This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Closed] Internet Explorer problems?

11 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I am recieving a message "internet explorer has encountered a problem and needs to close message" It is not finding sites that I know are good, and have visited in the past. And, it will not allow me to go to certain sites?? I am wondering if I have some kind of bug, and hijack problem?? Will you please look at my Hijack this log, thanks!!!

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 8:34:16 AM, on 5/2/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\iS3\Anti-Spyware\SZServer.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Ahead\InCD\InCDsrv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\eMachines Bay Reader\shwiconem.exe
C:\PROGRA~1\AVG\AVG8\avgtray.exe
C:\Program Files\YourWare Solutions\FreeRAM XP Pro\FreeRAM XP Pro.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\System32\nvsvc32.exe
c:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\PROGRA~1\AVG\AVG8\avgnsx.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.emachines.com/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: SITEguard BHO - {1827766B-9F49-4854-8034-F6EE26FCB1EC} - C:\Program Files\STOPzilla!\SZSG.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: STOPzilla Browser Helper Object - {E3215F20-3212-11D6-9F8B-00D0B743919D} - C:\Program Files\STOPzilla!\SZIEBHO.dll
O3 - Toolbar: STOPzilla - {98828DED-A591-462F-83BA-D2F62A68B8B8} - C:\Program Files\STOPzilla!\SZSG.dll
O3 - Toolbar: (no name) - {381FFDE8-2394-4f90-B10D-FC6124A40F8C} - (no file)
O4 - HKLM\..\Run: [nwiz] "nwiz.exe" /install
O4 - HKLM\..\Run: [SunKistEM] "C:\Program Files\eMachines Bay Reader\shwiconem.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKLM\..\RunOnce: [PrivacyGuardianIndex] C:\Program Files\Privacy Guardian\PgIndex.exe
O4 - HKCU\..\Run: [FreeRAM XP] "C:\Program Files\YourWare Solutions\FreeRAM XP Pro\FreeRAM XP Pro.exe" -win
O4 - HKCU\..\RunOnce: [PGhist] C:\Program Files\Privacy Guardian\PgHist.exe WinguidesPG
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\program files\common files\is3\anti-spyware\is3lsp.dll
O10 - Unknown file in Winsock LSP: c:\program files\common files\is3\anti-spyware\is3lsp.dll
O10 - Unknown file in Winsock LSP: c:\program files\common files\is3\anti-spyware\is3lsp.dll
O10 - Unknown file in Winsock LSP: c:\program files\common files\is3\anti-spyware\is3lsp.dll
O10 - Unknown file in Winsock LSP: c:\program files\common files\is3\anti-spyware\is3lsp.dll
O10 - Unknown file in Winsock LSP: c:\program files\common files\is3\anti-spyware\is3lsp.dll
O14 - IERESET.INF: START_PAGE_URL=http://www.emachines.com
O15 - Trusted Zone: http://cgi5.ebay.com
O16 - DPF: {1239CC52-59EF-4DFA-8C61-90FFA846DF7E} (Musicnotes Viewer) - http://www.musicnotes.com/download/mnviewer.cab
O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} (MySpace Uploader Control) - http://lads.myspace.com/upload/MySpaceUploader1006.cab
O16 - DPF: {56762DEC-6B0D-4AB4-A8AD-989993B5D08B} - http://www.eset.eu/OnlineScanner.cab
O16 - DPF: {5F8469B4-B055-49DD-83F7-62B522420ECC} (Facebook Photo Uploader Control) - http://upload.facebook.com/controls/Facebo…otoUploader.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftu…b?1179876639609
O16 - DPF: {9D190AE6-C81E-4039-8061-978EBAD10073} (F-Secure Online Scanner 3.0) - http://portal.gci.net/static/scanner/fscax.cab
O16 - DPF: {A8F2B9BD-A6A0-486A-9744-18920D898429} (ScorchPlugin Class) - http://www.sibelius.com/download/software/…tiveXPlugin.cab
O16 - DPF: {B1E2B96C-12FE-45E2-BEF1-44A219113CDD} (SABScanProcesses Class) - http://www.superadblocker.com/activex/sabspx.cab
O16 - DPF: {C1FDEE68-98D5-4F42-A4DD-D0BECF5077EB} (EPUImageControl Class) - http://tools.ebayimg.com/eps/wl/activex/eB…l_v1-0-27-0.cab
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: InCD Helper (InCDsrv) - AHEAD Software - C:\Program Files\Ahead\InCD\InCDsrv.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: Protexis Licensing V2 (PSI_SVC_2) - Protexis Inc. - c:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe
O23 - Service: STOPzilla Service (szserver) - iS3, Inc. - C:\Program Files\Common Files\iS3\Anti-Spyware\SZServer.exe
Hi Otis99,

:welcome:

My name is Tomk. I would be glad to take a look at your log and help you with solving any malware problems. HijackThis logs can take a while to research, so please be patient and I'd be grateful if you would note the following:

  • I will be working on your Malware issues, this may or may not, solve other issues you have with your machine.
  • The fixes are specific to your problem and should only be used for the issues on this machine.
  • Please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear.
  • It's often worth reading through these instructions and printing them for ease of reference.
  • If you don't know or understand something, please don't hesitate to say or ask!! It's better to be sure and safe than sorry.
  • Please reply to this thread. Do not start a new topic.

  • Please open HijackThis and run Do a system scan only
  • Check the boxes next to ONLY the entries listed below(if present):
    • R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
      R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
      O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
      O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
      O3 - Toolbar: (no name) - {381FFDE8-2394-4f90-B10D-FC6124A40F8C} - (no file)
      O4 - HKLM\..\Run: [nwiz] "nwiz.exe" /install
      O15 - Trusted Zone: http://cgi5.ebay.com
  • Close all programs except for HijackThis.
  • Click on Fix checked
  • A box will pop up asking you if you wish to fix the selected items. Please choose YES.
  • Once it has fixed them, please exit/close HijackThis.

Please download ATF Cleaner by Atribune.
Download - ATF Cleaner
Double-click ATF-Cleaner.exe to run the program.
Under Main choose: Select All
Click the Empty Selected button.

(If you use FireFox or the Opera browser
To keep saved passwords, click No at the prompt.)

It's normal after running ATF cleaner that the PC will be slower to boot the first time or two.

Then

Please download Malwarebytes' Anti-Malware to your desktop.

  • Double-click mbam-setup.exe and follow the prompts to install the program.
  • At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select Perform quick scan, then click Scan.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Be sure that everything is checked, and click Remove Selected.
  • When completed, a log will open in Notepad. Please save it to a convenient location and post the results.
  • Note: If you receive a notice that some of the items couldn't be removed, that they have been added to the delete on reboot list, please reboot (shut down your computer then restart it).
Also "copy/paste" a new HijackThis log file into this thread.

Also please describe how your computer behaves at the moment.
Hello, here is the Malware scan results:
Malwarebytes' Anti-Malware 1.36
Database version: 2090
Windows 5.1.2600 Service Pack 3

5/7/2009 2:57:26 PM
mbam-log-2009-05-07 (14-57-26).txt

Scan type: Quick Scan
Objects scanned: 77909
Time elapsed: 4 minute(s), 48 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 3
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{9034a523-d068-4be8-a284-9df278be776e} (Trojan.Zlob) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{3ba4271e-5c1e-48e2-b432-d8bf420dd31d} (Rogue.DeusCleaner) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{6fd31ed6-7c94-4bbc-8e95-f927f4d3a949} (Adware.180Solutions) -> Quarantined and deleted successfully.

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)

Here is the new Hijack this log:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 3:00:13 PM, on 5/7/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16827)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\iS3\Anti-Spyware\SZServer.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Ahead\InCD\InCDsrv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\eMachines Bay Reader\shwiconem.exe
C:\PROGRA~1\AVG\AVG8\avgtray.exe
C:\Program Files\YourWare Solutions\FreeRAM XP Pro\FreeRAM XP Pro.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\System32\nvsvc32.exe
c:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\PROGRA~1\AVG\AVG8\avgnsx.exe
C:\Program Files\STOPzilla!\STOPzilla.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\MSN Messenger\usnsvc.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.emachines.com/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: SITEguard BHO - {1827766B-9F49-4854-8034-F6EE26FCB1EC} - C:\Program Files\STOPzilla!\SZSG.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O2 - BHO: STOPzilla Browser Helper Object - {E3215F20-3212-11D6-9F8B-00D0B743919D} - C:\Program Files\STOPzilla!\SZIEBHO.dll
O3 - Toolbar: STOPzilla - {98828DED-A591-462F-83BA-D2F62A68B8B8} - C:\Program Files\STOPzilla!\SZSG.dll
O4 - HKLM\..\Run: [SunKistEM] "C:\Program Files\eMachines Bay Reader\shwiconem.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKLM\..\RunOnce: [Malwarebytes' Anti-Malware] C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe /install /silent
O4 - HKCU\..\Run: [FreeRAM XP] "C:\Program Files\YourWare Solutions\FreeRAM XP Pro\FreeRAM XP Pro.exe" -win
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\program files\common files\is3\anti-spyware\is3lsp.dll
O10 - Unknown file in Winsock LSP: c:\program files\common files\is3\anti-spyware\is3lsp.dll
O10 - Unknown file in Winsock LSP: c:\program files\common files\is3\anti-spyware\is3lsp.dll
O10 - Unknown file in Winsock LSP: c:\program files\common files\is3\anti-spyware\is3lsp.dll
O10 - Unknown file in Winsock LSP: c:\program files\common files\is3\anti-spyware\is3lsp.dll
O10 - Unknown file in Winsock LSP: c:\program files\common files\is3\anti-spyware\is3lsp.dll
O14 - IERESET.INF: START_PAGE_URL=http://www.emachines.com
O16 - DPF: {1239CC52-59EF-4DFA-8C61-90FFA846DF7E} (Musicnotes Viewer) - http://www.musicnotes.com/download/mnviewer.cab
O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} (MySpace Uploader Control) - http://lads.myspace.com/upload/MySpaceUploader1006.cab
O16 - DPF: {56762DEC-6B0D-4AB4-A8AD-989993B5D08B} - http://www.eset.eu/OnlineScanner.cab
O16 - DPF: {5F8469B4-B055-49DD-83F7-62B522420ECC} (Facebook Photo Uploader Control) - http://upload.facebook.com/controls/Facebo…otoUploader.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftu…b?1179876639609
O16 - DPF: {9D190AE6-C81E-4039-8061-978EBAD10073} (F-Secure Online Scanner 3.0) - http://portal.gci.net/static/scanner/fscax.cab
O16 - DPF: {A8F2B9BD-A6A0-486A-9744-18920D898429} (ScorchPlugin Class) - http://www.sibelius.com/download/software/…tiveXPlugin.cab
O16 - DPF: {B1E2B96C-12FE-45E2-BEF1-44A219113CDD} (SABScanProcesses Class) - http://www.superadblocker.com/activex/sabspx.cab
O16 - DPF: {C1FDEE68-98D5-4F42-A4DD-D0BECF5077EB} (EPUImageControl Class) - http://tools.ebayimg.com/eps/wl/activex/eB…l_v1-0-27-0.cab
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: InCD Helper (InCDsrv) - AHEAD Software - C:\Program Files\Ahead\InCD\InCDsrv.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: Protexis Licensing V2 (PSI_SVC_2) - Protexis Inc. - c:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe
O23 - Service: STOPzilla Service (szserver) - iS3, Inc. - C:\Program Files\Common Files\iS3\Anti-Spyware\SZServer.exe

My computer seems to be working better. After I posted my message, I uninstalled Internet Explorer 8, and went back to version 7, and I have not gotten the IE error box since. I tried this before and it did not work, so I reinstalled IE 8, and it kept doing it. So maybe by uninstalling it a 2nd time, it took care of the problem?? But, I still would like help removing all unnecessary items(stuff) on my computer, thanks!!
Otis99,

You had some remnants of a couple pretty nasty infections. They may have been the cause of the IE problems.

Your Java is out of date. Older versions have vulnerabilities that malicious sites can use to exploit and infect your system. Please follow these steps to remove older version Java components and update:
  • Download the latest version of Java Runtime Environment (JRE) Version 6 and save it to your desktop.
  • Scroll down to where it says "JRE 6 Update 13.
  • Click the "Download" button to the right.
  • Select your Platform: "Windows".
  • Select your Language: "Multi-language".
  • Read the License Agreement, and then check the box that says: "Accept License Agreement".
  • Click Continue and the page will refresh.
  • Click on the link to download Windows Offline Installation and save the file to your desktop.
  • Close any programs you may have running - especially your web browser.
  • Go to Start > Settings > Control Panel, double-click on Add/Remove Programs and remove all older versions of Java.
  • Check (highlight) any item with Java Runtime Environment (JRE or J2SE) in the name.
  • Click the Remove or Change/Remove button and follow the onscreen instructions for the Java uninstaller.
  • Repeat as many times as necessary to remove each Java versions.
  • Reboot your computer once all Java components are removed.
  • Then from your desktop double-click on jre-6u13-windows-i586-p.exe to install the newest version.
Now to Clean out the Java cache:

Go into the Control Panel and double-click the Java Icon. [external image: Posted Image]
  • Under Temporary Internet Files, click the Settings… button
  • click the Delete Files button.
  • There are two options in the window to clear the cache - Leave both Checked
    • Applications and Applets
      Trace and Log Files
  • Click OK on Delete Temporary Files Window
    Note: This deletes ALL the Downloaded Applications and Applets from the CACHE.
  • Click OK to leave the Temporary Files Settings
  • Click OK to leave the Java Control Panel.


Please go to Kaspersky website and perform an online antivirus scan.

  • Read through the requirements and privacy statement and click on Accept button.
  • It will start downloading and installing the scanner and virus definitions. You will be prompted to install an application from Kaspersky. Click Run.
  • When the downloads have finished, click on Settings.
  • Make sure these boxes are checked (ticked). If they are not, please tick them and click on the Save button:
    • Spyware, Adware, Dialers, and other potentially dangerous programs
      Archives
      Mail databases
  • Click on My Computer under Scan.
  • Once the scan is complete, it will display the results. Click on View Scan Report.
  • You will see a list of infected items there. Click on Save Report As….
  • Save this report to a convenient place. Change the Files of type to Text file (.txt) before clicking on the Save button.
  • Please post this log in your next reply.
I deleted the old Java, installed the new. I did the Kaspersky online scan and it did not find any malware. So, whats next?? My computer will still not let me go to robertkeeley.com, which is a good website. I get the 404 webpage not found. Even doing a search through Yahoo, or Google, I still get the same thing. It's irritating, because I know the website is there. I am able to go to some of the other websites I could not get to before using IE 8???
Otis99,

Let's get a deeper look at what's going on.

  • Download OTListIt2 to your desktop.
  • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • Check the boxes beside LOP Check and Purity Check.
  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
  • When the scan completes, it will open two notepad windows. OTListIt.Txt and Extras.Txt. These are saved in the same location as OTListIt2.
  • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post it with your next reply. You may need two posts to fit them all in.
OTListIt logfile created on: 5/10/2009 8:52:21 AM - Run 1
OTListIt2 by OldTimer - Version 2.0.15.6 Folder = C:\Documents and Settings\curt summers\Desktop
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.13)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

959.48 Mb Total Physical Memory | 569.25 Mb Available Physical Memory | 59.33% Memory free
1.74 Gb Paging File | 1.40 Gb Available in Paging File | 80.66% Paging File free
Paging file location(s): C:\pagefile.sys 900 1344 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 149.05 Gb Total Space | 3.23 Gb Free Space | 2.17% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: OWNER-84J1T8A8N
Current User Name: curt summers
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Output = Standard
File Age = 30 Days
Company Name Whitelist: On

========== Processes (SafeList) ==========

PRC - [2008/02/01 15:39:26 | 00,057,344 | R— | M] (iS3, Inc.) – C:\Program Files\Common Files\iS3\Anti-Spyware\SZServer.exe
PRC - [2003/12/17 23:39:40 | 00,802,868 | —- | M] (AHEAD Software) – C:\Program Files\Ahead\InCD\InCDsrv.exe
PRC - [2008/04/13 16:12:19 | 01,033,728 | —- | M] (Microsoft Corporation) – C:\WINDOWS\Explorer.EXE
PRC - [2008/09/05 22:26:28 | 00,116,040 | —- | M] (Apple Inc.) – C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
PRC - [2009/05/01 16:46:38 | 00,298,776 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Program Files\AVG\AVG8\avgwdsvc.exe
PRC - [2008/08/29 10:18:44 | 00,238,888 | —- | M] (Apple Inc.) – C:\Program Files\Bonjour\mDNSResponder.exe
PRC - [2004/03/04 06:29:00 | 00,077,824 | —- | M] (NVIDIA Corporation) – C:\WINDOWS\System32\nvsvc32.exe
PRC - [2007/07/24 11:15:14 | 00,185,632 | —- | M] (Protexis Inc.) – c:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe
PRC - [2009/05/01 16:46:56 | 00,486,168 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Program Files\AVG\AVG8\avgrsx.exe
PRC - [2009/05/01 16:46:44 | 00,594,712 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Program Files\AVG\AVG8\avgnsx.exe
PRC - [2004/03/12 11:18:54 | 00,135,168 | —- | M] (Alcor Micro, Corp.) – C:\Program Files\eMachines Bay Reader\shwiconem.exe
PRC - [2007/08/31 12:04:56 | 01,591,808 | —- | M] (YourWare Solutions ™) – C:\Program Files\YourWare Solutions\FreeRAM XP Pro\FreeRAM XP Pro.exe
PRC - [2009/05/09 08:13:23 | 00,152,984 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files\Java\jre6\bin\jqs.exe
PRC - [2007/01/19 12:54:14 | 00,097,136 | —- | M] (Microsoft Corporation) – C:\Program Files\MSN Messenger\usnsvc.exe
PRC - [2009/05/01 16:46:48 | 01,947,928 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Program Files\AVG\AVG8\avgtray.exe
PRC - [2009/05/10 08:29:52 | 00,501,248 | —- | M] (OldTimer Tools) – C:\Documents and Settings\curt summers\Desktop\OTListIt2.exe

========== Win32 Services (SafeList) ==========

SRV - [2008/09/05 22:26:28 | 00,116,040 | —- | M] (Apple Inc.) – C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe – (Apple Mobile Device [Auto | Running])
SRV - [2008/07/25 11:16:40 | 00,034,312 | —- | M] (Microsoft Corporation) – C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe – (aspnet_state [On_Demand | Stopped])
SRV - [2009/05/01 16:46:38 | 00,298,776 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Program Files\AVG\AVG8\avgwdsvc.exe – (avg8wd [Auto | Running])
SRV - [2008/08/29 10:18:44 | 00,238,888 | —- | M] (Apple Inc.) – C:\Program Files\Bonjour\mDNSResponder.exe – (Bonjour Service [Auto | Running])
SRV - [2008/07/25 11:17:02 | 00,069,632 | —- | M] (Microsoft Corporation) – c:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe – (clr_optimization_v2.0.50727_32 [On_Demand | Stopped])
SRV - [2008/07/29 21:10:04 | 00,046,104 | —- | M] (Microsoft Corporation) – c:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe – (FontCache3.0.0.0 [On_Demand | Stopped])
SRV - [2008/04/13 16:12:02 | 00,038,400 | —- | M] (Microsoft Corporation) – C:\WINDOWS\PCHealth\HelpCtr\Binaries\pchsvc.dll – (helpsvc [On_Demand | Stopped])
SRV - [2004/10/22 03:24:18 | 00,073,728 | —- | M] (Macrovision Corporation) – C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe – (IDriverT [On_Demand | Stopped])
SRV - [2008/07/29 19:24:50 | 00,881,664 | —- | M] (Microsoft Corporation) – c:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe – (idsvc [Unknown | Stopped])
SRV - [2003/12/17 23:39:40 | 00,802,868 | —- | M] (AHEAD Software) – C:\Program Files\Ahead\InCD\InCDsrv.exe – (InCDsrv [Auto | Running])
SRV - [2008/09/08 23:02:00 | 00,536,872 | —- | M] (Apple Inc.) – C:\Program Files\iPod\bin\iPodService.exe – (iPod Service [On_Demand | Stopped])
SRV - [2008/07/29 19:16:38 | 00,132,096 | —- | M] (Microsoft Corporation) – c:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe – (NetTcpPortSharing [Disabled | Stopped])
SRV - [2004/03/04 06:29:00 | 00,077,824 | —- | M] (NVIDIA Corporation) – C:\WINDOWS\System32\nvsvc32.exe – (NVSvc [Auto | Running])
SRV - [2007/07/24 11:15:14 | 00,185,632 | —- | M] (Protexis Inc.) – c:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe – (PSI_SVC_2 [Auto | Running])
SRV - [2008/02/01 15:39:26 | 00,057,344 | R— | M] (iS3, Inc.) – C:\Program Files\Common Files\iS3\Anti-Spyware\SZServer.exe – (szserver [Auto | Running])
SRV - [2007/01/19 12:54:14 | 00,097,136 | —- | M] (Microsoft Corporation) – C:\Program Files\MSN Messenger\usnsvc.exe – (usnjsvc [On_Demand | Running])
SRV - [2006/10/18 21:05:24 | 00,913,408 | —- | M] (Microsoft Corporation) – C:\Program Files\Windows Media Player\WMPNetwk.exe – (WMPNetworkSvc [On_Demand | Stopped])
SRV - [2009/05/09 08:13:23 | 00,152,984 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files\Java\jre6\bin\jqs.exe – (JavaQuickStarterService [Auto | Running])

========== Driver Services (SafeList) ==========

DRV - [2008/04/13 10:46:20 | 00,048,128 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\DRIVERS\61883.sys – (61883 [On_Demand | Stopped])
DRV - [2003/03/31 04:00:00 | 00,005,248 | —- | M] (Acer Laboratories Inc.) – C:\WINDOWS\System32\DRIVERS\aliide.sys – (AliIde [Boot | Stopped])
DRV - [2008/04/13 10:36:39 | 00,043,008 | —- | M] (Advanced Micro Devices, Inc.) – C:\WINDOWS\System32\DRIVERS\amdagp.sys – (amdagp [Boot | Stopped])
DRV - [2003/03/31 04:00:00 | 00,026,496 | —- | M] (Advanced System Products, Inc.) – C:\WINDOWS\System32\DRIVERS\asc.sys – (asc [Boot | Stopped])
DRV - [2003/03/31 04:00:00 | 00,014,848 | —- | M] (Advanced System Products, Inc.) – C:\WINDOWS\System32\DRIVERS\asc3550.sys – (asc3550 [Boot | Stopped])
DRV - [2008/04/13 10:46:20 | 00,038,912 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\DRIVERS\avc.sys – (Avc [On_Demand | Stopped])
DRV - [2009/05/01 16:46:56 | 00,325,896 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\Drivers\avgldx86.sys – (AvgLdx86 [System | Running])
DRV - [2009/05/01 16:46:56 | 00,027,784 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\Drivers\avgmfx86.sys – (AvgMfx86 [System | Running])
DRV - [2009/05/01 16:46:40 | 00,108,552 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\Drivers\avgtdix.sys – (AvgTdiX [System | Running])
DRV - [2008/04/13 10:40:58 | 00,008,192 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\drivers\changer.sys – (Changer [System | Stopped])
DRV - [2003/03/31 04:00:00 | 00,006,656 | —- | M] (CMD Technology, Inc.) – C:\WINDOWS\System32\DRIVERS\cmdide.sys – (CmdIde [Boot | Stopped])
DRV - [2003/03/31 04:00:00 | 00,179,584 | —- | M] (Mylex Corporation) – C:\WINDOWS\System32\DRIVERS\dac2w2k.sys – (dac2w2k [Boot | Stopped])
DRV - [2008/04/17 13:12:54 | 00,015,464 | —- | M] (GEAR Software Inc.) – C:\WINDOWS\System32\Drivers\GEARAspiWDM.sys – (GEARAspiWDM [On_Demand | Running])
DRV - [2009/01/06 15:22:06 | 00,530,816 | —- | M] (Line 6) – C:\WINDOWS\System32\Drivers\GPWADrv.sys – (GPWADrv [On_Demand | Stopped])
DRV - [2003/11/14 14:19:48 | 00,210,304 | —- | M] (Conexant Systems, Inc.) – C:\WINDOWS\System32\DRIVERS\HSFHWBS2.sys – (HSFHWBS2 [On_Demand | Running])
DRV - [2003/11/14 14:17:00 | 01,042,816 | —- | M] (Conexant Systems, Inc.) – C:\WINDOWS\System32\DRIVERS\HSF_DP.sys – (HSF_DP [On_Demand | Running])
DRV - [2003/12/17 23:42:46 | 00,091,712 | —- | M] (Ahead Software) – C:\WINDOWS\System32\drivers\incdfs.sys – (InCDfs [Disabled | Running])
DRV - [2003/12/17 23:43:10 | 00,028,752 | —- | M] (Ahead Software) – C:\WINDOWS\System32\DRIVERS\InCDPass.sys – (InCDPass [System | Running])
DRV - [2009/01/06 15:22:04 | 00,029,312 | —- | M] (Line 6) – C:\WINDOWS\System32\Drivers\l6dp.sys – (L6DP [On_Demand | Running])
DRV - [2008/04/13 10:40:26 | 00,034,688 | —- | M] (Toshiba Corp.) – C:\WINDOWS\System32\drivers\lbrtfdc.sys – (lbrtfdc [System | Stopped])
DRV - [2004/01/17 10:21:48 | 00,012,970 | —- | M] (Conexant) – C:\WINDOWS\System32\DRIVERS\mdmxsdk.sys – (mdmxsdk [Auto | Running])
DRV - [2003/03/31 04:00:00 | 00,017,280 | —- | M] (American Megatrends Inc.) – C:\WINDOWS\System32\DRIVERS\mraid35x.sys – (mraid35x [Boot | Stopped])
DRV - [2008/04/13 10:46:09 | 00,051,200 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\DRIVERS\msdv.sys – (MSDV [On_Demand | Stopped])
DRV - [2001/08/17 05:49:32 | 00,019,968 | —- | M] (Macronix International Co., Ltd. ) – C:\WINDOWS\System32\DRIVERS\mxnic.sys – (mxnic [On_Demand | Stopped])
DRV - [2004/03/04 06:29:00 | 01,893,536 | —- | M] (NVIDIA Corporation) – C:\WINDOWS\System32\DRIVERS\nv4_mini.sys – (nv [On_Demand | Running])
DRV - [2003/09/03 12:51:00 | 00,036,864 | —- | M] (NVIDIA Corporation) – C:\WINDOWS\system32\drivers\nvax.sys – (nvax [On_Demand | Running])
DRV - [2003/08/16 15:22:16 | 00,072,771 | —- | M] (NVIDIA Corporation) – C:\WINDOWS\System32\DRIVERS\NVENET.sys – (NVENET [On_Demand | Running])
DRV - [2003/09/03 12:51:00 | 00,312,704 | —- | M] (NVIDIA Corporation) – C:\WINDOWS\system32\drivers\nvapu.sys – (nvnforce [On_Demand | Running])
DRV - [2003/03/20 11:51:00 | 00,018,688 | —- | M] (NVIDIA Corporation) – C:\WINDOWS\System32\DRIVERS\nv_agp.sys – (nv_agp [Boot | Running])
DRV - [2003/03/31 04:00:00 | 00,017,792 | —- | M] (Parallel Technologies, Inc.) – C:\WINDOWS\System32\DRIVERS\ptilink.sys – (Ptilink [On_Demand | Running])
DRV - [2003/03/31 04:00:00 | 00,040,320 | —- | M] (QLogic Corporation) – C:\WINDOWS\System32\DRIVERS\ql1080.sys – (ql1080 [Boot | Stopped])
DRV - [2003/03/31 04:00:00 | 00,045,312 | —- | M] (QLogic Corporation) – C:\WINDOWS\System32\DRIVERS\ql12160.sys – (ql12160 [Boot | Stopped])
DRV - [2003/03/31 04:00:00 | 00,049,024 | —- | M] (QLogic Corporation) – C:\WINDOWS\System32\DRIVERS\ql1280.sys – (ql1280 [Boot | Stopped])
DRV - [2007/01/18 10:24:58 | 00,026,496 | R— | M] (Research in Motion Ltd) – C:\WINDOWS\system32\DRIVERS\RimSerial.sys – (RimVSerPort [On_Demand | Stopped])
DRV - [2003/03/31 04:00:00 | 00,005,888 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\Drivers\RootMdm.sys – (ROOTMODEM [On_Demand | Stopped])
DRV - [2005/03/21 11:00:24 | 00,004,096 | —- | M] (SuperAdBlocker.com) – C:\WINDOWS\System32\sabprocenum.sys – (SABProcEnum [On_Demand | Stopped])
DRV - [2007/11/13 02:25:53 | 00,020,480 | —- | M] (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.) – C:\WINDOWS\System32\DRIVERS\secdrv.sys – (Secdrv [Auto | Running])
DRV - [2008/04/13 10:36:39 | 00,040,960 | —- | M] (Silicon Integrated Systems Corporation) – C:\WINDOWS\System32\DRIVERS\sisagp.sys – (sisagp [Boot | Stopped])
DRV - [2001/08/17 13:56:16 | 00,007,552 | —- | M] (Sony Corporation) – C:\WINDOWS\System32\DRIVERS\SONYPVU1.SYS – (SONYPVU1 [On_Demand | Stopped])
DRV - [2003/03/31 04:00:00 | 00,019,072 | —- | M] (Adaptec, Inc.) – C:\WINDOWS\System32\DRIVERS\sparrow.sys – (Sparrow [Boot | Stopped])
DRV - [2004/03/23 07:01:38 | 00,040,564 | —- | M] (Alcor Micro Corp.) – C:\WINDOWS\System32\Drivers\sunkfilt.sys – (SunkFilt [On_Demand | Stopped])
DRV - [2004/03/23 07:27:20 | 00,042,936 | —- | M] (Alcor Micro Corp.) – C:\WINDOWS\System32\Drivers\sunkfilt39.sys – (SunkFilt39 [On_Demand | Stopped])
DRV - [2003/03/31 04:00:00 | 00,016,256 | —- | M] (Symbios Logic Inc.) – C:\WINDOWS\System32\DRIVERS\symc810.sys – (symc810 [Boot | Stopped])
DRV - [2003/03/31 04:00:00 | 00,032,640 | —- | M] (LSI Logic) – C:\WINDOWS\System32\DRIVERS\symc8xx.sys – (symc8xx [Boot | Stopped])
DRV - [2003/03/31 04:00:00 | 00,028,384 | —- | M] (LSI Logic) – C:\WINDOWS\System32\DRIVERS\sym_hi.sys – (sym_hi [Boot | Stopped])
DRV - [2003/03/31 04:00:00 | 00,030,688 | —- | M] (LSI Logic) – C:\WINDOWS\System32\DRIVERS\sym_u3.sys – (sym_u3 [Boot | Stopped])
DRV - [2008/01/31 13:16:28 | 00,034,944 | R— | M] (iS3 Inc.) – C:\WINDOWS\system32\drivers\szkg.sys – (szkg5 [Boot | Running])
DRV - [2003/03/31 04:00:00 | 00,036,736 | —- | M] (Promise Technology, Inc.) – C:\WINDOWS\System32\DRIVERS\ultra.sys – (ultra [Boot | Stopped])
DRV - [2008/09/05 22:16:46 | 00,036,864 | —- | M] (Apple, Inc.) – C:\WINDOWS\System32\Drivers\usbaapl.sys – (USBAAPL [On_Demand | Stopped])
DRV - [2008/04/13 10:45:12 | 00,060,032 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\drivers\usbaudio.sys – (usbaudio [On_Demand | Stopped])
DRV - [2003/11/14 14:18:36 | 00,679,808 | —- | M] (Conexant Systems, Inc.) – C:\WINDOWS\System32\DRIVERS\HSF_CNXT.sys – (winachsf [On_Demand | Running])

========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = [binary data]
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:NoAdd-ons
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:SecurityRisk
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomizeSearch = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Page_Transitions = 1
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local

========== FireFox ==========

FF - prefs.js..browser.startup.homepage: "http://www.yahoo.com/"

FF - HKLM\software\mozilla\Firefox\Extensions\\{20a82645-c095-46ed-80e3-08825760534b}: C:\WINDOWS\MICROSOFT.NET\FRAMEWORK\V3.5\WINDOWS PRESENTATION FOUNDATION\DOTNETASSISTANTEXTENSION\ [2009/04/11 11:25:15 | 00,000,000 | —D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\[removed]: C:\PROGRAM FILES\JAVA\JRE6\LIB\DEPLOY\JQS\FF [2009/05/09 08:13:25 | 00,000,000 | —D | M]

[2008/02/28 19:15:23 | 00,000,000 | —D | M] – C:\Documents and Settings\curt summers\Application Data\mozilla\Firefox\Profiles\xfpoka9p.default\extensions
[2008/06/23 16:55:09 | 00,000,000 | —D | M] – C:\Program Files\mozilla firefox\extensions
[2008/03/15 20:10:24 | 00,000,000 | —D | M] – C:\Program Files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA}

O1 HOSTS File: (728 bytes) - C:\WINDOWS\System32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (ZILLAbar Browser Helper Object) - {1827766B-9F49-4854-8034-F6EE26FCB1EC} - C:\Program Files\STOPzilla!\SZSG.dll (iS3, Inc)
O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll (AVG Technologies CZ, s.r.o.)
O2 - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (STOPzilla Browser Helper Object) - {E3215F20-3212-11D6-9F8B-00D0B743919D} - C:\Program Files\STOPzilla!\SZIEBHO.dll (iS3, Inc.)
O2 - BHO: (JQSIEStartDetectorImpl Class) - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll (Sun Microsystems, Inc.)
O3 - HKLM\..\Toolbar: (STOPzilla) - {98828DED-A591-462F-83BA-D2F62A68B8B8} - C:\Program Files\STOPzilla!\SZSG.dll (iS3, Inc)
O3 - HKLM\..\Toolbar: (no name) - SITEguard - Reg Error: Key error. File not found
O3 - HKCU\..\Toolbar\ShellBrowser: (no name) - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - Reg Error: Key error. File not found
O4 - HKLM..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime (Apple Inc.)
O4 - HKLM..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe" (Sun Microsystems, Inc.)
O4 - HKLM..\Run: [SunKistEM] "C:\Program Files\eMachines Bay Reader\shwiconem.exe" (Alcor Micro, Corp.)
O4 - HKCU..\Run: [FreeRAM XP] "C:\Program Files\YourWare Solutions\FreeRAM XP Pro\FreeRAM XP Pro.exe" -win (YourWare Solutions ™)
O4 - HKLM..\RunOnce: [PrivacyGuardianIndex] C:\Program Files\Privacy Guardian\PgIndex.exe (WinGuides Software)
O4 - HKCU..\RunOnce: [PGhist] C:\Program Files\Privacy Guardian\PgHist.exe WinguidesPG ()
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\control panel present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Infodelivery present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\restrictions present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Toolbars present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: LinkResolveIgnoreLinkInfo = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoResolveSearch = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 255
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\control panel present
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\restrictions present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: LinkResolveIgnoreLinkInfo = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoLowDiskSpaceChecks = 1
O9 - Extra 'Tools' menuitem : @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe (Microsoft Corporation)
O9 - Extra Button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [mdnsNSP] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\Program Files\Common Files\iS3\Anti-Spyware\iS3lsp.dll (iS3 & Exploit Prevention Labs, Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\Program Files\Common Files\iS3\Anti-Spyware\iS3lsp.dll (iS3 & Exploit Prevention Labs, Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\Program Files\Common Files\iS3\Anti-Spyware\iS3lsp.dll (iS3 & Exploit Prevention Labs, Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - C:\Program Files\Common Files\iS3\Anti-Spyware\iS3lsp.dll (iS3 & Exploit Prevention Labs, Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - C:\Program Files\Common Files\iS3\Anti-Spyware\iS3lsp.dll (iS3 & Exploit Prevention Labs, Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000006 - C:\Program Files\Common Files\iS3\Anti-Spyware\iS3lsp.dll (iS3 & Exploit Prevention Labs, Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000007 - C:\Program Files\Common Files\iS3\Anti-Spyware\iS3lsp.dll (iS3 & Exploit Prevention Labs, Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000008 - C:\Program Files\Common Files\iS3\Anti-Spyware\iS3lsp.dll (iS3 & Exploit Prevention Labs, Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000009 - C:\Program Files\Common Files\iS3\Anti-Spyware\iS3lsp.dll (iS3 & Exploit Prevention Labs, Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000010 - C:\Program Files\Common Files\iS3\Anti-Spyware\iS3lsp.dll (iS3 & Exploit Prevention Labs, Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000011 - C:\Program Files\Common Files\iS3\Anti-Spyware\iS3lsp.dll (iS3 & Exploit Prevention Labs, Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000012 - C:\Program Files\Common Files\iS3\Anti-Spyware\iS3lsp.dll (iS3 & Exploit Prevention Labs, Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000013 - C:\Program Files\Common Files\iS3\Anti-Spyware\iS3lsp.dll (iS3 & Exploit Prevention Labs, Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000014 - C:\Program Files\Common Files\iS3\Anti-Spyware\iS3lsp.dll (iS3 & Exploit Prevention Labs, Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000015 - C:\Program Files\Common Files\iS3\Anti-Spyware\iS3lsp.dll (iS3 & Exploit Prevention Labs, Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000016 - C:\Program Files\Common Files\iS3\Anti-Spyware\iS3lsp.dll (iS3 & Exploit Prevention Labs, Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000017 - C:\Program Files\Common Files\iS3\Anti-Spyware\iS3lsp.dll (iS3 & Exploit Prevention Labs, Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000018 - C:\Program Files\Common Files\iS3\Anti-Spyware\iS3lsp.dll (iS3 & Exploit Prevention Labs, Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000019 - C:\Program Files\Common Files\iS3\Anti-Spyware\iS3lsp.dll (iS3 & Exploit Prevention Labs, Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000020 - C:\Program Files\Common Files\iS3\Anti-Spyware\iS3lsp.dll (iS3 & Exploit Prevention Labs, Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000021 - C:\Program Files\Common Files\iS3\Anti-Spyware\iS3lsp.dll (iS3 & Exploit Prevention Labs, Inc.)
O15 - HKLM\..Trusted Domains: 1 domain(s) and sub-domain(s) not assigned to a zone.
O15 - HKCU\..Trusted Domains: alaskausa.org ([ultrabranch] https in Trusted sites)
O15 - HKCU\..Trusted Domains: ebay.com ([signin] https in Trusted sites)
O15 - HKCU\..Trusted Domains: gci.net ([my] https in Trusted sites)
O15 - HKCU\..Trusted Domains: 3 domain(s) and sub-domain(s) not assigned to a zone.
O16 - DPF: {1239CC52-59EF-4DFA-8C61-90FFA846DF7E} http://www.musicnotes.com/download/mnviewer.cab (Musicnotes Viewer)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://download.microsoft.com/download/5/b…heckControl.cab (Windows Genuine Advantage Validation Tool)
O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} http://lads.myspace.com/upload/MySpaceUploader1006.cab (MySpace Uploader Control)
O16 - DPF: {56762DEC-6B0D-4AB4-A8AD-989993B5D08B} http://www.eset.eu/OnlineScanner.cab (Reg Error: Value error.)
O16 - DPF: {5F8469B4-B055-49DD-83F7-62B522420ECC} http://upload.facebook.com/controls/Facebo…otoUploader.cab (Facebook Photo Uploader Control)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} http://www.update.microsoft.com/microsoftu…b?1179876639609 (MUWebControl Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get/flash…t/ultrashim.cab (Reg Error: Value error.)
O16 - DPF: {9D190AE6-C81E-4039-8061-978EBAD10073} http://portal.gci.net/static/scanner/fscax.cab (F-Secure Online Scanner 3.0)
O16 - DPF: {A8F2B9BD-A6A0-486A-9744-18920D898429} http://www.sibelius.com/download/software/…tiveXPlugin.cab (ScorchPlugin Class)
O16 - DPF: {B1E2B96C-12FE-45E2-BEF1-44A219113CDD} http://www.superadblocker.com/activex/sabspx.cab (SABScanProcesses Class)
O16 - DPF: {C1FDEE68-98D5-4F42-A4DD-D0BECF5077EB} http://tools.ebayimg.com/eps/wl/activex/eB…l_v1-0-27-0.cab (EPUImageControl Class)
O16 - DPF: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_13)
O18 - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\http\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\https\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll (AVG Technologies CZ, s.r.o.)
O18 - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\MSN Messenger\msgrapp.8.1.0178.00.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\MSN Messenger\msgrapp.8.1.0178.00.dll (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\Explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\avgrsstarter: DllName - avgrsstx.dll - C:\WINDOWS\system32\avgrsstx.dll (AVG Technologies CZ, s.r.o.)
O24 - Desktop Components:0 (My Current Home Page) - About:Home
O31 - SafeBoot: AlternateShell - cmd.exe
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2004/05/01 09:54:27 | 00,000,000 | -HS- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O33 - MountPoints2\{c603426e-dff8-11dd-a312-0040ca7f4640}\Shell - "" = AutoRun
O33 - MountPoints2\{c603426e-dff8-11dd-a312-0040ca7f4640}\Shell\AutoRun - "" = Auto&Play;
O33 - MountPoints2\{c603426e-dff8-11dd-a312-0040ca7f4640}\Shell\AutoRun\command - "" = F:\LaunchU3.exe – File not found
O33 - MountPoints2\{fc005fa6-e0d4-11dc-a106-0040ca7f4640}\Shell\AutoRun\command - "" = nhbivui.exe
O33 - MountPoints2\{fc005fa6-e0d4-11dc-a106-0040ca7f4640}\Shell\explore\Command - "" = nhbivui.exe
O33 - MountPoints2\{fc005fa6-e0d4-11dc-a106-0040ca7f4640}\Shell\open\Command - "" = nhbivui.exe
O34 - HKLM BootExecute: (autocheck) - File not found
O34 - HKLM BootExecute: (autochk) - C:\WINDOWS\System32\autochk.exe (Microsoft Corporation)
O34 - HKLM BootExecute: (*) - File not found

========== Files/Folders - Created Within 30 Days ==========

[2009/11/10 08:50:26 | 00,000,000 | -HSD | C] – C:\Config.Msi
[2009/11/10 08:34:25 | 00,000,000 | —D | C] – C:\Documents and Settings\curt summers\Application Data\ESET
[2009/11/10 08:32:36 | 00,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\ESET
[2009/11/08 18:23:22 | 00,077,824 | —- | C] (Ala S. Wrawreh) – C:\WINDOWS\System32\alafile.ocx
[2009/11/08 18:23:17 | 00,151,552 | —- | C] (Asmw Soft Systems www.asmwsoft.com) – C:\WINDOWS\System32\style.ocx
[2009/11/08 18:23:07 | 00,069,632 | —- | C] (speedMyPc.com ) – C:\WINDOWS\System32\HotKeys.ocx
[2009/11/08 18:22:55 | 00,270,336 | —- | C] () – C:\WINDOWS\System32\hiscl.ocx
[2009/11/08 18:22:51 | 00,000,000 | —D | C] – C:\Program Files\AsmwSoft
[2009/11/08 01:13:51 | 00,000,000 | —D | C] – C:\Documents and Settings\curt summers\Application Data\Comodo
[2009/11/07 21:05:07 | 00,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\comodo
[2009/11/07 21:05:02 | 00,000,000 | —D | C] – C:\Program Files\COMODO
[2009/05/10 08:29:45 | 00,501,248 | —- | C] (OldTimer Tools) – C:\Documents and Settings\curt summers\Desktop\OTListIt2.exe
[2009/05/07 14:50:53 | 00,000,000 | —D | C] – C:\Documents and Settings\curt summers\Application Data\Malwarebytes
[2009/05/07 14:50:46 | 00,015,504 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys
[2009/05/07 14:50:46 | 00,000,714 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2009/05/07 14:50:44 | 00,038,496 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2009/05/07 14:50:43 | 00,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Malwarebytes
[2009/05/07 14:50:42 | 00,000,000 | —D | C] – C:\Program Files\Malwarebytes' Anti-Malware
[2009/05/06 15:19:54 | 00,019,456 | —- | C] () – C:\Documents and Settings\curt summers\My Documents\moan chords.doc
[2009/05/02 08:31:01 | 00,001,740 | —- | C] () – C:\Documents and Settings\curt summers\Desktop\HijackThis.lnk
[2009/05/02 08:30:59 | 00,000,000 | —D | C] – C:\Program Files\Trend Micro
[2009/04/19 11:26:50 | 00,019,456 | —- | C] () – C:\Documents and Settings\curt summers\My Documents\This is a 50th anniversary model.doc
[2009/04/15 18:09:43 | 00,473,600 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\fastprox.dll
[2009/04/15 18:09:43 | 00,453,120 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\wmiprvsd.dll
[2009/04/15 18:09:43 | 00,401,408 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\rpcss.dll
[2009/04/15 18:09:43 | 00,284,160 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\pdh.dll
[2009/04/15 18:09:43 | 00,227,840 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\wmiprvse.exe
[2009/04/15 18:09:43 | 00,110,592 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\services.exe
[2009/04/15 18:09:43 | 00,035,328 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\sc.exe
[2009/04/15 18:09:42 | 00,729,088 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\lsasrv.dll
[2009/04/15 18:09:42 | 00,714,752 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\ntdll.dll
[2009/04/15 18:09:42 | 00,617,472 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\advapi32.dll
[2009/04/15 18:09:18 | 00,002,560 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\xpsp4res.dll
[2009/04/15 18:09:17 | 01,203,922 | —- | C] () – C:\WINDOWS\System32\dllcache\sysmain.sdb
[2009/04/15 18:09:17 | 00,215,552 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\wordpad.exe
[2009/04/12 06:47:43 | 01,089,593 | —- | C] () – C:\WINDOWS\System32\dllcache\ntprint.cat
[2009/04/11 11:24:09 | 00,000,000 | —D | C] – C:\WINDOWS\System32\XPSViewer
[2009/04/11 11:24:04 | 00,000,000 | —D | C] – C:\Program Files\MSBuild
[2009/04/11 11:23:53 | 00,000,000 | —D | C] – C:\Program Files\Reference Assemblies
[2009/04/11 11:23:15 | 00,117,760 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\prntvpt.dll
[2009/04/11 11:23:15 | 00,089,088 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\filterpipelineprintproc.dll
[2009/04/11 11:23:14 | 01,676,288 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\xpssvcs.dll
[2009/04/11 11:23:14 | 01,676,288 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\xpssvcs.dll
[2009/04/11 11:23:14 | 00,597,504 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\printfilterpipelinesvc.exe
[2009/04/11 11:23:14 | 00,575,488 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\xpsshhdr.dll
[2009/04/11 11:23:14 | 00,575,488 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\xpsshhdr.dll
[2009/04/11 11:23:13 | 00,000,000 | —D | C] – C:\85034cae0b1a4f6003510ead8e23
[2009/04/11 11:22:53 | 00,000,000 | —D | C] – C:\WINDOWS\SxsCaPendDel
[2009/04/11 10:51:26 | 00,000,000 | —D | C] – C:\Documents and Settings\curt summers\Application Data\Yahoo!
[2009/04/11 10:51:24 | 00,000,000 | —D | C] – C:\Program Files\Yahoo!
[2009/04/11 09:39:52 | 00,078,336 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\ieencode.dll
[2008/09/27 17:00:30 | 00,000,379 | —- | C] () – C:\WINDOWS\GearBox.ini
[2008/07/21 16:52:12 | 00,000,121 | —- | C] () – C:\WINDOWS\bdagent.INI
[2007/08/19 19:37:41 | 00,000,282 | —- | C] () – C:\WINDOWS\RealFlight.INI
[2007/06/22 18:18:25 | 00,002,528 | —- | C] () – C:\WINDOWS\FCIC.INI
[2007/05/30 16:06:24 | 00,000,049 | —- | C] () – C:\WINDOWS\NeroDigital.ini
[2007/05/30 14:35:42 | 00,000,004 | —- | C] () – C:\WINDOWS\msoffice.ini
[2007/05/30 14:32:42 | 00,006,656 | —- | C] () – C:\WINDOWS\System32\CNMVS58.DLL
[2007/05/08 19:20:32 | 00,000,376 | —- | C] () – C:\WINDOWS\ODBC.INI
[2006/10/30 10:30:30 | 00,010,032 | —- | C] () – C:\WINDOWS\System32\drivers\SBTEDrv.sys
[2005/11/02 10:39:16 | 00,040,960 | —- | C] () – C:\WINDOWS\System32\SDelete.dll
[2005/11/02 10:39:16 | 00,024,924 | —- | C] () – C:\WINDOWS\System32\openports.dll
[2004/05/05 16:41:30 | 00,532,544 | —- | C] () – C:\WINDOWS\PIC.dll
[2004/05/05 16:41:30 | 00,024,576 | —- | C] () – C:\WINDOWS\HKNTDLL.dll
[2004/05/05 16:30:12 | 00,018,253 | —- | C] () – C:\WINDOWS\System32\ssnvfx.ini
[2004/05/04 02:13:35 | 00,000,061 | —- | C] () – C:\WINDOWS\smscfg.ini
[2004/05/02 06:40:08 | 00,001,120 | —- | C] () – C:\WINDOWS\System32\oeminfo.ini
[2004/05/02 06:40:08 | 00,000,489 | —- | C] () – C:\WINDOWS\System32\emver.ini
[2004/05/02 06:39:49 | 00,001,159 | —- | C] () – C:\WINDOWS\win.ini
[2004/05/01 10:50:46 | 00,000,132 | —- | C] () – C:\WINDOWS\winamp.ini
[2004/05/01 10:50:09 | 00,000,310 | —- | C] () – C:\WINDOWS\net2fone.ini
[2004/05/01 10:09:46 | 00,363,520 | —- | C] () – C:\WINDOWS\System32\psisdecd.dll
[2004/05/01 09:39:45 | 00,000,227 | —- | C] () – C:\WINDOWS\SYSTEM.INI

========== Files - Modified Within 30 Days ==========

[2009/11/08 10:16:32 | 00,000,292 | -H– | M] () – C:\sqmdata09.sqm
[2009/11/08 10:16:32 | 00,000,244 | -H– | M] () – C:\sqmnoopt09.sqm
[2009/05/10 08:29:52 | 00,501,248 | —- | M] (OldTimer Tools) – C:\Documents and Settings\curt summers\Desktop\OTListIt2.exe
[2009/05/10 08:04:26 | 35,961,689 | —- | M] () – C:\WINDOWS\System32\drivers\Avg\incavi.avm
[2009/05/10 08:04:26 | 00,052,945 | —- | M] () – C:\WINDOWS\System32\drivers\Avg\microavi.avg
[2009/05/09 19:44:48 | 00,000,458 | —- | M] () – C:\WINDOWS\tasks\ParetoLogic Registration.job
[2009/05/09 09:38:37 | 00,000,618 | —- | M] () – C:\Documents and Settings\curt summers\My Documents\My Sharing Folders.lnk
[2009/05/09 08:56:54 | 00,000,049 | —- | M] () – C:\WINDOWS\NeroDigital.ini
[2009/05/09 08:07:46 | 00,001,170 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2009/05/09 08:06:51 | 00,003,731 | —- | M] () – C:\WINDOWS\System32\nvapps.xml
[2009/05/09 08:06:03 | 00,000,062 | -HS- | M] () – C:\Documents and Settings\curt summers\Local Settings\desktop.ini
[2009/05/09 08:06:03 | 00,000,006 | -H– | M] () – C:\WINDOWS\tasks\SA.DAT
[2009/05/09 08:05:45 | 00,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2009/05/09 08:05:40 | 10,061,61920 | -HS- | M] () – C:\hiberfil.sys
[2009/05/07 14:50:46 | 00,000,714 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2009/05/06 15:19:54 | 00,019,456 | —- | M] () – C:\Documents and Settings\curt summers\My Documents\moan chords.doc
[2009/05/02 08:31:01 | 00,001,740 | —- | M] () – C:\Documents and Settings\curt summers\Desktop\HijackThis.lnk
[2009/05/01 16:46:56 | 00,325,896 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\drivers\avgldx86.sys
[2009/05/01 16:46:56 | 00,027,784 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\drivers\avgmfx86.sys
[2009/05/01 16:46:56 | 00,011,952 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\avgrsstx.dll
[2009/05/01 16:46:40 | 00,108,552 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\drivers\avgtdix.sys
[2009/04/19 11:26:50 | 00,019,456 | —- | M] () – C:\Documents and Settings\curt summers\My Documents\This is a 50th anniversary model.doc
[2009/04/17 18:16:24 | 00,434,673 | —- | M] () – C:\WINDOWS\System32\drivers\Avg\miniavi.avg
[2009/04/16 22:31:57 | 00,000,244 | -H– | M] () – C:\sqmnoopt08.sqm
[2009/04/16 22:31:57 | 00,000,232 | -H– | M] () – C:\sqmdata08.sqm
[2009/04/16 21:58:43 | 00,000,244 | -H– | M] () – C:\sqmnoopt07.sqm
[2009/04/16 21:58:43 | 00,000,232 | -H– | M] () – C:\sqmdata07.sqm
[2009/04/16 21:47:30 | 00,000,244 | -H– | M] () – C:\sqmnoopt06.sqm
[2009/04/16 21:47:30 | 00,000,232 | -H– | M] () – C:\sqmdata06.sqm
[2009/04/16 21:42:31 | 00,000,244 | -H– | M] () – C:\sqmnoopt05.sqm
[2009/04/16 21:42:31 | 00,000,232 | -H– | M] () – C:\sqmdata05.sqm
[2009/04/16 14:36:06 | 00,432,356 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2009/04/16 14:36:06 | 00,067,312 | —- | M] () – C:\WINDOWS\System32\perfc009.dat
[2009/04/16 14:36:03 | 00,508,780 | —- | M] () – C:\WINDOWS\System32\PerfStringBackup.INI
[2009/04/11 11:32:39 | 00,238,352 | —- | M] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2009/04/11 10:51:21 | 00,001,548 | —- | M] () – C:\Documents and Settings\curt summers\Desktop\CCleaner.lnk
[2009/04/11 09:47:29 | 00,000,084 | -HS- | M] () – C:\Documents and Settings\curt summers\My Documents\desktop.ini

========== LOP Check ==========

[2009/05/07 14:50:43 | 00,000,000 | RH-D | M] – C:\Documents and Settings\All Users\Application Data
[2008/09/12 01:23:34 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}
[2008/10/13 09:09:32 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Adobe
[2007/05/30 14:35:50 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\AOL
[2007/08/09 20:11:26 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Apple
[2007/08/09 20:18:00 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Apple Computer
[2009/02/27 17:28:22 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\avg8
[2009/03/02 18:22:39 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Avira
[2009/11/10 08:18:22 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\comodo
[2008/07/19 15:14:13 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Corel
[2004/05/07 14:11:10 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\CyberLink
[2009/11/10 08:32:36 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\ESET
[2007/06/22 18:18:25 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\FirstClass
[2008/04/05 07:42:17 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Grisoft
[2009/03/16 20:07:37 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Kaspersky Lab Setup Files
[2009/02/28 08:43:13 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Line 6
[2008/12/20 10:49:58 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\logs
[2009/05/07 14:50:43 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Malwarebytes
[2008/06/23 23:10:22 | 00,000,000 | –SD | M] – C:\Documents and Settings\All Users\Application Data\Microsoft
[2007/06/08 21:48:37 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\MSN6
[2007/06/29 16:48:03 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Musicnotes
[2008/11/04 08:38:48 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\NOS
[2004/05/07 14:11:12 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\nView_Profiles
[2008/09/30 08:17:37 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\ParetoLogic
[2008/01/12 16:29:52 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Prevx
[2004/05/07 14:11:11 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\QuickTime
[2008/11/27 07:47:28 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\SITEguard
[2007/05/30 18:10:59 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Sonoma Wire Works
[2008/11/28 18:15:22 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
[2009/05/10 08:29:07 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\STOPzilla!
[2007/05/30 14:38:24 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Symantec
[2009/03/16 20:03:28 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TEMP
[2008/11/28 18:20:26 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Trend Micro
[2004/05/07 14:11:12 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Viewpoint
[2007/05/15 15:00:22 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Windows Genuine Advantage
[2007/08/09 08:40:06 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\ZILLAbar
[2009/05/07 14:50:53 | 00,000,000 | RH-D | M] – C:\Documents and Settings\curt summers\Application Data
[2008/10/13 09:09:32 | 00,000,000 | —D | M] – C:\Documents and Settings\curt summers\Application Data\Adobe
[2007/09/02 09:14:51 | 00,000,000 | —D | M] – C:\Documents and Settings\curt summers\Application Data\AdobeUM
[2008/12/25 20:28:39 | 00,000,000 | —D | M] – C:\Documents and Settings\curt summers\Application Data\Ahead
[2008/06/03 09:06:36 | 00,000,000 | —D | M] – C:\Documents and Settings\curt summers\Application Data\Amazon
[2008/09/20 20:09:35 | 00,000,000 | —D | M] – C:\Documents and Settings\curt summers\Application Data\Apple Computer
[2007/05/30 15:14:57 | 00,000,000 | —D | M] – C:\Documents and Settings\curt summers\Application Data\ArcSoft
[2008/11/03 15:33:08 | 00,000,000 | —D | M] – C:\Documents and Settings\curt summers\Application Data\com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
[2009/11/10 08:17:22 | 00,000,000 | —D | M] – C:\Documents and Settings\curt summers\Application Data\Comodo
[2008/07/19 15:14:08 | 00,000,000 | —D | M] – C:\Documents and Settings\curt summers\Application Data\Corel
[2004/05/07 14:11:16 | 00,000,000 | —D | M] – C:\Documents and Settings\curt summers\Application Data\CyberLink
[2009/11/10 08:34:25 | 00,000,000 | —D | M] – C:\Documents and Settings\curt summers\Application Data\ESET
[2008/06/10 16:24:26 | 00,000,000 | —D | M] – C:\Documents and Settings\curt summers\Application Data\Help
[2004/05/07 14:11:16 | 00,000,000 | —D | M] – C:\Documents and Settings\curt summers\Application Data\Identities
[2008/11/15 15:46:08 | 00,000,000 | —D | M] – C:\Documents and Settings\curt summers\Application Data\IObit
[2007/06/28 15:39:28 | 00,000,000 | —D | M] – C:\Documents and Settings\curt summers\Application Data\LegalSounds
[2008/08/20 13:45:40 | 00,000,000 | —D | M] – C:\Documents and Settings\curt summers\Application Data\Line 6
[2007/05/05 15:24:48 | 00,000,000 | —D | M] – C:\Documents and Settings\curt summers\Application Data\Macromedia
[2009/05/07 14:50:53 | 00,000,000 | —D | M] – C:\Documents and Settings\curt summers\Application Data\Malwarebytes
[2009/03/03 22:46:08 | 00,000,000 | –SD | M] – C:\Documents and Settings\curt summers\Application Data\Microsoft
[2007/05/08 19:18:50 | 00,000,000 | —D | M] – C:\Documents and Settings\curt summers\Application Data\Microsoft Web Folders
[2008/02/28 19:15:19 | 00,000,000 | —D | M] – C:\Documents and Settings\curt summers\Application Data\Mozilla
[2007/06/29 12:43:16 | 00,000,000 | —D | M] – C:\Documents and Settings\curt summers\Application Data\MP3Rocket
[2007/06/08 21:48:53 | 00,000,000 | —D | M] – C:\Documents and Settings\curt summers\Application Data\MSN6
[2008/06/23 23:10:21 | 00,000,000 | —D | M] – C:\Documents and Settings\curt summers\Application Data\MySpace
[2008/04/25 16:20:42 | 00,000,000 | —D | M] – C:\Documents and Settings\curt summers\Application Data\Real
[2008/07/25 12:30:50 | 00,000,000 | —D | M] – C:\Documents and Settings\curt summers\Application Data\Sibelius Software
[2004/05/07 14:11:16 | 00,000,000 | —D | M] – C:\Documents and Settings\curt summers\Application Data\Sun
[2008/07/05 19:14:09 | 00,000,000 | —D | M] – C:\Documents and Settings\curt summers\Application Data\Sunbelt Software
[2008/07/31 19:40:17 | 00,000,000 | —D | M] – C:\Documents and Settings\curt summers\Application Data\SUPERAntiSpyware.com
[2004/05/07 14:11:16 | 00,000,000 | —D | M] – C:\Documents and Settings\curt summers\Application Data\Symantec
[2009/02/19 16:14:57 | 00,000,000 | —D | M] – C:\Documents and Settings\curt summers\Application Data\U3
[2008/07/30 14:05:41 | 00,000,000 | —D | M] – C:\Documents and Settings\curt summers\Application Data\Uniblue
[2008/08/25 23:04:48 | 00,000,000 | —D | M] – C:\Documents and Settings\curt summers\Application Data\VoipBuster
[2009/04/11 10:51:26 | 00,000,000 | —D | M] – C:\Documents and Settings\curt summers\Application Data\Yahoo!
[2008/09/19 07:04:04 | 00,000,284 | —- | M] () – C:\WINDOWS\Tasks\AppleSoftwareUpdate.job
[2003/03/31 11:00:00 | 00,000,065 | RH– | M] () – C:\WINDOWS\Tasks\desktop.ini
[2009/05/09 19:44:48 | 00,000,458 | —- | M] () – C:\WINDOWS\Tasks\ParetoLogic Registration.job
[2009/05/09 08:06:03 | 00,000,006 | -H– | M] () – C:\WINDOWS\Tasks\SA.DAT

========== Purity Check ==========


========== Alternate Data Streams ==========

@Alternate Data Stream - 127 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:1CA73D29
@Alternate Data Stream - 121 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:7E95B6FD
@Alternate Data Stream - 116 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:D1B5B4F1
@Alternate Data Stream - 104 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:DFC5A2B2
< End of report >
OTListIt Extras logfile created on: 5/10/2009 8:52:21 AM - Run 1
OTListIt2 by OldTimer - Version 2.0.15.6 Folder = C:\Documents and Settings\curt summers\Desktop
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.13)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

959.48 Mb Total Physical Memory | 569.25 Mb Available Physical Memory | 59.33% Memory free
1.74 Gb Paging File | 1.40 Gb Available in Paging File | 80.66% Paging File free
Paging file location(s): C:\pagefile.sys 900 1344 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 149.05 Gb Total Space | 3.23 Gb Free Space | 2.17% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: OWNER-84J1T8A8N
Current User Name: curt summers
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Output = Standard
File Age = 30 Days
Company Name Whitelist: On

========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.html [@ = htmlfile] – C:\Program Files\Internet Explorer\IEXPLORE.EXE (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 0
"AntiVirusDisableNotify" = 0
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile
"EnableFirewall" = 0

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile
"EnableFirewall" = 0
"DoNotAllowExceptions" = 0
"DisableNotifications" = 0

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List
"139:TCP" = 139:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22002
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
[2008/04/13 10:53:32 | 00,558,080 | —- | M] (Microsoft Corporation) – %windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000
[2007/01/19 12:54:56 | 05,674,352 | —- | M] (Microsoft Corporation) – C:\Program Files\MSN Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger 8.1
[2007/01/04 16:10:02 | 00,297,752 | —- | M] (Microsoft Corporation) – C:\Program Files\MSN Messenger\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone)

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
[2008/04/13 10:53:32 | 00,558,080 | —- | M] (Microsoft Corporation) – C:\WINDOWS\network diagnostic\xpnetdiag.exe:*:Enabled:Network Diagnostic for Windows XP
[2009/02/27 20:54:41 | 00,636,072 | —- | M] (Microsoft Corporation) – C:\Program Files\Internet Explorer\iexplore.exe:*:Enabled:Internet Explorer
[2008/04/13 10:53:32 | 00,558,080 | —- | M] (Microsoft Corporation) – %windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000
[2007/01/19 12:54:56 | 05,674,352 | —- | M] (Microsoft Corporation) – C:\Program Files\MSN Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger 8.1
[2007/01/04 16:10:02 | 00,297,752 | —- | M] (Microsoft Corporation) – C:\Program Files\MSN Messenger\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone)
File not found – C:\Program Files\Java\jre1.6.0_05\bin\javaw.exe:*:Enabled:Java™ Platform SE binary
[2008/08/29 10:18:44 | 00,238,888 | —- | M] (Apple Inc.) – C:\Program Files\Bonjour\mDNSResponder.exe:*:Enabled:Bonjour
[2008/09/08 23:02:02 | 14,228,264 | —- | M] (Apple Inc.) – C:\Program Files\iTunes\iTunes.exe:*:Enabled:iTunes
[2009/05/01 16:45:06 | 01,085,208 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Program Files\AVG\AVG8\avgupd.exe:*:Enabled:avgupd.exe
[2009/05/01 16:46:44 | 00,594,712 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Program Files\AVG\AVG8\avgnsx.exe:*:Enabled:avgnsx.exe

========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"_{7F05E704-30A6-421A-97A7-8EEB1C7FF010}" = CorelDRAW® Graphics Suite X4
"_{CE2DA11A-917F-4CF5-AB55-755EC115DD10}" = CorelDRAW® Graphics Suite X4 - Windows Shell Extension
"{00030409-78E1-11D2-B60F-006097C998E7}" = Microsoft Office 2000 Small Business
"{00203668-8170-44A0-BE44-B632FA4D780F}" = Adobe AIR
"{02DF19A9-DBAC-44E1-A018-D1AA7EBFAD36}" = STOPzilla
"{15CCBC5D-66A7-4131-8D36-E05F27B0E68F}" = Sibelius Scorch (ActiveX Only)
"{26A24AE4-039D-4CA4-87B4-2F83216013FF}" = Java™ 6 Update 13
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{3CCB26F5-E2A7-4C91-8340-9149D7B7C2BE}" = Virtual Earth 3D (Beta)
"{44A27085-0616-4181-A0C3-81C7ECA17F73}" = CorelDRAW Graphics Suite X4
"{49FC50FC-F965-40D9-89B4-CBFF80941033}" = Windows Movie Maker 2.0
"{571700F0-DB9D-4B3A-B03D-35A14BB5939F}" = Windows Live Messenger
"{5B35C417-2649-11D6-83D1-0050FC01225C}" = FirstClass® Client
"{6811CAA0-BF12-11D4-9EA1-0050BAE317E1}" = PowerDVD
"{6956856F-B6B3-4BE0-BA0B-8F495BE32033}" = Apple Software Update
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{764D06D8-D8DE-411E-A1C8-D9E9380F8A84}" = Microsoft Works 7.0
"{76EFFC7C-17A6-479D-9E47-8E658C1695AE}" = Windows Backup Utility
"{77DCDCE3-2DED-62F3-8154-05E745472D07}" = Acrobat.com
"{7F05E704-30A6-421A-97A7-8EEB1C7FF010}" = CorelDRAW Graphics SUite X4 - ICA
"{7F05E704-30A6-421A-97A7-8EEB1C7FF012}" = CorelDRAW Graphics Suite X4 - Capture
"{7F05E704-30A6-421A-97A7-8EEB1C7FF013}" = CorelDRAW Graphics Suite X4 - Draw
"{7F05E704-30A6-421A-97A7-8EEB1C7FF014}" = CorelDRAW Graphics Suite X4 - PP
"{7F05E704-30A6-421A-97A7-8EEB1C7FF016}" = CorelDRAW Graphics Suite X4 - Content
"{7F05E704-30A6-421A-97A7-8EEB1C7FF017}" = CorelDRAW Graphics Suite X4 - Filters
"{7F05E704-30A6-421A-97A7-8EEB1C7FF019}" = CorelDRAW Graphics Suite X4 - FontNav
"{7F05E704-30A6-421A-97A7-8EEB1C7FF100}" = CorelDRAW Graphics Suite X4 - Lang EN
"{81EED1A1-AE78-4B11-BE47-C6AE9F5E87F1}" = eMachines Bay Reader
"{8A25392D-C5D2-4E79-A2BD-C15DDC5B0959}" = Bonjour
"{8DC42D05-680B-41B0-8878-6C14D24602DB}" = QuickTime
"{9D0798D0-AF6C-4E62-94B1-AEBF1A43E00A}" = CorelDRAW Graphics Suite X4 - IPM
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{AC76BA86-7AD7-1033-7B44-A81100000003}" = Adobe Reader 8.1.1
"{B61D21B6-469D-4423-B161-62DB20B8A70E}" = Visual Basic for Applications ® Core - English
"{BD57EA4D-026E-4F08-9B93-080E282B81FE}" = iPod for Windows 2006-06-28
"{BF439B41-0252-48DE-8B8B-0430CB26A181}" = CorelDRAW Graphics Suite X4 - VBA
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{C7C895CA-331B-4D7D-A0FB-D3BC637949F9}" = Apple Mobile Device Support
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{CE2DA11A-917F-4CF5-AB55-755EC115DD10}" = CorelDRAW® Graphics Suite X4 - Windows Shell Extension
"{DB81779E-7CC5-4630-BCFC-754004956444}" = Visual Basic for Applications ® Core
"{DBA8B9E1-C6FF-4624-9598-73D3B41A0903}" = Microsoft Picture It! Photo Premium 9
"{EA418519-2160-43A0-AABD-6608DDD8D87F}" = iTunes
"{FF262740-C85A-11D5-BBEC-00D0B740900A}" = Multimedia Keyboard Driver
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Advanced Spyware Remover Free Edition_is1" = Advanced Spyware Remover Free Edition
"Advanced SystemCare 3_is1" = Advanced SystemCare 3
"Amazon MP3 Downloader" = Amazon MP3 Downloader 1.0.3
"AP Guitar Tuner" = AP Guitar Tuner
"Asmw Eraser Pro" = Asmw Eraser Pro
"Autorun Eater_is1" = Autorun Eater v2.3
"AVG8Uninstall" = AVG 8.5
"CCleaner" = CCleaner (remove only)
"CNXT_MODEM_PCI_VEN_14F1&DEV_2F20&SUBSYS_200014F1" = SoftV92 Data Fax Modem with SmartCP
"com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Acrobat.com
"GuitarPort 2.51.0" = GuitarPort 2.51.0 (Remove Only)
"HijackThis" = HijackThis 2.0.2
"IDNMitigationAPIs" = Microsoft Internationalized Domain Names Mitigation APIs
"ie7" = Windows Internet Explorer 7
"InCD!UninstallKey" = InCD
"InstallShield_{81EED1A1-AE78-4B11-BE47-C6AE9F5E87F1}" = eMachines Bay Reader
"InstallShield_{BD57EA4D-026E-4F08-9B93-080E282B81FE}" = iPod for Windows 2006-06-28
"IObit SmartDefrag Beta5.01_is1" = IObit SmartDefrag
"iPod To Computer Transfer_is1" = iPod To Computer Transfer 3.5
"Line 6 Uninstaller" = Line 6 Uninstaller
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"MSCompPackV1" = Microsoft Compression Client Pack 1.0 for Windows XP
"Nero - Burning Rom!UninstallKey" = Nero OEM
"NLSDownlevelMapping" = Microsoft National Language Support Downlevel APIs
"NVIDIA Display Driver" = NVIDIA Display Driver
"NVIDIA Ethernet Driver" = NVIDIA Ethernet Driver
"NVIDIA nForce Drivers" = NVIDIA nForce Drivers
"PictureIt_v9" = Microsoft Picture It! Photo Premium 9
"Privacy Guardian_is1" = Privacy Guardian 4.1
"RealFlight2" = RealFlight G2 Simulator
"RiffWorks Line 6 Edition" = RiffWorks Line 6 Edition
"StreetPlugin" = Learn2 Player (Uninstall Only)
"Windows Live OneCare safety scanner" = Windows Live OneCare safety scanner
"Windows Media Format Runtime" = Windows Media Format 11 runtime
"Windows Media Player" = Windows Media Player 11
"Windows XP Service Pack" = Windows XP Service Pack 3
"WMFDist11" = Windows Media Format 11 runtime
"wmp11" = Windows Media Player 11
"Wudf01000" = Microsoft User-Mode Driver Framework Feature Pack 1.0

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 4/30/2009 10:39:46 PM | Computer Name = OWNER-84J1T8A8N | Source = Application Error | ID = 1000
Description = Faulting application iexplore.exe, version 8.0.6001.18702, faulting
module sziebho.dll, version 5.0.7.1, fault address 0x0000b2c7.

Error - 5/1/2009 12:09:36 AM | Computer Name = OWNER-84J1T8A8N | Source = Application Error | ID = 1000
Description = Faulting application iexplore.exe, version 8.0.6001.18702, faulting
module wininet.dll, version 8.0.6001.18702, fault address 0x00006429.

Error - 5/1/2009 10:44:43 PM | Computer Name = OWNER-84J1T8A8N | Source = Application Error | ID = 1000
Description = Faulting application iexplore.exe, version 8.0.6001.18702, faulting
module sziebho.dll, version 5.0.7.1, fault address 0x0000b2c7.

Error - 5/2/2009 11:54:11 AM | Computer Name = OWNER-84J1T8A8N | Source = Application Error | ID = 1000
Description = Faulting application iexplore.exe, version 8.0.6001.18702, faulting
module urlmon.dll, version 8.0.6001.18702, fault address 0x0003e819.

Error - 5/2/2009 12:26:57 PM | Computer Name = OWNER-84J1T8A8N | Source = Application Error | ID = 1000
Description = Faulting application iexplore.exe, version 8.0.6001.18702, faulting
module urlmon.dll, version 8.0.6001.18702, fault address 0x0003e819.

Error - 5/2/2009 6:32:35 PM | Computer Name = OWNER-84J1T8A8N | Source = Application Error | ID = 1000
Description = Faulting application iexplore.exe, version 8.0.6001.18702, faulting
module urlmon.dll, version 8.0.6001.18702, fault address 0x0003e819.

Error - 5/2/2009 6:40:01 PM | Computer Name = OWNER-84J1T8A8N | Source = Application Error | ID = 1000
Description = Faulting application iexplore.exe, version 8.0.6001.18702, faulting
module urlmon.dll, version 8.0.6001.18702, fault address 0x0003e819.

Error - 5/2/2009 6:40:11 PM | Computer Name = OWNER-84J1T8A8N | Source = Application Error | ID = 1000
Description = Faulting application iexplore.exe, version 8.0.6001.18702, faulting
module urlmon.dll, version 8.0.6001.18702, fault address 0x0003e819.

Error - 5/2/2009 6:42:22 PM | Computer Name = OWNER-84J1T8A8N | Source = Application Error | ID = 1000
Description = Faulting application iexplore.exe, version 8.0.6001.18702, faulting
module urlmon.dll, version 8.0.6001.18702, fault address 0x0003e819.

Error - 5/2/2009 6:42:27 PM | Computer Name = OWNER-84J1T8A8N | Source = Application Error | ID = 1000
Description = Faulting application iexplore.exe, version 8.0.6001.18702, faulting
module urlmon.dll, version 8.0.6001.18702, fault address 0x0003e819.

[ System Events ]
Error - 5/9/2009 12:04:28 PM | Computer Name = OWNER-84J1T8A8N | Source = Service Control Manager | ID = 7023
Description = The Application Management service terminated with the following error:
%%2

Error - 5/9/2009 12:04:29 PM | Computer Name = OWNER-84J1T8A8N | Source = Service Control Manager | ID = 7023
Description = The Application Management service terminated with the following error:
%%2

Error - 5/9/2009 12:04:29 PM | Computer Name = OWNER-84J1T8A8N | Source = Service Control Manager | ID = 7023
Description = The Application Management service terminated with the following error:
%%2

Error - 5/9/2009 12:04:29 PM | Computer Name = OWNER-84J1T8A8N | Source = Service Control Manager | ID = 7023
Description = The Application Management service terminated with the following error:
%%2

Error - 5/9/2009 12:04:29 PM | Computer Name = OWNER-84J1T8A8N | Source = Service Control Manager | ID = 7023
Description = The Application Management service terminated with the following error:
%%2

Error - 5/9/2009 12:04:29 PM | Computer Name = OWNER-84J1T8A8N | Source = Service Control Manager | ID = 7023
Description = The Application Management service terminated with the following error:
%%2

Error - 5/9/2009 12:04:29 PM | Computer Name = OWNER-84J1T8A8N | Source = Service Control Manager | ID = 7023
Description = The Application Management service terminated with the following error:
%%2

Error - 5/9/2009 12:06:51 PM | Computer Name = OWNER-84J1T8A8N | Source = Service Control Manager | ID = 7023
Description = The HID Input Service service terminated with the following error:
%%2

Error - 5/9/2009 12:06:51 PM | Computer Name = OWNER-84J1T8A8N | Source = Service Control Manager | ID = 7026
Description = The following boot-start or system-start driver(s) failed to load:
abp480n5 adpu160m agp440 agpCPQ Aha154x aic78u2 aic78xx AliIde alim1541 amdagp amsint asc asc3350p
asc3550
AVG
Anti-Rootkit AvgArCln cbidf cd20xrnt CmdIde Cpqarray dac2w2k dac960nt dpti2o hpn i2omp ini910u
IntelIde
mraid35x
perc2
perc2hib
ql1080
Ql10wnt
ql12160
ql1240
ql1280
SASKUTIL
sisagp
Sparrow
symc810
symc8xx
sym_hi
sym_u3
TosIde
ultra
viaagp
ViaIde

Error - 5/10/2009 12:15:03 PM | Computer Name = OWNER-84J1T8A8N | Source = DCOM | ID = 10005
Description = DCOM got error "%1058" attempting to start the service upnphost with
arguments "" in order to run the server: {204810B9-73B2-11D4-BF42-00B0D0118B56}


< End of report >
Otis99,

Double click on OTList2.exe
  • Under the Custom Scans/Fixes box at the bottom, paste in the following
  • Do Not copy the word CODE
  • please note the fix starts with the :
:Processes
explorer.exe

:OTLI
O33 - MountPoints2\{fc005fa6-e0d4-11dc-a106-0040ca7f4640}\Shell\AutoRun\command - "" = nhbivui.exe
O33 - MountPoints2\{fc005fa6-e0d4-11dc-a106-0040ca7f4640}\Shell\explore\Command - "" = nhbivui.exe
O33 - MountPoints2\{fc005fa6-e0d4-11dc-a106-0040ca7f4640}\Shell\open\Command - "" = nhbivui.exe

:Services

:Reg

:Files
C:\85034cae0b1a4f6003510ead8e23
C:\sqmdata09.sqm
C:\sqmnoopt09.sqm
C:\sqmnoopt08.sqm
C:\sqmdata08.sqm
C:\sqmnoopt07.sqm
C:\sqmdata07.sqm
C:\sqmnoopt06.sqm
C:\sqmdata06.sqm
C:\sqmnoopt05.sqm
C:\sqmdata05.sqm

:Commands
[purity]
[emptytemp]
[start explorer]
[Reboot]

Then click the Run Fix button at the top
  • Let the program run unhindered
  • Please save the resulting log to be posted in your next reply.
  • Reboot your computer
Please post the OTL2 log.

Then

Please download SDFix and save it to your Desktop.

You should print out these instructions, or copy them to a NotePad file for reading while in Safe Mode, because you will not be able to connect to the Internet to read from this site.

Double click on SDFix.exe. It should automatically extract a folder called SDFix to your system drive (usually C:\). Please reboot your computer in Safe Mode by doing the following :
  • Restart your computer
  • After hearing your computer beep once during startup, but before the Windows icon appears, tap the F8 key repeatedly;
  • Instead of Windows loading as normal, a menu with options should appear;
  • Select the first option, to run Windows in Safe Mode, then press "Enter".
  • Choose your usual user account.
  • Open the SDFix folder and double click on RunThis.bat to start the script.
  • Type Y and press Enter to begin the script.
  • It will start cleaning your PC and then prompt you to press any key to Reboot.
  • Press any key to restart the PC.
  • Your system will take longer than normal to restart as the fixtool will be removing files.
  • When the desktop loads the Fixtool will complete the removal and display Finished.
  • Press any key to end the script and to load your desktop icons.
  • A text file should automatically open, so please copy the contents and post them here. We also need you to post a new HijackThis log
Before I go any farther, I did what you said:
Let the program run unhindered
Please save the resulting log to be posted in your next reply.
Reboot your computer
Please post the OTL2 log.

But, it did not create any kind of log, it went right to the reboot option, I did not see a log, or log option?? I did have to reboot, now what?
Otis99, Please look in the c:\_OTListIt\MovedFiles folder. If there are any .txt or .log files in there please post the information.
Is this what you are looking for? ========== PROCESSES ========== Process explorer.exe killed successfully! ========== OTLISTIT ========== Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{fc005fa6-e0d4-11dc-a106-0040ca7f4640}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{fc005fa6-e0d4-11dc-a106-0040ca7f4640}\ not found. File nhbivui.exe not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{fc005fa6-e0d4-11dc-a106-0040ca7f4640}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{fc005fa6-e0d4-11dc-a106-0040ca7f4640}\ not found. File nhbivui.exe not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{fc005fa6-e0d4-11dc-a106-0040ca7f4640}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{fc005fa6-e0d4-11dc-a106-0040ca7f4640}\ not found. File nhbivui.exe not found. ========== SERVICES/DRIVERS ========== ========== REGISTRY ========== ========== FILES ========== C:\85034cae0b1a4f6003510ead8e23\i386 moved successfully. C:\85034cae0b1a4f6003510ead8e23\amd64 moved successfully. C:\85034cae0b1a4f6003510ead8e23 moved successfully. C:\sqmdata09.sqm moved successfully. C:\sqmnoopt09.sqm moved successfully. C:\sqmnoopt08.sqm moved successfully. C:\sqmdata08.sqm moved successfully. C:\sqmnoopt07.sqm moved successfully. C:\sqmdata07.sqm moved successfully. C:\sqmnoopt06.sqm moved successfully. C:\sqmdata06.sqm moved successfully. C:\sqmnoopt05.sqm moved successfully. C:\sqmdata05.sqm moved successfully. ========== COMMANDS ========== File delete failed. C:\Documents and Settings\curt summers\Local Settings\Temp\Perflib_Perfdata_6d4.dat scheduled to be deleted on reboot. File delete failed. C:\Documents and Settings\curt summers\Local Settings\Temp\Perflib_Perfdata_b98.dat scheduled to be deleted on reboot. User's Temp folder emptied. User's Internet Explorer cache folder emptied. File delete failed. C:\WINDOWS\temp\Perflib_Perfdata_1bc.dat scheduled to be deleted on reboot. Windows Temp folder emptied. Java cache emptied. Temp folders emptied. Explorer started successfully OTListIt2 by OldTimer - Version 2.0.15.6 log created on 05112009_070207
OK, here you are…


SDFix: Version 1.240
Run by [removed] on Thu 05/14/2009 at 02:20 PM

Microsoft Windows XP [Version 5.1.2600]
Running From: C:\SDFix

Checking Services :


Restoring Default Security Values
Restoring Default Hosts File

Rebooting


Checking Files :

No Trojan Files Found






Removing Temp Files

ADS Check :



Final Check :

catchme 0.3.1361.2 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-05-14 14:32:01
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden services & system hive …

[HKEY_LOCAL_MACHINE\SYSTEM\controlset002\control\Class\{4D36E965-E325-11CE-BFC1-08002BE10318}\Properties]
"DeviceType"=dword:00000002
"DeviceCharacteristics"=dword:00000100
[HKEY_LOCAL_MACHINE\SYSTEM\controlset002\control\Class\{4D36E967-E325-11CE-BFC1-08002BE10318}\Properties]
"DeviceType"=dword:00000007
"DeviceCharacteristics"=dword:00000100
[HKEY_LOCAL_MACHINE\SYSTEM\controlset002\control\Class\{4D36E969-E325-11CE-BFC1-08002BE10318}\Properties]
"DeviceType"=dword:00000004
"DeviceCharacteristics"=dword:00000100
[HKEY_LOCAL_MACHINE\SYSTEM\controlset002\control\Class\{4D36E96A-E325-11CE-BFC1-08002BE10318}\Properties]
"DeviceType"=dword:00000004
"DeviceCharacteristics"=dword:00000100
[HKEY_LOCAL_MACHINE\SYSTEM\controlset002\control\Class\{4D36E97B-E325-11CE-BFC1-08002BE10318}\Properties]
"DeviceType"=dword:00000004
"DeviceCharacteristics"=dword:00000100
[HKEY_LOCAL_MACHINE\SYSTEM\controlset002\control\Class\{4D36E980-E325-11CE-BFC1-08002BE10318}\Properties]
"DeviceType"=dword:00000007
"DeviceCharacteristics"=dword:00000100
[HKEY_LOCAL_MACHINE\SYSTEM\controlset002\Services\MRxDAV\EncryptedDirectories]
@=""

scanning hidden registry entries …

scanning hidden files …

scan completed successfully
hidden processes: 0
hidden services: 0
hidden files: 0


Remaining Services :




Authorized Application Key Export:

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"C:\\WINDOWS\\network diagnostic\\xpnetdiag.exe"="C:\\WINDOWS\\network diagnostic\\xpnetdiag.exe:*:Enabled:Network Diagnostic for Windows XP"
"C:\\Program Files\\Internet Explorer\\iexplore.exe"="C:\\Program Files\\Internet Explorer\\iexplore.exe:*:Enabled:Internet Explorer"
"%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\\Program Files\\MSN Messenger\\msnmsgr.exe"="C:\\Program Files\\MSN Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger 8.1"
"C:\\Program Files\\MSN Messenger\\livecall.exe"="C:\\Program Files\\MSN Messenger\\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone)"
"C:\\Program Files\\Bonjour\\mDNSResponder.exe"="C:\\Program Files\\Bonjour\\mDNSResponder.exe:*:Enabled:Bonjour"
"C:\\Program Files\\iTunes\\iTunes.exe"="C:\\Program Files\\iTunes\\iTunes.exe:*:Enabled:iTunes"
"C:\\Program Files\\AVG\\AVG8\\avgupd.exe"="C:\\Program Files\\AVG\\AVG8\\avgupd.exe:*:Enabled:avgupd.exe"
"C:\\Program Files\\AVG\\AVG8\\avgnsx.exe"="C:\\Program Files\\AVG\\AVG8\\avgnsx.exe:*:Enabled:avgnsx.exe"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\\Program Files\\MSN Messenger\\msnmsgr.exe"="C:\\Program Files\\MSN Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger 8.1"
"C:\\Program Files\\MSN Messenger\\livecall.exe"="C:\\Program Files\\MSN Messenger\\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone)"

Remaining Files :



Files with Hidden Attributes :

Tue 22 Jul 2008 2,516 A.SH. — "C:\Documents and Settings\All Users\Application Data\KGyGaAvL.sys"
Thu 7 Jun 2007 4,348 A.SH. — "C:\Documents and Settings\All Users\DRM\DRMv1.bak"
Thu 25 Dec 2008 0 A.SH. — "C:\Documents and Settings\All Users\DRM\Cache\Indiv02.tmp"
Fri 1 Oct 2004 4,348 A.SH. — "C:\My Backup – 07-05-30 0248PM\My old Documents and Settings\All Users\DRM\DRMv1.bak"
Fri 1 Oct 2004 401 A.SH. — "C:\My Backup – 07-05-30 0248PM\My old Documents and Settings\All Users\DRM\DRMv12.bak"

Finished!

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 2:52:21 PM, on 5/14/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16827)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\iS3\Anti-Spyware\SZServer.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Ahead\InCD\InCDsrv.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\System32\nvsvc32.exe
c:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\PROGRA~1\AVG\AVG8\avgnsx.exe
C:\Program Files\STOPzilla!\STOPzilla.exe
C:\Program Files\eMachines Bay Reader\shwiconem.exe
C:\PROGRA~1\AVG\AVG8\avgtray.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\YourWare Solutions\FreeRAM XP Pro\FreeRAM XP Pro.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.emachines.com/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: SITEguard BHO - {1827766B-9F49-4854-8034-F6EE26FCB1EC} - C:\Program Files\STOPzilla!\SZSG.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: STOPzilla Browser Helper Object - {E3215F20-3212-11D6-9F8B-00D0B743919D} - C:\Program Files\STOPzilla!\SZIEBHO.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: STOPzilla - {98828DED-A591-462F-83BA-D2F62A68B8B8} - C:\Program Files\STOPzilla!\SZSG.dll
O4 - HKLM\..\Run: [SunKistEM] "C:\Program Files\eMachines Bay Reader\shwiconem.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKCU\..\Run: [FreeRAM XP] "C:\Program Files\YourWare Solutions\FreeRAM XP Pro\FreeRAM XP Pro.exe" -win
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\program files\common files\is3\anti-spyware\is3lsp.dll
O10 - Unknown file in Winsock LSP: c:\program files\common files\is3\anti-spyware\is3lsp.dll
O10 - Unknown file in Winsock LSP: c:\program files\common files\is3\anti-spyware\is3lsp.dll
O10 - Unknown file in Winsock LSP: c:\program files\common files\is3\anti-spyware\is3lsp.dll
O10 - Unknown file in Winsock LSP: c:\program files\common files\is3\anti-spyware\is3lsp.dll
O10 - Unknown file in Winsock LSP: c:\program files\common files\is3\anti-spyware\is3lsp.dll
O14 - IERESET.INF: START_PAGE_URL=http://www.emachines.com
O16 - DPF: {1239CC52-59EF-4DFA-8C61-90FFA846DF7E} (Musicnotes Viewer) - http://www.musicnotes.com/download/mnviewer.cab
O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} (MySpace Uploader Control) - http://lads.myspace.com/upload/MySpaceUploader1006.cab
O16 - DPF: {56762DEC-6B0D-4AB4-A8AD-989993B5D08B} - http://www.eset.eu/OnlineScanner.cab
O16 - DPF: {5F8469B4-B055-49DD-83F7-62B522420ECC} (Facebook Photo Uploader Control) - http://upload.facebook.com/controls/Facebo…otoUploader.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftu…b?1179876639609
O16 - DPF: {9D190AE6-C81E-4039-8061-978EBAD10073} (F-Secure Online Scanner 3.0) - http://portal.gci.net/static/scanner/fscax.cab
O16 - DPF: {A8F2B9BD-A6A0-486A-9744-18920D898429} (ScorchPlugin Class) - http://www.sibelius.com/download/software/…tiveXPlugin.cab
O16 - DPF: {B1E2B96C-12FE-45E2-BEF1-44A219113CDD} (SABScanProcesses Class) - http://www.superadblocker.com/activex/sabspx.cab
O16 - DPF: {C1FDEE68-98D5-4F42-A4DD-D0BECF5077EB} (EPUImageControl Class) - http://tools.ebayimg.com/eps/wl/activex/eB…l_v1-0-27-0.cab
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: InCD Helper (InCDsrv) - AHEAD Software - C:\Program Files\Ahead\InCD\InCDsrv.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: Protexis Licensing V2 (PSI_SVC_2) - Protexis Inc. - c:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe
O23 - Service: STOPzilla Service (szserver) - iS3, Inc. - C:\Program Files\Common Files\iS3\Anti-Spyware\SZServer.exe

–

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI