1" %*

 

 

 

CREATERESTOREPOINT

Restore point Set: OTL Restore Point

 

========== Files/Folders - Created Within 30 Days ==========

 

[8509/06/13 02:43:19 | 000,000,000 | ---D | C] -- C:\Windows\Panther

[8509/06/13 02:42:50 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\OEM

[8509/06/12 19:46:10 | 000,000,000 | ---D | C] -- C:\Windows\Debug

[8509/06/12 17:49:19 | 000,000,000 | ---D | C] -- C:\Windows\SoftwareDistribution

[8509/06/12 17:44:12 | 000,000,000 | ---D | C] -- C:\Windows\Prefetch

[2010/07/31 21:56:52 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Speccy

[2010/07/31 19:14:03 | 000,038,224 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\SysWow64\drivers\mbamswissarmy.sys

[2010/07/31 19:14:01 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Malwarebytes' Anti-Malware

[2010/07/31 17:48:07 | 000,060,928 | ---- | C] (Prevx) -- C:\Windows\SysWow64\PxSecure.dll

[2010/07/31 17:48:05 | 000,000,000 | ---D | C] -- C:\Program Files\Prevx

[2010/07/31 17:47:44 | 000,000,000 | ---D | C] -- C:\ProgramData\PrevxCSI

[2010/07/31 11:54:53 | 000,000,000 | ---D | C] -- C:\Users\Helen\Documents\Dell WebCam Central

[2010/02/11 13:38:08 | 000,364,544 | ---- | C] ( ) -- C:\Windows\SysWow64\dldwinpa.dll

[2010/02/11 13:38:08 | 000,339,968 | ---- | C] ( ) -- C:\Windows\SysWow64\dldwiesc.dll

[2010/02/11 13:38:06 | 000,651,264 | ---- | C] ( ) -- C:\Windows\SysWow64\dldwpmui.dll

[2010/02/11 13:38:04 | 000,851,968 | ---- | C] ( ) -- C:\Windows\SysWow64\dldwusb1.dll

[2010/02/11 13:38:03 | 001,069,056 | ---- | C] ( ) -- C:\Windows\SysWow64\dldwserv.dll

[2010/02/11 13:38:02 | 000,577,536 | ---- | C] ( ) -- C:\Windows\SysWow64\dldwlmpm.dll

[2010/02/11 13:38:01 | 000,679,936 | ---- | C] ( ) -- C:\Windows\SysWow64\dldwhbn3.dll

[2010/02/11 13:38:00 | 000,376,832 | ---- | C] ( ) -- C:\Windows\SysWow64\dldwcomm.dll

[2010/02/11 13:37:59 | 000,765,952 | ---- | C] ( ) -- C:\Windows\SysWow64\dldwcomc.dll

[1 C:\ProgramData\*.tmp files -> C:\ProgramData\*.tmp -> ]

[1 C:\ProgramData\*.tmp files -> C:\ProgramData\*.tmp -> ]

 

========== Files - Modified Within 30 Days ==========

 

[8509/06/12 17:52:05 | 000,047,092 | ---- | M] () -- C:\Windows\SysNative\license.rtf

[8509/06/12 17:51:28 | 000,000,000 | -H-- | M] () -- C:\Windows\SysNative\drivers\Msft_User_WpdFs_01_00_00.Wdf

[2010/08/01 07:15:11 | 000,690,960 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI

[2010/08/01 07:15:11 | 000,599,942 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat

[2010/08/01 07:15:11 | 000,105,448 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat

[2010/08/01 07:11:01 | 007,340,032 | -HS- | M] () -- C:\Users\Helen\ntuser.dat

[2010/08/01 07:08:49 | 000,000,217 | ---- | M] () -- C:\Users\Helen\Desktop\Google.url

[2010/08/01 07:08:17 | 000,000,890 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job

[2010/08/01 07:08:08 | 000,065,536 | ---- | M] () -- C:\Windows\SysNative\Ikeext.etl

[2010/08/01 07:08:07 | 000,003,616 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0

[2010/08/01 07:08:07 | 000,003,616 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0

[2010/08/01 07:08:01 | 000,000,006 | -H-- | M] () -- C:\Windows\tasks\SA.DAT

[2010/08/01 07:07:54 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat

[2010/08/01 00:20:52 | 000,524,288 | -HS- | M] () -- C:\Users\Helen\ntuser.dat{bd1e410d-9cbe-11df-b61d-0024e80c7d96}.TMContainer00000000000000000001.regtrans-ms

[2010/08/01 00:20:52 | 000,065,536 | -HS- | M] () -- C:\Users\Helen\ntuser.dat{bd1e410d-9cbe-11df-b61d-0024e80c7d96}.TM.blf

[2010/08/01 00:20:22 | 001,692,897 | -H-- | M] () -- C:\Users\Helen\AppData\Local\IconCache.db

[2010/07/31 23:50:48 | 000,000,208 | ---- | M] () -- C:\Users\Helen\Desktop\BBC - Homepage.url

[2010/07/31 23:49:51 | 000,000,211 | ---- | M] () -- C:\Users\Helen\Desktop\Runbox.url

[2010/07/31 23:31:00 | 000,000,894 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job

[2010/07/31 23:02:31 | 000,002,651 | ---- | M] () -- C:\Users\Helen\Desktop\Microsoft Office Word 2007.lnk

[2010/07/31 20:28:41 | 000,010,601 | ---- | M] () -- C:\Users\Helen\Documents\Malwarebytes2.docx

[2010/07/31 20:27:49 | 000,010,801 | ---- | M] () -- C:\Users\Helen\Documents\Malwarebytes1.docx

[2010/07/31 20:27:06 | 000,002,619 | ---- | M] () -- C:\Users\Helen\Desktop\Microsoft Office PowerPoint 2007.lnk

[2010/07/31 19:01:17 | 000,018,754 | ---- | M] () -- C:\Users\Helen\Documents\OTL Extras logfile created o1.docx

[2010/07/31 19:00:09 | 000,020,335 | ---- | M] () -- C:\Users\Helen\Documents\OTL Extras logfile created on.docx

[2010/07/31 17:48:07 | 000,060,928 | ---- | M] (Prevx) -- C:\Windows\SysWow64\PxSecure.dll

[2010/07/31 17:48:06 | 000,056,320 | ---- | M] () -- C:\Windows\SysNative\drivers\pxrts.sys

[2010/07/31 17:48:06 | 000,034,696 | ---- | M] () -- C:\Windows\SysNative\drivers\pxscan.sys

[2010/07/31 17:48:06 | 000,022,336 | ---- | M] () -- C:\Windows\SysNative\drivers\pxkbf.sys

[2010/07/31 17:47:53 | 000,000,050 | ---- | M] () -- C:\Windows\wininit.ini

[2010/07/31 17:34:44 | 000,524,288 | -HS- | M] () -- C:\Users\Helen\ntuser.dat{bd1e410d-9cbe-11df-b61d-0024e80c7d96}.TMContainer00000000000000000002.regtrans-ms

[2010/07/31 17:21:04 | 000,524,288 | -HS- | M] () -- C:\Users\Helen\NTUSER.DAT{bef7d13c-9b13-11df-83ed-0024e80c7d96}.TMContainer00000000000000000001.regtrans-ms

[2010/07/31 17:21:04 | 000,065,536 | -HS- | M] () -- C:\Users\Helen\NTUSER.DAT{bef7d13c-9b13-11df-83ed-0024e80c7d96}.TM.blf

[2010/07/30 01:47:38 | 000,524,288 | -HS- | M] () -- C:\Users\Helen\NTUSER.DAT{bef7d13c-9b13-11df-83ed-0024e80c7d96}.TMContainer00000000000000000002.regtrans-ms

[2010/07/29 22:11:04 | 000,002,826 | ---- | M] () -- C:\Users\Helen\Desktop\Ancestry.url

[2010/07/29 14:35:44 | 000,034,304 | ---- | M] () -- C:\Users\Helen\Desktop\Our Branch of Bennisons.doc

[2010/07/29 12:32:26 | 000,524,288 | -HS- | M] () -- C:\Users\Helen\NTUSER.DAT{f0f03d89-0deb-11df-b0f6-0024e80c7d96}.TMContainer00000000000000000001.regtrans-ms

[2010/07/29 12:32:26 | 000,065,536 | -HS- | M] () -- C:\Users\Helen\NTUSER.DAT{f0f03d89-0deb-11df-b0f6-0024e80c7d96}.TM.blf

[2010/07/25 16:46:23 | 001,146,091 | ---- | M] () -- C:\Users\Helen\Desktop\011074.pdf

[2010/07/25 00:53:13 | 000,030,720 | ---- | M] () -- C:\Users\Helen\Desktop\MRI scanning.doc

[2010/07/23 14:04:11 | 000,595,264 | ---- | M] () -- C:\Users\Helen\Desktop\HIS10_Coronary_angioplasty_0509.pdf

[2010/07/13 12:10:48 | 000,735,435 | ---- | M] () -- C:\Users\Helen\Desktop\Extras_Page.pdf

[2010/07/13 12:10:39 | 000,797,067 | ---- | M] () -- C:\Users\Helen\Desktop\Directions_to_Mimosa_.pdf

[2010/07/13 12:10:29 | 000,794,036 | ---- | M] () -- C:\Users\Helen\Desktop\Directions_to_Century_Wharf.pdf

[2010/07/13 12:10:14 | 000,075,729 | ---- | M] () -- C:\Users\Helen\Desktop\TermsOfBusinessMain.pdf

[2010/07/13 12:10:06 | 000,242,087 | ---- | M] () -- C:\Users\Helen\Desktop\receipt_12934_20100713-00003.pdf

[2010/07/13 12:09:57 | 000,243,042 | ---- | M] () -- C:\Users\Helen\Desktop\invoice_10194_20100713-00003.pdf

[2010/07/13 12:09:46 | 000,258,734 | ---- | M] () -- C:\Users\Helen\Desktop\checkinLetterManaged20100713-00003.pdf

[2010/07/03 19:21:49 | 000,327,052 | ---- | M] () -- C:\Users\Helen\Documents\03-07-2010 19;21;24.rtf

[1 C:\ProgramData\*.tmp files -> C:\ProgramData\*.tmp -> ]

[1 C:\ProgramData\*.tmp files -> C:\ProgramData\*.tmp -> ]

 

========== Files Created - No Company Name ==========

 

[8509/06/12 17:51:28 | 000,000,000 | -H-- | C] () -- C:\Windows\SysNative\drivers\Msft_User_WpdFs_01_00_00.Wdf

[2010/07/31 20:28:40 | 000,010,601 | ---- | C] () -- C:\Users\Helen\Documents\Malwarebytes2.docx

[2010/07/31 20:27:49 | 000,010,801 | ---- | C] () -- C:\Users\Helen\Documents\Malwarebytes1.docx

[2010/07/31 19:01:16 | 000,018,754 | ---- | C] () -- C:\Users\Helen\Documents\OTL Extras logfile created o1.docx

[2010/07/31 19:00:08 | 000,020,335 | ---- | C] () -- C:\Users\Helen\Documents\OTL Extras logfile created on.docx

[2010/07/31 17:48:06 | 000,056,320 | ---- | C] () -- C:\Windows\SysNative\drivers\pxrts.sys

[2010/07/31 17:48:06 | 000,034,696 | ---- | C] () -- C:\Windows\SysNative\drivers\pxscan.sys

[2010/07/31 17:48:06 | 000,022,336 | ---- | C] () -- C:\Windows\SysNative\drivers\pxkbf.sys

[2010/07/31 17:47:44 | 000,000,050 | ---- | C] () -- C:\Windows\wininit.ini

[2010/07/31 17:23:53 | 000,524,288 | -HS- | C] () -- C:\Users\Helen\ntuser.dat{bd1e410d-9cbe-11df-b61d-0024e80c7d96}.TMContainer00000000000000000002.regtrans-ms

[2010/07/31 17:23:53 | 000,524,288 | -HS- | C] () -- C:\Users\Helen\ntuser.dat{bd1e410d-9cbe-11df-b61d-0024e80c7d96}.TMContainer00000000000000000001.regtrans-ms

[2010/07/31 17:23:53 | 000,065,536 | -HS- | C] () -- C:\Users\Helen\ntuser.dat{bd1e410d-9cbe-11df-b61d-0024e80c7d96}.TM.blf

[2010/07/29 14:19:50 | 000,524,288 | -HS- | C] () -- C:\Users\Helen\NTUSER.DAT{bef7d13c-9b13-11df-83ed-0024e80c7d96}.TMContainer00000000000000000002.regtrans-ms

[2010/07/29 14:19:50 | 000,524,288 | -HS- | C] () -- C:\Users\Helen\NTUSER.DAT{bef7d13c-9b13-11df-83ed-0024e80c7d96}.TMContainer00000000000000000001.regtrans-ms

[2010/07/29 14:19:50 | 000,065,536 | -HS- | C] () -- C:\Users\Helen\NTUSER.DAT{bef7d13c-9b13-11df-83ed-0024e80c7d96}.TM.blf

[2010/07/29 01:32:11 | 000,034,304 | ---- | C] () -- C:\Users\Helen\Desktop\Our Branch of Bennisons.doc

[2010/07/25 16:46:22 | 001,146,091 | ---- | C] () -- C:\Users\Helen\Desktop\011074.pdf

[2010/07/24 16:23:46 | 000,030,720 | ---- | C] () -- C:\Users\Helen\Desktop\MRI scanning.doc

[2010/07/23 14:04:09 | 000,595,264 | ---- | C] () -- C:\Users\Helen\Desktop\HIS10_Coronary_angioplasty_0509.pdf

[2010/07/13 12:10:47 | 000,735,435 | ---- | C] () -- C:\Users\Helen\Desktop\Extras_Page.pdf

[2010/07/13 12:10:38 | 000,797,067 | ---- | C] () -- C:\Users\Helen\Desktop\Directions_to_Mimosa_.pdf

[2010/07/13 12:10:28 | 000,794,036 | ---- | C] () -- C:\Users\Helen\Desktop\Directions_to_Century_Wharf.pdf

[2010/07/13 12:10:14 | 000,075,729 | ---- | C] () -- C:\Users\Helen\Desktop\TermsOfBusinessMain.pdf

[2010/07/13 12:10:06 | 000,242,087 | ---- | C] () -- C:\Users\Helen\Desktop\receipt_12934_20100713-00003.pdf

[2010/07/13 12:09:57 | 000,243,042 | ---- | C] () -- C:\Users\Helen\Desktop\invoice_10194_20100713-00003.pdf

[2010/07/13 12:09:45 | 000,258,734 | ---- | C] () -- C:\Users\Helen\Desktop\checkinLetterManaged20100713-00003.pdf

[2010/07/03 19:21:48 | 000,327,052 | ---- | C] () -- C:\Users\Helen\Documents\03-07-2010 19;21;24.rtf

[2010/02/11 13:38:08 | 000,389,120 | ---- | C] () -- C:\Windows\SysWow64\DLDWinst.dll

[2010/02/11 13:38:08 | 000,335,872 | ---- | C] () -- C:\Windows\SysWow64\dldwcomx.dll

[2010/02/11 13:38:07 | 000,147,456 | ---- | C] () -- C:\Windows\SysWow64\dldwjswr.dll

[2010/02/11 13:38:07 | 000,106,496 | ---- | C] () -- C:\Windows\SysWow64\dldwinsr.dll

[2010/02/11 13:38:07 | 000,036,864 | ---- | C] () -- C:\Windows\SysWow64\dldwcur.dll

[2010/02/11 13:38:06 | 000,520,192 | ---- | C] () -- C:\Windows\SysWow64\dldwutil.dll

[2010/02/11 13:38:06 | 000,180,224 | ---- | C] () -- C:\Windows\SysWow64\dldwinsb.dll

[2010/02/11 13:38:06 | 000,176,128 | ---- | C] () -- C:\Windows\SysWow64\dldwins.dll

[2010/02/11 13:38:05 | 000,086,016 | ---- | C] () -- C:\Windows\SysWow64\dldwcub.dll

[2010/02/11 13:38:04 | 000,077,824 | ---- | C] () -- C:\Windows\SysWow64\dldwcu.dll

[2010/02/11 13:37:59 | 000,077,906 | ---- | C] () -- C:\Windows\SysWow64\DLDWcfg.dll

[2010/02/01 14:23:28 | 000,327,168 | ---- | C] () -- C:\Windows\SysWow64\cutil32.dll

[2008/05/07 21:42:00 | 001,036,288 | ---- | C] () -- C:\Windows\SysWow64\dldwdrs.dll

[2008/04/23 08:53:14 | 000,081,920 | ---- | C] () -- C:\Windows\SysWow64\dldwcaps.dll

[2008/02/26 20:24:06 | 000,069,632 | ---- | C] () -- C:\Windows\SysWow64\dldwcnv4.dll

[2008/01/21 03:50:05 | 000,060,124 | ---- | C] () -- C:\Windows\SysWow64\tcpmon.ini

[2008/01/21 03:49:49 | 000,368,640 | ---- | C] () -- C:\Windows\SysWow64\msjetoledb40.dll

 

========== LOP Check ==========

 

[2009/12/01 01:34:08 | 000,000,000 | ---D | M] -- C:\Users\Helen\AppData\Roaming\com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1

[2010/03/13 12:17:54 | 000,000,000 | ---D | M] -- C:\Users\Helen\AppData\Roaming\TomTom

[2010/02/15 00:55:51 | 000,000,000 | ---D | M] -- C:\Users\Helen\AppData\Roaming\Trusteer

[2009/06/19 15:09:44 | 000,000,000 | ---D | M] -- C:\Users\Helen\AppData\Roaming\V505 Series

[2010/06/27 02:02:00 | 000,000,366 | ---- | M] () -- C:\Windows\Tasks\Driver Robot.job

[2010/08/01 00:20:32 | 000,032,622 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT

 

========== Purity Check ==========

 

 

 

========== Custom Scans ==========

 

 

< >

 

< %SYSTEMDRIVE%\*.exe >

 

 

< MD5 for: AGP440.SYS >

[2008/01/21 03:46:51 | 000,064,568 | ---- | M] (Microsoft Corporation) MD5=F6F6793B7F17B550ECFDBD3B229173F7 -- C:\Windows\winsxs\amd64_machine.inf_31bf3856ad364e35_6.0.6001.18000_none_163188bf770e4ab0\AGP440.sys

 

< MD5 for: ATAPI.SYS >

[2008/01/21 03:46:50 | 000,022,584 | ---- | M] (Microsoft Corporation) MD5=1898FAE8E07D97F2F6C2D5326C633FAC -- C:\Windows\winsxs\amd64_mshdc.inf_31bf3856ad364e35_6.0.6001.18000_none_3956c39dd9e73fd2\atapi.sys

 

< MD5 for: CNGAUDIT.DLL >

[2006/11/02 12:16:48 | 000,014,848 | ---- | M] (Microsoft Corporation) MD5=21322B1A2AD337C579F4A65EA0D25193 -- C:\Windows\winsxs\amd64_microsoft-windows-cngaudit-dll_31bf3856ad364e35_6.0.6000.16386_none_424bc4aceb06de1c\cngaudit.dll

[2006/11/02 10:46:03 | 000,011,776 | ---- | M] (Microsoft Corporation) MD5=7F15B4953378C8B5161D65C26D5FED4D -- C:\Windows\SysWOW64\cngaudit.dll

[2006/11/02 10:46:03 | 000,011,776 | ---- | M] (Microsoft Corporation) MD5=7F15B4953378C8B5161D65C26D5FED4D -- C:\Windows\SysWOW64\cngaudit.dll

[2006/11/02 10:46:03 | 000,011,776 | ---- | M] (Microsoft Corporation) MD5=7F15B4953378C8B5161D65C26D5FED4D -- C:\Windows\winsxs\x86_microsoft-windows-cngaudit-dll_31bf3856ad364e35_6.0.6000.16386_none_e62d292932a96ce6\cngaudit.dll

 

< MD5 for: IASTORV.SYS >

[2008/01/21 03:46:59 | 000,290,872 | ---- | M] (Intel Corporation) MD5=3E3BF3627D886736D0B4E90054F929F6 -- C:\Windows\winsxs\amd64_iastorv.inf_31bf3856ad364e35_6.0.6001.18000_none_0b2fedfc40256bc5\iaStorV.sys

 

< MD5 for: NETLOGON.DLL >

[2008/01/21 03:51:03 | 000,716,800 | ---- | M] (Microsoft Corporation) MD5=5D0A4891F8CD0E9E64FF57A6A34044F5 -- C:\Windows\winsxs\amd64_microsoft-windows-security-netlogon_31bf3856ad364e35_6.0.6001.18000_none_59d652c6f057598d\netlogon.dll

[2008/01/21 03:48:28 | 000,592,384 | ---- | M] (Microsoft Corporation) MD5=A8EFC0B6E75B789F7FD3BA5025D4E37F -- C:\Windows\SysWOW64\netlogon.dll

[2008/01/21 03:48:28 | 000,592,384 | ---- | M] (Microsoft Corporation) MD5=A8EFC0B6E75B789F7FD3BA5025D4E37F -- C:\Windows\SysWOW64\netlogon.dll

[2008/01/21 03:48:28 | 000,592,384 | ---- | M] (Microsoft Corporation) MD5=A8EFC0B6E75B789F7FD3BA5025D4E37F -- C:\Windows\winsxs\wow64_microsoft-windows-security-netlogon_31bf3856ad364e35_6.0.6001.18000_none_642afd1924b81b88\netlogon.dll

 

< MD5 for: NVSTOR.SYS >

[2008/01/21 03:46:54 | 000,054,328 | ---- | M] (NVIDIA Corporation) MD5=F7EA0FE82842D05EDA3EFDD376DBFDBA -- C:\Windows\winsxs\amd64_nvraid.inf_31bf3856ad364e35_6.0.6001.18000_none_95f95eab775c159d\nvstor.sys

 

< MD5 for: SCECLI.DLL >

[2008/01/21 03:50:28 | 000,177,152 | ---- | M] (Microsoft Corporation) MD5=28B84EB538F7E8A0FE8B9299D591E0B9 -- C:\Windows\SysWOW64\scecli.dll

[2008/01/21 03:50:28 | 000,177,152 | ---- | M] (Microsoft Corporation) MD5=28B84EB538F7E8A0FE8B9299D591E0B9 -- C:\Windows\SysWOW64\scecli.dll

[2008/01/21 03:50:28 | 000,177,152 | ---- | M] (Microsoft Corporation) MD5=28B84EB538F7E8A0FE8B9299D591E0B9 -- C:\Windows\winsxs\wow64_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.0.6001.18000_none_9e812831c5d9a243\scecli.dll

[2008/01/21 03:49:49 | 000,235,520 | ---- | M] (Microsoft Corporation) MD5=35F1DD99F9903BC267C2AF16B09F9BF7 -- C:\Windows\winsxs\amd64_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.0.6001.18000_none_942c7ddf9178e048\scecli.dll

 

< %systemroot%\*. /mp /s >

 

< %systemroot%\system32\*.dll /lockedfiles >

[2008/01/21 03:49:43 | 000,347,136 | ---- | M] (Microsoft Corporation) Unable to obtain MD5 -- C:\Windows\SysWOW64\dxtmsft.dll

[2008/01/21 03:49:43 | 000,214,528 | ---- | M] (Microsoft Corporation) Unable to obtain MD5 -- C:\Windows\SysWOW64\dxtrans.dll

 

< %systemroot%\Tasks\*.job /lockedfiles >

 

< %systemroot%\system32\drivers\*.sys /lockedfiles >

 

========== Alternate Data Streams ==========

 

@Alternate Data Stream - 115 bytes -> C:\ProgramData\TEMP:A8ADE5D8

@Alternate Data Stream - 109 bytes -> C:\ProgramData\TEMP:DFC5A2B2

< End of report >

Posted

I didn't do it correctly did I?

 

Ok hopefully here's another otf log AND extras

cheers

jim

OTL logfile created on: 01/08/2010 08:09:44 - Run 3

OTL by OldTimer - Version 3.2.9.1 Folder = C:\Users\Helen\Desktop\computer rescue tools

64bit-Windows Vista Home Premium Edition Service Pack 1 (Version = 6.0.6001) - Type = NTWorkstation

Internet Explorer (Version = 7.0.6001.18000)

Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy

3.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 52.00% Memory free

6.00 Gb Paging File | 4.00 Gb Available in Paging File | 72.00% Paging File free

Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)

Drive C: | 451.07 Gb Total Space | 361.16 Gb Free Space | 80.07% Space Free | Partition Type: NTFS

Drive D: | 14.65 Gb Total Space | 13.59 Gb Free Space | 92.74% Space Free | Partition Type: NTFS

E: Drive not present or media not loaded

F: Drive not present or media not loaded

G: Drive not present or media not loaded

H: Drive not present or media not loaded

I: Drive not present or media not loaded

Computer Name: HELEN-PC

Current User Name: Helen

Logged in as Administrator.

Current Boot Mode: Normal

Scan Mode: Current user

Include 64bit Scans

Company Name Whitelist: Off

Skip Microsoft Files: Off

File Age = 30 Days

Output = Minimal

========== Processes (SafeList) ==========

PRC - C:\Users\Helen\Desktop\computer rescue tools\OTL.exe (OldTimer Tools)

PRC - C:\Program Files (x86)\Trusteer\Rapport\bin\RapportService.exe (Trusteer Ltd.)

PRC - C:\Program Files (x86)\Trusteer\Rapport\bin\RapportMgmtService.exe (Trusteer Ltd.)

PRC - C:\Program Files (x86)\TomTom HOME 2\TomTomHOMEService.exe (TomTom)

PRC - C:\Program Files (x86)\TomTom HOME 2\TomTomHOMERunner.exe (TomTom)

PRC - C:\Program Files (x86)\Spybot - Search & Destroy\TeaTimer.exe (Safer-Networking Ltd.)

PRC - C:\Program Files (x86)\Spybot - Search & Destroy\SDWinSec.exe (Safer Networking Ltd.)

PRC - C:\Program Files (x86)\Dell\OSD\AIO_OSD.exe (Dell Corporation)

PRC - C:\Program Files (x86)\Dell\OSD\OSDSvr.exe ()

PRC - C:\Program Files (x86)\Dell V505\dldwmsdmon.exe ()

PRC - C:\Program Files (x86)\Dell V505\dldwmon.exe ()

PRC - C:\Program Files (x86)\CyberLink\PowerDVD DX\PDVDDXSrv.exe (CyberLink Corp.)

PRC - C:\Program Files (x86)\Common Files\microsoft shared\ink\TabTip32.exe (Microsoft Corporation)

========== Modules (SafeList) ==========

MOD - C:\Users\Helen\Desktop\computer rescue tools\OTL.exe (OldTimer Tools)

MOD - C:\Program Files (x86)\Trusteer\Rapport\bin\rooksbas.dll (Trusteer Ltd.)

MOD - C:\Program Files (x86)\Common Files\microsoft shared\ink\tiptsf.dll (Microsoft Corporation)

MOD - C:\Windows\SysWOW64\msscript.ocx (Microsoft Corporation)

MOD - C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6001.18000_none_5cdbaa5a083979cc\comctl32.dll (Microsoft Corporation)

========== Win32 Services (SafeList) ==========

SRV:64bit: - (CSIScanner) -- C:\Program Files\Prevx\prevx.exe (Prevx)

SRV:64bit: - (wltrysvc) -- C:\Windows\SysNative\WLTRYSVC.EXE ()

SRV:64bit: - (AERTFilters) -- C:\Program Files\Realtek\Audio\HDA\AERTSr64.exe (Andrea Electronics Corporation)

SRV:64bit: - (dldwCATSCustConnectService) -- C:\Windows\SysNative\spool\DRIVERS\x64\3\\dldwserv.exe ()

SRV:64bit: - (dldw_device) -- C:\Windows\SysNative\dldwcoms.exe ()

SRV:64bit: - (WinDefend) -- C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)

SRV - (RapportLaunService) -- C:\Program Files (x86)\Trusteer\Rapport\bin\RapportLaunService64.exe (Trusteer Ltd.)

SRV - (RapportMgmtService) -- C:\Program Files (x86)\Trusteer\Rapport\bin\RapportMgmtService.exe (Trusteer Ltd.)

SRV - (GoToAssist) -- C:\Program Files (x86)\Citrix\GoToAssist\514\g2aservice.exe (Citrix Online, a division of Citrix Systems, Inc.)

SRV - (TomTomHOMEService) -- C:\Program Files (x86)\TomTom HOME 2\TomTomHOMEService.exe (TomTom)

SRV - (SBSDWSCService) -- C:\Program Files (x86)\Spybot - Search & Destroy\SDWinSec.exe (Safer Networking Ltd.)

SRV - (FOXOSDService) -- C:\Program Files (x86)\Dell\OSD\OSDSvr.exe ()

SRV - (dldw_device) -- C:\Windows\SysWow64\dldwcoms.exe ( )

========== Driver Services (SafeList) ==========

DRV:64bit: - (NwlnkFwd) -- C:\Windows\SysNative\DRIVERS\nwlnkfwd.sys File not found

DRV:64bit: - (NwlnkFlt) -- C:\Windows\SysNative\DRIVERS\nwlnkflt.sys File not found

DRV:64bit: - (IpInIp) -- C:\Windows\SysNative\DRIVERS\ipinip.sys File not found

DRV:64bit: - (pxrts) -- C:\Windows\SysNative\drivers\pxrts.sys ()

DRV:64bit: - (pxscan) -- C:\Windows\SysNative\drivers\pxscan.sys ()

DRV:64bit: - (pxkbf) -- C:\Windows\SysNative\drivers\pxkbf.sys ()

DRV:64bit: - (FXOSDDRV) -- C:\Windows\SysNative\DRIVERS\FxOSDdrv64.sys ()

DRV:64bit: - (BCM42RLY) -- C:\Windows\SysNative\drivers\BCM42RLY.sys ()

DRV:64bit: - (BCM43XX) -- C:\Windows\SysNative\DRIVERS\bcmwl664.sys ()

DRV:64bit: - (CtClsFlt) -- C:\Windows\SysNative\DRIVERS\CtClsFlt.sys ()

DRV:64bit: - (nvamacpi) -- C:\Windows\SysNative\DRIVERS\NVAMACPI.sys ()

DRV:64bit: - (b57nd60a) -- C:\Windows\SysNative\DRIVERS\b57nd60a.sys ()

DRV:64bit: - (WSDPrintDevice) -- C:\Windows\SysNative\DRIVERS\WSDPrint.sys ()

DRV:64bit: - (PxHlpa64) -- C:\Windows\SysNative\Drivers\PxHlpa64.sys ()

DRV:64bit: - (Ntfs) -- C:\Windows\SysNative\Wbem\ntfs.mof ()

DRV - (RapportKE64) -- C:\Program Files (x86)\Trusteer\Rapport\bin\RapportKE64.sys (Trusteer Ltd.)

DRV - (RapportPG64) -- C:\Program Files (x86)\Trusteer\Rapport\bin\RapportPG64.sys (Trusteer Ltd.)

========== Standard Registry (SafeList) ==========

========== Internet Explorer ==========

IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = about:blank

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1

IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

[2010/03/13 12:17:54 | 000,000,000 | ---D | M] -- C:\Users\Helen\AppData\Roaming\mozilla\Extensions

[2010/03/13 12:17:54 | 000,000,000 | ---D | M] -- C:\Users\Helen\AppData\Roaming\mozilla\Extensions\home2@tomtom.com

O1 HOSTS File: ([2010/03/30 01:24:59 | 000,380,983 | R--- | M]) - C:\Windows\SysNative\drivers\etc\Hosts

O1 - Hosts: 127.0.0.1 localhost

O1 - Hosts: ::1 localhost

O1 - Hosts: 127.0.0.1 007guard.com - 007guard and Windows Vista

O1 - Hosts: 127.0.0.1 007guard.com

O1 - Hosts: 127.0.0.1 008i.com

O1 - Hosts: 127.0.0.1 008k.com

O1 - Hosts: 127.0.0.1 008k.com

O1 - Hosts: 127.0.0.1 00hq.com

O1 - Hosts: 127.0.0.1 00hq.com

O1 - Hosts: 127.0.0.1 010402.com

O1 - Hosts: 127.0.0.1 http://www.032439.com

O1 - Hosts: 127.0.0.1 032439.com

O1 - Hosts: 127.0.0.1 0scan.com

O1 - Hosts: 127.0.0.1 0scan.com

O1 - Hosts: 127.0.0.1 1000gratisproben.com

O1 - Hosts: 127.0.0.1 http://www.1000gratisproben.com

O1 - Hosts: 127.0.0.1 1001namen.com

O1 - Hosts: 127.0.0.1 1001namen.com

O1 - Hosts: 127.0.0.1 100888290cs.com

O1 - Hosts: 127.0.0.1 http://www.100888290cs.com

O1 - Hosts: 127.0.0.1 100sexlinks.com

O1 - Hosts: 127.0.0.1 100sexlinks.com

O1 - Hosts: 127.0.0.1 10sek.com

O1 - Hosts: 127.0.0.1 10sek.com

O1 - Hosts: 127.0.0.1 http://www.1-2005-search.com

O1 - Hosts: 13125 more lines...

O2 - BHO: (Spybot-S&D IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files (x86)\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)

O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {472734EA-242A-422B-ADF8-83D1E48CC825} - No CLSID value found.

O4:64bit: - HKLM..\Run: [broadcom Wireless Manager UI] C:\Windows\SysNative\WLTRAY.exe ()

O4:64bit: - HKLM..\Run: [dldwamon] C:\Program Files (x86)\Dell V505\dldwamon.exe ()

O4:64bit: - HKLM..\Run: [dldwmon.exe] C:\Program Files (x86)\Dell V505\dldwmon.exe ()

O4:64bit: - HKLM..\Run: [NvCplDaemon] C:\Windows\SysNative\NvCpl.DLL ()

O4:64bit: - HKLM..\Run: [NvMediaCenter] C:\Windows\SysNative\NvMcTray.DLL ()

O4:64bit: - HKLM..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Realtek Semiconductor)

O4:64bit: - HKLM..\Run: [skytel] C:\Program Files\Realtek\Audio\HDA\Skytel.exe File not found

O4:64bit: - HKLM..\Run: [Windows Defender] C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)

O4 - HKLM..\Run: [Dell V505] C:\Program Files (x86)\Dell V505\fm3032.exe ()

O4 - HKLM..\Run: [PDVDDXSrv] C:\Program Files (x86)\CyberLink\PowerDVD DX\PDVDDXSrv.exe (CyberLink Corp.)

O4 - HKCU..\Run: [spybotSD TeaTimer] C:\Program Files (x86)\Spybot - Search & Destroy\TeaTimer.exe (Safer-Networking Ltd.)

O4 - HKCU..\Run: [TomTomHOME.exe] C:\Program Files (x86)\TomTom HOME 2\TomTomHOMERunner.exe (TomTom)

O4 - HKCU..\Run: [WMPNSCFG] C:\Program Files (x86)\Windows Media Player\WMPNSCFG.exe File not found

O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1

O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0

O9 - Extra Button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)

O9 - Extra 'Tools' menuitem : S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)

O9 - Extra 'Tools' menuitem : Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files (x86)\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)

O13 - gopher Prefix: missing

O13 - gopher Prefix: missing

O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab (Reg Error: Key error.)

O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)

O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.254

O18:64bit: - Protocol\Handler\belarc {6318E0AB-2E93-11D1-B8ED-00608CC9A71F} - Reg Error: Key error. File not found

O18:64bit: - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - Reg Error: Key error. File not found

O18 - Protocol\Handler\belarc {6318E0AB-2E93-11D1-B8ED-00608CC9A71F} - C:\Program Files (x86)\Belarc\Advisor\System\BAVoilaX.dll (Belarc, Inc.)

O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)

O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)

O20:64bit: - Winlogon\Notify\GoToAssist: DllName - Reg Error: Key error. - C:\Program Files (x86)\Citrix\GoToAssist\514\G2AWinLogon_x64.dll File not found

O32 - HKLM CDRom: AutoRun - 1

O33 - MountPoints2\{9e4670ed-127e-11df-9ed4-0024e80c7d96}\Shell\AutoRun\command - "" = G:\setup.exe -- File not found

O33 - MountPoints2\{a1420bea-2e91-11df-bb67-0024e80c7d96}\Shell\AutoRun\command - "" = G:\InstallTomTomHOME.exe -- File not found

O33 - MountPoints2\{e1d32dda-ac7b-1e55-b16e-806e6f6e6963}\Shell - "" = AutoRun

O34 - HKLM BootExecute: (autocheck autochk *) - File not found

O35:64bit: - HKLM\..comfile [open] -- "%1" %*

O35:64bit: - HKLM\..exefile [open] -- "%1" %*

O35 - HKLM\..comfile [open] -- "%1" %*

O35 - HKLM\..exefile [open] -- "%1" %*

O37:64bit: - HKLM\...com [@ = comfile] -- "%1" %*

O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %*

O37 - HKLM\...com [@ = comfile] -- "%1" %*

O37 - HKLM\...exe [@ = exefile] -- "%1" %*

CREATERESTOREPOINT

Restore point Set: OTL Restore Point

========== Files/Folders - Created Within 30 Days ==========

[8509/06/13 02:43:19 | 000,000,000 | ---D | C] -- C:\Windows\Panther

[8509/06/13 02:42:50 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\OEM

[8509/06/12 19:46:10 | 000,000,000 | ---D | C] -- C:\Windows\Debug

[8509/06/12 17:49:19 | 000,000,000 | ---D | C] -- C:\Windows\SoftwareDistribution

[8509/06/12 17:44:12 | 000,000,000 | ---D | C] -- C:\Windows\Prefetch

[2010/07/31 21:56:52 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Speccy

[2010/07/31 19:14:03 | 000,038,224 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\SysWow64\drivers\mbamswissarmy.sys

[2010/07/31 19:14:01 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Malwarebytes' Anti-Malware

[2010/07/31 17:48:07 | 000,060,928 | ---- | C] (Prevx) -- C:\Windows\SysWow64\PxSecure.dll

[2010/07/31 17:48:05 | 000,000,000 | ---D | C] -- C:\Program Files\Prevx

[2010/07/31 17:47:44 | 000,000,000 | ---D | C] -- C:\ProgramData\PrevxCSI

[2010/07/31 11:54:53 | 000,000,000 | ---D | C] -- C:\Users\Helen\Documents\Dell WebCam Central

[2010/02/11 13:38:08 | 000,364,544 | ---- | C] ( ) -- C:\Windows\SysWow64\dldwinpa.dll

[2010/02/11 13:38:08 | 000,339,968 | ---- | C] ( ) -- C:\Windows\SysWow64\dldwiesc.dll

[2010/02/11 13:38:06 | 000,651,264 | ---- | C] ( ) -- C:\Windows\SysWow64\dldwpmui.dll

[2010/02/11 13:38:04 | 000,851,968 | ---- | C] ( ) -- C:\Windows\SysWow64\dldwusb1.dll

[2010/02/11 13:38:03 | 001,069,056 | ---- | C] ( ) -- C:\Windows\SysWow64\dldwserv.dll

[2010/02/11 13:38:02 | 000,577,536 | ---- | C] ( ) -- C:\Windows\SysWow64\dldwlmpm.dll

[2010/02/11 13:38:01 | 000,679,936 | ---- | C] ( ) -- C:\Windows\SysWow64\dldwhbn3.dll

[2010/02/11 13:38:00 | 000,376,832 | ---- | C] ( ) -- C:\Windows\SysWow64\dldwcomm.dll

[2010/02/11 13:37:59 | 000,765,952 | ---- | C] ( ) -- C:\Windows\SysWow64\dldwcomc.dll

[1 C:\ProgramData\*.tmp files -> C:\ProgramData\*.tmp -> ]

[1 C:\ProgramData\*.tmp files -> C:\ProgramData\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[8509/06/12 17:52:05 | 000,047,092 | ---- | M] () -- C:\Windows\SysNative\license.rtf

[8509/06/12 17:51:28 | 000,000,000 | -H-- | M] () -- C:\Windows\SysNative\drivers\Msft_User_WpdFs_01_00_00.Wdf

[2010/08/01 08:09:09 | 000,003,616 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0

[2010/08/01 08:09:09 | 000,003,616 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0

[2010/08/01 08:07:18 | 007,340,032 | -HS- | M] () -- C:\Users\Helen\ntuser.dat

[2010/08/01 07:43:26 | 000,000,217 | ---- | M] () -- C:\Users\Helen\Desktop\Google.url

[2010/08/01 07:31:04 | 000,000,894 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job

[2010/08/01 07:22:48 | 000,002,651 | ---- | M] () -- C:\Users\Helen\Desktop\Microsoft Office Word 2007.lnk

[2010/08/01 07:15:11 | 000,690,960 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI

[2010/08/01 07:15:11 | 000,599,942 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat

[2010/08/01 07:15:11 | 000,105,448 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat

[2010/08/01 07:08:17 | 000,000,890 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job

[2010/08/01 07:08:08 | 000,065,536 | ---- | M] () -- C:\Windows\SysNative\Ikeext.etl

[2010/08/01 07:08:01 | 000,000,006 | -H-- | M] () -- C:\Windows\tasks\SA.DAT

[2010/08/01 07:07:54 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat

[2010/08/01 00:20:52 | 000,524,288 | -HS- | M] () -- C:\Users\Helen\ntuser.dat{bd1e410d-9cbe-11df-b61d-0024e80c7d96}.TMContainer00000000000000000001.regtrans-ms

[2010/08/01 00:20:52 | 000,065,536 | -HS- | M] () -- C:\Users\Helen\ntuser.dat{bd1e410d-9cbe-11df-b61d-0024e80c7d96}.TM.blf

[2010/08/01 00:20:22 | 001,692,897 | -H-- | M] () -- C:\Users\Helen\AppData\Local\IconCache.db

[2010/07/31 23:50:48 | 000,000,208 | ---- | M] () -- C:\Users\Helen\Desktop\BBC - Homepage.url

[2010/07/31 23:49:51 | 000,000,211 | ---- | M] () -- C:\Users\Helen\Desktop\Runbox.url

[2010/07/31 20:28:41 | 000,010,601 | ---- | M] () -- C:\Users\Helen\Documents\Malwarebytes2.docx

[2010/07/31 20:27:49 | 000,010,801 | ---- | M] () -- C:\Users\Helen\Documents\Malwarebytes1.docx

[2010/07/31 20:27:06 | 000,002,619 | ---- | M] () -- C:\Users\Helen\Desktop\Microsoft Office PowerPoint 2007.lnk

[2010/07/31 19:01:17 | 000,018,754 | ---- | M] () -- C:\Users\Helen\Documents\OTL Extras logfile created o1.docx

[2010/07/31 19:00:09 | 000,020,335 | ---- | M] () -- C:\Users\Helen\Documents\OTL Extras logfile created on.docx

[2010/07/31 17:48:07 | 000,060,928 | ---- | M] (Prevx) -- C:\Windows\SysWow64\PxSecure.dll

[2010/07/31 17:48:06 | 000,056,320 | ---- | M] () -- C:\Windows\SysNative\drivers\pxrts.sys

[2010/07/31 17:48:06 | 000,034,696 | ---- | M] () -- C:\Windows\SysNative\drivers\pxscan.sys

[2010/07/31 17:48:06 | 000,022,336 | ---- | M] () -- C:\Windows\SysNative\drivers\pxkbf.sys

[2010/07/31 17:47:53 | 000,000,050 | ---- | M] () -- C:\Windows\wininit.ini

[2010/07/31 17:34:44 | 000,524,288 | -HS- | M] () -- C:\Users\Helen\ntuser.dat{bd1e410d-9cbe-11df-b61d-0024e80c7d96}.TMContainer00000000000000000002.regtrans-ms

[2010/07/31 17:21:04 | 000,524,288 | -HS- | M] () -- C:\Users\Helen\NTUSER.DAT{bef7d13c-9b13-11df-83ed-0024e80c7d96}.TMContainer00000000000000000001.regtrans-ms

[2010/07/31 17:21:04 | 000,065,536 | -HS- | M] () -- C:\Users\Helen\NTUSER.DAT{bef7d13c-9b13-11df-83ed-0024e80c7d96}.TM.blf

[2010/07/30 01:47:38 | 000,524,288 | -HS- | M] () -- C:\Users\Helen\NTUSER.DAT{bef7d13c-9b13-11df-83ed-0024e80c7d96}.TMContainer00000000000000000002.regtrans-ms

[2010/07/29 22:11:04 | 000,002,826 | ---- | M] () -- C:\Users\Helen\Desktop\Ancestry.url

[2010/07/29 14:35:44 | 000,034,304 | ---- | M] () -- C:\Users\Helen\Desktop\Our Branch of Bennisons.doc

[2010/07/29 12:32:26 | 000,524,288 | -HS- | M] () -- C:\Users\Helen\NTUSER.DAT{f0f03d89-0deb-11df-b0f6-0024e80c7d96}.TMContainer00000000000000000001.regtrans-ms

[2010/07/29 12:32:26 | 000,065,536 | -HS- | M] () -- C:\Users\Helen\NTUSER.DAT{f0f03d89-0deb-11df-b0f6-0024e80c7d96}.TM.blf

[2010/07/25 16:46:23 | 001,146,091 | ---- | M] () -- C:\Users\Helen\Desktop\011074.pdf

[2010/07/25 00:53:13 | 000,030,720 | ---- | M] () -- C:\Users\Helen\Desktop\MRI scanning.doc

[2010/07/23 14:04:11 | 000,595,264 | ---- | M] () -- C:\Users\Helen\Desktop\HIS10_Coronary_angioplasty_0509.pdf

[2010/07/13 12:10:48 | 000,735,435 | ---- | M] () -- C:\Users\Helen\Desktop\Extras_Page.pdf

[2010/07/13 12:10:39 | 000,797,067 | ---- | M] () -- C:\Users\Helen\Desktop\Directions_to_Mimosa_.pdf

[2010/07/13 12:10:29 | 000,794,036 | ---- | M] () -- C:\Users\Helen\Desktop\Directions_to_Century_Wharf.pdf

[2010/07/13 12:10:14 | 000,075,729 | ---- | M] () -- C:\Users\Helen\Desktop\TermsOfBusinessMain.pdf

[2010/07/13 12:10:06 | 000,242,087 | ---- | M] () -- C:\Users\Helen\Desktop\receipt_12934_20100713-00003.pdf

[2010/07/13 12:09:57 | 000,243,042 | ---- | M] () -- C:\Users\Helen\Desktop\invoice_10194_20100713-00003.pdf

[2010/07/13 12:09:46 | 000,258,734 | ---- | M] () -- C:\Users\Helen\Desktop\checkinLetterManaged20100713-00003.pdf

[2010/07/03 19:21:49 | 000,327,052 | ---- | M] () -- C:\Users\Helen\Documents\03-07-2010 19;21;24.rtf

[1 C:\ProgramData\*.tmp files -> C:\ProgramData\*.tmp -> ]

[1 C:\ProgramData\*.tmp files -> C:\ProgramData\*.tmp -> ]

========== Files Created - No Company Name ==========

[8509/06/12 17:51:28 | 000,000,000 | -H-- | C] () -- C:\Windows\SysNative\drivers\Msft_User_WpdFs_01_00_00.Wdf

[2010/07/31 20:28:40 | 000,010,601 | ---- | C] () -- C:\Users\Helen\Documents\Malwarebytes2.docx

[2010/07/31 20:27:49 | 000,010,801 | ---- | C] () -- C:\Users\Helen\Documents\Malwarebytes1.docx

[2010/07/31 19:01:16 | 000,018,754 | ---- | C] () -- C:\Users\Helen\Documents\OTL Extras logfile created o1.docx

[2010/07/31 19:00:08 | 000,020,335 | ---- | C] () -- C:\Users\Helen\Documents\OTL Extras logfile created on.docx

[2010/07/31 17:48:06 | 000,056,320 | ---- | C] () -- C:\Windows\SysNative\drivers\pxrts.sys

[2010/07/31 17:48:06 | 000,034,696 | ---- | C] () -- C:\Windows\SysNative\drivers\pxscan.sys

[2010/07/31 17:48:06 | 000,022,336 | ---- | C] () -- C:\Windows\SysNative\drivers\pxkbf.sys

[2010/07/31 17:47:44 | 000,000,050 | ---- | C] () -- C:\Windows\wininit.ini

[2010/07/31 17:23:53 | 000,524,288 | -HS- | C] () -- C:\Users\Helen\ntuser.dat{bd1e410d-9cbe-11df-b61d-0024e80c7d96}.TMContainer00000000000000000002.regtrans-ms

[2010/07/31 17:23:53 | 000,524,288 | -HS- | C] () -- C:\Users\Helen\ntuser.dat{bd1e410d-9cbe-11df-b61d-0024e80c7d96}.TMContainer00000000000000000001.regtrans-ms

[2010/07/31 17:23:53 | 000,065,536 | -HS- | C] () -- C:\Users\Helen\ntuser.dat{bd1e410d-9cbe-11df-b61d-0024e80c7d96}.TM.blf

[2010/07/29 14:19:50 | 000,524,288 | -HS- | C] () -- C:\Users\Helen\NTUSER.DAT{bef7d13c-9b13-11df-83ed-0024e80c7d96}.TMContainer00000000000000000002.regtrans-ms

[2010/07/29 14:19:50 | 000,524,288 | -HS- | C] () -- C:\Users\Helen\NTUSER.DAT{bef7d13c-9b13-11df-83ed-0024e80c7d96}.TMContainer00000000000000000001.regtrans-ms

[2010/07/29 14:19:50 | 000,065,536 | -HS- | C] () -- C:\Users\Helen\NTUSER.DAT{bef7d13c-9b13-11df-83ed-0024e80c7d96}.TM.blf

[2010/07/29 01:32:11 | 000,034,304 | ---- | C] () -- C:\Users\Helen\Desktop\Our Branch of Bennisons.doc

[2010/07/25 16:46:22 | 001,146,091 | ---- | C] () -- C:\Users\Helen\Desktop\011074.pdf

[2010/07/24 16:23:46 | 000,030,720 | ---- | C] () -- C:\Users\Helen\Desktop\MRI scanning.doc

[2010/07/23 14:04:09 | 000,595,264 | ---- | C] () -- C:\Users\Helen\Desktop\HIS10_Coronary_angioplasty_0509.pdf

[2010/07/13 12:10:47 | 000,735,435 | ---- | C] () -- C:\Users\Helen\Desktop\Extras_Page.pdf

[2010/07/13 12:10:38 | 000,797,067 | ---- | C] () -- C:\Users\Helen\Desktop\Directions_to_Mimosa_.pdf

[2010/07/13 12:10:28 | 000,794,036 | ---- | C] () -- C:\Users\Helen\Desktop\Directions_to_Century_Wharf.pdf

[2010/07/13 12:10:14 | 000,075,729 | ---- | C] () -- C:\Users\Helen\Desktop\TermsOfBusinessMain.pdf

[2010/07/13 12:10:06 | 000,242,087 | ---- | C] () -- C:\Users\Helen\Desktop\receipt_12934_20100713-00003.pdf

[2010/07/13 12:09:57 | 000,243,042 | ---- | C] () -- C:\Users\Helen\Desktop\invoice_10194_20100713-00003.pdf

[2010/07/13 12:09:45 | 000,258,734 | ---- | C] () -- C:\Users\Helen\Desktop\checkinLetterManaged20100713-00003.pdf

[2010/07/03 19:21:48 | 000,327,052 | ---- | C] () -- C:\Users\Helen\Documents\03-07-2010 19;21;24.rtf

[2010/02/11 13:38:08 | 000,389,120 | ---- | C] () -- C:\Windows\SysWow64\DLDWinst.dll

[2010/02/11 13:38:08 | 000,335,872 | ---- | C] () -- C:\Windows\SysWow64\dldwcomx.dll

[2010/02/11 13:38:07 | 000,147,456 | ---- | C] () -- C:\Windows\SysWow64\dldwjswr.dll

[2010/02/11 13:38:07 | 000,106,496 | ---- | C] () -- C:\Windows\SysWow64\dldwinsr.dll

[2010/02/11 13:38:07 | 000,036,864 | ---- | C] () -- C:\Windows\SysWow64\dldwcur.dll

[2010/02/11 13:38:06 | 000,520,192 | ---- | C] () -- C:\Windows\SysWow64\dldwutil.dll

[2010/02/11 13:38:06 | 000,180,224 | ---- | C] () -- C:\Windows\SysWow64\dldwinsb.dll

[2010/02/11 13:38:06 | 000,176,128 | ---- | C] () -- C:\Windows\SysWow64\dldwins.dll

[2010/02/11 13:38:05 | 000,086,016 | ---- | C] () -- C:\Windows\SysWow64\dldwcub.dll

[2010/02/11 13:38:04 | 000,077,824 | ---- | C] () -- C:\Windows\SysWow64\dldwcu.dll

[2010/02/11 13:37:59 | 000,077,906 | ---- | C] () -- C:\Windows\SysWow64\DLDWcfg.dll

[2010/02/01 14:23:28 | 000,327,168 | ---- | C] () -- C:\Windows\SysWow64\cutil32.dll

[2008/05/07 21:42:00 | 001,036,288 | ---- | C] () -- C:\Windows\SysWow64\dldwdrs.dll

[2008/04/23 08:53:14 | 000,081,920 | ---- | C] () -- C:\Windows\SysWow64\dldwcaps.dll

[2008/02/26 20:24:06 | 000,069,632 | ---- | C] () -- C:\Windows\SysWow64\dldwcnv4.dll

[2008/01/21 03:50:05 | 000,060,124 | ---- | C] () -- C:\Windows\SysWow64\tcpmon.ini

[2008/01/21 03:49:49 | 000,368,640 | ---- | C] () -- C:\Windows\SysWow64\msjetoledb40.dll

========== LOP Check ==========

[2009/12/01 01:34:08 | 000,000,000 | ---D | M] -- C:\Users\Helen\AppData\Roaming\com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1

[2010/03/13 12:17:54 | 000,000,000 | ---D | M] -- C:\Users\Helen\AppData\Roaming\TomTom

[2010/02/15 00:55:51 | 000,000,000 | ---D | M] -- C:\Users\Helen\AppData\Roaming\Trusteer

[2009/06/19 15:09:44 | 000,000,000 | ---D | M] -- C:\Users\Helen\AppData\Roaming\V505 Series

[2010/06/27 02:02:00 | 000,000,366 | ---- | M] () -- C:\Windows\Tasks\Driver Robot.job

[2010/08/01 00:20:32 | 000,032,622 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT

========== Purity Check ==========

========== Custom Scans ==========

< %SYSTEMDRIVE%\*.exe >

< MD5 for: AGP440.SYS >

[2008/01/21 03:46:51 | 000,064,568 | ---- | M] (Microsoft Corporation) MD5=F6F6793B7F17B550ECFDBD3B229173F7 -- C:\Windows\winsxs\amd64_machine.inf_31bf3856ad364e35_6.0.6001.18000_none_163188bf770e4ab0\AGP440.sys

< MD5 for: ATAPI.SYS >

[2008/01/21 03:46:50 | 000,022,584 | ---- | M] (Microsoft Corporation) MD5=1898FAE8E07D97F2F6C2D5326C633FAC -- C:\Windows\winsxs\amd64_mshdc.inf_31bf3856ad364e35_6.0.6001.18000_none_3956c39dd9e73fd2\atapi.sys

< MD5 for: CNGAUDIT.DLL >

[2006/11/02 12:16:48 | 000,014,848 | ---- | M] (Microsoft Corporation) MD5=21322B1A2AD337C579F4A65EA0D25193 -- C:\Windows\winsxs\amd64_microsoft-windows-cngaudit-dll_31bf3856ad364e35_6.0.6000.16386_none_424bc4aceb06de1c\cngaudit.dll

[2006/11/02 10:46:03 | 000,011,776 | ---- | M] (Microsoft Corporation) MD5=7F15B4953378C8B5161D65C26D5FED4D -- C:\Windows\SysWOW64\cngaudit.dll

[2006/11/02 10:46:03 | 000,011,776 | ---- | M] (Microsoft Corporation) MD5=7F15B4953378C8B5161D65C26D5FED4D -- C:\Windows\SysWOW64\cngaudit.dll

[2006/11/02 10:46:03 | 000,011,776 | ---- | M] (Microsoft Corporation) MD5=7F15B4953378C8B5161D65C26D5FED4D -- C:\Windows\winsxs\x86_microsoft-windows-cngaudit-dll_31bf3856ad364e35_6.0.6000.16386_none_e62d292932a96ce6\cngaudit.dll

< MD5 for: IASTORV.SYS >

[2008/01/21 03:46:59 | 000,290,872 | ---- | M] (Intel Corporation) MD5=3E3BF3627D886736D0B4E90054F929F6 -- C:\Windows\winsxs\amd64_iastorv.inf_31bf3856ad364e35_6.0.6001.18000_none_0b2fedfc40256bc5\iaStorV.sys

< MD5 for: NETLOGON.DLL >

[2008/01/21 03:51:03 | 000,716,800 | ---- | M] (Microsoft Corporation) MD5=5D0A4891F8CD0E9E64FF57A6A34044F5 -- C:\Windows\winsxs\amd64_microsoft-windows-security-netlogon_31bf3856ad364e35_6.0.6001.18000_none_59d652c6f057598d\netlogon.dll

[2008/01/21 03:48:28 | 000,592,384 | ---- | M] (Microsoft Corporation) MD5=A8EFC0B6E75B789F7FD3BA5025D4E37F -- C:\Windows\SysWOW64\netlogon.dll

[2008/01/21 03:48:28 | 000,592,384 | ---- | M] (Microsoft Corporation) MD5=A8EFC0B6E75B789F7FD3BA5025D4E37F -- C:\Windows\SysWOW64\netlogon.dll

[2008/01/21 03:48:28 | 000,592,384 | ---- | M] (Microsoft Corporation) MD5=A8EFC0B6E75B789F7FD3BA5025D4E37F -- C:\Windows\winsxs\wow64_microsoft-windows-security-netlogon_31bf3856ad364e35_6.0.6001.18000_none_642afd1924b81b88\netlogon.dll

< MD5 for: NVSTOR.SYS >

[2008/01/21 03:46:54 | 000,054,328 | ---- | M] (NVIDIA Corporation) MD5=F7EA0FE82842D05EDA3EFDD376DBFDBA -- C:\Windows\winsxs\amd64_nvraid.inf_31bf3856ad364e35_6.0.6001.18000_none_95f95eab775c159d\nvstor.sys

< MD5 for: SCECLI.DLL >

[2008/01/21 03:50:28 | 000,177,152 | ---- | M] (Microsoft Corporation) MD5=28B84EB538F7E8A0FE8B9299D591E0B9 -- C:\Windows\SysWOW64\scecli.dll

[2008/01/21 03:50:28 | 000,177,152 | ---- | M] (Microsoft Corporation) MD5=28B84EB538F7E8A0FE8B9299D591E0B9 -- C:\Windows\SysWOW64\scecli.dll

[2008/01/21 03:50:28 | 000,177,152 | ---- | M] (Microsoft Corporation) MD5=28B84EB538F7E8A0FE8B9299D591E0B9 -- C:\Windows\winsxs\wow64_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.0.6001.18000_none_9e812831c5d9a243\scecli.dll

[2008/01/21 03:49:49 | 000,235,520 | ---- | M] (Microsoft Corporation) MD5=35F1DD99F9903BC267C2AF16B09F9BF7 -- C:\Windows\winsxs\amd64_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.0.6001.18000_none_942c7ddf9178e048\scecli.dll

< %systemroot%\*. /mp /s >

< %systemroot%\system32\*.dll /lockedfiles >

[2008/01/21 03:49:43 | 000,347,136 | ---- | M] (Microsoft Corporation) Unable to obtain MD5 -- C:\Windows\SysWOW64\dxtmsft.dll

[2008/01/21 03:49:43 | 000,214,528 | ---- | M] (Microsoft Corporation) Unable to obtain MD5 -- C:\Windows\SysWOW64\dxtrans.dll

< %systemroot%\Tasks\*.job /lockedfiles >

< %systemroot%\system32\drivers\*.sys /lockedfiles >

========== Alternate Data Streams ==========

@Alternate Data Stream - 115 bytes -> C:\ProgramData\TEMP:A8ADE5D8

@Alternate Data Stream - 109 bytes -> C:\ProgramData\TEMP:DFC5A2B2

< End of report >

OTL Extras logfile created on: 01/08/2010 08:09:44 - Run 3

OTL by OldTimer - Version 3.2.9.1 Folder = C:\Users\Helen\Desktop\computer rescue tools

64bit-Windows Vista Home Premium Edition Service Pack 1 (Version = 6.0.6001) - Type = NTWorkstation

Internet Explorer (Version = 7.0.6001.18000)

Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy

 

3.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 52.00% Memory free

6.00 Gb Paging File | 4.00 Gb Available in Paging File | 72.00% Paging File free

Paging file location(s): ?:\pagefile.sys [binary data]

 

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)

Drive C: | 451.07 Gb Total Space | 361.16 Gb Free Space | 80.07% Space Free | Partition Type: NTFS

Drive D: | 14.65 Gb Total Space | 13.59 Gb Free Space | 92.74% Space Free | Partition Type: NTFS

E: Drive not present or media not loaded

F: Drive not present or media not loaded

G: Drive not present or media not loaded

H: Drive not present or media not loaded

I: Drive not present or media not loaded

 

Computer Name: HELEN-PC

Current User Name: Helen

Logged in as Administrator.

 

Current Boot Mode: Normal

Scan Mode: Current user

Include 64bit Scans

Company Name Whitelist: Off

Skip Microsoft Files: Off

File Age = 30 Days

Output = Minimal

 

========== Extra Registry (SafeList) ==========

 

 

========== File Associations ==========

 

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]

.cpl [@ = cplfile] -- C:\Windows\SysWow64\control.exe (Microsoft Corporation)

 

========== Shell Spawning ==========

 

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]

batfile [open] -- "%1" %* File not found

cmdfile [open] -- "%1" %* File not found

comfile [open] -- "%1" %* File not found

exefile [open] -- "%1" %* File not found

helpfile [open] -- Reg Error: Key error.

htmlfile [edit] -- "C:\Program Files (x86)\Microsoft Office\Office12\msohtmed.exe" %1 (Microsoft Corporation)

htmlfile [print] -- "C:\Program Files (x86)\Microsoft Office\Office12\msohtmed.exe" /p %1 (Microsoft Corporation)

inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" ()

piffile [open] -- "%1" %* File not found

regfile [merge] -- Reg Error: Key error.

scrfile [config] -- "%1" File not found

scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l ()

scrfile [open] -- "%1" /S File not found

txtfile [edit] -- Reg Error: Key error.

Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1 File not found

Directory [cmd] -- cmd.exe /s /k pushd "%V" ()

Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)

Directory [OneNote.Open] -- C:\PROGRA~2\MICROS~1\Office12\ONENOTE.EXE "%L" (Microsoft Corporation)

Folder [open] -- %SystemRoot%\Explorer.exe /separate,/idlist,%I,%L (Microsoft Corporation)

Folder [explore] -- %SystemRoot%\Explorer.exe /separate,/e,/idlist,%I,%L (Microsoft Corporation)

Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]

batfile [open] -- "%1" %*

cmdfile [open] -- "%1" %*

comfile [open] -- "%1" %*

cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)

exefile [open] -- "%1" %*

helpfile [open] -- Reg Error: Key error.

htmlfile [edit] -- "C:\Program Files (x86)\Microsoft Office\Office12\msohtmed.exe" %1 (Microsoft Corporation)

htmlfile [print] -- "C:\Program Files (x86)\Microsoft Office\Office12\msohtmed.exe" /p %1 (Microsoft Corporation)

inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)

piffile [open] -- "%1" %*

regfile [merge] -- Reg Error: Key error.

scrfile [config] -- "%1"

scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)

scrfile [open] -- "%1" /S

txtfile [edit] -- Reg Error: Key error.

Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1

Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)

Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)

Directory [OneNote.Open] -- C:\PROGRA~2\MICROS~1\Office12\ONENOTE.EXE "%L" (Microsoft Corporation)

Folder [open] -- %SystemRoot%\Explorer.exe /separate,/idlist,%I,%L (Microsoft Corporation)

Folder [explore] -- %SystemRoot%\Explorer.exe /separate,/e,/idlist,%I,%L (Microsoft Corporation)

Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)

 

========== Security Center Settings ==========

 

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]

"cval" = 1

 

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

 

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]

"oobe_av" = 1

"AntiVirusOverride" = 0

"AntiSpywareOverride" = 0

"FirewallOverride" = 0

"VistaSp1" = 9F 9E 16 8C DC 5B C8 01 [binary data]

 

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]

"oobe_av" = 1

 

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]

"EnableFirewall" = 1

"DisableNotifications" = 0

 

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]

"EnableFirewall" = 1

"DisableNotifications" = 0

 

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]

"EnableFirewall" = 1

"DisableNotifications" = 0

 

========== Authorized Applications List ==========

 

 

========== Vista Active Open Ports Exception List ==========

 

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]

"{04CAA1D2-89C8-40A8-8435-DC70CEB7B59F}" = rport=3702 | protocol=17 | dir=out | svc=fdphost | app=c:\windows\system32\svchost.exe |

"{06D701B9-B572-46B4-BF07-00829B59C423}" = rport=3702 | protocol=17 | dir=out | svc=fdrespub | app=c:\windows\system32\svchost.exe |

"{185FEF66-E767-4E8B-BB7D-13423375DFB0}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=c:\windows\system32\svchost.exe |

"{1DBFB629-D99F-4E21-B957-7ADAF7E2711A}" = rport=137 | protocol=17 | dir=out | app=system |

"{1E8EC34D-ADA0-4014-9F7E-E2BBF79C9D55}" = lport=138 | protocol=17 | dir=in | app=system |

"{2172A892-1470-4B51-95B5-6C9A08FBBE21}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=c:\windows\system32\svchost.exe |

"{265F1DB8-5B8C-450F-992E-E6FC766CC67F}" = lport=137 | protocol=17 | dir=in | app=system |

"{3E768CFD-4043-4E86-889E-4FD1D625B4DE}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=c:\windows\system32\svchost.exe |

"{53EE01AB-7411-4F35-AD20-AB8422524611}" = rport=139 | protocol=6 | dir=out | app=system |

"{6E7651CD-CF8D-49B9-8271-CC08F4FE4B2E}" = lport=3702 | protocol=17 | dir=in | svc=fdrespub | app=c:\windows\system32\svchost.exe |

"{75FB23A0-9C41-4DB6-AEF6-7A4DE7EFEF43}" = lport=139 | protocol=6 | dir=in | app=system |

"{792B4700-D143-405C-8D89-B08B7E20294F}" = rport=138 | protocol=17 | dir=out | app=system |

"{796C4DAC-A480-44ED-8FB4-035EC0E92DD8}" = lport=3702 | protocol=17 | dir=in | svc=fdphost | app=c:\windows\system32\svchost.exe |

"{8FDCA368-4638-46A5-AFE6-B5AD89628860}" = lport=445 | protocol=6 | dir=in | app=system |

"{9B7206FD-396D-449D-896A-41F0BFB9D025}" = lport=2869 | protocol=6 | dir=in | app=system |

"{B6C6F256-3ABE-45F3-92A6-1B427F8BBC4A}" = rport=445 | protocol=6 | dir=out | app=system |

"{C167A117-2533-4168-9F44-F9CBBAB3957D}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe |

"{E8F083EC-37EA-4506-98D4-CDA43840F4DF}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=@firewallapi.dll,-28539 |

"{F19D9C0D-0539-4FBB-AF72-F635CB654BDD}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=c:\windows\system32\svchost.exe |

"{F4C26004-1FF5-4EC5-A0B1-65A315BE01B8}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=c:\windows\system32\svchost.exe |

"{FA12268D-25CB-488F-A699-1E4C0CA912CC}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=c:\windows\system32\svchost.exe |

 

========== Vista Active Application Exception List ==========

 

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]

"{0034C18C-603D-483D-B8AC-1FCEAE8FD4A7}" = protocol=17 | dir=in | app=c:\windows\syswow64\dldwcoms.exe |

"{0215F547-BC84-4C65-A695-46A65A9151CC}" = protocol=6 | dir=in | app=c:\program files (x86)\microsoft office\office12\onenote.exe |

"{051D9317-F2F1-4B41-9A44-567C367ED956}" = protocol=17 | dir=in | app=c:\program files (x86)\microsoft office\office12\onenote.exe |

"{081E5B35-4AE6-4E3F-BA19-D066CD8E3AE0}" = protocol=6 | dir=out | app=system |

"{10E4C948-9177-4719-B038-2B6760421247}" = protocol=17 | dir=in | app=c:\program files (x86)\dell v505\dldwfax.exe |

"{1137749F-1A60-41FA-8824-2F7AB3F9F799}" = protocol=6 | dir=in | app=c:\windows\system32\spool\drivers\x64\3\dldwpswx.exe |

"{2159542E-5E87-414C-A986-5151EFF19EB8}" = protocol=17 | dir=in | app=c:\windows\system32\dldwcoms.exe |

"{291A3694-4BFC-481F-9F11-501850482C41}" = protocol=17 | dir=in | app=c:\program files (x86)\dell v505\frun.exe |

"{2AF15D93-D834-46D0-BC40-A73883274E98}" = protocol=17 | dir=in | app=c:\program files (x86)\dell v505\dldwamon.exe |

"{2B28DC61-0478-471F-9EC9-95D7E7811F18}" = protocol=17 | dir=in | app=c:\program files (x86)\abbyy finereader 6.0 sprint\scan\scanman6.exe |

"{2EA075A0-3777-46D0-BD47-7127C71EB1D7}" = protocol=6 | dir=in | app=c:\windows\system32\dldwcoms.exe |

"{2F5997C0-85E0-4FF0-87C2-ABC1617F82E0}" = protocol=6 | dir=in | app=c:\program files (x86)\dell v505\dldwfax.exe |

"{303CE005-0B0E-4769-907E-B634B51F8A16}" = protocol=6 | dir=out | svc=upnphost | app=c:\windows\system32\svchost.exe |

"{350361EE-6341-4671-A582-963EB5CF9931}" = protocol=58 | dir=out | name=@firewallapi.dll,-28546 |

"{39FD4CC2-27B0-41CD-8B34-1232BA731561}" = protocol=6 | dir=in | app=c:\windows\syswow64\dldwcoms.exe |

"{3D7AAA1E-FAD0-4975-B826-D7DB289F3CAA}" = protocol=6 | dir=in | app=c:\windows\system32\spool\drivers\x64\3\dldwpswx.exe |

"{41823FD3-8EF6-4EBF-9FCF-482B66E76935}" = protocol=17 | dir=in | app=c:\program files (x86)\microsoft office\office12\onenote.exe |

"{4D736D0C-5FEA-480C-A9B8-9B08737B30A3}" = protocol=17 | dir=in | app=c:\windows\system32\dldwcoms.exe |

"{53265194-3A84-4962-926B-D8767F4031D0}" = protocol=1 | dir=in | name=@firewallapi.dll,-28543 |

"{5403EB46-A297-47DD-9D24-4F97707173AC}" = protocol=6 | dir=in | app=c:\program files\microsoft games\chess\chess.exe |

"{5EE0399A-BD79-4F6E-8750-9E86AA80D3A2}" = protocol=17 | dir=in | app=c:\program files (x86)\dell v505\dldwamon.exe |

"{6D640578-657B-496D-9CE6-A31F4FBDD1AF}" = dir=in | app=c:\program files (x86)\cyberlink\powerdvd dx\powerdvd.exe |

"{7B24D9D6-69B5-4162-B32E-EBF2116C7BF1}" = protocol=17 | dir=in | app=c:\program files (x86)\dell v505\dldwfax.exe |

"{8665F9C4-C95A-41A5-83E5-05F1E9A6FDA8}" = protocol=1 | dir=out | name=@firewallapi.dll,-28544 |

"{8ADB5114-B687-4430-BEEB-6BBE80656C7B}" = protocol=6 | dir=in | app=c:\program files (x86)\dell v505\dldwamon.exe |

"{8BF358DE-8FF0-41DF-8E98-DA2185A2D427}" = dir=in | app=c:\program files (x86)\cyberlink\powerdvd dx\pdvddxsrv.exe |

"{8FAAF2DA-E2E8-4E0B-9A21-ED034690E428}" = protocol=17 | dir=in | app=c:\windows\system32\spool\drivers\x64\3\dldwpswx.exe |

"{A2E5388F-92E3-492A-B59D-27341A92C85C}" = protocol=6 | dir=in | app=c:\program files (x86)\dell v505\frun.exe |

"{A5BD5366-DF70-4F11-9DAC-9B366A8450E0}" = protocol=6 | dir=in | app=c:\program files (x86)\abbyy finereader 6.0 sprint\scan\scanman6.exe |

"{A9D94416-86C5-4930-A9D3-8E4C2BCFF243}" = protocol=6 | dir=in | app=c:\windows\system32\dldwcoms.exe |

"{AC2645CE-AC4D-4F10-AD59-61A6DBC280DB}" = protocol=6 | dir=in | app=c:\windows\syswow64\dldwcoms.exe |

"{ADBC7124-5BD5-4764-AB9E-9FC8282CB6BD}" = protocol=17 | dir=in | app=c:\windows\system32\spool\drivers\x64\3\dldwpswx.exe |

"{C9387AA8-8DE9-427E-82DE-782FD2B3E07D}" = protocol=17 | dir=in | app=c:\program files\internet explorer\iexplore.exe |

"{CA527B28-3EE0-485B-B170-53D453F614EC}" = protocol=6 | dir=out | svc=upnphost | app=c:\windows\system32\svchost.exe |

"{CCC601D0-1579-4274-8013-894E29CBEBF6}" = protocol=17 | dir=in | app=c:\program files\microsoft games\chess\chess.exe |

"{CEBE0596-446B-4DB7-9749-D93046446BE2}" = protocol=6 | dir=in | app=c:\program files (x86)\dell v505\dldwfax.exe |

"{CEF3E64B-B8A7-433B-A804-95DEAC31B166}" = protocol=17 | dir=in | app=c:\program files (x86)\dell v505\frun.exe |

"{D33EC381-C81E-4B34-A7EA-BD30EB740627}" = protocol=58 | dir=in | name=@firewallapi.dll,-28545 |

"{D54A670B-F221-4ABA-B09B-B655498E416A}" = protocol=6 | dir=in | app=c:\program files (x86)\microsoft office\office12\onenote.exe |

"{D821E6CE-E1B1-4F02-B339-9C28879E3EF0}" = protocol=17 | dir=in | app=c:\windows\syswow64\dldwcoms.exe |

"{DE90E0D8-E900-4E0E-83D3-48A30A347524}" = protocol=6 | dir=in | app=c:\program files\internet explorer\iexplore.exe |

"{E191E3C4-0DFC-4E77-AF62-CEBBA8A156DC}" = protocol=6 | dir=in | app=c:\program files (x86)\dell v505\frun.exe |

"{F6CC75D7-72B2-4973-8DE9-9B53645A648A}" = protocol=6 | dir=in | app=c:\program files (x86)\dell v505\dldwamon.exe |

 

========== HKEY_LOCAL_MACHINE Uninstall List ==========

 

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]

"{071c9b48-7c32-4621-a0ac-3f809523288f}" = Microsoft Visual C++ 2005 Redistributable (x64)

"{8220EEFE-38CD-377E-8595-13398D740ACE}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17

"{90120000-002A-0000-1000-0000000FF1CE}" = Microsoft Office Office 64-bit Components 2007

"{90120000-002A-0409-1000-0000000FF1CE}" = Microsoft Office Shared 64-bit MUI (English) 2007

"{90120000-0116-0409-1000-0000000FF1CE}" = Microsoft Office Shared 64-bit Setup Metadata MUI (English) 2007

"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1

"{F870B987-18BC-45FC-9BE8-35C02DCDA10F}" = Broadcom Gigabit Integrated Controller

"Broadcom 802.11 Application" = Dell Wireless WLAN Card Utility

"Dell V505" = Dell V505

"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1

"NVIDIA Drivers" = NVIDIA Drivers

"PCSI" = Prevx

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]

"{08E81ABD-79F7-49C2-881F-FD6CB0975693}" = Roxio Creator Data

"{09760D42-E223-42AD-8C3E-55B47D0DDAC3}" = Roxio Creator DE

"{105CFC7C-6992-11D5-BD9D-000102C10FD8}" = Lizardtech DjVu Control

"{1DD81E7D-0D28-4CEB-87B2-C041A4FCB215}" = Rapport

"{1F54DAFA-9261-4A62-B59D-6C9F26B48FE4}" = Roxio Creator Tools

"{30465B6C-B53F-49A1-9EBA-A3F187AD502E}" = Roxio Update Manager

"{415B2719-AD3A-4944-B404-C472DB6085B3}" = Cisco EAP-FAST Module

"{42929F0F-CE14-47AF-9FC7-FF297A603021}" = Dell Resource CD

"{45A66726-69BC-466B-A7A4-12FCBA4883D7}" = HiJackThis

"{65D0C510-D7B6-4438-9FC8-E6B91115AB0D}" = Live! Cam Avatar Creator

"{6675CA7F-E51B-4F6A-99D4-F8F0124C6EAA}" = Roxio Express Labeler 3

"{669C7BD8-DAA2-49B6-966C-F1E2AAE6B17E}" = Cisco PEAP Module

"{6811CAA0-BF12-11D4-9EA1-0050BAE317E1}" = PowerDVD

"{6D8D64BE-F500-55B6-705D-DFD08AFE0624}" = Acrobat.com

"{73A4F29F-31AC-4EBD-AA1B-0CC5F18C8F83}" = Roxio Creator Audio

"{76CB3301-6463-4D01-8BE2-A3C99692EB31}" = OSD

"{83770D14-21B9-44B3-8689-F7B523F94560}" = Cisco LEAP Module

"{8F3C31C5-9C3A-4AA8-8EFA-71290A7AD533}" = TomTom HOME Visual Studio Merge Modules

"{90120000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2007

"{90120000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2007

"{90120000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2007

"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007

"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007

"{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007

"{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007

"{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007

"{90120000-00A1-0409-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2007

"{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007

"{91120000-002F-0000-0000-0000000FF1CE}" = Microsoft Office Home and Student 2007

"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17

"{A2BCA9F1-566C-4805-97D1-7FDC93386723}" = Adobe AIR

"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper

"{AC76BA86-7AD7-1033-7B44-A92000000001}" = Adobe Reader 9.2

"{ACF60000-22B9-4CE9-98D6-2CCF359BAC07}" = ABBYY FineReader 6.0 Sprint

"{B4092C6D-E886-4CB2-BA68-FE5A88D31DE6}_is1" = Spybot - Search & Destroy

"{B6A26DE5-F2B5-4D58-9570-4FC760E00FCD}" = Roxio Creator Copy

"{ED439A64-F018-4DD4-8BA5-328D85AB09AB}" = Roxio Creator DE

"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver

"{F7B0939E-58DF-11DF-B3A6-005056806466}" = Google Earth

"Adobe AIR" = Adobe AIR

"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX

"Advanced Audio FX Engine" = Advanced Audio FX Engine

"Belarc Advisor" = Belarc Advisor 8.1

"Dell Webcam Central" = Dell Webcam Central

"Eusing Free Registry Cleaner" = Eusing Free Registry Cleaner

"GoToAssist" = GoToAssist 8.0.0.514

"HOMESTUDENTR" = Microsoft Office Home and Student 2007

"IrfanView" = IrfanView (remove only)

"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware

"Rapport_msi" = Rapport

"Speccy" = Speccy

"TomTom HOME" = TomTom HOME 2.7.3.1894

 

========== Last 10 Event Log Errors ==========

 

[ Application Events ]

Error - 31/07/2010 12:16:47 | Computer Name = Helen-PC | Source = WinMgmt | ID = 10

Description =

 

Error - 31/07/2010 12:23:48 | Computer Name = Helen-PC | Source = Application Error | ID = 1000

Description = Faulting application svchost.exe_wudfsvc, version 6.0.6001.18000,

time stamp 0x47919291, faulting module ntdll.dll, version 6.0.6001.18000, time stamp

0x4791adec, exception code 0xc0000005, fault offset 0x000000000001f7fa, process

id 0x1b4, application start time 0x01cb30ccbf77e49d.

 

Error - 31/07/2010 12:24:01 | Computer Name = Helen-PC | Source = WinMgmt | ID = 10

Description =

 

Error - 31/07/2010 12:25:09 | Computer Name = Helen-PC | Source = ESENT | ID = 455

Description = Catalog Database (1356) Catalog Database: Error -1811 occurred while

opening logfile C:\Windows\system32\CatRoot2\edb00163.log.

 

Error - 31/07/2010 12:25:09 | Computer Name = Helen-PC | Source = Microsoft-Windows-CAPI2 | ID = 131329

Description =

 

Error - 31/07/2010 12:26:03 | Computer Name = Helen-PC | Source = Google Update | ID = 20

Description =

 

Error - 31/07/2010 12:35:34 | Computer Name = Helen-PC | Source = WinMgmt | ID = 10

Description =

 

Error - 31/07/2010 15:09:58 | Computer Name = Helen-PC | Source = WinMgmt | ID = 10

Description =

 

Error - 01/08/2010 02:08:12 | Computer Name = Helen-PC | Source = WinMgmt | ID = 10

Description =

 

Error - 01/08/2010 02:14:35 | Computer Name = Helen-PC | Source = Application Hang | ID = 1002

Description = The program OTL.exe version 3.2.9.1 stopped interacting with Windows

and was closed. To see if more information about the problem is available, check

the problem history in the Problem Reports and Solutions control panel. Process

ID: ae4 Start Time: 01cb31404ab76ad5 Termination Time: 0

 

[ System Events ]

Error - 31/07/2010 12:35:34 | Computer Name = Helen-PC | Source = Service Control Manager | ID = 7000

Description =

 

Error - 31/07/2010 12:36:37 | Computer Name = Helen-PC | Source = DCOM | ID = 10016

Description =

 

Error - 31/07/2010 15:09:51 | Computer Name = Helen-PC | Source = HTTP | ID = 15016

Description =

 

Error - 31/07/2010 15:09:58 | Computer Name = Helen-PC | Source = Service Control Manager | ID = 7009

Description =

 

Error - 31/07/2010 15:09:58 | Computer Name = Helen-PC | Source = Service Control Manager | ID = 7000

Description =

 

Error - 31/07/2010 15:11:05 | Computer Name = Helen-PC | Source = DCOM | ID = 10016

Description =

 

Error - 01/08/2010 02:08:02 | Computer Name = Helen-PC | Source = HTTP | ID = 15016

Description =

 

Error - 01/08/2010 02:08:13 | Computer Name = Helen-PC | Source = Service Control Manager | ID = 7009

Description =

 

Error - 01/08/2010 02:08:13 | Computer Name = Helen-PC | Source = Service Control Manager | ID = 7000

Description =

 

Error - 01/08/2010 02:09:16 | Computer Name = Helen-PC | Source = DCOM | ID = 10016

Description =

 

 

< End of report >

Posted

I'm back on my computer but the last three posts are not showing here? Woss-up?

Most peculier!

jim (mightlily puzzled)

  • ExTS Admin
Posted

Hi jim,

 

Step 1

Please disable Spybot S&D’s TeaTimer protection, because it is known to interfere with our fixes.

You can enable it again after you're clean.

Open Spybot and click on 'Mode' then click 'Advanced Mode'.

Click on 'Tools' in bottom left hand corner.

Click on the 'System Startup' icon.

Uncheck 'Teatimer' box and/or uncheck 'Resident'.

Then, check next to the computer clock to see if the icon for Spybot is still there.

If it is, right click it and choose 'exit Spybot-S&D Resident'.

 

Reboot the computer.

 

Step 2

There's no anti virus protection on this system!

This is somewhat suicidal in today's digital world.

You need to install an antivirus program as soon as you can and run a complete scan of the computer:

Install one of these, update the definitions and then run a full scan. Let it quarantine/delete anything it finds. Let me know if there is anything that it reports but can not remove.

 

Note*:

Upon installation MS Security Essentials will check that your OS is a legal copy.

 

Step 3

Double click on OTL.exe to run it.

Copy the lines in the codebox below. (make sure that :Otl is on the first line )

:Otl
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {472734EA-242A-422B-ADF8-83D1E48CC825} - No CLSID value found.
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get.../ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O18:64bit: - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - Reg Error: Key error. File not found
O20:64bit: - Winlogon\Notify\GoToAssist: DllName - Reg Error: Key error. - C:\Program Files (x86)\Citrix\GoToAssist\514\G2AWinLogon_x64.dll File not found
O33 - MountPoints2\{9e4670ed-127e-11df-9ed4-0024e80c7d96}\Shell\AutoRun\command - "" = G:\setup.exe -- File not found
O33 - MountPoints2\{a1420bea-2e91-11df-bb67-0024e80c7d96}\Shell\AutoRun\command - "" = G:\InstallTomTomHOME.exe -- File not found
O33 - MountPoints2\{e1d32dda-ac7b-1e55-b16e-806e6f6e6963}\Shell - "" = AutoRun
@Alternate Data Stream - 115 bytes -> C:\ProgramData\TEMP:A8ADE5D8
@Alternate Data Stream - 109 bytes -> C:\ProgramData\TEMP:DFC5A2B2

:commands
[emptytemp]
[purity]
[EMPTYFLASH]

  • Return to OTL,
  • right click in the Custom Scans/Fixes window (under the blue bar) and choose Paste.
     
    http://img.photobucket.com/albums/v708/starbuck50/new%20forum/scan-fix.png
     
  • Click the red Run Fix button.
     
    http://img.photobucket.com/albums/v708/starbuck50/runfixbutton.png
     
  • OTL will reboot your system once the fix has completed.
  • After the reboot, you may need to double click OTL to launch the program and retrieve the log.

 

Copy and paste the contents of the OTL log that comes up after the fix in your next reply.

 

if you lose the report, there will be a copy here:

C:\_OTL\MovedFiles

 

In your next reply, please submit:

Otl fix report

and let me know which Anti Virus you installed.

 

 

Thanks.

Member of:

UNITE

Posted

Ok done that. Switched off S&D teatimer and downloaded/installed Avast. That was what we had on before but removed it because it slowed the machine down so.

Ran otl and the log is below which surprised me as it came out on notepad.

All seems well? Sould I be worried?

cheers

jim

 

 

All processes killed

========== OTL ==========

Registry value HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{472734EA-242A-422B-ADF8-83D1E48CC825} deleted successfully.

Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{472734EA-242A-422B-ADF8-83D1E48CC825}\ not found.

Starting removal of ActiveX control {8FFBE65D-2C9C-4669-84BD-5829DC0B603C}

C:\Windows\Downloaded Program Files\erma.inf moved successfully.

Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{8FFBE65D-2C9C-4669-84BD-5829DC0B603C}\ deleted successfully.

Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8FFBE65D-2C9C-4669-84BD-5829DC0B603C}\ not found.

Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{8FFBE65D-2C9C-4669-84BD-5829DC0B603C}\ not found.

Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8FFBE65D-2C9C-4669-84BD-5829DC0B603C}\ not found.

Starting removal of ActiveX control {E2883E8F-472F-4FB0-9522-AC9BF37916A7}

Registry error reading value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{E2883E8F-472F-4FB0-9522-AC9BF37916A7}\DownloadInformation\\INF .

Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{E2883E8F-472F-4FB0-9522-AC9BF37916A7}\ deleted successfully.

Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E2883E8F-472F-4FB0-9522-AC9BF37916A7}\ not found.

Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{E2883E8F-472F-4FB0-9522-AC9BF37916A7}\ not found.

Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E2883E8F-472F-4FB0-9522-AC9BF37916A7}\ not found.

64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\ms-help\ deleted successfully.

64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{314111c7-a502-11d2-bbca-00c04f8ec294}\ not found.

File {314111c7-a502-11d2-bbca-00c04f8ec294} - Reg Error: Key error. File not found not found.

64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\GoToAssist\ deleted successfully.

Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{9e4670ed-127e-11df-9ed4-0024e80c7d96}\ deleted successfully.

Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{9e4670ed-127e-11df-9ed4-0024e80c7d96}\ not found.

File G:\setup.exe not found.

Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{a1420bea-2e91-11df-bb67-0024e80c7d96}\ deleted successfully.

Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{a1420bea-2e91-11df-bb67-0024e80c7d96}\ not found.

File G:\InstallTomTomHOME.exe not found.

Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{e1d32dda-ac7b-1e55-b16e-806e6f6e6963}\ deleted successfully.

Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{e1d32dda-ac7b-1e55-b16e-806e6f6e6963}\ not found.

ADS C:\ProgramData\TEMP:A8ADE5D8 deleted successfully.

ADS C:\ProgramData\TEMP:DFC5A2B2 deleted successfully.

========== COMMANDS ==========

[EMPTYTEMP]

User: All Users

User: Default

->Temp folder emptied: 0 bytes

->Temporary Internet Files folder emptied: 0 bytes

->Flash cache emptied: 0 bytes

User: Default User

->Temp folder emptied: 0 bytes

->Temporary Internet Files folder emptied: 0 bytes

->Flash cache emptied: 0 bytes

User: Helen

->Temp folder emptied: 14376513 bytes

->Temporary Internet Files folder emptied: 563703 bytes

->Flash cache emptied: 1304 bytes

User: Public

%systemdrive% .tmp files removed: 0 bytes

%systemroot% .tmp files removed: 0 bytes

%systemroot%\System32 .tmp files removed: 0 bytes

%systemroot%\System32 (64bit) .tmp files removed: 0 bytes

%systemroot%\System32\drivers .tmp files removed: 0 bytes

Windows Temp folder emptied: 14902828 bytes

%systemroot%\sysnative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 33170 bytes

RecycleBin emptied: 67739381 bytes

Total Files Cleaned = 93.00 mb

[EMPTYFLASH]

User: All Users

User: Default

->Flash cache emptied: 0 bytes

User: Default User

->Flash cache emptied: 0 bytes

User: Helen

->Flash cache emptied: 0 bytes

User: Public

Total Flash Files Cleaned = 0.00 mb

OTL by OldTimer - Version 3.2.9.1 log created on 08022010_192554

Files\Folders moved on Reboot...

File\Folder C:\Windows\temp\_avast5_\Webshlock.txt not found!

File move failed. C:\Windows\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\VODKZM9F\desktop.ini scheduled to be moved on reboot.

File move failed. C:\Windows\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\UB0C2RA5\desktop.ini scheduled to be moved on reboot.

File move failed. C:\Windows\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\KDVLT67A\desktop.ini scheduled to be moved on reboot.

File move failed. C:\Windows\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\9ML85YI4\desktop.ini scheduled to be moved on reboot.

File move failed. C:\Windows\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\desktop.ini scheduled to be moved on reboot.

File move failed. C:\Windows\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\desktop.ini scheduled to be moved on reboot.

Registry entries deleted on Reboot...

Posted

Oh dear, an error has ocurred.

 

'thunking spooler APIS from 32 to 64 process has stopped working'

 

This actually happened at the beginning of the previous problems. It happens as 'H' tried to print somehing out.

cheers

jim

  • ExTS Admin
Posted

Hi Jim,

 

downloaded/installed Avast. That was what we had on before but removed it because it slowed the machine down so.
Anti Virus seems to run differently for some people.

I tried installing Avast on my mothers system ... and it became so slow it was ridiculous. I removed it and replaced it with MSSE.

I've place Avast on our systems and it's run brilliantly.

So feel free to remove it and try one of the other programs i recommended.

 

'thunking spooler APIS from 32 to 64 process has stopped working'
This was a recognised error, but MS addressed the problem with SP1 ( which i see you have).

More here:

You experience problems when you try to print a document in a 32-bit program on a computer that is running a 64-bit version of Windows Vista

 

What sort of printer are you using and have you tried to update the drivers?

 

All seems well? Sould I be worried?
Everything looks pretty good.

But let's get an online scan done and double check everything for you:

 

Please read the note at the bottom:

 

I'd like you to do an ESET OnlineScan


     
    You may find it beneficial to close your resident AV program before running the scan.
     
  • Hold down Control and click on the following link to open ESET OnlineScan in a new window.
    ESET OnlineScan
     
  • Click the http://billy-oneal.com/Canned%20Speeches/speechimages/eset/esetOnline.png button.
     
  • For alternate browsers only: (Microsoft Internet Explorer users can skip these steps)
    • Click on http://billy-oneal.com/Canned%20Speeches/speechimages/eset/esetSmartInstall.png to download the ESET Smart Installer.
      Save it to your desktop.
    • Double click on the http://billy-oneal.com/Canned%20Speeches/speechimages/eset/esetSmartInstallDesktopIcon.png icon on your desktop.

    [*]Check http://billy-oneal.com/Canned%20Speeches/speechimages/eset/esetAcceptTerms.png

    [*]Click the http://billy-oneal.com/Canned%20Speeches/speechimages/eset/esetStart.png button.

    [*]Accept any security warnings from your browser.

    [*]Check http://billy-oneal.com/Canned%20Speeches/speechimages/eset/esetScanArchives.png

    [*]Click the Start button.

    [*]ESET will then download updates for itself, install itself, and begin scanning your computer. Please be patient as this can take some time.

    [*]When the scan completes, push http://billy-oneal.com/Canned%20Speeches/speechimages/eset/esetListThreats.png

    [*]Click http://billy-oneal.com/Canned%20Speeches/speechimages/eset/esetExport.png, and save the file to your desktop using a unique name, such as ESETScan.

    Include the contents of this report in your next reply.

    [*]Click the http://billy-oneal.com/Canned%20Speeches/speechimages/eset/esetBack.png button.

    [*]Click http://billy-oneal.com/Canned%20Speeches/speechimages/eset/esetFinish.png

A log file will be saved here: C:\Program Files\ESET\ESET Online Scanner\log.txt

 

Note:

As you are running a 64bit system:

The ESET Online Scanner is a 32-bit application, which means it must be run through in the 32-bit version of Internet Explorer, and as an Administrator. To do so, right-click on the Internet Explorer (32-bit) icon in the Start Menu and select "Run as administrator" from the context menu.

 

Thanks

Member of:

UNITE

Posted
Hi Jim,

This was a recognised error, but MS addressed the problem with SP1 ( which i see you have).

More here:

You experience problems when you try to print a document in a 32-bit program on a computer that is running a 64-bit version of Windows Vista

 

What sort of printer are you using and have you tried to update the drivers?

It is a complete Dell set up, the printer is a 505.

No it han't been updated.

 

But let's get an online scan done and double check everything for you:

 

I went to this site but it had only one button like you mentioned and that was the 'agree' the eula thingy. No scan or any others.

 

So even after obtaining a username and password it didn't work for me. Obviously not geeky enough here to understand <grin>

 

There is one 'update' still outstanding from the MS site and that appears to be a windows media update - not the SP2 that I was half expecting.

 

MS support directs me to the 947821 problem page but then wont install because it has a problem - 947821. Also error code 80073712 enters you into a similar spiral

 

Thanks very much for your patience in this matter. Peeps like me must make things very frustrating at your end.

cheers

jim

  • ExTS Admin
Posted

Hi Jim,

 

It is a complete Dell set up, the printer is a 505.
What is the make on the printer? ... probably HP (Hewlett & Packard)

Please confirm the make.

 

So even after obtaining a username and password it didn't work for me.
Ok, plan 'b'.

 

Step 1

  • Download the latest version of Java Runtime Environment (JRE) 6 Update 21 and save it to your desktop.
  • Scroll down to where it says "JDK 6 Update 21 (JDK or JRE).
  • Click the "Download JRE" button to the right.
  • select 'Windows x64' from the Platform down arrow.
  • Read the License Agreement and then check the box that says: "Accept License Agreement".
  • Click Continue.
  • The page will refresh.
  • Click on the link to download Windows Offline Installation and save the file to your desktop.
  • Close any programs you may have running - especially your web browser.
  • Then from your desktop double-click on jre-6u21-windows-i586-p.exe to install the newest version.

 

Step 2

Please do an online scan with Kaspersky WebScanner.

Notes

Java must be installed and enabled for the scan to work.

Disable your computer's antivirus program as leaving it active will cause conflicts

  • Close ALL programs and windows except for your browser
    Please go to Online Kaspersky Scan and perform an online antivirus scan.
  • Read through the Requirements and limitations statement and click on the Accept button.
  • You will be prompted to install an application from Kaspersky. Click the Run button. It will start downloading and installing the scanner and virus definitions.
  • When the downloads have finished, the scrolling window will show 'Database is updated. Ready to scan'. Click on the Settings button at the bottom left.
  • Make sure these boxes are checked/ticked. If they are not, please tick them and click on the Save button:
    • Spyware, Adware, Dialers, and other potentially dangerous programs
    • Archives
    • Mail databases

    [*] Click on My Computer under Scan on the left. OK any warnings from your protection programs.[*] Go for a long walk. Please be patient and let the scanner finish. It is better that you do NOT use the computer while the scan is running. Keep all other programs/windows closed.[*] Once the scan is complete (the 'status' will show complete), click on View Scan Report and any infected objects will be shown.[*] Click on Save Report As... and change the Files of type to Text file (.txt) [*] Name the file KAVScan-ddmmyy before clicking on the Save button. Save the report to a convenient place - for example the Desktop.[*] Please post this log in your next reply.

Note - enable your antivirus program before browsing away from the Kaspersky site.

 

Go to the Desktop and double-click on the Kaspersky report KAVScan-ddmmyy.txt, it will open in Notepad

Click Edit > Select all then Edit > Copy

Reply to this thread and paste (Ctrl+V) the report.

 

In your next reply, please submit:

Kaspersky scan report.

 

 

Thanks.

Member of:

UNITE

Posted

Ok, the printer has Dell V505 on it - no other names or logos. I assumed from that even if rebadged that Dell wasn't letting on who made it.

As I said it has the same driver it came with and has worked until this latest problem started.

 

I got as far as the Kapersky site where it gave me the message 'Kapersky Online Scanner 7.0 download and operator require Java framework version 1.6 or later'.

 

Not knowing what this was I had to reverse out of there and just give you the message. I thought the java thing was ok, it seemed to download and install allright.

cheers

jim

  • ExTS Admin
Posted

Hi Jim,

 

I got as far as the Kapersky site where it gave me the message 'Kapersky Online Scanner 7.0 download and operator require Java framework version 1.6 or later'.
That's why i had you download and install the latest version Java before using the Kaspersky scanner.

Just continue to run the scanner, it'll be fine.

 

In the meantime, i'll look into the drivers for the printer.

 

Thanks.

Member of:

UNITE

Posted

Doh - too late!

It has now got the 'Anti vir Solution pro' thingy!

Picked it up from an ozzy site where she was trying to trace ancient relly.

I transferred iExplore to it via a CD from this machine and used MBAM against it and supposedly killed it but when I booted it this morning the Anti vir solution pro returned.

 

Now it wont go on the net to download superantispyware - and I don't know how to transfer that by CD?

cheers

jim (in deeper doo doos than before)

Posted (edited)

My last message is not showing on this computer? I wonder why not?

Anyway scrub that last message as I have now managed to save suprantispyware to a CD and am running that on the infected Dell. It has found one bit of alienware already but will leave it go the full 9 yards - where ever did that saying come from?

cheers

jim

PS That last message is now showing - doh! Computers!

Edited by mij
Posted

Superantispyware found 202 adware thingies but nowt else.

And the antivir solution pro is still there.

Pernicious bit of s8$2ware innit!

cheers

jim

  • ExTS Admin
Posted

Hi Jim,

 

The problem with 64bit systems , is that a lot of the tools we use won't run on them.

They're designed for 32bit systems.

But we still have backup plans.

 

Ok, it sounds as if we'll have to use a bigger hammer on this: :D

 

Download Dr.Web CureIt!.

 

Click the free download option.

Tick 'I accept'... then click on download.

Click on 'Save File'.

 

Double-click on the downloaded file.

Choose a desired protection mode.

 

Choose Standard mode:

 

Note:

In the enhanced protection mode Dr.Web CureIt! is run on a protected desktop where no other application can be launched.

So if something tries to prevent it from running... use the 'enhanced' mode.

In order to continue working in the enhanced protection mode choose OK or click Cancel to switch to the standard mode.

 

Click the “Start” button in the anti-virus window. Select “Yes” in the confirmation dialogue, and wait while Dr.Web CureIt! scans system memory and autorun objects.

 

Wait while the utility scans your system. When the scanning is finished, view the scan report.

 

Note:

Dr.Web CureIt! does not require installation and is compatible with all known anti-virus software. You do not need to disable your anti-virus software to check your system with Dr.Web CureIt!

 

I've written a tutorial with full instructions Here if you need it.

You can download it to another pc and transfer it if need be... it's always a fresh copy.

 

Let me know what the report says.

 

Thanks

Member of:

UNITE

Posted
Hi Jim,

 

That's why i had you download and install the latest version Java before using the Kaspersky scanner.

Just continue to run the scanner, it'll be fine.

 

In the meantime, i'll look into the drivers for the printer.

 

Thanks.

 

The other computer would not allow me to go online or update the antispyware program not even with a repair. Also it wouldn't allow me to restore before todays date which means the virus would still be there.

So I've gone for a re-installtion (re-installification <Bushism>)

Thanks for the guidance folks, it has been a long couple of days - and you do this for a living?

Cheers

jim

PS I chose to answer this way because 'the token ran out' when I replied via the quicky method.

  • ExTS Admin
Posted

Hi Jim,

 

So I've gone for a re-installtion (re-installification )

Thanks for the guidance folks, it has been a long couple of days - and you do this for a living?

Ok, a reformat/reinstall will certainly fix the problem.

Thanks for letting us know.

We don't actually do this for a living, (as we don't get paid for it :) ) it's a spare time thing.

 

Any problems in the future... you know where we are.

 

Safe surfing. http://fc08.deviantart.net/fs71/f/2010/033/b/3/Computer_addict__by_Sinister_Starfeesh.gif

Member of:

UNITE

Posted (edited)

Hey

 

i removed the antivir solution pro of a mates pc. here is the tutorial from bleepingcomputers.com

 

 

Automated Removal Instructions for Antivir Solution Pro using Malwarebytes' Anti-Malware:

 

 

  1. Print out these instructions as we may need to close every window that is open later in the fix.
  2. It is possible that the infection you are trying to remove will not allow you to download files on the infected computer. If you run into this problem when following the steps in this guide you will need to download the files requested in this guide on another computer and then transfer them to the infected computer. You can transfer the files via a CD/DVD, external drive, or USB flash drive.
  3. Reboot your computer into Safe Mode with Networking using the instructions for your version of Windows found in the following tutorial:

    When following the steps in the above tutorial, select Safe Mode with Networking rather than just Safe Mode. When the computer reboots into Safe Mode with Networking make sure you login with the username you normally use. When you are at your Windows desktop, please continue with the rest of the steps.

  4. This infection changes your Windows settings to use a proxy server that will not allow you to browse any pages on the Internet with Internet Explorer or update security software. Regardless of the web browser you use, for these instructions we will first need need to fix this problem so that we can download the utilities we need to remove this infection.
     
    Please start Internet Explorer, and when the program is open, click on the Tools menu and then select Internet Options as shown in the image below.
     
     
     
    http://www.bleepstatic.com/swr-guides/tools/proxy/tools-internet-options.jpg
     
     


  5. You should now be in the Internet Options screen as shown in the image below.
     
     
     
    http://www.bleepstatic.com/swr-guides/tools/proxy/internet-options.jpg


     
     
     
    Now click on the Connections tab as designated by the blue arrow above.

  6. You will now be at the Connections tab as shown by the image below.
     
     
    http://www.bleepstatic.com/swr-guides/tools/proxy/connections.jpg


     
     
     
    Now click on the Lan Settings button as designated by the blue arrow above.

  7. You will now be at the Local Area Network (LAN) settings screen as shown by the image below.
     
     
     
    http://www.bleepstatic.com/swr-guides/tools/proxy/uncheck-proxy.jpg


     
     
     
    Under the Proxy Server section, please uncheck the checkbox labeled Use a proxy server for your LAN. Then press the OK button to close this screen. Then press the OK button to close the Internet Options screen. Now that you have disabled the proxy server you will be able to browse the web again with Internet Explorer.

  8. Now we must end the processes that belong to Antivir Solution Pro so that it does not interfere with the cleaning procedure. To do this, download the following file to your desktop.
     
    rkill.com Download Link
     
    If you are unable to connect to the site to download rkill, please go back and do steps 3-6 again and make sure the infection has not reenabled the proxy settings. You may have to do this quite a few times before you can get the rkill.com file downloaded. If you still cannot download the rkill.com program on the infected computer, you should download it to a clean computer and copy it to the infected one via a USB flash drive or CDROM.
  9. Once it is downloaded, double-click on the rkill.com in order to automatically attempt to stop any processes associated with Antivir Solution Pro and other Rogue programs. Please be patient while the program looks for various malware programs and ends them. When it has finished, the black window will automatically close and you can continue with the next step. If you get a message that rkill is an infection, do not be concerned. This message is just a fake warning given by Antivir Solution Pro when it terminates programs that may potentially remove it. If you run into these infections warnings that close Rkill, a trick is to leave the warning on the screen and then run Rkill again. By not closing the warning, this typically will allow you to bypass the malware trying to protect itself so that rkill can terminate Antivir Solution Pro . So, please try running Rkill until the malware is no longer running. You will then be able to proceed with the rest of the guide. If you continue having problems running rkill.com, you can download iExplore.exe or eXplorer.exe, which are renamed copies of rkill.com, and try them instead.
     
    Do not reboot your computer after running rkill as the malware programs will start again.
  10. Now you should download Malwarebytes' Anti-Malware, or MBAM, from the following location and save it to your desktop:
     
    Malwarebytes' Anti-Malware Download Link (Download page will open in a new window)
     
    If you are unable to connect to the site to download Malwarebytes', please go back and do steps 3-6 again and make sure the infection has not reenabled the proxy settings.
  11. Once downloaded, close all programs and Windows on your computer, including this one.
  12. Double-click on the icon on your desktop named mbam-setup.exe. This will start the installation of MBAM onto your computer.
  13. When the installation begins, keep following the prompts in order to continue with the installation process. Do not make any changes to default settings and when the program has finished installing, make sure you leave both the Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware checked. Then click on the Finish button. If MalwareBytes' prompts you to reboot, please do not do so.
  14. MBAM will now automatically start and you will see a message stating that you should update the program before performing a scan. As MBAM will automatically update itself after the install, you can press the OK button to close that box and you will now be at the main program as shown below.
     
     
    http://www.bleepstatic.com/swr-guides/mbam/mbam.jpg


  15. On the Scanner tab, make sure the the Perform full scan option is selected and then click on the Scan button to start scanning your computer for Antivir Solution Pro related files.
  16. MBAM will now start scanning your computer for malware. This process can take quite a while, so we suggest you go and do something else and periodically check on the status of the scan. When MBAM is scanning it will look like the image below.
     
     
    http://www.bleepstatic.com/swr-guides/mbam/scanning.jpg


  17. When the scan is finished a message box will appear as shown in the image below.
     
     
    http://www.bleepstatic.com/swr-guides/mbam/scan-finished.jpg
     


    You should click on the OK button to close the message box and continue with the Antivir Solution Pro removal process.

  18. You will now be back at the main Scanner screen. At this point you should click on the Show Results button.
  19. A screen displaying all the malware that the program found will be shown as seen in the image below. Please note that the infections found may be different than what is shown in the image.
     
     
    http://www.bleepstatic.com//swr-guides/a/antivir-solution-pro/mbam-antivir-solution-pro.jpg
     


     
    You should now click on the Remove Selected button to remove all the listed malware. MBAM will now delete all of the files and registry keys and add them to the programs quarantine. When removing the files, MBAM may require a reboot in order to remove some of them. If it displays a message stating that it needs to reboot, please allow it to do so. Once your computer has rebooted, and you are logged in, please continue with the rest of the steps.

  20. When MBAM has finished removing the malware, it will open the scan log and display it in Notepad. Review the log as desired, and then close the Notepad window.
  21. You can now exit the MBAM program.

Your computer should now be free of the Antivir Solution Pro program.

 

To get rid of it with hjackthis you need to run the log and fix these too processses

 

%UserProfile%\Local Settings\Application Data\<random>\

%UserProfile%\Local Settings\Application Data\<random>\<random>.exe

 

Hope it helps

 

 

 

Seedy21

Edited by seedy21

“It's only after we've lost everything that we're free to do anything.”

― Chuck Palahniuk, Fight Club

 

http://www.geekstogo.com/downloads/unite_blue.png

 

Need help with your computer problems? Then why not join Free PC Help. Register here

 

If Free PC Help has helped you then please consider a donation. Click here

 

We are all members helping other members.

Please return here where you may be able to help someone else.

After all, no one knows everything and you may have the answer that someone needs.

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.

Guest
Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.


×
×
  • Create New...