This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved]  Need Help with Complete Removal of AntiVirus Pro 2010

25 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

My PC was infected with Anti-Virus Pro 2010, and I am having difficulty completing the removal. Thank you in advance for your help.

Infection was first noted on 9/4/09. My child was using the PC at the time, so I don't know the specific details of how the infection occurred.

I am running Avast 4.8 Home, and was able to run a boot scan. Avast identified several infected files (cru629.dat, beep.sys, scui.cp1, BraviaX.exe), and I moved them all into quarantine in the virus chest. However, on reboot, Anti-Virus Pro reinstalled.

Next, I followed the instructions here: http://www.whatthetech.com/2009/09/03/how-…anti-virus-pro/

This procedure did not go quite as expected, as follows:

1. I was not blocked from accessing the Task Manager, so I did not download or run the Fixtm.reg file.

2. In the Task Manager, I terminated Anti-Virus Pro.exe, but I did not have any instances of svchast.exe running.

3. I ran Malwarebytes Anti-Malware, and it located a number of infected files, which I removed. However, upon restart, I still got the Anti-Virus Pro startup screen and task tray icon, although the exe no longer seemed to be running (it did not reappear in Task Manager). At this point, I was also able to reactivate Windows Firewall (which Anti-Virus Pro had apparently disabled).

4. Using msconfig, I found and disabled a startup item for Anti-Virus Pro. I also disabled two other items that were suspicious because their "Startup Item" and "Command" fields were blank.

5. After reboot, I did not see the Anti-Virus Pro startup screen or task tray icon. I ran Malwarebytes Anti-Malware again, and it found an additional three items, which I removed.

6. After reboot, I ran Malwarebytes Anti-Malware a third time, and this time got a clean result.

After the above steps, the PC appears to be operating normally. However, I am concerned because Anti-Virus Pro still shows up as an installed program in the Add or Remove Programs Utility. Also, those startup items are still listed in msconfig (although now disabled).

Below are the log files from all three runs of Malwarebytes Anti-Malware, along with a current HijackThis log file.


======= Anti-Malware 1st Run =========

Malwarebytes' Anti-Malware 1.40
Database version: 2744
Windows 5.1.2600 Service Pack 3

9/5/2009 8:20:29 AM
mbam-log-2009-09-05 (08-20-29).txt

Scan type: Quick Scan
Objects scanned: 149488
Time elapsed: 29 minute(s), 23 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 4
Registry Data Items Infected: 6
Folders Infected: 0
Files Infected: 10

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
HKEY_CURRENT_USER\Control Panel\don't load\scui.cpl (Hijack.SecurityCenter) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\Control Panel\don't load\wscui.cpl (Hijack.SecurityCenter) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\ForceClassicControlPanel (Hijack.ControlPanelStyle) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\braviax (Trojan.Downloader) -> Quarantined and deleted successfully.

Registry Data Items Infected:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Security Center\AntiVirusDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Security Center\FirewallDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Security Center\UpdatesDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\AntiVirusDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\FirewallDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\UpdatesDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.

Folders Infected:
(No malicious items detected)

Files Infected:
C:\WINDOWS\system32\wisdstr.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
C:\Documents and Settings\Eric\Local Settings\Temp\msupd_2.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
C:\Documents and Settings\Katie\Local Settings\Temp\90.tmp (Trojan.Dropper) -> Quarantined and deleted successfully.
C:\Documents and Settings\Katie\Local Settings\Temp\msupd_2.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
C:\Documents and Settings\Katie\Local Settings\Temporary Internet Files\Content.IE5\JQURKJR2\Install[1].exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
C:\Program Files\Common Files\axyti.dll (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\~.exe (Backdoor.Bot) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\braviax.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
C:\Documents and Settings\Eric\Local Settings\Temporary Internet Files\aqabazakih.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\braviax.exe (Trojan.Downloader) -> Quarantined and deleted successfully.


======= Anti-Malware 2nd Run =========

Malwarebytes' Anti-Malware 1.40
Database version: 2744
Windows 5.1.2600 Service Pack 3

9/5/2009 8:59:49 AM
mbam-log-2009-09-05 (08-59-49).txt

Scan type: Quick Scan
Objects scanned: 134465
Time elapsed: 11 minute(s), 6 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 3
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\AntiVirusDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\FirewallDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\UpdatesDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)


======= Anti-Malware 3rd Run =========

Malwarebytes' Anti-Malware 1.40
Database version: 2744
Windows 5.1.2600 Service Pack 3

9/5/2009 9:19:29 AM
mbam-log-2009-09-05 (09-19-29).txt

Scan type: Quick Scan
Objects scanned: 134505
Time elapsed: 11 minute(s), 15 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)


======= HijackThis Log File = =========

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 9:24:41 AM, on 9/5/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\System32\CTsvcCDA.exe
c:\program files\dell printers\Additional Color Laser Software\Status Monitor\DLSDBNT.EXE
C:\Program Files\DriveCrypt\DcrServ.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\M-Audio\M-Audio Series II MIDI\MA_CMIDI_Inst.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\dllhost.exe
C:\Program Files\UPHClean\uphclean.exe
C:\WINDOWS\System32\vssvc.exe
C:\WINDOWS\System32\MsPMSPSv.exe
C:\WINDOWS\system32\ZuneBusEnum.exe
c:\program files\dell printers\Additional Color Laser Software\Status Monitor\DLPWDNT.EXE
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\System32\dllhost.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\System32\wbem\wmiapsrv.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Creative\SBAudigy2ZS\Surround Mixer\CTSysVol.exe
C:\Program Files\Creative\SBAudigy2ZS\DVDAudio\CTDVDDET.EXE
C:\WINDOWS\system32\CTHELPER.EXE
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\Roxio\Easy CD Creator 6\DragToDisc\DrgToDsc.exe
C:\Program Files\Roxio\Easy CD Creator 6\AudioCentral\RxMon.exe
C:\Program Files\Creative\Prodikeys\Prodload.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\Roland\VSC32\vsc32cnf.exe
C:\Program Files\Roland\VSC32\vscvol.exe
C:\PROGRA~1\Sony\SONICS~1\SsAAD.exe
C:\program files\dell printers\Additional Color Laser Software\Status Monitor\DLPSP.EXE
C:\Program Files\Brother\Brmfcmon\BrMfcWnd.exe
C:\Program Files\Zune\ZuneLauncher.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Logitech\Profiler\lwemon.exe
C:\Program Files\Creative\MediaSource\RemoteControl\RcMan.exe
C:\Program Files\Creative\MediaSource\Go\CTCMSGo.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Roxio\Easy CD Creator 6\AudioCentral\Playlist.exe
C:\Program Files\Brother\ControlCenter3\brccMCtl.exe
C:\Program Files\Brother\Brmfcmon\BrMfimon.exe
C:\Documents and Settings\Eric\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Eric\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Eric\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O4 - HKLM\..\Run: [CTSysVol] C:\Program Files\Creative\SBAudigy2ZS\Surround Mixer\CTSysVol.exe /r
O4 - HKLM\..\Run: [CTDVDDET] C:\Program Files\Creative\SBAudigy2ZS\DVDAudio\CTDVDDET.EXE
O4 - HKLM\..\Run: [CTHelper] CTHELPER.EXE
O4 - HKLM\..\Run: [SBDrvDet] C:\Program Files\Creative\SB Drive Det\SBDrvDet.exe /r
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [RoxioEngineUtility] "C:\Program Files\Common Files\Roxio Shared\System\EngUtil.exe"
O4 - HKLM\..\Run: [RoxioDragToDisc] "C:\Program Files\Roxio\Easy CD Creator 6\DragToDisc\DrgToDsc.exe"
O4 - HKLM\..\Run: [RoxioAudioCentral] "C:\Program Files\Roxio\Easy CD Creator 6\AudioCentral\RxMon.exe"
O4 - HKLM\..\Run: [PinnacleDriverCheck] C:\WINDOWS\System32\PSDrvCheck.exe -CheckReg
O4 - HKLM\..\Run: [ProdikeysAutorun] "C:\Program Files\Creative\Prodikeys\Prodload.exe"
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [vsc32cnf.exe] C:\Program Files\Roland\VSC32\vsc32cnf.exe
O4 - HKLM\..\Run: [vscvol.exe] C:\Program Files\Roland\VSC32\vscvol.exe
O4 - HKLM\..\Run: [SsAAD.exe] C:\PROGRA~1\Sony\SONICS~1\SsAAD.exe
O4 - HKLM\..\Run: [DLPSP] "c:\program files\dell printers\Additional Color Laser Software\Status Monitor\DLPSP.EXE"
O4 - HKLM\..\Run: [ISUSPM Startup] "C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [SSBkgdUpdate] "C:\Program Files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" -Embedding -boot
O4 - HKLM\..\Run: [BrMfcWnd] C:\Program Files\Brother\Brmfcmon\BrMfcWnd.exe /AUTORUN
O4 - HKLM\..\Run: [ControlCenter3] C:\Program Files\Brother\ControlCenter3\brctrcen.exe /autorun
O4 - HKLM\..\Run: [Zune Launcher] "C:\Program Files\Zune\ZuneLauncher.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKCU\..\Run: [Start WingMan Profiler] "C:\Program Files\Logitech\Profiler\lwemon.exe" /noui
O4 - HKCU\..\Run: [RemoteCenter] C:\Program Files\Creative\MediaSource\RemoteControl\RcMan.exe
O4 - HKCU\..\Run: [Creative MediaSource Go] C:\Program Files\Creative\MediaSource\Go\CTCMSGo.exe /SCB
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Google Update] "C:\Documents and Settings\Eric\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" /c
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {01113300-3E00-11D2-8470-0060089874ED} (Support.com Configuration Class) - https://activatemyfios.verizon.net/sdcCommo…20Installer.cab
O16 - DPF: {0A5FD7C5-A45C-49FC-ADB5-9952547D5715} (Creative Software AutoUpdate) - http://www.creative.com/su/ocx/15026/CTSUEng.cab
O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} (Snapfish Activia) - http://www.snapfish.com/SnapfishActivia.cab
O16 - DPF: {4CCA4E6B-9259-11D9-AC6E-444553544200} (FixController Control) - http://h30155.www3.hp.com/ediags/dd/instal…tallMgr_v01.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1136547307687
O16 - DPF: {8A0019EB-51FA-4AE5-A40B-C0496BBFC739} (Verizon Wireless Media Upload) - http://picture.vzw.com/activex/VerizonWire…loadControl.cab
O16 - DPF: {A90A5822-F108-45AD-8482-9BC8B12DD539} (Crucial cpcScan) - http://www.crucial.com/controls/cpcScanner.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} (Creative Software AutoUpdate Support Package) - http://www.creative.com/su/ocx/15026/CTPID.cab
O20 - AppInit_DLLs: cru629.dat
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\System32\CTsvcCDA.exe
O23 - Service: Dell Printer Status Watcher (DLPWD) - Dell Inc. - c:\program files\dell printers\Additional Color Laser Software\Status Monitor\DLPWDNT.EXE
O23 - Service: Dell Printer Status Database (DLSDB) - Dell Inc. - c:\program files\dell printers\Additional Color Laser Software\Status Monitor\DLSDBNT.EXE
O23 - Service: DriveCrypt Service (DriveCryptService) - Unknown owner - C:\Program Files\DriveCrypt\DcrServ.exe
O23 - Service: getPlus® Helper - NOS Microsystems Ltd. - C:\Program Files\NOS\bin\getPlus_HelperSvc.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: M-Audio Series II MIDI Installer (MA_CMIDI_InstallerService) - Unknown owner - C:\Program Files\M-Audio\M-Audio Series II MIDI\MA_CMIDI_Inst.exe
O23 - Service: MSCSPTISRV - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\MSCSPTISRV.exe
O23 - Service: PACSPTISVR - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe
O23 - Service: SonicStage SCSI Service (SSScsiSV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SSScsiSV.exe

–
End of file - 10787 bytes
Hi modena2904, welcome to the forum.

To make cleaning this machine easier
  • Please do not uninstall/install any programs unless asked to
    It is more difficult when files/programs are appearing in/disappearing from the logs.
  • Please do not run any scans other than those requested
  • Please follow all instructions in the order posted
  • All logs/reports, etc.. must be posted in Notepad. Please ensure that word wrap is unchecked. In notepad click format, uncheck word wrap if it is checked.
  • Do not attach any logs/reports, etc.. unless specifically requested to do so.
  • If you have problems with or do not understand the instructions, Please ask before continuing.
  • Please stay with this thread until given the All Clear. A absence of symptoms does not mean a clean machine.

Please read through the instructions to familarize youself with what to expect when the tool runs.

It is vitally important that combofix is renamed before it is even started to download


Please download ComboFix from Here or Here to your Desktop.

**Note: In the event you already have Combofix, this is a new version that I need you to download. It is important that it is saved directly to your desktop**

  • If you are using Firefox, make sure that your download settings are as follows:
    -Tools->Options->Main tab
    -Set to "Always ask me where to Save the files".
  • During the download, rename Combofix to Combo-Fix as follows:

[external image: Posted Image]

[external image: Posted Image]

  • It is important you rename Combofix during the download, but not after.
  • Please do not rename Combofix to other names, but only to the one indicated.
  • Close any open browsers.
  • Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix

———————————————————–

  • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before performing a scan. They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
  • Click on this link to see a list of programs that should be disabled. The list is not all inclusive. If yours is not listed and you don't know how to disable it, please ask.

    ———————————————————–

  • Double click on ComboFix.exe & follow the prompts.
  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.
  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.

[external image: Posted Image]


Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]

Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.

Notes:

1.Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. ComboFix may reset a number of Internet Explorer's settings, including making I-E the default browser.
3. Combofix prevents autorun of ALL CD, floppy and USB devices to assist with malware removal & increase security. If this is an issue or makes it difficult for you – please tell your helper.
4. CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.


Next

Please make an uninstall list
  • Start HijackThis
  • Click the Config button
  • Click the Misc Tools button
  • Click the Open Uninstall Manager button.
  • Click the Save list button and save it to your desktop.
When you press Save, a notepad will open with the contents. Copy/paste the contents of the notepad file in your next reply.



Please post back with the combofix log and the uninstall list. How is the computer at the moment?

Thanks
Thanks for your guidance. I have executed the steps as outlined. The only unexpected result was that I got a notification box titled "Hot Keys Configuration" – this occurred three times while ComboFix was running. I clicked "ok" each time. The ComboFix log and HijackThis uninstall list are pasted below. The PC appears to be running normally. The only change I notice after running ComboFix is that under msconfig startup items, the two blank items that I had previously disabled are now gone completely. Anti-Virus Pro still appears as a disabled startup item, and it still appears in the add/remove programs list. Thanks. - Eric ========= CombiFix Log ========== ComboFix 09-09-04.02 - Eric 09/05/2009 12:42.1.1 - NTFSx86 Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1535.1026 [GMT -4:00] Running from: d:\users\[removed]\Desktop\Combo-Fix.exe AV: avast! antivirus 4.8.1351 [VPS 090904-0] *On-access scanning disabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D} . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . c:\docume~1\Eric\LOCALS~1\Temp\catchme.dll c:\documents and settings\All Users\Application Data\apemela.pif c:\documents and settings\All Users\Application Data\ezagixegy.bin c:\documents and settings\All Users\Application Data\imorak.lib c:\documents and settings\All Users\Application Data\irufo.dl c:\documents and settings\All Users\Application Data\laqi.lib c:\documents and settings\All Users\Application Data\newe.scr c:\documents and settings\All Users\Application Data\opibycigem.dll c:\documents and settings\All Users\Application Data\pahohulo.pif c:\documents and settings\All Users\Application Data\xekykyw.reg c:\documents and settings\All Users\Application Data\yxylimato.dl c:\documents and settings\All Users\Documents\fybajawocy.reg c:\documents and settings\All Users\Documents\kazozimewe.ban c:\documents and settings\All Users\Documents\obutoby.ban c:\documents and settings\All Users\Documents\omyvek.bat c:\documents and settings\Eric\Application Data\afimur._dl c:\documents and settings\Eric\Application Data\inst.exe c:\documents and settings\Eric\Application Data\oqape.lib c:\documents and settings\Eric\Application Data\umefe.vbs c:\documents and settings\Eric\Application Data\ypinu.sys c:\documents and settings\Eric\Cookies\adozy.ban c:\documents and settings\Eric\Cookies\bogihone.com c:\documents and settings\Eric\Cookies\ohotom.scr c:\documents and settings\Eric\Cookies\ywyjusemow.scr c:\documents and settings\Eric\Local Settings\Application Data\{B7080EEB-ED19-455C-BFA8-12EEC8A20D83} c:\documents and settings\Eric\Local Settings\Application Data\{B7080EEB-ED19-455C-BFA8-12EEC8A20D83}\chrome.manifest c:\documents and settings\Eric\Local Settings\Application Data\{B7080EEB-ED19-455C-BFA8-12EEC8A20D83}\chrome\content\_cfg.js c:\documents and settings\Eric\Local Settings\Application Data\{B7080EEB-ED19-455C-BFA8-12EEC8A20D83}\chrome\content\c.js c:\documents and settings\Eric\Local Settings\Application Data\{B7080EEB-ED19-455C-BFA8-12EEC8A20D83}\chrome\content\overlay.xul c:\documents and settings\Eric\Local Settings\Application Data\{B7080EEB-ED19-455C-BFA8-12EEC8A20D83}\install.rdf c:\documents and settings\Eric\Local Settings\Application Data\nogyde.com c:\documents and settings\Eric\Local Settings\Application Data\xivugunyti._dl c:\documents and settings\Eric\Local Settings\Application Data\ybyjedyme.scr c:\documents and settings\Eric\Local Settings\Temp\catchme.dll c:\documents and settings\Eric\Local Settings\Temporary Internet Files\evacuno.ban c:\documents and settings\Eric\Local Settings\Temporary Internet Files\gufuf.inf c:\documents and settings\Eric\Local Settings\Temporary Internet Files\joqurazano.db c:\documents and settings\Eric\Local Settings\Temporary Internet Files\numacakeqo.bin c:\documents and settings\Eric\Local Settings\Temporary Internet Files\runidol.sys c:\documents and settings\Katie\Application Data\nadanagex.pif c:\documents and settings\Katie\Application Data\ubal.dll c:\documents and settings\Katie\Application Data\vipirasi._sy c:\documents and settings\Katie\Application Data\xyryqytab.pif c:\documents and settings\Katie\Application Data\zegopinuja.ban c:\documents and settings\Katie\Application Data\zejece.inf c:\documents and settings\Katie\Cookies\akofefoj.bin c:\documents and settings\Katie\Cookies\igamypa.dll c:\documents and settings\Katie\Cookies\logyre.ban c:\documents and settings\Katie\Cookies\lydoky.dat c:\documents and settings\Katie\Cookies\uvobojy.ban c:\documents and settings\Katie\Cookies\ypitimapuz.sys c:\documents and settings\Katie\Local Settings\Application Data\ecygesul.ban c:\documents and settings\Katie\Local Settings\Application Data\nudexoxi.dll c:\documents and settings\Katie\Local Settings\Application Data\zukipil.pif c:\documents and settings\Katie\Local Settings\Temporary Internet Files\adujate.bat c:\documents and settings\Katie\Local Settings\Temporary Internet Files\edepazorum._sy c:\documents and settings\Katie\Local Settings\Temporary Internet Files\rajamaqyzo.db c:\documents and settings\Katie\Local Settings\Temporary Internet Files\ukahiqixul.ban c:\documents and settings\Katie\Local Settings\Temporary Internet Files\vehiqo.db c:\program files\Common Files\gidaqyv.bin c:\program files\Common Files\hulyhy.bat c:\program files\Common Files\koxa.ban c:\program files\Common Files\lojeromiro.inf c:\program files\Common Files\nuhebisuby.exe c:\program files\Common Files\toxe.pif c:\program files\Common Files\valyd.dl c:\program files\Common Files\vyhynobeq.com c:\program files\Common Files\wykij.dl c:\program files\Common Files\yjepavelid._dl c:\program files\Common Files\zalamukyde.scr c:\windows\bumim.vbs c:\windows\buzysadur.dl c:\windows\dizod.reg c:\windows\eluxod.ban c:\windows\hosozazumu.pif c:\windows\Installer\1c80a1.msi c:\windows\Installer\4a697.msi c:\windows\kugawo.vbs c:\windows\mibexul.pif c:\windows\nigyrezusu.reg c:\windows\razudysek.reg c:\windows\system32\jytygu.bat c:\windows\system32\qozocy.reg c:\windows\system32\vocuqizy.scr c:\windows\ufebereqiw.exe c:\windows\ulihogela.ban c:\windows\uzes.exe c:\windows\vojegyg.dl c:\windows\wpd99.drv c:\windows\wuruse.ban c:\windows\wycyxari.bin c:\windows\wyzyh.exe . ((((((((((((((((((((((((( Files Created from 2009-08-05 to 2009-09-05 ))))))))))))))))))))))))))))))) . 2009-09-05 11:45 . 2009-09-05 11:45 ——– d—–w- c:\documents and settings\Eric\Application Data\Malwarebytes 2009-09-05 11:45 . 2009-08-03 17:36 38160 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys 2009-09-05 11:45 . 2009-09-05 12:20 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware 2009-09-05 11:45 . 2009-09-05 11:45 ——– d—–w- c:\documents and settings\All Users\Application Data\Malwarebytes 2009-09-05 11:45 . 2009-08-03 17:36 19096 —-a-w- c:\windows\system32\drivers\mbam.sys 2009-09-05 11:30 . 2009-09-05 11:30 10296 —-a-w- c:\documents and settings\Katie\Local Settings\Application Data\jecuviwy.dat 2009-09-05 11:30 . 2009-09-05 11:30 12233 —-a-w- c:\windows\type.com 2009-09-05 03:16 . 2009-09-05 03:17 ——– d—–w- c:\program files\AntivirusPro_2010 2009-09-05 03:07 . 2009-09-05 03:07 19159 —-a-w- c:\documents and settings\Eric\Local Settings\Application Data\kirure.dat 2009-09-05 03:07 . 2009-09-05 03:07 18736 —-a-w- c:\windows\xidusoveh.com 2009-09-05 03:07 . 2009-09-05 03:07 18142 —-a-w- c:\windows\system32\covatuhe.dat 2009-09-05 03:07 . 2009-09-05 03:07 13619 —-a-w- c:\windows\yqujup.com 2009-09-04 20:59 . 2009-09-04 20:59 15085 —-a-w- c:\windows\oqadyzi.com 2009-09-03 23:29 . 2009-09-03 23:29 ——– d-sh–w- c:\documents and settings\Katie\IECompatCache 2009-08-25 17:14 . 2009-08-25 17:14 ——– d—–w- c:\documents and settings\Katie Lou\Local Settings\Application Data\WMTools Downloaded Files 2009-08-14 20:24 . 2009-08-14 20:24 ——– d-sh–w- c:\documents and settings\Brian\IECompatCache 2009-08-13 06:40 . 2009-07-10 13:27 1315328 -c—-w- c:\windows\system32\dllcache\msoe.dll . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2009-09-05 14:08 . 2004-12-30 20:46 384 —-a-w- c:\windows\system32\DVCStateBkp-{00000000-00000000-0000000E-00001102-00000004-20021102}.dat 2009-09-05 14:08 . 2004-12-30 20:46 384 —-a-w- c:\windows\system32\DVCState-{00000000-00000000-0000000E-00001102-00000004-20021102}.dat 2009-09-05 13:24 . 2004-03-15 02:15 ——– d—–w- c:\program files\Trend Micro 2009-09-05 11:33 . 2009-09-05 11:33 13920 —-a-w- c:\program files\Common Files\ycefe.db 2009-09-05 03:07 . 2009-09-05 03:07 14486 —-a-w- c:\documents and settings\All Users\Application Data\juci.dat 2009-09-05 03:07 . 2009-09-05 03:07 11354 —-a-w- c:\program files\Common Files\ekihom._sy 2009-09-03 18:56 . 2009-05-07 17:32 ——– d—–w- c:\documents and settings\Katie\Application Data\AdobeUM 2009-08-30 21:57 . 2008-06-21 19:59 ——– d—–w- c:\program files\Firefox 2009-08-25 00:44 . 2006-06-27 01:23 ——– d—–w- c:\documents and settings\Eric\Application Data\AdobeUM 2009-08-17 16:10 . 2005-04-30 15:04 1279456 —-a-w- c:\windows\system32\aswBoot.exe 2009-08-17 16:06 . 2004-10-24 23:51 93392 —-a-w- c:\windows\system32\drivers\aswmon.sys 2009-08-17 16:06 . 2004-10-24 23:51 94160 —-a-w- c:\windows\system32\drivers\aswmon2.sys 2009-08-17 16:05 . 2008-04-05 12:36 114768 —-a-w- c:\windows\system32\drivers\aswSP.sys 2009-08-17 16:05 . 2008-04-05 12:36 20560 —-a-w- c:\windows\system32\drivers\aswFsBlk.sys 2009-08-17 16:04 . 2005-04-30 15:04 23152 —-a-w- c:\windows\system32\drivers\aswRdr.sys 2009-08-17 16:03 . 2004-10-24 23:51 26944 —-a-w- c:\windows\system32\drivers\aavmker4.sys 2009-08-17 16:02 . 2004-10-24 23:51 97480 —-a-w- c:\windows\system32\AVASTSS.scr 2009-08-05 09:01 . 2004-03-27 00:30 204800 —-a-w- c:\windows\system32\mswebdvd.dll 2009-07-29 17:45 . 2004-11-04 19:56 54416 —-a-w- c:\documents and settings\Brian\Local Settings\Application Data\GDIPFONTCACHEV1.DAT 2009-07-27 17:33 . 2006-07-15 20:24 54416 —-a-w- c:\documents and settings\Katie\Local Settings\Application Data\GDIPFONTCACHEV1.DAT 2009-07-27 01:29 . 2004-07-05 22:37 54416 —-a-w- c:\documents and settings\Eric\Local Settings\Application Data\GDIPFONTCACHEV1.DAT 2009-07-27 00:03 . 2009-07-27 00:03 126456 —-a-w- c:\documents and settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat 2009-07-26 23:43 . 2009-07-26 23:37 ——– d—–w- c:\program files\NOS 2009-07-26 23:43 . 2009-07-26 23:37 ——– d—–w- c:\documents and settings\All Users\Application Data\NOS 2009-07-17 19:01 . 2003-03-31 12:00 58880 —-a-w- c:\windows\system32\atl.dll 2009-07-14 03:43 . 2004-03-27 00:46 286208 —-a-w- c:\windows\system32\wmpdxm.dll 2009-07-12 18:19 . 2009-07-12 18:19 ——– d—–w- c:\program files\CCleaner 2009-07-03 17:09 . 2004-02-06 22:05 915456 —-a-w- c:\windows\system32\wininet.dll 2009-06-25 08:25 . 2003-03-31 12:00 730112 —-a-w- c:\windows\system32\lsasrv.dll 2009-06-25 08:25 . 2003-03-31 12:00 56832 —-a-w- c:\windows\system32\secur32.dll 2009-06-25 08:25 . 2003-03-31 12:00 54272 —-a-w- c:\windows\system32\wdigest.dll 2009-06-25 08:25 . 2003-03-31 12:00 301568 —-a-w- c:\windows\system32\kerberos.dll 2009-06-25 08:25 . 2003-03-31 12:00 147456 —-a-w- c:\windows\system32\schannel.dll 2009-06-25 08:25 . 2003-03-31 12:00 136192 —-a-w- c:\windows\system32\msv1_0.dll 2009-06-24 11:18 . 2003-03-31 12:00 92928 —-a-w- c:\windows\system32\drivers\ksecdd.sys 2009-06-16 14:36 . 2003-03-31 12:00 81920 —-a-w- c:\windows\system32\fontsub.dll 2009-06-16 14:36 . 2003-03-31 12:00 119808 —-a-w- c:\windows\system32\t2embed.dll 2009-06-12 12:31 . 2003-03-31 12:00 80896 —-a-w- c:\windows\system32\tlntsess.exe 2009-06-12 12:31 . 2003-03-31 12:00 76288 —-a-w- c:\windows\system32\telnet.exe 2009-06-10 14:13 . 2003-03-31 12:00 84992 —-a-w- c:\windows\system32\avifil32.dll 2009-06-10 13:19 . 2004-03-13 01:50 2066432 —-a-w- c:\windows\system32\mstscax.dll 2009-06-10 06:14 . 2003-03-31 12:00 132096 —-a-w- c:\windows\system32\wkssvc.dll 2008-08-31 20:09 . 2008-08-31 20:09 0 —-a-w- c:\program files\error.dat . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Start WingMan Profiler"="c:\program files\Logitech\Profiler\lwemon.exe" [2003-08-07 77824] "RemoteCenter"="c:\program files\Creative\MediaSource\RemoteControl\RcMan.exe" [2003-11-21 143360] "Creative MediaSource Go"="c:\program files\Creative\MediaSource\Go\CTCMSGo.exe" [2003-08-12 131072] "Google Update"="c:\documents and settings\Eric\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" [2008-11-07 133104] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "CTSysVol"="c:\program files\Creative\SBAudigy2ZS\Surround Mixer\CTSysVol.exe" [2003-07-02 57344] "CTDVDDET"="c:\program files\Creative\SBAudigy2ZS\DVDAudio\CTDVDDET.EXE" [2003-06-18 45056] "SBDrvDet"="c:\program files\Creative\SB Drive Det\SBDrvDet.exe" [2002-12-03 45056] "UpdReg"="c:\windows\UpdReg.EXE" [2000-05-11 90112] "ATIPTA"="c:\program files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2003-12-12 335872] "RoxioEngineUtility"="c:\program files\Common Files\Roxio Shared\System\EngUtil.exe" [2003-05-01 65536] "RoxioDragToDisc"="c:\program files\Roxio\Easy CD Creator 6\DragToDisc\DrgToDsc.exe" [2003-06-25 868352] "RoxioAudioCentral"="c:\program files\Roxio\Easy CD Creator 6\AudioCentral\RxMon.exe" [2003-06-24 319488] "PinnacleDriverCheck"="c:\windows\System32\PSDrvCheck.exe" [2003-12-04 406016] "ProdikeysAutorun"="c:\program files\Creative\Prodikeys\Prodload.exe" [2003-08-27 131072] "avast!"="c:\progra~1\ALWILS~1\Avast4\ashDisp.exe" [2009-08-17 81000] "vsc32cnf.exe"="c:\program files\Roland\VSC32\vsc32cnf.exe" [2000-02-07 36864] "vscvol.exe"="c:\program files\Roland\VSC32\vscvol.exe" [2000-02-09 36864] "SsAAD.exe"="c:\progra~1\Sony\SONICS~1\SsAAD.exe" [2006-01-07 81920] "DLPSP"="c:\program files\dell printers\Additional Color Laser Software\Status Monitor\DLPSP.EXE" [2005-01-13 126976] "ISUSPM Startup"="c:\program files\Common Files\InstallShield\UpdateService\isuspm.exe" [2005-08-11 249856] "ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2005-08-11 81920] "SSBkgdUpdate"="c:\program files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" [2006-10-25 210472] "BrMfcWnd"="c:\program files\Brother\Brmfcmon\BrMfcWnd.exe" [2007-11-06 741376] "ControlCenter3"="c:\program files\Brother\ControlCenter3\brctrcen.exe" [2007-10-30 77824] "Zune Launcher"="c:\program files\Zune\ZuneLauncher.exe" [2008-11-10 157312] "QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2009-01-05 413696] "iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-03-13 342312] "SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-05-21 148888] "CTHelper"="CTHELPER.EXE" - c:\windows\system32\CTHELPER.EXE [2003-10-06 24576] c:\documents and settings\All Users\Start Menu\Programs\Startup\ Microsoft Office.lnk - c:\program files\Microsoft Office\Office\OSA9.EXE [2000-1-21 65588] [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32] "WAVE1"=vscapi.dll "Midi1"=PRODMI32.DLL "Midi2"=vscapi.dll "Midi3"=ProdMidi.dll "midi4"=ma_cmidn.dll "midi5"=ma_cmidn.dll "midi6"=ma_cmidn.dll [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys] @="Driver" [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List] "c:\\WINDOWS\\system32\\sessmgr.exe"= "c:\\Program Files\\BitTornado\\btdownloadgui.exe"= "c:\\Program Files\\Adobe\\Photoshop Album\\Apps\\PhotoshopAlbum.exe"= "c:\\WINDOWS\\system32\\dplaysvr.exe"= "%windir%\\Network Diagnostic\\xpnetdiag.exe"= "c:\\WINDOWS\\system32\\ftp.exe"= "%windir%\\system32\\sessmgr.exe"= "c:\\Program Files\\Brother\\Brmfl07b\\FAXRX.exe"= "c:\\Program Files\\Brother\\BRAdmin Light\\BRAdmLight.exe"= "l:\\Sierra2\\gplsecrets\\iGOR\\iGOR.exe"= "c:\\Program Files\\Microsoft Games\\Monster Truck Madness 2\\monster.exe"= "c:\\Program Files\\Bonjour\\mDNSResponder.exe"= "c:\\Program Files\\iTunes\\iTunes.exe"= [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List] "54925:UDP"= 54925:UDP:Brother Network Scanner "6881:TCP"= 6881:TCP:Bit Torrent 1 "6882:TCP"= 6882:TCP:Bit Torrent 2 "6883:TCP"= 6883:TCP:Bit Torrent 3 "6884:TCP"= 6884:TCP:Bit Torrent 4 "6885:TCP"= 6885:TCP:Bit Torrent 5 "6886:TCP"= 6886:TCP:Bit Torrent 6 "6887:TCP"= 6887:TCP:Bit Torrent 7 "6888:TCP"= 6888:TCP:Bit Torrent 8 "6889:TCP"= 6889:TCP:Bit Torrent 9 R0 DCR;DCR;c:\windows\system32\drivers\DCR.sys [4/3/2004 6:16 PM 224800] R0 viasraid;viasraid;c:\windows\system32\drivers\viasraid.sys [3/13/2004 2:07 PM 77312] R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [4/5/2008 8:36 AM 114768] R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [4/5/2008 8:36 AM 20560] R2 DLSDB;Dell Printer Status Database;c:\program files\Dell Printers\Additional Color Laser Software\Status Monitor\dlsdbnt.exe [3/4/2006 5:02 PM 135168] R2 DriveCryptService;DriveCrypt Service;c:\program files\DriveCrypt\DcrServ.exe [4/3/2004 6:16 PM 208012] R2 PfDetNT;PfDetNT;c:\windows\system32\drivers\PFModNT.sys [3/26/2004 11:49 PM 15840] R2 RVIEGVST;VSC VST Engine;c:\program files\Roland\Virtual Sound Canvas VST\RVIEg01VST.sys [6/21/2005 9:09 PM 188276] R3 Prodikeys;Creative Prodikeys Driver;c:\windows\system32\drivers\ProdDrvr.sys [6/6/2004 1:55 PM 14392] R3 vsc32;Virtual Sound Canvas 3.2;c:\windows\system32\drivers\vsc.sys [6/21/2005 9:08 PM 951284] S2 BridDfu;LINKSYS WAP11 USB Device Driver;c:\windows\system32\drivers\BridDFU.sys [5/1/2004 8:47 PM 16302] S3 ATIXPGAA;ATIXPGAA;\??\c:\program files\ASUS\SmartDoctor\ATIXPGAA.SYS –> c:\program files\ASUS\SmartDoctor\ATIXPGAA.SYS [?] S3 getPlus® Helper;getPlus® Helper;c:\program files\NOS\bin\getPlus_HelperSvc.exe [7/26/2009 7:43 PM 66056] — Other Services/Drivers In Memory — *Deregistered* - uphcleanhlp [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}] "c:\windows\system32\rundll32.exe" "c:\windows\system32\iedkcs32.dll",BrandIEActiveSetup SIGNUP . Contents of the 'Scheduled Tasks' folder 2009-08-31 c:\windows\Tasks\AppleSoftwareUpdate.job - c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 16:34] 2009-09-04 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2000478354-1177238915-725345543-1004Core.job - c:\documents and settings\Eric\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2008-11-07 01:15] 2009-09-05 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2000478354-1177238915-725345543-1004UA.job - c:\documents and settings\Eric\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2008-11-07 01:15] 2009-09-04 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2000478354-1177238915-725345543-1006Core.job - c:\documents and settings\Brian\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2008-12-03 22:30] 2009-09-05 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2000478354-1177238915-725345543-1006UA.job - c:\documents and settings\Brian\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2008-12-03 22:30] 2009-09-05 c:\windows\Tasks\User_Feed_Synchronization-{41FA4664-24F9-49C8-ABCF-3D592CD4C8BD}.job - c:\windows\system32\msfeedssync.exe [2006-10-17 08:31] . . ——- Supplementary Scan ——- . uStart Page = hxxp://www.google.com uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms} mStart Page = hxxp://www.google.com uInternet Settings,ProxyOverride = *.local FF - ProfilePath - c:\documents and settings\Eric\Application Data\Mozilla\Firefox\Profiles\s7rib94w.default\ FF - prefs.js: browser.search.selectedEngine - Google FF - prefs.js: browser.startup.homepage - hxxp://start.mozilla.org/firefox?client=firefox-a&rls;=org.mozilla:en-US:official FF - plugin: c:\documents and settings\Eric\Local Settings\Application Data\Google\Update\1.2.183.7\npGoogleOneClick8.dll FF - plugin: c:\program files\Opera7\Program\Plugins\np32dsw.dll FF - plugin: c:\program files\Opera7\Program\Plugins\npdrmv2.dll FF - plugin: c:\program files\Opera7\Program\Plugins\npdsplay.dll FF - plugin: c:\program files\Opera7\Program\Plugins\NPJava11.dll FF - plugin: c:\program files\Opera7\Program\Plugins\NPJava12.dll FF - plugin: c:\program files\Opera7\Program\Plugins\NPJava13.dll FF - plugin: c:\program files\Opera7\Program\Plugins\NPJava14.dll FF - plugin: c:\program files\Opera7\Program\Plugins\NPJava32.dll FF - plugin: c:\program files\Opera7\Program\Plugins\NPJPI142_03.dll FF - plugin: c:\program files\Opera7\Program\Plugins\NPOJI610.dll FF - plugin: c:\program files\Opera7\Program\Plugins\nppdf32.dll FF - plugin: c:\program files\Opera7\Program\Plugins\nppl3260.dll FF - plugin: c:\program files\Opera7\Program\Plugins\nprjplug.dll FF - plugin: c:\program files\Opera7\Program\Plugins\nprpjplug.dll FF - plugin: c:\program files\Opera7\Program\Plugins\NPSWF32.dll FF - plugin: c:\program files\Opera7\Program\Plugins\npwmsdrm.dll FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\ FF - HiddenExtension: XUL Cache: {8848879C-0C9D-4FCD-8E2D-8E6623B83023} - c:\documents and settings\Brian\Local Settings\Application Data\{8848879C-0C9D-4FCD-8E2D-8E6623B83023} FF - HiddenExtension: XUL Cache: {CE313A2C-1D74-44D0-8468-FD24A759C19F} - c:\documents and settings\Katie\Local Settings\Application Data\{CE313A2C-1D74-44D0-8468-FD24A759C19F} FF - HiddenExtension: XUL Cache: {934CD260-2FEA-4669-9520-0119415E7052} - c:\documents and settings\Katie Lou\Local Settings\Application Data\{934CD260-2FEA-4669-9520-0119415E7052} . ************************************************************************** disk not found C:\ please note that you need administrator rights to perform deep scan scanning hidden processes … scanning hidden autostart entries … scanning hidden files … scan completed successfully hidden files: ************************************************************************** . ——————— LOCKED REGISTRY KEYS ——————— [HKEY_USERS\S-1-5-21-2000478354-1177238915-725345543-1004\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{968FC8AB-2AD7-812D-5F98-ABDAAC5C0A60}*] @Allowed: (Read) (RestrictedCode) @Allowed: (Read) (RestrictedCode) "iapejmgkikpgeallfl"=hex:69,61,6d,6a,66,65,6b,6e,69,63,63,6f,6a,63,6a,6f,6f,70, 00,00 "hajeplhngifgblnc"=hex:6a,61,6c,6a,6c,65,68,6c,69,6a,61,62,66,61,61,69,66,69, 6e,64,00,06 "jafjlgfhpnmajckghapn"=hex:6a,61,61,66,66,70,62,62,70,63,70,6f,61,68,61,6e,69, 6d,65,6c,00,30 "jafjlgpgojcgieofbijb"=hex:64,62,63,67,6e,6e,67,68,6e,6f,6a,6f,61,6c,6f,6b,61, 68,6f,67,64,6d,63,6f,6c,6a,6f,65,69,67,62,62,6b,69,6f,68,6b,70,61,61,00,a2 [HKEY_USERS\S-1-5-21-2000478354-1177238915-725345543-1004\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{B39A6384-4344-80EB-B057-B976B8A2EA54}*] @Allowed: (Read) (RestrictedCode) @Allowed: (Read) (RestrictedCode) "abpnhkkfommdmmnmdhkghalddiodjmmbdf"=hex:6a,61,67,6c,68,68,64,68,65,6d,6c,65, 63,67,66,66,67,65,66,68,00,00 "maaocbojaankagoghnmnldhjkc"=hex:6f,61,68,6c,66,6d,64,6c,70,62,62,62,67,67,6f, 6c,62,68,63,6c,66,63,6f,6f,69,6b,6e,65,6c,64,00,b0 . ——————— DLLs Loaded Under Running Processes ——————— - - - - - - - > 'winlogon.exe'(640) c:\windows\system32\Ati2evxx.dll . Completion time: 2009-09-05 12:54 ComboFix-quarantined-files.txt 2009-09-05 16:54 Pre-Run: 23,800,098,816 bytes free Post-Run: 24,301,338,624 bytes free WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe [boot loader] timeout=2 default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS [operating systems] c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /fastdetect /NoExecute=OptIn 348 — E O F — 2009-08-26 09:35 ===== HijackThis Uninstall List ====== 123 Audio Video Merger 3D Home Architect Design Suite Deluxe 6 Ad-Aware SE Personal Adobe Download Manager Adobe Flash Player 10 ActiveX Adobe Flash Player 10 Plugin Adobe Image Viewer Plugin 4.0 Adobe Photoshop Album Adobe Reader 6.0.1 Adobe Reader Multimedia Package Adobe Shockwave Player Amazon MP3 Downloader 1.0.3 AnalogX DXMan Antivirus Pro 2010 Apple Mobile Device Support Apple Software Update AsfTools 3.1 (remove only) ASIO4ALL ASIO4ALL v2 AsusUpdate ATI - Software Uninstall Utility ATI Control Panel ATI Display Driver Audacity 1.2.0 avast! Antivirus Backup4all 3 Beatscape 1.0 BitPim 1.0.6 BitTornado 0.3.8 Bonjour BreezeBrowser v2.4a Brother BRAdmin Light 1.12 Brother MFC-7440N Cakewalk VST Adapter [removed] CCleaner (remove only) ConvertXtoDVD 2.2.3.258g Cool & Quiet Corel Print House 6 Creative MediaSource Creative Prodikeys DM Creative Removable Disk Manager Creative System Information Creative Zen MicroPhoto Critical Update for Windows Media Player 11 (KB959772) Cubasis VST 4 CutePDF Writer 2.7 Dell Printer Software Dimension Pro DivX ;-) Audio Compressor 4.02 DivX Codec 3.1alpha release DreamStation DXi2 DriveCrypt DTS Neo:6 Settings DVD Shrink 3.2 DVDFab Decrypter 2.9.7.2 Easy CD & DVD Creator 6 Enigma EZBack-it-up 2.0.1 Finale PrintMusic 2009 FL Studio Creative Edition FLV Player 1.3.3 FLV Player 2.0, build 24 FMS GEM Plus GEM+ 2 & iGOR GOM Player Google Earth GSpot Codec Information Appliance Higher Cockpit view for Trans-Am Series HijackThis 2.0.2 Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595) Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484) Hotfix for Windows Internet Explorer 7 (KB947864) Hotfix for Windows Media Format 11 SDK (KB929399) Hotfix for Windows Media Player 11 (KB939683) Hotfix for Windows XP (KB932716-v2) Hotfix for Windows XP (KB952287) Hotfix for Windows XP (KB961118) Hotfix for Windows XP (KB970653-v3) Huffyuv AVI lossless video codec (Remove Only) HyperSnap-DX 4 Intelliremote 2.1 iPod for Windows 2005-06-26 iPod for Windows 2006-01-10 iTunes Jamstix 2.5.1 Update Jasc Paint Shop Pro 8 Java 2 Runtime Environment, SE v1.4.2_01 Java 2 Runtime Environment, SE v1.4.2_03 Java™ 6 Update 14 JumpStart Typing LG USB Modem driver Linksys WAP11 Firmware Upgrade LiveUpdate 2.6 (Symantec Corporation) Logitech Gaming Software Malwarebytes' Anti-Malware M-Audio Series II MIDI Microsoft .NET Framework 1.1 Microsoft .NET Framework 1.1 Microsoft .NET Framework 1.1 Hotfix (KB928366) Microsoft .NET Framework 2.0 Service Pack 2 Microsoft .NET Framework 3.0 Service Pack 2 Microsoft .NET Framework 3.5 SP1 Microsoft .NET Framework 3.5 SP1 Microsoft Compression Client Pack 1.0 for Windows XP Microsoft Data Access Components KB870669 Microsoft Internationalized Domain Names Mitigation APIs Microsoft Kernel-Mode Driver Framework Feature Pack 1.5 Microsoft Kernel-Mode Driver Framework Feature Pack 1.7 Microsoft Monster Truck Madness 2 Microsoft National Language Support Downlevel APIs Microsoft Office 2000 SR-1 Professional Microsoft Plus! Digital Media Edition Microsoft User-Mode Driver Framework Feature Pack 1.7 Microsoft Visual C++ 2005 Redistributable Microsoft WinUsb 1.0 MIDI-OX MoTeC Interpreter Motorola Driver Installation Mozilla Firefox (3.0) MSXML 4.0 SP2 (KB936181) MSXML 4.0 SP2 (KB954430) NASCAR® Racing 2003 Season Native Instruments Guitar Rig 3 Native Instruments Service Center NEC-Mitsubishi NaViSet Nero - Burning Rom OpenMG Limited Patch 4.4-06-13-19-01 OpenMG Secure Module 4.4.00 OpenOffice.org 2.0 Opera OptiPix Photocopier 3.02 PhotoWorks PhotoWorks Cards PicViewer 2.74 Pinnacle Hollywood FX 4.6 Power Tab Editor 1.7 PowerDVD Project Wildfire Trans Am Series for Nascar Racing 2003 Puppy Luv (remove only) QuickTime rayzoon jamstix Readiris 7.5 Real Alternative 1.29 RealPlayer REAPER rFactor (remove only) Richard Burns Rally Demo ScanSoft PaperPort 11 Security Update for Windows Internet Explorer 7 (KB928090) Security Update for Windows Internet Explorer 7 (KB929969) Security Update for Windows Internet Explorer 7 (KB931768) Security Update for Windows Internet Explorer 7 (KB933566) Security Update for Windows Internet Explorer 7 (KB937143) Security Update for Windows Internet Explorer 7 (KB938127) Security Update for Windows Internet Explorer 7 (KB939653) Security Update for Windows Internet Explorer 7 (KB942615) Security Update for Windows Internet Explorer 7 (KB944533) Security Update for Windows Internet Explorer 7 (KB950759) Security Update for Windows Internet Explorer 7 (KB953838) Security Update for Windows Internet Explorer 7 (KB956390) Security Update for Windows Internet Explorer 7 (KB958215) Security Update for Windows Internet Explorer 7 (KB960714) Security Update for Windows Internet Explorer 7 (KB961260) Security Update for Windows Internet Explorer 7 (KB963027) Security Update for Windows Internet Explorer 7 (KB969897) Security Update for Windows Internet Explorer 8 (KB969897) Security Update for Windows Internet Explorer 8 (KB972260) Security Update for Windows Media Player (KB952069) Security Update for Windows Media Player (KB973540) Security Update for Windows Media Player 10 (KB911565) Security Update for Windows Media Player 10 (KB917734) Security Update for Windows Media Player 10 (KB936782) Security Update for Windows Media Player 11 (KB936782) Security Update for Windows Media Player 11 (KB954154) Security Update for Windows XP (KB923561) Security Update for Windows XP (KB938464) Security Update for Windows XP (KB941569) Security Update for Windows XP (KB946648) Security Update for Windows XP (KB950760) Security Update for Windows XP (KB950762) Security Update for Windows XP (KB950974) Security Update for Windows XP (KB951066) Security Update for Windows XP (KB951376) Security Update for Windows XP (KB951376-v2) Security Update for Windows XP (KB951698) Security Update for Windows XP (KB951748) Security Update for Windows XP (KB952004) Security Update for Windows XP (KB952954) Security Update for Windows XP (KB953839) Security Update for Windows XP (KB954211) Security Update for Windows XP (KB954459) Security Update for Windows XP (KB954600) Security Update for Windows XP (KB955069) Security Update for Windows XP (KB956391) Security Update for Windows XP (KB956572) Security Update for Windows XP (KB956744) Security Update for Windows XP (KB956802) Security Update for Windows XP (KB956803) Security Update for Windows XP (KB956841) Security Update for Windows XP (KB957095) Security Update for Windows XP (KB957097) Security Update for Windows XP (KB958644) Security Update for Windows XP (KB958687) Security Update for Windows XP (KB958690) Security Update for Windows XP (KB959426) Security Update for Windows XP (KB960225) Security Update for Windows XP (KB960715) Security Update for Windows XP (KB960803) Security Update for Windows XP (KB960859) Security Update for Windows XP (KB961371) Security Update for Windows XP (KB961373) Security Update for Windows XP (KB961501) Security Update for Windows XP (KB968537) Security Update for Windows XP (KB969898) Security Update for Windows XP (KB970238) Security Update for Windows XP (KB971557) Security Update for Windows XP (KB971633) Security Update for Windows XP (KB971657) Security Update for Windows XP (KB973346) Security Update for Windows XP (KB973354) Security Update for Windows XP (KB973507) Security Update for Windows XP (KB973869) sfArk Snapfish PhotoShow Express SONAR 5 Studio Edition SONAR 6.2.1 Studio Edition SONAR 8.0 Producer Edition SonicStage 3.4 Sound Blaster Audigy 2 ZS Spybot - Search & Destroy 1.2 Studio 8 TaxCut 2004 TaxCut Deluxe 2005 The BOB&TOM; Media Center Theme Park World Fix TI Connect 1.6 TruePianos 1.0.2 TruePianos: Diamond Module 1.0.1 TruePianos: Emerald Module 1.0.1 TruePianos: Sapphire Module 1.0 Tweak UI Update for Microsoft .NET Framework 3.5 SP1 (KB963707) Update for Windows Internet Explorer 8 (KB971930) Update for Windows XP (KB951072-v2) Update for Windows XP (KB951978) Update for Windows XP (KB955839) Update for Windows XP (KB967715) Update for Windows XP (KB968389) Update for Windows XP (KB973815) User Profile Hive Cleanup Service VIA Integrated Setup Wizard Viewpoint Media Player (Remove Only) Virtual Sound Canvas VST WAP11 Utility WaveLab Lite Windows Genuine Advantage v1.3.0254.0 Windows Internet Explorer 8 Windows Media Format 11 runtime Windows Media Format 11 runtime Windows Media Player 11 Windows Media Player 11 Windows XP Service Pack 3 WinRAR archiver XviD MPEG-4 Video Codec Zune Zune Zune Language Pack (ES) Zune Language Pack (FR)
Hi modena2904,

Before we continue, please confirm that you have attempted to uninstall Antivirus Pro 2010 via Add/Remove programs.

Thanks
I tried to uninstall several times using Windows add/remove programs. In each case, the malware came back. But all of those attempts were prior to following the self-help instructions on this site (i.e., running Malwarebytes) and prior to when I first initiated this thread and followed your instructions. Once I had the malware seemingly under control, I did not want to run the uninstall routine because I was concerned that it would actually reinstall instead of uninstall. Thanks. - Eric
Hi modena2904,

Thanks. I haven't found any references to it being reinstalled when you try to uninstall it, but with malware, anything is possible.

Still some more to do.

BitTornado 0.3.8
You have BitTornado 0.3.8, a P2P/file sharing program installed on your computer. P2P applications like it are the largest source of malware we see. You'll be doing yourself a favor by removing it.

References for the risk of these programs can be found in these links:
http://www.microsoft.com/windows/ie/commun…protection.mspx

http://www.internetworldstats.com/articles…cles/art053.htm

I would recommend that you uninstall BitTornado 0.3.8, however that choice is up to you. If you choose to remove these programs, you can do so via Control Panel >> Add or Remove Programs.

If you wish to keep it, please do not use it until your computer is cleaned.

Please download GooredFix from one of the locations below and save it to your Desktop
Download Mirror #1
Download Mirror #2
  • Ensure all Firefox windows are closed.
  • To run the tool, double-click it (XP), or right-click and select Run As Administrator (Vista).
  • When prompted to run the scan, click Yes.
  • GooredFix will check for infections, and then a log will appear. Please post the contents of that log in your next reply (it can also be found on your desktop, called GooredFix.txt).

Next, open HJT (hijackthis)
  • Click Open the Misc Tools Section
  • Click Open Uninstall Manager
  • In the list, please locate AntiVirus Pro 2010
  • Click Delete this entry
  • Close HJT

Next

We will be using Combofix again but will run it differently.

Please read through the instructions to familarize youself with what to expect when the tool runs.

Please follow all previous instructions regarding security programs.

Open a new Notepad session
  • Click the Start button, click run
  • in the run box type notepad
  • click ok
  • In the notepad, Click "Format" and be certain that Word Wrap is not checked.
  • Copy and paste all the all of the text in the code box below into the Notepad, (including the URL). Do Not copy the word CODE

http://forums.whatthetech.com/Need_Help_Complete_Removal_AntiVirus_Pro_2010_t106730.html

KillAll::

Collect::[4]
c:\documents and settings\Katie\Local Settings\Application Data\jecuviwy.dat
c:\windows\type.com
c:\documents and settings\Eric\Local Settings\Application Data\kirure.dat
c:\windows\xidusoveh.com
c:\windows\system32\covatuhe.dat
c:\windows\yqujup.com
c:\windows\oqadyzi.com
c:\program files\Common Files\ycefe.db
c:\documents and settings\All Users\Application Data\juci.dat
c:\program files\Common Files\ekihom._sy

File::
c:\program files\error.dat

Folder::
c:\program files\AntivirusPro_2010

Regnull:: 
[HKEY_USERS\S-1-5-21-2000478354-1177238915-725345543-1004\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{B39A6384-4344-80EB-B057-B976B8A2EA54}*]
[HKEY_USERS\S-1-5-21-2000478354-1177238915-725345543-1004\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{968FC8AB-2AD7-812D-5F98-ABDAAC5C0A60}*]

In the notepad
  • Click File, Save as…, and set the Save in to your Desktop
  • In the filename box, type (including quotation marks) as the filename: "CFScript.txt"
  • Click save
Using your mouse left button, drag the new file CFscript.txt and drop it on the ComboFix.exe icon as shown below.

This will start ComboFix again.Close all browser/windows first.

**Note: Do not mouseclick combofix's window while it's running. That may cause it to stall**

[external image: Posted Image]

**Note**

When CF finishes running, the ComboFix log will open along with a message box–do not be alarmed. With the above script, ComboFix will capture files to submit for analysis.
  • Ensure you are connected to the internet and click OK on the message box.
Please post back with
  • GooredFix log
  • combofix log

Thanks
I have completed the steps as follows: 1. BitTornado uninstalled as suggested. 2. Downloaded and ran GooredFix, log is pasted in below. 3. Used HJT uninstall manager to delete entry for Anti-Virus Pro 2010. I also confirmed that the entry no longer appears in Add/Remove Programs. 4. Created CFScript.txt and ran ComboFix as directed, log is pasted in below. ComboFix prompted me that there was a newer version available and asked if I wanted to download it. I clicked "no". After completing its scan and running the script, CF rebooted my PC. After reboot, CF completed and displayed the log. However, I did not receive any other message box, nor did I see any indication that CF was capturing and/or submitting files for analysis. Thanks. - Eric ============ GooredFix Log ============= GooredFix by jpshortstuff (12.07.09) Log created at 17:10 on 05/09/2009 (Eric) Firefox version 3.0 (en-US) ========== GooredScan ========== Deleting HKEY_LOCAL_MACHINE\Software\Mozilla\Firefox\Extensions\\{8848879C-0C9D-4FCD-8E2D-8E6623B83023} -> Success! Deleting C:\Documents and Settings\Brian\Local Settings\Application Data\{8848879C-0C9D-4FCD-8E2D-8E6623B83023} -> Success! Deleting HKEY_LOCAL_MACHINE\Software\Mozilla\Firefox\Extensions\\{CE313A2C-1D74-44D0-8468-FD24A759C19F} -> Success! Deleting C:\Documents and Settings\Katie\Local Settings\Application Data\{CE313A2C-1D74-44D0-8468-FD24A759C19F} -> Success! Deleting HKEY_LOCAL_MACHINE\Software\Mozilla\Firefox\Extensions\\{934CD260-2FEA-4669-9520-0119415E7052} -> Success! Deleting C:\Documents and Settings\Katie Lou\Local Settings\Application Data\{934CD260-2FEA-4669-9520-0119415E7052} -> Success! C:\Program Files\Mozilla Firefox\extensions\ (none) [HKEY_LOCAL_MACHINE\Software\Mozilla\Firefox\Extensions] "{20a82645-c095-46ed-80e3-08825760534b}"="C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\" [21:56 03/12/2008] "{60305F03-96C0-4B12-82EC-F43265C7B7F5}"="C:\Documents and Settings\Amy\Local Settings\Application Data\{60305F03-96C0-4B12-82EC-F43265C7B7F5}" [] "[removed]"="C:\Program Files\Java\jre6\lib\deploy\jqs\ff" [23:33 24/10/2008] -=E.O.F=- ============ ComboFix Log ============= ComboFix 09-09-04.02 - Eric 09/05/2009 17:15.2.1 - NTFSx86 Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1535.1006 [GMT -4:00] Running from: d:\users\[removed]\Desktop\Combo-Fix.exe Command switches used :: d:\users\Eric\Desktop\CFScript.txt AV: avast! antivirus 4.8.1351 [VPS 090905-0] *On-access scanning disabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D} FILE :: "c:\program files\error.dat" . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . c:\docume~1\Eric\LOCALS~1\Temp\catchme.dll c:\documents and settings\All Users\Application Data\juci.dat c:\documents and settings\Eric\Local Settings\Application Data\kirure.dat c:\documents and settings\Eric\Local Settings\temp\catchme.dll c:\documents and settings\Katie\Local Settings\Application Data\jecuviwy.dat c:\program files\AntivirusPro_2010 c:\program files\AntivirusPro_2010\AntivirusPro_2010.cfg c:\program files\AntivirusPro_2010\AntivirusPro_2010.exe c:\program files\AntivirusPro_2010\AVEngn.dll c:\program files\AntivirusPro_2010\data\daily.cvd c:\program files\AntivirusPro_2010\htmlayout.dll c:\program files\AntivirusPro_2010\Microsoft.VC80.CRT\Microsoft.VC80.CRT.manifest c:\program files\AntivirusPro_2010\Microsoft.VC80.CRT\msvcm80.dll c:\program files\AntivirusPro_2010\Microsoft.VC80.CRT\msvcp80.dll c:\program files\AntivirusPro_2010\Microsoft.VC80.CRT\msvcr80.dll c:\program files\AntivirusPro_2010\pthreadVC2.dll c:\program files\AntivirusPro_2010\Uninstall.exe c:\program files\AntivirusPro_2010\wscui.cpl c:\program files\Common Files\ekihom._sy c:\program files\Common Files\ycefe.db c:\program files\error.dat c:\windows\oqadyzi.com c:\windows\system32\covatuhe.dat c:\windows\type.com c:\windows\xidusoveh.com c:\windows\yqujup.com . ((((((((((((((((((((((((( Files Created from 2009-08-05 to 2009-09-05 ))))))))))))))))))))))))))))))) . 2009-09-05 11:45 . 2009-09-05 11:45 ——– d—–w- c:\documents and settings\Eric\Application Data\Malwarebytes 2009-09-05 11:45 . 2009-08-03 17:36 38160 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys 2009-09-05 11:45 . 2009-09-05 12:20 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware 2009-09-05 11:45 . 2009-09-05 11:45 ——– d—–w- c:\documents and settings\All Users\Application Data\Malwarebytes 2009-09-05 11:45 . 2009-08-03 17:36 19096 —-a-w- c:\windows\system32\drivers\mbam.sys 2009-09-03 23:29 . 2009-09-03 23:29 ——– d-sh–w- c:\documents and settings\Katie\IECompatCache 2009-08-25 17:14 . 2009-08-25 17:14 ——– d—–w- c:\documents and settings\Katie Lou\Local Settings\Application Data\WMTools Downloaded Files 2009-08-14 20:24 . 2009-08-14 20:24 ——– d-sh–w- c:\documents and settings\Brian\IECompatCache 2009-08-13 06:40 . 2009-07-10 13:27 1315328 -c—-w- c:\windows\system32\dllcache\msoe.dll . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2009-09-05 21:26 . 2004-12-30 20:46 384 —-a-w- c:\windows\system32\DVCStateBkp-{00000000-00000000-0000000E-00001102-00000004-20021102}.dat 2009-09-05 21:26 . 2004-12-30 20:46 384 —-a-w- c:\windows\system32\DVCState-{00000000-00000000-0000000E-00001102-00000004-20021102}.dat 2009-09-05 13:24 . 2004-03-15 02:15 ——– d—–w- c:\program files\Trend Micro 2009-09-03 18:56 . 2009-05-07 17:32 ——– d—–w- c:\documents and settings\Katie\Application Data\AdobeUM 2009-08-30 21:57 . 2008-06-21 19:59 ——– d—–w- c:\program files\Firefox 2009-08-25 00:44 . 2006-06-27 01:23 ——– d—–w- c:\documents and settings\Eric\Application Data\AdobeUM 2009-08-17 16:10 . 2005-04-30 15:04 1279456 —-a-w- c:\windows\system32\aswBoot.exe 2009-08-17 16:06 . 2004-10-24 23:51 93392 —-a-w- c:\windows\system32\drivers\aswmon.sys 2009-08-17 16:06 . 2004-10-24 23:51 94160 —-a-w- c:\windows\system32\drivers\aswmon2.sys 2009-08-17 16:05 . 2008-04-05 12:36 114768 —-a-w- c:\windows\system32\drivers\aswSP.sys 2009-08-17 16:05 . 2008-04-05 12:36 20560 —-a-w- c:\windows\system32\drivers\aswFsBlk.sys 2009-08-17 16:04 . 2005-04-30 15:04 23152 —-a-w- c:\windows\system32\drivers\aswRdr.sys 2009-08-17 16:03 . 2004-10-24 23:51 26944 —-a-w- c:\windows\system32\drivers\aavmker4.sys 2009-08-17 16:02 . 2004-10-24 23:51 97480 —-a-w- c:\windows\system32\AVASTSS.scr 2009-08-05 09:01 . 2004-03-27 00:30 204800 —-a-w- c:\windows\system32\mswebdvd.dll 2009-07-29 17:45 . 2004-11-04 19:56 54416 —-a-w- c:\documents and settings\Brian\Local Settings\Application Data\GDIPFONTCACHEV1.DAT 2009-07-27 17:33 . 2006-07-15 20:24 54416 —-a-w- c:\documents and settings\Katie\Local Settings\Application Data\GDIPFONTCACHEV1.DAT 2009-07-27 01:29 . 2004-07-05 22:37 54416 —-a-w- c:\documents and settings\Eric\Local Settings\Application Data\GDIPFONTCACHEV1.DAT 2009-07-27 00:03 . 2009-07-27 00:03 126456 —-a-w- c:\documents and settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat 2009-07-26 23:43 . 2009-07-26 23:37 ——– d—–w- c:\program files\NOS 2009-07-26 23:43 . 2009-07-26 23:37 ——– d—–w- c:\documents and settings\All Users\Application Data\NOS 2009-07-17 19:01 . 2003-03-31 12:00 58880 —-a-w- c:\windows\system32\atl.dll 2009-07-14 03:43 . 2004-03-27 00:46 286208 —-a-w- c:\windows\system32\wmpdxm.dll 2009-07-12 18:19 . 2009-07-12 18:19 ——– d—–w- c:\program files\CCleaner 2009-07-03 17:09 . 2004-02-06 22:05 915456 ——w- c:\windows\system32\wininet.dll 2009-06-25 08:25 . 2003-03-31 12:00 730112 —-a-w- c:\windows\system32\lsasrv.dll 2009-06-25 08:25 . 2003-03-31 12:00 56832 —-a-w- c:\windows\system32\secur32.dll 2009-06-25 08:25 . 2003-03-31 12:00 54272 —-a-w- c:\windows\system32\wdigest.dll 2009-06-25 08:25 . 2003-03-31 12:00 301568 —-a-w- c:\windows\system32\kerberos.dll 2009-06-25 08:25 . 2003-03-31 12:00 147456 —-a-w- c:\windows\system32\schannel.dll 2009-06-25 08:25 . 2003-03-31 12:00 136192 —-a-w- c:\windows\system32\msv1_0.dll 2009-06-24 11:18 . 2003-03-31 12:00 92928 —-a-w- c:\windows\system32\drivers\ksecdd.sys 2009-06-16 14:36 . 2003-03-31 12:00 81920 —-a-w- c:\windows\system32\fontsub.dll 2009-06-16 14:36 . 2003-03-31 12:00 119808 —-a-w- c:\windows\system32\t2embed.dll 2009-06-12 12:31 . 2003-03-31 12:00 80896 —-a-w- c:\windows\system32\tlntsess.exe 2009-06-12 12:31 . 2003-03-31 12:00 76288 —-a-w- c:\windows\system32\telnet.exe 2009-06-10 14:13 . 2003-03-31 12:00 84992 —-a-w- c:\windows\system32\avifil32.dll 2009-06-10 13:19 . 2004-03-13 01:50 2066432 —-a-w- c:\windows\system32\mstscax.dll 2009-06-10 06:14 . 2003-03-31 12:00 132096 —-a-w- c:\windows\system32\wkssvc.dll . ((((((((((((((((((((((((((((( SnapShot@2009-09-05_16.52.41 ))))))))))))))))))))))))))))))))))))))))) . + 2009-09-05 21:28 . 2009-09-05 21:28 16384 c:\windows\Temp\Perflib_Perfdata_f4.dat + 2009-09-05 21:04 . 2009-09-05 21:04 16384 c:\windows\Temp\Perflib_Perfdata_580.dat + 2009-09-05 21:28 . 2009-09-05 21:28 16384 c:\windows\Temp\Perflib_Perfdata_574.dat . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Start WingMan Profiler"="c:\program files\Logitech\Profiler\lwemon.exe" [2003-08-07 77824] "RemoteCenter"="c:\program files\Creative\MediaSource\RemoteControl\RcMan.exe" [2003-11-21 143360] "Creative MediaSource Go"="c:\program files\Creative\MediaSource\Go\CTCMSGo.exe" [2003-08-12 131072] "Google Update"="c:\documents and settings\Eric\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" [2008-11-07 133104] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "CTSysVol"="c:\program files\Creative\SBAudigy2ZS\Surround Mixer\CTSysVol.exe" [2003-07-02 57344] "CTDVDDET"="c:\program files\Creative\SBAudigy2ZS\DVDAudio\CTDVDDET.EXE" [2003-06-18 45056] "SBDrvDet"="c:\program files\Creative\SB Drive Det\SBDrvDet.exe" [2002-12-03 45056] "UpdReg"="c:\windows\UpdReg.EXE" [2000-05-11 90112] "ATIPTA"="c:\program files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2003-12-12 335872] "RoxioEngineUtility"="c:\program files\Common Files\Roxio Shared\System\EngUtil.exe" [2003-05-01 65536] "RoxioDragToDisc"="c:\program files\Roxio\Easy CD Creator 6\DragToDisc\DrgToDsc.exe" [2003-06-25 868352] "RoxioAudioCentral"="c:\program files\Roxio\Easy CD Creator 6\AudioCentral\RxMon.exe" [2003-06-24 319488] "PinnacleDriverCheck"="c:\windows\System32\PSDrvCheck.exe" [2003-12-04 406016] "ProdikeysAutorun"="c:\program files\Creative\Prodikeys\Prodload.exe" [2003-08-27 131072] "avast!"="c:\progra~1\ALWILS~1\Avast4\ashDisp.exe" [2009-08-17 81000] "vsc32cnf.exe"="c:\program files\Roland\VSC32\vsc32cnf.exe" [2000-02-07 36864] "vscvol.exe"="c:\program files\Roland\VSC32\vscvol.exe" [2000-02-09 36864] "SsAAD.exe"="c:\progra~1\Sony\SONICS~1\SsAAD.exe" [2006-01-07 81920] "DLPSP"="c:\program files\dell printers\Additional Color Laser Software\Status Monitor\DLPSP.EXE" [2005-01-13 126976] "ISUSPM Startup"="c:\program files\Common Files\InstallShield\UpdateService\isuspm.exe" [2005-08-11 249856] "ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2005-08-11 81920] "SSBkgdUpdate"="c:\program files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" [2006-10-25 210472] "BrMfcWnd"="c:\program files\Brother\Brmfcmon\BrMfcWnd.exe" [2007-11-06 741376] "ControlCenter3"="c:\program files\Brother\ControlCenter3\brctrcen.exe" [2007-10-30 77824] "Zune Launcher"="c:\program files\Zune\ZuneLauncher.exe" [2008-11-10 157312] "QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2009-01-05 413696] "iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-03-13 342312] "SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-05-21 148888] "CTHelper"="CTHELPER.EXE" - c:\windows\system32\CTHELPER.EXE [2003-10-06 24576] c:\documents and settings\All Users\Start Menu\Programs\Startup\ Microsoft Office.lnk - c:\program files\Microsoft Office\Office\OSA9.EXE [2000-1-21 65588] [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32] "WAVE1"=vscapi.dll "Midi1"=PRODMI32.DLL "Midi2"=vscapi.dll "Midi3"=ProdMidi.dll "midi4"=ma_cmidn.dll "midi5"=ma_cmidn.dll "midi6"=ma_cmidn.dll [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys] @="Driver" [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List] "c:\\WINDOWS\\system32\\sessmgr.exe"= "c:\\Program Files\\Adobe\\Photoshop Album\\Apps\\PhotoshopAlbum.exe"= "c:\\WINDOWS\\system32\\dplaysvr.exe"= "%windir%\\Network Diagnostic\\xpnetdiag.exe"= "c:\\WINDOWS\\system32\\ftp.exe"= "%windir%\\system32\\sessmgr.exe"= "c:\\Program Files\\Brother\\Brmfl07b\\FAXRX.exe"= "c:\\Program Files\\Brother\\BRAdmin Light\\BRAdmLight.exe"= "l:\\Sierra2\\gplsecrets\\iGOR\\iGOR.exe"= "c:\\Program Files\\Microsoft Games\\Monster Truck Madness 2\\monster.exe"= "c:\\Program Files\\Bonjour\\mDNSResponder.exe"= "c:\\Program Files\\iTunes\\iTunes.exe"= [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List] "54925:UDP"= 54925:UDP:Brother Network Scanner "6881:TCP"= 6881:TCP:Bit Torrent 1 "6882:TCP"= 6882:TCP:Bit Torrent 2 "6883:TCP"= 6883:TCP:Bit Torrent 3 "6884:TCP"= 6884:TCP:Bit Torrent 4 "6885:TCP"= 6885:TCP:Bit Torrent 5 "6886:TCP"= 6886:TCP:Bit Torrent 6 "6887:TCP"= 6887:TCP:Bit Torrent 7 "6888:TCP"= 6888:TCP:Bit Torrent 8 "6889:TCP"= 6889:TCP:Bit Torrent 9 R0 DCR;DCR;c:\windows\system32\drivers\DCR.sys [4/3/2004 6:16 PM 224800] R0 viasraid;viasraid;c:\windows\system32\drivers\viasraid.sys [3/13/2004 2:07 PM 77312] R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [4/5/2008 8:36 AM 114768] R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [4/5/2008 8:36 AM 20560] R2 DLSDB;Dell Printer Status Database;c:\program files\Dell Printers\Additional Color Laser Software\Status Monitor\dlsdbnt.exe [3/4/2006 5:02 PM 135168] R2 DriveCryptService;DriveCrypt Service;c:\program files\DriveCrypt\DcrServ.exe [4/3/2004 6:16 PM 208012] R2 PfDetNT;PfDetNT;c:\windows\system32\drivers\PFModNT.sys [3/26/2004 11:49 PM 15840] R2 RVIEGVST;VSC VST Engine;c:\program files\Roland\Virtual Sound Canvas VST\RVIEg01VST.sys [6/21/2005 9:09 PM 188276] R3 Prodikeys;Creative Prodikeys Driver;c:\windows\system32\drivers\ProdDrvr.sys [6/6/2004 1:55 PM 14392] R3 vsc32;Virtual Sound Canvas 3.2;c:\windows\system32\drivers\vsc.sys [6/21/2005 9:08 PM 951284] S2 BridDfu;LINKSYS WAP11 USB Device Driver;c:\windows\system32\drivers\BridDFU.sys [5/1/2004 8:47 PM 16302] S3 ATIXPGAA;ATIXPGAA;\??\c:\program files\ASUS\SmartDoctor\ATIXPGAA.SYS –> c:\program files\ASUS\SmartDoctor\ATIXPGAA.SYS [?] S3 getPlus® Helper;getPlus® Helper;c:\program files\NOS\bin\getPlus_HelperSvc.exe [7/26/2009 7:43 PM 66056] — Other Services/Drivers In Memory — *Deregistered* - uphcleanhlp [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}] "c:\windows\system32\rundll32.exe" "c:\windows\system32\iedkcs32.dll",BrandIEActiveSetup SIGNUP . Contents of the 'Scheduled Tasks' folder 2009-08-31 c:\windows\Tasks\AppleSoftwareUpdate.job - c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 16:34] 2009-09-04 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2000478354-1177238915-725345543-1004Core.job - c:\documents and settings\Eric\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2008-11-07 01:15] 2009-09-05 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2000478354-1177238915-725345543-1004UA.job - c:\documents and settings\Eric\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2008-11-07 01:15] 2009-09-04 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2000478354-1177238915-725345543-1006Core.job - c:\documents and settings\Brian\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2008-12-03 22:30] 2009-09-05 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2000478354-1177238915-725345543-1006UA.job - c:\documents and settings\Brian\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2008-12-03 22:30] 2009-09-05 c:\windows\Tasks\User_Feed_Synchronization-{41FA4664-24F9-49C8-ABCF-3D592CD4C8BD}.job - c:\windows\system32\msfeedssync.exe [2006-10-17 08:31] . . ——- Supplementary Scan ——- . uStart Page = hxxp://www.google.com uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms} mStart Page = hxxp://www.google.com uInternet Settings,ProxyOverride = *.local FF - ProfilePath - c:\documents and settings\Eric\Application Data\Mozilla\Firefox\Profiles\s7rib94w.default\ FF - prefs.js: browser.search.selectedEngine - Google FF - prefs.js: browser.startup.homepage - hxxp://start.mozilla.org/firefox?client=firefox-a&rls;=org.mozilla:en-US:official FF - plugin: c:\documents and settings\Eric\Local Settings\Application Data\Google\Update\1.2.183.7\npGoogleOneClick8.dll FF - plugin: c:\program files\Opera7\Program\Plugins\np32dsw.dll FF - plugin: c:\program files\Opera7\Program\Plugins\npdrmv2.dll FF - plugin: c:\program files\Opera7\Program\Plugins\npdsplay.dll FF - plugin: c:\program files\Opera7\Program\Plugins\NPJava11.dll FF - plugin: c:\program files\Opera7\Program\Plugins\NPJava12.dll FF - plugin: c:\program files\Opera7\Program\Plugins\NPJava13.dll FF - plugin: c:\program files\Opera7\Program\Plugins\NPJava14.dll FF - plugin: c:\program files\Opera7\Program\Plugins\NPJava32.dll FF - plugin: c:\program files\Opera7\Program\Plugins\NPJPI142_03.dll FF - plugin: c:\program files\Opera7\Program\Plugins\NPOJI610.dll FF - plugin: c:\program files\Opera7\Program\Plugins\nppdf32.dll FF - plugin: c:\program files\Opera7\Program\Plugins\nppl3260.dll FF - plugin: c:\program files\Opera7\Program\Plugins\nprjplug.dll FF - plugin: c:\program files\Opera7\Program\Plugins\nprpjplug.dll FF - plugin: c:\program files\Opera7\Program\Plugins\NPSWF32.dll FF - plugin: c:\program files\Opera7\Program\Plugins\npwmsdrm.dll FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\ . ************************************************************************** disk not found C:\ please note that you need administrator rights to perform deep scan scanning hidden processes … scanning hidden autostart entries … scanning hidden files … scan completed successfully hidden files: ************************************************************************** . ——————— DLLs Loaded Under Running Processes ——————— - - - - - - - > 'winlogon.exe'(632) c:\windows\system32\Ati2evxx.dll - - - - - - - > 'explorer.exe'(3088) c:\windows\system32\WININET.dll c:\program files\Logitech\Profiler\LWEHook.dll c:\windows\system32\ieframe.dll c:\windows\system32\webcheck.dll c:\windows\system32\WPDShServiceObj.dll c:\windows\system32\PortableDeviceTypes.dll c:\windows\system32\PortableDeviceApi.dll . ———————— Other Running Processes ———————— . c:\windows\system32\ati2evxx.exe c:\program files\Alwil Software\Avast4\aswUpdSv.exe c:\program files\Alwil Software\Avast4\ashServ.exe c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe c:\program files\Bonjour\mDNSResponder.exe c:\windows\system32\CTSVCCDA.EXE c:\program files\Java\jre6\bin\jqs.exe c:\program files\M-Audio\M-Audio Series II MIDI\MA_CMIDI_Inst.exe c:\windows\system32\ati2evxx.exe c:\windows\system32\dllhost.exe c:\program files\UPHClean\uphclean.exe c:\windows\system32\vssvc.exe c:\windows\system32\MsPMSPSv.exe c:\windows\system32\ZuneBusEnum.exe c:\program files\Dell Printers\Additional Color Laser Software\Status Monitor\dlpwdnt.exe c:\program files\Alwil Software\Avast4\ashMaiSv.exe c:\program files\Alwil Software\Avast4\ashWebSv.exe c:\windows\system32\dllhost.exe c:\windows\system32\msdtc.exe c:\program files\Brother\ControlCenter3\BrccMCtl.exe c:\program files\Roxio\Easy CD Creator 6\AudioCentral\Playlist.exe c:\windows\system32\wbem\wmiapsrv.exe c:\program files\Brother\Brmfcmon\BrMfimon.exe c:\program files\iPod\bin\iPodService.exe . ************************************************************************** . Completion time: 2009-09-05 17:33 - machine was rebooted ComboFix-quarantined-files.txt 2009-09-05 21:33 ComboFix2.txt 2009-09-05 16:55 Pre-Run: 24,335,663,104 bytes free Post-Run: 24,288,800,768 bytes free 286 — E O F — 2009-08-26 09:35
Hi modena2904,

Not sure why that happened with that script. Did you copy the URL?

Download OTL2 to your desktop.
  • Double click on OTL.exe to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output
  • Check the boxes beside LOP Check and Purity Check.
  • In the Extra Registry section, change the setting to None
  • At the bottom Under the Custom Scans/Fixes box at the bottom, paste in the following
    msconfig
  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
When the scan completes, it will open a notepad windows. OTL.Txt

Please post back with
  • OTL log

Thanks
I tried to be very careful to paste all of the text (including the URL) into the script. Unfortunately, ComboFix seems to have deleted the script file when it ran, so I can't check for sure.

OTL log file is below.

Thanks.

- Eric


======== OTL Log ===========

OTL logfile created on: 9/5/2009 6:14:18 PM - Run 1
OTL by OldTimer - Version 3.0.10.7 Folder = D:\Users\Eric\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

1.50 Gb Total Physical Memory | 0.98 Gb Available Physical Memory | 65.15% Memory free
4.00 Gb Paging File | 3.92 Gb Available in Paging File | 97.99% Paging File free
Paging file location(s): L:\pagefile.sys 3072 3072 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 73.24 Gb Total Space | 22.61 Gb Free Space | 30.87% Space Free | Partition Type: NTFS
Drive D: | 73.24 Gb Total Space | 38.89 Gb Free Space | 53.10% Space Free | Partition Type: NTFS
Drive E: | 117.19 Gb Total Space | 105.55 Gb Free Space | 90.07% Space Free | Partition Type: NTFS
Drive F: | 34.42 Gb Total Space | 14.83 Gb Free Space | 43.08% Space Free | Partition Type: NTFS
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Drive L: | 465.76 Gb Total Space | 236.86 Gb Free Space | 50.85% Space Free | Partition Type: NTFS
Drive Z: | 73.24 Gb Total Space | 38.89 Gb Free Space | 53.10% Space Free | Partition Type: NTFS

Computer Name: FAMILYPC3
Current User Name: Eric
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal

========== Processes (SafeList) ==========

PRC - C:\WINDOWS\System32\Ati2evxx.exe ()
PRC - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe (ALWIL Software)
PRC - C:\Program Files\Alwil Software\Avast4\ashServ.exe (ALWIL Software)
PRC - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe (Apple Inc.)
PRC - C:\Program Files\Bonjour\mDNSResponder.exe (Apple Inc.)
PRC - C:\WINDOWS\System32\CTsvcCDA.exe (Creative Technology Ltd)
PRC - c:\program files\dell printers\Additional Color Laser Software\Status Monitor\DLSDBNT.EXE (Dell Inc.)
PRC - C:\Program Files\DriveCrypt\DcrServ.exe ()
PRC - C:\Program Files\Java\jre6\bin\jqs.exe (Sun Microsystems, Inc.)
PRC - C:\Program Files\M-Audio\M-Audio Series II MIDI\MA_CMIDI_Inst.exe ()
PRC - C:\Program Files\UPHClean\uphclean.exe (Microsoft Corporation)
PRC - C:\WINDOWS\System32\MsPMSPSv.exe (Microsoft Corporation)
PRC - C:\WINDOWS\System32\ZuneBusEnum.exe (Microsoft Corporation)
PRC - c:\program files\dell printers\Additional Color Laser Software\Status Monitor\DLPWDNT.EXE (Dell Inc.)
PRC - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe (ALWIL Software)
PRC - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe (ALWIL Software)
PRC - C:\Program Files\iPod\bin\iPodService.exe (Apple Inc.)
PRC - C:\WINDOWS\System32\Ati2evxx.exe ()
PRC - C:\WINDOWS\Explorer.EXE (Microsoft Corporation)
PRC - C:\Program Files\Creative\SBAudigy2ZS\Surround Mixer\CTSysVol.exe (Creative Technology Ltd)
PRC - C:\Program Files\Creative\SBAudigy2ZS\DVDAudio\CTDVDDET.EXE (Creative Technology Ltd)
PRC - C:\WINDOWS\System32\CTHELPER.EXE (Creative Technology Ltd)
PRC - C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe (ATI Technologies, Inc.)
PRC - C:\Program Files\Roxio\Easy CD Creator 6\DragToDisc\DrgToDsc.exe (Roxio)
PRC - C:\Program Files\Roxio\Easy CD Creator 6\AudioCentral\RxMon.exe (Roxio, Inc.)
PRC - C:\Program Files\Creative\Prodikeys\Prodload.exe (Creative Technology Ltd)
PRC - C:\Program Files\Alwil Software\Avast4\ashDisp.exe (ALWIL Software)
PRC - C:\Program Files\Roland\VSC32\vsc32cnf.exe (Roland)
PRC - C:\Program Files\Roland\VSC32\vscvol.exe (Roland)
PRC - C:\Program Files\Sony\SonicStage\SSAAD.exe ()
PRC - C:\program files\dell printers\Additional Color Laser Software\Status Monitor\DLPSP.EXE (Dell Inc.)
PRC - C:\Program Files\Brother\Brmfcmon\BrMfcWnd.exe (Brother Industries, Ltd.)
PRC - C:\Program Files\Zune\ZuneLauncher.exe (Microsoft Corporation)
PRC - C:\Program Files\iTunes\iTunesHelper.exe (Apple Inc.)
PRC - C:\Program Files\Java\jre6\bin\jusched.exe (Sun Microsystems, Inc.)
PRC - C:\Program Files\Logitech\Profiler\lwemon.exe (Logitech Inc.)
PRC - C:\Program Files\Brother\ControlCenter3\brccMCtl.exe (Brother Industries, Ltd.)
PRC - C:\Program Files\Roxio\Easy CD Creator 6\AudioCentral\Playlist.exe (Roxio, Inc.)
PRC - C:\Program Files\Creative\MediaSource\RemoteControl\RcMan.exe (Creative Technology Ltd)
PRC - C:\Program Files\Creative\MediaSource\Go\CTCMSGo.exe (Creative Technology Ltd)
PRC - C:\Program Files\Brother\Brmfcmon\BrMfimon.exe (Brother Industries, Ltd.)
PRC - D:\Users\Eric\Desktop\OTL.exe (OldTimer Tools)

========== Win32 Services (SafeList) ==========

SRV - (Apple Mobile Device [Auto | Running]) – C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe (Apple Inc.)
SRV - (aspnet_state [On_Demand | Stopped]) – C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe (Microsoft Corporation)
SRV - (aswUpdSv [Auto | Running]) – C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe (ALWIL Software)
SRV - (Ati HotKey Poller [Auto | Running]) – C:\WINDOWS\System32\Ati2evxx.exe ()
SRV - (ATI Smart [Auto | Stopped]) – C:\WINDOWS\System32\ati2sgag.exe ()
SRV - (avast! Antivirus [Auto | Running]) – C:\Program Files\Alwil Software\Avast4\ashServ.exe (ALWIL Software)
SRV - (avast! Mail Scanner [On_Demand | Running]) – C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe (ALWIL Software)
SRV - (avast! Web Scanner [On_Demand | Running]) – C:\Program Files\Alwil Software\Avast4\ashWebSv.exe (ALWIL Software)
SRV - (Bonjour Service [Auto | Running]) – C:\Program Files\Bonjour\mDNSResponder.exe (Apple Inc.)
SRV - (clr_optimization_v2.0.50727_32 [On_Demand | Stopped]) – C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
SRV - (Creative Service for CDROM Access [Auto | Running]) – C:\WINDOWS\System32\CTsvcCDA.exe (Creative Technology Ltd)
SRV - (DLPWD [Auto | Running]) – c:\program files\dell printers\Additional Color Laser Software\Status Monitor\DLPWDNT.EXE (Dell Inc.)
SRV - (DLSDB [Auto | Running]) – c:\program files\dell printers\Additional Color Laser Software\Status Monitor\DLSDBNT.EXE (Dell Inc.)
SRV - (DriveCryptService [Auto | Running]) – C:\Program Files\DriveCrypt\DcrServ.exe ()
SRV - (FontCache3.0.0.0 [On_Demand | Stopped]) – C:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe (Microsoft Corporation)
SRV - (getPlus® Helper [On_Demand | Stopped]) – C:\Program Files\NOS\bin\getPlus_HelperSvc.exe (NOS Microsystems Ltd.)
SRV - (helpsvc [Auto | Running]) – C:\WINDOWS\PCHealth\HelpCtr\Binaries\pchsvc.dll (Microsoft Corporation)
SRV - (IDriverT [On_Demand | Stopped]) – C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe (Macrovision Corporation)
SRV - (idsvc [Unknown | Stopped]) – C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe (Microsoft Corporation)
SRV - (iPod Service [On_Demand | Running]) – C:\Program Files\iPod\bin\iPodService.exe (Apple Inc.)
SRV - (JavaQuickStarterService [Auto | Running]) – C:\Program Files\Java\jre6\bin\jqs.exe (Sun Microsystems, Inc.)
SRV - (MA_CMIDI_InstallerService [Auto | Running]) – C:\Program Files\M-Audio\M-Audio Series II MIDI\MA_CMIDI_Inst.exe ()
SRV - (MSCSPTISRV [On_Demand | Stopped]) – C:\Program Files\Common Files\Sony Shared\AVLib\MSCSPTISRV.exe (Sony Corporation)
SRV - (NetTcpPortSharing [Disabled | Stopped]) – C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe (Microsoft Corporation)
SRV - (PACSPTISVR [On_Demand | Stopped]) – C:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exe (Sony Corporation)
SRV - (Pml Driver HPZ12 [On_Demand | Stopped]) – C:\WINDOWS\System32\HPZipm12.exe (HP)
SRV - (SPTISRV [On_Demand | Stopped]) – C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe (Sony Corporation)
SRV - (SSScsiSV [On_Demand | Stopped]) – C:\Program Files\Common Files\Sony Shared\AVLib\SSScsiSV.exe (Sony Corporation)
SRV - (UPHClean [Auto | Running]) – C:\Program Files\UPHClean\uphclean.exe (Microsoft Corporation)
SRV - (WMDM PMSP Service [Auto | Running]) – C:\WINDOWS\System32\MsPMSPSv.exe (Microsoft Corporation)
SRV - (WMPNetworkSvc [On_Demand | Stopped]) – C:\Program Files\Windows Media Player\WMPNetwk.exe (Microsoft Corporation)
SRV - (ZuneBusEnum [Auto | Running]) – C:\WINDOWS\System32\ZuneBusEnum.exe (Microsoft Corporation)
SRV - (ZuneNetworkSvc [On_Demand | Stopped]) – C:\Program Files\Zune\ZuneNss.exe (Microsoft Corporation)
SRV - (ZuneWlanCfgSvc [On_Demand | Stopped]) – C:\WINDOWS\System32\ZuneWlanCfgSvc.exe (Microsoft Corporation)

========== Driver Services (SafeList) ==========

DRV - (61883 [On_Demand | Stopped]) – C:\WINDOWS\System32\DRIVERS\61883.sys (Microsoft Corporation)
DRV - (Aavmker4 [System | Running]) – C:\WINDOWS\System32\drivers\aavmker4.sys (ALWIL Software)
DRV - (AmdK8 [System | Running]) – C:\WINDOWS\System32\DRIVERS\AmdK8.sys (Advanced Micro Devices)
DRV - (ASAPIW2k [On_Demand | Running]) – C:\WINDOWS\System32\drivers\ASAPIW2k.sys (Pinnacle Systems GmbH)
DRV - (aslm75 [Auto | Running]) – C:\WINDOWS\System32\drivers\aslm75.sys ()
DRV - (aswFsBlk [Auto | Running]) – C:\WINDOWS\System32\DRIVERS\aswFsBlk.sys (ALWIL Software)
DRV - (aswMon2 [Auto | Running]) – C:\WINDOWS\System32\drivers\aswmon2.sys (ALWIL Software)
DRV - (aswRdr [On_Demand | Running]) – C:\WINDOWS\System32\drivers\aswRdr.sys (ALWIL Software)
DRV - (aswSP [System | Running]) – C:\WINDOWS\System32\drivers\aswSP.sys (ALWIL Software)
DRV - (ati2mtag [On_Demand | Running]) – C:\WINDOWS\System32\DRIVERS\ati2mtag.sys (ATI Technologies Inc.)
DRV - (atinrvxx [On_Demand | Running]) – C:\WINDOWS\System32\DRIVERS\atinrvxx.sys (ATI Technologies Inc.)
DRV - (Avc [On_Demand | Stopped]) – C:\WINDOWS\System32\DRIVERS\avc.sys (Microsoft Corporation)
DRV - (BridDfu [Auto | Stopped]) – C:\WINDOWS\System32\Drivers\BridDfu.sys ()
DRV - (catchme [On_Demand | Running]) – File not found
DRV - (Cdr4_xp [System | Running]) – C:\WINDOWS\System32\drivers\cdr4_xp.sys (Roxio)
DRV - (Cdralw2k [System | Running]) – C:\WINDOWS\System32\drivers\cdralw2k.sys (Roxio)
DRV - (cdudf_xp [System | Running]) – C:\WINDOWS\System32\drivers\Cdudf_xp.sys (Roxio)
DRV - (ctac32k [On_Demand | Running]) – C:\WINDOWS\System32\drivers\ctac32k.sys (Creative Technology Ltd)
DRV - (ctaud2k [On_Demand | Running]) – C:\WINDOWS\System32\drivers\ctaud2k.sys (Creative Technology Ltd)
DRV - (ctdvda2k [On_Demand | Stopped]) – C:\WINDOWS\System32\drivers\ctdvda2k.sys (Creative Technology Ltd)
DRV - (ctprxy2k [On_Demand | Running]) – C:\WINDOWS\System32\drivers\ctprxy2k.sys (Creative Technology Ltd)
DRV - (ctsfm2k [On_Demand | Running]) – C:\WINDOWS\System32\drivers\ctsfm2k.sys (Creative Technology Ltd)
DRV - (DCR [Boot | Running]) – C:\WINDOWS\System32\Drivers\DCR.sys ()
DRV - (DVDVRRdr_xp [System | Running]) – C:\WINDOWS\System32\drivers\DVDVRRdr_xp.sys (Roxio)
DRV - (dvd_2K [On_Demand | Running]) – C:\WINDOWS\System32\drivers\Dvd_2k.sys (Roxio)
DRV - (EIO [On_Demand | Stopped]) – C:\WINDOWS\System32\drivers\EIO.sys (ASUSTeK Computer Inc.)
DRV - (EL2000 [On_Demand | Running]) – C:\WINDOWS\System32\DRIVERS\EL2K_XP.sys (3Com Corporation)
DRV - (emupia [On_Demand | Running]) – C:\WINDOWS\System32\drivers\emupia2k.sys (Creative Technology Ltd)
DRV - (gameenum [On_Demand | Running]) – C:\WINDOWS\System32\DRIVERS\gameenum.sys (Microsoft Corporation)
DRV - (GEARAspiWDM [On_Demand | Running]) – C:\WINDOWS\System32\DRIVERS\GEARAspiWDM.sys (GEAR Software Inc.)
DRV - (ha10kx2k [On_Demand | Running]) – C:\WINDOWS\System32\drivers\ha10kx2k.sys (Creative Technology Ltd)
DRV - (hap16v2k [On_Demand | Running]) – C:\WINDOWS\System32\drivers\hap16v2k.sys (Creative Technology Ltd)
DRV - (HPZid412 [On_Demand | Stopped]) – C:\WINDOWS\System32\DRIVERS\HPZid412.sys (HP)
DRV - (HPZipr12 [On_Demand | Stopped]) – C:\WINDOWS\System32\DRIVERS\HPZipr12.sys (HP)
DRV - (HPZius12 [On_Demand | Stopped]) – C:\WINDOWS\System32\DRIVERS\HPZius12.sys (HP)
DRV - (MA_CMIDI [On_Demand | Stopped]) – C:\WINDOWS\System32\drivers\ma_cmidi.sys (M-Audio)
DRV - (mmc_2K [On_Demand | Stopped]) – C:\WINDOWS\System32\drivers\Mmc_2k.sys (Roxio)
DRV - (motmodem [On_Demand | Stopped]) – C:\WINDOWS\System32\DRIVERS\motmodem.sys (Motorola)
DRV - (MREMP50 [On_Demand | Stopped]) – C:\Program Files\Common Files\Motive\MREMP50.sys (Printing Communications Assoc., Inc. (PCAUSA))
DRV - (MRESP50 [On_Demand | Stopped]) – C:\Program Files\Common Files\Motive\MRESP50.sys (Printing Communications Assoc., Inc. (PCAUSA))
DRV - (MSDV [On_Demand | Stopped]) – C:\WINDOWS\System32\DRIVERS\msdv.sys (Microsoft Corporation)
DRV - (MVDCODEC [Auto | Running]) – C:\WINDOWS\System32\DRIVERS\atinmdxx.sys (ATI Technologies Inc.)
DRV - (ossrv [On_Demand | Running]) – C:\WINDOWS\System32\drivers\ctoss2k.sys (Creative Technology Ltd.)
DRV - (papycpu2 [System | Running]) – C:\WINDOWS\system32\drivers\papycpu2.sys ()
DRV - (papyjoy [System | Running]) – C:\WINDOWS\System32\DRIVERS\papyjoy.sys ()
DRV - (pcouffin [On_Demand | Running]) – C:\WINDOWS\System32\Drivers\pcouffin.sys (VSO Software)
DRV - (pfc [On_Demand | Running]) – C:\WINDOWS\System32\drivers\pfc.sys (Padus, Inc.)
DRV - (PfDetNT [Auto | Running]) – C:\WINDOWS\System32\drivers\PfModNT.sys (Creative Technology Ltd.)
DRV - (PfModNT [Auto | Stopped]) – C:\WINDOWS\System32\drivers\PfModNT.sys (Creative Technology Ltd.)
DRV - (Prodikeys [On_Demand | Running]) – C:\WINDOWS\System32\DRIVERS\ProdDrvr.sys (Creative Technology Ltd)
DRV - (Ptilink [On_Demand | Running]) – C:\WINDOWS\System32\DRIVERS\ptilink.sys (Parallel Technologies, Inc.)
DRV - (pwd_2k [System | Running]) – C:\WINDOWS\System32\drivers\pwd_2K.sys (Roxio)
DRV - (PxHelp20 [Boot | Running]) – C:\WINDOWS\System32\DRIVERS\PxHelp20.sys (Sonic Solutions)
DRV - (RVIEGVST [Auto | Running]) – C:\Program Files\Roland\Virtual Sound Canvas VST\RVIEg01VST.sys (Roland)
DRV - (Secdrv [On_Demand | Stopped]) – C:\WINDOWS\System32\DRIVERS\secdrv.sys (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.)
DRV - (StillCam [On_Demand | Running]) – C:\WINDOWS\System32\DRIVERS\serscan.sys (Microsoft Corporation)
DRV - (UdfReadr_xp [System | Running]) – C:\WINDOWS\System32\drivers\UdfReadr_xp.sys (Roxio)
DRV - (usbaudio [On_Demand | Stopped]) – C:\WINDOWS\System32\drivers\usbaudio.sys (Microsoft Corporation)
DRV - (usbbus [On_Demand | Stopped]) – C:\WINDOWS\System32\DRIVERS\lgusbbus.sys (LG Electronics Inc.)
DRV - (UsbDiag [On_Demand | Stopped]) – C:\WINDOWS\System32\DRIVERS\lgusbdiag.sys (LG Electronics Inc.)
DRV - (USBModem [On_Demand | Stopped]) – C:\WINDOWS\System32\DRIVERS\lgusbmodem.sys (LG Electronics Inc.)
DRV - (viaagp1 [Boot | Running]) – C:\WINDOWS\System32\DRIVERS\viaagp1.sys (VIA Technologies, Inc.)
DRV - (viamraid [Boot | Running]) – C:\WINDOWS\system32\DRIVERS\viamraid.sys (VIA Technologies inc,.ltd)
DRV - (viasraid [Boot | Running]) – C:\WINDOWS\system32\drivers\viasraid.sys (VIA Technologies inc,.ltd)
DRV - (vsc32 [On_Demand | Running]) – C:\WINDOWS\System32\DRIVERS\vsc.sys (Roland)
DRV - (WinUSB [On_Demand | Stopped]) – C:\WINDOWS\System32\DRIVERS\WinUSB.sys (Microsoft Corporation)
DRV - (WmBEnum [On_Demand | Running]) – C:\WINDOWS\System32\drivers\WmBEnum.sys (Logitech Inc.)
DRV - (WmFilter [On_Demand | Stopped]) – C:\WINDOWS\System32\drivers\WmFilter.sys (Logitech Inc.)
DRV - (WmHidLo [On_Demand | Stopped]) – C:\WINDOWS\System32\drivers\WmHidLo.sys (Logitech Inc.)
DRV - (WmVirHid [On_Demand | Stopped]) – C:\WINDOWS\System32\drivers\WmVirHid.sys (Logitech Inc.)
DRV - (WmXlCore [On_Demand | Running]) – C:\WINDOWS\System32\drivers\WmXlCore.sys (Logitech Inc.)
DRV - (zumbus [Auto | Running]) – C:\WINDOWS\System32\DRIVERS\zumbus.sys (Microsoft Corporation)

========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = [binary data]
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:NoAdd-ons
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:SecurityRisk
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomizeSearch = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\system32\blank.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?p…amp;ar=iesearch
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultName = Google
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultURL = http://www.google.com/search?q={searchTerms}
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local

========== FireFox ==========

FF - prefs.js..browser.search.selectedEngine: "Google"
FF - prefs.js..browser.startup.homepage: "http://start.mozilla.org/firefox?client=firefox-a&rls;=org.mozilla:en-US:official"
FF - prefs.js..extensions.enabledItems: {DDC359D1-844A-42a7-9AA1-88A850A938A8}:1.1.4
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0010-ABCDEFFEDCBA}:6.0.10
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA}:6.0.11
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA}:6.0.13
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0014-ABCDEFFEDCBA}:6.0.14
FF - prefs.js..extensions.enabledItems: [removed]:1.0
FF - prefs.js..extensions.enabledItems: {914DC373-ACF6-4305-B877-8508A576E9B6}:0.6.2
FF - prefs.js..extensions.enabledItems: {20a82645-c095-46ed-80e3-08825760534b}:1.1
FF - prefs.js..extensions.enabledItems: {B7080EEB-ED19-455C-BFA8-12EEC8A20D83}:1.0
FF - prefs.js..extensions.enabledItems: {8848879C-0C9D-4FCD-8E2D-8E6623B83023}:1.0
FF - prefs.js..extensions.enabledItems: {CE313A2C-1D74-44D0-8468-FD24A759C19F}:1.0
FF - prefs.js..extensions.enabledItems: {934CD260-2FEA-4669-9520-0119415E7052}:1.0
FF - prefs.js..extensions.enabledItems: {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.0

FF - HKLM\software\mozilla\Firefox\extensions\\{20a82645-c095-46ed-80e3-08825760534b}: C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\ [2009/06/24 11:00:27 | 00,000,000 | —D | M]
FF - HKLM\software\mozilla\Firefox\extensions\\{60305F03-96C0-4B12-82EC-F43265C7B7F5}: C:\Documents and Settings\Amy\Local Settings\Application Data\{60305F03-96C0-4B12-82EC-F43265C7B7F5}
FF - HKLM\software\mozilla\Firefox\extensions\\[removed]: C:\Program Files\Java\jre6\lib\deploy\jqs\ff [2008/10/24 19:33:18 | 00,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.0\extensions\\Components: C:\Program Files\Firefox\components [2009/03/29 17:32:58 | 00,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.0\extensions\\Plugins: C:\Program Files\Firefox\plugins [2009/07/26 19:43:31 | 00,000,000 | —D | M]

[2008/06/21 15:59:54 | 00,000,000 | —D | M] – C:\Documents and Settings\Eric\Application Data\mozilla\Extensions
[2008/06/21 15:59:54 | 00,000,000 | —D | M] – C:\Documents and Settings\Eric\Application Data\mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}
[2009/08/25 06:20:22 | 00,000,000 | —D | M] – C:\Documents and Settings\Eric\Application Data\mozilla\Firefox\Profiles\s7rib94w.default\extensions
[2009/06/27 08:02:38 | 00,000,000 | —D | M] – C:\Documents and Settings\Eric\Application Data\mozilla\Firefox\Profiles\s7rib94w.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2008/06/21 20:18:17 | 00,000,000 | —D | M] – C:\Documents and Settings\Eric\Application Data\mozilla\Firefox\Profiles\s7rib94w.default\extensions\{914DC373-ACF6-4305-B877-8508A576E9B6}
[2009/07/04 16:23:09 | 00,000,000 | —D | M] – C:\Documents and Settings\Eric\Application Data\mozilla\Firefox\Profiles\s7rib94w.default\extensions\{DDC359D1-844A-42a7-9AA1-88A850A938A8}

O1 HOSTS File: (27 bytes) - C:\WINDOWS\System32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O3 - HKCU\..\Toolbar\ShellBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {4064EA35-578D-4073-A834-C96D82CBCF40} - No CLSID value found.
O4 - HKLM..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe (ATI Technologies, Inc.)
O4 - HKLM..\Run: [avast!] C:\Program Files\Alwil Software\Avast4\ashDisp.exe (ALWIL Software)
O4 - HKLM..\Run: [BrMfcWnd] C:\Program Files\Brother\Brmfcmon\BrMfcWnd.exe (Brother Industries, Ltd.)
O4 - HKLM..\Run: [ControlCenter3] C:\Program Files\Brother\ControlCenter3\brctrcen.exe (Brother Industries, Ltd.)
O4 - HKLM..\Run: [CTDVDDET] C:\Program Files\Creative\SBAudigy2ZS\DVDAudio\CTDVDDET.EXE (Creative Technology Ltd)
O4 - HKLM..\Run: [CTHelper] C:\WINDOWS\System32\CTHELPER.EXE (Creative Technology Ltd)
O4 - HKLM..\Run: [CTSysVol] C:\Program Files\Creative\SBAudigy2ZS\Surround Mixer\CTSysVol.exe (Creative Technology Ltd)
O4 - HKLM..\Run: [DLPSP] c:\program files\dell printers\Additional Color Laser Software\Status Monitor\DLPSP.EXE (Dell Inc.)
O4 - HKLM..\Run: [ISUSPM Startup] C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe (Macrovision Corporation)
O4 - HKLM..\Run: [ISUSScheduler] C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe (Macrovision Corporation)
O4 - HKLM..\Run: [iTunesHelper] C:\Program Files\iTunes\iTunesHelper.exe (Apple Inc.)
O4 - HKLM..\Run: [PinnacleDriverCheck] C:\WINDOWS\System32\PSDrvCheck.exe ()
O4 - HKLM..\Run: [ProdikeysAutorun] C:\Program Files\Creative\Prodikeys\Prodload.exe (Creative Technology Ltd)
O4 - HKLM..\Run: [QuickTime Task] C:\Program Files\QuickTime\qttask.exe (Apple Inc.)
O4 - HKLM..\Run: [RoxioAudioCentral] C:\Program Files\Roxio\Easy CD Creator 6\AudioCentral\RxMon.exe (Roxio, Inc.)
O4 - HKLM..\Run: [RoxioDragToDisc] C:\Program Files\Roxio\Easy CD Creator 6\DragToDisc\DrgToDsc.exe (Roxio)
O4 - HKLM..\Run: [RoxioEngineUtility] C:\Program Files\Common Files\Roxio Shared\System\EngUtil.exe (Roxio)
O4 - HKLM..\Run: [SBDrvDet] C:\Program Files\Creative\SB Drive Det\SBDrvDet.exe (Creative Technology Ltd)
O4 - HKLM..\Run: [SsAAD.exe] C:\Program Files\Sony\SonicStage\SSAAD.exe ()
O4 - HKLM..\Run: [SSBkgdUpdate] C:\Program Files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe (Nuance Communications, Inc.)
O4 - HKLM..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre6\bin\jusched.exe (Sun Microsystems, Inc.)
O4 - HKLM..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE (Creative Technology Ltd.)
O4 - HKLM..\Run: [vsc32cnf.exe] C:\Program Files\Roland\VSC32\vsc32cnf.exe (Roland)
O4 - HKLM..\Run: [vscvol.exe] C:\Program Files\Roland\VSC32\vscvol.exe (Roland)
O4 - HKLM..\Run: [Zune Launcher] C:\Program Files\Zune\ZuneLauncher.exe (Microsoft Corporation)
O4 - HKCU..\Run: [Creative MediaSource Go] C:\Program Files\Creative\MediaSource\Go\CTCMSGo.exe (Creative Technology Ltd)
O4 - HKCU..\Run: [Google Update] C:\Documents and Settings\Eric\Local Settings\Application Data\Google\Update\GoogleUpdate.exe (Google Inc.)
O4 - HKCU..\Run: [RemoteCenter] C:\Program Files\Creative\MediaSource\RemoteControl\RcMan.exe (Creative Technology Ltd)
O4 - HKCU..\Run: [Start WingMan Profiler] C:\Program Files\Logitech\Profiler\lwemon.exe (Logitech Inc.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE (Microsoft Corporation)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: AllowLegacyWebView = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: AllowUnhashedWebView = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableRegistryTools = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoRecentDocsMenu = 01 00 00 00 [binary data]
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: ClearRecentDocsOnExit = 01 00 00 00 [binary data]
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoRecentDocsHistory = 01 00 00 00 [binary data]
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoLowDiskSpaceChecks = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O9 - Extra 'Tools' menuitem : @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe (Microsoft Corporation)
O9 - Extra Button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O15 - HKLM\..Trusted Domains: 1 domain(s) and sub-domain(s) not assigned to a zone.
O15 - HKCU\..Trusted Domains: familypc3 ([]file in Local intranet)
O15 - HKCU\..Trusted Domains: familypc4 ([]file in Local intranet)
O16 - DPF: {01113300-3E00-11D2-8470-0060089874ED} https://activatemyfios.verizon.net/sdcCommo…20Installer.cab (Support.com Configuration Class)
O16 - DPF: {0A5FD7C5-A45C-49FC-ADB5-9952547D5715} http://www.creative.com/su/ocx/15026/CTSUEng.cab (Creative Software AutoUpdate)
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://fpdownload.macromedia.com/pub/shock…director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {233C1507-6A77-46A4-9443-F871F945D258} http://fpdownload.macromedia.com/get/shock…director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} http://www.snapfish.com/SnapfishActivia.cab (Snapfish Activia)
O16 - DPF: {4CCA4E6B-9259-11D9-AC6E-444553544200} http://h30155.www3.hp.com/ediags/dd/instal…tallMgr_v01.cab (FixController Control)
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} http://update.microsoft.com/windowsupdate/…b?1136547307687 (WUWebControl Class)
O16 - DPF: {8A0019EB-51FA-4AE5-A40B-C0496BBFC739} http://picture.vzw.com/activex/VerizonWire…loadControl.cab (Verizon Wireless Media Upload)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_14)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get/flash…t/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {99FE5072-78AA-4FEE-89BA-69A5FA55343F} http://download.microsoft.com/download/B/3…44/igdtoolx.cab (IGDTester Class)
O16 - DPF: {A90A5822-F108-45AD-8482-9BC8B12DD539} http://www.crucial.com/controls/cpcScanner.cab (Crucial cpcScan)
O16 - DPF: {CAFEEFAC-0014-0002-0003-ABCDEFFEDCBA} http://java.sun.com/products/plugin/autodl…indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0014-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_14)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_14)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab (Shockwave Flash Object)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} http://www.creative.com/su/ocx/15026/CTPID.cab (Creative Software AutoUpdate Support Package)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.0.1
O18 - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\http\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\https\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\ipp - No CLSID value found
O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp - No CLSID value found
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\msdaipp.dll (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\Explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\AtiExtEvent: DllName - Ati2evxx.dll - C:\WINDOWS\System32\Ati2evxx.dll ()
O24 - Desktop Components:0 (My Current Home Page) - About:Home
O31 - SafeBoot: AlternateShell - cmd.exe
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2004/03/12 21:53:12 | 00,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O34 - HKLM BootExecute: (autocheck) - File not found
O34 - HKLM BootExecute: (autochk) - C:\WINDOWS\System32\autochk.exe (Microsoft Corporation)
O34 - HKLM BootExecute: (*) - File not found

MsConfig - StartUpReg: Antivirus Pro 2010 - hkey= - key= - C:\Program Files\AntivirusPro_2010\AntivirusPro_2010.exe File not found
MsConfig - StartUpReg: IndexSearch - hkey= - key= - C:\Program Files\ScanSoft\PaperPort\IndexSearch.exe (Nuance Communications, Inc.)
MsConfig - StartUpReg: PaperPort PTD - hkey= - key= - C:\Program Files\ScanSoft\PaperPort\pptd40nt.exe (Nuance Communications, Inc.)
MsConfig - StartUpReg: PPort11reminder - hkey= - key= - C:\Program Files\ScanSoft\PaperPort\Ereg\Ereg.exe (Nuance Communications, Inc.)
MsConfig - StartUpReg: Verizon_McciTrayApp - hkey= - key= - C:\Program Files\Verizon\McciTrayApp.exe File not found
MsConfig - State: "system.ini" - 0
MsConfig - State: "win.ini" - 0
MsConfig - State: "bootini" - 0
MsConfig - State: "services" - 0
MsConfig - State: "startup" - 2

========== Files/Folders - Created Within 30 Days ==========

[1 C:\*.tmp files]
[5 C:\WINDOWS\*.tmp files]
[2009/09/05 18:12:27 | 00,514,048 | —- | C] (OldTimer Tools) – D:\Users\Eric\Desktop\OTL.exe
[2009/09/05 12:40:21 | 00,000,211 | —- | C] () – C:\Boot.bak
[2009/09/05 12:40:18 | 00,260,272 | —- | C] () – C:\cmldr
[2009/09/05 12:40:16 | 00,000,000 | RHSD | C] – C:\cmdcons
[2009/09/05 12:39:23 | 00,230,912 | —- | C] () – C:\WINDOWS\PEV.exe
[2009/09/05 12:39:23 | 00,212,480 | —- | C] (SteelWerX) – C:\WINDOWS\SWXCACLS.exe
[2009/09/05 12:39:23 | 00,161,792 | —- | C] (SteelWerX) – C:\WINDOWS\SWREG.exe
[2009/09/05 12:39:23 | 00,136,704 | —- | C] (SteelWerX) – C:\WINDOWS\SWSC.exe
[2009/09/05 12:39:23 | 00,098,816 | —- | C] () – C:\WINDOWS\sed.exe
[2009/09/05 12:39:23 | 00,080,412 | —- | C] () – C:\WINDOWS\grep.exe
[2009/09/05 12:39:23 | 00,068,096 | —- | C] () – C:\WINDOWS\zip.exe
[2009/09/05 12:39:23 | 00,031,232 | —- | C] (NirSoft) – C:\WINDOWS\NIRCMD.exe
[2009/09/05 12:39:16 | 00,000,000 | —D | C] – C:\WINDOWS\ERDNT
[2009/09/05 12:38:53 | 00,000,000 | —D | C] – C:\Qoobox
[2009/09/05 12:34:11 | 03,195,526 | R— | C] () – D:\Users\Eric\Desktop\Combo-Fix.exe
[2009/09/05 09:19:52 | 00,000,000 | —D | C] – D:\Users\Eric\Desktop\Virus infection 2009-09-04
[2009/09/05 07:45:23 | 00,000,000 | —D | C] – C:\Documents and Settings\Eric\Application Data\Malwarebytes
[2009/09/05 07:45:19 | 00,038,160 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2009/09/05 07:45:17 | 00,019,096 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys
[2009/09/05 07:45:17 | 00,000,000 | —D | C] – C:\Program Files\Malwarebytes' Anti-Malware
[2009/09/05 07:45:17 | 00,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Malwarebytes
[2009/09/05 07:33:47 | 00,017,306 | —- | C] () – C:\WINDOWS\ugul._sy
[2009/09/05 07:33:47 | 00,016,967 | —- | C] () – C:\WINDOWS\patukup.db
[2009/09/05 07:33:47 | 00,015,992 | —- | C] () – C:\Documents and Settings\Eric\Local Settings\Application Data\bedil.lib
[2009/09/05 07:33:46 | 00,016,462 | —- | C] () – C:\Documents and Settings\All Users\Documents\dekorugup._sy
[2009/09/05 07:33:46 | 00,012,146 | —- | C] () – C:\Documents and Settings\All Users\Documents\ekaqogakur.lib
[2009/09/04 23:07:50 | 00,013,053 | —- | C] () – C:\Documents and Settings\Eric\Local Settings\Application Data\jamovameqa.db
[2009/09/04 16:59:41 | 00,015,834 | —- | C] () – C:\Documents and Settings\All Users\Documents\kylalyveky._sy
[2009/09/04 16:59:41 | 00,011,804 | —- | C] () – C:\Documents and Settings\All Users\Documents\ixamy.dat
[2009/08/13 02:40:31 | 00,128,512 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\dhtmled.ocx
[2009/08/13 02:40:26 | 01,315,328 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\msoe.dll
[2009/08/10 19:55:51 | 00,000,000 | —D | C] – D:\Users\Eric\Desktop\Temp Maine Photos
[2009/01/23 16:04:28 | 00,087,552 | —- | C] () – C:\WINDOWS\System32\cpwmon2k.dll
[2008/09/06 11:00:35 | 00,000,028 | —- | C] () – C:\WINDOWS\pdf995.ini
[2008/09/06 10:58:19 | 00,051,716 | —- | C] () – C:\WINDOWS\System32\pdf995mon.dll
[2008/08/31 16:09:03 | 00,000,000 | —- | C] () – C:\WINDOWS\brmx2001.ini
[2008/08/31 16:08:20 | 00,000,030 | —- | C] () – C:\WINDOWS\Brownie.ini
[2008/08/31 15:58:43 | 00,000,426 | —- | C] () – C:\WINDOWS\BRWMARK.INI
[2008/08/31 15:58:26 | 00,000,823 | —- | C] () – C:\WINDOWS\Brpfx04a.ini
[2008/08/31 15:58:26 | 00,000,153 | —- | C] () – C:\WINDOWS\brpcfx.ini
[2008/08/31 15:57:17 | 00,045,056 | —- | C] () – C:\WINDOWS\System32\BRTCPCON.DLL
[2008/08/31 15:57:17 | 00,000,114 | —- | C] () – C:\WINDOWS\System32\BRLMW03A.INI
[2008/08/31 15:57:15 | 00,000,086 | —- | C] () – C:\WINDOWS\Brfaxrx.ini
[2008/08/31 15:57:14 | 00,106,496 | —- | C] () – C:\WINDOWS\System32\BrMuSNMP.dll
[2008/08/31 15:20:18 | 00,031,567 | —- | C] () – C:\WINDOWS\maxlink.ini
[2008/03/13 22:39:13 | 00,005,632 | —- | C] () – C:\WINDOWS\System32\drivers\StarOpen.sys
[2007/10/18 19:41:46 | 00,000,181 | —- | C] () – C:\WINDOWS\js2.ini
[2007/05/25 15:48:45 | 00,126,464 | —- | C] () – C:\WINDOWS\System32\vsmidi.dll
[2007/01/23 21:39:26 | 00,000,214 | —- | C] () – C:\WINDOWS\HP_48BitScanUpdatePatch.ini
[2006/09/11 19:42:17 | 00,000,230 | —- | C] () – C:\WINDOWS\KA.INI
[2006/09/09 11:44:35 | 00,000,000 | —- | C] () – C:\WINDOWS\SETUP32.INI
[2005/10/29 20:48:12 | 00,000,487 | —- | C] () – C:\WINDOWS\hegames.ini
[2005/09/20 15:13:00 | 00,000,726 | —- | C] () – C:\WINDOWS\PODW.INI
[2005/09/20 15:12:59 | 00,141,824 | —- | C] () – C:\WINDOWS\System32\RASTY.DLL
[2005/08/14 18:08:43 | 00,374,784 | —- | C] () – C:\WINDOWS\3dg32.dll
[2005/06/21 21:09:27 | 00,000,041 | —- | C] () – C:\WINDOWS\wininit.ini
[2004/09/12 20:16:45 | 00,000,031 | —- | C] () – C:\WINDOWS\CTWave32.ini
[2004/09/05 09:59:50 | 00,155,648 | —- | C] () – C:\WINDOWS\System32\xvidvfw.dll
[2004/09/05 09:58:04 | 00,679,936 | —- | C] () – C:\WINDOWS\System32\xvidcore.dll
[2004/08/21 15:19:04 | 00,056,832 | —- | C] () – C:\WINDOWS\System32\iyvu9_32.dll
[2004/05/23 19:49:40 | 01,385,984 | —- | C] () – C:\WINDOWS\System32\telintf.DLL
[2004/05/01 20:47:02 | 00,016,302 | —- | C] () – C:\WINDOWS\System32\drivers\BridDFU.sys
[2004/04/06 20:35:32 | 00,000,158 | —- | C] () – C:\WINDOWS\pagesuit.ini
[2004/04/06 20:35:31 | 00,023,040 | —- | C] () – C:\WINDOWS\System32\irisco32.dll
[2004/04/04 21:16:56 | 00,001,984 | —- | C] () – C:\WINDOWS\System32\drivers\papycpu2.sys
[2004/04/04 21:16:56 | 00,001,856 | —- | C] () – C:\WINDOWS\System32\drivers\papyjoy.sys
[2004/04/04 21:14:08 | 00,000,199 | —- | C] () – C:\WINDOWS\Sierra.ini
[2004/04/03 23:50:31 | 00,002,300 | —- | C] () – C:\WINDOWS\DriveCrypt.ini
[2004/04/03 18:16:18 | 00,224,800 | —- | C] () – C:\WINDOWS\System32\drivers\DCR.sys
[2004/03/29 21:32:52 | 00,000,122 | —- | C] () – C:\WINDOWS\mdm.ini
[2004/03/29 21:32:48 | 00,000,000 | —- | C] () – C:\WINDOWS\NSREX.INI
[2004/03/29 21:24:10 | 00,000,478 | —- | C] () – C:\WINDOWS\ODBC.INI
[2004/03/26 23:49:55 | 00,065,536 | —- | C] ( ) – C:\WINDOWS\System32\a3d.dll
[2004/03/26 23:49:55 | 00,005,515 | —- | C] () – C:\WINDOWS\System32\ENSDEF.INI
[2004/03/26 23:49:55 | 00,000,194 | —- | C] () – C:\WINDOWS\System32\KILL.INI
[2004/03/26 20:30:18 | 00,363,520 | —- | C] () – C:\WINDOWS\System32\psisdecd.dll
[2004/03/13 15:57:34 | 00,000,231 | —- | C] () – C:\WINDOWS\AC3API.INI
[2004/03/13 15:56:31 | 00,043,513 | —- | C] () – C:\WINDOWS\System32\e10kxwdm.ini
[2004/03/13 15:56:31 | 00,000,175 | —- | C] () – C:\WINDOWS\System32\ctzapxx.ini
[2004/03/13 15:55:11 | 00,000,136 | —- | C] () – C:\WINDOWS\SBWIN.INI
[2004/03/13 14:38:19 | 00,006,272 | —- | C] () – C:\WINDOWS\System32\drivers\ASLM75.SYS
[2004/03/13 14:30:50 | 00,002,527 | —- | C] () – C:\WINDOWS\Ascd_tmp.ini
[2004/03/13 14:30:49 | 00,005,824 | —- | C] () – C:\WINDOWS\System32\drivers\ASUSHWIO.SYS
[2003/12/12 13:42:14 | 00,086,016 | —- | C] () – C:\WINDOWS\System32\ati2evxx.dll
[2003/03/31 08:00:00 | 00,000,963 | —- | C] () – C:\WINDOWS\win.ini
[2003/03/31 08:00:00 | 00,000,227 | —- | C] () – C:\WINDOWS\system.ini
[2002/05/29 09:50:02 | 00,561,152 | —- | C] () – C:\WINDOWS\System32\hpotscl.dll
[1999/01/22 14:46:56 | 00,065,536 | —- | C] () – C:\WINDOWS\System32\MSRTEDIT.DLL
[1998/06/13 23:53:26 | 00,044,544 | —- | C] () – C:\WINDOWS\System32\Gif89.dll

========== Files - Modified Within 30 Days ==========

[1 C:\*.tmp files]
[11 C:\WINDOWS\System32\*.tmp files]
[5 C:\WINDOWS\*.tmp files]
[2009/09/05 18:15:00 | 00,000,422 | -H– | M] () – C:\WINDOWS\tasks\User_Feed_Synchronization-{41FA4664-24F9-49C8-ABCF-3D592CD4C8BD}.job
[2009/09/05 18:12:27 | 00,514,048 | —- | M] (OldTimer Tools) – D:\Users\Eric\Desktop\OTL.exe
[2009/09/05 18:12:04 | 04,933,177 | —- | M] () – C:\WINDOWS\{00000000-00000000-0000000E-00001102-00000004-20021102}.CDF
[2009/09/05 18:11:46 | 00,013,646 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2009/09/05 17:58:00 | 00,000,974 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-2000478354-1177238915-725345543-1004UA.job
[2009/09/05 17:29:07 | 00,000,227 | —- | M] () – C:\WINDOWS\system.ini
[2009/09/05 17:29:00 | 00,000,978 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-2000478354-1177238915-725345543-1006UA.job
[2009/09/05 17:28:26 | 00,000,027 | —- | M] () – C:\WINDOWS\System32\drivers\etc\hosts
[2009/09/05 17:27:59 | 00,000,006 | -H– | M] () – C:\WINDOWS\tasks\SA.DAT
[2009/09/05 17:27:50 | 00,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2009/09/05 17:26:49 | 00,031,812 | —- | M] () – C:\WINDOWS\System32\BMXCtrlState-{00000000-00000000-0000000E-00001102-00000004-20021102}.rfx
[2009/09/05 17:26:49 | 00,031,812 | —- | M] () – C:\WINDOWS\System32\BMXBkpCtrlState-{00000000-00000000-0000000E-00001102-00000004-20021102}.rfx
[2009/09/05 17:26:49 | 00,031,440 | —- | M] () – C:\WINDOWS\System32\BMXStateBkp-{00000000-00000000-0000000E-00001102-00000004-20021102}.rfx
[2009/09/05 17:26:49 | 00,031,440 | —- | M] () – C:\WINDOWS\System32\BMXState-{00000000-00000000-0000000E-00001102-00000004-20021102}.rfx
[2009/09/05 17:26:49 | 00,001,072 | —- | M] () – C:\WINDOWS\System32\settingsbkup.sfm
[2009/09/05 17:26:49 | 00,001,072 | —- | M] () – C:\WINDOWS\System32\settings.sfm
[2009/09/05 17:26:49 | 00,000,384 | —- | M] () – C:\WINDOWS\System32\DVCStateBkp-{00000000-00000000-0000000E-00001102-00000004-20021102}.dat
[2009/09/05 17:26:49 | 00,000,384 | —- | M] () – C:\WINDOWS\System32\DVCState-{00000000-00000000-0000000E-00001102-00000004-20021102}.dat
[2009/09/05 12:40:22 | 00,000,281 | RHS- | M] () – C:\boot.ini
[2009/09/05 12:34:11 | 03,195,526 | R— | M] () – D:\Users\Eric\Desktop\Combo-Fix.exe
[2009/09/05 09:03:23 | 00,000,963 | —- | M] () – C:\WINDOWS\win.ini
[2009/09/05 09:03:23 | 00,000,211 | —- | M] () – C:\Boot.bak
[2009/09/05 08:26:12 | 00,002,626 | —- | M] () – C:\WINDOWS\System32\CONFIG.NT
[2009/09/05 07:33:47 | 00,017,306 | —- | M] () – C:\WINDOWS\ugul._sy
[2009/09/05 07:33:47 | 00,016,967 | —- | M] () – C:\WINDOWS\patukup.db
[2009/09/05 07:33:47 | 00,015,992 | —- | M] () – C:\Documents and Settings\Eric\Local Settings\Application Data\bedil.lib
[2009/09/05 07:33:46 | 00,016,462 | —- | M] () – C:\Documents and Settings\All Users\Documents\dekorugup._sy
[2009/09/05 07:33:46 | 00,012,146 | —- | M] () – C:\Documents and Settings\All Users\Documents\ekaqogakur.lib
[2009/09/04 23:07:50 | 00,013,053 | —- | M] () – C:\Documents and Settings\Eric\Local Settings\Application Data\jamovameqa.db
[2009/09/04 16:59:41 | 00,015,834 | —- | M] () – C:\Documents and Settings\All Users\Documents\kylalyveky._sy
[2009/09/04 16:59:41 | 00,011,804 | —- | M] () – C:\Documents and Settings\All Users\Documents\ixamy.dat
[2009/09/04 13:58:00 | 00,000,922 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-2000478354-1177238915-725345543-1004Core.job
[2009/09/03 22:25:22 | 00,230,912 | —- | M] () – C:\WINDOWS\PEV.exe
[2009/09/03 20:29:00 | 00,000,926 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-2000478354-1177238915-725345543-1006Core.job
[2009/08/31 09:48:01 | 00,000,284 | —- | M] () – C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2009/08/17 12:10:20 | 01,279,456 | —- | M] (ALWIL Software) – C:\WINDOWS\System32\aswBoot.exe
[2009/08/17 12:06:54 | 00,093,392 | —- | M] (ALWIL Software) – C:\WINDOWS\System32\drivers\aswmon.sys
[2009/08/17 12:06:43 | 00,094,160 | —- | M] (ALWIL Software) – C:\WINDOWS\System32\drivers\aswmon2.sys
[2009/08/17 12:05:52 | 00,114,768 | —- | M] (ALWIL Software) – C:\WINDOWS\System32\drivers\aswSP.sys
[2009/08/17 12:05:37 | 00,020,560 | —- | M] (ALWIL Software) – C:\WINDOWS\System32\drivers\aswFsBlk.sys
[2009/08/17 12:04:29 | 00,023,152 | —- | M] (ALWIL Software) – C:\WINDOWS\System32\drivers\aswRdr.sys
[2009/08/17 12:03:21 | 00,026,944 | —- | M] (ALWIL Software) – C:\WINDOWS\System32\drivers\aavmker4.sys
[2009/08/17 12:02:50 | 00,097,480 | —- | M] (ALWIL Software) – C:\WINDOWS\System32\AVASTSS.scr
[2009/08/15 21:25:59 | 00,130,048 | —- | M] () – C:\Documents and Settings\Eric\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009/08/14 18:23:47 | 00,001,374 | —- | M] () – C:\WINDOWS\imsins.BAK

========== LOP Check ==========

[2009/09/05 17:23:30 | 00,000,000 | RH-D | M] – C:\Documents and Settings\All Users\Application Data
[2009/03/29 17:34:59 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{00D89592-F643-4D8D-8F0F-AFAE0F14D4C3}
[2008/08/31 15:18:27 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Brother
[2009/04/28 21:07:30 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Cakewalk
[2004/03/20 22:35:16 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\CyberLink
[2008/07/05 15:27:06 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\DVD Shrink
[2008/08/16 21:45:07 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\GRETECH
[2009/04/14 13:14:31 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Motive
[2008/12/27 23:34:31 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\pdf995
[2008/08/31 15:20:18 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\ScanSoft
[2008/03/13 22:39:12 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Softland
[2009/06/27 12:41:05 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TEMP
[2006/08/05 21:15:38 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Trymedia
[2004/07/12 21:14:26 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Viewpoint
[2007/10/27 21:40:01 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\vsosdk
[2009/09/05 12:50:53 | 00,000,000 | RH-D | M] – C:\Documents and Settings\Eric\Application Data
[2004/10/23 09:48:19 | 00,000,000 | —D | M] – C:\Documents and Settings\Eric\Application Data\.BitTornado
[2008/04/23 20:38:55 | 00,000,000 | —D | M] – C:\Documents and Settings\Eric\Application Data\Amazon
[2008/08/31 16:03:26 | 00,000,000 | R–D | M] – C:\Documents and Settings\Eric\Application Data\Brother
[2009/04/28 20:43:39 | 00,000,000 | —D | M] – C:\Documents and Settings\Eric\Application Data\Cakewalk
[2006/12/31 10:49:25 | 00,000,000 | —D | M] – C:\Documents and Settings\Eric\Application Data\GetRightToGo
[2008/08/16 21:44:29 | 00,000,000 | —D | M] – C:\Documents and Settings\Eric\Application Data\GRETECH
[2004/03/29 22:49:46 | 00,000,000 | —D | M] – C:\Documents and Settings\Eric\Application Data\InterTrust
[2009/04/14 13:06:50 | 00,000,000 | —D | M] – C:\Documents and Settings\Eric\Application Data\Motive
[2009/07/03 17:19:53 | 00,000,000 | —D | M] – C:\Documents and Settings\Eric\Application Data\Moyea
[2009/07/03 17:53:08 | 00,000,000 | —D | M] – C:\Documents and Settings\Eric\Application Data\MxBoost
[2008/10/31 13:45:05 | 00,000,000 | —D | M] – C:\Documents and Settings\Eric\Application Data\OpenOffice.org2
[2004/04/03 18:54:59 | 00,000,000 | —D | M] – C:\Documents and Settings\Eric\Application Data\Opera
[2008/10/21 20:16:24 | 00,000,000 | —D | M] – C:\Documents and Settings\Eric\Application Data\PC-FAX TX
[2008/09/06 11:00:35 | 00,000,000 | —D | M] – C:\Documents and Settings\Eric\Application Data\pdf995
[2006/01/15 14:15:34 | 00,000,000 | —D | M] – C:\Documents and Settings\Eric\Application Data\Premiere
[2008/12/30 20:27:11 | 00,000,000 | —D | M] – C:\Documents and Settings\Eric\Application Data\REAPER
[2004/03/29 22:49:45 | 00,000,000 | —D | M] – C:\Documents and Settings\Eric\Application Data\Roxio
[2004/04/06 20:31:57 | 00,000,000 | —D | M] – C:\Documents and Settings\Eric\Application Data\Share-to-Web Upload Folder
[2004/11/07 20:32:48 | 00,000,000 | —D | M] – C:\Documents and Settings\Eric\Application Data\Steinberg
[2007/05/20 13:31:20 | 00,000,000 | —D | M] – C:\Documents and Settings\Eric\Application Data\SynthFont
[2004/04/06 21:37:10 | 00,000,000 | —D | M] – C:\Documents and Settings\Eric\Application Data\Toolbars
[2007/10/27 22:08:59 | 00,000,000 | —D | M] – C:\Documents and Settings\Eric\Application Data\Vso
[2009/08/31 09:48:01 | 00,000,284 | —- | M] () – C:\WINDOWS\Tasks\AppleSoftwareUpdate.job
[2003/03/31 08:00:00 | 00,000,065 | RH– | M] () – C:\WINDOWS\Tasks\desktop.ini
[2009/09/04 13:58:00 | 00,000,922 | —- | M] () – C:\WINDOWS\Tasks\GoogleUpdateTaskUserS-1-5-21-2000478354-1177238915-725345543-1004Core.job
[2009/09/05 17:58:00 | 00,000,974 | —- | M] () – C:\WINDOWS\Tasks\GoogleUpdateTaskUserS-1-5-21-2000478354-1177238915-725345543-1004UA.job
[2009/09/03 20:29:00 | 00,000,926 | —- | M] () – C:\WINDOWS\Tasks\GoogleUpdateTaskUserS-1-5-21-2000478354-1177238915-725345543-1006Core.job
[2009/09/05 17:29:00 | 00,000,978 | —- | M] () – C:\WINDOWS\Tasks\GoogleUpdateTaskUserS-1-5-21-2000478354-1177238915-725345543-1006UA.job
[2009/09/05 17:27:59 | 00,000,006 | -H– | M] () – C:\WINDOWS\Tasks\SA.DAT
[2009/09/05 18:15:00 | 00,000,422 | -H– | M] () – C:\WINDOWS\Tasks\User_Feed_Synchronization-{41FA4664-24F9-49C8-ABCF-3D592CD4C8BD}.job

========== Purity Check ==========



========== Alternate Data Streams ==========

@Alternate Data Stream - 185 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:E29ACA54
< End of report >
Hi modena2904,

Ok, that's fine. The files were removed regardless. You could have a look in this folder C:\Qoobox
and see if CFScript.txt is there.

You have some old vulnerable java installed as well as something left over from Norton (Symantec)

Open Control Panel > Add/Remove Programs and uninstall

Java 2 Runtime Environment, SE v1.4.2_01
Java 2 Runtime Environment, SE v1.4.2_03
LiveUpdate 2.6 (Symantec Corporation)


Do not uninstall Java TM 6 Update 14 if found! :yeah:

Click your start button, open Control panel
  • Locate the Java icon (it looks like a coffee cup)
  • double click it to open it
  • click the Update tab
  • Click update now

After the java is updated, reboot your computer if not prompted to.

Next, Double click on OTL.exe
  • Under the Custom Scans/Fixes box at the bottom, paste in the following
  • Do Not copy the word CODE
  • please note the fix starts with the :
:OTL
MsConfig - StartUpReg: Antivirus Pro 2010 - hkey= - key= - C:\Program Files\AntivirusPro_2010\AntivirusPro_2010.exe File not found
2009/09/05 07:33:47 | 00,017,306 | —- | C] () – C:\WINDOWS\ugul._sy
[2009/09/05 07:33:47 | 00,016,967 | —- | C] () – C:\WINDOWS\patukup.db
[2009/09/05 07:33:47 | 00,015,992 | —- | C] () – C:\Documents and Settings\Eric\Local Settings\Application Data\bedil.lib
[2009/09/05 07:33:46 | 00,016,462 | —- | C] () – C:\Documents and Settings\All Users\Documents\dekorugup._sy
[2009/09/05 07:33:46 | 00,012,146 | —- | C] () – C:\Documents and Settings\All Users\Documents\ekaqogakur.lib
[2009/09/04 23:07:50 | 00,013,053 | —- | C] () – C:\Documents and Settings\Eric\Local Settings\Application Data\jamovameqa.db
[2009/09/04 16:59:41 | 00,015,834 | —- | C] () – C:\Documents and Settings\All Users\Documents\kylalyveky._sy
[2009/09/04 16:59:41 | 00,011,804 | —- | C] () – C:\Documents and Settings\All Users\Documents\ixamy.dat

:Commands
[emptytemp]
[reboot]

Then click the Run Fix button at the top
  • Let the program run unhindered
  • Please save the resulting log to be posted in your next reply.

Let's make sure no changes were made while we were cleaning your computer.

You have this program installed, Malwarebytes' Anti-Malware (MBAM). Please update it and run a scan.

Open MBAM

  • Click the Update tab
  • Click Check for Updates
  • If an update is found, it will download and install the latest version.
  • The program will close to update and reopen.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish,so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected.
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.
Extra Note:
If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process,if asked to restart the computer,please do so immediatly.

Please post back with
  • OTL fix log
  • MBAM log
Let me know how the java update went and if you were able to locate CFScript.txt. Also any problems you are pesently having.

Thanks
The OTL Fix log and MBAM log are pasted below. The MBAM scan was clean. I deleted the two older Java items and completed the Java update without any issues. I did find the CFScript in the directory you cited – it was saved as CFScript_used_2009-09-05_17.15.42.txt. It appears to match the original script that you posted, including the URL. The PC appears to be running normally. I can't find any trace of Anti-Virus Pro 2010, including in the msconfig startup items. Thanks. - Eric ====== OTL Fix Log ====== All processes killed ========== OTL ========== Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\StartUpReg\Antivirus Pro 2010\ deleted successfully. C:\WINDOWS\patukup.db moved successfully. C:\Documents and Settings\Eric\Local Settings\Application Data\bedil.lib moved successfully. C:\Documents and Settings\All Users\Documents\dekorugup._sy moved successfully. C:\Documents and Settings\All Users\Documents\ekaqogakur.lib moved successfully. C:\Documents and Settings\Eric\Local Settings\Application Data\jamovameqa.db moved successfully. C:\Documents and Settings\All Users\Documents\kylalyveky._sy moved successfully. C:\Documents and Settings\All Users\Documents\ixamy.dat moved successfully. ========== COMMANDS ========== [EMPTYTEMP] User: Administrator ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 67 bytes User: All Users User: Amy User: Brian ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 373795 bytes ->Java cache emptied: 38801936 bytes ->Google Chrome cache emptied: 350465367 bytes User: Default User ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 67 bytes User: Eric ->Temp folder emptied: 2503555 bytes ->Temporary Internet Files folder emptied: 2569435 bytes ->Java cache emptied: 13425775 bytes ->FireFox cache emptied: 103066464 bytes ->Google Chrome cache emptied: 147822189 bytes User: Katie ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 373795 bytes ->Java cache emptied: 24134220 bytes ->FireFox cache emptied: 1124082 bytes User: Katie Lou ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 78991 bytes ->Java cache emptied: 13425519 bytes User: LocalService ->Temp folder emptied: 0 bytes File delete failed. C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot. ->Temporary Internet Files folder emptied: 32902 bytes User: NetworkService ->Temp folder emptied: 0 bytes File delete failed. C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot. ->Temporary Internet Files folder emptied: 49286 bytes C:\~QTWTMP.TMP folder deleted successfully. %systemdrive% .tmp files removed: 14648 bytes C:\WINDOWS\A8B9466986544126BD28D0D2412CDED6.TMP folder deleted successfully. %systemroot% .tmp files removed: 5677185 bytes %systemroot%\System32 .tmp files removed: 5838581 bytes File delete failed. C:\WINDOWS\temp\_avast4_\Webshlock.txt scheduled to be deleted on reboot. File delete failed. C:\WINDOWS\temp\Perflib_Perfdata_580.dat scheduled to be deleted on reboot. Windows Temp folder emptied: 17048 bytes RecycleBin emptied: 0 bytes Total Files Cleaned = 676.91 mb OTL by OldTimer - Version 3.0.10.7 log created on 09052009_195949 Files\Folders moved on Reboot… File move failed. C:\WINDOWS\temp\_avast4_\Webshlock.txt scheduled to be moved on reboot. C:\WINDOWS\temp\Perflib_Perfdata_580.dat moved successfully. Registry entries deleted on Reboot… ======= MBAM Log ======= Malwarebytes' Anti-Malware 1.40 Database version: 2746 Windows 5.1.2600 Service Pack 3 9/5/2009 8:17:23 PM mbam-log-2009-09-05 (20-17-23).txt Scan type: Quick Scan Objects scanned: 121009 Time elapsed: 9 minute(s), 32 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 0 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 0 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: (No malicious items detected) Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: (No malicious items detected)
Hi modena2904,

It appears to match the original script that you posted, including the URL.

Thanks. I'll have to look into that. It won't effect what we are doing.

So far so good. One more scan just to confirm our handiwork.

*Note
It is recommended to disable onboard antivirus program and antispyware programs while performing scans so there are no conflicts and it will speed up scan time.
Please don't go surfing while your resident protection is disabled!
Once the scan is finished remember to re-enable your antivirus along with your antispyware programs.



Please go to Kaspersky website and perform an online antivirus scan.
  • Read through the requirements and privacy statement and click on Accept button.
  • It will start downloading and installing the scanner and virus definitions.
  • You will be prompted to install an application from Kaspersky. Click Run.
  • When the downloads have finished, click on Settings.
  • Make sure these boxes are checked (ticked). If they are not, please tick them and click on the Save button
    • Spyware, Adware, Dialers, and other potentially dangerous programs
    • Archives
    • Mail databases
  • Click on My Computerr under Scan.
  • Once the scan is complete, it will display the results. Click on View Scan Report.
  • You will see a list of infected items there. Click on Save Report As….
  • Change the Files of type to Text file (.txt)
  • Set the Save In to Desktop
  • click the Save button.
  • Please post this log in your next reply.

Next
  • Double click on OTL.exe to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output
  • Uncheck the boxes beside LOP Check and Purity Check.
  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
Please post back with
  • Kaspersky log
  • OTL log

Thanks
Kaspersky and OTL logs are pasted below.

Thanks.

- Eric


========= Kaspersky Log =========

——————————————————————————–
KASPERSKY ONLINE SCANNER 7.0: scan report
Sunday, September 6, 2009
Operating system: Microsoft Windows XP Professional Service Pack 3 (build 2600)
Kaspersky Online Scanner version: 7.0.26.13
Last database update: Sunday, September 06, 2009 03:33:18
Records in database: 2751034
——————————————————————————–

Scan settings:
scan using the following database: extended
Scan archives: yes
Scan e-mail databases: yes

Scan area - My Computer:
A:\
C:\
D:\
E:\
F:\
G:\
H:\
L:\
Z:\

Scan statistics:
Objects scanned: 349890
Threats found: 4
Infected objects found: 8
Suspicious objects found: 0
Scan duration: 07:53:57


File name / Threat / Threats count
C:\Program Files\Puppy Luv\bfgt_silent_en.exe Infected: not-a-virus:AdWare.Win32.BHO.w 1
C:\Qoobox\Quarantine\C\Program Files\AntivirusPro_2010\wscui.cpl.vir Infected: not-a-virus:FraudTool.Win32.XPSecurityCenter.dj 1
C:\System Volume Information\_restore{489613BB-153B-4368-8BB5-A0D07A9BBA43}\RP1958\A0307737.sys Infected: Backdoor.Win32.UltimateDefender.igv 1
C:\System Volume Information\_restore{489613BB-153B-4368-8BB5-A0D07A9BBA43}\RP1958\A0307738.sys Infected: Backdoor.Win32.UltimateDefender.igv 1
C:\System Volume Information\_restore{489613BB-153B-4368-8BB5-A0D07A9BBA43}\RP1958\A0307739.cpl Infected: not-a-virus:FraudTool.Win32.XPSecurityCenter.dj 1
C:\System Volume Information\_restore{489613BB-153B-4368-8BB5-A0D07A9BBA43}\RP1958\A0307762.cpl Infected: not-a-virus:FraudTool.Win32.XPSecurityCenter.dj 1
C:\System Volume Information\_restore{489613BB-153B-4368-8BB5-A0D07A9BBA43}\RP1958\A0307783.exe Infected: Packed.Win32.Krap.x 1
C:\System Volume Information\_restore{489613BB-153B-4368-8BB5-A0D07A9BBA43}\RP1958\A0308233.cpl Infected: not-a-virus:FraudTool.Win32.XPSecurityCenter.dj 1

Selected area has been scanned.



======== OTL Log =========

OTL logfile created on: 9/6/2009 6:18:15 AM - Run 2
OTL by OldTimer - Version 3.0.10.7 Folder = D:\Users\Eric\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

1.50 Gb Total Physical Memory | 0.98 Gb Available Physical Memory | 65.16% Memory free
4.00 Gb Paging File | 3.76 Gb Available in Paging File | 94.02% Paging File free
Paging file location(s): L:\pagefile.sys 3072 3072 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 73.24 Gb Total Space | 23.14 Gb Free Space | 31.59% Space Free | Partition Type: NTFS
Drive D: | 73.24 Gb Total Space | 38.89 Gb Free Space | 53.10% Space Free | Partition Type: NTFS
Drive E: | 117.19 Gb Total Space | 105.55 Gb Free Space | 90.07% Space Free | Partition Type: NTFS
Drive F: | 34.42 Gb Total Space | 14.83 Gb Free Space | 43.08% Space Free | Partition Type: NTFS
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Drive L: | 465.76 Gb Total Space | 236.86 Gb Free Space | 50.85% Space Free | Partition Type: NTFS
Drive Z: | 73.24 Gb Total Space | 38.89 Gb Free Space | 53.10% Space Free | Partition Type: NTFS

Computer Name: FAMILYPC3
Current User Name: Eric
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal

========== Processes (SafeList) ==========

PRC - C:\WINDOWS\System32\Ati2evxx.exe ()
PRC - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe (ALWIL Software)
PRC - C:\Program Files\Alwil Software\Avast4\ashServ.exe (ALWIL Software)
PRC - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe (Apple Inc.)
PRC - C:\Program Files\Bonjour\mDNSResponder.exe (Apple Inc.)
PRC - C:\WINDOWS\System32\CTsvcCDA.exe (Creative Technology Ltd)
PRC - c:\program files\dell printers\Additional Color Laser Software\Status Monitor\DLSDBNT.EXE (Dell Inc.)
PRC - C:\Program Files\DriveCrypt\DcrServ.exe ()
PRC - C:\Program Files\Java\jre6\bin\jqs.exe (Sun Microsystems, Inc.)
PRC - C:\Program Files\M-Audio\M-Audio Series II MIDI\MA_CMIDI_Inst.exe ()
PRC - C:\Program Files\UPHClean\uphclean.exe (Microsoft Corporation)
PRC - C:\WINDOWS\System32\MsPMSPSv.exe (Microsoft Corporation)
PRC - C:\WINDOWS\System32\ZuneBusEnum.exe (Microsoft Corporation)
PRC - c:\program files\dell printers\Additional Color Laser Software\Status Monitor\DLPWDNT.EXE (Dell Inc.)
PRC - C:\WINDOWS\System32\Ati2evxx.exe ()
PRC - C:\WINDOWS\Explorer.EXE (Microsoft Corporation)
PRC - C:\Program Files\Creative\SBAudigy2ZS\Surround Mixer\CTSysVol.exe (Creative Technology Ltd)
PRC - C:\Program Files\Creative\SBAudigy2ZS\DVDAudio\CTDVDDET.EXE (Creative Technology Ltd)
PRC - C:\WINDOWS\System32\CTHELPER.EXE (Creative Technology Ltd)
PRC - C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe (ATI Technologies, Inc.)
PRC - C:\Program Files\Roxio\Easy CD Creator 6\DragToDisc\DrgToDsc.exe (Roxio)
PRC - C:\Program Files\Roxio\Easy CD Creator 6\AudioCentral\RxMon.exe (Roxio, Inc.)
PRC - C:\Program Files\Roxio\Easy CD Creator 6\AudioCentral\Playlist.exe (Roxio, Inc.)
PRC - C:\Program Files\Creative\Prodikeys\Prodload.exe (Creative Technology Ltd)
PRC - C:\Program Files\Alwil Software\Avast4\ashDisp.exe (ALWIL Software)
PRC - C:\Program Files\Roland\VSC32\vsc32cnf.exe (Roland)
PRC - C:\Program Files\Roland\VSC32\vscvol.exe (Roland)
PRC - C:\Program Files\Sony\SonicStage\SSAAD.exe ()
PRC - C:\program files\dell printers\Additional Color Laser Software\Status Monitor\DLPSP.EXE (Dell Inc.)
PRC - C:\Program Files\Brother\Brmfcmon\BrMfcWnd.exe (Brother Industries, Ltd.)
PRC - C:\Program Files\Zune\ZuneLauncher.exe (Microsoft Corporation)
PRC - C:\Program Files\Brother\ControlCenter3\brccMCtl.exe (Brother Industries, Ltd.)
PRC - C:\Program Files\iTunes\iTunesHelper.exe (Apple Inc.)
PRC - C:\Program Files\Java\jre6\bin\jusched.exe (Sun Microsystems, Inc.)
PRC - C:\Program Files\Logitech\Profiler\lwemon.exe (Logitech Inc.)
PRC - C:\Program Files\Creative\MediaSource\RemoteControl\RcMan.exe (Creative Technology Ltd)
PRC - C:\Program Files\Creative\MediaSource\Go\CTCMSGo.exe (Creative Technology Ltd)
PRC - C:\Program Files\Brother\Brmfcmon\BrMfimon.exe (Brother Industries, Ltd.)
PRC - C:\Program Files\iPod\bin\iPodService.exe (Apple Inc.)
PRC - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe (ALWIL Software)
PRC - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe (ALWIL Software)
PRC - D:\Users\Eric\Desktop\OTL.exe (OldTimer Tools)

========== Win32 Services (SafeList) ==========

SRV - (Apple Mobile Device [Auto | Running]) – C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe (Apple Inc.)
SRV - (aspnet_state [On_Demand | Stopped]) – C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe (Microsoft Corporation)
SRV - (aswUpdSv [Auto | Running]) – C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe (ALWIL Software)
SRV - (Ati HotKey Poller [Auto | Running]) – C:\WINDOWS\System32\Ati2evxx.exe ()
SRV - (ATI Smart [Auto | Stopped]) – C:\WINDOWS\System32\ati2sgag.exe ()
SRV - (avast! Antivirus [Auto | Running]) – C:\Program Files\Alwil Software\Avast4\ashServ.exe (ALWIL Software)
SRV - (avast! Mail Scanner [On_Demand | Running]) – C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe (ALWIL Software)
SRV - (avast! Web Scanner [On_Demand | Running]) – C:\Program Files\Alwil Software\Avast4\ashWebSv.exe (ALWIL Software)
SRV - (Bonjour Service [Auto | Running]) – C:\Program Files\Bonjour\mDNSResponder.exe (Apple Inc.)
SRV - (clr_optimization_v2.0.50727_32 [On_Demand | Stopped]) – C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
SRV - (Creative Service for CDROM Access [Auto | Running]) – C:\WINDOWS\System32\CTsvcCDA.exe (Creative Technology Ltd)
SRV - (DLPWD [Auto | Running]) – c:\program files\dell printers\Additional Color Laser Software\Status Monitor\DLPWDNT.EXE (Dell Inc.)
SRV - (DLSDB [Auto | Running]) – c:\program files\dell printers\Additional Color Laser Software\Status Monitor\DLSDBNT.EXE (Dell Inc.)
SRV - (DriveCryptService [Auto | Running]) – C:\Program Files\DriveCrypt\DcrServ.exe ()
SRV - (FontCache3.0.0.0 [On_Demand | Stopped]) – C:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe (Microsoft Corporation)
SRV - (getPlus® Helper [On_Demand | Stopped]) – C:\Program Files\NOS\bin\getPlus_HelperSvc.exe (NOS Microsystems Ltd.)
SRV - (helpsvc [Auto | Running]) – C:\WINDOWS\PCHealth\HelpCtr\Binaries\pchsvc.dll (Microsoft Corporation)
SRV - (IDriverT [On_Demand | Stopped]) – C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe (Macrovision Corporation)
SRV - (idsvc [Unknown | Stopped]) – C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe (Microsoft Corporation)
SRV - (iPod Service [On_Demand | Running]) – C:\Program Files\iPod\bin\iPodService.exe (Apple Inc.)
SRV - (JavaQuickStarterService [Auto | Running]) – C:\Program Files\Java\jre6\bin\jqs.exe (Sun Microsystems, Inc.)
SRV - (MA_CMIDI_InstallerService [Auto | Running]) – C:\Program Files\M-Audio\M-Audio Series II MIDI\MA_CMIDI_Inst.exe ()
SRV - (MSCSPTISRV [On_Demand | Stopped]) – C:\Program Files\Common Files\Sony Shared\AVLib\MSCSPTISRV.exe (Sony Corporation)
SRV - (NetTcpPortSharing [Disabled | Stopped]) – C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe (Microsoft Corporation)
SRV - (PACSPTISVR [On_Demand | Stopped]) – C:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exe (Sony Corporation)
SRV - (Pml Driver HPZ12 [On_Demand | Stopped]) – C:\WINDOWS\System32\HPZipm12.exe (HP)
SRV - (SPTISRV [On_Demand | Stopped]) – C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe (Sony Corporation)
SRV - (SSScsiSV [On_Demand | Stopped]) – C:\Program Files\Common Files\Sony Shared\AVLib\SSScsiSV.exe (Sony Corporation)
SRV - (UPHClean [Auto | Running]) – C:\Program Files\UPHClean\uphclean.exe (Microsoft Corporation)
SRV - (WMDM PMSP Service [Auto | Running]) – C:\WINDOWS\System32\MsPMSPSv.exe (Microsoft Corporation)
SRV - (WMPNetworkSvc [On_Demand | Stopped]) – C:\Program Files\Windows Media Player\WMPNetwk.exe (Microsoft Corporation)
SRV - (ZuneBusEnum [Auto | Running]) – C:\WINDOWS\System32\ZuneBusEnum.exe (Microsoft Corporation)
SRV - (ZuneNetworkSvc [On_Demand | Stopped]) – C:\Program Files\Zune\ZuneNss.exe (Microsoft Corporation)
SRV - (ZuneWlanCfgSvc [On_Demand | Stopped]) – C:\WINDOWS\System32\ZuneWlanCfgSvc.exe (Microsoft Corporation)

========== Driver Services (SafeList) ==========

DRV - (61883 [On_Demand | Stopped]) – C:\WINDOWS\System32\DRIVERS\61883.sys (Microsoft Corporation)
DRV - (Aavmker4 [System | Running]) – C:\WINDOWS\System32\drivers\aavmker4.sys (ALWIL Software)
DRV - (AmdK8 [System | Running]) – C:\WINDOWS\System32\DRIVERS\AmdK8.sys (Advanced Micro Devices)
DRV - (ASAPIW2k [On_Demand | Running]) – C:\WINDOWS\System32\drivers\ASAPIW2k.sys (Pinnacle Systems GmbH)
DRV - (aslm75 [Auto | Running]) – C:\WINDOWS\System32\drivers\aslm75.sys ()
DRV - (aswFsBlk [Auto | Running]) – C:\WINDOWS\System32\DRIVERS\aswFsBlk.sys (ALWIL Software)
DRV - (aswMon2 [Auto | Running]) – C:\WINDOWS\System32\drivers\aswmon2.sys (ALWIL Software)
DRV - (aswRdr [On_Demand | Running]) – C:\WINDOWS\System32\drivers\aswRdr.sys (ALWIL Software)
DRV - (aswSP [System | Running]) – C:\WINDOWS\System32\drivers\aswSP.sys (ALWIL Software)
DRV - (ati2mtag [On_Demand | Running]) – C:\WINDOWS\System32\DRIVERS\ati2mtag.sys (ATI Technologies Inc.)
DRV - (atinrvxx [On_Demand | Running]) – C:\WINDOWS\System32\DRIVERS\atinrvxx.sys (ATI Technologies Inc.)
DRV - (Avc [On_Demand | Stopped]) – C:\WINDOWS\System32\DRIVERS\avc.sys (Microsoft Corporation)
DRV - (BridDfu [Auto | Stopped]) – C:\WINDOWS\System32\Drivers\BridDfu.sys ()
DRV - (Cdr4_xp [System | Running]) – C:\WINDOWS\System32\drivers\cdr4_xp.sys (Roxio)
DRV - (Cdralw2k [System | Running]) – C:\WINDOWS\System32\drivers\cdralw2k.sys (Roxio)
DRV - (cdudf_xp [System | Running]) – C:\WINDOWS\System32\drivers\Cdudf_xp.sys (Roxio)
DRV - (ctac32k [On_Demand | Running]) – C:\WINDOWS\System32\drivers\ctac32k.sys (Creative Technology Ltd)
DRV - (ctaud2k [On_Demand | Running]) – C:\WINDOWS\System32\drivers\ctaud2k.sys (Creative Technology Ltd)
DRV - (ctdvda2k [On_Demand | Stopped]) – C:\WINDOWS\System32\drivers\ctdvda2k.sys (Creative Technology Ltd)
DRV - (ctprxy2k [On_Demand | Running]) – C:\WINDOWS\System32\drivers\ctprxy2k.sys (Creative Technology Ltd)
DRV - (ctsfm2k [On_Demand | Running]) – C:\WINDOWS\System32\drivers\ctsfm2k.sys (Creative Technology Ltd)
DRV - (DCR [Boot | Running]) – C:\WINDOWS\System32\Drivers\DCR.sys ()
DRV - (DVDVRRdr_xp [System | Running]) – C:\WINDOWS\System32\drivers\DVDVRRdr_xp.sys (Roxio)
DRV - (dvd_2K [On_Demand | Running]) – C:\WINDOWS\System32\drivers\Dvd_2k.sys (Roxio)
DRV - (EIO [On_Demand | Stopped]) – C:\WINDOWS\System32\drivers\EIO.sys (ASUSTeK Computer Inc.)
DRV - (EL2000 [On_Demand | Running]) – C:\WINDOWS\System32\DRIVERS\EL2K_XP.sys (3Com Corporation)
DRV - (emupia [On_Demand | Running]) – C:\WINDOWS\System32\drivers\emupia2k.sys (Creative Technology Ltd)
DRV - (gameenum [On_Demand | Running]) – C:\WINDOWS\System32\DRIVERS\gameenum.sys (Microsoft Corporation)
DRV - (GEARAspiWDM [On_Demand | Running]) – C:\WINDOWS\System32\DRIVERS\GEARAspiWDM.sys (GEAR Software Inc.)
DRV - (ha10kx2k [On_Demand | Running]) – C:\WINDOWS\System32\drivers\ha10kx2k.sys (Creative Technology Ltd)
DRV - (hap16v2k [On_Demand | Running]) – C:\WINDOWS\System32\drivers\hap16v2k.sys (Creative Technology Ltd)
DRV - (HPZid412 [On_Demand | Stopped]) – C:\WINDOWS\System32\DRIVERS\HPZid412.sys (HP)
DRV - (HPZipr12 [On_Demand | Stopped]) – C:\WINDOWS\System32\DRIVERS\HPZipr12.sys (HP)
DRV - (HPZius12 [On_Demand | Stopped]) – C:\WINDOWS\System32\DRIVERS\HPZius12.sys (HP)
DRV - (MA_CMIDI [On_Demand | Stopped]) – C:\WINDOWS\System32\drivers\ma_cmidi.sys (M-Audio)
DRV - (mmc_2K [On_Demand | Stopped]) – C:\WINDOWS\System32\drivers\Mmc_2k.sys (Roxio)
DRV - (motmodem [On_Demand | Stopped]) – C:\WINDOWS\System32\DRIVERS\motmodem.sys (Motorola)
DRV - (MREMP50 [On_Demand | Stopped]) – C:\Program Files\Common Files\Motive\MREMP50.sys (Printing Communications Assoc., Inc. (PCAUSA))
DRV - (MRESP50 [On_Demand | Stopped]) – C:\Program Files\Common Files\Motive\MRESP50.sys (Printing Communications Assoc., Inc. (PCAUSA))
DRV - (MSDV [On_Demand | Stopped]) – C:\WINDOWS\System32\DRIVERS\msdv.sys (Microsoft Corporation)
DRV - (MVDCODEC [Auto | Running]) – C:\WINDOWS\System32\DRIVERS\atinmdxx.sys (ATI Technologies Inc.)
DRV - (ossrv [On_Demand | Running]) – C:\WINDOWS\System32\drivers\ctoss2k.sys (Creative Technology Ltd.)
DRV - (papycpu2 [System | Running]) – C:\WINDOWS\system32\drivers\papycpu2.sys ()
DRV - (papyjoy [System | Running]) – C:\WINDOWS\System32\DRIVERS\papyjoy.sys ()
DRV - (pcouffin [On_Demand | Running]) – C:\WINDOWS\System32\Drivers\pcouffin.sys (VSO Software)
DRV - (pfc [On_Demand | Running]) – C:\WINDOWS\System32\drivers\pfc.sys (Padus, Inc.)
DRV - (PfDetNT [Auto | Running]) – C:\WINDOWS\System32\drivers\PfModNT.sys (Creative Technology Ltd.)
DRV - (PfModNT [Auto | Stopped]) – C:\WINDOWS\System32\drivers\PfModNT.sys (Creative Technology Ltd.)
DRV - (Prodikeys [On_Demand | Running]) – C:\WINDOWS\System32\DRIVERS\ProdDrvr.sys (Creative Technology Ltd)
DRV - (Ptilink [On_Demand | Running]) – C:\WINDOWS\System32\DRIVERS\ptilink.sys (Parallel Technologies, Inc.)
DRV - (pwd_2k [System | Running]) – C:\WINDOWS\System32\drivers\pwd_2K.sys (Roxio)
DRV - (PxHelp20 [Boot | Running]) – C:\WINDOWS\System32\DRIVERS\PxHelp20.sys (Sonic Solutions)
DRV - (RVIEGVST [Auto | Running]) – C:\Program Files\Roland\Virtual Sound Canvas VST\RVIEg01VST.sys (Roland)
DRV - (Secdrv [On_Demand | Stopped]) – C:\WINDOWS\System32\DRIVERS\secdrv.sys (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.)
DRV - (StillCam [On_Demand | Running]) – C:\WINDOWS\System32\DRIVERS\serscan.sys (Microsoft Corporation)
DRV - (UdfReadr_xp [System | Running]) – C:\WINDOWS\System32\drivers\UdfReadr_xp.sys (Roxio)
DRV - (usbaudio [On_Demand | Stopped]) – C:\WINDOWS\System32\drivers\usbaudio.sys (Microsoft Corporation)
DRV - (usbbus [On_Demand | Stopped]) – C:\WINDOWS\System32\DRIVERS\lgusbbus.sys (LG Electronics Inc.)
DRV - (UsbDiag [On_Demand | Stopped]) – C:\WINDOWS\System32\DRIVERS\lgusbdiag.sys (LG Electronics Inc.)
DRV - (USBModem [On_Demand | Stopped]) – C:\WINDOWS\System32\DRIVERS\lgusbmodem.sys (LG Electronics Inc.)
DRV - (viaagp1 [Boot | Running]) – C:\WINDOWS\System32\DRIVERS\viaagp1.sys (VIA Technologies, Inc.)
DRV - (viamraid [Boot | Running]) – C:\WINDOWS\system32\DRIVERS\viamraid.sys (VIA Technologies inc,.ltd)
DRV - (viasraid [Boot | Running]) – C:\WINDOWS\system32\drivers\viasraid.sys (VIA Technologies inc,.ltd)
DRV - (vsc32 [On_Demand | Running]) – C:\WINDOWS\System32\DRIVERS\vsc.sys (Roland)
DRV - (WinUSB [On_Demand | Stopped]) – C:\WINDOWS\System32\DRIVERS\WinUSB.sys (Microsoft Corporation)
DRV - (WmBEnum [On_Demand | Running]) – C:\WINDOWS\System32\drivers\WmBEnum.sys (Logitech Inc.)
DRV - (WmFilter [On_Demand | Stopped]) – C:\WINDOWS\System32\drivers\WmFilter.sys (Logitech Inc.)
DRV - (WmHidLo [On_Demand | Stopped]) – C:\WINDOWS\System32\drivers\WmHidLo.sys (Logitech Inc.)
DRV - (WmVirHid [On_Demand | Stopped]) – C:\WINDOWS\System32\drivers\WmVirHid.sys (Logitech Inc.)
DRV - (WmXlCore [On_Demand | Running]) – C:\WINDOWS\System32\drivers\WmXlCore.sys (Logitech Inc.)
DRV - (zumbus [Auto | Running]) – C:\WINDOWS\System32\DRIVERS\zumbus.sys (Microsoft Corporation)

========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = [binary data]
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:NoAdd-ons
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:SecurityRisk
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomizeSearch = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\system32\blank.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?p…amp;ar=iesearch
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultName = Google
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultURL = http://www.google.com/search?q={searchTerms}
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local

========== FireFox ==========

FF - prefs.js..browser.search.selectedEngine: "Google"
FF - prefs.js..browser.startup.homepage: "http://start.mozilla.org/firefox?client=firefox-a&rls;=org.mozilla:en-US:official"
FF - prefs.js..extensions.enabledItems: {DDC359D1-844A-42a7-9AA1-88A850A938A8}:1.1.4
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0010-ABCDEFFEDCBA}:6.0.10
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA}:6.0.11
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA}:6.0.13
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0014-ABCDEFFEDCBA}:6.0.14
FF - prefs.js..extensions.enabledItems: [removed]:1.0
FF - prefs.js..extensions.enabledItems: {914DC373-ACF6-4305-B877-8508A576E9B6}:0.6.2
FF - prefs.js..extensions.enabledItems: {20a82645-c095-46ed-80e3-08825760534b}:1.1
FF - prefs.js..extensions.enabledItems: {B7080EEB-ED19-455C-BFA8-12EEC8A20D83}:1.0
FF - prefs.js..extensions.enabledItems: {8848879C-0C9D-4FCD-8E2D-8E6623B83023}:1.0
FF - prefs.js..extensions.enabledItems: {CE313A2C-1D74-44D0-8468-FD24A759C19F}:1.0
FF - prefs.js..extensions.enabledItems: {934CD260-2FEA-4669-9520-0119415E7052}:1.0
FF - prefs.js..extensions.enabledItems: {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.0

FF - HKLM\software\mozilla\Firefox\extensions\\{20a82645-c095-46ed-80e3-08825760534b}: C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\ [2009/06/24 11:00:27 | 00,000,000 | —D | M]
FF - HKLM\software\mozilla\Firefox\extensions\\{60305F03-96C0-4B12-82EC-F43265C7B7F5}: C:\Documents and Settings\Amy\Local Settings\Application Data\{60305F03-96C0-4B12-82EC-F43265C7B7F5}
FF - HKLM\software\mozilla\Firefox\extensions\\[removed]: C:\Program Files\Java\jre6\lib\deploy\jqs\ff [2008/10/24 19:33:18 | 00,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.0\extensions\\Components: C:\Program Files\Firefox\components [2009/03/29 17:32:58 | 00,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.0\extensions\\Plugins: C:\Program Files\Firefox\plugins [2009/07/26 19:43:31 | 00,000,000 | —D | M]

[2008/06/21 15:59:54 | 00,000,000 | —D | M] – C:\Documents and Settings\Eric\Application Data\mozilla\Extensions
[2008/06/21 15:59:54 | 00,000,000 | —D | M] – C:\Documents and Settings\Eric\Application Data\mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}
[2009/08/25 06:20:22 | 00,000,000 | —D | M] – C:\Documents and Settings\Eric\Application Data\mozilla\Firefox\Profiles\s7rib94w.default\extensions
[2009/06/27 08:02:38 | 00,000,000 | —D | M] – C:\Documents and Settings\Eric\Application Data\mozilla\Firefox\Profiles\s7rib94w.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2008/06/21 20:18:17 | 00,000,000 | —D | M] – C:\Documents and Settings\Eric\Application Data\mozilla\Firefox\Profiles\s7rib94w.default\extensions\{914DC373-ACF6-4305-B877-8508A576E9B6}
[2009/07/04 16:23:09 | 00,000,000 | —D | M] – C:\Documents and Settings\Eric\Application Data\mozilla\Firefox\Profiles\s7rib94w.default\extensions\{DDC359D1-844A-42a7-9AA1-88A850A938A8}

O1 HOSTS File: (27 bytes) - C:\WINDOWS\System32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (JQSIEStartDetectorImpl Class) - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll (Sun Microsystems, Inc.)
O3 - HKCU\..\Toolbar\ShellBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {4064EA35-578D-4073-A834-C96D82CBCF40} - No CLSID value found.
O4 - HKLM..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe (ATI Technologies, Inc.)
O4 - HKLM..\Run: [avast!] C:\Program Files\Alwil Software\Avast4\ashDisp.exe (ALWIL Software)
O4 - HKLM..\Run: [BrMfcWnd] C:\Program Files\Brother\Brmfcmon\BrMfcWnd.exe (Brother Industries, Ltd.)
O4 - HKLM..\Run: [ControlCenter3] C:\Program Files\Brother\ControlCenter3\brctrcen.exe (Brother Industries, Ltd.)
O4 - HKLM..\Run: [CTDVDDET] C:\Program Files\Creative\SBAudigy2ZS\DVDAudio\CTDVDDET.EXE (Creative Technology Ltd)
O4 - HKLM..\Run: [CTHelper] C:\WINDOWS\System32\CTHELPER.EXE (Creative Technology Ltd)
O4 - HKLM..\Run: [CTSysVol] C:\Program Files\Creative\SBAudigy2ZS\Surround Mixer\CTSysVol.exe (Creative Technology Ltd)
O4 - HKLM..\Run: [DLPSP] c:\program files\dell printers\Additional Color Laser Software\Status Monitor\DLPSP.EXE (Dell Inc.)
O4 - HKLM..\Run: [ISUSPM Startup] C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe (Macrovision Corporation)
O4 - HKLM..\Run: [ISUSScheduler] C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe (Macrovision Corporation)
O4 - HKLM..\Run: [iTunesHelper] C:\Program Files\iTunes\iTunesHelper.exe (Apple Inc.)
O4 - HKLM..\Run: [PinnacleDriverCheck] C:\WINDOWS\System32\PSDrvCheck.exe ()
O4 - HKLM..\Run: [ProdikeysAutorun] C:\Program Files\Creative\Prodikeys\Prodload.exe (Creative Technology Ltd)
O4 - HKLM..\Run: [QuickTime Task] C:\Program Files\QuickTime\qttask.exe (Apple Inc.)
O4 - HKLM..\Run: [RoxioAudioCentral] C:\Program Files\Roxio\Easy CD Creator 6\AudioCentral\RxMon.exe (Roxio, Inc.)
O4 - HKLM..\Run: [RoxioDragToDisc] C:\Program Files\Roxio\Easy CD Creator 6\DragToDisc\DrgToDsc.exe (Roxio)
O4 - HKLM..\Run: [RoxioEngineUtility] C:\Program Files\Common Files\Roxio Shared\System\EngUtil.exe (Roxio)
O4 - HKLM..\Run: [SBDrvDet] C:\Program Files\Creative\SB Drive Det\SBDrvDet.exe (Creative Technology Ltd)
O4 - HKLM..\Run: [SsAAD.exe] C:\Program Files\Sony\SonicStage\SSAAD.exe ()
O4 - HKLM..\Run: [SSBkgdUpdate] C:\Program Files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe (Nuance Communications, Inc.)
O4 - HKLM..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre6\bin\jusched.exe (Sun Microsystems, Inc.)
O4 - HKLM..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE (Creative Technology Ltd.)
O4 - HKLM..\Run: [vsc32cnf.exe] C:\Program Files\Roland\VSC32\vsc32cnf.exe (Roland)
O4 - HKLM..\Run: [vscvol.exe] C:\Program Files\Roland\VSC32\vscvol.exe (Roland)
O4 - HKLM..\Run: [Zune Launcher] C:\Program Files\Zune\ZuneLauncher.exe (Microsoft Corporation)
O4 - HKCU..\Run: [Creative MediaSource Go] C:\Program Files\Creative\MediaSource\Go\CTCMSGo.exe (Creative Technology Ltd)
O4 - HKCU..\Run: [Google Update] C:\Documents and Settings\Eric\Local Settings\Application Data\Google\Update\GoogleUpdate.exe (Google Inc.)
O4 - HKCU..\Run: [RemoteCenter] C:\Program Files\Creative\MediaSource\RemoteControl\RcMan.exe (Creative Technology Ltd)
O4 - HKCU..\Run: [Start WingMan Profiler] C:\Program Files\Logitech\Profiler\lwemon.exe (Logitech Inc.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE (Microsoft Corporation)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: AllowLegacyWebView = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: AllowUnhashedWebView = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableRegistryTools = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoRecentDocsMenu = 01 00 00 00 [binary data]
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: ClearRecentDocsOnExit = 01 00 00 00 [binary data]
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoRecentDocsHistory = 01 00 00 00 [binary data]
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoLowDiskSpaceChecks = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O9 - Extra 'Tools' menuitem : @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe (Microsoft Corporation)
O9 - Extra Button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O15 - HKLM\..Trusted Domains: 1 domain(s) and sub-domain(s) not assigned to a zone.
O15 - HKCU\..Trusted Domains: familypc3 ([]file in Local intranet)
O15 - HKCU\..Trusted Domains: familypc4 ([]file in Local intranet)
O16 - DPF: {01113300-3E00-11D2-8470-0060089874ED} https://activatemyfios.verizon.net/sdcCommo…20Installer.cab (Support.com Configuration Class)
O16 - DPF: {0A5FD7C5-A45C-49FC-ADB5-9952547D5715} http://www.creative.com/su/ocx/15026/CTSUEng.cab (Creative Software AutoUpdate)
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://fpdownload.macromedia.com/pub/shock…director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {233C1507-6A77-46A4-9443-F871F945D258} http://fpdownload.macromedia.com/get/shock…director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} http://www.snapfish.com/SnapfishActivia.cab (Snapfish Activia)
O16 - DPF: {4CCA4E6B-9259-11D9-AC6E-444553544200} http://h30155.www3.hp.com/ediags/dd/instal…tallMgr_v01.cab (FixController Control)
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} http://update.microsoft.com/windowsupdate/…b?1136547307687 (WUWebControl Class)
O16 - DPF: {8A0019EB-51FA-4AE5-A40B-C0496BBFC739} http://picture.vzw.com/activex/VerizonWire…loadControl.cab (Verizon Wireless Media Upload)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_15)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get/flash…t/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {99FE5072-78AA-4FEE-89BA-69A5FA55343F} http://download.microsoft.com/download/B/3…44/igdtoolx.cab (IGDTester Class)
O16 - DPF: {A90A5822-F108-45AD-8482-9BC8B12DD539} http://www.crucial.com/controls/cpcScanner.cab (Crucial cpcScan)
O16 - DPF: {CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_15)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_15)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab (Shockwave Flash Object)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} http://www.creative.com/su/ocx/15026/CTPID.cab (Creative Software AutoUpdate Support Package)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.0.1
O18 - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\http\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\https\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\ipp - No CLSID value found
O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp - No CLSID value found
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\msdaipp.dll (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\Explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\AtiExtEvent: DllName - Ati2evxx.dll - C:\WINDOWS\System32\Ati2evxx.dll ()
O24 - Desktop Components:0 (My Current Home Page) - About:Home
O31 - SafeBoot: AlternateShell - cmd.exe
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2004/03/12 21:53:12 | 00,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O34 - HKLM BootExecute: (autocheck) - File not found
O34 - HKLM BootExecute: (autochk) - C:\WINDOWS\System32\autochk.exe (Microsoft Corporation)
O34 - HKLM BootExecute: (*) - File not found

========== Files/Folders - Created Within 30 Days ==========

[2009/09/05 20:00:36 | 00,000,000 | -HSD | C] – C:\RECYCLER
[2009/09/05 18:12:27 | 00,514,048 | —- | C] (OldTimer Tools) – D:\Users\Eric\Desktop\OTL.exe
[2009/09/05 12:40:21 | 00,000,211 | —- | C] () – C:\Boot.bak
[2009/09/05 12:40:18 | 00,260,272 | —- | C] () – C:\cmldr
[2009/09/05 12:40:16 | 00,000,000 | RHSD | C] – C:\cmdcons
[2009/09/05 12:39:23 | 00,230,912 | —- | C] () – C:\WINDOWS\PEV.exe
[2009/09/05 12:39:23 | 00,212,480 | —- | C] (SteelWerX) – C:\WINDOWS\SWXCACLS.exe
[2009/09/05 12:39:23 | 00,161,792 | —- | C] (SteelWerX) – C:\WINDOWS\SWREG.exe
[2009/09/05 12:39:23 | 00,136,704 | —- | C] (SteelWerX) – C:\WINDOWS\SWSC.exe
[2009/09/05 12:39:23 | 00,098,816 | —- | C] () – C:\WINDOWS\sed.exe
[2009/09/05 12:39:23 | 00,080,412 | —- | C] () – C:\WINDOWS\grep.exe
[2009/09/05 12:39:23 | 00,068,096 | —- | C] () – C:\WINDOWS\zip.exe
[2009/09/05 12:39:23 | 00,031,232 | —- | C] (NirSoft) – C:\WINDOWS\NIRCMD.exe
[2009/09/05 12:39:16 | 00,000,000 | —D | C] – C:\WINDOWS\ERDNT
[2009/09/05 12:38:53 | 00,000,000 | —D | C] – C:\Qoobox
[2009/09/05 12:34:11 | 03,195,526 | R— | C] () – D:\Users\Eric\Desktop\Combo-Fix.exe
[2009/09/05 09:19:52 | 00,000,000 | —D | C] – D:\Users\Eric\Desktop\Virus infection 2009-09-04
[2009/09/05 07:45:23 | 00,000,000 | —D | C] – C:\Documents and Settings\Eric\Application Data\Malwarebytes
[2009/09/05 07:45:19 | 00,038,160 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2009/09/05 07:45:17 | 00,019,096 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys
[2009/09/05 07:45:17 | 00,000,000 | —D | C] – C:\Program Files\Malwarebytes' Anti-Malware
[2009/09/05 07:45:17 | 00,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Malwarebytes
[2009/09/05 07:33:47 | 00,017,306 | —- | C] () – C:\WINDOWS\ugul._sy
[2009/08/13 02:40:31 | 00,128,512 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\dhtmled.ocx
[2009/08/13 02:40:26 | 01,315,328 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\msoe.dll
[2009/08/10 19:55:51 | 00,000,000 | —D | C] – D:\Users\Eric\Desktop\Temp Maine Photos
[2009/01/23 16:04:28 | 00,087,552 | —- | C] () – C:\WINDOWS\System32\cpwmon2k.dll
[2008/09/06 11:00:35 | 00,000,028 | —- | C] () – C:\WINDOWS\pdf995.ini
[2008/09/06 10:58:19 | 00,051,716 | —- | C] () – C:\WINDOWS\System32\pdf995mon.dll
[2008/08/31 16:09:03 | 00,000,000 | —- | C] () – C:\WINDOWS\brmx2001.ini
[2008/08/31 16:08:20 | 00,000,030 | —- | C] () – C:\WINDOWS\Brownie.ini
[2008/08/31 15:58:43 | 00,000,426 | —- | C] () – C:\WINDOWS\BRWMARK.INI
[2008/08/31 15:58:26 | 00,000,823 | —- | C] () – C:\WINDOWS\Brpfx04a.ini
[2008/08/31 15:58:26 | 00,000,153 | —- | C] () – C:\WINDOWS\brpcfx.ini
[2008/08/31 15:57:17 | 00,045,056 | —- | C] () – C:\WINDOWS\System32\BRTCPCON.DLL
[2008/08/31 15:57:17 | 00,000,114 | —- | C] () – C:\WINDOWS\System32\BRLMW03A.INI
[2008/08/31 15:57:15 | 00,000,086 | —- | C] () – C:\WINDOWS\Brfaxrx.ini
[2008/08/31 15:57:14 | 00,106,496 | —- | C] () – C:\WINDOWS\System32\BrMuSNMP.dll
[2008/08/31 15:20:18 | 00,031,567 | —- | C] () – C:\WINDOWS\maxlink.ini
[2008/03/13 22:39:13 | 00,005,632 | —- | C] () – C:\WINDOWS\System32\drivers\StarOpen.sys
[2007/10/18 19:41:46 | 00,000,181 | —- | C] () – C:\WINDOWS\js2.ini
[2007/05/25 15:48:45 | 00,126,464 | —- | C] () – C:\WINDOWS\System32\vsmidi.dll
[2007/01/23 21:39:26 | 00,000,214 | —- | C] () – C:\WINDOWS\HP_48BitScanUpdatePatch.ini
[2006/09/11 19:42:17 | 00,000,230 | —- | C] () – C:\WINDOWS\KA.INI
[2006/09/09 11:44:35 | 00,000,000 | —- | C] () – C:\WINDOWS\SETUP32.INI
[2005/10/29 20:48:12 | 00,000,487 | —- | C] () – C:\WINDOWS\hegames.ini
[2005/09/20 15:13:00 | 00,000,726 | —- | C] () – C:\WINDOWS\PODW.INI
[2005/09/20 15:12:59 | 00,141,824 | —- | C] () – C:\WINDOWS\System32\RASTY.DLL
[2005/08/14 18:08:43 | 00,374,784 | —- | C] () – C:\WINDOWS\3dg32.dll
[2005/06/21 21:09:27 | 00,000,041 | —- | C] () – C:\WINDOWS\wininit.ini
[2004/09/12 20:16:45 | 00,000,031 | —- | C] () – C:\WINDOWS\CTWave32.ini
[2004/09/05 09:59:50 | 00,155,648 | —- | C] () – C:\WINDOWS\System32\xvidvfw.dll
[2004/09/05 09:58:04 | 00,679,936 | —- | C] () – C:\WINDOWS\System32\xvidcore.dll
[2004/08/21 15:19:04 | 00,056,832 | —- | C] () – C:\WINDOWS\System32\iyvu9_32.dll
[2004/05/23 19:49:40 | 01,385,984 | —- | C] () – C:\WINDOWS\System32\telintf.DLL
[2004/05/01 20:47:02 | 00,016,302 | —- | C] () – C:\WINDOWS\System32\drivers\BridDFU.sys
[2004/04/06 20:35:32 | 00,000,158 | —- | C] () – C:\WINDOWS\pagesuit.ini
[2004/04/06 20:35:31 | 00,023,040 | —- | C] () – C:\WINDOWS\System32\irisco32.dll
[2004/04/04 21:16:56 | 00,001,984 | —- | C] () – C:\WINDOWS\System32\drivers\papycpu2.sys
[2004/04/04 21:16:56 | 00,001,856 | —- | C] () – C:\WINDOWS\System32\drivers\papyjoy.sys
[2004/04/04 21:14:08 | 00,000,199 | —- | C] () – C:\WINDOWS\Sierra.ini
[2004/04/03 23:50:31 | 00,002,300 | —- | C] () – C:\WINDOWS\DriveCrypt.ini
[2004/04/03 18:16:18 | 00,224,800 | —- | C] () – C:\WINDOWS\System32\drivers\DCR.sys
[2004/03/29 21:32:52 | 00,000,122 | —- | C] () – C:\WINDOWS\mdm.ini
[2004/03/29 21:32:48 | 00,000,000 | —- | C] () – C:\WINDOWS\NSREX.INI
[2004/03/29 21:24:10 | 00,000,478 | —- | C] () – C:\WINDOWS\ODBC.INI
[2004/03/26 23:49:55 | 00,065,536 | —- | C] ( ) – C:\WINDOWS\System32\a3d.dll
[2004/03/26 23:49:55 | 00,005,515 | —- | C] () – C:\WINDOWS\System32\ENSDEF.INI
[2004/03/26 23:49:55 | 00,000,194 | —- | C] () – C:\WINDOWS\System32\KILL.INI
[2004/03/26 20:30:18 | 00,363,520 | —- | C] () – C:\WINDOWS\System32\psisdecd.dll
[2004/03/13 15:57:34 | 00,000,231 | —- | C] () – C:\WINDOWS\AC3API.INI
[2004/03/13 15:56:31 | 00,043,513 | —- | C] () – C:\WINDOWS\System32\e10kxwdm.ini
[2004/03/13 15:56:31 | 00,000,175 | —- | C] () – C:\WINDOWS\System32\ctzapxx.ini
[2004/03/13 15:55:11 | 00,000,136 | —- | C] () – C:\WINDOWS\SBWIN.INI
[2004/03/13 14:38:19 | 00,006,272 | —- | C] () – C:\WINDOWS\System32\drivers\ASLM75.SYS
[2004/03/13 14:30:50 | 00,002,527 | —- | C] () – C:\WINDOWS\Ascd_tmp.ini
[2004/03/13 14:30:49 | 00,005,824 | —- | C] () – C:\WINDOWS\System32\drivers\ASUSHWIO.SYS
[2003/12/12 13:42:14 | 00,086,016 | —- | C] () – C:\WINDOWS\System32\ati2evxx.dll
[2003/03/31 08:00:00 | 00,000,963 | —- | C] () – C:\WINDOWS\win.ini
[2003/03/31 08:00:00 | 00,000,227 | —- | C] () – C:\WINDOWS\system.ini
[2002/05/29 09:50:02 | 00,561,152 | —- | C] () – C:\WINDOWS\System32\hpotscl.dll
[1999/01/22 14:46:56 | 00,065,536 | —- | C] () – C:\WINDOWS\System32\MSRTEDIT.DLL
[1998/06/13 23:53:26 | 00,044,544 | —- | C] () – C:\WINDOWS\System32\Gif89.dll

========== Files - Modified Within 30 Days ==========

[2009/09/06 06:20:00 | 00,000,422 | -H– | M] () – C:\WINDOWS\tasks\User_Feed_Synchronization-{41FA4664-24F9-49C8-ABCF-3D592CD4C8BD}.job
[2009/09/06 05:58:02 | 00,000,974 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-2000478354-1177238915-725345543-1004UA.job
[2009/09/06 05:29:00 | 00,000,978 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-2000478354-1177238915-725345543-1006UA.job
[2009/09/05 20:29:00 | 00,000,926 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-2000478354-1177238915-725345543-1006Core.job
[2009/09/05 20:05:48 | 04,932,148 | —- | M] () – C:\WINDOWS\{00000000-00000000-0000000E-00001102-00000004-20021102}.CDF
[2009/09/05 20:05:09 | 00,013,646 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2009/09/05 20:04:38 | 00,000,006 | -H– | M] () – C:\WINDOWS\tasks\SA.DAT
[2009/09/05 20:04:30 | 00,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2009/09/05 20:03:32 | 00,031,812 | —- | M] () – C:\WINDOWS\System32\BMXCtrlState-{00000000-00000000-0000000E-00001102-00000004-20021102}.rfx
[2009/09/05 20:03:32 | 00,031,812 | —- | M] () – C:\WINDOWS\System32\BMXBkpCtrlState-{00000000-00000000-0000000E-00001102-00000004-20021102}.rfx
[2009/09/05 20:03:32 | 00,031,440 | —- | M] () – C:\WINDOWS\System32\BMXStateBkp-{00000000-00000000-0000000E-00001102-00000004-20021102}.rfx
[2009/09/05 20:03:32 | 00,031,440 | —- | M] () – C:\WINDOWS\System32\BMXState-{00000000-00000000-0000000E-00001102-00000004-20021102}.rfx
[2009/09/05 20:03:32 | 00,001,072 | —- | M] () – C:\WINDOWS\System32\settingsbkup.sfm
[2009/09/05 20:03:32 | 00,001,072 | —- | M] () – C:\WINDOWS\System32\settings.sfm
[2009/09/05 20:03:32 | 00,000,384 | —- | M] () – C:\WINDOWS\System32\DVCStateBkp-{00000000-00000000-0000000E-00001102-00000004-20021102}.dat
[2009/09/05 20:03:32 | 00,000,384 | —- | M] () – C:\WINDOWS\System32\DVCState-{00000000-00000000-0000000E-00001102-00000004-20021102}.dat
[2009/09/05 18:12:27 | 00,514,048 | —- | M] (OldTimer Tools) – D:\Users\Eric\Desktop\OTL.exe
[2009/09/05 17:29:07 | 00,000,227 | —- | M] () – C:\WINDOWS\system.ini
[2009/09/05 17:28:26 | 00,000,027 | —- | M] () – C:\WINDOWS\System32\drivers\etc\hosts
[2009/09/05 12:40:22 | 00,000,281 | RHS- | M] () – C:\boot.ini
[2009/09/05 12:34:11 | 03,195,526 | R— | M] () – D:\Users\Eric\Desktop\Combo-Fix.exe
[2009/09/05 09:03:23 | 00,000,963 | —- | M] () – C:\WINDOWS\win.ini
[2009/09/05 09:03:23 | 00,000,211 | —- | M] () – C:\Boot.bak
[2009/09/05 08:26:12 | 00,002,626 | —- | M] () – C:\WINDOWS\System32\CONFIG.NT
[2009/09/05 07:33:47 | 00,017,306 | —- | M] () – C:\WINDOWS\ugul._sy
[2009/09/04 13:58:00 | 00,000,922 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-2000478354-1177238915-725345543-1004Core.job
[2009/09/03 22:25:22 | 00,230,912 | —- | M] () – C:\WINDOWS\PEV.exe
[2009/08/31 09:48:01 | 00,000,284 | —- | M] () – C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2009/08/17 12:10:20 | 01,279,456 | —- | M] (ALWIL Software) – C:\WINDOWS\System32\aswBoot.exe
[2009/08/17 12:06:54 | 00,093,392 | —- | M] (ALWIL Software) – C:\WINDOWS\System32\drivers\aswmon.sys
[2009/08/17 12:06:43 | 00,094,160 | —- | M] (ALWIL Software) – C:\WINDOWS\System32\drivers\aswmon2.sys
[2009/08/17 12:05:52 | 00,114,768 | —- | M] (ALWIL Software) – C:\WINDOWS\System32\drivers\aswSP.sys
[2009/08/17 12:05:37 | 00,020,560 | —- | M] (ALWIL Software) – C:\WINDOWS\System32\drivers\aswFsBlk.sys
[2009/08/17 12:04:29 | 00,023,152 | —- | M] (ALWIL Software) – C:\WINDOWS\System32\drivers\aswRdr.sys
[2009/08/17 12:03:21 | 00,026,944 | —- | M] (ALWIL Software) – C:\WINDOWS\System32\drivers\aavmker4.sys
[2009/08/17 12:02:50 | 00,097,480 | —- | M] (ALWIL Software) – C:\WINDOWS\System32\AVASTSS.scr
[2009/08/15 21:25:59 | 00,130,048 | —- | M] () – C:\Documents and Settings\Eric\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009/08/14 18:23:47 | 00,001,374 | —- | M] () – C:\WINDOWS\imsins.BAK
< End of report >
Hi modena2904,

One little fix to do. The other files detected by Kaspersky are either all ready quarantined or in old System Restore points. These will be removed when we remove our tools.

Next, Double click on OTL.exe
  • Under the Custom Scans/Fixes box at the bottom, paste in the following
  • Do Not copy the word CODE
  • please note the fix starts with the :
:OTL
PRC - C:\WINDOWS\Explorer.EXE (Microsoft Corporation)

:Files
C:\Program Files\Puppy Luv\bfgt_silent_en.exe
C:\WINDOWS\ugul._sy

:Commands
[Reboot]

Then click the Run Fix button at the top
  • Let the program run unhindered
  • Please save the resulting log to be posted in your next reply.
Please post the OTL fix log.

How is the computer, any problems remaining? If none, we will clean up our tools after you post back.

Thanks
I ran the script in OTL as instructed. However, after the reboot, the program did not give me a log file. The OTL.txt on my desktop is still the one from earlier today. I did look to verify that the two files listed in FILES section of the script are in fact no longer on my PC. I believe the PC is working well – no other problems. Thanks. - Eric

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI