This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Firefox gets re-directed and IE no longer runs

14 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

When trying use Firefox and Google search, am likely to be redirected to ad sites unless I copy and paste the exact URL into the address bar. Used to be able to use Internet Explorer for sites incompatible with Firefox, but now IE doesn't even launch. Have tried AVG, SpyBot, GooredFix, and ATF Cleaner, but without success.

Attaching Malwarebytes' Anti-Malware scan results; Here is my HiJackThis log report:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 7:10:04 PM, on 6/18/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16762)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\arservice.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\iWin Games\iWinGamesInstaller.exe
C:\Program Files\iWin Games\iWinTrusted.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\HPZIPM12.EXE
C:\WINDOWS\system32\svchost.exe
C:\PROGRA~1\AVG\AVG8\avgemc.exe
C:\WINDOWS\ehome\ehtray.exe
C:\WINDOWS\ARPWRMSG.EXE
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\eHome\ehmsas.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\WINDOWS\system32\wuauclt.exe
C:\HP\KBD\KBD.EXE
C:\PROGRA~1\AVG\AVG8\avgtray.exe
C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Registry Mechanic\RegMech.exe
C:\Program Files\Logitech\SetPoint\SetPoint.exe
C:\Program Files\Updates from HP\9972322\Program\Updates from HP.exe
C:\PROGRA~1\Webshots\Webshots.scr
C:\Program Files\Common Files\Logishrd\KHAL2\KHALMNPR.EXE
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…arm1=seconduser
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {22D8E815-4A5E-4DFB-845E-AAB64207F5BD} - (no file)
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - (no file)
O2 - BHO: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
O2 - BHO: (no name) - {B56A7D7D-6927-48C8-A975-17DF180C71AC} - (no file)
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
O4 - HKLM\..\Run: [AlwaysReady Power Message APP] ARPWRMSG.EXE
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" runtime
O4 - HKLM\..\Run: [HPHUPD08] c:\Program Files\HP\Digital Imaging\{33D6CC28-9F75-4d1b-A11D-98895B3A3729}\hphupd08.exe
O4 - HKLM\..\Run: [HPBootOp] "C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp.exe" /run
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKLM\..\Run: [Ad-Watch] C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [updateMgr] C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe AcRdB7_1_0
O4 - HKCU\..\Run: [RegistryMechanic] C:\Program Files\Registry Mechanic\RegMech.exe /H
O4 - Startup: ChkDisk.dll
O4 - Startup: Webshots.lnk = C:\Program Files\Webshots\Launcher.exe
O4 - Global Startup: Logitech SetPoint.lnk = C:\Program Files\Logitech\SetPoint\SetPoint.exe
O4 - Global Startup: Updates from HP.lnk = C:\Program Files\Updates from HP\9972322\Program\Updates from HP.exe
O4 - Global Startup: Webshots.lnk = C:\Program Files\Webshots\Launcher.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office12\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\Office12\REFIEBAR.DLL
O9 - Extra button: Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
O9 - Extra 'Tools' menuitem: Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {11260943-421B-11D0-8EAC-0000C07D88CF} -
O16 - DPF: {31E68DE2-5548-4B23-88F0-C51E6A0F695E} -
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} -
O16 - DPF: {74FFE28D-2378-11D5-990C-006094235084} -
O16 - DPF: {CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA} (Java Plug-in 1.5.0_06) -
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540022} -
O17 - HKLM\System\CCS\Services\Tcpip\..\{C915206A-CD3E-4B35-879A-57BF02D24CA6}: NameServer = 208.67.220.220,208.67.222.222
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: NameServer = 208.67.220.220,208.67.222.222
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: NameServer = 208.67.220.220,208.67.222.222
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: NameServer = 208.67.220.220,208.67.222.222
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O20 - AppInit_DLLs: avgrsstx.dll
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: AVG8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: HP Port Resolver - Hewlett-Packard Company - C:\WINDOWS\system32\spool\drivers\w32x86\3\HPBPRO.EXE
O23 - Service: HP Status Server - Hewlett-Packard Company - C:\WINDOWS\system32\spool\drivers\w32x86\3\HPBOID.EXE
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: iWinGamesInstaller - iWin Inc. - C:\Program Files\iWin Games\iWinGamesInstaller.exe
O23 - Service: iWinTrusted - iWin Inc. - C:\Program Files\iWin Games\iWinTrusted.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: Lavasoft Ad-Aware Service - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
O23 - Service: Logitech Bluetooth Service (LBTServ) - Logitech, Inc. - C:\Program Files\Common Files\Logishrd\Bluetooth\LBTServ.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\HPZIPM12.EXE
O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\pctsAuxs.exe
O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\pctsSvc.exe

–
End of file - 9221 bytes

📎mbam_log_2009_06_18__18_56_40_.txt
Hi,

Please download DDS and save it to your desktop.
  • Disable any script blocking protection
  • Double click dds.scr to run the tool.
  • When done two logs should open:
  • DDS.txt
  • Attach.txt
  • Save both reports to your desktop.
—————————————————
  • Post the contents of the DDS.txt report in your next reply
  • Attach the Attach.txt report to your post by scrolling down to the Attachments area and then clicking Browse. Browse to where you saved the file, and click Open and then click UPLOAD.
Thank you for your help! Here are the DDS reports: DDS (Ver_09-05-14.01) - NTFSx86 Run by [removed] at 6:11:49.39 on Fri 06/19/2009 Internet Explorer: 7.0.5730.13 BrowserJavaVersion: 1.6.0_14 Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1022.385 [GMT -5:00] AV: AVG Anti-Virus Free *On-access scanning enabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF} ============== Running Processes =============== C:\WINDOWS\system32\Ati2evxx.exe C:\WINDOWS\system32\svchost -k DcomLaunch svchost.exe C:\WINDOWS\System32\svchost.exe -k netsvcs svchost.exe svchost.exe C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\system32\Ati2evxx.exe C:\WINDOWS\Explorer.EXE svchost.exe C:\WINDOWS\ehome\ehtray.exe C:\WINDOWS\arservice.exe C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe C:\WINDOWS\ARPWRMSG.EXE C:\WINDOWS\eHome\ehRecvr.exe C:\WINDOWS\eHome\ehSched.exe C:\Program Files\iWin Games\iWinGamesInstaller.exe C:\Program Files\iWin Games\iWinTrusted.exe C:\Program Files\Java\jre6\bin\jqs.exe C:\PROGRA~1\AVG\AVG8\avgrsx.exe C:\Program Files\Common Files\LightScribe\LSSrvc.exe C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE C:\WINDOWS\RTHDCPL.EXE C:\Program Files\ATI Technologies\ATI.ACE\cli.exe C:\Program Files\HP\HP Software Update\HPWuSchd2.exe svchost.exe C:\WINDOWS\system32\svchost.exe -k imgsvc C:\PROGRA~1\AVG\AVG8\avgemc.exe C:\HP\KBD\KBD.EXE C:\PROGRA~1\AVG\AVG8\avgtray.exe C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe C:\Program Files\Java\jre6\bin\jusched.exe C:\WINDOWS\system32\ctfmon.exe C:\Program Files\Registry Mechanic\RegMech.exe C:\Program Files\Logitech\SetPoint\SetPoint.exe C:\Program Files\Updates from HP\9972322\Program\Updates from HP.exe C:\PROGRA~1\Webshots\Webshots.scr C:\WINDOWS\eHome\ehmsas.exe C:\WINDOWS\system32\dllhost.exe C:\Program Files\Common Files\Logishrd\KHAL2\KHALMNPR.EXE c:\windows\system\hpsysdrv.exe C:\Program Files\Mozilla Firefox\firefox.exe C:\Documents and Settings\Administrator\Desktop\dds.scr ============== Pseudo HJT Report =============== uSearch Page = hxxp://www.google.com uSearch Bar = hxxp://www.google.com/ie uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8 mSearch Bar = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q405&bd=pavilion&pf=desktop&parm1=seconduser uSearchURL,(Default) = hxxp://www.google.com/keyword/%s mSearchAssistant = hxxp://www.google.com/ie BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\adobe\acrobat 7.0\activex\AcroIEHelper.dll BHO: {22D8E815-4A5E-4DFB-845E-AAB64207F5BD} - No File BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - c:\program files\avg\avg8\avgssie.dll BHO: : {53707962-6f74-2d53-2644-206d7942484f} - c:\progra~1\spybot~1\SDHelper.dll BHO: {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - No File BHO: AVG Security Toolbar: {a057a204-bacc-4d26-9990-79a187e2698e} - c:\progra~1\avg\avg8\AVGTOO~1.DLL BHO: {B56A7D7D-6927-48C8-A975-17DF180C71AC} - No File BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll TB: AVG Security Toolbar: {a057a204-bacc-4d26-9990-79a187e2698e} - c:\progra~1\avg\avg8\AVGTOO~1.DLL uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe uRun: [updateMgr] c:\program files\adobe\acrobat 7.0\reader\AdobeUpdateManager.exe AcRdB7_1_0 uRun: [RegistryMechanic] c:\program files\registry mechanic\RegMech.exe /H mRun: [ehTray] c:\windows\ehome\ehtray.exe mRun: [AlwaysReady Power Message APP] ARPWRMSG.EXE mRun: [RTHDCPL] RTHDCPL.EXE mRun: [ATICCC] "c:\program files\ati technologies\ati.ace\cli.exe" runtime mRun: [HPHUPD08] c:\program files\hp\digital imaging\{33d6cc28-9f75-4d1b-a11d-98895b3a3729}\hphupd08.exe mRun: [PCDrProfiler] mRun: [HPBootOp] "c:\program files\hewlett-packard\hp boot optimizer\HPBootOp.exe" /run mRun: [HP Software Update] c:\program files\hp\hp software update\HPWuSchd2.exe mRun: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE mRun: [TkBellExe] "c:\program files\common files\real\update_ob\realsched.exe" -osboot mRun: [KBD] c:\hp\kbd\KBD.EXE mRun: [AVG8_TRAY] c:\progra~1\avg\avg8\avgtray.exe mRun: [Ad-Watch] c:\program files\lavasoft\ad-aware\AAWTray.exe mRun: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe" StartupFolder: c:\docume~1\admini~1\startm~1\programs\startup\webshots.lnk - c:\program files\webshots\Launcher.exe StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\logite~1.lnk - c:\program files\logitech\setpoint\SetPoint.exe StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\update~1.lnk - c:\program files\updates from hp\9972322\program\Updates from HP.exe StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\webshots.lnk - c:\program files\webshots\Launcher.exe IE: E&xport to Microsoft Excel - c:\progra~1\micros~4\office12\EXCEL.EXE/3000 IE: {E2D4D26B-0180-43a4-B05F-462D6D54C789} - c:\windows\pchealth\helpctr\vendors\cn=hewlett-packard,l=cupertino,s=ca,c=us\iebutton\support.htm IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~4\office12\REFIEBAR.DLL DPF: {11260943-421B-11D0-8EAC-0000C07D88CF} DPF: {31E68DE2-5548-4B23-88F0-C51E6A0F695E} DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} DPF: {74FFE28D-2378-11D5-990C-006094235084} DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_14-windows-i586.cab DPF: {CAFEEFAC-0015-0000-0000-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0-windows-i586.cab DPF: {CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA} DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_05-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0014-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_14-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_14-windows-i586.cab DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab DPF: {D27CDB6E-AE6D-11CF-96B8-444553540022} DPF: {DE22A7AB-A739-4C58-AD52-21F9CD6306B7} - hxxp://download.microsoft.com/download/7/E/6/7E6A8567-DFE4-4624-87C3-163549BE2704/clearadj.cab TCP: NameServer = 208.67.220.220,208.67.222.222 TCP: {C915206A-CD3E-4B35-879A-57BF02D24CA6} = 208.67.220.220,208.67.222.222 Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - c:\program files\avg\avg8\avgpp.dll Notify: AtiExtEvent - Ati2evxx.dll Notify: LBTWlgn - c:\program files\common files\logishrd\bluetooth\LBTWlgn.dll AppInit_DLLs: avgrsstx.dll SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll ================= FIREFOX =================== FF - ProfilePath - c:\docume~1\admini~1\applic~1\mozilla\firefox\profiles\4ez0bllk.default user\ FF - prefs.js: browser.startup.homepage - hxxp://www.netscape.com/ FF - component: c:\program files\avg\avg8\firefox\components\avgssff.dll FF - component: c:\program files\avg\avg8\toolbarff\components\vmAVGConnector.dll FF - plugin: c:\documents and settings\administrator\application data\mozilla\firefox\profiles\4ez0bllk.default user\extensions\[removed]\platform\winnt_x86-msvc\plugins\npmnqmp07074039.dll FF - plugin: c:\program files\mozilla firefox\plugins\NpIpx32.dll FF - plugin: c:\program files\mozilla firefox\plugins\npmozax.dll —- FIREFOX POLICIES —- FF - user.js: yahoo.homepage.dontask - truec:\program files\mozilla firefox\defaults\pref\activex.js - pref("capability.policy.default.ClassID.CIDFE0BD779-44EE-4A4B-AA2E-743C63F2E5E6", "AllAccess"); c:\program files\mozilla firefox\defaults\pref\activex.js - pref("capability.policy.default.ClassID.CIDFE0BD779-44EE-4A4B-AA2E-743C63F2E5E6", "AllAccess"); c:\program files\mozilla firefox\defaults\pref\activex.js - pref("capability.policy.default.ClassID.CIDFE0BD779-44EE-4A4B-AA2E-743C63F2E5E6", "AllAccess"); ============= SERVICES / DRIVERS =============== R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [2009-6-14 64160] R1 AvgLdx86;AVG AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [2008-6-16 97928] R1 AvgMfx86;AVG On-access Scanner Minifilter Driver x86;c:\windows\system32\drivers\avgmfx86.sys [2008-4-17 26824] R2 avg8emc;AVG8 E-mail Scanner;c:\progra~1\avg\avg8\avgemc.exe [2008-7-3 875288] R2 avg8wd;AVG8 WatchDog;c:\progra~1\avg\avg8\avgwdsvc.exe [2008-7-3 231704] R2 AvgTdiX;AVG8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [2008-6-16 76040] R2 iWinGamesInstaller;iWinGamesInstaller;c:\program files\iwin games\iWinGamesInstaller.exe [2008-9-9 78104] R2 iWinTrusted;iWinTrusted;c:\program files\iwin games\iWinTrusted.exe [2009-1-16 78104] R2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\lavasoft\ad-aware\AAWService.exe [2009-3-9 951632] R2 McrdSvc;Media Center Extender Service;c:\windows\ehome\mcrdsvc.exe [2005-8-5 99328] S3 IKFileSec;File Security Driver;c:\windows\system32\drivers\ikfilesec.sys [2009-2-13 40840] S3 IKSysFlt;System Filter Driver;c:\windows\system32\drivers\iksysflt.sys [2009-2-13 66952] S3 IKSysSec;System Security Driver;c:\windows\system32\drivers\iksyssec.sys [2009-2-13 81288] S3 sdAuxService;PC Tools Auxiliary Service;c:\program files\spyware doctor\pctsAuxs.exe [2009-2-13 356920] S3 sdCoreService;PC Tools Security Service;c:\program files\spyware doctor\pctsSvc.exe [2009-2-13 1079176] =============== Created Last 30 ================ 2009-06-18 22:08 284,160 ——– c:\windows\system32\dllcache\pdh.dll 2009-06-18 22:08 473,600 ——– c:\windows\system32\dllcache\fastprox.dll 2009-06-18 22:08 401,408 ——– c:\windows\system32\dllcache\rpcss.dll 2009-06-18 22:08 227,840 ——– c:\windows\system32\dllcache\wmiprvse.exe 2009-06-18 22:08 110,592 ——– c:\windows\system32\dllcache\services.exe 2009-06-18 22:08 729,088 ——– c:\windows\system32\dllcache\lsasrv.dll 2009-06-18 22:08 714,752 ——– c:\windows\system32\dllcache\ntdll.dll 2009-06-18 22:08 617,472 ——– c:\windows\system32\dllcache\advapi32.dll 2009-06-18 22:08 453,120 ——– c:\windows\system32\dllcache\wmiprvsd.dll 2009-06-18 22:05 1,203,922 ——– c:\windows\system32\dllcache\sysmain.sdb 2009-06-18 22:05 2,560 ——– c:\windows\system32\xpsp4res.dll 2009-06-18 22:05 215,552 ——– c:\windows\system32\dllcache\wordpad.exe 2009-06-18 18:43 –d—– c:\docume~1\admini~1\applic~1\Malwarebytes 2009-06-18 18:43 38,160 a——- c:\windows\system32\drivers\mbamswissarmy.sys 2009-06-18 18:43 19,096 a——- c:\windows\system32\drivers\mbam.sys 2009-06-18 18:43 –d—– c:\program files\Malwarebytes' Anti-Malware 2009-06-18 18:43 –d—– c:\docume~1\alluse~1\applic~1\Malwarebytes 2009-06-16 23:52 –d—– c:\program files\Trend Micro 2009-06-14 18:39 15,688 a——- c:\windows\system32\lsdelete.exe 2009-06-14 17:31 64,160 a——- c:\windows\system32\drivers\Lbd.sys 2009-06-14 17:31 -cd-h— c:\docume~1\alluse~1\applic~1\{7972B2E5-3E09-4E5E-81B7-FE5819D6772F} 2009-05-31 22:04 –d—– c:\docume~1\alluse~1\applic~1\Big Fish Games Vancouver 2009-05-31 22:03 –d—– c:\program files\Unwell Mel 2009-05-31 22:02 –d—– c:\program files\bfgclient 2009-05-31 22:01 –d—– c:\docume~1\alluse~1\applic~1\BigFishGamesCache 2009-05-27 07:06 –d-h— c:\windows\system32\GroupPolicy ==================== Find3M ==================== 2009-05-21 11:33 410,984 a——- c:\windows\system32\deploytk.dll 2009-05-07 10:32 345,600 a——- c:\windows\system32\localspl.dll 2009-05-07 10:32 345,600 ——– c:\windows\system32\dllcache\localspl.dll 2009-04-28 23:56 827,392 a——- c:\windows\system32\wininet.dll 2009-04-28 23:56 827,392 a——- c:\windows\system32\dllcache\wininet.dll 2009-04-28 23:56 233,472 a——- c:\windows\system32\dllcache\webcheck.dll 2009-04-28 23:56 1,159,680 a——- c:\windows\system32\dllcache\urlmon.dll 2009-04-28 23:56 671,232 a——- c:\windows\system32\dllcache\mstime.dll 2009-04-28 23:56 105,984 a——- c:\windows\system32\dllcache\url.dll 2009-04-28 23:56 102,912 a——- c:\windows\system32\dllcache\occache.dll 2009-04-28 23:56 44,544 a——- c:\windows\system32\dllcache\pngfilt.dll 2009-04-28 23:56 3,596,288 a——- c:\windows\system32\dllcache\mshtml.dll 2009-04-28 23:56 477,696 a——- c:\windows\system32\dllcache\mshtmled.dll 2009-04-28 23:56 193,024 a——- c:\windows\system32\dllcache\msrating.dll 2009-04-28 04:05 70,656 a——- c:\windows\system32\dllcache\ie4uinit.exe 2009-04-28 04:05 13,824 ——– c:\windows\system32\dllcache\ieudinit.exe 2009-04-25 00:27 636,088 a——- c:\windows\system32\dllcache\iexplore.exe 2009-04-25 00:26 161,792 a——- c:\windows\system32\dllcache\ieakui.dll 2009-04-17 07:26 1,847,168 a——- c:\windows\system32\win32k.sys 2009-04-17 07:26 1,847,168 ——– c:\windows\system32\dllcache\win32k.sys 2009-04-15 09:51 585,216 a——- c:\windows\system32\rpcrt4.dll 2009-04-15 09:51 585,216 ——– c:\windows\system32\dllcache\rpcrt4.dll 2009-03-21 09:06 989,696 ——– c:\windows\system32\dllcache\kernel32.dll 2005-10-17 20:36 32 a——- c:\documents and settings\all users\hash.dat 2005-01-25 15:47 45,200 a——- c:\docume~1\alluse~1\applic~1\GDIPFONTCACHEV1.DAT ============= FINISH: 6:12:46.56 =============== 📎Attach.txt
Hi,

Nothing but a few orphans showing there, let's look elsewhere.

Please download SystemLook from one of the links below and save it to your Desktop.
Download Mirror #1
Download Mirror #2

  • Double-click SystemLook.exe to run it.
  • Copy the content of the following codebox into the main textfield:
    :reg
    HKLM\Software\Microsoft\Windows NT\CurrentVersion\drivers32
  • Click the Look button to start the scan.
  • When finished, a notepad window will open with the results of the scan. Please post this log in your next reply.
Note: The log can also be found on your Desktop entitled SystemLook.txt


Download the GMER Rootkit Scanner. Unzip it to your Desktop.

Before scanning, make sure all other running programs are closed and no other actions like a scheduled antivirus scan will occur while the scan is being performed. Do not use your computer for anything else during the scan.

Right-click gmer.exe and select Run As Administrator. The program will begin to run.

**Caution**
These types of scans can produce false positives. Do NOT take any action on any
"<— ROOKIT" entries unless advised!

If possible rootkit activity is found, you will be asked if you would like to perform a full scan.
  • Click NO
  • In the right panel, you will see a bunch of boxes that have been checked … leave everything checked and ensure the Show all box is un-checked.
  • Now click the Scan button.
    Once the scan is complete, you may receive another notice about rootkit activity.
  • Click OK.
  • GMER will produce a log. Click on the [Save..] button, and in the File name area, type in "GMER.txt"
  • Save it where you can easily find it, such as your desktop.
Post the contents of GMER.txt in your next reply.
When I ran the GMER, it found a possible rootkit and I answered No as instructed. Unfortunately, after waiting 5 hours for the scan to finish, it popped up a message saying that it could save the data and prompted me to try to save it elsewhere. But I had no interactive control of the computer and ended up having to reboot. I'm setting the GMER to scan again, but in the meantime here's the SystemLook report: SystemLook v1.0 by jpshortstuff (22.05.09) Log created at 07:57 on 19/06/2009 by Administrator (Administrator - Elevation successful) ========== reg ========== [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\drivers32] "aux"="wdmaud.drv" "midi"="wdmaud.drv" "midimapper"="midimap.dll" "mixer"="wdmaud.drv" "msacm.iac2"="C:\WINDOWS\system32\iac25_32.ax" "msacm.imaadpcm"="imaadp32.acm" "msacm.l3acm"="C:\WINDOWS\system32\l3codeca.acm" "msacm.msadpcm"="msadp32.acm" "msacm.msaudio1"="msaud32.acm" "msacm.msg711"="msg711.acm" "msacm.msg723"="msg723.acm" "msacm.msgsm610"="msgsm32.acm" "msacm.sl_anet"="sl_anet.acm" "msacm.trspch"="tssoft32.acm" "MSVideo8"="VfWWDM32.dll" "vidc.cvid"="iccvid.dll" "VIDC.I420"="msh263.drv" "vidc.iv31"="ir32_32.dll" "vidc.iv32"="ir32_32.dll" "vidc.iv41"="ir41_32.ax" "vidc.iv50"="ir50_32.dll" "VIDC.IYUV"="iyuv_32.dll" "vidc.LEAD"="LCODCCMP.DLL" "vidc.M261"="msh261.drv" "vidc.M263"="msh263.drv" "vidc.mrle"="msrle32.dll" "vidc.msvc"="msvidc32.dll" "VIDC.UYVY"="msyuv.dll" "VIDC.YUY2"="msyuv.dll" "VIDC.YVU9"="tsbyuv.dll" "VIDC.YVYU"="msyuv.dll" "wave"="wdmaud.drv" "wavemapper"="msacm32.drv" [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\drivers32\Terminal Server] -=End Of File=-
Nothing bad showing there. There's no way GMER should take 5 hours. Try this scan instead if it doesn't work the second time:

Please download RootRepeal to your desktop
  • Unzip it to it's own folder, close all other programs especially your security programs (anti-spyware, anti-virus, and firewall) and run RootRepeal.exe
  • Click the Report tab at the bottom and then the Scan button.
  • A box will pop up, check the boxes beside Drivers, Files, Processes and click OK.
  • Another box will open, check the boxes beside all the drives, eg : C:\, then click OK.
  • The scan will take a little while to run, so let it go unhindered.
  • Once it is done, click the Save Report button, call it RepealScan and save the log to your desktop. Post that log here in your reply
GMER scan may have finished this time - not sure because had 3 messages on the screen at end run. At least this time I still had control of the mouse.
The three messages were: (in order of layers, with #1 on top)
1. Windows was unable to save all the data for the file \Device\HarddiskVolume2\Windows\Assembly\GAC_32
2. Updates from HP.exe Application Error

The instruction at "0x00933dad" referenced memory @ "0x00000020". The memory could not be "read". Click on OK to terminate. Click on Cancel to debug the program.

3. GMER Warning!!! GMER has found system modification caused by Rootkit activity.

Here's the GMER log: (I'm also attaching the log as a .txt file)

GMER 1.0.15.14972 - http://www.gmer.net
Rootkit scan 2009-06-19 20:31:48
Windows 5.1.2600 Service Pack 3


—- System - GMER 1.0.15 —-

SSDT Lbd.sys (Boot Driver/Lavasoft AB) ZwCreateKey [0xF762087E]
SSDT Lbd.sys (Boot Driver/Lavasoft AB) ZwSetValueKey [0xF7620C10]

—- Kernel code sections - GMER 1.0.15 —-

.text ntkrnlpa.exe!ZwCallbackReturn + 2C68 80504504 2 Bytes [7E, 08] {JLE 0xa}
.text ntkrnlpa.exe!ZwCallbackReturn + 2FA0 8050483C 2 Bytes [10, 0C]

—- Devices - GMER 1.0.15 —-

Device \Driver\Tcpip \Device\Ip avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)

AttachedDevice \Driver\Kbdclass \Device\KeyboardClass0 arkbcfltr.sys (Microsoft AR PS/2 Keyboard Filter Driver (Beta 2 Release 2)/Microsoft Corporation)
AttachedDevice \Driver\Kbdclass \Device\KeyboardClass1 arkbcfltr.sys (Microsoft AR PS/2 Keyboard Filter Driver (Beta 2 Release 2)/Microsoft Corporation)

Device \Driver\Tcpip \Device\Tcp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)

AttachedDevice \Driver\Tcpip \Device\Tcp Lbd.sys (Boot Driver/Lavasoft AB)

Device \Driver\Tcpip \Device\Udp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
Device \Driver\Tcpip \Device\RawIp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
Device \Driver\Tcpip \Device\IPMULTICAST avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)

AttachedDevice \FileSystem\Fastfat \Fat fltmgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)

—- Services - GMER 1.0.15 —-

Service system32\drivers\gaopdxkqewftmn.sys (*** hidden *** ) [SYSTEM] gaopdxserv.sys <– ROOTKIT !!!

—- Registry - GMER 1.0.15 —-

Reg HKLM\SYSTEM\CurrentControlSet\Services\gaopdxserv.sys@start 1
Reg HKLM\SYSTEM\CurrentControlSet\Services\gaopdxserv.sys@type 1
Reg HKLM\SYSTEM\CurrentControlSet\Services\gaopdxserv.sys@imagepath \systemroot\system32\drivers\gaopdxkqewftmn.sys
Reg HKLM\SYSTEM\CurrentControlSet\Services\gaopdxserv.sys@group file system
Reg HKLM\SYSTEM\CurrentControlSet\Services\gaopdxserv.sys\modules
Reg HKLM\SYSTEM\CurrentControlSet\Services\gaopdxserv.sys\modules@gaopdxserv \\?\globalroot\systemroot\system32\drivers\gaopdxkqewftmn.sys
Reg HKLM\SYSTEM\CurrentControlSet\Services\gaopdxserv.sys\modules@gaopdxl \\?\globalroot\systemroot\system32\gaopdxsaafodtq.dll
Reg HKLM\SYSTEM\ControlSet002\Services\gaopdxserv.sys@start 1
Reg HKLM\SYSTEM\ControlSet002\Services\gaopdxserv.sys@type 1
Reg HKLM\SYSTEM\ControlSet002\Services\gaopdxserv.sys@imagepath \systemroot\system32\drivers\gaopdxkqewftmn.sys
Reg HKLM\SYSTEM\ControlSet002\Services\gaopdxserv.sys@group file system
Reg HKLM\SYSTEM\ControlSet002\Services\gaopdxserv.sys\modules
Reg HKLM\SYSTEM\ControlSet002\Services\gaopdxserv.sys\modules@gaopdxserv \\?\globalroot\systemroot\system32\drivers\gaopdxkqewftmn.sys
Reg HKLM\SYSTEM\ControlSet002\Services\gaopdxserv.sys\modules@gaopdxl \\?\globalroot\systemroot\system32\gaopdxsaafodtq.dll
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{5EB1534C-89A8-4110-9C46-2F24EE5CFD34}
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{5EB1534C-89A8-4110-9C46-2F24EE5CFD34}@abigkhnjnnemgmhgnedojmjjjebgaiolmo 0x61 0x61 0x00 0x00
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{5EB1534C-89A8-4110-9C46-2F24EE5CFD34}@bbigkhnjnnemgmhgnekoikojikjepdagcbdk 0x61 0x61 0x00 0x00

—- EOF - GMER 1.0.15 —-

📎GMER_log.txt
Sorry, looks like I overlooked your last request. Here's the RepealScan report: ROOTREPEAL © AD, 2007-2008 ================================================== Scan Time: 2009/06/19 21:19 Program Version: Version 1.1.2.0 Windows Version: Windows XP Media Center Edition SP3 ================================================== Drivers ——————- Name: dump_atapi.sys Image Path: C:\WINDOWS\System32\Drivers\dump_atapi.sys Address: 0xED2C1000 Size: 98304 File Visible: No Status: - Name: dump_WMILIB.SYS Image Path: C:\WINDOWS\System32\Drivers\dump_WMILIB.SYS Address: 0xF7B4A000 Size: 8192 File Visible: No Status: - Name: RootRepeal.sys Image Path: C:\WINDOWS\system32\drivers\RootRepeal.sys Address: 0xBAB32000 Size: 40960 File Visible: No Status: - Hidden/Locked Files ——————- Path: C:\hiberfil.sys Status: Locked to the Windows API! Path: C:\Documents and Settings\Administrator\Local Settings\Temp\Perflib_Perfdata_178.dat Status: Allocation size mismatch (API: 16384, Raw: 0) Path: C:\Documents and Settings\Administrator\Local Settings\Temp\Perflib_Perfdata_1cc.dat Status: Allocation size mismatch (API: 16384, Raw: 0) Path: C:\Documents and Settings\Administrator\Local Settings\Temp\Perflib_Perfdata_954.dat Status: Allocation size mismatch (API: 16384, Raw: 0) Path: C:\Documents and Settings\Administrator\Local Settings\Temp\etilqs_Lhi4wXZdyg9NPKFBIXaO Status: Allocation size mismatch (API: 32768, Raw: 0) Path: C:\WINDOWS\assembly\GAC_32\System.EnterpriseServices\2.0.0.0__b03f5f7f11d50a3a Status: Locked to the Windows API! Path: C:\Documents and Settings\Old_Owner\Local Settings\Temporary Internet Files\Content.IE5\1WKZ1HWH\domain=orbitz&channel=air&Section=results&adsize=hotwireBottom&origin=DFW&dest=CID&OrbitzCookieName=OSC&orbitzID=AQ1VeCyryI!698302125!171067201!7001!-1!1087[1].ÁŽõw Status: Locked to the Windows API! Path: C:\Documents and Settings\Old_Owner\Local Settings\Temporary Internet Files\Content.IE5\1WKZ1HWH\domain=orbitz&channel=air&Section=results&adsize=hotwireBottom&origin=DFW&dest=CID&OrbitzCookieName=OSC&orbitzID=AQ1VeCyryI!698302125!171067201!7001!-1!1087[2].ÁŽõw Status: Locked to the Windows API! Path: C:\Documents and Settings\Old_Owner\Local Settings\Temporary Internet Files\Content.IE5\1WKZ1HWH\domain=orbitz&channel=air&Section=results&adsize=hotwireTop&origin=DFW&dest=CID&OrbitzCookieName=OSC&orbitzID=AQ1VeCyryI!698302125!171067201!7001!-1!1087438[1].ÁŽõw Status: Locked to the Windows API! Path: C:\Documents and Settings\Old_Owner\Local Settings\Temporary Internet Files\Content.IE5\1WKZ1HWH\domain=orbitz&channel=air&Section=results&adsize=1x1&origin=DFW&dest=CID&OrbitzCookieName=OSC&OrbitzID=AQ1VeCyryI!698302125!171067201!7001!-1!1087438805657[1].ÁŽõw Status: Locked to the Windows API! Path: C:\Documents and Settings\Old_Owner\Local Settings\Temporary Internet Files\Content.IE5\4B9JIEJ5\domain=orbitz&channel=air&Section=exitApp&adsize=430x55&origin=CID&dest=DFW&OrbitzCookieName=OSC&orbitzID=APwzGWkU9N!1280186485!171067259!7001!-1!1087336691[1].ÁŽõw Status: Locked to the Windows API! Path: C:\Documents and Settings\Old_Owner\Local Settings\Temporary Internet Files\Content.IE5\4B9JIEJ5\domain=orbitz&channel=air&Section=results&adsize=1x1&origin=CID&dest=DFW&OrbitzCookieName=OSC&OrbitzID=AOuCdvDIMp!1280186485!171067259!7001!-1!1087303362221[1].html Status: Locked to the Windows API! Path: C:\Documents and Settings\Old_Owner\Local Settings\Temporary Internet Files\Content.IE5\4B9JIEJ5\domain=orbitz&channel=air&Section=results&adsize=299x42&origin=CID&dest=DFW&OrbitzCookieName=OSC&OrbitzID=AOuCdvDIMp!1280186485!171067259!7001!-1!1087303362[1].ÁŽõw Status: Locked to the Windows API! Path: C:\Documents and Settings\Old_Owner\Local Settings\Temporary Internet Files\Content.IE5\4B9JIEJ5\domain=orbitz&channel=air&Section=results&adsize=hotwireBottom&origin=CID&dest=DFW&OrbitzCookieName=OSC&orbitzID=AOuCdvDIMp!1280186485!171067259!7001!-1!108[1].ÁŽõw Status: Locked to the Windows API! Path: C:\Documents and Settings\Old_Owner\Local Settings\Temporary Internet Files\Content.IE5\4B9JIEJ5\domain=orbitz&channel=air&Section=results&adsize=hotwireBottom&origin=CID&dest=DFW&OrbitzCookieName=OSC&orbitzID=APwzGWkU9N!1280186485!171067259!7001!-1!108[1].ÁŽõw Status: Locked to the Windows API! Path: C:\Documents and Settings\Old_Owner\Local Settings\Temporary Internet Files\Content.IE5\4B9JIEJ5\domain=orbitz&channel=air&Section=results&adsize=hotwireTop&origin=CID&dest=DFW&OrbitzCookieName=OSC&orbitzID=AOuCdvDIMp!1280186485!171067259!7001!-1!108730[1].ÁŽõw Status: Locked to the Windows API! Path: C:\Documents and Settings\Old_Owner\Local Settings\Temporary Internet Files\Content.IE5\4B9JIEJ5\domain=orbitz&channel=air&Section=results&adsize=hotwireTop&origin=CID&dest=DFW&OrbitzCookieName=OSC&orbitzID=APwzGWkU9N!1280186485!171067259!7001!-1!108733[1].ÁŽõw Status: Locked to the Windows API! Path: C:\Documents and Settings\Old_Owner\Local Settings\Temporary Internet Files\Content.IE5\4B9JIEJ5\domain=orbitz&channel=air&Section=results&adsize=299x42&origin=CID&dest=DFW&OrbitzCookieName=OSC&OrbitzID=APwzGWkU9N!1280186485!171067259!7001!-1!1087336691[1].ÁŽõw Status: Locked to the Windows API! Path: C:\Documents and Settings\Old_Owner\Local Settings\Temporary Internet Files\Content.IE5\4XIJW92J\domain=orbitz&channel=air&Section=main&adsize=342x188&origin=CID&dest=MLB&homeCityCode=CID&OrbitzCookieName=OSC&orbitzID=BQRGJcGkNj!669641983!171067181!7001[1].html Status: Locked to the Windows API! Path: C:\Documents and Settings\Old_Owner\Local Settings\Temporary Internet Files\Content.IE5\4XIJW92J\domain=orbitz&channel=air&Section=interstitial&adsize=450x200&origin=CID&dest=MLB&homeCityCode=CID&OrbitzCookieName=OSC&orbitzID=BQRGJcGkNj!669641983!17106718[1].js Status: Locked to the Windows API! Path: C:\Documents and Settings\Old_Owner\Local Settings\Temporary Internet Files\Content.IE5\4XIJW92J\domain=orbitz&channel=air&Section=main&adsize=1x1&origin=CID&dest=MLB&homeCityCode=CID&OrbitzCookieName=OSC&orbitzID=BQRGJcGkNj!669641983!171067181!7001!-1![1].html Status: Locked to the Windows API! Path: C:\Documents and Settings\Old_Owner\Local Settings\Temporary Internet Files\Content.IE5\4XIJW92J\domain=orbitz&channel=air&Section=main&adsize=hometext1&origin=CID&dest=MLB&homeCityCode=CID&OrbitzCookieName=OSC&orbitzID=BQRGJcGkNj!669641983!171067181!70[1].html Status: Locked to the Windows API! Path: C:\Documents and Settings\Old_Owner\Local Settings\Temporary Internet Files\Content.IE5\4XIJW92J\transactionID=88486270&apg=4068&site=webmd&dom=my%2Ewebmd%2Ecom&brand=mywebmd&uri=%2Fcontent%2Farticle%2F95%2F103133%2Ehtm&pos=top&adsize=728x90&adsize=468x60[1].js Status: Locked to the Windows API! Path: C:\Documents and Settings\Old_Owner\Local Settings\Temporary Internet Files\Content.IE5\4XIJW92J\transactionID=54649470&apg=1675&site=AOL_Netscape&brand=netscape_webcenter&to=1675&uri=%2Fcontent%2Farticle%2F83%2F97705%2Ehtm&pos=middle&adsize=300x250&adsiz[1].js Status: Locked to the Windows API! Path: C:\Documents and Settings\Old_Owner\Local Settings\Temporary Internet Files\Content.IE5\4XIJW92J\transactionID=54649470&apg=1675&site=AOL_Netscape&brand=netscape_webcenter&to=1675&uri=%2Fcontent%2Farticle%2F83%2F97705%2Ehtm&pos=top&adsize=728x90&adsize=46[1].js Status: Locked to the Windows API! Path: C:\Documents and Settings\Old_Owner\Local Settings\Temporary Internet Files\Content.IE5\4XIJW92J\transactionID=88486270&apg=4068&site=webmd&dom=my%2Ewebmd%2Ecom&brand=mywebmd&uri=%2Fcontent%2Farticle%2F95%2F103133%2Ehtm&pos=middle&adsize=300x250&adsize=33[1].js Status: Locked to the Windows API! Path: C:\Documents and Settings\Old_Owner\Local Settings\Temporary Internet Files\Content.IE5\4XIJW92J\transactionID=92147944&apg=4068&site=webmd&dom=my%2Ewebmd%2Ecom&brand=mywebmd&uri=%2Fcontent%2Farticle%2F95%2F103133%2Ehtm&pos=middle&adsize=300x250&adsize=33[1].js Status: Locked to the Windows API! Path: C:\Documents and Settings\Old_Owner\Local Settings\Temporary Internet Files\Content.IE5\4XIJW92J\transactionID=92147944&apg=4068&site=webmd&dom=my%2Ewebmd%2Ecom&brand=mywebmd&uri=%2Fcontent%2Farticle%2F95%2F103133%2Ehtm&pos=top&adsize=728x90&adsize=468x60[1].js Status: Locked to the Windows API! Path: C:\Documents and Settings\Old_Owner\Local Settings\Temporary Internet Files\Content.IE5\559AVZHI\domain=orbitz&channel=air&Section=main&adsize=1x1&origin=CID&dest=ORL&homeCityCode=CID&OrbitzCookieName=OSC&orbitzID=BRFRO83qnK!315815477!171067194!7001!-1![1].html Status: Locked to the Windows API! Path: C:\Documents and Settings\Old_Owner\Local Settings\Temporary Internet Files\Content.IE5\559AVZHI\domain=orbitz&channel=air&Section=main&adsize=342x188&origin=CID&dest=ORL&homeCityCode=CID&OrbitzCookieName=OSC&orbitzID=BRFRO83qnK!315815477!171067194!7001[1].html Status: Locked to the Windows API! Path: C:\Documents and Settings\Old_Owner\Local Settings\Temporary Internet Files\Content.IE5\559AVZHI\domain=orbitz&channel=air&Section=main&adsize=hometext1&origin=CID&dest=ORL&homeCityCode=CID&OrbitzCookieName=OSC&orbitzID=BRFRO83qnK!315815477!171067194!70[1].html Status: Locked to the Windows API! Path: C:\Documents and Settings\Old_Owner\Local Settings\Temporary Internet Files\Content.IE5\559AVZHI\domain=orbitz&channel=home&Section=main&adsize=1x1&homeCityCode=CID&OrbitzCookieName=OSC&orbitzID=BRYzdJh1QD!457631945!171067176!7001!-1!1100060723443&secur[1].html Status: Locked to the Windows API! Path: C:\Documents and Settings\Old_Owner\Local Settings\Temporary Internet Files\Content.IE5\559AVZHI\domain=orbitz&channel=home&Section=main&adsize=342x188&homeCityCode=CID&OrbitzCookieName=OSC&orbitzID=BRFRO83qnK!315815477!171067194!7001!-1!1100023185606&s[1].html Status: Locked to the Windows API! Path: C:\Documents and Settings\Old_Owner\Local Settings\Temporary Internet Files\Content.IE5\559AVZHI\domain=orbitz&channel=home&Section=main&adsize=342x188&homeCityCode=CID&OrbitzCookieName=OSC&orbitzID=BRYzdJh1QD!457631945!171067176!7001!-1!1100060723443&s[1].html Status: Locked to the Windows API! Path: C:\Documents and Settings\Old_Owner\Local Settings\Temporary Internet Files\Content.IE5\559AVZHI\domain=orbitz&channel=home&Section=main&adsize=342x40&homeCityCode=CID&OrbitzCookieName=OSC&orbitzID=BRYzdJh1QD!457631945!171067176!7001!-1!1100060723443&secu[1].js Status: Locked to the Windows API! Path: C:\Documents and Settings\Old_Owner\Local Settings\Temporary Internet Files\Content.IE5\559AVZHI\domain=orbitz&channel=home&Section=main&adsize=hometext1&homeCityCode=CID&OrbitzCookieName=OSC&orbitzID=BRFRO83qnK!315815477!171067194!7001!-1!1100023185606[1].html Status: Locked to the Windows API! Path: C:\Documents and Settings\Old_Owner\Local Settings\Temporary Internet Files\Content.IE5\559AVZHI\domain=orbitz&channel=home&Section=main&adsize=hometext1&homeCityCode=CID&OrbitzCookieName=OSC&orbitzID=BRYzdJh1QD!457631945!171067176!7001!-1!1100060723443[1].html Status: Locked to the Windows API! Path: C:\Documents and Settings\Old_Owner\Local Settings\Temporary Internet Files\Content.IE5\559AVZHI\domain=orbitz&channel=home&Section=main&adsize=hometext2&homeCityCode=CID&OrbitzCookieName=OSC&orbitzID=BRFRO83qnK!315815477!171067194!7001!-1!1100023185606[1].html Status: Locked to the Windows API! Path: C:\Documents and Settings\Old_Owner\Local Settings\Temporary Internet Files\Content.IE5\559AVZHI\domain=orbitz&channel=home&Section=main&adsize=hometext3&homeCityCode=CID&OrbitzCookieName=OSC&orbitzID=BRFRO83qnK!315815477!171067194!7001!-1!1100023185606[1].html Status: Locked to the Windows API! Path: C:\Documents and Settings\Old_Owner\Local Settings\Temporary Internet Files\Content.IE5\559AVZHI\domain=orbitz&channel=home&Section=main&adsize=hometext3&homeCityCode=CID&OrbitzCookieName=OSC&orbitzID=BRYzdJh1QD!457631945!171067176!7001!-1!1100060723443[1].html Status: Locked to the Windows API! Path: C:\Documents and Settings\Old_Owner\Local Settings\Temporary Internet Files\Content.IE5\559AVZHI\domain=orbitz&channel=home&Section=main&adsize=1x1&homeCityCode=CID&OrbitzCookieName=OSC&orbitzID=BRFRO83qnK!315815477!171067194!7001!-1!1100023185606&secur[1].html Status: Locked to the Windows API! Path: C:\Documents and Settings\Old_Owner\Local Settings\Temporary Internet Files\Content.IE5\559AVZHI\domain=orbitz&channel=home&Section=main&adsize=342x40&homeCityCode=CID&OrbitzCookieName=OSC&orbitzID=BRFRO83qnK!315815477!171067194!7001!-1!1100023185606&secu[1].js Status: Locked to the Windows API! Path: C:\Documents and Settings\Old_Owner\Local Settings\Temporary Internet Files\Content.IE5\559AVZHI\domain=orbitz&channel=home&Section=main&adsize=hometext2&homeCityCode=CID&OrbitzCookieName=OSC&orbitzID=BRYzdJh1QD!457631945!171067176!7001!-1!1100060723443[1].html Status: Locked to the Windows API! Path: C:\Documents and Settings\Old_Owner\Local Settings\Temporary Internet Files\Content.IE5\5WKBX1OH\domain=orbitz&channel=mystuff&Section=mytrips&adsize=468x60_top&homeCityCode=CID&OrbitzCookieName=OSC&orbitzID=BRYzdJh1QD!457631945!171067176!7001!-1!110006[1].html Status: Locked to the Windows API! Path: C:\Documents and Settings\Old_Owner\Local Settings\Temporary Internet Files\Content.IE5\5WKBX1OH\domain=orbitz&channel=mystuff&Section=mytrips&adsize=125x125_top&homeCityCode=CID&OrbitzCookieName=OSC&orbitzID=BRYzdJh1QD!457631945!171067176!7001!-1!11000[1].html Status: Locked to the Windows API! Path: C:\Documents and Settings\Old_Owner\Local Settings\Temporary Internet Files\Content.IE5\6LDUZQXG\domain=orbitz&channel=air&Section=interstitial&adsize=450x200&origin=DFW&dest=CID&OrbitzCookieName=OSC&orbitzID=AQ1VeCyryI!698302125!171067201!7001!-1!108743880[1] Status: Locked to the Windows API! Path: C:\Documents and Settings\Old_Owner\Local Settings\Temporary Internet Files\Content.IE5\6LDUZQXG\domain=orbitz&channel=air&Section=results&adsize=299x42&origin=CID&dest=DFW&OrbitzCookieName=OSC&OrbitzID=AOrNo6qBPQ!1280186485!171067259!7001!-1!1087302413[1].ÁŽõw Status: Locked to the Windows API! Path: C:\Documents and Settings\Old_Owner\Local Settings\Temporary Internet Files\Content.IE5\6LDUZQXG\domain=orbitz&channel=air&Section=results&adsize=hotwireBottom&origin=CID&dest=DFW&OrbitzCookieName=OSC&orbitzID=AOrNo6qBPQ!1280186485!171067259!7001!-1!108[1].ÁŽõw Status: Locked to the Windows API! Path: C:\Documents and Settings\Old_Owner\Local Settings\Temporary Internet Files\Content.IE5\6LDUZQXG\domain=orbitz&channel=air&Section=results&adsize=hotwireTop&origin=CID&dest=DFW&OrbitzCookieName=OSC&orbitzID=AOrNo6qBPQ!1280186485!171067259!7001!-1!108730[1].ÁŽõw Status: Locked to the Windows API! Path: C:\Documents and Settings\Old_Owner\Local Settings\Temporary Internet Files\Content.IE5\6LDUZQXG\domain=orbitz&channel=air&Section=results&adsize=299x42&origin=CID&dest=DFW&OrbitzCookieName=OSC&OrbitzID=AOrNo6qBPQ!1280186485!171067259!7001!-1!1087302413[2].ÁŽõw Status: Locked to the Windows API! Path: C:\Documents and Settings\Old_Owner\Local Settings\Temporary Internet Files\Content.IE5\6LDUZQXG\S10;channel=S10;id=S10;gender=0;age=0000;income=00;genderage=0_0000;ageinco me=0000_00;genderincome=0_00;user=0_0000_00;type=category;ptile=2;sz=160x600;ord= 10[1].js Status: Locked to the Windows API! Path: C:\Documents and Settings\Old_Owner\Local Settings\Temporary Internet Files\Content.IE5\8DAN4567\domain=orbitz&channel=air&Section=results&adsize=1x1&origin=CID&dest=DFW&OrbitzCookieName=OSC&OrbitzID=APwzGWkU9N!1280186485!171067259!7001!-1!1087336691494[1].ÁŽõw Status: Locked to the Windows API! Path: C:\Documents and Settings\Old_Owner\Local Settings\Temporary Internet Files\Content.IE5\8DAN4567\domain=orbitz&channel=air&Section=results&adsize=hotwireBottom&origin=CID&dest=DFW&OrbitzCookieName=OSC&orbitzID=APwzGWkU9N!1280186485!171067259!7001!-1!108[1].ÁŽõw Status: Locked to the Windows API! Path: C:\Documents and Settings\Old_Owner\Local Settings\Temporary Internet Files\Content.IE5\8DAN4567\Type%3dclick%26FlightID%3d38828%26AdID%3d67568%26TargetID%3d1389%26Segments%3d12,729,837,962,2798,5187,5193,7408%26Targets%3d9899,9209,892,1389,1204,3948%26[1].html Status: Locked to the Windows API! Path: C:\Documents and Settings\Old_Owner\Local Settings\Temporary Internet Files\Content.IE5\APXUBMHC\domain=orbitz&channel=air&Section=exitApp&adsize=430x55&origin=CID&dest=DFW&OrbitzCookieName=OSC&orbitzID=AOrNo6qBPQ!1280186485!171067259!7001!-1!1087302413[1].ÁŽõw Status: Locked to the Windows API! Path: C:\Documents and Settings\Old_Owner\Local Settings\Temporary Internet Files\Content.IE5\APXUBMHC\domain=orbitz&channel=air&Section=interstitial&adsize=450x200&origin=CID&dest=DFW&OrbitzCookieName=OSC&orbitzID=AOuCdvDIMp!1280186485!171067259!7001!-1!108730[1].js Status: Locked to the Windows API! Path: C:\Documents and Settings\Old_Owner\Local Settings\Temporary Internet Files\Content.IE5\APXUBMHC\domain=orbitz&channel=air&Section=main&adsize=342x188&origin=CID&dest=DFW&OrbitzCookieName=OSC&orbitzID=APwzGWkU9N!1280186485!171067259!7001!-1!108733669149[1].html Status: Locked to the Windows API! Path: C:\Documents and Settings\Old_Owner\Local Settings\Temporary Internet Files\Content.IE5\APXUBMHC\domain=orbitz&channel=air&Section=results&adsize=1x1&origin=CID&dest=DFW&OrbitzCookieName=OSC&OrbitzID=AOrNo6qBPQ!1280186485!171067259!7001!-1!1087302413333[1].ÁŽõw Status: Locked to the Windows API! Path: C:\Documents and Settings\Old_Owner\Local Settings\Temporary Internet Files\Content.IE5\APXUBMHC\domain=orbitz&channel=home&Section=main&adsize=342x188&homeCityCode=CID&OrbitzCookieName=OSC&orbitzID=BRYzdJh1QD!457631945!171067176!7001!-1!1100060723443&s[1].html Status: Locked to the Windows API! Path: C:\Documents and Settings\Old_Owner\Local Settings\Temporary Internet Files\Content.IE5\APXUBMHC\domain=orbitz&channel=air&Section=results&adsize=hotwireTop&origin=DFW&dest=CID&OrbitzCookieName=OSC&orbitzID=AQ1VeCyryI!698302125!171067201!7001!-1!1087438[1].ÁŽõw Status: Locked to the Windows API! Path: C:\Documents and Settings\Old_Owner\Local Settings\Temporary Internet Files\Content.IE5\APXUBMHC\domain=orbitz&channel=deals&Section=main&adsize=468x60_top&origin=CID&dest=DFW&OrbitzCookieName=OSC&OrbitzID=AOSVQNflgN!1280186485!171067259!7001!-1!1087296[1].ÁŽõw Status: Locked to the Windows API! Path: C:\Documents and Settings\Old_Owner\Local Settings\Temporary Internet Files\Content.IE5\C52FUJ4D\domain=orbitz&channel=air&Section=exitApp&adsize=430x55&origin=CID&dest=DFW&OrbitzCookieName=OSC&orbitzID=APwzGWkU9N!1280186485!171067259!7001!-1!1087336691[1].ÁŽõw Status: Locked to the Windows API! Path: C:\Documents and Settings\Old_Owner\Local Settings\Temporary Internet Files\Content.IE5\C52FUJ4D\domain=orbitz&channel=air&Section=interstitial&adsize=450x200&origin=CID&dest=MLB&homeCityCode=CID&OrbitzCookieName=OSC&orbitzID=BQRGJcGkNj!669641983!17106718[1].js Status: Locked to the Windows API! Path: C:\Documents and Settings\Old_Owner\Local Settings\Temporary Internet Files\Content.IE5\C52FUJ4D\domain=orbitz&channel=air&Section=main&adsize=1x1&homeCityCode=CID&OrbitzCookieName=OSC&orbitzID=BQRGJcGkNj!669641983!171067181!7001!-1!1099976966533&secure[1].html Status: Locked to the Windows API! Path: C:\Documents and Settings\Old_Owner\Local Settings\Temporary Internet Files\Content.IE5\C52FUJ4D\domain=orbitz&channel=home&Section=main&adsize=342x188&origin=CID&dest=DFW&OrbitzCookieName=OSC&orbitzID=APwzGWkU9N!1280186485!171067259!7001!-1!10873366914[1].html Status: Locked to the Windows API! Path: C:\Documents and Settings\Old_Owner\Local Settings\Temporary Internet Files\Content.IE5\C52FUJ4D\flight;pgrp=flight;sgrp=flight_search_simple;zone=flight_deals_4;st=;cpax=; ch=;dc=;;ach=;ca=;apax=;sh=;ach=;ac=;ba=;acc=;sa=;pa=;bh=;abr=!webtv;sz=1x1;tile=6;[1].js Status: Locked to the Windows API! Path: C:\Documents and Settings\Old_Owner\Local Settings\Temporary Internet Files\Content.IE5\C52FUJ4D\flight;pgrp=flight;sgrp=flight_search_simple;zone=flight_deals_6;st=;cpax=; ch=;dc=;;ach=;ca=;apax=;sh=;ach=;ac=;ba=;acc=;sa=;pa=;bh=;abr=!webtv;sz=1x1;tile=8;[1].js Status: Locked to the Windows API! Path: C:\Documents and Settings\Old_Owner\Local Settings\Temporary Internet Files\Content.IE5\EPCR4B6Z\domain=orbitz&channel=deals&Section=deals_air_main&adsize=120x600&origin=CID&dest=DFW&OrbitzCookieName=OSC&OrbitzID=AOSVQNflgN!1280186485!171067259!7001!-1![1].ÁŽõw Status: Locked to the Windows API! Path: C:\Documents and Settings\Old_Owner\Local Settings\Temporary Internet Files\Content.IE5\EPCR4B6Z\domain=orbitz&channel=deals&Section=deals_air_main&adsize=468x60_top&origin=CID&dest=DFW&OrbitzCookieName=OSC&OrbitzID=AOSVQNflgN!1280186485!171067259!7001![1].html Status: Locked to the Windows API! Path: C:\Documents and Settings\Old_Owner\Local Settings\Temporary Internet Files\Content.IE5\EPCR4B6Z\domain=orbitz&channel=deals&Section=main&adsize=1x1&origin=CID&dest=DFW&OrbitzCookieName=OSC&orbitzID=AOSVQNflgN!1280186485!171067259!7001!-1!1087296085043&[1].ÁŽõw Status: Locked to the Windows API! Path: C:\Documents and Settings\Old_Owner\Local Settings\Temporary Internet Files\Content.IE5\EPCR4B6Z\domain=orbitz&channel=deals&Section=main&adsize=dealshoteltext1&origin=CID&dest=DFW&OrbitzCookieName=OSC&orbitzID=AOSVQNflgN!1280186485!171067259!7001!-1!108729[1] Status: Locked to the Windows API! Path: C:\Documents and Settings\Old_Owner\Local Settings\Temporary Internet Files\Content.IE5\GTYZG9I7\domain=orbitz&channel=air&Section=results&adsize=1x1&origin=CID&dest=ORL&homeCityCode=CID&OrbitzCookieName=OSC&orbitzID=BRFRO83qnK!315815477!171067194!7001![1].html Status: Locked to the Windows API! Path: C:\Documents and Settings\Old_Owner\Local Settings\Temporary Internet Files\Content.IE5\GTYZG9I7\domain=orbitz&channel=air&Section=results&adsize=1x1&origin=CID&dest=ORL&homeCityCode=CID&OrbitzCookieName=OSC&orbitzID=BRFRO83qnK!315815477!171067194!7001![2].html Status: Locked to the Windows API! Path: C:\Documents and Settings\Old_Owner\Local Settings\Temporary Internet Files\Content.IE5\GTYZG9I7\domain=orbitz&channel=air&Section=results&adsize=hotwireBottom&origin=CID&dest=ORL&homeCityCode=CID&OrbitzCookieName=OSC&orbitzID=BRFRO83qnK!315815477!17106[1].html Status: Locked to the Windows API! Path: C:\Documents and Settings\Old_Owner\Local Settings\Temporary Internet Files\Content.IE5\GTYZG9I7\domain=orbitz&channel=air&Section=results&adsize=hotwireBottom&origin=CID&dest=ORL&homeCityCode=CID&OrbitzCookieName=OSC&orbitzID=BRFRO83qnK!315815477!17106[2].html Status: Locked to the Windows API! Path: C:\Documents and Settings\Old_Owner\Local Settings\Temporary Internet Files\Content.IE5\GTYZG9I7\domain=orbitz&channel=air&Section=results&adsize=hotwireTop&origin=CID&dest=ORL&homeCityCode=CID&OrbitzCookieName=OSC&orbitzID=BRFRO83qnK!315815477!17106719[1].html Status: Locked to the Windows API! Path: C:\Documents and Settings\Old_Owner\Local Settings\Temporary Internet Files\Content.IE5\GTYZG9I7\domain=orbitz&channel=air&Section=results&adsize=hotwireTop&origin=CID&dest=ORL&homeCityCode=CID&OrbitzCookieName=OSC&orbitzID=BRFRO83qnK!315815477!17106719[2].html Status: Locked to the Windows API! Path: C:\Documents and Settings\Old_Owner\Local Settings\Temporary Internet Files\Content.IE5\GTYZG9I7\domain=orbitz&channel=home&Section=main&adsize=342x188&homeCityCode=CID&OrbitzCookieName=OSC&orbitzID=BQRGJcGkNj!669641983!171067181!7001!-1!1099976966533&s[1].html Status: Locked to the Windows API! Path: C:\Documents and Settings\Old_Owner\Local Settings\Temporary Internet Files\Content.IE5\GTYZG9I7\domain=orbitz&channel=home&Section=main&adsize=342x40&homeCityCode=CID&OrbitzCookieName=OSC&orbitzID=BQRGJcGkNj!669641983!171067181!7001!-1!1099976966533&secu[1].js Status: Locked to the Windows API! Path: C:\Documents and Settings\Old_Owner\Local Settings\Temporary Internet Files\Content.IE5\GTYZG9I7\domain=orbitz&channel=home&Section=main&adsize=hometext1&homeCityCode=CID&OrbitzCookieName=OSC&orbitzID=BQRGJcGkNj!669641983!171067181!7001!-1!1099976966533[1].html Status: Locked to the Windows API! Path: C:\Documents and Settings\Old_Owner\Local Settings\Temporary Internet Files\Content.IE5\GTYZG9I7\domain=orbitz&channel=home&Section=main&adsize=hometext2&homeCityCode=CID&OrbitzCookieName=OSC&orbitzID=BQRGJcGkNj!669641983!171067181!7001!-1!1099976966533[1].html Status: Locked to the Windows API! Path: C:\Documents and Settings\Old_Owner\Local Settings\Temporary Internet Files\Content.IE5\GTYZG9I7\domain=orbitz&channel=hotel&Section=results&adsize=450x200&dest=DALLAS&state=TX&country=US&OrbitzCookieName=OSC&orbitzID=A1isPsDBXY!-544357154!171067169!7001![1].js Status: Locked to the Windows API! Path: C:\Documents and Settings\Old_Owner\Local Settings\Temporary Internet Files\Content.IE5\GTYZG9I7\domain=orbitz&channel=air&Section=results&adsize=1x1&origin=DFW&dest=CID&OrbitzCookieName=OSC&OrbitzID=AQ1VeCyryI!698302125!171067201!7001!-1!1087438805657[1].ÁŽõw Status: Locked to the Windows API! Path: C:\Documents and Settings\Old_Owner\Local Settings\Temporary Internet Files\Content.IE5\GTYZG9I7\domain=orbitz&channel=home&Section=main&adsize=1x1&homeCityCode=CID&OrbitzCookieName=OSC&orbitzID=BQRGJcGkNj!669641983!171067181!7001!-1!1099976966533&secur[1].html Status: Locked to the Windows API! Path: C:\Documents and Settings\Old_Owner\Local Settings\Temporary Internet Files\Content.IE5\GTYZG9I7\domain=orbitz&channel=home&Section=main&adsize=hometext3&homeCityCode=CID&OrbitzCookieName=OSC&orbitzID=BQRGJcGkNj!669641983!171067181!7001!-1!1099976966533[1].html Status: Locked to the Windows API! Path: C:\Documents and Settings\Old_Owner\Local Settings\Temporary Internet Files\Content.IE5\GXA3GHUT\domain=orbitz&channel=home&Section=main&adsize=hometext2&origin=CID&dest=DFW&OrbitzCookieName=OSC&orbitzID=APwzGWkU9N!1280186485!171067259!7001!-1!108733669[1].html Status: Locked to the Windows API! Path: C:\Documents and Settings\Old_Owner\Local Settings\Temporary Internet Files\Content.IE5\GXA3GHUT\flight;pgrp=flight;sgrp=flight_search_simple;zone=C;pos=lower;st=;ach=;ach= ;dc=CID;ach=;ca=;ac=DFW;ba=;acc=;sa=;pa=;abr=!webtv;sz=1x1;tile=6;ord=7461289106519[1].js Status: Locked to the Windows API! Path: C:\Documents and Settings\Old_Owner\Local Settings\Temporary Internet Files\Content.IE5\I2V79SBF\domain=orbitz&channel=air&Section=results&adsize=1x1&origin=CID&dest=ORL&homeCityCode=CID&OrbitzCookieName=OSC&orbitzID=BRFRO83qnK!315815477!171067194!7001![1].html Status: Locked to the Windows API! Path: C:\Documents and Settings\Old_Owner\Local Settings\Temporary Internet Files\Content.IE5\I2V79SBF\domain=orbitz&channel=air&Section=results&adsize=hotwireBottom&origin=CID&dest=ORL&homeCityCode=CID&OrbitzCookieName=OSC&orbitzID=BRFRO83qnK!315815477!17106[1].html Status: Locked to the Windows API! Path: C:\Documents and Settings\Old_Owner\Local Settings\Temporary Internet Files\Content.IE5\I2V79SBF\domain=orbitz&channel=air&Section=results&adsize=hotwireTop&origin=CID&dest=ORL&homeCityCode=CID&OrbitzCookieName=OSC&orbitzID=BRFRO83qnK!315815477!17106719[1].html Status: Locked to the Windows API! Path: C:\Documents and Settings\Old_Owner\Local Settings\Temporary Internet Files\Content.IE5\I2V79SBF\domain=orbitz&channel=air&Section=results_flex_v3&adsize=hotwireTop&origin=CID&dest=ORL&homeCityCode=CID&OrbitzCookieName=OSC&orbitzID=BRFRO83qnK!315815477![1].html Status: Locked to the Windows API! Path: C:\Documents and Settings\Old_Owner\Local Settings\Temporary Internet Files\Content.IE5\I2V79SBF\domain=orbitz&channel=home&Section=main&adsize=1x1&homeCityCode=CID&OrbitzCookieName=OSC&orbitzID=BRFRO83qnK!315815477!171067194!7001!-1!1100023185606&secur[1].html Status: Locked to the Windows API! Path: C:\Documents and Settings\Old_Owner\Local Settings\Temporary Internet Files\Content.IE5\I2V79SBF\domain=orbitz&channel=home&Section=main&adsize=342x188&homeCityCode=CID&OrbitzCookieName=OSC&orbitzID=BRFRO83qnK!315815477!171067194!7001!-1!1100023185606&s[1].html Status: Locked to the Windows API! Path: C:\Documents and Settings\Old_Owner\Local Settings\Temporary Internet Files\Content.IE5\I2V79SBF\domain=orbitz&channel=home&Section=main&adsize=hometext1&homeCityCode=CID&OrbitzCookieName=OSC&orbitzID=BRFRO83qnK!315815477!171067194!7001!-1!1100023185606[1].html Status: Locked to the Windows API! Path: C:\Documents and Settings\Old_Owner\Local Settings\Temporary Internet Files\Content.IE5\I2V79SBF\domain=orbitz&channel=home&Section=main&adsize=hometext2&homeCityCode=CID&OrbitzCookieName=OSC&orbitzID=BRFRO83qnK!315815477!171067194!7001!-1!1100023185606[1].html Status: Locked to the Windows API! Path: C:\Documents and Settings\Old_Owner\Local Settings\Temporary Internet Files\Content.IE5\I2V79SBF\domain=orbitz&channel=home&Section=main&adsize=hometext3&homeCityCode=CID&OrbitzCookieName=OSC&orbitzID=BRFRO83qnK!315815477!171067194!7001!-1!1100023185606[1].html Status: Locked to the Windows API! Path: C:\Documents and Settings\Old_Owner\Local Settings\Temporary Internet Files\Content.IE5\I2V79SBF\domain=orbitz&channel=air&Section=main&adsize=hometext1&origin=CID&dest=ORL&homeCityCode=CID&OrbitzCookieName=OSC&orbitzID=BRFRO83qnK!315815477!171067194!70[1].html Status: Locked to the Windows API! Path: C:\Documents and Settings\Old_Owner\Local Settings\Temporary Internet Files\Content.IE5\I2V79SBF\domain=orbitz&channel=air&Section=results_flex_v3&adsize=hotwireTop&origin=CID&dest=ORL&homeCityCode=CID&OrbitzCookieName=OSC&orbitzID=BRFRO83qnK!315815477![2].html Status: Locked to the Windows API! Path: C:\Documents and Settings\Old_Owner\Local Settings\Temporary Internet Files\Content.IE5\I2V79SBF\domain=orbitz&channel=air&Section=interstitial&adsize=450x200&origin=CID&dest=ORL&homeCityCode=CID&OrbitzCookieName=OSC&o
OK, I still don't know why it took 5 hours, but at least we've found the source of the problem.

Download ComboFix by sUBs from here or here

Note: If you already have a copy of ComboFix on your system it is essential that you delete it before downloading this copy.

**Save it to your desktop**

We need to disable one or more of your security programs so that they do not interfere with ComboFix.

Please use this topic for assistance with disabling your Security Programs:
How To Disable Your Security Programs

Double click on ComboFix.exe & follow the prompts. If you are prompted to install the Recovery Console I recommend you go ahead and hit yes.
When finished, it shall produce a log for you. Please save that log to post in your next reply along with a fresh HJT log

Notes:
  • Do not mouseclick combofix's window whilst it's running. That may cause it to stall.
  • ComboFix may reset a number of Internet Explorer's settings, including making I-E the default browser.
  • Combofix prevents autorun of ALL CD, floppy and USB devices to assist with malware removal & increase security. If this is an issue or makes it difficult for you - please let me know.
  • ComboFix disconnects your machine from the internet when it runs. This connection should be automatically restored when ComboFix completes its run. If ComboFix runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.
Ran ComboFix without having any trouble. Here's the ComboFixLog and fresh HJTlog:

ComboFix 09-06-19.01 - Administrator 06/20/2009 8:26.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1022.501 [GMT -5:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
AV: AVG Anti-Virus Free *On-access scanning disabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\docume~1\ADMINI~1\LOCALS~1\Temp\IadHide5.dll
c:\documents and settings\Administrator\Local Settings\Temp\IadHide5.dll
c:\program files\Download Plugin
c:\recycler\S-1-5-21-1799784117-972149550-2037642983-1008
c:\recycler\S-1-5-21-4063818903-2177821252-1511872149-1009
c:\recycler\S-1-5-21-776561741-1229272821-725345543-500
E:\resycled
c:\documents and settings\All Users\Start Menu\Programs\Internet Explorer.lnk
c:\program files\download plugin\DlPlugin-Moz\buddy.dat
c:\program files\Download Plugin\DlPlugin-Moz\vendor.txt
c:\recycler\S-1-5-21-1799784117-972149550-2037642983-1008\Dc1.lnk
c:\recycler\S-1-5-21-1799784117-972149550-2037642983-1008\Dc2.lnk
c:\recycler\S-1-5-21-1799784117-972149550-2037642983-1008\Dc3.lnk
c:\recycler\S-1-5-21-1799784117-972149550-2037642983-1008\Dc4.lnk
c:\recycler\S-1-5-21-1799784117-972149550-2037642983-1008\Dc5.lnk
c:\recycler\S-1-5-21-1799784117-972149550-2037642983-1008\Dc6.lnk
c:\recycler\S-1-5-21-1799784117-972149550-2037642983-1008\Dc7.lnk
c:\recycler\S-1-5-21-1799784117-972149550-2037642983-1008\Dc8.lnk
c:\recycler\S-1-5-21-1799784117-972149550-2037642983-1008\Dc9\- HP Game Console -.lnk
c:\recycler\S-1-5-21-1799784117-972149550-2037642983-1008\Dc9\Barnyard Invasion.lnk
c:\recycler\S-1-5-21-1799784117-972149550-2037642983-1008\Dc9\Bejeweled 2 Deluxe.lnk
c:\recycler\S-1-5-21-1799784117-972149550-2037642983-1008\Dc9\Big Kahuna Reef.lnk
c:\recycler\S-1-5-21-1799784117-972149550-2037642983-1008\Dc9\Blackhawk Striker 2.lnk
c:\recycler\S-1-5-21-1799784117-972149550-2037642983-1008\Dc9\Blasterball 2 Holidays.lnk
c:\recycler\S-1-5-21-1799784117-972149550-2037642983-1008\Dc9\Blasterball 2.lnk
c:\recycler\S-1-5-21-1799784117-972149550-2037642983-1008\Dc9\Boggle Supreme.lnk
c:\recycler\S-1-5-21-1799784117-972149550-2037642983-1008\Dc9\Bookworm Deluxe.lnk
c:\recycler\S-1-5-21-1799784117-972149550-2037642983-1008\Dc9\Bounce Symphony.lnk
c:\recycler\S-1-5-21-1799784117-972149550-2037642983-1008\Dc9\Crystal Maze.lnk
c:\recycler\S-1-5-21-1799784117-972149550-2037642983-1008\Dc9\Digby's Donuts.lnk
c:\recycler\S-1-5-21-1799784117-972149550-2037642983-1008\Dc9\FATE Demo.lnk
c:\recycler\S-1-5-21-1799784117-972149550-2037642983-1008\Dc9\Flip Words.lnk
c:\recycler\S-1-5-21-1799784117-972149550-2037642983-1008\Dc9\Insaniquarium Deluxe.lnk
c:\recycler\S-1-5-21-1799784117-972149550-2037642983-1008\Dc9\Jewel Quest.lnk
c:\recycler\S-1-5-21-1799784117-972149550-2037642983-1008\Dc9\Mah Jong Quest.lnk
c:\recycler\S-1-5-21-1799784117-972149550-2037642983-1008\Dc9\Play Contests.lnk
c:\recycler\S-1-5-21-1799784117-972149550-2037642983-1008\Dc9\Polar Bowler.lnk
c:\recycler\S-1-5-21-1799784117-972149550-2037642983-1008\Dc9\Polar Golfer.lnk
c:\recycler\S-1-5-21-1799784117-972149550-2037642983-1008\Dc9\Puzzle Express.lnk
c:\recycler\S-1-5-21-1799784117-972149550-2037642983-1008\Dc9\Ricochet Lost Worlds.lnk
c:\recycler\S-1-5-21-1799784117-972149550-2037642983-1008\Dc9\SCRABBLE Blast.lnk
c:\recycler\S-1-5-21-1799784117-972149550-2037642983-1008\Dc9\SCRABBLE Rack Attack.lnk
c:\recycler\S-1-5-21-1799784117-972149550-2037642983-1008\Dc9\SCRABBLE.lnk
c:\recycler\S-1-5-21-1799784117-972149550-2037642983-1008\Dc9\See High Scores.lnk
c:\recycler\S-1-5-21-1799784117-972149550-2037642983-1008\Dc9\Shrek 2 Ogre Bowler.lnk
c:\recycler\S-1-5-21-1799784117-972149550-2037642983-1008\Dc9\Slingo Deluxe.lnk
c:\recycler\S-1-5-21-1799784117-972149550-2037642983-1008\Dc9\Slyder.lnk
c:\recycler\S-1-5-21-1799784117-972149550-2037642983-1008\Dc9\Super Granny.lnk
c:\recycler\S-1-5-21-1799784117-972149550-2037642983-1008\Dc9\Swarm.lnk
c:\recycler\S-1-5-21-1799784117-972149550-2037642983-1008\Dc9\Tradewinds.lnk
c:\recycler\S-1-5-21-1799784117-972149550-2037642983-1008\desktop.ini
c:\recycler\S-1-5-21-1799784117-972149550-2037642983-1008\INFO2
c:\recycler\S-1-5-21-4063818903-2177821252-1511872149-1009\desktop.ini
c:\recycler\S-1-5-21-4063818903-2177821252-1511872149-1009\INFO2
c:\recycler\S-1-5-21-776561741-1229272821-725345543-500\desktop.ini
c:\recycler\S-1-5-21-776561741-1229272821-725345543-500\INFO2
c:\windows\kb913800.exe
E:\Desktop.ini

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

——-\Legacy_IWINGAMESINSTALLER
——-\Service_gaopdxserv.sys
——-\Service_iWinGamesInstaller


((((((((((((((((((((((((( Files Created from 2009-05-20 to 2009-06-20 )))))))))))))))))))))))))))))))
.

2009-06-20 02:16 . 2009-06-20 02:17 ——– d—–w- c:\program files\RootRepeal
2009-06-19 03:08 . 2009-03-06 14:22 284160 ——w- c:\windows\system32\dllcache\pdh.dll
2009-06-19 03:08 . 2009-02-09 12:10 473600 ——w- c:\windows\system32\dllcache\fastprox.dll
2009-06-19 03:08 . 2009-02-09 12:10 401408 ——w- c:\windows\system32\dllcache\rpcss.dll
2009-06-19 03:08 . 2009-02-06 11:11 110592 ——w- c:\windows\system32\dllcache\services.exe
2009-06-19 03:08 . 2009-02-06 10:10 227840 ——w- c:\windows\system32\dllcache\wmiprvse.exe
2009-06-19 03:08 . 2009-02-09 12:10 729088 ——w- c:\windows\system32\dllcache\lsasrv.dll
2009-06-19 03:08 . 2009-02-09 12:10 714752 ——w- c:\windows\system32\dllcache\ntdll.dll
2009-06-19 03:08 . 2009-02-09 12:10 617472 ——w- c:\windows\system32\dllcache\advapi32.dll
2009-06-19 03:08 . 2009-02-09 12:10 453120 ——w- c:\windows\system32\dllcache\wmiprvsd.dll
2009-06-19 03:05 . 2008-05-03 11:55 2560 ——w- c:\windows\system32\xpsp4res.dll
2009-06-19 03:05 . 2008-04-21 12:08 215552 ——w- c:\windows\system32\dllcache\wordpad.exe
2009-06-18 23:43 . 2009-06-18 23:43 ——– d—–w- c:\documents and settings\Administrator\Application Data\Malwarebytes
2009-06-18 23:43 . 2009-06-17 16:27 38160 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-06-18 23:43 . 2009-06-18 23:43 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2009-06-18 23:43 . 2009-06-18 23:43 ——– d—–w- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-06-18 23:43 . 2009-06-17 16:27 19096 —-a-w- c:\windows\system32\drivers\mbam.sys
2009-06-17 04:52 . 2009-06-17 04:52 ——– d—–w- c:\program files\Trend Micro
2009-06-15 00:27 . 2009-06-15 00:27 152576 —-a-w- c:\documents and settings\Administrator\Application Data\Sun\Java\jre1.6.0_14\lzma.dll
2009-06-14 23:39 . 2009-03-09 19:06 15688 —-a-w- c:\windows\system32\lsdelete.exe
2009-06-14 22:31 . 2009-03-09 19:06 64160 —-a-w- c:\windows\system32\drivers\Lbd.sys
2009-06-14 22:31 . 2009-06-14 22:31 ——– dc-h–w- c:\documents and settings\All Users\Application Data\{7972B2E5-3E09-4E5E-81B7-FE5819D6772F}
2009-06-14 22:31 . 2009-03-12 08:17 2902048 -c–a-w- c:\documents and settings\All Users\Application Data\{7972B2E5-3E09-4E5E-81B7-FE5819D6772F}\Ad-AwareAE.exe
2009-06-01 03:04 . 2009-06-01 03:04 ——– d—–w- c:\documents and settings\All Users\Application Data\Big Fish Games Vancouver
2009-06-01 03:03 . 2009-06-01 03:04 ——– d—–w- c:\program files\Unwell Mel
2009-06-01 03:02 . 2009-06-01 03:02 ——– d—–w- c:\program files\bfgclient
2009-06-01 03:01 . 2009-06-02 04:49 ——– d—–w- c:\documents and settings\All Users\Application Data\BigFishGamesCache
2009-05-27 12:06 . 2009-05-27 12:06 ——– d–h–w- c:\windows\system32\GroupPolicy

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-06-20 13:47 . 2007-07-23 23:55 ——– d—a-w- c:\documents and settings\All Users\Application Data\TEMP
2009-06-20 05:46 . 2005-12-04 16:31 ——– d—–w- c:\program files\Mozilla Thunderbird
2009-06-19 12:55 . 2005-12-04 20:13 10 —-a-w- c:\windows\popcinfo.dat
2009-06-19 11:40 . 2005-12-04 16:27 ——– d—–w- c:\program files\Jewel Quest
2009-06-19 08:21 . 2008-06-06 02:24 ——– d—–w- c:\documents and settings\All Users\Application Data\Microsoft Help
2009-06-17 04:22 . 2005-10-18 23:23 ——– d—–w- c:\program files\Google
2009-06-15 00:28 . 2005-10-18 22:23 ——– d—–w- c:\program files\Java
2009-06-14 22:32 . 2008-04-17 13:18 ——– d—–w- c:\documents and settings\All Users\Application Data\Lavasoft
2009-06-14 22:31 . 2005-12-04 16:27 ——– d—–w- c:\program files\Lavasoft
2009-06-14 04:29 . 2008-09-08 21:32 ——– d—–w- c:\program files\Coupons
2009-05-21 16:33 . 2008-12-08 13:42 410984 —-a-w- c:\windows\system32\deploytk.dll
2009-05-07 15:32 . 2004-08-10 12:00 345600 —-a-w- c:\windows\system32\localspl.dll
2009-04-29 04:56 . 2004-08-10 12:00 827392 —-a-w- c:\windows\system32\wininet.dll
2009-04-29 04:55 . 2004-08-10 12:00 78336 —-a-w- c:\windows\system32\ieencode.dll
2009-04-17 12:26 . 2004-08-10 12:00 1847168 —-a-w- c:\windows\system32\win32k.sys
2009-04-15 14:51 . 2004-08-10 12:00 585216 —-a-w- c:\windows\system32\rpcrt4.dll
2009-04-08 12:18 . 2009-04-08 12:18 152576 —-a-w- c:\documents and settings\Administrator\Application Data\Sun\Java\jre1.6.0_13\lzma.dll
2000-06-05 22:47 . 2006-08-01 00:40 32768 —-a-w- c:\program files\mozilla firefox\plugins\AppSub32.dll
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
"updateMgr"="c:\program files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" [2006-03-30 313472]
"RegistryMechanic"="c:\program files\Registry Mechanic\RegMech.exe" [2008-07-08 2828184]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray"="c:\windows\ehome\ehtray.exe" [2005-08-06 64512]
"ATICCC"="c:\program files\ATI Technologies\ATI.ACE\cli.exe" [2005-08-10 61440]
"HPHUPD08"="c:\program files\HP\Digital Imaging\{33D6CC28-9F75-4d1b-A11D-98895B3A3729}\hphupd08.exe" [2005-06-02 49152]
"HPBootOp"="c:\program files\Hewlett-Packard\HP Boot Optimizer\HPBootOp.exe" [2005-02-26 245760]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2007-05-08 54840]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2005-10-18 180269]
"KBD"="c:\hp\KBD\KBD.EXE" [2005-02-02 61440]
"AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2008-11-27 1261336]
"Ad-Watch"="c:\program files\Lavasoft\Ad-Aware\AAWTray.exe" [2009-03-09 515416]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-05-21 148888]
"AlwaysReady Power Message APP"="ARPWRMSG.EXE" - c:\windows\arpwrmsg.exe [2005-08-03 77312]
"RTHDCPL"="RTHDCPL.EXE" - c:\windows\RTHDCPL.EXE [2005-08-18 14820864]
"Kernel and Hardware Abstraction Layer"="KHALMNPR.EXE" - c:\windows\KHALMNPR.Exe [2008-02-29 76304]

c:\documents and settings\Administrator\Start Menu\Programs\Startup\
Webshots.lnk - c:\program files\Webshots\Launcher.exe [2005-12-4 157008]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
Logitech SetPoint.lnk - c:\program files\Logitech\SetPoint\SetPoint.exe [2008-11-2 805392]
Updates from HP.lnk - c:\program files\Updates from HP\9972322\Program\Updates from HP.exe [2005-10-18 36903]
Webshots.lnk - c:\program files\Webshots\Launcher.exe [2005-12-4 157008]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\LBTWlgn]
2008-05-02 08:42 72208 —-a-w- c:\program files\Common Files\Logishrd\Bluetooth\LBTWLgn.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\windows\system32\avgrsstx.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdauxservice]
@=""

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdcoreservice]
@=""

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WdfLoadGroup]
@=""

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Updates from HP\\9972322\\Program\\Updates from HP.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqCopy.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpfccopy.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqPhUnl.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqDIA.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqnrs08.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Downloads\\utorrent.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgemc.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Logitech\\Logitech Harmony Remote Software 7\\HarmonyRemote.exe"=
"c:\\Program Files\\iWin Games\\iWinGames.exe"=
"c:\\Program Files\\iWin Games\\WebUpdater.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3389:TCP"= 3389:TCP:*:Disabled:@xpsp2res.dll,-22009

R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [6/14/2009 5:31 PM 64160]
R1 AvgLdx86;AVG AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [6/16/2008 1:42 PM 97928]
R2 avg8emc;AVG8 E-mail Scanner;c:\progra~1\AVG\AVG8\avgemc.exe [7/3/2008 7:27 PM 875288]
R2 avg8wd;AVG8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [7/3/2008 7:27 PM 231704]
R2 AvgTdiX;AVG8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [6/16/2008 1:42 PM 76040]
R2 iWinTrusted;iWinTrusted;c:\program files\iWin Games\iWinTrusted.exe [1/16/2009 7:18 PM 78104]
R2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [3/9/2009 2:06 PM 951632]
S3 sdAuxService;PC Tools Auxiliary Service;c:\program files\Spyware Doctor\pctsAuxs.exe [2/13/2009 11:25 PM 356920]
.
Contents of the 'Scheduled Tasks' folder

2009-06-15 c:\windows\Tasks\Ad-Aware Update (Weekly).job
- c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2009-03-09 19:06]

2009-06-20 c:\windows\Tasks\Symantec NetDetect.job
- c:\program files\Symantec\LiveUpdate\NDETECT.EXE [2005-10-18 02:24]
.
- - - - ORPHANS REMOVED - - - -

HKLM-Run-PCDrProfiler - (no file)
Notify-WgaLogon - (no file)


.
——- Supplementary Scan ——-
.
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid;=ie7&rls;=com.microsoft:en-US&ie;=utf8&oe;=utf8
mSearch Bar = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp;=iesearch&locale;=EN_US&c;=Q405&bd;=pavilion&pf;=desktop&parm1;=seconduser
uSearchURL,(Default) = hxxp://www.google.com/keyword/%s
IE: E&xport; to Microsoft Excel - c:\progra~1\MICROS~4\Office12\EXCEL.EXE/3000
TCP: {C915206A-CD3E-4B35-879A-57BF02D24CA6} = 208.67.220.220,208.67.222.222
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540022}
FF - ProfilePath -

—- FIREFOX POLICIES —-
c:\program files\Mozilla Firefox\defaults\pref\activex.js - pref("capability.policy.default.ClassID.CIDFE0BD779-44EE-4A4B-AA2E-743C63F2E5E6", "AllAccess");
c:\program files\Mozilla Firefox\defaults\pref\activex.js - pref("capability.policy.default.ClassID.CIDFE0BD779-44EE-4A4B-AA2E-743C63F2E5E6", "AllAccess");
c:\program files\Mozilla Firefox\defaults\pref\activex.js - pref("capability.policy.default.ClassID.CIDFE0BD779-44EE-4A4B-AA2E-743C63F2E5E6", "AllAccess");
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-06-20 08:44
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————

[HKEY_USERS\S-1-5-21-521744339-3598513094-3718192303-1009\Software\Google]
@DACL=(02 0000)

[HKEY_USERS\S-1-5-21-521744339-3598513094-3718192303-1009\Software\Microsoft\Multimedia]
@DACL=(02 0000)

[HKEY_USERS\S-1-5-21-521744339-3598513094-3718192303-1009\Software\Microsoft\SystemCertificates]
@DACL=(02 0000)

[HKEY_USERS\S-1-5-21-521744339-3598513094-3718192303-1009\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced]
@DACL=(02 0000)
"NoNetCrawling"=dword:00000000
"FolderContentsInfoTip"=dword:00000001
"FriendlyTree"=dword:00000001
"WebViewBarricade"=dword:00000001
"DisableThumbnailCache"=dword:00000000
"Hidden"=dword:00000001
"HideFileExt"=dword:00000000
"ShowSuperHidden"=dword:00000000
"SeparateProcess"=dword:00000000
"ClassicViewState"=dword:00000000
"PersistBrowsers"=dword:00000001
"ShowCompColor"=dword:00000001
"ShowInfoTip"=dword:00000001

[HKEY_USERS\S-1-5-21-521744339-3598513094-3718192303-1009\Software\Microsoft\Windows\CurrentVersion\Explorer\CabinetState]
@DACL=(02 0000)
"FullPathAddress"=dword:00000001
"FullPath"=dword:00000001
"Settings"=hex:0c,00,02,00,0b,01,fc,75,60,00,00,00

[HKEY_USERS\S-1-5-21-521744339-3598513094-3718192303-1009\Software\Microsoft\Windows\CurrentVersion\Explorer\HideMyComputerIcons]
@DACL=(02 0000)
"{21EC2020-3AEA-1069-A2DD-08002B30309D}"=dword:00000000

[HKEY_USERS\S-1-5-21-521744339-3598513094-3718192303-1009\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2]
@DACL=(02 0000)

[HKEY_USERS\S-1-5-21-521744339-3598513094-3718192303-1009\Software\Microsoft\Windows\CurrentVersion\Explorer\StartPage]
@DACL=(02 0000)
"FavoritesResolve"=hex:00,00,00,00,00,00,00,00
"Favorites"=hex:00,16,00,00,00,14,00,1f,80,f4,a1,59,25,d7,21,d4,11,bd,af,00,c0,
4f,60,b9,f0,00,00,00,16,00,00,00,14,00,1f,80,f5,a1,59,25,d7,21,d4,11,bd,af,\
"FavoritesChanges"=dword:00000001

[HKEY_USERS\S-1-5-21-521744339-3598513094-3718192303-1009\Software\Microsoft\Windows\CurrentVersion\Explorer\Streams]
@DACL=(02 0000)
"Settings"=hex:08,00,00,00,06,00,00,00,01,00,00,00,e5,25,f1,65,e1,7b,10,48,ba,
9d,d2,71,c8,43,2c,e3,04,00,00,00,02,00,00,00,43,00,00,00

[HKEY_USERS\S-1-5-21-521744339-3598513094-3718192303-1009\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
@DACL=(02 0000)
"ProxyEnable"=dword:00000000
"MigrateProxy"=dword:00000001

[HKEY_USERS\S-1-5-21-521744339-3598513094-3718192303-1009\Software\Microsoft\Windows\CurrentVersion\WinTrust]
@DACL=(02 0000)

[HKEY_USERS\S-1-5-21-521744339-3598513094-3718192303-1009\Software\Microsoft\Windows\Shell]
@DACL=(02 0000)

[HKEY_USERS\S-1-5-21-521744339-3598513094-3718192303-1009\Software\Microsoft\Windows\ShellNoRoam]
@DACL=(02 0000)
@="GODDESS2"

[HKEY_USERS\S-1-5-21-521744339-3598513094-3718192303-1009\Software\Microsoft\Windows NT\CurrentVersion\DiskQuota]
@DACL=(02 0000)

[HKEY_USERS\S-1-5-21-521744339-3598513094-3718192303-1009\Software\Microsoft\Windows NT\CurrentVersion\Network]
@Class="REG_SZ"
@DACL=(02 0000)

[HKEY_USERS\S-1-5-21-521744339-3598513094-3718192303-1009\Software\Google]
@DACL=(02 0000)

[HKEY_USERS\S-1-5-21-521744339-3598513094-3718192303-1009\Software\Microsoft\Multimedia]
@DACL=(02 0000)

[HKEY_USERS\S-1-5-21-521744339-3598513094-3718192303-1009\Software\Microsoft\SystemCertificates]
@DACL=(02 0000)

[HKEY_USERS\S-1-5-21-521744339-3598513094-3718192303-1009\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced]
@DACL=(02 0000)
"NoNetCrawling"=dword:00000000
"FolderContentsInfoTip"=dword:00000001
"FriendlyTree"=dword:00000001
"WebViewBarricade"=dword:00000001
"DisableThumbnailCache"=dword:00000000
"Hidden"=dword:00000001
"HideFileExt"=dword:00000000
"ShowSuperHidden"=dword:00000000
"SeparateProcess"=dword:00000000
"ClassicViewState"=dword:00000000
"PersistBrowsers"=dword:00000001
"ShowCompColor"=dword:00000001
"ShowInfoTip"=dword:00000001

[HKEY_USERS\S-1-5-21-521744339-3598513094-3718192303-1009\Software\Microsoft\Windows\CurrentVersion\Explorer\CabinetState]
@DACL=(02 0000)
"FullPathAddress"=dword:00000001
"FullPath"=dword:00000001
"Settings"=hex:0c,00,02,00,0b,01,fc,75,60,00,00,00

[HKEY_USERS\S-1-5-21-521744339-3598513094-3718192303-1009\Software\Microsoft\Windows\CurrentVersion\Explorer\HideMyComputerIcons]
@DACL=(02 0000)
"{21EC2020-3AEA-1069-A2DD-08002B30309D}"=dword:00000000

[HKEY_USERS\S-1-5-21-521744339-3598513094-3718192303-1009\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2]
@DACL=(02 0000)

[HKEY_USERS\S-1-5-21-521744339-3598513094-3718192303-1009\Software\Microsoft\Windows\CurrentVersion\Explorer\StartPage]
@DACL=(02 0000)
"FavoritesResolve"=hex:00,00,00,00,00,00,00,00
"Favorites"=hex:00,16,00,00,00,14,00,1f,80,f4,a1,59,25,d7,21,d4,11,bd,af,00,c0,
4f,60,b9,f0,00,00,00,16,00,00,00,14,00,1f,80,f5,a1,59,25,d7,21,d4,11,bd,af,\
"FavoritesChanges"=dword:00000001

[HKEY_USERS\S-1-5-21-521744339-3598513094-3718192303-1009\Software\Microsoft\Windows\CurrentVersion\Explorer\Streams]
@DACL=(02 0000)
"Settings"=hex:08,00,00,00,06,00,00,00,01,00,00,00,e5,25,f1,65,e1,7b,10,48,ba,
9d,d2,71,c8,43,2c,e3,04,00,00,00,02,00,00,00,43,00,00,00

[HKEY_USERS\S-1-5-21-521744339-3598513094-3718192303-1009\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
@DACL=(02 0000)
"ProxyEnable"=dword:00000000
"MigrateProxy"=dword:00000001

[HKEY_USERS\S-1-5-21-521744339-3598513094-3718192303-1009\Software\Microsoft\Windows\CurrentVersion\WinTrust]
@DACL=(02 0000)

[HKEY_USERS\S-1-5-21-521744339-3598513094-3718192303-1009\Software\Microsoft\Windows\Shell]
@DACL=(02 0000)

[HKEY_USERS\S-1-5-21-521744339-3598513094-3718192303-1009\Software\Microsoft\Windows\ShellNoRoam]
@DACL=(02 0000)
@="GODDESS2"

[HKEY_USERS\S-1-5-21-521744339-3598513094-3718192303-1009\Software\Microsoft\Windows NT\CurrentVersion\DiskQuota]
@DACL=(02 0000)

[HKEY_USERS\S-1-5-21-521744339-3598513094-3718192303-1009\Software\Microsoft\Windows NT\CurrentVersion\Network]
@Class="REG_SZ"
@DACL=(02 0000)

[HKEY_USERS\S-1-5-21-521744339-3598513094-3718192303-500\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{5EB1534C-89A8-4110-9C46-2F24EE5CFD34}*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
"abigkhnjnnemgmhgnedojmjjjebgaiolmo"=hex:61,61,00,00
"bbigkhnjnnemgmhgnekoikojikjepdagcbdk"=hex:61,61,00,00
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'winlogon.exe'(756)
c:\windows\system32\Ati2evxx.dll
c:\program files\common files\logishrd\bluetooth\LBTWlgn.dll
c:\program files\common files\logishrd\bluetooth\LBTServ.dll

- - - - - - - > 'explorer.exe'(2392)
c:\docume~1\ADMINI~1\LOCALS~1\Temp\IadHide5.dll
c:\program files\Logitech\SetPoint\GameHook.dll
c:\program files\Logitech\SetPoint\lgscroll.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
———————— Other Running Processes ————————
.
c:\windows\system32\ati2evxx.exe
c:\windows\system32\ati2evxx.exe
c:\windows\arservice.exe
c:\windows\ehome\ehrecvr.exe
c:\windows\ehome\ehSched.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Common Files\LightScribe\LSSrvc.exe
c:\program files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\windows\system32\spool\drivers\w32x86\3\HPZIPM12.EXE
c:\windows\ehome\mcrdsvc.exe
c:\program files\AVG\AVG8\avgrsx.exe
c:\windows\system32\wbem\unsecapp.exe
c:\windows\system32\dllhost.exe
c:\windows\system32\wscntfy.exe
c:\windows\ehome\ehmsas.exe
c:\progra~1\Webshots\Webshots.scr
c:\program files\Common Files\Logishrd\KHAL2\KHALMNPR.exe
.
**************************************************************************
.
Completion time: 2009-06-20 8:51 - machine was rebooted
ComboFix-quarantined-files.txt 2009-06-20 13:51

Pre-Run: 36,621,127,680 bytes free
Post-Run: 37,836,201,984 bytes free

396 — E O F — 2009-06-19 08:21

_____________________________________________________

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 8:56:47 AM, on 6/20/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16850)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\arservice.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\iWin Games\iWinTrusted.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\HPZIPM12.EXE
C:\WINDOWS\system32\svchost.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\PROGRA~1\AVG\AVG8\avgemc.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\ehome\ehtray.exe
C:\WINDOWS\ARPWRMSG.EXE
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\HP\KBD\KBD.EXE
C:\WINDOWS\eHome\ehmsas.exe
C:\PROGRA~1\AVG\AVG8\avgtray.exe
C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Logitech\SetPoint\SetPoint.exe
C:\Program Files\Updates from HP\9972322\Program\Updates from HP.exe
C:\PROGRA~1\Webshots\Webshots.scr
C:\Program Files\Common Files\Logishrd\KHAL2\KHALMNPR.EXE
C:\WINDOWS\explorer.exe
c:\windows\system\hpsysdrv.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…arm1=seconduser
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {22D8E815-4A5E-4DFB-845E-AAB64207F5BD} - (no file)
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - (no file)
O2 - BHO: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
O2 - BHO: (no name) - {B56A7D7D-6927-48C8-A975-17DF180C71AC} - (no file)
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
O4 - HKLM\..\Run: [AlwaysReady Power Message APP] ARPWRMSG.EXE
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" runtime
O4 - HKLM\..\Run: [HPHUPD08] c:\Program Files\HP\Digital Imaging\{33D6CC28-9F75-4d1b-A11D-98895B3A3729}\hphupd08.exe
O4 - HKLM\..\Run: [HPBootOp] "C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp.exe" /run
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKLM\..\Run: [Ad-Watch] C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [updateMgr] C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe AcRdB7_1_0
O4 - HKCU\..\Run: [RegistryMechanic] C:\Program Files\Registry Mechanic\RegMech.exe /H
O4 - Startup: Webshots.lnk = C:\Program Files\Webshots\Launcher.exe
O4 - Global Startup: Logitech SetPoint.lnk = C:\Program Files\Logitech\SetPoint\SetPoint.exe
O4 - Global Startup: Updates from HP.lnk = C:\Program Files\Updates from HP\9972322\Program\Updates from HP.exe
O4 - Global Startup: Webshots.lnk = C:\Program Files\Webshots\Launcher.exe
O8 - Extra context menu item: E&xport; to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office12\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\Office12\REFIEBAR.DLL
O9 - Extra button: Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
O9 - Extra 'Tools' menuitem: Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {11260943-421B-11D0-8EAC-0000C07D88CF} -
O16 - DPF: {31E68DE2-5548-4B23-88F0-C51E6A0F695E} -
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} -
O16 - DPF: {74FFE28D-2378-11D5-990C-006094235084} -
O16 - DPF: {CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA} (Java Plug-in 1.5.0_06) -
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540022} -
O17 - HKLM\System\CCS\Services\Tcpip\..\{C915206A-CD3E-4B35-879A-57BF02D24CA6}: NameServer = 208.67.220.220,208.67.222.222
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O20 - AppInit_DLLs: C:\WINDOWS\system32\avgrsstx.dll
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: AVG8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: HP Port Resolver - Hewlett-Packard Company - C:\WINDOWS\system32\spool\drivers\w32x86\3\HPBPRO.EXE
O23 - Service: HP Status Server - Hewlett-Packard Company - C:\WINDOWS\system32\spool\drivers\w32x86\3\HPBOID.EXE
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: iWinTrusted - iWin Inc. - C:\Program Files\iWin Games\iWinTrusted.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: Lavasoft Ad-Aware Service - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
O23 - Service: Logitech Bluetooth Service (LBTServ) - Logitech, Inc. - C:\Program Files\Common Files\Logishrd\Bluetooth\LBTServ.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\HPZIPM12.EXE
O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\pctsAuxs.exe
O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\pctsSvc.exe

–
End of file - 8699 bytes
ComboFix has done a good job there. There are a few more items to clean up there, but before we clean those up I would like you to try and run GMER again, to see if there is any Rootkit left. If it takes more than 15 minutes, then give up on it and we'll just proceed without for now. Any change to the computer's behaviour yet?
Fantastic!! A quick check of Firefox using Google search indicates that it's no longer being re-directed and IE is now running again and not being redirected either.

I re-ran GMER and although it was running much faster and went well beyond the point where it had flagged for a Rootkit before, I cut it off after 20 minutes. I still saved the log file however; here what was there:

GMER 1.0.15.14972 - http://www.gmer.net
Rootkit scan 2009-06-21 07:31:56
Windows 5.1.2600 Service Pack 3


—- System - GMER 1.0.15 —-

SSDT Lbd.sys (Boot Driver/Lavasoft AB) ZwCreateKey [0xF762087E]
SSDT Lbd.sys (Boot Driver/Lavasoft AB) ZwSetValueKey [0xF7620C10]

—- Kernel code sections - GMER 1.0.15 —-

.text ntkrnlpa.exe!ZwCallbackReturn + 2C68 80504504 2 Bytes [7E, 08] {JLE 0xa}
.text ntkrnlpa.exe!ZwCallbackReturn + 2FA0 8050483C 2 Bytes [10, 0C]

—- Devices - GMER 1.0.15 —-

Device \Driver\Tcpip \Device\Ip avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)

AttachedDevice \Driver\Kbdclass \Device\KeyboardClass0 arkbcfltr.sys (Microsoft AR PS/2 Keyboard Filter Driver (Beta 2 Release 2)/Microsoft Corporation)
AttachedDevice \Driver\Kbdclass \Device\KeyboardClass1 arkbcfltr.sys (Microsoft AR PS/2 Keyboard Filter Driver (Beta 2 Release 2)/Microsoft Corporation)

Device \Driver\Tcpip \Device\Tcp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)

AttachedDevice \Driver\Tcpip \Device\Tcp Lbd.sys (Boot Driver/Lavasoft AB)

Device \Driver\Tcpip \Device\Udp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
Device \Driver\Tcpip \Device\RawIp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
Device \Driver\Tcpip \Device\IPMULTICAST avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)

AttachedDevice \FileSystem\Fastfat \Fat fltmgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)

—- Registry - GMER 1.0.15 —-

Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{5EB1534C-89A8-4110-9C46-2F24EE5CFD34}
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{5EB1534C-89A8-4110-9C46-2F24EE5CFD34}@abigkhnjnnemgmhgnedojmjjjebgaiolmo 0x61 0x61 0x00 0x00
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{5EB1534C-89A8-4110-9C46-2F24EE5CFD34}@bbigkhnjnnemgmhgnekoikojikjepdagcbdk 0x61 0x61 0x00 0x00

—- EOF - GMER 1.0.15 —-
Hi,

1. Please open Notepad
  • Click Start , then Run
  • Type notepad.exe in the Run Box.
2. Now copy/paste the entire content of the codebox below into the Notepad window:

RootKit::
C:\WINDOWS\system32\drivers\gaopdxkqewftmn.sys

Registry::
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{22D8E815-4A5E-4DFB-845E-AAB64207F5BD}]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB}]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B56A7D7D-6927-48C8-A975-17DF180C71AC}]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{11260943-421B-11D0-8EAC-0000C07D88CF}]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{31E68DE2-5548-4B23-88F0-C51E6A0F695E}]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21}]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{74FFE28D-2378-11D5-990C-006094235084}]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{D27CDB6E-AE6D-11CF-96B8-444553540022}]

RegLock::
[HKEY_USERS\S-1-5-21-521744339-3598513094-3718192303-1009\Software\Google]
[HKEY_USERS\S-1-5-21-521744339-3598513094-3718192303-1009\Software\Microsoft\Multimedia]
[HKEY_USERS\S-1-5-21-521744339-3598513094-3718192303-1009\Software\Microsoft\SystemCertificates]
[HKEY_USERS\S-1-5-21-521744339-3598513094-3718192303-1009\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced]
[HKEY_USERS\S-1-5-21-521744339-3598513094-3718192303-1009\Software\Microsoft\Windows\CurrentVersion\Explorer\CabinetState]
[HKEY_USERS\S-1-5-21-521744339-3598513094-3718192303-1009\Software\Microsoft\Windows\CurrentVersion\Explorer\HideMyComputerIcons]
[HKEY_USERS\S-1-5-21-521744339-3598513094-3718192303-1009\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2]
[HKEY_USERS\S-1-5-21-521744339-3598513094-3718192303-1009\Software\Microsoft\Windows\CurrentVersion\Explorer\StartPage]
[HKEY_USERS\S-1-5-21-521744339-3598513094-3718192303-1009\Software\Microsoft\Windows\CurrentVersion\Explorer\Streams]
[HKEY_USERS\S-1-5-21-521744339-3598513094-3718192303-1009\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
[HKEY_USERS\S-1-5-21-521744339-3598513094-3718192303-1009\Software\Microsoft\Windows\CurrentVersion\WinTrust]
[HKEY_USERS\S-1-5-21-521744339-3598513094-3718192303-1009\Software\Microsoft\Windows\Shell]
[HKEY_USERS\S-1-5-21-521744339-3598513094-3718192303-1009\Software\Microsoft\Windows\ShellNoRoam]
[HKEY_USERS\S-1-5-21-521744339-3598513094-3718192303-1009\Software\Microsoft\Windows NT\CurrentVersion\DiskQuota]
[HKEY_USERS\S-1-5-21-521744339-3598513094-3718192303-1009\Software\Microsoft\Windows NT\CurrentVersion\Network]
[HKEY_USERS\S-1-5-21-521744339-3598513094-3718192303-1009\Software\Google]
[HKEY_USERS\S-1-5-21-521744339-3598513094-3718192303-1009\Software\Microsoft\Multimedia]
[HKEY_USERS\S-1-5-21-521744339-3598513094-3718192303-1009\Software\Microsoft\SystemCertificates]
[HKEY_USERS\S-1-5-21-521744339-3598513094-3718192303-1009\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced]
[HKEY_USERS\S-1-5-21-521744339-3598513094-3718192303-1009\Software\Microsoft\Windows\CurrentVersion\Explorer\CabinetState]
[HKEY_USERS\S-1-5-21-521744339-3598513094-3718192303-1009\Software\Microsoft\Windows\CurrentVersion\Explorer\HideMyComputerIcons]
[HKEY_USERS\S-1-5-21-521744339-3598513094-3718192303-1009\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2]
[HKEY_USERS\S-1-5-21-521744339-3598513094-3718192303-1009\Software\Microsoft\Windows\CurrentVersion\Explorer\StartPage]
[HKEY_USERS\S-1-5-21-521744339-3598513094-3718192303-1009\Software\Microsoft\Windows\CurrentVersion\Explorer\Streams]
[HKEY_USERS\S-1-5-21-521744339-3598513094-3718192303-1009\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
[HKEY_USERS\S-1-5-21-521744339-3598513094-3718192303-1009\Software\Microsoft\Windows\CurrentVersion\WinTrust]
[HKEY_USERS\S-1-5-21-521744339-3598513094-3718192303-1009\Software\Microsoft\Windows\Shell]
[HKEY_USERS\S-1-5-21-521744339-3598513094-3718192303-1009\Software\Microsoft\Windows\ShellNoRoam]
[HKEY_USERS\S-1-5-21-521744339-3598513094-3718192303-1009\Software\Microsoft\Windows NT\CurrentVersion\DiskQuota]
[HKEY_USERS\S-1-5-21-521744339-3598513094-3718192303-1009\Software\Microsoft\Windows NT\CurrentVersion\Network]

RegLockDel::
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{5EB1534C-89A8-4110-9C46-2F24EE5CFD34}]

3. Save the above as CFScript.txt

4. Then drag the CFScript.txt into ComboFix.exe as depicted in the animation below. This will start ComboFix again.

[external image: Posted Image]

5. After reboot, (in case it asks to reboot), please post ComboFix.txt in your next reply.
After this, please run MalawreBytes' Anti-Malware, update it, and then run a Full System Scan. If it finds anything, post its log. Also, let me know how things are running.
Do you know what a packrat is? I'd send you a picture of one but I'm not that good at self-portraits!! I'm still running the Malware scan and sense that because I'm running a Full Scan, it's probably going to take close to the same time it would with GMER. This is probably due to the vast number of files that have been Packrated on my computer. 40 minutes into the scan Malware has only looked at ~200,00 files which is probably about one-fifth of the total. The file bloat is is my fault, having no good idea of what files are really necessary to keep even if I haven't accessed them for years. Thank you for your patience.

Here's a posting of the new ComboFix log while waiting for the Malware to finish:

ComboFix 09-06-19.01 - Administrator 06/21/2009 14:23.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1022.494 [GMT -5:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\Administrator\Desktop\CFScript.txt
AV: AVG Anti-Virus Free *On-access scanning disabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\docume~1\ADMINI~1\LOCALS~1\Temp\IadHide5.dll
c:\documents and settings\Administrator\Local Settings\Temp\IadHide5.dll

.
((((((((((((((((((((((((( Files Created from 2009-05-21 to 2009-06-21 )))))))))))))))))))))))))))))))
.

2009-06-20 02:16 . 2009-06-20 02:17 ——– d—–w- c:\program files\RootRepeal
2009-06-19 03:08 . 2009-03-06 14:22 284160 ——w- c:\windows\system32\dllcache\pdh.dll
2009-06-19 03:08 . 2009-02-09 12:10 473600 ——w- c:\windows\system32\dllcache\fastprox.dll
2009-06-19 03:08 . 2009-02-09 12:10 401408 ——w- c:\windows\system32\dllcache\rpcss.dll
2009-06-19 03:08 . 2009-02-06 11:11 110592 ——w- c:\windows\system32\dllcache\services.exe
2009-06-19 03:08 . 2009-02-06 10:10 227840 ——w- c:\windows\system32\dllcache\wmiprvse.exe
2009-06-19 03:08 . 2009-02-09 12:10 729088 ——w- c:\windows\system32\dllcache\lsasrv.dll
2009-06-19 03:08 . 2009-02-09 12:10 714752 ——w- c:\windows\system32\dllcache\ntdll.dll
2009-06-19 03:08 . 2009-02-09 12:10 617472 ——w- c:\windows\system32\dllcache\advapi32.dll
2009-06-19 03:08 . 2009-02-09 12:10 453120 ——w- c:\windows\system32\dllcache\wmiprvsd.dll
2009-06-19 03:05 . 2008-05-03 11:55 2560 ——w- c:\windows\system32\xpsp4res.dll
2009-06-19 03:05 . 2008-04-21 12:08 215552 ——w- c:\windows\system32\dllcache\wordpad.exe
2009-06-18 23:43 . 2009-06-18 23:43 ——– d—–w- c:\documents and settings\Administrator\Application Data\Malwarebytes
2009-06-18 23:43 . 2009-06-17 16:27 38160 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-06-18 23:43 . 2009-06-18 23:43 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2009-06-18 23:43 . 2009-06-18 23:43 ——– d—–w- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-06-18 23:43 . 2009-06-17 16:27 19096 —-a-w- c:\windows\system32\drivers\mbam.sys
2009-06-17 04:52 . 2009-06-17 04:52 ——– d—–w- c:\program files\Trend Micro
2009-06-15 00:27 . 2009-06-15 00:27 152576 —-a-w- c:\documents and settings\Administrator\Application Data\Sun\Java\jre1.6.0_14\lzma.dll
2009-06-14 23:39 . 2009-03-09 19:06 15688 —-a-w- c:\windows\system32\lsdelete.exe
2009-06-14 22:31 . 2009-03-09 19:06 64160 —-a-w- c:\windows\system32\drivers\Lbd.sys
2009-06-14 22:31 . 2009-06-14 22:31 ——– dc-h–w- c:\documents and settings\All Users\Application Data\{7972B2E5-3E09-4E5E-81B7-FE5819D6772F}
2009-06-14 22:31 . 2009-03-12 08:17 2902048 -c–a-w- c:\documents and settings\All Users\Application Data\{7972B2E5-3E09-4E5E-81B7-FE5819D6772F}\Ad-AwareAE.exe
2009-06-01 03:04 . 2009-06-01 03:04 ——– d—–w- c:\documents and settings\All Users\Application Data\Big Fish Games Vancouver
2009-06-01 03:03 . 2009-06-01 03:04 ——– d—–w- c:\program files\Unwell Mel
2009-06-01 03:02 . 2009-06-01 03:02 ——– d—–w- c:\program files\bfgclient
2009-06-01 03:01 . 2009-06-02 04:49 ——– d—–w- c:\documents and settings\All Users\Application Data\BigFishGamesCache
2009-05-27 12:06 . 2009-05-27 12:06 ——– d–h–w- c:\windows\system32\GroupPolicy

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-06-21 19:39 . 2007-07-23 23:55 ——– d—a-w- c:\documents and settings\All Users\Application Data\TEMP
2009-06-20 14:27 . 2005-12-04 16:27 ——– d—–w- c:\program files\Jewel Quest
2009-06-20 05:46 . 2005-12-04 16:31 ——– d—–w- c:\program files\Mozilla Thunderbird
2009-06-19 12:55 . 2005-12-04 20:13 10 —-a-w- c:\windows\popcinfo.dat
2009-06-19 08:21 . 2008-06-06 02:24 ——– d—–w- c:\documents and settings\All Users\Application Data\Microsoft Help
2009-06-17 04:22 . 2005-10-18 23:23 ——– d—–w- c:\program files\Google
2009-06-15 00:28 . 2005-10-18 22:23 ——– d—–w- c:\program files\Java
2009-06-14 22:32 . 2008-04-17 13:18 ——– d—–w- c:\documents and settings\All Users\Application Data\Lavasoft
2009-06-14 22:31 . 2005-12-04 16:27 ——– d—–w- c:\program files\Lavasoft
2009-06-14 04:29 . 2008-09-08 21:32 ——– d—–w- c:\program files\Coupons
2009-05-21 16:33 . 2008-12-08 13:42 410984 —-a-w- c:\windows\system32\deploytk.dll
2009-05-07 15:32 . 2004-08-10 12:00 345600 —-a-w- c:\windows\system32\localspl.dll
2009-04-29 04:56 . 2004-08-10 12:00 827392 —-a-w- c:\windows\system32\wininet.dll
2009-04-29 04:55 . 2004-08-10 12:00 78336 —-a-w- c:\windows\system32\ieencode.dll
2009-04-17 12:26 . 2004-08-10 12:00 1847168 —-a-w- c:\windows\system32\win32k.sys
2009-04-15 14:51 . 2004-08-10 12:00 585216 —-a-w- c:\windows\system32\rpcrt4.dll
2009-04-08 12:18 . 2009-04-08 12:18 152576 —-a-w- c:\documents and settings\Administrator\Application Data\Sun\Java\jre1.6.0_13\lzma.dll
2000-06-05 22:47 . 2006-08-01 00:40 32768 —-a-w- c:\program files\mozilla firefox\plugins\AppSub32.dll
.

((((((((((((((((((((((((((((( SnapShot@2009-06-20_13.44.18 )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-06-21 19:36 . 2009-06-21 19:36 16384 c:\windows\Temp\Perflib_Perfdata_1bc.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
"updateMgr"="c:\program files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" [2006-03-30 313472]
"RegistryMechanic"="c:\program files\Registry Mechanic\RegMech.exe" [2008-07-08 2828184]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray"="c:\windows\ehome\ehtray.exe" [2005-08-06 64512]
"ATICCC"="c:\program files\ATI Technologies\ATI.ACE\cli.exe" [2005-08-10 61440]
"HPHUPD08"="c:\program files\HP\Digital Imaging\{33D6CC28-9F75-4d1b-A11D-98895B3A3729}\hphupd08.exe" [2005-06-02 49152]
"HPBootOp"="c:\program files\Hewlett-Packard\HP Boot Optimizer\HPBootOp.exe" [2005-02-26 245760]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2007-05-08 54840]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2005-10-18 180269]
"KBD"="c:\hp\KBD\KBD.EXE" [2005-02-02 61440]
"AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2008-11-27 1261336]
"Ad-Watch"="c:\program files\Lavasoft\Ad-Aware\AAWTray.exe" [2009-03-09 515416]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-05-21 148888]
"AlwaysReady Power Message APP"="ARPWRMSG.EXE" - c:\windows\arpwrmsg.exe [2005-08-03 77312]
"RTHDCPL"="RTHDCPL.EXE" - c:\windows\RTHDCPL.EXE [2005-08-18 14820864]
"Kernel and Hardware Abstraction Layer"="KHALMNPR.EXE" - c:\windows\KHALMNPR.Exe [2008-02-29 76304]

c:\documents and settings\Administrator\Start Menu\Programs\Startup\
Webshots.lnk - c:\program files\Webshots\Launcher.exe [2005-12-4 157008]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
Logitech SetPoint.lnk - c:\program files\Logitech\SetPoint\SetPoint.exe [2008-11-2 805392]
Updates from HP.lnk - c:\program files\Updates from HP\9972322\Program\Updates from HP.exe [2005-10-18 36903]
Webshots.lnk - c:\program files\Webshots\Launcher.exe [2005-12-4 157008]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\LBTWlgn]
2008-05-02 08:42 72208 —-a-w- c:\program files\Common Files\Logishrd\Bluetooth\LBTWLgn.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\windows\system32\avgrsstx.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdauxservice]
@=""

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdcoreservice]
@=""

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WdfLoadGroup]
@=""

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Updates from HP\\9972322\\Program\\Updates from HP.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqCopy.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpfccopy.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqPhUnl.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqDIA.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqnrs08.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Downloads\\utorrent.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgemc.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Logitech\\Logitech Harmony Remote Software 7\\HarmonyRemote.exe"=
"c:\\Program Files\\iWin Games\\iWinGames.exe"=
"c:\\Program Files\\iWin Games\\WebUpdater.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3389:TCP"= 3389:TCP:*:Disabled:@xpsp2res.dll,-22009

R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [6/14/2009 5:31 PM 64160]
R1 AvgLdx86;AVG AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [6/16/2008 1:42 PM 97928]
R2 avg8emc;AVG8 E-mail Scanner;c:\progra~1\AVG\AVG8\avgemc.exe [7/3/2008 7:27 PM 875288]
R2 avg8wd;AVG8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [7/3/2008 7:27 PM 231704]
R2 AvgTdiX;AVG8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [6/16/2008 1:42 PM 76040]
R2 iWinTrusted;iWinTrusted;c:\program files\iWin Games\iWinTrusted.exe [1/16/2009 7:18 PM 78104]
R2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [3/9/2009 2:06 PM 951632]
S3 sdAuxService;PC Tools Auxiliary Service;c:\program files\Spyware Doctor\pctsAuxs.exe [2/13/2009 11:25 PM 356920]
.
Contents of the 'Scheduled Tasks' folder

2009-06-15 c:\windows\Tasks\Ad-Aware Update (Weekly).job
- c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2009-03-09 19:06]

2009-06-21 c:\windows\Tasks\Symantec NetDetect.job
- c:\program files\Symantec\LiveUpdate\NDETECT.EXE [2005-10-18 02:24]
.
.
——- Supplementary Scan ——-
.
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid;=ie7&rls;=com.microsoft:en-US&ie;=utf8&oe;=utf8
uSearchURL,(Default) = hxxp://www.google.com/keyword/%s
IE: E&xport; to Microsoft Excel - c:\progra~1\MICROS~4\Office12\EXCEL.EXE/3000
TCP: {C915206A-CD3E-4B35-879A-57BF02D24CA6} = 208.67.220.220,208.67.222.222
FF - ProfilePath -

—- FIREFOX POLICIES —-
c:\program files\Mozilla Firefox\defaults\pref\activex.js - pref("capability.policy.default.ClassID.CIDFE0BD779-44EE-4A4B-AA2E-743C63F2E5E6", "AllAccess");
c:\program files\Mozilla Firefox\defaults\pref\activex.js - pref("capability.policy.default.ClassID.CIDFE0BD779-44EE-4A4B-AA2E-743C63F2E5E6", "AllAccess");
c:\program files\Mozilla Firefox\defaults\pref\activex.js - pref("capability.policy.default.ClassID.CIDFE0BD779-44EE-4A4B-AA2E-743C63F2E5E6", "AllAccess");
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-06-21 14:37
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————

[HKEY_USERS\S-1-5-21-521744339-3598513094-3718192303-1009\Software\Google]
@DACL=(02 0000)

[HKEY_USERS\S-1-5-21-521744339-3598513094-3718192303-1009\Software\Microsoft\Multimedia]
@DACL=(02 0000)

[HKEY_USERS\S-1-5-21-521744339-3598513094-3718192303-1009\Software\Microsoft\SystemCertificates]
@DACL=(02 0000)

[HKEY_USERS\S-1-5-21-521744339-3598513094-3718192303-1009\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced]
@DACL=(02 0000)
"NoNetCrawling"=dword:00000000
"FolderContentsInfoTip"=dword:00000001
"FriendlyTree"=dword:00000001
"WebViewBarricade"=dword:00000001
"DisableThumbnailCache"=dword:00000000
"Hidden"=dword:00000001
"HideFileExt"=dword:00000000
"ShowSuperHidden"=dword:00000000
"SeparateProcess"=dword:00000000
"ClassicViewState"=dword:00000000
"PersistBrowsers"=dword:00000001
"ShowCompColor"=dword:00000001
"ShowInfoTip"=dword:00000001

[HKEY_USERS\S-1-5-21-521744339-3598513094-3718192303-1009\Software\Microsoft\Windows\CurrentVersion\Explorer\CabinetState]
@DACL=(02 0000)
"FullPathAddress"=dword:00000001
"FullPath"=dword:00000001
"Settings"=hex:0c,00,02,00,0b,01,fc,75,60,00,00,00

[HKEY_USERS\S-1-5-21-521744339-3598513094-3718192303-1009\Software\Microsoft\Windows\CurrentVersion\Explorer\HideMyComputerIcons]
@DACL=(02 0000)
"{21EC2020-3AEA-1069-A2DD-08002B30309D}"=dword:00000000

[HKEY_USERS\S-1-5-21-521744339-3598513094-3718192303-1009\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2]
@DACL=(02 0000)

[HKEY_USERS\S-1-5-21-521744339-3598513094-3718192303-1009\Software\Microsoft\Windows\CurrentVersion\Explorer\StartPage]
@DACL=(02 0000)
"FavoritesResolve"=hex:00,00,00,00,00,00,00,00
"Favorites"=hex:00,16,00,00,00,14,00,1f,80,f4,a1,59,25,d7,21,d4,11,bd,af,00,c0,
4f,60,b9,f0,00,00,00,16,00,00,00,14,00,1f,80,f5,a1,59,25,d7,21,d4,11,bd,af,\
"FavoritesChanges"=dword:00000001

[HKEY_USERS\S-1-5-21-521744339-3598513094-3718192303-1009\Software\Microsoft\Windows\CurrentVersion\Explorer\Streams]
@DACL=(02 0000)
"Settings"=hex:08,00,00,00,06,00,00,00,01,00,00,00,e5,25,f1,65,e1,7b,10,48,ba,
9d,d2,71,c8,43,2c,e3,04,00,00,00,02,00,00,00,43,00,00,00

[HKEY_USERS\S-1-5-21-521744339-3598513094-3718192303-1009\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
@DACL=(02 0000)
"ProxyEnable"=dword:00000000
"MigrateProxy"=dword:00000001

[HKEY_USERS\S-1-5-21-521744339-3598513094-3718192303-1009\Software\Microsoft\Windows\CurrentVersion\WinTrust]
@DACL=(02 0000)

[HKEY_USERS\S-1-5-21-521744339-3598513094-3718192303-1009\Software\Microsoft\Windows\Shell]
@DACL=(02 0000)

[HKEY_USERS\S-1-5-21-521744339-3598513094-3718192303-1009\Software\Microsoft\Windows\ShellNoRoam]
@DACL=(02 0000)
@="GODDESS2"

[HKEY_USERS\S-1-5-21-521744339-3598513094-3718192303-1009\Software\Microsoft\Windows NT\CurrentVersion\DiskQuota]
@DACL=(02 0000)

[HKEY_USERS\S-1-5-21-521744339-3598513094-3718192303-1009\Software\Microsoft\Windows NT\CurrentVersion\Network]
@Class="REG_SZ"
@DACL=(02 0000)

[HKEY_USERS\S-1-5-21-521744339-3598513094-3718192303-1009\Software\Google\Google Toolbar\4.0\Options]
@DACL=(02 0000)

[HKEY_USERS\S-1-5-21-521744339-3598513094-3718192303-1009\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content]
@Class="DefaultClass"
@DACL=(02 0000)
"CachePrefix"=""
"CacheLimit"=dword:00706e78

[HKEY_USERS\S-1-5-21-521744339-3598513094-3718192303-1009\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies]
@Class="DefaultClass"
@DACL=(02 0000)
"CachePrefix"="Cookie:"
"CacheLimit"=dword:00002000

[HKEY_USERS\S-1-5-21-521744339-3598513094-3718192303-1009\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache]
@Class="DefaultClass"
@DACL=(02 0000)

[HKEY_USERS\S-1-5-21-521744339-3598513094-3718192303-1009\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History]
@Class="DefaultClass"
@DACL=(02 0000)
"CachePrefix"="Visited:"
"CacheLimit"=dword:00002000

[HKEY_USERS\S-1-5-21-521744339-3598513094-3718192303-1009\Software\Microsoft\Windows\Shell\Bags\1\Desktop]
@DACL=(02 0000)
"Mode"=dword:00000001
"ScrollPos1280x1024(1).x"=dword:00000000
"ScrollPos1280x1024(1).y"=dword:00000000
"Sort"=dword:00000000
"SortDir"=dword:00000001
"Col"=dword:ffffffff
"ColInfo"=hex:00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,fd,df,df,fd,0f,
00,00,00,00,00,00,00,00,00,10,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
"ItemPos1280x1024(1)"=hex:00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,15,
00,00,00,02,00,00,00,14,00,1f,60,40,f0,5f,64,81,50,1b,10,9f,08,00,aa,00,2f,\

[HKEY_USERS\S-1-5-21-521744339-3598513094-3718192303-1009\Software\Microsoft\Windows\ShellNoRoam\BagMRU\0\0]
@DACL=(02 0000)
"0"=hex:4a,00,31,00,00,00,00,00,91,38,7d,6a,10,00,50,52,4f,47,52,41,7e,31,00,
00,32,00,03,00,04,00,ef,be,ee,32,51,86,95,38,15,56,14,00,00,00,50,00,72,00,\
"MRUListEx"=hex:00,00,00,00,ff,ff,ff,ff

[HKEY_USERS\S-1-5-21-521744339-3598513094-3718192303-1009\Software\Microsoft\Windows\ShellNoRoam\Bags\1\Shell]
@DACL=(02 0000)
"Mode"=dword:00000006
"ScrollPos1280x1024(1).x"=dword:00000000
"ScrollPos1280x1024(1).y"=dword:00000000
"Sort"=dword:00000000
"SortDir"=dword:00000001
"Col"=dword:ffffffff
"ColInfo"=hex:00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,fd,df,df,fd,0f,
00,04,00,20,00,10,00,28,00,3c,00,00,00,00,00,01,00,00,00,02,00,00,00,03,00,\
"FolderType"="Documents"

[HKEY_USERS\S-1-5-21-521744339-3598513094-3718192303-500\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{5EB1534C-89A8-4110-9C46-2F24EE5CFD34}*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
"abigkhnjnnemgmhgnedojmjjjebgaiolmo"=hex:61,61,00,00
"bbigkhnjnnemgmhgnekoikojikjepdagcbdk"=hex:61,61,00,00
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'winlogon.exe'(760)
c:\windows\system32\Ati2evxx.dll
c:\program files\common files\logishrd\bluetooth\LBTWlgn.dll
c:\program files\common files\logishrd\bluetooth\LBTServ.dll

- - - - - - - > 'explorer.exe'(300)
c:\docume~1\ADMINI~1\LOCALS~1\Temp\IadHide5.dll
c:\program files\Logitech\SetPoint\GameHook.dll
c:\program files\Logitech\SetPoint\lgscroll.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
———————— Other Running Processes ————————
.
c:\windows\system32\ati2evxx.exe
c:\windows\system32\ati2evxx.exe
c:\windows\arservice.exe
c:\windows\ehome\ehrecvr.exe
c:\windows\ehome\ehSched.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Common Files\LightScribe\LSSrvc.exe
c:\program files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\windows\system32\spool\drivers\w32x86\3\HPZIPM12.EXE
c:\windows\ehome\mcrdsvc.exe
c:\program files\AVG\AVG8\avgrsx.exe
c:\windows\system32\wbem\unsecapp.exe
c:\windows\system32\dllhost.exe
c:\windows\system32\wscntfy.exe
c:\windows\ehome\ehmsas.exe
c:\program files\Common Files\Logishrd\KHAL2\KHALMNPR.exe
.
**************************************************************************
.
Completion time: 2009-06-21 14:46 - machine was rebooted
ComboFix-quarantined-files.txt 2009-06-21 19:46
ComboFix2.txt 2009-06-20 13:51

Pre-Run: 35,940,933,632 bytes free
Post-Run: 35,926,536,192 bytes free

326 — E O F — 2009-06-19 08:21
Malware finished!! And it was only 400,000 files with no malicious items found! Here's the log: Malwarebytes' Anti-Malware 1.38 Database version: 2319 Windows 5.1.2600 Service Pack 3 6/21/2009 4:18:49 PM mbam-log-2009-06-21 (16-18-49).txt Scan type: Full Scan (C:\|E:\|) Objects scanned: 399246 Time elapsed: 1 hour(s), 20 minute(s), 39 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 0 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 0 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: (No malicious items detected) Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: (No malicious items detected)

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI