This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Please Help!

36 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Okay. For your information the Kaspersky Online Scanner can take a couple of hours to run.


Hi there! Would you still like me to do so at this time?




(also, I edited my post so that it shows all previous instructions were done.)

Yes, I would. I'd like to see what the scan turns up so that we have a better idea of where we stand.

Okay, I will begin it now!
The scan finished and it didn't have a report like the one in the instructions however, I did a cut and paste of the end report. Objects scanned: 104541 Threats found: 0 Infected objects found: 0 Suspicious objects found: 0 Scan duration: And since everything is okay I'll re-run the OTL
OTL:

OTL logfile created on: 3/17/2010 7:02:56 PM - Run 5
OTL by OldTimer - Version 3.1.37.0 Folder = C:\Documents and Settings\Jodi\Desktop
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

510.00 Mb Total Physical Memory | 289.00 Mb Available Physical Memory | 57.00% Memory free
1.00 Gb Paging File | 1.00 Gb Available in Paging File | 43.00% Paging File free
Paging file location(s): C:\pagefile.sys 768 1536 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 71.54 Gb Total Space | 27.10 Gb Free Space | 37.88% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: D894GL61
Current User Name: Jodi
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal

========== Processes (SafeList) ==========

PRC - C:\Documents and Settings\Jodi\Local Settings\Temp\jkos-Jodi\binaries\ScanningProcess.exe (Kaspersky Lab.)
PRC - C:\Program Files\AVG\AVG9\avgchsvx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG9\avgnsx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG9\avgrsx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG9\avgcsrvx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG9\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Documents and Settings\Jodi\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
PRC - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe (Google)
PRC - C:\Program Files\Java\jre6\bin\jucheck.exe (Sun Microsystems, Inc.)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe (Eastman Kodak Company)
PRC - C:\Program Files\Analog Devices\Core\smax4pnp.exe (Analog Devices, Inc.)
PRC - C:\Program Files\Logitech\Video\LogiTray.exe (Logitech Inc.)
PRC - C:\Program Files\Logitech\Video\FxSvr2.exe (Logitech Inc.)
PRC - C:\WINDOWS\SYSTEM32\LVCOMSX.EXE (Logitech Inc.)


========== Modules (SafeList) ==========

MOD - C:\Documents and Settings\Jodi\Desktop\OTL.exe (OldTimer Tools)


========== Win32 Services (SafeList) ==========

SRV - (avg9wd) – C:\Program Files\AVG\AVG9\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
SRV - (GoogleDesktopManager-110309-193829) – C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe (Google)
SRV - (YahooAUService) – C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe (Yahoo! Inc.)
SRV - (DSBrokerService) – C:\Program Files\DellSupport\brkrsvc.exe ()
SRV - (usnjsvc) – C:\Program Files\MSN Messenger\usnsvc.exe (Microsoft Corporation)


========== Driver Services (SafeList) ==========

DRV - (catchme) – File not found
DRV - (AvgTdiX) – C:\WINDOWS\System32\Drivers\avgtdix.sys (AVG Technologies CZ, s.r.o.)
DRV - (AvgMfx86) – C:\WINDOWS\System32\Drivers\avgmfx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (AvgLdx86) – C:\WINDOWS\System32\Drivers\avgldx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (amdagp) – C:\WINDOWS\system32\DRIVERS\amdagp.sys (Advanced Micro Devices, Inc.)
DRV - (sisagp) – C:\WINDOWS\system32\DRIVERS\sisagp.sys (Silicon Integrated Systems Corporation)
DRV - (dsunidrv) – C:\WINDOWS\SYSTEM32\DRIVERS\dsunidrv.sys (Gteko Ltd.)
DRV - (DSproct) – C:\Program Files\DellSupport\GTAction\triggers\DSproct.sys (Gteko Ltd.)
DRV - (drvmcdb) – C:\WINDOWS\system32\drivers\drvmcdb.sys (Sonic Solutions)
DRV - (PID_0928) Logitech QuickCam Express(PID_0928) – C:\WINDOWS\SYSTEM32\DRIVERS\LV561AV.SYS (Logitech Inc.)
DRV - (LVUSBSta) – C:\WINDOWS\SYSTEM32\DRIVERS\LVUSBSta.sys (Logitech Inc.)
DRV - (drvnddm) – C:\WINDOWS\SYSTEM32\DRIVERS\drvnddm.sys (Sonic Solutions)
DRV - (tfsnudfa) – C:\WINDOWS\SYSTEM32\dla\tfsnudfa.sys (Sonic Solutions)
DRV - (tfsnudf) – C:\WINDOWS\SYSTEM32\dla\tfsnudf.sys (Sonic Solutions)
DRV - (tfsnifs) – C:\WINDOWS\SYSTEM32\dla\tfsnifs.sys (Sonic Solutions)
DRV - (tfsncofs) – C:\WINDOWS\SYSTEM32\dla\tfsncofs.sys (Sonic Solutions)
DRV - (tfsnboio) – C:\WINDOWS\SYSTEM32\dla\tfsnboio.sys (Sonic Solutions)
DRV - (tfsnopio) – C:\WINDOWS\SYSTEM32\dla\tfsnopio.sys (Sonic Solutions)
DRV - (tfsnpool) – C:\WINDOWS\SYSTEM32\dla\tfsnpool.sys (Sonic Solutions)
DRV - (tfsndrct) – C:\WINDOWS\SYSTEM32\dla\tfsndrct.sys (Sonic Solutions)
DRV - (tfsndres) – C:\WINDOWS\SYSTEM32\dla\tfsndres.sys (Sonic Solutions)
DRV - (senfilt) – C:\WINDOWS\SYSTEM32\DRIVERS\senfilt.sys (Creative Technology Ltd.)
DRV - (nv) – C:\WINDOWS\SYSTEM32\DRIVERS\NV4_MINI.SYS (NVIDIA Corporation)
DRV - (sscdbhk5) – C:\WINDOWS\SYSTEM32\DRIVERS\sscdbhk5.sys (Sonic Solutions)
DRV - (ssrtln) – C:\WINDOWS\SYSTEM32\DRIVERS\ssrtln.sys (Sonic Solutions)
DRV - (IntelC53) – C:\WINDOWS\SYSTEM32\DRIVERS\IntelC53.sys (Intel Corporation)
DRV - (IntelC52) – C:\WINDOWS\SYSTEM32\DRIVERS\IntelC52.sys (Intel Corporation)
DRV - (IntelC51) – C:\WINDOWS\SYSTEM32\DRIVERS\IntelC51.sys (Intel Corporation)
DRV - (mohfilt) – C:\WINDOWS\SYSTEM32\DRIVERS\mohfilt.sys (Intel Corporation)
DRV - (pfc) – C:\WINDOWS\SYSTEM32\DRIVERS\pfc.sys (Padus, Inc.)
DRV - (Sparrow) – C:\WINDOWS\system32\DRIVERS\sparrow.sys (Adaptec, Inc.)
DRV - (sym_u3) – C:\WINDOWS\system32\DRIVERS\sym_u3.sys (LSI Logic)
DRV - (sym_hi) – C:\WINDOWS\system32\DRIVERS\sym_hi.sys (LSI Logic)
DRV - (symc8xx) – C:\WINDOWS\system32\DRIVERS\symc8xx.sys (LSI Logic)
DRV - (symc810) – C:\WINDOWS\system32\DRIVERS\symc810.sys (Symbios Logic Inc.)
DRV - (MODEMCSA) – C:\WINDOWS\SYSTEM32\DRIVERS\MODEMCSA.sys (Microsoft Corporation)
DRV - (ultra) – C:\WINDOWS\system32\DRIVERS\ultra.sys (Promise Technology, Inc.)
DRV - (ql12160) – C:\WINDOWS\system32\DRIVERS\ql12160.sys (QLogic Corporation)
DRV - (ql1080) – C:\WINDOWS\system32\DRIVERS\ql1080.sys (QLogic Corporation)
DRV - (ql1280) – C:\WINDOWS\system32\DRIVERS\ql1280.sys (QLogic Corporation)
DRV - (dac2w2k) – C:\WINDOWS\system32\DRIVERS\dac2w2k.sys (Mylex Corporation)
DRV - (mraid35x) – C:\WINDOWS\system32\DRIVERS\mraid35x.sys (American Megatrends Inc.)
DRV - (asc) – C:\WINDOWS\system32\DRIVERS\asc.sys (Advanced System Products, Inc.)
DRV - (asc3550) – C:\WINDOWS\system32\DRIVERS\asc3550.sys (Advanced System Products, Inc.)
DRV - (AliIde) – C:\WINDOWS\system32\DRIVERS\aliide.sys (Acer Laboratories Inc.)
DRV - (CmdIde) – C:\WINDOWS\system32\DRIVERS\cmdide.sys (CMD Technology, Inc.)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Secondary Start Pages = [Binary data over 100 bytes]
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomSearch = http://us.rd.yahoo.com/customize/ie/defaul…rch/search.html

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.google.com/ie
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local

========== FireFox ==========

FF - prefs.js..browser.search.defaultenginename: "Yahoo! Search"
FF - prefs.js..browser.search.defaulturl: "http://www.google.com/search?lr=&ie;=UTF-8&oe;=UTF-8&q;="
FF - prefs.js..browser.search.selectedEngine: "Google"
FF - prefs.js..browser.startup.homepage: "http://hamptonroads.cox.net/cci/home"
FF - prefs.js..extensions.enabledItems: {3f963a5b-e555-4543-90e2-c3908898db71}:9.0.0.716
FF - prefs.js..extensions.enabledItems: [removed]:1.0
FF - prefs.js..keyword.URL: "http://us.yhs.search.yahoo.com/avg/search?fr=yhs-avg&type;=yahoo_avg_hs2-tb-web_us&p;="


FF - HKLM\software\mozilla\Firefox\Extensions\\{3f963a5b-e555-4543-90e2-c3908898db71}: C:\Program Files\AVG\AVG9\Firefox [2010/03/14 09:24:57 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\{3112ca9c-de6d-4884-a869-9855de68056c}: C:\Documents and Settings\All Users\Application Data\Google\Toolbar for Firefox\{3112ca9c-de6d-4884-a869-9855de68056c} [2010/02/12 03:38:32 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.5.8\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010/03/13 13:09:04 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.5.8\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010/02/20 15:56:35 | 000,000,000 | —D | M]

[2008/09/08 17:30:46 | 000,000,000 | —D | M] – C:\Documents and Settings\Jodi\Application Data\Mozilla\Extensions
[2005/09/04 10:24:28 | 000,000,000 | —D | M] – C:\Documents and Settings\Jodi\Application Data\Mozilla\Firefox\Profiles\8otyaupt.default\extensions
[2006/07/04 22:55:46 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Jodi\Application Data\Mozilla\Firefox\Profiles\8otyaupt.default\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1}
[2005/01/20 19:48:01 | 000,000,000 | —D | M] (Firefox (default)) – C:\Documents and Settings\Jodi\Application Data\Mozilla\Firefox\Profiles\8otyaupt.default\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
[2010/03/16 18:54:26 | 000,000,000 | —D | M] – C:\Documents and Settings\Jodi\Application Data\Mozilla\Firefox\Profiles\zgepjo2r.Default User\extensions
[2009/12/22 07:48:43 | 000,000,000 | —D | M] (Google Toolbar for Firefox) – C:\Documents and Settings\Jodi\Application Data\Mozilla\Firefox\Profiles\zgepjo2r.Default User\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}
[2009/12/09 21:47:20 | 000,000,000 | —D | M] – C:\Documents and Settings\Jodi\Application Data\Mozilla\Firefox\Profiles\zgepjo2r.Default User\extensions\[removed]
[2010/03/16 18:54:26 | 000,000,000 | —D | M] – C:\Program Files\Mozilla Firefox\extensions
[2007/04/07 13:09:45 | 000,000,000 | —D | M] (Google Toolbar for Firefox) – C:\Program Files\Mozilla Firefox\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}
[2004/12/22 12:08:32 | 000,110,592 | —- | M] () – C:\Program Files\Mozilla Firefox\plugins\npmozax.dll

O1 HOSTS File: ([2010/03/13 17:21:14 | 000,000,027 | —- | M]) - C:\WINDOWS\SYSTEM32\DRIVERS\ETC\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (&Yahoo;! Toolbar Helper) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.)
O2 - BHO: (HP Print Enhancer) - {0347C33E-8762-4905-BF09-768834316C61} - C:\Program Files\HP\Smart Web Printing\hpswp_printenhancer.dll (Hewlett-Packard Co.)
O2 - BHO: (HP Print Clips) - {053F9267-DC04-4294-A72C-58F732D338C0} - C:\Program Files\HP\Smart Web Printing\hpswp_framework.dll (Hewlett-Packard Co.)
O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG9\avgssie.dll (AVG Technologies CZ, s.r.o.)
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O2 - BHO: (Yahoo! IE Services Button) - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll (Yahoo! Inc.)
O2 - BHO: (DriveLetterAccess) - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\SYSTEM32\dla\tfswshx.dll (Sonic Solutions)
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - No CLSID value found.
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.3.4501.1418\swg.dll (Google Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (&Google; Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll ()
O3 - HKCU\..\Toolbar\WebBrowser: (Yahoo! Toolbar) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.)
O4 - HKLM..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe (Apple Inc.)
O4 - HKLM..\Run: [Google Desktop Search] C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe (Google)
O4 - HKLM..\Run: [ISUSPM Startup] C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe (InstallShield Software Corporation)
O4 - HKLM..\Run: [ISUSScheduler] C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe (InstallShield Software Corporation)
O4 - HKLM..\Run: [LogitechVideoTray] C:\Program Files\Logitech\Video\LogiTray.exe (Logitech Inc.)
O4 - HKLM..\Run: [LVCOMSX] C:\WINDOWS\SYSTEM32\LVCOMSX.EXE (Logitech Inc.)
O4 - HKLM..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe (Analog Devices, Inc.)
O4 - HKLM..\Run: [UpdateManager] C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe (Sonic Solutions)
O4 - HKCU..\Run: [LogitechSoftwareUpdate] C:\Program Files\Logitech\Video\ManifestEngine.exe (Logitech Inc.)
O4 - HKCU..\Run: [Messenger (Yahoo!)] C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe (Yahoo! Inc.)
O4 - HKCU..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.)
O4 - HKLM..\RunOnce: [Malwarebytes' Anti-Malware] C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Kodak EasyShare software.lnk = C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe (Eastman Kodak Company)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE (Microsoft Corporation)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O8 - Extra context menu item: &Yahoo;! Search - C:\Program Files\Yahoo!\Common [2009/05/30 19:33:07 | 000,000,000 | —D | M]
O8 - Extra context menu item: Add to Google Photos Screensa&ver; - C:\WINDOWS\System32\GPhotos.scr (Google Inc.)
O8 - Extra context menu item: Yahoo! &Dictionary; - C:\Program Files\Yahoo!\Common [2009/05/30 19:33:07 | 000,000,000 | —D | M]
O8 - Extra context menu item: Yahoo! &Maps; - C:\Program Files\Yahoo!\Common [2009/05/30 19:33:07 | 000,000,000 | —D | M]
O8 - Extra context menu item: Yahoo! &SMS; - C:\Program Files\Yahoo!\Common [2009/05/30 19:33:07 | 000,000,000 | —D | M]
O9 - Extra Button: HP Clipbook - {58ECB495-38F0-49cb-A538-10282ABF65E7} - C:\Program Files\HP\Smart Web Printing\hpswp_extensions.dll (Hewlett-Packard Co.)
O9 - Extra Button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll (Yahoo! Inc.)
O9 - Extra Button: HP Smart Select - {700259D7-1666-479a-93B1-3250410481E8} - C:\Program Files\HP\Smart Web Printing\hpswp_extensions.dll (Hewlett-Packard Co.)
O9 - Extra Button: MUSICMATCH MX Web Player - {d81ca86b-ef63-42af-bee3-4502d9a03c2d} - File not found
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O15 - HKCU\..Trusted Domains: artistarena.com ([tix] https in Trusted sites)
O15 - HKCU\..Trusted Domains: localhost ([]http in Local intranet)
O15 - HKCU\..Trusted Ranges: GD ([http] in Local intranet)
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://fpdownload.macromedia.com/get/shock…director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://download.microsoft.com/download/9/b…heckControl.cab (Windows Genuine Advantage Validation Tool)
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} C:\Program Files\Yahoo!\Common\yinsthelper.dll (YInstStarter Class)
O16 - DPF: {3E68E405-C6DE-49FF-83AE-41EE9F4C36CE} http://office.microsoft.com/officeupdate/content/opuc2.cab (Office Update Installation Engine)
O16 - DPF: {474F00F5-3853-492C-AC3A-476512BBC336} http://picasaweb.google.com/s/v/23.30/uploader2.cab (UploadListView Class)
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} http://v5.windowsupdate.microsoft.com/v5co…b?1106262745037 (WUWebControl Class)
O16 - DPF: {6F750203-1362-4815-A476-88533DE61D0C} http://www.kodakgallery.com/downloads/BUM/…_2/axofupld.cab (Kodak Gallery Easy Upload Manager Class)
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} http://download.eset.com/special/eos/OnlineScanner.cab (OnlineScanner Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_15)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get/flash…t/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_15)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_15)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload.macromedia.com/get/flash…ent/swflash.cab (Shockwave Flash Object)
O16 - DPF: {EBF85371-A38F-485B-B28F-0B4C82D25937} http://update.hpphoto.com/download/HPSWUpdate.ocx (CUpdateCtl Object)
O16 - DPF: {FE0BD779-44EE-4A4B-AA2E-743C63F2E5E6} http://pdl.stream.aol.com/downloads/aol/unagi/ampx_en_dl.cab (IWinAmpActiveX Class)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = [removed] [removed] [removed]
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG9\avgpp.dll (AVG Technologies CZ, s.r.o.)
O18 - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\MSN Messenger\msgrapp.8.1.0178.00.dll (Microsoft Corporation)
O18 - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\MSN Messenger\msgrapp.8.1.0178.00.dll (Microsoft Corporation)
O18 - Protocol\Handler\offline-8876480 {A51AD373-9572-47E7-8B36-550FB14F819E} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (Logitech)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\avgrsstarter: DllName - avgrsstx.dll - C:\WINDOWS\System32\avgrsstx.dll (AVG Technologies CZ, s.r.o.)
O20 - Winlogon\Notify\dimsntfy: DllName - - File not found
O20 - Winlogon\Notify\igfxcui: DllName - igfxdev.dll - C:\WINDOWS\System32\igfxdev.dll (Intel Corporation)
O24 - Desktop WallPaper: C:\Documents and Settings\Jodi\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Jodi\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2004/08/10 15:04:08 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKCU\…com [@ = ComFile] – Reg Error: Key error. File not found
O37 - HKCU\…exe [@ = exefile] – Reg Error: Key error. File not found

========== Files/Folders - Created Within 30 Days ==========

[2010/03/14 09:25:00 | 000,012,464 | —- | C] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\avgrsstx.dll.prepare
[2010/03/14 00:21:18 | 000,000,000 | —D | C] – C:\Program Files\Winamp
[2010/03/13 16:47:42 | 000,212,480 | —- | C] (SteelWerX) – C:\WINDOWS\SWXCACLS.exe
[2010/03/13 16:47:42 | 000,161,792 | —- | C] (SteelWerX) – C:\WINDOWS\SWREG.exe
[2010/03/13 16:47:42 | 000,136,704 | —- | C] (SteelWerX) – C:\WINDOWS\SWSC.exe
[2010/03/13 16:47:42 | 000,031,232 | —- | C] (NirSoft) – C:\WINDOWS\NIRCMD.exe
[2010/03/13 16:47:00 | 000,000,000 | —D | C] – C:\Qoobox
[2010/03/13 16:24:25 | 000,000,000 | —D | C] – C:\$AVG
[2010/03/13 16:22:47 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\avg9
[2010/03/13 16:18:58 | 000,000,000 | —D | M] – C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft
[2010/03/13 16:18:58 | 000,000,000 | —D | M] – C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft
[2010/03/13 16:18:57 | 000,000,000 | –SD | M] – C:\Documents and Settings\NetworkService\Application Data\Microsoft
[2010/03/13 16:18:57 | 000,000,000 | –SD | M] – C:\Documents and Settings\LocalService\Application Data\Microsoft
[2010/03/12 19:15:02 | 000,891,248 | —- | C] (AVG Technologies) – C:\Documents and Settings\Jodi\Desktop\avg_free_stb_all_9_40_cnet.exe
[2010/03/12 16:18:57 | 000,555,520 | —- | C] (OldTimer Tools) – C:\Documents and Settings\Jodi\Desktop\OTL.exe
[2010/03/12 15:00:13 | 000,000,000 | RH-D | C] – C:\Documents and Settings\Jodi\Recent
[2010/03/10 06:52:54 | 003,558,912 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\moviemk.exe
[2010/02/24 13:16:56 | 000,000,000 | —D | C] – C:\WINDOWS\Minidump
[2009/12/25 03:44:04 | 000,000,000 | —D | M] – C:\Documents and Settings\NetworkService\Local Settings\Application Data\Google
[2009/12/25 03:40:04 | 000,000,000 | —D | M] – C:\Documents and Settings\LocalService\Local Settings\Application Data\Google
[2007/09/13 23:21:03 | 000,000,000 | —D | M] – C:\Documents and Settings\NetworkService\Local Settings\Application Data\Apple
[2007/03/13 11:06:13 | 000,000,000 | —D | M] – C:\Documents and Settings\NetworkService\Application Data\Symantec
[2005/02/04 17:36:49 | 000,000,000 | —D | M] – C:\Documents and Settings\LocalService\Application Data\McAfee.com
[2005/01/23 19:43:19 | 000,000,000 | -H-D | M] – C:\Documents and Settings\LocalService\Application Data\GTek
[2005/01/21 21:29:53 | 000,000,000 | —D | M] – C:\Documents and Settings\LocalService\Local Settings\Application Data\Identities
[2005/01/20 23:29:33 | 000,000,000 | —D | M] – C:\Documents and Settings\LocalService\Application Data\Mozilla
[2005/01/20 18:51:41 | 000,000,000 | —D | M] – C:\Documents and Settings\LocalService\Application Data\McAfee.com Personal Firewall
[4 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[3 C:\Documents and Settings\Jodi\My Documents\*.tmp files -> C:\Documents and Settings\Jodi\My Documents\*.tmp -> ]
[12 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[1 C:\*.tmp files -> C:\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2010/03/17 18:49:04 | 000,000,886 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2010/03/17 12:12:21 | 000,000,868 | —- | M] () – C:\WINDOWS\tasks\Google Software Updater.job
[2010/03/17 09:49:01 | 000,000,882 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2010/03/17 09:23:12 | 057,241,725 | —- | M] () – C:\WINDOWS\System32\drivers\Avg\incavi.avm
[2010/03/16 18:06:43 | 000,002,415 | —- | M] () – C:\Documents and Settings\Jodi\Desktop\runme.bat
[2010/03/15 19:27:59 | 000,052,295 | —- | M] () – C:\Documents and Settings\Jodi\My Documents\Mom and Chelsea.jpg
[2010/03/15 17:18:03 | 000,000,284 | —- | M] () – C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2010/03/14 20:24:08 | 000,002,473 | —- | M] () – C:\Documents and Settings\Jodi\Desktop\Microsoft Word.lnk
[2010/03/14 09:25:03 | 000,242,696 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\drivers\avgtdix.sys
[2010/03/14 09:25:00 | 000,029,512 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\drivers\avgmfx86.sys
[2010/03/14 09:25:00 | 000,012,464 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\avgrsstx.dll.prepare
[2010/03/14 09:23:50 | 000,216,200 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\drivers\avgldx86.sys
[2010/03/13 17:24:39 | 000,036,420 | —- | M] () – C:\logfile
[2010/03/13 17:21:45 | 000,000,227 | —- | M] () – C:\WINDOWS\system.ini
[2010/03/13 17:21:14 | 000,000,027 | —- | M] () – C:\WINDOWS\System32\drivers\ETC\hosts
[2010/03/13 17:20:37 | 000,002,206 | —- | M] () – C:\WINDOWS\System32\WPA.DBL
[2010/03/13 17:05:05 | 000,000,006 | -H– | M] () – C:\WINDOWS\tasks\SA.DAT
[2010/03/13 17:05:01 | 534,827,008 | -HS- | M] () – C:\hiberfil.sys
[2010/03/13 17:05:01 | 000,002,048 | –S- | M] () – C:\WINDOWS\BOOTSTAT.DAT
[2010/03/13 17:04:17 | 007,864,320 | —- | M] () – C:\Documents and Settings\Jodi\ntuser.dat
[2010/03/13 17:04:04 | 000,000,278 | -HS- | M] () – C:\Documents and Settings\Jodi\NTUSER.INI
[2010/03/13 16:23:51 | 000,142,495 | —- | M] () – C:\WINDOWS\System32\drivers\Avg\microavi.avg
[2010/03/13 16:23:29 | 000,001,507 | —- | M] () – C:\Documents and Settings\All Users\Desktop\AVG Free 9.0.lnk
[2010/03/13 16:23:27 | 000,113,461 | —- | M] () – C:\WINDOWS\System32\drivers\Avg\iavichjw.avm
[2010/03/13 16:23:27 | 000,012,464 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\avgrsstx.dll
[2010/03/13 15:44:52 | 003,888,953 | R— | M] () – C:\Documents and Settings\Jodi\Desktop\ComboFix.exe
[2010/03/12 21:09:39 | 000,077,312 | —- | M] () – C:\mbr.exe
[2010/03/12 19:41:56 | 000,412,056 | —- | M] () – C:\Documents and Settings\Jodi\Desktop\HelpAsst_mebroot_fix.exe
[2010/03/12 19:41:05 | 000,891,248 | —- | M] (AVG Technologies) – C:\Documents and Settings\Jodi\Desktop\avg_free_stb_all_9_40_cnet.exe
[2010/03/12 19:12:22 | 000,485,688 | —- | M] () – C:\Documents and Settings\Jodi\Desktop\HAMeb_check.exe
[2010/03/12 17:14:57 | 000,293,376 | —- | M] () – C:\Documents and Settings\Jodi\Desktop\fnn0bxzu.exe
[2010/03/12 16:18:58 | 000,555,520 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Jodi\Desktop\OTL.exe
[2010/03/06 13:28:11 | 000,001,729 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Adobe Reader 9.lnk
[2010/03/02 12:52:55 | 000,002,137 | —- | M] () – C:\Documents and Settings\Jodi\Desktop\iTunes.lnk
[2010/02/27 22:13:32 | 000,029,473 | —- | M] () – C:\Documents and Settings\Jodi\My Documents\Steve avatar.jpg
[2010/02/27 18:49:06 | 000,061,066 | —- | M] () – C:\Documents and Settings\Jodi\My Documents\back of my hair.jpg
[2010/02/26 23:42:25 | 000,028,672 | —- | M] () – C:\Documents and Settings\Jodi\Desktop\Prayer List for Feb 28.doc
[2010/02/26 23:41:16 | 000,019,456 | —- | M] () – C:\Documents and Settings\Jodi\Desktop\KA Quotes.doc
[2010/02/26 13:07:39 | 000,051,200 | —- | M] () – C:\Documents and Settings\Jodi\Desktop\Prayer Chain List updated 2.26.2010.doc
[2010/02/26 12:52:32 | 000,092,672 | —- | M] () – C:\Documents and Settings\Jodi\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/02/26 12:43:14 | 000,024,064 | —- | M] () – C:\Documents and Settings\Jodi\Desktop\Cover Letter for Jodi 2.doc
[2010/02/26 12:42:50 | 000,024,064 | —- | M] () – C:\Documents and Settings\Jodi\Desktop\Cover Letter for Zales.doc
[2010/02/25 13:51:36 | 000,140,757 | —- | M] () – C:\Documents and Settings\Jodi\My Documents\My new ring.jpg
[2010/02/25 13:50:59 | 001,151,427 | —- | M] () – C:\Documents and Settings\Jodi\My Documents\my work area.jpg
[2010/02/17 16:40:57 | 000,054,345 | —- | M] () – C:\Documents and Settings\Jodi\My Documents\Ryan Prom.jpg
[2010/02/17 16:40:11 | 000,038,775 | —- | M] () – C:\Documents and Settings\Jodi\My Documents\Ryan Guilford track.jpg
[2010/02/17 16:39:03 | 000,077,879 | —- | M] () – C:\Documents and Settings\Jodi\My Documents\Ryan Guilford cross country race 3.jpg
[2010/02/17 15:06:16 | 000,065,158 | —- | M] () – C:\Documents and Settings\Jodi\My Documents\Ryan Guilford cross country race 2.jpg
[2010/02/17 15:05:51 | 000,077,879 | —- | M] () – C:\Documents and Settings\Jodi\My Documents\Ryan Guilford cross country race.jpg
[2010/02/17 15:04:07 | 000,039,571 | —- | M] () – C:\Documents and Settings\Jodi\My Documents\Ryan Turkey Trot 2009.jpg
[2010/02/17 15:02:23 | 000,030,389 | —- | M] () – C:\Documents and Settings\Jodi\My Documents\Ryan winter 2010.jpg
[2010/02/16 20:07:35 | 005,127,013 | —- | M] () – C:\Documents and Settings\Jodi\My Documents\She's_Got_You.wmv
[2010/02/15 21:28:52 | 000,030,154 | —- | M] () – C:\Documents and Settings\Jodi\My Documents\Robby and the crowd.jpg
[4 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[3 C:\Documents and Settings\Jodi\My Documents\*.tmp files -> C:\Documents and Settings\Jodi\My Documents\*.tmp -> ]
[12 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[1 C:\*.tmp files -> C:\*.tmp -> ]

========== Files Created - No Company Name ==========

[2010/03/16 18:06:43 | 000,002,415 | —- | C] () – C:\Documents and Settings\Jodi\Desktop\runme.bat
[2010/03/15 19:27:57 | 000,052,295 | —- | C] () – C:\Documents and Settings\Jodi\My Documents\Mom and Chelsea.jpg
[2010/03/13 16:47:42 | 000,261,632 | —- | C] () – C:\WINDOWS\PEV.exe
[2010/03/13 16:47:42 | 000,098,816 | —- | C] () – C:\WINDOWS\sed.exe
[2010/03/13 16:47:42 | 000,080,412 | —- | C] () – C:\WINDOWS\grep.exe
[2010/03/13 16:47:42 | 000,077,312 | —- | C] () – C:\WINDOWS\MBR.exe
[2010/03/13 16:47:42 | 000,068,096 | —- | C] () – C:\WINDOWS\zip.exe
[2010/03/13 16:23:29 | 000,001,507 | —- | C] () – C:\Documents and Settings\All Users\Desktop\AVG Free 9.0.lnk
[2010/03/13 15:44:51 | 003,888,953 | R— | C] () – C:\Documents and Settings\Jodi\Desktop\ComboFix.exe
[2010/03/12 21:09:39 | 000,077,312 | —- | C] () – C:\mbr.exe
[2010/03/12 19:41:55 | 000,412,056 | —- | C] () – C:\Documents and Settings\Jodi\Desktop\HelpAsst_mebroot_fix.exe
[2010/03/12 19:12:21 | 000,485,688 | —- | C] () – C:\Documents and Settings\Jodi\Desktop\HAMeb_check.exe
[2010/03/12 17:14:55 | 000,293,376 | —- | C] () – C:\Documents and Settings\Jodi\Desktop\fnn0bxzu.exe
[2010/02/27 22:13:32 | 000,029,473 | —- | C] () – C:\Documents and Settings\Jodi\My Documents\Steve avatar.jpg
[2010/02/27 18:49:06 | 000,061,066 | —- | C] () – C:\Documents and Settings\Jodi\My Documents\back of my hair.jpg
[2010/02/26 23:42:25 | 000,028,672 | —- | C] () – C:\Documents and Settings\Jodi\Desktop\Prayer List for Feb 28.doc
[2010/02/26 23:41:16 | 000,019,456 | —- | C] () – C:\Documents and Settings\Jodi\Desktop\KA Quotes.doc
[2010/02/26 12:51:31 | 000,002,137 | —- | C] () – C:\Documents and Settings\Jodi\Desktop\iTunes.lnk
[2010/02/26 12:49:43 | 000,051,200 | —- | C] () – C:\Documents and Settings\Jodi\Desktop\Prayer Chain List updated 2.26.2010.doc
[2010/02/25 13:51:36 | 000,140,757 | —- | C] () – C:\Documents and Settings\Jodi\My Documents\My new ring.jpg
[2010/02/25 13:50:57 | 001,151,427 | —- | C] () – C:\Documents and Settings\Jodi\My Documents\my work area.jpg
[2010/02/23 13:42:28 | 000,024,064 | —- | C] () – C:\Documents and Settings\Jodi\Desktop\Cover Letter for Zales.doc
[2010/02/17 16:40:56 | 000,054,345 | —- | C] () – C:\Documents and Settings\Jodi\My Documents\Ryan Prom.jpg
[2010/02/17 16:40:11 | 000,038,775 | —- | C] () – C:\Documents and Settings\Jodi\My Documents\Ryan Guilford track.jpg
[2010/02/17 16:39:03 | 000,077,879 | —- | C] () – C:\Documents and Settings\Jodi\My Documents\Ryan Guilford cross country race 3.jpg
[2010/02/17 15:06:15 | 000,065,158 | —- | C] () – C:\Documents and Settings\Jodi\My Documents\Ryan Guilford cross country race 2.jpg
[2010/02/17 15:05:51 | 000,077,879 | —- | C] () – C:\Documents and Settings\Jodi\My Documents\Ryan Guilford cross country race.jpg
[2010/02/17 15:04:07 | 000,039,571 | —- | C] () – C:\Documents and Settings\Jodi\My Documents\Ryan Turkey Trot 2009.jpg
[2010/02/17 15:02:19 | 000,030,389 | —- | C] () – C:\Documents and Settings\Jodi\My Documents\Ryan winter 2010.jpg
[2010/02/16 20:07:28 | 005,127,013 | —- | C] () – C:\Documents and Settings\Jodi\My Documents\She's_Got_You.wmv
[2010/02/15 21:28:49 | 000,030,154 | —- | C] () – C:\Documents and Settings\Jodi\My Documents\Robby and the crowd.jpg
[2009/04/22 11:54:34 | 000,000,072 | —- | C] () – C:\WINDOWS\CmdPrint.INI
[2008/08/24 15:16:56 | 000,870,128 | —- | C] () – C:\Documents and Settings\Jodi\Application Data\mcs.rma
[2008/08/24 15:16:56 | 000,000,004 | —- | C] () – C:\Documents and Settings\Jodi\Application Data\901D7A
[2008/02/10 16:37:00 | 000,006,518 | —- | C] () – C:\Documents and Settings\All Users\Application Data\hpzinstall.log
[2007/02/20 11:58:31 | 000,000,054 | —- | C] () – C:\WINDOWS\gbsaver.ini
[2007/02/03 19:38:05 | 000,000,002 | —- | C] () – C:\WINDOWS\msoffice.ini
[2006/01/30 15:55:26 | 000,000,072 | —- | C] () – C:\WINDOWS\CmdFile.INI
[2005/12/15 22:45:22 | 000,001,382 | —- | C] () – C:\Documents and Settings\All Users\Application Data\QTSBandwidthCache
[2005/11/18 20:28:29 | 000,000,112 | —- | C] () – C:\WINDOWS\ActiveSkin.INI
[2005/11/17 20:12:48 | 000,000,000 | —- | C] () – C:\WINDOWS\RAWImage.INI
[2005/07/29 16:13:50 | 000,000,044 | —- | C] () – C:\WINDOWS\liveup.ini
[2005/04/15 16:45:25 | 000,009,254 | R— | C] () – C:\WINDOWS\System32\lvcoinst.ini
[2005/04/11 18:59:34 | 000,092,672 | —- | C] () – C:\Documents and Settings\Jodi\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2005/01/28 19:34:02 | 000,000,376 | —- | C] () – C:\WINDOWS\ODBC.INI
[2005/01/24 21:49:46 | 000,000,000 | —- | C] () – C:\WINDOWS\OpPrintServer.INI
[2005/01/24 21:43:11 | 000,007,680 | —- | C] () – C:\WINDOWS\System32\CNMVS66.DLL
[2005/01/21 14:25:12 | 000,002,516 | -HS- | C] () – C:\WINDOWS\System32\KGyGaAvL.sys
[2005/01/20 22:47:24 | 000,004,687 | —- | C] () – C:\WINDOWS\cdPlayer.ini
[2005/01/20 21:04:44 | 000,061,678 | —- | C] () – C:\Documents and Settings\Jodi\Application Data\PFP120JPR.{PB
[2005/01/20 21:04:44 | 000,012,358 | —- | C] () – C:\Documents and Settings\Jodi\Application Data\PFP120JCM.{PB
[2005/01/17 23:15:12 | 000,000,061 | —- | C] () – C:\WINDOWS\smscfg.ini
[2005/01/17 23:07:48 | 000,000,262 | —- | C] () – C:\WINDOWS\wininit.ini
[2005/01/17 22:36:18 | 000,000,520 | —- | C] () – C:\WINDOWS\System32\OEMINFO.INI
[2004/09/16 00:03:14 | 000,000,000 | —- | C] () – C:\WINDOWS\System32\px.ini
[2004/08/10 15:13:12 | 000,000,780 | —- | C] () – C:\WINDOWS\ORUN32.INI
[2004/08/04 07:00:00 | 000,001,793 | —- | C] () – C:\WINDOWS\System32\FXSPERF.INI
[1999/01/27 13:39:06 | 000,065,024 | —- | C] () – C:\WINDOWS\System32\indounin.dll
[1999/01/22 14:46:56 | 000,065,536 | —- | C] () – C:\WINDOWS\System32\MSRTEDIT.DLL
[1997/06/13 07:56:08 | 000,056,832 | —- | C] () – C:\WINDOWS\System32\Iyvu9_32.dll
[1980/01/01 02:00:00 | 000,012,288 | —- | C] () – C:\WINDOWS\System32\e100bmsg.dll

========== LOP Check ==========

[2010/03/13 16:22:49 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\avg9
[2008/06/26 17:54:20 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Grisoft
[2008/05/25 16:57:21 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\SupportSoft
[2007/03/20 10:32:29 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TEMP
[2009/03/13 19:02:53 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{00D89592-F643-4D8D-8F0F-AFAE0F14D4C3}
[2009/09/12 10:54:10 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{755AC846-7372-4AC8-8550-C52491DAA8BD}
[2009/05/04 17:28:38 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906}
[2008/12/17 18:46:36 | 000,000,000 | —D | M] – C:\Documents and Settings\Jodi\Application Data\ByteCrusher
[2005/06/02 12:05:33 | 000,000,000 | —D | M] – C:\Documents and Settings\Jodi\Application Data\Leadertech
[2009/08/11 13:40:59 | 000,000,000 | —D | M] – C:\Documents and Settings\Jodi\Application Data\Musicmatch
[2006/01/13 18:03:47 | 000,000,000 | —D | M] – C:\Documents and Settings\Jodi\Application Data\MyPublisher
[2006/01/16 14:10:09 | 000,000,000 | —D | M] – C:\Documents and Settings\Jodi\Application Data\Pixmantec
[2007/10/27 18:34:51 | 000,000,000 | —D | M] – C:\Documents and Settings\Jodi\Application Data\SecondLife
[2008/05/25 10:11:26 | 000,000,000 | —D | M] – C:\Documents and Settings\Jodi\Application Data\Uniblue
[2008/12/18 10:33:18 | 000,000,000 | —D | M] – C:\Documents and Settings\Jodi\Application Data\WinPatrol

========== Purity Check ==========



========== Alternate Data Streams ==========

@Alternate Data Stream - 118 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:DFC5A2B2
< End of report >
Please make sure you include the following items in your next post: 1. Any comments or questions you may have that you'd like for me to answer in my next post to you. Do you know how I caught this virus? Like via a web site or email? 2. The log that was produced after running the MalwareBytes' Anti-Malware scan. Done. 3. The log that was produced after running the Kaspersky Online scanner. Done. 4. The log that was produced after running the new OTL scan. Done. 5. An update on how your computer is currently running. My computer is running fantastic! :woot:
OTL Fix
Run OTL.exe
  • Copy/paste the following text written inside of the code box into the Custom Scans/Fixes box located at the bottom of OTL

    :Services
    :OTL
    DRV - (catchme) – File not found
    O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - No CLSID value found.
    O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
    O9 - Extra Button: MUSICMATCH MX Web Player - {d81ca86b-ef63-42af-bee3-4502d9a03c2d} - File not found
    O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get/flash…t/ultrashim.cab (Reg Error: Key error.)
    O20 - Winlogon\Notify\dimsntfy: DllName - - File not found
    [4 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
    [3 C:\Documents and Settings\Jodi\My Documents\*.tmp files -> C:\Documents and Settings\Jodi\My Documents\*.tmp -> ]
    [12 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
    [1 C:\*.tmp files -> C:\*.tmp -> ]
    @Alternate Data Stream - 118 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:DFC5A2B2
    :Commands
    [EMPTYFLASH]
    [emptytemp]
    [start explorer]
    [Reboot]
  • Then click the Run Fix button at the top
  • Let the program run unhindered, reboot when it is done

NEXT:



Java Outdated
Your Java is out of date. Older versions have vulnerabilities that malware can use to infect your system.
Please follow these steps to remove older version Java components and update.

  • Download the latest version of Java Runtime Environment (JRE) 6 and save it to your desktop.
  • Scroll down to where it says "Java SE Runtime Environment (JRE) 6 Update 18. The Java SE Runtime Environment (JRE) allows end-users to run Java applications."
  • Click the "Download" button to the right.
  • Select the Windows platform from the drop-down menu.
  • Read the License Agreement and then check the box that says: " I agree to the Java SE Runtime Environment 6 with JavaFX License Agreement". Click on Continue.The page will refresh.
  • Click on the link to download Windows Offline Installation and save the file to your desktop.
  • Close any programs you may have running - especially your web browser.
  • Now go to Start > Settings > Control Panel, double-click on Add/Remove Programs and remove all older versions of Java.
  • Check (highlight) any item with Java Runtime Environment (JRE or J2SE or Java™ 6) in the name.
  • Click the Remove or Change/Remove button.
  • Repeat as many times as necessary to remove each Java version.
  • Reboot your computer once all Java components are removed.
  • Then from your desktop double-click on jre-6u18-windows-i586-p.exe to install the newest version.
  • After the install is complete, go into the Control Panel (using Classic View) and double-click the Java Icon. (looks like a coffee cup)
    • On the General tab, under Temporary Internet Files, click the Settings button.
    • Next, click on the Delete Files button
    • There are two options in the window to clear the cache - Leave BOTH CheckedApplications and AppletsTrace and Log Files
  • Click OK on Delete Temporary Files Window

    Note: This deletes ALL the Downloaded Applications and Applets from the CACHE.
  • Click OK to leave the Temporary Files Window
  • Click OK to leave the Java Control Panel.

NEXT:



Update FireFox
While in Firefox go to the Help menu.
Locate Check for Updates.
Allow Firefox to install the latest update. Which is 3.6



NEXT:



Firewall

Looking over your log it seems you don't have any evidence of a third party FIREWALL. As the term conveys a firewall is an extra layer of security installed onto computers which restricts access to systems from the outside world. Firewalls protect against hackers and malicious intruders.

If you are using the built-in Windows XP firewall it is not recommended as it does not block outgoing connections. This means that any malware on your computer is free to phone home for more instructions. Simply put Windows XP contains a mediocre firewall. This firewall is NO replacement for a dedicated software solution. Remember to use only one firewall at the same time.

I would recommend to install install a free firewall for personal use from one of these excellent vendors. Choice is yours:


NEXT:



Time for some housekeeping
The following will implement some cleanup procedures as well as reset System Restore points:
[external image: Posted Image]
Click Start > Run and copy/paste the following bolded text into the Run box and click OK: ComboFix /Uninstall



NEXT:



OTL Clean-Up
Clean up with OTL:
  • Double-click OTL.exe to start the program.
  • Close all other programs apart from OTL as this step will require a reboot
  • On the OTL main screen, press the CLEANUP button
  • Say Yes to the prompt and then allow the program to reboot your computer.
If you still have any tools or logs leftover on your computer you can go ahead and delete those off of your computer now.



NEXT:



All Clean Speech

===> Make sure you've re-enabled any Security Programs that we may have disabled during the malware removal process. <===

Below I have included a number of recommendations for how to protect your computer against malware infections.
  • It is good security practice to change your passwords to all your online accounts on a fairly regular basis, this is especially true after an infection. Refer to this Microsoft article
    Strong passwords: How to create and use them
    then consider a password keeper, to keep all your passwords safe.
  • Keep Windows updated by regularly checking their website at: http://windowsupdate.microsoft.com/
    This will ensure your computer has always the latest security updates available installed on your computer.
  • SpywareBlaster protects against bad ActiveX, it immunizes your PC against them.
  • SpywareGuard offers realtime protection from spyware installation attempts. Make sure you are only running one real-time anti-spyware protection program ( eg : TeaTimer, Windows Defender ) or there will be a conflict.
  • Make Internet Explorer more secure
    • Click Start > Run
    • Type Inetcpl.cpl & click OK
    • Click on the Security tab
    • Click Reset all zones to default level
    • Make sure the Internet Zone is selected & Click Custom level
    • In the ActiveX section, set the first two options ("Download signed and unsigned ActiveX controls) to "Prompt", and ("Initialize and Script ActiveX controls not marked as safe") to "Disable".
    • Next Click OK, then Apply button and then OK to exit the Internet Properties page.
  • ATF Cleaner - Cleans temporary files from IE and Windows, empties the recycle bin and more. Great tool to help speed up your computer and knock out those nasties that like to reside in the temp folders.
  • MVPS Hosts file replaces your current HOSTS file with one containing well known ad sites and other bad sites. Basically, this prevents your computer from connecting to those sites by redirecting them to 127.0.0.1 which is your local computer, meaning it will be difficult to infect yourself in the future.
  • WOT, Web of Trust, warns you about risky websites that try to scam visitors, deliver malware or send spam. Protect your computer against online threats by using WOT as your front-line layer of protection when browsing or searching in unfamiliar territory. WOT's color-coded icons show you ratings for 21 million websites, helping you avoid the dangerous sites:
    • Green to go
    • Yellow for caution
    • Red to stop
    WOT has an addon available for both Firefox and IE
  • Please consider using an alternate browser. Mozilla's Firefox browser is fantastic; it is much more secure than Internet Explorer, immune to almost all known browser hijackers, and also has the best built-in pop up blocker (as an added benefit!) that I have ever seen. If you are interested, Firefox may be downloaded from Here
    • If you choose to use Firefox, I highly recommend this add-on to keep your PC even more secure.
      • NoScript - for blocking ads and other potential website attacks
  • Keep a backup of your important files - Now, more than ever, it's especially important to protect your digital files and memories. This article is full of good information on alternatives for home backup solutions.
  • ERUNT (Emergency Recovery Utility NT) allows you to keep a complete backup of your registry and restore it when needed. The standard registry backup options that come with Windows back up most of the registry but not all of it. ERUNT however creates a complete backup set, including the Security hive and user related sections. ERUNT is easy to use and since it creates a full backup, there are no options or choices other than to select the location of the backup files. The backup set includes a small executable that will launch the registry restore if needed.
  • In light of your recent issue, I'm sure you'd like to avoid any future infections. Please take a look at these well written articles:
    Think Prevention.
    PC Safety and Security–What Do I Need?.
**Be very wary with any security software that is advertised in popups or in other ways. They are not only usually of no use, but often have malware in them.

Thank you for your patience, and performing all of the procedures requested.

Please respond one last time so we can consider the thread resolved and close it, thank-you.

The Java Installation file said this after you finished installing it?


It never installed it and now the link on my desktop is gone. I've never seen that happen before.

Are you still making your way down through my instructions?


Yes. I was having a little trouble answering questions while downloading my Comodo Firewall Protection. I hope I made all the right choices. I will continue on as much as I can tonight and will have to leave some of the rest for the morning as it's 10pm on the East Coast.

I will read as much of the "all clean speech" tonight and save the rest for tomorrow.

Thanks for being so thorough as well as patient and kind.
Nite! :)

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI