This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Not sure what's wrong with wife's comp.

20 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Let's see, it won't let me update Malwarebytes. Redirects Google. SLower than it's normal slow speed…

You fine folks helped me fix my daughters comp last year so hopefully you can walk me through this.

ANy help will be appreciated

My name is Neil btw… :-))

I was able to run a Hijack this file:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 11:18:35 PM, on 2/25/2010
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\WINDOWS\system32\cisvc.exe
C:\WINDOWS\system32\crypserv.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\PROGRA~1\AVG\AVG8\avgnsx.exe
C:\Program Files\Common Files\Motive\McciCMService.exe
C:\Program Files\Apoint\Apoint.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\Dell\QuickSet\QuickSet.exe
C:\WINDOWS\System32\DSentry.exe
C:\ImageMate CompactFlash USB\SandIcon.Exe
C:\Program Files\Canon\Memory Card Utility\PIXMA iP6000D\PDUiP6000DMon.exe
C:\Program Files\Canon\Memory Card Utility\PIXMA iP6000D\PDUiP6000DTskbr.exe
C:\Program Files\Canon\Memory Card Utility\PIXMA iP6000D\PDUiP6000DMemCrdMgr.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Dell Support Center\bin\sprtsvc.exe
C:\Program Files\Spyware Terminator\sp_rsser.exe
C:\PROGRA~1\AVG\AVG8\avgtray.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Dell Support Center\bin\sprtcmd.exe
C:\PROGRA~1\AVG\AVG8\avgemc.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe
C:\Program Files\AVG\AVG8\avgcsrvx.exe
C:\Program Files\MemoKit\memokit2.exe
C:\WINDOWS\webshots.scr
C:\Program Files\Apoint\Apntex.exe
C:\Program Files\Microsoft Office\Office\1033\msoffice.exe
C:\WINDOWS\system32\cidaemon.exe
C:\WINDOWS\system32\cidaemon.exe
C:\Program Files\SlimBrowser\sbrowser.exe
C:\Documents and Settings\Neil\Local Settings\Temporary Internet Files\Content.IE5\32TYBA4F\HijackThis[1].exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.optonline.net
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.smokinholsters.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R3 - URLSearchHook: AVG Security Toolbar BHO - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG8\Toolbar\IEToolbar.dll
R3 - URLSearchHook: (no name) - *{CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file)
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {243B17DE-77C7-46BF-B94B-0B5F309A0E64} - C:\Program Files\Microsoft Money\System\mnyside.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: RoboForm - {724d43a9-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\RoboForm.dll
O2 - BHO: AVG Security Toolbar BHO - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG8\Toolbar\IEToolbar.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)
O3 - Toolbar: &RoboForm - {724d43a0-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\RoboForm.dll
O3 - Toolbar: AVG Security Toolbar - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - C:\Program Files\AVG\AVG8\Toolbar\IEToolbar.dll
O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint\Apoint.exe
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [Dell QuickSet] C:\Program Files\Dell\QuickSet\QuickSet.exe
O4 - HKLM\..\Run: [DVDSentry] C:\WINDOWS\System32\DSentry.exe
O4 - HKLM\..\Run: [SandIcon] C:\ImageMate CompactFlash USB\SandIcon.Exe
O4 - HKLM\..\Run: [PDUiP6000DMon] C:\Program Files\Canon\Memory Card Utility\PIXMA iP6000D\PDUiP6000DMon.exe
O4 - HKLM\..\Run: [PDUiP6000DTskbr] C:\Program Files\Canon\Memory Card Utility\PIXMA iP6000D\PDUiP6000DTskbr.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Verizon_McciTrayApp] C:\Program Files\Verizon\McciTrayApp.exe
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKLM\..\Run: [dellsupportcenter] "C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P dellsupportcenter
O4 - HKLM\..\Run: [dscactivate] "C:\Program Files\Dell Support Center\gs_agent\custom\dsca.exe"
O4 - HKLM\..\Run: [yokowijer] Rundll32.exe "c:\windows\system32\ganizoni.dll",a
O4 - HKLM\..\RunOnce: [Malwarebytes' Anti-Malware] C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe /install /silent
O4 - HKCU\..\Run: [Uniblue Registry Booster] C:\Program Files\Uniblue\Registry Booster\RegistryBooster.exe /S
O4 - HKCU\..\Run: [updateMgr] "C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_7 -reboot 1
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [DellSupportCenter] "C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P DellSupportCenter
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [RoboForm] "C:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe"
O4 - Startup: MemoKit.lnk = C:\Program Files\MemoKit\mk.exe
O4 - Startup: Webshots.lnk = C:\Program Files\Webshots\Launcher.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O8 - Extra context menu item: Customize Menu - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComCustomizeIEMenu.html
O8 - Extra context menu item: Fill Forms - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O8 - Extra context menu item: RoboForm Toolbar - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O8 - Extra context menu item: Save Forms - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O9 - Extra button: Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O9 - Extra 'Tools' menuitem: Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O9 - Extra button: Save - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O9 - Extra 'Tools' menuitem: Save Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O9 - Extra button: RoboForm - {724d43aa-0d85-11d4-9908-00400523e39a} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O9 - Extra 'Tools' menuitem: RoboForm Toolbar - {724d43aa-0d85-11d4-9908-00400523e39a} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - C:\Program Files\Microsoft Money\System\mnyside.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: vzTCPConfig - http://www2.verizon.net/help/fios_settings…vzTCPConfig.CAB
O16 - DPF: {01113300-3E00-11D2-8470-0060089874ED} (Support.com Configuration Class) - https://activatemyfios.verizon.net/sdcCommo…IOS/tgctlcm.cab
O16 - DPF: {01A88BB1-1174-41EC-ACCB-963509EAE56B} (SysProWmi Class) - http://support.dell.com/systemprofiler/SysPro.CAB
O16 - DPF: {0C568603-D79D-11D2-87A7-00C04FF158BB} (BrowseFolderPopup Class) - http://download.mcafee.com/molbin/Shared/MGBrwFld.cab
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/2008.1…toUploader5.cab
O16 - DPF: {11260943-421B-11D0-8EAC-0000C07D88CF} (iPIX ActiveX Control) - http://www.ipix.com/viewers/ipixx.cab
O16 - DPF: {362C56AA-6E4F-40C7-A0B5-85501DBDAD77} (Scanner.SysScanner) - http://i.dell.com/images/global/js/scanner/SysProExe.cab
O16 - DPF: {36C417C6-13C6-448B-9784-DD73A93B0582} - http://download.mcafee.com/molbin/shared/m…56/mcinsctl.cab
O16 - DPF: {3BFFE033-BF43-11D5-A271-00A024A51325} (iNotes6 Class) - https://notes1.cc.sunysb.edu/iNotes6W.cab
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} - http://download.mcafee.com/molbin/shared/m…83/mcinsctl.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://groups.msn.com/controls/PhotoUC/MsnPUpld.cab
O16 - DPF: {5C6698D9-7BE4-4122-8EC5-291D84DBD4A0} (Facebook Photo Uploader 4 Control) - http://upload.facebook.com/controls/Facebo…toUploader3.cab
O16 - DPF: {94B82441-A413-4E43-8422-D49930E69764} (TLIEFlashObj Class) - https://echat.us.dell.com/Media/VisitorChat/TLIEFlash.CAB
O16 - DPF: {A8F2B9BD-A6A0-486A-9744-18920D898429} (ScorchPlugin Class) - http://www.sibelius.com/download/software/…tiveXPlugin.cab
O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} - http://download.mcafee.com/molbin/shared/m…,20/mcgdmgr.cab
O16 - DPF: {C432C4BD-3566-411C-8F3C-E5E0D3AE5D33} (CBrowser Class) - http://viewers.multicastmedia.com/common/m…MINIBrowser.CAB
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab
O16 - DPF: {F5820AD3-9B20-423E-B2AA-7AF2B4055746} (CRegistryDownload Class) - http://download.paltalk.com/download/0.x/regdload.cab
O16 - DPF: {F58E1CEF-A068-4C15-BA5E-587CAF3EE8C6} (MSN Chat Control 4.5) - http://chat.msn.com/bin/msnchat45.cab
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O18 - Filter hijack: text/html - {a69b112d-bfbe-400b-a81f-51b93ed57824} - C:\WINDOWS\default32.dll
O20 - AppInit_DLLs: c:\windows\system32\doyoginu.dll kayukore.dll c:\windows\system32\suwefosa.dll c:\windows\system32\ganizoni.dll
O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll
O21 - SSODL: pasikulos - {52d38f86-216b-4bcd-ac83-f951b152cedd} - c:\windows\system32\doyoginu.dll (file missing)
O21 - SSODL: pukujayug - {a8969e8d-de4e-457a-ba43-5955702f6c82} - c:\windows\system32\suwefosa.dll (file missing)
O21 - SSODL: dayohumis - {88ee50ff-9ec4-4ef2-b685-473f6d3b59e1} - c:\windows\system32\ganizoni.dll
O22 - SharedTaskScheduler: tokatiluy - {52d38f86-216b-4bcd-ac83-f951b152cedd} - c:\windows\system32\doyoginu.dll (file missing)
O22 - SharedTaskScheduler: kupuhivus - {a8969e8d-de4e-457a-ba43-5955702f6c82} - c:\windows\system32\suwefosa.dll (file missing)
O22 - SharedTaskScheduler: tokatiluy - {88ee50ff-9ec4-4ef2-b685-473f6d3b59e1} - c:\windows\system32\ganizoni.dll
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: AVG Free8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: Crypkey License - Kenonic Controls Ltd. - C:\WINDOWS\SYSTEM32\crypserv.exe
O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: McciCMService - Motive Communications, Inc. - C:\Program Files\Common Files\Motive\McciCMService.exe
O23 - Service: Canon PIXMA iP6000D Memory Card Manager (PDUiP6000DMemCrdMgr) - CANON INC. - C:\Program Files\Canon\Memory Card Utility\PIXMA iP6000D\PDUiP6000DMemCrdMgr.exe
O23 - Service: SupportSoft Sprocket Service (dellsupportcenter) (sprtsvc_dellsupportcenter) - SupportSoft, Inc. - C:\Program Files\Dell Support Center\bin\sprtsvc.exe
O23 - Service: Spyware Terminator Realtime Shield Service (sp_rssrv) - Crawler.com - C:\Program Files\Spyware Terminator\sp_rsser.exe

–
End of file - 14323 bytes
Hi sagiter, welcome to the forum.

To make cleaning this machine easier
  • Please do not uninstall/install any programs unless asked to
    It is more difficult when files/programs are appearing in/disappearing from the logs.
  • Please do not run any scans other than those requested
  • Please follow all instructions in the order posted
  • All logs/reports, etc.. must be posted in Notepad. Please ensure that word wrap is unchecked. In notepad click format, uncheck word wrap if it is checked.
  • Do not attach any logs/reports, etc.. unless specifically requested to do so.
  • If you have problems with or do not understand the instructions, Please ask before continuing.
  • Please stay with this thread until given the All Clear. A absence of symptoms does not mean a clean machine.


Please download DeFogger to your desktop.

Double click DeFogger to run the tool.
  • The application window will appear
  • Click the Disable button to disable your CD Emulation drivers
  • Click Yes to continue
  • A 'Finished!' message will appear
  • Click OK
  • DeFogger will now ask to reboot the machine - click OK
IMPORTANT! If you receive an error message while running DeFogger, please post the log defogger_disable which will appear on your desktop.

Do not re-enable these drivers until otherwise instructed.



Go HERE to get a random named copy of GMER. Scroll down to the Download section and click Download EXE. Save it to your desktop.

Before scanning with GMER, make sure all other running programs are closed and no other actions like a scheduled antivirus scan will occur while the scan is being performed. Do not use your computer for anything else during the scan.

  • Double click on the file you downloaded. If asked to allow gmer.sys driver to load, please consent .
  • If it gives you a warning about rootkit activity and asks if you want to run scan…click on NO.

    [external image: Posted Image]
    Click the image to enlarge it
  • In the right panel, you will see several boxes that have been checked. Uncheck the following …
    • Sections
    • IAT/EAT
    • Drives/Partition other than Systemdrive (typically C:\)
    • Show All (don't miss this one)
  • Then click the Scan button & wait for it to finish.
  • Once done click on the [Save..] button, and in the File name area, type in "Gmer.txt" or it will save as a .log file which cannot be uploaded to your post.
  • Save it where you can easily find it, such as your desktop, and post it in your next reply.

**Caution**
Rootkit scans often produce false positives. Do NOT take any action on any "<— ROOKIT" entries


*If GMER will not complete please run it in Safe Mode.*



Download OTL to your desktop.
  • Double click on OTL.exe to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output
  • Check the boxes beside LOP Check and Purity Check.
  • In the window under Custom Scans/Fixes copy and paste the following


    netsvcs
    %SYSTEMDRIVE%\*.exe
    /md5start
    eventlog.dll
    scecli.dll
    netlogon.dll
    cngaudit.dll
    sceclt.dll
    ntelogon.dll
    logevent.dll
    iaStor.sys
    nvstor.sys
    atapi.sys
    IdeChnDr.sys
    viasraid.sys
    AGP440.sys
    vaxscsi.sys
    nvatabus.sys
    viamraid.sys
    nvata.sys
    nvgts.sys
    iastorv.sys
    ViPrt.sys
    eNetHook.dll
    ahcix86.sys
    KR10N.sys
    nvstor32.sys
    ahcix86s.sys
    nvrd32.sys
    symmpi.sys
    adp3132.sys
    mv61xx.sys
    /md5stop
    %systemroot%\*. /mp /s
    %systemroot%\system32\*.dll /lockedfiles
    %systemroot%\Tasks\*.job /lockedfiles
    %systemroot%\system32\drivers\*.sys /lockedfiles
    %systemroot%\System32\config\*.sav

  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.

Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post it with your next reply. You may need two posts to fit them all in.

Please post back with
  • GMER log
  • both OTL logs
Thanks
I ran defogger after the Finished OK it doesn't ask to reboot the machine the box with the "Disable" and "Re-enable" is still there. Here is the log: defogger_disable by jpshortstuff (23.02.10.1) Log created at 08:58 on 26/02/2010 (Neil) Checking for autostart values… HKCU\~\Run values retrieved. HKLM\~\Run values retrieved. Checking for services/drivers… -=E.O.F=-
Hi sagiter, That's fine, close the windows and continue with the rest of the instructions. Thanks
The computer crashed during GMER. I got a blue screen that said A problem has been detected and windows has been shut down to prevent damage to your computer. A process or thread crucial to system operation has unexpectedly exited or been terminated. If this is the first time you've seen this stop error screen restart your computer. It then goes on to say that if it happens again use F8 to start the computer in safe mode, etc. Technical info: stop: 0X000000F4: (0X00000003; 0X82459DAO; 0X82459F14; 0X805FB066) Should I try to start the computer in safe mode and run gmer again ? I might have a problem as this is a laptop with a broken LCD screen and I am using an external monitor, but I can try to figure out how to do it. I will be away most of the day tomorrow so I don't know if I will be able to do what you ask until Sunday so please be patient with the response to your reply to this. Thanks, Sagiter
Hi

No problem, I'll be here.

Try GMER in safe mode, if it still won't run skip it and run the OTL scan in normal windows.

To boot to safe mode
  • Restart your computer
  • After hearing your computer beep once during startup, but before the Windows icon appears, tap the F8 key continually;
  • Instead of Windows loading as normal, a menu with options should appear;
  • Select the first option, to run Windows in Safe Mode, then press "Enter".
  • Choose your usual account.
Just to let you know that during the OTL Scans I got about 10 different po-up windows that at least looked like AVG windows warning me that there were Trojans and asking me to delete, heal, etc. I know that you guys don't like things changing during scans so I just closed those files. I could not get into safe-mode so here are the OTL files. Thanks, Sagiter

OTL.TXT

OTL logfile created on: 2/28/2010 9:13:22 AM - Run 1
OTL by OldTimer - Version 3.1.30.3 Folder = C:\Documents and Settings\Neil\Desktop
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

255.00 Mb Total Physical Memory | 18.00 Mb Available Physical Memory | 7.00% Memory free
1,000.00 Mb Paging File | 352.00 Mb Available in Paging File | 35.00% Paging File free
Paging file location(s): C:\pagefile.sys 384 768 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 37.22 Gb Total Space | 15.39 Gb Free Space | 41.34% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: OFFICE
Current User Name: Neil
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal

========== Processes (SafeList) ==========

PRC - C:\Documents and Settings\Neil\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe (Siber Systems)
PRC - C:\Program Files\SlimBrowser\sbrowser.exe (FlashPeak, Inc.)
PRC - C:\Program Files\AVG\AVG8\avgtray.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\Java\jre6\bin\jqs.exe (Sun Microsystems, Inc.)
PRC - C:\Program Files\Java\jre6\bin\jusched.exe (Sun Microsystems, Inc.)
PRC - C:\Program Files\AVG\AVG8\avgrsx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG8\avgcsrvx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG8\avgnsx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG8\avgemc.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG8\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\Common Files\Motive\McciCMService.exe (Motive Communications, Inc.)
PRC - C:\Program Files\Dell Support Center\bin\sprtcmd.exe (SupportSoft, Inc.)
PRC - C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe (Safer-Networking Ltd.)
PRC - C:\Program Files\Dell Support Center\bin\sprtsvc.exe (SupportSoft, Inc.)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Uniblue\Registry Booster\RegistryBooster.exe (Uniblue Registry Booster)
PRC - C:\Program Files\Adobe\Acrobat 7.0\Reader\AcroRd32.exe (Adobe Systems Incorporated)
PRC - C:\Program Files\QuickTime\qttask.exe (Apple Computer, Inc.)
PRC - C:\Program Files\MemoKit\MemoKit2.exe (Software Benefits Inc.)
PRC - C:\Program Files\Canon\Memory Card Utility\PIXMA iP6000D\PDUiP6000DMon.exe (CANON INC.)
PRC - C:\Program Files\Canon\Memory Card Utility\PIXMA iP6000D\PDUiP6000DTskbr.exe (CANON INC.)
PRC - C:\Program Files\Canon\Memory Card Utility\PIXMA iP6000D\PDUiP6000DMemCrdMgr.exe (CANON INC.)
PRC - C:\WINDOWS\SYSTEM32\ati2evxx.exe ()
PRC - C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe (ATI Technologies, Inc.)
PRC - C:\Program Files\Common Files\Real\Update_OB\realsched.exe (RealNetworks, Inc.)
PRC - C:\Program Files\Dell\QuickSet\quickset.exe ()
PRC - C:\WINDOWS\SYSTEM32\CIDAEMON.EXE (Microsoft Corporation)
PRC - C:\Program Files\Apoint\Apoint.exe (Alps Electric Co., Ltd.)
PRC - C:\WINDOWS\SYSTEM32\DSentry.exe (Dell - Advanced Desktop Engineering)
PRC - C:\Program Files\Apoint\ApntEx.exe (Alps Electric Co., Ltd.)
PRC - C:\ImageMate CompactFlash USB\SandIcon.exe ()
PRC - C:\WINDOWS\SYSTEM32\Crypserv.exe (Kenonic Controls Ltd.)
PRC - C:\Program Files\Microsoft Office\Office\1033\MSOFFICE.EXE (Microsoft Corporation)


========== Modules (SafeList) ==========

MOD - C:\Documents and Settings\Neil\Desktop\OTL.exe (OldTimer Tools)


========== Win32 Services (SafeList) ==========

SRV - (JavaQuickStarterService) – C:\Program Files\Java\jre6\bin\jqs.exe (Sun Microsystems, Inc.)
SRV - (avg8emc) – C:\Program Files\AVG\AVG8\avgemc.exe (AVG Technologies CZ, s.r.o.)
SRV - (avg8wd) – C:\Program Files\AVG\AVG8\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
SRV - (McciCMService) – C:\Program Files\Common Files\Motive\McciCMService.exe (Motive Communications, Inc.)
SRV - (sprtsvc_dellsupportcenter) SupportSoft Sprocket Service (dellsupportcenter) – C:\Program Files\Dell Support Center\bin\sprtsvc.exe (SupportSoft, Inc.)
SRV - (sp_rssrv) – C:\Program Files\Spyware Terminator\sp_rsser.exe (Crawler.com)
SRV - (DSBrokerService) – C:\Program Files\DellSupport\brkrsvc.exe ()
SRV - (IDriverT) – C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe (Macrovision Corporation)
SRV - (PDUiP6000DMemCrdMgr) – C:\Program Files\Canon\Memory Card Utility\PIXMA iP6000D\PDUiP6000DMemCrdMgr.exe (CANON INC.)
SRV - (Ati HotKey Poller) – C:\WINDOWS\SYSTEM32\ati2evxx.exe ()
SRV - (Crypkey License) – C:\WINDOWS\System32\Crypserv.exe (Kenonic Controls Ltd.)


========== Driver Services (SafeList) ==========

DRV - (AvgMfx86) – C:\WINDOWS\System32\Drivers\avgmfx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (AvgLdx86) – C:\WINDOWS\System32\Drivers\avgldx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (AvgTdiX) – C:\WINDOWS\System32\Drivers\avgtdix.sys (AVG Technologies CZ, s.r.o.)
DRV - (usbaudio) USB Audio Driver (WDM) – C:\WINDOWS\SYSTEM32\DRIVERS\usbaudio.sys (Microsoft Corporation)
DRV - (amdagp) – C:\WINDOWS\System32\DRIVERS\amdagp.sys (Advanced Micro Devices, Inc.)
DRV - (sisagp) – C:\WINDOWS\System32\DRIVERS\sisagp.sys (Silicon Integrated Systems Corporation)
DRV - (Secdrv) – C:\WINDOWS\SYSTEM32\DRIVERS\secdrv.sys (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.)
DRV - (MRENDIS5) – C:\Program Files\Common Files\Motive\MRENDIS5.sys (Motive, Inc.)
DRV - (MREMPR5) – C:\Program Files\Common Files\Motive\MREMPR5.sys (Motive, Inc.)
DRV - (dsunidrv) – C:\WINDOWS\SYSTEM32\DRIVERS\dsunidrv.sys (Gteko Ltd.)
DRV - (DSproct) – C:\Program Files\DellSupport\GTAction\triggers\DSproct.sys (Gteko Ltd.)
DRV - (USBModem) – C:\WINDOWS\SYSTEM32\DRIVERS\lgusbmodem.sys (LG Electronics Inc.)
DRV - (UsbDiag) – C:\WINDOWS\SYSTEM32\DRIVERS\lgusbdiag.sys (LG Electronics Inc.)
DRV - (usbbus) – C:\WINDOWS\SYSTEM32\DRIVERS\lgusbbus.sys (LG Electronics Inc.)
DRV - (GEARAspiWDM) – C:\WINDOWS\SYSTEM32\DRIVERS\GEARAspiWDM.sys (GEAR Software Inc.)
DRV - (nv) – C:\WINDOWS\SYSTEM32\DRIVERS\nv4_mini.sys (NVIDIA Corporation)
DRV - (iAimFP4) – C:\WINDOWS\SYSTEM32\DRIVERS\wvchntxx.sys (Intel® Corporation)
DRV - (iAimFP3) – C:\WINDOWS\SYSTEM32\DRIVERS\wsiintxx.sys (Intel® Corporation)
DRV - (iAimTV4) – C:\WINDOWS\SYSTEM32\DRIVERS\wch7xxnt.sys (Intel® Corporation)
DRV - (iAimTV3) – C:\WINDOWS\SYSTEM32\DRIVERS\watv04nt.sys (Intel® Corporation)
DRV - (iAimTV1) – C:\WINDOWS\SYSTEM32\DRIVERS\watv02nt.sys (Intel® Corporation)
DRV - (iAimTV0) – C:\WINDOWS\SYSTEM32\DRIVERS\watv01nt.sys (Intel® Corporation)
DRV - (iAimFP0) – C:\WINDOWS\SYSTEM32\DRIVERS\wadv01nt.sys (Intel® Corporation)
DRV - (iAimFP1) – C:\WINDOWS\SYSTEM32\DRIVERS\wadv02nt.sys (Intel® Corporation)
DRV - (iAimFP2) – C:\WINDOWS\SYSTEM32\DRIVERS\wadv05nt.sys (Intel® Corporation)
DRV - (i81x) – C:\WINDOWS\SYSTEM32\DRIVERS\i81xnt5.sys (Intel® Corporation)
DRV - (ati2mtag) – C:\WINDOWS\SYSTEM32\DRIVERS\ati2mtag.sys (ATI Technologies Inc.)
DRV - (STAC97) Audio Driver (WDM) – C:\WINDOWS\SYSTEM32\DRIVERS\STAC97.sys (SigmaTel, Inc.)
DRV - (ApfiltrService) – C:\WINDOWS\SYSTEM32\DRIVERS\Apfiltr.sys (Alps Electric Co., Ltd.)
DRV - (omci) – C:\WINDOWS\SYSTEM32\DRIVERS\omci.sys (Dell Computer Corporation)
DRV - (bcm4sbxp) – C:\WINDOWS\SYSTEM32\DRIVERS\bcm4sbxp.sys (Broadcom Corporation)
DRV - (BCM43XX) – C:\WINDOWS\SYSTEM32\DRIVERS\LSBCMNDS.SYS (The Linksys Group, Inc.)
DRV - (Vpctcom) – C:\WINDOWS\System32\DRIVERS\vpctcom.sys (PCtel, Inc.)
DRV - (Ptserial) – C:\WINDOWS\SYSTEM32\DRIVERS\ptserial.sys (PCTEL, INC.)
DRV - (Vvoice) – C:\WINDOWS\System32\DRIVERS\vvoice.sys (PCtel, Inc.)
DRV - (Vmodem) – C:\WINDOWS\System32\DRIVERS\vmodem.sys (PCTEL, INC.)
DRV - (Ptilink) – C:\WINDOWS\SYSTEM32\DRIVERS\PTILINK.SYS (Parallel Technologies, Inc.)
DRV - (AloPar) – C:\WINDOWS\SYSTEM32\DRIVERS\AloPar.sys (Eisenworld, Inc.)
DRV - (Sparrow) – C:\WINDOWS\System32\DRIVERS\sparrow.sys (Adaptec, Inc.)
DRV - (sym_u3) – C:\WINDOWS\System32\DRIVERS\sym_u3.sys (LSI Logic)
DRV - (sym_hi) – C:\WINDOWS\System32\DRIVERS\sym_hi.sys (LSI Logic)
DRV - (symc8xx) – C:\WINDOWS\System32\DRIVERS\symc8xx.sys (LSI Logic)
DRV - (symc810) – C:\WINDOWS\System32\DRIVERS\symc810.sys (Symbios Logic Inc.)
DRV - (ultra) – C:\WINDOWS\System32\DRIVERS\ultra.sys (Promise Technology, Inc.)
DRV - (ql12160) – C:\WINDOWS\System32\DRIVERS\ql12160.sys (QLogic Corporation)
DRV - (ql1080) – C:\WINDOWS\System32\DRIVERS\ql1080.sys (QLogic Corporation)
DRV - (ql1280) – C:\WINDOWS\System32\DRIVERS\ql1280.sys (QLogic Corporation)
DRV - (dac2w2k) – C:\WINDOWS\System32\DRIVERS\dac2w2k.sys (Mylex Corporation)
DRV - (mraid35x) – C:\WINDOWS\System32\DRIVERS\mraid35x.sys (American Megatrends Inc.)
DRV - (asc) – C:\WINDOWS\System32\DRIVERS\asc.sys (Advanced System Products, Inc.)
DRV - (asc3550) – C:\WINDOWS\System32\DRIVERS\asc3550.sys (Advanced System Products, Inc.)
DRV - (AliIde) – C:\WINDOWS\System32\DRIVERS\aliide.sys (Acer Laboratories Inc.)
DRV - (CmdIde) – C:\WINDOWS\System32\DRIVERS\cmdide.sys (CMD Technology, Inc.)
DRV - (EL90XBC) – C:\WINDOWS\SYSTEM32\DRIVERS\EL90XBC5.SYS (3Com Corporation)
DRV - (BrPar) – C:\WINDOWS\System32\drivers\BrPar.sys (Brother Industries Ltd.)
DRV - (NetworkX) – C:\WINDOWS\system32\ckldrv.sys ()


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,StartPage = http://www.optonline.net
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.optonline.net
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultName = Google
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultURL = http://www.google.com/search?q={searchTerm…tf8&oe=utf8
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.smokinholsters.com/
IE - HKCU\..\URLSearchHook: *{CFBFAE00-17A6-11D0-99CB-00C04FD64497} - Reg Error: Key error. File not found
IE - HKCU\..\URLSearchHook: {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG8\Toolbar\IEToolbar.dll ()
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0


[2004/07/04 22:38:45 | 000,000,000 | —D | M] – C:\Documents and Settings\Neil\Application Data\Mozilla\Firefox\Profiles\default.exe\extensions
[2004/07/04 22:38:45 | 000,000,000 | —D | M] (DOM Inspector) – C:\Documents and Settings\Neil\Application Data\Mozilla\Firefox\Profiles\default.exe\extensions\{641d8d09-7dda-4850-8228-ac0ab65e2ac9}
[2004/07/04 22:38:45 | 000,000,000 | —D | M] (Firefox (default)) – C:\Documents and Settings\Neil\Application Data\Mozilla\Firefox\Profiles\default.exe\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}

O1 HOSTS File: ([2008/10/14 09:11:00 | 000,266,850 | R— | M]) - C:\WINDOWS\SYSTEM32\DRIVERS\ETC\HOSTS
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: 127.0.0.1 www.007guard.com
O1 - Hosts: 127.0.0.1 007guard.com
O1 - Hosts: 127.0.0.1 008i.com
O1 - Hosts: 127.0.0.1 www.008k.com
O1 - Hosts: 127.0.0.1 008k.com
O1 - Hosts: 127.0.0.1 www.00hq.com
O1 - Hosts: 127.0.0.1 00hq.com
O1 - Hosts: 127.0.0.1 010402.com
O1 - Hosts: 127.0.0.1 www.032439.com
O1 - Hosts: 127.0.0.1 032439.com
O1 - Hosts: 127.0.0.1 www.100888290cs.com
O1 - Hosts: 127.0.0.1 100888290cs.com
O1 - Hosts: 127.0.0.1 www.100sexlinks.com
O1 - Hosts: 127.0.0.1 100sexlinks.com
O1 - Hosts: 127.0.0.1 www.10sek.com
O1 - Hosts: 127.0.0.1 10sek.com
O1 - Hosts: 127.0.0.1 www.123topsearch.com
O1 - Hosts: 127.0.0.1 123topsearch.com
O1 - Hosts: 127.0.0.1 www.132.com
O1 - Hosts: 127.0.0.1 132.com
O1 - Hosts: 127.0.0.1 www.136136.net
O1 - Hosts: 127.0.0.1 136136.net
O1 - Hosts: 127.0.0.1 www.163ns.com
O1 - Hosts: 127.0.0.1 163ns.com
O1 - Hosts: 9243 more lines…
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (no name) - {243B17DE-77C7-46BF-B94B-0B5F309A0E64} - C:\Program Files\Microsoft Money\System\mnyside.dll (Microsoft Corporation)
O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll (AVG Technologies CZ, s.r.o.)
O2 - BHO: (Spybot-S&D IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O2 - BHO: (no name) - {724d43a9-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\RoboForm.dll (Siber Systems Inc.)
O2 - BHO: (AVG Security Toolbar BHO) - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG8\Toolbar\IEToolbar.dll ()
O2 - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (JQSIEStartDetectorImpl Class) - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll (Sun Microsystems, Inc.)
O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - No CLSID value found.
O3 - HKLM\..\Toolbar: (&RoboForm) - {724d43a0-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\RoboForm.dll (Siber Systems Inc.)
O3 - HKLM\..\Toolbar: (AVG Security Toolbar) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - C:\Program Files\AVG\AVG8\Toolbar\IEToolbar.dll ()
O3 - HKCU\..\Toolbar\ShellBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {4B3803EA-5230-4DC3-A7FC-33638F3D3542} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (&RoboForm) - {724D43A0-0D85-11D4-9908-00400523E39A} - C:\Program Files\Siber Systems\AI RoboForm\RoboForm.dll (Siber Systems Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (AVG Security Toolbar) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - C:\Program Files\AVG\AVG8\Toolbar\IEToolbar.dll ()
O4 - HKLM..\Run: [Apoint] C:\Program Files\Apoint\Apoint.exe (Alps Electric Co., Ltd.)
O4 - HKLM..\Run: [ATIModeChange] C:\WINDOWS\System32\Ati2mdxx.exe (ATI Technologies, Inc.)
O4 - HKLM..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe (ATI Technologies, Inc.)
O4 - HKLM..\Run: [AVG8_TRAY] C:\Program Files\AVG\AVG8\avgtray.exe (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [Dell QuickSet] C:\Program Files\Dell\QuickSet\quickset.exe ()
O4 - HKLM..\Run: [dellsupportcenter] C:\Program Files\Dell Support Center\bin\sprtcmd.exe (SupportSoft, Inc.)
O4 - HKLM..\Run: [dscactivate] C:\Program Files\Dell Support Center\gs_agent\custom\dsca.exe ( )
O4 - HKLM..\Run: [DVDSentry] C:\WINDOWS\SYSTEM32\DSentry.exe (Dell - Advanced Desktop Engineering)
O4 - HKLM..\Run: [PDUiP6000DMon] C:\Program Files\Canon\Memory Card Utility\PIXMA iP6000D\PDUiP6000DMon.exe (CANON INC.)
O4 - HKLM..\Run: [PDUiP6000DTskbr] C:\Program Files\Canon\Memory Card Utility\PIXMA iP6000D\PDUiP6000DTskbr.exe (CANON INC.)
O4 - HKLM..\Run: [QuickTime Task] C:\Program Files\QuickTime\qttask.exe (Apple Computer, Inc.)
O4 - HKLM..\Run: [SandIcon] C:\ImageMate CompactFlash USB\SandIcon.exe ()
O4 - HKLM..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre6\bin\jusched.exe (Sun Microsystems, Inc.)
O4 - HKLM..\Run: [TkBellExe] C:\Program Files\Common Files\Real\Update_OB\realsched.exe (RealNetworks, Inc.)
O4 - HKLM..\Run: [Verizon_McciTrayApp] C:\Program Files\Verizon\McciTrayApp.exe File not found
O4 - HKLM..\Run: [yokowijer] C:\WINDOWS\System32\majudusu.DLL File not found
O4 - HKCU..\Run: [DellSupportCenter] C:\Program Files\Dell Support Center\bin\sprtcmd.exe (SupportSoft, Inc.)
O4 - HKCU..\Run: [RoboForm] C:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe (Siber Systems)
O4 - HKCU..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe (Safer-Networking Ltd.)
O4 - HKCU..\Run: [Uniblue Registry Booster] C:\Program Files\Uniblue\Registry Booster\RegistryBooster.exe (Uniblue Registry Booster)
O4 - HKCU..\Run: [updateMgr] C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe (Adobe Systems Incorporated)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe (Adobe Systems Incorporated)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE (Microsoft Corporation)
O4 - Startup: C:\Documents and Settings\Neil\Start Menu\Programs\Startup\MemoKit.lnk = C:\Program Files\MemoKit\mk.exe ()
O4 - Startup: C:\Documents and Settings\Neil\Start Menu\Programs\Startup\Webshots.lnk = C:\Program Files\Webshots\Launcher.exe ()
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Main present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\PhishingFilter present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O8 - Extra context menu item: Customize Menu - C:\Program Files\Siber Systems\AI RoboForm\RoboFormComCustomizeIEMenu.html ()
O8 - Extra context menu item: Fill Forms - C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html ()
O8 - Extra context menu item: RoboForm Toolbar - C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html ()
O8 - Extra context menu item: Save Forms - C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html ()
O9 - Extra Button: Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html ()
O9 - Extra 'Tools' menuitem : Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html ()
O9 - Extra Button: Save - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html ()
O9 - Extra 'Tools' menuitem : Save Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html ()
O9 - Extra Button: RoboForm - {724d43aa-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html ()
O9 - Extra 'Tools' menuitem : RoboForm Toolbar - {724d43aa-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html ()
O9 - Extra 'Tools' menuitem : Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O9 - Extra Button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - C:\Program Files\Microsoft Money\System\mnyside.dll (Microsoft Corporation)
O15 - HKCU\..Trusted Domains: ([]msn in My Computer)
O16 - DPF: {01113300-3E00-11D2-8470-0060089874ED} https://activatemyfios.verizon.net/sdcCommo…IOS/tgctlcm.cab (Support.com Configuration Class)
O16 - DPF: {01A88BB1-1174-41EC-ACCB-963509EAE56B} http://support.dell.com/systemprofiler/SysPro.CAB (SysProWmi Class)
O16 - DPF: {02BCC737-B171-4746-94C9-0D8A0B2C0089} http://office.microsoft.com/templates/ieawsdc.cab (Microsoft Office Template and Media Control)
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} http://www.apple.com/qtactivex/qtplugin.cab (QuickTime Object)
O16 - DPF: {05CA9FB0-3E3E-4B36-BF41-0E3A5CAA8CD8} http://download.microsoft.com/download/d/c…/OGAControl.cab (Office Genuine Advantage Validation Tool)
O16 - DPF: {0C568603-D79D-11D2-87A7-00C04FF158BB} http://download.mcafee.com/molbin/Shared/MGBrwFld.cab (BrowseFolderPopup Class)
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} http://upload.facebook.com/controls/2008.1…toUploader5.cab (Facebook Photo Uploader 5 Control)
O16 - DPF: {11260943-421B-11D0-8EAC-0000C07D88CF} http://www.ipix.com/viewers/ipixx.cab (iPIX ActiveX Control)
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://fpdownload.macromedia.com/get/shock…director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://download.microsoft.com/download/3/9…heckControl.cab (Windows Genuine Advantage Validation Tool)
O16 - DPF: {1E3F1348-4370-4BBE-A67A-CC7ED824CA85} http://download.microsoft.com/download/7/4…helpcontrol.cab (Microsoft Genuine Advantage Self Support Tool)
O16 - DPF: {33564D57-0000-0010-8000-00AA00389B71} http://download.microsoft.com/download/F/6…922/wmv9VCM.CAB (Reg Error: Key error.)
O16 - DPF: {362C56AA-6E4F-40C7-A0B5-85501DBDAD77} http://i.dell.com/images/global/js/scanner/SysProExe.cab (Scanner.SysScanner)
O16 - DPF: {36C417C6-13C6-448B-9784-DD73A93B0582} http://download.mcafee.com/molbin/shared/m…56/mcinsctl.cab (Reg Error: Key error.)
O16 - DPF: {3BFFE033-BF43-11D5-A271-00A024A51325} https://notes1.cc.sunysb.edu/iNotes6W.cab (iNotes6 Class)
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} http://download.mcafee.com/molbin/shared/m…83/mcinsctl.cab (Reg Error: Key error.)
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} http://groups.msn.com/controls/PhotoUC/MsnPUpld.cab (MSN Photo Upload Tool)
O16 - DPF: {5C6698D9-7BE4-4122-8EC5-291D84DBD4A0} http://upload.facebook.com/controls/Facebo…toUploader3.cab (Facebook Photo Uploader 4 Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_17)
O16 - DPF: {94B82441-A413-4E43-8422-D49930E69764} https://echat.us.dell.com/Media/VisitorChat/TLIEFlash.CAB (TLIEFlashObj Class)
O16 - DPF: {A8658086-E6AC-4957-BC8E-7D54A7E8A78D} http://www.microsoft.com/security/controls/DoomCln.CAB (DoomCln Object)
O16 - DPF: {A8F2B9BD-A6A0-486A-9744-18920D898429} http://www.sibelius.com/download/software/…tiveXPlugin.cab (ScorchPlugin Class)
O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} http://download.mcafee.com/molbin/shared/m…,20/mcgdmgr.cab (Reg Error: Key error.)
O16 - DPF: {C432C4BD-3566-411C-8F3C-E5E0D3AE5D33} http://viewers.multicastmedia.com/common/m…MINIBrowser.CAB (CBrowser Class)
O16 - DPF: {CAFEEFAC-0014-0002-0006-ABCDEFFEDCBA} http://java.sun.com/products/plugin/autodl…indows-i586.cab (Java Plug-in 1.4.2_06)
O16 - DPF: {CAFEEFAC-0015-0000-0002-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-…indows-i586.cab (Java Plug-in 1.5.0_02)
O16 - DPF: {CAFEEFAC-0015-0000-0004-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-…indows-i586.cab (Java Plug-in 1.5.0_04)
O16 - DPF: {CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-…indows-i586.cab (Java Plug-in 1.5.0_06)
O16 - DPF: {CAFEEFAC-0015-0000-0009-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-…indows-i586.cab (Java Plug-in 1.5.0_09)
O16 - DPF: {CAFEEFAC-0015-0000-0010-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-…indows-i586.cab (Java Plug-in 1.5.0_10)
O16 - DPF: {CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_01)
O16 - DPF: {CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_02)
O16 - DPF: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_03)
O16 - DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_05)
O16 - DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_07)
O16 - DPF: {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_17)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_17)
O16 - DPF: {D27CDB6E-0000-0000-0000-000000000000} http://download.macromedia.com/pub/shockwa…ash/swflash.cab (Reg Error: Key error.)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab (Shockwave Flash Object)
O16 - DPF: {F5820AD3-9B20-423E-B2AA-7AF2B4055746} http://download.paltalk.com/download/0.x/regdload.cab (CRegistryDownload Class)
O16 - DPF: {F58E1CEF-A068-4C15-BA5E-587CAF3EE8C6} http://chat.msn.com/bin/msnchat45.cab (MSN Chat Control 4.5)
O16 - DPF: DirectAnimation Java Classes Reg Error: Value error. (Reg Error: Key error.)
O16 - DPF: Microsoft XML Parser for Java Reg Error: Value error. (Reg Error: Key error.)
O16 - DPF: vzTCPConfig http://www2.verizon.net/help/fios_settings…vzTCPConfig.CAB (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll (AVG Technologies CZ, s.r.o.)
O20 - AppInit_DLLs: (c:\windows\system32\doyoginu.dll) - C:\WINDOWS\System32\doyoginu.dll File not found
O20 - AppInit_DLLs: (kayukore.dll) - File not found
O20 - AppInit_DLLs: (c:\windows\system32\suwefosa.dll) - C:\WINDOWS\System32\suwefosa.dll File not found
O20 - AppInit_DLLs: (c:\windows\system32\majudusu.dll) - C:\WINDOWS\System32\majudusu.dll File not found
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\AtiExtEvent: DllName - Ati2evxx.dll - C:\WINDOWS\System32\ati2evxx.dll ()
O20 - Winlogon\Notify\avgrsstarter: DllName - avgrsstx.dll - C:\WINDOWS\System32\avgrsstx.dll (AVG Technologies CZ, s.r.o.)
O21 - SSODL: dirimeyib - {25ced2a1-dc24-4e14-af92-baf48451c48a} - C:\WINDOWS\System32\majudusu.dll File not found
O21 - SSODL: pasikulos - {52d38f86-216b-4bcd-ac83-f951b152cedd} - C:\WINDOWS\System32\doyoginu.dll File not found
O21 - SSODL: pukujayug - {a8969e8d-de4e-457a-ba43-5955702f6c82} - C:\WINDOWS\System32\suwefosa.dll File not found
O22 - SharedTaskScheduler: {25ced2a1-dc24-4e14-af92-baf48451c48a} - gahurihor - C:\WINDOWS\System32\majudusu.dll File not found
O22 - SharedTaskScheduler: {52d38f86-216b-4bcd-ac83-f951b152cedd} - tokatiluy - C:\WINDOWS\System32\doyoginu.dll File not found
O22 - SharedTaskScheduler: {a8969e8d-de4e-457a-ba43-5955702f6c82} - kupuhivus - C:\WINDOWS\System32\suwefosa.dll File not found
O24 - Desktop WallPaper: C:\Documents and Settings\Neil\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Neil\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2002/09/03 08:59:58 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O33 - MountPoints2\{907ca763-1772-11db-befe-00062541da30}\Shell - "" = AutoRun
O33 - MountPoints2\{907ca763-1772-11db-befe-00062541da30}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{907ca763-1772-11db-befe-00062541da30}\Shell\AutoRun\command - "" = F:\LaunchU3.exe – File not found
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - comfile [open] – "%1" %*
O35 - exefile [open] – "%1" %*

NetSvcs: 6to4 - File not found
NetSvcs: Ias - C:\WINDOWS\SYSTEM32\IAS [2003/07/03 06:31:18 | 000,000,000 | —D | M]
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: Wmi - C:\WINDOWS\SYSTEM32\wmi.dll (Microsoft Corporation)
NetSvcs: WmdmPmSp - File not found

========== Files/Folders - Created Within 30 Days ==========

[2010/02/28 09:10:19 | 000,549,888 | —- | C] (OldTimer Tools) – C:\Documents and Settings\Neil\Desktop\OTL.exe
[2010/02/28 08:43:51 | 000,000,000 | —D | M] – C:\Documents and Settings\NetworkService\Application Data\AdobeUM
[2010/02/28 08:43:40 | 000,000,000 | —D | M] – C:\Documents and Settings\NetworkService\Local Settings\Application Data\Adobe
[2010/02/25 23:44:50 | 000,000,000 | —D | M] – C:\Documents and Settings\NetworkService\Application Data\Adobe
[2010/02/25 11:44:49 | 000,000,000 | —D | M] – C:\Documents and Settings\NetworkService\Application Data\Macromedia
[2010/02/24 15:12:26 | 000,000,000 | —D | M] – C:\Documents and Settings\LocalService\Application Data\Real
[2010/02/24 09:16:45 | 000,000,000 | —D | M] – C:\Documents and Settings\LocalService\Application Data\Adobe
[2009/06/29 07:25:48 | 000,000,000 | —D | M] – C:\Documents and Settings\LocalService\Application Data\AVGTOOLBAR
[2008/10/22 09:05:35 | 000,000,000 | –SD | M] – C:\Documents and Settings\NetworkService\Application Data\Microsoft
[2008/10/22 09:05:35 | 000,000,000 | –SD | M] – C:\Documents and Settings\LocalService\Application Data\Microsoft
[2008/10/22 09:05:35 | 000,000,000 | —D | M] – C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft
[2008/10/22 09:05:35 | 000,000,000 | —D | M] – C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft
[2007/02/09 00:19:36 | 000,000,000 | —D | M] – C:\Documents and Settings\LocalService\Local Settings\Application Data\Adobe
[2006/11/30 11:53:22 | 000,000,000 | —D | M] – C:\Documents and Settings\LocalService\Application Data\Gtek
[2006/11/05 05:05:42 | 000,000,000 | —D | M] – C:\Documents and Settings\LocalService\Application Data\SlimBrowser
[2006/06/20 21:19:58 | 000,000,000 | —D | M] – C:\Documents and Settings\LocalService\Application Data\Macromedia
[2005/04/30 09:43:38 | 000,000,000 | —D | M] – C:\Documents and Settings\LocalService\Local Settings\Application Data\Help
[2005/04/30 09:43:38 | 000,000,000 | —D | M] – C:\Documents and Settings\LocalService\Application Data\Help
[2004/05/08 20:06:28 | 000,000,000 | —D | M] – C:\Documents and Settings\LocalService\Local Settings\Application Data\Google
[2003/09/05 10:16:53 | 000,000,000 | —D | M] – C:\Documents and Settings\LocalService\Application Data\McAfee.com Personal Firewall
[7 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[4 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[4 C:\*.tmp files -> C:\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2099/01/01 12:00:00 | 000,097,280 | -HS- | M] () – C:\WINDOWS\System32\dusukaga.dll
[2099/01/01 12:00:00 | 000,096,768 | -HS- | M] () – C:\WINDOWS\System32\duyesedi.dll
[2099/01/01 12:00:00 | 000,061,440 | -HS- | M] () – C:\WINDOWS\System32\vagiwara.dll
[2099/01/01 12:00:00 | 000,061,440 | -HS- | M] () – C:\WINDOWS\System32\judopuje.dll
[2099/01/01 12:00:00 | 000,061,440 | -HS- | M] () – C:\WINDOWS\System32\himesuvo.dll
[2099/01/01 12:00:00 | 000,047,616 | -HS- | M] () – C:\WINDOWS\System32\zobubabe.dll
[2099/01/01 12:00:00 | 000,047,616 | -HS- | M] () – C:\WINDOWS\System32\tipilifi.dll
[2099/01/01 12:00:00 | 000,047,616 | -HS- | M] () – C:\WINDOWS\System32\tipifipo.dll
[2099/01/01 12:00:00 | 000,047,616 | -HS- | M] () – C:\WINDOWS\System32\lewabenu.dll
[2099/01/01 12:00:00 | 000,047,616 | -HS- | M] () – C:\WINDOWS\System32\hutijezu.dll
[2099/01/01 12:00:00 | 000,047,104 | -HS- | M] () – C:\WINDOWS\System32\woheluba.dll
[2099/01/01 12:00:00 | 000,047,104 | -HS- | M] () – C:\WINDOWS\System32\dazuyelu.dll
[2099/01/01 12:00:00 | 000,043,520 | -HS- | M] () – C:\WINDOWS\System32\wayofuge.dll
[2099/01/01 12:00:00 | 000,043,520 | -HS- | M] () – C:\WINDOWS\System32\gifeleho.dll
[2099/01/01 12:00:00 | 000,043,008 | -HS- | M] () – C:\WINDOWS\System32\zugoyepi.dll
[2010/02/28 10:05:53 | 000,006,456 | -H– | M] () – C:\WINDOWS\System32\komobome
[2010/02/28 09:35:42 | 000,000,608 | —- | M] () – C:\WINDOWS\aclockz6.dat
[2010/02/28 09:10:20 | 000,549,888 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Neil\Desktop\OTL.exe
[2010/02/28 09:00:10 | 000,000,296 | —- | M] () – C:\WINDOWS\tasks\oqqaesob.job
[2010/02/28 08:18:51 | 000,000,006 | -H– | M] () – C:\WINDOWS\tasks\SA.DAT
[2010/02/28 08:18:26 | 000,002,048 | –S- | M] () – C:\WINDOWS\BOOTSTAT.DAT
[2010/02/28 01:05:04 | 056,402,923 | —- | M] () – C:\WINDOWS\System32\drivers\Avg\incavi.avm
[2010/02/27 11:18:42 | 000,000,178 | -HS- | M] () – C:\Documents and Settings\Neil\NTUSER.INI
[2010/02/27 11:18:41 | 009,175,040 | -H– | M] () – C:\Documents and Settings\Neil\NTUSER.DAT
[2010/02/27 07:35:53 | 000,002,469 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Dell Support Center.lnk
[2010/02/26 15:18:20 | 000,293,376 | —- | M] () – C:\Documents and Settings\Neil\Desktop\v8vqkne5.exe
[2010/02/26 07:19:28 | 000,000,000 | —- | M] () – C:\Documents and Settings\Neil\defogger_reenable
[2010/02/26 07:11:27 | 000,050,477 | —- | M] () – C:\Documents and Settings\Neil\Desktop\Defogger.exe
[2010/02/26 00:01:03 | 003,932,214 | —- | M] () – C:\WINDOWS\Webshots for Neil.bmp
[2010/02/25 22:59:35 | 000,000,710 | —- | M] () – C:\Documents and Settings\Neil\Start Menu\Programs\Startup\Webshots.lnk
[2010/02/24 01:44:49 | 000,142,495 | —- | M] () – C:\WINDOWS\System32\drivers\Avg\microavi.avg
[2010/02/24 01:44:46 | 000,492,629 | —- | M] () – C:\WINDOWS\System32\drivers\Avg\miniavi.avg
[2010/02/24 01:44:41 | 006,061,540 | —- | M] () – C:\WINDOWS\System32\drivers\Avg\avi7.avg
[2010/02/23 20:02:48 | 000,054,156 | -H– | M] () – C:\WINDOWS\QTFont.qfn
[2010/02/20 11:57:43 | 000,059,392 | —- | M] () – C:\Documents and Settings\Neil\My Documents\TAXES and FAFSA 2009.doc
[2010/02/11 05:27:24 | 000,001,374 | —- | M] () – C:\WINDOWS\imsins.BAK
[2010/02/10 16:55:27 | 000,000,452 | —- | M] () – C:\Documents and Settings\Neil\My Documents\spider.sav
[2010/02/07 16:39:29 | 000,050,688 | —- | M] () – C:\Documents and Settings\Neil\My Documents\TAXES 2009 for accountant NO SAM.doc
[2010/02/07 16:37:34 | 000,024,576 | —- | M] () – C:\Documents and Settings\Neil\My Documents\SAMSON FLANCBAUM TAXES 2009.doc
[2010/02/07 15:33:07 | 000,024,576 | —- | M] () – C:\Documents and Settings\Neil\My Documents\Smokin Taxes 2009.doc
[2010/02/06 20:40:02 | 000,054,272 | —- | M] () – C:\Documents and Settings\Neil\My Documents\TAXES 2009.doc
[2010/02/06 20:32:16 | 000,052,736 | —- | M] () – C:\Documents and Settings\Neil\My Documents\TAXES 2009 for accountant.doc
[2010/02/06 16:46:13 | 004,456,448 | —- | M] () – C:\Documents and Settings\Neil\My Documents\My Money.mny
[2010/02/06 15:49:41 | 000,024,064 | —- | M] () – C:\Documents and Settings\Neil\My Documents\Smokin Taxes 2008.doc
[2010/02/05 11:41:40 | 000,001,409 | —- | M] () – C:\WINDOWS\QTFont.for
[7 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[4 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[4 C:\*.tmp files -> C:\*.tmp -> ]

========== Files Created - No Company Name ==========

[2099/01/01 12:00:00 | 000,097,280 | -HS- | C] () – C:\WINDOWS\System32\dusukaga.dll
[2099/01/01 12:00:00 | 000,096,768 | -HS- | C] () – C:\WINDOWS\System32\duyesedi.dll
[2099/01/01 12:00:00 | 000,061,440 | -HS- | C] () – C:\WINDOWS\System32\vagiwara.dll
[2099/01/01 12:00:00 | 000,061,440 | -HS- | C] () – C:\WINDOWS\System32\judopuje.dll
[2099/01/01 12:00:00 | 000,061,440 | -HS- | C] () – C:\WINDOWS\System32\himesuvo.dll
[2099/01/01 12:00:00 | 000,047,616 | -HS- | C] () – C:\WINDOWS\System32\zobubabe.dll
[2099/01/01 12:00:00 | 000,047,616 | -HS- | C] () – C:\WINDOWS\System32\tipilifi.dll
[2099/01/01 12:00:00 | 000,047,616 | -HS- | C] () – C:\WINDOWS\System32\tipifipo.dll
[2099/01/01 12:00:00 | 000,047,616 | -HS- | C] () – C:\WINDOWS\System32\lewabenu.dll
[2099/01/01 12:00:00 | 000,047,616 | -HS- | C] () – C:\WINDOWS\System32\hutijezu.dll
[2099/01/01 12:00:00 | 000,047,104 | -HS- | C] () – C:\WINDOWS\System32\woheluba.dll
[2099/01/01 12:00:00 | 000,047,104 | -HS- | C] () – C:\WINDOWS\System32\dazuyelu.dll
[2099/01/01 12:00:00 | 000,043,520 | -HS- | C] () – C:\WINDOWS\System32\wayofuge.dll
[2099/01/01 12:00:00 | 000,043,520 | -HS- | C] () – C:\WINDOWS\System32\gifeleho.dll
[2099/01/01 12:00:00 | 000,043,008 | -HS- | C] () – C:\WINDOWS\System32\zugoyepi.dll
[2099/01/01 12:00:00 | 000,006,456 | -H– | C] () – C:\WINDOWS\System32\komobome
[2010/02/27 07:35:53 | 000,002,469 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Dell Support Center.lnk
[2010/02/26 15:18:19 | 000,293,376 | —- | C] () – C:\Documents and Settings\Neil\Desktop\v8vqkne5.exe
[2010/02/26 07:19:28 | 000,000,000 | —- | C] () – C:\Documents and Settings\Neil\defogger_reenable
[2010/02/26 07:11:27 | 000,050,477 | —- | C] () – C:\Documents and Settings\Neil\Desktop\Defogger.exe
[2010/02/23 22:26:16 | 000,000,296 | —- | C] () – C:\WINDOWS\tasks\oqqaesob.job
[2010/02/07 16:31:12 | 000,050,688 | —- | C] () – C:\Documents and Settings\Neil\My Documents\TAXES 2009 for accountant NO SAM.doc
[2010/02/07 16:30:39 | 000,024,576 | —- | C] () – C:\Documents and Settings\Neil\My Documents\SAMSON FLANCBAUM TAXES 2009.doc
[2010/02/07 15:26:55 | 000,024,576 | —- | C] () – C:\Documents and Settings\Neil\My Documents\Smokin Taxes 2009.doc
[2010/02/06 20:39:38 | 000,059,392 | —- | C] () – C:\Documents and Settings\Neil\My Documents\TAXES and FAFSA 2009.doc
[2010/02/06 20:16:13 | 000,052,736 | —- | C] () – C:\Documents and Settings\Neil\My Documents\TAXES 2009 for accountant.doc
[2010/02/05 11:41:40 | 000,054,156 | -H– | C] () – C:\WINDOWS\QTFont.qfn
[2010/02/05 11:41:40 | 000,001,409 | —- | C] () – C:\WINDOWS\QTFont.for
[2010/01/30 15:02:10 | 000,054,272 | —- | C] () – C:\Documents and Settings\Neil\My Documents\TAXES 2009.doc
[2008/05/09 07:44:34 | 000,141,312 | —- | C] () – C:\WINDOWS\System32\drivers\sp_rsdrv2.sys
[2008/03/06 00:36:33 | 000,086,016 | —- | C] () – C:\WINDOWS\System32\ati2evxx.dll
[2007/01/23 15:15:22 | 000,676,224 | —- | C] () – C:\WINDOWS\System32\OGACheckControl.DLL
[2006/10/20 16:15:34 | 000,001,359 | —- | C] () – C:\Documents and Settings\All Users\Application Data\QTSBandwidthCache
[2006/01/11 13:25:19 | 000,000,576 | —- | C] () – C:\WINDOWS\_delis32.ini
[2006/01/11 13:25:13 | 000,001,216 | —- | C] () – C:\WINDOWS\_isenv31.ini
[2006/01/11 13:25:12 | 000,000,521 | —- | C] () – C:\WINDOWS\_iserr31.ini
[2006/01/09 12:28:27 | 000,000,313 | —- | C] () – C:\WINDOWS\BRDIAG.INI
[2006/01/09 12:28:27 | 000,000,145 | —- | C] () – C:\WINDOWS\BRVIDEO.INI
[2006/01/09 12:28:26 | 000,000,023 | —- | C] () – C:\WINDOWS\Brownie.ini
[2006/01/09 12:28:17 | 000,026,624 | —- | C] () – C:\WINDOWS\System32\BRGSRC32.DLL
[2006/01/09 12:28:17 | 000,004,608 | —- | C] () – C:\WINDOWS\System32\BRGSRC16.DLL
[2006/01/09 12:28:16 | 000,077,824 | —- | C] () – C:\WINDOWS\System32\BROSNMP.DLL
[2006/01/09 12:28:12 | 000,009,013 | —- | C] () – C:\WINDOWS\HL-2040.INI
[2006/01/09 12:27:26 | 000,000,426 | —- | C] () – C:\WINDOWS\BRWMARK.INI
[2005/11/29 00:11:56 | 000,000,037 | —- | C] () – C:\WINDOWS\ipixActivex.ini
[2005/08/09 17:12:28 | 003,596,288 | —- | C] () – C:\WINDOWS\System32\qt-dx331.dll
[2004/11/18 14:30:13 | 000,000,000 | —- | C] () – C:\WINDOWS\OpPrintServer.INI
[2004/11/18 14:21:16 | 000,007,680 | —- | C] () – C:\WINDOWS\System32\CNMVS69.DLL
[2004/09/11 21:54:11 | 000,000,063 | —- | C] () – C:\WINDOWS\mdm.ini
[2004/09/03 17:52:50 | 000,196,608 | —- | C] () – C:\WINDOWS\System32\GCCollection.dll
[2004/06/30 15:04:46 | 000,040,960 | —- | C] () – C:\WINDOWS\System32\SDelete.dll
[2004/04/21 13:34:48 | 000,071,749 | —- | C] () – C:\WINDOWS\HCExtOutput.dll
[2004/04/21 13:34:48 | 000,000,823 | —- | C] () – C:\WINDOWS\TSC.ini
[2004/04/21 13:34:32 | 000,000,170 | —- | C] () – C:\WINDOWS\GetServer.ini
[2004/03/25 11:20:56 | 000,000,127 | —- | C] () – C:\Documents and Settings\Neil\Local Settings\Application Data\fusioncache.dat
[2004/03/25 08:33:21 | 000,000,024 | —- | C] () – C:\WINDOWS\wininit.ini
[2004/03/25 08:33:05 | 000,000,002 | —- | C] () – C:\WINDOWS\msoffice.ini
[2004/03/07 13:51:00 | 000,024,924 | —- | C] () – C:\WINDOWS\System32\openports.dll
[2004/02/09 15:42:28 | 000,000,071 | —- | C] () – C:\WINDOWS\Theme Uninstall.ini
[2003/10/14 15:54:32 | 000,030,720 | —- | C] () – C:\Documents and Settings\Neil\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2003/10/03 17:10:14 | 000,000,036 | —- | C] () – C:\WINDOWS\Crypkey.ini
[2003/10/03 17:10:09 | 000,024,608 | —- | C] () – C:\WINDOWS\System32\Ckldrv.sys
[2003/10/03 17:10:09 | 000,018,432 | —- | C] () – C:\WINDOWS\Setup_ck.dll
[2003/10/03 17:10:08 | 000,000,000 | —- | C] () – C:\WINDOWS\PROTOCOL.INI
[2003/08/22 19:23:38 | 000,000,026 | —- | C] () – C:\WINDOWS\INTUIT.INI
[2003/07/23 18:57:41 | 000,002,154 | —- | C] () – C:\WINDOWS\Solitaire.ini
[2003/07/11 19:12:37 | 000,000,210 | —- | C] () – C:\WINDOWS\cdPlayer.ini
[2003/07/10 06:55:57 | 000,000,208 | —- | C] () – C:\WINDOWS\QUICKEN.INI
[2003/07/10 01:36:45 | 000,000,000 | —- | C] () – C:\WINDOWS\NSREX.INI
[2003/07/10 00:53:16 | 000,000,054 | —- | C] () – C:\WINDOWS\setihome.ini
[2003/07/09 23:12:55 | 000,000,034 | —- | C] () – C:\WINDOWS\alohabob.INI
[2003/07/03 07:29:25 | 000,000,061 | —- | C] () – C:\WINDOWS\smscfg.ini
[2003/07/03 07:19:29 | 000,000,376 | —- | C] () – C:\WINDOWS\ODBC.INI
[2003/07/03 07:04:28 | 000,000,893 | —- | C] () – C:\WINDOWS\orun32.ini
[2003/07/03 06:35:24 | 000,000,546 | —- | C] () – C:\WINDOWS\System32\OEMINFO.INI
[2002/10/28 10:53:49 | 000,210,944 | —- | C] () – C:\WINDOWS\System32\MSVCRT10.DLL
[2002/10/28 10:53:43 | 000,000,083 | —- | C] () – C:\WINDOWS\KPCMS.INI
[2002/07/03 10:57:48 | 000,013,203 | —- | C] () – C:\WINDOWS\System32\drivers\packet.sys
[2002/01/08 19:03:10 | 000,077,824 | —- | C] () – C:\WINDOWS\System32\MiniBrowser.dll
[2001/12/17 21:30:43 | 000,000,359 | —- | C] () – C:\WINDOWS\smsafari.ini
[2001/12/17 21:17:17 | 000,012,416 | —- | C] () – C:\WINDOWS\System32\VRX1.DLL
[2001/12/17 21:17:16 | 000,027,136 | —- | C] () – C:\WINDOWS\System32\VERMONT1.DLL
[2001/12/17 21:17:11 | 000,107,520 | —- | C] () – C:\WINDOWS\System32\SIMANT.DLL
[2001/12/03 15:58:32 | 000,286,208 | —- | C] () – C:\WINDOWS\System32\DCSSDK32.dll
[2001/12/03 15:58:32 | 000,107,456 | —- | C] () – C:\WINDOWS\System32\SH33W32.DLL
[2001/11/21 19:44:10 | 000,003,413 | —- | C] () – C:\Documents and Settings\Neil\Application Data\dw.log
[2001/07/05 16:36:07 | 000,000,370 | —- | C] () – C:\WINDOWS\KA.INI
[2001/05/30 08:47:44 | 000,110,592 | —- | C] () – C:\WINDOWS\System32\cdtool.dll
[2001/05/12 16:10:41 | 000,056,832 | —- | C] () – C:\WINDOWS\System32\iyvu9_32.dll
[2001/05/12 11:01:14 | 000,167,936 | —- | C] () – C:\WINDOWS\System32\XFILEXR.DLL
[2001/05/12 10:59:13 | 000,040,960 | —- | C] () – C:\WINDOWS\System32\OEMREG.DLL
[2001/05/12 10:58:38 | 000,008,576 | —- | C] () – C:\WINDOWS\System32\ICMUPG.DLL
[2001/05/12 10:54:15 | 000,028,672 | —- | C] () – C:\WINDOWS\System32\NETBIOS.DLL
[2001/05/12 10:53:38 | 000,188,416 | —- | C] () – C:\WINDOWS\System32\MEMBG.DLL
[2001/05/12 10:51:28 | 000,002,490 | —- | C] () – C:\WINDOWS\System32\DLCNDI.DLL
[2001/05/12 09:46:50 | 000,009,216 | —- | C] () – C:\WINDOWS\System32\Spktrn32.dll
[2001/05/12 09:29:56 | 000,040,448 | —- | C] () – C:\WINDOWS\System32\hcfuninst.dll
[2001/05/12 09:29:56 | 000,028,672 | —- | C] () – C:\WINDOWS\System32\hcfapi.dll
[2000/10/21 01:21:26 | 000,363,520 | —- | C] () – C:\WINDOWS\System32\psisdecd.dll
[1999/12/07 00:00:00 | 000,024,975 | —- | C] () – C:\WINDOWS\twain_16.dll
[1999/07/23 12:46:48 | 000,000,116 | —- | C] () – C:\WINDOWS\AuHCcup1.ini
[1999/07/23 09:53:20 | 000,129,536 | —- | C] () – C:\WINDOWS\AuHCcup1.dll
[1999/01/22 17:46:58 | 000,065,536 | —- | C] () – C:\WINDOWS\System32\MSRTEDIT.DLL
[1980/01/01 00:00:00 | 000,031,744 | —- | C] () – C:\WINDOWS\System32\mdmmoh.dll
[1979/12/31 11:29:50 | 000,038,352 | —- | C] () – C:\WINDOWS\System32\NAVAPGUI.DLL

========== LOP Check ==========

[2009/11/06 06:56:41 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\AVG Security Toolbar
[2008/10/23 21:50:10 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Banner Maker Pro 7
[2007/11/03 14:11:59 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\GlobalSCAPE
[2005/04/03 22:08:03 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\RoboForm
[2008/08/22 07:34:02 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Spyware Terminator
[2008/03/20 08:50:30 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\SupportSoft
[2007/11/08 14:55:57 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TEMP
[2007/12/03 11:27:07 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Viewpoint
[2008/12/30 21:58:40 | 000,000,000 | —D | M] – C:\Documents and Settings\Neil\Application Data\AVGTOOLBAR
[2007/04/25 18:03:39 | 000,000,000 | —D | M] – C:\Documents and Settings\Neil\Application Data\Digital Photo Slide Show
[2007/11/03 14:11:52 | 000,000,000 | —D | M] – C:\Documents and Settings\Neil\Application Data\GlobalSCAPE
[2003/07/09 17:05:42 | 000,000,000 | —D | M] – C:\Documents and Settings\Neil\Application Data\InterVideo
[2006/04/06 15:10:57 | 000,000,000 | —D | M] – C:\Documents and Settings\Neil\Application Data\Kensington
[2007/05/17 22:28:21 | 000,000,000 | —D | M] – C:\Documents and Settings\Neil\Application Data\KompoZer
[2004/04/20 16:38:15 | 000,000,000 | —D | M] – C:\Documents and Settings\Neil\Application Data\Leadertech
[2007/07/12 21:22:05 | 000,000,000 | —D | M] – C:\Documents and Settings\Neil\Application Data\Novagraph
[2010/02/25 11:47:37 | 000,000,000 | —D | M] – C:\Documents and Settings\Neil\Application Data\Registry Booster
[2004/07/10 01:31:42 | 000,000,000 | —D | M] – C:\Documents and Settings\Neil\Application Data\Screen Calendar
[2010/02/28 09:13:18 | 000,000,000 | —D | M] – C:\Documents and Settings\Neil\Application Data\SlimBrowser
[2008/08/21 22:42:02 | 000,000,000 | —D | M] – C:\Documents and Settings\Neil\Application Data\Spyware Terminator
[2004/06/30 20:03:31 | 000,000,000 | —D | M] – C:\Documents and Settings\Neil\Application Data\Thunderbird
[2007/01/13 22:29:07 | 000,000,000 | —D | M] – C:\Documents and Settings\Neil\Application Data\Uniblue
[2007/12/03 11:27:14 | 000,000,000 | —D | M] – C:\Documents and Settings\Neil\Application Data\Viewpoint
[2003/07/09 22:53:59 | 000,000,258 | —- | M] () – C:\WINDOWS\Tasks\ISP signup reminder 1.job
[2010/02/28 09:00:10 | 000,000,296 | —- | M] () – C:\WINDOWS\Tasks\oqqaesob.job

========== Purity Check ==========



========== Custom Scans ==========


< %SYSTEMDRIVE%\*.exe >


< MD5 for: AGP440.SYS >
[2004/09/13 16:13:57 | 022,245,337 | —- | M] () .cab file – C:\WINDOWS\Driver Cache\I386\sp2.cab:AGP440.sys
[2008/11/18 15:37:15 | 023,852,652 | —- | M] () .cab file – C:\WINDOWS\Driver Cache\I386\sp3.cab:AGP440.sys
[2004/09/13 16:13:57 | 022,245,337 | —- | M] () .cab file – C:\WINDOWS\ServicePackFiles\i386\sp2.cab:AGP440.sys
[2008/11/18 15:37:15 | 023,852,652 | —- | M] () .cab file – C:\WINDOWS\ServicePackFiles\i386\sp3.cab:AGP440.sys
[2008/04/13 13:36:38 | 000,042,368 | —- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 – C:\WINDOWS\ServicePackFiles\i386\agp440.sys
[2008/04/13 13:36:38 | 000,042,368 | —- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 – C:\WINDOWS\SYSTEM32\DRIVERS\agp440.sys
[2004/08/04 01:07:41 | 000,042,368 | —- | M] (Microsoft Corporation) MD5=2C428FA0C3E3A01ED93C9B2A27D8D4BB – C:\WINDOWS\$NtServicePackUninstall$\agp440.sys
[2001/08/17 13:58:00 | 000,025,472 | —- | M] (Microsoft Corporation) MD5=65880045C51AA36184841CEE915A61DF – C:\I386\AGP440.SYS
[2001/08/17 13:58:00 | 000,025,472 | —- | M] (Microsoft Corporation) MD5=65880045C51AA36184841CEE915A61DF – C:\WINDOWS\SYSTEM32\ReinstallBackups\0002\DriverFiles\i386\AGP440.SYS

< MD5 for: ATAPI.SYS >
[2002/08/29 05:00:00 | 010,158,890 | —- | M] () .cab file – C:\I386\sp1.cab:atapi.sys
[2002/08/29 05:00:00 | 010,158,890 | —- | M] () .cab file – C:\WINDOWS\Driver Cache\I386\sp1.cab:atapi.sys
[2004/09/13 16:13:57 | 022,245,337 | —- | M] () .cab file – C:\WINDOWS\Driver Cache\I386\sp2.cab:atapi.sys
[2008/11/18 15:37:15 | 023,852,652 | —- | M] () .cab file – C:\WINDOWS\Driver Cache\I386\sp3.cab:atapi.sys
[2004/09/13 16:13:57 | 022,245,337 | —- | M] () .cab file – C:\WINDOWS\ServicePackFiles\i386\sp2.cab:atapi.sys
[2008/11/18 15:37:15 | 023,852,652 | —- | M] () .cab file – C:\WINDOWS\ServicePackFiles\i386\sp3.cab:atapi.sys
[2002/08/29 01:27:50 | 000,086,912 | —- | M] (Microsoft Corporation) MD5=95B858761A00E1D4F81F79A0DA019ACA – C:\I386\atapi.sys
[2002/08/29 01:27:50 | 000,086,912 | —- | M] (Microsoft Corporation) MD5=95B858761A00E1D4F81F79A0DA019ACA – C:\WINDOWS\SYSTEM32\ReinstallBackups\0007\DriverFiles\i386\atapi.sys
[2008/04/13 13:40:30 | 000,096,512 | —- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 – C:\WINDOWS\ServicePackFiles\i386\atapi.sys
[2008/04/13 13:40:30 | 000,096,512 | —- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 – C:\WINDOWS\SYSTEM32\DRIVERS\atapi.sys
[2004/08/04 00:59:42 | 000,095,360 | —- | M] (Microsoft Corporation) MD5=CDFE4411A69C224BD1D11B2DA92DAC51 – C:\WINDOWS\$NtServicePackUninstall$\atapi.sys

< MD5 for: EVENTLOG.DLL >
[2008/04/13 19:11:53 | 000,056,320 | —- | M] (Microsoft Corporation) MD5=6D4FEB43EE538FC5428CC7F0565AA656 – C:\WINDOWS\ServicePackFiles\i386\eventlog.dll
[2008/04/13 19:11:53 | 000,056,320 | —- | M] (Microsoft Corporation) MD5=6D4FEB43EE538FC5428CC7F0565AA656 – C:\WINDOWS\SYSTEM32\eventlog.dll
[2004/08/04 02:56:42 | 000,055,808 | —- | M] (Microsoft Corporation) MD5=82B24CB70E5944E6E34662205A2A5B78 – C:\WINDOWS\$NtServicePackUninstall$\eventlog.dll
[2002/08/29 05:00:00 | 000,049,152 | —- | M] (Microsoft Corporation) MD5=BF3C8CF53C77B48206B39910B6D6CBCC – C:\I386\EVENTLOG.DLL

< MD5 for: NETLOGON.DLL >
[2008/04/13 19:12:01 | 000,407,040 | —- | M] (Microsoft Corporation) MD5=1B7F071C51B77C272875C3A23E1E4550 – C:\WINDOWS\ServicePackFiles\i386\netlogon.dll
[2008/04/13 19:12:01 | 000,407,040 | —- | M] (Microsoft Corporation) MD5=1B7F071C51B77C272875C3A23E1E4550 – C:\WINDOWS\SYSTEM32\netlogon.dll
[2002/08/29 05:00:00 | 000,399,360 | —- | M] (Microsoft Corporation) MD5=3ADD563ED7A1C66E6F5E0F7A661AA96D – C:\I386\NETLOGON.DLL
[2004/08/04 02:56:44 | 000,407,040 | —- | M] (Microsoft Corporation) MD5=96353FCECBA774BB8DA74A1C6507015A – C:\WINDOWS\$NtServicePackUninstall$\netlogon.dll

< MD5 for: SCECLI.DLL >
[2004/08/04 02:56:44 | 000,180,224 | —- | M] (Microsoft Corporation) MD5=0F78E27F563F2AAF74B91A49E2ABF19A – C:\WINDOWS\$NtServicePackUninstall$\scecli.dll
[2002/08/29 05:00:00 | 000,174,592 | —- | M] (Microsoft Corporation) MD5=97418A5C642A5C748A28BD7CF6860B57 – C:\I386\SCECLI.DLL
[2008/04/13 19:12:05 | 000,181,248 | —- | M] (Microsoft Corporation) MD5=A86BB5E61BF3E39B62AB4C7E7085A084 – C:\WINDOWS\ServicePackFiles\i386\scecli.dll
[2008/04/13 19:12:05 | 000,181,248 | —- | M] (Microsoft Corporation) MD5=A86BB5E61BF3E39B62AB4C7E7085A084 – C:\WINDOWS\SYSTEM32\scecli.dll

< %systemroot%\*. /mp /s >

< %systemroot%\system32\*.dll /lockedfiles >
[2099/01/01 12:00:00 | 000,047,104 | -HS- | M] () Unable to obtain MD5 – C:\WINDOWS\SYSTEM32\dazuyelu.dll
[2099/01/01 12:00:00 | 000,061,440 | -HS- | M] () Unable to obtain MD5 – C:\WINDOWS\SYSTEM32\himesuvo.dll
[2099/01/01 12:00:00 | 000,047,616 | -HS- | M] () Unable to obtain MD5 – C:\WINDOWS\SYSTEM32\hutijezu.dll
[2099/01/01 12:00:00 | 000,061,440 | -HS- | M] () Unable to obtain MD5 – C:\WINDOWS\SYSTEM32\judopuje.dll
[2099/01/01 12:00:00 | 000,047,616 | -HS- | M] () Unable to obtain MD5 – C:\WINDOWS\SYSTEM32\lewabenu.dll
[2099/01/01 12:00:00 | 000,047,616 | -HS- | M] () Unable to obtain MD5 – C:\WINDOWS\SYSTEM32\tipifipo.dll
[2099/01/01 12:00:00 | 000,047,616 | -HS- | M] () Unable to obtain MD5 – C:\WINDOWS\SYSTEM32\tipilifi.dll
[2099/01/01 12:00:00 | 000,061,440 | -HS- | M] () Unable to obtain MD5 – C:\WINDOWS\SYSTEM32\vagiwara.dll
[2099/01/01 12:00:00 | 000,047,104 | -HS- | M] () Unable to obtain MD5 – C:\WINDOWS\SYSTEM32\woheluba.dll
[2099/01/01 12:00:00 | 000,047,616 | -HS- | M] () Unable to obtain MD5 – C:\WINDOWS\SYSTEM32\zobubabe.dll
[7 C:\WINDOWS\system32\*.tmp files -> C:\WINDOWS\system32\*.tmp -> ]

< %systemroot%\Tasks\*.job /lockedfiles >

< %systemroot%\system32\drivers\*.sys /lockedfiles >

< %systemroot%\System32\config\*.sav >
[2002/09/03 08:47:18 | 000,094,208 | —- | M] () – C:\WINDOWS\SYSTEM32\CONFIG\DEFAULT.SAV
[2002/09/03 08:47:18 | 000,602,112 | —- | M] () – C:\WINDOWS\SYSTEM32\CONFIG\SOFTWARE.SAV
[2002/09/03 08:47:18 | 000,380,928 | —- | M] () – C:\WINDOWS\SYSTEM32\CONFIG\SYSTEM.SAV

========== Alternate Data Streams ==========

@Alternate Data Stream - 125 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:08948D52
< End of report >

Extras.txt:

OTL Extras logfile created on: 2/28/2010 9:13:22 AM - Run 1
OTL by OldTimer - Version 3.1.30.3 Folder = C:\Documents and Settings\Neil\Desktop
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

255.00 Mb Total Physical Memory | 18.00 Mb Available Physical Memory | 7.00% Memory free
1,000.00 Mb Paging File | 352.00 Mb Available in Paging File | 35.00% Paging File free
Paging file location(s): C:\pagefile.sys 384 768 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 37.22 Gb Total Space | 15.39 Gb Free Space | 41.34% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: OFFICE
Current User Name: Neil
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.html [@ = SlimBrowserHtml] – C:\Program Files\SlimBrowser\sbrowser.exe (FlashPeak, Inc.)

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
exefile [open] – "%1" %*
htmlfile – "C:\Program Files\Microsoft Office\Office10\msohtmed.exe" %1 (Microsoft Corporation)
htmlfile [open] – "C:\Program Files\Internet Explorer\IEXPLORE.EXE" -nohome (Microsoft Corporation)
htmlfile [opennew] – "C:\Program Files\Internet Explorer\IEXPLORE.EXE" %1 (Microsoft Corporation)
http [open] – "C:\Program Files\SlimBrowser\sbrowser.exe" %1 (FlashPeak, Inc.)
https [open] – "C:\Program Files\SlimBrowser\sbrowser.exe" %1 (FlashPeak, Inc.)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] – "%1" %*
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Applications\iexplore.exe [open] – "C:\Program Files\Internet Explorer\IEXPLORE.EXE" %1 (Microsoft Corporation)
CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] – "C:\Program Files\Internet Explorer\iexplore.exe" (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"AntiVirusDisableNotify" = 1
"FirewallDisableNotify" = 1
"UpdatesDisableNotify" = 1
"AntiVirusOverride" = 0
"FirewallOverride" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
"139:TCP" = 139:TCP:*:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:*:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:*:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:*:Enabled:@xpsp2res.dll,-22002

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DoNotAllowExceptions" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"139:TCP" = 139:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22002
"1900:UDP" = 1900:UDP:LocalSubNet:Disabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Disabled:@xpsp2res.dll,-22008

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files\AIM\aim.exe" = C:\Program Files\AIM\aim.exe:*:Disabled:AOL Instant Messenger – File not found
"C:\Program Files\Real\RealPlayer\realplay.exe" = C:\Program Files\Real\RealPlayer\realplay.exe:*:Enabled:RealOne Player – (RealNetworks, Inc.)
"C:\Program Files\SlimBrowser\sbrowser.exe" = C:\Program Files\SlimBrowser\sbrowser.exe:*:Enabled:FlashPeak SlimBrowser – (FlashPeak, Inc.)
"C:\Program Files\East Bay Technologies\CTube!\CTube.exe" = C:\Program Files\East Bay Technologies\CTube!\CTube.exe:*:Enabled:CTube – File not found
"C:\mirc\mirc32.exe" = C:\mirc\mirc32.exe:*:Enabled:mIRC – File not found
"C:\Documents and Settings\Neil\Local Settings\Temp\{F9229DD7-2F4A-48C6-8311-E74A7F5D696A}\{4C78937F-0C8E-11D9-A3EB-0001025FA304}\k_update.exe" = C:\Documents and Settings\Neil\Local Settings\Temp\{F9229DD7-2F4A-48C6-8311-E74A7F5D696A}\{4C78937F-0C8E-11D9-A3EB-0001025FA304}\k_update.exe:*:Enabled:Kensington Digital Update of installed software via the Web. – File not found
"C:\mirc\mirc.exe" = C:\mirc\mirc.exe:*:Enabled:mIRC – File not found
"C:\Program Files\Windows Media Player\wmplayer.exe" = C:\Program Files\Windows Media Player\wmplayer.exe:*:Enabled:Windows Media Player – (Microsoft Corporation)
"C:\Program Files\AVG\AVG8\avgemc.exe" = C:\Program Files\AVG\AVG8\avgemc.exe:*:Enabled:avgemc.exe – (AVG Technologies CZ, s.r.o.)
"C:\Program Files\AVG\AVG8\avgupd.exe" = C:\Program Files\AVG\AVG8\avgupd.exe:*:Enabled:avgupd.exe – (AVG Technologies CZ, s.r.o.)


========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{00000409-78E1-11D2-B60F-006097C998E7}" = Microsoft Office 2000 Premium
"{01F9D88C-3C86-4E82-840A-101A3221F67A}" = Microsoft Money 2003
"{02B42D23-10F2-4862-ADA4-3DF1EA0021B2}" = Microsoft Money 2003 System Pack
"{0BEDBD4E-2D34-47B5-9973-57E62B29307C}" = ATI Control Panel
"{0D499481-22C6-4B25-8AC2-6D3F6C885FB9}" = OpenOffice.org Installer 1.0
"{0F745260-192A-11D5-A511-00C04F9643C9}" = ImageMate CompactFlash USB (SDDR-31) Ver. 5.05
"{11F1920A-56A2-4642-B6E0-3B31A12C9288}" = Dell Solution Center
"{151C555A-A9E7-4A2E-B6D7-165D04A3C956}" = Dell Picture Studio - Dell Image Expert
"{18D10072035C4515918F7E37EAFAACFC}" = AutoUpdate
"{20227921-DB38-4810-9162-DDC6FCA936E7}" = Dell Home Systems Services Agreement
"{22DE1881-9D24-4981-B5CC-EC7E9F2F4D52}" = Rhapsody Player Engine
"{26A24AE4-039D-4CA4-87B4-2F83216017FF}" = Java™ 6 Update 17
"{3248F0A8-6813-11D6-A77B-00B0D0150020}" = J2SE Runtime Environment 5.0 Update 2
"{3248F0A8-6813-11D6-A77B-00B0D0150040}" = J2SE Runtime Environment 5.0 Update 4
"{3248F0A8-6813-11D6-A77B-00B0D0150060}" = J2SE Runtime Environment 5.0 Update 6
"{3248F0A8-6813-11D6-A77B-00B0D0150090}" = J2SE Runtime Environment 5.0 Update 9
"{3248F0A8-6813-11D6-A77B-00B0D0150100}" = J2SE Runtime Environment 5.0 Update 10
"{3248F0A8-6813-11D6-A77B-00B0D0160010}" = Java™ SE Runtime Environment 6 Update 1
"{3248F0A8-6813-11D6-A77B-00B0D0160020}" = Java™ 6 Update 2
"{3248F0A8-6813-11D6-A77B-00B0D0160030}" = Java™ 6 Update 3
"{3248F0A8-6813-11D6-A77B-00B0D0160050}" = Java™ 6 Update 5
"{3248F0A8-6813-11D6-A77B-00B0D0160070}" = Java™ 6 Update 7
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{35F768BD-330E-4A2C-89C5-A38B588AF08D}" = Canon PIXMA iP6000D Memory Card Utility
"{369B36BE-3D64-4641-9AEA-808D436FE132}" = Microsoft Picture It! Photo 7.0
"{3868A8EE-5051-4DB0-8DF6-4F4B8A98D083}" = QuickTime
"{3F92ABBB-6BBF-11D5-B229-002078017FBF}" = Dell Modem-On-Hold
"{43FCA273-9534-40DB-B7C5-D7758875616A}" = Dell Support
"{468190DA-FB4C-45BA-8E40-4B165FF1A939}" = BACS
"{47D3687E-1586-475F-8188-CE87CD0A03ED}" = Brother HL-2040
"{64116298-93C5-401D-B06C-39D8E3338508}" = DAO
"{7148F0A8-6813-11D6-A77B-00B0D0142060}" = Java 2 Runtime Environment, SE v1.4.2_06
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{764D06D8-D8DE-411E-A1C8-D9E9380F8A84}" = Microsoft Works 7.0
"{7B63B2922B174135AFC0E1377DD81EC2}" = DivX
"{7EE9DE0D-9228-4C33-B80E-FDD1773600DF}" = Microsoft Works Suite Add-in for Microsoft Word
"{7EFA5E6F-74F7-4AFB-8AEA-AA790BD3A76D}" = DellSupport
"{7F142D56-3326-11D5-B229-002078017FBF}" = Modem Helper
"{84834762-4259-4213-8EE3-91481F05BC19}" = Web Camera Control
"{8ADFC4160D694100B5B8A22DE9DCABD9}" = DivX Player
"{90D55A3F-1D99-4C94-A77E-46DC14F0BF08}" = Help and Support Customization
"{911B0409-6000-11D3-8CFE-0050048383C9}" = Microsoft Word 2002
"{949DBB22-2FB7-4de1-804C-23D495A988D8}" = CuteFTP 8 Home
"{98DF85D9-96C0-4F57-A92E-C3539477EF5E}" = DVDSentry
"{98E8A2EF-4EAE-43B8-A172-74842B764777}" = InterVideo WinDVD
"{9F72EF8B-AEC9-4CA5-B483-143980AFD6FD}" = ALPS Touch Pad Driver
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{A9DFC08E-0256-4F90-A547-FA69A4CB1D3E}" = SpeedUpMyPC
"{AC76BA86-7AD7-1033-7B44-A70000000000}" = Adobe Reader 7.0.7
"{B4092C6D-E886-4CB2-BA68-FE5A88D31DE6}_is1" = Spybot - Search & Destroy
"{B43357AA-3A6D-4D94-B56E-43C44D09E548}" = Microsoft .NET Framework (English)
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{C3ABE126-2BB2-4246-BFE1-6797679B3579}" = LG USB Modem driver
"{C5074CC4-0E26-4716-A307-960272A90040}" = QuickSet
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{D64DCF1C-7A95-49A4-BAFA-C42B5CF6B8B6}" = Works Suite OS Pack
"{D6DE02C7-1F47-11D4-9515-00105AE4B89A}" = Paint Shop Pro 7
"{D958FAC4-BAE0-4B1D-A42E-DE9BFDE7DDEE}" = Canon PhotoRecord
"{E3BFEE55-39E2-4BE0-B966-89FE583822C1}" = Dell Support Center (Support Software)
"{FA61D601-A0FC-48BD-AE7A-54946BCD7FB6}_is1" = BitPim 1.0.5
"Adobe Atmosphere Player" = Adobe Atmosphere Player for Acrobat and Adobe Reader
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Shockwave Player" = Adobe Shockwave Player 11
"All ATI Software" = ATI - Software Uninstall Utility
"ATI Display Driver" = ATI Display Driver
"AVG8Uninstall" = AVG Free 8.5
"Banner Maker Pro 7_is1" = Banner Maker Pro Version 7
"Canon PhotoStitch 3.1" = Canon Utilities PhotoStitch 3.1
"CANONBJ_Deinstall_CNMCP69.DLL" = Canon PIXMA iP6000D
"Easy-PhotoPrint" = Canon Utilities Easy-PhotoPrint
"EVEREST Home Edition_is1" = EVEREST Home Edition v2.20
"GoogleVideoPlayer" = Google Video Player
"HijackThis" = HijackThis 2.0.2
"IDNMitigationAPIs" = Microsoft Internationalized Domain Names Mitigation APIs
"ie7" = Windows Internet Explorer 7
"ie8" = Windows Internet Explorer 8
"Image Composer" = Microsoft Image Composer 1.5
"Installing HSP56 MicroModem Drivers" = PCTEL 2304WT V.92 MDC Modem Drivers
"InstallShield_{3868A8EE-5051-4DB0-8DF6-4F4B8A98D083}" = QuickTime
"InstallShield_{468190DA-FB4C-45BA-8E40-4B165FF1A939}" = Broadcom Advanced Control Suite
"LG USB Drivers" = LG USB Drivers
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"MemoKit" = MemoKit
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Microsoft .NET Framework Full v1.0.3705 (1033)" = Microsoft .NET Framework (English) v1.0.3705
"MicrosoftWordMTWLingo" = Translation Services Provided by WorldLingo for Microsoft Word
"MOBv2.1" = MOBv2.1
"MSCompPackV1" = Microsoft Compression Client Pack 1.0 for Windows XP
"MSN Music Assistant" = MSN Music Assistant
"MSPUB4" = Microsoft Publisher 97
"NLSDownlevelMapping" = Microsoft National Language Support Downlevel APIs
"RealPlayer 6.0" = RealOne Player
"Registry Booster_is1" = Uniblue Registry Booster
"RemoteCapture" = Canon Utilities RemoteCapture 2.2
"Shockwave" = Shockwave
"SimSafariUninstall" = SimSafari
"SlimBrowser" = SlimBrowser (remove only)
"Spybot - Search & Destroy_is1" = Spybot - Search & Destroy 1.5.2.20
"Spyware Terminator_is1" = Spyware Terminator
"Verizon FiOS Activation_is1" = Verizon FiOS Activation
"Viewpoint Manager" = Viewpoint Manager (Remove Only)
"ViewpointMediaPlayer" = Viewpoint Media Player
"Webshots Desktop" = Webshots Desktop
"Wild Things! by Wild Ginger Software, Inc." = Wild Things! by Wild Ginger Software, Inc.
"Windows Media Format Runtime" = Windows Media Format 11 runtime
"Windows Media Player" = Windows Media Player 11
"Windows XP Service Pack" = Windows XP Service Pack 3
"WMFDist11" = Windows Media Format 11 runtime
"wmp11" = Windows Media Player 11
"Works2003Setup" = Microsoft Works 2003 Setup Launcher
"Wudf01000" = Microsoft User-Mode Driver Framework Feature Pack 1.0
"ZoomBrowserEXDeInstall" = Canon Utilities ZoomBrowser EX

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"AI RoboForm" = AI RoboForm
"Move Networks Player - IE" = Move Networks Media Player for Internet Explorer

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 2/26/2010 11:53:32 AM | Computer Name = OFFICE | Source = MsiInstaller | ID = 11706
Description = Product: Microsoft Office 2000 Premium – Error 1706. No valid source
could be found for product Microsoft Office 2000 Premium. The Windows installer
cannot continue.

Error - 2/26/2010 1:12:05 PM | Computer Name = OFFICE | Source = MsiInstaller | ID = 11706
Description = Product: Microsoft Office 2000 Premium – Error 1706. No valid source
could be found for product Microsoft Office 2000 Premium. The Windows installer
cannot continue.

Error - 2/26/2010 1:13:06 PM | Computer Name = OFFICE | Source = MsiInstaller | ID = 11706
Description = Product: Microsoft Office 2000 Premium – Error 1706. No valid source
could be found for product Microsoft Office 2000 Premium. The Windows installer
cannot continue.

Error - 2/26/2010 5:11:08 PM | Computer Name = OFFICE | Source = MsiInstaller | ID = 11706
Description = Product: Microsoft Office 2000 Premium – Error 1706. No valid source
could be found for product Microsoft Office 2000 Premium. The Windows installer
cannot continue.

Error - 2/26/2010 6:11:10 PM | Computer Name = OFFICE | Source = MsiInstaller | ID = 11706
Description = Product: Microsoft Office 2000 Premium – Error 1706. No valid source
could be found for product Microsoft Office 2000 Premium. The Windows installer
cannot continue.

Error - 2/26/2010 6:38:24 PM | Computer Name = OFFICE | Source = MsiInstaller | ID = 11706
Description = Product: Microsoft Office 2000 Premium – Error 1706. No valid source
could be found for product Microsoft Office 2000 Premium. The Windows installer
cannot continue.

Error - 2/26/2010 9:05:19 PM | Computer Name = OFFICE | Source = Application Hang | ID = 1002
Description = Hanging application explorer.exe, version 6.0.2900.5512, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.

Error - 2/27/2010 7:57:24 AM | Computer Name = OFFICE | Source = Application Error | ID = 1000
Description = Faulting application , version 0.0.0.0, faulting module unknown, version
0.0.0.0, fault address 0x10052cad.

Error - 2/28/2010 2:50:55 AM | Computer Name = OFFICE | Source = Application Hang | ID = 1002
Description = Hanging application msimn.exe, version 6.0.2900.5512, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.

Error - 2/28/2010 2:51:01 AM | Computer Name = OFFICE | Source = Application Hang | ID = 1002
Description = Hanging application msimn.exe, version 6.0.2900.5512, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.

[ System Events ]
Error - 2/28/2010 9:22:00 AM | Computer Name = OFFICE | Source = Service Control Manager | ID = 7000
Description = The Spyware Terminator Realtime Shield Service service failed to start
due to the following error: %%1053

Error - 2/28/2010 9:22:00 AM | Computer Name = OFFICE | Source = Service Control Manager | ID = 7000
Description = The WinDriver service failed to start due to the following error:
%%2

Error - 2/28/2010 9:24:31 AM | Computer Name = OFFICE | Source = DCOM | ID = 10010
Description = The server {0002DF01-0000-0000-C000-000000000046} did not register
with DCOM within the required timeout.

Error - 2/28/2010 9:26:44 AM | Computer Name = OFFICE | Source = Service Control Manager | ID = 7009
Description = Timeout (30000 milliseconds) waiting for the IMAPI CD-Burning COM
Service service to connect.

Error - 2/28/2010 9:26:44 AM | Computer Name = OFFICE | Source = Service Control Manager | ID = 7000
Description = The IMAPI CD-Burning COM Service service failed to start due to the
following error: %%1053

Error - 2/28/2010 9:30:22 AM | Computer Name = OFFICE | Source = DCOM | ID = 10010
Description = The server {0002DF01-0000-0000-C000-000000000046} did not register
with DCOM within the required timeout.

Error - 2/28/2010 10:24:43 AM | Computer Name = OFFICE | Source = DCOM | ID = 10010
Description = The server {0002DF01-0000-0000-C000-000000000046} did not register
with DCOM within the required timeout.

Error - 2/28/2010 10:30:01 AM | Computer Name = OFFICE | Source = DCOM | ID = 10010
Description = The server {0002DF01-0000-0000-C000-000000000046} did not register
with DCOM within the required timeout.

Error - 2/28/2010 11:25:05 AM | Computer Name = OFFICE | Source = DCOM | ID = 10010
Description = The server {0002DF01-0000-0000-C000-000000000046} did not register
with DCOM within the required timeout.

Error - 2/28/2010 11:30:19 AM | Computer Name = OFFICE | Source = DCOM | ID = 10010
Description = The server {0002DF01-0000-0000-C000-000000000046} did not register
with DCOM within the required timeout.


< End of report >
Hi sagiter,

Let's clean some of this up and see if we can get safe mode to work.

First you have a program we need disabled. Please leave it disabled until we are done.

SPYBOT TEATIMER
  • Launch Spybot S&D, go to the Mode menu and make sure "Advanced Mode" is selected.
  • On the left hand side, click on Tools, then click on the Resident Icon in the list.
  • Uncheck the "Resident "TeaTimer" (Protection of overall system settings) active." box.
  • Click on the "System Startup" icon in the List
  • Uncheck the "TeaTimer" box and "OK" any prompts.
  • If Teatimer gives you a warning that changes were made, click the "Allow Change" box when prompted.
  • Exit Spybot S&D when done and reboot your computer.
    (When we are done, you can re-enable Teatimer using the same steps but this time place a check next to "Resident TeaTimer" and check the "TeaTimer" box in System Startup.]

Next, Double click on OTL.exe
  • Under the Custom Scans/Fixes box at the bottom, paste in the following
  • Do Not copy the word CODE
  • please note the fix starts with the :
:Services
:OTL
O4 - HKLM..\Run: [yokowijer] C:\WINDOWS\System32\majudusu.DLL File not found
O20 - AppInit_DLLs: (c:\windows\system32\doyoginu.dll) - C:\WINDOWS\System32\doyoginu.dll File not found
O20 - AppInit_DLLs: (kayukore.dll) - File not found
O20 - AppInit_DLLs: (c:\windows\system32\suwefosa.dll) - C:\WINDOWS\System32\suwefosa.dll File not found
O20 - AppInit_DLLs: (c:\windows\system32\majudusu.dll) - C:\WINDOWS\System32\majudusu.dll File not found
O21 - SSODL: dirimeyib - {25ced2a1-dc24-4e14-af92-baf48451c48a} - C:\WINDOWS\System32\majudusu.dll File not found
O21 - SSODL: pasikulos - {52d38f86-216b-4bcd-ac83-f951b152cedd} - C:\WINDOWS\System32\doyoginu.dll File not found
O21 - SSODL: pukujayug - {a8969e8d-de4e-457a-ba43-5955702f6c82} - C:\WINDOWS\System32\suwefosa.dll File not found
O22 - SharedTaskScheduler: {25ced2a1-dc24-4e14-af92-baf48451c48a} - gahurihor - C:\WINDOWS\System32\majudusu.dll File not found
O22 - SharedTaskScheduler: {52d38f86-216b-4bcd-ac83-f951b152cedd} - tokatiluy - C:\WINDOWS\System32\doyoginu.dll File not found
O22 - SharedTaskScheduler: {a8969e8d-de4e-457a-ba43-5955702f6c82} - kupuhivus - C:\WINDOWS\System32\suwefosa.dll File not found
[2099/01/01 12:00:00 | 000,097,280 | -HS- | M] () – C:\WINDOWS\System32\dusukaga.dll
[2099/01/01 12:00:00 | 000,096,768 | -HS- | M] () – C:\WINDOWS\System32\duyesedi.dll
[2099/01/01 12:00:00 | 000,061,440 | -HS- | M] () – C:\WINDOWS\System32\vagiwara.dll
[2099/01/01 12:00:00 | 000,061,440 | -HS- | M] () – C:\WINDOWS\System32\judopuje.dll
[2099/01/01 12:00:00 | 000,061,440 | -HS- | M] () – C:\WINDOWS\System32\himesuvo.dll
[2099/01/01 12:00:00 | 000,047,616 | -HS- | M] () – C:\WINDOWS\System32\zobubabe.dll
[2099/01/01 12:00:00 | 000,047,616 | -HS- | M] () – C:\WINDOWS\System32\tipilifi.dll
[2099/01/01 12:00:00 | 000,047,616 | -HS- | M] () – C:\WINDOWS\System32\tipifipo.dll
[2099/01/01 12:00:00 | 000,047,616 | -HS- | M] () – C:\WINDOWS\System32\lewabenu.dll
[2099/01/01 12:00:00 | 000,047,616 | -HS- | M] () – C:\WINDOWS\System32\hutijezu.dll
[2099/01/01 12:00:00 | 000,047,104 | -HS- | M] () – C:\WINDOWS\System32\woheluba.dll
[2099/01/01 12:00:00 | 000,047,104 | -HS- | M] () – C:\WINDOWS\System32\dazuyelu.dll
[2099/01/01 12:00:00 | 000,043,520 | -HS- | M] () – C:\WINDOWS\System32\wayofuge.dll
[2099/01/01 12:00:00 | 000,043,520 | -HS- | M] () – C:\WINDOWS\System32\gifeleho.dll
[2099/01/01 12:00:00 | 000,043,008 | -HS- | M] () – C:\WINDOWS\System32\zugoyepi.dll
[2010/02/28 09:00:10 | 000,000,296 | —- | M] () – C:\WINDOWS\tasks\oqqaesob.job
[2099/01/01 12:00:00 | 000,006,456 | -H– | C] () – C:\WINDOWS\System32\komobome

:Commands
[createrestorepoint]
[emptytemp]
[Reboot]

Then click the Run Fix button at the top
  • Let the program run unhindered
  • Please save the resulting log to be posted in your next reply.



Download the attached file user.zip to your desktop.

📎user.zip

Extract the contents to your desktop. You should now have a file called SafeBoot-for-Windows-XP-SP3.reg with an icon like this [external image: Posted Image]

Right click the file and select merge. Click yes to confirm.

Try booting into safe mode and see if GMER will run.

Please post back with
  • OTL fix log
  • GMER log
  • new OTL log taken after all other steps. There will only be a OTL.txt this time
How's the computer?

Thanks
I couldn't get the computer into Safe Mode. I have two issues that is causing this. One is that I don't get a beep when I start the computer so I have no prompt to hit F8. The second is that the laptop is being used as a desktop computer because the screen is dead and the external monitor doesn't start up until the windows screen.

Anyway I tried to run GMER after the OTL fix overnight but I think it crashed at one point or another, I attached whatever log it produced.

The computer is running a bit faster but I still got the AVG pop-ups during the OTL scan and the google search is still redirected.

OTL fix:

All processes killed
========== SERVICES/DRIVERS ==========
========== OTL ==========
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\yokowijer deleted successfully.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\\AppInit_Dlls:c:\windows\system32\doyoginu.dll deleted successfully.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\\AppInit_Dlls:kayukore.dll deleted successfully.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\\AppInit_Dlls:c:\windows\system32\suwefosa.dll deleted successfully.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\\AppInit_Dlls:c:\windows\system32\majudusu.dll deleted successfully.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\\dirimeyib deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{25ced2a1-dc24-4e14-af92-baf48451c48a}\ deleted successfully.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\\pasikulos deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{52d38f86-216b-4bcd-ac83-f951b152cedd}\ deleted successfully.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\\pukujayug deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{a8969e8d-de4e-457a-ba43-5955702f6c82}\ deleted successfully.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler\\{25ced2a1-dc24-4e14-af92-baf48451c48a} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{25ced2a1-dc24-4e14-af92-baf48451c48a}\ not found.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler\\{52d38f86-216b-4bcd-ac83-f951b152cedd} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{52d38f86-216b-4bcd-ac83-f951b152cedd}\ not found.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler\\{a8969e8d-de4e-457a-ba43-5955702f6c82} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{a8969e8d-de4e-457a-ba43-5955702f6c82}\ not found.
C:\WINDOWS\SYSTEM32\dusukaga.dll moved successfully.
C:\WINDOWS\SYSTEM32\duyesedi.dll moved successfully.
C:\WINDOWS\SYSTEM32\vagiwara.dll moved successfully.
C:\WINDOWS\SYSTEM32\judopuje.dll moved successfully.
C:\WINDOWS\SYSTEM32\himesuvo.dll moved successfully.
C:\WINDOWS\SYSTEM32\zobubabe.dll moved successfully.
C:\WINDOWS\SYSTEM32\tipilifi.dll moved successfully.
C:\WINDOWS\SYSTEM32\tipifipo.dll moved successfully.
C:\WINDOWS\SYSTEM32\lewabenu.dll moved successfully.
C:\WINDOWS\SYSTEM32\hutijezu.dll moved successfully.
C:\WINDOWS\SYSTEM32\woheluba.dll moved successfully.
C:\WINDOWS\SYSTEM32\dazuyelu.dll moved successfully.
C:\WINDOWS\SYSTEM32\wayofuge.dll moved successfully.
C:\WINDOWS\SYSTEM32\gifeleho.dll moved successfully.
C:\WINDOWS\SYSTEM32\zugoyepi.dll moved successfully.
C:\WINDOWS\tasks\oqqaesob.job moved successfully.
C:\WINDOWS\SYSTEM32\komobome moved successfully.
========== COMMANDS ==========
Restore point Set: OTL Restore Point (64424509440)

[EMPTYTEMP]

User: All Users

User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes

User: LocalService
->Temp folder emptied: 66016 bytes
->Temporary Internet Files folder emptied: 4418906 bytes

User: Neil
->Temp folder emptied: 118933282 bytes
->Temporary Internet Files folder emptied: 538293536 bytes
->Java cache emptied: 39913704 bytes

User: NetworkService
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 1538591 bytes

%systemdrive% .tmp files removed: 4749766 bytes
%systemroot% .tmp files removed: 46401 bytes
%systemroot%\System32 .tmp files removed: 2574079 bytes
%systemroot%\System32\dllcache .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 3281348 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 23946294 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 2270420 bytes
RecycleBin emptied: 2757952 bytes

Total Files Cleaned = 708.00 mb


OTL by OldTimer - Version 3.1.30.3 log created on 02282010_230144

Files\Folders moved on Reboot…

Registry entries deleted on Reboot…

GMER:

GMER 1.0.15.15281 - http://www.gmer.net
Rootkit scan 2010-03-01 06:42:49
Windows 5.1.2600 Service Pack 3
Running: v8vqkne5.exe; Driver: C:\DOCUME~1\Neil\LOCALS~1\Temp\pwtdapod.sys


—- Devices - GMER 1.0.15 —-

AttachedDevice \Driver\Tcpip \Device\Ip avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
AttachedDevice \Driver\Tcpip \Device\Tcp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
AttachedDevice \Driver\Tcpip \Device\Udp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
AttachedDevice \Driver\Tcpip \Device\RawIp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)

Device \FileSystem\Fastfat \Fat B3779D20

AttachedDevice \FileSystem\Fastfat \Fat fltmgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)

Device -> \Driver\atapi \Device\Harddisk0\DR0 826C6A9A

—- Files - GMER 1.0.15 —-

File C:\WINDOWS\system32\drivers\atapi.sys suspicious modification

—- EOF - GMER 1.0.15 —-


OTL Scan:

OTL logfile created on: 3/1/2010 7:12:50 AM - Run 2
OTL by OldTimer - Version 3.1.30.3 Folder = C:\Documents and Settings\Neil\Desktop
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

255.00 Mb Total Physical Memory | 79.00 Mb Available Physical Memory | 31.00% Memory free
618.00 Mb Paging File | 253.00 Mb Available in Paging File | 41.00% Paging File free
Paging file location(s): C:\pagefile.sys 384 768 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 37.22 Gb Total Space | 16.77 Gb Free Space | 45.05% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: OFFICE
Current User Name: Neil
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal

========== Processes (SafeList) ==========

PRC - C:\Documents and Settings\Neil\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe (Siber Systems)
PRC - C:\Program Files\AVG\AVG8\avgtray.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\Java\jre6\bin\jqs.exe (Sun Microsystems, Inc.)
PRC - C:\Program Files\Java\jre6\bin\jusched.exe (Sun Microsystems, Inc.)
PRC - C:\Program Files\AVG\AVG8\avgrsx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG8\avgcsrvx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG8\avgnsx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG8\avgemc.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG8\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\Common Files\Motive\McciCMService.exe (Motive Communications, Inc.)
PRC - C:\Program Files\Dell Support Center\bin\sprtcmd.exe (SupportSoft, Inc.)
PRC - C:\Program Files\Dell Support Center\bin\sprtsvc.exe (SupportSoft, Inc.)
PRC - C:\Program Files\Spyware Terminator\sp_rsser.exe (Crawler.com)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\QuickTime\qttask.exe (Apple Computer, Inc.)
PRC - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe (Adobe Systems Incorporated)
PRC - C:\Program Files\MemoKit\MemoKit2.exe (Software Benefits Inc.)
PRC - C:\Program Files\Canon\Memory Card Utility\PIXMA iP6000D\PDUiP6000DMon.exe (CANON INC.)
PRC - C:\Program Files\Canon\Memory Card Utility\PIXMA iP6000D\PDUiP6000DTskbr.exe (CANON INC.)
PRC - C:\Program Files\Canon\Memory Card Utility\PIXMA iP6000D\PDUiP6000DMemCrdMgr.exe (CANON INC.)
PRC - C:\WINDOWS\webshots.scr (Webshots.com)
PRC - C:\WINDOWS\SYSTEM32\ati2evxx.exe ()
PRC - C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe (ATI Technologies, Inc.)
PRC - C:\Program Files\Common Files\Real\Update_OB\realsched.exe (RealNetworks, Inc.)
PRC - C:\Program Files\Dell\QuickSet\quickset.exe ()
PRC - C:\WINDOWS\SYSTEM32\CIDAEMON.EXE (Microsoft Corporation)
PRC - C:\Program Files\Apoint\Apoint.exe (Alps Electric Co., Ltd.)
PRC - C:\WINDOWS\SYSTEM32\DSentry.exe (Dell - Advanced Desktop Engineering)
PRC - C:\Program Files\Apoint\ApntEx.exe (Alps Electric Co., Ltd.)
PRC - C:\ImageMate CompactFlash USB\SandIcon.exe ()
PRC - C:\WINDOWS\SYSTEM32\Crypserv.exe (Kenonic Controls Ltd.)
PRC - C:\Program Files\Microsoft Office\Office\1033\MSOFFICE.EXE (Microsoft Corporation)


========== Modules (SafeList) ==========

MOD - C:\Documents and Settings\Neil\Desktop\OTL.exe (OldTimer Tools)


========== Win32 Services (SafeList) ==========

SRV - (JavaQuickStarterService) – C:\Program Files\Java\jre6\bin\jqs.exe (Sun Microsystems, Inc.)
SRV - (avg8emc) – C:\Program Files\AVG\AVG8\avgemc.exe (AVG Technologies CZ, s.r.o.)
SRV - (avg8wd) – C:\Program Files\AVG\AVG8\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
SRV - (McciCMService) – C:\Program Files\Common Files\Motive\McciCMService.exe (Motive Communications, Inc.)
SRV - (sprtsvc_dellsupportcenter) SupportSoft Sprocket Service (dellsupportcenter) – C:\Program Files\Dell Support Center\bin\sprtsvc.exe (SupportSoft, Inc.)
SRV - (sp_rssrv) – C:\Program Files\Spyware Terminator\sp_rsser.exe (Crawler.com)
SRV - (DSBrokerService) – C:\Program Files\DellSupport\brkrsvc.exe ()
SRV - (IDriverT) – C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe (Macrovision Corporation)
SRV - (PDUiP6000DMemCrdMgr) – C:\Program Files\Canon\Memory Card Utility\PIXMA iP6000D\PDUiP6000DMemCrdMgr.exe (CANON INC.)
SRV - (Ati HotKey Poller) – C:\WINDOWS\SYSTEM32\ati2evxx.exe ()
SRV - (Crypkey License) – C:\WINDOWS\System32\Crypserv.exe (Kenonic Controls Ltd.)


========== Driver Services (SafeList) ==========

DRV - (AvgMfx86) – C:\WINDOWS\System32\Drivers\avgmfx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (AvgLdx86) – C:\WINDOWS\System32\Drivers\avgldx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (AvgTdiX) – C:\WINDOWS\System32\Drivers\avgtdix.sys (AVG Technologies CZ, s.r.o.)
DRV - (usbaudio) USB Audio Driver (WDM) – C:\WINDOWS\SYSTEM32\DRIVERS\usbaudio.sys (Microsoft Corporation)
DRV - (amdagp) – C:\WINDOWS\System32\DRIVERS\amdagp.sys (Advanced Micro Devices, Inc.)
DRV - (sisagp) – C:\WINDOWS\System32\DRIVERS\sisagp.sys (Silicon Integrated Systems Corporation)
DRV - (Secdrv) – C:\WINDOWS\SYSTEM32\DRIVERS\secdrv.sys (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.)
DRV - (MRENDIS5) – C:\Program Files\Common Files\Motive\MRENDIS5.sys (Motive, Inc.)
DRV - (MREMPR5) – C:\Program Files\Common Files\Motive\MREMPR5.sys (Motive, Inc.)
DRV - (dsunidrv) – C:\WINDOWS\SYSTEM32\DRIVERS\dsunidrv.sys (Gteko Ltd.)
DRV - (DSproct) – C:\Program Files\DellSupport\GTAction\triggers\DSproct.sys (Gteko Ltd.)
DRV - (USBModem) – C:\WINDOWS\SYSTEM32\DRIVERS\lgusbmodem.sys (LG Electronics Inc.)
DRV - (UsbDiag) – C:\WINDOWS\SYSTEM32\DRIVERS\lgusbdiag.sys (LG Electronics Inc.)
DRV - (usbbus) – C:\WINDOWS\SYSTEM32\DRIVERS\lgusbbus.sys (LG Electronics Inc.)
DRV - (GEARAspiWDM) – C:\WINDOWS\SYSTEM32\DRIVERS\GEARAspiWDM.sys (GEAR Software Inc.)
DRV - (nv) – C:\WINDOWS\SYSTEM32\DRIVERS\nv4_mini.sys (NVIDIA Corporation)
DRV - (iAimFP4) – C:\WINDOWS\SYSTEM32\DRIVERS\wvchntxx.sys (Intel® Corporation)
DRV - (iAimFP3) – C:\WINDOWS\SYSTEM32\DRIVERS\wsiintxx.sys (Intel® Corporation)
DRV - (iAimTV4) – C:\WINDOWS\SYSTEM32\DRIVERS\wch7xxnt.sys (Intel® Corporation)
DRV - (iAimTV3) – C:\WINDOWS\SYSTEM32\DRIVERS\watv04nt.sys (Intel® Corporation)
DRV - (iAimTV1) – C:\WINDOWS\SYSTEM32\DRIVERS\watv02nt.sys (Intel® Corporation)
DRV - (iAimTV0) – C:\WINDOWS\SYSTEM32\DRIVERS\watv01nt.sys (Intel® Corporation)
DRV - (iAimFP0) – C:\WINDOWS\SYSTEM32\DRIVERS\wadv01nt.sys (Intel® Corporation)
DRV - (iAimFP1) – C:\WINDOWS\SYSTEM32\DRIVERS\wadv02nt.sys (Intel® Corporation)
DRV - (iAimFP2) – C:\WINDOWS\SYSTEM32\DRIVERS\wadv05nt.sys (Intel® Corporation)
DRV - (i81x) – C:\WINDOWS\SYSTEM32\DRIVERS\i81xnt5.sys (Intel® Corporation)
DRV - (ati2mtag) – C:\WINDOWS\SYSTEM32\DRIVERS\ati2mtag.sys (ATI Technologies Inc.)
DRV - (STAC97) Audio Driver (WDM) – C:\WINDOWS\SYSTEM32\DRIVERS\STAC97.sys (SigmaTel, Inc.)
DRV - (ApfiltrService) – C:\WINDOWS\SYSTEM32\DRIVERS\Apfiltr.sys (Alps Electric Co., Ltd.)
DRV - (omci) – C:\WINDOWS\SYSTEM32\DRIVERS\omci.sys (Dell Computer Corporation)
DRV - (bcm4sbxp) – C:\WINDOWS\SYSTEM32\DRIVERS\bcm4sbxp.sys (Broadcom Corporation)
DRV - (BCM43XX) – C:\WINDOWS\SYSTEM32\DRIVERS\LSBCMNDS.SYS (The Linksys Group, Inc.)
DRV - (Vpctcom) – C:\WINDOWS\System32\DRIVERS\vpctcom.sys (PCtel, Inc.)
DRV - (Ptserial) – C:\WINDOWS\SYSTEM32\DRIVERS\ptserial.sys (PCTEL, INC.)
DRV - (Vvoice) – C:\WINDOWS\System32\DRIVERS\vvoice.sys (PCtel, Inc.)
DRV - (Vmodem) – C:\WINDOWS\System32\DRIVERS\vmodem.sys (PCTEL, INC.)
DRV - (Ptilink) – C:\WINDOWS\SYSTEM32\DRIVERS\PTILINK.SYS (Parallel Technologies, Inc.)
DRV - (AloPar) – C:\WINDOWS\SYSTEM32\DRIVERS\AloPar.sys (Eisenworld, Inc.)
DRV - (Sparrow) – C:\WINDOWS\System32\DRIVERS\sparrow.sys (Adaptec, Inc.)
DRV - (sym_u3) – C:\WINDOWS\System32\DRIVERS\sym_u3.sys (LSI Logic)
DRV - (sym_hi) – C:\WINDOWS\System32\DRIVERS\sym_hi.sys (LSI Logic)
DRV - (symc8xx) – C:\WINDOWS\System32\DRIVERS\symc8xx.sys (LSI Logic)
DRV - (symc810) – C:\WINDOWS\System32\DRIVERS\symc810.sys (Symbios Logic Inc.)
DRV - (ultra) – C:\WINDOWS\System32\DRIVERS\ultra.sys (Promise Technology, Inc.)
DRV - (ql12160) – C:\WINDOWS\System32\DRIVERS\ql12160.sys (QLogic Corporation)
DRV - (ql1080) – C:\WINDOWS\System32\DRIVERS\ql1080.sys (QLogic Corporation)
DRV - (ql1280) – C:\WINDOWS\System32\DRIVERS\ql1280.sys (QLogic Corporation)
DRV - (dac2w2k) – C:\WINDOWS\System32\DRIVERS\dac2w2k.sys (Mylex Corporation)
DRV - (mraid35x) – C:\WINDOWS\System32\DRIVERS\mraid35x.sys (American Megatrends Inc.)
DRV - (asc) – C:\WINDOWS\System32\DRIVERS\asc.sys (Advanced System Products, Inc.)
DRV - (asc3550) – C:\WINDOWS\System32\DRIVERS\asc3550.sys (Advanced System Products, Inc.)
DRV - (AliIde) – C:\WINDOWS\System32\DRIVERS\aliide.sys (Acer Laboratories Inc.)
DRV - (CmdIde) – C:\WINDOWS\System32\DRIVERS\cmdide.sys (CMD Technology, Inc.)
DRV - (EL90XBC) – C:\WINDOWS\SYSTEM32\DRIVERS\EL90XBC5.SYS (3Com Corporation)
DRV - (BrPar) – C:\WINDOWS\System32\drivers\BrPar.sys (Brother Industries Ltd.)
DRV - (NetworkX) – C:\WINDOWS\system32\ckldrv.sys ()


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,StartPage = http://www.optonline.net
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.optonline.net
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultName = Google
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultURL = http://www.google.com/search?q={searchTerm…tf8&oe=utf8
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.smokinholsters.com/
IE - HKCU\..\URLSearchHook: *{CFBFAE00-17A6-11D0-99CB-00C04FD64497} - Reg Error: Key error. File not found
IE - HKCU\..\URLSearchHook: {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG8\Toolbar\IEToolbar.dll ()
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0


[2004/07/04 22:38:45 | 000,000,000 | —D | M] – C:\Documents and Settings\Neil\Application Data\Mozilla\Firefox\Profiles\default.exe\extensions
[2004/07/04 22:38:45 | 000,000,000 | —D | M] (DOM Inspector) – C:\Documents and Settings\Neil\Application Data\Mozilla\Firefox\Profiles\default.exe\extensions\{641d8d09-7dda-4850-8228-ac0ab65e2ac9}
[2004/07/04 22:38:45 | 000,000,000 | —D | M] (Firefox (default)) – C:\Documents and Settings\Neil\Application Data\Mozilla\Firefox\Profiles\default.exe\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}

O1 HOSTS File: ([2008/10/14 09:11:00 | 000,266,850 | R— | M]) - C:\WINDOWS\SYSTEM32\DRIVERS\ETC\HOSTS
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: 127.0.0.1 www.007guard.com
O1 - Hosts: 127.0.0.1 007guard.com
O1 - Hosts: 127.0.0.1 008i.com
O1 - Hosts: 127.0.0.1 www.008k.com
O1 - Hosts: 127.0.0.1 008k.com
O1 - Hosts: 127.0.0.1 www.00hq.com
O1 - Hosts: 127.0.0.1 00hq.com
O1 - Hosts: 127.0.0.1 010402.com
O1 - Hosts: 127.0.0.1 www.032439.com
O1 - Hosts: 127.0.0.1 032439.com
O1 - Hosts: 127.0.0.1 www.100888290cs.com
O1 - Hosts: 127.0.0.1 100888290cs.com
O1 - Hosts: 127.0.0.1 www.100sexlinks.com
O1 - Hosts: 127.0.0.1 100sexlinks.com
O1 - Hosts: 127.0.0.1 www.10sek.com
O1 - Hosts: 127.0.0.1 10sek.com
O1 - Hosts: 127.0.0.1 www.123topsearch.com
O1 - Hosts: 127.0.0.1 123topsearch.com
O1 - Hosts: 127.0.0.1 www.132.com
O1 - Hosts: 127.0.0.1 132.com
O1 - Hosts: 127.0.0.1 www.136136.net
O1 - Hosts: 127.0.0.1 136136.net
O1 - Hosts: 127.0.0.1 www.163ns.com
O1 - Hosts: 127.0.0.1 163ns.com
O1 - Hosts: 9243 more lines…
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (no name) - {243B17DE-77C7-46BF-B94B-0B5F309A0E64} - C:\Program Files\Microsoft Money\System\mnyside.dll (Microsoft Corporation)
O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll (AVG Technologies CZ, s.r.o.)
O2 - BHO: (Spybot-S&D IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O2 - BHO: (no name) - {724d43a9-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\RoboForm.dll (Siber Systems Inc.)
O2 - BHO: (AVG Security Toolbar BHO) - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG8\Toolbar\IEToolbar.dll ()
O2 - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (JQSIEStartDetectorImpl Class) - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll (Sun Microsystems, Inc.)
O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - No CLSID value found.
O3 - HKLM\..\Toolbar: (&RoboForm) - {724d43a0-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\RoboForm.dll (Siber Systems Inc.)
O3 - HKLM\..\Toolbar: (AVG Security Toolbar) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - C:\Program Files\AVG\AVG8\Toolbar\IEToolbar.dll ()
O3 - HKCU\..\Toolbar\ShellBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {4B3803EA-5230-4DC3-A7FC-33638F3D3542} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (&RoboForm) - {724D43A0-0D85-11D4-9908-00400523E39A} - C:\Program Files\Siber Systems\AI RoboForm\RoboForm.dll (Siber Systems Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (AVG Security Toolbar) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - C:\Program Files\AVG\AVG8\Toolbar\IEToolbar.dll ()
O4 - HKLM..\Run: [Apoint] C:\Program Files\Apoint\Apoint.exe (Alps Electric Co., Ltd.)
O4 - HKLM..\Run: [ATIModeChange] C:\WINDOWS\System32\Ati2mdxx.exe (ATI Technologies, Inc.)
O4 - HKLM..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe (ATI Technologies, Inc.)
O4 - HKLM..\Run: [AVG8_TRAY] C:\Program Files\AVG\AVG8\avgtray.exe (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [Dell QuickSet] C:\Program Files\Dell\QuickSet\quickset.exe ()
O4 - HKLM..\Run: [dellsupportcenter] C:\Program Files\Dell Support Center\bin\sprtcmd.exe (SupportSoft, Inc.)
O4 - HKLM..\Run: [dscactivate] C:\Program Files\Dell Support Center\gs_agent\custom\dsca.exe ( )
O4 - HKLM..\Run: [DVDSentry] C:\WINDOWS\SYSTEM32\DSentry.exe (Dell - Advanced Desktop Engineering)
O4 - HKLM..\Run: [PDUiP6000DMon] C:\Program Files\Canon\Memory Card Utility\PIXMA iP6000D\PDUiP6000DMon.exe (CANON INC.)
O4 - HKLM..\Run: [PDUiP6000DTskbr] C:\Program Files\Canon\Memory Card Utility\PIXMA iP6000D\PDUiP6000DTskbr.exe (CANON INC.)
O4 - HKLM..\Run: [QuickTime Task] C:\Program Files\QuickTime\qttask.exe (Apple Computer, Inc.)
O4 - HKLM..\Run: [SandIcon] C:\ImageMate CompactFlash USB\SandIcon.exe ()
O4 - HKLM..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre6\bin\jusched.exe (Sun Microsystems, Inc.)
O4 - HKLM..\Run: [TkBellExe] C:\Program Files\Common Files\Real\Update_OB\realsched.exe (RealNetworks, Inc.)
O4 - HKLM..\Run: [Verizon_McciTrayApp] C:\Program Files\Verizon\McciTrayApp.exe File not found
O4 - HKCU..\Run: [DellSupportCenter] C:\Program Files\Dell Support Center\bin\sprtcmd.exe (SupportSoft, Inc.)
O4 - HKCU..\Run: [RoboForm] C:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe (Siber Systems)
O4 - HKCU..\Run: [Uniblue Registry Booster] C:\Program Files\Uniblue\Registry Booster\RegistryBooster.exe (Uniblue Registry Booster)
O4 - HKCU..\Run: [updateMgr] C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe (Adobe Systems Incorporated)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe (Adobe Systems Incorporated)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE (Microsoft Corporation)
O4 - Startup: C:\Documents and Settings\Neil\Start Menu\Programs\Startup\MemoKit.lnk = C:\Program Files\MemoKit\mk.exe ()
O4 - Startup: C:\Documents and Settings\Neil\Start Menu\Programs\Startup\Webshots.lnk = C:\Program Files\Webshots\Launcher.exe ()
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Main present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\PhishingFilter present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O8 - Extra context menu item: Customize Menu - C:\Program Files\Siber Systems\AI RoboForm\RoboFormComCustomizeIEMenu.html ()
O8 - Extra context menu item: Fill Forms - C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html ()
O8 - Extra context menu item: RoboForm Toolbar - C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html ()
O8 - Extra context menu item: Save Forms - C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html ()
O9 - Extra Button: Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html ()
O9 - Extra 'Tools' menuitem : Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html ()
O9 - Extra Button: Save - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html ()
O9 - Extra 'Tools' menuitem : Save Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html ()
O9 - Extra Button: RoboForm - {724d43aa-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html ()
O9 - Extra 'Tools' menuitem : RoboForm Toolbar - {724d43aa-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html ()
O9 - Extra 'Tools' menuitem : Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O9 - Extra Button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - C:\Program Files\Microsoft Money\System\mnyside.dll (Microsoft Corporation)
O15 - HKCU\..Trusted Domains: ([]msn in My Computer)
O16 - DPF: {01113300-3E00-11D2-8470-0060089874ED} https://activatemyfios.verizon.net/sdcCommo…IOS/tgctlcm.cab (Support.com Configuration Class)
O16 - DPF: {01A88BB1-1174-41EC-ACCB-963509EAE56B} http://support.dell.com/systemprofiler/SysPro.CAB (SysProWmi Class)
O16 - DPF: {02BCC737-B171-4746-94C9-0D8A0B2C0089} http://office.microsoft.com/templates/ieawsdc.cab (Microsoft Office Template and Media Control)
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} http://www.apple.com/qtactivex/qtplugin.cab (QuickTime Object)
O16 - DPF: {05CA9FB0-3E3E-4B36-BF41-0E3A5CAA8CD8} http://download.microsoft.com/download/d/c…/OGAControl.cab (Office Genuine Advantage Validation Tool)
O16 - DPF: {0C568603-D79D-11D2-87A7-00C04FF158BB} http://download.mcafee.com/molbin/Shared/MGBrwFld.cab (BrowseFolderPopup Class)
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} http://upload.facebook.com/controls/2008.1…toUploader5.cab (Facebook Photo Uploader 5 Control)
O16 - DPF: {11260943-421B-11D0-8EAC-0000C07D88CF} http://www.ipix.com/viewers/ipixx.cab (iPIX ActiveX Control)
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://fpdownload.macromedia.com/get/shock…director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://download.microsoft.com/download/3/9…heckControl.cab (Windows Genuine Advantage Validation Tool)
O16 - DPF: {1E3F1348-4370-4BBE-A67A-CC7ED824CA85} http://download.microsoft.com/download/7/4…helpcontrol.cab (Microsoft Genuine Advantage Self Support Tool)
O16 - DPF: {33564D57-0000-0010-8000-00AA00389B71} http://download.microsoft.com/download/F/6…922/wmv9VCM.CAB (Reg Error: Key error.)
O16 - DPF: {362C56AA-6E4F-40C7-A0B5-85501DBDAD77} http://i.dell.com/images/global/js/scanner/SysProExe.cab (Scanner.SysScanner)
O16 - DPF: {36C417C6-13C6-448B-9784-DD73A93B0582} http://download.mcafee.com/molbin/shared/m…56/mcinsctl.cab (Reg Error: Key error.)
O16 - DPF: {3BFFE033-BF43-11D5-A271-00A024A51325} https://notes1.cc.sunysb.edu/iNotes6W.cab (iNotes6 Class)
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} http://download.mcafee.com/molbin/shared/m…83/mcinsctl.cab (Reg Error: Key error.)
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} http://groups.msn.com/controls/PhotoUC/MsnPUpld.cab (MSN Photo Upload Tool)
O16 - DPF: {5C6698D9-7BE4-4122-8EC5-291D84DBD4A0} http://upload.facebook.com/controls/Facebo…toUploader3.cab (Facebook Photo Uploader 4 Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_17)
O16 - DPF: {94B82441-A413-4E43-8422-D49930E69764} https://echat.us.dell.com/Media/VisitorChat/TLIEFlash.CAB (TLIEFlashObj Class)
O16 - DPF: {A8658086-E6AC-4957-BC8E-7D54A7E8A78D} http://www.microsoft.com/security/controls/DoomCln.CAB (DoomCln Object)
O16 - DPF: {A8F2B9BD-A6A0-486A-9744-18920D898429} http://www.sibelius.com/download/software/…tiveXPlugin.cab (ScorchPlugin Class)
O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} http://download.mcafee.com/molbin/shared/m…,20/mcgdmgr.cab (Reg Error: Key error.)
O16 - DPF: {C432C4BD-3566-411C-8F3C-E5E0D3AE5D33} http://viewers.multicastmedia.com/common/m…MINIBrowser.CAB (CBrowser Class)
O16 - DPF: {CAFEEFAC-0014-0002-0006-ABCDEFFEDCBA} http://java.sun.com/products/plugin/autodl…indows-i586.cab (Java Plug-in 1.4.2_06)
O16 - DPF: {CAFEEFAC-0015-0000-0002-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-…indows-i586.cab (Java Plug-in 1.5.0_02)
O16 - DPF: {CAFEEFAC-0015-0000-0004-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-…indows-i586.cab (Java Plug-in 1.5.0_04)
O16 - DPF: {CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-…indows-i586.cab (Java Plug-in 1.5.0_06)
O16 - DPF: {CAFEEFAC-0015-0000-0009-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-…indows-i586.cab (Java Plug-in 1.5.0_09)
O16 - DPF: {CAFEEFAC-0015-0000-0010-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-…indows-i586.cab (Java Plug-in 1.5.0_10)
O16 - DPF: {CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_01)
O16 - DPF: {CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_02)
O16 - DPF: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_03)
O16 - DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_05)
O16 - DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_07)
O16 - DPF: {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_17)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_17)
O16 - DPF: {D27CDB6E-0000-0000-0000-000000000000} http://download.macromedia.com/pub/shockwa…ash/swflash.cab (Reg Error: Key error.)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab (Shockwave Flash Object)
O16 - DPF: {F5820AD3-9B20-423E-B2AA-7AF2B4055746} http://download.paltalk.com/download/0.x/regdload.cab (CRegistryDownload Class)
O16 - DPF: {F58E1CEF-A068-4C15-BA5E-587CAF3EE8C6} http://chat.msn.com/bin/msnchat45.cab (MSN Chat Control 4.5)
O16 - DPF: DirectAnimation Java Classes Reg Error: Value error. (Reg Error: Key error.)
O16 - DPF: Microsoft XML Parser for Java Reg Error: Value error. (Reg Error: Key error.)
O16 - DPF: vzTCPConfig http://www2.verizon.net/help/fios_settings…vzTCPConfig.CAB (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll (AVG Technologies CZ, s.r.o.)
O20 - AppInit_DLLs: (kayukore.dll) - File not found
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\AtiExtEvent: DllName - Ati2evxx.dll - C:\WINDOWS\System32\ati2evxx.dll ()
O20 - Winlogon\Notify\avgrsstarter: DllName - avgrsstx.dll - C:\WINDOWS\System32\avgrsstx.dll (AVG Technologies CZ, s.r.o.)
O24 - Desktop WallPaper: C:\Documents and Settings\Neil\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Neil\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2002/09/03 08:59:58 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O33 - MountPoints2\{907ca763-1772-11db-befe-00062541da30}\Shell - "" = AutoRun
O33 - MountPoints2\{907ca763-1772-11db-befe-00062541da30}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{907ca763-1772-11db-befe-00062541da30}\Shell\AutoRun\command - "" = F:\LaunchU3.exe – File not found
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - comfile [open] – "%1" %*
O35 - exefile [open] – "%1" %*

========== Files/Folders - Created Within 30 Days ==========

[2010/02/28 23:01:44 | 000,000,000 | —D | C] – C:\_OTL
[2010/02/28 16:56:39 | 000,000,000 | -HSD | C] – C:\Config.Msi
[2010/02/28 09:10:19 | 000,549,888 | —- | C] (OldTimer Tools) – C:\Documents and Settings\Neil\Desktop\OTL.exe
[2010/02/28 08:43:51 | 000,000,000 | —D | M] – C:\Documents and Settings\NetworkService\Application Data\AdobeUM
[2010/02/28 08:43:40 | 000,000,000 | —D | M] – C:\Documents and Settings\NetworkService\Local Settings\Application Data\Adobe
[2010/02/25 23:44:50 | 000,000,000 | —D | M] – C:\Documents and Settings\NetworkService\Application Data\Adobe
[2010/02/25 11:44:49 | 000,000,000 | —D | M] – C:\Documents and Settings\NetworkService\Application Data\Macromedia
[2010/02/24 15:12:26 | 000,000,000 | —D | M] – C:\Documents and Settings\LocalService\Application Data\Real
[2010/02/24 09:16:45 | 000,000,000 | —D | M] – C:\Documents and Settings\LocalService\Application Data\Adobe
[2009/06/29 07:25:48 | 000,000,000 | —D | M] – C:\Documents and Settings\LocalService\Application Data\AVGTOOLBAR
[2008/10/22 09:05:35 | 000,000,000 | –SD | M] – C:\Documents and Settings\NetworkService\Application Data\Microsoft
[2008/10/22 09:05:35 | 000,000,000 | –SD | M] – C:\Documents and Settings\LocalService\Application Data\Microsoft
[2008/10/22 09:05:35 | 000,000,000 | —D | M] – C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft
[2008/10/22 09:05:35 | 000,000,000 | —D | M] – C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft
[2007/02/09 00:19:36 | 000,000,000 | —D | M] – C:\Documents and Settings\LocalService\Local Settings\Application Data\Adobe
[2006/11/30 11:53:22 | 000,000,000 | —D | M] – C:\Documents and Settings\LocalService\Application Data\Gtek
[2006/11/05 05:05:42 | 000,000,000 | —D | M] – C:\Documents and Settings\LocalService\Application Data\SlimBrowser
[2006/06/20 21:19:58 | 000,000,000 | —D | M] – C:\Documents and Settings\LocalService\Application Data\Macromedia
[2005/04/30 09:43:38 | 000,000,000 | —D | M] – C:\Documents and Settings\LocalService\Local Settings\Application Data\Help
[2005/04/30 09:43:38 | 000,000,000 | —D | M] – C:\Documents and Settings\LocalService\Application Data\Help
[2004/05/08 20:06:28 | 000,000,000 | —D | M] – C:\Documents and Settings\LocalService\Local Settings\Application Data\Google
[2003/09/05 10:16:53 | 000,000,000 | —D | M] – C:\Documents and Settings\LocalService\Application Data\McAfee.com Personal Firewall

========== Files - Modified Within 30 Days ==========

[2099/01/01 12:00:00 | 000,100,352 | -HS- | M] () – C:\WINDOWS\System32\jebanemu.dll
[2099/01/01 12:00:00 | 000,071,168 | -HS- | M] () – C:\WINDOWS\System32\gemewoda.dll
[2099/01/01 12:00:00 | 000,047,616 | -HS- | M] () – C:\WINDOWS\System32\yoyorena.dll
[2010/03/01 07:35:13 | 000,000,608 | —- | M] () – C:\WINDOWS\aclockz6.dat
[2010/03/01 06:59:35 | 000,000,006 | -H– | M] () – C:\WINDOWS\tasks\SA.DAT
[2010/03/01 06:59:11 | 000,002,048 | –S- | M] () – C:\WINDOWS\BOOTSTAT.DAT
[2010/03/01 00:10:47 | 009,175,040 | -H– | M] () – C:\Documents and Settings\Neil\NTUSER.DAT
[2010/03/01 00:10:47 | 000,000,178 | -HS- | M] () – C:\Documents and Settings\Neil\NTUSER.INI
[2010/03/01 00:06:27 | 000,001,671 | —- | M] () – C:\Documents and Settings\Neil\Desktop\user.zip
[2010/02/28 23:47:41 | 056,460,208 | —- | M] () – C:\WINDOWS\System32\drivers\Avg\incavi.avm
[2010/02/28 23:45:47 | 000,001,170 | —- | M] () – C:\WINDOWS\System32\WPA.DBL
[2010/02/28 23:34:58 | 000,001,744 | -H– | M] () – C:\WINDOWS\System32\komobome
[2010/02/28 16:52:00 | 000,027,144 | —- | M] () – C:\Documents and Settings\Neil\Desktop\SafeBoot-for-Windows-XP-SP3.reg
[2010/02/28 13:29:02 | 000,100,352 | -HS- | M] () – C:\WINDOWS\System32\janeguwo.dll
[2010/02/28 13:29:02 | 000,079,872 | -HS- | M] () – C:\WINDOWS\System32\feyumaze.exe
[2010/02/28 13:29:02 | 000,070,656 | -HS- | M] () – C:\WINDOWS\System32\yuterahi.dll
[2010/02/28 13:29:02 | 000,047,104 | -HS- | M] () – C:\WINDOWS\System32\hatutiza.dll
[2010/02/28 12:37:01 | 000,047,104 | —- | M] () – C:\WINDOWS\System32\zelovumi.dll
[2010/02/28 12:35:52 | 000,070,656 | —- | M] () – C:\WINDOWS\System32\yikujode.dll
[2010/02/28 09:10:20 | 000,549,888 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Neil\Desktop\OTL.exe
[2010/02/27 07:35:53 | 000,002,469 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Dell Support Center.lnk
[2010/02/26 15:18:20 | 000,293,376 | —- | M] () – C:\Documents and Settings\Neil\Desktop\v8vqkne5.exe
[2010/02/26 07:19:28 | 000,000,000 | —- | M] () – C:\Documents and Settings\Neil\defogger_reenable
[2010/02/26 07:11:27 | 000,050,477 | —- | M] () – C:\Documents and Settings\Neil\Desktop\Defogger.exe
[2010/02/26 00:01:03 | 003,932,214 | —- | M] () – C:\WINDOWS\Webshots for Neil.bmp
[2010/02/25 22:59:35 | 000,000,710 | —- | M] () – C:\Documents and Settings\Neil\Start Menu\Programs\Startup\Webshots.lnk
[2010/02/24 01:44:49 | 000,142,495 | —- | M] () – C:\WINDOWS\System32\drivers\Avg\microavi.avg
[2010/02/24 01:44:46 | 000,492,629 | —- | M] () – C:\WINDOWS\System32\drivers\Avg\miniavi.avg
[2010/02/24 01:44:41 | 006,061,540 | —- | M] () – C:\WINDOWS\System32\drivers\Avg\avi7.avg
[2010/02/23 20:02:48 | 000,054,156 | -H– | M] () – C:\WINDOWS\QTFont.qfn
[2010/02/20 11:57:43 | 000,059,392 | —- | M] () – C:\Documents and Settings\Neil\My Documents\TAXES and FAFSA 2009.doc
[2010/02/11 05:27:24 | 000,001,374 | —- | M] () – C:\WINDOWS\imsins.BAK
[2010/02/10 16:55:27 | 000,000,452 | —- | M] () – C:\Documents and Settings\Neil\My Documents\spider.sav
[2010/02/07 16:39:29 | 000,050,688 | —- | M] () – C:\Documents and Settings\Neil\My Documents\TAXES 2009 for accountant NO SAM.doc
[2010/02/07 16:37:34 | 000,024,576 | —- | M] () – C:\Documents and Settings\Neil\My Documents\SAMSON FLANCBAUM TAXES 2009.doc
[2010/02/07 15:33:07 | 000,024,576 | —- | M] () – C:\Documents and Settings\Neil\My Documents\Smokin Taxes 2009.doc
[2010/02/06 20:40:02 | 000,054,272 | —- | M] () – C:\Documents and Settings\Neil\My Documents\TAXES 2009.doc
[2010/02/06 20:32:16 | 000,052,736 | —- | M] () – C:\Documents and Settings\Neil\My Documents\TAXES 2009 for accountant.doc
[2010/02/06 16:46:13 | 004,456,448 | —- | M] () – C:\Documents and Settings\Neil\My Documents\My Money.mny
[2010/02/06 15:49:41 | 000,024,064 | —- | M] () – C:\Documents and Settings\Neil\My Documents\Smokin Taxes 2008.doc
[2010/02/05 11:41:40 | 000,001,409 | —- | M] () – C:\WINDOWS\QTFont.for

========== Files Created - No Company Name ==========

[2099/01/01 12:00:00 | 000,100,352 | -HS- | C] () – C:\WINDOWS\System32\jebanemu.dll
[2099/01/01 12:00:00 | 000,071,168 | -HS- | C] () – C:\WINDOWS\System32\gemewoda.dll
[2099/01/01 12:00:00 | 000,047,616 | -HS- | C] () – C:\WINDOWS\System32\yoyorena.dll
[2010/03/01 00:09:14 | 000,027,144 | —- | C] () – C:\Documents and Settings\Neil\Desktop\SafeBoot-for-Windows-XP-SP3.reg
[2010/03/01 00:06:23 | 000,001,671 | —- | C] () – C:\Documents and Settings\Neil\Desktop\user.zip
[2010/02/28 23:05:17 | 000,001,744 | -H– | C] () – C:\WINDOWS\System32\komobome
[2010/02/28 13:29:02 | 000,100,352 | -HS- | C] () – C:\WINDOWS\System32\janeguwo.dll
[2010/02/28 13:29:02 | 000,079,872 | -HS- | C] () – C:\WINDOWS\System32\feyumaze.exe
[2010/02/28 13:29:02 | 000,070,656 | -HS- | C] () – C:\WINDOWS\System32\yuterahi.dll
[2010/02/28 13:29:02 | 000,047,104 | -HS- | C] () – C:\WINDOWS\System32\hatutiza.dll
[2010/02/28 12:37:01 | 000,047,104 | —- | C] () – C:\WINDOWS\System32\zelovumi.dll
[2010/02/28 12:35:52 | 000,070,656 | —- | C] () – C:\WINDOWS\System32\yikujode.dll
[2010/02/27 07:35:53 | 000,002,469 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Dell Support Center.lnk
[2010/02/26 15:18:19 | 000,293,376 | —- | C] () – C:\Documents and Settings\Neil\Desktop\v8vqkne5.exe
[2010/02/26 07:19:28 | 000,000,000 | —- | C] () – C:\Documents and Settings\Neil\defogger_reenable
[2010/02/26 07:11:27 | 000,050,477 | —- | C] () – C:\Documents and Settings\Neil\Desktop\Defogger.exe
[2010/02/07 16:31:12 | 000,050,688 | —- | C] () – C:\Documents and Settings\Neil\My Documents\TAXES 2009 for accountant NO SAM.doc
[2010/02/07 16:30:39 | 000,024,576 | —- | C] () – C:\Documents and Settings\Neil\My Documents\SAMSON FLANCBAUM TAXES 2009.doc
[2010/02/07 15:26:55 | 000,024,576 | —- | C] () – C:\Documents and Settings\Neil\My Documents\Smokin Taxes 2009.doc
[2010/02/06 20:39:38 | 000,059,392 | —- | C] () – C:\Documents and Settings\Neil\My Documents\TAXES and FAFSA 2009.doc
[2010/02/06 20:16:13 | 000,052,736 | —- | C] () – C:\Documents and Settings\Neil\My Documents\TAXES 2009 for accountant.doc
[2010/02/05 11:41:40 | 000,054,156 | -H– | C] () – C:\WINDOWS\QTFont.qfn
[2010/02/05 11:41:40 | 000,001,409 | —- | C] () – C:\WINDOWS\QTFont.for
[2010/01/30 15:02:10 | 000,054,272 | —- | C] () – C:\Documents and Settings\Neil\My Documents\TAXES 2009.doc
[2008/05/09 07:44:34 | 000,141,312 | —- | C] () – C:\WINDOWS\System32\drivers\sp_rsdrv2.sys
[2008/03/06 00:36:33 | 000,086,016 | —- | C] () – C:\WINDOWS\System32\ati2evxx.dll
[2007/01/23 15:15:22 | 000,676,224 | —- | C] () – C:\WINDOWS\System32\OGACheckControl.DLL
[2006/10/20 16:15:34 | 000,001,359 | —- | C] () – C:\Documents and Settings\All Users\Application Data\QTSBandwidthCache
[2006/01/11 13:25:19 | 000,000,576 | —- | C] () – C:\WINDOWS\_delis32.ini
[2006/01/11 13:25:13 | 000,001,216 | —- | C] () – C:\WINDOWS\_isenv31.ini
[2006/01/11 13:25:12 | 000,000,521 | —- | C] () – C:\WINDOWS\_iserr31.ini
[2006/01/09 12:28:27 | 000,000,313 | —- | C] () – C:\WINDOWS\BRDIAG.INI
[2006/01/09 12:28:27 | 000,000,145 | —- | C] () – C:\WINDOWS\BRVIDEO.INI
[2006/01/09 12:28:26 | 000,000,023 | —- | C] () – C:\WINDOWS\Brownie.ini
[2006/01/09 12:28:17 | 000,026,624 | —- | C] () – C:\WINDOWS\System32\BRGSRC32.DLL
[2006/01/09 12:28:17 | 000,004,608 | —- | C] () – C:\WINDOWS\System32\BRGSRC16.DLL
[2006/01/09 12:28:16 | 000,077,824 | —- | C] () – C:\WINDOWS\System32\BROSNMP.DLL
[2006/01/09 12:28:12 | 000,009,013 | —- | C] () – C:\WINDOWS\HL-2040.INI
[2006/01/09 12:27:26 | 000,000,426 | —- | C] () – C:\WINDOWS\BRWMARK.INI
[2005/11/29 00:11:56 | 000,000,037 | —- | C] () – C:\WINDOWS\ipixActivex.ini
[2005/08/09 17:12:28 | 003,596,288 | —- | C] () – C:\WINDOWS\System32\qt-dx331.dll
[2004/11/18 14:30:13 | 000,000,000 | —- | C] () – C:\WINDOWS\OpPrintServer.INI
[2004/11/18 14:21:16 | 000,007,680 | —- | C] () – C:\WINDOWS\System32\CNMVS69.DLL
[2004/09/11 21:54:11 | 000,000,063 | —- | C] () – C:\WINDOWS\mdm.ini
[2004/09/03 17:52:50 | 000,196,608 | —- | C] () – C:\WINDOWS\System32\GCCollection.dll
[2004/06/30 15:04:46 | 000,040,960 | —- | C] () – C:\WINDOWS\System32\SDelete.dll
[2004/04/21 13:34:48 | 000,071,749 | —- | C] () – C:\WINDOWS\HCExtOutput.dll
[2004/04/21 13:34:48 | 000,000,823 | —- | C] () – C:\WINDOWS\TSC.ini
[2004/04/21 13:34:32 | 000,000,170 | —- | C] () – C:\WINDOWS\GetServer.ini
[2004/03/25 11:20:56 | 000,000,127 | —- | C] () – C:\Documents and Settings\Neil\Local Settings\Application Data\fusioncache.dat
[2004/03/25 08:33:21 | 000,000,024 | —- | C] () – C:\WINDOWS\wininit.ini
[2004/03/25 08:33:05 | 000,000,002 | —- | C] () – C:\WINDOWS\msoffice.ini
[2004/03/07 13:51:00 | 000,024,924 | —- | C] () – C:\WINDOWS\System32\openports.dll
[2004/02/09 15:42:28 | 000,000,071 | —- | C] () – C:\WINDOWS\Theme Uninstall.ini
[2003/10/14 15:54:32 | 000,030,720 | —- | C] () – C:\Documents and Settings\Neil\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2003/10/03 17:10:14 | 000,000,036 | —- | C] () – C:\WINDOWS\Crypkey.ini
[2003/10/03 17:10:09 | 000,024,608 | —- | C] () – C:\WINDOWS\System32\Ckldrv.sys
[2003/10/03 17:10:09 | 000,018,432 | —- | C] () – C:\WINDOWS\Setup_ck.dll
[2003/10/03 17:10:08 | 000,000,000 | —- | C] () – C:\WINDOWS\PROTOCOL.INI
[2003/08/22 19:23:38 | 000,000,026 | —- | C] () – C:\WINDOWS\INTUIT.INI
[2003/07/23 18:57:41 | 000,002,154 | —- | C] () – C:\WINDOWS\Solitaire.ini
[2003/07/11 19:12:37 | 000,000,210 | —- | C] () – C:\WINDOWS\cdPlayer.ini
[2003/07/10 06:55:57 | 000,000,208 | —- | C] () – C:\WINDOWS\QUICKEN.INI
[2003/07/10 01:36:45 | 000,000,000 | —- | C] () – C:\WINDOWS\NSREX.INI
[2003/07/10 00:53:16 | 000,000,054 | —- | C] () – C:\WINDOWS\setihome.ini
[2003/07/09 23:12:55 | 000,000,034 | —- | C] () – C:\WINDOWS\alohabob.INI
[2003/07/03 07:29:25 | 000,000,061 | —- | C] () – C:\WINDOWS\smscfg.ini
[2003/07/03 07:19:29 | 000,000,376 | —- | C] () – C:\WINDOWS\ODBC.INI
[2003/07/03 07:04:28 | 000,000,893 | —- | C] () – C:\WINDOWS\orun32.ini
[2003/07/03 06:35:24 | 000,000,546 | —- | C] () – C:\WINDOWS\System32\OEMINFO.INI
[2002/10/28 10:53:49 | 000,210,944 | —- | C] () – C:\WINDOWS\System32\MSVCRT10.DLL
[2002/10/28 10:53:43 | 000,000,083 | —- | C] () – C:\WINDOWS\KPCMS.INI
[2002/07/03 10:57:48 | 000,013,203 | —- | C] () – C:\WINDOWS\System32\drivers\packet.sys
[2002/01/08 19:03:10 | 000,077,824 | —- | C] () – C:\WINDOWS\System32\MiniBrowser.dll
[2001/12/17 21:30:43 | 000,000,359 | —- | C] () – C:\WINDOWS\smsafari.ini
[2001/12/17 21:17:17 | 000,012,416 | —- | C] () – C:\WINDOWS\System32\VRX1.DLL
[2001/12/17 21:17:16 | 000,027,136 | —- | C] () – C:\WINDOWS\System32\VERMONT1.DLL
[2001/12/17 21:17:11 | 000,107,520 | —- | C] () – C:\WINDOWS\System32\SIMANT.DLL
[2001/12/03 15:58:32 | 000,286,208 | —- | C] () – C:\WINDOWS\System32\DCSSDK32.dll
[2001/12/03 15:58:32 | 000,107,456 | —- | C] () – C:\WINDOWS\System32\SH33W32.DLL
[2001/11/21 19:44:10 | 000,003,413 | —- | C] () – C:\Documents and Settings\Neil\Application Data\dw.log
[2001/07/05 16:36:07 | 000,000,370 | —- | C] () – C:\WINDOWS\KA.INI
[2001/05/30 08:47:44 | 000,110,592 | —- | C] () – C:\WINDOWS\System32\cdtool.dll
[2001/05/12 16:10:41 | 000,056,832 | —- | C] () – C:\WINDOWS\System32\iyvu9_32.dll
[2001/05/12 11:01:14 | 000,167,936 | —- | C] () – C:\WINDOWS\System32\XFILEXR.DLL
[2001/05/12 10:59:13 | 000,040,960 | —- | C] () – C:\WINDOWS\System32\OEMREG.DLL
[2001/05/12 10:58:38 | 000,008,576 | —- | C] () – C:\WINDOWS\System32\ICMUPG.DLL
[2001/05/12 10:54:15 | 000,028,672 | —- | C] () – C:\WINDOWS\System32\NETBIOS.DLL
[2001/05/12 10:53:38 | 000,188,416 | —- | C] () – C:\WINDOWS\System32\MEMBG.DLL
[2001/05/12 10:51:28 | 000,002,490 | —- | C] () – C:\WINDOWS\System32\DLCNDI.DLL
[2001/05/12 09:46:50 | 000,009,216 | —- | C] () – C:\WINDOWS\System32\Spktrn32.dll
[2001/05/12 09:29:56 | 000,040,448 | —- | C] () – C:\WINDOWS\System32\hcfuninst.dll
[2001/05/12 09:29:56 | 000,028,672 | —- | C] () – C:\WINDOWS\System32\hcfapi.dll
[2000/10/21 01:21:26 | 000,363,520 | —- | C] () – C:\WINDOWS\System32\psisdecd.dll
[1999/12/07 00:00:00 | 000,024,975 | —- | C] () – C:\WINDOWS\twain_16.dll
[1999/07/23 12:46:48 | 000,000,116 | —- | C] () – C:\WINDOWS\AuHCcup1.ini
[1999/07/23 09:53:20 | 000,129,536 | —- | C] () – C:\WINDOWS\AuHCcup1.dll
[1999/01/22 17:46:58 | 000,065,536 | —- | C] () – C:\WINDOWS\System32\MSRTEDIT.DLL
[1980/01/01 00:00:00 | 000,031,744 | —- | C] () – C:\WINDOWS\System32\mdmmoh.dll
[1979/12/31 11:29:50 | 000,038,352 | —- | C] () – C:\WINDOWS\System32\NAVAPGUI.DLL

========== LOP Check ==========

[2010/02/28 11:29:50 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\AVG Security Toolbar
[2008/10/23 21:50:10 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Banner Maker Pro 7
[2007/11/03 14:11:59 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\GlobalSCAPE
[2005/04/03 22:08:03 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\RoboForm
[2008/08/22 07:34:02 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Spyware Terminator
[2008/03/20 08:50:30 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\SupportSoft
[2007/11/08 14:55:57 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TEMP
[2007/12/03 11:27:07 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Viewpoint
[2008/12/30 21:58:40 | 000,000,000 | —D | M] – C:\Documents and Settings\Neil\Application Data\AVGTOOLBAR
[2007/04/25 18:03:39 | 000,000,000 | —D | M] – C:\Documents and Settings\Neil\Application Data\Digital Photo Slide Show
[2007/11/03 14:11:52 | 000,000,000 | —D | M] – C:\Documents and Settings\Neil\Application Data\GlobalSCAPE
[2003/07/09 17:05:42 | 000,000,000 | —D | M] – C:\Documents and Settings\Neil\Application Data\InterVideo
[2006/04/06 15:10:57 | 000,000,000 | —D | M] – C:\Documents and Settings\Neil\Application Data\Kensington
[2007/05/17 22:28:21 | 000,000,000 | —D | M] – C:\Documents and Settings\Neil\Application Data\KompoZer
[2004/04/20 16:38:15 | 000,000,000 | —D | M] – C:\Documents and Settings\Neil\Application Data\Leadertech
[2007/07/12 21:22:05 | 000,000,000 | —D | M] – C:\Documents and Settings\Neil\Application Data\Novagraph
[2010/02/25 11:47:37 | 000,000,000 | —D | M] – C:\Documents and Settings\Neil\Application Data\Registry Booster
[2004/07/10 01:31:42 | 000,000,000 | —D | M] – C:\Documents and Settings\Neil\Application Data\Screen Calendar
[2010/03/01 00:33:30 | 000,000,000 | —D | M] – C:\Documents and Settings\Neil\Application Data\SlimBrowser
[2008/08/21 22:42:02 | 000,000,000 | —D | M] – C:\Documents and Settings\Neil\Application Data\Spyware Terminator
[2004/06/30 20:03:31 | 000,000,000 | —D | M] – C:\Documents and Settings\Neil\Application Data\Thunderbird
[2007/01/13 22:29:07 | 000,000,000 | —D | M] – C:\Documents and Settings\Neil\Application Data\Uniblue
[2007/12/03 11:27:14 | 000,000,000 | —D | M] – C:\Documents and Settings\Neil\Application Data\Viewpoint
[2003/07/09 22:53:59 | 000,000,258 | —- | M] () – C:\WINDOWS\Tasks\ISP signup reminder 1.job

========== Purity Check ==========



========== Alternate Data Streams ==========

@Alternate Data Stream - 125 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:08948D52
< End of report >
Hi sagiter,

I think the GMER log shows us enough to go after this guy.

Next, Double click on OTL.exe
  • Under the Custom Scans/Fixes box at the bottom, paste in the following
  • Do Not copy the word CODE
  • please note the fix starts with the :
:Services

:OTL
[2099/01/01 12:00:00 | 000,100,352 | -HS- | M] () – C:\WINDOWS\System32\jebanemu.dll
[2099/01/01 12:00:00 | 000,071,168 | -HS- | M] () – C:\WINDOWS\System32\gemewoda.dll
[2099/01/01 12:00:00 | 000,047,616 | -HS- | M] () – C:\WINDOWS\System32\yoyorena.dll
O20 - AppInit_DLLs: (kayukore.dll) - File not found

:Commands
[reboot]

Then click the Run Fix button at the top
  • Let the program run unhindered
  • Please save the resulting log to be posted in your next reply.

Let's see if we can kill some of this. If you get any windows error, just close them.

Download this file & extract TDSSKiller.exe onto your Desktop

Then create this batch file to be placed next to TDSSKiller

—-

Open a new Notepad session
  • Click the Start button, click run
  • in the run box type notepad
  • click ok
  • In the notepad, Click "Format" and be certain that Word Wrap is not checked.
  • Copy and paste all the text in the code box below into the Notepad. Do Not copy the word CODE
@ECHO OFF
START /WAIT TDSSKILLER.exe -l Logit.txt -v
START Logit.txt
del %0

In the notepad
  • Click File, Save as…, and set the Save in to your Desktop
  • In the filename box, type (including quotation marks) as the filename: "fix.bat"
  • Click save
It should look like this: [external image: Posted Image]
Double click on fix.bat & allow it to run

Post back with the OTL fix log and Logit.txt and a new OTL scan log.

Thanks
I did not get an OTL Fix File but it seemed to run fine.

Still getting AVG Pop-ups while running OTL.

Here are the files I got:

20:47:01:998 2348 TDSS rootkit removing tool 2.2.7.1 Feb 27 2010 13:29:25
20:47:01:998 2348 ================================================================================
20:47:01:998 2348 SystemInfo:

20:47:01:998 2348 OS Version: 5.1.2600 ServicePack: 3.0
20:47:01:998 2348 Product type: Workstation
20:47:01:998 2348 ComputerName: OFFICE
20:47:01:998 2348 UserName: Neil
20:47:01:998 2348 Windows directory: C:\WINDOWS
20:47:01:998 2348 Processor architecture: Intel x86
20:47:01:998 2348 Number of processors: 1
20:47:01:998 2348 Page size: 0x1000
20:47:01:998 2348 Boot type: Normal boot
20:47:01:998 2348 ================================================================================
20:47:02:068 2348 UnloadDriverW: NtUnloadDriver error 2
20:47:02:068 2348 ForceUnloadDriverW: UnloadDriverW(klmd21) error 2
20:47:02:599 2348 Initialize success
20:47:02:599 2348
20:47:02:599 2348 Scanning Services …
20:47:02:599 2348 wfopen_ex: Trying to open file C:\WINDOWS\system32\config\system
20:47:02:599 2348 wfopen_ex: MyNtCreateFileW error 32 (C0000043)
20:47:02:599 2348 wfopen_ex: Trying to KLMD file open
20:47:02:599 2348 wfopen_ex: File opened ok (Flags 2)
20:47:02:599 2348 wfopen_ex: Trying to open file C:\WINDOWS\system32\config\software
20:47:02:599 2348 wfopen_ex: MyNtCreateFileW error 32 (C0000043)
20:47:02:599 2348 wfopen_ex: Trying to KLMD file open
20:47:02:599 2348 wfopen_ex: File opened ok (Flags 2)
20:47:03:330 2348 GetAdvancedServicesInfo: Raw services enum returned 364 services
20:47:03:360 2348 fclose_ex: Trying to close file C:\WINDOWS\system32\config\system
20:47:03:380 2348 fclose_ex: Trying to close file C:\WINDOWS\system32\config\software
20:47:03:380 2348
20:47:03:380 2348 Scanning Kernel memory …
20:47:03:380 2348 Devices to scan: 3
20:47:03:380 2348
20:47:03:380 2348 Driver Name: Disk
20:47:03:380 2348 IRP_MJ_CREATE : F9978BB0
20:47:03:380 2348 IRP_MJ_CREATE_NAMED_PIPE : 804FA88E
20:47:03:380 2348 IRP_MJ_CLOSE : F9978BB0
20:47:03:380 2348 IRP_MJ_READ : F9972D1F
20:47:03:380 2348 IRP_MJ_WRITE : F9972D1F
20:47:03:380 2348 IRP_MJ_QUERY_INFORMATION : 804FA88E
20:47:03:380 2348 IRP_MJ_SET_INFORMATION : 804FA88E
20:47:03:380 2348 IRP_MJ_QUERY_EA : 804FA88E
20:47:03:380 2348 IRP_MJ_SET_EA : 804FA88E
20:47:03:380 2348 IRP_MJ_FLUSH_BUFFERS : F99732E2
20:47:03:380 2348 IRP_MJ_QUERY_VOLUME_INFORMATION : 804FA88E
20:47:03:380 2348 IRP_MJ_SET_VOLUME_INFORMATION : 804FA88E
20:47:03:380 2348 IRP_MJ_DIRECTORY_CONTROL : 804FA88E
20:47:03:380 2348 IRP_MJ_FILE_SYSTEM_CONTROL : 804FA88E
20:47:03:380 2348 IRP_MJ_DEVICE_CONTROL : F99733BB
20:47:03:380 2348 IRP_MJ_INTERNAL_DEVICE_CONTROL : F9976F28
20:47:03:380 2348 IRP_MJ_SHUTDOWN : F99732E2
20:47:03:380 2348 IRP_MJ_LOCK_CONTROL : 804FA88E
20:47:03:380 2348 IRP_MJ_CLEANUP : 804FA88E
20:47:03:380 2348 IRP_MJ_CREATE_MAILSLOT : 804FA88E
20:47:03:380 2348 IRP_MJ_QUERY_SECURITY : 804FA88E
20:47:03:380 2348 IRP_MJ_SET_SECURITY : 804FA88E
20:47:03:380 2348 IRP_MJ_POWER : F9974C82
20:47:03:380 2348 IRP_MJ_SYSTEM_CONTROL : F997999E
20:47:03:380 2348 IRP_MJ_DEVICE_CHANGE : 804FA88E
20:47:03:380 2348 IRP_MJ_QUERY_QUOTA : 804FA88E
20:47:03:380 2348 IRP_MJ_SET_QUOTA : 804FA88E
20:47:03:430 2348 TDL3_StartIoLastChanceHookDetect: Unable to dump StartIo handler code
20:47:03:430 2348 sion
20:47:03:440 2348 C:\WINDOWS\system32\DRIVERS\disk.sys - Verdict: Clean
20:47:03:440 2348
20:47:03:440 2348 Driver Name: Disk
20:47:03:440 2348 IRP_MJ_CREATE : F9978BB0
20:47:03:440 2348 IRP_MJ_CREATE_NAMED_PIPE : 804FA88E
20:47:03:450 2348 IRP_MJ_CLOSE : F9978BB0
20:47:03:450 2348 IRP_MJ_READ : F9972D1F
20:47:03:450 2348 IRP_MJ_WRITE : F9972D1F
20:47:03:450 2348 IRP_MJ_QUERY_INFORMATION : 804FA88E
20:47:03:450 2348 IRP_MJ_SET_INFORMATION : 804FA88E
20:47:03:450 2348 IRP_MJ_QUERY_EA : 804FA88E
20:47:03:450 2348 IRP_MJ_SET_EA : 804FA88E
20:47:03:450 2348 IRP_MJ_FLUSH_BUFFERS : F99732E2
20:47:03:450 2348 IRP_MJ_QUERY_VOLUME_INFORMATION : 804FA88E
20:47:03:450 2348 IRP_MJ_SET_VOLUME_INFORMATION : 804FA88E
20:47:03:450 2348 IRP_MJ_DIRECTORY_CONTROL : 804FA88E
20:47:03:450 2348 IRP_MJ_FILE_SYSTEM_CONTROL : 804FA88E
20:47:03:450 2348 IRP_MJ_DEVICE_CONTROL : F99733BB
20:47:03:450 2348 IRP_MJ_INTERNAL_DEVICE_CONTROL : F9976F28
20:47:03:450 2348 IRP_MJ_SHUTDOWN : F99732E2
20:47:03:450 2348 IRP_MJ_LOCK_CONTROL : 804FA88E
20:47:03:450 2348 IRP_MJ_CLEANUP : 804FA88E
20:47:03:450 2348 IRP_MJ_CREATE_MAILSLOT : 804FA88E
20:47:03:450 2348 IRP_MJ_QUERY_SECURITY : 804FA88E
20:47:03:450 2348 IRP_MJ_SET_SECURITY : 804FA88E
20:47:03:450 2348 IRP_MJ_POWER : F9974C82
20:47:03:450 2348 IRP_MJ_SYSTEM_CONTROL : F997999E
20:47:03:450 2348 IRP_MJ_DEVICE_CHANGE : 804FA88E
20:47:03:450 2348 IRP_MJ_QUERY_QUOTA : 804FA88E
20:47:03:450 2348 IRP_MJ_SET_QUOTA : 804FA88E
20:47:03:460 2348 TDL3_StartIoLastChanceHookDetect: Unable to dump StartIo handler code
20:47:03:460 2348 sion
20:47:03:460 2348 C:\WINDOWS\system32\DRIVERS\disk.sys - Verdict: Clean
20:47:03:460 2348
20:47:03:460 2348 Driver Name: atapi
20:47:03:460 2348 IRP_MJ_CREATE : 826C6A9A
20:47:03:460 2348 IRP_MJ_CREATE_NAMED_PIPE : 826C6A9A
20:47:03:460 2348 IRP_MJ_CLOSE : 826C6A9A
20:47:03:460 2348 IRP_MJ_READ : 826C6A9A
20:47:03:460 2348 IRP_MJ_WRITE : 826C6A9A
20:47:03:460 2348 IRP_MJ_QUERY_INFORMATION : 826C6A9A
20:47:03:460 2348 IRP_MJ_SET_INFORMATION : 826C6A9A
20:47:03:460 2348 IRP_MJ_QUERY_EA : 826C6A9A
20:47:03:460 2348 IRP_MJ_SET_EA : 826C6A9A
20:47:03:460 2348 IRP_MJ_FLUSH_BUFFERS : 826C6A9A
20:47:03:460 2348 IRP_MJ_QUERY_VOLUME_INFORMATION : 826C6A9A
20:47:03:460 2348 IRP_MJ_SET_VOLUME_INFORMATION : 826C6A9A
20:47:03:460 2348 IRP_MJ_DIRECTORY_CONTROL : 826C6A9A
20:47:03:460 2348 IRP_MJ_FILE_SYSTEM_CONTROL : 826C6A9A
20:47:03:460 2348 IRP_MJ_DEVICE_CONTROL : 826C6A9A
20:47:03:460 2348 IRP_MJ_INTERNAL_DEVICE_CONTROL : 826C6A9A
20:47:03:460 2348 IRP_MJ_SHUTDOWN : 826C6A9A
20:47:03:460 2348 IRP_MJ_LOCK_CONTROL : 826C6A9A
20:47:03:460 2348 IRP_MJ_CLEANUP : 826C6A9A
20:47:03:460 2348 IRP_MJ_CREATE_MAILSLOT : 826C6A9A
20:47:03:460 2348 IRP_MJ_QUERY_SECURITY : 826C6A9A
20:47:03:460 2348 IRP_MJ_SET_SECURITY : 826C6A9A
20:47:03:460 2348 IRP_MJ_POWER : 826C6A9A
20:47:03:460 2348 IRP_MJ_SYSTEM_CONTROL : 826C6A9A
20:47:03:460 2348 IRP_MJ_DEVICE_CHANGE : 826C6A9A
20:47:03:460 2348 IRP_MJ_QUERY_QUOTA : 826C6A9A
20:47:03:460 2348 IRP_MJ_SET_QUOTA : 826C6A9A
20:47:03:470 2348 ihd: 0, 0, 607, 138, 3, 120, 1
20:47:03:470 2348 Driver "atapi" Irp handler infected by TDSS rootkit … 20:47:03:470 2348 cured
20:47:03:480 2348 Driver "atapi" StartIo handler infected by TDSS rootkit … 20:47:03:480 2348 cured
20:47:03:480 2348 siohd: 1
20:47:03:480 2348 Driver "atapi" StartIo handler infected by TDSS rootkit … 20:47:03:480 2348 cured
20:47:03:540 2348 C:\WINDOWS\system32\DRIVERS\atapi.sys - Verdict: Infected
20:47:03:540 2348 File C:\WINDOWS\system32\DRIVERS\atapi.sys infected by TDSS rootkit … 20:47:03:540 2348 Processing driver file: C:\WINDOWS\system32\DRIVERS\atapi.sys
20:47:03:540 2348 ProcessDirEnumEx: FindFirstFile(C:\WINDOWS\system32\DriverStore\FileRepository\*) error 3
20:47:03:781 2348 vfvi6
20:47:04:211 2348 !dsvbh1
20:47:23:689 2348 dsvbh2
20:47:23:729 2348 fdfb2
20:47:23:729 2348 Backup copy found, using it..
20:47:24:110 2348 will be cured on next reboot
20:47:24:110 2348 Reboot required for cure complete..
20:47:24:200 2348 Cure on reboot scheduled successfully
20:47:24:200 2348
20:47:24:210 2348 Completed
20:47:24:210 2348
20:47:24:210 2348 Results:
20:47:24:210 2348 Memory objects infected / cured / cured on reboot: 3 / 3 / 0
20:47:24:210 2348 Registry objects infected / cured / cured on reboot: 0 / 0 / 0
20:47:24:210 2348 File objects infected / cured / cured on reboot: 1 / 0 / 1
20:47:24:210 2348
20:47:24:210 2348 UnloadDriverW: NtUnloadDriver error 1
20:47:24:210 2348 KLMD_Unload: UnloadDriverW(klmd21) error 1
20:47:24:210 2348 KLMD(ARK) unloaded successfully


OTL logfile created on: 3/1/2010 8:56:06 PM - Run 3
OTL by OldTimer - Version 3.1.30.3 Folder = C:\Documents and Settings\Neil\Desktop
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

255.00 Mb Total Physical Memory | 45.00 Mb Available Physical Memory | 17.00% Memory free
618.00 Mb Paging File | 311.00 Mb Available in Paging File | 50.00% Paging File free
Paging file location(s): C:\pagefile.sys 384 768 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 37.22 Gb Total Space | 16.68 Gb Free Space | 44.80% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: OFFICE
Current User Name: Neil
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal

========== Processes (SafeList) ==========

PRC - C:\Documents and Settings\Neil\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe (Siber Systems)
PRC - C:\Program Files\AVG\AVG8\avgtray.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\Java\jre6\bin\jqs.exe (Sun Microsystems, Inc.)
PRC - C:\Program Files\Java\jre6\bin\jusched.exe (Sun Microsystems, Inc.)
PRC - C:\Program Files\AVG\AVG8\avgrsx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG8\avgcsrvx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG8\avgnsx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG8\avgemc.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG8\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\Common Files\Motive\McciCMService.exe (Motive Communications, Inc.)
PRC - C:\Program Files\Dell Support Center\gs_agent\dsc.exe (SupportSoft, Inc.)
PRC - C:\Program Files\Dell Support Center\bin\sprtcmd.exe (SupportSoft, Inc.)
PRC - C:\Program Files\Dell Support Center\bin\sprtsvc.exe (SupportSoft, Inc.)
PRC - C:\Program Files\Spyware Terminator\sp_rsser.exe (Crawler.com)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\QuickTime\qttask.exe (Apple Computer, Inc.)
PRC - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe (Adobe Systems Incorporated)
PRC - C:\Program Files\MemoKit\MemoKit2.exe (Software Benefits Inc.)
PRC - C:\Program Files\Canon\Memory Card Utility\PIXMA iP6000D\PDUiP6000DMon.exe (CANON INC.)
PRC - C:\Program Files\Canon\Memory Card Utility\PIXMA iP6000D\PDUiP6000DTskbr.exe (CANON INC.)
PRC - C:\Program Files\Canon\Memory Card Utility\PIXMA iP6000D\PDUiP6000DMemCrdMgr.exe (CANON INC.)
PRC - C:\WINDOWS\webshots.scr (Webshots.com)
PRC - C:\WINDOWS\SYSTEM32\ati2evxx.exe ()
PRC - C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe (ATI Technologies, Inc.)
PRC - C:\Program Files\Common Files\Real\Update_OB\realsched.exe (RealNetworks, Inc.)
PRC - C:\Program Files\Dell\QuickSet\quickset.exe ()
PRC - C:\Program Files\Apoint\Apoint.exe (Alps Electric Co., Ltd.)
PRC - C:\WINDOWS\SYSTEM32\DSentry.exe (Dell - Advanced Desktop Engineering)
PRC - C:\Program Files\Apoint\ApntEx.exe (Alps Electric Co., Ltd.)
PRC - C:\ImageMate CompactFlash USB\SandIcon.exe ()
PRC - C:\WINDOWS\SYSTEM32\Crypserv.exe (Kenonic Controls Ltd.)
PRC - C:\Program Files\Microsoft Office\Office\1033\MSOFFICE.EXE (Microsoft Corporation)


========== Modules (SafeList) ==========

MOD - C:\Documents and Settings\Neil\Desktop\OTL.exe (OldTimer Tools)


========== Win32 Services (SafeList) ==========

SRV - (JavaQuickStarterService) – C:\Program Files\Java\jre6\bin\jqs.exe (Sun Microsystems, Inc.)
SRV - (avg8emc) – C:\Program Files\AVG\AVG8\avgemc.exe (AVG Technologies CZ, s.r.o.)
SRV - (avg8wd) – C:\Program Files\AVG\AVG8\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
SRV - (McciCMService) – C:\Program Files\Common Files\Motive\McciCMService.exe (Motive Communications, Inc.)
SRV - (sprtsvc_dellsupportcenter) SupportSoft Sprocket Service (dellsupportcenter) – C:\Program Files\Dell Support Center\bin\sprtsvc.exe (SupportSoft, Inc.)
SRV - (sp_rssrv) – C:\Program Files\Spyware Terminator\sp_rsser.exe (Crawler.com)
SRV - (DSBrokerService) – C:\Program Files\DellSupport\brkrsvc.exe ()
SRV - (IDriverT) – C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe (Macrovision Corporation)
SRV - (PDUiP6000DMemCrdMgr) – C:\Program Files\Canon\Memory Card Utility\PIXMA iP6000D\PDUiP6000DMemCrdMgr.exe (CANON INC.)
SRV - (Ati HotKey Poller) – C:\WINDOWS\SYSTEM32\ati2evxx.exe ()
SRV - (Crypkey License) – C:\WINDOWS\System32\Crypserv.exe (Kenonic Controls Ltd.)


========== Driver Services (SafeList) ==========

DRV - (AvgMfx86) – C:\WINDOWS\System32\Drivers\avgmfx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (AvgLdx86) – C:\WINDOWS\System32\Drivers\avgldx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (AvgTdiX) – C:\WINDOWS\System32\Drivers\avgtdix.sys (AVG Technologies CZ, s.r.o.)
DRV - (usbaudio) USB Audio Driver (WDM) – C:\WINDOWS\SYSTEM32\DRIVERS\usbaudio.sys (Microsoft Corporation)
DRV - (amdagp) – C:\WINDOWS\System32\DRIVERS\amdagp.sys (Advanced Micro Devices, Inc.)
DRV - (sisagp) – C:\WINDOWS\System32\DRIVERS\sisagp.sys (Silicon Integrated Systems Corporation)
DRV - (Secdrv) – C:\WINDOWS\SYSTEM32\DRIVERS\secdrv.sys (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.)
DRV - (MRENDIS5) – C:\Program Files\Common Files\Motive\MRENDIS5.sys (Motive, Inc.)
DRV - (MREMPR5) – C:\Program Files\Common Files\Motive\MREMPR5.sys (Motive, Inc.)
DRV - (dsunidrv) – C:\WINDOWS\SYSTEM32\DRIVERS\dsunidrv.sys (Gteko Ltd.)
DRV - (DSproct) – C:\Program Files\DellSupport\GTAction\triggers\DSproct.sys (Gteko Ltd.)
DRV - (USBModem) – C:\WINDOWS\SYSTEM32\DRIVERS\lgusbmodem.sys (LG Electronics Inc.)
DRV - (UsbDiag) – C:\WINDOWS\SYSTEM32\DRIVERS\lgusbdiag.sys (LG Electronics Inc.)
DRV - (usbbus) – C:\WINDOWS\SYSTEM32\DRIVERS\lgusbbus.sys (LG Electronics Inc.)
DRV - (GEARAspiWDM) – C:\WINDOWS\SYSTEM32\DRIVERS\GEARAspiWDM.sys (GEAR Software Inc.)
DRV - (nv) – C:\WINDOWS\SYSTEM32\DRIVERS\nv4_mini.sys (NVIDIA Corporation)
DRV - (iAimFP4) – C:\WINDOWS\SYSTEM32\DRIVERS\wvchntxx.sys (Intel® Corporation)
DRV - (iAimFP3) – C:\WINDOWS\SYSTEM32\DRIVERS\wsiintxx.sys (Intel® Corporation)
DRV - (iAimTV4) – C:\WINDOWS\SYSTEM32\DRIVERS\wch7xxnt.sys (Intel® Corporation)
DRV - (iAimTV3) – C:\WINDOWS\SYSTEM32\DRIVERS\watv04nt.sys (Intel® Corporation)
DRV - (iAimTV1) – C:\WINDOWS\SYSTEM32\DRIVERS\watv02nt.sys (Intel® Corporation)
DRV - (iAimTV0) – C:\WINDOWS\SYSTEM32\DRIVERS\watv01nt.sys (Intel® Corporation)
DRV - (iAimFP0) – C:\WINDOWS\SYSTEM32\DRIVERS\wadv01nt.sys (Intel® Corporation)
DRV - (iAimFP1) – C:\WINDOWS\SYSTEM32\DRIVERS\wadv02nt.sys (Intel® Corporation)
DRV - (iAimFP2) – C:\WINDOWS\SYSTEM32\DRIVERS\wadv05nt.sys (Intel® Corporation)
DRV - (i81x) – C:\WINDOWS\SYSTEM32\DRIVERS\i81xnt5.sys (Intel® Corporation)
DRV - (ati2mtag) – C:\WINDOWS\SYSTEM32\DRIVERS\ati2mtag.sys (ATI Technologies Inc.)
DRV - (STAC97) Audio Driver (WDM) – C:\WINDOWS\SYSTEM32\DRIVERS\STAC97.sys (SigmaTel, Inc.)
DRV - (ApfiltrService) – C:\WINDOWS\SYSTEM32\DRIVERS\Apfiltr.sys (Alps Electric Co., Ltd.)
DRV - (omci) – C:\WINDOWS\SYSTEM32\DRIVERS\omci.sys (Dell Computer Corporation)
DRV - (bcm4sbxp) – C:\WINDOWS\SYSTEM32\DRIVERS\bcm4sbxp.sys (Broadcom Corporation)
DRV - (BCM43XX) – C:\WINDOWS\SYSTEM32\DRIVERS\LSBCMNDS.SYS (The Linksys Group, Inc.)
DRV - (Vpctcom) – C:\WINDOWS\System32\DRIVERS\vpctcom.sys (PCtel, Inc.)
DRV - (Ptserial) – C:\WINDOWS\SYSTEM32\DRIVERS\ptserial.sys (PCTEL, INC.)
DRV - (Vvoice) – C:\WINDOWS\System32\DRIVERS\vvoice.sys (PCtel, Inc.)
DRV - (Vmodem) – C:\WINDOWS\System32\DRIVERS\vmodem.sys (PCTEL, INC.)
DRV - (Ptilink) – C:\WINDOWS\SYSTEM32\DRIVERS\PTILINK.SYS (Parallel Technologies, Inc.)
DRV - (AloPar) – C:\WINDOWS\SYSTEM32\DRIVERS\AloPar.sys (Eisenworld, Inc.)
DRV - (Sparrow) – C:\WINDOWS\System32\DRIVERS\sparrow.sys (Adaptec, Inc.)
DRV - (sym_u3) – C:\WINDOWS\System32\DRIVERS\sym_u3.sys (LSI Logic)
DRV - (sym_hi) – C:\WINDOWS\System32\DRIVERS\sym_hi.sys (LSI Logic)
DRV - (symc8xx) – C:\WINDOWS\System32\DRIVERS\symc8xx.sys (LSI Logic)
DRV - (symc810) – C:\WINDOWS\System32\DRIVERS\symc810.sys (Symbios Logic Inc.)
DRV - (ultra) – C:\WINDOWS\System32\DRIVERS\ultra.sys (Promise Technology, Inc.)
DRV - (ql12160) – C:\WINDOWS\System32\DRIVERS\ql12160.sys (QLogic Corporation)
DRV - (ql1080) – C:\WINDOWS\System32\DRIVERS\ql1080.sys (QLogic Corporation)
DRV - (ql1280) – C:\WINDOWS\System32\DRIVERS\ql1280.sys (QLogic Corporation)
DRV - (dac2w2k) – C:\WINDOWS\System32\DRIVERS\dac2w2k.sys (Mylex Corporation)
DRV - (mraid35x) – C:\WINDOWS\System32\DRIVERS\mraid35x.sys (American Megatrends Inc.)
DRV - (asc) – C:\WINDOWS\System32\DRIVERS\asc.sys (Advanced System Products, Inc.)
DRV - (asc3550) – C:\WINDOWS\System32\DRIVERS\asc3550.sys (Advanced System Products, Inc.)
DRV - (AliIde) – C:\WINDOWS\System32\DRIVERS\aliide.sys (Acer Laboratories Inc.)
DRV - (CmdIde) – C:\WINDOWS\System32\DRIVERS\cmdide.sys (CMD Technology, Inc.)
DRV - (EL90XBC) – C:\WINDOWS\SYSTEM32\DRIVERS\EL90XBC5.SYS (3Com Corporation)
DRV - (BrPar) – C:\WINDOWS\System32\drivers\BrPar.sys (Brother Industries Ltd.)
DRV - (NetworkX) – C:\WINDOWS\system32\ckldrv.sys ()


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,StartPage = http://www.optonline.net
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.optonline.net
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultName = Google
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultURL = http://www.google.com/search?q={searchTerm…tf8&oe=utf8
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.smokinholsters.com/
IE - HKCU\..\URLSearchHook: *{CFBFAE00-17A6-11D0-99CB-00C04FD64497} - Reg Error: Key error. File not found
IE - HKCU\..\URLSearchHook: {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG8\Toolbar\IEToolbar.dll ()
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0


[2004/07/04 22:38:45 | 000,000,000 | —D | M] – C:\Documents and Settings\Neil\Application Data\Mozilla\Firefox\Profiles\default.exe\extensions
[2004/07/04 22:38:45 | 000,000,000 | —D | M] (DOM Inspector) – C:\Documents and Settings\Neil\Application Data\Mozilla\Firefox\Profiles\default.exe\extensions\{641d8d09-7dda-4850-8228-ac0ab65e2ac9}
[2004/07/04 22:38:45 | 000,000,000 | —D | M] (Firefox (default)) – C:\Documents and Settings\Neil\Application Data\Mozilla\Firefox\Profiles\default.exe\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}

O1 HOSTS File: ([2008/10/14 09:11:00 | 000,266,850 | R— | M]) - C:\WINDOWS\SYSTEM32\DRIVERS\ETC\HOSTS
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: 127.0.0.1 www.007guard.com
O1 - Hosts: 127.0.0.1 007guard.com
O1 - Hosts: 127.0.0.1 008i.com
O1 - Hosts: 127.0.0.1 www.008k.com
O1 - Hosts: 127.0.0.1 008k.com
O1 - Hosts: 127.0.0.1 www.00hq.com
O1 - Hosts: 127.0.0.1 00hq.com
O1 - Hosts: 127.0.0.1 010402.com
O1 - Hosts: 127.0.0.1 www.032439.com
O1 - Hosts: 127.0.0.1 032439.com
O1 - Hosts: 127.0.0.1 www.100888290cs.com
O1 - Hosts: 127.0.0.1 100888290cs.com
O1 - Hosts: 127.0.0.1 www.100sexlinks.com
O1 - Hosts: 127.0.0.1 100sexlinks.com
O1 - Hosts: 127.0.0.1 www.10sek.com
O1 - Hosts: 127.0.0.1 10sek.com
O1 - Hosts: 127.0.0.1 www.123topsearch.com
O1 - Hosts: 127.0.0.1 123topsearch.com
O1 - Hosts: 127.0.0.1 www.132.com
O1 - Hosts: 127.0.0.1 132.com
O1 - Hosts: 127.0.0.1 www.136136.net
O1 - Hosts: 127.0.0.1 136136.net
O1 - Hosts: 127.0.0.1 www.163ns.com
O1 - Hosts: 127.0.0.1 163ns.com
O1 - Hosts: 9243 more lines…
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (no name) - {243B17DE-77C7-46BF-B94B-0B5F309A0E64} - C:\Program Files\Microsoft Money\System\mnyside.dll (Microsoft Corporation)
O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll (AVG Technologies CZ, s.r.o.)
O2 - BHO: (Spybot-S&D IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O2 - BHO: (no name) - {724d43a9-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\RoboForm.dll (Siber Systems Inc.)
O2 - BHO: (AVG Security Toolbar BHO) - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG8\Toolbar\IEToolbar.dll ()
O2 - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (JQSIEStartDetectorImpl Class) - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll (Sun Microsystems, Inc.)
O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - No CLSID value found.
O3 - HKLM\..\Toolbar: (&RoboForm) - {724d43a0-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\RoboForm.dll (Siber Systems Inc.)
O3 - HKLM\..\Toolbar: (AVG Security Toolbar) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - C:\Program Files\AVG\AVG8\Toolbar\IEToolbar.dll ()
O3 - HKCU\..\Toolbar\ShellBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {4B3803EA-5230-4DC3-A7FC-33638F3D3542} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (&RoboForm) - {724D43A0-0D85-11D4-9908-00400523E39A} - C:\Program Files\Siber Systems\AI RoboForm\RoboForm.dll (Siber Systems Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (AVG Security Toolbar) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - C:\Program Files\AVG\AVG8\Toolbar\IEToolbar.dll ()
O4 - HKLM..\Run: [Apoint] C:\Program Files\Apoint\Apoint.exe (Alps Electric Co., Ltd.)
O4 - HKLM..\Run: [ATIModeChange] C:\WINDOWS\System32\Ati2mdxx.exe (ATI Technologies, Inc.)
O4 - HKLM..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe (ATI Technologies, Inc.)
O4 - HKLM..\Run: [AVG8_TRAY] C:\Program Files\AVG\AVG8\avgtray.exe (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [Dell QuickSet] C:\Program Files\Dell\QuickSet\quickset.exe ()
O4 - HKLM..\Run: [dellsupportcenter] C:\Program Files\Dell Support Center\bin\sprtcmd.exe (SupportSoft, Inc.)
O4 - HKLM..\Run: [dscactivate] C:\Program Files\Dell Support Center\gs_agent\custom\dsca.exe ( )
O4 - HKLM..\Run: [DVDSentry] C:\WINDOWS\SYSTEM32\DSentry.exe (Dell - Advanced Desktop Engineering)
O4 - HKLM..\Run: [PDUiP6000DMon] C:\Program Files\Canon\Memory Card Utility\PIXMA iP6000D\PDUiP6000DMon.exe (CANON INC.)
O4 - HKLM..\Run: [PDUiP6000DTskbr] C:\Program Files\Canon\Memory Card Utility\PIXMA iP6000D\PDUiP6000DTskbr.exe (CANON INC.)
O4 - HKLM..\Run: [QuickTime Task] C:\Program Files\QuickTime\qttask.exe (Apple Computer, Inc.)
O4 - HKLM..\Run: [SandIcon] C:\ImageMate CompactFlash USB\SandIcon.exe ()
O4 - HKLM..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre6\bin\jusched.exe (Sun Microsystems, Inc.)
O4 - HKLM..\Run: [TkBellExe] C:\Program Files\Common Files\Real\Update_OB\realsched.exe (RealNetworks, Inc.)
O4 - HKLM..\Run: [Verizon_McciTrayApp] C:\Program Files\Verizon\McciTrayApp.exe File not found
O4 - HKCU..\Run: [DellSupportCenter] C:\Program Files\Dell Support Center\bin\sprtcmd.exe (SupportSoft, Inc.)
O4 - HKCU..\Run: [RoboForm] C:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe (Siber Systems)
O4 - HKCU..\Run: [Uniblue Registry Booster] C:\Program Files\Uniblue\Registry Booster\RegistryBooster.exe (Uniblue Registry Booster)
O4 - HKCU..\Run: [updateMgr] C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe (Adobe Systems Incorporated)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe (Adobe Systems Incorporated)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE (Microsoft Corporation)
O4 - Startup: C:\Documents and Settings\Neil\Start Menu\Programs\Startup\MemoKit.lnk = C:\Program Files\MemoKit\mk.exe ()
O4 - Startup: C:\Documents and Settings\Neil\Start Menu\Programs\Startup\Webshots.lnk = C:\Program Files\Webshots\Launcher.exe ()
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Main present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\PhishingFilter present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O8 - Extra context menu item: Customize Menu - C:\Program Files\Siber Systems\AI RoboForm\RoboFormComCustomizeIEMenu.html ()
O8 - Extra context menu item: Fill Forms - C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html ()
O8 - Extra context menu item: RoboForm Toolbar - C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html ()
O8 - Extra context menu item: Save Forms - C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html ()
O9 - Extra Button: Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html ()
O9 - Extra 'Tools' menuitem : Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html ()
O9 - Extra Button: Save - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html ()
O9 - Extra 'Tools' menuitem : Save Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html ()
O9 - Extra Button: RoboForm - {724d43aa-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html ()
O9 - Extra 'Tools' menuitem : RoboForm Toolbar - {724d43aa-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html ()
O9 - Extra 'Tools' menuitem : Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O9 - Extra Button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - C:\Program Files\Microsoft Money\System\mnyside.dll (Microsoft Corporation)
O15 - HKCU\..Trusted Domains: ([]msn in My Computer)
O16 - DPF: {01113300-3E00-11D2-8470-0060089874ED} https://activatemyfios.verizon.net/sdcCommo…IOS/tgctlcm.cab (Support.com Configuration Class)
O16 - DPF: {01A88BB1-1174-41EC-ACCB-963509EAE56B} http://support.dell.com/systemprofiler/SysPro.CAB (SysProWmi Class)
O16 - DPF: {02BCC737-B171-4746-94C9-0D8A0B2C0089} http://office.microsoft.com/templates/ieawsdc.cab (Microsoft Office Template and Media Control)
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} http://www.apple.com/qtactivex/qtplugin.cab (QuickTime Object)
O16 - DPF: {05CA9FB0-3E3E-4B36-BF41-0E3A5CAA8CD8} http://download.microsoft.com/download/d/c…/OGAControl.cab (Office Genuine Advantage Validation Tool)
O16 - DPF: {0C568603-D79D-11D2-87A7-00C04FF158BB} http://download.mcafee.com/molbin/Shared/MGBrwFld.cab (BrowseFolderPopup Class)
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} http://upload.facebook.com/controls/2008.1…toUploader5.cab (Facebook Photo Uploader 5 Control)
O16 - DPF: {11260943-421B-11D0-8EAC-0000C07D88CF} http://www.ipix.com/viewers/ipixx.cab (iPIX ActiveX Control)
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://fpdownload.macromedia.com/get/shock…director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://download.microsoft.com/download/3/9…heckControl.cab (Windows Genuine Advantage Validation Tool)
O16 - DPF: {1E3F1348-4370-4BBE-A67A-CC7ED824CA85} http://download.microsoft.com/download/7/4…helpcontrol.cab (Microsoft Genuine Advantage Self Support Tool)
O16 - DPF: {33564D57-0000-0010-8000-00AA00389B71} http://download.microsoft.com/download/F/6…922/wmv9VCM.CAB (Reg Error: Key error.)
O16 - DPF: {362C56AA-6E4F-40C7-A0B5-85501DBDAD77} http://i.dell.com/images/global/js/scanner/SysProExe.cab (Scanner.SysScanner)
O16 - DPF: {36C417C6-13C6-448B-9784-DD73A93B0582} http://download.mcafee.com/molbin/shared/m…56/mcinsctl.cab (Reg Error: Key error.)
O16 - DPF: {3BFFE033-BF43-11D5-A271-00A024A51325} https://notes1.cc.sunysb.edu/iNotes6W.cab (iNotes6 Class)
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} http://download.mcafee.com/molbin/shared/m…83/mcinsctl.cab (Reg Error: Key error.)
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} http://groups.msn.com/controls/PhotoUC/MsnPUpld.cab (MSN Photo Upload Tool)
O16 - DPF: {5C6698D9-7BE4-4122-8EC5-291D84DBD4A0} http://upload.facebook.com/controls/Facebo…toUploader3.cab (Facebook Photo Uploader 4 Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_17)
O16 - DPF: {94B82441-A413-4E43-8422-D49930E69764} https://echat.us.dell.com/Media/VisitorChat/TLIEFlash.CAB (TLIEFlashObj Class)
O16 - DPF: {A8658086-E6AC-4957-BC8E-7D54A7E8A78D} http://www.microsoft.com/security/controls/DoomCln.CAB (DoomCln Object)
O16 - DPF: {A8F2B9BD-A6A0-486A-9744-18920D898429} http://www.sibelius.com/download/software/…tiveXPlugin.cab (ScorchPlugin Class)
O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} http://download.mcafee.com/molbin/shared/m…,20/mcgdmgr.cab (Reg Error: Key error.)
O16 - DPF: {C432C4BD-3566-411C-8F3C-E5E0D3AE5D33} http://viewers.multicastmedia.com/common/m…MINIBrowser.CAB (CBrowser Class)
O16 - DPF: {CAFEEFAC-0014-0002-0006-ABCDEFFEDCBA} http://java.sun.com/products/plugin/autodl…indows-i586.cab (Java Plug-in 1.4.2_06)
O16 - DPF: {CAFEEFAC-0015-0000-0002-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-…indows-i586.cab (Java Plug-in 1.5.0_02)
O16 - DPF: {CAFEEFAC-0015-0000-0004-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-…indows-i586.cab (Java Plug-in 1.5.0_04)
O16 - DPF: {CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-…indows-i586.cab (Java Plug-in 1.5.0_06)
O16 - DPF: {CAFEEFAC-0015-0000-0009-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-…indows-i586.cab (Java Plug-in 1.5.0_09)
O16 - DPF: {CAFEEFAC-0015-0000-0010-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-…indows-i586.cab (Java Plug-in 1.5.0_10)
O16 - DPF: {CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_01)
O16 - DPF: {CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_02)
O16 - DPF: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_03)
O16 - DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_05)
O16 - DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_07)
O16 - DPF: {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_17)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_17)
O16 - DPF: {D27CDB6E-0000-0000-0000-000000000000} http://download.macromedia.com/pub/shockwa…ash/swflash.cab (Reg Error: Key error.)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab (Shockwave Flash Object)
O16 - DPF: {F5820AD3-9B20-423E-B2AA-7AF2B4055746} http://download.paltalk.com/download/0.x/regdload.cab (CRegistryDownload Class)
O16 - DPF: {F58E1CEF-A068-4C15-BA5E-587CAF3EE8C6} http://chat.msn.com/bin/msnchat45.cab (MSN Chat Control 4.5)
O16 - DPF: DirectAnimation Java Classes Reg Error: Value error. (Reg Error: Key error.)
O16 - DPF: Microsoft XML Parser for Java Reg Error: Value error. (Reg Error: Key error.)
O16 - DPF: vzTCPConfig http://www2.verizon.net/help/fios_settings…vzTCPConfig.CAB (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll (AVG Technologies CZ, s.r.o.)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\AtiExtEvent: DllName - Ati2evxx.dll - C:\WINDOWS\System32\ati2evxx.dll ()
O20 - Winlogon\Notify\avgrsstarter: DllName - avgrsstx.dll - C:\WINDOWS\System32\avgrsstx.dll (AVG Technologies CZ, s.r.o.)
O24 - Desktop WallPaper: C:\Documents and Settings\Neil\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Neil\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2002/09/03 08:59:58 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O33 - MountPoints2\{907ca763-1772-11db-befe-00062541da30}\Shell - "" = AutoRun
O33 - MountPoints2\{907ca763-1772-11db-befe-00062541da30}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{907ca763-1772-11db-befe-00062541da30}\Shell\AutoRun\command - "" = F:\LaunchU3.exe – File not found
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - comfile [open] – "%1" %*
O35 - exefile [open] – "%1" %*

========== Files/Folders - Created Within 30 Days ==========

[2010/03/01 20:42:42 | 000,000,000 | —D | C] – C:\Documents and Settings\Neil\Desktop\tdsskiller
[2010/03/01 07:53:44 | 000,000,000 | —D | C] – C:\Documents and Settings\Neil\Desktop\scans
[2010/02/28 23:01:44 | 000,000,000 | —D | C] – C:\_OTL
[2010/02/28 09:10:19 | 000,549,888 | —- | C] (OldTimer Tools) – C:\Documents and Settings\Neil\Desktop\OTL.exe
[2010/02/28 08:43:51 | 000,000,000 | —D | M] – C:\Documents and Settings\NetworkService\Application Data\AdobeUM
[2010/02/28 08:43:40 | 000,000,000 | —D | M] – C:\Documents and Settings\NetworkService\Local Settings\Application Data\Adobe
[2010/02/27 13:29:40 | 000,177,928 | —- | C] (Kaspersky Lab) – C:\Documents and Settings\Neil\Desktop\TDSSKiller.exe
[2010/02/25 23:44:50 | 000,000,000 | —D | M] – C:\Documents and Settings\NetworkService\Application Data\Adobe
[2010/02/25 11:44:49 | 000,000,000 | —D | M] – C:\Documents and Settings\NetworkService\Application Data\Macromedia
[2010/02/24 15:12:26 | 000,000,000 | —D | M] – C:\Documents and Settings\LocalService\Application Data\Real
[2010/02/24 09:16:45 | 000,000,000 | —D | M] – C:\Documents and Settings\LocalService\Application Data\Adobe
[2009/06/29 07:25:48 | 000,000,000 | —D | M] – C:\Documents and Settings\LocalService\Application Data\AVGTOOLBAR
[2008/10/22 09:05:35 | 000,000,000 | –SD | M] – C:\Documents and Settings\NetworkService\Application Data\Microsoft
[2008/10/22 09:05:35 | 000,000,000 | –SD | M] – C:\Documents and Settings\LocalService\Application Data\Microsoft
[2008/10/22 09:05:35 | 000,000,000 | —D | M] – C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft
[2008/10/22 09:05:35 | 000,000,000 | —D | M] – C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft
[2007/02/09 00:19:36 | 000,000,000 | —D | M] – C:\Documents and Settings\LocalService\Local Settings\Application Data\Adobe
[2006/11/30 11:53:22 | 000,000,000 | —D | M] – C:\Documents and Settings\LocalService\Application Data\Gtek
[2006/11/05 05:05:42 | 000,000,000 | —D | M] – C:\Documents and Settings\LocalService\Application Data\SlimBrowser
[2006/06/20 21:19:58 | 000,000,000 | —D | M] – C:\Documents and Settings\LocalService\Application Data\Macromedia
[2005/04/30 09:43:38 | 000,000,000 | —D | M] – C:\Documents and Settings\LocalService\Local Settings\Application Data\Help
[2005/04/30 09:43:38 | 000,000,000 | —D | M] – C:\Documents and Settings\LocalService\Application Data\Help
[2004/05/08 20:06:28 | 000,000,000 | —D | M] – C:\Documents and Settings\LocalService\Local Settings\Application Data\Google
[2003/09/05 10:16:53 | 000,000,000 | —D | M] – C:\Documents and Settings\LocalService\Application Data\McAfee.com Personal Firewall

========== Files - Modified Within 30 Days ==========

[2010/03/01 21:14:55 | 000,000,608 | —- | M] () – C:\WINDOWS\aclockz6.dat
[2010/03/01 20:50:44 | 000,000,006 | -H– | M] () – C:\WINDOWS\tasks\SA.DAT
[2010/03/01 20:50:20 | 000,002,048 | –S- | M] () – C:\WINDOWS\BOOTSTAT.DAT
[2010/03/01 20:48:46 | 009,175,040 | -H– | M] () – C:\Documents and Settings\Neil\NTUSER.DAT
[2010/03/01 20:48:46 | 000,000,178 | -HS- | M] () – C:\Documents and Settings\Neil\NTUSER.INI
[2010/03/01 20:42:45 | 000,177,928 | —- | M] (Kaspersky Lab) – C:\Documents and Settings\Neil\Desktop\TDSSKiller.exe
[2010/03/01 20:40:53 | 000,154,657 | —- | M] () – C:\Documents and Settings\Neil\Desktop\tdsskiller.zip
[2010/03/01 09:07:53 | 056,483,219 | —- | M] () – C:\WINDOWS\System32\drivers\Avg\incavi.avm
[2010/03/01 00:06:27 | 000,001,671 | —- | M] () – C:\Documents and Settings\Neil\Desktop\user.zip
[2010/02/28 23:45:47 | 000,001,170 | —- | M] () – C:\WINDOWS\System32\WPA.DBL
[2010/02/28 23:34:58 | 000,001,744 | -H– | M] () – C:\WINDOWS\System32\komobome
[2010/02/28 16:52:00 | 000,027,144 | —- | M] () – C:\Documents and Settings\Neil\Desktop\SafeBoot-for-Windows-XP-SP3.reg
[2010/02/28 13:29:02 | 000,100,352 | -HS- | M] () – C:\WINDOWS\System32\janeguwo.dll
[2010/02/28 13:29:02 | 000,079,872 | -HS- | M] () – C:\WINDOWS\System32\feyumaze.exe
[2010/02/28 13:29:02 | 000,070,656 | -HS- | M] () – C:\WINDOWS\System32\yuterahi.dll
[2010/02/28 13:29:02 | 000,047,104 | -HS- | M] () – C:\WINDOWS\System32\hatutiza.dll
[2010/02/28 12:37:01 | 000,047,104 | —- | M] () – C:\WINDOWS\System32\zelovumi.dll
[2010/02/28 12:35:52 | 000,070,656 | —- | M] () – C:\WINDOWS\System32\yikujode.dll
[2010/02/28 09:10:20 | 000,549,888 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Neil\Desktop\OTL.exe
[2010/02/27 07:35:53 | 000,002,469 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Dell Support Center.lnk
[2010/02/26 15:18:20 | 000,293,376 | —- | M] () – C:\Documents and Settings\Neil\Desktop\v8vqkne5.exe
[2010/02/26 07:19:28 | 000,000,000 | —- | M] () – C:\Documents and Settings\Neil\defogger_reenable
[2010/02/26 07:11:27 | 000,050,477 | —- | M] () – C:\Documents and Settings\Neil\Desktop\Defogger.exe
[2010/02/26 00:01:03 | 003,932,214 | —- | M] () – C:\WINDOWS\Webshots for Neil.bmp
[2010/02/25 22:59:35 | 000,000,710 | —- | M] () – C:\Documents and Settings\Neil\Start Menu\Programs\Startup\Webshots.lnk
[2010/02/24 01:44:49 | 000,142,495 | —- | M] () – C:\WINDOWS\System32\drivers\Avg\microavi.avg
[2010/02/24 01:44:46 | 000,492,629 | —- | M] () – C:\WINDOWS\System32\drivers\Avg\miniavi.avg
[2010/02/24 01:44:41 | 006,061,540 | —- | M] () – C:\WINDOWS\System32\drivers\Avg\avi7.avg
[2010/02/23 20:02:48 | 000,054,156 | -H– | M] () – C:\WINDOWS\QTFont.qfn
[2010/02/20 11:57:43 | 000,059,392 | —- | M] () – C:\Documents and Settings\Neil\My Documents\TAXES and FAFSA 2009.doc
[2010/02/11 05:27:24 | 000,001,374 | —- | M] () – C:\WINDOWS\imsins.BAK
[2010/02/10 16:55:27 | 000,000,452 | —- | M] () – C:\Documents and Settings\Neil\My Documents\spider.sav
[2010/02/07 16:39:29 | 000,050,688 | —- | M] () – C:\Documents and Settings\Neil\My Documents\TAXES 2009 for accountant NO SAM.doc
[2010/02/07 16:37:34 | 000,024,576 | —- | M] () – C:\Documents and Settings\Neil\My Documents\SAMSON FLANCBAUM TAXES 2009.doc
[2010/02/07 15:33:07 | 000,024,576 | —- | M] () – C:\Documents and Settings\Neil\My Documents\Smokin Taxes 2009.doc
[2010/02/06 20:40:02 | 000,054,272 | —- | M] () – C:\Documents and Settings\Neil\My Documents\TAXES 2009.doc
[2010/02/06 20:32:16 | 000,052,736 | —- | M] () – C:\Documents and Settings\Neil\My Documents\TAXES 2009 for accountant.doc
[2010/02/06 16:46:13 | 004,456,448 | —- | M] () – C:\Documents and Settings\Neil\My Documents\My Money.mny
[2010/02/06 15:49:41 | 000,024,064 | —- | M] () – C:\Documents and Settings\Neil\My Documents\Smokin Taxes 2008.doc
[2010/02/05 11:41:40 | 000,001,409 | —- | M] () – C:\WINDOWS\QTFont.for

========== Files Created - No Company Name ==========

[2010/03/01 20:40:45 | 000,154,657 | —- | C] () – C:\Documents and Settings\Neil\Desktop\tdsskiller.zip
[2010/03/01 00:09:14 | 000,027,144 | —- | C] () – C:\Documents and Settings\Neil\Desktop\SafeBoot-for-Windows-XP-SP3.reg
[2010/03/01 00:06:23 | 000,001,671 | —- | C] () – C:\Documents and Settings\Neil\Desktop\user.zip
[2010/02/28 23:05:17 | 000,001,744 | -H– | C] () – C:\WINDOWS\System32\komobome
[2010/02/28 13:29:02 | 000,100,352 | -HS- | C] () – C:\WINDOWS\System32\janeguwo.dll
[2010/02/28 13:29:02 | 000,079,872 | -HS- | C] () – C:\WINDOWS\System32\feyumaze.exe
[2010/02/28 13:29:02 | 000,070,656 | -HS- | C] () – C:\WINDOWS\System32\yuterahi.dll
[2010/02/28 13:29:02 | 000,047,104 | -HS- | C] () – C:\WINDOWS\System32\hatutiza.dll
[2010/02/28 12:37:01 | 000,047,104 | —- | C] () – C:\WINDOWS\System32\zelovumi.dll
[2010/02/28 12:35:52 | 000,070,656 | —- | C] () – C:\WINDOWS\System32\yikujode.dll
[2010/02/27 07:35:53 | 000,002,469 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Dell Support Center.lnk
[2010/02/26 15:18:19 | 000,293,376 | —- | C] () – C:\Documents and Settings\Neil\Desktop\v8vqkne5.exe
[2010/02/26 07:19:28 | 000,000,000 | —- | C] () – C:\Documents and Settings\Neil\defogger_reenable
[2010/02/26 07:11:27 | 000,050,477 | —- | C] () – C:\Documents and Settings\Neil\Desktop\Defogger.exe
[2010/02/07 16:31:12 | 000,050,688 | —- | C] () – C:\Documents and Settings\Neil\My Documents\TAXES 2009 for accountant NO SAM.doc
[2010/02/07 16:30:39 | 000,024,576 | —- | C] () – C:\Documents and Settings\Neil\My Documents\SAMSON FLANCBAUM TAXES 2009.doc
[2010/02/07 15:26:55 | 000,024,576 | —- | C] () – C:\Documents and Settings\Neil\My Documents\Smokin Taxes 2009.doc
[2010/02/06 20:39:38 | 000,059,392 | —- | C] () – C:\Documents and Settings\Neil\My Documents\TAXES and FAFSA 2009.doc
[2010/02/06 20:16:13 | 000,052,736 | —- | C] () – C:\Documents and Settings\Neil\My Documents\TAXES 2009 for accountant.doc
[2010/02/05 11:41:40 | 000,054,156 | -H– | C] () – C:\WINDOWS\QTFont.qfn
[2010/02/05 11:41:40 | 000,001,409 | —- | C] () – C:\WINDOWS\QTFont.for
[2008/05/09 07:44:34 | 000,141,312 | —- | C] () – C:\WINDOWS\System32\drivers\sp_rsdrv2.sys
[2008/03/06 00:36:33 | 000,086,016 | —- | C] () – C:\WINDOWS\System32\ati2evxx.dll
[2007/01/23 15:15:22 | 000,676,224 | —- | C] () – C:\WINDOWS\System32\OGACheckControl.DLL
[2006/10/20 16:15:34 | 000,001,359 | —- | C] () – C:\Documents and Settings\All Users\Application Data\QTSBandwidthCache
[2006/01/11 13:25:19 | 000,000,576 | —- | C] () – C:\WINDOWS\_delis32.ini
[2006/01/11 13:25:13 | 000,001,216 | —- | C] () – C:\WINDOWS\_isenv31.ini
[2006/01/11 13:25:12 | 000,000,521 | —- | C] () – C:\WINDOWS\_iserr31.ini
[2006/01/09 12:28:27 | 000,000,313 | —- | C] () – C:\WINDOWS\BRDIAG.INI
[2006/01/09 12:28:27 | 000,000,145 | —- | C] () – C:\WINDOWS\BRVIDEO.INI
[2006/01/09 12:28:26 | 000,000,023 | —- | C] () – C:\WINDOWS\Brownie.ini
[2006/01/09 12:28:17 | 000,026,624 | —- | C] () – C:\WINDOWS\System32\BRGSRC32.DLL
[2006/01/09 12:28:17 | 000,004,608 | —- | C] () – C:\WINDOWS\System32\BRGSRC16.DLL
[2006/01/09 12:28:16 | 000,077,824 | —- | C] () – C:\WINDOWS\System32\BROSNMP.DLL
[2006/01/09 12:28:12 | 000,009,013 | —- | C] () – C:\WINDOWS\HL-2040.INI
[2006/01/09 12:27:26 | 000,000,426 | —- | C] () – C:\WINDOWS\BRWMARK.INI
[2005/11/29 00:11:56 | 000,000,037 | —- | C] () – C:\WINDOWS\ipixActivex.ini
[2005/08/09 17:12:28 | 003,596,288 | —- | C] () – C:\WINDOWS\System32\qt-dx331.dll
[2004/11/18 14:30:13 | 000,000,000 | —- | C] () – C:\WINDOWS\OpPrintServer.INI
[2004/11/18 14:21:16 | 000,007,680 | —- | C] () – C:\WINDOWS\System32\CNMVS69.DLL
[2004/09/11 21:54:11 | 000,000,063 | —- | C] () – C:\WINDOWS\mdm.ini
[2004/09/03 17:52:50 | 000,196,608 | —- | C] () – C:\WINDOWS\System32\GCCollection.dll
[2004/06/30 15:04:46 | 000,040,960 | —- | C] () – C:\WINDOWS\System32\SDelete.dll
[2004/04/21 13:34:48 | 000,071,749 | —- | C] () – C:\WINDOWS\HCExtOutput.dll
[2004/04/21 13:34:48 | 000,000,823 | —- | C] () – C:\WINDOWS\TSC.ini
[2004/04/21 13:34:32 | 000,000,170 | —- | C] () – C:\WINDOWS\GetServer.ini
[2004/03/25 11:20:56 | 000,000,127 | —- | C] () – C:\Documents and Settings\Neil\Local Settings\Application Data\fusioncache.dat
[2004/03/25 08:33:21 | 000,000,024 | —- | C] () – C:\WINDOWS\wininit.ini
[2004/03/25 08:33:05 | 000,000,002 | —- | C] () – C:\WINDOWS\msoffice.ini
[2004/03/07 13:51:00 | 000,024,924 | —- | C] () – C:\WINDOWS\System32\openports.dll
[2004/02/09 15:42:28 | 000,000,071 | —- | C] () – C:\WINDOWS\Theme Uninstall.ini
[2003/10/14 15:54:32 | 000,030,720 | —- | C] () – C:\Documents and Settings\Neil\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2003/10/03 17:10:14 | 000,000,036 | —- | C] () – C:\WINDOWS\Crypkey.ini
[2003/10/03 17:10:09 | 000,024,608 | —- | C] () – C:\WINDOWS\System32\Ckldrv.sys
[2003/10/03 17:10:09 | 000,018,432 | —- | C] () – C:\WINDOWS\Setup_ck.dll
[2003/10/03 17:10:08 | 000,000,000 | —- | C] () – C:\WINDOWS\PROTOCOL.INI
[2003/08/22 19:23:38 | 000,000,026 | —- | C] () – C:\WINDOWS\INTUIT.INI
[2003/07/23 18:57:41 | 000,002,154 | —- | C] () – C:\WINDOWS\Solitaire.ini
[2003/07/11 19:12:37 | 000,000,210 | —- | C] () – C:\WINDOWS\cdPlayer.ini
[2003/07/10 06:55:57 | 000,000,208 | —- | C] () – C:\WINDOWS\QUICKEN.INI
[2003/07/10 01:36:45 | 000,000,000 | —- | C] () – C:\WINDOWS\NSREX.INI
[2003/07/10 00:53:16 | 000,000,054 | —- | C] () – C:\WINDOWS\setihome.ini
[2003/07/09 23:12:55 | 000,000,034 | —- | C] () – C:\WINDOWS\alohabob.INI
[2003/07/03 07:29:25 | 000,000,061 | —- | C] () – C:\WINDOWS\smscfg.ini
[2003/07/03 07:19:29 | 000,000,376 | —- | C] () – C:\WINDOWS\ODBC.INI
[2003/07/03 07:04:28 | 000,000,893 | —- | C] () – C:\WINDOWS\orun32.ini
[2003/07/03 06:35:24 | 000,000,546 | —- | C] () – C:\WINDOWS\System32\OEMINFO.INI
[2002/10/28 10:53:49 | 000,210,944 | —- | C] () – C:\WINDOWS\System32\MSVCRT10.DLL
[2002/10/28 10:53:43 | 000,000,083 | —- | C] () – C:\WINDOWS\KPCMS.INI
[2002/07/03 10:57:48 | 000,013,203 | —- | C] () – C:\WINDOWS\System32\drivers\packet.sys
[2002/01/08 19:03:10 | 000,077,824 | —- | C] () – C:\WINDOWS\System32\MiniBrowser.dll
[2001/12/17 21:30:43 | 000,000,359 | —- | C] () – C:\WINDOWS\smsafari.ini
[2001/12/17 21:17:17 | 000,012,416 | —- | C] () – C:\WINDOWS\System32\VRX1.DLL
[2001/12/17 21:17:16 | 000,027,136 | —- | C] () – C:\WINDOWS\System32\VERMONT1.DLL
[2001/12/17 21:17:11 | 000,107,520 | —- | C] () – C:\WINDOWS\System32\SIMANT.DLL
[2001/12/03 15:58:32 | 000,286,208 | —- | C] () – C:\WINDOWS\System32\DCSSDK32.dll
[2001/12/03 15:58:32 | 000,107,456 | —- | C] () – C:\WINDOWS\System32\SH33W32.DLL
[2001/11/21 19:44:10 | 000,003,413 | —- | C] () – C:\Documents and Settings\Neil\Application Data\dw.log
[2001/07/05 16:36:07 | 000,000,370 | —- | C] () – C:\WINDOWS\KA.INI
[2001/05/30 08:47:44 | 000,110,592 | —- | C] () – C:\WINDOWS\System32\cdtool.dll
[2001/05/12 16:10:41 | 000,056,832 | —- | C] () – C:\WINDOWS\System32\iyvu9_32.dll
[2001/05/12 11:01:14 | 000,167,936 | —- | C] () – C:\WINDOWS\System32\XFILEXR.DLL
[2001/05/12 10:59:13 | 000,040,960 | —- | C] () – C:\WINDOWS\System32\OEMREG.DLL
[2001/05/12 10:58:38 | 000,008,576 | —- | C] () – C:\WINDOWS\System32\ICMUPG.DLL
[2001/05/12 10:54:15 | 000,028,672 | —- | C] () – C:\WINDOWS\System32\NETBIOS.DLL
[2001/05/12 10:53:38 | 000,188,416 | —- | C] () – C:\WINDOWS\System32\MEMBG.DLL
[2001/05/12 10:51:28 | 000,002,490 | —- | C] () – C:\WINDOWS\System32\DLCNDI.DLL
[2001/05/12 09:46:50 | 000,009,216 | —- | C] () – C:\WINDOWS\System32\Spktrn32.dll
[2001/05/12 09:29:56 | 000,040,448 | —- | C] () – C:\WINDOWS\System32\hcfuninst.dll
[2001/05/12 09:29:56 | 000,028,672 | —- | C] () – C:\WINDOWS\System32\hcfapi.dll
[2000/10/21 01:21:26 | 000,363,520 | —- | C] () – C:\WINDOWS\System32\psisdecd.dll
[1999/12/07 00:00:00 | 000,024,975 | —- | C] () – C:\WINDOWS\twain_16.dll
[1999/07/23 12:46:48 | 000,000,116 | —- | C] () – C:\WINDOWS\AuHCcup1.ini
[1999/07/23 09:53:20 | 000,129,536 | —- | C] () – C:\WINDOWS\AuHCcup1.dll
[1999/01/22 17:46:58 | 000,065,536 | —- | C] () – C:\WINDOWS\System32\MSRTEDIT.DLL
[1980/01/01 00:00:00 | 000,031,744 | —- | C] () – C:\WINDOWS\System32\mdmmoh.dll
[1979/12/31 11:29:50 | 000,038,352 | —- | C] () – C:\WINDOWS\System32\NAVAPGUI.DLL

========== LOP Check ==========

[2010/02/28 11:29:50 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\AVG Security Toolbar
[2008/10/23 21:50:10 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Banner Maker Pro 7
[2007/11/03 14:11:59 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\GlobalSCAPE
[2005/04/03 22:08:03 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\RoboForm
[2008/08/22 07:34:02 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Spyware Terminator
[2008/03/20 08:50:30 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\SupportSoft
[2007/11/08 14:55:57 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TEMP
[2007/12/03 11:27:07 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Viewpoint
[2008/12/30 21:58:40 | 000,000,000 | —D | M] – C:\Documents and Settings\Neil\Application Data\AVGTOOLBAR
[2007/04/25 18:03:39 | 000,000,000 | —D | M] – C:\Documents and Settings\Neil\Application Data\Digital Photo Slide Show
[2007/11/03 14:11:52 | 000,000,000 | —D | M] – C:\Documents and Settings\Neil\Application Data\GlobalSCAPE
[2003/07/09 17:05:42 | 000,000,000 | —D | M] – C:\Documents and Settings\Neil\Application Data\InterVideo
[2006/04/06 15:10:57 | 000,000,000 | —D | M] – C:\Documents and Settings\Neil\Application Data\Kensington
[2007/05/17 22:28:21 | 000,000,000 | —D | M] – C:\Documents and Settings\Neil\Application Data\KompoZer
[2004/04/20 16:38:15 | 000,000,000 | —D | M] – C:\Documents and Settings\Neil\Application Data\Leadertech
[2007/07/12 21:22:05 | 000,000,000 | —D | M] – C:\Documents and Settings\Neil\Application Data\Novagraph
[2010/02/25 11:47:37 | 000,000,000 | —D | M] – C:\Documents and Settings\Neil\Application Data\Registry Booster
[2004/07/10 01:31:42 | 000,000,000 | —D | M] – C:\Documents and Settings\Neil\Application Data\Screen Calendar
[2010/03/01 20:46:42 | 000,000,000 | —D | M] – C:\Documents and Settings\Neil\Application Data\SlimBrowser
[2008/08/21 22:42:02 | 000,000,000 | —D | M] – C:\Documents and Settings\Neil\Application Data\Spyware Terminator
[2004/06/30 20:03:31 | 000,000,000 | —D | M] – C:\Documents and Settings\Neil\Application Data\Thunderbird
[2007/01/13 22:29:07 | 000,000,000 | —D | M] – C:\Documents and Settings\Neil\Application Data\Uniblue
[2007/12/03 11:27:14 | 000,000,000 | —D | M] – C:\Documents and Settings\Neil\Application Data\Viewpoint
[2003/07/09 22:53:59 | 000,000,258 | —- | M] () – C:\WINDOWS\Tasks\ISP signup reminder 1.job

========== Purity Check ==========



========== Alternate Data Streams ==========

@Alternate Data Stream - 125 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:08948D52
< End of report >
Hi sagiter,

Looks better but there's still a bit more.


Please read through these instructions to familarize yourself with what to expect when this tool runs


Download ComboFix from one of these locations:

Link 1
Link 2


* IMPORTANT !!! Save ComboFix.exe to your Desktop

  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. Note: If you are having difficulty properly disabling your protective programs, or are unsure as to what programs need to be disabled, please refer to the information available through this link : How to Disable your Security Programs
  • Double click on ComboFix.exe & follow the prompts.
  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.
  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.

[external image: Posted Image]


Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]

Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.

Notes:

1.Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. ComboFix may reset a number of Internet Explorer's settings, including making I-E the default browser.
3. CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.


Please post back with the combofix log.

How's the computer now?

Thanks
Right now the computer seems fine. I will try to spend some time using it first thing in the morning and report back again.

Here is the combofix log:

ComboFix 10-03-01.01 - Neil 03/01/2010 22:57:09.1.1 - x86
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
AV: AVG Anti-Virus Free *On-access scanning disabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\windows\BackUp
c:\windows\BackUp\TB040421.DAT
c:\windows\patch.exe
c:\windows\system32\devmgr32.dll
c:\windows\system32\DMUSIC32.DLL
c:\windows\system32\hatutiza.dll
c:\windows\system32\janeguwo.dll
c:\windows\system32\yikujode.dll
c:\windows\system32\yuterahi.dll
c:\windows\system32\zelovumi.dll
c:\windows\twain_16.dll

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

——-\Legacy_FAD
——-\Legacy_WINDRIVER
——-\Service_WinDriver


((((((((((((((((((((((((( Files Created from 2010-02-02 to 2010-03-02 )))))))))))))))))))))))))))))))
.

2010-03-01 04:01 . 2010-03-01 04:01 ——– d—–w- C:\_OTL
2010-02-28 18:29 . 2010-02-28 18:29 79872 –sh–w- c:\windows\system32\feyumaze.exe
2010-02-28 14:29 . 2010-02-28 14:29 ——– d-sh–w- c:\windows\system32\config\systemprofile\IETldCache
2010-02-28 13:43 . 2010-02-28 13:43 ——– d—–w- c:\documents and settings\NetworkService\Application Data\AdobeUM
2010-02-26 04:44 . 2010-02-28 13:43 ——– d—–w- c:\documents and settings\NetworkService\Local Settings\Application Data\Adobe
2010-02-24 04:00 . 2010-02-24 04:00 ——– d-sh–w- c:\documents and settings\NetworkService\IETldCache

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-03-02 04:33 . 2006-08-17 19:31 608 —-a-w- c:\windows\aclockz6.dat
2010-03-02 03:44 . 2004-07-10 01:39 ——– d—–w- c:\documents and settings\Neil\Application Data\SlimBrowser
2010-03-02 01:49 . 2003-07-03 12:07 96512 —-a-w- c:\windows\system32\drivers\atapi.sys
2010-02-28 16:29 . 2009-06-29 12:26 ——– d—–w- c:\documents and settings\All Users\Application Data\AVG Security Toolbar
2010-02-28 13:31 . 2008-10-22 14:06 ——– d—–w- c:\documents and settings\All Users\Application Data\avg8
2010-02-26 04:09 . 2008-06-04 17:15 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2010-02-25 16:47 . 2006-09-19 16:48 ——– d—–w- c:\documents and settings\Neil\Application Data\Registry Booster
2010-02-22 11:28 . 2003-07-03 12:13 ——– d—–w- c:\program files\Modem Helper
2010-01-14 20:39 . 2003-08-25 11:49 ——– d—–w- c:\program files\Spybot - Search & Destroy
2010-01-07 21:07 . 2008-08-29 04:12 38224 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-01-07 21:07 . 2008-06-04 17:15 19160 —-a-w- c:\windows\system32\drivers\mbam.sys
2009-12-31 16:50 . 2002-08-29 10:00 353792 ——w- c:\windows\system32\drivers\srv.sys
2009-12-21 19:14 . 2004-02-06 22:05 916480 —-a-w- c:\windows\system32\wininet.dll
2009-12-16 18:43 . 2002-08-29 10:00 343040 ——w- c:\windows\system32\mspaint.exe
2009-12-14 07:08 . 2002-08-29 10:00 33280 ——w- c:\windows\system32\csrsrv.dll
2009-12-11 19:51 . 2009-12-11 19:52 411368 —-a-w- c:\windows\system32\deploytk.dll
2009-12-08 19:27 . 2002-08-29 10:00 2189184 ——w- c:\windows\system32\ntoskrnl.exe
2009-12-08 18:43 . 2002-08-29 10:00 2066048 ——w- c:\windows\system32\ntkrnlpa.exe
2009-12-04 18:22 . 2002-08-29 10:00 455424 ——w- c:\windows\system32\drivers\mrxsmb.sys
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{A3BC75A2-1F87-4686-AA43-5347D756017C}"= "c:\program files\AVG\AVG8\Toolbar\IEToolbar.dll" [2009-09-02 1107200]

[HKEY_CLASSES_ROOT\clsid\{a3bc75a2-1f87-4686-aa43-5347d756017c}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A3BC75A2-1F87-4686-AA43-5347D756017C}]
2009-09-02 16:58 1107200 —-a-w- c:\program files\AVG\AVG8\Toolbar\IEToolbar.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{CCC7A320-B3CA-4199-B1A6-9F516DD69829}"= "c:\program files\AVG\AVG8\Toolbar\IEToolbar.dll" [2009-09-02 1107200]

[HKEY_CLASSES_ROOT\clsid\{ccc7a320-b3ca-4199-b1a6-9f516dd69829}]

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{CCC7A320-B3CA-4199-B1A6-9F516DD69829}"= "c:\program files\AVG\AVG8\Toolbar\IEToolbar.dll" [2009-09-02 1107200]

[HKEY_CLASSES_ROOT\clsid\{ccc7a320-b3ca-4199-b1a6-9f516dd69829}]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Uniblue Registry Booster"="c:\program files\Uniblue\Registry Booster\RegistryBooster.exe" [2006-04-27 1761280]
"updateMgr"="c:\program files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" [2005-08-18 307200]
"DellSupportCenter"="c:\program files\Dell Support Center\bin\sprtcmd.exe" [2009-05-21 206064]
"RoboForm"="c:\program files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe" [2009-12-31 160592]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ATIModeChange"="Ati2mdxx.exe" [2001-09-04 28672]
"Apoint"="c:\program files\Apoint\Apoint.exe" [2002-08-23 143360]
"ATIPTA"="c:\program files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2003-07-29 335872]
"Dell QuickSet"="c:\program files\Dell\QuickSet\QuickSet.exe" [2003-01-31 364544]
"DVDSentry"="c:\windows\System32\DSentry.exe" [2002-07-17 28672]
"SandIcon"="c:\imagemate compactflash usb\SandIcon.Exe" [2000-11-13 131072]
"PDUiP6000DMon"="c:\program files\Canon\Memory Card Utility\PIXMA iP6000D\PDUiP6000DMon.exe" [2004-05-31 57344]
"PDUiP6000DTskbr"="c:\program files\Canon\Memory Card Utility\PIXMA iP6000D\PDUiP6000DTskbr.exe" [2004-05-28 69632]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-12-11 149280]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2003-07-03 151597]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2005-12-21 155648]
"AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2009-12-12 2043160]
"dellsupportcenter"="c:\program files\Dell Support Center\bin\sprtcmd.exe" [2009-05-21 206064]
"dscactivate"="c:\program files\Dell Support Center\gs_agent\custom\dsca.exe" [2007-11-15 16384]

c:\documents and settings\Neil\Start Menu\Programs\Startup\
MemoKit.lnk - c:\program files\MemoKit\mk.exe [2004-12-15 21504]
Webshots.lnk - c:\program files\Webshots\Launcher.exe [2004-7-9 45056]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-9-24 29696]
Microsoft Office.lnk - c:\program files\Microsoft Office\Office\OSA9.EXE [1999-2-17 65588]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2009-08-18 12:29 11952 —-a-w- c:\windows\SYSTEM32\avgrsstx.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\AloPar.sys]
@="Driver"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcmscsvc]
@=""

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Parallel Arbitrator]
@="Driver Group"

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" /background
"SpybotSD TeaTimer"=c:\program files\Spybot - Search & Destroy\TeaTimer.exe
"DellSupport"="c:\program files\DellSupport\DSAgnt.exe" /startup

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"dscactivate"="c:\program files\Dell Support Center\gs_agent\custom\dsca.exe"
"DellSupportCenter"="c:\program files\Dell Support Center\bin\sprtcmd.exe" /P DellSupportCenter

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Real\\RealPlayer\\realplay.exe"=
"c:\\Program Files\\SlimBrowser\\sbrowser.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Windows Media Player\\wmplayer.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgemc.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=

R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\SYSTEM32\DRIVERS\avgldx86.sys [10/22/2008 9:07 AM 335240]
R1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\SYSTEM32\DRIVERS\avgtdix.sys [10/22/2008 9:08 AM 108552]
R2 avg8emc;AVG Free8 E-mail Scanner;c:\progra~1\AVG\AVG8\avgemc.exe [7/4/2009 8:18 AM 908056]
R2 avg8wd;AVG Free8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [10/22/2008 9:06 AM 297752]
S3 wdpnp;Eisenworld Generic USB Bridge Cable Service;c:\windows\system32\Drivers\wdpnp.sys –> c:\windows\system32\Drivers\wdpnp.sys [?]
S4 AloPar;AloPar;c:\windows\SYSTEM32\DRIVERS\AloPar.sys [7/9/2003 8:02 PM 4112]
.
Contents of the 'Scheduled Tasks' folder

2003-07-10 c:\windows\Tasks\ISP signup reminder 1.job
- c:\windows\System32\OOBE\OOBEBALN.EXE [2002-08-29 00:12]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.smokinholsters.com/
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
IE: Customize Menu - file://c:\program files\Siber Systems\AI RoboForm\RoboFormComCustomizeIEMenu.html
IE: Fill Forms - file://c:\program files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
IE: RoboForm Toolbar - file://c:\program files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
IE: Save Forms - file://c:\program files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
DPF: DirectAnimation Java Classes
DPF: Microsoft XML Parser for Java
DPF: vzTCPConfig - hxxp://www2.verizon.net/help/fios_settings/include/vzTCPConfig.CAB
DPF: {F5820AD3-9B20-423E-B2AA-7AF2B4055746} - hxxp://download.paltalk.com/download/0.x/regdload.cab
.
- - - - ORPHANS REMOVED - - - -

HKLM-Run-Verizon_McciTrayApp - c:\program files\Verizon\McciTrayApp.exe
SafeBoot-klmdb.sys
AddRemove-HijackThis - c:\documents and settings\Neil\Local Settings\Temporary Internet Files\Content.IE5\32TYBA4F\HijackThis.exe
AddRemove-SimSafariUninstall - c:\windows\DeIsL1.isu



**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-03-01 23:26
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'winlogon.exe'(836)
c:\windows\system32\Ati2evxx.dll

- - - - - - - > 'explorer.exe'(2924)
c:\windows\system32\WININET.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
———————— Other Running Processes ————————
.
c:\windows\system32\Ati2evxx.exe
c:\windows\system32\Ati2evxx.exe
c:\windows\system32\crypserv.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Common Files\Motive\McciCMService.exe
c:\program files\Canon\Memory Card Utility\PIXMA iP6000D\PDUiP6000DMemCrdMgr.exe
c:\program files\Dell Support Center\bin\sprtsvc.exe
c:\program files\Spyware Terminator\sp_rsser.exe
c:\progra~1\AVG\AVG8\avgrsx.exe
c:\progra~1\AVG\AVG8\avgnsx.exe
c:\program files\AVG\AVG8\avgcsrvx.exe
c:\windows\system32\wscntfy.exe
c:\program files\Apoint\Apntex.exe
c:\program files\MemoKit\memokit2.exe
c:\windows\webshots.scr
c:\program files\Microsoft Office\Office\1033\msoffice.exe
.
**************************************************************************
.
Completion time: 2010-03-01 23:45:08 - machine was rebooted
ComboFix-quarantined-files.txt 2010-03-02 04:44

Pre-Run: 17,808,207,872 bytes free
Post-Run: 17,748,701,184 bytes free

WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Microsoft Windows XP Home Edition" /fastdetect /NoExecute=OptIn

- - End Of File - - 9D98645E98A66506A32A7F0E44714B3B
Hi sagiter,

Looking better.

You have some very old vulnerable java installed. Please go to Add/Remove programs and uninstall the following


Java 2 Runtime Environment, SE v1.4.2_06
J2SE Runtime Environment 5.0 Update 2
J2SE Runtime Environment 5.0 Update 4
J2SE Runtime Environment 5.0 Update 6
J2SE Runtime Environment 5.0 Update 9
J2SE Runtime Environment 5.0 Update 10
Java™ SE Runtime Environment 6 Update 1
Java™ 6 Update 2
Java™ 6 Update 3
Java™ 6 Update 5
Java™ 6 Update 7


Do not uninstall Java™ 6 Update 17



Next, Click your start button, open Control panel.
  • Locate the Java icon (it looks like a coffee cup)
  • double click it to open it
  • click the Update tab
  • Click update now



Next, Double click on OTL.exe
  • Under the Custom Scans/Fixes box at the bottom, paste in the following
  • Do Not copy the word CODE
  • please note the fix starts with the :
:Services

:Files
C:\WINDOWS\System32\feyumaze.exe
C:\WINDOWS\System32\komobome

:Commands
[emptytemp]

Then click the Run Fix button at the top
  • Let the program run unhindered



You have this program installed, Malwarebytes' Anti-Malware (MBAM). Please update it and run a scan.

Open MBAM

  • Click the Update tab
  • Click Check for Updates
  • If an update is found, it will download and install the latest version.
  • The program will close to update and reopen.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish,so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected.
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.
Extra Note:
If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process,if asked to restart the computer,please do so immediatly.

Please post back with
  • MBAM log
  • new OTL scan log, there will only be an OTL.txt this time

Thanks
Computer seems to be running nicely.

My Malwarebytes didn't work for some reason so I downloaded a new one off of a link in the stickies section on this forum.

Don't think there were any other problems running these files. Here are the logs:

OTL Fix:

All processes killed
========== SERVICES/DRIVERS ==========
========== FILES ==========
C:\WINDOWS\System32\feyumaze.exe moved successfully.
C:\WINDOWS\System32\komobome moved successfully.
========== COMMANDS ==========

[EMPTYTEMP]

User: All Users

User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes

User: LocalService
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 213126 bytes

User: Neil
->Temp folder emptied: 7181685 bytes
->Temporary Internet Files folder emptied: 1749391 bytes
->Java cache emptied: 0 bytes

User: NetworkService
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 67 bytes

%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32\dllcache .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 33432 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 0 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 0 bytes
RecycleBin emptied: 0 bytes

Total Files Cleaned = 9.00 mb


OTL by OldTimer - Version 3.1.30.3 log created on 03022010_111615

Files\Folders moved on Reboot…

Registry entries deleted on Reboot…

MBAM:

Malwarebytes' Anti-Malware 1.44
Database version: 3814
Windows 5.1.2600 Service Pack 3
Internet Explorer 8.0.6001.18702

3/2/2010 12:02:20 PM
mbam-log-2010-03-02 (12-02-20).txt

Scan type: Quick Scan
Objects scanned: 119487
Time elapsed: 18 minute(s), 30 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)

OTL Scan:

OTL logfile created on: 3/2/2010 12:04:20 PM - Run 4
OTL by OldTimer - Version 3.1.30.3 Folder = C:\Documents and Settings\Neil\Desktop
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

255.00 Mb Total Physical Memory | 131.00 Mb Available Physical Memory | 51.00% Memory free
618.00 Mb Paging File | 295.00 Mb Available in Paging File | 48.00% Paging File free
Paging file location(s): C:\pagefile.sys 384 768 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 37.22 Gb Total Space | 17.09 Gb Free Space | 45.91% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: OFFICE
Current User Name: Neil
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal

========== Processes (SafeList) ==========

PRC - C:\Documents and Settings\Neil\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Common Files\Java\Java Update\jusched.exe (Sun Microsystems, Inc.)
PRC - C:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe (Siber Systems)
PRC - C:\Program Files\Java\jre6\bin\jqs.exe (Sun Microsystems, Inc.)
PRC - C:\Program Files\AVG\AVG8\avgtray.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG8\avgrsx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG8\avgcsrvx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG8\avgnsx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG8\avgemc.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG8\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\Common Files\Motive\McciCMService.exe (Motive Communications, Inc.)
PRC - C:\Program Files\Dell Support Center\bin\sprtcmd.exe (SupportSoft, Inc.)
PRC - C:\Program Files\Dell Support Center\bin\sprtsvc.exe (SupportSoft, Inc.)
PRC - C:\Program Files\Spyware Terminator\sp_rsser.exe (Crawler.com)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\QuickTime\qttask.exe (Apple Computer, Inc.)
PRC - C:\Program Files\MemoKit\MemoKit2.exe (Software Benefits Inc.)
PRC - C:\Program Files\Canon\Memory Card Utility\PIXMA iP6000D\PDUiP6000DMon.exe (CANON INC.)
PRC - C:\Program Files\Canon\Memory Card Utility\PIXMA iP6000D\PDUiP6000DTskbr.exe (CANON INC.)
PRC - C:\Program Files\Canon\Memory Card Utility\PIXMA iP6000D\PDUiP6000DMemCrdMgr.exe (CANON INC.)
PRC - C:\WINDOWS\webshots.scr (Webshots.com)
PRC - C:\WINDOWS\SYSTEM32\ati2evxx.exe ()
PRC - C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe (ATI Technologies, Inc.)
PRC - C:\Program Files\Common Files\Real\Update_OB\realsched.exe (RealNetworks, Inc.)
PRC - C:\Program Files\Dell\QuickSet\quickset.exe ()
PRC - C:\Program Files\Apoint\Apoint.exe (Alps Electric Co., Ltd.)
PRC - C:\WINDOWS\SYSTEM32\DSentry.exe (Dell - Advanced Desktop Engineering)
PRC - C:\Program Files\Apoint\ApntEx.exe (Alps Electric Co., Ltd.)
PRC - C:\ImageMate CompactFlash USB\SandIcon.exe ()
PRC - C:\WINDOWS\SYSTEM32\Crypserv.exe (Kenonic Controls Ltd.)
PRC - C:\Program Files\Microsoft Office\Office\1033\MSOFFICE.EXE (Microsoft Corporation)


========== Modules (SafeList) ==========

MOD - C:\Documents and Settings\Neil\Desktop\OTL.exe (OldTimer Tools)


========== Win32 Services (SafeList) ==========

SRV - (JavaQuickStarterService) – C:\Program Files\Java\jre6\bin\jqs.exe (Sun Microsystems, Inc.)
SRV - (avg8emc) – C:\Program Files\AVG\AVG8\avgemc.exe (AVG Technologies CZ, s.r.o.)
SRV - (avg8wd) – C:\Program Files\AVG\AVG8\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
SRV - (McciCMService) – C:\Program Files\Common Files\Motive\McciCMService.exe (Motive Communications, Inc.)
SRV - (sprtsvc_dellsupportcenter) SupportSoft Sprocket Service (dellsupportcenter) – C:\Program Files\Dell Support Center\bin\sprtsvc.exe (SupportSoft, Inc.)
SRV - (sp_rssrv) – C:\Program Files\Spyware Terminator\sp_rsser.exe (Crawler.com)
SRV - (DSBrokerService) – C:\Program Files\DellSupport\brkrsvc.exe ()
SRV - (IDriverT) – C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe (Macrovision Corporation)
SRV - (PDUiP6000DMemCrdMgr) – C:\Program Files\Canon\Memory Card Utility\PIXMA iP6000D\PDUiP6000DMemCrdMgr.exe (CANON INC.)
SRV - (Ati HotKey Poller) – C:\WINDOWS\SYSTEM32\ati2evxx.exe ()
SRV - (Crypkey License) – C:\WINDOWS\System32\Crypserv.exe (Kenonic Controls Ltd.)


========== Driver Services (SafeList) ==========

DRV - (AvgMfx86) – C:\WINDOWS\System32\Drivers\avgmfx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (AvgLdx86) – C:\WINDOWS\System32\Drivers\avgldx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (AvgTdiX) – C:\WINDOWS\System32\Drivers\avgtdix.sys (AVG Technologies CZ, s.r.o.)
DRV - (usbaudio) USB Audio Driver (WDM) – C:\WINDOWS\SYSTEM32\DRIVERS\usbaudio.sys (Microsoft Corporation)
DRV - (amdagp) – C:\WINDOWS\System32\DRIVERS\amdagp.sys (Advanced Micro Devices, Inc.)
DRV - (sisagp) – C:\WINDOWS\System32\DRIVERS\sisagp.sys (Silicon Integrated Systems Corporation)
DRV - (Secdrv) – C:\WINDOWS\SYSTEM32\DRIVERS\secdrv.sys (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.)
DRV - (MRENDIS5) – C:\Program Files\Common Files\Motive\MRENDIS5.sys (Motive, Inc.)
DRV - (MREMPR5) – C:\Program Files\Common Files\Motive\MREMPR5.sys (Motive, Inc.)
DRV - (dsunidrv) – C:\WINDOWS\SYSTEM32\DRIVERS\dsunidrv.sys (Gteko Ltd.)
DRV - (DSproct) – C:\Program Files\DellSupport\GTAction\triggers\DSproct.sys (Gteko Ltd.)
DRV - (USBModem) – C:\WINDOWS\SYSTEM32\DRIVERS\lgusbmodem.sys (LG Electronics Inc.)
DRV - (UsbDiag) – C:\WINDOWS\SYSTEM32\DRIVERS\lgusbdiag.sys (LG Electronics Inc.)
DRV - (usbbus) – C:\WINDOWS\SYSTEM32\DRIVERS\lgusbbus.sys (LG Electronics Inc.)
DRV - (GEARAspiWDM) – C:\WINDOWS\SYSTEM32\DRIVERS\GEARAspiWDM.sys (GEAR Software Inc.)
DRV - (nv) – C:\WINDOWS\SYSTEM32\DRIVERS\nv4_mini.sys (NVIDIA Corporation)
DRV - (iAimFP4) – C:\WINDOWS\SYSTEM32\DRIVERS\wvchntxx.sys (Intel® Corporation)
DRV - (iAimFP3) – C:\WINDOWS\SYSTEM32\DRIVERS\wsiintxx.sys (Intel® Corporation)
DRV - (iAimTV4) – C:\WINDOWS\SYSTEM32\DRIVERS\wch7xxnt.sys (Intel® Corporation)
DRV - (iAimTV3) – C:\WINDOWS\SYSTEM32\DRIVERS\watv04nt.sys (Intel® Corporation)
DRV - (iAimTV1) – C:\WINDOWS\SYSTEM32\DRIVERS\watv02nt.sys (Intel® Corporation)
DRV - (iAimTV0) – C:\WINDOWS\SYSTEM32\DRIVERS\watv01nt.sys (Intel® Corporation)
DRV - (iAimFP0) – C:\WINDOWS\SYSTEM32\DRIVERS\wadv01nt.sys (Intel® Corporation)
DRV - (iAimFP1) – C:\WINDOWS\SYSTEM32\DRIVERS\wadv02nt.sys (Intel® Corporation)
DRV - (iAimFP2) – C:\WINDOWS\SYSTEM32\DRIVERS\wadv05nt.sys (Intel® Corporation)
DRV - (i81x) – C:\WINDOWS\SYSTEM32\DRIVERS\i81xnt5.sys (Intel® Corporation)
DRV - (ati2mtag) – C:\WINDOWS\SYSTEM32\DRIVERS\ati2mtag.sys (ATI Technologies Inc.)
DRV - (STAC97) Audio Driver (WDM) – C:\WINDOWS\SYSTEM32\DRIVERS\STAC97.sys (SigmaTel, Inc.)
DRV - (ApfiltrService) – C:\WINDOWS\SYSTEM32\DRIVERS\Apfiltr.sys (Alps Electric Co., Ltd.)
DRV - (omci) – C:\WINDOWS\SYSTEM32\DRIVERS\omci.sys (Dell Computer Corporation)
DRV - (bcm4sbxp) – C:\WINDOWS\SYSTEM32\DRIVERS\bcm4sbxp.sys (Broadcom Corporation)
DRV - (BCM43XX) – C:\WINDOWS\SYSTEM32\DRIVERS\LSBCMNDS.SYS (The Linksys Group, Inc.)
DRV - (Vpctcom) – C:\WINDOWS\System32\DRIVERS\vpctcom.sys (PCtel, Inc.)
DRV - (Ptserial) – C:\WINDOWS\SYSTEM32\DRIVERS\ptserial.sys (PCTEL, INC.)
DRV - (Vvoice) – C:\WINDOWS\System32\DRIVERS\vvoice.sys (PCtel, Inc.)
DRV - (Vmodem) – C:\WINDOWS\System32\DRIVERS\vmodem.sys (PCTEL, INC.)
DRV - (Ptilink) – C:\WINDOWS\SYSTEM32\DRIVERS\PTILINK.SYS (Parallel Technologies, Inc.)
DRV - (AloPar) – C:\WINDOWS\SYSTEM32\DRIVERS\AloPar.sys (Eisenworld, Inc.)
DRV - (Sparrow) – C:\WINDOWS\System32\DRIVERS\sparrow.sys (Adaptec, Inc.)
DRV - (sym_u3) – C:\WINDOWS\System32\DRIVERS\sym_u3.sys (LSI Logic)
DRV - (sym_hi) – C:\WINDOWS\System32\DRIVERS\sym_hi.sys (LSI Logic)
DRV - (symc8xx) – C:\WINDOWS\System32\DRIVERS\symc8xx.sys (LSI Logic)
DRV - (symc810) – C:\WINDOWS\System32\DRIVERS\symc810.sys (Symbios Logic Inc.)
DRV - (ultra) – C:\WINDOWS\System32\DRIVERS\ultra.sys (Promise Technology, Inc.)
DRV - (ql12160) – C:\WINDOWS\System32\DRIVERS\ql12160.sys (QLogic Corporation)
DRV - (ql1080) – C:\WINDOWS\System32\DRIVERS\ql1080.sys (QLogic Corporation)
DRV - (ql1280) – C:\WINDOWS\System32\DRIVERS\ql1280.sys (QLogic Corporation)
DRV - (dac2w2k) – C:\WINDOWS\System32\DRIVERS\dac2w2k.sys (Mylex Corporation)
DRV - (mraid35x) – C:\WINDOWS\System32\DRIVERS\mraid35x.sys (American Megatrends Inc.)
DRV - (asc) – C:\WINDOWS\System32\DRIVERS\asc.sys (Advanced System Products, Inc.)
DRV - (asc3550) – C:\WINDOWS\System32\DRIVERS\asc3550.sys (Advanced System Products, Inc.)
DRV - (AliIde) – C:\WINDOWS\System32\DRIVERS\aliide.sys (Acer Laboratories Inc.)
DRV - (CmdIde) – C:\WINDOWS\System32\DRIVERS\cmdide.sys (CMD Technology, Inc.)
DRV - (EL90XBC) – C:\WINDOWS\SYSTEM32\DRIVERS\EL90XBC5.SYS (3Com Corporation)
DRV - (BrPar) – C:\WINDOWS\System32\drivers\BrPar.sys (Brother Industries Ltd.)
DRV - (NetworkX) – C:\WINDOWS\system32\ckldrv.sys ()


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,StartPage = http://www.optonline.net

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultName = Google
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultURL = http://www.google.com/search?q={searchTerm…tf8&oe=utf8
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.smokinholsters.com/
IE - HKCU\..\URLSearchHook: *{CFBFAE00-17A6-11D0-99CB-00C04FD64497} - Reg Error: Key error. File not found
IE - HKCU\..\URLSearchHook: {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG8\Toolbar\IEToolbar.dll ()
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0


[2004/07/04 22:38:45 | 000,000,000 | —D | M] – C:\Documents and Settings\Neil\Application Data\Mozilla\Firefox\Profiles\default.exe\extensions
[2004/07/04 22:38:45 | 000,000,000 | —D | M] (DOM Inspector) – C:\Documents and Settings\Neil\Application Data\Mozilla\Firefox\Profiles\default.exe\extensions\{641d8d09-7dda-4850-8228-ac0ab65e2ac9}
[2004/07/04 22:38:45 | 000,000,000 | —D | M] (Firefox (default)) – C:\Documents and Settings\Neil\Application Data\Mozilla\Firefox\Profiles\default.exe\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}

O1 HOSTS File: ([2010/03/01 23:25:40 | 000,000,027 | —- | M]) - C:\WINDOWS\SYSTEM32\DRIVERS\ETC\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (no name) - {243B17DE-77C7-46BF-B94B-0B5F309A0E64} - C:\Program Files\Microsoft Money\System\mnyside.dll (Microsoft Corporation)
O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll (AVG Technologies CZ, s.r.o.)
O2 - BHO: (Spybot-S&D IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O2 - BHO: (no name) - {724d43a9-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\RoboForm.dll (Siber Systems Inc.)
O2 - BHO: (AVG Security Toolbar BHO) - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG8\Toolbar\IEToolbar.dll ()
O2 - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (JQSIEStartDetectorImpl Class) - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll (Sun Microsystems, Inc.)
O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - No CLSID value found.
O3 - HKLM\..\Toolbar: (&RoboForm) - {724d43a0-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\RoboForm.dll (Siber Systems Inc.)
O3 - HKLM\..\Toolbar: (AVG Security Toolbar) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - C:\Program Files\AVG\AVG8\Toolbar\IEToolbar.dll ()
O3 - HKCU\..\Toolbar\ShellBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {4B3803EA-5230-4DC3-A7FC-33638F3D3542} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (&RoboForm) - {724D43A0-0D85-11D4-9908-00400523E39A} - C:\Program Files\Siber Systems\AI RoboForm\RoboForm.dll (Siber Systems Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (AVG Security Toolbar) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - C:\Program Files\AVG\AVG8\Toolbar\IEToolbar.dll ()
O4 - HKLM..\Run: [Apoint] C:\Program Files\Apoint\Apoint.exe (Alps Electric Co., Ltd.)
O4 - HKLM..\Run: [ATIModeChange] C:\WINDOWS\System32\Ati2mdxx.exe (ATI Technologies, Inc.)
O4 - HKLM..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe (ATI Technologies, Inc.)
O4 - HKLM..\Run: [AVG8_TRAY] C:\Program Files\AVG\AVG8\avgtray.exe (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [Dell QuickSet] C:\Program Files\Dell\QuickSet\quickset.exe ()
O4 - HKLM..\Run: [dellsupportcenter] C:\Program Files\Dell Support Center\bin\sprtcmd.exe (SupportSoft, Inc.)
O4 - HKLM..\Run: [dscactivate] C:\Program Files\Dell Support Center\gs_agent\custom\dsca.exe ( )
O4 - HKLM..\Run: [DVDSentry] C:\WINDOWS\SYSTEM32\DSentry.exe (Dell - Advanced Desktop Engineering)
O4 - HKLM..\Run: [PDUiP6000DMon] C:\Program Files\Canon\Memory Card Utility\PIXMA iP6000D\PDUiP6000DMon.exe (CANON INC.)
O4 - HKLM..\Run: [PDUiP6000DTskbr] C:\Program Files\Canon\Memory Card Utility\PIXMA iP6000D\PDUiP6000DTskbr.exe (CANON INC.)
O4 - HKLM..\Run: [QuickTime Task] C:\Program Files\QuickTime\qttask.exe (Apple Computer, Inc.)
O4 - HKLM..\Run: [SandIcon] C:\ImageMate CompactFlash USB\SandIcon.exe ()
O4 - HKLM..\Run: [SunJavaUpdateSched] C:\Program Files\Common Files\Java\Java Update\jusched.exe (Sun Microsystems, Inc.)
O4 - HKLM..\Run: [TkBellExe] C:\Program Files\Common Files\Real\Update_OB\realsched.exe (RealNetworks, Inc.)
O4 - HKCU..\Run: [DellSupportCenter] C:\Program Files\Dell Support Center\bin\sprtcmd.exe (SupportSoft, Inc.)
O4 - HKCU..\Run: [RoboForm] C:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe (Siber Systems)
O4 - HKCU..\Run: [Uniblue Registry Booster] C:\Program Files\Uniblue\Registry Booster\RegistryBooster.exe (Uniblue Registry Booster)
O4 - HKCU..\Run: [updateMgr] C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe (Adobe Systems Incorporated)
O4 - HKLM..\RunOnce: [Malwarebytes' Anti-Malware] C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe (Adobe Systems Incorporated)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE (Microsoft Corporation)
O4 - Startup: C:\Documents and Settings\Neil\Start Menu\Programs\Startup\MemoKit.lnk = C:\Program Files\MemoKit\mk.exe ()
O4 - Startup: C:\Documents and Settings\Neil\Start Menu\Programs\Startup\Webshots.lnk = C:\Program Files\Webshots\Launcher.exe ()
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Main present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\PhishingFilter present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O8 - Extra context menu item: Customize Menu - C:\Program Files\Siber Systems\AI RoboForm\RoboFormComCustomizeIEMenu.html ()
O8 - Extra context menu item: Fill Forms - C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html ()
O8 - Extra context menu item: RoboForm Toolbar - C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html ()
O8 - Extra context menu item: Save Forms - C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html ()
O9 - Extra Button: Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html ()
O9 - Extra 'Tools' menuitem : Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html ()
O9 - Extra Button: Save - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html ()
O9 - Extra 'Tools' menuitem : Save Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html ()
O9 - Extra Button: RoboForm - {724d43aa-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html ()
O9 - Extra 'Tools' menuitem : RoboForm Toolbar - {724d43aa-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html ()
O9 - Extra 'Tools' menuitem : Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O9 - Extra Button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - C:\Program Files\Microsoft Money\System\mnyside.dll (Microsoft Corporation)
O15 - HKCU\..Trusted Domains: ([]msn in My Computer)
O16 - DPF: {01113300-3E00-11D2-8470-0060089874ED} https://activatemyfios.verizon.net/sdcCommo…IOS/tgctlcm.cab (Support.com Configuration Class)
O16 - DPF: {01A88BB1-1174-41EC-ACCB-963509EAE56B} http://support.dell.com/systemprofiler/SysPro.CAB (SysProWmi Class)
O16 - DPF: {02BCC737-B171-4746-94C9-0D8A0B2C0089} http://office.microsoft.com/templates/ieawsdc.cab (Microsoft Office Template and Media Control)
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} http://www.apple.com/qtactivex/qtplugin.cab (QuickTime Object)
O16 - DPF: {05CA9FB0-3E3E-4B36-BF41-0E3A5CAA8CD8} http://download.microsoft.com/download/d/c…/OGAControl.cab (Office Genuine Advantage Validation Tool)
O16 - DPF: {0C568603-D79D-11D2-87A7-00C04FF158BB} http://download.mcafee.com/molbin/Shared/MGBrwFld.cab (BrowseFolderPopup Class)
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} http://upload.facebook.com/controls/2008.1…toUploader5.cab (Facebook Photo Uploader 5 Control)
O16 - DPF: {11260943-421B-11D0-8EAC-0000C07D88CF} http://www.ipix.com/viewers/ipixx.cab (iPIX ActiveX Control)
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://fpdownload.macromedia.com/get/shock…director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://download.microsoft.com/download/3/9…heckControl.cab (Windows Genuine Advantage Validation Tool)
O16 - DPF: {1E3F1348-4370-4BBE-A67A-CC7ED824CA85} http://download.microsoft.com/download/7/4…helpcontrol.cab (Microsoft Genuine Advantage Self Support Tool)
O16 - DPF: {33564D57-0000-0010-8000-00AA00389B71} http://download.microsoft.com/download/F/6…922/wmv9VCM.CAB (Reg Error: Key error.)
O16 - DPF: {362C56AA-6E4F-40C7-A0B5-85501DBDAD77} http://i.dell.com/images/global/js/scanner/SysProExe.cab (Scanner.SysScanner)
O16 - DPF: {36C417C6-13C6-448B-9784-DD73A93B0582} http://download.mcafee.com/molbin/shared/m…56/mcinsctl.cab (Reg Error: Key error.)
O16 - DPF: {3BFFE033-BF43-11D5-A271-00A024A51325} https://notes1.cc.sunysb.edu/iNotes6W.cab (iNotes6 Class)
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} http://download.mcafee.com/molbin/shared/m…83/mcinsctl.cab (Reg Error: Key error.)
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} http://groups.msn.com/controls/PhotoUC/MsnPUpld.cab (MSN Photo Upload Tool)
O16 - DPF: {5C6698D9-7BE4-4122-8EC5-291D84DBD4A0} http://upload.facebook.com/controls/Facebo…toUploader3.cab (Facebook Photo Uploader 4 Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_18)
O16 - DPF: {94B82441-A413-4E43-8422-D49930E69764} https://echat.us.dell.com/Media/VisitorChat/TLIEFlash.CAB (TLIEFlashObj Class)
O16 - DPF: {A8658086-E6AC-4957-BC8E-7D54A7E8A78D} http://www.microsoft.com/security/controls/DoomCln.CAB (DoomCln Object)
O16 - DPF: {A8F2B9BD-A6A0-486A-9744-18920D898429} http://www.sibelius.com/download/software/…tiveXPlugin.cab (ScorchPlugin Class)
O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} http://download.mcafee.com/molbin/shared/m…,20/mcgdmgr.cab (Reg Error: Key error.)
O16 - DPF: {C432C4BD-3566-411C-8F3C-E5E0D3AE5D33} http://viewers.multicastmedia.com/common/m…MINIBrowser.CAB (CBrowser Class)
O16 - DPF: {CAFEEFAC-0016-0000-0018-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_18)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_18)
O16 - DPF: {D27CDB6E-0000-0000-0000-000000000000} http://download.macromedia.com/pub/shockwa…ash/swflash.cab (Reg Error: Key error.)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab (Shockwave Flash Object)
O16 - DPF: {F5820AD3-9B20-423E-B2AA-7AF2B4055746} http://download.paltalk.com/download/0.x/regdload.cab (CRegistryDownload Class)
O16 - DPF: {F58E1CEF-A068-4C15-BA5E-587CAF3EE8C6} http://chat.msn.com/bin/msnchat45.cab (MSN Chat Control 4.5)
O16 - DPF: DirectAnimation Java Classes Reg Error: Value error. (Reg Error: Key error.)
O16 - DPF: Microsoft XML Parser for Java Reg Error: Value error. (Reg Error: Key error.)
O16 - DPF: vzTCPConfig http://www2.verizon.net/help/fios_settings…vzTCPConfig.CAB (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll (AVG Technologies CZ, s.r.o.)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\AtiExtEvent: DllName - Ati2evxx.dll - C:\WINDOWS\System32\ati2evxx.dll ()
O20 - Winlogon\Notify\avgrsstarter: DllName - avgrsstx.dll - C:\WINDOWS\System32\avgrsstx.dll (AVG Technologies CZ, s.r.o.)
O24 - Desktop WallPaper: C:\Documents and Settings\Neil\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Neil\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2002/09/03 08:59:58 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - comfile [open] – "%1" %*
O35 - exefile [open] – "%1" %*

========== Files/Folders - Created Within 30 Days ==========

[2010/03/02 11:34:03 | 005,115,840 | —- | C] (Malwarebytes Corporation ) – C:\Documents and Settings\Neil\Desktop\mbam-setup.exe
[2010/03/02 11:17:08 | 000,000,000 | -HSD | C] – C:\RECYCLER
[2010/03/02 11:03:07 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Sun
[2010/03/02 11:02:49 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Java
[2010/03/02 11:01:08 | 000,073,728 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javacpl.cpl
[2010/03/02 11:01:05 | 000,153,376 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javaws.exe
[2010/03/02 11:01:04 | 000,145,184 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javaw.exe
[2010/03/02 11:01:04 | 000,145,184 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\java.exe
[2010/03/01 22:48:36 | 000,000,000 | RHSD | C] – C:\cmdcons
[2010/03/01 22:45:28 | 000,212,480 | —- | C] (SteelWerX) – C:\WINDOWS\SWXCACLS.exe
[2010/03/01 22:45:28 | 000,161,792 | —- | C] (SteelWerX) – C:\WINDOWS\SWREG.exe
[2010/03/01 22:45:28 | 000,136,704 | —- | C] (SteelWerX) – C:\WINDOWS\SWSC.exe
[2010/03/01 22:45:28 | 000,031,232 | —- | C] (NirSoft) – C:\WINDOWS\NIRCMD.exe
[2010/03/01 22:45:10 | 000,000,000 | —D | C] – C:\WINDOWS\ERDNT
[2010/03/01 22:44:45 | 000,000,000 | —D | C] – C:\Qoobox
[2010/03/01 20:42:42 | 000,000,000 | —D | C] – C:\Documents and Settings\Neil\Desktop\tdsskiller
[2010/03/01 07:53:44 | 000,000,000 | —D | C] – C:\Documents and Settings\Neil\Desktop\scans
[2010/02/28 23:01:44 | 000,000,000 | —D | C] – C:\_OTL
[2010/02/28 09:10:19 | 000,549,888 | —- | C] (OldTimer Tools) – C:\Documents and Settings\Neil\Desktop\OTL.exe
[2010/02/28 08:43:51 | 000,000,000 | —D | M] – C:\Documents and Settings\NetworkService\Application Data\AdobeUM
[2010/02/28 08:43:40 | 000,000,000 | —D | M] – C:\Documents and Settings\NetworkService\Local Settings\Application Data\Adobe
[2010/02/25 23:44:50 | 000,000,000 | —D | M] – C:\Documents and Settings\NetworkService\Application Data\Adobe
[2010/02/25 11:44:49 | 000,000,000 | —D | M] – C:\Documents and Settings\NetworkService\Application Data\Macromedia
[2010/02/24 15:12:26 | 000,000,000 | —D | M] – C:\Documents and Settings\LocalService\Application Data\Real
[2010/02/24 09:16:45 | 000,000,000 | —D | M] – C:\Documents and Settings\LocalService\Application Data\Adobe
[2009/06/29 07:25:48 | 000,000,000 | —D | M] – C:\Documents and Settings\LocalService\Application Data\AVGTOOLBAR
[2008/10/22 09:05:35 | 000,000,000 | –SD | M] – C:\Documents and Settings\NetworkService\Application Data\Microsoft
[2008/10/22 09:05:35 | 000,000,000 | –SD | M] – C:\Documents and Settings\LocalService\Application Data\Microsoft
[2008/10/22 09:05:35 | 000,000,000 | —D | M] – C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft
[2008/10/22 09:05:35 | 000,000,000 | —D | M] – C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft
[2007/02/09 00:19:36 | 000,000,000 | —D | M] – C:\Documents and Settings\LocalService\Local Settings\Application Data\Adobe
[2006/11/30 11:53:22 | 000,000,000 | —D | M] – C:\Documents and Settings\LocalService\Application Data\Gtek
[2006/11/05 05:05:42 | 000,000,000 | —D | M] – C:\Documents and Settings\LocalService\Application Data\SlimBrowser
[2006/06/20 21:19:58 | 000,000,000 | —D | M] – C:\Documents and Settings\LocalService\Application Data\Macromedia
[2005/04/30 09:43:38 | 000,000,000 | —D | M] – C:\Documents and Settings\LocalService\Local Settings\Application Data\Help
[2005/04/30 09:43:38 | 000,000,000 | —D | M] – C:\Documents and Settings\LocalService\Application Data\Help
[2004/05/08 20:06:28 | 000,000,000 | —D | M] – C:\Documents and Settings\LocalService\Local Settings\Application Data\Google
[2003/09/05 10:16:53 | 000,000,000 | —D | M] – C:\Documents and Settings\LocalService\Application Data\McAfee.com Personal Firewall

========== Files - Modified Within 30 Days ==========

[2010/03/02 12:12:41 | 000,000,608 | —- | M] () – C:\WINDOWS\aclockz6.dat
[2010/03/02 11:34:15 | 005,115,840 | —- | M] (Malwarebytes Corporation ) – C:\Documents and Settings\Neil\Desktop\mbam-setup.exe
[2010/03/02 11:22:00 | 000,001,170 | —- | M] () – C:\WINDOWS\System32\WPA.DBL
[2010/03/02 11:19:36 | 000,000,006 | -H– | M] () – C:\WINDOWS\tasks\SA.DAT
[2010/03/02 11:19:13 | 000,002,048 | –S- | M] () – C:\WINDOWS\BOOTSTAT.DAT
[2010/03/02 11:17:42 | 009,175,040 | -H– | M] () – C:\Documents and Settings\Neil\NTUSER.DAT
[2010/03/02 11:17:42 | 000,000,178 | -HS- | M] () – C:\Documents and Settings\Neil\NTUSER.INI
[2010/03/02 08:23:03 | 056,532,882 | —- | M] () – C:\WINDOWS\System32\drivers\Avg\incavi.avm
[2010/03/02 00:53:09 | 000,001,355 | —- | M] () – C:\WINDOWS\imsins.BAK
[2010/03/01 23:27:03 | 000,000,359 | —- | M] () – C:\WINDOWS\system.ini
[2010/03/01 23:25:40 | 000,000,027 | —- | M] () – C:\WINDOWS\System32\drivers\ETC\hosts
[2010/03/01 22:48:58 | 000,000,281 | RHS- | M] () – C:\BOOT.INI
[2010/03/01 22:43:45 | 003,875,750 | R— | M] () – C:\Documents and Settings\Neil\Desktop\ComboFix.exe
[2010/03/01 20:40:53 | 000,154,657 | —- | M] () – C:\Documents and Settings\Neil\Desktop\tdsskiller.zip
[2010/03/01 00:06:27 | 000,001,671 | —- | M] () – C:\Documents and Settings\Neil\Desktop\user.zip
[2010/02/28 16:52:00 | 000,027,144 | —- | M] () – C:\Documents and Settings\Neil\Desktop\SafeBoot-for-Windows-XP-SP3.reg
[2010/02/28 09:10:20 | 000,549,888 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Neil\Desktop\OTL.exe
[2010/02/27 07:35:53 | 000,002,469 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Dell Support Center.lnk
[2010/02/26 15:18:20 | 000,293,376 | —- | M] () – C:\Documents and Settings\Neil\Desktop\v8vqkne5.exe
[2010/02/26 07:19:28 | 000,000,000 | —- | M] () – C:\Documents and Settings\Neil\defogger_reenable
[2010/02/26 07:11:27 | 000,050,477 | —- | M] () – C:\Documents and Settings\Neil\Desktop\Defogger.exe
[2010/02/26 00:01:03 | 003,932,214 | —- | M] () – C:\WINDOWS\Webshots for Neil.bmp
[2010/02/25 22:59:35 | 000,000,710 | —- | M] () – C:\Documents and Settings\Neil\Start Menu\Programs\Startup\Webshots.lnk
[2010/02/24 01:44:49 | 000,142,495 | —- | M] () – C:\WINDOWS\System32\drivers\Avg\microavi.avg
[2010/02/24 01:44:46 | 000,492,629 | —- | M] () – C:\WINDOWS\System32\drivers\Avg\miniavi.avg
[2010/02/24 01:44:41 | 006,061,540 | —- | M] () – C:\WINDOWS\System32\drivers\Avg\avi7.avg
[2010/02/23 20:02:48 | 000,054,156 | -H– | M] () – C:\WINDOWS\QTFont.qfn
[2010/02/20 11:57:43 | 000,059,392 | —- | M] () – C:\Documents and Settings\Neil\My Documents\TAXES and FAFSA 2009.doc
[2010/02/10 16:55:27 | 000,000,452 | —- | M] () – C:\Documents and Settings\Neil\My Documents\spider.sav
[2010/02/07 16:39:29 | 000,050,688 | —- | M] () – C:\Documents and Settings\Neil\My Documents\TAXES 2009 for accountant NO SAM.doc
[2010/02/07 16:37:34 | 000,024,576 | —- | M] () – C:\Documents and Settings\Neil\My Documents\SAMSON FLANCBAUM TAXES 2009.doc
[2010/02/07 15:33:07 | 000,024,576 | —- | M] () – C:\Documents and Settings\Neil\My Documents\Smokin Taxes 2009.doc
[2010/02/06 20:40:02 | 000,054,272 | —- | M] () – C:\Documents and Settings\Neil\My Documents\TAXES 2009.doc
[2010/02/06 20:32:16 | 000,052,736 | —- | M] () – C:\Documents and Settings\Neil\My Documents\TAXES 2009 for accountant.doc
[2010/02/06 16:46:13 | 004,456,448 | —- | M] () – C:\Documents and Settings\Neil\My Documents\My Money.mny
[2010/02/06 15:49:41 | 000,024,064 | —- | M] () – C:\Documents and Settings\Neil\My Documents\Smokin Taxes 2008.doc
[2010/02/05 11:41:40 | 000,001,409 | —- | M] () – C:\WINDOWS\QTFont.for

========== Files Created - No Company Name ==========

[2010/03/01 22:48:58 | 000,000,211 | —- | C] () – C:\Boot.bak
[2010/03/01 22:48:48 | 000,260,272 | —- | C] () – C:\cmldr
[2010/03/01 22:45:28 | 000,261,632 | —- | C] () – C:\WINDOWS\PEV.exe
[2010/03/01 22:45:28 | 000,098,816 | —- | C] () – C:\WINDOWS\sed.exe
[2010/03/01 22:45:28 | 000,080,412 | —- | C] () – C:\WINDOWS\grep.exe
[2010/03/01 22:45:28 | 000,077,312 | —- | C] () – C:\WINDOWS\MBR.exe
[2010/03/01 22:45:28 | 000,068,096 | —- | C] () – C:\WINDOWS\zip.exe
[2010/03/01 22:43:44 | 003,875,750 | R— | C] () – C:\Documents and Settings\Neil\Desktop\ComboFix.exe
[2010/03/01 20:40:45 | 000,154,657 | —- | C] () – C:\Documents and Settings\Neil\Desktop\tdsskiller.zip
[2010/03/01 00:09:14 | 000,027,144 | —- | C] () – C:\Documents and Settings\Neil\Desktop\SafeBoot-for-Windows-XP-SP3.reg
[2010/03/01 00:06:23 | 000,001,671 | —- | C] () – C:\Documents and Settings\Neil\Desktop\user.zip
[2010/02/27 07:35:53 | 000,002,469 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Dell Support Center.lnk
[2010/02/26 15:18:19 | 000,293,376 | —- | C] () – C:\Documents and Settings\Neil\Desktop\v8vqkne5.exe
[2010/02/26 07:19:28 | 000,000,000 | —- | C] () – C:\Documents and Settings\Neil\defogger_reenable
[2010/02/26 07:11:27 | 000,050,477 | —- | C] () – C:\Documents and Settings\Neil\Desktop\Defogger.exe
[2010/02/07 16:31:12 | 000,050,688 | —- | C] () – C:\Documents and Settings\Neil\My Documents\TAXES 2009 for accountant NO SAM.doc
[2010/02/07 16:30:39 | 000,024,576 | —- | C] () – C:\Documents and Settings\Neil\My Documents\SAMSON FLANCBAUM TAXES 2009.doc
[2010/02/07 15:26:55 | 000,024,576 | —- | C] () – C:\Documents and Settings\Neil\My Documents\Smokin Taxes 2009.doc
[2010/02/06 20:39:38 | 000,059,392 | —- | C] () – C:\Documents and Settings\Neil\My Documents\TAXES and FAFSA 2009.doc
[2010/02/06 20:16:13 | 000,052,736 | —- | C] () – C:\Documents and Settings\Neil\My Documents\TAXES 2009 for accountant.doc
[2010/02/05 11:41:40 | 000,054,156 | -H– | C] () – C:\WINDOWS\QTFont.qfn
[2010/02/05 11:41:40 | 000,001,409 | —- | C] () – C:\WINDOWS\QTFont.for
[2008/05/09 07:44:34 | 000,141,312 | —- | C] () – C:\WINDOWS\System32\drivers\sp_rsdrv2.sys
[2008/03/06 00:36:33 | 000,086,016 | —- | C] () – C:\WINDOWS\System32\ati2evxx.dll
[2007/01/23 15:15:22 | 000,676,224 | —- | C] () – C:\WINDOWS\System32\OGACheckControl.DLL
[2006/10/20 16:15:34 | 000,001,359 | —- | C] () – C:\Documents and Settings\All Users\Application Data\QTSBandwidthCache
[2006/01/11 13:25:19 | 000,000,576 | —- | C] () – C:\WINDOWS\_delis32.ini
[2006/01/11 13:25:13 | 000,001,216 | —- | C] () – C:\WINDOWS\_isenv31.ini
[2006/01/11 13:25:12 | 000,000,521 | —- | C] () – C:\WINDOWS\_iserr31.ini
[2006/01/09 12:28:27 | 000,000,313 | —- | C] () – C:\WINDOWS\BRDIAG.INI
[2006/01/09 12:28:27 | 000,000,145 | —- | C] () – C:\WINDOWS\BRVIDEO.INI
[2006/01/09 12:28:26 | 000,000,023 | —- | C] () – C:\WINDOWS\Brownie.ini
[2006/01/09 12:28:17 | 000,026,624 | —- | C] () – C:\WINDOWS\System32\BRGSRC32.DLL
[2006/01/09 12:28:17 | 000,004,608 | —- | C] () – C:\WINDOWS\System32\BRGSRC16.DLL
[2006/01/09 12:28:16 | 000,077,824 | —- | C] () – C:\WINDOWS\System32\BROSNMP.DLL
[2006/01/09 12:28:12 | 000,009,013 | —- | C] () – C:\WINDOWS\HL-2040.INI
[2006/01/09 12:27:26 | 000,000,426 | —- | C] () – C:\WINDOWS\BRWMARK.INI
[2005/11/29 00:11:56 | 000,000,037 | —- | C] () – C:\WINDOWS\ipixActivex.ini
[2005/08/09 17:12:28 | 003,596,288 | —- | C] () – C:\WINDOWS\System32\qt-dx331.dll
[2004/11/18 14:30:13 | 000,000,000 | —- | C] () – C:\WINDOWS\OpPrintServer.INI
[2004/11/18 14:21:16 | 000,007,680 | —- | C] () – C:\WINDOWS\System32\CNMVS69.DLL
[2004/09/11 21:54:11 | 000,000,063 | —- | C] () – C:\WINDOWS\mdm.ini
[2004/09/03 17:52:50 | 000,196,608 | —- | C] () – C:\WINDOWS\System32\GCCollection.dll
[2004/06/30 15:04:46 | 000,040,960 | —- | C] () – C:\WINDOWS\System32\SDelete.dll
[2004/04/21 13:34:48 | 000,071,749 | —- | C] () – C:\WINDOWS\HCExtOutput.dll
[2004/04/21 13:34:48 | 000,000,823 | —- | C] () – C:\WINDOWS\TSC.ini
[2004/04/21 13:34:32 | 000,000,170 | —- | C] () – C:\WINDOWS\GetServer.ini
[2004/03/25 11:20:56 | 000,000,127 | —- | C] () – C:\Documents and Settings\Neil\Local Settings\Application Data\fusioncache.dat
[2004/03/25 08:33:21 | 000,000,024 | —- | C] () – C:\WINDOWS\wininit.ini
[2004/03/25 08:33:05 | 000,000,002 | —- | C] () – C:\WINDOWS\msoffice.ini
[2004/03/07 13:51:00 | 000,024,924 | —- | C] () – C:\WINDOWS\System32\openports.dll
[2004/02/09 15:42:28 | 000,000,071 | —- | C] () – C:\WINDOWS\Theme Uninstall.ini
[2003/10/14 15:54:32 | 000,030,720 | —- | C] () – C:\Documents and Settings\Neil\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2003/10/03 17:10:14 | 000,000,036 | —- | C] () – C:\WINDOWS\Crypkey.ini
[2003/10/03 17:10:09 | 000,024,608 | —- | C] () – C:\WINDOWS\System32\Ckldrv.sys
[2003/10/03 17:10:09 | 000,018,432 | —- | C] () – C:\WINDOWS\Setup_ck.dll
[2003/10/03 17:10:08 | 000,000,000 | —- | C] () – C:\WINDOWS\PROTOCOL.INI
[2003/08/22 19:23:38 | 000,000,026 | —- | C] () – C:\WINDOWS\INTUIT.INI
[2003/07/23 18:57:41 | 000,002,154 | —- | C] () – C:\WINDOWS\Solitaire.ini
[2003/07/11 19:12:37 | 000,000,210 | —- | C] () – C:\WINDOWS\cdPlayer.ini
[2003/07/10 06:55:57 | 000,000,208 | —- | C] () – C:\WINDOWS\QUICKEN.INI
[2003/07/10 01:36:45 | 000,000,000 | —- | C] () – C:\WINDOWS\NSREX.INI
[2003/07/10 00:53:16 | 000,000,054 | —- | C] () – C:\WINDOWS\setihome.ini
[2003/07/09 23:12:55 | 000,000,034 | —- | C] () – C:\WINDOWS\alohabob.INI
[2003/07/03 07:29:25 | 000,000,061 | —- | C] () – C:\WINDOWS\smscfg.ini
[2003/07/03 07:19:29 | 000,000,376 | —- | C] () – C:\WINDOWS\ODBC.INI
[2003/07/03 07:04:28 | 000,000,893 | —- | C] () – C:\WINDOWS\orun32.ini
[2003/07/03 06:35:24 | 000,000,546 | —- | C] () – C:\WINDOWS\System32\OEMINFO.INI
[2002/10/28 10:53:49 | 000,210,944 | —- | C] () – C:\WINDOWS\System32\MSVCRT10.DLL
[2002/10/28 10:53:43 | 000,000,083 | —- | C] () – C:\WINDOWS\KPCMS.INI
[2002/07/03 10:57:48 | 000,013,203 | —- | C] () – C:\WINDOWS\System32\drivers\packet.sys
[2002/01/08 19:03:10 | 000,077,824 | —- | C] () – C:\WINDOWS\System32\MiniBrowser.dll
[2001/12/17 21:30:43 | 000,000,359 | —- | C] () – C:\WINDOWS\smsafari.ini
[2001/12/17 21:17:17 | 000,012,416 | —- | C] () – C:\WINDOWS\System32\VRX1.DLL
[2001/12/17 21:17:16 | 000,027,136 | —- | C] () – C:\WINDOWS\System32\VERMONT1.DLL
[2001/12/17 21:17:11 | 000,107,520 | —- | C] () – C:\WINDOWS\System32\SIMANT.DLL
[2001/12/03 15:58:32 | 000,286,208 | —- | C] () – C:\WINDOWS\System32\DCSSDK32.dll
[2001/12/03 15:58:32 | 000,107,456 | —- | C] () – C:\WINDOWS\System32\SH33W32.DLL
[2001/11/21 19:44:10 | 000,003,413 | —- | C] () – C:\Documents and Settings\Neil\Application Data\dw.log
[2001/07/05 16:36:07 | 000,000,370 | —- | C] () – C:\WINDOWS\KA.INI
[2001/05/30 08:47:44 | 000,110,592 | —- | C] () – C:\WINDOWS\System32\cdtool.dll
[2001/05/12 16:10:41 | 000,056,832 | —- | C] () – C:\WINDOWS\System32\iyvu9_32.dll
[2001/05/12 11:01:14 | 000,167,936 | —- | C] () – C:\WINDOWS\System32\XFILEXR.DLL
[2001/05/12 10:59:13 | 000,040,960 | —- | C] () – C:\WINDOWS\System32\OEMREG.DLL
[2001/05/12 10:58:38 | 000,008,576 | —- | C] () – C:\WINDOWS\System32\ICMUPG.DLL
[2001/05/12 10:54:15 | 000,028,672 | —- | C] () – C:\WINDOWS\System32\NETBIOS.DLL
[2001/05/12 10:53:38 | 000,188,416 | —- | C] () – C:\WINDOWS\System32\MEMBG.DLL
[2001/05/12 10:51:28 | 000,002,490 | —- | C] () – C:\WINDOWS\System32\DLCNDI.DLL
[2001/05/12 09:46:50 | 000,009,216 | —- | C] () – C:\WINDOWS\System32\Spktrn32.dll
[2001/05/12 09:29:56 | 000,040,448 | —- | C] () – C:\WINDOWS\System32\hcfuninst.dll
[2001/05/12 09:29:56 | 000,028,672 | —- | C] () – C:\WINDOWS\System32\hcfapi.dll
[2000/10/21 01:21:26 | 000,363,520 | —- | C] () – C:\WINDOWS\System32\psisdecd.dll
[1999/07/23 12:46:48 | 000,000,116 | —- | C] () – C:\WINDOWS\AuHCcup1.ini
[1999/07/23 09:53:20 | 000,129,536 | —- | C] () – C:\WINDOWS\AuHCcup1.dll
[1999/01/22 17:46:58 | 000,065,536 | —- | C] () – C:\WINDOWS\System32\MSRTEDIT.DLL
[1980/01/01 00:00:00 | 000,031,744 | —- | C] () – C:\WINDOWS\System32\mdmmoh.dll
[1979/12/31 11:29:50 | 000,038,352 | —- | C] () – C:\WINDOWS\System32\NAVAPGUI.DLL

========== LOP Check ==========

[2010/02/28 11:29:50 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\AVG Security Toolbar
[2008/10/23 21:50:10 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Banner Maker Pro 7
[2007/11/03 14:11:59 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\GlobalSCAPE
[2005/04/03 22:08:03 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\RoboForm
[2008/08/22 07:34:02 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Spyware Terminator
[2008/03/20 08:50:30 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\SupportSoft
[2007/11/08 14:55:57 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TEMP
[2007/12/03 11:27:07 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Viewpoint
[2008/12/30 21:58:40 | 000,000,000 | —D | M] – C:\Documents and Settings\Neil\Application Data\AVGTOOLBAR
[2007/04/25 18:03:39 | 000,000,000 | —D | M] – C:\Documents and Settings\Neil\Application Data\Digital Photo Slide Show
[2007/11/03 14:11:52 | 000,000,000 | —D | M] – C:\Documents and Settings\Neil\Application Data\GlobalSCAPE
[2003/07/09 17:05:42 | 000,000,000 | —D | M] – C:\Documents and Settings\Neil\Application Data\InterVideo
[2006/04/06 15:10:57 | 000,000,000 | —D | M] – C:\Documents and Settings\Neil\Application Data\Kensington
[2007/05/17 22:28:21 | 000,000,000 | —D | M] – C:\Documents and Settings\Neil\Application Data\KompoZer
[2004/04/20 16:38:15 | 000,000,000 | —D | M] – C:\Documents and Settings\Neil\Application Data\Leadertech
[2007/07/12 21:22:05 | 000,000,000 | —D | M] – C:\Documents and Settings\Neil\Application Data\Novagraph
[2010/02/25 11:47:37 | 000,000,000 | —D | M] – C:\Documents and Settings\Neil\Application Data\Registry Booster
[2004/07/10 01:31:42 | 000,000,000 | —D | M] – C:\Documents and Settings\Neil\Application Data\Screen Calendar
[2010/03/02 11:35:03 | 000,000,000 | —D | M] – C:\Documents and Settings\Neil\Application Data\SlimBrowser
[2008/08/21 22:42:02 | 000,000,000 | —D | M] – C:\Documents and Settings\Neil\Application Data\Spyware Terminator
[2004/06/30 20:03:31 | 000,000,000 | —D | M] – C:\Documents and Settings\Neil\Application Data\Thunderbird
[2007/01/13 22:29:07 | 000,000,000 | —D | M] – C:\Documents and Settings\Neil\Application Data\Uniblue
[2007/12/03 11:27:14 | 000,000,000 | —D | M] – C:\Documents and Settings\Neil\Application Data\Viewpoint
[2003/07/09 22:53:59 | 000,000,258 | —- | M] () – C:\WINDOWS\Tasks\ISP signup reminder 1.job

========== Purity Check ==========



========== Alternate Data Streams ==========

@Alternate Data Stream - 125 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:08948D52
< End of report >

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI