This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Help request: Search Engines have been hijacked

6 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hello, this is the first time I've contacted a forum like this for help. I downloaded the "Hijack This" program and ran it. The logfile is posted below. I would appreciate any help locating the source of a particularly stubborn infection. I run AVG, Super Anti-Spyware, SpyBot.

The Problem: any time I use an internet search engine (google, yahoo, etc) in either IE or Firefox, my search results in a legitimate page of links, per usual, but when I click on a link the browser doesn't take me to that link. Instead, it redirects me to a nasty porn site or obnoxious gaming site. I was able to download a newer version of FireFox to try and get around the malware, but the internet search functions seem to be disabled.

I'm very frustrated because I just paid to have my computer 'cleaned' last week, and this problem started just after the clean. I contacted the service, thinking they might have overlooked something and they said it was my problem (!) BTW, this has never happened before. I don't do much browsing but when I do it is for research or find info, not entertainment. Any help you can offer would be great.

When Hijack This ran, it indicated that HJT found some host files that were 'write protected'? (sorry didn't copy down exact language). HJT instructed me to RUN:
notepad C:\WINDOWS\System32\drivers\etc\hosts "Find the line(s) that Hijack This reports and delete them. Save the file as 'hosts' and reboot."
This is the 'hosts' file:

89.149.227.223 google.ae
[removed] google.as
[removed] google.at
[removed] google.az
[removed] google.ba
[removed] google.be
[removed] google.bg
[removed] google.bs
[removed] google.ca
[removed] google.cd
[removed] google.com.gh
[removed] google.com.gi
[removed] google.com.hk
[removed] google.com.jm
[removed] google.com.ly
[removed] google.com.mx
[removed] google.com.my
[removed] google.com.na
[removed] google.com.nf
[removed] google.com.ng
[removed] google.ch
[removed] google.com.np
[removed] google.com.om
[removed] google.com.pa
[removed] google.com.pr
[removed] google.com.qa
[removed] google.com.sg
[removed] google.com.tj
[removed] google.com.tr
[removed] google.com.tw
[removed] google.com.ua
[removed] google.dj
[removed] google.com.vc
[removed] google.it.ao
[removed] google.de
[removed] google.dk
[removed] google.dm
[removed] google.dz
[removed] google.ee
[removed] google.fi
[removed] google.fm
[removed] google.fr
[removed] google.ge
[removed] google.gg
[removed] google.gm
[removed] google.gr
[removed] google.gy
[removed] google.ht
[removed] google.ie
[removed] google.im
[removed] google.in
[removed] google.it
[removed] google.ki
[removed] google.kz
[removed] google.la
[removed] google.li
[removed] google.lk
[removed] google.lv
[removed] google.ma
[removed] google.md
[removed] google.ms
[removed] google.mu
[removed] google.mv
[removed] google.mw
[removed] google.nl
[removed] google.no
[removed] google.nr
[removed] google.nu
[removed] google.pl
[removed] google.pn
[removed] google.pt
[removed] google.ro
[removed] google.ru
[removed] google.rw
[removed] google.sc
[removed] google.se
[removed] google.sh
[removed] google.si
[removed] google.sm
[removed] google.sn
[removed] google.st
[removed] google.tl
[removed] google.tm
[removed] google.tt
[removed] google.us
[removed] google.vg
[removed] google.vu
[removed] google.ws
[removed] google.co.bw
[removed] google.co.ck
[removed] google.co.id
[removed] google.co.il
[removed] google.co.in
[removed] google.co.jp
[removed] google.co.ke
[removed] google.co.kr
[removed] google.co.ls
[removed] google.co.ma
[removed] google.co.mz
[removed] google.co.nz
[removed] google.co.th
[removed] google.co.tz
[removed] google.co.ug
[removed] google.co.uk
[removed] google.co.za
[removed] google.co.zm
[removed] google.co.zw
[removed] google.com
[removed] google.com.af
[removed] google.com.ag
[removed] google.com.ai
[removed] google.com.ar
[removed] google.com.au
[removed] google.com.bn
[removed] google.com.br
[removed] google.com.by
[removed] google.com.bz
[removed] google.com.co
[removed] google.com.cu
89.149.227.223 google.com.ec
89.149.227.223 google.com.et
89.149.227.223 google.com.fj
89.149.227.223 www.google.ae
89.149.227.223 www.google.as
89.149.227.223 www.google.at
89.149.227.223 www.google.az
89.149.227.223 www.google.ba
89.149.227.223 www.google.be
89.149.227.223 www.google.bg
89.149.227.223 www.google.bs
89.149.227.223 www.google.ca
89.149.227.223 www.google.cd
89.149.227.223 www.google.com.gh
89.149.227.223 www.google.com.gi
89.149.227.223 www.google.com.hk
89.149.227.223 www.google.com.jm
89.149.227.223 www.google.com.ly
89.149.227.223 www.google.com.mx
89.149.227.223 www.google.com.my
89.149.227.223 www.google.com.na
89.149.227.223 www.google.com.nf
89.149.227.223 www.google.com.ng
89.149.227.223 www.google.ch
89.149.227.223 www.google.com.np
89.149.227.223 www.google.com.om
89.149.227.223 www.google.com.pa
89.149.227.223 www.google.com.pr
89.149.227.223 www.google.com.qa
89.149.227.223 www.google.com.sg
89.149.227.223 www.google.com.tj
89.149.227.223 www.google.com.tr
89.149.227.223 www.google.com.tw
89.149.227.223 www.google.com.ua
89.149.227.223 www.google.dj
89.149.227.223 www.google.com.vc
89.149.227.223 www.google.it.ao
89.149.227.223 www.google.de
89.149.227.223 www.google.dk
89.149.227.223 www.google.dm
89.149.227.223 www.google.dz
89.149.227.223 www.google.ee
89.149.227.223 www.google.fi
89.149.227.223 www.google.fm
89.149.227.223 www.google.fr
89.149.227.223 www.google.ge
89.149.227.223 www.google.gg
89.149.227.223 www.google.gm
89.149.227.223 www.google.gr
89.149.227.223 www.google.gy
89.149.227.223 www.google.ht
89.149.227.223 www.google.ie
89.149.227.223 www.google.im
89.149.227.223 www.google.in
89.149.227.223 www.google.it
89.149.227.223 www.google.ki
89.149.227.223 www.google.kz
89.149.227.223 www.google.la
89.149.227.223 www.google.li
89.149.227.223 www.google.lk
89.149.227.223 www.google.lv
89.149.227.223 www.google.ma
89.149.227.223 www.google.md
89.149.227.223 www.google.ms
89.149.227.223 www.google.mu
89.149.227.223 www.google.mv
89.149.227.223 www.google.mw
89.149.227.223 www.google.nl
89.149.227.223 www.google.no
89.149.227.223 www.google.nr
89.149.227.223 www.google.nu
89.149.227.223 www.google.pl
89.149.227.223 www.google.pn
89.149.227.223 www.google.pt
89.149.227.223 www.google.ro
89.149.227.223 www.google.ru
89.149.227.223 www.google.rw
89.149.227.223 www.google.sc
89.149.227.223 www.google.se
89.149.227.223 www.google.sh
89.149.227.223 www.google.si
89.149.227.223 www.google.sm
89.149.227.223 www.google.sn
89.149.227.223 www.google.st
89.149.227.223 www.google.tl
89.149.227.223 www.google.tm
89.149.227.223 www.google.tt
89.149.227.223 www.google.us
89.149.227.223 www.google.vg
89.149.227.223 www.google.vu
89.149.227.223 www.google.ws
89.149.227.223 www.google.co.bw
89.149.227.223 www.google.co.ck
89.149.227.223 www.google.co.id
89.149.227.223 www.google.co.il
89.149.227.223 www.google.co.in
89.149.227.223 www.google.co.jp
89.149.227.223 www.google.co.ke
89.149.227.223 www.google.co.kr
89.149.227.223 www.google.co.ls
89.149.227.223 www.google.co.ma
89.149.227.223 www.google.co.mz
89.149.227.223 www.google.co.nz
89.149.227.223 www.google.co.th
89.149.227.223 www.google.co.tz
89.149.227.223 www.google.co.ug
89.149.227.223 www.google.co.uk
89.149.227.223 www.google.co.za
89.149.227.223 www.google.co.zm
89.149.227.223 www.google.co.zw
89.149.227.223 www.google.com
89.149.227.223 www.google.com.af
89.149.227.223 www.google.com.ag
89.149.227.223 www.google.com.ai
89.149.227.223 www.google.com.ar
89.149.227.223 www.google.com.au
89.149.227.223 www.google.com.bn
89.149.227.223 www.google.com.br
89.149.227.223 www.google.com.by
89.149.227.223 www.google.com.bz
89.149.227.223 www.google.com.co
89.149.227.223 www.google.com.cu
89.149.227.223 www.google.com.ec
89.149.227.223 www.google.com.et
89.149.227.223 www.google.com.fj
89.149.227.223 search.yahoo.com
89.149.227.223 www.search.yahoo.com
89.149.227.223 search.live.com
89.149.227.223 search.msn.com
# Copyright © 1993-1999 Microsoft Corp.
#
# This is a sample HOSTS file used by Microsoft TCP/IP for Windows.
#
# This file contains the mappings of IP addresses to host names. Each
# entry should be kept on an individual line. The IP address should
# be placed in the first column followed by the corresponding host name.
# The IP address and the host name should be separated by at least one
# space.
#
# Additionally, comments (such as these) may be inserted on individual
# lines or following the machine name denoted by a '#' symbol.
#
# For example:
#
# 102.54.94.97 rhino.acme.com # source server
# 38.25.63.10 x.acme.com # x client host

127.0.0.1 localhost

—————————————————————————————————————————————————————————-

Anyway, listed below is the logfile from the Hijack This program run about an hour ago:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 4:11:30 AM, on 3/12/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16791)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\AVG\AVG8\avgtray.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Program Files\APC\APC PowerChute Personal Edition\mainserv.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Intel\ASF Agent\ASFAgent.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\PROGRA~1\AVG\AVG8\avgnsx.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Mozilla Firefox\firefox.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Windows Internet Explorer provided by Yahoo!
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: AcroIEToolbarHelper Class - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\shdocvw.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\shdocvw.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O16 - DPF: {01113300-3E00-11D2-8470-0060089874ED} (Support.com Configuration Class) - http://supportcenter.rr.com/sdccommon/download/tgctlcm.cab
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5) - http://upload.facebook.com/controls/Facebo…toUploader5.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1174499935843
O16 - DPF: {AB86CE53-AC9F-449F-9399-D8ABCA09EC09} (Get_ActiveX Control) - https://h17000.www1.hp.com/ewfrf-JAVA/Secur…loadManager.ocx
O16 - DPF: {B1E2B96C-12FE-45E2-BEF1-44A219113CDD} (SABScanProcesses Class) - http://www.superadblocker.com/activex/sabspx.cab
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL
O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll
O23 - Service: APC UPS Service - American Power Conversion Corporation - C:\Program Files\APC\APC PowerChute Personal Edition\mainserv.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: ASF Agent (ASFAgent) - Intel Corporation - C:\Program Files\Intel\ASF Agent\ASFAgent.exe
O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: pcAnywhere Host Service (awhost32) - Symantec Corporation - C:\Program Files\Symantec\pcAnywhere\awhost32.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe
O23 - Service: Intuit QuickBooks FCS (QBFCService) - Intuit Inc. - C:\Program Files\Common Files\Intuit\QuickBooks\FCS\Intuit.QuickBooks.FCS.exe
O23 - Service: SupportSoft RemoteAssist - SupportSoft, Inc. - C:\Program Files\Common Files\supportsoft\bin\ssrc.exe

–
End of file - 5897 bytes
Hello jamm and welcome to the forums here at WTT!

:welcome:

First let's reset your Hosts file.

Download the HostsXpert 4.3 - Hosts File Manager.
  • Unzip HostsXpert 4.3 - Hosts File Manager to a convenient folder such as C:\HostsXpert 4.3 - Hosts File Manager
  • Run HostsXpert 4.3 - Hosts File Manager from its new home
  • Click on "File Handling".
  • Click on "Restore MS Hosts File".
  • Click OK on the Confirmation box.
  • Click on "Make Read Only?"
  • Click the X to exit the program.
  • Note: If you were using a custom Hosts file you will need to replace any of those entries yourself.

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

We'll also do a couple of more thorough scans.

  • Download OTListIt2 to your desktop.
  • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output.
  • Check the boxes beside LOP Check and Purity Check.
  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
  • When the scan completes, it will open two notepad windows. OTListIt.Txt and Extras.Txt. These are saved in the same location as OTListIt2.
  • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post it with your next reply. You may need two posts to fit them all in.

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

Download Rooter.exe to your desktop
  • Then doubleclick it to start the tool
  • A Notepad file containing the report will open, also found at %systemdrive%\Rooter.txt (Where %systemdrive% is usually C: or the drive that you have installed Windows). Post that in your next reply.
Please post back with
  • Rooter log
  • OTListIt2 log
Hi IndiGenus, thanks for responding. Just downloaded, unzipped & ran HostsXpert 4.3. (message: "Your HOSTS file is marked as a "system file" and can NOT be manipulated. Press OK to remove this system file attribute" - pressed 'OK') (2nd message: "Your HOSTS file is marked as a "Hidden file" and can NOT be manipulated. Press OK to remove this hidden file attribute" - pressed 'OK') clicked on "Restore MS Hosts File" and got ERROR message: "ERROR: Cannot create file C:\WINDOWS\system32\DRIVERS\ETC\hosts" Response box: OK (no other option) Should I click OK? ~ JAMM
clicking on "Make Writeable?" doesn't change anything… The icon stays in "locked" position. seems disabled :(
Maybe locked by Spybot. Let's check…. Open Spybot, Click Mode > Advanced Mode > Tools > IE Tweaks. Under "Miscellaneous locks" uncheck the following: * Lock Hosts file read-only as protection against hijackers. See if you can reset it now.
Ok, unchecked box as you directed. Ran HostsXpert.exe again. This time the button "Make Writeable?" was not locked, but clicking on "Restore MS Hosts file" still results in ERROR: Cannot create file: C:\WINDOWS\system32\DRIVERS\ETC\hosts
Rooter Log: ————————————————————————————————————– Microsoft Windows XP Professional (5.1.2600) Service Pack 3 A:\ [Removable] (Total:0 Mo/Free:0 Mo) C:\ [Fixed] - NTFS - (Total:38099 Mo/Free:2336 Mo) D:\ [CD-Rom] (Total:0 Mo/Free:0 Mo) E:\ [CD-Rom] (Total:0 Mo/Free:0 Mo) F:\ [Removable] (Total:123 Mo/Free:85 Mo) Thu 03/12/2009|22:20 ———————-\\ Processes.. –Locked– [System Process] ———- System ———- \SystemRoot\System32\smss.exe ———- \??\C:\WINDOWS\system32\csrss.exe ———- \??\C:\WINDOWS\system32\winlogon.exe ———- C:\WINDOWS\system32\services.exe ———- C:\WINDOWS\system32\lsass.exe ———- C:\WINDOWS\system32\svchost.exe ———- C:\WINDOWS\system32\svchost.exe ———- C:\WINDOWS\System32\svchost.exe ———- C:\WINDOWS\system32\svchost.exe ———- C:\WINDOWS\System32\svchost.exe ———- C:\WINDOWS\System32\svchost.exe ———- C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe ———- C:\WINDOWS\system32\spoolsv.exe ———- C:\WINDOWS\Explorer.EXE ———- C:\PROGRA~1\AVG\AVG8\avgtray.exe ———- C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe ———- C:\WINDOWS\system32\ctfmon.exe ———- C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe ———- C:\Program Files\APC\APC PowerChute Personal Edition\mainserv.exe ———- C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe ———- C:\Program Files\Intel\ASF Agent\ASFAgent.exe ———- C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe ———- C:\Program Files\Bonjour\mDNSResponder.exe ———- C:\WINDOWS\System32\nvsvc32.exe ———- C:\WINDOWS\System32\svchost.exe ———- C:\PROGRA~1\AVG\AVG8\avgrsx.exe ———- C:\PROGRA~1\AVG\AVG8\avgnsx.exe ———- C:\WINDOWS\System32\wbem\wmiprvse.exe ———- C:\WINDOWS\System32\wbem\unsecapp.exe ———- C:\WINDOWS\System32\alg.exe ———- C:\WINDOWS\System32\svchost.exe ———- C:\Documents and Settings\Jill Menezes\Desktop\OTListIt2.exe ———- C:\WINDOWS\notepad.exe ———- C:\WINDOWS\notepad.exe ———- C:\WINDOWS\system32\cmd.exe ———- C:\Rooter$\RK.exe ———————-\\ Search.. ———————-\\ ROOTKIT !! 1 - "C:\Rooter$\Rooter_1.txt" - Thu 03/12/2009|22:21 ———————-\\ Scan completed at 22:21
OTListlt.2 Log:—————————————————————————————————————————

OTListIt logfile created on: 3/12/2009 10:15:47 PM - Run 1
OTListIt2 by OldTimer - Version 2.0.3.5 Folder = C:\Documents and Settings\Jill Menezes\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.11)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

1022.98 Mb Total Physical Memory | 609.19 Mb Available Physical Memory | 59.55% Memory free
2.41 Gb Paging File | 1.99 Gb Available in Paging File | 82.66% Paging File free
Paging file location(s): C:\pagefile.sys 1536 3072;

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 37.21 Gb Total Space | 18.28 Gb Free Space | 49.14% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
Drive F: | 123.72 Mb Total Space | 85.82 Mb Free Space | 69.37% Space Free | Partition Type: FAT
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: OFFICE1
Current User Name: Jill Menezes
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Output = Minimal
File Age = 30 Days
Company Name Whitelist: On

========== Processes (SafeList) ==========

PRC - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe (Lavasoft)
PRC - C:\WINDOWS\Explorer.EXE (Microsoft Corporation)
PRC - C:\Program Files\AVG\AVG8\avgtray.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe (Lavasoft)
PRC - C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe (SUPERAntiSpyware.com)
PRC - C:\Program Files\APC\APC PowerChute Personal Edition\mainserv.exe (American Power Conversion Corporation)
PRC - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe (Apple Inc.)
PRC - C:\Program Files\Intel\ASF Agent\ASFAgent.exe (Intel Corporation)
PRC - C:\Program Files\AVG\AVG8\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\Bonjour\mDNSResponder.exe (Apple Inc.)
PRC - C:\WINDOWS\System32\nvsvc32.exe (NVIDIA Corporation)
PRC - C:\Program Files\AVG\AVG8\avgrsx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG8\avgnsx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\WINDOWS\System32\wbem\wmiprvse.exe (Microsoft Corporation)
PRC - C:\WINDOWS\System32\wbem\unsecapp.exe (Microsoft Corporation)
PRC - C:\Documents and Settings\Jill Menezes\Desktop\OTListIt2.exe (OldTimer Tools)

========== Win32 Services (SafeList) ==========

SRV - (APC UPS Service [Auto | Running]) – C:\Program Files\APC\APC PowerChute Personal Edition\mainserv.exe (American Power Conversion Corporation)
SRV - (Apple Mobile Device [Auto | Running]) – C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe (Apple Inc.)
SRV - (ASFAgent [Auto | Running]) – C:\Program Files\Intel\ASF Agent\ASFAgent.exe (Intel Corporation)
SRV - (aspnet_state [On_Demand | Stopped]) – C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe (Microsoft Corporation)
SRV - (avg8wd [Auto | Running]) – C:\Program Files\AVG\AVG8\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
SRV - (awhost32 [On_Demand | Stopped]) – C:\Program Files\Symantec\pcAnywhere\awhost32.exe (Symantec Corporation)
SRV - (Bonjour Service [Auto | Running]) – C:\Program Files\Bonjour\mDNSResponder.exe (Apple Inc.)
SRV - (clr_optimization_v2.0.50727_32 [On_Demand | Stopped]) – C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
SRV - (FontCache3.0.0.0 [On_Demand | Stopped]) – c:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe (Microsoft Corporation)
SRV - (helpsvc [Auto | Running]) – C:\WINDOWS\PCHealth\HelpCtr\Binaries\pchsvc.dll (Microsoft Corporation)
SRV - (Iap [Disabled | Stopped]) – C:\Program Files\Dell\OpenManage\Client\Iap.exe (Dell Computer Corporation)
SRV - (IDriverT [Disabled | Stopped]) – C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe (Macrovision Corporation)
SRV - (idsvc [Unknown | Stopped]) – c:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe (Microsoft Corporation)
SRV - (Iomega Activity Disk2 [Disabled | Stopped]) – File not found
SRV - (Iomega App Services [Disabled | Stopped]) – C:\Program Files\Iomega\System32\AppServices.exe (Iomega Corporation)
SRV - (iPod Service [On_Demand | Stopped]) – C:\Program Files\iPod\bin\iPodService.exe (Apple Inc.)
SRV - (Lavasoft Ad-Aware Service [Auto | Running]) – C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe (Lavasoft)
SRV - (MDM [Disabled | Stopped]) – C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE (Microsoft Corporation)
SRV - (NetSvc [Disabled | Stopped]) – C:\Program Files\Intel\NCS\Sync\NetSvc.exe (Intel® Corporation)
SRV - (NetTcpPortSharing [Disabled | Stopped]) – c:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe (Microsoft Corporation)
SRV - (NVSvc [Auto | Running]) – C:\WINDOWS\System32\nvsvc32.exe (NVIDIA Corporation)
SRV - (ose [On_Demand | Stopped]) – C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE (Microsoft Corporation)
SRV - (Pml Driver HPZ12 [On_Demand | Stopped]) – C:\WINDOWS\System32\HPZipm12.exe (HP)
SRV - (QBCFMonitorService [Disabled | Stopped]) – C:\Program Files\Common Files\Intuit\QuickBooks\QBCFMonitorService.exe (Intuit)
SRV - (QBFCService [On_Demand | Stopped]) – C:\Program Files\Common Files\Intuit\QuickBooks\FCS\Intuit.QuickBooks.FCS.exe (Intuit Inc.)
SRV - (SupportSoft RemoteAssist [On_Demand | Stopped]) – C:\Program Files\Common Files\supportsoft\bin\ssrc.exe (SupportSoft, Inc.)
SRV - (WMPNetworkSvc [Disabled | Stopped]) – C:\Program Files\Windows Media Player\WMPNetwk.exe (Microsoft Corporation)

========== Driver Services (SafeList) ==========

DRV - (aeaudio [On_Demand | Running]) – C:\WINDOWS\system32\drivers\aeaudio.sys (Andrea Electronics Corporation)
DRV - (AFS2K [System | Running]) – C:\WINDOWS\System32\drivers\AFS2K.SYS (Oak Technology Inc.)
DRV - (AliIde [Disabled | Stopped]) – C:\WINDOWS\System32\DRIVERS\aliide.sys (Acer Laboratories Inc.)
DRV - (amdagp [Disabled | Stopped]) – C:\WINDOWS\System32\DRIVERS\amdagp.sys (Advanced Micro Devices, Inc.)
DRV - (asc [Disabled | Stopped]) – C:\WINDOWS\System32\DRIVERS\asc.sys (Advanced System Products, Inc.)
DRV - (asc3550 [Disabled | Stopped]) – C:\WINDOWS\System32\DRIVERS\asc3550.sys (Advanced System Products, Inc.)
DRV - (AsfAlrt [Auto | Running]) – C:\WINDOWS\System32\drivers\AsfAlrt.sys (Intel Corporation)
DRV - (AvgLdx86 [System | Running]) – C:\WINDOWS\System32\Drivers\avgldx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (AvgMfx86 [System | Running]) – C:\WINDOWS\System32\Drivers\avgmfx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (AvgTdiX [System | Running]) – C:\WINDOWS\System32\Drivers\avgtdix.sys (AVG Technologies CZ, s.r.o.)
DRV - (awecho [System | Running]) – C:\WINDOWS\system32\drivers\awechomd.sys (Symantec Corporation)
DRV - (awlegacy [System | Running]) – C:\WINDOWS\System32\Drivers\awlegacy.sys (Symantec Corporation)
DRV - (AW_HOST [System | Running]) – C:\WINDOWS\system32\drivers\aw_host5.sys (Symantec Corporation)
DRV - (Cdr4_xp [System | Running]) – C:\WINDOWS\System32\drivers\cdr4_xp.sys (Sonic Solutions)
DRV - (Cdralw2k [System | Running]) – C:\WINDOWS\System32\drivers\cdralw2k.sys (Sonic Solutions)
DRV - (cdudf_xp [System | Running]) – C:\WINDOWS\System32\drivers\cdudf_xp.sys (Roxio)
DRV - (CmdIde [Disabled | Stopped]) – C:\WINDOWS\System32\DRIVERS\cmdide.sys (CMD Technology, Inc.)
DRV - (dac2w2k [Disabled | Stopped]) – C:\WINDOWS\System32\DRIVERS\dac2w2k.sys (Mylex Corporation)
DRV - (dvd_2K [On_Demand | Stopped]) – C:\WINDOWS\System32\drivers\Dvd_2k.sys (Roxio)
DRV - (E1000 [On_Demand | Running]) – C:\WINDOWS\System32\DRIVERS\e1000325.sys (Intel Corporation)
DRV - (EL90XBC [On_Demand | Stopped]) – C:\WINDOWS\System32\DRIVERS\el90xbc5.sys (3Com Corporation)
DRV - (GEARAspiWDM [On_Demand | Running]) – C:\WINDOWS\SYSTEM32\DRIVERS\GEARAspiWDM.sys (GEAR Software Inc.)
DRV - (Gernuwa [Boot | Running]) – C:\WINDOWS\System32\drivers\GERNUWA.sys (Symantec Corporation)
DRV - (HidBatt [On_Demand | Stopped]) – C:\WINDOWS\System32\DRIVERS\HidBatt.sys (Microsoft Corporation)
DRV - (HPZid412 [On_Demand | Running]) – C:\WINDOWS\System32\DRIVERS\HPZid412.sys (HP)
DRV - (HPZipr12 [On_Demand | Running]) – C:\WINDOWS\System32\DRIVERS\HPZipr12.sys (HP)
DRV - (HPZius12 [On_Demand | Running]) – C:\WINDOWS\System32\DRIVERS\HPZius12.sys (HP)
DRV - (HSFHWBS2 [On_Demand | Running]) – C:\WINDOWS\System32\DRIVERS\HSFHWBS2.sys (Conexant Systems, Inc.)
DRV - (HSF_DP [On_Demand | Running]) – C:\WINDOWS\System32\DRIVERS\HSF_DP.sys (Conexant Systems, Inc.)
DRV - (i81x [On_Demand | Stopped]) – C:\WINDOWS\System32\DRIVERS\i81xnt5.sys (Intel® Corporation)
DRV - (iAimFP0 [On_Demand | Stopped]) – C:\WINDOWS\System32\DRIVERS\wADV01nt.sys (Intel® Corporation)
DRV - (iAimFP1 [On_Demand | Stopped]) – C:\WINDOWS\System32\DRIVERS\wADV02NT.sys (Intel® Corporation)
DRV - (iAimFP2 [On_Demand | Stopped]) – C:\WINDOWS\System32\DRIVERS\wADV05NT.sys (Intel® Corporation)
DRV - (iAimFP3 [On_Demand | Stopped]) – C:\WINDOWS\System32\DRIVERS\wSiINTxx.sys (Intel® Corporation)
DRV - (iAimFP4 [On_Demand | Stopped]) – C:\WINDOWS\System32\DRIVERS\wVchNTxx.sys (Intel® Corporation)
DRV - (iAimTV0 [On_Demand | Stopped]) – C:\WINDOWS\System32\DRIVERS\wATV01nt.sys (Intel® Corporation)
DRV - (iAimTV1 [On_Demand | Stopped]) – C:\WINDOWS\System32\DRIVERS\wATV02NT.sys (Intel® Corporation)
DRV - (iAimTV3 [On_Demand | Stopped]) – C:\WINDOWS\System32\DRIVERS\wATV04nt.sys (Intel® Corporation)
DRV - (iAimTV4 [On_Demand | Stopped]) – C:\WINDOWS\System32\DRIVERS\wCh7xxNT.sys (Intel® Corporation)
DRV - (iomdisk [Boot | Running]) – C:\WINDOWS\System32\DRIVERS\iomdisk.sys (Iomega Corporation)
DRV - (Lbd [Boot | Running]) – C:\WINDOWS\system32\DRIVERS\Lbd.sys (Lavasoft AB)
DRV - (mdmxsdk [Auto | Running]) – C:\WINDOWS\System32\DRIVERS\mdmxsdk.sys (Conexant)
DRV - (mmc_2K [On_Demand | Running]) – C:\WINDOWS\System32\drivers\Mmc_2k.sys (Roxio)
DRV - (MODEMCSA [On_Demand | Running]) – C:\WINDOWS\system32\drivers\MODEMCSA.sys (Microsoft Corporation)
DRV - (mraid35x [Disabled | Stopped]) – C:\WINDOWS\System32\DRIVERS\mraid35x.sys (American Megatrends Inc.)
DRV - (nv [On_Demand | Running]) – C:\WINDOWS\System32\DRIVERS\nv4_mini.sys (NVIDIA Corporation)
DRV - (omci [System | Running]) – C:\WINDOWS\System32\DRIVERS\omci.sys (Dell Computer Corporation)
DRV - (Ptilink [On_Demand | Running]) – C:\WINDOWS\System32\DRIVERS\ptilink.sys (Parallel Technologies, Inc.)
DRV - (pwd_2k [System | Running]) – C:\WINDOWS\System32\drivers\pwd_2K.sys (Roxio)
DRV - (PxHelp20 [Boot | Running]) – C:\WINDOWS\System32\Drivers\PxHelp20.sys (Sonic Solutions)
DRV - (ql1080 [Disabled | Stopped]) – C:\WINDOWS\System32\DRIVERS\ql1080.sys (QLogic Corporation)
DRV - (ql12160 [Disabled | Stopped]) – C:\WINDOWS\System32\DRIVERS\ql12160.sys (QLogic Corporation)
DRV - (ql1280 [Disabled | Stopped]) – C:\WINDOWS\System32\DRIVERS\ql1280.sys (QLogic Corporation)
DRV - (SABProcEnum [On_Demand | Stopped]) – C:\WINDOWS\System32\sabprocenum.sys (SuperAdBlocker.com)
DRV - (SASDIFSV [System | Running]) – C:\Program Files\SUPERAntiSpyware\SASDIFSV.SYS (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (SASENUM [On_Demand | Running]) – C:\Program Files\SUPERAntiSpyware\SASENUM.SYS ( SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (SASKUTIL [System | Running]) – C:\Program Files\SUPERAntiSpyware\SASKUTIL.sys (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (Secdrv [On_Demand | Stopped]) – C:\WINDOWS\System32\DRIVERS\secdrv.sys (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.)
DRV - (sisagp [Disabled | Stopped]) – C:\WINDOWS\System32\DRIVERS\sisagp.sys (Silicon Integrated Systems Corporation)
DRV - (smwdm [On_Demand | Running]) – C:\WINDOWS\system32\drivers\smwdm.sys (Analog Devices, Inc.)
DRV - (Sparrow [Disabled | Stopped]) – C:\WINDOWS\System32\DRIVERS\sparrow.sys (Adaptec, Inc.)
DRV - (symc810 [Disabled | Stopped]) – C:\WINDOWS\System32\DRIVERS\symc810.sys (Symbios Logic Inc.)
DRV - (symc8xx [Disabled | Stopped]) – C:\WINDOWS\System32\DRIVERS\symc8xx.sys (LSI Logic)
DRV - (SymEvent [On_Demand | Stopped]) – C:\Program Files\Symantec\SYMEVENT.SYS (Symantec Corporation)
DRV - (sym_hi [Disabled | Stopped]) – C:\WINDOWS\System32\DRIVERS\sym_hi.sys (LSI Logic)
DRV - (sym_u3 [Disabled | Stopped]) – C:\WINDOWS\System32\DRIVERS\sym_u3.sys (LSI Logic)
DRV - (UdfReadr_xp [System | Running]) – C:\WINDOWS\System32\drivers\udfreadr_xp.sys (Roxio)
DRV - (ultra [Disabled | Stopped]) – C:\WINDOWS\System32\DRIVERS\ultra.sys (Promise Technology, Inc.)
DRV - (winachsf [On_Demand | Running]) – C:\WINDOWS\System32\DRIVERS\HSF_CNXT.sys (Conexant Systems, Inc.)

========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL =
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:NoAdd-ons
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\SYSTEM32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:SecurityRisk
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.msn.com/
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomizeSearch = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\SYSTEM32\blank.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Page_Transitions = 1
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchDefaultBranded = 1
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultName = Google
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultURL = http://www.google.com/search?q={searchTerm…tf8&oe=utf8
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = about:blank
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local

FF - prefs.js..browser.search.selectedEngine: "Google"
FF - prefs.js..browser.startup.homepage: "about:blank"
FF - prefs.js..extensions.enabledItems: {3f963a5b-e555-4543-90e2-c3908898db71}:8.0
FF - prefs.js..extensions.enabledItems: {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.0.7
FF - HKLM\software\mozilla\Firefox\Extensions\\{3f963a5b-e555-4543-90e2-c3908898db71} -> %ProgramFiles%\AVG\AVG8\FIREFOX [C:\PROGRAM FILES\AVG\AVG8\FIREFOX] -> [2009/03/03 13:44:01 00,000,000 | —D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\{20a82645-c095-46ed-80e3-08825760534b} -> %SystemRoot%\MICROSOFT.NET\FRAMEWORK\V3.5\WINDOWS PRESENTATION FOUNDATION\DOTNETASSISTANTEXTENSION [C:\WINDOWS\MICROSOFT.NET\FRAMEWORK\V3.5\WINDOWS PRESENTATION FOUNDATION\DOTNETASSISTANTEXTENSION\] -> [2009/03/08 21:28:31 00,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.0.7\extensions\\Components -> %ProgramFiles%\MOZILLA FIREFOX\COMPONENTS [C:\PROGRAM FILES\MOZILLA FIREFOX\COMPONENTS] -> [2009/03/11 18:54:47 00,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.0.7\extensions\\Plugins -> %ProgramFiles%\MOZILLA FIREFOX\PLUGINS [C:\PROGRAM FILES\MOZILLA FIREFOX\PLUGINS] -> [2009/03/11 18:54:46 00,000,000 | —D | M]
FF - C:\Documents and Settings\Jill Menezes\Application Data\mozilla\Extensions [2009/03/11 18:54:59 00,000,000 | —D | M]
FF - C:\Documents and Settings\Jill Menezes\Application Data\mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384} [2009/03/11 18:54:59 00,000,000 | —D | M]
FF - C:\Documents and Settings\Jill Menezes\Application Data\mozilla\Firefox\Profiles\eaod5uxm.default\extensions [2009/03/11 18:55:00 00,000,000 | —D | M]
FF - C:\Program Files\mozilla firefox\extensions [2009/03/11 18:55:00 00,000,000 | —D | M]
FF - C:\Program Files\mozilla firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd} [2009/03/11 18:54:47 00,000,000 | —D | M]

O1 HOSTS File: (7853 bytes) - C:\WINDOWS\System32\drivers\etc\Hosts
O1 - Hosts: 89.149.227.223 google.ae
O1 - Hosts: 89.149.227.223 google.as
O1 - Hosts: 89.149.227.223 google.at
O1 - Hosts: 89.149.227.223 google.az
O1 - Hosts: 89.149.227.223 google.ba
O1 - Hosts: 89.149.227.223 google.be
O1 - Hosts: 89.149.227.223 google.bg
O1 - Hosts: 89.149.227.223 google.bs
O1 - Hosts: 89.149.227.223 google.ca
O1 - Hosts: 89.149.227.223 google.cd
O1 - Hosts: 89.149.227.223 google.com.gh
O1 - Hosts: 89.149.227.223 google.com.gi
O1 - Hosts: 89.149.227.223 google.com.hk
O1 - Hosts: 89.149.227.223 google.com.jm
O1 - Hosts: 89.149.227.223 google.com.ly
O1 - Hosts: 89.149.227.223 google.com.mx
O1 - Hosts: 89.149.227.223 google.com.my
O1 - Hosts: 89.149.227.223 google.com.na
O1 - Hosts: 89.149.227.223 google.com.nf
O1 - Hosts: 89.149.227.223 google.com.ng
O1 - Hosts: 89.149.227.223 google.ch
O1 - Hosts: 89.149.227.223 google.com.np
O1 - Hosts: 89.149.227.223 google.com.om
O1 - Hosts: 89.149.227.223 google.com.pa
O1 - Hosts: 89.149.227.223 google.com.pr
O1 - Hosts: 242 more lines…
O2 - BHO: (AcroIEHlprObj Class) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll (AVG Technologies CZ, s.r.o.)
O2 - BHO: (AcroIEToolbarHelper Class) - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll ()
O3 - HKLM\..\Toolbar: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll ()
O3 - HKLM\..\Toolbar: (no name) - SITEguard - Reg Error: Key error. File not found
O3 - HKCU\..\Toolbar\ShellBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - Reg Error: Key error. File not found
O3 - HKCU\..\Toolbar\ShellBrowser: (no name) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll ()
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {4194307F-65BB-454A-81D4-9E8A9D7CBAEA} - Reg Error: Value error. File not found
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll ()
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {C7768536-96F8-4001-B1A2-90EE21279187} - Reg Error: Key error. File not found
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - Reg Error: Key error. File not found
O4 - HKLM..\Run: [Ad-Watch] C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe (Lavasoft)
O4 - HKLM..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup (NVIDIA Corporation)
O4 - HKLM..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime (Apple Inc.)
O4 - HKCU..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe (SUPERAntiSpyware.com)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\control panel present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 1
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\control panel present
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\restrictions present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra 'Tools' menuitem : Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - Reg Error: Key error. File not found
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Program Files\Microsoft Office\OFFICE11\REFIEBAR.DLL (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [mdnsNSP] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O15 - HKLM\..Trusted Domains: 1 domain(s) and sub-domain(s) not assigned to a zone.
O15 - HKCU\..Trusted Sites: ([]msn in My Computer)
O16 - DPF: {01113300-3E00-11D2-8470-0060089874ED} http://supportcenter.rr.com/sdccommon/download/tgctlcm.cab (Support.com Configuration Class)
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} http://upload.facebook.com/controls/Facebo…toUploader5.cab (Facebook Photo Uploader 5)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://go.microsoft.com/fwlink/?linkid=39204 (Windows Genuine Advantage Validation Tool)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} http://update.microsoft.com/microsoftupdat…b?1174499935843 (MUWebControl Class)
O16 - DPF: {AB86CE53-AC9F-449F-9399-D8ABCA09EC09} https://h17000.www1.hp.com/ewfrf-JAVA/Secur…loadManager.ocx (Get_ActiveX Control)
O16 - DPF: {B1E2B96C-12FE-45E2-BEF1-44A219113CDD} http://www.superadblocker.com/activex/sabspx.cab (SABScanProcesses Class)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload.macromedia.com/get/flash…ent/swflash.cab (Shockwave Flash Object)
O18 - Protocol\Handler\cetihpz {CF184AD3-CDCB-4168-A3F7-8E447D129300} - C:\Program Files\HP\hpcoretech\comp\hpuiprot.dll (Hewlett-Packard Company)
O18 - Protocol\Handler\ipp Reg Error: Value error. - Reg Error: Key error. File not found
O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll (AVG Technologies CZ, s.r.o.)
O18 - Protocol\Handler\msdaipp Reg Error: Value error. - Reg Error: Key error. File not found
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\mso-offdap {3D9F03FA-7A94-11D3-BE81-0050048385D1} - C:\Program Files\Common Files\Microsoft Shared\Web Components\10\OWC10.DLL (Microsoft Corporation)
O18 - Protocol\Handler\mso-offdap11 {32505114-5902-49B2-880A-1F7738E5A384} - C:\Program Files\Common Files\Microsoft Shared\Web Components\11\OWC11.DLL (Microsoft Corporation)
O18 - Protocol\Filter: - text/xml - C:\Program Files\Common Files\Microsoft Shared\OFFICE11\MSOXMLMF.DLL (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\!SASWinLogon: DllName - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL (SUPERAntiSpyware.com)
O20 - Winlogon\Notify\avgrsstarter: DllName - avgrsstx.dll - C:\WINDOWS\system32\avgrsstx.dll (AVG Technologies CZ, s.r.o.)
O20 - Winlogon\Notify\PCANotify: DllName - PCANotify.dll - C:\WINDOWS\system32\PCANotify.dll (Symantec Corporation)
O24 - Desktop Components:0 (My Current Home Page) - About:Home
O28 - HKLM ShellExecuteHooks: {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - C:\Program Files\SUPERAntiSpyware\SASSEH.DLL (SuperAdBlocker.com)
O31 - SafeBoot: AlternateShell - cmd.exe
O32 - HKLM CDRom: AutoRun - 1
O32 - Autorun File - C:\AUTOEXEC.BAT () - [ NTFS ]

========== Files/Folders - Created Within 30 Days ==========

[1 C:\WINDOWS\System32\*.tmp files]
[3 C:\WINDOWS\*.tmp files]
[2009/03/12 22:14:32 | 00,267,612 | —- | C] () – C:\Documents and Settings\Jill Menezes\Desktop\Rooter.exe
[2009/03/12 22:13:39 | 00,497,664 | —- | C] (OldTimer Tools) – C:\Documents and Settings\Jill Menezes\Desktop\OTListIt2.exe
[2009/03/12 20:57:08 | 00,000,633 | —- | C] () – C:\Documents and Settings\Jill Menezes\Desktop\Shortcut to HostsXpert.exe.lnk
[2009/03/12 16:52:50 | 00,001,734 | —- | C] () – C:\Documents and Settings\Jill Menezes\Desktop\HijackThis.lnk
[2009/03/12 16:04:36 | 00,000,000 | —D | C] – C:\HostsXpert 4.3
[2009/03/12 10:53:35 | 00,015,688 | —- | C] () – C:\WINDOWS\System32\lsdelete.exe
[2009/03/12 05:51:22 | 00,000,472 | —- | C] () – C:\WINDOWS\tasks\Ad-Aware Update (Daily).job
[2009/03/12 05:44:32 | 00,064,160 | —- | C] (Lavasoft AB) – C:\WINDOWS\System32\drivers\Lbd.sys
[2009/03/12 05:43:22 | 00,000,000 | -H-D | C] – C:\Documents and Settings\All Users\Application Data\{83C91755-2546-441D-AC40-9A6B4B860800}
[2009/03/12 05:43:21 | 00,000,867 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Ad-Aware.lnk
[2009/03/12 04:06:55 | 00,000,000 | —D | C] – C:\Program Files\Trend Micro
[2009/03/11 18:54:55 | 00,000,000 | —D | C] – C:\Documents and Settings\Jill Menezes\Local Settings\Application Data\Mozilla
[2009/03/11 18:54:49 | 00,001,602 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Mozilla Firefox.lnk
[2009/03/11 09:43:21 | 00,000,000 | -H-D | C] – C:\WINDOWS\$hf_mig$
[2009/03/09 07:33:32 | 01,089,593 | —- | C] () – C:\WINDOWS\System32\dllcache\ntprint.cat
[2009/03/08 21:27:18 | 00,000,000 | —D | C] – C:\WINDOWS\System32\XPSViewer
[2009/03/08 21:27:13 | 00,000,000 | —D | C] – C:\Program Files\MSBuild
[2009/03/08 21:27:00 | 00,000,000 | —D | C] – C:\Program Files\Reference Assemblies
[2009/03/08 21:26:17 | 01,676,288 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\xpssvcs.dll
[2009/03/08 21:26:17 | 01,676,288 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\xpssvcs.dll
[2009/03/08 21:26:17 | 00,597,504 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\printfilterpipelinesvc.exe
[2009/03/08 21:26:17 | 00,575,488 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\xpsshhdr.dll
[2009/03/08 21:26:17 | 00,575,488 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\xpsshhdr.dll
[2009/03/08 21:26:17 | 00,117,760 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\prntvpt.dll
[2009/03/08 21:26:17 | 00,089,088 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\filterpipelineprintproc.dll
[2009/03/08 21:26:15 | 00,000,000 | —D | C] – C:\0b96be0235e3ae5039d283c8
[2009/03/03 14:38:46 | 00,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
[2009/03/03 14:38:39 | 00,001,756 | —- | C] () – C:\Documents and Settings\All Users\Desktop\SUPERAntiSpyware Professional.lnk
[2009/03/03 14:38:36 | 00,000,000 | —D | C] – C:\Program Files\SUPERAntiSpyware
[2009/03/03 14:38:36 | 00,000,000 | —D | C] – C:\Documents and Settings\Jill Menezes\Application Data\SUPERAntiSpyware.com
[2009/03/03 14:38:09 | 00,000,000 | —D | C] – C:\Program Files\Common Files\Wise Installation Wizard
[2009/03/03 14:09:12 | 00,000,000 | -H-D | C] – C:\$AVG8.VAULT$
[2009/03/03 13:44:35 | 00,010,520 | —- | C] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\avgrsstx.dll
[2009/03/03 13:44:35 | 00,001,507 | —- | C] () – C:\Documents and Settings\All Users\Desktop\AVG Free 8.0.lnk
[2009/03/03 13:44:34 | 00,107,272 | —- | C] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\drivers\avgtdix.sys
[2009/03/03 13:44:28 | 00,325,128 | —- | C] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\drivers\avgldx86.sys
[2009/03/03 13:44:27 | 00,027,656 | —- | C] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\drivers\avgmfx86.sys
[2009/03/03 13:44:20 | 34,013,460 | —- | C] () – C:\WINDOWS\System32\drivers\Avg\incavi.avm
[2009/03/03 13:44:20 | 06,061,540 | —- | C] () – C:\WINDOWS\System32\drivers\Avg\avi7.avg
[2009/03/03 13:44:20 | 00,401,372 | —- | C] () – C:\WINDOWS\System32\drivers\Avg\miniavi.avg
[2009/03/03 13:44:20 | 00,033,747 | —- | C] () – C:\WINDOWS\System32\drivers\Avg\microavi.avg
[2009/03/03 13:44:20 | 00,000,000 | —D | C] – C:\WINDOWS\System32\drivers\Avg
[2009/03/03 13:44:01 | 00,000,000 | —D | C] – C:\Program Files\AVG
[2009/03/03 13:44:01 | 00,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\avg8
[2009/03/03 13:23:18 | 00,000,000 | —D | C] – C:\WINDOWS\temp
[2009/03/03 13:22:12 | 00,428,032 | —- | C] (SteelWerX) – C:\WINDOWS\System32\swreg.exe
[2009/03/03 13:22:12 | 00,370,688 | —- | C] (SteelWerX) – C:\WINDOWS\System32\swsc.exe
[2009/03/03 13:22:12 | 00,086,528 | —- | C] () – C:\WINDOWS\catchme.exe
[2009/03/03 13:22:12 | 00,049,152 | —- | C] (NirSoft) – C:\WINDOWS\nircmd.exe
[2009/03/03 13:22:12 | 00,049,152 | —- | C] () – C:\WINDOWS\System32\vfind.exe
[2009/03/03 13:22:12 | 00,038,400 | —- | C] () – C:\WINDOWS\System32\moveex.exe
[2009/03/03 13:21:44 | 00,000,000 | —D | C] – C:\QooBox
[2009/03/03 12:22:35 | 00,000,000 | —D | C] – C:\WINDOWS\pss
[2009/03/03 01:27:04 | 00,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\SITEguard
[2009/03/03 01:26:01 | 00,000,000 | —D | C] – C:\Program Files\Common Files\iS3
[2009/03/03 01:26:01 | 00,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\STOPzilla!
[2009/03/02 23:47:44 | 00,000,000 | -HSD | C] – C:\Documents and Settings\Jill Menezes\Application Data\Virus Melt
[2009/03/02 23:47:33 | 00,000,000 | -HSD | C] – C:\Documents and Settings\All Users\Application Data\System Data
[2009/02/28 17:06:54 | 00,000,000 | —D | C] – C:\Documents and Settings\Jill Menezes\Desktop\Photo Frame

========== Files - Modified Within 30 Days ==========

[1 C:\WINDOWS\System32\*.tmp files]
[3 C:\WINDOWS\*.tmp files]
[2009/03/12 22:14:32 | 00,267,612 | —- | M] () – C:\Documents and Settings\Jill Menezes\Desktop\Rooter.exe
[2009/03/12 22:13:41 | 00,497,664 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Jill Menezes\Desktop\OTListIt2.exe
[2009/03/12 21:18:56 | 00,000,452 | —- | M] () – C:\WINDOWS\tasks\RegCure Program Check.job
[2009/03/12 21:18:44 | 00,001,170 | —- | M] () – C:\WINDOWS\System32\WPA.DBL
[2009/03/12 21:18:20 | 00,000,006 | -H– | M] () – C:\WINDOWS\tasks\SA.DAT
[2009/03/12 21:18:15 | 00,002,048 | –S- | M] () – C:\WINDOWS\BOOTSTAT.DAT
[2009/03/12 20:57:08 | 00,000,633 | —- | M] () – C:\Documents and Settings\Jill Menezes\Desktop\Shortcut to HostsXpert.exe.lnk
[2009/03/12 17:11:31 | 00,033,747 | —- | M] () – C:\WINDOWS\System32\drivers\Avg\microavi.avg
[2009/03/12 17:11:30 | 34,013,460 | —- | M] () – C:\WINDOWS\System32\drivers\Avg\incavi.avm
[2009/03/12 16:52:50 | 00,001,734 | —- | M] () – C:\Documents and Settings\Jill Menezes\Desktop\HijackThis.lnk
[2009/03/12 05:51:22 | 00,000,472 | —- | M] () – C:\WINDOWS\tasks\Ad-Aware Update (Daily).job
[2009/03/12 05:44:27 | 00,015,688 | —- | M] () – C:\WINDOWS\System32\lsdelete.exe
[2009/03/12 05:44:15 | 00,064,160 | —- | M] (Lavasoft AB) – C:\WINDOWS\System32\drivers\Lbd.sys
[2009/03/12 05:43:21 | 00,000,867 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Ad-Aware.lnk
[2009/03/11 18:54:49 | 00,001,602 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Mozilla Firefox.lnk
[2009/03/11 14:05:15 | 00,067,584 | —- | M] () – C:\Documents and Settings\Jill Menezes\Desktop\Child Support Remittance Advice Blank.xls
[2009/03/11 10:28:28 | 00,324,320 | —- | M] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2009/03/11 10:01:32 | 00,001,374 | —- | M] () – C:\WINDOWS\imsins.BAK
[2009/03/09 13:00:26 | 00,000,020 | —- | M] () – C:\dirref.ini
[2009/03/09 08:21:30 | 00,091,848 | —- | M] () – C:\Documents and Settings\Jill Menezes\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
[2009/03/08 21:32:16 | 00,533,172 | —- | M] () – C:\WINDOWS\System32\PerfStringBackup.INI
[2009/03/08 21:32:16 | 00,463,200 | —- | M] () – C:\WINDOWS\System32\PERFH009.DAT
[2009/03/08 21:32:16 | 00,080,226 | —- | M] () – C:\WINDOWS\System32\PERFC009.DAT
[2009/03/03 19:20:28 | 00,000,701 | —- | M] () – C:\WINDOWS\WIN.INI
[2009/03/03 14:38:39 | 00,001,756 | —- | M] () – C:\Documents and Settings\All Users\Desktop\SUPERAntiSpyware Professional.lnk
[2009/03/03 13:46:00 | 00,401,372 | —- | M] () – C:\WINDOWS\System32\drivers\Avg\miniavi.avg
[2009/03/03 13:44:35 | 00,010,520 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\avgrsstx.dll
[2009/03/03 13:44:35 | 00,001,507 | —- | M] () – C:\Documents and Settings\All Users\Desktop\AVG Free 8.0.lnk
[2009/03/03 13:44:34 | 00,107,272 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\drivers\avgtdix.sys
[2009/03/03 13:44:28 | 00,325,128 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\drivers\avgldx86.sys
[2009/03/03 13:44:27 | 00,027,656 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\drivers\avgmfx86.sys
[2009/03/03 13:44:20 | 06,061,540 | —- | M] () – C:\WINDOWS\System32\drivers\Avg\avi7.avg
[2009/03/03 13:34:49 | 00,000,227 | —- | M] () – C:\WINDOWS\SYSTEM.INI
[2009/03/03 13:34:49 | 00,000,211 | RHS- | M] () – C:\BOOT.INI
[2009/03/03 00:45:06 | 00,007,853 | -HS- | M] () – C:\WINDOWS\System32\drivers\ETC\hosts
[2009/02/28 17:18:27 | 00,009,728 | —- | M] () – C:\Documents and Settings\Jill Menezes\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009/02/25 12:55:00 | 24,768,960 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\MRT.exe

========== LOP Check ==========

[2009/03/12 05:43:22 | 00,000,000 | RH-D | M] – C:\Documents and Settings\All Users\Application Data
[2009/02/07 16:21:01 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}
[2009/03/12 05:43:22 | 00,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\{83C91755-2546-441D-AC40-9A6B4B860800}
[2007/04/17 08:50:16 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Adobe
[2007/07/26 10:42:18 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Apple
[2006/09/13 13:05:36 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Apple Computer
[2009/03/03 13:44:01 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\avg8
[2007/02/05 09:24:38 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\COMMON FILES
[2009/03/03 13:36:05 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Grisoft
[2004/09/08 11:11:23 | 00,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\GTek
[2004/10/16 11:07:38 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\HP
[2008/01/16 08:54:53 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Intuit
[2007/06/12 10:01:10 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Kodak
[2009/03/12 05:43:09 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Lavasoft
[2007/10/04 18:48:15 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\McAfee
[2007/02/16 10:00:30 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\McAfee.com
[2008/01/23 15:26:19 | 00,000,000 | –SD | M] – C:\Documents and Settings\All Users\Application Data\Microsoft
[2004/03/13 11:45:27 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\MSN6
[2008/01/02 11:38:15 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\nView_Profiles
[2005/08/18 12:23:06 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\QuickTime
[2004/02/15 18:23:01 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\SBSI
[2007/10/04 18:45:10 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\SiteAdvisor
[2009/03/03 01:27:04 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\SITEguard
[2009/03/12 21:03:22 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
[2009/03/03 12:33:09 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\STOPzilla!
[2009/03/03 14:38:46 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
[2004/03/11 20:01:41 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Support.com
[2008/04/17 09:39:15 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Symantec
[2009/03/02 23:47:33 | 00,000,000 | -HSD | M] – C:\Documents and Settings\All Users\Application Data\System Data
[2005/08/05 16:19:00 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Viewpoint
[2005/08/06 10:15:51 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Windows Genuine Advantage
[2006/09/05 14:57:56 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Yahoo!
[2009/03/03 14:38:36 | 00,000,000 | RH-D | M] – C:\Documents and Settings\Jill Menezes\Application Data
[2008/07/17 17:45:23 | 00,000,000 | —D | M] – C:\Documents and Settings\Jill Menezes\Application Data\Adobe
[2009/03/12 17:27:57 | 00,000,000 | —D | M] – C:\Documents and Settings\Jill Menezes\Application Data\AdobeUM
[2005/08/05 01:34:17 | 00,000,000 | —D | M] – C:\Documents and Settings\Jill Menezes\Application Data\Aim
[2008/03/28 12:22:10 | 00,000,000 | —D | M] – C:\Documents and Settings\Jill Menezes\Application Data\Apple Computer
[2007/01/30 18:45:37 | 00,000,000 | —D | M] – C:\Documents and Settings\Jill Menezes\Application Data\Google
[2004/09/08 11:11:23 | 00,000,000 | -H-D | M] – C:\Documents and Settings\Jill Menezes\Application Data\GTek
[2004/03/14 17:17:15 | 00,000,000 | —D | M] – C:\Documents and Settings\Jill Menezes\Application Data\Help
[2004/10/16 11:07:38 | 00,000,000 | —D | M] – C:\Documents and Settings\Jill Menezes\Application Data\HP
[2004/02/15 17:51:42 | 00,000,000 | —D | M] – C:\Documents and Settings\Jill Menezes\Application Data\Identities
[2007/02/05 09:35:09 | 00,000,000 | —D | M] – C:\Documents and Settings\Jill Menezes\Application Data\Intuit
[2008/12/25 12:56:19 | 00,000,000 | —D | M] – C:\Documents and Settings\Jill Menezes\Application Data\KompoZer
[2008/01/23 15:26:21 | 00,000,000 | —D | M] – C:\Documents and Settings\Jill Menezes\Application Data\Lavasoft
[2004/03/11 20:14:50 | 00,000,000 | —D | M] – C:\Documents and Settings\Jill Menezes\Application Data\Macromedia
[2004/03/11 19:39:53 | 00,000,000 | —D | M] – C:\Documents and Settings\Jill Menezes\Application Data\McAfee
[2006/11/02 22:28:55 | 00,000,000 | –SD | M] – C:\Documents and Settings\Jill Menezes\Application Data\Microsoft
[2009/03/11 18:54:59 | 00,000,000 | —D | M] – C:\Documents and Settings\Jill Menezes\Application Data\Mozilla
[2004/03/23 14:28:47 | 00,000,000 | —D | M] – C:\Documents and Settings\Jill Menezes\Application Data\MSN6
[2008/03/21 09:54:23 | 00,000,000 | —D | M] – C:\Documents and Settings\Jill Menezes\Application Data\Real
[2007/04/26 13:55:38 | 00,000,000 | —D | M] – C:\Documents and Settings\Jill Menezes\Application Data\Stamps.com Internet Postage
[2004/02/15 18:14:10 | 00,000,000 | —D | M] – C:\Documents and Settings\Jill Menezes\Application Data\Sun
[2009/03/03 14:38:36 | 00,000,000 | —D | M] – C:\Documents and Settings\Jill Menezes\Application Data\SUPERAntiSpyware.com
[2005/03/02 09:08:46 | 00,000,000 | —D | M] – C:\Documents and Settings\Jill Menezes\Application Data\Symantec
[2007/12/26 19:24:00 | 00,000,000 | —D | M] – C:\Documents and Settings\Jill Menezes\Application Data\Tenebril
[2006/01/03 11:30:06 | 00,000,000 | —D | M] – C:\Documents and Settings\Jill Menezes\Application Data\Thunderbird
[2008/09/20 20:16:11 | 00,000,000 | —D | M] – C:\Documents and Settings\Jill Menezes\Application Data\Uniblue
[2006/01/03 15:29:25 | 00,000,000 | —D | M] – C:\Documents and Settings\Jill Menezes\Application Data\UVC
[2009/03/03 00:45:11 | 00,000,000 | -HSD | M] – C:\Documents and Settings\Jill Menezes\Application Data\Virus Melt
[2005/04/28 14:04:57 | 00,000,000 | —D | M] – C:\Documents and Settings\Jill Menezes\Application Data\Webshots
[2009/03/12 05:51:22 | 00,000,472 | —- | M] () – C:\WINDOWS\Tasks\Ad-Aware Update (Daily).job
[2002/08/29 07:00:00 | 00,000,065 | RH– | M] () – C:\WINDOWS\Tasks\DESKTOP.INI
[2009/03/12 21:18:56 | 00,000,452 | —- | M] () – C:\WINDOWS\Tasks\RegCure Program Check.job
[2009/01/08 08:27:28 | 00,000,386 | —- | M] () – C:\WINDOWS\Tasks\RegCure.job
[2009/03/12 21:18:20 | 00,000,006 | -H– | M] () – C:\WINDOWS\Tasks\SA.DAT

========== Purity Check ==========


========== Alternate Data Streams ==========

@Alternate Data Stream - 0 bytes -> C:\Documents and Settings\Jill Menezes\My Documents\Thumbs.db:encryptable
@Alternate Data Stream - 0 bytes -> C:\Documents and Settings\Jill Menezes\Desktop\Thumbs.db:encryptable
< End of report >
Extras (OTListlt 2) Log: ————————————————————————————————–

OTListIt Extras logfile created on: 3/12/2009 10:15:47 PM - Run 1
OTListIt2 by OldTimer - Version 2.0.3.5 Folder = C:\Documents and Settings\Jill Menezes\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.11)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

1022.98 Mb Total Physical Memory | 609.19 Mb Available Physical Memory | 59.55% Memory free
2.41 Gb Paging File | 1.99 Gb Available in Paging File | 82.66% Paging File free
Paging file location(s): C:\pagefile.sys 1536 3072;

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 37.21 Gb Total Space | 18.28 Gb Free Space | 49.14% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
Drive F: | 123.72 Mb Total Space | 85.82 Mb Free Space | 69.37% Space Free | Partition Type: FAT
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: OFFICE1
Current User Name: Jill Menezes
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Output = Minimal
File Age = 30 Days
Company Name Whitelist: On

========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.html [@ = htmlfile] – C:\Program Files\Internet Explorer\IEXPLORE.EXE (Microsoft Corporation)

[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.html [@ = FirefoxHTML] – C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"AntiVirusDisableNotify" = 1
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 0
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile
"EnableFirewall" = 1
"DoNotAllowExceptions" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts]

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
C:\Program Files\AVG\AVG8\avgupd.exe:*:Enabled:avgupd.exe (AVG Technologies CZ, s.r.o.)
C:\Program Files\AVG\AVG8\avgnsx.exe:*:Enabled:avgnsx.exe (AVG Technologies CZ, s.r.o.)

========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{07287123-B8AC-41CE-8346-3D777245C35B}" = Bonjour
"{0FABD3D7-3036-4e78-B29D-58957ADB0A12}" = HP PSC & OfficeJet 3.5
"{115E8183-866A-11D3-97DF-0000F8D8F2E9}" = Symantec pcAnywhere
"{1E04F83B-2AB9-4301-9EF7-E86307F79C72}" = Google Earth
"{216AB108-2AE1-4130-B3D5-20B2C4C80F8F}" = QuickTime
"{24C8FBF7-26C6-48ca-834B-A4E5C09E362F}" = AiO_Scan
"{257EC58E-03FD-472B-A9B6-93F23A3C4CB0}" = Scan
"{2BBC9458-07CA-4843-848B-5C8146E5EFA8}" = CreativeProjects
"{2E132061-C78A-48D4-A899-1D13B9D189FA}" = Memories Disc Creator 2.0
"{300D9EF4-2721-4cb4-A6C3-FB2337CFEA2D}" = AIOMinimal
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{3AE681E0-4E8D-453F-950A-48534D3C0724}" = Copy
"{3C50A915-DD33-4802-B83B-9EA997D3337B}" = Intel ® Pro Alerting Agent
"{3CF78481-FB7B-4B51-99A2-D5E0CD0B3AAF}" = HPSystemDiagnostics
"{5421155F-B033-49DB-9B33-8F80F233D4D5}" = GdiplusUpgrade
"{55584E16-4D70-44EE-93DD-F144E8B7D4B7}" = QuickBooks Product Listing Service
"{57C7C46A-D35D-492d-A328-4F8C9B5B4B52}" = PrintScreen
"{595D0DE8-C38A-4432-B851-47DECC1A99BD}" = HP Unload DLL Patch
"{5A0C892E-FD1C-4203-941E-0956AED20A6A}" = APC PowerChute Personal Edition
"{5A3F6A80-7913-475E-8B96-477A952CFA43}" = SupportSoft Assisted Service
"{609F7AC8-C510-11D4-A788-009027ABA5D0}" = Easy CD Creator 5 Basic
"{625BD732-ACDF-4552-BF22-98EBB413B6F3}" = McAfee Shredder
"{62F79C52-E264-44ab-ABC2-7BEA2962C70D}" = 5500Trb
"{63F2408D-A675-4d97-A256-70EACB6B9B4A}" = AiOSoftware
"{6811CAA0-BF12-11D4-9EA1-0050BAE317E1}" = PowerDVD
"{6D4E56A1-22EE-44d8-BD14-7B9FB7F80D1B}" = 5500_Help
"{7148F0A8-6813-11D6-A77B-00B0D0142000}" = Java 2 Runtime Environment, SE v1.4.2
"{716E0306-8318-4364-8B8F-0CC4E9376BAC}" = MSXML 4.0 SP2 Parser and SDK
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{73C23496-A105-4b6f-B8F0-22523DFE4E4E}" = 5500
"{73F1BDB7-11E1-11D5-9DC6-00C04F2FC33B}" = OMCI
"{766273C1-A39B-47EB-ACE8-DEBDD8094BCC}" = overland
"{7E545666-F422-45FD-B3DF-C0B99A1A579F}" = QuickBooks Pro 2007
"{7F142D56-3326-11D5-B229-002078017FBF}" = Modem Helper
"{8777AC6D-89F9-4793-8266-DE406F343E89}" = QFolder
"{90120000-0020-0409-0000-0000000FF1CE}" = Compatibility Pack for the 2007 Office system
"{90D55A3F-1D99-4C94-A77E-46DC14F0BF08}" = Help and Support Customization
"{91110409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office Professional Edition 2003
"{981FB376-8418-4EA8-BBED-9DE5AA63E7D5}" = SkinsHP1
"{98DF85D9-96C0-4F57-A92E-C3539477EF5E}" = DVDSentry
"{9CB2512B-3EC4-43DF-8002-46BDAB5EDD1B}" = QuickProjects
"{A1DCC235-DACC-4E1F-8D11-D630634B4AEF}" = PhotoGallery
"{A2500497-FD32-493e-B8E5-28D6728DBEF5}" = Readme
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{A790BEB1-BCCF-4EC6-807B-5708B36E8A79}" = Intel® PROSet
"{AC76BA86-0000-0000-0000-6028747ADE01}" = Adobe Acrobat - Reader 6.0.2 Update
"{AC76BA86-0000-7EC8-7489-000000000603}" = Adobe Acrobat and Reader 6.0.3 Update
"{AC76BA86-0000-7EC8-7489-000000000604}" = Adobe Acrobat and Reader 6.0.4 Update
"{AC76BA86-0000-7EC8-7489-000000000605}" = Adobe Acrobat and Reader 6.0.5 Update
"{AC76BA86-0000-7EC8-7489-000000000606}" = Adobe Acrobat and Reader 6.0.6 Update
"{AC76BA86-1033-0000-BA7E-000000000001}" = Adobe Acrobat 6.0.1 Standard
"{AC76BA86-7AD7-1033-7B44-A81000000003}" = Adobe Reader 8.1.1
"{AC76BA86-7AD7-1033-7B44-A81200000003}" = Adobe Reader 8.1.2
"{AF226123-1A6F-4ec1-8DEF-E35E7A0D0127}" = Fax
"{B32C75F2-7495-4D01-9431-C11E97D66F8C}" = DocProc
"{B3D5D4E0-E965-41C4-ABFD-A7B1AD0663C2}" = Director
"{B45D9FEE-1AF4-46F3-9A83-2545F81547F5}" = CreativeProjectsTemplates
"{B56D5B09-C4FB-4EA0-8EAD-7BC3E2715A2D}" = DocumentViewer
"{B5FDA445-CAC4-4BA6-A8FB-A7212BD439DE}" = Microsoft XML Parser
"{BC339BFD-F550-471a-8D26-4D08126C62F7}" = SkinsHP2
"{BCC992E5-5C81-4066-9B55-03DC10B24D21}" = InstantShare
"{BF018D2F-C788-4AB1-AB95-1280EAB8F13E}" = TrayApp
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{C4BA56E6-3DA9-4454-AD39-81FB11810984}" = McAfee VirusScan Professional Bonus Pack
"{C544F99D-39EF-4E6D-95BE-4E41C1D8C4CB}" = Dr Watson for Microsoft Windows OneCare Live v1.1.1067.14
"{CAE7D1D9-3794-4169-B4DD-964ADBC534EE}" = HP Product Detection
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{CDBFDD5B-50E0-4021-94AF-516B80509ABE}" = 5500Tour
"{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}" = SUPERAntiSpyware Professional
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{D186329B-1B4D-408D-ABEC-EA5CE1F182C9}" = Overland
"{DCC72248-D3D2-4846-8499-A400053A430E}" = TWC User Controls
"{DED53B0B-B67C-4244-AE6A-D6FD3C28D1EF}" = Ad-Aware
"{E646DCF0-5A68-11D5-B229-002078017FBF}" = Digital Line Detect
"{EC4455AB-F155-4CC1-A4C5-88F3777F9886}" = Apple Mobile Device Support
"{EC8673DA-F96B-497E-B2DB-BC7B029FD680}" = BufferChm
"{F333A33D-125C-32A2-8DCE-5C5D14231E27}" = Visual C++ 2008 x86 Runtime - (v9.0.30729)
"{F333A33D-125C-32A2-8DCE-5C5D14231E27}.vc_x86runtime_30729_01" = Visual C++ 2008 x86 Runtime - v9.0.30729.01
"{F4F47155-5B4D-42AA-97F8-490BC52EA7F3}" = Destinations
"{F5C63795-2708-4D15-BF18-5ABBFF7DFFC8}" = iTunes
"{F65787F3-B356-45EC-8DD0-0E6758EDBCEE}" = WebReg
"{FF102450-55AA-4AE1-ACE4-E271E2470C83}" = hpmdtab
"{FF26F7EA-BCEE-478C-9A1B-6B4F88717D73}" = CueTour
"Ad-Aware" = Ad-Aware
"Adobe Atmosphere Player" = Adobe Atmosphere Player for Acrobat and Adobe Reader
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"AMP Calendar" = AMP Calendar
"AVG8Uninstall" = AVG Free 8.0
"CNXT_MODEM_PCI_VEN_14F1&DEV_2702" = Conexant SmartHSFi V92 56K Speakerphone PCI Modem
"CNXT_MODEM_PCI_VEN_14F1&DEV_2F20&SUBSYS_200F14F1" = Conexant D850 56K V.9x DFVc Modem
"Free PS Convert driver_is1" = Free PS Convert driver
"HijackThis" = HijackThis 2.0.2
"HP Photo & Imaging" = HP Image Zone 4.2
"IDNMitigationAPIs" = Microsoft Internationalized Domain Names Mitigation APIs
"ie7" = Windows Internet Explorer 7
"LiveReg" = LiveReg (Symantec Corporation)
"LiveUpdate" = LiveUpdate 2.5 (Symantec Corporation)
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Mozilla Firefox (3.0.7)" = Mozilla Firefox (3.0.7)
"MSCompPackV1" = Microsoft Compression Client Pack 1.0 for Windows XP
"MSN Music Assistant" = MSN Music Assistant
"NLSDownlevelMapping" = Microsoft National Language Support Downlevel APIs
"NVIDIA" = NVIDIA Windows 2000/XP Display Drivers
"NVIDIA Display Driver" = NVIDIA Display Driver
"PROSet" = Intel® PRO Network Adapters and Drivers
"RealPlayer 6.0" = RealPlayer
"RegCure" = RegCure 1.5.0.1
"Surveyor_is1" = Surveyor [removed]
"Windows Media Format Runtime" = Windows Media Format 11 runtime
"Windows Media Player" = Windows Media Player 11
"Windows XP Service Pack" = Windows XP Service Pack 3
"WinZip" = WinZip
"WMFDist11" = Windows Media Format 11 runtime
"wmp11" = Windows Media Player 11
"Wudf01000" = Microsoft User-Mode Driver Framework Feature Pack 1.0

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 3/3/2009 12:59:56 PM | Computer Name = OFFICE1 | Source = AVG7 | ID = 100
Description =

Error - 3/3/2009 12:59:56 PM | Computer Name = OFFICE1 | Source = AVG7 | ID = 100
Description =

Error - 3/3/2009 1:00:34 PM | Computer Name = OFFICE1 | Source = AVG7 | ID = 100
Description =

Error - 3/3/2009 1:01:24 PM | Computer Name = OFFICE1 | Source = AVG7 | ID = 100
Description =

Error - 3/3/2009 2:43:31 PM | Computer Name = OFFICE1 | Source = Application Hang | ID = 1002
Description = Hanging application explorer.exe, version 6.0.2900.5512, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.

Error - 3/10/2009 8:03:24 AM | Computer Name = OFFICE1 | Source = Lavasoft Ad-Aware Service | ID = 0
Description =

Error - 3/11/2009 7:05:32 PM | Computer Name = OFFICE1 | Source = Lavasoft Ad-Aware Service | ID = 0
Description =

Error - 3/11/2009 7:06:46 PM | Computer Name = OFFICE1 | Source = Lavasoft Ad-Aware Service | ID = 0
Description =

Error - 3/12/2009 3:40:56 AM | Computer Name = OFFICE1 | Source = Lavasoft Ad-Aware Service | ID = 0
Description =

Error - 3/12/2009 5:43:31 AM | Computer Name = OFFICE1 | Source = Lavasoft Ad-Aware Service | ID = 0
Description =

[ System Events ]
Error - 3/12/2009 1:38:04 PM | Computer Name = OFFICE1 | Source = DCOM | ID = 10005
Description = DCOM got error "%1058" attempting to start the service Iap with arguments
"-Service" in order to run the server: {B0C61A79-0870-4BE4-9153-9CCAF422E31F}

Error - 3/12/2009 1:38:04 PM | Computer Name = OFFICE1 | Source = DCOM | ID = 10005
Description = DCOM got error "%1058" attempting to start the service Iap with arguments
"-Service" in order to run the server: {B0C61A79-0870-4BE4-9153-9CCAF422E31F}

Error - 3/12/2009 1:38:08 PM | Computer Name = OFFICE1 | Source = DCOM | ID = 10005
Description = DCOM got error "%1058" attempting to start the service Iap with arguments
"-Service" in order to run the server: {B0C61A79-0870-4BE4-9153-9CCAF422E31F}

Error - 3/12/2009 1:38:08 PM | Computer Name = OFFICE1 | Source = DCOM | ID = 10005
Description = DCOM got error "%1058" attempting to start the service Iap with arguments
"-Service" in order to run the server: {B0C61A79-0870-4BE4-9153-9CCAF422E31F}

Error - 3/12/2009 1:48:02 PM | Computer Name = OFFICE1 | Source = DCOM | ID = 10005
Description = DCOM got error "%1058" attempting to start the service Iap with arguments
"-Service" in order to run the server: {B0C61A79-0870-4BE4-9153-9CCAF422E31F}

Error - 3/12/2009 6:57:46 PM | Computer Name = OFFICE1 | Source = DCOM | ID = 10005
Description = DCOM got error "%1058" attempting to start the service Iap with arguments
"-Service" in order to run the server: {B0C61A79-0870-4BE4-9153-9CCAF422E31F}

Error - 3/12/2009 6:57:46 PM | Computer Name = OFFICE1 | Source = DCOM | ID = 10005
Description = DCOM got error "%1058" attempting to start the service Iap with arguments
"-Service" in order to run the server: {B0C61A79-0870-4BE4-9153-9CCAF422E31F}

Error - 3/12/2009 6:57:48 PM | Computer Name = OFFICE1 | Source = DCOM | ID = 10005
Description = DCOM got error "%1058" attempting to start the service Iap with arguments
"-Service" in order to run the server: {B0C61A79-0870-4BE4-9153-9CCAF422E31F}

Error - 3/12/2009 6:57:48 PM | Computer Name = OFFICE1 | Source = DCOM | ID = 10005
Description = DCOM got error "%1058" attempting to start the service Iap with arguments
"-Service" in order to run the server: {B0C61A79-0870-4BE4-9153-9CCAF422E31F}

Error - 3/12/2009 6:57:52 PM | Computer Name = OFFICE1 | Source = DCOM | ID = 10005
Description = DCOM got error "%1058" attempting to start the service Iap with arguments
"-Service" in order to run the server: {B0C61A79-0870-4BE4-9153-9CCAF422E31F}


< End of report >
Opening (clicking on) the shortcut to RenHosts produced a red box like the illustration EXCEPT: Top line: "The system cannot find the file specified." Box displays: "Hosts file blocking is now de-activated" "X" (advertising will be visible…etc etc…) Press any key to continue…. I pressed , the box disappeared. Opening (clicking on) the shortcut to RenHosts again DID NOT produce the 2nd box. BTW, before I contacted WhattheTech I downloaded a fresh copy of Mozilla Firefox and installed it, setting that to my default browser. I've been using the fresh copy of Firefox to communicate with you. Just tried using IE to do the same, and I get message: "you are not allowed to reply to this posting". It feels like IE is majorly corrupted. March 3rd was the date that I had a service tech to my home to remove Virus Melt from this computer. (my daughter had clicked on a popup link the previous evening). Fortunately, I had NOT clicked on any of the rogue popups that infected my machine, so my files stayed relatively OK. It was obviously a serious infection, however, so I called a tech outfit to clean it. I'm thinking that he missed something, enabling the search engines to be hijacked. I contacted the service & told them the service hadn't finished the job and he got defensive & told me it was a NEW infection. Would appreciate your opinion. This thing is so stubborn I'm thinking it would be best to contact the local tech service again rather than try to work it out myself, even with your help. I'm not a tech, and I'm afraid to make a mistake.
I have no problem helping you out with this, but if I were you I would go back to them and tell them they did not finish their job. The infection corrupted the Hosts file, and from the OTScan I can see when…

[2009/03/03 00:45:06 | 00,007,853 | -HS- | M] () – C:\WINDOWS\System32\drivers\ETC\hosts

They also left a folder (or 2) behind from Virus Melt.

[2009/03/02 23:47:44 | 00,000,000 | -HSD | C] – C:\Documents and Settings\Jill Menezes\Application Data\Virus Melt
[2009/03/02 23:47:33 | 00,000,000 | -HSD | C] – C:\Documents and Settings\All Users\Application Data\System Data

I can see they used combofix and didn't clean up after it properly either….

[2009/03/03 13:21:44 | 00,000,000 | —D | C] – C:\QooBox

There are likely infected files in the Qoobox folder do don't click on anything in there.

I imagine you paid good money for them to do the job properly and this is proof they did not. I would suggest you print this post out and bring it to them as evidence that they did not finish the job.

But if you want me to guide you through this that's okay too. Let me know.

Regards,
Dave

EDIT:

Just tried using IE to do the same, and I get message: "you are not allowed to reply to this posting". It feels like IE is majorly corrupted.

Are you signed in?
Thanks Dave. I contacted the service and they worked on my computer remotely for a couple of hours and cleaned up a lot of 'stuff'. If bad things keep happening, I will follow up with them. I appreciate your input - it gave me credibility when I re-contacted them. Meanwhile, I will invite them to read the forum postings to see what we did. Thanks again, ~ Jill M.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI