This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Vista HJT log

13 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

My neighbor is complaining of symptoms that sound like an infection of the "Ultimate Defender" variety on her Windows Vista laptop. Her husband says there are pop ups prompting him to download anti-virus software and that his Desktop background has disappeared. I've booted into her account and it seems to be okay. I updated McAfee and did a full system scan and it came back clean. I went ahead and scanned with HijackThis and have posted the log below. Does anyone mind having a look?

Thanks,

David

%%begin log

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 8:52:52 AM, on 2/17/2010
Platform: Windows Vista SP1 (WinNT 6.00.1905)
MSIE: Internet Explorer v8.00 (8.00.6001.18882)
Boot mode: Normal

Running processes:
c:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\Windows\system32\Dwm.exe
C:\Windows\system32\taskeng.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\taskeng.exe
C:\Program Files\Search Guard PlusU\sgpupdaters.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\SGPSA\ie3sh.exe
C:\Windows\System32\wpcumi.exe
C:\Program Files\MyWebSearch\bar\1.bin\M3SRCHMN.EXE
C:\Program Files\MyWebSearch\bar\1.bin\MWSOEMON.EXE
C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe
C:\Program Files\Hewlett-Packard\HP Advisor\HPAdvisor.exe
C:\Windows\ehome\ehtray.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\McAfee Security Scan\2.0.181\SSScheduler.exe
C:\Program Files\LimeWire\LimeWire.exe
C:\Program Files\OpenOffice.org 3\program\soffice.exe
C:\Program Files\OpenOffice.org 3\program\soffice.bin
C:\Windows\ehome\ehmsas.exe
C:\Users\Angela\AppData\Local\Temp\bwgo044ac9f9.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…rio&pf=cnnb
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://toolbar.inbox.com/search/dispatcher…d&%language
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…rio&pf=cnnb
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…rio&pf=cnnb
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,SearchAssistant = http://toolbar.inbox.com/search/ie.aspx?tbid=80114
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,CustomizeSearch = http://toolbar.inbox.com/help/sa_customize.aspx?tbid=80114
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…rio&pf=cnnb
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://toolbar.inbox.com/search/ie.aspx?tbid=80114
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://toolbar.inbox.com/help/sa_customize.aspx?tbid=80114
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: (no name) - {D3D233D5-9F6D-436C-B6C7-E63F77503B30} - C:\PROGRA~1\INBOXT~1\Inbox.dll
R3 - URLSearchHook: (no name) - {00A6FAF6-072E-44cf-8957-5838F569A31D} - C:\Program Files\MyWebSearch\bar\1.bin\MWSSRCAS.DLL
O1 - Hosts: ::1 localhost
O2 - BHO: MyWebSearch Search Assistant BHO - {00A6FAF1-072E-44cf-8957-5838F569A31D} - C:\Program Files\MyWebSearch\bar\1.bin\MWSSRCAS.DLL
O2 - BHO: mwsBar BHO - {07B18EA1-A523-4961-B6BB-170DE4475CCA} - C:\Program Files\MyWebSearch\bar\1.bin\MWSBAR.DLL
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\McAfee\VirusScan\scriptsn.dll
O2 - BHO: BrowserHelper Class - {8A9D74F9-560B-4FE7-ABEB-3B2E638E5CD6} - C:\Program Files\SGPSA\SearchAssistant.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.4.4525.1752\swg.dll
O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_B7C5AC242193BB3E.dll
O2 - BHO: Microsoft Live Search Toolbar Helper - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - c:\Program Files\MSN\Toolbar\3.0.0541.0\msneshellx.dll
O2 - BHO: (no name) - {D3D233D5-9F6D-436C-B6C7-E63F77503B30} - C:\PROGRA~1\INBOXT~1\Inbox.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: Search Assistant - {F0626A63-410B-45E2-99A1-3F2475B2D695} - C:\Program Files\SGPSA\BHO.dll
O2 - BHO: XBTBPos00 - {FCBCCB87-9224-4B8D-B117-F56D924BEB18} - C:\Program Files\Fast Browser Search\IE\FBStoolbar.dll
O3 - Toolbar: Microsoft Live Search Toolbar - {1E61ED7C-7CB8-49d6-B9E9-AB4C880C8414} - c:\Program Files\MSN\Toolbar\3.0.0541.0\msneshellx.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O3 - Toolbar: Fast Browser Search Toolbar - {1BB22D38-A411-4B13-A746-C2A4F4EC7344} - C:\Program Files\Fast Browser Search\IE\FBStoolbar.dll
O3 - Toolbar: My Web Search - {07B18EA9-A523-4961-B6BB-170DE4475CCA} - C:\Program Files\MyWebSearch\bar\1.bin\MWSBAR.DLL
O3 - Toolbar: &Inbox Toolbar - {D7E97865-918F-41E4-9CD0-25AB1C574CE8} - C:\PROGRA~1\INBOXT~1\Inbox.dll
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [mcagent_exe] "C:\Program Files\McAfee.com\Agent\mcagent.exe" /runkey
O4 - HKLM\..\Run: [FBSSA] C:\Program Files\SGPSA\ie3sh.exe
O4 - HKLM\..\Run: [WPCUMI] C:\Windows\system32\WpcUmi.exe
O4 - HKLM\..\Run: [My Web Search Bar Search Scope Monitor] "C:\PROGRA~1\MYWEBS~1\bar\1.bin\m3SrchMn.exe" /m=2 /w /h
O4 - HKLM\..\Run: [MyWebSearch Email Plugin] C:\PROGRA~1\MYWEBS~1\bar\1.bin\mwsoemon.exe
O4 - HKCU\..\Run: [LightScribe Control Panel] C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe -hidden
O4 - HKCU\..\Run: [HPAdvisor] C:\Program Files\Hewlett-Packard\HP Advisor\HPAdvisor.exe autorun=AUTORUN
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
O4 - HKCU\..\Run: [Weather] C:\Program Files\AWS\WeatherBug\Weather.exe 1
O4 - HKCU\..\Run: [MyWebSearch Email Plugin] C:\PROGRA~1\MYWEBS~1\bar\1.bin\mwsoemon.exe
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O4 - Startup: LimeWire On Startup.lnk = C:\Program Files\LimeWire\LimeWire.exe
O4 - Startup: OpenOffice.org 3.1.lnk = C:\Program Files\OpenOffice.org 3\program\quickstart.exe
O4 - Global Startup: Kodak EasyShare software.lnk = C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
O4 - Global Startup: Kodak software updater.lnk = C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\backWeb-7288971.exe
O4 - Global Startup: McAfee Security Scan Plus.lnk = ?
O4 - Global Startup: Philips Device Manager.lnk = C:\Program Files\Philips\GoGear Mix Device Manager\main.exe
O8 - Extra context menu item: &Search - http://edits.mywebsearch.com/toolbaredits/…?p=ZCxdm492YJUS
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O13 - Gopher Prefix:
O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} - http://ak.exe.imgfarm.com/images/nocache/f…etup1.0.1.1.cab
O16 - DPF: {6A060448-60F9-11D5-A6CD-0002B31F7455} (ExentInf Class) -
O16 - DPF: {75A6AEA3-F26E-4608-AE9B-8DA78C87576E} (Wizard101GameLauncher) - https://kingsisle.hs.llnwd.net/e1/static/th…ameLauncher.CAB
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O18 - Protocol: inbox - {37540F19-DD4C-478B-B2DF-C19281BCAF27} - C:\PROGRA~1\INBOXT~1\Inbox.dll
O23 - Service: Com4QLBEx - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe
O23 - Service: GameConsoleService - WildTangent, Inc. - C:\Program Files\HP Games\My HP Game Console\GameConsoleService.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: HP Health Check Service - Hewlett-Packard - c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe
O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: McAfee Security Scan Component Host Service (McComponentHostService) - McAfee, Inc. - C:\Program Files\McAfee Security Scan\2.0.181\McCHSvc.exe
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe
O23 - Service: My Web Search Service (MyWebSearchService) - MyWebSearch.com - C:\PROGRA~1\MYWEBS~1\bar\1.bin\mwssvc.exe
O23 - Service: Recovery Service for Windows - Unknown owner - C:\Program Files\SMINST\BLService.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared files\RichVideo.exe
O23 - Service: ScsiAccess - Unknown owner - C:\Windows\system32\ScsiAccess.EXE
O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe

–
End of file - 12090 bytes

%%end log
Hello notesetter and Posted Image

My name is patndoris. I will be glad to take a look at your log and help you with solving any malware problems. It will be very helpful if you follow these guidelines:
  • Malware logs are often lengthy and can take a lot of time to research and interpret. Please be patient while I review your logs.
  • Please note that there is no "Quick Fix" to modern malware infections and we may need to use several different approaches to get your system clean.
  • Please make sure to carefully read any instruction that I give you. If you're not sure, or if something unexpected happens, do NOT continue! Stop and ask!
  • Please follow my instructions carefully and in the order they are posted. You may also find it helpful to print out the instructions you receive.
  • Please do not run any scans or install/uninstall any applications or delete anything without being directed to do so.
  • Remember, absence of symptoms does not mean the infection is all gone. Please stick with me till you're given the "all clear".
  • Please do not use the Attachment feature for any log file. Do a Copy/Paste of the entire contents of the log file and submit it inside your post.
  • Please reply within 3 days. If I do not hear back from you in that time frame, I will post a reminder for you. Topics with no reply in 5 days are closed!
Please be advised I am still in training, and all of my replies to you will be checked for accuracy by one of our experts to ensure that I am giving you the best possible advice.
This may cause a delay in response time, but I will do my best to keep it as short as possible.

I will post back shortly with instructions.
Hi David :)

P2P - I see there is P2P software ( LimeWire ) installed on the machine. We are not here to pass judgment on file-sharing as a concept. However, you may want to warn your neightbor that engaging in this activity and having this kind of software installed on the machine will always make them more susceptible to re-infections. It likely contributed to the current situation. This page will give further information.
Please note: Even when using a "safe" P2P program, it is only the program that is safe. You will be sharing files from uncertified sources, and these are often infected. The bad guys use P2P filesharing as a major conduit to spread their wares.
Please see this topic for more information:
Perils of P2P File Sharing.
I would strongly recommend that your neighbor uninstall these now. You can do so via Control Panel >> Add or Remove Programs.

HijackThis has largely been replaced by other tools. Since being acquired by TrendMicro, HijackThis has not been regularly updated. Many infections are now able to hide partly, or completely from a HijackThis scan. OTL ncludes all the scan locations of HijackThis and more. It's not only a more comprehensive scan tool, but also offers more powerful removal features.

Download and Run OTL
  • Download OTL to your desktop.
  • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output.
  • Check the boxes beside LOP Check and Purity Check.
  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
  • When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt.
    Note:These logs can be located in the OTL. folder on you C:\ drive if they fail to open automatically.
  • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post it with your next reply. You may need two posts to fit them both in.

Download and Run GMER

[external image: Posted Image]
Download GMER Rootkit Scanner from here or here.
  • Extract the contents of the zipped file to desktop.
  • Double click GMER.exe. If asked to allow gmer.sys driver to load, please consent .
  • If it gives you a warning about rootkit activity and asks if you want to run scan…click on NO.

    [external image: Posted Image]
    Click the image to enlarge it
  • In the right panel, you will see several boxes that have been checked. Uncheck the following …
    • Sections
    • IAT/EAT
    • Drives/Partition other than Systemdrive (typically C:\)
    • Show All (don't miss this one)
  • Then click the Scan button & wait for it to finish.
  • Once done click on the [Save..] button, and in the File name area, type in "Gmer.txt" or it will save as a .log file.
  • Save it where you can easily find it, such as your desktop, and copy/paste the results in your next reply.

**Caution**
Rootkit scans often produce false positives. Do NOT take any action on any "<— ROOKIT" entries


Please post the OTL logs and the GMER log in your next reply
Hi patndoris,

I ran OTL as you directed and both of the logs are posted below.

At some point in the GMER scan, Windows crashed and rebooted itself. When I logged in to the user account I was working in, Windows crashed a second time before I could even attempt to run the GMER scan again. At that point, I booted a Ubuntu LiveCD, which is what I'm using now to get access to the logs from the OTL scan.

It appears as though I'm not going to get a GMER scan unless I try to run it in safe mode. Should I boot into safe mode and attempt the GMER scan again? Let me know.

OTL logs posted below

%%begin OTL log

OTL logfile created on: 2/17/2010 8:39:44 PM - Run 1

OTL by OldTimer - Version 3.1.28.0 Folder = C:\Users\Angela\Desktop\infection

Windows Vista Home Premium Edition Service Pack 1 (Version = 6.0.6001) - Type = NTWorkstation

Internet Explorer (Version = 8.0.6001.18882)

Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy



3.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 46.00% Memory free

6.00 Gb Paging File | 5.00 Gb Available in Paging File | 80.00% Paging File free

Paging file location(s): c:\pagefile.sys 0 0 [binary data]



%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files

Drive C: | 138.13 Gb Total Space | 81.20 Gb Free Space | 58.79% Space Free | Partition Type: NTFS

Drive D: | 10.92 Gb Total Space | 1.83 Gb Free Space | 16.76% Space Free | Partition Type: NTFS

E: Drive not present or media not loaded

F: Drive not present or media not loaded

G: Drive not present or media not loaded

H: Drive not present or media not loaded

I: Drive not present or media not loaded



Computer Name: ANGELA-PC

Current User Name: Angela

Logged in as Administrator.



Current Boot Mode: Normal

Scan Mode: Current user

Company Name Whitelist: Off

Skip Microsoft Files: Off

File Age = 30 Days

Output = Minimal



========== Processes (SafeList) ==========



PRC - C:\Users\Angela\Desktop\infection\OTL.exe (OldTimer Tools)

PRC - C:\Program Files\McAfee Security Scan\2.0.181\SSScheduler.exe (McAfee, Inc.)

PRC - C:\Program Files\MyWebSearch\bar\1.bin\MWSOEMON.EXE (MyWebSearch.com)

PRC - C:\Program Files\MyWebSearch\bar\1.bin\MWSSVC.EXE (MyWebSearch.com)

PRC - C:\Program Files\MyWebSearch\bar\1.bin\M3SRCHMN.EXE (MyWebSearch.com)

PRC - C:\Program Files\LimeWire\LimeWire.exe (Lime Wire, LLC)

PRC - c:\Program Files\McAfee.com\Agent\mcagent.exe (McAfee, Inc.)

PRC - C:\Program Files\McAfee\MPF\MpfSrv.exe (McAfee, Inc.)

PRC - C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.)

PRC - C:\Program Files\QuickTime\qttask.exe (Apple Computer, Inc.)

PRC - C:\Program Files\McAfee\VirusScan\Mcshield.exe (McAfee, Inc.)

PRC - C:\Program Files\McAfee\VirusScan\mcsysmon.exe (McAfee, Inc.)

PRC - C:\Program Files\SGPSA\ie3sh.exe ()

PRC - C:\Program Files\McAfee\MSC\mcmscsvc.exe (McAfee, Inc.)

PRC - c:\Program Files\Common Files\McAfee\McProxy\McProxy.exe (McAfee, Inc.)

PRC - c:\Program Files\Common Files\McAfee\MNA\McNASvc.exe (McAfee, Inc.)

PRC - C:\Program Files\OpenOffice.org 3\program\soffice.bin (OpenOffice.org)

PRC - C:\Program Files\OpenOffice.org 3\program\soffice.exe (OpenOffice.org)

PRC - C:\Windows\explorer.exe (Microsoft Corporation)

PRC - c:\Program Files\Hewlett-Packard\HP Health Check\HPHC_Service.exe (Hewlett-Packard)

PRC - C:\Program Files\SMINST\BLService.exe ()

PRC - C:\Program Files\Hewlett-Packard\HP Advisor\HPAdvisor.exe (Hewlett-Packard)

PRC - C:\Program Files\CyberLink\Shared files\RichVideo.exe ()

PRC - C:\Program Files\Common Files\LightScribe\LSSrvc.exe (Hewlett-Packard Company)

PRC - C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe (Hewlett-Packard Company)

PRC - C:\Program Files\Windows Media Player\wmpnscfg.exe (Microsoft Corporation)

PRC - C:\Windows\System32\drivers\XAudio.exe (Conexant Systems, Inc.)

PRC - C:\Windows\System32\wpcumi.exe (Microsoft Corporation)

PRC - C:\Windows\System32\ScsiAccess.EXE ()

PRC - C:\Users\Angela\AppData\Local\Temp\bwgo044ac9f9.exe ()





========== Modules (SafeList) ==========



MOD - C:\Users\Angela\Desktop\infection\OTL.exe (OldTimer Tools)

MOD - C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6001.18000_none_5cdbaa5a083979cc\comctl32.dll (Microsoft Corporation)





========== Win32 Services (SafeList) ==========



SRV - (McComponentHostService) – C:\Program Files\McAfee Security Scan\2.0.181\McCHSvc.exe (McAfee, Inc.)

SRV - (MyWebSearchService) – C:\Program Files\MyWebSearch\bar\1.bin\MWSSVC.EXE (MyWebSearch.com)

SRV - (GameConsoleService) – C:\Program Files\HP Games\My HP Game Console\GameConsoleService.exe (WildTangent, Inc.)

SRV - (MpfService) – C:\Program Files\McAfee\MPF\MPFSrv.exe (McAfee, Inc.)

SRV - (gusvc) – C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe (Google)

SRV - (McODS) – C:\Program Files\McAfee\VirusScan\mcods.exe (McAfee, Inc.)

SRV - (McShield) – C:\Program Files\McAfee\VirusScan\Mcshield.exe (McAfee, Inc.)

SRV - (McSysmon) – C:\Program Files\McAfee\VirusScan\mcsysmon.exe (McAfee, Inc.)

SRV - (mcmscsvc) – C:\Program Files\McAfee\MSC\mcmscsvc.exe (McAfee, Inc.)

SRV - (McProxy) – c:\Program Files\Common Files\McAfee\McProxy\McProxy.exe (McAfee, Inc.)

SRV - (McNASvc) – c:\Program Files\Common Files\McAfee\MNA\McNASvc.exe (McAfee, Inc.)

SRV - (odserv) – C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE (Microsoft Corporation)

SRV - (HP Health Check Service) – c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe (Hewlett-Packard)

SRV - (Recovery Service for Windows) – C:\Program Files\SMINST\BLService.exe ()

SRV - (RichVideo) Cyberlink RichVideo Service(CRVS) – C:\Program Files\CyberLink\Shared files\RichVideo.exe ()

SRV - (LightScribeService) – C:\Program Files\Common Files\LightScribe\LSSrvc.exe (Hewlett-Packard Company)

SRV - (hpqwmiex) – C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe (Hewlett-Packard Development Company, L.P.)

SRV - (Com4QLBEx) – C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe (Hewlett-Packard Development Company, L.P.)

SRV - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)

SRV - (XAudioService) – C:\Windows\System32\drivers\XAudio.exe (Conexant Systems, Inc.)

SRV - (ehstart) – C:\Windows\ehome\ehstart.dll (Microsoft Corporation)

SRV - (ose) – C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE (Microsoft Corporation)

SRV - (IDriverT) – C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe (Macrovision Corporation)

SRV - (ScsiAccess) – C:\Windows\System32\ScsiAccess.EXE ()





========== Driver Services (SafeList) ==========



DRV - (mfehidk) – C:\Windows\System32\drivers\mfehidk.sys (McAfee, Inc.)

DRV - (mfeavfk) – C:\Windows\System32\drivers\mfeavfk.sys (McAfee, Inc.)

DRV - (mfesmfk) – C:\Windows\System32\drivers\mfesmfk.sys (McAfee, Inc.)

DRV - (mfebopk) – C:\Windows\System32\drivers\mfebopk.sys (McAfee, Inc.)

DRV - (mferkdk) – C:\Windows\System32\drivers\mferkdk.sys (McAfee, Inc.)

DRV - (MPFP) – C:\Windows\System32\drivers\Mpfp.sys (McAfee, Inc.)

DRV - (viaide) – C:\Windows\system32\drivers\viaide.sys (VIA Technologies, Inc.)

DRV - (cmdide) – C:\Windows\system32\drivers\cmdide.sys (CMD Technology, Inc.)

DRV - (aliide) – C:\Windows\system32\drivers\aliide.sys (Acer Laboratories Inc.)

DRV - (athr) – C:\Windows\System32\drivers\athr.sys (Atheros Communications, Inc.)

DRV - (igfx) – C:\Windows\System32\drivers\igdkmd32.sys (Intel Corporation)

DRV - (IntcHdmiAddService) Intel® – C:\Windows\System32\drivers\IntcHdmi.sys (Intel® Corporation)

DRV - (RTL8169) – C:\Windows\System32\drivers\Rtlh86.sys (Realtek Corporation )

DRV - (CnxtHdAudService) – C:\Windows\System32\drivers\CHDRT32.sys (Conexant Systems Inc.)

DRV - (SynTP) – C:\Windows\System32\drivers\SynTP.sys (Synaptics, Inc.)

DRV - (MegaSR) – C:\Windows\system32\drivers\megasr.sys (LSI Corporation, Inc.)

DRV - (adpu320) – C:\Windows\system32\drivers\adpu320.sys (Adaptec, Inc.)

DRV - (megasas) – C:\Windows\system32\drivers\megasas.sys (LSI Corporation)

DRV - (adpu160m) – C:\Windows\system32\drivers\adpu160m.sys (Adaptec, Inc.)

DRV - (SiSRaid4) – C:\Windows\system32\drivers\sisraid4.sys (Silicon Integrated Systems)

DRV - (HpCISSs) – C:\Windows\system32\drivers\hpcisss.sys (Hewlett-Packard Company)

DRV - (adpahci) – C:\Windows\system32\drivers\adpahci.sys (Adaptec, Inc.)

DRV - (LSI_SAS) – C:\Windows\system32\drivers\lsi_sas.sys (LSI Logic)

DRV - (ql2300) – C:\Windows\system32\drivers\ql2300.sys (QLogic Corporation)

DRV - (E1G60) Intel® – C:\Windows\System32\drivers\E1G60I32.sys (Intel Corporation)

DRV - (arcsas) – C:\Windows\system32\drivers\arcsas.sys (Adaptec, Inc.)

DRV - (iaStorV) – C:\Windows\system32\drivers\iastorv.sys (Intel Corporation)

DRV - (vsmraid) – C:\Windows\system32\drivers\vsmraid.sys (VIA Technologies Inc.,Ltd)

DRV - (ulsata2) – C:\Windows\system32\drivers\ulsata2.sys (Promise Technology, Inc.)

DRV - (LSI_SCSI) – C:\Windows\system32\drivers\lsi_scsi.sys (LSI Logic)

DRV - (LSI_FC) – C:\Windows\system32\drivers\lsi_fc.sys (LSI Logic)

DRV - (arc) – C:\Windows\system32\drivers\arc.sys (Adaptec, Inc.)

DRV - (elxstor) – C:\Windows\system32\drivers\elxstor.sys (Emulex)

DRV - (adp94xx) – C:\Windows\system32\drivers\adp94xx.sys (Adaptec, Inc.)

DRV - (nvraid) – C:\Windows\system32\drivers\nvraid.sys (NVIDIA Corporation)

DRV - (nvstor) – C:\Windows\system32\drivers\nvstor.sys (NVIDIA Corporation)

DRV - (NETw3v32) Intel® – C:\Windows\System32\drivers\NETw3v32.sys (Intel Corporation)

DRV - (uliahci) – C:\Windows\system32\drivers\uliahci.sys (ULi Electronics Inc.)

DRV - (HSF_DPV) – C:\Windows\System32\drivers\HSX_DPV.sys (Conexant Systems, Inc.)

DRV - (HSXHWAZL) – C:\Windows\System32\drivers\HSXHWAZL.sys (Conexant Systems, Inc.)

DRV - (winachsf) – C:\Windows\System32\drivers\HSX_CNXT.sys (Conexant Systems, Inc.)

DRV - (XAudio) – C:\Windows\System32\drivers\XAudio.sys (Conexant Systems, Inc.)

DRV - (HpqKbFiltr) – C:\Windows\System32\drivers\HpqKbFiltr.sys (Hewlett-Packard Development Company, L.P.)

DRV - (ql40xx) – C:\Windows\system32\drivers\ql40xx.sys (QLogic Corporation)

DRV - (UlSata) – C:\Windows\system32\drivers\ulsata.sys (Promise Technology, Inc.)

DRV - (nfrd960) – C:\Windows\system32\drivers\nfrd960.sys (IBM Corporation)

DRV - (iirsp) – C:\Windows\system32\drivers\iirsp.sys (Intel Corp./ICP vortex GmbH)

DRV - (aic78xx) – C:\Windows\system32\drivers\djsvs.sys (Adaptec, Inc.)

DRV - (iteraid) – C:\Windows\system32\drivers\iteraid.sys (Integrated Technology Express, Inc.)

DRV - (iteatapi) – C:\Windows\system32\drivers\iteatapi.sys (Integrated Technology Express, Inc.)

DRV - (Symc8xx) – C:\Windows\system32\drivers\symc8xx.sys (LSI Logic)

DRV - (Sym_u3) – C:\Windows\system32\drivers\sym_u3.sys (LSI Logic)

DRV - (Mraid35x) – C:\Windows\system32\drivers\mraid35x.sys (LSI Logic Corporation)

DRV - (Sym_hi) – C:\Windows\system32\drivers\sym_hi.sys (LSI Logic)

DRV - (Brserid) Brother MFC Serial Port Interface Driver (WDM) – C:\Windows\system32\drivers\brserid.sys (Brother Industries Ltd.)

DRV - (BrUsbSer) – C:\Windows\system32\drivers\brusbser.sys (Brother Industries Ltd.)

DRV - (BrFiltUp) – C:\Windows\system32\drivers\brfiltup.sys (Brother Industries, Ltd.)

DRV - (BrFiltLo) – C:\Windows\system32\drivers\brfiltlo.sys (Brother Industries, Ltd.)

DRV - (BrSerWdm) – C:\Windows\system32\drivers\brserwdm.sys (Brother Industries Ltd.)

DRV - (BrUsbMdm) – C:\Windows\system32\drivers\brusbmdm.sys (Brother Industries Ltd.)

DRV - (ntrigdigi) – C:\Windows\system32\drivers\ntrigdigi.sys (N-trig Innovative Technologies)

DRV - (yukonwlh) – C:\Windows\System32\drivers\yk60x86.sys (Marvell)

DRV - (secdrv) – C:\Windows\System32\drivers\secdrv.sys (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.)

DRV - (mdmxsdk) – C:\Windows\System32\drivers\mdmxsdk.sys (Conexant)





========== Standard Registry (SafeList) ==========





========== Internet Explorer ==========



IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…rio&pf;=cnnb

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…rio&pf;=cnnb

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomizeSearch = http://toolbar.inbox.com/help/sa_customize.aspx?tbid=80114

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://toolbar.inbox.com/search/ie.aspx?tbid=80114



IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…rio&pf;=cnnb

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…rio&pf;=cnnb

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1

IE - HKCU\..\URLSearchHook: {00A6FAF6-072E-44cf-8957-5838F569A31D} - C:\Program Files\MyWebSearch\bar\1.bin\MWSSRCAS.DLL (MyWebSearch.com)

IE - HKCU\..\URLSearchHook: {D3D233D5-9F6D-436C-B6C7-E63F77503B30} - C:\Program Files\Inbox Toolbar\Inbox.dll (Inbox.com, Inc.)

IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = localhost



========== FireFox ==========



FF - prefs.js..browser.search.defaultenginename: "Fast Browser Search"

FF - prefs.js..browser.search.defaulturl: "http://www.fastbrowsersearch.com/results/results.aspx?s=DEF&v;=19&q;="

FF - prefs.js..browser.search.order.1: "Fast Browser Search"

FF - prefs.js..browser.search.selectedEngine: "Inbox Search"

FF - prefs.js..browser.search.useDBForOrder: true

FF - prefs.js..browser.startup.homepage: "http://www.inbox.com/homepage.aspx?tbid=80114"

FF - prefs.js..extensions.enabledItems: [removed]:1.0.0.26

FF - prefs.js..extensions.enabledItems: [removed]:1.1

FF - prefs.js..keyword.URL: "http://toolbar.inbox.com/search/dispatcher.aspx?tp=sf&tbid;=80114&language;=en&qkw;="



FF - HKLM\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files\MyWebSearch\bar\firefox\ [2009/12/29 12:30:53 | 000,000,000 | —D | M]

FF - HKLM\software\mozilla\Mozilla Firefox 3.5.3\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2009/10/17 18:47:07 | 000,000,000 | —D | M]

FF - HKLM\software\mozilla\Mozilla Firefox 3.5.3\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010/01/31 21:47:41 | 000,000,000 | —D | M]

FF - HKLM\software\mozilla\Mozilla Thunderbird 2.0.0.23\extensions\\Components: C:\Program Files\Mozilla Thunderbird\components [2009/10/17 18:47:47 | 000,000,000 | —D | M]

FF - HKLM\software\mozilla\Mozilla Thunderbird 2.0.0.23\extensions\\Plugins: C:\Program Files\Mozilla Thunderbird\plugins



[2009/12/27 10:49:21 | 000,000,000 | —D | M] – C:\Users\Angela\AppData\Roaming\Mozilla\Extensions

[2009/12/27 10:49:21 | 000,000,000 | —D | M] – C:\Users\Angela\AppData\Roaming\Mozilla\Extensions\[removed]

[2010/02/17 20:34:33 | 000,000,000 | —D | M] – C:\Users\Angela\AppData\Roaming\Mozilla\Firefox\Profiles\1a25mlrl.default\extensions

[2009/11/18 14:57:54 | 000,000,000 | —D | M] (No name found) – C:\Users\Angela\AppData\Roaming\Mozilla\Firefox\Profiles\1a25mlrl.default\extensions\{C2DCA7EB-22D2-4FD2-86A9-F99FCC8122BB}

[2010/02/12 15:48:37 | 000,000,000 | —D | M] – C:\Users\Angela\AppData\Roaming\Mozilla\Firefox\Profiles\1a25mlrl.default\extensions\[removed]

[2009/11/18 14:57:55 | 000,005,413 | —- | M] () – C:\Users\Angela\AppData\Roaming\Mozilla\Firefox\Profiles\1a25mlrl.default\searchplugins\fast-browser-search.xml

[2010/02/12 16:54:33 | 000,002,179 | —- | M] () – C:\Users\Angela\AppData\Roaming\Mozilla\Firefox\Profiles\1a25mlrl.default\searchplugins\inbox-search.xml

[2010/01/06 22:32:19 | 000,009,985 | —- | M] () – C:\Users\Angela\AppData\Roaming\Mozilla\Firefox\Profiles\1a25mlrl.default\searchplugins\mywebsearch.xml

[2009/10/17 18:47:06 | 000,000,000 | —D | M] – C:\Program Files\Mozilla Firefox\extensions

[2007/07/26 12:05:16 | 000,001,329 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\crawlersrch.xml

[2009/12/14 19:48:52 | 000,003,700 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\fast.png

[2009/12/14 19:48:52 | 000,001,963 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\fast.xml



O1 HOSTS File: ([2006/09/18 13:41:30 | 000,000,761 | —- | M]) - C:\Windows\System32\drivers\etc\hosts

O1 - Hosts: 127.0.0.1 localhost

O1 - Hosts: ::1 localhost

O2 - BHO: (MyWebSearch Search Assistant BHO) - {00A6FAF1-072E-44cf-8957-5838F569A31D} - C:\Program Files\MyWebSearch\bar\1.bin\MWSSRCAS.DLL (MyWebSearch.com)

O2 - BHO: (mwsBar BHO) - {07B18EA1-A523-4961-B6BB-170DE4475CCA} - C:\Program Files\MyWebSearch\bar\1.bin\MWSBAR.DLL (MyWebSearch.com)

O2 - BHO: (Adobe PDF Link Helper) - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)

O2 - BHO: (scriptproxy) - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\McAfee\VirusScan\scriptsn.dll (McAfee, Inc.)

O2 - BHO: (BrowserHelper Class) - {8A9D74F9-560B-4FE7-ABEB-3B2E638E5CD6} - C:\Program Files\SGPSA\SearchAssistant.dll (Make The Web Better, LLC)

O2 - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)

O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.4.4525.1752\swg.dll (Google Inc.)

O2 - BHO: (Google Dictionary Compression sdch) - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_B7C5AC242193BB3E.dll (Google Inc.)

O2 - BHO: (Microsoft Live Search Toolbar Helper) - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - c:\Program Files\MSN\Toolbar\3.0.0541.0\msneshellx.dll (Microsoft Corp.)

O2 - BHO: () - {D3D233D5-9F6D-436C-B6C7-E63F77503B30} - C:\Program Files\Inbox Toolbar\Inbox.dll (Inbox.com, Inc.)

O2 - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)

O2 - BHO: (Search Assistant) - {F0626A63-410B-45E2-99A1-3F2475B2D695} - C:\Program Files\SGPSA\BHO.dll (MTWB)

O2 - BHO: (Fast Browser Search Toolbar Helper) - {FCBCCB87-9224-4B8D-B117-F56D924BEB18} - C:\Program Files\Fast Browser Search\IE\FBStoolbar.dll ()

O3 - HKLM\..\Toolbar: (My Web Search) - {07B18EA9-A523-4961-B6BB-170DE4475CCA} - C:\Program Files\MyWebSearch\bar\1.bin\MWSBAR.DLL (MyWebSearch.com)

O3 - HKLM\..\Toolbar: (Fast Browser Search Toolbar) - {1BB22D38-A411-4B13-A746-C2A4F4EC7344} - C:\Program Files\Fast Browser Search\IE\FBStoolbar.dll ()

O3 - HKLM\..\Toolbar: (Microsoft Live Search Toolbar) - {1E61ED7C-7CB8-49d6-B9E9-AB4C880C8414} - c:\Program Files\MSN\Toolbar\3.0.0541.0\msneshellx.dll (Microsoft Corp.)

O3 - HKLM\..\Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)

O3 - HKLM\..\Toolbar: (&Inbox; Toolbar) - {D7E97865-918F-41E4-9CD0-25AB1C574CE8} - C:\Program Files\Inbox Toolbar\Inbox.dll (Inbox.com, Inc.)

O3 - HKCU\..\Toolbar\WebBrowser: (Fast Browser Search Toolbar) - {1BB22D38-A411-4B13-A746-C2A4F4EC7344} - C:\Program Files\Fast Browser Search\IE\FBStoolbar.dll ()

O3 - HKCU\..\Toolbar\WebBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)

O4 - HKLM..\Run: [] File not found

O4 - HKLM..\Run: [FBSSA] C:\Program Files\SGPSA\ie3sh.exe ()

O4 - HKLM..\Run: [mcagent_exe] C:\Program Files\McAfee.com\Agent\mcagent.exe (McAfee, Inc.)

O4 - HKLM..\Run: [My Web Search Bar Search Scope Monitor] C:\Program Files\MyWebSearch\bar\1.bin\M3SRCHMN.EXE (MyWebSearch.com)

O4 - HKLM..\Run: [MyWebSearch Email Plugin] C:\Program Files\MyWebSearch\bar\1.bin\MWSOEMON.EXE (MyWebSearch.com)

O4 - HKLM..\Run: [QuickTime Task] C:\Program Files\QuickTime\qttask.exe (Apple Computer, Inc.)

O4 - HKLM..\Run: [WPCUMI] C:\Windows\System32\wpcumi.exe (Microsoft Corporation)

O4 - HKCU..\Run: [HPAdvisor] C:\Program Files\Hewlett-Packard\HP Advisor\HPAdvisor.exe (Hewlett-Packard)

O4 - HKCU..\Run: [LightScribe Control Panel] C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe (Hewlett-Packard Company)

O4 - HKCU..\Run: [MyWebSearch Email Plugin] C:\Program Files\MyWebSearch\bar\1.bin\MWSOEMON.EXE (MyWebSearch.com)

O4 - HKCU..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.)

O4 - HKCU..\Run: [Weather] C:\Program Files\AWS\WeatherBug\Weather.exe File not found

O4 - HKCU..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\wmpnscfg.exe (Microsoft Corporation)

O4 - HKLM..\RunOnceEx: [] File not found

O4 - Startup: C:\Users\Angela\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\LimeWire On Startup.lnk = C:\Program Files\LimeWire\LimeWire.exe (Lime Wire, LLC)

O4 - Startup: C:\Users\Angela\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.1.lnk = C:\Program Files\OpenOffice.org 3\program\quickstart.exe ()

O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145

O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: LogonHoursAction = 2

O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DontDisplayLogonHoursWarnings = 1

O8 - Extra context menu item: E&xport; to Microsoft Excel - C:\Program Files\Microsoft Office\Office12\EXCEL.EXE (Microsoft Corporation)

O9 - Extra Button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)

O9 - Extra 'Tools' menuitem : S&end; to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)

O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Program Files\Microsoft Office\Office12\REFIEBAR.DLL (Microsoft Corporation)

O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\Windows\System32\wpclsp.dll (Microsoft Corporation)

O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\Windows\System32\wpclsp.dll (Microsoft Corporation)

O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\Windows\System32\wpclsp.dll (Microsoft Corporation)

O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - C:\Windows\System32\wpclsp.dll (Microsoft Corporation)

O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - C:\Windows\System32\wpclsp.dll (Microsoft Corporation)

O10 - Protocol_Catalog9\Catalog_Entries\000000000006 - C:\Windows\System32\wpclsp.dll (Microsoft Corporation)

O10 - Protocol_Catalog9\Catalog_Entries\000000000007 - C:\Windows\System32\wpclsp.dll (Microsoft Corporation)

O10 - Protocol_Catalog9\Catalog_Entries\000000000008 - C:\Windows\System32\wpclsp.dll (Microsoft Corporation)

O10 - Protocol_Catalog9\Catalog_Entries\000000000019 - C:\Windows\System32\wpclsp.dll (Microsoft Corporation)

O13 - gopher Prefix: missing

O15 - HKCU\..Trusted Ranges: Range1 ([http] in Local intranet)

O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} http://ak.exe.imgfarm.com/images/nocache/f…etup1.0.1.1.cab (Reg Error: Key error.)

O16 - DPF: {6A060448-60F9-11D5-A6CD-0002B31F7455} (ExentInf Class)

O16 - DPF: {75A6AEA3-F26E-4608-AE9B-8DA78C87576E} https://kingsisle.hs.llnwd.net/e1/static/th…ameLauncher.CAB (Wizard101GameLauncher)

O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_13)

O16 - DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_07)

O16 - DPF: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_13)

O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_13)

O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)

O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = [removed] [removed]

O18 - Protocol\Handler\inbox {37540F19-DD4C-478B-B2DF-C19281BCAF27} - C:\Program Files\Inbox Toolbar\Inbox.dll (Inbox.com, Inc.)

O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Program Files\Common Files\microsoft shared\Help\hxds.dll (Microsoft Corporation)

O18 - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\microsoft shared\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)

O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)

O20 - Winlogon\Notify\igfxcui: DllName - igfxdev.dll - C:\Windows\System32\igfxdev.dll (Intel Corporation)

O24 - Desktop WallPaper: C:\Windows\Web\Wallpaper\img4.jpg

O24 - Desktop BackupWallPaper: C:\Windows\Web\Wallpaper\img4.jpg

O32 - HKLM CDRom: AutoRun - 1

O32 - AutoRun File - [2006/09/18 13:43:36 | 000,000,024 | —- | M] () - C:\autoexec.bat – [ NTFS ]

O33 - MountPoints2\{33f1dd8d-88aa-11de-94f3-001f16de91aa}\Shell - "" = AutoRun

O33 - MountPoints2\{33f1dd8d-88aa-11de-94f3-001f16de91aa}\Shell\AutoRun\command - "" = G:\LaunchU3.exe – File not found

O33 - MountPoints2\{bb7e2df3-f244-11de-b8a8-001f16de91aa}\Shell\AutoRun\command - "" = F:\installer.exe – File not found

O33 - MountPoints2\{bb7e2df3-f244-11de-b8a8-001f16de91aa}\Shell\verb\command - "" = F:\installer.exe – File not found

O34 - HKLM BootExecute: (autocheck autochk *) - File not found

O35 - comfile [open] – "%1" %*

O35 - exefile [open] – "%1" %*



========== Files/Folders - Created Within 30 Days ==========



[2010/02/17 08:54:20 | 000,000,000 | —D | C] – C:\Users\Angela\Desktop\infection

[2010/02/17 08:52:00 | 000,000,000 | —D | C] – C:\Program Files\Trend Micro

[2010/02/15 21:01:31 | 000,000,000 | —D | C] – C:\83fb74e5229ee173efa97349

[2010/02/15 19:43:24 | 000,000,000 | —D | C] – C:\ProgramData\29812628

[2010/02/12 15:49:33 | 000,000,000 | —D | C] – C:\Program Files\RebateInformer

[2010/02/12 15:48:55 | 000,000,000 | —D | C] – C:\Program Files\Crawler

[2010/02/12 15:48:36 | 000,000,000 | —D | C] – C:\Program Files\Inbox Toolbar

[2010/02/11 07:07:34 | 003,597,912 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ntkrnlpa.exe

[2010/02/11 07:07:34 | 003,546,200 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ntoskrnl.exe

[2010/02/11 07:07:20 | 001,314,816 | —- | C] (Microsoft Corporation) – C:\Windows\System32\quartz.dll

[2010/02/11 07:07:19 | 000,123,904 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msvfw32.dll

[2010/02/11 07:07:19 | 000,091,136 | —- | C] (Microsoft Corporation) – C:\Windows\System32\avifil32.dll

[2010/02/11 07:07:19 | 000,082,944 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mciavi32.dll

[2010/02/11 07:07:19 | 000,065,024 | —- | C] (Microsoft Corporation) – C:\Windows\System32\avicap32.dll

[2010/02/07 16:21:25 | 000,000,000 | —D | C] – C:\b99d80c27827da6d4c3a

[2010/01/31 20:29:38 | 000,000,000 | —D | C] – C:\ProgramData\McAfee Security Scan

[2010/01/31 20:29:34 | 000,000,000 | —D | C] – C:\Program Files\McAfee Security Scan

[2010/01/22 15:43:10 | 000,594,432 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msfeeds.dll

[2010/01/22 15:43:10 | 000,387,584 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iedkcs32.dll

[2010/01/22 15:43:09 | 001,638,912 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mshtml.tlb

[2010/01/22 15:43:09 | 001,469,440 | —- | C] (Microsoft Corporation) – C:\Windows\System32\inetcpl.cpl

[2010/01/22 15:43:09 | 000,184,320 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iepeers.dll

[2010/01/22 15:43:09 | 000,173,056 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ie4uinit.exe

[2010/01/22 15:43:09 | 000,164,352 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieui.dll

[2010/01/22 15:43:09 | 000,133,632 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieUnatt.exe

[2010/01/22 15:43:09 | 000,109,056 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iesysprep.dll

[2010/01/22 15:43:09 | 000,071,680 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iesetup.dll

[2010/01/22 15:43:09 | 000,055,808 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iernonce.dll

[2010/01/22 15:43:09 | 000,055,296 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msfeedsbs.dll

[2010/01/22 15:43:09 | 000,025,600 | —- | C] (Microsoft Corporation) – C:\Windows\System32\jsproxy.dll

[2010/01/22 15:43:09 | 000,013,312 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msfeedssync.exe

[2010/01/19 00:15:07 | 000,000,000 | —D | C] – C:\Program Files\Philips

[2010/01/19 00:14:33 | 000,000,000 | —D | C] – C:\Users\Angela\AppData\Roaming\InstallShield

[2010/01/18 23:35:01 | 000,000,000 | —D | C] – C:\Users\Angela\AppData\Roaming\Amazon

[2010/01/18 23:28:33 | 000,000,000 | —D | C] – C:\Program Files\Amazon

[3 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]

[2 C:\*.tmp files -> C:\*.tmp -> ]



========== Files - Modified Within 30 Days ==========



[2010/02/17 20:42:03 | 000,000,278 | -H– | M] () – C:\Windows\tasks\{35DC3473-A719-4d14-B7C1-FD326CA84A0C}.job

[2010/02/17 20:38:57 | 001,835,008 | -HS- | M] () – C:\Users\Angela\ntuser.dat

[2010/02/17 20:35:03 | 000,020,236 | —- | M] () – C:\Windows\System32\Config.MPF

[2010/02/17 20:34:33 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat

[2010/02/17 11:21:01 | 000,000,278 | -H– | M] () – C:\Windows\tasks\{66BA574B-1E11-49b8-909C-8CC9E0E8E015}.job

[2010/02/17 10:46:09 | 000,003,216 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0

[2010/02/17 10:46:09 | 000,003,216 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0

[2010/02/17 08:52:00 | 000,001,874 | —- | M] () – C:\Users\Angela\Desktop\HijackThis.lnk

[2010/02/17 08:46:48 | 000,065,536 | -HS- | M] () – C:\Users\Angela\NTUSER.DAT{3a539871-6a70-11db-887c-d362bd253390}.TM.blf

[2010/02/17 08:46:47 | 000,524,288 | -HS- | M] () – C:\Users\Angela\NTUSER.DAT{3a539871-6a70-11db-887c-d362bd253390}.TMContainer00000000000000000001.regtrans-ms

[2010/02/17 08:46:38 | 004,131,477 | -H– | M] () – C:\Users\Angela\AppData\Local\IconCache.db

[2010/02/16 12:48:30 | 000,000,006 | -H– | M] () – C:\Windows\tasks\SA.DAT

[2010/02/16 12:48:02 | 3149,082,624 | -HS- | M] () – C:\hiberfil.sys

[2010/02/02 22:20:06 | 000,000,326 | —- | M] () – C:\Windows\tasks\HPCeeScheduleForAngela.job

[2010/01/31 23:19:56 | 000,027,268 | —- | M] () – C:\Users\Angela\Documents\Strawberry Letter 23.odt

[2010/01/31 20:29:36 | 000,001,717 | —- | M] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\McAfee Security Scan Plus.lnk

[2010/01/19 14:01:58 | 000,690,960 | —- | M] () – C:\Windows\System32\PerfStringBackup.INI

[2010/01/19 14:01:58 | 000,595,684 | —- | M] () – C:\Windows\System32\perfh009.dat

[2010/01/19 14:01:58 | 000,101,350 | —- | M] () – C:\Windows\System32\perfc009.dat

[2010/01/19 00:15:27 | 000,001,943 | —- | M] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Philips Device Manager.lnk

[3 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]

[2 C:\*.tmp files -> C:\*.tmp -> ]



========== Files Created - No Company Name ==========



[2010/02/17 08:52:00 | 000,001,874 | —- | C] () – C:\Users\Angela\Desktop\HijackThis.lnk

[2010/01/31 23:19:55 | 000,027,268 | —- | C] () – C:\Users\Angela\Documents\Strawberry Letter 23.odt

[2010/01/31 20:29:36 | 000,001,717 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\McAfee Security Scan Plus.lnk

[2010/01/19 00:15:27 | 000,001,943 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Philips Device Manager.lnk

[2009/11/26 17:48:14 | 000,000,023 | —- | C] () – C:\Windows\CANDYLND.INI

[2009/09/07 17:14:48 | 000,000,405 | —- | C] () – C:\Windows\ka.ini

[2009/09/01 21:57:03 | 000,000,021 | —- | C] () – C:\ProgramData\hpqp.txt

[2009/08/28 22:03:15 | 000,005,120 | —- | C] () – C:\Users\Angela\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini

[2009/08/14 20:50:24 | 000,000,000 | —- | C] () – C:\Users\Angela\AppData\Local\QSwitch.txt

[2009/08/14 20:50:24 | 000,000,000 | —- | C] () – C:\Users\Angela\AppData\Local\DSwitch.txt

[2009/08/14 20:50:24 | 000,000,000 | —- | C] () – C:\Users\Angela\AppData\Local\AtStart.txt

[2009/07/27 05:17:20 | 000,000,105 | —- | C] () – C:\ProgramData\{d36dd326-7280-11d8-97c8-000129760cbe}.log

[2009/07/27 05:17:13 | 000,000,032 | —- | C] () – C:\ProgramData\{051B9612-4D82-42AC-8C63-CD2DCEDC1CB3}.log

[2009/07/27 05:16:52 | 000,000,032 | —- | C] () – C:\ProgramData\{9867824A-C86D-4A83-8F3C-E7A86BE0AFD3}.log

[2009/07/27 05:16:21 | 000,000,032 | —- | C] () – C:\ProgramData\{23F3DA62-2D9E-4A69-B8D5-BE8E9E148092}.log

[2009/07/27 05:14:34 | 000,000,032 | —- | C] () – C:\ProgramData\{4FC670EB-5F02-4B07-90DB-022B86BFEFD0}.log

[2009/07/27 05:14:05 | 000,000,284 | —- | C] () – C:\ProgramData\hpqp.ini

[2009/04/22 07:11:20 | 000,000,109 | —- | C] () – C:\ProgramData\{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}.log

[2009/04/22 07:06:18 | 000,000,110 | —- | C] () – C:\ProgramData\{CB099890-1D5F-11D5-9EA9-0050BAE317E1}.log

[2009/04/22 07:04:35 | 000,000,105 | —- | C] () – C:\ProgramData\{40BF1E83-20EB-11D8-97C5-0009C5020658}.log

[2009/04/22 07:03:24 | 000,000,107 | —- | C] () – C:\ProgramData\{C59C179C-668D-49A9-B6EA-0121CCFC1243}.log

[2008/07/06 12:29:46 | 000,147,456 | —- | C] () – C:\Windows\System32\igfxCoIn_v1518.dll

[2008/06/29 06:52:14 | 000,004,608 | —- | C] () – C:\Windows\System32\HdmiCoin.dll

[2006/11/02 04:35:32 | 000,005,632 | —- | C] () – C:\Windows\System32\sysprepMCE.dll

[2006/11/01 23:40:29 | 000,013,750 | —- | C] () – C:\Windows\System32\pacerprf.ini

[2006/03/09 01:58:00 | 001,060,424 | —- | C] () – C:\Windows\System32\WdfCoInstaller01000.dll

[2000/09/08 14:53:50 | 000,073,839 | —- | C] () – C:\Windows\System32\KodakOneTouch.dll



========== LOP Check ==========



[2010/01/18 23:35:01 | 000,000,000 | —D | M] – C:\Users\Angela\AppData\Roaming\Amazon

[2009/09/22 19:33:49 | 000,000,000 | —D | M] – C:\Users\Angela\AppData\Roaming\Gamelab

[2009/12/22 22:02:04 | 000,000,000 | —D | M] – C:\Users\Angela\AppData\Roaming\iWin

[2010/02/17 15:48:02 | 000,000,000 | —D | M] – C:\Users\Angela\AppData\Roaming\LimeWire

[2009/08/14 21:59:29 | 000,000,000 | —D | M] – C:\Users\Angela\AppData\Roaming\Ludia

[2009/12/22 21:48:09 | 000,000,000 | —D | M] – C:\Users\Angela\AppData\Roaming\Merscom

[2009/08/14 21:29:58 | 000,000,000 | —D | M] – C:\Users\Angela\AppData\Roaming\OpenOffice.org

[2009/08/24 18:35:40 | 000,000,000 | —D | M] – C:\Users\Angela\AppData\Roaming\PlayFirst

[2009/08/26 18:49:19 | 000,000,000 | —D | M] – C:\Users\Angela\AppData\Roaming\SPORE Creature Creator

[2009/10/17 18:47:47 | 000,000,000 | —D | M] – C:\Users\Angela\AppData\Roaming\Thunderbird

[2009/12/24 21:11:59 | 000,000,000 | —D | M] – C:\Users\Angela\AppData\Roaming\Titanium Gears

[2009/12/24 21:06:09 | 000,000,000 | —D | M] – C:\Users\Angela\AppData\Roaming\WeatherBug

[2009/08/14 21:58:22 | 000,000,000 | —D | M] – C:\Users\Angela\AppData\Roaming\WildTangent

[2009/10/17 18:55:07 | 000,000,342 | —- | M] () – C:\Windows\Tasks\McDefragTask.job

[2010/01/01 00:59:59 | 000,000,320 | —- | M] () – C:\Windows\Tasks\McQcTask.job

[2010/02/15 21:16:19 | 000,032,632 | —- | M] () – C:\Windows\Tasks\SCHEDLGU.TXT

[2010/02/17 20:42:03 | 000,000,278 | -H– | M] () – C:\Windows\Tasks\{35DC3473-A719-4d14-B7C1-FD326CA84A0C}.job

[2010/02/17 11:21:01 | 000,000,278 | -H– | M] () – C:\Windows\Tasks\{66BA574B-1E11-49b8-909C-8CC9E0E8E015}.job



========== Purity Check ==========





< End of report >


%%end OTL log

%%begin Extras log

OTL Extras logfile created on: 2/17/2010 8:39:44 PM - Run 1

OTL by OldTimer - Version 3.1.28.0 Folder = C:\Users\Angela\Desktop\infection

Windows Vista Home Premium Edition Service Pack 1 (Version = 6.0.6001) - Type = NTWorkstation

Internet Explorer (Version = 8.0.6001.18882)

Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy



3.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 46.00% Memory free

6.00 Gb Paging File | 5.00 Gb Available in Paging File | 80.00% Paging File free

Paging file location(s): c:\pagefile.sys 0 0 [binary data]



%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files

Drive C: | 138.13 Gb Total Space | 81.20 Gb Free Space | 58.79% Space Free | Partition Type: NTFS

Drive D: | 10.92 Gb Total Space | 1.83 Gb Free Space | 16.76% Space Free | Partition Type: NTFS

E: Drive not present or media not loaded

F: Drive not present or media not loaded

G: Drive not present or media not loaded

H: Drive not present or media not loaded

I: Drive not present or media not loaded



Computer Name: ANGELA-PC

Current User Name: Angela

Logged in as Administrator.



Current Boot Mode: Normal

Scan Mode: Current user

Company Name Whitelist: Off

Skip Microsoft Files: Off

File Age = 30 Days

Output = Minimal



========== Extra Registry (SafeList) ==========





========== File Associations ==========



[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]

.cpl [@ = cplfile] – C:\Windows\System32\control.exe (Microsoft Corporation)

.hlp [@ = hlpfile] – C:\Windows\winhlp32.exe (Microsoft Corporation)

.html [@ = htmlfile] – C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation)



[HKEY_CURRENT_USER\SOFTWARE\Classes\]

.html [@ = FirefoxHTML] – C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)



========== Shell Spawning ==========



[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]

batfile [open] – "%1" %*

cmdfile [open] – "%1" %*

comfile [open] – "%1" %*

cplfile [cplopen] – %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)

exefile [open] – "%1" %*

helpfile [open] – Reg Error: Key error.

hlpfile [open] – %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation)

htmlfile – "C:\Program Files\Microsoft Office\Office12\msohtmed.exe" %1 (Microsoft Corporation)

htmlfile [open] – "C:\Program Files\Internet Explorer\iexplore.exe" -nohome (Microsoft Corporation)

htmlfile [opennew] – "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)

htmlfile [print] – "C:\Program Files\Microsoft Office\Office12\msohtmed.exe" /p %1 (Microsoft Corporation)

http [open] – "C:\Program Files\Internet Explorer\iexplore.exe" -nohome (Microsoft Corporation)

https [open] – "C:\Program Files\Internet Explorer\iexplore.exe" -nohome (Microsoft Corporation)

inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)

piffile [open] – "%1" %*

regfile [merge] – Reg Error: Key error.

scrfile [config] – "%1"

scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)

scrfile [open] – "%1" /S

txtfile – Reg Error: Key error.

Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1

Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)

Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

Directory [OneNote.Open] – C:\PROGRA~1\MICROS~3\Office12\ONENOTE.EXE "%L" (Microsoft Corporation)

Folder [open] – %SystemRoot%\Explorer.exe /separate,/idlist,%I,%L (Microsoft Corporation)

Folder [explore] – %SystemRoot%\Explorer.exe /separate,/e,/idlist,%I,%L (Microsoft Corporation)

Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

Applications\iexplore.exe [open] – "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)

CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] – "C:\Program Files\Internet Explorer\iexplore.exe" (Microsoft Corporation)



========== Security Center Settings ==========



[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]

"cval" = 1



[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]



[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]

"AntiVirusOverride" = 0

"AntiSpywareOverride" = 0

"FirewallOverride" = 0

"VistaSp1" = Reg Error: Unknown registry data type – File not found



[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]



[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]

"EnableFirewall" = 0

"DisableNotifications" = 0



[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]

"EnableFirewall" = 0

"DisableNotifications" = 0



[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]

"EnableFirewall" = 0

"DisableNotifications" = 0



========== Authorized Applications List ==========





========== Vista Active Open Ports Exception List ==========



[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]



========== Vista Active Application Exception List ==========



[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]

"{08E5DFD7-2EA4-4C13-BA70-74A27CBB7391}" = protocol=17 | dir=in | app=c:\program files\microsoft office\office12\onenote.exe |

"{26ADFB49-333D-4E06-AB08-544421753757}" = protocol=17 | dir=in | app=c:\program files\limewire\limewire.exe |

"{58C0153A-8AE6-4BA0-BE73-6744D201C6AB}" = protocol=6 | dir=in | app=c:\program files\limewire\limewire.exe |

"{6470FB4A-5782-44D3-B8B0-F572E636D271}" = dir=in | app=c:\program files\cyberlink\powerdirector\pdr.exe |

"{67004B62-3794-4AB7-919F-C6EB00B24213}" = protocol=6 | dir=in | app=c:\program files\microsoft office\office12\onenote.exe |

"{94F55685-903F-47B1-B583-ADD3D613180F}" = dir=in | app=c:\program files\hp\quickplay\qp.exe |

"{D30080CA-2E49-4304-907B-941DE7190EAC}" = dir=in | app=c:\program files\hp\quickplay\qpservice.exe |

"{F0DC068C-9FC6-4CA2-B2FE-81442F584BAA}" = dir=in | app=c:\program files\common files\mcafee\mna\mcnasvc.exe |

"TCP Query User{BAC5B105-ED42-4B76-8046-7C4A6A8F6408}C:\program files\kodak\kodak software updater\7288971\program\backweb-7288971.exe" = protocol=6 | dir=in | app=c:\program files\kodak\kodak software updater\7288971\program\backweb-7288971.exe |

"UDP Query User{08174096-03A0-4E15-92A7-A47B70120288}C:\program files\kodak\kodak software updater\7288971\program\backweb-7288971.exe" = protocol=17 | dir=in | app=c:\program files\kodak\kodak software updater\7288971\program\backweb-7288971.exe |



========== HKEY_LOCAL_MACHINE Uninstall List ==========



[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]

"{0008546E-DF6E-4CC1-AFD0-2CB8E16C95A2}" = Notifier

"{00203668-8170-44A0-BE44-B632FA4D780F}" = Adobe AIR

"{0054A0F6-00C9-4498-B821-B5C9578F433E}" = HP Help and Support

"{015E4B8A-29B5-4AE3-BD08-38220FADFF4C}" = aspi

"{082702D5-5DD8-4600-BCE5-48B15174687F}" = HP Doc Viewer

"{08C1D270-DD63-4E4A-875B-1347C5998E08}" = Rugrats™ All Growed Up

"{0B26A979-EC68-4624-A647-98A506CEE048}" = GoGear Mix Device Manager

"{0DFB3DE8-65B9-44FF-AA0A-3BECC5A2BFD1}" = Adobe Flash Player 10 Plugin

"{0E7DBD52-B097-4F2B-A7C7-F105B0D20FDB}" = LightScribe System Software 1.14.17.1

"{10E98E14-832C-4AF7-A4D1-6A9EF83B282E}" = VCAMCEN

"{123F407A-BAD1-425F-9C17-334FB6DDC339}" = GoGear Mix Device Manager

"{14D4ED84-6A9A-45A0-96F6-1753768C3CB5}" = ESSPCD

"{154508C0-07C5-4659-A7A0-E49968750D21}" = HLPPDOCK

"{154A4184-1A3D-4BF9-A5AE-4FA1660445F3}" = HP Total Care Advisor

"{15BC8CD0-A65B-47D0-A2DD-90A824590FA8}" = Microsoft Works

"{18455581-E099-4BA8-BC6B-F34B2F06600C}" = Google Toolbar for Internet Explorer

"{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}" = CyberLink DVD Suite

"{228C6B46-64E2-404E-898A-EF0830603EF4}" = HPNetworkAssistant

"{2318C2B1-4965-11d4-9B18-009027A5CD4F}" = Google Toolbar for Internet Explorer

"{254C37AA-6B72-4300-84F6-98A82419187E}" = ActiveCheck component for HP Active Support Library

"{26A24AE4-039D-4CA4-87B4-2F83216013FF}" = Java™ 6 Update 13

"{2B7BDADB-EC8C-4C54-B5DD-CE45A016D3A7}" = Free Ride Games Player

"{3248F0A8-6813-11D6-A77B-00B0D0160070}" = Java™ 6 Update 7

"{34D2AB40-150D-475D-AE32-BD23FB5EE355}" = HP Quick Launch Buttons 6.40 H2

"{352310C3-E46B-42D3-8F32-54721FDD72D9}" = NetZero Preloader

"{38058455-8C21-4C2F-B2F6-14ED166039CB}" = HP Total Care Setup

"{3877C901-7B90-4727-A639-B6ED2DD59D43}" = ESU for Microsoft Vista

"{3F92ABBB-6BBF-11D5-B229-002078017FBF}" = NetWaiting

"{40BF1E83-20EB-11D8-97C5-0009C5020658}" = Power2Go

"{432C3720-37BF-4BD7-8E49-F38E090246D0}" = CR2

"{45D707E9-F3C4-11D9-A373-0050BAE317E1}" = HP DVD Play 3.7

"{469730CC-78DF-4CD3-B286-562D459EA619}" = ESSCAM

"{48C82F7A-F100-4DAB-A310-8E18BF2159E1}" = ESSvpot

"{57A5AEC1-97FC-474D-92C4-908FCC2253D4}" = HP Customer Experience Enhancements

"{612AD33D-9824-4E87-8396-92374E91C4BB}_is1" = Inbox Toolbar

"{6423EF83-6E1D-4D22-A36F-689CD19FD4D2}" = Juno Preloader

"{643EAE81-920C-4931-9F0B-4B343B225CA6}" = ESSBrwr

"{65DA2EC9-0642-47E9-AAE2-B5267AA14D75}" = Activation Assistant for the 2007 Microsoft Office suites

"{665CBCA4-5AB0-414B-A288-3F8F99FEFC45}" = HP User Guides 0118

"{669D4A35-146B-4314-89F1-1AC3D7B88367}" = HPAsset component for HP Active Support Library

"{69BD6399-3D8F-45B7-81D9-819361F5101D}" = PCDLNCH

"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable

"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053

"{77DCDCE3-2DED-62F3-8154-05E745472D07}" = Acrobat.com

"{78F79C84-BFD5-4D79-A07D-F39A3CF428DC}" = HLPIndex

"{87843A41-7808-4F2E-B13F-25C1E67CF2FD}" = ESShelp

"{8833FFB6-5B0C-4764-81AA-06DFEED9A476}" = Realtek 8169 8168 8101E 8102E Ethernet Driver

"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight

"{8BB4B58A-A402-4DE8-8FCD-287E60B88DD8}" = ESSCT

"{8E92D746-CD9F-4B90-9668-42B74C14F765}" = ESSini

"{90120000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2007

"{90120000-0016-0409-0000-0000000FF1CE}_HOMESTUDENTR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)

"{90120000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2007

"{90120000-0018-0409-0000-0000000FF1CE}_HOMESTUDENTR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)

"{90120000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2007

"{90120000-001B-0409-0000-0000000FF1CE}_HOMESTUDENTR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)

"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007

"{90120000-001F-0409-0000-0000000FF1CE}_HOMESTUDENTR_{ABDDE972-355B-4AF1-89A8-DA50B7B5C045}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)

"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007

"{90120000-001F-040C-0000-0000000FF1CE}_HOMESTUDENTR_{F580DDD5-8D37-4998-968E-EBB76BB86787}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)

"{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007

"{90120000-001F-0C0A-0000-0000000FF1CE}_HOMESTUDENTR_{187308AB-5FA7-4F14-9AB9-D290383A10D9}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)

"{90120000-0020-0409-0000-0000000FF1CE}" = Compatibility Pack for the 2007 Office system

"{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007

"{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007

"{90120000-006E-0409-0000-0000000FF1CE}_HOMESTUDENTR_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)

"{90120000-00A1-0409-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2007

"{90120000-00A1-0409-0000-0000000FF1CE}_HOMESTUDENTR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)

"{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007

"{90120000-0115-0409-0000-0000000FF1CE}_HOMESTUDENTR_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)

"{91120000-002F-0000-0000-0000000FF1CE}" = Microsoft Office Home and Student 2007

"{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{0B36C6D6-F5D8-4EAF-BF94-4376A230AD5B}" = Microsoft Office 2007 Service Pack 2 (SP2)

"{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{3D019598-7B59-447A-80AE-815B703B84FF}" = Security Update for Microsoft Office system 2007 (972581)

"{91517631-A9F3-4B7C-B482-43E0068FD55A}" = ESSgui

"{95120000-00AF-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint Viewer 2007 (English)

"{96384578-C6A2-4EC6-92CD-B62A60713040}" = Microsoft Live Search Toolbar

"{9ADABDDE-9644-461B-9E73-83FA3EFCAB50}" = HP Wireless Assistant

"{9D1CF8B6-17B3-4832-B062-2C2DD0B57B04}" = CCHelp

"{9D8FEE90-0377-49A9-AEFB-525BDE549BA4}" = ESScore

"{A0AF08BA-3630-4505-BFB2-A41F3837B0D0}" = SFR2

"{A5B3EB8A-4071-42F0-8E8E-7A8342AA8E69}" = ESSvpaht

"{A6F18A67-B771-4191-8A33-36D2E742D6D9}" = ESSANUP

"{A9E27FF5-6294-46A8-B8FD-77B1DECA3021}" = Wizard101

"{AC76BA86-7AD7-1033-7B44-A90000000001}" = Adobe Reader 9

"{AD72CFB4-C2BF-424E-9DF0-C7BAD1F30A11}" = Adobe Shockwave Player

"{AE1FA02D-E6A4-4EA0-8E58-6483CAC016DD}" = ESSCDBK

"{B4B44FE7-41FF-4DAD-8C0A-E406DDA72992}" = CCScore

"{B997C2A0-4383-41BF-B76E-9B8B7ECFB267}" = KSU

"{C354C9B6-A4E0-4BB0-A368-6DC6BCA0E314}" = SFR

"{C3A32068-8AB1-4327-BB16-BED9C6219DC7}" = Atheros Driver Installation Program

"{C59C179C-668D-49A9-B6EA-0121CCFC1243}" = LabelPrint

"{C8FD5BC1-92EF-4C15-92A9-F9AC7F61985F}" = HP Update

"{CA60320D-6A16-49C8-A34F-84EEF4799567}" = ESSTUTOR

"{CB099890-1D5F-11D5-9EA9-0050BAE317E1}" = PowerDirector

"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1

"{CE7E3BE0-2DD3-4416-A690-F9E4A99A8CFF}" = HP Active Support Library

"{D15E9DB5-6BEB-4534-901E-80C0A29BAB97}" = ESSAdpt

"{D32470A1-B10C-4059-BA53-CF0486F68EBC}" = Kodak EasyShare software

"{DD35C328-F115-BEDA-6EEE-E00C5AACCCBC}" = muvee Reveal

"{E6B87DC4-2B3D-4483-ADFF-E483BF718991}" = OpenOffice.org 3.1

"{ECEE0279-785F-4CB3-9F28-E69813234BF8}" = SPORE Creature Creator Trial Edition

"{F2D0C1B1-80FF-46F9-BA61-33B01A07FAFC}" = HLPCCTR

"{F71760CD-0F8B-4DCC-B7B7-6B223CC3843C}" = OTtBP

"{F751C062-87DA-4D33-8A12-6E7F1D4C051C}" = Netflix in Windows Media Center

"{FCDB1C92-03C6-4C76-8625-371224256091}" = ESSPDock

"Activation Assistant for the 2007 Microsoft Office suites" = Activation Assistant for the 2007 Microsoft Office suites

"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX

"Amazon MP3 Downloader" = Amazon MP3 Downloader 1.0.9

"Bug_2.0" = Bug Adventure v2.0

"CNXT_AUDIO_HDA" = Conexant HD Audio

"CNXT_MODEM_HDAUDIO_HERMOSA_HSF" = HDAUDIO Soft Data Fax Modem with SmartCP

"com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Acrobat.com

"HDMI" = Intel® Graphics Media Accelerator Driver

"HijackThis" = HijackThis 2.0.2

"HOMESTUDENTR" = Microsoft Office Home and Student 2007

"InstallShield_{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}" = CyberLink DVD Suite

"InstallShield_{40BF1E83-20EB-11D8-97C5-0009C5020658}" = Power2Go

"InstallShield_{C59C179C-668D-49A9-B6EA-0121CCFC1243}" = LabelPrint

"InstallShield_{CB099890-1D5F-11D5-9EA9-0050BAE317E1}" = PowerDirector

"LimeWire" = LimeWire 5.4.6

"Maestro-GS3R-1GSI-PWUT1P0VJIHF" = Garfield - Grade 2 Math

"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1

"Mozilla Firefox (3.5.3)" = Mozilla Firefox (3.5.3)

"Mozilla Thunderbird (2.0.0.23)" = Mozilla Thunderbird (2.0.0.23)

"MSC" = McAfee SecurityCenter

"My.Freeze.com NetAssistant" = My.Freeze.com NetAssistant

"MyWebSearch bar Uninstall" = My Web Search (Cursor Mania)

"Night Before Christmas Full Screen Saver" = Night Before Christmas Full Screen Saver

"QuickTime" = QuickTime

"Ringling Bros. - Frankie Goes to the Circus" = Ringling Bros. - Frankie Goes to the Circus

"Search Guard Plus" = Search Guard Plus (My Web Tattoo)

"SynTPDeinstKey" = Synaptics Pointing Device Driver

"TBSB07183.TBSB07183Toolbar" = Fast Browser Search (My Web Tattoo)

"WildTangent hp Master Uninstall" = HP Games



========== Last 10 Event Log Errors ==========



[ Application Events ]

Error - 2/12/2010 8:51:38 PM | Computer Name = Angela-PC | Source = Windows Search Service | ID = 3013

Description =



Error - 2/12/2010 10:59:48 PM | Computer Name = Angela-PC | Source = HP AdvisorUpdate | ID = 0

Description = Could not find a part of the path 'C:\_pack6\hp-advisor\src\HPAdvisor\Shared\Content\xsd\HPAdvisor.xsd'.

at System.IO.__Error.WinIOError(Int32 errorCode, String maybeFullPath) at System.IO.FileStream.Init(String

path, FileMode mode, FileAccess access, Int32 rights, Boolean useRights, FileShare

share, Int32 bufferSize, FileOptions options, SECURITY_ATTRIBUTES secAttrs, String

msgPath, Boolean bFromProxy) at System.IO.FileStream..ctor(String path, FileMode

mode, FileAccess access, FileShare share, Int32 bufferSize) at System.Xml.XmlDownloadManager.GetStream(Uri

uri, ICredentials credentials) at System.Xml.XmlUrlResolver.GetEntity(Uri absoluteUri,

String role, Type ofObjectToReturn) at System.Xml.XmlReader.Create(String inputUri,

XmlReaderSettings settings, XmlParserContext inputContext) at System.Xml.Schema.XmlSchemaSet.Add(String

targetNamespace, String schemaUri) at HPAdvisor.Common.Content.CategoryCollection.ValidateDocument(String

path) ValidateDocument failed Business\SearchTargets.xml



Error - 2/13/2010 12:55:16 AM | Computer Name = Angela-PC | Source = HP AdvisorUpdate | ID = 0

Description = Could not find a part of the path 'C:\_pack6\hp-advisor\src\HPAdvisor\Shared\Content\xsd\HPAdvisor.xsd'.

at System.IO.__Error.WinIOError(Int32 errorCode, String maybeFullPath) at System.IO.FileStream.Init(String

path, FileMode mode, FileAccess access, Int32 rights, Boolean useRights, FileShare

share, Int32 bufferSize, FileOptions options, SECURITY_ATTRIBUTES secAttrs, String

msgPath, Boolean bFromProxy) at System.IO.FileStream..ctor(String path, FileMode

mode, FileAccess access, FileShare share, Int32 bufferSize) at System.Xml.XmlDownloadManager.GetStream(Uri

uri, ICredentials credentials) at System.Xml.XmlUrlResolver.GetEntity(Uri absoluteUri,

String role, Type ofObjectToReturn) at System.Xml.XmlReader.Create(String inputUri,

XmlReaderSettings settings, XmlParserContext inputContext) at System.Xml.Schema.XmlSchemaSet.Add(String

targetNamespace, String schemaUri) at HPAdvisor.Common.Content.CategoryCollection.ValidateDocument(String

path) ValidateDocument failed Business\SearchTargets.xml



Error - 2/13/2010 12:56:10 AM | Computer Name = Angela-PC | Source = Windows Search Service | ID = 3013

Description =



Error - 2/13/2010 2:27:34 AM | Computer Name = Angela-PC | Source = HP AdvisorUpdate | ID = 0

Description = Could not find a part of the path 'C:\_pack6\hp-advisor\src\HPAdvisor\Shared\Content\xsd\HPAdvisor.xsd'.

at System.IO.__Error.WinIOError(Int32 errorCode, String maybeFullPath) at System.IO.FileStream.Init(String

path, FileMode mode, FileAccess access, Int32 rights, Boolean useRights, FileShare

share, Int32 bufferSize, FileOptions options, SECURITY_ATTRIBUTES secAttrs, String

msgPath, Boolean bFromProxy) at System.IO.FileStream..ctor(String path, FileMode

mode, FileAccess access, FileShare share, Int32 bufferSize) at System.Xml.XmlDownloadManager.GetStream(Uri

uri, ICredentials credentials) at System.Xml.XmlUrlResolver.GetEntity(Uri absoluteUri,

String role, Type ofObjectToReturn) at System.Xml.XmlReader.Create(String inputUri,

XmlReaderSettings settings, XmlParserContext inputContext) at System.Xml.Schema.XmlSchemaSet.Add(String

targetNamespace, String schemaUri) at HPAdvisor.Common.Content.CategoryCollection.ValidateDocument(String

path) ValidateDocument failed Business\SearchTargets.xml



Error - 2/13/2010 7:16:54 PM | Computer Name = Angela-PC | Source = WinMgmt | ID = 10

Description =



Error - 2/13/2010 7:17:25 PM | Computer Name = Angela-PC | Source = HP AdvisorUpdate | ID = 0

Description = Could not find a part of the path 'C:\_pack6\hp-advisor\src\HPAdvisor\Shared\Content\xsd\HPAdvisor.xsd'.

at System.IO.__Error.WinIOError(Int32 errorCode, String maybeFullPath) at System.IO.FileStream.Init(String

path, FileMode mode, FileAccess access, Int32 rights, Boolean useRights, FileShare

share, Int32 bufferSize, FileOptions options, SECURITY_ATTRIBUTES secAttrs, String

msgPath, Boolean bFromProxy) at System.IO.FileStream..ctor(String path, FileMode

mode, FileAccess access, FileShare share, Int32 bufferSize) at System.Xml.XmlDownloadManager.GetStream(Uri

uri, ICredentials credentials) at System.Xml.XmlUrlResolver.GetEntity(Uri absoluteUri,

String role, Type ofObjectToReturn) at System.Xml.XmlReader.Create(String inputUri,

XmlReaderSettings settings, XmlParserContext inputContext) at System.Xml.Schema.XmlSchemaSet.Add(String

targetNamespace, String schemaUri) at HPAdvisor.Common.Content.CategoryCollection.ValidateDocument(String

path) ValidateDocument failed Business\SearchTargets.xml



Error - 2/14/2010 12:26:56 AM | Computer Name = Angela-PC | Source = HP AdvisorUpdate | ID = 0

Description = Could not find a part of the path 'C:\_pack6\hp-advisor\src\HPAdvisor\Shared\Content\xsd\HPAdvisor.xsd'.

at System.IO.__Error.WinIOError(Int32 errorCode, String maybeFullPath) at System.IO.FileStream.Init(String

path, FileMode mode, FileAccess access, Int32 rights, Boolean useRights, FileShare

share, Int32 bufferSize, FileOptions options, SECURITY_ATTRIBUTES secAttrs, String

msgPath, Boolean bFromProxy) at System.IO.FileStream..ctor(String path, FileMode

mode, FileAccess access, FileShare share, Int32 bufferSize) at System.Xml.XmlDownloadManager.GetStream(Uri

uri, ICredentials credentials) at System.Xml.XmlUrlResolver.GetEntity(Uri absoluteUri,

String role, Type ofObjectToReturn) at System.Xml.XmlReader.Create(String inputUri,

XmlReaderSettings settings, XmlParserContext inputContext) at System.Xml.Schema.XmlSchemaSet.Add(String

targetNamespace, String schemaUri) at HPAdvisor.Common.Content.CategoryCollection.ValidateDocument(String

path) ValidateDocument failed Business\SearchTargets.xml



Error - 2/14/2010 1:05:55 AM | Computer Name = Angela-PC | Source = HP AdvisorUpdate | ID = 0

Description = Could not find a part of the path 'C:\_pack6\hp-advisor\src\HPAdvisor\Shared\Content\xsd\HPAdvisor.xsd'.

at System.IO.__Error.WinIOError(Int32 errorCode, String maybeFullPath) at System.IO.FileStream.Init(String

path, FileMode mode, FileAccess access, Int32 rights, Boolean useRights, FileShare

share, Int32 bufferSize, FileOptions options, SECURITY_ATTRIBUTES secAttrs, String

msgPath, Boolean bFromProxy) at System.IO.FileStream..ctor(String path, FileMode

mode, FileAccess access, FileShare share, Int32 bufferSize) at System.Xml.XmlDownloadManager.GetStream(Uri

uri, ICredentials credentials) at System.Xml.XmlUrlResolver.GetEntity(Uri absoluteUri,

String role, Type ofObjectToReturn) at System.Xml.XmlReader.Create(String inputUri,

XmlReaderSettings settings, XmlParserContext inputContext) at System.Xml.Schema.XmlSchemaSet.Add(String

targetNamespace, String schemaUri) at HPAdvisor.Common.Content.CategoryCollection.ValidateDocument(String

path) ValidateDocument failed Business\SearchTargets.xml



Error - 2/14/2010 1:06:53 AM | Computer Name = Angela-PC | Source = Windows Search Service | ID = 3013

Description =



[ System Events ]

Error - 1/3/2010 1:34:41 AM | Computer Name = Angela-PC | Source = Service Control Manager | ID = 7000

Description =



Error - 1/4/2010 6:29:19 AM | Computer Name = Angela-PC | Source = EventLog | ID = 6008

Description = The previous system shutdown at 2:25:33 AM on 1/4/2010 was unexpected.



Error - 1/4/2010 6:29:21 AM | Computer Name = Angela-PC | Source = HTTP | ID = 15016

Description =



Error - 1/4/2010 6:30:45 AM | Computer Name = Angela-PC | Source = Service Control Manager | ID = 7000

Description =



Error - 1/4/2010 2:43:26 PM | Computer Name = Angela-PC | Source = DCOM | ID = 10010

Description =



Error - 1/4/2010 2:44:45 PM | Computer Name = Angela-PC | Source = HTTP | ID = 15016

Description =



Error - 1/4/2010 2:46:14 PM | Computer Name = Angela-PC | Source = Service Control Manager | ID = 7000

Description =



Error - 1/5/2010 1:06:23 AM | Computer Name = Angela-PC | Source = DCOM | ID = 10010

Description =



Error - 1/6/2010 12:49:42 AM | Computer Name = Angela-PC | Source = DCOM | ID = 10010

Description =



Error - 1/6/2010 10:51:15 PM | Computer Name = Angela-PC | Source = DCOM | ID = 10010

Description =





< End of report >


%%end Extras log
David - Don't worry about GMER for the moment. We'll try a different rootkit scanner.

Please go to: VirusTotal
  • [external image: Posted Image]
  • Click the Browse button and search for the following file:
    C:\Users\Angela\AppData\Local\Temp\bwgo044ac9f9.exe
    C:\Windows\ka.ini
  • Click Open
  • Then click Send File
  • Please be patient while the file is scanned.
  • Once the scan results appear, please provide them in your next reply.
If it says already scanned – click "reanalyze now"

Please post the results in your next reply.

Download Rooter.exe to your desktop
  • Then doubleclick it to start the tool
  • A Notepad file containing the report will open, also found at %systemdrive%\Rooter.txt. Post that here

Please download Malwarebytes' Anti-Malware to your desktop.
  • Double-click mbam-setup.exe and follow the prompts to install the program.
  • At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select Perform quick scan, then click Scan.
    [external image: Posted Image]
  • When the scan is complete, click OK, then Show Results to view the results.
  • Be sure that everything is checked, and click Remove Selected .
  • When completed, a log will open in Notepad. Please save it to a convenient location and post the results.
  • Note: If you receive a notice that some of the items couldn't be removed, that they have been added to the delete on reboot list, please reboot.
Please post the Malwarebytes log in your next reply.

Please let me know if there is any improvement in how the machine is running at the moment.
Hi patndoris,

I've followed all of the directed steps sequentially and saved all of the generated logs. Windows didn't crash at any point while I was running the scans. After this post I'll log into the user account that was experiencing the pop-ups and disappearing wallpaper and see how it looks.

Here are the logs, in the order that they were requested:

%% bwgo044ac9f9.exe


File bwgo044ac9f9.exe received on 2010.02.18 02:51:34 (UTC)
Antivirus Version Last Update Result
a-squared 4.5.0.50 2010.02.17 -
AhnLab-V3 5.0.0.2 2010.02.17 -
AntiVir 8.2.1.170 2010.02.17 -
Antiy-AVL 2.0.3.7 2010.02.17 -
Authentium 5.2.0.5 2010.02.18 -
Avast 4.8.1351.0 2010.02.17 -
AVG 9.0.0.730 2010.02.18 -
BitDefender 7.2 2010.02.18 -
CAT-QuickHeal 10.00 2010.02.18 -
ClamAV 0.96.0.0-git 2010.02.18 -
Comodo 3975 2010.02.18 UnclassifiedMalware
DrWeb 5.0.1.12222 2010.02.18 -
eSafe 7.0.17.0 2010.02.17 Win32.TRBHO.SecretCr
eTrust-Vet 35.2.7309 2010.02.17 -
F-Prot 4.5.1.85 2010.02.17 -
F-Secure 9.0.15370.0 2010.02.18 -
Fortinet 4.0.14.0 2010.02.15 -
GData 19 2010.02.18 -
Ikarus T3.1.1.80.0 2010.02.18 -
Jiangmin 13.0.900 2010.02.17 -
K7AntiVirus 7.10.976 2010.02.17 -
Kaspersky 7.0.0.125 2010.02.17 -
McAfee 5895 2010.02.17 -
McAfee+Artemis 5895 2010.02.17 -
McAfee-GW-Edition 6.8.5 2010.02.17 -
Microsoft 1.5406 2010.02.17 -
NOD32 4875 2010.02.17 -
Norman 6.04.08 2010.02.17 -
nProtect 2009.1.8.0 2010.02.17 -
Panda 10.0.2.2 2010.02.17 -
PCTools 7.0.3.5 2010.02.17 -
Prevx 3.0 2010.02.18 -
Rising 22.34.01.03 2010.02.11 -
Sophos 4.50.0 2010.02.18 -
Sunbelt 5684 2010.02.18 -
Symantec 20091.2.0.41 2010.02.18 -
TheHacker [removed].197 2010.02.18 -
TrendMicro 9.120.0.1004 2010.02.17 -
VBA32 3.12.12.2 2010.02.16 -
ViRobot 2010.2.17.2190 2010.02.17 -
VirusBuster 5.0.21.0 2010.02.17 -
Additional information
File size: 16384 bytes
MD5…: da188490fa45198f15bdab5f1bd81594
SHA1..: 9ee119bd595c0957e4d15916ff0d172cdeda0b89
SHA256: 2ec949d62375dfc206c525943ff1106b6624f4297b58de6ba616df69bdd8a835
ssdeep: 48:a8GdlblHfzqS6+c7tU8qxbM9+dQrlAjv4B87iAxbhBEkBQ5T7dgxe0d90sKY3
PtG:hi3qS6RoI5gv4BvA+uD3T3Ptboyn1q

PEiD..: -
PEInfo: PE Structure information

( base data )
entrypointaddress.: 0x1526
timedatestamp…..: 0x3c504d4f (Thu Jan 24 18:07:11 2002)
machinetype…….: 0x14c (I386)

( 3 sections )
name viradd virsiz rawdsiz ntrpy md5
.text 0x1000 0x6b2 0x1000 3.35 c3ae2e8e069d1b4ac05f89439e0bc19c
.rdata 0x2000 0x4a4 0x1000 1.83 53aeab99912e1e4e8f92c70846c6131c
.data 0x3000 0xd0 0x1000 0.38 96258a3ca95c12c199bfb87bd90e59b2

( 4 imports )
> KERNEL32.dll: WaitForMultipleObjects, GetStartupInfoA, GetModuleFileNameA, Sleep, GetCurrentProcessId, GetTickCount, CloseHandle, CreateProcessA, WaitForSingleObject, OpenProcess, GetLastError, CreateEventA, GetModuleHandleA
> USER32.dll: MessageBoxA
> ole32.dll: CoInitialize, CoUninitialize, CoCreateGuid
> MSVCRT.dll: _sopen, _strlwr, strchr, _ftol, _snprintf, strcpy, strlen, _close, strcspn, _read, _XcptFilter, rand, srand, sprintf, sscanf, atol, _controlfp, _exit, __setusermatherr, exit, _acmdln, __getmainargs, _initterm, _adjust_fdiv, __p__commode, __p__fmode, __set_app_type, _except_handler3

( 0 exports )

RDS…: NSRL Reference Data Set
-
pdfid.: -
sigcheck:
publisher….: n/a
copyright….: n/a
product……: n/a
description..: n/a
original name: n/a
internal name: n/a
file version.: n/a
comments…..: n/a
signers……: -
signing date.: -
verified…..: Unsigned

trid..: Win32 Executable Generic (42.3%)
Win32 Dynamic Link Library (generic) (37.6%)
Generic Win/DOS Executable (9.9%)
DOS Executable Generic (9.9%)
Autodesk FLIC Image File (extensions: flc, fli, cel) (0.0%)

Antivirus;Version;Last Update;Result
a-squared;4.5.0.50;2010.02.17;-
AhnLab-V3;5.0.0.2;2010.02.17;-
AntiVir;8.2.1.170;2010.02.17;-
Antiy-AVL;2.0.3.7;2010.02.17;-
Authentium;5.2.0.5;2010.02.18;-
Avast;4.8.1351.0;2010.02.17;-
AVG;9.0.0.730;2010.02.18;-
BitDefender;7.2;2010.02.18;-
CAT-QuickHeal;10.00;2010.02.18;-
ClamAV;0.96.0.0-git;2010.02.18;-
Comodo;3975;2010.02.18;UnclassifiedMalware
DrWeb;5.0.1.12222;2010.02.18;-
eSafe;7.0.17.0;2010.02.17;Win32.TRBHO.SecretCr
eTrust-Vet;35.2.7309;2010.02.17;-
F-Prot;4.5.1.85;2010.02.17;-
F-Secure;9.0.15370.0;2010.02.18;-
Fortinet;4.0.14.0;2010.02.15;-
GData;19;2010.02.18;-
Ikarus;T3.1.1.80.0;2010.02.18;-
Jiangmin;13.0.900;2010.02.17;-
K7AntiVirus;7.10.976;2010.02.17;-
Kaspersky;7.0.0.125;2010.02.17;-
McAfee;5895;2010.02.17;-
McAfee+Artemis;5895;2010.02.17;-
McAfee-GW-Edition;6.8.5;2010.02.17;-
Microsoft;1.5406;2010.02.17;-
NOD32;4875;2010.02.17;-
Norman;6.04.08;2010.02.17;-
nProtect;2009.1.8.0;2010.02.17;-
Panda;10.0.2.2;2010.02.17;-
PCTools;[removed];2010.02.17;-
Prevx;3.0;2010.02.18;-
Rising;22.34.01.03;2010.02.11;-
Sophos;4.50.0;2010.02.18;-
Sunbelt;5684;2010.02.18;-
Symantec;20091.2.0.41;2010.02.18;-
TheHacker;[removed].197;2010.02.18;-
TrendMicro;9.120.0.1004;2010.02.17;-
VBA32;[removed];2010.02.16;-
ViRobot;2010.2.17.2190;2010.02.17;-
VirusBuster;[removed];2010.02.17;-

Additional information
File size: 16384 bytes
MD5…: da188490fa45198f15bdab5f1bd81594
SHA1..: 9ee119bd595c0957e4d15916ff0d172cdeda0b89
SHA256: 2ec949d62375dfc206c525943ff1106b6624f4297b58de6ba616df69bdd8a835
ssdeep: 48:a8GdlblHfzqS6+c7tU8qxbM9+dQrlAjv4B87iAxbhBEkBQ5T7dgxe0d90sKY3
PtG:hi3qS6RoI5gv4BvA+uD3T3Ptboyn1q

PEiD..: -
PEInfo: PE Structure information

( base data )
entrypointaddress.: 0x1526
timedatestamp…..: 0x3c504d4f (Thu Jan 24 18:07:11 2002)
machinetype…….: 0x14c (I386)

( 3 sections )
name viradd virsiz rawdsiz ntrpy md5
.text 0x1000 0x6b2 0x1000 3.35 c3ae2e8e069d1b4ac05f89439e0bc19c
.rdata 0x2000 0x4a4 0x1000 1.83 53aeab99912e1e4e8f92c70846c6131c
.data 0x3000 0xd0 0x1000 0.38 96258a3ca95c12c199bfb87bd90e59b2

( 4 imports )
> KERNEL32.dll: WaitForMultipleObjects, GetStartupInfoA, GetModuleFileNameA, Sleep, GetCurrentProcessId, GetTickCount, CloseHandle, CreateProcessA, WaitForSingleObject, OpenProcess, GetLastError, CreateEventA, GetModuleHandleA
> USER32.dll: MessageBoxA
> ole32.dll: CoInitialize, CoUninitialize, CoCreateGuid
> MSVCRT.dll: _sopen, _strlwr, strchr, _ftol, _snprintf, strcpy, strlen, _close, strcspn, _read, _XcptFilter, rand, srand, sprintf, sscanf, atol, _controlfp, _exit, __setusermatherr, exit, _acmdln, __getmainargs, _initterm, _adjust_fdiv, __p__commode, __p__fmode, __set_app_type, _except_handler3

( 0 exports )

RDS…: NSRL Reference Data Set
-
pdfid.: -
sigcheck:
publisher….: n/a
copyright….: n/a
product……: n/a
description..: n/a
original name: n/a
internal name: n/a
file version.: n/a
comments…..: n/a
signers……: -
signing date.: -
verified…..: Unsigned

trid..: Win32 Executable Generic (42.3%)
Win32 Dynamic Link Library (generic) (37.6%)
Generic Win/DOS Executable (9.9%)
DOS Executable Generic (9.9%)
Autodesk FLIC Image File (extensions: flc, fli, cel) (0.0%)


%%% end bwgo044ac9f9.exe


%%% ka.ini


File ka.ini received on 2010.02.18 02:56:51 (UTC)
Antivirus Version Last Update Result
a-squared 4.5.0.50 2010.02.17 -
AhnLab-V3 5.0.0.2 2010.02.17 -
AntiVir 8.2.1.170 2010.02.17 -
Antiy-AVL 2.0.3.7 2010.02.17 -
Authentium 5.2.0.5 2010.02.18 -
Avast 4.8.1351.0 2010.02.17 -
AVG 9.0.0.730 2010.02.18 -
BitDefender 7.2 2010.02.18 -
CAT-QuickHeal 10.00 2010.02.18 -
ClamAV 0.96.0.0-git 2010.02.18 -
Comodo 3975 2010.02.18 -
DrWeb 5.0.1.12222 2010.02.18 -
eSafe 7.0.17.0 2010.02.17 -
eTrust-Vet 35.2.7309 2010.02.17 -
F-Prot 4.5.1.85 2010.02.17 -
F-Secure 9.0.15370.0 2010.02.18 -
Fortinet 4.0.14.0 2010.02.15 -
GData 19 2010.02.18 -
Ikarus T3.1.1.80.0 2010.02.18 -
Jiangmin 13.0.900 2010.02.17 -
K7AntiVirus 7.10.976 2010.02.17 -
Kaspersky 7.0.0.125 2010.02.17 -
McAfee 5895 2010.02.17 -
McAfee+Artemis 5895 2010.02.17 -
McAfee-GW-Edition 6.8.5 2010.02.17 -
Microsoft 1.5406 2010.02.17 -
NOD32 4875 2010.02.17 -
Norman 6.04.08 2010.02.17 -
nProtect 2009.1.8.0 2010.02.17 -
Panda 10.0.2.2 2010.02.17 -
PCTools 7.0.3.5 2010.02.17 -
Prevx 3.0 2010.02.18 -
Rising 22.34.01.03 2010.02.11 -
Sophos 4.50.0 2010.02.18 -
Sunbelt 5684 2010.02.18 -
Symantec 20091.2.0.41 2010.02.18 -
TheHacker [removed].197 2010.02.18 -
TrendMicro 9.120.0.1004 2010.02.17 -
VBA32 3.12.12.2 2010.02.16 -
ViRobot 2010.2.17.2190 2010.02.17 -
VirusBuster 5.0.21.0 2010.02.17 -
Additional information
File size: 405 bytes
MD5…: 4a7442c92557df1e2d72d82656fc230c
SHA1..: 9d05edf71673de22de99eb121de92ff2ed6cd35a
SHA256: 1e7148980a6cdeda658401b420631fac1d4611c6cea21ec73a2dae9d32008968
ssdeep: 12:jSWHWjAfuTWHGDFu6XAYWHO4gcUBu+TLQN4I:mW2jAmTWmI8nWu4wHSJ

PEiD..: -
PEInfo: -
RDS…: NSRL Reference Data Set
-
trid..: Generic INI configuration (100.0%)
sigcheck:
publisher….: n/a
copyright….: n/a
product……: n/a
description..: n/a
original name: n/a
internal name: n/a
file version.: n/a
comments…..: n/a
signers……: -
signing date.: -
verified…..: Unsigned

pdfid.: -

Antivirus;Version;Last Update;Result
a-squared;4.5.0.50;2010.02.17;-
AhnLab-V3;5.0.0.2;2010.02.17;-
AntiVir;8.2.1.170;2010.02.17;-
Antiy-AVL;2.0.3.7;2010.02.17;-
Authentium;5.2.0.5;2010.02.18;-
Avast;4.8.1351.0;2010.02.17;-
AVG;9.0.0.730;2010.02.18;-
BitDefender;7.2;2010.02.18;-
CAT-QuickHeal;10.00;2010.02.18;-
ClamAV;0.96.0.0-git;2010.02.18;-
Comodo;3975;2010.02.18;-
DrWeb;5.0.1.12222;2010.02.18;-
eSafe;7.0.17.0;2010.02.17;-
eTrust-Vet;35.2.7309;2010.02.17;-
F-Prot;4.5.1.85;2010.02.17;-
F-Secure;9.0.15370.0;2010.02.18;-
Fortinet;4.0.14.0;2010.02.15;-
GData;19;2010.02.18;-
Ikarus;T3.1.1.80.0;2010.02.18;-
Jiangmin;13.0.900;2010.02.17;-
K7AntiVirus;7.10.976;2010.02.17;-
Kaspersky;7.0.0.125;2010.02.17;-
McAfee;5895;2010.02.17;-
McAfee+Artemis;5895;2010.02.17;-
McAfee-GW-Edition;6.8.5;2010.02.17;-
Microsoft;1.5406;2010.02.17;-
NOD32;4875;2010.02.17;-
Norman;6.04.08;2010.02.17;-
nProtect;2009.1.8.0;2010.02.17;-
Panda;10.0.2.2;2010.02.17;-
PCTools;[removed];2010.02.17;-
Prevx;3.0;2010.02.18;-
Rising;22.34.01.03;2010.02.11;-
Sophos;4.50.0;2010.02.18;-
Sunbelt;5684;2010.02.18;-
Symantec;20091.2.0.41;2010.02.18;-
TheHacker;[removed].197;2010.02.18;-
TrendMicro;9.120.0.1004;2010.02.17;-
VBA32;[removed];2010.02.16;-
ViRobot;2010.2.17.2190;2010.02.17;-
VirusBuster;[removed];2010.02.17;-

Additional information
File size: 405 bytes
MD5…: 4a7442c92557df1e2d72d82656fc230c
SHA1..: 9d05edf71673de22de99eb121de92ff2ed6cd35a
SHA256: 1e7148980a6cdeda658401b420631fac1d4611c6cea21ec73a2dae9d32008968
ssdeep: 12:jSWHWjAfuTWHGDFu6XAYWHO4gcUBu+TLQN4I:mW2jAmTWmI8nWu4wHSJ

PEiD..: -
PEInfo: -
RDS…: NSRL Reference Data Set
-
trid..: Generic INI configuration (100.0%)
sigcheck:
publisher….: n/a
copyright….: n/a
product……: n/a
description..: n/a
original name: n/a
internal name: n/a
file version.: n/a
comments…..: n/a
signers……: -
signing date.: -
verified…..: Unsigned

pdfid.: -


%% end ka.ini




%% Rooter log

Rooter.exe (v1.0.2) by Eric_71
.
The token does not have the SeDebugPrivilege privilege ! (error:1300)
Can not acquire SeDebugPrivilege !
Please run the tool as administrator ..

.
Windows Vista Home Edition (6.0.6001) Service Pack 1
[32_bits] - x86 Family 6 Model 23 Stepping 10, GenuineIntel
.
Error OpenService (wscsvc) : 6
Error OpenSCManager : 5
Error OpenService (MpsSvc) : 6
Windows Defender -> Disabled !
User Account Control (UAC) -> Enabled
.
Internet Explorer 8.0.6001.18882
Mozilla Firefox 3.5.3 (en-US)
.
C:\ [Fixed-NTFS] .. ( Total:138 Go - Free:80 Go )
D:\ [Fixed-NTFS] .. ( Total:10 Go - Free:1 Go )
E:\ [CD_Rom]
.
Scan : 03:05.15
Path : C:\Users\Angela\Desktop\infection\Rooter.exe
User : Angela ( Administrator -> YES )
.
———————-\\ Processes
.
Locked [System Process] (0)
Locked System (4)
Locked smss.exe (416)
Locked csrss.exe (484)
Locked wininit.exe (528)
Locked csrss.exe (536)
Locked winlogon.exe (584)
Locked services.exe (616)
Locked lsass.exe (632)
Locked lsm.exe (640)
Locked svchost.exe (796)
Locked svchost.exe (880)
Locked svchost.exe (996)
Locked svchost.exe (1076)
Locked svchost.exe (1092)
Locked audiodg.exe (1172)
Locked svchost.exe (1192)
Locked SLsvc.exe (1208)
Locked svchost.exe (1240)
Locked svchost.exe (1380)
Locked spoolsv.exe (1556)
Locked svchost.exe (1580)
Locked LSSrvc.exe (1744)
Locked McProxy.exe (1780)
Locked Mcshield.exe (1820)
Locked MpfSrv.exe (1872)
Locked MWSSVC.EXE (1920)
Locked svchost.exe (1968)
Locked BLService.exe (2028)
Locked RichVideo.exe (248)
Locked ScsiAccess.EXE (448)
Locked svchost.exe (788)
Locked svchost.exe (1336)
Locked SearchIndexer.exe (1724)
Locked XAudio.exe (1156)
Locked taskeng.exe (876)
Locked mcmscsvc.exe (2144)
______ c:\PROGRA~1\mcafee.com\agent\mcagent.exe (2684)
______ C:\Windows\system32\taskeng.exe (2740)
______ C:\Windows\system32\Dwm.exe (2776)
______ C:\Windows\Explorer.EXE (2796)
______ C:\Program Files\QuickTime\qttask.exe (3072)
______ C:\Program Files\SGPSA\ie3sh.exe (3088)
______ C:\Windows\System32\wpcumi.exe (3096)
______ C:\Program Files\MyWebSearch\bar\1.bin\M3SRCHMN.EXE (3104)
______ C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe (3120)
______ C:\Program Files\Hewlett-Packard\HP Advisor\HPAdvisor.exe (3128)
______ C:\Windows\ehome\ehtray.exe (3136)
Locked GoogleToolbarNotifier.exe (3144)
______ C:\Program Files\MyWebSearch\bar\1.bin\MWSOEMON.EXE (3156)
______ C:\Program Files\Windows Media Player\wmpnscfg.exe (3168)
______ C:\Program Files\McAfee Security Scan\2.0.181\SSScheduler.exe (3204)
______ C:\Windows\ehome\ehmsas.exe (3524)
______ C:\Program Files\OpenOffice.org 3\program\soffice.exe (3720)
______ C:\Program Files\OpenOffice.org 3\program\soffice.bin (3776)
Locked wmpnetwk.exe (3992)
______ C:\Users\Angela\AppData\Local\Temp\bwgo0001a1ab.exe (1228)
Locked PresentationFontCache.exe (3244)
Locked mcsysmon.exe (3344)
Locked HPHC_Service.exe (1252)
Locked McNASvc.exe (3884)
______ C:\Program Files\Mozilla Firefox\firefox.exe (2256)
______ C:\Windows\system32\wuauclt.exe (916)
______ C:\Users\Angela\Desktop\infection\Rooter.exe (6080)
.
———————-\\ Device\Harddisk0\
.
\Device\Harddisk0 [Sectors : 63 x 512 Bytes]
.
\Device\Harddisk0\Partition1 –[ MBR ]– (Start_Offset:1048576 | Length:148311638016)
\Device\Harddisk0\Partition2 (Start_Offset:148312686592 | Length:11725176832)
.
———————-\\ Scheduled Tasks
.
C:\Windows\Tasks\HPCeeScheduleForAngela.job
C:\Windows\Tasks\McDefragTask.job
C:\Windows\Tasks\McQcTask.job
C:\Windows\Tasks\SA.DAT
C:\Windows\Tasks\SCHEDLGU.TXT
C:\Windows\Tasks\{35DC3473-A719-4d14-B7C1-FD326CA84A0C}.job
C:\Windows\Tasks\{66BA574B-1E11-49b8-909C-8CC9E0E8E015}.job
.
———————-\\ Registry
.
.
———————-\\ Files & Folders
.
———————-\\ Scan completed at 03:05.18
.
C:\Rooter$\Rooter_1.txt - (18/02/2010 | 03:05.18)



%%% Malwarebytes log

Malwarebytes' Anti-Malware 1.44
Database version: 3754
Windows 6.0.6001 Service Pack 1
Internet Explorer 8.0.6001.18882

2/17/2010 10:19:08 PM
mbam-log-2010-02-17 (22-19-08).txt

Scan type: Quick Scan
Objects scanned: 130666
Time elapsed: 7 minute(s), 5 second(s)

Memory Processes Infected: 2
Memory Modules Infected: 7
Registry Keys Infected: 149
Registry Values Infected: 8
Registry Data Items Infected: 0
Folders Infected: 14
Files Infected: 71

Memory Processes Infected:
C:\Program Files\MyWebSearch\bar\1.bin\M3SRCHMN.EXE (Adware.MyWebSearch) -> Unloaded process successfully.
C:\Program Files\MyWebSearch\bar\1.bin\MWSOEMON.EXE (Adware.MyWebSearch) -> Unloaded process successfully.

Memory Modules Infected:
C:\Program Files\MyWebSearch\bar\1.bin\MWSOESTB.DLL (Adware.MyWebSearch) -> Delete on reboot.
C:\Program Files\MyWebSearch\bar\1.bin\F3HKSTUB.DLL (Adware.MyWebSearch) -> Delete on reboot.
C:\Program Files\MyWebSearch\bar\1.bin\MWSSRCAS.DLL (Adware.MyWebSearch) -> Delete on reboot.
C:\Program Files\MyWebSearch\bar\1.bin\MWSBAR.DLL (Adware.MyWebSearch) -> Delete on reboot.
C:\Program Files\MyWebSearch\bar\firefox\NPMYWEBS.DLL (Adware.MyWebSearch) -> Delete on reboot.
C:\Program Files\MyWebSearch\bar\1.bin\M3PLUGIN.DLL (Adware.MyWebSearch) -> Delete on reboot.
C:\Program Files\MyWebSearch\bar\1.bin\F3HTMLMU.DLL (Adware.MyWebSearch) -> Delete on reboot.

Registry Keys Infected:
HKEY_CLASSES_ROOT\CLSID\{00a6faf1-072e-44cf-8957-5838f569a31d} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{00a6faf1-072e-44cf-8957-5838f569a31d} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{00a6faf1-072e-44cf-8957-5838f569a31d} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{00a6faf1-072e-44cf-8957-5838f569a31d} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{00a6faf6-072e-44cf-8957-5838f569a31d} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\TypeLib\{07b18ea0-a523-4961-b6bb-170de4475cca} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{07b18eaa-a523-4961-b6bb-170de4475cca} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{07b18eac-a523-4961-b6bb-170de4475cca} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{f87d7fb5-9dc5-4c8c-b998-d8dfe02e2978} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{07b18ea1-a523-4961-b6bb-170de4475cca} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{07b18ea1-a523-4961-b6bb-170de4475cca} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{07b18ea1-a523-4961-b6bb-170de4475cca} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{07b18ea1-a523-4961-b6bb-170de4475cca} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{07b18ea9-a523-4961-b6bb-170de4475cca} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{07b18ea9-a523-4961-b6bb-170de4475cca} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{07b18ea9-a523-4961-b6bb-170de4475cca} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{07b18eab-a523-4961-b6bb-170de4475cca} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{07b18eab-a523-4961-b6bb-170de4475cca} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{07b18eab-a523-4961-b6bb-170de4475cca} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{07b18eab-a523-4961-b6bb-170de4475cca} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{53ced2d0-5e9a-4761-9005-648404e6f7e5} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\funwebproducts.datacontrol (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\TypeLib\{c8cecde3-1ae1-4c4a-ad82-6d5b00212144} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{17de5e5e-bfe3-4e83-8e1f-8755795359ec} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{1f52a5fa-a705-4415-b975-88503b291728} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{a626cdbd-3d13-4f78-b819-440a28d7e8fc} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{25560540-9571-4d7b-9389-0f166788785a} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{25560540-9571-4d7b-9389-0f166788785a} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\funwebproducts.datacontrol.1 (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\funwebproducts.historykillerscheduler (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\TypeLib\{8ca01f0e-987c-49c3-b852-2f1ac4a7094c} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{1093995a-ba37-41d2-836e-091067c4ad17} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{120927bf-1700-43bc-810f-fab92549b390} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{247a115f-06c2-4fb3-967d-2d62d3cf4f0a} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{3e53e2cb-86db-4a4a-8bd9-ffeb7a64df82} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{90449521-d834-4703-bb4e-d3aa44042ff8} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{991aac62-b100-47ce-8b75-253965244f69} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{bbabdc90-f3d5-4801-863a-ee6ae529862d} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{d6ff3684-ad3b-48eb-bbb4-b9e6c5a355c1} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{eb9e5c1c-b1f9-4c2b-be8a-27d6446fdaf8} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{0f8ecf4f-3646-4c3a-8881-8e138ffcaf70} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{b813095c-81c0-4e40-aa14-67520372b987} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{c9d7be3e-141a-4c85-8cd6-32461f3df2c7} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{cff4ce82-3aa2-451f-9b77-7165605fb835} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\funwebproducts.historykillerscheduler.1 (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\funwebproducts.historyswattercontrolbar (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\funwebproducts.historyswattercontrolbar.1 (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\funwebproducts.htmlmenu (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\TypeLib\{e47caee0-deea-464a-9326-3f2801535a4d} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{3e1656ed-f60e-4597-b6aa-b6a58e171495} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{741de825-a6f0-4497-9aa6-8023cf9b0fff} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{3dc201fb-e9c9-499c-a11f-23c360d7c3f8} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{3dc201fb-e9c9-499c-a11f-23c360d7c3f8} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{98d9753d-d73b-42d5-8c85-4469cda897ab} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{98d9753d-d73b-42d5-8c85-4469cda897ab} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\funwebproducts.htmlmenu.1 (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\funwebproducts.htmlmenu.2 (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\funwebproducts.iecookiesmanager (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\funwebproducts.iecookiesmanager.1 (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\funwebproducts.killerobjmanager (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\funwebproducts.killerobjmanager.1 (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\funwebproducts.popswatterbarbutton (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\TypeLib\{8e6f1830-9607-4440-8530-13be7c4b1d14} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{63d0ed2b-b45b-4458-8b3b-60c69bbbd83c} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{63d0ed2d-b45b-4458-8b3b-60c69bbbd83c} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{63d0ed2c-b45b-4458-8b3b-60c69bbbd83c} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{63d0ed2c-b45b-4458-8b3b-60c69bbbd83c} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{8e6f1832-9607-4440-8530-13be7c4b1d14} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{a9571378-68a1-443d-b082-284f960c6d17} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\funwebproducts.popswatterbarbutton.1 (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\funwebproducts.popswattersettingscontrol (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\funwebproducts.popswattersettingscontrol.1 (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\mywebsearch.chatsessionplugin (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\TypeLib\{e79dfbc0-5697-4fbd-94e5-5b2a9c7c1612} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{72ee7f04-15bd-4845-a005-d6711144d86a} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{e79dfbc9-5697-4fbd-94e5-5b2a9c7c1612} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{e79dfbcb-5697-4fbd-94e5-5b2a9c7c1612} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{e79dfbca-5697-4fbd-94e5-5b2a9c7c1612} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{e79dfbca-5697-4fbd-94e5-5b2a9c7c1612} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\mywebsearch.chatsessionplugin.1 (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\mywebsearch.htmlpanel (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\TypeLib\{3e720450-b472-4954-b7aa-33069eb53906} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{3e720451-b472-4954-b7aa-33069eb53906} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{3e720453-b472-4954-b7aa-33069eb53906} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{3e720452-b472-4954-b7aa-33069eb53906} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{3e720452-b472-4954-b7aa-33069eb53906} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\mywebsearch.htmlpanel.1 (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\mywebsearch.outlookaddin (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{adb01e81-3c79-4272-a0f1-7b2be7a782dc} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\mywebsearch.outlookaddin.1 (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\mywebsearch.pseudotransparentplugin (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\TypeLib\{7473d290-b7bb-4f24-ae82-7e2ce94bb6a9} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{7473d291-b7bb-4f24-ae82-7e2ce94bb6a9} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{7473d293-b7bb-4f24-ae82-7e2ce94bb6a9} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{7473d295-b7bb-4f24-ae82-7e2ce94bb6a9} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{7473d297-b7bb-4f24-ae82-7e2ce94bb6a9} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{7473d292-b7bb-4f24-ae82-7e2ce94bb6a9} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{7473d294-b7bb-4f24-ae82-7e2ce94bb6a9} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{7473d294-b7bb-4f24-ae82-7e2ce94bb6a9} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{7473d296-b7bb-4f24-ae82-7e2ce94bb6a9} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\mywebsearch.pseudotransparentplugin.1 (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\mywebsearchtoolbar.settingsplugin (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\mywebsearchtoolbar.settingsplugin.1 (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\mywebsearchtoolbar.toolbarplugin (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\mywebsearchtoolbar.toolbarplugin.1 (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\screensavercontrol.screensaverinstaller (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\TypeLib\{29d67d3c-509a-4544-903f-c8c1b8236554} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{2e3537fc-cf2f-4f56-af54-5a6a3dd375cc} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{2e9937fc-cf2f-4f56-af54-5a6a3dd375cc} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{938aa51a-996c-4884-98ce-80dd16a5c9da} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{9ff05104-b030-46fc-94b8-81276e4e27df} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{9ff05104-b030-46fc-94b8-81276e4e27df} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{9ff05104-b030-46fc-94b8-81276e4e27df} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\screensavercontrol.screensaverinstaller.1 (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{6e74766c-4d93-4cc0-96d1-47b8e07ff9ca} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{cf54be1c-9359-4395-8533-1657cf209cfe} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{de38c398-b328-4f4c-a3ad-1b5e4ed93477} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{e342af55-b78a-4cd0-a2bb-da7f52d9d25e} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{e342af55-b78a-4cd0-a2bb-da7f52d9d25f} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{147a976f-eee1-4377-8ea7-4716e4cdd239} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{1e0de227-5ce4-4ea3-ab0c-8b03e1aa76bc} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{84da4fdf-a1cf-4195-8688-3e961f505983} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{a4730ebe-43a6-443e-9776-36915d323ad3} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{d9fffb27-d62a-4d64-8cec-1ff006528805} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\TypeLib\{0d26bc71-a633-4e71-ad31-eadc3a1b6a3a} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Typelib\{d518921a-4a03-425e-9873-b9a71756821e} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Typelib\{f42228fb-e84e-479e-b922-fbbd096e792c} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{56256a51-b582-467e-b8d4-7786eda79ae0} (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{1d4db7d2-6ec9-47a3-bd87-1e41684e07bb} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{1d4db7d2-6ec9-47a3-bd87-1e41684e07bb} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{1d4db7d2-6ec9-47a3-bd87-1e41684e07bb} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{59c7fc09-1c83-4648-b3e6-003d2bbc7481} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{68af847f-6e91-45dd-9b68-d6a12c30e5d7} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{9170b96c-28d4-4626-8358-27e6caeef907} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{d1a71fa0-ff48-48dd-9b6d-7a13a3e42127} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{ddb1968e-ead6-40fd-8dae-ff14757f60c7} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{f138d901-86f0-4383-99b6-9cdd406036da} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{56256a51-b582-467e-b8d4-7786eda79ae0} (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\MyWebSearchService (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\MyWebSearch (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\FocusInteractive (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Fun Web Products (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\FunWebProducts (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\RunDll32Policy\f3ScrCtr.dll (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Multimedia\WMPlayer\Schemes\f3pss (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Outlook\Addins\MyWebSearch.OutlookAddin (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Word\Addins\MyWebSearch.OutlookAddin (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\MyWebSearch bar Uninstall (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\MyWebSearch (Adware.MyWebSearch) -> Quarantined and deleted successfully.

Registry Values Infected:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks\{00a6faf6-072e-44cf-8957-5838f569a31d} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar\{07b18ea9-a523-4961-b6bb-170de4475cca} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\MenuExt\&Search\(default) (Adware.Hotbar) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Media\WMSDK\Sources\f3popularscreensavers (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent\Post Platform\funwebproducts (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\my web search bar search scope monitor (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\mywebsearch email plugin (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\mywebsearch email plugin (Adware.MyWebSearch) -> Quarantined and deleted successfully.

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
C:\ProgramData\29812628 (Rogue.Multiple) -> Quarantined and deleted successfully.
C:\Program Files\FunWebProducts (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\MyWebSearch (Adware.MyWebSearch) -> Delete on reboot.
C:\Program Files\MyWebSearch\bar (Adware.MyWebSearch) -> Delete on reboot.
C:\Program Files\MyWebSearch\bar\1.bin (Adware.MyWebSearch) -> Delete on reboot.
C:\Program Files\MyWebSearch\bar\Avatar (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\MyWebSearch\bar\firefox (Adware.MyWebSearch) -> Delete on reboot.
C:\Program Files\MyWebSearch\bar\firefox\chrome (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\MyWebSearch\bar\Game (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\MyWebSearch\bar\History (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\MyWebSearch\bar\icons (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\MyWebSearch\bar\Message (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\MyWebSearch\bar\Notifier (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\MyWebSearch\bar\Settings (Adware.MyWebSearch) -> Quarantined and deleted successfully.

Files Infected:
C:\Program Files\MyWebSearch\bar\1.bin\MWSSVC.EXE (Adware.MyWebSearch) -> Delete on reboot.
C:\Program Files\MyWebSearch\bar\1.bin\MWSOESTB.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\MyWebSearch\bar\1.bin\F3HKSTUB.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\MyWebSearch\bar\1.bin\MWSSRCAS.DLL (Adware.MyWebSearch) -> Delete on reboot.
C:\Program Files\MyWebSearch\bar\1.bin\MWSBAR.DLL (Adware.MyWebSearch) -> Delete on reboot.
C:\Program Files\MyWebSearch\bar\1.bin\M3SRCHMN.EXE (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\MyWebSearch\bar\1.bin\MWSOEMON.EXE (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\MyWebSearch\bar\firefox\NPMYWEBS.DLL (Adware.MyWebSearch) -> Delete on reboot.
C:\Program Files\MyWebSearch\bar\1.bin\M3PLUGIN.DLL (Adware.MyWebSearch) -> Delete on reboot.
C:\Program Files\MyWebSearch\bar\1.bin\F3DTACTL.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\MyWebSearch\bar\1.bin\F3HISTSW.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\MyWebSearch\bar\1.bin\F3HTMLMU.DLL (Adware.MyWebSearch) -> Delete on reboot.
C:\Program Files\MyWebSearch\bar\1.bin\F3POPSWT.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\MyWebSearch\bar\1.bin\M3MSG.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\MyWebSearch\bar\1.bin\M3HTML.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\MyWebSearch\bar\1.bin\M3OUTLCN.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\MyWebSearch\bar\1.bin\M3SKIN.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\MyWebSearch\bar\1.bin\F3SCRCTR.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\MyWebSearch\bar\1.bin\F3CJPEG.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\MyWebSearch\bar\1.bin\F3HTTPCT.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\MyWebSearch\bar\1.bin\F3REPROX.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\MyWebSearch\bar\1.bin\MWSOEPLG.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Windows\System32\f3PSSavr.scr (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\ProgramData\29812628\29812628.exe (Rogue.Multiple) -> Quarantined and deleted successfully.
C:\Program Files\MyWebSearch\bar\1.bin\F3BKGERR.JPG (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\MyWebSearch\bar\1.bin\F3PSSAVR.SCR (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\MyWebSearch\bar\1.bin\F3REGHK.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\MyWebSearch\bar\1.bin\F3RESTUB.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\MyWebSearch\bar\1.bin\F3SCHMON.EXE (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\MyWebSearch\bar\1.bin\F3SPACER.WMV (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\MyWebSearch\bar\1.bin\F3WALLPP.DAT (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\MyWebSearch\bar\1.bin\F3WPHOOK.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\MyWebSearch\bar\1.bin\FWPBUDDY.PNG (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\MyWebSearch\bar\1.bin\M3AUXSTB.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\MyWebSearch\bar\1.bin\M3DLGHK.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\MyWebSearch\bar\1.bin\M3HIGHIN.EXE (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\MyWebSearch\bar\1.bin\M3IDLE.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\MyWebSearch\bar\1.bin\M3IMPIPE.EXE (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\MyWebSearch\bar\1.bin\M3MEDINT.EXE (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\MyWebSearch\bar\1.bin\M3SKPLAY.EXE (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\MyWebSearch\bar\1.bin\M3SLSRCH.EXE (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\MyWebSearch\bar\Avatar\COMMON.F3S (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\MyWebSearch\bar\firefox\CHROME.MANIFEST (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\MyWebSearch\bar\firefox\INSTALL.RDF (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\MyWebSearch\bar\firefox\chrome\M3FFXTBR.JAR (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\MyWebSearch\bar\Game\CHECKERS.F3S (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\MyWebSearch\bar\Game\CHESS.F3S (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\MyWebSearch\bar\Game\REVERSI.F3S (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\MyWebSearch\bar\icons\CM.ICO (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\MyWebSearch\bar\icons\MFC.ICO (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\MyWebSearch\bar\icons\PSS.ICO (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\MyWebSearch\bar\icons\SMILEY.ICO (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\MyWebSearch\bar\icons\WB.ICO (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\MyWebSearch\bar\icons\ZWINKY.ICO (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\MyWebSearch\bar\Message\COMMON.F3S (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\MyWebSearch\bar\Notifier\COMMON.F3S (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\MyWebSearch\bar\Notifier\DOG.F3S (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\MyWebSearch\bar\Notifier\FISH.F3S (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\MyWebSearch\bar\Notifier\KUNGFU.F3S (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\MyWebSearch\bar\Notifier\LIFEGARD.F3S (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\MyWebSearch\bar\Notifier\MAID.F3S (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\MyWebSearch\bar\Notifier\MAILBOX.F3S (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\MyWebSearch\bar\Notifier\OPERA.F3S (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\MyWebSearch\bar\Notifier\ROBOT.F3S (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\MyWebSearch\bar\Notifier\SEDUCT.F3S (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\MyWebSearch\bar\Notifier\SURFER.F3S (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\MyWebSearch\bar\Settings\s_pid.dat (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Windows\Tasks\{66BA574B-1E11-49b8-909C-8CC9E0E8E015}.job (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Users\Lee\Desktop\Security Tool.LNK (Rogue.SecurityTool) -> Quarantined and deleted successfully.
C:\Users\Lee\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Security Tool.LNK (Rogue.SecurityTool) -> Quarantined and deleted successfully.
C:\Windows\Tasks\{35DC3473-A719-4d14-B7C1-FD326CA84A0C}.job (Trojan.Downloader) -> Quarantined and deleted successfully.
Please download JavaRa to your desktop and unzip it to its own folder
  • Run JavaRa.exe, pick the language of your choice and click Select. Then click Remove Older Versions.
  • Accept any prompts.
  • Open JavaRa.exe again and select Search For Updates.
  • Select Update Using Sun Java's Website then click Search and click on the Open Webpage button. Download and install the latest Java Runtime Environment (JRE) version for your computer.


Please download ATF Cleaner by Atribune.
Download - ATF Cleaner
This program is for XP, Windows 2000, and Vista
  • Double-click ATF-Cleaner.exe to run the program.
  • Under Main choose: Select All
  • Click the Empty Selected button.
(If you use FireFox or the Opera browser to keep saved passwords, click No at the prompt.)

Notes for Windows Vista users: On Windows Vista that "Windows Temp" is disabled, to empty "Windows Temp" ATF-Cleaner must be "Run as an Administrator"

It's normal after running ATF cleaner that the PC will be slower to boot the first time or two.

Please do a scan with Kaspersky Online Scanner
  • Click on the Accept button and install any components it needs.
  • The program will install and then begin downloading the latest definition files.
  • After the files have been downloaded on the left side of the page in the Scan section select My Computer.
  • This will start the program and scan your system.
  • The scan will take a while, so be patient and let it run. (At times it may appear to stall)
  • Once the update is complete, click on My Computer under the green Scan bar to the left to start the scan.
  • Once the scan is complete, it will display if your system has been infected. It does not provide an option to clean/disinfect. We only require a report from it.
  • Do NOT be alarmed by what you see in the report. Many of the finds have likely been quarantined.
  • Once the scan is complete, click on View scan report To obtain the report:
  • Click on: Save Report As
  • Next, in the ]Save as prompt, Save in area, select: Desktop
  • In the File name area, use KScan, or something similar In Save as type, click the drop arrow and select:
  • Text file [*.txt] Then, click: Save

Please post the Kaspersky Online Scanner Report in your reply.

It is important I know how the machine is running at this point please.
Hello patndoris, I've taken the directed steps and pasted the Kaspersky online scan below. At this point, the computer appears to be behaving normally. There doesn't seem to be anything out of the ordinary and it moves at a speed I would expect of a machine of its specs. At this point, is it okay to start removing some software using Add/Remove Applications or run Windows Update? Thanks, David ——————————————————————————– KASPERSKY ONLINE SCANNER 7.0: scan report Friday, February 19, 2010 Operating system: Microsoft Windows Vista Home Premium Edition, 32-bit Service Pack 1 (build 6001) Kaspersky Online Scanner version: 7.0.26.13 Last database update: Friday, February 19, 2010 17:35:22 Records in database: 3588395 ——————————————————————————– Scan settings: scan using the following database: extended Scan archives: yes Scan e-mail databases: yes Scan area - My Computer: C:\ D:\ E:\ Scan statistics: Objects scanned: 244742 Threats found: 0 Infected objects found: 0 Suspicious objects found: 0 Scan duration: 02:02:33 No threats found. Scanned area is clean. Selected area has been scanned.
Great job! The logs appear to be malware free and the machien does not appear to be experiencing any malware related problems.

Now to remove most of the tools that we have used in fixing the machine:
  • Make sure you have an Internet Connection.
  • Download OTC to your desktop and run it
  • A list of tool components used in the cleanup of malware will be downloaded.
  • If your Firewall or Real Time protection attempts to block OTC to reach the Internet, please allow the application to do so.
  • Click Yes to begin the cleanup process and remove these components, including this application.
  • You will be asked to reboot the machine to finish the cleanup process. If you are asked to reboot the machine choose Yes.

Please follow these simple steps in order to keep the computer malware free and secure:

Set a New Restore Point to prevent possible reinfection from an old one.
Some of the malware that was picked up could have been saved in System Restore. Since System Restore is a protected directory, your tools can not access it to delete these bad files which sometimes can reinfect your system. Setting a new restore point AFTER cleaning your system will help prevent this and enable your computer to "roll-back" to a clean working state.

The easiest and safest way to do this is:
* Go to Start > Programs > Accessories > System Tools
* Click "System Restore"
* Choose the radio button marked "Create a Restore Point" on the first screen then click "Next"
* Give the Restore Point a name then click "Create". The new point will be stamped with the current date and time. Keep a log of this so you can find it easily should you need to use System Restore.
* Then go to Start > Run and type: Cleanmgr
* Click "OK"
* Click the "More Options" Tab.
* Click "Clean Up" in the System Restore section to remove all previous restore points except the newly created one.

Visit Microsoft's Windows Update Site Frequently
It is important that you visit http://www.windowsupdate.com regularly. This will ensure your computer has always the latest security updates available installed on your computer. If there are new updates to install, install them immediately, reboot your computer, and revisit the site until there are no more critical updates.

Use and Update your McAfee AntiVirus Software & Firewall
It is very important that your computer has an anti-virus software running on your machine. This alone can save you a lot of trouble with malware in the future. It is imperitive that you update your Antivirus software at least once a week (Even more if you wish). If you do not update your antivirus software then it will not be able to catch any of the new variants that may come out.

I can not stress how important it is that you use your McAfee Firewall on your computer. Without a firewall your computer is succeptible to being hacked and taken over. I am very serious about this. Simply using a Firewall in its default configuration can lower your risk greatly.

Make your Internet Explorer more secure
This can be done by following these simple instructions:

1. From within Internet Explorer click on the Tools menu and then click on Options.
2. Click once on the Security tab
3. Click once on the Internet icon so it becomes highlighted.
4. Click once on the Custom Level button.

1. Change the Download signed ActiveX controls to Prompt
2. Change theDownload unsigned ActiveX controls to Disable
3. Change the Initialise and script ActiveX controls not marked as safe to Disable
4. Change the Installation of desktop items to Prompt
5. Change the Launching programs and files in an IFRAME to Prompt
6. Change the Navigate sub-frames across different domains to Prompt
7. When all these settings have been made, click on the OK button.
8. If it prompts you as to whether or not you want to save the settings, press the Yes button.

Next press the Apply button and then the OK to exit the Internet Properties page.

You should update your version of the Adobe Flash to the newest version:
You should make sure to keep your version of the Sun Java Platform (JRE) to the newest version:
We already did this in our steps but you may want to keep this information for future use.
  • Download and install the latest version of Java
Install SpywareBlaster
SpywareBlaster will added a large list of programs and sites into your Internet Explorer settings that will protect you from running and downloading known malicious programs.

The download and tutorial on installing & using this product can be found here:
Using SpywareBlaster to protect your computer from Spyware and Malware

Update and run Malwarebytes Anti-Malware
Updaste and scan your computer with this program on a regular basis just as you would an antivirus software in conjunction with SuperAntiSpyware.

Install SUPERAntiSpyware Home Edition (free edition)
You should also scan your computer with this program on a regular basis just as you would an antivirus software in conjunction with Malwarebytes.

Perform an online virus scan
Every so often, also perform an online virus scan.
AntiVirus scanners use databases which are not identical, and one may find malware that another does not.

Some online scanners:
TrendMicro HouseCall: http://uk.trendmicro-europe.com/consumer/h…call_launch.php
Panda ActiveScan: http://www.pandasoftware.com/products/activescan.htm
Kaspersky Online Scanner (using Internet Explorer): http://www.kaspersky.com/virusscanner
BitDefender: http://www.bitdefender.com/scan8/

To simplify making sure you have the latest version of many of your security programs and applications, you may want to consider:
Secunia's Personal Software Inspector (PSI). It is a free utility that scans your computer for installed applications and checks to see if they have the latest security patches and updates. If it finds any applications with possible security issues, links and/or instructions are provided for the necessariy updates.

Filehippo's Update Checker. It is free utilitiy that scan your computer for installed software, checks the versions and then sends this information to see if there are any newer releases. Available software updates are displayed and you can decide which ones to download and install. Among many other types of programs, they includes a number of the Anti-Spyware, Firewall/Security and Anti-Virus programs that have been recommended (though not all of them). Note: Definition files should be updated from within the programs themselves. The Update Checker look for newer versions of the software program, not definition files.

Update all these programs regularly
Make sure you update all the programs I have listed regularly. Without regular updates you WILL NOT be protected when new malicious programs are released.

Please also read Tony Klein's excellent article: How I got Infected in the First Place

Follow this list and your potential for being infected again will reduce dramatically.

Hopefully this should take care of your problems! Good luck & Happy surfing!
patndoris, thank you for your careful and timely attention. Everything seems to be shipshape now. I've emailed the computer owners a link to this thread so that they can read through the safe surfing recommendations. Once again, thanks for all of your help. Take care. :D David

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI