1. Welcome Guest! In order to create a new topic or reply to an existing one, you must register first. It is easy and free. Click here to sign up now!.
    Dismiss Notice

Malware And Trogen Problems

Discussion in 'Malware Removal Help' started by wendy, Jan 18, 2010.

  1. wendy

    wendy Registered Members

    Joined:
    Jan 18, 2010
    Messages:
    49
    Location:
    wales uk
    Operating System:
    Windows XP Home
    ok onto it now thanks
     
  2. schrauber

    schrauber Guest

    You're welcome :)
     
  3. wendy

    wendy Registered Members

    Joined:
    Jan 18, 2010
    Messages:
    49
    Location:
    wales uk
    Operating System:
    Windows XP Home
    NGNNNNNNOTGOING WELL
     
  4. wendy

    wendy Registered Members

    Joined:
    Jan 18, 2010
    Messages:
    49
    Location:
    wales uk
    Operating System:
    Windows XP Home
    hiya on home pc infected pc is giving me major problems when accessing this site unless this site having problems at present did say system unavailable. Infected computer is on a go slow wont down load window update says error page unavailable it is running very very slow tried to put the firewall but wont let me whats next to hit the badies wendy <_<
     
  5. schrauber

    schrauber Guest

    Hi,

    Please post back with a fresh OTL logfile.
     
  6. BeeCeeBee

    BeeCeeBee ADMINISTRATOR IN MEMORY

    Joined:
    Apr 20, 2009
    Messages:
    7,201
    Location:
    New Jersey "Stronger than the Storm"
    Operating System:
    Windows 7
    I am a bit confused here. You reference your "home Computer," is this a different machine than the one you have been working on. If it is it should be in its own thread. Please just let us know and we will correct it.
     
  7. wendy

    wendy Registered Members

    Joined:
    Jan 18, 2010
    Messages:
    49
    Location:
    wales uk
    Operating System:
    Windows XP Home
    no onlydown loaded a program from my home compter
     
  8. wendy

    wendy Registered Members

    Joined:
    Jan 18, 2010
    Messages:
    49
    Location:
    wales uk
    Operating System:
    Windows XP Home
    sosorry for the bluntness but the infected computer not showing me my text on the reply boxes
     
  9. schrauber

    schrauber Guest

    Can you post a fresh OTL logfile from the infected computer?
     
  10. wendy

    wendy Registered Members

    Joined:
    Jan 18, 2010
    Messages:
    49
    Location:
    wales uk
    Operating System:
    Windows XP Home
    OTL logfile created on: 22/01/2010 18:44:11 - Run 5
    OTL by OldTimer - Version 3.1.25.2 Folder = C:\Documents and Settings\Tasha Z\Desktop
    Windows XP Professional Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
    Internet Explorer (Version = 6.0.2900.2180)
    Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy

    502.00 Mb Total Physical Memory | 251.00 Mb Available Physical Memory | 50.00% Memory free
    1.00 Gb Paging File | 1.00 Gb Available in Paging File | 82.00% Paging File free
    Paging file location(s): c:\pagefile.sys 756 1512 [binary data]

    %SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
    Drive C: | 93.15 Gb Total Space | 85.51 Gb Free Space | 91.79% Space Free | Partition Type: NTFS
    D: Drive not present or media not loaded
    E: Drive not present or media not loaded
    F: Drive not present or media not loaded
    G: Drive not present or media not loaded
    H: Drive not present or media not loaded
    I: Drive not present or media not loaded

    Computer Name: TASHA
    Current User Name: Tasha Z
    Logged in as Administrator.

    Current Boot Mode: Normal
    Scan Mode: Current user
    Company Name Whitelist: On
    Skip Microsoft Files: On
    File Age = 14 Days
    Output = Minimal
    Quick Scan

    ========== Processes (SafeList) ==========

    PRC - C:\Documents and Settings\Tasha Z\Desktop\OTL.exe (OldTimer Tools)
    PRC - C:\Program Files\Windows Live\Contacts\wlcomm.exe (Microsoft Corporation)
    PRC - C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe (Microsoft Corp.)
    PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
    PRC - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe (Intel Corporation)
    PRC - C:\WINDOWS\system32\wscntfy.exe (Microsoft Corporation)


    ========== Modules (SafeList) ==========

    MOD - C:\Documents and Settings\Tasha Z\Desktop\OTL.exe (OldTimer Tools)
    MOD - C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03\comctl32.dll (Microsoft Corporation)


    ========== Win32 Services (SafeList) ==========

    SRV - (fsssvc) -- C:\Program Files\Windows Live\Family Safety\fsssvc.exe (Microsoft Corporation)
    SRV - (SeaPort) -- C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe (Microsoft Corp.)
    SRV - (EvtEng) Intel(R) -- C:\Program Files\Intel\Wireless\Bin\EvtEng.exe (Intel Corporation)
    SRV - (IDriverT) -- C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe (Macrovision Corporation)
    SRV - (ose) -- C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE (Microsoft Corporation)


    ========== Standard Registry (SafeList) ==========


    ========== Internet Explorer ==========

    IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
    IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://home.sweetim.com
    IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie

    IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://computerhelpforums.net/topic/14391-malware-and-trogen-problems/page__gopid__52878&
    IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie
    IE - HKCU\..\URLSearchHook: {31c7d459-9cc3-44f2-9dca-fc11795309b4} - C:\Program Files\IObitCom\tbIObi.dll (Conduit Ltd.)
    IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

    ========== FireFox ==========

    FF - prefs.js..browser.search.defaultenginename: "Google"
    FF - prefs.js..browser.search.defaulturl: "http://www.google.com/search?lr=&ie=UTF-8&oe=UTF-8&q="
    FF - prefs.js..browser.search.selectedEngine: "Google"

    FF - HKLM\software\mozilla\Firefox\Extensions\\{3112ca9c-de6d-4884-a869-9855de68056c}: C:\Documents and Settings\All Users\Application Data\Mozilla\Firefox Extensions\{3112ca9c-de6d-4884-a869-9855de68056c} [2007/09/23 13:00:04 | 00,000,000 | ---D | M]

    [2007/11/07 21:38:29 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Tasha Z\Application Data\Mozilla\Firefox\Profiles\uykhn9v0.default\extensions

    O1 HOSTS File: ([2010/01/20 21:35:53 | 00,000,027 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
    O1 - Hosts: 127.0.0.1 localhost
    O2 - BHO: (Search Helper) - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SearchHelper.dll (Microsoft Corp.)
    O2 - BHO: (Windows Live Toolbar Helper) - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files\Windows Live\Toolbar\wltcore.dll (Microsoft Corporation)
    O3 - HKLM\..\Toolbar: (&Windows Live Toolbar) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll (Microsoft Corporation)
    O3 - HKCU\..\Toolbar\ShellBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No CLSID value found.
    O3 - HKCU\..\Toolbar\ShellBrowser: (no name) - {C75C8E7E-5059-4469-AC11-D7544B260382} - No CLSID value found.
    O3 - HKCU\..\Toolbar\WebBrowser: (&Windows Live Toolbar) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll (Microsoft Corporation)
    O3 - HKCU\..\Toolbar\WebBrowser: (IObitCom Toolbar) - {31C7D459-9CC3-44F2-9DCA-FC11795309B4} - C:\Program Files\IObitCom\tbIObi.dll (Conduit Ltd.)
    O3 - HKCU\..\Toolbar\WebBrowser: (Yahoo! Toolbar) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.)
    O4 - HKCU..\Run: [Google Update] C:\Documents and Settings\Tasha Z\Local Settings\Application Data\Google\Update\GoogleUpdate.exe (Google Inc.)
    O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Infodelivery present
    O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: LinkResolveIgnoreLinkInfo = 0
    O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoResolveSearch = 1
    O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
    O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
    O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
    O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
    O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
    O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: LinkResolveIgnoreLinkInfo = 0
    O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
    O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
    O15 - HKLM\..Trusted Domains: 1 domain(s) and sub-domain(s) not assigned to a zone.
    O15 - HKCU\..Trusted Domains: ([]msn in My Computer)
    O15 - HKCU\..Trusted Domains: 8 domain(s) and sub-domain(s) not assigned to a zone.
    O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} http://download.eset.com/special/eos/OnlineScanner.cab (OnlineScanner Control)
    O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
    O18 - Protocol\Handler\vnd.ms.radio {3DA2AA3B-3D96-11D2-9BD2-204C4F4F5020} - C:\WINDOWS\system32\msdxm.ocx ()
    O18 - Protocol\Handler\wlmailhtml {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - C:\Program Files\Windows Live\Mail\mailcomm.dll (Microsoft Corporation)
    O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
    O20 - Winlogon\Notify\igfxcui: DllName - igfxdev.dll - C:\WINDOWS\System32\igfxdev.dll (Intel Corporation)
    O20 - Winlogon\Notify\NavLogon: DllName - C:\WINDOWS\system32\NavLogon.dll - C:\WINDOWS\system32\NavLogon.dll ()
    O24 - Desktop Components:1 () - http://www.orange.co.uk/
    O24 - Desktop WallPaper: C:\Documents and Settings\Tasha Z\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
    O24 - Desktop BackupWallPaper: C:\Documents and Settings\Tasha Z\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
    O32 - HKLM CDRom: AutoRun - 1
    O32 - AutoRun File - [2006/12/18 22:35:04 | 00,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
    O34 - HKLM BootExecute: (autocheck autochk *) - File not found
    O35 - comfile [open] -- "%1" %*
    O35 - exefile [open] -- "%1" %*

    ========== Files/Folders - Created Within 14 Days ==========

    [2010/01/21 20:12:09 | 00,000,000 | ---D | C] -- C:\Program Files\ESET
    [2010/01/21 19:11:14 | 00,000,000 | -HSD | C] -- C:\RECYCLER
    [2010/01/21 19:10:36 | 00,000,000 | ---D | C] -- C:\_OTL
    [2010/01/20 22:06:08 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Tasha Z\Application Data\Malwarebytes
    [2010/01/20 22:06:04 | 00,038,224 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbamswissarmy.sys
    [2010/01/20 22:06:02 | 00,019,160 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbam.sys
    [2010/01/20 22:06:02 | 00,000,000 | ---D | C] -- C:\Program Files\Malwarebytes' Anti-Malware
    [2010/01/20 22:06:02 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Malwarebytes
    [2010/01/20 21:39:46 | 00,000,000 | ---D | C] -- C:\WINDOWS\temp
    [2010/01/20 20:32:12 | 00,000,000 | RHSD | C] -- C:\cmdcons
    [2010/01/20 20:29:50 | 00,212,480 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWXCACLS.exe
    [2010/01/20 20:29:50 | 00,161,792 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWREG.exe
    [2010/01/20 20:29:50 | 00,136,704 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWSC.exe
    [2010/01/20 20:29:50 | 00,031,232 | ---- | C] (NirSoft) -- C:\WINDOWS\NIRCMD.exe
    [2010/01/20 20:29:41 | 00,000,000 | ---D | C] -- C:\WINDOWS\ERDNT
    [2010/01/20 20:29:27 | 00,000,000 | ---D | C] -- C:\Qoobox
    [2010/01/20 12:26:19 | 00,547,328 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\Tasha Z\Desktop\OTL.exe
    [2010/01/16 23:33:09 | 00,000,000 | ---D | C] -- C:\Program Files\Microsoft Sync Framework
    [2010/01/16 23:07:23 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Tasha Z\My Documents\Downloads
    [2010/01/16 23:01:38 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Tasha Z\Local Settings\Application Data\Temp
    [2010/01/16 22:27:00 | 00,000,000 | R--D | C] -- C:\Documents and Settings\Tasha Z\My Documents\Copy of My Music
    [2010/01/16 22:25:44 | 00,000,000 | ---D | C] -- C:\Program Files\msn gaming zone
    [2010/01/16 18:25:58 | 00,000,000 | ---D | C] -- C:\Program Files\IObitCom
    [2010/01/16 18:25:58 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Tasha Z\Local Settings\Application Data\IObitCom
    [2010/01/16 18:25:58 | 00,000,000 | ---D | C] -- C:\Program Files\Conduit
    [2010/01/16 18:25:58 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Tasha Z\Local Settings\Application Data\Conduit
    [2010/01/16 18:25:50 | 00,000,000 | ---D | C] -- C:\Program Files\IObit
    [2010/01/16 18:25:50 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Tasha Z\Application Data\IObit
    [2010/01/16 18:24:32 | 09,537,816 | ---- | C] (IObit ) -- C:\Documents and Settings\Tasha Z\My Documents\asc-setup.exe
    [2010/01/16 16:45:05 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\Logfiles
    [2010/01/16 16:45:05 | 00,000,000 | ---D | C] -- C:\Inetpub
    [2010/01/15 18:47:01 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Tasha Z\Local Settings\Application Data\Identities
    [2010/01/14 21:53:48 | 00,000,000 | ---D | M] -- C:\Documents and Settings\LocalService\Application Data\Adobe
    [2010/01/14 21:22:20 | 00,055,656 | ---- | C] (Avira GmbH) -- C:\WINDOWS\System32\drivers\avgntflt.sys
    [2010/01/14 12:05:59 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Tasha Z\Local Settings\Application Data\ICS
    [2010/01/13 22:57:09 | 00,000,000 | -H-D | C] -- C:\WINDOWS\System32\GroupPolicy
    [2010/01/13 22:01:24 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\drivers\N360
    [2010/01/13 22:01:21 | 00,000,000 | ---D | C] -- C:\Program Files\Windows Sidebar
    [2010/01/13 20:28:35 | 00,000,000 | ---D | C] -- C:\Program Files\Microsoft
    [2010/01/13 20:28:33 | 00,000,000 | ---D | C] -- C:\Program Files\Windows Live SkyDrive
    [2010/01/13 20:27:36 | 00,000,000 | ---D | C] -- C:\Config.Msi
    [2010/01/13 19:17:37 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Tasha Z\Tracing
    [2010/01/13 19:15:58 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Documents\microsoft
    [2010/01/13 19:15:12 | 00,000,000 | ---D | C] -- C:\Program Files\Windows Live
    [2010/01/13 15:23:54 | 00,000,000 | ---D | C] -- C:\Program Files\Common Files\Windows Live
    [2010/01/13 10:21:39 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Tasha Z\Desktop\mike
    [2010/01/12 13:40:18 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Tasha Z\Desktop\sue doc
    [2010/01/12 11:23:50 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Tasha Z\Local Settings\Application Data\Symantec
    [2010/01/12 10:38:26 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Norton
    [2010/01/12 10:35:39 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\NortonInstaller
    [2010/01/12 10:22:24 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\appmgmt
    [2007/07/27 13:55:54 | 00,000,000 | ---D | M] -- C:\Documents and Settings\LocalService\Application Data\Help
    [2007/07/27 13:55:29 | 00,000,000 | ---D | M] -- C:\Documents and Settings\LocalService\Local Settings\Application Data\Help
    [2007/05/30 11:08:08 | 00,000,000 | ---D | M] -- C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft
    [2007/05/30 11:08:08 | 00,000,000 | ---D | M] -- C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft
    [2006/12/18 22:34:43 | 00,000,000 | --SD | M] -- C:\Documents and Settings\NetworkService\Application Data\Microsoft
    [2006/12/18 22:34:43 | 00,000,000 | --SD | M] -- C:\Documents and Settings\LocalService\Application Data\Microsoft

    ========== Files - Modified Within 14 Days ==========

    [2010/01/22 18:06:57 | 00,000,006 | -H-- | M] () -- C:\WINDOWS\tasks\SA.DAT
    [2010/01/22 18:06:55 | 00,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
    [2010/01/21 22:53:59 | 03,932,160 | -H-- | M] () -- C:\Documents and Settings\Tasha Z\NTUSER.DAT
    [2010/01/21 22:53:54 | 00,000,278 | -HS- | M] () -- C:\Documents and Settings\Tasha Z\ntuser.ini
    [2010/01/21 22:53:50 | 04,286,440 | -H-- | M] () -- C:\Documents and Settings\Tasha Z\Local Settings\Application Data\IconCache.db
    [2010/01/21 22:06:00 | 00,000,986 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-436374069-1500820517-725345543-1003UA.job
    [2010/01/20 22:06:06 | 00,000,696 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
    [2010/01/20 21:36:07 | 00,000,000 | ---- | M] () -- C:\WINDOWS\system.ini
    [2010/01/20 21:35:53 | 00,000,027 | ---- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts
    [2010/01/20 20:32:18 | 00,000,281 | RHS- | M] () -- C:\boot.ini
    [2010/01/20 20:27:41 | 03,830,599 | R--- | M] () -- C:\Documents and Settings\Tasha Z\Desktop\schrauber.exe
    [2010/01/20 16:35:46 | 00,293,376 | ---- | M] () -- C:\Documents and Settings\Tasha Z\Desktop\u0n696ig.exe
    [2010/01/20 12:26:26 | 00,547,328 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Tasha Z\Desktop\OTL.exe
    [2010/01/19 21:40:32 | 00,002,444 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
    [2010/01/19 21:27:08 | 00,005,372 | ---- | M] () -- C:\WINDOWS\imsins.BAK
    [2010/01/17 10:35:07 | 00,315,408 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat
    [2010/01/17 10:35:07 | 00,041,586 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat
    [2010/01/17 10:35:06 | 00,360,124 | ---- | M] () -- C:\WINDOWS\System32\PerfStringBackup.INI
    [2010/01/16 23:06:00 | 00,000,934 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-436374069-1500820517-725345543-1003Core.job
    [2010/01/16 22:17:15 | 00,005,569 | ---- | M] () -- C:\Documents and Settings\Tasha Z\My Documents\My Favorite Theme.theme
    [2010/01/16 18:56:28 | 00,502,752 | ---- | M] () -- C:\Documents and Settings\Tasha Z\My Documents\cfremover.exe
    [2010/01/16 18:25:56 | 00,000,874 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Advanced SystemCare.lnk
    [2010/01/16 18:25:19 | 09,537,816 | ---- | M] (IObit ) -- C:\Documents and Settings\Tasha Z\My Documents\asc-setup.exe
    [2010/01/15 18:31:51 | 52,659,8144 | ---- | M] () -- C:\WINDOWS\MEMORY.DMP
    [2010/01/14 23:20:16 | 00,000,162 | -H-- | M] () -- C:\Documents and Settings\Tasha Z\My Documents\~$ssage to Natasha Skye Zeraschi.doc
    [2010/01/14 21:57:52 | 00,000,779 | ---- | M] () -- C:\Documents and Settings\Tasha Z\Desktop\Launch Internet Explorer Browser.lnk
    [2010/01/14 18:31:15 | 61,551,4112 | -HS- | M] () -- C:\NRTPage.sys
    [2010/01/14 18:03:27 | 00,000,211 | ---- | M] () -- C:\Boot.bak
    [2010/01/14 18:03:27 | 00,000,000 | ---- | M] () -- C:\WINDOWS\win.ini
    [2010/01/13 20:13:16 | 00,001,743 | ---- | M] () -- C:\Documents and Settings\All Users\Application Data\QTSBandwidthCache
    [2010/01/13 19:42:48 | 00,195,368 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT
    [2010/01/13 19:17:14 | 00,043,832 | ---- | M] () -- C:\Documents and Settings\Tasha Z\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
    [2010/01/13 10:24:35 | 25,753,6806 | ---- | M] () -- C:\Documents and Settings\Tasha Z\Desktop\photos 1.zip
    [2010/01/12 12:48:44 | 00,002,473 | ---- | M] () -- C:\Documents and Settings\All Users\Documents\Global.sw2
    [2010/01/12 10:21:17 | 00,000,453 | ---- | M] () -- C:\WINDOWS\ODBC.INI

    ========== Files Created - No Company Name ==========

    [2010/01/20 22:06:06 | 00,000,696 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
    [2010/01/20 20:32:18 | 00,000,211 | ---- | C] () -- C:\Boot.bak
    [2010/01/20 20:32:14 | 00,260,272 | ---- | C] () -- C:\cmldr
    [2010/01/20 20:29:50 | 00,261,632 | ---- | C] () -- C:\WINDOWS\PEV.exe
    [2010/01/20 20:29:50 | 00,098,816 | ---- | C] () -- C:\WINDOWS\sed.exe
    [2010/01/20 20:29:50 | 00,080,412 | ---- | C] () -- C:\WINDOWS\grep.exe
    [2010/01/20 20:29:50 | 00,077,312 | ---- | C] () -- C:\WINDOWS\MBR.exe
    [2010/01/20 20:29:50 | 00,068,096 | ---- | C] () -- C:\WINDOWS\zip.exe
    [2010/01/20 20:27:41 | 03,830,599 | R--- | C] () -- C:\Documents and Settings\Tasha Z\Desktop\schrauber.exe
    [2010/01/20 16:35:45 | 00,293,376 | ---- | C] () -- C:\Documents and Settings\Tasha Z\Desktop\u0n696ig.exe
    [2010/01/16 23:01:25 | 00,000,986 | ---- | C] () -- C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-436374069-1500820517-725345543-1003UA.job
    [2010/01/16 23:01:24 | 00,000,934 | ---- | C] () -- C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-436374069-1500820517-725345543-1003Core.job
    [2010/01/16 18:56:04 | 00,502,752 | ---- | C] () -- C:\Documents and Settings\Tasha Z\My Documents\cfremover.exe
    [2010/01/16 18:25:56 | 00,000,874 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Advanced SystemCare.lnk
    [2010/01/14 23:20:16 | 00,000,162 | -H-- | C] () -- C:\Documents and Settings\Tasha Z\My Documents\~$ssage to Natasha Skye Zeraschi.doc
    [2010/01/14 18:31:15 | 61,551,4112 | -HS- | C] () -- C:\NRTPage.sys
    [2010/01/13 20:13:16 | 00,001,743 | ---- | C] () -- C:\Documents and Settings\All Users\Application Data\QTSBandwidthCache
    [2010/01/13 10:23:37 | 25,753,6806 | ---- | C] () -- C:\Documents and Settings\Tasha Z\Desktop\photos 1.zip
    [2010/01/12 12:21:18 | 00,005,569 | ---- | C] () -- C:\Documents and Settings\Tasha Z\My Documents\My Favorite Theme.theme
    [2009/03/21 20:06:40 | 00,002,880 | ---- | C] () -- C:\Documents and Settings\Tasha Z\Application Data\NMM-MetaData.db
    [2007/12/25 23:22:03 | 00,009,216 | ---- | C] () -- C:\Documents and Settings\Tasha Z\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
    [2007/09/18 10:52:59 | 00,326,589 | ---- | C] () -- C:\Documents and Settings\Tasha Z\Application Data\update.log
    [2007/03/29 23:00:40 | 00,203,264 | R--- | C] () -- C:\WINDOWS\System32\CddbCdda.dll
    [2006/12/19 20:28:00 | 00,000,453 | ---- | C] () -- C:\WINDOWS\ODBC.INI
    [2006/12/19 20:14:37 | 00,069,632 | R--- | C] () -- C:\WINDOWS\sm56spn.dll
    [2006/12/19 20:14:37 | 00,069,632 | R--- | C] () -- C:\WINDOWS\sm56itl.dll
    [2006/12/19 20:14:37 | 00,069,632 | R--- | C] () -- C:\WINDOWS\sm56eng.dll
    [2006/12/19 20:14:37 | 00,069,632 | R--- | C] () -- C:\WINDOWS\sm56brz.dll
    [2006/12/19 20:14:37 | 00,061,440 | R--- | C] () -- C:\WINDOWS\sm56ger.dll
    [2006/12/19 20:14:37 | 00,061,440 | R--- | C] () -- C:\WINDOWS\sm56fra.dll
    [2006/12/19 20:14:37 | 00,053,248 | R--- | C] () -- C:\WINDOWS\sm56jpn.dll
    [2006/12/19 20:14:37 | 00,049,152 | R--- | C] () -- C:\WINDOWS\sm56cht.dll
    [2006/12/19 20:14:37 | 00,049,152 | R--- | C] () -- C:\WINDOWS\sm56chs.dll
    [2005/01/21 04:02:28 | 00,013,312 | ---- | C] () -- C:\WINDOWS\System32\RMDevice.dll
    [2004/08/04 10:00:00 | 00,081,920 | ---- | C] () -- C:\WINDOWS\System32\ieencode.dll
    [2003/01/07 15:05:08 | 00,002,695 | ---- | C] () -- C:\WINDOWS\System32\OUTLPERF.INI
    [2001/09/24 06:59:00 | 00,045,056 | ---- | C] () -- C:\WINDOWS\System32\NavLogon.dll

    ========== LOP Check ==========

    [2009/03/21 19:41:52 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Installations
    [2009/03/21 19:52:11 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\PC Suite
    [2010/01/19 16:39:26 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Tasha Z\Application Data\IObit
    [2009/10/30 08:34:56 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Tasha Z\Application Data\Leadertech
    [2009/03/21 19:51:41 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Tasha Z\Application Data\Nokia
    [2009/03/21 19:44:53 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Tasha Z\Application Data\PC Suite

    ========== Purity Check ==========


    < End of report >
     
  11. wendy

    wendy Registered Members

    Joined:
    Jan 18, 2010
    Messages:
    49
    Location:
    wales uk
    Operating System:
    Windows XP Home
     
  12. schrauber

    schrauber Guest

    Hi,


    Run OTL
    • Under the Custom Scans/Fixes box at the bottom, paste in the following
    • Then click the Run Fix button at the top
    • Let the program run unhindered, when done it will say "Fix Complete press ok to open the log"
    • Please post that log in your next reply. Note: If a file or folder cannot be moved immediately you may be asked to reboot the machine to finish the move process. If you are asked to reboot the machine choose Yes. In this case, after the reboot, open Notepad (Start->All Programs->Accessories->Notepad), click File->Open, in the File Name box enter *.log and press the Enter key, navigate to the C:\_OTL\MovedFiles folder, and open the newest .log file present, and copy/paste the contents of that document back here in your next post.
    ================================Follow up scan=================================
    • Double click on OTL to run it. Make sure all other windows are closed and to let it run uninterrupted.
    • When the window appears, underneath Output at the top change it to Minimal Output.
    • Under the Standard Registry box change it to All.
    • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
      • When the scan completes, it will open one notepad window. OTL.Txt a This is saved in the same location as OTL.
      • Please copy (Edit->Select All, Edit->Copy) the contents of this file and post it with your next reply.
     
  13. wendy

    wendy Registered Members

    Joined:
    Jan 18, 2010
    Messages:
    49
    Location:
    wales uk
    Operating System:
    Windows XP Home
     
  14. wendy

    wendy Registered Members

    Joined:
    Jan 18, 2010
    Messages:
    49
    Location:
    wales uk
    Operating System:
    Windows XP Home
    OTL logfile created on: 22/01/2010 21:16:09 - Run 6
    OTL by OldTimer - Version 3.1.25.2 Folder = C:\Documents and Settings\Tasha Z\Desktop
    Windows XP Professional Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
    Internet Explorer (Version = 6.0.2900.2180)
    Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy

    502.00 Mb Total Physical Memory | 253.00 Mb Available Physical Memory | 50.00% Memory free
    1.00 Gb Paging File | 1.00 Gb Available in Paging File | 82.00% Paging File free
    Paging file location(s): c:\pagefile.sys 756 1512 [binary data]

    %SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
    Drive C: | 93.15 Gb Total Space | 85.49 Gb Free Space | 91.78% Space Free | Partition Type: NTFS
    D: Drive not present or media not loaded
    E: Drive not present or media not loaded
    F: Drive not present or media not loaded
    G: Drive not present or media not loaded
    H: Drive not present or media not loaded
    I: Drive not present or media not loaded

    Computer Name: TASHA
    Current User Name: Tasha Z
    Logged in as Administrator.

    Current Boot Mode: Normal
    Scan Mode: Current user
    Company Name Whitelist: Off
    Skip Microsoft Files: Off
    File Age = 30 Days
    Output = Minimal

    ========== Processes (SafeList) ==========

    PRC - C:\Documents and Settings\Tasha Z\Desktop\OTL.exe (OldTimer Tools)
    PRC - C:\Program Files\Windows Live\Contacts\wlcomm.exe (Microsoft Corporation)
    PRC - C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe (Microsoft Corp.)
    PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
    PRC - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe (Intel Corporation)
    PRC - C:\WINDOWS\system32\wscntfy.exe (Microsoft Corporation)


    ========== Modules (SafeList) ==========

    MOD - C:\Documents and Settings\Tasha Z\Desktop\OTL.exe (OldTimer Tools)
    MOD - C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03\comctl32.dll (Microsoft Corporation)


    ========== Win32 Services (SafeList) ==========

    SRV - (fsssvc) -- C:\Program Files\Windows Live\Family Safety\fsssvc.exe (Microsoft Corporation)
    SRV - (SeaPort) -- C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe (Microsoft Corp.)
    SRV - (EvtEng) Intel(R) -- C:\Program Files\Intel\Wireless\Bin\EvtEng.exe (Intel Corporation)
    SRV - (IDriverT) -- C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe (Macrovision Corporation)
    SRV - (ose) -- C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE (Microsoft Corporation)


    ========== Driver Services (SafeList) ==========

    DRV - (fssfltr) -- C:\WINDOWS\system32\drivers\fssfltr_tdi.sys (Microsoft Corporation)
    DRV - (Secdrv) -- C:\WINDOWS\system32\drivers\secdrv.sys (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.)
    DRV - (AegisP) AEGIS Protocol (IEEE 802.1x) -- C:\WINDOWS\system32\drivers\AegisP.sys (Meetinghouse Data Communications)
    DRV - (IntcAzAudAddService) Service for Realtek HD Audio (WDM) -- C:\WINDOWS\system32\drivers\RtkHDAud.Sys (Realtek Semiconductor Corp.)
    DRV - (ialm) -- C:\WINDOWS\system32\drivers\ialmnt5.sys (Intel Corporation)
    DRV - (O2MDRDR) -- C:\WINDOWS\System32\DRIVERS\o2media.sys (O2Micro )
    DRV - (RTL8023xp) -- C:\WINDOWS\system32\drivers\Rtnicxp.sys (Realtek Semiconductor Corporation )
    DRV - (O2SDRDR) -- C:\WINDOWS\System32\DRIVERS\o2sd.sys (O2Micro )
    DRV - (smserial) -- C:\WINDOWS\system32\drivers\smserial.sys (Motorola Inc.)
    DRV - (w39n51) Intel(R) -- C:\WINDOWS\system32\drivers\w39n51.sys (Intel® Corporation)
    DRV - (s24trans) -- C:\WINDOWS\system32\drivers\s24trans.sys (Intel Corporation)
    DRV - (HDAudBus) -- C:\WINDOWS\system32\drivers\Hdaudbus.sys (Windows (R) Server 2003 DDK provider)
    DRV - (cercsr6) -- C:\WINDOWS\system32\drivers\cercsr6.sys (Adaptec, Inc.)
    DRV - (Ptilink) -- C:\WINDOWS\system32\drivers\ptilink.sys (Parallel Technologies, Inc.)


    ========== Standard Registry (All) ==========


    ========== Internet Explorer ==========

    IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
    IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
    IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
    IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://home.sweetim.com
    IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomizeSearch = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm
    IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie
    IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm

    IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\system32\blank.htm
    IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Page_Transitions = 1
    IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
    IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://computerhelpforums.net/topic/14391-malware-and-trogen-problems/page__gopid__52878&
    IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie
    IE - HKCU\..\URLSearchHook: {31c7d459-9cc3-44f2-9dca-fc11795309b4} - C:\Program Files\IObitCom\tbIObi.dll (Conduit Ltd.)
    IE - HKCU\..\URLSearchHook: {CFBFAE00-17A6-11D0-99CB-00C04FD64497} - C:\WINDOWS\system32\shdocvw.dll (Microsoft Corporation)
    IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

    ========== FireFox ==========

    FF - prefs.js..browser.search.defaultenginename: "Google"
    FF - prefs.js..browser.search.defaulturl: "http://www.google.com/search?lr=&ie=UTF-8&oe=UTF-8&q="
    FF - prefs.js..browser.search.selectedEngine: "Google"

    FF - HKLM\software\mozilla\Firefox\Extensions\\{3112ca9c-de6d-4884-a869-9855de68056c}: C:\Documents and Settings\All Users\Application Data\Mozilla\Firefox Extensions\{3112ca9c-de6d-4884-a869-9855de68056c} [2007/09/23 13:00:04 | 00,000,000 | ---D | M]

    [2007/11/07 21:38:29 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Tasha Z\Application Data\Mozilla\Firefox\Profiles\uykhn9v0.default\extensions
    [2007/11/07 21:38:29 | 00,000,000 | ---D | M] (Google Toolbar for Firefox) -- C:\Documents and Settings\Tasha Z\Application Data\Mozilla\Firefox\Profiles\uykhn9v0.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}
    [2007/07/26 23:03:34 | 00,717,312 | ---- | M] (DivX,Inc.) -- C:\Program Files\Mozilla Firefox\plugins\npdivx32.dll
    [2007/05/10 21:52:34 | 00,095,864 | ---- | M] (Adobe Systems Inc.) -- C:\Program Files\Mozilla Firefox\plugins\nppdf32.dll
    [2007/12/25 22:56:48 | 00,131,072 | ---- | M] (Apple Inc.) -- C:\Program Files\Mozilla Firefox\plugins\npqtplugin.dll
    [2007/12/25 22:56:48 | 00,131,072 | ---- | M] (Apple Inc.) -- C:\Program Files\Mozilla Firefox\plugins\npqtplugin2.dll
    [2007/12/25 22:56:48 | 00,131,072 | ---- | M] (Apple Inc.) -- C:\Program Files\Mozilla Firefox\plugins\npqtplugin3.dll
    [2007/12/25 22:56:48 | 00,131,072 | ---- | M] (Apple Inc.) -- C:\Program Files\Mozilla Firefox\plugins\npqtplugin4.dll
    [2007/12/25 22:56:48 | 00,131,072 | ---- | M] (Apple Inc.) -- C:\Program Files\Mozilla Firefox\plugins\npqtplugin5.dll
    [2007/12/25 22:56:48 | 00,131,072 | ---- | M] (Apple Inc.) -- C:\Program Files\Mozilla Firefox\plugins\npqtplugin6.dll
    [2007/12/25 22:56:48 | 00,131,072 | ---- | M] (Apple Inc.) -- C:\Program Files\Mozilla Firefox\plugins\npqtplugin7.dll
    [2010/01/12 12:47:30 | 00,002,221 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\SafeSearch.xml

    O1 HOSTS File: ([2010/01/20 21:35:53 | 00,000,027 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
    O1 - Hosts: 127.0.0.1 localhost
    O2 - BHO: (Search Helper) - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SearchHelper.dll (Microsoft Corp.)
    O2 - BHO: (Windows Live Toolbar Helper) - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files\Windows Live\Toolbar\wltcore.dll (Microsoft Corporation)
    O3 - HKLM\..\Toolbar: (&Windows Live Toolbar) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll (Microsoft Corporation)
    O3 - HKCU\..\Toolbar\ShellBrowser: (&Address) - {01E04581-4EEE-11D0-BFE9-00AA005B4383} - C:\WINDOWS\system32\browseui.dll (Microsoft Corporation)
    O3 - HKCU\..\Toolbar\WebBrowser: (&Address) - {01E04581-4EEE-11D0-BFE9-00AA005B4383} - C:\WINDOWS\system32\browseui.dll (Microsoft Corporation)
    O3 - HKCU\..\Toolbar\WebBrowser: (&Links) - {0E5CBF21-D15F-11D0-8301-00AA005B4383} - C:\WINDOWS\system32\shell32.dll (Microsoft Corporation)
    O3 - HKCU\..\Toolbar\WebBrowser: (&Windows Live Toolbar) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll (Microsoft Corporation)
    O3 - HKCU\..\Toolbar\WebBrowser: (IObitCom Toolbar) - {31C7D459-9CC3-44F2-9DCA-FC11795309B4} - C:\Program Files\IObitCom\tbIObi.dll (Conduit Ltd.)
    O3 - HKCU\..\Toolbar\WebBrowser: (Yahoo! Toolbar) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.)
    O4 - HKCU..\Run: [Google Update] C:\Documents and Settings\Tasha Z\Local Settings\Application Data\Google\Update\GoogleUpdate.exe (Google Inc.)
    O4 - HKCU..\Run: [MSMSGS] C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
    O4 - HKCU..\Run: [msnmsgr] C:\Program Files\Windows Live\Messenger\msnmsgr.exe (Microsoft Corporation)
    O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Infodelivery present
    O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: LinkResolveIgnoreLinkInfo = 0
    O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoResolveSearch = 1
    O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
    O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
    O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
    O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0
    O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption =
    O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext =
    O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1
    O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1
    O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableRegistryTools = 0
    O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
    O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
    O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: LinkResolveIgnoreLinkInfo = 0
    O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
    O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
    O10 - NameSpace_Catalog5\Catalog_Entries\000000000001 [] - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
    O10 - NameSpace_Catalog5\Catalog_Entries\000000000002 [] - C:\WINDOWS\system32\winrnr.dll (Microsoft Corporation)
    O10 - NameSpace_Catalog5\Catalog_Entries\000000000003 [] - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
    O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
    O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
    O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
    O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - C:\WINDOWS\system32\rsvpsp.dll (Microsoft Corporation)
    O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - C:\WINDOWS\system32\rsvpsp.dll (Microsoft Corporation)
    O10 - Protocol_Catalog9\Catalog_Entries\000000000006 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
    O10 - Protocol_Catalog9\Catalog_Entries\000000000007 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
    O10 - Protocol_Catalog9\Catalog_Entries\000000000008 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
    O10 - Protocol_Catalog9\Catalog_Entries\000000000009 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
    O10 - Protocol_Catalog9\Catalog_Entries\000000000010 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
    O10 - Protocol_Catalog9\Catalog_Entries\000000000011 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
    O10 - Protocol_Catalog9\Catalog_Entries\000000000012 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
    O10 - Protocol_Catalog9\Catalog_Entries\000000000013 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
    O10 - Protocol_Catalog9\Catalog_Entries\000000000014 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
    O10 - Protocol_Catalog9\Catalog_Entries\000000000015 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
    O15 - HKLM\..Trusted Domains: 1 domain(s) and sub-domain(s) not assigned to a zone.
    O15 - HKCU\..Trusted Domains: ([]msn in My Computer)
    O15 - HKCU\..Trusted Domains: 8 domain(s) and sub-domain(s) not assigned to a zone.
    O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} http://download.eset.com/special/eos/OnlineScanner.cab (OnlineScanner Control)
    O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
    O18 - Protocol\Handler\about {3050F406-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\system32\mshtml.dll (Microsoft Corporation)
    O18 - Protocol\Handler\cdl {3dd53d40-7b8b-11D0-b013-00aa0059ce02} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
    O18 - Protocol\Handler\dvd {12D51199-0DB5-46FE-A120-47A3D7D937CC} - C:\WINDOWS\system32\msvidctl.dll (Microsoft Corporation)
    O18 - Protocol\Handler\file {79eac9e7-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
    O18 - Protocol\Handler\ftp {79eac9e3-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
    O18 - Protocol\Handler\gopher {79eac9e4-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
    O18 - Protocol\Handler\http {79eac9e2-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
    O18 - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
    O18 - Protocol\Handler\http\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
    O18 - Protocol\Handler\https {79eac9e5-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
    O18 - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
    O18 - Protocol\Handler\https\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
    O18 - Protocol\Handler\ipp - No CLSID value found
    O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
    O18 - Protocol\Handler\its {9D148291-B9C8-11D0-A4CC-0000F80149F6} - C:\WINDOWS\system32\itss.dll (Microsoft Corporation)
    O18 - Protocol\Handler\javascript {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\system32\mshtml.dll (Microsoft Corporation)
    O18 - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\Windows Live\Messenger\msgrapp.14.0.8089.0726.dll (Microsoft Corporation)
    O18 - Protocol\Handler\local {79eac9e7-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
    O18 - Protocol\Handler\mailto {3050f3DA-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\system32\mshtml.dll (Microsoft Corporation)
    O18 - Protocol\Handler\mhtml {05300401-BCBC-11d0-85E3-00C04FD85AB4} - C:\WINDOWS\system32\inetcomm.dll (Microsoft Corporation)
    O18 - Protocol\Handler\mk {79eac9e6-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
    O18 - Protocol\Handler\msdaipp - No CLSID value found
    O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
    O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
    O18 - Protocol\Handler\ms-its {9D148291-B9C8-11D0-A4CC-0000F80149F6} - C:\WINDOWS\system32\itss.dll (Microsoft Corporation)
    O18 - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\Windows Live\Messenger\msgrapp.14.0.8089.0726.dll (Microsoft Corporation)
    O18 - Protocol\Handler\mso-offdap {3D9F03FA-7A94-11D3-BE81-0050048385D1} - C:\Program Files\Common Files\Microsoft Shared\Web Components\10\OWC10.DLL (Microsoft Corporation)
    O18 - Protocol\Handler\mso-offdap11 {32505114-5902-49B2-880A-1F7738E5A384} - C:\Program Files\Common Files\Microsoft Shared\Web Components\11\OWC11.DLL (Microsoft Corporation)
    O18 - Protocol\Handler\res {3050F3BC-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\system32\mshtml.dll (Microsoft Corporation)
    O18 - Protocol\Handler\sysimage {76E67A63-06E9-11D2-A840-006008059382} - C:\WINDOWS\system32\mshtml.dll (Microsoft Corporation)
    O18 - Protocol\Handler\tv {CBD30858-AF45-11D2-B6D6-00C04FBBDE6E} - C:\WINDOWS\system32\msvidctl.dll (Microsoft Corporation)
    O18 - Protocol\Handler\vbscript {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\system32\mshtml.dll (Microsoft Corporation)
    O18 - Protocol\Handler\vnd.ms.radio {3DA2AA3B-3D96-11D2-9BD2-204C4F4F5020} - C:\WINDOWS\system32\msdxm.ocx ()
    O18 - Protocol\Handler\wia {13F3EA8B-91D7-4F0A-AD76-D2853AC8BECE} - C:\WINDOWS\system32\wiascr.dll (Microsoft Corporation)
    O18 - Protocol\Handler\wlmailhtml {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - C:\Program Files\Windows Live\Mail\mailcomm.dll (Microsoft Corporation)
    O18 - Protocol\Filter\Class Install Handler {32B533BB-EDAE-11d0-BD5A-00AA00B92AF1} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
    O18 - Protocol\Filter\deflate {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
    O18 - Protocol\Filter\gzip {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
    O18 - Protocol\Filter\lzdhtml {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
    O18 - Protocol\Filter\text/webviewhtml {733AC4CB-F1A4-11d0-B951-00A0C90312E1} - C:\WINDOWS\system32\shell32.dll (Microsoft Corporation)
    O18 - Protocol\Filter\text/xml {807553E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\Microsoft Shared\OFFICE11\MSOXMLMF.DLL (Microsoft Corporation)
    O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
    O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) - C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
    O20 - HKLM Winlogon: UIHost - (logonui.exe) - C:\WINDOWS\System32\logonui.exe (Microsoft Corporation)
    O20 - HKLM Winlogon: VMApplet - (rundll32 shell32) - C:\WINDOWS\System32\shell32.dll (Microsoft Corporation)
    O20 - HKLM Winlogon: VMApplet - (Control_RunDLL "sysdm.cpl") - C:\WINDOWS\System32\sysdm.cpl (Microsoft Corporation)
    O20 - Winlogon\Notify\crypt32chain: DllName - crypt32.dll - C:\WINDOWS\System32\crypt32.dll (Microsoft Corporation)
    O20 - Winlogon\Notify\cryptnet: DllName - cryptnet.dll - C:\WINDOWS\System32\cryptnet.dll (Microsoft Corporation)
    O20 - Winlogon\Notify\cscdll: DllName - cscdll.dll - C:\WINDOWS\System32\cscdll.dll (Microsoft Corporation)
    O20 - Winlogon\Notify\igfxcui: DllName - igfxdev.dll - C:\WINDOWS\System32\igfxdev.dll (Intel Corporation)
    O20 - Winlogon\Notify\NavLogon: DllName - C:\WINDOWS\system32\NavLogon.dll - C:\WINDOWS\system32\NavLogon.dll ()
    O20 - Winlogon\Notify\ScCertProp: DllName - wlnotify.dll - C:\WINDOWS\System32\wlnotify.dll (Microsoft Corporation)
    O20 - Winlogon\Notify\Schedule: DllName - wlnotify.dll - C:\WINDOWS\System32\wlnotify.dll (Microsoft Corporation)
    O20 - Winlogon\Notify\sclgntfy: DllName - sclgntfy.dll - C:\WINDOWS\System32\sclgntfy.dll (Microsoft Corporation)
    O20 - Winlogon\Notify\SensLogn: DllName - WlNotify.dll - C:\WINDOWS\System32\wlnotify.dll (Microsoft Corporation)
    O20 - Winlogon\Notify\termsrv: DllName - wlnotify.dll - C:\WINDOWS\System32\wlnotify.dll (Microsoft Corporation)
    O20 - Winlogon\Notify\wlballoon: DllName - wlnotify.dll - C:\WINDOWS\System32\wlnotify.dll (Microsoft Corporation)
    O21 - SSODL: CDBurn - {fbeb8a05-beee-4442-804e-409d6c4515e9} - C:\WINDOWS\system32\shell32.dll (Microsoft Corporation)
    O21 - SSODL: PostBootReminder - {7849596a-48ea-486e-8937-a2a3009f31a9} - C:\WINDOWS\system32\shell32.dll (Microsoft Corporation)
    O21 - SSODL: SysTray - {35CEC8A3-2BE6-11D2-8773-92E220524153} - C:\WINDOWS\system32\stobject.dll (Microsoft Corporation)
    O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - C:\WINDOWS\system32\webcheck.dll (Microsoft Corporation)
    O22 - SharedTaskScheduler: {438755C2-A8BA-11D1-B96B-00A0C90312E1} - Browseui preloader - C:\WINDOWS\system32\browseui.dll (Microsoft Corporation)
    O22 - SharedTaskScheduler: {8C7461EF-2B13-11d2-BE35-3078302C2030} - Component Categories cache daemon - C:\WINDOWS\system32\browseui.dll (Microsoft Corporation)
    O24 - Desktop Components:0 (My Current Home Page) - About:Home
    O24 - Desktop Components:1 () - http://www.orange.co.uk/
    O24 - Desktop WallPaper: C:\Documents and Settings\Tasha Z\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
    O24 - Desktop BackupWallPaper: C:\Documents and Settings\Tasha Z\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
    O28 - HKLM ShellExecuteHooks: {AEB6717E-7E19-11d0-97EE-00C04FD91972} - C:\WINDOWS\System32\shell32.dll (Microsoft Corporation)
    O29 - HKLM SecurityProviders - (msapsspc.dll) - C:\WINDOWS\System32\msapsspc.dll (Microsoft Corporation)
    O29 - HKLM SecurityProviders - (schannel.dll) - C:\WINDOWS\System32\schannel.dll (Microsoft Corporation)
    O29 - HKLM SecurityProviders - (digest.dll) - C:\WINDOWS\System32\digest.dll (Microsoft Corporation)
    O29 - HKLM SecurityProviders - (msnsspc.dll) - C:\WINDOWS\System32\msnsspc.dll (Microsoft Corporation)
    O30 - LSA: Authentication Packages - (msv1_0) - C:\WINDOWS\System32\msv1_0.dll (Microsoft Corporation)
    O30 - LSA: Security Packages - (kerberos) - C:\WINDOWS\System32\kerberos.dll (Microsoft Corporation)
    O30 - LSA: Security Packages - (msv1_0) - C:\WINDOWS\System32\msv1_0.dll (Microsoft Corporation)
    O30 - LSA: Security Packages - (schannel) - C:\WINDOWS\System32\schannel.dll (Microsoft Corporation)
    O30 - LSA: Security Packages - (wdigest) - C:\WINDOWS\System32\wdigest.dll (Microsoft Corporation)
    O31 - SafeBoot: AlternateShell - cmd.exe
    O32 - HKLM CDRom: AutoRun - 1
    O32 - AutoRun File - [2006/12/18 22:35:04 | 00,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
    O34 - HKLM BootExecute: (autocheck autochk *) - File not found
    O35 - comfile [open] -- "%1" %*
    O35 - exefile [open] -- "%1" %*

    ========== Files/Folders - Created Within 30 Days ==========

    [2010/01/21 20:12:09 | 00,000,000 | ---D | C] -- C:\Program Files\ESET
    [2010/01/21 19:11:14 | 00,000,000 | -HSD | C] -- C:\RECYCLER
    [2010/01/21 19:10:36 | 00,000,000 | ---D | C] -- C:\_OTL
    [2010/01/21 10:21:08 | 00,016,736 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\mucltui.dll.mui
    [2010/01/21 10:21:07 | 00,274,288 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\mucltui.dll
    [2010/01/20 22:06:08 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Tasha Z\Application Data\Malwarebytes
    [2010/01/20 22:06:04 | 00,038,224 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbamswissarmy.sys
    [2010/01/20 22:06:02 | 00,019,160 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbam.sys
    [2010/01/20 22:06:02 | 00,000,000 | ---D | C] -- C:\Program Files\Malwarebytes' Anti-Malware
    [2010/01/20 22:06:02 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Malwarebytes
    [2010/01/20 21:39:46 | 00,000,000 | ---D | C] -- C:\WINDOWS\temp
    [2010/01/20 20:32:12 | 00,000,000 | RHSD | C] -- C:\cmdcons
    [2010/01/20 20:29:50 | 00,212,480 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWXCACLS.exe
    [2010/01/20 20:29:50 | 00,161,792 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWREG.exe
    [2010/01/20 20:29:50 | 00,136,704 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWSC.exe
    [2010/01/20 20:29:50 | 00,031,232 | ---- | C] (NirSoft) -- C:\WINDOWS\NIRCMD.exe
    [2010/01/20 20:29:41 | 00,000,000 | ---D | C] -- C:\WINDOWS\ERDNT
    [2010/01/20 20:29:27 | 00,000,000 | ---D | C] -- C:\Qoobox
    [2010/01/20 12:26:19 | 00,547,328 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\Tasha Z\Desktop\OTL.exe
    [2010/01/17 10:24:24 | 00,054,752 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\fssfltr_tdi.sys
    [2010/01/16 23:33:09 | 00,000,000 | ---D | C] -- C:\Program Files\Microsoft Sync Framework
    [2010/01/16 23:07:23 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Tasha Z\My Documents\Downloads
    [2010/01/16 23:01:38 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Tasha Z\Local Settings\Application Data\Temp
    [2010/01/16 22:27:00 | 00,000,000 | R--D | C] -- C:\Documents and Settings\Tasha Z\My Documents\Copy of My Music
    [2010/01/16 22:25:44 | 00,000,000 | ---D | C] -- C:\Program Files\msn gaming zone
    [2010/01/16 18:25:58 | 00,000,000 | ---D | C] -- C:\Program Files\IObitCom
    [2010/01/16 18:25:58 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Tasha Z\Local Settings\Application Data\IObitCom
    [2010/01/16 18:25:58 | 00,000,000 | ---D | C] -- C:\Program Files\Conduit
    [2010/01/16 18:25:58 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Tasha Z\Local Settings\Application Data\Conduit
    [2010/01/16 18:25:50 | 00,000,000 | ---D | C] -- C:\Program Files\IObit
    [2010/01/16 18:25:50 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Tasha Z\Application Data\IObit
    [2010/01/16 18:24:32 | 09,537,816 | ---- | C] (IObit ) -- C:\Documents and Settings\Tasha Z\My Documents\asc-setup.exe
    [2010/01/16 16:45:05 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\Logfiles
    [2010/01/16 16:45:05 | 00,000,000 | ---D | C] -- C:\Inetpub
    [2010/01/15 18:47:01 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Tasha Z\Local Settings\Application Data\Identities
    [2010/01/14 21:53:48 | 00,000,000 | ---D | M] -- C:\Documents and Settings\LocalService\Application Data\Adobe
    [2010/01/14 21:22:20 | 00,055,656 | ---- | C] (Avira GmbH) -- C:\WINDOWS\System32\drivers\avgntflt.sys
    [2010/01/14 12:05:59 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Tasha Z\Local Settings\Application Data\ICS
    [2010/01/13 22:57:09 | 00,000,000 | -H-D | C] -- C:\WINDOWS\System32\GroupPolicy
    [2010/01/13 22:01:24 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\drivers\N360
    [2010/01/13 22:01:21 | 00,000,000 | ---D | C] -- C:\Program Files\Windows Sidebar
    [2010/01/13 20:28:35 | 00,000,000 | ---D | C] -- C:\Program Files\Microsoft
    [2010/01/13 20:28:33 | 00,000,000 | ---D | C] -- C:\Program Files\Windows Live SkyDrive
    [2010/01/13 20:27:36 | 00,000,000 | ---D | C] -- C:\Config.Msi
    [2010/01/13 19:17:37 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Tasha Z\Tracing
    [2010/01/13 19:15:58 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Documents\microsoft
    [2010/01/13 19:15:12 | 00,000,000 | ---D | C] -- C:\Program Files\Windows Live
    [2010/01/13 15:23:54 | 00,000,000 | ---D | C] -- C:\Program Files\Common Files\Windows Live
    [2010/01/13 10:21:39 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Tasha Z\Desktop\mike
    [2010/01/12 13:40:18 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Tasha Z\Desktop\sue doc
    [2010/01/12 11:23:50 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Tasha Z\Local Settings\Application Data\Symantec
    [2010/01/12 10:38:26 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Norton
    [2010/01/12 10:35:39 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\NortonInstaller
    [2010/01/12 10:22:24 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\appmgmt
    [2007/07/27 13:55:54 | 00,000,000 | ---D | M] -- C:\Documents and Settings\LocalService\Application Data\Help
    [2007/07/27 13:55:29 | 00,000,000 | ---D | M] -- C:\Documents and Settings\LocalService\Local Settings\Application Data\Help
    [2007/05/30 11:08:08 | 00,000,000 | ---D | M] -- C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft
    [2007/05/30 11:08:08 | 00,000,000 | ---D | M] -- C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft
    [2006/12/18 22:34:43 | 00,000,000 | --SD | M] -- C:\Documents and Settings\NetworkService\Application Data\Microsoft
    [2006/12/18 22:34:43 | 00,000,000 | --SD | M] -- C:\Documents and Settings\LocalService\Application Data\Microsoft

    ========== Files - Modified Within 30 Days ==========

    [2010/01/22 21:08:25 | 00,000,006 | -H-- | M] () -- C:\WINDOWS\tasks\SA.DAT
    [2010/01/22 21:08:23 | 00,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
    [2010/01/22 21:07:51 | 03,932,160 | -H-- | M] () -- C:\Documents and Settings\Tasha Z\NTUSER.DAT
    [2010/01/22 21:07:45 | 00,000,278 | -HS- | M] () -- C:\Documents and Settings\Tasha Z\ntuser.ini
    [2010/01/22 21:06:00 | 00,000,986 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-436374069-1500820517-725345543-1003UA.job
    [2010/01/22 20:58:29 | 04,816,130 | -H-- | M] () -- C:\Documents and Settings\Tasha Z\Local Settings\Application Data\IconCache.db
    [2010/01/20 22:06:06 | 00,000,696 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
    [2010/01/20 21:36:07 | 00,000,000 | ---- | M] () -- C:\WINDOWS\system.ini
    [2010/01/20 21:35:53 | 00,000,027 | ---- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts
    [2010/01/20 20:32:18 | 00,000,281 | RHS- | M] () -- C:\boot.ini
    [2010/01/20 20:27:41 | 03,830,599 | R--- | M] () -- C:\Documents and Settings\Tasha Z\Desktop\schrauber.exe
    [2010/01/20 16:35:46 | 00,293,376 | ---- | M] () -- C:\Documents and Settings\Tasha Z\Desktop\u0n696ig.exe
    [2010/01/20 12:26:26 | 00,547,328 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Tasha Z\Desktop\OTL.exe
    [2010/01/19 21:40:32 | 00,002,444 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
    [2010/01/19 21:27:08 | 00,005,372 | ---- | M] () -- C:\WINDOWS\imsins.BAK
    [2010/01/17 10:35:07 | 00,315,408 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat
    [2010/01/17 10:35:07 | 00,041,586 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat
    [2010/01/17 10:35:06 | 00,360,124 | ---- | M] () -- C:\WINDOWS\System32\PerfStringBackup.INI
    [2010/01/16 23:06:00 | 00,000,934 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-436374069-1500820517-725345543-1003Core.job
    [2010/01/16 22:17:15 | 00,005,569 | ---- | M] () -- C:\Documents and Settings\Tasha Z\My Documents\My Favorite Theme.theme
    [2010/01/16 18:56:28 | 00,502,752 | ---- | M] () -- C:\Documents and Settings\Tasha Z\My Documents\cfremover.exe
    [2010/01/16 18:25:56 | 00,000,874 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Advanced SystemCare.lnk
    [2010/01/16 18:25:19 | 09,537,816 | ---- | M] (IObit ) -- C:\Documents and Settings\Tasha Z\My Documents\asc-setup.exe
    [2010/01/15 18:31:51 | 52,659,8144 | ---- | M] () -- C:\WINDOWS\MEMORY.DMP
    [2010/01/14 23:20:16 | 00,000,162 | -H-- | M] () -- C:\Documents and Settings\Tasha Z\My Documents\~$ssage to Natasha Skye Zeraschi.doc
    [2010/01/14 21:57:52 | 00,000,779 | ---- | M] () -- C:\Documents and Settings\Tasha Z\Desktop\Launch Internet Explorer Browser.lnk
    [2010/01/14 18:31:15 | 61,551,4112 | -HS- | M] () -- C:\NRTPage.sys
    [2010/01/14 18:03:27 | 00,000,211 | ---- | M] () -- C:\Boot.bak
    [2010/01/14 18:03:27 | 00,000,000 | ---- | M] () -- C:\WINDOWS\win.ini
    [2010/01/13 20:13:16 | 00,001,743 | ---- | M] () -- C:\Documents and Settings\All Users\Application Data\QTSBandwidthCache
    [2010/01/13 19:42:48 | 00,195,368 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT
    [2010/01/13 19:17:14 | 00,043,832 | ---- | M] () -- C:\Documents and Settings\Tasha Z\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
    [2010/01/13 10:24:35 | 25,753,6806 | ---- | M] () -- C:\Documents and Settings\Tasha Z\Desktop\photos 1.zip
    [2010/01/12 12:48:44 | 00,002,473 | ---- | M] () -- C:\Documents and Settings\All Users\Documents\Global.sw2
    [2010/01/12 10:21:17 | 00,000,453 | ---- | M] () -- C:\WINDOWS\ODBC.INI
    [2010/01/07 16:07:14 | 00,038,224 | ---- | M] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbamswissarmy.sys
    [2010/01/07 16:07:04 | 00,019,160 | ---- | M] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbam.sys

    ========== Files Created - No Company Name ==========

    [2010/01/20 22:06:06 | 00,000,696 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
    [2010/01/20 20:32:18 | 00,000,211 | ---- | C] () -- C:\Boot.bak
    [2010/01/20 20:32:14 | 00,260,272 | ---- | C] () -- C:\cmldr
    [2010/01/20 20:29:50 | 00,261,632 | ---- | C] () -- C:\WINDOWS\PEV.exe
    [2010/01/20 20:29:50 | 00,098,816 | ---- | C] () -- C:\WINDOWS\sed.exe
    [2010/01/20 20:29:50 | 00,080,412 | ---- | C] () -- C:\WINDOWS\grep.exe
    [2010/01/20 20:29:50 | 00,077,312 | ---- | C] () -- C:\WINDOWS\MBR.exe
    [2010/01/20 20:29:50 | 00,068,096 | ---- | C] () -- C:\WINDOWS\zip.exe
    [2010/01/20 20:27:41 | 03,830,599 | R--- | C] () -- C:\Documents and Settings\Tasha Z\Desktop\schrauber.exe
    [2010/01/20 16:35:45 | 00,293,376 | ---- | C] () -- C:\Documents and Settings\Tasha Z\Desktop\u0n696ig.exe
    [2010/01/16 23:01:25 | 00,000,986 | ---- | C] () -- C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-436374069-1500820517-725345543-1003UA.job
    [2010/01/16 23:01:24 | 00,000,934 | ---- | C] () -- C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-436374069-1500820517-725345543-1003Core.job
    [2010/01/16 18:56:04 | 00,502,752 | ---- | C] () -- C:\Documents and Settings\Tasha Z\My Documents\cfremover.exe
    [2010/01/16 18:25:56 | 00,000,874 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Advanced SystemCare.lnk
    [2010/01/14 23:20:16 | 00,000,162 | -H-- | C] () -- C:\Documents and Settings\Tasha Z\My Documents\~$ssage to Natasha Skye Zeraschi.doc
    [2010/01/14 18:31:15 | 61,551,4112 | -HS- | C] () -- C:\NRTPage.sys
    [2010/01/13 20:13:16 | 00,001,743 | ---- | C] () -- C:\Documents and Settings\All Users\Application Data\QTSBandwidthCache
    [2010/01/13 10:23:37 | 25,753,6806 | ---- | C] () -- C:\Documents and Settings\Tasha Z\Desktop\photos 1.zip
    [2010/01/12 12:21:18 | 00,005,569 | ---- | C] () -- C:\Documents and Settings\Tasha Z\My Documents\My Favorite Theme.theme
    [2009/03/21 20:06:40 | 00,002,880 | ---- | C] () -- C:\Documents and Settings\Tasha Z\Application Data\NMM-MetaData.db
    [2007/12/25 23:22:03 | 00,009,216 | ---- | C] () -- C:\Documents and Settings\Tasha Z\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
    [2007/09/18 10:52:59 | 00,326,589 | ---- | C] () -- C:\Documents and Settings\Tasha Z\Application Data\update.log
    [2007/03/29 23:00:40 | 00,203,264 | R--- | C] () -- C:\WINDOWS\System32\CddbCdda.dll
    [2006/12/19 20:28:00 | 00,000,453 | ---- | C] () -- C:\WINDOWS\ODBC.INI
    [2006/12/19 20:14:37 | 00,069,632 | R--- | C] () -- C:\WINDOWS\sm56spn.dll
    [2006/12/19 20:14:37 | 00,069,632 | R--- | C] () -- C:\WINDOWS\sm56itl.dll
    [2006/12/19 20:14:37 | 00,069,632 | R--- | C] () -- C:\WINDOWS\sm56eng.dll
    [2006/12/19 20:14:37 | 00,069,632 | R--- | C] () -- C:\WINDOWS\sm56brz.dll
    [2006/12/19 20:14:37 | 00,061,440 | R--- | C] () -- C:\WINDOWS\sm56ger.dll
    [2006/12/19 20:14:37 | 00,061,440 | R--- | C] () -- C:\WINDOWS\sm56fra.dll
    [2006/12/19 20:14:37 | 00,053,248 | R--- | C] () -- C:\WINDOWS\sm56jpn.dll
    [2006/12/19 20:14:37 | 00,049,152 | R--- | C] () -- C:\WINDOWS\sm56cht.dll
    [2006/12/19 20:14:37 | 00,049,152 | R--- | C] () -- C:\WINDOWS\sm56chs.dll
    [2005/01/21 04:02:28 | 00,013,312 | ---- | C] () -- C:\WINDOWS\System32\RMDevice.dll
    [2004/08/04 10:00:00 | 00,081,920 | ---- | C] () -- C:\WINDOWS\System32\ieencode.dll
    [2003/01/07 15:05:08 | 00,002,695 | ---- | C] () -- C:\WINDOWS\System32\OUTLPERF.INI
    [2001/09/24 06:59:00 | 00,045,056 | ---- | C] () -- C:\WINDOWS\System32\NavLogon.dll
    < End of report >
     
  15. schrauber

    schrauber Guest

    Nice :)

    How is your system running? Still any issues?
     
  16. wendy

    wendy Registered Members

    Joined:
    Jan 18, 2010
    Messages:
    49
    Location:
    wales uk
    Operating System:
    Windows XP Home
     
  17. wendy

    wendy Registered Members

    Joined:
    Jan 18, 2010
    Messages:
    49
    Location:
    wales uk
    Operating System:
    Windows XP Home
    hiya seems to be running faster then before now trying to update window system up date will let you know how that goes with in next couple of mins <_<
     
  18. schrauber

    schrauber Guest

    Oki doki :)
     
  19. wendy

    wendy Registered Members

    Joined:
    Jan 18, 2010
    Messages:
    49
    Location:
    wales uk
    Operating System:
    Windows XP Home
    hiya still wont let me download any updates from window as you suggested.
    thanks again
    wendy
     
  20. schrauber

    schrauber Guest

    Do you get an error message? Can you explain what happened when you try to download updates?
     

Share This Page