This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Virus updates blocked

31 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hello,

I was running Mcafee and got an error that it was not up to date. I tried to download spybot and can not access the website or any other related websites.

I downloaded avira cd boot software and ran it by booting from cd first. It found 4 in my system volume information directory. I turned off restore points and then unlocked the directory and clean them out. Running it again system shows cleaned. still can not access virus/malware websites.

I have run spybot and it says all is ok

I have checked my host file and it only has the one entry for local host

Ihave run macaffe, avira and now AVG all say clean (I used one at a time, unistallaed before installing next one)

I have followed the instructions listed to do before posting.

malwarebytes says clean and when I try to run the update I get error code 732 (12029,0) log file below

when I run GMER I get the quick scan first and log file is listed below.

when i run the GMER scan with proper unclicked boxes it starts and list things but then crashes and I get blue screen "irql_not_less_or_equal"

I have a comand in my startup that has no name and it will not let me delete or dissable it.

Thanks for help

LOGS:

Malwarebytes' Anti-Malware 1.44
Database version: 3510
Windows 5.1.2600 Service Pack 3
Internet Explorer 8.0.6001.18702

3/7/2010 11:37:14 AM
mbam-log-2010-03-07 (11-37-14).txt

Scan type: Quick Scan
Objects scanned: 127442
Time elapsed: 5 minute(s), 15 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)

—————————————————-
GMER quick scan log

GMER 1.0.15.15281 - http://www.gmer.net
Rootkit quick scan 2010-03-07 12:06:12
Windows 5.1.2600 Service Pack 3
Running: 547bc5r1.exe; Driver: C:\DOCUME~1\LANCES~1\LOCALS~1\Temp\kfkciuod.sys


—- Devices - GMER 1.0.15 —-

AttachedDevice \Driver\Tcpip \Device\Ip avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
AttachedDevice \Driver\Tcpip \Device\Tcp tcpipBM.SYS (Bytemobile Kernel Network Provider/Bytemobile, Inc.)
AttachedDevice \Driver\Tcpip \Device\Tcp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
AttachedDevice \Driver\Tcpip \Device\Udp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
AttachedDevice \Driver\Tcpip \Device\Udp fssfltr_tdi.sys (Family Safety Filter Driver (TDI)/Microsoft Corporation)
AttachedDevice \Driver\Tcpip \Device\RawIp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
AttachedDevice \Driver\Tcpip \Device\RawIp fssfltr_tdi.sys (Family Safety Filter Driver (TDI)/Microsoft Corporation)
AttachedDevice \Driver\Kbdclass \Device\KeyboardClass0 wdf01000.sys (WDF Dynamic/Microsoft Corporation)
AttachedDevice \Driver\Kbdclass \Device\KeyboardClass1 wdf01000.sys (WDF Dynamic/Microsoft Corporation)

—- EOF - GMER 1.0.15 —-


GMER run in safe mode

GMER 1.0.15.15281 - http://www.gmer.net
Rootkit scan 2010-03-07 14:55:19
Windows 5.1.2600 Service Pack 3
Running: 547bc5r1.exe; Driver: C:\DOCUME~1\LANCES~1\LOCALS~1\Temp\kfkciuod.sys


—- Devices - GMER 1.0.15 —-

AttachedDevice \Driver\Kbdclass \Device\KeyboardClass0 wdf01000.sys (WDF Dynamic/Microsoft Corporation)
AttachedDevice \Driver\Kbdclass \Device\KeyboardClass1 wdf01000.sys (WDF Dynamic/Microsoft Corporation)

Device \FileSystem\Fastfat \Fat F6A0ED20

—- EOF - GMER 1.0.15 —-
Hello lancesandra,

Welcome to WTT!

My name is SweetTech. I would be glad to take a look at your log and help you with solving any malware problems. I'd be grateful if you would note the following:
  • Logs from malware removal programs (DDS is one of them) can take some time to analyze. I need you to be patient while I analyze any logs you post.
  • Please make sure to carefully read any instruction that I give you.
    Reading too lightly will cause you to miss important steps, which could have destructive effects.
  • If you're not sure, or if something unexpected happens, do NOT continue! Stop and ask!
  • These instructions have been specifically tailored to your computer and the issues you are experiencing with your computer. It's important to note that these instructions are not suitable for any other computer, even if the issues are fairly similar.
  • Do not do things I do not ask for, such as running a spyware scan on your computer. The one thing that you should always do, is to make sure sure that your anti-virus definitions are up-to-date!
  • If I instruct you to download a specific tool in which you already have, please delete the copy that you have and re-download the tool. The reason I ask you to do this is because these tools are updated fairly regularly.
  • Please do not use the Attachment feature for any log file. Do a Copy/Paste of the entire contents of the log file and submit it inside your post.
  • I am going to stick with you until ALL malware is gone from your system. I would appreciate it if you would do the same. From this point, we're in this together ;)
    Because of this, you must reply within three days
    . I will post a reminder should you seem to fail to do this, however, if you fail to reply within two days then,
    unless I have been notified of your absence in advance, the topic shall be closed!
  • Please do not PM me directly for help. If you have any questions, post them in this topic.
  • Lastly, I am no magician. I will try very hard to fix your issues, but no promises can be made. Also be aware that some infections are so severe that you might need to resort to reformatting and reinstalling your operating system.
    Don't worry, this only happens in severe cases, but it sadly does happen. Be prepared to back up your data. Have means of backing up your data available.
____________________________________________________


Enable System Restore
It's never a good idea to disable System Restore especially when we are attempting to get your computer cleaned. Lets go ahead and enable your system restore now.

Please carry out the following:
  • On the Desktop, right-click My Computer.
  • Click Properties.
  • Click the System Restore tab.
  • Check Turn On System Restore.
  • Click Apply, and then click OK.

NEXT:


OTL Custom Scan
  • Download OTL to your desktop.
  • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output.
  • Check the boxes beside LOP Check and Purity Check.
  • Under Custom Scan paste this in


    netsvcs
    %SYSTEMDRIVE%\*.exe
    /md5start
    eventlog.dll
    scecli.dll
    netlogon.dll
    cngaudit.dll
    sceclt.dll
    ntelogon.dll
    logevent.dll
    iaStor.sys
    nvstor.sys
    atapi.sys
    IdeChnDr.sys
    viasraid.sys
    AGP440.sys
    vaxscsi.sys
    nvatabus.sys
    viamraid.sys
    nvata.sys
    nvgts.sys
    iastorv.sys
    ViPrt.sys
    eNetHook.dll
    ahcix86.sys
    KR10N.sys
    nvstor32.sys
    ahcix86s.sys
    nvrd32.sys
    symmpi.sys
    adp3132.sys
    mv61xx.sys
    /md5stop
    %systemroot%\*. /mp /s
    CREATERESTOREPOINT
    %systemroot%\system32\*.dll /lockedfiles
    %systemroot%\Tasks\*.job /lockedfiles
    %systemroot%\system32\drivers\*.sys /lockedfiles
    %systemroot%\System32\config\*.sav

  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
  • When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.
  • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post it with your next reply.
  • You may need two posts to fit them both in.

NEXT:


Please make sure you include the following items in your next post:

1. Any comments or questions you may have that you'd like for me to answer in my next post to you.
2. The logs that were produced after running OTL. (OTL.txt & Extras.txt)
3. An update on how your computer is currently running.

It would be helpful if you could answer each question in the order asked, as well as numbering your answers.
Hello SweetTech and thanks for your help

Forgot to infomr you that the virus that was in my "system volume information" directory was fakealert.bvs and cosmu.mot

1. System restore is back on
2. here is the first log file from OTL will make second post with other file.

OTL logfile created on: 3/7/2010 4:37:35 PM - Run 1
OTL by OldTimer - Version 3.1.34.0 Folder = C:\Documents and Settings\Lancesandra\Desktop
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

1,015.00 Mb Total Physical Memory | 566.00 Mb Available Physical Memory | 56.00% Memory free
2.00 Gb Paging File | 2.00 Gb Available in Paging File | 84.00% Paging File free
Paging file location(s): C:\pagefile.sys 1524 3048 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 72.06 Gb Total Space | 57.41 Gb Free Space | 79.67% Space Free | Partition Type: NTFS
Drive D: | 72.05 Gb Total Space | 71.94 Gb Free Space | 99.85% Space Free | Partition Type: NTFS
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: LANCESANDRAEEPC
Current User Name: Lancesandra
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal

========== Processes (SafeList) ==========

PRC - C:\Documents and Settings\Lancesandra\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\AVG\AVG9\avgchsvx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG9\avgcsrvx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG9\avgnsx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG9\avgrsx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG9\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\Common Files\Intuit\Update Service\IntuitUpdateService.exe (Intuit Inc.)
PRC - C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe (Microsoft Corporation)
PRC - C:\Program Files\EeePC\ACPI\AsAcpiSvr.exe (ASUSTeK Computer Inc.)
PRC - C:\Program Files\EeePC\ACPI\AsTray.exe (ASUSTeK Computer Inc.)
PRC - C:\Program Files\ASUS\EeePC\Super Hybrid Engine\SuperHybridEngine.exe (ASUSTeK Computer Inc.)
PRC - C:\Program Files\EeePC\ACPI\AsEPCMon.exe (ASUSTeK Computer Inc.)
PRC - C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe (Adobe Systems Incorporated)
PRC - C:\Program Files\Windows Desktop Search\WindowsSearch.exe (Microsoft Corporation)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\WINDOWS\system32\igfxext.exe (Intel Corporation)


========== Modules (SafeList) ==========

MOD - C:\Documents and Settings\Lancesandra\Desktop\OTL.exe (OldTimer Tools)


========== Win32 Services (SafeList) ==========

SRV - (avg9wd) – C:\Program Files\AVG\AVG9\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
SRV - (AVG Security Toolbar Service) – C:\Program Files\AVG\AVG9\Toolbar\ToolbarBroker.exe ()
SRV - (ATTRcAppSvc) – C:\Program Files\AT&T\Communication Manager\RcAppSvc.exe (SmithMicro Inc.)
SRV - (IntuitUpdateService) – C:\Program Files\Common Files\Intuit\Update Service\IntuitUpdateService.exe (Intuit Inc.)
SRV - (SeaPort) – C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe (Microsoft Corporation)
SRV - (fsssvc) – C:\Program Files\Windows Live\Family Safety\fsssvc.exe (Microsoft Corporation)


========== Driver Services (SafeList) ==========

DRV - (AvgTdiX) – C:\WINDOWS\system32\drivers\avgtdix.sys (AVG Technologies CZ, s.r.o.)
DRV - (AvgLdx86) – C:\WINDOWS\system32\drivers\avgldx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (AvgMfx86) – C:\WINDOWS\system32\drivers\avgmfx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (tcpipBM) – C:\WINDOWS\system32\drivers\tcpipBM.sys (Bytemobile, Inc.)
DRV - (PCTINDIS5) – C:\WINDOWS\system32\PCTINDIS5.sys (Smith Micro Inc.)
DRV - (mfehidk) – C:\WINDOWS\system32\drivers\mfehidk.sys (McAfee, Inc.)
DRV - (mfeavfk) – C:\WINDOWS\system32\drivers\mfeavfk.sys (McAfee, Inc.)
DRV - (mfesmfk) – C:\WINDOWS\system32\drivers\mfesmfk.sys (McAfee, Inc.)
DRV - (mfebopk) – C:\WINDOWS\system32\drivers\mfebopk.sys (McAfee, Inc.)
DRV - (mferkdk) – C:\WINDOWS\system32\drivers\mferkdk.sys (McAfee, Inc.)
DRV - (SWUMXA3) Sierra Wireless USB MUX Driver (UMTSA3) – C:\WINDOWS\system32\drivers\swumxa3.sys (Sierra Wireless Inc.)
DRV - (IntcAzAudAddService) Service for Realtek HD Audio (WDM) – C:\WINDOWS\system32\drivers\RtkHDAud.sys (Realtek Semiconductor Corp.)
DRV - (SRS_PremiumSound_Service) – C:\WINDOWS\system32\drivers\SRS_PremiumSound_i386.sys ()
DRV - (SWNC8UA3) Sierra Wireless MUX NDIS Driver (UMTSA3) – C:\WINDOWS\system32\drivers\swnc8ua3.sys (Sierra Wireless Inc.)
DRV - (AR5416) – C:\WINDOWS\system32\drivers\athw.sys (Atheros Communications, Inc.)
DRV - (SynTP) – C:\WINDOWS\system32\drivers\SynTP.sys (Synaptics Incorporated)
DRV - (L1c) – C:\WINDOWS\system32\drivers\l1c51x86.sys (Atheros Communications, Inc.)
DRV - (fssfltr) – C:\WINDOWS\system32\drivers\fssfltr_tdi.sys (Microsoft Corporation)
DRV - (uvclf) – C:\WINDOWS\system32\drivers\uvclf.sys (GenesysLogic Technologies, Inc.)
DRV - (iaStor) – C:\WINDOWS\system32\drivers\iaStor.sys (Intel Corporation)
DRV - (swmsflt) – C:\WINDOWS\System32\drivers\swmsflt.sys ()
DRV - (Ambfilt) – C:\WINDOWS\system32\drivers\Ambfilt.sys (Creative)
DRV - (HDAudBus) – C:\WINDOWS\system32\drivers\hdaudbus.sys (Windows ® Server 2003 DDK provider)
DRV - (AsusACPI) – C:\WINDOWS\system32\drivers\ASUSACPI.SYS (ASUSTeK Computer Inc.)
DRV - (ialm) – C:\WINDOWS\system32\drivers\igxpmp32.sys (Intel Corporation)
DRV - (Monfilt) – C:\WINDOWS\system32\drivers\Monfilt.sys (Creative Technology Ltd.)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========


IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://my.yahoo.com/
IE - HKCU\..\URLSearchHook: {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dll ()
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..extensions.enabledItems: {B7082FAA-CB62-4872-9106-E42DD88EDE45}:3.0
FF - prefs.js..extensions.enabledItems: {635abd67-4fe9-1b23-4f01-e679fa7484c1}:1.5.4.20081105


FF - HKLM\software\mozilla\Firefox\Extensions\\{3f963a5b-e555-4543-90e2-c3908898db71}: C:\Program Files\AVG\AVG9\Firefox [2010/03/06 17:11:49 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\avg@igeared: C:\Program Files\AVG\AVG9\Toolbar\Firefox\avg@igeared [2010/03/06 17:12:03 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010/02/25 20:26:58 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010/02/25 20:26:30 | 000,000,000 | —D | M]

[2010/02/25 20:27:29 | 000,000,000 | —D | M] – C:\Documents and Settings\Lancesandra\Application Data\Mozilla\Extensions
[2010/02/28 19:30:04 | 000,000,000 | —D | M] – C:\Documents and Settings\Lancesandra\Application Data\Mozilla\Firefox\Profiles\we7cl42s.default\extensions
[2010/02/26 06:59:18 | 000,000,000 | —D | M] (Microsoft .NET Framework Assistant) – C:\Documents and Settings\Lancesandra\Application Data\Mozilla\Firefox\Profiles\we7cl42s.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2010/02/26 07:02:22 | 000,000,000 | —D | M] (Yahoo! Toolbar) – C:\Documents and Settings\Lancesandra\Application Data\Mozilla\Firefox\Profiles\we7cl42s.default\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1}
[2010/02/25 20:26:31 | 000,000,000 | —D | M] – C:\Program Files\Mozilla Firefox\extensions

O1 HOSTS File: ([2008/04/14 06:00:00 | 000,000,734 | —- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (Skype add-on (mastermind)) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Skype Technologies S.A.)
O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG9\avgssie.dll (AVG Technologies CZ, s.r.o.)
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O2 - BHO: (Search Helper) - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll (Microsoft Corporation)
O2 - BHO: (Groove GFS Browser Helper) - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation)
O2 - BHO: (AVG Security Toolbar BHO) - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dll ()
O2 - BHO: (TBSB00982 Class) - {DA3D342F-FF20-4E31-9E82-22334155730C} - C:\Program Files\Antbar\Ant.com Toolbar\tbcore3.dll ()
O2 - BHO: (Windows Live Toolbar Helper) - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files\Windows Live\Toolbar\wltcore.dll (Microsoft Corporation)
O3 - HKLM\..\Toolbar: (&Windows Live Toolbar) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll (Microsoft Corporation)
O3 - HKLM\..\Toolbar: (Ant.com Toolbar) - {6CD56C02-CB4D-41B5-A0FE-B479061CCB41} - C:\Program Files\Antbar\Ant.com Toolbar\tbcore3.dll ()
O3 - HKLM\..\Toolbar: (AVG Security Toolbar) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - C:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dll ()
O3 - HKCU\..\Toolbar\WebBrowser: (&Windows Live Toolbar) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll (Microsoft Corporation)
O3 - HKCU\..\Toolbar\WebBrowser: (Ant.com Toolbar) - {6CD56C02-CB4D-41B5-A0FE-B479061CCB41} - C:\Program Files\Antbar\Ant.com Toolbar\tbcore3.dll ()
O3 - HKCU\..\Toolbar\WebBrowser: (AVG Security Toolbar) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - C:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dll ()
O4 - HKLM..\Run: [Adobe Reader Speed Launcher] C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [AsusACPIServer] C:\Program Files\EeePC\ACPI\AsAcpiSvr.exe (ASUSTeK Computer Inc.)
O4 - HKLM..\Run: [AsusEPCMonitor] C:\Program Files\EeePC\ACPI\AsEPCMon.exe (ASUSTeK Computer Inc.)
O4 - HKLM..\Run: [AsusTray] C:\Program Files\EeePC\ACPI\AsTray.exe (ASUSTeK Computer Inc.)
O4 - HKLM..\Run: [SynAsusAcpi] C:\Program Files\Synaptics\SynTP\SynAsusAcpi.exe (Synaptics Incorporated)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\ SuperHybridEngine.lnk = C:\Program Files\ASUS\EeePC\Super Hybrid Engine\SuperHybridEngine.exe (ASUSTeK Computer Inc.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Windows Search.lnk = C:\Program Files\Windows Desktop Search\WindowsSearch.exe (Microsoft Corporation)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O8 - Extra context menu item: E&xport to Microsoft Excel - C:\Program Files\Microsoft Office\Office12\EXCEL.EXE (Microsoft Corporation)
O9 - Extra Button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : &Blog This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation)
O9 - Extra Button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Skype Technologies S.A.)
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Program Files\Microsoft Office\Office12\REFIEBAR.DLL (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - File not found
O15 - HKCU\..Trusted Domains: intuit.com ([ttlc] https in Trusted sites)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} http://www.update.microsoft.com/microsoftu…b?1256933014609 (MUWebControl Class)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab (Shockwave Flash Object)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.254
O18 - Protocol\Handler\avgsecuritytoolbar {F2DDE6B2-9684-4A55-86D4-E255E237B77C} - C:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dll ()
O18 - Protocol\Handler\grooveLocalGWS {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll (Microsoft Corporation)
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG9\avgpp.dll (AVG Technologies CZ, s.r.o.)
O18 - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\Windows Live\Messenger\msgrapp.14.0.8064.0206.dll (Microsoft Corporation)
O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll (Microsoft Corporation)
O18 - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\Windows Live\Messenger\msgrapp.14.0.8064.0206.dll (Microsoft Corporation)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Handler\wlmailhtml {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - C:\Program Files\Windows Live\Mail\mailcomm.dll (Microsoft Corporation)
O18 - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\Microsoft Shared\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\avgrsstarter: DllName - avgrsstx.dll - C:\WINDOWS\System32\avgrsstx.dll (AVG Technologies CZ, s.r.o.)
O20 - Winlogon\Notify\igfxcui: DllName - igfxdev.dll - C:\WINDOWS\System32\igfxdev.dll (Intel Corporation)
O24 - Desktop WallPaper: C:\Documents and Settings\Lancesandra\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Lancesandra\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O28 - HKLM ShellExecuteHooks: {56F9679E-7826-4C84-81F3-532071A8BCC5} - C:\Program Files\Windows Desktop Search\MsnlNamespaceMgr.dll (Microsoft Corporation)
O28 - HKLM ShellExecuteHooks: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009/04/27 23:03:59 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - comfile [open] – "%1" %*
O35 - exefile [open] – "%1" %*

NetSvcs: 6to4 - File not found
NetSvcs: Ias - C:\WINDOWS\system32\ias [2009/04/27 23:03:27 | 000,000,000 | —D | M]
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: Wmi - C:\WINDOWS\system32\wmi.dll (Microsoft Corporation)
NetSvcs: WmdmPmSp - File not found

CREATERESTOREPOINT
Restore point Set: OTL Restore Point (17173366603513856)

========== Files/Folders - Created Within 30 Days ==========

[2010/03/07 16:25:05 | 000,553,984 | —- | C] (OldTimer Tools) – C:\Documents and Settings\Lancesandra\Desktop\OTL.exe
[2010/03/07 16:23:06 | 000,000,000 | —D | C] – C:\WINDOWS\temp
[2010/03/07 16:15:21 | 000,000,000 | RHSD | C] – C:\cmdcons
[2010/03/07 16:14:16 | 000,212,480 | —- | C] (SteelWerX) – C:\WINDOWS\SWXCACLS.exe
[2010/03/07 16:14:16 | 000,161,792 | —- | C] (SteelWerX) – C:\WINDOWS\SWREG.exe
[2010/03/07 16:14:16 | 000,136,704 | —- | C] (SteelWerX) – C:\WINDOWS\SWSC.exe
[2010/03/07 16:14:16 | 000,031,232 | —- | C] (NirSoft) – C:\WINDOWS\NIRCMD.exe
[2010/03/07 16:14:05 | 000,000,000 | —D | C] – C:\ComboFix
[2010/03/07 16:13:37 | 000,000,000 | —D | C] – C:\Qoobox
[2010/03/07 11:26:06 | 000,000,000 | —D | C] – C:\WINDOWS\ERDNT
[2010/03/07 11:25:04 | 000,000,000 | —D | C] – C:\Program Files\ERUNT
[2010/03/07 11:24:11 | 000,791,393 | —- | C] (Lars Hederer ) – C:\Documents and Settings\Lancesandra\My Documents\erunt_setup.exe
[2010/03/07 11:22:25 | 000,021,504 | —- | C] (Doug Knox) – C:\Documents and Settings\Lancesandra\My Documents\SysRestorePoint.exe
[2010/03/07 11:17:02 | 000,050,688 | —- | C] (Atribune.org) – C:\Documents and Settings\Lancesandra\My Documents\ATF_Cleaner.exe
[2010/03/07 10:58:08 | 000,000,000 | —D | C] – C:\Program Files\Trend Micro
[2010/03/07 10:58:01 | 000,812,344 | —- | C] (Trend Micro Inc.) – C:\Documents and Settings\Lancesandra\My Documents\HJTInstall.exe
[2010/03/07 10:28:23 | 000,038,224 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2010/03/07 10:28:21 | 000,019,160 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys
[2010/03/07 10:28:20 | 000,000,000 | —D | C] – C:\Program Files\Malwarebytes' Anti-Malware
[2010/03/07 10:27:36 | 005,115,824 | —- | C] (Malwarebytes Corporation ) – C:\Documents and Settings\Lancesandra\My Documents\mbam-setup.exe
[2010/03/06 17:38:12 | 000,000,000 | —D | C] – C:\$AVG
[2010/03/06 17:12:20 | 000,242,696 | —- | C] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\drivers\avgtdix.sys
[2010/03/06 17:12:20 | 000,012,464 | —- | C] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\avgrsstx.dll
[2010/03/06 17:12:10 | 000,216,200 | —- | C] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\drivers\avgldx86.sys
[2010/03/06 17:12:09 | 000,029,512 | —- | C] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\drivers\avgmfx86.sys
[2010/03/06 17:12:04 | 000,000,000 | —D | C] – C:\WINDOWS\System32\drivers\Avg
[2010/03/06 17:12:03 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\AVG Security Toolbar
[2010/03/06 17:11:49 | 000,000,000 | —D | C] – C:\Program Files\AVG
[2010/03/06 17:11:48 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\avg9
[2010/03/06 17:10:50 | 000,000,000 | –SD | M] – C:\Documents and Settings\NetworkService\Application Data\Microsoft
[2010/03/06 17:10:50 | 000,000,000 | –SD | M] – C:\Documents and Settings\LocalService\Application Data\Microsoft
[2010/03/06 17:10:50 | 000,000,000 | —D | M] – C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft
[2010/03/06 17:10:50 | 000,000,000 | —D | M] – C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft
[2010/03/06 16:46:33 | 095,829,360 | —- | C] (AVG Technologies) – C:\Documents and Settings\Lancesandra\My Documents\avg_free_stf_all_90_787a2721.exe
[2010/03/06 07:28:36 | 000,055,656 | —- | C] (Avira GmbH) – C:\WINDOWS\System32\drivers\avgntflt.sys
[2010/03/06 07:18:34 | 009,758,152 | —- | C] (Microsoft Corporation) – C:\Documents and Settings\Lancesandra\My Documents\windows-kb890830-v3.4.exe
[2010/03/06 07:18:28 | 016,409,960 | —- | C] (Safer Networking Limited ) – C:\Documents and Settings\Lancesandra\My Documents\spybotsd162.exe
[2010/03/06 07:18:24 | 000,367,616 | —- | C] (Avira GmbH) – C:\Documents and Settings\Lancesandra\My Documents\removaltool-win32-en.exe
[2010/03/03 17:53:13 | 000,000,000 | —D | C] – C:\Documents and Settings\Lancesandra\Application Data\Windows Search
[2010/02/28 20:37:59 | 000,000,000 | —D | C] – C:\Program Files\Spybot - Search & Destroy
[2010/02/28 20:37:59 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
[2010/02/28 20:05:26 | 000,000,000 | —D | C] – C:\Documents and Settings\Lancesandra\Application Data\Malwarebytes
[2010/02/28 20:05:13 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Malwarebytes
[2010/02/26 07:35:37 | 000,000,000 | RH-D | C] – C:\Documents and Settings\Lancesandra\Recent
[2010/02/26 07:01:58 | 000,000,000 | —D | C] – C:\Program Files\CCleaner
[2010/02/26 06:54:24 | 000,000,000 | —D | C] – C:\WINDOWS\Minidump
[2010/02/25 20:47:08 | 015,083,520 | —- | C] (Safer Networking Limited ) – C:\Documents and Settings\Lancesandra\My Documents\spybotsd160.exe
[2010/02/25 20:31:17 | 000,000,000 | —D | C] – C:\Documents and Settings\Lancesandra\My Documents\Downloads
[2010/02/25 20:26:51 | 000,000,000 | —D | C] – C:\Documents and Settings\Lancesandra\Local Settings\Application Data\Mozilla
[2010/02/25 20:26:16 | 000,000,000 | —D | C] – C:\Program Files\Mozilla Firefox
[2010/02/21 16:09:58 | 000,000,000 | —D | C] – C:\Documents and Settings\Lancesandra\Application Data\U3
[2010/02/21 16:08:40 | 000,000,000 | —D | C] – C:\Documents and Settings\Lancesandra\My Documents\TurboTax
[2010/02/21 15:43:32 | 000,000,000 | —D | M] – C:\Documents and Settings\LocalService\Local Settings\Application Data\IsolatedStorage
[2010/02/21 15:43:28 | 000,000,000 | —D | C] – C:\Documents and Settings\Lancesandra\Local Settings\Application Data\Intuit
[2010/02/21 15:37:41 | 000,000,000 | —D | C] – C:\Documents and Settings\Lancesandra\Application Data\Intuit
[2010/02/21 15:37:32 | 000,000,000 | —D | C] – C:\Program Files\Common Files\AnswerWorks 5.0
[2010/02/21 15:31:08 | 000,000,000 | —D | C] – C:\Documents and Settings\Lancesandra\Local Settings\Application Data\IsolatedStorage
[2010/02/21 15:31:03 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Intuit
[2010/02/21 15:30:22 | 000,000,000 | —D | C] – C:\Program Files\TurboTax
[2010/02/21 15:29:46 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Intuit
[2010/02/10 19:28:23 | 000,000,000 | —D | C] – C:\Documents and Settings\Lancesandra\Application Data\Mozilla
[2010/02/10 19:25:02 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Remote Control USB Driver
[2010/02/08 18:09:06 | 000,000,000 | —D | C] – C:\Documents and Settings\Lancesandra\Local Settings\Application Data\assembly
[2010/02/05 16:41:33 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Research In Motion
[2010/02/05 16:41:31 | 000,000,000 | —D | C] – C:\Program Files\AT&T
[2009/12/07 15:22:35 | 000,000,000 | —D | M] – C:\Documents and Settings\LocalService\Local Settings\Application Data\Adobe
[2009/12/03 21:51:48 | 000,000,000 | —D | M] – C:\Documents and Settings\LocalService\Application Data\McAfee
[2009/11/18 11:57:09 | 000,000,000 | —D | M] – C:\Documents and Settings\NetworkService\Application Data\Bytemobile
[2009/10/30 18:39:49 | 000,000,000 | —D | M] – C:\Documents and Settings\LocalService\Application Data\SACore
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2010/03/07 16:34:07 | 000,000,006 | -H– | M] () – C:\WINDOWS\tasks\SA.DAT
[2010/03/07 16:34:04 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2010/03/07 16:34:02 | 1064,554,496 | -HS- | M] () – C:\hiberfil.sys
[2010/03/07 16:25:05 | 000,553,984 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Lancesandra\Desktop\OTL.exe
[2010/03/07 16:21:08 | 000,000,227 | —- | M] () – C:\WINDOWS\system.ini
[2010/03/07 16:15:25 | 000,000,281 | RHS- | M] () – C:\boot.ini
[2010/03/07 16:09:50 | 004,122,023 | R— | M] () – C:\Documents and Settings\Lancesandra\Desktop\ComboFix.exe
[2010/03/07 14:55:33 | 004,447,632 | -H– | M] () – C:\Documents and Settings\Lancesandra\Local Settings\Application Data\IconCache.db
[2010/03/07 11:39:03 | 000,293,376 | —- | M] () – C:\Documents and Settings\Lancesandra\My Documents\547bc5r1.exe
[2010/03/07 11:25:11 | 000,000,611 | —- | M] () – C:\Documents and Settings\Lancesandra\Desktop\NTREGOPT.lnk
[2010/03/07 11:25:11 | 000,000,592 | —- | M] () – C:\Documents and Settings\Lancesandra\Desktop\ERUNT.lnk
[2010/03/07 11:24:21 | 000,791,393 | —- | M] (Lars Hederer ) – C:\Documents and Settings\Lancesandra\My Documents\erunt_setup.exe
[2010/03/07 11:22:30 | 000,021,504 | —- | M] (Doug Knox) – C:\Documents and Settings\Lancesandra\My Documents\SysRestorePoint.exe
[2010/03/07 11:17:02 | 000,050,688 | —- | M] (Atribune.org) – C:\Documents and Settings\Lancesandra\My Documents\ATF_Cleaner.exe
[2010/03/07 10:58:10 | 000,001,734 | —- | M] () – C:\Documents and Settings\Lancesandra\Desktop\HijackThis.lnk
[2010/03/07 10:58:05 | 000,812,344 | —- | M] (Trend Micro Inc.) – C:\Documents and Settings\Lancesandra\My Documents\HJTInstall.exe
[2010/03/07 10:28:26 | 000,000,696 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2010/03/07 10:27:57 | 005,115,824 | —- | M] (Malwarebytes Corporation ) – C:\Documents and Settings\Lancesandra\My Documents\mbam-setup.exe
[2010/03/07 09:18:56 | 056,819,350 | —- | M] () – C:\WINDOWS\System32\drivers\Avg\incavi.avm
[2010/03/06 17:12:20 | 000,242,696 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\drivers\avgtdix.sys
[2010/03/06 17:12:20 | 000,012,464 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\avgrsstx.dll
[2010/03/06 17:12:20 | 000,001,507 | —- | M] () – C:\Documents and Settings\All Users\Desktop\AVG Free 9.0.lnk
[2010/03/06 17:12:10 | 000,216,200 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\drivers\avgldx86.sys
[2010/03/06 17:12:09 | 000,113,461 | —- | M] () – C:\WINDOWS\System32\drivers\Avg\iavichjw.avm
[2010/03/06 17:12:09 | 000,029,512 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\drivers\avgmfx86.sys
[2010/03/06 16:51:02 | 004,456,448 | -H– | M] () – C:\Documents and Settings\Lancesandra\NTUSER.DAT
[2010/03/06 16:50:41 | 000,000,178 | -HS- | M] () – C:\Documents and Settings\Lancesandra\ntuser.ini
[2010/03/06 16:47:04 | 095,829,360 | —- | M] (AVG Technologies) – C:\Documents and Settings\Lancesandra\My Documents\avg_free_stf_all_90_787a2721.exe
[2010/03/05 17:07:00 | 009,758,152 | —- | M] (Microsoft Corporation) – C:\Documents and Settings\Lancesandra\My Documents\windows-kb890830-v3.4.exe
[2010/03/05 17:04:06 | 030,042,194 | —- | M] () – C:\Documents and Settings\Lancesandra\My Documents\vdf_fusebundle.zip
[2010/03/05 17:00:50 | 000,367,616 | —- | M] (Avira GmbH) – C:\Documents and Settings\Lancesandra\My Documents\removaltool-win32-en.exe
[2010/03/05 09:46:00 | 030,909,992 | —- | M] () – C:\Documents and Settings\Lancesandra\My Documents\avira_antivir_personal_en.exe
[2010/03/03 17:59:30 | 000,000,933 | —- | M] () – C:\Documents and Settings\Lancesandra\Desktop\Spybot - Search & Destroy.lnk
[2010/03/03 17:47:45 | 000,001,158 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2010/03/02 16:09:00 | 006,723,216 | —- | M] () – C:\Documents and Settings\Lancesandra\My Documents\spybotsd_includes.exe
[2010/03/02 16:06:54 | 016,409,960 | —- | M] (Safer Networking Limited ) – C:\Documents and Settings\Lancesandra\My Documents\spybotsd162.exe
[2010/02/28 20:36:37 | 000,000,582 | —- | M] () – C:\WINDOWS\win.ini
[2010/02/28 20:36:37 | 000,000,211 | —- | M] () – C:\Boot.bak
[2010/02/28 17:49:57 | 000,218,938 | —- | M] () – C:\Documents and Settings\Lancesandra\My Documents\cc_20100228_174936.reg
[2010/02/26 07:05:50 | 000,074,362 | —- | M] () – C:\Documents and Settings\Lancesandra\My Documents\cc_20100226_070536.reg
[2010/02/26 07:02:13 | 000,001,548 | —- | M] () – C:\Documents and Settings\Lancesandra\Desktop\CCleaner.lnk
[2010/02/25 20:52:16 | 000,092,582 | —- | M] () – C:\Documents and Settings\Lancesandra\My Documents\spybot.docx
[2010/02/25 20:50:06 | 000,002,515 | —- | M] () – C:\Documents and Settings\Lancesandra\Desktop\Microsoft Office Word 2007.lnk
[2010/02/25 20:43:24 | 015,083,520 | —- | M] (Safer Networking Limited ) – C:\Documents and Settings\Lancesandra\My Documents\spybotsd160.exe
[2010/02/25 20:27:06 | 000,000,000 | —- | M] () – C:\WINDOWS\nsreg.dat
[2010/02/25 20:26:40 | 000,001,602 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Mozilla Firefox.lnk
[2010/02/25 19:22:10 | 000,002,393 | —- | M] () – C:\Documents and Settings\All Users\Desktop\TurboTax 2009.lnk
[2010/02/24 18:50:19 | 000,002,521 | —- | M] () – C:\Documents and Settings\Lancesandra\Desktop\Microsoft Office Outlook 2007.lnk
[2010/02/21 23:27:54 | 000,354,568 | —- | M] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2010/02/21 15:43:14 | 000,094,888 | —- | M] () – C:\Documents and Settings\Lancesandra\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]

========== Files Created - No Company Name ==========

[2010/03/07 16:15:25 | 000,000,211 | —- | C] () – C:\Boot.bak
[2010/03/07 16:15:22 | 000,260,272 | —- | C] () – C:\cmldr
[2010/03/07 16:14:16 | 000,261,632 | —- | C] () – C:\WINDOWS\PEV.exe
[2010/03/07 16:14:16 | 000,098,816 | —- | C] () – C:\WINDOWS\sed.exe
[2010/03/07 16:14:16 | 000,080,412 | —- | C] () – C:\WINDOWS\grep.exe
[2010/03/07 16:14:16 | 000,077,312 | —- | C] () – C:\WINDOWS\MBR.exe
[2010/03/07 16:14:16 | 000,068,096 | —- | C] () – C:\WINDOWS\zip.exe
[2010/03/07 16:09:42 | 004,122,023 | R— | C] () – C:\Documents and Settings\Lancesandra\Desktop\ComboFix.exe
[2010/03/07 14:58:54 | 1064,554,496 | -HS- | C] () – C:\hiberfil.sys
[2010/03/07 11:39:03 | 000,293,376 | —- | C] () – C:\Documents and Settings\Lancesandra\My Documents\547bc5r1.exe
[2010/03/07 11:25:11 | 000,000,611 | —- | C] () – C:\Documents and Settings\Lancesandra\Desktop\NTREGOPT.lnk
[2010/03/07 11:25:11 | 000,000,592 | —- | C] () – C:\Documents and Settings\Lancesandra\Desktop\ERUNT.lnk
[2010/03/07 10:58:10 | 000,001,734 | —- | C] () – C:\Documents and Settings\Lancesandra\Desktop\HijackThis.lnk
[2010/03/07 10:28:26 | 000,000,696 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2010/03/06 17:12:20 | 000,001,507 | —- | C] () – C:\Documents and Settings\All Users\Desktop\AVG Free 9.0.lnk
[2010/03/06 17:12:09 | 000,113,461 | —- | C] () – C:\WINDOWS\System32\drivers\Avg\iavichjw.avm
[2010/03/06 17:12:04 | 056,819,350 | —- | C] () – C:\WINDOWS\System32\drivers\Avg\incavi.avm
[2010/03/06 07:18:35 | 030,909,992 | —- | C] () – C:\Documents and Settings\Lancesandra\My Documents\avira_antivir_personal_en.exe
[2010/03/06 07:18:31 | 030,042,194 | —- | C] () – C:\Documents and Settings\Lancesandra\My Documents\vdf_fusebundle.zip
[2010/03/06 07:18:30 | 006,723,216 | —- | C] () – C:\Documents and Settings\Lancesandra\My Documents\spybotsd_includes.exe
[2010/02/28 20:38:06 | 000,000,933 | —- | C] () – C:\Documents and Settings\Lancesandra\Desktop\Spybot - Search & Destroy.lnk
[2010/02/28 17:49:41 | 000,218,938 | —- | C] () – C:\Documents and Settings\Lancesandra\My Documents\cc_20100228_174936.reg
[2010/02/26 07:05:39 | 000,074,362 | —- | C] () – C:\Documents and Settings\Lancesandra\My Documents\cc_20100226_070536.reg
[2010/02/26 07:02:12 | 000,001,548 | —- | C] () – C:\Documents and Settings\Lancesandra\Desktop\CCleaner.lnk
[2010/02/25 20:52:15 | 000,092,582 | —- | C] () – C:\Documents and Settings\Lancesandra\My Documents\spybot.docx
[2010/02/25 20:27:06 | 000,000,000 | —- | C] () – C:\WINDOWS\nsreg.dat
[2010/02/25 20:26:40 | 000,001,602 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Mozilla Firefox.lnk
[2010/02/21 23:27:01 | 000,197,760 | —- | C] () – C:\Documents and Settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
[2010/02/21 15:33:47 | 000,002,393 | —- | C] () – C:\Documents and Settings\All Users\Desktop\TurboTax 2009.lnk
[2010/01/02 17:37:57 | 000,000,000 | —- | C] () – C:\Documents and Settings\Lancesandra\Application Data\wklnhst.dat
[2009/11/18 11:37:55 | 000,026,760 | R— | C] () – C:\WINDOWS\System32\drivers\swmsflt.sys
[2009/11/01 11:43:18 | 000,000,161 | —- | C] () – C:\WINDOWS\System32\AddPort.ini
[2009/11/01 11:42:00 | 000,000,636 | —- | C] () – C:\WINDOWS\hpntwksetup.ini
[2009/11/01 11:41:13 | 000,000,337 | —- | C] () – C:\Documents and Settings\All Users\Application Data\hpzinstall.log
[2009/10/30 18:29:03 | 000,000,134 | —- | C] () – C:\Documents and Settings\Lancesandra\Local Settings\Application Data\fusioncache.dat
[2009/05/05 12:13:43 | 000,000,061 | —- | C] () – C:\WINDOWS\smscfg.ini
[2009/05/05 11:16:46 | 000,232,872 | R— | C] () – C:\WINDOWS\System32\drivers\SRS_PremiumSound_i386.sys
[2009/05/05 10:03:49 | 000,021,864 | —- | C] () – C:\WINDOWS\AsAcpiSvrLang.ini
[2009/05/05 10:03:49 | 000,012,208 | —- | C] () – C:\WINDOWS\AsTrayLang.ini
[2009/05/05 09:52:19 | 000,147,456 | —- | C] () – C:\WINDOWS\System32\igfxCoIn_v4906.dll
[2009/04/27 22:51:49 | 000,005,312 | —- | C] () – C:\WINDOWS\System32\OEMINFO.INI
[2007/09/27 10:51:02 | 000,020,698 | —- | C] () – C:\WINDOWS\System32\idxcntrs.ini
[2007/09/27 10:48:48 | 000,030,628 | —- | C] () – C:\WINDOWS\System32\gsrvctr.ini
[2007/09/27 10:48:28 | 000,031,698 | —- | C] () – C:\WINDOWS\System32\gthrctr.ini
[2007/03/16 17:00:00 | 000,003,403 | —- | C] () – C:\WINDOWS\System32\hptcpmon.ini

========== LOP Check ==========

[2010/02/03 17:52:58 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\AT&T
[2010/03/07 09:50:57 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\AVG Security Toolbar
[2010/03/06 17:11:49 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\avg9
[2009/05/05 10:02:02 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Wireless LAN Card
[2009/11/18 11:38:11 | 000,000,000 | —D | M] – C:\Documents and Settings\Lancesandra\Application Data\AT&T
[2009/11/18 11:38:20 | 000,000,000 | —D | M] – C:\Documents and Settings\Lancesandra\Application Data\Bytemobile
[2009/11/18 11:37:55 | 000,000,000 | —D | M] – C:\Documents and Settings\Lancesandra\Application Data\Sierra Wireless
[2010/01/02 17:38:02 | 000,000,000 | —D | M] – C:\Documents and Settings\Lancesandra\Application Data\Template
[2009/11/25 09:01:04 | 000,000,000 | —D | M] – C:\Documents and Settings\Lancesandra\Application Data\Windows Desktop Search
[2010/03/03 17:53:13 | 000,000,000 | —D | M] – C:\Documents and Settings\Lancesandra\Application Data\Windows Search

========== Purity Check ==========



========== Custom Scans ==========


< %SYSTEMDRIVE%\*.exe >


< MD5 for: AGP440.SYS >
[2008/04/14 06:00:00 | 020,056,462 | —- | M] () .cab file – C:\WINDOWS\Driver Cache\i386\sp3.cab:AGP440.sys
[2008/04/14 06:00:00 | 020,056,462 | —- | M] () .cab file – C:\WINDOWS\I386\sp3.cab:AGP440.sys

< MD5 for: ATAPI.SYS >
[2008/04/14 06:00:00 | 020,056,462 | —- | M] () .cab file – C:\WINDOWS\Driver Cache\i386\sp3.cab:atapi.sys
[2008/04/14 06:00:00 | 020,056,462 | —- | M] () .cab file – C:\WINDOWS\I386\sp3.cab:atapi.sys
[2008/04/14 01:10:32 | 000,096,512 | —- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 – C:\WINDOWS\ERDNT\cache\atapi.sys
[2008/04/14 01:10:32 | 000,096,512 | —- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 – C:\WINDOWS\system32\dllcache\atapi.sys
[2008/04/14 01:10:32 | 000,096,512 | —- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 – C:\WINDOWS\system32\drivers\atapi.sys
[2008/04/14 06:00:00 | 000,096,512 | —- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 – C:\WINDOWS\system32\ReinstallBackups\0005\DriverFiles\i386\atapi.sys

< MD5 for: EVENTLOG.DLL >
[2008/04/14 06:00:00 | 000,056,320 | —- | M] (Microsoft Corporation) MD5=6D4FEB43EE538FC5428CC7F0565AA656 – C:\WINDOWS\ERDNT\cache\eventlog.dll
[2008/04/14 06:00:00 | 000,056,320 | —- | M] (Microsoft Corporation) MD5=6D4FEB43EE538FC5428CC7F0565AA656 – C:\WINDOWS\system32\dllcache\eventlog.dll
[2008/04/14 06:00:00 | 000,056,320 | —- | M] (Microsoft Corporation) MD5=6D4FEB43EE538FC5428CC7F0565AA656 – C:\WINDOWS\system32\eventlog.dll

< MD5 for: IASTOR.SYS >
[2008/09/11 23:32:56 | 000,327,192 | —- | M] (Intel Corporation) MD5=8EF427C54497C5F8A7A645990E4278C7 – C:\WINDOWS\I386\$OEM$\TEXTMODE\IASTOR.SYS
[2008/09/11 23:32:56 | 000,327,192 | —- | M] (Intel Corporation) MD5=8EF427C54497C5F8A7A645990E4278C7 – C:\WINDOWS\OemDir\iaStor.sys
[2008/09/11 23:32:56 | 000,327,192 | —- | M] (Intel Corporation) MD5=8EF427C54497C5F8A7A645990E4278C7 – C:\WINDOWS\system32\drivers\iaStor.sys

< MD5 for: NETLOGON.DLL >
[2008/04/14 06:00:00 | 000,407,040 | —- | M] (Microsoft Corporation) MD5=1B7F071C51B77C272875C3A23E1E4550 – C:\WINDOWS\ERDNT\cache\netlogon.dll
[2008/04/14 06:00:00 | 000,407,040 | —- | M] (Microsoft Corporation) MD5=1B7F071C51B77C272875C3A23E1E4550 – C:\WINDOWS\system32\dllcache\netlogon.dll
[2008/04/14 06:00:00 | 000,407,040 | —- | M] (Microsoft Corporation) MD5=1B7F071C51B77C272875C3A23E1E4550 – C:\WINDOWS\system32\netlogon.dll

< MD5 for: SCECLI.DLL >
[2008/04/14 06:00:00 | 000,181,248 | —- | M] (Microsoft Corporation) MD5=A86BB5E61BF3E39B62AB4C7E7085A084 – C:\WINDOWS\ERDNT\cache\scecli.dll
[2008/04/14 06:00:00 | 000,181,248 | —- | M] (Microsoft Corporation) MD5=A86BB5E61BF3E39B62AB4C7E7085A084 – C:\WINDOWS\system32\dllcache\scecli.dll
[2008/04/14 06:00:00 | 000,181,248 | —- | M] (Microsoft Corporation) MD5=A86BB5E61BF3E39B62AB4C7E7085A084 – C:\WINDOWS\system32\scecli.dll

< %systemroot%\*. /mp /s >

< %systemroot%\system32\*.dll /lockedfiles >
[1 C:\WINDOWS\system32\*.tmp files -> C:\WINDOWS\system32\*.tmp -> ]

< %systemroot%\Tasks\*.job /lockedfiles >

< %systemroot%\system32\drivers\*.sys /lockedfiles >

< %systemroot%\System32\config\*.sav >
[2009/04/27 15:57:35 | 000,094,208 | —- | M] () – C:\WINDOWS\system32\config\default.sav
[2009/04/27 15:57:35 | 001,064,960 | —- | M] () – C:\WINDOWS\system32\config\software.sav
[2009/04/27 15:57:35 | 000,909,312 | —- | M] () – C:\WINDOWS\system32\config\system.sav
< End of report >
extra log file THANKS

OTL Extras logfile created on: 3/7/2010 4:37:35 PM - Run 1
OTL by OldTimer - Version 3.1.34.0 Folder = C:\Documents and Settings\Lancesandra\Desktop
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

1,015.00 Mb Total Physical Memory | 566.00 Mb Available Physical Memory | 56.00% Memory free
2.00 Gb Paging File | 2.00 Gb Available in Paging File | 84.00% Paging File free
Paging file location(s): C:\pagefile.sys 1524 3048 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 72.06 Gb Total Space | 57.41 Gb Free Space | 79.67% Space Free | Partition Type: NTFS
Drive D: | 72.05 Gb Total Space | 71.94 Gb Free Space | 99.85% Space Free | Partition Type: NTFS
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: LANCESANDRAEEPC
Current User Name: Lancesandra
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]

[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.html [@ = htmlfile] – Reg Error: Key error. File not found

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
exefile [open] – "%1" %*
htmlfile – "C:\Program Files\Microsoft Office\Office12\msohtmed.exe" %1 (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [OneNote.Open] – C:\PROGRA~1\MICROS~3\Office12\ONENOTE.EXE "%L" (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
"65533:TCP" = 65533:TCP:*:Enabled:Services
"52344:TCP" = 52344:TCP:*:Enabled:Services
"2479:TCP" = 2479:TCP:*:Enabled:Services
"9438:TCP" = 9438:TCP:*:Enabled:Services
"3389:TCP" = 3389:TCP:*:Enabled:Remote Desktop

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"65533:TCP" = 65533:TCP:*:Enabled:Services
"52344:TCP" = 52344:TCP:*:Enabled:Services
"2479:TCP" = 2479:TCP:*:Enabled:Services
"9438:TCP" = 9438:TCP:*:Enabled:Services
"3389:TCP" = 3389:TCP:*:Enabled:Remote Desktop

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
"C:\Program Files\Windows Live\Messenger\wlcsdk.exe" = C:\Program Files\Windows Live\Messenger\wlcsdk.exe:*:Enabled:Windows Live Call – (Microsoft Corporation)
"C:\Program Files\Windows Live\Sync\WindowsLiveSync.exe" = C:\Program Files\Windows Live\Sync\WindowsLiveSync.exe:*:Enabled:Windows Live Sync – (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files\Windows Live\Messenger\wlcsdk.exe" = C:\Program Files\Windows Live\Messenger\wlcsdk.exe:*:Enabled:Windows Live Call – (Microsoft Corporation)
"C:\Program Files\Windows Live\Sync\WindowsLiveSync.exe" = C:\Program Files\Windows Live\Sync\WindowsLiveSync.exe:*:Enabled:Windows Live Sync – (Microsoft Corporation)
"C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE" = C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE:*:Enabled:Microsoft Office OneNote – (Microsoft Corporation)
"C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE" = C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE:*:Enabled:Microsoft Office Outlook – (Microsoft Corporation)
"C:\Program Files\Microsoft Office\Office12\GROOVE.EXE" = C:\Program Files\Microsoft Office\Office12\GROOVE.EXE:*:Enabled:Microsoft Office Groove – (Microsoft Corporation)
"C:\Program Files\Common Files\Intuit\Update Service\IntuitUpdateService.exe" = C:\Program Files\Common Files\Intuit\Update Service\IntuitUpdateService.exe:LocalSubNet:Disabled:Intuit Update Shared Downloads Server – (Intuit Inc.)
"C:\Program Files\AVG\AVG9\avgupd.exe" = C:\Program Files\AVG\AVG9\avgupd.exe:*:Enabled:avgupd.exe – (AVG Technologies CZ, s.r.o.)
"C:\Program Files\AVG\AVG9\avgnsx.exe" = C:\Program Files\AVG\AVG9\avgnsx.exe:*:Enabled:avgnsx.exe – (AVG Technologies CZ, s.r.o.)


========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{0AAA9C97-74D4-47CE-B089-0B147EF3553C}" = Windows Live Messenger
"{15BC8CD0-A65B-47D0-A2DD-90A824590FA8}" = Microsoft Works
"{19F5658D-92E8-4A08-8657-D38ABB1574B2}" = Asus ACPI Driver
"{205C6BDD-7B73-42DE-8505-9A093F35A238}" = Windows Live Upload Tool
"{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}" = MSVCRT
"{28006915-2739-4EBE-B5E8-49B25D32EB33}" = Atheros Client Installation Program
"{3108C217-BE83-42E4-AE9E-A56A2A92E549}" = Atheros Communications Inc.® AR81Family Gigabit/Fast Ethernet Driver
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{3881DB80-EAA2-012B-ADAE-000000000000}" = TurboTax 2009 WinPerFedFormset
"{38975F50-EAA2-012B-ADB4-000000000000}" = TurboTax 2009 WinPerReleaseEngine
"{38A34630-EAA2-012B-ADB6-000000000000}" = TurboTax 2009 WinPerTaxSupport
"{3A915D43-FD4F-4e4f-BEF7-B75C160B0236}" = HP LaserJet M2727 MFP Series 5.0
"{3B4E636E-9D65-4D67-BA61-189800823F52}" = Windows Live Communications Platform
"{3C52E7DA-C431-4239-B66B-1BF703D5B194}" = Windows Live Photo Gallery
"{3C5A81D0-EAA2-012B-AE9F-000000000000}" = TurboTax 2009 wrapper
"{3FB39BED-37C8-4E60-8E02-315B8C2B07E3}" = USB2.0 UVC Camera Device
"{45338B07-A236-4270-9A77-EBB4115517B5}" = Windows Live Sign-in Assistant
"{47BACF74-5A07-48BD-BADB-A769550F0F5A}" = FontResizer
"{4CBA3D4C-8F51-4D60-B27E-F6B641C571E7}" = Microsoft Search Enhancement Pack
"{4DE3E3D9-AE81-45DE-9195-3015F7B1DBF3}" = Junk Mail filter update
"{5672A10E-1B21-4C2F-85D3-3542D0BC8246}" = hppscanM2727
"{587178E7-B1DF-494E-9838-FA4DD36E873C}" = ASUSUpdate for Eee PC
"{5C82DAE5-6EB0-4374-9254-BE3319BA4E82}" = Skype™ 3.6
"{6333FC29-BFE5-4024-AC78-958A1A7555D1}" = EeeSplendid
"{63C1109E-D977-49ED-BCE3-D00D0BF187D6}" = Windows Live Mail
"{6A92E5C5-0578-443D-91F3-92ECE5F2CAE2}" = Windows Live Writer
"{76CD2979-09C0-493A-84B3-8FD97EF4BCEA}" = Windows Live Family Safety
"{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable
"{8471021C-F529-43DE-84DF-3612E10F58C4}" = Remote Control USB Driver
"{88F08F98-12BC-4613-81A2-8F9B88CFC73E}" = Super Hybrid Engine
"{8A74E887-8F0F-4017-AF53-CBA42211AAA5}" = Microsoft Sync Framework Runtime Native v1.0 (x86)
"{8FC4F1DD-F7FD-4766-804D-3C8FF1D309AF}" = Azurewave Wireless LAN Card
"{8FFC5648-FAF8-43A3-BC8F-42BA1E275C4E}" = Choice Guard
"{90120000-0010-0409-0000-0000000FF1CE}" = Microsoft Software Update for Web Folders (English) 12
"{90120000-0015-0409-0000-0000000FF1CE}" = Microsoft Office Access MUI (English) 2007
"{90120000-0015-0409-0000-0000000FF1CE}_ENTERPRISER_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2007
"{90120000-0016-0409-0000-0000000FF1CE}_HOMESTUDENTR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2007
"{90120000-0018-0409-0000-0000000FF1CE}_HOMESTUDENTR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0019-0409-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (English) 2007
"{90120000-0019-0409-0000-0000000FF1CE}_ENTERPRISER_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001A-0409-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (English) 2007
"{90120000-001A-0409-0000-0000000FF1CE}_ENTERPRISER_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2007
"{90120000-001B-0409-0000-0000000FF1CE}_HOMESTUDENTR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}_HOMESTUDENTR_{ABDDE972-355B-4AF1-89A8-DA50B7B5C045}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-040C-0000-0000000FF1CE}_HOMESTUDENTR_{F580DDD5-8D37-4998-968E-EBB76BB86787}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007
"{90120000-001F-0C0A-0000-0000000FF1CE}_HOMESTUDENTR_{187308AB-5FA7-4F14-9AB9-D290383A10D9}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-0020-0409-0000-0000000FF1CE}" = Compatibility Pack for the 2007 Office system
"{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007
"{90120000-0044-0409-0000-0000000FF1CE}" = Microsoft Office InfoPath MUI (English) 2007
"{90120000-0044-0409-0000-0000000FF1CE}_ENTERPRISER_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}_HOMESTUDENTR_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-00A1-0409-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2007
"{90120000-00A1-0409-0000-0000000FF1CE}_HOMESTUDENTR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-00BA-0409-0000-0000000FF1CE}" = Microsoft Office Groove MUI (English) 2007
"{90120000-00BA-0409-0000-0000000FF1CE}_ENTERPRISER_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0114-0409-0000-0000000FF1CE}" = Microsoft Office Groove Setup Metadata MUI (English) 2007
"{90120000-0114-0409-0000-0000000FF1CE}_ENTERPRISER_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007
"{90120000-0115-0409-0000-0000000FF1CE}_HOMESTUDENTR_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0117-0409-0000-0000000FF1CE}" = Microsoft Office Access Setup Metadata MUI (English) 2007
"{90120000-0117-0409-0000-0000000FF1CE}_ENTERPRISER_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{91120000-002F-0000-0000-0000000FF1CE}" = Microsoft Office Home and Student 2007
"{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{0B36C6D6-F5D8-4EAF-BF94-4376A230AD5B}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{3D019598-7B59-447A-80AE-815B703B84FF}" = Security Update for Microsoft Office system 2007 (972581)
"{91120000-0030-0000-0000-0000000FF1CE}" = Microsoft Office Enterprise 2007
"{91120000-0030-0000-0000-0000000FF1CE}_ENTERPRISER_{0B36C6D6-F5D8-4EAF-BF94-4376A230AD5B}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{91120000-0030-0000-0000-0000000FF1CE}_ENTERPRISER_{3D019598-7B59-447A-80AE-815B703B84FF}" = Security Update for Microsoft Office system 2007 (972581)
"{94824ADD-8F26-43D2-84DB-22E11F377E5E}" = Microsoft English TTS Engine
"{95120000-00AF-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint Viewer 2007 (English)
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{96172E04-BB14-45F6-A77B-8EE7A421B903}" = SAPI Wrapper
"{97D0C0A1-7E64-4B05-A2EE-61D2CE23F154}" = TTS Wrapper
"{995F1E2E-F542-4310-8E1D-9926F5A279B3}" = Windows Live Toolbar
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9DE3F260-B88E-42CE-90E7-73C78C37D95E}" = 32 Bit HP BiDi Channel Components Installer
"{9E5A03E3-6246-4920-9630-0527D5DA9B07}" = iSEEK AnswerWorks English Runtime
"{A1BF9950-8CDB-468E-83FA-EACFB00EA7D5}" = Windows Live Sync
"{A1F66FC9-11EE-4F2F-98C9-16F8D1E69FB7}" = Segoe UI
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{AC76BA86-7AD7-1033-7B44-A81300000003}" = Adobe Reader 8.1.3
"{B00690AD-B4F5-4730-9110-5C495B89E647}" = Scan
"{B4092C6D-E886-4CB2-BA68-FE5A88D31DE6}_is1" = Spybot - Search & Destroy
"{B9BDA46B-2E17-4F43-9D7A-9B1E09A0A4D8}" = Data Sync
"{BD64AF4A-8C80-4152-AD77-FCDDF05208AB}" = Microsoft Sync Framework Services Native v1.0 (x86)
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{C6CA8874-5F22-4AF0-9BE3-016BF299C536}" = Windows Live Essentials
"{C72CA49A-9237-4810-8449-45DA3BD26D64}" = EzMessenger
"{C82185E8-C27B-4EF4-2008-4444BC2C2B6D}" = Microsoft Streets & Trips 2008
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{D0E39A1D-0CEE-4D85-B4A2-E3BE990D075E}" = Destination Component
"{E50AE784-FABE-46DA-A1F8-7B6B56DCB22E}" = Microsoft Office Suite Activation Assistant
"{E5BA0430-919F-46DD-B656-0796F8A5ADFF}" = Microsoft Office Communicator 2007
"{E9EB1566-BA9E-458D-9EF3-5776FE58FC69}" = AT&T Communication Manager
"{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU]
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{F6BD194C-4190-4D73-B1B1-C48C99921BFE}" = Windows Live Call
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"AVG9Uninstall" = AVG Free 9.0
"CCleaner" = CCleaner
"Eee Docking_is1" = Eee Docking 1.3.1.0
"EeePC_1005HA" = EeePC_1005HA Screen Saver
"ENTERPRISER" = Microsoft Office Enterprise 2007
"ERUNT_is1" = ERUNT 1.1j
"FLV Player" = FLV Player 2.0 (build 25)
"HDMI" = Intel® Graphics Media Accelerator Driver
"HijackThis" = HijackThis 2.0.2
"HOMESTUDENTR" = Microsoft Office Home and Student 2007
"IDNMitigationAPIs" = Microsoft Internationalized Domain Names Mitigation APIs
"ie8" = Windows Internet Explorer 8
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Mozilla Firefox (3.6)" = Mozilla Firefox (3.6)
"MSCompPackV1" = Microsoft Compression Client Pack 1.0 for Windows XP
"NLSDownlevelMapping" = Microsoft National Language Support Downlevel APIs
"SynTPDeinstKey" = Synaptics Pointing Device Driver
"TBSB00982.TBSB00982Toolbar" = Ant.com Toolbar
"TurboTax 2009" = TurboTax 2009
"Wdf01007" = Microsoft Kernel-Mode Driver Framework Feature Pack 1.7
"Windows Media Format Runtime" = Windows Media Format 11 runtime
"Windows Media Player" = Windows Media Player 11
"WinLiveSuite_Wave3" = Windows Live Essentials
"WMFDist11" = Windows Media Format 11 runtime
"wmp11" = Windows Media Player 11
"Wudf01000" = Microsoft User-Mode Driver Framework Feature Pack 1.0

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 2/25/2010 9:40:15 PM | Computer Name = LANCESANDRAEEPC | Source = crypt32 | ID = 131077
Description = Failed auto update retrieval of third-party root certificate from:
<http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/B31EB1B740E36C8402DADC37D44DF5D4674952F9.crt>
with error: This network connection does not exist.

Error - 2/25/2010 9:40:15 PM | Computer Name = LANCESANDRAEEPC | Source = crypt32 | ID = 131077
Description = Failed auto update retrieval of third-party root certificate from:
<http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/B31EB1B740E36C8402DADC37D44DF5D4674952F9.crt>
with error: This network connection does not exist.

Error - 2/25/2010 9:58:17 PM | Computer Name = LANCESANDRAEEPC | Source = Windows Search Service | ID = 3013
Description = The entry BERRY S FORM 1040 INDIVIDUAL TAX RETURN.TAX2009> in the hash map cannot be updated.

Context:
Application, SystemIndex Catalog Details: A device attached to the system is not
functioning. (0x8007001f)

Error - 2/25/2010 9:58:17 PM | Computer Name = LANCESANDRAEEPC | Source = Windows Search Service | ID = 3013
Description = The entry BERRY S FORM 1040 INDIVIDUAL TAX RETURN.TAX2009> in the hash map cannot be updated.

Context:
Application, SystemIndex Catalog Details: A device attached to the system is not
functioning. (0x8007001f)

Error - 2/25/2010 11:00:56 PM | Computer Name = LANCESANDRAEEPC | Source = Windows Search Service | ID = 3013
Description = The entry BERRY S FORM 1040 INDIVIDUAL TAX RETURN.TAX2009> in the hash map cannot be updated.

Context:
Application, SystemIndex Catalog Details: A device attached to the system is not
functioning. (0x8007001f)

Error - 2/26/2010 9:36:26 AM | Computer Name = LANCESANDRAEEPC | Source = Windows Search Service | ID = 3013
Description = The entry
in the hash map cannot be updated. Context: Application, SystemIndex Catalog Details:
A
device attached to the system is not functioning. (0x8007001f)

Error - 2/26/2010 5:45:17 PM | Computer Name = LANCESANDRAEEPC | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt>
with error: The server name or address could not be resolved

Error - 2/26/2010 5:45:17 PM | Computer Name = LANCESANDRAEEPC | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt>
with error: This network connection does not exist.

Error - 2/26/2010 5:45:18 PM | Computer Name = LANCESANDRAEEPC | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt>
with error: This network connection does not exist.

Error - 2/26/2010 5:45:18 PM | Computer Name = LANCESANDRAEEPC | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt>
with error: This network connection does not exist.

[ System Events ]
Error - 1/13/2010 5:06:24 AM | Computer Name = LANCESANDRAEEPC | Source = Service Control Manager | ID = 7000
Description = The Windows Search service failed to start due to the following error:
%%1053

Error - 1/13/2010 5:06:53 AM | Computer Name = LANCESANDRAEEPC | Source = DCOM | ID = 10010
Description = The server {7D096C5F-AC08-4F1F-BEB7-5C22C517CE39} did not register
with DCOM within the required timeout.

Error - 1/13/2010 5:22:31 AM | Computer Name = LANCESANDRAEEPC | Source = Service Control Manager | ID = 7011
Description = Timeout (30000 milliseconds) waiting for a transaction response from
the mcmscsvc service.

Error - 1/13/2010 5:22:37 AM | Computer Name = LANCESANDRAEEPC | Source = DCOM | ID = 10010
Description = The server {6A972E27-93E2-4F98-8367-4101B2073814} did not register
with DCOM within the required timeout.

Error - 1/22/2010 5:03:38 AM | Computer Name = LANCESANDRAEEPC | Source = BROWSER | ID = 8032
Description = The browser service has failed to retrieve the backup list too many
times on transport \Device\NetBT_Tcpip_{D2FBFFBC-149B-431F-99B9-5D7060491268}. The
backup browser is stopping.

Error - 1/22/2010 5:17:00 AM | Computer Name = LANCESANDRAEEPC | Source = DCOM | ID = 10010
Description = The server {6A972E27-93E2-4F98-8367-4101B2073814} did not register
with DCOM within the required timeout.

Error - 1/22/2010 6:35:27 AM | Computer Name = LANCESANDRAEEPC | Source = BROWSER | ID = 8032
Description = The browser service has failed to retrieve the backup list too many
times on transport \Device\NetBT_Tcpip_{D2FBFFBC-149B-431F-99B9-5D7060491268}. The
backup browser is stopping.

Error - 1/22/2010 1:58:41 PM | Computer Name = LANCESANDRAEEPC | Source = DCOM | ID = 10010
Description = The server {7D096C5F-AC08-4F1F-BEB7-5C22C517CE39} did not register
with DCOM within the required timeout.

Error - 1/22/2010 2:17:02 PM | Computer Name = LANCESANDRAEEPC | Source = Dhcp | ID = 1002
Description = The IP address lease 192.168.1.107 for the Network Card with network
address 0025D348DBA2 has been denied by the DHCP server 0.0.0.0 (The DHCP Server
sent a DHCPNACK message).

Error - 1/22/2010 10:21:11 PM | Computer Name = LANCESANDRAEEPC | Source = BROWSER | ID = 8032
Description = The browser service has failed to retrieve the backup list too many
times on transport \Device\NetBT_Tcpip_{D2FBFFBC-149B-431F-99B9-5D7060491268}. The
backup browser is stopping.


< End of report >
I see that you have run ComboFix on your computer. I'd like to take a look at that log.

Locating ComboFix Log
  • Right click on START on the left end of your Windows toolbar (lower left corner of your screen)
  • Click on Explore
  • Click on Local Disk (C:) in the left-hand window pane
  • Look for ComboFix.txt in the right-hand window pane and right click on it
  • Put your cursor (arrow) on Open With
  • Move your cursor to the new menu that opens and click on Choose Program…
  • Click on Notepad

When file opens, Copy/Paste text here.
Yes I did, forgot that. Here is the log. looking at it myself now it seems to have found and corrected some things. I have tested my connection and I can now access sites that I was not able to before. I think I might be fixed now unless you see something strange?

ComboFix 10-03-07.02 - Lancesandra 03/07/2010 16:16:35.1.2 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.1015.442 [GMT -6:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
AV: AVG Anti-Virus Free *On-access scanning disabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\recycler\S-1-5-21-783013601-2911902795-2016744192-1003
c:\windows\system32\Thumbs.db

.
original MBR restored successfully !
.
((((((((((((((((((((((((( Files Created from 2010-02-07 to 2010-03-07 )))))))))))))))))))))))))))))))
.

2010-03-07 17:25 . 2010-03-07 17:25 ——– d—–w- c:\program files\ERUNT
2010-03-07 16:58 . 2010-03-07 16:58 ——– d—–w- c:\program files\Trend Micro
2010-03-07 16:28 . 2010-01-07 22:07 38224 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-03-07 16:28 . 2010-01-07 22:07 19160 —-a-w- c:\windows\system32\drivers\mbam.sys
2010-03-07 16:28 . 2010-03-07 16:28 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2010-03-07 15:41 . 2010-02-23 20:04 1664256 —-a-w- c:\documents and settings\All Users\Application Data\AVG Security Toolbar\IEToolbar.dll
2010-03-06 23:38 . 2010-03-06 23:38 ——– d—–w- C:\$AVG
2010-03-04 04:42 . 2009-10-30 21:20 ——– d-sh–w- c:\documents and settings\HelpAssistant\IETldCache
2010-03-04 04:42 . 2010-03-06 23:12 ——– d—–w- c:\documents and settings\HelpAssistant
2010-03-03 23:53 . 2010-03-03 23:53 ——– d—–w- c:\documents and settings\Lancesandra\Application Data\Windows Search
2010-03-01 02:37 . 2010-03-03 23:59 ——– d—–w- c:\program files\Spybot - Search & Destroy
2010-03-01 02:37 . 2010-03-01 02:54 ——– d—–w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2010-03-01 02:05 . 2010-03-01 02:05 ——– d—–w- c:\documents and settings\Lancesandra\Application Data\Malwarebytes
2010-03-01 02:05 . 2010-03-01 02:05 ——– d—–w- c:\documents and settings\All Users\Application Data\Malwarebytes
2010-02-26 13:01 . 2010-02-26 13:02 ——– d—–w- c:\program files\CCleaner
2010-02-26 02:27 . 2010-02-26 02:27 0 —-a-w- c:\windows\nsreg.dat
2010-02-26 02:26 . 2010-02-26 02:26 ——– d—–w- c:\documents and settings\Lancesandra\Local Settings\Application Data\Mozilla
2010-02-22 05:27 . 2010-02-22 05:27 197760 —-a-w- c:\documents and settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
2010-02-21 22:17 . 2007-10-23 15:27 110592 —-a-w- c:\documents and settings\Lancesandra\Application Data\U3\temp\cleanup.exe
2010-02-21 22:10 . 2007-10-23 15:22 3350528 —ha-w- c:\documents and settings\Lancesandra\Application Data\U3\temp\Launchpad Removal.exe
2010-02-21 22:09 . 2010-02-21 22:17 ——– d—–w- c:\documents and settings\Lancesandra\Application Data\U3
2010-02-21 21:43 . 2010-02-21 21:43 ——– d—–w- c:\documents and settings\LocalService\Local Settings\Application Data\IsolatedStorage
2010-02-21 21:43 . 2010-02-21 21:43 ——– d—–w- c:\documents and settings\Lancesandra\Local Settings\Application Data\Intuit
2010-02-21 21:37 . 2010-02-21 21:37 ——– d—–w- c:\documents and settings\Lancesandra\Application Data\Intuit
2010-02-21 21:37 . 2010-02-21 21:37 ——– d—–w- c:\program files\Common Files\AnswerWorks 5.0
2010-02-21 21:31 . 2010-02-21 21:31 ——– d—–w- c:\documents and settings\Lancesandra\Local Settings\Application Data\IsolatedStorage
2010-02-21 21:31 . 2010-02-21 21:36 ——– d—–w- c:\program files\Common Files\Intuit
2010-02-21 21:30 . 2010-02-21 21:30 ——– d—–w- c:\program files\TurboTax
2010-02-21 21:29 . 2010-02-21 21:32 ——– d—–w- c:\documents and settings\All Users\Application Data\Intuit
2010-02-11 01:25 . 2010-02-11 01:25 ——– d—–w- c:\program files\Common Files\Remote Control USB Driver
2010-02-09 00:09 . 2010-02-09 00:09 ——– d—–w- c:\documents and settings\Lancesandra\Local Settings\Application Data\assembly
2010-02-05 22:41 . 2010-02-05 22:41 ——– d—–w- c:\program files\Common Files\Research In Motion
2010-02-05 22:41 . 2010-02-05 22:41 ——– d—–w- c:\program files\AT&T

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-03-07 15:50 . 2010-03-06 23:12 ——– d—–w- c:\documents and settings\All Users\Application Data\AVG Security Toolbar
2010-03-06 23:12 . 2010-03-06 23:12 242696 —-a-w- c:\windows\system32\drivers\avgtdix.sys
2010-03-06 23:12 . 2010-03-06 23:12 12464 —-a-w- c:\windows\system32\avgrsstx.dll
2010-03-06 23:12 . 2010-03-06 23:12 216200 —-a-w- c:\windows\system32\drivers\avgldx86.sys
2010-03-06 23:12 . 2010-03-06 23:12 29512 —-a-w- c:\windows\system32\drivers\avgmfx86.sys
2010-03-06 23:11 . 2010-03-06 23:11 ——– d—–w- c:\program files\AVG
2010-03-06 23:11 . 2010-03-06 23:11 ——– d—–w- c:\documents and settings\All Users\Application Data\avg9
2010-03-06 13:25 . 2009-10-31 00:08 ——– d—–w- c:\documents and settings\All Users\Application Data\McAfee
2010-02-26 21:46 . 2010-02-26 21:46 ——– d—–w- c:\documents and settings\Administrator\Application Data\Windows Search
2010-02-21 21:43 . 2009-10-31 04:58 94888 —-a-w- c:\documents and settings\Lancesandra\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2010-02-11 01:25 . 2009-05-05 16:00 ——– d–h–w- c:\program files\InstallShield Installation Information
2010-02-10 09:02 . 2009-05-05 16:43 ——– d—–w- c:\documents and settings\All Users\Application Data\Microsoft Help
2010-02-05 22:33 . 2009-11-18 17:34 ——– d—–w- c:\program files\Sierra Wireless Inc
2010-02-03 23:52 . 2010-02-03 23:52 ——– d—–w- c:\documents and settings\All Users\Application Data\AT&T
2010-01-02 23:37 . 2010-01-02 23:37 0 —-a-w- c:\documents and settings\Lancesandra\Application Data\wklnhst.dat
2009-12-31 16:50 . 2009-04-28 04:51 353792 —-a-w- c:\windows\system32\drivers\srv.sys
2009-12-21 19:14 . 2009-04-28 04:51 916480 —-a-w- c:\windows\system32\wininet.dll
2009-12-16 18:43 . 2009-04-28 05:01 343040 —-a-w- c:\windows\system32\mspaint.exe
2009-12-14 07:08 . 2009-04-28 04:51 33280 —-a-w- c:\windows\system32\csrsrv.dll
2009-12-08 19:26 . 2008-04-14 00:54 2145280 —-a-w- c:\windows\system32\ntoskrnl.exe
2009-12-08 18:43 . 2008-04-14 00:01 2023936 —-a-w- c:\windows\system32\ntkrnlpa.exe
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{A3BC75A2-1F87-4686-AA43-5347D756017C}"= "c:\program files\AVG\AVG9\Toolbar\IEToolbar.dll" [2010-02-23 1664256]

[HKEY_CLASSES_ROOT\clsid\{a3bc75a2-1f87-4686-aa43-5347d756017c}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A3BC75A2-1F87-4686-AA43-5347D756017C}]
2010-02-23 20:04 1664256 —-a-w- c:\program files\AVG\AVG9\Toolbar\IEToolbar.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{DA3D342F-FF20-4E31-9E82-22334155730C}]
2009-06-02 14:51 2695168 —-a-w- c:\program files\Antbar\Ant.com Toolbar\tbcore3.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{6CD56C02-CB4D-41B5-A0FE-B479061CCB41}"= "c:\program files\Antbar\Ant.com Toolbar\tbcore3.dll" [2009-06-02 2695168]
"{CCC7A320-B3CA-4199-B1A6-9F516DD69829}"= "c:\program files\AVG\AVG9\Toolbar\IEToolbar.dll" [2010-02-23 1664256]

[HKEY_CLASSES_ROOT\clsid\{6cd56c02-cb4d-41b5-a0fe-b479061ccb41}]
[HKEY_CLASSES_ROOT\TBSB00982.TBSB00982.3]
[HKEY_CLASSES_ROOT\TypeLib\{EC4085F2-8DB3-45a6-AD0B-CA289F3C5D7E}]
[HKEY_CLASSES_ROOT\TBSB00982.TBSB00982]

[HKEY_CLASSES_ROOT\clsid\{ccc7a320-b3ca-4199-b1a6-9f516dd69829}]

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{6CD56C02-CB4D-41B5-A0FE-B479061CCB41}"= "c:\program files\Antbar\Ant.com Toolbar\tbcore3.dll" [2009-06-02 2695168]
"{CCC7A320-B3CA-4199-B1A6-9F516DD69829}"= "c:\program files\AVG\AVG9\Toolbar\IEToolbar.dll" [2010-02-23 1664256]

[HKEY_CLASSES_ROOT\clsid\{6cd56c02-cb4d-41b5-a0fe-b479061ccb41}]
[HKEY_CLASSES_ROOT\TBSB00982.TBSB00982.3]
[HKEY_CLASSES_ROOT\TypeLib\{EC4085F2-8DB3-45a6-AD0B-CA289F3C5D7E}]
[HKEY_CLASSES_ROOT\TBSB00982.TBSB00982]

[HKEY_CLASSES_ROOT\clsid\{ccc7a320-b3ca-4199-b1a6-9f516dd69829}]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2007-12-19 135168]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2007-12-19 159744]
"Persistence"="c:\windows\system32\igfxpers.exe" [2007-12-19 131072]
"AsusACPIServer"="c:\program files\EeePC\ACPI\AsAcpiSvr.exe" [2009-04-16 630784]
"AsusEPCMonitor"="c:\program files\EeePC\ACPI\AsEPCMon.exe" [2009-03-13 98304]
"AsusTray"="c:\program files\EeePC\ACPI\AsTray.exe" [2009-04-16 118784]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2009-03-06 1434920]
"SynAsusAcpi"="c:\program files\Synaptics\SynTP\SynAsusAcpi.exe" [2009-03-06 79144]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2008-10-25 31072]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-10-15 39792]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
SuperHybridEngine.lnk - c:\program files\ASUS\EeePC\Super Hybrid Engine\SuperHybridEngine.exe [2009-5-5 376832]
Windows Search.lnk - c:\program files\Windows Desktop Search\WindowsSearch.exe [2008-5-26 123904]

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"= "c:\program files\Windows Desktop Search\MSNLNamespaceMgr.dll" [2009-05-25 304128]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2010-03-06 23:12 12464 —-a-w- c:\windows\system32\avgrsstx.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Logitech Desktop Messenger.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Logitech Desktop Messenger.lnk
backup=c:\windows\pss\Logitech Desktop Messenger.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
2008-10-15 07:04 39792 —-a-w- c:\program files\Adobe\Reader 8.0\Reader\reader_sl.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AT&T Communication Manager]
2009-10-09 23:58 883272 —-a-w- c:\program files\AT&T\Communication Manager\ATTCM.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IMJPMIG8.1]
2008-04-14 12:00 208952 —-a-w- c:\windows\ime\imjp8_1\imjpmig.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MsnMsgr]
2009-02-06 22:51 3885408 —-a-w- c:\program files\Windows Live\Messenger\msnmsgr.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSPY2002]
2008-04-14 12:00 59392 —-a-w- c:\windows\system32\IME\PINTLGNT\IMSCINST.EXE

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PHIME2002A]
2008-04-14 12:00 455168 —-a-w- c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PHIME2002ASync]
2008-04-14 12:00 455168 —-a-w- c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RTHDCPL]
2009-04-27 21:08 17881088 —-a-w- c:\windows\RTHDCPL.EXE

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Sync\\WindowsLiveSync.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"c:\\Program Files\\AVG\\AVG9\\avgupd.exe"=
"c:\\Program Files\\AVG\\AVG9\\avgnsx.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"65533:TCP"= 65533:TCP:Services
"52344:TCP"= 52344:TCP:Services
"2479:TCP"= 2479:TCP:Services
"9438:TCP"= 9438:TCP:Services
"3389:TCP"= 3389:TCP:Remote Desktop

R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [3/6/2010 5:12 PM 216200]
R1 AvgTdiX;AVG Free Network Redirector;c:\windows\system32\drivers\avgtdix.sys [3/6/2010 5:12 PM 242696]
R2 avg9wd;AVG Free WatchDog;c:\program files\AVG\AVG9\avgwdsvc.exe [3/6/2010 5:11 PM 308064]
R2 fssfltr;FssFltr;c:\windows\system32\drivers\fssfltr_tdi.sys [5/5/2009 10:39 AM 55152]
R3 L1c;NDIS Miniport Driver for Atheros AR8131/AR8132 PCI-E Ethernet Controller;c:\windows\system32\drivers\l1c51x86.sys [4/27/2009 7:59 PM 38912]
S3 Ambfilt;Ambfilt;c:\windows\system32\drivers\Ambfilt.sys [5/5/2009 10:00 AM 1684736]
S3 ATTRcAppSvc;AT&T RcAppSvc;c:\program files\AT&T\Communication Manager\RcAppSvc.exe [10/9/2009 5:59 PM 121416]
S3 AVG Security Toolbar Service;AVG Security Toolbar Service;c:\program files\AVG\AVG9\Toolbar\ToolbarBroker.exe [3/6/2010 5:12 PM 369920]
S3 fsssvc;Windows Live Family Safety;c:\program files\Windows Live\Family Safety\fsssvc.exe [2/6/2009 4:08 PM 533360]
S3 SRS_PremiumSound_Service;SRS Labs Premium Sound;c:\windows\system32\drivers\SRS_PremiumSound_i386.sys [5/5/2009 11:16 AM 232872]
S3 SWNC8UA3;Sierra Wireless MUX NDIS Driver (UMTSA3);c:\windows\system32\drivers\swnc8ua3.sys [3/31/2009 2:45 PM 190080]
S3 SWUMXA3;Sierra Wireless USB MUX Driver (UMTSA3);c:\windows\system32\drivers\swumxa3.sys [5/4/2009 3:57 PM 148096]
S3 uvclf;uvclf;c:\windows\system32\drivers\uvclf.sys [3/16/2009 3:27 PM 39040]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt REG_MULTI_SZ hpqcxs08
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://my.yahoo.com/
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~3\Office12\EXCEL.EXE/3000
IE: Send to &Bluetooth Device… - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
IE: Send To Bluetooth - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
LSP: bmnet.dll
Trusted Zone: intuit.com\ttlc
Handler: avgsecuritytoolbar - {F2DDE6B2-9684-4A55-86D4-E255E237B77C} - c:\program files\AVG\AVG9\Toolbar\IEToolbar.dll
FF - ProfilePath - c:\documents and settings\Lancesandra\Application Data\Mozilla\Firefox\Profiles\we7cl42s.default\
FF - plugin: c:\program files\Windows Live\Photo Gallery\NPWLPG.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\

—- FIREFOX POLICIES —-
FF - user.js: yahoo.homepage.dontask - truec:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_colors", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_popup_windows", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.enable_click_image_resizing", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("accessibility.browsewithcaret_shortcut.enabled", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("javascript.options.mem.high_water_mark", 32);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("javascript.options.mem.gc_frequency", 1600);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("svg.smil.enabled", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.trackpoint_hack.enabled", -1);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.debug", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.agedWeight", 2);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.bucketSize", 1);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.maxTimeGroupings", 25);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.timeGroupingSize", 604800);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.boundaryWeight", 25);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.prefixWeight", 5);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("html5.enable", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("app.update.download.backgroundInterval", 600);
c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("app.update.url.manual", "http://www.firefox.com");
c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-ja", "mozff");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add", "addons.mozilla.org");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add.36", "getpersonas.com");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("lightweightThemes.update.enabled", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.allTabs.previews", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.hide_infobar_for_outdated_plugin", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("toolbar.customization.usesheet", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.enable", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.max", 20);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.cachetime", 20);
.
- - - - ORPHANS REMOVED - - - -

SafeBoot-mcmscsvc
SafeBoot-MCODS
MSConfigStartUp-TOY5KNQ8OC - c:\docume~1\LANCES~1\LOCALS~1\Temp\Skq.exe



**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-03-07 16:21
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************

Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer, http://www.gmer.net

device: opened successfully
user: MBR read successfully
called modules: ntkrnlpa.exe catchme.sys CLASSPNP.SYS disk.sys >>UNKNOWN [0x858F5D70]<<
kernel: MBR read successfully
detected MBR rootkit hooks:
\Driver\Disk -> CLASSPNP.SYS @ 0xf75ccf28
\Driver\ACPI -> 0x858f5d70
\Driver\atapi -> atapi.sys @ 0xf7417852
\Driver\iaStor -> iaStor.sys @ 0xf7374e74
IoDeviceObjectType -> DeleteProcedure -> ntkrnlpa.exe @ 0x805836a8
ParseProcedure -> ntkrnlpa.exe @ 0x805827e8
\Device\Harddisk0\DR0 -> DeleteProcedure -> ntkrnlpa.exe @ 0x805836a8
ParseProcedure -> ntkrnlpa.exe @ 0x805827e8
NDIS: Atheros AR8132 PCI-E Fast Ethernet Controller -> SendCompleteHandler -> NDIS.sys @ 0xf725bbb0
PacketIndicateHandler -> NDIS.sys @ 0xf724aa0d
SendHandler -> NDIS.sys @ 0xf725eb40
Warning: possible MBR rootkit infection !
copy of MBR has been found in sector 0x012A18AC1
malicious code @ sector 0x012A18AC4 !
PE file found in sector at 0x012A18ADA !
MBR rootkit infection detected ! Use: "mbr.exe -f" to fix.

**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'lsass.exe'(800)
c:\windows\system32\bmnet.dll
.
Completion time: 2010-03-07 16:23:03
ComboFix-quarantined-files.txt 2010-03-07 22:23

Pre-Run: 61,674,840,064 bytes free
Post-Run: 61,641,506,816 bytes free

WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Home Edition" /noexecute=optin /fastdetect

- - End Of File - - 2E400657E14C73DDAF337603AB4B8C0B
Hello lancesandra,

We still have some work to do. Your infected with a fairly new infection. This infection isn't easy to clean and will often require you to perform a number of scans with a variety of different tools, and at times will ask that you repeat the steps several times.

This infection can be cleaned, and if you stick with me through it, it can be cleaned.


____________________________________________________

IMPORTANT NOTE: Please make sure you read the following set of instructions very carefully.

OTL Fix
Run OTL.exe
  • Copy/paste the following text written inside of the code box into the Custom Scans/Fixes box located at the bottom of OTL

    :Services
    :OTL
    PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
    [2010/03/07 11:39:03 | 000,293,376 | —- | M] () – C:\Documents and Settings\Lancesandra\My Documents\547bc5r1.exe
    :Reg
    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List] 
    "65533:TCP" =-
    "52344:TCP" =-
    "2479:TCP" =-
    "9438:TCP" =-
    "3389:TCP" =-
    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List] 
    "65533:TCP" =-
    "52344:TCP" =-
    "2479:TCP" =-
    "9438:TCP" =-
    "3389:TCP" =-
    :Commands
    [emptytemp]
    [start explorer]
    [Reboot]
  • Then click the Run Fix button at the top
  • Let the program run unhindered, reboot when it is done

NEXT:


Download and save HelpAsst_mebroot_fix.exe
Double click to run the tool.

When the tool completes,

click on Start > Run > type the following bolded command c:\mbr.exe -f then press OK

Once you've entered the above command you should see that a black box flashes on your screen for a few seconds and then should disappear shortly after appearing.

After the black box has disappeared please go ahead and reboot your computer.

After reboot, provide a fresh OTL log

Then a new mbr log
by going to Start > Run > type the following bolded command c:\mbr.exe -t then press OK

(the mbr log can be found wherever you saved the MBR.exe program to. In your case I asked you to save it to your root drive (C:)).


NEXT:


Please make sure you include the following items in your next post:

1. Any comments or questions you may have that you'd like for me to answer in my next post to you.
2. The log that was produced after running the OTL Fix.
3. The log that was produced after running a new OTL scan.
4. The log that was produced after running the MBR scan.
5. An update on how your computer is currently running.

It would be helpful if you could answer each question in the order asked, as well as numbering your answers.
Thank you, I did the OTL fix it ran and rebooted. I ran the helpasst tool. I tried the c:\mbr.exe -f but it says it can not find the file? Here is the log that came up after the reboot. All processes killed ========== SERVICES/DRIVERS ========== ========== OTL ========== No active process named explorer.exe was found! C:\Documents and Settings\Lancesandra\My Documents\547bc5r1.exe moved successfully. ========== REGISTRY ========== Registry value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List\\65533:TCP deleted successfully. Registry value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List\\52344:TCP deleted successfully. Registry value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List\\2479:TCP deleted successfully. Registry value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List\\9438:TCP deleted successfully. Registry value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List\\3389:TCP deleted successfully. Registry value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List\\65533:TCP deleted successfully. Registry value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List\\52344:TCP deleted successfully. Registry value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List\\2479:TCP deleted successfully. Registry value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List\\9438:TCP deleted successfully. Registry value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List\\3389:TCP deleted successfully. ========== COMMANDS ========== [EMPTYTEMP] User: Administrator ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 67 bytes User: All Users User: Default User ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 67 bytes User: HelpAssistant ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 67 bytes ->FireFox cache emptied: 389968 bytes ->Flash cache emptied: 4954 bytes User: Lancesandra ->Temp folder emptied: 53608 bytes ->Temporary Internet Files folder emptied: 11384333 bytes ->FireFox cache emptied: 9859121 bytes ->Flash cache emptied: 4954 bytes User: LocalService ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 32902 bytes User: NetworkService ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 67 bytes %systemdrive% .tmp files removed: 0 bytes %systemroot% .tmp files removed: 0 bytes %systemroot%\System32 .tmp files removed: 2577 bytes %systemroot%\System32\dllcache .tmp files removed: 0 bytes %systemroot%\System32\drivers .tmp files removed: 0 bytes Windows Temp folder emptied: 0 bytes %systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 0 bytes %systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 33170 bytes RecycleBin emptied: 0 bytes Total Files Cleaned = 21.00 mb OTL by OldTimer - Version 3.1.34.0 log created on 03072010_181304 Files\Folders moved on Reboot… C:\Documents and Settings\Lancesandra\Local Settings\Temporary Internet Files\Content.IE5\9JMI19LT\iframe[2].htm moved successfully. C:\Documents and Settings\Lancesandra\Local Settings\Temporary Internet Files\Content.IE5\9JMI19LT\Virus_updates_blocked_t110773[1].html moved successfully. Registry entries deleted on Reboot…
Please download mbr.exe and save it to your root directory, usually C:\ <- (Important!).

Click on Start > Run > type the following bolded command c:\mbr.exe -f then press OK

Once you've entered the above command you should see that a black box flashes on your screen for a few seconds and then should disappear shortly after appearing.

After the black box has disappeared please go ahead and reboot your computer.

After reboot, provide a fresh OTL log

Then a new mbr log
by going to Start > Run > type the following bolded command c:\mbr.exe -t then press OK

(the mbr log can be found wherever you saved the MBR.exe program to. In your case I asked you to save it to your root drive (C:)).

Make sure you include the log that was produced after running mbr, as well as a new OTL log.
Thanks again and here are the file logs:

I ran OTL again with the extra but it did not make a log file for that this time??

Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer, http://www.gmer.net

device: opened successfully
user: MBR read successfully
called modules: ntkrnlpa.exe CLASSPNP.SYS disk.sys ACPI.sys hal.dll iaStor.sys
kernel: MBR read successfully
user & kernel MBR OK
copy of MBR has been found in sector 0x012A18AC1
malicious code @ sector 0x012A18AC4 !
PE file found in sector at 0x012A18ADA !


OTL logfile created on: 3/7/2010 6:39:08 PM - Run 2
OTL by OldTimer - Version 3.1.34.0 Folder = C:\Documents and Settings\Lancesandra\Desktop
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

1,015.00 Mb Total Physical Memory | 591.00 Mb Available Physical Memory | 58.00% Memory free
2.00 Gb Paging File | 2.00 Gb Available in Paging File | 85.00% Paging File free
Paging file location(s): C:\pagefile.sys 1524 3048 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 72.06 Gb Total Space | 57.43 Gb Free Space | 79.70% Space Free | Partition Type: NTFS
Drive D: | 72.05 Gb Total Space | 71.94 Gb Free Space | 99.85% Space Free | Partition Type: NTFS
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: LANCESANDRAEEPC
Current User Name: Lancesandra
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal

========== Processes (SafeList) ==========

PRC - C:\Documents and Settings\Lancesandra\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\AVG\AVG9\avgchsvx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG9\avgcsrvx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG9\avgnsx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG9\avgrsx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG9\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\Common Files\Intuit\Update Service\IntuitUpdateService.exe (Intuit Inc.)
PRC - C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe (Microsoft Corporation)
PRC - C:\Program Files\EeePC\ACPI\AsAcpiSvr.exe (ASUSTeK Computer Inc.)
PRC - C:\Program Files\EeePC\ACPI\AsTray.exe (ASUSTeK Computer Inc.)
PRC - C:\Program Files\ASUS\EeePC\Super Hybrid Engine\SuperHybridEngine.exe (ASUSTeK Computer Inc.)
PRC - C:\Program Files\EeePC\ACPI\AsEPCMon.exe (ASUSTeK Computer Inc.)
PRC - C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe (Adobe Systems Incorporated)
PRC - C:\Program Files\Windows Desktop Search\WindowsSearch.exe (Microsoft Corporation)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\WINDOWS\system32\igfxext.exe (Intel Corporation)


========== Modules (SafeList) ==========

MOD - C:\Documents and Settings\Lancesandra\Desktop\OTL.exe (OldTimer Tools)


========== Win32 Services (SafeList) ==========

SRV - (avg9wd) – C:\Program Files\AVG\AVG9\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
SRV - (AVG Security Toolbar Service) – C:\Program Files\AVG\AVG9\Toolbar\ToolbarBroker.exe ()
SRV - (ATTRcAppSvc) – C:\Program Files\AT&T\Communication Manager\RcAppSvc.exe (SmithMicro Inc.)
SRV - (IntuitUpdateService) – C:\Program Files\Common Files\Intuit\Update Service\IntuitUpdateService.exe (Intuit Inc.)
SRV - (SeaPort) – C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe (Microsoft Corporation)
SRV - (fsssvc) – C:\Program Files\Windows Live\Family Safety\fsssvc.exe (Microsoft Corporation)


========== Driver Services (SafeList) ==========

DRV - (AvgTdiX) – C:\WINDOWS\system32\drivers\avgtdix.sys (AVG Technologies CZ, s.r.o.)
DRV - (AvgLdx86) – C:\WINDOWS\system32\drivers\avgldx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (AvgMfx86) – C:\WINDOWS\system32\drivers\avgmfx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (tcpipBM) – C:\WINDOWS\system32\drivers\tcpipBM.sys (Bytemobile, Inc.)
DRV - (PCTINDIS5) – C:\WINDOWS\system32\PCTINDIS5.sys (Smith Micro Inc.)
DRV - (mfehidk) – C:\WINDOWS\system32\drivers\mfehidk.sys (McAfee, Inc.)
DRV - (mfeavfk) – C:\WINDOWS\system32\drivers\mfeavfk.sys (McAfee, Inc.)
DRV - (mfesmfk) – C:\WINDOWS\system32\drivers\mfesmfk.sys (McAfee, Inc.)
DRV - (mfebopk) – C:\WINDOWS\system32\drivers\mfebopk.sys (McAfee, Inc.)
DRV - (mferkdk) – C:\WINDOWS\system32\drivers\mferkdk.sys (McAfee, Inc.)
DRV - (SWUMXA3) Sierra Wireless USB MUX Driver (UMTSA3) – C:\WINDOWS\system32\drivers\swumxa3.sys (Sierra Wireless Inc.)
DRV - (IntcAzAudAddService) Service for Realtek HD Audio (WDM) – C:\WINDOWS\system32\drivers\RtkHDAud.sys (Realtek Semiconductor Corp.)
DRV - (SRS_PremiumSound_Service) – C:\WINDOWS\system32\drivers\SRS_PremiumSound_i386.sys ()
DRV - (SWNC8UA3) Sierra Wireless MUX NDIS Driver (UMTSA3) – C:\WINDOWS\system32\drivers\swnc8ua3.sys (Sierra Wireless Inc.)
DRV - (AR5416) – C:\WINDOWS\system32\drivers\athw.sys (Atheros Communications, Inc.)
DRV - (SynTP) – C:\WINDOWS\system32\drivers\SynTP.sys (Synaptics Incorporated)
DRV - (L1c) – C:\WINDOWS\system32\drivers\l1c51x86.sys (Atheros Communications, Inc.)
DRV - (fssfltr) – C:\WINDOWS\system32\drivers\fssfltr_tdi.sys (Microsoft Corporation)
DRV - (uvclf) – C:\WINDOWS\system32\drivers\uvclf.sys (GenesysLogic Technologies, Inc.)
DRV - (iaStor) – C:\WINDOWS\system32\drivers\iaStor.sys (Intel Corporation)
DRV - (swmsflt) – C:\WINDOWS\System32\drivers\swmsflt.sys ()
DRV - (Ambfilt) – C:\WINDOWS\system32\drivers\Ambfilt.sys (Creative)
DRV - (HDAudBus) – C:\WINDOWS\system32\drivers\hdaudbus.sys (Windows ® Server 2003 DDK provider)
DRV - (AsusACPI) – C:\WINDOWS\system32\drivers\ASUSACPI.SYS (ASUSTeK Computer Inc.)
DRV - (ialm) – C:\WINDOWS\system32\drivers\igxpmp32.sys (Intel Corporation)
DRV - (Monfilt) – C:\WINDOWS\system32\drivers\Monfilt.sys (Creative Technology Ltd.)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========


IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://my.yahoo.com/
IE - HKCU\..\URLSearchHook: {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dll ()
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..extensions.enabledItems: {B7082FAA-CB62-4872-9106-E42DD88EDE45}:3.0
FF - prefs.js..extensions.enabledItems: {635abd67-4fe9-1b23-4f01-e679fa7484c1}:1.5.4.20081105


FF - HKLM\software\mozilla\Firefox\Extensions\\{3f963a5b-e555-4543-90e2-c3908898db71}: C:\Program Files\AVG\AVG9\Firefox [2010/03/06 17:11:49 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\avg@igeared: C:\Program Files\AVG\AVG9\Toolbar\Firefox\avg@igeared [2010/03/06 17:12:03 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010/02/25 20:26:58 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010/02/25 20:26:30 | 000,000,000 | —D | M]

[2010/02/25 20:27:29 | 000,000,000 | —D | M] – C:\Documents and Settings\Lancesandra\Application Data\Mozilla\Extensions
[2010/02/28 19:30:04 | 000,000,000 | —D | M] – C:\Documents and Settings\Lancesandra\Application Data\Mozilla\Firefox\Profiles\we7cl42s.default\extensions
[2010/02/26 06:59:18 | 000,000,000 | —D | M] (Microsoft .NET Framework Assistant) – C:\Documents and Settings\Lancesandra\Application Data\Mozilla\Firefox\Profiles\we7cl42s.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2010/02/26 07:02:22 | 000,000,000 | —D | M] (Yahoo! Toolbar) – C:\Documents and Settings\Lancesandra\Application Data\Mozilla\Firefox\Profiles\we7cl42s.default\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1}
[2010/02/25 20:26:31 | 000,000,000 | —D | M] – C:\Program Files\Mozilla Firefox\extensions

O1 HOSTS File: ([2008/04/14 06:00:00 | 000,000,734 | —- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (Skype add-on (mastermind)) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Skype Technologies S.A.)
O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG9\avgssie.dll (AVG Technologies CZ, s.r.o.)
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O2 - BHO: (Search Helper) - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll (Microsoft Corporation)
O2 - BHO: (Groove GFS Browser Helper) - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation)
O2 - BHO: (AVG Security Toolbar BHO) - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dll ()
O2 - BHO: (TBSB00982 Class) - {DA3D342F-FF20-4E31-9E82-22334155730C} - C:\Program Files\Antbar\Ant.com Toolbar\tbcore3.dll ()
O2 - BHO: (Windows Live Toolbar Helper) - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files\Windows Live\Toolbar\wltcore.dll (Microsoft Corporation)
O3 - HKLM\..\Toolbar: (&Windows Live Toolbar) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll (Microsoft Corporation)
O3 - HKLM\..\Toolbar: (Ant.com Toolbar) - {6CD56C02-CB4D-41B5-A0FE-B479061CCB41} - C:\Program Files\Antbar\Ant.com Toolbar\tbcore3.dll ()
O3 - HKLM\..\Toolbar: (AVG Security Toolbar) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - C:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dll ()
O3 - HKCU\..\Toolbar\WebBrowser: (&Windows Live Toolbar) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll (Microsoft Corporation)
O3 - HKCU\..\Toolbar\WebBrowser: (Ant.com Toolbar) - {6CD56C02-CB4D-41B5-A0FE-B479061CCB41} - C:\Program Files\Antbar\Ant.com Toolbar\tbcore3.dll ()
O3 - HKCU\..\Toolbar\WebBrowser: (AVG Security Toolbar) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - C:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dll ()
O4 - HKLM..\Run: [Adobe Reader Speed Launcher] C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [AsusACPIServer] C:\Program Files\EeePC\ACPI\AsAcpiSvr.exe (ASUSTeK Computer Inc.)
O4 - HKLM..\Run: [AsusEPCMonitor] C:\Program Files\EeePC\ACPI\AsEPCMon.exe (ASUSTeK Computer Inc.)
O4 - HKLM..\Run: [AsusTray] C:\Program Files\EeePC\ACPI\AsTray.exe (ASUSTeK Computer Inc.)
O4 - HKLM..\Run: [SynAsusAcpi] C:\Program Files\Synaptics\SynTP\SynAsusAcpi.exe (Synaptics Incorporated)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\ SuperHybridEngine.lnk = C:\Program Files\ASUS\EeePC\Super Hybrid Engine\SuperHybridEngine.exe (ASUSTeK Computer Inc.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Windows Search.lnk = C:\Program Files\Windows Desktop Search\WindowsSearch.exe (Microsoft Corporation)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O8 - Extra context menu item: E&xport to Microsoft Excel - C:\Program Files\Microsoft Office\Office12\EXCEL.EXE (Microsoft Corporation)
O9 - Extra Button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : &Blog This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation)
O9 - Extra Button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Skype Technologies S.A.)
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Program Files\Microsoft Office\Office12\REFIEBAR.DLL (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - File not found
O15 - HKCU\..Trusted Domains: intuit.com ([ttlc] https in Trusted sites)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} http://www.update.microsoft.com/microsoftu…b?1256933014609 (MUWebControl Class)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab (Shockwave Flash Object)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.254
O18 - Protocol\Handler\avgsecuritytoolbar {F2DDE6B2-9684-4A55-86D4-E255E237B77C} - C:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dll ()
O18 - Protocol\Handler\grooveLocalGWS {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll (Microsoft Corporation)
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG9\avgpp.dll (AVG Technologies CZ, s.r.o.)
O18 - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\Windows Live\Messenger\msgrapp.14.0.8064.0206.dll (Microsoft Corporation)
O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll (Microsoft Corporation)
O18 - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\Windows Live\Messenger\msgrapp.14.0.8064.0206.dll (Microsoft Corporation)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Handler\wlmailhtml {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - C:\Program Files\Windows Live\Mail\mailcomm.dll (Microsoft Corporation)
O18 - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\Microsoft Shared\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\avgrsstarter: DllName - avgrsstx.dll - C:\WINDOWS\System32\avgrsstx.dll (AVG Technologies CZ, s.r.o.)
O20 - Winlogon\Notify\igfxcui: DllName - igfxdev.dll - C:\WINDOWS\System32\igfxdev.dll (Intel Corporation)
O24 - Desktop WallPaper: C:\Documents and Settings\Lancesandra\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Lancesandra\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O28 - HKLM ShellExecuteHooks: {56F9679E-7826-4C84-81F3-532071A8BCC5} - C:\Program Files\Windows Desktop Search\MsnlNamespaceMgr.dll (Microsoft Corporation)
O28 - HKLM ShellExecuteHooks: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009/04/27 23:03:59 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - comfile [open] – "%1" %*
O35 - exefile [open] – "%1" %*

NetSvcs: 6to4 - File not found
NetSvcs: Ias - C:\WINDOWS\system32\ias [2009/04/27 23:03:27 | 000,000,000 | —D | M]
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: Wmi - C:\WINDOWS\system32\wmi.dll (Microsoft Corporation)
NetSvcs: WmdmPmSp - File not found

CREATERESTOREPOINT
Restore point Set: OTL Restore Point (17173366603513856)

========== Files/Folders - Created Within 30 Days ==========

[2010/03/07 18:13:16 | 000,000,000 | -HSD | C] – C:\RECYCLER
[2010/03/07 18:13:04 | 000,000,000 | —D | C] – C:\_OTL
[2010/03/07 16:25:05 | 000,553,984 | —- | C] (OldTimer Tools) – C:\Documents and Settings\Lancesandra\Desktop\OTL.exe
[2010/03/07 16:23:06 | 000,000,000 | —D | C] – C:\WINDOWS\temp
[2010/03/07 16:15:21 | 000,000,000 | RHSD | C] – C:\cmdcons
[2010/03/07 16:14:16 | 000,212,480 | —- | C] (SteelWerX) – C:\WINDOWS\SWXCACLS.exe
[2010/03/07 16:14:16 | 000,161,792 | —- | C] (SteelWerX) – C:\WINDOWS\SWREG.exe
[2010/03/07 16:14:16 | 000,136,704 | —- | C] (SteelWerX) – C:\WINDOWS\SWSC.exe
[2010/03/07 16:14:16 | 000,031,232 | —- | C] (NirSoft) – C:\WINDOWS\NIRCMD.exe
[2010/03/07 16:14:05 | 000,000,000 | —D | C] – C:\ComboFix
[2010/03/07 16:13:37 | 000,000,000 | —D | C] – C:\Qoobox
[2010/03/07 11:26:06 | 000,000,000 | —D | C] – C:\WINDOWS\ERDNT
[2010/03/07 11:25:04 | 000,000,000 | —D | C] – C:\Program Files\ERUNT
[2010/03/07 11:24:11 | 000,791,393 | —- | C] (Lars Hederer ) – C:\Documents and Settings\Lancesandra\My Documents\erunt_setup.exe
[2010/03/07 11:22:25 | 000,021,504 | —- | C] (Doug Knox) – C:\Documents and Settings\Lancesandra\My Documents\SysRestorePoint.exe
[2010/03/07 11:17:02 | 000,050,688 | —- | C] (Atribune.org) – C:\Documents and Settings\Lancesandra\My Documents\ATF_Cleaner.exe
[2010/03/07 10:58:08 | 000,000,000 | —D | C] – C:\Program Files\Trend Micro
[2010/03/07 10:58:01 | 000,812,344 | —- | C] (Trend Micro Inc.) – C:\Documents and Settings\Lancesandra\My Documents\HJTInstall.exe
[2010/03/07 10:28:23 | 000,038,224 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2010/03/07 10:28:21 | 000,019,160 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys
[2010/03/07 10:28:20 | 000,000,000 | —D | C] – C:\Program Files\Malwarebytes' Anti-Malware
[2010/03/07 10:27:36 | 005,115,824 | —- | C] (Malwarebytes Corporation ) – C:\Documents and Settings\Lancesandra\My Documents\mbam-setup.exe
[2010/03/06 17:38:12 | 000,000,000 | —D | C] – C:\$AVG
[2010/03/06 17:12:20 | 000,242,696 | —- | C] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\drivers\avgtdix.sys
[2010/03/06 17:12:20 | 000,012,464 | —- | C] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\avgrsstx.dll
[2010/03/06 17:12:10 | 000,216,200 | —- | C] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\drivers\avgldx86.sys
[2010/03/06 17:12:09 | 000,029,512 | —- | C] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\drivers\avgmfx86.sys
[2010/03/06 17:12:04 | 000,000,000 | —D | C] – C:\WINDOWS\System32\drivers\Avg
[2010/03/06 17:12:03 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\AVG Security Toolbar
[2010/03/06 17:11:49 | 000,000,000 | —D | C] – C:\Program Files\AVG
[2010/03/06 17:11:48 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\avg9
[2010/03/06 17:10:50 | 000,000,000 | –SD | M] – C:\Documents and Settings\NetworkService\Application Data\Microsoft
[2010/03/06 17:10:50 | 000,000,000 | –SD | M] – C:\Documents and Settings\LocalService\Application Data\Microsoft
[2010/03/06 17:10:50 | 000,000,000 | —D | M] – C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft
[2010/03/06 17:10:50 | 000,000,000 | —D | M] – C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft
[2010/03/06 16:46:33 | 095,829,360 | —- | C] (AVG Technologies) – C:\Documents and Settings\Lancesandra\My Documents\avg_free_stf_all_90_787a2721.exe
[2010/03/06 07:28:36 | 000,055,656 | —- | C] (Avira GmbH) – C:\WINDOWS\System32\drivers\avgntflt.sys
[2010/03/06 07:18:34 | 009,758,152 | —- | C] (Microsoft Corporation) – C:\Documents and Settings\Lancesandra\My Documents\windows-kb890830-v3.4.exe
[2010/03/06 07:18:28 | 016,409,960 | —- | C] (Safer Networking Limited ) – C:\Documents and Settings\Lancesandra\My Documents\spybotsd162.exe
[2010/03/06 07:18:24 | 000,367,616 | —- | C] (Avira GmbH) – C:\Documents and Settings\Lancesandra\My Documents\removaltool-win32-en.exe
[2010/03/03 17:53:13 | 000,000,000 | —D | C] – C:\Documents and Settings\Lancesandra\Application Data\Windows Search
[2010/02/28 20:37:59 | 000,000,000 | —D | C] – C:\Program Files\Spybot - Search & Destroy
[2010/02/28 20:37:59 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
[2010/02/28 20:05:26 | 000,000,000 | —D | C] – C:\Documents and Settings\Lancesandra\Application Data\Malwarebytes
[2010/02/28 20:05:13 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Malwarebytes
[2010/02/26 07:35:37 | 000,000,000 | RH-D | C] – C:\Documents and Settings\Lancesandra\Recent
[2010/02/26 07:01:58 | 000,000,000 | —D | C] – C:\Program Files\CCleaner
[2010/02/26 06:54:24 | 000,000,000 | —D | C] – C:\WINDOWS\Minidump
[2010/02/25 20:47:08 | 015,083,520 | —- | C] (Safer Networking Limited ) – C:\Documents and Settings\Lancesandra\My Documents\spybotsd160.exe
[2010/02/25 20:31:17 | 000,000,000 | —D | C] – C:\Documents and Settings\Lancesandra\My Documents\Downloads
[2010/02/25 20:26:51 | 000,000,000 | —D | C] – C:\Documents and Settings\Lancesandra\Local Settings\Application Data\Mozilla
[2010/02/25 20:26:16 | 000,000,000 | —D | C] – C:\Program Files\Mozilla Firefox
[2010/02/21 16:09:58 | 000,000,000 | —D | C] – C:\Documents and Settings\Lancesandra\Application Data\U3
[2010/02/21 16:08:40 | 000,000,000 | —D | C] – C:\Documents and Settings\Lancesandra\My Documents\TurboTax
[2010/02/21 15:43:32 | 000,000,000 | —D | M] – C:\Documents and Settings\LocalService\Local Settings\Application Data\IsolatedStorage
[2010/02/21 15:43:28 | 000,000,000 | —D | C] – C:\Documents and Settings\Lancesandra\Local Settings\Application Data\Intuit
[2010/02/21 15:37:41 | 000,000,000 | —D | C] – C:\Documents and Settings\Lancesandra\Application Data\Intuit
[2010/02/21 15:37:32 | 000,000,000 | —D | C] – C:\Program Files\Common Files\AnswerWorks 5.0
[2010/02/21 15:31:08 | 000,000,000 | —D | C] – C:\Documents and Settings\Lancesandra\Local Settings\Application Data\IsolatedStorage
[2010/02/21 15:31:03 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Intuit
[2010/02/21 15:30:22 | 000,000,000 | —D | C] – C:\Program Files\TurboTax
[2010/02/21 15:29:46 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Intuit
[2010/02/10 19:28:23 | 000,000,000 | —D | C] – C:\Documents and Settings\Lancesandra\Application Data\Mozilla
[2010/02/10 19:25:02 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Remote Control USB Driver
[2010/02/08 18:09:06 | 000,000,000 | —D | C] – C:\Documents and Settings\Lancesandra\Local Settings\Application Data\assembly
[2009/12/07 15:22:35 | 000,000,000 | —D | M] – C:\Documents and Settings\LocalService\Local Settings\Application Data\Adobe
[2009/12/03 21:51:48 | 000,000,000 | —D | M] – C:\Documents and Settings\LocalService\Application Data\McAfee
[2009/11/18 11:57:09 | 000,000,000 | —D | M] – C:\Documents and Settings\NetworkService\Application Data\Bytemobile
[2009/10/30 18:39:49 | 000,000,000 | —D | M] – C:\Documents and Settings\LocalService\Application Data\SACore

========== Files - Modified Within 30 Days ==========

[2010/03/07 18:36:29 | 000,000,006 | -H– | M] () – C:\WINDOWS\tasks\SA.DAT
[2010/03/07 18:36:27 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2010/03/07 18:36:25 | 1064,554,496 | -HS- | M] () – C:\hiberfil.sys
[2010/03/07 18:35:37 | 004,456,448 | -H– | M] () – C:\Documents and Settings\Lancesandra\NTUSER.DAT
[2010/03/07 18:35:19 | 000,000,178 | -HS- | M] () – C:\Documents and Settings\Lancesandra\ntuser.ini
[2010/03/07 18:34:51 | 004,500,960 | -H– | M] () – C:\Documents and Settings\Lancesandra\Local Settings\Application Data\IconCache.db
[2010/03/07 18:32:35 | 000,077,312 | —- | M] () – C:\mbr.exe
[2010/03/07 18:19:18 | 000,412,056 | —- | M] () – C:\Documents and Settings\Lancesandra\Desktop\HelpAsst_mebroot_fix.exe
[2010/03/07 16:52:59 | 056,858,676 | —- | M] () – C:\WINDOWS\System32\drivers\Avg\incavi.avm
[2010/03/07 16:25:05 | 000,553,984 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Lancesandra\Desktop\OTL.exe
[2010/03/07 16:21:08 | 000,000,227 | —- | M] () – C:\WINDOWS\system.ini
[2010/03/07 16:15:25 | 000,000,281 | RHS- | M] () – C:\boot.ini
[2010/03/07 16:09:50 | 004,122,023 | R— | M] () – C:\Documents and Settings\Lancesandra\Desktop\ComboFix.exe
[2010/03/07 11:25:11 | 000,000,611 | —- | M] () – C:\Documents and Settings\Lancesandra\Desktop\NTREGOPT.lnk
[2010/03/07 11:25:11 | 000,000,592 | —- | M] () – C:\Documents and Settings\Lancesandra\Desktop\ERUNT.lnk
[2010/03/07 11:24:21 | 000,791,393 | —- | M] (Lars Hederer ) – C:\Documents and Settings\Lancesandra\My Documents\erunt_setup.exe
[2010/03/07 11:22:30 | 000,021,504 | —- | M] (Doug Knox) – C:\Documents and Settings\Lancesandra\My Documents\SysRestorePoint.exe
[2010/03/07 11:17:02 | 000,050,688 | —- | M] (Atribune.org) – C:\Documents and Settings\Lancesandra\My Documents\ATF_Cleaner.exe
[2010/03/07 10:58:10 | 000,001,734 | —- | M] () – C:\Documents and Settings\Lancesandra\Desktop\HijackThis.lnk
[2010/03/07 10:58:05 | 000,812,344 | —- | M] (Trend Micro Inc.) – C:\Documents and Settings\Lancesandra\My Documents\HJTInstall.exe
[2010/03/07 10:28:26 | 000,000,696 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2010/03/07 10:27:57 | 005,115,824 | —- | M] (Malwarebytes Corporation ) – C:\Documents and Settings\Lancesandra\My Documents\mbam-setup.exe
[2010/03/06 17:12:20 | 000,242,696 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\drivers\avgtdix.sys
[2010/03/06 17:12:20 | 000,012,464 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\avgrsstx.dll
[2010/03/06 17:12:20 | 000,001,507 | —- | M] () – C:\Documents and Settings\All Users\Desktop\AVG Free 9.0.lnk
[2010/03/06 17:12:10 | 000,216,200 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\drivers\avgldx86.sys
[2010/03/06 17:12:09 | 000,113,461 | —- | M] () – C:\WINDOWS\System32\drivers\Avg\iavichjw.avm
[2010/03/06 17:12:09 | 000,029,512 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\drivers\avgmfx86.sys
[2010/03/06 16:47:04 | 095,829,360 | —- | M] (AVG Technologies) – C:\Documents and Settings\Lancesandra\My Documents\avg_free_stf_all_90_787a2721.exe
[2010/03/05 17:07:00 | 009,758,152 | —- | M] (Microsoft Corporation) – C:\Documents and Settings\Lancesandra\My Documents\windows-kb890830-v3.4.exe
[2010/03/05 17:04:06 | 030,042,194 | —- | M] () – C:\Documents and Settings\Lancesandra\My Documents\vdf_fusebundle.zip
[2010/03/05 17:00:50 | 000,367,616 | —- | M] (Avira GmbH) – C:\Documents and Settings\Lancesandra\My Documents\removaltool-win32-en.exe
[2010/03/05 09:46:00 | 030,909,992 | —- | M] () – C:\Documents and Settings\Lancesandra\My Documents\avira_antivir_personal_en.exe
[2010/03/03 17:59:30 | 000,000,933 | —- | M] () – C:\Documents and Settings\Lancesandra\Desktop\Spybot - Search & Destroy.lnk
[2010/03/03 17:47:45 | 000,001,158 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2010/03/02 16:09:00 | 006,723,216 | —- | M] () – C:\Documents and Settings\Lancesandra\My Documents\spybotsd_includes.exe
[2010/03/02 16:06:54 | 016,409,960 | —- | M] (Safer Networking Limited ) – C:\Documents and Settings\Lancesandra\My Documents\spybotsd162.exe
[2010/02/28 20:36:37 | 000,000,582 | —- | M] () – C:\WINDOWS\win.ini
[2010/02/28 20:36:37 | 000,000,211 | —- | M] () – C:\Boot.bak
[2010/02/28 17:49:57 | 000,218,938 | —- | M] () – C:\Documents and Settings\Lancesandra\My Documents\cc_20100228_174936.reg
[2010/02/26 07:05:50 | 000,074,362 | —- | M] () – C:\Documents and Settings\Lancesandra\My Documents\cc_20100226_070536.reg
[2010/02/26 07:02:13 | 000,001,548 | —- | M] () – C:\Documents and Settings\Lancesandra\Desktop\CCleaner.lnk
[2010/02/25 20:52:16 | 000,092,582 | —- | M] () – C:\Documents and Settings\Lancesandra\My Documents\spybot.docx
[2010/02/25 20:50:06 | 000,002,515 | —- | M] () – C:\Documents and Settings\Lancesandra\Desktop\Microsoft Office Word 2007.lnk
[2010/02/25 20:43:24 | 015,083,520 | —- | M] (Safer Networking Limited ) – C:\Documents and Settings\Lancesandra\My Documents\spybotsd160.exe
[2010/02/25 20:27:06 | 000,000,000 | —- | M] () – C:\WINDOWS\nsreg.dat
[2010/02/25 20:26:40 | 000,001,602 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Mozilla Firefox.lnk
[2010/02/25 19:22:10 | 000,002,393 | —- | M] () – C:\Documents and Settings\All Users\Desktop\TurboTax 2009.lnk
[2010/02/24 18:50:19 | 000,002,521 | —- | M] () – C:\Documents and Settings\Lancesandra\Desktop\Microsoft Office Outlook 2007.lnk
[2010/02/21 23:27:54 | 000,354,568 | —- | M] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2010/02/21 15:43:14 | 000,094,888 | —- | M] () – C:\Documents and Settings\Lancesandra\Local Settings\Application Data\GDIPFONTCACHEV1.DAT

========== Files Created - No Company Name ==========

[2010/03/07 18:32:35 | 000,077,312 | —- | C] () – C:\mbr.exe
[2010/03/07 18:19:18 | 000,412,056 | —- | C] () – C:\Documents and Settings\Lancesandra\Desktop\HelpAsst_mebroot_fix.exe
[2010/03/07 16:15:25 | 000,000,211 | —- | C] () – C:\Boot.bak
[2010/03/07 16:15:22 | 000,260,272 | —- | C] () – C:\cmldr
[2010/03/07 16:14:16 | 000,261,632 | —- | C] () – C:\WINDOWS\PEV.exe
[2010/03/07 16:14:16 | 000,098,816 | —- | C] () – C:\WINDOWS\sed.exe
[2010/03/07 16:14:16 | 000,080,412 | —- | C] () – C:\WINDOWS\grep.exe
[2010/03/07 16:14:16 | 000,077,312 | —- | C] () – C:\WINDOWS\MBR.exe
[2010/03/07 16:14:16 | 000,068,096 | —- | C] () – C:\WINDOWS\zip.exe
[2010/03/07 16:09:42 | 004,122,023 | R— | C] () – C:\Documents and Settings\Lancesandra\Desktop\ComboFix.exe
[2010/03/07 14:58:54 | 1064,554,496 | -HS- | C] () – C:\hiberfil.sys
[2010/03/07 11:25:11 | 000,000,611 | —- | C] () – C:\Documents and Settings\Lancesandra\Desktop\NTREGOPT.lnk
[2010/03/07 11:25:11 | 000,000,592 | —- | C] () – C:\Documents and Settings\Lancesandra\Desktop\ERUNT.lnk
[2010/03/07 10:58:10 | 000,001,734 | —- | C] () – C:\Documents and Settings\Lancesandra\Desktop\HijackThis.lnk
[2010/03/07 10:28:26 | 000,000,696 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2010/03/06 17:12:20 | 000,001,507 | —- | C] () – C:\Documents and Settings\All Users\Desktop\AVG Free 9.0.lnk
[2010/03/06 17:12:09 | 000,113,461 | —- | C] () – C:\WINDOWS\System32\drivers\Avg\iavichjw.avm
[2010/03/06 17:12:04 | 056,858,676 | —- | C] () – C:\WINDOWS\System32\drivers\Avg\incavi.avm
[2010/03/06 07:18:35 | 030,909,992 | —- | C] () – C:\Documents and Settings\Lancesandra\My Documents\avira_antivir_personal_en.exe
[2010/03/06 07:18:31 | 030,042,194 | —- | C] () – C:\Documents and Settings\Lancesandra\My Documents\vdf_fusebundle.zip
[2010/03/06 07:18:30 | 006,723,216 | —- | C] () – C:\Documents and Settings\Lancesandra\My Documents\spybotsd_includes.exe
[2010/02/28 20:38:06 | 000,000,933 | —- | C] () – C:\Documents and Settings\Lancesandra\Desktop\Spybot - Search & Destroy.lnk
[2010/02/28 17:49:41 | 000,218,938 | —- | C] () – C:\Documents and Settings\Lancesandra\My Documents\cc_20100228_174936.reg
[2010/02/26 07:05:39 | 000,074,362 | —- | C] () – C:\Documents and Settings\Lancesandra\My Documents\cc_20100226_070536.reg
[2010/02/26 07:02:12 | 000,001,548 | —- | C] () – C:\Documents and Settings\Lancesandra\Desktop\CCleaner.lnk
[2010/02/25 20:52:15 | 000,092,582 | —- | C] () – C:\Documents and Settings\Lancesandra\My Documents\spybot.docx
[2010/02/25 20:27:06 | 000,000,000 | —- | C] () – C:\WINDOWS\nsreg.dat
[2010/02/25 20:26:40 | 000,001,602 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Mozilla Firefox.lnk
[2010/02/21 23:27:01 | 000,197,760 | —- | C] () – C:\Documents and Settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
[2010/02/21 15:33:47 | 000,002,393 | —- | C] () – C:\Documents and Settings\All Users\Desktop\TurboTax 2009.lnk
[2010/01/02 17:37:57 | 000,000,000 | —- | C] () – C:\Documents and Settings\Lancesandra\Application Data\wklnhst.dat
[2009/11/18 11:37:55 | 000,026,760 | R— | C] () – C:\WINDOWS\System32\drivers\swmsflt.sys
[2009/11/01 11:43:18 | 000,000,161 | —- | C] () – C:\WINDOWS\System32\AddPort.ini
[2009/11/01 11:42:00 | 000,000,636 | —- | C] () – C:\WINDOWS\hpntwksetup.ini
[2009/11/01 11:41:13 | 000,000,337 | —- | C] () – C:\Documents and Settings\All Users\Application Data\hpzinstall.log
[2009/10/30 18:29:03 | 000,000,134 | —- | C] () – C:\Documents and Settings\Lancesandra\Local Settings\Application Data\fusioncache.dat
[2009/05/05 12:13:43 | 000,000,061 | —- | C] () – C:\WINDOWS\smscfg.ini
[2009/05/05 11:16:46 | 000,232,872 | R— | C] () – C:\WINDOWS\System32\drivers\SRS_PremiumSound_i386.sys
[2009/05/05 10:03:49 | 000,021,864 | —- | C] () – C:\WINDOWS\AsAcpiSvrLang.ini
[2009/05/05 10:03:49 | 000,012,208 | —- | C] () – C:\WINDOWS\AsTrayLang.ini
[2009/05/05 09:52:19 | 000,147,456 | —- | C] () – C:\WINDOWS\System32\igfxCoIn_v4906.dll
[2009/04/27 22:51:49 | 000,005,312 | —- | C] () – C:\WINDOWS\System32\OEMINFO.INI
[2007/09/27 10:51:02 | 000,020,698 | —- | C] () – C:\WINDOWS\System32\idxcntrs.ini
[2007/09/27 10:48:48 | 000,030,628 | —- | C] () – C:\WINDOWS\System32\gsrvctr.ini
[2007/09/27 10:48:28 | 000,031,698 | —- | C] () – C:\WINDOWS\System32\gthrctr.ini
[2007/03/16 17:00:00 | 000,003,403 | —- | C] () – C:\WINDOWS\System32\hptcpmon.ini

========== LOP Check ==========

[2010/02/03 17:52:58 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\AT&T
[2010/03/07 09:50:57 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\AVG Security Toolbar
[2010/03/06 17:11:49 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\avg9
[2009/05/05 10:02:02 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Wireless LAN Card
[2009/11/18 11:38:11 | 000,000,000 | —D | M] – C:\Documents and Settings\Lancesandra\Application Data\AT&T
[2009/11/18 11:38:20 | 000,000,000 | —D | M] – C:\Documents and Settings\Lancesandra\Application Data\Bytemobile
[2009/11/18 11:37:55 | 000,000,000 | —D | M] – C:\Documents and Settings\Lancesandra\Application Data\Sierra Wireless
[2010/01/02 17:38:02 | 000,000,000 | —D | M] – C:\Documents and Settings\Lancesandra\Application Data\Template
[2009/11/25 09:01:04 | 000,000,000 | —D | M] – C:\Documents and Settings\Lancesandra\Application Data\Windows Desktop Search
[2010/03/03 17:53:13 | 000,000,000 | —D | M] – C:\Documents and Settings\Lancesandra\Application Data\Windows Search

========== Purity Check ==========



========== Custom Scans ==========


< %SYSTEMDRIVE%\*.exe >
[2010/03/07 18:32:35 | 000,077,312 | —- | M] () – C:\mbr.exe


< MD5 for: AGP440.SYS >
[2008/04/14 06:00:00 | 020,056,462 | —- | M] () .cab file – C:\WINDOWS\Driver Cache\i386\sp3.cab:AGP440.sys
[2008/04/14 06:00:00 | 020,056,462 | —- | M] () .cab file – C:\WINDOWS\I386\sp3.cab:AGP440.sys

< MD5 for: ATAPI.SYS >
[2008/04/14 06:00:00 | 020,056,462 | —- | M] () .cab file – C:\WINDOWS\Driver Cache\i386\sp3.cab:atapi.sys
[2008/04/14 06:00:00 | 020,056,462 | —- | M] () .cab file – C:\WINDOWS\I386\sp3.cab:atapi.sys
[2008/04/14 01:10:32 | 000,096,512 | —- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 – C:\WINDOWS\ERDNT\cache\atapi.sys
[2008/04/14 01:10:32 | 000,096,512 | —- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 – C:\WINDOWS\system32\dllcache\atapi.sys
[2008/04/14 01:10:32 | 000,096,512 | —- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 – C:\WINDOWS\system32\drivers\atapi.sys
[2008/04/14 06:00:00 | 000,096,512 | —- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 – C:\WINDOWS\system32\ReinstallBackups\0005\DriverFiles\i386\atapi.sys

< MD5 for: EVENTLOG.DLL >
[2008/04/14 06:00:00 | 000,056,320 | —- | M] (Microsoft Corporation) MD5=6D4FEB43EE538FC5428CC7F0565AA656 – C:\WINDOWS\ERDNT\cache\eventlog.dll
[2008/04/14 06:00:00 | 000,056,320 | —- | M] (Microsoft Corporation) MD5=6D4FEB43EE538FC5428CC7F0565AA656 – C:\WINDOWS\system32\dllcache\eventlog.dll
[2008/04/14 06:00:00 | 000,056,320 | —- | M] (Microsoft Corporation) MD5=6D4FEB43EE538FC5428CC7F0565AA656 – C:\WINDOWS\system32\eventlog.dll

< MD5 for: IASTOR.SYS >
[2008/09/11 23:32:56 | 000,327,192 | —- | M] (Intel Corporation) MD5=8EF427C54497C5F8A7A645990E4278C7 – C:\WINDOWS\I386\$OEM$\TEXTMODE\IASTOR.SYS
[2008/09/11 23:32:56 | 000,327,192 | —- | M] (Intel Corporation) MD5=8EF427C54497C5F8A7A645990E4278C7 – C:\WINDOWS\OemDir\iaStor.sys
[2008/09/11 23:32:56 | 000,327,192 | —- | M] (Intel Corporation) MD5=8EF427C54497C5F8A7A645990E4278C7 – C:\WINDOWS\system32\drivers\iaStor.sys

< MD5 for: NETLOGON.DLL >
[2008/04/14 06:00:00 | 000,407,040 | —- | M] (Microsoft Corporation) MD5=1B7F071C51B77C272875C3A23E1E4550 – C:\WINDOWS\ERDNT\cache\netlogon.dll
[2008/04/14 06:00:00 | 000,407,040 | —- | M] (Microsoft Corporation) MD5=1B7F071C51B77C272875C3A23E1E4550 – C:\WINDOWS\system32\dllcache\netlogon.dll
[2008/04/14 06:00:00 | 000,407,040 | —- | M] (Microsoft Corporation) MD5=1B7F071C51B77C272875C3A23E1E4550 – C:\WINDOWS\system32\netlogon.dll

< MD5 for: SCECLI.DLL >
[2008/04/14 06:00:00 | 000,181,248 | —- | M] (Microsoft Corporation) MD5=A86BB5E61BF3E39B62AB4C7E7085A084 – C:\WINDOWS\ERDNT\cache\scecli.dll
[2008/04/14 06:00:00 | 000,181,248 | —- | M] (Microsoft Corporation) MD5=A86BB5E61BF3E39B62AB4C7E7085A084 – C:\WINDOWS\system32\dllcache\scecli.dll
[2008/04/14 06:00:00 | 000,181,248 | —- | M] (Microsoft Corporation) MD5=A86BB5E61BF3E39B62AB4C7E7085A084 – C:\WINDOWS\system32\scecli.dll

< %systemroot%\*. /mp /s >

< %systemroot%\system32\*.dll /lockedfiles >

< %systemroot%\Tasks\*.job /lockedfiles >

< %systemroot%\system32\drivers\*.sys /lockedfiles >

< %systemroot%\System32\config\*.sav >
[2009/04/27 15:57:35 | 000,094,208 | —- | M] () – C:\WINDOWS\system32\config\default.sav
[2009/04/27 15:57:35 | 001,064,960 | —- | M] () – C:\WINDOWS\system32\config\software.sav
[2009/04/27 15:57:35 | 000,909,312 | —- | M] () – C:\WINDOWS\system32\config\system.sav
< End of report >
Questions:

Do you have any idea what this file is?

C:\Documents and Settings\Lancesandra\My Documents\vdf_fusebundle.zip


NEXT:


OTL Fix
Run OTL.exe
  • Copy/paste the following text written inside of the code box into the Custom Scans/Fixes box located at the bottom of OTL

    :Services
    :OTL
    PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
    O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
    O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
    :Commands
    [emptytemp]
    [start explorer]
    [Reboot]
  • Then click the Run Fix button at the top
  • Let the program run unhindered, reboot when it is done

NEXT:


Open notepad and copy/paste the text in the code box below into it:

regedit /a log.txt "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List" 
reg query HKLM\SYSTEM\CurrentControlSet\Services\TermService\Parameters /v ServiceDll>>log.txt
start notepad log.txt


Save this as look.bat Choose to "Save type as - All Files"

It should look like this: [external image: Posted Image]

Double click on look.bat & allow it to run. A notepad file will open. Copy that information into your next reply, please.


NEXT:


Re-Running OTL
  • Please double click on the OTL icon which should be located on your desktop. This will run OTL. Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output.
  • Check the boxes beside LOP Check and Purity Check.
  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
  • When the scan completes, it will open up a notepad window called OTL.txt.
    Note: This log can be located in the OTL folder on you C:\ drive if they fail to open automatically.
  • Please copy (Edit->Select All, Edit->Copy) the contents of the OTL.txt file, and post it with your next reply.

NEXT:


Please make sure you include the following items in your next post:

1. Any comments or questions you may have that you'd like for me to answer in my next post to you.
2. An answer to my question regarding the file mentioned above.
3. The log that was produced after running the OTL Fix.
4. The log that was produced after running the look.bat
5. The log that was produced after running a new OTL scan.
6. An update on how your computer is currently running.

It would be helpful if you could answer each question in the order asked, as well as numbering your answers.
Hej Do you have any idea what this file is? C:\Documents and Settings\Lancesandra\My Documents\vdf_fusebundle.zip I think it is one of the manual update virus definition files I downloaded due to not being able to do auto updates. I can delete it now if need or suspiecios? working on the other items now
Don't worry about this file: C:\Documents and Settings\Lancesandra\My Documents\vdf_fusebundle.zip for right now. It looks like its related to Avira Anti-Virus.
Hej,

#2 OK, thanks

OTL - fix log

All processes killed
========== SERVICES/DRIVERS ==========
========== OTL ==========
No active process named explorer.exe was found!
Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{5C255C8A-E604-49b4-9D64-90988571CECB}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5C255C8A-E604-49b4-9D64-90988571CECB}\ not found.
Registry key HKEY_CURRENT_USER\Software\Policies\Microsoft\Internet Explorer\Control Panel\ deleted successfully.
========== COMMANDS ==========

[EMPTYTEMP]

User: Administrator
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes

User: All Users

User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes

User: Lancesandra
->Temp folder emptied: 16864 bytes
->Temporary Internet Files folder emptied: 4069295 bytes
->FireFox cache emptied: 0 bytes
->Flash cache emptied: 0 bytes

User: LocalService
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes

User: NetworkService
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes

%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32\dllcache .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 409087 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 0 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 0 bytes
RecycleBin emptied: 0 bytes

Total Files Cleaned = 4.00 mb


OTL by OldTimer - Version 3.1.34.0 log created on 03072010_191325

Files\Folders moved on Reboot…
C:\Documents and Settings\Lancesandra\Local Settings\Temporary Internet Files\Content.IE5\QGE9BZGR\iframe[1].htm moved successfully.
C:\Documents and Settings\Lancesandra\Local Settings\Temporary Internet Files\Content.IE5\10QTXWJ9\Virus_updates_blocked_t110773[1].htm moved successfully.

Registry entries deleted on Reboot…


LOOK log

REGEDIT4

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"65533:TCP"="65533:TCP:*:Enabled:Services"
"52344:TCP"="52344:TCP:*:Enabled:Services"
"2479:TCP"="2479:TCP:*:Enabled:Services"
"4118:TCP"="4118:TCP:*:Enabled:Services"
"3389:TCP"="3389:TCP:*:Enabled:Remote Desktop"


! REG.EXE VERSION 3.0

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\TermService\Parameters
ServiceDll REG_EXPAND_SZ %SystemRoot%\System32\termsrv32.dll



OTL SCAN LOG

OTL logfile created on: 3/7/2010 7:24:05 PM - Run 3
OTL by OldTimer - Version 3.1.34.0 Folder = C:\Documents and Settings\Lancesandra\Desktop
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

1,015.00 Mb Total Physical Memory | 476.00 Mb Available Physical Memory | 47.00% Memory free
2.00 Gb Paging File | 2.00 Gb Available in Paging File | 79.00% Paging File free
Paging file location(s): C:\pagefile.sys 1524 3048 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 72.06 Gb Total Space | 57.41 Gb Free Space | 79.66% Space Free | Partition Type: NTFS
Drive D: | 72.05 Gb Total Space | 71.94 Gb Free Space | 99.85% Space Free | Partition Type: NTFS
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: LANCESANDRAEEPC
Current User Name: Lancesandra
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal

========== Processes (SafeList) ==========

PRC - C:\Documents and Settings\Lancesandra\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\AVG\AVG9\avgchsvx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG9\avgcsrvx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG9\avgnsx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG9\avgrsx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG9\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\Common Files\Intuit\Update Service\IntuitUpdateService.exe (Intuit Inc.)
PRC - C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe (Microsoft Corporation)
PRC - C:\Program Files\EeePC\ACPI\AsAcpiSvr.exe (ASUSTeK Computer Inc.)
PRC - C:\Program Files\EeePC\ACPI\AsTray.exe (ASUSTeK Computer Inc.)
PRC - C:\Program Files\ASUS\EeePC\Super Hybrid Engine\SuperHybridEngine.exe (ASUSTeK Computer Inc.)
PRC - C:\Program Files\EeePC\ACPI\AsEPCMon.exe (ASUSTeK Computer Inc.)
PRC - C:\Program Files\Windows Live\Toolbar\wltuser.exe (Microsoft Corporation)
PRC - C:\Program Files\Windows Desktop Search\WindowsSearch.exe (Microsoft Corporation)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\WINDOWS\system32\igfxext.exe (Intel Corporation)


========== Modules (SafeList) ==========

MOD - C:\Documents and Settings\Lancesandra\Desktop\OTL.exe (OldTimer Tools)


========== Win32 Services (SafeList) ==========

SRV - (avg9wd) – C:\Program Files\AVG\AVG9\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
SRV - (AVG Security Toolbar Service) – C:\Program Files\AVG\AVG9\Toolbar\ToolbarBroker.exe ()
SRV - (ATTRcAppSvc) – C:\Program Files\AT&T\Communication Manager\RcAppSvc.exe (SmithMicro Inc.)
SRV - (IntuitUpdateService) – C:\Program Files\Common Files\Intuit\Update Service\IntuitUpdateService.exe (Intuit Inc.)
SRV - (SeaPort) – C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe (Microsoft Corporation)
SRV - (fsssvc) – C:\Program Files\Windows Live\Family Safety\fsssvc.exe (Microsoft Corporation)


========== Driver Services (SafeList) ==========

DRV - (AvgTdiX) – C:\WINDOWS\system32\drivers\avgtdix.sys (AVG Technologies CZ, s.r.o.)
DRV - (AvgLdx86) – C:\WINDOWS\system32\drivers\avgldx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (AvgMfx86) – C:\WINDOWS\system32\drivers\avgmfx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (tcpipBM) – C:\WINDOWS\system32\drivers\tcpipBM.sys (Bytemobile, Inc.)
DRV - (PCTINDIS5) – C:\WINDOWS\system32\PCTINDIS5.sys (Smith Micro Inc.)
DRV - (mfehidk) – C:\WINDOWS\system32\drivers\mfehidk.sys (McAfee, Inc.)
DRV - (mfeavfk) – C:\WINDOWS\system32\drivers\mfeavfk.sys (McAfee, Inc.)
DRV - (mfesmfk) – C:\WINDOWS\system32\drivers\mfesmfk.sys (McAfee, Inc.)
DRV - (mfebopk) – C:\WINDOWS\system32\drivers\mfebopk.sys (McAfee, Inc.)
DRV - (mferkdk) – C:\WINDOWS\system32\drivers\mferkdk.sys (McAfee, Inc.)
DRV - (SWUMXA3) Sierra Wireless USB MUX Driver (UMTSA3) – C:\WINDOWS\system32\drivers\swumxa3.sys (Sierra Wireless Inc.)
DRV - (IntcAzAudAddService) Service for Realtek HD Audio (WDM) – C:\WINDOWS\system32\drivers\RtkHDAud.sys (Realtek Semiconductor Corp.)
DRV - (SRS_PremiumSound_Service) – C:\WINDOWS\system32\drivers\SRS_PremiumSound_i386.sys ()
DRV - (SWNC8UA3) Sierra Wireless MUX NDIS Driver (UMTSA3) – C:\WINDOWS\system32\drivers\swnc8ua3.sys (Sierra Wireless Inc.)
DRV - (AR5416) – C:\WINDOWS\system32\drivers\athw.sys (Atheros Communications, Inc.)
DRV - (SynTP) – C:\WINDOWS\system32\drivers\SynTP.sys (Synaptics Incorporated)
DRV - (L1c) – C:\WINDOWS\system32\drivers\l1c51x86.sys (Atheros Communications, Inc.)
DRV - (fssfltr) – C:\WINDOWS\system32\drivers\fssfltr_tdi.sys (Microsoft Corporation)
DRV - (uvclf) – C:\WINDOWS\system32\drivers\uvclf.sys (GenesysLogic Technologies, Inc.)
DRV - (iaStor) – C:\WINDOWS\system32\drivers\iaStor.sys (Intel Corporation)
DRV - (swmsflt) – C:\WINDOWS\System32\drivers\swmsflt.sys ()
DRV - (Ambfilt) – C:\WINDOWS\system32\drivers\Ambfilt.sys (Creative)
DRV - (HDAudBus) – C:\WINDOWS\system32\drivers\hdaudbus.sys (Windows ® Server 2003 DDK provider)
DRV - (AsusACPI) – C:\WINDOWS\system32\drivers\ASUSACPI.SYS (ASUSTeK Computer Inc.)
DRV - (ialm) – C:\WINDOWS\system32\drivers\igxpmp32.sys (Intel Corporation)
DRV - (Monfilt) – C:\WINDOWS\system32\drivers\Monfilt.sys (Creative Technology Ltd.)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========


IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://my.yahoo.com/
IE - HKCU\..\URLSearchHook: {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dll ()
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..extensions.enabledItems: {B7082FAA-CB62-4872-9106-E42DD88EDE45}:3.0
FF - prefs.js..extensions.enabledItems: {635abd67-4fe9-1b23-4f01-e679fa7484c1}:1.5.4.20081105


FF - HKLM\software\mozilla\Firefox\Extensions\\{3f963a5b-e555-4543-90e2-c3908898db71}: C:\Program Files\AVG\AVG9\Firefox [2010/03/06 17:11:49 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\avg@igeared: C:\Program Files\AVG\AVG9\Toolbar\Firefox\avg@igeared [2010/03/06 17:12:03 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010/02/25 20:26:58 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010/02/25 20:26:30 | 000,000,000 | —D | M]

[2010/02/25 20:27:29 | 000,000,000 | —D | M] – C:\Documents and Settings\Lancesandra\Application Data\Mozilla\Extensions
[2010/02/28 19:30:04 | 000,000,000 | —D | M] – C:\Documents and Settings\Lancesandra\Application Data\Mozilla\Firefox\Profiles\we7cl42s.default\extensions
[2010/02/26 06:59:18 | 000,000,000 | —D | M] (Microsoft .NET Framework Assistant) – C:\Documents and Settings\Lancesandra\Application Data\Mozilla\Firefox\Profiles\we7cl42s.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2010/02/26 07:02:22 | 000,000,000 | —D | M] (Yahoo! Toolbar) – C:\Documents and Settings\Lancesandra\Application Data\Mozilla\Firefox\Profiles\we7cl42s.default\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1}
[2010/02/25 20:26:31 | 000,000,000 | —D | M] – C:\Program Files\Mozilla Firefox\extensions

O1 HOSTS File: ([2008/04/14 06:00:00 | 000,000,734 | —- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (Skype add-on (mastermind)) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Skype Technologies S.A.)
O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG9\avgssie.dll (AVG Technologies CZ, s.r.o.)
O2 - BHO: (Search Helper) - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll (Microsoft Corporation)
O2 - BHO: (Groove GFS Browser Helper) - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation)
O2 - BHO: (AVG Security Toolbar BHO) - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dll ()
O2 - BHO: (TBSB00982 Class) - {DA3D342F-FF20-4E31-9E82-22334155730C} - C:\Program Files\Antbar\Ant.com Toolbar\tbcore3.dll ()
O2 - BHO: (Windows Live Toolbar Helper) - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files\Windows Live\Toolbar\wltcore.dll (Microsoft Corporation)
O3 - HKLM\..\Toolbar: (&Windows Live Toolbar) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll (Microsoft Corporation)
O3 - HKLM\..\Toolbar: (Ant.com Toolbar) - {6CD56C02-CB4D-41B5-A0FE-B479061CCB41} - C:\Program Files\Antbar\Ant.com Toolbar\tbcore3.dll ()
O3 - HKLM\..\Toolbar: (AVG Security Toolbar) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - C:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dll ()
O3 - HKCU\..\Toolbar\WebBrowser: (&Windows Live Toolbar) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll (Microsoft Corporation)
O3 - HKCU\..\Toolbar\WebBrowser: (Ant.com Toolbar) - {6CD56C02-CB4D-41B5-A0FE-B479061CCB41} - C:\Program Files\Antbar\Ant.com Toolbar\tbcore3.dll ()
O3 - HKCU\..\Toolbar\WebBrowser: (AVG Security Toolbar) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - C:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dll ()
O4 - HKLM..\Run: [Adobe Reader Speed Launcher] C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [AsusACPIServer] C:\Program Files\EeePC\ACPI\AsAcpiSvr.exe (ASUSTeK Computer Inc.)
O4 - HKLM..\Run: [AsusEPCMonitor] C:\Program Files\EeePC\ACPI\AsEPCMon.exe (ASUSTeK Computer Inc.)
O4 - HKLM..\Run: [AsusTray] C:\Program Files\EeePC\ACPI\AsTray.exe (ASUSTeK Computer Inc.)
O4 - HKLM..\Run: [SynAsusAcpi] C:\Program Files\Synaptics\SynTP\SynAsusAcpi.exe (Synaptics Incorporated)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\ SuperHybridEngine.lnk = C:\Program Files\ASUS\EeePC\Super Hybrid Engine\SuperHybridEngine.exe (ASUSTeK Computer Inc.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Windows Search.lnk = C:\Program Files\Windows Desktop Search\WindowsSearch.exe (Microsoft Corporation)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O8 - Extra context menu item: E&xport to Microsoft Excel - C:\Program Files\Microsoft Office\Office12\EXCEL.EXE (Microsoft Corporation)
O9 - Extra Button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : &Blog This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation)
O9 - Extra Button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Skype Technologies S.A.)
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Program Files\Microsoft Office\Office12\REFIEBAR.DLL (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - File not found
O15 - HKCU\..Trusted Domains: intuit.com ([ttlc] https in Trusted sites)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} http://www.update.microsoft.com/microsoftu…b?1256933014609 (MUWebControl Class)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab (Shockwave Flash Object)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.254
O18 - Protocol\Handler\avgsecuritytoolbar {F2DDE6B2-9684-4A55-86D4-E255E237B77C} - C:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dll ()
O18 - Protocol\Handler\grooveLocalGWS {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll (Microsoft Corporation)
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG9\avgpp.dll (AVG Technologies CZ, s.r.o.)
O18 - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\Windows Live\Messenger\msgrapp.14.0.8064.0206.dll (Microsoft Corporation)
O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll (Microsoft Corporation)
O18 - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\Windows Live\Messenger\msgrapp.14.0.8064.0206.dll (Microsoft Corporation)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Handler\wlmailhtml {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - C:\Program Files\Windows Live\Mail\mailcomm.dll (Microsoft Corporation)
O18 - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\Microsoft Shared\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\avgrsstarter: DllName - avgrsstx.dll - C:\WINDOWS\System32\avgrsstx.dll (AVG Technologies CZ, s.r.o.)
O20 - Winlogon\Notify\igfxcui: DllName - igfxdev.dll - C:\WINDOWS\System32\igfxdev.dll (Intel Corporation)
O24 - Desktop WallPaper: C:\Documents and Settings\Lancesandra\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Lancesandra\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O28 - HKLM ShellExecuteHooks: {56F9679E-7826-4C84-81F3-532071A8BCC5} - C:\Program Files\Windows Desktop Search\MsnlNamespaceMgr.dll (Microsoft Corporation)
O28 - HKLM ShellExecuteHooks: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009/04/27 23:03:59 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - comfile [open] – "%1" %*
O35 - exefile [open] – "%1" %*

========== Files/Folders - Created Within 30 Days ==========

[2010/03/07 18:13:16 | 000,000,000 | -HSD | C] – C:\RECYCLER
[2010/03/07 18:13:04 | 000,000,000 | —D | C] – C:\_OTL
[2010/03/07 16:25:05 | 000,553,984 | —- | C] (OldTimer Tools) – C:\Documents and Settings\Lancesandra\Desktop\OTL.exe
[2010/03/07 16:23:06 | 000,000,000 | —D | C] – C:\WINDOWS\temp
[2010/03/07 16:15:21 | 000,000,000 | RHSD | C] – C:\cmdcons
[2010/03/07 16:14:16 | 000,212,480 | —- | C] (SteelWerX) – C:\WINDOWS\SWXCACLS.exe
[2010/03/07 16:14:16 | 000,161,792 | —- | C] (SteelWerX) – C:\WINDOWS\SWREG.exe
[2010/03/07 16:14:16 | 000,136,704 | —- | C] (SteelWerX) – C:\WINDOWS\SWSC.exe
[2010/03/07 16:14:16 | 000,031,232 | —- | C] (NirSoft) – C:\WINDOWS\NIRCMD.exe
[2010/03/07 16:14:05 | 000,000,000 | —D | C] – C:\ComboFix
[2010/03/07 16:13:37 | 000,000,000 | —D | C] – C:\Qoobox
[2010/03/07 11:26:06 | 000,000,000 | —D | C] – C:\WINDOWS\ERDNT
[2010/03/07 11:25:04 | 000,000,000 | —D | C] – C:\Program Files\ERUNT
[2010/03/07 11:24:11 | 000,791,393 | —- | C] (Lars Hederer ) – C:\Documents and Settings\Lancesandra\My Documents\erunt_setup.exe
[2010/03/07 11:22:25 | 000,021,504 | —- | C] (Doug Knox) – C:\Documents and Settings\Lancesandra\My Documents\SysRestorePoint.exe
[2010/03/07 11:17:02 | 000,050,688 | —- | C] (Atribune.org) – C:\Documents and Settings\Lancesandra\My Documents\ATF_Cleaner.exe
[2010/03/07 10:58:08 | 000,000,000 | —D | C] – C:\Program Files\Trend Micro
[2010/03/07 10:58:01 | 000,812,344 | —- | C] (Trend Micro Inc.) – C:\Documents and Settings\Lancesandra\My Documents\HJTInstall.exe
[2010/03/07 10:28:23 | 000,038,224 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2010/03/07 10:28:21 | 000,019,160 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys
[2010/03/07 10:28:20 | 000,000,000 | —D | C] – C:\Program Files\Malwarebytes' Anti-Malware
[2010/03/07 10:27:36 | 005,115,824 | —- | C] (Malwarebytes Corporation ) – C:\Documents and Settings\Lancesandra\My Documents\mbam-setup.exe
[2010/03/06 17:38:12 | 000,000,000 | —D | C] – C:\$AVG
[2010/03/06 17:12:20 | 000,242,696 | —- | C] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\drivers\avgtdix.sys
[2010/03/06 17:12:20 | 000,012,464 | —- | C] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\avgrsstx.dll
[2010/03/06 17:12:10 | 000,216,200 | —- | C] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\drivers\avgldx86.sys
[2010/03/06 17:12:09 | 000,029,512 | —- | C] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\drivers\avgmfx86.sys
[2010/03/06 17:12:04 | 000,000,000 | —D | C] – C:\WINDOWS\System32\drivers\Avg
[2010/03/06 17:12:03 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\AVG Security Toolbar
[2010/03/06 17:11:49 | 000,000,000 | —D | C] – C:\Program Files\AVG
[2010/03/06 17:11:48 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\avg9
[2010/03/06 17:10:50 | 000,000,000 | –SD | M] – C:\Documents and Settings\NetworkService\Application Data\Microsoft
[2010/03/06 17:10:50 | 000,000,000 | –SD | M] – C:\Documents and Settings\LocalService\Application Data\Microsoft
[2010/03/06 17:10:50 | 000,000,000 | —D | M] – C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft
[2010/03/06 17:10:50 | 000,000,000 | —D | M] – C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft
[2010/03/06 16:46:33 | 095,829,360 | —- | C] (AVG Technologies) – C:\Documents and Settings\Lancesandra\My Documents\avg_free_stf_all_90_787a2721.exe
[2010/03/06 07:28:36 | 000,055,656 | —- | C] (Avira GmbH) – C:\WINDOWS\System32\drivers\avgntflt.sys
[2010/03/06 07:18:34 | 009,758,152 | —- | C] (Microsoft Corporation) – C:\Documents and Settings\Lancesandra\My Documents\windows-kb890830-v3.4.exe
[2010/03/06 07:18:28 | 016,409,960 | —- | C] (Safer Networking Limited ) – C:\Documents and Settings\Lancesandra\My Documents\spybotsd162.exe
[2010/03/06 07:18:24 | 000,367,616 | —- | C] (Avira GmbH) – C:\Documents and Settings\Lancesandra\My Documents\removaltool-win32-en.exe
[2010/03/03 17:53:13 | 000,000,000 | —D | C] – C:\Documents and Settings\Lancesandra\Application Data\Windows Search
[2010/02/28 20:37:59 | 000,000,000 | —D | C] – C:\Program Files\Spybot - Search & Destroy
[2010/02/28 20:37:59 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
[2010/02/28 20:05:26 | 000,000,000 | —D | C] – C:\Documents and Settings\Lancesandra\Application Data\Malwarebytes
[2010/02/28 20:05:13 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Malwarebytes
[2010/02/26 07:35:37 | 000,000,000 | RH-D | C] – C:\Documents and Settings\Lancesandra\Recent
[2010/02/26 07:01:58 | 000,000,000 | —D | C] – C:\Program Files\CCleaner
[2010/02/26 06:54:24 | 000,000,000 | —D | C] – C:\WINDOWS\Minidump
[2010/02/25 20:47:08 | 015,083,520 | —- | C] (Safer Networking Limited ) – C:\Documents and Settings\Lancesandra\My Documents\spybotsd160.exe
[2010/02/25 20:31:17 | 000,000,000 | —D | C] – C:\Documents and Settings\Lancesandra\My Documents\Downloads
[2010/02/25 20:26:51 | 000,000,000 | —D | C] – C:\Documents and Settings\Lancesandra\Local Settings\Application Data\Mozilla
[2010/02/25 20:26:16 | 000,000,000 | —D | C] – C:\Program Files\Mozilla Firefox
[2010/02/21 16:09:58 | 000,000,000 | —D | C] – C:\Documents and Settings\Lancesandra\Application Data\U3
[2010/02/21 16:08:40 | 000,000,000 | —D | C] – C:\Documents and Settings\Lancesandra\My Documents\TurboTax
[2010/02/21 15:43:32 | 000,000,000 | —D | M] – C:\Documents and Settings\LocalService\Local Settings\Application Data\IsolatedStorage
[2010/02/21 15:43:28 | 000,000,000 | —D | C] – C:\Documents and Settings\Lancesandra\Local Settings\Application Data\Intuit
[2010/02/21 15:37:41 | 000,000,000 | —D | C] – C:\Documents and Settings\Lancesandra\Application Data\Intuit
[2010/02/21 15:37:32 | 000,000,000 | —D | C] – C:\Program Files\Common Files\AnswerWorks 5.0
[2010/02/21 15:31:08 | 000,000,000 | —D | C] – C:\Documents and Settings\Lancesandra\Local Settings\Application Data\IsolatedStorage
[2010/02/21 15:31:03 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Intuit
[2010/02/21 15:30:22 | 000,000,000 | —D | C] – C:\Program Files\TurboTax
[2010/02/21 15:29:46 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Intuit
[2010/02/10 19:28:23 | 000,000,000 | —D | C] – C:\Documents and Settings\Lancesandra\Application Data\Mozilla
[2010/02/10 19:25:02 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Remote Control USB Driver
[2010/02/08 18:09:06 | 000,000,000 | —D | C] – C:\Documents and Settings\Lancesandra\Local Settings\Application Data\assembly
[2009/12/07 15:22:35 | 000,000,000 | —D | M] – C:\Documents and Settings\LocalService\Local Settings\Application Data\Adobe
[2009/12/03 21:51:48 | 000,000,000 | —D | M] – C:\Documents and Settings\LocalService\Application Data\McAfee
[2009/11/18 11:57:09 | 000,000,000 | —D | M] – C:\Documents and Settings\NetworkService\Application Data\Bytemobile
[2009/10/30 18:39:49 | 000,000,000 | —D | M] – C:\Documents and Settings\LocalService\Application Data\SACore

========== Files - Modified Within 30 Days ==========

[2010/03/07 19:22:24 | 000,000,271 | —- | M] () – C:\Documents and Settings\Lancesandra\Desktop\look.bat
[2010/03/07 19:15:07 | 000,000,006 | -H– | M] () – C:\WINDOWS\tasks\SA.DAT
[2010/03/07 19:15:04 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2010/03/07 19:15:02 | 1064,554,496 | -HS- | M] () – C:\hiberfil.sys
[2010/03/07 19:13:58 | 004,456,448 | -H– | M] () – C:\Documents and Settings\Lancesandra\NTUSER.DAT
[2010/03/07 19:13:58 | 000,000,178 | -HS- | M] () – C:\Documents and Settings\Lancesandra\ntuser.ini
[2010/03/07 18:34:51 | 004,500,960 | -H– | M] () – C:\Documents and Settings\Lancesandra\Local Settings\Application Data\IconCache.db
[2010/03/07 18:32:35 | 000,077,312 | —- | M] () – C:\mbr.exe
[2010/03/07 18:19:18 | 000,412,056 | —- | M] () – C:\Documents and Settings\Lancesandra\Desktop\HelpAsst_mebroot_fix.exe
[2010/03/07 16:52:59 | 056,858,676 | —- | M] () – C:\WINDOWS\System32\drivers\Avg\incavi.avm
[2010/03/07 16:25:05 | 000,553,984 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Lancesandra\Desktop\OTL.exe
[2010/03/07 16:21:08 | 000,000,227 | —- | M] () – C:\WINDOWS\system.ini
[2010/03/07 16:15:25 | 000,000,281 | RHS- | M] () – C:\boot.ini
[2010/03/07 16:09:50 | 004,122,023 | R— | M] () – C:\Documents and Settings\Lancesandra\Desktop\ComboFix.exe
[2010/03/07 11:25:11 | 000,000,611 | —- | M] () – C:\Documents and Settings\Lancesandra\Desktop\NTREGOPT.lnk
[2010/03/07 11:25:11 | 000,000,592 | —- | M] () – C:\Documents and Settings\Lancesandra\Desktop\ERUNT.lnk
[2010/03/07 11:24:21 | 000,791,393 | —- | M] (Lars Hederer ) – C:\Documents and Settings\Lancesandra\My Documents\erunt_setup.exe
[2010/03/07 11:22:30 | 000,021,504 | —- | M] (Doug Knox) – C:\Documents and Settings\Lancesandra\My Documents\SysRestorePoint.exe
[2010/03/07 11:17:02 | 000,050,688 | —- | M] (Atribune.org) – C:\Documents and Settings\Lancesandra\My Documents\ATF_Cleaner.exe
[2010/03/07 10:58:10 | 000,001,734 | —- | M] () – C:\Documents and Settings\Lancesandra\Desktop\HijackThis.lnk
[2010/03/07 10:58:05 | 000,812,344 | —- | M] (Trend Micro Inc.) – C:\Documents and Settings\Lancesandra\My Documents\HJTInstall.exe
[2010/03/07 10:28:26 | 000,000,696 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2010/03/07 10:27:57 | 005,115,824 | —- | M] (Malwarebytes Corporation ) – C:\Documents and Settings\Lancesandra\My Documents\mbam-setup.exe
[2010/03/06 17:12:20 | 000,242,696 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\drivers\avgtdix.sys
[2010/03/06 17:12:20 | 000,012,464 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\avgrsstx.dll
[2010/03/06 17:12:20 | 000,001,507 | —- | M] () – C:\Documents and Settings\All Users\Desktop\AVG Free 9.0.lnk
[2010/03/06 17:12:10 | 000,216,200 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\drivers\avgldx86.sys
[2010/03/06 17:12:09 | 000,113,461 | —- | M] () – C:\WINDOWS\System32\drivers\Avg\iavichjw.avm
[2010/03/06 17:12:09 | 000,029,512 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\drivers\avgmfx86.sys
[2010/03/06 16:47:04 | 095,829,360 | —- | M] (AVG Technologies) – C:\Documents and Settings\Lancesandra\My Documents\avg_free_stf_all_90_787a2721.exe
[2010/03/05 17:07:00 | 009,758,152 | —- | M] (Microsoft Corporation) – C:\Documents and Settings\Lancesandra\My Documents\windows-kb890830-v3.4.exe
[2010/03/05 17:04:06 | 030,042,194 | —- | M] () – C:\Documents and Settings\Lancesandra\My Documents\vdf_fusebundle.zip
[2010/03/05 17:00:50 | 000,367,616 | —- | M] (Avira GmbH) – C:\Documents and Settings\Lancesandra\My Documents\removaltool-win32-en.exe
[2010/03/05 09:46:00 | 030,909,992 | —- | M] () – C:\Documents and Settings\Lancesandra\My Documents\avira_antivir_personal_en.exe
[2010/03/03 17:59:30 | 000,000,933 | —- | M] () – C:\Documents and Settings\Lancesandra\Desktop\Spybot - Search & Destroy.lnk
[2010/03/03 17:47:45 | 000,001,158 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2010/03/02 16:09:00 | 006,723,216 | —- | M] () – C:\Documents and Settings\Lancesandra\My Documents\spybotsd_includes.exe
[2010/03/02 16:06:54 | 016,409,960 | —- | M] (Safer Networking Limited ) – C:\Documents and Settings\Lancesandra\My Documents\spybotsd162.exe
[2010/02/28 20:36:37 | 000,000,582 | —- | M] () – C:\WINDOWS\win.ini
[2010/02/28 20:36:37 | 000,000,211 | —- | M] () – C:\Boot.bak
[2010/02/28 17:49:57 | 000,218,938 | —- | M] () – C:\Documents and Settings\Lancesandra\My Documents\cc_20100228_174936.reg
[2010/02/26 07:05:50 | 000,074,362 | —- | M] () – C:\Documents and Settings\Lancesandra\My Documents\cc_20100226_070536.reg
[2010/02/26 07:02:13 | 000,001,548 | —- | M] () – C:\Documents and Settings\Lancesandra\Desktop\CCleaner.lnk
[2010/02/25 20:52:16 | 000,092,582 | —- | M] () – C:\Documents and Settings\Lancesandra\My Documents\spybot.docx
[2010/02/25 20:50:06 | 000,002,515 | —- | M] () – C:\Documents and Settings\Lancesandra\Desktop\Microsoft Office Word 2007.lnk
[2010/02/25 20:43:24 | 015,083,520 | —- | M] (Safer Networking Limited ) – C:\Documents and Settings\Lancesandra\My Documents\spybotsd160.exe
[2010/02/25 20:27:06 | 000,000,000 | —- | M] () – C:\WINDOWS\nsreg.dat
[2010/02/25 20:26:40 | 000,001,602 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Mozilla Firefox.lnk
[2010/02/25 19:22:10 | 000,002,393 | —- | M] () – C:\Documents and Settings\All Users\Desktop\TurboTax 2009.lnk
[2010/02/24 18:50:19 | 000,002,521 | —- | M] () – C:\Documents and Settings\Lancesandra\Desktop\Microsoft Office Outlook 2007.lnk
[2010/02/21 23:27:54 | 000,354,568 | —- | M] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2010/02/21 15:43:14 | 000,094,888 | —- | M] () – C:\Documents and Settings\Lancesandra\Local Settings\Application Data\GDIPFONTCACHEV1.DAT

========== Files Created - No Company Name ==========

[2010/03/07 19:22:24 | 000,000,271 | —- | C] () – C:\Documents and Settings\Lancesandra\Desktop\look.bat
[2010/03/07 18:32:35 | 000,077,312 | —- | C] () – C:\mbr.exe
[2010/03/07 18:19:18 | 000,412,056 | —- | C] () – C:\Documents and Settings\Lancesandra\Desktop\HelpAsst_mebroot_fix.exe
[2010/03/07 16:15:25 | 000,000,211 | —- | C] () – C:\Boot.bak
[2010/03/07 16:15:22 | 000,260,272 | —- | C] () – C:\cmldr
[2010/03/07 16:14:16 | 000,261,632 | —- | C] () – C:\WINDOWS\PEV.exe
[2010/03/07 16:14:16 | 000,098,816 | —- | C] () – C:\WINDOWS\sed.exe
[2010/03/07 16:14:16 | 000,080,412 | —- | C] () – C:\WINDOWS\grep.exe
[2010/03/07 16:14:16 | 000,077,312 | —- | C] () – C:\WINDOWS\MBR.exe
[2010/03/07 16:14:16 | 000,068,096 | —- | C] () – C:\WINDOWS\zip.exe
[2010/03/07 16:09:42 | 004,122,023 | R— | C] () – C:\Documents and Settings\Lancesandra\Desktop\ComboFix.exe
[2010/03/07 14:58:54 | 1064,554,496 | -HS- | C] () – C:\hiberfil.sys
[2010/03/07 11:25:11 | 000,000,611 | —- | C] () – C:\Documents and Settings\Lancesandra\Desktop\NTREGOPT.lnk
[2010/03/07 11:25:11 | 000,000,592 | —- | C] () – C:\Documents and Settings\Lancesandra\Desktop\ERUNT.lnk
[2010/03/07 10:58:10 | 000,001,734 | —- | C] () – C:\Documents and Settings\Lancesandra\Desktop\HijackThis.lnk
[2010/03/07 10:28:26 | 000,000,696 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2010/03/06 17:12:20 | 000,001,507 | —- | C] () – C:\Documents and Settings\All Users\Desktop\AVG Free 9.0.lnk
[2010/03/06 17:12:09 | 000,113,461 | —- | C] () – C:\WINDOWS\System32\drivers\Avg\iavichjw.avm
[2010/03/06 17:12:04 | 056,858,676 | —- | C] () – C:\WINDOWS\System32\drivers\Avg\incavi.avm
[2010/03/06 07:18:35 | 030,909,992 | —- | C] () – C:\Documents and Settings\Lancesandra\My Documents\avira_antivir_personal_en.exe
[2010/03/06 07:18:31 | 030,042,194 | —- | C] () – C:\Documents and Settings\Lancesandra\My Documents\vdf_fusebundle.zip
[2010/03/06 07:18:30 | 006,723,216 | —- | C] () – C:\Documents and Settings\Lancesandra\My Documents\spybotsd_includes.exe
[2010/02/28 20:38:06 | 000,000,933 | —- | C] () – C:\Documents and Settings\Lancesandra\Desktop\Spybot - Search & Destroy.lnk
[2010/02/28 17:49:41 | 000,218,938 | —- | C] () – C:\Documents and Settings\Lancesandra\My Documents\cc_20100228_174936.reg
[2010/02/26 07:05:39 | 000,074,362 | —- | C] () – C:\Documents and Settings\Lancesandra\My Documents\cc_20100226_070536.reg
[2010/02/26 07:02:12 | 000,001,548 | —- | C] () – C:\Documents and Settings\Lancesandra\Desktop\CCleaner.lnk
[2010/02/25 20:52:15 | 000,092,582 | —- | C] () – C:\Documents and Settings\Lancesandra\My Documents\spybot.docx
[2010/02/25 20:27:06 | 000,000,000 | —- | C] () – C:\WINDOWS\nsreg.dat
[2010/02/25 20:26:40 | 000,001,602 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Mozilla Firefox.lnk
[2010/02/21 23:27:01 | 000,197,760 | —- | C] () – C:\Documents and Settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
[2010/02/21 15:33:47 | 000,002,393 | —- | C] () – C:\Documents and Settings\All Users\Desktop\TurboTax 2009.lnk
[2010/01/02 17:37:57 | 000,000,000 | —- | C] () – C:\Documents and Settings\Lancesandra\Application Data\wklnhst.dat
[2009/11/18 11:37:55 | 000,026,760 | R— | C] () – C:\WINDOWS\System32\drivers\swmsflt.sys
[2009/11/01 11:43:18 | 000,000,161 | —- | C] () – C:\WINDOWS\System32\AddPort.ini
[2009/11/01 11:42:00 | 000,000,636 | —- | C] () – C:\WINDOWS\hpntwksetup.ini
[2009/11/01 11:41:13 | 000,000,337 | —- | C] () – C:\Documents and Settings\All Users\Application Data\hpzinstall.log
[2009/10/30 18:29:03 | 000,000,134 | —- | C] () – C:\Documents and Settings\Lancesandra\Local Settings\Application Data\fusioncache.dat
[2009/05/05 12:13:43 | 000,000,061 | —- | C] () – C:\WINDOWS\smscfg.ini
[2009/05/05 11:16:46 | 000,232,872 | R— | C] () – C:\WINDOWS\System32\drivers\SRS_PremiumSound_i386.sys
[2009/05/05 10:03:49 | 000,021,864 | —- | C] () – C:\WINDOWS\AsAcpiSvrLang.ini
[2009/05/05 10:03:49 | 000,012,208 | —- | C] () – C:\WINDOWS\AsTrayLang.ini
[2009/05/05 09:52:19 | 000,147,456 | —- | C] () – C:\WINDOWS\System32\igfxCoIn_v4906.dll
[2009/04/27 22:51:49 | 000,005,312 | —- | C] () – C:\WINDOWS\System32\OEMINFO.INI
[2007/09/27 10:51:02 | 000,020,698 | —- | C] () – C:\WINDOWS\System32\idxcntrs.ini
[2007/09/27 10:48:48 | 000,030,628 | —- | C] () – C:\WINDOWS\System32\gsrvctr.ini
[2007/09/27 10:48:28 | 000,031,698 | —- | C] () – C:\WINDOWS\System32\gthrctr.ini
[2007/03/16 17:00:00 | 000,003,403 | —- | C] () – C:\WINDOWS\System32\hptcpmon.ini

========== LOP Check ==========

[2010/02/03 17:52:58 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\AT&T
[2010/03/07 09:50:57 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\AVG Security Toolbar
[2010/03/06 17:11:49 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\avg9
[2009/05/05 10:02:02 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Wireless LAN Card
[2009/11/18 11:38:11 | 000,000,000 | —D | M] – C:\Documents and Settings\Lancesandra\Application Data\AT&T
[2009/11/18 11:38:20 | 000,000,000 | —D | M] – C:\Documents and Settings\Lancesandra\Application Data\Bytemobile
[2009/11/18 11:37:55 | 000,000,000 | —D | M] – C:\Documents and Settings\Lancesandra\Application Data\Sierra Wireless
[2010/01/02 17:38:02 | 000,000,000 | —D | M] – C:\Documents and Settings\Lancesandra\Application Data\Template
[2009/11/25 09:01:04 | 000,000,000 | —D | M] – C:\Documents and Settings\Lancesandra\Application Data\Windows Desktop Search
[2010/03/03 17:53:13 | 000,000,000 | —D | M] – C:\Documents and Settings\Lancesandra\Application Data\Windows Search

========== Purity Check ==========


< End of report >
Open notepad and copy/paste the text inside the codebox below into it:

net user HelpAssistant>%temp%\temp0
start notepad %temp%\temp0
exit
cls

Save this as help.bat Choose to "Save type as" - "All Files"

It should look like this: [external image: Posted Image]

Double click on help.bat & allow it to run. Then post the log which it produces

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI