This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Mal Hifrm keeps coming back

6 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Last Friday, Trend Micro Antivirus caught a Mal Hifrm virus, and did not know what to do with it. I looked up how to remove it and followed the instructions from a forum that someone else created (http://forums.whatthetech.com/Need_Help_Removing_Mal_Hifrm_t102224.html) and it seemed to have worked. However, over the weekend Sunday morning to be exact, TMA caught the same virus. Since I didn't have time to work on it Sunday, I worked on it today (Monday morning). I went to turn on my PC and it couldn't get past the Windows splash screen. I turned my PC off and started in Safe Mode, and ran all the steps from the earlier post. It seemed to have cleaned it, I thought, but then about an hour and half later TMA caught the virus a 3rd time. I have just ran through all the steps the 3rd time, but it seems that the virus just won't go away. What can I do, and why does it keep coming back?

This is the log file from Hijackthis:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 6:05:44 PM, on 4/24/2009
Platform: Windows Vista SP1 (WinNT 6.00.1905)
MSIE: Internet Explorer v7.00 (7.00.6001.18226)
Boot mode: Normal

Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\system32\taskeng.exe
C:\Windows\Explorer.EXE
C:\Windows\RtHDVCpl.exe
C:\Windows\System32\igfxtray.exe
C:\Windows\System32\hkcmd.exe
C:\Windows\system32\igfxsrvc.exe
C:\Windows\System32\igfxpers.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\Program Files\Trend Micro\Internet Security\UfSeAgnt.exe
C:\Program Files\TuneClone\TuneClone.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\HP\HP Software Update\hpwuSchd2.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Windows\ehome\ehtray.exe
C:\Windows\ehome\ehmsas.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\OpenOffice.org 2.4\program\soffice.exe
C:\Program Files\OpenOffice.org 2.4\program\soffice.BIN
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\Program Files\HP\Digital Imaging\bin\hpqbam08.exe
C:\Program Files\HP\Digital Imaging\bin\hpqgpc01.exe
C:\Program Files\Internet Explorer\ieuser.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_clipbook.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Users\Owner\AppData\Local\Temp\cdBC7B.tmp\2009 codebase\installers\cdinstaller8\bin\runtime\edc-cyberdefender_v2\cdinstx.exe
C:\Windows\system32\Macromed\Flash\FlashUtil10b.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.msnbc.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Internet Explorer provided by Dell
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O1 - Hosts: ::1 localhost
O2 - BHO: (no name) - MRI_DISABLED - (no file)
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
O2 - BHO: HP Smart BHO Class - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [dscactivate] "C:\Program Files\Dell Support Center\gs_agent\custom\dsca.exe"
O4 - HKLM\..\Run: [ISUSPM Startup] "C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe" -startup
O4 - HKLM\..\Run: [UfSeAgnt.exe] "C:\Program Files\Trend Micro\Internet Security\UfSeAgnt.exe"
O4 - HKLM\..\Run: [TuneClone] "C:\Program Files\TuneClone\TuneClone.exe" /silence
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [AppleSyncNotifier] "C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe"
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\HP\HP Software Update\HPWuSchd2.exe"
O4 - HKLM\..\Run: [hpqSRMon] "C:\Program Files\HP\Digital Imaging\bin\hpqSRMon.exe"
O4 - HKLM\..\Run: [SpySweeper] C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe /startintray
O4 - HKCU\..\Run: [Sidebar] "C:\Program Files\Windows Sidebar\Sidebar.exe" /autorun
O4 - HKCU\..\Run: [RunSpySweeperScheduleAtStartup] "C:\Windows\system32\msfeedssync.exe" /ScheduleSweep=User_Feed_Synchronization-{27F294F5-2659-4FFE-A5C1-A02D8A2CB28D}
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [WMPNSCFG] "C:\Program Files\Windows Media Player\WMPNSCFG.exe"
O4 - HKCU\..\Run: [CyberDefender Early Detection Center] "C:\Users\Owner\AppData\Local\CyberDefender Internet Security\AntiSpyware\cdas7ad.exe" /minimize
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O4 - Startup: OpenOffice.org 2.4.lnk = C:\Program Files\OpenOffice.org 2.4\program\quickstart.exe
O4 - Global Startup: Digital Line Detect.lnk = C:\Program Files\Digital Line Detect\DLG.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_04\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_04\bin\ssv.dll
O9 - Extra button: HP Smart Select - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
O13 - Gopher Prefix:
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx1.hotmail.com/mail/w3/pr01/resou…NPUplden-us.cab
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: Intuit Update Service (IntuitUpdateService) - Intuit Inc. - C:\Program Files\Common Files\Intuit\Update Service\IntuitUpdateService.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Linksys Updater (LinksysUpdater) - Unknown owner - C:\Program Files\Linksys\Linksys Updater\bin\LinksysUpdater.exe
O23 - Service: RoxMediaDB9 - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
O23 - Service: Roxio Hard Drive Watcher 9 (RoxWatch9) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe
O23 - Service: Trend Micro Central Control Component (SfCtlCom) - Trend Micro Inc. - C:\Program Files\Trend Micro\Internet Security\SfCtlCom.exe
O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe
O23 - Service: Trend Micro Unauthorized Change Prevention Service (TMBMServer) - Trend Micro Inc. - C:\Program Files\Trend Micro\BM\TMBMSRV.exe
O23 - Service: Trend Micro Proxy Service (tmproxy) - Trend Micro Inc. - C:\Program Files\Trend Micro\Internet Security\TmProxy.exe
O23 - Service: Webroot Spy Sweeper Engine (WebrootSpySweeperService) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe

–
End of file - 8093 bytes
Hi and :welcome:

The reason the infection keeps returning is because I didn't design that fix for your machine…no two computers are the same and the same infection can infect different computers in different ways…that computer was a 64bit system - yours is 32 bit.

Now lets look after yours:

Please do the following:

Download Rooter.exe to your desktop

  • Doubleclick it to start the tool
  • A Notepad file containing the report will open, also found at %systemdrive%\Rooter.txt (Where %systemdrive% is usually C: or the drive that you have installed Windows).
  • Post that in your next reply.

NEXT

  • Download OTListIt2 to your desktop.
  • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output.
  • Check the boxes beside LOP Check and Purity Check.
  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
  • When the scan completes, it will open two notepad windows. OTListIt.Txt and Extras.Txt. These are saved in the same location as OTListIt2.
  • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post it with your next reply.

In your next reply I need

  • Rooter Log
  • OTLI2 Log
Hi CatByte,

Thank you for taking a look at this.

I ran the Rooter.exe program and right as it started I got this error message

windows - no disk
Exception processing Message 0xc0000013 Parameters 0x75BE92a0
0x00000004 0x75BE92A0 0x75BE92A0

I clicked on the continue button several times finally it gave me the TXT file. Below is the file.

Microsoft Windows Vista Home Edition (6.0.6001) Service Pack 1

C:\ [Fixed] - NTFS - (Total:294955 Mo/Free:3774 Mo)
D:\ [Fixed] - NTFS - (Total:305242 Mo/Free:2039 Mo)
E:\ [Fixed] - NTFS - (Total:10239 Mo/Free:1974 Mo)
F:\ [CD-Rom] (Total:0 Mo/Free:0 Mo)
H:\ [Removable] (Total:0 Mo/Free:0 Mo)
I:\ [Removable] (Total:0 Mo/Free:0 Mo)
J:\ [Removable] (Total:0 Mo/Free:0 Mo)
K:\ [CD-Rom] (Total:0 Mo/Free:0 Mo)
L:\ [Removable] (Total:0 Mo/Free:0 Mo)

Mon 04/27/2009|18:37

———————-\\ Processes..

–Locked– [System Process]
–Locked– System
———- \SystemRoot\System32\smss.exe
———- C:\Windows\system32\csrss.exe
———- C:\Windows\system32\wininit.exe
———- C:\Windows\system32\csrss.exe
———- C:\Windows\system32\services.exe
———- C:\Windows\system32\lsass.exe
———- C:\Windows\system32\lsm.exe
———- C:\Windows\system32\winlogon.exe
———- C:\Windows\system32\svchost.exe
———- C:\Windows\system32\svchost.exe
———- C:\Windows\System32\svchost.exe
———- C:\Windows\System32\svchost.exe
———- C:\Windows\system32\svchost.exe
–Locked– audiodg.exe
———- C:\Windows\system32\SLsvc.exe
———- C:\Windows\system32\svchost.exe
———- C:\Windows\system32\svchost.exe
———- C:\Windows\System32\spoolsv.exe
———- C:\Windows\system32\svchost.exe
———- C:\Windows\system32\Dwm.exe
———- C:\Windows\system32\taskeng.exe
———- C:\Windows\Explorer.EXE
———- C:\Windows\RtHDVCpl.exe
———- C:\Windows\System32\igfxtray.exe
———- C:\Windows\System32\hkcmd.exe
———- C:\Windows\System32\igfxpers.exe
———- C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
———- C:\Program Files\Trend Micro\Internet Security\UfSeAgnt.exe
———- C:\Program Files\TuneClone\TuneClone.exe
———- C:\Windows\system32\taskeng.exe
———- C:\Program Files\iTunes\iTunesHelper.exe
———- C:\Program Files\HP\HP Software Update\hpwuSchd2.exe
———- C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe
———- C:\Program Files\Windows Sidebar\sidebar.exe
———- C:\Windows\ehome\ehtray.exe
———- C:\Program Files\Windows Media Player\wmpnscfg.exe
———- C:\Program Files\Digital Line Detect\DLG.exe
———- C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
———- C:\Windows\system32\igfxsrvc.exe
———- C:\Windows\ehome\ehmsas.exe
———- C:\Program Files\OpenOffice.org 2.4\program\soffice.exe
———- C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
———- C:\Windows\system32\svchost.exe
———- C:\Program Files\Linksys\Linksys Updater\bin\LinksysUpdater.exe
———- C:\Windows\System32\svchost.exe
———- C:\Windows\System32\svchost.exe
———- C:\Windows\system32\svchost.exe
———- C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe
———- C:\Program Files\Trend Micro\Internet Security\SfCtlCom.exe
———- C:\Windows\system32\svchost.exe
———- C:\Windows\system32\java.exe
———- C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
———- C:\Windows\System32\svchost.exe
———- C:\Windows\system32\SearchIndexer.exe
———- C:\Windows\system32\DRIVERS\xaudio.exe
———- C:\Program Files\Trend Micro\BM\TMBMSRV.exe
———- C:\Windows\system32\WUDFHost.exe
———- C:\Program Files\OpenOffice.org 2.4\program\soffice.BIN
———- C:\Program Files\Windows Media Player\wmpnetwk.exe
———- C:\Program Files\iPod\bin\iPodService.exe
———- C:\Program Files\Webroot\Spy Sweeper\SSU.EXE
———- C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
———- C:\Program Files\HP\Digital Imaging\bin\hpqbam08.exe
———- C:\Program Files\Trend Micro\Internet Security\TmProxy.exe
———- C:\Program Files\HP\Digital Imaging\bin\hpqgpc01.exe
———- C:\Windows\system32\wbem\unsecapp.exe
———- C:\Windows\system32\wbem\wmiprvse.exe
———- C:\Program Files\Common Files\Intuit\Update Service\IntuitUpdateService.exe
———- C:\Program Files\Internet Explorer\ieuser.exe
———- C:\Program Files\Internet Explorer\iexplore.exe
———- C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_clipbook.exe
———- C:\Windows\system32\taskeng.exe
———- C:\Windows\system32\cmd.exe
———- C:\Windows\system32\SearchProtocolHost.exe
———- C:\Windows\system32\SearchFilterHost.exe
———- C:\Rooter$\RK.exe

———————-\\ Search..

———————-\\ ROOTKIT !!



1 - "C:\Rooter$\Rooter_1.txt" - Mon 04/27/2009|18:30
2 - "C:\Rooter$\Rooter_2.txt" - Mon 04/27/2009|18:37

**********************************************************************

Next I ran the OTList2.exe program, It only proivded me with the OTLIST.TxT file. the Extras.TXT file never came up. I ran it twice to ensure I wasn't messing anything up. Here is the TXT file below.

OTListIt logfile created on: 4/27/2009 6:52:36 PM - Run 3
OTListIt2 by OldTimer - Version 2.0.14.0 Folder = C:\Users\Owner\Desktop
Windows Vista Home Premium Edition Service Pack 1 (Version = 6.0.6001) - Type = NTWorkstation
Internet Explorer (Version = 7.0.6001.18000)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

2.00 Gb Total Physical Memory | 1.85 Gb Available Physical Memory | 92.31% Memory free
4.00 Gb Paging File | 4.00 Gb Available in Paging File | 100.00% Paging File free
Paging file location(s): ?:\pagefile.sys;

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 288.04 Gb Total Space | 207.66 Gb Free Space | 72.09% Space Free | Partition Type: NTFS
Drive D: | 298.09 Gb Total Space | 297.99 Gb Free Space | 99.97% Space Free | Partition Type: NTFS
Drive E: | 10.00 Gb Total Space | 5.93 Gb Free Space | 59.28% Space Free | Partition Type: NTFS
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: OWNER-PC
Current User Name: Owner
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Output = Minimal
File Age = 30 Days
Company Name Whitelist: On

========== Processes (SafeList) ==========

PRC - C:\Windows\Explorer.EXE (Microsoft Corporation)
PRC - C:\Windows\RtHDVCpl.exe (Realtek Semiconductor)
PRC - C:\Windows\System32\igfxtray.exe (Intel Corporation)
PRC - C:\Windows\System32\hkcmd.exe (Intel Corporation)
PRC - C:\Windows\System32\igfxpers.exe (Intel Corporation)
PRC - C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe (Macrovision Corporation)
PRC - C:\Program Files\Trend Micro\Internet Security\UfSeAgnt.exe (Trend Micro Inc.)
PRC - C:\Program Files\TuneClone\TuneClone.exe (TuneClone.COM)
PRC - C:\Program Files\iTunes\iTunesHelper.exe (Apple Inc.)
PRC - C:\Program Files\HP\HP Software Update\hpwuSchd2.exe (Hewlett-Packard)
PRC - C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe (Webroot Software, Inc.)
PRC - C:\Program Files\Windows Sidebar\sidebar.exe (Microsoft Corporation)
PRC - C:\Windows\ehome\ehtray.exe (Microsoft Corporation)
PRC - C:\Program Files\Windows Media Player\wmpnscfg.exe (Microsoft Corporation)
PRC - C:\Program Files\Digital Line Detect\DLG.exe (Avanquest Software )
PRC - C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe (Hewlett-Packard Co.)
PRC - C:\Windows\system32\igfxsrvc.exe (Intel Corporation)
PRC - C:\Windows\ehome\ehmsas.exe (Microsoft Corporation)
PRC - C:\Program Files\OpenOffice.org 2.4\program\soffice.exe (OpenOffice.org)
PRC - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe (Apple Inc.)
PRC - C:\Program Files\Linksys\Linksys Updater\bin\LinksysUpdater.exe ()
PRC - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe (Sonic Solutions)
PRC - C:\Program Files\Trend Micro\Internet Security\SfCtlCom.exe (Trend Micro Inc.)
PRC - C:\Windows\system32\java.exe (Sun Microsystems, Inc.)
PRC - C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe (Webroot Software, Inc.)
PRC - C:\Windows\system32\DRIVERS\xaudio.exe (Conexant Systems, Inc.)
PRC - C:\Program Files\Trend Micro\BM\TMBMSRV.exe (Trend Micro Inc.)
PRC - C:\Windows\system32\WUDFHost.exe (Microsoft Corporation)
PRC - C:\Program Files\OpenOffice.org 2.4\program\soffice.BIN (OpenOffice.org)
PRC - C:\Program Files\Windows Media Player\wmpnetwk.exe (Microsoft Corporation)
PRC - C:\Program Files\iPod\bin\iPodService.exe (Apple Inc.)
PRC - C:\Program Files\Webroot\Spy Sweeper\SSU.EXE ()
PRC - C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe (Hewlett-Packard Co.)
PRC - C:\Program Files\HP\Digital Imaging\bin\hpqbam08.exe (Hewlett-Packard Co.)
PRC - C:\Program Files\Trend Micro\Internet Security\TmProxy.exe (Trend Micro Inc.)
PRC - C:\Program Files\HP\Digital Imaging\bin\hpqgpc01.exe (Hewlett-Packard)
PRC - C:\Windows\system32\wbem\unsecapp.exe (Microsoft Corporation)
PRC - C:\Windows\system32\wbem\wmiprvse.exe (Microsoft Corporation)
PRC - C:\Program Files\Common Files\Intuit\Update Service\IntuitUpdateService.exe (Intuit Inc.)
PRC - C:\Users\Owner\Desktop\OTListIt2.exe (OldTimer Tools)
PRC - C:\Program Files\Internet Explorer\ieuser.exe (Microsoft Corporation)
PRC - C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation)
PRC - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_clipbook.exe (Hewlett-Packard Co.)

========== Win32 Services (SafeList) ==========

SRV - (Apple Mobile Device [Auto | Running]) – C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe (Apple Inc.)
SRV - (clr_optimization_v2.0.50727_32 [On_Demand | Stopped]) – C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
SRV - (ehRecvr [On_Demand | Stopped]) – C:\Windows\ehome\ehRecvr.exe (Microsoft Corporation)
SRV - (ehSched [On_Demand | Stopped]) – C:\Windows\ehome\ehsched.exe (Microsoft Corporation)
SRV - (ehstart [Auto | Stopped]) – C:\Windows\ehome\ehstart.dll (Microsoft Corporation)
SRV - (FontCache3.0.0.0 [On_Demand | Stopped]) – C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe (Microsoft Corporation)
SRV - (hpqcxs08 [On_Demand | Running]) – C:\Program Files\HP\Digital Imaging\bin\hpqcxs08.dll (Hewlett-Packard Co.)
SRV - (hpqddsvc [Auto | Running]) – C:\Program Files\HP\Digital Imaging\bin\hpqddsvc.dll (Hewlett-Packard Co.)
SRV - (IDriverT [On_Demand | Stopped]) – C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe (Macrovision Corporation)
SRV - (idsvc [Unknown | Stopped]) – C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe (Microsoft Corporation)
SRV - (IntuitUpdateService [Auto | Running]) – C:\Program Files\Common Files\Intuit\Update Service\IntuitUpdateService.exe (Intuit Inc.)
SRV - (iPod Service [On_Demand | Running]) – C:\Program Files\iPod\bin\iPodService.exe (Apple Inc.)
SRV - (LinksysUpdater [Auto | Running]) – C:\Program Files\Linksys\Linksys Updater\bin\LinksysUpdater.exe ()
SRV - (Net Driver HPZ12 [Auto | Running]) – C:\Windows\system32\HPZinw12.dll (Hewlett-Packard)
SRV - (NetTcpPortSharing [Disabled | Stopped]) – C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe (Microsoft Corporation)
SRV - (Pml Driver HPZ12 [Auto | Running]) – C:\Windows\system32\HPZipm12.dll (Hewlett-Packard)
SRV - (RoxMediaDB9 [On_Demand | Stopped]) – C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe (Sonic Solutions)
SRV - (RoxWatch9 [Auto | Running]) – C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe (Sonic Solutions)
SRV - (SfCtlCom [Auto | Running]) – C:\Program Files\Trend Micro\Internet Security\SfCtlCom.exe (Trend Micro Inc.)
SRV - (stllssvr [On_Demand | Stopped]) – C:\Program Files\Common Files\SureThing Shared\stllssvr.exe (MicroVision Development, Inc.)
SRV - (TMBMServer [Auto | Running]) – C:\Program Files\Trend Micro\BM\TMBMSRV.exe (Trend Micro Inc.)
SRV - (tmproxy [On_Demand | Running]) – C:\Program Files\Trend Micro\Internet Security\TmProxy.exe (Trend Micro Inc.)
SRV - (WebrootSpySweeperService [Auto | Running]) – C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe (Webroot Software, Inc.)
SRV - (WinDefend [Auto | Stopped]) – C:\Program Files\Windows Defender\mpsvc.dll (Microsoft Corporation)
SRV - (WMPNetworkSvc [On_Demand | Running]) – C:\Program Files\Windows Media Player\wmpnetwk.exe (Microsoft Corporation)
SRV - (XAudioService [Auto | Running]) – C:\Windows\system32\DRIVERS\xaudio.exe (Conexant Systems, Inc.)

========== Driver Services (SafeList) ==========

DRV - (adp94xx [Disabled | Stopped]) – C:\Windows\system32\drivers\adp94xx.sys (Adaptec, Inc.)
DRV - (adpahci [Disabled | Stopped]) – C:\Windows\system32\drivers\adpahci.sys (Adaptec, Inc.)
DRV - (adpu160m [Disabled | Stopped]) – C:\Windows\system32\drivers\adpu160m.sys (Adaptec, Inc.)
DRV - (adpu320 [Disabled | Stopped]) – C:\Windows\system32\drivers\adpu320.sys (Adaptec, Inc.)
DRV - (aic78xx [Disabled | Stopped]) – C:\Windows\system32\drivers\djsvs.sys (Adaptec, Inc.)
DRV - (aliide [Disabled | Stopped]) – C:\Windows\system32\drivers\aliide.sys (Acer Laboratories Inc.)
DRV - (arc [Disabled | Stopped]) – C:\Windows\system32\drivers\arc.sys (Adaptec, Inc.)
DRV - (arcsas [Disabled | Stopped]) – C:\Windows\system32\drivers\arcsas.sys (Adaptec, Inc.)
DRV - (BrFiltLo [On_Demand | Stopped]) – C:\Windows\system32\drivers\brfiltlo.sys (Brother Industries, Ltd.)
DRV - (BrFiltUp [On_Demand | Stopped]) – C:\Windows\system32\drivers\brfiltup.sys (Brother Industries, Ltd.)
DRV - (Brserid [Disabled | Stopped]) – C:\Windows\system32\drivers\brserid.sys (Brother Industries Ltd.)
DRV - (BrSerWdm [Disabled | Stopped]) – C:\Windows\system32\drivers\brserwdm.sys (Brother Industries Ltd.)
DRV - (BrUsbMdm [Disabled | Stopped]) – C:\Windows\system32\drivers\brusbmdm.sys (Brother Industries Ltd.)
DRV - (BrUsbSer [On_Demand | Stopped]) – C:\Windows\system32\drivers\brusbser.sys (Brother Industries Ltd.)
DRV - (cmdide [Disabled | Stopped]) – C:\Windows\system32\drivers\cmdide.sys (CMD Technology, Inc.)
DRV - (DrmCDriverV32 [On_Demand | Stopped]) – C:\Windows\system32\drivers\DrmCDriverV32.sys (Windows ® Codename Longhorn DDK provider)
DRV - (DrmCVideo32 [On_Demand | Stopped]) – C:\Windows\system32\DRIVERS\DrmCVideo32.sys (Windows ® 2000 DDK provider)
DRV - (e1express [On_Demand | Running]) – C:\Windows\system32\DRIVERS\e1e6032.sys (Intel Corporation)
DRV - (E1G60 [On_Demand | Stopped]) – C:\Windows\system32\DRIVERS\E1G60I32.sys (Intel Corporation)
DRV - (elxstor [Disabled | Stopped]) – C:\Windows\system32\drivers\elxstor.sys (Emulex)
DRV - (GEARAspiWDM [On_Demand | Running]) – C:\Windows\System32\Drivers\GEARAspiWDM.sys (GEAR Software Inc.)
DRV - (HpCISSs [Disabled | Stopped]) – C:\Windows\system32\drivers\hpcisss.sys (Hewlett-Packard Company)
DRV - (HSF_DPV [On_Demand | Running]) – C:\Windows\system32\DRIVERS\HSX_DPV.sys (Conexant Systems, Inc.)
DRV - (HSXHWBS2 [On_Demand | Running]) – C:\Windows\system32\DRIVERS\HSXHWBS2.sys (Conexant Systems, Inc.)
DRV - (iaStor [Disabled | Stopped]) – C:\Windows\system32\drivers\iastor.sys (Intel Corporation)
DRV - (iaStorV [Disabled | Stopped]) – C:\Windows\system32\drivers\iastorv.sys (Intel Corporation)
DRV - (igfx [On_Demand | Running]) – C:\Windows\system32\DRIVERS\igdkmd32.sys (Intel Corporation)
DRV - (iirsp [Disabled | Stopped]) – C:\Windows\system32\drivers\iirsp.sys (Intel Corp./ICP vortex GmbH)
DRV - (IntcAzAudAddService [On_Demand | Running]) – C:\Windows\system32\drivers\RTKVHDA.sys (Realtek Semiconductor Corp.)
DRV - (iteatapi [Disabled | Stopped]) – C:\Windows\system32\drivers\iteatapi.sys (Integrated Technology Express, Inc.)
DRV - (iteraid [Disabled | Stopped]) – C:\Windows\system32\drivers\iteraid.sys (Integrated Technology Express, Inc.)
DRV - (LSI_FC [Disabled | Stopped]) – C:\Windows\system32\drivers\lsi_fc.sys (LSI Logic)
DRV - (LSI_SAS [Disabled | Stopped]) – C:\Windows\system32\drivers\lsi_sas.sys (LSI Logic)
DRV - (LSI_SCSI [Disabled | Stopped]) – C:\Windows\system32\drivers\lsi_scsi.sys (LSI Logic)
DRV - (mdmxsdk [Auto | Running]) – C:\Windows\system32\DRIVERS\mdmxsdk.sys (Conexant)
DRV - (megasas [Disabled | Stopped]) – C:\Windows\system32\drivers\megasas.sys (LSI Corporation)
DRV - (MegaSR [Disabled | Stopped]) – C:\Windows\system32\drivers\megasr.sys (LSI Corporation, Inc.)
DRV - (Mraid35x [Disabled | Stopped]) – C:\Windows\system32\drivers\mraid35x.sys (LSI Logic Corporation)
DRV - (nfrd960 [Disabled | Stopped]) – C:\Windows\system32\drivers\nfrd960.sys (IBM Corporation)
DRV - (ntrigdigi [Disabled | Stopped]) – C:\Windows\system32\drivers\ntrigdigi.sys (N-trig Innovative Technologies)
DRV - (nvraid [Disabled | Stopped]) – C:\Windows\system32\drivers\nvraid.sys (NVIDIA Corporation)
DRV - (nvstor [Disabled | Stopped]) – C:\Windows\system32\drivers\nvstor.sys (NVIDIA Corporation)
DRV - (PxHelp20 [Boot | Running]) – C:\Windows\System32\Drivers\PxHelp20.sys (Sonic Solutions)
DRV - (ql2300 [Disabled | Stopped]) – C:\Windows\system32\drivers\ql2300.sys (QLogic Corporation)
DRV - (ql40xx [Disabled | Stopped]) – C:\Windows\system32\drivers\ql40xx.sys (QLogic Corporation)
DRV - (R300 [On_Demand | Stopped]) – C:\Windows\system32\DRIVERS\atikmdag.sys (ATI Technologies Inc.)
DRV - (secdrv [Auto | Running]) – C:\Windows\System32\drivers\secdrv.sys (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.)
DRV - (SiSRaid4 [Disabled | Stopped]) – C:\Windows\system32\drivers\sisraid4.sys (Silicon Integrated Systems)
DRV - (SSFS0BB9 [Boot | Running]) – C:\Windows\SYSTEM32\Drivers\SSFS0BB9.SYS (Webroot Software Inc (www.webroot.com))
DRV - (SSHRMD [Boot | Running]) – C:\Windows\SYSTEM32\Drivers\SSHRMD.SYS (Webroot Software Inc (www.webroot.com))
DRV - (SSIDRV [Boot | Running]) – C:\Windows\SYSTEM32\Drivers\SSIDRV.SYS (Webroot Software Inc (www.webroot.com))
DRV - (SSKBFD [On_Demand | Running]) – C:\Windows\System32\Drivers\sskbfd.sys (Webroot Software Inc (www.webroot.com))
DRV - (Symc8xx [Disabled | Stopped]) – C:\Windows\system32\drivers\symc8xx.sys (LSI Logic)
DRV - (Sym_hi [Disabled | Stopped]) – C:\Windows\system32\drivers\sym_hi.sys (LSI Logic)
DRV - (Sym_u3 [Disabled | Stopped]) – C:\Windows\system32\drivers\sym_u3.sys (LSI Logic)
DRV - (tclondrv [Boot | Running]) – C:\Windows\system32\DRIVERS\tclondrv.sys (TuneClone Software)
DRV - (tmactmon [Auto | Running]) – C:\Windows\system32\DRIVERS\tmactmon.sys (Trend Micro Inc.)
DRV - (tmcomm [Auto | Running]) – C:\Windows\system32\DRIVERS\tmcomm.sys (Trend Micro Inc.)
DRV - (tmevtmgr [Auto | Running]) – C:\Windows\system32\DRIVERS\tmevtmgr.sys (Trend Micro Inc.)
DRV - (tmpreflt [Auto | Running]) – C:\Windows\system32\DRIVERS\tmpreflt.sys (Trend Micro Inc.)
DRV - (tmtdi [System | Running]) – C:\Windows\system32\DRIVERS\tmtdi.sys (Trend Micro Inc.)
DRV - (tmxpflt [Auto | Running]) – C:\Windows\system32\DRIVERS\tmxpflt.sys (Trend Micro Inc.)
DRV - (uliahci [Disabled | Stopped]) – C:\Windows\system32\drivers\uliahci.sys (ULi Electronics Inc.)
DRV - (UlSata [Disabled | Stopped]) – C:\Windows\system32\drivers\ulsata.sys (Promise Technology, Inc.)
DRV - (ulsata2 [Disabled | Stopped]) – C:\Windows\system32\drivers\ulsata2.sys (Promise Technology, Inc.)
DRV - (USBAAPL [On_Demand | Stopped]) – C:\Windows\System32\Drivers\usbaapl.sys (Apple, Inc.)
DRV - (viaide [Disabled | Stopped]) – C:\Windows\system32\drivers\viaide.sys (VIA Technologies, Inc.)
DRV - (vsapint [Auto | Running]) – C:\Windows\system32\DRIVERS\vsapint.sys (Trend Micro Inc.)
DRV - (vsmraid [Disabled | Stopped]) – C:\Windows\system32\drivers\vsmraid.sys (VIA Technologies Inc.,Ltd)
DRV - (winachsf [On_Demand | Running]) – C:\Windows\system32\DRIVERS\HSX_CNXT.sys (Conexant Systems, Inc.)
DRV - (XAudio [Auto | Running]) – C:\Windows\system32\DRIVERS\xaudio.sys (Conexant Systems, Inc.)

========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL =
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:NoAdd-ons
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:SecurityRisk
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.google.com/ig/dell?hl=en&cl…amp;ibd=2080313
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\system32\blank.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.msnbc.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

FF - HKLM\software\mozilla\Firefox\Extensions\\{20a82645-c095-46ed-80e3-08825760534b}: C:\WINDOWS\MICROSOFT.NET\FRAMEWORK\V3.5\WINDOWS PRESENTATION FOUNDATION\DOTNETASSISTANTEXTENSION\ [2009/04/27 07:53:22 | 00,000,000 | —D | M]


O1 HOSTS File: (761 bytes) - C:\Windows\System32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - Reg Error: Key error. File not found
O2 - BHO: (HP Smart BHO Class) - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll (Hewlett-Packard Co.)
O2 - BHO: (no name) - MRI_DISABLED - Reg Error: Key error. File not found
O4 - HKLM..\Run: [] File not found
O4 - HKLM..\Run: [AppleSyncNotifier] "C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe" (Apple Inc.)
O4 - HKLM..\Run: [dscactivate] "C:\Program Files\Dell Support Center\gs_agent\custom\dsca.exe" ( )
O4 - HKLM..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe (Intel Corporation)
O4 - HKLM..\Run: [HP Software Update] "C:\Program Files\HP\HP Software Update\HPWuSchd2.exe" (Hewlett-Packard)
O4 - HKLM..\Run: [hpqSRMon] "C:\Program Files\HP\Digital Imaging\bin\hpqSRMon.exe" (Hewlett-Packard)
O4 - HKLM..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe (Intel Corporation)
O4 - HKLM..\Run: [ISUSPM Startup] "C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe" -startup (Macrovision Corporation)
O4 - HKLM..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start (Macrovision Corporation)
O4 - HKLM..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe" (Apple Inc.)
O4 - HKLM..\Run: [Persistence] C:\Windows\system32\igfxpers.exe (Intel Corporation)
O4 - HKLM..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime (Apple Inc.)
O4 - HKLM..\Run: [RtHDVCpl] RtHDVCpl.exe (Realtek Semiconductor)
O4 - HKLM..\Run: [SpySweeper] C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe /startintray (Webroot Software, Inc.)
O4 - HKLM..\Run: [TuneClone] "C:\Program Files\TuneClone\TuneClone.exe" /silence (TuneClone.COM)
O4 - HKLM..\Run: [UfSeAgnt.exe] "C:\Program Files\Trend Micro\Internet Security\UfSeAgnt.exe" (Trend Micro Inc.)
O4 - HKCU..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe (Microsoft Corporation)
O4 - HKCU..\Run: [RunSpySweeperScheduleAtStartup] "C:\Windows\system32\msfeedssync.exe" /ScheduleSweep=User_Feed_Synchronization-{27F294F5-2659-4FFE-A5C1-A02D8A2CB28D} (Microsoft Corporation)
O4 - HKCU..\Run: [Sidebar] "C:\Program Files\Windows Sidebar\Sidebar.exe" /autorun (Microsoft Corporation)
O4 - HKCU..\Run: [WMPNSCFG] "C:\Program Files\Windows Media Player\WMPNSCFG.exe" (Microsoft Corporation)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 2
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableInstallerDetection = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableSecureUIAPaths = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableVirtualization = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ValidateAdminCodeSignatures = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: scforceoption = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: FilterAdministratorToken = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_TEXT = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_BITMAP = 2
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_OEMTEXT = 7
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_DIB = 8
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_PALETTE = 9
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_UNICODETEXT = 13
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_DIBV5 = 17
O9 - Extra 'Tools' menuitem : Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_04\bin\ssv.dll (Sun Microsystems, Inc.)
O9 - Extra Button: HP Smart Select - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll (Hewlett-Packard Co.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000001 [@%SystemRoot%\system32\nlasvc.dll,-1000] - C:\Windows\system32\NLAapi.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000002 [@%SystemRoot%\system32\napinsp.dll,-1000] - C:\Windows\system32\napinsp.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000003 [@%SystemRoot%\system32\pnrpnsp.dll,-1000] - C:\Windows\system32\pnrpnsp.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [@%SystemRoot%\system32\pnrpnsp.dll,-1001] - C:\Windows\system32\pnrpnsp.dll (Microsoft Corporation)
O13 - gopher Prefix: missing
O15 - HKCU\..Trusted Sites: //@surf.mar@/ ([]money in Local intranet)
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} http://gfx1.hotmail.com/mail/w3/pr01/resou…NPUplden-us.cab (MSN Photo Upload Tool)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_04)
O16 - DPF: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_03)
O16 - DPF: {CAFEEFAC-0016-0000-0004-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_04)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_04)
O18 - Protocol\Handler\ms-itss {0A9007C0-4076-11D3-8789-0000F8105754} - C:\Program Files\Common Files\Microsoft Shared\Information Retrieval\msitss.dll (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\igfxcui: DllName - igfxdev.dll - C:\Windows\system32\igfxdev.dll (Intel Corporation)
O31 - SafeBoot: AlternateShell - cmd.exe
O32 - HKLM CDRom: AutoRun - 1
O32 - Autorun File - C:\autoexec.bat () - [ NTFS ]
O33 - MountPoints2\{2da635ff-eca1-11dd-a4a8-001d098d59ab}\Shell\AutoRun\command - "" = G:\mri.exe – File not found
O34 - HKLM BootExecute: (autocheck) - File not found
O34 - HKLM BootExecute: (autochk) - C:\Windows\System32\autochk.exe (Microsoft Corporation)
O34 - HKLM BootExecute: (*) - File not found

========== Files/Folders - Created Within 30 Days ==========

[2009/04/27 18:38:56 | 00,501,248 | —- | C] (OldTimer Tools) – C:\Users\Owner\Desktop\OTListIt2.exe
[2009/04/27 18:34:11 | 00,267,612 | —- | C] () – C:\Users\Owner\Desktop\Rooter.exe
[2009/04/27 18:29:07 | 00,000,000 | —D | C] – C:\Rooter$
[2009/04/27 08:01:57 | 00,000,000 | —D | C] – C:\Users\Owner\AppData\Local\Apple Computer
[2009/04/27 07:48:18 | 00,097,800 | —- | C] (Microsoft Corporation) – C:\Windows\System32\infocardapi.dll
[2009/04/27 07:48:17 | 00,622,080 | —- | C] (Microsoft Corporation) – C:\Windows\System32\icardagt.exe
[2009/04/27 07:48:17 | 00,105,016 | —- | C] (Microsoft Corporation) – C:\Windows\System32\PresentationCFFRasterizerNative_v0300.dll
[2009/04/27 07:48:17 | 00,043,544 | —- | C] (Microsoft Corporation) – C:\Windows\System32\PresentationHostProxy.dll
[2009/04/27 07:48:17 | 00,037,384 | —- | C] (Microsoft Corporation) – C:\Windows\System32\infocardcpl.cpl
[2009/04/27 07:48:17 | 00,011,264 | —- | C] (Microsoft Corporation) – C:\Windows\System32\icardres.dll
[2009/04/27 07:48:15 | 00,781,344 | —- | C] (Microsoft Corporation) – C:\Windows\System32\PresentationNative_v0300.dll
[2009/04/27 07:48:13 | 00,326,160 | —- | C] (Microsoft Corporation) – C:\Windows\System32\PresentationHost.exe
[2009/04/27 07:40:50 | 00,096,760 | —- | C] (Microsoft Corporation) – C:\Windows\System32\dfshim.dll
[2009/04/27 07:40:46 | 00,282,112 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mscoree.dll
[2009/04/27 07:40:44 | 00,041,984 | —- | C] (Microsoft Corporation) – C:\Windows\System32\netfxperf.dll
[2009/04/27 07:40:29 | 00,158,720 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mscorier.dll
[2009/04/27 07:40:25 | 00,083,968 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mscories.dll
[2009/04/27 07:32:19 | 01,328,228 | -H– | C] () – C:\Users\Owner\AppData\Local\IconCache.db
[2009/04/27 07:23:45 | 32,098,75456 | -HS- | C] () – C:\hiberfil.sys
[2009/04/24 18:14:22 | 00,000,000 | —D | C] – C:\Users\Owner\AppData\Roaming\Malwarebytes
[2009/04/24 18:14:20 | 00,015,504 | —- | C] (Malwarebytes Corporation) – C:\Windows\System32\drivers\mbam.sys
[2009/04/24 18:14:20 | 00,000,820 | —- | C] () – C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2009/04/24 18:14:17 | 00,038,496 | —- | C] (Malwarebytes Corporation) – C:\Windows\System32\drivers\mbamswissarmy.sys
[2009/04/24 18:14:16 | 00,000,000 | —D | C] – C:\ProgramData\Malwarebytes
[2009/04/24 18:14:16 | 00,000,000 | —D | C] – C:\Program Files\Malwarebytes' Anti-Malware
[2009/04/24 18:04:59 | 00,001,876 | —- | C] () – C:\Users\Owner\Desktop\HijackThis.lnk
[2009/04/15 07:13:47 | 00,376,832 | —- | C] (Microsoft Corporation) – C:\Windows\System32\winhttp.dll
[2009/04/15 07:13:46 | 00,562,176 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msdtcprx.dll
[2009/04/15 07:13:46 | 00,038,912 | —- | C] (Microsoft Corporation) – C:\Windows\System32\xolehlp.dll
[2009/04/15 07:13:39 | 03,599,328 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ntkrnlpa.exe
[2009/04/15 07:13:39 | 03,547,632 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ntoskrnl.exe
[2009/04/15 07:13:39 | 00,551,424 | —- | C] (Microsoft Corporation) – C:\Windows\System32\rpcss.dll
[2009/04/15 07:13:38 | 00,666,624 | —- | C] (Microsoft Corporation) – C:\Windows\System32\printfilterpipelinesvc.exe
[2009/04/15 07:13:38 | 00,183,296 | —- | C] (Microsoft Corporation) – C:\Windows\System32\sdohlp.dll
[2009/04/15 07:13:38 | 00,098,304 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iasrecst.dll
[2009/04/15 07:13:38 | 00,054,784 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iasads.dll
[2009/04/15 07:13:38 | 00,044,032 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iasdatastore.dll
[2009/04/15 07:13:38 | 00,026,112 | —- | C] (Microsoft Corporation) – C:\Windows\System32\printfilterpipelineprxy.dll
[2009/04/15 07:13:38 | 00,017,408 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iashost.exe
[2009/04/15 07:13:35 | 01,255,936 | —- | C] (Microsoft Corporation) – C:\Windows\System32\lsasrv.dll
[2009/04/15 07:13:35 | 00,888,832 | —- | C] (Microsoft Corporation) – C:\Windows\System32\kernel32.dll
[2009/04/15 07:13:35 | 00,072,704 | —- | C] (Microsoft Corporation) – C:\Windows\System32\secur32.dll
[2009/04/15 07:13:34 | 00,024,064 | —- | C] (Microsoft Corporation) – C:\Windows\System32\amxread.dll
[2009/04/15 07:13:34 | 00,013,824 | —- | C] (Microsoft Corporation) – C:\Windows\System32\apilogen.dll
[2009/04/15 07:13:31 | 03,580,928 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mshtml.dll
[2009/04/15 07:13:30 | 06,068,736 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieframe.dll
[2009/04/15 07:13:30 | 01,166,336 | —- | C] (Microsoft Corporation) – C:\Windows\System32\urlmon.dll
[2009/04/15 07:13:29 | 00,827,392 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wininet.dll
[2009/04/15 07:13:29 | 00,671,232 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mstime.dll
[2009/04/15 07:13:29 | 00,458,240 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msfeeds.dll
[2009/04/15 07:13:29 | 00,389,632 | —- | C] (Microsoft Corporation) – C:\Windows\System32\html.iec
[2009/04/15 07:13:29 | 00,389,120 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iedkcs32.dll
[2009/04/15 07:13:29 | 00,270,336 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iertutil.dll
[2009/04/15 07:13:29 | 00,230,400 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieaksie.dll
[2009/04/15 07:13:29 | 00,102,912 | —- | C] (Microsoft Corporation) – C:\Windows\System32\occache.dll
[2009/04/15 07:13:29 | 00,078,336 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieencode.dll
[2009/04/15 07:13:29 | 00,026,624 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieUnatt.exe
[2009/04/15 07:13:28 | 01,383,424 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mshtml.tlb
[2009/04/15 07:13:28 | 00,028,160 | —- | C] (Microsoft Corporation) – C:\Windows\System32\jsproxy.dll
[2009/04/11 16:59:52 | 04,707,148 | —- | C] () – C:\Users\Owner\Desktop\Audit_Support_Center.zip
[2008/06/29 15:30:33 | 00,026,480 | —- | C] () – C:\Windows\System32\wrlzma.dll
[2008/03/13 01:30:39 | 01,953,696 | —- | C] () – C:\Windows\System32\igklg400.dll
[2008/03/13 01:30:39 | 01,533,360 | —- | C] () – C:\Windows\System32\igklg450.dll
[2008/03/13 01:30:39 | 00,147,456 | —- | C] () – C:\Windows\System32\igfxCoIn_v1409.dll
[2008/03/13 01:30:39 | 00,104,636 | —- | C] () – C:\Windows\System32\igmedcompkrn.dll
[2008/03/13 01:30:38 | 00,876,544 | —- | C] () – C:\Windows\System32\TEACico2.dll
[2007/11/26 22:56:28 | 00,151,415 | —- | C] () – C:\Windows\System32\xlive.dll.cat
[2006/11/07 15:25:58 | 00,000,000 | —- | C] () – C:\Windows\System32\px.ini
[2006/11/02 08:35:32 | 00,005,632 | —- | C] () – C:\Windows\System32\sysprepMCE.dll
[2006/11/02 06:25:44 | 00,159,744 | —- | C] () – C:\Windows\System32\atitmmxx.dll
[2006/11/02 06:23:31 | 00,000,219 | —- | C] () – C:\Windows\system.ini
[2006/11/02 06:23:31 | 00,000,179 | —- | C] () – C:\Windows\win.ini
[2006/11/02 03:40:29 | 00,013,750 | —- | C] () – C:\Windows\System32\pacerprf.ini
[2006/09/16 23:36:50 | 00,520,192 | —- | C] () – C:\Windows\System32\CddbPlaylist2Roxio.dll
[2006/09/16 23:36:50 | 00,204,800 | —- | C] () – C:\Windows\System32\CddbFileTaggerRoxio.dll

========== Files - Modified Within 30 Days ==========

[2009/04/27 18:39:05 | 00,501,248 | —- | M] (OldTimer Tools) – C:\Users\Owner\Desktop\OTListIt2.exe
[2009/04/27 18:34:12 | 00,267,612 | —- | M] () – C:\Users\Owner\Desktop\Rooter.exe
[2009/04/27 18:15:44 | 05,230,318 | —- | M] () – C:\Windows\System32\perfh009.dat
[2009/04/27 18:15:44 | 01,712,588 | —- | M] () – C:\Windows\System32\perfc009.dat
[2009/04/27 18:15:44 | 00,004,884 | —- | M] () – C:\Windows\System32\PerfStringBackup.INI
[2009/04/27 18:11:23 | 00,003,616 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2009/04/27 18:11:21 | 00,003,616 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2009/04/27 18:11:16 | 00,000,006 | -H– | M] () – C:\Windows\tasks\SA.DAT
[2009/04/27 18:11:15 | 00,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2009/04/27 18:11:02 | 32,098,75456 | -HS- | M] () – C:\hiberfil.sys
[2009/04/27 08:22:59 | 01,328,228 | -H– | M] () – C:\Users\Owner\AppData\Local\IconCache.db
[2009/04/27 07:25:49 | 00,000,418 | -H– | M] () – C:\Windows\tasks\User_Feed_Synchronization-{27F294F5-2659-4FFE-A5C1-A02D8A2CB28D}.job
[2009/04/26 07:54:48 | 00,054,976 | —- | M] () – C:\Users\Owner\Desktop\Check Book.ods
[2009/04/24 18:14:20 | 00,000,820 | —- | M] () – C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2009/04/24 18:04:59 | 00,001,876 | —- | M] () – C:\Users\Owner\Desktop\HijackThis.lnk
[2009/04/11 17:00:06 | 04,707,148 | —- | M] () – C:\Users\Owner\Desktop\Audit_Support_Center.zip
[2009/04/06 15:32:54 | 00,038,496 | —- | M] (Malwarebytes Corporation) – C:\Windows\System32\drivers\mbamswissarmy.sys
[2009/04/06 15:32:46 | 00,015,504 | —- | M] (Malwarebytes Corporation) – C:\Windows\System32\drivers\mbam.sys
[2009/04/06 10:57:24 | 24,921,544 | —- | M] (Microsoft Corporation) – C:\Windows\System32\mrt.exe
[2009/04/02 16:00:12 | 00,052,752 | —- | M] (Trend Micro Inc.) – C:\Windows\System32\drivers\tmactmon.sys
[2009/04/02 16:00:08 | 00,052,624 | —- | M] (Trend Micro Inc.) – C:\Windows\System32\drivers\tmevtmgr.sys
[2009/04/02 16:00:00 | 00,142,864 | —- | M] (Trend Micro Inc.) – C:\Windows\System32\drivers\tmcomm.sys

========== LOP Check ==========

[2009/04/27 18:11:16 | 00,000,006 | -H– | M] () – C:\Windows\Tasks\SA.DAT
[2009/04/27 08:23:05 | 00,032,642 | —- | M] () – C:\Windows\Tasks\SCHEDLGU.TXT
[2009/04/27 07:25:49 | 00,000,418 | -H– | M] () – C:\Windows\Tasks\User_Feed_Synchronization-{27F294F5-2659-4FFE-A5C1-A02D8A2CB28D}.job

========== Purity Check ==========


========== Alternate Data Streams ==========

@Alternate Data Stream - 122 bytes -> C:\ProgramData\TEMP:0B174FAE
< End of report >


Thank you,

rk1115
Hi,

Please do the following:

Download ComboFix from one of these locations:
Link 1
Link 2
Link 3

VERY IMPORTANT !!!
Save ComboFix.exe to your Desktop

* IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here
  • Double click on ComboFix.exe & follow the prompts.
As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.
**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.

[external image: Posted Image]

  • Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]
  • Click on Yes, to continue scanning for malware.
When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.
Notes:
1. Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. Do not "re-run" Combofix. If you have a problem, reply back for further instructions.
3. ComboFix may reset a number of Internet Explorer's settings, including making I-E the default browser.
4. Combofix prevents autorun of ALL CD, floppy and USB devices to assist with malware removal & increase security. If this is an issue or makes it difficult for you – please advise.
5. CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.


Please make sure you include the combo fix log in your next reply as well as describe how your computer is running now
ok I downloaded and saved Combofix to my desktop, and disabled spysweeper and Trend Micro Antivirus. I did not get the "Query - Recovery Console" message box, so I'm assuming that my PC has Microsoft Windows Recovery Console installed. After Combofix finished running it produced the log, but I could not re-connect to the internet via IE. I restarted my PC as you advised. Below is the log from Combofix:

ComboFix 09-04-27.02 - Owner 04/27/2009 20:20.1 - NTFSx86
Microsoft® Windows Vista™ Home Premium 6.0.6001.1.1252.1.1033.18.3060.1865 [GMT -4:00]
Running from: c:\users\[removed]\Desktop\ComboFix.exe
AV: Trend Micro AntiVirus *On-access scanning disabled* (Updated)
* Created a new restore point
.

((((((((((((((((((((((((( Files Created from 2009-05-28 to 2009-4-28 )))))))))))))))))))))))))))))))
.

2009-04-27 22:29 . 2009-04-27 22:37 ——– d—–w C:\Rooter$
2009-04-27 12:01 . 2009-04-27 22:51 ——– d—–w c:\users\Owner\AppData\Local\Apple Computer
2009-04-27 11:48 . 2008-06-20 01:14 97800 —-a-w c:\windows\system32\infocardapi.dll
2009-04-27 11:48 . 2008-06-20 01:14 105016 —-a-w c:\windows\system32\PresentationCFFRasterizerNative_v0300.dll
2009-04-27 11:48 . 2008-06-20 01:14 622080 —-a-w c:\windows\system32\icardagt.exe
2009-04-27 11:48 . 2008-06-20 01:14 11264 —-a-w c:\windows\system32\icardres.dll
2009-04-27 11:48 . 2008-06-20 01:14 43544 —-a-w c:\windows\system32\PresentationHostProxy.dll
2009-04-27 11:48 . 2008-06-20 01:14 781344 —-a-w c:\windows\system32\PresentationNative_v0300.dll
2009-04-27 11:48 . 2008-06-20 01:14 326160 —-a-w c:\windows\system32\PresentationHost.exe
2009-04-27 11:40 . 2008-07-27 18:03 96760 —-a-w c:\windows\system32\dfshim.dll
2009-04-27 11:40 . 2008-07-27 18:03 282112 —-a-w c:\windows\system32\mscoree.dll
2009-04-27 11:40 . 2008-07-27 18:03 41984 —-a-w c:\windows\system32\netfxperf.dll
2009-04-27 11:40 . 2008-07-27 18:03 158720 —-a-w c:\windows\system32\mscorier.dll
2009-04-27 11:40 . 2008-07-27 18:03 83968 —-a-w c:\windows\system32\mscories.dll
2009-04-24 22:14 . 2009-04-24 22:14 ——– d—–w c:\users\Owner\AppData\Roaming\Malwarebytes
2009-04-24 22:14 . 2009-04-06 19:32 15504 —-a-w c:\windows\system32\drivers\mbam.sys
2009-04-24 22:14 . 2009-04-06 19:32 38496 —-a-w c:\windows\system32\drivers\mbamswissarmy.sys
2009-04-24 22:14 . 2009-04-24 22:14 ——– d—–w c:\programdata\Malwarebytes
2009-04-24 22:14 . 2009-04-24 22:14 ——– d—–w c:\users\All Users\Malwarebytes
2009-04-24 22:14 . 2009-04-24 22:14 ——– d—–w c:\program files\Malwarebytes' Anti-Malware

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-04-24 22:04 . 2008-06-29 19:30 ——– d—–w c:\program files\Trend Micro
2009-04-16 12:07 . 2006-11-02 11:18 ——– d—–w c:\program files\Windows Mail
2009-04-02 20:00 . 2008-02-16 04:34 52752 —-a-w c:\windows\system32\drivers\tmactmon.sys
2009-04-02 20:00 . 2008-02-16 04:34 52624 —-a-w c:\windows\system32\drivers\tmevtmgr.sys
2009-04-02 20:00 . 2008-02-16 04:34 142864 —-a-w c:\windows\system32\drivers\tmcomm.sys
2009-03-17 11:01 . 2008-06-29 18:03 87968 —-a-w c:\users\Owner\AppData\Local\GDIPFONTCACHEV1.DAT
2009-03-17 10:48 . 2009-03-17 10:48 ——– d—–w c:\program files\Common Files\AnswerWorks 5.0
2009-03-17 10:45 . 2009-03-17 10:42 ——– d—–w c:\program files\Common Files\Intuit
2009-03-17 10:40 . 2009-03-17 10:40 ——– d—–w c:\program files\TurboTax
2009-03-17 03:38 . 2009-04-15 11:13 40960 —-a-w c:\windows\AppPatch\apihex86.dll
2009-03-17 03:38 . 2009-04-15 11:13 13824 —-a-w c:\windows\system32\apilogen.dll
2009-03-17 03:38 . 2009-04-15 11:13 24064 —-a-w c:\windows\system32\amxread.dll
2009-03-03 04:46 . 2009-04-15 11:13 3599328 —-a-w c:\windows\system32\ntkrnlpa.exe
2009-03-03 04:46 . 2009-04-15 11:13 3547632 —-a-w c:\windows\system32\ntoskrnl.exe
2009-03-03 04:40 . 2009-04-15 11:13 827392 —-a-w c:\windows\system32\wininet.dll
2009-03-03 04:39 . 2009-04-15 11:13 183296 —-a-w c:\windows\system32\sdohlp.dll
2009-03-03 04:39 . 2009-04-15 11:13 551424 —-a-w c:\windows\system32\rpcss.dll
2009-03-03 04:39 . 2009-04-15 11:13 26112 —-a-w c:\windows\system32\printfilterpipelineprxy.dll
2009-03-03 04:37 . 2009-04-15 11:13 78336 —-a-w c:\windows\system32\ieencode.dll
2009-03-03 04:37 . 2009-04-15 11:13 98304 —-a-w c:\windows\system32\iasrecst.dll
2009-03-03 04:37 . 2009-04-15 11:13 54784 —-a-w c:\windows\system32\iasads.dll
2009-03-03 04:37 . 2009-04-15 11:13 44032 —-a-w c:\windows\system32\iasdatastore.dll
2009-03-03 03:04 . 2009-04-15 11:13 666624 —-a-w c:\windows\system32\printfilterpipelinesvc.exe
2009-03-03 02:38 . 2009-04-15 11:13 17408 —-a-w c:\windows\system32\iashost.exe
2009-03-03 02:28 . 2009-04-15 11:13 26624 —-a-w c:\windows\system32\ieUnatt.exe
2009-02-13 08:49 . 2009-04-15 11:13 72704 —-a-w c:\windows\system32\secur32.dll
2009-02-13 08:49 . 2009-04-15 11:13 1255936 —-a-w c:\windows\system32\lsasrv.dll
2009-02-09 03:10 . 2009-03-11 10:58 2033152 —-a-w c:\windows\system32\win32k.sys
2008-01-21 02:43 . 2006-11-02 12:50 174 –sha-w c:\program files\desktop.ini
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\Sidebar.exe" [2008-01-21 1233920]
"RunSpySweeperScheduleAtStartup"="c:\windows\system32\msfeedssync.exe" [2008-01-21 12800]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-21 125952]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2008-01-21 202240]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2008-01-03 141848]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2008-01-03 166424]
"Persistence"="c:\windows\system32\igfxpers.exe" [2008-01-03 133656]
"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2006-10-03 81920]
"dscactivate"="c:\program files\Dell Support Center\gs_agent\custom\dsca.exe" [2007-11-15 16384]
"ISUSPM Startup"="c:\progra~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe" [2006-10-03 221184]
"UfSeAgnt.exe"="c:\program files\Trend Micro\Internet Security\UfSeAgnt.exe" [2008-07-29 1398024]
"TuneClone"="c:\program files\TuneClone\TuneClone.exe" [2008-07-15 4345856]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2008-09-06 413696]
"AppleSyncNotifier"="c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe" [2008-10-01 111936]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2008-10-01 289576]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2007-10-15 49152]
"hpqSRMon"="c:\program files\HP\Digital Imaging\bin\hpqSRMon.exe" [2008-06-02 80896]
"SpySweeper"="c:\program files\Webroot\Spy Sweeper\SpySweeperUI.exe" [2008-01-05 5367664]
"RtHDVCpl"="RtHDVCpl.exe" - c:\windows\RtHDVCpl.exe [2007-05-11 4452352]

c:\users\Owner\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
OpenOffice.org 2.4.lnk - c:\program files\OpenOffice.org 2.4\program\quickstart.exe [2008-1-21 393216]

c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Digital Line Detect.lnk - c:\program files\Digital Line Detect\DLG.exe [2008-3-12 50688]
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2007-10-14 214360]

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AutoUpdateDisableNotify"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"TCP Query User{32A81ECE-CE17-4B3F-A784-7E41851B69C4}c:\\users\\owner\\appdata\\local\\temp\\wzse0.tmp\\symnrt.exe"= UDP:c:\users\owner\appdata\local\temp\wzse0.tmp\symnrt.exe:symnrt.exe
"UDP Query User{84B473A6-4C8D-4184-9ADD-DA45319AA824}c:\\users\\owner\\appdata\\local\\temp\\wzse0.tmp\\symnrt.exe"= TCP:c:\users\owner\appdata\local\temp\wzse0.tmp\symnrt.exe:symnrt.exe
"{BD0B40B5-A34F-4392-BFDA-909802FE68D4}"= UDP:c:\program files\Bonjour\mDNSResponder.exe:Bonjour
"{E54FB90A-24F3-46DB-B4C3-227BCE89D520}"= TCP:c:\program files\Bonjour\mDNSResponder.exe:Bonjour
"{6A1A5DC7-A7AC-4D51-A148-C356C3D72514}"= UDP:c:\program files\iTunes\iTunes.exe:iTunes
"{44FDB336-2C4F-4E86-8932-FEDEAFDE9C1B}"= TCP:c:\program files\iTunes\iTunes.exe:iTunes
"TCP Query User{2B4510A3-E541-4DD0-943B-662AD82B54FF}c:\\program files\\packet tracer 5.0\\bin\\packettracer5.exe"= UDP:c:\program files\packet tracer 5.0\bin\packettracer5.exe:PacketTracer5
"UDP Query User{84866F57-82EE-4F5F-9AE2-2E3BC050627E}c:\\program files\\packet tracer 5.0\\bin\\packettracer5.exe"= TCP:c:\program files\packet tracer 5.0\bin\packettracer5.exe:PacketTracer5
"{66DB85D3-AD30-46D6-8F9C-30C513F27C5E}"= Disabled:UDP:c:\program files\HP\Digital Imaging\bin\hpqtra08.exe:hpqtra08.exe
"{C1CFB880-1D8E-45F4-A391-33FF260FFB39}"= Disabled:TCP:c:\program files\HP\Digital Imaging\bin\hpqtra08.exe:hpqtra08.exe
"{22B9EA44-D0ED-43A4-8417-287E270497CB}"= Disabled:UDP:c:\program files\HP\Digital Imaging\bin\hpqste08.exe:hpqste08.exe
"{8CC502C3-3FB8-43C1-9302-04E0B7817EF9}"= Disabled:TCP:c:\program files\HP\Digital Imaging\bin\hpqste08.exe:hpqste08.exe
"{95E6C420-6CD4-4115-A24F-A73D483DB209}"= Disabled:UDP:c:\program files\HP\Digital Imaging\bin\hpofxm08.exe:hpofxm08.exe
"{9A5A84E3-0182-483C-98F7-BDEA0120F4AF}"= Disabled:TCP:c:\program files\HP\Digital Imaging\bin\hpofxm08.exe:hpofxm08.exe
"{FCB057BF-A62F-4097-9394-8C735A366CEB}"= Disabled:UDP:c:\program files\HP\Digital Imaging\bin\hposfx08.exe:hposfx08.exe
"{EE4D403B-3AC9-465D-A2E4-69363827B2DB}"= Disabled:TCP:c:\program files\HP\Digital Imaging\bin\hposfx08.exe:hposfx08.exe
"{EE0FA95B-6519-4123-81FD-723EC2A92DA2}"= Disabled:UDP:c:\program files\HP\Digital Imaging\bin\hposid01.exe:hposid01.exe
"{14D12DE4-0F77-4EAB-8CD9-C841AC7F8928}"= Disabled:TCP:c:\program files\HP\Digital Imaging\bin\hposid01.exe:hposid01.exe
"{125B3DE0-E9A0-47F0-B571-C82CE178B0C0}"= Disabled:UDP:c:\program files\HP\Digital Imaging\bin\hpzwiz01.exe:hpzwiz01.exe
"{A14CAF5B-D29D-43AA-8D99-0588CE970A57}"= Disabled:TCP:c:\program files\HP\Digital Imaging\bin\hpzwiz01.exe:hpzwiz01.exe
"{64D19211-22A8-4974-B8F3-69A9A25D356B}"= Disabled:UDP:c:\program files\HP\Digital Imaging\bin\hpoews01.exe:hpoews01.exe
"{E9EE95ED-4F7A-404B-8939-A91B0D88A679}"= Disabled:TCP:c:\program files\HP\Digital Imaging\bin\hpoews01.exe:hpoews01.exe
"{BE43B76A-1E3D-451A-8C73-6D71031A58E5}"= Disabled:UDP:c:\program files\HP\Digital Imaging\bin\hpiscnapp.exe:hpiscnapp.exe
"{DABF3B80-3A22-46F7-A5D2-D5313A1D8AFF}"= Disabled:TCP:c:\program files\HP\Digital Imaging\bin\hpiscnapp.exe:hpiscnapp.exe
"{5DFD6D49-1343-4BD9-9E2E-56759B8B5D10}"= Disabled:UDP:c:\program files\HP\Digital Imaging\bin\hpqkygrp.exe:hpqkygrp.exe
"{D143E1D7-C5CC-417A-8B39-774A6B37D869}"= Disabled:TCP:c:\program files\HP\Digital Imaging\bin\hpqkygrp.exe:hpqkygrp.exe
"{6AA90D4A-0BA4-4078-BBA4-657C8B42D8F5}"= UDP:c:\program files\Yahoo!\Messenger\YahooMessenger.exe:Yahoo! Messenger
"{593051C4-2D0D-4E45-AEDE-7EB90CDF37C9}"= TCP:c:\program files\Yahoo!\Messenger\YahooMessenger.exe:Yahoo! Messenger
"{D74CDA3D-CFCA-4686-8AE9-FA45338A2F0F}"= UDP:c:\program files\Yahoo!\Messenger\YahooMessenger.exe:Yahoo! Messenger
"{9EDBF15F-CACC-40E5-A0FA-ED72876ED4D3}"= TCP:c:\program files\Yahoo!\Messenger\YahooMessenger.exe:Yahoo! Messenger

R2 tmevtmgr;tmevtmgr;c:\windows\system32\DRIVERS\tmevtmgr.sys [2009-04-02 52624]
R3 DrmCDriverV32;DrmCDriverV32;c:\windows\system32\drivers\DrmCDriverV32.sys [2008-06-04 23096]
R3 DrmCVideo32;DrmCVideo32;c:\windows\system32\DRIVERS\DrmCVideo32.sys [2008-06-04 3768]
R3 tmproxy;Trend Micro Proxy Service;c:\program files\Trend Micro\Internet Security\TmProxy.exe [2008-02-26 648456]
S0 tclondrv;tclondrv;c:\windows\system32\DRIVERS\tclondrv.sys [2008-05-12 20352]
S2 IntuitUpdateService;Intuit Update Service;c:\program files\Common Files\Intuit\Update Service\IntuitUpdateService.exe [2008-10-10 13088]
S2 LinksysUpdater;Linksys Updater;c:\program files\Linksys\Linksys Updater\bin\LinksysUpdater.exe [2008-01-15 204800]
S2 tmpreflt;tmpreflt;c:\windows\system32\DRIVERS\tmpreflt.sys [2008-11-26 36368]


[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{2da635ff-eca1-11dd-a4a8-001d098d59ab}]
\shell\AutoRun\command - G:\mri.exe
.
Contents of the 'Scheduled Tasks' folder

2009-04-27 c:\windows\Tasks\User_Feed_Synchronization-{27F294F5-2659-4FFE-A5C1-A02D8A2CB28D}.job
- c:\windows\system32\msfeedssync.exe [2008-01-21 02:24]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.msnbc.com
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-04-27 20:23
Windows 6.0.6001 Service Pack 1 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …


c:\users\Owner\AppData\Local\Temp\catchme.dll 53248 bytes executable

scan completed successfully
hidden files: 1

**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————

[HKEY_USERS\SOFTWARE\Classes\CLSID\{0BE09CC1-42E0-11DD-AE16-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil10b.exe,-101"

[HKEY_USERS\SOFTWARE\Classes\CLSID\{0BE09CC1-42E0-11DD-AE16-0800200C9A66}\Elevation]
"Enabled"=dword:00000001

[HKEY_USERS\SOFTWARE\Classes\CLSID\{0BE09CC1-42E0-11DD-AE16-0800200C9A66}\LocalServer32]
@="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil10b.exe"

[HKEY_USERS\SOFTWARE\Classes\CLSID\{0BE09CC1-42E0-11DD-AE16-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"

[HKEY_USERS\SOFTWARE\Classes\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"

[HKEY_USERS\SOFTWARE\Classes\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\system32\\Macromed\\Flash\\Flash10b.ocx"
"ThreadingModel"="Apartment"

[HKEY_USERS\SOFTWARE\Classes\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"

[HKEY_USERS\SOFTWARE\Classes\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.10"

[HKEY_USERS\SOFTWARE\Classes\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\system32\\Macromed\\Flash\\Flash10b.ocx, 1"

[HKEY_USERS\SOFTWARE\Classes\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"

[HKEY_USERS\SOFTWARE\Classes\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"

[HKEY_USERS\SOFTWARE\Classes\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"

[HKEY_USERS\SOFTWARE\Classes\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"

[HKEY_USERS\SOFTWARE\Classes\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\system32\\Macromed\\Flash\\Flash10b.ocx"
"ThreadingModel"="Apartment"

[HKEY_USERS\SOFTWARE\Classes\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"

[HKEY_USERS\SOFTWARE\Classes\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\system32\\Macromed\\Flash\\Flash10b.ocx, 1"

[HKEY_USERS\SOFTWARE\Classes\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"

[HKEY_USERS\SOFTWARE\Classes\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"

[HKEY_USERS\SOFTWARE\Classes\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"

[HKEY_USERS\SOFTWARE\Classes\Interface\{DDF4CE26-4BDA-42BC-B0F0-0E75243AD285}]
@Denied: (A 2) (Everyone)
@="IFlashBroker2"

[HKEY_USERS\SOFTWARE\Classes\Interface\{DDF4CE26-4BDA-42BC-B0F0-0E75243AD285}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"

[HKEY_USERS\SOFTWARE\Classes\Interface\{DDF4CE26-4BDA-42BC-B0F0-0E75243AD285}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"

[HKEY_USERS\SOFTWARE\Classes\TypeLib\{D27CDB6B-AE6D-11CF-96B8-444553540000}]
@Denied: (A 2) (Everyone)

[HKEY_USERS\SOFTWARE\Classes\TypeLib\{D27CDB6B-AE6D-11CF-96B8-444553540000}\1.0]
@="Shockwave Flash"

[HKEY_USERS\SOFTWARE\Classes\TypeLib\{FAB3E735-69C7-453B-A446-B6823C6DF1C9}]
@Denied: (A 2) (Everyone)
@=""

[HKEY_USERS\SOFTWARE\Classes\TypeLib\{FAB3E735-69C7-453B-A446-B6823C6DF1C9}\1.0]
@="FlashBroker"

[HKEY_USERS\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000

[HKEY_USERS\SYSTEM\ControlSet003\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
Completion time: 2009-04-28 20:24
ComboFix-quarantined-files.txt 2009-04-28 00:24

Pre-Run: 223,232,765,952 bytes free
Post-Run: 223,206,080,512 bytes free

243 — E O F — 2009-04-27 11:54
Hi,

Not sure from the reply if rebooting restored your IE connection if you could advise.

Please do the following:

Please download the GMER Rootkit Scanner. Unzip it to your Desktop.
Before scanning, make sure all other running programs are closed and no other actions like a scheduled antivirus scan will occur while the scan is being performed. Do not use your computer for anything else during the scan.
Double-click gmer.exe. The program will begin to run.
**Caution**
These types of scans can produce false positives. Do NOT take any action on any
"<— ROOKIT" entries unless advised!
If possible rootkit activity is found, you will be asked if you would like to perform a full scan.
  • Click NO
  • In the right panel, you will see a number of boxes that have been checked … leave everything checked and ensure the Show all box is un-checked.
  • Now click the Scan button.
    Once the scan is complete, you may receive another notice about rootkit activity.
  • Click OK.
  • GMER will produce a log. Click on the [Save..] button, and in the File name area, type in "GMER.txt"
  • Save it where you can easily find it, such as your desktop.

  • Post the contents of GMER.txt in your next reply.
quick question before I do this, do I need to disable Trend Micro Antivirus and Spysweeper before running the program? Thank you
okay, don't think it's working properly. I unzipped the file to my desktop. I turned off TMA and Spy sweeper. I ran the program and during the scan I got this message: GMER.EXE has stopped working a problem caused the program to stop working correctly windows will close the program and notify you if a solution is available. After the first time I closed this error message, my PC went into a blue screen with a Windows Message saying a program has casued Windows to close if this is your first time getting this message restart your computer, if it continues contact you admin. the 2nd and 3rd time I ran the program I just rebooted my PC before letting it get to Blue screen again. is my system really fried?!?!? :(
Hi Can you tap the F8 key before it boots up to get into safe mode… If you can - select 'last known good configuration" or see if you can access safe mode and try a system restore to an earlier time. Do you have a boot CD Unfortunately I have no way of knowing the status of your system prior to your post as you had been using programs on your own, this could be a hardware failure also. Please advise
I tried running that scan again this morning and it always stops GMER when it start to scan \Device\HarddiskVolume ShadowCopy1 not sure if that helps at all. If not I will try to reboot to an early known good working configuration. Please advise
Appears that there might be a problem with your hard drive. boot into the last known good configuration and refrain from any further scans until I can find out more from our tech experts as to what might be happening.
Hi Catbyte, I think i'm going to take my PC back to where I bought it and have them look at it. It's still under warenty, so they should be able to solve the problem. I haven't had the Mal Hifrm virus come back up though. So maybe through all the scans and fixs it might have removed it. I want to thank you for your time in helping me. If I get any other virus' I'll be sure to come back and get some help. Thank you!!! :)
I do think it is a hardware issue as I have run that tool on my own system too many times to mention while training with it and it has never caused a problem, so I don't believe any of the tools we have run have caused the issues you are experiencing now. Good luck CB
Since this issue appears to be resolved … this Topic has been closed. Glad we could be of assistance. If you're the topic starter, and need this topic reopened, please contact a staff member with the address of the thread. Everyone else please begin a New Topic.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI