This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Please Help!

36 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Please don't worry about the custom scan items for now. Just follow the instructions above for re-running OTL.


okay… I asked this because it was taking a while to finish. I will log off and try again. Thank you for your patience. :)
Finally!!

OTL logfile created on: 3/13/2010 1:32:50 PM - Run 4
OTL by OldTimer - Version 3.1.37.0 Folder = C:\Documents and Settings\Jodi\Desktop
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

510.00 Mb Total Physical Memory | 179.00 Mb Available Physical Memory | 35.00% Memory free
1.00 Gb Paging File | 1.00 Gb Available in Paging File | 70.00% Paging File free
Paging file location(s): C:\pagefile.sys 768 1536 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 71.54 Gb Total Space | 21.07 Gb Free Space | 29.45% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: D894GL61
Current User Name: Jodi
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal

========== Processes (SafeList) ==========

PRC - C:\Documents and Settings\Jodi\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe (Google)
PRC - C:\Program Files\AVG\AVG8\avgtray.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG8\avgcsrvx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG8\avgnsx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG8\avgrsx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG8\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\Java\jre6\bin\jucheck.exe (Sun Microsystems, Inc.)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe (Eastman Kodak Company)
PRC - C:\Program Files\Analog Devices\Core\smax4pnp.exe (Analog Devices, Inc.)
PRC - C:\Program Files\Logitech\Video\LogiTray.exe (Logitech Inc.)
PRC - C:\Program Files\Logitech\Video\FxSvr2.exe (Logitech Inc.)
PRC - C:\WINDOWS\SYSTEM32\LVCOMSX.EXE (Logitech Inc.)


========== Modules (SafeList) ==========

MOD - C:\Documents and Settings\Jodi\Desktop\OTL.exe (OldTimer Tools)


========== Win32 Services (SafeList) ==========

SRV - (GoogleDesktopManager-110309-193829) – C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe (Google)
SRV - (avg8wd) – C:\Program Files\AVG\AVG8\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
SRV - (YahooAUService) – C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe (Yahoo! Inc.)
SRV - (DSBrokerService) – C:\Program Files\DellSupport\brkrsvc.exe ()
SRV - (usnjsvc) – C:\Program Files\MSN Messenger\usnsvc.exe (Microsoft Corporation)


========== Driver Services (SafeList) ==========

DRV - (AvgTdiX) – C:\WINDOWS\System32\Drivers\avgtdix.sys (AVG Technologies CZ, s.r.o.)
DRV - (AvgLdx86) – C:\WINDOWS\System32\Drivers\avgldx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (AvgMfx86) – C:\WINDOWS\System32\Drivers\avgmfx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (amdagp) – C:\WINDOWS\system32\DRIVERS\amdagp.sys (Advanced Micro Devices, Inc.)
DRV - (sisagp) – C:\WINDOWS\system32\DRIVERS\sisagp.sys (Silicon Integrated Systems Corporation)
DRV - (dsunidrv) – C:\WINDOWS\SYSTEM32\DRIVERS\dsunidrv.sys (Gteko Ltd.)
DRV - (DSproct) – C:\Program Files\DellSupport\GTAction\triggers\DSproct.sys (Gteko Ltd.)
DRV - (drvmcdb) – C:\WINDOWS\system32\drivers\drvmcdb.sys (Sonic Solutions)
DRV - (PID_0928) Logitech QuickCam Express(PID_0928) – C:\WINDOWS\SYSTEM32\DRIVERS\LV561AV.SYS (Logitech Inc.)
DRV - (LVUSBSta) – C:\WINDOWS\SYSTEM32\DRIVERS\LVUSBSta.sys (Logitech Inc.)
DRV - (drvnddm) – C:\WINDOWS\SYSTEM32\DRIVERS\drvnddm.sys (Sonic Solutions)
DRV - (tfsnudfa) – C:\WINDOWS\SYSTEM32\dla\tfsnudfa.sys (Sonic Solutions)
DRV - (tfsnudf) – C:\WINDOWS\SYSTEM32\dla\tfsnudf.sys (Sonic Solutions)
DRV - (tfsnifs) – C:\WINDOWS\SYSTEM32\dla\tfsnifs.sys (Sonic Solutions)
DRV - (tfsncofs) – C:\WINDOWS\SYSTEM32\dla\tfsncofs.sys (Sonic Solutions)
DRV - (tfsnboio) – C:\WINDOWS\SYSTEM32\dla\tfsnboio.sys (Sonic Solutions)
DRV - (tfsnopio) – C:\WINDOWS\SYSTEM32\dla\tfsnopio.sys (Sonic Solutions)
DRV - (tfsnpool) – C:\WINDOWS\SYSTEM32\dla\tfsnpool.sys (Sonic Solutions)
DRV - (tfsndrct) – C:\WINDOWS\SYSTEM32\dla\tfsndrct.sys (Sonic Solutions)
DRV - (tfsndres) – C:\WINDOWS\SYSTEM32\dla\tfsndres.sys (Sonic Solutions)
DRV - (senfilt) – C:\WINDOWS\SYSTEM32\DRIVERS\senfilt.sys (Creative Technology Ltd.)
DRV - (nv) – C:\WINDOWS\SYSTEM32\DRIVERS\NV4_MINI.SYS (NVIDIA Corporation)
DRV - (sscdbhk5) – C:\WINDOWS\SYSTEM32\DRIVERS\sscdbhk5.sys (Sonic Solutions)
DRV - (ssrtln) – C:\WINDOWS\SYSTEM32\DRIVERS\ssrtln.sys (Sonic Solutions)
DRV - (IntelC53) – C:\WINDOWS\SYSTEM32\DRIVERS\IntelC53.sys (Intel Corporation)
DRV - (IntelC52) – C:\WINDOWS\SYSTEM32\DRIVERS\IntelC52.sys (Intel Corporation)
DRV - (IntelC51) – C:\WINDOWS\SYSTEM32\DRIVERS\IntelC51.sys (Intel Corporation)
DRV - (mohfilt) – C:\WINDOWS\SYSTEM32\DRIVERS\mohfilt.sys (Intel Corporation)
DRV - (pfc) – C:\WINDOWS\SYSTEM32\DRIVERS\pfc.sys (Padus, Inc.)
DRV - (Sparrow) – C:\WINDOWS\system32\DRIVERS\sparrow.sys (Adaptec, Inc.)
DRV - (sym_u3) – C:\WINDOWS\system32\DRIVERS\sym_u3.sys (LSI Logic)
DRV - (sym_hi) – C:\WINDOWS\system32\DRIVERS\sym_hi.sys (LSI Logic)
DRV - (symc8xx) – C:\WINDOWS\system32\DRIVERS\symc8xx.sys (LSI Logic)
DRV - (symc810) – C:\WINDOWS\system32\DRIVERS\symc810.sys (Symbios Logic Inc.)
DRV - (MODEMCSA) – C:\WINDOWS\SYSTEM32\DRIVERS\MODEMCSA.sys (Microsoft Corporation)
DRV - (ultra) – C:\WINDOWS\system32\DRIVERS\ultra.sys (Promise Technology, Inc.)
DRV - (ql12160) – C:\WINDOWS\system32\DRIVERS\ql12160.sys (QLogic Corporation)
DRV - (ql1080) – C:\WINDOWS\system32\DRIVERS\ql1080.sys (QLogic Corporation)
DRV - (ql1280) – C:\WINDOWS\system32\DRIVERS\ql1280.sys (QLogic Corporation)
DRV - (dac2w2k) – C:\WINDOWS\system32\DRIVERS\dac2w2k.sys (Mylex Corporation)
DRV - (mraid35x) – C:\WINDOWS\system32\DRIVERS\mraid35x.sys (American Megatrends Inc.)
DRV - (asc) – C:\WINDOWS\system32\DRIVERS\asc.sys (Advanced System Products, Inc.)
DRV - (asc3550) – C:\WINDOWS\system32\DRIVERS\asc3550.sys (Advanced System Products, Inc.)
DRV - (AliIde) – C:\WINDOWS\system32\DRIVERS\aliide.sys (Acer Laboratories Inc.)
DRV - (CmdIde) – C:\WINDOWS\system32\DRIVERS\cmdide.sys (CMD Technology, Inc.)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Secondary Start Pages = [Binary data over 100 bytes]
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomSearch = http://us.rd.yahoo.com/customize/ie/defaul…rch/search.html

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.google.com/ie
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie
IE - HKCU\..\URLSearchHook: {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG8\Toolbar\IEToolbar.dll ()
IE - HKCU\..\URLSearchHook: CFBFAE00-17A6-11D0-99CB-00C04FD64497} - Reg Error: Key error. File not found
IE - HKCU\..\URLSearchHook: EF99BD32-C1FB-11D2-892F-0090271D4F88} - Reg Error: Key error. File not found
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local

========== FireFox ==========

FF - prefs.js..browser.search.defaultenginename: "Yahoo! Search"
FF - prefs.js..browser.search.defaulturl: "http://www.google.com/search?lr=&ie;=UTF-8&oe;=UTF-8&q;="
FF - prefs.js..browser.search.selectedEngine: "Google"
FF - prefs.js..browser.startup.homepage: "http://hamptonroads.cox.net/cci/home"
FF - prefs.js..extensions.enabledItems: {3f963a5b-e555-4543-90e2-c3908898db71}:8.5.0.429
FF - prefs.js..extensions.enabledItems: [removed]:1.0
FF - prefs.js..keyword.URL: "http://us.yhs.search.yahoo.com/avg/search?fr=yhs-avg&type;=yahoo_avg_hs2-tb-web_us&p;="


FF - HKLM\software\mozilla\Firefox\Extensions\\{3f963a5b-e555-4543-90e2-c3908898db71}: C:\Program Files\AVG\AVG8\Firefox [2009/12/22 08:48:43 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\avg@igeared: C:\Program Files\AVG\AVG8\Toolbar\Firefox\avg@igeared [2009/10/03 12:05:23 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\{3112ca9c-de6d-4884-a869-9855de68056c}: C:\Documents and Settings\All Users\Application Data\Google\Toolbar for Firefox\{3112ca9c-de6d-4884-a869-9855de68056c} [2010/02/12 02:38:32 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.5.8\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010/03/13 12:09:04 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.5.8\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010/02/20 14:56:35 | 000,000,000 | —D | M]

[2008/09/08 16:30:46 | 000,000,000 | —D | M] – C:\Documents and Settings\Jodi\Application Data\Mozilla\Extensions
[2005/09/04 09:24:28 | 000,000,000 | —D | M] – C:\Documents and Settings\Jodi\Application Data\Mozilla\Firefox\Profiles\8otyaupt.default\extensions
[2006/07/04 21:55:46 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Jodi\Application Data\Mozilla\Firefox\Profiles\8otyaupt.default\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1}
[2005/01/20 18:48:01 | 000,000,000 | —D | M] (Firefox (default)) – C:\Documents and Settings\Jodi\Application Data\Mozilla\Firefox\Profiles\8otyaupt.default\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
[2010/03/12 13:48:51 | 000,000,000 | —D | M] – C:\Documents and Settings\Jodi\Application Data\Mozilla\Firefox\Profiles\zgepjo2r.Default User\extensions
[2009/12/22 06:48:43 | 000,000,000 | —D | M] (Google Toolbar for Firefox) – C:\Documents and Settings\Jodi\Application Data\Mozilla\Firefox\Profiles\zgepjo2r.Default User\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}
[2009/12/09 20:47:20 | 000,000,000 | —D | M] – C:\Documents and Settings\Jodi\Application Data\Mozilla\Firefox\Profiles\zgepjo2r.Default User\extensions\[removed]
[2010/03/12 13:48:51 | 000,000,000 | —D | M] – C:\Program Files\Mozilla Firefox\extensions
[2007/04/07 12:09:45 | 000,000,000 | —D | M] (Google Toolbar for Firefox) – C:\Program Files\Mozilla Firefox\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}
[2004/12/22 11:08:32 | 000,110,592 | —- | M] () – C:\Program Files\Mozilla Firefox\plugins\npmozax.dll

O1 HOSTS File: ([2008/12/17 18:07:58 | 000,000,027 | —- | M]) - C:\WINDOWS\SYSTEM32\DRIVERS\ETC\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (&Yahoo;! Toolbar Helper) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.)
O2 - BHO: (HP Print Enhancer) - {0347C33E-8762-4905-BF09-768834316C61} - C:\Program Files\HP\Smart Web Printing\hpswp_printenhancer.dll (Hewlett-Packard Co.)
O2 - BHO: (HP Print Clips) - {053F9267-DC04-4294-A72C-58F732D338C0} - C:\Program Files\HP\Smart Web Printing\hpswp_framework.dll (Hewlett-Packard Co.)
O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll (AVG Technologies CZ, s.r.o.)
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O2 - BHO: (Yahoo! IE Services Button) - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll (Yahoo! Inc.)
O2 - BHO: (DriveLetterAccess) - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\SYSTEM32\dla\tfswshx.dll (Sonic Solutions)
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - No CLSID value found.
O2 - BHO: (AVG Security Toolbar BHO) - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG8\Toolbar\IEToolbar.dll ()
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.3.4501.1418\swg.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (AVG Security Toolbar) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - C:\Program Files\AVG\AVG8\Toolbar\IEToolbar.dll ()
O3 - HKCU\..\Toolbar\WebBrowser: (&Google; Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll ()
O3 - HKCU\..\Toolbar\WebBrowser: (AVG Security Toolbar) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - C:\Program Files\AVG\AVG8\Toolbar\IEToolbar.dll ()
O3 - HKCU\..\Toolbar\WebBrowser: (Yahoo! Toolbar) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.)
O4 - HKLM..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe (Apple Inc.)
O4 - HKLM..\Run: [AVG8_TRAY] C:\Program Files\AVG\AVG8\avgtray.exe (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [Google Desktop Search] C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe (Google)
O4 - HKLM..\Run: [ISUSPM Startup] C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe (InstallShield Software Corporation)
O4 - HKLM..\Run: [ISUSScheduler] C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe (InstallShield Software Corporation)
O4 - HKLM..\Run: [KernelFaultCheck] File not found
O4 - HKLM..\Run: [LogitechVideoTray] C:\Program Files\Logitech\Video\LogiTray.exe (Logitech Inc.)
O4 - HKLM..\Run: [LVCOMSX] C:\WINDOWS\SYSTEM32\LVCOMSX.EXE (Logitech Inc.)
O4 - HKLM..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe (Analog Devices, Inc.)
O4 - HKLM..\Run: [UpdateManager] C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe (Sonic Solutions)
O4 - HKCU..\Run: [LogitechSoftwareUpdate] C:\Program Files\Logitech\Video\ManifestEngine.exe (Logitech Inc.)
O4 - HKCU..\Run: [Messenger (Yahoo!)] C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe (Yahoo! Inc.)
O4 - HKCU..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Kodak EasyShare software.lnk = C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe (Eastman Kodak Company)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE (Microsoft Corporation)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: HideLegacyLogonScripts = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: HideLogoffScripts = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: RunLogonScriptSync = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: RunStartupScriptSync = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: HideStartupScripts = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: HideLegacyLogonScripts = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: HideLogoffScripts = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: HideStartupScripts = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: RunLogonScriptSync = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: RunStartupScriptSync = 0
O8 - Extra context menu item: &Yahoo;! Search - C:\Program Files\Yahoo!\Common [2009/05/30 18:33:07 | 000,000,000 | —D | M]
O8 - Extra context menu item: Add to Google Photos Screensa&ver; - C:\WINDOWS\System32\GPhotos.scr (Google Inc.)
O8 - Extra context menu item: Yahoo! &Dictionary; - C:\Program Files\Yahoo!\Common [2009/05/30 18:33:07 | 000,000,000 | —D | M]
O8 - Extra context menu item: Yahoo! &Maps; - C:\Program Files\Yahoo!\Common [2009/05/30 18:33:07 | 000,000,000 | —D | M]
O8 - Extra context menu item: Yahoo! &SMS; - C:\Program Files\Yahoo!\Common [2009/05/30 18:33:07 | 000,000,000 | —D | M]
O9 - Extra Button: HP Clipbook - {58ECB495-38F0-49cb-A538-10282ABF65E7} - C:\Program Files\HP\Smart Web Printing\hpswp_extensions.dll (Hewlett-Packard Co.)
O9 - Extra Button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll (Yahoo! Inc.)
O9 - Extra Button: HP Smart Select - {700259D7-1666-479a-93B1-3250410481E8} - C:\Program Files\HP\Smart Web Printing\hpswp_extensions.dll (Hewlett-Packard Co.)
O9 - Extra Button: MUSICMATCH MX Web Player - {d81ca86b-ef63-42af-bee3-4502d9a03c2d} - File not found
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O15 - HKCU\..Trusted Domains: artistarena.com ([tix] https in Trusted sites)
O15 - HKCU\..Trusted Domains: localhost ([]http in Local intranet)
O15 - HKCU\..Trusted Ranges: GD ([http] in Local intranet)
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://fpdownload.macromedia.com/get/shock…director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://download.microsoft.com/download/9/b…heckControl.cab (Windows Genuine Advantage Validation Tool)
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} C:\Program Files\Yahoo!\Common\yinsthelper.dll (YInstStarter Class)
O16 - DPF: {3E68E405-C6DE-49FF-83AE-41EE9F4C36CE} http://office.microsoft.com/officeupdate/content/opuc2.cab (Office Update Installation Engine)
O16 - DPF: {474F00F5-3853-492C-AC3A-476512BBC336} http://picasaweb.google.com/s/v/23.30/uploader2.cab (UploadListView Class)
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} http://v5.windowsupdate.microsoft.com/v5co…b?1106262745037 (WUWebControl Class)
O16 - DPF: {6F750203-1362-4815-A476-88533DE61D0C} http://www.kodakgallery.com/downloads/BUM/…_2/axofupld.cab (Kodak Gallery Easy Upload Manager Class)
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} http://download.eset.com/special/eos/OnlineScanner.cab (OnlineScanner Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_15)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get/flash…t/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_15)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_15)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload.macromedia.com/get/flash…ent/swflash.cab (Shockwave Flash Object)
O16 - DPF: {EBF85371-A38F-485B-B28F-0B4C82D25937} http://update.hpphoto.com/download/HPSWUpdate.ocx (CUpdateCtl Object)
O16 - DPF: {FE0BD779-44EE-4A4B-AA2E-743C63F2E5E6} http://pdl.stream.aol.com/downloads/aol/unagi/ampx_en_dl.cab (IWinAmpActiveX Class)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = [removed] [removed] [removed]
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll (AVG Technologies CZ, s.r.o.)
O18 - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\MSN Messenger\msgrapp.8.1.0178.00.dll (Microsoft Corporation)
O18 - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\MSN Messenger\msgrapp.8.1.0178.00.dll (Microsoft Corporation)
O18 - Protocol\Handler\offline-8876480 {A51AD373-9572-47E7-8B36-550FB14F819E} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (Logitech)
O20 - AppInit_DLLs: (C:\PROGRA~1\Google\GOOGLE~4\GOEC62~1.DLL) - C:\Program Files\Google\Google Desktop Search\GoogleDesktopNetwork3.dll (Google)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\avgrsstarter: DllName - avgrsstx.dll - C:\WINDOWS\System32\avgrsstx.dll (AVG Technologies CZ, s.r.o.)
O20 - Winlogon\Notify\dimsntfy: DllName - - File not found
O20 - Winlogon\Notify\igfxcui: DllName - igfxdev.dll - C:\WINDOWS\System32\igfxdev.dll (Intel Corporation)
O24 - Desktop WallPaper: C:\Documents and Settings\Jodi\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Jodi\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2004/08/10 14:04:08 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKCU\…com [@ = ComFile] – Reg Error: Key error. File not found
O37 - HKCU\…exe [@ = exefile] – Reg Error: Key error. File not found

========== Files/Folders - Created Within 30 Days ==========

[2010/03/12 18:15:02 | 000,891,248 | —- | C] (AVG Technologies) – C:\Documents and Settings\Jodi\Desktop\avg_free_stb_all_9_40_cnet.exe
[2010/03/12 15:18:57 | 000,555,520 | —- | C] (OldTimer Tools) – C:\Documents and Settings\Jodi\Desktop\OTL.exe
[2010/03/12 14:00:13 | 000,000,000 | RH-D | C] – C:\Documents and Settings\Jodi\Recent
[2010/03/10 05:52:54 | 003,558,912 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\moviemk.exe
[2010/02/24 12:16:56 | 000,000,000 | —D | C] – C:\WINDOWS\Minidump
[2009/12/25 02:44:04 | 000,000,000 | —D | M] – C:\Documents and Settings\NetworkService\Local Settings\Application Data\Google
[2009/12/25 02:40:04 | 000,000,000 | —D | M] – C:\Documents and Settings\LocalService\Local Settings\Application Data\Google
[2009/08/11 11:31:25 | 000,000,000 | –SD | M] – C:\Documents and Settings\NetworkService\Application Data\Microsoft
[2009/08/11 11:31:25 | 000,000,000 | –SD | M] – C:\Documents and Settings\LocalService\Application Data\Microsoft
[2009/08/11 11:31:25 | 000,000,000 | —D | M] – C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft
[2009/08/11 11:31:25 | 000,000,000 | —D | M] – C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft
[2007/09/13 22:21:03 | 000,000,000 | —D | M] – C:\Documents and Settings\NetworkService\Local Settings\Application Data\Apple
[2007/03/13 10:06:13 | 000,000,000 | —D | M] – C:\Documents and Settings\NetworkService\Application Data\Symantec
[2005/02/04 16:36:49 | 000,000,000 | —D | M] – C:\Documents and Settings\LocalService\Application Data\McAfee.com
[2005/01/23 18:43:19 | 000,000,000 | -H-D | M] – C:\Documents and Settings\LocalService\Application Data\GTek
[2005/01/21 20:29:53 | 000,000,000 | —D | M] – C:\Documents and Settings\LocalService\Local Settings\Application Data\Identities
[2005/01/20 22:29:33 | 000,000,000 | —D | M] – C:\Documents and Settings\LocalService\Application Data\Mozilla
[2005/01/20 17:51:41 | 000,000,000 | —D | M] – C:\Documents and Settings\LocalService\Application Data\McAfee.com Personal Firewall
[4 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[3 C:\Documents and Settings\Jodi\My Documents\*.tmp files -> C:\Documents and Settings\Jodi\My Documents\*.tmp -> ]
[12 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[1 C:\*.tmp files -> C:\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2010/03/13 13:18:54 | 000,036,116 | —- | M] () – C:\logfile
[2010/03/13 13:15:16 | 000,002,206 | —- | M] () – C:\WINDOWS\System32\WPA.DBL
[2010/03/13 13:15:11 | 000,000,882 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2010/03/13 13:15:08 | 000,000,436 | —- | M] () – C:\WINDOWS\tasks\RegCure Program Check.job
[2010/03/13 13:15:03 | 000,000,868 | —- | M] () – C:\WINDOWS\tasks\Google Software Updater.job
[2010/03/13 13:14:45 | 000,000,006 | -H– | M] () – C:\WINDOWS\tasks\SA.DAT
[2010/03/13 13:14:42 | 000,002,048 | –S- | M] () – C:\WINDOWS\BOOTSTAT.DAT
[2010/03/13 13:14:41 | 534,827,008 | -HS- | M] () – C:\hiberfil.sys
[2010/03/13 13:13:54 | 007,864,320 | —- | M] () – C:\Documents and Settings\Jodi\ntuser.dat
[2010/03/13 13:13:39 | 000,000,278 | -HS- | M] () – C:\Documents and Settings\Jodi\NTUSER.INI
[2010/03/13 12:49:18 | 000,000,886 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2010/03/13 08:44:43 | 057,057,501 | —- | M] () – C:\WINDOWS\System32\drivers\Avg\incavi.avm
[2010/03/12 20:09:39 | 000,077,312 | —- | M] () – C:\mbr.exe
[2010/03/12 18:41:56 | 000,412,056 | —- | M] () – C:\Documents and Settings\Jodi\Desktop\HelpAsst_mebroot_fix.exe
[2010/03/12 18:41:05 | 000,891,248 | —- | M] (AVG Technologies) – C:\Documents and Settings\Jodi\Desktop\avg_free_stb_all_9_40_cnet.exe
[2010/03/12 18:12:22 | 000,485,688 | —- | M] () – C:\Documents and Settings\Jodi\Desktop\HAMeb_check.exe
[2010/03/12 16:14:57 | 000,293,376 | —- | M] () – C:\Documents and Settings\Jodi\Desktop\fnn0bxzu.exe
[2010/03/12 15:18:58 | 000,555,520 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Jodi\Desktop\OTL.exe
[2010/03/08 17:18:15 | 000,000,284 | —- | M] () – C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2010/03/08 15:09:01 | 000,002,473 | —- | M] () – C:\Documents and Settings\Jodi\Desktop\Microsoft Word.lnk
[2010/03/06 12:28:11 | 000,001,729 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Adobe Reader 9.lnk
[2010/03/02 11:52:55 | 000,002,137 | —- | M] () – C:\Documents and Settings\Jodi\Desktop\iTunes.lnk
[2010/02/28 14:24:13 | 000,000,434 | —- | M] () – C:\WINDOWS\tasks\EasyShare Registration Task.job
[2010/02/27 21:13:32 | 000,029,473 | —- | M] () – C:\Documents and Settings\Jodi\My Documents\Steve avatar.jpg
[2010/02/27 17:49:06 | 000,061,066 | —- | M] () – C:\Documents and Settings\Jodi\Desktop\back of my hair.jpg
[2010/02/26 22:42:25 | 000,028,672 | —- | M] () – C:\Documents and Settings\Jodi\Desktop\Prayer List for Feb 28.doc
[2010/02/26 22:41:16 | 000,019,456 | —- | M] () – C:\Documents and Settings\Jodi\Desktop\KA Quotes.doc
[2010/02/26 12:07:39 | 000,051,200 | —- | M] () – C:\Documents and Settings\Jodi\Desktop\Prayer Chain List updated 2.26.2010.doc
[2010/02/26 11:52:32 | 000,092,672 | —- | M] () – C:\Documents and Settings\Jodi\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/02/26 11:43:14 | 000,024,064 | —- | M] () – C:\Documents and Settings\Jodi\Desktop\Cover Letter for Jodi 2.doc
[2010/02/26 11:42:50 | 000,024,064 | —- | M] () – C:\Documents and Settings\Jodi\Desktop\Cover Letter for Zales.doc
[2010/02/25 12:51:36 | 000,140,757 | —- | M] () – C:\Documents and Settings\Jodi\My Documents\My new ring.jpg
[2010/02/25 12:50:59 | 001,151,427 | —- | M] () – C:\Documents and Settings\Jodi\My Documents\my work area.jpg
[2010/02/17 15:40:57 | 000,054,345 | —- | M] () – C:\Documents and Settings\Jodi\My Documents\Ryan Prom.jpg
[2010/02/17 15:40:11 | 000,038,775 | —- | M] () – C:\Documents and Settings\Jodi\My Documents\Ryan Guilford track.jpg
[2010/02/17 15:39:03 | 000,077,879 | —- | M] () – C:\Documents and Settings\Jodi\My Documents\Ryan Guilford cross country race 3.jpg
[2010/02/17 14:06:16 | 000,065,158 | —- | M] () – C:\Documents and Settings\Jodi\My Documents\Ryan Guilford cross country race 2.jpg
[2010/02/17 14:05:51 | 000,077,879 | —- | M] () – C:\Documents and Settings\Jodi\My Documents\Ryan Guilford cross country race.jpg
[2010/02/17 14:04:07 | 000,039,571 | —- | M] () – C:\Documents and Settings\Jodi\My Documents\Ryan Turkey Trot 2009.jpg
[2010/02/17 14:02:23 | 000,030,389 | —- | M] () – C:\Documents and Settings\Jodi\My Documents\Ryan winter 2010.jpg
[2010/02/16 19:07:35 | 005,127,013 | —- | M] () – C:\Documents and Settings\Jodi\My Documents\She's_Got_You.wmv
[2010/02/15 20:28:52 | 000,030,154 | —- | M] () – C:\Documents and Settings\Jodi\My Documents\Robby and the crowd.jpg
[2010/02/15 15:54:26 | 000,053,248 | —- | M] () – C:\Documents and Settings\Jodi\Desktop\Prayer Chain List updated 2.3.2010.doc
[2010/02/12 16:29:52 | 000,029,850 | —- | M] () – C:\Documents and Settings\Jodi\My Documents\Me and Steve.jpg
[2010/02/12 02:38:25 | 000,001,602 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Mozilla Firefox.lnk
[4 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[3 C:\Documents and Settings\Jodi\My Documents\*.tmp files -> C:\Documents and Settings\Jodi\My Documents\*.tmp -> ]
[12 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[1 C:\*.tmp files -> C:\*.tmp -> ]

========== Files Created - No Company Name ==========

[2010/03/12 20:09:39 | 000,077,312 | —- | C] () – C:\mbr.exe
[2010/03/12 18:41:55 | 000,412,056 | —- | C] () – C:\Documents and Settings\Jodi\Desktop\HelpAsst_mebroot_fix.exe
[2010/03/12 18:12:21 | 000,485,688 | —- | C] () – C:\Documents and Settings\Jodi\Desktop\HAMeb_check.exe
[2010/03/12 16:14:55 | 000,293,376 | —- | C] () – C:\Documents and Settings\Jodi\Desktop\fnn0bxzu.exe
[2010/02/27 21:13:32 | 000,029,473 | —- | C] () – C:\Documents and Settings\Jodi\My Documents\Steve avatar.jpg
[2010/02/27 17:49:06 | 000,061,066 | —- | C] () – C:\Documents and Settings\Jodi\Desktop\back of my hair.jpg
[2010/02/26 22:42:25 | 000,028,672 | —- | C] () – C:\Documents and Settings\Jodi\Desktop\Prayer List for Feb 28.doc
[2010/02/26 22:41:16 | 000,019,456 | —- | C] () – C:\Documents and Settings\Jodi\Desktop\KA Quotes.doc
[2010/02/26 11:51:31 | 000,002,137 | —- | C] () – C:\Documents and Settings\Jodi\Desktop\iTunes.lnk
[2010/02/26 11:49:43 | 000,051,200 | —- | C] () – C:\Documents and Settings\Jodi\Desktop\Prayer Chain List updated 2.26.2010.doc
[2010/02/25 12:51:36 | 000,140,757 | —- | C] () – C:\Documents and Settings\Jodi\My Documents\My new ring.jpg
[2010/02/25 12:50:57 | 001,151,427 | —- | C] () – C:\Documents and Settings\Jodi\My Documents\my work area.jpg
[2010/02/23 12:42:28 | 000,024,064 | —- | C] () – C:\Documents and Settings\Jodi\Desktop\Cover Letter for Zales.doc
[2010/02/17 15:40:56 | 000,054,345 | —- | C] () – C:\Documents and Settings\Jodi\My Documents\Ryan Prom.jpg
[2010/02/17 15:40:11 | 000,038,775 | —- | C] () – C:\Documents and Settings\Jodi\My Documents\Ryan Guilford track.jpg
[2010/02/17 15:39:03 | 000,077,879 | —- | C] () – C:\Documents and Settings\Jodi\My Documents\Ryan Guilford cross country race 3.jpg
[2010/02/17 14:06:15 | 000,065,158 | —- | C] () – C:\Documents and Settings\Jodi\My Documents\Ryan Guilford cross country race 2.jpg
[2010/02/17 14:05:51 | 000,077,879 | —- | C] () – C:\Documents and Settings\Jodi\My Documents\Ryan Guilford cross country race.jpg
[2010/02/17 14:04:07 | 000,039,571 | —- | C] () – C:\Documents and Settings\Jodi\My Documents\Ryan Turkey Trot 2009.jpg
[2010/02/17 14:02:19 | 000,030,389 | —- | C] () – C:\Documents and Settings\Jodi\My Documents\Ryan winter 2010.jpg
[2010/02/16 19:07:28 | 005,127,013 | —- | C] () – C:\Documents and Settings\Jodi\My Documents\She's_Got_You.wmv
[2010/02/15 20:28:49 | 000,030,154 | —- | C] () – C:\Documents and Settings\Jodi\My Documents\Robby and the crowd.jpg
[2010/02/12 16:29:52 | 000,029,850 | —- | C] () – C:\Documents and Settings\Jodi\My Documents\Me and Steve.jpg
[2009/04/22 10:54:34 | 000,000,072 | —- | C] () – C:\WINDOWS\CmdPrint.INI
[2008/08/24 14:16:56 | 000,870,128 | —- | C] () – C:\Documents and Settings\Jodi\Application Data\mcs.rma
[2008/08/24 14:16:56 | 000,000,004 | —- | C] () – C:\Documents and Settings\Jodi\Application Data\901D7A
[2008/02/10 15:37:00 | 000,006,518 | —- | C] () – C:\Documents and Settings\All Users\Application Data\hpzinstall.log
[2007/02/20 10:58:31 | 000,000,054 | —- | C] () – C:\WINDOWS\gbsaver.ini
[2007/02/03 18:38:05 | 000,000,002 | —- | C] () – C:\WINDOWS\msoffice.ini
[2006/01/30 14:55:26 | 000,000,072 | —- | C] () – C:\WINDOWS\CmdFile.INI
[2005/12/15 21:45:22 | 000,001,382 | —- | C] () – C:\Documents and Settings\All Users\Application Data\QTSBandwidthCache
[2005/11/18 19:28:29 | 000,000,112 | —- | C] () – C:\WINDOWS\ActiveSkin.INI
[2005/11/17 19:12:48 | 000,000,000 | —- | C] () – C:\WINDOWS\RAWImage.INI
[2005/07/29 15:13:50 | 000,000,044 | —- | C] () – C:\WINDOWS\liveup.ini
[2005/04/15 15:45:25 | 000,009,254 | R— | C] () – C:\WINDOWS\System32\lvcoinst.ini
[2005/04/11 17:59:34 | 000,092,672 | —- | C] () – C:\Documents and Settings\Jodi\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2005/01/28 18:34:02 | 000,000,376 | —- | C] () – C:\WINDOWS\ODBC.INI
[2005/01/24 20:49:46 | 000,000,000 | —- | C] () – C:\WINDOWS\OpPrintServer.INI
[2005/01/24 20:43:11 | 000,007,680 | —- | C] () – C:\WINDOWS\System32\CNMVS66.DLL
[2005/01/21 13:25:12 | 000,002,516 | -HS- | C] () – C:\WINDOWS\System32\KGyGaAvL.sys
[2005/01/20 21:47:24 | 000,004,687 | —- | C] () – C:\WINDOWS\cdPlayer.ini
[2005/01/20 20:04:44 | 000,061,678 | —- | C] () – C:\Documents and Settings\Jodi\Application Data\PFP120JPR.{PB
[2005/01/20 20:04:44 | 000,012,358 | —- | C] () – C:\Documents and Settings\Jodi\Application Data\PFP120JCM.{PB
[2005/01/17 22:15:12 | 000,000,061 | —- | C] () – C:\WINDOWS\smscfg.ini
[2005/01/17 22:07:48 | 000,000,262 | —- | C] () – C:\WINDOWS\wininit.ini
[2005/01/17 21:36:18 | 000,000,520 | —- | C] () – C:\WINDOWS\System32\OEMINFO.INI
[2004/09/15 23:03:14 | 000,000,000 | —- | C] () – C:\WINDOWS\System32\px.ini
[2004/08/10 14:13:12 | 000,000,780 | —- | C] () – C:\WINDOWS\ORUN32.INI
[2004/08/04 06:00:00 | 000,001,793 | —- | C] () – C:\WINDOWS\System32\FXSPERF.INI
[1999/01/27 12:39:06 | 000,065,024 | —- | C] () – C:\WINDOWS\System32\indounin.dll
[1999/01/22 13:46:56 | 000,065,536 | —- | C] () – C:\WINDOWS\System32\MSRTEDIT.DLL
[1997/06/13 06:56:08 | 000,056,832 | —- | C] () – C:\WINDOWS\System32\Iyvu9_32.dll
[1980/01/01 01:00:00 | 000,012,288 | —- | C] () – C:\WINDOWS\System32\e100bmsg.dll

========== LOP Check ==========

[2009/08/11 11:41:57 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\AVG Security Toolbar
[2008/06/26 16:54:20 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Grisoft
[2008/05/25 15:57:21 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\SupportSoft
[2007/03/20 09:32:29 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TEMP
[2009/03/13 18:02:53 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{00D89592-F643-4D8D-8F0F-AFAE0F14D4C3}
[2009/09/12 09:54:10 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{755AC846-7372-4AC8-8550-C52491DAA8BD}
[2009/05/04 16:28:38 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906}
[2008/12/17 17:46:36 | 000,000,000 | —D | M] – C:\Documents and Settings\Jodi\Application Data\ByteCrusher
[2005/06/02 11:05:33 | 000,000,000 | —D | M] – C:\Documents and Settings\Jodi\Application Data\Leadertech
[2009/08/11 12:40:59 | 000,000,000 | —D | M] – C:\Documents and Settings\Jodi\Application Data\Musicmatch
[2006/01/13 17:03:47 | 000,000,000 | —D | M] – C:\Documents and Settings\Jodi\Application Data\MyPublisher
[2006/01/16 13:10:09 | 000,000,000 | —D | M] – C:\Documents and Settings\Jodi\Application Data\Pixmantec
[2007/10/27 17:34:51 | 000,000,000 | —D | M] – C:\Documents and Settings\Jodi\Application Data\SecondLife
[2008/05/25 09:11:26 | 000,000,000 | —D | M] – C:\Documents and Settings\Jodi\Application Data\Uniblue
[2008/12/18 09:33:18 | 000,000,000 | —D | M] – C:\Documents and Settings\Jodi\Application Data\WinPatrol
[2010/02/28 14:24:13 | 000,000,434 | —- | M] () – C:\WINDOWS\Tasks\EasyShare Registration Task.job
[2010/03/13 13:15:08 | 000,000,436 | —- | M] () – C:\WINDOWS\Tasks\RegCure Program Check.job

========== Purity Check ==========



========== Alternate Data Streams ==========

@Alternate Data Stream - 118 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:DFC5A2B2
< End of report >
Mbr txt:

Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer, http://www.gmer.net

device: opened successfully
user: MBR read successfully
called modules: ntoskrnl.exe CLASSPNP.SYS disk.sys atapi.sys hal.dll pciide.sys PCIIDEX.SYS
kernel: MBR read successfully
user & kernel MBR OK
copy of MBR has been found in sector 0x094FE9BD
malicious code @ sector 0x094FE9C0 !
PE file found in sector at 0x094FE9D6 !
Okay. That is good news. We still have some additional work to do first though.

Running ComboFix
Download ComboFix from one of the following locations:
Link 1
Link 2

VERY IMPORTANT !!! Save ComboFix.exe to your Desktop

* IMPORTANT - Disable your Anti-Virus and Anti-Spyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here
  • Double click on ComboFix.exe & follow the prompts.
As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.
**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.

[external image: Posted Image]

  • Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]

  • Click on Yes, to continue scanning for malware.
When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.
Notes:
1. Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. Do not "re-run" Combofix. If you have a problem, reply back for further instructions.

Please make sure you include the ComboFix log in your next reply as well as describe how your computer is running now
It's been a long day with this computer but it seems to be up and running just fine…. thanks to you!!! :)
Here is my ComboFix.exe…..

ComboFix 10-03-13.01 - Jodi 03/13/2010 15:49:38.2.1 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.510.96 [GMT -5:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
AV: AVG Anti-Virus Free *On-access scanning disabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
FW: COMODO Firewall Pro *disabled* {043803A3-4F86-4ef6-AFC5-F6E02A79969B}
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\documents and settings\Jodi\My Documents\ZbThumbnail.info
c:\windows\system32\Thumbs.db

.
((((((((((((((((((((((((( Files Created from 2010-02-13 to 2010-03-13 )))))))))))))))))))))))))))))))
.

2010-03-13 20:24 . 2010-03-13 20:36 ——– d—–w- C:\$AVG
2010-03-13 20:22 . 2010-03-13 20:22 ——– d—–w- c:\documents and settings\All Users\Application Data\avg9
2010-03-13 15:43 . 2010-03-13 15:43 ——– d—–w- c:\documents and settings\HelpAssistant.D894GL61.000\WINDOWS
2010-03-13 15:43 . 2010-03-13 15:43 ——– d—–w- c:\documents and settings\HelpAssistant.D894GL61.000\UserData
2010-03-13 15:17 . 2010-03-13 17:15 ——– d—–w- c:\documents and settings\HelpAssistant.D894GL61.000
2010-03-13 03:13 . 2010-03-13 03:13 ——– d—–w- c:\documents and settings\HelpAssistant.D894GL61\WINDOWS
2010-03-13 03:13 . 2010-03-13 03:13 ——– d—–w- c:\documents and settings\HelpAssistant.D894GL61\UserData
2010-03-13 03:13 . 2010-03-13 03:13 ——– d—–w- c:\documents and settings\HelpAssistant.D894GL61\PrivacIE
2010-03-13 03:13 . 2009-08-12 18:04 0 —-a-w- c:\documents and settings\HelpAssistant.D894GL61\settings.dat
2010-03-13 02:56 . 2008-07-08 16:17 23 —-a-w- c:\documents and settings\HelpAssistant.D894GL61\jagex_runescape_preferences.dat
2010-03-13 02:56 . 2010-03-13 02:56 ——– d—–w- c:\documents and settings\HelpAssistant.D894GL61\IETldCache
2010-03-13 02:56 . 2010-03-13 02:56 ——– d—–w- c:\documents and settings\HelpAssistant.D894GL61\IECompatCache
2010-03-13 02:56 . 2010-03-13 02:56 ——– d—–w- c:\documents and settings\HelpAssistant.D894GL61\Contacts
2010-03-13 02:56 . 2010-03-13 02:56 ——– d—–w- c:\documents and settings\HelpAssistant.D894GL61\Application Data\Yahoo! Messenger
2010-03-13 02:56 . 2010-03-13 02:56 ——– d—–w- c:\documents and settings\HelpAssistant.D894GL61\Application Data\Yahoo!
2010-03-13 02:56 . 2010-03-13 02:56 ——– d—–w- c:\documents and settings\HelpAssistant.D894GL61\Application Data\WinPatrol
2010-03-13 02:56 . 2010-03-13 02:56 ——– d—–w- c:\documents and settings\HelpAssistant.D894GL61\Application Data\Uniblue
2010-03-13 02:56 . 2010-03-13 02:56 ——– d—–w- c:\documents and settings\HelpAssistant.D894GL61\Application Data\Talkback
2010-03-13 02:56 . 2010-03-13 02:56 ——– d—–w- c:\documents and settings\HelpAssistant.D894GL61\Application Data\SUPERAntiSpyware.com
2010-03-13 02:52 . 2010-03-13 02:56 ——– d—–w- c:\documents and settings\HelpAssistant.D894GL61\Application Data\SecondLife
2010-03-13 02:52 . 2010-03-13 02:52 ——– d—–w- c:\documents and settings\HelpAssistant.D894GL61\Application Data\Pixmantec
2010-03-13 02:52 . 2010-03-13 02:52 ——– d—–w- c:\documents and settings\HelpAssistant.D894GL61\Application Data\MyPublisher
2010-03-13 02:52 . 2010-03-13 02:52 ——– d—–w- c:\documents and settings\HelpAssistant.D894GL61\Application Data\Musicmatch
2010-03-13 02:50 . 2010-03-13 02:50 ——– d—–w- c:\documents and settings\HelpAssistant.D894GL61\Application Data\McAfee.com Personal Firewall
2010-03-13 02:50 . 2010-03-13 02:50 ——– d—–w- c:\documents and settings\HelpAssistant.D894GL61\Application Data\McAfee.com
2010-03-13 02:50 . 2010-03-13 02:50 ——– d—–w- c:\documents and settings\HelpAssistant.D894GL61\Application Data\Malwarebytes
2010-03-13 02:50 . 2010-03-13 02:50 ——– d—–w- c:\documents and settings\HelpAssistant.D894GL61\Application Data\Leadertech
2010-03-13 02:50 . 2010-03-13 02:50 ——– d—–w- c:\documents and settings\HelpAssistant.D894GL61\Application Data\Lavasoft
2010-03-13 02:50 . 2010-03-13 02:50 ——– d—–w- c:\documents and settings\HelpAssistant.D894GL61\Application Data\HpUpdate
2010-03-13 02:50 . 2010-03-13 02:50 ——– d—–w- c:\documents and settings\HelpAssistant.D894GL61\Application Data\HPAppData
2010-03-13 02:50 . 2010-03-13 02:50 ——– d—–w- c:\documents and settings\HelpAssistant.D894GL61\Application Data\HP
2010-03-13 02:48 . 2010-03-13 02:48 ——– d—–w- c:\documents and settings\HelpAssistant.D894GL61\Application Data\Gtek
2010-03-13 02:48 . 2010-03-13 02:48 ——– d—–w- c:\documents and settings\HelpAssistant.D894GL61\Application Data\CyberLink
2010-03-13 02:48 . 2010-03-13 02:48 ——– d—–w- c:\documents and settings\HelpAssistant.D894GL61\Application Data\Corel Photo Album
2010-03-13 02:48 . 2010-03-13 02:48 ——– d—–w- c:\documents and settings\HelpAssistant.D894GL61\Application Data\Corel
2010-03-13 02:48 . 2010-03-13 02:48 ——– d—–w- c:\documents and settings\HelpAssistant.D894GL61\Application Data\Comodo
2010-03-13 02:48 . 2010-03-13 02:48 ——– d—–w- c:\documents and settings\HelpAssistant.D894GL61\Application Data\ByteCrusher
2010-03-13 02:45 . 2010-03-13 02:45 ——– d—–w- c:\documents and settings\HelpAssistant.D894GL61\Application Data\ArcSoft
2010-03-13 02:45 . 2010-03-13 02:45 ——– d—–w- c:\documents and settings\HelpAssistant.D894GL61\Application Data\Apple Computer
2010-03-13 02:45 . 2010-03-13 02:45 ——– d—–w- c:\documents and settings\HelpAssistant.D894GL61\Application Data\AdobeUM
2010-03-13 02:45 . 2010-03-13 02:45 ——– d—–w- c:\documents and settings\HelpAssistant.D894GL61\Application Data\AdobeAUM
2010-03-13 02:44 . 2010-03-13 02:44 ——– d—–w- c:\documents and settings\HelpAssistant.D894GL61\.SunDownloadManager
2010-03-13 02:06 . 2010-03-13 02:06 ——– d—–w- c:\documents and settings\HelpAssistant\WINDOWS
2010-03-13 01:18 . 2010-03-13 02:06 ——– d—–w- c:\documents and settings\HelpAssistant
2010-03-13 01:09 . 2010-03-13 01:09 77312 —-a-w- C:\mbr.exe
2010-03-10 10:52 . 2009-10-23 15:28 3558912 ——w- c:\windows\system32\dllcache\moviemk.exe

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-03-13 20:24 . 2009-08-11 16:34 360584 —-a-w- c:\windows\system32\drivers\avgtdix.sys
2010-03-13 20:24 . 2009-08-11 16:33 333192 —-a-w- c:\windows\system32\drivers\avgldx86.sys
2010-03-13 20:24 . 2009-08-11 16:33 28424 —-a-w- c:\windows\system32\drivers\avgmfx86.sys
2010-03-13 20:23 . 2009-08-11 16:34 12464 —-a-w- c:\windows\system32\avgrsstx.dll
2010-03-13 20:22 . 2008-05-25 14:29 ——– d—–w- c:\program files\AVG
2010-03-13 12:08 . 2007-02-20 15:58 ——– d—–w- c:\documents and settings\All Users\Application Data\Google Updater
2010-03-13 02:56 . 2010-03-13 02:43 ——– d—–w- c:\documents and settings\HelpAssistant.D894GL61\Application Data\Sonic
2010-03-13 02:50 . 2010-03-13 02:43 ——– d—–w- c:\documents and settings\HelpAssistant.D894GL61\Application Data\Jasc Software Inc
2010-02-12 07:37 . 2010-02-12 07:37 33558 —-a-w- c:\documents and settings\All Users\Application Data\Google\Toolbar for Firefox\Firefox_Toolbar_Uninstaller.exe
2010-02-08 21:06 . 2010-02-08 21:04 ——– d—–w- c:\program files\iTunes
2010-02-08 21:04 . 2005-01-21 02:02 ——– d—–w- c:\program files\iPod
2010-02-08 21:04 . 2007-07-11 19:06 ——– d—–w- c:\program files\Common Files\Apple
2010-02-08 20:44 . 2010-02-08 20:43 ——– d—–w- c:\program files\QuickTime
2010-02-08 20:26 . 2010-02-08 20:26 72488 —-a-w- c:\documents and settings\All Users\Application Data\Apple Computer\Installer Cache\iTunes 9.0.3.15\SetupAdmin.exe
2010-02-05 23:19 . 2010-02-05 23:19 ——– d—–w- c:\program files\Microsoft Silverlight
2010-02-04 19:24 . 2007-02-20 15:42 ——– d—–w- c:\program files\CCleaner
2010-01-17 23:36 . 2010-01-17 23:35 ——– d—–w- c:\documents and settings\Jodi\Application Data\HpUpdate
2010-01-15 19:58 . 2005-02-02 16:33 ——– d—–w- c:\program files\Common Files\Adobe
2010-01-15 17:20 . 2008-02-10 20:40 ——– d—–w- c:\documents and settings\All Users\Application Data\HP
2010-01-13 14:28 . 2010-01-13 14:28 79856 —-a-w- c:\documents and settings\All Users\Application Data\Google\Toolbar for Firefox\{3112ca9c-de6d-4884-a869-9855de68056c}\uninstaller.exe
2010-01-08 01:16 . 2008-02-10 20:36 141260 —-a-w- c:\windows\hpoins14.dat
2009-12-31 16:50 . 2004-08-04 11:00 353792 —-a-w- c:\windows\system32\drivers\srv.sys
2009-12-23 03:09 . 2009-12-23 03:09 77488 —ha-w- c:\windows\system32\mlfcache.dat
2009-12-21 19:14 . 2004-08-04 11:00 916480 —-a-w- c:\windows\system32\wininet.dll
2009-12-16 19:42 . 2010-03-13 02:52 872960 —-a-w- c:\documents and settings\HelpAssistant.D894GL61\Application Data\Mozilla\Firefox\Profiles\zgepjo2r.Default User\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\components\frozen.dll
2009-12-16 19:42 . 2009-12-22 11:48 872960 —-a-w- c:\documents and settings\Jodi\Application Data\Mozilla\Firefox\Profiles\zgepjo2r.Default User\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\components\frozen.dll
2009-12-16 19:42 . 2010-03-13 02:52 43008 —-a-w- c:\documents and settings\HelpAssistant.D894GL61\Application Data\Mozilla\Firefox\Profiles\zgepjo2r.Default User\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\components\googletoolbarloader.dll
2009-12-16 19:42 . 2009-12-22 11:48 43008 —-a-w- c:\documents and settings\Jodi\Application Data\Mozilla\Firefox\Profiles\zgepjo2r.Default User\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\components\googletoolbarloader.dll
2009-12-16 19:42 . 2010-03-13 02:52 340480 —-a-w- c:\documents and settings\HelpAssistant.D894GL61\Application Data\Mozilla\Firefox\Profiles\zgepjo2r.Default User\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\libraries\googletoolbar-ff2.dll
2009-12-16 19:42 . 2009-12-22 11:48 340480 —-a-w- c:\documents and settings\Jodi\Application Data\Mozilla\Firefox\Profiles\zgepjo2r.Default User\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\libraries\googletoolbar-ff2.dll
2009-12-16 19:41 . 2010-03-13 02:52 346624 —-a-w- c:\documents and settings\HelpAssistant.D894GL61\Application Data\Mozilla\Firefox\Profiles\zgepjo2r.Default User\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\libraries\googletoolbar-ff3.dll
2009-12-16 19:41 . 2009-12-22 11:48 346624 —-a-w- c:\documents and settings\Jodi\Application Data\Mozilla\Firefox\Profiles\zgepjo2r.Default User\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\libraries\googletoolbar-ff3.dll
2009-12-16 18:43 . 2004-08-04 11:00 343040 —-a-w- c:\windows\system32\mspaint.exe
2009-12-14 19:49 . 2009-12-14 19:49 471040 —-a-w- c:\documents and settings\All Users\Application Data\Google\Toolbar for Firefox\{3112ca9c-de6d-4884-a869-9855de68056c}\components\DictionaryCompressionFF.dll
2009-12-14 19:49 . 2009-12-14 19:49 43008 —-a-w- c:\documents and settings\All Users\Application Data\Google\Toolbar for Firefox\{3112ca9c-de6d-4884-a869-9855de68056c}\components\googletoolbarloader.dll
2009-12-14 19:49 . 2009-12-14 19:49 347136 —-a-w- c:\documents and settings\All Users\Application Data\Google\Toolbar for Firefox\{3112ca9c-de6d-4884-a869-9855de68056c}\libraries\googletoolbar-ff3.dll
2009-12-14 19:49 . 2009-12-14 19:49 340992 —-a-w- c:\documents and settings\All Users\Application Data\Google\Toolbar for Firefox\{3112ca9c-de6d-4884-a869-9855de68056c}\libraries\googletoolbar-ff2.dll
2009-12-14 19:49 . 2009-12-14 19:49 1452032 —-a-w- c:\documents and settings\All Users\Application Data\Google\Toolbar for Firefox\{3112ca9c-de6d-4884-a869-9855de68056c}\components\frozen.dll
2009-12-14 07:08 . 2004-08-04 11:00 33280 —-a-w- c:\windows\system32\csrsrv.dll
2009-12-19 14:00 . 2007-09-05 20:11 119808 —-a-w- c:\program files\mozilla firefox\components\GoogleDesktopMozilla.dll
2009-12-03 17:44 . 2005-01-21 18:25 2516 –sha-w- c:\windows\SYSTEM32\KGyGaAvL.sys
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"LogitechSoftwareUpdate"="c:\program files\Logitech\Video\ManifestEngine.exe" [2004-10-08 196608]
"msnmsgr"="c:\program files\MSN Messenger\MsnMsgr.Exe" [2007-01-19 5674352]
"Messenger (Yahoo!)"="c:\program files\Yahoo!\Messenger\YahooMessenger.exe" [2009-05-27 4351216]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-03-29 68856]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SoundMAXPnP"="c:\program files\Analog Devices\Core\smax4pnp.exe" [2004-10-14 1404928]
"IntelMeM"="c:\program files\Intel\Modem Event Monitor\IntelMEM.exe" [2003-09-04 221184]
"PCMService"="c:\program files\Dell\Media Experience\PCMService.exe" [2004-04-12 290816]
"UpdateManager"="c:\program files\Common Files\Sonic\Update Manager\sgtray.exe" [2004-01-07 110592]
"LVCOMSX"="c:\windows\system32\LVCOMSX.EXE" [2004-10-08 221184]
"LogitechVideoTray"="c:\program files\Logitech\Video\LogiTray.exe" [2004-10-08 217088]
"dla"="c:\windows\system32\dla\tfswctrl.exe" [2004-11-16 127035]
"ISUSPM Startup"="c:\program files\Common Files\InstallShield\UpdateService\ISUSPM.exe" [2005-06-10 249856]
"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2005-06-10 81920]
"igfxtray"="c:\windows\system32\igfxtray.exe" [2005-09-20 94208]
"igfxhkcmd"="c:\windows\system32\hkcmd.exe" [2005-09-20 77824]
"igfxpers"="c:\windows\system32\igfxpers.exe" [2005-09-20 114688]
"Google Desktop Search"="c:\program files\Google\Google Desktop Search\GoogleDesktop.exe" [2009-12-19 30192]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2007-03-12 49152]
"AppleSyncNotifier"="c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe" [2009-08-13 177440]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-07-25 149280]
"hpqSRMon"="c:\program files\HP\Digital Imaging\bin\hpqSRMon.exe" [2008-08-20 150016]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-12-22 35760]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2009-12-11 948672]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-11-11 417792]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2010-01-23 141608]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"RunNarrator"="Narrator.exe" [2008-04-14 53760]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2007-3-11 210520]
Kodak EasyShare software.lnk - c:\program files\Kodak\Kodak EasyShare software\bin\EasyShare.exe [2007-9-19 282624]
Microsoft Office.lnk - c:\program files\Microsoft Office\Office\OSA9.EXE [2000-1-21 65588]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2010-03-13 20:23 12464 —-a-w- c:\windows\SYSTEM32\avgrsstx.dll

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Messenger\\MSMSGS.EXE"=
"c:\\Program Files\\IncrediMail\\bin\\ImpCnt.exe"=
"c:\\Program Files\\Logitech\\Desktop Messenger\\8876480\\Program\\LogitechDesktopMessenger.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Kodak\\Kodak EasyShare software\\bin\\EasyShare.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"c:\\Program Files\\MSN Messenger\\livecall.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqpse.exe"=
"c:\\Program Files\\Common Files\\HP\\Digital Imaging\\bin\\hpqPhotoCrm.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqsudi.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqpsapp.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\AVG\\AVG9\\avgupd.exe"=
"c:\\Program Files\\AVG\\AVG9\\avgnsx.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"65533:TCP"= 65533:TCP:Services
"52344:TCP"= 52344:TCP:Services
"2479:TCP"= 2479:TCP:Services
"3246:TCP"= 3246:TCP:Services
"3389:TCP"= 3389:TCP:Remote Desktop
"4100:TCP"= 4100:TCP:Services
"1944:TCP"= 1944:TCP:Services
"6021:TCP"= 6021:TCP:Services
"7021:TCP"= 7021:TCP:Services
"4835:TCP"= 4835:TCP:Services
"6366:TCP"= 6366:TCP:Services

R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\SYSTEM32\DRIVERS\avgldx86.sys [8/11/2009 11:33 AM 333192]
R1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\SYSTEM32\DRIVERS\avgtdix.sys [8/11/2009 11:34 AM 360584]
R2 avg9wd;AVG Free WatchDog;c:\program files\AVG\AVG9\avgwdsvc.exe [3/13/2010 3:23 PM 285392]
S2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [12/25/2009 2:39 AM 135664]
S3 GoogleDesktopManager-110309-193829;Google Desktop Manager 5.9.911.3589;c:\program files\Google\Google Desktop Search\GoogleDesktop.exe [9/5/2007 3:10 PM 30192]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
.
Contents of the 'Scheduled Tasks' folder

2010-03-08 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 16:34]

2010-03-13 c:\windows\Tasks\Google Software Updater.job
- c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2007-02-20 20:48]

2010-03-13 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-12-25 07:39]

2010-03-13 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-12-25 07:39]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.yahoo.com/
uDefault_Search_URL = hxxp://www.google.com/ie
mSearch Bar = hxxp://us.rd.yahoo.com/customize/ie/defaults/sb/msgr9/*http://www.yahoo.com/ext/search/search.html
uInternet Settings,ProxyOverride = *.local
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://us.rd.yahoo.com/customize/ie/defaults/su/msgr9/*http://www.yahoo.com
IE: &Yahoo;! Search - file:///c:\program files\Yahoo!\Common/ycsrch.htm
IE: Add to Google Photos Screensa&ver; - c:\windows\system32\GPhotos.scr/200
IE: Yahoo! &Dictionary; - file:///c:\program files\Yahoo!\Common/ycdict.htm
IE: Yahoo! &Maps; - file:///c:\program files\Yahoo!\Common/ycmap.htm
IE: Yahoo! &SMS; - file:///c:\program files\Yahoo!\Common/ycsms.htm
Trusted Zone: artistarena.com\tix
FF - ProfilePath - c:\documents and settings\Jodi\Application Data\Mozilla\Firefox\Profiles\zgepjo2r.Default User\
FF - prefs.js: browser.search.defaulturl - hxxp://www.google.com/search?lr=&ie;=UTF-8&oe;=UTF-8&q;=
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://hamptonroads.cox.net/cci/home
FF - prefs.js: keyword.URL - hxxp://us.yhs.search.yahoo.com/avg/search?fr=yhs-avg&type;=yahoo_avg_hs2-tb-web_us&p;=
FF - component: c:\documents and settings\Jodi\Application Data\Mozilla\Firefox\Profiles\zgepjo2r.Default User\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\components\frozen.dll
FF - component: c:\program files\AVG\AVG9\Firefox\components\avgssff.dll
FF - component: c:\program files\Mozilla Firefox\components\GoogleDesktopMozilla.dll
FF - plugin: c:\progra~1\Yahoo!\Common\npyaxmpb.dll
FF - plugin: c:\program files\Google\Google Earth\plugin\npgeplugin.dll
FF - plugin: c:\program files\Google\Google Updater\2.4.1536.6592\npCIDetect13.dll
FF - plugin: c:\program files\Google\Picasa3\npPicasa2.dll
FF - plugin: c:\program files\Google\Picasa3\npPicasa3.dll
FF - plugin: c:\program files\Google\Update\1.2.183.17\npGoogleOneClick8.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\NPMGWRAP.DLL
FF - plugin: c:\program files\Mozilla Firefox\plugins\npmozax.dll

—- FIREFOX POLICIES —-
FF - user.js: yahoo.homepage.dontask - truec:\program files\Mozilla Firefox\defaults\pref\activex.js - pref("capability.policy.default.ClassID.CIDFE0BD779-44EE-4A4B-AA2E-743C63F2E5E6", "AllAccess");
.
- - - - ORPHANS REMOVED - - - -

URLSearchHooks-CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file)
URLSearchHooks-EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
Toolbar-{CCC7A320-B3CA-4199-B1A6-9F516DD69829} - (no file)
WebBrowser-{CCC7A320-B3CA-4199-B1A6-9F516DD69829} - (no file)
SafeBoot-AVG Anti-Spyware Driver
SafeBoot-AVG Anti-Spyware Guard
AddRemove-Safety Alert 2006 - c:\docume~1\Jodi\LOCALS~1\Temp\laf839.tmp
AddRemove-Octoshape add-in for Adobe Flash Player - c:\documents and settings\Jodi\Application Data\Macromedia\Flash Player\www.macromedia.com\bin\octoshape\octoshape.exe



**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-03-13 16:22
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————

[HKEY_USERS\S-1-5-21-3533875668-1734397294-677057713-1006\Software\Microsoft\SystemCertificates\AddressBook*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)

[HKEY_USERS\S-1-5-21-3533875668-1734397294-677057713-1006\Software\Policies\Microsoft\SystemCertificates\AddressBook*]
@Allowed: (Read) (S-1-5-21-3533875668-1734397294-677057713-1006)
@Allowed: (Read) (S-1-5-21-3533875668-1734397294-677057713-1006)
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'explorer.exe'(3856)
c:\windows\system32\WININET.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\IEFRAME.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
———————— Other Running Processes ————————
.
c:\program files\AVG\AVG9\avgchsvx.exe
c:\program files\AVG\AVG9\avgrsx.exe
c:\program files\AVG\AVG9\avgcsrvx.exe
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\AVG\AVG9\avgnsx.exe
c:\windows\system32\wscntfy.exe
c:\program files\Logitech\Video\FxSvr2.exe
c:\program files\iPod\bin\iPodService.exe
c:\program files\HP\Digital Imaging\bin\hpqSTE08.exe
c:\program files\Java\jre6\bin\jucheck.exe
.
**************************************************************************
.
Completion time: 2010-03-13 16:34:44 - machine was rebooted
ComboFix-quarantined-files.txt 2010-03-13 21:34
ComboFix2.txt 2008-12-17 23:19

Pre-Run: 22,460,739,584 bytes free
Post-Run: 22,721,617,920 bytes free

- - End Of File - - EDD484F856FB6260B99E30997A26BCA3
Create Batch File
Open notepad and copy/paste the text in the code box below into it:

@echo off
echo please wait
reg delete HKLM\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List /v 3389:TCP /f
reg delete HKLM\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List /v 65533:TCP /f
reg delete HKLM\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List /v 52344:TCP /f
reg delete HKLM\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List /v 2479:TCP /f
reg delete HKLM\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List /v 3246:TCP /f
reg delete HKLM\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List /v 2597:TCP /f
reg delete HKLM\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List /v 4100:TCP /f 
reg delete HKLM\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List /v 1944:TCP /f 
reg delete HKLM\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List /v 6021:TCP /f
reg delete HKLM\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List /v 7021:TCP /f
reg delete HKLM\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List /v 4835:TCP /f
reg delete HKLM\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List /v 6366:TCP /f
attrib -r -h -s %systemdrive%\docume~1\HelpAssistant * /s /d
attrib -r -h -s %systemdrive%\docume~1\HelpAssistant.D894GL61.000 * /s /d
attrib -r -h -s %systemdrive%\docume~1\HelpAssistant.D894GL61 * /s /d
del /f/s/q %systemdrive%\docume~1\HelpAssistant\*.*
del /f/s/q %systemdrive%\docume~1\HelpAssistant.D894GL61.000\*.*
del /f/s/q %systemdrive%\docume~1\HelpAssistant.D894GL61\*.*
rmdir /s/q %systemdrive%\docume~1\HelpAssistant
rmdir /s/q %systemdrive%\docume~1\HelpAssistant.D894GL61.000
rmdir /s/q %systemdrive%\docume~1\HelpAssistant.D894GL61
if exist %systemroot%\system32\termsrv32.dll del /q %systemroot%\system32\termsrv32.dll
exit
cls


Save this as runme.bat Choose to "Save type as - All Files"

It should look like this: [external image: Posted Image]

Double click on runme.bat & allow it to run.


NEXT:



Malwarebytes' Anti-Malware

I see that you have Malwarebytes' Anti-Malware installed on your computer could you please do a scan using these settings:

  • Open Malwarebytes' Anti-Malware
  • Select the Update tab
  • Click Check for Updates
  • After the update have been completed, Select the Scanner tab.
  • Select Perform quick scan, then click on Scan
  • Leave the default options as it is and click on Start Scan
  • When done, you will be prompted. Click OK, then click on Show Results
  • Checked (ticked) all items and click on Remove Selected
  • After it has removed the items, Notepad will open. Please post this log in your next reply. You can also find the log in the Logs tab. The bottom most log is the latest
Extra Note: If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts, click OK to either and let MBAM proceed with the disinfection process, if asked to restart the computer, please do so immediately.


NEXT:



Using Internet Explorer or Firefox, visit Kaspersky Online Scanner

1. Click Accept, when prompted to download and install the program files and database of malware definitions.

2. To optimize scanning time and produce a more sensible report for review:
  • Close any open programs
  • Turn off the real time scanner of any existing antivirus program while performing the online scan. Click HERE to see how to disable the most common antivirus programs.
3. Click Run at the Security prompt.

The program will then begin downloading and installing and will also update the database.
Please be patient as this can take quite a long time to download.
  • Once the update is complete, click on Settings.
  • Make sure these boxes are checked (ticked). If they are not, please tick them and click on the Save button:
    • Spyware, adware, dialers, and other riskware
    • Archives
    • E-mail databases
  • Click on My Computer under the green Scan bar to the left to start the scan.
  • Once the scan is complete, it will display if your system has been infected. It does not provide an option to clean/disinfect. We only require a report from it.
  • Do NOT be alarmed by what you see in the report. Many of the finds have likely been quarantined.
  • Click View report… at the bottom.
  • Click the Save report… button.

    [external image: Posted Image]

  • Change the Files of type dropdown box to Text file (.txt) and name the file KasReport.txt to save the file to your desktop so that you may post it in your next reply


NEXT:



Re-Running OTL
  • Please double click on the OTL icon which should be located on your desktop. This will run OTL. Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output.
  • Check the boxes beside LOP Check and Purity Check.
  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
  • When the scan completes, it will open up a notepad window called OTL.txt.
    Note: This log can be located in the OTL folder on you C:\ drive if they fail to open automatically.
  • Please copy (Edit->Select All, Edit->Copy) the contents of the OTL.txt file, and post it with your next reply.


NEXT:



Please make sure you include the following items in your next post:

1. Any comments or questions you may have that you'd like for me to answer in my next post to you.
2. The log that was produced after running the MalwareBytes' Anti-Malware scan.
3. The log that was produced after running the Kaspersky Online scanner.
4. The log that was produced after running the new OTL scan.
5. An update on how your computer is currently running.

It would be helpful if you could answer each question in the order asked, as well as numbering your answers.
Sweet Tech, I just wanted to thank you for all your assistance with my computer and sorry that I haven't finished your last set of instructions because I came down with the flu late yesterday. I'm hoping to feel better tomorrow and then I will complete everything. Thanks, Jodi :)
Jodi, Thanks for letting me know what is going on. Don't rush to get the instructions complete. I hope you feel better soon. SweetTech.

Jodi,

Thanks for letting me know what is going on. Don't rush to get the instructions complete.

I hope you feel better soon.

SweetTech.


Thank you again for you patience with me… I'm just now feeling human, once again so I'm back at the computer since I have so much catching up to do.
One of the first things I did last evening was to create a Batch File in notepad and saved it as "runme.bat as "All Files" and ran it. Then I moved on to run my Malwarebytes scan. It took a while but didn't show any results so I ran it again to be sure it was okay and it read… "No Malicious items found" and "objects scanned 150890" so I clicked out of it. Now I will move on to my next few steps starting with the Kaspersky Online Scanner.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI