This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Additional Guard infection...

7 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Tried Malwarebytes to no avail. Ran CCleaner before I ran Malwarebytes. eSet online scan didn't pick up anything but I know its still there

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 1:13:00 AM, on 12/20/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\LogMeIn\x86\RaMaint.exe
C:\Program Files\LogMeIn\x86\LogMeIn.exe
C:\Program Files\Apoint2K\Apoint.exe
C:\WINDOWS\GWHotKey.exe
C:\Program Files\LogMeIn\x86\LogMeInSystray.exe
C:\Program Files\BillP Studios\WinPatrol\winpatrol.exe
C:\Program Files\IObit\Advanced SystemCare 3\AWC.exe
C:\Program Files\Apoint2K\Apntex.exe
C:\Program Files\Hamachi\hamachi.exe
C:\Program Files\LogMeIn\x86\LMIGuardian.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\LogMeIn\x86\LMIGuardian.exe
C:\Program Files\internet explorer\iexplore.exe
C:\Program Files\internet explorer\iexplore.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.i29.net/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O1 - Hosts: 74.125.45.100 4-open-davinci.com
O1 - Hosts: 74.125.45.100 securitysoftwarepayments.com
O1 - Hosts: 74.125.45.100 privatesecuredpayments.com
O1 - Hosts: 74.125.45.100 secure.privatesecuredpayments.com
O1 - Hosts: 74.125.45.100 getantivirusplusnow.com
O1 - Hosts: 74.125.45.100 secure-plus-payments.com
O1 - Hosts: 74.125.45.100 www.getantivirusplusnow.com
O1 - Hosts: 74.125.45.100 www.secure-plus-payments.com
O1 - Hosts: 74.125.45.100 www.getavplusnow.com
O1 - Hosts: 74.125.45.100 safebrowsing-cache.google.com
O1 - Hosts: 74.125.45.100 urs.microsoft.com
O1 - Hosts: 74.125.45.100 www.securesoftwarebill.com
O1 - Hosts: 74.125.45.100 secure.paysecuresystem.com
O1 - Hosts: 74.125.45.100 paysoftbillsolution.com
O1 - Hosts: 74.125.45.100 protected.maxisoftwaremart.com
O1 - Hosts: 88.198.198.202 google.ae
O1 - Hosts: 88.198.198.202 google.as
O1 - Hosts: 88.198.198.202 google.at
O1 - Hosts: 88.198.198.202 google.az
O1 - Hosts: 88.198.198.202 google.ba
O1 - Hosts: 88.198.198.202 google.be
O1 - Hosts: 88.198.198.202 google.bg
O1 - Hosts: 88.198.198.202 google.bs
O1 - Hosts: 88.198.198.202 google.ca
O1 - Hosts: 88.198.198.202 google.cd
O1 - Hosts: 88.198.198.202 google.com.gh
O1 - Hosts: 88.198.198.202 google.com.hk
O1 - Hosts: 88.198.198.202 google.com.jm
O1 - Hosts: 88.198.198.202 google.com.mx
O1 - Hosts: 88.198.198.202 google.com.my
O1 - Hosts: 88.198.198.202 google.com.na
O1 - Hosts: 88.198.198.202 google.com.nf
O1 - Hosts: 88.198.198.202 google.com.ng
O1 - Hosts: 88.198.198.202 google.ch
O1 - Hosts: 88.198.198.202 google.com.np
O1 - Hosts: 88.198.198.202 google.com.pr
O1 - Hosts: 88.198.198.202 google.com.qa
O1 - Hosts: 88.198.198.202 google.com.sg
O1 - Hosts: 88.198.198.202 google.com.tj
O1 - Hosts: 88.198.198.202 google.com.tw
O1 - Hosts: 88.198.198.202 google.dj
O1 - Hosts: 88.198.198.202 google.de
O1 - Hosts: 88.198.198.202 google.dk
O1 - Hosts: 88.198.198.202 google.dm
O1 - Hosts: 88.198.198.202 google.ee
O1 - Hosts: 88.198.198.202 google.fi
O1 - Hosts: 88.198.198.202 google.fm
O1 - Hosts: 88.198.198.202 google.fr
O1 - Hosts: 88.198.198.202 google.ge
O1 - Hosts: 88.198.198.202 google.gg
O1 - Hosts: 88.198.198.202 google.gm
O1 - Hosts: 88.198.198.202 google.gr
O1 - Hosts: 88.198.198.202 google.ht
O1 - Hosts: 88.198.198.202 google.ie
O1 - Hosts: 88.198.198.202 google.im
O1 - Hosts: 88.198.198.202 google.in
O1 - Hosts: 88.198.198.202 google.it
O1 - Hosts: 88.198.198.202 google.ki
O1 - Hosts: 88.198.198.202 google.la
O1 - Hosts: 88.198.198.202 google.li
O1 - Hosts: 88.198.198.202 google.lv
O1 - Hosts: 88.198.198.202 google.ma
O1 - Hosts: 88.198.198.202 google.ms
O1 - Hosts: 88.198.198.202 google.mu
O1 - Hosts: 88.198.198.202 google.mw
O1 - Hosts: 88.198.198.202 google.nl
O1 - Hosts: 88.198.198.202 google.no
O1 - Hosts: 88.198.198.202 google.nr
O1 - Hosts: 88.198.198.202 google.nu
O1 - Hosts: 88.198.198.202 google.pl
O1 - Hosts: 88.198.198.202 google.pn
O1 - Hosts: 88.198.198.202 google.pt
O1 - Hosts: 88.198.198.202 google.ro
O1 - Hosts: 88.198.198.202 google.ru
O1 - Hosts: 88.198.198.202 google.rw
O1 - Hosts: 88.198.198.202 google.sc
O1 - Hosts: 88.198.198.202 google.se
O1 - Hosts: 88.198.198.202 google.sh
O1 - Hosts: 88.198.198.202 google.si
O1 - Hosts: 88.198.198.202 google.sm
O1 - Hosts: 88.198.198.202 google.sn
O1 - Hosts: 88.198.198.202 google.st
O1 - Hosts: 88.198.198.202 google.tl
O1 - Hosts: 88.198.198.202 google.tm
O1 - Hosts: 88.198.198.202 google.tt
O1 - Hosts: 88.198.198.202 google.us
O1 - Hosts: 88.198.198.202 google.vu
O1 - Hosts: 88.198.198.202 google.ws
O1 - Hosts: 88.198.198.202 google.co.ck
O1 - Hosts: 88.198.198.202 google.co.id
O1 - Hosts: 88.198.198.202 google.co.il
O1 - Hosts: 88.198.198.202 google.co.in
O1 - Hosts: 88.198.198.202 google.co.jp
O1 - Hosts: 88.198.198.202 google.co.kr
O1 - Hosts: 88.198.198.202 google.co.ls
O1 - Hosts: 88.198.198.202 google.co.ma
O1 - Hosts: 88.198.198.202 google.co.nz
O1 - Hosts: 88.198.198.202 google.co.tz
O1 - Hosts: 88.198.198.202 google.co.ug
O1 - Hosts: 88.198.198.202 google.co.uk
O1 - Hosts: 88.198.198.202 google.co.za
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - (no file)
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint2K\Apoint.exe
O4 - HKLM\..\Run: [Multi-function Keyboard] GWHotKey.exe
O4 - HKLM\..\Run: [LogMeIn GUI] "C:\Program Files\LogMeIn\x86\LogMeInSystray.exe"
O4 - HKLM\..\Run: [WinPatrol] C:\Program Files\BillP Studios\WinPatrol\winpatrol.exe -expressboot
O4 - HKCU\..\Run: [Advanced SystemCare 3] "C:\Program Files\IObit\Advanced SystemCare 3\AWC.exe" /startup
O4 - HKUS\S-1-5-18\..\Run: [MySpaceIM] C:\Program Files\MySpace\IM\MySpaceIM.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [MySpaceIM] C:\Program Files\MySpace\IM\MySpaceIM.exe (User 'Default user')
O4 - Startup: hamachi.lnk = C:\Program Files\Hamachi\hamachi.exe
O4 - Global Startup: Install Pending Files.LNK = C:\Program Files\SIFXINST\SIFXINST.EXE
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
O16 - DPF: {739E8D90-2F4C-43AD-A1B8-66C356FCEA35} (RunExeActiveX.RunExe) - hcp://system/RunExeActiveX.CAB
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} - http://download.eset.com/special/eos/OnlineScanner.cab
O16 - DPF: {99CDFD87-F97A-42E1-9C13-D18220D90AD1} (StartFirstControl.CheckFirst) - hcp://system/StartFirstControl.CAB
O16 - DPF: {FD0B6769-6490-4A91-AA0A-B5AE0DC75AC9} (Performance Viewer Activex Control) - https://secure.logmein.com/activex/ractrl.cab?lmi=100
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll
O23 - Service: Cacheman Service (CachemanService) - Unknown owner - C:\Program Files\Cacheman\CachemanServ.exe (file missing)
O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: LogMeIn Maintenance Service (LMIMaint) - LogMeIn, Inc. - C:\Program Files\LogMeIn\x86\RaMaint.exe
O23 - Service: LogMeIn - LogMeIn, Inc. - C:\Program Files\LogMeIn\x86\LogMeIn.exe

–
End of file - 9409 bytes
Hi teeps, welcome to the forum.

To make cleaning this machine easier
  • Please do not uninstall/install any programs unless asked to
    It is more difficult when files/programs are appearing in/disappearing from the logs.
  • Please do not run any scans other than those requested
  • Please follow all instructions in the order posted
  • All logs/reports, etc.. must be posted in Notepad. Please ensure that word wrap is unchecked. In notepad click format, uncheck word wrap if it is checked.
  • Do not attach any logs/reports, etc.. unless specifically requested to do so.
  • If you have problems with or do not understand the instructions, Please ask before continuing.
  • Please stay with this thread until given the All Clear. A absence of symptoms does not mean a clean machine.
Download OTL to your desktop.

Double click on OTL.exe
  • Under the Custom Scans/Fixes box at the bottom, paste in the following
  • Do Not copy the word CODE
  • please note the fix starts with the :
:Commands
[purity]
[emptytemp]
[resethosts]
[Reboot]

Then click the Run Fix button at the top
  • Let the program run unhindered

After the computer has rebooted, it should boot twice, open OTL again if it isn't still open.

  • Make sure all other windows are closed and to let it run uninterrupted.
  • Underneath Output at the top change it to Minimal Output
  • Check the boxes beside LOP Check
  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.

Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post it with your next reply. You may need two posts to fit them all in.

No need for a Hijackthis log this time.

Thanks
Here's the OTL log
OTL logfile created on: 12/20/2009 1:13:05 PM - Run 1
OTL by OldTimer - Version 3.1.19.0 Folder = C:\Documents and Settings\Administrator\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

254.00 Mb Total Physical Memory | 37.00 Mb Available Physical Memory | 14.00% Memory free
624.00 Mb Paging File | 442.00 Mb Available in Paging File | 71.00% Paging File free
Paging file location(s): C:\pagefile.sys 384 768 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 18.62 Gb Total Space | 7.97 Gb Free Space | 42.80% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: CRAIGSLAPTOP
Current User Name: Administrator
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal

========== Processes (SafeList) ==========

PRC - C:\Documents and Settings\Administrator\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\IObit\Advanced SystemCare 3\AWC.exe (IObit)
PRC - C:\Program Files\LogMeIn\x86\ramaint.exe (LogMeIn, Inc.)
PRC - C:\Program Files\LogMeIn\x86\LMIGuardian.exe (LogMeIn, Inc.)
PRC - C:\Program Files\BillP Studios\WinPatrol\WinPatrol.exe (BillP Studios)
PRC - C:\Program Files\Hamachi\hamachi.exe (LogMeIn Inc.)
PRC - C:\Program Files\LogMeIn\x86\LogMeInSystray.exe (LogMeIn, Inc.)
PRC - C:\Program Files\LogMeIn\x86\LogMeIn.exe (LogMeIn, Inc.)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Apoint2K\Apoint.exe (Alps Electric Co., Ltd.)
PRC - C:\Program Files\Apoint2K\ApntEx.exe (Alps Electric Co., Ltd.)
PRC - C:\WINDOWS\GWHotKey.exe (BillP Studios)


========== Modules (SafeList) ==========

MOD - C:\Documents and Settings\Administrator\Desktop\OTL.exe (OldTimer Tools)
MOD - C:\Program Files\BillP Studios\WinPatrol\patrolpro.dll (BillP Studios)
MOD - C:\Program Files\Apoint2K\EzAuto.dll (Alps Electric Co., Ltd.)


========== Win32 Services (SafeList) ==========

SRV - (CachemanService) – File not found
SRV - (gupdate) Google Update Service (gupdate) – C:\Program Files\Google\Update\GoogleUpdate.exe (Google Inc.)
SRV - (LMIMaint) – C:\Program Files\LogMeIn\x86\RaMaint.exe (LogMeIn, Inc.)
SRV - (odserv) – C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE (Microsoft Corporation)
SRV - (Microsoft Office Groove Audit Service) – C:\Program Files\Microsoft Office\Office12\GrooveAuditService.exe (Microsoft Corporation)
SRV - (LogMeIn) – C:\Program Files\LogMeIn\x86\LogMeIn.exe (LogMeIn, Inc.)
SRV - (NWCWorkstation) – C:\WINDOWS\system32\nwwks.dll (Microsoft Corporation)
SRV - (gusvc) – C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe (Google)
SRV - (ose) – C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE (Microsoft Corporation)
SRV - (PictureTaker) – C:\WINDOWS\system32\PCTKRNT.SYS (LANovation)


========== Driver Services (SafeList) ==========

DRV - (rootrepeal) – C:\WINDOWS\system32\drivers\rootrepeal.sys ()
DRV - (LMIRfsClientNP) – C:\WINDOWS\system32\LMIRfsClientNP.dll (LogMeIn, Inc.)
DRV - (LMIInfo) – C:\Program Files\LogMeIn\x86\rainfo.sys (LogMeIn, Inc.)
DRV - (LMIRfsDriver) – C:\WINDOWS\system32\drivers\LMIRfsDriver.sys (LogMeIn, Inc.)
DRV - (lmimirr) – C:\WINDOWS\system32\drivers\lmimirr.sys (LogMeIn, Inc.)
DRV - (tifsfilter) – C:\WINDOWS\system32\drivers\tifsfilt.sys (Acronis)
DRV - (timounter) – C:\WINDOWS\system32\DRIVERS\timntr.sys (Acronis)
DRV - (hamachi) – C:\WINDOWS\system32\drivers\hamachi.sys (LogMeIn, Inc.)
DRV - (NwlnkIpx) – C:\WINDOWS\system32\drivers\nwlnkipx.sys (Microsoft Corporation)
DRV - (NWRDR) – C:\WINDOWS\system32\drivers\nwrdr.sys (Microsoft Corporation)
DRV - (Secdrv) – C:\WINDOWS\system32\drivers\secdrv.sys (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.)
DRV - (sscdserd) SAMSUNG Mobile Modem Diagnostic Serial Port (WDM) – C:\WINDOWS\system32\drivers\sscdserd.sys (MCCI Corporation)
DRV - (sscdmdm) – C:\WINDOWS\system32\drivers\sscdmdm.sys (MCCI Corporation)
DRV - (sscdmdfl) – C:\WINDOWS\system32\drivers\sscdmdfl.sys (MCCI Corporation)
DRV - (sscdbus) SAMSUNG USB Composite Device driver (WDM) – C:\WINDOWS\system32\drivers\sscdbus.sys (MCCI Corporation)
DRV - (ialm) – C:\WINDOWS\system32\drivers\ialmnt5.sys (Intel Corporation)
DRV - (PxHelp20) – C:\WINDOWS\system32\DRIVERS\PxHelp20.sys (Sonic Solutions)
DRV - (cdudf_xp) – C:\WINDOWS\system32\drivers\cdudf_xp.sys (Roxio)
DRV - (pwd_2K) – C:\WINDOWS\system32\drivers\pwd_2K.sys (Roxio)
DRV - (mmc_2K) – C:\WINDOWS\system32\drivers\Mmc_2k.sys (Roxio)
DRV - (dvd_2K) – C:\WINDOWS\system32\drivers\Dvd_2k.sys (Roxio)
DRV - (Cdr4_xp) – C:\WINDOWS\system32\drivers\cdr4_xp.sys (Roxio)
DRV - (Cdralw2k) – C:\WINDOWS\system32\drivers\cdralw2k.sys (Roxio)
DRV - (AEIWL_USB) – C:\WINDOWS\system32\drivers\AEIWLUSB.sys (Actiontec Electronics, Inc)
DRV - (AEIWL) – C:\WINDOWS\system32\drivers\AEIWLUSB.sys (Actiontec Electronics, Inc)
DRV - (ApfiltrService) – C:\WINDOWS\system32\drivers\Apfiltr.sys (Alps Electric Co., Ltd.)
DRV - (allegro) ESS Allegro Audio Driver (WDM) – C:\WINDOWS\system32\drivers\es198x.sys (ESS Technology, Inc.)
DRV - (GTWModem) – C:\WINDOWS\system32\drivers\GWMDM.sys (GTW)
DRV - (E100B) Intel® – C:\WINDOWS\system32\drivers\e100b325.sys (Intel Corporation)
DRV - (UdfReadr_xp) – C:\WINDOWS\system32\drivers\udfreadr_xp.sys (Roxio)
DRV - ({A7E39B01-B403-11d4-BD18-00D0B7A1821E}) – C:\WINDOWS\system32\drivers\vch.sys (Intel Corporation)
DRV - (NwlnkNb) – C:\WINDOWS\system32\drivers\nwlnknb.sys (Microsoft Corporation)
DRV - (NwlnkSpx) – C:\WINDOWS\system32\drivers\nwlnkspx.sys (Microsoft Corporation)
DRV - (Ptilink) – C:\WINDOWS\system32\drivers\ptilink.sys (Parallel Technologies, Inc.)
DRV - (MODEMCSA) – C:\WINDOWS\system32\drivers\MODEMCSA.sys (Microsoft Corporation)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========


IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultName = Google
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultURL = http://www.google.com/search?q={searchTerm…tf8&oe=utf8
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.i29.net/
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0



O1 HOSTS File: (98 bytes) - C:\WINDOWS\system32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - No CLSID value found.
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (Groove GFS Browser Helper) - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation)
O3 - HKLM\..\Toolbar: (no name) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - No CLSID value found.
O3 - HKCU\..\Toolbar\ShellBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - No CLSID value found.
O4 - HKLM..\Run: [Apoint] C:\Program Files\Apoint2K\Apoint.exe (Alps Electric Co., Ltd.)
O4 - HKLM..\Run: [LogMeIn GUI] C:\Program Files\LogMeIn\x86\LogMeInSystray.exe (LogMeIn, Inc.)
O4 - HKLM..\Run: [Multi-function Keyboard] C:\WINDOWS\GWHotKey.exe (BillP Studios)
O4 - HKLM..\Run: [WinPatrol] C:\Program Files\BillP Studios\WinPatrol\winpatrol.exe (BillP Studios)
O4 - HKCU..\Run: [Advanced SystemCare 3] C:\Program Files\IObit\Advanced SystemCare 3\AWC.exe (IObit)
O4 - Startup: C:\Documents and Settings\Administrator\Start Menu\Programs\Startup\hamachi.lnk = C:\Program Files\Hamachi\hamachi.exe (LogMeIn Inc.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Install Pending Files.LNK = C:\Program Files\SIFXINST\SIFXINST.EXE (LANovation)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Infodelivery present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: LinkResolveIgnoreLinkInfo = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoResolveSearch = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: LinkResolveIgnoreLinkInfo = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O9 - Extra Button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Program Files\Microsoft Office\Office12\REFIEBAR.DLL (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\WINDOWS\system32\nwprovau.dll (Microsoft Corporation)
O15 - HKLM\..Trusted Domains: 45 domain(s) and sub-domain(s) not assigned to a zone.
O15 - HKCU\..Trusted Domains: 8 domain(s) and sub-domain(s) not assigned to a zone.
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://download.macromedia.com/pub/shockwa…director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} C:\Program Files\Yahoo!\Common\Yinsthelper.dll (Installation Support)
O16 - DPF: {33564D57-9980-0010-8000-00AA00389B71} http://download.microsoft.com/download/D/0…D0C/wmv9dmo.cab (Reg Error: Value error.)
O16 - DPF: {739E8D90-2F4C-43AD-A1B8-66C356FCEA35} hcp://system/RunExeActiveX.CAB (RunExeActiveX.RunExe)
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} http://download.eset.com/special/eos/OnlineScanner.cab (Reg Error: Value error.)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get/flash…t/ultrashim.cab (Reg Error: Value error.)
O16 - DPF: {99CDFD87-F97A-42E1-9C13-D18220D90AD1} hcp://system/StartFirstControl.CAB (StartFirstControl.CheckFirst)
O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} http://v4.windowsupdate.microsoft.com/CAB/…7985.4699884259 (Reg Error: Value error.)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload.macromedia.com/pub/shock…ash/swflash.cab (Shockwave Flash Object)
O16 - DPF: {FD0B6769-6490-4A91-AA0A-B5AE0DC75AC9} https://secure.logmein.com/activex/ractrl.cab?lmi=100 (Performance Viewer Activex Control)
O16 - DPF: Microsoft XML Parser for Java file://C:\WINDOWS\Java\classes\xmldso.cab (Reg Error: Key error.)
O18 - Protocol\Handler\grooveLocalGWS {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll (Microsoft Corporation)
O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll (Microsoft Corporation)
O18 - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\Microsoft Shared\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\igfxcui: DllName - igfxsrvc.dll - C:\WINDOWS\System32\igfxsrvc.dll (Intel Corporation)
O20 - Winlogon\Notify\LMIinit: DllName - LMIinit.dll - C:\WINDOWS\System32\LMIinit.dll (LogMeIn, Inc.)
O28 - HKLM ShellExecuteHooks: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation)
O30 - LSA: Authentication Packages - (nwprovau) - C:\WINDOWS\System32\nwprovau.dll (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2003/12/30 11:40:11 | 00,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O34 - HKLM BootExecute: (!"$%&$#!%&$#!$#%!&$#&%!$#%$"!DF!CXY!DWCER"!,) - File not found
O35 - comfile [open] – "%1" %*
O35 - exefile [open] – "%1" %*

========== Files/Folders - Created Within 30 Days ==========

[2009/12/20 13:06:46 | 00,000,000 | —D | C] – C:\_OTL
[2009/12/20 13:05:30 | 00,513,536 | —- | C] (OldTimer Tools) – C:\Documents and Settings\Administrator\Desktop\OTL.exe
[2009/12/20 08:48:08 | 00,000,000 | —D | M] – C:\Documents and Settings\NetworkService\Local Settings\Application Data\Temp
[2009/12/20 01:10:22 | 00,000,000 | —D | C] – C:\ComboFix
[2009/12/20 00:48:06 | 00,472,064 | —- | C] ( ) – C:\Documents and Settings\Administrator\Desktop\RootRepeal.exe
[2009/12/20 00:38:42 | 00,000,000 | —D | C] – C:\Qoobox
[2009/12/20 00:26:55 | 00,000,000 | RH-D | C] – C:\Documents and Settings\Administrator\Recent
[2009/12/20 00:26:55 | 00,000,000 | -HSD | C] – C:\RECYCLER
[2009/12/20 00:24:13 | 00,000,000 | —D | C] – C:\Documents and Settings\Administrator\Application Data\WinPatrol
[2009/12/20 00:24:03 | 00,000,000 | —D | C] – C:\Program Files\BillP Studios
[2009/12/20 00:10:27 | 00,000,000 | —D | C] – C:\WINDOWS\temp
[2009/12/19 23:50:49 | 00,000,000 | RHSD | C] – C:\cmdcons
[2009/12/19 23:11:39 | 00,025,992 | —- | C] (Sysinternals - www.sysinternals.com) – C:\WINDOWS\System32\pgdfgsvc.exe
[2009/12/19 23:10:49 | 00,000,000 | —D | C] – C:\Program Files\PageDefrag
[2009/12/19 22:30:44 | 00,000,000 | —D | C] – C:\WINDOWS\ERDNT
[2009/12/19 22:27:09 | 00,000,000 | -HSD | C] – C:\Documents and Settings\Administrator\IECompatCache
[2009/12/19 22:26:40 | 00,000,000 | -HSD | C] – C:\Documents and Settings\Administrator\PrivacIE
[2009/12/19 22:21:27 | 00,000,000 | -HSD | C] – C:\Documents and Settings\Administrator\IETldCache
[2009/12/19 22:14:15 | 00,000,000 | —D | C] – C:\WINDOWS\ie8updates
[2009/12/19 22:07:19 | 00,000,000 | -H-D | C] – C:\WINDOWS\ie8
[2009/12/19 19:53:52 | 00,000,000 | —D | C] – C:\Program Files\Microsoft Bootvis
[2009/12/19 19:47:53 | 00,000,000 | —D | C] – C:\Program Files\Cacheman
[2009/12/19 19:39:30 | 00,000,000 | —D | C] – C:\Program Files\Resource Kit
[2009/12/19 19:29:23 | 00,000,000 | —D | M] – C:\Documents and Settings\NetworkService\Local Settings\Application Data\ICS
[2009/12/19 18:52:08 | 00,266,360 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\TweakUI.exe
[2009/12/19 12:43:56 | 00,000,000 | —D | C] – C:\Documents and Settings\Administrator\Application Data\IObit
[2009/12/19 12:43:55 | 00,000,000 | —D | C] – C:\Program Files\IObit
[2009/12/19 11:17:52 | 00,000,000 | —D | C] – C:\Documents and Settings\Administrator\Application Data\Malwarebytes
[2009/12/19 11:16:40 | 00,038,224 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2009/12/19 11:16:29 | 00,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Malwarebytes
[2009/12/19 11:15:19 | 00,019,160 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys
[2009/12/19 11:15:16 | 00,000,000 | —D | C] – C:\Program Files\Malwarebytes' Anti-Malware
[2009/10/18 08:05:49 | 00,000,000 | —D | M] – C:\Documents and Settings\LocalService\Local Settings\Application Data\ICS
[2009/10/16 21:38:07 | 00,000,000 | —D | M] – C:\Documents and Settings\NetworkService\Local Settings\Application Data\Google
[2009/10/16 21:33:40 | 00,000,000 | —D | M] – C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft
[2009/10/16 21:33:40 | 00,000,000 | —D | M] – C:\Documents and Settings\LocalService\Local Settings\Application Data\Google
[2008/10/26 20:00:49 | 00,000,000 | —D | M] – C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft
[2008/07/12 12:05:18 | 00,000,000 | —D | M] – C:\Documents and Settings\LocalService\Application Data\Acronis
[2003/12/30 11:45:13 | 00,000,000 | –SD | M] – C:\Documents and Settings\LocalService\Application Data\Microsoft
[2003/12/30 11:45:12 | 00,000,000 | –SD | M] – C:\Documents and Settings\NetworkService\Application Data\Microsoft
[5 C:\Documents and Settings\All Users\Application Data\*.tmp files -> C:\Documents and Settings\All Users\Application Data\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2009/12/20 13:10:05 | 00,002,206 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2009/12/20 13:09:33 | 00,000,896 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2009/12/20 13:09:26 | 00,000,006 | -H– | M] () – C:\WINDOWS\tasks\SA.DAT
[2009/12/20 13:09:23 | 00,002,048 | —- | M] () – C:\WINDOWS\bootstat.dat
[2009/12/20 13:07:48 | 06,815,744 | -H– | M] () – C:\Documents and Settings\Administrator\NTUSER.DAT
[2009/12/20 13:07:48 | 00,000,278 | -HS- | M] () – C:\Documents and Settings\Administrator\ntuser.ini
[2009/12/20 13:07:38 | 00,000,098 | —- | M] () – C:\WINDOWS\System32\drivers\etc\Hosts
[2009/12/20 13:05:30 | 00,513,536 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Administrator\Desktop\OTL.exe
[2009/12/20 12:46:27 | 00,001,010 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1409436206-1863585682-1345747165-500UA.job
[2009/12/20 12:46:00 | 00,000,900 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2009/12/20 09:46:03 | 00,000,958 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1409436206-1863585682-1345747165-500Core.job
[2009/12/20 08:53:29 | 00,001,915 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Google Earth.lnk
[2009/12/20 01:11:36 | 00,001,734 | —- | M] () – C:\Documents and Settings\Administrator\Desktop\HijackThis.lnk
[2009/12/20 01:04:55 | 01,930,896 | -H– | M] () – C:\Documents and Settings\Administrator\Local Settings\Application Data\IconCache.db
[2009/12/20 00:58:39 | 00,034,816 | —- | M] () – C:\WINDOWS\System32\drivers\rootrepeal.sys
[2009/12/20 00:56:46 | 00,524,288 | —- | M] () – C:\Documents and Settings\Administrator\Desktop\dds.scr
[2009/12/20 00:48:07 | 00,472,064 | —- | M] ( ) – C:\Documents and Settings\Administrator\Desktop\RootRepeal.exe
[2009/12/20 00:44:06 | 03,858,804 | R— | M] () – C:\Documents and Settings\Administrator\Desktop\ComboFix.exe
[2009/12/20 00:22:26 | 00,128,242 | —- | M] () – C:\Documents and Settings\Administrator\My Documents\cc_20091220_002221.reg
[2009/12/20 00:02:09 | 00,000,246 | —- | M] () – C:\WINDOWS\system.ini
[2009/12/19 23:51:03 | 00,000,281 | RHS- | M] () – C:\boot.ini
[2009/12/19 23:11:39 | 00,025,992 | —- | M] (Sysinternals - www.sysinternals.com) – C:\WINDOWS\System32\pgdfgsvc.exe
[2009/12/19 22:23:23 | 00,360,124 | —- | M] () – C:\WINDOWS\System32\PerfStringBackup.INI
[2009/12/19 22:23:23 | 00,315,076 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2009/12/19 22:23:23 | 00,041,238 | —- | M] () – C:\WINDOWS\System32\perfc009.dat
[2009/12/19 22:20:49 | 00,088,704 | —- | M] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2009/12/19 14:58:10 | 00,000,400 | —- | M] () – C:\WINDOWS\tasks\SmartDefrag.job
[2009/12/19 14:57:33 | 00,000,792 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Smart Defrag.lnk
[2009/12/19 14:51:04 | 00,007,816 | —- | M] () – C:\Documents and Settings\Administrator\My Documents\cc_20091219_145056.reg
[2009/12/19 12:44:10 | 00,000,874 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Advanced SystemCare.lnk
[2009/12/19 11:16:51 | 00,000,696 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2009/12/19 11:10:16 | 00,001,548 | —- | M] () – C:\Documents and Settings\Administrator\Desktop\CCleaner.lnk
[2009/12/04 20:54:34 | 00,040,133 | —- | M] () – C:\Documents and Settings\Administrator\Desktop\December 09 CCC Albania Prayer Calendar.pdf
[2009/12/03 16:14:06 | 00,038,224 | —- | M] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2009/12/03 16:13:56 | 00,019,160 | —- | M] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys
[2009/11/21 17:58:16 | 02,504,866 | —- | M] () – C:\Documents and Settings\Administrator\Desktop\Bush_at_UN.AVI (1).avi
[2009/11/21 17:57:11 | 02,504,866 | —- | M] () – C:\Documents and Settings\Administrator\Desktop\Bush_at_UN.AVI.avi
[2009/11/20 21:52:35 | 00,002,344 | —- | M] () – C:\Documents and Settings\Administrator\Desktop\Google Chrome.lnk
[5 C:\Documents and Settings\All Users\Application Data\*.tmp files -> C:\Documents and Settings\All Users\Application Data\*.tmp -> ]

========== Files Created - No Company Name ==========

[2009/12/20 08:53:29 | 00,001,915 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Google Earth.lnk
[2009/12/20 01:11:36 | 00,001,734 | —- | C] () – C:\Documents and Settings\Administrator\Desktop\HijackThis.lnk
[2009/12/20 00:58:31 | 00,034,816 | —- | C] () – C:\WINDOWS\System32\drivers\rootrepeal.sys
[2009/12/20 00:56:46 | 00,524,288 | —- | C] () – C:\Documents and Settings\Administrator\Desktop\dds.scr
[2009/12/20 00:43:43 | 03,858,804 | R— | C] () – C:\Documents and Settings\Administrator\Desktop\ComboFix.exe
[2009/12/20 00:22:24 | 00,128,242 | —- | C] () – C:\Documents and Settings\Administrator\My Documents\cc_20091220_002221.reg
[2009/12/19 23:51:03 | 00,000,211 | —- | C] () – C:\Boot.bak
[2009/12/19 23:50:56 | 00,260,272 | —- | C] () – C:\cmldr
[2009/12/19 18:52:08 | 00,160,217 | —- | C] () – C:\WINDOWS\System32\PowerToysLicense.rtf
[2009/12/19 14:58:08 | 00,000,400 | —- | C] () – C:\WINDOWS\tasks\SmartDefrag.job
[2009/12/19 14:57:33 | 00,000,792 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Smart Defrag.lnk
[2009/12/19 14:51:02 | 00,007,816 | —- | C] () – C:\Documents and Settings\Administrator\My Documents\cc_20091219_145056.reg
[2009/12/19 12:44:10 | 00,000,874 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Advanced SystemCare.lnk
[2009/12/19 11:16:51 | 00,000,696 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2009/12/04 20:54:25 | 00,040,133 | —- | C] () – C:\Documents and Settings\Administrator\Desktop\December 09 CCC Albania Prayer Calendar.pdf
[2009/11/21 17:58:16 | 02,504,866 | —- | C] () – C:\Documents and Settings\Administrator\Desktop\Bush_at_UN.AVI (1).avi
[2009/11/21 17:56:13 | 02,504,866 | —- | C] () – C:\Documents and Settings\Administrator\Desktop\Bush_at_UN.AVI.avi
[2008/08/27 07:49:05 | 00,009,728 | —- | C] () – C:\Documents and Settings\Administrator\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2008/07/15 08:32:13 | 00,000,045 | —- | C] () – C:\WINDOWS\EPSONC86.ini
[2008/07/15 08:31:22 | 00,000,051 | —- | C] () – C:\WINDOWS\System32\EAL32.INI
[2007/08/06 12:07:30 | 00,008,784 | —- | C] () – C:\WINDOWS\System32\ractrlkeyhook.dll
[2007/02/11 17:24:09 | 00,000,000 | —- | C] () – C:\WINDOWS\JDSecure31.INI
[2006/07/26 15:00:34 | 00,000,018 | —- | C] () – C:\WINDOWS\gwhotkey.ini
[2004/09/23 13:48:53 | 00,000,376 | —- | C] () – C:\WINDOWS\ODBC.INI
[2004/07/26 13:04:15 | 00,000,041 | —- | C] () – C:\WINDOWS\GBT.INI
[2004/07/12 09:56:14 | 00,000,000 | —- | C] () – C:\Documents and Settings\Administrator\Application Data\sversion.ini
[2003/12/30 11:49:48 | 00,249,856 | —- | C] () – C:\WINDOWS\System32\shpshftr.dll
[2003/12/30 11:47:40 | 00,000,208 | —- | C] () – C:\WINDOWS\System32\oeminfo.ini
[2003/12/30 11:47:31 | 00,126,976 | —- | C] () – C:\WINDOWS\System32\unzdll.dll
[2003/09/05 05:25:12 | 00,000,423 | —- | C] () – C:\WINDOWS\System32\Dext3050.ini
[2000/09/08 16:53:50 | 00,073,839 | —- | C] () – C:\WINDOWS\System32\KodakOneTouch.dll
[1999/01/22 12:46:58 | 00,065,536 | —- | C] () – C:\WINDOWS\System32\MSRTEDIT.DLL

========== LOP Check ==========

[2008/07/12 12:08:37 | 00,000,000 | —D | M] – C:\Documents and Settings\Administrator\Application Data\Acronis
[2008/08/26 16:55:24 | 00,000,000 | —D | M] – C:\Documents and Settings\Administrator\Application Data\Babylon
[2009/06/06 12:04:07 | 00,000,000 | —D | M] – C:\Documents and Settings\Administrator\Application Data\FileZilla
[2003/12/30 14:16:54 | 00,000,000 | —D | M] – C:\Documents and Settings\Administrator\Application Data\InterVideo
[2009/12/19 14:57:29 | 00,000,000 | —D | M] – C:\Documents and Settings\Administrator\Application Data\IObit
[2008/07/15 08:35:03 | 00,000,000 | —D | M] – C:\Documents and Settings\Administrator\Application Data\Leadertech
[2008/06/20 22:20:10 | 00,000,000 | —D | M] – C:\Documents and Settings\Administrator\Application Data\Smith Micro
[2008/09/07 18:28:19 | 00,000,000 | —D | M] – C:\Documents and Settings\Administrator\Application Data\VersionTracker Pro
[2009/12/20 00:24:13 | 00,000,000 | —D | M] – C:\Documents and Settings\Administrator\Application Data\WinPatrol
[2008/07/12 12:01:04 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Acronis
[2008/08/26 16:55:25 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Babylon
[2008/12/10 22:32:07 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\LogMeIn
[2009/12/19 14:58:10 | 00,000,400 | —- | M] () – C:\WINDOWS\Tasks\SmartDefrag.job
< End of report >
Thanks for the promt reply by the way.

Here's the Extras log:
OTL Extras logfile created on: 12/20/2009 1:13:05 PM - Run 1
OTL by OldTimer - Version 3.1.19.0 Folder = C:\Documents and Settings\Administrator\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

254.00 Mb Total Physical Memory | 37.00 Mb Available Physical Memory | 14.00% Memory free
624.00 Mb Paging File | 442.00 Mb Available in Paging File | 71.00% Paging File free
Paging file location(s): C:\pagefile.sys 384 768 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 18.62 Gb Total Space | 7.97 Gb Free Space | 42.80% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: CRAIGSLAPTOP
Current User Name: Administrator
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.chm [@ = chm.file] – "%SYSTEMROOT%\hh.exe" %1
.html [@ = htmlfile] – C:\Program Files\Internet Explorer\IEXPLORE.EXE (Microsoft Corporation)

[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.html [@ = ChromeHTML] – C:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe (Google Inc.)

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
chm.file [open] – "%SYSTEMROOT%\hh.exe" %1
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
exefile [open] – "%1" %*
htmlfile – "C:\Program Files\Microsoft Office\Office12\msohtmed.exe" %1 (Microsoft Corporation)
htmlfile [open] – "C:\Program Files\Internet Explorer\IEXPLORE.EXE" -nohome (Microsoft Corporation)
htmlfile [opennew] – "C:\Program Files\Internet Explorer\IEXPLORE.EXE" %1 (Microsoft Corporation)
http [open] – "C:\Program Files\Internet Explorer\IEXPLORE.EXE" -nohome (Microsoft Corporation)
https [open] – "C:\Program Files\Internet Explorer\IEXPLORE.EXE" -nohome (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [OneNote.Open] – C:\PROGRA~1\MICROS~2\Office12\ONENOTE.EXE "%L" (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Applications\iexplore.exe [open] – "C:\Program Files\Internet Explorer\IEXPLORE.EXE" %1 (Microsoft Corporation)
CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] – "%programfiles%\internet explorer\iexplore.exe"

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
"139:TCP" = 139:TCP:*:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:*:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:*:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:*:Enabled:@xpsp2res.dll,-22002
"1723:TCP" = 1723:TCP:*:Enabled:@xpsp2res.dll,-22015
"1701:UDP" = 1701:UDP:*:Enabled:@xpsp2res.dll,-22016
"500:UDP" = 500:UDP:*:Enabled:@xpsp2res.dll,-22017

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DoNotAllowExceptions" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"139:TCP" = 139:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22002
"1900:UDP" = 1900:UDP:LocalSubNet:Disabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Disabled:@xpsp2res.dll,-22008
"1723:TCP" = 1723:TCP:*:Enabled:@xpsp2res.dll,-22015
"1701:UDP" = 1701:UDP:*:Enabled:@xpsp2res.dll,-22016
"500:UDP" = 500:UDP:*:Enabled:@xpsp2res.dll,-22017

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe" = C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe:*:Enabled:Kodak Software Updater – ()
"C:\Program Files\Hamachi\hamachi.exe" = C:\Program Files\Hamachi\hamachi.exe:*:Disabled:Hamachi Client – (LogMeIn Inc.)
"C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE" = C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE:*:Enabled:Microsoft Office Outlook – (Microsoft Corporation)
"C:\Program Files\Microsoft Office\Office12\GROOVE.EXE" = C:\Program Files\Microsoft Office\Office12\GROOVE.EXE:*:Enabled:Microsoft Office Groove – (Microsoft Corporation)
"C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE" = C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE:*:Enabled:Microsoft Office OneNote – (Microsoft Corporation)
"C:\Program Files\MySpace\IM\MySpaceIM.exe" = C:\Program Files\MySpace\IM\MySpaceIM.exe:*:Enabled:MySpace Instant Messenger – ()
"C:\Program Files\FileZilla FTP Client\filezilla.exe" = C:\Program Files\FileZilla FTP Client\filezilla.exe:*:Enabled:FileZilla FTP Client – (FileZilla Project)
"C:\Documents and Settings\All Users\Application Data\ba94e39\WIba94.exe" = C:\Documents and Settings\All Users\Application Data\ba94e39\WIba94.exe:*:Enabled:Additional Guard – File not found


========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{00000409-78E1-11D2-B60F-006097C998E7}" = Microsoft Office 2000 Premium
"{0008546E-DF6E-4CC1-AFD0-2CB8E16C95A2}" = Notifier
"{0F9196C6-58B4-445B-B56E-B1200FECC151}" = Microsoft Bootvis
"{14D4ED84-6A9A-45A0-96F6-1753768C3CB5}" = ESSPCD
"{22DE1881-9D24-4981-B5CC-EC7E9F2F4D52}" = Rhapsody Player Engine
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{38441BE7-79B0-42B8-8297-833704F949FE}" = HLPIndex
"{3CA39B0C-BA85-4D42-AC0F-1FF5F60C3353}" = OTtBPSDK
"{469730CC-78DF-4CD3-B286-562D459EA619}" = ESSCAM
"{48C82F7A-F100-4DAB-A310-8E18BF2159E1}" = ESSvpot
"{4F677FC7-7AA8-412B-A957-F13CBE1C7331}" = ESSSONIC
"{609F7AC8-C510-11D4-A788-009027ABA5D0}" = Easy CD Creator 5 Basic
"{64A32253-A906-4AEB-B6A7-A90512B68D87}" = VersionTracker Pro Windows
"{65D85050-5610-4A91-A3B1-D5C744291AD4}" = PCDADDIN
"{69BD6399-3D8F-45B7-81D9-819361F5101D}" = PCDLNCH
"{7F831576-6246-42C7-B523-55B3F96509CC}" = LogMeIn
"{87843A41-7808-4F2E-B13F-25C1E67CF2FD}" = ESShelp
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8A708DD8-A5E6-11D4-A706-000629E95E20}" = Intel® Extreme Graphics Driver
"{8E92D746-CD9F-4B90-9668-42B74C14F765}" = ESSini
"{90120000-0010-0409-0000-0000000FF1CE}" = Microsoft Software Update for Web Folders (English) 12
"{90120000-0015-0409-0000-0000000FF1CE}" = Microsoft Office Access MUI (English) 2007
"{90120000-0015-0409-0000-0000000FF1CE}_ENTERPRISER_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2007
"{90120000-0016-0409-0000-0000000FF1CE}_ENTERPRISER_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2007
"{90120000-0018-0409-0000-0000000FF1CE}_ENTERPRISER_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0019-0409-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (English) 2007
"{90120000-0019-0409-0000-0000000FF1CE}_ENTERPRISER_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001A-0409-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (English) 2007
"{90120000-001A-0409-0000-0000000FF1CE}_ENTERPRISER_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2007
"{90120000-001B-0409-0000-0000000FF1CE}_ENTERPRISER_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}_ENTERPRISER_{ABDDE972-355B-4AF1-89A8-DA50B7B5C045}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-040C-0000-0000000FF1CE}_ENTERPRISER_{F580DDD5-8D37-4998-968E-EBB76BB86787}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007
"{90120000-001F-0C0A-0000-0000000FF1CE}_ENTERPRISER_{187308AB-5FA7-4F14-9AB9-D290383A10D9}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-0020-0409-0000-0000000FF1CE}" = Compatibility Pack for the 2007 Office system
"{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007
"{90120000-0044-0409-0000-0000000FF1CE}" = Microsoft Office InfoPath MUI (English) 2007
"{90120000-0044-0409-0000-0000000FF1CE}_ENTERPRISER_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}_ENTERPRISER_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-00A1-0409-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2007
"{90120000-00A1-0409-0000-0000000FF1CE}_ENTERPRISER_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-00BA-0409-0000-0000000FF1CE}" = Microsoft Office Groove MUI (English) 2007
"{90120000-00BA-0409-0000-0000000FF1CE}_ENTERPRISER_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0114-0409-0000-0000000FF1CE}" = Microsoft Office Groove Setup Metadata MUI (English) 2007
"{90120000-0114-0409-0000-0000000FF1CE}_ENTERPRISER_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007
"{90120000-0115-0409-0000-0000000FF1CE}_ENTERPRISER_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0117-0409-0000-0000000FF1CE}" = Microsoft Office Access Setup Metadata MUI (English) 2007
"{90120000-0117-0409-0000-0000000FF1CE}_ENTERPRISER_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{91120000-0030-0000-0000-0000000FF1CE}" = Microsoft Office Enterprise 2007
"{91120000-0030-0000-0000-0000000FF1CE}_ENTERPRISER_{0B36C6D6-F5D8-4EAF-BF94-4376A230AD5B}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{91120000-0030-0000-0000-0000000FF1CE}_ENTERPRISER_{3D019598-7B59-447A-80AE-815B703B84FF}" = Security Update for Microsoft Office system 2007 (972581)
"{91517631-A9F3-4B7C-B482-43E0068FD55A}" = ESSgui
"{999D43F4-9709-4887-9B1A-83EBB15A8370}" = VPRINTOL
"{9D1CF8B6-17B3-4832-B062-2C2DD0B57B04}" = CCHelp
"{9D8FEE90-0377-49A9-AEFB-525BDE549BA4}" = ESScore
"{A0AF08BA-3630-4505-BFB2-A41F3837B0D0}" = SFR2
"{A5B3EB8A-4071-42F0-8E8E-7A8342AA8E69}" = ESSvpaht
"{A6F18A67-B771-4191-8A33-36D2E742D6D9}" = ESSANUP
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{AADAC983-FDE9-42FA-8FD9-7BB324155593}" = HLPRFO
"{AC76BA86-7AD7-1033-7B44-A81200000003}" = Adobe Reader 8.1.2
"{AE1FA02D-E6A4-4EA0-8E58-6483CAC016DD}" = ESSCDBK
"{B0650E3D-FDCA-4908-B74B-0CC1731BDB93}" = Microsoft Tool Web Package : EXCTRLST.EXE
"{B4B44FE7-41FF-4DAD-8C0A-E406DDA72992}" = CCScore
"{B997C2A0-4383-41BF-B76E-9B8B7ECFB267}" = KSU
"{C084BC61-E537-11DE-8616-005056806466}" = Google Earth
"{C354C9B6-A4E0-4BB0-A368-6DC6BCA0E314}" = SFR
"{C99DCDA4-7407-4F72-A77E-C81C551D0C4E}" = PCDHELP
"{D15E9DB5-6BEB-4534-901E-80C0A29BAB97}" = ESSAdpt
"{D32470A1-B10C-4059-BA53-CF0486F68EBC}" = Kodak EasyShare software
"{E9ED0801-253D-4FE9-AB20-F63DEFE72547}" = SAMSUNG Mobile USB DRIVER(4.40.7.0) v1.6
"{F1FBF021-B965-42D3-BF63-D7A121B5490D}" = HelpSpot
"{F71760CD-0F8B-4DCC-B7B7-6B223CC3843C}" = OTtBP
"Adobe Flash Player ActiveX" = Adobe Flash Player ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Advanced SystemCare 3_is1" = Advanced SystemCare 3
"CCleaner" = CCleaner
"ENTERPRISER" = Microsoft Office Enterprise 2007
"EPSON Printer and Utilities" = EPSON Printer Software
"FileZilla Client" = FileZilla Client [removed]
"Gateway Desktop Manager" = Gateway Desktop Manager
"Gateway Power Management" = Gateway Power Management
"GTW V.92 Voice Modem" = GTW V.92 Voice Modem
"Hamachi" = Hamachi 1.0.3.0
"Hard Disk Sentinel_is1" = Hard Disk Sentinel PRO
"HijackThis" = HijackThis 2.0.2
"IDNMitigationAPIs" = Microsoft Internationalized Domain Names Mitigation APIs
"ie7" = Windows Internet Explorer 7
"ie8" = Windows Internet Explorer 8
"InstallShield_{E9ED0801-253D-4FE9-AB20-F63DEFE72547}" = SAMSUNG Mobile USB DRIVER(4.40.7.0) v1.6
"Macromedia Shockwave Player" = Macromedia Shockwave Player
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"MSCompPackV1" = Microsoft Compression Client Pack 1.0 for Windows XP
"Multi-function Keyboard Utility" = Gateway Multi-function Keyboard
"Multimedia Transcoding Tool_is1" = Multimedia Transcoding Tool
"MySpaceIM" = MySpaceIM
"NLSDownlevelMapping" = Microsoft National Language Support Downlevel APIs
"PROSet" = Intel® PRO Ethernet Adapter and Software
"PX: {99A393E0-1F86-4AB7-9FE3-ACEC7E10098F}" = Gateway Internet Links
"PX: {F87AA2D3-FE22-4AF5-9BCB-DF7E662942C8}" = GTW Printer Files
"PX: {FBD609B8-2F51-4321-A545-D2132E281BCE}" = GTW Wallpaper
"QuickLink Mobile" = QuickLink Mobile
"QuickLink PhoneManager" = QuickLink PhoneManager
"QuickTime" = QuickTime
"Smart Defrag_is1" = Smart Defrag
"Tweak UI 2.10" = Tweak UI
"UltimateDefrag V1 FREE Public Domain Version" = UltimateDefrag V1 FREE Public Domain Version
"VLC media player" = VideoLAN VLC media player 0.8.6i
"Windows Media Format Runtime" = Windows Media Format 11 runtime
"Windows Media Player" = Windows Media Player 11
"Windows XP Service Pack" = Windows XP Service Pack 3
"WinPatrol" = WinPatrol 2009
"WMFDist11" = Windows Media Format 11 runtime
"wmp11" = Windows Media Player 11
"Wudf01000" = Microsoft User-Mode Driver Framework Feature Pack 1.0

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Google Chrome" = Google Chrome

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 12/5/2009 10:17:16 PM | Computer Name = CRAIGSLAPTOP | Source = Application Error | ID = 1000
Description = Faulting application wiba94.exe, version 0.0.0.0, faulting module
kernel32.dll, version 5.1.2600.5781, fault address 0x00012afb.

Error - 12/6/2009 3:58:50 PM | Computer Name = CRAIGSLAPTOP | Source = MsiInstaller | ID = 11706
Description = Product: CA eTrust Antivirus – Error 1706.No valid source could be
found for product CA eTrust Antivirus. The Windows Installer cannot continue.

Error - 12/6/2009 3:58:59 PM | Computer Name = CRAIGSLAPTOP | Source = MsiInstaller | ID = 11706
Description = Product: CA eTrust Antivirus – Error 1706.No valid source could be
found for product CA eTrust Antivirus. The Windows Installer cannot continue.

Error - 12/6/2009 4:36:05 PM | Computer Name = CRAIGSLAPTOP | Source = Application Error | ID = 1000
Description = Faulting application ping.exe, version 5.1.2600.5512, faulting module
ntdll.dll, version 5.1.2600.5755, fault address 0x0000100b.

Error - 12/6/2009 4:36:16 PM | Computer Name = CRAIGSLAPTOP | Source = Application Error | ID = 1000
Description = Faulting application ping.exe, version 5.1.2600.5512, faulting module
ntdll.dll, version 5.1.2600.5755, fault address 0x0000100b.

Error - 12/6/2009 4:36:22 PM | Computer Name = CRAIGSLAPTOP | Source = Application Error | ID = 1000
Description = Faulting application ping.exe, version 5.1.2600.5512, faulting module
ntdll.dll, version 5.1.2600.5755, fault address 0x0000100b.

Error - 12/6/2009 4:36:24 PM | Computer Name = CRAIGSLAPTOP | Source = Application Error | ID = 1000
Description = Faulting application ping.exe, version 5.1.2600.5512, faulting module
ntdll.dll, version 5.1.2600.5755, fault address 0x0000100b.

Error - 12/19/2009 1:07:56 PM | Computer Name = CRAIGSLAPTOP | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <http://www.download.windowsupdate.com/msdo…authrootseq.txt>
with error: This operation returned because the timeout period expired.

Error - 12/19/2009 1:21:04 PM | Computer Name = CRAIGSLAPTOP | Source = MsiInstaller | ID = 11706
Description = Product: CA eTrust Antivirus – Error 1706.No valid source could be
found for product CA eTrust Antivirus. The Windows Installer cannot continue.

Error - 12/19/2009 1:21:17 PM | Computer Name = CRAIGSLAPTOP | Source = MsiInstaller | ID = 11706
Description = Product: CA eTrust Antivirus – Error 1706.No valid source could be
found for product CA eTrust Antivirus. The Windows Installer cannot continue.

[ OSession Events ]
Error - 6/30/2009 11:53:01 PM | Computer Name = CRAIGSLAPTOP | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 6, Application Name: Microsoft Office Outlook, Application Version:
12.0.6504.5000, Microsoft Office Version: 12.0.6215.1000. This session lasted 10
seconds with 0 seconds of active time. This session ended with a crash.

Error - 6/30/2009 11:53:24 PM | Computer Name = CRAIGSLAPTOP | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 6, Application Name: Microsoft Office Outlook, Application Version:
12.0.6504.5000, Microsoft Office Version: 12.0.6215.1000. This session lasted 20
seconds with 0 seconds of active time. This session ended with a crash.

[ System Events ]
Error - 12/20/2009 3:03:01 AM | Computer Name = CRAIGSLAPTOP | Source = Service Control Manager | ID = 7001
Description = The IPSEC Services service depends on the IPSEC driver service which
failed to start because of the following error: %%31

Error - 12/20/2009 3:03:01 AM | Computer Name = CRAIGSLAPTOP | Source = Service Control Manager | ID = 7026
Description = The following boot-start or system-start driver(s) failed to load:
AFD Fips IPSec MRxSmb NetBIOS NetBT P3 RasAcd Rdbss Tcpip

Error - 12/20/2009 3:04:47 AM | Computer Name = CRAIGSLAPTOP | Source = DCOM | ID = 10005
Description = DCOM got error "%1084" attempting to start the service netman with
arguments "" in order to run the server: {BA126AE5-2166-11D1-B1D0-00805FC1270E}

Error - 12/20/2009 3:04:56 AM | Computer Name = CRAIGSLAPTOP | Source = DCOM | ID = 10005
Description = DCOM got error "%1084" attempting to start the service EventSystem
with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF}

Error - 12/20/2009 3:06:58 AM | Computer Name = CRAIGSLAPTOP | Source = Service Control Manager | ID = 7000
Description = The Cacheman Service service failed to start due to the following
error: %%2

Error - 12/20/2009 3:06:58 AM | Computer Name = CRAIGSLAPTOP | Source = Service Control Manager | ID = 7000
Description = The Video Camera Device service failed to start due to the following
error: %%2

Error - 12/20/2009 3:06:50 PM | Computer Name = CRAIGSLAPTOP | Source = Service Control Manager | ID = 7034
Description = The LogMeIn Maintenance Service service terminated unexpectedly.
It has done this 1 time(s).

Error - 12/20/2009 3:06:50 PM | Computer Name = CRAIGSLAPTOP | Source = Service Control Manager | ID = 7034
Description = The LogMeIn service terminated unexpectedly. It has done this 1 time(s).

Error - 12/20/2009 3:09:54 PM | Computer Name = CRAIGSLAPTOP | Source = Service Control Manager | ID = 7000
Description = The Cacheman Service service failed to start due to the following
error: %%2

Error - 12/20/2009 3:09:54 PM | Computer Name = CRAIGSLAPTOP | Source = Service Control Manager | ID = 7000
Description = The Video Camera Device service failed to start due to the following
error: %%2


< End of report >
Yeah… ran Combofix prior to the OTL directions. I know I'm stuck when that first run of Combofix doesn't work. I tried manually deleting these directories but it didn't seem to accomplish much.
Application Data\WIHDNAG
Application Data\ba94e39


ComboFix 09-12-18.07 - Administrator 12/19/2009 23:52:31.1.1 - x86
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
AV: Additional Guard *On-access scanning enabled* (Updated) {7B15D2E9-3C53-4056-9CF3-DB8562AA03D9}
FW: Additional Guard *enabled* {7C6BF493-A50C-41BF-B120-7D3DADD5F2B7}
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\recycler\S-1-5-21-1644491937-1606980848-1343024091-500

.
((((((((((((((((((((((((( Files Created from 2009-11-20 to 2009-12-20 )))))))))))))))))))))))))))))))
.

2009-12-20 05:11 . 2009-12-20 05:11 25992 —-a-w- c:\windows\system32\pgdfgsvc.exe
2009-12-20 05:10 . 2009-12-20 05:11 ——– d—–w- c:\program files\PageDefrag
2009-12-20 04:27 . 2009-12-20 04:27 ——– d-sh–w- c:\documents and settings\Administrator\IECompatCache
2009-12-20 04:26 . 2009-12-20 04:26 ——– d-sh–w- c:\documents and settings\Administrator\PrivacIE
2009-12-20 04:21 . 2009-12-20 04:21 ——– d-sh–w- c:\documents and settings\Administrator\IETldCache
2009-12-20 04:14 . 2009-10-29 07:45 12800 -c—-w- c:\windows\system32\dllcache\xpshims.dll
2009-12-20 04:14 . 2009-10-29 07:45 246272 -c—-w- c:\windows\system32\dllcache\ieproxy.dll
2009-12-20 04:14 . 2009-12-20 04:14 ——– d—–w- c:\windows\ie8updates
2009-12-20 04:13 . 2009-10-02 04:44 92160 -c—-w- c:\windows\system32\dllcache\iecompat.dll
2009-12-20 04:07 . 2009-12-20 04:12 ——– dc-h–w- c:\windows\ie8
2009-12-20 01:53 . 2009-12-20 01:53 1078 —-a-r- c:\documents and settings\Administrator\Application Data\Microsoft\Installer\{0F9196C6-58B4-445B-B56E-B1200FECC151}\_4ae13d6c.exe
2009-12-20 01:53 . 2009-12-20 01:53 1078 —-a-r- c:\documents and settings\Administrator\Application Data\Microsoft\Installer\{0F9196C6-58B4-445B-B56E-B1200FECC151}\_2cd672ae.exe
2009-12-20 01:53 . 2009-12-20 01:53 1078 —-a-r- c:\documents and settings\Administrator\Application Data\Microsoft\Installer\{0F9196C6-58B4-445B-B56E-B1200FECC151}\_294823.exe
2009-12-20 01:53 . 2009-12-20 01:53 1078 —-a-r- c:\documents and settings\Administrator\Application Data\Microsoft\Installer\{0F9196C6-58B4-445B-B56E-B1200FECC151}\_18be6784.exe
2009-12-20 01:53 . 2009-12-20 03:19 ——– d—–w- c:\program files\Microsoft Bootvis
2009-12-20 01:47 . 2009-12-20 01:54 ——– d—–w- c:\program files\Cacheman
2009-12-20 01:39 . 2009-12-20 01:39 ——– d—–w- c:\program files\Resource Kit
2009-12-20 01:29 . 2009-12-20 01:29 ——– d—–w- c:\documents and settings\NetworkService\Local Settings\Application Data\ICS
2009-12-20 00:52 . 2003-06-25 22:05 266360 —-a-w- c:\windows\system32\TweakUI.exe
2009-12-19 18:43 . 2009-12-19 20:57 ——– d—–w- c:\documents and settings\Administrator\Application Data\IObit
2009-12-19 18:43 . 2009-12-19 20:57 ——– d—–w- c:\program files\IObit
2009-12-19 17:17 . 2009-12-19 17:17 ——– d—–w- c:\documents and settings\Administrator\Application Data\Malwarebytes
2009-12-19 17:16 . 2009-12-03 22:14 38224 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-12-19 17:16 . 2009-12-19 17:16 ——– d—–w- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-12-19 17:15 . 2009-12-03 22:13 19160 —-a-w- c:\windows\system32\drivers\mbam.sys
2009-12-19 17:15 . 2009-12-19 17:17 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2009-12-06 02:14 . 2009-12-06 02:14 ——– d-sh–w- c:\documents and settings\All Users\Application Data\WIHDNAG
2009-12-06 02:12 . 2009-12-06 02:13 2257408 —-a-w- c:\documents and settings\All Users\Application Data\ba94e39\WIba94.exe
2009-12-06 02:11 . 2009-12-06 02:16 ——– d-sh–w- c:\documents and settings\All Users\Application Data\ba94e39

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-12-20 04:33 . 2008-04-21 18:31 ——– d—–w- c:\documents and settings\Administrator\Application Data\Hamachi
2009-12-20 04:00 . 2008-08-15 23:42 ——– d—–w- c:\documents and settings\All Users\Application Data\Microsoft Help
2009-12-19 18:38 . 2006-07-26 21:12 ——– d—–w- c:\program files\Yahoo!
2009-12-19 18:38 . 2006-07-26 21:28 ——– d—–w- c:\program files\Spybot - Search & Destroy
2009-12-19 18:38 . 2006-07-26 21:28 ——– d—–w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2009-12-19 17:10 . 2006-07-26 21:12 ——– d—–w- c:\program files\CCleaner
2009-12-19 16:53 . 2008-12-09 01:33 ——– d—–w- c:\program files\LogMeIn
2009-12-06 02:08 . 2006-12-10 00:24 ——– d—–w- c:\program files\Google
2009-10-30 01:56 . 2005-03-19 15:46 71272 —-a-w- c:\documents and settings\Administrator\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-10-29 07:45 . 2004-12-07 22:37 916480 —-a-w- c:\windows\system32\wininet.dll
2009-10-26 01:47 . 2008-08-16 00:05 ——– d—–w- c:\program files\Microsoft Works
2009-10-21 05:38 . 2004-08-04 07:56 75776 —-a-w- c:\windows\system32\strmfilt.dll
2009-10-21 05:38 . 2004-08-04 07:56 25088 —-a-w- c:\windows\system32\httpapi.dll
2009-10-20 16:20 . 2004-08-04 06:00 265728 ——w- c:\windows\system32\drivers\http.sys
2009-10-17 03:27 . 2008-12-09 01:35 83288 —-a-w- c:\windows\system32\LMIRfsClientNP.dll
2009-10-17 03:27 . 2008-12-09 01:35 28984 —-a-w- c:\windows\system32\LMIport.dll
2009-10-17 03:27 . 2008-10-17 02:35 11552 —-a-w- c:\windows\system32\lmimirr2.dll
2009-10-17 03:27 . 2008-12-09 01:34 87352 —-a-w- c:\windows\system32\LMIinit.dll
2009-10-17 03:27 . 2008-10-17 02:35 25248 —-a-w- c:\windows\system32\lmimirr.dll
2009-10-13 10:30 . 2003-12-30 19:25 270336 —-a-w- c:\windows\system32\oakley.dll
2009-10-12 13:38 . 2003-12-30 19:26 149504 —-a-w- c:\windows\system32\rastls.dll
2009-10-12 13:38 . 2003-12-30 19:26 79872 —-a-w- c:\windows\system32\raschap.dll
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Advanced SystemCare 3"="c:\program files\IObit\Advanced SystemCare 3\AWC.exe" [2009-11-20 2335880]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Apoint"="c:\program files\Apoint2K\Apoint.exe" [2002-02-21 118784]
"Multi-function Keyboard"="GWHotKey.exe" [2001-08-28 98361]
"LogMeIn GUI"="c:\program files\LogMeIn\x86\LogMeInSystray.exe" [2008-07-25 63048]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"MySpaceIM"="c:\program files\MySpace\IM\MySpaceIM.exe" [2008-04-17 9117696]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\LMIinit]
2009-10-17 03:27 87352 —-a-w- c:\windows\system32\LMIinit.dll

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ !"$%&$#!%&$#!$#%!&$#&%!$#%$"!DF!CXY!DWCER"!

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Authentication Packages REG_MULTI_SZ msv1_0 nwprovau

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Install Pending Files.LNK]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Install Pending Files.LNK
backup=c:\windows\pss\Install Pending Files.LNKCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Kodak EasyShare software.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Kodak EasyShare software.lnk
backup=c:\windows\pss\Kodak EasyShare software.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Kodak software updater.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Kodak software updater.lnk
backup=c:\windows\pss\Kodak software updater.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Office.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk
backup=c:\windows\pss\Microsoft Office.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AEIWLSTA.EXE]
AEIWLSTA.EXE START [X]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AdaptecDirectCD]
2003-12-30 19:09 675840 —-a-w- c:\program files\Adaptec\Easy CD Creator 5\DirectCD\Directcd.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Update]
2008-09-10 04:14 133104 —-atw- c:\documents and settings\Administrator\Local Settings\Application Data\Google\Update\GoogleUpdate.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\GrooveMonitor]
2008-10-25 16:44 31072 —-a-w- c:\program files\Microsoft Office\Office12\GrooveMonitor.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HotKeysCmds]
2004-08-20 20:51 118784 —-a-w- c:\windows\system32\hkcmd.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IgfxTray]
2004-08-20 20:55 155648 —-a-w- c:\windows\system32\igfxtray.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
2008-04-14 00:12 1695232 —-a-w- c:\program files\Messenger\msmsgs.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MySpaceIM]
2008-04-17 23:27 9117696 —-a-w- c:\program files\MySpace\IM\MySpaceIM.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
2006-06-18 19:01 77824 —-a-w- c:\program files\QuickTime\qttask.exe

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Kodak\\KODAK Software Updater\\7288971\\Program\\Kodak Software Updater.exe"=
"c:\\Program Files\\Hamachi\\hamachi.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\Program Files\\MySpace\\IM\\MySpaceIM.exe"=
"c:\\Program Files\\FileZilla FTP Client\\filezilla.exe"=
"c:\\Documents and Settings\\All Users\\Application Data\\ba94e39\\WIba94.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"1723:TCP"= 1723:TCP:@xpsp2res.dll,-22015
"1701:UDP"= 1701:UDP:@xpsp2res.dll,-22016
"500:UDP"= 500:UDP:@xpsp2res.dll,-22017

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\IcmpSettings]
"AllowInboundEchoRequest"= 1 (0x1)

R2 CachemanService;Cacheman Service;c:\program files\Cacheman\CachemanServ.exe [x]
R2 LMIInfo;LogMeIn Kernel Information Provider;c:\program files\LogMeIn\x86\RaInfo.sys [2008-07-25 12856]
R2 pmp3050v;Video Camera Device;c:\windows\system32\Drivers\pmp3050v.sys [x]
R3 {A7E39B01-B403-11d4-BD18-00D0B7A1821E};AIM 3.0 Part 01 Codec Driver VCH-A;c:\windows\system32\drivers\Vch.sys [2002-01-15 18487]
R3 AEIWL;Actiontec PRISM Wireless LAN USB Driver;c:\windows\system32\DRIVERS\AEIWLUSB.sys [2002-09-24 607232]
R3 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [2009-10-17 133104]
R3 iscFlash;iscFlash;c:\windows\SYSTEM32\DRIVERS\iscflash.sys [x]
R4 LMIRfsClientNP;LMIRfsClientNP; [x]
S2 LMIRfsDriver;LogMeIn Remote File System Driver;c:\windows\system32\drivers\LMIRfsDriver.sys [2008-07-25 47640]
S3 AEIWL_USB;Actiontec Wireless LAN USB Driver;c:\windows\system32\DRIVERS\AEIWLUSB.sys [2002-09-24 607232]


— Other Services/Drivers In Memory —

*NewlyCreated* - PAGEDFRG
*Deregistered* - PAGEDFRG
.
——- Supplementary Scan ——-
.
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
uStart Page = hxxp://www.i29.net/
DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
.
- - - - ORPHANS REMOVED - - - -

MSConfigStartUp-Realtime Monitor - c:\progra~1\CA\ETRUST~1\realmon.exe
AddRemove-Adobe ConnectNow Add-in - c:\documents and settings\Administrator\Application Data\Macromedia\Flash Player\www.macromedia.com\bin\acaddin\acaddin.exe



**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-12-20 00:01
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————

[HKEY_USERS\S-1-5-21-1409436206-1863585682-1345747165-500\Software\Microsoft\Internet Explorer\User Preferences]
@Denied: (2) (Administrator)
"88D7D0879DAB32E14DE5B3A805A34F98AFF34F5977"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,6b,3a,f8,a2,72,64,19,44,a3,c3,c2,\
"2D53CFFC5C1A3DD2E97B7979AC2A92BD59BC839E81"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,6b,3a,f8,a2,72,64,19,44,a3,c3,c2,\
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'winlogon.exe'(912)
c:\windows\system32\LMIinit.dll
c:\windows\system32\l3codecx.acm

- - - - - - - > 'explorer.exe'(3868)
c:\windows\system32\WININET.dll
c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_6b128700\MSVCR80.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\IEFRAME.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
c:\windows\system32\LMIRfsClientNP.dll
.
Completion time: 2009-12-20 00:10:18
ComboFix-quarantined-files.txt 2009-12-20 06:10

Pre-Run: 8,559,598,592 bytes free
Post-Run: 8,547,295,232 bytes free

WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /fastdetect /NoExecute=OptIn

- - End Of File - - 8BFA5C1068925359231814DAC36AFCF5
When I went to re-run CF after the one I posted, it still thought Additional Guard was running as a security item. So it seems the computer is faster than it was, but I think there is a remnant of Additional Guard still floating around to make CF think its still there.
Hi teeps,

Combofix is a very powerfull tool and should not be used without supervision. Please do not run any tools or do any scans unless requested.




We need some file information
  • Make sure to use Internet Explorer for this
  • Please go to VirSCAN.org FREE on-line scan service
  • Copy and paste the following file path, one at a time if more than file is listed, into the "Suspicious files to scan" box on the top of the page:

    c:\documents and settings\All Users\Application Data\ba94e39\WIba94.exe

  • Click on the Upload button
  • Please ensure the scan is complete and the results saved before submitting the next.
  • If a pop-up appears saying the file has been scanned already, please select the ReScan button.
  • Once the Scan is completed, click on the "Copy to Clipboard" button. This will copy the link of the report into the Clipboard.
  • Paste the contents of the Clipboard in your next reply.


We will use combofix again but run it differently.

Please follow all previous instructions regarding security programs.

Open a new Notepad session
  • Click the Start button, click run
  • in the run box type notepad
  • click ok
  • In the notepad, Click "Format" and be certain that Word Wrap is not checked.
  • Copy and paste all the text in the code box below into the Notepad. Do Not copy the word CODE

DirLook::
c:\documents and settings\All Users\Application Data\WIHDNAG
c:\documents and settings\All Users\Application Data\ba94e39

SecCenter::
{7B15D2E9-3C53-4056-9CF3-DB8562AA03D9}
{7C6BF493-A50C-41BF-B120-7D3DADD5F2B7}

RegLock::
[HKEY_USERS\S-1-5-21-1409436206-1863585682-1345747165-500\Software\Microsoft\Internet Explorer\User Preferences]

In the notepad
  • Click File, Save as…, and set the Save in to your Desktop
  • In the filename box, type (including quotation marks) as the filename: "CFScript.txt"
  • Click save
Using your mouse left button, drag the new file CFscript.txt and drop it on the ComboFix.exe icon as shown below.

This will start ComboFix again.Close all browser/windows first.

**Note: Do not mouseclick combofix's window while it's running. That may cause it to stall**

[external image: Posted Image]

Plwase post the
  • VirScan results
  • combofix log

Thanks
Since opening this thread, I haven't run anything except for what you have asked. I have been a good boy since Christmas is just around the corner. Don't want any coal in my stocking. :D

I had manually removed the directories containing the file that you wanted the jotti on. This was done prior to opening this thread. So no log from that. Below is the cf log.

ComboFix 09-12-20.08 - Administrator 12/21/2009 8:43.2.1 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.254.116 [GMT -6:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\Administrator\Desktop\CFScript.txt
.

((((((((((((((((((((((((( Files Created from 2009-11-21 to 2009-12-21 )))))))))))))))))))))))))))))))
.

2009-12-20 19:06 . 2009-12-20 19:06 ——– d—–w- C:\_OTL
2009-12-20 14:49 . 2009-12-20 14:49 ——– d-sh–w- c:\documents and settings\NetworkService\IETldCache
2009-12-20 06:58 . 2009-12-20 06:58 34816 —-a-w- c:\windows\system32\drivers\rootrepeal.sys
2009-12-20 06:24 . 2009-12-20 06:24 ——– d—–w- c:\documents and settings\Administrator\Application Data\WinPatrol
2009-12-20 06:24 . 2003-12-30 17:40 0 —-a-w- c:\documents and settings\Administrator\Application Data\WinPatrol\Config.sys
2009-12-20 06:24 . 2003-12-30 17:40 0 —-a-w- c:\documents and settings\Administrator\Application Data\WinPatrol\Autoexec.bat
2009-12-20 06:24 . 2009-12-20 06:24 ——– d—–w- c:\program files\BillP Studios
2009-12-20 05:11 . 2009-12-20 05:11 25992 —-a-w- c:\windows\system32\pgdfgsvc.exe
2009-12-20 05:10 . 2009-12-20 05:11 ——– d—–w- c:\program files\PageDefrag
2009-12-20 04:27 . 2009-12-20 04:27 ——– d-sh–w- c:\documents and settings\Administrator\IECompatCache
2009-12-20 04:26 . 2009-12-20 04:26 ——– d-sh–w- c:\documents and settings\Administrator\PrivacIE
2009-12-20 04:21 . 2009-12-20 04:21 ——– d-sh–w- c:\documents and settings\Administrator\IETldCache
2009-12-20 04:14 . 2009-10-29 07:45 12800 -c—-w- c:\windows\system32\dllcache\xpshims.dll
2009-12-20 04:14 . 2009-10-29 07:45 246272 -c—-w- c:\windows\system32\dllcache\ieproxy.dll
2009-12-20 04:14 . 2009-12-20 04:14 ——– d—–w- c:\windows\ie8updates
2009-12-20 04:13 . 2009-10-02 04:44 92160 -c—-w- c:\windows\system32\dllcache\iecompat.dll
2009-12-20 04:07 . 2009-12-20 04:12 ——– dc-h–w- c:\windows\ie8
2009-12-20 01:53 . 2009-12-20 01:53 1078 —-a-r- c:\documents and settings\Administrator\Application Data\Microsoft\Installer\{0F9196C6-58B4-445B-B56E-B1200FECC151}\_4ae13d6c.exe
2009-12-20 01:53 . 2009-12-20 01:53 1078 —-a-r- c:\documents and settings\Administrator\Application Data\Microsoft\Installer\{0F9196C6-58B4-445B-B56E-B1200FECC151}\_2cd672ae.exe
2009-12-20 01:53 . 2009-12-20 01:53 1078 —-a-r- c:\documents and settings\Administrator\Application Data\Microsoft\Installer\{0F9196C6-58B4-445B-B56E-B1200FECC151}\_294823.exe
2009-12-20 01:53 . 2009-12-20 01:53 1078 —-a-r- c:\documents and settings\Administrator\Application Data\Microsoft\Installer\{0F9196C6-58B4-445B-B56E-B1200FECC151}\_18be6784.exe
2009-12-20 01:53 . 2009-12-20 03:19 ——– d—–w- c:\program files\Microsoft Bootvis
2009-12-20 01:47 . 2009-12-20 01:54 ——– d—–w- c:\program files\Cacheman
2009-12-20 01:39 . 2009-12-20 01:39 ——– d—–w- c:\program files\Resource Kit
2009-12-20 01:29 . 2009-12-20 01:29 ——– d—–w- c:\documents and settings\NetworkService\Local Settings\Application Data\ICS
2009-12-20 00:52 . 2003-06-25 22:05 266360 —-a-w- c:\windows\system32\TweakUI.exe
2009-12-19 18:43 . 2009-12-19 20:57 ——– d—–w- c:\documents and settings\Administrator\Application Data\IObit
2009-12-19 18:43 . 2009-12-19 20:57 ——– d—–w- c:\program files\IObit
2009-12-19 17:17 . 2009-12-19 17:17 ——– d—–w- c:\documents and settings\Administrator\Application Data\Malwarebytes
2009-12-19 17:16 . 2009-12-03 22:14 38224 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-12-19 17:16 . 2009-12-19 17:16 ——– d—–w- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-12-19 17:15 . 2009-12-03 22:13 19160 —-a-w- c:\windows\system32\drivers\mbam.sys
2009-12-19 17:15 . 2009-12-19 17:17 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-12-21 09:19 . 2008-12-09 01:33 ——– d—–w- c:\program files\LogMeIn
2009-12-20 14:51 . 2006-12-10 00:24 ——– d—–w- c:\program files\Google
2009-12-20 04:33 . 2008-04-21 18:31 ——– d—–w- c:\documents and settings\Administrator\Application Data\Hamachi
2009-12-20 04:00 . 2008-08-15 23:42 ——– d—–w- c:\documents and settings\All Users\Application Data\Microsoft Help
2009-12-19 18:38 . 2006-07-26 21:12 ——– d—–w- c:\program files\Yahoo!
2009-12-19 18:38 . 2006-07-26 21:28 ——– d—–w- c:\program files\Spybot - Search & Destroy
2009-12-19 18:38 . 2006-07-26 21:28 ——– d—–w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2009-12-19 17:10 . 2006-07-26 21:12 ——– d—–w- c:\program files\CCleaner
2009-10-30 01:56 . 2005-03-19 15:46 71272 —-a-w- c:\documents and settings\Administrator\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-10-29 07:45 . 2004-12-07 22:37 916480 ——w- c:\windows\system32\wininet.dll
2009-10-26 01:47 . 2008-08-16 00:05 ——– d—–w- c:\program files\Microsoft Works
2009-10-21 05:38 . 2004-08-04 07:56 75776 —-a-w- c:\windows\system32\strmfilt.dll
2009-10-21 05:38 . 2004-08-04 07:56 25088 —-a-w- c:\windows\system32\httpapi.dll
2009-10-20 16:20 . 2004-08-04 06:00 265728 ——w- c:\windows\system32\drivers\http.sys
2009-10-17 03:27 . 2008-12-09 01:35 83288 —-a-w- c:\windows\system32\LMIRfsClientNP.dll
2009-10-17 03:27 . 2008-12-09 01:35 28984 —-a-w- c:\windows\system32\LMIport.dll
2009-10-17 03:27 . 2008-10-17 02:35 11552 —-a-w- c:\windows\system32\lmimirr2.dll
2009-10-17 03:27 . 2008-12-09 01:34 87352 —-a-w- c:\windows\system32\LMIinit.dll
2009-10-17 03:27 . 2008-10-17 02:35 25248 —-a-w- c:\windows\system32\lmimirr.dll
2009-10-13 10:30 . 2003-12-30 19:25 270336 —-a-w- c:\windows\system32\oakley.dll
2009-10-12 13:38 . 2003-12-30 19:26 149504 —-a-w- c:\windows\system32\rastls.dll
2009-10-12 13:38 . 2003-12-30 19:26 79872 —-a-w- c:\windows\system32\raschap.dll
.

(((((((((((((((((((((((((((((((((((((((((((( Look )))))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
—- Directory of c:\documents and settings\All Users\Application Data\ba94e39 —-


—- Directory of c:\documents and settings\All Users\Application Data\WIHDNAG —-



((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Advanced SystemCare 3"="c:\program files\IObit\Advanced SystemCare 3\AWC.exe" [2009-11-20 2335880]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Apoint"="c:\program files\Apoint2K\Apoint.exe" [2002-02-21 118784]
"Multi-function Keyboard"="GWHotKey.exe" [2001-08-28 98361]
"LogMeIn GUI"="c:\program files\LogMeIn\x86\LogMeInSystray.exe" [2008-07-25 63048]
"WinPatrol"="c:\program files\BillP Studios\WinPatrol\winpatrol.exe" [2009-10-10 320832]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"MySpaceIM"="c:\program files\MySpace\IM\MySpaceIM.exe" [2008-04-17 9117696]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\LMIinit]
2009-10-17 03:27 87352 —-a-w- c:\windows\system32\LMIinit.dll

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ !$%&$#!%&$#!$#%!&$#&%!$#%$!DF!CXY!DWCER!

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Authentication Packages REG_MULTI_SZ msv1_0 nwprovau

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Install Pending Files.LNK]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Install Pending Files.LNK
backup=c:\windows\pss\Install Pending Files.LNKCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Kodak EasyShare software.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Kodak EasyShare software.lnk
backup=c:\windows\pss\Kodak EasyShare software.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Kodak software updater.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Kodak software updater.lnk
backup=c:\windows\pss\Kodak software updater.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Office.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk
backup=c:\windows\pss\Microsoft Office.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AEIWLSTA.EXE]
AEIWLSTA.EXE START [X]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AdaptecDirectCD]
2003-12-30 19:09 675840 —-a-w- c:\program files\Adaptec\Easy CD Creator 5\DirectCD\Directcd.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Update]
2008-09-10 04:14 133104 —-atw- c:\documents and settings\Administrator\Local Settings\Application Data\Google\Update\GoogleUpdate.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\GrooveMonitor]
2008-10-25 16:44 31072 —-a-w- c:\program files\Microsoft Office\Office12\GrooveMonitor.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HotKeysCmds]
2004-08-20 20:51 118784 —-a-w- c:\windows\system32\hkcmd.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IgfxTray]
2004-08-20 20:55 155648 —-a-w- c:\windows\system32\igfxtray.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
2008-04-14 00:12 1695232 —-a-w- c:\program files\Messenger\msmsgs.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MySpaceIM]
2008-04-17 23:27 9117696 —-a-w- c:\program files\MySpace\IM\MySpaceIM.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
2006-06-18 19:01 77824 —-a-w- c:\program files\QuickTime\qttask.exe

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Kodak\\KODAK Software Updater\\7288971\\Program\\Kodak Software Updater.exe"=
"c:\\Program Files\\Hamachi\\hamachi.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\Program Files\\MySpace\\IM\\MySpaceIM.exe"=
"c:\\Program Files\\FileZilla FTP Client\\filezilla.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"1723:TCP"= 1723:TCP:@xpsp2res.dll,-22015
"1701:UDP"= 1701:UDP:@xpsp2res.dll,-22016
"500:UDP"= 500:UDP:@xpsp2res.dll,-22017

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\IcmpSettings]
"AllowInboundEchoRequest"= 1 (0x1)

R2 LMIInfo;LogMeIn Kernel Information Provider;c:\program files\LogMeIn\x86\rainfo.sys [7/24/2008 6:46 PM 12856]
R2 LMIRfsDriver;LogMeIn Remote File System Driver;c:\windows\system32\drivers\LMIRfsDriver.sys [12/8/2008 7:35 PM 47640]
R3 AEIWL_USB;Actiontec Wireless LAN USB Driver;c:\windows\system32\drivers\AEIWLUSB.sys [12/30/2003 2:42 PM 607232]
S2 CachemanService;Cacheman Service;c:\program files\Cacheman\CachemanServ.exe –> c:\program files\Cacheman\CachemanServ.exe [?]
S2 pmp3050v;Video Camera Device;c:\windows\system32\Drivers\pmp3050v.sys –> c:\windows\system32\Drivers\pmp3050v.sys [?]
S3 {A7E39B01-B403-11d4-BD18-00D0B7A1821E};AIM 3.0 Part 01 Codec Driver VCH-A;c:\windows\system32\drivers\vch.sys [12/30/2003 11:49 AM 18487]
S3 AEIWL;Actiontec PRISM Wireless LAN USB Driver;c:\windows\system32\drivers\AEIWLUSB.sys [12/30/2003 2:42 PM 607232]
S3 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [10/16/2009 9:33 PM 133104]
S3 iscFlash;iscFlash;\??\c:\windows\SYSTEM32\DRIVERS\iscflash.sys –> c:\windows\SYSTEM32\DRIVERS\iscflash.sys [?]
S4 LMIRfsClientNP;LMIRfsClientNP; [x]
.
——- Supplementary Scan ——-
.
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid;=ie7&rls;=com.microsoft:en-US&ie;=utf8&oe;=utf8
uStart Page = hxxp://www.i29.net/
DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-12-21 08:53
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
"ImagePath"="\??\c:\windows\system32\drivers\rootrepeal
[1].sys"


[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\rootrepeal[1]]
"ImagePath"="\??\c:\windows\system32\drivers\rootrepeal
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'winlogon.exe'(912)
c:\windows\system32\LMIinit.dll
c:\windows\system32\l3codecx.acm

- - - - - - - > 'explorer.exe'(3632)
c:\windows\system32\WININET.dll
c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_6b128700\MSVCR80.dll
c:\program files\Apoint2K\EzAuto.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
c:\windows\system32\LMIRfsClientNP.dll
.
Completion time: 2009-12-21 09:02:46
ComboFix-quarantined-files.txt 2009-12-21 15:02
ComboFix2.txt 2009-12-20 06:10

Pre-Run: 8,457,041,408 bytes free
Post-Run: 8,422,215,680 bytes free

- - End Of File - - 0701B2DD5AC6630E3C63BA21C873852F
Hi teeps,

Since opening this thread, I haven't run anything except for what you have asked.

:thumbup:

How is the computer?

Where is your antivirus program?
Computer seems good. I have to check with the owner on AV. He had CA partially installed on here. Don't know if it was a disinfection effort or what. If he has a license, I will got that route. If not, Avira is going on. I'm going to throw spywareblaster on as well.
Hi teeps,

Install the AV as soon as possible. The logs look good.

If no other problems, wecan clean up our tools.

From your desktop, please delete
  • any notepads/logs that we created

Next

Click the Start button, click Run. Copy and paste the following line into the run box and click OK
Combofix /uninstall


Open OTL then click the Clean Up button. You may get prompted by your firewall that OTL wants to contact the internet - allow this. A cleanup.txt will be downloaded, a message dialog will ask you if you want to proceed with the cleanup process, click Yes. This will do some clean up tasks and delete some of the tools you have downloaded plus itself.


I suggest you keep MBAM. Keep it updated and use it regularly.


Updates and upgrades

You have an older version of Adobe Reader. You can download the current version HERE

You may want to consider Foxit Reader instead. It may be a bit lighter on resources.

Visit their support forum
Foxit Forum

In either case you should uninstall Adobe Reader 8.1.2 first. Be sure to move any PDF documents to another folder first though.


Some Recommendations and prevention tips

Basic security consists of 1 antivirus program, 1 resident antispyware program, 1 on demand antispyware program and a firewall. Just add a firewall. (Don't forget the antivirus program)

* If you are behind a router Windows firewall should be fine. Otherwise a 3rd party firewall with outbound monitoring is recommended.

Click FIREWALL for tips, reviews and links to good, free and paid for firewalls. (Note: Zone Alarm is becoming bloatware)


You should also use Spyware Blaster to help immunize your computer.

- SpywareBlaster will add a large list of programs and sites into your Internet Explorer
settings that will protect you from running and downloading known malicious programs.

OR

A guide to understanding and using the hosts file.

Learn how your Hosts file can protect you and how you can protect it.
Besides the Hosts file information, there are links to a very good updated hosts file, a host file manager. and some programs that can protect your hosts file.
HOSTS

Please read the info on disabling the DNS Client before installing a custom hosts file.


-Secure your Internet Explorer

From within Internet Explorer click on the Tools menu and then click on Options.
  • Click once on the Security tab
  • Click once on the Internet icon so it becomes highlighted.
  • Click once on the Custom Level button.
  • Change the Download signed ActiveX controls to Prompt
  • Change the Download unsigned ActiveX controls to Disable
  • Change the Initialize and script ActiveX controls not marked as safe to Disable
  • Change the Installation of desktop items to Prompt
  • Change the Launching programs and files in an IFRAME to Prompt
  • Change the Navigate sub-frames across different domains to Prompt
  • When all these settings have been made, click on the OK button.
  • If it prompts you as to whether or not you want to save the settings, press the Yes button.
Next press the Apply button and then the OK to exit the Internet Properties page.


- Keeping your Windows up-to-date is crucial to your computer's security. Please go to the Windows Update Site (using Internet Explorer) and download and install all critical updates on a regular basis


- Ensure that Automatic Update is turned on so you get all the latest patches.
Click start, control panel, click Security Center.


- Keep your antivirus program updated, as well as any other security programs you have.


-Check this site out to check for out of date programs
Secunia Personal Software Inspector (PSI) 1.0


-More tips and programs can be found HERE



- You may also want to read this article By Tony Klein
http://www.freedomlist.com/forum/viewtopic.php?t=22879

We will keep this thread open for a couple of days. Please post back if you have any problems or questions. Please post back when you have finished so this thread can be marked "Resolved".

Take care :adios:
Thanks a lot Oldman. I have Avira and Spywareblaster installed. I appreciate your hard work on this forum. I provide free services to people here in my community to help keep them virus/malware free. Thank you for enabling me to provide not only free, but effective services. Blessings to you, Teeps Resolved…
Since this issue appears to be resolved … this Topic has been closed. Glad we could be of assistance. If you're the topic starter, and need this topic reopened, please contact a staff member with the address of the thread. Everyone else please begin a New Topic.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI