This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] AntiVirus XP and Your Protection

40 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

OK, hello all. Here's my brother's Dell Dimension 8300 with a huge infection or more precisely "set of infections". XP Pro SP3. 80 gig drive 65% full. Used mostly for browsing and picture development. He wasn't aware that his AV had elapsed and it didn't take long.

I have gone thru the initial steps found at: http://forums.whatthetech.com/Before_Posti…elp_t57813.html. However, these steps are thwarted because they're being intercepted by the malware. Example: Step 1: Tried SysRestorePoint. It runs & says Restore Point successfully created but then right after that Restore Point failed! I can't check the restore points as the sys says group policy is not set (the malware probably again). Task Mgr is disabled. MSCONFIG: unchecked fomehelaro and rohenahoz but of course they come back. Regedit: removed the calls for Rundll32.exe fodulivu.dll and topapope.dll from the keys (HKLM/Microsoft/CurrVers etc.) but they return. Attempted to load in MBAM but after the installer runs and we try to launch, mbam.exe it has disappeared (probably defeated by the malware). So as much as I'd have like to have all the logs ready to go here, I think I need help getting the system into some sort of better working shape so we can do the logs and deal with the problem. Also, on standard boot, I only get a few minutes of run time before the thing simply hangs up. The only way out is a hard reset which often will result in a partial boot. I then have to run it into Safe Mode, back out and the user (Admin rights assured) desktop can be evoked. I have a Hiren's boot CD at the ready in case that helps.

This computer is set up downstairs so I'll have to shuttle software/logs back and forth with a thumb drive. I'm going to stand closely by this weekend and will be willing to work closely with one of the experts to return this to useful life.

Thanks and I'm standing by….

Hoib
Hello, Hoib
Welcome to the WhatTheTech Forums. My name is Thomas (Tom is fine), and I will be helping you fixing your problems.



Please take note of some guidelines for this fix:
  • Refrain from making any changes to your computer including installing/uninstall programs, deleting files, modifying the registry, and running scanners or tools. Doing so could cause changes to the directions I have to give you and prolong the time required. Further more, you should not be taking any advice relating to this computer from any other source throughout the course of this fix.
  • If you do not understand any step(s) provided, please do not hesitate to ask before continuing. I would much rather clarify instructions or explain them differently than have something important broken.
  • Even if things appear to be better, it might not mean we are finished. Please continue to follow my instructions and reply back until I give you the "all clean". We do not want to clean you part-way, only to have the system re-infect itself.
  • Do not start a new topic. The logs that you post should be pasted directly into the reply. Only attach them if requested or if they do not fit into the post.
  • Please set your system to show all files.
    Click Start, open My Computer, select the Tools menu and click Folder Options.
    Select the View Tab. Under the Hidden files and folders heading, select Show hidden files and folders.
    Uncheck: Hide file extensions for known file types
    Uncheck the Hide protected operating system files (recommended) option.
    Click Yes to confirm.





  • Please download OTL from one of the following mirrors:
    • This is THE Mirror
  • Save it to your desktop.
  • Double click on the [external image: Posted Image] icon on your desktop.
  • Under the Custom Scan box paste this in
    netsvcs
    %SYSTEMDRIVE%\*.exe
    /md5start
    eventlog.dll
    scecli.dll
    netlogon.dll
    cngaudit.dll
    sceclt.dll
    ntelogon.dll
    logevent.dll
    iaStor.sys
    nvstor.sys
    atapi.sys
    IdeChnDr.sys
    viasraid.sys
    AGP440.sys
    vaxscsi.sys
    nvatabus.sys
    viamraid.sys
    nvata.sys
    nvgts.sys
    iastorv.sys
    ViPrt.sys
    eNetHook.dll
    ahcix86.sys
    KR10N.sys
    /md5stop
    %systemroot%\*. /mp /s
    CREATERESTOREPOINT
  • Push the Quick Scan button.
  • Two reports will open, copy and paste them in a reply here:
    • OTL.txt <– Will be opened
    • Extra.txt <– Will be minimized
Hi Tom - Question: When XP boots in Standard mode, I only get about 45 seconds of up time before it freezes up. Your Prot rogue shows up and starts to "scan" then while scanning it bugs me to buy. I X-off these two and it freezes. Then typically I have to hard reset and sometimes it only gets past the Win logon screen (blue caterpillar), the black screen, mouse pointer shows but won't respond and neither will the keyboard). Another hard reset will often bring it back to the logon choices where I launch the user account but again, only for less than a minute's time. Can I run OTL in Safe Mode which affords more opportunity? And, in Safe Mode, should I run OTL from the (real) Administrator's account or my brother's user account with admin rights. Standing by to run this… H
Logs follow:

OTL logfile created on: 4/9/2010 5:16:31 PM - Run 1
OTL by OldTimer - Version 3.2.1.1 Folder = C:\Infection
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.11)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

511.00 Mb Total Physical Memory | 341.00 Mb Available Physical Memory | 67.00% Memory free
1.00 Gb Paging File | 1.00 Gb Available in Paging File | 91.00% Paging File free
Paging file location(s): C:\pagefile.sys 768 1536 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 38.24 Gb Total Space | 15.31 Gb Free Space | 40.04% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
Drive E: | 981.05 Mb Total Space | 978.29 Mb Free Space | 99.72% Space Free | Partition Type: FAT32
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: KOUCHI
Current User Name: Administrator
Logged in as Administrator.

Current Boot Mode: SafeMode
Scan Mode: Current user
Company Name Whitelist: On
Skip Microsoft Files: On
File Age = 14 Days
Output = Standard
Quick Scan

========== Processes (SafeList) ==========

PRC - [2010/04/09 16:47:34 | 000,561,664 | —- | M] (OldTimer Tools) – C:\Infection\OTL.exe
PRC - [2008/04/13 20:12:19 | 001,058,816 | —- | M] (Microsoft Corporation) – C:\WINDOWS\explorer.exe
PRC - [2008/03/19 17:08:58 | 000,607,576 | —- | M] (Lavasoft) – C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe


========== Modules (SafeList) ==========

MOD - [2010/04/09 16:47:34 | 000,561,664 | —- | M] (OldTimer Tools) – C:\Infection\OTL.exe
MOD - [2010/04/05 13:53:24 | 000,020,000 | —- | M] () – C:\WINDOWS\SYSTEM32\cjyppboxj.dll
MOD - [2010/01/08 17:06:43 | 000,096,256 | -HS- | M] () – C:\WINDOWS\SYSTEM32\fodulivu.dll


========== Win32 Services (SafeList) ==========

SRV - [2010/04/05 13:54:56 | 000,004,608 | —- | M] () [Auto | Running] – C:\WINDOWS\SYSTEM32\srsvc.dll – (srservice)
SRV - [2008/07/26 08:25:36 | 000,150,040 | —- | M] (Logitech Inc.) [Auto | Stopped] – C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe – (LVPrcSrv)
SRV - [2008/07/26 08:23:42 | 000,186,904 | —- | M] (Logitech Inc.) [Auto | Stopped] – C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe – (LVCOMSer)
SRV - [2008/06/26 10:24:08 | 000,031,592 | —- | M] (NOS Microsystems Ltd.) [On_Demand | Stopped] – C:\Program Files\NOS\bin\getPlus_HelperSvc.exe – (getPlus® Helper) getPlus®
SRV - [2008/05/30 23:25:51 | 000,307,968 | —- | M] (TuneUp Software GmbH) [On_Demand | Stopped] – C:\WINDOWS\SYSTEM32\TuneUpDefragService.exe – (TuneUp.Defrag)
SRV - [2008/04/23 15:04:16 | 000,019,200 | —- | M] (ESET) [On_Demand | Stopped] – C:\Program Files\ESET\ESET Smart Security\EHttpSrv.exe – (EhttpSrv)
SRV - [2008/04/23 14:58:30 | 000,472,320 | —- | M] (ESET) [Auto | Stopped] – C:\Program Files\ESET\ESET Smart Security\ekrn.exe – (ekrn)
SRV - [2008/04/13 20:11:56 | 000,053,248 | —- | M] () [Auto | Stopped] – C:\WINDOWS\SYSTEM32\6to4v32.dll – (6to4)
SRV - [2008/03/19 17:08:58 | 000,607,576 | —- | M] (Lavasoft) [Auto | Running] – C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe – (aawservice)
SRV - [2008/02/27 13:15:14 | 000,028,416 | —- | M] (TuneUp Software GmbH) [Auto | Stopped] – C:\WINDOWS\SYSTEM32\uxtuneup.dll – (UxTuneUp)
SRV - [2008/02/23 15:45:17 | 000,658,432 | —- | M] (Macrovision Europe Ltd.) [On_Demand | Stopped] – C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe – (FLEXnet Licensing Service)
SRV - [2007/09/11 00:45:04 | 000,124,832 | —- | M] () [Auto | Stopped] – C:\Program Files\Adobe\Photoshop Elements 6.0\PhotoshopElementsFileAgent.exe – (AdobeActiveFileMonitor6.0)
SRV - [2007/08/09 03:27:52 | 000,098,304 | —- | M] (HP) [Auto | Stopped] – C:\WINDOWS\SYSTEM32\HPZipm12.exe – (Pml Driver HPZ12)
SRV - [2007/03/07 16:47:46 | 000,076,848 | —- | M] () [On_Demand | Stopped] – C:\Program Files\DellSupport\brkrsvc.exe – (DSBrokerService)
SRV - [2007/01/04 17:38:08 | 000,024,652 | —- | M] (Viewpoint Corporation) [Disabled | Stopped] – C:\Program Files\Viewpoint\Common\ViewpointService.exe – (Viewpoint Manager Service)
SRV - [2005/04/27 14:59:24 | 000,266,240 | —- | M] (Microsoft Corporation) [Auto | Stopped] – C:\Program Files\UPHClean\uphclean.exe – (UPHClean)
SRV - [2004/08/17 20:00:00 | 000,073,748 | -H– | M] () [Auto | Stopped] – C:\WINDOWS\SYSTEM32\Iasex.dll – (Ias)
SRV - [2003/03/03 14:33:40 | 000,167,936 | —- | M] (Intel® Corporation) [On_Demand | Stopped] – C:\Program Files\Intel\NCS\Sync\NetSvc.exe – (NetSvc)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dellnet.com
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.dellnet.com

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dellnet.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.dellnet.com
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..extensions.enabledItems: [removed]:1.0

FF - HKLM\software\mozilla\Mozilla Firefox 3.6.3\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010/04/03 10:15:12 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.3\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010/04/03 10:15:11 | 000,000,000 | —D | M]

[2010/04/08 16:42:22 | 000,000,000 | —D | M] – C:\Documents and Settings\Administrator\Application Data\Mozilla\Extensions
[2010/04/08 16:42:45 | 000,000,000 | —D | M] – C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\3rjfqrma.default\extensions
[2010/04/08 16:42:45 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\3rjfqrma.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2010/04/08 16:42:45 | 000,000,000 | —D | M] – C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\3rjfqrma.default\extensions\staged-xpis
[2010/04/08 16:42:24 | 000,000,000 | —D | M] – C:\Program Files\Mozilla Firefox\extensions

O1 HOSTS File: ([2009/09/12 15:47:23 | 000,244,641 | R— | M]) - C:\WINDOWS\SYSTEM32\DRIVERS\ETC\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: 127.0.0.1 www.007guard.com
O1 - Hosts: 127.0.0.1 007guard.com
O1 - Hosts: 127.0.0.1 008i.com
O1 - Hosts: 127.0.0.1 www.008k.com
O1 - Hosts: 127.0.0.1 008k.com
O1 - Hosts: 127.0.0.1 www.00hq.com
O1 - Hosts: 127.0.0.1 00hq.com
O1 - Hosts: 127.0.0.1 010402.com
O1 - Hosts: 127.0.0.1 www.032439.com
O1 - Hosts: 127.0.0.1 032439.com
O1 - Hosts: 127.0.0.1 www.1001-search.info
O1 - Hosts: 127.0.0.1 1001-search.info
O1 - Hosts: 127.0.0.1 www.100888290cs.com
O1 - Hosts: 127.0.0.1 100888290cs.com
O1 - Hosts: 127.0.0.1 www.100sexlinks.com
O1 - Hosts: 127.0.0.1 100sexlinks.com
O1 - Hosts: 127.0.0.1 www.10sek.com
O1 - Hosts: 127.0.0.1 10sek.com
O1 - Hosts: 127.0.0.1 www.123topsearch.com
O1 - Hosts: 127.0.0.1 123topsearch.com
O1 - Hosts: 127.0.0.1 www.132.com
O1 - Hosts: 127.0.0.1 132.com
O1 - Hosts: 127.0.0.1 www.136136.net
O1 - Hosts: 127.0.0.1 136136.net
O1 - Hosts: 8540 more lines…
O2 - BHO: (C:\WINDOWS\system32\cjyppboxj.dll) - {A9BA40A1-74F1-52BD-F431-00B15A2C8953} - C:\WINDOWS\SYSTEM32\cjyppboxj.dll ()
O3 - HKLM\..\Toolbar: (no name) - - No CLSID value found.
O4 - HKLM..\Run: [fomehelaro] C:\WINDOWS\System32\topapope.dll ()
O4 - HKLM..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe (Microsoft Corporation)
O4 - HKLM..\Run: [NvCplDaemon] C:\WINDOWS\System32\NvCpl.DLL (NVIDIA Corporation)
O4 - HKLM..\Run: [rohenahoz] C:\WINDOWS\System32\fodulivu.DLL ()
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Main present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O9 - Extra 'Tools' menuitem : Skype add-on for Internet Explorer - {5067A26B-1337-4436-8AFE-EE169C2DA79F} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Skype Technologies S.A.)
O9 - Extra Button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\WINDOWS\SYSTEM32\nwprovau.dll (Microsoft Corporation)
O16 - DPF: {05CA9FB0-3E3E-4B36-BF41-0E3A5CAA8CD8} http://download.microsoft.com/download/e/7…/OGAControl.cab (Office Genuine Advantage Validation Tool)
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://download.macromedia.com/pub/shockwa…director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://download.microsoft.com/download/E/5…heckControl.cab (Windows Genuine Advantage Validation Tool)
O16 - DPF: {193C772A-87BE-4B19-A7BB-445B226FE9A1} http://downloads.ewido.net/ewidoOnlineScan.cab (ewidoOnlineScan Control)
O16 - DPF: {19E28AFC-EAE3-4CE5-AC83-2407B42F57C9} http://download.microsoft.com/download/0/5…b?1076002397078 (MSSecurityAdvisor Class)
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} http://update.microsoft.com/windowsupdate/…b?1120230108640 (WUWebControl Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} http://download.av.aol.com/molbin/shared/m…,20/mcgdmgr.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0014-0002-0000-ABCDEFFEDCBA} http://java.sun.com/products/plugin/autodl…indows-i586.cab (Java Plug-in 1.4.2)
O16 - DPF: {CAFEEFAC-0016-0000-0006-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_06)
O16 - DPF: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload.macromedia.com/pub/shock…ash/swflash.cab (Shockwave Flash Object)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O20 - AppInit_DLLs: (c:\windows\system32\fodulivu.dll) - C:\WINDOWS\SYSTEM32\fodulivu.dll ()
O20 - AppInit_DLLs: (famujize.dll) - File not found
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (rundll32.exe) - File not found
O20 - HKLM Winlogon: Shell - (awxm.vho) - C:\WINDOWS\System32\awxm.vho ()
O20 - HKLM Winlogon: Shell - (rlvgf) - File not found
O20 - Winlogon\Notify\datmps: DllName - Reg Error: Value error. - Reg Error: Value error. File not found
O20 - Winlogon\Notify\qomnnlj: DllName - qomnnlj.dll - File not found
O21 - SSODL: pedulibub - {3d208b70-b224-4a08-b571-992734b1e1e2} - C:\WINDOWS\SYSTEM32\fodulivu.dll ()
O22 - SharedTaskScheduler: {3d208b70-b224-4a08-b571-992734b1e1e2} - mujuzedij - C:\WINDOWS\SYSTEM32\fodulivu.dll ()
O22 - SharedTaskScheduler: {A9BA40A1-74F1-52BD-F431-00B15A2C8953} - hasiufhiusdfjdhfudd - C:\WINDOWS\SYSTEM32\cjyppboxj.dll ()
O24 - Desktop WallPaper: C:\WINDOWS\Web\Wallpaper\Bliss.bmp
O24 - Desktop BackupWallPaper: C:\WINDOWS\Web\Wallpaper\Bliss.bmp
O27 - HKLM IFEO\MpCmdRun.exe: Debugger - C:\WINDOWS\system32\svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\MSASCui.exe: Debugger - C:\WINDOWS\system32\svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\MsMpEng.exe: Debugger - C:\WINDOWS\system32\svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\msseces.exe: Debugger - C:\WINDOWS\system32\svchost.exe (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2002/09/03 14:36:02 | 000,000,000 | -HS- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O32 - AutoRun File - [2010/04/09 06:57:38 | 000,000,027 | —- | M] () - E:\AUTORUN.INF – [ FAT32 ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O34 - HKLM BootExecute: (stera) - File not found
O34 - HKLM BootExecute: (lsdelete) - C:\WINDOWS\System32\lsdelete.exe ()
O34 - HKLM BootExecute: (cute settings…) - File not found
O34 - HKLM BootExecute: (on\Explorer\Moun) - File not found
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKCU\…exe [@ = exefile] – Reg Error: Key error. File not found

NetSvcs: 6to4 - C:\WINDOWS\SYSTEM32\6to4v32.dll ()
NetSvcs: Ias - C:\WINDOWS\SYSTEM32\Iasex.dll ()
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: SRService - C:\WINDOWS\SYSTEM32\srsvc.dll ()
NetSvcs: UxTuneUp - C:\WINDOWS\SYSTEM32\uxtuneup.dll (TuneUp Software GmbH)
NetSvcs: WmdmPmSp - File not found

CREATERESTOREPOINT
Error starting restore point: System Restore is disabled.
Error closing restore point: System Restore is disabled.

========== Files/Folders - Created Within 14 Days ==========

[2010/04/09 07:21:46 | 000,000,000 | —D | C] – C:\Program Files\VS Revo Group
[2010/04/09 06:59:38 | 000,000,000 | —D | C] – C:\Infection
[2010/04/08 17:07:46 | 000,000,000 | —D | C] – C:\Documents and Settings\Administrator\Application Data\AntiVirus Plus
[2010/04/08 17:06:56 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\e70ff5a
[2010/04/08 16:23:43 | 000,000,000 | —D | C] – C:\Documents and Settings\Administrator\Application Data\Malwarebytes
[2010/04/08 16:23:34 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Malwarebytes
[2010/04/08 16:21:38 | 005,115,824 | —- | C] (Malwarebytes Corporation ) – C:\mbs.exe.exe
[2010/04/08 16:13:27 | 000,000,000 | —D | C] – C:\Documents and Settings\Administrator\Application Data\WinRAR
[2010/04/07 17:05:19 | 000,000,000 | —D | M] – C:\Documents and Settings\NetworkService\Local Settings\Application Data\Adobe
[2010/04/07 17:05:10 | 000,000,000 | —D | M] – C:\Documents and Settings\NetworkService\Application Data\Sun
[2010/04/05 15:19:41 | 000,000,000 | —D | M] – C:\Documents and Settings\NetworkService\Application Data\Macromedia
[2010/04/05 15:19:41 | 000,000,000 | —D | M] – C:\Documents and Settings\NetworkService\Application Data\Adobe
[2010/04/05 14:01:08 | 000,000,000 | —D | C] – C:\Program Files\Your Protection
[2010/04/05 13:54:57 | 000,000,000 | —D | C] – C:\WINDOWS\_VOIDcbvttrrpti
[2010/02/13 11:18:44 | 000,000,000 | —D | M] – C:\Documents and Settings\NetworkService\Local Settings\Application Data\Google
[2010/02/12 18:12:20 | 000,000,000 | —D | M] – C:\Documents and Settings\LocalService\Local Settings\Application Data\Google
[2009/03/27 13:35:37 | 000,000,000 | —D | M] – C:\Documents and Settings\NetworkService\Local Settings\Application Data\ESET
[2008/06/02 17:31:18 | 000,000,000 | —D | M] – C:\Documents and Settings\LocalService\Local Settings\Application Data\ESET
[2008/06/01 15:39:39 | 000,000,000 | –SD | M] – C:\Documents and Settings\NetworkService\Application Data\Microsoft
[2008/06/01 15:39:39 | 000,000,000 | –SD | M] – C:\Documents and Settings\LocalService\Application Data\Microsoft
[2008/06/01 15:39:39 | 000,000,000 | —D | M] – C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft
[2008/06/01 15:39:39 | 000,000,000 | —D | M] – C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft
[2008/02/18 16:51:28 | 000,000,000 | —D | M] – C:\Documents and Settings\LocalService\Local Settings\Application Data\Adobe
[2008/02/11 16:51:53 | 000,000,000 | —D | M] – C:\Documents and Settings\LocalService\Application Data\Adobe
[2007/04/27 11:52:05 | 000,000,000 | —D | M] – C:\Documents and Settings\LocalService\Local Settings\Application Data\AOL
[2007/04/24 12:43:00 | 000,000,000 | —D | M] – C:\Documents and Settings\LocalService\Application Data\Share-to-Web Upload Folder
[2005/05/11 23:36:48 | 000,012,288 | —- | C] (Hewlett-Packard Co.) – C:\WINDOWS\Fonts\RandFont.dll
[2004/09/02 10:18:29 | 000,000,000 | —D | M] – C:\Documents and Settings\LocalService\Application Data\Macromedia
[2004/02/14 11:52:37 | 000,000,000 | —D | M] – C:\Documents and Settings\LocalService\Local Settings\Application Data\Help
[2004/02/14 11:52:37 | 000,000,000 | —D | M] – C:\Documents and Settings\LocalService\Application Data\Help

========== Files - Modified Within 14 Days ==========

[2010/04/09 17:15:30 | 002,621,440 | -H– | M] () – C:\Documents and Settings\Administrator\ntuser.dat
[2010/04/09 17:14:00 | 000,000,749 | —- | M] () – C:\WINDOWS\WIN.INI
[2010/04/09 17:14:00 | 000,000,292 | —- | M] () – C:\WINDOWS\SYSTEM.INI
[2010/04/09 17:14:00 | 000,000,211 | RHS- | M] () – C:\BOOT.INI
[2010/04/09 17:12:41 | 000,001,170 | —- | M] () – C:\WINDOWS\System32\WPA.DBL
[2010/04/09 17:04:37 | 000,002,048 | –S- | M] () – C:\WINDOWS\BOOTSTAT.DAT
[2010/04/09 17:00:01 | 000,000,488 | —- | M] () – C:\WINDOWS\tasks\1-Click Maintenance.job
[2010/04/09 16:55:41 | 000,182,038 | —- | M] () – C:\WINDOWS\System32\nvapps.xml
[2010/04/09 16:55:29 | 000,000,882 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2010/04/09 16:55:19 | 000,000,006 | -H– | M] () – C:\WINDOWS\tasks\SA.DAT
[2010/04/09 07:30:08 | 000,000,886 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2010/04/09 07:27:06 | 000,000,178 | -HS- | M] () – C:\Documents and Settings\Administrator\NTUSER.INI
[2010/04/09 07:21:46 | 000,000,917 | —- | M] () – C:\Documents and Settings\Administrator\Desktop\Revo Uninstaller.lnk
[2010/04/08 21:24:00 | 000,000,982 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-217248739-2920639104-3160564834-1007UA.job
[2010/04/08 20:17:45 | 000,000,882 | —- | M] () – C:\WINDOWS\orun32.ini
[2010/04/08 17:11:15 | 000,000,099 | —- | M] () – C:\Documents and Settings\Administrator\Desktop\How to remove XP Security Tool 2010, XP Defender Pro, and Vista Security Tool 2010 (Uninstall Guide).URL
[2010/04/08 17:07:55 | 000,004,286 | —- | M] () – C:\Documents and Settings\Administrator\Application Data\avp.ico
[2010/04/08 16:52:38 | 000,018,198 | -HS- | M] () – C:\Documents and Settings\All Users\Application Data\GbW53PfLB
[2010/04/08 16:52:37 | 000,018,198 | -HS- | M] () – C:\Documents and Settings\Administrator\Local Settings\Application Data\GbW53PfLB
[2010/04/08 16:43:52 | 000,226,304 | -HS- | M] () – C:\Documents and Settings\Administrator\Local Settings\Application Data\2269221376.dll
[2010/04/08 16:40:02 | 000,226,304 | -HS- | M] () – C:\Documents and Settings\Administrator\Local Settings\Application Data\ave.exe
[2010/04/08 16:32:30 | 000,016,722 | -HS- | M] () – C:\Documents and Settings\All Users\Application Data\1xbvAgw
[2010/04/08 16:32:30 | 000,016,722 | -HS- | M] () – C:\Documents and Settings\Administrator\Local Settings\Application Data\1xbvAgw
[2010/04/08 16:16:52 | 000,000,798 | —- | M] () – C:\Documents and Settings\Administrator\Desktop\Shortcut to mbam-setup.lnk
[2010/04/08 10:24:00 | 000,000,930 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-217248739-2920639104-3160564834-1007Core.job
[2010/04/07 17:05:10 | 000,000,664 | —- | M] () – C:\WINDOWS\System32\d3d9caps.dat
[2010/04/07 16:41:48 | 000,000,408 | RHS- | M] () – C:\Documents and Settings\All Users\ntuser.pol
[2010/04/06 17:33:16 | 000,000,196 | —- | M] () – C:\WINDOWS\System32\_VOIDcndecdmxjy.dat
[2010/04/06 10:48:12 | 000,001,168 | —- | M] () – C:\Documents and Settings\All Users\Application Data\_VOIDmfeklnmal.dll
[2010/04/05 15:21:25 | 000,000,003 | —- | M] () – C:\WINDOWS\System32\fhpatch.dll
[2010/04/05 15:21:25 | 000,000,000 | —- | M] () – C:\WINDOWS\System32\fiplock.dll
[2010/04/05 15:21:06 | 000,573,440 | —- | M] () – C:\WINDOWS\System32\IPHACTION.dll
[2010/04/05 15:19:33 | 000,049,152 | —- | M] () – C:\WINDOWS\System32\_VOIDufrfujecxo.dll
[2010/04/05 15:19:32 | 000,049,152 | —- | M] () – C:\WINDOWS\System32\_VOIDtegrmeyqol.dll
[2010/04/05 15:04:51 | 000,000,127 | —- | M] () – C:\WINDOWS\wininit.ini
[2010/04/05 13:55:07 | 000,037,888 | —- | M] () – C:\WINDOWS\System32\awxm.vho
[2010/04/05 13:54:59 | 000,029,696 | —- | M] () – C:\WINDOWS\System32\_VOIDbxvoaictbh.dll
[2010/04/05 13:54:56 | 000,008,192 | —- | M] () – C:\WINDOWS\System32\htmp.030
[2010/04/05 13:54:56 | 000,004,608 | —- | M] () – C:\WINDOWS\System32\srsvc.dll
[2010/04/05 13:54:56 | 000,000,006 | —- | M] () – C:\WINDOWS\System32\iphy.dll
[2010/04/05 13:53:24 | 000,020,000 | —- | M] () – C:\WINDOWS\System32\cjyppboxj.dll

========== Files Created - No Company Name ==========

[2010/04/09 07:21:46 | 000,000,917 | —- | C] () – C:\Documents and Settings\Administrator\Desktop\Revo Uninstaller.lnk
[2010/04/08 17:11:15 | 000,000,099 | —- | C] () – C:\Documents and Settings\Administrator\Desktop\How to remove XP Security Tool 2010, XP Defender Pro, and Vista Security Tool 2010 (Uninstall Guide).URL
[2010/04/08 17:07:54 | 000,004,286 | —- | C] () – C:\Documents and Settings\Administrator\Application Data\avp.ico
[2010/04/08 16:42:09 | 000,226,304 | -HS- | C] () – C:\Documents and Settings\Administrator\Local Settings\Application Data\2269221376.dll
[2010/04/08 16:40:03 | 000,018,198 | -HS- | C] () – C:\Documents and Settings\Administrator\Local Settings\Application Data\GbW53PfLB
[2010/04/08 16:16:52 | 000,000,798 | —- | C] () – C:\Documents and Settings\Administrator\Desktop\Shortcut to mbam-setup.lnk
[2010/04/08 16:08:16 | 000,016,722 | -HS- | C] () – C:\Documents and Settings\Administrator\Local Settings\Application Data\1xbvAgw
[2010/04/08 16:08:15 | 000,226,304 | -HS- | C] () – C:\Documents and Settings\Administrator\Local Settings\Application Data\ave.exe
[2010/04/08 09:51:01 | 000,016,714 | -HS- | C] () – C:\Documents and Settings\LocalService\Local Settings\Application Data\1xbvAgw
[2010/04/07 17:07:37 | 000,016,722 | -HS- | C] () – C:\Documents and Settings\All Users\Application Data\1xbvAgw
[2010/04/07 17:07:37 | 000,001,282 | -HS- | C] () – C:\Documents and Settings\NetworkService\Local Settings\Application Data\1xbvAgw
[2010/04/07 17:05:10 | 000,000,664 | —- | C] () – C:\WINDOWS\System32\d3d9caps.dat
[2010/04/07 16:41:48 | 000,000,408 | RHS- | C] () – C:\Documents and Settings\All Users\ntuser.pol
[2010/04/05 15:52:28 | 000,001,168 | —- | C] () – C:\Documents and Settings\All Users\Application Data\_VOIDmfeklnmal.dll
[2010/04/05 15:21:25 | 000,000,003 | —- | C] () – C:\WINDOWS\System32\fhpatch.dll
[2010/04/05 15:21:25 | 000,000,000 | —- | C] () – C:\WINDOWS\System32\fiplock.dll
[2010/04/05 15:20:48 | 000,573,440 | —- | C] () – C:\WINDOWS\System32\IPHACTION.dll
[2010/04/05 15:19:32 | 000,049,152 | —- | C] () – C:\WINDOWS\System32\_VOIDtegrmeyqol.dll
[2010/04/05 15:19:31 | 000,049,152 | —- | C] () – C:\WINDOWS\System32\_VOIDufrfujecxo.dll
[2010/04/05 15:04:51 | 000,000,127 | —- | C] () – C:\WINDOWS\wininit.ini
[2010/04/05 13:55:20 | 000,037,888 | —- | C] () – C:\WINDOWS\System32\awxm.vho
[2010/04/05 13:54:59 | 000,029,696 | —- | C] () – C:\WINDOWS\System32\_VOIDbxvoaictbh.dll
[2010/04/05 13:54:59 | 000,000,196 | —- | C] () – C:\WINDOWS\System32\_VOIDcndecdmxjy.dat
[2010/04/05 13:54:56 | 000,008,192 | —- | C] () – C:\WINDOWS\System32\htmp.030
[2010/04/05 13:54:56 | 000,000,006 | —- | C] () – C:\WINDOWS\System32\iphy.dll
[2010/04/05 13:53:43 | 000,018,198 | -HS- | C] () – C:\Documents and Settings\All Users\Application Data\GbW53PfLB
[2010/04/05 13:53:24 | 000,020,000 | —- | C] () – C:\WINDOWS\System32\cjyppboxj.dll
[2010/01/08 17:07:21 | 000,066,560 | -HS- | C] () – C:\WINDOWS\System32\topapope.dll
[2010/01/08 17:07:21 | 000,066,560 | -HS- | C] () – C:\WINDOWS\System32\sohojire.dll
[2010/01/08 17:06:43 | 000,096,256 | -HS- | C] () – C:\WINDOWS\System32\fodulivu.dll
[2010/01/08 17:06:43 | 000,066,560 | -HS- | C] () – C:\WINDOWS\System32\jahanane.dll
[2010/01/08 17:06:43 | 000,064,512 | -HS- | C] () – C:\WINDOWS\System32\fagopitu.dll
[2010/01/08 17:06:43 | 000,048,640 | -HS- | C] () – C:\WINDOWS\System32\sozivado.dll
[2010/01/08 17:06:43 | 000,042,496 | -HS- | C] () – C:\WINDOWS\System32\guderasa.dll
[2010/01/05 16:01:01 | 000,002,561 | -HS- | C] () – C:\WINDOWS\System32\ropusolo.dll
[2010/01/05 16:01:01 | 000,002,560 | -HS- | C] () – C:\WINDOWS\System32\sinizamu.dll
[2010/01/05 16:01:01 | 000,002,560 | -HS- | C] () – C:\WINDOWS\System32\fadokase.dll
[2009/06/17 10:32:47 | 000,066,482 | R— | C] () – C:\WINDOWS\System32\lvcoinst.ini
[2008/07/27 11:35:32 | 000,000,000 | —- | C] () – C:\WINDOWS\System32\wlite.sys
[2008/07/26 08:25:02 | 000,025,624 | —- | C] () – C:\WINDOWS\System32\drivers\LVPr2Mon.sys
[2008/05/31 19:54:28 | 000,002,508 | —- | C] () – C:\Documents and Settings\Administrator\Application Data\$_hpcst$.hpc
[2008/05/02 22:46:00 | 001,703,936 | —- | C] () – C:\WINDOWS\System32\nvwdmcpl.dll
[2008/05/02 22:46:00 | 001,486,848 | —- | C] () – C:\WINDOWS\System32\nview.dll
[2008/05/02 22:46:00 | 001,019,904 | —- | C] () – C:\WINDOWS\System32\nvwimg.dll
[2008/05/02 22:46:00 | 000,466,944 | —- | C] () – C:\WINDOWS\System32\nvshell.dll
[2008/05/02 22:46:00 | 000,286,720 | —- | C] () – C:\WINDOWS\System32\nvnt4cpl.dll
[2007/11/19 13:59:24 | 000,002,508 | —- | C] () – C:\Documents and Settings\LocalService\Application Data\$_hpcst$.hpc
[2007/11/14 20:15:10 | 000,000,206 | —- | C] () – C:\WINDOWS\System32\MRT.INI
[2007/08/01 14:13:44 | 000,000,344 | —- | C] () – C:\WINDOWS\QTW.INI
[2007/07/24 14:10:36 | 000,021,085 | —- | C] () – C:\WINDOWS\cookies.ini
[2007/06/08 12:28:18 | 000,000,227 | —- | C] () – C:\WINDOWS\HP_CounterReport_Update_HPSU.ini
[2007/06/08 12:27:56 | 000,000,214 | —- | C] () – C:\WINDOWS\HP_48BitScanUpdatePatch.ini
[2007/06/08 12:23:33 | 000,000,221 | —- | C] () – C:\WINDOWS\HP_RedboxHprblog_HPSU.ini
[2007/05/05 16:02:21 | 000,001,751 | —- | C] () – C:\Documents and Settings\All Users\Application Data\QTSBandwidthCache
[2007/03/05 14:34:28 | 000,676,224 | —- | C] () – C:\WINDOWS\System32\OGACheckControl.DLL
[2006/09/28 15:36:44 | 000,000,000 | —- | C] () – C:\WINDOWS\hpqEmlSz.INI
[2006/09/18 14:56:55 | 000,000,221 | —- | C] () – C:\WINDOWS\NCLogConfig.ini
[2006/03/09 13:42:41 | 000,003,692 | —- | C] () – C:\Documents and Settings\All Users\Application Data\hpzinstall.log
[2005/06/30 10:17:00 | 000,000,000 | —- | C] () – C:\WINDOWS\SETUP32.INI
[2005/04/13 11:38:24 | 000,004,560 | —- | C] () – C:\WINDOWS\cdplayer.ini
[2004/11/18 12:20:46 | 000,000,026 | —- | C] () – C:\WINDOWS\UP9ASP.INI
[2004/11/18 12:11:29 | 000,000,024 | —- | C] () – C:\WINDOWS\atid.ini
[2004/11/18 12:11:28 | 000,000,365 | —- | C] () – C:\WINDOWS\upst.ini
[2004/10/30 15:14:45 | 000,000,032 | —- | C] () – C:\WINDOWS\CD_Start.INI
[2004/08/24 13:39:18 | 000,000,844 | —- | C] () – C:\WINDOWS\hegames.ini
[2004/08/24 13:39:14 | 000,000,080 | —- | C] () – C:\WINDOWS\encore_launcher.ini
[2004/08/17 20:00:00 | 000,073,748 | -H– | C] () – C:\WINDOWS\System32\Iasex.dll
[2004/08/07 15:31:23 | 000,000,024 | —- | C] () – C:\WINDOWS\RVBOOK.INI
[2004/01/23 11:29:51 | 000,335,872 | —- | C] () – C:\WINDOWS\System32\ldf252.dll
[2004/01/23 11:25:39 | 000,000,034 | —- | C] () – C:\WINDOWS\hpfsched.ini
[2003/12/29 11:42:06 | 000,002,368 | —- | C] () – C:\WINDOWS\disney.ini
[2003/12/05 17:22:04 | 000,000,293 | —- | C] () – C:\WINDOWS\iPlayer.INI
[2003/11/01 16:42:01 | 000,000,174 | —- | C] () – C:\WINDOWS\System32\mcini.ini
[2003/10/29 17:31:35 | 000,000,024 | —- | C] () – C:\WINDOWS\msoffice.ini
[2003/10/28 17:58:13 | 000,262,144 | —- | C] () – C:\Documents and Settings\All Users\NTUSER.DAT
[2003/10/28 17:58:13 | 000,001,024 | -H– | C] () – C:\Documents and Settings\All Users\NTUSER.DAT.LOG
[2003/10/23 03:48:03 | 000,000,061 | —- | C] () – C:\WINDOWS\smscfg.ini
[2003/10/23 03:46:15 | 000,000,376 | —- | C] () – C:\WINDOWS\ODBC.INI
[2003/10/23 03:35:08 | 000,000,882 | —- | C] () – C:\WINDOWS\orun32.ini
[2003/10/23 03:20:46 | 000,155,648 | -H– | C] () – C:\Documents and Settings\Administrator\ntuser.dat.LOG
[2003/10/23 03:20:46 | 000,000,178 | -HS- | C] () – C:\Documents and Settings\Administrator\NTUSER.INI
[2003/10/23 03:19:35 | 000,363,520 | —- | C] () – C:\WINDOWS\System32\psisdecd.dll
[2003/10/23 03:19:19 | 000,001,793 | —- | C] () – C:\WINDOWS\System32\fxsperf.ini
[2003/10/23 03:07:02 | 000,000,546 | —- | C] () – C:\WINDOWS\System32\OEMINFO.INI
[2003/08/14 00:13:00 | 000,000,000 | —- | C] () – C:\WINDOWS\System32\px.ini
[2003/01/07 16:05:08 | 000,002,695 | —- | C] () – C:\WINDOWS\System32\OUTLPERF.INI
[2002/08/29 06:00:00 | 000,053,248 | —- | C] () – C:\WINDOWS\System32\6to4v32.dll
[2002/08/29 06:00:00 | 000,004,608 | —- | C] () – C:\WINDOWS\System32\srsvc.dll
[2002/08/29 06:00:00 | 000,002,304 | —- | C] () – C:\WINDOWS\System32\seagate.sys
[2001/07/06 16:30:00 | 000,003,399 | —- | C] () – C:\WINDOWS\System32\hptcpmon.ini
[1980/01/01 08:00:00 | 002,621,440 | -H– | C] () – C:\Documents and Settings\Administrator\ntuser.dat
[1980/01/01 01:00:00 | 000,012,288 | —- | C] () – C:\WINDOWS\System32\e100bmsg.dll

========== LOP Check ==========

[2010/04/08 17:07:46 | 000,000,000 | —D | M] – C:\Documents and Settings\Administrator\Application Data\AntiVirus Plus
[2008/05/31 06:59:37 | 000,000,000 | —D | M] – C:\Documents and Settings\Administrator\Application Data\TuneUp Software
[2008/05/31 19:57:20 | 000,000,000 | —D | M] – C:\Documents and Settings\Administrator\Application Data\URSoft
[2008/09/18 11:15:57 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Avery
[2010/04/08 17:06:56 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\e70ff5a
[2008/06/01 07:04:56 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\ESET
[2008/09/03 15:18:59 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\espionServerData
[2004/04/03 16:33:44 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\MSScanAppDataDir
[2009/09/16 11:02:48 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Office-Kit.com
[2007/08/20 12:22:32 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Riverdeep
[2008/12/19 16:05:37 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Rosetta Stone DEMO
[2010/04/05 15:59:33 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TEMP
[2008/05/30 23:17:21 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TuneUp Software
[2008/05/31 08:20:33 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Viewpoint
[2010/04/09 17:00:01 | 000,000,488 | —- | M] () – C:\WINDOWS\Tasks\1-Click Maintenance.job

========== Purity Check ==========



========== Custom Scans ==========


< %SYSTEMDRIVE%\*.exe >
[2008/02/16 13:09:20 | 023,454,528 | —- | M] ( ) – C:\AdbeRdr812_en_US.exe
[2005/12/06 10:37:30 | 000,010,920 | —- | M] () – C:\aolconnfix.exe
[2007/05/23 13:35:47 | 011,470,608 | —- | M] () – C:\avgas-setup-7.5.0.50.exe
[2006/06/08 11:20:38 | 000,249,856 | —- | M] (Versis) – C:\c0.exe
[2010/01/07 18:55:54 | 005,115,824 | —- | M] (Malwarebytes Corporation ) – C:\mbs.exe.exe
[2004/08/31 11:15:49 | 009,663,488 | —- | M] (Skype Software S.A. ) – C:\SkypeSetup.exe
[2006/12/27 17:21:52 | 002,010,624 | —- | M] () – C:\ventrilo-2.3.0-Windows-i386.exe


< MD5 for: AGP440.SYS >
[2004/09/18 13:21:10 | 022,245,337 | —- | M] () .cab file – C:\WINDOWS\Driver Cache\I386\sp2.cab:AGP440.sys
[2008/10/04 13:45:21 | 023,852,652 | —- | M] () .cab file – C:\WINDOWS\Driver Cache\I386\sp3.cab:AGP440.sys
[2004/09/18 13:21:10 | 022,245,337 | —- | M] () .cab file – C:\WINDOWS\ServicePackFiles\i386\sp2.cab:AGP440.sys
[2008/10/04 13:45:21 | 023,852,652 | —- | M] () .cab file – C:\WINDOWS\ServicePackFiles\i386\sp3.cab:AGP440.sys
[2008/10/04 13:45:21 | 023,852,652 | —- | M] () .cab file – C:\WINDOWS\SoftwareDistribution\Download\dd9ab5193501484cf5e6884fa1d22f9e\sp3.cab:AGP440.sys
[2008/04/13 14:36:38 | 000,042,368 | —- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 – C:\WINDOWS\ServicePackFiles\i386\agp440.sys
[2008/04/13 14:36:38 | 000,042,368 | —- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 – C:\WINDOWS\SoftwareDistribution\Download\dd9ab5193501484cf5e6884fa1d22f9e\agp440.sys
[2008/04/13 14:36:38 | 000,042,368 | —- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 – C:\WINDOWS\SYSTEM32\DRIVERS\agp440.sys
[2004/08/04 02:07:41 | 000,042,368 | —- | M] (Microsoft Corporation) MD5=2C428FA0C3E3A01ED93C9B2A27D8D4BB – C:\WINDOWS\$NtServicePackUninstall$\agp440.sys
[2001/08/17 14:58:00 | 000,025,472 | —- | M] (Microsoft Corporation) MD5=65880045C51AA36184841CEE915A61DF – C:\I386\AGP440.SYS

< MD5 for: ATAPI.SYS >
[2002/08/29 06:00:00 | 010,158,890 | —- | M] () .cab file – C:\I386\sp1.cab:atapi.sys
[2002/08/29 06:00:00 | 010,158,890 | —- | M] () .cab file – C:\WINDOWS\Driver Cache\I386\sp1.cab:atapi.sys
[2004/09/18 13:21:10 | 022,245,337 | —- | M] () .cab file – C:\WINDOWS\Driver Cache\I386\sp2.cab:atapi.sys
[2008/10/04 13:45:21 | 023,852,652 | —- | M] () .cab file – C:\WINDOWS\Driver Cache\I386\sp3.cab:atapi.sys
[2004/09/18 13:21:10 | 022,245,337 | —- | M] () .cab file – C:\WINDOWS\ServicePackFiles\i386\sp2.cab:atapi.sys
[2008/10/04 13:45:21 | 023,852,652 | —- | M] () .cab file – C:\WINDOWS\ServicePackFiles\i386\sp3.cab:atapi.sys
[2008/10/04 13:45:21 | 023,852,652 | —- | M] () .cab file – C:\WINDOWS\SoftwareDistribution\Download\dd9ab5193501484cf5e6884fa1d22f9e\sp3.cab:atapi.sys
[2003/01/31 16:43:30 | 000,087,040 | —- | M] (Microsoft Corporation) MD5=3C33F5479520844A186C2D43ECFFD477 – C:\I386\atapi.sys
[2002/08/29 02:27:50 | 000,086,912 | —- | M] (Microsoft Corporation) MD5=95B858761A00E1D4F81F79A0DA019ACA – C:\WINDOWS\SYSTEM32\ReinstallBackups\0003\DriverFiles\i386\atapi.sys
[2002/08/29 02:27:50 | 000,086,912 | —- | M] (Microsoft Corporation) MD5=95B858761A00E1D4F81F79A0DA019ACA – C:\WINDOWS\SYSTEM32\ReinstallBackups\0007\DriverFiles\i386\atapi.sys
[2008/04/13 14:40:30 | 000,096,512 | —- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 – C:\WINDOWS\ServicePackFiles\i386\atapi.sys
[2008/04/13 14:40:30 | 000,096,512 | —- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 – C:\WINDOWS\SoftwareDistribution\Download\dd9ab5193501484cf5e6884fa1d22f9e\atapi.sys
[2008/04/13 14:40:30 | 000,096,512 | —- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 – C:\WINDOWS\SYSTEM32\DRIVERS\atapi.sys
[2004/08/04 01:59:42 | 000,095,360 | —- | M] (Microsoft Corporation) MD5=CDFE4411A69C224BD1D11B2DA92DAC51 – C:\WINDOWS\$NtServicePackUninstall$\atapi.sys

< MD5 for: EVENTLOG.DLL >
[2008/04/13 20:11:53 | 000,056,320 | —- | M] (Microsoft Corporation) MD5=6D4FEB43EE538FC5428CC7F0565AA656 – C:\WINDOWS\ServicePackFiles\i386\eventlog.dll
[2008/04/13 20:11:53 | 000,056,320 | —- | M] (Microsoft Corporation) MD5=6D4FEB43EE538FC5428CC7F0565AA656 – C:\WINDOWS\SoftwareDistribution\Download\dd9ab5193501484cf5e6884fa1d22f9e\eventlog.dll
[2008/04/13 20:11:53 | 000,056,320 | —- | M] (Microsoft Corporation) MD5=6D4FEB43EE538FC5428CC7F0565AA656 – C:\WINDOWS\SYSTEM32\eventlog.dll
[2004/08/04 03:56:42 | 000,055,808 | —- | M] (Microsoft Corporation) MD5=82B24CB70E5944E6E34662205A2A5B78 – C:\WINDOWS\$NtServicePackUninstall$\eventlog.dll
[2002/08/29 06:00:00 | 000,049,152 | —- | M] (Microsoft Corporation) MD5=BF3C8CF53C77B48206B39910B6D6CBCC – C:\I386\EVENTLOG.DLL

< MD5 for: NETLOGON.DLL >
[2008/04/13 20:12:01 | 000,407,040 | —- | M] (Microsoft Corporation) MD5=1B7F071C51B77C272875C3A23E1E4550 – C:\WINDOWS\ServicePackFiles\i386\netlogon.dll
[2008/04/13 20:12:01 | 000,407,040 | —- | M] (Microsoft Corporation) MD5=1B7F071C51B77C272875C3A23E1E4550 – C:\WINDOWS\SoftwareDistribution\Download\dd9ab5193501484cf5e6884fa1d22f9e\netlogon.dll
[2008/04/13 20:12:01 | 000,407,040 | —- | M] (Microsoft Corporation) MD5=1B7F071C51B77C272875C3A23E1E4550 – C:\WINDOWS\SYSTEM32\netlogon.dll
[2002/08/29 06:00:00 | 000,399,360 | —- | M] (Microsoft Corporation) MD5=3ADD563ED7A1C66E6F5E0F7A661AA96D – C:\I386\NETLOGON.DLL
[2004/08/04 03:56:44 | 000,407,040 | —- | M] (Microsoft Corporation) MD5=96353FCECBA774BB8DA74A1C6507015A – C:\WINDOWS\$NtServicePackUninstall$\netlogon.dll

< MD5 for: SCECLI.DLL >
[2004/08/04 03:56:44 | 000,180,224 | —- | M] (Microsoft Corporation) MD5=0F78E27F563F2AAF74B91A49E2ABF19A – C:\WINDOWS\$NtServicePackUninstall$\scecli.dll
[2002/08/29 06:00:00 | 000,174,592 | —- | M] (Microsoft Corporation) MD5=97418A5C642A5C748A28BD7CF6860B57 – C:\I386\SCECLI.DLL
[2008/04/13 20:12:05 | 000,181,248 | —- | M] (Microsoft Corporation) MD5=A86BB5E61BF3E39B62AB4C7E7085A084 – C:\WINDOWS\ServicePackFiles\i386\scecli.dll
[2008/04/13 20:12:05 | 000,181,248 | —- | M] (Microsoft Corporation) MD5=A86BB5E61BF3E39B62AB4C7E7085A084 – C:\WINDOWS\SoftwareDistribution\Download\dd9ab5193501484cf5e6884fa1d22f9e\scecli.dll
[2008/04/13 20:12:05 | 000,181,248 | —- | M] (Microsoft Corporation) MD5=A86BB5E61BF3E39B62AB4C7E7085A084 – C:\WINDOWS\SYSTEM32\scecli.dll

< %systemroot%\*. /mp /s >

========== Files - Unicode (All) ==========
[2007/04/27 16:37:16 | 000,000,000 | —D | M](C:\Program Files\s?curity) – C:\Program Files\sеcurity
[2007/04/27 16:37:16 | 000,000,000 | —D | M](C:\Program Files\s?curity) – C:\Program Files\sеcurity
[2007/04/25 11:58:15 | 000,000,000 | —D | M](C:\Program Files\Common Files\F?nts) – C:\Program Files\Common Files\Fοnts
[2007/04/25 11:58:15 | 000,000,000 | —D | M](C:\Program Files\Common Files\F?nts) – C:\Program Files\Common Files\Fοnts
(C:\Program Files\s?curity) – C:\Program Files\sеcurity
(C:\Program Files\Common Files\F?nts) – C:\Program Files\Common Files\Fοnts

========== Alternate Data Streams ==========

@Alternate Data Stream - 174 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:B3D74A13
< End of report >


Extras:

OTL Extras logfile created on: 4/9/2010 5:16:31 PM - Run 1
OTL by OldTimer - Version 3.2.1.1 Folder = C:\Infection
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.11)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

511.00 Mb Total Physical Memory | 341.00 Mb Available Physical Memory | 67.00% Memory free
1.00 Gb Paging File | 1.00 Gb Available in Paging File | 91.00% Paging File free
Paging file location(s): C:\pagefile.sys 768 1536 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 38.24 Gb Total Space | 15.31 Gb Free Space | 40.04% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
Drive E: | 981.05 Mb Total Space | 978.29 Mb Free Space | 99.72% Space Free | Partition Type: FAT32
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: KOUCHI
Current User Name: Administrator
Logged in as Administrator.

Current Boot Mode: SafeMode
Scan Mode: Current user
Company Name Whitelist: On
Skip Microsoft Files: On
File Age = 14 Days
Output = Standard
Quick Scan

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]

[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.exe [@ = exefile] – Reg Error: Key error. File not found
.html [@ = FirefoxHTML] – C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
exefile [open] – "%1" %*
htmlfile – "C:\Program Files\Microsoft Office\OFFICE11\msohtmed.exe" %1 (Microsoft Corporation)
htmlfile [print] – "C:\Program Files\Microsoft Office\OFFICE11\msohtmed.exe" /p %1 (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [ACDBrowse] – "C:\PROGRA~1\ACDSYS~1\ACDSee\ACDSee.exe" "%1" (ACD Systems, Ltd.)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"AntiVirusDisableNotify" = 1
"FirewallDisableNotify" = 1
"UpdatesDisableNotify" = 1
"AntiVirusOverride" = 0
"FirewallOverride" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]
"DisableMonitoring" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 0
"" =
"DisableNotifications" = 1
"DoNotAllowExceptions" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
"26675:TCP" = 26675:TCP:169.254.2.0/255.255.255.0:Enabled:ActiveSync Service
"139:TCP" = 139:TCP:*:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:*:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:*:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:*:Enabled:@xpsp2res.dll,-22002
"" =

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 0
"DoNotAllowExceptions" = 0
"DisableNotifications" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"26675:TCP" = 26675:TCP:169.254.2.0/255.255.255.0:Enabled:ActiveSync Service
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008
"139:TCP" = 139:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22002
"" =

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
"C:\Program Files\America Online 9.0\waol.exe" = C:\Program Files\America Online 9.0\waol.exe:*:Enabled:America Online 9.0 – File not found
"C:\Program Files\Microsoft ActiveSync\rapimgr.exe" = C:\Program Files\Microsoft ActiveSync\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager – (Microsoft Corporation)
"C:\Program Files\Microsoft ActiveSync\wcescomm.exe" = C:\Program Files\Microsoft ActiveSync\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager – (Microsoft Corporation)
"C:\Program Files\Microsoft ActiveSync\WCESMgr.exe" = C:\Program Files\Microsoft ActiveSync\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application – (Microsoft Corporation)
"C:\Program Files\Rosetta Stone\Rosetta Stone V3 DEMO\support\bin\RosettaStoneLtdServices.exe" = C:\Program Files\Rosetta Stone\Rosetta Stone V3 DEMO\support\bin\RosettaStoneLtdServices.exe:*:Enabled:Rosetta Stone Online Component – ()
"C:\Program Files\Rosetta Stone\Rosetta Stone V3 DEMO\RosettaStoneVersion3.exe" = C:\Program Files\Rosetta Stone\Rosetta Stone V3 DEMO\RosettaStoneVersion3.exe:*:Enabled:Rosetta Stone V3 DEMO Application – ()

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files\Common Files\aol\Loader\aolload.exe" = C:\Program Files\Common Files\aol\Loader\aolload.exe:*:Enabled:AOL Application Loader – (AOL LLC)
"C:\Program Files\Common Files\aol\System Information\sinf.exe" = C:\Program Files\Common Files\aol\System Information\sinf.exe:*:Enabled:AOL – (America Online Inc.)
"C:\WINDOWS\SYSTEM32\fxsclnt.exe" = C:\WINDOWS\SYSTEM32\fxsclnt.exe:*:Enabled:Microsoft Fax Console – (Microsoft Corporation)
"C:\Program Files\HP\Digital Imaging\bin\hpofxm08.exe" = C:\Program Files\HP\Digital Imaging\bin\hpofxm08.exe:*:Enabled:hpofxm08.exe – (Hewlett-Packard Co.)
"C:\Program Files\HP\Digital Imaging\bin\hposfx08.exe" = C:\Program Files\HP\Digital Imaging\bin\hposfx08.exe:*:Enabled:hposfx08.exe – (Hewlett-Packard Co.)
"C:\Program Files\HP\Digital Imaging\bin\hposid01.exe" = C:\Program Files\HP\Digital Imaging\bin\hposid01.exe:*:Enabled:hposid01.exe – (Hewlett-Packard Co.)
"C:\Program Files\HP\Digital Imaging\bin\hpqCopy.exe" = C:\Program Files\HP\Digital Imaging\bin\hpqCopy.exe:*:Enabled:hpqcopy.exe – (Hewlett-Packard Co.)
"C:\Program Files\HP\Digital Imaging\bin\hpfccopy.exe" = C:\Program Files\HP\Digital Imaging\bin\hpfccopy.exe:*:Enabled:hpfccopy.exe – (Hewlett-Packard)
"C:\Program Files\HP\Digital Imaging\bin\hpzwiz01.exe" = C:\Program Files\HP\Digital Imaging\bin\hpzwiz01.exe:*:Enabled:hpzwiz01.exe – (Hewlett-Packard Co.)
"C:\Program Files\HP\Digital Imaging\Unload\HpqPhUnl.exe" = C:\Program Files\HP\Digital Imaging\Unload\HpqPhUnl.exe:*:Enabled:hpqphunl.exe – ()
"C:\Program Files\HP\Digital Imaging\Unload\HpqDIA.exe" = C:\Program Files\HP\Digital Imaging\Unload\HpqDIA.exe:*:Enabled:hpqdia.exe – ( )
"C:\Program Files\HP\Digital Imaging\bin\hpoews01.exe" = C:\Program Files\HP\Digital Imaging\bin\hpoews01.exe:*:Enabled:hpoews01.exe – (Hewlett-Packard Co.)
"C:\Program Files\Microsoft ActiveSync\rapimgr.exe" = C:\Program Files\Microsoft ActiveSync\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager – (Microsoft Corporation)
"C:\Program Files\Microsoft ActiveSync\wcescomm.exe" = C:\Program Files\Microsoft ActiveSync\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager – (Microsoft Corporation)
"C:\Program Files\Microsoft ActiveSync\WCESMgr.exe" = C:\Program Files\Microsoft ActiveSync\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application – (Microsoft Corporation)
"C:\Program Files\Real\RealPlayer\trueplay.exe" = C:\Program Files\Real\RealPlayer\trueplay.exe:*:Disabled:RealOne Player – (RealNetworks, Inc.)
"C:\WINDOWS\system32\uwpnxecg.exe" = C:\WINDOWS\system32\uwp
"C:\WINDOWS\system32\hcptirno.exe" = C:\WINDOWS\system32\hcptostic\xpnetdiag.exe – File not found
"C:\WINDOWS\system32\fvqhonrw.exe" = C:\WINDOWS\system32\fvq
"C:\WINDOWS\system32\leuctjph.exe" = C:\WINDOWS\system32\leuconrw.exe – File not found
"C:\WINDOWS\system32\bnydycqh.exe" = C:\WINDOWS\system32\bnydonrw.exe – File not found
"C:\WINDOWS\system32\wuqswhyq.exe" = C:\WINDOWS\system32\wuq
"C:\WINDOWS\system32\qvqwgtje.exe" = C:\WINDOWS\system32\qvqwwhyq.exe – File not found
"C:\Program Files\Rosetta Stone\Rosetta Stone V3 DEMO\RosettaStoneVersion3.exe" = C:\Program Files\Rosetta Stone\Rosetta Stone V3 DEMO\RosettaStoneVersion3.exe:*:Enabled:Rosetta Stone V3 DEMO Application – ()
"C:\Program Files\Rosetta Stone\Rosetta Stone V3 DEMO\support\bin\RosettaStoneLtdServices.exe" = C:\Program Files\Rosetta Stone\Rosetta Stone V3 DEMO\support\bin\RosettaStoneLtdServices.exe:*:Enabled:Rosetta Stone Online Component – ()
"C:\Documents and Settings\Andrew\Local Settings\Application Data\Google\Google Talk Plugin\googletalkplugin.dll" = C:\Documents and Settings\Andrew\Local Settings\Application Data\Google\Google Talk Plugin\googletalkplugin.dll:*:Enabled:Google Talk Plugin – (Google)
"C:\Documents and Settings\Andrew\Local Settings\Application Data\Google\Google Talk Plugin\googletalkplugin.exe" = C:\Documents and Settings\Andrew\Local Settings\Application Data\Google\Google Talk Plugin\googletalkplugin.exe:*:Enabled:Google Talk Plugin – (Google)
"C:\Program Files\TurboTax\Home & Business 2007\32bit\ttax.exe" = C:\Program Files\TurboTax\Home & Business 2007\32bit\ttax.exe:LocalSubNet:Enabled:TurboTax – (Intuit, Inc.)
"C:\Program Files\TurboTax\Home & Business 2007\32bit\updatemgr.exe" = C:\Program Files\TurboTax\Home & Business 2007\32bit\updatemgr.exe:LocalSubNet:Enabled:TurboTax Update Manager – (Intuit, Inc.)
"C:\WINDOWS\explorer.exe" = C:\WINDOWS\explorer.exe:*:Enabled:Explorer – (Microsoft Corporation)


========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{00203668-8170-44A0-BE44-B632FA4D780F}" = Adobe AIR
"{00F0588F-5F9C-4661-84E0-176790BDF709}" = ESET Smart Security
"{0143CF89-5CF2-4F2D-80D5-BFAE64E1BA00}" = Media Wizard 3.0
"{03B1B42B-F6DE-41d9-8CFF-DC44E895C7A7}" = PhotoGallery
"{0611BD4E-4FE4-4a62-B0C0-18A4CC463428}" = CP_Package_Variety1
"{06230E02-2B7E-11D2-92D0-0040051BD005}" = OLYMPUS CAMEDIA Master 2.5
"{09984AEC-6B9F-4ca7-B78D-CB44D4771DA3}" = Destinations
"{09DA4F91-2A09-4232-AB8C-6BC740096DE3}" = Sonic Update Manager
"{0B33B738-AD79-4E32-90C5-E67BFB10BBFF}" = AiO_Scan
"{11F1920A-56A2-4642-B6E0-3B31A12C9288}" = Dell Solution Center
"{1206EF92-2E83-4859-ACCB-2048C3CB7DA6}" = Sonic DLA
"{151C555A-A9E7-4A2E-B6D7-165D04A3C956}" = Dell Picture Studio - Dell Image Expert
"{1C139D7D-9FEA-468d-A9C8-2A6E3BDE564A}" = CP_Package_Variety3
"{21DB3D90-D816-4092-A260-CA3F6B55A6DD}" = Sonic_PrimoSDK
"{23A7B376-BBEC-4e76-BBD7-0F155E70D74B}" = CP_Panorama1Config
"{2466E904-7E48-4597-9321-722CF02930EB}" = 5600
"{26A24AE4-039D-4CA4-87B4-2F83216013FF}" = Java™ 6 Update 13
"{2CADCEAB-D5DA-44D6-B5FC-7DEE87AB3C0C}" = Unload
"{30C19FF2-7FBA-4d09-B9DE-1659977F64F6}" = TrayApp
"{3248F0A8-6813-11D6-A77B-00B0D0160060}" = Java™ 6 Update 6
"{32BDCCB8-9DC8-496d-9DB1-F77510775BDB}" = InstantShareDevices
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{36E47DA1-10E1-45d9-8B19-14D19607CDCF}" = CP_CalendarTemplates1
"{36FDBE6E-6684-462B-AE98-9A39A1B200CC}" = HP Product Assistant
"{3AF8FCCD-F51A-4014-9002-F195E1CBC876}" = Logitech QuickCam
"{410438A3-B591-4028-B70A-3CC0B33FBCD1}" =
"{4B9F45E8-E3CE-40B4-9463-80A9B3481DEF}" = Banctec Service Agreement
"{53735ECE-E461-4FD0-B742-23A352436D3A}" = Logitech Updater
"{53EE9E42-CECB-4C92-BF76-9CA65DAF8F1C}" = FullDPAppQFolder
"{541DEAC0-5F3D-45E6-B7CB-94ECF3B96748}" = Skype web features
"{54E3707F-808E-4fd4-95C9-15D1AB077E5D}" = NewCopy
"{56EE8B17-8274-418d-89AC-C057C5DB251E}" = RandMap
"{56F8AFC3-FA98-4ff1-9673-8A026CBF85BE}" = WebReg
"{5888428E-699C-4E71-BF71-94EE06B497DA}" = TuneUp Utilities 2008
"{5A01C58E-B0EC-49b9-AD71-7C0468688087}" = CP_Package_Basic1
"{5B622B7A-60FB-4630-B11D-F121D20BCCD6}" = MarketResearch
"{5B79CFD1-6845-4158-9D7D-6BE89DF2C135}" = HP PSC & OfficeJet 5.3.B
"{5E835305-63BB-4E55-BBB7-EEBBE67774DB}" = Sonic MyDVD
"{60859BF2-5151-473C-8F76-7F3A232CF7E7}" = MM Number Heroes
"{64116298-93C5-401D-B06C-39D8E3338508}" = DAO
"{64658686-0CD4-4CF6-983D-0A6BE32007DB}" = Business Complete Care Services Agreement
"{66BA8C26-AFE4-4408-807B-43E76B57EF53}" = SkinsHP1
"{66E6CE0C-5A1E-430C-B40A-0C90FF1804A8}" = eSupportQFolder
"{6811CAA0-BF12-11D4-9EA1-0050BAE317E1}" = PowerDVD
"{68D60342-7686-45C9-B8EB-40EF843D0460}" = Dell Networking Guide
"{6994491D-D491-48F1-AE1F-E179C1FFFC2F}" = HP Photosmart Essential
"{6BB6627C-694F-4FDC-A3E5-C7F4BED4C724}" = DocProc
"{6F5E2F4A-377D-4700-B0E3-8F7F7507EA15}" = CustomerResearchQFolder
"{70C002F0-5308-42D8-A65A-91436B90255C}" = MakeAMov
"{7148F0A8-6813-11D6-A77B-00B0D0142000}" = Java 2 Runtime Environment, SE v1.4.2
"{748F4870-8350-11D3-B0BF-080009FB4A19}" = HP Share-to-Web
"{77DCDCE3-2DED-62F3-8154-05E745472D07}" = Acrobat.com
"{77FCC1D4-E78E-46A4-80A6-7F456FA9AC90}" = Finding Nemo: Nemo's Underwater World of Fun Special Edition
"{7850A6D2-CBEA-4728-9877-F1BEDEA9F619}" = AiOSoftware
"{7C9B95B7-B598-4398-B30F-7F6827192E6C}" = ProductContext
"{7DD9A065-2C86-4A9F-A5FF-796EC1B99DCA}" = AnswerWorks 4.0 Runtime - English
"{7E27304E-BAA2-4d90-A34E-76641FAFABB4}" = CP_AtenaShokunin1Config
"{7EFA5E6F-74F7-4AFB-8AEA-AA790BD3A76D}" = DellSupport
"{7F142D56-3326-11D5-B229-002078017FBF}" = Modem Helper
"{8EF1122E-E90C-4EE9-AB0C-7FDE2BA42C26}" = Musicmatch® Jukebox
"{90AF0409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office PowerPoint Viewer 2003
"{90D55A3F-1D99-4C94-A77E-46DC14F0BF08}" = Help and Support Customization
"{91130409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office Basic Edition 2003
"{923A7F5A-1E8C-4FBE-8DF6-85940A60A79F}" = Readme
"{9541FED0-327F-4DF0-8B96-EF57EF622F19}" = Sonic RecordNow!
"{98DF85D9-96C0-4F57-A92E-C3539477EF5E}" = DVDSentry
"{9B79DCB0-AAD7-456B-8D07-433C936FA24B}" = DS21Patch
"{A195B13E-A5E3-4BAF-A995-7F70F445CD06}" = ScannerCopy
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{A5BB5365-EFB4-44c3-A7E2-EB59B7EFD23D}" = CueTour
"{A790BEB1-BCCF-4EC6-807B-5708B36E8A79}" = Intel® PROSet
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{AB5D51AE-EBC3-438D-872C-705C7C2084B0}" = DeviceManagementQFolder
"{AC76BA86-7AD7-1033-7B44-A90000000001}" = Adobe Reader 9
"{AEAEEAD6-38EC-4321-92A7-599367E21FF2}" = Rosetta Stone V3 DEMO
"{B208806F-A231-4FA0-AB3F-5C1B8979223E}" = Microsoft ActiveSync 4.0
"{B4092C6D-E886-4CB2-BA68-FE5A88D31DE6}_is1" = Spybot - Search & Destroy
"{B824B5C9-849F-4b9e-9EA7-6FD8CD8116DA}" = CP_Package_Variety2
"{B996AE66-10DB-4ac5-B151-E8B4BFBC42FC}" = BufferChm
"{BBA67AB4-94E3-4818-8104-7B6CF7F8538C}" = DesignPro 5.0 Sign Edition
"{BBF6D0CD-A081-369F-B0B8-F168594CBB6B}" = Google Talk Plugin
"{BFD5AC8A-5884-4da8-9873-3DF8E3DCCE18}" = 5600Trb
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{C506A18C-1469-4678-B094-F4EC9DAE6DB7}" = Scan
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{CC7984C5-020D-4944-85A0-58D09D4A8BFB}" = 5600_Help
"{CE24344F-DFD8-40C8-8FD8-C9740B5F25AC}" = Fax
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{CF40ACC5-E1BB-4aff-AC72-04C2F616BCA7}" = getPlus®
"{D103C4BA-F905-437A-8049-DB24763BBE36}" = Skype™ 4.1
"{D6DE02C7-1F47-11D4-9515-00105AE4B89A}" = Paint Shop Pro 7
"{DD2F0FE7-A3FD-45AE-92A6-DA46166B3158}" = Find Rugs
"{DED53B0B-B67C-4244-AE6A-D6FD3C28D1EF}" = Ad-Aware 2007
"{E3F90083-80D4-4b5a-87C7-E97E12F5516D}" = HPProductAssistant
"{EA103B64-C0E4-4C0E-A506-751590E1653D}" = SolutionCenter
"{EF6F70D0-C242-4047-946B-98EA8208481A}" = ArcSoft TotalMedia Backup & Record
"{F07B861C-72B9-40A4-8B1A-AAED4C06A7E8}" = QuickTime
"{F4C2E5F5-2970-45f4-ABD3-C180C4D961C4}" = Status
"{F54AC413-D2C6-4A24-B324-370C223C6250}" = Adobe Photoshop Elements 6.0
"{FC4ED75D-916C-4A8C-BB67-3C6F6E06D62B}" = Banctec Service Agreement
"{FF77941A-2BFA-4A18-BE2E-69B9498E4D55}" = User Profile Hive Cleanup Service
"102 Dalmatians Activity Center" = 102 Dalmatians Activity Center
"ACDSee" = ACDSee
"ActiveTouchMeetingClient" = WebEx
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Adobe Photoshop Elements 6" = Adobe Photoshop Elements 6.0
"AOL Toolbar 5.0" =
"BCM V.92 56K Modem" = BCM V.92 56K Modem
"com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Acrobat.com
"Dell Digital Jukebox Driver" = Dell Digital Jukebox Driver
"Excel Invoice Manager_is1" = Excel Invoice Manager 2.12.1016
"Full Speed2.1" = Full Speed
"HP Imaging Device Functions" = HP Imaging Device Functions 5.3
"HP Photo & Imaging" = HP Image Zone 5.3
"HP Photo Imaging Software" = HP Photo Imaging Software
"HP Photo Printing Software" = HP Photo Printing Software
"HP Solution Center & Imaging Support Tools" = HP Solution Center & Imaging Support Tools 5.3
"HPExtendedCapabilities" = HP Extended Capabilities 5.3
"IDNMitigationAPIs" = Microsoft Internationalized Domain Names Mitigation APIs
"InstallShield_{70C002F0-5308-42D8-A65A-91436B90255C}" = Make a Movie
"InstallShield_{77FCC1D4-E78E-46A4-80A6-7F456FA9AC90}" = Finding Nemo: Nemo's Underwater World of Fun Special Edition
"InstallShield_{BBA67AB4-94E3-4818-8104-7B6CF7F8538C}" = DesignPro 5.0 Sign Edition
"InterActual Player" = InterActual Player
"Knowmad" = Knowmad
"lvdrivers_11.80" = Logitech QuickCam Driver Package
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Mozilla Firefox (3.6.3)" = Mozilla Firefox (3.6.3)
"MSCompPackV1" = Microsoft Compression Client Pack 1.0 for Windows XP
"NetAlyzer_is1" = NetAlyzer 0.3
"NLSDownlevelMapping" = Microsoft National Language Support Downlevel APIs
"NVIDIA Drivers" = NVIDIA Drivers
"PROSet" = Intel® PRO Network Adapters and Drivers
"RealPlayer 6.0" = RealOne Player
"Revo Uninstaller" = Revo Uninstaller 1.85
"Shockwave" = Shockwave
"StreetPlugin" = Learn2 Player (Uninstall Only)
"The ClueFinders Reading Adventures Ages 9-12" = The ClueFinders Reading Adventures Ages 9-12
"TS2AC" = Toy Story 2 Activity Center
"TurboTax Home & Business 2007" = TurboTax Home & Business 2007
"Windows Media Format Runtime" = Windows Media Format 11 runtime
"Windows Media Player" = Windows Media Player 11
"Windows XP Service Pack" = Windows XP Service Pack 3
"WinRAR archiver" = WinRAR archiver
"WMFDist11" = Windows Media Format 11 runtime
"wmp11" = Windows Media Player 11
"Wudf01000" = Microsoft User-Mode Driver Framework Feature Pack 1.0
"Your Uninstaller! 2008_is1" = Your Uninstaller! 2008 Version 6.0

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 9/15/2009 10:35:30 AM | Computer Name = KOUCHI | Source = Application Hang | ID = 1002
Description = Hanging application firefox.exe, version 1.9.0.3526, hang module hungapp,
version 0.0.0.0, hang address 0x00000000.

Error - 9/15/2009 10:35:41 AM | Computer Name = KOUCHI | Source = Application Hang | ID = 1001
Description = Fault bucket 1442353534.

Error - 9/19/2009 11:05:07 AM | Computer Name = KOUCHI | Source = Google Update | ID = 20
Description =

Error - 9/26/2009 10:40:09 AM | Computer Name = KOUCHI | Source = Application Hang | ID = 1002
Description = Hanging application firefox.exe, version 1.9.0.3526, hang module hungapp,
version 0.0.0.0, hang address 0x00000000.

Error - 9/26/2009 10:40:39 AM | Computer Name = KOUCHI | Source = Application Hang | ID = 1001
Description = Fault bucket 1442353534.

Error - 10/1/2009 1:31:30 PM | Computer Name = KOUCHI | Source = Application Error | ID = 1000
Description = Faulting application acdsee.exe, version 3.1.0.0, faulting module
acdsee.exe, version 3.1.0.0, fault address 0x00080726.

Error - 10/10/2009 12:10:49 PM | Computer Name = KOUCHI | Source = Application Hang | ID = 1002
Description = Hanging application firefox.exe, version 1.9.0.3526, hang module hungapp,
version 0.0.0.0, hang address 0x00000000.

Error - 10/10/2009 12:10:49 PM | Computer Name = KOUCHI | Source = Application Hang | ID = 1002
Description = Hanging application firefox.exe, version 1.9.0.3526, hang module hungapp,
version 0.0.0.0, hang address 0x00000000.

Error - 10/19/2009 11:39:16 AM | Computer Name = KOUCHI | Source = Application Hang | ID = 1002
Description = Hanging application firefox.exe, version 1.9.0.3526, hang module hungapp,
version 0.0.0.0, hang address 0x00000000.

Error - 10/19/2009 11:39:37 AM | Computer Name = KOUCHI | Source = Application Hang | ID = 1001
Description = Fault bucket 1442353534.

[ System Events ]
Error - 4/9/2010 5:12:56 PM | Computer Name = KOUCHI | Source = DCOM | ID = 10005
Description = DCOM got error "%1084" attempting to start the service EventSystem
with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF}

Error - 4/9/2010 5:13:08 PM | Computer Name = KOUCHI | Source = DCOM | ID = 10005
Description = DCOM got error "%1084" attempting to start the service MDM with arguments
"" in order to run the server: {0C0A3666-30C9-11D0-8F20-00805F2CD064}

Error - 4/9/2010 5:13:16 PM | Computer Name = KOUCHI | Source = DCOM | ID = 10005
Description = DCOM got error "%1084" attempting to start the service MDM with arguments
"" in order to run the server: {0C0A3666-30C9-11D0-8F20-00805F2CD064}

Error - 4/9/2010 5:14:31 PM | Computer Name = KOUCHI | Source = DCOM | ID = 10005
Description = DCOM got error "%1084" attempting to start the service netman with
arguments "" in order to run the server: {BA126AE5-2166-11D1-B1D0-00805FC1270E}

Error - 4/9/2010 5:14:53 PM | Computer Name = KOUCHI | Source = DCOM | ID = 10005
Description = DCOM got error "%1084" attempting to start the service StiSvc with
arguments "" in order to run the server: {A1F4E726-8CF1-11D1-BF92-0060081ED811}

Error - 4/9/2010 5:14:53 PM | Computer Name = KOUCHI | Source = DCOM | ID = 10005
Description = DCOM got error "%1084" attempting to start the service StiSvc with
arguments "" in order to run the server: {A1F4E726-8CF1-11D1-BF92-0060081ED811}

Error - 4/9/2010 5:18:08 PM | Computer Name = KOUCHI | Source = DCOM | ID = 10005
Description = DCOM got error "%1084" attempting to start the service MDM with arguments
"" in order to run the server: {0C0A3666-30C9-11D0-8F20-00805F2CD064}

Error - 4/9/2010 5:18:16 PM | Computer Name = KOUCHI | Source = DCOM | ID = 10005
Description = DCOM got error "%1084" attempting to start the service MDM with arguments
"" in order to run the server: {0C0A3666-30C9-11D0-8F20-00805F2CD064}

Error - 4/9/2010 5:23:08 PM | Computer Name = KOUCHI | Source = DCOM | ID = 10005
Description = DCOM got error "%1084" attempting to start the service MDM with arguments
"" in order to run the server: {0C0A3666-30C9-11D0-8F20-00805F2CD064}

Error - 4/9/2010 5:23:16 PM | Computer Name = KOUCHI | Source = DCOM | ID = 10005
Description = DCOM got error "%1084" attempting to start the service MDM with arguments
"" in order to run the server: {0C0A3666-30C9-11D0-8F20-00805F2CD064}


< End of report >

Comments: I note several AV suites may have been involved. I can only find ESET Smart Security actually installed. May be leftover entries in the reg. We'll (I'll) need to clean the reg up too (I'll use CCleaner). He purchased this used several months ago. Everything running fine until… The registry is to be respected but I have no problem editting it just FYI.


Ready for next step???

H
Hi,


Please go here and have a look how you can disable your security software.

Download Combofix from any of the links below but rename it to before saving it to your desktop.

Link 1
Link 2



——————————————————————–

Double click on the renamed Combofix.exe & follow the prompts.
  • When finished, it will produce a report for you.
  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.
  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.
**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.

[external image: Posted Image]


Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]


Click on Yes, to continue scanning for malware.

When finished, it will produce a log for you. Please include the C:\ComboFix.txt in your next reply.

This tool is not a toy and not for everyday use.
ComboFix SHOULD NOT be used unless requested by a forum helper


If you need help, see this link:
http://www.bleepingcomputer.com/combofix/how-to-use-combofix
Shrauber - Question: I am running CF in Safe Mode. Although not specifically requested to do so, I am doing it. CF (what I renamed ComboFix to) reports that ESET v3 is running and warns me to close it. TaskMgr does not show ESET running (it would be named "ekrn" and "egui" in the Processes panel. In Safe Mode, no AV is launched, I believe. Therefore… Is it safe/OK for me to continue with CF? In Safe Mode there is no ESET GUI to disable it. I don't really think it's running. Agree? Continue? H
Schrauber - here's where we are after roughly 2 hours of CF. CF started in Safe Mode. AS CF stepped through its "phases", I went out. Came back some time later and System was sitting at the Windows LogIn screen for all three users. It had rebooted on its own. Foolishly, hastily, I clicked on a user account and launched. Desktop appeared, icons appeared. ComboFix put up its DOS box and said, "Please wait". Then a bit later it said "Writing the Log File" and "Do not run any programs until CF is finished". Well, as you can expect, after about 3 minutes the crapware (Your Protection, Network Activity Attack, Keylogger Detected - please clean - started popping up which to me means a program is running. I realize I should not have logged in but I should have done a restart into Safe Mode. Would CF have continued? Probably. Should I be dismissing or handling these popups in any way? Anyway, CF has been sitting on this "Do not run…" window for about a half hour. I can see and hear disk activity. Have I ruined it? H
Scrauber: It finally produced a log! I thought for sure it was dead. Below is the CF log. Just remember, this log was created while in Standard mode, not Safe Mode. I started CF in Safe Mode but it ended in Standard Mode, OK? If I need to redo CF, please let me know and this time, I'll be more careful. If this log is OK (I think I recognize some things in there) then just let me know the next step(s). Thanks.
H

ComboFix 10-04-10.01 - Administrator 04/10/2010 14:30:44.1.2 - x86 MINIMAL
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.511.199 [GMT -4:00]
Running from: c:\infection\CF.exe
AV: ESET Smart Security 3.0 *On-access scanning enabled* (Outdated) {E5E70D32-0101-4F12-8FB0-D96ACA4F34C0}
FW: ESET Personal firewall *enabled* {E5E70D32-0101-4340-86A3-A7B0F1C8FFE0}

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\documents and settings\Administrator\Application Data\AntiVirus Plus
c:\documents and settings\Administrator\Application Data\AntiVirus Plus\AntiVirus Plus.55532.dll
c:\documents and settings\Administrator\Application Data\avp.ico
c:\documents and settings\Administrator\Local Settings\Application Data\ave.exe
c:\documents and settings\All Users\Application Data\_VOIDmfeklnmal.dll
c:\documents and settings\All Users\Favorites\_favdata.dat
c:\documents and settings\All Users\Start Menu\HP Image Zone .lnk
c:\documents and settings\Andrew\.COMMgr
c:\documents and settings\Andrew\.COMMgr\complmgr.exe
c:\documents and settings\Andrew\Application Data\ACD Systems\ACDSee\ImageDB.ddf
c:\documents and settings\Andrew\Application Data\AntiVirus Plus
c:\documents and settings\Andrew\Application Data\AntiVirus Plus\AntiVirus Plus.55532.dll
c:\documents and settings\Andrew\Application Data\avp.ico
c:\documents and settings\Andrew\err.log
c:\documents and settings\Andrew\ResErrors.log
c:\documents and settings\Cynthia\Application Data\ACD Systems\ACDSee\ImageDB.ddf
c:\program files\Common Files\fnts~1
c:\program files\scurit~1
c:\temp\tn3
C:\Thumbs.db
c:\windows\_VOIDcbvttrrpti
c:\windows\_VOIDcbvttrrpti\_VOIDd.sys
c:\windows\cookies.ini
c:\windows\system32\_VOIDbxvoaictbh.dll
c:\windows\system32\_VOIDcndecdmxjy.dat
c:\windows\system32\_VOIDtegrmeyqol.dll
c:\windows\system32\_VOIDufrfujecxo.dll
c:\windows\system32\4F3X
c:\windows\system32\6to4v32.dll
c:\windows\system32\awxm.vho
c:\windows\system32\certstore.dat
c:\windows\system32\cjyppboxj.dll
c:\windows\system32\fadokase.dll
c:\windows\system32\fagopitu.dll
c:\windows\system32\famujize.dll
c:\windows\system32\fhpatch.dll
c:\windows\system32\fiplock.dll
c:\windows\system32\fodulivu.dll
c:\windows\system32\guderasa.dll
c:\windows\system32\htmp.030
c:\windows\system32\Iasex.dll
c:\windows\system32\IPHACTION.dll
c:\windows\system32\iphy.dll
c:\windows\system32\jahanane.dll
c:\windows\system32\k86.bin
c:\windows\system32\lomehuda.exe
c:\windows\system32\mehoguhi.exe
c:\windows\system32\ropusolo.dll
c:\windows\system32\seagate.sys
c:\windows\system32\sinizamu.dll
c:\windows\system32\sohojire.dll
c:\windows\system32\sozivado.dll
c:\windows\system32\stera.log
c:\windows\system32\tmp.reg
c:\windows\system32\topapope.dll

Infected copy of c:\windows\system32\srsvc.dll was found and disinfected
Restored copy from - c:\windows\ServicePackFiles\i386\srsvc.dll

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

——-\Legacy_6TO4
——-\Legacy_CORE
——-\Legacy_IAS
——-\Legacy_NETWORK_MONITOR
——-\Legacy_SEAGATE
——-\Legacy__VOIDCBVTTRRPTI
——-\Legacy__VOIDd.sys
——-\Service__VOIDcbvttrrpti
——-\Service__VOIDd.sys
——-\Service_6to4
——-\Service_Ias
——-\Service_seagate


((((((((((((((((((((((((( Files Created from 2010-03-10 to 2010-04-10 )))))))))))))))))))))))))))))))
.

2010-04-09 11:21 . 2010-04-09 11:21 ——– d—–w- c:\program files\VS Revo Group
2010-04-09 10:59 . 2010-04-10 18:16 ——– d—–w- C:\Infection
2010-04-08 21:06 . 2010-04-08 21:06 ——– d—–w- c:\documents and settings\All Users\Application Data\e70ff5a
2010-04-08 20:42 . 2010-04-08 20:43 226304 –sha-w- c:\documents and settings\Administrator\Local Settings\Application Data\2269221376.dll
2010-04-08 20:23 . 2010-04-08 20:23 ——– d—–w- c:\documents and settings\Administrator\Application Data\Malwarebytes
2010-04-08 20:23 . 2010-04-08 20:23 ——– d—–w- c:\documents and settings\All Users\Application Data\Malwarebytes
2010-04-08 20:21 . 2010-01-07 22:55 5115824 —-a-w- C:\mbs.exe.exe
2010-04-07 21:05 . 2010-04-07 21:06 ——– d—–w- c:\documents and settings\NetworkService\Local Settings\Application Data\Adobe
2010-04-07 21:05 . 2010-04-07 21:05 664 —-a-w- c:\windows\system32\d3d9caps.dat
2010-04-05 18:01 . 2010-04-05 19:25 ——– d—–w- c:\program files\Your Protection

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-04-10 19:09 . 2002-08-29 10:00 153344 —-a-w- c:\windows\system32\drivers\dmio.sys
2010-04-05 20:01 . 2005-07-06 18:18 ——– d—–w- c:\program files\The Learning Company
2010-04-05 19:59 . 2008-05-31 12:14 ——– d—a-w- c:\documents and settings\All Users\Application Data\TEMP
2010-04-05 18:19 . 2008-07-05 16:04 ——– d—–w- c:\documents and settings\Andrew\Application Data\Skype
2010-04-05 15:24 . 2009-05-09 18:46 ——– d—–w- c:\documents and settings\Andrew\Application Data\skypePM
2010-03-26 09:23 . 2009-05-16 18:18 0 —-a-w- c:\windows\system32\drivers\lvuvc.hs
2010-03-26 09:23 . 2009-05-16 18:18 0 —-a-w- c:\windows\system32\drivers\logiflt.iad
2010-03-11 12:38 . 2004-02-06 22:05 832512 —-a-w- c:\windows\system32\wininet.dll
2010-03-11 12:38 . 2004-08-04 07:56 78336 —-a-w- c:\windows\system32\ieencode.dll
2010-03-11 12:38 . 2002-08-29 10:00 17408 —-a-w- c:\windows\system32\corpol.dll
2010-03-10 15:04 . 2006-03-11 21:29 ——– d—–w- c:\documents and settings\Andrew\Application Data\Image Zone Express
2010-02-12 22:12 . 2009-05-09 18:45 ——– d—–w- c:\program files\Google
2002-08-29 10:00 . 2002-08-29 10:00 94784 –sh–w- c:\windows\TWAIN.DLL
2008-04-14 00:12 . 2002-08-29 10:00 50688 –sh–w- c:\windows\twain_32.dll
2010-01-08 21:06 . 2010-01-08 21:06 200704 –sha-w- c:\windows\SYSTEM32\diperede.exe
2008-04-14 00:11 . 2002-08-29 10:00 1028096 –sha-w- c:\windows\SYSTEM32\mfc42.dll
2008-04-14 00:12 . 2002-08-29 10:00 57344 –sha-w- c:\windows\SYSTEM32\msvcirt.dll
2008-04-14 00:12 . 2002-08-29 10:00 413696 –sha-w- c:\windows\SYSTEM32\msvcp60.dll
2008-04-14 00:12 . 2002-08-29 10:00 343040 –sha-w- c:\windows\SYSTEM32\msvcrt.dll
2008-04-14 00:12 . 2002-08-29 10:00 551936 –sh–w- c:\windows\SYSTEM32\oleaut32.dll
2008-04-14 00:12 . 2002-08-29 10:00 84992 –sha-w- c:\windows\SYSTEM32\olepro32.dll
.

——- Sigcheck ——-

[7] 2008-04-14 . D8E14A61ACC1D4A6CD0D38AEBAC7FA3B . 57856 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\spoolsv.exe
[7] 2008-04-14 . D8E14A61ACC1D4A6CD0D38AEBAC7FA3B . 57856 . . [5.1.2600.5512] . . c:\windows\SoftwareDistribution\Download\dd9ab5193501484cf5e6884fa1d22f9e\spoolsv.exe
[-] 2008-04-14 . 58F7C0F84451D2C4CC5DC0E840722908 . 82432 . . [5.1.2600.5512] . . c:\windows\SYSTEM32\spoolsv.exe
[7] 2005-06-11 . AD3D9D191AEA7B5445FE1D82FFBB4788 . 57856 . . [5.1.2600.2696] . . c:\windows\$hf_mig$\KB896423\SP2QFE\spoolsv.exe
[7] 2005-06-10 . DA81EC57ACD4CDC3D4C51CF3D409AF9F . 57856 . . [5.1.2600.2696] . . c:\windows\$NtServicePackUninstall$\spoolsv.exe
[7] 2004-08-04 . 7435B108B935E42EA92CA94F59C8E717 . 57856 . . [5.1.2600.2180] . . c:\windows\$NtUninstallKB896423$\spoolsv.exe

[7] 2008-04-14 . A93AEE1928A9D7CE3E16D24EC7380F89 . 26112 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\userinit.exe
[7] 2008-04-14 . A93AEE1928A9D7CE3E16D24EC7380F89 . 26112 . . [5.1.2600.5512] . . c:\windows\SoftwareDistribution\Download\dd9ab5193501484cf5e6884fa1d22f9e\userinit.exe
[-] 2008-04-14 . E26CCD9204B71DA3458E7FE61AB1502E . 50688 . . [5.1.2600.5512] . . c:\windows\SYSTEM32\userinit.exe
[7] 2004-08-04 . 39B1FFB03C2296323832ACBAE50D2AFF . 24576 . . [5.1.2600.2180] . . c:\windows\$NtServicePackUninstall$\userinit.exe

[-] 2008-04-14 . 0EC7851A403627717B23D86CC5561423 . 1058816 . . [6.00.2900.5512] . . c:\windows\explorer.exe
[7] 2008-04-14 . 12896823FB95BFB3DC9B46BCAEDC9923 . 1033728 . . [6.00.2900.5512] . . c:\windows\ServicePackFiles\i386\explorer.exe
[7] 2008-04-14 . 12896823FB95BFB3DC9B46BCAEDC9923 . 1033728 . . [6.00.2900.5512] . . c:\windows\SoftwareDistribution\Download\dd9ab5193501484cf5e6884fa1d22f9e\explorer.exe
[7] 2007-06-13 . 7712DF0CDDE3A5AC89843E61CD5B3658 . 1033216 . . [6.00.2900.3156] . . c:\windows\$hf_mig$\KB938828\SP2QFE\explorer.exe
[7] 2007-06-13 . 97BD6515465659FF8F3B7BE375B2EA87 . 1033216 . . [6.00.2900.3156] . . c:\windows\$NtServicePackUninstall$\explorer.exe
[7] 2004-08-04 . A0732187050030AE399B241436565E64 . 1032192 . . [6.00.2900.2180] . . c:\windows\$NtUninstallKB938828$\explorer.exe

[7] 2008-04-14 . F92E1076C42FCD6DB3D72D8CFE9816D5 . 13824 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\wscntfy.exe
[7] 2008-04-14 . F92E1076C42FCD6DB3D72D8CFE9816D5 . 13824 . . [5.1.2600.5512] . . c:\windows\SoftwareDistribution\Download\dd9ab5193501484cf5e6884fa1d22f9e\wscntfy.exe
[-] 2008-04-14 . 8CAB904B982D7ADBC71405DFFE72930D . 38400 . . [5.1.2600.5512] . . c:\windows\SYSTEM32\wscntfy.exe
[7] 2004-08-04 . 49911DD39E023BB6C45E4E436CFBD297 . 13824 . . [5.1.2600.2180] . . c:\windows\$NtServicePackUninstall$\wscntfy.exe

[7] 2008-04-14 . 5F1D5F88303D4A4DBC8E5F97BA967CC3 . 15360 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\ctfmon.exe
[7] 2008-04-14 . 5F1D5F88303D4A4DBC8E5F97BA967CC3 . 15360 . . [5.1.2600.5512] . . c:\windows\SoftwareDistribution\Download\dd9ab5193501484cf5e6884fa1d22f9e\ctfmon.exe
[-] 2008-04-14 . 9FB8051B8A86FC686EAB5EC83952C5CB . 39936 . . [5.1.2600.5512] . . c:\windows\SYSTEM32\ctfmon.exe
[7] 2004-08-04 . 24232996A38C0B0CF151C2140AE29FC8 . 15360 . . [5.1.2600.2180] . . c:\windows\$NtServicePackUninstall$\ctfmon.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Your Protection"="c:\program files\Your Protection\urpprot.exe" [2010-04-05 2383872]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-05-03 13529088]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk *\0stera\0lsdelete

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\aawservice]
@="Service"

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^America Online 8.0 Tray Icon.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\America Online 8.0 Tray Icon.lnk
backup=c:\windows\pss\America Online 8.0 Tray Icon.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^AOL Companion.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\AOL Companion.lnk
backup=c:\windows\pss\AOL Companion.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk
backup=c:\windows\pss\HP Digital Imaging Monitor.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HP Image Zone Fast Start.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\HP Image Zone Fast Start.lnk
backup=c:\windows\pss\HP Image Zone Fast Start.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HP OfficeJet Startup.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\HP OfficeJet Startup.lnk
backup=c:\windows\pss\HP OfficeJet Startup.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^TotalMedia Backup Monitor.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\TotalMedia Backup Monitor.lnk
backup=c:\windows\pss\TotalMedia Backup Monitor.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UserFaultCheck]
c:\windows\system32\dumprep 0 -u [X]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Photo Downloader]
2007-09-11 04:43 67488 —-a-w- c:\program files\Adobe\Photoshop Elements 6.0\apdproxy.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BCMSMMSG]
2003-08-29 08:59 122880 —-a-w- c:\windows\BCMSMMSG.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
2008-04-14 00:12 39936 —-a-w- c:\windows\SYSTEM32\ctfmon.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CXMon]
2001-09-19 15:18 69632 —-a-w- c:\program files\Hewlett-Packard\PhotoSmart\Photo Imaging\Hpi_monitor.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DellSupport]
2007-03-15 16:09 460784 —-a-w- c:\program files\DellSupport\DSAgnt.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\dla]
2003-08-06 06:04 114741 —-a-w- c:\windows\SYSTEM32\dla\tfswctrl.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DVDSentry]
2003-08-13 15:27 28672 —-a-w- c:\windows\SYSTEM32\DSentry.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\egui]
2008-04-23 18:57 1443072 —-a-w- c:\program files\ESET\ESET Smart Security\egui.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\H/PC Connection Agent]
2006-06-21 02:36 1207080 —-a-w- c:\program files\Microsoft ActiveSync\wcescomm.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]
2007-05-08 20:24 54840 —-a-w- c:\program files\HP\HP Software Update\hpwuSchd2.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HPDJ Taskbar Utility]
2005-03-08 04:42 176128 —-a-w- c:\windows\SYSTEM32\SPOOL\DRIVERS\W32X86\3\hpztsb12.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LogitechCommunicationsManager]
2008-08-14 21:11 565008 —-a-w- c:\program files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LogitechQuickCamRibbon]
2008-08-14 21:15 2407184 —-a-w- c:\program files\Logitech\QuickCam\Quickcam.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\mmtask]
2006-01-17 18:03 53248 —-a-w- c:\program files\MUSICMATCH\MUSICMATCH Jukebox\mmtask.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
2008-04-14 00:12 1719808 —-a-w- c:\program files\Messenger\msmsgs.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nodenable]
2008-08-22 21:33 359639 —-a-w- c:\program files\ESET\nodenable.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NodLogin]
2008-07-29 10:00 358448 —-a-w- c:\program files\ESET\ESET Smart Security\nodlogin.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon]
2008-05-03 02:46 13529088 —-a-w- c:\windows\SYSTEM32\nvcpl.dll

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvMediaCenter]
2008-05-03 02:46 86016 —-a-w- c:\windows\SYSTEM32\nvmctray.dll

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nwiz]
2008-05-03 02:46 1630208 —-a-w- c:\windows\SYSTEM32\nwiz.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
2006-09-01 20:57 282624 —-a-w- c:\program files\QuickTime\qttask.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RealPlayer]
2006-05-26 16:19 1003520 —-a-w- c:\program files\Real\RealPlayer\realplay.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Share-to-Web Namespace Daemon]
2001-07-03 14:11 57344 —-a-w- c:\program files\Hewlett-Packard\PhotoSmart\HP Share-to-Web\hpgs2wnd.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpybotSD TeaTimer]
2008-01-28 15:43 2097488 –sha-r- c:\program files\Spybot - Search & Destroy\TeaTimer.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\StorageGuard]
2003-02-13 06:01 155648 —-a-w- c:\program files\Common Files\Sonic\Update Manager\sgtray.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
2003-10-23 07:43 151597 —-a-w- c:\program files\Common Files\Real\Update_OB\realsched.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"mcpromgr"=2 (0x2)
"mcmispupdmgr"=3 (0x3)
"Viewpoint Manager Service"=2 (0x2)

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" -atboottime

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiVirus]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
"DisableNotifications"= 1 (0x1)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Common Files\\aol\\Loader\\aolload.exe"=
"c:\\Program Files\\Common Files\\aol\\System Information\\sinf.exe"=
"c:\\WINDOWS\\SYSTEM32\\fxsclnt.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqCopy.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpfccopy.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqPhUnl.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqDIA.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"=
"c:\program files\Microsoft ActiveSync\rapimgr.exe"= c:\program files\Microsoft ActiveSync\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager
"c:\program files\Microsoft ActiveSync\wcescomm.exe"= c:\program files\Microsoft ActiveSync\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager
"c:\program files\Microsoft ActiveSync\WCESMgr.exe"= c:\program files\Microsoft ActiveSync\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application
"c:\\Program Files\\Real\\RealPlayer\\trueplay.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Rosetta Stone\\Rosetta Stone V3 DEMO\\RosettaStoneVersion3.exe"=
"c:\\Program Files\\Rosetta Stone\\Rosetta Stone V3 DEMO\\support\\bin\\RosettaStoneLtdServices.exe"=
"c:\\Documents and Settings\\Andrew\\Local Settings\\Application Data\\Google\\Google Talk Plugin\\googletalkplugin.dll"=
"c:\\Documents and Settings\\Andrew\\Local Settings\\Application Data\\Google\\Google Talk Plugin\\googletalkplugin.exe"=
"c:\\Program Files\\Skype\\Plugin Manager\\skypePM.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\WINDOWS\\SYSTEM32\\spoolsv.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"26675:TCP"= 26675:TCP:169.254.2.0/255.255.255.0:Enabled:ActiveSync Service
""=


— Other Services/Drivers In Memory —

*Deregistered* - uphcleanhlp

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp
.
Contents of the 'Scheduled Tasks' folder

2010-04-10 c:\windows\Tasks\1-Click Maintenance.job
- c:\program files\TuneUp Utilities 2008\OneClickStarter.exe [2008-02-29 18:24]

2010-04-10 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-02-12 16:09]

2010-04-10 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-02-12 16:09]

2010-04-08 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-217248739-2920639104-3160564834-1007Core.job
- c:\documents and settings\Andrew\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2009-04-20 15:50]

2010-04-10 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-217248739-2920639104-3160564834-1007UA.job
- c:\documents and settings\Andrew\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2009-04-20 15:50]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.aol.com/
mStart Page = hxxp://www.dellnet.com
Trusted Zone: turbotax.com
TCP: {897681E9-2067-422E-A8FD-37CBF811F708} = 83.149.115.157,4.2.2.1,68.87.71.230 68.87.73.246
DPF: {193C772A-87BE-4B19-A7BB-445B226FE9A1} - hxxp://downloads.ewido.net/ewidoOnlineScan.cab
FF - ProfilePath - c:\documents and settings\Andrew\Application Data\Mozilla\Firefox\Profiles\823v7m0i.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.aol.com/
FF - plugin: c:\documents and settings\Andrew\Application Data\Mozilla\plugins\npgoogletalk.dll
FF - plugin: c:\documents and settings\Andrew\Local Settings\Application Data\Google\Update\1.2.183.23\npGoogleOneClick8.dll
FF - plugin: c:\program files\Google\Update\1.2.183.23\npGoogleOneClick8.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\

—- FIREFOX POLICIES —-
FF - user.js: network.http.max-persistent-connections-per-server - 4
FF - user.js: content.max.tokenizing.time - 200000
FF - user.js: content.notify.interval - 100000
FF - user.js: content.switch.threshold - 650000
FF - user.js: nglayout.initialpaint.delay - 300
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_colors", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_popup_windows", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.enable_click_image_resizing", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("accessibility.browsewithcaret_shortcut.enabled", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("javascript.options.mem.high_water_mark", 32);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("javascript.options.mem.gc_frequency", 1600);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("svg.smil.enabled", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.trackpoint_hack.enabled", -1);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.debug", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.agedWeight", 2);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.bucketSize", 1);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.maxTimeGroupings", 25);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.timeGroupingSize", 604800);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.boundaryWeight", 25);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.prefixWeight", 5);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("html5.enable", false);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pr
ef", true);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("app.update.download.backgroundInterval", 600);
c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("app.update.url.manual", "http://www.firefox.com");
c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-ja", "mozff");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add", "addons.mozilla.org");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add.36", "getpersonas.com");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("lightweightThemes.update.enabled", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.allTabs.previews", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.hide_infobar_for_outdated_plugin", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("toolbar.customization.usesheet", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.enable", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.max", 20);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.cachetime", 20);
.
- - - - ORPHANS REMOVED - - - -

BHO-{4fb83b6c-9563-49ed-b598-e71317081946} - sohojire.dll
BHO-{A9BA40A1-74F1-52BD-F431-00B15A2C8953} - (no file)
HKLM-Run-fomehelaro - topapope.dll
HKLM-Run-rohenahoz - c:\windows\system32\fodulivu.dll
HKU-Default-Run-AntiVirus Plus - c:\documents and settings\Administrator\Application Data\AntiVirus Plus\AntiVirus Plus.55532.dll
SharedTaskScheduler-{A9BA40A1-74F1-52BD-F431-00B15A2C8953} - (no file)
SharedTaskScheduler-{3d208b70-b224-4a08-b571-992734b1e1e2} - (no file)
SSODL-pedulibub-{3d208b70-b224-4a08-b571-992734b1e1e2} - (no file)
Notify-qomnnlj - qomnnlj.dll
SafeBoot-wATV03nt.sys
MSConfigStartUp-Adobe Reader Speed Launcher - c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe
MSConfigStartUp-AOLDialer - c:\program files\Common Files\AOL\ACS\AOLDial.exe
MSConfigStartUp-AOLSPScheduler - c:\program files\Common Files\AOL\1106322127\ee\services\safetyCore\ver210_5_4_1\AOLSP Scheduler.exe
MSConfigStartUp-COM+ Manager - c:\documents and settings\Andrew\.COMMgr\complmgr.exe
MSConfigStartUp-EmailScan - c:\program files\mcafee.com\antivirus\mcvsescn.exe
MSConfigStartUp-fomehelaro - topapope.dll
MSConfigStartUp-hf8wefhuaihf8ewfydiujhfdsfdf - c:\docume~1\Andrew\LOCALS~1\Temp\f7a6j.exe
MSConfigStartUp-HostManager - c:\program files\Common Files\AOL\1106322127\ee\AOLSoftware.exe
MSConfigStartUp-hsf87efjhdsf87f3jfsdi7fhsujfd - c:\docume~1\Andrew\LOCALS~1\Temp\login.exe
MSConfigStartUp-j5251532 - c:\windows\system32\j5251532.dll
MSConfigStartUp-mav_startupmon - c:\program files\Common Files\WinAntiVirus Pro 2007\mav_startupmon.exe
MSConfigStartUp-MCAgentExe - c:\progra~1\mcafee.com\agent\mcagent.exe
MSConfigStartUp-mcagent_exe - c:\program files\McAfee.com\Agent\mcagent.exe
MSConfigStartUp-MCUpdateExe - c:\progra~1\mcafee.com\agent\McUpdate.exe
MSConfigStartUp-MPFExe - c:\progra~1\McAfee.com\PERSON~1\MpfTray.exe
MSConfigStartUp-mplay32xe - c:\docume~1\Andrew\LOCALS~1\Temp\mplay32xe.exe
MSConfigStartUp-OASClnt - c:\program files\mcafee.com\antivirus\oasclnt.exe
MSConfigStartUp-ofmz - c:\progra~1\COMMON~1\ofmz\ofmzm.exe
MSConfigStartUp-rohenahoz - c:\windows\system32\fodulivu.dll
MSConfigStartUp-sscRun - c:\program files\Common Files\AOL\1106322127\ee\SSCRun.exe
MSConfigStartUp-updateMgr - c:\program files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe
MSConfigStartUp-VirusScan Online - c:\progra~1\mcafee.com\vso\mcvsshld.exe
MSConfigStartUp-VSOCheckTask - c:\progra~1\mcafee.com\vso\mcmnhdlr.exe
MSConfigStartUp-Yahoo! Pager - c:\program files\Yahoo!\Messenger\ypager.exe



**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-04-10 16:37
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************

Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer, http://www.gmer.net

device: opened successfully
user: MBR read successfully
called modules: ntoskrnl.exe CLASSPNP.SYS disk.sys >>UNKNOWN [0x8331BAC8]<<
kernel: MBR read successfully
detected MBR rootkit hooks:
\Driver\Disk -> CLASSPNP.SYS @ 0xf86eff28
\Driver\ACPI -> ACPI.sys @ 0xf8662cb8
\Driver\atapi -> atapi.sys @ 0xf85f4852
IoDeviceObjectType -> DeleteProcedure -> ntoskrnl.exe @ 0x805e668e
ParseProcedure -> ntoskrnl.exe @ 0x8057b6b1
\Device\Harddisk0\DR0 -> DeleteProcedure -> ntoskrnl.exe @ 0x805e668e
ParseProcedure -> ntoskrnl.exe @ 0x8057b6b1
NDIS: Intel® PRO/100 VE Network Connection -> SendCompleteHandler -> NDIS.sys @ 0xf84d8bb0
PacketIndicateHandler -> NDIS.sys @ 0xf84c7a0d
SendHandler -> NDIS.sys @ 0xf84dbb40
user & kernel MBR OK

**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————

[HKEY_USERS\S-1-5-21-217248739-2920639104-3160564834-1007\Software\Microsoft\Windows Mobile Disc\S*a*m*s*u*n*g* *B*l*a*c*k*J*a*c*k*"!\CriticalAppInstall\ActiveSync]
"Name"="ActiveSync"
"DisplayName"="Microsoft ActiveSync"
"Param1"="ActiveSync"
"Type"="wellknown"
"Order"=dword:00000001
"State"=dword:00000020

[HKEY_USERS\S-1-5-21-217248739-2920639104-3160564834-1007\Software\Microsoft\Windows Mobile Disc\S*a*m*s*u*n*g* *B*l*a*c*k*J*a*c*k*"!\CriticalAppInstall\IESettings]
"Name"="IESettings"
"Type"="IESettings"
"Order"=dword:00000004
"State"=dword:0000000b

[HKEY_USERS\S-1-5-21-217248739-2920639104-3160564834-1007\Software\Microsoft\Windows Mobile Disc\S*a*m*s*u*n*g* *B*l*a*c*k*J*a*c*k*"!\CriticalAppInstall\MediaFiles]
"Name"="MediaFiles"
"Type"="MediaFiles"
"Order"=dword:00000003
"State"=dword:0000000b

[HKEY_USERS\S-1-5-21-217248739-2920639104-3160564834-1007\Software\Microsoft\Windows Mobile Disc\S*a*m*s*u*n*g* *B*l*a*c*k*J*a*c*k*"!\CriticalAppInstall\NPW]
"Name"="NPW"
"Param1"="NPW"
"Type"="wellknown"
"Order"=dword:00000002
"State"=dword:0000000b

[HKEY_USERS\S-1-5-21-217248739-2920639104-3160564834-1007\Software\Microsoft\Windows Mobile Disc\S*a*m*s*u*n*g* *B*l*a*c*k*J*a*c*k*"!\CriticalAppInstall\Outlook]
"Name"="Outlook"
"DisplayName"="Microsoft Outlook"
"Param1"="Outlook"
"Type"="wellknown"
"Order"=dword:00000000
"State"=dword:00000020

[HKEY_USERS\S-1-5-21-217248739-2920639104-3160564834-1007\Software\Microsoft\Windows Mobile Disc\S*a*m*s*u*n*g* *B*l*a*c*k*J*a*c*k*"!\DesktopAppInstall\oemDesktop2]
"Name"="oemDesktop2"
"DisplayName"="Media Wizard"
"Param1"="\\EXTRAS\\DESKTOP\\Media_Wizard\\Media_Wizard_3.0.exe"
"Param2"=""
"Type"="createprocess"
"Order"=dword:00000000
"State"=dword:0000000b

[HKEY_USERS\S-1-5-21-217248739-2920639104-3160564834-1007\Software\Microsoft\Windows Mobile Disc\S*a*m*s*u*n*g* *B*l*a*c*k*J*a*c*k*"!\DesktopAppInstall\oemDesktop3]
"Name"="oemDesktop3"
"DisplayName"="QuickTime Player"
"Param1"="\\EXTRAS\\DESKTOP\\QuickTimePlayer\\QuickTimeInstaller.exe"
"Param2"=""
"Type"="createprocess"
"Order"=dword:00000001
"State"=dword:0000000b
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'winlogon.exe'(912)
c:\windows\system32\WININET.dll

- - - - - - - > 'lsass.exe'(972)
c:\windows\system32\WININET.dll

- - - - - - - > 'explorer.exe'(5204)
c:\windows\system32\WININET.dll
c:\windows\TEMP\logishrd\LVPrcInj01.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
———————— Other Running Processes ————————
.
c:\program files\Lavasoft\Ad-Aware 2007\aawservice.exe
c:\program files\Adobe\Photoshop Elements 6.0\PhotoshopElementsFileAgent.exe
c:\program files\ESET\ESET Smart Security\ekrn.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
c:\program files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
c:\program files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\windows\system32\nvsvc32.exe
c:\windows\system32\HPZipm12.exe
c:\program files\UPHClean\uphclean.exe
c:\windows\System32\TuneUpDefragService.exe
.
**************************************************************************
.
Completion time: 2010-04-10 17:09:47 - machine was rebooted
ComboFix-quarantined-files.txt 2010-04-10 21:09

Pre-Run: 16,367,087,616 bytes free
Post-Run: 15,882,932,224 bytes free

- - End Of File - - C3C555FE50695B2EE2C69B12EA511C9B
Hi,

1. Close any open browsers.

2. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.

3. Open notepad and copy/paste the text in the quotebox below into it:

KillAll::

Folder::
c:\program files\Your Protection
c:\documents and settings\All Users\Application Data\e70ff5a
File::
c:\documents and settings\Administrator\Local Settings\Application Data\2269221376.dll
C:\mbs.exe.exe
c:\windows\SYSTEM32\diperede.exe
FCopy::
c:\windows\ServicePackFiles\i386\spoolsv.exe | c:\windows\SYSTEM32\spoolsv.exe
c:\windows\ServicePackFiles\i386\userinit.exe | c:\windows\SYSTEM32\userinit.exe
c:\windows\ServicePackFiles\i386\explorer.exe | c:\windows\explorer.exe
c:\windows\ServicePackFiles\i386\wscntfy.exe | c:\windows\SYSTEM32\wscntfy.exe
c:\windows\ServicePackFiles\i386\ctfmon.exe | c:\windows\SYSTEM32\ctfmon.exe
Registry::
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Your Protection"=-

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"26675:TCP"=-
""=-

Save this as CFScript.txt, in the same location as ComboFix.exe


[external image: Posted Image]

Refering to the picture above, drag CFScript into ComboFix.exe

When finished, it shall produce a log for you at C:\ComboFix.txt which I will require in your next reply.






Download GMER from Here. Note the file's name and save it to your root folder, such as C:\.
  • Disconnect from the Internet and close all running programs.
  • Temporarily disable any real-time active protection so your security program drivers will not conflict with this file.
  • Click on this link to see a list of programs that should be disabled.
  • Double-click on the downloaded file to start the program. (If running Vista, right click on it and select "Run as an Administrator")
  • Allow the driver to load if asked.
  • You may be prompted to scan immediately if it detects rootkit activity.
  • If you are prompted to scan your system click "No", save the log and post back the results.
  • If not prompted, click the "Rootkit/Malware" tab.
  • On the right-side, all items to be scanned should be checked by default except for "Show All". Leave that box unchecked.
  • Select all drives that are connected to your system to be scanned.
  • Click the Scan button to begin. (Please be patient as it can take some time to complete)
  • When the scan is finished, click Save to save the scan results to your Desktop.
  • Save the file as Results.log and copy/paste the contents in your next reply.
  • Exit the program and re-enable all active protection when done.
Hi Tom - As directed, here are the two logs. Note I am now able to log on to a user account AND have the system stay viable. Unless otherwise indicated from here on out, all my work is or will be in Normal mode.

ComboFix 10-04-10.01 - Andrew 04/12/2010 22:42:21.2.2 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.511.176 [GMT -4:00]
Running from: c:\infection\CF.exe
Command switches used :: c:\infection\CFScript.txt
AV: ESET Smart Security 3.0 *On-access scanning enabled* (Outdated) {E5E70D32-0101-4F12-8FB0-D96ACA4F34C0}
FW: ESET Personal firewall *enabled* {E5E70D32-0101-4340-86A3-A7B0F1C8FFE0}

FILE ::
"c:\documents and settings\Administrator\Local Settings\Application Data\2269221376.dll"
"C:\mbs.exe.exe"
"c:\windows\SYSTEM32\diperede.exe"
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\documents and settings\Administrator\Local Settings\Application Data\2269221376.dll
c:\documents and settings\All Users\Application Data\e70ff5a
c:\documents and settings\Andrew\Local Settings\Application Data\Windows Server
c:\documents and settings\Andrew\Local Settings\Application Data\Windows Server\zvxgax.dll
c:\documents and settings\Andrew\Templates\memory.tmp
C:\mbs.exe.exe
c:\program files\Windows NT\Accessories\svchost.exe
C:\Thumbs.db
c:\windows\Install.txt
c:\windows\SYSTEM32\1054483.exe
c:\windows\system32\4744.exe
c:\windows\system32\6899225.exe
c:\windows\system32\9476282.exe
c:\windows\system32\Install.txt
c:\windows\system32\ms.bin
c:\windows\system32\msejfzrl.dll
c:\windows\system32\so.bin
c:\windows\system32\w.exe

Infected copy of c:\windows\explorer.exe was found and disinfected
Restored copy from - c:\windows\ServicePackFiles\i386\explorer.exe

.
————— FCopy —————

c:\windows\ServicePackFiles\i386\spoolsv.exe –> c:\windows\SYSTEM32\spoolsv.exe
c:\windows\ServicePackFiles\i386\userinit.exe –> c:\windows\SYSTEM32\userinit.exe
c:\windows\ServicePackFiles\i386\explorer.exe –> c:\windows\explorer.exe
c:\windows\ServicePackFiles\i386\wscntfy.exe –> c:\windows\SYSTEM32\wscntfy.exe
c:\windows\ServicePackFiles\i386\ctfmon.exe –> c:\windows\SYSTEM32\ctfmon.exe
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

——-\Legacy_BTWSVC


((((((((((((((((((((((((( Files Created from 2010-03-13 to 2010-04-13 )))))))))))))))))))))))))))))))
.

2010-04-13 03:01 . 2010-04-13 03:01 167200 —-a-w- c:\windows\system32\9121058.exe
2010-04-13 02:36 . 2010-04-13 00:52 36864 —-a-w- c:\windows\system32\d.bin
2010-04-12 12:26 . 2010-04-12 12:26 ——– d—–w- C:\OEMSettings
2010-04-12 12:26 . 2010-04-12 12:26 21035 —-a-w- c:\windows\system32\drivers\AegisP.sys
2010-04-12 12:25 . 2010-04-12 12:25 ——– d—–w- c:\program files\NETGEAR
2010-04-12 03:24 . 2010-04-12 03:24 ——– d—–w- c:\documents and settings\Andrew\Application Data\Malwarebytes
2010-04-12 03:24 . 2010-03-30 04:46 38224 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-04-12 03:24 . 2010-03-30 04:45 20824 —-a-w- c:\windows\system32\drivers\mbam.sys
2010-04-12 03:23 . 2010-04-12 03:24 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2010-04-09 11:21 . 2010-04-09 11:21 ——– d—–w- c:\program files\VS Revo Group
2010-04-09 10:59 . 2010-04-13 02:41 ——– d—–w- C:\Infection
2010-04-08 20:23 . 2010-04-08 20:23 ——– d—–w- c:\documents and settings\Administrator\Application Data\Malwarebytes
2010-04-08 20:23 . 2010-04-08 20:23 ——– d—–w- c:\documents and settings\All Users\Application Data\Malwarebytes
2010-04-07 21:05 . 2010-04-07 21:06 ——– d—–w- c:\documents and settings\NetworkService\Local Settings\Application Data\Adobe
2010-04-07 21:05 . 2010-04-12 12:45 664 —-a-w- c:\windows\system32\d3d9caps.dat

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-04-12 12:27 . 2003-10-23 07:39 ——– d–h–w- c:\program files\InstallShield Installation Information
2010-04-10 19:09 . 2002-08-29 10:00 153344 —-a-w- c:\windows\system32\drivers\dmio.sys
2010-04-05 20:01 . 2005-07-06 18:18 ——– d—–w- c:\program files\The Learning Company
2010-04-05 19:59 . 2008-05-31 12:14 ——– d—a-w- c:\documents and settings\All Users\Application Data\TEMP
2010-04-05 18:19 . 2008-07-05 16:04 ——– d—–w- c:\documents and settings\Andrew\Application Data\Skype
2010-04-05 15:24 . 2009-05-09 18:46 ——– d—–w- c:\documents and settings\Andrew\Application Data\skypePM
2010-03-26 09:23 . 2009-05-16 18:18 0 —-a-w- c:\windows\system32\drivers\lvuvc.hs
2010-03-26 09:23 . 2009-05-16 18:18 0 —-a-w- c:\windows\system32\drivers\logiflt.iad
2010-03-11 12:38 . 2004-02-06 22:05 832512 ——w- c:\windows\system32\wininet.dll
2010-03-11 12:38 . 2004-08-04 07:56 78336 —-a-w- c:\windows\system32\ieencode.dll
2010-03-11 12:38 . 2002-08-29 10:00 17408 —-a-w- c:\windows\system32\corpol.dll
2010-03-10 15:04 . 2006-03-11 21:29 ——– d—–w- c:\documents and settings\Andrew\Application Data\Image Zone Express
2010-02-12 22:12 . 2009-05-09 18:45 ——– d—–w- c:\program files\Google
2002-08-29 10:00 . 2002-08-29 10:00 94784 –sh–w- c:\windows\TWAIN.DLL
2008-04-14 00:12 . 2002-08-29 10:00 50688 –sh–w- c:\windows\twain_32.dll
2008-04-14 00:11 . 2002-08-29 10:00 1028096 –sha-w- c:\windows\SYSTEM32\mfc42.dll
2008-04-14 00:12 . 2002-08-29 10:00 57344 –sha-w- c:\windows\SYSTEM32\msvcirt.dll
2008-04-14 00:12 . 2002-08-29 10:00 413696 –sha-w- c:\windows\SYSTEM32\msvcp60.dll
2008-04-14 00:12 . 2002-08-29 10:00 551936 –sh–w- c:\windows\SYSTEM32\oleaut32.dll
2008-04-14 00:12 . 2002-08-29 10:00 84992 –sha-w- c:\windows\SYSTEM32\olepro32.dll
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-05-03 13529088]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
NETGEAR WG111v3 Smart Wizard.lnk - c:\program files\NETGEAR\WG111v3\WG111v3.exe [2007-9-12 1552384]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\egui.exe]
"Debugger"=c:\windows\system32\ahui.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\ekrn.exe]
"Debugger"=c:\windows\system32\ahui.exe

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk *\0stera\0lsdelete

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\aawservice]
@="Service"

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^America Online 8.0 Tray Icon.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\America Online 8.0 Tray Icon.lnk
backup=c:\windows\pss\America Online 8.0 Tray Icon.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^AOL Companion.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\AOL Companion.lnk
backup=c:\windows\pss\AOL Companion.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk
backup=c:\windows\pss\HP Digital Imaging Monitor.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HP Image Zone Fast Start.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\HP Image Zone Fast Start.lnk
backup=c:\windows\pss\HP Image Zone Fast Start.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HP OfficeJet Startup.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\HP OfficeJet Startup.lnk
backup=c:\windows\pss\HP OfficeJet Startup.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^TotalMedia Backup Monitor.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\TotalMedia Backup Monitor.lnk
backup=c:\windows\pss\TotalMedia Backup Monitor.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UserFaultCheck]
c:\windows\system32\dumprep 0 -u [X]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Photo Downloader]
2007-09-11 04:43 67488 —-a-w- c:\program files\Adobe\Photoshop Elements 6.0\apdproxy.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BCMSMMSG]
2003-08-29 08:59 122880 —-a-w- c:\windows\BCMSMMSG.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
2008-04-14 00:12 15360 —-a-w- c:\windows\SYSTEM32\ctfmon.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CXMon]
2001-09-19 15:18 69632 —-a-w- c:\program files\Hewlett-Packard\PhotoSmart\Photo Imaging\Hpi_monitor.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DellSupport]
2007-03-15 16:09 460784 —-a-w- c:\program files\DellSupport\DSAgnt.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\dla]
2003-08-06 06:04 114741 —-a-w- c:\windows\SYSTEM32\dla\tfswctrl.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DVDSentry]
2003-08-13 15:27 28672 —-a-w- c:\windows\SYSTEM32\DSentry.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\egui]
2008-04-23 18:57 1443072 —-a-w- c:\program files\ESET\ESET Smart Security\egui.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\H/PC Connection Agent]
2006-06-21 02:36 1207080 —-a-w- c:\program files\Microsoft ActiveSync\wcescomm.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]
2007-05-08 20:24 54840 —-a-w- c:\program files\HP\HP Software Update\hpwuSchd2.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HPDJ Taskbar Utility]
2005-03-08 04:42 176128 —-a-w- c:\windows\SYSTEM32\SPOOL\DRIVERS\W32X86\3\hpztsb12.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LogitechCommunicationsManager]
2008-08-14 21:11 565008 —-a-w- c:\program files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LogitechQuickCamRibbon]
2008-08-14 21:15 2407184 —-a-w- c:\program files\Logitech\QuickCam\Quickcam.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\mmtask]
2006-01-17 18:03 53248 —-a-w- c:\program files\MUSICMATCH\MUSICMATCH Jukebox\mmtask.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
2008-04-14 00:12 1719808 —-a-w- c:\program files\Messenger\msmsgs.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nodenable]
2008-08-22 21:33 359639 —-a-w- c:\program files\ESET\nodenable.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon]
2008-05-03 02:46 13529088 —-a-w- c:\windows\SYSTEM32\nvcpl.dll

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvMediaCenter]
2008-05-03 02:46 86016 —-a-w- c:\windows\SYSTEM32\nvmctray.dll

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nwiz]
2008-05-03 02:46 1630208 —-a-w- c:\windows\SYSTEM32\nwiz.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
2006-09-01 20:57 282624 —-a-w- c:\program files\QuickTime\qttask.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RealPlayer]
2006-05-26 16:19 1003520 —-a-w- c:\program files\Real\RealPlayer\realplay.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Share-to-Web Namespace Daemon]
2001-07-03 14:11 57344 —-a-w- c:\program files\Hewlett-Packard\PhotoSmart\HP Share-to-Web\hpgs2wnd.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpybotSD TeaTimer]
2008-01-28 15:43 2097488 –sha-r- c:\program files\Spybot - Search & Destroy\TeaTimer.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\StorageGuard]
2003-02-13 06:01 155648 —-a-w- c:\program files\Common Files\Sonic\Update Manager\sgtray.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
2003-10-23 07:43 151597 —-a-w- c:\program files\Common Files\Real\Update_OB\realsched.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"mcpromgr"=2 (0x2)
"mcmispupdmgr"=3 (0x3)
"Viewpoint Manager Service"=2 (0x2)

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" -atboottime

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
"FirewallOverride"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiVirus]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
"DisableNotifications"= 1 (0x1)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Common Files\\aol\\Loader\\aolload.exe"=
"c:\\Program Files\\Common Files\\aol\\System Information\\sinf.exe"=
"c:\\WINDOWS\\SYSTEM32\\fxsclnt.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqCopy.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpfccopy.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqPhUnl.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqDIA.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"=
"c:\program files\Microsoft ActiveSync\rapimgr.exe"= c:\program files\Microsoft ActiveSync\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager
"c:\program files\Microsoft ActiveSync\wcescomm.exe"= c:\program files\Microsoft ActiveSync\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager
"c:\program files\Microsoft ActiveSync\WCESMgr.exe"= c:\program files\Microsoft ActiveSync\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application
"c:\\Program Files\\Real\\RealPlayer\\trueplay.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Rosetta Stone\\Rosetta Stone V3 DEMO\\RosettaStoneVersion3.exe"=
"c:\\Program Files\\Rosetta Stone\\Rosetta Stone V3 DEMO\\support\\bin\\RosettaStoneLtdServices.exe"=
"c:\\Documents and Settings\\Andrew\\Local Settings\\Application Data\\Google\\Google Talk Plugin\\googletalkplugin.dll"=
"c:\\Documents and Settings\\Andrew\\Local Settings\\Application Data\\Google\\Google Talk Plugin\\googletalkplugin.exe"=
"c:\\Program Files\\Skype\\Plugin Manager\\skypePM.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\WINDOWS\\SYSTEM32\\spoolsv.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
""=

R2 ekrn;Eset Service;c:\program files\ESET\ESET Smart Security\ekrn.exe [4/23/2008 2:58 PM 472320]
R3 RTL8187B;NETGEAR WG111v3 54Mbps Wireless USB 2.0 Adapter Vista Driver;c:\windows\SYSTEM32\DRIVERS\wg111v3.sys [4/23/2007 2:11 PM 224896]
S2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [2/12/2010 6:12 PM 135664]
S4 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\Viewpoint\Common\ViewpointService.exe [1/11/2007 12:17 PM 24652]

— Other Services/Drivers In Memory —

*Deregistered* - uphcleanhlp

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp
.
Contents of the 'Scheduled Tasks' folder

2010-04-13 c:\windows\Tasks\1-Click Maintenance.job
- c:\program files\TuneUp Utilities 2008\OneClickStarter.exe [2008-02-29 18:24]

2010-04-13 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-02-12 16:09]

2010-04-13 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-02-12 16:09]

2010-04-11 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-217248739-2920639104-3160564834-1007Core.job
- c:\documents and settings\Andrew\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2009-04-20 15:50]

2010-04-13 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-217248739-2920639104-3160564834-1007UA.job
- c:\documents and settings\Andrew\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2009-04-20 15:50]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.aol.com/
mStart Page = hxxp://www.dellnet.com
Trusted Zone: turbotax.com
DPF: {193C772A-87BE-4B19-A7BB-445B226FE9A1} - hxxp://downloads.ewido.net/ewidoOnlineScan.cab
FF - ProfilePath - c:\documents and settings\Andrew\Application Data\Mozilla\Firefox\Profiles\823v7m0i.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.aol.com/
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\

—- FIREFOX POLICIES —-
FF - user.js: network.http.max-persistent-connections-per-server - 4
FF - user.js: content.max.tokenizing.time - 200000
FF - user.js: content.notify.interval - 100000
FF - user.js: content.switch.threshold - 650000
FF - user.js: nglayout.initialpaint.delay - 300
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_colors", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_popup_windows", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.enable_click_image_resizing", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("accessibility.browsewithcaret_shortcut.enabled", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("javascript.options.mem.high_water_mark", 32);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("javascript.options.mem.gc_frequency", 1600);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("svg.smil.enabled", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.trackpoint_hack.enabled", -1);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.debug", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.agedWeight", 2);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.bucketSize", 1);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.maxTimeGroupings", 25);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.timeGroupingSize", 604800);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.boundaryWeight", 25);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.prefixWeight", 5);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("html5.enable", false);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pr
ef", true);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("app.update.download.backgroundInterval", 600);
c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("app.update.url.manual", "http://www.firefox.com");
c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-ja", "mozff");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add", "addons.mozilla.org");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add.36", "getpersonas.com");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("lightweightThemes.update.enabled", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.allTabs.previews", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.hide_infobar_for_outdated_plugin", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("toolbar.customization.usesheet", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.enable", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.max", 20);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.cachetime", 20);
.
- - - - ORPHANS REMOVED - - - -

HKLM-Run-qyfvwm - c:\windows\system32\msejfzrl.dll
HKLM-Explorer_Run-mslivemsn - c:\program files\Windows NT\Accessories\svchost.exe
MSConfigStartUp-NodLogin - c:\program files\ESET\ESET Smart Security\nodlogin.exe



**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-04-12 23:07
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————

[HKEY_USERS\S-1-5-21-217248739-2920639104-3160564834-1007\Software\Microsoft\Windows Mobile Disc\S*a*m*s*u*n*g* *B*l*a*c*k*J*a*c*k*"!\CriticalAppInstall\ActiveSync]
"Name"="ActiveSync"
"DisplayName"="Microsoft ActiveSync"
"Param1"="ActiveSync"
"Type"="wellknown"
"Order"=dword:00000001
"State"=dword:00000020

[HKEY_USERS\S-1-5-21-217248739-2920639104-3160564834-1007\Software\Microsoft\Windows Mobile Disc\S*a*m*s*u*n*g* *B*l*a*c*k*J*a*c*k*"!\CriticalAppInstall\IESettings]
"Name"="IESettings"
"Type"="IESettings"
"Order"=dword:00000004
"State"=dword:0000000b

[HKEY_USERS\S-1-5-21-217248739-2920639104-3160564834-1007\Software\Microsoft\Windows Mobile Disc\S*a*m*s*u*n*g* *B*l*a*c*k*J*a*c*k*"!\CriticalAppInstall\MediaFiles]
"Name"="MediaFiles"
"Type"="MediaFiles"
"Order"=dword:00000003
"State"=dword:0000000b

[HKEY_USERS\S-1-5-21-217248739-2920639104-3160564834-1007\Software\Microsoft\Windows Mobile Disc\S*a*m*s*u*n*g* *B*l*a*c*k*J*a*c*k*"!\CriticalAppInstall\NPW]
"Name"="NPW"
"Param1"="NPW"
"Type"="wellknown"
"Order"=dword:00000002
"State"=dword:0000000b

[HKEY_USERS\S-1-5-21-217248739-2920639104-3160564834-1007\Software\Microsoft\Windows Mobile Disc\S*a*m*s*u*n*g* *B*l*a*c*k*J*a*c*k*"!\CriticalAppInstall\Outlook]
"Name"="Outlook"
"DisplayName"="Microsoft Outlook"
"Param1"="Outlook"
"Type"="wellknown"
"Order"=dword:00000000
"State"=dword:00000020

[HKEY_USERS\S-1-5-21-217248739-2920639104-3160564834-1007\Software\Microsoft\Windows Mobile Disc\S*a*m*s*u*n*g* *B*l*a*c*k*J*a*c*k*"!\DesktopAppInstall\oemDesktop2]
"Name"="oemDesktop2"
"DisplayName"="Media Wizard"
"Param1"="\\EXTRAS\\DESKTOP\\Media_Wizard\\Media_Wizard_3.0.exe"
"Param2"=""
"Type"="createprocess"
"Order"=dword:00000000
"State"=dword:0000000b

[HKEY_USERS\S-1-5-21-217248739-2920639104-3160564834-1007\Software\Microsoft\Windows Mobile Disc\S*a*m*s*u*n*g* *B*l*a*c*k*J*a*c*k*"!\DesktopAppInstall\oemDesktop3]
"Name"="oemDesktop3"
"DisplayName"="QuickTime Player"
"Param1"="\\EXTRAS\\DESKTOP\\QuickTimePlayer\\QuickTimeInstaller.exe"
"Param2"=""
"Type"="createprocess"
"Order"=dword:00000001
"State"=dword:0000000b
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'winlogon.exe'(1192)
c:\windows\system32\WININET.dll

- - - - - - - > 'lsass.exe'(1252)
c:\windows\system32\WININET.dll

- - - - - - - > 'explorer.exe'(6028)
c:\windows\system32\WININET.dll
c:\windows\TEMP\logishrd\LVPrcInj01.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
———————— Other Running Processes ————————
.
c:\program files\Lavasoft\Ad-Aware 2007\aawservice.exe
c:\program files\Adobe\Photoshop Elements 6.0\PhotoshopElementsFileAgent.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
c:\program files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
c:\program files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\windows\system32\nvsvc32.exe
c:\windows\system32\HPZipm12.exe
c:\program files\UPHClean\uphclean.exe
c:\program files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
c:\windows\system32\rundll32.exe
.
**************************************************************************
.
Completion time: 2010-04-12 23:17:11 - machine was rebooted
ComboFix-quarantined-files.txt 2010-04-13 03:17

Pre-Run: 18,058,436,608 bytes free
Post-Run: 18,045,726,720 bytes free

WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Microsoft Windows XP Professional" /fastdetect /NoExecute=OptIn

- - End Of File - - 7A3FFD33A45B0C174B3A013B4991B106


GMER 1.0.15.15281 - http://www.gmer.net
Rootkit quick scan 2010-04-12 23:21:15
Windows 5.1.2600 Service Pack 3
Running: 5xutogdr.exe; Driver: C:\DOCUME~1\Andrew\LOCALS~1\Temp\fxtdqpog.sys


—- Devices - GMER 1.0.15 —-

AttachedDevice \FileSystem\Ntfs \Ntfs eamon.sys (Amon monitor/ESET)
AttachedDevice \FileSystem\Fastfat \Fat eamon.sys (Amon monitor/ESET)
AttachedDevice \Driver\Tcpip \Device\Ip epfwtdi.sys (Eset Personal Firewall TDI filter/ESET)
AttachedDevice \Driver\Tcpip \Device\Tcp epfwtdi.sys (Eset Personal Firewall TDI filter/ESET)
AttachedDevice \Driver\Tcpip \Device\Udp epfwtdi.sys (Eset Personal Firewall TDI filter/ESET)
AttachedDevice \Driver\Tcpip \Device\RawIp epfwtdi.sys (Eset Personal Firewall TDI filter/ESET)

Device -> \Driver\atapi \Device\Harddisk0\DR0 83319AC8

—- Files - GMER 1.0.15 —-

File C:\WINDOWS\system32\drivers\atapi.sys suspicious modification

—- EOF - GMER 1.0.15 —-


Hope I did OK. Note: I did install a wireless network device (USB based) so I could get to the 'net with it. It's unplugged from the system. I'm ready for the next step(s). Should MBAM be run now? Just curious if we're going to use it eventually.

Standing by…

H
Looks better. Please delete your copy of Combofix and download a fresh run, run the tool with doubleclick from normal mode and post back with the content of the logfile.
Hi Tom - we still have AVE.exe running which puts out "XP Defender" in the systray. System much more responsive but it's still not what we'd like to see. I'll wait up for you next instruction. I wonder if you have a favorite clean-up/fix-up routine handy that you could share with me? This was run from Standard mode.

Thanks and I'm standing by…

ComboFix 10-04-14.01 - Andrew 04/14/2010 17:20:05.3.2 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.511.251 [GMT -4:00]
Running from: c:\infection\ComboFix.exe
AV: ESET Smart Security 3.0 *On-access scanning enabled* (Outdated) {E5E70D32-0101-4F12-8FB0-D96ACA4F34C0}
FW: ESET Personal firewall *enabled* {E5E70D32-0101-4340-86A3-A7B0F1C8FFE0}
* Resident AV is active

.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\program files\Windows NT\Accessories\svchost.exe
c:\windows\system32\1611139.exe
c:\windows\system32\9121058.exe
c:\windows\system32\ms.bin
c:\windows\system32\msejfzrl.dll
c:\windows\system32\so.bin
c:\windows\system32\w.exe
c:\windows\TEMP\logishrd\LVPrcInj01.dll

Infected copy of c:\windows\system32\userinit.exe was found and disinfected
Restored copy from - c:\windows\ServicePackFiles\i386\userinit.exe

Infected copy of c:\windows\system32\spoolsv.exe was found and disinfected
Restored copy from - c:\windows\ServicePackFiles\i386\spoolsv.exe

Infected copy of c:\windows\explorer.exe was found and disinfected
Restored copy from - c:\windows\ServicePackFiles\i386\explorer.exe

.
((((((((((((((((((((((((( Files Created from 2010-03-14 to 2010-04-14 )))))))))))))))))))))))))))))))
.

2010-04-13 03:40 . 2010-04-13 03:40 ——– d—–w- c:\program files\CCleaner
2010-04-13 02:36 . 2010-04-13 15:19 36864 —-a-w- c:\windows\system32\d.bin
2010-04-12 12:26 . 2010-04-12 12:26 ——– d—–w- C:\OEMSettings
2010-04-12 12:26 . 2010-04-12 12:26 21035 —-a-w- c:\windows\system32\drivers\AegisP.sys
2010-04-12 12:25 . 2010-04-12 12:25 ——– d—–w- c:\program files\NETGEAR
2010-04-12 03:24 . 2010-04-12 03:24 ——– d—–w- c:\documents and settings\Andrew\Application Data\Malwarebytes
2010-04-12 03:24 . 2010-03-30 04:46 38224 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-04-12 03:24 . 2010-03-30 04:45 20824 —-a-w- c:\windows\system32\drivers\mbam.sys
2010-04-12 03:23 . 2010-04-12 03:24 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2010-04-09 11:21 . 2010-04-09 11:21 ——– d—–w- c:\program files\VS Revo Group
2010-04-09 10:59 . 2010-04-14 21:13 ——– d—–w- C:\Infection
2010-04-08 20:23 . 2010-04-08 20:23 ——– d—–w- c:\documents and settings\Administrator\Application Data\Malwarebytes
2010-04-08 20:23 . 2010-04-08 20:23 ——– d—–w- c:\documents and settings\All Users\Application Data\Malwarebytes
2010-04-07 21:05 . 2010-04-07 21:06 ——– d—–w- c:\documents and settings\NetworkService\Local Settings\Application Data\Adobe
2010-04-07 21:05 . 2010-04-12 12:45 664 —-a-w- c:\windows\system32\d3d9caps.dat

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-04-14 21:55 . 2002-08-29 10:00 153344 —-a-w- c:\windows\system32\drivers\dmio.sys
2010-04-13 03:42 . 2008-06-01 04:21 ——– d—–w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2010-04-12 12:27 . 2003-10-23 07:39 ——– d–h–w- c:\program files\InstallShield Installation Information
2010-04-05 20:01 . 2005-07-06 18:18 ——– d—–w- c:\program files\The Learning Company
2010-04-05 19:59 . 2008-05-31 12:14 ——– d—a-w- c:\documents and settings\All Users\Application Data\TEMP
2010-04-05 18:19 . 2008-07-05 16:04 ——– d—–w- c:\documents and settings\Andrew\Application Data\Skype
2010-04-05 15:24 . 2009-05-09 18:46 ——– d—–w- c:\documents and settings\Andrew\Application Data\skypePM
2010-03-26 09:23 . 2009-05-16 18:18 0 —-a-w- c:\windows\system32\drivers\lvuvc.hs
2010-03-26 09:23 . 2009-05-16 18:18 0 —-a-w- c:\windows\system32\drivers\logiflt.iad
2010-03-11 12:38 . 2004-02-06 22:05 832512 ——w- c:\windows\system32\wininet.dll
2010-03-11 12:38 . 2004-08-04 07:56 78336 —-a-w- c:\windows\system32\ieencode.dll
2010-03-11 12:38 . 2002-08-29 10:00 17408 —-a-w- c:\windows\system32\corpol.dll
2010-03-10 15:04 . 2006-03-11 21:29 ——– d—–w- c:\documents and settings\Andrew\Application Data\Image Zone Express
2010-02-05 15:39 . 2010-02-05 15:39 251376 —-a-w- c:\documents and settings\Andrew\Application Data\Mozilla\plugins\npgoogletalk.dll
2002-08-29 10:00 . 2002-08-29 10:00 94784 –sh–w- c:\windows\TWAIN.DLL
2008-04-14 00:12 . 2002-08-29 10:00 50688 –sh–w- c:\windows\twain_32.dll
2008-04-14 00:11 . 2002-08-29 10:00 1028096 –sha-w- c:\windows\SYSTEM32\mfc42.dll
2008-04-14 00:12 . 2002-08-29 10:00 57344 –sha-w- c:\windows\SYSTEM32\msvcirt.dll
2008-04-14 00:12 . 2002-08-29 10:00 413696 –sha-w- c:\windows\SYSTEM32\msvcp60.dll
2008-04-14 00:12 . 2002-08-29 10:00 551936 –sh–w- c:\windows\SYSTEM32\oleaut32.dll
2008-04-14 00:12 . 2002-08-29 10:00 84992 –sha-w- c:\windows\SYSTEM32\olepro32.dll
.

——- Sigcheck ——-

[7] 2008-04-14 . D8E14A61ACC1D4A6CD0D38AEBAC7FA3B . 57856 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\spoolsv.exe
[7] 2008-04-14 . D8E14A61ACC1D4A6CD0D38AEBAC7FA3B . 57856 . . [5.1.2600.5512] . . c:\windows\SoftwareDistribution\Download\dd9ab5193501484cf5e6884fa1d22f9e\spoolsv.exe
[-] 2008-04-14 . 7FAD372CF7EB2551BD9549BA6EA43908 . 82432 . . [5.1.2600.5512] . . c:\windows\SYSTEM32\spoolsv.exe
[7] 2005-06-11 . AD3D9D191AEA7B5445FE1D82FFBB4788 . 57856 . . [5.1.2600.2696] . . c:\windows\$hf_mig$\KB896423\SP2QFE\spoolsv.exe
[7] 2005-06-10 . DA81EC57ACD4CDC3D4C51CF3D409AF9F . 57856 . . [5.1.2600.2696] . . c:\windows\$NtServicePackUninstall$\spoolsv.exe
[7] 2004-08-04 . 7435B108B935E42EA92CA94F59C8E717 . 57856 . . [5.1.2600.2180] . . c:\windows\$NtUninstallKB896423$\spoolsv.exe

[7] 2008-04-14 . A93AEE1928A9D7CE3E16D24EC7380F89 . 26112 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\userinit.exe
[7] 2008-04-14 . A93AEE1928A9D7CE3E16D24EC7380F89 . 26112 . . [5.1.2600.5512] . . c:\windows\SoftwareDistribution\Download\dd9ab5193501484cf5e6884fa1d22f9e\userinit.exe
[-] 2008-04-14 . 92AB92206420FE63CBB03E05E37A4D94 . 50688 . . [5.1.2600.5512] . . c:\windows\SYSTEM32\userinit.exe
[7] 2004-08-04 . 39B1FFB03C2296323832ACBAE50D2AFF . 24576 . . [5.1.2600.2180] . . c:\windows\$NtServicePackUninstall$\userinit.exe

[-] 2008-04-14 . DC1DDE0FCD2CDCEF879F6C101A486B7B . 1058304 . . [6.00.2900.5512] . . c:\windows\explorer.exe
[7] 2008-04-14 . 12896823FB95BFB3DC9B46BCAEDC9923 . 1033728 . . [6.00.2900.5512] . . c:\windows\ServicePackFiles\i386\explorer.exe
[7] 2008-04-14 . 12896823FB95BFB3DC9B46BCAEDC9923 . 1033728 . . [6.00.2900.5512] . . c:\windows\SoftwareDistribution\Download\dd9ab5193501484cf5e6884fa1d22f9e\explorer.exe
[7] 2007-06-13 . 7712DF0CDDE3A5AC89843E61CD5B3658 . 1033216 . . [6.00.2900.3156] . . c:\windows\$hf_mig$\KB938828\SP2QFE\explorer.exe
[7] 2007-06-13 . 97BD6515465659FF8F3B7BE375B2EA87 . 1033216 . . [6.00.2900.3156] . . c:\windows\$NtServicePackUninstall$\explorer.exe
[7] 2004-08-04 . A0732187050030AE399B241436565E64 . 1032192 . . [6.00.2900.2180] . . c:\windows\$NtUninstallKB938828$\explorer.exe

[7] 2008-04-14 . F92E1076C42FCD6DB3D72D8CFE9816D5 . 13824 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\wscntfy.exe
[7] 2008-04-14 . F92E1076C42FCD6DB3D72D8CFE9816D5 . 13824 . . [5.1.2600.5512] . . c:\windows\SoftwareDistribution\Download\dd9ab5193501484cf5e6884fa1d22f9e\wscntfy.exe
[-] 2008-04-14 . 1D431AAA57087C1E84A2995795A2BD88 . 38400 . . [5.1.2600.5512] . . c:\windows\SYSTEM32\wscntfy.exe
[7] 2004-08-04 . 49911DD39E023BB6C45E4E436CFBD297 . 13824 . . [5.1.2600.2180] . . c:\windows\$NtServicePackUninstall$\wscntfy.exe

[7] 2008-04-14 . 5F1D5F88303D4A4DBC8E5F97BA967CC3 . 15360 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\ctfmon.exe
[7] 2008-04-14 . 5F1D5F88303D4A4DBC8E5F97BA967CC3 . 15360 . . [5.1.2600.5512] . . c:\windows\SoftwareDistribution\Download\dd9ab5193501484cf5e6884fa1d22f9e\ctfmon.exe
[-] 2008-04-14 . 3204B76ACD3E7269DB5F4F8DEFD0034A . 39936 . . [5.1.2600.5512] . . c:\windows\SYSTEM32\ctfmon.exe
[7] 2004-08-04 . 24232996A38C0B0CF151C2140AE29FC8 . 15360 . . [5.1.2600.2180] . . c:\windows\$NtServicePackUninstall$\ctfmon.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-05-03 13529088]
"qyfvwm"="c:\windows\system32\msejfzrl.dll" [BU]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\Currentversion\policies\explorer\Run]
"mslivemsn"="c:\program files\Windows NT\Accessories\svchost.exe" [BU]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
NETGEAR WG111v3 Smart Wizard.lnk - c:\program files\NETGEAR\WG111v3\WG111v3.exe [2007-9-12 1552384]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk *\0stera\0lsdelete

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\aawservice]
@="Service"

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^America Online 8.0 Tray Icon.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\America Online 8.0 Tray Icon.lnk
backup=c:\windows\pss\America Online 8.0 Tray Icon.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^AOL Companion.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\AOL Companion.lnk
backup=c:\windows\pss\AOL Companion.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk
backup=c:\windows\pss\HP Digital Imaging Monitor.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HP Image Zone Fast Start.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\HP Image Zone Fast Start.lnk
backup=c:\windows\pss\HP Image Zone Fast Start.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HP OfficeJet Startup.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\HP OfficeJet Startup.lnk
backup=c:\windows\pss\HP OfficeJet Startup.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^TotalMedia Backup Monitor.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\TotalMedia Backup Monitor.lnk
backup=c:\windows\pss\TotalMedia Backup Monitor.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UserFaultCheck]
c:\windows\system32\dumprep 0 -u [X]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Photo Downloader]
2007-09-11 04:43 67488 —-a-w- c:\program files\Adobe\Photoshop Elements 6.0\apdproxy.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BCMSMMSG]
2003-08-29 08:59 122880 —-a-w- c:\windows\BCMSMMSG.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
2008-04-14 00:12 39936 —-a-w- c:\windows\SYSTEM32\ctfmon.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CXMon]
2001-09-19 15:18 69632 —-a-w- c:\program files\Hewlett-Packard\PhotoSmart\Photo Imaging\Hpi_monitor.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DellSupport]
2007-03-15 16:09 460784 —-a-w- c:\program files\DellSupport\DSAgnt.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\dla]
2003-08-06 06:04 114741 —-a-w- c:\windows\SYSTEM32\dla\tfswctrl.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DVDSentry]
2003-08-13 15:27 28672 —-a-w- c:\windows\SYSTEM32\DSentry.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\egui]
2008-04-23 18:57 1443072 —-a-w- c:\program files\ESET\ESET Smart Security\egui.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\H/PC Connection Agent]
2006-06-21 02:36 1207080 —-a-w- c:\program files\Microsoft ActiveSync\wcescomm.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]
2007-05-08 20:24 54840 —-a-w- c:\program files\HP\HP Software Update\hpwuSchd2.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HPDJ Taskbar Utility]
2005-03-08 04:42 176128 —-a-w- c:\windows\SYSTEM32\SPOOL\DRIVERS\W32X86\3\hpztsb12.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LogitechCommunicationsManager]
2008-08-14 21:11 565008 —-a-w- c:\program files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LogitechQuickCamRibbon]
2008-08-14 21:15 2407184 —-a-w- c:\program files\Logitech\QuickCam\Quickcam.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\mmtask]
2006-01-17 18:03 53248 —-a-w- c:\program files\MUSICMATCH\MUSICMATCH Jukebox\mmtask.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
2008-04-14 00:12 1719808 —-a-w- c:\program files\Messenger\msmsgs.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nodenable]
2008-08-22 21:33 359639 —-a-w- c:\program files\ESET\nodenable.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon]
2008-05-03 02:46 13529088 —-a-w- c:\windows\SYSTEM32\nvcpl.dll

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvMediaCenter]
2008-05-03 02:46 86016 —-a-w- c:\windows\SYSTEM32\nvmctray.dll

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nwiz]
2008-05-03 02:46 1630208 —-a-w- c:\windows\SYSTEM32\nwiz.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
2006-09-01 20:57 282624 —-a-w- c:\program files\QuickTime\qttask.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RealPlayer]
2006-05-26 16:19 1003520 —-a-w- c:\program files\Real\RealPlayer\realplay.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Share-to-Web Namespace Daemon]
2001-07-03 14:11 57344 —-a-w- c:\program files\Hewlett-Packard\PhotoSmart\HP Share-to-Web\hpgs2wnd.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpybotSD TeaTimer]
2008-01-28 15:43 2097488 –sha-r- c:\program files\Spybot - Search & Destroy\TeaTimer.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\StorageGuard]
2003-02-13 06:01 155648 —-a-w- c:\program files\Common Files\Sonic\Update Manager\sgtray.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
2003-10-23 07:43 151597 —-a-w- c:\program files\Common Files\Real\Update_OB\realsched.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"mcpromgr"=2 (0x2)
"mcmispupdmgr"=3 (0x3)
"Viewpoint Manager Service"=2 (0x2)

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" -atboottime

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
"FirewallOverride"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiVirus]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
"DisableNotifications"= 1 (0x1)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Common Files\\aol\\Loader\\aolload.exe"=
"c:\\Program Files\\Common Files\\aol\\System Information\\sinf.exe"=
"c:\\WINDOWS\\SYSTEM32\\fxsclnt.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqCopy.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpfccopy.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqPhUnl.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqDIA.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"=
"c:\program files\Microsoft ActiveSync\rapimgr.exe"= c:\program files\Microsoft ActiveSync\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager
"c:\program files\Microsoft ActiveSync\wcescomm.exe"= c:\program files\Microsoft ActiveSync\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager
"c:\program files\Microsoft ActiveSync\WCESMgr.exe"= c:\program files\Microsoft ActiveSync\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application
"c:\\Program Files\\Real\\RealPlayer\\trueplay.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Rosetta Stone\\Rosetta Stone V3 DEMO\\RosettaStoneVersion3.exe"=
"c:\\Program Files\\Rosetta Stone\\Rosetta Stone V3 DEMO\\support\\bin\\RosettaStoneLtdServices.exe"=
"c:\\Documents and Settings\\Andrew\\Local Settings\\Application Data\\Google\\Google Talk Plugin\\googletalkplugin.dll"=
"c:\\Documents and Settings\\Andrew\\Local Settings\\Application Data\\Google\\Google Talk Plugin\\googletalkplugin.exe"=
"c:\\Program Files\\Skype\\Plugin Manager\\skypePM.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\WINDOWS\\SYSTEM32\\spoolsv.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
""=

R2 ekrn;Eset Service;c:\program files\ESET\ESET Smart Security\ekrn.exe [4/23/2008 2:58 PM 472320]
R3 RTL8187B;NETGEAR WG111v3 54Mbps Wireless USB 2.0 Adapter Vista Driver;c:\windows\SYSTEM32\DRIVERS\wg111v3.sys [4/23/2007 2:11 PM 224896]
S2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [2/12/2010 6:12 PM 135664]
S4 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\Viewpoint\Common\ViewpointService.exe [1/11/2007 12:17 PM 24652]

— Other Services/Drivers In Memory —

*Deregistered* - uphcleanhlp

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp
.
Contents of the 'Scheduled Tasks' folder

2010-04-14 c:\windows\Tasks\1-Click Maintenance.job
- c:\program files\TuneUp Utilities 2008\OneClickStarter.exe [2008-02-29 18:24]

2010-04-14 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-02-12 16:09]

2010-04-13 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-02-12 16:09]

2010-04-11 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-217248739-2920639104-3160564834-1007Core.job
- c:\documents and settings\Andrew\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2009-04-20 15:50]

2010-04-13 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-217248739-2920639104-3160564834-1007UA.job
- c:\documents and settings\Andrew\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2009-04-20 15:50]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.aol.com/
mStart Page = hxxp://www.dellnet.com
Trusted Zone: turbotax.com
DPF: {193C772A-87BE-4B19-A7BB-445B226FE9A1} - hxxp://downloads.ewido.net/ewidoOnlineScan.cab
FF - ProfilePath - c:\documents and settings\Andrew\Application Data\Mozilla\Firefox\Profiles\823v7m0i.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.aol.com/
FF - plugin: c:\documents and settings\Andrew\Application Data\Mozilla\plugins\npgoogletalk.dll
FF - plugin: c:\documents and settings\Andrew\Local Settings\Application Data\Google\Update\1.2.183.23\npGoogleOneClick8.dll
FF - plugin: c:\program files\Google\Update\1.2.183.23\npGoogleOneClick8.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\

—- FIREFOX POLICIES —-
FF - user.js: network.http.max-persistent-connections-per-server - 4
FF - user.js: content.max.tokenizing.time - 200000
FF - user.js: content.notify.interval - 100000
FF - user.js: content.switch.threshold - 650000
FF - user.js: nglayout.initialpaint.delay - 300
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_colors", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_popup_windows", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.enable_click_image_resizing", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("accessibility.browsewithcaret_shortcut.enabled", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("javascript.options.mem.high_water_mark", 32);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("javascript.options.mem.gc_frequency", 1600);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("svg.smil.enabled", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.trackpoint_hack.enabled", -1);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.debug", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.agedWeight", 2);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.bucketSize", 1);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.maxTimeGroupings", 25);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.timeGroupingSize", 604800);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.boundaryWeight", 25);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.prefixWeight", 5);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("html5.enable", false);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pr
ef", true);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("app.update.download.backgroundInterval", 600);
c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("app.update.url.manual", "http://www.firefox.com");
c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-ja", "mozff");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add", "addons.mozilla.org");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add.36", "getpersonas.com");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("lightweightThemes.update.enabled", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.allTabs.previews", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.hide_infobar_for_outdated_plugin", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("toolbar.customization.usesheet", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.enable", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.max", 20);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.cachetime", 20);
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-04-14 18:13
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************

Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer, http://www.gmer.net

device: opened successfully
user: MBR read successfully
called modules: ntoskrnl.exe CLASSPNP.SYS disk.sys >>UNKNOWN [0x8331CAC8]<<
kernel: MBR read successfully
detected MBR rootkit hooks:
\Driver\Disk -> CLASSPNP.SYS @ 0xf86baf28
\Driver\ACPI -> ACPI.sys @ 0xf862dcb8
\Driver\atapi -> atapi.sys @ 0xf85bf852
IoDeviceObjectType -> DeleteProcedure -> ntoskrnl.exe @ 0x805e668e
ParseProcedure -> ntoskrnl.exe @ 0x8057b6b1
\Device\Harddisk0\DR0 -> DeleteProcedure -> ntoskrnl.exe @ 0x805e668e
ParseProcedure -> ntoskrnl.exe @ 0x8057b6b1
NDIS: -> SendCompleteHandler -> 0x0
PacketIndicateHandler -> 0x0
SendHandler -> 0x0
user & kernel MBR OK

**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————

[HKEY_USERS\S-1-5-21-217248739-2920639104-3160564834-1007\Software\Microsoft\Windows Mobile Disc\S*a*m*s*u*n*g* *B*l*a*c*k*J*a*c*k*"!\CriticalAppInstall\ActiveSync]
"Name"="ActiveSync"
"DisplayName"="Microsoft ActiveSync"
"Param1"="ActiveSync"
"Type"="wellknown"
"Order"=dword:00000001
"State"=dword:00000020

[HKEY_USERS\S-1-5-21-217248739-2920639104-3160564834-1007\Software\Microsoft\Windows Mobile Disc\S*a*m*s*u*n*g* *B*l*a*c*k*J*a*c*k*"!\CriticalAppInstall\IESettings]
"Name"="IESettings"
"Type"="IESettings"
"Order"=dword:00000004
"State"=dword:0000000b

[HKEY_USERS\S-1-5-21-217248739-2920639104-3160564834-1007\Software\Microsoft\Windows Mobile Disc\S*a*m*s*u*n*g* *B*l*a*c*k*J*a*c*k*"!\CriticalAppInstall\MediaFiles]
"Name"="MediaFiles"
"Type"="MediaFiles"
"Order"=dword:00000003
"State"=dword:0000000b

[HKEY_USERS\S-1-5-21-217248739-2920639104-3160564834-1007\Software\Microsoft\Windows Mobile Disc\S*a*m*s*u*n*g* *B*l*a*c*k*J*a*c*k*"!\CriticalAppInstall\NPW]
"Name"="NPW"
"Param1"="NPW"
"Type"="wellknown"
"Order"=dword:00000002
"State"=dword:0000000b

[HKEY_USERS\S-1-5-21-217248739-2920639104-3160564834-1007\Software\Microsoft\Windows Mobile Disc\S*a*m*s*u*n*g* *B*l*a*c*k*J*a*c*k*"!\CriticalAppInstall\Outlook]
"Name"="Outlook"
"DisplayName"="Microsoft Outlook"
"Param1"="Outlook"
"Type"="wellknown"
"Order"=dword:00000000
"State"=dword:00000020

[HKEY_USERS\S-1-5-21-217248739-2920639104-3160564834-1007\Software\Microsoft\Windows Mobile Disc\S*a*m*s*u*n*g* *B*l*a*c*k*J*a*c*k*"!\DesktopAppInstall\oemDesktop2]
"Name"="oemDesktop2"
"DisplayName"="Media Wizard"
"Param1"="\\EXTRAS\\DESKTOP\\Media_Wizard\\Media_Wizard_3.0.exe"
"Param2"=""
"Type"="createprocess"
"Order"=dword:00000000
"State"=dword:0000000b

[HKEY_USERS\S-1-5-21-217248739-2920639104-3160564834-1007\Software\Microsoft\Windows Mobile Disc\S*a*m*s*u*n*g* *B*l*a*c*k*J*a*c*k*"!\DesktopAppInstall\oemDesktop3]
"Name"="oemDesktop3"
"DisplayName"="QuickTime Player"
"Param1"="\\EXTRAS\\DESKTOP\\QuickTimePlayer\\QuickTimeInstaller.exe"
"Param2"=""
"Type"="createprocess"
"Order"=dword:00000001
"State"=dword:0000000b
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'winlogon.exe'(1192)
c:\windows\system32\WININET.dll

- - - - - - - > 'lsass.exe'(1252)
c:\windows\system32\WININET.dll

- - - - - - - > 'explorer.exe'(5008)
c:\windows\system32\WININET.dll
c:\windows\TEMP\logishrd\LVPrcInj01.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
———————— Other Running Processes ————————
.
c:\program files\Lavasoft\Ad-Aware 2007\aawservice.exe
c:\program files\Adobe\Photoshop Elements 6.0\PhotoshopElementsFileAgent.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
c:\program files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
c:\program files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\windows\system32\nvsvc32.exe
c:\windows\system32\HPZipm12.exe
c:\program files\UPHClean\uphclean.exe
.
**************************************************************************
.
Completion time: 2010-04-14 18:24:13 - machine was rebooted
ComboFix-quarantined-files.txt 2010-04-14 22:24
ComboFix2.txt 2010-04-13 03:17

Pre-Run: 18,269,937,664 bytes free
Post-Run: 18,176,139,264 bytes free

- - End Of File - - 6EC459C6D1E03E5D93BC2DC3D9D58B58
Hi Tom - I know you'll be back to me but I have bigger problems now. I started it up just now because I simply wanted to copy a few files over (CCleaner, Defraggler) in prep for when you give me the OK. I couldn't copy anything because I can't log on! The standard icon-based log on screen appears after Windows XP loads up, I click on an icon (my brother's because he's an admin) and it briefly (about 1/2 second) puts the wallpaper up then immediately drops to "Saving your settings" then logs off back to the icon-based log on screen. I retried this with the two other user accounts - same deal. I then invoked safe mode which adds an extra "Administrator" log on icon. Again it won't allow a log on any one of the four because it logs off immediately! I turned it off and unplugged everything. Rebooted. No luck. This I've never seen but I'm sure you may have. Again, I'll hold on until you can take a look. Of course I can't tell if anything works now since I turned it off Apr 14. Update: Apr 17, 2010. Tom, I'm going to go to another forum to see if I can resolve the "log-in/log-out loop" situation. Obviously, we can't continue to clean and restore this without the ability to log on. Now, I have absolutely no right whatsoever to whine/complain however, my last post here was 4/14. It's now 3 days later. I have tried very hard to stay engaged which I know is often difficult for you volunteers to manage. I check this thread 4-5 times a day - minimum. At this point, I'm not going to be able to hold on/wait much longer before I have to take the whole issue somewhere else. Again, I don't want to come across as arogant or impaitent and I do just want to say I realize you are all volunteers, and I recognize that you all are very busy plus you have your own lives to live as well. H

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI