1. Welcome Guest! In order to create a new topic or reply to an existing one, you must register first. It is easy and free. Click here to sign up now!.
    Dismiss Notice

Malware And Trogen Problems

Discussion in 'Malware Removal Help' started by wendy, Jan 18, 2010.

  1. schrauber

    schrauber Guest

    Ok,


    Download Combofix from any of the links below but rename it to <schrauber> before saving it to your desktop.

    Link 1
    Link 2



    --------------------------------------------------------------------

    Double click on the renamed Combofix.exe & follow the prompts.
    • When finished, it will produce a report for you.
    • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.
    • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.
    **Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.

    [​IMG]

    Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

    [​IMG]

    Click on Yes, to continue scanning for malware.

    When finished, it will produce a log for you. Please include the C:\ComboFix.txt in your next reply.

    This tool is not a toy and not for everyday use.
    ComboFix SHOULD NOT be used unless requested by a forum helper


    If you need help, see this link:
    http://www.bleepingcomputer.com/combofix/how-to-use-combofix
     
  2. wendy

    wendy Registered Members

    Joined:
    Jan 18, 2010
    Messages:
    49
    Location:
    wales uk
    Operating System:
    Windows XP Home
    Do i need to do this in safe mode
     
  3. schrauber

    schrauber Guest

    Hi,

    Please run all scans and fixes in normal mode, if you did not read a specific speech to use safe mode :)
     
  4. wendy

    wendy Registered Members

    Joined:
    Jan 18, 2010
    Messages:
    49
    Location:
    wales uk
    Operating System:
    Windows XP Home
    ok done just now waiting for the auto scan to run i just cant see the hard drive light flashing should i worry in about 20mins what do you think
    thanks wendy
     
  5. schrauber

    schrauber Guest

    At which point is Combofix now? Do you write this from the other system?
     
  6. wendy

    wendy Registered Members

    Joined:
    Jan 18, 2010
    Messages:
    49
    Location:
    wales uk
    Operating System:
    Windows XP Home
    No download it straight on the infected laptop all other instructions went ok but now I have a small blue box with auto run saying scanning infection files... may take 10mins or double that but i am concerned because i think the machine has frozen as the hard drive light is not flashing and it been over 20mins now, what should i do dont want to switch it off.
     
  7. schrauber

    schrauber Guest

    Let it run for another 20 minutes, then stop it and reboot.
     
  8. wendy

    wendy Registered Members

    Joined:
    Jan 18, 2010
    Messages:
    49
    Location:
    wales uk
    Operating System:
    Windows XP Home
    ComboFix 10-01-19.08 - Tasha Z 20/01/2010 21:30:31.1.2 - x86
    Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.502.264 [GMT 0:00]
    Running from: c:\documents and settings\Tasha Z\Desktop\schrauber.exe
    .

    ((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
    .

    c:\documents and settings\Tasha Z\Application Data\Install.dat
    C:\fbcheck.bat
    c:\program files\captcha.dll
    c:\program files\FunWebProducts
    c:\program files\Mozilla Firefox\ftemp.exe
    c:\program files\MyWebSearch
    c:\program files\MyWebSearch\bar\History\search3
    c:\program files\MyWebSearch\bar\Settings\s_pid.dat
    c:\program files\MyWebSearch\bar\Settings\setting2.htm
    c:\program files\MyWebSearch\bar\Settings\settings.dat
    c:\program files\webserver
    c:\windows\010112010146100101.xxe
    c:\windows\010112010146101105.rx
    c:\windows\010112010146111103.xxe
    c:\windows\010112010146114101.xxe
    c:\windows\010112010146115116.xxe
    c:\windows\010112010146116101.xxe
    c:\windows\0101120101465150.xxe
    c:\windows\0101120101465155.xxe
    c:\windows\0101120101465249.xxe
    c:\windows\0101120101465250.xxe
    c:\windows\0101120101465255.xxe
    c:\windows\0101120101465349.xxe
    c:\windows\0101120101465355.xxe
    c:\windows\0101120101465548.xxe
    c:\windows\0101120101465649.xxe
    c:\windows\bk23567.dat
    c:\windows\bx4657.dat
    c:\windows\fdgg34353edfgdfdf
    c:\windows\hpm2.dat
    c:\windows\mmsmark3.dat
    c:\windows\pp12.exe
    c:\windows\rdr_1258395588.exe
    c:\windows\rdr_1258487055.exe
    c:\windows\rdr_1258489593.exe
    c:\windows\rdr_1258567779.exe
    c:\windows\rdr_1258741568.exe
    c:\windows\rdr_1258746876.exe
    c:\windows\rdr_1258823495.exe
    c:\windows\rdr_1258908807.exe
    c:\windows\rdr_1258910083.exe
    c:\windows\rdr_1258914792.exe
    c:\windows\rdr_1258918936.exe
    c:\windows\rdr_1259263995.exe
    c:\windows\rdr_1259396644.exe
    c:\windows\rdr_1259397966.exe
    c:\windows\rdr_1259400010.exe
    c:\windows\rdr_1259412729.exe
    c:\windows\rdr_1259483273.exe
    c:\windows\rdr_1259484023.exe
    c:\windows\rdr_1259484027.exe
    c:\windows\rdr_1259492315.exe
    c:\windows\rdr_1259492765.exe
    c:\windows\rdr_1259492768.exe
    c:\windows\rdr_1259522099.exe
    c:\windows\rdr_1259523431.exe
    c:\windows\rdr_1259699909.exe
    c:\windows\rdr_1263291159.exe
    c:\windows\rdr_1263292567.exe
    c:\windows\rdr_1263294639.exe
    c:\windows\rdr_1263294647.exe
    c:\windows\rdr_1263294652.exe
    c:\windows\rdr_1263295382.exe
    c:\windows\rdr_1263296326.exe
    c:\windows\rdr_1263298621.exe
    c:\windows\system32\__c007B6B4.dat
    c:\windows\system32\2754609835.dat
    c:\windows\system32\alog.txt
    c:\windows\system32\BcfgfMoq.ini
    c:\windows\system32\BcfgfMoq.ini2
    c:\windows\system32\cookie.dat
    c:\windows\system32\dlh9jkd1q1.exe
    c:\windows\system32\dlh9jkd1q8.exe
    c:\windows\system32\drivers\fio32.sys
    c:\windows\system32\fio32.dll
    c:\windows\system32\help.txt
    c:\windows\system32\kernel32.exe
    c:\windows\system32\kr_done1
    c:\windows\system32\ps.dat
    c:\windows\system32\sqvx5gamet2.exe
    c:\windows\system32\sqvxga6met3.exe
    c:\windows\system32\sqvxga7met4.exe
    c:\windows\system32\svcp.csv
    c:\windows\system32\vx.tll
    c:\windows\system32\windev-peers.ini
    c:\windows\system32\winsub.xml
    c:\windows\tag14.exe
    c:\windows\tgm2.dat
    c:\windows\tw23567.dat
    c:\windows\zwer_1258200833.exe
    c:\windows\zwer_1258200836.exe
    c:\windows\zwer_1258272729.exe
    c:\windows\zwer_1258301370.exe
    c:\windows\zwer_1258305350.exe
    C:\xcrashdump.dat

    .
    original MBR restored successfully !
    .
    ((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
    .

    -------\Legacy_EXAMPLE
    -------\Legacy_FIOO32
    -------\Legacy_FWDRV.SYS
    -------\Legacy_NDNET1
    -------\Legacy_RUNTIME
    -------\Service_EXAMPLE
    -------\Service_fioo32
    -------\Service_fwdrv.sys
    -------\Service_NDnet1
    -------\Service_runtime
    -------\Service_SfX
    -------\Legacy_fio32
    -------\Service_fio32


    ((((((((((((((((((((((((( Files Created from 2009-12-20 to 2010-01-20 )))))))))))))))))))))))))))))))
    .

    2010-01-17 10:24 . 2009-08-05 22:48 54752 ----a-w- c:\windows\system32\drivers\fssfltr_tdi.sys
    2010-01-16 23:33 . 2010-01-16 23:33 -------- d-----w- c:\program files\Microsoft Sync Framework
    2010-01-16 23:01 . 2010-01-16 23:05 -------- d-----w- c:\documents and settings\Tasha Z\Local Settings\Application Data\Temp
    2010-01-16 18:25 . 2010-01-16 18:26 -------- d-----w- c:\documents and settings\Tasha Z\Local Settings\Application Data\IObitCom
    2010-01-16 18:25 . 2010-01-16 18:25 -------- d-----w- c:\program files\IObitCom
    2010-01-16 18:25 . 2010-01-16 18:25 -------- d-----w- c:\program files\Conduit
    2010-01-16 18:25 . 2010-01-16 18:25 -------- d-----w- c:\documents and settings\Tasha Z\Local Settings\Application Data\Conduit
    2010-01-16 18:25 . 2010-01-19 16:39 -------- d-----w- c:\documents and settings\Tasha Z\Application Data\IObit
    2010-01-16 18:25 . 2010-01-16 18:25 -------- d-----w- c:\program files\IObit
    2010-01-16 18:25 . 2009-11-04 16:49 635664 ----a-w- c:\documents and settings\Tasha Z\Application Data\IObit\Common\TB_Helper.exe
    2010-01-16 16:45 . 2010-01-16 16:45 -------- d-----w- c:\windows\system32\Logfiles
    2010-01-16 16:45 . 2010-01-16 16:45 -------- d-----w- C:\Inetpub
    2010-01-16 16:43 . 2004-08-04 10:00 4096 ----a-w- c:\documents and settings\All Users\Application Data\Microsoft\USMT\iconlib.dll
    2010-01-15 21:11 . 2010-01-15 21:11 -------- d-----w- c:\documents and settings\Administrator\Application Data\Intel
    2010-01-15 18:47 . 2010-01-15 18:47 -------- d-----w- c:\documents and settings\Tasha Z\Local Settings\Application Data\Identities
    2010-01-14 21:22 . 2009-07-28 15:33 55656 ----a-w- c:\windows\system32\drivers\avgntflt.sys
    2010-01-14 18:31 . 2010-01-14 18:31 615514112 --sha-w- C:\NRTPage.sys
    2010-01-14 12:05 . 2010-01-14 12:05 -------- d-----w- c:\documents and settings\Tasha Z\Local Settings\Application Data\ICS
    2010-01-14 12:05 . 2010-01-14 13:48 -------- d-----w- c:\windows\LMI5.tmp
    2010-01-13 22:57 . 2010-01-13 22:57 -------- d--h--w- c:\windows\system32\GroupPolicy
    2010-01-13 22:01 . 2010-01-14 13:15 -------- d-----w- c:\windows\system32\drivers\N360
    2010-01-13 22:01 . 2010-01-13 22:01 -------- d-----w- c:\program files\Windows Sidebar
    2010-01-13 20:28 . 2010-01-14 23:04 -------- d-----w- c:\documents and settings\HelpAssistant\Tracing
    2010-01-13 20:28 . 2010-01-13 20:28 -------- d-----w- c:\program files\Microsoft
    2010-01-13 20:28 . 2010-01-13 20:28 -------- d-----w- c:\program files\Windows Live SkyDrive
    2010-01-13 19:17 . 2010-01-20 21:36 -------- d-----w- c:\documents and settings\Tasha Z\Tracing
    2010-01-13 19:15 . 2010-01-17 10:24 -------- d-----w- c:\program files\Windows Live
    2010-01-13 15:23 . 2010-01-13 15:23 -------- d-----w- c:\program files\Common Files\Windows Live
    2010-01-12 11:23 . 2010-01-12 11:23 -------- d-----w- c:\documents and settings\Tasha Z\Local Settings\Application Data\Symantec
    2010-01-12 10:38 . 2010-01-14 13:14 -------- d-----w- c:\documents and settings\All Users\Application Data\Norton
    2010-01-12 10:35 . 2010-01-13 21:57 -------- d-----w- c:\documents and settings\All Users\Application Data\NortonInstaller

    .
    (((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    2010-01-16 16:24 . 2009-10-08 18:27 -------- d-----w- c:\program files\Google
    2010-01-14 13:14 . 2007-05-30 11:17 -------- d-----w- c:\documents and settings\All Users\Application Data\Symantec
    2010-01-13 20:13 . 2007-12-25 22:57 -------- d-----w- c:\documents and settings\Tasha Z\Application Data\Apple Computer
    2010-01-13 19:17 . 2007-05-14 09:25 43832 -c--a-w- c:\documents and settings\Tasha Z\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
    2009-11-22 16:56 . 2009-11-22 16:56 31 ----a-w- c:\windows\bk20856.dat
    .

    ------- Sigcheck -------

    [-] 2007-10-30 . ECF02439FD31BBD0DBC2EC05600CF08A . 360064 . . [5.1.2600.3244] . . c:\windows\system32\dllcache\tcpip.sys
    [-] 2007-10-30 . ECF02439FD31BBD0DBC2EC05600CF08A . 360064 . . [5.1.2600.3244] . . c:\windows\system32\drivers\tcpip.sys
    [7] 2007-10-30 . 64798ECFA43D78C7178375FCDD16D8C8 . 360832 . . [5.1.2600.3244] . . c:\windows\$hf_mig$\KB941644\SP2QFE\tcpip.sys
    [7] 2006-04-20 . B2220C618B42A2212A59D91EBD6FC4B4 . 360576 . . [5.1.2600.2892] . . c:\windows\$hf_mig$\KB917953\SP2QFE\tcpip.sys
    [-] 2006-04-20 . 021415AD071EF3944C27DC9597ED2214 . 359808 . . [5.1.2600.2892] . . c:\windows\$NtUninstallKB941644$\tcpip.sys
    [-] 2004-08-04 . 1745B00FC1141404B28F4B94F69A8871 . 359040 . . [5.1.2600.2180] . . c:\windows\$NtUninstallKB917953$\tcpip.sys
    .
    ((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    *Note* empty entries & legit default entries are not shown
    REGEDIT4

    [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
    "{31c7d459-9cc3-44f2-9dca-fc11795309b4}"= "c:\program files\IObitCom\tbIObi.dll" [2009-11-09 2331672]

    [HKEY_CLASSES_ROOT\clsid\{31c7d459-9cc3-44f2-9dca-fc11795309b4}]

    [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
    "{31C7D459-9CC3-44F2-9DCA-FC11795309B4}"= "c:\program files\IObitCom\tbIObi.dll" [2009-11-09 2331672]

    [HKEY_CLASSES_ROOT\clsid\{31c7d459-9cc3-44f2-9dca-fc11795309b4}]

    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "Google Update"="c:\documents and settings\Tasha Z\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" [2010-01-16 135664]
    "MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2004-10-13 1694208]
    "msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2009-07-26 3883856]

    [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
    "Nokia.PCSync"="c:\program files\Nokia\Nokia PC Suite 6\PcSync2.exe" [2007-06-19 1241088]

    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
    "EnableFirewall"= 0 (0x0)

    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
    "%windir%\\system32\\sessmgr.exe"=
    "c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=

    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
    "3389:TCP"= 3389:TCP:Remote Desktop

    R0 O2MDRDR;O2MDRDR;c:\windows\system32\drivers\o2media.sys [27/02/2006 07:00 34880]
    R0 O2SDRDR;O2SDRDR;c:\windows\system32\drivers\o2sd.sys [20/02/2006 08:01 29056]
    R2 fssfltr;FssFltr;c:\windows\system32\drivers\fssfltr_tdi.sys [17/01/2010 10:24 54752]
    S3 fsssvc;Windows Live Family Safety Service;c:\program files\Windows Live\Family Safety\fsssvc.exe [05/08/2009 22:48 704864]
    .
    Contents of the 'Scheduled Tasks' folder

    2010-01-16 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-436374069-1500820517-725345543-1003Core.job
    - c:\documents and settings\Tasha Z\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2010-01-16 23:01]

    2010-01-20 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-436374069-1500820517-725345543-1003UA.job
    - c:\documents and settings\Tasha Z\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2010-01-16 23:01]
    .
    .
    ------- Supplementary Scan -------
    .
    uStart Page = hxxp://computerhelpforums.net/topic/14391-malware-and-trogen-problems/page__gopid__52878&
    mStart Page = hxxp://home.sweetim.com
    uSearchAssistant = hxxp://www.google.com/ie
    uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
    IE: &Search - http://edits.mywebsearch.com/toolbaredits/menusearch.jhtml?p=ZNxuk101YYGB
    TCP: {74DC3D0B-CE49-46ED-827E-4DDB1C5178D2} = 149.250.222.22
    TCP: {E7E936DD-74E9-4C8A-9D92-A6CB9C64674E} = 149.250.222.22
    .
    - - - - ORPHANS REMOVED - - - -

    URLSearchHooks-{EEE6C35D-6118-11DC-9C72-001320C79847} - (no file)
    Toolbar-instances - (no file)
    WebBrowser-{C75C8E7E-5059-4469-AC11-D7544B260382} - (no file)
    WebBrowser-{EEE6C35B-6118-11DC-9C72-001320C79847} - (no file)
    AddRemove-LiveUpdate1.6 - c:\program files\Symantec\LiveUpdate\LSETUP.EXE



    **************************************************************************

    catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
    Rootkit scan 2010-01-20 21:36
    Windows 5.1.2600 Service Pack 2 NTFS

    scanning hidden processes ...

    scanning hidden autostart entries ...

    HKCU\Software\Microsoft\Windows\CurrentVersion\Run
    msnmsgr = "c:\program files\Windows Live\Messenger\msnmsgr.exe" /background??s

    scanning hidden files ...

    scan completed successfully
    hidden files: 0

    **************************************************************************
    .
    --------------------- DLLs Loaded Under Running Processes ---------------------

    - - - - - - - > 'winlogon.exe'(788)
    c:\windows\system32\NavLogon.dll

    - - - - - - - > 'explorer.exe'(1016)
    c:\progra~1\COMMON~1\MICROS~1\WEBCOM~1\10\OWC10.DLL
    c:\progra~1\COMMON~1\MICROS~1\WEBCOM~1\11\OWC11.DLL
    c:\windows\system32\shdoclc.dll
    .
    ------------------------ Other Running Processes ------------------------
    .
    c:\program files\Intel\Wireless\Bin\EvtEng.exe
    c:\program files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
    c:\windows\system32\wscntfy.exe
    c:\program files\Windows Live\Contacts\wlcomm.exe
    .
    **************************************************************************
    .
    Completion time: 2010-01-20 21:39:42 - machine was rebooted
    ComboFix-quarantined-files.txt 2010-01-20 21:39

    Pre-Run: 91,152,277,504 bytes free
    Post-Run: 91,721,412,608 bytes free

    - - End Of File - - 151A666E0FC89EB0F2A54B096FFA3EE7
     
  9. wendy

    wendy Registered Members

    Joined:
    Jan 18, 2010
    Messages:
    49
    Location:
    wales uk
    Operating System:
    Windows XP Home
     
  10. schrauber

    schrauber Guest

    Round one goes to us ;)

    Now next round:


    Please download Malwarebytes Anti-Malware and save it to your desktop.
    alternate download link 1
    alternate download link 2

    MBAM may "make changes to your registry" as part of its disinfection routine. If using other security programs that detect registry changes (ie Spybot's Teatimer), they may interfere or alert you. Temporarily disable such programs or permit them to allow the changes.
    • Make sure you are connected to the Internet.
    • Double-click on mbam-setup.exe to install the application.
    • When the installation begins, follow the prompts and do not make any changes to default settings.
    • When installation has finished, make sure you leave both of these checked:
      • Update Malwarebytes' Anti-Malware
      • Launch Malwarebytes' Anti-Malware
    • Then click Finish.
    MBAM will automatically start and you will be asked to update the program before performing a scan.
    • If an update is found, the program will automatically update itself. Press the OK button to close that box and continue.
    • If you encounter any problems while downloading the definition updates, manually download them from here and just double-click on mbam-rules.exe to install.
    On the Scanner tab:
    • Make sure the "Perform Quick Scan" option is selected.
    • Then click on the Scan button.
    • If asked to select the drives to scan, leave all the drives selected and click on the Start Scan button.
    • The scan will begin and "Scan in progress" will show at the top. It may take some time to complete so please be patient.
    • When the scan is finished, a message box will say "The scan completed successfully. Click 'Show Results' to display all objects found".
    • Click OK to close the message box and continue with the removal process.
    Back at the main Scanner screen:
    • Click on the Show Results button to see a list of any malware that was found.
    • Make sure that everything is checked, and click Remove Selected.
    • When removal is completed, a log report will open in Notepad.
    • The log is automatically saved and can be viewed by clicking the Logs tab in MBAM.
    • Copy and paste the contents of that report in your next reply. Be sure to post the complete log to include the top portion which shows MBAM's database version and your operating system.
    • Exit MBAM when done.
    Note: If MBAM encounters a file that is difficult to remove, you will be asked to reboot your computer so MBAM can proceed with the disinfection process. If asked to restart the computer, please do so immediately. Failure to reboot normally (not into safe mode) will prevent MBAM from removing all the malware.



    Also please post back with a fresh OTL logfile after using Malwarebytes.
     
  11. wendy

    wendy Registered Members

    Joined:
    Jan 18, 2010
    Messages:
    49
    Location:
    wales uk
    Operating System:
    Windows XP Home
     
  12. schrauber

    schrauber Guest

    Hi,

    Now please post back with a fresh OTL logfile.
     
  13. wendy

    wendy Registered Members

    Joined:
    Jan 18, 2010
    Messages:
    49
    Location:
    wales uk
    Operating System:
    Windows XP Home
    OTL logfile created on: 21/01/2010 10:25:11 - Run 2
    OTL by OldTimer - Version 3.1.25.2 Folder = C:\Documents and Settings\Tasha Z\Desktop
    Windows XP Professional Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
    Internet Explorer (Version = 6.0.2900.2180)
    Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy

    502.00 Mb Total Physical Memory | 132.00 Mb Available Physical Memory | 26.00% Memory free
    1.00 Gb Paging File | 1.00 Gb Available in Paging File | 72.00% Paging File free
    Paging file location(s): c:\pagefile.sys 756 1512 [binary data]

    %SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
    Drive C: | 93.15 Gb Total Space | 85.37 Gb Free Space | 91.65% Space Free | Partition Type: NTFS
    D: Drive not present or media not loaded
    E: Drive not present or media not loaded
    F: Drive not present or media not loaded
    G: Drive not present or media not loaded
    H: Drive not present or media not loaded
    I: Drive not present or media not loaded

    Computer Name: TASHA
    Current User Name: Tasha Z
    Logged in as Administrator.

    Current Boot Mode: Normal
    Scan Mode: Current user
    Company Name Whitelist: Off
    Skip Microsoft Files: Off
    File Age = 30 Days
    Output = Standard

    ========== Processes (SafeList) ==========

    PRC - [2010/01/20 12:26:26 | 00,547,328 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Tasha Z\Desktop\OTL.exe
    PRC - [2009/09/30 19:58:42 | 00,026,464 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Windows Live\Contacts\wlcomm.exe
    PRC - [2009/01/14 17:53:02 | 00,226,656 | ---- | M] (Microsoft Corp.) -- C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
    PRC - [2007/06/13 10:23:07 | 01,033,216 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe
    PRC - [2005/11/28 11:29:00 | 00,114,753 | ---- | M] (Intel Corporation) -- C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
    PRC - [2004/08/04 10:00:00 | 00,013,824 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\wscntfy.exe


    ========== Modules (SafeList) ==========

    MOD - [2010/01/20 12:26:26 | 00,547,328 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Tasha Z\Desktop\OTL.exe
    MOD - [2006/08/25 15:45:55 | 01,054,208 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03\comctl32.dll


    ========== Win32 Services (SafeList) ==========

    SRV - [2009/08/05 22:48:42 | 00,704,864 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files\Windows Live\Family Safety\fsssvc.exe -- (fsssvc)
    SRV - [2009/01/14 17:53:02 | 00,226,656 | ---- | M] (Microsoft Corp.) [Auto | Running] -- C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe -- (SeaPort)
    SRV - [2005/11/28 11:29:00 | 00,114,753 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files\Intel\Wireless\Bin\EvtEng.exe -- (EvtEng) Intel(R)
    SRV - [2004/10/22 03:24:18 | 00,073,728 | ---- | M] (Macrovision Corporation) [On_Demand | Stopped] -- C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe -- (IDriverT)
    SRV - [2003/07/28 12:28:22 | 00,089,136 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE -- (ose)


    ========== Driver Services (SafeList) ==========

    DRV - [2009/08/05 22:48:42 | 00,054,752 | ---- | M] (Microsoft Corporation) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\fssfltr_tdi.sys -- (fssfltr)
    DRV - [2007/11/13 10:25:53 | 00,020,480 | ---- | M] (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\secdrv.sys -- (Secdrv)
    DRV - [2006/12/19 20:27:32 | 00,021,275 | ---- | M] (Meetinghouse Data Communications) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\AegisP.sys -- (AegisP) AEGIS Protocol (IEEE 802.1x)
    DRV - [2006/09/12 11:27:00 | 04,381,184 | R--- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\RtkHDAud.Sys -- (IntcAzAudAddService) Service for Realtek HD Audio (WDM)
    DRV - [2006/03/23 04:47:06 | 01,166,972 | R--- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\ialmnt5.sys -- (ialm)
    DRV - [2006/02/27 07:00:50 | 00,034,880 | ---- | M] (O2Micro ) [Kernel | Boot | Running] -- C:\WINDOWS\System32\DRIVERS\o2media.sys -- (O2MDRDR)
    DRV - [2006/02/26 21:46:20 | 00,081,408 | R--- | M] (Realtek Semiconductor Corporation ) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\Rtnicxp.sys -- (RTL8023xp)
    DRV - [2006/02/20 08:01:06 | 00,029,056 | ---- | M] (O2Micro ) [Kernel | Boot | Running] -- C:\WINDOWS\System32\DRIVERS\o2sd.sys -- (O2SDRDR)
    DRV - [2006/01/20 04:44:42 | 00,862,340 | R--- | M] (Motorola Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\smserial.sys -- (smserial)
    DRV - [2005/12/04 16:55:30 | 01,428,096 | R--- | M] (Intel® Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\w39n51.sys -- (w39n51) Intel(R)
    DRV - [2005/11/28 12:09:26 | 00,013,568 | ---- | M] (Intel Corporation) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\s24trans.sys -- (s24trans)
    DRV - [2005/01/07 17:07:18 | 00,138,752 | ---- | M] (Windows (R) Server 2003 DDK provider) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\Hdaudbus.sys -- (HDAudBus)
    DRV - [2004/12/13 21:14:00 | 00,039,904 | ---- | M] (Adaptec, Inc.) [Kernel | Boot | Stopped] -- C:\WINDOWS\system32\drivers\cercsr6.sys -- (cercsr6)
    DRV - [2004/08/04 10:00:00 | 00,017,792 | ---- | M] (Parallel Technologies, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\ptilink.sys -- (Ptilink)


    ========== Standard Registry (SafeList) ==========


    ========== Internet Explorer ==========

    IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
    IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://home.sweetim.com
    IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie

    IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://computerhelpforums.net/topic/14391-malware-and-trogen-problems/page__gopid__52878&
    IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie
    IE - HKCU\..\URLSearchHook: {31c7d459-9cc3-44f2-9dca-fc11795309b4} - C:\Program Files\IObitCom\tbIObi.dll (Conduit Ltd.)
    IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

    ========== FireFox ==========

    FF - prefs.js..browser.search.defaultenginename: "Google"
    FF - prefs.js..browser.search.defaulturl: "http://www.google.com/search?lr=&ie=UTF-8&oe=UTF-8&q="
    FF - prefs.js..browser.search.selectedEngine: "Google"

    FF - HKLM\software\mozilla\Firefox\Extensions\\{3112ca9c-de6d-4884-a869-9855de68056c}: C:\Documents and Settings\All Users\Application Data\Mozilla\Firefox Extensions\{3112ca9c-de6d-4884-a869-9855de68056c} [2007/09/23 13:00:04 | 00,000,000 | ---D | M]

    [2007/11/07 21:38:29 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Tasha Z\Application Data\Mozilla\Firefox\Profiles\uykhn9v0.default\extensions

    O1 HOSTS File: ([2010/01/20 21:35:53 | 00,000,027 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
    O1 - Hosts: 127.0.0.1 localhost
    O2 - BHO: (Search Helper) - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SearchHelper.dll (Microsoft Corp.)
    O2 - BHO: (Windows Live Toolbar Helper) - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files\Windows Live\Toolbar\wltcore.dll (Microsoft Corporation)
    O3 - HKLM\..\Toolbar: (&Windows Live Toolbar) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll (Microsoft Corporation)
    O3 - HKCU\..\Toolbar\ShellBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No CLSID value found.
    O3 - HKCU\..\Toolbar\ShellBrowser: (no name) - {C75C8E7E-5059-4469-AC11-D7544B260382} - No CLSID value found.
    O3 - HKCU\..\Toolbar\WebBrowser: (&Windows Live Toolbar) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll (Microsoft Corporation)
    O3 - HKCU\..\Toolbar\WebBrowser: (IObitCom Toolbar) - {31C7D459-9CC3-44F2-9DCA-FC11795309B4} - C:\Program Files\IObitCom\tbIObi.dll (Conduit Ltd.)
    O3 - HKCU\..\Toolbar\WebBrowser: (Yahoo! Toolbar) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.)
    O4 - HKCU..\Run: [Google Update] C:\Documents and Settings\Tasha Z\Local Settings\Application Data\Google\Update\GoogleUpdate.exe (Google Inc.)
    O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Infodelivery present
    O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: LinkResolveIgnoreLinkInfo = 0
    O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoResolveSearch = 1
    O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
    O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
    O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
    O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
    O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
    O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: LinkResolveIgnoreLinkInfo = 0
    O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
    O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
    O15 - HKLM\..Trusted Domains: 1 domain(s) and sub-domain(s) not assigned to a zone.
    O15 - HKCU\..Trusted Domains: ([]msn in My Computer)
    O15 - HKCU\..Trusted Domains: 8 domain(s) and sub-domain(s) not assigned to a zone.
    O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
    O18 - Protocol\Handler\vnd.ms.radio {3DA2AA3B-3D96-11D2-9BD2-204C4F4F5020} - C:\WINDOWS\system32\msdxm.ocx ()
    O18 - Protocol\Handler\wlmailhtml {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - C:\Program Files\Windows Live\Mail\mailcomm.dll (Microsoft Corporation)
    O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
    O20 - Winlogon\Notify\igfxcui: DllName - igfxdev.dll - C:\WINDOWS\System32\igfxdev.dll (Intel Corporation)
    O20 - Winlogon\Notify\NavLogon: DllName - C:\WINDOWS\system32\NavLogon.dll - C:\WINDOWS\system32\NavLogon.dll ()
    O24 - Desktop Components:1 () - http://www.orange.co.uk/
    O24 - Desktop WallPaper: C:\Documents and Settings\Tasha Z\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
    O24 - Desktop BackupWallPaper: C:\Documents and Settings\Tasha Z\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
    O32 - HKLM CDRom: AutoRun - 1
    O32 - AutoRun File - [2006/12/18 22:35:04 | 00,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
    O34 - HKLM BootExecute: (autocheck autochk *) - File not found
    O35 - comfile [open] -- "%1" %*
    O35 - exefile [open] -- "%1" %*

    ========== Files/Folders - Created Within 30 Days ==========

    [2010/01/21 10:21:08 | 00,016,736 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\mucltui.dll.mui
    [2010/01/21 10:21:07 | 00,274,288 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\mucltui.dll
    [2010/01/21 10:20:42 | 00,000,000 | ---D | C] -- C:\WINDOWS\LastGood
    [2010/01/20 22:06:08 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Tasha Z\Application Data\Malwarebytes
    [2010/01/20 22:06:04 | 00,038,224 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbamswissarmy.sys
    [2010/01/20 22:06:02 | 00,019,160 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbam.sys
    [2010/01/20 22:06:02 | 00,000,000 | ---D | C] -- C:\Program Files\Malwarebytes' Anti-Malware
    [2010/01/20 22:06:02 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Malwarebytes
    [2010/01/20 21:39:46 | 00,000,000 | ---D | C] -- C:\WINDOWS\temp
    [2010/01/20 20:32:12 | 00,000,000 | RHSD | C] -- C:\cmdcons
    [2010/01/20 20:29:50 | 00,212,480 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWXCACLS.exe
    [2010/01/20 20:29:50 | 00,161,792 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWREG.exe
    [2010/01/20 20:29:50 | 00,136,704 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWSC.exe
    [2010/01/20 20:29:50 | 00,031,232 | ---- | C] (NirSoft) -- C:\WINDOWS\NIRCMD.exe
    [2010/01/20 20:29:41 | 00,000,000 | ---D | C] -- C:\WINDOWS\ERDNT
    [2010/01/20 20:29:27 | 00,000,000 | ---D | C] -- C:\Qoobox
    [2010/01/20 12:26:19 | 00,547,328 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\Tasha Z\Desktop\OTL.exe
    [2010/01/17 10:24:24 | 00,054,752 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\fssfltr_tdi.sys
    [2010/01/16 23:33:09 | 00,000,000 | ---D | C] -- C:\Program Files\Microsoft Sync Framework
    [2010/01/16 23:07:23 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Tasha Z\My Documents\Downloads
    [2010/01/16 23:01:38 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Tasha Z\Local Settings\Application Data\Temp
    [2010/01/16 22:27:00 | 00,000,000 | R--D | C] -- C:\Documents and Settings\Tasha Z\My Documents\Copy of My Music
    [2010/01/16 22:25:44 | 00,000,000 | ---D | C] -- C:\Program Files\msn gaming zone
    [2010/01/16 18:25:58 | 00,000,000 | ---D | C] -- C:\Program Files\IObitCom
    [2010/01/16 18:25:58 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Tasha Z\Local Settings\Application Data\IObitCom
    [2010/01/16 18:25:58 | 00,000,000 | ---D | C] -- C:\Program Files\Conduit
    [2010/01/16 18:25:58 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Tasha Z\Local Settings\Application Data\Conduit
    [2010/01/16 18:25:50 | 00,000,000 | ---D | C] -- C:\Program Files\IObit
    [2010/01/16 18:25:50 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Tasha Z\Application Data\IObit
    [2010/01/16 18:24:32 | 09,537,816 | ---- | C] (IObit ) -- C:\Documents and Settings\Tasha Z\My Documents\asc-setup.exe
    [2010/01/16 16:45:05 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\Logfiles
    [2010/01/16 16:45:05 | 00,000,000 | ---D | C] -- C:\Inetpub
    [2010/01/15 18:47:01 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Tasha Z\Local Settings\Application Data\Identities
    [2010/01/14 21:53:48 | 00,000,000 | ---D | M] -- C:\Documents and Settings\LocalService\Application Data\Adobe
    [2010/01/14 21:22:20 | 00,055,656 | ---- | C] (Avira GmbH) -- C:\WINDOWS\System32\drivers\avgntflt.sys
    [2010/01/14 12:05:59 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Tasha Z\Local Settings\Application Data\ICS
    [2010/01/14 12:05:46 | 00,000,000 | ---D | C] -- C:\WINDOWS\LMI5.tmp
    [2010/01/13 22:57:09 | 00,000,000 | -H-D | C] -- C:\WINDOWS\System32\GroupPolicy
    [2010/01/13 22:01:24 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\drivers\N360
    [2010/01/13 22:01:21 | 00,000,000 | ---D | C] -- C:\Program Files\Windows Sidebar
    [2010/01/13 20:28:35 | 00,000,000 | ---D | C] -- C:\Program Files\Microsoft
    [2010/01/13 20:28:33 | 00,000,000 | ---D | C] -- C:\Program Files\Windows Live SkyDrive
    [2010/01/13 20:27:36 | 00,000,000 | ---D | C] -- C:\Config.Msi
    [2010/01/13 19:17:37 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Tasha Z\Tracing
    [2010/01/13 19:15:58 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Documents\microsoft
    [2010/01/13 19:15:12 | 00,000,000 | ---D | C] -- C:\Program Files\Windows Live
    [2010/01/13 15:23:54 | 00,000,000 | ---D | C] -- C:\Program Files\Common Files\Windows Live
    [2010/01/13 10:21:39 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Tasha Z\Desktop\mike
    [2010/01/12 13:40:18 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Tasha Z\Desktop\sue doc
    [2010/01/12 11:23:50 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Tasha Z\Local Settings\Application Data\Symantec
    [2010/01/12 10:38:26 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Norton
    [2010/01/12 10:35:39 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\NortonInstaller
    [2010/01/12 10:22:24 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\appmgmt
    [2007/07/27 13:55:54 | 00,000,000 | ---D | M] -- C:\Documents and Settings\LocalService\Application Data\Help
    [2007/07/27 13:55:29 | 00,000,000 | ---D | M] -- C:\Documents and Settings\LocalService\Local Settings\Application Data\Help
    [2007/05/30 11:08:08 | 00,000,000 | ---D | M] -- C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft
    [2007/05/30 11:08:08 | 00,000,000 | ---D | M] -- C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft
    [2006/12/18 22:34:43 | 00,000,000 | --SD | M] -- C:\Documents and Settings\NetworkService\Application Data\Microsoft
    [2006/12/18 22:34:43 | 00,000,000 | --SD | M] -- C:\Documents and Settings\LocalService\Application Data\Microsoft
    [8 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
    [1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]

    ========== Files - Modified Within 30 Days ==========

    [2010/01/21 10:19:06 | 00,000,006 | -H-- | M] () -- C:\WINDOWS\tasks\SA.DAT
    [2010/01/21 10:19:04 | 00,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
    [2010/01/20 22:38:33 | 03,932,160 | -H-- | M] () -- C:\Documents and Settings\Tasha Z\NTUSER.DAT
    [2010/01/20 22:38:27 | 00,000,278 | -HS- | M] () -- C:\Documents and Settings\Tasha Z\ntuser.ini
    [2010/01/20 22:38:24 | 03,755,146 | -H-- | M] () -- C:\Documents and Settings\Tasha Z\Local Settings\Application Data\IconCache.db
    [2010/01/20 22:06:15 | 00,000,986 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-436374069-1500820517-725345543-1003UA.job
    [2010/01/20 22:06:06 | 00,000,696 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
    [2010/01/20 21:36:07 | 00,000,000 | ---- | M] () -- C:\WINDOWS\system.ini
    [2010/01/20 21:35:53 | 00,000,027 | ---- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts
    [2010/01/20 20:32:18 | 00,000,281 | RHS- | M] () -- C:\boot.ini
    [2010/01/20 20:27:41 | 03,830,599 | R--- | M] () -- C:\Documents and Settings\Tasha Z\Desktop\schrauber.exe
    [2010/01/20 16:35:46 | 00,293,376 | ---- | M] () -- C:\Documents and Settings\Tasha Z\Desktop\u0n696ig.exe
    [2010/01/20 12:26:26 | 00,547,328 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Tasha Z\Desktop\OTL.exe
    [2010/01/19 21:40:32 | 00,002,444 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
    [2010/01/17 10:35:07 | 00,315,408 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat
    [2010/01/17 10:35:07 | 00,041,586 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat
    [2010/01/17 10:35:06 | 00,360,124 | ---- | M] () -- C:\WINDOWS\System32\PerfStringBackup.INI
    [2010/01/16 23:06:00 | 00,000,934 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-436374069-1500820517-725345543-1003Core.job
    [2010/01/16 22:17:15 | 00,005,569 | ---- | M] () -- C:\Documents and Settings\Tasha Z\My Documents\My Favorite Theme.theme
    [2010/01/16 18:56:28 | 00,502,752 | ---- | M] () -- C:\Documents and Settings\Tasha Z\My Documents\cfremover.exe
    [2010/01/16 18:25:56 | 00,000,874 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Advanced SystemCare.lnk
    [2010/01/16 18:25:19 | 09,537,816 | ---- | M] (IObit ) -- C:\Documents and Settings\Tasha Z\My Documents\asc-setup.exe
    [2010/01/15 19:27:04 | 00,003,739 | ---- | M] () -- C:\WINDOWS\imsins.BAK
    [2010/01/15 18:31:51 | 52,659,8144 | ---- | M] () -- C:\WINDOWS\MEMORY.DMP
    [2010/01/14 23:20:16 | 00,000,162 | -H-- | M] () -- C:\Documents and Settings\Tasha Z\My Documents\~$ssage to Natasha Skye Zeraschi.doc
    [2010/01/14 21:57:52 | 00,000,779 | ---- | M] () -- C:\Documents and Settings\Tasha Z\Desktop\Launch Internet Explorer Browser.lnk
    [2010/01/14 18:31:15 | 61,551,4112 | -HS- | M] () -- C:\NRTPage.sys
    [2010/01/14 18:03:27 | 00,000,211 | ---- | M] () -- C:\Boot.bak
    [2010/01/14 18:03:27 | 00,000,000 | ---- | M] () -- C:\WINDOWS\win.ini
    [2010/01/13 20:13:16 | 00,001,743 | ---- | M] () -- C:\Documents and Settings\All Users\Application Data\QTSBandwidthCache
    [2010/01/13 19:42:48 | 00,195,368 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT
    [2010/01/13 19:17:14 | 00,043,832 | ---- | M] () -- C:\Documents and Settings\Tasha Z\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
    [2010/01/13 10:24:35 | 25,753,6806 | ---- | M] () -- C:\Documents and Settings\Tasha Z\Desktop\photos 1.zip
    [2010/01/12 12:48:44 | 00,002,473 | ---- | M] () -- C:\Documents and Settings\All Users\Documents\Global.sw2
    [2010/01/12 10:21:17 | 00,000,453 | ---- | M] () -- C:\WINDOWS\ODBC.INI
    [2010/01/07 16:07:14 | 00,038,224 | ---- | M] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbamswissarmy.sys
    [2010/01/07 16:07:04 | 00,019,160 | ---- | M] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbam.sys
    [8 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
    [1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]

    ========== Files Created - No Company Name ==========

    [2010/01/20 22:06:06 | 00,000,696 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
    [2010/01/20 20:32:18 | 00,000,211 | ---- | C] () -- C:\Boot.bak
    [2010/01/20 20:32:14 | 00,260,272 | ---- | C] () -- C:\cmldr
    [2010/01/20 20:29:50 | 00,261,632 | ---- | C] () -- C:\WINDOWS\PEV.exe
    [2010/01/20 20:29:50 | 00,098,816 | ---- | C] () -- C:\WINDOWS\sed.exe
    [2010/01/20 20:29:50 | 00,080,412 | ---- | C] () -- C:\WINDOWS\grep.exe
    [2010/01/20 20:29:50 | 00,077,312 | ---- | C] () -- C:\WINDOWS\MBR.exe
    [2010/01/20 20:29:50 | 00,068,096 | ---- | C] () -- C:\WINDOWS\zip.exe
    [2010/01/20 20:27:41 | 03,830,599 | R--- | C] () -- C:\Documents and Settings\Tasha Z\Desktop\schrauber.exe
    [2010/01/20 16:35:45 | 00,293,376 | ---- | C] () -- C:\Documents and Settings\Tasha Z\Desktop\u0n696ig.exe
    [2010/01/16 23:01:25 | 00,000,986 | ---- | C] () -- C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-436374069-1500820517-725345543-1003UA.job
    [2010/01/16 23:01:24 | 00,000,934 | ---- | C] () -- C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-436374069-1500820517-725345543-1003Core.job
    [2010/01/16 18:56:04 | 00,502,752 | ---- | C] () -- C:\Documents and Settings\Tasha Z\My Documents\cfremover.exe
    [2010/01/16 18:25:56 | 00,000,874 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Advanced SystemCare.lnk
    [2010/01/14 23:20:16 | 00,000,162 | -H-- | C] () -- C:\Documents and Settings\Tasha Z\My Documents\~$ssage to Natasha Skye Zeraschi.doc
    [2010/01/14 18:31:15 | 61,551,4112 | -HS- | C] () -- C:\NRTPage.sys
    [2010/01/13 20:13:16 | 00,001,743 | ---- | C] () -- C:\Documents and Settings\All Users\Application Data\QTSBandwidthCache
    [2010/01/13 10:23:37 | 25,753,6806 | ---- | C] () -- C:\Documents and Settings\Tasha Z\Desktop\photos 1.zip
    [2010/01/12 12:21:18 | 00,005,569 | ---- | C] () -- C:\Documents and Settings\Tasha Z\My Documents\My Favorite Theme.theme
    [2009/03/21 20:06:40 | 00,002,880 | ---- | C] () -- C:\Documents and Settings\Tasha Z\Application Data\NMM-MetaData.db
    [2007/12/25 23:22:03 | 00,009,216 | ---- | C] () -- C:\Documents and Settings\Tasha Z\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
    [2007/09/18 10:52:59 | 00,326,589 | ---- | C] () -- C:\Documents and Settings\Tasha Z\Application Data\update.log
    [2007/03/29 23:00:40 | 00,203,264 | R--- | C] () -- C:\WINDOWS\System32\CddbCdda.dll
    [2006/12/19 20:28:00 | 00,000,453 | ---- | C] () -- C:\WINDOWS\ODBC.INI
    [2006/12/19 20:14:37 | 00,069,632 | R--- | C] () -- C:\WINDOWS\sm56spn.dll
    [2006/12/19 20:14:37 | 00,069,632 | R--- | C] () -- C:\WINDOWS\sm56itl.dll
    [2006/12/19 20:14:37 | 00,069,632 | R--- | C] () -- C:\WINDOWS\sm56eng.dll
    [2006/12/19 20:14:37 | 00,069,632 | R--- | C] () -- C:\WINDOWS\sm56brz.dll
    [2006/12/19 20:14:37 | 00,061,440 | R--- | C] () -- C:\WINDOWS\sm56ger.dll
    [2006/12/19 20:14:37 | 00,061,440 | R--- | C] () -- C:\WINDOWS\sm56fra.dll
    [2006/12/19 20:14:37 | 00,053,248 | R--- | C] () -- C:\WINDOWS\sm56jpn.dll
    [2006/12/19 20:14:37 | 00,049,152 | R--- | C] () -- C:\WINDOWS\sm56cht.dll
    [2006/12/19 20:14:37 | 00,049,152 | R--- | C] () -- C:\WINDOWS\sm56chs.dll
    [2005/01/21 04:02:28 | 00,013,312 | ---- | C] () -- C:\WINDOWS\System32\RMDevice.dll
    [2004/08/04 10:00:00 | 00,081,920 | ---- | C] () -- C:\WINDOWS\System32\ieencode.dll
    [2003/01/07 15:05:08 | 00,002,695 | ---- | C] () -- C:\WINDOWS\System32\OUTLPERF.INI
    [2001/09/24 06:59:00 | 00,045,056 | ---- | C] () -- C:\WINDOWS\System32\NavLogon.dll
    < End of report >
     
  14. schrauber

    schrauber Guest

    Hi,

    How is it running right now?


    Step 1

    Run OTL
    • Under the Custom Scans/Fixes box at the bottom, paste in the following
      Code:
      :OTL
      O3 - HKCU\..\Toolbar\ShellBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No CLSID value found.
      O3 - HKCU\..\Toolbar\ShellBrowser: (no name) - {C75C8E7E-5059-4469-AC11-D7544B260382} - No CLSID value found.
      :Commands
      [emptytemp]
    • Then click the Run Fix button at the top
    • Let the program run unhindered, when done it will say "Fix Complete press ok to open the log"
    • Please post that log in your next reply. Note: If a file or folder cannot be moved immediately you may be asked to reboot the machine to finish the move process. If you are asked to reboot the machine choose Yes. In this case, after the reboot, open Notepad (Start->All Programs->Accessories->Notepad), click File->Open, in the File Name box enter *.log and press the Enter key, navigate to the C:\_OTL\MovedFiles folder, and open the newest .log file present, and copy/paste the contents of that document back here in your next post.
    ================================Follow up scan=================================
    • Double click on OTL to run it. Make sure all other windows are closed and to let it run uninterrupted.
    • When the window appears, underneath Output at the top change it to Minimal Output.
    • Under the Standard Registry box change it to All.
    • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
      • When the scan completes, it will open one notepad window. OTL.Txt a This is saved in the same location as OTL.
      • Please copy (Edit->Select All, Edit->Copy) the contents of this file and post it with your next reply.



    Step 2

    I'd like us to scan your machine with ESET OnlineScan
    • Hold down Control and click on the following link to open ESET OnlineScan in a new window.
      ESET OnlineScan
    • Click the [​IMG] button.
    • For alternate browsers only: (Microsoft Internet Explorer users can skip these steps)
      • Click on [​IMG] to download the ESET Smart Installer. Save it to your desktop.
      • Double click on the [​IMG] icon on your desktop.
    • Check [​IMG]
    • Click the [​IMG] button.
    • Accept any security warnings from your browser.
    • Check [​IMG]
    • Push the Start button.
    • ESET will then download updates for itself, install itself, and begin scanning your computer. Please be patient as this can take some time.
    • When the scan completes, push [​IMG]
    • Push [​IMG], and save the file to your desktop using a unique name, such as ESETScan. Include the contents of this report in your next reply.
    • Push the [​IMG] button.
    • Push [​IMG]
    A log file will be saved here: C:\Program Files\ESET\ESET Online Scanner\log.txt
     
  15. wendy

    wendy Registered Members

    Joined:
    Jan 18, 2010
    Messages:
    49
    Location:
    wales uk
    Operating System:
    Windows XP Home
    hi computer working fine will just do what you said in your last reply and let you know tonight
    Thanks
    wendy
     
  16. wendy

    wendy Registered Members

    Joined:
    Jan 18, 2010
    Messages:
    49
    Location:
    wales uk
    Operating System:
    Windows XP Home
     
  17. wendy

    wendy Registered Members

    Joined:
    Jan 18, 2010
    Messages:
    49
    Location:
    wales uk
    Operating System:
    Windows XP Home
    otOTL logfile created on: 21/01/2010 19:38:03 - Run 4
    OTL by OldTimer - Version 3.1.25.2 Folder = C:\Documents and Settings\Tasha Z\Desktop
    Windows XP Professional Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
    Internet Explorer (Version = 6.0.2900.2180)
    Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy

    502.00 Mb Total Physical Memory | 228.00 Mb Available Physical Memory | 45.00% Memory free
    1.00 Gb Paging File | 1.00 Gb Available in Paging File | 80.00% Paging File free
    Paging file location(s): c:\pagefile.sys 756 1512 [binary data]

    %SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
    Drive C: | 93.15 Gb Total Space | 85.58 Gb Free Space | 91.88% Space Free | Partition Type: NTFS
    D: Drive not present or media not loaded
    E: Drive not present or media not loaded
    F: Drive not present or media not loaded
    G: Drive not present or media not loaded
    H: Drive not present or media not loaded
    I: Drive not present or media not loaded

    Computer Name: TASHA
    Current User Name: Tasha Z
    Logged in as Administrator.

    Current Boot Mode: Normal
    Scan Mode: Current user
    Company Name Whitelist: Off
    Skip Microsoft Files: Off
    File Age = 30 Days
    Output = Minimal

    ========== Processes (SafeList) ==========

    PRC - C:\Documents and Settings\Tasha Z\Desktop\OTL.exe (OldTimer Tools)
    PRC - C:\Program Files\Windows Live\Contacts\wlcomm.exe (Microsoft Corporation)
    PRC - C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe (Microsoft Corp.)
    PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
    PRC - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe (Intel Corporation)
    PRC - C:\WINDOWS\system32\wscntfy.exe (Microsoft Corporation)


    ========== Modules (SafeList) ==========

    MOD - C:\Documents and Settings\Tasha Z\Desktop\OTL.exe (OldTimer Tools)
    MOD - C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03\comctl32.dll (Microsoft Corporation)


    ========== Win32 Services (SafeList) ==========

    SRV - (fsssvc) -- C:\Program Files\Windows Live\Family Safety\fsssvc.exe (Microsoft Corporation)
    SRV - (SeaPort) -- C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe (Microsoft Corp.)
    SRV - (EvtEng) Intel(R) -- C:\Program Files\Intel\Wireless\Bin\EvtEng.exe (Intel Corporation)
    SRV - (IDriverT) -- C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe (Macrovision Corporation)
    SRV - (ose) -- C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE (Microsoft Corporation)


    ========== Driver Services (SafeList) ==========

    DRV - (fssfltr) -- C:\WINDOWS\system32\drivers\fssfltr_tdi.sys (Microsoft Corporation)
    DRV - (Secdrv) -- C:\WINDOWS\system32\drivers\secdrv.sys (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.)
    DRV - (AegisP) AEGIS Protocol (IEEE 802.1x) -- C:\WINDOWS\system32\drivers\AegisP.sys (Meetinghouse Data Communications)
    DRV - (IntcAzAudAddService) Service for Realtek HD Audio (WDM) -- C:\WINDOWS\system32\drivers\RtkHDAud.Sys (Realtek Semiconductor Corp.)
    DRV - (ialm) -- C:\WINDOWS\system32\drivers\ialmnt5.sys (Intel Corporation)
    DRV - (O2MDRDR) -- C:\WINDOWS\System32\DRIVERS\o2media.sys (O2Micro )
    DRV - (RTL8023xp) -- C:\WINDOWS\system32\drivers\Rtnicxp.sys (Realtek Semiconductor Corporation )
    DRV - (O2SDRDR) -- C:\WINDOWS\System32\DRIVERS\o2sd.sys (O2Micro )
    DRV - (smserial) -- C:\WINDOWS\system32\drivers\smserial.sys (Motorola Inc.)
    DRV - (w39n51) Intel(R) -- C:\WINDOWS\system32\drivers\w39n51.sys (Intel® Corporation)
    DRV - (s24trans) -- C:\WINDOWS\system32\drivers\s24trans.sys (Intel Corporation)
    DRV - (HDAudBus) -- C:\WINDOWS\system32\drivers\Hdaudbus.sys (Windows (R) Server 2003 DDK provider)
    DRV - (cercsr6) -- C:\WINDOWS\system32\drivers\cercsr6.sys (Adaptec, Inc.)
    DRV - (Ptilink) -- C:\WINDOWS\system32\drivers\ptilink.sys (Parallel Technologies, Inc.)


    ========== Standard Registry (All) ==========


    ========== Internet Explorer ==========

    IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
    IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
    IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
    IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://home.sweetim.com
    IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomizeSearch = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm
    IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie
    IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm

    IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\system32\blank.htm
    IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Page_Transitions = 1
    IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
    IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://computerhelpforums.net/topic/14391-malware-and-trogen-problems/page__gopid__52878&
    IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie
    IE - HKCU\..\URLSearchHook: {31c7d459-9cc3-44f2-9dca-fc11795309b4} - C:\Program Files\IObitCom\tbIObi.dll (Conduit Ltd.)
    IE - HKCU\..\URLSearchHook: {CFBFAE00-17A6-11D0-99CB-00C04FD64497} - C:\WINDOWS\system32\shdocvw.dll (Microsoft Corporation)
    IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

    ========== FireFox ==========

    FF - prefs.js..browser.search.defaultenginename: "Google"
    FF - prefs.js..browser.search.defaulturl: "http://www.google.com/search?lr=&ie=UTF-8&oe=UTF-8&q="
    FF - prefs.js..browser.search.selectedEngine: "Google"

    FF - HKLM\software\mozilla\Firefox\Extensions\\{3112ca9c-de6d-4884-a869-9855de68056c}: C:\Documents and Settings\All Users\Application Data\Mozilla\Firefox Extensions\{3112ca9c-de6d-4884-a869-9855de68056c} [2007/09/23 13:00:04 | 00,000,000 | ---D | M]

    [2007/11/07 21:38:29 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Tasha Z\Application Data\Mozilla\Firefox\Profiles\uykhn9v0.default\extensions
    [2007/11/07 21:38:29 | 00,000,000 | ---D | M] (Google Toolbar for Firefox) -- C:\Documents and Settings\Tasha Z\Application Data\Mozilla\Firefox\Profiles\uykhn9v0.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}
    [2007/07/26 23:03:34 | 00,717,312 | ---- | M] (DivX,Inc.) -- C:\Program Files\Mozilla Firefox\plugins\npdivx32.dll
    [2007/05/10 21:52:34 | 00,095,864 | ---- | M] (Adobe Systems Inc.) -- C:\Program Files\Mozilla Firefox\plugins\nppdf32.dll
    [2007/12/25 22:56:48 | 00,131,072 | ---- | M] (Apple Inc.) -- C:\Program Files\Mozilla Firefox\plugins\npqtplugin.dll
    [2007/12/25 22:56:48 | 00,131,072 | ---- | M] (Apple Inc.) -- C:\Program Files\Mozilla Firefox\plugins\npqtplugin2.dll
    [2007/12/25 22:56:48 | 00,131,072 | ---- | M] (Apple Inc.) -- C:\Program Files\Mozilla Firefox\plugins\npqtplugin3.dll
    [2007/12/25 22:56:48 | 00,131,072 | ---- | M] (Apple Inc.) -- C:\Program Files\Mozilla Firefox\plugins\npqtplugin4.dll
    [2007/12/25 22:56:48 | 00,131,072 | ---- | M] (Apple Inc.) -- C:\Program Files\Mozilla Firefox\plugins\npqtplugin5.dll
    [2007/12/25 22:56:48 | 00,131,072 | ---- | M] (Apple Inc.) -- C:\Program Files\Mozilla Firefox\plugins\npqtplugin6.dll
    [2007/12/25 22:56:48 | 00,131,072 | ---- | M] (Apple Inc.) -- C:\Program Files\Mozilla Firefox\plugins\npqtplugin7.dll
    [2010/01/12 12:47:30 | 00,002,221 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\SafeSearch.xml

    O1 HOSTS File: ([2010/01/20 21:35:53 | 00,000,027 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
    O1 - Hosts: 127.0.0.1 localhost
    O2 - BHO: (Search Helper) - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SearchHelper.dll (Microsoft Corp.)
    O2 - BHO: (Windows Live Toolbar Helper) - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files\Windows Live\Toolbar\wltcore.dll (Microsoft Corporation)
    O3 - HKLM\..\Toolbar: (&Windows Live Toolbar) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll (Microsoft Corporation)
    O3 - HKCU\..\Toolbar\ShellBrowser: (&Address) - {01E04581-4EEE-11D0-BFE9-00AA005B4383} - C:\WINDOWS\system32\browseui.dll (Microsoft Corporation)
    O3 - HKCU\..\Toolbar\WebBrowser: (&Address) - {01E04581-4EEE-11D0-BFE9-00AA005B4383} - C:\WINDOWS\system32\browseui.dll (Microsoft Corporation)
    O3 - HKCU\..\Toolbar\WebBrowser: (&Links) - {0E5CBF21-D15F-11D0-8301-00AA005B4383} - C:\WINDOWS\system32\shell32.dll (Microsoft Corporation)
    O3 - HKCU\..\Toolbar\WebBrowser: (&Windows Live Toolbar) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll (Microsoft Corporation)
    O3 - HKCU\..\Toolbar\WebBrowser: (IObitCom Toolbar) - {31C7D459-9CC3-44F2-9DCA-FC11795309B4} - C:\Program Files\IObitCom\tbIObi.dll (Conduit Ltd.)
    O3 - HKCU\..\Toolbar\WebBrowser: (Yahoo! Toolbar) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.)
    O4 - HKCU..\Run: [Google Update] C:\Documents and Settings\Tasha Z\Local Settings\Application Data\Google\Update\GoogleUpdate.exe (Google Inc.)
    O4 - HKCU..\Run: [MSMSGS] C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
    O4 - HKCU..\Run: [msnmsgr] C:\Program Files\Windows Live\Messenger\msnmsgr.exe (Microsoft Corporation)
    O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Infodelivery present
    O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: LinkResolveIgnoreLinkInfo = 0
    O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoResolveSearch = 1
    O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
    O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
    O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
    O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0
    O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption =
    O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext =
    O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1
    O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1
    O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableRegistryTools = 0
    O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
    O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
    O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: LinkResolveIgnoreLinkInfo = 0
    O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
    O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
    O10 - NameSpace_Catalog5\Catalog_Entries\000000000001 [] - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
    O10 - NameSpace_Catalog5\Catalog_Entries\000000000002 [] - C:\WINDOWS\system32\winrnr.dll (Microsoft Corporation)
    O10 - NameSpace_Catalog5\Catalog_Entries\000000000003 [] - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
    O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
    O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
    O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
    O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - C:\WINDOWS\system32\rsvpsp.dll (Microsoft Corporation)
    O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - C:\WINDOWS\system32\rsvpsp.dll (Microsoft Corporation)
    O10 - Protocol_Catalog9\Catalog_Entries\000000000006 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
    O10 - Protocol_Catalog9\Catalog_Entries\000000000007 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
    O10 - Protocol_Catalog9\Catalog_Entries\000000000008 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
    O10 - Protocol_Catalog9\Catalog_Entries\000000000009 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
    O10 - Protocol_Catalog9\Catalog_Entries\000000000010 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
    O10 - Protocol_Catalog9\Catalog_Entries\000000000011 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
    O10 - Protocol_Catalog9\Catalog_Entries\000000000012 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
    O10 - Protocol_Catalog9\Catalog_Entries\000000000013 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
    O10 - Protocol_Catalog9\Catalog_Entries\000000000014 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
    O10 - Protocol_Catalog9\Catalog_Entries\000000000015 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
    O15 - HKLM\..Trusted Domains: 1 domain(s) and sub-domain(s) not assigned to a zone.
    O15 - HKCU\..Trusted Domains: ([]msn in My Computer)
    O15 - HKCU\..Trusted Domains: 8 domain(s) and sub-domain(s) not assigned to a zone.
    O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
    O18 - Protocol\Handler\about {3050F406-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\system32\mshtml.dll (Microsoft Corporation)
    O18 - Protocol\Handler\cdl {3dd53d40-7b8b-11D0-b013-00aa0059ce02} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
    O18 - Protocol\Handler\dvd {12D51199-0DB5-46FE-A120-47A3D7D937CC} - C:\WINDOWS\system32\msvidctl.dll (Microsoft Corporation)
    O18 - Protocol\Handler\file {79eac9e7-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
    O18 - Protocol\Handler\ftp {79eac9e3-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
    O18 - Protocol\Handler\gopher {79eac9e4-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
    O18 - Protocol\Handler\http {79eac9e2-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
    O18 - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
    O18 - Protocol\Handler\http\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
    O18 - Protocol\Handler\https {79eac9e5-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
    O18 - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
    O18 - Protocol\Handler\https\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
    O18 - Protocol\Handler\ipp - No CLSID value found
    O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
    O18 - Protocol\Handler\its {9D148291-B9C8-11D0-A4CC-0000F80149F6} - C:\WINDOWS\system32\itss.dll (Microsoft Corporation)
    O18 - Protocol\Handler\javascript {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\system32\mshtml.dll (Microsoft Corporation)
    O18 - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\Windows Live\Messenger\msgrapp.14.0.8089.0726.dll (Microsoft Corporation)
    O18 - Protocol\Handler\local {79eac9e7-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
    O18 - Protocol\Handler\mailto {3050f3DA-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\system32\mshtml.dll (Microsoft Corporation)
    O18 - Protocol\Handler\mhtml {05300401-BCBC-11d0-85E3-00C04FD85AB4} - C:\WINDOWS\system32\inetcomm.dll (Microsoft Corporation)
    O18 - Protocol\Handler\mk {79eac9e6-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
    O18 - Protocol\Handler\msdaipp - No CLSID value found
    O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
    O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
    O18 - Protocol\Handler\ms-its {9D148291-B9C8-11D0-A4CC-0000F80149F6} - C:\WINDOWS\system32\itss.dll (Microsoft Corporation)
    O18 - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\Windows Live\Messenger\msgrapp.14.0.8089.0726.dll (Microsoft Corporation)
    O18 - Protocol\Handler\mso-offdap {3D9F03FA-7A94-11D3-BE81-0050048385D1} - C:\Program Files\Common Files\Microsoft Shared\Web Components\10\OWC10.DLL (Microsoft Corporation)
    O18 - Protocol\Handler\mso-offdap11 {32505114-5902-49B2-880A-1F7738E5A384} - C:\Program Files\Common Files\Microsoft Shared\Web Components\11\OWC11.DLL (Microsoft Corporation)
    O18 - Protocol\Handler\res {3050F3BC-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\system32\mshtml.dll (Microsoft Corporation)
    O18 - Protocol\Handler\sysimage {76E67A63-06E9-11D2-A840-006008059382} - C:\WINDOWS\system32\mshtml.dll (Microsoft Corporation)
    O18 - Protocol\Handler\tv {CBD30858-AF45-11D2-B6D6-00C04FBBDE6E} - C:\WINDOWS\system32\msvidctl.dll (Microsoft Corporation)
    O18 - Protocol\Handler\vbscript {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\system32\mshtml.dll (Microsoft Corporation)
    O18 - Protocol\Handler\vnd.ms.radio {3DA2AA3B-3D96-11D2-9BD2-204C4F4F5020} - C:\WINDOWS\system32\msdxm.ocx ()
    O18 - Protocol\Handler\wia {13F3EA8B-91D7-4F0A-AD76-D2853AC8BECE} - C:\WINDOWS\system32\wiascr.dll (Microsoft Corporation)
    O18 - Protocol\Handler\wlmailhtml {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - C:\Program Files\Windows Live\Mail\mailcomm.dll (Microsoft Corporation)
    O18 - Protocol\Filter\Class Install Handler {32B533BB-EDAE-11d0-BD5A-00AA00B92AF1} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
    O18 - Protocol\Filter\deflate {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
    O18 - Protocol\Filter\gzip {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
    O18 - Protocol\Filter\lzdhtml {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
    O18 - Protocol\Filter\text/webviewhtml {733AC4CB-F1A4-11d0-B951-00A0C90312E1} - C:\WINDOWS\system32\shell32.dll (Microsoft Corporation)
    O18 - Protocol\Filter\text/xml {807553E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\Microsoft Shared\OFFICE11\MSOXMLMF.DLL (Microsoft Corporation)
    O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
    O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) - C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
    O20 - HKLM Winlogon: UIHost - (logonui.exe) - C:\WINDOWS\System32\logonui.exe (Microsoft Corporation)
    O20 - HKLM Winlogon: VMApplet - (rundll32 shell32) - C:\WINDOWS\System32\shell32.dll (Microsoft Corporation)
    O20 - HKLM Winlogon: VMApplet - (Control_RunDLL "sysdm.cpl") - C:\WINDOWS\System32\sysdm.cpl (Microsoft Corporation)
    O20 - Winlogon\Notify\crypt32chain: DllName - crypt32.dll - C:\WINDOWS\System32\crypt32.dll (Microsoft Corporation)
    O20 - Winlogon\Notify\cryptnet: DllName - cryptnet.dll - C:\WINDOWS\System32\cryptnet.dll (Microsoft Corporation)
    O20 - Winlogon\Notify\cscdll: DllName - cscdll.dll - C:\WINDOWS\System32\cscdll.dll (Microsoft Corporation)
    O20 - Winlogon\Notify\igfxcui: DllName - igfxdev.dll - C:\WINDOWS\System32\igfxdev.dll (Intel Corporation)
    O20 - Winlogon\Notify\NavLogon: DllName - C:\WINDOWS\system32\NavLogon.dll - C:\WINDOWS\system32\NavLogon.dll ()
    O20 - Winlogon\Notify\ScCertProp: DllName - wlnotify.dll - C:\WINDOWS\System32\wlnotify.dll (Microsoft Corporation)
    O20 - Winlogon\Notify\Schedule: DllName - wlnotify.dll - C:\WINDOWS\System32\wlnotify.dll (Microsoft Corporation)
    O20 - Winlogon\Notify\sclgntfy: DllName - sclgntfy.dll - C:\WINDOWS\System32\sclgntfy.dll (Microsoft Corporation)
    O20 - Winlogon\Notify\SensLogn: DllName - WlNotify.dll - C:\WINDOWS\System32\wlnotify.dll (Microsoft Corporation)
    O20 - Winlogon\Notify\termsrv: DllName - wlnotify.dll - C:\WINDOWS\System32\wlnotify.dll (Microsoft Corporation)
    O20 - Winlogon\Notify\wlballoon: DllName - wlnotify.dll - C:\WINDOWS\System32\wlnotify.dll (Microsoft Corporation)
    O21 - SSODL: CDBurn - {fbeb8a05-beee-4442-804e-409d6c4515e9} - C:\WINDOWS\system32\shell32.dll (Microsoft Corporation)
    O21 - SSODL: PostBootReminder - {7849596a-48ea-486e-8937-a2a3009f31a9} - C:\WINDOWS\system32\shell32.dll (Microsoft Corporation)
    O21 - SSODL: SysTray - {35CEC8A3-2BE6-11D2-8773-92E220524153} - C:\WINDOWS\system32\stobject.dll (Microsoft Corporation)
    O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - C:\WINDOWS\system32\webcheck.dll (Microsoft Corporation)
    O22 - SharedTaskScheduler: {438755C2-A8BA-11D1-B96B-00A0C90312E1} - Browseui preloader - C:\WINDOWS\system32\browseui.dll (Microsoft Corporation)
    O22 - SharedTaskScheduler: {8C7461EF-2B13-11d2-BE35-3078302C2030} - Component Categories cache daemon - C:\WINDOWS\system32\browseui.dll (Microsoft Corporation)
    O24 - Desktop Components:0 (My Current Home Page) - About:Home
    O24 - Desktop Components:1 () - http://www.orange.co.uk/
    O24 - Desktop WallPaper: C:\Documents and Settings\Tasha Z\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
    O24 - Desktop BackupWallPaper: C:\Documents and Settings\Tasha Z\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
    O28 - HKLM ShellExecuteHooks: {AEB6717E-7E19-11d0-97EE-00C04FD91972} - C:\WINDOWS\System32\shell32.dll (Microsoft Corporation)
    O29 - HKLM SecurityProviders - (msapsspc.dll) - C:\WINDOWS\System32\msapsspc.dll (Microsoft Corporation)
    O29 - HKLM SecurityProviders - (schannel.dll) - C:\WINDOWS\System32\schannel.dll (Microsoft Corporation)
    O29 - HKLM SecurityProviders - (digest.dll) - C:\WINDOWS\System32\digest.dll (Microsoft Corporation)
    O29 - HKLM SecurityProviders - (msnsspc.dll) - C:\WINDOWS\System32\msnsspc.dll (Microsoft Corporation)
    O30 - LSA: Authentication Packages - (msv1_0) - C:\WINDOWS\System32\msv1_0.dll (Microsoft Corporation)
    O30 - LSA: Security Packages - (kerberos) - C:\WINDOWS\System32\kerberos.dll (Microsoft Corporation)
    O30 - LSA: Security Packages - (msv1_0) - C:\WINDOWS\System32\msv1_0.dll (Microsoft Corporation)
    O30 - LSA: Security Packages - (schannel) - C:\WINDOWS\System32\schannel.dll (Microsoft Corporation)
    O30 - LSA: Security Packages - (wdigest) - C:\WINDOWS\System32\wdigest.dll (Microsoft Corporation)
    O31 - SafeBoot: AlternateShell - cmd.exe
    O32 - HKLM CDRom: AutoRun - 1
    O32 - AutoRun File - [2006/12/18 22:35:04 | 00,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
    O34 - HKLM BootExecute: (autocheck autochk *) - File not found
    O35 - comfile [open] -- "%1" %*
    O35 - exefile [open] -- "%1" %*

    ========== Files/Folders - Created Within 30 Days ==========

    [2010/01/21 19:11:14 | 00,000,000 | -HSD | C] -- C:\RECYCLER
    [2010/01/21 19:10:36 | 00,000,000 | ---D | C] -- C:\_OTL
    [2010/01/21 10:21:08 | 00,016,736 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\mucltui.dll.mui
    [2010/01/21 10:21:07 | 00,274,288 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\mucltui.dll
    [2010/01/20 22:06:08 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Tasha Z\Application Data\Malwarebytes
    [2010/01/20 22:06:04 | 00,038,224 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbamswissarmy.sys
    [2010/01/20 22:06:02 | 00,019,160 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbam.sys
    [2010/01/20 22:06:02 | 00,000,000 | ---D | C] -- C:\Program Files\Malwarebytes' Anti-Malware
    [2010/01/20 22:06:02 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Malwarebytes
    [2010/01/20 21:39:46 | 00,000,000 | ---D | C] -- C:\WINDOWS\temp
    [2010/01/20 20:32:12 | 00,000,000 | RHSD | C] -- C:\cmdcons
    [2010/01/20 20:29:50 | 00,212,480 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWXCACLS.exe
    [2010/01/20 20:29:50 | 00,161,792 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWREG.exe
    [2010/01/20 20:29:50 | 00,136,704 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWSC.exe
    [2010/01/20 20:29:50 | 00,031,232 | ---- | C] (NirSoft) -- C:\WINDOWS\NIRCMD.exe
    [2010/01/20 20:29:41 | 00,000,000 | ---D | C] -- C:\WINDOWS\ERDNT
    [2010/01/20 20:29:27 | 00,000,000 | ---D | C] -- C:\Qoobox
    [2010/01/20 12:26:19 | 00,547,328 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\Tasha Z\Desktop\OTL.exe
    [2010/01/17 10:24:24 | 00,054,752 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\fssfltr_tdi.sys
    [2010/01/16 23:33:09 | 00,000,000 | ---D | C] -- C:\Program Files\Microsoft Sync Framework
    [2010/01/16 23:07:23 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Tasha Z\My Documents\Downloads
    [2010/01/16 23:01:38 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Tasha Z\Local Settings\Application Data\Temp
    [2010/01/16 22:27:00 | 00,000,000 | R--D | C] -- C:\Documents and Settings\Tasha Z\My Documents\Copy of My Music
    [2010/01/16 22:25:44 | 00,000,000 | ---D | C] -- C:\Program Files\msn gaming zone
    [2010/01/16 18:25:58 | 00,000,000 | ---D | C] -- C:\Program Files\IObitCom
    [2010/01/16 18:25:58 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Tasha Z\Local Settings\Application Data\IObitCom
    [2010/01/16 18:25:58 | 00,000,000 | ---D | C] -- C:\Program Files\Conduit
    [2010/01/16 18:25:58 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Tasha Z\Local Settings\Application Data\Conduit
    [2010/01/16 18:25:50 | 00,000,000 | ---D | C] -- C:\Program Files\IObit
    [2010/01/16 18:25:50 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Tasha Z\Application Data\IObit
    [2010/01/16 18:24:32 | 09,537,816 | ---- | C] (IObit ) -- C:\Documents and Settings\Tasha Z\My Documents\asc-setup.exe
    [2010/01/16 16:45:05 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\Logfiles
    [2010/01/16 16:45:05 | 00,000,000 | ---D | C] -- C:\Inetpub
    [2010/01/15 18:47:01 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Tasha Z\Local Settings\Application Data\Identities
    [2010/01/14 21:53:48 | 00,000,000 | ---D | M] -- C:\Documents and Settings\LocalService\Application Data\Adobe
    [2010/01/14 21:22:20 | 00,055,656 | ---- | C] (Avira GmbH) -- C:\WINDOWS\System32\drivers\avgntflt.sys
    [2010/01/14 12:05:59 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Tasha Z\Local Settings\Application Data\ICS
    [2010/01/13 22:57:09 | 00,000,000 | -H-D | C] -- C:\WINDOWS\System32\GroupPolicy
    [2010/01/13 22:01:24 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\drivers\N360
    [2010/01/13 22:01:21 | 00,000,000 | ---D | C] -- C:\Program Files\Windows Sidebar
    [2010/01/13 20:28:35 | 00,000,000 | ---D | C] -- C:\Program Files\Microsoft
    [2010/01/13 20:28:33 | 00,000,000 | ---D | C] -- C:\Program Files\Windows Live SkyDrive
    [2010/01/13 20:27:36 | 00,000,000 | ---D | C] -- C:\Config.Msi
    [2010/01/13 19:17:37 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Tasha Z\Tracing
    [2010/01/13 19:15:58 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Documents\microsoft
    [2010/01/13 19:15:12 | 00,000,000 | ---D | C] -- C:\Program Files\Windows Live
    [2010/01/13 15:23:54 | 00,000,000 | ---D | C] -- C:\Program Files\Common Files\Windows Live
    [2010/01/13 10:21:39 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Tasha Z\Desktop\mike
    [2010/01/12 13:40:18 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Tasha Z\Desktop\sue doc
    [2010/01/12 11:23:50 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Tasha Z\Local Settings\Application Data\Symantec
    [2010/01/12 10:38:26 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Norton
    [2010/01/12 10:35:39 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\NortonInstaller
    [2010/01/12 10:22:24 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\appmgmt
    [2007/07/27 13:55:54 | 00,000,000 | ---D | M] -- C:\Documents and Settings\LocalService\Application Data\Help
    [2007/07/27 13:55:29 | 00,000,000 | ---D | M] -- C:\Documents and Settings\LocalService\Local Settings\Application Data\Help
    [2007/05/30 11:08:08 | 00,000,000 | ---D | M] -- C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft
    [2007/05/30 11:08:08 | 00,000,000 | ---D | M] -- C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft
    [2006/12/18 22:34:43 | 00,000,000 | --SD | M] -- C:\Documents and Settings\NetworkService\Application Data\Microsoft
    [2006/12/18 22:34:43 | 00,000,000 | --SD | M] -- C:\Documents and Settings\LocalService\Application Data\Microsoft

    ========== Files - Modified Within 30 Days ==========

    [2010/01/21 19:12:00 | 00,000,006 | -H-- | M] () -- C:\WINDOWS\tasks\SA.DAT
    [2010/01/21 19:11:59 | 00,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
    [2010/01/21 19:11:25 | 03,932,160 | -H-- | M] () -- C:\Documents and Settings\Tasha Z\NTUSER.DAT
    [2010/01/21 19:11:20 | 00,000,278 | -HS- | M] () -- C:\Documents and Settings\Tasha Z\ntuser.ini
    [2010/01/21 19:06:02 | 00,000,986 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-436374069-1500820517-725345543-1003UA.job
    [2010/01/21 10:40:37 | 04,284,286 | -H-- | M] () -- C:\Documents and Settings\Tasha Z\Local Settings\Application Data\IconCache.db
    [2010/01/20 22:06:06 | 00,000,696 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
    [2010/01/20 21:36:07 | 00,000,000 | ---- | M] () -- C:\WINDOWS\system.ini
    [2010/01/20 21:35:53 | 00,000,027 | ---- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts
    [2010/01/20 20:32:18 | 00,000,281 | RHS- | M] () -- C:\boot.ini
    [2010/01/20 20:27:41 | 03,830,599 | R--- | M] () -- C:\Documents and Settings\Tasha Z\Desktop\schrauber.exe
    [2010/01/20 16:35:46 | 00,293,376 | ---- | M] () -- C:\Documents and Settings\Tasha Z\Desktop\u0n696ig.exe
    [2010/01/20 12:26:26 | 00,547,328 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Tasha Z\Desktop\OTL.exe
    [2010/01/19 21:40:32 | 00,002,444 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
    [2010/01/19 21:27:08 | 00,005,372 | ---- | M] () -- C:\WINDOWS\imsins.BAK
    [2010/01/17 10:35:07 | 00,315,408 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat
    [2010/01/17 10:35:07 | 00,041,586 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat
    [2010/01/17 10:35:06 | 00,360,124 | ---- | M] () -- C:\WINDOWS\System32\PerfStringBackup.INI
    [2010/01/16 23:06:00 | 00,000,934 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-436374069-1500820517-725345543-1003Core.job
    [2010/01/16 22:17:15 | 00,005,569 | ---- | M] () -- C:\Documents and Settings\Tasha Z\My Documents\My Favorite Theme.theme
    [2010/01/16 18:56:28 | 00,502,752 | ---- | M] () -- C:\Documents and Settings\Tasha Z\My Documents\cfremover.exe
    [2010/01/16 18:25:56 | 00,000,874 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Advanced SystemCare.lnk
    [2010/01/16 18:25:19 | 09,537,816 | ---- | M] (IObit ) -- C:\Documents and Settings\Tasha Z\My Documents\asc-setup.exe
    [2010/01/15 18:31:51 | 52,659,8144 | ---- | M] () -- C:\WINDOWS\MEMORY.DMP
    [2010/01/14 23:20:16 | 00,000,162 | -H-- | M] () -- C:\Documents and Settings\Tasha Z\My Documents\~$ssage to Natasha Skye Zeraschi.doc
    [2010/01/14 21:57:52 | 00,000,779 | ---- | M] () -- C:\Documents and Settings\Tasha Z\Desktop\Launch Internet Explorer Browser.lnk
    [2010/01/14 18:31:15 | 61,551,4112 | -HS- | M] () -- C:\NRTPage.sys
    [2010/01/14 18:03:27 | 00,000,211 | ---- | M] () -- C:\Boot.bak
    [2010/01/14 18:03:27 | 00,000,000 | ---- | M] () -- C:\WINDOWS\win.ini
    [2010/01/13 20:13:16 | 00,001,743 | ---- | M] () -- C:\Documents and Settings\All Users\Application Data\QTSBandwidthCache
    [2010/01/13 19:42:48 | 00,195,368 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT
    [2010/01/13 19:17:14 | 00,043,832 | ---- | M] () -- C:\Documents and Settings\Tasha Z\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
    [2010/01/13 10:24:35 | 25,753,6806 | ---- | M] () -- C:\Documents and Settings\Tasha Z\Desktop\photos 1.zip
    [2010/01/12 12:48:44 | 00,002,473 | ---- | M] () -- C:\Documents and Settings\All Users\Documents\Global.sw2
    [2010/01/12 10:21:17 | 00,000,453 | ---- | M] () -- C:\WINDOWS\ODBC.INI
    [2010/01/07 16:07:14 | 00,038,224 | ---- | M] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbamswissarmy.sys
    [2010/01/07 16:07:04 | 00,019,160 | ---- | M] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbam.sys

    ========== Files Created - No Company Name ==========

    [2010/01/20 22:06:06 | 00,000,696 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
    [2010/01/20 20:32:18 | 00,000,211 | ---- | C] () -- C:\Boot.bak
    [2010/01/20 20:32:14 | 00,260,272 | ---- | C] () -- C:\cmldr
    [2010/01/20 20:29:50 | 00,261,632 | ---- | C] () -- C:\WINDOWS\PEV.exe
    [2010/01/20 20:29:50 | 00,098,816 | ---- | C] () -- C:\WINDOWS\sed.exe
    [2010/01/20 20:29:50 | 00,080,412 | ---- | C] () -- C:\WINDOWS\grep.exe
    [2010/01/20 20:29:50 | 00,077,312 | ---- | C] () -- C:\WINDOWS\MBR.exe
    [2010/01/20 20:29:50 | 00,068,096 | ---- | C] () -- C:\WINDOWS\zip.exe
    [2010/01/20 20:27:41 | 03,830,599 | R--- | C] () -- C:\Documents and Settings\Tasha Z\Desktop\schrauber.exe
    [2010/01/20 16:35:45 | 00,293,376 | ---- | C] () -- C:\Documents and Settings\Tasha Z\Desktop\u0n696ig.exe
    [2010/01/16 23:01:25 | 00,000,986 | ---- | C] () -- C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-436374069-1500820517-725345543-1003UA.job
    [2010/01/16 23:01:24 | 00,000,934 | ---- | C] () -- C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-436374069-1500820517-725345543-1003Core.job
    [2010/01/16 18:56:04 | 00,502,752 | ---- | C] () -- C:\Documents and Settings\Tasha Z\My Documents\cfremover.exe
    [2010/01/16 18:25:56 | 00,000,874 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Advanced SystemCare.lnk
    [2010/01/14 23:20:16 | 00,000,162 | -H-- | C] () -- C:\Documents and Settings\Tasha Z\My Documents\~$ssage to Natasha Skye Zeraschi.doc
    [2010/01/14 18:31:15 | 61,551,4112 | -HS- | C] () -- C:\NRTPage.sys
    [2010/01/13 20:13:16 | 00,001,743 | ---- | C] () -- C:\Documents and Settings\All Users\Application Data\QTSBandwidthCache
    [2010/01/13 10:23:37 | 25,753,6806 | ---- | C] () -- C:\Documents and Settings\Tasha Z\Desktop\photos 1.zip
    [2010/01/12 12:21:18 | 00,005,569 | ---- | C] () -- C:\Documents and Settings\Tasha Z\My Documents\My Favorite Theme.theme
    [2009/03/21 20:06:40 | 00,002,880 | ---- | C] () -- C:\Documents and Settings\Tasha Z\Application Data\NMM-MetaData.db
    [2007/12/25 23:22:03 | 00,009,216 | ---- | C] () -- C:\Documents and Settings\Tasha Z\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
    [2007/09/18 10:52:59 | 00,326,589 | ---- | C] () -- C:\Documents and Settings\Tasha Z\Application Data\update.log
    [2007/03/29 23:00:40 | 00,203,264 | R--- | C] () -- C:\WINDOWS\System32\CddbCdda.dll
    [2006/12/19 20:28:00 | 00,000,453 | ---- | C] () -- C:\WINDOWS\ODBC.INI
    [2006/12/19 20:14:37 | 00,069,632 | R--- | C] () -- C:\WINDOWS\sm56spn.dll
    [2006/12/19 20:14:37 | 00,069,632 | R--- | C] () -- C:\WINDOWS\sm56itl.dll
    [2006/12/19 20:14:37 | 00,069,632 | R--- | C] () -- C:\WINDOWS\sm56eng.dll
    [2006/12/19 20:14:37 | 00,069,632 | R--- | C] () -- C:\WINDOWS\sm56brz.dll
    [2006/12/19 20:14:37 | 00,061,440 | R--- | C] () -- C:\WINDOWS\sm56ger.dll
    [2006/12/19 20:14:37 | 00,061,440 | R--- | C] () -- C:\WINDOWS\sm56fra.dll
    [2006/12/19 20:14:37 | 00,053,248 | R--- | C] () -- C:\WINDOWS\sm56jpn.dll
    [2006/12/19 20:14:37 | 00,049,152 | R--- | C] () -- C:\WINDOWS\sm56cht.dll
    [2006/12/19 20:14:37 | 00,049,152 | R--- | C] () -- C:\WINDOWS\sm56chs.dll
    [2005/01/21 04:02:28 | 00,013,312 | ---- | C] () -- C:\WINDOWS\System32\RMDevice.dll
    [2004/08/04 10:00:00 | 00,081,920 | ---- | C] () -- C:\WINDOWS\System32\ieencode.dll
    [2003/01/07 15:05:08 | 00,002,695 | ---- | C] () -- C:\WINDOWS\System32\OUTLPERF.INI
    [2001/09/24 06:59:00 | 00,045,056 | ---- | C] () -- C:\WINDOWS\System32\NavLogon.dll

    < End of report >
    otl.txt report from wendy
     
  18. wendy

    wendy Registered Members

    Joined:
    Jan 18, 2010
    Messages:
    49
    Location:
    wales uk
    Operating System:
    Windows XP Home
    OL OK C:\Program Files\Windows Live\Messenger\riched20.dll Win32/Toolbar.MyWebSearch application cleaned by deleting - quarantined
    C:\Qoobox\Quarantine\C\Program Files\captcha.dll.vir Win32/Agent.PEZ trojan cleaned by deleting - quarantined
    C:\Qoobox\Quarantine\C\Program Files\Mozilla Firefox\ftemp.exe.vir Win32/Koobface.NCJ worm cleaned by deleting - quarantined
    C:\Qoobox\Quarantine\C\WINDOWS\pp12.exe.vir Win32/Koobface.NBH worm cleaned by deleting - quarantined
    C:\Qoobox\Quarantine\C\WINDOWS\rdr_1258395588.exe.vir Win32/Tinxy.AJ trojan cleaned by deleting - quarantined
    C:\Qoobox\Quarantine\C\WINDOWS\rdr_1258487055.exe.vir Win32/Tinxy.AJ trojan cleaned by deleting - quarantined
    C:\Qoobox\Quarantine\C\WINDOWS\rdr_1258489593.exe.vir Win32/Tinxy.AJ trojan cleaned by deleting - quarantined
    C:\Qoobox\Quarantine\C\WINDOWS\rdr_1258567779.exe.vir Win32/Tinxy.AJ trojan cleaned by deleting - quarantined
    C:\Qoobox\Quarantine\C\WINDOWS\rdr_1258741568.exe.vir Win32/Tinxy.AJ trojan cleaned by deleting - quarantined
    C:\Qoobox\Quarantine\C\WINDOWS\rdr_1258746876.exe.vir Win32/Tinxy.AJ trojan cleaned by deleting - quarantined
    C:\Qoobox\Quarantine\C\WINDOWS\rdr_1258823495.exe.vir Win32/Tinxy.AJ trojan cleaned by deleting - quarantined
    C:\Qoobox\Quarantine\C\WINDOWS\rdr_1258908807.exe.vir Win32/Tinxy.AJ trojan cleaned by deleting - quarantined
    C:\Qoobox\Quarantine\C\WINDOWS\rdr_1258910083.exe.vir Win32/Tinxy.AJ trojan cleaned by deleting - quarantined
    C:\Qoobox\Quarantine\C\WINDOWS\rdr_1258914792.exe.vir Win32/Tinxy.AJ trojan cleaned by deleting - quarantined
    C:\Qoobox\Quarantine\C\WINDOWS\rdr_1258918936.exe.vir Win32/Tinxy.AJ trojan cleaned by deleting - quarantined
    C:\Qoobox\Quarantine\C\WINDOWS\rdr_1259263995.exe.vir Win32/Tinxy.AJ trojan cleaned by deleting - quarantined
    C:\Qoobox\Quarantine\C\WINDOWS\rdr_1259396644.exe.vir Win32/Tinxy.AJ trojan cleaned by deleting - quarantined
    C:\Qoobox\Quarantine\C\WINDOWS\rdr_1259397966.exe.vir Win32/Tinxy.AJ trojan cleaned by deleting - quarantined
    C:\Qoobox\Quarantine\C\WINDOWS\rdr_1259400010.exe.vir Win32/Tinxy.AJ trojan cleaned by deleting - quarantined
    C:\Qoobox\Quarantine\C\WINDOWS\rdr_1259412729.exe.vir Win32/Tinxy.AJ trojan cleaned by deleting - quarantined
    C:\Qoobox\Quarantine\C\WINDOWS\rdr_1259483273.exe.vir Win32/Tinxy.AJ trojan cleaned by deleting - quarantined
    C:\Qoobox\Quarantine\C\WINDOWS\rdr_1259492315.exe.vir Win32/Tinxy.AJ trojan cleaned by deleting - quarantined
    C:\Qoobox\Quarantine\C\WINDOWS\rdr_1259522099.exe.vir Win32/Tinxy.AJ trojan cleaned by deleting - quarantined
    C:\Qoobox\Quarantine\C\WINDOWS\rdr_1259523431.exe.vir Win32/Tinxy.AJ trojan cleaned by deleting - quarantined
    C:\Qoobox\Quarantine\C\WINDOWS\rdr_1259699909.exe.vir Win32/Tinxy.AJ trojan cleaned by deleting - quarantined
    C:\Qoobox\Quarantine\C\WINDOWS\rdr_1263291159.exe.vir Win32/Tinxy.AJ trojan cleaned by deleting - quarantined
    C:\Qoobox\Quarantine\C\WINDOWS\rdr_1263292567.exe.vir Win32/Tinxy.AJ trojan cleaned by deleting - quarantined
    C:\Qoobox\Quarantine\C\WINDOWS\rdr_1263295382.exe.vir Win32/Tinxy.AJ trojan cleaned by deleting - quarantined
    C:\Qoobox\Quarantine\C\WINDOWS\rdr_1263296326.exe.vir Win32/Tinxy.AJ trojan cleaned by deleting - quarantined
    C:\Qoobox\Quarantine\C\WINDOWS\rdr_1263298621.exe.vir Win32/Tinxy.AJ trojan cleaned by deleting - quarantined
    C:\Qoobox\Quarantine\C\WINDOWS\tag14.exe.vir a variant of Win32/Kryptik.ATS trojan cleaned by deleting - quarantined
    C:\Qoobox\Quarantine\C\WINDOWS\zwer_1258200833.exe.vir Win32/Tinxy.AJ trojan cleaned by deleting - quarantined
    C:\Qoobox\Quarantine\C\WINDOWS\zwer_1258200836.exe.vir Win32/Koobface.NBH worm cleaned by deleting - quarantined
    C:\Qoobox\Quarantine\C\WINDOWS\zwer_1258272729.exe.vir Win32/Tinxy.AJ trojan cleaned by deleting - quarantined
    C:\Qoobox\Quarantine\C\WINDOWS\zwer_1258301370.exe.vir Win32/Tinxy.AJ trojan cleaned by deleting - quarantined
    C:\Qoobox\Quarantine\C\WINDOWS\zwer_1258305350.exe.vir Win32/Tinxy.AJ trojan cleaned by deleting - quarantined
    C:\Qoobox\Quarantine\C\WINDOWS\system32\BcfgfMoq.ini.vir Win32/Adware.Virtumonde.NEO application cleaned by deleting - quarantined
    C:\Qoobox\Quarantine\C\WINDOWS\system32\BcfgfMoq.ini2.vir Win32/Adware.Virtumonde.NEO application cleaned by deleting - quarantined
    C:\Qoobox\Quarantine\C\WINDOWS\system32\dlh9jkd1q1.exe.vir Win32/TrojanDownloader.Small.AWA trojan cleaned by deleting - quarantined
    C:\Qoobox\Quarantine\C\WINDOWS\system32\sqvx5gamet2.exe.vir Win32/TrojanDownloader.Small.AWA trojan cleaned by deleting - quarantined
    C:\Qoobox\Quarantine\C\WINDOWS\system32\sqvxga6met3.exe.vir Win32/TrojanDownloader.Small.AWA trojan cleaned by deleting - quarantined
    C:\Qoobox\Quarantine\C\WINDOWS\system32\sqvxga7met4.exe.vir Win32/TrojanDownloader.Small.AWA trojan cleaned by deleting - quarantined
    C:\Qoobox\Quarantine\C\WINDOWS\system32\__c007B6B4.dat.vir a variant of Win32/Kryptik.BHV trojan cleaned by deleting - quarantined
    C:\Qoobox\Quarantine\C\WINDOWS\system32\drivers\fio32.sys.vir Win32/Tinxy.AP trojan cleaned by deleting - quarantined
    C:\WINDOWS\system32\ru.exe probably a variant of Win32/TrojanProxy.Agent trojan cleaned by deleting - quarantined
     
  19. wendy

    wendy Registered Members

    Joined:
    Jan 18, 2010
    Messages:
    49
    Location:
    wales uk
    Operating System:
    Windows XP Home
    All done what now :rolleyes:
     
  20. schrauber

    schrauber Guest

    Hi,

    Your Microsoft Windows installation is out of date. Using unpatched Windows systems on the Internet are a security risk to everyone. When there are insecure computers connected to the Internet, malware spreads faster and more extensively, distributed denial-of-service attacks are easier to launch, and spammers have more platforms from which to send e-mail. Whenever a security problem in its software is found, Microsoft will usually create a patch for it. After the patch is installed, attackers can't use the vulnerability to install malicious software on your computer. Keeping up-to-date with all these security patches will help prevent malware from reinfecting your machine. If you are not sure how to do this, see How to use Microsoft Update.

    Then go here to check for & install updates to Microsoft applications.
    Note: The update process uses ActiveX, so you will need to use Internet Explorer for it, and allow the ActiveX control that it wants to install.

    Please reboot and repeat the update process until there are no more updates to install.


    After that, please run OTL one more time. Doubleclick OTL and set "Extra Registry" to "Use Safe List", then hit the Run Scan button and post back with the 2 logfiles.
     

Share This Page