:OTL DRV - File not found [Kernel | On_Demand | Stopped] -- C:\Windows\system32\drivers\NIS\1000000.07D\SYMREDRV.SYS -- (SYMREDRV) DRV - File not found [Kernel | On_Demand | Stopped] -- C:\Windows\System32\Drivers\NIS\1008030.006\SYMNDISV.SYS -- (SYMNDISV) DRV - File not found [Kernel | On_Demand | Stopped] -- C:\Windows\System32\Drivers\NIS\1008030.006\SYMFW.SYS -- (SYMFW) DRV - File not found [Kernel | On_Demand | Stopped] -- C:\Windows\system32\drivers\NIS\1000000.07D\SYMDNS.SYS -- (SYMDNS) DRV - File not found [Kernel | On_Demand | Stopped] -- C:\PROGRA~1\DELLSU~1\HWDiag\bin\PCD5SRVC.pkms -- (PCD5SRVC{3F6A8B78-EC003E00-05040104}) DRV - File not found [Kernel | On_Demand | Unknown] -- C:\Users\HARRY~1.OUR\AppData\Local\Temp\mbr.sys -- (mbr) DRV - File not found [Kernel | On_Demand | Stopped] -- C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilDrv11122.sys -- (EraserUtilDrv11122) DRV - File not found [Kernel | On_Demand | Running] -- C:\ComboFix\catchme.sys -- (catchme) IE - HKU\S-1-5-21-807304935-213565314-3564997923-1001\..\URLSearchHook: {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - No CLSID value found IE - HKU\S-1-5-21-807304935-213565314-3564997923-1001\..\SearchScopes\{56256A51-B582-467e-B8D4-7786EDA79AE0}: "URL" = http://search.mywebsearch.com/mywebsearch/GGmain.jhtml?id=ZUxdm080YYUS&ptnrS=ZUxdm080YYUS&ptb=3x7p7KZAvvYKKKC1CD.eLw&ind=2010111217&n=77cfdcf1&psa=&st=sb&searchfor={searchTerms} IE - HKU\S-1-5-21-807304935-213565314-3564997923-1002\..\URLSearchHook: - No CLSID value found IE - HKU\S-1-5-21-807304935-213565314-3564997923-1002\..\URLSearchHook: {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - No CLSID value found IE - HKU\S-1-5-21-807304935-213565314-3564997923-1002\..\SearchScopes\{1CB20BF0-BBAE-40A7-93F4-6435FF3D0411}: "URL" = http://www.crawler.com/search/dispatcher.aspx?tp=bs&qkw={searchTerms}&tbid=60552 FF - HKLM\Software\MozillaPlugins\@mcafee.com/SAFFPlugin: C:\Program Files\McAfee\SiteAdvisor\npmcffplg32.dll File not found FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{4ED1F68A-5463-4931-9384-8FFF5ED91D92}: C:\Program Files\McAfee\SiteAdvisor [2011/12/26 02:12:41 | 000,000,000 | ---D | M] (Wincore Mediabar) -- C:\Users\Harry.OurPC\AppData\Roaming\mozilla\Firefox\Profiles\yf39y4a2.default\extensions\{c2d64ff7-0ab8-4263-89c9-ea3b0f8f050c} [2010/12/14 23:22:14 | 000,010,124 | ---- | M] () -- C:\Users\Harry.OurPC\AppData\Roaming\Mozilla\Firefox\Profiles\yf39y4a2.default\searchplugins\mywebsearch.xml [2010/01/01 01:00:00 | 000,002,252 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\bing.xml.old [2007/07/26 14:05:16 | 000,001,329 | -H-- | M] () -- C:\Program Files\mozilla firefox\searchplugins\crawlersrch.xml [2011/12/29 17:44:01 | 000,002,024 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\McSiteAdvisor.xml O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - No CLSID value found. O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found. O2 - BHO: (no name) - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - No CLSID value found. O3 - HKU\.DEFAULT\..\Toolbar\WebBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No CLSID value found. O3 - HKU\S-1-5-18\..\Toolbar\WebBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No CLSID value found. O3 - HKU\S-1-5-21-807304935-213565314-3564997923-1001\..\Toolbar\WebBrowser: (no name) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No CLSID value found. O3 - HKU\S-1-5-21-807304935-213565314-3564997923-1001\..\Toolbar\WebBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No CLSID value found. O3 - HKU\S-1-5-21-807304935-213565314-3564997923-1001\..\Toolbar\WebBrowser: (no name) - {5BED3930-2E9E-76D8-BACC-80DF2188D455} - No CLSID value found. O3 - HKU\S-1-5-21-807304935-213565314-3564997923-1001\..\Toolbar\WebBrowser: (no name) - {604BC32A-9680-40D1-9AC6-E06B23A1BA4C} - No CLSID value found. O3 - HKU\S-1-5-21-807304935-213565314-3564997923-1001\..\Toolbar\WebBrowser: (no name) - {9D425283-D487-4337-BAB6-AB8354A81457} - No CLSID value found. O3 - HKU\S-1-5-21-807304935-213565314-3564997923-1001\..\Toolbar\WebBrowser: (no name) - {D4027C7F-154A-4066-A1AD-4243D8127440} - No CLSID value found. O3 - HKU\S-1-5-21-807304935-213565314-3564997923-1002\..\Toolbar\WebBrowser: (no name) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No CLSID value found. O3 - HKU\S-1-5-21-807304935-213565314-3564997923-1002\..\Toolbar\WebBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No CLSID value found. O3 - HKU\S-1-5-21-807304935-213565314-3564997923-1002\..\Toolbar\WebBrowser: (no name) - {D7E97865-918F-41E4-9CD0-25AB1C574CE8} - No CLSID value found. O4 - HKLM..\RunOnce: [DSUpdateLauncher] C:\Program Files\Dell DataSafe Local Backup\Components\DSUpdate\runhstart.bat () O4 - Startup: C:\Users\Guest\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\MRI_DISABLED [2012/02/27 12:29:40 | 000,000,000 | -H-D | M] O4 - Startup: C:\Users\LogMeInRemoteUser\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\MRI_DISABLED [2012/02/27 12:29:25 | 000,000,000 | -H-D | M] O4 - Startup: C:\Users\Zachia\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\MRI_DISABLED [2012/02/27 12:29:21 | 000,000,000 | -H-D | M] O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} http://download.eset.com/special/eos/OnlineScanner.cab (OnlineScanner Control) O18 - Protocol\Handler\dssrequest - No CLSID value found O18 - Protocol\Handler\sacore - No CLSID value found [2012/05/06 01:01:18 | 000,000,000 | ---D | C] -- C:\ComboFix [2012/05/04 21:27:13 | 000,000,000 | ---D | C] -- C:\Users\Harry.OurPC\Desktop\Trouncer Anti-Virus Stuff [2012/05/04 20:30:59 | 000,518,144 | ---- | C] (SteelWerX) -- C:\Windows\SWREG.exe [2012/05/04 20:30:59 | 000,406,528 | ---- | C] (SteelWerX) -- C:\Windows\SWSC.exe [2012/05/04 20:30:59 | 000,060,416 | ---- | C] (NirSoft) -- C:\Windows\NIRCMD.exe [2012/05/04 20:30:41 | 000,000,000 | ---D | C] -- C:\Qoobox [2012/05/03 21:56:21 | 000,000,000 | ---D | C] -- C:\Program Files\ESET [2012/05/01 15:41:30 | 000,000,000 | ---D | C] -- C:\NPE [2012/04/28 12:02:10 | 000,000,000 | ---D | C] -- C:\Users\Harry.OurPC\AppData\Local\NPE [1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ] [2012/05/03 21:40:08 | 000,000,512 | ---- | M] () -- C:\Users\Harry.OurPC\Documents\MBR.dat [2012/05/02 23:39:57 | 000,000,554 | ---- | M] () -- C:\Users\Harry.OurPC\Desktop\Register.com.website [2012/05/04 20:30:59 | 000,256,000 | ---- | C] () -- C:\Windows\PEV.exe [2012/05/04 20:30:59 | 000,208,896 | ---- | C] () -- C:\Windows\MBR.exe [2012/05/04 20:30:59 | 000,098,816 | ---- | C] () -- C:\Windows\sed.exe [2012/05/04 20:30:59 | 000,080,412 | ---- | C] () -- C:\Windows\grep.exe [2012/05/04 20:30:59 | 000,068,096 | ---- | C] () -- C:\Windows\zip.exe [2012/05/03 21:40:08 | 000,000,512 | ---- | C] () -- C:\Users\Harry.OurPC\Documents\MBR.dat @Alternate Data Stream - 118 bytes -> C:\ProgramData\TEMP:0A8E2C33 :Files :Commands [purity] [emptytemp] [EMPTYFLASH] [emptyjava] [RESETHOSTS] [CLEARALLRESTOREPOINTS] [Reboot]