Recommended for You:
Fix up your PC Fast

TuneUp Utilities 2012 takes out the trash: Get back long lost disk space and performance in a snap – Free Download!






You are not connected. Please login or register

Goto page : 1, 2  Next

View previous topic View next topic Go down  Message [Page 1 of 2]

1 WhiteSmoke MBAM Logs on Wed Jun 08, 2011 11:11 pm

dr09294


Member
Member
Malwarebytes' Anti-Malware 1.50.1.1100
www.malwarebytes.org

Database version: 6814

Windows 5.1.2600 Service Pack 3
Internet Explorer 8.0.6001.18702

6/8/2011 9:26:57 PM
mbam-log-2011-06-08 (21-26-57).txt

Scan type: Quick scan
Objects scanned: 162752
Time elapsed: 10 minute(s), 41 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 2
Registry Keys Infected: 156
Registry Values Infected: 13
Registry Data Items Infected: 1
Folders Infected: 27
Files Infected: 111

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
d:\program files\mywebsearch\bar\1.bin\MWSSRCAS.DLL (Adware.MyWebSearch) -> Delete on reboot.
d:\program files\mywebsearch\bar\1.bin\MWSBAR.DLL (Adware.MyWebSearch) -> Delete on reboot.

Registry Keys Infected:
HKEY_CLASSES_ROOT\CLSID\{00A6FAF1-072E-44cf-8957-5838F569A31D} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{00A6FAF1-072E-44CF-8957-5838F569A31D} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{00A6FAF1-072E-44CF-8957-5838F569A31D} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{00A6FAF1-072E-44CF-8957-5838F569A31D} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{07B18EA1-A523-4961-B6BB-170DE4475CCA} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{07B18EA1-A523-4961-B6BB-170DE4475CCA} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{07B18EA1-A523-4961-B6BB-170DE4475CCA} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{07B18EA1-A523-4961-B6BB-170DE4475CCA} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\TypeLib\{07B18EA0-A523-4961-B6BB-170DE4475CCA} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{07B18EAA-A523-4961-B6BB-170DE4475CCA} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\MyWebSearch bar Uninstall (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\MyWebSearchService (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\AppID\{0D82ACD6-A652-4496-A298-2BDE705F4227} (Adware.ClickPotato) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\AppID\{7025E484-D4B0-441a-9F0B-69063BD679CE} (Adware.ClickPotato) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\AppID\{8258B35C-05B8-4c0e-9525-9BCCC70F8F2D} (Adware.ClickPotato) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\AppID\{A89256AD-EC17-4a83-BEF5-4B8BC4F39306} (Adware.ClickPotato) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{00A6FAF6-072E-44cf-8957-5838F569A31D} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{07B18EA9-A523-4961-B6BB-170DE4475CCA} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{07B18EA9-A523-4961-B6BB-170DE4475CCA} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{07B18EA9-A523-4961-B6BB-170DE4475CCA} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{07B18EAB-A523-4961-B6BB-170DE4475CCA} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\MyWebSearchToolBar.SettingsPlugin.1 (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\MyWebSearchToolBar.SettingsPlugin (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{07B18EAB-A523-4961-B6BB-170DE4475CCA} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{07B18EAB-A523-4961-B6BB-170DE4475CCA} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{0F8ECF4F-3646-4C3A-8881-8E138FFCAF70} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\TypeLib\{8CA01F0E-987C-49C3-B852-2F1AC4A7094C} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{1093995A-BA37-41D2-836E-091067C4AD17} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\FunWebProducts.IECookiesManager.1 (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\FunWebProducts.IECookiesManager (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{147A976F-EEE1-4377-8EA7-4716E4CDD239} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{1D4DB7D2-6EC9-47a3-BD87-1E41684E07BB} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\TypeLib\{1D4DB7D0-6EC9-47a3-BD87-1E41684E07BB} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{1D4DB7D1-6EC9-47A3-BD87-1E41684E07BB} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\FunWebProductsInstaller.Start.1 (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\FunWebProductsInstaller.Start (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{1E0DE227-5CE4-4ea3-AB0C-8B03E1AA76BC} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{25560540-9571-4D7B-9389-0F166788785A} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\TypeLib\{C8CECDE3-1AE1-4C4A-AD82-6D5B00212144} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{17DE5E5E-BFE3-4E83-8E1F-8755795359EC} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\FunWebProducts.DataControl.1 (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\FunWebProducts.DataControl (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{25560540-9571-4D7B-9389-0F166788785A} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{3DC201FB-E9C9-499C-A11F-23C360D7C3F8} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\TypeLib\{E47CAEE0-DEEA-464A-9326-3F2801535A4D} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{3E1656ED-F60E-4597-B6AA-B6A58E171495} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\FunWebProducts.HTMLMenu.2 (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\FunWebProducts.HTMLMenu (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{3DC201FB-E9C9-499C-A11F-23C360D7C3F8} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{3E720452-B472-4954-B7AA-33069EB53906} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\TypeLib\{3E720450-B472-4954-B7AA-33069EB53906} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{3E720451-B472-4954-B7AA-33069EB53906} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\MyWebSearch.HTMLPanel.1 (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\MyWebSearch.HTMLPanel (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{3E720452-B472-4954-B7AA-33069EB53906} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{53CED2D0-5E9A-4761-9005-648404E6F7E5} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\MyWebSearchToolBar.ToolbarPlugin.1 (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\MyWebSearchToolBar.ToolbarPlugin (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{63D0ED2C-B45B-4458-8B3B-60C69BBBD83C} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\TypeLib\{8E6F1830-9607-4440-8530-13BE7C4B1D14} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{63D0ED2B-B45B-4458-8B3B-60C69BBBD83C} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\FunWebProducts.PopSwatterSettingsControl.1 (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\FunWebProducts.PopSwatterSettingsControl (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{63D0ED2C-B45B-4458-8B3B-60C69BBBD83C} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{7473D292-B7BB-4f24-AE82-7E2CE94BB6A9} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\TypeLib\{7473D290-B7BB-4F24-AE82-7E2CE94BB6A9} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{7473D291-B7BB-4F24-AE82-7E2CE94BB6A9} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{7473D294-B7BB-4f24-AE82-7E2CE94BB6A9} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\MyWebSearch.PseudoTransparentPlugin.1 (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\MyWebSearch.PseudoTransparentPlugin (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{7473D294-B7BB-4F24-AE82-7E2CE94BB6A9} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{7473D296-B7BB-4f24-AE82-7E2CE94BB6A9} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{84DA4FDF-A1CF-4195-8688-3E961F505983} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{8E6F1832-9607-4440-8530-13BE7C4B1D14} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\FunWebProducts.PopSwatterBarButton.1 (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\FunWebProducts.PopSwatterBarButton (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{938AA51A-996C-4884-98CE-80DD16A5C9DA} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\TypeLib\{29D67D3C-509A-4544-903F-C8C1B8236554} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{2E3537FC-CF2F-4F56-AF54-5A6A3DD375CC} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{98D9753D-D73B-42D5-8C85-4469CDA897AB} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\FunWebProducts.HTMLMenu.1 (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{98D9753D-D73B-42D5-8C85-4469CDA897AB} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{9FF05104-B030-46FC-94B8-81276E4E27DF} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\ScreenSaverControl.ScreenSaverInstaller.1 (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\ScreenSaverControl.ScreenSaverInstaller (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{9FF05104-B030-46FC-94B8-81276E4E27DF} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{A4730EBE-43A6-443e-9776-36915D323AD3} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{A9571378-68A1-443d-B082-284F960C6D17} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{ADB01E81-3C79-4272-A0F1-7B2BE7A782DC} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\MyWebSearch.OutlookAddin.1 (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\MyWebSearch.OutlookAddin (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{B813095C-81C0-4E40-AA14-67520372B987} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\FunWebProducts.KillerObjManager.1 (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\FunWebProducts.KillerObjManager (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{C9D7BE3E-141A-4C85-8CD6-32461F3DF2C7} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\FunWebProducts.HistoryKillerScheduler.1 (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\FunWebProducts.HistoryKillerScheduler (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{CFF4CE82-3AA2-451F-9B77-7165605FB835} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\FunWebProducts.HistorySwatterControlBar.1 (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\FunWebProducts.HistorySwatterControlBar (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{D9FFFB27-D62A-4D64-8CEC-1FF006528805} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\TypeLib\{0D26BC71-A633-4E71-AD31-EADC3A1B6A3A} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{E342AF55-B78A-4CD0-A2BB-DA7F52D9D25E} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{E79DFBCA-5697-4fbd-94E5-5B2A9C7C1612} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\TypeLib\{E79DFBC0-5697-4FBD-94E5-5B2A9C7C1612} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{72EE7F04-15BD-4845-A005-D6711144D86A} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\MyWebSearch.ChatSessionPlugin.1 (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\MyWebSearch.ChatSessionPlugin (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{E79DFBCA-5697-4FBD-94E5-5B2A9C7C1612} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Typelib\{D518921A-4A03-425E-9873-B9A71756821E} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{CF54BE1C-9359-4395-8533-1657CF209CFE} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Typelib\{F42228FB-E84E-479E-B922-FBBD096E792C} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{6E74766C-4D93-4CC0-96D1-47B8E07FF9CA} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{56256A51-B582-467e-B8D4-7786EDA79AE0} (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{56256A51-B582-467e-B8D4-7786EDA79AE0} (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{100EB1FD-D03E-47FD-81F3-EE91287F9465} (Adware.ShopperReports) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{AEB04B5E-C981-47a9-B847-33EE4C92F6B9} (PUP.Magoo) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{AEB04B5E-C981-47a9-B847-33EE4C92F6B9} (PUP.Magoo) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{02F0243C-2E71-4A1A-A790-6C30888119D0} (PUP.Magoo) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{A7CDDCDC-BEEB-4685-A062-978F5E07CEEE} (Adware.ShopperReports) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{59C7FC09-1C83-4648-B3E6-003D2BBC7481} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{68AF847F-6E91-45dd-9B68-D6A12C30E5D7} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{9170B96C-28D4-4626-8358-27E6CAEEF907} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{D1A71FA0-FF48-48dd-9B6D-7A13A3E42127} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{DDB1968E-EAD6-40fd-8DAE-FF14757F60C7} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{F138D901-86F0-4383-99B6-9CDD406036DA} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\MyWebSearch.MultipleButton (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\MyWebSearch.MultipleButton.1 (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\MyWebSearch.ThirdPartyInstaller (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\MyWebSearch.ThirdPartyInstaller.1 (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\MyWebSearch.UrlAlertButton (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\MyWebSearch.UrlAlertButton.1 (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\ShopperReports.Reporter (Adware.ShopperReports) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\ShopperReports.Reporter.1 (Adware.ShopperReports) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\MyWebSearch (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\FocusInteractive (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Fun Web Products (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\FunWebProducts (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\MyWebSearch (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\QueryExplorer (Adware.QueryExplorer) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\RunDll32Policy\f3ScrCtr.dll (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Multimedia\WMPlayer\Schemes\f3pss (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Outlook\Addins\MyWebSearch.OutlookAddin (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Word\Addins\MyWebSearch.OutlookAddin (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\QueryExplorer (Adware.QueryExplorer) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_QUERYEXPLORER_SERVICE (Adware.QueryExplorer) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{819FFE22-35C7-4925-8CDA-4E0E2DB94302} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\TypeLib\{819FFE20-35C7-4925-8CDA-4E0E2DB94302} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{819FFE21-35C7-4925-8CDA-4E0E2DB94302} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{08858AF6-42AD-4914-95D2-AC3AB0DC8E28} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\TypeLib\{8FFDF636-0D87-4B33-B9E9-79A53F6E1DAE} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{01947140-417F-46B6-8751-A3A2B8345E1A} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{08858AF6-42AD-4914-95D2-AC3AB0DC8E28} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{799391D3-EB86-4bac-9BD3-CBFEA58A0E15} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{D858DAFC-9573-4811-B323-7011A3AA7E61} (Adware.MyWebSearch) -> Quarantined and deleted successfully.

Registry Values Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\MyWebSearch Email Plugin (Adware.MyWebSearch) -> Value: MyWebSearch Email Plugin -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\MyWebSearch Email Plugin (Adware.MyWebSearch) -> Value: MyWebSearch Email Plugin -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\My Web Search Bar Search Scope Monitor (Adware.MyWebSearch) -> Value: My Web Search Bar Search Scope Monitor -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks\{00A6FAF6-072E-44CF-8957-5838F569A31D} (Adware.MyWebSearch) -> Value: {00A6FAF6-072E-44CF-8957-5838F569A31D} -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Toolbar\WebBrowser\{07B18EA9-A523-4961-B6BB-170DE4475CCA} (Adware.MyWebSearch) -> Value: {07B18EA9-A523-4961-B6BB-170DE4475CCA} -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar\{07B18EA9-A523-4961-B6BB-170DE4475CCA} (Adware.MyWebSearch) -> Value: {07B18EA9-A523-4961-B6BB-170DE4475CCA} -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Toolbar\WebBrowser\{07B18EA9-A523-4961-B6BB-170DE4475CCA} (Adware.MyWebSearch) -> Value: {07B18EA9-A523-4961-B6BB-170DE4475CCA} -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks\{00A6FAF6-072E-44cf-8957-5838F569A31D} (Adware.MyWebSearch) -> Value: {00A6FAF6-072E-44cf-8957-5838F569A31D} -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar\{07B18EA9-A523-4961-B6BB-170DE4475CCA} (Adware.MyWebSearch) -> Value: {07B18EA9-A523-4961-B6BB-170DE4475CCA} -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\MenuExt\&Search\(default) (Adware.Hotbar) -> Value: (default) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Media\WMSDK\Sources\f3PopularScreensavers (Adware.MyWebSearch) -> Value: f3PopularScreensavers -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\User Agent\Post Platform\SRS_IT_E8790571BD765B5133A194 (Malware.Trace) -> Value: SRS_IT_E8790571BD765B5133A194 -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent\Post Platform\FunWebProducts (Adware.MyWebSearch) -> Value: FunWebProducts -> Quarantined and deleted successfully.

Registry Data Items Infected:
HKEY_CLASSES_ROOT\regfile\shell\open\command\(default) (Broken.OpenCommand) -> Bad: ("regedit.exe" "%1") Good: (regedit.exe "%1") -> Quarantined and deleted successfully.

Folders Infected:
d:\documents and settings\all users\application data\queryexplorer (Adware.QueryExplorer) -> Quarantined and deleted successfully.
d:\program files\funwebproducts (Adware.MyWebSearch) -> Quarantined and deleted successfully.
d:\program files\funwebproducts\Installr (Adware.MyWebSearch) -> Quarantined and deleted successfully.
d:\program files\funwebproducts\Installr\1.bin (Adware.MyWebSearch) -> Quarantined and deleted successfully.
d:\program files\funwebproducts\screensaver (Adware.MyWebSearch) -> Quarantined and deleted successfully.
d:\program files\funwebproducts\screensaver\Images (Adware.MyWebSearch) -> Quarantined and deleted successfully.
d:\program files\funwebproducts\Shared (Adware.MyWebSearch) -> Quarantined and deleted successfully.
d:\program files\funwebproducts\Shared\Cache (Adware.MyWebSearch) -> Quarantined and deleted successfully.
d:\program files\mozilla firefox\extensions\{27e679cc-6aab-4b2a-bb87-096fe4178464} (Adware.QueryExplorer) -> Quarantined and deleted successfully.
d:\program files\mozilla firefox\extensions\{27e679cc-6aab-4b2a-bb87-096fe4178464}\chrome (Adware.QueryExplorer) -> Quarantined and deleted successfully.
d:\program files\mozilla firefox\extensions\{27e679cc-6aab-4b2a-bb87-096fe4178464}\defaults (Adware.QueryExplorer) -> Quarantined and deleted successfully.
d:\program files\mozilla firefox\extensions\{27e679cc-6aab-4b2a-bb87-096fe4178464}\defaults\preferences (Adware.QueryExplorer) -> Quarantined and deleted successfully.
d:\program files\mywebsearch (Adware.MyWebSearch) -> Delete on reboot.
d:\program files\mywebsearch\bar (Adware.MyWebSearch) -> Delete on reboot.
d:\program files\mywebsearch\bar\1.bin (Adware.MyWebSearch) -> Delete on reboot.
d:\program files\mywebsearch\bar\1.bin\chrome (Adware.MyWebSearch) -> Quarantined and deleted successfully.
d:\program files\mywebsearch\bar\Avatar (Adware.MyWebSearch) -> Quarantined and deleted successfully.
d:\program files\mywebsearch\bar\Cache (Adware.MyWebSearch) -> Quarantined and deleted successfully.
d:\program files\mywebsearch\bar\Game (Adware.MyWebSearch) -> Quarantined and deleted successfully.
d:\program files\mywebsearch\bar\History (Adware.MyWebSearch) -> Quarantined and deleted successfully.
d:\program files\mywebsearch\bar\icons (Adware.MyWebSearch) -> Quarantined and deleted successfully.
d:\program files\mywebsearch\bar\Message (Adware.MyWebSearch) -> Quarantined and deleted successfully.
d:\program files\mywebsearch\bar\Notifier (Adware.MyWebSearch) -> Quarantined and deleted successfully.
d:\program files\mywebsearch\bar\Overlay (Adware.MyWebSearch) -> Quarantined and deleted successfully.
d:\program files\mywebsearch\bar\Settings (Adware.MyWebSearch) -> Quarantined and deleted successfully.
d:\program files\queryexplorer (Adware.QueryExplorer) -> Quarantined and deleted successfully.
d:\program files\queryexplorer\queryexplorer_deleted_ (Adware.QueryExplorer) -> Quarantined and deleted successfully.

Files Infected:
d:\Program Files\MyWebSearch\bar\1.bin\MWSOESTB.DLL (Adware.MyWebSearch) -> Delete on reboot.
d:\program files\mywebsearch\bar\1.bin\MWSSRCAS.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.
d:\program files\mywebsearch\bar\1.bin\MWSBAR.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.
d:\Program Files\MyWebSearch\bar\1.bin\MWSOEMON.EXE (Adware.MyWebSearch) -> Delete on reboot.
d:\program files\mywebsearch\bar\1.bin\M3SRCHMN.EXE (Adware.MyWebSearch) -> Quarantined and deleted successfully.
d:\program files\mywebsearch\bar\1.bin\MWSSVC.EXE (Adware.MyWebSearch) -> Quarantined and deleted successfully.
d:\program files\mywebsearch\bar\1.bin\F3HISTSW.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.
d:\program files\funwebproducts\Installr\1.bin\F3EZSETP.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.
d:\program files\mywebsearch\bar\1.bin\F3DTACTL.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.
d:\program files\mywebsearch\bar\1.bin\F3HTMLMU.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.
d:\program files\mywebsearch\bar\1.bin\M3HTML.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.
d:\program files\mywebsearch\bar\1.bin\F3POPSWT.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.
d:\program files\mywebsearch\bar\1.bin\M3SKIN.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.
d:\program files\mywebsearch\bar\1.bin\F3CJPEG.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.
d:\program files\mywebsearch\bar\1.bin\F3SCRCTR.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.
d:\program files\mywebsearch\bar\1.bin\M3OUTLCN.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.
d:\program files\mywebsearch\bar\1.bin\F3HTTPCT.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.
d:\program files\mywebsearch\bar\1.bin\M3MSG.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.
d:\program files\mywebsearch\bar\1.bin\F3REPROX.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.
d:\program files\mywebsearch\bar\1.bin\MWSOEPLG.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.
d:\WINDOWS\system32\f3PSSavr.scr (PUP.FunWebProducts) -> Quarantined and deleted successfully.
d:\WINDOWS\Temp\_avast_\unp176644949.tmp (Adware.MyWebSearch) -> Quarantined and deleted successfully.
d:\WINDOWS\Temp\_avast_\unp199522042.tmp (PUP.FunWebProducts) -> Quarantined and deleted successfully.
d:\WINDOWS\Temp\_avast_\unp201324698.tmp (Adware.MyWebSearch) -> Quarantined and deleted successfully.
d:\WINDOWS\Temp\_avast_\unp231987756.tmp (PUP.FunWebProducts) -> Quarantined and deleted successfully.
d:\WINDOWS\Temp\_avast_\unp95623205.tmp (PUP.FunWebProducts) -> Quarantined and deleted successfully.
d:\documents and settings\all users\application data\queryexplorer\queryexplorer119.exe (Adware.QueryExplorer) -> Quarantined and deleted successfully.
d:\documents and settings\all users\application data\queryexplorer\queryexplorer129.exe (Adware.QueryExplorer) -> Quarantined and deleted successfully.
d:\documents and settings\all users\application data\queryexplorer\queryexplorer133.exe (Adware.QueryExplorer) -> Quarantined and deleted successfully.
d:\program files\funwebproducts\Installr\1.bin\F3PLUGIN.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.
d:\program files\funwebproducts\Installr\1.bin\NPFUNWEB.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.
d:\program files\funwebproducts\Shared\Cache\cursormaniabtn.html (Adware.MyWebSearch) -> Quarantined and deleted successfully.
d:\program files\funwebproducts\Shared\Cache\myfuncardsimbtn.html (Adware.MyWebSearch) -> Quarantined and deleted successfully.
d:\program files\funwebproducts\Shared\Cache\smileycentralbtn.html (Adware.MyWebSearch) -> Quarantined and deleted successfully.
d:\program files\funwebproducts\Shared\Cache\webfettibtn.html (Adware.MyWebSearch) -> Quarantined and deleted successfully.
d:\program files\mozilla firefox\extensions\{27e679cc-6aab-4b2a-bb87-096fe4178464}\chrome.manifest (Adware.QueryExplorer) -> Quarantined and deleted successfully.
d:\program files\mozilla firefox\extensions\{27e679cc-6aab-4b2a-bb87-096fe4178464}\install.rdf (Adware.QueryExplorer) -> Quarantined and deleted successfully.
d:\program files\mozilla firefox\extensions\{27e679cc-6aab-4b2a-bb87-096fe4178464}\chrome\queryexplorer.jar (Adware.QueryExplorer) -> Quarantined and deleted successfully.
d:\program files\mozilla firefox\extensions\{27e679cc-6aab-4b2a-bb87-096fe4178464}\defaults\preferences\prefs.js (Adware.QueryExplorer) -> Quarantined and deleted successfully.
d:\program files\mywebsearch\bar\1.bin\F3SPACER.WMV (Adware.MyWebSearch) -> Quarantined and deleted successfully.
d:\program files\mywebsearch\bar\1.bin\chrome.manifest (Adware.MyWebSearch) -> Quarantined and deleted successfully.
d:\program files\mywebsearch\bar\1.bin\F3BKGERR.JPG (Adware.MyWebSearch) -> Quarantined and deleted successfully.
d:\program files\mywebsearch\bar\1.bin\F3HKSTUB.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.
d:\program files\mywebsearch\bar\1.bin\F3IMSTUB.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.
d:\program files\mywebsearch\bar\1.bin\F3PSSAVR.SCR (Adware.MyWebSearch) -> Quarantined and deleted successfully.
d:\program files\mywebsearch\bar\1.bin\F3REGHK.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.
d:\program files\mywebsearch\bar\1.bin\F3RESTUB.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.
d:\program files\mywebsearch\bar\1.bin\F3SCHMON.EXE (Adware.MyWebSearch) -> Quarantined and deleted successfully.
d:\program files\mywebsearch\bar\1.bin\F3WALLPP.DAT (Adware.MyWebSearch) -> Quarantined and deleted successfully.
d:\program files\mywebsearch\bar\1.bin\F3WPHOOK.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.
d:\program files\mywebsearch\bar\1.bin\FWPBUDDY.PNG (Adware.MyWebSearch) -> Quarantined and deleted successfully.
d:\program files\mywebsearch\bar\1.bin\INSTALL.RDF (Adware.MyWebSearch) -> Quarantined and deleted successfully.
d:\program files\mywebsearch\bar\1.bin\M3AUXSTB.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.
d:\program files\mywebsearch\bar\1.bin\M3DLGHK.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.
d:\program files\mywebsearch\bar\1.bin\M3HIGHIN.EXE (Adware.MyWebSearch) -> Quarantined and deleted successfully.
d:\program files\mywebsearch\bar\1.bin\M3IDLE.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.
d:\program files\mywebsearch\bar\1.bin\M3IMPIPE.EXE (Adware.MyWebSearch) -> Quarantined and deleted successfully.
d:\program files\mywebsearch\bar\1.bin\M3MEDINT.EXE (Adware.MyWebSearch) -> Quarantined and deleted successfully.
d:\program files\mywebsearch\bar\1.bin\M3PLUGIN.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.
d:\program files\mywebsearch\bar\1.bin\M3SKPLAY.EXE (Adware.MyWebSearch) -> Quarantined and deleted successfully.
d:\program files\mywebsearch\bar\1.bin\M3SLSRCH.EXE (Adware.MyWebSearch) -> Quarantined and deleted successfully.
d:\program files\mywebsearch\bar\1.bin\M3TPINST.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.
d:\program files\mywebsearch\bar\1.bin\MWSMLBTN.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.
d:\program files\mywebsearch\bar\1.bin\MWSUABTN.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.
d:\program files\mywebsearch\bar\1.bin\NPMYWEBS.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.
d:\program files\mywebsearch\bar\1.bin\chrome\M3FFXTBR.JAR (Adware.MyWebSearch) -> Quarantined and deleted successfully.
d:\program files\mywebsearch\bar\Avatar\COMMON.F3S (Adware.MyWebSearch) -> Quarantined and deleted successfully.
d:\program files\mywebsearch\bar\Cache\03279313.bmp (Adware.MyWebSearch) -> Quarantined and deleted successfully.
d:\program files\mywebsearch\bar\Cache\032793FD.bin (Adware.MyWebSearch) -> Quarantined and deleted successfully.
d:\program files\mywebsearch\bar\Cache\0327946A.bin (Adware.MyWebSearch) -> Quarantined and deleted successfully.
d:\program files\mywebsearch\bar\Cache\0906E991.bin (Adware.MyWebSearch) -> Quarantined and deleted successfully.
d:\program files\mywebsearch\bar\Cache\0906EBF2.bin (Adware.MyWebSearch) -> Quarantined and deleted successfully.
d:\program files\mywebsearch\bar\Cache\0C41ADAA (Adware.MyWebSearch) -> Quarantined and deleted successfully.
d:\program files\mywebsearch\bar\Cache\2540DC95 (Adware.MyWebSearch) -> Quarantined and deleted successfully.
d:\program files\mywebsearch\bar\Cache\2540E744 (Adware.MyWebSearch) -> Quarantined and deleted successfully.
d:\program files\mywebsearch\bar\Cache\2540E918.bin (Adware.MyWebSearch) -> Quarantined and deleted successfully.
d:\program files\mywebsearch\bar\Cache\2540EAFD.bin (Adware.MyWebSearch) -> Quarantined and deleted successfully.
d:\program files\mywebsearch\bar\Cache\2540ED3F.bin (Adware.MyWebSearch) -> Quarantined and deleted successfully.
d:\program files\mywebsearch\bar\Cache\2540EEB6.bin (Adware.MyWebSearch) -> Quarantined and deleted successfully.
d:\program files\mywebsearch\bar\Cache\2540EF91.bin (Adware.MyWebSearch) -> Quarantined and deleted successfully.
d:\program files\mywebsearch\bar\Cache\2540F07B.bin (Adware.MyWebSearch) -> Quarantined and deleted successfully.
d:\program files\mywebsearch\bar\Cache\2540F0D9.bin (Adware.MyWebSearch) -> Quarantined and deleted successfully.
d:\program files\mywebsearch\bar\Cache\files.ini (Adware.MyWebSearch) -> Quarantined and deleted successfully.
d:\program files\mywebsearch\bar\Game\CHECKERS.F3S (Adware.MyWebSearch) -> Quarantined and deleted successfully.
d:\program files\mywebsearch\bar\Game\CHESS.F3S (Adware.MyWebSearch) -> Quarantined and deleted successfully.
d:\program files\mywebsearch\bar\Game\REVERSI.F3S (Adware.MyWebSearch) -> Quarantined and deleted successfully.
d:\program files\mywebsearch\bar\History\search3 (Adware.MyWebSearch) -> Quarantined and deleted successfully.
d:\program files\mywebsearch\bar\icons\CM.ICO (Adware.MyWebSearch) -> Quarantined and deleted successfully.
d:\program files\mywebsearch\bar\icons\MFC.ICO (Adware.MyWebSearch) -> Quarantined and deleted successfully.
d:\program files\mywebsearch\bar\icons\PSS.ICO (Adware.MyWebSearch) -> Quarantined and deleted successfully.
d:\program files\mywebsearch\bar\icons\SMILEY.ICO (Adware.MyWebSearch) -> Quarantined and deleted successfully.
d:\program files\mywebsearch\bar\icons\Thumbs.db (Adware.MyWebSearch) -> Quarantined and deleted successfully.
d:\program files\mywebsearch\bar\icons\WB.ICO (Adware.MyWebSearch) -> Quarantined and deleted successfully.
d:\program files\mywebsearch\bar\icons\ZWINKY.ICO (Adware.MyWebSearch) -> Quarantined and deleted successfully.
d:\program files\mywebsearch\bar\Message\COMMON.F3S (Adware.MyWebSearch) -> Quarantined and deleted successfully.
d:\program files\mywebsearch\bar\Notifier\COMMON.F3S (Adware.MyWebSearch) -> Quarantined and deleted successfully.
d:\program files\mywebsearch\bar\Notifier\DOG.F3S (Adware.MyWebSearch) -> Quarantined and deleted successfully.
d:\program files\mywebsearch\bar\Notifier\FISH.F3S (Adware.MyWebSearch) -> Quarantined and deleted successfully.
d:\program files\mywebsearch\bar\Notifier\KUNGFU.F3S (Adware.MyWebSearch) -> Quarantined and deleted successfully.
d:\program files\mywebsearch\bar\Notifier\LIFEGARD.F3S (Adware.MyWebSearch) -> Quarantined and deleted successfully.
d:\program files\mywebsearch\bar\Notifier\MAID.F3S (Adware.MyWebSearch) -> Quarantined and deleted successfully.
d:\program files\mywebsearch\bar\Notifier\MAILBOX.F3S (Adware.MyWebSearch) -> Quarantined and deleted successfully.
d:\program files\mywebsearch\bar\Notifier\OPERA.F3S (Adware.MyWebSearch) -> Quarantined and deleted successfully.
d:\program files\mywebsearch\bar\Notifier\ROBOT.F3S (Adware.MyWebSearch) -> Quarantined and deleted successfully.
d:\program files\mywebsearch\bar\Notifier\SEDUCT.F3S (Adware.MyWebSearch) -> Quarantined and deleted successfully.
d:\program files\mywebsearch\bar\Notifier\SURFER.F3S (Adware.MyWebSearch) -> Quarantined and deleted successfully.
d:\program files\mywebsearch\bar\Overlay\COMMON.F3S (Adware.MyWebSearch) -> Quarantined and deleted successfully.
d:\program files\mywebsearch\bar\Settings\prevcfg2.htm (Adware.MyWebSearch) -> Quarantined and deleted successfully.
d:\program files\mywebsearch\bar\Settings\s_pid.dat (Adware.MyWebSearch) -> Quarantined and deleted successfully.
d:\program files\queryexplorer\uninstall.exe (Adware.QueryExplorer) -> Quarantined and deleted successfully.
d:\program files\queryexplorer\queryexplorer_deleted_\queryexplorer.exe (Adware.QueryExplorer) -> Quarantined and deleted successfully.

2 Re: WhiteSmoke MBAM Logs on Thu Jun 09, 2011 11:49 am

Belahzur


AMA Member
AMA Member
Hello.

Download OTL by OldTimer to your Desktop.

  • Close all windows and double click OTL.exe
  • Click Run Scan and let the program run uninterrupted
  • It will produce two logs for you, one will pop up - OTL.txt, the other will be saved on your Desktop - Extras.txt. Post both logs in this thread.
  • You may need to use two posts to get it all.

3 OLT Log on Thu Jun 09, 2011 12:29 pm

dr09294


Member
Member
OTL logfile created on: 6/9/2011 11:18:34 AM - Run 1
OTL by OldTimer - Version 3.2.23.0 Folder = D:\Documents and Settings\Familia Salinas\My Documents\Downloads
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

2.00 Gb Total Physical Memory | 1.39 Gb Available Physical Memory | 69.76% Memory free
3.72 Gb Paging File | 3.25 Gb Available in Paging File | 87.35% Paging File free
Paging file location(s): D:\pagefile.sys 1920 3840 [binary data]

%SystemDrive% = D: | %SystemRoot% = D:\WINDOWS | %ProgramFiles% = D:\Program Files
Drive C: | 74.50 Gb Total Space | 10.01 Gb Free Space | 13.44% Space Free | Partition Type: NTFS
Drive D: | 74.50 Gb Total Space | 8.47 Gb Free Space | 11.37% Space Free | Partition Type: NTFS

Computer Name: FAMILIASALINAS | User Name: Familia Salinas | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - [2011/06/09 11:16:17 | 000,580,096 | ---- | M] (OldTimer Tools) -- D:\Documents and Settings\Familia Salinas\My Documents\Downloads\OTL.exe
PRC - [2011/06/05 18:38:39 | 001,010,232 | ---- | M] (Google Inc.) -- D:\Documents and Settings\Familia Salinas\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
PRC - [2011/05/10 07:10:58 | 003,459,712 | ---- | M] (AVAST Software) -- D:\Program Files\Alwil Software\Avast5\AvastUI.exe
PRC - [2011/05/10 07:10:57 | 000,042,184 | ---- | M] (AVAST Software) -- D:\Program Files\Alwil Software\Avast5\AvastSvc.exe
PRC - [2011/04/13 15:42:36 | 000,196,608 | ---- | M] (Samsung Electronics Co. Ltd.) -- D:\Documents and Settings\Familia Salinas\Application Data\Verizon\SUA\VZWSUAM.exe
PRC - [2011/02/02 14:08:16 | 000,018,656 | ---- | M] () -- D:\Program Files\Autodesk\Content Service\Connect.Service.ContentService.exe
PRC - [2011/01/20 17:20:34 | 000,426,840 | ---- | M] (IObit) -- D:\Program Files\IObit\Game Booster 2\gbtray.exe
PRC - [2010/12/08 20:59:00 | 000,274,608 | ---- | M] (RealNetworks, Inc.) -- D:\Program Files\Real\RealPlayer\Update\realsched.exe
PRC - [2010/09/16 15:04:06 | 001,164,584 | ---- | M] () -- D:\Program Files\DivX\DivX Update\DivXUpdate.exe
PRC - [2010/04/12 03:40:16 | 000,180,224 | ---- | M] (PowerISO Computing, Inc.) -- D:\Program Files\PowerISO\PWRISOVM.EXE
PRC - [2008/04/14 05:42:20 | 001,033,728 | ---- | M] (Microsoft Corporation) -- D:\WINDOWS\explorer.exe
PRC - [2007/04/30 19:43:54 | 003,450,608 | ---- | M] (Stardock) -- D:\Program Files\Stardock\ObjectDock\ObjectDock.exe
PRC - [2005/03/22 17:20:44 | 000,339,968 | ---- | M] (SigmaTel, Inc.) -- D:\WINDOWS\stsystra.exe
PRC - [2005/02/23 15:57:24 | 000,057,344 | ---- | M] (Creative Technology Ltd) -- D:\Program Files\Creative\Mixer\CTSVolFE.exe


========== Modules (SafeList) ==========

MOD - [2011/06/09 11:16:17 | 000,580,096 | ---- | M] (OldTimer Tools) -- D:\Documents and Settings\Familia Salinas\My Documents\Downloads\OTL.exe
MOD - [2011/05/10 07:10:55 | 000,199,792 | ---- | M] (AVAST Software) -- D:\Program Files\Alwil Software\Avast5\snxhk.dll
MOD - [2011/01/11 10:59:44 | 000,653,136 | ---- | M] (Microsoft Corporation) -- D:\WINDOWS\WinSxS\x86_Microsoft.VC90.CRT_1fc8b3b9a1e18e3b_9.0.30729.5570_x-ww_0517bbc6\msvcr90.dll
MOD - [2011/01/11 10:59:44 | 000,569,680 | ---- | M] (Microsoft Corporation) -- D:\WINDOWS\WinSxS\x86_Microsoft.VC90.CRT_1fc8b3b9a1e18e3b_9.0.30729.5570_x-ww_0517bbc6\msvcp90.dll
MOD - [2010/12/08 20:59:20 | 000,040,448 | ---- | M] (RealNetworks, Inc.) -- D:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\Chrome\Hook\rpchromebrowserrecordhelper.dll
MOD - [2010/08/23 11:12:02 | 001,054,208 | ---- | M] (Microsoft Corporation) -- D:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.6028_x-ww_61e65202\comctl32.dll
MOD - [2007/04/30 19:18:50 | 000,112,400 | ---- | M] () -- D:\Program Files\Stardock\ObjectDock\DockShellHook.dll


========== Win32 Services (SafeList) ==========

SRV - File not found [Disabled | Stopped] -- -- (AppMgmt)
SRV - [2011/05/17 18:58:07 | 003,275,864 | ---- | M] () [Auto | Running] -- d:\Program Files\Common Files\Akamai\netsession_win_8832f4b.dll -- (Akamai)
SRV - [2011/05/10 07:10:57 | 000,042,184 | ---- | M] (AVAST Software) [Auto | Running] -- D:\Program Files\Alwil Software\Avast5\AvastSvc.exe -- (avast! Antivirus)
SRV - [2011/04/14 21:02:12 | 001,044,816 | ---- | M] (Flexera Software, Inc.) [On_Demand | Stopped] -- D:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe -- (FLEXnet Licensing Service)
SRV - [2011/03/28 10:35:06 | 000,069,632 | ---- | M] (Creative Labs) [On_Demand | Stopped] -- D:\Program Files\Common Files\Creative Labs Shared\Service\CreativeLicensing.exe -- (Creative Labs Licensing Service)
SRV - [2011/02/02 14:08:16 | 000,018,656 | ---- | M] () [Auto | Running] -- D:\Program Files\Autodesk\Content Service\Connect.Service.ContentService.exe -- (Autodesk Content Service)
SRV - [2010/02/19 13:37:14 | 000,517,096 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- D:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe -- (SwitchBoard)
SRV - [2005/07/12 16:33:02 | 000,491,520 | ---- | M] () [On_Demand | Stopped] -- D:\WINDOWS\System32\dlcjcoms.exe -- (dlcj_device)


========== Driver Services (SafeList) ==========

DRV - [2011/05/10 07:03:54 | 000,441,176 | ---- | M] (AVAST Software) [File_System | System | Running] -- D:\WINDOWS\System32\drivers\aswSnx.sys -- (aswSnx)
DRV - [2011/05/10 07:03:44 | 000,307,928 | ---- | M] (AVAST Software) [Kernel | System | Running] -- D:\WINDOWS\System32\drivers\aswSP.sys -- (aswSP)
DRV - [2011/05/10 07:02:37 | 000,049,240 | ---- | M] (AVAST Software) [Kernel | System | Running] -- D:\WINDOWS\System32\drivers\aswTdi.sys -- (aswTdi)
DRV - [2011/05/10 07:02:25 | 000,102,616 | ---- | M] (AVAST Software) [File_System | Auto | Running] -- D:\WINDOWS\System32\drivers\aswmon2.sys -- (aswMon2)
DRV - [2011/05/10 06:59:56 | 000,025,432 | ---- | M] (AVAST Software) [Kernel | System | Running] -- D:\WINDOWS\System32\drivers\aswRdr.sys -- (aswRdr)
DRV - [2011/05/10 06:59:37 | 000,030,808 | ---- | M] (AVAST Software) [Kernel | System | Running] -- D:\WINDOWS\System32\drivers\aavmker4.sys -- (Aavmker4)
DRV - [2011/05/10 06:59:35 | 000,019,544 | ---- | M] (AVAST Software) [File_System | Auto | Running] -- D:\WINDOWS\System32\drivers\aswFsBlk.sys -- (aswFsBlk)
DRV - [2010/11/30 11:07:06 | 000,025,088 | ---- | M] (TeamViewer GmbH) [Kernel | On_Demand | Stopped] -- D:\WINDOWS\system32\drivers\teamviewervpn.sys -- (teamviewervpn)
DRV - [2010/09/10 21:19:16 | 005,417,472 | ---- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Running] -- D:\WINDOWS\system32\drivers\ati2mtag.sys -- (ati2mtag)
DRV - [2010/04/26 21:25:20 | 000,132,424 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- D:\WINDOWS\system32\drivers\sscdmdm.sys -- (sscdmdm)
DRV - [2010/04/26 21:25:20 | 000,110,280 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- D:\WINDOWS\system32\drivers\sscdserd.sys -- (sscdserd) SAMSUNG Mobile Modem Diagnostic Serial Port (WDM)
DRV - [2010/04/26 21:25:20 | 000,104,648 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- D:\WINDOWS\system32\drivers\sscdbus.sys -- (sscdbus) SAMSUNG USB Composite Device driver (WDM)
DRV - [2010/04/26 21:25:20 | 000,014,920 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- D:\WINDOWS\system32\drivers\sscdmdfl.sys -- (sscdmdfl)
DRV - [2010/04/12 03:44:34 | 000,059,388 | ---- | M] (PowerISO Computing, Inc.) [Kernel | System | Running] -- D:\WINDOWS\System32\drivers\scdemu.sys -- (SCDEmu)
DRV - [2007/07/20 18:40:10 | 000,084,992 | ---- | M] (ATI Research Inc.) [Kernel | On_Demand | Running] -- D:\WINDOWS\system32\drivers\AtiHdmi.sys -- (AtiHdmiService)
DRV - [2006/01/07 12:09:50 | 000,007,548 | ---- | M] () [Kernel | On_Demand | Running] -- D:\WINDOWS\system32\drivers\Samhid.sys -- (samhid)
DRV - [2005/11/16 15:36:00 | 001,047,816 | ---- | M] (SigmaTel, Inc.) [Kernel | On_Demand | Running] -- D:\WINDOWS\system32\drivers\sthda.sys -- (STHDA)
DRV - [2005/09/24 00:18:32 | 000,171,520 | ---- | M] (Pinnacle Systems GmbH) [Kernel | On_Demand | Stopped] -- D:\WINDOWS\system32\drivers\MarvinBus.sys -- (MarvinBus)
DRV - [2003/11/17 15:59:20 | 000,212,224 | ---- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Running] -- D:\WINDOWS\system32\drivers\HSFHWBS2.sys -- (HSFHWBS2)
DRV - [2003/11/17 15:58:02 | 000,680,704 | ---- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Running] -- D:\WINDOWS\system32\drivers\HSF_CNXT.sys -- (winachsf)
DRV - [2003/11/17 15:56:26 | 001,042,432 | ---- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Running] -- D:\WINDOWS\system32\drivers\HSF_DP.sys -- (HSF_DP)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========


IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://search.conduit.com?SearchSource=10&ctid=CT3007394
IE - HKCU\..\URLSearchHook: - Reg Error: Key error. File not found
IE - HKCU\..\URLSearchHook: {9565115d-c7d6-46d3-bd63-b67b481a4368} - D:\Program Files\PageRage\prxtbPag0.dll (Conduit Ltd.)
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local

========== FireFox ==========

FF - prefs.js..browser.search.defaultthis.engineName: "WhiteSmoke Bar Customized Web Search"
FF - prefs.js..browser.search.defaulturl: "http://search.conduit.com/ResultsExt.aspx?ctid=CT3007394&SearchSource=3&q={searchTerms}"
FF - prefs.js..browser.search.selectedEngine: "WhiteSmoke Bar Customized Web Search"
FF - prefs.js..browser.startup.homepage: "http://search.conduit.com/?ctid=CT3007394&SearchSource=13"
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}:6.0.21
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}:6.0.22
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}:6.0.23
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}:6.0.24
FF - prefs.js..extensions.enabledItems: plugin@yontoo.com:1.20.00
FF - prefs.js..extensions.enabledItems: {167d9323-f7cc-48f5-948a-6f012831a69f}:3.4.2.0
FF - prefs.js..extensions.enabledItems: {9565115d-c7d6-46d3-bd63-b67b481a4368}:2.7.2.0
FF - prefs.js..extensions.enabledItems: {a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7}:20100908
FF - prefs.js..extensions.enabledItems: {01A8CA0A-4C96-465b-A49B-65C46FAD54F9}:6.0
FF - prefs.js..extensions.enabledItems: {ABDE892B-13A8-4d1b-88E6-365A6E755758}:14.0.1
FF - prefs.js..extensions.enabledItems: jqs@sun.com:1.0
FF - prefs.js..extensions.enabledItems: wrc@avast.com:20110101
FF - prefs.js..keyword.URL: "http://www.bing.com/search?pc=Z020&form=ZGAADF&q="
FF - prefs.js..network.proxy.ftp: "123123"
FF - prefs.js..network.proxy.gopher: "12312"
FF - prefs.js..network.proxy.http: "231321"
FF - prefs.js..network.proxy.no_proxies_on: "12312"
FF - prefs.js..network.proxy.socks: "123123"
FF - prefs.js..network.proxy.ssl: "1232"
FF - prefs.js..network.proxy.type: 1


FF - HKLM\software\mozilla\Firefox\Extensions\\{01A8CA0A-4C96-465b-A49B-65C46FAD54F9}: C:\Program Files\Adobe\Adobe Contribute CS5\Plugins\FirefoxPlugin\{01A8CA0A-4C96-465b-A49B-65C46FAD54F9} [2010/08/15 16:43:19 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\{ABDE892B-13A8-4d1b-88E6-365A6E755758}: D:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext [2010/12/08 20:59:20 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\m3ffxtbr@mywebsearch.com: D:\Program Files\MyWebSearch\bar\1.bin
FF - HKLM\software\mozilla\Firefox\Extensions\\wrc@avast.com: D:\Program Files\Alwil Software\Avast5\WebRep\FF [2011/06/08 21:35:04 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.17\extensions\\Components: D:\Program Files\Mozilla Firefox\components [2011/05/05 07:02:37 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.17\extensions\\Plugins: D:\Program Files\Mozilla Firefox\plugins [2011/05/10 16:04:37 | 000,000,000 | ---D | M]

[2010/08/21 20:18:12 | 000,000,000 | ---D | M] (No name found) -- D:\Documents and Settings\Familia Salinas\Application Data\Mozilla\Extensions
[2010/08/20 11:23:43 | 000,000,000 | ---D | M] (No name found) -- D:\Documents and Settings\Familia Salinas\Application Data\Mozilla\Extensions\mozswing@mozswing.org
[2011/06/06 14:14:08 | 000,000,000 | ---D | M] (No name found) -- D:\Documents and Settings\Familia Salinas\Application Data\Mozilla\Firefox\Profiles\sjhkgozz.default\extensions
[2010/12/19 21:47:30 | 000,000,000 | ---D | M] (No name found) -- D:\Documents and Settings\Familia Salinas\Application Data\Mozilla\Firefox\Profiles\sjhkgozz.default\extensions\{000F1EA4-5E08-4564-A29B-29076F63A37A}
[2011/06/06 12:44:36 | 000,000,000 | ---D | M] (WhiteSmoke Bar Community Toolbar) -- D:\Documents and Settings\Familia Salinas\Application Data\Mozilla\Firefox\Profiles\sjhkgozz.default\extensions\{167d9323-f7cc-48f5-948a-6f012831a69f}
[2010/08/27 18:35:42 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- D:\Documents and Settings\Familia Salinas\Application Data\Mozilla\Firefox\Profiles\sjhkgozz.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2011/03/25 15:00:44 | 000,000,000 | ---D | M] (No name found) -- D:\Documents and Settings\Familia Salinas\Application Data\Mozilla\Firefox\Profiles\sjhkgozz.default\extensions\{7b13ec3e-999a-4b70-b9cb-2617b8323822}
[2011/04/06 16:13:59 | 000,000,000 | ---D | M] (PageRage Toolbar) -- D:\Documents and Settings\Familia Salinas\Application Data\Mozilla\Firefox\Profiles\sjhkgozz.default\extensions\{9565115d-c7d6-46d3-bd63-b67b481a4368}
[2010/10/29 20:28:40 | 000,000,000 | ---D | M] (WOT) -- D:\Documents and Settings\Familia Salinas\Application Data\Mozilla\Firefox\Profiles\sjhkgozz.default\extensions\{a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7}
[2011/04/06 16:13:35 | 000,000,000 | ---D | M] (Yontoo Layers) -- D:\Documents and Settings\Familia Salinas\Application Data\Mozilla\Firefox\Profiles\sjhkgozz.default\extensions\plugin@yontoo.com
[2011/03/25 15:00:44 | 000,000,000 | ---D | M] (No name found) -- D:\Documents and Settings\Familia Salinas\Application Data\Mozilla\Firefox\Profiles\sjhkgozz.default\extensions\staged-xpis
[2010/12/25 16:04:45 | 000,001,919 | ---- | M] () -- D:\Documents and Settings\Familia Salinas\Application Data\Mozilla\Firefox\Profiles\sjhkgozz.default\searchplugins\bing-zugo.xml
[2011/06/06 13:58:08 | 000,000,931 | ---- | M] () -- D:\Documents and Settings\Familia Salinas\Application Data\Mozilla\Firefox\Profiles\sjhkgozz.default\searchplugins\conduit.xml
[2011/04/06 20:26:35 | 000,009,932 | ---- | M] () -- D:\Documents and Settings\Familia Salinas\Application Data\Mozilla\Firefox\Profiles\sjhkgozz.default\searchplugins\mywebsearch.xml
[2011/06/08 21:35:59 | 000,000,000 | ---D | M] (No name found) -- D:\Program Files\Mozilla Firefox\extensions
[2010/09/22 17:00:18 | 000,000,000 | ---D | M] (Java Console) -- D:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}
[2010/11/14 09:03:13 | 000,000,000 | ---D | M] (Java Console) -- D:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}
[2011/02/08 19:05:37 | 000,000,000 | ---D | M] (Java Console) -- D:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}
[2011/03/12 10:59:41 | 000,000,000 | ---D | M] (Java Console) -- D:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}
[2010/08/15 16:43:19 | 000,000,000 | ---D | M] (Adobe Contribute Toolbar) -- C:\PROGRAM FILES\ADOBE\ADOBE CONTRIBUTE CS5\PLUGINS\FIREFOXPLUGIN\{01A8CA0A-4C96-465B-A49B-65C46FAD54F9}
[2010/12/08 20:59:20 | 000,000,000 | ---D | M] (RealPlayer Browser Record Plugin) -- D:\DOCUMENTS AND SETTINGS\ALL USERS\APPLICATION DATA\REAL\REALPLAYER\BROWSERRECORDPLUGIN\FIREFOX\EXT
[2011/06/08 21:35:04 | 000,000,000 | ---D | M] (avast! WebRep) -- D:\PROGRAM FILES\ALWIL SOFTWARE\AVAST5\WEBREP\FF
[2011/03/12 10:59:11 | 000,000,000 | ---D | M] (Java Quick Starter) -- D:\PROGRAM FILES\JAVA\JRE6\LIB\DEPLOY\JQS\FF
[2011/03/12 10:59:10 | 000,472,808 | ---- | M] (Sun Microsystems, Inc.) -- D:\Program Files\Mozilla Firefox\plugins\npdeployJava1.dll

O1 HOSTS File: ([2003/07/16 15:29:34 | 000,000,734 | ---- | M]) - D:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (ContributeBHO Class) - {074C1DC5-9320-4A9A-947D-C042949C6216} - C:\Program Files\Adobe\Adobe Contribute CS5\Plugins\IEPlugin\contributeieplugin.dll (Adobe Systems, Inc.)
O2 - BHO: (RealPlayer Download and Record Plugin for Internet Explorer) - {3049C3E9-B461-4BC5-8870-4C09146192CA} - D:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll (RealPlayer)
O2 - BHO: (Conduit Engine ) - {30F9B915-B755-4826-820B-08FBA6BD249D} - D:\Program Files\ConduitEngine\prxConduitEngine.dll (Conduit Ltd.)
O2 - BHO: (avast! WebRep) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - D:\Program Files\Alwil Software\Avast5\aswWebRepIE.dll (AVAST Software)
O2 - BHO: (PageRage Toolbar) - {9565115d-c7d6-46d3-bd63-b67b481a4368} - D:\Program Files\PageRage\prxtbPag0.dll (Conduit Ltd.)
O2 - BHO: (no name) - {9D425283-D487-4337-BAB6-AB8354A81457} - No CLSID value found.
O2 - BHO: (Skype Browser Helper) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - D:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O3 - HKLM\..\Toolbar: (Conduit Engine ) - {30F9B915-B755-4826-820B-08FBA6BD249D} - D:\Program Files\ConduitEngine\prxConduitEngine.dll (Conduit Ltd.)
O3 - HKLM\..\Toolbar: (Contribute Toolbar) - {517BDDE4-E3A7-4570-B21E-2B52B6139FC7} - C:\Program Files\Adobe\Adobe Contribute CS5\Plugins\IEPlugin\contributeieplugin.dll (Adobe Systems, Inc.)
O3 - HKLM\..\Toolbar: (avast! WebRep) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - D:\Program Files\Alwil Software\Avast5\aswWebRepIE.dll (AVAST Software)
O3 - HKLM\..\Toolbar: (PageRage Toolbar) - {9565115d-c7d6-46d3-bd63-b67b481a4368} - D:\Program Files\PageRage\prxtbPag0.dll (Conduit Ltd.)
O3 - HKLM\..\Toolbar: (no name) - {9D425283-D487-4337-BAB6-AB8354A81457} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (PageRage Toolbar) - {9565115D-C7D6-46D3-BD63-B67B481A4368} - D:\Program Files\PageRage\prxtbPag0.dll (Conduit Ltd.)
O4 - HKLM..\Run: [AdobeAAMUpdater-1.0] D:\Program Files\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [AdobeCS5ServiceManager] D:\Program Files\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [ATICustomerCare] D:\Program Files\ATI\ATICustomerCare\ATICustomerCare.exe (Advanced Micro Devices, Inc.)
O4 - HKLM..\Run: [avast5] D:\Program Files\Alwil Software\Avast5\AvastUI.exe (AVAST Software)
O4 - HKLM..\Run: [CTSVolFE] D:\Program Files\Creative\Mixer\CTSVolFE.exe (Creative Technology Ltd)
O4 - HKLM..\Run: [DivXUpdate] D:\Program Files\DivX\DivX Update\DivXUpdate.exe ()
O4 - HKLM..\Run: [PWRISOVM.EXE] D:\Program Files\PowerISO\PWRISOVM.EXE (PowerISO Computing, Inc.)
O4 - HKLM..\Run: [SigmatelSysTrayApp] D:\WINDOWS\stsystra.exe (SigmaTel, Inc.)
O4 - HKLM..\Run: [StartCCC] D:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.)
O4 - HKLM..\Run: [SwitchBoard] D:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [TkBellExe] D:\Program Files\Real\RealPlayer\update\realsched.exe (RealNetworks, Inc.)
O4 - HKCU..\Run: [] File not found
O4 - HKCU..\Run: [AdobeBridge] File not found
O4 - HKCU..\Run: [DW6] D:\Program Files\The Weather Channel FW\Desktop\DesktopWeather.exe (The Weather Channel Interactive, Inc.)
O4 - HKCU..\Run: [VZWSUAM] D:\Documents and Settings\Familia Salinas\Application Data\Verizon\SUA\VZWSUAM.exe (Samsung Electronics Co. Ltd.)
O4 - Startup: D:\Documents and Settings\Familia Salinas\Start Menu\Programs\Startup\Stardock ObjectDock.lnk = D:\Program Files\Stardock\ObjectDock\ObjectDock.exe (Stardock)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Infodelivery present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O9 - Extra Button: Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - D:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - D:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - D:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab (Java Plug-in 1.6.0_24)
O16 - DPF: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab (Java Plug-in 1.6.0_24)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab (Java Plug-in 1.6.0_24)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - D:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - D:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - D:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\AtiExtEvent: DllName - Ati2evxx.dll - D:\WINDOWS\System32\ati2evxx.dll (ATI Technologies Inc.)
O24 - Desktop WallPaper: D:\Documents and Settings\Familia Salinas\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: D:\Documents and Settings\Familia Salinas\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2011/04/14 19:47:49 | 000,000,000 | ---D | M] - C:\Autodesk -- [ NTFS ]
O32 - AutoRun File - [2010/06/25 17:54:03 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O33 - MountPoints2\{0dfb8330-1f45-11e0-8d9c-00123fbdf875}\Shell - "" = AutoRun
O33 - MountPoints2\{0dfb8330-1f45-11e0-8d9c-00123fbdf875}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{0dfb8330-1f45-11e0-8d9c-00123fbdf875}\Shell\AutoRun\command - "" = K:\iStudio.exe
O33 - MountPoints2\{457ee501-4806-11e0-8da0-00123fbdf875}\Shell - "" = AutoRun
O33 - MountPoints2\{457ee501-4806-11e0-8da0-00123fbdf875}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{457ee501-4806-11e0-8da0-00123fbdf875}\Shell\AutoRun\command - "" = E:\TLBootstrap_WPP.exe
O33 - MountPoints2\{54abd8fb-6708-11e0-8da6-00123fbdf875}\Shell - "" = AutoRun
O33 - MountPoints2\{54abd8fb-6708-11e0-8da6-00123fbdf875}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{54abd8fb-6708-11e0-8da6-00123fbdf875}\Shell\AutoRun\command - "" = H:\TLBootstrap_WPP.exe
O33 - MountPoints2\{764e5e9b-a896-11df-8d74-d89a143a0a40}\Shell - "" = AutoRun
O33 - MountPoints2\{764e5e9b-a896-11df-8d74-d89a143a0a40}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{764e5e9b-a896-11df-8d74-d89a143a0a40}\Shell\AutoRun\command - "" = H:\LaunchU3.exe -a
O33 - MountPoints2\{83e4026b-a899-11df-8d75-00123fbdf875}\Shell - "" = AutoRun
O33 - MountPoints2\{83e4026b-a899-11df-8d75-00123fbdf875}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{83e4026b-a899-11df-8d75-00123fbdf875}\Shell\AutoRun\command - "" = E:\LaunchU3.exe -a
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*

========== Files/Folders - Created Within 30 Days ==========

[2011/06/08 21:42:01 | 000,446,464 | ---- | C] (OldTimer Tools) -- D:\Documents and Settings\Familia Salinas\Desktop\TFC.exe
[2011/06/08 21:41:42 | 000,000,000 | ---D | C] -- D:\Documents and Settings\Familia Salinas\Desktop\New Folder
[2011/06/08 21:35:07 | 000,441,176 | ---- | C] (AVAST Software) -- D:\WINDOWS\System32\drivers\aswSnx.sys
[2011/06/08 21:12:23 | 000,000,000 | ---D | C] -- D:\Documents and Settings\Familia Salinas\Application Data\Malwarebytes
[2011/06/08 21:12:19 | 000,038,224 | ---- | C] (Malwarebytes Corporation) -- D:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2011/06/08 21:12:19 | 000,000,000 | ---D | C] -- D:\Documents and Settings\All Users\Start Menu\Programs\Malwarebytes' Anti-Malware
[2011/06/08 21:12:18 | 000,000,000 | ---D | C] -- D:\Documents and Settings\All Users\Application Data\Malwarebytes
[2011/06/08 21:12:15 | 000,020,952 | ---- | C] (Malwarebytes Corporation) -- D:\WINDOWS\System32\drivers\mbam.sys
[2011/06/08 21:12:15 | 000,000,000 | ---D | C] -- D:\Program Files\Malwarebytes' Anti-Malware
[2011/06/08 21:09:54 | 000,000,000 | ---D | C] -- D:\Program Files\VS Revo Group
[2011/06/08 21:09:54 | 000,000,000 | ---D | C] -- D:\Documents and Settings\Familia Salinas\Start Menu\Programs\Revo Uninstaller
[2011/06/06 12:45:13 | 000,000,000 | ---D | C] -- D:\Documents and Settings\Familia Salinas\Application Data\WhiteSmoke
[2011/06/05 15:49:07 | 000,000,000 | ---D | C] -- D:\Documents and Settings\Familia Salinas\Desktop\New Folder (2)
[2011/05/26 07:44:51 | 000,000,000 | -HSD | C] -- D:\Documents and Settings\Familia Salinas\IECompatCache
[2011/05/21 12:52:10 | 000,000,000 | ---D | C] -- D:\Documents and Settings\Familia Salinas\My Documents\GTA San Andreas User Files
[2011/05/19 19:25:26 | 000,000,000 | ---D | C] -- D:\Documents and Settings\Familia Salinas\My Documents\old pictures
[2011/05/14 18:43:04 | 000,000,000 | ---D | C] -- D:\Documents and Settings\All Users\Application Data\Skype Extras
[2011/05/14 18:42:50 | 000,000,000 | ---D | C] -- D:\Program Files\Common Files\Skype
[2011/05/14 18:42:50 | 000,000,000 | ---D | C] -- D:\Documents and Settings\All Users\Start Menu\Programs\Skype
[2011/05/11 15:31:45 | 000,000,000 | ---D | C] -- D:\Documents and Settings\All Users\Start Menu\Programs\iTunes
[2011/05/11 15:30:27 | 000,000,000 | ---D | C] -- D:\Program Files\iPod
[2011/05/11 15:23:24 | 000,000,000 | ---D | C] -- D:\Program Files\Bonjour

========== Files - Modified Within 30 Days ==========

[2011/06/09 11:14:23 | 000,000,442 | -H-- | M] () -- D:\WINDOWS\tasks\User_Feed_Synchronization-{552E9B33-67C4-4751-8644-F10FBF41E711}.job
[2011/06/09 11:14:23 | 000,000,298 | ---- | M] () -- D:\WINDOWS\tasks\RealUpgradeLogonTaskS-1-5-21-1708537768-507921405-725345543-1004.job
[2011/06/09 11:14:16 | 000,000,306 | ---- | M] () -- D:\WINDOWS\tasks\RealUpgradeScheduledTaskS-1-5-21-1708537768-507921405-725345543-1004.job
[2011/06/09 11:11:21 | 000,000,272 | ---- | M] () -- D:\WINDOWS\tasks\Game_Booster_Startup.job
[2011/06/09 11:11:06 | 000,002,048 | --S- | M] () -- D:\WINDOWS\bootstat.dat
[2011/06/08 21:53:05 | 000,001,018 | ---- | M] () -- D:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1708537768-507921405-725345543-1004UA.job
[2011/06/08 21:42:02 | 000,446,464 | ---- | M] (OldTimer Tools) -- D:\Documents and Settings\Familia Salinas\Desktop\TFC.exe
[2011/06/08 21:35:07 | 000,002,626 | ---- | M] () -- D:\WINDOWS\System32\CONFIG.NT
[2011/06/08 21:12:19 | 000,000,784 | ---- | M] () -- D:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2011/06/08 21:09:54 | 000,000,917 | ---- | M] () -- D:\Documents and Settings\Familia Salinas\Desktop\Revo Uninstaller.lnk
[2011/06/08 21:01:24 | 000,002,206 | ---- | M] () -- D:\WINDOWS\System32\wpa.dbl
[2011/06/06 04:53:00 | 000,000,966 | ---- | M] () -- D:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1708537768-507921405-725345543-1004Core.job
[2011/06/06 02:00:00 | 000,000,362 | ---- | M] () -- D:\WINDOWS\tasks\AdobeAAMUpdater-1.0-FAMILIASALINAS-Familia Salinas.job
[2011/06/03 21:35:01 | 000,058,526 | ---- | M] () -- D:\Documents and Settings\Familia Salinas\My Documents\My Feet - Inches Setup.dwt
[2011/06/03 21:34:59 | 000,058,590 | ---- | M] () -- D:\Documents and Settings\Familia Salinas\My Documents\My Feet - Inches Setup 2.dwt
[2011/06/01 09:50:01 | 000,000,284 | ---- | M] () -- D:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2011/06/01 06:00:00 | 000,000,456 | ---- | M] () -- D:\WINDOWS\tasks\DriverNavigator Scheduled Scan.job
[2011/05/24 19:51:45 | 000,000,833 | ---- | M] () -- D:\Documents and Settings\Familia Salinas\Desktop\Shortcut to GTA-SA Crazy Trainer.lnk
[2011/05/23 15:52:50 | 000,000,180 | ---- | M] () -- D:\WINDOWS\System32\sam.ini
[2011/05/23 09:56:46 | 000,043,520 | ---- | M] () -- D:\Documents and Settings\Familia Salinas\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/05/11 15:21:33 | 000,001,854 | ---- | M] () -- D:\Documents and Settings\Familia Salinas\Application Data\Microsoft\Internet Explorer\Quick Launch\Apple Safari.lnk

========== Files Created - No Company Name ==========

[2011/06/08 21:12:19 | 000,000,784 | ---- | C] () -- D:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2011/06/08 21:09:54 | 000,000,917 | ---- | C] () -- D:\Documents and Settings\Familia Salinas\Desktop\Revo Uninstaller.lnk
[2011/06/03 21:35:01 | 000,058,526 | ---- | C] () -- D:\Documents and Settings\Familia Salinas\My Documents\My Feet - Inches Setup.dwt
[2011/06/03 21:34:59 | 000,058,590 | ---- | C] () -- D:\Documents and Settings\Familia Salinas\My Documents\My Feet - Inches Setup 2.dwt
[2011/05/26 07:41:47 | 000,000,442 | -H-- | C] () -- D:\WINDOWS\tasks\User_Feed_Synchronization-{552E9B33-67C4-4751-8644-F10FBF41E711}.job
[2011/05/24 19:51:45 | 000,000,833 | ---- | C] () -- D:\Documents and Settings\Familia Salinas\Desktop\Shortcut to GTA-SA Crazy Trainer.lnk
[2011/05/23 09:54:45 | 000,000,180 | ---- | C] () -- D:\WINDOWS\System32\sam.ini
[2011/04/23 19:10:40 | 000,487,424 | ---- | C] () -- D:\WINDOWS\System32\FDRpage.dll
[2011/04/23 19:10:40 | 000,007,548 | ---- | C] () -- D:\WINDOWS\System32\drivers\Samhid.sys
[2011/04/23 19:10:33 | 000,192,512 | ---- | C] () -- D:\WINDOWS\System32\CreateDir.exe
[2011/04/21 03:19:54 | 000,531,586 | ---- | C] () -- D:\Documents and Settings\LocalService\Local Settings\Application Data\WPFFontCache_v0400-S-1-5-21-1708537768-507921405-725345543-1004-0.dat
[2011/04/21 03:19:53 | 000,265,930 | ---- | C] () -- D:\Documents and Settings\LocalService\Local Settings\Application Data\WPFFontCache_v0400-System.dat
[2011/04/14 21:03:05 | 000,000,147 | ---- | C] () -- D:\Documents and Settings\All Users\Application Data\Microsoft.SqlServer.Compact.351.32.bc
[2011/02/25 20:19:32 | 000,041,872 | ---- | C] () -- D:\WINDOWS\System32\xfcodec.dll
[2011/02/10 17:31:36 | 000,643,640 | ---- | C] () -- D:\Documents and Settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
[2010/11/19 21:06:17 | 000,000,664 | ---- | C] () -- D:\WINDOWS\System32\d3d9caps.dat
[2010/10/17 12:24:29 | 000,815,104 | ---- | C] () -- D:\WINDOWS\System32\xvidcore.dll
[2010/10/17 12:24:29 | 000,180,224 | ---- | C] () -- D:\WINDOWS\System32\xvidvfw.dll
[2010/09/25 20:28:24 | 001,970,176 | ---- | C] () -- D:\WINDOWS\System32\d3dx9.dll
[2010/09/05 19:16:11 | 000,000,096 | -H-- | C] () -- D:\WINDOWS\System32\HsInfo.dat
[2010/09/01 18:56:14 | 000,000,376 | ---- | C] () -- D:\WINDOWS\ODBC.INI
[2010/08/25 06:32:24 | 000,040,960 | R--- | C] () -- D:\WINDOWS\System32\dlcjvs.dll
[2010/08/25 06:31:09 | 001,183,744 | ---- | C] () -- D:\WINDOWS\System32\dlcjserv.dll
[2010/08/25 06:31:09 | 001,122,304 | ---- | C] () -- D:\WINDOWS\System32\dlcjusb1.dll
[2010/08/25 06:31:09 | 000,155,648 | ---- | C] () -- D:\WINDOWS\System32\dlcjprox.dll
[2010/08/25 06:31:09 | 000,114,688 | ---- | C] () -- D:\WINDOWS\System32\dlcjpplc.dll
[2010/08/25 06:31:08 | 000,770,048 | ---- | C] () -- D:\WINDOWS\System32\dlcjhbn3.dll
[2010/08/25 06:31:08 | 000,704,512 | ---- | C] () -- D:\WINDOWS\System32\dlcjcomc.dll
[2010/08/25 06:31:08 | 000,630,784 | ---- | C] () -- D:\WINDOWS\System32\dlcjpmui.dll
[2010/08/25 06:31:08 | 000,491,520 | ---- | C] () -- D:\WINDOWS\System32\dlcjcoms.exe
[2010/08/25 06:31:08 | 000,413,696 | ---- | C] () -- D:\WINDOWS\System32\dlcjcomm.dll
[2010/08/25 06:31:08 | 000,372,736 | ---- | C] () -- D:\WINDOWS\System32\dlcjih.exe
[2010/08/25 06:31:07 | 000,491,520 | ---- | C] () -- D:\WINDOWS\System32\dlcjlmpm.dll
[2010/08/25 06:31:07 | 000,430,080 | ---- | C] () -- D:\WINDOWS\System32\dlcjutil.dll
[2010/08/25 06:31:07 | 000,368,640 | ---- | C] () -- D:\WINDOWS\System32\dlcjcfg.exe
[2010/08/25 06:31:03 | 000,131,072 | ---- | C] () -- D:\WINDOWS\System32\dlcjjswr.dll
[2010/08/25 06:31:02 | 000,176,128 | ---- | C] () -- D:\WINDOWS\System32\dlcjinsb.dll
[2010/08/25 06:31:02 | 000,155,648 | ---- | C] () -- D:\WINDOWS\System32\dlcjins.dll
[2010/08/25 06:31:02 | 000,106,496 | ---- | C] () -- D:\WINDOWS\System32\dlcjinsr.dll
[2010/08/25 06:31:01 | 000,086,016 | ---- | C] () -- D:\WINDOWS\System32\dlcjcub.dll
[2010/08/25 06:31:01 | 000,073,728 | ---- | C] () -- D:\WINDOWS\System32\dlcjcu.dll
[2010/08/25 06:31:01 | 000,036,864 | ---- | C] () -- D:\WINDOWS\System32\dlcjcur.dll
[2010/08/25 06:30:59 | 000,069,632 | ---- | C] () -- D:\WINDOWS\System32\dlcjcfg.dll
[2010/08/21 20:18:01 | 000,000,000 | ---- | C] () -- D:\WINDOWS\nsreg.dat
[2010/08/21 15:09:22 | 000,000,000 | ---- | C] () -- D:\WINDOWS\ativpsrm.bin
[2010/08/21 15:09:03 | 000,887,724 | ---- | C] () -- D:\WINDOWS\System32\ativva6x.dat
[2010/08/21 15:09:03 | 000,294,912 | ---- | C] () -- D:\WINDOWS\System32\ATIODE.exe
[2010/08/21 15:09:03 | 000,045,056 | ---- | C] () -- D:\WINDOWS\System32\ATIODCLI.exe
[2010/08/21 15:09:03 | 000,000,003 | ---- | C] () -- D:\WINDOWS\System32\ativva5x.dat
[2010/08/18 17:15:37 | 000,138,160 | ---- | C] () -- D:\WINDOWS\System32\drivers\PnkBstrK.sys
[2010/08/18 17:15:36 | 000,022,328 | ---- | C] () -- D:\Documents and Settings\Familia Salinas\Application Data\PnkBstrK.sys
[2010/08/18 17:15:17 | 000,271,200 | ---- | C] () -- D:\WINDOWS\System32\PnkBstrB.exe
[2010/08/18 17:15:16 | 000,075,136 | ---- | C] () -- D:\WINDOWS\System32\PnkBstrA.exe
[2010/08/18 17:15:14 | 000,000,319 | ---- | C] () -- D:\WINDOWS\game.ini
[2010/08/16 10:52:42 | 000,044,936 | -H-- | C] () -- D:\WINDOWS\System32\mlfcache.dat
[2010/08/16 09:59:41 | 000,000,056 | -H-- | C] () -- D:\WINDOWS\System32\ezsidmv.dat
[2010/08/16 09:30:04 | 000,002,560 | ---- | C] () -- D:\WINDOWS\_MSRSTRT.EXE
[2010/08/15 21:11:49 | 000,043,520 | ---- | C] () -- D:\Documents and Settings\Familia Salinas\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/08/15 13:11:21 | 000,520,192 | ---- | C] () -- D:\WINDOWS\System32\ati2sgag.exe
[2010/08/15 13:10:39 | 000,224,342 | ---- | C] () -- D:\WINDOWS\System32\atiicdxx.dat
[2010/08/15 12:52:21 | 000,002,048 | --S- | C] () -- D:\WINDOWS\bootstat.dat
[2010/08/15 12:43:32 | 000,021,640 | ---- | C] () -- D:\WINDOWS\System32\emptyregdb.dat
[2010/08/15 07:22:54 | 000,004,161 | ---- | C] () -- D:\WINDOWS\ODBCINST.INI
[2010/08/15 07:21:46 | 003,521,416 | ---- | C] () -- D:\WINDOWS\System32\FNTCACHE.DAT
[2007/11/26 21:56:28 | 000,151,415 | ---- | C] () -- D:\WINDOWS\System32\xlive.dll.cat
[2006/12/31 07:57:08 | 000,004,569 | ---- | C] () -- D:\WINDOWS\System32\secupd.dat
[2003/07/16 15:54:55 | 000,004,594 | ---- | C] () -- D:\WINDOWS\System32\oembios.dat
[2003/07/16 15:54:54 | 013,107,200 | ---- | C] () -- D:\WINDOWS\System32\oembios.bin
[2003/07/16 15:41:25 | 000,492,614 | ---- | C] () -- D:\WINDOWS\System32\perfh009.dat
[2003/07/16 15:41:25 | 000,272,128 | ---- | C] () -- D:\WINDOWS\System32\perfi009.dat
[2003/07/16 15:41:23 | 000,028,626 | ---- | C] () -- D:\WINDOWS\System32\perfd009.dat
[2003/07/16 15:41:21 | 000,083,262 | ---- | C] () -- D:\WINDOWS\System32\perfc009.dat
[2003/07/16 15:39:07 | 000,000,741 | ---- | C] () -- D:\WINDOWS\System32\noise.dat
[2003/07/16 15:33:50 | 000,673,088 | ---- | C] () -- D:\WINDOWS\System32\mlang.dat
[2003/07/16 15:33:39 | 000,046,258 | ---- | C] () -- D:\WINDOWS\System32\mib.bin
[2003/07/16 15:27:41 | 000,218,003 | ---- | C] () -- D:\WINDOWS\System32\dssec.dat
[2003/07/16 15:26:37 | 000,001,804 | ---- | C] () -- D:\WINDOWS\System32\dcache.bin
[2003/01/07 15:05:08 | 000,002,695 | ---- | C] () -- D:\WINDOWS\System32\OUTLPERF.INI

========== Alternate Data Streams ==========

@Alternate Data Stream - 133 bytes -> D:\Documents and Settings\All Users\Application Data\TEMP:05EE1EEF

< End of report >

4 Extras Log on Thu Jun 09, 2011 12:30 pm

dr09294


Member
Member
OTL Extras logfile created on: 6/9/2011 11:18:34 AM - Run 1
OTL by OldTimer - Version 3.2.23.0 Folder = D:\Documents and Settings\Familia Salinas\My Documents\Downloads
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

2.00 Gb Total Physical Memory | 1.39 Gb Available Physical Memory | 69.76% Memory free
3.72 Gb Paging File | 3.25 Gb Available in Paging File | 87.35% Paging File free
Paging file location(s): D:\pagefile.sys 1920 3840 [binary data]

%SystemDrive% = D: | %SystemRoot% = D:\WINDOWS | %ProgramFiles% = D:\Program Files
Drive C: | 74.50 Gb Total Space | 10.01 Gb Free Space | 13.44% Space Free | Partition Type: NTFS
Drive D: | 74.50 Gb Total Space | 8.47 Gb Free Space | 11.37% Space Free | Partition Type: NTFS

Computer Name: FAMILIASALINAS | User Name: Familia Salinas | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] -- rundll32.exe shell32.dll,Control_RunDLL "%1",%*

[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.html [@ = ChromeHTML] -- Reg Error: Key error. File not found

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
cplfile [cplopen] -- rundll32.exe shell32.dll,Control_RunDLL "%1",%*
exefile [open] -- "%1" %*
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [Bridge] -- C:\Program Files\Adobe\Adobe Bridge CS5\Bridge.exe "%L" (Adobe Systems, Inc.)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] -- %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] -- %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

========== System Restore Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sr]
"Start" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SrService]
"Start" = 2

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DoNotAllowExceptions" = 0
"DisableNotifications" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"1036:TCP" = 1036:TCP:*:Enabled:Akamai NetSession Interface
"5000:UDP" = 5000:UDP:*:Enabled:Akamai NetSession Interface

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"D:\Program Files\AIM\aim.exe" = D:\Program Files\AIM\aim.exe:*:Enabled:AIM -- (AOL Inc.)
"D:\Program Files\LimeWire\LimeWire.exe" = D:\Program Files\LimeWire\LimeWire.exe:*:Enabled:LimeWire
"D:\Program Files\Steam\Steam.exe" = D:\Program Files\Steam\Steam.exe:*:Enabled:Steam -- (Valve Corporation)
"D:\Program Files\Xfire\Xfire.exe" = D:\Program Files\Xfire\Xfire.exe:*:Enabled:Xfire -- (Xfire Inc.)
"D:\Documents and Settings\All Users\Application Data\Electronic Arts\Need For Speed World\Data\nfsw.exe" = D:\Documents and Settings\All Users\Application Data\Electronic Arts\Need For Speed World\Data\nfsw.exe:*:Enabled:Need for Speed World
"D:\Program Files\Java\jre6\bin\javaw.exe" = D:\Program Files\Java\jre6\bin\javaw.exe:*:Enabled:Java(TM) Platform SE binary -- (Sun Microsystems, Inc.)
"D:\WINDOWS\system32\java.exe" = D:\WINDOWS\system32\java.exe:*:Enabled:Java(TM) Platform SE binary -- (Sun Microsystems, Inc.)
"D:\Program Files\uTorrent\uTorrent.exe" = D:\Program Files\uTorrent\uTorrent.exe:*:Enabled:µTorrent -- (BitTorrent, Inc.)
"D:\Program Files\Graffiti Studio 2.0\Graffiti Studio.exe" = D:\Program Files\Graffiti Studio 2.0\Graffiti Studio.exe:*:Enabled:Macromedia Projector -- (Macromedia, Inc.)
"D:\Program Files\FrostWire\FrostWire.exe" = D:\Program Files\FrostWire\FrostWire.exe:*:Enabled:FrostWire
"D:\Program Files\Armagetron Advanced\armagetronad.exe" = D:\Program Files\Armagetron Advanced\armagetronad.exe:*:Enabled:armagetronad -- ()
"D:\Program Files\Java\jre6\bin\java.exe" = D:\Program Files\Java\jre6\bin\java.exe:*:Enabled:Java(TM) Platform SE binary -- (Sun Microsystems, Inc.)
"D:\Program Files\Valve\HLServer\orangebox\srcds.exe" = D:\Program Files\Valve\HLServer\orangebox\srcds.exe:*:Enabled:srcds -- ()
"D:\Program Files\TeamViewer\Version6\TeamViewer.exe" = D:\Program Files\TeamViewer\Version6\TeamViewer.exe:*:Enabled:Teamviewer Remote Control Application -- (TeamViewer GmbH)
"D:\Program Files\TeamViewer\Version6\TeamViewer_Service.exe" = D:\Program Files\TeamViewer\Version6\TeamViewer_Service.exe:*:Enabled:Teamviewer Remote Control Service -- (TeamViewer GmbH)
"C:\Program Files\Activision\Call of Duty 4 - Modern Warfare\iw3mp.exe" = C:\Program Files\Activision\Call of Duty 4 - Modern Warfare\iw3mp.exe:*:Enabled:Call of Duty(R) 4 - Modern Warfare(TM) -- ()
"D:\Program Files\Microsoft Games\Halo\halo.exe" = D:\Program Files\Microsoft Games\Halo\halo.exe:*:Enabled:Halo -- (Microsoft Corporation)
"D:\Program Files\Steam\steamapps\dr09294\counter-strike source\hl2.exe" = D:\Program Files\Steam\steamapps\dr09294\counter-strike source\hl2.exe:*:Enabled:Counter-Strike: Source
"C:\Program Files\Activision\Call of Duty 4 - Modern Warfare\iw3mp (2).exe" = C:\Program Files\Activision\Call of Duty 4 - Modern Warfare\iw3mp (2).exe:*:Enabled:iw3mp (2) -- ()


========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{016E6B1B-45FC-44FB-9F83-28E6B1FF6A42}" = Verizon Wireless Software Upgrade Assistant - SAMSUNG (TL-PC)
"{024521CF-C07E-4F8E-8481-0D75695E03AF}" = PxMergeModule
"{026C3D27-9BE1-46BE-BEAE-6DE38A0F4FBE}" = RealNetworks - Microsoft Visual C++ 2005 Runtime
"{033E378E-6AD3-4AD5-BDEB-CBD69B31046C}" = Microsoft_VC90_ATL_x86
"{048298C9-A4D3-490B-9FF9-AB023A9238F3}" = Steam
"{04F67CE9-C706-7C07-B882-4790D01C5A76}" = Catalyst Control Center Graphics Previews Common
"{05308C4E-7285-4066-BAE3-6B50DA6ED755}" = Adobe Update Manager CS4
"{054EFA56-2AC1-48F4-A883-0AB89874B972}" = Adobe Extension Manager CS4
"{086F9A69-CD39-4893-A9FB-D3A0634CE3F7}" = Autodesk Content Service
"{08D2E121-7F6A-43EB-97FD-629B44903403}" = Microsoft_VC90_CRT_x86
"{0A0CADCF-78DA-33C4-A350-CD51849B9702}" = Microsoft .NET Framework 4 Extended
"{0BEDBD4E-2D34-47B5-9973-57E62B29307C}" = ATI Control Panel
"{0D2DBE8A-43D0-7830-7AE7-CA6C99A832E7}" = Adobe Community Help
"{0E532C84-4275-41B3-9D81-D4A1A20D8EE7}" = PlayStation(R)Store
"{0F3647F8-E51D-4FCC-8862-9A8D0C5ACF25}" = Microsoft_VC80_ATL_x86
"{11083C7A-D0D6-4DA4-8C3A-74B8389EC07B}" = ATI Catalyst Registration
"{1618734A-3957-4ADD-8199-F973763109A8}" = Adobe Anchor Service CS4
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{26A24AE4-039D-4CA4-87B4-2F83216024FF}" = Java(TM) 6 Update 24
"{288DB08D-0708-4A94-B055-55B99E39EB62}" = Adobe Creative Suite 5 Master Collection
"{28C2DED6-325B-4CC7-983A-1777C8F7FBAB}" = RealUpgrade 1.1
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{3A4E8896-C2E7-4084-A4A4-B8FD1894E739}" = Adobe XMP Panels CS4
"{3C3901C5-3455-3E0A-A214-0B093A5070A6}" = Microsoft .NET Framework 4 Client Profile
"{3F92ABBB-6BBF-11D5-B229-002078017FBF}" = NetWaiting
"{411F3ABA-2AB5-4799-AA19-6ADF0A8F7424}" = Adobe Setup
"{43509E18-076E-40FE-AF38-CA5ED400A5A9}" = Pixel Bender Toolkit
"{44E240EC-2224-4078-A88B-2CEE0D3016EF}" = Adobe After Effects CS4 Presets
"{45EC816C-0771-4C14-AE6D-72D1B578F4C8}" = Adobe After Effects CS4
"{49471DB8-7F3C-42DB-89C2-AC50FA0C5290}" = Camtasia Studio 7
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{52504CE6-E909-4113-B232-4AFEC6543A61}" = Broadcom 440x 10/100 Integrated Controller
"{5335DADB-34BA-4AE8-A519-648D78498846}" = Skype™ 5.3
"{561968FD-56A1-49FD-9ED0-F55482C7C5BC}" = Adobe Media Encoder CS4 Exporter
"{57752979-A1C9-4C02-856B-FBB27AC4E02C}" = QuickTime
"{5783F2D7-9028-0409-0000-0060B0CE6BBA}" = DWG TrueView 2011
"{5783F2D7-A001-0409-0002-0060B0CE6BBA}" = AutoCAD 2012 - English
"{5783F2D7-A001-0409-1002-0060B0CE6BBA}" = AutoCAD 2012 Language Pack - English
"{5E3CB60D-627B-3B5C-2173-3EAB3397C9A1}" = Catalyst Control Center InstallProxy
"{5EE7D259-D137-4438-9A5F-42F432EC0421}" = VC80CRTRedist - 8.0.50727.4053
"{60DB5894-B5A1-4B62-B0F3-669A22C0EE5D}" = Adobe Dynamiclink Support
"{635FED5B-2C6D-49BE-87E6-7A6FCD22BC5A}" = Microsoft_VC90_MFC_x86
"{639673E9-D53F-44F4-A046-485C8A6ADA15}" = Paint.NET v3.5.6
"{63BF0B7D-DFB7-2A23-4212-E7C6D5196A46}" = ATI Stream SDK v2 Developer
"{65420DC9-306E-4371-905F-F4DC3B418E52}" = Autodesk Material Library Base Resolution Image Library 2012
"{679F739E-5C76-4A41-B562-F9392156B6DD}" = System Requirements Lab CYRI
"{67A9747A-E1F5-4E9A-81CC-12B5D5B81B6E}" = Adobe After Effects CS4 Third Party Content
"{67F0E67A-8E93-4C2C-B29D-47C48262738A}" = Adobe Device Central CS4
"{6C1E7AA1-44E9-446D-AAB2-0DE6D9EFEAB1}" = Safari
"{6D592E30-11EC-11E0-859C-0013D3D69929}" = Vegas Pro 10.0
"{6E9EF98E-259E-416D-B5F8-0ABDB99942CE}" = Adobe Flash Player 10 ActiveX
"{7032B400-11EC-11E0-A9BF-0013D3D69929}" = MSVCRT Redists
"{716E0306-8318-4364-8B8F-0CC4E9376BAC}" = MSXML 4.0 SP2 Parser and SDK
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{7770E71B-2D43-4800-9CB3-5B6CAAEBEBEA}" = RealNetworks - Microsoft Visual C++ 2008 Runtime
"{779DECD7-E072-4B56-9B6B-BEB5973EEEB5}" = MobileMe Control Panel
"{8186FF34-D389-4B7E-9A2F-C197585BCFBD}" = Adobe Media Encoder CS4 Importer
"{820D3F45-F6EE-4AAF-81EF-CE21FF21D230}" = Adobe Type Support CS4
"{8279BD5B-F4B7-3B75-95F5-F1D2BB219C7F}" = ccc-utility
"{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable
"{842B4B72-9E8F-4962-B3C1-1C422A5C4434}" = Suite Shared Configuration CS4
"{853A4763-6643-4604-8D64-28BDD8925F4C}" = Apple Application Support
"{86CE85E6-DBAC-3FFD-B977-E4B79F83C909}" = Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570
"{889DF117-14D1-44EE-9F31-C5FB5D47F68B}" = PageRage 1.10.01
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8A15B7D9-908A-4EF9-BA84-5AEDE61743EE}" = Call of Duty(R) 4 - Modern Warfare(TM) 1.6 Patch
"{8ACC73AA-6511-7C55-B1A9-8E5D1DEAFAA3}" = The Lord of the Rings FREE Trial
"{8F0837C2-EE09-4903-88F3-1976FE7FFF4E}" = Autodesk Material Library 2012
"{91130409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office Basic Edition 2003
"{929CE49F-1CA7-4CF3-A9A1-6D757443C63F}" = Microsoft Games for Windows - LIVE Redistributable
"{92D58719-BBC1-4CC3-A08B-56C9E884CC2C}" = Microsoft_VC80_CRT_x86
"{931C37FC-594D-43A9-B10F-A2F2B1F03498}" = Call of Duty(R) 4 - Modern Warfare(TM) 1.7 Patch
"{94D398EB-D2FD-4FD1-B8C4-592635E8A191}" = Adobe CMaps CS4
"{951B0F30-9F1A-4BF6-B3DA-99EB0E917B1C}" = FARO LS 1.1.406.58
"{9559F7CA-5E34-4237-A2D9-D856464AD727}" = Project64 1.6
"{974C4B12-4D02-4879-85E0-61C95CC63E9E}" = Fallout 3
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9DEABCB6-B759-4D52-92F8-51B34A2B4D40}" = Autodesk Material Library 2011
"{a0fe116e-9a8a-466f-aee0-625cb7c207e3}" = Microsoft Visual C++ 2005 Redistributable - KB2467175
"{A2BCA9F1-566C-4805-97D1-7FDC93386723}" = Adobe AIR
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{A462213D-EED4-42C2-9A60-7BDD4D4B0B17}" = SigmaTel Audio
"{A78FE97A-C0C8-49CE-89D0-EDD524A17392}" = PDF Settings CS5
"{AC76BA86-7AD7-1033-7B44-A94000000001}" = Adobe Reader 9.4.4
"{AC76BA86-7AD7-2448-0000-900000000003}" = Chinese Traditional Fonts Support For Adobe Reader 9
"{B05DE7B7-0B40-4411-BD4B-222CAE2D8F15}" = Adobe MotionPicture Color Files CS4
"{B15381DD-FF97-4FCD-A881-ED4DB0975500}" = Adobe Color Video Profiles AE CS4
"{B5751715-EC10-43D9-8C95-62E1368433EF}" = Autodesk Material Library Medium Resolution Image Library 2012
"{B6CF2967-C81E-40C0-9815-C05774FEF120}" = Skype Toolbars
"{B952A4EC-E5E9-47DF-A622-C420D107DD20}" = Verizon Wireless Software Upgrade Assistant - Samsung
"{BB4E33EC-8181-4685-96F7-8554293DEC6A}" = Adobe Output Module
"{BC4CA8FA-41D2-4B81-8680-E9B7573D6500}" = PlayStation(R)Network Downloader
"{BE9CEAAA-F069-4331-BF2F-8D350F6504F4}" = Adobe Media Encoder CS4 Additional Exporter
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{C2E4B5BD-32DB-4817-A060-341AB17C3F90}" = Bonjour
"{C41300B9-185D-475E-BFEC-39EF732F19B1}" = Apple Software Update
"{C52E3EC1-048C-45E1-8D53-10B0C6509683}" = Adobe Default Language CS4
"{C5A56577-49B4-331E-55DC-7143AFFAD108}" = ATI Catalyst Install Manager
"{CACAEB5F-174D-4C7C-AC56-A33289A807CA}" = Apple Mobile Device Support
"{CC75AB5C-2110-4A7F-AF52-708680D22FE8}" = Photoshop Camera Raw
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{D0795B21-0CDA-4a92-AB9E-6E92D8111E44}" = SAMSUNG USB Driver for Mobile Phones
"{D1A19B02-817E-4296-A45B-07853FD74D57}" = Microsoft_VC80_MFC_x86
"{D92BBB52-82FF-42ED-8A3C-4E062F944AB7}" = Microsoft_VC80_MFCLOC_x86
"{DDA34038-89BD-4804-B0B8-DC48D5DFB463}" = Catalyst Control Center - Branding
"{DE3A9DC5-9A5D-6485-9662-347162C7E4CA}" = Adobe Media Player
"{DEB90B8E-0DCB-48CE-B90E-8842A2BD643E}" = Adobe Media Encoder CS4
"{E48469CC-635E-4FD5-A122-1497C286D217}" = Call of Duty(R) 4 - Modern Warfare(TM)
"{E552C39C-C70E-464F-9733-8311331BDD90}" = Autodesk Inventor Fusion plug-in language pack for AutoCAD 2012
"{E6B4523B-A47C-4DBA-918C-D9E220B3F4EC}" = Gabbasoft Cube Demo
"{EAB3AC1A-68FF-486B-9C6B-E48EBB4B05CC}" = Autodesk Inventor Fusion plug-in for AutoCAD 2012
"{ED3866E9-4F50-4A47-9945-58D5C97AB56F}" = Media Go
"{F12B55DE-186C-42CA-E9B4-9FA7B786D023}" = ccc-core-static
"{F4731524-D4E9-2CCD-4471-5ABE373C3691}" = CCC Help English
"{F59A9E08-A6A4-4ACF-91F2-D0344956C30B}" = iTunes
"{F8EF2B3F-C345-4F20-8FE4-791A20333CD5}" = Adobe ExtendScript Toolkit CS4
"{F93C84A6-0DC6-42AF-89FA-776F7C377353}" = Adobe PDF Library Files CS4
"{FCDD51BB-CAD0-4BB1-B7DF-CE86D1032794}" = Adobe Fonts All
"{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022
"{FFF5619F-6669-4EC5-A85E-9994F70A9E5D}" = Autodesk Inventor Fusion 2012
"{FFF7F80F-929E-497F-A112-B070DE816128}" = Autodesk Inventor Fusion 2012 Language Pack
"Adobe AIR" = Adobe AIR
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Adobe Shockwave Player" = Adobe Shockwave Player 11.5
"Adobe_3dcb365ab9e01871fb8c6f27b0ea079" = Adobe After Effects CS4
"AIM_7" = AIM 7
"Akamai" = Akamai NetSession Interface
"Armagetron Advanced" = Armagetron Advanced 0.2.8.3.1.gcc
"ASIO4ALL" = ASIO4ALL
"Audacity 1.3 Beta (Unicode)_is1" = Audacity 1.3.12 (Unicode)
"AutoCAD 2012 - English" = AutoCAD 2012 - English
"Autodesk Inventor Fusion 2012" = Autodesk Inventor Fusion 2012
"Autodesk Inventor Fusion plug-in for AutoCAD 2012" = Autodesk Inventor Fusion plug-in for AutoCAD 2012
"avast" = avast! Free Antivirus
"chc.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Adobe Community Help
"Cheat Engine 5.6.1_is1" = Cheat Engine 5.6.1
"CNXT_MODEM_PCI_VEN_14F1&DEV_2F20&SUBSYS_200F14F1" = Conexant D850 56K V.9x DFVc Modem
"com.adobe.amp.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Adobe Media Player
"conduitEngine" = Conduit Engine
"CTMBDemo" = Sound Blaster Audigy ADVANCED MB Demo
"Dell Photo AIO Printer 964" = Dell Photo AIO Printer 964
"Dev-C++" = Dev-C++ 5 beta 9 release (4.9.9.2)
"DivX Setup.divx.com" = DivX Setup
"DWG TrueView 2011" = DWG TrueView 2011
"Fallout New Vegas_is1" = Fallout New Vegas
"FL Studio 9" = FL Studio 9
"Fraps" = Fraps (remove only)
"Game Booster_is1" = Game Booster
"GameSpy Arcade" = GameSpy Arcade
"GGE909 PC Recoil Pad" = GGE909 PC Recoil Pad
"Graffiti Studio 2.0_is1" = Graffiti Studio 2.0
"Half-Life Dedicated Server Update Tool" = Half-Life Dedicated Server Update Tool
"Halo" = Microsoft Halo
"Hardcore" = Hardcore
"ie8" = Windows Internet Explorer 8
"IL Download Manager" = IL Download Manager
"InstallShield_{52504CE6-E909-4113-B232-4AFEC6543A61}" = Broadcom 440x 10/100 Integrated Controller
"InstallShield_{8A15B7D9-908A-4EF9-BA84-5AEDE61743EE}" = Call of Duty(R) 4 - Modern Warfare(TM) 1.6 Patch
"InstallShield_{931C37FC-594D-43A9-B10F-A2F2B1F03498}" = Call of Duty(R) 4 - Modern Warfare(TM) 1.7 Patch
"InstallShield_{E48469CC-635E-4FD5-A122-1497C286D217}" = Call of Duty(R) 4 - Modern Warfare(TM)
"JDownloader" = JDownloader
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"Microsoft .NET Framework 4 Extended" = Microsoft .NET Framework 4 Extended
"MIXERLITE" = Mixer
"Mozilla Firefox (3.6.17)" = Mozilla Firefox (3.6.17)
"MSCompPackV1" = Microsoft Compression Client Pack 1.0 for Windows XP
"MusicManager" = Music Manager
"ObjectDock" = ObjectDock
"PageRage Toolbar" = PageRage Toolbar
"PoiZone" = PoiZone
"PowerISO" = PowerISO
"PROSet" = Intel(R) PRO Network Connections Drivers
"RealPlayer 12.0" = RealPlayer
"Revo Uninstaller" = Revo Uninstaller 1.92
"Sakura" = Sakura
"Sawer" = Sawer
"SoftwareUpdUtility" = Download Updater (AOL LLC)
"ST6UNST #1" = RCON 4 Call Of Duty Beta 0.4
"Steam App 240" = Counter-Strike: Source
"Steam App 260" = Counter-Strike: Source Beta
"TeamViewer 6" = TeamViewer 6
"uTorrent" = µTorrent
"Windows Media Format Runtime" = Windows Media Format 11 runtime
"Windows Media Player" = Windows Media Player 11
"Windows XP Service Pack" = Windows XP Service Pack 3
"WinRAR archiver" = WinRAR archiver
"WMFDist11" = Windows Media Format 11 runtime
"wmp11" = Windows Media Player 11
"Wudf01000" = Microsoft User-Mode Driver Framework Feature Pack 1.0
"Xfire" = Xfire (remove only)
"Xvid_is1" = Xvid 1.2.1 final uninstall

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Google Chrome" = Google Chrome
"Pong Project" = Pong Project

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 2/5/2011 4:13:29 PM | Computer Name = FAMILIASALINAS | Source = Application Error | ID = 1000
Description = Faulting application hl2.exe, version 0.0.0.0, faulting module vstdlib.dll,
version 0.0.0.0, fault address 0x00001422.

Error - 2/9/2011 8:42:47 AM | Computer Name = FAMILIASALINAS | Source = Application Error | ID = 1000
Description = Faulting application itunes.exe, version 10.1.2.17, faulting module
quicktime.qts, version 7.69.80.9, fault address 0x00104124.

Error - 2/19/2011 10:08:34 PM | Computer Name = FAMILIASALINAS | Source = Application Error | ID = 1000
Description = Faulting application explorer.exe, version 6.0.2900.5512, faulting
module unknown, version 0.0.0.0, fault address 0x06619290.

Error - 2/19/2011 10:08:44 PM | Computer Name = FAMILIASALINAS | Source = Application Error | ID = 1000
Description = Faulting application drwtsn32.exe, version 5.1.2600.0, faulting module
dbghelp.dll, version 5.1.2600.5512, fault address 0x0001295d.

Error - 2/19/2011 10:09:56 PM | Computer Name = FAMILIASALINAS | Source = Application Hang | ID = 1002
Description = Hanging application explorer.exe, version 6.0.2900.5512, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.

Error - 2/21/2011 8:43:28 PM | Computer Name = FAMILIASALINAS | Source = Application Error | ID = 1000
Description = Faulting application explorer.exe, version 6.0.2900.5512, faulting
module unknown, version 0.0.0.0, fault address 0x046e9290.

Error - 2/21/2011 8:49:47 PM | Computer Name = FAMILIASALINAS | Source = Application Hang | ID = 1002
Description = Hanging application explorer.exe, version 6.0.2900.5512, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.

Error - 2/21/2011 9:12:54 PM | Computer Name = FAMILIASALINAS | Source = Halo | ID = 1000
Description = Faulting application haloceded.exe, version 1.0.7.615, faulting module
haloceded.exe, version 1.0.7.615, fault address 0x0006d4cc.

Error - 2/21/2011 9:15:11 PM | Computer Name = FAMILIASALINAS | Source = Halo | ID = 1000
Description = Faulting application haloceded.exe, version 1.0.7.615, faulting module
haloceded.exe, version 1.0.7.615, fault address 0x0006d4cc.

Error - 2/26/2011 9:20:58 PM | Computer Name = FAMILIASALINAS | Source = Application Error | ID = 1000
Description = Faulting application istudio.exe, version 1.0.23.1, faulting module
ntdll.dll, version 5.1.2600.6055, fault address 0x00019af2.

[ System Events ]
Error - 6/8/2011 10:31:47 PM | Computer Name = FAMILIASALINAS | Source = Service Control Manager | ID = 7009
Description = Timeout (30000 milliseconds) waiting for the Autodesk Content Service
service to connect.

Error - 6/8/2011 10:31:47 PM | Computer Name = FAMILIASALINAS | Source = Service Control Manager | ID = 7000
Description = The Autodesk Content Service service failed to start due to the following
error: %%1053

Error - 6/8/2011 10:45:44 PM | Computer Name = FAMILIASALINAS | Source = Service Control Manager | ID = 7034
Description = The Ati HotKey Poller service terminated unexpectedly. It has done
this 1 time(s).

Error - 6/8/2011 10:45:44 PM | Computer Name = FAMILIASALINAS | Source = Service Control Manager | ID = 7031
Description = The Apple Mobile Device service terminated unexpectedly. It has done
this 1 time(s). The following corrective action will be taken in 60000 milliseconds:
Restart the service.

Error - 6/8/2011 10:45:44 PM | Computer Name = FAMILIASALINAS | Source = Service Control Manager | ID = 7034
Description = The Bonjour Service service terminated unexpectedly. It has done
this 1 time(s).

Error - 6/8/2011 10:45:44 PM | Computer Name = FAMILIASALINAS | Source = Service Control Manager | ID = 7034
Description = The PnkBstrA service terminated unexpectedly. It has done this 1
time(s).

Error - 6/8/2011 10:45:44 PM | Computer Name = FAMILIASALINAS | Source = Service Control Manager | ID = 7034
Description = The Java Quick Starter service terminated unexpectedly. It has done
this 1 time(s).

Error - 6/8/2011 10:45:44 PM | Computer Name = FAMILIASALINAS | Source = Service Control Manager | ID = 7034
Description = The iPod Service service terminated unexpectedly. It has done this
1 time(s).

Error - 6/8/2011 10:52:46 PM | Computer Name = FAMILIASALINAS | Source = Service Control Manager | ID = 7022
Description = The Autodesk Content Service service hung on starting.

Error - 6/9/2011 12:14:13 PM | Computer Name = FAMILIASALINAS | Source = Service Control Manager | ID = 7022
Description = The Autodesk Content Service service hung on starting.


< End of report >

5 Re: WhiteSmoke MBAM Logs on Fri Jun 10, 2011 9:59 am

dr09294


Member
Member
I NEED HELP PLZ!!

i think its been getting worse!!!!!! the boot time has gotten dramatically slower, im talking about atleast 3 min just to boot to the desktom and probably like a good 4 or 5 min just to load up all my icons and my doc!!! i ran another MBAM scan and avast scan, avast didn't come up with any infested files, but MBAM caome up with a couple new files.... il post the MBAM log and a new OTL Log incase anything changed.

6 Re: WhiteSmoke MBAM Logs on Fri Jun 10, 2011 10:01 am

dr09294


Member
Member
Malwarebytes' Anti-Malware 1.50.1.1100
www.malwarebytes.org

Database version: 6814

Windows 5.1.2600 Service Pack 3
Internet Explorer 8.0.6001.18702

6/10/2011 7:57:48 AM
mbam-log-2011-06-10 (07-57-48).txt

Scan type: Full scan (D:\|)
Objects scanned: 281681
Time elapsed: 3 hour(s), 5 minute(s), 4 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 3

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
d:\FOLDERS\easy account\easyaccount.exe (RiskWare.Tool.CK) -> Quarantined and deleted successfully.
d:\FOLDERS\cod4 server starters\oshcod4.v1.7\schoolhackcod4multirc5.exe (Backdoor.Bot) -> Quarantined and deleted successfully.
d:\system volume information\_restore{751212c1-5a78-40cc-b976-5dda649c9bde}\RP295\A0063811.exe (Backdoor.Bot) -> Quarantined and deleted successfully.

7 Re: WhiteSmoke MBAM Logs on Fri Jun 10, 2011 10:05 am

dr09294


Member
Member
OTL logfile created on: 6/10/2011 9:02:29 AM - Run 2
OTL by OldTimer - Version 3.2.23.0 Folder = D:\Documents and Settings\Familia Salinas\Desktop
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

2.00 Gb Total Physical Memory | 1.34 Gb Available Physical Memory | 66.84% Memory free
3.72 Gb Paging File | 3.18 Gb Available in Paging File | 85.40% Paging File free
Paging file location(s): D:\pagefile.sys 1920 3840 [binary data]

%SystemDrive% = D: | %SystemRoot% = D:\WINDOWS | %ProgramFiles% = D:\Program Files
Drive C: | 74.50 Gb Total Space | 10.01 Gb Free Space | 13.44% Space Free | Partition Type: NTFS
Drive D: | 74.50 Gb Total Space | 8.17 Gb Free Space | 10.96% Space Free | Partition Type: NTFS

Computer Name: FAMILIASALINAS | User Name: Familia Salinas | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - [2011/06/09 11:16:17 | 000,580,096 | ---- | M] (OldTimer Tools) -- D:\Documents and Settings\Familia Salinas\Desktop\OTL.exe
PRC - [2011/06/06 00:28:58 | 001,011,768 | ---- | M] (Google Inc.) -- D:\Documents and Settings\Familia Salinas\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
PRC - [2011/05/10 07:10:58 | 003,459,712 | ---- | M] (AVAST Software) -- D:\Program Files\Alwil Software\Avast5\AvastUI.exe
PRC - [2011/05/10 07:10:57 | 000,042,184 | ---- | M] (AVAST Software) -- D:\Program Files\Alwil Software\Avast5\AvastSvc.exe
PRC - [2011/04/13 15:42:36 | 000,196,608 | ---- | M] (Samsung Electronics Co. Ltd.) -- D:\Documents and Settings\Familia Salinas\Application Data\Verizon\SUA\VZWSUAM.exe
PRC - [2011/02/02 14:08:16 | 000,018,656 | ---- | M] () -- D:\Program Files\Autodesk\Content Service\Connect.Service.ContentService.exe
PRC - [2011/01/20 17:20:34 | 000,426,840 | ---- | M] (IObit) -- D:\Program Files\IObit\Game Booster 2\gbtray.exe
PRC - [2010/12/08 20:59:00 | 000,274,608 | ---- | M] (RealNetworks, Inc.) -- D:\Program Files\Real\RealPlayer\Update\realsched.exe
PRC - [2010/09/16 15:04:06 | 001,164,584 | ---- | M] () -- D:\Program Files\DivX\DivX Update\DivXUpdate.exe
PRC - [2010/04/12 03:40:16 | 000,180,224 | ---- | M] (PowerISO Computing, Inc.) -- D:\Program Files\PowerISO\PWRISOVM.EXE
PRC - [2008/04/14 05:42:20 | 001,033,728 | ---- | M] (Microsoft Corporation) -- D:\WINDOWS\explorer.exe
PRC - [2007/04/30 19:43:54 | 003,450,608 | ---- | M] (Stardock) -- D:\Program Files\Stardock\ObjectDock\ObjectDock.exe
PRC - [2005/07/12 16:33:02 | 000,491,520 | ---- | M] () -- D:\WINDOWS\system32\dlcjcoms.exe
PRC - [2005/03/22 17:20:44 | 000,339,968 | ---- | M] (SigmaTel, Inc.) -- D:\WINDOWS\stsystra.exe
PRC - [2005/02/23 15:57:24 | 000,057,344 | ---- | M] (Creative Technology Ltd) -- D:\Program Files\Creative\Mixer\CTSVolFE.exe


========== Modules (SafeList) ==========

MOD - [2011/06/09 11:16:17 | 000,580,096 | ---- | M] (OldTimer Tools) -- D:\Documents and Settings\Familia Salinas\Desktop\OTL.exe
MOD - [2011/05/10 07:10:55 | 000,199,792 | ---- | M] (AVAST Software) -- D:\Program Files\Alwil Software\Avast5\snxhk.dll
MOD - [2011/01/11 10:59:44 | 000,653,136 | ---- | M] (Microsoft Corporation) -- D:\WINDOWS\WinSxS\x86_Microsoft.VC90.CRT_1fc8b3b9a1e18e3b_9.0.30729.5570_x-ww_0517bbc6\msvcr90.dll
MOD - [2011/01/11 10:59:44 | 000,569,680 | ---- | M] (Microsoft Corporation) -- D:\WINDOWS\WinSxS\x86_Microsoft.VC90.CRT_1fc8b3b9a1e18e3b_9.0.30729.5570_x-ww_0517bbc6\msvcp90.dll
MOD - [2010/12/08 20:59:20 | 000,040,448 | ---- | M] (RealNetworks, Inc.) -- D:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\Chrome\Hook\rpchromebrowserrecordhelper.dll
MOD - [2010/08/23 11:12:02 | 001,054,208 | ---- | M] (Microsoft Corporation) -- D:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.6028_x-ww_61e65202\comctl32.dll
MOD - [2007/04/30 19:18:50 | 000,112,400 | ---- | M] () -- D:\Program Files\Stardock\ObjectDock\DockShellHook.dll


========== Win32 Services (SafeList) ==========

SRV - File not found [Disabled | Stopped] -- -- (AppMgmt)
SRV - [2011/05/17 18:58:07 | 003,275,864 | ---- | M] () [Auto | Running] -- d:\Program Files\Common Files\Akamai\netsession_win_8832f4b.dll -- (Akamai)
SRV - [2011/05/10 07:10:57 | 000,042,184 | ---- | M] (AVAST Software) [Auto | Running] -- D:\Program Files\Alwil Software\Avast5\AvastSvc.exe -- (avast! Antivirus)
SRV - [2011/04/14 21:02:12 | 001,044,816 | ---- | M] (Flexera Software, Inc.) [On_Demand | Stopped] -- D:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe -- (FLEXnet Licensing Service)
SRV - [2011/03/28 10:35:06 | 000,069,632 | ---- | M] (Creative Labs) [On_Demand | Stopped] -- D:\Program Files\Common Files\Creative Labs Shared\Service\CreativeLicensing.exe -- (Creative Labs Licensing Service)
SRV - [2011/02/02 14:08:16 | 000,018,656 | ---- | M] () [Auto | Running] -- D:\Program Files\Autodesk\Content Service\Connect.Service.ContentService.exe -- (Autodesk Content Service)
SRV - [2010/02/19 13:37:14 | 000,517,096 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- D:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe -- (SwitchBoard)
SRV - [2005/07/12 16:33:02 | 000,491,520 | ---- | M] () [On_Demand | Running] -- D:\WINDOWS\System32\dlcjcoms.exe -- (dlcj_device)


========== Driver Services (SafeList) ==========

DRV - [2011/05/10 07:03:54 | 000,441,176 | ---- | M] (AVAST Software) [File_System | System | Running] -- D:\WINDOWS\System32\drivers\aswSnx.sys -- (aswSnx)
DRV - [2011/05/10 07:03:44 | 000,307,928 | ---- | M] (AVAST Software) [Kernel | System | Running] -- D:\WINDOWS\System32\drivers\aswSP.sys -- (aswSP)
DRV - [2011/05/10 07:02:37 | 000,049,240 | ---- | M] (AVAST Software) [Kernel | System | Running] -- D:\WINDOWS\System32\drivers\aswTdi.sys -- (aswTdi)
DRV - [2011/05/10 07:02:25 | 000,102,616 | ---- | M] (AVAST Software) [File_System | Auto | Running] -- D:\WINDOWS\System32\drivers\aswmon2.sys -- (aswMon2)
DRV - [2011/05/10 06:59:56 | 000,025,432 | ---- | M] (AVAST Software) [Kernel | System | Running] -- D:\WINDOWS\System32\drivers\aswRdr.sys -- (aswRdr)
DRV - [2011/05/10 06:59:37 | 000,030,808 | ---- | M] (AVAST Software) [Kernel | System | Running] -- D:\WINDOWS\System32\drivers\aavmker4.sys -- (Aavmker4)
DRV - [2011/05/10 06:59:35 | 000,019,544 | ---- | M] (AVAST Software) [File_System | Auto | Running] -- D:\WINDOWS\System32\drivers\aswFsBlk.sys -- (aswFsBlk)
DRV - [2010/11/30 11:07:06 | 000,025,088 | ---- | M] (TeamViewer GmbH) [Kernel | On_Demand | Stopped] -- D:\WINDOWS\system32\drivers\teamviewervpn.sys -- (teamviewervpn)
DRV - [2010/09/10 21:19:16 | 005,417,472 | ---- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Running] -- D:\WINDOWS\system32\drivers\ati2mtag.sys -- (ati2mtag)
DRV - [2010/04/26 21:25:20 | 000,132,424 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- D:\WINDOWS\system32\drivers\sscdmdm.sys -- (sscdmdm)
DRV - [2010/04/26 21:25:20 | 000,110,280 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- D:\WINDOWS\system32\drivers\sscdserd.sys -- (sscdserd) SAMSUNG Mobile Modem Diagnostic Serial Port (WDM)
DRV - [2010/04/26 21:25:20 | 000,104,648 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- D:\WINDOWS\system32\drivers\sscdbus.sys -- (sscdbus) SAMSUNG USB Composite Device driver (WDM)
DRV - [2010/04/26 21:25:20 | 000,014,920 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- D:\WINDOWS\system32\drivers\sscdmdfl.sys -- (sscdmdfl)
DRV - [2010/04/12 03:44:34 | 000,059,388 | ---- | M] (PowerISO Computing, Inc.) [Kernel | System | Running] -- D:\WINDOWS\System32\drivers\scdemu.sys -- (SCDEmu)
DRV - [2007/07/20 18:40:10 | 000,084,992 | ---- | M] (ATI Research Inc.) [Kernel | On_Demand | Running] -- D:\WINDOWS\system32\drivers\AtiHdmi.sys -- (AtiHdmiService)
DRV - [2006/01/07 12:09:50 | 000,007,548 | ---- | M] () [Kernel | On_Demand | Running] -- D:\WINDOWS\system32\drivers\Samhid.sys -- (samhid)
DRV - [2005/11/16 15:36:00 | 001,047,816 | ---- | M] (SigmaTel, Inc.) [Kernel | On_Demand | Running] -- D:\WINDOWS\system32\drivers\sthda.sys -- (STHDA)
DRV - [2005/09/24 00:18:32 | 000,171,520 | ---- | M] (Pinnacle Systems GmbH) [Kernel | On_Demand | Stopped] -- D:\WINDOWS\system32\drivers\MarvinBus.sys -- (MarvinBus)
DRV - [2003/11/17 15:59:20 | 000,212,224 | ---- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Running] -- D:\WINDOWS\system32\drivers\HSFHWBS2.sys -- (HSFHWBS2)
DRV - [2003/11/17 15:58:02 | 000,680,704 | ---- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Running] -- D:\WINDOWS\system32\drivers\HSF_CNXT.sys -- (winachsf)
DRV - [2003/11/17 15:56:26 | 001,042,432 | ---- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Running] -- D:\WINDOWS\system32\drivers\HSF_DP.sys -- (HSF_DP)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========


IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://search.conduit.com?SearchSource=10&ctid=CT3007394
IE - HKCU\..\URLSearchHook: - Reg Error: Key error. File not found
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local

========== FireFox ==========

FF - prefs.js..browser.search.defaultthis.engineName: "WhiteSmoke Bar Customized Web Search"
FF - prefs.js..browser.search.defaulturl: "http://search.conduit.com/ResultsExt.aspx?ctid=CT3007394&SearchSource=3&q={searchTerms}"
FF - prefs.js..browser.search.selectedEngine: "WhiteSmoke Bar Customized Web Search"
FF - prefs.js..browser.startup.homepage: "http://www.google.com"
FF - prefs.js..extensions.enabledItems: {a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7}:20100908
FF - prefs.js..extensions.enabledItems: {01A8CA0A-4C96-465b-A49B-65C46FAD54F9}:6.0
FF - prefs.js..extensions.enabledItems: {ABDE892B-13A8-4d1b-88E6-365A6E755758}:14.0.1
FF - prefs.js..extensions.enabledItems: wrc@avast.com:20110101
FF - prefs.js..network.proxy.ftp: "123123"
FF - prefs.js..network.proxy.gopher: "12312"
FF - prefs.js..network.proxy.http: "231321"
FF - prefs.js..network.proxy.no_proxies_on: "12312"
FF - prefs.js..network.proxy.socks: "123123"
FF - prefs.js..network.proxy.ssl: "1232"
FF - prefs.js..network.proxy.type: 1


FF - HKLM\software\mozilla\Firefox\Extensions\\{01A8CA0A-4C96-465b-A49B-65C46FAD54F9}: C:\Program Files\Adobe\Adobe Contribute CS5\Plugins\FirefoxPlugin\{01A8CA0A-4C96-465b-A49B-65C46FAD54F9} [2010/08/15 16:43:19 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\{ABDE892B-13A8-4d1b-88E6-365A6E755758}: D:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext [2010/12/08 20:59:20 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\m3ffxtbr@mywebsearch.com: D:\Program Files\MyWebSearch\bar\1.bin
FF - HKLM\software\mozilla\Firefox\Extensions\\wrc@avast.com: D:\Program Files\Alwil Software\Avast5\WebRep\FF [2011/06/08 21:35:04 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.17\extensions\\Components: D:\Program Files\Mozilla Firefox\components [2011/05/05 07:02:37 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.17\extensions\\Plugins: D:\Program Files\Mozilla Firefox\plugins [2011/05/10 16:04:37 | 000,000,000 | ---D | M]

[2010/08/21 20:18:12 | 000,000,000 | ---D | M] (No name found) -- D:\Documents and Settings\Familia Salinas\Application Data\Mozilla\Extensions
[2010/08/20 11:23:43 | 000,000,000 | ---D | M] (No name found) -- D:\Documents and Settings\Familia Salinas\Application Data\Mozilla\Extensions\mozswing@mozswing.org
[2011/06/09 11:35:14 | 000,000,000 | ---D | M] (No name found) -- D:\Documents and Settings\Familia Salinas\Application Data\Mozilla\Firefox\Profiles\sjhkgozz.default\extensions
[2010/12/19 21:47:30 | 000,000,000 | ---D | M] (No name found) -- D:\Documents and Settings\Familia Salinas\Application Data\Mozilla\Firefox\Profiles\sjhkgozz.default\extensions\{000F1EA4-5E08-4564-A29B-29076F63A37A}
[2010/08/27 18:35:42 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- D:\Documents and Settings\Familia Salinas\Application Data\Mozilla\Firefox\Profiles\sjhkgozz.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2011/03/25 15:00:44 | 000,000,000 | ---D | M] (No name found) -- D:\Documents and Settings\Familia Salinas\Application Data\Mozilla\Firefox\Profiles\sjhkgozz.default\extensions\{7b13ec3e-999a-4b70-b9cb-2617b8323822}
[2010/10/29 20:28:40 | 000,000,000 | ---D | M] (WOT) -- D:\Documents and Settings\Familia Salinas\Application Data\Mozilla\Firefox\Profiles\sjhkgozz.default\extensions\{a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7}
[2011/03/25 15:00:44 | 000,000,000 | ---D | M] (No name found) -- D:\Documents and Settings\Familia Salinas\Application Data\Mozilla\Firefox\Profiles\sjhkgozz.default\extensions\staged-xpis
[2010/12/25 16:04:45 | 000,001,919 | ---- | M] () -- D:\Documents and Settings\Familia Salinas\Application Data\Mozilla\Firefox\Profiles\sjhkgozz.default\searchplugins\bing-zugo.xml
[2011/06/06 13:58:08 | 000,000,931 | ---- | M] () -- D:\Documents and Settings\Familia Salinas\Application Data\Mozilla\Firefox\Profiles\sjhkgozz.default\searchplugins\conduit.xml
[2011/04/06 20:26:35 | 000,009,932 | ---- | M] () -- D:\Documents and Settings\Familia Salinas\Application Data\Mozilla\Firefox\Profiles\sjhkgozz.default\searchplugins\mywebsearch.xml
[2011/06/09 11:35:20 | 000,000,000 | ---D | M] (No name found) -- D:\Program Files\Mozilla Firefox\extensions
[2010/08/15 16:43:19 | 000,000,000 | ---D | M] (Adobe Contribute Toolbar) -- C:\PROGRAM FILES\ADOBE\ADOBE CONTRIBUTE CS5\PLUGINS\FIREFOXPLUGIN\{01A8CA0A-4C96-465B-A49B-65C46FAD54F9}
[2010/12/08 20:59:20 | 000,000,000 | ---D | M] (RealPlayer Browser Record Plugin) -- D:\DOCUMENTS AND SETTINGS\ALL USERS\APPLICATION DATA\REAL\REALPLAYER\BROWSERRECORDPLUGIN\FIREFOX\EXT
[2011/06/08 21:35:04 | 000,000,000 | ---D | M] (avast! WebRep) -- D:\PROGRAM FILES\ALWIL SOFTWARE\AVAST5\WEBREP\FF
[2011/03/12 10:59:10 | 000,472,808 | ---- | M] (Sun Microsystems, Inc.) -- D:\Program Files\Mozilla Firefox\plugins\npdeployJava1.dll

O1 HOSTS File: ([2003/07/16 15:29:34 | 000,000,734 | ---- | M]) - D:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (ContributeBHO Class) - {074C1DC5-9320-4A9A-947D-C042949C6216} - C:\Program Files\Adobe\Adobe Contribute CS5\Plugins\IEPlugin\contributeieplugin.dll (Adobe Systems, Inc.)
O2 - BHO: (RealPlayer Download and Record Plugin for Internet Explorer) - {3049C3E9-B461-4BC5-8870-4C09146192CA} - D:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll (RealPlayer)
O2 - BHO: (avast! WebRep) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - D:\Program Files\Alwil Software\Avast5\aswWebRepIE.dll (AVAST Software)
O2 - BHO: (no name) - {9D425283-D487-4337-BAB6-AB8354A81457} - No CLSID value found.
O2 - BHO: (Skype Browser Helper) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - D:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O3 - HKLM\..\Toolbar: (Contribute Toolbar) - {517BDDE4-E3A7-4570-B21E-2B52B6139FC7} - C:\Program Files\Adobe\Adobe Contribute CS5\Plugins\IEPlugin\contributeieplugin.dll (Adobe Systems, Inc.)
O3 - HKLM\..\Toolbar: (avast! WebRep) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - D:\Program Files\Alwil Software\Avast5\aswWebRepIE.dll (AVAST Software)
O3 - HKLM\..\Toolbar: (no name) - {9D425283-D487-4337-BAB6-AB8354A81457} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {9D425283-D487-4337-BAB6-AB8354A81457} - No CLSID value found.
O4 - HKLM..\Run: [AdobeAAMUpdater-1.0] D:\Program Files\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [AdobeCS5ServiceManager] D:\Program Files\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [ATICustomerCare] D:\Program Files\ATI\ATICustomerCare\ATICustomerCare.exe (Advanced Micro Devices, Inc.)
O4 - HKLM..\Run: [avast5] D:\Program Files\Alwil Software\Avast5\AvastUI.exe (AVAST Software)
O4 - HKLM..\Run: [CTSVolFE] D:\Program Files\Creative\Mixer\CTSVolFE.exe (Creative Technology Ltd)
O4 - HKLM..\Run: [DivXUpdate] D:\Program Files\DivX\DivX Update\DivXUpdate.exe ()
O4 - HKLM..\Run: [PWRISOVM.EXE] D:\Program Files\PowerISO\PWRISOVM.EXE (PowerISO Computing, Inc.)
O4 - HKLM..\Run: [SigmatelSysTrayApp] D:\WINDOWS\stsystra.exe (SigmaTel, Inc.)
O4 - HKLM..\Run: [StartCCC] D:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.)
O4 - HKLM..\Run: [SwitchBoard] D:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [TkBellExe] D:\Program Files\Real\RealPlayer\update\realsched.exe (RealNetworks, Inc.)
O4 - HKCU..\Run: [] File not found
O4 - HKCU..\Run: [AdobeBridge] File not found
O4 - HKCU..\Run: [DW6] D:\Program Files\The Weather Channel FW\Desktop\DesktopWeather.exe (The Weather Channel Interactive, Inc.)
O4 - HKCU..\Run: [VZWSUAM] D:\Documents and Settings\Familia Salinas\Application Data\Verizon\SUA\VZWSUAM.exe (Samsung Electronics Co. Ltd.)
O4 - HKLM..\RunOnce: [Malwarebytes' Anti-Malware] D:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
O4 - Startup: D:\Documents and Settings\Familia Salinas\Start Menu\Programs\Startup\Stardock ObjectDock.lnk = D:\Program Files\Stardock\ObjectDock\ObjectDock.exe (Stardock)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Infodelivery present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O9 - Extra Button: Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - D:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - D:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - D:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab (Java Plug-in 1.6.0_24)
O16 - DPF: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab (Java Plug-in 1.6.0_24)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab (Java Plug-in 1.6.0_24)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - D:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - D:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - D:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\AtiExtEvent: DllName - Ati2evxx.dll - D:\WINDOWS\System32\ati2evxx.dll (ATI Technologies Inc.)
O24 - Desktop WallPaper: D:\Documents and Settings\Familia Salinas\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: D:\Documents and Settings\Familia Salinas\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2011/04/14 19:47:49 | 000,000,000 | ---D | M] - C:\Autodesk -- [ NTFS ]
O32 - AutoRun File - [2010/06/25 17:54:03 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O33 - MountPoints2\{0dfb8330-1f45-11e0-8d9c-00123fbdf875}\Shell - "" = AutoRun
O33 - MountPoints2\{0dfb8330-1f45-11e0-8d9c-00123fbdf875}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{0dfb8330-1f45-11e0-8d9c-00123fbdf875}\Shell\AutoRun\command - "" = K:\iStudio.exe
O33 - MountPoints2\{457ee501-4806-11e0-8da0-00123fbdf875}\Shell - "" = AutoRun
O33 - MountPoints2\{457ee501-4806-11e0-8da0-00123fbdf875}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{457ee501-4806-11e0-8da0-00123fbdf875}\Shell\AutoRun\command - "" = E:\TLBootstrap_WPP.exe
O33 - MountPoints2\{54abd8fb-6708-11e0-8da6-00123fbdf875}\Shell - "" = AutoRun
O33 - MountPoints2\{54abd8fb-6708-11e0-8da6-00123fbdf875}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{54abd8fb-6708-11e0-8da6-00123fbdf875}\Shell\AutoRun\command - "" = H:\TLBootstrap_WPP.exe
O33 - MountPoints2\{764e5e9b-a896-11df-8d74-d89a143a0a40}\Shell - "" = AutoRun
O33 - MountPoints2\{764e5e9b-a896-11df-8d74-d89a143a0a40}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{764e5e9b-a896-11df-8d74-d89a143a0a40}\Shell\AutoRun\command - "" = H:\LaunchU3.exe -a
O33 - MountPoints2\{83e4026b-a899-11df-8d75-00123fbdf875}\Shell - "" = AutoRun
O33 - MountPoints2\{83e4026b-a899-11df-8d75-00123fbdf875}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{83e4026b-a899-11df-8d75-00123fbdf875}\Shell\AutoRun\command - "" = E:\LaunchU3.exe -a
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*

========== Files/Folders - Created Within 30 Days ==========

[2011/06/09 11:16:13 | 000,580,096 | ---- | C] (OldTimer Tools) -- D:\Documents and Settings\Familia Salinas\Desktop\OTL.exe
[2011/06/08 21:42:01 | 000,446,464 | ---- | C] (OldTimer Tools) -- D:\Documents and Settings\Familia Salinas\Desktop\TFC.exe
[2011/06/08 21:41:42 | 000,000,000 | ---D | C] -- D:\Documents and Settings\Familia Salinas\Desktop\New Folder
[2011/06/08 21:35:07 | 000,441,176 | ---- | C] (AVAST Software) -- D:\WINDOWS\System32\drivers\aswSnx.sys
[2011/06/08 21:12:23 | 000,000,000 | ---D | C] -- D:\Documents and Settings\Familia Salinas\Application Data\Malwarebytes
[2011/06/08 21:12:19 | 000,039,984 | ---- | C] (Malwarebytes Corporation) -- D:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2011/06/08 21:12:19 | 000,000,000 | ---D | C] -- D:\Documents and Settings\All Users\Start Menu\Programs\Malwarebytes' Anti-Malware
[2011/06/08 21:12:18 | 000,000,000 | ---D | C] -- D:\Documents and Settings\All Users\Application Data\Malwarebytes
[2011/06/08 21:12:15 | 000,022,712 | ---- | C] (Malwarebytes Corporation) -- D:\WINDOWS\System32\drivers\mbam.sys
[2011/06/08 21:12:15 | 000,000,000 | ---D | C] -- D:\Program Files\Malwarebytes' Anti-Malware
[2011/06/08 21:09:54 | 000,000,000 | ---D | C] -- D:\Program Files\VS Revo Group
[2011/06/08 21:09:54 | 000,000,000 | ---D | C] -- D:\Documents and Settings\Familia Salinas\Start Menu\Programs\Revo Uninstaller
[2011/06/05 15:49:07 | 000,000,000 | ---D | C] -- D:\Documents and Settings\Familia Salinas\Desktop\New Folder (2)
[2011/05/26 07:44:51 | 000,000,000 | -HSD | C] -- D:\Documents and Settings\Familia Salinas\IECompatCache
[2011/05/21 12:52:10 | 000,000,000 | ---D | C] -- D:\Documents and Settings\Familia Salinas\My Documents\GTA San Andreas User Files
[2011/05/19 19:25:26 | 000,000,000 | ---D | C] -- D:\Documents and Settings\Familia Salinas\My Documents\old pictures
[2011/05/14 18:43:04 | 000,000,000 | ---D | C] -- D:\Documents and Settings\All Users\Application Data\Skype Extras
[2011/05/14 18:42:50 | 000,000,000 | ---D | C] -- D:\Program Files\Common Files\Skype
[2011/05/14 18:42:50 | 000,000,000 | ---D | C] -- D:\Documents and Settings\All Users\Start Menu\Programs\Skype
[2011/05/11 15:31:45 | 000,000,000 | ---D | C] -- D:\Documents and Settings\All Users\Start Menu\Programs\iTunes
[2011/05/11 15:30:27 | 000,000,000 | ---D | C] -- D:\Program Files\iPod
[2011/05/11 15:23:24 | 000,000,000 | ---D | C] -- D:\Program Files\Bonjour

========== Files - Modified Within 30 Days ==========

[2011/06/10 08:53:31 | 000,000,442 | -H-- | M] () -- D:\WINDOWS\tasks\User_Feed_Synchronization-{552E9B33-67C4-4751-8644-F10FBF41E711}.job
[2011/06/10 08:53:09 | 000,001,018 | ---- | M] () -- D:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1708537768-507921405-725345543-1004UA.job
[2011/06/10 08:02:53 | 000,000,298 | ---- | M] () -- D:\WINDOWS\tasks\RealUpgradeLogonTaskS-1-5-21-1708537768-507921405-725345543-1004.job
[2011/06/10 08:02:44 | 000,000,306 | ---- | M] () -- D:\WINDOWS\tasks\RealUpgradeScheduledTaskS-1-5-21-1708537768-507921405-725345543-1004.job
[2011/06/10 07:59:58 | 000,000,272 | ---- | M] () -- D:\WINDOWS\tasks\Game_Booster_Startup.job
[2011/06/10 07:59:45 | 000,002,048 | --S- | M] () -- D:\WINDOWS\bootstat.dat
[2011/06/10 04:53:00 | 000,000,966 | ---- | M] () -- D:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1708537768-507921405-725345543-1004Core.job
[2011/06/10 02:00:00 | 000,000,362 | ---- | M] () -- D:\WINDOWS\tasks\AdobeAAMUpdater-1.0-FAMILIASALINAS-Familia Salinas.job
[2011/06/09 11:16:17 | 000,580,096 | ---- | M] (OldTimer Tools) -- D:\Documents and Settings\Familia Salinas\Desktop\OTL.exe
[2011/06/08 21:42:02 | 000,446,464 | ---- | M] (OldTimer Tools) -- D:\Documents and Settings\Familia Salinas\Desktop\TFC.exe
[2011/06/08 21:35:07 | 000,002,626 | ---- | M] () -- D:\WINDOWS\System32\CONFIG.NT
[2011/06/08 21:12:19 | 000,000,784 | ---- | M] () -- D:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2011/06/08 21:09:54 | 000,000,917 | ---- | M] () -- D:\Documents and Settings\Familia Salinas\Desktop\Revo Uninstaller.lnk
[2011/06/08 21:01:24 | 000,002,206 | ---- | M] () -- D:\WINDOWS\System32\wpa.dbl
[2011/06/03 21:35:01 | 000,058,526 | ---- | M] () -- D:\Documents and Settings\Familia Salinas\My Documents\My Feet - Inches Setup.dwt
[2011/06/03 21:34:59 | 000,058,590 | ---- | M] () -- D:\Documents and Settings\Familia Salinas\My Documents\My Feet - Inches Setup 2.dwt
[2011/06/01 09:50:01 | 000,000,284 | ---- | M] () -- D:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2011/06/01 06:00:00 | 000,000,456 | ---- | M] () -- D:\WINDOWS\tasks\DriverNavigator Scheduled Scan.job
[2011/05/29 09:11:30 | 000,039,984 | ---- | M] (Malwarebytes Corporation) -- D:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2011/05/29 09:11:20 | 000,022,712 | ---- | M] (Malwarebytes Corporation) -- D:\WINDOWS\System32\drivers\mbam.sys
[2011/05/24 19:51:45 | 000,000,833 | ---- | M] () -- D:\Documents and Settings\Familia Salinas\Desktop\Shortcut to GTA-SA Crazy Trainer.lnk
[2011/05/23 15:52:50 | 000,000,180 | ---- | M] () -- D:\WINDOWS\System32\sam.ini
[2011/05/23 09:56:46 | 000,043,520 | ---- | M] () -- D:\Documents and Settings\Familia Salinas\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/05/11 15:21:33 | 000,001,854 | ---- | M] () -- D:\Documents and Settings\Familia Salinas\Application Data\Microsoft\Internet Explorer\Quick Launch\Apple Safari.lnk

========== Files Created - No Company Name ==========

[2011/06/08 21:12:19 | 000,000,784 | ---- | C] () -- D:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2011/06/08 21:09:54 | 000,000,917 | ---- | C] () -- D:\Documents and Settings\Familia Salinas\Desktop\Revo Uninstaller.lnk
[2011/06/03 21:35:01 | 000,058,526 | ---- | C] () -- D:\Documents and Settings\Familia Salinas\My Documents\My Feet - Inches Setup.dwt
[2011/06/03 21:34:59 | 000,058,590 | ---- | C] () -- D:\Documents and Settings\Familia Salinas\My Documents\My Feet - Inches Setup 2.dwt
[2011/05/26 07:41:47 | 000,000,442 | -H-- | C] () -- D:\WINDOWS\tasks\User_Feed_Synchronization-{552E9B33-67C4-4751-8644-F10FBF41E711}.job
[2011/05/24 19:51:45 | 000,000,833 | ---- | C] () -- D:\Documents and Settings\Familia Salinas\Desktop\Shortcut to GTA-SA Crazy Trainer.lnk
[2011/05/23 09:54:45 | 000,000,180 | ---- | C] () -- D:\WINDOWS\System32\sam.ini
[2011/04/23 19:10:40 | 000,487,424 | ---- | C] () -- D:\WINDOWS\System32\FDRpage.dll
[2011/04/23 19:10:40 | 000,007,548 | ---- | C] () -- D:\WINDOWS\System32\drivers\Samhid.sys
[2011/04/23 19:10:33 | 000,192,512 | ---- | C] () -- D:\WINDOWS\System32\CreateDir.exe
[2011/04/21 03:19:54 | 000,531,586 | ---- | C] () -- D:\Documents and Settings\LocalService\Local Settings\Application Data\WPFFontCache_v0400-S-1-5-21-1708537768-507921405-725345543-1004-0.dat
[2011/04/21 03:19:53 | 000,265,930 | ---- | C] () -- D:\Documents and Settings\LocalService\Local Settings\Application Data\WPFFontCache_v0400-System.dat
[2011/04/14 21:03:05 | 000,000,147 | ---- | C] () -- D:\Documents and Settings\All Users\Application Data\Microsoft.SqlServer.Compact.351.32.bc
[2011/02/25 20:19:32 | 000,041,872 | ---- | C] () -- D:\WINDOWS\System32\xfcodec.dll
[2011/02/10 17:31:36 | 000,643,640 | ---- | C] () -- D:\Documents and Settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
[2010/11/19 21:06:17 | 000,000,664 | ---- | C] () -- D:\WINDOWS\System32\d3d9caps.dat
[2010/10/17 12:24:29 | 000,815,104 | ---- | C] () -- D:\WINDOWS\System32\xvidcore.dll
[2010/10/17 12:24:29 | 000,180,224 | ---- | C] () -- D:\WINDOWS\System32\xvidvfw.dll
[2010/09/25 20:28:24 | 001,970,176 | ---- | C] () -- D:\WINDOWS\System32\d3dx9.dll
[2010/09/05 19:16:11 | 000,000,096 | -H-- | C] () -- D:\WINDOWS\System32\HsInfo.dat
[2010/09/01 18:56:14 | 000,000,376 | ---- | C] () -- D:\WINDOWS\ODBC.INI
[2010/08/25 06:32:24 | 000,040,960 | R--- | C] () -- D:\WINDOWS\System32\dlcjvs.dll
[2010/08/25 06:31:09 | 001,183,744 | ---- | C] () -- D:\WINDOWS\System32\dlcjserv.dll
[2010/08/25 06:31:09 | 001,122,304 | ---- | C] () -- D:\WINDOWS\System32\dlcjusb1.dll
[2010/08/25 06:31:09 | 000,155,648 | ---- | C] () -- D:\WINDOWS\System32\dlcjprox.dll
[2010/08/25 06:31:09 | 000,114,688 | ---- | C] () -- D:\WINDOWS\System32\dlcjpplc.dll
[2010/08/25 06:31:08 | 000,770,048 | ---- | C] () -- D:\WINDOWS\System32\dlcjhbn3.dll
[2010/08/25 06:31:08 | 000,704,512 | ---- | C] () -- D:\WINDOWS\System32\dlcjcomc.dll
[2010/08/25 06:31:08 | 000,630,784 | ---- | C] () -- D:\WINDOWS\System32\dlcjpmui.dll
[2010/08/25 06:31:08 | 000,491,520 | ---- | C] () -- D:\WINDOWS\System32\dlcjcoms.exe
[2010/08/25 06:31:08 | 000,413,696 | ---- | C] () -- D:\WINDOWS\System32\dlcjcomm.dll
[2010/08/25 06:31:08 | 000,372,736 | ---- | C] () -- D:\WINDOWS\System32\dlcjih.exe
[2010/08/25 06:31:07 | 000,491,520 | ---- | C] () -- D:\WINDOWS\System32\dlcjlmpm.dll
[2010/08/25 06:31:07 | 000,430,080 | ---- | C] () -- D:\WINDOWS\System32\dlcjutil.dll
[2010/08/25 06:31:07 | 000,368,640 | ---- | C] () -- D:\WINDOWS\System32\dlcjcfg.exe
[2010/08/25 06:31:03 | 000,131,072 | ---- | C] () -- D:\WINDOWS\System32\dlcjjswr.dll
[2010/08/25 06:31:02 | 000,176,128 | ---- | C] () -- D:\WINDOWS\System32\dlcjinsb.dll
[2010/08/25 06:31:02 | 000,155,648 | ---- | C] () -- D:\WINDOWS\System32\dlcjins.dll
[2010/08/25 06:31:02 | 000,106,496 | ---- | C] () -- D:\WINDOWS\System32\dlcjinsr.dll
[2010/08/25 06:31:01 | 000,086,016 | ---- | C] () -- D:\WINDOWS\System32\dlcjcub.dll
[2010/08/25 06:31:01 | 000,073,728 | ---- | C] () -- D:\WINDOWS\System32\dlcjcu.dll
[2010/08/25 06:31:01 | 000,036,864 | ---- | C] () -- D:\WINDOWS\System32\dlcjcur.dll
[2010/08/25 06:30:59 | 000,069,632 | ---- | C] () -- D:\WINDOWS\System32\dlcjcfg.dll
[2010/08/21 20:18:01 | 000,000,000 | ---- | C] () -- D:\WINDOWS\nsreg.dat
[2010/08/21 15:09:22 | 000,000,000 | ---- | C] () -- D:\WINDOWS\ativpsrm.bin
[2010/08/21 15:09:03 | 000,887,724 | ---- | C] () -- D:\WINDOWS\System32\ativva6x.dat
[2010/08/21 15:09:03 | 000,294,912 | ---- | C] () -- D:\WINDOWS\System32\ATIODE.exe
[2010/08/21 15:09:03 | 000,045,056 | ---- | C] () -- D:\WINDOWS\System32\ATIODCLI.exe
[2010/08/21 15:09:03 | 000,000,003 | ---- | C] () -- D:\WINDOWS\System32\ativva5x.dat
[2010/08/18 17:15:37 | 000,138,160 | ---- | C] () -- D:\WINDOWS\System32\drivers\PnkBstrK.sys
[2010/08/18 17:15:36 | 000,022,328 | ---- | C] () -- D:\Documents and Settings\Familia Salinas\Application Data\PnkBstrK.sys
[2010/08/18 17:15:17 | 000,271,200 | ---- | C] () -- D:\WINDOWS\System32\PnkBstrB.exe
[2010/08/18 17:15:16 | 000,075,136 | ---- | C] () -- D:\WINDOWS\System32\PnkBstrA.exe
[2010/08/18 17:15:14 | 000,000,319 | ---- | C] () -- D:\WINDOWS\game.ini
[2010/08/16 10:52:42 | 000,044,936 | -H-- | C] () -- D:\WINDOWS\System32\mlfcache.dat
[2010/08/16 09:59:41 | 000,000,056 | -H-- | C] () -- D:\WINDOWS\System32\ezsidmv.dat
[2010/08/16 09:30:04 | 000,002,560 | ---- | C] () -- D:\WINDOWS\_MSRSTRT.EXE
[2010/08/15 21:11:49 | 000,043,520 | ---- | C] () -- D:\Documents and Settings\Familia Salinas\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/08/15 13:11:21 | 000,520,192 | ---- | C] () -- D:\WINDOWS\System32\ati2sgag.exe
[2010/08/15 13:10:39 | 000,224,342 | ---- | C] () -- D:\WINDOWS\System32\atiicdxx.dat
[2010/08/15 12:52:21 | 000,002,048 | --S- | C] () -- D:\WINDOWS\bootstat.dat
[2010/08/15 12:43:32 | 000,021,640 | ---- | C] () -- D:\WINDOWS\System32\emptyregdb.dat
[2010/08/15 07:22:54 | 000,004,161 | ---- | C] () -- D:\WINDOWS\ODBCINST.INI
[2010/08/15 07:21:46 | 003,521,416 | ---- | C] () -- D:\WINDOWS\System32\FNTCACHE.DAT
[2007/11/26 21:56:28 | 000,151,415 | ---- | C] () -- D:\WINDOWS\System32\xlive.dll.cat
[2006/12/31 07:57:08 | 000,004,569 | ---- | C] () -- D:\WINDOWS\System32\secupd.dat
[2003/07/16 15:54:55 | 000,004,594 | ---- | C] () -- D:\WINDOWS\System32\oembios.dat
[2003/07/16 15:54:54 | 013,107,200 | ---- | C] () -- D:\WINDOWS\System32\oembios.bin
[2003/07/16 15:41:25 | 000,492,614 | ---- | C] () -- D:\WINDOWS\System32\perfh009.dat
[2003/07/16 15:41:25 | 000,272,128 | ---- | C] () -- D:\WINDOWS\System32\perfi009.dat
[2003/07/16 15:41:23 | 000,028,626 | ---- | C] () -- D:\WINDOWS\System32\perfd009.dat
[2003/07/16 15:41:21 | 000,083,262 | ---- | C] () -- D:\WINDOWS\System32\perfc009.dat
[2003/07/16 15:39:07 | 000,000,741 | ---- | C] () -- D:\WINDOWS\System32\noise.dat
[2003/07/16 15:33:50 | 000,673,088 | ---- | C] () -- D:\WINDOWS\System32\mlang.dat
[2003/07/16 15:33:39 | 000,046,258 | ---- | C] () -- D:\WINDOWS\System32\mib.bin
[2003/07/16 15:27:41 | 000,218,003 | ---- | C] () -- D:\WINDOWS\System32\dssec.dat
[2003/07/16 15:26:37 | 000,001,804 | ---- | C] () -- D:\WINDOWS\System32\dcache.bin
[2003/01/07 15:05:08 | 000,002,695 | ---- | C] () -- D:\WINDOWS\System32\OUTLPERF.INI

========== Alternate Data Streams ==========

@Alternate Data Stream - 133 bytes -> D:\Documents and Settings\All Users\Application Data\TEMP:05EE1EEF

< End of report >

8 Re: WhiteSmoke MBAM Logs on Fri Jun 10, 2011 10:56 pm

DragonMaster Jay


Site Owner
Site Owner
Please visit this webpage for a tutorial on downloading and running ComboFix:

http://www.bleepingcomputer.com/combofix/how-to-use-combofix

See the area: Using ComboFix, and when done, post the log back here.


..........................................................
DragonMaster Jay
Administrative Director SecuraGeek Association
Advanced Malware Analysts Group Owner


Kaspersky E-Store Kaspersky Anti-Virus 2012: Click Here

Contribute/donate to our site

9 Re: WhiteSmoke MBAM Logs on Sat Jun 11, 2011 3:30 pm

dr09294


Member
Member
ComboFix 11-06-11.01 - Familia Salinas 06/11/2011 14:00:16.1.2 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.2046.1088 [GMT -5:00]
Running from: d:\documents and settings\Familia Salinas\Desktop\ComboFix.exe
AV: avast! Antivirus *Disabled/Updated* {7591DB91-41F0-48A3-B128-1A293FD8233D}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
C:\install.exe
.
Infected copy of d:\windows\system32\drivers\ntfs.sys was found and disinfected
Restored copy from - d:\windows\ServicePackFiles\i386\ntfs.sys
.
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
-------\Legacy_MYWEBSEARCHSERVICE
.
.
((((((((((((((((((((((((( Files Created from 2011-05-11 to 2011-06-11 )))))))))))))))))))))))))))))))
.
.
2011-06-09 02:35 . 2011-05-10 12:03 441176 ----a-w- d:\windows\system32\drivers\aswSnx.sys
2011-06-09 02:12 . 2011-06-09 02:12 -------- d-----w- d:\documents and settings\Familia Salinas\Application Data\Malwarebytes
2011-06-09 02:12 . 2011-05-29 14:11 39984 ----a-w- d:\windows\system32\drivers\mbamswissarmy.sys
2011-06-09 02:12 . 2011-06-09 02:12 -------- d-----w- d:\documents and settings\All Users\Application Data\Malwarebytes
2011-06-09 02:12 . 2011-06-10 13:42 -------- d-----w- d:\program files\Malwarebytes' Anti-Malware
2011-06-09 02:12 . 2011-05-29 14:11 22712 ----a-w- d:\windows\system32\drivers\mbam.sys
2011-06-09 02:09 . 2011-06-09 02:09 -------- d-----w- d:\program files\VS Revo Group
2011-05-26 12:44 . 2011-05-26 12:44 -------- d-sh--w- d:\documents and settings\Familia Salinas\IECompatCache
2011-05-14 23:43 . 2011-06-03 21:58 -------- d-----w- d:\documents and settings\All Users\Application Data\Skype Extras
2011-05-14 23:42 . 2011-05-14 23:42 -------- d-----w- d:\program files\Common Files\Skype
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-05-10 12:10 . 2010-08-15 19:35 40112 ----a-w- d:\windows\avastSS.scr
2011-05-10 12:10 . 2010-08-15 19:35 199304 ----a-w- d:\windows\system32\aswBoot.exe
2011-05-10 12:03 . 2010-08-15 19:35 307928 ----a-w- d:\windows\system32\drivers\aswSP.sys
2011-05-10 12:02 . 2010-08-15 19:35 49240 ----a-w- d:\windows\system32\drivers\aswTdi.sys
2011-05-10 12:02 . 2010-08-15 19:35 102616 ----a-w- d:\windows\system32\drivers\aswmon2.sys
2011-05-10 12:02 . 2010-08-15 19:35 96344 ----a-w- d:\windows\system32\drivers\aswmon.sys
2011-05-10 11:59 . 2010-08-15 19:35 25432 ----a-w- d:\windows\system32\drivers\aswRdr.sys
2011-05-10 11:59 . 2010-08-15 19:35 30808 ----a-w- d:\windows\system32\drivers\aavmker4.sys
2011-05-10 11:59 . 2010-08-15 19:35 19544 ----a-w- d:\windows\system32\drivers\aswFsBlk.sys
2011-05-09 23:00 . 2010-08-18 22:15 138160 ----a-w- d:\windows\system32\drivers\PnkBstrK.sys
2011-05-09 22:59 . 2010-08-20 22:11 271200 ----a-w- d:\windows\system32\PnkBstrB.xtr
2011-05-09 22:59 . 2010-08-18 22:15 271200 ----a-w- d:\windows\system32\PnkBstrB.exe
2011-04-28 17:23 . 2011-04-28 17:23 40960 ----a-r- d:\documents and settings\Familia Salinas\Application Data\Microsoft\Installer\{9559F7CA-5E34-4237-A2D9-D856464AD727}\NewShortcut1_9559F7CA5E344237A2D9D856464AD727.exe
2011-04-28 17:23 . 2011-04-28 17:23 40960 ----a-r- d:\documents and settings\Familia Salinas\Application Data\Microsoft\Installer\{9559F7CA-5E34-4237-A2D9-D856464AD727}\ARPPRODUCTICON.exe
2011-04-27 20:47 . 2010-08-18 22:15 271200 ----a-w- d:\windows\system32\PnkBstrB.ex0
2011-04-21 08:27 . 2011-04-21 08:27 53248 ----a-r- d:\documents and settings\Familia Salinas\Application Data\Microsoft\Installer\{B952A4EC-E5E9-47DF-A622-C420D107DD20}\ARPPRODUCTICON.exe
2011-04-21 08:27 . 2011-04-21 08:27 155648 ----a-r- d:\documents and settings\Familia Salinas\Application Data\Microsoft\Installer\{B952A4EC-E5E9-47DF-A622-C420D107DD20}\NewShortcut2_F58C80F45C574084924192D12F6D6AEA.exe
2011-04-06 21:20 . 2011-04-06 21:20 91424 ----a-w- d:\windows\system32\dnssd.dll
2011-04-06 21:20 . 2011-04-06 21:20 75040 ----a-w- d:\windows\system32\jdns_sd.dll
2011-04-06 21:20 . 2011-04-06 21:20 197920 ----a-w- d:\windows\system32\dnssdX.dll
2011-04-06 21:20 . 2011-04-06 21:20 107808 ----a-w- d:\windows\system32\dns-sd.exe
2011-04-06 01:40 . 2011-04-06 01:40 286720 ------w- d:\windows\Setup1.exe
2011-04-06 01:40 . 2011-04-06 01:40 73216 ----a-w- d:\windows\ST6UNST.EXE
2011-04-03 19:59 . 2011-04-03 19:59 53248 ----a-r- d:\documents and settings\Familia Salinas\Application Data\Microsoft\Installer\{016E6B1B-45FC-44FB-9F83-28E6B1FF6A42}\ARPPRODUCTICON.exe
2011-03-25 22:44 . 2011-03-25 22:44 59888 ------w- d:\windows\system32\pxwma.dll
2011-03-18 01:50 . 2011-03-18 01:50 110592 ----a-r- d:\documents and settings\Familia Salinas\Application Data\Microsoft\Installer\{E6B4523B-A47C-4DBA-918C-D9E220B3F4EC}\NewShortcut1_E6B4523BA47C4DBA918CD9E220B3F4EC.exe
2011-03-18 01:50 . 2011-03-18 01:50 110592 ----a-r- d:\documents and settings\Familia Salinas\Application Data\Microsoft\Installer\{E6B4523B-A47C-4DBA-918C-D9E220B3F4EC}\Cube.exe1_E6B4523BA47C4DBA918CD9E220B3F4EC.exe
2011-04-14 16:26 . 2011-06-11 00:26 142296 ----a-w- d:\program files\mozilla firefox\components\browsercomps.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast]
@="{472083B0-C522-11CF-8763-00608CC02F24}"
[HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}]
2011-05-10 12:10 122512 ----a-w- d:\program files\Alwil Software\Avast5\ashShell.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DW6"="d:\program files\The Weather Channel FW\Desktop\DesktopWeather.exe" [2010-04-16 818288]
"VZWSUAM"="d:\documents and settings\Familia Salinas\Application Data\Verizon\SUA\VZWSUAM.exe" [2011-04-13 196608]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ATIPTA"="d:\program files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2006-02-10 344064]
"AdobeAAMUpdater-1.0"="d:\program files\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe" [2010-03-06 500208]
"AdobeCS5ServiceManager"="d:\program files\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe" [2010-07-23 402432]
"SwitchBoard"="d:\program files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe" [2010-02-19 517096]
"ATICustomerCare"="d:\program files\ATI\ATICustomerCare\ATICustomerCare.exe" [2010-03-04 311296]
"Adobe Reader Speed Launcher"="d:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2011-01-31 35760]
"Adobe ARM"="d:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-09-21 932288]
"DivXUpdate"="d:\program files\DivX\DivX Update\DivXUpdate.exe" [2010-09-16 1164584]
"PWRISOVM.EXE"="d:\program files\PowerISO\PWRISOVM.EXE" [2010-04-12 180224]
"StartCCC"="d:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2010-09-11 98304]
"TkBellExe"="d:\program files\Real\RealPlayer\update\realsched.exe" [2010-12-09 274608]
"QuickTime Task"="d:\program files\QuickTime\QTTask.exe" [2010-11-29 421888]
"SunJavaUpdateSched"="d:\program files\Common Files\Java\Java Update\jusched.exe" [2010-10-29 249064]
"SigmatelSysTrayApp"="stsystra.exe" [2005-03-22 339968]
"CTSVolFE"="d:\program files\Creative\Mixer\CTSVolFE.exe" [2005-02-23 57344]
"iTunesHelper"="d:\program files\iTunes\iTunesHelper.exe" [2011-04-27 421160]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"RunNarrator"="Narrator.exe" [2008-04-14 53760]
.
d:\documents and settings\Familia Salinas\Start Menu\Programs\Startup\
Stardock ObjectDock.lnk - d:\program files\Stardock\ObjectDock\ObjectDock.exe [2010-8-15 3450608]
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"d:\\Program Files\\AIM\\aim.exe"=
"d:\\Program Files\\Skype\\Plugin Manager\\skypePM.exe"=
"d:\\WINDOWS\\system32\\PnkBstrA.exe"=
"d:\\WINDOWS\\system32\\PnkBstrB.exe"=
"d:\\Program Files\\Steam\\Steam.exe"=
"d:\\Program Files\\Xfire\\Xfire.exe"=
"d:\\Program Files\\Java\\jre6\\bin\\javaw.exe"=
"d:\\WINDOWS\\system32\\java.exe"=
"d:\\Program Files\\uTorrent\\uTorrent.exe"=
"d:\\Program Files\\Graffiti Studio 2.0\\Graffiti Studio.exe"=
"d:\\Program Files\\Armagetron Advanced\\armagetronad.exe"=
"d:\\Program Files\\Java\\jre6\\bin\\java.exe"=
"d:\\Program Files\\Valve\\HLServer\\orangebox\\srcds.exe"=
"d:\\Program Files\\TeamViewer\\Version6\\TeamViewer.exe"=
"d:\\Program Files\\TeamViewer\\Version6\\TeamViewer_Service.exe"=
"c:\\Program Files\\Activision\\Call of Duty 4 - Modern Warfare\\iw3mp.exe"=
"d:\\Program Files\\Microsoft Games\\Halo\\halo.exe"=
"c:\\Program Files\\Activision\\Call of Duty 4 - Modern Warfare\\iw3mp (2).exe"=
"d:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"d:\\Program Files\\iTunes\\iTunes.exe"=
"d:\\Program Files\\Skype\\Phone\\Skype.exe"=
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"1035:TCP"= 1035:TCP:Akamai NetSession Interface
"5000:UDP"= 5000:UDP:Akamai NetSession Interface
.
R1 aswSnx;aswSnx;d:\windows\system32\drivers\aswSnx.sys [6/8/2011 9:35 PM 441176]
R1 aswSP;aswSP;d:\windows\system32\drivers\aswSP.sys [8/15/2010 2:35 PM 307928]
R2 Akamai;Akamai NetSession Interface;d:\windows\System32\svchost.exe -k Akamai [7/16/2003 3:47 PM 14336]
R2 aswFsBlk;aswFsBlk;d:\windows\system32\drivers\aswFsBlk.sys [8/15/2010 2:35 PM 19544]
R2 Autodesk Content Service;Autodesk Content Service;d:\program files\Autodesk\Content Service\Connect.Service.ContentService.exe [2/2/2011 2:08 PM 18656]
R3 samhid;samhid;d:\windows\system32\drivers\Samhid.sys [4/23/2011 7:10 PM 7548]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;d:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [3/18/2010 1:16 PM 130384]
S3 SwitchBoard;Adobe SwitchBoard;d:\program files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2/19/2010 1:37 PM 517096]
S3 teamviewervpn;TeamViewer VPN Adapter;d:\windows\system32\drivers\teamviewervpn.sys [1/10/2011 6:54 PM 25088]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;d:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [3/18/2010 1:16 PM 753504]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
Akamai REG_MULTI_SZ Akamai
.
Contents of the 'Scheduled Tasks' folder
.
2011-06-11 d:\windows\Tasks\AdobeAAMUpdater-1.0-FAMILIASALINAS-Familia Salinas.job
- d:\program files\Common Files\Adobe\OOBE\PDApp\UWA\updaterstartuputility.exe [2010-08-15 08:44]
.
2011-06-01 d:\windows\Tasks\AppleSoftwareUpdate.job
- d:\program files\Apple Software Update\SoftwareUpdate.exe [2009-10-22 16:50]
.
2011-06-11 d:\windows\Tasks\Game_Booster_Startup.job
- d:\program files\IObit\Game Booster 2\gbtray.exe [2011-01-17 22:20]
.
2011-06-11 d:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1708537768-507921405-725345543-1004Core.job
- d:\documents and settings\Familia Salinas\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2010-08-15 19:27]
.
2011-06-11 d:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1708537768-507921405-725345543-1004UA.job
- d:\documents and settings\Familia Salinas\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2010-08-15 19:27]
.
2011-06-11 d:\windows\Tasks\RealUpgradeLogonTaskS-1-5-21-1708537768-507921405-725345543-1004.job
- d:\program files\Real\RealUpgrade\realupgrade.exe [2010-11-05 17:33]
.
2011-06-11 d:\windows\Tasks\RealUpgradeScheduledTaskS-1-5-21-1708537768-507921405-725345543-1004.job
- d:\program files\Real\RealUpgrade\realupgrade.exe [2010-11-05 17:33]
.
2011-06-11 d:\windows\Tasks\User_Feed_Synchronization-{552E9B33-67C4-4751-8644-F10FBF41E711}.job
- d:\windows\system32\msfeedssync.exe [2009-03-08 09:31]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://search.conduit.com?SearchSource=10&ctid=CT3007394
uInternet Connection Wizard,ShellNext = iexplore
uInternet Settings,ProxyOverride = *.local
IE: E&xport to Microsoft Excel - d:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
TCP: DhcpNameServer = 192.168.1.1
FF - ProfilePath - d:\documents and settings\Familia Salinas\Application Data\Mozilla\Firefox\Profiles\eycwhfm8.default\
.
.
------- File Associations -------
.
.scr=AutoCADScriptFile
.
- - - - ORPHANS REMOVED - - - -
.
HKCU-Run-AdobeBridge - (no file)
AddRemove-03_Swallowtail - d:\program files\SAMSUNG\USB Drivers\03_Swallowtail\Uninstall.exe
AddRemove-04_semseyite - d:\program files\SAMSUNG\USB Drivers\04_semseyite\Uninstall.exe
AddRemove-16_Shrewsbury - d:\program files\SAMSUNG\USB Drivers\16_Shrewsbury\Uninstall.exe
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2011-06-11 14:17
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes ...
.
scanning hidden autostart entries ...
.
scanning hidden files ...
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_USERS\S-1-5-21-1708537768-507921405-725345543-1004\Software\Microsoft\Windows\CurrentVersion\Explorer\CLSID]
@Denied: (Full) (LocalSystem)
.
--------------------- DLLs Loaded Under Running Processes ---------------------
.
- - - - - - - > 'winlogon.exe'(764)
d:\windows\system32\Ati2evxx.dll
d:\windows\system32\atiadlxx.dll
.
- - - - - - - > 'explorer.exe'(3592)
d:\windows\system32\WININET.dll
d:\program files\Stardock\ObjectDock\DockShellHook.dll
d:\windows\system32\msi.dll
d:\windows\system32\AcSignIcon.dll
c:\program files\Autodesk\Inventor Fusion 2012\AcSignCore16.dll
d:\windows\system32\ieframe.dll
d:\windows\system32\webcheck.dll
d:\windows\system32\WPDShServiceObj.dll
d:\windows\system32\PortableDeviceTypes.dll
d:\windows\system32\PortableDeviceApi.dll
.
------------------------ Other Running Processes ------------------------
.
d:\windows\system32\Ati2evxx.exe
d:\windows\system32\Ati2evxx.exe
d:\program files\Alwil Software\Avast5\AvastSvc.exe
d:\program files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
d:\program files\Bonjour\mDNSResponder.exe
d:\program files\Java\jre6\bin\jqs.exe
d:\windows\system32\PnkBstrA.exe
d:\windows\stsystra.exe
d:\program files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
d:\program files\iPod\bin\iPodService.exe
d:\program files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe
.
**************************************************************************
.
Completion time: 2011-06-11 14:29:08 - machine was rebooted
ComboFix-quarantined-files.txt 2011-06-11 19:28
.
Pre-Run: 9,225,109,504 bytes free
Post-Run: 8,991,997,952 bytes free
.
WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(1)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
UnsupportedDebug="do not select this" /debug
multi(0)disk(0)rdisk(1)partition(1)\WINDOWS="Microsoft Windows XP Home Edition" /fastdetect /NoExecute=OptIn
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Home Edition" /fastdetect
.
- - End Of File - - AC55BB9024C98E9DD387C804AFB34CEE

10 Re: WhiteSmoke MBAM Logs on Sat Jun 11, 2011 3:32 pm

dr09294


Member
Member
after running combofix when my comp rebooted, it didn't go to the weird desktop picture it normally goes to before the welcome screen and it booted a bit faster....idk if that means anything..........

11 Re: WhiteSmoke MBAM Logs on Sat Jun 11, 2011 5:44 pm

DragonMaster Jay


Site Owner
Site Owner
What signs of the WhiteSmoke installation are still there?


..........................................................
DragonMaster Jay
Administrative Director SecuraGeek Association
Advanced Malware Analysts Group Owner


Kaspersky E-Store Kaspersky Anti-Virus 2012: Click Here

Contribute/donate to our site

12 Re: WhiteSmoke MBAM Logs on Sat Jun 11, 2011 6:08 pm

dr09294


Member
Member
well i uninstalled bot chrome and firefox with Revo uninstaller and got rid of any file that was created by the browser so that got rid of the stupid homepage it left behind and the toolbar but i didn't do anything to IE so the toolbar appears to be gone but is still takes me to the stupid whitesmoke conduit homepage

13 Re: WhiteSmoke MBAM Logs on Sat Jun 11, 2011 10:34 pm

DragonMaster Jay


Site Owner
Site Owner
Please download: HijackThis to your Desktop.
  • Double Click the HijackThis icon, located on your Desktop.
  • By Default, it will install to: C:\Program Files\Trend Micro\HijackThis
    It will also create a shortcut on your Desktop.
  • Accept the license agreement.
  • Click Do a System Scan and Save a Logfile.
  • Please post the log in your next reply.


..........................................................
DragonMaster Jay
Administrative Director SecuraGeek Association
Advanced Malware Analysts Group Owner


Kaspersky E-Store Kaspersky Anti-Virus 2012: Click Here

Contribute/donate to our site

14 Re: WhiteSmoke MBAM Logs on Sun Jun 12, 2011 1:25 am

dr09294


Member
Member
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 12:24:36 AM, on 6/12/2011
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
D:\WINDOWS\System32\smss.exe
D:\WINDOWS\system32\winlogon.exe
D:\WINDOWS\system32\services.exe
D:\WINDOWS\system32\lsass.exe
D:\WINDOWS\system32\Ati2evxx.exe
D:\WINDOWS\system32\svchost.exe
D:\WINDOWS\System32\svchost.exe
D:\WINDOWS\system32\svchost.exe
D:\WINDOWS\system32\Ati2evxx.exe
D:\Program Files\Alwil Software\Avast5\AvastSvc.exe
D:\WINDOWS\system32\spoolsv.exe
D:\Program Files\IObit\Game Booster 2\gbtray.exe
D:\WINDOWS\System32\svchost.exe
D:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
D:\Program Files\Autodesk\Content Service\Connect.Service.ContentService.exe
D:\Program Files\Bonjour\mDNSResponder.exe
D:\Program Files\Java\jre6\bin\jqs.exe
D:\WINDOWS\system32\PnkBstrA.exe
D:\WINDOWS\System32\svchost.exe
D:\Program Files\DivX\DivX Update\DivXUpdate.exe
D:\Program Files\PowerISO\PWRISOVM.EXE
D:\Program Files\Real\RealPlayer\update\realsched.exe
D:\Program Files\Common Files\Java\Java Update\jusched.exe
D:\WINDOWS\stsystra.exe
D:\Program Files\Creative\Mixer\CTSVolFE.exe
D:\Program Files\iTunes\iTunesHelper.exe
D:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
D:\Documents and Settings\Familia Salinas\Application Data\Verizon\SUA\VZWSUAM.exe
D:\Program Files\Stardock\ObjectDock\ObjectDock.exe
D:\Program Files\iPod\bin\iPodService.exe
D:\WINDOWS\System32\svchost.exe
D:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe
D:\WINDOWS\explorer.exe
D:\Program Files\Alwil Software\Avast5\AvastUI.exe
D:\WINDOWS\system32\ctfmon.exe
D:\Documents and Settings\Familia Salinas\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
D:\Documents and Settings\Familia Salinas\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
D:\Documents and Settings\Familia Salinas\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
D:\WINDOWS\system32\msiexec.exe
D:\Program Files\Trend Micro\HiJackThis\HiJackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://search.conduit.com?SearchSource=10&ctid=CT3007394
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R3 - URLSearchHook: (no name) - - (no file)
O2 - BHO: ContributeBHO Class - {074C1DC5-9320-4A9A-947D-C042949C6216} - C:\Program Files\Adobe\Adobe Contribute CS5\Plugins\IEPlugin\contributeieplugin.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - D:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - D:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll
O2 - BHO: avast! WebRep - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - D:\Program Files\Alwil Software\Avast5\aswWebRepIE.dll
O2 - BHO: SkypeIEPluginBHO - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - D:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - D:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - D:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: Contribute Toolbar - {517BDDE4-E3A7-4570-B21E-2B52B6139FC7} - C:\Program Files\Adobe\Adobe Contribute CS5\Plugins\IEPlugin\contributeieplugin.dll
O3 - Toolbar: avast! WebRep - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - D:\Program Files\Alwil Software\Avast5\aswWebRepIE.dll
O4 - HKLM\..\Run: [ATIPTA] "D:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe"
O4 - HKLM\..\Run: [AdobeAAMUpdater-1.0] "D:\Program Files\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe"
O4 - HKLM\..\Run: [AdobeCS5ServiceManager] "D:\Program Files\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe" -launchedbylogin
O4 - HKLM\..\Run: [SwitchBoard] D:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
O4 - HKLM\..\Run: [ATICustomerCare] "D:\Program Files\ATI\ATICustomerCare\ATICustomerCare.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "D:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "D:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [DivXUpdate] "D:\Program Files\DivX\DivX Update\DivXUpdate.exe" /CHECKNOW
O4 - HKLM\..\Run: [PWRISOVM.EXE] D:\Program Files\PowerISO\PWRISOVM.EXE
O4 - HKLM\..\Run: [StartCCC] "D:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
O4 - HKLM\..\Run: [TkBellExe] "D:\Program Files\Real\RealPlayer\update\realsched.exe" -osboot
O4 - HKLM\..\Run: [QuickTime Task] "D:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [SunJavaUpdateSched] "D:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [SigmatelSysTrayApp] stsystra.exe
O4 - HKLM\..\Run: [CTSVolFE] "D:\Program Files\Creative\Mixer\CTSVolFE.exe" /r
O4 - HKLM\..\Run: [iTunesHelper] "D:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKCU\..\Run: [DW6] "D:\Program Files\The Weather Channel FW\Desktop\DesktopWeather.exe"
O4 - HKCU\..\Run: [VZWSUAM] "D:\Documents and Settings\Familia Salinas\Application Data\Verizon\SUA\VZWSUAM.exe" /boot
O4 - HKCU\..\Run: [ctfmon.exe] D:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-18\..\RunOnce: [RunNarrator] Narrator.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\RunOnce: [RunNarrator] Narrator.exe (User 'Default user')
O4 - Startup: Stardock ObjectDock.lnk = D:\Program Files\Stardock\ObjectDock\ObjectDock.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://D:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - D:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra 'Tools' menuitem: Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - D:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - D:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - D:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - D:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - D:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - D:\Program Files\Messenger\msmsgs.exe
O18 - Protocol: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - D:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - D:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - D:\WINDOWS\System32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - D:\WINDOWS\System32\browseui.dll
O23 - Service: Apple Mobile Device - Apple Inc. - D:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - D:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - D:\WINDOWS\system32\ati2sgag.exe
O23 - Service: Autodesk Content Service - Unknown owner - D:\Program Files\Autodesk\Content Service\Connect.Service.ContentService.exe
O23 - Service: avast! Antivirus - AVAST Software - D:\Program Files\Alwil Software\Avast5\AvastSvc.exe
O23 - Service: Bonjour Service - Apple Inc. - D:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Creative Labs Licensing Service - Creative Labs - D:\Program Files\Common Files\Creative Labs Shared\Service\CreativeLicensing.exe
O23 - Service: dlcj_device - Unknown owner - D:\WINDOWS\system32\dlcjcoms.exe
O23 - Service: FLEXnet Licensing Service - Flexera Software, Inc. - D:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: iPod Service - Apple Inc. - D:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - D:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: PnkBstrA - Unknown owner - D:\WINDOWS\system32\PnkBstrA.exe
O23 - Service: Adobe SwitchBoard (SwitchBoard) - Adobe Systems Incorporated - D:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe

--
End of file - 9324 bytes

15 Re: WhiteSmoke MBAM Logs on Sun Jun 12, 2011 1:43 pm

DragonMaster Jay


Site Owner
Site Owner
Please re-open HijackThis and click Do a System Scan only. Check the boxes to the left of all the entries listed below.

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://search.conduit.com?SearchSource=10&ctid=CT3007394
R3 - URLSearchHook: (no name) - - (no file)

Then, please exit all programs except for HijackThis (System Tray (bottom right of screen): right-click on each program icon and click an Exit or shut down option, etc.), then click Fix Checked.

After it completes its process, please close HijackThis and reboot your computer.


ESET Online Scan

Please run a free online scan with the ESET Online Scanner
  • Tick the box next to YES, I accept the Terms of Use
  • Click Start
  • When asked, allow the ActiveX control to install
  • Click Start
  • Make sure that the options Remove found threats and the option Scan unwanted applications is checked
  • Click Scan (This scan can take several hours, so please be patient)
  • Once the scan is completed, you may close the window
  • Use Notepad to open the logfile located at C:\Program Files\EsetOnlineScanner\log.txt
  • Copy and paste that log as a reply to this topic


..........................................................
DragonMaster Jay
Administrative Director SecuraGeek Association
Advanced Malware Analysts Group Owner


Kaspersky E-Store Kaspersky Anti-Virus 2012: Click Here

Contribute/donate to our site

Ad Bot


View previous topic View next topic Back to top  Message [Page 1 of 2]

Goto page : 1, 2  Next

Permissions in this forum:
You cannot reply to topics in this forum