Welcome guest. Before posting on our computer help forum, you must register. Click here it's easy and free.
Also it never asked so I never did reboot. Is this ok?
:OTLuURLSearchHooks: H - No FileBHO: Complitly: {d27fc31c-6e3d-4305-8d53-acdaefa5f862} - c:\users\johnny ola\appdata\roaming\complitly\Complitly.dllmRun: [<NO NAME>] :COMMANDS[resethosts][purity][start explorer]
========== OTL ==================== COMMANDS ==========C:\Windows\System32\drivers\etc\Hosts moved successfully.HOSTS file reset successfully OTL by OldTimer - Version 3.2.31.0 log created on 12292011_141813
ComboFix 11-12-29.04 - Johnny Ola 12/29/2011 14:31:52.1.2 - x86Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.1.1033.18.2038.1055 [GMT -5:00]Running from: c:\users\Johnny Ola\Desktop\ComboFix.exeAV: AVG Anti-Virus Free Edition 2012 *Disabled/Updated* {5A2746B1-DEE9-F85A-FBCD-ADB11639C5F0}FW: COMODO Firewall *Enabled* {4D6F75E0-14AF-2E9E-AACD-24CDCF08AA2A}SP: AVG Anti-Virus Free Edition 2012 *Disabled/Updated* {E146A755-F8D3-F7D4-C17D-96C36DBE8F4D}SP: COMODO Defense+ *Enabled/Updated* {CE351521-78FA-2048-BB22-B68A4A5CA7EC}..((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))..C:\Install.exec:\programdata\pswi_preloaded.exec:\users\Johnny Ola\AppData\Local\assembly\tmp..((((((((((((((((((((((((( Files Created from 2011-11-28 to 2011-12-29 )))))))))))))))))))))))))))))))..2011-12-29 20:18 . 2011-12-29 20:21 -------- d-----w- c:\users\Johnny Ola\AppData\Local\temp2011-12-29 20:18 . 2011-12-29 20:18 -------- d-----w- c:\users\Guest\AppData\Local\temp2011-12-29 20:18 . 2011-12-29 20:18 -------- d-----w- c:\users\Default\AppData\Local\temp2011-12-29 19:18 . 2011-12-29 19:18 -------- d-----w- C:\_OTL2011-12-21 04:56 . 2011-12-21 04:56 -------- d-----w- c:\program files\iPod2011-12-21 04:56 . 2011-12-21 04:56 -------- d-----w- c:\program files\iTunes2011-12-15 01:33 . 2011-11-23 13:37 2043904 ----a-w- c:\windows\system32\win32k.sys2011-12-15 01:33 . 2011-11-08 12:10 2409784 ----a-w- c:\program files\Windows Mail\OESpamFilter.dat2011-12-15 01:33 . 2011-10-27 08:01 3602816 ----a-w- c:\windows\system32\ntkrnlpa.exe2011-12-15 01:33 . 2011-10-27 08:01 3550080 ----a-w- c:\windows\system32\ntoskrnl.exe2011-12-15 01:33 . 2011-10-14 16:02 429056 ----a-w- c:\windows\system32\EncDec.dll2011-12-15 01:33 . 2011-10-25 15:56 49152 ----a-w- c:\windows\system32\csrsrv.dll2011-12-15 01:33 . 2011-11-08 14:42 2048 ----a-w- c:\windows\system32\tzres.dll2011-12-08 18:02 . 2011-12-08 18:02 -------- d-----w- C:\Temp2011-12-08 17:29 . 2011-12-15 18:06 -------- d-----w- c:\users\Johnny Ola\AppData\Local\LogMeIn Rescue Applet...(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))).2011-12-29 19:05 . 2011-10-17 04:18 472808 ----a-w- c:\windows\system32\deployJava1.dll2011-12-19 18:59 . 2011-10-07 22:47 82400 ----a-w- c:\windows\system32\drivers\inspect.sys2011-12-19 18:59 . 2011-10-07 22:47 38616 ----a-w- c:\windows\system32\drivers\cmdhlp.sys2011-12-19 18:59 . 2011-10-07 22:47 491816 ----a-w- c:\windows\system32\drivers\cmdGuard.sys2011-12-19 18:59 . 2011-10-07 22:47 19600 ----a-w- c:\windows\system32\drivers\cmderd.sys2011-12-19 18:58 . 2011-10-07 22:47 33984 ----a-w- c:\windows\system32\cmdcsr.dll2011-12-19 18:58 . 2011-10-07 22:47 301224 ----a-w- c:\windows\system32\guard32.dll2011-12-10 20:24 . 2011-10-11 20:06 20464 ----a-w- c:\windows\system32\drivers\mbam.sys2011-11-19 21:24 . 2011-10-11 18:18 414368 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl2011-11-05 17:47 . 2011-11-05 17:47 11264 ----a-r- c:\users\Johnny Ola\AppData\Roaming\Microsoft\Installer\{98613C99-1399-416C-A07C-1EE1C585D872}\Icon98613C992.exe2011-10-29 23:10 . 2011-10-29 23:10 0 ----a-w- c:\windows\system32\ConduitEngine.tmp2011-10-26 06:49 . 2011-10-26 06:49 86528 ----a-w- c:\windows\system32\iesysprep.dll2011-10-26 06:49 . 2011-10-26 06:49 76800 ----a-w- c:\windows\system32\SetIEInstalledDate.exe2011-10-26 06:49 . 2011-10-26 06:49 74752 ----a-w- c:\windows\system32\RegisterIEPKEYs.exe2011-10-26 06:49 . 2011-10-26 06:49 48640 ----a-w- c:\windows\system32\mshtmler.dll2011-10-26 06:49 . 2011-10-26 06:49 161792 ----a-w- c:\windows\system32\msls31.dll2011-10-26 06:49 . 2011-10-26 06:49 63488 ----a-w- c:\windows\system32\tdc.ocx2011-10-26 06:49 . 2011-10-26 06:49 367104 ----a-w- c:\windows\system32\html.iec2011-10-26 06:49 . 2011-10-26 06:49 74752 ----a-w- c:\windows\system32\iesetup.dll2011-10-26 06:49 . 2011-10-26 06:49 23552 ----a-w- c:\windows\system32\licmgr10.dll2011-10-26 06:49 . 2011-10-26 06:49 420864 ----a-w- c:\windows\system32\vbscript.dll2011-10-26 06:49 . 2011-10-26 06:49 152064 ----a-w- c:\windows\system32\wextract.exe2011-10-26 06:49 . 2011-10-26 06:49 150528 ----a-w- c:\windows\system32\iexpress.exe2011-10-26 06:49 . 2011-10-26 06:49 142848 ----a-w- c:\windows\system32\ieUnatt.exe2011-10-26 06:49 . 2011-10-26 06:49 35840 ----a-w- c:\windows\system32\imgutil.dll2011-10-26 06:49 . 2011-10-26 06:49 11776 ----a-w- c:\windows\system32\mshta.exe2011-10-26 06:49 . 2011-10-26 06:49 110592 ----a-w- c:\windows\system32\IEAdvpack.dll2011-10-26 06:49 . 2011-10-26 06:49 101888 ----a-w- c:\windows\system32\admparse.dll2011-10-26 06:48 . 2011-10-26 06:48 979456 ----a-w- c:\windows\system32\MFH264Dec.dll2011-10-26 06:48 . 2011-10-26 06:48 357376 ----a-w- c:\windows\system32\MFHEAACdec.dll2011-10-26 06:48 . 2011-10-26 06:48 302592 ----a-w- c:\windows\system32\mfmp4src.dll2011-10-26 06:48 . 2011-10-26 06:48 98816 ----a-w- c:\windows\system32\mfps.dll2011-10-26 06:48 . 2011-10-26 06:48 2873344 ----a-w- c:\windows\system32\mf.dll2011-10-26 06:48 . 2011-10-26 06:48 261632 ----a-w- c:\windows\system32\mfreadwrite.dll2011-10-26 06:48 . 2011-10-26 06:48 209920 ----a-w- c:\windows\system32\mfplat.dll2011-10-26 06:48 . 2011-10-26 06:48 586240 ----a-w- c:\windows\system32\stobject.dll2011-10-26 06:48 . 2011-10-26 06:48 667648 ----a-w- c:\windows\system32\printfilterpipelinesvc.exe2011-10-26 06:48 . 2011-10-26 06:48 638336 ----a-w- c:\windows\system32\drivers\dxgkrnl.sys2011-10-26 06:48 . 2011-10-26 06:48 478720 ----a-w- c:\windows\system32\dxgi.dll2011-10-26 06:48 . 2011-10-26 06:48 37376 ----a-w- c:\windows\system32\cdd.dll2011-10-26 06:48 . 2011-10-26 06:48 26112 ----a-w- c:\windows\system32\printfilterpipelineprxy.dll2011-10-26 06:48 . 2011-10-26 06:48 258048 ----a-w- c:\windows\system32\winspool.drv2011-10-26 06:48 . 2011-10-26 06:48 135680 ----a-w- c:\windows\system32\XpsRasterService.dll2011-10-26 06:47 . 2011-10-26 06:47 4096 ----a-w- c:\windows\system32\drivers\en-US\dxgkrnl.sys.mui2011-10-26 06:47 . 2011-10-26 06:47 369664 ----a-w- c:\windows\system32\WMPhoto.dll2011-10-26 06:47 . 2011-10-26 06:47 252928 ----a-w- c:\windows\system32\dxdiag.exe2011-10-26 06:47 . 2011-10-26 06:47 195584 ----a-w- c:\windows\system32\dxdiagn.dll2011-10-26 06:47 . 2011-10-26 06:47 974848 ----a-w- c:\windows\system32\WindowsCodecs.dll2011-10-26 06:47 . 2011-10-26 06:47 519680 ----a-w- c:\windows\system32\d3d11.dll2011-10-26 06:47 . 2011-10-26 06:47 321024 ----a-w- c:\windows\system32\PhotoMetadataHandler.dll2011-10-26 06:47 . 2011-10-26 06:47 189440 ----a-w- c:\windows\system32\WindowsCodecsExt.dll2011-10-17 05:25 . 2006-11-02 10:32 101888 ----a-w- c:\windows\system32\ifxcardm.dll2011-10-17 05:25 . 2006-11-02 10:32 82432 ----a-w- c:\windows\system32\axaltocm.dll2011-10-14 07:04 . 2011-10-14 07:04 377344 ----a-w- c:\windows\system32\winhttp.dll2011-10-14 07:02 . 2011-10-14 07:02 36864 ----a-w- c:\windows\system32\drivers\en-US\http.sys.mui2011-10-13 08:09 . 2011-10-13 08:09 23552 ----a-w- c:\windows\system32\lpk.dll2011-10-13 08:09 . 2011-10-13 08:09 10240 ----a-w- c:\windows\system32\dciman32.dll2011-10-13 08:05 . 2011-10-13 08:05 61440 ----a-w- c:\windows\system32\winipsec.dll2011-10-13 08:05 . 2011-10-13 08:05 272896 ----a-w- c:\windows\system32\polstore.dll2011-10-13 08:02 . 2011-10-13 08:02 9728 ----a-w- c:\windows\system32\TCPSVCS.EXE2011-10-13 08:02 . 2011-10-13 08:02 8704 ----a-w- c:\windows\system32\HOSTNAME.EXE2011-10-13 08:02 . 2011-10-13 08:02 11264 ----a-w- c:\windows\system32\MRINFO.EXE2011-10-13 08:02 . 2011-10-13 08:02 105984 ----a-w- c:\windows\system32\netiohlp.dll2011-10-13 08:02 . 2011-10-13 08:02 10240 ----a-w- c:\windows\system32\finger.exe2011-10-13 08:02 . 2011-10-13 08:02 27136 ----a-w- c:\windows\system32\NETSTAT.EXE2011-10-13 08:02 . 2011-10-13 08:02 19968 ----a-w- c:\windows\system32\ARP.EXE2011-10-13 08:02 . 2011-10-13 08:02 17920 ----a-w- c:\windows\system32\ROUTE.EXE2011-10-13 07:59 . 2011-10-13 07:59 65024 ----a-w- c:\windows\system32\wlanapi.dll2011-10-13 07:59 . 2011-10-13 07:59 127488 ----a-w- c:\windows\system32\L2SecHC.dll2011-10-13 07:59 . 2011-10-13 07:59 68096 ----a-w- c:\windows\system32\wlanhlp.dll2011-10-13 07:59 . 2011-10-13 07:59 513536 ----a-w- c:\windows\system32\wlansvc.dll2011-10-13 07:59 . 2011-10-13 07:59 302592 ----a-w- c:\windows\system32\wlansec.dll2011-10-13 07:59 . 2011-10-13 07:59 293376 ----a-w- c:\windows\system32\wlanmsm.dll2011-10-13 07:59 . 2011-10-13 07:59 15181 ----a-w- c:\windows\system32\gatherWirelessInfo.vbs2011-10-13 07:58 . 2011-10-13 07:58 1401856 ----a-w- c:\windows\system32\msxml6.dll2011-10-13 07:58 . 2011-10-13 07:58 2048 ----a-w- c:\windows\system32\msxml3r.dll2011-10-13 07:58 . 2011-10-13 07:58 2048 ----a-w- c:\windows\system32\msxml6r.dll2011-10-13 07:57 . 2011-10-13 07:57 218624 ----a-w- c:\windows\system32\msv1_0.dll2011-10-13 07:55 . 2011-10-13 07:55 53248 ----a-w- c:\windows\system32\rrinstaller.exe2011-10-13 07:55 . 2011-10-13 07:55 24576 ----a-w- c:\windows\system32\mfpmp.exe2011-10-13 07:55 . 2011-10-13 07:55 2048 ----a-w- c:\windows\system32\mferror.dll2011-10-13 07:52 . 2011-10-13 07:52 71680 ----a-w- c:\windows\system32\atl.dll2011-10-13 07:47 . 2011-10-13 07:47 160256 ----a-w- c:\windows\system32\wkssvc.dll2011-10-13 07:46 . 2011-10-13 07:46 53248 ----a-w- c:\windows\system32\tsgqec.dll2011-10-13 07:46 . 2011-10-13 07:46 136192 ----a-w- c:\windows\system32\aaclient.dll2011-10-13 07:44 . 2011-10-13 07:44 714240 ----a-w- c:\windows\system32\timedate.cpl2011-10-13 07:36 . 2011-10-13 07:36 623616 ----a-w- c:\windows\system32\localspl.dll2011-10-13 07:33 . 2011-10-13 07:33 499712 ----a-w- c:\windows\system32\kerberos.dll2011-10-13 07:33 . 2011-10-13 07:33 175104 ----a-w- c:\windows\system32\wdigest.dll2011-10-13 07:33 . 2011-10-13 07:33 9728 ----a-w- c:\windows\system32\lsass.exe2011-10-13 07:33 . 2011-10-13 07:33 72704 ----a-w- c:\windows\system32\secur32.dll2011-10-13 07:33 . 2011-10-13 07:33 439864 ----a-w- c:\windows\system32\drivers\ksecdd.sys2011-10-13 07:33 . 2011-10-13 07:33 1259008 ----a-w- c:\windows\system32\lsasrv.dll2011-10-13 07:31 . 2011-10-13 07:31 6656 ----a-w- c:\windows\system32\kbd106n.dll2011-10-13 07:29 . 2011-10-13 07:29 62464 ----a-w- c:\windows\system32\l3codeca.acm2011-10-13 07:29 . 2011-10-13 07:29 220672 ----a-w- c:\windows\system32\l3codecp.acm2011-10-13 07:27 . 2011-10-13 07:27 30720 ----a-w- c:\windows\system32\drivers\tcpipreg.sys2011-10-13 07:27 . 2011-10-13 07:27 25088 ----a-w- c:\windows\system32\drivers\tunnel.sys2011-10-13 07:27 . 2011-10-13 07:27 200704 ----a-w- c:\windows\system32\iphlpsvc.dll2011-10-13 07:27 . 2011-10-13 07:27 15360 ----a-w- c:\windows\system32\drivers\TUNMP.SYS2011-11-09 16:37 . 2011-10-11 17:40 134104 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll..((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))..*Note* empty entries & legit default entries are not shown REGEDIT4.[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1]@="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}"[HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}]2011-10-31 21:02 94208 ----a-w- c:\users\Johnny Ola\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll.[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2]@="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}"[HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}]2011-10-31 21:02 94208 ----a-w- c:\users\Johnny Ola\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll.[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3]@="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}"[HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}]2011-10-31 21:02 94208 ----a-w- c:\users\Johnny Ola\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll.[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]"iCloudServices"="c:\program files\Common Files\Apple\Internet Services\iCloudServices.exe" [2011-11-11 59240]"ApplePhotoStreams"="c:\program files\Common Files\Apple\Internet Services\ApplePhotoStreams.exe" [2011-11-11 59240]"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2008-01-19 202240].[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]"RtHDVCpl"="RtHDVCpl.exe" [2007-04-06 4423680]"IgfxTray"="c:\windows\system32\igfxtray.exe" [2007-03-24 138008]"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2007-03-24 154392]"Persistence"="c:\windows\system32\igfxpers.exe" [2007-03-24 133912]"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2007-03-08 835584]"ISBMgr.exe"="c:\program files\Sony\ISB Utility\ISBMgr.exe" [2007-04-17 321656]"VAIOCameraUtility"="c:\program files\Sony\VAIO Camera Utility\VCUServe.exe" [2007-04-02 411768]"VAIO Center Access Bar"="c:\program files\sony\VAIO Center Access Bar\VCAB.exe" [2007-03-06 36864]"VAIOSecurity"="c:\program files\Sony\VAIO Security Center\VSC.exe" [2007-03-14 2322432]"VAIOSurvey"="c:\program files\Sony\VAIO Survey\Vista VAIO Survey.exe" [2006-12-07 577536]"AVG_TRAY"="c:\program files\AVG\AVG2012\avgtray.exe" [2011-12-03 2415456]"COMODO Internet Security"="c:\program files\COMODO\COMODO Internet Security\cfp.exe" [2011-12-21 6676808].c:\users\Johnny Ola\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk - c:\users\Johnny Ola\AppData\Roaming\Dropbox\bin\Dropbox.exe [2011-12-5 24242056].c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\Bluetooth Manager.lnk - c:\program files\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe [2007-2-3 2756608].[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]"EnableUIADesktopToggle"= 0 (0x0).[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2011-07-19 113024].[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]2011-05-04 17:54 551296 ----a-w- c:\program files\SUPERAntiSpyware\SASWINLO.DLL.[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\VESWinlogon]2007-04-24 00:19 98304 ----a-w- c:\windows\System32\VESWinlogon.dll.[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]"AppInit_DLLs"=c:\windows\System32\guard32.dll.[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]BootExecute REG_MULTI_SZ autocheck autochk *\0SsiEfr.exe\0c:\progra~1\AVG\AVG2012\avgrsx.exe /sync /restart.[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\!SASCORE]@="".[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]path=c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnkbackup=c:\windows\pss\Adobe Reader Speed Launch.lnk.CommonStartupbackupExtension=.CommonStartup.[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Adobe Reader Synchronizer.lnk]path=c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\Adobe Reader Synchronizer.lnkbackup=c:\windows\pss\Adobe Reader Synchronizer.lnk.CommonStartupbackupExtension=.CommonStartup.[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^QuickBooks Update Agent.lnk]path=c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\QuickBooks Update Agent.lnkbackup=c:\windows\pss\QuickBooks Update Agent.lnk.CommonStartupbackupExtension=.CommonStartup.[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Aim]2011-05-03 15:43 4321112 ----a-w- c:\program files\AIM\aim.exe.[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\APSDaemon]2011-11-02 04:25 59240 ----a-w- c:\program files\Common Files\Apple\Apple Application Support\APSDaemon.exe.[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\com.apple.dav.bookmarks.daemon]2011-11-16 02:52 59240 ----a-w- c:\program files\Common Files\Apple\Internet Services\BookmarkDAV_client.exe.[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Update]2011-10-11 20:04 136176 ----atw- c:\users\Johnny Ola\AppData\Local\Google\Update\GoogleUpdate.exe.[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]2011-12-08 06:36 421736 ----a-w- c:\program files\iTunes\iTunesHelper.exe.[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Malwarebytes' Anti-Malware (reboot)]2011-12-24 22:50 981680 ----a-w- c:\program files\Malwarebytes' Anti-Malware\mbam.exe.[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickBooks Simple Start]2007-01-31 05:59 371712 ----a-w- c:\program files\Intuit\SimpleStartEntice\entice.exe.[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RunSpySweeperScheduleAtStartup]2011-10-26 06:49 10752 ----a-w- c:\windows\System32\msfeedssync.exe.[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skytel]2007-04-06 18:18 1822720 ----a-w- c:\windows\SkyTel.exe.[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Windows Defender]2008-01-19 07:38 1008184 ----a-w- c:\program files\Windows Defender\MSASCui.exe.[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WindowsWelcomeCenter]2009-04-11 06:28 2153472 ----a-w- c:\windows\System32\oobefldr.dll.[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]"DisableMonitoring"=dword:00000001.[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]"DisableMonitoring"=dword:00000001.[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]"DisableMonitoring"=dword:00000001.R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]R2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [2011-10-11 136176]R3 DIRECTIO;DIRECTIO;T:\DirectIo.sys R3 gupdatem;Google Update Service (gupdatem);c:\program files\Google\Update\GoogleUpdate.exe [2011-10-11 136176]R3 ICScsiSV;Image Converter SCSI Service;c:\program files\Sony\Image Converter 3\ICScsiSV.exe [2007-01-26 75952]R3 IcVzMonLauncher;IcVzMonLauncher;c:\program files\Sony\Image Converter 3\IcVzMonLauncher.exe [2007-01-26 67760]R3 VAIOMediaPlatform-UCLS-AppServer;VAIO Media Content Collection;c:\program files\Sony\VAIO Media Integrated Server\UCLS.exe [2007-01-11 745472]R3 VAIOMediaPlatform-UCLS-HTTP;VAIO Media Content Collection (HTTP);c:\program files\Sony\VAIO Media Integrated Server\Platform\SV_Httpd.exe [2007-01-09 397312]R3 VAIOMediaPlatform-UCLS-UPnP;VAIO Media Content Collection (UPnP);c:\program files\Sony\VAIO Media Integrated Server\Platform\UPnPFramework.exe [2007-01-16 1089536]R3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [2010-03-18 753504]S0 AVGIDSEH;AVGIDSEH;c:\windows\system32\DRIVERS\AVGIDSEH.Sys [2011-07-11 23120]S0 Avgrkx86;AVG Anti-Rootkit Driver;c:\windows\system32\DRIVERS\avgrkx86.sys [2011-09-13 32592]S1 Avgldx86;AVG AVI Loader Driver;c:\windows\system32\DRIVERS\avgldx86.sys [2011-10-07 230608]S1 Avgtdix;AVG TDI Driver;c:\windows\system32\DRIVERS\avgtdix.sys [2011-07-11 295248]S1 cmdGuard;COMODO Internet Security Sandbox Driver;c:\windows\system32\DRIVERS\cmdguard.sys [2011-12-19 491816]S1 cmdHlp;COMODO Internet Security Helper Driver;c:\windows\system32\DRIVERS\cmdhlp.sys [2011-12-19 38616]S1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\SASDIFSV.SYS [2011-07-22 12880]S1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [2011-07-12 67664]S2 !SASCORE;SAS Core Service;c:\program files\SUPERAntiSpyware\SASCORE.EXE [2011-08-11 116608]S2 AVGIDSAgent;AVGIDSAgent;c:\program files\AVG\AVG2012\AVGIDSAgent.exe [2011-10-12 4433248]S2 avgwd;AVG WatchDog;c:\program files\AVG\AVG2012\avgwdsvc.exe [2011-08-02 192776]S2 MSSQL$VAIO_VEDB;SQL Server (VAIO_VEDB);c:\program files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe [2010-12-10 29293408]S2 regi;regi;c:\windows\system32\drivers\regi.sys [2007-01-03 11032]S3 AVGIDSDriver;AVGIDSDriver;c:\windows\system32\DRIVERS\AVGIDSDriver.Sys [2011-07-11 134736]S3 AVGIDSFilter;AVGIDSFilter;c:\windows\system32\DRIVERS\AVGIDSFilter.Sys [2011-07-11 24272]S3 AVGIDSShim;AVGIDSShim;c:\windows\system32\DRIVERS\AVGIDSShim.Sys [2011-10-04 16720]S3 R5U870FLx86;R5U870 UVC Lower Filter ;c:\windows\system32\Drivers\R5U870FLx86.sys [2007-04-04 73472]S3 R5U870FUx86;R5U870 UVC Upper Filter ;c:\windows\system32\Drivers\R5U870FUx86.sys [2007-04-04 43904]S3 SonyImgF;Sony Image Conversion Filter Driver;c:\windows\system32\DRIVERS\SonyImgF.sys [2007-04-05 31104]S3 ti21sony;ti21sony;c:\windows\system32\drivers\ti21sony.sys [2007-02-08 807424]..[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache.Contents of the 'Scheduled Tasks' folder.2011-12-29 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job- c:\program files\Google\Update\GoogleUpdate.exe [2011-10-11 19:59].2011-12-29 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job- c:\program files\Google\Update\GoogleUpdate.exe [2011-10-11 19:59].2011-12-29 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-463125951-12254502-3284758742-1005Core.job- c:\users\Johnny Ola\AppData\Local\Google\Update\GoogleUpdate.exe [2011-10-11 20:04].2011-12-29 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-463125951-12254502-3284758742-1005UA.job- c:\users\Johnny Ola\AppData\Local\Google\Update\GoogleUpdate.exe [2011-10-11 20:04]..------- Supplementary Scan -------.uStart Page = hxxp://search.conduit.com?SearchSource=10&ctid=CT2818425uInternet Settings,ProxyOverride = *.localIE: E&xport to Microsoft Excel - c:\progra~1\MICROS~4\Office12\EXCEL.EXE/3000TCP: DhcpNameServer = 68.105.28.12 68.105.29.12 68.105.28.11TCP: Interfaces\{20DA44BE-98A1-475D-B8AC-88DF3AD26CDD}: NameServer = 8.26.56.26,156.154.70.22TCP: Interfaces\{D83D5627-FB49-437C-B3E7-C61C85550B27}: NameServer = 8.26.56.26,156.154.70.22FF - ProfilePath - c:\users\Johnny Ola\AppData\Roaming\Mozilla\Firefox\Profiles\3yu3mje6.default\FF - prefs.js: browser.search.defaulturl - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2818425&SearchSource=3&q={searchTerms}FF - prefs.js: browser.startup.homepage - hxxps://www.google.com/FF - user.js: network.protocol-handler.warn-external.dnupdate - false.- - - - ORPHANS REMOVED - - - -.URLSearchHooks-{7aeb3efd-e564-43f1-b658-5058a7c5743b} - (no file)HKLM-Run-SunJavaUpdateSched - c:\program files\Java\jre6\bin\jusched.exeMSConfigStartUp-COMODO - c:\program files\COMODO\COMODO GeekBuddy\CLPSLA.exeMSConfigStartUp-CPA - c:\program files\COMODO\COMODO GeekBuddy\VALA.exeMSConfigStartUp-NapsterShell - c:\program files\Napster\napster.exe...**************************************************************************.catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.netRootkit scan 2011-12-29 15:21Windows 6.0.6002 Service Pack 2 NTFS.detected NTDLL code modification:ZwClose.scanning hidden processes ... .scanning hidden autostart entries ... .scanning hidden files ... .scan completed successfullyhidden files: 0.**************************************************************************.--------------------- LOCKED REGISTRY KEYS ---------------------.[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]@Denied: (A) (Users)@Denied: (A) (Everyone)@Allowed: (B 1 2 3 4 5) (S-1-5-20)"BlindDial"=dword:00000000.--------------------- DLLs Loaded Under Running Processes ---------------------.- - - - - - - > 'winlogon.exe'(1112)c:\windows\system32\guard32.dll.- - - - - - - > 'lsass.exe'(1060)c:\windows\system32\guard32.dll.Completion time: 2011-12-29 15:26:46ComboFix-quarantined-files.txt 2011-12-29 20:26.Pre-Run: 208,664,760,320 bytes freePost-Run: 207,876,616,192 bytes free.- - End Of File - - 5F749A562566151542C7F28A2F0CEFC5
I have heard more grinding
Java RA-OTL-Combo fix?
SysProt AntiRootkit v1.0.1.0by swatkat************************************************************************************************************************************************************************************No Hidden Processes found************************************************************************************************************************************************************************************Kernel Modules:Module Name: \SystemRoot\System32\Drivers\dump_dumpata.sysService Name: ---Module Base: 8C9F0000Module End: 8C9FB000Hidden: YesModule Name: \SystemRoot\System32\Drivers\dump_atapi.sysService Name: ---Module Base: 8E3F8000Module End: 8E400000Hidden: Yes************************************************************************************************************************************************************************************SSDT:Function Name: ZwAdjustPrivilegesTokenAddress: 8E6E0F60Driver Base: 8E6D3000Driver End: 8E74E000Driver Name: \SystemRoot\System32\DRIVERS\cmdguard.sysFunction Name: ZwAlpcConnectPortAddress: 8E6E114CDriver Base: 8E6D3000Driver End: 8E74E000Driver Name: \SystemRoot\System32\DRIVERS\cmdguard.sysFunction Name: ZwConnectPortAddress: 8E6E02C0Driver Base: 8E6D3000Driver End: 8E74E000Driver Name: \SystemRoot\System32\DRIVERS\cmdguard.sysFunction Name: ZwCreateFileAddress: 8E6E0BC6Driver Base: 8E6D3000Driver End: 8E74E000Driver Name: \SystemRoot\System32\DRIVERS\cmdguard.sysFunction Name: ZwCreateSectionAddress: 8E6E097ADriver Base: 8E6D3000Driver End: 8E74E000Driver Name: \SystemRoot\System32\DRIVERS\cmdguard.sysFunction Name: ZwCreateSymbolicLinkObjectAddress: 8E6E1CC4Driver Base: 8E6D3000Driver End: 8E74E000Driver Name: \SystemRoot\System32\DRIVERS\cmdguard.sysFunction Name: ZwCreateThreadAddress: 8E6DFCACDriver Base: 8E6D3000Driver End: 8E74E000Driver Name: \SystemRoot\System32\DRIVERS\cmdguard.sysFunction Name: ZwLoadDriverAddress: 8E6E16F6Driver Base: 8E6D3000Driver End: 8E74E000Driver Name: \SystemRoot\System32\DRIVERS\cmdguard.sysFunction Name: ZwMakeTemporaryObjectAddress: 8E6E0588Driver Base: 8E6D3000Driver End: 8E74E000Driver Name: \SystemRoot\System32\DRIVERS\cmdguard.sysFunction Name: ZwOpenFileAddress: 8E6E0DA2Driver Base: 8E6D3000Driver End: 8E74E000Driver Name: \SystemRoot\System32\DRIVERS\cmdguard.sysFunction Name: ZwOpenProcessAddress: AC925F3CDriver Base: AC925000Driver End: AC928000Driver Name: \SystemRoot\system32\DRIVERS\AVGIDSShim.SysFunction Name: ZwOpenSectionAddress: 8E6E0822Driver Base: 8E6D3000Driver End: 8E74E000Driver Name: \SystemRoot\System32\DRIVERS\cmdguard.sysFunction Name: ZwSetSystemInformationAddress: 8E6E19E2Driver Base: 8E6D3000Driver End: 8E74E000Driver Name: \SystemRoot\System32\DRIVERS\cmdguard.sysFunction Name: ZwShutdownSystemAddress: 8E6E04F2Driver Base: 8E6D3000Driver End: 8E74E000Driver Name: \SystemRoot\System32\DRIVERS\cmdguard.sysFunction Name: ZwSystemDebugControlAddress: 8E6E070EDriver Base: 8E6D3000Driver End: 8E74E000Driver Name: \SystemRoot\System32\DRIVERS\cmdguard.sysFunction Name: ZwTerminateProcessAddress: AC925FE4Driver Base: AC925000Driver End: AC928000Driver Name: \SystemRoot\system32\DRIVERS\AVGIDSShim.SysFunction Name: ZwTerminateThreadAddress: AC926080Driver Base: AC925000Driver End: AC928000Driver Name: \SystemRoot\system32\DRIVERS\AVGIDSShim.SysFunction Name: ZwWriteVirtualMemoryAddress: AC92611CDriver Base: AC925000Driver End: AC928000Driver Name: \SystemRoot\system32\DRIVERS\AVGIDSShim.SysFunction Name: ZwCreateThreadExAddress: 8E6E137ADriver Base: 8E6D3000Driver End: 8E74E000Driver Name: \SystemRoot\System32\DRIVERS\cmdguard.sys************************************************************************************************************************************************************************************No Kernel Hooks found************************************************************************************************************************************************************************************Hidden files/folders:Object: C:\Qoobox\BackEnv\AppData.folder.datStatus: Access deniedObject: C:\Qoobox\BackEnv\Cache.folder.datStatus: Access deniedObject: C:\Qoobox\BackEnv\Cookies.folder.datStatus: Access deniedObject: C:\Qoobox\BackEnv\Desktop.folder.datStatus: Access deniedObject: C:\Qoobox\BackEnv\Favorites.folder.datStatus: Access deniedObject: C:\Qoobox\BackEnv\History.folder.datStatus: Access deniedObject: C:\Qoobox\BackEnv\LocalAppData.folder.datStatus: Access deniedObject: C:\Qoobox\BackEnv\LocalSettings.folder.datStatus: Access deniedObject: C:\Qoobox\BackEnv\Music.folder.datStatus: Access deniedObject: C:\Qoobox\BackEnv\NetHood.folder.datStatus: Access deniedObject: C:\Qoobox\BackEnv\Personal.folder.datStatus: Access deniedObject: C:\Qoobox\BackEnv\Pictures.folder.datStatus: Access deniedObject: C:\Qoobox\BackEnv\PrintHood.folder.datStatus: Access deniedObject: C:\Qoobox\BackEnv\Profiles.Folder.datStatus: Access deniedObject: C:\Qoobox\BackEnv\Profiles.Folder.folder.datStatus: Access deniedObject: C:\Qoobox\BackEnv\Programs.folder.datStatus: Access deniedObject: C:\Qoobox\BackEnv\Recent.folder.datStatus: Access deniedObject: C:\Qoobox\BackEnv\SendTo.folder.datStatus: Access deniedObject: C:\Qoobox\BackEnv\SetPath.batStatus: Access deniedObject: C:\Qoobox\BackEnv\StartMenu.folder.datStatus: Access deniedObject: C:\Qoobox\BackEnv\StartUp.folder.datStatus: Access deniedObject: C:\Qoobox\BackEnv\SysPath.datStatus: Access deniedObject: C:\Qoobox\BackEnv\Templates.folder.datStatus: Access deniedObject: C:\Qoobox\BackEnv\VikPev00Status: Access deniedObject: C:\Windows\System32\LogFiles\WMI\RtBackup\EtwRTDiagLog.etlStatus: Access deniedObject: C:\Windows\System32\LogFiles\WMI\RtBackup\EtwRTEventLog-Application.etlStatus: Access deniedObject: C:\Windows\System32\LogFiles\WMI\RtBackup\EtwRTEventlog-Security.etlStatus: Access deniedObject: C:\Windows\System32\LogFiles\WMI\RtBackup\EtwRTEventLog-System.etlStatus: Access denied
Pretty good, it got better last Friday.Can we call it clear, or is there another scan, any, we can do, just to be sure?
Is my PC safe, and clear?
Do I really need TFC, or can I just use CC Cleaner.
Is it alarming that it did not work?