This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Fell prey to Enterprise Rogue

9 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

My friend called for help after paying for the Enterprise Security Suite and encountering lots of pop-up warnings. He has a Gateway with Vista Home Premium Service Pack 1. He'd allowed his introductory anti-virus/anti-spyware programs to lapse over a year ago. We'd appreciate help cleaning it up. Thanks!
-Jcatsmom

I have run ATF Cleaner, Malwarebytes, Gmer, ERUNT, and DDS Screen. I uninstalled his outdated Java, but have not installed the updated version. I've also not installed SP2 or his new AV program because I don't want to attach the computer to the internet with the unknown 010 Winsock entries. ALOT and Ask taskbars are the other leftovers that I know of.

Malwarebytes' Anti-Malware 1.43
Database version: 3458
Windows 6.0.6001 Service Pack 1
Internet Explorer 8.0.6001.18865

1/1/2010 10:32:54 PM
mbam-log-2010-01-01 (22-32-54).txt

Scan type: Quick Scan
Objects scanned: 94610
Time elapsed: 4 minute(s), 21 second(s)

Memory Processes Infected: 1
Memory Modules Infected: 0
Registry Keys Infected: 3
Registry Values Infected: 1
Registry Data Items Infected: 2
Folders Infected: 3
Files Infected: 7

Memory Processes Infected:
C:\ProgramData\c8d52aa\WEc8d5.exe (Rogue.Multiple) -> Unloaded process successfully.

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{1d4db7d2-6ec9-47a3-bd87-1e41684e07bb} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Sellmosoft (Rogue.Multiple) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Sellmosoft (Rogue.Multiple) -> Quarantined and deleted successfully.

Registry Values Infected:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\enterprise suite (Rogue.Multiple) -> Quarantined and deleted successfully.

Registry Data Items Infected:
HKEY_CLASSES_ROOT\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\URL (Hijack.SearchPage) -> Bad: (http://search-gala.com/?&uid=195&q={searchTerms}) Good: (http://www.Google.com/) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Start_ShowSearch (Hijack.StartMenu) -> Bad: (0) Good: (1) -> Quarantined and deleted successfully.

Folders Infected:
C:\Users\Ted Hall\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Performance Optimizer (Rogue.Performanceoptimizer) -> Quarantined and deleted successfully.
C:\Users\Ted Hall\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Performance Optimizer\Documentation (Rogue.Performanceoptimizer) -> Quarantined and deleted successfully.
C:\Users\Ted Hall\AppData\Roaming\Enterprise Suite (Rogue.EnterpriseSuite) -> Quarantined and deleted successfully.

Files Infected:
C:\ProgramData\c8d52aa\WEc8d5.exe (Rogue.Multiple) -> Quarantined and deleted successfully.
C:\Users\Ted Hall\downloads\Antivir-31c7ff_2024-1.exe (Rogue.Installer) -> Quarantined and deleted successfully.
C:\Users\Ted Hall\AppData\Roaming\Enterprise Suite\Instructions.ini (Rogue.EnterpriseSuite) -> Quarantined and deleted successfully.
C:\Users\Ted Hall\Desktop\Enterprise Suite.lnk (Rogue.EnterpriseSuite) -> Quarantined and deleted successfully.
C:\Users\Ted Hall\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Enterprise Suite.lnk (Rogue.EnterpriseSuite) -> Quarantined and deleted successfully.
C:\Users\Ted Hall\AppData\Roaming\Microsoft\Windows\Start Menu\Enterprise Suite.lnk (Rogue.EnterpriseSuite) -> Quarantined and deleted successfully.
C:\Users\Ted Hall\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Enterprise Suite.lnk (Rogue.EnterpriseSuite) -> Quarantined and deleted successfully.


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 10:41:41 PM, on 1/1/2010
Platform: Windows Vista SP1 (WinNT 6.00.1905)
MSIE: Internet Explorer v8.00 (8.00.6001.18865)
Boot mode: Normal

Running processes:
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Trend Micro\AntiVirus 2007\tavui.exe
C:\Windows\RtHDVCpl.exe
C:\Windows\zHotkey.exe
C:\Program Files\ScanSoft\OmniPageSE4.0\OpWareSE4.exe
C:\Windows\System32\spool\drivers\w32x86\3\WrtMon.exe
C:\Windows\System32\igfxtray.exe
C:\Windows\System32\hkcmd.exe
C:\Windows\System32\igfxpers.exe
C:\Windows\System32\spool\drivers\w32x86\3\WrtProc.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe
C:\Windows\system32\igfxsrvc.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Windows\ehome\ehtray.exe
C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
C:\Windows\ehome\ehmsas.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Windows\system32\wuauclt.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\Windows\system32\SearchFilterHost.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.gateway.com/g/startpage.html?Ch…TP&M=GT5468
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.gateway.com/g/startpage.html?Ch…TP&M=GT5468
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.gateway.com/g/sidepanel.html?Ch…TP&M=GT5468
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: (no name) - {0579B4B6-0293-4d73-B02D-5EBB0BA0F0A2} - C:\Program Files\AskSBar\SrchAstt\1.bin\A2SRCHAS.DLL
O1 - Hosts: ::1 localhost
O2 - BHO: Ask Search Assistant BHO - {0579B4B1-0293-4d73-B02D-5EBB0BA0F0A2} - C:\Program Files\AskSBar\SrchAstt\1.bin\A2SRCHAS.DLL
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: ALOT Toolbar BHO - {14CEEAFF-96DD-4101-AE37-D5ECDC23C3F6} - C:\Program Files\alot\bin\alot.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O2 - BHO: Ask Toolbar BHO - {F0D4B231-DA4B-4daf-81E4-DFEE4931A4AA} - C:\Program Files\AskSBar\bar\1.bin\ASKSBAR.DLL
O3 - Toolbar: Ask Toolbar - {F0D4B239-DA4B-4daf-81E4-DFEE4931A4AA} - C:\Program Files\AskSBar\bar\1.bin\ASKSBAR.DLL
O3 - Toolbar: ALOT Toolbar - {5AA2BA46-9913-4dc7-9620-69AB0FA17AE7} - C:\Program Files\alot\bin\alot.dll
O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
O4 - HKLM\..\Run: [CHotkey] zHotkey.exe
O4 - HKLM\..\Run: [ShowWnd] ShowWnd.exe
O4 - HKLM\..\Run: [Trend Micro AntiVirus 2007] "C:\Program Files\Trend Micro\AntiVirus 2007\tavui.exe" -1 –delay 200
O4 - HKLM\..\Run: [SSBkgdUpdate] "C:\Program Files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" -Embedding -boot
O4 - HKLM\..\Run: [OpwareSE4] "C:\Program Files\ScanSoft\OmniPageSE4.0\OpwareSE4.exe"
O4 - HKLM\..\Run: [WrtMon.exe] C:\Windows\system32\spool\drivers\w32x86\3\WrtMon.exe
O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [AppleSyncNotifier] "C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [Malwarebytes Anti-Malware (reboot)] "C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe" /runcleanupscript
O4 - HKLM\..\Run: [SpySweeper] C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe /startintray
O4 - HKLM\..\RunOnce: [Launcher] %WINDIR%\SMINST\launcher.exe
O4 - HKCU\..\Run: [Windows Sidebar] "C:\Program Files\Windows Sidebar\Sidebar.exe" /autorun
O4 - HKCU\..\Run: [Sidebar] "C:\Program Files\Windows Sidebar\sidebar.exe" /autoRun
O4 - HKCU\..\Run: [RunSpySweeperScheduleAtStartup] "C:\Windows\system32\msfeedssync.exe" /ScheduleSweep=User_Feed_Synchronization-{BFC14688-45C9-4E2F-8D4C-EB7F3F59BEC8}
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [Magentic] "C:\PROGRA~1\Magentic\bin\Magentic.exe" /c
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O4 - Startup: OneNote 2007 Screen Clipper and Launcher.lnk = C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\npjpi160_01.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\npjpi160_01.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O10 - Unknown file in Winsock LSP: c:\windows\system32\tmlsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\tmlsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\tmlsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\tmlsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\tmlsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\tmlsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\tmlsp.dll
O13 - Gopher Prefix:
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - http://a1540.g.akamai.net/7/1540/52/200707…ex/qtplugin.cab
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: McciCMService - Motive Communications, Inc. - C:\Program Files\Common Files\Motive\McciCMService.exe
O23 - Service: Trend Micro AntiVirus Protection Service (tavsvc) - Trend Micro Inc. - C:\Program Files\Trend Micro\AntiVirus 2007\tavsvc.exe
O23 - Service: Trend Micro Proxy Service (tmproxy) - Trend Micro Inc. - C:\Program Files\Trend Micro\AntiVirus 2007\Components\tmproxy.exe
O23 - Service: Webroot Spy Sweeper Engine (WebrootSpySweeperService) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe

–
End of file - 7959 bytes


GMER 1.0.15.15281 - http://www.gmer.net
Rootkit scan 2010-01-02 00:41:14
Windows 6.0.6001 Service Pack 1
Running: 1w69rcxe.exe; Driver: C:\Users\TEDHAL~1\AppData\Local\Temp\uwldrfow.sys


—- System - GMER 1.0.15 —-

SSDT 84078400 ZwAllocateVirtualMemory
SSDT 84078D88 ZwCreateKey
SSDT 84078928 ZwCreateProcess
SSDT 840788B0 ZwCreateProcessEx
SSDT 840786D0 ZwCreateThread
SSDT 84078B80 ZwDeleteKey
SSDT 840789A0 ZwDeleteValueKey
SSDT 84078478 ZwQueueApcThread
SSDT 84078310 ZwReadVirtualMemory
SSDT 84078B08 ZwRenameKey
SSDT 84078568 ZwSetContextThread
SSDT 84078A90 ZwSetInformationKey
SSDT 840787C0 ZwSetInformationProcess
SSDT 840785E0 ZwSetInformationThread
SSDT 84078A18 ZwSetValueKey
SSDT 84078748 ZwSuspendProcess
SSDT 840784F0 ZwSuspendThread
SSDT 84078838 ZwTerminateProcess
SSDT 84078658 ZwTerminateThread
SSDT 84078388 ZwWriteVirtualMemory
SSDT 84078298 ZwCreateUserProcess

—- Devices - GMER 1.0.15 —-

AttachedDevice \FileSystem\Ntfs \Ntfs SSFS0BB9.SYS (Spy Sweeper FileSystem Filter Driver/Webroot Software Inc (www.webroot.com))
AttachedDevice \FileSystem\fastfat \Fat SSFS0BB9.SYS (Spy Sweeper FileSystem Filter Driver/Webroot Software Inc (www.webroot.com))
AttachedDevice \FileSystem\fastfat \Fat fltmgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)

—- EOF - GMER 1.0.15 —-
Hi , welcome to the forum.

To make cleaning this machine easier
  • Please do not uninstall/install any programs unless asked to
    It is more difficult when files/programs are appearing in/disappearing from the logs.
  • Please do not run any scans other than those requested
  • Please follow all instructions in the order posted
  • All logs/reports, etc.. must be posted in Notepad. Please ensure that word wrap is unchecked. In notepad click format, uncheck word wrap if it is checked.
  • Do not attach any logs/reports, etc.. unless specifically requested to do so.
  • If you have problems with or do not understand the instructions, Please ask before continuing.
  • Please stay with this thread until given the All Clear. A absence of symptoms does not mean a clean machine.

the unknown 010 Winsock entries

Belong to the TrendMicro firewall so they are ok.

Download OTL to your desktop.
  • Right click on OTL.exe and choose "Run as Adminstrator" to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output
  • Check the boxes beside LOP Check and Purity Check.
  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.

Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post it with your next reply. You may need two posts to fit them all in.

Any major issues, such as redirects etc?

Thanks
Oldman960,
Thank you for your prompt reply. Here are the Oldtimer results:

OTL Extras logfile created on: 1/2/2010 4:15:28 PM - Run 1

OTL by OldTimer - Version 3.1.20.1 Folder = C:\Users\Ted Hall\Desktop\computer tools
Windows Vista Home Premium Edition Service Pack 1 (Version = 6.0.6001) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18865)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

2.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 69.00% Memory free
4.00 Gb Paging File | 4.00 Gb Available in Paging File | 84.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 362.81 Gb Total Space | 283.47 Gb Free Space | 78.13% Space Free | Partition Type: NTFS
Drive D: | 9.80 Gb Total Space | 4.43 Gb Free Space | 45.21% Space Free | Partition Type: NTFS
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Drive J: | 488.60 Mb Total Space | 309.41 Mb Free Space | 63.33% Space Free | Partition Type: FAT

Computer Name: TEDHALL-PC
Current User Name: Ted Hall
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.chm [@ = chm.file] – "%SystemRoot%\hh.exe" %1
.cpl [@ = cplfile] – C:\Windows\System32\control.exe (Microsoft Corporation)
.hlp [@ = hlpfile] – C:\Windows\winhlp32.exe (Microsoft Corporation)
.html [@ = htmlfile] – C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation)

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
chm.file [open] – "%SystemRoot%\hh.exe" %1
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
hlpfile [open] – %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation)
htmlfile – "C:\Program Files\Microsoft Office\Office12\msohtmed.exe" %1 (Microsoft Corporation)
htmlfile [open] – "C:\Program Files\Internet Explorer\iexplore.exe" -nohome (Microsoft Corporation)
htmlfile [opennew] – "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
htmlfile [print] – "C:\Program Files\Microsoft Office\Office12\msohtmed.exe" /p %1 (Microsoft Corporation)
http [open] – "C:\Program Files\Internet Explorer\iexplore.exe" -nohome (Microsoft Corporation)
https [open] – "C:\Program Files\Internet Explorer\iexplore.exe" -nohome (Microsoft Corporation)
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [OneNote.Open] – C:\PROGRA~1\MICROS~2\Office12\ONENOTE.EXE "%L" (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe /separate,/idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /separate,/e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Applications\iexplore.exe [open] – "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] – "C:\Program Files\Internet Explorer\iexplore.exe" (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiSpyware]
"DisableMonitoring" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
"VistaSp1" = Reg Error: Unknown registry data type – File not found

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

========== Authorized Applications List ==========


========== Vista Active Open Ports Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]

========== Vista Active Application Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{6A5DC333-B243-45E8-8FFD-728899A70DA7}" = protocol=17 | dir=in | app=c:\program files\microsoft office\office12\onenote.exe |
"{6E989BB4-9B4C-4201-AB2E-F0DF57998E81}" = protocol=17 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{9341180D-DAF3-46D4-AE43-06ED548A847D}" = protocol=6 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{A91C26E9-9F2A-4750-A903-FB978C2E0309}" = protocol=6 | dir=in | app=c:\program files\microsoft office\office12\onenote.exe |
"{CD3D3097-B0E1-4AA1-BE9C-1033313C8D95}" = protocol=17 | dir=in | app=c:\program files\itunes\itunes.exe |
"{DB5E5774-4DC9-4833-B6F5-E9F67BEC1243}" = protocol=6 | dir=in | app=c:\program files\itunes\itunes.exe |
"TCP Query User{65A6A749-C549-42E1-8ECC-7C91C5CDB9CE}C:\program files\internet explorer\iexplore.exe" = protocol=6 | dir=in | app=c:\program files\internet explorer\iexplore.exe |
"TCP Query User{FD84BA91-8381-4C9B-B9FF-89699B560C4A}C:\programdata\c8d52aa\wec8d5.exe" = protocol=6 | dir=in | app=c:\programdata\c8d52aa\wec8d5.exe |
"UDP Query User{81C67F23-91E6-430F-9872-6719F959CD9E}C:\program files\internet explorer\iexplore.exe" = protocol=17 | dir=in | app=c:\program files\internet explorer\iexplore.exe |
"UDP Query User{AA22C6D0-B75C-4D93-8557-A21195F8C2F4}C:\programdata\c8d52aa\wec8d5.exe" = protocol=17 | dir=in | app=c:\programdata\c8d52aa\wec8d5.exe |

========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{07287123-B8AC-41CE-8346-3D777245C35B}" = Bonjour
"{3215EBED-1D06-42fb-A05C-A752A46FB24C}" = Canon MP530
"{34FF0741-EC67-4C05-AC2A-6D257123DF2E}" = BigFix
"{3AC54383-31D1-4907-961B-B12CBB1D0AE8}" = MobileMe Control Panel
"{3f8b1f23-7c9e-4842-9b00-f9923710db0f}.sdb" = Performance Optimizer
"{3FA365DF-2D68-45ED-8F83-8C8A33E65143}" = Apple Application Support
"{40BF1E83-20EB-11D8-97C5-0009C5020658}" = Power2Go 5.0
"{44C05309-60F4-410B-BC32-31733CFF1A41}" = Microsoft Digital Image Starter Edition 2006 Editor
"{4FE542EB-FF0B-4739-94DD-25C8AE0AB251}" = Microsoft Digital Image Starter Edition 2006 Library
"{65DA2EC9-0642-47E9-AAE2-B5267AA14D75}" = Activation Assistant for the 2007 Microsoft Office suites
"{6956856F-B6B3-4BE0-BA0B-8F495BE32033}" = Apple Software Update
"{6D52C408-B09A-4520-9B18-475B81D393F1}" = Microsoft Works
"{71E4D679-20AB-41E9-A350-D5BF92088FFE}" = Trend Micro AntiVirus
"{76F8CB2B-6516-4E1E-B6F1-AED4ABDB4B0A}_is1" = Spy Sweeper
"{7F3BCF8A-8E02-4659-AF25-F9AB66BD6718}" = Gateway Recovery Center Installer
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{90120000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2007
"{90120000-0016-0409-0000-0000000FF1CE}_HOMESTUDENTR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2007
"{90120000-0018-0409-0000-0000000FF1CE}_HOMESTUDENTR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2007
"{90120000-001B-0409-0000-0000000FF1CE}_HOMESTUDENTR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}_HOMESTUDENTR_{ABDDE972-355B-4AF1-89A8-DA50B7B5C045}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-040C-0000-0000000FF1CE}_HOMESTUDENTR_{F580DDD5-8D37-4998-968E-EBB76BB86787}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007
"{90120000-001F-0C0A-0000-0000000FF1CE}_HOMESTUDENTR_{187308AB-5FA7-4F14-9AB9-D290383A10D9}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}_HOMESTUDENTR_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-00A1-0409-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2007
"{90120000-00A1-0409-0000-0000000FF1CE}_HOMESTUDENTR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007
"{90120000-0115-0409-0000-0000000FF1CE}_HOMESTUDENTR_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{91120000-002F-0000-0000-0000000FF1CE}" = Microsoft Office Home and Student 2007
"{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{0B36C6D6-F5D8-4EAF-BF94-4376A230AD5B}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{3D019598-7B59-447A-80AE-815B703B84FF}" = Security Update for Microsoft Office system 2007 (972581)
"{91B3BEC8-748B-4912-82ED-29D38E140B2A}" = Linkit_eBay
"{9F7FC79B-3059-4264-9450-39EB368E3225}" = Microsoft Digital Image Library 9 - Blocker
"{A429C2AE-EBF1-4F81-A221-1C115CAADDAD}" = QuickTime
"{AADEA55D-C834-4BCB-98A3-4B8D1C18F4EE}" = Apple Mobile Device Support
"{AC76BA86-7AD7-1033-7B44-A81200000003}" = Adobe Reader 8.1.2
"{B2544A03-10D0-4E5E-BA69-0362FFC20D18}" = OGA Notifier 2.0.0048.0
"{BE2CC4A5-2128-4EA2-941D-14F7A6A1AB61}" = Digital Media Reader
"{C1E693A4-B1D5-4DCD-B68D-2087835B7184}" = ScanSoft OmniPage SE 4.0
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{D1A74FBB-CA8D-4CCA-9B89-BAAA436DB178}" = iTunes
"{D2D6B9EB-C6DC-4DAA-B4DE-BB7D9735E7DA}" = Presto! PageManager 7.15.14
"{D6E4E5D6-7693-4BB4-95BA-21F38FAFEE90}" = Safari
"{EE5EEDAF-F932-462B-A2CB-EEBDF819D5F5}" = Gateway Connect
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{FA54AFB1-5745-4389-B8C1-9F7509672ED1}" = iPhone Configuration Utility
"{FF262740-C85A-11D5-BBEC-00D0B740900A}" = PS2 Multimedia Keyboard Driver
"Activation Assistant for the 2007 Microsoft Office suites" = Activation Assistant for the 2007 Microsoft Office suites
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"alotToolbar" = ALOT Toolbar
"AskSBar Uninstall" = Ask Toolbar
"Canon MP530 User Registration" = Canon MP530 User Registration
"CNXT_MODEM_PCI_VEN_14F1&DEV_2F40&SUBSYS_200014F1" = Soft Data Fax Modem with SmartCP
"Easy-PhotoPrint" = Canon Utilities Easy-PhotoPrint
"ERUNT_is1" = ERUNT 1.1j
"HD Tune_is1" = HD Tune 2.54
"HDMI" = Intel® Graphics Media Accelerator Driver
"HijackThis" = HijackThis 2.0.2
"HOMESTUDENTR" = Microsoft Office Home and Student 2007
"InstallShield_{BE2CC4A5-2128-4EA2-941D-14F7A6A1AB61}" = Digital Media Reader
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Money2006b" = Microsoft Money 2006
"MP Navigator 2.2" = Canon MP Navigator 2.2
"PictureItSuiteTrial_v12" = Microsoft Digital Image Starter Edition 2006
"RC_Vista.exe" = RC_Vista.exe

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Enterprise Suite" = Enterprise Suite
"Move Media Player" = Move Media Player

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 12/7/2009 7:06:48 PM | Computer Name = TedHall-PC | Source = Windows Search Service | ID = 3013
Description =

Error - 12/9/2009 5:02:01 PM | Computer Name = TedHall-PC | Source = Windows Search Service | ID = 3013
Description =

Error - 12/9/2009 5:02:03 PM | Computer Name = TedHall-PC | Source = Windows Search Service | ID = 3013
Description =

Error - 12/10/2009 9:37:34 AM | Computer Name = TedHall-PC | Source = Windows Search Service | ID = 3013
Description =

Error - 12/18/2009 12:18:47 AM | Computer Name = TedHall-PC | Source = Windows Search Service | ID = 3013
Description =

Error - 12/18/2009 12:18:48 AM | Computer Name = TedHall-PC | Source = Windows Search Service | ID = 3013
Description =

Error - 12/18/2009 12:18:48 AM | Computer Name = TedHall-PC | Source = Windows Search Service | ID = 3013
Description =

Error - 12/18/2009 12:18:48 AM | Computer Name = TedHall-PC | Source = Windows Search Service | ID = 3013
Description =

Error - 12/18/2009 12:18:49 AM | Computer Name = TedHall-PC | Source = Windows Search Service | ID = 3013
Description =

Error - 12/18/2009 12:18:50 AM | Computer Name = TedHall-PC | Source = Windows Search Service | ID = 3013
Description =

[ Media Center Events ]
Error - 10/2/2007 8:59:54 PM | Computer Name = TedHall-PC | Source = MCUpdate | ID = 0
Description = DownloadPackgeTask.SubTasksComplete: failed downloading package SportsSchedule.

Error - 10/3/2007 7:40:57 PM | Computer Name = TedHall-PC | Source = MCUpdate | ID = 0
Description = DownloadPackgeTask.SubTasksComplete: failed downloading package SportsSchedule.

Error - 10/6/2007 9:59:47 PM | Computer Name = TedHall-PC | Source = MCUpdate | ID = 0
Description = DownloadPackgeTask.SubTasksComplete: failed downloading package SportsSchedule.

Error - 10/24/2007 5:48:20 PM | Computer Name = TedHall-PC | Source = MCUpdate | ID = 0
Description = DownloadPackgeTask.SubTasksComplete: failed downloading package SportsSchedule.

Error - 12/14/2007 12:48:52 AM | Computer Name = TedHall-PC | Source = MCUpdate | ID = 0
Description = DownloadPackgeTask.SubTasksComplete: failed downloading package SportsSchedule.

Error - 12/15/2007 6:56:31 AM | Computer Name = TedHall-PC | Source = MCUpdate | ID = 0
Description = DownloadPackgeTask.SubTasksComplete: failed downloading package SportsSchedule.

Error - 12/18/2007 10:23:45 PM | Computer Name = TedHall-PC | Source = MCUpdate | ID = 0
Description = DownloadPackgeTask.SubTasksComplete: failed downloading package SportsSchedule.

Error - 5/24/2008 6:58:10 PM | Computer Name = TedHall-PC | Source = MCUpdate | ID = 0
Description = DownloadPackgeTask.SubTasksComplete: failed downloading package MCESpotlight.

Error - 8/28/2008 8:02:55 AM | Computer Name = TedHall-PC | Source = MCUpdate | ID = 0
Description = DownloadPackgeTask.SubTasksComplete: failed downloading package SportsSchedule.

Error - 6/10/2009 6:20:42 AM | Computer Name = TedHall-PC | Source = MCUpdate | ID = 0
Description = DownloadPackgeTask.SubTasksComplete: failed downloading package SportsSchedule.

[ OSession Events ]
Error - 8/24/2007 5:43:37 AM | Computer Name = TedHall-PC | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 0, Application Name: Microsoft Office Word, Application Version:
12.0.4518.1014, Microsoft Office Version: 12.0.4518.1014. This session lasted 106
seconds with 60 seconds of active time. This session ended with a crash.

Error - 8/24/2007 8:32:36 AM | Computer Name = TedHall-PC | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 0, Application Name: Microsoft Office Word, Application Version:
12.0.4518.1014, Microsoft Office Version: 12.0.4518.1014. This session lasted 575
seconds with 480 seconds of active time. This session ended with a crash.

Error - 1/25/2008 9:57:04 AM | Computer Name = TedHall-PC | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 1, Application Name: Microsoft Office Excel, Application Version:
12.0.6024.5000, Microsoft Office Version: 12.0.4518.1014. This session lasted 264
seconds with 60 seconds of active time. This session ended with a crash.

Error - 1/25/2008 10:01:14 AM | Computer Name = TedHall-PC | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 1, Application Name: Microsoft Office Excel, Application Version:
12.0.6024.5000, Microsoft Office Version: 12.0.4518.1014. This session lasted 242
seconds with 60 seconds of active time. This session ended with a crash.

[ System Events ]
Error - 12/29/2009 9:50:22 AM | Computer Name = TedHall-PC | Source = HTTP | ID = 15016
Description =

Error - 12/30/2009 9:56:33 AM | Computer Name = TedHall-PC | Source = HTTP | ID = 15016
Description =

Error - 12/30/2009 4:15:29 PM | Computer Name = TedHall-PC | Source = DCOM | ID = 10010
Description =

Error - 12/30/2009 4:17:04 PM | Computer Name = TedHall-PC | Source = HTTP | ID = 15016
Description =

Error - 12/30/2009 4:30:09 PM | Computer Name = TedHall-PC | Source = HTTP | ID = 15016
Description =

Error - 1/1/2010 11:43:35 PM | Computer Name = TedHall-PC | Source = HTTP | ID = 15016
Description =

Error - 1/2/2010 12:35:20 AM | Computer Name = TedHall-PC | Source = HTTP | ID = 15016
Description =

Error - 1/2/2010 2:56:45 AM | Computer Name = TedHall-PC | Source = EventLog | ID = 6008
Description = The previous system shutdown at 12:55:15 AM on 1/2/2010 was unexpected.

Error - 1/2/2010 2:56:47 AM | Computer Name = TedHall-PC | Source = HTTP | ID = 15016
Description =

Error - 1/2/2010 5:47:28 PM | Computer Name = TedHall-PC | Source = HTTP | ID = 15016
Description =


< End of report >

OTL logfile created on: 1/2/2010 4:15:28 PM - Run 1

OTL by OldTimer - Version 3.1.20.1 Folder = C:\Users\Ted Hall\Desktop\computer tools
Windows Vista Home Premium Edition Service Pack 1 (Version = 6.0.6001) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18865)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

2.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 69.00% Memory free
4.00 Gb Paging File | 4.00 Gb Available in Paging File | 84.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 362.81 Gb Total Space | 283.47 Gb Free Space | 78.13% Space Free | Partition Type: NTFS
Drive D: | 9.80 Gb Total Space | 4.43 Gb Free Space | 45.21% Space Free | Partition Type: NTFS
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Drive J: | 488.60 Mb Total Space | 309.41 Mb Free Space | 63.33% Space Free | Partition Type: FAT

Computer Name: TEDHALL-PC
Current User Name: Ted Hall
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal

========== Processes (SafeList) ==========

PRC - C:\Users\Ted Hall\Desktop\computer tools\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\iTunes\iTunesHelper.exe (Apple Inc.)
PRC - C:\Program Files\iPod\bin\iPodService.exe (Apple Inc.)
PRC - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe (Apple Inc.)
PRC - C:\Program Files\Bonjour\mDNSResponder.exe (Apple Inc.)
PRC - C:\Windows\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE (Microsoft Corporation)
PRC - C:\Program Files\Common Files\Motive\McciCMService.exe (Motive Communications, Inc.)
PRC - C:\Windows\System32\WUDFHost.exe (Microsoft Corporation)
PRC - C:\Windows\System32\wbem\unsecapp.exe (Microsoft Corporation)
PRC - C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe (Webroot Software, Inc.)
PRC - C:\Windows\System32\igfxtray.exe (Intel Corporation)
PRC - C:\Windows\System32\igfxsrvc.exe (Intel Corporation)
PRC - C:\Windows\System32\igfxpers.exe (Intel Corporation)
PRC - C:\Windows\System32\hkcmd.exe (Intel Corporation)
PRC - C:\Windows\RtHDVCpl.exe (Realtek Semiconductor)
PRC - C:\Windows\zHotkey.exe ()
PRC - C:\Program Files\ScanSoft\OmniPageSE4.0\OpWareSE4.exe (ScanSoft, Inc.)
PRC - C:\Windows\System32\spool\drivers\w32x86\3\WrtMon.exe ()
PRC - C:\Windows\System32\spool\drivers\w32x86\3\WrtProc.exe ()
PRC - C:\Windows\System32\drivers\XAudio.exe (Conexant Systems, Inc.)


========== Modules (SafeList) ==========

MOD - C:\Users\Ted Hall\Desktop\computer tools\OTL.exe (OldTimer Tools)
MOD - C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6001.18000_none_5cdbaa5a083979cc\comctl32.dll (Microsoft Corporation)


========== Win32 Services (SafeList) ==========

SRV - (0222221186118406mcinstcleanup) McAfee Application Installer Cleanup (0222221186118406) – File not found
SRV - (iPod Service) – C:\Program Files\iPod\bin\iPodService.exe (Apple Inc.)
SRV - (Apple Mobile Device) – C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe (Apple Inc.)
SRV - (Bonjour Service) – C:\Program Files\Bonjour\mDNSResponder.exe (Apple Inc.)
SRV - (odserv) – C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE (Microsoft Corporation)
SRV - (McciCMService) – C:\Program Files\Common Files\Motive\McciCMService.exe (Motive Communications, Inc.)
SRV - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV - (WebrootSpySweeperService) – C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe (Webroot Software, Inc.)
SRV - (tavsvc) – C:\Program Files\Trend Micro\AntiVirus 2007\tavsvc.exe (Trend Micro Inc.)
SRV - (tmproxy) – C:\Program Files\Trend Micro\AntiVirus 2007\components\TmProxy.exe (Trend Micro Inc.)
SRV - (ehstart) – C:\Windows\ehome\ehstart.dll (Microsoft Corporation)
SRV - (ose) – C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE (Microsoft Corporation)
SRV - (XAudioService) – C:\Windows\System32\drivers\XAudio.exe (Conexant Systems, Inc.)


========== Driver Services (SafeList) ==========

DRV - (GEARAspiWDM) – C:\Windows\System32\drivers\GEARAspiWDM.sys (GEAR Software Inc.)
DRV - (tmxpflt) – C:\Windows\System32\drivers\tmxpflt.sys (Trend Micro Inc.)
DRV - (tmpreflt) – C:\Windows\System32\drivers\tmpreflt.sys (Trend Micro Inc.)
DRV - (vsapint) – C:\Windows\System32\drivers\vsapint.sys (Trend Micro Inc.)
DRV - (SSKBFD) – C:\Windows\System32\drivers\sskbfd.sys (Webroot Software Inc (www.webroot.com))
DRV - (SSIDRV) – C:\Windows\SYSTEM32\Drivers\SSIDRV.SYS (Webroot Software Inc (www.webroot.com))
DRV - (SSHRMD) – C:\Windows\SYSTEM32\Drivers\SSHRMD.SYS (Webroot Software Inc (www.webroot.com))
DRV - (SSFS0BB9) – C:\Windows\SYSTEM32\Drivers\SSFS0BB9.SYS (Webroot Software Inc (www.webroot.com))
DRV - (igfx) – C:\Windows\System32\drivers\igdkmd32.sys (Intel Corporation)
DRV - (ialm) – C:\Windows\System32\drivers\igdkmd32.sys (Intel Corporation)
DRV - (tmcomm) – C:\Windows\System32\drivers\tmcomm.sys (Trend Micro Inc.)
DRV - (IntcAzAudAddService) Service for Realtek HD Audio (WDM) – C:\Windows\System32\drivers\RTKVHDA.sys (Realtek Semiconductor Corp.)
DRV - (HSF_DPV) – C:\Windows\System32\drivers\HSX_DPV.sys (Conexant Systems, Inc.)
DRV - (HSXHWBS2) – C:\Windows\System32\drivers\HSXHWBS2.sys (Conexant Systems, Inc.)
DRV - (winachsf) – C:\Windows\System32\drivers\HSX_CNXT.sys (Conexant Systems, Inc.)
DRV - (ql2300) – C:\Windows\system32\drivers\ql2300.sys (QLogic Corporation)
DRV - (adp94xx) – C:\Windows\system32\drivers\adp94xx.sys (Adaptec, Inc.)
DRV - (elxstor) – C:\Windows\system32\drivers\elxstor.sys (Emulex)
DRV - (adpahci) – C:\Windows\system32\drivers\adpahci.sys (Adaptec, Inc.)
DRV - (uliahci) – C:\Windows\system32\drivers\uliahci.sys (ULi Electronics Inc.)
DRV - (iaStorV) – C:\Windows\system32\drivers\iastorv.sys (Intel Corporation)
DRV - (adpu320) – C:\Windows\system32\drivers\adpu320.sys (Adaptec, Inc.)
DRV - (ulsata2) – C:\Windows\system32\drivers\ulsata2.sys (Promise Technology, Inc.)
DRV - (vsmraid) – C:\Windows\system32\drivers\vsmraid.sys (VIA Technologies Inc.,Ltd)
DRV - (ql40xx) – C:\Windows\system32\drivers\ql40xx.sys (QLogic Corporation)
DRV - (UlSata) – C:\Windows\system32\drivers\ulsata.sys (Promise Technology, Inc.)
DRV - (adpu160m) – C:\Windows\system32\drivers\adpu160m.sys (Adaptec, Inc.)
DRV - (nvraid) – C:\Windows\system32\drivers\nvraid.sys (NVIDIA Corporation)
DRV - (nfrd960) – C:\Windows\system32\drivers\nfrd960.sys (IBM Corporation)
DRV - (iirsp) – C:\Windows\system32\drivers\iirsp.sys (Intel Corp./ICP vortex GmbH)
DRV - (SiSRaid4) – C:\Windows\system32\drivers\sisraid4.sys (Silicon Integrated Systems)
DRV - (nvstor) – C:\Windows\system32\drivers\nvstor.sys (NVIDIA Corporation)
DRV - (aic78xx) – C:\Windows\system32\drivers\djsvs.sys (Adaptec, Inc.)
DRV - (arcsas) – C:\Windows\system32\drivers\arcsas.sys (Adaptec, Inc.)
DRV - (LSI_SCSI) – C:\Windows\system32\drivers\lsi_scsi.sys (LSI Logic)
DRV - (SiSRaid2) – C:\Windows\system32\drivers\sisraid2.sys (Silicon Integrated Systems Corp.)
DRV - (HpCISSs) – C:\Windows\system32\drivers\hpcisss.sys (Hewlett-Packard Company)
DRV - (arc) – C:\Windows\system32\drivers\arc.sys (Adaptec, Inc.)
DRV - (iteraid) – C:\Windows\system32\drivers\iteraid.sys (Integrated Technology Express, Inc.)
DRV - (iteatapi) – C:\Windows\system32\drivers\iteatapi.sys (Integrated Technology Express, Inc.)
DRV - (LSI_SAS) – C:\Windows\system32\drivers\lsi_sas.sys (LSI Logic)
DRV - (Symc8xx) – C:\Windows\system32\drivers\symc8xx.sys (LSI Logic)
DRV - (LSI_FC) – C:\Windows\system32\drivers\lsi_fc.sys (LSI Logic)
DRV - (Sym_u3) – C:\Windows\system32\drivers\sym_u3.sys (LSI Logic)
DRV - (Mraid35x) – C:\Windows\system32\drivers\mraid35x.sys (LSI Logic Corporation)
DRV - (Sym_hi) – C:\Windows\system32\drivers\sym_hi.sys (LSI Logic)
DRV - (megasas) – C:\Windows\system32\drivers\megasas.sys (LSI Logic Corporation)
DRV - (viaide) – C:\Windows\system32\drivers\viaide.sys (VIA Technologies, Inc.)
DRV - (cmdide) – C:\Windows\system32\drivers\cmdide.sys (CMD Technology, Inc.)
DRV - (aliide) – C:\Windows\system32\drivers\aliide.sys (Acer Laboratories Inc.)
DRV - (Brserid) Brother MFC Serial Port Interface Driver (WDM) – C:\Windows\system32\drivers\brserid.sys (Brother Industries Ltd.)
DRV - (BrUsbSer) – C:\Windows\system32\drivers\brusbser.sys (Brother Industries Ltd.)
DRV - (BrFiltUp) – C:\Windows\system32\drivers\brfiltup.sys (Brother Industries, Ltd.)
DRV - (BrFiltLo) – C:\Windows\system32\drivers\brfiltlo.sys (Brother Industries, Ltd.)
DRV - (BrSerWdm) – C:\Windows\system32\drivers\brserwdm.sys (Brother Industries Ltd.)
DRV - (BrUsbMdm) – C:\Windows\system32\drivers\brusbmdm.sys (Brother Industries Ltd.)
DRV - (ntrigdigi) – C:\Windows\system32\drivers\ntrigdigi.sys (N-trig Innovative Technologies)
DRV - (ac97intc) Intel® 82801 Audio Driver Install Service (WDM) – C:\Windows\System32\drivers\ac97intc.sys (Intel Corporation)
DRV - (NETw2v32) Intel® – C:\Windows\System32\drivers\NETw2v32.sys (Intel® Corporation)
DRV - (RTL8023xp) – C:\Windows\System32\drivers\Rtnicxp.sys (Realtek Semiconductor Corporation )
DRV - (E1G60) Intel® – C:\Windows\System32\drivers\E1G60I32.sys (Intel Corporation)
DRV - (bcm4sbxp) – C:\Windows\System32\drivers\bcm4sbxp.sys (Broadcom Corporation)
DRV - (secdrv) – C:\Windows\System32\drivers\secdrv.sys (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.)
DRV - (XAudio) – C:\Windows\System32\drivers\XAudio.sys (Conexant Systems, Inc.)
DRV - (mdmxsdk) – C:\Windows\System32\drivers\mdmxsdk.sys (Conexant)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.gateway.com/g/startpage.html?Ch…TP&M=GT5468
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.gateway.com/g/startpage.html?Ch…TP&M=GT5468
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.gateway.com/g/sidepanel.html?Ch…TP&M=GT5468

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchDefaultBranded = 1
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/ig/gatewayr?hl=en
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKCU\..\URLSearchHook: {0579B4B6-0293-4d73-B02D-5EBB0BA0F0A2} - C:\Program Files\AskSBar\SrchAstt\1.bin\A2SRCHAS.DLL (Ask.com)
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = ;*.local



O1 HOSTS File: (761 bytes) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2 - BHO: (Ask Search Assistant BHO) - {0579B4B1-0293-4d73-B02D-5EBB0BA0F0A2} - C:\Program Files\AskSBar\SrchAstt\1.bin\A2SRCHAS.DLL (Ask.com)
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (ALOT Toolbar BHO) - {14CEEAFF-96DD-4101-AE37-D5ECDC23C3F6} - C:\Program Files\alot\bin\alot.dll (Miva)
O2 - BHO: (Ask Toolbar BHO) - {F0D4B231-DA4B-4daf-81E4-DFEE4931A4AA} - C:\Program Files\AskSBar\bar\1.bin\ASKSBAR.DLL (Ask.com)
O3 - HKLM\..\Toolbar: (ALOT Toolbar) - {5AA2BA46-9913-4dc7-9620-69AB0FA17AE7} - C:\Program Files\alot\bin\alot.dll (Miva)
O3 - HKLM\..\Toolbar: (Ask Toolbar) - {F0D4B239-DA4B-4daf-81E4-DFEE4931A4AA} - C:\Program Files\AskSBar\bar\1.bin\ASKSBAR.DLL (Ask.com)
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (Ask Toolbar) - {F0D4B239-DA4B-4DAF-81E4-DFEE4931A4AA} - C:\Program Files\AskSBar\bar\1.bin\ASKSBAR.DLL (Ask.com)
O4 - HKLM..\Run: [Adobe Reader Speed Launcher] C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe (Apple Inc.)
O4 - HKLM..\Run: [CHotkey] C:\Windows\zHotkey.exe ()
O4 - HKLM..\Run: [HotKeysCmds] C:\Windows\System32\hkcmd.exe (Intel Corporation)
O4 - HKLM..\Run: [IgfxTray] C:\Windows\System32\igfxtray.exe (Intel Corporation)
O4 - HKLM..\Run: [iTunesHelper] C:\Program Files\iTunes\iTunesHelper.exe (Apple Inc.)
O4 - HKLM..\Run: [Malwarebytes Anti-Malware (reboot)] C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe (Malwarebytes Corporation)
O4 - HKLM..\Run: [OpwareSE4] C:\Program Files\ScanSoft\OmniPageSE4.0\OpwareSE4.exe (ScanSoft, Inc.)
O4 - HKLM..\Run: [Persistence] C:\Windows\System32\igfxpers.exe (Intel Corporation)
O4 - HKLM..\Run: [QuickTime Task] C:\Program Files\QuickTime\QTTask.exe (Apple Inc.)
O4 - HKLM..\Run: [RtHDVCpl] C:\Windows\RtHDVCpl.exe (Realtek Semiconductor)
O4 - HKLM..\Run: [ShowWnd] C:\Windows\ShowWnd.exe ()
O4 - HKLM..\Run: [SpySweeper] C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe (Webroot Software, Inc.)
O4 - HKLM..\Run: [SSBkgdUpdate] C:\Program Files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe (Nuance Communications, Inc.)
O4 - HKLM..\Run: [Trend Micro AntiVirus 2007] C:\Program Files\Trend Micro\AntiVirus 2007\tavui.exe (Trend Micro Inc.)
O4 - HKLM..\Run: [WrtMon.exe] C:\Windows\System32\spool\drivers\w32x86\3\WrtMon.exe ()
O4 - HKCU..\Run: [Magentic] C:\PROGRA~1\Magentic\bin\Magentic.exe File not found
O4 - HKCU..\Run: [RunSpySweeperScheduleAtStartup] C:\Windows\System32\msfeedssync.exe (Microsoft Corporation)
O4 - HKLM..\RunOnce: [Launcher] C:\Windows\SMINST\Launcher.exe (soft thinks)
O4 - Startup: C:\Users\Ted Hall\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OneNote 2007 Screen Clipper and Launcher.lnk = C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE (Microsoft Corporation)
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDesktopCleanupWizard = 1
O8 - Extra context menu item: E&xport to Microsoft Excel - C:\Program Files\Microsoft Office\Office12\EXCEL.EXE (Microsoft Corporation)
O9 - Extra Button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Program Files\Microsoft Office\Office12\REFIEBAR.DLL (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000005 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\Windows\System32\TmLsp.dll (Trend Micro Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\Windows\System32\TmLsp.dll (Trend Micro Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\Windows\System32\TmLsp.dll (Trend Micro Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - C:\Windows\System32\TmLsp.dll (Trend Micro Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - C:\Windows\System32\TmLsp.dll (Trend Micro Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000006 - C:\Windows\System32\TmLsp.dll (Trend Micro Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000017 - C:\Windows\System32\TmLsp.dll (Trend Micro Inc.)
O13 - gopher Prefix: missing
O15 - HKCU\..Trusted Domains: 1 domain(s) and sub-domain(s) not assigned to a zone.
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} http://a1540.g.akamai.net/7/1540/52/200707…ex/qtplugin.cab (QuickTime Object)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.254 192.168.1.254
O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Program Files\Common Files\microsoft shared\Help\hxds.dll (Microsoft Corporation)
O18 - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\microsoft shared\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\igfxcui: DllName - igfxdev.dll - C:\Windows\System32\igfxdev.dll (Intel Corporation)
O20 - Winlogon\Notify\WRNotifier: DllName - WRLogonNTF.dll - C:\Windows\System32\WRLogonNtf.dll (Webroot Software, Inc.)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006/09/18 15:43:36 | 00,000,024 | —- | M] () - C:\autoexec.bat – [ NTFS ]
O32 - AutoRun File - [2004/04/30 18:01:00 | 00,000,053 | -HS- | M] () - D:\Autorun.inf – [ NTFS ]
O32 - AutoRun File - [2009/08/14 11:43:06 | 00,000,000 | RHSD | M] - J:\autorun.inf – [ FAT ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - comfile [open] – "%1" %*
O35 - exefile [open] – "%1" %*

========== Files/Folders - Created Within 30 Days ==========

[2010/01/01 23:45:38 | 00,000,000 | —D | C] – C:\Windows\ERDNT
[2010/01/01 23:44:53 | 00,000,000 | —D | C] – C:\Program Files\ERUNT
[2010/01/01 23:40:05 | 00,000,000 | —D | C] – C:\Users\Ted Hall\Desktop\computer tools
[2010/01/01 22:52:55 | 00,000,000 | —D | C] – C:\Program Files\HD Tune
[2010/01/01 22:35:39 | 00,000,000 | —D | C] – C:\Users\Ted Hall\AppData\Local\Apple Computer
[2010/01/01 22:27:57 | 00,000,000 | —D | C] – C:\Users\Ted Hall\AppData\Roaming\Malwarebytes
[2010/01/01 22:27:54 | 00,038,224 | —- | C] (Malwarebytes Corporation) – C:\Windows\System32\drivers\mbamswissarmy.sys
[2010/01/01 22:27:52 | 00,019,160 | —- | C] (Malwarebytes Corporation) – C:\Windows\System32\drivers\mbam.sys
[2010/01/01 22:27:52 | 00,000,000 | —D | C] – C:\Program Files\Malwarebytes' Anti-Malware
[2010/01/01 22:27:52 | 00,000,000 | —D | C] – C:\ProgramData\Malwarebytes
[2009/12/30 14:11:06 | 01,638,912 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mshtml.tlb
[2009/12/30 14:11:06 | 00,594,432 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msfeeds.dll
[2009/12/30 14:11:06 | 00,184,320 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iepeers.dll
[2009/12/30 14:11:06 | 00,025,600 | —- | C] (Microsoft Corporation) – C:\Windows\System32\jsproxy.dll
[2009/12/30 14:11:05 | 00,164,352 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieui.dll
[2009/12/30 14:11:05 | 00,071,680 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iesetup.dll
[2009/12/30 14:11:05 | 00,055,296 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msfeedsbs.dll
[2009/12/30 14:11:04 | 00,055,808 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iernonce.dll
[2009/12/30 14:11:03 | 01,469,440 | —- | C] (Microsoft Corporation) – C:\Windows\System32\inetcpl.cpl
[2009/12/30 14:11:03 | 00,387,584 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iedkcs32.dll
[2009/12/30 14:11:03 | 00,173,056 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ie4uinit.exe
[2009/12/30 14:11:03 | 00,133,632 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieUnatt.exe
[2009/12/30 14:11:03 | 00,109,056 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iesysprep.dll
[2009/12/30 14:11:03 | 00,013,312 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msfeedssync.exe
[2009/12/30 14:09:41 | 00,072,704 | —- | C] (Microsoft Corporation) – C:\Windows\System32\admparse.dll
[2009/12/30 14:09:41 | 00,048,128 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mshtmler.dll
[2009/12/30 14:09:40 | 00,348,160 | —- | C] (Microsoft Corporation) – C:\Windows\System32\dxtmsft.dll
[2009/12/30 14:09:40 | 00,216,064 | —- | C] (Microsoft Corporation) – C:\Windows\System32\dxtrans.dll
[2009/12/30 14:09:40 | 00,156,160 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msls31.dll
[2009/12/30 14:09:40 | 00,125,952 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieakeng.dll
[2009/12/30 14:09:40 | 00,034,816 | —- | C] (Microsoft Corporation) – C:\Windows\System32\imgutil.dll
[2009/12/30 14:09:40 | 00,018,944 | —- | C] (Microsoft Corporation) – C:\Windows\System32\corpol.dll
[2009/12/30 14:09:39 | 00,229,376 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieaksie.dll
[2009/12/30 14:09:39 | 00,193,536 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msrating.dll
[2009/12/30 14:09:39 | 00,094,720 | —- | C] (Microsoft Corporation) – C:\Windows\System32\inseng.dll
[2009/12/30 14:09:39 | 00,043,008 | —- | C] (Microsoft Corporation) – C:\Windows\System32\licmgr10.dll
[2009/12/30 14:09:38 | 00,611,840 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mstime.dll
[2009/12/30 14:09:38 | 00,208,384 | —- | C] (Microsoft Corporation) – C:\Windows\System32\WinFXDocObj.exe
[2009/12/30 14:09:38 | 00,163,840 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieakui.dll
[2009/12/30 14:09:38 | 00,128,512 | —- | C] (Microsoft Corporation) – C:\Windows\System32\advpack.dll
[2009/12/30 14:09:38 | 00,066,560 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wextract.exe
[2009/12/30 14:09:38 | 00,046,592 | —- | C] (Microsoft Corporation) – C:\Windows\System32\pngfilt.dll
[2009/12/30 14:09:37 | 00,445,952 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieapfltr.dll
[2009/12/30 14:09:37 | 00,420,352 | —- | C] (Microsoft Corporation) – C:\Windows\System32\vbscript.dll
[2009/12/30 14:09:36 | 00,726,528 | —- | C] (Microsoft Corporation) – C:\Windows\System32\jscript.dll
[2009/12/30 14:09:36 | 00,105,984 | —- | C] (Microsoft Corporation) – C:\Windows\System32\url.dll
[2009/12/30 14:09:35 | 03,698,584 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieapfltr.dat
[2009/12/30 14:09:35 | 00,385,024 | —- | C] (Microsoft Corporation) – C:\Windows\System32\html.iec
[2009/12/30 14:09:35 | 00,169,472 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iexpress.exe
[2009/12/30 14:09:34 | 00,109,568 | —- | C] (Microsoft Corporation) – C:\Windows\System32\PDMSetup.exe
[2009/12/30 14:09:34 | 00,107,520 | —- | C] (Microsoft Corporation) – C:\Windows\System32\RegisterIEPKEYs.exe
[2009/12/30 14:09:34 | 00,107,008 | —- | C] (Microsoft Corporation) – C:\Windows\System32\SetIEInstalledDate.exe
[2009/12/30 14:09:34 | 00,103,936 | —- | C] (Microsoft Corporation) – C:\Windows\System32\SetDepNx.exe
[2009/12/25 12:39:37 | 00,000,000 | -HSD | C] – C:\ProgramData\WEXGXALUBHS
[2009/12/25 12:39:13 | 00,000,000 | -HSD | C] – C:\ProgramData\c8d52aa
[2009/12/12 08:05:59 | 00,024,064 | —- | C] (Microsoft Corporation) – C:\Windows\System32\nshhttp.dll
[2009/12/12 08:05:54 | 00,031,232 | —- | C] (Microsoft Corporation) – C:\Windows\System32\httpapi.dll
[2009/12/09 18:47:55 | 00,281,600 | —- | C] (Microsoft Corporation) – C:\Windows\System32\raschap.dll
[2009/12/09 18:47:55 | 00,244,224 | —- | C] (Microsoft Corporation) – C:\Windows\System32\rastls.dll
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2010/01/02 16:15:16 | 02,621,440 | -HS- | M] () – C:\Users\Ted Hall\ntuser.dat
[2010/01/02 16:13:23 | 00,690,960 | —- | M] () – C:\Windows\System32\PerfStringBackup.INI
[2010/01/02 16:13:23 | 00,595,446 | —- | M] () – C:\Windows\System32\perfh009.dat
[2010/01/02 16:13:23 | 00,101,144 | —- | M] () – C:\Windows\System32\perfc009.dat
[2010/01/02 15:48:12 | 00,000,424 | -H– | M] () – C:\Windows\tasks\User_Feed_Synchronization-{BFC14688-45C9-4E2F-8D4C-EB7F3F59BEC8}.job
[2010/01/02 15:47:34 | 00,003,168 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2010/01/02 15:47:33 | 00,003,168 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2010/01/02 15:47:28 | 00,000,006 | -H– | M] () – C:\Windows\tasks\SA.DAT
[2010/01/02 15:47:23 | 00,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2010/01/02 15:47:20 | 21,386,28096 | -HS- | M] () – C:\hiberfil.sys
[2010/01/02 01:09:54 | 00,524,288 | -HS- | M] () – C:\Users\Ted Hall\ntuser.dat{3856319d-4ebf-11dd-8551-001bb9791bd7}.TMContainer00000000000000000001.regtrans-ms
[2010/01/02 01:09:54 | 00,065,536 | -HS- | M] () – C:\Users\Ted Hall\ntuser.dat{3856319d-4ebf-11dd-8551-001bb9791bd7}.TM.blf
[2010/01/02 01:09:51 | 03,592,682 | -H– | M] () – C:\Users\Ted Hall\AppData\Local\IconCache.db
[2010/01/02 00:44:08 | 00,359,929 | —- | M] () – C:\Users\Ted Hall\Desktop\dds.scr
[2010/01/01 22:27:56 | 00,000,818 | —- | M] () – C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2010/01/01 21:52:45 | 00,000,000 | -H– | M] () – C:\Windows\System32\drivers\Msft_User_WpdFs_01_00_00.Wdf
[2009/12/30 15:38:28 | 00,002,585 | —- | M] () – C:\Users\Ted Hall\Desktop\Microsoft Office Excel 2007.lnk
[2009/12/30 15:16:04 | 00,000,104 | —- | M] () – C:\Users\Ted Hall\Desktop\Recycle Bin - Shortcut.lnk
[2009/12/30 14:55:24 | 00,038,224 | —- | M] (Malwarebytes Corporation) – C:\Windows\System32\drivers\mbamswissarmy.sys
[2009/12/30 14:54:58 | 00,019,160 | —- | M] (Malwarebytes Corporation) – C:\Windows\System32\drivers\mbam.sys
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]

========== Files Created - No Company Name ==========

[2010/01/02 00:46:47 | 00,359,929 | —- | C] () – C:\Users\Ted Hall\Desktop\dds.scr
[2010/01/01 22:27:56 | 00,000,818 | —- | C] () – C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2010/01/01 21:52:45 | 00,000,000 | -H– | C] () – C:\Windows\System32\drivers\Msft_User_WpdFs_01_00_00.Wdf
[2009/12/30 15:16:04 | 00,000,104 | —- | C] () – C:\Users\Ted Hall\Desktop\Recycle Bin - Shortcut.lnk
[2009/12/30 14:11:03 | 00,057,667 | —- | C] () – C:\Windows\System32\ieuinit.inf
[2009/08/03 14:07:42 | 00,403,816 | —- | C] () – C:\Windows\System32\OGACheckControl.dll
[2008/07/08 21:17:52 | 00,000,000 | —- | C] () – C:\Users\Ted Hall\AppData\Roaming\wklnhst.dat
[2008/01/02 16:57:36 | 00,147,456 | —- | C] () – C:\Windows\System32\igfxCoIn_v1409.dll
[2007/08/05 12:16:38 | 00,006,144 | —- | C] () – C:\Users\Ted Hall\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2007/08/04 22:36:50 | 00,040,960 | —- | C] () – C:\Windows\System32\IPPCPUID.DLL
[2007/08/04 22:34:44 | 00,011,776 | —- | C] () – C:\Windows\System32\pmsbfn32.dll
[2007/08/04 22:29:45 | 00,000,416 | —- | C] () – C:\Windows\MAXLINK.INI
[2007/08/03 11:40:44 | 00,026,480 | —- | C] () – C:\Windows\System32\wrlzma.dll
[2007/05/21 12:24:28 | 00,204,800 | —- | C] () – C:\Windows\System32\igfxCoIn_v1227.dll
[2007/05/21 11:41:05 | 00,532,544 | —- | C] () – C:\Windows\PIC.dll
[2007/05/21 11:41:05 | 00,024,576 | —- | C] () – C:\Windows\HKNTDLL.dll
[2006/11/22 15:16:18 | 00,003,612 | —- | C] () – C:\Windows\ReaderString.ini
[2006/11/21 11:50:06 | 00,000,037 | —- | C] () – C:\Windows\sunkist.ini
[2006/11/02 06:35:32 | 00,005,632 | —- | C] () – C:\Windows\System32\sysprepMCE.dll
[2006/11/02 01:40:29 | 00,013,750 | —- | C] () – C:\Windows\System32\pacerprf.ini

========== LOP Check ==========

[2009/07/15 06:20:44 | 00,000,000 | —D | M] – C:\Users\Ted Hall\AppData\Roaming\Canon
[2007/09/05 07:51:52 | 00,000,000 | —D | M] – C:\Users\Ted Hall\AppData\Roaming\NewSoft
[2007/08/26 18:29:32 | 00,000,000 | —D | M] – C:\Users\Ted Hall\AppData\Roaming\SampleView
[2007/08/04 22:29:31 | 00,000,000 | —D | M] – C:\Users\Ted Hall\AppData\Roaming\ScanSoft
[2008/07/08 21:17:53 | 00,000,000 | —D | M] – C:\Users\Ted Hall\AppData\Roaming\Template
[2009/11/26 08:25:55 | 00,000,000 | —D | M] – C:\Users\Ted Hall\AppData\Roaming\Wal-Mart Digital Photo Viewer
[2010/01/02 01:09:56 | 00,032,542 | —- | M] () – C:\Windows\Tasks\SCHEDLGU.TXT
[2010/01/02 15:48:12 | 00,000,424 | -H– | M] () – C:\Windows\Tasks\User_Feed_Synchronization-{BFC14688-45C9-4E2F-8D4C-EB7F3F59BEC8}.job

========== Purity Check ==========


< End of report >
Hi Jcatsmom,

If you don't want the toolbars you can uninstall them

Click on the Start button > Control Panel

Depending on your setings, either
  • click on the Uninstall a program option under the Programs category.
  • If you are using the Classic View of the Control Panel, then you would double-click on the Programs and Features icon instead.
Uninstall the following program

ALOT Toolbar
Ask Toolbar


Please download SystemLook from one of the links below and save it to your Desktop.
Download Mirror #1
Download Mirror #2

  • Right click SystemLook.exe and choose "Run as Adminstrator" to run it.
  • Copy the content of the following codebox into the main textfield
  • Do not copy the word CODE , please note the script starts with the :
    :dir
    C:\ProgramData\WEXGXALUBHS
    C:\ProgramData\c8d52aa
  • Click the Look button to start the scan.
  • When finished, a notepad window will open with the results of the scan. Please post this log in your next reply.
Note: The log can also be found on your Desktop entitled SystemLook.txt

Please post back with
  • SystemLook log

Any problems?

Thanks
Oldman960- here are the system look and latest HJT. I wanted to include a screenshot from Windows Defender showing blocked start-up programs that comes up every time the machine is started, but wasn't able to paste it into this message. Thanks! -Jcatsmom

SystemLook v1.0 by jpshortstuff (29.08.09)
Log created at 21:46 on 02/01/2010 by Ted Hall (Administrator - Elevation successful)

========== dir ==========

C:\ProgramData\WEXGXALUBHS - Parameters: "(none)"

—Files—
WEMDWBS.cfg –ahs- 12774 bytes [18:39 25/12/2009] [03:46 02/01/2010]

—Folders—
None found.

C:\ProgramData\c8d52aa - Parameters: "(none)"

—Files—
WES.ico –a— 4286 bytes [18:39 25/12/2009] [18:39 25/12/2009]
WinESuite.exe –a— 1945088 bytes [22:03 25/12/2009] [22:03 25/12/2009]

—Folders—
BackUp d—– [18:39 25/12/2009]
Quarantine Items d—– [18:39 25/12/2009]
WESSys d—– [18:39 25/12/2009]

-=End Of File=-

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 9:47:42 PM, on 1/2/2010
Platform: Windows Vista SP1 (WinNT 6.00.1905)
MSIE: Internet Explorer v8.00 (8.00.6001.18865)
Boot mode: Normal

Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\taskeng.exe
C:\Program Files\Trend Micro\AntiVirus 2007\tavui.exe
C:\Windows\RtHDVCpl.exe
C:\Windows\zHotkey.exe
C:\Program Files\ScanSoft\OmniPageSE4.0\OpWareSE4.exe
C:\Windows\System32\spool\drivers\w32x86\3\WrtMon.exe
C:\Windows\System32\igfxtray.exe
C:\Windows\System32\hkcmd.exe
C:\Windows\System32\igfxpers.exe
C:\Windows\system32\igfxsrvc.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Windows\ehome\ehtray.exe
C:\Windows\System32\spool\drivers\w32x86\3\WrtProc.exe
C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
C:\Windows\ehome\ehmsas.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Windows\System32\mobsync.exe
C:\Windows\system32\wuauclt.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.gateway.com/g/startpage.html?Ch…TP&M=GT5468
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.gateway.com/g/startpage.html?Ch…TP&M=GT5468
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.gateway.com/g/sidepanel.html?Ch…TP&M=GT5468
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O1 - Hosts: ::1 localhost
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
O4 - HKLM\..\Run: [CHotkey] zHotkey.exe
O4 - HKLM\..\Run: [ShowWnd] ShowWnd.exe
O4 - HKLM\..\Run: [Trend Micro AntiVirus 2007] "C:\Program Files\Trend Micro\AntiVirus 2007\tavui.exe" -1 –delay 200
O4 - HKLM\..\Run: [SSBkgdUpdate] "C:\Program Files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" -Embedding -boot
O4 - HKLM\..\Run: [OpwareSE4] "C:\Program Files\ScanSoft\OmniPageSE4.0\OpwareSE4.exe"
O4 - HKLM\..\Run: [WrtMon.exe] C:\Windows\system32\spool\drivers\w32x86\3\WrtMon.exe
O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [AppleSyncNotifier] "C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [Malwarebytes Anti-Malware (reboot)] "C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe" /runcleanupscript
O4 - HKLM\..\Run: [SpySweeper] C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe /startintray
O4 - HKLM\..\RunOnce: [Launcher] %WINDIR%\SMINST\launcher.exe
O4 - HKCU\..\Run: [Windows Sidebar] "C:\Program Files\Windows Sidebar\Sidebar.exe" /autorun
O4 - HKCU\..\Run: [Sidebar] "C:\Program Files\Windows Sidebar\sidebar.exe" /autoRun
O4 - HKCU\..\Run: [RunSpySweeperScheduleAtStartup] "C:\Windows\system32\msfeedssync.exe" /ScheduleSweep=User_Feed_Synchronization-{BFC14688-45C9-4E2F-8D4C-EB7F3F59BEC8}
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [Magentic] "C:\PROGRA~1\Magentic\bin\Magentic.exe" /c
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O4 - Startup: OneNote 2007 Screen Clipper and Launcher.lnk = C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O10 - Unknown file in Winsock LSP: c:\windows\system32\tmlsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\tmlsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\tmlsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\tmlsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\tmlsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\tmlsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\tmlsp.dll
O13 - Gopher Prefix:
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - http://a1540.g.akamai.net/7/1540/52/200707…ex/qtplugin.cab
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: McciCMService - Motive Communications, Inc. - C:\Program Files\Common Files\Motive\McciCMService.exe
O23 - Service: Trend Micro AntiVirus Protection Service (tavsvc) - Trend Micro Inc. - C:\Program Files\Trend Micro\AntiVirus 2007\tavsvc.exe
O23 - Service: Trend Micro Proxy Service (tmproxy) - Trend Micro Inc. - C:\Program Files\Trend Micro\AntiVirus 2007\Components\tmproxy.exe
O23 - Service: Webroot Spy Sweeper Engine (WebrootSpySweeperService) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe

–
End of file - 6899 bytes
Hi Jcatsmom,

Save the screenshot as a jpeg and attach it.

I see you have an antivirus program installed. :thumbup:

Those folders are part of the infection you had.

Next, Right click on OTL.exe and chose Run as Administrator to run it
  • Under the Custom Scans/Fixes box at the bottom, paste in the following
  • Do Not copy the word CODE
  • please note the fix starts with the :
:Files
C:\ProgramData\WEXGXALUBHS
C:\ProgramData\c8d52aa

:Commands
[emptytemp]

Then click the Run Fix button at the top
  • Let the program run unhindered
  • Please save the resulting log to be posted in your next reply.

Please post back with
  • OTL fix log

Thanks
Oldman960- Actually, I need to install a new version of the Antivirus program. The subscription actually ran out August 2008. So many people seem to get in trouble with not renewing initially installed Antivirus/Antispyware. I am attaching the screenshot as requested. I didn't want to make any attachments without permission. I am also including the OTL log. All processes killed ========== FILES ========== C:\ProgramData\WEXGXALUBHS folder moved successfully. C:\ProgramData\c8d52aa\WESSys folder moved successfully. C:\ProgramData\c8d52aa\Quarantine Items folder moved successfully. C:\ProgramData\c8d52aa\BackUp folder moved successfully. C:\ProgramData\c8d52aa folder moved successfully. ========== COMMANDS ========== [EMPTYTEMP] User: All Users User: Default ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 33170 bytes User: Default User ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes User: Public User: Ted Hall ->Temp folder emptied: 32305 bytes ->Temporary Internet Files folder emptied: 521405005 bytes ->Java cache emptied: 450627 bytes ->Apple Safari cache emptied: 45564 bytes %systemdrive% .tmp files removed: 0 bytes %systemroot% .tmp files removed: 0 bytes %systemroot%\System32 .tmp files removed: 0 bytes Windows Temp folder emptied: 8092 bytes RecycleBin emptied: 7308488 bytes Total Files Cleaned = 505.00 mb OTL by OldTimer - Version 3.1.20.1 log created on 01032010_105635 Files\Folders moved on Reboot… Registry entries deleted on Reboot…
Hi Jcatsmom,

If you are concerned about magentic.exe, it's legitamate. Looks like Windows Defender is flagging them because the file isn't signed.

http://www.systemlookup.com/lists.php?list…ch=Magentic.exe

If you are going to install a newer version of Trend Micro that's fine. You could also use a free one. I can give you some links when we are done.


Let's finish this up first.

Install the java then do an online scan.


  • Go to http://java.sun.com/javase/downloads/index.jsp
  • Scroll down to "Java Runtime Environment (JRE) 6 Update 16
  • Click the download button on the right.
If Information Bar pop-ups up, right-click on it and say it's OK to display the blocked content.
  • Select the platform (Windows, in your case), mutli language.
  • Accept the license agreement, click continue.
You do not have to install the Java Web Start ActiveX Control
  • Scroll down and click on Windows Offline Installation,
  • Save the file jre-6u17-windows-i586-p.exe to your desktop;
Do not select Run . Do not install it yet.

When the download is complete, close your browser.


  • Double-click on the saved file ( jre-6u17-windows-i586-p.exe) to install the update.
  • Delete the downloaded installation file after completing the above procedure and reboot if not prompted to do so.


*Note
It is recommended to disable onboard antivirus program and antispyware programs while performing scans so there are no conflicts and it will speed up scan time.
Please don't go surfing while your resident protection is disabled!
Once the scan is finished remember to re-enable your antivirus along with your antispyware programs.



Please go to Kaspersky website and perform an online antivirus scan.
  • Read through the requirements and privacy statement and click on Accept button.
  • It will start downloading and installing the scanner and virus definitions.
  • You will be prompted to install an application from Kaspersky. Click Run.
  • When the downloads have finished, click on Settings.
  • Make sure these boxes are checked (ticked). If they are not, please tick them and click on the Save button
    • Spyware, Adware, Dialers, and other potentially dangerous programs
    • Archives
    • Mail databases
  • Click on My Computer under Scan.
  • Once the scan is complete, it will display the results. Click on View Scan Report.
  • You will see a list of infected items there. Click on Save Report As….
  • Change the Files of type to Text file (.txt)
  • Set the Save In to Desktop
  • click the Save button.
  • Please post this log in your next reply.


Thanks
Hi, Oldman960! Good news- Kaspersky shows a clean scan. :P I uninstalled an Incredimail bin that I found in program/files and successfully installed a new paid version of TrendMicro Internet Suite. I also installed Java 6.17. By the way in your post, you inserted
  • Go to http://java.sun.com/javase/downloads/index.jsp
  • Scroll down to "Java Runtime Environment (JRE) 6 Update 16

    The links are right to ver. 6 Update 17, though.

    Thank you for your help. Looks like all we need to do some securing of the computer and clean-up of our tools. Jcatsmom
  • Hi Jcatsmom,

    Thanks, old canned and I missed one 16 when I edited it.


    From your desktop, please delete
    • any notepads/logs that we created
    • SystemLook.exe
    • GMER.zip
    • GMER.exe

    Next

    Open OTL then click the Clean Up button. You may get prompted by your firewall that OTL wants to contact the internet - allow this. A cleanup.txt will be downloaded, a message dialog will ask you if you want to proceed with the cleanup process, click Yes. This will do some clean up tasks and delete some of the tools you have downloaded plus itself.

    I suggest you keep MBAM. Keep it updated and use it regularly.


    *We'll reset your restore points

    • Click on the Start button to open your Start Menu.
    • Click on the Control Panel menu option.
    • Click on the System and Maintenance menu option.
    • Click on the System menu option.
    • Click on System Protection in the left-hand task list.
    • Create the manual restore point you should click on the Create button. When you press this button a prompt will appear asking you to provide a title for this manual restore point.
    • Type in a title for the manual restore point and press the Create button.
    • Close the System window after you have been advised that the procedure has been successfully completed.
    • Next, go to Start > Run and type in cleanmgr
    • Select the More options tab
    • Choose the option to clean up system restore and Ok it
    This will remove all restore points except the most recent one.


    Updates and upgrades

    You have an older version of Adobe Reader. You can download the current version HERE

    You may want to consider Foxit Reader instead. It may be a bit lighter on resources.

    Visit their support forum
    Foxit Forum

    In either case you should uninstall Adobe Reader 8.1.2 first. Be sure to move any PDF documents to another folder first though.


    Some Recommendations and prevention tips

    Basic security consists of 1 antivirus program, 1 resident antispyware program, 1 on demand antispyware program and a firewall. Just add a firewall.

    * If you are behind a router Windows firewall should be fine. Otherwise a 3rd party firewall with outbound monitoring is recommended.

    Click FIREWALL for tips, reviews and links to good, free and paid for firewalls. (Note: Zone Alarm is becoming bloatware)


    You should also use Spyware Blaster to help immunize your computer.

    - SpywareBlaster will add a large list of programs and sites into your Internet Explorer
    settings that will protect you from running and downloading known malicious programs.

    OR

    A guide to understanding and using the hosts file.

    Learn how your Hosts file can protect you and how you can protect it.
    Besides the Hosts file information, there are links to a very good updated hosts file, a host file manager. and some programs that can protect your hosts file.
    HOSTS

    Please read the info on disabling the DNS Client before installing a custom hosts file.

    Note the additional information for Vista.



    -Secure your Internet Explorer

    From within Internet Explorer click on the Tools menu and then click on Options.
    • Click once on the Security tab
    • Click once on the Internet icon so it becomes highlighted.
    • Click once on the Custom Level button.
    • Change the Download signed ActiveX controls to Prompt
    • Change the Download unsigned ActiveX controls to Disable
    • Change the Initialize and script ActiveX controls not marked as safe to Disable
    • Change the Installation of desktop items to Prompt
    • Change the Launching programs and files in an IFRAME to Prompt
    • Change the Navigate sub-frames across different domains to Prompt
    • When all these settings have been made, click on the OK button.
    • If it prompts you as to whether or not you want to save the settings, press the Yes button.
    Next press the Apply button and then the OK to exit the Internet Properties page.


    - Keeping your Windows up-to-date is crucial to your computer's security. Please go to the Windows Update Site (using Internet Explorer) and download and install all critical updates on a regular basis


    - Ensure that Automatic Update is turned on so you get all the latest patches.
    Click start, control panel, click Security Center.


    - Keep your antivirus program updated, as well as any other security programs you have.


    -Check this site out to check for out of date programs
    Secunia Personal Software Inspector (PSI) 1.0


    -More tips and programs can be found HERE

    - You may also want to read this article By Tony Klein
    http://www.freedomlist.com/forum/viewtopic.php?t=22879

    We will keep this thread open for a couple of days. Please post back if you have any problems or questions. Please post back when you have finished so this thread can be marked "Resolved".

    Take care
    Since this issue appears to be resolved … this Topic has been closed. Glad we could be of assistance. If you're the topic starter, and need this topic reopened, please contact a staff member with the address of the thread. Everyone else please begin a New Topic.

    Ask AI

    AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

    Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI