This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Root Kit/Malware Problems

13 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi guys a few days ago my girlfriend opened a forwarded e-mail from her grandma and it installed some kind of PC Protector with a trojan. At first I was unable to open windows explorer or run any kind of virus/malware scans. I finally was able to run an MBAM scan in Safe mode that removed enough of it to let me get on here and get more help. I have been going through your self help section and have completed everything up to running GMER however when I run GMER it will scan for a while and then the computer completely locks up, and the second time I tried to run it, the computer shut down and restarted on it's own. I didn't want to continue without some advice on where to go. I have 2 MBAM logs if you would like me to post them, one from when I ran it in SAFE mode and another that I ran when I ran Defogger. Thanks for you help.
Hi Willem, welcome to the forum.

To make cleaning this machine easier
  • Please do not uninstall/install any programs unless asked to
    It is more difficult when files/programs are appearing in/disappearing from the logs.
  • Please do not run any scans other than those requested
  • Please follow all instructions in the order posted
  • All logs/reports, etc.. must be posted in Notepad. Please ensure that word wrap is unchecked. In notepad click format, uncheck word wrap if it is checked.
  • Do not attach any logs/reports, etc.. unless specifically requested to do so.
  • If you have problems with or do not understand the instructions, Please ask before continuing.
  • Please stay with this thread until given the All Clear. A absence of symptoms does not mean a clean machine.

Please post both MBAM logs in your next reply.

Try renaming gmer.exe to fgh.exe and running it in safe mode.


Download OTL to your desktop.
  • Double click on OTL.exe to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output
  • Check the boxes beside LOP Check and Purity Check.
  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.

Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post it with your next reply. You may need two posts to fit them all in.


Please post back with
  • MBAM logs
  • both OTL logs
  • gmer log if it ran

Thanks
Here are the 2 MBAM Logs as well as the OTL log, I was still unable to get gmer to run even in safe mode it crashed and brought up the blue screen of death. When I was administering the self help earlier in the day I used defogger and my CD emulation drives are still disabled does that have something to do with it?

OTL log

OTL logfile created on: 2/9/2010 9:08:41 PM - Run 1
OTL by OldTimer - Version 3.1.28.0 Folder = C:\Users\Brittany R Belcher\Desktop
Windows Vista Home Basic Edition Service Pack 1 (Version = 6.0.6001) - Type = NTWorkstation
Internet Explorer (Version = 7.0.6001.18000)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

2.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 62.00% Memory free
4.00 Gb Paging File | 3.00 Gb Available in Paging File | 79.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 136.50 Gb Total Space | 89.79 Gb Free Space | 65.78% Space Free | Partition Type: NTFS
Drive D: | 10.00 Gb Total Space | 6.50 Gb Free Space | 65.01% Space Free | Partition Type: NTFS
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: BRITTANYRBEL-PC
Current User Name: Brittany R Belcher
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal

========== Processes (SafeList) ==========

PRC - C:\Users\Brittany R Belcher\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\AVG\AVG8\avgnsx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG8\avgrsx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG8\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Windows\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe (Microsoft Corporation)
PRC - C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
PRC - \\?\C:\Windows\System32\wbem\WMIADAP.EXE ()
PRC - C:\Windows\System32\WerFault.exe (Microsoft Corporation)
PRC - C:\Program Files\Internet Explorer\ieuser.exe (Microsoft Corporation)
PRC - C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe (Symantec Corporation)
PRC - C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe (Symantec Corporation)
PRC - C:\Program Files\Synaptics\SynTP\SynTPEnh.exe (Synaptics, Inc.)
PRC - C:\Program Files\Dell\MediaDirect\PCMService.exe (CyberLink Corp.)
PRC - C:\Windows\System32\WLTRAY.EXE (Dell Inc.)
PRC - C:\Windows\System32\WLTRYSVC.EXE ()
PRC - C:\Windows\System32\BCMWLTRY.EXE (Dell Inc.)
PRC - C:\Windows\System32\Ati2evxx.exe (ATI Technologies Inc.)
PRC - C:\Program Files\DellSupport\DSAgnt.exe (Gteko Ltd.)
PRC - C:\Windows\System32\stacsv.exe (SigmaTel, Inc.)
PRC - C:\Windows\sttray.exe (SigmaTel, Inc.)
PRC - C:\Program Files\Dell\QuickSet\quickset.exe (Dell Inc)
PRC - C:\Program Files\Viewpoint\Common\ViewpointService.exe (Viewpoint Corporation)
PRC - C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe (Hewlett-Packard Co.)
PRC - C:\Program Files\HP\HP Software Update\hpwuSchd2.exe (Hewlett-Packard Co.)
PRC - C:\Program Files\HP\Digital Imaging\bin\hpqste08.exe (Hewlett-Packard Co.)
PRC - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe (Sonic Solutions)
PRC - C:\Program Files\Digital Line Detect\DLG.exe (Avanquest Software )
PRC - C:\Windows\System32\drivers\XAudio.exe (Conexant Systems, Inc.)
PRC - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe (Adobe Systems Incorporated)
PRC - C:\Windows\System32\LEXBCES.EXE (Lexmark International, Inc.)
PRC - C:\Windows\System32\LEXPPS.EXE (Lexmark International, Inc.)


========== Modules (SafeList) ==========

MOD - C:\Users\Brittany R Belcher\Desktop\OTL.exe (OldTimer Tools)
MOD - C:\Windows\System32\avgrsstx.dll (AVG Technologies CZ, s.r.o.)
MOD - C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6001.18000_none_5cdbaa5a083979cc\comctl32.dll (Microsoft Corporation)


========== Win32 Services (SafeList) ==========

SRV - (LiveUpdate Notice Ex) – File not found
SRV - (CLTNetCnService) – File not found
SRV - (avg8wd) – C:\Program Files\AVG\AVG8\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
SRV - (odserv) – C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE (Microsoft Corporation)
SRV - (Microsoft Office Groove Audit Service) – C:\Program Files\Microsoft Office\Office12\GrooveAuditService.exe (Microsoft Corporation)
SRV - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV - (LiveUpdate Notice Service) – C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe (Symantec Corporation)
SRV - (LiveUpdate) – C:\Program Files\Symantec\LiveUpdate\LuComServer_3_2.EXE (Symantec Corporation)
SRV - (Automatic LiveUpdate Scheduler) – C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe (Symantec Corporation)
SRV - (wltrysvc) – C:\Windows\System32\WLTRYSVC.EXE ()
SRV - (Ati External Event Utility) – C:\Windows\System32\Ati2evxx.exe (ATI Technologies Inc.)
SRV - (DSBrokerService) – C:\Program Files\DellSupport\brkrsvc.exe ()
SRV - (STacSV) – C:\Windows\System32\stacsv.exe (SigmaTel, Inc.)
SRV - (hpqcxs08) – C:\Program Files\HP\Digital Imaging\bin\hpqcxs08.dll (Hewlett-Packard Co.)
SRV - (hpqddsvc) – C:\Program Files\HP\Digital Imaging\bin\hpqddsvc.dll (Hewlett-Packard Co.)
SRV - (usnjsvc) – C:\Program Files\MSN Messenger\usnsvc.exe (Microsoft Corporation)
SRV - (Viewpoint Manager Service) – C:\Program Files\Viewpoint\Common\ViewpointService.exe (Viewpoint Corporation)
SRV - (Pml Driver HPZ12) – C:\Windows\System32\HPZipm12.dll (Hewlett-Packard)
SRV - (Net Driver HPZ12) – C:\Windows\System32\HPZinw12.dll (Hewlett-Packard)
SRV - (RoxMediaDB9) – C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe (Sonic Solutions)
SRV - (RoxWatch9) – C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe (Sonic Solutions)
SRV - (ose) – C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE (Microsoft Corporation)
SRV - (stllssvr) – C:\Program Files\Common Files\SureThing Shared\stllssvr.exe (MicroVision Development, Inc.)
SRV - (XAudioService) – C:\Windows\System32\drivers\XAudio.exe (Conexant Systems, Inc.)
SRV - (IDriverT) – C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe (Macrovision Corporation)
SRV - (LexBceS) – C:\Windows\System32\LEXBCES.EXE (Lexmark International, Inc.)


========== Driver Services (SafeList) ==========

DRV - (AvgTdiX) – C:\Windows\System32\Drivers\avgtdix.sys (AVG Technologies CZ, s.r.o.)
DRV - (AvgLdx86) – C:\Windows\System32\Drivers\avgldx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (AvgMfx86) – C:\Windows\System32\Drivers\avgmfx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (viaide) – C:\Windows\system32\drivers\viaide.sys (VIA Technologies, Inc.)
DRV - (cmdide) – C:\Windows\system32\drivers\cmdide.sys (CMD Technology, Inc.)
DRV - (aliide) – C:\Windows\system32\drivers\aliide.sys (Acer Laboratories Inc.)
DRV - (SynTP) – C:\Windows\System32\drivers\SynTP.sys (Synaptics, Inc.)
DRV - (BCM43XX) – C:\Windows\System32\drivers\BCMWL6.SYS (Broadcom Corporation)
DRV - (R300) – C:\Windows\System32\drivers\atikmdag.sys (ATI Technologies Inc.)
DRV - (atikmdag) – C:\Windows\System32\drivers\atikmdag.sys (ATI Technologies Inc.)
DRV - (STHDA) – C:\Windows\System32\drivers\stwrt.sys (SigmaTel, Inc.)
DRV - (dsunidrv) – C:\Windows\System32\drivers\dsunidrv.sys (Gteko Ltd.)
DRV - (bcm4sbxp) – C:\Windows\System32\drivers\bcm4sbxp.sys (Broadcom Corporation)
DRV - (rimmptsk) – C:\Windows\System32\drivers\rimmptsk.sys (REDC)
DRV - (rimsptsk) – C:\Windows\System32\drivers\rimsptsk.sys (REDC)
DRV - (rismxdp) – C:\Windows\System32\drivers\rixdptsk.sys (REDC)
DRV - (HSF_DPV) – C:\Windows\System32\drivers\HSX_DPV.sys (Conexant Systems, Inc.)
DRV - (HSXHWAZL) – C:\Windows\System32\drivers\HSXHWAZL.sys (Conexant Systems, Inc.)
DRV - (winachsf) – C:\Windows\System32\drivers\HSX_CNXT.sys (Conexant Systems, Inc.)
DRV - (ql2300) – C:\Windows\system32\drivers\ql2300.sys (QLogic Corporation)
DRV - (adp94xx) – C:\Windows\system32\drivers\adp94xx.sys (Adaptec, Inc.)
DRV - (elxstor) – C:\Windows\system32\drivers\elxstor.sys (Emulex)
DRV - (adpahci) – C:\Windows\system32\drivers\adpahci.sys (Adaptec, Inc.)
DRV - (uliahci) – C:\Windows\system32\drivers\uliahci.sys (ULi Electronics Inc.)
DRV - (iaStorV) – C:\Windows\system32\drivers\iastorv.sys (Intel Corporation)
DRV - (adpu320) – C:\Windows\system32\drivers\adpu320.sys (Adaptec, Inc.)
DRV - (ulsata2) – C:\Windows\system32\drivers\ulsata2.sys (Promise Technology, Inc.)
DRV - (vsmraid) – C:\Windows\system32\drivers\vsmraid.sys (VIA Technologies Inc.,Ltd)
DRV - (ql40xx) – C:\Windows\system32\drivers\ql40xx.sys (QLogic Corporation)
DRV - (UlSata) – C:\Windows\system32\drivers\ulsata.sys (Promise Technology, Inc.)
DRV - (adpu160m) – C:\Windows\system32\drivers\adpu160m.sys (Adaptec, Inc.)
DRV - (nvraid) – C:\Windows\system32\drivers\nvraid.sys (NVIDIA Corporation)
DRV - (nfrd960) – C:\Windows\system32\drivers\nfrd960.sys (IBM Corporation)
DRV - (iirsp) – C:\Windows\system32\drivers\iirsp.sys (Intel Corp./ICP vortex GmbH)
DRV - (SiSRaid4) – C:\Windows\system32\drivers\sisraid4.sys (Silicon Integrated Systems)
DRV - (nvstor) – C:\Windows\system32\drivers\nvstor.sys (NVIDIA Corporation)
DRV - (aic78xx) – C:\Windows\system32\drivers\djsvs.sys (Adaptec, Inc.)
DRV - (arcsas) – C:\Windows\system32\drivers\arcsas.sys (Adaptec, Inc.)
DRV - (LSI_SCSI) – C:\Windows\system32\drivers\lsi_scsi.sys (LSI Logic)
DRV - (SiSRaid2) – C:\Windows\system32\drivers\sisraid2.sys (Silicon Integrated Systems Corp.)
DRV - (HpCISSs) – C:\Windows\system32\drivers\hpcisss.sys (Hewlett-Packard Company)
DRV - (arc) – C:\Windows\system32\drivers\arc.sys (Adaptec, Inc.)
DRV - (iteraid) – C:\Windows\system32\drivers\iteraid.sys (Integrated Technology Express, Inc.)
DRV - (iteatapi) – C:\Windows\system32\drivers\iteatapi.sys (Integrated Technology Express, Inc.)
DRV - (LSI_SAS) – C:\Windows\system32\drivers\lsi_sas.sys (LSI Logic)
DRV - (Symc8xx) – C:\Windows\system32\drivers\symc8xx.sys (LSI Logic)
DRV - (LSI_FC) – C:\Windows\system32\drivers\lsi_fc.sys (LSI Logic)
DRV - (Sym_u3) – C:\Windows\system32\drivers\sym_u3.sys (LSI Logic)
DRV - (Mraid35x) – C:\Windows\system32\drivers\mraid35x.sys (LSI Logic Corporation)
DRV - (Sym_hi) – C:\Windows\system32\drivers\sym_hi.sys (LSI Logic)
DRV - (megasas) – C:\Windows\system32\drivers\megasas.sys (LSI Logic Corporation)
DRV - (Brserid) Brother MFC Serial Port Interface Driver (WDM) – C:\Windows\system32\drivers\brserid.sys (Brother Industries Ltd.)
DRV - (BrUsbSer) – C:\Windows\system32\drivers\brusbser.sys (Brother Industries Ltd.)
DRV - (BrFiltUp) – C:\Windows\system32\drivers\brfiltup.sys (Brother Industries, Ltd.)
DRV - (BrFiltLo) – C:\Windows\system32\drivers\brfiltlo.sys (Brother Industries, Ltd.)
DRV - (BrSerWdm) – C:\Windows\system32\drivers\brserwdm.sys (Brother Industries Ltd.)
DRV - (BrUsbMdm) – C:\Windows\system32\drivers\brusbmdm.sys (Brother Industries Ltd.)
DRV - (ntrigdigi) – C:\Windows\system32\drivers\ntrigdigi.sys (N-trig Innovative Technologies)
DRV - (e1express) Intel® – C:\Windows\System32\drivers\e1e6032.sys (Intel Corporation)
DRV - (E1G60) Intel® – C:\Windows\System32\drivers\E1G60I32.sys (Intel Corporation)
DRV - (secdrv) – C:\Windows\System32\drivers\secdrv.sys (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.)
DRV - (AtiPcie) ATI PCI Express (3GIO) – C:\Windows\system32\DRIVERS\AtiPcie.sys (ATI Technologies Inc.)
DRV - (DSproct) – C:\Program Files\DellSupport\GTAction\triggers\DSproct.sys (Gteko Ltd.)
DRV - (XAudio) – C:\Windows\System32\drivers\XAudio.sys (Conexant Systems, Inc.)
DRV - (PxHelp20) – C:\Windows\System32\Drivers\PxHelp20.sys (Sonic Solutions)
DRV - (mdmxsdk) – C:\Windows\System32\drivers\mdmxsdk.sys (Conexant)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKLM\..\URLSearchHook: {03402f96-3dc7-4285-bc50-9e81fefafe43} - C:\Program Files\AIM Toolbar\aimtb.dll (AOL LLC.)

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.msn.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKCU\..\URLSearchHook: {03402f96-3dc7-4285-bc50-9e81fefafe43} - C:\Program Files\AIM Toolbar\aimtb.dll (AOL LLC.)
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0



O1 HOSTS File: ([2006/09/18 15:41:30 | 000,000,761 | —- | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll (AVG Technologies CZ, s.r.o.)
O2 - BHO: (Groove GFS Browser Helper) - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation)
O2 - BHO: (SSVHelper Class) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - c:\Program Files\Java\jre1.6.0\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - No CLSID value found.
O2 - BHO: (AIM Toolbar Loader) - {b0cda128-b425-4eef-a174-61a11ac5dbf8} - C:\Program Files\AIM Toolbar\aimtb.dll (AOL LLC.)
O2 - BHO: (CBrowserHelperObject Object) - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files\BAE\BAE.dll (Dell Inc.)
O3 - HKLM\..\Toolbar: (AIM Toolbar) - {61539ecd-cc67-4437-a03c-9aaccbd14326} - C:\Program Files\AIM Toolbar\aimtb.dll (AOL LLC.)
O3 - HKCU\..\Toolbar\WebBrowser: (AIM Toolbar) - {61539ECD-CC67-4437-A03C-9AACCBD14326} - C:\Program Files\AIM Toolbar\aimtb.dll (AOL LLC.)
O4 - HKLM..\Run: [] File not found
O4 - HKLM..\Run: [AVG8_TRAY] C:\Program Files\AVG\AVG8\avgtray.exe (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [Broadcom Wireless Manager UI] C:\Windows\System32\WLTRAY.EXE (Dell Inc.)
O4 - HKLM..\Run: [GrooveMonitor] C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe (Microsoft Corporation)
O4 - HKLM..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\hpwuSchd2.exe (Hewlett-Packard Co.)
O4 - HKLM..\Run: [ISUSScheduler] C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe (Macrovision Corporation)
O4 - HKLM..\Run: [Malwarebytes Anti-Malware (reboot)] C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe (Malwarebytes Corporation)
O4 - HKLM..\Run: [PCMService] C:\Program Files\Dell\MediaDirect\PCMService.exe (CyberLink Corp.)
O4 - HKLM..\Run: [SigmatelSysTrayApp] C:\Windows\sttray.exe (SigmaTel, Inc.)
O4 - HKLM..\Run: [Symantec PIF AlertEng] C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe (Symantec Corporation)
O4 - HKLM..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe (Synaptics, Inc.)
O4 - HKLM..\Run: [Windows Defender] C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
O4 - HKCU..\Run: [DellSupport] C:\Program Files\DellSupport\DSAgnt.exe (Gteko Ltd.)
O4 - HKCU..\Run: [updateMgr] C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe (Adobe Systems Incorporated)
O4 - HKCU..\Run: [vomavijum] c:\PROGRA~2\midinuro\midinuro.DLL File not found
O4 - HKCU..\Run: [WindowsWelcomeCenter] C:\Windows\System32\oobefldr.dll (Microsoft Corporation)
O8 - Extra context menu item: &AIM Toolbar Search - C:\ProgramData\AIM Toolbar\ieToolbar\resources\en-US\local\search.html ()
O8 - Extra context menu item: E&xport to Microsoft Excel - C:\Program Files\Microsoft Office\Office12\EXCEL.EXE (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - c:\Program Files\Java\jre1.6.0\bin\npjpi160.dll (Sun Microsystems, Inc.)
O9 - Extra Button: AIM Toolbar - {0b83c99c-1efa-4259-858f-bcb33e007a5b} - C:\Program Files\AIM Toolbar\aimtb.dll (AOL LLC.)
O9 - Extra Button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Program Files\Microsoft Office\Office12\REFIEBAR.DLL (Microsoft Corporation)
O13 - gopher Prefix: missing
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} http://upload.facebook.com/controls/2008.1…toUploader5.cab (Facebook Photo Uploader 5 Control)
O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} http://www2.snapfish.com/SnapfishActivia.cab (Snapfish Activia)
O16 - DPF: {5C6698D9-7BE4-4122-8EC5-291D84DBD4A0} http://upload.facebook.com/controls/Facebo…toUploader3.cab (Facebook Photo Uploader 4 Control)
O16 - DPF: {5F8469B4-B055-49DD-83F7-62B522420ECC} http://upload.facebook.com/controls/Facebo…otoUploader.cab (Facebook Photo Uploader Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0)
O16 - DPF: {CAFEEFAC-0016-0000-0000-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = [removed] [removed] [removed]
O18 - Protocol\Handler\grooveLocalGWS {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll (Microsoft Corporation)
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll (AVG Technologies CZ, s.r.o.)
O18 - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\MSN Messenger\msgrapp.8.1.0178.00.dll (Microsoft Corporation)
O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Program Files\Common Files\microsoft shared\Help\hxds.dll (Microsoft Corporation)
O18 - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\MSN Messenger\msgrapp.8.1.0178.00.dll (Microsoft Corporation)
O18 - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\microsoft shared\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
O20 - AppInit_DLLs: (avgrsstx.dll) - C:\Windows\System32\avgrsstx.dll (AVG Technologies CZ, s.r.o.)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Users\Brittany R Belcher\Pictures\Fall 2009\2009-10-12 2009 Fall Weddings\2009 Fall Weddings 036.JPG
O24 - Desktop BackupWallPaper: C:\Users\Brittany R Belcher\Pictures\Fall 2009\2009-10-12 2009 Fall Weddings\2009 Fall Weddings 036.JPG
O28 - HKLM ShellExecuteHooks: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006/09/18 15:43:36 | 000,000,024 | —- | M] () - C:\autoexec.bat – [ NTFS ]
O33 - MountPoints2\{acb7fd8f-06d6-11dd-ac9c-001c23845fb1}\Shell\AutoRun\command - "" = F:\JDSecure\Windows\JDSecure31.exe – File not found
O33 - MountPoints2\{bbcf3106-9eaa-11de-a381-001c23845fb1}\Shell - "" = AutoRun
O33 - MountPoints2\{bbcf3106-9eaa-11de-a381-001c23845fb1}\Shell\AutoRun\command - "" = F:\ImageViewer4.exe – File not found
O33 - MountPoints2\{f4e18577-9860-11de-acdb-001c23845fb1}\Shell\Explore\command - "" = F:\system.exe – File not found
O33 - MountPoints2\{f4e18577-9860-11de-acdb-001c23845fb1}\Shell\Open\command - "" = F:\system.exe – File not found
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - comfile [open] – "%1" %*
O35 - exefile [open] – "%1" %*

========== Files/Folders - Created Within 30 Days ==========

[2010/02/09 20:51:07 | 000,000,000 | —D | C] – C:\Users\Brittany R Belcher\Desktop\Scans
[2010/02/09 20:26:09 | 000,549,376 | —- | C] (OldTimer Tools) – C:\Users\Brittany R Belcher\Desktop\OTL.exe
[2010/02/09 15:42:16 | 000,000,000 | —D | C] – C:\Windows\ERDNT
[2010/02/09 15:40:58 | 000,000,000 | —D | C] – C:\Program Files\ERUNT
[2010/02/09 15:39:11 | 000,791,393 | —- | C] (Lars Hederer ) – C:\Users\Brittany R Belcher\Desktop\erunt_setup.exe
[2010/02/09 15:33:01 | 000,021,504 | —- | C] (Doug Knox) – C:\Users\Brittany R Belcher\Desktop\SysRestorePoint.exe
[2010/02/08 18:49:31 | 000,050,688 | —- | C] (Atribune.org) – C:\Users\Brittany R Belcher\Desktop\ATF-Cleaner.exe
[2010/02/08 10:27:56 | 000,000,000 | —D | C] – C:\ProgramData\yikavaji
[2010/02/08 10:27:56 | 000,000,000 | —D | C] – C:\ProgramData\pirotima
[2010/02/08 10:27:56 | 000,000,000 | —D | C] – C:\ProgramData\padofewi
[2010/02/08 10:27:23 | 000,000,000 | —D | C] – C:\ProgramData\zevububu
[2010/02/08 10:27:23 | 000,000,000 | —D | C] – C:\ProgramData\tiruyagu
[2010/02/08 10:27:23 | 000,000,000 | —D | C] – C:\ProgramData\midinuro
[2010/02/08 10:27:23 | 000,000,000 | —D | C] – C:\ProgramData\hodisuto
[2010/02/08 07:31:36 | 000,000,000 | —D | C] – C:\Users\Brittany R Belcher\AppData\Roaming\Malwarebytes
[2010/02/08 07:31:31 | 000,038,224 | —- | C] (Malwarebytes Corporation) – C:\Windows\System32\drivers\mbamswissarmy.sys
[2010/02/08 07:31:28 | 000,019,160 | —- | C] (Malwarebytes Corporation) – C:\Windows\System32\drivers\mbam.sys
[2010/02/08 07:31:28 | 000,000,000 | —D | C] – C:\Program Files\Malwarebytes' Anti-Malware
[2010/02/08 07:31:28 | 000,000,000 | —D | C] – C:\ProgramData\Malwarebytes
[2010/02/07 22:33:20 | 000,000,000 | —D | C] – C:\Users\Brittany R Belcher\AppData\Roaming\schtml
[2010/02/07 22:28:41 | 000,000,000 | —D | C] – C:\Users\Brittany R Belcher\AppData\Roaming\Your PC Protector
[2010/02/07 22:27:21 | 000,000,000 | —D | C] – C:\ProgramData\kemowisu
[2010/02/07 22:27:21 | 000,000,000 | —D | C] – C:\ProgramData\kegawida
[2010/02/07 22:27:21 | 000,000,000 | —D | C] – C:\ProgramData\kalufuli
[2010/02/07 22:22:08 | 000,000,000 | —D | C] – C:\ProgramData\zajezumu
[2010/02/07 22:22:08 | 000,000,000 | —D | C] – C:\ProgramData\momenena
[2010/02/07 22:22:08 | 000,000,000 | —D | C] – C:\ProgramData\fonipebo
[2010/01/21 19:59:30 | 000,380,928 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieapfltr.dll
[2010/01/21 19:59:29 | 000,458,240 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msfeeds.dll
[2010/01/21 19:59:29 | 000,389,120 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iedkcs32.dll
[2010/01/21 19:59:29 | 000,193,024 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iepeers.dll
[2010/01/21 19:59:28 | 000,671,232 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mstime.dll
[2010/01/21 19:59:28 | 000,389,632 | —- | C] (Microsoft Corporation) – C:\Windows\System32\html.iec
[2010/01/21 19:59:28 | 000,230,400 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieaksie.dll
[2010/01/21 19:59:28 | 000,078,336 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieencode.dll
[2010/01/21 19:59:28 | 000,026,624 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieUnatt.exe
[2010/01/21 19:59:27 | 001,383,424 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mshtml.tlb
[2010/01/21 19:59:27 | 000,028,160 | —- | C] (Microsoft Corporation) – C:\Windows\System32\jsproxy.dll
[2010/01/12 19:45:34 | 000,156,672 | —- | C] (Microsoft Corporation) – C:\Windows\System32\t2embed.dll
[2010/01/12 19:45:34 | 000,072,704 | —- | C] (Microsoft Corporation) – C:\Windows\System32\fontsub.dll

========== Files - Modified Within 30 Days ==========

[2010/02/09 21:10:33 | 000,690,960 | —- | M] () – C:\Windows\System32\PerfStringBackup.INI
[2010/02/09 21:10:33 | 000,595,684 | —- | M] () – C:\Windows\System32\perfh009.dat
[2010/02/09 21:10:33 | 000,101,350 | —- | M] () – C:\Windows\System32\perfc009.dat
[2010/02/09 21:08:02 | 002,883,584 | -HS- | M] () – C:\Users\Brittany R Belcher\NTUSER.DAT
[2010/02/09 21:04:03 | 000,003,552 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2010/02/09 21:04:02 | 000,003,552 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2010/02/09 21:03:56 | 000,000,006 | -H– | M] () – C:\Windows\tasks\SA.DAT
[2010/02/09 21:03:49 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2010/02/09 21:03:44 | 2011,324,416 | -HS- | M] () – C:\hiberfil.sys
[2010/02/09 21:03:41 | 117,645,209 | —- | M] () – C:\Windows\MEMORY.DMP
[2010/02/09 20:55:04 | 000,524,288 | -HS- | M] () – C:\Users\Brittany R Belcher\NTUSER.DAT{d8932e6d-6a6f-11db-b6ab-a038f15a5785}.TMContainer00000000000000000001.regtrans-ms
[2010/02/09 20:55:04 | 000,065,536 | -HS- | M] () – C:\Users\Brittany R Belcher\NTUSER.DAT{d8932e6d-6a6f-11db-b6ab-a038f15a5785}.TM.blf
[2010/02/09 20:55:00 | 001,608,134 | -H– | M] () – C:\Users\Brittany R Belcher\AppData\Local\IconCache.db
[2010/02/09 20:26:23 | 000,549,376 | —- | M] (OldTimer Tools) – C:\Users\Brittany R Belcher\Desktop\OTL.exe
[2010/02/09 17:53:44 | 055,361,540 | —- | M] () – C:\Windows\System32\drivers\Avg\incavi.avm
[2010/02/09 15:41:04 | 000,000,735 | —- | M] () – C:\Users\Brittany R Belcher\Desktop\NTREGOPT.lnk
[2010/02/09 15:41:03 | 000,000,716 | —- | M] () – C:\Users\Brittany R Belcher\Desktop\ERUNT.lnk
[2010/02/09 15:39:23 | 000,791,393 | —- | M] (Lars Hederer ) – C:\Users\Brittany R Belcher\Desktop\erunt_setup.exe
[2010/02/09 15:33:03 | 000,021,504 | —- | M] (Doug Knox) – C:\Users\Brittany R Belcher\Desktop\SysRestorePoint.exe
[2010/02/09 15:24:50 | 000,000,000 | —- | M] () – C:\Users\Brittany R Belcher\defogger_reenable
[2010/02/08 18:51:46 | 000,293,376 | —- | M] () – C:\Users\Brittany R Belcher\Desktop\fgh.exe
[2010/02/08 18:49:35 | 000,050,688 | —- | M] (Atribune.org) – C:\Users\Brittany R Belcher\Desktop\ATF-Cleaner.exe
[2010/02/08 18:47:49 | 000,050,477 | —- | M] () – C:\Users\Brittany R Belcher\Desktop\Defogger.exe
[2010/02/08 18:00:35 | 000,006,456 | -H– | M] () – C:\ProgramData\semewosu
[2010/02/08 07:31:34 | 000,000,820 | —- | M] () – C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2010/02/08 07:30:34 | 000,000,299 | —- | M] () – C:\Users\Brittany R Belcher\Desktop\mbam-setup - Shortcut.lnk
[2010/02/07 23:45:33 | 000,000,083 | —- | M] () – C:\Users\Brittany R Belcher\AppData\Roaming\wp4.dat
[2010/02/07 23:45:33 | 000,000,002 | —- | M] () – C:\Users\Brittany R Belcher\AppData\Roaming\wp3.dat
[2010/02/07 22:28:56 | 000,000,036 | —- | M] () – C:\Users\Brittany R Belcher\AppData\Roaming\skynet.dat
[2010/02/07 22:28:52 | 000,000,009 | —- | M] () – C:\Users\Brittany R Belcher\AppData\Roaming\nuar.old
[2010/02/07 15:06:06 | 000,013,168 | —- | M] () – C:\Users\Brittany R Belcher\Documents\check register.docx
[2010/02/07 14:21:57 | 000,013,505 | —- | M] () – C:\Users\Brittany R Belcher\Documents\Bugdet Worksheet.docx
[2010/02/04 16:48:27 | 000,015,307 | —- | M] () – C:\Users\Brittany R Belcher\Documents\5.docx
[2010/01/22 03:21:30 | 000,142,495 | —- | M] () – C:\Windows\System32\drivers\Avg\microavi.avg
[2010/01/14 11:12:06 | 000,181,120 | —- | M] (Microsoft Corporation) – C:\Windows\System32\MpSigStub.exe

========== Files Created - No Company Name ==========

[2099/01/01 12:00:00 | 000,006,456 | -H– | C] () – C:\ProgramData\semewosu
[2010/02/09 21:03:44 | 2011,324,416 | -HS- | C] () – C:\hiberfil.sys
[2010/02/09 15:41:04 | 000,000,735 | —- | C] () – C:\Users\Brittany R Belcher\Desktop\NTREGOPT.lnk
[2010/02/09 15:41:03 | 000,000,716 | —- | C] () – C:\Users\Brittany R Belcher\Desktop\ERUNT.lnk
[2010/02/09 15:24:50 | 000,000,000 | —- | C] () – C:\Users\Brittany R Belcher\defogger_reenable
[2010/02/08 18:51:36 | 000,293,376 | —- | C] () – C:\Users\Brittany R Belcher\Desktop\fgh.exe
[2010/02/08 18:47:45 | 000,050,477 | —- | C] () – C:\Users\Brittany R Belcher\Desktop\Defogger.exe
[2010/02/08 07:31:34 | 000,000,820 | —- | C] () – C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2010/02/08 07:30:34 | 000,000,299 | —- | C] () – C:\Users\Brittany R Belcher\Desktop\mbam-setup - Shortcut.lnk
[2010/02/07 22:28:52 | 000,000,009 | —- | C] () – C:\Users\Brittany R Belcher\AppData\Roaming\nuar.old
[2010/02/07 22:28:51 | 000,000,083 | —- | C] () – C:\Users\Brittany R Belcher\AppData\Roaming\wp4.dat
[2010/02/07 22:28:51 | 000,000,036 | —- | C] () – C:\Users\Brittany R Belcher\AppData\Roaming\skynet.dat
[2010/02/07 22:28:51 | 000,000,002 | —- | C] () – C:\Users\Brittany R Belcher\AppData\Roaming\wp3.dat
[2010/02/07 15:06:05 | 000,013,168 | —- | C] () – C:\Users\Brittany R Belcher\Documents\check register.docx
[2010/02/07 14:21:56 | 000,013,505 | —- | C] () – C:\Users\Brittany R Belcher\Documents\Bugdet Worksheet.docx
[2010/02/04 16:48:22 | 000,015,307 | —- | C] () – C:\Users\Brittany R Belcher\Documents\5.docx
[2009/06/16 17:36:41 | 000,000,300 | —- | C] () – C:\Users\Brittany R Belcher\AppData\Roaming\wklnhst.dat
[2008/07/05 08:21:05 | 000,008,248 | —- | C] () – C:\ProgramData\LUUnInstall.LiveUpdate
[2007/08/28 19:51:48 | 000,000,778 | —- | C] () – C:\ProgramData\hpzinstall.log
[2007/08/19 21:46:56 | 000,017,920 | —- | C] () – C:\Users\Brittany R Belcher\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2007/08/10 13:07:08 | 000,159,744 | —- | C] () – C:\Windows\System32\atitmmxx.dll
[2007/08/10 13:07:06 | 000,016,480 | —- | C] () – C:\Windows\System32\rixdicon.dll
[2007/08/10 13:06:53 | 001,060,424 | —- | C] () – C:\Windows\System32\WdfCoInstaller01000.dll
[2007/08/10 05:35:51 | 000,065,536 | —- | C] () – C:\Windows\System32\bcmwlrmt.dll
[2007/08/10 05:31:17 | 000,006,656 | —- | C] () – C:\Windows\System32\stacutil.dll
[2006/11/07 13:25:58 | 000,000,000 | —- | C] () – C:\Windows\System32\px.ini
[2006/11/02 01:40:29 | 000,013,750 | —- | C] () – C:\Windows\System32\pacerprf.ini
[2006/09/16 22:36:50 | 000,520,192 | —- | C] () – C:\Windows\System32\CddbPlaylist2Roxio.dll
[2006/09/16 22:36:50 | 000,204,800 | —- | C] () – C:\Windows\System32\CddbFileTaggerRoxio.dll
[2002/01/25 05:47:51 | 000,077,824 | —- | C] () – C:\Windows\System32\lxazlcnp.dll

========== LOP Check ==========

[2008/12/22 21:05:12 | 000,000,000 | —D | M] – C:\Users\Brittany R Belcher\AppData\Roaming\acccore
[2008/11/16 21:58:59 | 000,000,000 | —D | M] – C:\Users\Brittany R Belcher\AppData\Roaming\Grisoft
[2008/12/24 19:45:34 | 000,000,000 | —D | M] – C:\Users\Brittany R Belcher\AppData\Roaming\Image Zone Express
[2009/04/17 23:53:19 | 000,000,000 | —D | M] – C:\Users\Brittany R Belcher\AppData\Roaming\LimeWire
[2008/01/03 21:16:09 | 000,000,000 | —D | M] – C:\Users\Brittany R Belcher\AppData\Roaming\Printer Info Cache
[2010/02/07 23:01:24 | 000,000,000 | —D | M] – C:\Users\Brittany R Belcher\AppData\Roaming\schtml
[2009/06/16 17:36:44 | 000,000,000 | —D | M] – C:\Users\Brittany R Belcher\AppData\Roaming\Template
[2010/02/07 23:45:36 | 000,000,000 | —D | M] – C:\Users\Brittany R Belcher\AppData\Roaming\Your PC Protector
[2010/02/09 20:55:07 | 000,032,602 | —- | M] () – C:\Windows\Tasks\SCHEDLGU.TXT

========== Purity Check ==========


< End of report >

OTL Extras logfile created on: 2/9/2010 9:08:41 PM - Run 1
OTL by OldTimer - Version 3.1.28.0 Folder = C:\Users\Brittany R Belcher\Desktop
Windows Vista Home Basic Edition Service Pack 1 (Version = 6.0.6001) - Type = NTWorkstation
Internet Explorer (Version = 7.0.6001.18000)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

2.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 62.00% Memory free
4.00 Gb Paging File | 3.00 Gb Available in Paging File | 79.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 136.50 Gb Total Space | 89.79 Gb Free Space | 65.78% Space Free | Partition Type: NTFS
Drive D: | 10.00 Gb Total Space | 6.50 Gb Free Space | 65.01% Space Free | Partition Type: NTFS
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: BRITTANYRBEL-PC
Current User Name: Brittany R Belcher
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – C:\Windows\System32\control.exe (Microsoft Corporation)
.hlp [@ = hlpfile] – C:\Windows\winhlp32.exe (Microsoft Corporation)
.html [@ = htmlfile] – C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation)

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
hlpfile [open] – %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation)
htmlfile – "C:\Program Files\Microsoft Office\Office12\msohtmed.exe" %1 (Microsoft Corporation)
htmlfile [open] – "C:\Program Files\Internet Explorer\iexplore.exe" -nohome (Microsoft Corporation)
htmlfile [opennew] – "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
htmlfile [print] – "C:\Program Files\Microsoft Office\Office12\msohtmed.exe" /p %1 (Microsoft Corporation)
http [open] – "C:\Program Files\Internet Explorer\iexplore.exe" -nohome (Microsoft Corporation)
https [open] – "C:\Program Files\Internet Explorer\iexplore.exe" -nohome (Microsoft Corporation)
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [OneNote.Open] – C:\PROGRA~1\MICROS~3\Office12\ONENOTE.EXE "%L" (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe /separate,/idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /separate,/e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Applications\iexplore.exe [open] – "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] – "C:\Program Files\Internet Explorer\iexplore.exe" (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1
"UacDisableNotify" = 1
"InternetSettingsDisableNotify" = 1
"AutoUpdateDisableNotify" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
"DisableMonitoring" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
"DisableMonitoring" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]
"DisableMonitoring" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
"VistaSp1" = Reg Error: Unknown registry data type – File not found

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"DisableNotifications" = 0
"EnableFirewall" = 0

========== Authorized Applications List ==========


========== Vista Active Open Ports Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{5C3F506E-D207-44DC-8E95-3A584EBA42E1}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=svchost.exe |
"{C0A768C6-77E2-4BC8-BE8A-5FF0FC150472}" = lport=6004 | protocol=17 | dir=in | app=c:\program files\microsoft office\office12\outlook.exe |
"{EEC00DF6-F52F-4566-981F-3469D48BBE30}" = lport=2869 | protocol=6 | dir=in | app=system |

========== Vista Active Application Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{02082FE9-EBBF-4A93-A854-B7563865B24C}" = dir=in | app=c:\program files\avg\avg8\avgupd.exe |
"{0D002AA2-E40B-46BB-8784-39965D09562A}" = protocol=6 | dir=in | app=c:\program files\common files\aol\loader\aolload.exe |
"{0DE26C2C-20F7-44DE-8C9B-E4D73B6ED918}" = protocol=6 | dir=in | app=c:\program files\microsoft office\office12\onenote.exe |
"{11A49973-5BBF-4931-838C-A0B6FB98E6FD}" = dir=in | app=c:\program files\msn messenger\msnmsgr.exe |
"{1F829099-7C58-493A-866E-F2E5F5DD8187}" = protocol=17 | dir=in | app=c:\program files\aim6\aim6.exe |
"{5447BB94-C705-4E86-9254-EFA972233495}" = protocol=17 | dir=in | app=c:\program files\microsoft office\office12\onenote.exe |
"{562707C4-C81C-4BCE-98E4-9BC43950B972}" = protocol=6 | dir=in | app=c:\program files\yahoo!\yahoo! music jukebox\yahoomusicengine.exe |
"{5FD68021-33DC-417C-8C5A-872B85028AD4}" = dir=in | app=c:\program files\dell\mediadirect\kernel\dmp\clbrowserengine.exe |
"{7AA39CDF-2672-4F80-B1B7-3CF836449D63}" = protocol=6 | dir=in | app=c:\users\brittany r belcher\desktop\music\limewire\limewire.exe |
"{7C06A4B8-A3EF-4EBB-9B21-DD6EB3DEF41D}" = dir=in | app=c:\program files\avg\avg8\avgnsx.exe |
"{8FB21B0D-4D6F-4C5E-A3EB-527F50798EEF}" = protocol=17 | dir=in | app=c:\users\brittany r belcher\desktop\music\limewire\limewire.exe |
"{9DCDE91F-7477-45A4-9653-EACDA6EAC68B}" = dir=in | app=c:\program files\msn messenger\livecall.exe |
"{AAEA28D7-6EBC-4D24-88EB-32DF16E093F3}" = protocol=17 | dir=in | app=c:\program files\microsoft office\office12\groove.exe |
"{AB6A8171-0C5B-4646-98A6-D5299DBFEED0}" = dir=in | app=c:\program files\dell\mediadirect\pcmservice.exe |
"{AE851F4C-834E-4A43-A52B-61F883A06EDD}" = protocol=17 | dir=in | app=c:\program files\yahoo!\yahoo! music jukebox\yahoomusicengine.exe |
"{C1D51714-8AC8-4BB2-8D3A-89C63BDB694B}" = dir=in | app=c:\program files\dell\mediadirect\powercinema.exe |
"{C509DB86-952D-4011-986E-4A748840B919}" = protocol=17 | dir=in | app=c:\program files\common files\aol\loader\aolload.exe |
"{DC517504-1080-4600-8665-F5C6A0BF9BB7}" = protocol=6 | dir=in | app=c:\program files\microsoft office\office12\groove.exe |
"{DC7E29A6-CCED-4268-A5E3-02EE8DB2E580}" = dir=in | app=c:\program files\dell\mediadirect\kernel\dms\clmsservice.exe |
"{E266C007-0B98-4144-B622-6F2D2913897A}" = protocol=6 | dir=in | app=c:\program files\aim6\aim6.exe |
"TCP Query User{25B86381-D4DA-4063-B043-C8F635747950}C:\program files\internet explorer\iexplore.exe" = protocol=6 | dir=in | app=c:\program files\internet explorer\iexplore.exe |
"TCP Query User{544101A1-8DC4-4D64-9B7C-4A90ABE7AD50}C:\users\brittany r belcher\desktop\music\limewire\limewire.exe" = protocol=6 | dir=in | app=c:\users\brittany r belcher\desktop\music\limewire\limewire.exe |
"TCP Query User{72D3080E-1EA4-4E5A-9D68-79566ECD635D}C:\program files\aim6\aim6.exe" = protocol=6 | dir=in | app=c:\program files\aim6\aim6.exe |
"TCP Query User{FD56BCD9-2582-4090-9723-3A7B5F6F090B}C:\program files\internet explorer\iexplore.exe" = protocol=6 | dir=in | app=c:\program files\internet explorer\iexplore.exe |
"UDP Query User{1B683133-C6C2-494A-8F1A-8353D013F4BF}C:\program files\internet explorer\iexplore.exe" = protocol=17 | dir=in | app=c:\program files\internet explorer\iexplore.exe |
"UDP Query User{59CF982F-60AE-4172-A421-A12212762C8E}C:\program files\aim6\aim6.exe" = protocol=17 | dir=in | app=c:\program files\aim6\aim6.exe |
"UDP Query User{DDCED9A7-D8AB-45D1-95FE-12BD7EF9FBBE}C:\users\brittany r belcher\desktop\music\limewire\limewire.exe" = protocol=17 | dir=in | app=c:\users\brittany r belcher\desktop\music\limewire\limewire.exe |
"UDP Query User{EBA3D84A-4585-4F03-A005-9C727D1707E8}C:\program files\internet explorer\iexplore.exe" = protocol=17 | dir=in | app=c:\program files\internet explorer\iexplore.exe |

========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{0394CDC8-FABD-4ed8-B104-03393876DFDF}" = Roxio Creator Tools
"{055EE59D-217B-43A7-ABFF-507B966405D8}" = ATI Catalyst Control Center
"{0D2E9DCB-9938-475E-B4DD-8851738852FF}" = AIO_Scan
"{0D397393-9B50-4c52-84D5-77E344289F87}" = Roxio Creator Data
"{13BA7B44-B712-4DEE-A7B8-1DD564F37AE5}" = Dell System Customization Wizard
"{1746EA69-DCB6-4408-B5A5-E75F55439CDF}" = Scan
"{179C56A4-F57F-4561-8BBF-F911D26EB435}" = WebReg
"{1FBE067B-EDA5-C4DC-1CAE-0A97869668F5}" = CCC Help English
"{233A09B2-5DDD-1D47-41F3-283243CD6E58}" = Catalyst Control Center Localization Finnish
"{2357B8BC-88C9-4A72-818C-050CC4EB0778}" = AOL Install
"{24557DC0-0839-496f-82F9-C4EB72EFE4FA}" = HP Deskjet All-In-One Software 8.0
"{26521EB6-D0C1-9AA9-EC73-743A75F5E390}" = CCC Help German
"{28166874-4E4D-AA06-22D5-3FFF80D9DF71}" = CCC Help Norwegian
"{2C6C74C2-042F-4D36-B7B0-0C538FCF01AB}" = Dell DataSafe Online
"{30465B6C-B53F-49A1-9EBA-A3F187AD502E}" = Roxio Update Manager
"{3248F0A8-6813-11D6-A77B-00B0D0160000}" = Java™ SE Runtime Environment 6
"{352310C3-E46B-42D3-8F32-54721FDD72D9}" = NetZeroInstallers
"{35E1EC43-D4FC-4E4A-AAB3-20DDA27E8BB0}" = Sonic Activation Module
"{3D736E48-0BFE-1E36-C3CC-D40027C8D779}" = CCC Help Chinese Traditional
"{3E25E350-949F-4DB7-8288-2A60E018B4C1}" = Games, Music, & Photos Launcher
"{3EE33958-7381-4E7B-A4F3-6E43098E9E9C}" = URL Assistant
"{3F92ABBB-6BBF-11D5-B229-002078017FBF}" = NetWaiting
"{3FA54B99-76EA-54D7-E821-3A6D4C58B485}" = Catalyst Control Center Localization Korean
"{4902AA2F-558B-709F-2EC4-ABCCA5817DE2}" = Catalyst Control Center Localization Chinese Standard
"{4AE661B2-2CA3-689C-7B07-633946D93DBA}" = Catalyst Control Center Localization Spanish
"{4BCDF14A-0140-DAA1-197D-2A0714C304EB}" = CCC Help Dutch
"{4F5A53E6-3CBE-44D7-91AD-2E535348484F}" = ccc-Branding
"{571700F0-DB9D-4B3A-B03D-35A14BB5939F}" = Windows Live Messenger
"{5985DC34-0F90-473E-4B11-79BDD38129EA}" = CCC Help Italian
"{5B5B4253-B83B-970A-BF2A-BE76EB105C17}" = Catalyst Control Center Core Implementation
"{5CD29180-A95E-11D3-A4EB-00C04F7BDB2C}" = User's Guides
"{5E68BB65-4059-4FE5-AAC4-0CD1D79BBDE2}" = EarthLink Setup Files
"{5F818EFF-7F69-3E9A-EA3D-78F7C3A6FD61}" = Catalyst Control Center Graphics Light
"{619CDD8A-14B6-43a1-AB6C-0F4EE48CE048}" = Roxio Creator Copy
"{657F8B33-CBBB-45F4-9087-274F22C89400}" = DJ_AIO_ProductContext
"{6675CA7F-E51B-4F6A-99D4-F8F0124C6EAA}" = Roxio Express Labeler
"{66E6CE0C-5A1E-430C-B40A-0C90FF1804A8}" = eSupportQFolder
"{67D3F1A0-A1F2-49b7-B9EE-011277B170CD}" = HPProductAssistant
"{69D4EE67-EE0D-9CC4-1FDF-189B136EE1E5}" = ccc-utility
"{6D52C408-B09A-4520-9B18-475B81D393F1}" = Microsoft Works
"{6F5E2F4A-377D-4700-B0E3-8F7F7507EA15}" = CustomerResearchQFolder
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{74EB8F02-9EA7-5893-93E9-17C473D919EA}" = CCC Help Portuguese
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{7C49EA42-5647-4051-84C2-E6404F25A931}" = Yahoo! Music Jukebox
"{7DDEABFB-0621-4321-B385-CB86D3A6F90F}" = F4100
"{7EFA5E6F-74F7-4AFB-8AEA-AA790BD3A76D}" = DellSupport
"{7F0C4457-8E64-491B-8D7B-991504365D1E}" = QuickSet
"{801A52D3-2855-BF00-0F13-8CFE6F79047D}" = Catalyst Control Center Localization Portuguese
"{80A50951-628C-2476-095F-57BABB5B23B6}" = CCC Help Spanish
"{80F05497-9244-9323-44D2-A919DDD7E4CC}" = Catalyst Control Center Localization Dutch
"{83FFCFC7-88C6-41c6-8752-958A45325C82}" = Roxio Creator Audio
"{880AF49C-34F7-4285-A8AD-8F7A3D1C33DC}" = Roxio Creator BDAV Plugin
"{89CEAE14-DD0F-448E-9554-15781EC9DB24}" = Product Documentation Launcher
"{8A46C2AE-E88F-191E-5EA6-8BDBC37726F9}" = Catalyst Control Center Localization Norwegian
"{8C6027FD-53DC-446D-BB75-CACD7028A134}" = HP Update
"{90120000-0015-0409-0000-0000000FF1CE}" = Microsoft Office Access MUI (English) 2007
"{90120000-0015-0409-0000-0000000FF1CE}_ENTERPRISER_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2007
"{90120000-0016-0409-0000-0000000FF1CE}_ENTERPRISER_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2007
"{90120000-0018-0409-0000-0000000FF1CE}_ENTERPRISER_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0019-0409-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (English) 2007
"{90120000-0019-0409-0000-0000000FF1CE}_ENTERPRISER_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001A-0409-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (English) 2007
"{90120000-001A-0409-0000-0000000FF1CE}_ENTERPRISER_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2007
"{90120000-001B-0409-0000-0000000FF1CE}_ENTERPRISER_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}_ENTERPRISER_{ABDDE972-355B-4AF1-89A8-DA50B7B5C045}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-040C-0000-0000000FF1CE}_ENTERPRISER_{F580DDD5-8D37-4998-968E-EBB76BB86787}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007
"{90120000-001F-0C0A-0000-0000000FF1CE}_ENTERPRISER_{187308AB-5FA7-4F14-9AB9-D290383A10D9}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007
"{90120000-0044-0409-0000-0000000FF1CE}" = Microsoft Office InfoPath MUI (English) 2007
"{90120000-0044-0409-0000-0000000FF1CE}_ENTERPRISER_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}_ENTERPRISER_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-00A1-0409-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2007
"{90120000-00A1-0409-0000-0000000FF1CE}_ENTERPRISER_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-00BA-0409-0000-0000000FF1CE}" = Microsoft Office Groove MUI (English) 2007
"{90120000-00BA-0409-0000-0000000FF1CE}_ENTERPRISER_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0114-0409-0000-0000000FF1CE}" = Microsoft Office Groove Setup Metadata MUI (English) 2007
"{90120000-0114-0409-0000-0000000FF1CE}_ENTERPRISER_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007
"{90120000-0115-0409-0000-0000000FF1CE}_ENTERPRISER_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0117-0409-0000-0000000FF1CE}" = Microsoft Office Access Setup Metadata MUI (English) 2007
"{90120000-0117-0409-0000-0000000FF1CE}_ENTERPRISER_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{91120000-0030-0000-0000-0000000FF1CE}" = Microsoft Office Enterprise 2007
"{91120000-0030-0000-0000-0000000FF1CE}_ENTERPRISER_{0B36C6D6-F5D8-4EAF-BF94-4376A230AD5B}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{91120000-0030-0000-0000-0000000FF1CE}_ENTERPRISER_{3D019598-7B59-447A-80AE-815B703B84FF}" = Security Update for Microsoft Office system 2007 (972581)
"{916DA72C-457F-E1F6-E121-B15E38F79C0D}" = CCC Help Japanese
"{9306D753-8B36-06D4-0C39-9E6D58441C6C}" = Catalyst Control Center Localization Japanese
"{95D08F4E-DFC2-4ce3-ACB7-8C8E206217E9}" = MarketResearch
"{978C25EE-5777-46e4-8988-732C297CBDBD}" = Status
"{99713F20-B2FA-5B9F-0775-46378377F905}" = Catalyst Control Center Localization Chinese Traditional
"{9B1FD9CE-0776-4f0b-A6F5-C6AB7B650CDF}" = Destinations
"{9BCA646B-4EDE-5178-9755-4B3860F57111}" = Catalyst Control Center Localization Italian
"{9BD418EE-31DE-1A67-5D3B-C83B0FAEAFBE}" = ccc-core-static
"{9BDEF074-020E-458D-ADC5-8FF68E0C9B56}" = OutlookAddinSetup
"{9C573DB4-847C-44E2-D7EE-CC6640441A27}" = Catalyst Control Center Localization French
"{9C6978E8-B6D0-4AB7-A7A0-D81A74FBF745}" = MediaDirect
"{9ECB4705-B9CB-405A-B6D4-33BDF707308E}" = DJ_AIO_Software
"{A36CD345-625C-4d6c-B3E2-76E1248CB451}" = SolutionCenter
"{A3B7C670-4A1E-4EE2-950E-C875BC1965D0}" = Copy
"{A462213D-EED4-42C2-9A60-7BDD4D4B0B17}" = SigmaTel Audio
"{A5B6B6E2-3460-567B-D269-38E0C99B455B}" = CCC Help Russian
"{AB5D51AE-EBC3-438D-872C-705C7C2084B0}" = DeviceManagementQFolder
"{AC76BA86-7AD7-1033-7B44-A70800000002}" = Adobe Reader 7.0.8
"{ACE22C48-49D7-4531-BE20-5C3D03393AB6}" = F4100_Help
"{B0BC58D2-3B22-6E43-E755-97569B788832}" = Catalyst Control Center Localization German
"{B4F4B5A5-9B6E-15DC-BB9B-7AF45168F1DE}" = Catalyst Control Center Graphics Full Existing
"{B8C54AB1-7E1A-40E8-B794-EDB6E8921F3A}" = Dell Support Center
"{BB4CC91D-63C5-85F6-D7DE-2FECD29639F6}" = CCC Help Danish
"{BE77A81F-B315-4666-9BF3-AE70C0ADB057}" = BufferChm
"{C0E5147E-C9F3-4360-9ED0-2E875F11766C}" = Respondus LockDown Browser
"{C2CBDFC6-D4E0-5747-5EBE-7579611CC562}" = Catalyst Control Center Graphics Full New
"{C45901E9-F9B0-5F5A-C40E-BA45B115D76B}" = Catalyst Control Center Localization Russian
"{C61664A1-6832-57B6-6189-0CD3F4E25E2F}" = CCC Help French
"{C716522C-3731-4667-8579-40B098294500}" = Toolbox
"{C8AF8F27-F6D1-9193-9F1A-8CFFE2B2A9E6}" = CCC Help Finnish
"{C8B0680B-CDAE-4809-9F91-387B6DE00F7C}" = Roxio Creator DE
"{C99C0593-3B48-41D9-B42F-6E035B320449}" = Broadcom Management Programs
"{CB1C5826-5A8A-1856-BB92-29704009E56F}" = Catalyst Control Center Localization Swedish
"{CC187DB7-98D2-5485-4084-A092F9BB1F84}" = CCC Help Korean
"{CCFF1E13-77A2-4032-8B12-7566982A27DF}" = Internet Service Offers Launcher
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{D639085F-4B6E-4105-9F37-A0DBB023E2FB}" = Roxio MyDVD DE
"{D65FB87A-566D-2457-4775-899C220E048E}" = CCC Help Chinese Standard
"{DBA4DB9D-EE51-4944-A419-98AB1F1249C8}" = LiveUpdate Notice (Symantec Corporation)
"{DC83F417-8068-4074-BA2F-C4F8AB872556}" = DJ_AIO_Software_min
"{DD43D652-6932-A54F-D7A5-D6448379E8F9}" = CCC Help Swedish
"{E06F04B9-45E6-4AC0-8083-85F7515F40F7}" = UnloadSupport
"{E17047A0-167D-1BA3-983E-CEE6ED87A890}" = Skins
"{E646DCF0-5A68-11D5-B229-002078017FBF}" = Digital Line Detect
"{E713653C-8312-4BC6-AFC9-ADE1F2F04AB9}" = ATI PCI Express (3GIO) Filter Driver
"{EB21A812-671B-4D08-B974-2A347F0D8F70}" = HP Photosmart Essential
"{EB75DE50-5754-4F6F-875D-126EDF8E4CB3}" = HPSSupply
"{F1E63043-54FC-429B-AB2C-31AF9FBA4BC7}" = 32 Bit HP CIO Components Installer
"{F63A3748-B93D-4360-9AD4-B064481A5C7B}" = Modem Diagnostic Tool
"{F99AFBD3-0276-AF23-C1CC-FBF6A5F2865C}" = Catalyst Control Center Localization Danish
"{FF075778-6E50-47ed-991D-3B07FD4E3250}" = TrayApp
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"AVG8Uninstall" = AVG Free 8.5
"Broadcom 802.11b Network Adapter" = Dell Wireless WLAN Card
"CNXT_MODEM_HDAUDIO_VEN_14F1&DEV_2C06&SUBSYS_14F1000F" = Conexant HDA D330 MDC V.92 Modem
"ENTERPRISER" = Microsoft Office Enterprise 2007
"ERUNT_is1" = ERUNT 1.1j
"HP Imaging Device Functions" = HP Imaging Device Functions 8.0
"HP Solution Center & Imaging Support Tools" = HP Solution Center 8.0
"HPExtendedCapabilities" = HP Customer Participation Program 8.0
"LiveUpdate" = LiveUpdate 3.2 (Symantec Corporation)
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Move Networks Player - IE" = Move Networks Media Player for Internet Explorer
"ShockwaveFlash" = Adobe Flash Player 9 ActiveX
"SoftwareUpdUtility" = Download Updater (AOL LLC)
"SynTPDeinstKey" = Dell Touchpad
"ViewpointMediaPlayer" = Viewpoint Media Player

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 11/4/2009 5:21:26 AM | Computer Name = BrittanyRBel-PC | Source = VSS | ID = 8194
Description =

Error - 11/8/2009 10:20:28 AM | Computer Name = BrittanyRBel-PC | Source = VSS | ID = 8194
Description =

Error - 11/23/2009 10:51:55 PM | Computer Name = BrittanyRBel-PC | Source = Application Hang | ID = 1002
Description = The program iexplore.exe version 7.0.6001.18319 stopped interacting
with Windows and was closed. To see if more information about the problem is available,
check the problem history in the Problem Reports and Solutions control panel. Process
ID: 1044 Start Time: 01ca6caede8872d0 Termination Time: 31

Error - 11/25/2009 12:28:29 PM | Computer Name = BrittanyRBel-PC | Source = VSS | ID = 8194
Description =

Error - 12/15/2009 9:25:23 PM | Computer Name = BrittanyRBel-PC | Source = VSS | ID = 8194
Description =

Error - 12/15/2009 9:27:10 PM | Computer Name = BrittanyRBel-PC | Source = VSS | ID = 8194
Description =

Error - 12/21/2009 9:35:46 PM | Computer Name = BrittanyRBel-PC | Source = VSS | ID = 8194
Description =

Error - 1/1/2010 3:47:37 PM | Computer Name = BrittanyRBel-PC | Source = Application Hang | ID = 1002
Description = The program iexplore.exe version 7.0.6001.18349 stopped interacting
with Windows and was closed. To see if more information about the problem is available,
check the problem history in the Problem Reports and Solutions control panel. Process
ID: 1300 Start Time: 01ca8b1b04719190 Termination Time: 78

Error - 1/7/2010 11:26:51 AM | Computer Name = BrittanyRBel-PC | Source = VSS | ID = 8194
Description =

Error - 1/7/2010 12:24:54 PM | Computer Name = BrittanyRBel-PC | Source = Application Hang | ID = 1002
Description = The program iexplore.exe version 7.0.6001.18349 stopped interacting
with Windows and was closed. To see if more information about the problem is available,
check the problem history in the Problem Reports and Solutions control panel. Process
ID: 1410 Start Time: 01ca8fad6270cbd0 Termination Time: 47

[ Broadcom Wireless LAN Events ]
Error - 7/20/2009 8:36:10 PM | Computer Name = BrittanyRBel-PC | Source = WLAN-Tray | ID = 0
Description = 19:36:10, Mon, Jul 20, 09 Error - Unable to gain access to user store


Error - 8/4/2009 8:51:52 PM | Computer Name = BRITTANYRBEL-PC | Source = WLAN-Tray | ID = 0
Description = 19:51:52, Tue, Aug 04, 09 Error - Unable to gain access to user store


Error - 8/31/2009 8:01:45 PM | Computer Name = BRITTANYRBEL-PC | Source = WLAN-Tray | ID = 0
Description = 19:01:44, Mon, Aug 31, 09 Error - Unable to gain access to user store


Error - 9/27/2009 1:39:26 PM | Computer Name = BrittanyRBel-PC | Source = WLAN-Tray | ID = 0
Description = 12:39:26, Sun, Sep 27, 09 Error - Unable to gain access to user store


Error - 2/8/2010 8:21:12 PM | Computer Name = BrittanyRBel-PC | Source = WLAN-Tray | ID = 0
Description = 18:21:12, Mon, Feb 08, 10 Error - Unable to gain access to user store


Error - 2/9/2010 6:36:12 PM | Computer Name = BrittanyRBel-PC | Source = WLAN-Tray | ID = 0
Description = 16:36:12, Tue, Feb 09, 10 Error - Unable to gain access to user store


Error - 2/9/2010 6:46:00 PM | Computer Name = BrittanyRBel-PC | Source = WLAN-Tray | ID = 0
Description = 16:46:00, Tue, Feb 09, 10 Error - Unable to gain access to user store


Error - 2/9/2010 9:00:30 PM | Computer Name = BrittanyRBel-PC | Source = WLAN-Tray | ID = 0
Description = 19:00:30, Tue, Feb 09, 10 Error - Unable to gain access to user store


Error - 2/9/2010 9:27:38 PM | Computer Name = BrittanyRBel-PC | Source = WLAN-Tray | ID = 0
Description = 19:27:38, Tue, Feb 09, 10 Error - Unable to gain access to user store


Error - 2/9/2010 11:03:58 PM | Computer Name = BrittanyRBel-PC | Source = WLAN-Tray | ID = 0
Description = 21:03:58, Tue, Feb 09, 10 Error - Unable to gain access to user store


[ OSession Events ]
Error - 1/30/2008 10:45:57 PM | Computer Name = BrittanyRBel-PC | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 3, Application Name: Microsoft Office PowerPoint, Application
Version: 12.0.4518.1014, Microsoft Office Version: 12.0.4518.1014. This session
lasted 220 seconds with 0 seconds of active time. This session ended with a crash.

Error - 7/8/2008 10:37:29 PM | Computer Name = BrittanyRBel-PC | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 0, Application Name: Microsoft Office Word, Application Version:
12.0.6308.5000, Microsoft Office Version: 12.0.4518.1014. This session lasted 102449
seconds with 1860 seconds of active time. This session ended with a crash.

Error - 6/10/2009 11:42:37 PM | Computer Name = BrittanyRBel-PC | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 0, Application Name: Microsoft Office Word, Application Version:
12.0.6331.5000, Microsoft Office Version: 12.0.6215.1000. This session lasted 2318
seconds with 2100 seconds of active time. This session ended with a crash.

Error - 7/15/2009 4:10:09 AM | Computer Name = BrittanyRBel-PC | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 1, Application Name: Microsoft Office Excel, Application Version:
12.0.6504.5001, Microsoft Office Version: 12.0.6215.1000. This session lasted 126779
seconds with 1500 seconds of active time. This session ended with a crash.

[ System Events ]
Error - 2/9/2010 10:59:55 PM | Computer Name = BrittanyRBel-PC | Source = DCOM | ID = 10005
Description =

Error - 2/9/2010 10:59:55 PM | Computer Name = BrittanyRBel-PC | Source = DCOM | ID = 10005
Description =

Error - 2/9/2010 10:59:55 PM | Computer Name = BrittanyRBel-PC | Source = Service Control Manager | ID = 7001
Description =

Error - 2/9/2010 10:59:55 PM | Computer Name = BrittanyRBel-PC | Source = Service Control Manager | ID = 7001
Description =

Error - 2/9/2010 11:00:28 PM | Computer Name = BrittanyRBel-PC | Source = Service Control Manager | ID = 7001
Description =

Error - 2/9/2010 11:00:29 PM | Computer Name = BrittanyRBel-PC | Source = DCOM | ID = 10005
Description =

Error - 2/9/2010 11:00:29 PM | Computer Name = BrittanyRBel-PC | Source = Service Control Manager | ID = 7001
Description =

Error - 2/9/2010 11:03:51 PM | Computer Name = BrittanyRBel-PC | Source = EventLog | ID = 6008
Description = The previous system shutdown at 9:02:22 PM on 2/9/2010 was unexpected.

Error - 2/9/2010 11:03:57 PM | Computer Name = BrittanyRBel-PC | Source = Dhcp | ID = 1002
Description = The IP address lease 192.168.1.104 for the Network Card with network
address 001C26239E9A has been denied by the DHCP server 192.168.1.1 (The DHCP Server
sent a DHCPNACK message).

Error - 2/9/2010 11:03:56 PM | Computer Name = BrittanyRBel-PC | Source = HTTP | ID = 15016
Description =


< End of report >

MBAM Logs

Malwarebytes' Anti-Malware 1.44
Database version: 3510
Windows 6.0.6001 Service Pack 1 (Safe Mode)
Internet Explorer 7.0.6001.18000

2/8/2010 6:19:11 PM
mbam-log-2010-02-08 (18-19-02).txt

Scan type: Quick Scan
Objects scanned: 101459
Time elapsed: 6 minute(s), 12 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 1
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 3

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\kimokobojo (Trojan.Agent) -> No action taken.

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
C:\Users\Brittany R Belcher\AppData\Roaming\wpp.exe (Rogue.WindowsPolicePro) -> No action taken.
C:\Users\Brittany R Belcher\AppData\Roaming\svchost.exe (Trojan.Delf) -> No action taken.
C:\ProgramData\pirotima\pirotima.dll (Trojan.Agent) -> No action taken.


Malwarebytes' Anti-Malware 1.44
Database version: 3716
Windows 6.0.6001 Service Pack 1
Internet Explorer 7.0.6001.18000

2/9/2010 3:58:01 PM
mbam-log-2010-02-09 (15-58-01).txt

Scan type: Quick Scan
Objects scanned: 106711
Time elapsed: 9 minute(s), 45 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 1
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 1
Files Infected: 2

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
HKEY_CURRENT_USER\SOFTWARE\Your PC Protector (Rogue.YourPCProtector) -> Quarantined and deleted successfully.

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
C:\Users\Brittany R Belcher\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Your PC Protector (Rogue.YourPCProtector) -> Quarantined and deleted successfully.

Files Infected:
C:\Users\Brittany R Belcher\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Your PC Protector\Your PC Protector.lnk (Rogue.YourPCProtector) -> Quarantined and deleted successfully.
C:\Users\Brittany R Belcher\Desktop\Your PC Protector.lnk (Rogue.YourPCProtector) -> Quarantined and deleted successfully.
Hi Willem ,

When I was administering the self help earlier in the day I used defogger and my CD emulation drives are still disabled does that have something to do with it?

I don't think so. Please leave the emulators disabled.



Next, Right click on OTL.exe and chose Run as Administrator to run it
  • Under the Custom Scans/Fixes box at the bottom, paste in the following
  • Do Not copy the word CODE
  • please note the fix starts with the :
:Services

:OTL
[2010/02/08 10:27:56 | 000,000,000 | —D | C] – C:\ProgramData\yikavaji
[2010/02/08 10:27:56 | 000,000,000 | —D | C] – C:\ProgramData\pirotima
[2010/02/08 10:27:56 | 000,000,000 | —D | C] – C:\ProgramData\padofewi
[2010/02/08 10:27:23 | 000,000,000 | —D | C] – C:\ProgramData\zevububu
[2010/02/08 10:27:23 | 000,000,000 | —D | C] – C:\ProgramData\tiruyagu
[2010/02/08 10:27:23 | 000,000,000 | —D | C] – C:\ProgramData\midinuro
[2010/02/08 10:27:23 | 000,000,000 | —D | C] – C:\ProgramData\hodisuto
O4 - HKCU..\Run: [vomavijum] c:\PROGRA~2\midinuro\midinuro.DLL File not found
2010/02/07 22:27:21 | 000,000,000 | —D | C] – C:\ProgramData\kemowisu
[2010/02/07 22:27:21 | 000,000,000 | —D | C] – C:\ProgramData\kegawida
[2010/02/07 22:27:21 | 000,000,000 | —D | C] – C:\ProgramData\kalufuli
[2010/02/07 22:22:08 | 000,000,000 | —D | C] – C:\ProgramData\zajezumu
[2010/02/07 22:22:08 | 000,000,000 | —D | C] – C:\ProgramData\momenena
[2010/02/07 22:22:08 | 000,000,000 | —D | C] – C:\ProgramData\fonipebo
[2010/02/08 18:00:35 | 000,006,456 | -H– | M] () – C:\ProgramData\semewosu
[2099/01/01 12:00:00 | 000,006,456 | -H– | C] () – C:\ProgramData\semewosu
:Commands
[emptytemp]
[start explorer]
[Reboot]

Then click the Run Fix button at the top
  • Let the program run unhindered
  • Please save the resulting log to be posted in your next reply.



Next


Download ComboFix from one of these locations:

Link 1
Link 2

* IMPORTANT !!! Save ComboFix.exe to your Desktop

  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. Note: If you are having difficulty properly disabling your protective programs, or are unsure as to what programs need to be disabled, please refer to the information available through this link : How to Disable your Security Programs
  • Right click on ComboFix.exe, click Run as Administrator & follow the prompts.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.

Notes:

1.Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. ComboFix may reset a number of Internet Explorer's settings, including making I-E the default browser.
3. Combofix prevents autorun of ALL CD, floppy and USB devices to assist with malware removal & increase security. If this is an issue or makes it difficult for you – please tell your helper.
4. CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.

Please post back with
  • OTL fix log
  • Combofix log
How is the computer?

Thanks
Ok got those scans done, I just restarted after running Combofix and the machine seems a little jerky when opening programs, is that normal? Anyway here are the log files. All processes killed ========== SERVICES/DRIVERS ========== ========== OTL ========== C:\ProgramData\yikavaji folder moved successfully. C:\ProgramData\pirotima folder moved successfully. C:\ProgramData\padofewi folder moved successfully. C:\ProgramData\zevububu folder moved successfully. C:\ProgramData\tiruyagu folder moved successfully. C:\ProgramData\midinuro folder moved successfully. C:\ProgramData\hodisuto folder moved successfully. Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\vomavijum deleted successfully. C:\ProgramData\kegawida folder moved successfully. C:\ProgramData\kalufuli folder moved successfully. C:\ProgramData\zajezumu folder moved successfully. C:\ProgramData\momenena folder moved successfully. C:\ProgramData\fonipebo folder moved successfully. C:\ProgramData\semewosu moved successfully. File C:\ProgramData\semewosu not found. ========== COMMANDS ========== [EMPTYTEMP] User: All Users User: Brittany R Belcher ->Temp folder emptied: 382755 bytes ->Temporary Internet Files folder emptied: 194747114 bytes ->Java cache emptied: 19964080 bytes User: Default ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 33170 bytes User: Default User ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes User: Public %systemdrive% .tmp files removed: 0 bytes %systemroot% .tmp files removed: 0 bytes %systemroot%\System32 .tmp files removed: 0 bytes %systemroot%\System32\drivers .tmp files removed: 0 bytes Windows Temp folder emptied: 13916 bytes RecycleBin emptied: 4898520 bytes Total Files Cleaned = 210.00 mb OTL by OldTimer - Version 3.1.28.0 log created on 02092010_220535 Files\Folders moved on Reboot… Registry entries deleted on Reboot… ComboFix 10-02-09.03 - Brittany R Belcher 02/09/2010 22:21:36.1.2 - x86 Microsoft® Windows Vista™ Home Basic 6.0.6001.1.1252.1.1033.18.1917.1183 [GMT -6:00] Running from: c:\users\[removed]\Desktop\ComboFix.exe SP: AVG Anti-Spyware *disabled* (Outdated) {48F2E28D-ED66-4646-9C11-B3055B0AF604} SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46} . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . c:\$recycle.bin\S-1-5-21-1738422755-998661840-641317060-500 c:\$recycle.bin\S-1-5-21-1895212916-1239893769-2219206363-500 c:\$recycle.bin\S-1-5-21-2365545147-1999384947-2466353664-500 c:\windows\system32\stacsv.exe . ((((((((((((((((((((((((((((((((((((((( Drivers/Services ))))))))))))))))))))))))))))))))))))))))))))))))) . ——-\Service_STacSV ((((((((((((((((((((((((( Files Created from 2010-01-10 to 2010-02-10 ))))))))))))))))))))))))))))))) . 2010-02-10 04:30 . 2010-02-10 04:30 ——– d—–w- c:\users\Default\AppData\Local\temp 2010-02-10 04:05 . 2010-02-10 04:05 ——– d—–w- C:\_OTL 2010-02-09 21:40 . 2010-02-09 21:41 ——– d—–w- c:\program files\ERUNT 2010-02-08 13:31 . 2010-02-08 13:31 ——– d—–w- c:\users\Brittany R Belcher\AppData\Roaming\Malwarebytes 2010-02-08 13:31 . 2010-01-07 22:07 38224 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys 2010-02-08 13:31 . 2010-02-08 13:31 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware 2010-02-08 13:31 . 2010-02-08 13:31 ——– d—–w- c:\programdata\Malwarebytes 2010-02-08 13:31 . 2010-01-07 22:07 19160 —-a-w- c:\windows\system32\drivers\mbam.sys 2010-02-08 04:33 . 2010-02-08 05:01 ——– d—–w- c:\users\Brittany R Belcher\AppData\Roaming\schtml 2010-02-08 04:28 . 2010-02-08 05:45 ——– d—–w- c:\users\Brittany R Belcher\AppData\Roaming\Your PC Protector 2010-02-08 04:27 . 2010-02-08 04:27 ——– d—–w- c:\programdata\kemowisu 2010-01-13 01:45 . 2009-10-19 14:27 156672 —-a-w- c:\windows\system32\t2embed.dll 2010-01-13 01:45 . 2009-10-19 14:24 72704 —-a-w- c:\windows\system32\fontsub.dll . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2010-02-08 05:45 . 2010-02-08 04:28 83 —-a-w- c:\users\Brittany R Belcher\AppData\Roaming\wp4.dat 2010-02-08 05:45 . 2010-02-08 04:28 2 —-a-w- c:\users\Brittany R Belcher\AppData\Roaming\wp3.dat 2010-02-08 05:01 . 2010-02-08 04:33 152884 —-a-w- c:\users\Brittany R Belcher\AppData\Roaming\schtml\dbsinit.exe 2010-02-08 04:28 . 2010-02-08 04:28 36 —-a-w- c:\users\Brittany R Belcher\AppData\Roaming\skynet.dat 2010-01-14 17:12 . 2009-10-03 00:12 181120 ——w- c:\windows\system32\MpSigStub.exe 2010-01-13 09:04 . 2007-08-28 01:44 ——– d—–w- c:\programdata\Microsoft Help 2010-01-13 09:03 . 2006-11-02 11:18 ——– d—–w- c:\program files\Windows Mail 2009-12-18 13:05 . 2010-01-22 01:59 833024 —-a-w- c:\windows\system32\wininet.dll 2009-12-18 13:01 . 2010-01-22 01:59 78336 —-a-w- c:\windows\system32\ieencode.dll 2009-12-18 10:14 . 2010-01-22 01:59 26624 —-a-w- c:\windows\system32\ieUnatt.exe 2007-08-10 19:06 . 2007-08-10 19:02 8192 –sha-w- c:\windows\Users\Default\NTUSER.DAT . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "WindowsWelcomeCenter"="oobefldr.dll" [2008-01-19 2153472] "DellSupport"="c:\program files\DellSupport\DSAgnt.exe" [2007-03-15 460784] "updateMgr"="c:\program files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" [2006-03-30 313472] "MsnMsgr"="c:\program files\MSN Messenger\MsnMsgr.Exe" [2007-01-19 5674352] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Windows Defender"="c:\program files\Windows Defender\MSASCui.exe" [2008-01-19 1008184] "SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2007-04-28 857648] "Broadcom Wireless Manager UI"="c:\windows\system32\WLTRAY.exe" [2007-03-21 1548288] "ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2006-10-03 81920] "PCMService"="c:\program files\Dell\MediaDirect\PCMService.exe" [2007-04-16 184320] "GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2008-10-25 31072] "HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2006-12-11 49152] "Symantec PIF AlertEng"="c:\program files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" [2007-11-29 583048] "SigmatelSysTrayApp"="sttray.exe" [2007-03-06 303104] "AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2009-12-16 2043160] "Malwarebytes Anti-Malware (reboot)"="c:\program files\Malwarebytes' Anti-Malware\mbam.exe" [2010-01-07 1394000] c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\ Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-9-23 29696] Digital Line Detect.lnk - c:\program files\Digital Line Detect\DLG.exe [2007-8-10 50688] HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2007-1-2 210520] QuickSet.lnk - c:\windows\Installer\{7F0C4457-8E64-491B-8D7B-991504365D1E}\NewShortcut2_53A01CC614B04512A2E710D39BF83DC4.exe [2007-8-10 45056] [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "EnableUIADesktopToggle"= 0 (0x0) [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows] "AppInit_DLLs"=c:\windows\System32\avgrsstx.dll [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32] "mixer"=wdmaud.drv [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend] @="Service" [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring] "DisableMonitoring"=dword:00000001 [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus] "DisableMonitoring"=dword:00000001 [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall] "DisableMonitoring"=dword:00000001 R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\System32\drivers\avgldx86.sys [8/23/2009 2:04 PM 335240] R1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\System32\drivers\avgtdix.sys [8/23/2009 2:04 PM 108552] R2 avg8wd;AVG Free8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [8/23/2009 2:04 PM 297752] R2 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\Viewpoint\Common\ViewpointService.exe [9/10/2008 9:52 PM 24652] [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost] LocalServiceNoNetwork REG_MULTI_SZ PLA DPS BFE mpssvc HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12 hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc . . ——- Supplementary Scan ——- . IE: &AIM Toolbar Search - c:\programdata\AIM Toolbar\ieToolbar\resources\en-US\local\search.html IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~3\Office12\EXCEL.EXE/3000 . ************************************************************************** scanning hidden processes … scanning hidden autostart entries … scanning hidden files … scan completed successfully hidden files: ************************************************************************** . ——————— LOCKED REGISTRY KEYS ——————— [HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.aac\UserChoice] @Denied: (2) (LocalSystem) "Progid"="YMP.Media" [HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.aif\UserChoice] @Denied: (2) (LocalSystem) "Progid"="YMP.Media" [HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.aifc\UserChoice] @Denied: (2) (LocalSystem) "Progid"="YMP.Media" [HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.aiff\UserChoice] @Denied: (2) (LocalSystem) "Progid"="YMP.Media" [HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.au\UserChoice] @Denied: (2) (LocalSystem) "Progid"="YMP.Media" [HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.flac\UserChoice] @Denied: (2) (LocalSystem) "Progid"="YMP.Media" [HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.m3u\UserChoice] @Denied: (2) (LocalSystem) "Progid"="YMP.Media" [HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.m4a\UserChoice] @Denied: (2) (LocalSystem) "Progid"="YMP.Media" [HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mid\UserChoice] @Denied: (2) (LocalSystem) "Progid"="YMP.Media" [HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.midi\UserChoice] @Denied: (2) (LocalSystem) "Progid"="YMP.Media" [HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mp3\UserChoice] @Denied: (2) (LocalSystem) "Progid"="YMP.Media" [HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mp4\UserChoice] @Denied: (2) (LocalSystem) "Progid"="YMP.Media" [HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ogg\UserChoice] @Denied: (2) (LocalSystem) "Progid"="YMP.Media" [HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.pcm\UserChoice] @Denied: (2) (LocalSystem) "Progid"="YMP.Media" [HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.pls\UserChoice] @Denied: (2) (LocalSystem) "Progid"="YMP.Media" [HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.snd\UserChoice] @Denied: (2) (LocalSystem) "Progid"="YMP.Media" [HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.spx\UserChoice] @Denied: (2) (LocalSystem) "Progid"="YMP.Media" [HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wav\UserChoice] @Denied: (2) (LocalSystem) "Progid"="YMP.Media" [HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wma\UserChoice] @Denied: (2) (LocalSystem) "Progid"="YMP.Media" [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . ———————— Other Running Processes ———————— . c:\windows\system32\Ati2evxx.exe c:\windows\system32\Ati2evxx.exe c:\windows\System32\WLTRYSVC.EXE c:\windows\System32\bcmwltry.exe c:\windows\System32\LEXBCES.EXE c:\windows\System32\LEXPPS.EXE c:\program files\Symantec\LiveUpdate\ALUSchedulerSvc.exe c:\progra~1\AVG\AVG8\avgrsx.exe c:\progra~1\AVG\AVG8\avgnsx.exe c:\program files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe c:\windows\system32\DRIVERS\xaudio.exe c:\windows\System32\osk.exe . ************************************************************************** . Completion time: 2010-02-09 22:41:28 - machine was rebooted ComboFix-quarantined-files.txt 2010-02-10 04:41 Pre-Run: 96,529,870,848 bytes free Post-Run: 96,074,997,760 bytes free - - End Of File - - 55DC145282AD7187E0A796856C417653
Hi Willem,


We cleaned out some temporary folders so it may take a couple of reboots for things to settle down.

I see some Symantec (Norton) in the logs. Is this a program you no longer use? Does AVG show in Security Center?



We will be using Combofix again but will run it differently.

Please follow all previous instructions regarding security programs.

Open a new Notepad session
  • Click the Start button, click run
  • in the run box type notepad
  • click ok
  • In the notepad, Click "Format" and be certain that Word Wrap is not checked.
  • Copy and paste all the all of the text in the code box below into the Notepad, (including the URL). Do Not copy the word CODE

http://forums.whatthetech.com/Root_Kit_Malware_Problems_t110151.html&pid=631836#entry631836

Collect::
c:\users\Brittany R Belcher\AppData\Roaming\wp4.dat
c:\users\Brittany R Belcher\AppData\Roaming\wp3.dat
c:\users\Brittany R Belcher\AppData\Roaming\schtml\dbsinit.exe
c:\users\Brittany R Belcher\AppData\Roaming\skynet.dat

Folder::
c:\users\Brittany R Belcher\AppData\Roaming\schtml
c:\programdata\kemowisu
c:\users\Brittany R Belcher\AppData\Roaming\Your PC Protector

Registry::

In the notepad
  • Click File, Save as…, and set the Save in to your Desktop
  • In the filename box, type (including quotation marks) as the filename: "CFScript.txt"
  • Click save
Using your mouse left button, drag the new file CFscript.txt and drop it on the ComboFix.exe icon as shown below.

This will start ComboFix again.Close all browser/windows first.

**Note: Do not mouseclick combofix's window while it's running. That may cause it to stall**

[external image: Posted Image]

**Note**

When CF finishes running, the ComboFix log will open along with a message box–do not be alarmed. With the above script, ComboFix will capture files to submit for analysis.
  • Ensure you are connected to the internet and click OK on the message box.



Let's see if this scanner will show anything.

  • We Need to check for Rootkits with RootRepeal
    • Download RootRepeal from one of the following locations and save it to your desktop.
    • Open [external image: Posted Image] on your desktop.
    • Click the [external image: Posted Image] tab.
    • Click the [external image: Posted Image] button.
    • In the Select Scan dialog, check
      [external image: Posted Image]
    • Push Ok
    • Check the box for your main system drive (Usually C:), and press Ok.
    • Allow RootRepeal to run a scan of your system. This may take some time.
    • Once the scan completes, push the [external image: Posted Image] button. Save the log to your desktop, using a distinctive name, such as RootRepeal.txt.
  • Copy/paste the log (that you've previously saved to your desktop) from RootRepeal onto your post.

Please post back with
  • combofix log
  • RootRepeal log
Thanks
Here are the two new logs you asked for, as far as the Norton my girlfriend said she thought she uninstalled it whenever her free trial period was over so she does not use that program anymore. Thank you very much for you time and help. I will try to reply as soon as possible today but I will be at work later so my replies this evening may be non existent until tonight.

ComboFix 10-02-09.03 - Brittany R Belcher 02/10/2010 9:16.2.2 - x86
Microsoft® Windows Vista™ Home Basic 6.0.6001.1.1252.1.1033.18.1917.1323 [GMT -6:00]
Running from: c:\users\[removed]\Desktop\ComboFix.exe
Command switches used :: c:\users\Brittany R Belcher\Desktop\CFScript.txt
SP: AVG Anti-Spyware *disabled* (Outdated) {48F2E28D-ED66-4646-9C11-B3055B0AF604}
SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}

file zipped: c:\users\Brittany R Belcher\AppData\Roaming\schtml\dbsinit.exe
file zipped: c:\users\Brittany R Belcher\AppData\Roaming\skynet.dat
file zipped: c:\users\Brittany R Belcher\AppData\Roaming\wp3.dat
file zipped: c:\users\Brittany R Belcher\AppData\Roaming\wp4.dat
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\programdata\kemowisu
c:\programdata\kemowisu\kemowisu.dll
c:\users\Brittany R Belcher\AppData\Roaming\schtml
c:\users\Brittany R Belcher\AppData\Roaming\schtml\dbsinit.exe
c:\users\Brittany R Belcher\AppData\Roaming\schtml\images\i1.gif
c:\users\Brittany R Belcher\AppData\Roaming\schtml\images\i2.gif
c:\users\Brittany R Belcher\AppData\Roaming\schtml\images\i3.gif
c:\users\Brittany R Belcher\AppData\Roaming\schtml\images\j1.gif
c:\users\Brittany R Belcher\AppData\Roaming\schtml\images\j2.gif
c:\users\Brittany R Belcher\AppData\Roaming\schtml\images\j3.gif
c:\users\Brittany R Belcher\AppData\Roaming\schtml\images\jj1.gif
c:\users\Brittany R Belcher\AppData\Roaming\schtml\images\jj2.gif
c:\users\Brittany R Belcher\AppData\Roaming\schtml\images\jj3.gif
c:\users\Brittany R Belcher\AppData\Roaming\schtml\images\l1.gif
c:\users\Brittany R Belcher\AppData\Roaming\schtml\images\l2.gif
c:\users\Brittany R Belcher\AppData\Roaming\schtml\images\l3.gif
c:\users\Brittany R Belcher\AppData\Roaming\schtml\images\pix.gif
c:\users\Brittany R Belcher\AppData\Roaming\schtml\images\t1.gif
c:\users\Brittany R Belcher\AppData\Roaming\schtml\images\t2.gif
c:\users\Brittany R Belcher\AppData\Roaming\schtml\images\Thumbs.db
c:\users\Brittany R Belcher\AppData\Roaming\schtml\images\up1.gif
c:\users\Brittany R Belcher\AppData\Roaming\schtml\images\up2.gif
c:\users\Brittany R Belcher\AppData\Roaming\schtml\images\w1.gif
c:\users\Brittany R Belcher\AppData\Roaming\schtml\images\w11.gif
c:\users\Brittany R Belcher\AppData\Roaming\schtml\images\w2.gif
c:\users\Brittany R Belcher\AppData\Roaming\schtml\images\w3.gif
c:\users\Brittany R Belcher\AppData\Roaming\schtml\images\w3.jpg
c:\users\Brittany R Belcher\AppData\Roaming\schtml\images\word.doc
c:\users\Brittany R Belcher\AppData\Roaming\schtml\images\wt1.gif
c:\users\Brittany R Belcher\AppData\Roaming\schtml\images\wt2.gif
c:\users\Brittany R Belcher\AppData\Roaming\schtml\images\wt3.gif
c:\users\Brittany R Belcher\AppData\Roaming\schtml\wispex.html
c:\users\Brittany R Belcher\AppData\Roaming\skynet.dat
c:\users\Brittany R Belcher\AppData\Roaming\wp3.dat
c:\users\Brittany R Belcher\AppData\Roaming\wp4.dat
c:\users\Brittany R Belcher\AppData\Roaming\Your PC Protector

.
((((((((((((((((((((((((( Files Created from 2010-01-10 to 2010-02-10 )))))))))))))))))))))))))))))))
.

2010-02-10 15:23 . 2010-02-10 15:23 ——– d—–w- c:\users\Public\AppData\Local\temp
2010-02-10 15:23 . 2010-02-10 15:23 ——– d—–w- c:\users\Default\AppData\Local\temp
2010-02-10 14:59 . 2010-02-10 14:59 ——– d—–w- C:\32788R22FWJFW
2010-02-10 04:41 . 2010-02-10 15:24 ——– d—–w- c:\users\Brittany R Belcher\AppData\Local\temp
2010-02-10 04:05 . 2010-02-10 04:05 ——– d—–w- C:\_OTL
2010-02-09 21:40 . 2010-02-09 21:41 ——– d—–w- c:\program files\ERUNT
2010-02-08 13:31 . 2010-02-08 13:31 ——– d—–w- c:\users\Brittany R Belcher\AppData\Roaming\Malwarebytes
2010-02-08 13:31 . 2010-01-07 22:07 38224 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-02-08 13:31 . 2010-02-08 13:31 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2010-02-08 13:31 . 2010-02-08 13:31 ——– d—–w- c:\programdata\Malwarebytes
2010-02-08 13:31 . 2010-01-07 22:07 19160 —-a-w- c:\windows\system32\drivers\mbam.sys
2010-01-13 01:45 . 2009-10-19 14:27 156672 —-a-w- c:\windows\system32\t2embed.dll
2010-01-13 01:45 . 2009-10-19 14:24 72704 —-a-w- c:\windows\system32\fontsub.dll

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-02-10 09:20 . 2006-11-02 11:18 ——– d—–w- c:\program files\Windows Mail
2010-02-10 09:03 . 2007-08-28 01:44 ——– d—–w- c:\programdata\Microsoft Help
2010-01-14 17:12 . 2009-10-03 00:12 181120 ——w- c:\windows\system32\MpSigStub.exe
2009-12-28 12:35 . 2010-02-09 21:22 11776 —-a-w- c:\windows\system32\tsbyuv.dll
2009-12-28 12:35 . 2010-02-09 21:22 1314816 —-a-w- c:\windows\system32\quartz.dll
2009-12-28 12:32 . 2010-02-09 21:22 22528 —-a-w- c:\windows\system32\msyuv.dll
2009-12-28 12:32 . 2010-02-09 21:22 31744 —-a-w- c:\windows\system32\msvidc32.dll
2009-12-28 12:32 . 2010-02-09 21:22 123904 —-a-w- c:\windows\system32\msvfw32.dll
2009-12-28 12:32 . 2010-02-09 21:22 13312 —-a-w- c:\windows\system32\msrle32.dll
2009-12-28 12:31 . 2010-02-09 21:22 82944 —-a-w- c:\windows\system32\mciavi32.dll
2009-12-28 12:31 . 2010-02-09 21:22 50176 —-a-w- c:\windows\system32\iyuv_32.dll
2009-12-28 12:28 . 2010-02-09 21:22 91136 —-a-w- c:\windows\system32\avifil32.dll
2009-12-28 12:28 . 2010-02-09 21:22 65024 —-a-w- c:\windows\system32\avicap32.dll
2009-12-18 13:05 . 2010-01-22 01:59 833024 —-a-w- c:\windows\system32\wininet.dll
2009-12-18 13:01 . 2010-01-22 01:59 78336 —-a-w- c:\windows\system32\ieencode.dll
2009-12-18 10:14 . 2010-01-22 01:59 26624 —-a-w- c:\windows\system32\ieUnatt.exe
2009-12-11 12:07 . 2010-02-09 21:22 301568 —-a-w- c:\windows\system32\drivers\srv.sys
2009-12-11 12:07 . 2010-02-09 21:22 98304 —-a-w- c:\windows\system32\drivers\srvnet.sys
2009-12-08 20:52 . 2010-02-09 21:22 897624 —-a-w- c:\windows\system32\drivers\tcpip.sys
2009-12-08 20:52 . 2010-02-09 21:22 3597912 —-a-w- c:\windows\system32\ntkrnlpa.exe
2009-12-08 20:52 . 2010-02-09 21:22 3546200 —-a-w- c:\windows\system32\ntoskrnl.exe
2009-12-04 16:12 . 2010-02-09 21:22 212992 —-a-w- c:\windows\system32\drivers\mrxsmb10.sys
2009-12-04 16:12 . 2010-02-09 21:22 105472 —-a-w- c:\windows\system32\drivers\mrxsmb.sys
2007-08-10 19:06 . 2007-08-10 19:02 8192 –sha-w- c:\windows\Users\Default\NTUSER.DAT
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"WindowsWelcomeCenter"="oobefldr.dll" [2008-01-19 2153472]
"DellSupport"="c:\program files\DellSupport\DSAgnt.exe" [2007-03-15 460784]
"updateMgr"="c:\program files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" [2006-03-30 313472]
"MsnMsgr"="c:\program files\MSN Messenger\MsnMsgr.Exe" [2007-01-19 5674352]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Windows Defender"="c:\program files\Windows Defender\MSASCui.exe" [2008-01-19 1008184]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2007-04-28 857648]
"Broadcom Wireless Manager UI"="c:\windows\system32\WLTRAY.exe" [2007-03-21 1548288]
"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2006-10-03 81920]
"PCMService"="c:\program files\Dell\MediaDirect\PCMService.exe" [2007-04-16 184320]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2008-10-25 31072]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2006-12-11 49152]
"Symantec PIF AlertEng"="c:\program files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" [2007-11-29 583048]
"SigmatelSysTrayApp"="sttray.exe" [2007-03-06 303104]
"AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2009-12-16 2043160]
"Malwarebytes Anti-Malware (reboot)"="c:\program files\Malwarebytes' Anti-Malware\mbam.exe" [2010-01-07 1394000]

c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-9-23 29696]
Digital Line Detect.lnk - c:\program files\Digital Line Detect\DLG.exe [2007-8-10 50688]
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2007-1-2 210520]
QuickSet.lnk - c:\windows\Installer\{7F0C4457-8E64-491B-8D7B-991504365D1E}\NewShortcut2_53A01CC614B04512A2E710D39BF83DC4.exe [2007-8-10 45056]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\windows\System32\avgrsstx.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"mixer"=wdmaud.drv

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001

R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\System32\drivers\avgldx86.sys [8/23/2009 2:04 PM 335240]
R1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\System32\drivers\avgtdix.sys [8/23/2009 2:04 PM 108552]
R2 avg8wd;AVG Free8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [8/23/2009 2:04 PM 297752]
R2 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\Viewpoint\Common\ViewpointService.exe [9/10/2008 9:52 PM 24652]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalServiceNoNetwork REG_MULTI_SZ PLA DPS BFE mpssvc
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
.
.
——- Supplementary Scan ——-
.
IE: &AIM Toolbar Search - c:\programdata\AIM Toolbar\ieToolbar\resources\en-US\local\search.html
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~3\Office12\EXCEL.EXE/3000
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-02-10 09:24
Windows 6.0.6001 Service Pack 1 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————

[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.aac\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="YMP.Media"

[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.aif\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="YMP.Media"

[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.aifc\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="YMP.Media"

[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.aiff\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="YMP.Media"

[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.au\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="YMP.Media"

[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.flac\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="YMP.Media"

[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.m3u\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="YMP.Media"

[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.m4a\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="YMP.Media"

[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mid\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="YMP.Media"

[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.midi\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="YMP.Media"

[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mp3\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="YMP.Media"

[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mp4\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="YMP.Media"

[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ogg\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="YMP.Media"

[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.pcm\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="YMP.Media"

[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.pls\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="YMP.Media"

[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.snd\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="YMP.Media"

[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.spx\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="YMP.Media"

[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wav\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="YMP.Media"

[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wma\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="YMP.Media"

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
Completion time: 2010-02-10 09:26:52
ComboFix-quarantined-files.txt 2010-02-10 15:26
ComboFix2.txt 2010-02-10 04:41

Pre-Run: 95,428,894,720 bytes free
Post-Run: 95,398,387,712 bytes free

- - End Of File - - 3493A713D9DC76E64BBE7F911C4406A1
Upload was successful




ROOTREPEAL © AD, 2007-2009
==================================================
Scan Start Time: 2010/02/10 09:35
Program Version: Version 1.3.5.0
Windows Version: Windows Vista SP1
==================================================

Drivers
——————-
Name: catchme.sys
Image Path: C:\Users\BRITTA~1\AppData\Local\Temp\catchme.sys
Address: 0x997C0000 Size: 31744 File Visible: No Signed: -
Status: -

Name: dump_atapi.sys
Image Path: C:\Windows\System32\Drivers\dump_atapi.sys
Address: 0x8C379000 Size: 32768 File Visible: No Signed: -
Status: -

Name: dump_dumpata.sys
Image Path: C:\Windows\System32\Drivers\dump_dumpata.sys
Address: 0x8C36E000 Size: 45056 File Visible: No Signed: -
Status: -

Name: PROCEXP113.SYS
Image Path: C:\Windows\system32\Drivers\PROCEXP113.SYS
Address: 0x997C8000 Size: 7872 File Visible: No Signed: -
Status: -

Name: rootrepeal.sys
Image Path: C:\Windows\system32\drivers\rootrepeal.sys
Address: 0x997E2000 Size: 49152 File Visible: No Signed: -
Status: -

Processes
——————-
Path: System
PID: 4 Status: Locked to the Windows API!

Path: C:\Windows\System32\audiodg.exe
PID: 1224 Status: Locked to the Windows API!

==EOF==
Hi Willem,

Does AVG show in Security Center?



We'll remove the Norton leftovers then and some old java.

Click on the Start button > Control Panel

Depending on your settings, either
[*]click on the Uninstall a program option under the Programs category.

[*]If you are using the Classic View of the Control Panel, then you would double-click on the Programs and Features icon instead.

Uninstall the following program


Java™ SE Runtime Environment
LiveUpdate 3.2 (Symantec Corporation)




Next

Download the Norton Removal Tool from HERE and save it to your desktop.

Next Right click on Norton_Removal_Tool.exe and chose Run as Administrator to run the tool.

Follow the on-screen instructions.
Your computer may be restarted more than once, and you may be asked to repeat some steps after the computer restarts.



Next
  • Go to http://java.sun.com/javase/downloads/index.jsp
  • Scroll down to "Java Runtime Environment (JRE) 6 Update 18
  • Click the download button on the right.
If Information Bar pop-ups up, right-click on it and say it's OK to display the blocked content.
  • Select the platform (Windows, in your case), mutli language.
  • Accept the license agreement, click continue.
You do not have to install the Java Web Start ActiveX Control
  • Scroll down and click on Windows Offline Installation,
  • Save the file jre-6u18-windows-i586-p.exe to your desktop;
Do not select Run . Do not install it yet.

When the download is complete, close your browser.

  • Right click on the saved file ( jre-6u18-windows-i586-p.exe) and choose "Run as Administrator" to install the update.
  • Delete the downloaded installation file after completing the above procedure and reboot if not prompted to do so.



One more scan to do.

Please note: When doing this scan you must use a browser that was opned by right clicking it's icon and clicking "Run as Administrator"

Please do not use this instance of the browser for anything other than the scan. When the scan is complete and you have saved the reseults, please close that browser an open one the usual way and post the requested log.


*Note
It is recommended to disable onboard antivirus program and antispyware programs while performing scans so there are no conflicts and it will speed up scan time.
Please don't go surfing while your resident protection is disabled!
Once the scan is finished remember to re-enable your antivirus along with your antispyware programs.



Please go to Kaspersky website and perform an online antivirus scan.
  • Read through the requirements and privacy statement and click on Accept button.
  • It will start downloading and installing the scanner and virus definitions.
  • You will be prompted to install an application from Kaspersky. Click Run.
  • When the downloads have finished, click on Settings.
  • Make sure these boxes are checked (ticked). If they are not, please tick them and click on the Save button
    • Spyware, Adware, Dialers, and other potentially dangerous programs
    • Archives
    • Mail databases
  • Click on My Computer under Scan.
  • Once the scan is complete, it will display the results. Click on View Scan Report.
  • You will see a list of infected items there. Click on Save Report As….
  • Change the Files of type to Text file (.txt)
  • Set the Save In to Desktop
  • click the Save button.
  • Please post this log in your next reply.

Please post back with
  • Kaspersky log
Any problems?

Thanks
Sorry it took me a while to respond but here is the Kasperky log you asked for, thank you agian for you time and help with this. ——————————————————————————– KASPERSKY ONLINE SCANNER 7.0: scan report Thursday, February 11, 2010 Operating system: Microsoft Windows Vista Home Basic Edition, 32-bit Service Pack 1 (build 6001) Kaspersky Online Scanner version: 7.0.26.13 Last database update: Thursday, February 11, 2010 07:39:26 Records in database: 3472817 ——————————————————————————– Scan settings: scan using the following database: extended Scan archives: yes Scan e-mail databases: yes Scan area - My Computer: C:\ D:\ E:\ Scan statistics: Objects scanned: 127170 Threats found: 2 Infected objects found: 2 Suspicious objects found: 0 Scan duration: 02:22:27 File name / Threat / Threats count C:\_OTL\MovedFiles\02092010_220535\C_ProgramData\kalufuli\kalufuli.dll Infected: Trojan.Win32.Monder.cxka 1 C:\_OTL\MovedFiles\02092010_220535\C_ProgramData\tiruyagu\tiruyagu.dll Infected: Trojan.Win32.Monder.cxlq 1 Selected area has been scanned.
Hi Willem,

The files Kaspersky detected are files we have already quarantined. They will be completely removed when we remove the tools we used.

If no other problems, we can clean up our tools. Do not remove Defogger, we will use it shorty.

From your desktop, please delete, if present
  • any notepads/logs that we created
  • GMER.zip
  • GMER.exe
  • RootRepeal

Next

Click the Start button, click Run. Copy and paste the following line into the run box and click OK
Combofix /uninstall



Open OTL then click the Clean Up button. You may get prompted by your firewall that OTL wants to contact the internet - allow this. A cleanup.txt will be downloaded, a message dialog will ask you if you want to proceed with the cleanup process, click Yes. This will do some clean up tasks and delete some of the tools you have downloaded plus itself.




I suggest you keep MBAM, keep it updated and use it regularly.



To re-enable your Emulation drivers, right click DeFogger and click "Run as Administrator" to run the tool.
  • The application window will appear
  • Click the Re-enable button to re-enable your CD Emulation drivers
  • Click Yes to continue
  • A 'Finished!' message will appear
  • Click OK
  • DeFogger will now ask to reboot the machine - click OK
IMPORTANT! If you receive an error message while running DeFogger, please post the log defogger_enable which will appear on your desktop.
Your Emulation drivers are now re-enabled.



Updates and upgrades

You have an older version of Adobe Reader. You can download the current version HERE

You may want to consider Foxit Reader instead. It may be a bit lighter on resources.

Visit their support forum
Foxit Forum

In either case you should uninstall Adobe Reader 7.0.8 first. Be sure to move any PDF documents to another folder first though.


Some Recommendations and prevention tips

Basic security consists of 1 antivirus program, 1 resident antispyware program, 1 on demand antispyware program and a firewall. Just add a firewall.

* If you are behind a router Windows firewall should be fine. Otherwise a 3rd party firewall with outbound monitoring is recommended.

Click FIREWALL for tips, reviews and links to good, free and paid for firewalls. (Note: Zone Alarm is becoming bloatware, IMO). You will also find some links to good free firewalls in the link lower down in these recommendstions.

Or you may find another to your liking in the link to some addional information that I have posted further down.



You should also use Spyware Blaster to help immunize your computer.

- SpywareBlaster will add a large list of programs and sites into your Internet Explorer
settings that will protect you from running and downloading known malicious programs.

OR

A guide to understanding and using the hosts file.

Learn how your Hosts file can protect you and how you can protect it.
Besides the Hosts file information, there are links to a very good updated hosts file, a host file manager. and some programs that can protect your hosts file.
HOSTS

Please read the info on disabling the DNS Client before installing a custom hosts file.



-Secure your Internet Explorer

From within Internet Explorer click on the Tools menu and then click on Options.
  • Click once on the Security tab
  • Click once on the Internet icon so it becomes highlighted.
  • Click once on the Custom Level button.
  • Change the Download signed ActiveX controls to Prompt
  • Change the Download unsigned ActiveX controls to Disable
  • Change the Initialize and script ActiveX controls not marked as safe to Disable
  • Change the Installation of desktop items to Prompt
  • Change the Launching programs and files in an IFRAME to Prompt
  • Change the Navigate sub-frames across different domains to Prompt
  • When all these settings have been made, click on the OK button.
  • If it prompts you as to whether or not you want to save the settings, press the Yes button.
Next press the Apply button and then the OK to exit the Internet Properties page.


- Keeping your Windows up-to-date is crucial to your computer's security. Please go to the Windows Update Site (using Internet Explorer) and download and install all critical updates on a regular basis.


- Ensure that Automatic Update is turned on so you get all the latest patches.
Click start, control panel, click Security Center.


- Keep your antivirus program updated, as well as any other security programs you have.


-Check this site out to check for out of date programs
Secunia Personal Software Inspector (PSI) 1.0


-More tips and programs can be found HERE


- You may also want to read this article By Tony Klein
http://www.freedomlist.com/forum/viewtopic.php?t=22879

We will keep this thread open for a couple of days. Please post back if you have any problems or questions. Please post back when you have finished so this thread can be marked "Resolved".

Take care :adios:
Thank you very much for you time and assistance, I will be reminding my girlfriend to discard all forwarded e-mails from now on. I will be sure and read the articles that you have posted on here within the next day or so. Once again thank you very much and while I enjoyed your assistance I hope I won't need it again for a long time. I have finished with all of your final instructions so you may mark the thread "Resolved" Thank you again!
Since this issue appears to be resolved … this Topic has been closed. Glad we could be of assistance. If you're the topic starter, and need this topic reopened, please contact a staff member with the address of the thread. Everyone else please begin a New Topic.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI