This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] google redirect = infection?

25 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hello; great place you have here, I hope you will be able to help me out.

The last several days I have been getting random redirects to different google and other sites when I do a search {I only use yahoo search so the google stands out when this happens}
Yesterday and today I have the problem of turning on my computer and I have no internet conection messages{ in my browser only}, I still have connection to a couple online games but get the "no connection" messages anytime I go to a webpage.
If I reboot I can access the internet again for a time but after awhile I will start getting this again.

I have Eset NOD32 antivirus and it doesn't scan any problems and for some reason it hasn't been coming on when I start my computer unless I go to the start menu and manually start it, is this related?

I downloaded HijackThis and have a logfile here so I'm hoping someone a lot smarter then me can see what may be causing my problems and help me get it fixed.

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 8:22:37 AM, on 1/8/2010
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Softex\OmniPass\Omniserv.exe
C:\Program Files\Common Files\supportsoft\bin\sprtlisten.exe
C:\Program Files\Softex\OmniPass\OPXPApp.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\SearchIndexer.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Qwest\Quickcare\bin\sprtcmd.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\Windows Desktop Search\WindowsSearch.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqgalry.exe
C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://qwest.live.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://srch-us8.hpwis.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://srch-us8.hpwis.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://qwest.live.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://srch-us8.hpwis.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://qwest.live.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Windows Internet Explorer provided by Qwest
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=localhost:7171
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local;
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O1 - Hosts: ::1 localhost
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: hp toolkit - {B2847E28-5D7D-4DEB-8B67-05D28BCF79F5} - C:\HP\EXPLOREBAR\HPTOOLKT.DLL
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O3 - Toolbar: (no name) - {90222687-F593-4738-B738-FBEE9C7B26DF} - (no file)
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O4 - HKLM\..\Run: [QuickCare] C:\Program Files\Qwest\Quickcare\bin\sprtcmd.exe /P QuickCare
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [updateMgr] "C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_9 -reboot 1
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - HKCU\..\Run: [igndlm.exe] C:\Program Files\Download Manager\DLM.exe /windowsstart /startifwork
O4 - S-1-5-18 Startup: GameSpot Download Manager.lnk = C:\Program Files\GameSpot\GameSpotDownloadManager_Win32.exe (User 'SYSTEM')
O4 - .DEFAULT Startup: GameSpot Download Manager.lnk = C:\Program Files\GameSpot\GameSpotDownloadManager_Win32.exe (User 'Default user')
O4 - Startup: GameSpot Download Manager.lnk = C:\Program Files\GameSpot\GameSpotDownloadManager_Win32.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: HP Image Zone Fast Start.lnk = C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqthb08.exe
O4 - Global Startup: Quicken Scheduled Updates.lnk = C:\Program Files\Quicken\bagent.exe
O4 - Global Startup: Updates from HP.lnk = C:\Program Files\Updates from HP\137903\Program\BackWeb-137903.exe
O4 - Global Startup: Windows Search.lnk = C:\Program Files\Windows Desktop Search\WindowsSearch.exe
O8 - Extra context menu item: &ieSpell Options - res://C:\Program Files\ieSpell\iespell.dll/SPELLOPTION.HTM
O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
O8 - Extra context menu item: Add to Windows &Live Favorites - http://favorites.live.com/quickadd.aspx
O8 - Extra context menu item: Check &Spelling - res://C:\Program Files\ieSpell\iespell.dll/SPELLCHECK.HTM
O8 - Extra context menu item: Lookup on Merriam Webster - file://C:\Program Files\ieSpell\Merriam Webster.HTM
O8 - Extra context menu item: Lookup on Wikipedia - file://C:\Program Files\ieSpell\wikipedia.HTM
O9 - Extra button: ieSpell - {0E17D5B7-9F5D-4fee-9DF6-CA6EE38B68A8} - C:\Program Files\ieSpell\iespell.dll
O9 - Extra 'Tools' menuitem: ieSpell - {0E17D5B7-9F5D-4fee-9DF6-CA6EE38B68A8} - C:\Program Files\ieSpell\iespell.dll
O9 - Extra button: (no name) - {1606D6F9-9D3B-4aea-A025-ED5B2FD488E7} - C:\Program Files\ieSpell\iespell.dll
O9 - Extra 'Tools' menuitem: ieSpell Options - {1606D6F9-9D3B-4aea-A025-ED5B2FD488E7} - C:\Program Files\ieSpell\iespell.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: Qwest Live - {4976605D-A51B-4C64-94A3-C647D599991B} - http://qwest.live.com (file missing) (HKCU)
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} - http://a1540.g.akamai.net/7/1540/52/200705…ex/qtplugin.cab
O16 - DPF: {39B0684F-D7BF-4743-B050-FDC3F48F7E3B} (CDownloadCtrl Object) - http://www.fileplanet.com/fpdlmgr/cabs/FPDC_2.3.9.113.cab
O16 - DPF: {44990301-3C9D-426D-81DF-AAB636FA4345} (Symantec Script Runner Class) - https://www-secure.symantec.com/techsupp/as…abs/tgctlsr.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1162338879046
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1222980964593
O16 - DPF: {A90A5822-F108-45AD-8482-9BC8B12DD539} (Crucial cpcScan) - http://www.crucial.com/controls/cpcScanner.cab
O16 - DPF: {A9F8D9EC-3D0A-4A60-BD82-FBD64BAD370D} (DDRevision Class) - http://h20264.www2.hp.com/ediags/dd/instal…nosticsxp2k.cab
O16 - DPF: {FFBB3F3B-0A5A-4106-BE53-DFE1E2340CB1} - http://dlm.tools.akamai.com/dlmanager/vers…vex-2.2.2.1.cab
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: ESET HTTP Server (EhttpSrv) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe
O23 - Service: ESET Service (ekrn) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Softex OmniPass Service (omniserv) - Unknown owner - C:\Program Files\Softex\OmniPass\Omniserv.exe
O23 - Service: Pml Driver HPH11 - HP - C:\WINDOWS\system32\HPHipm11.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: SupportSoft Listener Service (sprtlisten) - SupportSoft, Inc. - C:\Program Files\Common Files\supportsoft\bin\sprtlisten.exe
O23 - Service: SupportSoft RemoteAssist - SupportSoft, Inc. - C:\Program Files\Common Files\supportsoft\bin\ssrc.exe

–
End of file - 9555 bytes

Thanks for you time and brains!!!
Hi six, welcome to the forum.

To make cleaning this machine easier
  • Please do not uninstall/install any programs unless asked to
    It is more difficult when files/programs are appearing in/disappearing from the logs.
  • Please do not run any scans other than those requested
  • Please follow all instructions in the order posted
  • All logs/reports, etc.. must be posted in Notepad. Please ensure that word wrap is unchecked. In notepad click format, uncheck word wrap if it is checked.
  • Do not attach any logs/reports, etc.. unless specifically requested to do so.
  • If you have problems with or do not understand the instructions, Please ask before continuing.
  • Please stay with this thread until given the All Clear. A absence of symptoms does not mean a clean machine.

Make sure these settings are correct.

Open Internet Explorer
  • at the top click Tools
  • Click Internet Options
  • Click Connections tab
  • Click Lan Settings button
  • Make sure the box beside "Use a proxy sever for your Lan" is UNchecked
  • OK your way out.

Open hijackthis, do a system scan only and checkmark these lines, if present

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=localhost:7171
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local;
O3 - Toolbar: (no name) - {90222687-F593-4738-B738-FBEE9C7B26DF} - (no file)


Close ALL other windows/browsers and click Fix Checked. Answer Yes if prompted. Close HJT.



NEXT

Before scanning, make sure all other running programs are closed and no other actions like a scheduled antivirus scan will occur while the scan is being performed. Do not use your computer for anything else during the scan.

[external image: Posted Image]
Download GMER Rootkit Scanner from here or here.
  • Extract the contents of the zipped file to desktop.
  • Double click GMER.exe. If asked to allow gmer.sys driver to load, please consent .
  • If it gives you a warning about rootkit activity and asks if you want to run scan…click on NO.

    [external image: Posted Image]
    Click the image to enlarge it
  • In the right panel, you will see several boxes that have been checked. Uncheck the following …
    • Sections
    • IAT/EAT
    • Drives/Partition other than Systemdrive (typically C:\)
    • Show All (don't miss this one)
  • Then click the Scan button & wait for it to finish.
  • Once done click on the [Save..] button, and in the File name area, type in "Gmer.txt" or it will save as a .log file which cannot be uploaded to your post.
  • Save it where you can easily find it, such as your desktop, and post it in your next reply.

**Caution**
Rootkit scans often produce false positives. Do NOT take any action on any "<— ROOKIT" entries


Next

Download OTL to your desktop.
  • Double click on OTL.exe to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output
  • Check the boxes beside LOP Check and Purity Check.
  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.

Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post it with your next reply. You may need two posts to fit them all in.

Please post back with
  • GMER log
  • both OTL logs
No need for a Hijackthis log this time.

Thanks
Thanks for your help here are the logs you asked for

GMER log
GMER 1.0.15.15281 - http://www.gmer.net
Rootkit scan 2010-01-08 17:43:16
Windows 5.1.2600 Service Pack 3
Running: gmer.exe; Driver: C:\DOCUME~1\Owner\LOCALS~1\Temp\pwxdyaoc.sys


—- System - GMER 1.0.15 —-

SSDT 8A5608A0 ZwAssignProcessToJobObject
SSDT 8A55FCB0 ZwOpenProcess
SSDT 8A5600D0 ZwOpenThread
SSDT 8A5606D0 ZwSuspendProcess
SSDT 8A5604F0 ZwSuspendThread
SSDT \??\C:\Program Files\SUPERAntiSpyware\SASKUTIL.sys (SASKUTIL.SYS/SUPERAdBlocker.com and SUPERAntiSpyware.com) ZwTerminateProcess [0xB679F0B0]
SSDT 8A560310 ZwTerminateThread

—- Devices - GMER 1.0.15 —-

AttachedDevice \FileSystem\Ntfs \Ntfs eamon.sys (Amon monitor/ESET)
AttachedDevice \Driver\Tcpip \Device\Tcp epfwtdir.sys (ESET Antivirus Network Redirector/ESET)
AttachedDevice \FileSystem\Fastfat \Fat fltmgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)
AttachedDevice \FileSystem\Fastfat \Fat eamon.sys (Amon monitor/ESET)

—- Threads - GMER 1.0.15 —-

Thread System [4:360] 8A55E930

—- EOF - GMER 1.0.15 —-


OTL logfile created on: 1/8/2010 7:02:26 PM - Run 1
OTL by OldTimer - Version 3.1.21.2 Folder = C:\Documents and Settings\Owner\Desktop
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.13)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

3.00 Gb Total Physical Memory | 3.00 Gb Available Physical Memory | 84.00% Memory free
4.00 Gb Paging File | 4.00 Gb Available in Paging File | 91.00% Paging File free
Paging file location(s): C:\pagefile.sys 1536 3072 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 105.65 Gb Total Space | 56.81 Gb Free Space | 53.77% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
Drive I: | 6.12 Gb Total Space | 2.61 Gb Free Space | 42.72% Space Free | Partition Type: FAT32

Computer Name: YOUR-O0KWKW9JWC
Current User Name: Owner
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal

========== Processes (SafeList) ==========

PRC - C:\Documents and Settings\Owner\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\SUPERAntiSpyware\SUPERANTISPYWARE.EXE (SUPERAntiSpyware.com)
PRC - C:\Program Files\Java\jre6\bin\jqs.exe (Sun Microsystems, Inc.)
PRC - C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe (ESET)
PRC - C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe (ESET)
PRC - C:\WINDOWS\system32\nvsvc32.exe (NVIDIA Corporation)
PRC - C:\Program Files\Qwest\Quickcare\bin\sprtcmd.exe (SupportSoft, Inc.)
PRC - C:\Program Files\Windows Desktop Search\WindowsSearch.exe (Microsoft Corporation)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Common Files\SupportSoft\bin\sprtlisten.exe (SupportSoft, Inc.)
PRC - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe (Apple, Inc.)
PRC - C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqgalry.exe (Hewlett-Packard Co.)
PRC - C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqtra08.exe (Hewlett-Packard Co.)
PRC - C:\Program Files\Softex\OmniPass\omniServ.exe ()
PRC - C:\Program Files\Softex\OmniPass\OPXPApp.exe ()


========== Modules (SafeList) ==========

MOD - C:\Documents and Settings\Owner\Desktop\OTL.exe (OldTimer Tools)
MOD - C:\Program Files\Qwest\Quickcare\bin\sprthook.dll (SupportSoft, Inc.)
MOD - C:\WINDOWS\system32\msvcp60.dll (Microsoft Corporation)


========== Win32 Services (SafeList) ==========

SRV - (JavaQuickStarterService) – C:\Program Files\Java\jre6\bin\jqs.exe (Sun Microsystems, Inc.)
SRV - (EhttpSrv) – C:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe (ESET)
SRV - (ekrn) – C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe (ESET)
SRV - (NVSvc) – C:\WINDOWS\system32\nvsvc32.exe (NVIDIA Corporation)
SRV - (SupportSoft RemoteAssist) – C:\Program Files\Common Files\SupportSoft\bin\ssrc.exe (SupportSoft, Inc.)
SRV - (sprtlisten) – C:\Program Files\Common Files\supportsoft\bin\sprtlisten.exe (SupportSoft, Inc.)
SRV - (WLSetupSvc) – C:\Program Files\Windows Live\installer\WLSetupSvc.exe (Microsoft Corporation)
SRV - (usnjsvc) – C:\Program Files\Windows Live\Messenger\usnsvc.exe (Microsoft Corporation)
SRV - (Pml Driver HPZ12) – C:\WINDOWS\system32\HPZipm12.exe (HP)
SRV - (Apple Mobile Device) – C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe (Apple, Inc.)
SRV - (omniserv) – C:\Program Files\Softex\OmniPass\omniServ.exe ()
SRV - (Pml Driver HPH11) – C:\WINDOWS\system32\hphipm11.exe (HP)


========== Driver Services (SafeList) ==========

DRV - (SASKUTIL) – C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (SASENUM) – C:\Program Files\SUPERAntiSpyware\SASENUM.SYS ( SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (SASDIFSV) – C:\Program Files\SUPERAntiSpyware\sasdifsv.sys (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (epfwtdir) – C:\WINDOWS\system32\drivers\epfwtdir.sys (ESET)
DRV - (ehdrv) – C:\WINDOWS\system32\drivers\ehdrv.sys (ESET)
DRV - (eamon) – C:\WINDOWS\system32\drivers\eamon.sys (ESET)
DRV - (RTL8023xp) – C:\WINDOWS\system32\drivers\Rtnicxp.sys (Realtek Semiconductor Corporation )
DRV - (nv) – C:\WINDOWS\system32\drivers\nv4_mini.sys (NVIDIA Corporation)
DRV - (Secdrv) – C:\WINDOWS\system32\drivers\secdrv.sys (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.)
DRV - (PxHelp20) – C:\WINDOWS\System32\DRIVERS\PxHelp20.sys (Sonic Solutions)
DRV - (hamachi_oem) – C:\WINDOWS\system32\drivers\gan_adapter.sys (Applied Networking Inc.)
DRV - (Ps2) – C:\WINDOWS\system32\drivers\PS2.sys (Hewlett-Packard Company)
DRV - (HPZius12) – C:\WINDOWS\system32\drivers\HPZius12.sys (HP)
DRV - (HPZipr12) – C:\WINDOWS\system32\drivers\HPZipr12.sys (HP)
DRV - (HPZid412) – C:\WINDOWS\system32\drivers\HPZid412.sys (HP)
DRV - (AFS2K) – C:\WINDOWS\system32\drivers\AFS2K.SYS (Oak Technology Inc.)
DRV - (ALCXWDM) Service for Realtek AC97 Audio (WDM) – C:\WINDOWS\system32\drivers\ALCXWDM.SYS (Realtek Semiconductor Corp.)
DRV - (S3Psddr) – C:\WINDOWS\system32\drivers\s3gnbm.sys (S3 Graphics, Inc.)
DRV - (ltmodem5) – C:\WINDOWS\system32\drivers\ltmdmnt.sys (Agere Systems)
DRV - (LMouFlt2) – C:\WINDOWS\system32\drivers\LMouFlt2.Sys (Logitech, Inc.)
DRV - (L8042pr2) – C:\WINDOWS\system32\drivers\L8042pr2.Sys (Logitech, Inc.)
DRV - (MxlW2k) – C:\WINDOWS\system32\drivers\MxlW2k.sys (MusicMatch, Inc.)
DRV - ({6080A529-897E-4629-A488-ABA0C29B635E}) Intel® Graphics Platform (SoftBIOS) – C:\WINDOWS\system32\drivers\ialmsbw.sys (Intel Corporation)
DRV - ({D31A0762-0CEB-444e-ACFF-B049A1F6FE91}) Intel® Graphics Chipset (KCH) – C:\WINDOWS\system32\drivers\ialmkchw.sys (Intel Corporation)
DRV - (ialm) – C:\WINDOWS\system32\drivers\ialmnt5.sys (Intel Corporation)
DRV - (SiS315) – C:\WINDOWS\system32\drivers\sisgrp.sys (Silicon Integrated Systems Corporation)
DRV - (fasttx2k) – C:\WINDOWS\System32\DRIVERS\fasttx2k.sys (Promise Technology, Inc.)
DRV - (viaagp1) – C:\WINDOWS\System32\DRIVERS\viaagp1.sys (VIA Technologies, Inc.)
DRV - (SISAGP) – C:\WINDOWS\System32\DRIVERS\SISAGPX.sys (Silicon Integrated Systems Corporation)
DRV - (drvmcdb) – C:\WINDOWS\System32\DRIVERS\drvmcdb.sys (VERITAS Software, Inc.)
DRV - (rtl8139) – C:\WINDOWS\system32\drivers\R8139n51.sys (Realtek Semiconductor Corporation )
DRV - (pfc) – C:\WINDOWS\system32\drivers\pfc.sys (Padus, Inc.)
DRV - (nv_agp) – C:\WINDOWS\System32\DRIVERS\nv_agp.sys (NVIDIA Corporation)
DRV - (Ptilink) – C:\WINDOWS\system32\drivers\ptilink.sys (Parallel Technologies, Inc.)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://qwest.live.com
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Secondary Start Pages = [Binary data over 100 bytes]
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://qwest.live.com
IE - HKLM\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 1
IE - HKLM\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local;
IE - HKLM\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = http=localhost:7171

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://qwest.live.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://srch-us8.hpwis.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://srch-us8.hpwis.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://my.yahoo.com/
IE - HKCU\Software\Microsoft\Internet Explorer\SearchURL\CNNSI, = search.sportsillustrated.cnn.com/pages/search.jsp?query=%s
IE - HKCU\Software\Microsoft\Internet Explorer\SearchURL\Dictionary, = dictionary.reference.com/search?q=%s
IE - HKCU\Software\Microsoft\Internet Explorer\SearchURL\Google, = google.com/search?q=%s
IE - HKCU\Software\Microsoft\Internet Explorer\SearchURL\GoogleGroups, = groups-beta.google.com/groups?q=%s
IE - HKCU\Software\Microsoft\Internet Explorer\SearchURL\GoogleImages, = images.google.com/images?hl=en&lr=&q=%s
IE - HKCU\Software\Microsoft\Internet Explorer\SearchURL\GoogleNews, = news.google.com/news?tab=gn&hl=en&ie=UTF-8&q=%s&btnG=Search+News
IE - HKCU\Software\Microsoft\Internet Explorer\SearchURL\KB, = support.microsoft.com/search/default.aspx?query=%s
IE - HKCU\Software\Microsoft\Internet Explorer\SearchURL\KBDLL, = support.microsoft.com/dllhelp/default.aspx?dlltype=file&l=55&alpha=%s&S=1
IE - HKCU\Software\Microsoft\Internet Explorer\SearchURL\Movies, = fandango.com/my_box_office.asp?searchby=2&txtCityZip=%s
IE - HKCU\Software\Microsoft\Internet Explorer\SearchURL\MSN, = search.msn.com/results.asp?q=%s
IE - HKCU\Software\Microsoft\Internet Explorer\SearchURL\Thesaurus, = thesaurus.reference.com/search?q=%s
IE - HKCU\Software\Microsoft\Internet Explorer\SearchURL\Weather, = weather.com/weather/local/%s
IE - HKCU\Software\Microsoft\Internet Explorer\SearchURL\Yahoo, = search.yahoo.com/search?p=%s
IE - HKCU\..\URLSearchHook: {EF99BD32-C1FB-11D2-892F-0090271D4F88} - Reg Error: Key error. File not found
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

FF - HKLM\software\mozilla\Thunderbird\Extensions\\[removed]: C:\Program Files\ESET\ESET NOD32 Antivirus\Mozilla Thunderbird [2009/06/11 17:50:23 | 00,000,000 | —D | M]

[2009/04/28 16:27:16 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Mozilla\Extensions

O1 HOSTS File: (36 bytes) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (Windows Live Toolbar Helper) - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll (Microsoft Corporation)
O2 - BHO: (JQSIEStartDetectorImpl Class) - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll (Sun Microsystems, Inc.)
O3 - HKLM\..\Toolbar: (hp toolkit) - {B2847E28-5D7D-4DEB-8B67-05D28BCF79F5} - C:\hp\EXPLOREBAR\HPTOOLKT.DLL (Hewlett-Packard Company)
O3 - HKLM\..\Toolbar: (Windows Live Toolbar) - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll (Microsoft Corporation)
O3 - HKLM\..\Toolbar: (no name) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - No CLSID value found.
O3 - HKCU\..\Toolbar\ShellBrowser: (no name) - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - No CLSID value found.
O3 - HKCU\..\Toolbar\ShellBrowser: (hp toolkit) - {B2847E28-5D7D-4DEB-8B67-05D28BCF79F5} - C:\hp\EXPLOREBAR\HPTOOLKT.DLL (Hewlett-Packard Company)
O3 - HKCU\..\Toolbar\WebBrowser: (hp toolkit) - {B2847E28-5D7D-4DEB-8B67-05D28BCF79F5} - C:\hp\EXPLOREBAR\HPTOOLKT.DLL (Hewlett-Packard Company)
O3 - HKCU\..\Toolbar\WebBrowser: (Windows Live Toolbar) - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll (Microsoft Corporation)
O4 - HKLM..\Run: [KernelFaultCheck] File not found
O4 - HKLM..\Run: [NvCplDaemon] C:\WINDOWS\System32\NvCpl.DLL (NVIDIA Corporation)
O4 - HKLM..\Run: [QuickCare] C:\Program Files\Qwest\Quickcare\bin\sprtcmd.exe (SupportSoft, Inc.)
O4 - HKCU..\Run: [igndlm.exe] C:\Program Files\Download Manager\DLM.exe (IGN Entertainment)
O4 - HKCU..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERANTISPYWARE.EXE (SUPERAntiSpyware.com)
O4 - HKCU..\Run: [updateMgr] C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe (Adobe Systems Incorporated)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe (Adobe Systems Incorporated)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk = C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqtra08.exe (Hewlett-Packard Co.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\HP Image Zone Fast Start.lnk = C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqthb08.exe (Hewlett-Packard Co.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Quicken Scheduled Updates.lnk = C:\Program Files\Quicken\bagent.exe (Intuit Inc.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Updates from HP.lnk = C:\Program Files\Updates from HP\137903\Program\BackWeb-137903.exe File not found
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Windows Search.lnk = C:\Program Files\Windows Desktop Search\WindowsSearch.exe (Microsoft Corporation)
O4 - Startup: C:\Documents and Settings\Owner\Start Menu\Programs\Startup\GameSpot Download Manager.lnk = C:\Program Files\GameSpot\GameSpotDownloadManager_Win32.exe File not found
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O8 - Extra context menu item: &ieSpell Options - C:\Program Files\ieSpell\iespell.dll (Red Egg Software)
O8 - Extra context menu item: &Windows Live Search - C:\Program Files\Windows Live Toolbar\msntb.dll (Microsoft Corporation)
O8 - Extra context menu item: Check &Spelling - C:\Program Files\ieSpell\iespell.dll (Red Egg Software)
O8 - Extra context menu item: Lookup on Merriam Webster - C:\Program Files\ieSpell\Merriam Webster.HTM ()
O8 - Extra context menu item: Lookup on Wikipedia - C:\Program Files\ieSpell\wikipedia.HTM ()
O9 - Extra Button: ieSpell - {0E17D5B7-9F5D-4fee-9DF6-CA6EE38B68A8} - C:\Program Files\ieSpell\iespell.dll (Red Egg Software)
O9 - Extra 'Tools' menuitem : ieSpell - {0E17D5B7-9F5D-4fee-9DF6-CA6EE38B68A8} - C:\Program Files\ieSpell\iespell.dll (Red Egg Software)
O9 - Extra 'Tools' menuitem : ieSpell Options - {1606D6F9-9D3B-4aea-A025-ED5B2FD488E7} - C:\Program Files\ieSpell\iespell.dll (Red Egg Software)
O12 - Plugin for: .spop - C:\Program Files\Internet Explorer\PLUGINS\NPDocBox.dll (InterTrust Technologies Corporation, Inc.)
O15 - HKLM\..Trusted Domains: 1 domain(s) and sub-domain(s) not assigned to a zone.
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} http://a1540.g.akamai.net/7/1540/52/200705…ex/qtplugin.cab (Reg Error: Key error.)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://download.microsoft.com/download/8/b…heckControl.cab (Windows Genuine Advantage Validation Tool)
O16 - DPF: {39B0684F-D7BF-4743-B050-FDC3F48F7E3B} http://www.fileplanet.com/fpdlmgr/cabs/FPDC_2.3.9.113.cab (CDownloadCtrl Object)
O16 - DPF: {44990301-3C9D-426D-81DF-AAB636FA4345} https://www-secure.symantec.com/techsupp/as…abs/tgctlsr.cab (Symantec Script Runner Class)
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} http://update.microsoft.com/windowsupdate/…b?1162338879046 (WUWebControl Class)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} http://update.microsoft.com/microsoftupdat…b?1222980964593 (MUWebControl Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {A90A5822-F108-45AD-8482-9BC8B12DD539} http://www.crucial.com/controls/cpcScanner.cab (Crucial cpcScan)
O16 - DPF: {A9F8D9EC-3D0A-4A60-BD82-FBD64BAD370D} http://h20264.www2.hp.com/ediags/dd/instal…nosticsxp2k.cab (DDRevision Class)
O16 - DPF: {CAFEEFAC-0015-0000-0009-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-…indows-i586.cab (Java Plug-in 1.5.0_09)
O16 - DPF: {CAFEEFAC-0015-0000-0010-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-…indows-i586.cab (Java Plug-in 1.5.0_10)
O16 - DPF: {CAFEEFAC-0015-0000-0011-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-…indows-i586.cab (Java Plug-in 1.5.0_11)
O16 - DPF: {CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_01)
O16 - DPF: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload.macromedia.com/get/flash…ent/swflash.cab (Shockwave Flash Object)
O16 - DPF: {FFBB3F3B-0A5A-4106-BE53-DFE1E2340CB1} http://dlm.tools.akamai.com/dlmanager/vers…vex-2.2.2.1.cab (Reg Error: Key error.)
O16 - DPF: DirectAnimation Java Classes file://C:\WINDOWS\Java\classes\dajava.cab (Reg Error: Key error.)
O16 - DPF: Microsoft XML Parser for Java file://C:\WINDOWS\Java\classes\xmldso.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.2.1
O18 - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\Windows Live\Messenger\msgrapp.8.5.1302.1018.dll (Microsoft Corporation)
O18 - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\Windows Live\Messenger\msgrapp.8.5.1302.1018.dll (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\!SASWinLogon: DllName - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL (SUPERAntiSpyware.com)
O20 - Winlogon\Notify\igfxcui: DllName - igfxsrvc.dll - C:\WINDOWS\System32\igfxsrvc.dll (Intel Corporation)
O20 - Winlogon\Notify\OPXPGina: DllName - C:\Program Files\Softex\OmniPass\opxpgina.dll - C:\Program Files\Softex\OmniPass\OPXPGina.dll ()
O28 - HKLM ShellExecuteHooks: {56F9679E-7826-4C84-81F3-532071A8BCC5} - C:\Program Files\Windows Desktop Search\MsnlNamespaceMgr.dll (Microsoft Corporation)
O28 - HKLM ShellExecuteHooks: {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - C:\Program Files\SUPERAntiSpyware\SASSEH.DLL (SuperAdBlocker.com)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2003/04/09 22:19:17 | 00,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O32 - AutoRun File - [2001/07/28 07:07:38 | 00,000,000 | -HS- | M] () - I:\AUTOEXEC.BAT – [ FAT32 ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - comfile [open] – "%1" %*
O35 - exefile [open] – "%1" %*

========== Files/Folders - Created Within 30 Days ==========

[2010/01/08 18:59:23 | 00,513,536 | —- | C] (OldTimer Tools) – C:\Documents and Settings\Owner\Desktop\OTL.exe
[2010/01/07 05:38:16 | 00,000,000 | —D | C] – C:\Program Files\Trend Micro
[2009/07/21 22:14:30 | 00,000,000 | —D | M] – C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft
[2009/06/04 10:22:13 | 00,000,000 | —D | M] – C:\Documents and Settings\LocalService\Local Settings\Application Data\ESET
[2009/04/28 16:25:18 | 00,000,000 | —D | M] – C:\Documents and Settings\NetworkService\Application Data\Mozilla
[2007/07/30 19:03:22 | 00,000,000 | —D | M] – C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft
[2007/07/19 21:31:58 | 00,000,000 | –SD | M] – C:\Documents and Settings\NetworkService\Application Data\Microsoft
[2006/11/01 21:16:30 | 00,000,000 | –SD | M] – C:\Documents and Settings\LocalService\Application Data\Microsoft
[5 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2010/01/08 18:59:23 | 00,513,536 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Owner\Desktop\OTL.exe
[2010/01/08 18:31:00 | 00,000,254 | —- | M] () – C:\WINDOWS\tasks\Check Updates for Windows Live Toolbar.job
[2010/01/08 17:48:25 | 00,205,272 | —- | M] () – C:\WINDOWS\System32\nvapps.xml
[2010/01/08 17:48:18 | 00,001,158 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2010/01/08 17:48:01 | 00,000,006 | -H– | M] () – C:\WINDOWS\tasks\SA.DAT
[2010/01/08 17:47:58 | 00,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2010/01/08 17:47:55 | 32,205,57824 | -HS- | M] () – C:\hiberfil.sys
[2010/01/08 17:29:22 | 00,284,915 | —- | M] () – C:\Documents and Settings\Owner\Desktop\gmer.zip
[2010/01/08 11:53:09 | 04,718,592 | -H– | M] () – C:\Documents and Settings\Owner\NTUSER.DAT
[2010/01/08 11:52:54 | 00,000,268 | -H– | M] () – C:\sqmdata07.sqm
[2010/01/08 11:52:54 | 00,000,244 | -H– | M] () – C:\sqmnoopt07.sqm
[2010/01/08 08:23:32 | 00,000,178 | -HS- | M] () – C:\Documents and Settings\Owner\ntuser.ini
[2010/01/08 08:23:23 | 00,000,268 | -H– | M] () – C:\sqmdata06.sqm
[2010/01/08 08:23:23 | 00,000,244 | -H– | M] () – C:\sqmnoopt06.sqm
[2010/01/08 08:23:21 | 06,435,384 | -H– | M] () – C:\Documents and Settings\Owner\Local Settings\Application Data\IconCache.db
[2010/01/07 23:59:53 | 00,000,268 | -H– | M] () – C:\sqmdata05.sqm
[2010/01/07 23:59:53 | 00,000,244 | -H– | M] () – C:\sqmnoopt05.sqm
[2010/01/07 17:18:28 | 00,000,268 | -H– | M] () – C:\sqmdata04.sqm
[2010/01/07 17:18:27 | 00,000,244 | -H– | M] () – C:\sqmnoopt04.sqm
[2010/01/07 08:05:55 | 00,000,268 | -H– | M] () – C:\sqmdata03.sqm
[2010/01/07 08:05:55 | 00,000,244 | -H– | M] () – C:\sqmnoopt03.sqm
[2010/01/07 07:01:18 | 00,000,268 | -H– | M] () – C:\sqmdata02.sqm
[2010/01/07 07:01:18 | 00,000,244 | -H– | M] () – C:\sqmnoopt02.sqm
[2010/01/07 05:38:18 | 00,001,745 | —- | M] () – C:\Documents and Settings\Owner\Desktop\HijackThis.lnk
[2010/01/07 05:31:11 | 00,000,268 | -H– | M] () – C:\sqmdata01.sqm
[2010/01/07 05:31:11 | 00,000,244 | -H– | M] () – C:\sqmnoopt01.sqm
[2010/01/06 22:22:20 | 00,000,268 | -H– | M] () – C:\sqmdata00.sqm
[2010/01/06 22:22:20 | 00,000,244 | -H– | M] () – C:\sqmnoopt00.sqm
[2010/01/06 17:28:30 | 00,000,268 | -H– | M] () – C:\sqmdata19.sqm
[2010/01/06 17:28:30 | 00,000,244 | -H– | M] () – C:\sqmnoopt19.sqm
[2010/01/06 06:27:02 | 00,000,268 | -H– | M] () – C:\sqmdata18.sqm
[2010/01/06 06:27:02 | 00,000,244 | -H– | M] () – C:\sqmnoopt18.sqm
[2010/01/05 20:49:59 | 00,000,268 | -H– | M] () – C:\sqmdata17.sqm
[2010/01/05 20:49:59 | 00,000,244 | -H– | M] () – C:\sqmnoopt17.sqm
[2010/01/05 15:53:51 | 00,000,268 | -H– | M] () – C:\sqmdata16.sqm
[2010/01/05 15:53:51 | 00,000,244 | -H– | M] () – C:\sqmnoopt16.sqm
[2010/01/05 15:49:25 | 00,000,036 | —- | M] () – C:\WINDOWS\System32\drivers\etc\hosts
[2010/01/05 07:01:30 | 00,000,268 | -H– | M] () – C:\sqmdata15.sqm
[2010/01/05 07:01:30 | 00,000,244 | -H– | M] () – C:\sqmnoopt15.sqm
[2010/01/05 05:01:38 | 00,000,268 | -H– | M] () – C:\sqmdata14.sqm
[2010/01/05 05:01:38 | 00,000,244 | -H– | M] () – C:\sqmnoopt14.sqm
[2010/01/04 21:22:43 | 00,000,268 | -H– | M] () – C:\sqmdata13.sqm
[2010/01/04 21:22:43 | 00,000,244 | -H– | M] () – C:\sqmnoopt13.sqm
[2010/01/04 09:59:50 | 00,000,268 | -H– | M] () – C:\sqmdata12.sqm
[2010/01/04 09:59:49 | 00,000,244 | -H– | M] () – C:\sqmnoopt12.sqm
[2010/01/04 08:07:17 | 00,000,268 | -H– | M] () – C:\sqmdata11.sqm
[2010/01/04 08:07:17 | 00,000,244 | -H– | M] () – C:\sqmnoopt11.sqm
[2010/01/03 20:50:31 | 00,000,268 | -H– | M] () – C:\sqmdata10.sqm
[2010/01/03 20:50:31 | 00,000,244 | -H– | M] () – C:\sqmnoopt10.sqm
[2010/01/02 22:24:25 | 00,000,268 | -H– | M] () – C:\sqmdata09.sqm
[2010/01/02 22:24:25 | 00,000,244 | -H– | M] () – C:\sqmnoopt09.sqm
[2009/12/30 00:51:43 | 00,000,268 | -H– | M] () – C:\sqmdata08.sqm
[2009/12/30 00:51:43 | 00,000,244 | -H– | M] () – C:\sqmnoopt08.sqm
[2009/12/10 03:06:58 | 00,553,238 | —- | M] () – C:\WINDOWS\System32\PerfStringBackup.INI
[2009/12/10 03:06:58 | 00,463,510 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2009/12/10 03:06:58 | 00,078,786 | —- | M] () – C:\WINDOWS\System32\perfc009.dat
[2009/12/10 03:03:30 | 00,001,393 | —- | M] () – C:\WINDOWS\imsins.BAK
[5 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]

========== Files Created - No Company Name ==========

[2010/01/08 17:29:48 | 00,284,915 | —- | C] () – C:\Documents and Settings\Owner\Desktop\gmer.zip
[2010/01/07 05:38:17 | 00,001,745 | —- | C] () – C:\Documents and Settings\Owner\Desktop\HijackThis.lnk
[2009/09/10 11:43:49 | 00,095,856 | —- | C] () – C:\Documents and Settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
[2009/06/10 07:36:07 | 00,000,911 | —- | C] () – C:\WINDOWS\STA2.ini
[2009/04/28 15:25:03 | 00,002,928 | —- | C] () – C:\Documents and Settings\NetworkService\Local Settings\Application Data\81F79ABC-AB11-494C-859E-88424AA60ADF.txt
[2009/04/28 15:24:16 | 00,003,756 | —- | C] () – C:\Documents and Settings\Owner\Local Settings\Application Data\81F79ABC-AB11-494C-859E-88424AA60ADF.txt
[2008/11/18 17:34:20 | 00,000,262 | —- | C] () – C:\WINDOWS\{789289CA-F73A-4A16-A331-54D498CE069F}_WiseFW.ini
[2008/07/21 16:14:10 | 00,073,728 | —- | C] () – C:\WINDOWS\System32\RtNicProp32.dll
[2007/11/26 21:56:28 | 00,151,415 | —- | C] () – C:\WINDOWS\System32\xlive.dll.cat
[2007/09/27 10:51:02 | 00,020,698 | —- | C] () – C:\WINDOWS\System32\idxcntrs.ini
[2007/09/27 10:48:48 | 00,030,628 | —- | C] () – C:\WINDOWS\System32\gsrvctr.ini
[2007/09/27 10:48:28 | 00,031,698 | —- | C] () – C:\WINDOWS\System32\gthrctr.ini
[2007/07/23 08:03:32 | 00,053,248 | —- | C] () – C:\WINDOWS\System32\AgCPanelTraditionalChinese.dll
[2007/07/23 08:03:32 | 00,053,248 | —- | C] () – C:\WINDOWS\System32\AgCPanelSwedish.dll
[2007/07/23 08:03:32 | 00,053,248 | —- | C] () – C:\WINDOWS\System32\AgCPanelSpanish.dll
[2007/07/23 08:03:30 | 00,053,248 | —- | C] () – C:\WINDOWS\System32\AgCPanelSimplifiedChinese.dll
[2007/07/23 08:03:30 | 00,053,248 | —- | C] () – C:\WINDOWS\System32\AgCPanelPortugese.dll
[2007/07/23 08:03:30 | 00,053,248 | —- | C] () – C:\WINDOWS\System32\AgCPanelKorean.dll
[2007/07/23 08:03:30 | 00,053,248 | —- | C] () – C:\WINDOWS\System32\AgCPanelJapanese.dll
[2007/07/23 08:03:30 | 00,053,248 | —- | C] () – C:\WINDOWS\System32\AgCPanelGerman.dll
[2007/07/23 08:03:30 | 00,053,248 | —- | C] () – C:\WINDOWS\System32\AgCPanelFrench.dll
[2006/12/30 02:29:35 | 00,006,144 | —- | C] () – C:\Documents and Settings\Owner\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2006/12/02 18:13:19 | 00,000,214 | —- | C] () – C:\WINDOWS\HP_48BitScanUpdatePatch.ini
[2006/11/24 18:24:46 | 00,021,840 | —- | C] () – C:\WINDOWS\System32\SIntfNT.dll
[2006/11/24 18:24:45 | 00,017,212 | —- | C] () – C:\WINDOWS\System32\SIntf32.dll
[2006/11/24 18:24:45 | 00,012,067 | —- | C] () – C:\WINDOWS\System32\SIntf16.dll
[2006/11/14 19:57:18 | 00,000,000 | —- | C] () – C:\WINDOWS\iPlayer.INI
[2006/11/08 05:52:36 | 00,061,678 | —- | C] () – C:\Documents and Settings\Owner\Application Data\PFP100JPR.{PB
[2006/11/08 05:52:36 | 00,012,358 | —- | C] () – C:\Documents and Settings\Owner\Application Data\PFP100JCM.{PB
[2006/11/01 16:23:02 | 00,000,128 | —- | C] () – C:\Documents and Settings\Owner\Local Settings\Application Data\fusioncache.dat
[2006/11/01 15:52:30 | 00,001,109 | —- | C] () – C:\Documents and Settings\All Users\Application Data\hpzinstall.log
[2006/10/31 16:40:31 | 00,019,968 | —- | C] () – C:\WINDOWS\System32\cpuinf32.dll
[2006/08/11 21:45:20 | 00,581,632 | —- | C] () – C:\WINDOWS\System32\nvhwvid.dll
[2006/08/11 21:43:00 | 01,724,416 | —- | C] () – C:\WINDOWS\System32\nvwdmcpl.dll
[2006/08/11 21:43:00 | 01,101,824 | —- | C] () – C:\WINDOWS\System32\nvwimg.dll
[2006/08/11 21:43:00 | 00,286,720 | —- | C] () – C:\WINDOWS\System32\nvnt4cpl.dll
[2004/09/13 16:35:56 | 00,000,000 | —- | C] () – C:\WINDOWS\System32\px.ini
[2003/04/10 04:35:00 | 00,000,061 | —- | C] () – C:\WINDOWS\smscfg.ini
[2003/04/10 04:21:36 | 00,000,051 | —- | C] () – C:\WINDOWS\System32\mshrml.ini
[2003/04/10 01:51:07 | 00,000,438 | —- | C] () – C:\WINDOWS\System32\1_ssetup.ini
[2003/04/10 01:51:07 | 00,000,000 | —- | C] () – C:\WINDOWS\System32\sunistlog.ini
[2003/04/10 00:32:34 | 00,094,208 | —- | C] () – C:\WINDOWS\System32\PcdrKernelModeServices.dll
[2003/04/10 00:32:34 | 00,077,824 | —- | C] () – C:\WINDOWS\System32\ProgressTrace.dll
[2003/04/10 00:06:10 | 00,167,936 | —- | C] () – C:\WINDOWS\System32\PCDrJNI_1_1.dll
[2003/04/10 00:03:38 | 00,045,056 | —- | C] () – C:\WINDOWS\System32\hpreg.dll
[2003/04/10 00:03:38 | 00,024,576 | —- | C] () – C:\WINDOWS\System32\syscontr.dll
[2003/04/09 23:57:15 | 00,000,052 | —- | C] () – C:\WINDOWS\intuprof.ini
[2003/04/09 23:57:04 | 00,000,626 | —- | C] () – C:\WINDOWS\QUICKEN.INI
[2003/04/09 23:16:44 | 00,001,793 | —- | C] () – C:\WINDOWS\System32\fxsperf.ini
[2003/04/09 23:08:03 | 00,466,944 | —- | C] () – C:\WINDOWS\System32\nvshell.dll
[2003/04/09 23:08:01 | 01,507,328 | —- | C] () – C:\WINDOWS\System32\nview.dll
[2003/04/09 22:55:02 | 00,363,520 | —- | C] () – C:\WINDOWS\System32\psisdecd.dll
[2003/04/09 22:44:58 | 00,299,073 | —- | C] () – C:\WINDOWS\System32\PythonCOM22.dll
[2003/04/09 22:44:58 | 00,065,536 | —- | C] () – C:\WINDOWS\System32\PyWinTypes22.dll
[2003/04/09 22:44:29 | 00,016,896 | —- | C] () – C:\WINDOWS\System32\bcbmm.dll
[2003/04/09 22:23:21 | 00,000,802 | —- | C] () – C:\WINDOWS\orun32.ini
[2003/04/09 22:05:45 | 00,000,659 | —- | C] () – C:\WINDOWS\System32\oeminfo.ini
[2001/08/14 18:47:08 | 00,020,480 | —- | C] () – C:\WINDOWS\System32\vxpsapi.dll

========== LOP Check ==========

[2008/12/10 21:09:34 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Comcast
[2009/06/04 10:20:33 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\ESET
[2008/12/03 15:59:09 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Fallout3
[2008/04/17 01:31:04 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Funcom
[2006/11/01 11:55:45 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Geek Squad
[2009/04/28 19:20:05 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\PCSettings
[2009/09/10 16:50:01 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\SupportSoft
[2007/07/14 19:44:46 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\WildTangent
[2008/10/02 09:17:00 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{51019853-129C-4EDE-9030-D5FD7BBD9AD0}
[2006/11/02 12:40:04 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\acccore
[2006/12/24 00:59:05 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\ieSpell
[2009/06/11 17:42:41 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\interMute
[2003/04/09 23:52:19 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\InterTrust
[2003/04/10 00:04:31 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\SampleView
[2009/09/10 11:15:50 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\uniblue
[2006/11/02 02:17:08 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\VERITAS
[2008/11/12 09:58:00 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Windows Desktop Search
[2008/11/12 10:03:17 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Windows Search
[2010/01/08 18:31:00 | 00,000,254 | —- | M] () – C:\WINDOWS\Tasks\Check Updates for Windows Live Toolbar.job

========== Purity Check ==========


< End of report >
OTL Extras logfile created on: 1/8/2010 7:02:26 PM - Run 1
OTL by OldTimer - Version 3.1.21.2 Folder = C:\Documents and Settings\Owner\Desktop
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.13)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

3.00 Gb Total Physical Memory | 3.00 Gb Available Physical Memory | 84.00% Memory free
4.00 Gb Paging File | 4.00 Gb Available in Paging File | 91.00% Paging File free
Paging file location(s): C:\pagefile.sys 1536 3072 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 105.65 Gb Total Space | 56.81 Gb Free Space | 53.77% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
Drive I: | 6.12 Gb Total Space | 2.61 Gb Free Space | 42.72% Space Free | Partition Type: FAT32

Computer Name: YOUR-O0KWKW9JWC
Current User Name: Owner
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.html [@ = htmlfile] – C:\Program Files\Internet Explorer\IEXPLORE.EXE (Microsoft Corporation)

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
exefile [open] – "%1" %*
htmlfile – Reg Error: Key error.
htmlfile [open] – "C:\Program Files\Internet Explorer\IEXPLORE.EXE" -nohome (Microsoft Corporation)
htmlfile [opennew] – "C:\Program Files\Internet Explorer\IEXPLORE.EXE" %1 (Microsoft Corporation)
http [open] – "C:\Program Files\Internet Explorer\IEXPLORE.EXE" -nohome (Microsoft Corporation)
https [open] – "C:\Program Files\Internet Explorer\IEXPLORE.EXE" -nohome (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [cmd] – cmd.exe /k "cd %L" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Applications\iexplore.exe [open] – "C:\Program Files\Internet Explorer\IEXPLORE.EXE" %1 (Microsoft Corporation)
CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] – "%programfiles%\internet explorer\iexplore.exe" (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"AntiVirusDisableNotify" = 1
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 1
"AntiVirusOverride" = 0
"FirewallOverride" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
"DisableMonitoring" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
"DisableMonitoring" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]
"DisableMonitoring" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
"C:\Program Files\Windows Live\Messenger\livecall.exe" = C:\Program Files\Windows Live\Messenger\livecall.exe:*:Enabled:Windows Live Messenger (Phone) – (Microsoft Corporation)
"C:\Program Files\Qwest\QuickConnect\QuickConnect.exe" = C:\Program Files\Qwest\QuickConnect\QuickConnect.exe:*:Enabled:QuickConnect – (Qwest Communications International Inc.)

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files\Atari\Neverwinter Nights 2\nwn2main.exe" = C:\Program Files\Atari\Neverwinter Nights 2\nwn2main.exe:*:Enabled:Neverwinter Nights 2 Main – (Obsidian Entertainment, Inc.)
"C:\Program Files\Atari\Neverwinter Nights 2\nwn2main_amdxp.exe" = C:\Program Files\Atari\Neverwinter Nights 2\nwn2main_amdxp.exe:*:Enabled:Neverwinter Nights 2 AMD – (Obsidian Entertainment, Inc.)
"C:\Program Files\Atari\Neverwinter Nights 2\nwupdate.exe" = C:\Program Files\Atari\Neverwinter Nights 2\nwupdate.exe:*:Enabled:Neverwinter Nights 2 Updater – (Obsidian Entertainment, Inc.)
"C:\Program Files\Atari\Neverwinter Nights 2\nwn2server.exe" = C:\Program Files\Atari\Neverwinter Nights 2\nwn2server.exe:*:Enabled:Neverwinter Nights 2 Server – (Obsidian Entertainment, Inc.)
"C:\Program Files\Ventrilo\Ventrilo.exe" = C:\Program Files\Ventrilo\Ventrilo.exe:*:Enabled:Ventrilo.exe – ()
"C:\Program Files\Windows Live\Messenger\livecall.exe" = C:\Program Files\Windows Live\Messenger\livecall.exe:*:Enabled:Windows Live Messenger (Phone) – (Microsoft Corporation)
"C:\Program Files\Reality Pump\Two Worlds\TwoWorlds.exe" = C:\Program Files\Reality Pump\Two Worlds\TwoWorlds.exe:*:Enabled:Two Worlds – (Reality Pump)
"C:\Program Files\Reality Pump\Two Worlds\TwoWorlds_RADEON.exe" = C:\Program Files\Reality Pump\Two Worlds\TwoWorlds_RADEON.exe:*:Enabled:Two Worlds – (Reality Pump)
"C:\Program Files\Qwest\QuickConnect\QuickConnect.exe" = C:\Program Files\Qwest\QuickConnect\QuickConnect.exe:*:Enabled:QuickConnect – (Qwest Communications International Inc.)


========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{0613467F-A45E-4CB1-9ECE-1F3DD79FB927}" = easy Internet sign-up
"{08E9C35A-A0AE-43FA-AEA1-E4F58A87FBD1}" = Arcanum
"{09DA4F91-2A09-4232-AB8C-6BC740096DE3}" = Sonic Update Manager
"{0DC86BEC-5CE3-413A-BB61-C40A3D186B24}" = Scan
"{0FADC5B1-E0E8-4DCA-A1BF-8B3B6496207A}" = Form Fill (Windows Live Toolbar)
"{0FF18B53-CA57-40BB-B562-21A27B662005}" = 1600
"{1306C737-0AF4-46C7-B282-64E099304712}" = Smart Menus (Windows Live Toolbar)
"{14589F05-C658-4594-9429-D437BA688686}" = IntelliMover Data Transfer Demo
"{14BEB6DF-A499-4A38-8E06-E173BCD5C087}" = ScannerCopy
"{17293791-C82E-476C-9997-9A0FF234A19B}" = HP Product Assistant
"{181821B7-82AA-44DA-9DAF-EF254CCB670A}" = Fax
"{1AD5F465-8282-4DAD-B957-E09C0B783D18}" = InstantShare
"{1B680FBA-E317-4E93-AF43-3B59798A4BE0}" = Copy
"{1F7CCFA3-D926-4882-B2A5-A0217ED25597}" = PC-Doctor for Windows
"{20FBC0A0-3160-4F14-83ED-3A74BB6B8C31}" = TrayApp
"{26A24AE4-039D-4CA4-87B4-2F83216013FF}" = Java™ 6 Update 13
"{272EC8BA-5A08-4ea1-A189-684466A06B02}" = cp_dwShrek2Albums1
"{29D88826-2AB9-11D5-8854-00902761A46D}" = WordPerfect Productivity Pack
"{2A267BC6-F77F-4DD4-825F-7AEB1F68B4B1}" = HpSdpAppCoreApp
"{2D4F6BE3-6FEF-4FE9-9D01-1406B220D08C}" = Windows Live Photo Gallery
"{2E8428AD-6CD2-4031-916A-3CF9BBF2DEC9}" = Unload
"{2EEBAC31-3EEF-4118-91CB-1A286A507DB2}" = ESET NOD32 Antivirus
"{3248F0A8-6813-11D6-A77B-00B0D0150090}" = J2SE Runtime Environment 5.0 Update 9
"{3248F0A8-6813-11D6-A77B-00B0D0150100}" = J2SE Runtime Environment 5.0 Update 10
"{3248F0A8-6813-11D6-A77B-00B0D0150110}" = J2SE Runtime Environment 5.0 Update 11
"{3248F0A8-6813-11D6-A77B-00B0D0160010}" = Java™ SE Runtime Environment 6 Update 1
"{328420FA-7638-4AB1-81DF-E0FECEFF24E3}" = Windows Live Toolbar Feed Detector (Windows Live Toolbar)
"{342C7C88-D335-4bc2-8CF1-281857629CE2}" = HP PSC & OfficeJet 4.7
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{35E90FA5-2CB4-4039-A8BB-BE1B9DB94E21}" = HP Memories Disc
"{36FDBE6E-6684-462B-AE98-9A39A1B200CC}" = HP Product Assistant
"{3762DB2D-71BD-421F-9E55-C74DA7DF4D07}" = CueTour
"{391E18CE-7D3B-45E9-A8F0-34E77F14F47A}" = ProductContext
"{442BE28B-782B-4DC0-B490-E70A403B1C69}" = Readme
"{45EBDA59-D33B-433A-956E-B2F236468B56}" = MUSICMATCH® Jukebox
"{47D4AF7B-EDE6-4ADB-8D2F-0BDA25C7321F}" = HP Digital Imaging Album Printing 1.0
"{48BD24F5-13DE-493A-A7CE-28A85113FF0C}" = HP Deskjet printer preloaded drivers
"{4998FF95-709A-430A-B104-92A009ABB848}" = QuickConnect
"{4CCC7F68-A437-4559-A840-F5E010934951}" = HP Driver Diagnostics
"{4F5FC172-F0E7-4EA5-902F-8D005DF9F000}" = HP Photo and Imaging 1.2 - Photosmart Cameras
"{4FCC384C-18EA-4E25-9281-A06AE006D219}" = Weblink
"{508CE775-4BA4-4748-82DF-FE28DA9F03B0}" = Windows Live Messenger
"{5809E7CF-4DCF-11D4-9875-00105ACE7734}" = Logitech MouseWare 9.79
"{588C135F-0B15-4A02-8F2D-04697BE2904E}" = Icewind Dale II
"{59932D51-F260-4EF6-A784-4F69659F1A62}" = Map Button (Windows Live Toolbar)
"{5E8D588F-307C-4250-B622-26969027319A}" = PanoStandAlone
"{60E80B13-8649-4A69-85E2-1AE99E061F43}" = ShowBiz DVD
"{60E971B7-51A0-48CA-8687-C6B8F094A409}" = Simple Backup for My Pictures
"{644D04A2-C682-4FD5-977D-03B804C4B9C5}" = CreativeProjects
"{646A65DD-23FC-418E-B9F0-E0500FB42CB1}" = PhotoGallery
"{655CB07D-C944-40BE-B93F-55957CAC7625}" = AiO_Scan
"{66034137-F1CE-4CEF-8180-46553C54DB18}" = Popup Blocker (Windows Live Toolbar)
"{68963635-14A4-48D9-B431-DF3A74D1AAE1}" = Destinations
"{700A6597-3CE6-49C1-AA75-846B24CDA66D}" = BufferChm
"{71CB529E-21A4-42AD-BF38-564F08988633}" = Windows Live Outlook Toolbar (Windows Live Toolbar)
"{724517BD-1DE1-4986-BFCA-C1DFD379E3BC}" = cp_dwShrek2Cards1
"{74EC78BC-B379-4E29-9006-8F161DCAABA6}" = Apple Software Update
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{786C4AD1-DCBA-49A6-B0EF-B317A344BD66}" = Windows Live Favorites for Windows Live Toolbar
"{789289CA-F73A-4A16-A331-54D498CE069F}" = Ventrilo Client
"{7AD25C9F-9957-4D1C-95EF-9BCD09F6D31B}" = HPSystemDiagnostics
"{84CDF5A8-1D57-4B69-BAB6-1F11D8923375}" = SkinsHP1
"{85CFD253-38AE-4DB1-ACB7-F0F4C791990D}" = AiOSoftware
"{8777AC6D-89F9-4793-8266-DE406F343E89}" = QFolder
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8A708DD8-A5E6-11D4-A706-000629E95E20}" = Intel® Extreme Graphics Driver
"{8BC3B99B-A6BE-4A0B-8535-B1B94BA4B1B1}" = DocProc
"{8FC46258-0843-4D79-B7F0-F2B82FE6173B}" = Apple Mobile Device Support
"{929CE49F-1CA7-4CF3-A9A1-6D757443C63F}" = Microsoft Games for Windows - LIVE Redistributable
"{9422C8EA-B0C6-4197-B8FC-DC797658CA00}" = Windows Live Sign-in Assistant
"{9541FED0-327F-4DF0-8B96-EF57EF622F19}" = Sonic RecordNow!
"{95FC26FB-19FD-4A96-BBB1-B1062E8648F5}" = AGEIA PhysX v7.11.13
"{9692FD03-6662-4E62-B08C-30DFF51651E1}" = Actiontec Gateway
"{974C4B12-4D02-4879-85E0-61C95CC63E9E}" = Fallout 3
"{97AA0C55-AFAD-4126-B21C-F1318FB6DADA}" = Realtek RTL8139/810x Fast Ethernet NIC Driver Setup
"{98E8A2EF-4EAE-43B8-A172-74842B764777}" = InterVideo WinDVD Player
"{9E88DAA4-1352-4272-BA3A-897668408400}" = HP Photosmart printers preloaded drivers
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{A49F249F-0C91-497F-86DF-B2585E8E76B7}" = Microsoft Visual C++ 2005 Redistributable
"{A5B9D22C-755A-4AC6-9904-875E80838BB6}" = CP_AtenaShokunin1Config
"{A63E18AC-B504-4045-AFE6-A279BBABB988}" = Qwest QuickAssist Desktop Tools
"{A7E4ECCA-4A8E-4258-8EC8-2DCCF5B11320}" = Windows Live installer
"{AC76BA86-7AD7-1033-7B44-A70900000002}" = Adobe Reader 7.0.9
"{B42F73D4-AFDA-4761-B3F4-23A872D11339}" = Morrowind
"{B43357AA-3A6D-4D94-B56E-43C44D09E548}" = Microsoft .NET Framework (English)
"{B911B811-BA3E-46D4-90F8-6F3338359651}" = Director
"{BAF78226-3200-4DB4-BE33-4D922A799840}" = Windows Presentation Foundation
"{BD29EBAC-AD7D-4b27-B727-4CC6AC52D36B}" = MarketResearch
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{C6522325-92ED-4312-A45A-04E45896C130}" = WLTB Custom Buttons
"{C6876FE6-A314-4628-B0D7-F3EE5E35C4B4}" = Windows Live Toolbar
"{C8FD5BC1-92EF-4C15-92A9-F9AC7F61985F}" = HP Update
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{CB449D5A-7710-47aa-B9F5-352B877C90E6}" = 1600_Help
"{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}" = SUPERAntiSpyware Free Edition
"{CDFCF124-115F-4976-8BF4-08C89187A146}" = WebReg
"{CE0C8CC5-E396-442B-A50E-D1D374A9E820}" = DocumentViewer
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{D3F28364-8B10-45F1-8C2D-0037F4538BBB}" = Windows Live Toolbar Extension (Windows Live Toolbar)
"{D42B6F90-1084-4C9B-AF28-958926E6E32E}" = LP_Flash
"{D9044DCB-F8F9-4A81-9B06-ACAC1A59B261}" = QuickConnect
"{DF821FC5-C198-452B-A0D4-82433EFEAE9B}" = OneCare Advisor (Windows Live Toolbar)
"{EEF397AC-DAEF-4C04-90A9-5B2BD31875DC}" = Simple Installer - Multilanguage Version
"{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU]
"{F20C1251-1D0A-4944-B2AE-678581B33B19}" = Neverwinter Nights 2
"{F4C6CC40-1142-49be-A28C-7BBD36F0B41A}" = 1600Trb
"{F4E57F49-84B4-4CF2-B0A1-8CA1752BDF7E}" = OmniPass
"{F61F2821-694C-475F-99AB-6AF2EFDF40FD}" = Quicken 2003 New User Edition
"{F80BA35D-D1CD-4B8B-8129-9FC918F9D42D}" = Windows Vista Upgrade Advisor
"{FC22D020-3005-4715-8DF9-F3EDE81DEB3D}" = CreativeProjectsTemplates
"{FF70923C-8A51-47F4-A7E9-893C6D54EB68}" = TES Construction Set
"1ABC286C-DE10-4590-BEFF-4D0DFF5EA1EC" = GemMaster 3 from Hewlett-Packard Desktops (remove only)
"28BA89E7-2F60-4BE7-BAA2-7949EB3FE527" = BlasterBall Wild from Hewlett-Packard Desktops (remove only)
"357ECB62-CD36-4B63-B57E-769D0CA174F4" = Blasterball 2 from Hewlett-Packard Desktops (remove only)
"3EA6838C-5C34-4F9C-A8DA-434D65DD1356" = Men In Black II CROSSFIRE from Hewlett-Packard Desktops (remove only)
"4F0AE1FB-4082-4A27-8363-05D292D92FB0" = Virtual Warfare from Hewlett-Packard Desktops (remove only)
"5415BC25-6D6C-46C4-B34C-EA8470FE56D5" = Blackhawk Striker from Hewlett-Packard Desktops (remove only)
"63272979-21F0-48EF-9B97-A83DBC05BE39" = Disney`s Lilo and Stitch Pinball from Hewlett-Packard Desktops (remove only)
"753FE96B-D926-4B6C-BCFB-CC59153D004A" = Snowboard Extreme from Hewlett-Packard Desktops (remove only)
"7841B68B-B7DD-408E-8B45-D5CA39608185" = Dark Orbit from Hewlett-Packard Desktops (remove only)
"8c9c48d7-2d03-4a1f-a303-5bd22ccabae1" = RingMaster from Hewlett-Packard Desktops (remove only)
"9FA01E11-9015-4140-B10A-5C6AA949B2FC" = Space Rocks from Hewlett-Packard Desktops (remove only)
"Adobe Acrobat 5.0" = Adobe Acrobat 5.0
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"ArcSoft Software Suite" = ArcSoft Picture Software
"BackWeb-137903 Uninstaller" = Updates from HP
"DF479CEA-34C0-460F-9B56-93BCE4CD4086" = Excavation from Hewlett-Packard Desktops (remove only)
"Divine Divinity" = Divine Divinity
"Download Manager" = Download Manager 2.3.9
"Guild Wars" = Guild Wars
"HijackThis" = HijackThis 2.0.2
"hp instant support" = HP Instant Support
"HP Photo & Imaging" = HP Image Zone 4.7
"HPExtendedCapabilities" = HP Extended Capabilities 4.7
"HPTOOLKIT" = toolkit
"IDNMitigationAPIs" = Microsoft Internationalized Domain Names Mitigation APIs
"ie7" = Windows Internet Explorer 7
"ie8" = Windows Internet Explorer 8
"ieSpell" = ieSpell
"InstallShield_{0613467F-A45E-4CB1-9ECE-1F3DD79FB927}" = easy Internet sign-up
"InstallShield_{F61F2821-694C-475F-99AB-6AF2EFDF40FD}" = Quicken 2003 New User Edition
"Logitech Resource Center" = Logitech Resource Center
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Microsoft .NET Framework Full v1.0.3705 (1033)" = Microsoft .NET Framework (English) v1.0.3705
"MSCompPackV1" = Microsoft Compression Client Pack 1.0 for Windows XP
"NLSDownlevelMapping" = Microsoft National Language Support Downlevel APIs
"NVIDIA Drivers" = NVIDIA Drivers
"PS2" = PS2
"QwestQuickCare_is1" = Qwest Quickcare 2.5
"RealPlayer 6.0" = RealOne Player
"S3Display" = S3Display
"S3Gamma2" = S3Gamma2
"S3Info2" = S3Info2
"S3Overlay" = S3Overlay
"Star Trek Armada II" = Star Trek Armada II
"tv_enua" = Lernout & Hauspie TruVoice American English TTS Engine
"Two Worlds" = Two Worlds
"UltimateDefrag V1 FREE Public Domain Version" = UltimateDefrag V1 FREE Public Domain Version
"Windows Live Toolbar" = Windows Live Toolbar
"Windows Media Format Runtime" = Windows Media Format 11 runtime
"Windows Media Player" = Windows Media Player 11
"Windows XP Service Pack" = Windows XP Service Pack 3
"WMFDist11" = Windows Media Format 11 runtime
"wmp11" = Windows Media Player 11
"WordPerfect Productivity Pack" = WordPerfect Productivity Pack
"Wudf01000" = Microsoft User-Mode Driver Framework Feature Pack 1.0
"XpsEPSC" = XML Paper Specification Shared Components Pack 1.0

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 7/13/2009 2:19:58 AM | Computer Name = YOUR-O0KWKW9JWC | Source = nview_info | ID = 11141121
Description =

Error - 9/10/2009 7:50:01 PM | Computer Name = YOUR-O0KWKW9JWC | Source = quickcare | ID = 131073
Description = Support Provider: quickcare Job ID: eda99b64-a525-458a-8acb-7116d88e2977
Job
Status: Error creating process for job: name=Upload Qwest User Info, cmd="C:\Program
Files\Qwest\QuickCare\agentui\quickcare.exe" /url "file:\\C:\Program Files\Qwest\QuickCare\agentui\util\clientinfo.htm"
/title "Qwest Client Info Utility" /starthidden /ignoresingle

Error - 12/29/2009 5:59:07 PM | Computer Name = YOUR-O0KWKW9JWC | Source = Application Error | ID = 1000
Description = Faulting application fallout3.exe, version 1.0.0.12, faulting module
fallout3.exe, version 1.0.0.12, fault address 0x007fba9d.

Error - 12/29/2009 5:59:15 PM | Computer Name = YOUR-O0KWKW9JWC | Source = Application Error | ID = 1001
Description = Fault bucket 988806787.

Error - 1/4/2010 11:03:37 AM | Computer Name = YOUR-O0KWKW9JWC | Source = Application Error | ID = 1000
Description = Faulting application alg.exe, version 5.1.2600.5512, faulting module
unknown, version 0.0.0.0, fault address 0x00b0fecb.

Error - 1/5/2010 10:06:02 AM | Computer Name = YOUR-O0KWKW9JWC | Source = MsiInstaller | ID = 1013
Description = Product: ESET NOD32 Antivirus – A more recent version of ESET NOD32
Antivirus is already installed on this computer.

Error - 1/6/2010 9:26:11 AM | Computer Name = YOUR-O0KWKW9JWC | Source = MsiInstaller | ID = 1013
Description = Product: ESET NOD32 Antivirus – A more recent version of ESET NOD32
Antivirus is already installed on this computer.

Error - 1/7/2010 10:57:18 AM | Computer Name = YOUR-O0KWKW9JWC | Source = Application Error | ID = 1000
Description = Faulting application alg.exe, version 5.1.2600.5512, faulting module
unknown, version 0.0.0.0, fault address 0x00b0fecb.

Error - 1/7/2010 10:57:22 AM | Computer Name = YOUR-O0KWKW9JWC | Source = Application Error | ID = 1001
Description = Fault bucket 1218182392.

Error - 1/8/2010 11:10:22 AM | Computer Name = YOUR-O0KWKW9JWC | Source = Application Error | ID = 1000
Description = Faulting application alg.exe, version 5.1.2600.5512, faulting module
unknown, version 0.0.0.0, fault address 0x00b0fecb.

[ System Events ]
Error - 1/7/2010 8:32:34 AM | Computer Name = YOUR-O0KWKW9JWC | Source = Service Control Manager | ID = 7000
Description = The mrtRate service failed to start due to the following error: %%2

Error - 1/7/2010 10:53:55 AM | Computer Name = YOUR-O0KWKW9JWC | Source = Service Control Manager | ID = 7000
Description = The mrtRate service failed to start due to the following error: %%2

Error - 1/7/2010 10:57:27 AM | Computer Name = YOUR-O0KWKW9JWC | Source = Service Control Manager | ID = 7034
Description = The Application Layer Gateway Service service terminated unexpectedly.
It has done this 1 time(s).

Error - 1/7/2010 8:12:07 PM | Computer Name = YOUR-O0KWKW9JWC | Source = Service Control Manager | ID = 7000
Description = The mrtRate service failed to start due to the following error: %%2

Error - 1/7/2010 8:19:49 PM | Computer Name = YOUR-O0KWKW9JWC | Source = Service Control Manager | ID = 7000
Description = The mrtRate service failed to start due to the following error: %%2

Error - 1/8/2010 10:44:21 AM | Computer Name = YOUR-O0KWKW9JWC | Source = Service Control Manager | ID = 7000
Description = The mrtRate service failed to start due to the following error: %%2

Error - 1/8/2010 11:10:31 AM | Computer Name = YOUR-O0KWKW9JWC | Source = Service Control Manager | ID = 7034
Description = The Application Layer Gateway Service service terminated unexpectedly.
It has done this 1 time(s).

Error - 1/8/2010 11:25:26 AM | Computer Name = YOUR-O0KWKW9JWC | Source = Service Control Manager | ID = 7000
Description = The mrtRate service failed to start due to the following error: %%2

Error - 1/8/2010 2:54:16 PM | Computer Name = YOUR-O0KWKW9JWC | Source = Service Control Manager | ID = 7000
Description = The mrtRate service failed to start due to the following error: %%2

Error - 1/8/2010 8:48:14 PM | Computer Name = YOUR-O0KWKW9JWC | Source = Service Control Manager | ID = 7000
Description = The mrtRate service failed to start due to the following error: %%2


< End of report >
Hi six,

Did you fix anything with HijackThis or disable anything via msconfig?

Are these search redirects or browser redirects also?

Which browser do you use? How is your connection now?

Error - 1/6/2010 9:26:11 AM | Computer Name = YOUR-O0KWKW9JWC | Source = MsiInstaller | ID = 1013
Description = Product: ESET NOD32 Antivirus – A more recent version of ESET NOD32
Antivirus is already installed on this computer

It looks like you attempted to reinstall ESET with an older version to try to fix the problem.

Messenger left a lot of junk behind so we'll clean that up to make the log easier to read and I'll get you to do another OTL scan with a little different configuration.


Next, Double click on OTL.exe
  • Under the Custom Scans/Fixes box at the bottom, paste in the following
  • Do Not copy the word CODE
  • please note the fix starts with the :
:OTL
IE - HKCU\..\URLSearchHook: {EF99BD32-C1FB-11D2-892F-0090271D4F88} - Reg Error: Key error. File not found.
O3 - HKLM\..\Toolbar: (no name) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - No CLSID value found.
IE - HKLM\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 1
IE - HKLM\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local;
IE - HKLM\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = http=localhost:7171
O3 - HKCU\..\Toolbar\ShellBrowser: (no name) - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - No CLSID value found.
O4 - HKLM..\Run: [KernelFaultCheck] File not found
:Services

:Reg

:Files
C:\sqmdata*.sqm
C:\sqmnoopt*.sqm

:Commands
[CREATERESTOREPOINT]
[emptytemp]
[resethosts]
[Reboot]

Then click the Run Fix button at the top
  • Let the program run unhindered
  • Please save the resulting log to be posted in your next reply.
Please post the OTL fix log.


Next

Open OTL if it isn't still open an set it up like this

  • Double click on OTL.exe to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output
  • UNCheck the boxes beside LOP Check and Purity Check.
  • In the Services section set it to All
  • Under the Custom Scans/Fixes box at the bottom, paste in the following bold text

    hijackthisbackups
    msconfig
  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
When the scan completes, it will open a notepad window, OTL.Txt.

Please post back with
  • OTL fix log
  • OTL scan log.
Please answer any questions asked as best you can.

Thanks

Hi six,

Did you fix anything with HijackThis or disable anything via msconfig?

Are these search redirects or browser redirects also?

Which browser do you use? How is your connection now?

It looks like you attempted to reinstall ESET with an older version to try to fix the problem.

Hi again

#1 no
#2 search redirects only
#3 windows internet explorer, connection is the same, works if I get on right away but if I wait it locks out eset and won't let me connection through browsers.
#4 I stuck the eset disc in to see if reloading it would fix it a few days ago, it told me newer version available and I left it alone after that.
When I didn't manually start ESET right away at startup I get an error message saying "kernel not found" and it won't let me start it at all unless I restart the computer and manually start ESET right away.
Eset use to auto start when I booted up, any idea how I get it to do that again or why it stopped doing it?

Here are the logs you asked for, Thanks again for your time!!!

All processes killed
========== OTL ==========
Registry value HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks\\{EF99BD32-C1FB-11D2-892F-0090271D4F88} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{EF99BD32-C1FB-11D2-892F-0090271D4F88}\ deleted successfully.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\{EF99BD32-C1FB-11D2-892F-0090271D4F88} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{EF99BD32-C1FB-11D2-892F-0090271D4F88}\ not found.
HKLM\Software\Microsoft\Windows\CurrentVersion\Internet Settings\\ProxyEnable|dword:0 /E : value set successfully!
HKLM\Software\Microsoft\Windows\CurrentVersion\Internet Settings\\ProxyOverride| /E : value set successfully!
HKLM\Software\Microsoft\Windows\CurrentVersion\Internet Settings\\ProxyServer| /E : value set successfully!
Registry value HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\ShellBrowser\\{42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6}\ not found.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\KernelFaultCheck deleted successfully.
========== SERVICES/DRIVERS ==========
========== REGISTRY ==========
========== FILES ==========
C:\sqmdata00.sqm moved successfully.
C:\sqmdata01.sqm moved successfully.
C:\sqmdata02.sqm moved successfully.
C:\sqmdata03.sqm moved successfully.
C:\sqmdata04.sqm moved successfully.
C:\sqmdata05.sqm moved successfully.
C:\sqmdata06.sqm moved successfully.
C:\sqmdata07.sqm moved successfully.
C:\sqmdata08.sqm moved successfully.
C:\sqmdata09.sqm moved successfully.
C:\sqmdata10.sqm moved successfully.
C:\sqmdata11.sqm moved successfully.
C:\sqmdata12.sqm moved successfully.
C:\sqmdata13.sqm moved successfully.
C:\sqmdata14.sqm moved successfully.
C:\sqmdata15.sqm moved successfully.
C:\sqmdata16.sqm moved successfully.
C:\sqmdata17.sqm moved successfully.
C:\sqmdata18.sqm moved successfully.
C:\sqmdata19.sqm moved successfully.
C:\sqmnoopt00.sqm moved successfully.
C:\sqmnoopt01.sqm moved successfully.
C:\sqmnoopt02.sqm moved successfully.
C:\sqmnoopt03.sqm moved successfully.
C:\sqmnoopt04.sqm moved successfully.
C:\sqmnoopt05.sqm moved successfully.
C:\sqmnoopt06.sqm moved successfully.
C:\sqmnoopt07.sqm moved successfully.
C:\sqmnoopt08.sqm moved successfully.
C:\sqmnoopt09.sqm moved successfully.
C:\sqmnoopt10.sqm moved successfully.
C:\sqmnoopt11.sqm moved successfully.
C:\sqmnoopt12.sqm moved successfully.
C:\sqmnoopt13.sqm moved successfully.
C:\sqmnoopt14.sqm moved successfully.
C:\sqmnoopt15.sqm moved successfully.
C:\sqmnoopt16.sqm moved successfully.
C:\sqmnoopt17.sqm moved successfully.
C:\sqmnoopt18.sqm moved successfully.
C:\sqmnoopt19.sqm moved successfully.
========== COMMANDS ==========
Restore point Set: OTL Restore Point (64424509440)

[EMPTYTEMP]

User: All Users

User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 32902 bytes

User: LocalService
->Temp folder emptied: 65748 bytes
->Temporary Internet Files folder emptied: 33170 bytes

User: NetworkService
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 49286 bytes

User: Owner
->Temp folder emptied: 27034914 bytes
->Temporary Internet Files folder emptied: 92680817 bytes
->Java cache emptied: 33980880 bytes

User: TEMP
->Temporary Internet Files folder emptied: 32768 bytes

User: TEMP.YOUR-O0KWKW9JWC
->Temporary Internet Files folder emptied: 32768 bytes

User: TEMP.YOUR-O0KWKW9JWC.000
->Temporary Internet Files folder emptied: 32768 bytes

User: TEMP.YOUR-O0KWKW9JWC.001
->Temporary Internet Files folder emptied: 32768 bytes

User: TEMP.YOUR-O0KWKW9JWC.002
->Temporary Internet Files folder emptied: 32768 bytes

%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 219321 bytes
%systemroot%\System32 .tmp files removed: 2577 bytes
Windows Temp folder emptied: 2550572815 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 502056 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 33728 bytes
RecycleBin emptied: 0 bytes

Total Files Cleaned = 2,580.00 mb

C:\WINDOWS\System32\drivers\etc\Hosts moved successfully.
HOSTS file reset successfully

OTL by OldTimer - Version 3.1.21.2 log created on 01092010_082608

Files\Folders moved on Reboot…

Registry entries deleted on Reboot…

………..


OTL logfile created on: 1/9/2010 8:50:51 AM - Run 2
OTL by OldTimer - Version 3.1.21.2 Folder = C:\Documents and Settings\Owner\Desktop
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.13)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

3.00 Gb Total Physical Memory | 3.00 Gb Available Physical Memory | 84.00% Memory free
4.00 Gb Paging File | 4.00 Gb Available in Paging File | 90.00% Paging File free
Paging file location(s): C:\pagefile.sys 1536 3072 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 105.65 Gb Total Space | 59.26 Gb Free Space | 56.09% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
Drive I: | 6.12 Gb Total Space | 2.61 Gb Free Space | 42.72% Space Free | Partition Type: FAT32

Computer Name: YOUR-O0KWKW9JWC
Current User Name: Owner
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal

========== Processes (SafeList) ==========

PRC - C:\Documents and Settings\Owner\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\SUPERAntiSpyware\SUPERANTISPYWARE.EXE (SUPERAntiSpyware.com)
PRC - C:\Program Files\Java\jre6\bin\jqs.exe (Sun Microsystems, Inc.)
PRC - C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe (ESET)
PRC - C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe (ESET)
PRC - C:\WINDOWS\system32\nvsvc32.exe (NVIDIA Corporation)
PRC - C:\Program Files\Qwest\Quickcare\bin\sprtcmd.exe (SupportSoft, Inc.)
PRC - C:\Program Files\Windows Desktop Search\WindowsSearch.exe (Microsoft Corporation)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Common Files\SupportSoft\bin\sprtlisten.exe (SupportSoft, Inc.)
PRC - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe (Apple, Inc.)
PRC - C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqgalry.exe (Hewlett-Packard Co.)
PRC - C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqtra08.exe (Hewlett-Packard Co.)
PRC - C:\Program Files\Softex\OmniPass\omniServ.exe ()
PRC - C:\Program Files\Softex\OmniPass\OPXPApp.exe ()


========== Modules (SafeList) ==========

MOD - C:\Documents and Settings\Owner\Desktop\OTL.exe (OldTimer Tools)
MOD - C:\Program Files\Windows Desktop Search\MsnlNamespaceMgr.dll (Microsoft Corporation)
MOD - C:\Program Files\Qwest\Quickcare\bin\sprthook.dll (SupportSoft, Inc.)
MOD - C:\Program Files\SUPERAntiSpyware\SASSEH.DLL (SuperAdBlocker.com)
MOD - C:\WINDOWS\system32\msvcp60.dll (Microsoft Corporation)
MOD - C:\WINDOWS\system32\linkinfo.dll (Microsoft Corporation)


========== Win32 Services (All) ==========

SRV - (JavaQuickStarterService) – C:\Program Files\Java\jre6\bin\jqs.exe (Sun Microsystems, Inc.)
SRV - (lanmanworkstation) – C:\WINDOWS\system32\wkssvc.dll (Microsoft Corporation)
SRV - (EhttpSrv) – C:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe (ESET)
SRV - (ekrn) – C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe (ESET)
SRV - (NVSvc) – C:\WINDOWS\system32\nvsvc32.exe (NVIDIA Corporation)
SRV - (RpcSs) Remote Procedure Call (RPC) – C:\WINDOWS\system32\rpcss.dll (Microsoft Corporation)
SRV - (DcomLaunch) – C:\WINDOWS\system32\rpcss.dll (Microsoft Corporation)
SRV - (PlugPlay) – C:\WINDOWS\system32\services.exe (Microsoft Corporation)
SRV - (Eventlog) – C:\WINDOWS\system32\services.exe (Microsoft Corporation)
SRV - (SupportSoft RemoteAssist) – C:\Program Files\Common Files\SupportSoft\bin\ssrc.exe (SupportSoft, Inc.)
SRV - (FontCache3.0.0.0) – c:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe (Microsoft Corporation)
SRV - (idsvc) – C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe (Microsoft Corporation)
SRV - (NetTcpPortSharing) – C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe (Microsoft Corporation)
SRV - (clr_optimization_v2.0.50727_32) – C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
SRV - (aspnet_state) – C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe (Microsoft Corporation)
SRV - (EventSystem) – C:\WINDOWS\system32\es.dll (Microsoft Corporation)
SRV - (Nla) Network Location Awareness (NLA) – C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
SRV - (WSearch) – C:\WINDOWS\System32\SearchIndexer.exe (Microsoft Corporation)
SRV - (WmiApSrv) – C:\WINDOWS\system32\wbem\wmiapsrv.exe (Microsoft Corporation)
SRV - (VSS) – C:\WINDOWS\system32\vssvc.exe (Microsoft Corporation)
SRV - (UPS) – C:\WINDOWS\system32\ups.exe (Microsoft Corporation)
SRV - (Spooler) – C:\WINDOWS\system32\spoolsv.exe (Microsoft Corporation)
SRV - (HidServ) – C:\WINDOWS\system32\svchost.exe (Microsoft Corporation)
SRV - (AppMgmt) – C:\WINDOWS\system32\svchost.exe (Microsoft Corporation)
SRV - (SysmonLog) – C:\WINDOWS\system32\smlogsvc.exe (Microsoft Corporation)
SRV - (RDSessMgr) – C:\WINDOWS\system32\sessmgr.exe (Microsoft Corporation)
SRV - (SCardSvr) – C:\WINDOWS\system32\scardsvr.exe (Microsoft Corporation)
SRV - (NetDDEdsdm) – C:\WINDOWS\system32\netdde.exe (Microsoft Corporation)
SRV - (NetDDE) – C:\WINDOWS\system32\netdde.exe (Microsoft Corporation)
SRV - (MSIServer) – C:\WINDOWS\System32\msiexec.exe (Microsoft Corporation)
SRV - (MSDTC) – C:\WINDOWS\system32\msdtc.exe (Microsoft Corporation)
SRV - (mnmsrvc) – C:\WINDOWS\system32\mnmsrvc.exe (Microsoft Corporation)
SRV - (RpcLocator) Remote Procedure Call (RPC) – C:\WINDOWS\system32\locator.exe (Microsoft Corporation)
SRV - (SamSs) – C:\WINDOWS\system32\lsass.exe (Microsoft Corporation)
SRV - (ProtectedStorage) – C:\WINDOWS\system32\lsass.exe (Microsoft Corporation)
SRV - (PolicyAgent) – C:\WINDOWS\system32\lsass.exe (Microsoft Corporation)
SRV - (NtLmSsp) – C:\WINDOWS\system32\lsass.exe (Microsoft Corporation)
SRV - (Netlogon) – C:\WINDOWS\system32\lsass.exe (Microsoft Corporation)
SRV - (ImapiService) – C:\WINDOWS\system32\imapi.exe (Microsoft Corporation)
SRV - (Fax) – C:\WINDOWS\system32\fxssvc.exe (Microsoft Corporation)
SRV - (dmadmin) – C:\WINDOWS\System32\dmadmin.exe (Microsoft Corp., Veritas Software)
SRV - (SwPrv) – C:\WINDOWS\System32\dllhost.exe (Microsoft Corporation)
SRV - (COMSysApp) – C:\WINDOWS\System32\dllhost.exe (Microsoft Corporation)
SRV - (ClipSrv) – C:\WINDOWS\system32\clipsrv.exe (Microsoft Corporation)
SRV - (CiSvc) – C:\WINDOWS\system32\cisvc.exe (Microsoft Corporation)
SRV - (ALG) – C:\WINDOWS\system32\alg.exe (Microsoft Corporation)
SRV - (WZCSVC) – C:\WINDOWS\system32\wzcsvc.dll (Microsoft Corporation)
SRV - (xmlprov) – C:\WINDOWS\system32\xmlprov.dll (Microsoft Corporation)
SRV - (wuauserv) – C:\WINDOWS\system32\wuauserv.dll (Microsoft Corporation)
SRV - (wscsvc) – C:\WINDOWS\system32\wscsvc.dll (Microsoft Corporation)
SRV - (winmgmt) – C:\WINDOWS\system32\wbem\wmisvc.dll (Microsoft Corporation)
SRV - (stisvc) Windows Image Acquisition (WIA) – C:\WINDOWS\system32\wiaservc.dll (Microsoft Corporation)
SRV - (upnphost) – C:\WINDOWS\system32\upnphost.dll (Microsoft Corporation)
SRV - (W32Time) – C:\WINDOWS\system32\w32time.dll (Microsoft Corporation)
SRV - (WebClient) – C:\WINDOWS\system32\webclnt.dll (Microsoft Corporation)
SRV - (HTTPFilter) – C:\WINDOWS\system32\w3ssl.dll (Microsoft Corporation)
SRV - (TermService) – C:\WINDOWS\system32\termsrv.dll (Microsoft Corporation)
SRV - (TapiSrv) – C:\WINDOWS\system32\tapisrv.dll (Microsoft Corporation)
SRV - (srservice) – C:\WINDOWS\system32\srsvc.dll (Microsoft Corporation)
SRV - (lanmanserver) – C:\WINDOWS\system32\srvsvc.dll (Microsoft Corporation)
SRV - (TrkWks) – C:\WINDOWS\system32\trkwks.dll (Microsoft Corporation)
SRV - (SSDPSRV) – C:\WINDOWS\system32\ssdpsrv.dll (Microsoft Corporation)
SRV - (Schedule) – C:\WINDOWS\system32\schedsvc.dll (Microsoft Corporation)
SRV - (Themes) – C:\WINDOWS\system32\shsvcs.dll (Microsoft Corporation)
SRV - (ShellHWDetection) – C:\WINDOWS\system32\shsvcs.dll (Microsoft Corporation)
SRV - (FastUserSwitchingCompatibility) – C:\WINDOWS\system32\shsvcs.dll (Microsoft Corporation)
SRV - (SENS) – C:\WINDOWS\system32\sens.dll (Microsoft Corporation)
SRV - (seclogon) – C:\WINDOWS\system32\seclogon.dll (Microsoft Corporation)
SRV - (BITS) – C:\WINDOWS\system32\qmgr.dll (Microsoft Corporation)
SRV - (napagent) – C:\WINDOWS\system32\qagentrt.dll (Microsoft Corporation)
SRV - (RasMan) – C:\WINDOWS\system32\rasmans.dll (Microsoft Corporation)
SRV - (RasAuto) – C:\WINDOWS\system32\rasauto.dll (Microsoft Corporation)
SRV - (NtmsSvc) – C:\WINDOWS\system32\ntmssvc.dll (Microsoft Corporation)
SRV - (helpsvc) – C:\WINDOWS\PCHealth\HelpCtr\Binaries\pchsvc.dll (Microsoft Corporation)
SRV - (Netman) – C:\WINDOWS\system32\netman.dll (Microsoft Corporation)
SRV - (Messenger) – C:\WINDOWS\system32\msgsvc.dll (Microsoft Corporation)
SRV - (RemoteAccess) – C:\WINDOWS\system32\mprdim.dll (Microsoft Corporation)
SRV - (hkmsvc) – C:\WINDOWS\system32\kmsvc.dll (Microsoft Corporation)
SRV - (LmHosts) – C:\WINDOWS\system32\lmhsvc.dll (Microsoft Corporation)
SRV - (SharedAccess) Windows Firewall/Internet Connection Sharing (ICS) – C:\WINDOWS\system32\ipnathlp.dll (Microsoft Corporation)
SRV - (ERSvc) – C:\WINDOWS\system32\ersvc.dll (Microsoft Corporation)
SRV - (Dot3svc) – C:\WINDOWS\system32\dot3svc.dll (Microsoft Corporation)
SRV - (Dnscache) – C:\WINDOWS\system32\dnsrslvr.dll (Microsoft Corporation)
SRV - (EapHost) – C:\WINDOWS\system32\eapsvc.dll (Microsoft Corporation)
SRV - (dmserver) – C:\WINDOWS\system32\dmserver.dll (Microsoft Corp.)
SRV - (Dhcp) – C:\WINDOWS\system32\dhcpcsvc.dll (Microsoft Corporation)
SRV - (CryptSvc) – C:\WINDOWS\system32\cryptsvc.dll (Microsoft Corporation)
SRV - (Browser) – C:\WINDOWS\system32\browser.dll (Microsoft Corporation)
SRV - (AudioSrv) – C:\WINDOWS\system32\audiosrv.dll (Microsoft Corporation)
SRV - (Alerter) – C:\WINDOWS\system32\alrsvc.dll (Microsoft Corporation)
SRV - (sprtlisten) – C:\Program Files\Common Files\supportsoft\bin\sprtlisten.exe (SupportSoft, Inc.)
SRV - (WLSetupSvc) – C:\Program Files\Windows Live\installer\WLSetupSvc.exe (Microsoft Corporation)
SRV - (usnjsvc) – C:\Program Files\Windows Live\Messenger\usnsvc.exe (Microsoft Corporation)
SRV - (Pml Driver HPZ12) – C:\WINDOWS\system32\HPZipm12.exe (HP)
SRV - (Apple Mobile Device) – C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe (Apple, Inc.)
SRV - (WmdmPmSN) – C:\WINDOWS\system32\mspmsnsv.dll (Microsoft Corporation)
SRV - (WMPNetworkSvc) – C:\Program Files\Windows Media Player\WMPNetwk.exe (Microsoft Corporation)
SRV - (WudfSvc) – C:\WINDOWS\system32\WudfSvc.dll (Microsoft Corporation)
SRV - (omniserv) – C:\Program Files\Softex\OmniPass\omniServ.exe ()
SRV - (Pml Driver HPH11) – C:\WINDOWS\system32\hphipm11.exe (HP)
SRV - (RSVP) – C:\WINDOWS\system32\rsvp.exe (Microsoft Corporation)


========== Driver Services (SafeList) ==========

DRV - (SASKUTIL) – C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (SASENUM) – C:\Program Files\SUPERAntiSpyware\SASENUM.SYS ( SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (SASDIFSV) – C:\Program Files\SUPERAntiSpyware\sasdifsv.sys (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (epfwtdir) – C:\WINDOWS\system32\drivers\epfwtdir.sys (ESET)
DRV - (ehdrv) – C:\WINDOWS\system32\drivers\ehdrv.sys (ESET)
DRV - (eamon) – C:\WINDOWS\system32\drivers\eamon.sys (ESET)
DRV - (RTL8023xp) – C:\WINDOWS\system32\drivers\Rtnicxp.sys (Realtek Semiconductor Corporation )
DRV - (nv) – C:\WINDOWS\system32\drivers\nv4_mini.sys (NVIDIA Corporation)
DRV - (Secdrv) – C:\WINDOWS\system32\drivers\secdrv.sys (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.)
DRV - (PxHelp20) – C:\WINDOWS\System32\DRIVERS\PxHelp20.sys (Sonic Solutions)
DRV - (hamachi_oem) – C:\WINDOWS\system32\drivers\gan_adapter.sys (Applied Networking Inc.)
DRV - (Ps2) – C:\WINDOWS\system32\drivers\PS2.sys (Hewlett-Packard Company)
DRV - (HPZius12) – C:\WINDOWS\system32\drivers\HPZius12.sys (HP)
DRV - (HPZipr12) – C:\WINDOWS\system32\drivers\HPZipr12.sys (HP)
DRV - (HPZid412) – C:\WINDOWS\system32\drivers\HPZid412.sys (HP)
DRV - (AFS2K) – C:\WINDOWS\system32\drivers\AFS2K.SYS (Oak Technology Inc.)
DRV - (ALCXWDM) Service for Realtek AC97 Audio (WDM) – C:\WINDOWS\system32\drivers\ALCXWDM.SYS (Realtek Semiconductor Corp.)
DRV - (S3Psddr) – C:\WINDOWS\system32\drivers\s3gnbm.sys (S3 Graphics, Inc.)
DRV - (ltmodem5) – C:\WINDOWS\system32\drivers\ltmdmnt.sys (Agere Systems)
DRV - (LMouFlt2) – C:\WINDOWS\system32\drivers\LMouFlt2.Sys (Logitech, Inc.)
DRV - (L8042pr2) – C:\WINDOWS\system32\drivers\L8042pr2.Sys (Logitech, Inc.)
DRV - (MxlW2k) – C:\WINDOWS\system32\drivers\MxlW2k.sys (MusicMatch, Inc.)
DRV - ({6080A529-897E-4629-A488-ABA0C29B635E}) Intel® Graphics Platform (SoftBIOS) – C:\WINDOWS\system32\drivers\ialmsbw.sys (Intel Corporation)
DRV - ({D31A0762-0CEB-444e-ACFF-B049A1F6FE91}) Intel® Graphics Chipset (KCH) – C:\WINDOWS\system32\drivers\ialmkchw.sys (Intel Corporation)
DRV - (ialm) – C:\WINDOWS\system32\drivers\ialmnt5.sys (Intel Corporation)
DRV - (SiS315) – C:\WINDOWS\system32\drivers\sisgrp.sys (Silicon Integrated Systems Corporation)
DRV - (fasttx2k) – C:\WINDOWS\System32\DRIVERS\fasttx2k.sys (Promise Technology, Inc.)
DRV - (viaagp1) – C:\WINDOWS\System32\DRIVERS\viaagp1.sys (VIA Technologies, Inc.)
DRV - (SISAGP) – C:\WINDOWS\System32\DRIVERS\SISAGPX.sys (Silicon Integrated Systems Corporation)
DRV - (drvmcdb) – C:\WINDOWS\System32\DRIVERS\drvmcdb.sys (VERITAS Software, Inc.)
DRV - (rtl8139) – C:\WINDOWS\system32\drivers\R8139n51.sys (Realtek Semiconductor Corporation )
DRV - (pfc) – C:\WINDOWS\system32\drivers\pfc.sys (Padus, Inc.)
DRV - (nv_agp) – C:\WINDOWS\System32\DRIVERS\nv_agp.sys (NVIDIA Corporation)
DRV - (Ptilink) – C:\WINDOWS\system32\drivers\ptilink.sys (Parallel Technologies, Inc.)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://qwest.live.com
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Secondary Start Pages = [Binary data over 100 bytes]
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://qwest.live.com
IE - HKLM\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKLM\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" =
IE - HKLM\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" =

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://qwest.live.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://srch-us8.hpwis.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://srch-us8.hpwis.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://my.yahoo.com/
IE - HKCU\Software\Microsoft\Internet Explorer\SearchURL\CNNSI, = search.sportsillustrated.cnn.com/pages/search.jsp?query=%s
IE - HKCU\Software\Microsoft\Internet Explorer\SearchURL\Dictionary, = dictionary.reference.com/search?q=%s
IE - HKCU\Software\Microsoft\Internet Explorer\SearchURL\Google, = google.com/search?q=%s
IE - HKCU\Software\Microsoft\Internet Explorer\SearchURL\GoogleGroups, = groups-beta.google.com/groups?q=%s
IE - HKCU\Software\Microsoft\Internet Explorer\SearchURL\GoogleImages, = images.google.com/images?hl=en&lr=&q=%s
IE - HKCU\Software\Microsoft\Internet Explorer\SearchURL\GoogleNews, = news.google.com/news?tab=gn&hl=en&ie=UTF-8&q=%s&btnG=Search+News
IE - HKCU\Software\Microsoft\Internet Explorer\SearchURL\KB, = support.microsoft.com/search/default.aspx?query=%s
IE - HKCU\Software\Microsoft\Internet Explorer\SearchURL\KBDLL, = support.microsoft.com/dllhelp/default.aspx?dlltype=file&l=55&alpha=%s&S=1
IE - HKCU\Software\Microsoft\Internet Explorer\SearchURL\Movies, = fandango.com/my_box_office.asp?searchby=2&txtCityZip=%s
IE - HKCU\Software\Microsoft\Internet Explorer\SearchURL\MSN, = search.msn.com/results.asp?q=%s
IE - HKCU\Software\Microsoft\Internet Explorer\SearchURL\Thesaurus, = thesaurus.reference.com/search?q=%s
IE - HKCU\Software\Microsoft\Internet Explorer\SearchURL\Weather, = weather.com/weather/local/%s
IE - HKCU\Software\Microsoft\Internet Explorer\SearchURL\Yahoo, = search.yahoo.com/search?p=%s
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

FF - HKLM\software\mozilla\Thunderbird\Extensions\\[removed]: C:\Program Files\ESET\ESET NOD32 Antivirus\Mozilla Thunderbird [2009/06/11 17:50:23 | 00,000,000 | —D | M]

[2009/04/28 16:27:16 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Mozilla\Extensions

O1 HOSTS File: (98 bytes) - C:\WINDOWS\system32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (Windows Live Toolbar Helper) - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll (Microsoft Corporation)
O2 - BHO: (JQSIEStartDetectorImpl Class) - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll (Sun Microsystems, Inc.)
O3 - HKLM\..\Toolbar: (hp toolkit) - {B2847E28-5D7D-4DEB-8B67-05D28BCF79F5} - C:\hp\EXPLOREBAR\HPTOOLKT.DLL (Hewlett-Packard Company)
O3 - HKLM\..\Toolbar: (Windows Live Toolbar) - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll (Microsoft Corporation)
O3 - HKCU\..\Toolbar\ShellBrowser: (hp toolkit) - {B2847E28-5D7D-4DEB-8B67-05D28BCF79F5} - C:\hp\EXPLOREBAR\HPTOOLKT.DLL (Hewlett-Packard Company)
O3 - HKCU\..\Toolbar\WebBrowser: (hp toolkit) - {B2847E28-5D7D-4DEB-8B67-05D28BCF79F5} - C:\hp\EXPLOREBAR\HPTOOLKT.DLL (Hewlett-Packard Company)
O3 - HKCU\..\Toolbar\WebBrowser: (Windows Live Toolbar) - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll (Microsoft Corporation)
O4 - HKLM..\Run: [NvCplDaemon] C:\WINDOWS\System32\NvCpl.DLL (NVIDIA Corporation)
O4 - HKLM..\Run: [QuickCare] C:\Program Files\Qwest\Quickcare\bin\sprtcmd.exe (SupportSoft, Inc.)
O4 - HKCU..\Run: [igndlm.exe] C:\Program Files\Download Manager\DLM.exe (IGN Entertainment)
O4 - HKCU..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERANTISPYWARE.EXE (SUPERAntiSpyware.com)
O4 - HKCU..\Run: [updateMgr] C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe (Adobe Systems Incorporated)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe (Adobe Systems Incorporated)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk = C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqtra08.exe (Hewlett-Packard Co.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\HP Image Zone Fast Start.lnk = C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqthb08.exe (Hewlett-Packard Co.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Quicken Scheduled Updates.lnk = C:\Program Files\Quicken\bagent.exe (Intuit Inc.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Updates from HP.lnk = C:\Program Files\Updates from HP\137903\Program\BackWeb-137903.exe File not found
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Windows Search.lnk = C:\Program Files\Windows Desktop Search\WindowsSearch.exe (Microsoft Corporation)
O4 - Startup: C:\Documents and Settings\Owner\Start Menu\Programs\Startup\GameSpot Download Manager.lnk = C:\Program Files\GameSpot\GameSpotDownloadManager_Win32.exe File not found
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O8 - Extra context menu item: &ieSpell Options - C:\Program Files\ieSpell\iespell.dll (Red Egg Software)
O8 - Extra context menu item: &Windows Live Search - C:\Program Files\Windows Live Toolbar\msntb.dll (Microsoft Corporation)
O8 - Extra context menu item: Check &Spelling - C:\Program Files\ieSpell\iespell.dll (Red Egg Software)
O8 - Extra context menu item: Lookup on Merriam Webster - C:\Program Files\ieSpell\Merriam Webster.HTM ()
O8 - Extra context menu item: Lookup on Wikipedia - C:\Program Files\ieSpell\wikipedia.HTM ()
O9 - Extra Button: ieSpell - {0E17D5B7-9F5D-4fee-9DF6-CA6EE38B68A8} - C:\Program Files\ieSpell\iespell.dll (Red Egg Software)
O9 - Extra 'Tools' menuitem : ieSpell - {0E17D5B7-9F5D-4fee-9DF6-CA6EE38B68A8} - C:\Program Files\ieSpell\iespell.dll (Red Egg Software)
O9 - Extra 'Tools' menuitem : ieSpell Options - {1606D6F9-9D3B-4aea-A025-ED5B2FD488E7} - C:\Program Files\ieSpell\iespell.dll (Red Egg Software)
O12 - Plugin for: .spop - C:\Program Files\Internet Explorer\PLUGINS\NPDocBox.dll (InterTrust Technologies Corporation, Inc.)
O15 - HKLM\..Trusted Domains: 1 domain(s) and sub-domain(s) not assigned to a zone.
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} http://a1540.g.akamai.net/7/1540/52/200705…ex/qtplugin.cab (Reg Error: Key error.)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://download.microsoft.com/download/8/b…heckControl.cab (Windows Genuine Advantage Validation Tool)
O16 - DPF: {39B0684F-D7BF-4743-B050-FDC3F48F7E3B} http://www.fileplanet.com/fpdlmgr/cabs/FPDC_2.3.9.113.cab (CDownloadCtrl Object)
O16 - DPF: {44990301-3C9D-426D-81DF-AAB636FA4345} https://www-secure.symantec.com/techsupp/as…abs/tgctlsr.cab (Symantec Script Runner Class)
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} http://update.microsoft.com/windowsupdate/…b?1162338879046 (WUWebControl Class)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} http://update.microsoft.com/microsoftupdat…b?1222980964593 (MUWebControl Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {A90A5822-F108-45AD-8482-9BC8B12DD539} http://www.crucial.com/controls/cpcScanner.cab (Crucial cpcScan)
O16 - DPF: {A9F8D9EC-3D0A-4A60-BD82-FBD64BAD370D} http://h20264.www2.hp.com/ediags/dd/instal…nosticsxp2k.cab (DDRevision Class)
O16 - DPF: {CAFEEFAC-0015-0000-0009-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-…indows-i586.cab (Java Plug-in 1.5.0_09)
O16 - DPF: {CAFEEFAC-0015-0000-0010-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-…indows-i586.cab (Java Plug-in 1.5.0_10)
O16 - DPF: {CAFEEFAC-0015-0000-0011-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-…indows-i586.cab (Java Plug-in 1.5.0_11)
O16 - DPF: {CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_01)
O16 - DPF: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload.macromedia.com/get/flash…ent/swflash.cab (Shockwave Flash Object)
O16 - DPF: {FFBB3F3B-0A5A-4106-BE53-DFE1E2340CB1} http://dlm.tools.akamai.com/dlmanager/vers…vex-2.2.2.1.cab (Reg Error: Key error.)
O16 - DPF: DirectAnimation Java Classes file://C:\WINDOWS\Java\classes\dajava.cab (Reg Error: Key error.)
O16 - DPF: Microsoft XML Parser for Java file://C:\WINDOWS\Java\classes\xmldso.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.2.1
O18 - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\Windows Live\Messenger\msgrapp.8.5.1302.1018.dll (Microsoft Corporation)
O18 - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\Windows Live\Messenger\msgrapp.8.5.1302.1018.dll (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\!SASWinLogon: DllName - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL (SUPERAntiSpyware.com)
O20 - Winlogon\Notify\igfxcui: DllName - igfxsrvc.dll - C:\WINDOWS\System32\igfxsrvc.dll (Intel Corporation)
O20 - Winlogon\Notify\OPXPGina: DllName - C:\Program Files\Softex\OmniPass\opxpgina.dll - C:\Program Files\Softex\OmniPass\OPXPGina.dll ()
O28 - HKLM ShellExecuteHooks: {56F9679E-7826-4C84-81F3-532071A8BCC5} - C:\Program Files\Windows Desktop Search\MsnlNamespaceMgr.dll (Microsoft Corporation)
O28 - HKLM ShellExecuteHooks: {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - C:\Program Files\SUPERAntiSpyware\SASSEH.DLL (SuperAdBlocker.com)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2003/04/09 22:19:17 | 00,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O32 - AutoRun File - [2001/07/28 07:07:38 | 00,000,000 | -HS- | M] () - I:\AUTOEXEC.BAT – [ FAT32 ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - comfile [open] – "%1" %*
O35 - exefile [open] – "%1" %*

MsConfig - State: "system.ini" - 0
MsConfig - State: "win.ini" - 0
MsConfig - State: "bootini" - 0
MsConfig - State: "services" - 0
MsConfig - State: "startup" - 0

========== Files/Folders - Created Within 30 Days ==========

[2010/01/09 08:26:08 | 00,000,000 | —D | C] – C:\_OTL
[2010/01/08 18:59:23 | 00,513,536 | —- | C] (OldTimer Tools) – C:\Documents and Settings\Owner\Desktop\OTL.exe
[2010/01/07 05:38:16 | 00,000,000 | —D | C] – C:\Program Files\Trend Micro
[2009/07/21 22:14:30 | 00,000,000 | —D | M] – C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft
[2009/06/04 10:22:13 | 00,000,000 | —D | M] – C:\Documents and Settings\LocalService\Local Settings\Application Data\ESET
[2009/04/28 16:25:18 | 00,000,000 | —D | M] – C:\Documents and Settings\NetworkService\Application Data\Mozilla
[2007/07/30 19:03:22 | 00,000,000 | —D | M] – C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft
[2007/07/19 21:31:58 | 00,000,000 | –SD | M] – C:\Documents and Settings\NetworkService\Application Data\Microsoft
[2006/11/01 21:16:30 | 00,000,000 | –SD | M] – C:\Documents and Settings\LocalService\Application Data\Microsoft

========== Files - Modified Within 30 Days ==========

[2010/01/09 08:31:10 | 00,205,272 | —- | M] () – C:\WINDOWS\System32\nvapps.xml
[2010/01/09 08:31:05 | 00,000,254 | —- | M] () – C:\WINDOWS\tasks\Check Updates for Windows Live Toolbar.job
[2010/01/09 08:30:59 | 00,001,158 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2010/01/09 08:30:44 | 00,000,006 | -H– | M] () – C:\WINDOWS\tasks\SA.DAT
[2010/01/09 08:30:41 | 00,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2010/01/09 08:30:38 | 32,205,57824 | -HS- | M] () – C:\hiberfil.sys
[2010/01/09 08:29:04 | 04,718,592 | -H– | M] () – C:\Documents and Settings\Owner\NTUSER.DAT
[2010/01/09 08:29:04 | 00,000,178 | -HS- | M] () – C:\Documents and Settings\Owner\ntuser.ini
[2010/01/09 08:29:00 | 00,000,268 | -H– | M] () – C:\sqmdata00.sqm
[2010/01/09 08:29:00 | 00,000,244 | -H– | M] () – C:\sqmnoopt00.sqm
[2010/01/09 08:28:23 | 00,000,098 | —- | M] () – C:\WINDOWS\System32\drivers\etc\Hosts
[2010/01/09 00:34:02 | 06,435,682 | -H– | M] () – C:\Documents and Settings\Owner\Local Settings\Application Data\IconCache.db
[2010/01/08 18:59:23 | 00,513,536 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Owner\Desktop\OTL.exe
[2010/01/08 17:29:22 | 00,284,915 | —- | M] () – C:\Documents and Settings\Owner\Desktop\gmer.zip
[2010/01/07 05:38:18 | 00,001,745 | —- | M] () – C:\Documents and Settings\Owner\Desktop\HijackThis.lnk

========== Files Created - No Company Name ==========

[2010/01/09 08:29:00 | 00,000,268 | -H– | C] () – C:\sqmdata00.sqm
[2010/01/09 08:29:00 | 00,000,244 | -H– | C] () – C:\sqmnoopt00.sqm
[2010/01/08 17:29:48 | 00,284,915 | —- | C] () – C:\Documents and Settings\Owner\Desktop\gmer.zip
[2010/01/07 05:38:17 | 00,001,745 | —- | C] () – C:\Documents and Settings\Owner\Desktop\HijackThis.lnk
[2009/09/10 11:43:49 | 00,095,856 | —- | C] () – C:\Documents and Settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
[2009/06/10 07:36:07 | 00,000,911 | —- | C] () – C:\WINDOWS\STA2.ini
[2009/04/28 15:25:03 | 00,002,928 | —- | C] () – C:\Documents and Settings\NetworkService\Local Settings\Application Data\81F79ABC-AB11-494C-859E-88424AA60ADF.txt
[2009/04/28 15:24:16 | 00,003,756 | —- | C] () – C:\Documents and Settings\Owner\Local Settings\Application Data\81F79ABC-AB11-494C-859E-88424AA60ADF.txt
[2008/11/18 17:34:20 | 00,000,262 | —- | C] () – C:\WINDOWS\{789289CA-F73A-4A16-A331-54D498CE069F}_WiseFW.ini
[2008/07/21 16:14:10 | 00,073,728 | —- | C] () – C:\WINDOWS\System32\RtNicProp32.dll
[2007/11/26 21:56:28 | 00,151,415 | —- | C] () – C:\WINDOWS\System32\xlive.dll.cat
[2007/09/27 10:51:02 | 00,020,698 | —- | C] () – C:\WINDOWS\System32\idxcntrs.ini
[2007/09/27 10:48:48 | 00,030,628 | —- | C] () – C:\WINDOWS\System32\gsrvctr.ini
[2007/09/27 10:48:28 | 00,031,698 | —- | C] () – C:\WINDOWS\System32\gthrctr.ini
[2007/07/23 08:03:32 | 00,053,248 | —- | C] () – C:\WINDOWS\System32\AgCPanelTraditionalChinese.dll
[2007/07/23 08:03:32 | 00,053,248 | —- | C] () – C:\WINDOWS\System32\AgCPanelSwedish.dll
[2007/07/23 08:03:32 | 00,053,248 | —- | C] () – C:\WINDOWS\System32\AgCPanelSpanish.dll
[2007/07/23 08:03:30 | 00,053,248 | —- | C] () – C:\WINDOWS\System32\AgCPanelSimplifiedChinese.dll
[2007/07/23 08:03:30 | 00,053,248 | —- | C] () – C:\WINDOWS\System32\AgCPanelPortugese.dll
[2007/07/23 08:03:30 | 00,053,248 | —- | C] () – C:\WINDOWS\System32\AgCPanelKorean.dll
[2007/07/23 08:03:30 | 00,053,248 | —- | C] () – C:\WINDOWS\System32\AgCPanelJapanese.dll
[2007/07/23 08:03:30 | 00,053,248 | —- | C] () – C:\WINDOWS\System32\AgCPanelGerman.dll
[2007/07/23 08:03:30 | 00,053,248 | —- | C] () – C:\WINDOWS\System32\AgCPanelFrench.dll
[2006/12/30 02:29:35 | 00,006,144 | —- | C] () – C:\Documents and Settings\Owner\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2006/12/02 18:13:19 | 00,000,214 | —- | C] () – C:\WINDOWS\HP_48BitScanUpdatePatch.ini
[2006/11/24 18:24:46 | 00,021,840 | —- | C] () – C:\WINDOWS\System32\SIntfNT.dll
[2006/11/24 18:24:45 | 00,017,212 | —- | C] () – C:\WINDOWS\System32\SIntf32.dll
[2006/11/24 18:24:45 | 00,012,067 | —- | C] () – C:\WINDOWS\System32\SIntf16.dll
[2006/11/14 19:57:18 | 00,000,000 | —- | C] () – C:\WINDOWS\iPlayer.INI
[2006/11/08 05:52:36 | 00,061,678 | —- | C] () – C:\Documents and Settings\Owner\Application Data\PFP100JPR.{PB
[2006/11/08 05:52:36 | 00,012,358 | —- | C] () – C:\Documents and Settings\Owner\Application Data\PFP100JCM.{PB
[2006/11/01 16:23:02 | 00,000,128 | —- | C] () – C:\Documents and Settings\Owner\Local Settings\Application Data\fusioncache.dat
[2006/11/01 15:52:30 | 00,001,109 | —- | C] () – C:\Documents and Settings\All Users\Application Data\hpzinstall.log
[2006/10/31 16:40:31 | 00,019,968 | —- | C] () – C:\WINDOWS\System32\cpuinf32.dll
[2006/08/11 21:45:20 | 00,581,632 | —- | C] () – C:\WINDOWS\System32\nvhwvid.dll
[2006/08/11 21:43:00 | 01,724,416 | —- | C] () – C:\WINDOWS\System32\nvwdmcpl.dll
[2006/08/11 21:43:00 | 01,101,824 | —- | C] () – C:\WINDOWS\System32\nvwimg.dll
[2006/08/11 21:43:00 | 00,286,720 | —- | C] () – C:\WINDOWS\System32\nvnt4cpl.dll
[2004/09/13 16:35:56 | 00,000,000 | —- | C] () – C:\WINDOWS\System32\px.ini
[2003/04/10 04:35:00 | 00,000,061 | —- | C] () – C:\WINDOWS\smscfg.ini
[2003/04/10 04:21:36 | 00,000,051 | —- | C] () – C:\WINDOWS\System32\mshrml.ini
[2003/04/10 01:51:07 | 00,000,438 | —- | C] () – C:\WINDOWS\System32\1_ssetup.ini
[2003/04/10 01:51:07 | 00,000,000 | —- | C] () – C:\WINDOWS\System32\sunistlog.ini
[2003/04/10 00:32:34 | 00,094,208 | —- | C] () – C:\WINDOWS\System32\PcdrKernelModeServices.dll
[2003/04/10 00:32:34 | 00,077,824 | —- | C] () – C:\WINDOWS\System32\ProgressTrace.dll
[2003/04/10 00:06:10 | 00,167,936 | —- | C] () – C:\WINDOWS\System32\PCDrJNI_1_1.dll
[2003/04/10 00:03:38 | 00,045,056 | —- | C] () – C:\WINDOWS\System32\hpreg.dll
[2003/04/10 00:03:38 | 00,024,576 | —- | C] () – C:\WINDOWS\System32\syscontr.dll
[2003/04/09 23:57:15 | 00,000,052 | —- | C] () – C:\WINDOWS\intuprof.ini
[2003/04/09 23:57:04 | 00,000,626 | —- | C] () – C:\WINDOWS\QUICKEN.INI
[2003/04/09 23:16:44 | 00,001,793 | —- | C] () – C:\WINDOWS\System32\fxsperf.ini
[2003/04/09 23:08:03 | 00,466,944 | —- | C] () – C:\WINDOWS\System32\nvshell.dll
[2003/04/09 23:08:01 | 01,507,328 | —- | C] () – C:\WINDOWS\System32\nview.dll
[2003/04/09 22:55:02 | 00,363,520 | —- | C] () – C:\WINDOWS\System32\psisdecd.dll
[2003/04/09 22:44:58 | 00,299,073 | —- | C] () – C:\WINDOWS\System32\PythonCOM22.dll
[2003/04/09 22:44:58 | 00,065,536 | —- | C] () – C:\WINDOWS\System32\PyWinTypes22.dll
[2003/04/09 22:44:29 | 00,016,896 | —- | C] () – C:\WINDOWS\System32\bcbmm.dll
[2003/04/09 22:23:21 | 00,000,802 | —- | C] () – C:\WINDOWS\orun32.ini
[2003/04/09 22:05:45 | 00,000,659 | —- | C] () – C:\WINDOWS\System32\oeminfo.ini
[2001/08/14 18:47:08 | 00,020,480 | —- | C] () – C:\WINDOWS\System32\vxpsapi.dll

========== Custom Scans ==========



========== HijackThis Backups ==========

C:\Program Files\Trend Micro\HijackThis\backups\backup-20100108-172739-582
O3 - Toolbar: (no name) - {90222687-F593-4738-B738-FBEE9C7B26DF} - (no file)

C:\Program Files\Trend Micro\HijackThis\backups\backup-20100108-172739-803
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local;

C:\Program Files\Trend Micro\HijackThis\backups\backup-20100108-172739-885
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=localhost:7171

======= End HijackThis Backups =========

< End of report >
Hi six,

We'll flush the DNS cache

  • Now go to Start > Run > type: cmd
  • Press OK or Hit Enter.
  • At the command prompt, type or copy/paste: ipconfig /flushdns (note the space between “..g /f…” it needs to be there)
  • Hit Enter.
  • You will get a confirmation that the flush was successful.
  • Close the command box.

Regarding ESET, there is a registry key missing to start it at startup. The services appear to be there but I don't know their status. The key we may be able to replace. Would you be able to get a copy of the current version of ESET should it come to reinstalling it?

Run OTL the same way but this time change the Output to Standard. This will show the status of the services and drivers.

Reboot and run OTL before you manually start ESET. This way we can see the status of the ESET services on startup.

Try searching again and let us know if you are still being redirected and to where.

Please post the OTL log.

Thanks

Regarding ESET, there is a registry key missing to start it at startup. The services appear to be there but I don't know their status. The key we may be able to replace. Would you be able to get a copy of the current version of ESET should it come to reinstalling it?

I still have the disc for ESET if thats what you mean? It just updates itself online after being installed doesn't it?

I flushed things as instructed and did a few searches and had no problems, it wasn't redirecting me everytime before but I didn't have any troubles in the ones I just did.

Here is the newest OTL log, I did it right after startup and before starting ESET.

OTL logfile created on: 1/9/2010 3:24:16 PM - Run 3
OTL by OldTimer - Version 3.1.21.2 Folder = C:\Documents and Settings\Owner\Desktop
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.13)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

3.00 Gb Total Physical Memory | 2.00 Gb Available Physical Memory | 83.00% Memory free
4.00 Gb Paging File | 4.00 Gb Available in Paging File | 91.00% Paging File free
Paging file location(s): C:\pagefile.sys 1536 3072 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 105.65 Gb Total Space | 59.30 Gb Free Space | 56.13% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
Drive I: | 6.12 Gb Total Space | 2.61 Gb Free Space | 42.72% Space Free | Partition Type: FAT32

Computer Name: YOUR-O0KWKW9JWC
Current User Name: Owner
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Standard

========== Processes (SafeList) ==========

PRC - [2010/01/08 18:59:23 | 00,513,536 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Owner\Desktop\OTL.exe
PRC - [2010/01/06 17:45:13 | 02,002,160 | —- | M] (SUPERAntiSpyware.com) – C:\Program Files\SUPERAntiSpyware\SUPERANTISPYWARE.EXE
PRC - [2009/07/16 12:07:35 | 00,152,984 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files\Java\jre6\bin\jqs.exe
PRC - [2009/05/14 14:47:54 | 00,731,840 | —- | M] (ESET) – C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
PRC - [2009/02/18 13:44:00 | 00,163,908 | —- | M] (NVIDIA Corporation) – C:\WINDOWS\system32\nvsvc32.exe
PRC - [2008/05/31 07:11:04 | 00,202,016 | —- | M] (SupportSoft, Inc.) – C:\Program Files\Qwest\Quickcare\bin\sprtcmd.exe
PRC - [2008/05/26 22:19:14 | 00,123,904 | —- | M] (Microsoft Corporation) – C:\Program Files\Windows Desktop Search\WindowsSearch.exe
PRC - [2008/04/13 17:12:19 | 01,033,728 | —- | M] (Microsoft Corporation) – C:\WINDOWS\explorer.exe
PRC - [2008/01/08 12:02:16 | 01,213,728 | —- | M] (SupportSoft, Inc.) – C:\Program Files\Common Files\SupportSoft\bin\sprtlisten.exe
PRC - [2007/06/28 03:06:52 | 00,106,496 | —- | M] (Apple, Inc.) – C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
PRC - [2005/09/23 21:05:26 | 00,029,696 | —- | M] (Adobe Systems Incorporated) – C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
PRC - [2004/11/04 19:36:46 | 00,425,984 | —- | M] (Hewlett-Packard Co.) – C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqgalry.exe
PRC - [2004/11/04 19:28:24 | 00,258,048 | —- | M] (Hewlett-Packard Co.) – C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqtra08.exe
PRC - [2003/02/21 04:07:06 | 00,068,704 | —- | M] () – C:\Program Files\Softex\OmniPass\omniServ.exe
PRC - [2003/02/21 03:50:10 | 00,053,248 | —- | M] () – C:\Program Files\Softex\OmniPass\OPXPApp.exe


========== Modules (SafeList) ==========

MOD - [2010/01/08 18:59:23 | 00,513,536 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Owner\Desktop\OTL.exe
MOD - [2008/05/31 07:11:08 | 00,116,000 | —- | M] (SupportSoft, Inc.) – C:\Program Files\Qwest\Quickcare\bin\sprthook.dll
MOD - [2008/04/13 17:12:01 | 00,413,696 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\msvcp60.dll


========== Win32 Services (SafeList) ==========

SRV - [2009/07/16 12:07:35 | 00,152,984 | —- | M] (Sun Microsystems, Inc.) [Auto | Running] – C:\Program Files\Java\jre6\bin\jqs.exe – (JavaQuickStarterService)
SRV - [2009/05/14 14:54:22 | 00,020,680 | —- | M] (ESET) [On_Demand | Stopped] – C:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe – (EhttpSrv)
SRV - [2009/05/14 14:47:54 | 00,731,840 | —- | M] (ESET) [Auto | Running] – C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe – (ekrn)
SRV - [2009/02/18 13:44:00 | 00,163,908 | —- | M] (NVIDIA Corporation) [Auto | Running] – C:\WINDOWS\system32\nvsvc32.exe – (NVSvc)
SRV - [2008/08/18 11:22:44 | 00,382,320 | —- | M] (SupportSoft, Inc.) [On_Demand | Stopped] – C:\Program Files\Common Files\SupportSoft\bin\ssrc.exe – (SupportSoft RemoteAssist)
SRV - [2008/01/08 12:02:16 | 01,213,728 | —- | M] (SupportSoft, Inc.) [Auto | Running] – C:\Program Files\Common Files\supportsoft\bin\sprtlisten.exe – (sprtlisten)
SRV - [2007/10/25 15:27:54 | 00,266,240 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\Program Files\Windows Live\installer\WLSetupSvc.exe – (WLSetupSvc)
SRV - [2007/10/18 11:31:54 | 00,098,328 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\Program Files\Windows Live\Messenger\usnsvc.exe – (usnjsvc)
SRV - [2007/08/09 00:27:52 | 00,073,728 | —- | M] (HP) [Auto | Stopped] – C:\WINDOWS\system32\HPZipm12.exe – (Pml Driver HPZ12)
SRV - [2007/06/28 03:06:52 | 00,106,496 | —- | M] (Apple, Inc.) [Auto | Running] – C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe – (Apple Mobile Device)
SRV - [2003/02/21 04:07:06 | 00,068,704 | —- | M] () [Auto | Running] – C:\Program Files\Softex\OmniPass\omniServ.exe – (omniserv)
SRV - [2002/11/14 08:09:14 | 00,077,824 | —- | M] (HP) [On_Demand | Stopped] – C:\WINDOWS\system32\hphipm11.exe – (Pml Driver HPH11)


========== Driver Services (SafeList) ==========

DRV - [2009/08/08 05:51:42 | 00,074,480 | —- | M] (SUPERAdBlocker.com and SUPERAntiSpyware.com) [Kernel | System | Running] – C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS – (SASKUTIL)
DRV - [2009/05/26 09:05:56 | 00,007,408 | R— | M] ( SUPERAdBlocker.com and SUPERAntiSpyware.com) [Kernel | On_Demand | Running] – C:\Program Files\SUPERAntiSpyware\SASENUM.SYS – (SASENUM)
DRV - [2009/05/26 09:05:54 | 00,009,968 | —- | M] (SUPERAdBlocker.com and SUPERAntiSpyware.com) [Kernel | System | Running] – C:\Program Files\SUPERAntiSpyware\sasdifsv.sys – (SASDIFSV)
DRV - [2009/05/14 14:49:32 | 00,094,360 | —- | M] (ESET) [Kernel | System | Running] – C:\WINDOWS\system32\drivers\epfwtdir.sys – (epfwtdir)
DRV - [2009/05/14 14:47:14 | 00,107,256 | —- | M] (ESET) [Kernel | System | Running] – C:\WINDOWS\system32\drivers\ehdrv.sys – (ehdrv)
DRV - [2009/05/14 14:41:10 | 00,114,472 | —- | M] (ESET) [File_System | Auto | Running] – C:\WINDOWS\system32\drivers\eamon.sys – (eamon)
DRV - [2009/03/25 05:29:52 | 00,130,432 | —- | M] (Realtek Semiconductor Corporation ) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\Rtnicxp.sys – (RTL8023xp)
DRV - [2009/02/18 13:44:00 | 06,308,224 | —- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\nv4_mini.sys – (nv)
DRV - [2007/11/13 03:25:53 | 00,020,480 | —- | M] (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\secdrv.sys – (Secdrv)
DRV - [2006/11/02 18:56:49 | 00,020,576 | —- | M] (Sonic Solutions) [Kernel | Boot | Running] – C:\WINDOWS\System32\DRIVERS\PxHelp20.sys – (PxHelp20)
DRV - [2006/08/28 23:54:56 | 00,010,664 | —- | M] (Applied Networking Inc.) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\gan_adapter.sys – (hamachi_oem)
DRV - [2005/12/12 17:27:00 | 00,019,072 | —- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\PS2.sys – (Ps2)
DRV - [2005/10/22 07:22:48 | 00,021,568 | —- | M] (HP) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\HPZius12.sys – (HPZius12)
DRV - [2005/10/21 19:58:58 | 00,016,496 | —- | M] (HP) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\HPZipr12.sys – (HPZipr12)
DRV - [2005/10/21 19:58:52 | 00,049,920 | —- | M] (HP) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\HPZid412.sys – (HPZid412)
DRV - [2004/10/07 18:16:04 | 00,035,840 | —- | M] (Oak Technology Inc.) [Kernel | System | Running] – C:\WINDOWS\system32\drivers\AFS2K.SYS – (AFS2K)
DRV - [2004/10/01 10:24:02 | 02,279,424 | —- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\ALCXWDM.SYS – (ALCXWDM) Service for Realtek AC97 Audio (WDM)
DRV - [2004/08/03 23:29:52 | 00,166,912 | —- | M] (S3 Graphics, Inc.) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\s3gnbm.sys – (S3Psddr)
DRV - [2003/12/12 19:03:10 | 00,652,689 | —- | M] (Agere Systems) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\ltmdmnt.sys – (ltmodem5)
DRV - [2003/11/07 02:50:00 | 00,070,798 | —- | M] (Logitech, Inc.) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\LMouFlt2.Sys – (LMouFlt2)
DRV - [2003/11/07 02:50:00 | 00,051,486 | —- | M] (Logitech, Inc.) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\L8042pr2.Sys – (L8042pr2)
DRV - [2003/04/09 23:38:21 | 00,028,276 | —- | M] (MusicMatch, Inc.) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\MxlW2k.sys – (MxlW2k)
DRV - [2003/03/14 01:14:28 | 00,112,288 | —- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\ialmsbw.sys – ({6080A529-897E-4629-A488-ABA0C29B635E}) Intel® Graphics Platform (SoftBIOS)
DRV - [2003/03/14 01:14:16 | 00,078,496 | —- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\ialmkchw.sys – ({D31A0762-0CEB-444e-ACFF-B049A1F6FE91}) Intel® Graphics Chipset (KCH)
DRV - [2003/03/14 01:13:04 | 00,090,395 | —- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\ialmnt5.sys – (ialm)
DRV - [2003/02/26 19:19:50 | 00,260,736 | —- | M] (Silicon Integrated Systems Corporation) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\sisgrp.sys – (SiS315)
DRV - [2003/02/22 19:55:26 | 00,141,824 | —- | M] (Promise Technology, Inc.) [Kernel | Boot | Running] – C:\WINDOWS\System32\DRIVERS\fasttx2k.sys – (fasttx2k)
DRV - [2002/12/27 11:41:00 | 00,026,880 | —- | M] (VIA Technologies, Inc.) [Kernel | Boot | Running] – C:\WINDOWS\System32\DRIVERS\viaagp1.sys – (viaagp1)
DRV - [2002/12/24 22:09:48 | 00,030,848 | —- | M] (Silicon Integrated Systems Corporation) [Kernel | Boot | Running] – C:\WINDOWS\System32\DRIVERS\SISAGPX.sys – (SISAGP)
DRV - [2002/10/21 10:21:00 | 00,082,784 | —- | M] (VERITAS Software, Inc.) [Kernel | Boot | Running] – C:\WINDOWS\System32\DRIVERS\drvmcdb.sys – (drvmcdb)
DRV - [2002/10/04 10:04:10 | 00,046,976 | —- | M] (Realtek Semiconductor Corporation ) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\R8139n51.sys – (rtl8139)
DRV - [2002/10/01 09:22:32 | 00,009,856 | —- | M] (Padus, Inc.) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\pfc.sys – (pfc)
DRV - [2002/09/06 18:24:00 | 00,013,568 | —- | M] (NVIDIA Corporation) [Kernel | Boot | Running] – C:\WINDOWS\System32\DRIVERS\nv_agp.sys – (nv_agp)
DRV - [2002/08/29 04:00:00 | 00,017,792 | —- | M] (Parallel Technologies, Inc.) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\ptilink.sys – (Ptilink)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://qwest.live.com
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Secondary Start Pages = [Binary data over 100 bytes]
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://qwest.live.com
IE - HKLM\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKLM\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" =
IE - HKLM\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" =

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://qwest.live.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://srch-us8.hpwis.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://srch-us8.hpwis.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://my.yahoo.com/
IE - HKCU\Software\Microsoft\Internet Explorer\SearchURL\CNNSI, = search.sportsillustrated.cnn.com/pages/search.jsp?query=%s
IE - HKCU\Software\Microsoft\Internet Explorer\SearchURL\Dictionary, = dictionary.reference.com/search?q=%s
IE - HKCU\Software\Microsoft\Internet Explorer\SearchURL\Google, = google.com/search?q=%s
IE - HKCU\Software\Microsoft\Internet Explorer\SearchURL\GoogleGroups, = groups-beta.google.com/groups?q=%s
IE - HKCU\Software\Microsoft\Internet Explorer\SearchURL\GoogleImages, = images.google.com/images?hl=en&lr=&q=%s
IE - HKCU\Software\Microsoft\Internet Explorer\SearchURL\GoogleNews, = news.google.com/news?tab=gn&hl=en&ie=UTF-8&q=%s&btnG=Search+News
IE - HKCU\Software\Microsoft\Internet Explorer\SearchURL\KB, = support.microsoft.com/search/default.aspx?query=%s
IE - HKCU\Software\Microsoft\Internet Explorer\SearchURL\KBDLL, = support.microsoft.com/dllhelp/default.aspx?dlltype=file&l=55&alpha=%s&S=1
IE - HKCU\Software\Microsoft\Internet Explorer\SearchURL\Movies, = fandango.com/my_box_office.asp?searchby=2&txtCityZip=%s
IE - HKCU\Software\Microsoft\Internet Explorer\SearchURL\MSN, = search.msn.com/results.asp?q=%s
IE - HKCU\Software\Microsoft\Internet Explorer\SearchURL\Thesaurus, = thesaurus.reference.com/search?q=%s
IE - HKCU\Software\Microsoft\Internet Explorer\SearchURL\Weather, = weather.com/weather/local/%s
IE - HKCU\Software\Microsoft\Internet Explorer\SearchURL\Yahoo, = search.yahoo.com/search?p=%s
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

FF - HKLM\software\mozilla\Thunderbird\Extensions\\[removed]: C:\Program Files\ESET\ESET NOD32 Antivirus\Mozilla Thunderbird [2009/06/11 17:50:23 | 00,000,000 | —D | M]

[2009/04/28 16:27:16 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Mozilla\Extensions

O1 HOSTS File: (98 bytes) - C:\WINDOWS\system32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (Windows Live Toolbar Helper) - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll (Microsoft Corporation)
O2 - BHO: (JQSIEStartDetectorImpl Class) - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll (Sun Microsystems, Inc.)
O3 - HKLM\..\Toolbar: (hp toolkit) - {B2847E28-5D7D-4DEB-8B67-05D28BCF79F5} - C:\hp\EXPLOREBAR\HPTOOLKT.DLL (Hewlett-Packard Company)
O3 - HKLM\..\Toolbar: (Windows Live Toolbar) - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll (Microsoft Corporation)
O3 - HKCU\..\Toolbar\ShellBrowser: (hp toolkit) - {B2847E28-5D7D-4DEB-8B67-05D28BCF79F5} - C:\hp\EXPLOREBAR\HPTOOLKT.DLL (Hewlett-Packard Company)
O3 - HKCU\..\Toolbar\WebBrowser: (hp toolkit) - {B2847E28-5D7D-4DEB-8B67-05D28BCF79F5} - C:\hp\EXPLOREBAR\HPTOOLKT.DLL (Hewlett-Packard Company)
O3 - HKCU\..\Toolbar\WebBrowser: (Windows Live Toolbar) - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll (Microsoft Corporation)
O4 - HKLM..\Run: [NvCplDaemon] C:\WINDOWS\System32\NvCpl.DLL (NVIDIA Corporation)
O4 - HKLM..\Run: [QuickCare] C:\Program Files\Qwest\Quickcare\bin\sprtcmd.exe (SupportSoft, Inc.)
O4 - HKCU..\Run: [igndlm.exe] C:\Program Files\Download Manager\DLM.exe (IGN Entertainment)
O4 - HKCU..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERANTISPYWARE.EXE (SUPERAntiSpyware.com)
O4 - HKCU..\Run: [updateMgr] C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe (Adobe Systems Incorporated)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe (Adobe Systems Incorporated)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk = C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqtra08.exe (Hewlett-Packard Co.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\HP Image Zone Fast Start.lnk = C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqthb08.exe (Hewlett-Packard Co.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Quicken Scheduled Updates.lnk = C:\Program Files\Quicken\bagent.exe (Intuit Inc.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Updates from HP.lnk = C:\Program Files\Updates from HP\137903\Program\BackWeb-137903.exe File not found
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Windows Search.lnk = C:\Program Files\Windows Desktop Search\WindowsSearch.exe (Microsoft Corporation)
O4 - Startup: C:\Documents and Settings\Owner\Start Menu\Programs\Startup\GameSpot Download Manager.lnk = C:\Program Files\GameSpot\GameSpotDownloadManager_Win32.exe File not found
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O8 - Extra context menu item: &ieSpell Options - C:\Program Files\ieSpell\iespell.dll (Red Egg Software)
O8 - Extra context menu item: &Windows Live Search - C:\Program Files\Windows Live Toolbar\msntb.dll (Microsoft Corporation)
O8 - Extra context menu item: Check &Spelling - C:\Program Files\ieSpell\iespell.dll (Red Egg Software)
O8 - Extra context menu item: Lookup on Merriam Webster - C:\Program Files\ieSpell\Merriam Webster.HTM ()
O8 - Extra context menu item: Lookup on Wikipedia - C:\Program Files\ieSpell\wikipedia.HTM ()
O9 - Extra Button: ieSpell - {0E17D5B7-9F5D-4fee-9DF6-CA6EE38B68A8} - C:\Program Files\ieSpell\iespell.dll (Red Egg Software)
O9 - Extra 'Tools' menuitem : ieSpell - {0E17D5B7-9F5D-4fee-9DF6-CA6EE38B68A8} - C:\Program Files\ieSpell\iespell.dll (Red Egg Software)
O9 - Extra 'Tools' menuitem : ieSpell Options - {1606D6F9-9D3B-4aea-A025-ED5B2FD488E7} - C:\Program Files\ieSpell\iespell.dll (Red Egg Software)
O12 - Plugin for: .spop - C:\Program Files\Internet Explorer\PLUGINS\NPDocBox.dll (InterTrust Technologies Corporation, Inc.)
O15 - HKLM\..Trusted Domains: 1 domain(s) and sub-domain(s) not assigned to a zone.
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} http://a1540.g.akamai.net/7/1540/52/200705…ex/qtplugin.cab (Reg Error: Key error.)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://download.microsoft.com/download/8/b…heckControl.cab (Windows Genuine Advantage Validation Tool)
O16 - DPF: {39B0684F-D7BF-4743-B050-FDC3F48F7E3B} http://www.fileplanet.com/fpdlmgr/cabs/FPDC_2.3.9.113.cab (CDownloadCtrl Object)
O16 - DPF: {44990301-3C9D-426D-81DF-AAB636FA4345} https://www-secure.symantec.com/techsupp/as…abs/tgctlsr.cab (Symantec Script Runner Class)
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} http://update.microsoft.com/windowsupdate/…b?1162338879046 (WUWebControl Class)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} http://update.microsoft.com/microsoftupdat…b?1222980964593 (MUWebControl Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {A90A5822-F108-45AD-8482-9BC8B12DD539} http://www.crucial.com/controls/cpcScanner.cab (Crucial cpcScan)
O16 - DPF: {A9F8D9EC-3D0A-4A60-BD82-FBD64BAD370D} http://h20264.www2.hp.com/ediags/dd/instal…nosticsxp2k.cab (DDRevision Class)
O16 - DPF: {CAFEEFAC-0015-0000-0009-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-…indows-i586.cab (Java Plug-in 1.5.0_09)
O16 - DPF: {CAFEEFAC-0015-0000-0010-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-…indows-i586.cab (Java Plug-in 1.5.0_10)
O16 - DPF: {CAFEEFAC-0015-0000-0011-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-…indows-i586.cab (Java Plug-in 1.5.0_11)
O16 - DPF: {CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_01)
O16 - DPF: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload.macromedia.com/get/flash…ent/swflash.cab (Shockwave Flash Object)
O16 - DPF: {FFBB3F3B-0A5A-4106-BE53-DFE1E2340CB1} http://dlm.tools.akamai.com/dlmanager/vers…vex-2.2.2.1.cab (Reg Error: Key error.)
O16 - DPF: DirectAnimation Java Classes file://C:\WINDOWS\Java\classes\dajava.cab (Reg Error: Key error.)
O16 - DPF: Microsoft XML Parser for Java file://C:\WINDOWS\Java\classes\xmldso.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.2.1
O18 - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\Windows Live\Messenger\msgrapp.8.5.1302.1018.dll (Microsoft Corporation)
O18 - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\Windows Live\Messenger\msgrapp.8.5.1302.1018.dll (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\!SASWinLogon: DllName - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL (SUPERAntiSpyware.com)
O20 - Winlogon\Notify\igfxcui: DllName - igfxsrvc.dll - C:\WINDOWS\System32\igfxsrvc.dll (Intel Corporation)
O20 - Winlogon\Notify\OPXPGina: DllName - C:\Program Files\Softex\OmniPass\opxpgina.dll - C:\Program Files\Softex\OmniPass\OPXPGina.dll ()
O28 - HKLM ShellExecuteHooks: {56F9679E-7826-4C84-81F3-532071A8BCC5} - C:\Program Files\Windows Desktop Search\MsnlNamespaceMgr.dll (Microsoft Corporation)
O28 - HKLM ShellExecuteHooks: {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - C:\Program Files\SUPERAntiSpyware\SASSEH.DLL (SuperAdBlocker.com)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2003/04/09 22:19:17 | 00,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O32 - AutoRun File - [2001/07/28 07:07:38 | 00,000,000 | -HS- | M] () - I:\AUTOEXEC.BAT – [ FAT32 ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - comfile [open] – "%1" %*
O35 - exefile [open] – "%1" %*

========== Files/Folders - Created Within 30 Days ==========

[2010/01/09 08:26:08 | 00,000,000 | —D | C] – C:\_OTL
[2010/01/08 18:59:23 | 00,513,536 | —- | C] (OldTimer Tools) – C:\Documents and Settings\Owner\Desktop\OTL.exe
[2010/01/07 05:38:16 | 00,000,000 | —D | C] – C:\Program Files\Trend Micro
[2009/07/21 22:14:30 | 00,000,000 | —D | M] – C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft
[2009/06/04 10:22:13 | 00,000,000 | —D | M] – C:\Documents and Settings\LocalService\Local Settings\Application Data\ESET
[2009/04/28 16:25:18 | 00,000,000 | —D | M] – C:\Documents and Settings\NetworkService\Application Data\Mozilla
[2007/07/30 19:03:22 | 00,000,000 | —D | M] – C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft
[2007/07/19 21:31:58 | 00,000,000 | –SD | M] – C:\Documents and Settings\NetworkService\Application Data\Microsoft
[2006/11/01 21:16:30 | 00,000,000 | –SD | M] – C:\Documents and Settings\LocalService\Application Data\Microsoft

========== Files - Modified Within 30 Days ==========

[2010/01/09 15:23:21 | 00,205,272 | —- | M] () – C:\WINDOWS\System32\nvapps.xml
[2010/01/09 15:23:15 | 00,001,158 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2010/01/09 15:22:58 | 00,000,006 | -H– | M] () – C:\WINDOWS\tasks\SA.DAT
[2010/01/09 15:22:55 | 00,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2010/01/09 15:22:52 | 32,205,57824 | -HS- | M] () – C:\hiberfil.sys
[2010/01/09 15:21:17 | 04,718,592 | -H– | M] () – C:\Documents and Settings\Owner\NTUSER.DAT
[2010/01/09 15:21:17 | 00,000,178 | -HS- | M] () – C:\Documents and Settings\Owner\ntuser.ini
[2010/01/09 15:21:11 | 00,000,268 | -H– | M] () – C:\sqmdata02.sqm
[2010/01/09 15:21:11 | 00,000,244 | -H– | M] () – C:\sqmnoopt02.sqm
[2010/01/09 15:21:10 | 06,435,758 | -H– | M] () – C:\Documents and Settings\Owner\Local Settings\Application Data\IconCache.db
[2010/01/09 14:31:00 | 00,000,254 | —- | M] () – C:\WINDOWS\tasks\Check Updates for Windows Live Toolbar.job
[2010/01/09 12:21:26 | 00,000,268 | -H– | M] () – C:\sqmdata01.sqm
[2010/01/09 12:21:26 | 00,000,244 | -H– | M] () – C:\sqmnoopt01.sqm
[2010/01/09 08:29:00 | 00,000,268 | -H– | M] () – C:\sqmdata00.sqm
[2010/01/09 08:29:00 | 00,000,244 | -H– | M] () – C:\sqmnoopt00.sqm
[2010/01/09 08:28:23 | 00,000,098 | —- | M] () – C:\WINDOWS\System32\drivers\etc\Hosts
[2010/01/08 18:59:23 | 00,513,536 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Owner\Desktop\OTL.exe
[2010/01/08 17:29:22 | 00,284,915 | —- | M] () – C:\Documents and Settings\Owner\Desktop\gmer.zip
[2010/01/07 05:38:18 | 00,001,745 | —- | M] () – C:\Documents and Settings\Owner\Desktop\HijackThis.lnk

========== Files Created - No Company Name ==========

[2010/01/09 15:21:11 | 00,000,268 | -H– | C] () – C:\sqmdata02.sqm
[2010/01/09 15:21:11 | 00,000,244 | -H– | C] () – C:\sqmnoopt02.sqm
[2010/01/09 12:21:26 | 00,000,268 | -H– | C] () – C:\sqmdata01.sqm
[2010/01/09 12:21:26 | 00,000,244 | -H– | C] () – C:\sqmnoopt01.sqm
[2010/01/09 08:29:00 | 00,000,268 | -H– | C] () – C:\sqmdata00.sqm
[2010/01/09 08:29:00 | 00,000,244 | -H– | C] () – C:\sqmnoopt00.sqm
[2010/01/08 17:29:48 | 00,284,915 | —- | C] () – C:\Documents and Settings\Owner\Desktop\gmer.zip
[2010/01/07 05:38:17 | 00,001,745 | —- | C] () – C:\Documents and Settings\Owner\Desktop\HijackThis.lnk
[2009/09/10 11:43:49 | 00,095,856 | —- | C] () – C:\Documents and Settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
[2009/06/10 07:36:07 | 00,000,911 | —- | C] () – C:\WINDOWS\STA2.ini
[2009/04/28 15:25:03 | 00,002,928 | —- | C] () – C:\Documents and Settings\NetworkService\Local Settings\Application Data\81F79ABC-AB11-494C-859E-88424AA60ADF.txt
[2009/04/28 15:24:16 | 00,003,756 | —- | C] () – C:\Documents and Settings\Owner\Local Settings\Application Data\81F79ABC-AB11-494C-859E-88424AA60ADF.txt
[2008/11/18 17:34:20 | 00,000,262 | —- | C] () – C:\WINDOWS\{789289CA-F73A-4A16-A331-54D498CE069F}_WiseFW.ini
[2008/07/21 16:14:10 | 00,073,728 | —- | C] () – C:\WINDOWS\System32\RtNicProp32.dll
[2007/11/26 21:56:28 | 00,151,415 | —- | C] () – C:\WINDOWS\System32\xlive.dll.cat
[2007/09/27 10:51:02 | 00,020,698 | —- | C] () – C:\WINDOWS\System32\idxcntrs.ini
[2007/09/27 10:48:48 | 00,030,628 | —- | C] () – C:\WINDOWS\System32\gsrvctr.ini
[2007/09/27 10:48:28 | 00,031,698 | —- | C] () – C:\WINDOWS\System32\gthrctr.ini
[2007/07/23 08:03:32 | 00,053,248 | —- | C] () – C:\WINDOWS\System32\AgCPanelTraditionalChinese.dll
[2007/07/23 08:03:32 | 00,053,248 | —- | C] () – C:\WINDOWS\System32\AgCPanelSwedish.dll
[2007/07/23 08:03:32 | 00,053,248 | —- | C] () – C:\WINDOWS\System32\AgCPanelSpanish.dll
[2007/07/23 08:03:30 | 00,053,248 | —- | C] () – C:\WINDOWS\System32\AgCPanelSimplifiedChinese.dll
[2007/07/23 08:03:30 | 00,053,248 | —- | C] () – C:\WINDOWS\System32\AgCPanelPortugese.dll
[2007/07/23 08:03:30 | 00,053,248 | —- | C] () – C:\WINDOWS\System32\AgCPanelKorean.dll
[2007/07/23 08:03:30 | 00,053,248 | —- | C] () – C:\WINDOWS\System32\AgCPanelJapanese.dll
[2007/07/23 08:03:30 | 00,053,248 | —- | C] () – C:\WINDOWS\System32\AgCPanelGerman.dll
[2007/07/23 08:03:30 | 00,053,248 | —- | C] () – C:\WINDOWS\System32\AgCPanelFrench.dll
[2006/12/30 02:29:35 | 00,006,144 | —- | C] () – C:\Documents and Settings\Owner\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2006/12/02 18:13:19 | 00,000,214 | —- | C] () – C:\WINDOWS\HP_48BitScanUpdatePatch.ini
[2006/11/24 18:24:46 | 00,021,840 | —- | C] () – C:\WINDOWS\System32\SIntfNT.dll
[2006/11/24 18:24:45 | 00,017,212 | —- | C] () – C:\WINDOWS\System32\SIntf32.dll
[2006/11/24 18:24:45 | 00,012,067 | —- | C] () – C:\WINDOWS\System32\SIntf16.dll
[2006/11/14 19:57:18 | 00,000,000 | —- | C] () – C:\WINDOWS\iPlayer.INI
[2006/11/08 05:52:36 | 00,061,678 | —- | C] () – C:\Documents and Settings\Owner\Application Data\PFP100JPR.{PB
[2006/11/08 05:52:36 | 00,012,358 | —- | C] () – C:\Documents and Settings\Owner\Application Data\PFP100JCM.{PB
[2006/11/01 16:23:02 | 00,000,128 | —- | C] () – C:\Documents and Settings\Owner\Local Settings\Application Data\fusioncache.dat
[2006/11/01 15:52:30 | 00,001,109 | —- | C] () – C:\Documents and Settings\All Users\Application Data\hpzinstall.log
[2006/10/31 16:40:31 | 00,019,968 | —- | C] () – C:\WINDOWS\System32\cpuinf32.dll
[2006/08/11 21:45:20 | 00,581,632 | —- | C] () – C:\WINDOWS\System32\nvhwvid.dll
[2006/08/11 21:43:00 | 01,724,416 | —- | C] () – C:\WINDOWS\System32\nvwdmcpl.dll
[2006/08/11 21:43:00 | 01,101,824 | —- | C] () – C:\WINDOWS\System32\nvwimg.dll
[2006/08/11 21:43:00 | 00,286,720 | —- | C] () – C:\WINDOWS\System32\nvnt4cpl.dll
[2004/09/13 16:35:56 | 00,000,000 | —- | C] () – C:\WINDOWS\System32\px.ini
[2003/04/10 04:35:00 | 00,000,061 | —- | C] () – C:\WINDOWS\smscfg.ini
[2003/04/10 04:21:36 | 00,000,051 | —- | C] () – C:\WINDOWS\System32\mshrml.ini
[2003/04/10 01:51:07 | 00,000,438 | —- | C] () – C:\WINDOWS\System32\1_ssetup.ini
[2003/04/10 01:51:07 | 00,000,000 | —- | C] () – C:\WINDOWS\System32\sunistlog.ini
[2003/04/10 00:32:34 | 00,094,208 | —- | C] () – C:\WINDOWS\System32\PcdrKernelModeServices.dll
[2003/04/10 00:32:34 | 00,077,824 | —- | C] () – C:\WINDOWS\System32\ProgressTrace.dll
[2003/04/10 00:06:10 | 00,167,936 | —- | C] () – C:\WINDOWS\System32\PCDrJNI_1_1.dll
[2003/04/10 00:03:38 | 00,045,056 | —- | C] () – C:\WINDOWS\System32\hpreg.dll
[2003/04/10 00:03:38 | 00,024,576 | —- | C] () – C:\WINDOWS\System32\syscontr.dll
[2003/04/09 23:57:15 | 00,000,052 | —- | C] () – C:\WINDOWS\intuprof.ini
[2003/04/09 23:57:04 | 00,000,626 | —- | C] () – C:\WINDOWS\QUICKEN.INI
[2003/04/09 23:16:44 | 00,001,793 | —- | C] () – C:\WINDOWS\System32\fxsperf.ini
[2003/04/09 23:08:03 | 00,466,944 | —- | C] () – C:\WINDOWS\System32\nvshell.dll
[2003/04/09 23:08:01 | 01,507,328 | —- | C] () – C:\WINDOWS\System32\nview.dll
[2003/04/09 22:55:02 | 00,363,520 | —- | C] () – C:\WINDOWS\System32\psisdecd.dll
[2003/04/09 22:44:58 | 00,299,073 | —- | C] () – C:\WINDOWS\System32\PythonCOM22.dll
[2003/04/09 22:44:58 | 00,065,536 | —- | C] () – C:\WINDOWS\System32\PyWinTypes22.dll
[2003/04/09 22:44:29 | 00,016,896 | —- | C] () – C:\WINDOWS\System32\bcbmm.dll
[2003/04/09 22:23:21 | 00,000,802 | —- | C] () – C:\WINDOWS\orun32.ini
[2003/04/09 22:05:45 | 00,000,659 | —- | C] () – C:\WINDOWS\System32\oeminfo.ini
[2001/08/14 18:47:08 | 00,020,480 | —- | C] () – C:\WINDOWS\System32\vxpsapi.dll
< End of report >
Hi six,

While I check to see if all the services are present we'll do a little reg fix and see if ESET starts and your connection is ok without you having to do anything.

Open a new Notepad session
  • Click the Start button, click run
  • in the run box type notepad
  • click ok
  • In the notepad, Click "Format" and be certain that Word Wrap is not checked.
  • Copy and paste all the text in the code box below into the Notepad. Do Not copy the word CODE
reg add "HKLM\Software\Microsoft\Windows\CurrentVersion\Run" /v egui /t REG_SZ /d "\"C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe\" /hide /waitservice"

In the notepad
  • Click File, Save as…, and set the Save in to your Desktop
  • In the filename box, type (including quotation marks) as the filename: "fix.bat"
  • Click save

You should now have a file on your desktop named fix.bat with an icon that looks like this 📎bat.PNG

Double click the file to run it. You may get a small black screen briefly flash on your screen.

Reboot and try to connect withut have to do anything else.

Let us know how it goes.
Hi six,

I still have the disc for ESET if thats what you mean? It just updates itself online after being installed doesn't it?

It should providing it's the same version of ESET that you have installed. You appear to have Version 4 installed. Plus you must have a current subscription.

As best as I can tell all the services were set correctly at startup and the necessary ones were running. The only thing that was not running was the GUI which should now be running if the regfix did what it was supposed to.

I don't know if ESET running correctly is dependant on the User Interface running. I'm not sure why that registry entry would have disappeared unless there is an option within the Interface not to run at startup that was accidently checked.

When you were manually starting it, what exactly were you starting?

Just because nothing hasn't shown up so far doesn't mean there isn't something there. We can can keep looking if you wish.

Is the ESET interface now loading at startup? Are th searches still OK?

Thanks
Good morning! I do have a current subscription to ESET. After doing your last thing you gave me the ESET is starting up on it's own at startup. {Thanks} I had been having to go to the start/programs/eset to manually start it as I don't believe it was running at all, I couldn't find anything in controls or options in ESET that gave the option of checking/unchecking to make it start upon startup and I'm certain that it wasn't something I did so I assumed it was something from whatever bug I picked up that caused it. ?? I still haven't had any other search redirect problems but when I started the computer today I didn't try to get online for about 20 minutes after I started it and I got another cannot connect to internet message and had to restart the machine to be able to connect through a browser so whatever is causing that is still there. Here is what the window diagnostic said from that. I don't know if it will help you or not but just in case. Last diagnostic run time: 01/10/10 08:55:01 HTTP, HTTPS, FTP Diagnostic HTTP, HTTPS, FTP connectivity warn HTTP: Error 12152 connecting to www.microsoft.com: The server returned an invalid or unrecognized response warn HTTPS: Error 12157 connecting to www.microsoft.com: An error occurred in the secure channel support warn HTTP: Error 12152 connecting to www.hotmail.com: The server returned an invalid or unrecognized response warn HTTPS: Error 12157 connecting to www.passport.net: An error occurred in the secure channel support info FTP (Passive): Successfully connected to ftp.microsoft.com. error Could not make an HTTP connection. error Could not make an HTTPS connection. info Redirecting user to support call DNS Client Diagnostic DNS - Not a home user scenario info Using Web Proxy: no info Resolving name ok for (www.microsoft.com): yes No DNS servers DNS failure Gateway Diagnostic Gateway info The following proxy configuration is being used by IE: Automatically Detect Settings:Disabled Automatic Configuration Script: Proxy Server: Proxy Bypass list: info This computer has the following default gateway entry(ies): 192.168.2.1 info This computer has the following IP address(es): 192.168.2.2 info The default gateway is in the same subnet as this computer info The default gateway entry is a valid unicast address info The default gateway address was resolved via ARP in 1 try(ies) info The default gateway was reached via ICMP Ping in 1 try(ies) info TCP port 80 on host [removed] was successfully reached info The Internet host www.microsoft.com was successfully reached info The default gateway is OK IP Layer Diagnostic Corrupted IP routing table info The default route is valid info The loopback route is valid info The local host route is valid info The local subnet route is valid Invalid ARP cache entries action The ARP cache has been flushed IP Configuration Diagnostic Invalid IP address info Valid IP address detected: 192.168.2.2 Wireless Diagnostic Wireless - Service disabled Wireless - User SSID Wireless - First time setup Wireless - Radio off Wireless - Out of range Wireless - Hardware issue Wireless - Novice user Wireless - Ad-hoc network Wireless - Less preferred Wireless - 802.1x enabled Wireless - Configuration mismatch Wireless - Low SNR WinSock Diagnostic WinSock status info All base service provider entries are present in the Winsock catalog. info The Winsock Service provider chains are valid. info Provider entry MSAFD Tcpip [TCP/IP] passed the loopback communication test. info Provider entry MSAFD Tcpip [UDP/IP] passed the loopback communication test. info Provider entry RSVP UDP Service Provider passed the loopback communication test. info Provider entry RSVP TCP Service Provider passed the loopback communication test. info Connectivity is valid for all Winsock service providers. Network Adapter Diagnostic Network location detection info Using home Internet connection Network adapter identification info Network connection: Name=Local Area Connection, Device=Realtek RTL8139/810x Family Fast Ethernet NIC, MediaType=LAN, SubMediaType=LAN info Network connection: Name=1394 Connection, Device=1394 Net Adapter, MediaType=LAN, SubMediaType=1394 info Ethernet connection selected Network adapter status info Network connection status: Connected HTTP, HTTPS, FTP Diagnostic HTTP, HTTPS, FTP connectivity warn HTTP: Error 12152 connecting to www.microsoft.com: The server returned an invalid or unrecognized response warn HTTPS: Error 12157 connecting to www.microsoft.com: An error occurred in the secure channel support warn HTTP: Error 12152 connecting to www.hotmail.com: The server returned an invalid or unrecognized response info FTP (Passive): Successfully connected to ftp.microsoft.com. warn HTTPS: Error 12157 connecting to www.passport.net: An error occurred in the secure channel support error Could not make an HTTP connection. error Could not make an HTTPS connection.
Hi six,

Are you using a router? If so, name and model number.

Wireless or wired connection?

What did you use for an antivirus program before ESET?

Let's start with the easy.

Download and save to your desktop Malwarebytes Anti-Malware

Double Click mbam-setup.exe to install the application.
  • Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish,so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected.
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.
Extra Note:
If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process,if asked to restart the computer,please do so immediatly.



I see you have SuperAntiSpyware installed. If you ran a scan just prior to the problem with your AntiVirus not showing, please post that log also. Please edit out the cookies section, it will make for a shorter log.

Thanks

Hi six,

Are you using a router? If so, name and model number.

Wireless or wired connection?

What did you use for an antivirus program before ESET?

Let's start with the easy.

Download and save to your desktop Malwarebytes Anti-Malware

Double Click mbam-setup.exe to install the application.

  • Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish,so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected.
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.
Extra Note:
If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process,if asked to restart the computer,please do so immediatly.



I see you have SuperAntiSpyware installed. If you ran a scan just prior to the problem with your AntiVirus not showing, please post that log also. Please edit out the cookies section, it will make for a shorter log.

Thanks

Yes I have a router = Belkin Model:F5D7234-4 v4
Wired connection

Before ESET I used Norton and got a trojan while using it that I believe was attached to some Norton files so I got ESET thinking it would keep the bugs away {seems not to be the case} :angry:

SuperAntiSpyware is something that I have leftover from removing the trojan that I got when I had Norton I believe.

Here is the newest log for you.

Malwarebytes' Anti-Malware 1.44
Database version: 3537
Windows 5.1.2600 Service Pack 3
Internet Explorer 7.0.5730.13

1/10/2010 4:48:51 PM
mbam-log-2010-01-10 (16-48-51).txt

Scan type: Quick Scan
Objects scanned: 116419
Time elapsed: 6 minute(s), 57 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 8
Registry Values Infected: 1
Registry Data Items Infected: 2
Folders Infected: 1
Files Infected: 1

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
HKEY_CLASSES_ROOT\y537.y537mgr (Trojan.BHO) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\y537.y537mgr.1 (Trojan.BHO) -> Quarantined and deleted successfully.
HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\{c48635ad-d6b5-3ee4-aaa2-540d5a173658} (Backdoor.Bot) -> Quarantined and deleted successfully.
HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\{c48635ad-d6b5-3ee4-aaa2-540d5a173658} (Backdoor.Bot) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\TypeLib\{497dddb6-6eee-4561-9621-b77dc82c1f84} (Rogue.Ascentive) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{4e980492-027b-47f1-a7ab-ab086dacbb9e} (Rogue.Ascentive) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{5ead8321-fcbb-4c3f-888c-ac373d366c3f} (Rogue.Ascentive) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{31f3cf6e-a71a-4daa-852b-39ac230940b4} (Rogue.Ascentive) -> Quarantined and deleted successfully.

Registry Values Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs\C:\WINDOWS\system32\SysRestore.dll (Rogue.Ascentive) -> Quarantined and deleted successfully.

Registry Data Items Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\AntiVirusDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\UpdatesDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.

Folders Infected:
C:\WINDOWS\system32\796525 (Trojan.BHO) -> Quarantined and deleted successfully.

Files Infected:
C:\WINDOWS\system32\SysRestore.dll (Rogue.Ascentive) -> Quarantined and deleted successfully.


Thanks again for all of your time and help, even if I don't understand much of it I do appreciate it greatly!!! :D
Hi six,

Thanks for the info. When you uninstalled Norton, did you run the removal tool and how long ago was this?

Your system has been infected by one or more Backdoor Trojans.

This allows the malware to open backdoors and dwonload more malicious files.

I strongly suggest you do the following immediately:
  • From a know clean private computer, change *all* your online passwords – for email, for banks, financial accounts, PayPal, eBay, online companies, any online forums or groups you belong to.
  • DO NOT change passwords while using the infected computer.

Let's go deeper.

Please read through these instructions to familarize yourself with what to expect when this tool runs

Download ComboFix from one of these locations:

Link 1
Link 2

* IMPORTANT !!! Save ComboFix.exe to your Desktop

  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. Note: If you are having difficulty properly disabling your protective programs, or are unsure as to what programs need to be disabled, please refer to the information available through this link : How to Disable your Security Programs
  • Double click on ComboFix.exe & follow the prompts.
  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.
  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.

[external image: Posted Image]


Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]

Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.

Notes:

1.Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. ComboFix may reset a number of Internet Explorer's settings, including making I-E the default browser.
3. CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.



Please post the combofix log.

How's the computer.

Thanks

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI