[RESOLVED] Programs missing
#1
Posted 17 April 2011 - 11:19 PM
GMER 1.0.15.15570 - http://www.gmer.net
Rootkit scan 2011-04-17 18:16:03
Windows 5.1.2600 Service Pack 3 Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-3 ST340014A rev.3.16
Running: lt94ctkh.exe; Driver: C:\DOCUME~1\MARGIE\LOCALS~1\Temp\uwxdqfog.sys
---- User code sections - GMER 1.0.15 ----
.text C:\Program Files\internet explorer\iexplore.exe[2912] USER32.dll!DialogBoxParamW 7E4247AB 5 Bytes JMP 3E1DF4D9 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\internet explorer\iexplore.exe[2912] USER32.dll!DialogBoxIndirectParamW 7E432072 5 Bytes JMP 3E3527F6 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\internet explorer\iexplore.exe[2912] USER32.dll!MessageBoxIndirectA 7E43A082 5 Bytes JMP 3E352777 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\internet explorer\iexplore.exe[2912] USER32.dll!DialogBoxParamA 7E43B144 5 Bytes JMP 3E3527BB C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\internet explorer\iexplore.exe[2912] USER32.dll!MessageBoxExW 7E450838 5 Bytes JMP 3E352703 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\internet explorer\iexplore.exe[2912] USER32.dll!MessageBoxExA 7E45085C 5 Bytes JMP 3E35273D C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\internet explorer\iexplore.exe[2912] USER32.dll!DialogBoxIndirectParamA 7E456D7D 5 Bytes JMP 3E352831 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\internet explorer\iexplore.exe[2912] USER32.dll!MessageBoxIndirectW 7E4664D5 5 Bytes JMP 3E20178A C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\internet explorer\iexplore.exe[2912] ole32.dll!OleLoadFromStream 7752981B 5 Bytes JMP 3E3529F3 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
---- Devices - GMER 1.0.15 ----
Device mrxsmb.sys (Windows NT SMB Minirdr/Microsoft Corporation)
Device Fastfat.SYS (Fast FAT File System Driver/Microsoft Corporation)
AttachedDevice fltmgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)
AttachedDevice fltmgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)
Device \FileSystem\Fs_Rec \FileSystem\UdfsCdRomRecognizer tfsnifs.sys (Drive Letter Access Component/Sonic Solutions)
Device \FileSystem\Fs_Rec \FileSystem\FatCdRomRecognizer tfsnifs.sys (Drive Letter Access Component/Sonic Solutions)
Device \FileSystem\Fs_Rec \FileSystem\CdfsRecognizer tfsnifs.sys (Drive Letter Access Component/Sonic Solutions)
Device \FileSystem\Fs_Rec \FileSystem\FatDiskRecognizer tfsnifs.sys (Drive Letter Access Component/Sonic Solutions)
Device \FileSystem\Fs_Rec \FileSystem\UdfsDiskRecognizer tfsnifs.sys (Drive Letter Access Component/Sonic Solutions)
Device Cdfs.SYS (CD-ROM File System Driver/Microsoft Corporation)
Device tfsnifs.sys (Drive Letter Access Component/Sonic Solutions)
---- Processes - GMER 1.0.15 ----
Library C:\Program (*** hidden *** ) @ C:\Program Files\LogMeIn\x86\LogMeIn.exe [2252] 0x758C0000
Library C:\Program (*** hidden *** ) @ C:\Program Files\LogMeIn\x86\LMIGuardianSvc.exe [3844] 0x758C0000
---- Disk sectors - GMER 1.0.15 ----
Disk \Device\Harddisk0\DR0 malicious Win32:MBRoot code @ sector 78108033
Disk \Device\Harddisk0\DR0 PE file @ sector 78108055
---- EOF - GMER 1.0.15 ----
I will return with the other logs.
#2 Re: [RESOLVED] Programs missing
Posted 17 April 2011 - 11:21 PM
DDS (Ver_11-03-05.01) - NTFSx86
Run by MARGIE at 18:20:22.01 on Sun 04/17/2011
Internet Explorer: 7.0.5730.11 BrowserJavaVersion: 1.6.0_18
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.1151.639 [GMT -5:00]
.
AV: Microsoft Security Essentials *Disabled/Updated* {EDB4FA23-53B8-4AFA-8C5D-99752CCA7095}
AV: Microsoft Security Essentials *Disabled/Updated* {BCF43643-A118-4432-AEDE-D861FCBCFCDF}
.
============== Running Processes ===============
.
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
c:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
C:\WINDOWS\system32\svchost.exe -k WudfServiceGroup
svchost.exe
svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\dla\tfswctrl.exe
svchost.exe
C:\Program Files\Belkin\Router Setup and Monitor\BelkinService.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\system32\lxcycoms.exe
C:\WINDOWS\System32\svchost.exe -k imgsvc
C:\Program Files\Belkin\Router Setup and Monitor\BelkinRouterMonitor.exe
C:\Program Files\Microsoft Security Client\msseces.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Documents and Settings\MARGIE\Application Data\Smilebox\SmileboxTray.exe
C:\Program Files\Belkin\Router Setup and Monitor\BelkinSetup.exe
C:\Program Files\Belkin\Router Setup and Monitor\dlnaPlugin.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\System32\svchost.exe -k HTTPFilter
C:\Program Files\internet explorer\iexplore.exe
C:\Program Files\LogMeIn\x86\LMIGuardianSvc.exe
C:\Program Files\LogMeIn\x86\LogMeIn.exe
C:\Program Files\LogMeIn\x86\RaMaint.exe
C:\Program Files\LogMeIn\x86\LogMeInSystray.exe
C:\Program Files\LogMeIn\x86\LogMeInToolkit.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\LogMeIn\x86\LogMeIn.exe
C:\Documents and Settings\MARGIE\Desktop\dds.scr
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://www.msn.com
uSearchMigratedDefaultURL = hxxp://search.live.com/results.aspx?q={searchTerms}&src={referrer:source?}
BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\adobe\acrobat 7.0\activex\AcroIEHelper.dll
BHO: {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - No File
BHO: DriveLetterAccess: {5ca3d70e-1895-11cf-8e15-001234567890} - c:\windows\system32\dla\tfswshx.dll
BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: Google Dictionary Compression sdch: {c84d72fe-e17d-4195-bb24-76c02e2e7c4e} - c:\program files\google\google toolbar\component\fastsearch_B7C5AC242193BB3E.dll
BHO: WOT Helper: {c920e44a-7f78-4e64-bdd7-a57026e7feb7} - c:\program files\wot\WOT.dll
BHO: Java Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
TB: WOT: {71576546-354d-41c9-aae8-31f2ec22bf0d} - c:\program files\wot\WOT.dll
TB: {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No File
EB: {32683183-48a0-441b-a342-7c2a440a9478} - No File
uRun: [SmileboxTray] "c:\documents and settings\margie\application data\smilebox\SmileboxTray.exe"
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
mRun: [dla] c:\windows\system32\dla\tfswctrl.exe
mRun: [LXCYCATS] rundll32 c:\windows\system32\spool\drivers\w32x86\3\LXCYtime.dll,_RunDLLEntry@16
mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime
mRun: [InstaLAN] "c:\program files\belkin\router setup and monitor\BelkinRouterMonitor.exe" startup
mRun: [MSC] "c:\program files\microsoft security client\msseces.exe" -hide -runkey
mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
mRun: [LogMeIn GUI] "c:\program files\logmein\x86\LogMeInSystray.exe"
mPolicies-explorer: NoActiveDesktop = 1 (0x1)
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
DPF: {00B71CFB-6864-4346-A978-C0A14556272C} - hxxp://messenger.zone.msn.com/binary/msgrchkr.cab31267.cab
DPF: {48DD0448-9209-4F81-9F6D-D83562940134} - hxxp://lads.myspace.com/upload/MySpaceUploader1006.cab
DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} - hxxp://gfx1.hotmail.com/mail/w2/resources/MSNPUpld.cab
DPF: {5F8469B4-B055-49DD-83F7-62B522420ECC} - hxxp://upload.facebook.com/controls/FacebookPhotoUploader.cab
DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} - hxxp://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1265480380265
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_18-windows-i586.cab
DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} - hxxp://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab
DPF: {BB21F850-63F4-4EC9-BF9D-565BD30C9AE9} - hxxp://ax.emsisoft.com/asquared.cab
DPF: {CAFEEFAC-0016-0000-0018-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_18-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_18-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
DPF: {E77F23EB-E7AB-4502-8F37-247DBAF1A147} - hxxp://gfx1.hotmail.com/mail/w4/pr01/photouploadcontrol/MSNPUpld.cab
Filter: text/html - {3ea10681-ae53-4b21-b806-c7228072057a} -
Handler: wot - {C2A44D6B-CB9F-4663-88A6-DF2F26E4D952} - c:\program files\wot\WOT.dll
Notify: avgrsstarter - avgrsstx.dll
Notify: LMIinit - LMIinit.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
SEH: SABShellExecuteHook Class: {5ae067d3-9afb-48e0-853a-ebb7f4a000da} - c:\program files\superantispyware\SASSEH.DLL
.
================= FIREFOX ===================
.
FF - ProfilePath - c:\docume~1\margie\applic~1\mozilla\firefox\profiles\d0jvnpba.default\
FF - prefs.js: browser.search.defaulturl - hxxp://www.google.com/search?lr=&ie=UTF-8&oe=UTF-8&q=
FF - prefs.js: browser.search.selectedEngine - Google
FF - component: c:\documents and settings\margie\application data\mozilla\firefox\profiles\d0jvnpba.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\components\frozen.dll
FF - component: c:\documents and settings\margie\application data\mozilla\firefox\profiles\d0jvnpba.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\components\googletoolbar-ff3.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npCouponPrinter.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npMozCouponPrinter.dll
.
============= SERVICES / DRIVERS ===============
.
R1 MpFilter;Microsoft Malware Protection Driver;c:\windows\system32\drivers\MpFilter.sys [2009-12-2 165264]
R1 MpKslef13f7ec;MpKslef13f7ec;c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{e4507579-aa8a-49f2-b051-0ece8584d1ee}\MpKslef13f7ec.sys [2011-4-17 28752]
R1 SASDIFSV;SASDIFSV;c:\program files\superantispyware\sasdifsv.sys [2010-2-17 12872]
R1 SASKUTIL;SASKUTIL;c:\program files\superantispyware\SASKUTIL.SYS [2010-2-17 66632]
R2 LMIGuardianSvc;LMIGuardianSvc;c:\program files\logmein\x86\LMIGuardianSvc.exe [2011-3-1 374152]
R2 LMIInfo;LogMeIn Kernel Information Provider;c:\program files\logmein\x86\rainfo.sys [2010-9-17 12856]
R2 LMIRfsDriver;LogMeIn Remote File System Driver;c:\windows\system32\drivers\LMIRfsDriver.sys [2011-4-17 47640]
R2 lxcy_device;lxcy_device;c:\windows\system32\lxcycoms.exe -service --> c:\windows\system32\lxcycoms.exe -service [?]
S1 MpKsl0b14781f;MpKsl0b14781f;\??\c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{abc87890-ab79-46a0-9784-8023255952a2}\mpksl0b14781f.sys --> c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{abc87890-ab79-46a0-9784-8023255952a2}\MpKsl0b14781f.sys [?]
S1 MpKsl4b4a8d69;MpKsl4b4a8d69;\??\c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{9a294822-06be-4f73-8f0f-d569ed75c1f2}\mpksl4b4a8d69.sys --> c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{9a294822-06be-4f73-8f0f-d569ed75c1f2}\MpKsl4b4a8d69.sys [?]
S1 MpKsl4e7124f7;MpKsl4e7124f7;\??\c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{a734d427-b116-468d-b98a-4cfc3086044b}\mpksl4e7124f7.sys --> c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{a734d427-b116-468d-b98a-4cfc3086044b}\MpKsl4e7124f7.sys [?]
S3 SASENUM;SASENUM;c:\program files\superantispyware\SASENUM.SYS [2010-2-17 12872]
.
=============== Created Last 30 ================
.
2011-04-17 20:58:38 -------- d-----w- c:\docume~1\margie\locals~1\applic~1\LogMeIn
2011-04-17 20:58:32 83360 ----a-w- c:\windows\system32\LMIRfsClientNP.dll
2011-04-17 20:58:32 53632 ----a-w- c:\windows\system32\spool\prtprocs\w32x86\LMIproc.dll
2011-04-17 20:58:32 47640 ----a-w- c:\windows\system32\drivers\LMIRfsDriver.sys
2011-04-17 20:58:32 29568 ----a-w- c:\windows\system32\LMIport.dll
2011-04-17 20:58:23 87424 ----a-w- c:\windows\system32\LMIinit.dll
2011-04-17 20:58:18 -------- d-----w- c:\docume~1\alluse~1\applic~1\LogMeIn
2011-04-17 20:58:02 -------- d-----w- c:\program files\LogMeIn
2011-04-17 20:52:15 28752 ----a-w- c:\docume~1\alluse~1\applic~1\microsoft\microsoft antimalware\definition updates\{e4507579-aa8a-49f2-b051-0ece8584d1ee}\MpKslef13f7ec.sys
2011-04-17 19:52:48 28752 ----a-w- c:\docume~1\alluse~1\applic~1\microsoft\microsoft antimalware\definition updates\{e4507579-aa8a-49f2-b051-0ece8584d1ee}\MpKslde9e38ce.sys
2011-04-17 19:40:10 28752 ----a-w- c:\docume~1\alluse~1\applic~1\microsoft\microsoft antimalware\definition updates\{e4507579-aa8a-49f2-b051-0ece8584d1ee}\MpKsl97dcede1.sys
2011-04-17 07:11:22 6792528 ----a-w- c:\docume~1\alluse~1\applic~1\microsoft\microsoft antimalware\definition updates\{e4507579-aa8a-49f2-b051-0ece8584d1ee}\mpengine.dll
2011-03-24 23:51:37 142296 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll
2011-03-24 23:51:33 781272 ----a-w- c:\program files\mozilla firefox\mozsqlite3.dll
2011-03-24 23:51:33 728024 ----a-w- c:\program files\mozilla firefox\libGLESv2.dll
2011-03-24 23:51:33 1975768 ----a-w- c:\program files\mozilla firefox\D3DCompiler_42.dll
2011-03-24 23:51:33 1893336 ----a-w- c:\program files\mozilla firefox\d3dx9_42.dll
2011-03-24 23:51:33 1874904 ----a-w- c:\program files\mozilla firefox\mozjs.dll
2011-03-24 23:51:33 15832 ----a-w- c:\program files\mozilla firefox\mozalloc.dll
2011-03-24 23:51:33 142296 ----a-w- c:\program files\mozilla firefox\libEGL.dll
.
==================== Find3M ====================
.
2011-03-07 05:33:50 692736 ----a-w- c:\windows\system32\inetcomm.dll
2011-03-04 06:45:07 434176 ----a-w- c:\windows\system32\vbscript.dll
2011-03-03 13:21:11 1857920 ----a-w- c:\windows\system32\win32k.sys
2011-02-17 19:00:29 832512 ----a-w- c:\windows\system32\wininet.dll
2011-02-17 19:00:28 78336 ----a-w- c:\windows\system32\ieencode.dll
2011-02-17 19:00:28 1830912 ----a-w- c:\windows\system32\inetcpl.cpl
2011-02-17 19:00:27 17408 ----a-w- c:\windows\system32\corpol.dll
2011-02-17 12:32:12 5120 ----a-w- c:\windows\system32\xpsp4res.dll
2011-02-17 11:44:16 389120 ----a-w- c:\windows\system32\html.iec
2011-02-15 12:56:39 290432 ----a-w- c:\windows\system32\atmfd.dll
2011-02-09 13:53:52 270848 ----a-w- c:\windows\system32\sbe.dll
2011-02-09 13:53:52 186880 ----a-w- c:\windows\system32\encdec.dll
2011-02-08 13:33:55 978944 ----a-w- c:\windows\system32\mfc42.dll
2011-02-08 13:33:55 974848 ----a-w- c:\windows\system32\mfc42u.dll
2011-02-02 07:58:35 2067456 ----a-w- c:\windows\system32\mstscax.dll
2011-01-27 11:57:06 677888 ----a-w- c:\windows\system32\mstsc.exe
2011-01-21 14:44:37 439296 ----a-w- c:\windows\system32\shimgvw.dll
.
============= FINISH: 18:20:48.62 ===============
.
UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT
.
DDS (Ver_11-03-05.01)
.
Microsoft Windows XP Home Edition
Boot Device: \Device\HarddiskVolume2
Install Date: 5/14/2006 8:27:25 AM
System Uptime: 4/17/2011 3:50:58 PM (3 hours ago)
.
Motherboard: Dell Computer Corp. | | 0F4491
Processor: Intel® Pentium® 4 CPU 2.80GHz | Microprocessor | 2793/533mhz
.
==== Disk Partitions =========================
.
A: is Removable
C: is FIXED (NTFS) - 37 GiB total, 17.151 GiB free.
D: is CDROM ()
E: is CDROM (CDFS)
F: is Removable
.
==== Disabled Device Manager Items =============
.
==== System Restore Points ===================
.
RP419: 2/17/2011 3:28:51 AM - Software Distribution Service 3.0
RP420: 2/18/2011 3:29:00 AM - Software Distribution Service 3.0
RP421: 2/19/2011 3:28:54 AM - Software Distribution Service 3.0
RP422: 2/20/2011 1:35:12 AM - Software Distribution Service 3.0
RP423: 2/21/2011 2:26:20 AM - System Checkpoint
RP424: 2/21/2011 3:29:00 AM - Software Distribution Service 3.0
RP425: 2/22/2011 3:28:53 AM - Software Distribution Service 3.0
RP426: 2/23/2011 3:28:57 AM - Software Distribution Service 3.0
RP427: 2/24/2011 3:29:12 AM - Software Distribution Service 3.0
RP428: 2/25/2011 3:29:07 AM - Software Distribution Service 3.0
RP429: 2/26/2011 3:29:00 AM - Software Distribution Service 3.0
RP430: 2/27/2011 1:35:26 AM - Software Distribution Service 3.0
RP431: 2/28/2011 2:26:17 AM - System Checkpoint
RP432: 2/28/2011 3:28:56 AM - Software Distribution Service 3.0
RP433: 3/1/2011 3:00:16 AM - Software Distribution Service 3.0
RP434: 3/2/2011 3:21:21 AM - System Checkpoint
RP435: 3/2/2011 3:23:54 AM - Software Distribution Service 3.0
RP436: 3/3/2011 3:23:44 AM - Software Distribution Service 3.0
RP437: 3/4/2011 3:23:51 AM - Software Distribution Service 3.0
RP438: 3/4/2011 8:55:31 PM - Restore Operation
RP439: 3/4/2011 9:20:35 PM - Software Distribution Service 3.0
RP440: 3/5/2011 9:14:22 PM - Software Distribution Service 3.0
RP441: 3/6/2011 2:02:42 AM - Software Distribution Service 3.0
RP442: 3/6/2011 9:14:02 PM - Software Distribution Service 3.0
RP443: 3/7/2011 8:11:24 PM - Restore Operation
RP444: 3/8/2011 7:06:37 PM - Software Distribution Service 3.0
RP445: 3/9/2011 3:00:17 AM - Software Distribution Service 3.0
RP446: 3/9/2011 1:43:37 PM - Software Distribution Service 3.0
RP447: 3/10/2011 1:37:35 PM - Software Distribution Service 3.0
RP448: 3/11/2011 1:37:09 PM - Software Distribution Service 3.0
RP449: 3/12/2011 1:37:29 PM - Software Distribution Service 3.0
RP450: 3/13/2011 2:42:33 PM - Software Distribution Service 3.0
RP451: 3/14/2011 1:37:31 PM - Software Distribution Service 3.0
RP452: 3/15/2011 2:46:23 PM - System Checkpoint
RP453: 3/15/2011 8:38:09 PM - Software Distribution Service 3.0
RP454: 3/16/2011 8:38:18 PM - Software Distribution Service 3.0
RP455: 3/17/2011 8:38:20 PM - Software Distribution Service 3.0
RP456: 3/18/2011 8:38:21 PM - Software Distribution Service 3.0
RP457: 3/19/2011 8:37:53 PM - Software Distribution Service 3.0
RP458: 3/20/2011 1:38:16 AM - Software Distribution Service 3.0
RP459: 3/20/2011 8:37:53 PM - Software Distribution Service 3.0
RP460: 3/21/2011 8:38:43 PM - Software Distribution Service 3.0
RP461: 3/23/2011 12:28:32 AM - System Checkpoint
RP462: 3/23/2011 8:38:19 PM - Software Distribution Service 3.0
RP463: 3/24/2011 3:00:17 AM - Software Distribution Service 3.0
RP464: 3/25/2011 1:26:17 PM - System Checkpoint
RP465: 3/25/2011 7:30:01 PM - Software Distribution Service 3.0
RP466: 3/26/2011 7:29:52 PM - Software Distribution Service 3.0
RP467: 3/27/2011 1:55:21 AM - Software Distribution Service 3.0
RP468: 3/28/2011 2:03:09 AM - System Checkpoint
RP469: 3/28/2011 10:05:53 AM - Software Distribution Service 3.0
RP470: 3/29/2011 11:03:06 AM - System Checkpoint
RP471: 3/30/2011 3:13:09 PM - Software Distribution Service 3.0
RP472: 3/31/2011 3:06:18 PM - Software Distribution Service 3.0
RP473: 4/1/2011 3:06:18 PM - Software Distribution Service 3.0
RP474: 4/2/2011 3:06:40 PM - Software Distribution Service 3.0
RP475: 4/3/2011 1:52:30 AM - Software Distribution Service 3.0
RP476: 4/3/2011 3:06:39 PM - Software Distribution Service 3.0
RP477: 4/4/2011 3:06:46 PM - Software Distribution Service 3.0
RP478: 4/5/2011 3:27:59 PM - System Checkpoint
RP479: 4/5/2011 10:19:55 PM - Software Distribution Service 3.0
RP480: 4/6/2011 10:19:49 PM - Software Distribution Service 3.0
RP481: 4/7/2011 10:19:51 PM - Software Distribution Service 3.0
RP482: 4/8/2011 10:19:22 PM - Software Distribution Service 3.0
RP483: 4/9/2011 11:17:01 PM - System Checkpoint
RP484: 4/10/2011 10:20:05 PM - Software Distribution Service 3.0
RP485: 4/12/2011 3:04:22 PM - Software Distribution Service 3.0
RP486: 4/13/2011 2:59:02 PM - Software Distribution Service 3.0
RP487: 4/14/2011 3:00:22 AM - Software Distribution Service 3.0
RP488: 4/15/2011 3:28:17 AM - System Checkpoint
RP489: 4/15/2011 3:30:27 AM - Software Distribution Service 3.0
RP490: 4/16/2011 3:30:34 AM - Software Distribution Service 3.0
RP491: 4/17/2011 2:11:19 AM - Software Distribution Service 3.0
RP492: 4/17/2011 2:53:26 PM - Restore Operation
RP493: 4/17/2011 2:57:53 PM - Restore Operation
RP494: 4/17/2011 3:12:26 PM - Restore Operation
RP495: 4/17/2011 3:57:57 PM - Installed LogMeIn
.
==== Installed Programs ======================
.
Adobe AIR
Adobe Download Manager
Adobe Flash Player 10 ActiveX
Adobe Flash Player 10 Plugin
Adobe Reader 7.1.0
Apple Application Support
Apple Mobile Device Support
Apple Software Update
Autodesk MapGuide® Viewer ActiveX Control Release 6.5
Belkin Setup and Router Monitor
Bonjour
CCleaner
Compatibility Pack for the 2007 Office system
Conexant D850 56K V.9x DFVc Modem
Counter-Strike: Source
Coupon Printer for Windows
Critical Update for Windows Media Player 11 (KB959772)
Dell ResourceCD
Google Video Player
HijackThis 2.0.2
Hotfix for Windows Internet Explorer 7 (KB947864)
Hotfix for Windows Media Format 11 SDK (KB929399)
Hotfix for Windows Media Player 11 (KB939683)
Hotfix for Windows XP (KB2158563)
Hotfix for Windows XP (KB2443685)
Hotfix for Windows XP (KB952287)
Hotfix for Windows XP (KB970653-v3)
Hotfix for Windows XP (KB976098-v2)
Hotfix for Windows XP (KB979306)
Hotfix for Windows XP (KB981793)
Intel® PRO Network Adapters and Drivers
iTunes
Java Auto Updater
Java 6 Update 18
Lexmark 3400 Series
LogMeIn
Malwarebytes' Anti-Malware
Microsoft Antimalware
Microsoft Application Error Reporting
Microsoft Compression Client Pack 1.0 for Windows XP
Microsoft Internationalized Domain Names Mitigation APIs
Microsoft Money 2004
Microsoft Money 2004 System Pack
Microsoft National Language Support Downlevel APIs
Microsoft Picture It! Photo Premium 9
Microsoft Security Client
Microsoft Security Essentials
Microsoft User-Mode Driver Framework Feature Pack 1.0
Microsoft Visual C++ 2005 Redistributable
Microsoft Word 2002
Microsoft Works
Microsoft Works 2004 Setup Launcher
Microsoft Works Suite Add-in for Microsoft Word
Move Networks Media Player for Internet Explorer
Mozilla Firefox 4.0 (x86 en-US)
MSN Music Assistant
MSXML 4.0 SP2 (KB927978)
MSXML 4.0 SP2 (KB936181)
MSXML 4.0 SP2 (KB954430)
MSXML 4.0 SP2 (KB973688)
Netflix Movie Viewer
OpenOffice.org Installer 1.0
PowerDVD 5.1
QuickTime
Rhapsody Player Engine
Security Update for Windows Internet Explorer 7 (KB2183461)
Security Update for Windows Internet Explorer 7 (KB2360131)
Security Update for Windows Internet Explorer 7 (KB2416400)
Security Update for Windows Internet Explorer 7 (KB2482017)
Security Update for Windows Internet Explorer 7 (KB2497640)
Security Update for Windows Internet Explorer 7 (KB928090)
Security Update for Windows Internet Explorer 7 (KB929969)
Security Update for Windows Internet Explorer 7 (KB931768)
Security Update for Windows Internet Explorer 7 (KB933566)
Security Update for Windows Internet Explorer 7 (KB937143)
Security Update for Windows Internet Explorer 7 (KB938127)
Security Update for Windows Internet Explorer 7 (KB939653)
Security Update for Windows Internet Explorer 7 (KB942615)
Security Update for Windows Internet Explorer 7 (KB944533)
Security Update for Windows Internet Explorer 7 (KB950759)
Security Update for Windows Internet Explorer 7 (KB953838)
Security Update for Windows Internet Explorer 7 (KB956390)
Security Update for Windows Internet Explorer 7 (KB958215)
Security Update for Windows Internet Explorer 7 (KB960714)
Security Update for Windows Internet Explorer 7 (KB961260)
Security Update for Windows Internet Explorer 7 (KB963027)
Security Update for Windows Internet Explorer 7 (KB969897)
Security Update for Windows Internet Explorer 7 (KB972260)
Security Update for Windows Internet Explorer 7 (KB976325)
Security Update for Windows Internet Explorer 7 (KB978207)
Security Update for Windows Internet Explorer 7 (KB982381)
Security Update for Windows Media Player (KB2378111)
Security Update for Windows Media Player (KB911564)
Security Update for Windows Media Player (KB952069)
Security Update for Windows Media Player (KB954155)
Security Update for Windows Media Player (KB968816)
Security Update for Windows Media Player (KB973540)
Security Update for Windows Media Player (KB975558)
Security Update for Windows Media Player (KB978695)
Security Update for Windows Media Player 10 (KB917734)
Security Update for Windows Media Player 10 (KB936782)
Security Update for Windows Media Player 11 (KB936782)
Security Update for Windows Media Player 11 (KB954154)
Security Update for Windows Media Player 6.4 (KB925398)
Security Update for Windows Media Player 9 (KB911565)
Security Update for Windows Media Player 9 (KB917734)
Security Update for Windows XP (KB2079403)
Security Update for Windows XP (KB2115168)
Security Update for Windows XP (KB2121546)
Security Update for Windows XP (KB2160329)
Security Update for Windows XP (KB2229593)
Security Update for Windows XP (KB2259922)
Security Update for Windows XP (KB2279986)
Security Update for Windows XP (KB2286198)
Security Update for Windows XP (KB2296011)
Security Update for Windows XP (KB2296199)
Security Update for Windows XP (KB2347290)
Security Update for Windows XP (KB2360937)
Security Update for Windows XP (KB2387149)
Security Update for Windows XP (KB2393802)
Security Update for Windows XP (KB2412687)
Security Update for Windows XP (KB2419632)
Security Update for Windows XP (KB2423089)
Security Update for Windows XP (KB2436673)
Security Update for Windows XP (KB2440591)
Security Update for Windows XP (KB2443105)
Security Update for Windows XP (KB2476687)
Security Update for Windows XP (KB2478960)
Security Update for Windows XP (KB2478971)
Security Update for Windows XP (KB2479628)
Security Update for Windows XP (KB2479943)
Security Update for Windows XP (KB2481109)
Security Update for Windows XP (KB2483185)
Security Update for Windows XP (KB2485376)
Security Update for Windows XP (KB2485663)
Security Update for Windows XP (KB2503658)
Security Update for Windows XP (KB2506212)
Security Update for Windows XP (KB2506223)
Security Update for Windows XP (KB2507618)
Security Update for Windows XP (KB2508272)
Security Update for Windows XP (KB2508429)
Security Update for Windows XP (KB2509553)
Security Update for Windows XP (KB2510581)
Security Update for Windows XP (KB2511455)
Security Update for Windows XP (KB2524375)
Security Update for Windows XP (KB913433)
Security Update for Windows XP (KB923561)
Security Update for Windows XP (KB923689)
Security Update for Windows XP (KB938464)
Security Update for Windows XP (KB941569)
Security Update for Windows XP (KB946648)
Security Update for Windows XP (KB950760)
Security Update for Windows XP (KB950762)
Security Update for Windows XP (KB950974)
Security Update for Windows XP (KB951066)
Security Update for Windows XP (KB951376-v2)
Security Update for Windows XP (KB951376)
Security Update for Windows XP (KB951698)
Security Update for Windows XP (KB951748)
Security Update for Windows XP (KB952004)
Security Update for Windows XP (KB952954)
Security Update for Windows XP (KB953839)
Security Update for Windows XP (KB954211)
Security Update for Windows XP (KB954459)
Security Update for Windows XP (KB954600)
Security Update for Windows XP (KB955069)
Security Update for Windows XP (KB956391)
Security Update for Windows XP (KB956572)
Security Update for Windows XP (KB956744)
Security Update for Windows XP (KB956802)
Security Update for Windows XP (KB956803)
Security Update for Windows XP (KB956841)
Security Update for Windows XP (KB956844)
Security Update for Windows XP (KB957095)
Security Update for Windows XP (KB957097)
Security Update for Windows XP (KB958644)
Security Update for Windows XP (KB958687)
Security Update for Windows XP (KB958690)
Security Update for Windows XP (KB958869)
Security Update for Windows XP (KB959426)
Security Update for Windows XP (KB960225)
Security Update for Windows XP (KB960715)
Security Update for Windows XP (KB960803)
Security Update for Windows XP (KB960859)
Security Update for Windows XP (KB961371)
Security Update for Windows XP (KB961373)
Security Update for Windows XP (KB961501)
Security Update for Windows XP (KB968537)
Security Update for Windows XP (KB969059)
Security Update for Windows XP (KB969898)
Security Update for Windows XP (KB969947)
Security Update for Windows XP (KB970238)
Security Update for Windows XP (KB970430)
Security Update for Windows XP (KB971468)
Security Update for Windows XP (KB971486)
Security Update for Windows XP (KB971557)
Security Update for Windows XP (KB971633)
Security Update for Windows XP (KB971657)
Security Update for Windows XP (KB971961)
Security Update for Windows XP (KB972270)
Security Update for Windows XP (KB973346)
Security Update for Windows XP (KB973354)
Security Update for Windows XP (KB973507)
Security Update for Windows XP (KB973525)
Security Update for Windows XP (KB973869)
Security Update for Windows XP (KB973904)
Security Update for Windows XP (KB974112)
Security Update for Windows XP (KB974318)
Security Update for Windows XP (KB974392)
Security Update for Windows XP (KB974571)
Security Update for Windows XP (KB975467)
Security Update for Windows XP (KB975560)
Security Update for Windows XP (KB975561)
Security Update for Windows XP (KB975562)
Security Update for Windows XP (KB975713)
Security Update for Windows XP (KB977165)
Security Update for Windows XP (KB977816)
Security Update for Windows XP (KB977914)
Security Update for Windows XP (KB978037)
Security Update for Windows XP (KB978251)
Security Update for Windows XP (KB978262)
Security Update for Windows XP (KB978338)
Security Update for Windows XP (KB978542)
Security Update for Windows XP (KB978601)
Security Update for Windows XP (KB978706)
Security Update for Windows XP (KB979309)
Security Update for Windows XP (KB979482)
Security Update for Windows XP (KB979559)
Security Update for Windows XP (KB979683)
Security Update for Windows XP (KB979687)
Security Update for Windows XP (KB980195)
Security Update for Windows XP (KB980218)
Security Update for Windows XP (KB980232)
Security Update for Windows XP (KB980436)
Security Update for Windows XP (KB981322)
Security Update for Windows XP (KB981349)
Security Update for Windows XP (KB981852)
Security Update for Windows XP (KB981957)
Security Update for Windows XP (KB981997)
Security Update for Windows XP (KB982132)
Security Update for Windows XP (KB982214)
Security Update for Windows XP (KB982665)
Security Update for Windows XP (KB982802)
Shockwave
Smilebox
Sonic DLA
Sonic RecordNow!
Sonic Update Manager
SoundMAX
Spybot - Search & Destroy 1.4
SpywareBlaster v3.5.1
Steam
SUPERAntiSpyware Free Edition
Update for Windows Internet Explorer 7 (KB980182)
Update for Windows XP (KB2141007)
Update for Windows XP (KB2345886)
Update for Windows XP (KB2467659)
Update for Windows XP (KB951072-v2)
Update for Windows XP (KB951978)
Update for Windows XP (KB955759)
Update for Windows XP (KB955839)
Update for Windows XP (KB967715)
Update for Windows XP (KB968389)
Update for Windows XP (KB971029)
Update for Windows XP (KB971737)
Update for Windows XP (KB973687)
Update for Windows XP (KB973815)
Video Mover
WebFldrs XP
Windows Driver Package - MSN (usbccgp) USB (04/19/2006 1.1.0.2)
Windows Genuine Advantage Notifications (KB905474)
Windows Genuine Advantage Validation Tool (KB892130)
Windows Internet Explorer 7
Windows Live Sign-in Assistant
Windows Media Format 11 runtime
Windows Media Player 11
Windows XP Service Pack 3
WOT for Internet Explorer
.
==== Event Viewer Messages From Past Week ========
.
4/17/2011 3:29:32 PM, error: sr [1] - The System Restore filter encountered the unexpected error '0xC0000001' while processing the file '' on the volume 'HarddiskVolume2'. It has stopped monitoring the volume.
4/17/2011 3:06:00 PM, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service wuauserv with arguments "" in order to run the server: {E60687F7-01A1-40AA-86AC-DB1CBF673334}
4/17/2011 3:04:37 PM, error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: Fips intelppm MpFilter OMCI SASDIFSV SASKUTIL
4/17/2011 3:03:40 PM, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service EventSystem with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF}
4/17/2011 2:06:45 PM, error: sr [1] - The System Restore filter encountered the unexpected error '0xC0000243' while processing the file '76432.sys' on the volume 'HarddiskVolume2'. It has stopped monitoring the volume.
4/14/2011 4:23:57 AM, error: SideBySide [59] - Resolve Partial Assembly failed for Microsoft.VC90.CRT. Reference error message: The referenced assembly is not installed on your system. .
4/14/2011 4:23:57 AM, error: SideBySide [59] - Generate Activation Context failed for C:\Program Files\Belkin\Router Setup and Monitor\imageformats\qsvg4.dll. Reference error message: The operation completed successfully. .
4/14/2011 4:23:57 AM, error: SideBySide [59] - Generate Activation Context failed for C:\Program Files\Belkin\Router Setup and Monitor\imageformats\qjpeg4.dll. Reference error message: The operation completed successfully. .
4/14/2011 4:23:57 AM, error: SideBySide [32] - Dependent Assembly Microsoft.VC90.CRT could not be found and Last Error was The referenced assembly is not installed on your system.
4/12/2011 2:51:22 PM, error: Dhcp [1002] - The IP address lease 192.168.2.2 for the Network Card with network address 00111100D949 has been denied by the DHCP server 192.168.2.1 (The DHCP Server sent a DHCPNACK message).
4/10/2011 2:17:39 AM, error: Microsoft Antimalware [2001] - Microsoft Antimalware has encountered an error trying to update signatures. New Signature Version: Previous Signature Version: 1.101.1106.0 Update Source: Microsoft Update Server Update Stage: Search Source Path: http://www.microsoft.com Signature Type: AntiVirus Update Type: Full User: NT AUTHORITY\SYSTEM Current Engine Version: Previous Engine Version: 1.1.6702.0 Error code: 0x8024402c Error description: An unexpected problem occurred while checking for updates. For information on installing or troubleshooting updates, see Help and Support.
.
==== End Of File ===========================
#3 Re: [RESOLVED] Programs missing
Posted 17 April 2011 - 11:22 PM
Please, observe following rules:
- Read all of my instructions very carefully. Your mistakes during cleaning process may have very serious consequences, like unbootable computer.
- If you're stuck, or you're not sure about certain step, always ask before doing anything else.
- Please refrain from running tools or applying updates other than those I suggest.
- Never run more than one scan at a time.
- Keep updating me regarding your computer behavior, good, or bad.
- The cleaning process, once started, has to be completed. Even if your computer appears to act better, it may still be infected. Once the computer is totally clean, I'll certainly let you know.
- If you leave the topic without explanation in the middle of a cleaning process, you may not be eligible to receive any more help in malware removal forum.
- I close my topics if you have not replied in 5 days. If you need more time, simply let me know. If I closed your topic and you need it to be reopened, simply PM me.
============================================================================
I'll need Malwarebytes log as well.
Regarding hidden items....
Download and run UnHide
You can do it at any time.
#4 Re: [RESOLVED] Programs missing
Posted 17 April 2011 - 11:23 PM
www.malwarebytes.org
Database version: 6386
Windows 5.1.2600 Service Pack 3 (Safe Mode)
Internet Explorer 7.0.5730.11
4/17/2011 3:28:18 PM
mbam-log-2011-04-17 (15-28-18).txt
Scan type: Quick scan
Objects scanned: 154027
Time elapsed: 2 minute(s), 8 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 1
Registry Data Items Infected: 3
Folders Infected: 0
Files Infected: 2
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
(No malicious items detected)
Registry Values Infected:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\CijYFJMKlQ (Trojan.Agent) -> Value: CijYFJMKlQ -> Quarantined and deleted successfully.
Registry Data Items Infected:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\ActiveDesktop\NoChangingWallPaper (PUM.Hijack.DisplayProperties) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\DisableTaskMgr (PUM.Hijack.TaskManager) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\DisableTaskMgr (PUM.Hijack.TaskManager) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
Folders Infected:
(No malicious items detected)
Files Infected:
c:\documents and settings\all users\application data\cijyfjmklq.exe (Trojan.Agent) -> Quarantined and deleted successfully.
c:\documents and settings\all users\application data\19783476.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
#5 Re: [RESOLVED] Programs missing
#6 Re: [RESOLVED] Programs missing
Posted 17 April 2011 - 11:24 PM
© 2010, AD
Command-line:
Windows Version: Windows XP Home Edition
Windows Information: Service Pack 3 (build 2600)
Logical Drives Mask: 0x0000003d
Kernel Drivers (total 148):
0x804D7000 \WINDOWS\system32\ntoskrnl.exe
0x806EF000 \WINDOWS\system32\hal.dll
0xBA5A8000 \WINDOWS\system32\KDCOM.DLL
0xBA4B8000 \WINDOWS\system32\BOOTVID.dll
0xBA059000 ACPI.sys
0xBA5AA000 \WINDOWS\System32\DRIVERS\WMILIB.SYS
0xBA048000 pci.sys
0xBA0A8000 isapnp.sys
0xBA670000 pciide.sys
0xBA328000 \WINDOWS\System32\DRIVERS\PCIIDEX.SYS
0xBA0B8000 MountMgr.sys
0xBA029000 ftdisk.sys
0xBA330000 PartMgr.sys
0xBA0C8000 VolSnap.sys
0xBA011000 atapi.sys
0xBA0D8000 disk.sys
0xBA0E8000 \WINDOWS\System32\DRIVERS\CLASSPNP.SYS
0xB9FF1000 fltmgr.sys
0xB9FDF000 sr.sys
0xB9FCA000 drvmcdb.sys
0xBA0F8000 PxHelp20.sys
0xB9FB3000 KSecDD.sys
0xB9FA0000 WudfPf.sys
0xB9F13000 Ntfs.sys
0xB9EE6000 NDIS.sys
0xB9ECC000 Mup.sys
0xBA108000 agp440.sys
0xB98E9000 \SystemRoot\System32\DRIVERS\intelppm.sys
0xB9839000 \SystemRoot\System32\DRIVERS\ati2mtaa.sys
0xB9825000 \SystemRoot\System32\DRIVERS\VIDEOPRT.SYS
0xBA448000 \SystemRoot\System32\DRIVERS\usbuhci.sys
0xB9801000 \SystemRoot\System32\DRIVERS\USBPORT.SYS
0xBA450000 \SystemRoot\System32\DRIVERS\usbehci.sys
0xB97CD000 \SystemRoot\System32\DRIVERS\HSFHWBS2.sys
0xB97AA000 \SystemRoot\System32\DRIVERS\ks.sys
0xB96AB000 \SystemRoot\System32\DRIVERS\HSF_DP.sys
0xB9604000 \SystemRoot\System32\DRIVERS\HSF_CNXT.sys
0xBA458000 \SystemRoot\System32\Drivers\Modem.SYS
0xB95E0000 \SystemRoot\System32\DRIVERS\e100b325.sys
0xBA460000 \SystemRoot\System32\DRIVERS\fdc.sys
0xB98D9000 \SystemRoot\System32\DRIVERS\i8042prt.sys
0xBA468000 \SystemRoot\System32\DRIVERS\kbdclass.sys
0xB98C9000 \SystemRoot\System32\DRIVERS\serial.sys
0xBA564000 \SystemRoot\System32\DRIVERS\serenum.sys
0xB95CC000 \SystemRoot\System32\DRIVERS\parport.sys
0xBA5C6000 \SystemRoot\system32\drivers\sscdbhk5.sys
0xB98B9000 \SystemRoot\System32\DRIVERS\cdrom.sys
0xB9899000 \SystemRoot\System32\DRIVERS\redbook.sys
0xBA470000 \SystemRoot\System32\Drivers\GEARAspiWDM.sys
0xB9889000 \SystemRoot\System32\DRIVERS\imapi.sys
0xB953E000 \SystemRoot\system32\drivers\smwdm.sys
0xB951A000 \SystemRoot\system32\drivers\portcls.sys
0xBA138000 \SystemRoot\system32\drivers\drmk.sys
0xBA5C8000 \SystemRoot\system32\drivers\aeaudio.sys
0xBA7A7000 \SystemRoot\System32\DRIVERS\audstub.sys
0xBA148000 \SystemRoot\System32\DRIVERS\rasl2tp.sys
0xBA570000 \SystemRoot\System32\DRIVERS\ndistapi.sys
0xB9503000 \SystemRoot\System32\DRIVERS\ndiswan.sys
0xBA158000 \SystemRoot\System32\DRIVERS\raspppoe.sys
0xBA168000 \SystemRoot\System32\DRIVERS\raspptp.sys
0xBA478000 \SystemRoot\System32\DRIVERS\TDI.SYS
0xB94F2000 \SystemRoot\System32\DRIVERS\psched.sys
0xBA178000 \SystemRoot\System32\DRIVERS\msgpc.sys
0xBA480000 \SystemRoot\System32\DRIVERS\ptilink.sys
0xBA488000 \SystemRoot\System32\DRIVERS\raspti.sys
0xBA188000 \SystemRoot\System32\DRIVERS\termdd.sys
0xBA490000 \SystemRoot\System32\DRIVERS\mouclass.sys
0xBA5CA000 \SystemRoot\System32\DRIVERS\swenum.sys
0xB9494000 \SystemRoot\System32\DRIVERS\update.sys
0xBA580000 \SystemRoot\System32\DRIVERS\mssmbios.sys
0xBA198000 \SystemRoot\System32\Drivers\NDProxy.SYS
0xBA1A8000 \SystemRoot\System32\DRIVERS\usbhub.sys
0xBA5CC000 \SystemRoot\System32\DRIVERS\USBD.SYS
0xB9B39000 \SystemRoot\system32\drivers\MODEMCSA.sys
0xBA4A8000 \SystemRoot\System32\DRIVERS\flpydisk.sys
0xB63B9000 \SystemRoot\system32\DRIVERS\MpFilter.sys
0xBA348000 \SystemRoot\system32\DRIVERS\usbccgp.sys
0xBA5EE000 \SystemRoot\System32\Drivers\Fs_Rec.SYS
0xBA7CD000 \SystemRoot\System32\Drivers\Null.SYS
0xBA5F0000 \SystemRoot\System32\Drivers\Beep.SYS
0xBA358000 \SystemRoot\system32\drivers\ssrtln.sys
0xBA360000 \SystemRoot\System32\drivers\vga.sys
0xBA5F2000 \SystemRoot\System32\Drivers\mnmdd.SYS
0xBA5F4000 \SystemRoot\System32\DRIVERS\RDPCDD.sys
0xBA368000 \SystemRoot\System32\Drivers\Msfs.SYS
0xBA370000 \SystemRoot\System32\Drivers\Npfs.SYS
0xBA534000 \SystemRoot\System32\DRIVERS\rasacd.sys
0xB635E000 \SystemRoot\System32\DRIVERS\ipsec.sys
0xB6305000 \SystemRoot\System32\DRIVERS\tcpip.sys
0xB62DD000 \SystemRoot\System32\DRIVERS\netbt.sys
0xB62BB000 \SystemRoot\System32\drivers\afd.sys
0xBA218000 \SystemRoot\System32\DRIVERS\netbios.sys
0xB629A000 \??\C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS
0xBA378000 \??\C:\Program Files\SUPERAntiSpyware\SASDIFSV.SYS
0xB626F000 \SystemRoot\System32\DRIVERS\rdbss.sys
0xBA540000 \SystemRoot\SYSTEM32\DRIVERS\OMCI.SYS
0xB61FF000 \SystemRoot\System32\DRIVERS\mrxsmb.sys
0xBA248000 \SystemRoot\System32\Drivers\Fips.SYS
0xB61D9000 \SystemRoot\System32\DRIVERS\ipnat.sys
0xBA258000 \SystemRoot\System32\DRIVERS\wanarp.sys
0xBA550000 \SystemRoot\system32\DRIVERS\hidusb.sys
0xBA268000 \SystemRoot\system32\DRIVERS\HIDCLASS.SYS
0xBA380000 \SystemRoot\system32\DRIVERS\HIDPARSE.SYS
0xBA554000 \SystemRoot\system32\DRIVERS\usbscan.sys
0xBA388000 \SystemRoot\system32\DRIVERS\usbprint.sys
0xBA390000 \SystemRoot\system32\DRIVERS\USBSTOR.SYS
0xBA558000 \SystemRoot\System32\DRIVERS\mouhid.sys
0xBA288000 \SystemRoot\System32\Drivers\Cdfs.SYS
0xB6199000 \SystemRoot\System32\Drivers\dump_atapi.sys
0xBA5F6000 \SystemRoot\System32\Drivers\dump_WMILIB.SYS
0xBF800000 \SystemRoot\System32\win32k.sys
0xB947C000 \SystemRoot\System32\drivers\Dxapi.sys
0xBA398000 \SystemRoot\System32\watchdog.sys
0xBF000000 \SystemRoot\System32\drivers\dxg.sys
0xBA6E4000 \SystemRoot\System32\drivers\dxgthk.sys
0xBF012000 \SystemRoot\System32\ati2dvaa.dll
0xBA1D8000 \SystemRoot\system32\drivers\drvnddm.sys
0xBA701000 \SystemRoot\system32\dla\tfsndres.sys
0xB606C000 \SystemRoot\system32\dla\tfsnifs.sys
0xB60F5000 \SystemRoot\system32\dla\tfsnopio.sys
0xBA5FE000 \SystemRoot\system32\dla\tfsnpool.sys
0xBA3A8000 \SystemRoot\system32\dla\tfsnboio.sys
0xBA1E8000 \SystemRoot\system32\dla\tfsncofs.sys
0xBA702000 \SystemRoot\system32\dla\tfsndrct.sys
0xB5F8B000 \SystemRoot\system32\dla\tfsnudf.sys
0xB5F72000 \SystemRoot\system32\dla\tfsnudfa.sys
0xB5F3E000 \SystemRoot\System32\DRIVERS\ndisuio.sys
0xB5CDD000 \SystemRoot\system32\drivers\wdmaud.sys
0xB6004000 \SystemRoot\system32\drivers\sysaudio.sys
0xB5ACA000 \SystemRoot\System32\DRIVERS\mrxdav.sys
0xBA654000 \SystemRoot\System32\Drivers\ParVdm.SYS
0xB5982000 \SystemRoot\System32\DRIVERS\srv.sys
0xB5B17000 \SystemRoot\System32\DRIVERS\mdmxsdk.sys
0xBA430000 \SystemRoot\System32\Drivers\TDTCP.SYS
0xB545F000 \SystemRoot\System32\Drivers\RDPWD.SYS
0xB5306000 \SystemRoot\System32\Drivers\HTTP.sys
0xBA438000 \??\c:\Documents and Settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{E4507579-AA8A-49F2-B051-0ECE8584D1EE}\MpKslef13f7ec.sys
0xB512A000 \SystemRoot\System32\Drivers\Fastfat.SYS
0xBA66A000 \??\C:\Program Files\LogMeIn\x86\RaInfo.sys
0xBA7D5000 \SystemRoot\system32\DRIVERS\lmimirr.sys
0xB5C6F000 \??\C:\WINDOWS\system32\drivers\LMIRfsDriver.sys
0xB4CAE000 \??\C:\DOCUME~1\MARGIE\LOCALS~1\Temp\uwxdqfog.sys
0xBF06F000 \SystemRoot\System32\lmimirr.dll
0xBF074000 \SystemRoot\System32\lmimirr2.dll
0xB4C83000 \SystemRoot\system32\drivers\kmixer.sys
0xBA622000 \SystemRoot\system32\drivers\splitter.sys
0xBA3C0000 \??\C:\DOCUME~1\MARGIE\LOCALS~1\Temp\mbr.sys
0x7C900000 \WINDOWS\system32\ntdll.dll
Processes (total 44):
0 System Idle Process
4 System
544 C:\WINDOWS\system32\smss.exe
608 csrss.exe
632 C:\WINDOWS\system32\winlogon.exe
676 C:\WINDOWS\system32\services.exe
688 C:\WINDOWS\system32\lsass.exe
872 C:\WINDOWS\system32\svchost.exe
952 svchost.exe
1044 C:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe
1084 C:\WINDOWS\system32\svchost.exe
1116 C:\WINDOWS\system32\svchost.exe
1308 svchost.exe
1400 svchost.exe
1532 C:\WINDOWS\system32\spoolsv.exe
1808 C:\WINDOWS\explorer.exe
1864 C:\WINDOWS\system32\dla\tfswctrl.exe
1896 svchost.exe
1928 C:\Program Files\Belkin\Router Setup and Monitor\BelkinService.exe
1940 C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
1964 C:\Program Files\Bonjour\mDNSResponder.exe
2028 C:\Program Files\Java\jre6\bin\jqs.exe
200 C:\WINDOWS\system32\lxcycoms.exe
380 C:\WINDOWS\system32\svchost.exe
468 C:\Program Files\Belkin\Router Setup and Monitor\BelkinRouterMonitor.exe
496 C:\Program Files\Microsoft Security Client\msseces.exe
512 C:\Program Files\iTunes\iTunesHelper.exe
1004 C:\Documents and Settings\MARGIE\Application Data\Smilebox\SmileboxTray.exe
1192 C:\Program Files\Belkin\Router Setup and Monitor\BelkinSetup.exe
1288 C:\Program Files\Belkin\Router Setup and Monitor\dlnaPlugin.exe
1296 C:\WINDOWS\system32\ctfmon.exe
2336 C:\Program Files\iPod\bin\iPodService.exe
2420 alg.exe
2920 C:\WINDOWS\system32\svchost.exe
2912 C:\Program Files\Internet Explorer\iexplore.exe
3844 C:\Program Files\LogMeIn\x86\LMIGuardianSvc.exe
2252 C:\Program Files\LogMeIn\x86\LogMeIn.exe
3480 C:\Program Files\LogMeIn\x86\ramaint.exe
3612 C:\Program Files\LogMeIn\x86\LogMeInSystray.exe
1748 C:\Program Files\LogMeIn\x86\LogMeInToolkit.exe
3240 C:\WINDOWS\system32\wscntfy.exe
2936 C:\Program Files\LogMeIn\x86\LogMeIn.exe
2312 C:\WINDOWS\system32\notepad.exe
3616 C:\Documents and Settings\MARGIE\Desktop\MBRCheck.exe
\\.\C: --> \\.\PhysicalDrive0 at offset 0x00000000`02738a00 (NTFS)
PhysicalDrive0 Model Number: ST340014A, Rev: 3.16
Size Device Name MBR Status
--------------------------------------------
37 GB \\.\PhysicalDrive0 Windows XP MBR code detected
SHA1: DA38B874B7713D1B51CBC449F4EF809B0DEC644A
Done!
#7 Re: [RESOLVED] Programs missing
#8 Re: [RESOLVED] Programs missing
Posted 17 April 2011 - 11:54 PM
#9 Re: [RESOLVED] Programs missing
Posted 18 April 2011 - 12:01 AM
When done....
Please download ComboFix from Here or Here to your Desktop.
**Note: In the event you already have Combofix, this is a new version that I need you to download. It is important that it is saved directly to your desktop**
- Please, never rename Combofix unless instructed.
- Close any open browsers.
- Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.
- Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before performing a scan. They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
- Click on this link to see a list of programs that should be disabled. The list is not all inclusive. If yours is not listed and you don't know how to disable it, please ask.
NOTE 2. If Combofix asks you to update the program, always do so.
- Close any open browsers.
- WARNING: Combofix will disconnect your machine from the Internet as soon as it starts
- Please do not attempt to re-connect your machine back to the Internet until Combofix has completely finished.
- If there is no internet connection after running Combofix, then restart your computer to restore back your connection.
- Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before performing a scan. They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
- Double click on combofix.exe & follow the prompts.
- When finished, it will produce a report for you.
- Please post the "C:\ComboFix.txt"
**Note 2 for AVG users: ComboFix will not run until AVG is uninstalled as a protective measure against the anti-virus. This is because AVG "falsely" detects ComboFix (or its embedded files) as a threat and may remove them resulting in the tool not working correctly which in turn can cause "unpredictable results". Since AVG cannot be effectively disabled before running ComboFix, the author recommends you to uninstall AVG first.
Use AppRemover to uninstall it: http://www.appremover.com/
We can reinstall it when we're done with CF.
**Note 3: If you receive an error "Illegal operation attempted on a registery key that has been marked for deletion", restart computer to fix the issue.
Make sure, you re-enable your security programs, when you're done with Combofix.
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
NOTE.
If, for some reason, Combofix refuses to run, try one of the following:
1. Run Combofix from Safe Mode.
2. Delete Combofix file, download fresh one, but rename combofix.exe to your_name.exe BEFORE saving it to your desktop.
Do NOT run it yet.
Please download and run the below tool named Rkill (courtesy of BleepingComputer.com) which may help allow other programs to run.
There are 4 different versions. If one of them won't run then download and try to run the other one.
Vista and Win7 users need to right click Rkill and choose Run as Administrator
You only need to get one of these to run, not all of them. You may get warnings from your antivirus about this tool, ignore them or shutdown your antivirus.
Rkill.com
Rkill.scr
Rkill.exe
- Double-click on the Rkill desktop icon to run the tool.
- If using Vista or Windows 7 right-click on it and choose Run As Administrator.
- A black DOS box will briefly flash and then disappear. This is normal and indicates the tool ran successfully.
- If not, delete the file, then download and use the one provided in Link 2.
- If it does not work, repeat the process and attempt to use one of the remaining links until the tool runs.
- Do not reboot until instructed.
- If the tool does not run from any of the links provided, please let me know.
Once you've gotten one of them to run, immediately run your_name.exe by double clicking on it.
If normal mode still doesn't work, run BOTH tools from safe mode.
In case #2, please post BOTH logs, rKill and Combofix.
DO NOT make any other changes to your computer (like installing programs, using other cleaning tools, etc.), until it's officially declared clean!!!
#10 Re: [RESOLVED] Programs missing
Posted 18 April 2011 - 12:21 AM
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.1151.616 [GMT -5:00]
Running from: c:\documents and settings\MARGIE\Desktop\ComboFix.exe
AV: Microsoft Security Essentials *Disabled/Updated* {BCF43643-A118-4432-AEDE-D861FCBCFCDF}
AV: Microsoft Security Essentials *Disabled/Updated* {EDB4FA23-53B8-4AFA-8C5D-99752CCA7095}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\docume~1\MARGIE\LOCALS~1\Temp\1.tmp\F_IN_BOX.dll
c:\documents and settings\MARGIE\Local Settings\temp\1.tmp\F_IN_BOX.dll
c:\program files\Shared
c:\windows\system32\drivers\etc\lmhosts
c:\windows\system32\Drivers\psqhdixb.sys
.
.
((((((((((((((((((((((((( Files Created from 2011-03-18 to 2011-04-18 )))))))))))))))))))))))))))))))
.
.
2011-04-17 21:00 . 2011-04-17 23:06 -------- d-----w- c:\documents and settings\LogMeInRemoteUser
2011-04-17 20:58 . 2011-04-17 20:58 -------- d-----w- c:\documents and settings\MARGIE\Local Settings\Application Data\LogMeIn
2011-04-17 20:58 . 2011-03-01 17:12 83360 ----a-w- c:\windows\system32\LMIRfsClientNP.dll
2011-04-17 20:58 . 2011-03-01 17:12 53632 ----a-w- c:\windows\system32\Spool\prtprocs\w32x86\LMIproc.dll
2011-04-17 20:58 . 2011-03-01 17:12 29568 ----a-w- c:\windows\system32\LMIport.dll
2011-04-17 20:58 . 2010-09-17 20:40 47640 ----a-w- c:\windows\system32\drivers\LMIRfsDriver.sys
2011-04-17 20:58 . 2011-03-01 17:12 87424 ----a-w- c:\windows\system32\LMIinit.dll
2011-04-17 20:58 . 2011-04-17 20:58 -------- d-----w- c:\documents and settings\All Users\Application Data\LogMeIn
2011-04-17 20:58 . 2011-04-17 21:00 -------- d-----w- c:\program files\LogMeIn
2011-04-17 19:52 . 2011-04-17 19:52 28752 ----a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{E4507579-AA8A-49F2-B051-0ECE8584D1EE}\MpKslde9e38ce.sys
2011-04-17 19:40 . 2011-04-17 19:40 28752 ----a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{E4507579-AA8A-49F2-B051-0ECE8584D1EE}\MpKsl97dcede1.sys
2011-04-17 07:11 . 2011-03-15 04:05 6792528 ----a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{E4507579-AA8A-49F2-B051-0ECE8584D1EE}\mpengine.dll
2011-03-24 23:51 . 2011-03-18 17:53 142296 ----a-w- c:\program files\Mozilla Firefox\components\browsercomps.dll
2011-03-24 23:51 . 2011-03-18 17:53 781272 ----a-w- c:\program files\Mozilla Firefox\mozsqlite3.dll
2011-03-24 23:51 . 2011-03-18 17:53 1874904 ----a-w- c:\program files\Mozilla Firefox\mozjs.dll
2011-03-24 23:51 . 2011-03-18 17:53 15832 ----a-w- c:\program files\Mozilla Firefox\mozalloc.dll
2011-03-24 23:51 . 2011-03-18 17:53 728024 ----a-w- c:\program files\Mozilla Firefox\libGLESv2.dll
2011-03-24 23:51 . 2011-03-18 17:53 142296 ----a-w- c:\program files\Mozilla Firefox\libEGL.dll
2011-03-24 23:51 . 2011-03-18 17:53 1893336 ----a-w- c:\program files\Mozilla Firefox\d3dx9_42.dll
2011-03-24 23:51 . 2011-03-18 17:53 1975768 ----a-w- c:\program files\Mozilla Firefox\D3DCompiler_42.dll
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-03-15 04:05 . 2010-03-23 02:22 6792528 ----a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
2011-03-07 05:33 . 2006-05-14 13:20 692736 ----a-w- c:\windows\system32\inetcomm.dll
2011-03-04 06:45 . 2003-07-16 20:49 434176 ----a-w- c:\windows\system32\vbscript.dll
2011-03-03 13:21 . 2003-07-16 20:51 1857920 ----a-w- c:\windows\system32\win32k.sys
2011-02-17 19:00 . 2003-07-16 20:51 832512 ----a-w- c:\windows\system32\wininet.dll
2011-02-17 19:00 . 2006-05-14 13:51 78336 ----a-w- c:\windows\system32\ieencode.dll
2011-02-17 19:00 . 2003-07-16 20:30 1830912 ----a-w- c:\windows\system32\inetcpl.cpl
2011-02-17 19:00 . 2003-07-16 20:25 17408 ----a-w- c:\windows\system32\corpol.dll
2011-02-17 13:18 . 2003-07-16 20:34 455936 ----a-w- c:\windows\system32\drivers\mrxsmb.sys
2011-02-17 13:18 . 2003-07-16 20:46 357888 ----a-w- c:\windows\system32\drivers\srv.sys
2011-02-17 12:32 . 2009-04-17 01:24 5120 ----a-w- c:\windows\system32\xpsp4res.dll
2011-02-17 11:44 . 2006-05-14 13:51 389120 ----a-w- c:\windows\system32\html.iec
2011-02-15 12:56 . 2003-07-16 20:24 290432 ----a-w- c:\windows\system32\atmfd.dll
2011-02-09 13:53 . 2003-07-16 20:43 270848 ----a-w- c:\windows\system32\sbe.dll
2011-02-09 13:53 . 2003-07-16 20:27 186880 ----a-w- c:\windows\system32\encdec.dll
2011-02-08 13:33 . 2003-07-16 20:33 978944 ----a-w- c:\windows\system32\mfc42.dll
2011-02-08 13:33 . 2003-07-16 20:33 974848 ----a-w- c:\windows\system32\mfc42u.dll
2011-02-02 07:58 . 2006-05-14 13:19 2067456 ----a-w- c:\windows\system32\mstscax.dll
2011-01-27 11:57 . 2006-05-14 13:19 677888 ----a-w- c:\windows\system32\mstsc.exe
2011-01-21 14:44 . 2003-07-16 20:44 439296 ----a-w- c:\windows\system32\shimgvw.dll
2011-03-18 17:53 . 2011-03-24 23:51 142296 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SmileboxTray"="c:\documents and settings\MARGIE\Application Data\Smilebox\SmileboxTray.exe" [2010-03-09 287368]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"dla"="c:\windows\system32\dla\tfswctrl.exe" [2004-03-15 122933]
"LXCYCATS"="c:\windows\System32\spool\DRIVERS\W32X86\3\LXCYtime.dll" [2006-11-21 106496]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2010-08-10 421888]
"InstaLAN"="c:\program files\Belkin\Router Setup and Monitor\BelkinRouterMonitor.exe" [2010-07-28 1485208]
"MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2010-11-30 997408]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-11-12 141600]
"LogMeIn GUI"="c:\program files\LogMeIn\x86\LogMeInSystray.exe" [2010-09-17 63048]
.
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\LMIinit]
2011-03-01 17:12 87424 ----a-w- c:\windows\system32\LMIinit.dll
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk
backup=c:\windows\pss\Adobe Reader Speed Launch.lnkCommon Startup
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Office.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk
backup=c:\windows\pss\Microsoft Office.lnkCommon Startup
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DVDLauncher]
2004-04-11 16:43 53248 ------w- c:\program files\CyberLink\PowerDVD\DVDLauncher.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\EzPrint]
2007-06-25 16:34 82608 ----a-w- c:\program files\Lexmark 3400 Series\ezprint.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
2009-11-12 22:33 141600 ----a-w- c:\program files\iTunes\iTunesHelper.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\lxcymon.exe]
2007-06-25 16:34 291504 ----a-w- c:\program files\Lexmark 3400 Series\lxcymon.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Microsoft Works Update Detection]
2003-06-07 11:32 50688 ----a-w- c:\program files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
2010-08-10 10:15 421888 ----a-w- c:\program files\QuickTime\QTTask.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SUPERAntiSpyware]
2010-02-18 21:40 2012912 ----a-w- c:\program files\SUPERAntiSpyware\SUPERAntiSpyware.exe
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\WINDOWS\\system32\\lxcycoms.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3724:TCP"= 3724:TCP:Blizzard Downloader: 3724
.
R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys [2/17/2010 10:25 AM 12872]
R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [2/17/2010 10:15 AM 66632]
R2 LMIGuardianSvc;LMIGuardianSvc;c:\program files\LogMeIn\x86\LMIGuardianSvc.exe [3/1/2011 12:11 PM 374152]
R2 LMIInfo;LogMeIn Kernel Information Provider;c:\program files\LogMeIn\x86\rainfo.sys [9/17/2010 3:40 PM 12856]
R2 lxcy_device;lxcy_device;c:\windows\system32\lxcycoms.exe -service --> c:\windows\system32\lxcycoms.exe -service [?]
S1 MpKsl0b14781f;MpKsl0b14781f;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{ABC87890-AB79-46A0-9784-8023255952A2}\MpKsl0b14781f.sys --> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{ABC87890-AB79-46A0-9784-8023255952A2}\MpKsl0b14781f.sys [?]
S1 MpKsl4b4a8d69;MpKsl4b4a8d69;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{9A294822-06BE-4F73-8F0F-D569ED75C1F2}\MpKsl4b4a8d69.sys --> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{9A294822-06BE-4F73-8F0F-D569ED75C1F2}\MpKsl4b4a8d69.sys [?]
S1 MpKsl4e7124f7;MpKsl4e7124f7;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{A734D427-B116-468D-B98A-4CFC3086044B}\MpKsl4e7124f7.sys --> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{A734D427-B116-468D-B98A-4CFC3086044B}\MpKsl4e7124f7.sys [?]
S3 SASENUM;SASENUM;c:\program files\SUPERAntiSpyware\SASENUM.SYS [2/17/2010 10:15 AM 12872]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
getPlusHelper REG_MULTI_SZ getPlusHelper
.
Contents of the 'Scheduled Tasks' folder
.
2011-04-18 c:\windows\Tasks\MP Scheduled Scan.job
- c:\program files\Microsoft Security Client\Antimalware\MpCmdRun.exe [2010-11-11 18:26]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.msn.com
uSearchMigratedDefaultURL = hxxp://search.live.com/results.aspx?q={searchTerms}&src={referrer:source?}
FF - ProfilePath - c:\documents and settings\MARGIE\Application Data\Mozilla\Firefox\Profiles\d0jvnpba.default\
FF - prefs.js: browser.search.defaulturl - hxxp://www.google.com/search?lr=&ie=UTF-8&oe=UTF-8&q=
FF - prefs.js: browser.search.selectedEngine - Google
.
- - - - ORPHANS REMOVED - - - -
.
Notify-avgrsstarter - avgrsstx.dll
MSConfigStartUp-swg - c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2011-04-17 19:12
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes ...
.
scanning hidden autostart entries ...
.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
LXCYCATS = rundll32 c:\windows\System32\spool\DRIVERS\W32X86\3\LXCYtime.dll,_RunDLLEntry@16???????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????
.
scanning hidden files ...
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10l_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10l_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
--------------------- DLLs Loaded Under Running Processes ---------------------
.
- - - - - - - > 'winlogon.exe'(632)
c:\windows\system32\LMIinit.dll
c:\windows\system32\LMIRfsClientNP.dll
.
- - - - - - - > 'explorer.exe'(3424)
c:\windows\system32\WININET.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Other Running Processes ------------------------
.
c:\program files\Microsoft Security Client\Antimalware\MsMpEng.exe
c:\program files\Belkin\Router Setup and Monitor\BelkinService.exe
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\LogMeIn\x86\RaMaint.exe
c:\program files\LogMeIn\x86\LogMeIn.exe
c:\windows\system32\lxcycoms.exe
c:\windows\system32\wscntfy.exe
c:\program files\LogMeIn\x86\LogMeIn.exe
c:\program files\Belkin\Router Setup and Monitor\BelkinSetup.exe
c:\program files\Belkin\Router Setup and Monitor\dlnaPlugin.exe
c:\program files\iPod\bin\iPodService.exe
.
**************************************************************************
.
Completion time: 2011-04-17 19:19:52 - machine was rebooted
ComboFix-quarantined-files.txt 2011-04-18 00:19
ComboFix2.txt 2010-03-21 17:33
.
Pre-Run: 18,350,661,632 bytes free
Post-Run: 18,360,844,288 bytes free
.
- - End Of File - - 2D5A4272E150967A4849EB1370271A02
#11 Re: [RESOLVED] Programs missing
Posted 18 April 2011 - 12:24 AM
How is computer doing?
Download OTL to your Desktop.
- Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
- Click the Scan All Users checkbox.
- Under the Custom Scan box paste this in:
netsvcs
drivers32
%SYSTEMDRIVE%\*.*
%systemroot%\Fonts\*.com
%systemroot%\Fonts\*.dll
%systemroot%\Fonts\*.ini
%systemroot%\Fonts\*.ini2
%systemroot%\Fonts\*.exe
%systemroot%\system32\spool\prtprocs\w32x86\*.*
%systemroot%\REPAIR\*.bak1
%systemroot%\REPAIR\*.ini
%systemroot%\system32\*.jpg
%systemroot%\*.jpg
%systemroot%\*.png
%systemroot%\*.scr
%systemroot%\*._sy
%APPDATA%\Adobe\Update\*.*
%ALLUSERSPROFILE%\Favorites\*.*
%APPDATA%\Microsoft\*.*
%PROGRAMFILES%\*.*
%APPDATA%\Update\*.*
%systemroot%\*. /mp /s
CREATERESTOREPOINT
%systemroot%\System32\config\*.sav
%PROGRAMFILES%\bak. /s
%systemroot%\system32\bak. /s
%ALLUSERSPROFILE%\Start Menu\*.lnk /x
%systemroot%\system32\config\systemprofile\*.dat /x
%systemroot%\*.config
%systemroot%\system32\*.db
%APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x
%USERPROFILE%\Desktop\*.exe
%PROGRAMFILES%\Common Files\*.*
%systemroot%\*.src
%systemroot%\install\*.*
%systemroot%\system32\DLL\*.*
%systemroot%\system32\HelpFiles\*.*
%systemroot%\system32\rundll\*.*
%systemroot%\winn32\*.*
%systemroot%\Java\*.*
%systemroot%\system32\test\*.*
%systemroot%\system32\Rundll32\*.*
%systemroot%\AppPatch\Custom\*.*
%APPDATA%\Roaming\Microsoft\Windows\Recent\*.lnk /x
%PROGRAMFILES%\PC-Doctor\Downloads\*.*
%PROGRAMFILES%\Internet Explorer\*.tmp
%PROGRAMFILES%\Internet Explorer\*.dat
%USERPROFILE%\My Documents\*.exe
%USERPROFILE%\*.exe
%systemroot%\ADDINS\*.*
%systemroot%\assembly\*.bak2
%systemroot%\Config\*.*
%systemroot%\REPAIR\*.bak2
%systemroot%\SECURITY\Database\*.sdb /x
%systemroot%\SYSTEM\*.bak2
%systemroot%\Web\*.bak2
%systemroot%\Driver Cache\*.*
%PROGRAMFILES%\Mozilla Firefox\0*.exe
%ProgramFiles%\Microsoft Common\*.*
%ProgramFiles%\TinyProxy.
%USERPROFILE%\Favorites\*.url /x
%systemroot%\system32\*.bk
%systemroot%\*.te
%systemroot%\system32\system32\*.*
%ALLUSERSPROFILE%\*.dat /x
%systemroot%\system32\drivers\*.rmv
dir /b "%systemroot%\system32\*.exe" | find /i " " /c
dir /b "%systemroot%\*.exe" | find /i " " /c
%PROGRAMFILES%\Microsoft\*.*
%systemroot%\System32\Wbem\proquota.exe
%PROGRAMFILES%\Mozilla Firefox\*.dat
%USERPROFILE%\Cookies\*.txt /x
%SystemRoot%\system32\fonts\*.*
%systemroot%\system32\winlog\*.*
%systemroot%\system32\Language\*.*
%systemroot%\system32\Settings\*.*
%systemroot%\system32\*.quo
%SYSTEMROOT%\AppPatch\*.exe
%SYSTEMROOT%\inf\*.exe
%SYSTEMROOT%\Installer\*.exe
%systemroot%\system32\config\*.bak2
%systemroot%\system32\Computers\*.*
%SystemRoot%\system32\Sound\*.*
%SystemRoot%\system32\SpecialImg\*.*
%SystemRoot%\system32\code\*.*
%SystemRoot%\system32\draft\*.*
%SystemRoot%\system32\MSSSys\*.*
%ProgramFiles%\Javascript\*.*
%systemroot%\pchealth\helpctr\System\*.exe /s
%systemroot%\Web\*.exe
%systemroot%\system32\msn\*.*
%systemroot%\system32\*.tro
%AppData%\Microsoft\Installer\msupdates\*.*
%ProgramFiles%\Messenger\*.*
%systemroot%\system32\systhem32\*.*
%systemroot%\system\*.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs
/md5start
/md5stop
- Click the Quick Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
- When the scan completes, it will open two notepad windows: OTL.txt and Extras.txt. These are saved in the same location as OTL.
- Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post them back here.
#12 Re: [RESOLVED] Programs missing
Posted 18 April 2011 - 12:32 AM
OTL by OldTimer - Version 3.2.22.3 Folder = C:\Documents and Settings\MARGIE\Desktop
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.11)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
1.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 57.00% Memory free
1.00 Gb Paging File | 1.00 Gb Available in Paging File | 65.00% Paging File free
Paging file location(s): C:\pagefile.sys 384 768 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 37.21 Gb Total Space | 17.12 Gb Free Space | 46.00% Space Free | Partition Type: NTFS
Unable to calculate disk information.
Computer Name: MARGIE-69SGZAZK | User Name: MARGIE | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - [2011/04/17 19:27:14 | 000,580,608 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\MARGIE\Desktop\OTL.exe
PRC - [2011/03/01 12:12:00 | 000,136,584 | ---- | M] (LogMeIn, Inc.) -- C:\Program Files\LogMeIn\x86\ramaint.exe
PRC - [2011/03/01 12:11:56 | 000,374,152 | ---- | M] (LogMeIn, Inc.) -- C:\Program Files\LogMeIn\x86\LMIGuardianSvc.exe
PRC - [2010/11/30 14:20:36 | 000,997,408 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Microsoft Security Client\msseces.exe
PRC - [2010/11/11 13:26:40 | 000,011,736 | ---- | M] (Microsoft Corporation) -- c:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe
PRC - [2010/11/08 12:04:20 | 000,390,528 | ---- | M] (LogMeIn, Inc.) -- C:\Program Files\LogMeIn\x86\LogMeIn.exe
PRC - [2010/09/17 15:40:06 | 000,063,048 | ---- | M] (LogMeIn, Inc.) -- C:\Program Files\LogMeIn\x86\LogMeInSystray.exe
PRC - [2010/08/06 19:54:14 | 001,505,688 | ---- | M] (Affinegy, Inc.) -- C:\Program Files\Belkin\Router Setup and Monitor\dlnaPlugin.exe
PRC - [2010/07/28 18:34:02 | 000,569,752 | ---- | M] (Affinegy, Inc.) -- C:\Program Files\Belkin\Router Setup and Monitor\BelkinService.exe
PRC - [2010/07/28 18:33:58 | 006,995,864 | ---- | M] (Affinegy, Inc.) -- C:\Program Files\Belkin\Router Setup and Monitor\BelkinSetup.exe
PRC - [2010/07/28 18:33:58 | 001,485,208 | ---- | M] (Affinegy, Inc.) -- C:\Program Files\Belkin\Router Setup and Monitor\BelkinRouterMonitor.exe
PRC - [2010/03/09 14:15:42 | 000,287,368 | ---- | M] (Smilebox, Inc.) -- C:\Documents and Settings\MARGIE\Application Data\Smilebox\SmileboxTray.exe
PRC - [2008/04/13 19:12:19 | 001,033,728 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe
PRC - [2007/06/20 07:28:56 | 000,537,264 | ---- | M] ( ) -- C:\WINDOWS\system32\lxcycoms.exe
========== Modules (SafeList) ==========
MOD - [2011/04/17 19:27:14 | 000,580,608 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\MARGIE\Desktop\OTL.exe
MOD - [2010/08/23 11:12:02 | 001,054,208 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.6028_x-ww_61e65202\comctl32.dll
========== Win32 Services (SafeList) ==========
SRV - File not found [On_Demand | Stopped] -- -- (usnsvc)
SRV - File not found [Disabled | Stopped] -- -- (HidServ)
SRV - File not found [Disabled | Stopped] -- -- (AppMgmt)
SRV - [2011/03/01 12:12:00 | 000,136,584 | ---- | M] (LogMeIn, Inc.) [Auto | Running] -- C:\Program Files\LogMeIn\x86\RaMaint.exe -- (LMIMaint)
SRV - [2011/03/01 12:11:56 | 000,374,152 | ---- | M] (LogMeIn, Inc.) [Auto | Running] -- C:\Program Files\LogMeIn\x86\LMIGuardianSvc.exe -- (LMIGuardianSvc)
SRV - [2010/11/11 13:26:40 | 000,011,736 | ---- | M] (Microsoft Corporation) [Auto | Running] -- c:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe -- (MsMpSvc)
SRV - [2010/11/08 12:04:20 | 000,390,528 | ---- | M] (LogMeIn, Inc.) [Auto | Running] -- C:\Program Files\LogMeIn\x86\LogMeIn.exe -- (LogMeIn)
SRV - [2010/07/28 18:34:02 | 000,569,752 | ---- | M] (Affinegy, Inc.) [Auto | Running] -- C:\Program Files\Belkin\Router Setup and Monitor\BelkinService.exe -- (AffinegyService)
SRV - [2009/08/07 12:44:18 | 000,045,816 | ---- | M] (NOS Microsystems Ltd.) [On_Demand | Stopped] -- C:\Program Files\NOS\bin\getPlus_Helper.dll -- (getPlusHelper) getPlus®
SRV - [2007/06/20 07:28:56 | 000,537,264 | ---- | M] ( ) [Auto | Running] -- C:\WINDOWS\System32\lxcycoms.exe -- (lxcy_device)
========== Driver Services (SafeList) ==========
DRV - File not found [Kernel | On_Demand | Running] -- -- (catchme)
DRV - [2011/03/01 12:12:24 | 000,083,360 | ---- | M] (LogMeIn, Inc.) [File_System | Disabled | Stopped] -- C:\WINDOWS\System32\LMIRfsClientNP.dll -- (LMIRfsClientNP)
DRV - [2010/09/17 15:40:06 | 000,047,640 | ---- | M] (LogMeIn, Inc.) [File_System | Auto | Running] -- C:\WINDOWS\system32\drivers\LMIRfsDriver.sys -- (LMIRfsDriver)
DRV - [2010/09/17 15:40:06 | 000,012,856 | ---- | M] (LogMeIn, Inc.) [Kernel | Auto | Running] -- C:\Program Files\LogMeIn\x86\rainfo.sys -- (LMIInfo)
DRV - [2010/06/23 19:12:50 | 000,027,072 | ---- | M] (Printing Communications Assoc., Inc. (PCAUSA)) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\AFGSp50.sys -- (AFGSp50)
DRV - [2010/02/17 10:25:50 | 000,012,872 | ---- | M] (SUPERAdBlocker.com and SUPERAntiSpyware.com) [Kernel | System | Running] -- C:\Program Files\SUPERAntiSpyware\sasdifsv.sys -- (SASDIFSV)
DRV - [2010/02/17 10:15:58 | 000,066,632 | ---- | M] (SUPERAdBlocker.com and SUPERAntiSpyware.com) [Kernel | System | Running] -- C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS -- (SASKUTIL)
DRV - [2010/02/17 10:15:58 | 000,012,872 | R--- | M] ( SUPERAdBlocker.com and SUPERAntiSpyware.com) [Kernel | On_Demand | Stopped] -- C:\Program Files\SUPERAntiSpyware\SASENUM.SYS -- (SASENUM)
DRV - [2004/08/03 22:29:28 | 000,327,040 | ---- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\ati2mtaa.sys -- (ati2mtaa)
DRV - [2003/11/17 15:59:20 | 000,212,224 | R--- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\HSFHWBS2.sys -- (HSFHWBS2)
DRV - [2003/11/17 15:58:02 | 000,680,704 | R--- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\HSF_CNXT.sys -- (winachsf)
DRV - [2003/11/17 15:56:26 | 001,042,432 | R--- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\HSF_DP.sys -- (HSF_DP)
DRV - [2001/08/22 08:42:58 | 000,013,632 | ---- | M] (Dell Computer Corporation) [Kernel | System | Running] -- C:\WINDOWS\SYSTEM32\DRIVERS\OMCI.SYS -- (OMCI)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-2052111302-1284227242-725345543-1004\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultName = Live Search
IE - HKU\S-1-5-21-2052111302-1284227242-725345543-1004\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultURL = http://search.live.c...ferrer:source?}
IE - HKU\S-1-5-21-2052111302-1284227242-725345543-1004\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.msn.com
IE - HKU\S-1-5-21-2052111302-1284227242-725345543-1004\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-2052111302-1284227242-725345543-1008\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
========== FireFox ==========
FF - prefs.js..browser.search.defaultenginename: "Google"
FF - prefs.js..browser.search.defaulturl: "http://www.google.com/search?lr=&ie=UTF-8&oe=UTF-8&q="
FF - prefs.js..browser.search.selectedEngine: "Google"
FF - prefs.js..extensions.enabledItems: avg@igeared:3.011.025.005
FF - prefs.js..extensions.enabledItems: jqs@sun.com:1.0
FF - prefs.js..extensions.enabledItems: {B13721C7-F507-4982-B2E5-502A71474FED}:3.3.0.3971
FF - HKLM\software\mozilla\Firefox\extensions\\avg@igeared: C:\Program Files\AVG\AVG9\Toolbar\Firefox\avg@igeared [2010/03/21 18:54:03 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 4.0\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011/03/24 19:20:38 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 4.0\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011/03/24 19:20:38 | 000,000,000 | ---D | M]
[2008/09/01 00:23:24 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\MARGIE\Application Data\Mozilla\Extensions
[2011/03/24 00:47:05 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\MARGIE\Application Data\Mozilla\Firefox\Profiles\d0jvnpba.default\extensions
[2011/02/01 00:04:14 | 000,000,000 | ---D | M] (Google Toolbar for Firefox) -- C:\Documents and Settings\MARGIE\Application Data\Mozilla\Firefox\Profiles\d0jvnpba.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}
[2011/03/24 18:51:37 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions
[2007/10/06 11:46:00 | 000,000,000 | ---D | M] (Google Toolbar for Firefox) -- C:\Program Files\Mozilla Firefox\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}
File not found (No name found) --
[2010/03/21 16:45:54 | 000,000,000 | ---D | M] (Java Quick Starter) -- C:\PROGRAM FILES\JAVA\JRE6\LIB\DEPLOY\JQS\FF
[2011/03/18 12:53:24 | 000,142,296 | ---- | M] (Mozilla Foundation) -- C:\Program Files\Mozilla Firefox\components\browsercomps.dll
[2009/11/19 17:16:28 | 000,091,552 | ---- | M] (Coupons, Inc.) -- C:\Program Files\Mozilla Firefox\plugins\npCouponPrinter.dll
[2009/11/19 17:16:29 | 000,091,552 | ---- | M] (Coupons, Inc.) -- C:\Program Files\Mozilla Firefox\plugins\npMozCouponPrinter.dll
[2010/01/01 03:00:00 | 000,002,252 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\bing.xml
O1 HOSTS File: ([2011/04/17 19:11:52 | 000,000,027 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (no name) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - No CLSID value found.
O2 - BHO: (DriveLetterAccess) - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll (Sonic Solutions)
O2 - BHO: (Google Dictionary Compression sdch) - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - File not found
O2 - BHO: (WOT Helper) - {C920E44A-7F78-4E64-BDD7-A57026E7FEB7} - C:\Program Files\WOT\WOT.dll ()
O3 - HKLM\..\Toolbar: (WOT) - {71576546-354D-41c9-AAE8-31F2EC22BF0D} - C:\Program Files\WOT\WOT.dll ()
O3 - HKU\.DEFAULT\..\Toolbar\WebBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No CLSID value found.
O3 - HKU\S-1-5-18\..\Toolbar\WebBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No CLSID value found.
O3 - HKU\S-1-5-21-2052111302-1284227242-725345543-1004\..\Toolbar\WebBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No CLSID value found.
O3 - HKU\S-1-5-21-2052111302-1284227242-725345543-1004\..\Toolbar\WebBrowser: (WOT) - {71576546-354D-41C9-AAE8-31F2EC22BF0D} - C:\Program Files\WOT\WOT.dll ()
O4 - HKLM..\Run: [InstaLAN] C:\Program Files\Belkin\Router Setup and Monitor\BelkinRouterMonitor.exe (Affinegy, Inc.)
O4 - HKLM..\Run: [LogMeIn GUI] C:\Program Files\LogMeIn\x86\LogMeInSystray.exe (LogMeIn, Inc.)
O4 - HKLM..\Run: [LXCYCATS] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\LXCYtime.DLL (Lexmark International Inc.)
O4 - HKLM..\Run: [MSC] c:\Program Files\Microsoft Security Client\msseces.exe (Microsoft Corporation)
O4 - HKU\S-1-5-21-2052111302-1284227242-725345543-1004..\Run: [SmileboxTray] C:\Documents and Settings\MARGIE\Application Data\Smilebox\SmileboxTray.exe (Smilebox, Inc.)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-21-2052111302-1284227242-725345543-1004\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-2052111302-1284227242-725345543-1004\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKU\S-1-5-21-2052111302-1284227242-725345543-1004\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKU\S-1-5-21-2052111302-1284227242-725345543-1004\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKU\S-1-5-21-2052111302-1284227242-725345543-1008\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-2052111302-1284227242-725345543-1008\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} http://messenger.zon...kr.cab31267.cab (Checkers Class)
O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} http://lads.myspace....ploader1006.cab (MySpace Uploader Control)
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} http://gfx1.hotmail....es/MSNPUpld.cab (MSN Photo Upload Tool)
O16 - DPF: {5F8469B4-B055-49DD-83F7-62B522420ECC} http://upload.facebo...otoUploader.cab (Facebook Photo Uploader Control)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} http://www.update.mi...b?1265480380265 (MUWebControl Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_18)
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} http://messenger.zon...nt.cab31267.cab (MessengerStatsClient Class)
O16 - DPF: {BB21F850-63F4-4EC9-BF9D-565BD30C9AE9} http://ax.emsisoft.com/asquared.cab (a-squared Scanner)
O16 - DPF: {CAFEEFAC-0016-0000-0018-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_18)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_18)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://download.macr...ash/swflash.cab (Shockwave Flash Object)
O16 - DPF: {E77F23EB-E7AB-4502-8F37-247DBAF1A147} http://gfx1.hotmail....ol/MSNPUpld.cab (Windows Live Hotmail Photo Upload Tool)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.2.1
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - Reg Error: Key error. File not found
O18 - Protocol\Handler\wot {C2A44D6B-CB9F-4663-88A6-DF2F26E4D952} - C:\Program Files\WOT\WOT.dll ()
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\LMIinit: DllName - LMIinit.dll - C:\WINDOWS\System32\LMIinit.dll (LogMeIn, Inc.)
O24 - Desktop WallPaper: C:\Documents and Settings\MARGIE\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\MARGIE\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O28 - HKLM ShellExecuteHooks: {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - C:\Program Files\SUPERAntiSpyware\SASSEH.DLL (SuperAdBlocker.com)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006/05/14 08:22:26 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKU\S-1-5-21-2052111302-1284227242-725345543-1004\...com [@ = ComFile] -- Reg Error: Key error. File not found
O37 - HKU\S-1-5-21-2052111302-1284227242-725345543-1004\...exe [@ = exefile] -- Reg Error: Key error. File not found
NetSvcs: 6to4 - File not found
NetSvcs: AppMgmt - File not found
NetSvcs: HidServ - File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found
Drivers32: msacm.iac2 - C:\WINDOWS\System32\iac25_32.ax (Intel Corporation)
Drivers32: msacm.l3acm - C:\WINDOWS\System32\l3codecp.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.l3codec - C:\WINDOWS\System32\l3codecp.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.sl_anet - C:\WINDOWS\System32\sl_anet.acm (Sipro Lab Telecom Inc.)
Drivers32: msacm.trspch - C:\WINDOWS\System32\tssoft32.acm (DSP GROUP, INC.)
Drivers32: vidc.cvid - C:\WINDOWS\System32\iccvid.dll (Radius Inc.)
Drivers32: vidc.iv31 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv32 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv41 - C:\WINDOWS\System32\ir41_32.ax (Intel Corporation)
Drivers32: vidc.iv50 - C:\WINDOWS\System32\ir50_32.dll (Intel Corporation)
Drivers32: vidc.XVID - C:\WINDOWS\System32\xvidvfw.dll ()
Drivers32: wave1 - C:\WINDOWS\System32\serwvdrv.dll (Microsoft Corporation)
CREATERESTOREPOINT
Restore point Set: OTL Restore Point (16902109354000384)
========== Files/Folders - Created Within 30 Days ==========
[2011/04/17 19:27:12 | 000,580,608 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\MARGIE\Desktop\OTL.exe
[2011/04/17 19:04:38 | 000,212,480 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWXCACLS.exe
[2011/04/17 19:04:38 | 000,161,792 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWREG.exe
[2011/04/17 19:04:38 | 000,136,704 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWSC.exe
[2011/04/17 19:04:38 | 000,031,232 | ---- | C] (NirSoft) -- C:\WINDOWS\NIRCMD.exe
[2011/04/17 19:04:25 | 000,000,000 | ---D | C] -- C:\Qoobox
[2011/04/17 15:58:38 | 000,000,000 | ---D | C] -- C:\Documents and Settings\MARGIE\Local Settings\Application Data\LogMeIn
[2011/04/17 15:58:32 | 000,083,360 | ---- | C] (LogMeIn, Inc.) -- C:\WINDOWS\System32\LMIRfsClientNP.dll
[2011/04/17 15:58:32 | 000,047,640 | ---- | C] (LogMeIn, Inc.) -- C:\WINDOWS\System32\drivers\LMIRfsDriver.sys
[2011/04/17 15:58:32 | 000,029,568 | ---- | C] (LogMeIn, Inc.) -- C:\WINDOWS\System32\LMIport.dll
[2011/04/17 15:58:23 | 000,087,424 | ---- | C] (LogMeIn, Inc.) -- C:\WINDOWS\System32\LMIinit.dll
[2011/04/17 15:58:18 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\LogMeIn
[2011/04/17 15:58:02 | 000,000,000 | ---D | C] -- C:\Program Files\LogMeIn
[2011/04/17 15:13:08 | 000,000,000 | R--D | C] -- C:\Documents and Settings\MARGIE\Recent
[2011/04/16 09:37:36 | 000,000,000 | ---D | C] -- C:\Documents and Settings\MARGIE\Start Menu\Programs\Windows Recovery
[2010/02/06 13:00:28 | 000,323,584 | ---- | C] ( ) -- C:\WINDOWS\System32\lxcyhcp.dll
[2010/02/06 13:00:27 | 000,413,696 | ---- | C] ( ) -- C:\WINDOWS\System32\lxcyinpa.dll
[2010/02/06 13:00:27 | 000,397,312 | ---- | C] ( ) -- C:\WINDOWS\System32\lxcyiesc.dll
[2010/02/06 13:00:26 | 000,995,328 | ---- | C] ( ) -- C:\WINDOWS\System32\lxcyusb1.dll
[2010/02/06 13:00:25 | 001,224,704 | ---- | C] ( ) -- C:\WINDOWS\System32\lxcyserv.dll
[2010/02/06 13:00:25 | 000,163,840 | ---- | C] ( ) -- C:\WINDOWS\System32\lxcyprox.dll
[2010/02/06 13:00:25 | 000,094,208 | ---- | C] ( ) -- C:\WINDOWS\System32\lxcypplc.dll
[2010/02/06 13:00:24 | 000,643,072 | ---- | C] ( ) -- C:\WINDOWS\System32\lxcypmui.dll
[2010/02/06 13:00:24 | 000,585,728 | ---- | C] ( ) -- C:\WINDOWS\System32\lxcylmpm.dll
[2010/02/06 13:00:22 | 000,385,712 | ---- | C] ( ) -- C:\WINDOWS\System32\lxcyih.exe
[2010/02/06 13:00:21 | 000,696,320 | ---- | C] ( ) -- C:\WINDOWS\System32\lxcyhbn3.dll
[2010/02/06 13:00:19 | 000,537,264 | ---- | C] ( ) -- C:\WINDOWS\System32\lxcycoms.exe
[2010/02/06 13:00:19 | 000,421,888 | ---- | C] ( ) -- C:\WINDOWS\System32\lxcycomm.dll
[2010/02/06 13:00:18 | 000,684,032 | ---- | C] ( ) -- C:\WINDOWS\System32\lxcycomc.dll
[2010/02/06 13:00:18 | 000,381,616 | ---- | C] ( ) -- C:\WINDOWS\System32\lxcycfg.exe
[3 C:\Documents and Settings\All Users\*.tmp files -> C:\Documents and Settings\All Users\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2011/04/17 19:27:14 | 000,580,608 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\MARGIE\Desktop\OTL.exe
[2011/04/17 19:22:08 | 000,000,349 | ---- | M] () -- C:\Documents and Settings\MARGIE\Desktop\SmartestComputing - Computer help forum.url
[2011/04/17 19:17:14 | 000,000,424 | -H-- | M] () -- C:\WINDOWS\tasks\MP Scheduled Scan.job
[2011/04/17 19:11:52 | 000,000,027 | ---- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts
[2011/04/17 19:11:28 | 000,002,206 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2011/04/17 19:11:02 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2011/04/17 19:11:01 | 1206,964,224 | -HS- | M] () -- C:\hiberfil.sys
[2011/04/17 19:03:32 | 004,323,312 | R--- | M] () -- C:\Documents and Settings\MARGIE\Desktop\ComboFix.exe
[2011/04/17 18:52:00 | 000,504,657 | ---- | M] () -- C:\Documents and Settings\MARGIE\Desktop\unhide.exe
[2011/04/17 16:10:18 | 000,625,664 | ---- | M] () -- C:\Documents and Settings\MARGIE\Desktop\dds.scr
[2011/04/17 16:09:51 | 000,080,384 | ---- | M] () -- C:\Documents and Settings\MARGIE\Desktop\MBRCheck.exe
[2011/04/17 16:09:29 | 000,301,568 | ---- | M] () -- C:\Documents and Settings\MARGIE\Desktop\lt94ctkh.exe
[2011/04/17 16:08:59 | 000,446,464 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\MARGIE\Desktop\TFC.exe
[2011/04/17 15:58:21 | 000,001,024 | ---- | M] () -- C:\.rnd
[2011/04/17 15:23:20 | 000,000,784 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2011/04/17 15:13:27 | 000,000,160 | ---- | M] () -- C:\Documents and Settings\All Users\Application Data\~19783476r
[2011/04/17 15:13:27 | 000,000,120 | ---- | M] () -- C:\Documents and Settings\All Users\Application Data\~19783476
[2011/04/16 09:37:37 | 000,000,813 | ---- | M] () -- C:\Documents and Settings\MARGIE\Desktop\Windows Recovery.lnk
[2011/04/16 09:37:33 | 000,000,344 | ---- | M] () -- C:\Documents and Settings\All Users\Application Data\19783476
[2011/04/14 03:24:26 | 000,239,944 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2011/04/13 23:32:52 | 000,002,137 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\iTunes.lnk
[2011/03/24 18:51:44 | 000,000,724 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Mozilla Firefox.lnk
[3 C:\Documents and Settings\All Users\*.tmp files -> C:\Documents and Settings\All Users\*.tmp -> ]
========== Files Created - No Company Name ==========
[2011/04/17 19:22:08 | 000,000,349 | ---- | C] () -- C:\Documents and Settings\MARGIE\Desktop\SmartestComputing - Computer help forum.url
[2011/04/17 19:04:38 | 000,256,512 | ---- | C] () -- C:\WINDOWS\PEV.exe
[2011/04/17 19:04:38 | 000,098,816 | ---- | C] () -- C:\WINDOWS\sed.exe
[2011/04/17 19:04:38 | 000,089,088 | ---- | C] () -- C:\WINDOWS\MBR.exe
[2011/04/17 19:04:38 | 000,080,412 | ---- | C] () -- C:\WINDOWS\grep.exe
[2011/04/17 19:04:38 | 000,068,096 | ---- | C] () -- C:\WINDOWS\zip.exe
[2011/04/17 19:03:25 | 004,323,312 | R--- | C] () -- C:\Documents and Settings\MARGIE\Desktop\ComboFix.exe
[2011/04/17 18:51:59 | 000,504,657 | ---- | C] () -- C:\Documents and Settings\MARGIE\Desktop\unhide.exe
[2011/04/17 16:10:15 | 000,625,664 | ---- | C] () -- C:\Documents and Settings\MARGIE\Desktop\dds.scr
[2011/04/17 16:09:56 | 000,080,384 | ---- | C] () -- C:\Documents and Settings\MARGIE\Desktop\MBRCheck.exe
[2011/04/17 16:09:22 | 000,301,568 | ---- | C] () -- C:\Documents and Settings\MARGIE\Desktop\lt94ctkh.exe
[2011/04/17 15:58:20 | 000,001,024 | ---- | C] () -- C:\.rnd
[2011/04/17 15:58:10 | 000,000,719 | ---- | C] () -- C:\Documents and Settings\All Users\Start Menu\Programs\LogMeIn.lnk
[2011/04/17 15:29:20 | 1206,964,224 | -HS- | C] () -- C:\hiberfil.sys
[2011/04/17 15:23:20 | 000,000,784 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2011/04/16 09:37:37 | 000,000,813 | ---- | C] () -- C:\Documents and Settings\MARGIE\Desktop\Windows Recovery.lnk
[2011/04/16 09:37:37 | 000,000,160 | ---- | C] () -- C:\Documents and Settings\All Users\Application Data\~19783476r
[2011/04/16 09:37:37 | 000,000,120 | ---- | C] () -- C:\Documents and Settings\All Users\Application Data\~19783476
[2011/04/16 09:37:33 | 000,000,344 | ---- | C] () -- C:\Documents and Settings\All Users\Application Data\19783476
[2011/03/24 18:51:44 | 000,000,730 | ---- | C] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Mozilla Firefox.lnk
[2010/05/15 16:48:20 | 000,043,636 | ---- | C] () -- C:\WINDOWS\System32\mlfcache.dat
[2010/03/20 21:31:08 | 000,000,036 | ---- | C] () -- C:\Documents and Settings\MARGIE\Local Settings\Application Data\housecall.guid.cache
[2010/02/06 13:03:58 | 000,040,960 | ---- | C] () -- C:\WINDOWS\System32\lxcyvs.dll
[2010/02/06 13:03:50 | 000,344,064 | ---- | C] () -- C:\WINDOWS\System32\lxcycoin.dll
[2010/02/06 13:02:38 | 000,692,224 | ---- | C] () -- C:\WINDOWS\System32\lxcydrs.dll
[2010/02/06 13:02:38 | 000,065,536 | ---- | C] () -- C:\WINDOWS\System32\lxcycaps.dll
[2010/02/06 13:02:37 | 000,061,440 | ---- | C] () -- C:\WINDOWS\System32\lxcycnv4.dll
[2010/02/06 13:00:29 | 000,274,432 | ---- | C] () -- C:\WINDOWS\System32\lxcyinst.dll
[2009/12/02 00:34:17 | 000,000,056 | ---- | C] () -- C:\WINDOWS\System32\ezsidmv.dat
[2009/07/07 12:16:06 | 000,000,664 | ---- | C] () -- C:\WINDOWS\System32\d3d9caps.dat
[2008/12/10 04:03:24 | 000,000,285 | ---- | C] () -- C:\WINDOWS\System32\MRT.INI
[2008/06/14 23:20:24 | 000,000,033 | ---- | C] () -- C:\WINDOWS\EasyRip.ini
[2008/03/09 15:58:38 | 000,000,095 | ---- | C] () -- C:\WINDOWS\RCAMPEG4VC.ini
[2007/12/25 20:11:09 | 000,561,152 | ---- | C] () -- C:\WINDOWS\System32\xvidcore.dll
[2007/12/25 20:11:09 | 000,237,568 | ---- | C] () -- C:\WINDOWS\System32\xvidvfw.dll
[2007/10/07 21:44:45 | 000,001,156 | ---- | C] () -- C:\WINDOWS\mozver.dat
[2007/10/06 11:46:07 | 000,000,000 | ---- | C] () -- C:\WINDOWS\nsreg.dat
[2006/05/24 18:03:00 | 000,001,404 | ---- | C] () -- C:\Documents and Settings\All Users\Application Data\QTSBandwidthCache
[2006/05/14 09:47:24 | 000,000,138 | ---- | C] () -- C:\WINDOWS\wininit.ini
[2006/05/14 09:34:54 | 000,005,116 | ---- | C] () -- C:\Documents and Settings\MARGIE\Application Data\wklnhst.dat
[2006/05/14 09:26:02 | 000,000,376 | ---- | C] () -- C:\WINDOWS\ODBC.INI
[2006/05/14 08:34:15 | 000,012,288 | ---- | C] () -- C:\WINDOWS\System32\e100bmsg.dll
[2006/05/14 08:27:32 | 000,002,048 | --S- | C] () -- C:\WINDOWS\bootstat.dat
[2006/05/14 08:20:15 | 000,021,640 | ---- | C] () -- C:\WINDOWS\System32\emptyregdb.dat
[2006/05/14 03:15:36 | 000,004,161 | ---- | C] () -- C:\WINDOWS\ODBCINST.INI
[2006/05/14 03:14:40 | 000,239,944 | ---- | C] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2004/08/02 14:20:40 | 000,004,569 | ---- | C] () -- C:\WINDOWS\System32\secupd.dat
[2004/03/26 17:59:22 | 000,000,000 | ---- | C] () -- C:\WINDOWS\System32\px.ini
[2003/07/16 15:54:55 | 000,004,594 | ---- | C] () -- C:\WINDOWS\System32\oembios.dat
[2003/07/16 15:54:54 | 013,107,200 | ---- | C] () -- C:\WINDOWS\System32\oembios.bin
[2003/07/16 15:41:25 | 000,311,604 | ---- | C] () -- C:\WINDOWS\System32\perfh009.dat
[2003/07/16 15:41:25 | 000,272,128 | ---- | C] () -- C:\WINDOWS\System32\perfi009.dat
[2003/07/16 15:41:23 | 000,028,626 | ---- | C] () -- C:\WINDOWS\System32\perfd009.dat
[2003/07/16 15:41:21 | 000,039,992 | ---- | C] () -- C:\WINDOWS\System32\perfc009.dat
[2003/07/16 15:39:07 | 000,000,741 | ---- | C] () -- C:\WINDOWS\System32\noise.dat
[2003/07/16 15:33:50 | 000,673,088 | ---- | C] () -- C:\WINDOWS\System32\mlang.dat
[2003/07/16 15:33:39 | 000,046,258 | ---- | C] () -- C:\WINDOWS\System32\mib.bin
[2003/07/16 15:27:41 | 000,218,003 | ---- | C] () -- C:\WINDOWS\System32\dssec.dat
[2003/07/16 15:26:37 | 000,001,804 | ---- | C] () -- C:\WINDOWS\System32\dcache.bin
========== LOP Check ==========
[2010/12/25 11:20:35 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Affinegy
[2010/03/21 18:53:59 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\AVG Security Toolbar
[2009/12/17 04:31:24 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\avg7
[2010/03/21 19:10:04 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\avg9
[2010/12/13 15:04:06 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\eMhGc06301
[2008/06/04 23:15:20 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\GameTap
[2009/08/29 01:04:27 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\gra
[2011/04/17 15:58:38 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\LogMeIn
[2011/03/07 21:12:14 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\oDoGaDn06300
[2008/09/21 00:25:30 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\YAHOO
[2009/12/25 16:57:13 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\{755AC846-7372-4AC8-8550-C52491DAA8BD}
[2009/12/17 04:31:30 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Hayden\Application Data\AVG7
[2010/06/26 12:51:56 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Hayden\Application Data\Facebook
[2009/12/17 04:31:30 | 000,000,000 | ---D | M] -- C:\Documents and Settings\LocalService\Application Data\AVG7
[2009/12/17 04:31:30 | 000,000,000 | ---D | M] -- C:\Documents and Settings\MARGIE\Application Data\AVG7
[2006/05/14 09:48:57 | 000,000,000 | ---D | M] -- C:\Documents and Settings\MARGIE\Application Data\Leadertech
[2010/03/20 21:26:02 | 000,000,000 | ---D | M] -- C:\Documents and Settings\MARGIE\Application Data\Smilebox
[2006/12/25 03:51:04 | 000,000,000 | ---D | M] -- C:\Documents and Settings\MARGIE\Application Data\Wal-Mart Digital Photo Viewer
[2011/04/17 19:17:14 | 000,000,424 | -H-- | M] () -- C:\WINDOWS\Tasks\MP Scheduled Scan.job
========== Purity Check ==========
========== Custom Scans ==========
< %SYSTEMDRIVE%\*.* >
[2011/04/17 15:58:21 | 000,001,024 | ---- | M] () -- C:\.rnd
[2008/06/14 23:20:21 | 000,001,296 | ---- | M] () -- C:\Audio Recorder_log.txt
[2006/05/14 08:22:26 | 000,000,000 | ---- | M] () -- C:\AUTOEXEC.BAT
[2006/05/15 08:00:07 | 012,286,415 | ---- | M] () -- C:\AVG7QT.DAT
[2010/03/20 19:54:27 | 000,000,211 | ---- | M] () -- C:\Boot.bak
[2010/03/21 10:28:11 | 000,000,281 | RHS- | M] () -- C:\boot.ini
[2004/08/03 23:00:00 | 000,260,272 | ---- | M] () -- C:\cmldr
[2011/04/17 19:19:52 | 000,015,248 | ---- | M] () -- C:\ComboFix.txt
[2006/05/14 08:22:26 | 000,000,000 | ---- | M] () -- C:\CONFIG.SYS
[2008/06/17 17:51:25 | 000,004,948 | ---- | M] () -- C:\EasyCD Ripper_log.txt
[2008/09/12 21:05:08 | 000,077,132 | ---- | M] () -- C:\EZ Dock_log.txt
[2010/03/21 12:13:24 | 000,001,934 | ---- | M] () -- C:\HelpAsst.log
[2011/04/17 19:11:01 | 1206,964,224 | -HS- | M] () -- C:\hiberfil.sys
[2006/05/14 08:22:26 | 000,000,000 | RHS- | M] () -- C:\IO.SYS
[2010/03/16 19:04:08 | 000,170,634 | ---- | M] () -- C:\lxcy.log
[2010/05/02 15:54:40 | 000,000,109 | ---- | M] () -- C:\mbam-error.txt
[2006/05/14 08:22:26 | 000,000,000 | RHS- | M] () -- C:\MSDOS.SYS
[2006/05/14 08:47:39 | 000,047,564 | RHS- | M] () -- C:\NTDETECT.COM
[2008/08/30 13:30:53 | 000,250,048 | RHS- | M] () -- C:\ntldr
[2011/04/17 19:11:00 | 402,653,184 | -HS- | M] () -- C:\pagefile.sys
[2008/06/17 17:25:11 | 000,003,888 | ---- | M] () -- C:\Player Library_log.txt
[2008/07/16 17:16:15 | 000,024,252 | ---- | M] () -- C:\Player Loader_log.txt
[2008/09/19 15:25:12 | 000,000,232 | ---- | M] () -- C:\sqmdata00.sqm
[2008/09/19 15:44:08 | 000,000,232 | ---- | M] () -- C:\sqmdata01.sqm
[2008/09/20 16:53:54 | 000,000,232 | ---- | M] () -- C:\sqmdata02.sqm
[2008/09/20 16:54:13 | 000,000,232 | ---- | M] () -- C:\sqmdata03.sqm
[2008/09/21 00:11:14 | 000,000,232 | ---- | M] () -- C:\sqmdata04.sqm
[2008/09/21 00:11:17 | 000,000,172 | ---- | M] () -- C:\sqmdata05.sqm
[2008/09/21 00:18:35 | 000,000,232 | ---- | M] () -- C:\sqmdata06.sqm
[2008/09/21 00:18:39 | 000,000,172 | ---- | M] () -- C:\sqmdata07.sqm
[2008/09/21 00:20:41 | 000,000,232 | ---- | M] () -- C:\sqmdata08.sqm
[2008/09/21 00:20:44 | 000,000,232 | ---- | M] () -- C:\sqmdata09.sqm
[2008/09/21 01:00:23 | 000,000,268 | ---- | M] () -- C:\sqmdata10.sqm
[2008/09/19 15:04:01 | 000,000,232 | ---- | M] () -- C:\sqmdata11.sqm
[2008/09/19 15:06:33 | 000,000,232 | ---- | M] () -- C:\sqmdata12.sqm
[2008/09/19 15:14:44 | 000,000,232 | ---- | M] () -- C:\sqmdata13.sqm
[2008/09/19 15:15:00 | 000,000,232 | ---- | M] () -- C:\sqmdata14.sqm
[2008/09/19 15:15:03 | 000,000,232 | ---- | M] () -- C:\sqmdata15.sqm
[2008/09/19 15:17:21 | 000,000,232 | ---- | M] () -- C:\sqmdata16.sqm
[2008/09/19 15:17:29 | 000,000,232 | ---- | M] () -- C:\sqmdata17.sqm
[2008/09/19 15:25:07 | 000,000,232 | ---- | M] () -- C:\sqmdata18.sqm
[2008/09/19 15:36:03 | 000,000,232 | ---- | M] () -- C:\sqmdata19.sqm
[2008/09/21 01:00:23 | 000,000,244 | ---- | M] () -- C:\sqmnoopt00.sqm
[2008/09/19 15:04:01 | 000,000,244 | ---- | M] () -- C:\sqmnoopt01.sqm
[2008/09/19 15:06:33 | 000,000,244 | ---- | M] () -- C:\sqmnoopt02.sqm
[2008/09/19 15:14:44 | 000,000,244 | ---- | M] () -- C:\sqmnoopt03.sqm
[2008/09/19 15:15:00 | 000,000,244 | ---- | M] () -- C:\sqmnoopt04.sqm
[2008/09/19 15:15:03 | 000,000,244 | ---- | M] () -- C:\sqmnoopt05.sqm
[2008/09/19 15:17:21 | 000,000,244 | ---- | M] () -- C:\sqmnoopt06.sqm
[2008/09/19 15:17:29 | 000,000,244 | ---- | M] () -- C:\sqmnoopt07.sqm
[2008/09/19 15:25:07 | 000,000,244 | ---- | M] () -- C:\sqmnoopt08.sqm
[2008/09/19 15:25:12 | 000,000,244 | ---- | M] () -- C:\sqmnoopt09.sqm
[2008/09/19 15:36:03 | 000,000,244 | ---- | M] () -- C:\sqmnoopt10.sqm
[2008/09/19 15:44:08 | 000,000,244 | ---- | M] () -- C:\sqmnoopt11.sqm
[2008/09/20 16:53:53 | 000,000,244 | ---- | M] () -- C:\sqmnoopt12.sqm
[2008/09/20 16:54:13 | 000,000,244 | ---- | M] () -- C:\sqmnoopt13.sqm
[2008/09/21 00:11:14 | 000,000,244 | ---- | M] () -- C:\sqmnoopt14.sqm
[2008/09/21 00:11:17 | 000,000,172 | ---- | M] () -- C:\sqmnoopt15.sqm
[2008/09/21 00:18:35 | 000,000,244 | ---- | M] () -- C:\sqmnoopt16.sqm
[2008/09/21 00:18:39 | 000,000,172 | ---- | M] () -- C:\sqmnoopt17.sqm
[2008/09/21 00:20:41 | 000,000,244 | ---- | M] () -- C:\sqmnoopt18.sqm
[2008/09/21 00:20:44 | 000,000,244 | ---- | M] () -- C:\sqmnoopt19.sqm
[2008/03/09 15:57:45 | 000,000,328 | ---- | M] () -- C:\ThVC_log.txt
[2008/09/21 00:26:10 | 000,000,162 | ---- | M] () -- C:\YServer.txt
< %systemroot%\Fonts\*.com >
< %systemroot%\Fonts\*.dll >
< %systemroot%\Fonts\*.ini >
[2006/05/14 08:22:05 | 000,000,067 | -HS- | M] () -- C:\WINDOWS\Fonts\desktop.ini
< %systemroot%\Fonts\*.ini2 >
< %systemroot%\Fonts\*.exe >
< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2011/03/01 12:12:16 | 000,053,632 | ---- | M] (LogMeIn, Inc.) -- C:\WINDOWS\system32\spool\prtprocs\w32x86\LMIproc.dll
[2007/03/16 07:38:26 | 000,117,760 | ---- | M] () -- C:\WINDOWS\system32\spool\prtprocs\w32x86\lxcypp5c.dll
< %systemroot%\REPAIR\*.bak1 >
< %systemroot%\REPAIR\*.ini >
< %systemroot%\system32\*.jpg >
< %systemroot%\*.jpg >
< %systemroot%\*.png >
< %systemroot%\*.scr >
< %systemroot%\*._sy >
< %APPDATA%\Adobe\Update\*.* >
< %ALLUSERSPROFILE%\Favorites\*.* >
< %APPDATA%\Microsoft\*.* >
< %PROGRAMFILES%\*.* >
< %APPDATA%\Update\*.* >
< %systemroot%\*. /mp /s >
< %systemroot%\System32\config\*.sav >
[2006/05/14 03:13:35 | 000,094,208 | ---- | M] () -- C:\WINDOWS\system32\config\default.sav
[2006/05/14 03:13:35 | 000,602,112 | ---- | M] () -- C:\WINDOWS\system32\config\software.sav
[2006/05/14 03:13:35 | 000,397,312 | ---- | M] () -- C:\WINDOWS\system32\config\system.sav
< %PROGRAMFILES%\bak. /s >
< %systemroot%\system32\bak. /s >
< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >
[2008/08/30 13:41:10 | 000,000,272 | -HS- | M] () -- C:\Documents and Settings\All Users\Start Menu\desktop.ini
< %systemroot%\system32\config\systemprofile\*.dat /x >
< %systemroot%\*.config >
< %systemroot%\system32\*.db >
< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2006/05/14 09:05:17 | 000,000,177 | -HS- | M] () -- C:\Documents and Settings\MARGIE\Application Data\Microsoft\Internet Explorer\Quick Launch\desktop.ini
[2006/05/14 08:29:41 | 000,000,079 | ---- | M] () -- C:\Documents and Settings\MARGIE\Application Data\Microsoft\Internet Explorer\Quick Launch\Show Desktop.scf
< %USERPROFILE%\Desktop\*.exe >
[2011/04/17 19:03:32 | 004,323,312 | R--- | M] () -- C:\Documents and Settings\MARGIE\Desktop\ComboFix.exe
[2011/04/17 16:09:29 | 000,301,568 | ---- | M] () -- C:\Documents and Settings\MARGIE\Desktop\lt94ctkh.exe
[2011/04/17 16:09:51 | 000,080,384 | ---- | M] () -- C:\Documents and Settings\MARGIE\Desktop\MBRCheck.exe
[2011/04/17 19:27:14 | 000,580,608 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\MARGIE\Desktop\OTL.exe
[2011/04/17 16:08:59 | 000,446,464 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\MARGIE\Desktop\TFC.exe
[2011/04/17 18:52:00 | 000,504,657 | ---- | M] () -- C:\Documents and Settings\MARGIE\Desktop\unhide.exe
< %PROGRAMFILES%\Common Files\*.* >
< %systemroot%\*.src >
< %systemroot%\install\*.* >
< %systemroot%\system32\DLL\*.* >
< %systemroot%\system32\HelpFiles\*.* >
< %systemroot%\system32\rundll\*.* >
< %systemroot%\winn32\*.* >
< %systemroot%\Java\*.* >
< %systemroot%\system32\test\*.* >
< %systemroot%\system32\Rundll32\*.* >
< %systemroot%\AppPatch\Custom\*.* >
< %APPDATA%\Roaming\Microsoft\Windows\Recent\*.lnk /x >
< %PROGRAMFILES%\PC-Doctor\Downloads\*.* >
< %PROGRAMFILES%\Internet Explorer\*.tmp >
< %PROGRAMFILES%\Internet Explorer\*.dat >
< %USERPROFILE%\My Documents\*.exe >
[2010/03/21 19:19:32 | 003,396,856 | ---- | M] (Piriform Ltd) -- C:\Documents and Settings\MARGIE\My Documents\ccsetup229.exe
[2010/03/21 19:12:57 | 011,862,896 | ---- | M] (Microsoft Corporation) -- C:\Documents and Settings\MARGIE\My Documents\mssefullinstall-x86fre-en-us-xp.exe
< %USERPROFILE%\*.exe >
< %systemroot%\ADDINS\*.* >
< %systemroot%\assembly\*.bak2 >
< %systemroot%\Config\*.* >
< %systemroot%\REPAIR\*.bak2 >
< %systemroot%\SECURITY\Database\*.sdb /x >
< %systemroot%\SYSTEM\*.bak2 >
< %systemroot%\Web\*.bak2 >
< %systemroot%\Driver Cache\*.* >
< %PROGRAMFILES%\Mozilla Firefox\0*.exe >
< %ProgramFiles%\Microsoft Common\*.* >
< %ProgramFiles%\TinyProxy. >
< %USERPROFILE%\Favorites\*.url /x >
[2006/05/14 09:05:17 | 000,000,122 | -HS- | M] () -- C:\Documents and Settings\MARGIE\Favorites\Desktop.ini
< %systemroot%\system32\*.bk >
< %systemroot%\*.te >
< %systemroot%\system32\system32\*.* >
< %ALLUSERSPROFILE%\*.dat /x >
[3 C:\Documents and Settings\All Users\*.tmp files -> C:\Documents and Settings\All Users\*.tmp -> ]
< %systemroot%\system32\drivers\*.rmv >
< dir /b "%systemroot%\system32\*.exe" | find /i " " /c >
< dir /b "%systemroot%\*.exe" | find /i " " /c >
< %PROGRAMFILES%\Microsoft\*.* >
< %systemroot%\System32\Wbem\proquota.exe >
< %PROGRAMFILES%\Mozilla Firefox\*.dat >
< %USERPROFILE%\Cookies\*.txt /x >
[2009/04/26 16:41:33 | 000,000,067 | -HS- | M] () -- C:\Documents and Settings\MARGIE\Cookies\desktop.ini
[2011/04/17 19:20:08 | 000,147,456 | -HS- | M] () -- C:\Documents and Settings\MARGIE\Cookies\index.dat
< %SystemRoot%\system32\fonts\*.* >
< %systemroot%\system32\winlog\*.* >
< %systemroot%\system32\Language\*.* >
< %systemroot%\system32\Settings\*.* >
< %systemroot%\system32\*.quo >
< %SYSTEMROOT%\AppPatch\*.exe >
< %SYSTEMROOT%\inf\*.exe >
[2007/06/26 23:10:26 | 000,317,440 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\inf\unregmp2.exe
< %SYSTEMROOT%\Installer\*.exe >
< %systemroot%\system32\config\*.bak2 >
< %systemroot%\system32\Computers\*.* >
< %SystemRoot%\system32\Sound\*.* >
< %SystemRoot%\system32\SpecialImg\*.* >
< %SystemRoot%\system32\code\*.* >
< %SystemRoot%\system32\draft\*.* >
< %SystemRoot%\system32\MSSSys\*.* >
< %ProgramFiles%\Javascript\*.* >
< %systemroot%\pchealth\helpctr\System\*.exe /s >
< %systemroot%\Web\*.exe >
< %systemroot%\system32\msn\*.* >
< %systemroot%\system32\*.tro >
< %AppData%\Microsoft\Installer\msupdates\*.* >
< %ProgramFiles%\Messenger\*.* >
[2008/04/13 19:11:51 | 000,033,792 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Messenger\custsat.dll
[2003/07/16 15:32:13 | 000,004,821 | ---- | M] () -- C:\Program Files\Messenger\logowin.gif
[2002/08/20 12:32:18 | 000,007,047 | ---- | M] () -- C:\Program Files\Messenger\lvback.gif
[2002/08/20 12:32:22 | 000,000,807 | ---- | M] () -- C:\Program Files\Messenger\mailtmpl.txt
[2008/05/02 09:01:49 | 000,083,968 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Messenger\msgsc.dll
[2008/04/13 12:30:28 | 000,180,224 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Messenger\msgslang.dll
[2008/04/13 19:12:28 | 001,695,232 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Messenger\msmsgs.exe
[2002/08/20 15:08:38 | 000,069,663 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Messenger\msmsgsin.exe
[2003/07/16 15:38:45 | 000,002,882 | ---- | M] () -- C:\Program Files\Messenger\newalert.wav
[2003/07/16 15:38:46 | 000,006,156 | ---- | M] () -- C:\Program Files\Messenger\newemail.wav
[2003/07/16 15:40:43 | 000,006,160 | ---- | M] () -- C:\Program Files\Messenger\online.wav
[2002/08/20 12:32:20 | 000,004,454 | ---- | M] () -- C:\Program Files\Messenger\type.wav
[2004/07/17 11:41:06 | 000,115,981 | ---- | M] () -- C:\Program Files\Messenger\xpmsgr.chm
< %systemroot%\system32\systhem32\*.* >
< %systemroot%\system\*.exe >
< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >
< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2011-04-14 08:08:22
< >
< End of report >
#13 Re: [RESOLVED] Programs missing
Posted 18 April 2011 - 12:33 AM
OTL by OldTimer - Version 3.2.22.3 Folder = C:\Documents and Settings\MARGIE\Desktop
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.11)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
1.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 57.00% Memory free
1.00 Gb Paging File | 1.00 Gb Available in Paging File | 65.00% Paging File free
Paging file location(s): C:\pagefile.sys 384 768 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 37.21 Gb Total Space | 17.12 Gb Free Space | 46.00% Space Free | Partition Type: NTFS
Unable to calculate disk information.
Computer Name: MARGIE-69SGZAZK | User Name: MARGIE | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
========== Extra Registry (SafeList) ==========
========== File Associations ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.cpl [@ = cplfile] -- rundll32.exe shell32.dll,Control_RunDLL "%1",%*
.html [@ = FirefoxHTML] -- C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
.url [@ = InternetShortcut] -- rundll32.exe ieframe.dll,OpenURL %l
[HKEY_USERS\S-1-5-21-2052111302-1284227242-725345543-1004\SOFTWARE\Classes\<extension>]
.bat [@ = batfile] -- Reg Error: Key error. File not found
.cmd [@ = cmdfile] -- Reg Error: Key error. File not found
.com [@ = ComFile] -- Reg Error: Key error. File not found
.exe [@ = exefile] -- Reg Error: Key error. File not found
.html [@ = FirefoxHTML] -- C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
.vbs [@ = VBSFile] -- Reg Error: Key error. File not found
========== Shell Spawning ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
cplfile [cplopen] -- rundll32.exe shell32.dll,Control_RunDLL "%1",%*
exefile [open] -- "%1" %*
https [open] -- "C:\Program Files\Mozilla Firefox\firefox.exe" -requestPending -osint -url "%1" (Mozilla Corporation)
InternetShortcut [open] -- rundll32.exe ieframe.dll,OpenURL %l
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] -- %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] -- %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
========== Security Center Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 0
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]
========== System Restore Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sr]
"Start" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SrService]
"Start" = 2
========== Firewall Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile]
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
"80:TCP" = 80:TCP:*:Enabled:Services
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DoNotAllowExceptions" = 0
"DisableNotifications" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008
"3724:TCP" = 3724:TCP:*:Enabled:Blizzard Downloader: 3724
========== Authorized Applications List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
"C:\Program Files\MSN Messenger\msncall.exe" = C:\Program Files\MSN Messenger\msncall.exe:*:Enabled:Windows Live Messenger 8.0 (Phone)
"C:\Program Files\MSN Messenger\msnmsgr.exe" = C:\Program Files\MSN Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger 8.1
"C:\Program Files\MSN Messenger\livecall.exe" = C:\Program Files\MSN Messenger\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone)
"C:\Program Files\Belkin\Router Setup and Monitor\BelkinSetup.exe" = C:\Program Files\Belkin\Router Setup and Monitor\BelkinSetup.exe:LocalSubNet:Enabled:Belkin Setup -- (Affinegy, Inc.)
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\WINDOWS\system32\lxcycoms.exe" = C:\WINDOWS\system32\lxcycoms.exe:*:Enabled:3400 Series Server -- ( )
"C:\Program Files\Belkin\Router Setup and Monitor\BelkinSetup.exe" = C:\Program Files\Belkin\Router Setup and Monitor\BelkinSetup.exe:LocalSubNet:Enabled:Belkin Setup -- (Affinegy, Inc.)
========== HKEY_LOCAL_MACHINE Uninstall List ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{048298C9-A4D3-490B-9FF9-AB023A9238F3}" = Steam
"{07287123-B8AC-41CE-8346-3D777245C35B}" = Bonjour
"{09DA4F91-2A09-4232-AB8C-6BC740096DE3}" = Sonic Update Manager
"{0D499481-22C6-4B25-8AC2-6D3F6C885FB9}" = OpenOffice.org Installer 1.0
"{1206EF92-2E83-4859-ACCB-2048C3CB7DA6}" = Sonic DLA
"{1D643CD7-4DD6-11D7-A4E0-000874180BB3}" = Microsoft Money 2004
"{26A24AE4-039D-4CA4-87B4-2F83216018FF}" = Java 6 Update 18
"{30C2FCD0-FF7B-4FFA-8DDE-43A22E01A1E7}" = Rhapsody Player Engine
"{33BEE6F3-9987-4F98-A069-97A64EC8321A}" = Microsoft Works Suite Add-in for Microsoft Word
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{65179FD8-04C0-40A7-87FC-007F2CD5BF1E}" = LogMeIn
"{6811CAA0-BF12-11D4-9EA1-0050BAE317E1}" = PowerDVD 5.1
"{6956856F-B6B3-4BE0-BA0B-8F495BE32033}" = Apple Software Update
"{774088D4-0777-4D78-904D-E435B318F5D2}" = Microsoft Antimalware
"{77A776C4-D10F-416D-88F0-53F2D9DCD9B3}" = Microsoft Security Client
"{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable
"{8C64E145-54BA-11D6-91B1-00500462BE80}" = Microsoft Money 2004 System Pack
"{90120000-0020-0409-0000-0000000FF1CE}" = Compatibility Pack for the 2007 Office system
"{911B0409-6000-11D3-8CFE-0050048383C9}" = Microsoft Word 2002
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{9541FED0-327F-4DF0-8B96-EF57EF622F19}" = Sonic RecordNow!
"{9580813D-94B1-4C28-9426-A441E2BB29A5}" = Counter-Strike: Source
"{A2BCA9F1-566C-4805-97D1-7FDC93386723}" = Adobe AIR
"{A6FDF86A-F541-4E7B-AEA0-8849A2A700D5}" = iTunes
"{A93944F2-D2D4-4750-BFE7-9A288FEAF2CF}" = Apple Application Support
"{AADEA55D-C834-4BCB-98A3-4B8D1C18F4EE}" = Apple Mobile Device Support
"{AC76BA86-7AD7-1033-7B44-A71000000002}" = Adobe Reader 7.1.0
"{B9966F27-9678-4620-9579-925E3084647E}" = Microsoft Works
"{BCE72AED-3332-4863-9567-C5DCB9052CA2}" = Netflix Movie Viewer
"{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}" = SUPERAntiSpyware Free Edition
"{D78653C3-A8FF-415F-92E6-D774E634FF2D}" = Dell ResourceCD
"{DB0BB9FA-1B60-4036-8E29-3D56D8085256}" = WOT for Internet Explorer
"{DBA8B9E1-C6FF-4624-9598-73D3B41A0903}" = Microsoft Picture It! Photo Premium 9
"{E031338C-839D-4EDD-9537-99B653C39D81}" = Autodesk MapGuide® Viewer ActiveX Control Release 6.5
"{E2883E8F-472F-4fb0-9522-AC9BF37916A7}" = Adobe Download Manager
"{EB900AF8-CC61-4E15-871B-98D1EA3E8025}" = QuickTime
"{F0A37341-D692-11D4-A984-009027EC0A9C}" = SoundMAX
"{F652D238-5F29-42D5-BAF3-0115EF977EC2}" = Windows Live Sign-in Assistant
"60A5FC6E548B5906438A6A163A886BAF2BE75AA9" = Windows Driver Package - MSN (usbccgp) USB (04/19/2006 1.1.0.2)
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Belkin Setup and Router Monitor_is1" = Belkin Setup and Router Monitor
"CCleaner" = CCleaner
"CNXT_MODEM_PCI_VEN_14F1&DEV_2F20&SUBSYS_200F14F1" = Conexant D850 56K V.9x DFVc Modem
"Coupon Printer for Windows5.0.0.0" = Coupon Printer for Windows
"GoogleVideoPlayer" = Google Video Player
"HijackThis" = HijackThis 2.0.2
"IDNMitigationAPIs" = Microsoft Internationalized Domain Names Mitigation APIs
"ie7" = Windows Internet Explorer 7
"Lexmark 3400 Series" = Lexmark 3400 Series
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"Microsoft Security Client" = Microsoft Security Essentials
"Mozilla Firefox 4.0 (x86 en-US)" = Mozilla Firefox 4.0 (x86 en-US)
"MSCompPackV1" = Microsoft Compression Client Pack 1.0 for Windows XP
"MSN Music Assistant" = MSN Music Assistant
"NLSDownlevelMapping" = Microsoft National Language Support Downlevel APIs
"PictureIt_v9" = Microsoft Picture It! Photo Premium 9
"PROSet" = Intel® PRO Network Adapters and Drivers
"Shockwave" = Shockwave
"Spybot - Search & Destroy_is1" = Spybot - Search & Destroy 1.4
"SpywareBlaster_is1" = SpywareBlaster v3.5.1
"Video Mover_is1" = Video Mover
"Windows Media Format Runtime" = Windows Media Format 11 runtime
"Windows Media Player" = Windows Media Player 11
"Windows XP Service Pack" = Windows XP Service Pack 3
"WMFDist11" = Windows Media Format 11 runtime
"wmp11" = Windows Media Player 11
"Works2004Setup" = Microsoft Works 2004 Setup Launcher
"Wudf01000" = Microsoft User-Mode Driver Framework Feature Pack 1.0
========== HKEY_USERS Uninstall List ==========
[HKEY_USERS\S-1-5-21-2052111302-1284227242-725345543-1004\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Move Networks Player - IE" = Move Networks Media Player for Internet Explorer
"Smilebox" = Smilebox
========== Last 10 Event Log Errors ==========
[ Application Events ]
Error - 1/4/2011 1:04:30 PM | Computer Name = MARGIE-69SGZAZK | Source = MPSampleSubmission | ID = 5000
Description = EventType mptelemetry, P1 8024402c, P2 endsearch, P3 search, P4 2.1.6805.0,
P5 mpsigdwn.dll, P6 2.1.6805.0, P7 microsoft antimalware (bcf43643-a118-4432-aede-d861fcbcfcde),
P8 NIL, P9 NIL, P10 NIL.
Error - 1/27/2011 12:42:36 AM | Computer Name = MARGIE-69SGZAZK | Source = MPSampleSubmission | ID = 5000
Description = EventType mptelemetry, P1 0x80070003, P2 moac, P3 cachereset, P4 3.0.8107.0,
P5 unspecified, P6 unspecified, P7 unspecified, P8 NIL, P9 NIL, P10 NIL.
Error - 1/30/2011 3:46:11 AM | Computer Name = MARGIE-69SGZAZK | Source = MPSampleSubmission | ID = 5000
Description = EventType mptelemetry, P1 0, P2 moaccapability, P3 3.0.8107.0, P4
0, P5 0, P6 unspecified, P7 unspecified, P8 NIL, P9 NIL, P10 NIL.
Error - 2/2/2011 3:26:11 PM | Computer Name = MARGIE-69SGZAZK | Source = MPSampleSubmission | ID = 5000
Description = EventType mptelemetry, P1 0x80070670, P2 patchapplication, P3 am bdd,
P4 10.3.1781.0, P5 mpsigstub.exe, P6 3.0.8107.0, P7 microsoft security essentials,
P8 NIL, P9 NIL, P10 NIL.
Error - 3/7/2011 10:26:50 PM | Computer Name = MARGIE-69SGZAZK | Source = MPSampleSubmission | ID = 5000
Description = EventType mptelemetry, P1 8024402c, P2 endsearch, P3 search, P4 3.0.8107.0,
P5 mpsigdwn.dll, P6 3.0.8107.0, P7 microsoft security essentials (edb4fa23-53b8-4afa-8c5d-99752cca7094),
P8 NIL, P9 NIL, P10 NIL.
Error - 3/22/2011 9:38:06 PM | Computer Name = MARGIE-69SGZAZK | Source = MPSampleSubmission | ID = 5000
Description = EventType mptelemetry, P1 8024402c, P2 endsearch, P3 search, P4 3.0.8107.0,
P5 mpsigdwn.dll, P6 3.0.8107.0, P7 microsoft security essentials (edb4fa23-53b8-4afa-8c5d-99752cca7094),
P8 NIL, P9 NIL, P10 NIL.
Error - 3/29/2011 11:05:21 AM | Computer Name = MARGIE-69SGZAZK | Source = MPSampleSubmission | ID = 5000
Description = EventType mptelemetry, P1 8024402c, P2 endsearch, P3 search, P4 3.0.8107.0,
P5 mpsigdwn.dll, P6 3.0.8107.0, P7 microsoft security essentials (edb4fa23-53b8-4afa-8c5d-99752cca7094),
P8 NIL, P9 NIL, P10 NIL.
Error - 4/9/2011 11:25:34 PM | Computer Name = MARGIE-69SGZAZK | Source = MPSampleSubmission | ID = 5000
Description = EventType mptelemetry, P1 8024402c, P2 endsearch, P3 search, P4 3.0.8107.0,
P5 mpsigdwn.dll, P6 3.0.8107.0, P7 microsoft security essentials (edb4fa23-53b8-4afa-8c5d-99752cca7094),
P8 NIL, P9 NIL, P10 NIL.
Error - 4/10/2011 3:17:39 AM | Computer Name = MARGIE-69SGZAZK | Source = MPSampleSubmission | ID = 5000
Description = EventType mptelemetry, P1 8024402c, P2 endsearch, P3 search, P4 3.0.8107.0,
P5 mpsigdwn.dll, P6 3.0.8107.0, P7 microsoft security essentials (edb4fa23-53b8-4afa-8c5d-99752cca7094),
P8 NIL, P9 NIL, P10 NIL.
Error - 4/17/2011 8:07:45 PM | Computer Name = MARGIE-69SGZAZK | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt>
with error: A connection with the server could not be established
[ System Events ]
Error - 4/17/2011 8:12:12 PM | Computer Name = MARGIE-69SGZAZK | Source = SideBySide | ID = 16842811
Description = Generate Activation Context failed for C:\Program Files\Belkin\Router
Setup and Monitor\imageformats\qjpeg4.dll. Reference error message: The operation
completed successfully. .
Error - 4/17/2011 8:12:13 PM | Computer Name = MARGIE-69SGZAZK | Source = SideBySide | ID = 16842784
Description = Dependent Assembly Microsoft.VC90.CRT could not be found and Last
Error was The referenced assembly is not installed on your system.
Error - 4/17/2011 8:12:13 PM | Computer Name = MARGIE-69SGZAZK | Source = SideBySide | ID = 16842811
Description = Resolve Partial Assembly failed for Microsoft.VC90.CRT. Reference error
message: The referenced assembly is not installed on your system. .
Error - 4/17/2011 8:12:13 PM | Computer Name = MARGIE-69SGZAZK | Source = SideBySide | ID = 16842811
Description = Generate Activation Context failed for C:\Program Files\Belkin\Router
Setup and Monitor\imageformats\qsvg4.dll. Reference error message: The operation
completed successfully. .
Error - 4/17/2011 8:12:15 PM | Computer Name = MARGIE-69SGZAZK | Source = SideBySide | ID = 16842784
Description = Dependent Assembly Microsoft.VC90.CRT could not be found and Last
Error was The referenced assembly is not installed on your system.
Error - 4/17/2011 8:12:15 PM | Computer Name = MARGIE-69SGZAZK | Source = SideBySide | ID = 16842811
Description = Resolve Partial Assembly failed for Microsoft.VC90.CRT. Reference error
message: The referenced assembly is not installed on your system. .
Error - 4/17/2011 8:12:15 PM | Computer Name = MARGIE-69SGZAZK | Source = SideBySide | ID = 16842811
Description = Generate Activation Context failed for C:\Program Files\Belkin\Router
Setup and Monitor\imageformats\qjpeg4.dll. Reference error message: The operation
completed successfully. .
Error - 4/17/2011 8:12:15 PM | Computer Name = MARGIE-69SGZAZK | Source = SideBySide | ID = 16842784
Description = Dependent Assembly Microsoft.VC90.CRT could not be found and Last
Error was The referenced assembly is not installed on your system.
Error - 4/17/2011 8:12:15 PM | Computer Name = MARGIE-69SGZAZK | Source = SideBySide | ID = 16842811
Description = Resolve Partial Assembly failed for Microsoft.VC90.CRT. Reference error
message: The referenced assembly is not installed on your system. .
Error - 4/17/2011 8:12:15 PM | Computer Name = MARGIE-69SGZAZK | Source = SideBySide | ID = 16842811
Description = Generate Activation Context failed for C:\Program Files\Belkin\Router
Setup and Monitor\imageformats\qsvg4.dll. Reference error message: The operation
completed successfully. .
< End of report >
#14 Re: [RESOLVED] Programs missing
Posted 18 April 2011 - 12:42 AM
Note 1: UNCHECK any pre-checked toolbar and/or software offered with the Java update. The pre-checked toolbars/software are not part of the Java update.
Note 2: The Java Quick Starter (JQS.exe) adds a service to improve the initial startup time of Java applets and applications. If you don't want to run another extra service, go to Start > Control Panel > Java > Advanced > Miscellaneous and uncheck the box for Java Quick Starter. Click OK and restart your computer.
2. Now, we need to remove old Java version and its remnants...
Download JavaRa to your desktop and unzip it to its own folder
- Run JavaRa.exe (Vista users! Right click on JavaRa.exe, click Run As Administrator), pick the language of your choice and click Select. Then click Remove Older Versions.
- Accept any prompts.
==============================================================================================
Run OTL
- Under the Custom Scans/Fixes box at the bottom, paste in the following
:OTL SRV - File not found [On_Demand | Stopped] -- -- (usnsvc) FF - prefs.js..extensions.enabledItems: avg@igeared:3.011.025.005 FF - HKLM\software\mozilla\Firefox\extensions\\avg@igeared: C:\Program Files\AVG\AVG9\Toolbar\Firefox\avg@igeared [2010/03/21 18:54:03 | 000,000,000 | ---D | M] O2 - BHO: (no name) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - No CLSID value found. O2 - BHO: (Google Dictionary Compression sdch) - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - File not found O3 - HKU\.DEFAULT\..\Toolbar\WebBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No CLSID value found. O3 - HKU\S-1-5-18\..\Toolbar\WebBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No CLSID value found. O3 - HKU\S-1-5-21-2052111302-1284227242-725345543-1004\..\Toolbar\WebBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No CLSID value found. O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - Reg Error: Key error. File not found [3 C:\Documents and Settings\All Users\*.tmp files -> C:\Documents and Settings\All Users\*.tmp -> ] [2011/04/17 15:13:27 | 000,000,160 | ---- | M] () -- C:\Documents and Settings\All Users\Application Data\~19783476r [2011/04/17 15:13:27 | 000,000,120 | ---- | M] () -- C:\Documents and Settings\All Users\Application Data\~19783476 [2011/04/16 09:37:33 | 000,000,344 | ---- | M] () -- C:\Documents and Settings\All Users\Application Data\19783476 [2010/03/21 18:53:59 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\AVG Security Toolbar [2009/12/17 04:31:24 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\avg7 [2010/03/21 19:10:04 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\avg9 [2009/12/17 04:31:30 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Hayden\Application Data\AVG7 [2009/12/17 04:31:30 | 000,000,000 | ---D | M] -- C:\Documents and Settings\LocalService\Application Data\AVG7 [2009/12/17 04:31:30 | 000,000,000 | ---D | M] -- C:\Documents and Settings\MARGIE\Application Data\AVG7 [2006/05/15 08:00:07 | 012,286,415 | ---- | M] () -- C:\AVG7QT.DAT :Commands [purity] [emptytemp] [emptyflash] [Reboot] - Then click the Run Fix button at the top
- Let the program run unhindered, reboot the PC when it is done
- You will get a log that shows the results of the fix. Please post it.
====================================================================================
Last scans....
1. Download Security Check from HERE, and save it to your Desktop.
- Double-click SecurityCheck.exe
- Follow the onscreen instructions inside of the black box.
- A Notepad document should open automatically called checkup.txt; please post the contents of that document.
NOTE SecurityCheck may produce some false warning(s), so leave the results reading to me.
2. Download Temp File Cleaner (TFC)
- Double click on TFC.exe to run the program.
- Click on Start button to begin cleaning process.
- TFC will close all running programs, and it may ask you to restart computer.
3. Please run a free online scan with the ESET Online Scanner
- Disable your antivirus program
- Tick the box next to YES, I accept the Terms of Use
- Click Start
- IMPORTANT! UN-check Remove found threats
- Accept any security warnings from your browser.
- Check Scan archives
- Click Start
- ESET will then download updates for itself, install itself, and begin scanning your computer. Please be patient as this can take some time.
- When the scan completes, push List of found threats
- Click on Export to text file , and save the file to your desktop using a unique name, such as ESETScan. Include the contents of this report in your next reply.
- NOTE. If Eset won't find any threats, it won't produce any log.
#15 Re: [RESOLVED] Programs missing
Posted 18 April 2011 - 12:54 AM
========== OTL ==========
Service usnsvc stopped successfully!
Service usnsvc deleted successfully!
Prefs.js: avg@igeared:3.011.025.005 removed from extensions.enabledItems
Registry value HKEY_LOCAL_MACHINE\software\mozilla\Firefox\extensions\\avg@igeared deleted successfully.
C:\Program Files\AVG\AVG9\Toolbar\Firefox\avg@igeared\ch_48\chrome\skin folder moved successfully.
C:\Program Files\AVG\AVG9\Toolbar\Firefox\avg@igeared\ch_48\chrome\content\Languages folder moved successfully.
C:\Program Files\AVG\AVG9\Toolbar\Firefox\avg@igeared\ch_48\chrome\content\html folder moved successfully.
C:\Program Files\AVG\AVG9\Toolbar\Firefox\avg@igeared\ch_48\chrome\content folder moved successfully.
C:\Program Files\AVG\AVG9\Toolbar\Firefox\avg@igeared\ch_48\chrome folder moved successfully.
C:\Program Files\AVG\AVG9\Toolbar\Firefox\avg@igeared\ch_48 folder moved successfully.
C:\Program Files\AVG\AVG9\Toolbar\Firefox\avg@igeared\ch_40\chrome\skin folder moved successfully.
C:\Program Files\AVG\AVG9\Toolbar\Firefox\avg@igeared\ch_40\chrome\content\Languages folder moved successfully.
C:\Program Files\AVG\AVG9\Toolbar\Firefox\avg@igeared\ch_40\chrome\content\html folder moved successfully.
C:\Program Files\AVG\AVG9\Toolbar\Firefox\avg@igeared\ch_40\chrome\content folder moved successfully.
C:\Program Files\AVG\AVG9\Toolbar\Firefox\avg@igeared\ch_40\chrome folder moved successfully.
C:\Program Files\AVG\AVG9\Toolbar\Firefox\avg@igeared\ch_40 folder moved successfully.
C:\Program Files\AVG\AVG9\Toolbar\Firefox\avg@igeared\ch_39\chrome\skin folder moved successfully.
C:\Program Files\AVG\AVG9\Toolbar\Firefox\avg@igeared\ch_39\chrome\content\Languages folder moved successfully.
C:\Program Files\AVG\AVG9\Toolbar\Firefox\avg@igeared\ch_39\chrome\content\html folder moved successfully.
C:\Program Files\AVG\AVG9\Toolbar\Firefox\avg@igeared\ch_39\chrome\content folder moved successfully.
C:\Program Files\AVG\AVG9\Toolbar\Firefox\avg@igeared\ch_39\chrome folder moved successfully.
C:\Program Files\AVG\AVG9\Toolbar\Firefox\avg@igeared\ch_39 folder moved successfully.
C:\Program Files\AVG\AVG9\Toolbar\Firefox\avg@igeared\ch_23\chrome\skin folder moved successfully.
C:\Program Files\AVG\AVG9\Toolbar\Firefox\avg@igeared\ch_23\chrome\content\Languages folder moved successfully.
C:\Program Files\AVG\AVG9\Toolbar\Firefox\avg@igeared\ch_23\chrome\content\html folder moved successfully.
C:\Program Files\AVG\AVG9\Toolbar\Firefox\avg@igeared\ch_23\chrome\content folder moved successfully.
C:\Program Files\AVG\AVG9\Toolbar\Firefox\avg@igeared\ch_23\chrome folder moved successfully.
C:\Program Files\AVG\AVG9\Toolbar\Firefox\avg@igeared\ch_23 folder moved successfully.
C:\Program Files\AVG\AVG9\Toolbar\Firefox\avg@igeared folder moved successfully.
Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0}\ not found.
Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{C84D72FE-E17D-4195-BB24-76C02E2E7C4E}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{C84D72FE-E17D-4195-BB24-76C02E2E7C4E}\ deleted successfully.
Registry value HKEY_USERS\.DEFAULT\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{2318C2B1-4965-11D4-9B18-009027A5CD4F} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{2318C2B1-4965-11D4-9B18-009027A5CD4F}\ not found.
Registry value HKEY_USERS\S-1-5-18\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{2318C2B1-4965-11D4-9B18-009027A5CD4F} not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{2318C2B1-4965-11D4-9B18-009027A5CD4F}\ not found.
Registry value HKEY_USERS\S-1-5-21-2052111302-1284227242-725345543-1004\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{2318C2B1-4965-11D4-9B18-009027A5CD4F} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{2318C2B1-4965-11D4-9B18-009027A5CD4F}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\linkscanner\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{F274614C-63F8-47D5-A4D1-FBDDE494F8D1}\ not found.
File {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - Reg Error: Key error. File not found not found.
C:\Documents and Settings\All Users\SPL148.tmp deleted successfully.
C:\Documents and Settings\All Users\SPL82.tmp deleted successfully.
C:\Documents and Settings\All Users\SPL9B.tmp deleted successfully.
C:\Documents and Settings\All Users\Application Data\~19783476r moved successfully.
C:\Documents and Settings\All Users\Application Data\~19783476 moved successfully.
C:\Documents and Settings\All Users\Application Data\19783476 moved successfully.
C:\Documents and Settings\All Users\Application Data\AVG Security Toolbar\cache folder moved successfully.
C:\Documents and Settings\All Users\Application Data\AVG Security Toolbar folder moved successfully.
C:\Documents and Settings\All Users\Application Data\avg7\QUEUE\TEMP folder moved successfully.
C:\Documents and Settings\All Users\Application Data\avg7\QUEUE\OUT folder moved successfully.
C:\Documents and Settings\All Users\Application Data\avg7\QUEUE\ACTIVE folder moved successfully.
C:\Documents and Settings\All Users\Application Data\avg7\QUEUE folder moved successfully.
C:\Documents and Settings\All Users\Application Data\avg7\Log folder moved successfully.
C:\Documents and Settings\All Users\Application Data\avg7 folder moved successfully.
C:\Documents and Settings\All Users\Application Data\avg9\update\prepare\temp folder moved successfully.
C:\Documents and Settings\All Users\Application Data\avg9\update\prepare folder moved successfully.
C:\Documents and Settings\All Users\Application Data\avg9\update folder moved successfully.
C:\Documents and Settings\All Users\Application Data\avg9\Chjw\7c88e68688e63e70 folder moved successfully.
C:\Documents and Settings\All Users\Application Data\avg9\Chjw folder moved successfully.
C:\Documents and Settings\All Users\Application Data\avg9 folder moved successfully.
C:\Documents and Settings\Hayden\Application Data\AVG7 folder moved successfully.
C:\Documents and Settings\LocalService\Application Data\AVG7 folder moved successfully.
C:\Documents and Settings\MARGIE\Application Data\AVG7 folder moved successfully.
C:\AVG7QT.DAT moved successfully.
========== COMMANDS ==========
[EMPTYTEMP]
User: All Users
User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
User: Hayden
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 67 bytes
->Java cache emptied: 1707087 bytes
->FireFox cache emptied: 226493073 bytes
->Flash cache emptied: 152637 bytes
User: LocalService
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 32835 bytes
User: LogMeInRemoteUser
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
User: MARGIE
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 4133491 bytes
->Java cache emptied: 0 bytes
->FireFox cache emptied: 51766138 bytes
->Flash cache emptied: 15832 bytes
User: NetworkService
->Temp folder emptied: 2302 bytes
->Temporary Internet Files folder emptied: 32835 bytes
%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32\dllcache .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 1610 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 0 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 0 bytes
RecycleBin emptied: 0 bytes
Total Files Cleaned = 271.00 mb
[EMPTYFLASH]
User: All Users
User: Default User
User: Hayden
->Flash cache emptied: 0 bytes
User: LocalService
User: LogMeInRemoteUser
User: MARGIE
->Flash cache emptied: 0 bytes
User: NetworkService
Total Flash Files Cleaned = 0.00 mb
OTL by OldTimer - Version 3.2.22.3 log created on 04172011_194430
Files\Folders moved on Reboot...
C:\Documents and Settings\MARGIE\Local Settings\Temporary Internet Files\Content.IE5\TI1JZWD5\page__gopid__165019[1].htm moved successfully.
C:\Documents and Settings\MARGIE\Local Settings\Temporary Internet Files\AntiPhishing\A0AB7674-8D67-4F4D-B5E1-96FAEADFB79D.dat moved successfully.
Registry entries deleted on Reboot...
#16 Re: [RESOLVED] Programs missing
Posted 18 April 2011 - 01:24 AM
Results of screen317's Security Check version 0.99.7
Windows XP Service Pack 3
Internet Explorer 7 Out of date!
``````````````````````````````
Antivirus/Firewall Check:
Windows Firewall Enabled!
ESET Online Scanner v3
Microsoft Security Essentials
```````````````````````````````
Anti-malware/Other Utilities Check:
Out of date Spybot installed!
Malwarebytes' Anti-Malware
HijackThis 2.0.2
CCleaner
Java 6 Update 18
Out of date Java installed!
Adobe Flash Player 10.1.85.3
Adobe Reader 7.1.0
Out of date Adobe Reader installed!
Mozilla Firefox (x86 en-US..) Firefox Out of Date!
````````````````````````````````
Process Check:
objlist.exe by Laurent
Windows Defender MSMpEng.exe
Microsoft Security Essentials msseces.exe
ESET ESET Online Scanner OnlineCmdLineScanner.exe
Microsoft Security Client Antimalware MsMpEng.exe
``````````End of Log````````````
#17 Re: [RESOLVED] Programs missing
Posted 18 April 2011 - 01:28 AM
You can download it from http://www.adobe.com.../readstep2.html
After installing the latest Adobe Reader, uninstall all previous versions.
Note. If you already have Adobe Photoshop® Album Starter Edition installed or do not wish to have it installed UNcheck the box which says Also Download Adobe Photoshop® Album Starter Edition.
Alternatively, you can uninstall Adobe Reader (33.5 MB), download and install Foxit PDF Reader(3.5MB) from HERE.
It's a much smaller file to download and uses a lot less resources than Adobe Reader.
Note: When installing FoxitReader, make sure to UN-check any pre-checked toolbar, or other garbage.
#18 Re: [RESOLVED] Programs missing
Posted 18 April 2011 - 01:58 AM
C:\System Volume Information\_restore{7956E894-DF3B-4211-9ED9-EB3174EAA0D2}\RP494\A0075981.exe a variant of Win32/Kryptik.MSA trojan
#19 Re: [RESOLVED] Programs missing
Posted 18 April 2011 - 02:00 AM
Your computer is clean

1. We need to reset system restore to prevent your computer from being accidentally reinfected by using some old restore point(s). We'll create fresh, clean restore point, using following OTL script:
Run OTL
- Under the Custom Scans/Fixes box at the bottom, paste in the following:
:OTL :Commands [purity] [emptytemp] [EMPTYFLASH] [CLEARALLRESTOREPOINTS] [Reboot]
- Then click the Run Fix button at the top
- Let the program run unhindered, reboot the PC when it is done
- Post resulting log.
2. Now, we'll remove all tools, we used during our cleaning process
Clean up with OTL:
- Double-click OTL.exe to start the program.
- Close all other programs apart from OTL as this step will require a reboot
- On the OTL main screen, press the CLEANUP button
- Say Yes to the prompt and then allow the program to reboot your computer.
If you still have any tools or logs leftover on your computer you can go ahead and delete those off of your computer now.
3. Make sure, Windows Updates are current.
4. If any Trojan was listed among your infection(s), make sure, you change all of your on-line important passwords (bank account(s), secured web sites, etc.) immediately!
5. Download, and install WOT (Web OF Trust): http://www.mywot.com/. It'll warn you (in most cases) about dangerous web sites.
6. Run Malwarebytes "Quick scan" once in a while to assure safety of your computer.
7. Run Temporary File Cleaner (TFC) weekly.
8. Download and install Secunia Personal Software Inspector (PSI): http://secunia.com/v...ning/personal/. The Secunia PSI is a FREE security tool designed to detect vulnerable and out-dated programs and plug-ins which expose your PC to attacks. Run it weekly.
9. (optional) If you want to keep all your programs up to date, download and install FileHippo Update Checker.
The Update Checker will scan your computer for installed software, check the versions and then send this information to FileHippo.com to see if there are any newer releases.
10. Run defrag at your convenience.
11. Read How did I get infected?, With steps so it does not happen again!: http://www.bleepingc.../topic2520.html
12. Please, let me know, how your computer is doing.
#20 Re: [RESOLVED] Programs missing
Posted 18 April 2011 - 02:21 AM
========== OTL ==========
========== COMMANDS ==========
[EMPTYTEMP]
User: All Users
User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
User: Hayden
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Java cache emptied: 0 bytes
->FireFox cache emptied: 0 bytes
->Flash cache emptied: 0 bytes
User: LocalService
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes
User: LogMeInRemoteUser
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
User: MARGIE
->Temp folder emptied: 182117 bytes
->Temporary Internet Files folder emptied: 7760582 bytes
->Java cache emptied: 0 bytes
->FireFox cache emptied: 0 bytes
->Flash cache emptied: 0 bytes
User: NetworkService
->Temp folder emptied: 2384 bytes
->Temporary Internet Files folder emptied: 33170 bytes
%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32\dllcache .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 2274 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 0 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 0 bytes
RecycleBin emptied: 0 bytes
Total Files Cleaned = 8.00 mb
[EMPTYFLASH]
User: All Users
User: Default User
User: Hayden
->Flash cache emptied: 0 bytes
User: LocalService
User: LogMeInRemoteUser
User: MARGIE
->Flash cache emptied: 0 bytes
User: NetworkService
Total Flash Files Cleaned = 0.00 mb
Restore points cleared and new OTL Restore Point set!
OTL by OldTimer - Version 3.2.22.3 log created on 04172011_210209
Files\Folders moved on Reboot...
C:\Documents and Settings\MARGIE\Local Settings\Temporary Internet Files\Content.IE5\RBK92BN1\45303-programs-missing[1].htm moved successfully.
C:\Documents and Settings\MARGIE\Local Settings\Temporary Internet Files\AntiPhishing\A0AB7674-8D67-4F4D-B5E1-96FAEADFB79D.dat moved successfully.
Registry entries deleted on Reboot...
1 user(s) are reading this topic
0 members, 1 guests, 0 anonymous users















