This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] recurring Win32.kstp trojan, may be rootkit?

15 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Okie-doke, Tom. Named it schrauberB this time. Here's combofix log

ComboFix 10-03-15.04 - Owner 03/15/2010 20:54:02.2.1 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.894.440 [GMT -4:00]
Running from: c:\documents and settings\[removed]\Desktop\schrauberB.exe
AV: ZoneAlarm Security Suite Antivirus *On-access scanning disabled* (Updated) {5D467B10-818C-4CAB-9FF7-6893B5B8F3CF}
FW: ZoneAlarm Security Suite Firewall *disabled* {829BDA32-94B3-44F4-8446-F8FCFF809F8B}
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\windows\TEMP\logishrd\LVPrcInj01.dll

.
((((((((((((((((((((((((( Files Created from 2010-02-16 to 2010-03-16 )))))))))))))))))))))))))))))))
.

2010-03-10 22:30 . 2010-03-10 22:30 ——– d—–w- C:\_OTL
2010-03-10 13:15 . 2009-10-23 15:28 3558912 -c—-w- c:\windows\system32\dllcache\moviemk.exe
2010-03-10 12:19 . 2010-03-10 12:19 ——– d—–w- c:\program files\Common Files\Java
2010-03-10 12:18 . 2010-03-10 12:18 ——– d—–w- c:\program files\Java
2010-03-09 00:33 . 2010-03-09 00:33 ——– d—–w- c:\program files\ESET
2010-03-05 15:43 . 2010-03-05 15:43 ——– d—–w- c:\windows\system32\XPSViewer
2010-03-05 15:43 . 2010-03-05 15:43 ——– d—–w- c:\program files\MSBuild
2010-03-05 15:43 . 2010-03-05 15:43 ——– d—–w- c:\program files\Reference Assemblies
2010-03-05 15:42 . 2008-07-06 12:06 89088 —-a-w- c:\windows\system32\Spool\prtprocs\w32x86\filterpipelineprintproc.dll
2010-03-05 15:42 . 2008-07-06 12:06 89088 -c—-w- c:\windows\system32\dllcache\filterpipelineprintproc.dll
2010-03-05 15:42 . 2008-07-06 12:06 575488 -c—-w- c:\windows\system32\dllcache\xpsshhdr.dll
2010-03-05 15:42 . 2008-07-06 12:06 575488 ——w- c:\windows\system32\xpsshhdr.dll
2010-03-05 15:42 . 2008-07-06 12:06 117760 ——w- c:\windows\system32\prntvpt.dll
2010-03-05 15:42 . 2008-07-06 10:50 597504 -c—-w- c:\windows\system32\dllcache\printfilterpipelinesvc.exe
2010-03-05 15:42 . 2008-07-06 10:50 597504 ——w- c:\windows\system32\Spool\prtprocs\w32x86\printfilterpipelinesvc.exe
2010-03-05 15:42 . 2008-07-06 12:06 1676288 -c—-w- c:\windows\system32\dllcache\xpssvcs.dll
2010-03-05 15:42 . 2008-07-06 12:06 1676288 ——w- c:\windows\system32\xpssvcs.dll
2010-03-05 15:42 . 2010-03-05 15:42 ——– d—–w- C:\54e28b4d65b8699388263bd778
2010-03-04 12:56 . 2010-03-04 12:56 ——– d—–w- c:\program files\ERUNT
2010-02-25 12:14 . 2010-02-25 12:14 ——– d—–w- c:\documents and settings\Owner\Local Settings\Application Data\Temp

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-03-16 01:11 . 2007-01-20 13:55 915735328 –sha-w- c:\windows\system32\drivers\fidbox.dat
2010-03-16 01:04 . 2007-01-20 13:55 12264404 –sha-w- c:\windows\system32\drivers\fidbox.idx
2010-03-16 01:03 . 2010-03-16 01:05 192000 —-a-w- c:\windows\Internet Logs\xDBC2.tmp
2010-03-16 00:40 . 2009-08-30 20:24 ——– d—–w- c:\program files\SpywareBlaster
2010-03-15 22:49 . 2010-01-22 14:11 3947 —-a-w- c:\documents and settings\Owner\Application Data\Trillian\users\default\buddyicons\[removed]
2010-03-15 16:49 . 2007-02-24 11:02 65189385 —-a-w- c:\windows\Internet Logs\tvDebug.zip
2010-03-13 17:10 . 2010-03-13 22:16 53248 —-a-w- c:\windows\Internet Logs\xDBC1.tmp
2010-03-13 15:09 . 2010-03-13 16:06 60928 —-a-w- c:\windows\Internet Logs\xDBC0.tmp
2010-03-13 00:52 . 2010-03-13 00:52 127998 —-a-w- c:\windows\Internet Logs\vsmon_2nd_2010_03_12_19_46_42_small.dmp.zip
2010-03-13 00:44 . 2010-03-13 00:47 1839104 —-a-w- c:\windows\Internet Logs\xDBBF.tmp
2010-03-11 11:47 . 2007-01-20 13:49 4212 —ha-w- c:\windows\system32\zllictbl.dat
2010-03-10 12:19 . 2010-03-10 12:19 348160 —-a-w- c:\documents and settings\Owner\Application Data\Sun\Java\Deployment\SystemCache\6.0\54\1a209876-6b2d2e64-n\msvcr71.dll
2010-03-10 12:19 . 2010-03-10 12:19 61440 —-a-w- c:\documents and settings\Owner\Application Data\Sun\Java\Deployment\SystemCache\6.0\17\6d0ad391-623155e9-n\decora-sse.dll
2010-03-10 12:19 . 2010-03-10 12:19 503808 —-a-w- c:\documents and settings\Owner\Application Data\Sun\Java\Deployment\SystemCache\6.0\54\1a209876-6b2d2e64-n\msvcp71.dll
2010-03-10 12:19 . 2010-03-10 12:19 499712 —-a-w- c:\documents and settings\Owner\Application Data\Sun\Java\Deployment\SystemCache\6.0\54\1a209876-6b2d2e64-n\jmc.dll
2010-03-10 12:19 . 2010-03-10 12:19 12800 —-a-w- c:\documents and settings\Owner\Application Data\Sun\Java\Deployment\SystemCache\6.0\17\6d0ad391-623155e9-n\decora-d3d.dll
2010-03-10 12:18 . 2008-11-29 13:42 411368 —-a-w- c:\windows\system32\deploytk.dll
2010-03-10 12:17 . 2010-03-10 12:17 79488 —-a-w- c:\documents and settings\Owner\Application Data\Sun\Java\jre1.6.0_18\gtapi.dll
2010-03-10 12:17 . 2010-03-10 12:17 152576 —-a-w- c:\documents and settings\Owner\Application Data\Sun\Java\jre1.6.0_18\lzma.dll
2010-03-10 11:57 . 2005-08-03 15:34 ——– d—–w- c:\documents and settings\All Users\Application Data\Viewpoint
2010-03-08 02:31 . 2010-03-08 02:32 3284480 —-a-w- c:\windows\Internet Logs\xDBBE.tmp
2010-03-05 16:16 . 2005-11-13 17:44 59168 —-a-w- c:\documents and settings\Owner\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2010-03-02 12:17 . 2010-03-02 12:17 118653 —-a-w- c:\windows\Internet Logs\vsmon_2nd_2010_03_02_07_12_23_small.dmp.zip
2010-03-02 12:12 . 2010-03-03 15:30 8704 —-a-w- c:\windows\Internet Logs\xDBBD.tmp
2010-03-02 12:12 . 2010-03-02 12:12 729600 —-a-w- c:\windows\Internet Logs\xDBBC.tmp
2010-03-02 03:36 . 2009-08-30 20:05 ——– d—–w- c:\program files\CCleaner
2010-03-02 02:24 . 2009-08-30 20:24 ——– d—a-w- c:\documents and settings\All Users\Application Data\TEMP
2010-02-23 22:22 . 2010-02-23 22:22 115990 —-a-w- c:\windows\Internet Logs\vsmon_2nd_2010_02_23_17_17_19_small.dmp.zip
2010-02-23 22:17 . 2010-02-24 00:54 8704 —-a-w- c:\windows\Internet Logs\xDBBB.tmp
2010-02-23 22:17 . 2010-02-23 22:17 539648 —-a-w- c:\windows\Internet Logs\xDBBA.tmp
2010-02-20 23:27 . 2010-02-21 16:17 2689024 —-a-w- c:\windows\Internet Logs\xDBB9.tmp
2010-02-17 12:18 . 2010-02-17 12:18 118853 —-a-w- c:\windows\Internet Logs\vsmon_2nd_2010_02_17_07_13_22_small.dmp.zip
2010-02-17 12:11 . 2010-02-17 12:13 3065856 —-a-w- c:\windows\Internet Logs\xDBB8.tmp
2010-02-17 03:08 . 2010-02-17 03:08 23058 —-a-w- c:\documents and settings\Owner\Application Data\Trillian\users\default\buddyicons\[removed]
2010-01-30 18:08 . 2005-08-03 15:36 ——– d—–w- c:\program files\Google
2010-01-23 20:23 . 2006-04-28 15:30 ——– d—–w- c:\program files\Trillian
2010-01-20 01:38 . 2010-01-20 01:19 ——– d—–w- c:\documents and settings\Owner\Application Data\Trillian
2010-01-18 14:48 . 2010-01-18 14:48 131161 —-a-w- c:\windows\Internet Logs\vsmon_2nd_2010_01_18_09_42_59_small.dmp.zip
2010-01-18 14:43 . 2010-01-18 14:43 3585024 —-a-w- c:\windows\Internet Logs\xDBB7.tmp
2010-01-08 09:15 . 2009-08-22 12:19 5115824 —-a-w- c:\documents and settings\All Users\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\mbam-setup.exe
2010-01-07 21:07 . 2009-04-27 14:37 38224 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-01-07 21:07 . 2009-04-27 14:37 19160 —-a-w- c:\windows\system32\drivers\mbam.sys
2010-01-07 02:53 . 2010-01-07 11:42 3220480 —-a-w- c:\windows\Internet Logs\xDBB6.tmp
2010-01-05 10:00 . 2005-04-13 16:56 832512 ——w- c:\windows\system32\wininet.dll
2010-01-05 10:00 . 2005-04-13 16:55 78336 —-a-w- c:\windows\system32\ieencode.dll
2010-01-05 10:00 . 2005-04-13 16:55 17408 —-a-w- c:\windows\system32\corpol.dll
2009-12-31 16:50 . 2008-08-24 13:31 353792 —-a-w- c:\windows\system32\drivers\srv.sys
2009-12-16 18:43 . 2005-04-13 17:12 343040 —-a-w- c:\windows\system32\mspaint.exe
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-05-31 68856]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray"="c:\windows\ehome\ehtray.exe" [2004-08-10 59392]
"CHotkey"="zHotkey.exe" [2004-05-18 543232]
"ShowWnd"="ShowWnd.exe" [2003-09-19 36864]
"AOL Spyware Protection"="c:\progra~1\COMMON~1\AOL\AOLSPY~1\AOLSP Scheduler.exe" [2004-03-19 78960]
"SunKistEM"="c:\program files\Digital Media Reader\shwiconem.exe" [2004-11-15 135168]
"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2005-08-03 98304]
"ATIPTA"="c:\program files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2005-03-18 339968]
"RemoteControl"="c:\program files\CyberLink\PowerDVD\PDVDServ.exe" [2004-11-03 32768]
"Recguard"="c:\windows\SMINST\RECGUARD.EXE" [2002-09-14 212992]
"SoundMan"="SOUNDMAN.EXE" [2004-12-01 77824]
"Adobe Photo Downloader"="c:\program files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe" [2005-06-07 57344]
"ADUserMon"="c:\program files\Iomega\AutoDisk\ADUserMon.exe" [2002-09-24 147456]
"Iomega Drive Icons"="c:\program files\Iomega\DriveIcons\ImgIcon.exe" [2002-08-13 86016]
"Deskup"="c:\program files\Iomega\DriveIcons\deskup.exe" [2002-07-16 32768]
"Windows Defender"="c:\program files\Windows Defender\MSASCui.exe" [2006-11-03 866584]
"LogitechQuickCamRibbon"="c:\program files\Logitech\QuickCam\Quickcam.exe" [2008-12-20 2656528]
"ZoneAlarm Client"="c:\program files\Zone Labs\ZoneAlarm\zlclient.exe" [2009-05-29 1005960]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-02-18 248040]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2008-4-23 29696]
HPAiODevice(hp officejet g series) - 1.lnk - c:\program files\Hewlett-Packard\AiO\hp officejet g series\Bin\hpoavn07.exe [2002-11-20 151552]
Logitech Desktop Messenger.lnk - c:\program files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe [2008-7-20 67128]
Quicken Scheduled Updates.lnk - c:\program files\Quicken\bagent.exe [2006-9-16 57344]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\ZoneLabsFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Common Files\\AOL\\ACS\\AOLacsd.exe"=
"c:\\Program Files\\Common Files\\AOL\\ACS\\AOLDial.exe"=
"c:\\Program Files\\America Online 9.0\\waol.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\Hewlett-Packard\\AiO\\hp officejet g series\\Bin\\hpoavn07.exe"=
"c:\\Program Files\\Logitech\\Desktop Messenger\\8876480\\Program\\LogitechDesktopMessenger.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=

S2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [1/30/2010 2:08 PM 135664]
S2 WinDefend;Windows Defender;c:\program files\Windows Defender\MsMpEng.exe [11/3/2006 7:19 PM 13592]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
getPlusHelper REG_MULTI_SZ getPlusHelper
.
Contents of the 'Scheduled Tasks' folder

2010-03-16 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-01-30 18:08]

2010-03-16 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-01-30 18:08]
.
.
——- Supplementary Scan ——-
.
uStart Page = about:blank
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
uInternet Settings,ProxyOverride = 127.0.0.1
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: &AOL Toolbar search - c:\program files\AOL Toolbar\toolbar.dll/SEARCH.HTML
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
IE: Google Sidewiki… - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_96D6FF0C6D236BF8.dll/cmsidewiki.html
Handler: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - c:\program files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
DPF: {EF6E7E56-9229-4C73-AAD0-15316405DB95} - hxxp://lmitchell619.photosite.com/~site/UploadBox/UploadBox_live.cab
FF - ProfilePath - c:\documents and settings\Owner\Application Data\Mozilla\Firefox\Profiles\0vop8812.default\
FF - plugin: c:\program files\Google\Update\1.2.183.17\npGoogleOneClick8.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\

—- FIREFOX POLICIES —-
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_colors", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_popup_windows", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.enable_click_image_resizing", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("accessibility.browsewithcaret_shortcut.enabled", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("javascript.options.mem.high_water_mark", 32);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("javascript.options.mem.gc_frequency", 1600);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("svg.smil.enabled", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.trackpoint_hack.enabled", -1);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.debug", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.agedWeight", 2);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.bucketSize", 1);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.maxTimeGroupings", 25);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.timeGroupingSize", 604800);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.boundaryWeight", 25);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.prefixWeight", 5);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("html5.enable", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("app.update.download.backgroundInterval", 600);
c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("app.update.url.manual", "http://www.firefox.com");
c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-ja", "mozff");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add", "addons.mozilla.org");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add.36", "getpersonas.com");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("lightweightThemes.update.enabled", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.allTabs.previews", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.hide_infobar_for_outdated_plugin", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("toolbar.customization.usesheet", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.enable", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.max", 20);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.cachetime", 20);
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-03-15 21:06
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Iomega Activity Disk2]
"ImagePath"="\"\""
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'winlogon.exe'(608)
c:\windows\system32\Ati2evxx.dll

- - - - - - - > 'explorer.exe'(7892)
c:\windows\system32\WININET.dll
c:\windows\TEMP\logishrd\LVPrcInj01.dll
c:\progra~1\ZONELA~1\ZONEAL~1\MAILFR~1\mlfhook.dll
c:\program files\Iomega\DriveIcons\IMGHOOK.DLL
c:\windows\system32\ieframe.dll
.
———————— Other Running Processes ————————
.
c:\windows\system32\Ati2evxx.exe
c:\progra~1\COMMON~1\AOL\ACS\AOLacsd.exe
c:\windows\eHome\ehRecvr.exe
c:\windows\eHome\ehSched.exe
c:\progra~1\Iomega\System32\AppServices.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
c:\program files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
c:\windows\system32\wdfmgr.exe
c:\program files\Iomega\AutoDisk\ADService.exe
c:\windows\system32\Ati2evxx.exe
c:\windows\system32\dllhost.exe
c:\windows\zHotkey.exe
c:\windows\eHome\ehmsas.exe
c:\windows\SOUNDMAN.EXE
c:\windows\system32\wscntfy.exe
c:\program files\Common Files\Logishrd\LQCVFX\COCIManager.exe
c:\progra~1\ZONELA~1\ZONEAL~1\MAILFR~1\mantispm.exe
c:\progra~1\HEWLET~1\AiO\Shared\Bin\hpoevm07.exe
c:\windows\system32\hpoipm07.exe
c:\program files\Hewlett-Packard\AiO\Shared\bin\hpOSTS07.exe
c:\program files\Hewlett-Packard\AiO\Shared\bin\hpOFXM07.exe
.
**************************************************************************
.
Completion time: 2010-03-15 21:14:08 - machine was rebooted
ComboFix-quarantined-files.txt 2010-03-16 01:14
ComboFix2.txt 2010-03-08 03:09

Pre-Run: 164,770,549,760 bytes free
Post-Run: 164,874,366,976 bytes free

Current=1 Default=1 Failed=0 LastKnownGood=5 Sets=1,2,3,4,5
- - End Of File - - 65A8573D1DBE7D8C1871233FAED60F7B
Hi, Tom.

Running so-so.

Wasn't sure how you wanted me to run the OTL, so I used the same list of items for the Custom Scan box as you gave me the first time, back on the 8th.

OTL logfile created on: 3/17/2010 5:46:22 PM - Run 3
OTL by OldTimer - Version 3.1.35.0 Folder = C:\Documents and Settings\Owner\Desktop
Windows XP Media Center Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.11)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

894.00 Mb Total Physical Memory | 520.00 Mb Available Physical Memory | 58.00% Memory free
2.00 Gb Paging File | 2.00 Gb Available in Paging File | 73.00% Paging File free
Paging file location(s): C:\pagefile.sys 1344 2688 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 182.10 Gb Total Space | 153.49 Gb Free Space | 84.29% Space Free | Partition Type: NTFS
Drive D: | 4.20 Gb Total Space | 0.99 Gb Free Space | 23.63% Space Free | Partition Type: FAT32
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: LINDAOFFICE
Current User Name: Owner
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: On
Skip Microsoft Files: On
File Age = 14 Days
Output = Minimal
Quick Scan

========== Processes (SafeList) ==========

PRC - C:\Documents and Settings\Owner\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Trillian\trillian.exe (Cerulean Studios)
PRC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe (Check Point Software Technologies LTD)
PRC - C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe (Check Point Software Technologies LTD)
PRC - C:\WINDOWS\system32\ZoneLabs\avsys\ScanningProcess.exe (Kaspersky Lab.)
PRC - C:\Program Files\Zone Labs\ZoneAlarm\MailFrontier\mantispm.exe (SonicWALL, Inc.)
PRC - C:\Program Files\Logitech\QuickCam\Quickcam.exe ()
PRC - C:\Program Files\Common Files\LogiShrd\LQCVFX\COCIManager.exe ()
PRC - C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe (Logitech Inc.)
PRC - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe (Logitech Inc.)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.)
PRC - C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS (New Boundary Technologies, Inc.)
PRC - C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe (Adobe Systems Incorporated)
PRC - C:\WINDOWS\SOUNDMAN.EXE (Realtek Semiconductor Corp.)
PRC - C:\Program Files\Digital Media Reader\shwiconEM.exe (Alcor Micro, Corp.)
PRC - C:\WINDOWS\zHotkey.exe ()
PRC - C:\Program Files\Common Files\AOL\ACS\AOLacsd.exe (America Online, Inc.)
PRC - C:\Program Files\Common Files\AOL\AOL Spyware Protection\AOLSP Scheduler.exe ()
PRC - C:\Program Files\Hewlett-Packard\AiO\Shared\Bin\hpofxm07.exe (Hewlett-Packard Co.)
PRC - C:\WINDOWS\system32\hpoipm07.exe (HP)
PRC - C:\Program Files\Hewlett-Packard\AiO\Shared\Bin\hposts07.exe (Hewlett-Packard Co.)
PRC - C:\Program Files\Hewlett-Packard\AiO\Shared\Bin\hpoevm07.exe (Hewlett-Packard Co.)
PRC - C:\Program Files\Hewlett-Packard\AiO\hp officejet g series\Bin\hpoavn07.exe (Hewlett-Packard Co.)
PRC - C:\Program Files\Iomega\AutoDisk\ADService.exe (Iomega Corporation)
PRC - C:\Program Files\Iomega\AutoDisk\ADUserMon.exe (Iomega Corporation)
PRC - C:\Program Files\Iomega\System32\AppServices.exe (Iomega Corporation)
PRC - C:\Program Files\Iomega\DriveIcons\Imgicon.exe (Iomega)


========== Modules (SafeList) ==========

MOD - C:\Documents and Settings\Owner\Desktop\OTL.exe (OldTimer Tools)
MOD - C:\Program Files\Zone Labs\ZoneAlarm\MailFrontier\MlfHook.dll ()
MOD - C:\WINDOWS\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.3053_x-ww_b80fa8ca\msvcr80.dll (Microsoft Corporation)
MOD - C:\WINDOWS\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.3053_x-ww_b80fa8ca\msvcp80.dll (Microsoft Corporation)
MOD - C:\WINDOWS\system32\cabinet.dll (Microsoft Corporation)
MOD - C:\WINDOWS\system32\rsaenh.dll (Microsoft Corporation)
MOD - C:\Program Files\Windows Defender\MpShHook.dll (Microsoft Corporation)
MOD - C:\Program Files\Iomega\DriveIcons\Imghook.dll (Iomega Corporation)


========== Win32 Services (SafeList) ==========

SRV - (Iomega Activity Disk2) – File not found
SRV - (getPlusHelper) getPlus® – C:\Program Files\NOS\bin\getPlus_Helper.dll (NOS Microsystems Ltd.)
SRV - (vsmon) – C:\WINDOWS\System32\ZoneLabs\vsmon.exe (Check Point Software Technologies LTD)
SRV - (LVPrcSrv) – C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe (Logitech Inc.)
SRV - (WLSetupSvc) – C:\Program Files\Windows Live\installer\WLSetupSvc.exe (Microsoft Corporation)
SRV - (usnjsvc) – C:\Program Files\Windows Live\Messenger\usnsvc.exe (Microsoft Corporation)
SRV - (WinDefend) – C:\Program Files\Windows Defender\MsMpEng.exe (Microsoft Corporation)
SRV - (PrismXL) – C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS (New Boundary Technologies, Inc.)
SRV - (AOL ACS) – C:\Program Files\Common Files\AOL\ACS\AOLacsd.exe (America Online, Inc.)
SRV - (_IOMEGA_ACTIVE_DISK_SERVICE_) – C:\Program Files\Iomega\AutoDisk\ADService.exe (Iomega Corporation)
SRV - (Iomega App Services) – C:\Program Files\Iomega\System32\AppServices.exe (Iomega Corporation)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultName = Google
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultURL = http://www.google.com/search?q={searchTerm…tf8&oe=utf8
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = about:blank
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = 127.0.0.1

========== FireFox ==========

FF - prefs.js..extensions.enabledItems: [removed]:1.0

FF - HKLM\software\mozilla\Mozilla Firefox 3.6\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010/01/28 10:00:59 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010/03/10 08:19:03 | 000,000,000 | —D | M]

[2010/01/28 10:01:12 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Mozilla\Extensions
[2010/03/16 18:39:51 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\0vop8812.default\extensions
[2010/03/06 08:47:37 | 000,000,000 | —D | M] (Microsoft .NET Framework Assistant) – C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\0vop8812.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2010/03/16 18:39:51 | 000,000,000 | —D | M] – C:\Program Files\Mozilla Firefox\extensions

O1 HOSTS File: ([2010/03/15 21:05:38 | 000,000,027 | —- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll File not found
O2 - BHO: (Skype add-on (mastermind)) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Skype Technologies S.A.)
O2 - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.5.4723.1820\swg.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O3 - HKCU\..\Toolbar\ShellBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O4 - HKLM..\Run: [Adobe Photo Downloader] C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [ADUserMon] C:\Program Files\Iomega\AutoDisk\ADUserMon.exe (Iomega Corporation)
O4 - HKLM..\Run: [AOL Spyware Protection] C:\Program Files\Common Files\AOL\AOL Spyware Protection\AOLSP Scheduler.exe ()
O4 - HKLM..\Run: [CHotkey] C:\WINDOWS\zHotkey.exe ()
O4 - HKLM..\Run: [Deskup] C:\Program Files\Iomega\DriveIcons\deskup.exe (Iomega)
O4 - HKLM..\Run: [Iomega Drive Icons] C:\Program Files\Iomega\DriveIcons\Imgicon.exe (Iomega)
O4 - HKLM..\Run: [LogitechQuickCamRibbon] C:\Program Files\Logitech\QuickCam\Quickcam.exe ()
O4 - HKLM..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe (Ahead Software Gmbh)
O4 - HKLM..\Run: [Recguard] C:\WINDOWS\SMINST\Recguard.exe ()
O4 - HKLM..\Run: [ShowWnd] C:\WINDOWS\ShowWnd.exe ()
O4 - HKLM..\Run: [SoundMan] C:\WINDOWS\SOUNDMAN.EXE (Realtek Semiconductor Corp.)
O4 - HKLM..\Run: [SunKistEM] C:\Program Files\Digital Media Reader\shwiconEM.exe (Alcor Micro, Corp.)
O4 - HKLM..\Run: [Windows Defender] C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
O4 - HKLM..\Run: [ZoneAlarm Client] C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe (Check Point Software Technologies LTD)
O4 - HKCU..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe (Adobe Systems Incorporated)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\HPAiODevice(hp officejet g series) - 1.lnk = C:\Program Files\Hewlett-Packard\AiO\hp officejet g series\Bin\hpoavn07.exe (Hewlett-Packard Co.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe (Logitech Inc.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Quicken Scheduled Updates.lnk = C:\Program Files\Quicken\bagent.exe (Intuit Inc.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: InstallVisualStyle = C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles (Microsoft)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: InstallTheme = C:\WINDOWS\Resources\Themes\Royale.theme ()
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O8 - Extra context menu item: Google Sidewiki… - C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_96D6FF0C6D236BF8.dll (Google Inc.)
O9 - Extra Button: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - Reg Error: Key error. File not found
O9 - Extra 'Tools' menuitem : AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - Reg Error: Value error. File not found
O9 - Extra 'Tools' menuitem : Skype add-on for Internet Explorer - {5067A26B-1337-4436-8AFE-EE169C2DA79F} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Skype Technologies S.A.)
O9 - Extra Button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - Reg Error: Key error. File not found
O12 - Plugin for: .wav - C:\Program Files\Internet Explorer\PLUGINS\npqtplugin2.dll (Apple Computer, Inc.)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://go.microsoft.com/fwlink/?linkid=39204 (Windows Genuine Advantage Validation Tool)
O16 - DPF: {3E68E405-C6DE-49FF-83AE-41EE9F4C36CE} http://office.microsoft.com/officeupdate/content/opuc3.cab (Office Update Installation Engine)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} http://update.microsoft.com/microsoftupdat…b?1130977407812 (MUWebControl Class)
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} http://download.eset.com/special/eos/OnlineScanner.cab (OnlineScanner Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_18)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get/flash…r/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {A90A5822-F108-45AD-8482-9BC8B12DD539} http://www.crucial.com/controls/cpcScanner.cab (Crucial cpcScan)
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} http://messenger.msn.com/download/MsnMesse…pDownloader.cab (MsnMessengerSetupDownloadControl Class)
O16 - DPF: {CAFEEFAC-0016-0000-0018-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_18)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_18)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/flas…ent/swflash.cab (Shockwave Flash Object)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (get_atlcom Class)
O16 - DPF: {EF6E7E56-9229-4C73-AAD0-15316405DB95} http://lmitchell619.photosite.com/~site/Up…oadBox_live.cab (Easy Photo Uploader)
O16 - DPF: {F58E1CEF-A068-4C15-BA5E-587CAF3EE8C6} http://chat.msn.com/controls/msnchat45.cab (MSN Chat Control 4.5)
O16 - DPF: Microsoft XML Parser for Java file://C:\WINDOWS\Java\classes\xmldso.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = [removed]
O18 - Protocol\Handler\bwfile-8876480 {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll (Logitech Inc.)
O18 - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\Windows Live\Messenger\msgrapp.8.5.1302.1018.dll (Microsoft Corporation)
O18 - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\Windows Live\Messenger\msgrapp.8.5.1302.1018.dll (Microsoft Corporation)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\AtiExtEvent: DllName - Ati2evxx.dll - C:\WINDOWS\System32\ati2evxx.dll (ATI Technologies Inc.)
O24 - Desktop WallPaper: C:\Documents and Settings\Owner\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Owner\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O28 - HKLM ShellExecuteHooks: {091EB208-39DD-417D-A5DD-7E2C2D8FB9CB} - C:\Program Files\Windows Defender\MpShHook.dll (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2005/04/13 13:20:25 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*

========== Files/Folders - Created Within 14 Days ==========

[2010/03/10 18:30:54 | 000,000,000 | —D | C] – C:\_OTL
[2010/03/09 00:04:09 | 000,554,496 | —- | C] (OldTimer Tools) – C:\Documents and Settings\Owner\Desktop\OTL.exe
[2010/03/07 22:20:14 | 000,000,000 | RHSD | C] – C:\cmdcons
[2010/03/07 22:17:28 | 000,212,480 | —- | C] (SteelWerX) – C:\WINDOWS\SWXCACLS.exe
[2010/03/07 22:17:28 | 000,161,792 | —- | C] (SteelWerX) – C:\WINDOWS\SWREG.exe
[2010/03/07 22:17:28 | 000,136,704 | —- | C] (SteelWerX) – C:\WINDOWS\SWSC.exe
[2010/03/07 22:17:28 | 000,031,232 | —- | C] (NirSoft) – C:\WINDOWS\NIRCMD.exe
[2010/03/07 22:16:33 | 000,000,000 | —D | C] – C:\Qoobox
[2010/03/06 22:12:53 | 000,000,000 | —D | C] – C:\Documents and Settings\Owner\Desktop\New Folder
[2010/03/05 11:43:29 | 000,000,000 | —D | C] – C:\WINDOWS\System32\XPSViewer
[2010/03/05 11:42:23 | 000,000,000 | —D | C] – C:\54e28b4d65b8699388263bd778
[2010/03/04 08:57:07 | 000,000,000 | —D | C] – C:\WINDOWS\ERDNT
[2010/03/04 08:53:46 | 000,791,393 | —- | C] (Lars Hederer ) – C:\Documents and Settings\Owner\Desktop\erunt_setup.exe
[2010/03/04 08:37:45 | 000,021,504 | —- | C] (Doug Knox) – C:\Documents and Settings\Owner\Desktop\SysRestorePoint.exe

========== Files - Modified Within 14 Days ==========

[2010/03/17 17:39:39 | 930,770,208 | -HS- | M] () – C:\WINDOWS\System32\drivers\fidbox.dat
[2010/03/17 17:19:00 | 000,000,886 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2010/03/17 16:56:38 | 000,001,661 | —- | M] () – C:\Documents and Settings\Owner\Desktop\Trillian.lnk
[2010/03/17 16:50:36 | 000,415,153 | —- | M] () – C:\WINDOWS\System32\vsconfig.xml
[2010/03/17 16:48:26 | 000,001,170 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2010/03/17 16:48:24 | 000,000,882 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2010/03/17 16:47:10 | 000,000,006 | -H– | M] () – C:\WINDOWS\tasks\SA.DAT
[2010/03/17 16:47:00 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2010/03/17 16:46:56 | 938,004,480 | -HS- | M] () – C:\hiberfil.sys
[2010/03/17 15:15:52 | 012,463,388 | -HS- | M] () – C:\WINDOWS\System32\drivers\fidbox.idx
[2010/03/17 15:15:07 | 000,000,278 | -HS- | M] () – C:\Documents and Settings\Owner\ntuser.ini
[2010/03/17 15:15:06 | 012,582,912 | -H– | M] () – C:\Documents and Settings\Owner\NTUSER.DAT
[2010/03/17 15:05:48 | 000,001,599 | —- | M] () – C:\rollback.ini
[2010/03/16 15:41:27 | 000,000,232 | -H– | M] () – C:\sqmdata12.sqm
[2010/03/16 15:41:26 | 000,000,244 | -H– | M] () – C:\sqmnoopt12.sqm
[2010/03/15 21:06:14 | 000,000,227 | —- | M] () – C:\WINDOWS\system.ini
[2010/03/15 21:05:38 | 000,000,027 | —- | M] () – C:\WINDOWS\System32\drivers\etc\hosts
[2010/03/15 20:45:00 | 003,891,061 | R— | M] () – C:\Documents and Settings\Owner\Desktop\schrauberB.exe
[2010/03/15 20:25:07 | 000,054,156 | -H– | M] () – C:\WINDOWS\QTFont.qfn
[2010/03/15 14:29:57 | 000,000,244 | -H– | M] () – C:\sqmnoopt11.sqm
[2010/03/15 14:29:57 | 000,000,232 | -H– | M] () – C:\sqmdata11.sqm
[2010/03/15 13:04:14 | 000,525,770 | —- | M] () – C:\WINDOWS\System32\PerfStringBackup.INI
[2010/03/15 13:04:14 | 000,444,358 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2010/03/15 13:04:14 | 000,072,108 | —- | M] () – C:\WINDOWS\System32\perfc009.dat
[2010/03/13 18:58:14 | 000,000,244 | -H– | M] () – C:\sqmnoopt10.sqm
[2010/03/13 18:58:14 | 000,000,232 | -H– | M] () – C:\sqmdata10.sqm
[2010/03/12 10:53:35 | 000,000,244 | -H– | M] () – C:\sqmnoopt09.sqm
[2010/03/12 10:53:35 | 000,000,232 | -H– | M] () – C:\sqmdata09.sqm
[2010/03/12 09:50:49 | 000,000,244 | -H– | M] () – C:\sqmnoopt08.sqm
[2010/03/12 09:50:49 | 000,000,232 | -H– | M] () – C:\sqmdata08.sqm
[2010/03/11 15:07:40 | 000,000,244 | -H– | M] () – C:\sqmnoopt07.sqm
[2010/03/11 15:07:40 | 000,000,232 | -H– | M] () – C:\sqmdata07.sqm
[2010/03/11 07:47:48 | 000,004,212 | -H– | M] () – C:\WINDOWS\System32\zllictbl.dat
[2010/03/10 20:31:09 | 000,000,244 | -H– | M] () – C:\sqmnoopt06.sqm
[2010/03/10 20:31:09 | 000,000,232 | -H– | M] () – C:\sqmdata06.sqm
[2010/03/10 09:22:07 | 000,000,759 | —- | M] () – C:\WINDOWS\win.ini
[2010/03/09 00:04:11 | 000,554,496 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Owner\Desktop\OTL.exe
[2010/03/08 14:49:07 | 000,000,244 | -H– | M] () – C:\sqmnoopt05.sqm
[2010/03/08 14:49:07 | 000,000,232 | -H– | M] () – C:\sqmdata05.sqm
[2010/03/07 22:20:28 | 000,000,279 | RHS- | M] () – C:\boot.ini
[2010/03/07 12:43:24 | 000,000,232 | -H– | M] () – C:\sqmdata04.sqm
[2010/03/07 12:43:23 | 000,000,244 | -H– | M] () – C:\sqmnoopt04.sqm
[2010/03/06 22:30:06 | 000,000,244 | -H– | M] () – C:\sqmnoopt03.sqm
[2010/03/06 22:30:06 | 000,000,232 | -H– | M] () – C:\sqmdata03.sqm
[2010/03/06 07:58:47 | 000,001,355 | —- | M] () – C:\WINDOWS\imsins.BAK
[2010/03/05 12:16:16 | 000,059,168 | —- | M] () – C:\Documents and Settings\Owner\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
[2010/03/05 12:05:55 | 000,220,840 | —- | M] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2010/03/04 09:33:57 | 000,359,929 | —- | M] () – C:\Documents and Settings\Owner\Desktop\dds.scr
[2010/03/04 09:23:18 | 000,293,376 | —- | M] () – C:\Documents and Settings\Owner\Desktop\1cm4rzbq.exe
[2010/03/04 08:56:06 | 000,000,650 | —- | M] () – C:\Documents and Settings\Owner\Desktop\NTREGOPT.lnk
[2010/03/04 08:56:06 | 000,000,631 | —- | M] () – C:\Documents and Settings\Owner\Desktop\ERUNT.lnk
[2010/03/04 08:53:47 | 000,791,393 | —- | M] (Lars Hederer ) – C:\Documents and Settings\Owner\Desktop\erunt_setup.exe
[2010/03/04 08:37:46 | 000,021,504 | —- | M] (Doug Knox) – C:\Documents and Settings\Owner\Desktop\SysRestorePoint.exe

========== Files Created - No Company Name ==========

[2010/03/15 20:44:57 | 003,891,061 | R— | C] () – C:\Documents and Settings\Owner\Desktop\schrauberB.exe
[2010/03/07 22:20:28 | 000,000,209 | —- | C] () – C:\Boot.bak
[2010/03/07 22:20:22 | 000,260,272 | —- | C] () – C:\cmldr
[2010/03/07 22:17:28 | 000,261,632 | —- | C] () – C:\WINDOWS\PEV.exe
[2010/03/07 22:17:28 | 000,098,816 | —- | C] () – C:\WINDOWS\sed.exe
[2010/03/07 22:17:28 | 000,080,412 | —- | C] () – C:\WINDOWS\grep.exe
[2010/03/07 22:17:28 | 000,077,312 | —- | C] () – C:\WINDOWS\MBR.exe
[2010/03/07 22:17:28 | 000,068,096 | —- | C] () – C:\WINDOWS\zip.exe
[2010/03/05 16:20:20 | 000,001,355 | —- | C] () – C:\WINDOWS\imsins.BAK
[2010/03/04 09:33:56 | 000,359,929 | —- | C] () – C:\Documents and Settings\Owner\Desktop\dds.scr
[2010/03/04 09:23:16 | 000,293,376 | —- | C] () – C:\Documents and Settings\Owner\Desktop\1cm4rzbq.exe
[2010/03/04 08:56:06 | 000,000,650 | —- | C] () – C:\Documents and Settings\Owner\Desktop\NTREGOPT.lnk
[2010/03/04 08:56:06 | 000,000,631 | —- | C] () – C:\Documents and Settings\Owner\Desktop\ERUNT.lnk
[2008/12/16 22:58:54 | 000,025,624 | —- | C] () – C:\WINDOWS\System32\drivers\LVPr2Mon.sys
[2008/12/16 22:50:56 | 000,013,584 | —- | C] () – C:\WINDOWS\System32\drivers\iKeyLgFT.dll
[2008/07/20 18:12:19 | 000,081,110 | —- | C] () – C:\WINDOWS\System32\lvcoinst.ini
[2007/01/20 09:49:13 | 000,796,312 | —- | C] () – C:\WINDOWS\System32\libeay32_0.9.6l.dll
[2006/09/16 10:02:56 | 000,000,116 | —- | C] () – C:\WINDOWS\Quicken.ini
[2006/09/16 10:02:56 | 000,000,052 | —- | C] () – C:\WINDOWS\intuprof.ini
[2006/09/16 09:52:19 | 000,000,016 | —- | C] () – C:\WINDOWS\WinInit.ini.backup
[2006/04/28 11:31:19 | 000,000,016 | —- | C] () – C:\WINDOWS\WinInit.ini
[2006/03/12 12:11:48 | 000,000,049 | —- | C] () – C:\WINDOWS\NeroDigital.ini
[2005/12/03 19:08:33 | 000,248,832 | —- | C] () – C:\WINDOWS\System32\ECircles.dll
[2005/12/03 19:08:33 | 000,153,088 | —- | C] () – C:\WINDOWS\System32\SoyWeb.dll
[2005/12/03 19:07:01 | 000,006,144 | —- | C] () – C:\WINDOWS\System32\ImgLibLead.dll
[2005/12/03 19:07:00 | 000,100,864 | —- | C] () – C:\WINDOWS\System32\Dc50ip32.dll
[2005/12/03 19:07:00 | 000,065,864 | —- | C] () – C:\WINDOWS\System32\Digita.sys
[2005/12/03 19:07:00 | 000,007,808 | —- | C] () – C:\WINDOWS\System32\dc240u.sys
[2005/12/03 19:06:46 | 000,210,944 | —- | C] () – C:\WINDOWS\System32\MSVCRT10.DLL
[2005/10/24 21:35:33 | 000,002,833 | —- | C] () – C:\WINDOWS\DevMgr.ini
[2005/10/24 21:32:45 | 000,000,020 | —- | C] () – C:\WINDOWS\Hposcv07.INI
[2005/10/24 21:32:09 | 000,003,399 | —- | C] () – C:\WINDOWS\System32\hptcpmon.ini
[2005/10/24 21:32:09 | 000,000,143 | —- | C] () – C:\WINDOWS\System32\AddPort.ini
[2005/10/24 20:43:35 | 000,005,632 | —- | C] () – C:\Documents and Settings\Owner\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2005/08/03 11:42:47 | 000,156,672 | —- | C] () – C:\WINDOWS\System32\RTLCPAPI.dll
[2005/08/03 11:38:19 | 000,000,376 | —- | C] () – C:\WINDOWS\ODBC.INI
[2005/08/03 11:19:23 | 000,532,544 | —- | C] () – C:\WINDOWS\PIC.dll
[2005/08/03 11:19:23 | 000,024,576 | —- | C] () – C:\WINDOWS\HKNTDLL.dll
[2005/04/13 15:02:03 | 000,000,061 | —- | C] () – C:\WINDOWS\smscfg.ini
[2005/04/13 12:57:05 | 000,001,446 | —- | C] () – C:\WINDOWS\System32\oeminfo.ini
[2005/04/13 12:57:05 | 000,000,498 | —- | C] () – C:\WINDOWS\System32\emver.ini
[2003/01/07 18:05:08 | 000,002,695 | —- | C] () – C:\WINDOWS\System32\OUTLPERF.INI
[2002/11/20 18:51:34 | 000,159,744 | —- | C] () – C:\WINDOWS\System32\win2000.dll
[2002/04/11 14:47:52 | 000,049,152 | —- | C] () – C:\WINDOWS\System32\msmscoin.dll

========== LOP Check ==========


========== Purity Check ==========



========== Custom Scans ==========


< %SYSTEMDRIVE%\*.exe >


< MD5 for: AGP440.SYS >
[2004/08/10 15:00:00 | 016,971,599 | —- | M] () .cab file – C:\WINDOWS\Driver Cache\i386\sp2.cab:AGP440.sys
[2008/08/24 09:30:37 | 023,852,652 | —- | M] () .cab file – C:\WINDOWS\Driver Cache\i386\sp3.cab:AGP440.sys
[2004/08/10 15:00:00 | 016,971,599 | —- | M] () .cab file – C:\WINDOWS\I386\sp2.cab:AGP440.sys
[2008/08/24 09:30:37 | 023,852,652 | —- | M] () .cab file – C:\WINDOWS\ServicePackFiles\i386\sp3.cab:AGP440.sys
[2008/04/13 14:36:38 | 000,042,368 | —- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 – C:\WINDOWS\ERDNT\cache\agp440.sys
[2008/04/13 14:36:38 | 000,042,368 | —- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 – C:\WINDOWS\ServicePackFiles\i386\agp440.sys
[2008/04/13 14:36:38 | 000,042,368 | —- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 – C:\WINDOWS\system32\drivers\agp440.sys
[2004/08/04 09:07:42 | 000,042,368 | —- | M] (Microsoft Corporation) MD5=2C428FA0C3E3A01ED93C9B2A27D8D4BB – C:\WINDOWS\$NtServicePackUninstall$\agp440.sys

< MD5 for: ATAPI.SYS >
[2004/08/10 15:00:00 | 016,971,599 | —- | M] () .cab file – C:\WINDOWS\Driver Cache\i386\sp2.cab:atapi.sys
[2008/08/24 09:30:37 | 023,852,652 | —- | M] () .cab file – C:\WINDOWS\Driver Cache\i386\sp3.cab:atapi.sys
[2004/08/10 15:00:00 | 016,971,599 | —- | M] () .cab file – C:\WINDOWS\I386\sp2.cab:atapi.sys
[2008/08/24 09:30:37 | 023,852,652 | —- | M] () .cab file – C:\WINDOWS\ServicePackFiles\i386\sp3.cab:atapi.sys
[2008/04/13 14:40:30 | 000,096,512 | —- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 – C:\WINDOWS\ERDNT\cache\atapi.sys
[2008/04/13 14:40:30 | 000,096,512 | —- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 – C:\WINDOWS\ServicePackFiles\i386\atapi.sys
[2008/04/13 14:40:30 | 000,096,512 | —- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 – C:\WINDOWS\system32\drivers\atapi.sys
[2004/08/04 01:59:44 | 000,095,360 | —- | M] (Microsoft Corporation) MD5=CDFE4411A69C224BD1D11B2DA92DAC51 – C:\WINDOWS\$NtServicePackUninstall$\atapi.sys
[2004/08/04 08:59:44 | 000,095,360 | —- | M] (Microsoft Corporation) MD5=CDFE4411A69C224BD1D11B2DA92DAC51 – C:\WINDOWS\system32\ReinstallBackups\0001\DriverFiles\i386\atapi.sys

< MD5 for: EVENTLOG.DLL >
[2008/04/13 20:11:53 | 000,056,320 | —- | M] (Microsoft Corporation) MD5=6D4FEB43EE538FC5428CC7F0565AA656 – C:\WINDOWS\ERDNT\cache\eventlog.dll
[2008/04/13 20:11:53 | 000,056,320 | —- | M] (Microsoft Corporation) MD5=6D4FEB43EE538FC5428CC7F0565AA656 – C:\WINDOWS\ServicePackFiles\i386\eventlog.dll
[2008/04/13 20:11:53 | 000,056,320 | —- | M] (Microsoft Corporation) MD5=6D4FEB43EE538FC5428CC7F0565AA656 – C:\WINDOWS\system32\eventlog.dll
[2004/08/10 15:00:00 | 000,055,808 | —- | M] (Microsoft Corporation) MD5=82B24CB70E5944E6E34662205A2A5B78 – C:\WINDOWS\$NtServicePackUninstall$\eventlog.dll

< MD5 for: NETLOGON.DLL >
[2008/04/13 20:12:01 | 000,407,040 | —- | M] (Microsoft Corporation) MD5=1B7F071C51B77C272875C3A23E1E4550 – C:\WINDOWS\ERDNT\cache\netlogon.dll
[2008/04/13 20:12:01 | 000,407,040 | —- | M] (Microsoft Corporation) MD5=1B7F071C51B77C272875C3A23E1E4550 – C:\WINDOWS\ServicePackFiles\i386\netlogon.dll
[2008/04/13 20:12:01 | 000,407,040 | —- | M] (Microsoft Corporation) MD5=1B7F071C51B77C272875C3A23E1E4550 – C:\WINDOWS\system32\netlogon.dll
[2004/08/10 15:00:00 | 000,407,040 | —- | M] (Microsoft Corporation) MD5=96353FCECBA774BB8DA74A1C6507015A – C:\WINDOWS\$NtServicePackUninstall$\netlogon.dll

< MD5 for: SCECLI.DLL >
[2004/08/10 15:00:00 | 000,180,224 | —- | M] (Microsoft Corporation) MD5=0F78E27F563F2AAF74B91A49E2ABF19A – C:\WINDOWS\$NtServicePackUninstall$\scecli.dll
[2008/04/13 20:12:05 | 000,181,248 | —- | M] (Microsoft Corporation) MD5=A86BB5E61BF3E39B62AB4C7E7085A084 – C:\WINDOWS\ERDNT\cache\scecli.dll
[2008/04/13 20:12:05 | 000,181,248 | —- | M] (Microsoft Corporation) MD5=A86BB5E61BF3E39B62AB4C7E7085A084 – C:\WINDOWS\ServicePackFiles\i386\scecli.dll
[2008/04/13 20:12:05 | 000,181,248 | —- | M] (Microsoft Corporation) MD5=A86BB5E61BF3E39B62AB4C7E7085A084 – C:\WINDOWS\system32\scecli.dll

< %systemroot%\*. /mp /s >

========== Alternate Data Streams ==========

@Alternate Data Stream - 125 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:5C321E34
< End of report >
Hi,


Please make sure that you can view all hidden files. Instructions on how to do this can be found here:

How to see hidden files in Windows

Please click this link–>Jotti

When the jotti page has finished loading, click the Browse button and navigate to the following file and click Submit.

C:\WINDOWS\system32\Macromed\Flash\FlashUtil10d.exe


Please post back the results of the scan in your next post.

If Jotti is busy, try the same at Virustotal: http://www.virustotal.com/



Running so-so.


Can you explain it a bit better? :)
Whaaa? "so-so" isn't the recognized technical term? ;) Well, Adobe Flash updated itself yesterday, so apparently the 10d.exe file is gone. Submitting the 10e.exe file to Jotti found zilch. Filename: FlashUtil10e.exe Status: Scan finished. 0 out of 20 scanners reported malware. Scan taken on: Thu 18 Mar 2010 22:04:19 (CET) Permalink File size: 256280 bytes Filetype: PE32 executable for MS Windows (GUI) Intel 80386 32-bit MD5: 678f50cbc5537150cfdcca7944130b6d SHA1: 100704db628a9323d9b6d0f07226da192ce7460b Who knows, maybe the Flash update gets rid of the recurrent trojan. And maybe the recurrent tojan wasn't causing my slowdown, it just happened to start showing up coincidentally at the same time. The only way for me to know if that trojan is still occurring is to run the Zone Alarm scan. As far as judging speed/performance—- it only takes about 45 minutes of surfing eBay, running say 3 to 8 windows at a time, before it slows to a crawl. Used to be, I would empty the temp internet files and then run my virus-spy scans once a week. Just recently, it got so I have to do that about every two hours to restore reasonable surfing speed. And that trojan was showing up every time. So a friend who'd had a recurring trojan suggested I contact you guys. So here I am. [Surfing eBay is a typical use of the computer for me, therefore a way to evaluate speed, but the trojan would show up even when I didn't go to eBay.] "so-so" meant that it didn't seem quite as slow as it had been, but not as fast as it should be. And that I hadn't put it thru a full typical session. Weather's turning good! I don't surf as much once the winter wanes. But I did surf last night and once again it slowed down within an hour. Quitting and rebooting bought me another hour or so. Now, I suppose it could be just that content load of most web pages has crested some threshold that my computer just can't handle. Admittedly, it's not the newest on the block. If you think it'll help, I'll go to the section on "what to do if your computer is running slowly" and try all that stuff. Tho I've never found defragging to make any noticeable difference. Thanks for bearing with me here, Thomas.
You're welcome :) In which browser do you get those problems? Did you try another one? Also, I would suggest to uninstall Zone Alarm, this software is oftentimes a pain for the system speed. Please also try the steps from the other topic and let me know :).
Hi, Tom. I was getting the trojan in both IE-7 and Firefox. But now the trojan seems to have taken a hike. The worst slowdowns are in surfing eBay on IE-7. I've not heard much good about IE-8. And I don't like Firefox for eBay, though maybe I could find some add-ons to Firefox to make it more useful for me. As of yet, I only use Firefox to play Lexulous on Facebook. Was figuring on switching to Firefox eventually. Yes, I know ZA is bloatware. It wasn't when I first got it, but too many updateslater, it is now. I don't even try to surf when ZA is updating itself. I'll probably switch to McAfee unless y'all have some reason not to. I'll be away from the computer now til Tuesday afternoon, so will get to the speed-up tasks then. Cya! and thanks again.
Ok :) Also please open OTL again, set the extra registry tab to use safe list and hit the run scan button, post back with the 2 logfiles.
Ok, have done disk cleanup, defragged. Rubberducky's StartupLite didn't work, got the message that it "is not a valid WIN32 application". Don't have a Hosts file. Indexing Service was already disabled. My hard drive has 84% free space. I removed all but the last System Restore Point. So that's the speed-up stuff. Will do OTL run tomorrow.
OTL results just now:

OTL logfile created on: 3/24/2010 1:27:38 PM - Run 4
OTL by OldTimer - Version 3.1.35.0 Folder = C:\Documents and Settings\Owner\Desktop
Windows XP Media Center Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.11)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

894.00 Mb Total Physical Memory | 390.00 Mb Available Physical Memory | 44.00% Memory free
2.00 Gb Paging File | 2.00 Gb Available in Paging File | 75.00% Paging File free
Paging file location(s): C:\pagefile.sys 1344 2688 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 182.10 Gb Total Space | 161.88 Gb Free Space | 88.90% Space Free | Partition Type: NTFS
Drive D: | 4.20 Gb Total Space | 0.99 Gb Free Space | 23.64% Space Free | Partition Type: FAT32
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: LINDAOFFICE
Current User Name: Owner
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal

========== Processes (SafeList) ==========

PRC - C:\Documents and Settings\Owner\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe (Check Point Software Technologies LTD)
PRC - C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe (Check Point Software Technologies LTD)
PRC - C:\WINDOWS\system32\ZoneLabs\avsys\ScanningProcess.exe (Kaspersky Lab.)
PRC - C:\Program Files\Zone Labs\ZoneAlarm\MailFrontier\mantispm.exe (SonicWALL, Inc.)
PRC - C:\Program Files\Logitech\QuickCam\Quickcam.exe ()
PRC - C:\Program Files\Common Files\LogiShrd\LQCVFX\COCIManager.exe ()
PRC - C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe (Logitech Inc.)
PRC - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe (Logitech Inc.)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.)
PRC - C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS (New Boundary Technologies, Inc.)
PRC - C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe (Adobe Systems Incorporated)
PRC - C:\WINDOWS\SOUNDMAN.EXE (Realtek Semiconductor Corp.)
PRC - C:\Program Files\Digital Media Reader\shwiconEM.exe (Alcor Micro, Corp.)
PRC - C:\WINDOWS\zHotkey.exe ()
PRC - C:\Program Files\Common Files\AOL\ACS\AOLacsd.exe (America Online, Inc.)
PRC - C:\Program Files\Common Files\AOL\AOL Spyware Protection\AOLSP Scheduler.exe ()
PRC - C:\Program Files\Hewlett-Packard\AiO\Shared\Bin\hpofxm07.exe (Hewlett-Packard Co.)
PRC - C:\WINDOWS\system32\hpoipm07.exe (HP)
PRC - C:\Program Files\Hewlett-Packard\AiO\Shared\Bin\hposts07.exe (Hewlett-Packard Co.)
PRC - C:\Program Files\Hewlett-Packard\AiO\Shared\Bin\hpoevm07.exe (Hewlett-Packard Co.)
PRC - C:\Program Files\Hewlett-Packard\AiO\hp officejet g series\Bin\hpoavn07.exe (Hewlett-Packard Co.)
PRC - C:\Program Files\Iomega\AutoDisk\ADService.exe (Iomega Corporation)
PRC - C:\Program Files\Iomega\AutoDisk\ADUserMon.exe (Iomega Corporation)
PRC - C:\Program Files\Iomega\System32\AppServices.exe (Iomega Corporation)
PRC - C:\Program Files\Iomega\DriveIcons\Imgicon.exe (Iomega)


========== Modules (SafeList) ==========

MOD - C:\Documents and Settings\Owner\Desktop\OTL.exe (OldTimer Tools)
MOD - C:\Program Files\Zone Labs\ZoneAlarm\MailFrontier\MlfHook.dll ()
MOD - C:\Program Files\Iomega\DriveIcons\Imghook.dll (Iomega Corporation)


========== Win32 Services (SafeList) ==========

SRV - (Iomega Activity Disk2) – File not found
SRV - (getPlusHelper) getPlus® – C:\Program Files\NOS\bin\getPlus_Helper.dll (NOS Microsystems Ltd.)
SRV - (vsmon) – C:\WINDOWS\System32\ZoneLabs\vsmon.exe (Check Point Software Technologies LTD)
SRV - (LVPrcSrv) – C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe (Logitech Inc.)
SRV - (WLSetupSvc) – C:\Program Files\Windows Live\installer\WLSetupSvc.exe (Microsoft Corporation)
SRV - (usnjsvc) – C:\Program Files\Windows Live\Messenger\usnsvc.exe (Microsoft Corporation)
SRV - (WinDefend) – C:\Program Files\Windows Defender\MsMpEng.exe (Microsoft Corporation)
SRV - (PrismXL) – C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS (New Boundary Technologies, Inc.)
SRV - (AOL ACS) – C:\Program Files\Common Files\AOL\ACS\AOLacsd.exe (America Online, Inc.)
SRV - (_IOMEGA_ACTIVE_DISK_SERVICE_) – C:\Program Files\Iomega\AutoDisk\ADService.exe (Iomega Corporation)
SRV - (Iomega App Services) – C:\Program Files\Iomega\System32\AppServices.exe (Iomega Corporation)


========== Driver Services (SafeList) ==========

DRV - (vsdatant) – C:\WINDOWS\system32\vsdatant.sys (Check Point Software Technologies LTD)
DRV - (KLIF) – C:\WINDOWS\system32\drivers\klif.sys (Kaspersky Lab)
DRV - (LVUSBSta) – C:\WINDOWS\system32\drivers\LVUSBSta.sys (Logitech Inc.)
DRV - (LVRS) – C:\WINDOWS\system32\drivers\lvrs.sys (Logitech Inc.)
DRV - (PID_PEPI) Logitech QuickCam IM(PID_PEPI) – C:\WINDOWS\system32\drivers\LV302V32.SYS (Logitech Inc.)
DRV - (pepifilter) – C:\WINDOWS\system32\drivers\lv302af.sys (Logitech Inc.)
DRV - (LVPr2Mon) – C:\WINDOWS\system32\drivers\LVPr2Mon.sys ()
DRV - (srescan) – C:\WINDOWS\system32\ZoneLabs\srescan.sys (Check Point Software Technologies LTD)
DRV - (usbaudio) USB Audio Driver (WDM) – C:\WINDOWS\system32\drivers\USBAUDIO.sys (Microsoft Corporation)
DRV - (ppa3) – C:\WINDOWS\system32\DRIVERS\ppa3.sys (Microsoft Corporation)
DRV - (amdagp) – C:\WINDOWS\system32\DRIVERS\amdagp.sys (Advanced Micro Devices, Inc.)
DRV - (sisagp) – C:\WINDOWS\system32\DRIVERS\sisagp.sys (Silicon Integrated Systems Corporation)
DRV - (ati2mtag) – C:\WINDOWS\system32\drivers\ati2mtag.sys (ATI Technologies Inc.)
DRV - (ASCTRM) – C:\WINDOWS\system32\drivers\asctrm.sys (Windows ® 2000 DDK provider)
DRV - (ALCXWDM) Service for Realtek AC97 Audio (WDM) – C:\WINDOWS\system32\drivers\ALCXWDM.SYS (Realtek Semiconductor Corp.)
DRV - (SunkFilt) – C:\WINDOWS\system32\drivers\Sunkfilt.sys (Alcor Micro Corp.)
DRV - (Cdralw2k) – C:\WINDOWS\system32\drivers\cdralw2k.sys (Roxio)
DRV - (Cdr4_xp) – C:\WINDOWS\system32\drivers\cdr4_xp.sys (Roxio)
DRV - (nv) – C:\WINDOWS\system32\drivers\nv4_mini.sys (NVIDIA Corporation)
DRV - (HSFHWBS2) – C:\WINDOWS\system32\drivers\HSFHWBS2.sys (Conexant Systems, Inc.)
DRV - (winachsf) – C:\WINDOWS\system32\drivers\HSF_CNXT.sys (Conexant Systems, Inc.)
DRV - (HSF_DP) – C:\WINDOWS\system32\drivers\HSF_DP.sys (Conexant Systems, Inc.)
DRV - (RTL8023xp) – C:\WINDOWS\system32\drivers\Rtlnicxp.sys (Realtek Semiconductor Corporation )
DRV - (wanatw) WAN Miniport (ATW) – C:\WINDOWS\system32\drivers\wanatw4.sys (America Online, Inc.)
DRV - (iomdisk) – C:\WINDOWS\System32\DRIVERS\iomdisk.sys (Iomega Corporation)
DRV - (IPFilter) – C:\WINDOWS\system32\drivers\ipfilter.sys (Microsoft Corporation)
DRV - (Sparrow) – C:\WINDOWS\system32\DRIVERS\sparrow.sys (Adaptec, Inc.)
DRV - (sym_u3) – C:\WINDOWS\system32\DRIVERS\sym_u3.sys (LSI Logic)
DRV - (sym_hi) – C:\WINDOWS\system32\DRIVERS\sym_hi.sys (LSI Logic)
DRV - (symc8xx) – C:\WINDOWS\system32\DRIVERS\symc8xx.sys (LSI Logic)
DRV - (symc810) – C:\WINDOWS\system32\DRIVERS\symc810.sys (Symbios Logic Inc.)
DRV - (ultra) – C:\WINDOWS\system32\DRIVERS\ultra.sys (Promise Technology, Inc.)
DRV - (ql12160) – C:\WINDOWS\system32\DRIVERS\ql12160.sys (QLogic Corporation)
DRV - (ql1080) – C:\WINDOWS\system32\DRIVERS\ql1080.sys (QLogic Corporation)
DRV - (ql1280) – C:\WINDOWS\system32\DRIVERS\ql1280.sys (QLogic Corporation)
DRV - (dac2w2k) – C:\WINDOWS\system32\DRIVERS\dac2w2k.sys (Mylex Corporation)
DRV - (mraid35x) – C:\WINDOWS\system32\DRIVERS\mraid35x.sys (American Megatrends Inc.)
DRV - (asc) – C:\WINDOWS\system32\DRIVERS\asc.sys (Advanced System Products, Inc.)
DRV - (asc3550) – C:\WINDOWS\system32\DRIVERS\asc3550.sys (Advanced System Products, Inc.)
DRV - (AliIde) – C:\WINDOWS\system32\DRIVERS\aliide.sys (Acer Laboratories Inc.)
DRV - (CmdIde) – C:\WINDOWS\system32\DRIVERS\cmdide.sys (CMD Technology, Inc.)
DRV - (mxnic) – C:\WINDOWS\system32\drivers\mxnic.sys (Macronix International Co., Ltd. )


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultName = Google
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultURL = http://www.google.com/search?q={searchTerm…tf8&oe=utf8
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = about:blank
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = 127.0.0.1

========== FireFox ==========

FF - prefs.js..extensions.enabledItems: [removed]:1.0

FF - HKLM\software\mozilla\Mozilla Firefox 3.6\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010/01/28 10:00:59 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010/03/10 08:19:03 | 000,000,000 | —D | M]

[2010/01/28 10:01:12 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Mozilla\Extensions
[2010/03/24 07:10:21 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\0vop8812.default\extensions
[2010/03/06 08:47:37 | 000,000,000 | —D | M] (Microsoft .NET Framework Assistant) – C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\0vop8812.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2010/03/24 07:10:21 | 000,000,000 | —D | M] – C:\Program Files\Mozilla Firefox\extensions

O1 HOSTS File: ([2010/03/15 21:05:38 | 000,000,027 | —- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll File not found
O2 - BHO: (Skype add-on (mastermind)) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Skype Technologies S.A.)
O2 - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.5.4723.1820\swg.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O3 - HKCU\..\Toolbar\ShellBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O4 - HKLM..\Run: [Adobe Photo Downloader] C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [ADUserMon] C:\Program Files\Iomega\AutoDisk\ADUserMon.exe (Iomega Corporation)
O4 - HKLM..\Run: [AOL Spyware Protection] C:\Program Files\Common Files\AOL\AOL Spyware Protection\AOLSP Scheduler.exe ()
O4 - HKLM..\Run: [CHotkey] C:\WINDOWS\zHotkey.exe ()
O4 - HKLM..\Run: [Deskup] C:\Program Files\Iomega\DriveIcons\deskup.exe (Iomega)
O4 - HKLM..\Run: [Iomega Drive Icons] C:\Program Files\Iomega\DriveIcons\Imgicon.exe (Iomega)
O4 - HKLM..\Run: [LogitechQuickCamRibbon] C:\Program Files\Logitech\QuickCam\Quickcam.exe ()
O4 - HKLM..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe (Ahead Software Gmbh)
O4 - HKLM..\Run: [Recguard] C:\WINDOWS\SMINST\Recguard.exe ()
O4 - HKLM..\Run: [ShowWnd] C:\WINDOWS\ShowWnd.exe ()
O4 - HKLM..\Run: [SoundMan] C:\WINDOWS\SOUNDMAN.EXE (Realtek Semiconductor Corp.)
O4 - HKLM..\Run: [SunKistEM] C:\Program Files\Digital Media Reader\shwiconEM.exe (Alcor Micro, Corp.)
O4 - HKLM..\Run: [Windows Defender] C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
O4 - HKLM..\Run: [ZoneAlarm Client] C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe (Check Point Software Technologies LTD)
O4 - HKCU..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe (Adobe Systems Incorporated)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\HPAiODevice(hp officejet g series) - 1.lnk = C:\Program Files\Hewlett-Packard\AiO\hp officejet g series\Bin\hpoavn07.exe (Hewlett-Packard Co.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe (Logitech Inc.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Quicken Scheduled Updates.lnk = C:\Program Files\Quicken\bagent.exe (Intuit Inc.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: InstallVisualStyle = C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles (Microsoft)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: InstallTheme = C:\WINDOWS\Resources\Themes\Royale.theme ()
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O8 - Extra context menu item: Google Sidewiki… - C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_96D6FF0C6D236BF8.dll (Google Inc.)
O9 - Extra Button: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - Reg Error: Key error. File not found
O9 - Extra 'Tools' menuitem : AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - Reg Error: Value error. File not found
O9 - Extra 'Tools' menuitem : Skype add-on for Internet Explorer - {5067A26B-1337-4436-8AFE-EE169C2DA79F} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Skype Technologies S.A.)
O9 - Extra Button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - Reg Error: Key error. File not found
O12 - Plugin for: .wav - C:\Program Files\Internet Explorer\PLUGINS\npqtplugin2.dll (Apple Computer, Inc.)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://go.microsoft.com/fwlink/?linkid=39204 (Windows Genuine Advantage Validation Tool)
O16 - DPF: {3E68E405-C6DE-49FF-83AE-41EE9F4C36CE} http://office.microsoft.com/officeupdate/content/opuc3.cab (Office Update Installation Engine)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} http://update.microsoft.com/microsoftupdat…b?1130977407812 (MUWebControl Class)
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} http://download.eset.com/special/eos/OnlineScanner.cab (OnlineScanner Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_18)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get/flash…r/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {A90A5822-F108-45AD-8482-9BC8B12DD539} http://www.crucial.com/controls/cpcScanner.cab (Crucial cpcScan)
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} http://messenger.msn.com/download/MsnMesse…pDownloader.cab (MsnMessengerSetupDownloadControl Class)
O16 - DPF: {CAFEEFAC-0016-0000-0018-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_18)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_18)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/flas…ent/swflash.cab (Shockwave Flash Object)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (get_atlcom Class)
O16 - DPF: {EF6E7E56-9229-4C73-AAD0-15316405DB95} http://lmitchell619.photosite.com/~site/Up…oadBox_live.cab (Easy Photo Uploader)
O16 - DPF: {F58E1CEF-A068-4C15-BA5E-587CAF3EE8C6} http://chat.msn.com/controls/msnchat45.cab (MSN Chat Control 4.5)
O16 - DPF: Microsoft XML Parser for Java file://C:\WINDOWS\Java\classes\xmldso.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = [removed]
O18 - Protocol\Handler\bwfile-8876480 {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll (Logitech Inc.)
O18 - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\Windows Live\Messenger\msgrapp.8.5.1302.1018.dll (Microsoft Corporation)
O18 - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\Windows Live\Messenger\msgrapp.8.5.1302.1018.dll (Microsoft Corporation)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\AtiExtEvent: DllName - Ati2evxx.dll - C:\WINDOWS\System32\ati2evxx.dll (ATI Technologies Inc.)
O24 - Desktop WallPaper: C:\Documents and Settings\Owner\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Owner\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O28 - HKLM ShellExecuteHooks: {091EB208-39DD-417D-A5DD-7E2C2D8FB9CB} - C:\Program Files\Windows Defender\MpShHook.dll (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2005/04/13 13:20:25 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*

========== Files/Folders - Created Within 30 Days ==========

[2010/03/23 19:59:11 | 000,198,268 | —- | C] (Malwarebytes) – C:\Documents and Settings\Owner\Desktop\StartUpLite.exe
[2010/03/21 11:04:06 | 000,000,000 | RH-D | C] – C:\Documents and Settings\Owner\Recent
[2010/03/21 11:04:06 | 000,000,000 | -HSD | C] – C:\RECYCLER
[2010/03/10 18:30:54 | 000,000,000 | —D | C] – C:\_OTL
[2010/03/10 09:15:57 | 003,558,912 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\moviemk.exe
[2010/03/10 08:19:31 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Sun
[2010/03/10 08:19:30 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Java
[2010/03/10 08:19:03 | 000,073,728 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javacpl.cpl
[2010/03/10 08:19:01 | 000,153,376 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javaws.exe
[2010/03/10 08:19:01 | 000,145,184 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javaw.exe
[2010/03/10 08:19:01 | 000,145,184 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\java.exe
[2010/03/10 08:18:25 | 000,000,000 | —D | C] – C:\Program Files\Java
[2010/03/10 08:02:20 | 016,492,320 | —- | C] (Sun Microsystems, Inc.) – C:\Documents and Settings\Owner\Desktop\jre-6u18-windows-i586-s.exe
[2010/03/09 00:04:09 | 000,554,496 | —- | C] (OldTimer Tools) – C:\Documents and Settings\Owner\Desktop\OTL.exe
[2010/03/08 20:33:36 | 000,000,000 | —D | C] – C:\Program Files\ESET
[2010/03/07 22:20:14 | 000,000,000 | RHSD | C] – C:\cmdcons
[2010/03/07 22:17:28 | 000,212,480 | —- | C] (SteelWerX) – C:\WINDOWS\SWXCACLS.exe
[2010/03/07 22:17:28 | 000,161,792 | —- | C] (SteelWerX) – C:\WINDOWS\SWREG.exe
[2010/03/07 22:17:28 | 000,136,704 | —- | C] (SteelWerX) – C:\WINDOWS\SWSC.exe
[2010/03/07 22:17:28 | 000,031,232 | —- | C] (NirSoft) – C:\WINDOWS\NIRCMD.exe
[2010/03/07 22:16:33 | 000,000,000 | —D | C] – C:\Qoobox
[2010/03/06 22:12:53 | 000,000,000 | —D | C] – C:\Documents and Settings\Owner\Desktop\New Folder
[2010/03/05 11:43:29 | 000,000,000 | —D | C] – C:\WINDOWS\System32\XPSViewer
[2010/03/05 11:43:20 | 000,000,000 | —D | C] – C:\Program Files\MSBuild
[2010/03/05 11:43:06 | 000,000,000 | —D | C] – C:\Program Files\Reference Assemblies
[2010/03/05 11:42:26 | 000,597,504 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\printfilterpipelinesvc.exe
[2010/03/05 11:42:26 | 000,575,488 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\xpsshhdr.dll
[2010/03/05 11:42:26 | 000,117,760 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\prntvpt.dll
[2010/03/05 11:42:26 | 000,089,088 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\filterpipelineprintproc.dll
[2010/03/05 11:42:25 | 001,676,288 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\xpssvcs.dll
[2010/03/05 11:42:25 | 001,676,288 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\xpssvcs.dll
[2010/03/05 11:42:23 | 000,000,000 | —D | C] – C:\54e28b4d65b8699388263bd778
[2010/03/04 08:57:07 | 000,000,000 | —D | C] – C:\WINDOWS\ERDNT
[2010/03/04 08:56:05 | 000,000,000 | —D | C] – C:\Program Files\ERUNT
[2010/03/04 08:53:46 | 000,791,393 | —- | C] (Lars Hederer ) – C:\Documents and Settings\Owner\Desktop\erunt_setup.exe
[2010/03/04 08:37:45 | 000,021,504 | —- | C] (Doug Knox) – C:\Documents and Settings\Owner\Desktop\SysRestorePoint.exe
[2010/03/04 08:32:11 | 000,050,688 | —- | C] (Atribune.org) – C:\Documents and Settings\Owner\Desktop\ATF_Cleaner.exe
[2010/03/01 23:43:55 | 000,000,000 | —D | C] – C:\Documents and Settings\Owner\My Documents\Downloads
[2010/02/25 08:14:00 | 000,000,000 | —D | C] – C:\Documents and Settings\Owner\Local Settings\Application Data\Temp
[2010/01/30 21:16:01 | 000,000,000 | —D | M] – C:\Documents and Settings\NetworkService\Local Settings\Application Data\Google
[2010/01/30 14:09:09 | 000,000,000 | —D | M] – C:\Documents and Settings\LocalService\Local Settings\Application Data\Google
[2009/04/26 16:36:54 | 000,000,000 | —D | M] – C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft
[2006/01/10 11:22:11 | 000,000,000 | —D | M] – C:\Documents and Settings\LocalService\Application Data\Symantec
[2005/04/13 13:26:13 | 000,000,000 | –SD | M] – C:\Documents and Settings\LocalService\Application Data\Microsoft
[2005/04/13 13:26:12 | 000,000,000 | –SD | M] – C:\Documents and Settings\NetworkService\Application Data\Microsoft
[2005/04/13 13:26:11 | 000,000,000 | —D | M] – C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft

========== Files - Modified Within 30 Days ==========

[2010/03/24 13:27:41 | 946,600,736 | -HS- | M] () – C:\WINDOWS\System32\drivers\fidbox.dat
[2010/03/24 13:24:00 | 000,000,886 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2010/03/24 12:50:48 | 000,002,698 | —- | M] () – C:\rollback.ini
[2010/03/24 12:44:26 | 000,001,170 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2010/03/24 12:44:21 | 000,000,882 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2010/03/24 12:43:53 | 000,415,153 | —- | M] () – C:\WINDOWS\System32\vsconfig.xml
[2010/03/24 12:43:39 | 000,000,006 | -H– | M] () – C:\WINDOWS\tasks\SA.DAT
[2010/03/24 12:43:30 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2010/03/24 12:43:26 | 938,004,480 | -HS- | M] () – C:\hiberfil.sys
[2010/03/24 09:28:06 | 012,667,124 | -HS- | M] () – C:\WINDOWS\System32\drivers\fidbox.idx
[2010/03/24 09:27:34 | 012,582,912 | -H– | M] () – C:\Documents and Settings\Owner\NTUSER.DAT
[2010/03/24 09:27:34 | 000,000,278 | -HS- | M] () – C:\Documents and Settings\Owner\ntuser.ini
[2010/03/24 08:03:04 | 000,001,661 | —- | M] () – C:\Documents and Settings\Owner\Desktop\Trillian.lnk
[2010/03/23 19:59:11 | 000,198,268 | —- | M] (Malwarebytes) – C:\Documents and Settings\Owner\Desktop\StartUpLite.exe
[2010/03/23 16:13:02 | 000,000,244 | -H– | M] () – C:\sqmnoopt14.sqm
[2010/03/23 16:13:02 | 000,000,232 | -H– | M] () – C:\sqmdata14.sqm
[2010/03/20 10:11:08 | 000,054,156 | -H– | M] () – C:\WINDOWS\QTFont.qfn
[2010/03/18 15:21:21 | 000,000,244 | -H– | M] () – C:\sqmnoopt13.sqm
[2010/03/18 15:21:21 | 000,000,232 | -H– | M] () – C:\sqmdata13.sqm
[2010/03/16 15:41:27 | 000,000,232 | -H– | M] () – C:\sqmdata12.sqm
[2010/03/16 15:41:26 | 000,000,244 | -H– | M] () – C:\sqmnoopt12.sqm
[2010/03/15 21:06:14 | 000,000,227 | —- | M] () – C:\WINDOWS\system.ini
[2010/03/15 21:05:38 | 000,000,027 | —- | M] () – C:\WINDOWS\System32\drivers\etc\hosts
[2010/03/15 20:45:00 | 003,891,061 | R— | M] () – C:\Documents and Settings\Owner\Desktop\schrauberB.exe
[2010/03/15 14:29:57 | 000,000,244 | -H– | M] () – C:\sqmnoopt11.sqm
[2010/03/15 14:29:57 | 000,000,232 | -H– | M] () – C:\sqmdata11.sqm
[2010/03/15 13:04:14 | 000,525,770 | —- | M] () – C:\WINDOWS\System32\PerfStringBackup.INI
[2010/03/15 13:04:14 | 000,444,358 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2010/03/15 13:04:14 | 000,072,108 | —- | M] () – C:\WINDOWS\System32\perfc009.dat
[2010/03/13 18:58:14 | 000,000,244 | -H– | M] () – C:\sqmnoopt10.sqm
[2010/03/13 18:58:14 | 000,000,232 | -H– | M] () – C:\sqmdata10.sqm
[2010/03/12 10:53:35 | 000,000,244 | -H– | M] () – C:\sqmnoopt09.sqm
[2010/03/12 10:53:35 | 000,000,232 | -H– | M] () – C:\sqmdata09.sqm
[2010/03/12 09:50:49 | 000,000,244 | -H– | M] () – C:\sqmnoopt08.sqm
[2010/03/12 09:50:49 | 000,000,232 | -H– | M] () – C:\sqmdata08.sqm
[2010/03/11 15:07:40 | 000,000,244 | -H– | M] () – C:\sqmnoopt07.sqm
[2010/03/11 15:07:40 | 000,000,232 | -H– | M] () – C:\sqmdata07.sqm
[2010/03/11 07:47:48 | 000,004,212 | -H– | M] () – C:\WINDOWS\System32\zllictbl.dat
[2010/03/10 20:31:09 | 000,000,244 | -H– | M] () – C:\sqmnoopt06.sqm
[2010/03/10 20:31:09 | 000,000,232 | -H– | M] () – C:\sqmdata06.sqm
[2010/03/10 09:22:07 | 000,000,759 | —- | M] () – C:\WINDOWS\win.ini
[2010/03/10 08:18:35 | 000,411,368 | —- | M] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\deploytk.dll
[2010/03/10 08:18:35 | 000,153,376 | —- | M] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javaws.exe
[2010/03/10 08:18:35 | 000,145,184 | —- | M] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javaw.exe
[2010/03/10 08:18:35 | 000,145,184 | —- | M] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\java.exe
[2010/03/10 08:18:35 | 000,073,728 | —- | M] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javacpl.cpl
[2010/03/10 08:02:36 | 016,492,320 | —- | M] (Sun Microsystems, Inc.) – C:\Documents and Settings\Owner\Desktop\jre-6u18-windows-i586-s.exe
[2010/03/09 00:04:11 | 000,554,496 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Owner\Desktop\OTL.exe
[2010/03/08 14:49:07 | 000,000,244 | -H– | M] () – C:\sqmnoopt05.sqm
[2010/03/08 14:49:07 | 000,000,232 | -H– | M] () – C:\sqmdata05.sqm
[2010/03/07 22:20:28 | 000,000,279 | RHS- | M] () – C:\boot.ini
[2010/03/07 12:43:24 | 000,000,232 | -H– | M] () – C:\sqmdata04.sqm
[2010/03/07 12:43:23 | 000,000,244 | -H– | M] () – C:\sqmnoopt04.sqm
[2010/03/06 22:30:06 | 000,000,244 | -H– | M] () – C:\sqmnoopt03.sqm
[2010/03/06 22:30:06 | 000,000,232 | -H– | M] () – C:\sqmdata03.sqm
[2010/03/05 12:16:16 | 000,059,168 | —- | M] () – C:\Documents and Settings\Owner\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
[2010/03/05 12:05:55 | 000,220,840 | —- | M] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2010/03/04 09:33:57 | 000,359,929 | —- | M] () – C:\Documents and Settings\Owner\Desktop\dds.scr
[2010/03/04 09:23:18 | 000,293,376 | —- | M] () – C:\Documents and Settings\Owner\Desktop\1cm4rzbq.exe
[2010/03/04 08:56:06 | 000,000,650 | —- | M] () – C:\Documents and Settings\Owner\Desktop\NTREGOPT.lnk
[2010/03/04 08:56:06 | 000,000,631 | —- | M] () – C:\Documents and Settings\Owner\Desktop\ERUNT.lnk
[2010/03/04 08:53:47 | 000,791,393 | —- | M] (Lars Hederer ) – C:\Documents and Settings\Owner\Desktop\erunt_setup.exe
[2010/03/04 08:37:46 | 000,021,504 | —- | M] (Doug Knox) – C:\Documents and Settings\Owner\Desktop\SysRestorePoint.exe
[2010/03/04 08:32:11 | 000,050,688 | —- | M] (Atribune.org) – C:\Documents and Settings\Owner\Desktop\ATF_Cleaner.exe
[2010/03/03 11:44:55 | 000,000,244 | -H– | M] () – C:\sqmnoopt02.sqm
[2010/03/03 11:44:55 | 000,000,232 | -H– | M] () – C:\sqmdata02.sqm
[2010/03/02 09:12:27 | 000,000,244 | -H– | M] () – C:\sqmnoopt01.sqm
[2010/03/02 09:12:27 | 000,000,232 | -H– | M] () – C:\sqmdata01.sqm
[2010/03/01 23:36:33 | 000,001,587 | —- | M] () – C:\Documents and Settings\Owner\Desktop\CCleaner.lnk

========== Files Created - No Company Name ==========

[2010/03/19 22:19:42 | 000,001,498 | —- | C] () – C:\Documents and Settings\Owner\Desktop\Calculator.lnk
[2010/03/15 20:44:57 | 003,891,061 | R— | C] () – C:\Documents and Settings\Owner\Desktop\schrauberB.exe
[2010/03/07 22:20:28 | 000,000,209 | —- | C] () – C:\Boot.bak
[2010/03/07 22:20:22 | 000,260,272 | —- | C] () – C:\cmldr
[2010/03/07 22:17:28 | 000,261,632 | —- | C] () – C:\WINDOWS\PEV.exe
[2010/03/07 22:17:28 | 000,098,816 | —- | C] () – C:\WINDOWS\sed.exe
[2010/03/07 22:17:28 | 000,080,412 | —- | C] () – C:\WINDOWS\grep.exe
[2010/03/07 22:17:28 | 000,077,312 | —- | C] () – C:\WINDOWS\MBR.exe
[2010/03/07 22:17:28 | 000,068,096 | —- | C] () – C:\WINDOWS\zip.exe
[2010/03/04 09:33:56 | 000,359,929 | —- | C] () – C:\Documents and Settings\Owner\Desktop\dds.scr
[2010/03/04 09:23:16 | 000,293,376 | —- | C] () – C:\Documents and Settings\Owner\Desktop\1cm4rzbq.exe
[2010/03/04 08:56:06 | 000,000,650 | —- | C] () – C:\Documents and Settings\Owner\Desktop\NTREGOPT.lnk
[2010/03/04 08:56:06 | 000,000,631 | —- | C] () – C:\Documents and Settings\Owner\Desktop\ERUNT.lnk
[2008/12/16 22:58:54 | 000,025,624 | —- | C] () – C:\WINDOWS\System32\drivers\LVPr2Mon.sys
[2008/12/16 22:50:56 | 000,013,584 | —- | C] () – C:\WINDOWS\System32\drivers\iKeyLgFT.dll
[2008/07/20 18:12:19 | 000,081,110 | —- | C] () – C:\WINDOWS\System32\lvcoinst.ini
[2007/01/20 09:49:13 | 000,796,312 | —- | C] () – C:\WINDOWS\System32\libeay32_0.9.6l.dll
[2006/09/16 10:02:56 | 000,000,116 | —- | C] () – C:\WINDOWS\Quicken.ini
[2006/09/16 10:02:56 | 000,000,052 | —- | C] () – C:\WINDOWS\intuprof.ini
[2006/09/16 09:52:19 | 000,000,016 | —- | C] () – C:\WINDOWS\WinInit.ini.backup
[2006/04/28 11:31:19 | 000,000,016 | —- | C] () – C:\WINDOWS\WinInit.ini
[2006/03/12 12:11:48 | 000,000,049 | —- | C] () – C:\WINDOWS\NeroDigital.ini
[2005/12/03 19:08:33 | 000,248,832 | —- | C] () – C:\WINDOWS\System32\ECircles.dll
[2005/12/03 19:08:33 | 000,153,088 | —- | C] () – C:\WINDOWS\System32\SoyWeb.dll
[2005/12/03 19:07:01 | 000,006,144 | —- | C] () – C:\WINDOWS\System32\ImgLibLead.dll
[2005/12/03 19:07:00 | 000,100,864 | —- | C] () – C:\WINDOWS\System32\Dc50ip32.dll
[2005/12/03 19:07:00 | 000,065,864 | —- | C] () – C:\WINDOWS\System32\Digita.sys
[2005/12/03 19:07:00 | 000,007,808 | —- | C] () – C:\WINDOWS\System32\dc240u.sys
[2005/12/03 19:06:46 | 000,210,944 | —- | C] () – C:\WINDOWS\System32\MSVCRT10.DLL
[2005/10/24 21:35:33 | 000,002,833 | —- | C] () – C:\WINDOWS\DevMgr.ini
[2005/10/24 21:32:45 | 000,000,020 | —- | C] () – C:\WINDOWS\Hposcv07.INI
[2005/10/24 21:32:09 | 000,003,399 | —- | C] () – C:\WINDOWS\System32\hptcpmon.ini
[2005/10/24 21:32:09 | 000,000,143 | —- | C] () – C:\WINDOWS\System32\AddPort.ini
[2005/10/24 20:43:35 | 000,005,632 | —- | C] () – C:\Documents and Settings\Owner\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2005/08/03 11:42:47 | 000,156,672 | —- | C] () – C:\WINDOWS\System32\RTLCPAPI.dll
[2005/08/03 11:38:19 | 000,000,376 | —- | C] () – C:\WINDOWS\ODBC.INI
[2005/08/03 11:19:23 | 000,532,544 | —- | C] () – C:\WINDOWS\PIC.dll
[2005/08/03 11:19:23 | 000,024,576 | —- | C] () – C:\WINDOWS\HKNTDLL.dll
[2005/04/13 15:02:03 | 000,000,061 | —- | C] () – C:\WINDOWS\smscfg.ini
[2005/04/13 12:57:05 | 000,001,446 | —- | C] () – C:\WINDOWS\System32\oeminfo.ini
[2005/04/13 12:57:05 | 000,000,498 | —- | C] () – C:\WINDOWS\System32\emver.ini
[2003/01/07 18:05:08 | 000,002,695 | —- | C] () – C:\WINDOWS\System32\OUTLPERF.INI
[2002/11/20 18:51:34 | 000,159,744 | —- | C] () – C:\WINDOWS\System32\win2000.dll
[2002/04/11 14:47:52 | 000,049,152 | —- | C] () – C:\WINDOWS\System32\msmscoin.dll

========== Alternate Data Streams ==========

@Alternate Data Stream - 125 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:5C321E34
< End of report >


OTL Extras logfile created on: 3/24/2010 1:27:38 PM - Run 4
OTL by OldTimer - Version 3.1.35.0 Folder = C:\Documents and Settings\Owner\Desktop
Windows XP Media Center Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.11)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

894.00 Mb Total Physical Memory | 390.00 Mb Available Physical Memory | 44.00% Memory free
2.00 Gb Paging File | 2.00 Gb Available in Paging File | 75.00% Paging File free
Paging file location(s): C:\pagefile.sys 1344 2688 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 182.10 Gb Total Space | 161.88 Gb Free Space | 88.90% Space Free | Partition Type: NTFS
Drive D: | 4.20 Gb Total Space | 0.99 Gb Free Space | 23.64% Space Free | Partition Type: FAT32
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: LINDAOFFICE
Current User Name: Owner
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
exefile [open] – "%1" %*
htmlfile – "C:\Program Files\Microsoft Office\OFFICE11\msohtmed.exe" %1 (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 1
"FirewallOverride" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]
"DisableMonitoring" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
"139:TCP" = 139:TCP:*:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:*:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:*:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:*:Enabled:@xpsp2res.dll,-22002

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008
"139:TCP" = 139:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22002

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
"C:\Program Files\Common Files\AOL\ACS\AOLacsd.exe" = C:\Program Files\Common Files\AOL\ACS\AOLacsd.exe:*:Enabled:AOL – (America Online, Inc.)
"C:\Program Files\Common Files\AOL\ACS\AOLDial.exe" = C:\Program Files\Common Files\AOL\ACS\AOLDial.exe:*:Enabled:AOL – (America Online, Inc)
"C:\Program Files\America Online 9.0\waol.exe" = C:\Program Files\America Online 9.0\waol.exe:*:Enabled:AOL – (America Online, Inc.)
"C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe" = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe:*:Enabled:Logitech Desktop Messenger – (Logitech Inc.)
"C:\Program Files\Windows Live\Messenger\livecall.exe" = C:\Program Files\Windows Live\Messenger\livecall.exe:*:Enabled:Windows Live Messenger (Phone) – (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files\Common Files\AOL\ACS\AOLacsd.exe" = C:\Program Files\Common Files\AOL\ACS\AOLacsd.exe:*:Enabled:AOL – (America Online, Inc.)
"C:\Program Files\Common Files\AOL\ACS\AOLDial.exe" = C:\Program Files\Common Files\AOL\ACS\AOLDial.exe:*:Enabled:AOL – (America Online, Inc)
"C:\Program Files\America Online 9.0\waol.exe" = C:\Program Files\America Online 9.0\waol.exe:*:Enabled:AOL – (America Online, Inc.)
"C:\Program Files\Hewlett-Packard\AiO\hp officejet g series\Bin\hpoavn07.exe" = C:\Program Files\Hewlett-Packard\AiO\hp officejet g series\Bin\hpoavn07.exe:*:Enabled:HP OfficeJet COM Device Objects – (Hewlett-Packard Co.)
"C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe" = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe:*:Enabled:Logitech Desktop Messenger – (Logitech Inc.)
"C:\Program Files\Windows Live\Messenger\livecall.exe" = C:\Program Files\Windows Live\Messenger\livecall.exe:*:Enabled:Windows Live Messenger (Phone) – (Microsoft Corporation)


========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{02E89EFC-7B07-4D5A-AA03-9EC0902914EE}" = VC 9.0 Runtime
"{0BEDBD4E-2D34-47B5-9973-57E62B29307C}" = ATI Control Panel
"{15377C3E-9655-400F-B441-E69F0A6BEAFE}" = Recovery Software Suite eMachines
"{18455581-E099-4BA8-BC6B-F34B2F06600C}" = Google Toolbar for Internet Explorer
"{1FD0C5C1-B01B-4B4C-9607-E5D3B3D1318F}" = Microsoft IntelliPoint 4.1
"{2318C2B1-4965-11d4-9B18-009027A5CD4F}" = Google Toolbar for Internet Explorer
"{26A24AE4-039D-4CA4-87B4-2F83216018FF}" = Java™ 6 Update 18
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{3F262ADC-5AD2-48E5-A586-44315E04A9E2}" = Microsoft Picture It! Library 10
"{416D80BA-6F6D-4672-B7CF-F54DA2F80B44}" = Microsoft Works
"{42756145-9997-4D28-809B-8756BFD00106}" = Microsoft Picture It! Premium 10
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{4BDFD2CE-6329-42E4-9801-9B3D1F10D79B}" = Adobe® Photoshop® Album Starter Edition 3.0
"{508CE775-4BA4-4748-82DF-FE28DA9F03B0}" = Windows Live Messenger
"{541DEAC0-5F3D-45E6-B7CB-94ECF3B96748}" = Skype web features
"{63569CE9-FA00-469C-AF5C-E5D4D93ACF91}" = Windows Genuine Advantage v1.3.0254.0
"{6811CAA0-BF12-11D4-9EA1-0050BAE317E1}" = PowerDVD
"{81EED1A1-AE78-4B11-BE47-C6AE9F5E87F1}" = Digital Media Reader
"{8DCE550C-CA43-4E82-92DF-FFC4A48F5BE1}" = Napster Burn Engine
"{900B1197-53F5-4F46-A882-2CFFFE2EEDCB}" = Logitech Desktop Messenger
"{91120409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office Standard Edition 2003
"{937B232D-9776-471E-92BD-D424E514EF14}" = Logitech QuickCam
"{9422C8EA-B0C6-4197-B8FC-DC797658CA00}" = Windows Live Sign-in Assistant
"{9941F0AA-B903-4AF4-A055-83A9815CC011}" = Sonic Encoders
"{9F7FC79B-3059-4264-9450-39EB368E3225}" = Microsoft Digital Image Library 9 - Blocker
"{A040AC77-C1AA-4CC9-8931-9F648AF178F6}" = VC 9.0 Runtime
"{A06275F4-324B-4E85-95E6-87B2CD729401}" = Windows Defender
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{A50885B4-2D9B-4DC7-961D-2661B3A037F0}" = Quicken 2006
"{A5CC2A09-E9D3-49EC-923D-03874BBD4C2C}" = Windows Defender Signatures
"{A7E4ECCA-4A8E-4258-8EC8-2DCCF5B11320}" = Windows Live installer
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{AC76BA86-7AD7-1033-7B44-A71000000002}" = Adobe Reader 7.1.0
"{BBBCAE4B-B416-4182-A6F2-438180894A81}" = Napster
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{D103C4BA-F905-437A-8049-DB24763BBE36}" = Skype™ 4.1
"{E2883E8F-472F-4fb0-9522-AC9BF37916A7}" = Adobe Download Manager
"{FB08F381-6533-4108-B7DD-039E11FBC27E}" = Realtek AC'97 Audio
"{FF262740-C85A-11D5-BBEC-00D0B740900A}" = Multimedia Keyboard Driver
"Active Disk" = Active Disk
"Adobe ActiveShare" = Adobe ActiveShare 1.2
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Adobe PhotoDeluxe Home Edition 4.0" = Adobe PhotoDeluxe Home Edition 4.0
"All ATI Software" = ATI - Software Uninstall Utility
"America Online us" = America Online (Choose which version to remove)
"AOL Connectivity Services" = AOL Connectivity Services
"AOL Spyware Protection" = AOL Spyware Protection
"AOL Toolbar" = AOL Toolbar
"AOL YGP Screensaver" = AOL You've Got Pictures Screensaver
"AOLCoach" = AOL Coach Version 1.0(Build:20040229.1 en)
"ATI Display Driver" = ATI Display Driver
"CCleaner" = CCleaner
"CNXT_MODEM_PCI_VEN_14F1&DEV_2F20&SUBSYS_200014F1" = SoftV92 Data Fax Modem with SmartCP
"ERUNT_is1" = ERUNT 1.1j
"ESET Online Scanner" = ESET Online Scanner v3
"hp instant support" = hp instant support
"hp officejet g series 1209210039" = hp officejet g series
"IDNMitigationAPIs" = Microsoft Internationalized Domain Names Mitigation APIs
"ie7" = Windows Internet Explorer 7
"InstallShield_{81EED1A1-AE78-4B11-BE47-C6AE9F5E87F1}" = Digital Media Reader
"IomegaWare" = IomegaWare 4.0.2
"Kazoo Player" = Kazoo Player
"legacyqcam_11.10" = Logitech Legacy USB Camera Driver Package
"lvdrivers_11.90" = Logitech QuickCam Driver Package
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Money2005b" = Microsoft Money 2005
"Mozilla Firefox (3.6)" = Mozilla Firefox (3.6)
"Nero - Burning Rom!UninstallKey" = Nero OEM
"Nero BurnRights!UninstallKey" = Nero BurnRights
"NLSDownlevelMapping" = Microsoft National Language Support Downlevel APIs
"OLYMPUS CAMEDIA Master 2.0" = OLYMPUS CAMEDIA Master 2.01
"PictureItPrem_v10" = Microsoft Picture It! Premium 10
"Port Magic" = Pure Networks Port Magic
"QuickTime" = QuickTime
"RealPlayer 6.0" = RealPlayer Basic
"StreetPlugin" = Learn2 Player (Uninstall Only)
"Trillian" = Trillian
"Windows XP Service Pack" = Windows XP Service Pack 3
"ZoneAlarm Security Suite" = ZoneAlarm Security Suite

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 11/12/2009 9:10:49 PM | Computer Name = LINDAOFFICE | Source = Application Error | ID = 1000
Description = Faulting application iexplore.exe, version 7.0.6000.16915, faulting
module googletoolbardynamic_32_d5b8545f3cfb02d4.dll, version 6.2.1910.1554, fault
address 0x00104532.

Error - 11/12/2009 9:11:01 PM | Computer Name = LINDAOFFICE | Source = Application Error | ID = 1001
Description = Fault bucket 1497770801.

Error - 12/18/2009 5:30:49 PM | Computer Name = LINDAOFFICE | Source = Application Error | ID = 1000
Description = Faulting application iexplore.exe, version 7.0.6000.16945, faulting
module unknown, version 0.0.0.0, fault address 0x60b47930.

Error - 12/18/2009 5:30:56 PM | Computer Name = LINDAOFFICE | Source = Application Error | ID = 1001
Description = Fault bucket 1595742545.

Error - 1/19/2010 11:09:40 PM | Computer Name = LINDAOFFICE | Source = Application Error | ID = 1000
Description = Faulting application trillian.exe, version 4.1.0.23, faulting module
talk.dll, version 4.1.0.23, fault address 0x000a828e.

Error - 1/21/2010 10:44:45 AM | Computer Name = LINDAOFFICE | Source = Application Error | ID = 1000
Description = Faulting application trillian.exe, version 4.1.0.23, faulting module
talk.dll, version 4.1.0.23, fault address 0x000a828e.

Error - 1/21/2010 10:45:03 AM | Computer Name = LINDAOFFICE | Source = Application Error | ID = 1001
Description = Fault bucket 1669173376.

Error - 3/5/2010 4:06:54 PM | Computer Name = LINDAOFFICE | Source = Application Error | ID = 1000
Description = Faulting application dds.scr, version 0.0.0.0, faulting module imghook.dll,
version 6.4.0.29, fault address 0x00012017.

Error - 3/5/2010 4:08:20 PM | Computer Name = LINDAOFFICE | Source = Application Error | ID = 1000
Description = Faulting application dds.scr, version 0.0.0.0, faulting module imghook.dll,
version 6.4.0.29, fault address 0x00012017.

Error - 3/19/2010 4:03:52 PM | Computer Name = LINDAOFFICE | Source = Application Hang | ID = 1002
Description = Hanging application calc.exe, version 5.1.2600.0, hang module hungapp,
version 0.0.0.0, hang address 0x00000000.

[ System Events ]
Error - 3/10/2010 6:32:26 PM | Computer Name = LINDAOFFICE | Source = Service Control Manager | ID = 7034
Description = The AOL Connectivity Service service terminated unexpectedly. It
has done this 1 time(s).

Error - 3/10/2010 6:32:26 PM | Computer Name = LINDAOFFICE | Source = Service Control Manager | ID = 7034
Description = The Iomega App Services service terminated unexpectedly. It has done
this 1 time(s).

Error - 3/10/2010 6:32:26 PM | Computer Name = LINDAOFFICE | Source = Service Control Manager | ID = 7034
Description = The Java Quick Starter service terminated unexpectedly. It has done
this 1 time(s).

Error - 3/10/2010 6:32:26 PM | Computer Name = LINDAOFFICE | Source = Service Control Manager | ID = 7034
Description = The Process Monitor service terminated unexpectedly. It has done
this 1 time(s).

Error - 3/10/2010 6:32:26 PM | Computer Name = LINDAOFFICE | Source = Service Control Manager | ID = 7034
Description = The PrismXL service terminated unexpectedly. It has done this 1 time(s).

Error - 3/10/2010 6:32:27 PM | Computer Name = LINDAOFFICE | Source = Service Control Manager | ID = 7034
Description = The Iomega Active Disk service terminated unexpectedly. It has done
this 1 time(s).

Error - 3/12/2010 8:47:10 PM | Computer Name = LINDAOFFICE | Source = Service Control Manager | ID = 7034
Description = The TrueVector Internet Monitor service terminated unexpectedly.
It has done this 1 time(s).

Error - 3/15/2010 8:52:35 PM | Computer Name = LINDAOFFICE | Source = Service Control Manager | ID = 7034
Description = The Process Monitor service terminated unexpectedly. It has done
this 1 time(s).

Error - 3/18/2010 8:32:51 AM | Computer Name = LINDAOFFICE | Source = Service Control Manager | ID = 7011
Description = Timeout (30000 milliseconds) waiting for a transaction response from
the stisvc service.

Error - 3/18/2010 8:34:57 AM | Computer Name = LINDAOFFICE | Source = Service Control Manager | ID = 7011
Description = Timeout (30000 milliseconds) waiting for a transaction response from
the stisvc service.


< End of report >


That's it!
It is running better now, Tom. When I dump ZoneAlarm this weekend, that should give it a further kick. Thanks so much for your help. Now, how much of this diagnostic stuff can I delete?
Good :)

Let's cleanup our work.


Step 1

We have to remove all tools that we have used to clean up your system.

Tool CleanUp


Delete ComboFix and Clean Up
Click Start > Run > type combofix /Uninstall > OK (Note the space between combofix and /Uninstall)
Please advise if this step is missed for any reason as it performs some important actions.



Restart OTL.
Doubleclick on the CleanUp Button on the Top.
Now most of our tools should been removed. If there are any tools or logs left over on your desktop please delete them and clean your recycler.


Step 2

Now it is a good time to clear your systemrestore- points because it is possible that some kind of malware backed up there.
If you restore your system back to an earlier point you could get reinfected.


Clear restore points
  • Right click on your desktop.
  • On the Desktop, right-click My Computer.
  • Click Properties.
  • Click the System Restore tab.
  • Check Turn off System Restore.
  • Click Apply, and then click OK.
Restart your computer.

Turn ON System Restore after reboot. ( Important )


Step 3

Updates for Windows

Its essential to keep your PC up to date.
Lets have a look if the Windows Updates download automatically. This is the best way to get all securtiy patches and security fixes.

Click start –> settings –> Control Panel
Select Automatic Updates and set them to automatic.

Now choose a day and a time when you know that your computer will be connected to the internet


Step 4

To protect you for further infections we will install different tools.

  • SpywareBlaster
    A tutorial for Spywareblaster can be found here. If you wish, the commercial version provides automatic updating.

  • MalwareBytes Anti Malware
    This is one of the most important Anti Malware Tools i know. It is an on- demand scan tool that detects and removes most of the known malware. Update the tool and let it run one time a week.
    A tutorial can be found here.

  • Temp File Cleaner
    A powerfull tool which cleans temporary files from IE and Windows, emptied the recycle bin and more. It really helps you to speed up your computer.
    You can download TFC ( by OldTimer ) here

  • MVPs hosts file
    A tutorial for MVPs hosts file can be found here. For more information about Hosts file you can consult the Tutorial for Hosts files.

  • Keep your Windows up to date
    Often there are holes found in the Internet Explorer or Windows itself. These ned to be patched because attackers can use this holes to access to your computer.
    Therefor visit the Microsoft Update Site.

  • Keep your Software up to date
    The easiest way to check your software is to use the Secunia Online Software.

Step 5

Tipps for safer surfing

These are my tipps to keep away from infections while surfing.
Use a different browser than Internet Explorer.
i recommend Mozilla Firefox

For this browser there a serveral Add Ons to help you for a safer surfing.
  • NoScript
    This Add On blocks JavaScript, Java and Flash and other plugins to be executed only by trusted web sites of your choice.
  • AdblockPlus
    This Add On blocks mostly of the advertisements automatically. Only a rightclick on the banner and ad them to AdblockPlus and the banner will never download again.
  • WOT (Web of trust)
    This one warns you before you interact with a risky site.

Don't
  • click all you are able to click.
  • use peer to peer or filesharing.
  • use cracks, keygens, serials or other illegal software.
  • open untrusted emails or attachments.



If you have any questions feel free to ask.
Best wishes! Posted Image
Okay, deleted all the schtuff, got thru the TFC part of Step 4. Dumped ZA and put on McAfee. The Hosts tutorial is not as clearly written as the other tuttorials, so I might have some questions. Will tackle that Monday evening. thanks, JoHawk

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI