PDA

View Full Version : in safe mode programs still are not working



Ambie
2012-08-31, 21:45
.
DDS (Ver_2011-08-26.01) - NTFSx86 NETWORK
Internet Explorer: 8.0.6001.18702
Run by oneonta at 12:07:03 on 2012-08-31
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.894.645 [GMT -5:00]
.
.
============== Running Processes ===============
.
C:\WINDOWS\system32\svchost.exe -k DcomLaunch
svchost.exe
C:\WINDOWS\system32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
.
============== Pseudo HJT Report ===============
.
uSearch Page = hxxp://www.google.com/hws/sb/dell-usuk/en/side.html?channel=us
uSearch Bar = hxxp://www.google.com/hws/sb/dell-usuk/en/side.html?channel=us
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
mSearchAssistant = hxxp://www.google.com/hws/sb/dell-usuk/en/side.html?channel=us
BHO: HP Print Enhancer: {0347c33e-8762-4905-bf09-768834316c61} - c:\program files\hp\smart web printing\hpswp_printenhancer.dll
BHO: HP Print Clips: {053f9267-dc04-4294-a72c-58f732d338c0} - c:\program files\hp\smart web printing\hpswp_framework.dll
BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelper.dll
BHO: AVG Do Not Track: {31332eef-cb9f-458f-afeb-d30e9a66b6ba} - c:\program files\avg\avg2012\avgdtiex.dll
BHO: SSVHelper Class: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre6\bin\ssv.dll
BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\2.0.301.7164\swg.dll
BHO: CBrowserHelperObject Object: {ca6319c0-31b7-401e-a518-a07c3db8f777} - c:\program files\dell\bae\BAE.dll
BHO: Ask Toolbar: {d4027c7f-154a-4066-a1ad-4243d8127440} - c:\program files\ask.com\GenericAskToolbar.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
BHO: Yontoo: {fd72061e-9fde-484d-a58a-0bab4151cad8} - c:\program files\yontoo\YontooIEClient.dll
TB: Ask Toolbar: {d4027c7f-154a-4066-a1ad-4243d8127440} - c:\program files\ask.com\GenericAskToolbar.dll
TB: {0B53EAC3-8D69-4B9E-9B19-A37C9A5676A7} - No File
TB: {C4069E3A-68F1-403E-B40E-20066696354B} - No File
uRun: [swg] c:\windows\system32\regsvr32.exe
uRun: [MSMSGS] "c:\program files\messenger\msmsgs.exe" /background
uRun: [DellSupport] "c:\program files\dellsupport\DSAgnt.exe" /startup
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
uRunOnce: [831_750187672418] "c:\documents and settings\oneonta\local settings\application data\logmein rescue applet\LMIR0001.tmp_r.bat"
mRun: [SynTPEnh] c:\program files\synaptics\syntp\SynTPEnh.exe
mRun: [SigmatelSysTrayApp] stsystra.exe
mRun: [PDVDDXSrv] "c:\program files\cyberlink\powerdvd dx\PDVDDXSrv.exe"
mRun: [hpbdfawep] c:\program files\hp\dfawep\bin\hpbdfawep.exe 1
mRun: [HP Software Update] c:\program files\hp\hp software update\HPWuSchd2.exe
mRun: [Google Desktop Search] "c:\program files\google\google desktop search\GoogleDesktop.exe" /startup
mRun: [Dell QuickSet] c:\program files\dell\quickset\quickset.exe
mRun: [Broadcom Wireless Manager UI] c:\windows\system32\WLTRAY.exe
mRun: [ATICCC] "c:\program files\ati technologies\ati.ace\CLIStart.exe"
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 8.0\reader\Reader_sl.exe"
mRun: [<NO NAME>]
mRun: [ApnUpdater] "c:\program files\ask.com\updater\Updater.exe"
mRun: [SunJavaUpdateSched] c:\program files\java\jre6\bin\jusched.exe
mRun: [ROC_roc_ssl_v12] "c:\program files\avg secure search\ROC_roc_ssl_v12.exe" / /PROMPT /CMPID=roc_ssl_v12
StartupFolder: c:\docume~1\oneonta\startm~1\programs\startup\erunta~1.lnk - c:\documents and settings\all users\desktop\erunt\AUTOBACK.EXE
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\digita~1.lnk - c:\program files\digital line detect\DLG.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\hpdigi~1.lnk - c:\program files\hp\digital imaging\bin\hpqtra08.exe
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - {CAFEEFAC-0016-0000-0034-ABCDEFFEDCBC} - c:\program files\java\jre6\bin\jp2iexp.dll
IE: {58ECB495-38F0-49cb-A538-10282ABF65E7} - {E763472E-A716-4CD9-89BD-DBDA6122F741} - c:\program files\hp\smart web printing\hpswp_extensions.dll
IE: {68BCFFE1-A2DA-4B40-9068-87ECBFC19D16} - {68BCFFE1-A2DA-4B40-9068-87ECBFC19D16} - c:\program files\avg\avg2012\avgdtiex.dll
IE: {700259D7-1666-479a-93B1-3250410481E8} - {A93C41D8-01F8-4F8B-B14C-DE20B117E636} - c:\program files\hp\smart web printing\hpswp_extensions.dll
Trusted Zone: microsoft.com\www.update
DPF: {17492023-C23A-453E-A040-C7C580BBF700} - hxxp://download.microsoft.com/download/E/5/6/E5611B10-0D6D-4117-8430-A67417AA88CD/LegitCheckControl.cab
DPF: {5AE58FCF-6F6A-49B2-B064-02492C66E3F4} - hxxp://catalog.update.microsoft.com/v7/site/ClientControl/en/x86/MuCatalogWebControl.cab?1346087306875
DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} - hxxp://windowsupdate.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1346269034781
DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} - hxxp://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab
DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} - hxxp://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1346079803069
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_34-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0034-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_34-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_34-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
TCP: DhcpNameServer = 192.168.43.1
TCP: Interfaces\{7143CEFB-2312-43ED-B18A-5C0A9BAA9BC1} : DhcpNameServer = 192.168.43.1
Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} -
Notify: AtiExtEvent - Ati2evxx.dll
.
============= SERVICES / DRIVERS ===============
.
R0 atiide;atiide;c:\windows\system32\drivers\atiide.sys [2007-11-16 3456]
R0 AVG Anti-Rootkit;AVG Anti-Rootkit;c:\windows\system32\drivers\avgarkt.sys [2007-1-31 5632]
R1 AvgArCln;Avg Anti-Rootkit Clean Driver;c:\windows\system32\drivers\AvgArCln.sys [2012-8-31 3968]
R4 AVGIDSHX;AVGIDSHX;c:\windows\system32\drivers\avgidshx.sys --> c:\windows\system32\drivers\avgidshx.sys [?]
R4 Avgrkx86;AVG Anti-Rootkit Driver;c:\windows\system32\drivers\avgrkx86.sys --> c:\windows\system32\drivers\avgrkx86.sys [?]
R4 Avgtdix;AVG TDI Driver;c:\windows\system32\drivers\avgtdix.sys --> c:\windows\system32\drivers\avgtdix.sys [?]
S1 avgtp;avgtp;c:\windows\system32\drivers\avgtpx86.sys [2012-8-31 27496]
S2 SentinelKeysServer;Sentinel Keys Server;c:\program files\common files\safenet sentinel\sentinel keys server\sntlkeyssrvr.exe [2008-7-11 328992]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\system32\macromed\flash\FlashPlayerUpdateService.exe [2012-8-27 250568]
S3 Avgfwdx;Avgfwdx;c:\windows\system32\drivers\avgfwdx.sys --> c:\windows\system32\drivers\avgfwdx.sys [?]
S3 Avgfwfd;AVG network filter service;c:\windows\system32\drivers\avgfwdx.sys --> c:\windows\system32\drivers\avgfwdx.sys [?]
S3 MDGECG;Midmark ECG USB Driver (mdgecg.sys);c:\windows\system32\drivers\mdgecg.sys [2008-1-30 18216]
S3 MECGLDR;Midmark ECG USB Loader(mdgecldr.sys);c:\windows\system32\drivers\mdgecldr.sys [2008-1-30 17192]
.
=============== Created Last 30 ================
.
2012-08-31 17:04:54 497463 ----a-w- c:\program files\internet explorer\temporary internet files\content.ie5\ee3vs3lj\aswMBR[1].exe
2012-08-31 17:03:31 607260 ------r- c:\program files\internet explorer\temporary internet files\content.ie5\ee3vs3lj\dds[1].scr
2012-08-31 16:51:14 791393 ----a-w- c:\program files\internet explorer\temporary internet files\content.ie5\ufjr266c\erunt-setup[1].exe
2012-08-31 16:28:55 27496 ----a-w- c:\windows\system32\drivers\avgtpx86.sys
2012-08-31 15:01:08 3879800 ----a-w- c:\program files\internet explorer\temporary internet files\content.ie5\poo9vmv0\avg_isct_stb_all_2012_2197_free[1].exe
2012-08-31 14:42:38 8544 ----a-w- c:\program files\internet explorer\temporary internet files\content.ie5\10m6490o\msert[1].exe
2012-08-31 12:38:01 -------- d-----w- c:\documents and settings\oneonta\local settings\application data\LogMeIn Rescue Applet
2012-08-31 09:36:58 135820 ----a-w- c:\program files\internet explorer\temporary internet files\content.ie5\ufjr266c\avg_free_x86_all_2012_2197a5126[1].exe
2012-08-31 07:33:06 3968 ----a-w- c:\windows\system32\drivers\AvgArCln.sys
2012-08-31 07:15:06 423736 ----a-w- c:\program files\avgarkt-setup.exe
2012-08-31 07:12:22 431312 ----a-w- c:\program files\Brothersoft_downloader_For_AVG_Anti_Rootkit_Free.exe
2012-08-31 05:14:52 179968 ----a-w- c:\program files\kss12.0.1.117mlg_en_ru_fr_de.exe
2012-08-31 05:08:08 -------- d-----w- c:\program files\Yontoo
2012-08-31 05:08:07 -------- d-----w- c:\documents and settings\all users\application data\Tarma Installer
2012-08-31 04:52:52 50688 ----a-w- c:\program files\ATF-Cleaner.exe
2012-08-31 03:39:41 587640 ----a-w- c:\program files\cbsidlm-tr1_6-Combofix-75221073.exe
2012-08-31 01:10:24 739856 ----a-w- c:\program files\ChromeSetup.exe
2012-08-30 23:16:23 275696 ----a-w- c:\windows\system32\mucltui.dll
2012-08-30 23:16:23 17136 ----a-w- c:\windows\system32\mucltui.dll.mui
2012-08-30 09:02:03 327816 ----a-w- c:\program files\BullGuardDownloader.exe
2012-08-30 08:36:21 15384 ----a-w- c:\windows\system32\wuapi.dll.mui
2012-08-30 08:27:28 75776 ------w- c:\windows\system32\dllcache\strmfilt.dll
2012-08-30 08:27:28 265728 ------w- c:\windows\system32\dllcache\http.sys
2012-08-30 08:27:28 25088 ------w- c:\windows\system32\dllcache\httpapi.dll
2012-08-30 08:13:48 -------- d-----w- c:\windows\system32\en
2012-08-30 08:13:48 -------- d-----w- c:\windows\system32\bits
2012-08-30 05:14:39 -------- d-----w- c:\program files\Ask.com
2012-08-30 05:14:39 -------- d-----w- C:\Firefox
2012-08-30 05:14:37 -------- d-----w- c:\documents and settings\oneonta\local settings\application data\AskToolbar
2012-08-30 04:49:22 -------- d-----w- c:\documents and settings\all users\application data\Ask
2012-08-30 04:47:51 73728 ----a-w- c:\windows\system32\javacpl.cpl
2012-08-30 04:47:51 477168 ----a-w- c:\windows\system32\npdeployJava1.dll
2012-08-30 04:47:51 473072 ----a-w- c:\windows\system32\deployJava1.dll
2012-08-30 02:08:12 -------- d-----w- c:\program files\Microsoft CAPICOM 2.1.0.2
2012-08-29 23:25:19 285696 ------w- c:\windows\system32\dllcache\atmfd.dll
2012-08-29 23:25:09 272128 ------w- c:\windows\system32\drivers\bthport.sys
2012-08-29 23:25:09 272128 ------w- c:\windows\system32\dllcache\bthport.sys
2012-08-29 23:25:00 74240 ------w- c:\windows\system32\dllcache\mscms.dll
2012-08-29 23:24:48 989696 ------w- c:\windows\system32\dllcache\kernel32.dll
2012-08-29 23:24:48 56832 ------w- c:\windows\system32\dllcache\secur32.dll
2012-08-29 23:23:54 80896 ------w- c:\windows\system32\dllcache\tlntsess.exe
2012-08-29 23:23:54 76288 ------w- c:\windows\system32\dllcache\telnet.exe
2012-08-29 23:23:44 353792 ------w- c:\windows\system32\dllcache\srv.sys
2012-08-29 23:22:03 485376 ------w- c:\windows\system32\dllcache\wmspdmod.dll
2012-08-29 23:20:55 455680 ------w- c:\windows\system32\dllcache\mrxsmb.sys
2012-08-29 23:20:15 471552 ------w- c:\windows\system32\dllcache\aclayers.dll
2012-08-29 23:19:33 79872 ------w- c:\windows\system32\dllcache\raschap.dll
2012-08-29 23:19:33 149504 ------w- c:\windows\system32\dllcache\rastls.dll
2012-08-29 23:19:02 1435648 ------w- c:\windows\system32\dllcache\query.dll
2012-08-29 23:18:42 744448 ------w- c:\windows\system32\dllcache\helpsvc.exe
2012-08-29 23:18:20 253952 ------w- c:\windows\system32\dllcache\es.dll
2012-08-29 23:18:06 33280 ------w- c:\windows\system32\dllcache\csrsrv.dll
2012-08-29 23:17:54 474112 ------w- c:\windows\system32\dllcache\shlwapi.dll
2012-08-29 23:17:41 132096 ------w- c:\windows\system32\dllcache\wkssvc.dll
2012-08-29 23:17:29 100864 ------w- c:\windows\system32\dllcache\6to4svc.dll
2012-08-29 23:17:15 147456 ------w- c:\windows\system32\dllcache\schannel.dll
2012-08-29 23:17:04 81920 ------w- c:\windows\system32\dllcache\fontsub.dll
2012-08-29 23:17:04 119808 ------w- c:\windows\system32\dllcache\t2embed.dll
2012-08-29 23:14:00 897024 ------w- c:\windows\system32\dllcache\wmspdmoe.dll
2012-08-29 23:14:00 809984 ------w- c:\windows\system32\dllcache\wmvdmod.dll
2012-08-29 23:14:00 759296 ------w- c:\windows\system32\dllcache\wmsdmod.dll
2012-08-29 23:14:00 303616 ------w- c:\windows\system32\dllcache\wmstream.dll
2012-08-29 23:14:00 20480 ------w- c:\windows\system32\dllcache\wmpui.dll
2012-08-29 23:14:00 115200 ------w- c:\windows\system32\dllcache\wmsdmoe.dll
2012-08-29 23:14:00 1119744 ------w- c:\windows\system32\dllcache\wmsdmoe2.dll
2012-08-29 23:14:00 102400 ------w- c:\windows\system32\dllcache\wmpshell.dll
2012-08-29 23:14:00 1001472 ------w- c:\windows\system32\dllcache\wmvdmoe2.dll
2012-08-29 23:12:56 4126 ------w- c:\windows\system32\dllcache\msdxmlc.dll
2012-08-29 23:11:54 159232 ------w- c:\windows\system32\dllcache\cewmdm.dll
2012-08-29 23:10:59 203136 ------w- c:\windows\system32\dllcache\rmcast.sys
2012-08-29 23:09:57 95744 ------w- c:\windows\system32\dllcache\mqsec.dll
2012-08-29 23:08:53 -------- d-----w- c:\windows\system32\PreInstall
2012-08-29 17:56:10 -------- d-----w- C:\wuagent
2012-08-29 15:06:10 -------- d-----w- c:\documents and settings\oneonta\application data\AVG2012
2012-08-29 15:05:42 -------- d-----w- c:\windows\system32\appmgmt
2012-08-29 09:25:20 -------- d-----w- c:\documents and settings\all users\application data\AVG2012
2012-08-28 04:08:15 73416 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2012-08-28 04:08:15 696520 ----a-w- c:\windows\system32\FlashPlayerApp.exe
2012-08-27 13:38:04 -------- d-----w- c:\windows\system32\wbem\repository\FS
2012-08-27 13:38:04 -------- d-----w- c:\windows\system32\wbem\Repository
2012-08-27 05:17:49 -------- d-----w- c:\documents and settings\oneonta\application data\MSNInstaller
2012-08-26 11:01:49 -------- d-----w- c:\windows\LastGood(2)
2012-08-26 10:30:58 -------- d-----w- c:\windows\system32\scripting
2012-08-26 10:30:57 -------- d-----w- c:\windows\l2schemas
2012-08-26 10:20:28 -------- d-----w- c:\windows\network diagnostic
2012-08-26 07:52:05 -------- d-----w- c:\documents and settings\oneonta\local settings\application data\Solid State Networks
2012-08-25 16:55:39 -------- d-----w- c:\documents and settings\all users\application data\CPA_VA
2012-08-25 16:53:29 880832 ----a-w- c:\windows\system32\drivers\sfi.dat
2012-08-25 14:37:33 -------- d-----w- c:\documents and settings\all users\application data\Comodo
2012-08-25 04:06:51 -------- d-----w- c:\documents and settings\all users\application data\MFAData
2012-08-25 04:06:51 -------- d-----w- c:\documents and settings\all users\application data\Common Files
2012-08-25 01:05:51 -------- d-----w- c:\windows\system32\XPSViewer
2012-08-25 01:05:01 -------- d-----w- c:\documents and settings\oneonta\local settings\application data\visi_coupon
2012-08-24 13:34:23 -------- d-sh--w- c:\documents and settings\oneonta\IECompatCache
2012-08-24 13:20:16 -------- d-sh--w- c:\documents and settings\oneonta\PrivacIE
2012-08-24 12:45:42 -------- d-sh--w- c:\documents and settings\oneonta\IETldCache
2012-08-24 12:42:04 -------- d-----w- c:\windows\ie8updates
2012-08-24 12:40:37 -------- d-----w- c:\program files\Yahoo!
2012-08-24 12:38:47 -------- dc-h--w- c:\windows\ie8
2012-08-24 12:36:55 599040 ------w- c:\windows\system32\dllcache\msfeeds.dll
2012-08-24 12:36:55 55296 ------w- c:\windows\system32\dllcache\msfeedsbs.dll
2012-08-24 12:36:55 12800 ------w- c:\windows\system32\dllcache\xpshims.dll
2012-08-24 12:36:54 743424 ------w- c:\windows\system32\dllcache\iedvtool.dll
2012-08-24 12:36:54 247808 ------w- c:\windows\system32\dllcache\ieproxy.dll
2012-08-24 12:36:53 1985536 ------w- c:\windows\system32\dllcache\iertutil.dll
2012-08-24 12:36:51 11076096 ------w- c:\windows\system32\dllcache\ieframe.dll
2012-08-23 14:11:28 -------- d-----w- c:\windows\ServicePackFiles
2012-08-20 20:06:46 -------- d-----w- c:\program files\One Million Recipes
2012-08-20 19:26:59 -------- d-----w- c:\program files\GameSpy Arcade
2012-08-20 19:19:32 -------- d-----w- c:\program files\Firefly Studios
2012-08-20 19:16:53 -------- d-----w- c:\program files\Edmark
2012-08-20 18:57:50 -------- d-----w- c:\program files\common files\gst
2012-08-20 18:56:57 -------- d-----w- c:\program files\greenstreet
.
==================== Find3M ====================
.
2012-06-04 22:35:26 222448 ----a-w- c:\windows\system32\muweb.dll
2012-06-02 20:19:44 22040 ----a-w- c:\windows\system32\wucltui.dll.mui
2012-06-02 20:19:38 219160 ----a-w- c:\windows\system32\wuaucpl.cpl
2012-06-02 20:19:38 15384 ----a-w- c:\windows\system32\wuaucpl.cpl.mui
2012-06-02 20:19:34 45080 ----a-w- c:\windows\system32\wups2(2).dll
2012-06-02 20:19:30 17944 ----a-w- c:\windows\system32\wuaueng.dll.mui
.
============= FINISH: 12:08:12.98 ===============
aswMBR version 0.9.9.1665 Copyright(c) 2011 AVAST Software
Run date: 2012-08-31 12:23:54
-----------------------------
12:23:54.250 OS Version: Windows 5.1.2600 Service Pack 3
12:23:54.250 Number of processors: 1 586 0x4C02
12:23:54.250 ComputerName: DDDSD3F1 UserName: oneonta
12:23:56.562 Initialize success
12:34:11.359 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP2T0L0-3
12:34:11.421 Disk 0 Vendor: FUJITSU_MHW2080BH 0085001C Size: 76319MB BusType: 3
12:34:12.593 Disk 0 MBR read successfully
12:34:12.625 Disk 0 MBR scan
12:34:12.656 Disk 0 Windows XP default MBR code
12:34:12.687 Disk 0 Partition 1 00 DE Dell Utility Dell 8.0 78 MB offset 63
12:34:12.734 Disk 0 Partition 2 80 (A) 07 HPFS/NTFS NTFS 76238 MB offset 160650
12:34:12.765 Disk 0 scanning sectors +156296385
12:34:12.921 Disk 0 scanning C:\WINDOWS\system32\drivers
12:34:23.234 Service scanning
12:34:43.500 Modules scanning
12:34:49.437 Disk 0 trace - called modules:
12:34:49.546 ntoskrnl.exe CLASSPNP.SYS disk.sys atapi.sys hal.dll atiide.sys PCIIDEX.SYS
12:34:49.578 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x8531bab8]
12:34:51.625 3 CLASSPNP.SYS[f7797fd7] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP2T0L0-3[0x85342d98]
12:34:51.734 Scan finished successfully
12:35:32.375 Disk 0 MBR has been saved successfully to "C:\Documents and Settings\oneonta\Desktop\MBR.dat"
12:35:32.421 The log file has been saved successfully to "C:\Documents and Settings\oneonta\Desktop\aswMBR.txt"

ken545
2012-09-26, 03:11
:snwelcome:


Please read Before You Post (http://forums.spybot.info/showthread.php?t=288)
While best efforts are made to assist in removing infections safely, unexpected stuff can happen. It is advisable that you back up your important data before starting any clean up procedure. Neither Safer Networking Forums nor the Analyst providing the advice may be held responsible for any loss.

Until we deem your system clean I am going to ask you not to install or uninstall any software or hardware except for the programs we may run.

Running programs with Vista or Windows 7 , you need to Right Click on the program and select RUN AS ADMINISTATOR






Please download Malwarebytes from Here (http://www.malwarebytes.org/mbam-download.php) or Here (http://www.majorgeeks.com/Malwarebytes_Anti-Malware_d5756.html)


Double-click mbam-setup.exe and follow the prompts to install the program.
At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
If an update is found, it will download and install the latest version.
Once the program has loaded, select Perform quick scan, then click Scan.
http://i24.photobucket.com/albums/c30/ken545/MBAMCapture.jpg
When the scan is complete, click OK, then Show Results to view the results.
Be sure that everything is checked, and click Remove Selected .
When completed, a log will open in Notepad. Please save it to a convenient location and post the results.
Note: If you receive a notice that some of the items couldn't be removed, that they have been added to the delete on reboot list, please reboot.
Post the report please








OTL by OldTimer

Download OTL (http://oldtimer.geekstogo.com/OTL.exe) to your desktop.
Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
When the window appears, underneath Output at the top change it to Minimal Output.
Click the "Scan All Users" checkbox.
Check the boxes beside LOP Check and Purity Check.
Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.

When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt.
Note:These logs can be located in the OTL. folder on you C:\ drive if they fail to open automatically.
Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post it with your next reply. You may need two posts to fit them both in.

ken545
2012-09-29, 13:00
Due to inactivity, this thread will now be closed.

If it has been three days or more since your last post, and the helper assisting you posted a response to that post to which you did not reply, your topic will not be reopened. At that point, if you still require help, please start a new topic and include a new DDS log with a link to your previous thread. Please do not add any logs that might have been requested in the closed topic, you would be starting fresh.