This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] something attempts to connect to known malware sites

17 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

compaq cnr751 laptop, vista Home Prem., running (since day 1)zonealarm pro & had avg free for awhile then changed to avast AV (free) , windows update is on automatic download & ask. + resident scanners: spysweeper(free), threatfire, spybot s&d,

about a week ago, webroot spysweeper (free/scan only version) started showing numberous alerts that it was blocking attempts to connect to known malware sites. It's log file shows a new site attempted repeatedly abt every 50 seconds. Unfortunately it doesnt I.D. WHAT is doing this.

the spysweeper alert msg is this: "The Internet Communication shield has blocked access to:(enter ur favorite malware site name :pullhair: )"

i have installed, updated and run about a known utilites w/o any results.: zonealarm pro's spyware sweep, spysweeper, spybot s&d, spyware doctor, spyware blaster, spyware terminator, threatfire, ad-aware, Malwarebytes' Anti-Malware, SUPERAntiSpyware, windows defender(for what thats worth). also ran some rootkit scanners: Avira RootKit Detection, GMER, SanityCheck, … rootkitrevealer, & sophos antirootkit wont install/run
so far nothing - other than the usual 1-3 cookies, and false alarm w/ c:\windows\system\drivers\Launcher.exe(part of the HP/compaq factory software)

as requested by the faq, heres the hijackthis log - ran it, as administrator from a user, not administrator account.

Thanks!

————————
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 8:14:10 PM, on 3/16/2009
Platform: Windows Vista SP1 (WinNT 6.00.1905)
MSIE: Internet Explorer v7.00 (7.00.6001.18000)
Boot mode: Normal

Running processes:
C:\Windows\System32\smss.exe
C:\Windows\system32\csrss.exe
C:\Windows\system32\wininit.exe
C:\Windows\system32\csrss.exe
C:\Windows\system32\services.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\winlogon.exe
C:\Windows\system32\svchost.exe
C:\Util\Security\Spy Sweeper\WRConsumerService.exe
C:\Windows\system32\svchost.exe
C:\Windows\System32\svchost.exe
C:\Windows\System32\svchost.exe
C:\Windows\System32\svchost.exe
C:\Windows\system32\svchost.exe
C:\Windows\system32\SLsvc.exe
C:\Windows\system32\svchost.exe
C:\Windows\system32\svchost.exe
C:\Windows\System32\ZoneLabs\vsmon.exe
C:\Windows\system32\WLANExt.exe
C:\Util\Security\Alwil Software\Avast\aswUpdSv.exe
C:\Util\Security\Alwil Software\Avast\ashServ.exe
C:\Util\Security\Lavasoft\Ad-Aware\AAWService.exe
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe
C:\Windows\system32\taskeng.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\Windows\system32\svchost.exe
C:\Util\Security\Spyware Terminator\sp_rsser.exe
c:\Program Files\Microsoft SQL Server\90\Shared\sqlbrowser.exe
c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
C:\Util\Security\ThreatFire\TFService.exe
C:\Util\Security\Spy Sweeper\SpySweeper.exe
C:\Windows\System32\svchost.exe
C:\Windows\system32\SearchIndexer.exe
C:\Windows\system32\Dwm.exe
C:\Windows\system32\DRIVERS\xaudio.exe
C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
C:\Windows\Explorer.EXE
C:\Util\Security\Spybot - Search & Destroy\SDWinSec.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Util\Security\Alwil Software\Avast\ashMaiSv.exe
C:\Util\Security\Alwil Software\Avast\ashWebSv.exe
C:\Program Files\Synaptics\SynTP\SynTPStart.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Windows\System32\igfxpers.exe
C:\Windows\system32\igfxsrvc.exe
C:\Windows\System32\hkcmd.exe
C:\Util\Security\ZoneAlarm\zlclient.exe
C:\Util\Security\Alwil Software\Avast\ashDisp.exe
C:\Windows\system32\taskeng.exe
C:\Util\Security\Spyware Terminator\SpywareTerminatorShield.Exe
C:\Util\Security\ThreatFire\TFTray.exe
C:\Util\Security\Lavasoft\Ad-Aware\AAWTray.exe
C:\Util\Security\Spy Sweeper\SpySweeperUI.exe
C:\Util\Security\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Util\Security\Spy Sweeper\SSU.EXE
C:\Telecom\Internet\PMAIL\Programs\winpm-32.exe
C:\Windows\system32\taskeng.exe
C:\Util\Security\Trend Micro\HijackThis\HijackThis.exe
C:\Windows\system32\wbem\wmiprvse.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://home.mchsi.com/~auntlorrie
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…O&pf=laptop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…O&pf=laptop
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Telecom\Internet\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O2 - BHO: QFX Software KeyScrambler - {2B9F5787-88A5-4945-90E7-C4B18563BC5E} - C:\Util\Security\KeyScrambler\KeyScramblerIE.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Util\Security\SPYBOT~1\SDHelper.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll
O2 - BHO: Java™ Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O4 - HKLM\..\Run: [SynTPStart] "C:\Program Files\Synaptics\SynTP\SynTPStart.exe"
O4 - HKLM\..\Run: [SynTPEnh] "C:\Program Files\Synaptics\SynTP\SynTPEnh.exe"
O4 - HKLM\..\Run: [Kernel and Hardware Abstraction Layer] "C:\Windows\KHALMNPR.EXE"
O4 - HKLM\..\Run: [Persistence] "C:\Windows\system32\igfxpers.exe"
O4 - HKLM\..\Run: [IgfxTray] "C:\Windows\system32\igfxtray.exe"
O4 - HKLM\..\Run: [HotKeysCmds] "C:\Windows\system32\hkcmd.exe"
O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Util\Security\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [avast!] C:\Util\Security\ALWILS~1\Avast\ashDisp.exe
O4 - HKLM\..\Run: [SpywareTerminator] "C:\Util\Security\Spyware Terminator\SpywareTerminatorShield.exe"
O4 - HKLM\..\Run: [ThreatFire] "C:\Util\Security\ThreatFire\TFTray.exe"
O4 - HKLM\..\Run: [Ad-Watch] "C:\Util\Security\Lavasoft\Ad-Aware\AAWTray.exe"
O4 - HKLM\..\Run: [SpySweeper] "C:\Util\Security\Spy Sweeper\SpySweeperUI.exe" /startintray
O4 - HKCU\..\Run: [SpybotSD TeaTimer] "C:\Util\Security\Spybot - Search & Destroy\TeaTimer.exe"
O4 - HKUS\S-1-5-21-3722091140-1563400330-3389692580-1001\..\Run: [SpybotSD TeaTimer] "C:\Util\Security\Spybot - Search & Destroy\TeaTimer.exe" (User 'HP')
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra button: (no name) - {5C106A59-CC3C-4caa-81A4-6D909B5ACE23} - C:\Util\Security\KeyScrambler\KeyScramblerIE.dll
O9 - Extra 'Tools' menuitem: &KeyScrambler… - {5C106A59-CC3C-4caa-81A4-6D909B5ACE23} - C:\Util\Security\KeyScrambler\KeyScramblerIE.dll
O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Telecom\Internet\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Util\Security\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Util\Security\SPYBOT~1\SDHelper.dll
O13 - Gopher Prefix:
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedC…n/bin/cabsa.cab
O16 - DPF: {BDBDE413-7B1C-4C68-A8FF-C5B2B4090876} (F-Secure Online Scanner 3.3) - http://support.f-secure.com/ols/fscax.cab
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - Winlogon Notify: !SASWinLogon - C:\Util\Security\SUPERAntiSpyware\SASWINLO.dll
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Util\Security\Alwil Software\Avast\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Util\Security\Alwil Software\Avast\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Util\Security\Alwil Software\Avast\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Util\Security\Alwil Software\Avast\ashWebSv.exe
O23 - Service: Com4Qlb - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\Com4Qlb.exe
O23 - Service: Seagate Service (FreeAgentGoNext Service) - Seagate Technology LLC - C:\Util\AddOns\Seagate\SeagateManager\Sync\FreeAgentService.exe
O23 - Service: HP Health Check Service - Hewlett-Packard - C:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe
O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Lavasoft Ad-Aware Service - Lavasoft - C:\Util\Security\Lavasoft\Ad-Aware\AAWService.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: MHPHAAJC - Unknown owner - c:\temp\WinTemp\MHPHAAJC.exe (file missing)
O23 - Service: NBService - Nero AG - C:\Util\CD-DVD\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
O23 - Service: nmraapache - Nero AG - (no file)
O23 - Service: RoxMediaDB9 - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
O23 - Service: SBSD Security Center Service (SBSDWSCService) - Safer Networking Ltd. - C:\Util\Security\Spybot - Search & Destroy\SDWinSec.exe
O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\svcntaux.exe
O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\swdsvc.exe
O23 - Service: Spyware Terminator Realtime Shield Service (sp_rssrv) - Crawler.com - C:\Util\Security\Spyware Terminator\sp_rsser.exe
O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe
O23 - Service: TeamViewer 3 (TeamViewer) - Unknown owner - C:\Telecom\Internet\TeamViewer3\TeamViewer_Host.exe
O23 - Service: ThreatFire - PC Tools - C:\Util\Security\ThreatFire\TFService.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Check Point Software Technologies LTD - C:\Windows\System32\ZoneLabs\vsmon.exe
O23 - Service: Webroot Spy Sweeper Engine (WebrootSpySweeperService) - Webroot Software, Inc. (www.webroot.com) - C:\Util\Security\Spy Sweeper\SpySweeper.exe
O23 - Service: Webroot Client Service (WRConsumerService) - Webroot Software, Inc. - C:\Util\Security\Spy Sweeper\WRConsumerService.exe
O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe

–
End of file - 11295 bytes
Hi and :welcome:

sorry for the delay,

If you still need help with your machine, please do the following:

  • Download OTListIt2 to your desktop.
  • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output.
  • Check the boxes beside LOP Check and Purity Check.
  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
  • When the scan completes, it will open two notepad windows. OTListIt.Txt and Extras.Txt.
    Note:These logs can be located in the OTListIt2. folder on you C:\ drive if they fail to open automatically.
  • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post it with your next reply. You may need two posts to fit them both in.
questions - 1)does it matter which user account i run this from? i have an admin level account and 3 regular user accts. normal use is from one of the regular user accts. 2) should i also rt. clk and "run as administrator" ? THANKS!
just fyi - i dont know if its related or not, but had trouble getitng the administrator acct to finish loading after login. had to power off to reboot to safe mode and then reboot to regular mode 2x b4 it would.
i didnt change any settings – but i did have the laptops wireless "power button" switched off so maybe it had something to do w/ it. - been leaving it off most of the time since this problem started. 3rd reboot i tried having it on.
windows update and some of the other resident anti-malware programs were trying to update. i put off the updates that asked. but some were automatic.
scan was done after 3rd attempt to logon worked.
firefox auto-loaded a bunch of updates (firefox v3.07 + plugin updates) after the scan. will rerun the scan if u think i should.

heres the 1st log file - OTListIt.txt…

——-
OTListIt logfile created on: 3/23/2009 4:19:27 PM - Run 2
OTListIt2 by OldTimer - Version 2.0.7.1 Folder = C:\Users\Administrator\Desktop
Windows Vista Home Premium Edition Service Pack 1 (Version = 6.0.6001) - Type = NTWorkstation
Internet Explorer (Version = 7.0.6001.18000)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

1.99 Gb Total Physical Memory | 1.06 Gb Available Physical Memory | 53.50% Memory free
4.00 Gb Paging File | 3.05 Gb Available in Paging File | 76.13% Paging File free
Paging file location(s): ?:\pagefile.sys;

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 66.48 Gb Total Space | 8.66 Gb Free Space | 13.03% Space Free | Partition Type: NTFS
Drive D: | 8.04 Gb Total Space | 7.77 Gb Free Space | 96.66% Space Free | Partition Type: NTFS
Drive E: | 4.30 Gb Total Space | 0.00 Gb Free Space | 0.00% Space Free | Partition Type: CDFS
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: LORIS-COMPAQ
Current User Name: Administrator
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Output = Minimal
File Age = 30 Days
Company Name Whitelist: On

========== Processes (SafeList) ==========

PRC - C:\Util\Security\Spy Sweeper\WRConsumerService.exe (Webroot Software, Inc. )
PRC - C:\Windows\System32\ZoneLabs\vsmon.exe (Check Point Software Technologies LTD)
PRC - C:\Util\Security\Alwil Software\Avast\aswUpdSv.exe (ALWIL Software)
PRC - C:\Util\Security\Alwil Software\Avast\ashServ.exe (ALWIL Software)
PRC - C:\Util\Security\Lavasoft\Ad-Aware\AAWService.exe (Lavasoft)
PRC - C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe (Microsoft Corporation)
PRC - C:\Util\Security\Spyware Terminator\sp_rsser.exe (Crawler.com)
PRC - c:\Program Files\Microsoft SQL Server\90\Shared\sqlbrowser.exe (Microsoft Corporation)
PRC - c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe (Microsoft Corporation)
PRC - C:\Util\Security\ThreatFire\TFService.exe (PC Tools)
PRC - C:\Util\Security\Spy Sweeper\SpySweeper.exe (Webroot Software, Inc. (www.webroot.com))
PRC - C:\Windows\system32\DRIVERS\xaudio.exe (Conexant Systems, Inc.)
PRC - C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe (Hewlett-Packard Development Company, L.P.)
PRC - C:\Util\Security\Spybot - Search & Destroy\SDWinSec.exe (Safer Networking Ltd.)
PRC - C:\Windows\system32\wbem\unsecapp.exe (Microsoft Corporation)
PRC - C:\Util\Security\Alwil Software\Avast\ashMaiSv.exe (ALWIL Software)
PRC - C:\Util\Security\Alwil Software\Avast\ashWebSv.exe (ALWIL Software)
PRC - C:\Windows\system32\wbem\wmiprvse.exe (Microsoft Corporation)
PRC - C:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe (Hewlett-Packard)
PRC - C:\Windows\Explorer.EXE (Microsoft Corporation)
PRC - C:\Program Files\Synaptics\SynTP\SynTPStart.exe (Synaptics, Inc.)
PRC - C:\Program Files\Synaptics\SynTP\SynTPEnh.exe (Synaptics, Inc.)
PRC - C:\Windows\System32\igfxpers.exe (Intel Corporation)
PRC - C:\Windows\System32\hkcmd.exe (Intel Corporation)
PRC - C:\Windows\system32\igfxsrvc.exe (Intel Corporation)
PRC - C:\Util\Security\ZoneAlarm\zlclient.exe (Check Point Software Technologies LTD)
PRC - C:\Util\Security\Alwil Software\Avast\ashDisp.exe (ALWIL Software)
PRC - C:\Util\Security\Spyware Terminator\SpywareTerminatorShield.Exe (Crawler.com)
PRC - C:\Util\Security\ThreatFire\TFTray.exe (PC Tools)
PRC - C:\Windows\system32\wbem\unsecapp.exe (Microsoft Corporation)
PRC - C:\Util\Security\Lavasoft\Ad-Aware\AAWTray.exe (Lavasoft)
PRC - C:\Util\Security\Spybot - Search & Destroy\TeaTimer.exe (Safer-Networking Ltd.)
PRC - C:\Users\Administrator\Desktop\OTListIt2.exe (OldTimer Tools)
PRC - C:\Windows\notepad.exe (Microsoft Corporation)

========== Win32 Services (SafeList) ==========

SRV - (AdeonaClientService [Disabled | Stopped]) – C:\Util\AddOns\Adeona\cygrunsrv.exe ()
SRV - (Apple Mobile Device [Disabled | Stopped]) – C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe (Apple Inc.)
SRV - (aswUpdSv [Auto | Running]) – C:\Util\Security\Alwil Software\Avast\aswUpdSv.exe (ALWIL Software)
SRV - (avast! Antivirus [Auto | Running]) – C:\Util\Security\Alwil Software\Avast\ashServ.exe (ALWIL Software)
SRV - (avast! Mail Scanner [On_Demand | Running]) – C:\Util\Security\Alwil Software\Avast\ashMaiSv.exe (ALWIL Software)
SRV - (avast! Web Scanner [On_Demand | Running]) – C:\Util\Security\Alwil Software\Avast\ashWebSv.exe (ALWIL Software)
SRV - (BcmSqlStartupSvc [On_Demand | Stopped]) – C:\Program Files\Microsoft Small Business\Business Contact Manager\BcmSqlStartupSvc.exe (Microsoft Corporation)
SRV - (Bonjour Service [Disabled | Stopped]) – C:\Program Files\Bonjour\mDNSResponder.exe (Apple Inc.)
SRV - (clr_optimization_v2.0.50727_32 [On_Demand | Stopped]) – C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
SRV - (Com4Qlb [On_Demand | Stopped]) – C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\Com4Qlb.exe (Hewlett-Packard Development Company, L.P.)
SRV - (ehRecvr [On_Demand | Stopped]) – C:\Windows\ehome\ehRecvr.exe (Microsoft Corporation)
SRV - (ehSched [On_Demand | Stopped]) – C:\Windows\ehome\ehsched.exe (Microsoft Corporation)
SRV - (ehstart [Auto | Stopped]) – C:\Windows\ehome\ehstart.dll (Microsoft Corporation)
SRV - (EPMGXAG [Disabled | Stopped]) – File not found
SRV - (FontCache3.0.0.0 [On_Demand | Stopped]) – C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe (Microsoft Corporation)
SRV - (FreeAgentGoNext Service [On_Demand | Stopped]) – C:\Util\AddOns\Seagate\SeagateManager\Sync\FreeAgentService.exe (Seagate Technology LLC)
SRV - (gusvc [Disabled | Stopped]) – C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe (Google)
SRV - (GYY [Disabled | Stopped]) – File not found
SRV - (HP Health Check Service [Auto | Running]) – C:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe (Hewlett-Packard)
SRV - (hpqwmiex [Auto | Running]) – C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe (Hewlett-Packard Development Company, L.P.)
SRV - (IDriverT [On_Demand | Stopped]) – C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe (Macrovision Corporation)
SRV - (idsvc [Unknown | Stopped]) – C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe (Microsoft Corporation)
SRV - (iPod Service [Disabled | Stopped]) – C:\Program Files\iPod\bin\iPodService.exe (Apple Inc.)
SRV - (Lavasoft Ad-Aware Service [Auto | Running]) – C:\Util\Security\Lavasoft\Ad-Aware\AAWService.exe (Lavasoft)
SRV - (LightScribeService [On_Demand | Stopped]) – C:\Program Files\Common Files\LightScribe\LSSrvc.exe (Hewlett-Packard Company)
SRV - (MDM [Auto | Running]) – C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe (Microsoft Corporation)
SRV - (MHPHAAJC [On_Demand | Stopped]) – File not found
SRV - (Microsoft Office Groove Audit Service [On_Demand | Stopped]) – C:\Program Files\Microsoft Office\Office12\GrooveAuditService.exe (Microsoft Corporation)
SRV - (MSCamSvc [On_Demand | Stopped]) – C:\Program Files\Microsoft LifeCam\MSCamS32.exe (Microsoft Corporation)
SRV - (MSSQL$MSSMLBIZ [On_Demand | Stopped]) – c:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe (Microsoft Corporation)
SRV - (MSSQLServerADHelper [Disabled | Stopped]) – c:\Program Files\Microsoft SQL Server\90\Shared\sqladhlp90.exe (Microsoft Corporation)
SRV - (NBService [On_Demand | Stopped]) – C:\Util\CD-DVD\Nero\Nero 7\Nero BackItUp\NBService.exe (Nero AG)
SRV - (NetTcpPortSharing [Disabled | Stopped]) – C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe (Microsoft Corporation)
SRV - (NMIndexingService [On_Demand | Stopped]) – C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe (Nero AG)
SRV - (nmraapache [On_Demand | Stopped]) – File not found
SRV - (odserv [On_Demand | Stopped]) – C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE (Microsoft Corporation)
SRV - (ose [On_Demand | Stopped]) – C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE (Microsoft Corporation)
SRV - (PAWC [Disabled | Stopped]) – File not found
SRV - (RoxMediaDB9 [On_Demand | Stopped]) – C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe (Sonic Solutions)
SRV - (S [Disabled | Stopped]) – File not found
SRV - (SBSDWSCService [Auto | Running]) – C:\Util\Security\Spybot - Search & Destroy\SDWinSec.exe (Safer Networking Ltd.)
SRV - (sdAuxService [On_Demand | Stopped]) – C:\Program Files\Spyware Doctor\svcntaux.exe (PC Tools)
SRV - (sdCoreService [On_Demand | Stopped]) – C:\Program Files\Spyware Doctor\swdsvc.exe (PC Tools)
SRV - (sp_rssrv [Auto | Running]) – C:\Util\Security\Spyware Terminator\sp_rsser.exe (Crawler.com)
SRV - (SQLBrowser [Auto | Running]) – c:\Program Files\Microsoft SQL Server\90\Shared\sqlbrowser.exe (Microsoft Corporation)
SRV - (SQLWriter [Auto | Running]) – c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe (Microsoft Corporation)
SRV - (stllssvr [On_Demand | Stopped]) – C:\Program Files\Common Files\SureThing Shared\stllssvr.exe (MicroVision Development, Inc.)
SRV - (TeamViewer [On_Demand | Stopped]) – C:\Telecom\Internet\TeamViewer3\TeamViewer_Host.exe ()
SRV - (ThreatFire [Auto | Running]) – C:\Util\Security\ThreatFire\TFService.exe (PC Tools)
SRV - (vsmon [Auto | Running]) – C:\Windows\System32\ZoneLabs\vsmon.exe (Check Point Software Technologies LTD)
SRV - (WebrootSpySweeperService [Auto | Running]) – C:\Util\Security\Spy Sweeper\SpySweeper.exe (Webroot Software, Inc. (www.webroot.com))
SRV - (WinDefend [Auto | Running]) – C:\Program Files\Windows Defender\mpsvc.dll (Microsoft Corporation)
SRV - (WLSetupSvc [On_Demand | Stopped]) – C:\Program Files\Windows Live\installer\WLSetupSvc.exe (Microsoft Corporation)
SRV - (WMPNetworkSvc [Disabled | Stopped]) – C:\Program Files\Windows Media Player\wmpnetwk.exe (Microsoft Corporation)
SRV - (WRConsumerService [Auto | Running]) – C:\Util\Security\Spy Sweeper\WRConsumerService.exe (Webroot Software, Inc. )
SRV - (XAudioService [Auto | Running]) – C:\Windows\system32\DRIVERS\xaudio.exe (Conexant Systems, Inc.)
SRV - (YRO [Disabled | Stopped]) – File not found

========== Driver Services (SafeList) ==========

DRV - (adp94xx [Disabled | Stopped]) – C:\Windows\system32\drivers\adp94xx.sys (Adaptec, Inc.)
DRV - (adpahci [Disabled | Stopped]) – C:\Windows\system32\drivers\adpahci.sys (Adaptec, Inc.)
DRV - (adpu160m [Disabled | Stopped]) – C:\Windows\system32\drivers\adpu160m.sys (Adaptec, Inc.)
DRV - (adpu320 [Disabled | Stopped]) – C:\Windows\system32\drivers\adpu320.sys (Adaptec, Inc.)
DRV - (aic78xx [Disabled | Stopped]) – C:\Windows\system32\drivers\djsvs.sys (Adaptec, Inc.)
DRV - (aliide [Disabled | Stopped]) – C:\Windows\system32\drivers\aliide.sys (Acer Laboratories Inc.)
DRV - (arc [Disabled | Stopped]) – C:\Windows\system32\drivers\arc.sys (Adaptec, Inc.)
DRV - (arcsas [Disabled | Stopped]) – C:\Windows\system32\drivers\arcsas.sys (Adaptec, Inc.)
DRV - (aswFsBlk [Auto | Running]) – C:\Windows\system32\DRIVERS\aswFsBlk.sys (ALWIL Software)
DRV - (aswMonFlt [Auto | Running]) – C:\Windows\system32\DRIVERS\aswMonFlt.sys (ALWIL Software)
DRV - (aswRdr [System | Running]) – C:\Windows\System32\drivers\aswRdr.sys (ALWIL Software)
DRV - (aswSP [System | Running]) – C:\Windows\System32\drivers\aswSP.sys (ALWIL Software)
DRV - (aswTdi [System | Running]) – C:\Windows\System32\drivers\aswTdi.sys (ALWIL Software)
DRV - (avipbb [System | Running]) – C:\Windows\system32\DRIVERS\avipbb.sys (Avira GmbH)
DRV - (BCM43XV [On_Demand | Stopped]) – C:\Windows\system32\DRIVERS\bcmwl6.sys (Broadcom Corporation)
DRV - (BCM43XX [On_Demand | Running]) – C:\Windows\system32\DRIVERS\bcmwl6.sys (Broadcom Corporation)
DRV - (BrFiltLo [On_Demand | Stopped]) – C:\Windows\system32\drivers\brfiltlo.sys (Brother Industries, Ltd.)
DRV - (BrFiltUp [On_Demand | Stopped]) – C:\Windows\system32\drivers\brfiltup.sys (Brother Industries, Ltd.)
DRV - (Brserid [Disabled | Stopped]) – C:\Windows\system32\drivers\brserid.sys (Brother Industries Ltd.)
DRV - (BrSerWdm [Disabled | Stopped]) – C:\Windows\system32\drivers\brserwdm.sys (Brother Industries Ltd.)
DRV - (BrUsbMdm [Disabled | Stopped]) – C:\Windows\system32\drivers\brusbmdm.sys (Brother Industries Ltd.)
DRV - (BrUsbSer [On_Demand | Stopped]) – C:\Windows\system32\drivers\brusbser.sys (Brother Industries Ltd.)
DRV - (cmdide [Disabled | Stopped]) – C:\Windows\system32\drivers\cmdide.sys (CMD Technology, Inc.)
DRV - (CnxtHdAudService [On_Demand | Running]) – C:\Windows\system32\drivers\CHDRT32.sys (Conexant Systems Inc.)
DRV - (DgiVecp [Auto | Stopped]) – C:\Windows\system32\Drivers\DgiVecp.sys (Samsung Electronics Co., Ltd.)
DRV - (E100B [On_Demand | Stopped]) – C:\Windows\system32\DRIVERS\e100b325.sys (Intel Corporation)
DRV - (E1G60 [On_Demand | Stopped]) – C:\Windows\system32\DRIVERS\E1G60I32.sys (Intel Corporation)
DRV - (eabfiltr [System | Running]) – C:\Windows\system32\DRIVERS\eabfiltr.sys (Hewlett-Packard Development Company, L.P.)
DRV - (elxstor [Disabled | Stopped]) – C:\Windows\system32\drivers\elxstor.sys (Emulex)
DRV - (GEARAspiWDM [On_Demand | Running]) – C:\Windows\System32\Drivers\GEARAspiWDM.sys (GEAR Software Inc.)
DRV - (gmer [On_Demand | Stopped]) – C:\Windows\System32\DRIVERS\gmer.sys (GMER)
DRV - (HBtnKey [On_Demand | Running]) – C:\Windows\system32\DRIVERS\cpqbttn.sys (Hewlett-Packard Development Company, L.P.)
DRV - (HdAudAddService [On_Demand | Stopped]) – C:\Windows\system32\drivers\CHDART.sys (Conexant Systems Inc.)
DRV - (HpCISSs [Disabled | Stopped]) – C:\Windows\system32\drivers\hpcisss.sys (Hewlett-Packard Company)
DRV - (HSFHWAZL [On_Demand | Stopped]) – C:\Windows\system32\DRIVERS\VSTAZL3.SYS (Conexant Systems, Inc.)
DRV - (HSF_DPV [On_Demand | Running]) – C:\Windows\system32\DRIVERS\HSX_DPV.sys (Conexant Systems, Inc.)
DRV - (HSXHWAZL [On_Demand | Running]) – C:\Windows\system32\DRIVERS\HSXHWAZL.sys (Conexant Systems, Inc.)
DRV - (ialm [On_Demand | Stopped]) – C:\Windows\system32\DRIVERS\igdkmd32.sys (Intel Corporation)
DRV - (iaStorV [Disabled | Stopped]) – C:\Windows\system32\drivers\iastorv.sys (Intel Corporation)
DRV - (igfx [On_Demand | Running]) – C:\Windows\system32\DRIVERS\igdkmd32.sys (Intel Corporation)
DRV - (iirsp [Disabled | Stopped]) – C:\Windows\system32\drivers\iirsp.sys (Intel Corp./ICP vortex GmbH)
DRV - (IKFileSec [On_Demand | Stopped]) – C:\Windows\system32\drivers\ikfilesec.sys (PCTools Research Pty Ltd.)
DRV - (IKSysFlt [On_Demand | Stopped]) – C:\Windows\system32\drivers\iksysflt.sys (PCTools Research Pty Ltd.)
DRV - (IKSysSec [On_Demand | Stopped]) – C:\Windows\system32\drivers\iksyssec.sys (PCTools Research Pty Ltd.)
DRV - (iteatapi [Disabled | Stopped]) – C:\Windows\system32\drivers\iteatapi.sys (Integrated Technology Express, Inc.)
DRV - (iteraid [Disabled | Stopped]) – C:\Windows\system32\drivers\iteraid.sys (Integrated Technology Express, Inc.)
DRV - (KeyScrambler [On_Demand | Running]) – C:\Windows\System32\drivers\keyscrambler.sys (QFX Software Corporation)
DRV - (Lbd [Boot | Running]) – C:\Windows\system32\DRIVERS\Lbd.sys (Lavasoft AB)
DRV - (leafnets [On_Demand | Stopped]) – C:\Windows\system32\DRIVERS\leafnets.sys (Leaf Networks)
DRV - (LHidFilt [On_Demand | Stopped]) – C:\Windows\system32\DRIVERS\LHidFilt.Sys (Logitech, Inc.)
DRV - (LMouFilt [On_Demand | Stopped]) – C:\Windows\system32\DRIVERS\LMouFilt.Sys (Logitech, Inc.)
DRV - (LSI_FC [Disabled | Stopped]) – C:\Windows\system32\drivers\lsi_fc.sys (LSI Logic)
DRV - (LSI_SAS [Disabled | Stopped]) – C:\Windows\system32\drivers\lsi_sas.sys (LSI Logic)
DRV - (LSI_SCSI [Disabled | Stopped]) – C:\Windows\system32\drivers\lsi_scsi.sys (LSI Logic)
DRV - (maa950c [On_Demand | Stopped]) – C:\Windows\System32\Drivers\maa950c.sys (Mobile Action Technology Inc.)
DRV - (maa950m [On_Demand | Stopped]) – C:\Windows\System32\Drivers\maa950m.sys (Mobile Action Technology Inc.)
DRV - (maa950u [On_Demand | Stopped]) – C:\Windows\System32\Drivers\maa950u.sys (Mobile Action Technology Inc.)
DRV - (MaRdPnp [On_Demand | Stopped]) – C:\Windows\system32\DRIVERS\MaRdP2K.sys (Mobile Action Technology Inc.)
DRV - (MaVctrl [Auto | Running]) – C:\Windows\system32\DRIVERS\MaVc2K.sys (Mobile Action Technology Inc.)
DRV - (mdmxsdk [Auto | Running]) – C:\Windows\system32\DRIVERS\mdmxsdk.sys (Conexant)
DRV - (megasas [Disabled | Stopped]) – C:\Windows\system32\drivers\megasas.sys (LSI Logic Corporation)
DRV - (Mraid35x [Disabled | Stopped]) – C:\Windows\system32\drivers\mraid35x.sys (LSI Logic Corporation)
DRV - (NETw3v32 [On_Demand | Stopped]) – C:\Windows\system32\DRIVERS\NETw3v32.sys (Intel® Corporation)
DRV - (nfrd960 [Disabled | Stopped]) – C:\Windows\system32\drivers\nfrd960.sys (IBM Corporation)
DRV - (ntrigdigi [Disabled | Stopped]) – C:\Windows\system32\drivers\ntrigdigi.sys (N-trig Innovative Technologies)
DRV - (nvraid [Disabled | Stopped]) – C:\Windows\system32\drivers\nvraid.sys (NVIDIA Corporation)
DRV - (nvstor [Disabled | Stopped]) – C:\Windows\system32\drivers\nvstor.sys (NVIDIA Corporation)
DRV - (pcouffin [On_Demand | Running]) – C:\Windows\System32\Drivers\pcouffin.sys (VSO Software)
DRV - (pfc [On_Demand | Running]) – C:\Windows\system32\drivers\pfc.sys (Padus, Inc.)
DRV - (PxHelp20 [Boot | Running]) – C:\Windows\System32\Drivers\PxHelp20.sys (Sonic Solutions)
DRV - (ql2300 [Disabled | Stopped]) – C:\Windows\system32\drivers\ql2300.sys (QLogic Corporation)
DRV - (ql40xx [Disabled | Stopped]) – C:\Windows\system32\drivers\ql40xx.sys (QLogic Corporation)
DRV - (rspSanity [On_Demand | Stopped]) – C:\Windows\system32\DRIVERS\rspSanity32.sys (Resplendence Software Projects Sp.)
DRV - (RTL8023xp [On_Demand | Running]) – C:\Windows\system32\DRIVERS\Rtnicxp.sys (Realtek Semiconductor Corporation )
DRV - (SASDIFSV [System | Running]) – C:\Util\Security\SUPERAntiSpyware\SASDIFSV.SYS (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (SASENUM [On_Demand | Stopped]) – C:\Util\Security\SUPERAntiSpyware\SASENUM.SYS ( SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (SASKUTIL [System | Running]) – C:\Util\Security\SUPERAntiSpyware\SASKUTIL.sys (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (secdrv [Auto | Running]) – C:\Windows\System32\drivers\secdrv.sys (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.)
DRV - (SiSRaid2 [Disabled | Stopped]) – C:\Windows\system32\drivers\sisraid2.sys (Silicon Integrated Systems Corp.)
DRV - (SiSRaid4 [Disabled | Stopped]) – C:\Windows\system32\drivers\sisraid4.sys (Silicon Integrated Systems)
DRV - (sp_rsdrv2 [System | Running]) – C:\Windows\system32\drivers\sp_rsdrv2.sys ()
DRV - (ssfs0bbc [Boot | Running]) – C:\Windows\system32\DRIVERS\ssfs0bbc.sys (Webroot Software, Inc. (www.webroot.com))
DRV - (sshrmd [Boot | Running]) – C:\Windows\system32\DRIVERS\sshrmd.sys (Webroot Software, Inc. (www.webroot.com))
DRV - (ssidrv [Boot | Running]) – C:\Windows\system32\DRIVERS\ssidrv.sys (Webroot Software, Inc. (www.webroot.com))
DRV - (SSKBFD [On_Demand | Stopped]) – C:\Windows\System32\Drivers\sskbfd.sys (Webroot Software Inc (www.webroot.com))
DRV - (ssmdrv [System | Running]) – C:\Windows\system32\DRIVERS\ssmdrv.sys (Avira GmbH)
DRV - (SSPORT [Auto | Running]) – C:\Windows\system32\Drivers\SSPORT.sys (Samsung Electronics)
DRV - (Symc8xx [Disabled | Stopped]) – C:\Windows\system32\drivers\symc8xx.sys (LSI Logic)
DRV - (Sym_hi [Disabled | Stopped]) – C:\Windows\system32\drivers\sym_hi.sys (LSI Logic)
DRV - (Sym_u3 [Disabled | Stopped]) – C:\Windows\system32\drivers\sym_u3.sys (LSI Logic)
DRV - (SynTP [On_Demand | Running]) – C:\Windows\system32\DRIVERS\SynTP.sys (Synaptics, Inc.)
DRV - (TfFsMon [Boot | Running]) – C:\Windows\system32\drivers\TfFsMon.sys (PC Tools)
DRV - (TfNetMon [On_Demand | Running]) – C:\Windows\system32\drivers\TfNetMon.sys (PC Tools)
DRV - (TfSysMon [Boot | Running]) – C:\Windows\system32\drivers\TfSysMon.sys (PC Tools)
DRV - (uliahci [Disabled | Stopped]) – C:\Windows\system32\drivers\uliahci.sys (ULi Electronics Inc.)
DRV - (UlSata [Disabled | Stopped]) – C:\Windows\system32\drivers\ulsata.sys (Promise Technology, Inc.)
DRV - (ulsata2 [Disabled | Stopped]) – C:\Windows\system32\drivers\ulsata2.sys (Promise Technology, Inc.)
DRV - (usbaudio [On_Demand | Stopped]) – C:\Windows\system32\drivers\usbaudio.sys (Microsoft Corporation)
DRV - (viaide [Disabled | Stopped]) – C:\Windows\system32\drivers\viaide.sys (VIA Technologies, Inc.)
DRV - (Vsdatant [System | Running]) – C:\Windows\system32\DRIVERS\vsdatant.sys (Check Point Software Technologies LTD)
DRV - (vsmraid [Disabled | Stopped]) – C:\Windows\system32\drivers\vsmraid.sys (VIA Technologies Inc.,Ltd)
DRV - (VX3000 [On_Demand | Stopped]) – C:\Windows\system32\DRIVERS\VX3000.sys (Microsoft Corporation)
DRV - (winachsf [On_Demand | Running]) – C:\Windows\system32\DRIVERS\HSX_CNXT.sys (Conexant Systems, Inc.)
DRV - (XAudio [Auto | Running]) – C:\Windows\system32\DRIVERS\xaudio.sys (Conexant Systems, Inc.)

========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…O&pf;=laptop
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL =
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:NoAdd-ons
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:SecurityRisk
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…O&pf;=laptop

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\system32\blank.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Page_Transitions = 1
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://home.mchsi.com/~auntlorrie/
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local

========== FireFox ==========

FF - prefs.js..browser.startup.homepage: "http://home.mchsi.com/~auntlorrie/"
FF - prefs.js..extensions.enabledItems: filtersetg@updater:0.3.1.3
FF - prefs.js..extensions.enabledItems: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}:0.7.5.4
FF - prefs.js..extensions.enabledItems: {3f963a5b-e555-4543-90e2-c3908898db71}:8.0
FF - prefs.js..extensions.enabledItems: {fce36c1e-58d8-498a-b2a5-66ad1cedebbb}:0.72
FF - prefs.js..extensions.enabledItems: {0538E3E3-7E9B-4d49-8831-A227C80A7AD3}:0.9.7.6
FF - prefs.js..extensions.enabledItems: {EF522540-89F5-46b9-B6FE-1829E2B572C6}:3.11
FF - prefs.js..extensions.enabledItems: {1A2D0EC4-75F5-4c91-89C4-3656F6E44B68}:0.3.1
FF - prefs.js..extensions.enabledItems: [removed]:1.3.3
FF - prefs.js..extensions.enabledItems: {73a6fe31-595d-460b-a920-fcc0f8843232}:1.6.9
FF - prefs.js..extensions.enabledItems: {03B08592-E5B4-45ff-A0BE-C1D975458688}:0.5.0.4
FF - prefs.js..extensions.enabledItems: {95f24680-9e31-11da-a746-0800200c9a66}:0.1.5.4
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA}:6.0.11
FF - prefs.js..extensions.enabledItems: {B7082FAA-CB62-4872-9106-E42DD88EDE45}:2.9
FF - prefs.js..extensions.enabledItems: {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.0.5

FF - HKLM\software\mozilla\Mozilla Firefox 3.0.7\extensions\\Components: C:\TELECOM\INTERNET\FIREFOX\COMPONENTS [2009/03/04 22:34:20 | 00,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.0.7\extensions\\Plugins: C:\TELECOM\INTERNET\FIREFOX\PLUGINS [2009/03/11 20:22:39 | 00,000,000 | —D | M]

[2008/07/12 00:19:09 | 00,000,000 | —D | M] – C:\Users\Administrator\AppData\Roaming\mozilla\Extensions
[2008/07/12 00:19:09 | 00,000,000 | —D | M] – C:\Users\Administrator\AppData\Roaming\mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}
[2009/01/21 22:50:58 | 00,000,000 | —D | M] – C:\Users\Administrator\AppData\Roaming\mozilla\Firefox\Profiles\4z48f371.default\extensions
[2008/04/27 02:55:07 | 00,000,000 | —D | M] – C:\Users\Administrator\AppData\Roaming\mozilla\Firefox\Profiles\4z48f371.default\extensions\{03B08592-E5B4-45ff-A0BE-C1D975458688}
[2008/06/13 05:05:57 | 00,000,000 | —D | M] – C:\Users\Administrator\AppData\Roaming\mozilla\Firefox\Profiles\4z48f371.default\extensions\{0538E3E3-7E9B-4d49-8831-A227C80A7AD3}
[2008/03/22 11:36:05 | 00,000,000 | —D | M] – C:\Users\Administrator\AppData\Roaming\mozilla\Firefox\Profiles\4z48f371.default\extensions\{1A2D0EC4-75F5-4c91-89C4-3656F6E44B68}
[2007/10/26 02:46:39 | 00,000,000 | —D | M] – C:\Users\Administrator\AppData\Roaming\mozilla\Firefox\Profiles\4z48f371.default\extensions\{50B7AB30-18EF-4c9c-9FAF-E413C3A1FA78}
[2008/06/13 05:06:02 | 00,000,000 | —D | M] – C:\Users\Administrator\AppData\Roaming\mozilla\Firefox\Profiles\4z48f371.default\extensions\{73a6fe31-595d-460b-a920-fcc0f8843232}
[2008/06/13 05:06:04 | 00,000,000 | —D | M] – C:\Users\Administrator\AppData\Roaming\mozilla\Firefox\Profiles\4z48f371.default\extensions\{95f24680-9e31-11da-a746-0800200c9a66}
[2008/04/27 02:54:59 | 00,000,000 | —D | M] – C:\Users\Administrator\AppData\Roaming\mozilla\Firefox\Profiles\4z48f371.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}
[2007/10/26 02:46:38 | 00,000,000 | —D | M] – C:\Users\Administrator\AppData\Roaming\mozilla\Firefox\Profiles\4z48f371.default\extensions\{dc572301-7619-498c-a57d-39143191b318}
[2008/04/27 02:55:04 | 00,000,000 | —D | M] – C:\Users\Administrator\AppData\Roaming\mozilla\Firefox\Profiles\4z48f371.default\extensions\{EF522540-89F5-46b9-B6FE-1829E2B572C6}
[2008/04/27 02:55:01 | 00,000,000 | —D | M] – C:\Users\Administrator\AppData\Roaming\mozilla\Firefox\Profiles\4z48f371.default\extensions\{fce36c1e-58d8-498a-b2a5-66ad1cedebbb}
[2008/01/21 00:48:46 | 00,000,000 | —D | M] – C:\Users\Administrator\AppData\Roaming\mozilla\Firefox\Profiles\4z48f371.default\extensions\filtersetg@updater
[2008/01/21 00:48:53 | 00,000,000 | —D | M] – C:\Users\Administrator\AppData\Roaming\mozilla\Firefox\Profiles\4z48f371.default\extensions\[removed]
[2009/01/16 22:15:17 | 00,001,690 | —- | M] () – C:\Users\Administrator\AppData\Roaming\Mozilla\FireFox\Profiles\4z48f371.default\searchplugins\amazondotcom.xml
[2009/01/16 22:15:16 | 00,001,068 | —- | M] () – C:\Users\Administrator\AppData\Roaming\Mozilla\FireFox\Profiles\4z48f371.default\searchplugins\ebay.xml
[2007/09/27 00:42:36 | 00,002,386 | —- | M] () – C:\Users\Administrator\AppData\Roaming\Mozilla\FireFox\Profiles\4z48f371.default\searchplugins\siteadvisor.xml

O1 HOSTS File: (302308 bytes) - C:\Windows\System32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 www.007guard.com
O1 - Hosts: 127.0.0.1 007guard.com
O1 - Hosts: 127.0.0.1 008i.com
O1 - Hosts: 127.0.0.1 www.008k.com
O1 - Hosts: 127.0.0.1 008k.com
O1 - Hosts: 127.0.0.1 www.00hq.com
O1 - Hosts: 127.0.0.1 00hq.com
O1 - Hosts: 127.0.0.1 010402.com
O1 - Hosts: 127.0.0.1 www.032439.com
O1 - Hosts: 127.0.0.1 032439.com
O1 - Hosts: 127.0.0.1 www.0scan.com
O1 - Hosts: 127.0.0.1 0scan.com
O1 - Hosts: 127.0.0.1 www.1000gratisproben.com
O1 - Hosts: 127.0.0.1 1000gratisproben.com
O1 - Hosts: 127.0.0.1 www.1001namen.com
O1 - Hosts: 127.0.0.1 1001namen.com
O1 - Hosts: 127.0.0.1 100888290cs.com
O1 - Hosts: 127.0.0.1 www.100888290cs.com
O1 - Hosts: 127.0.0.1 100sexlinks.com
O1 - Hosts: 127.0.0.1 www.100sexlinks.com
O1 - Hosts: 127.0.0.1 10sek.com
O1 - Hosts: 127.0.0.1 www.10sek.com
O1 - Hosts: 127.0.0.1 www.1-2005-search.com
O1 - Hosts: 127.0.0.1 1-2005-search.com
O1 - Hosts: 127.0.0.1 123haustiereundmehr.com
O1 - Hosts: 10443 more lines…
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (Skype add-on (mastermind)) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Telecom\Internet\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Skype Technologies S.A.)
O2 - BHO: (CKeyScramblerBHO Object) - {2B9F5787-88A5-4945-90E7-C4B18563BC5E} - C:\Util\Security\KeyScrambler\KeyScramblerIE.dll (QFX Software Corporation)
O2 - BHO: (Spybot-S&D; IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Util\Security\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O2 - BHO: (Groove GFS Browser Helper) - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation)
O2 - BHO: (Java™ Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
O4 - HKLM..\Run: [Ad-Watch] "C:\Util\Security\Lavasoft\Ad-Aware\AAWTray.exe" (Lavasoft)
O4 - HKLM..\Run: [avast!] C:\Util\Security\ALWILS~1\Avast\ashDisp.exe (ALWIL Software)
O4 - HKLM..\Run: [HotKeysCmds] "C:\Windows\system32\hkcmd.exe" (Intel Corporation)
O4 - HKLM..\Run: [IgfxTray] "C:\Windows\system32\igfxtray.exe" (Intel Corporation)
O4 - HKLM..\Run: [Kernel and Hardware Abstraction Layer] "C:\Windows\KHALMNPR.EXE" (Logitech Inc.)
O4 - HKLM..\Run: [Persistence] "C:\Windows\system32\igfxpers.exe" (Intel Corporation)
O4 - HKLM..\Run: [SpywareTerminator] "C:\Util\Security\Spyware Terminator\SpywareTerminatorShield.exe" (Crawler.com)
O4 - HKLM..\Run: [SynTPEnh] "C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" (Synaptics, Inc.)
O4 - HKLM..\Run: [SynTPStart] "C:\Program Files\Synaptics\SynTP\SynTPStart.exe" (Synaptics, Inc.)
O4 - HKLM..\Run: [ThreatFire] C:\Util\Security\ThreatFire\TFTray.exe (PC Tools)
O4 - HKLM..\Run: [ZoneAlarm Client] "C:\Util\Security\ZoneAlarm\zlclient.exe" (Check Point Software Technologies LTD)
O4 - HKCU..\Run: [Aim6] File not found
O4 - HKCU..\Run: [SpybotSD TeaTimer] "C:\Util\Security\Spybot - Search & Destroy\TeaTimer.exe" (Safer-Networking Ltd.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 2
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableInstallerDetection = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableSecureUIAPaths = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableVirtualization = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ValidateAdminCodeSignatures = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: scforceoption = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: FilterAdministratorToken = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableUIADesktopToggle = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_TEXT = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_BITMAP = 2
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_OEMTEXT = 7
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_DIB = 8
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_PALETTE = 9
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_UNICODETEXT = 13
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_DIBV5 = 17
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O8 - Extra context menu item: Add to Google Photos Screensa&ver; - res://C:\Windows\system32\GPhotos.scr/200
O8 - Extra context menu item: E&xport; to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
O9 - Extra Button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : S&end; to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : &KeyScrambler;… - {5C106A59-CC3C-4caa-81A4-6D909B5ACE23} - C:\Util\Security\KeyScrambler\KeyScramblerIE.dll (QFX Software Corporation)
O9 - Extra Button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Telecom\Internet\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Skype Technologies S.A.)
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Program Files\Microsoft Office\Office12\REFIEBAR.DLL (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Util\Security\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000001 [@%SystemRoot%\system32\nlasvc.dll,-1000] - C:\Windows\system32\NLAapi.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000002 [@%SystemRoot%\system32\napinsp.dll,-1000] - C:\Windows\system32\napinsp.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000003 [@%SystemRoot%\system32\pnrpnsp.dll,-1000] - C:\Windows\system32\pnrpnsp.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [@%SystemRoot%\system32\pnrpnsp.dll,-1001] - C:\Windows\system32\pnrpnsp.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000005 [mdnsNSP] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O13 - gopher Prefix: missing
O15 - HKLM\..Trusted Domains: 50 domain(s) and sub-domain(s) not assigned to a zone.
O15 - HKCU\..Trusted Domains: 409 domain(s) and sub-domain(s) not assigned to a zone.
O15 - HKCU\..Trusted Ranges: Range1 ([http] in Local intranet)
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://download.macromedia.com/pub/shockwa…director/sw.cab (Reg Error: Key error.)
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} http://download.bitdefender.com/resources/scan8/oscan8.cab (BDSCANONLINE Control)
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} http://security.symantec.com/sscv6/SharedC…n/bin/cabsa.cab (Symantec RuFSI Utility Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_11)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get/flash…r/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {BDBDE413-7B1C-4C68-A8FF-C5B2B4090876} http://support.f-secure.com/ols/fscax.cab (F-Secure Online Scanner 3.3)
O16 - DPF: {CAFEEFAC-0016-0000-0000-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0)
O16 - DPF: {CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_11)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_11)
O18 - Protocol\Handler\grooveLocalGWS {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll (Microsoft Corporation)
O18 - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\http\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\https\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll (Microsoft Corporation)
O18 - Protocol\Handler\ms-itss {0A9007C0-4076-11D3-8789-0000F8105754} - C:\Program Files\Common Files\Microsoft Shared\Information Retrieval\msitss.dll (Microsoft Corporation)
O18 - Protocol\Handler\mso-offdap {3D9F03FA-7A94-11D3-BE81-0050048385D1} - C:\Program Files\Common Files\microsoft shared\Web Components\10\OWC10.DLL (Microsoft Corporation)
O18 - Protocol\Handler\mso-offdap11 {32505114-5902-49B2-880A-1F7738E5A384} - C:\Program Files\Common Files\microsoft shared\Web Components\11\OWC11.DLL (Microsoft Corporation)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Filter: - text/xml - C:\Program Files\Common Files\microsoft shared\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\!SASWinLogon: DllName - C:\Util\Security\SUPERAntiSpyware\SASWINLO.dll - C:\Util\Security\SUPERAntiSpyware\SASWINLO.dll (SUPERAntiSpyware.com)
O20 - Winlogon\Notify\igfxcui: DllName - igfxdev.dll - C:\Windows\system32\igfxdev.dll (Intel Corporation)
O28 - HKLM ShellExecuteHooks: {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - C:\Util\Security\SUPERAntiSpyware\SASSEH.DLL (SuperAdBlocker.com)
O28 - HKLM ShellExecuteHooks: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation)
O31 - SafeBoot: AlternateShell - cmd.exe
O32 - HKLM CDRom: AutoRun - 1
O32 - Autorun File - C:\autoexec.bat () - [ NTFS ]
O32 - Autorun File - D:\AUTOMODE () - [ NTFS ]
O33 - MountPoints2\{74132f76-e42c-11dc-a40e-0016d4eba4d3}\Shell - "" = AutoRun
O33 - MountPoints2\{74132f76-e42c-11dc-a40e-0016d4eba4d3}\Shell\AutoRun\command - "" = G:\LaunchU3.exe – File not found
O33 - MountPoints2\G\Shell - "" = AutoRun
O33 - MountPoints2\G\Shell\AutoRun\command - "" = G:\LaunchU3.exe – File not found
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O34 - HKLM BootExecute: (lsdelete) - C:\Windows\System32\lsdelete.exe ()

========== Files/Folders - Created Within 30 Days ==========

[2009/03/23 16:03:33 | 21,371,20768 | -HS- | C] () – C:\hiberfil.sys
[2009/03/23 15:28:15 | 00,499,200 | —- | C] (OldTimer Tools) – C:\Users\Administrator\Desktop\OTListIt2.exe
[2009/03/16 05:33:22 | 00,015,688 | —- | C] () – C:\Windows\System32\lsdelete.exe
[2009/03/15 21:52:09 | 00,000,472 | —- | C] () – C:\Windows\tasks\Ad-Aware Update (Weekly).job
[2009/03/15 21:52:00 | 00,064,160 | —- | C] (Lavasoft AB) – C:\Windows\System32\drivers\Lbd.sys
[2009/03/13 03:45:31 | 00,000,266 | —- | C] () – C:\Windows\tasks\Spybot - Search & Destroy Updater - Scheduled Task.job
[2009/03/12 21:29:20 | 00,000,804 | —- | C] () – C:\Users\Public\Desktop\FileSeek.lnk
[2009/03/12 16:22:29 | 00,886,008 | —- | C] (2BrightSparks Pte Ltd) – C:\Windows\System32\SNU.dll
[2009/03/12 16:22:29 | 00,000,000 | —D | C] – C:\ProgramData\2BrightSparks
[2009/03/12 04:17:04 | 00,051,472 | —- | C] (PC Tools) – C:\Windows\System32\drivers\TfFsMon.sys
[2009/03/12 04:17:04 | 00,039,184 | —- | C] (PC Tools) – C:\Windows\System32\drivers\TfSysMon.sys
[2009/03/12 04:17:04 | 00,033,040 | —- | C] (PC Tools) – C:\Windows\System32\drivers\TfNetMon.sys
[2009/03/12 04:17:04 | 00,012,560 | —- | C] (PC Tools) – C:\Windows\System32\drivers\TfKbMon.sys
[2009/03/11 17:00:24 | 00,001,596 | —- | C] () – C:\Windows\tasks\wrSpySweeper_LF261E20F388141D8848B2F940FBD80C4.job
[2009/03/11 05:23:52 | 00,051,376 | —- | C] (ALWIL Software) – C:\Windows\System32\drivers\aswTdi.sys
[2009/03/11 05:23:52 | 00,023,152 | —- | C] (ALWIL Software) – C:\Windows\System32\drivers\aswRdr.sys
[2009/03/11 05:23:51 | 00,097,480 | —- | C] (ALWIL Software) – C:\Windows\System32\AvastSS.scr
[2009/03/11 05:23:50 | 00,114,768 | —- | C] (ALWIL Software) – C:\Windows\System32\drivers\aswSP.sys
[2009/03/11 05:23:50 | 00,020,560 | —- | C] (ALWIL Software) – C:\Windows\System32\drivers\aswFsBlk.sys
[2009/03/11 05:23:22 | 01,256,296 | —- | C] (ALWIL Software) – C:\Windows\System32\aswBoot.exe
[2009/03/11 05:23:22 | 00,380,928 | —- | C] () – C:\Windows\System32\actskin4.ocx
[2009/03/11 05:23:22 | 00,051,792 | —- | C] (ALWIL Software) – C:\Windows\System32\drivers\aswMonFlt.sys
[2009/03/11 05:21:08 | 00,268,288 | —- | C] (Microsoft Corporation) – C:\Windows\System32\schannel.dll
[2009/03/11 05:20:39 | 02,033,152 | —- | C] (Microsoft Corporation) – C:\Windows\System32\win32k.sys
[2009/03/10 22:20:21 | 01,553,784 | —- | C] (Webroot Software, Inc.) – C:\Windows\WRSetup.dll
[2009/03/10 22:14:46 | 00,000,000 | -H-D | C] – C:\ProgramData\{83C91755-2546-441D-AC40-9A6B4B860800}
[2009/03/10 08:10:33 | 00,352,605 | -H– | C] () – C:\Windows\System32\drivers\vsconfig.xml
[2009/03/10 01:48:36 | 00,155,648 | —- | C] () – C:\Windows\System32\drivers\KeDetective121.sys
[2009/03/10 00:54:14 | 00,043,584 | —- | C] (Avira GmbH) – C:\Windows\System32\drivers\avipbb.sys
[2009/03/10 00:54:14 | 00,028,352 | —- | C] (Avira GmbH) – C:\Windows\System32\drivers\ssmdrv.sys
[2009/03/05 22:30:17 | 00,000,000 | —D | C] – C:\ProgramData\SecTaskMan
[2009/03/05 20:57:45 | 00,000,000 | —D | C] – C:\ProgramData\Webroot
[2009/03/05 20:44:54 | 00,007,946 | —- | C] () – C:\temp22.html
[2009/03/05 19:04:29 | 00,009,003 | —- | C] () – C:\temp24.html
[2009/03/05 02:18:16 | 00,000,250 | —- | C] () – C:\Windows\gmer.ini
[2009/03/05 02:18:15 | 00,884,736 | —- | C] () – C:\Windows\gmer.dll
[2009/03/05 02:18:15 | 00,085,969 | —- | C] (GMER) – C:\Windows\System32\drivers\gmer.sys
[2009/03/05 02:18:15 | 00,000,080 | —- | C] () – C:\Windows\gmer_uninstall.cmd
[2009/03/05 00:45:52 | 00,001,293 | —- | C] () – C:\temp1.html
[2009/03/05 00:42:51 | 00,030,136 | —- | C] (Resplendence Software Projects Sp.) – C:\Windows\System32\drivers\rspSanity32.sys
[2009/03/04 12:02:21 | 00,000,164 | —- | C] () – C:\Windows\install.dat
[2009/03/04 05:49:46 | 10,622,976 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wmp.dll
[2009/03/04 05:49:28 | 00,007,680 | —- | C] (Microsoft Corporation) – C:\Windows\System32\spwmp.dll
[2009/03/04 05:49:22 | 00,004,096 | —- | C] (Microsoft Corporation) – C:\Windows\System32\dxmasf.dll
[2009/03/04 05:49:21 | 00,004,096 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msdxm.ocx
[2009/03/04 05:49:18 | 08,147,456 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wmploc.DLL
[2009/03/03 06:43:15 | 00,000,000 | —D | C] – C:\fsaua.data
[2009/03/03 00:13:06 | 00,000,000 | —D | C] – C:\Windows\BDOSCAN8
[2009/03/02 23:33:16 | 00,000,000 | —D | C] – C:\Program Files\Panda Security
[2009/02/26 21:06:14 | 00,000,000 | —D | C] – C:\Windows\System32\Adobe
[2009/02/26 16:10:05 | 00,000,000 | —D | C] – C:\ProgramData\Artificial Dynamics
[2009/02/26 15:59:58 | 00,000,824 | —- | C] () – C:\Users\Administrator\Desktop\MozBackup.lnk
[2009/02/25 15:24:56 | 00,176,752 | —- | C] (Webroot Software, Inc. (www.webroot.com)) – C:\Windows\System32\drivers\ssidrv.sys
[2009/02/25 15:24:56 | 00,023,152 | —- | C] (Webroot Software, Inc. (www.webroot.com)) – C:\Windows\System32\drivers\sshrmd.sys
[2009/02/25 15:24:54 | 00,029,808 | —- | C] (Webroot Software, Inc. (www.webroot.com)) – C:\Windows\System32\drivers\ssfs0bbc.sys
[2009/02/25 15:24:48 | 00,031,088 | —- | C] () – C:\Windows\System32\wrLZMA.dll
[2009/02/25 15:24:40 | 00,016,240 | —- | C] () – C:\Windows\System32\SsiEfr.exe

========== Files - Modified Within 30 Days ==========

[2009/03/23 16:03:49 | 00,000,006 | -H– | M] () – C:\Windows\tasks\SA.DAT
[2009/03/23 16:03:47 | 00,352,605 | -H– | M] () – C:\Windows\System32\drivers\vsconfig.xml
[2009/03/23 16:03:42 | 00,003,296 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2009/03/23 16:03:42 | 00,003,296 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2009/03/23 16:03:35 | 00,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2009/03/23 16:03:33 | 21,371,20768 | -HS- | M] () – C:\hiberfil.sys
[2009/03/23 14:20:51 | 00,499,200 | —- | M] (OldTimer Tools) – C:\Users\Administrator\Desktop\OTListIt2.exe
[2009/03/23 08:59:59 | 00,000,346 | —- | M] () – C:\Windows\tasks\Spybot - Search & Destroy - Scheduled Task.job
[2009/03/22 21:51:43 | 00,000,472 | —- | M] () – C:\Windows\tasks\Ad-Aware Update (Weekly).job
[2009/03/21 21:16:36 | 00,000,460 | —- | M] () – C:\Windows\System32\BIN_STRSBW.SPT
[2009/03/21 18:00:00 | 00,000,442 | —- | M] () – C:\Windows\tasks\ParetoLogic Registration.job
[2009/03/21 17:42:37 | 00,302,308 | R— | M] () – C:\Windows\System32\drivers\etc\hosts
[2009/03/21 17:12:00 | 00,645,296 | —- | M] () – C:\Windows\System32\perfh009.dat
[2009/03/21 17:11:59 | 00,760,648 | —- | M] () – C:\Windows\System32\PerfStringBackup.INI
[2009/03/21 17:11:59 | 00,119,716 | —- | M] () – C:\Windows\System32\perfc009.dat
[2009/03/20 01:00:00 | 00,001,596 | —- | M] () – C:\Windows\tasks\wrSpySweeper_LF261E20F388141D8848B2F940FBD80C4.job
[2009/03/16 15:59:51 | 00,898,973 | R— | M] () – C:\Windows\System32\drivers\etc\HOSTS.bak
[2009/03/16 07:53:59 | 00,000,250 | —- | M] () – C:\Windows\gmer.ini
[2009/03/15 21:47:44 | 00,015,688 | —- | M] () – C:\Windows\System32\lsdelete.exe
[2009/03/15 21:47:29 | 00,064,160 | —- | M] (Lavasoft AB) – C:\Windows\System32\drivers\Lbd.sys
[2009/03/15 00:37:39 | 00,000,416 | —- | M] () – C:\Windows\tasks\ParetoLogic Update Version2.job
[2009/03/13 03:45:31 | 00,000,266 | —- | M] () – C:\Windows\tasks\Spybot - Search & Destroy Updater - Scheduled Task.job
[2009/03/12 21:29:20 | 00,000,804 | —- | M] () – C:\Users\Public\Desktop\FileSeek.lnk
[2009/03/12 20:30:40 | 00,000,385 | —- | M] () – C:\Windows\win.ini
[2009/03/12 20:27:13 | 00,000,164 | —- | M] () – C:\Windows\install.dat
[2009/03/12 16:09:12 | 00,610,711 | —- | M] () – C:\Windows\System32\drivers\etc\hosts.20090313-030932.backup
[2009/03/11 22:04:36 | 00,303,820 | R— | M] () – C:\Windows\System32\drivers\etc\HOSTS backup b4 mvps hosts
[2009/03/11 16:27:33 | 00,293,168 | R— | M] () – C:\Windows\System32\drivers\etc\hosts.20090311-220436.backup
[2009/03/11 07:05:41 | 00,461,232 | —- | M] () – C:\Windows\System32\FNTCACHE.DAT
[2009/03/11 05:23:49 | 00,002,577 | —- | M] () – C:\Windows\System32\config.nt
[2009/03/10 01:48:36 | 00,155,648 | —- | M] () – C:\Windows\System32\drivers\KeDetective121.sys
[2009/03/05 20:44:54 | 00,007,946 | —- | M] () – C:\temp22.html
[2009/03/05 20:44:02 | 00,001,293 | —- | M] () – C:\temp1.html
[2009/03/05 19:04:29 | 00,009,003 | —- | M] () – C:\temp24.html
[2009/03/05 17:10:10 | 01,553,784 | —- | M] (Webroot Software, Inc.) – C:\Windows\WRSetup.dll
[2009/03/05 02:18:15 | 00,884,736 | —- | M] () – C:\Windows\gmer.dll
[2009/03/05 02:18:15 | 00,085,969 | —- | M] (GMER) – C:\Windows\System32\drivers\gmer.sys
[2009/03/05 02:18:15 | 00,000,080 | —- | M] () – C:\Windows\gmer_uninstall.cmd
[2009/03/05 02:18:12 | 00,811,008 | R— | M] () – C:\Windows\gmer.exe
[2009/03/03 22:35:48 | 00,000,224 | —- | M] () – C:\Windows\System32\9B13A86D.plf
[2009/03/03 13:19:58 | 00,039,184 | —- | M] (PC Tools) – C:\Windows\System32\drivers\TfSysMon.sys
[2009/03/03 13:19:56 | 00,033,040 | —- | M] (PC Tools) – C:\Windows\System32\drivers\TfNetMon.sys
[2009/03/03 13:19:55 | 00,012,560 | —- | M] (PC Tools) – C:\Windows\System32\drivers\TfKbMon.sys
[2009/03/03 13:19:54 | 00,051,472 | —- | M] (PC Tools) – C:\Windows\System32\drivers\TfFsMon.sys
[2009/03/02 12:24:26 | 00,030,136 | —- | M] (Resplendence Software Projects Sp.) – C:\Windows\System32\drivers\rspSanity32.sys
[2009/03/02 03:29:30 | 00,001,537 | —- | M] () – C:\Users\Public\Desktop\Windows Explorer.lnk
[2009/02/27 00:12:58 | 00,290,947 | R— | M] () – C:\Windows\System32\drivers\etc\hosts.20090303-164814.backup
[2009/02/26 15:59:58 | 00,000,824 | —- | M] () – C:\Users\Administrator\Desktop\MozBackup.lnk
[2009/02/25 15:24:56 | 00,176,752 | —- | M] (Webroot Software, Inc. (www.webroot.com)) – C:\Windows\System32\drivers\ssidrv.sys
[2009/02/25 15:24:56 | 00,023,152 | —- | M] (Webroot Software, Inc. (www.webroot.com)) – C:\Windows\System32\drivers\sshrmd.sys
[2009/02/25 15:24:54 | 00,029,808 | —- | M] (Webroot Software, Inc. (www.webroot.com)) – C:\Windows\System32\drivers\ssfs0bbc.sys
[2009/02/25 15:24:48 | 00,031,088 | —- | M] () – C:\Windows\System32\wrLZMA.dll
[2009/02/25 15:24:40 | 00,016,240 | —- | M] () – C:\Windows\System32\SsiEfr.exe
[2009/02/25 12:55:00 | 24,768,960 | —- | M] (Microsoft Corporation) – C:\Windows\System32\mrt.exe

========== LOP Check ==========

[2009/03/22 21:51:43 | 00,000,472 | —- | M] () – C:\Windows\Tasks\Ad-Aware Update (Weekly).job
[2009/03/21 18:00:00 | 00,000,442 | —- | M] () – C:\Windows\Tasks\ParetoLogic Registration.job
[2009/03/15 00:37:39 | 00,000,416 | —- | M] () – C:\Windows\Tasks\ParetoLogic Update Version2.job
[2009/03/23 16:03:49 | 00,000,006 | -H– | M] () – C:\Windows\Tasks\SA.DAT
[2009/03/23 01:49:36 | 00,032,600 | —- | M] () – C:\Windows\Tasks\SCHEDLGU.TXT
[2009/03/23 08:59:59 | 00,000,346 | —- | M] () – C:\Windows\Tasks\Spybot - Search & Destroy - Scheduled Task.job
[2009/03/13 03:45:31 | 00,000,266 | —- | M] () – C:\Windows\Tasks\Spybot - Search & Destroy Updater - Scheduled Task.job
[2009/03/20 01:00:00 | 00,001,596 | —- | M] () – C:\Windows\Tasks\wrSpySweeper_LF261E20F388141D8848B2F940FBD80C4.job

========== Purity Check ==========


========== Alternate Data Streams ==========

@Alternate Data Stream - 127 bytes -> C:\ProgramData\TEMP:1CA73D29
@Alternate Data Stream - 120 bytes -> C:\ProgramData\TEMP:5C321E34
@Alternate Data Stream - 106 bytes -> C:\ProgramData\TEMP:DFC5A2B2
< End of report >

———-end of OTListIt.txt Log file // Start of Extras.txt ——–

OTListIt Extras logfile created on: 3/23/2009 4:13:52 PM - Run 1
OTListIt2 by OldTimer - Version 2.0.7.1 Folder = C:\Users\Administrator\Desktop
Windows Vista Home Premium Edition Service Pack 1 (Version = 6.0.6001) - Type = NTWorkstation
Internet Explorer (Version = 7.0.6001.18000)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

1.99 Gb Total Physical Memory | 1.11 Gb Available Physical Memory | 55.82% Memory free
4.00 Gb Paging File | 3.07 Gb Available in Paging File | 76.80% Paging File free
Paging file location(s): ?:\pagefile.sys;

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 66.48 Gb Total Space | 8.66 Gb Free Space | 13.03% Space Free | Partition Type: NTFS
Drive D: | 8.04 Gb Total Space | 7.77 Gb Free Space | 96.66% Space Free | Partition Type: NTFS
Drive E: | 4.30 Gb Total Space | 0.00 Gb Free Space | 0.00% Space Free | Partition Type: CDFS
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: LORIS-COMPAQ
Current User Name: Administrator
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Output = Minimal
File Age = 30 Days
Company Name Whitelist: On

========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – C:\Windows\System32\control.exe (Microsoft Corporation)
.hlp [@ = hlpfile] – C:\Windows\winhlp32.exe (Microsoft Corporation)
.html [@ = Reg Error: Value error.] – Reg Error: Key error. File not found

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
"DisableMonitoring" = 1
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
"DisableMonitoring" = 1
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]
"DisableMonitoring" = 1
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]
"DisableMonitoring" = 1
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
"VistaSp1" =
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\S-1-5-21-3722091140-1563400330-3389692580-1000]
"EnableNotifications" = 1
"EnableNotificationsRef" = 1
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile
"DisableNotifications" = 0
"EnableFirewall" = 0

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
C:\Program Files\EarthLink TotalAccess\TaskPanl.exe:*:Enabled:Earthlink (EarthLink, Inc.)

========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{0394CDC8-FABD-4ed8-B104-03393876DFDF}" = Roxio Creator Tools
"{082702D5-5DD8-4600-BCE5-48B15174687F}" = HP Doc Viewer
"{0BFC200F-C45D-4271-AF34-4CA969225DEB}" = muvee autoProducer 6.0
"{0CFD3BAF-9F4D-4D70-BD0B-638EA2504C25}" = PSSWCORE
"{0D397393-9B50-4c52-84D5-77E344289F87}" = Roxio Creator Data
"{0DD140D3-9563-481E-AA75-BA457CBDAEF2}" = PC Inspector File Recovery
"{11F93B4B-48F0-4A4E-AE77-DFA96A99664B}" = Roxio Creator EasyArchive
"{13F3917B56CD4C25848BDC69916971BB}" = DivX Converter
"{15D8D315-BB4C-4867-BCD7-2B829EF0F38B}" = ParetoLogic Data Recovery
"{18D10072035C4515918F7E37EAFAACFC}" = AutoUpdate
"{1E04F83B-2AB9-4301-9EF7-E86307F79C72}" = Google Earth
"{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}" = Multimedia Launcher
"{1FD25FCD-6F39-4686-AFBB-7056EBAE5E68}" = Avira RootKit Detection
"{228C6B46-64E2-404E-898A-EF0830603EF4}" = HPNetworkAssistant
"{24D753CA-6AE9-4E30-8F5F-EFC93E08BF3D}" = Skype™ 4.0
"{254C37AA-6B72-4300-84F6-98A82419187E}" = Hewlett-Packard Active Check for Health Check
"{26A24AE4-039D-4CA4-87B4-2F83216011FF}" = Java™ 6 Update 11
"{290B83AA-093A-45BF-A917-D1C4A1E8D917}" = HP Active Support Library
"{296B2D8E-CE82-92AF-B2E8-A646E7CB78A2}_is1" = RegAlyzer
"{2AFFFDD7-ED85-4A90-8C52-5DA9EBDC9B8F}" = Microsoft SQL Server 2005 Express Edition (MSSMLBIZ)
"{32343DB6-9A52-40C9-87E4-5E7C79791C87}" = MSXML 4.0 SP2 and SOAP Toolkit 3.0
"{3248F0A8-6813-11D6-A77B-00B0D0160000}" = Java™ SE Runtime Environment 6
"{33C65B6A-5D73-4E3E-A1F9-127C27BD3F72}" = Roxio MyDVD Basic v9
"{34D2AB40-150D-475D-AE32-BD23FB5EE355}" = HP Quick Launch Buttons 6.20 D3
"{353D20CC-719B-4A60-AD33-D03F88C10330}" = Microsoft Office Accounting PayPal Addin
"{35E1EC43-D4FC-4E4A-AAB3-20DDA27E8BB0}" = Roxio Activation Module
"{3F5B6210-0903-4DC6-8034-8F488AA3A782}" = Spy Sweeper Core
"{3FC7CBBC4C1E11DCA1A752EA55D89593}" = DivX Version Checker
"{3FFB3B34-D639-4384-9AE9-DDE58430D86F}" = MSCU for Microsoft Vista
"{40F7AED3-0C7D-4582-99F6-484A515C73F2}" = HP Easy Setup - Frontend
"{41B9E2CF-0B3F-442A-B5B3-592A4A355634}" = iTunes
"{44C05309-60F4-410B-BC32-31733CFF1A49}" = Microsoft Digital Image Suite Anniversary Edition Editor
"{45D707E9-F3C4-11D9-A373-0050BAE317E1}" = HP DVD Play 3.2
"{46614A49-222A-48EF-87A9-BFD603E608E1}" = Microsoft Office Accounting Fixed Asset Manager
"{47609E69-4C5E-48B1-A889-24C6B82B5C04}" = Vista Shortcut Manager
"{4FE542EB-FF0B-4739-94DD-25C8AE0AB259}" = Microsoft Digital Image Suite Anniversary Edition Library
"{50120000-1105-0000-0000-0000000FF1CE}" = Microsoft Office 2007 Primary Interop Assemblies
"{53F5C3EE-05ED-4830-994B-50B2F0D50FCE}" = Microsoft SQL Server Setup Support Files (English)
"{56918C0C-0D87-4CA6-92BF-4975A43AC719}" = KhalInstallWrapper
"{56B4002F-671C-49F4-984C-C760FE3806B5}" = Microsoft SQL Server VSS Writer
"{56C049BE-79E9-4502-BEA7-9754A3E60F9B}" = neroxml
"{5FA793A6-0071-42C1-9355-8F69A428C44F}" = Microsoft Office Accounting ADP Payroll Addin
"{619CDD8A-14B6-43a1-AB6C-0F4EE48CE048}" = Roxio Creator Copy
"{63AFACBC-4795-4A1B-8037-5085DC03FC54}" = Microsoft LifeCam
"{65DA2EC9-0642-47E9-AAE2-B5267AA14D75}" = Activation Assistant for the 2007 Microsoft Office suites
"{6675CA7F-E51B-4F6A-99D4-F8F0124C6EAA}" = Roxio Express Labeler 3
"{669D4A35-146B-4314-89F1-1AC3D7B88367}" = Hewlett-Packard Asset Agent for Health Check
"{6811CAA0-BF12-11D4-9EA1-0050BAE317E1}" = PowerDVD
"{6B10045E-6789-49C4-BFED-52575F5B76BF}" = Avery Wizard 3.0
"{6D52C408-B09A-4520-9B18-475B81D393F1}" = Microsoft Works
"{7059BDA7-E1DB-442C-B7A1-6144596720A4}" = HP Update
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{767CC44C-9BBC-438D-BAD3-FD4595DD148B}" = VC80CRTRedist - 8.0.50727.762
"{76F8CB2B-6516-4E1E-B6F1-AED4ABDB4B0A}_is1" = Spy Sweeper
"{7B63B2922B174135AFC0E1377DD81EC2}" = DivX Codec
"{81A34902-9D0B-4920-A25C-4CDC5D14B328}" = Jasc Paint Shop Pro 8
"{83FFCFC7-88C6-41c6-8752-958A45325C82}" = Roxio Creator Audio
"{88A548E6-4B09-43E7-AD55-3C7D1B37706D}" = ESU for Microsoft Vista
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8A25392D-C5D2-4E79-A2BD-C15DDC5B0959}" = Bonjour
"{8A5F34E2-37CF-4AD4-808C-2D413786E31A}" = Microsoft Visual C Runtime
"{8ADFC4160D694100B5B8A22DE9DCABD9}" = DivX Player
"{8C711818-076E-475C-B95B-DF11CD9D8DBE}" = Microsoft Office Accounting Equifax Addin
"{8CC990CD-87C8-475C-AC32-8A7984E2FCFA}" = CDDRV_Installer
"{8CEA85DE-955B-4BF4-87F2-0BAA62821633}" = HP Photosmart Essential2.5
"{8DC42D05-680B-41B0-8878-6C14D24602DB}" = QuickTime
"{90120000-0015-0409-0000-0000000FF1CE}" = Microsoft Office Access MUI (English) 2007
"{90120000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2007
"{90120000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2007
"{90120000-0019-0409-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (English) 2007
"{90120000-001A-0409-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (English) 2007
"{90120000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007
"{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007
"{90120000-0044-0409-0000-0000000FF1CE}" = Microsoft Office InfoPath MUI (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007
"{90120000-00A1-0409-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2007
"{90120000-00BA-0409-0000-0000000FF1CE}" = Microsoft Office Groove MUI (English) 2007
"{90120000-0114-0409-0000-0000000FF1CE}" = Microsoft Office Groove Setup Metadata MUI (English) 2007
"{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007
"{90120000-0117-0409-0000-0000000FF1CE}" = Microsoft Office Access Setup Metadata MUI (English) 2007
"{9061CEF2-51F5-42C9-8A70-9ED351C6597A}" = HP Help and Support
"{90A40409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office 2003 Web Components
"{91110409-6000-11D3-8CFE-0050048383C9}" = Microsoft Office XP Professional
"{91120000-002E-0000-0000-0000000FF1CE}" = Microsoft Office Ultimate 2007
"{91120000-002F-0000-0000-0000000FF1CE}" = Microsoft Office Home and Student 2007
"{9F7FC79B-3059-4264-9450-39EB368E3225}" = Microsoft Digital Image Library 9 - Blocker
"{A040AC77-C1AA-4CC9-8931-9F648AF178F6}" = VC 9.0 Runtime
"{A49F249F-0C91-497F-86DF-B2585E8E76B7}" = Microsoft Visual C++ 2005 Redistributable
"{A5181519-9F3D-4372-ABC6-C333C2F3A816}_is1" = RunAlyzer
"{A7E4ECCA-4A8E-4258-8EC8-2DCCF5B11320}" = Windows Live installer
"{A85D8CC4-4DB9-11D6-B038-0000B49CEE91}" = PCForrest StartMan 1.3.96
"{A87B11AC-4344-4E5D-8B12-8F471A87DAD9}" = LightScribe 1.4.136.1
"{A918DE8A-98C8-0920-0000-000000220051}" = Samsung A950 USB - Handset Manager V9.2
"{A918DE8A-98C8-0920-1000-0000040F0000}" = Mediaphone Expert - V9.2
"{A939D341-5A04-4E0A-BB55-3E65B386432D}" = Microsoft Office Small Business Connectivity Components
"{A96E97134CA649888820BCDE5E300BBD}" = H.264 Decoder
"{AA9768AA-FF0B-4C66-A085-31E934F77841}" = Apple Mobile Device Support
"{AAC389499AEF40428987B3D30CFC76C9}" = MKV Splitter
"{AB5E289E-76BF-4251-9F3F-9B763F681AE0}" = HP Customer Experience Enhancements
"{AC76BA86-7AD7-1033-7B44-A81000000003}" = Adobe Reader 8.1.1
"{AC76BA86-7AD7-5464-3428-800000000003}" = Spelling Dictionaries Support For Adobe Reader 8
"{AEF9DC35ADDF4825B049ACBFD1C6EB37}" = AAC Decoder
"{AF5E8D43-49AD-4BE7-A941-2BB0A8CACA62}" = ACDSee 5.0 Standard
"{B0717D5A-1976-482B-9ADF-F19631A541A4}" = Microsoft Office Accounting 2007
"{B13A7C41581B411290FBC0395694E2A9}" = DivX Converter
"{B1D89E54-08B1-4542-A69B-E634AEF10A40}" = Seagate Manager Installer
"{B32C4059-6E7A-41EF-AD20-56DF1872B923}" = Business Contact Manager for Outlook 2007 SP1
"{B4092C6D-E886-4CB2-BA68-FE5A88D31DE6}_is1" = Spybot - Search & Destroy
"{B6335C5F-0064-4F90-8447-52614F8F0CE0}" = HP User Guides 0079
"{B7050CBDB2504B34BC2A9CA0A692CC29}" = DivX Web Player
"{B76D4A7F-FF11-4420-947C-C3AD624B9DBA}" = Jasc Paint Shop Photo Album
"{B7A0CE06-068E-11D6-97FD-0050BACBF861}" = PowerProducer
"{B97CF5C3-0487-11D8-A36E-0050BAE317E1}" = DVD Solution
"{BD68F46D-8A82-4664-8E68-F87C55BDEFD4}" = Microsoft SQL Server Native Client
"{C8B0680B-CDAE-4809-9F91-387B6DE00F7C}" = Roxio Creator Basic v9
"{C9A87D86-FDFD-418B-BF96-EF09320973B3}" = PC Inspector smart recovery
"{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}" = SUPERAntiSpyware Free Edition
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{CF097717-F174-4144-954A-FBC4BF301033}" = Nero 7 Ultra Edition
"{D2FCC1AE-6311-47C5-8130-C6C66D77DD71}" = Nikon Message Center
"{D32067CD-7409-4792-BFA0-1469BCD8F0C8}" = HP Wireless Assistant
"{D3A04D2F-28C4-4D9C-8487-DAB75992AE09}" = AIM Pro
"{D45E8C45-B601-4A80-AFD8-E16338744DE1}" = ArcSoft Panorama Maker 4
"{DED53B0B-B67C-4244-AE6A-D6FD3C28D1EF}" = Ad-Aware
"{E9757890-7EC5-46C8-99AB-B00F07B6525C}" = Nikon Transfer
"{F333A33D-125C-32A2-8DCE-5C5D14231E27}" = Visual C++ 2008 x86 Runtime - (v9.0.30729)
"{F333A33D-125C-32A2-8DCE-5C5D14231E27}.vc_x86runtime_30729_01" = Visual C++ 2008 x86 Runtime - v9.0.30729.01
"{F6B29003-A078-4491-AFBE-62EFB6CFFE19}" = HP Total Care Advisor
"{FA61D601-A0FC-48BD-AE7A-54946BCD7FB6}_is1" = BitPim 1.0.5
"{FAB0C302-CB18-4A7A-BA03-C3DC23101A68}" = HP Active Support Library 32 bit components
"{FDA14220-0C7A-4804-ACC5-E01A2AA791D2}" = Jasc After Shot
"3554AA4B-9B0B-451a-A269-2B5F53982209_is1" = ThreatFire
"44953928-E730-4e8c-A2B2-3A85BC96A3D0_is1" = FileSeek 1.6.0
"Activation Assistant for the 2007 Microsoft Office suites" = Activation Assistant for the 2007 Microsoft Office suites
"Ad-Aware" = Ad-Aware
"Advanced SystemCare 3_is1" = Advanced SystemCare 3
"AIM_6" = AIM 6
"Aspell English Dictionary_is1" = Aspell English Dictionary-0.50-2
"avast!" = avast! Antivirus
"AVS4YOU Software Navigator_is1" = AVS4YOU Software Navigator 1.2
"AVS4YOU Video Converter 6_is1" = AVS Video Converter 6
"Business Contact Manager" = Business Contact Manager for Outlook 2007 SP1
"CCleaner" = CCleaner (remove only)
"CNXT_AUDIO_HDA" = Conexant HD Audio
"CNXT_MODEM_HDA_HSF" = HDAUDIO Soft Data Fax Modem with SmartCP
"CodeStuff Starter" = CodeStuff Starter
"Daniusoft Media Converter_is1" = Daniusoft Media Converter(Build [removed])
"Disketch" = Disketch CD Label Software
"DivX Plus DirectShow Filters" = DivX Plus DirectShow Filters
"DVDFab (Platinum/Gold/HD Decrypter) (Option: Mobile) 5_is1" = DVDFab (Platinum/Gold/HD Decrypter) (Option: Mobile) 5.0.5.0
"DVDFab HD Decrypter 4_is1" = DVDFab HD Decrypter 4.0.6.2
"DVDFab HD Decrypter_is1" = DVDFab HD Decrypter 3.1.5.0
"EF Commander Free" = EF Commander Free
"exPressit S.E. 2.2" = exPressit S.E. 2.2
"Free M4a to MP3 Converter_is1" = Free M4a to MP3 Converter 6.0
"GNU Aspell_is1" = GNU Aspell 0.50-3
"Google Updater" = Google Updater
"GTK 2.0" = GTK+ Runtime 2.12.12 rev a (remove only)
"HashOnClick_is1" = HashOnClick
"HDMI" = Intel® Graphics Media Accelerator Driver
"HijackThis" = HijackThis 2.0.2
"HOMESTUDENTR" = Microsoft Office Home and Student 2007
"HP Photosmart Essential" = HP Photosmart Essential 2.0
"HP-Color LaserJet 2600n" = Color LaserJet 2600n
"InstallShield_{6B10045E-6789-49C4-BFED-52575F5B76BF}" = Avery Wizard 3.0
"InstallShield_{B1D89E54-08B1-4542-A69B-E634AEF10A40}" = Seagate Manager Installer
"InstallShield_{FDA14220-0C7A-4804-ACC5-E01A2AA791D2}" = Jasc After Shot
"IrfanView" = IrfanView (remove only)
"JDVoiceMail" = JDVoiceMail 2.50
"KeyScrambler" = KeyScrambler
"KLiteCodecPack_is1" = K-Lite Mega Codec Pack 4.5.3
"Kronen-Design_is1" = Kronen-Design 1.43
"LogonStudio Vista" = LogonStudio Vista
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"MediaMonkey_is1" = MediaMonkey 3.0
"MediaNavigation.CDLabelPrint" = CD-LabelPrint
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Microsoft Office Accounting 2007" = Microsoft Office Accounting 2007
"Microsoft Office Accounting Equifax Addin" = Microsoft Office Accounting Equifax Addin
"Microsoft Office Accounting PayPal Addin" = Microsoft Office Accounting PayPal Addin
"Microsoft SQL Server 2005" = Microsoft SQL Server 2005
"Miro" = Miro
"Mozilla Firefox (3.0.7)" = Mozilla Firefox (3.0.7)
"MSNINST" = MSN
"Passport to 35 Languages" = Passport to 35 Languages
"Pegasus Mail" = Pegasus Mail
"Picasa2" = Picasa 2
"PictureItSuite_v12" = Microsoft Digital Image Suite Anniversary Edition
"Pidgin" = Pidgin
"Revo Uninstaller" = Revo Uninstaller 1.50
"Samsung ML-1710 Series" = Samsung ML-1710 Series
"SanityCheck_is1" = SanityCheck 1.02
"Send To Toys_is1" = Send To Toys v2.5
"SereneScreen Marine Aquarium" = SereneScreen Marine Aquarium
"ShadowExplorer_is1" = ShadowExplorer 0.4
"SimplyCapture1.3" = SimplyCapture
"Spybot - Search & Destroy_is1" = Spybot - Search & Destroy 1.5.2.20
"Spyware Doctor" = Spyware Doctor 5.1
"Spyware Terminator_is1" = Spyware Terminator
"SpywareBlaster_is1" = SpywareBlaster 4.1
"SX Print" = SX Print
"SynTPDeinstKey" = Synaptics Pointing Device Driver
"TeamViewer 3" = TeamViewer 3
"ULTIMATER" = Microsoft Office Ultimate 2007
"Veoh Web Player Beta" = Veoh Web Player Beta
"VidShot Capturer_is1" = VidShot Capturer
"VLC media player" = VideoLAN VLC media player 0.8.6c
"ZoneAlarm Pro" = ZoneAlarm Pro

========== Last 10 Event Log Errors ==========

[ Antivirus Events ]
Error - 3/14/2009 12:01:33 AM | Computer Name = Loris-Compaq | Source = avast! | ID = 33554522
Description = AAVM - scanning error: x_AavmCheckFileDirectEx: avfilesScanReal of
http://ubuntu.cs.wisc.edu/pub/mirrors/linu…esktop-i386.iso
failed, 00000084.

Error - 3/14/2009 9:19:10 AM | Computer Name = Loris-Compaq | Source = avast! | ID = 33554522
Description = AAVM - scanning error: x_AavmCheckFileDirectEx: avfilesScanReal of
C:\Users\HP\AppData\Local\Temp\~DFF2C4.tmp failed, 00000005.

Error - 3/22/2009 12:34:49 PM | Computer Name = Loris-Compaq | Source = avast! | ID = 33554522
Description = AAVM - scanning error: x_AavmCheckFileDirectEx: avfilesScanReal of
C:\Windows\System32\msiltcfg.dll failed, 00000005.

[ Application Events ]
Error - 3/15/2009 10:40:39 PM | Computer Name = Loris-Compaq | Source = Lavasoft Ad-Aware Service | ID = 0
Description =

Error - 3/15/2009 11:37:08 PM | Computer Name = Loris-Compaq | Source = Application Error | ID = 1000
Description = Faulting application winpm-32.exe, version 4.4.1.0, time stamp 0x00000000,
faulting module winpm-32.exe, version 4.4.1.0, time stamp 0x00000000, exception
code 0xc0000005, fault offset 0x00097e08, process id 0x12d8, application start time
0x01c9a5e4c0c0b877.

Error - 3/16/2009 6:41:52 AM | Computer Name = Loris-Compaq | Source = EventSystem | ID = 4621
Description =

Error - 3/16/2009 9:24:22 AM | Computer Name = Loris-Compaq | Source = Perflib | ID = 1010
Description =

Error - 3/17/2009 12:57:34 AM | Computer Name = Loris-Compaq | Source = EventSystem | ID = 4609
Description =

Error - 3/17/2009 5:15:05 AM | Computer Name = Loris-Compaq | Source = EventSystem | ID = 4621
Description =

Error - 3/18/2009 6:15:03 PM | Computer Name = Loris-Compaq | Source = EventSystem | ID = 4609
Description =

Error - 3/23/2009 4:26:34 PM | Computer Name = Loris-Compaq | Source = EventSystem | ID = 4621
Description =

Error - 3/23/2009 4:39:38 PM | Computer Name = Loris-Compaq | Source = EventSystem | ID = 4609
Description =

Error - 3/23/2009 4:59:07 PM | Computer Name = Loris-Compaq | Source = EventSystem | ID = 4609
Description =

[ OSession Events ]
Error - 3/20/2009 8:52:01 PM | Computer Name = Loris-Compaq | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 16, Application Name: Microsoft Office Groove, Application Version:
12.0.6211.1000, Microsoft Office Version: 12.0.6215.1000. This session lasted 51
seconds with 0 seconds of active time. This session ended with a crash.

[ System Events ]
Error - 3/19/2008 8:44:48 PM | Computer Name = Loris-Compaq | Source = Service Control Manager | ID = 7011
Description =

Error - 3/19/2008 10:22:18 PM | Computer Name = Loris-Compaq | Source = EventLog | ID = 6008
Description = The previous system shutdown at 9:20:09 PM on 3/19/2008 was unexpected.

Error - 3/19/2008 10:22:45 PM | Computer Name = Loris-Compaq | Source = Print | ID = 19
Description = The print spooler failed to share printer LOCAL Samsung ML-1710 Series
with shared resource name Samsung ML-1710 Series. Error 2114. The printer cannot
be used by others on the network.

Error - 3/19/2008 10:22:45 PM | Computer Name = Loris-Compaq | Source = Print | ID = 19
Description = The print spooler failed to share printer Canon i560 Inkjet with shared
resource name Canon i560 Inkjet. Error 2114. The printer cannot be used by others
on the network.

Error - 3/19/2008 10:23:51 PM | Computer Name = Loris-Compaq | Source = Service Control Manager | ID = 7000
Description =

Error - 3/19/2008 10:42:08 PM | Computer Name = Loris-Compaq | Source = DCOM | ID = 10010
Description =

Error - 3/19/2008 10:50:06 PM | Computer Name = Loris-Compaq | Source = EventLog | ID = 6008
Description = The previous system shutdown at 9:48:12 PM on 3/19/2008 was unexpected.

Error - 3/19/2008 10:50:33 PM | Computer Name = Loris-Compaq | Source = Print | ID = 19
Description = The print spooler failed to share printer LOCAL Samsung ML-1710 Series
with shared resource name Samsung ML-1710 Series. Error 2114. The printer cannot
be used by others on the network.

Error - 3/19/2008 10:50:33 PM | Computer Name = Loris-Compaq | Source = Print | ID = 19
Description = The print spooler failed to share printer Canon i560 Inkjet with shared
resource name Canon i560 Inkjet. Error 2114. The printer cannot be used by others
on the network.

Error - 3/19/2008 10:51:41 PM | Computer Name = Loris-Compaq | Source = Service Control Manager | ID = 7000
Description =


< End of report >


===== end of Extras.txt ========
Hi dtd,

There is no active malware showing in your log

What I do see is an over abundance of spyware programs, some of which don't have the best reputation in the industry.

You have too many offering real time protection, that may be causing conflicts.

The free trial program that is causing all the alerts is just trying to get you to buy their product.

I suggest you uninstall the following: (either through Add/Remove Programs or the programs own uninstaller)

  • Spy Sweeper
  • Zone Labs
  • Ad-Aware
  • Spyware Terminator
  • Threat Fire
  • Spybot Search and Destroy
  • Spyware Doctor.

Keep the others and then install a third party Firewall. (I uses Comodo - but can recommend others)

I recommend using a third party firewall to protect your computer.
We don't recommend the firewall that comes built in to Windows.
It doesn't block everything that may try to get in, and the entire firewall is written to the registry.

As various kinds of malware hack the Registry in order to disable the Windows firewall, it's far preferable to install one of the excellent third party solutions.

Three excellent free firewalls are:
Comodo
Sunbelt Kerio
Sygate
NOTE: DO NOT install more than one firewall.

Note: If you choose Comodo - Please be careful with the installation of the Comodo program, it comes bundled with an adware toolbar which you need to de-select when you are going through the installation process. It's not a malicious program, but it may be a privacy risk and I don't think you want it on your system.


  • Avast is a good anti-virus - keep it.
  • SuperAdBlocker
  • SuperAntiSpyware.com - both good to keep


I see you also have MalwareBytes Antimalware installed - that's a good program.

NEXT


To make sure you are totally clean of Malware please do the following:


First:

Please download ATF Cleaner by Atribune.
  • Double-click ATF-Cleaner.exe to run the program.
  • Under Main choose: Select All
  • Click the Empty Selected button.
    • If you use Firefox browser
    • Click Firefox at the top and choose: Select All
  • Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click No at the prompt.
Click Exit on the Main menu to close the program.
It's normal after running ATF cleaner that the PC will be slower to boot the first time.


Next


Open the MalwareBytes AntiMalware program
  • Update the program and allow it to do a quick scan…
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.
  • Copy&Paste the entire report in your next reply.

Next


Go to Kaspersky website and perform an online antivirus scan.
  • Read through the requirements and privacy statement and click on Accept button.
  • It will start downloading and installing the scanner and virus definitions. You will be prompted to install an application from Kaspersky. Click Run.
  • When the downloads have finished, click on Settings.
  • Make sure these boxes are checked (ticked). If they are not, please tick them and click on the Save button:
    • Spyware, Adware, Dialers, and other potentially dangerous programs
      Archives
      Mail databases
  • Click on My Computer under Scan.
  • Once the scan is complete, it will display the results. Click on View Scan Report.
  • You will see a list of infected items there. Click on Save Report As….
  • Save this report to a convenient place. Change the Files of type to Text file (.txt) before clicking on the Save button. Then post it here.
CB - thanks.. a couple questions - 1) are u sure about removing Zone Labs? –.. thats "ZoneAlarm Pro" (current version) - the paid version of the ZoneAlarm firewall. "ZoneLabs" is the old company name b4 it was bought out by Check Point Software. No idea why the old name is still being used… thanks for the warning -im aware of the Comodo Firewall adware, its one of the reasons i didnt use it. 2)I'll do it but i've some concern about uninstalling SpySweeper - SpySweeper is the only one that has notified me of the attempts to connect to those sites. not sure if was just "1st in line" or if any of the others would of detected these attempts. im aware of the possible conflicts (none that ive seen yet.. just slows things down) w/ too many security programs installed. i installed what i could, to try and root this problem out. I will uninstall them b4 doing the next steps on ur reply. thanks!
By all means keep the ZoneAlarm Pro if you like the program…don't know why they would keep the old name either…not a great rep. Zone alarm was noted for coming packaged with unwanted bloat ware at one time. SpySweeper is causing you alarm for no reason…I believe it to be a ploy to get you to purchase their product…I don't believe there is anything on your system to cause the behaviour it is reporting. I think you'll be fine with out it. There are much better programs out there….Spyware Guard and Spyware Blaster are two (I have links to those in my closing recommendations)…but we're getting ahead of ourselves here…lets run those scans and be certain you are clean first.
sorry, this is taking awhile… trying to do the kaspersky scan… 1) tried IE after 2nd scan w/ firefox, - vista DEP protection shuts IE down as soon as i clk "scan". 2)firefox - on 4th attempt now. scans take 3+ hrs. scan runs & completes BUT cant seem to get it to "save" the scan report - click the link but nothing happens. 3rd attempt was w/ safe mode firefox - wouldnt even do anything. current- 4th is w/ most firefox plug-ins disabled. (ad-block plus, noscript…) ================== did try to manually copy the scan results list line by line from 1st & 2nd FF scans ( had same results listed)… as follows — list order: FILE || RESULT || CODE C:\Telecom\Downloads\New Files\marratech v6.1 conference software - Marratech61.msi || not-a-virus:RemoteAdmin.Win32.WinVNC.4 || 2 C:\Temp\Memstick files\Telecom\Downloads\CrossLoop 1.11 remote access - crossloopsetup.exe || not-a-virus:RemoteAdmin.Win32.WinVNC-based.h || 1 C:\Temp\Memstick files\Telecom\Downloads\CrossLoop 1.11 remote access - crossloopsetup.exe || not-a-virus:RemoteAdmin.Win32.WinVNC-based.b || 1 C:\Telecom\Internet\PMAIL\MAIL\FOL00313.PMM || Exploit.HTML.Iframe.FileDownload || 2 C:\Telecom\Internet\PMAIL\MAIL\FOL06C0A.PMM || Exploit.HTML.CodeBaseExec || 1 ============================= first 3 im pretty sure are false positives, detected because the programs use the same methods "remote admin", downloaded either directly or from softpedia. 2nd 2 are compressed mail archive folders (couple yrs old) for Pegasus Mail. - i'm really not concerned about the infected msg's in them as pmail as configured will only display messages in plain text and w/o previews. haven't done anything w/ the above files/folders yet til you say so. have some bad thunderstorms moving in so may not get back on for a day or 2 will repost the kaspersky scan result if i can get it to save.., Thanks!
Sounds good, You can delete those old emails if you wish, then run ATF cleaner again to clear them out. Whenever you get the opportunity, I'd like to see the results of the MalwareBytes scan… sounds as though all the issues were as I suspected - false positives, but lets get the MBAM scan to be certain. Thanks CB
CB - ive backup copies of those email folders on cd's so just deleted em since they are a few yrs old and not really being used. the other 2 programs i also deleted - going to re-download and submit them online to (cant think of who it is right now)
Good Please run HJT Do a scan and save a log file Post the fresh HJT log here so I can make sure it's clean, thanks
CB -

heres the HJT log file

i notice that despite uninstalling it i still have the webroot spysweeper service…, along w/ lines from bitdefender & symantec (as usual), both uninstalled also.
prob should download and run the symantec uninstaller tool just to clear the clutter it leaves in the registery.
any suggestions as to a good uninstaller/registery cleaner?

Thanks!

========

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 10:43:24 PM, on 3/25/2009
Platform: Windows Vista SP1 (WinNT 6.00.1905)
MSIE: Internet Explorer v7.00 (7.00.6001.18000)
Boot mode: Normal

Running processes:
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Synaptics\SynTP\SynTPStart.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Windows\System32\igfxpers.exe
C:\Windows\System32\hkcmd.exe
C:\Util\Security\ZoneAlarm\zlclient.exe
C:\Util\Security\Alwil Software\Avast\ashDisp.exe
C:\Windows\system32\igfxsrvc.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Util\Security\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://home.mchsi.com/~auntlorrie/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…O&pf=laptop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…O&pf=laptop
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Telecom\Internet\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O2 - BHO: QFX Software KeyScrambler - {2B9F5787-88A5-4945-90E7-C4B18563BC5E} - C:\Util\Security\KeyScrambler\KeyScramblerIE.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll
O2 - BHO: Java™ Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O4 - HKLM\..\Run: [SynTPStart] "C:\Program Files\Synaptics\SynTP\SynTPStart.exe"
O4 - HKLM\..\Run: [SynTPEnh] "C:\Program Files\Synaptics\SynTP\SynTPEnh.exe"
O4 - HKLM\..\Run: [Kernel and Hardware Abstraction Layer] "C:\Windows\KHALMNPR.EXE"
O4 - HKLM\..\Run: [Persistence] "C:\Windows\system32\igfxpers.exe"
O4 - HKLM\..\Run: [IgfxTray] "C:\Windows\system32\igfxtray.exe"
O4 - HKLM\..\Run: [HotKeysCmds] "C:\Windows\system32\hkcmd.exe"
O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Util\Security\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [avast!] C:\Util\Security\ALWILS~1\Avast\ashDisp.exe
O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\Windows\system32\GPhotos.scr/200
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra button: (no name) - {5C106A59-CC3C-4caa-81A4-6D909B5ACE23} - C:\Util\Security\KeyScrambler\KeyScramblerIE.dll
O9 - Extra 'Tools' menuitem: &KeyScrambler… - {5C106A59-CC3C-4caa-81A4-6D909B5ACE23} - C:\Util\Security\KeyScrambler\KeyScramblerIE.dll
O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Telecom\Internet\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
O13 - Gopher Prefix:
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedC…n/bin/cabsa.cab
O16 - DPF: {BDBDE413-7B1C-4C68-A8FF-C5B2B4090876} (F-Secure Online Scanner 3.3) - http://support.f-secure.com/ols/fscax.cab
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - Winlogon Notify: !SASWinLogon - C:\Util\Security\SUPERAntiSpyware\SASWINLO.dll
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Util\Security\Alwil Software\Avast\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Util\Security\Alwil Software\Avast\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Util\Security\Alwil Software\Avast\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Util\Security\Alwil Software\Avast\ashWebSv.exe
O23 - Service: Com4Qlb - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\Com4Qlb.exe
O23 - Service: Seagate Service (FreeAgentGoNext Service) - Seagate Technology LLC - C:\Util\AddOns\Seagate\SeagateManager\Sync\FreeAgentService.exe
O23 - Service: HP Health Check Service - Hewlett-Packard - C:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe
O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: MHPHAAJC - Unknown owner - c:\temp\WinTemp\MHPHAAJC.exe (file missing)
O23 - Service: NBService - Nero AG - C:\Util\CD-DVD\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
O23 - Service: nmraapache - Nero AG - (no file)
O23 - Service: RoxMediaDB9 - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe
O23 - Service: TeamViewer 3 (TeamViewer) - Unknown owner - C:\Telecom\Internet\TeamViewer3\TeamViewer_Host.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Check Point Software Technologies LTD - C:\Windows\System32\ZoneLabs\vsmon.exe
O23 - Service: Webroot Client Service (WRConsumerService) - Webroot Software, Inc. - C:\Util\Security\Spy Sweeper\WRConsumerService.exe
O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe

–
End of file - 7352 bytes
Hi


Please do the following


Click Start >Run type notepad into the run box click OK
Click Format and make certain that Word Wrap is NOT checked.

Copy all the text inside of the code box, put your mouse cursor at the very beginning of the text and then hold down the left button and drag your mouse so that all of the text is highlighted. Press Ctrl+C (or right click on the highlighted section and choose 'copy')

@echo off
SC stop WRConsumerService 
SC delete WRConsumerService 
attrib -s -h -r C:\Util\Security\Spy Sweeper\WRConsumerService.exe 
del /f /q C:\Util\Security\Spy Sweeper\WRConsumerService.exe 
del %0

Now paste the copied text into the open notepad. To do this click in the blank page so that your cursor is flashing there and press CTRL+V (or right click and choose 'paste')

Now go to File > and click Save As,
From the drop down menu at the top of the box choose Desktop as the location to save this file.
Go down to the File Name box and type in runme.bat as the file name, then choose All Files as the save as file type.
Then click the save button.
Once you have clicked the save button, close Notepad.

You will now have a file on your desktop that looks like this

[external image: Posted Image]

Locate runme.bat on your Desktop and double-click it
A black window will flash up and disappear again, and runme.bat will be deleted.
This is normal.


NEXT

Download the Norton Removal Tool from HERE and save it to your desktop.
Next  Double click on Norton_Removal_Tool.exe  to run the tool.
Follow the on-screen instructions.
Your computer may be restarted more than once, and you may be asked to repeat some steps after the computer restarts.

NEXT

Download the BitDefender Uninstall Tool
Save it to your Desktop.
After the download completes double-click the bit defender uninstall tool icon on your desktop
After a couple of moments the uninstall tool interface will appear;
Click Uninstall;
Wait for the tool to display the completion message and then restart your computer.

NOTE:

DO NOT be tempted to install a registry cleaner…I do not recommend them - they can really mess up your registry - they are not required…clutter in your registry is exceptionally small and does no harm…it is best left alone.
we still have a little tidying up to do

please do the following:

Run OTList2.exe
  • Copy/paste the following text written inside of the code box into the Custom Scans/Fixes box located at the bottom of OTLI2

    :OTLI
    PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
    SRV - (EPMGXAG [Disabled | Stopped]) – File not found
    SRV - (GYY [Disabled | Stopped]) – File not found
    SRV - (MHPHAAJC [On_Demand | Stopped]) – File not found
    SRV - (nmraapache [On_Demand | Stopped]) – File not found
    SRV - (PAWC [Disabled | Stopped]) – File not found
    SRV - (S [Disabled | Stopped]) – File not found
    SRV - (YRO [Disabled | Stopped]) – File not found
    O23 - Service: MHPHAAJC - Unknown owner - c:\temp\WinTemp\MHPHAAJC.exe (file missing)
    
    :Services
    
    :Reg
    
    :Files
    
    :Commands
    [purity]
    [emptytemp]
    [start explorer]
    [Reboot]
  • Then click the Run Fix button at the top
  • Let the program run unhindered, reboot when it is done
  • Then post a new OTL2 log ( don't check the boxes beside LOP Check or Purity this time )

NEXT

Please download JavaRa to your desktop and unzip it to its own folder
  • Run JavaRa.exe, pick the language of your choice and click Select. Then click Remove Older Versions.
  • Accept any prompts.
  • Open JavaRa.exe again and select Search For Updates.
  • Select Update Using Sun Java's Website then click Search and click on the Open Webpage button.
  • Download and install the latest Java Runtime Environment (JRE) version for your computer. Version 6 update 13


Please include the OTListIt log in your next response and advise if you are having any other issues.

We still have the final clean up to do after that….

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI